403Webshell
Server IP : 162.241.226.12  /  Your IP : 216.73.217.142
Web Server : Apache
System : Linux box5305.bluehost.com 5.14.0-687.39.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Aug 18 06:09:16 EDT 2026 x86_64
User : zphiblgz ( 1848)
PHP Version : 8.1.34
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /usr/local/apache/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/local/apache/error_log
[Thu Sep 17 15:04:31.228385 2026] [lsapi:notice] [pid 907280:tid 907280] mod_lsapi:  version 1.1-92
[Thu Sep 17 15:04:31.234272 2026] [:notice] [pid 955834:tid 955834] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 955834 started
[Thu Sep 17 15:04:31.306357 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tylerblantonmusic.tylerblanton.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.317090 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: deraiz-mx.xavierlopezmiranda.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.358973 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ahmedteleb.tasameem-eg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.364318 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fst-i.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.365310 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fstsprinkler.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.371373 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: southislandpie.southislandpie.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.395632 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardashphotography.reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.412943 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcp-u.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.413832 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.415317 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reedcustomprinting.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.416195 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpphotorestoration.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.417075 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpmobileartscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.418436 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rjglobalhq.com.rebeccamerzius.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.472902 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mermco.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.473656 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ad1homes.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.474556 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-7b36017a.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.479267 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-3f11e808.livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.507448 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: api.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.508229 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: admin.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.537600 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: hamzaabdulhaq.gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.565428 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: site.tengushee.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.608415 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ayfertbarak.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.609325 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: becorenovation.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.610076 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: agent-immobilier.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.614740 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sqlerudition.commutervibe.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.619296 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bothe-net.cyber21.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.642469 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: troopkcampcadet.campcadetmontco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.646032 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vedur-app.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.646865 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: weather-is.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.647793 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tengja-net.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.648676 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bookin-city.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.649501 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-c557c2bf.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.650335 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-1a493541.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.651260 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitlinwhittington.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.651960 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jarrodandcaitlin-us.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.690861 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b2133dcc.idautovic.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.726928 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wellfedhealth.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.728650 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wear-out.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.733976 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vogito-inno.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.759966 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: thegoatmentality.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.781101 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.798175 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rpimanufacturing.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.799033 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rosebar.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.805782 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: revelinfear.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.808484 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.824258 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pazcreativehomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.827636 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pagepress.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.841372 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nikistepanianmft.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.844204 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nexgenimplant.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.858381 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mengesphotos.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.860531 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mdlzbenefits.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.865430 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: macmanagement.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.873862 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: lifepointechurchga.org:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.885409 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.889269 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kbmautomation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.895423 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jminner.photo:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.901323 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: janetaylor.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.902842 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.930853 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.949928 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ffwdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.951506 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: evansilver.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.953885 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ericbabin.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.959778 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ellenhirshberg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.981620 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: comfortspecialist.info:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.992923 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: biggselectrical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.995413 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.997084 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.998452 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bvpowersports.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.999159 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buliblog.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:31.999979 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buildingpro.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.004341 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bodylanguageohio.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.031762 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: afbaco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.033340 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: abelardpsychotherapy.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.137794 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b0f84876.robertsinteractive.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.145642 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tracertgame-com.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.147718 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-f2c0397e.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.150052 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-19b382b5.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.211711 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: marinabelous.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.228584 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: houlaentertainment.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.267030 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:04:32.282453 2026] [qos:notice] [pid 907280:tid 907280] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Sep 17 15:04:32.528388 2026] [http2:info] [pid 907280:tid 907280] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Thu Sep 17 15:04:32.533182 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Sep 17 15:04:32.533193 2026] [core:notice] [pid 907280:tid 907280] AH00094: Command line: '/usr/sbin/httpd'
[Thu Sep 17 15:04:33.584959 2026] [http2:info] [pid 955873:tid 955873] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:04:33.607870 2026] [security2:error] [pid 955873:tid 956009] [client 193.36.224.148:58615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhroYgAAARA"]
[Thu Sep 17 15:04:33.608008 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:44892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-blogs.php"] [unique_id "aqxV4RFTPRVSLOsRVhroXwAAAQs"]
[Thu Sep 17 15:04:33.608117 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:44892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-blogs.php"] [unique_id "aqxV4RFTPRVSLOsRVhroXwAAAQs"]
[Thu Sep 17 15:04:33.608822 2026] [fcgid:warn] [pid 955873:tid 956015] (70014)End of file found: [client 66.132.172.189:5576] mod_fcgid: can't get data from http client
[Thu Sep 17 15:04:33.609190 2026] [security2:error] [pid 955873:tid 956003] [client 141.98.252.162:56410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV4RFTPRVSLOsRVhroXgAAAQo"]
[Thu Sep 17 15:04:33.672181 2026] [security2:error] [pid 955873:tid 956015] [client 85.208.98.203:12988] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/modernizr.custom.min.js"] [unique_id "aqxV4RFTPRVSLOsRVhrocQAAARY"]
[Thu Sep 17 15:04:33.747355 2026] [security2:error] [pid 955873:tid 956031] [client 52.231.79.181:1796] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "toolmix24.sinkgp.com"] [uri "/1.php"] [unique_id "aqxV4RFTPRVSLOsRVhroegAAASY"]
[Thu Sep 17 15:04:33.747462 2026] [security2:error] [pid 955873:tid 956031] [client 52.231.79.181:1796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/1.php"] [unique_id "aqxV4RFTPRVSLOsRVhroegAAASY"]
[Thu Sep 17 15:04:33.766729 2026] [security2:error] [pid 955873:tid 956019] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/opt/.env"] [unique_id "aqxV4RFTPRVSLOsRVhroewAAARo"]
[Thu Sep 17 15:04:33.829147 2026] [security2:error] [pid 955873:tid 956041] [client 185.55.149.49:50267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogQAAATA"]
[Thu Sep 17 15:04:33.829249 2026] [security2:error] [pid 955873:tid 956041] [client 185.55.149.49:50267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogQAAATA"]
[Thu Sep 17 15:04:33.833377 2026] [security2:error] [pid 955873:tid 956076] [client 104.234.19.147:52503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhroggAAAVM"]
[Thu Sep 17 15:04:33.840522 2026] [security2:error] [pid 955873:tid 956048] [client 34.166.134.22:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/server-info.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogwAAATc"]
[Thu Sep 17 15:04:33.894088 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:57317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrohwAAARE"]
[Thu Sep 17 15:04:33.894197 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:57317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV4RFTPRVSLOsRVhrohwAAARE"]
[Thu Sep 17 15:04:33.896898 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-constants.php"] [unique_id "aqxV4RFTPRVSLOsRVhroiAAAAVw"]
[Thu Sep 17 15:04:33.897015 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:58292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-constants.php"] [unique_id "aqxV4RFTPRVSLOsRVhroiAAAAVw"]
[Thu Sep 17 15:04:33.898363 2026] [security2:error] [pid 955873:tid 956049] [client 129.121.122.126:50765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhroeQAAATg"]
[Thu Sep 17 15:04:33.928269 2026] [security2:error] [pid 955873:tid 956089] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/laravel/.env"] [unique_id "aqxV4RFTPRVSLOsRVhrojAAAAWA"]
[Thu Sep 17 15:04:33.930797 2026] [security2:error] [pid 955873:tid 956022] [client 141.98.252.162:55638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV4RFTPRVSLOsRVhrojQAAAR0"]
[Thu Sep 17 15:04:33.943265 2026] [security2:error] [pid 955873:tid 956037] [client 104.234.53.11:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxV4RFTPRVSLOsRVhroiwAAASw"]
[Thu Sep 17 15:04:33.999408 2026] [security2:error] [pid 955873:tid 956101] [client 192.178.6.3:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxV4RFTPRVSLOsRVhrokgAAAWw"]
[Thu Sep 17 15:04:34.002584 2026] [security2:error] [pid 955873:tid 956072] [client 17.166.232.51:53846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhrogAABTwU"]
[Thu Sep 17 15:04:34.056746 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:37748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4hFTPRVSLOsRVhrolwAAAXo"]
[Thu Sep 17 15:04:34.057432 2026] [security2:error] [pid 955873:tid 956116] [client 104.234.19.146:35105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxV4hFTPRVSLOsRVhromAAAAXs"]
[Thu Sep 17 15:04:34.095295 2026] [security2:error] [pid 955873:tid 956123] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/symfony/.env"] [unique_id "aqxV4hFTPRVSLOsRVhronwAAAYI"]
[Thu Sep 17 15:04:34.156516 2026] [security2:error] [pid 955873:tid 956110] [client 52.231.79.181:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/new.php"] [unique_id "aqxV4hFTPRVSLOsRVhroogAAAXU"]
[Thu Sep 17 15:04:34.185447 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:58306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-filters.php"] [unique_id "aqxV4hFTPRVSLOsRVhropAAAAYc"]
[Thu Sep 17 15:04:34.185587 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:58306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-default-filters.php"] [unique_id "aqxV4hFTPRVSLOsRVhropAAAAYc"]
[Thu Sep 17 15:04:34.200927 2026] [security2:error] [pid 955873:tid 956120] [client 107.10.44.149:34735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhronAABfwo"]
[Thu Sep 17 15:04:34.265149 2026] [security2:error] [pid 955873:tid 956023] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/wordpress/.env"] [unique_id "aqxV4hFTPRVSLOsRVhroqQAAAR4"]
[Thu Sep 17 15:04:34.327737 2026] [security2:error] [pid 955873:tid 956018] [client 193.36.224.156:29277] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/file.php"] [unique_id "aqxV4hFTPRVSLOsRVhroqgAAARk"]
[Thu Sep 17 15:04:34.352981 2026] [security2:error] [pid 955873:tid 956113] [client 129.121.122.126:50796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhroowAAAXg"]
[Thu Sep 17 15:04:34.436883 2026] [security2:error] [pid 955873:tid 956005] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/wp/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrorwAAAQw"]
[Thu Sep 17 15:04:34.466171 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.224.217:37762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4hFTPRVSLOsRVhrosgAAAQo"]
[Thu Sep 17 15:04:34.474799 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:58314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-files.php"] [unique_id "aqxV4hFTPRVSLOsRVhroswAAARY"]
[Thu Sep 17 15:04:34.474958 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:58314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-files.php"] [unique_id "aqxV4hFTPRVSLOsRVhroswAAARY"]
[Thu Sep 17 15:04:34.516910 2026] [security2:error] [pid 955873:tid 956033] [client 129.121.122.126:50796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.122.121.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxV4hFTPRVSLOsRVhrorAAAASg"]
[Thu Sep 17 15:04:34.554712 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.134.22:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/server-status.php"] [unique_id "aqxV4hFTPRVSLOsRVhrotwAAAR8"]
[Thu Sep 17 15:04:34.569937 2026] [security2:error] [pid 955873:tid 956030] [client 52.231.79.181:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/num.php"] [unique_id "aqxV4hFTPRVSLOsRVhrouAAAASU"]
[Thu Sep 17 15:04:34.600047 2026] [security2:error] [pid 955873:tid 956065] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cms/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrouQAAAUg"]
[Thu Sep 17 15:04:34.652928 2026] [security2:error] [pid 955873:tid 956129] [client 198.46.193.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "commonearthjc.com"] [uri "/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhropwAAAYg"]
[Thu Sep 17 15:04:34.669634 2026] [security2:error] [pid 955873:tid 956031] [client 141.98.252.162:56422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/vendor/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrovAAAASY"]
[Thu Sep 17 15:04:34.680208 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/.env.swp"] [unique_id "aqxV4hFTPRVSLOsRVhrovQAAARo"]
[Thu Sep 17 15:04:34.763035 2026] [security2:error] [pid 955873:tid 956069] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/drupal/.env"] [unique_id "aqxV4hFTPRVSLOsRVhrovwAAAUw"]
[Thu Sep 17 15:04:34.770998 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-functions.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowQAAAUs"]
[Thu Sep 17 15:04:34.771102 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-functions.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowQAAAUs"]
[Thu Sep 17 15:04:34.785154 2026] [security2:error] [pid 955873:tid 956014] [client 216.73.163.70:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowgAAARU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:34.824069 2026] [security2:error] [pid 955873:tid 956034] [client 5.189.145.112:52901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-login.php"] [unique_id "aqxV4hFTPRVSLOsRVhrowAAAASk"], referer: binance.com
[Thu Sep 17 15:04:34.848711 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/.env~"] [unique_id "aqxV4hFTPRVSLOsRVhroxAAAAUE"]
[Thu Sep 17 15:04:34.875083 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:37776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4hFTPRVSLOsRVhroxQAAATA"]
[Thu Sep 17 15:04:34.926026 2026] [security2:error] [pid 955873:tid 956081] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/joomla/.env"] [unique_id "aqxV4hFTPRVSLOsRVhroxwAAAVg"]
[Thu Sep 17 15:04:34.930342 2026] [security2:error] [pid 955873:tid 956021] [client 178.20.44.82:51085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxV4hFTPRVSLOsRVhrovgAAARw"], referer: https://berenice-vaucher.com/thank-you-for-your-comment/
[Thu Sep 17 15:04:34.977643 2026] [security2:error] [pid 955873:tid 956077] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4RFTPRVSLOsRVhrohgABVAY"], referer: http://jenniferniesslein.com/old/
[Thu Sep 17 15:04:35.064974 2026] [autoindex:error] [pid 955873:tid 956008] [client 52.231.79.181:0] AH01276: Cannot serve directory /home3/gruposi4/public_html/toolmix24/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:04:35.076438 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:58330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-load.php"] [unique_id "aqxV4xFTPRVSLOsRVhro1gAAAWQ"]
[Thu Sep 17 15:04:35.076518 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:58330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-load.php"] [unique_id "aqxV4xFTPRVSLOsRVhro1gAAAWQ"]
[Thu Sep 17 15:04:35.093890 2026] [security2:error] [pid 955873:tid 956095] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/magento/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro2AAAAWY"]
[Thu Sep 17 15:04:35.153630 2026] [security2:error] [pid 955873:tid 956072] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro2QABTw0"], referer: http://jenniferniesslein.com/wordpress/
[Thu Sep 17 15:04:35.239362 2026] [security2:error] [pid 955873:tid 956102] [client 52.231.79.181:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/admin.php"] [unique_id "aqxV4xFTPRVSLOsRVhro3wAAAW0"]
[Thu Sep 17 15:04:35.256727 2026] [security2:error] [pid 955873:tid 956123] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/shopify/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro4QAAAYI"]
[Thu Sep 17 15:04:35.327976 2026] [security2:error] [pid 955873:tid 956115] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro4gABeg4"], referer: http://jenniferniesslein.com/wp/
[Thu Sep 17 15:04:35.418033 2026] [security2:error] [pid 955873:tid 956103] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/prestashop/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro5gAAAW4"]
[Thu Sep 17 15:04:35.486185 2026] [security2:error] [pid 955873:tid 956037] [client 107.10.44.149:54769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro6AABLA8"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260817231440&hideanons=1&hidebots=0&limit=100&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:04:35.506625 2026] [security2:error] [pid 955873:tid 956006] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhro6wABDRA"], referer: http://jenniferniesslein.com/backup/
[Thu Sep 17 15:04:35.514470 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:37790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.cobblehillstudio.net"] [uri "/"] [unique_id "aqxV4xFTPRVSLOsRVhro7QAAARk"]
[Thu Sep 17 15:04:35.550368 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-network.php"] [unique_id "aqxV4xFTPRVSLOsRVhro8AAAATk"]
[Thu Sep 17 15:04:35.550449 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:58338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-network.php"] [unique_id "aqxV4xFTPRVSLOsRVhro8AAAATk"]
[Thu Sep 17 15:04:35.581879 2026] [security2:error] [pid 955873:tid 956017] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/codeigniter/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro8gAAARg"]
[Thu Sep 17 15:04:35.640826 2026] [security2:error] [pid 955873:tid 956004] [client 52.231.79.181:1692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/13.php"] [unique_id "aqxV4xFTPRVSLOsRVhro9wAAAQs"]
[Thu Sep 17 15:04:35.657550 2026] [security2:error] [pid 955873:tid 956060] [client 104.234.19.145:28827] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxV4xFTPRVSLOsRVhro-wAAAUM"]
[Thu Sep 17 15:04:35.719418 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.134.22:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxV4xFTPRVSLOsRVhro_AAAAUc"]
[Thu Sep 17 15:04:35.743140 2026] [security2:error] [pid 955873:tid 956065] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cakephp/.env"] [unique_id "aqxV4xFTPRVSLOsRVhro_gAAAUg"]
[Thu Sep 17 15:04:35.813324 2026] [security2:error] [pid 955873:tid 956046] [client 141.98.252.162:54307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/vendor/.env"] [unique_id "aqxV4xFTPRVSLOsRVhrpAAAAATU"]
[Thu Sep 17 15:04:35.833011 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env"] [unique_id "aqxV4xFTPRVSLOsRVhrpAwAAAUU"]
[Thu Sep 17 15:04:35.833060 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:58354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-settings.php"] [unique_id "aqxV4xFTPRVSLOsRVhrpBAAAAU0"]
[Thu Sep 17 15:04:35.833134 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:58354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-settings.php"] [unique_id "aqxV4xFTPRVSLOsRVhrpBAAAAU0"]
[Thu Sep 17 15:04:35.850330 2026] [security2:error] [pid 955873:tid 956027] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/js/email-subscribers-public.js"] [unique_id "aqxV4xFTPRVSLOsRVhrpBwAAASI"]
[Thu Sep 17 15:04:35.870986 2026] [security2:error] [pid 955873:tid 956019] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV4xFTPRVSLOsRVhrpAQABGhM"], referer: http://jenniferniesslein.com/new/
[Thu Sep 17 15:04:35.904473 2026] [security2:error] [pid 955873:tid 956068] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/zend/.env"] [unique_id "aqxV4xFTPRVSLOsRVhrpCAAAAUs"]
[Thu Sep 17 15:04:36.037326 2026] [security2:error] [pid 955873:tid 956124] [client 193.36.224.151:53785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-mail.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpDgAAAYM"]
[Thu Sep 17 15:04:36.058592 2026] [security2:error] [pid 955873:tid 956011] [client 192.241.166.94:33492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpCwABEhQ"], referer: http://jenniferniesslein.com/blog/
[Thu Sep 17 15:04:36.071263 2026] [security2:error] [pid 955873:tid 956079] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/yii/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpEwAAAVY"]
[Thu Sep 17 15:04:36.075631 2026] [security2:error] [pid 955873:tid 956045] [client 52.231.79.181:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/222.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFQAAATQ"]
[Thu Sep 17 15:04:36.110110 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-site.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFgAAAVs"]
[Thu Sep 17 15:04:36.110174 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:58370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ms-site.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFgAAAVs"]
[Thu Sep 17 15:04:36.159994 2026] [security2:error] [pid 955873:tid 956033] [client 45.131.194.119:28015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpFwAAASg"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:36.233679 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/laravel5/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpGgAAAQ8"]
[Thu Sep 17 15:04:36.348992 2026] [security2:error] [pid 955873:tid 956022] [client 104.234.19.148:32731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/ioxi-o.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpIQAAAR0"]
[Thu Sep 17 15:04:36.393100 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/nav-menu-template.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpIgAAAV4"]
[Thu Sep 17 15:04:36.393172 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:58376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/nav-menu-template.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpIgAAAV4"]
[Thu Sep 17 15:04:36.395070 2026] [security2:error] [pid 955873:tid 956104] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/v1/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpIwAAAW8"]
[Thu Sep 17 15:04:36.415847 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.134.22:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpJAAAATg"]
[Thu Sep 17 15:04:36.458085 2026] [security2:error] [pid 955873:tid 956097] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/app/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpJQAAAWg"]
[Thu Sep 17 15:04:36.462419 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpJwAAAU4"]
[Thu Sep 17 15:04:36.462514 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:61569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpJwAAAU4"]
[Thu Sep 17 15:04:36.477957 2026] [security2:error] [pid 955873:tid 956106] [client 52.231.79.181:1723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/aa.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpKAAAAXE"]
[Thu Sep 17 15:04:36.556832 2026] [security2:error] [pid 955873:tid 956078] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/v2/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpKwAAAVU"]
[Thu Sep 17 15:04:36.571827 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.bak"] [unique_id "aqxV5BFTPRVSLOsRVhrpLAAAAYI"]
[Thu Sep 17 15:04:36.616104 2026] [security2:error] [pid 955873:tid 956108] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/apps/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpLgAAAXM"]
[Thu Sep 17 15:04:36.636750 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.backup"] [unique_id "aqxV5BFTPRVSLOsRVhrpLwAAAUI"]
[Thu Sep 17 15:04:36.646031 2026] [security2:error] [pid 955873:tid 956039] [client 104.234.19.144:47643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpMAAAAS4"]
[Thu Sep 17 15:04:36.686440 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/option.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpMQAAAYU"]
[Thu Sep 17 15:04:36.686550 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:58390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/option.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpMQAAAYU"]
[Thu Sep 17 15:04:36.718834 2026] [security2:error] [pid 955873:tid 956127] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/v3/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpMgAAAYY"]
[Thu Sep 17 15:04:36.720251 2026] [security2:error] [pid 955873:tid 956128] [client 141.98.252.162:56880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpMwAAAYc"]
[Thu Sep 17 15:04:36.774417 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpNwAAATI"]
[Thu Sep 17 15:04:36.810178 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.old"] [unique_id "aqxV5BFTPRVSLOsRVhrpOQAAASA"]
[Thu Sep 17 15:04:36.880770 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/v1/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpOgAAAVw"]
[Thu Sep 17 15:04:36.883875 2026] [security2:error] [pid 955873:tid 956099] [client 52.231.79.181:1673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/abcd.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpOwAAAWo"]
[Thu Sep 17 15:04:36.886253 2026] [security2:error] [pid 955873:tid 956029] [client 216.24.219.102:31797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/style.php"] [unique_id "aqxV5BFTPRVSLOsRVhrpPAAAASQ"]
[Thu Sep 17 15:04:36.932222 2026] [security2:error] [pid 955873:tid 956130] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/web/.env"] [unique_id "aqxV5BFTPRVSLOsRVhrpPwAAAYk"]
[Thu Sep 17 15:04:36.976443 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:58402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/"] [unique_id "aqxV5BFTPRVSLOsRVhrpQQAAARk"]
[Thu Sep 17 15:04:37.044158 2026] [security2:error] [pid 955873:tid 956051] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/v2/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpTAAAATo"]
[Thu Sep 17 15:04:37.098043 2026] [security2:error] [pid 955873:tid 956129] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/site/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpUAAAAYg"]
[Thu Sep 17 15:04:37.101969 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.134.22:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpUQAAAQ4"]
[Thu Sep 17 15:04:37.156517 2026] [security2:error] [pid 955873:tid 956031] [client 104.234.19.149:26695] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/style.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpVAAAASY"]
[Thu Sep 17 15:04:37.207162 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/rest/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpVQAAAUU"]
[Thu Sep 17 15:04:37.261234 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/public/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpVgAAARo"]
[Thu Sep 17 15:04:37.295751 2026] [security2:error] [pid 955873:tid 956046] [client 52.231.79.181:1683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/about.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWgAAATU"]
[Thu Sep 17 15:04:37.342313 2026] [security2:error] [pid 955873:tid 956016] [client 154.190.208.131:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWAAAARc"]
[Thu Sep 17 15:04:37.342454 2026] [security2:error] [pid 955873:tid 956016] [client 154.190.208.131:41558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWAAAARc"]
[Thu Sep 17 15:04:37.346390 2026] [security2:error] [pid 955873:tid 956096] [client 47.79.218.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpSgAAAWc"], referer: https://www.google.com/
[Thu Sep 17 15:04:37.352287 2026] [security2:error] [pid 955873:tid 956073] [client 45.146.54.110:65131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpWQAAAVA"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:37.375123 2026] [security2:error] [pid 955873:tid 956048] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/graphql/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpXAAAATc"]
[Thu Sep 17 15:04:37.507018 2026] [security2:error] [pid 955873:tid 956045] [client 193.36.224.113:49547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/themes/style.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpYgAAATQ"]
[Thu Sep 17 15:04:37.543842 2026] [security2:error] [pid 955873:tid 956121] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/gateway/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpZgAAAYA"]
[Thu Sep 17 15:04:37.565177 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/"] [unique_id "aqxV5RFTPRVSLOsRVhrpZQAAAU0"]
[Thu Sep 17 15:04:37.617553 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/backend/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpaQAAAVc"]
[Thu Sep 17 15:04:37.709428 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:58402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/wp-includes/"] [unique_id "aqxV5RFTPRVSLOsRVhrpawAAARE"]
[Thu Sep 17 15:04:37.713129 2026] [security2:error] [pid 955873:tid 956033] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/microservice/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpbAAAASg"]
[Thu Sep 17 15:04:37.729294 2026] [security2:error] [pid 955873:tid 956091] [client 193.36.224.222:57855] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-editor.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpbQAAAWI"]
[Thu Sep 17 15:04:37.750587 2026] [security2:error] [pid 955873:tid 956081] [client 52.231.79.181:1710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/admin.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpbgAAAVg"]
[Thu Sep 17 15:04:37.777004 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/server/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpbwAAAWA"]
[Thu Sep 17 15:04:37.814419 2026] [security2:error] [pid 955873:tid 956109] [client 34.166.134.22:35596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpcQAAAXQ"]
[Thu Sep 17 15:04:37.847641 2026] [security2:error] [pid 955873:tid 956079] [client 141.98.252.162:58057] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpdAAAAVY"]
[Thu Sep 17 15:04:37.881098 2026] [security2:error] [pid 955873:tid 956098] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/service/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpdgAAAWk"]
[Thu Sep 17 15:04:37.899146 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env.swp"] [unique_id "aqxV5RFTPRVSLOsRVhrpeAAAAR0"]
[Thu Sep 17 15:04:37.913794 2026] [security2:error] [pid 955873:tid 956035] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/style.css"] [unique_id "aqxV5RFTPRVSLOsRVhrpeQAAASo"]
[Thu Sep 17 15:04:37.938355 2026] [security2:error] [pid 955873:tid 956104] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/frontend/.env"] [unique_id "aqxV5RFTPRVSLOsRVhrpegAAAW8"]
[Thu Sep 17 15:04:37.983573 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.env~"] [unique_id "aqxV5RFTPRVSLOsRVhrpfAAAAW0"]
[Thu Sep 17 15:04:38.023774 2026] [security2:error] [pid 955873:tid 956092] [client 193.36.224.170:28531] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/lufix.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpfwAAAWM"]
[Thu Sep 17 15:04:38.047353 2026] [security2:error] [pid 955873:tid 956108] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/v3/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpgQAAAXM"]
[Thu Sep 17 15:04:38.074090 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpdQAAAWw"]
[Thu Sep 17 15:04:38.074118 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5RFTPRVSLOsRVhrpdQAAAWw"]
[Thu Sep 17 15:04:38.098010 2026] [security2:error] [pid 955873:tid 956039] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/src/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrphAAAAS4"]
[Thu Sep 17 15:04:38.178337 2026] [security2:error] [pid 955873:tid 956078] [client 52.231.79.181:1716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/adminfuns.php"] [unique_id "aqxV5hFTPRVSLOsRVhrphgAAAVU"]
[Thu Sep 17 15:04:38.183406 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:65308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrphwAAAYI"]
[Thu Sep 17 15:04:38.183507 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:65308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrphwAAAYI"]
[Thu Sep 17 15:04:38.211203 2026] [security2:error] [pid 955873:tid 956088] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/dev/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpiAAAAV8"]
[Thu Sep 17 15:04:38.245099 2026] [security2:error] [pid 955873:tid 956103] [client 104.234.19.143:35355] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/txets.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpiwAAAW4"]
[Thu Sep 17 15:04:38.261019 2026] [security2:error] [pid 955873:tid 956119] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/core/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpjAAAAX4"]
[Thu Sep 17 15:04:38.350037 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/autoload.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpjgAAARk"]
[Thu Sep 17 15:04:38.350165 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:58402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/autoload.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpjgAAARk"]
[Thu Sep 17 15:04:38.374911 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/api/staging/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpjwAAAUM"]
[Thu Sep 17 15:04:38.416081 2026] [security2:error] [pid 955873:tid 956051] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/core/app/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpkgAAATo"]
[Thu Sep 17 15:04:38.507325 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.134.22:35606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxV5hFTPRVSLOsRVhrplAAAATI"]
[Thu Sep 17 15:04:38.519843 2026] [security2:error] [pid 955873:tid 956013] [client 193.36.224.150:57061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxV5hFTPRVSLOsRVhrplQAAARQ"]
[Thu Sep 17 15:04:38.544321 2026] [security2:error] [pid 955873:tid 956012] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/vendor/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrplgAAARM"]
[Thu Sep 17 15:04:38.575511 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/config/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpmwAAATE"]
[Thu Sep 17 15:04:38.577686 2026] [security2:error] [pid 955873:tid 956064] [client 52.231.79.181:1672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpnAAAAUc"]
[Thu Sep 17 15:04:38.628986 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/"] [unique_id "aqxV5hFTPRVSLOsRVhrpngAAAQs"]
[Thu Sep 17 15:04:38.631866 2026] [security2:error] [pid 955873:tid 956037] [client 115.244.164.14:57979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpnwAAASw"]
[Thu Sep 17 15:04:38.631939 2026] [security2:error] [pid 955873:tid 956037] [client 115.244.164.14:57979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrpnwAAASw"]
[Thu Sep 17 15:04:38.665046 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/app/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpoAAAAR4"]
[Thu Sep 17 15:04:38.711711 2026] [security2:error] [pid 955873:tid 956020] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/lib/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpogAAARs"]
[Thu Sep 17 15:04:38.747894 2026] [security2:error] [pid 955873:tid 956066] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/private/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrppAAAAUk"]
[Thu Sep 17 15:04:38.762571 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/apps/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrppQAAAVM"]
[Thu Sep 17 15:04:38.775748 2026] [security2:error] [pid 955873:tid 956017] [client 193.36.224.168:24453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-admin/txets.php"] [unique_id "aqxV5hFTPRVSLOsRVhrppwAAARg"]
[Thu Sep 17 15:04:38.833325 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/"] [unique_id "aqxV5hFTPRVSLOsRVhrppgAAATc"]
[Thu Sep 17 15:04:38.881930 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/resources/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpqQAAAYM"]
[Thu Sep 17 15:04:38.908077 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/application/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpqwAAAVk"]
[Thu Sep 17 15:04:38.915376 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrprAAAATQ"]
[Thu Sep 17 15:04:38.929062 2026] [security2:error] [pid 955873:tid 956046] [client 104.28.198.244:22970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrprgAAATU"]
[Thu Sep 17 15:04:38.981026 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:58408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/wp-includes/php-ai-client/"] [unique_id "aqxV5hFTPRVSLOsRVhrpsAAAASg"]
[Thu Sep 17 15:04:39.002615 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/web/.env"] [unique_id "aqxV5hFTPRVSLOsRVhrpsQAAAWI"]
[Thu Sep 17 15:04:39.024170 2026] [security2:error] [pid 955873:tid 956118] [client 52.231.79.181:1714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/ae.php"] [unique_id "aqxV5xFTPRVSLOsRVhrptQAAAX0"]
[Thu Sep 17 15:04:39.056225 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/assets/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrptgAAAQ8"]
[Thu Sep 17 15:04:39.065966 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/bootstrap/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrptwAAAXQ"]
[Thu Sep 17 15:04:39.074811 2026] [security2:error] [pid 955873:tid 956058] [client 193.36.224.156:36251] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/wp-includes/txets.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpuQAAAUE"]
[Thu Sep 17 15:04:39.098970 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/site/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpugAAATA"]
[Thu Sep 17 15:04:39.119553 2026] [security2:error] [pid 955873:tid 956046] [client 104.28.198.244:22970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV5hFTPRVSLOsRVhrprgAAATU"]
[Thu Sep 17 15:04:39.189864 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.134.22:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpvQAAAVQ"]
[Thu Sep 17 15:04:39.221280 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/public/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpvwAAAU8"]
[Thu Sep 17 15:04:39.221281 2026] [security2:error] [pid 955873:tid 956090] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/uploads/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpvgAAAWE"]
[Thu Sep 17 15:04:39.225762 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/database/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpwAAAASo"]
[Thu Sep 17 15:04:39.345002 2026] [security2:error] [pid 955873:tid 956108] [client 193.36.224.220:62413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/goods.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpwwAAAXM"]
[Thu Sep 17 15:04:39.362259 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpvAAAAWU"]
[Thu Sep 17 15:04:39.362288 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpvAAAAWU"]
[Thu Sep 17 15:04:39.388850 2026] [security2:error] [pid 955873:tid 956110] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/internal/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpxQAAAXU"]
[Thu Sep 17 15:04:39.396373 2026] [security2:error] [pid 955873:tid 956101] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/storage/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpxgAAAWw"]
[Thu Sep 17 15:04:39.407763 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/backend/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpyQAAAYU"]
[Thu Sep 17 15:04:39.439338 2026] [security2:error] [pid 955873:tid 956092] [client 52.231.79.181:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/akcc.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpywAAAWM"]
[Thu Sep 17 15:04:39.454780 2026] [security2:error] [pid 955873:tid 956088] [client 134.185.85.61:63417] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "flatpad.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxV5xFTPRVSLOsRVhrpzQAAAV8"]
[Thu Sep 17 15:04:39.501636 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/server/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrpzgAAAT8"]
[Thu Sep 17 15:04:39.502778 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/AiClient.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpzwAAAX4"]
[Thu Sep 17 15:04:39.502862 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:58408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/AiClient.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpzwAAAX4"]
[Thu Sep 17 15:04:39.513873 2026] [security2:error] [pid 955873:tid 956127] [client 200.82.236.45:55529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV5xFTPRVSLOsRVhrpygABhiM"]
[Thu Sep 17 15:04:39.550635 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/tools/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp0gAAAVw"]
[Thu Sep 17 15:04:39.555460 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/var/www/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp0wAAAXk"]
[Thu Sep 17 15:04:39.579962 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/frontend/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp1QAAARk"]
[Thu Sep 17 15:04:39.628465 2026] [security2:error] [pid 955873:tid 956060] [client 104.234.19.144:30979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "lmi.vkc.mybluehost.me"] [uri "/php8.php"] [unique_id "aqxV5xFTPRVSLOsRVhrp1gAAAUM"]
[Thu Sep 17 15:04:39.666167 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/src/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp1wAAAUg"]
[Thu Sep 17 15:04:39.712375 2026] [security2:error] [pid 955873:tid 956052] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/scripts/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp2QAAATs"]
[Thu Sep 17 15:04:39.724387 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/var/www/html/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp2gAAAXg"]
[Thu Sep 17 15:04:39.728858 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/core/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp2wAAARM"]
[Thu Sep 17 15:04:39.785127 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:58422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/"] [unique_id "aqxV5xFTPRVSLOsRVhrp3QAAATE"]
[Thu Sep 17 15:04:39.788550 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/core/app/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp3gAAAUc"]
[Thu Sep 17 15:04:39.798282 2026] [security2:error] [pid 955873:tid 956095] [client 45.146.54.109:44759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV5xFTPRVSLOsRVhrp3AAAAWY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:39.843538 2026] [security2:error] [pid 955873:tid 956004] [client 134.185.85.61:56053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "flatpad.com"] [uri "/media/system/js/core.js"] [unique_id "aqxV5xFTPRVSLOsRVhrp3wAAAQs"]
[Thu Sep 17 15:04:39.859826 2026] [security2:error] [pid 955873:tid 956043] [client 52.231.79.181:1989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/bak.php"] [unique_id "aqxV5xFTPRVSLOsRVhrp4AAAATI"]
[Thu Sep 17 15:04:39.873782 2026] [security2:error] [pid 955873:tid 956037] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/bin/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp4QAAASw"]
[Thu Sep 17 15:04:39.885304 2026] [security2:error] [pid 955873:tid 956036] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/current/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp4gAAASs"]
[Thu Sep 17 15:04:39.887946 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.134.22:35624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxV5xFTPRVSLOsRVhrp4wAAAXw"]
[Thu Sep 17 15:04:39.914503 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/config/.env"] [unique_id "aqxV5xFTPRVSLOsRVhrp5AAAARo"]
[Thu Sep 17 15:04:39.937074 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/"] [unique_id "aqxV5xFTPRVSLOsRVhrp5QAAAR4"]
[Thu Sep 17 15:04:40.011337 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/private/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp6AAAAVA"]
[Thu Sep 17 15:04:40.033310 2026] [security2:error] [pid 955873:tid 956005] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/demo1.min.js"] [unique_id "aqxV6BFTPRVSLOsRVhrp6gAAAQw"]
[Thu Sep 17 15:04:40.038147 2026] [security2:error] [pid 955873:tid 956063] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sbin/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp6wAAAUY"]
[Thu Sep 17 15:04:40.044924 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/release/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp7AAAARg"]
[Thu Sep 17 15:04:40.082464 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:58422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/wp-includes/php-ai-client/src/"] [unique_id "aqxV6BFTPRVSLOsRVhrp7QAAAUQ"]
[Thu Sep 17 15:04:40.084057 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/application/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp7gAAAT4"]
[Thu Sep 17 15:04:40.201601 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/local/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp7wAAASk"]
[Thu Sep 17 15:04:40.212335 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/releases/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp8AAAAVk"]
[Thu Sep 17 15:04:40.232452 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/bootstrap/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp8gAAAYA"]
[Thu Sep 17 15:04:40.299371 2026] [security2:error] [pid 955873:tid 956124] [client 52.231.79.181:2028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/cc.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp9AAAAYM"]
[Thu Sep 17 15:04:40.315391 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/database/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp9QAAAVs"]
[Thu Sep 17 15:04:40.370540 2026] [security2:error] [pid 955873:tid 956010] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/portal/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp9wAAARE"]
[Thu Sep 17 15:04:40.371353 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/shared/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp-AAAAWI"]
[Thu Sep 17 15:04:40.401998 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/storage/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrp_AAAAX0"]
[Thu Sep 17 15:04:40.415378 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp8QAAARA"]
[Thu Sep 17 15:04:40.415396 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp8QAAARA"]
[Thu Sep 17 15:04:40.447462 2026] [security2:error] [pid 955873:tid 956129] [client 216.73.163.43:47053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV6BFTPRVSLOsRVhrp_QAAAYg"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:40.511276 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/var/www/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqAAAAAVY"]
[Thu Sep 17 15:04:40.533288 2026] [security2:error] [pid 955873:tid 956105] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/deploy/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqAQAAAXA"]
[Thu Sep 17 15:04:40.533331 2026] [security2:error] [pid 955873:tid 956041] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/dashboard/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqAgAAATA"]
[Thu Sep 17 15:04:40.558238 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/MessageBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqBQAAAVQ"]
[Thu Sep 17 15:04:40.558348 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:58422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/MessageBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqBQAAAVQ"]
[Thu Sep 17 15:04:40.594047 2026] [security2:error] [pid 955873:tid 956054] [client 34.166.134.22:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php.old"] [unique_id "aqxV6BFTPRVSLOsRVhrqBwAAAT0"]
[Thu Sep 17 15:04:40.600223 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/var/www/html/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqCAAAAVo"]
[Thu Sep 17 15:04:40.687506 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/current/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqDAAAAXo"]
[Thu Sep 17 15:04:40.692552 2026] [security2:error] [pid 955873:tid 956038] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/build/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqDQAAAS0"]
[Thu Sep 17 15:04:40.695031 2026] [security2:error] [pid 955873:tid 956122] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/panel/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqDgAAAYE"]
[Thu Sep 17 15:04:40.706362 2026] [security2:error] [pid 955873:tid 956090] [client 52.231.79.181:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/chosen.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqEAAAAWE"]
[Thu Sep 17 15:04:40.761349 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/release/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqEwAAAUA"]
[Thu Sep 17 15:04:40.836295 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/PromptBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqFQAAAWM"]
[Thu Sep 17 15:04:40.836378 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:36664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Builders/PromptBuilder.php"] [unique_id "aqxV6BFTPRVSLOsRVhrqFQAAAWM"]
[Thu Sep 17 15:04:40.849625 2026] [security2:error] [pid 955873:tid 956088] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/dist/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqFgAAAV8"]
[Thu Sep 17 15:04:40.856884 2026] [security2:error] [pid 955873:tid 956120] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/crm/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqFwAAAX8"]
[Thu Sep 17 15:04:40.899986 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/releases/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqGQAAAXY"]
[Thu Sep 17 15:04:40.981459 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/shared/.env"] [unique_id "aqxV6BFTPRVSLOsRVhrqGgAAAT8"]
[Thu Sep 17 15:04:41.004196 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/public_html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqGwAAAU4"]
[Thu Sep 17 15:04:41.017536 2026] [security2:error] [pid 955873:tid 956029] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/erp/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqHgAAASQ"]
[Thu Sep 17 15:04:41.085766 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/deploy/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqIAAAATg"]
[Thu Sep 17 15:04:41.113405 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:36676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV6RFTPRVSLOsRVhrqIQAAATk"]
[Thu Sep 17 15:04:41.136598 2026] [security2:error] [pid 955873:tid 956127] [client 52.231.79.181:2038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/classwithtostring.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqIgAAAYY"]
[Thu Sep 17 15:04:41.162826 2026] [security2:error] [pid 955873:tid 956053] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/htdocs/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqIwAAATw"]
[Thu Sep 17 15:04:41.168044 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/build/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqJAAAARY"]
[Thu Sep 17 15:04:41.178805 2026] [security2:error] [pid 955873:tid 956051] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/shop/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqJQAAATo"]
[Thu Sep 17 15:04:41.264699 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/dist/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqJwAAAXE"]
[Thu Sep 17 15:04:41.295596 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV6RFTPRVSLOsRVhrqJgAAAWo"]
[Thu Sep 17 15:04:41.295612 2026] [security2:error] [pid 955873:tid 956130] [client 34.166.134.22:32980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php~"] [unique_id "aqxV6RFTPRVSLOsRVhrqKgAAAYk"]
[Thu Sep 17 15:04:41.320634 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/www/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqLAAAASY"]
[Thu Sep 17 15:04:41.341419 2026] [security2:error] [pid 955873:tid 956064] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/store/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqLgAAAUc"]
[Thu Sep 17 15:04:41.436440 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/wp-includes/php-ai-client/src/"] [unique_id "aqxV6RFTPRVSLOsRVhrqMAAAAXw"]
[Thu Sep 17 15:04:41.481008 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqMQAAARo"]
[Thu Sep 17 15:04:41.486611 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/public_html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqMgAAAR4"]
[Thu Sep 17 15:04:41.502894 2026] [security2:error] [pid 955873:tid 956068] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/saas/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqNAAAAUs"]
[Thu Sep 17 15:04:41.540954 2026] [security2:error] [pid 955873:tid 956036] [client 52.231.79.181:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/wp-signup.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqNwAAASs"]
[Thu Sep 17 15:04:41.542233 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/htdocs/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqOAAAASs"]
[Thu Sep 17 15:04:41.579325 2026] [security2:error] [pid 955873:tid 956003] [client 45.146.54.112:47423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqNgAAAQo"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:41.623576 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/www/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqOwAAASE"]
[Thu Sep 17 15:04:41.636297 2026] [security2:error] [pid 955873:tid 956017] [client 141.98.252.162:61824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqPAAAARg"]
[Thu Sep 17 15:04:41.639105 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/live/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqPQAAAQ4"]
[Thu Sep 17 15:04:41.665057 2026] [security2:error] [pid 955873:tid 956011] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/client/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqQQAAARI"]
[Thu Sep 17 15:04:41.755170 2026] [security2:error] [pid 955873:tid 956061] [client 45.230.33.226:58507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqPgABRCs"]
[Thu Sep 17 15:04:41.755200 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqOgAAAQw"]
[Thu Sep 17 15:04:41.755217 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqOgAAAQw"]
[Thu Sep 17 15:04:41.778525 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/html/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqQwAAAYA"]
[Thu Sep 17 15:04:41.797274 2026] [security2:error] [pid 955873:tid 956096] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/prod/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqRQAAAWc"]
[Thu Sep 17 15:04:41.826604 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/project/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqRgAAAYM"]
[Thu Sep 17 15:04:41.856937 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/live/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqRwAAAVs"]
[Thu Sep 17 15:04:41.892847 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractDataTransferObject.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqSAAAAVc"]
[Thu Sep 17 15:04:41.892964 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:36676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractDataTransferObject.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqSAAAAVc"]
[Thu Sep 17 15:04:41.927952 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/prod/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqSQAAAVI"]
[Thu Sep 17 15:04:41.955820 2026] [security2:error] [pid 955873:tid 956010] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/dev/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqSgAAARE"]
[Thu Sep 17 15:04:41.957491 2026] [security2:error] [pid 955873:tid 956016] [client 52.231.79.181:2042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/doc.php"] [unique_id "aqxV6RFTPRVSLOsRVhrqSwAAARc"]
[Thu Sep 17 15:04:41.984736 2026] [security2:error] [pid 955873:tid 956062] [client 34.166.134.22:32990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/info.php.bak"] [unique_id "aqxV6RFTPRVSLOsRVhrqTAAAAUU"]
[Thu Sep 17 15:04:41.988298 2026] [security2:error] [pid 955873:tid 956091] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/admin-panel/.env"] [unique_id "aqxV6RFTPRVSLOsRVhrqTQAAAWI"]
[Thu Sep 17 15:04:42.011981 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/dev/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqUAAAARA"]
[Thu Sep 17 15:04:42.094813 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/staging/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVAAAAS8"]
[Thu Sep 17 15:04:42.095320 2026] [security2:error] [pid 955873:tid 956079] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/trigger.min.js"] [unique_id "aqxV6hFTPRVSLOsRVhrqUwAAAVY"]
[Thu Sep 17 15:04:42.111308 2026] [security2:error] [pid 955873:tid 956105] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/staging/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVQAAAXA"]
[Thu Sep 17 15:04:42.154398 2026] [security2:error] [pid 955873:tid 956041] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/control-panel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVgAAATA"]
[Thu Sep 17 15:04:42.180491 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/opt/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqVwAAAXs"]
[Thu Sep 17 15:04:42.185500 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractEnum.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqWAAAAVQ"]
[Thu Sep 17 15:04:42.185586 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:36692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/AbstractEnum.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqWAAAAVQ"]
[Thu Sep 17 15:04:42.265200 2026] [security2:error] [pid 955873:tid 956083] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/opt/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqWQAAAVo"]
[Thu Sep 17 15:04:42.273871 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/laravel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqWgAAATM"]
[Thu Sep 17 15:04:42.318355 2026] [security2:error] [pid 955873:tid 956102] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/user-panel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqWwAAAW0"]
[Thu Sep 17 15:04:42.376854 2026] [security2:error] [pid 955873:tid 956054] [client 52.231.79.181:1667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/edit.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqXAAAAT0"]
[Thu Sep 17 15:04:42.385312 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/symfony/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqXQAAAS0"]
[Thu Sep 17 15:04:42.424455 2026] [security2:error] [pid 955873:tid 956059] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/laravel/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqXgAAAUI"]
[Thu Sep 17 15:04:42.472980 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:36698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/"] [unique_id "aqxV6hFTPRVSLOsRVhrqXwAAAW8"]
[Thu Sep 17 15:04:42.479820 2026] [security2:error] [pid 955873:tid 956098] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/node/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqYAAAAWk"]
[Thu Sep 17 15:04:42.534828 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/wordpress/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqYwAAAUA"]
[Thu Sep 17 15:04:42.583420 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/symfony/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqZQAAAVE"]
[Thu Sep 17 15:04:42.628637 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/"] [unique_id "aqxV6hFTPRVSLOsRVhrqZwAAATU"]
[Thu Sep 17 15:04:42.642964 2026] [security2:error] [pid 955873:tid 956078] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/express/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqaAAAAVU"]
[Thu Sep 17 15:04:42.661925 2026] [security2:error] [pid 955873:tid 956090] [client 185.55.149.49:50872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqaQAAAWE"]
[Thu Sep 17 15:04:42.662291 2026] [security2:error] [pid 955873:tid 956090] [client 185.55.149.49:50872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqaQAAAWE"]
[Thu Sep 17 15:04:42.666074 2026] [security2:error] [pid 955873:tid 956108] [client 34.166.134.22:32994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/phpinfo.php.save"] [unique_id "aqxV6hFTPRVSLOsRVhrqagAAAXM"]
[Thu Sep 17 15:04:42.671591 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/wp/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqawAAAYI"]
[Thu Sep 17 15:04:42.696373 2026] [security2:error] [pid 955873:tid 956122] [client 141.98.252.162:57361] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.226.11"] [uri "/162.241.226.11/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqbgAAAYE"]
[Thu Sep 17 15:04:42.738349 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/wordpress/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqcAAAAXI"]
[Thu Sep 17 15:04:42.769784 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cms/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqdAAAAXc"]
[Thu Sep 17 15:04:42.771487 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:36698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV6hFTPRVSLOsRVhrqdQAAAV4"]
[Thu Sep 17 15:04:42.776100 2026] [security2:error] [pid 955873:tid 956126] [client 52.231.79.181:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/worksec.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqdgAAAYU"]
[Thu Sep 17 15:04:42.805954 2026] [security2:error] [pid 955873:tid 956029] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/next/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqdwAAASQ"]
[Thu Sep 17 15:04:42.869360 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/drupal/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqeAAAAUM"]
[Thu Sep 17 15:04:42.886819 2026] [security2:error] [pid 955873:tid 956081] [client 204.14.250.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqcQAAAVg"], referer: https://facebook.com/
[Thu Sep 17 15:04:42.898848 2026] [security2:error] [pid 955873:tid 956065] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/wp/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqegAAAUg"]
[Thu Sep 17 15:04:42.968511 2026] [security2:error] [pid 955873:tid 956099] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/nuxt/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqfQAAAWo"]
[Thu Sep 17 15:04:42.976573 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/joomla/.env"] [unique_id "aqxV6hFTPRVSLOsRVhrqfgAAARM"]
[Thu Sep 17 15:04:43.059488 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cms/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqgQAAAXg"]
[Thu Sep 17 15:04:43.083592 2026] [security2:error] [pid 955873:tid 956095] [client 34.23.224.217:37794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/magento/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqgwAAAWY"]
[Thu Sep 17 15:04:43.112125 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqfAAAAVw"]
[Thu Sep 17 15:04:43.112148 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqfAAAAVw"]
[Thu Sep 17 15:04:43.134918 2026] [security2:error] [pid 955873:tid 956024] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/nest/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqhQAAAR8"]
[Thu Sep 17 15:04:43.201804 2026] [security2:error] [pid 955873:tid 956027] [client 52.231.79.181:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/ultra.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqhwAAASI"]
[Thu Sep 17 15:04:43.222259 2026] [security2:error] [pid 955873:tid 956117] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/drupal/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqiAAAAXw"]
[Thu Sep 17 15:04:43.263366 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/AiClientExceptionInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqiQAAARo"]
[Thu Sep 17 15:04:43.263468 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:36698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/AiClientExceptionInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqiQAAARo"]
[Thu Sep 17 15:04:43.298327 2026] [security2:error] [pid 955873:tid 956023] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/react/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqigAAAR4"]
[Thu Sep 17 15:04:43.372745 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/shopify/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqjAAAAUs"]
[Thu Sep 17 15:04:43.374189 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.134.22:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqjQAAAQs"]
[Thu Sep 17 15:04:43.384339 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/joomla/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqjgAAAUY"]
[Thu Sep 17 15:04:43.447679 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/prestashop/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqjwAAARI"]
[Thu Sep 17 15:04:43.465268 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/vue/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqkAAAASk"]
[Thu Sep 17 15:04:43.542739 2026] [security2:error] [pid 955873:tid 956067] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/magento/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqkwAAAUo"]
[Thu Sep 17 15:04:43.544507 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/codeigniter/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqlAAAAUQ"]
[Thu Sep 17 15:04:43.559103 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/CachesDataInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqlgAAAYA"]
[Thu Sep 17 15:04:43.559199 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/CachesDataInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqlgAAAYA"]
[Thu Sep 17 15:04:43.616000 2026] [security2:error] [pid 955873:tid 956066] [client 52.231.79.181:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/gecko.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqlwAAAUk"]
[Thu Sep 17 15:04:43.627231 2026] [security2:error] [pid 955873:tid 956096] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/angular/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqmAAAAWc"]
[Thu Sep 17 15:04:43.707437 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/shopify/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqmwAAASg"]
[Thu Sep 17 15:04:43.751993 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cakephp/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqnAAAAYg"]
[Thu Sep 17 15:04:43.791501 2026] [security2:error] [pid 955873:tid 956058] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/svelte/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqnQAAAUE"]
[Thu Sep 17 15:04:43.849623 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithArrayTransformationInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqoAAAAXA"]
[Thu Sep 17 15:04:43.849791 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithArrayTransformationInterface.php"] [unique_id "aqxV6xFTPRVSLOsRVhrqoAAAAXA"]
[Thu Sep 17 15:04:43.850283 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/zend/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqnwAAAVY"]
[Thu Sep 17 15:04:43.873336 2026] [security2:error] [pid 955873:tid 956041] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/prestashop/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqoQAAATA"]
[Thu Sep 17 15:04:43.957300 2026] [security2:error] [pid 955873:tid 956035] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/vite/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqogAAASo"]
[Thu Sep 17 15:04:43.971788 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/yii/.env"] [unique_id "aqxV6xFTPRVSLOsRVhrqowAAAVo"]
[Thu Sep 17 15:04:44.032122 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/codeigniter/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqpAAAASc"]
[Thu Sep 17 15:04:44.034988 2026] [security2:error] [pid 955873:tid 956089] [client 52.231.79.181:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/goods.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqpgAAAWA"]
[Thu Sep 17 15:04:44.040960 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/laravel5/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqqAAAAXo"]
[Thu Sep 17 15:04:44.059470 2026] [security2:error] [pid 955873:tid 956062] [client 141.98.252.162:54306] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "162.241.226.11"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqqQAAAUU"]
[Thu Sep 17 15:04:44.071798 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.134.22:33008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqqgAAAS8"]
[Thu Sep 17 15:04:44.124813 2026] [security2:error] [pid 955873:tid 956054] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/backup/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqqwAAAT0"]
[Thu Sep 17 15:04:44.133690 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithJsonSchemaInterface.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqrAAAAS0"]
[Thu Sep 17 15:04:44.133772 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Contracts/WithJsonSchemaInterface.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqrAAAAS0"]
[Thu Sep 17 15:04:44.157784 2026] [security2:error] [pid 955873:tid 956059] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/responsive-menu.min.js"] [unique_id "aqxV7BFTPRVSLOsRVhrqrQAAAUI"]
[Thu Sep 17 15:04:44.162589 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/v1/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqrgAAAWU"]
[Thu Sep 17 15:04:44.191272 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cakephp/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqrwAAAWk"]
[Thu Sep 17 15:04:44.291173 2026] [security2:error] [pid 955873:tid 956046] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/backups/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqsAAAATU"]
[Thu Sep 17 15:04:44.291877 2026] [security2:error] [pid 955873:tid 956074] [client 85.208.98.202:54165] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/images/spinner.gif"] [unique_id "aqxV7BFTPRVSLOsRVhrqsQAAAVE"]
[Thu Sep 17 15:04:44.300100 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/v2/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqsgAAAVU"]
[Thu Sep 17 15:04:44.355232 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/zend/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqswAAAYI"]
[Thu Sep 17 15:04:44.409495 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/v3/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqtAAAAYE"]
[Thu Sep 17 15:04:44.411322 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:36750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/"] [unique_id "aqxV7BFTPRVSLOsRVhrqtQAAAX8"]
[Thu Sep 17 15:04:44.461406 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/old/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqtwAAAWM"]
[Thu Sep 17 15:04:44.476388 2026] [security2:error] [pid 955873:tid 956108] [client 52.231.79.181:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/man.php"] [unique_id "aqxV7BFTPRVSLOsRVhrquAAAAXM"]
[Thu Sep 17 15:04:44.516038 2026] [security2:error] [pid 955873:tid 956101] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/yii/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrquQAAAWw"]
[Thu Sep 17 15:04:44.555624 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/v1/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqugAAAWQ"]
[Thu Sep 17 15:04:44.575992 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/"] [unique_id "aqxV7BFTPRVSLOsRVhrquwAAAXU"]
[Thu Sep 17 15:04:44.631928 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/tmp/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqvAAAAV0"]
[Thu Sep 17 15:04:44.646806 2026] [security2:error] [pid 955873:tid 956070] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV6hFTPRVSLOsRVhrqUgABTS4"], referer: http://radtechresourcegroup.net./blog/
[Thu Sep 17 15:04:44.676464 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/v2/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqvgAAAX4"]
[Thu Sep 17 15:04:44.683827 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/laravel5/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqvwAAATY"]
[Thu Sep 17 15:04:44.715136 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:36750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV7BFTPRVSLOsRVhrqwQAAATk"]
[Thu Sep 17 15:04:44.741941 2026] [security2:error] [pid 955873:tid 956116] [client 194.163.128.162:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqwwAAAXs"], referer: binance.com
[Thu Sep 17 15:04:44.756174 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/rest/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqxAAAATw"]
[Thu Sep 17 15:04:44.767357 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.134.22:33014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqxQAAAS4"]
[Thu Sep 17 15:04:44.801505 2026] [security2:error] [pid 955873:tid 956081] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/temp/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqxwAAAVg"]
[Thu Sep 17 15:04:44.823228 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/graphql/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqyAAAATo"]
[Thu Sep 17 15:04:44.868685 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/v1/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrqzAAAAYc"]
[Thu Sep 17 15:04:44.885475 2026] [security2:error] [pid 955873:tid 956060] [client 52.231.79.181:1688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/wp-settings.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqzQAAAUM"]
[Thu Sep 17 15:04:44.963705 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/lab/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrq0QAAAXE"]
[Thu Sep 17 15:04:44.963737 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/gateway/.env"] [unique_id "aqxV7BFTPRVSLOsRVhrq0AAAAQ0"]
[Thu Sep 17 15:04:45.030840 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/v2/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq0gAAAWo"]
[Thu Sep 17 15:04:45.090137 2026] [security2:error] [pid 955873:tid 956095] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/microservice/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq1AAAAWY"]
[Thu Sep 17 15:04:45.126516 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqywAAAV8"]
[Thu Sep 17 15:04:45.126534 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7BFTPRVSLOsRVhrqywAAAV8"]
[Thu Sep 17 15:04:45.143024 2026] [security2:error] [pid 955873:tid 956052] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cronlab/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq1wAAATs"]
[Thu Sep 17 15:04:45.169766 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/service/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq2AAAAXw"]
[Thu Sep 17 15:04:45.197320 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/v3/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq2QAAAR4"]
[Thu Sep 17 15:04:45.264440 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:36750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/InvalidArgumentException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq3QAAAUs"]
[Thu Sep 17 15:04:45.264886 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:36750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/InvalidArgumentException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq3QAAAUs"]
[Thu Sep 17 15:04:45.269185 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/v3/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq3gAAAQs"]
[Thu Sep 17 15:04:45.272919 2026] [security2:error] [pid 955873:tid 956043] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq1gABMjU"], referer: http://radtechresourcegroup.net./wordpress/
[Thu Sep 17 15:04:45.285472 2026] [security2:error] [pid 955873:tid 956027] [client 52.231.79.181:2026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/k.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq3wAAASI"]
[Thu Sep 17 15:04:45.305797 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cron/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4AAAAWs"]
[Thu Sep 17 15:04:45.334810 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/dev/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4QAAAQo"]
[Thu Sep 17 15:04:45.352474 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/v1/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4gAAATE"]
[Thu Sep 17 15:04:45.412261 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/api/staging/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq4wAAARs"]
[Thu Sep 17 15:04:45.467848 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/en/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq5AAAASk"]
[Thu Sep 17 15:04:45.473069 2026] [security2:error] [pid 955873:tid 956125] [client 34.166.134.22:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq5QAAAYQ"]
[Thu Sep 17 15:04:45.516826 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/vendor/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq5wAAAUQ"]
[Thu Sep 17 15:04:45.521916 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/v2/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq6AAAAYA"]
[Thu Sep 17 15:04:45.542673 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:36766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/RuntimeException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq6QAAASw"]
[Thu Sep 17 15:04:45.542749 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:36766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/RuntimeException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq6QAAASw"]
[Thu Sep 17 15:04:45.584404 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/lib/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq6gAAAWc"]
[Thu Sep 17 15:04:45.680408 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/rest/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq7QAAAQw"]
[Thu Sep 17 15:04:45.697032 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/administrator/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq6wAAAYM"]
[Thu Sep 17 15:04:45.699351 2026] [security2:error] [pid 955873:tid 956066] [client 52.231.79.181:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/autoload_classmap.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq7wAAAUk"]
[Thu Sep 17 15:04:45.730260 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/resources/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq8QAAAVM"]
[Thu Sep 17 15:04:45.821380 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/TokenLimitReachedException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq9AAAAXA"]
[Thu Sep 17 15:04:45.821470 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:36772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Exception/TokenLimitReachedException.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq9AAAAXA"]
[Thu Sep 17 15:04:45.836933 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/assets/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq9QAAATA"]
[Thu Sep 17 15:04:45.848577 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/graphql/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq9gAAASo"]
[Thu Sep 17 15:04:45.859807 2026] [security2:error] [pid 955873:tid 956048] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/psnlink/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq9wAAATc"]
[Thu Sep 17 15:04:45.884939 2026] [security2:error] [pid 955873:tid 956009] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV7RFTPRVSLOsRVhrq8gABEDg"], referer: http://radtechresourcegroup.net./wp/
[Thu Sep 17 15:04:45.910792 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/uploads/.env"] [unique_id "aqxV7RFTPRVSLOsRVhrq-AAAAX0"]
[Thu Sep 17 15:04:46.012324 2026] [security2:error] [pid 955873:tid 956054] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/gateway/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrq-QAAAT0"]
[Thu Sep 17 15:04:46.024611 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/internal/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrq-gAAAS0"]
[Thu Sep 17 15:04:46.029382 2026] [security2:error] [pid 955873:tid 956059] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/exapi/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrq-wAAAUI"]
[Thu Sep 17 15:04:46.104697 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:36778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/"] [unique_id "aqxV7hFTPRVSLOsRVhrq_QAAAWU"]
[Thu Sep 17 15:04:46.132121 2026] [security2:error] [pid 955873:tid 956062] [client 52.231.79.181:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/profile.php"] [unique_id "aqxV7hFTPRVSLOsRVhrq_wAAAUU"]
[Thu Sep 17 15:04:46.159337 2026] [security2:error] [pid 955873:tid 956032] [client 34.166.134.22:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrAAAAASc"]
[Thu Sep 17 15:04:46.164854 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/tools/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrAgAAAU8"]
[Thu Sep 17 15:04:46.174967 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/microservice/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrBQAAASM"]
[Thu Sep 17 15:04:46.194644 2026] [security2:error] [pid 955873:tid 956045] [client 34.95.193.102:35522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sitemaps/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrBgAAATQ"]
[Thu Sep 17 15:04:46.199081 2026] [security2:error] [pid 955873:tid 956040] [client 216.73.163.37:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrBAAAAS8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:46.218101 2026] [security2:error] [pid 955873:tid 956046] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/css/email-subscribers-public.css"] [unique_id "aqxV7hFTPRVSLOsRVhrrCAAAATU"]
[Thu Sep 17 15:04:46.250997 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/scripts/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrCgAAAVU"]
[Thu Sep 17 15:04:46.256339 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/"] [unique_id "aqxV7hFTPRVSLOsRVhrrCQAAAVE"]
[Thu Sep 17 15:04:46.330310 2026] [security2:error] [pid 955873:tid 956108] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/service/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrDAAAAXM"]
[Thu Sep 17 15:04:46.353267 2026] [security2:error] [pid 955873:tid 956101] [client 85.208.98.202:54165] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/style.css"] [unique_id "aqxV7hFTPRVSLOsRVhrrDQAAAWw"]
[Thu Sep 17 15:04:46.393148 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/bin/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrDwAAAXc"]
[Thu Sep 17 15:04:46.394192 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/wp-includes/php-ai-client/src/Common/"] [unique_id "aqxV7hFTPRVSLOsRVhrrEAAAASU"]
[Thu Sep 17 15:04:46.463592 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sbin/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrEwAAAU0"]
[Thu Sep 17 15:04:46.480152 2026] [security2:error] [pid 955873:tid 956107] [client 216.73.163.52:41181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrEgAAAXI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:46.485607 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:50076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/v3/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrFAAAAU4"]
[Thu Sep 17 15:04:46.530220 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/local/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrFQAAAYU"]
[Thu Sep 17 15:04:46.543848 2026] [security2:error] [pid 955873:tid 956008] [client 52.231.79.181:2045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/server.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrFgAAAQ8"]
[Thu Sep 17 15:04:46.606104 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/portal/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrGAAAATk"]
[Thu Sep 17 15:04:46.756893 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrFwAAASQ"]
[Thu Sep 17 15:04:46.756916 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrFwAAASQ"]
[Thu Sep 17 15:04:46.772995 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/dashboard/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrIwAAAYY"]
[Thu Sep 17 15:04:46.852575 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.134.22:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/www/phpinfo.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrJgAAAXs"]
[Thu Sep 17 15:04:46.865133 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/panel/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrJwAAAXw"]
[Thu Sep 17 15:04:46.927681 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:36778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/WithDataCachingTrait.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrKQAAAQo"]
[Thu Sep 17 15:04:46.927773 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:36778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Common/Traits/WithDataCachingTrait.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrKQAAAQo"]
[Thu Sep 17 15:04:46.950329 2026] [security2:error] [pid 955873:tid 956113] [client 52.231.79.181:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/shell.php"] [unique_id "aqxV7hFTPRVSLOsRVhrrKwAAAXg"]
[Thu Sep 17 15:04:46.962066 2026] [security2:error] [pid 955873:tid 956020] [client 185.191.171.18:50700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tab-funkenwerk.com"] [uri "/robots.txt"] [unique_id "aqxV7hFTPRVSLOsRVhrrLgAAARs"]
[Thu Sep 17 15:04:46.962137 2026] [security2:error] [pid 955873:tid 956020] [client 185.191.171.18:50700] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tab-funkenwerk.com"] [uri "/robots.txt"] [unique_id "aqxV7hFTPRVSLOsRVhrrLgAAARs"]
[Thu Sep 17 15:04:46.965694 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/crm/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrLwAAASE"]
[Thu Sep 17 15:04:46.981919 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/dev/.env"] [unique_id "aqxV7hFTPRVSLOsRVhrrMAAAATg"]
[Thu Sep 17 15:04:47.058270 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/erp/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrNAAAASw"]
[Thu Sep 17 15:04:47.143975 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/api/staging/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrNgAAAWI"]
[Thu Sep 17 15:04:47.178603 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/shop/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrNwAAAUE"]
[Thu Sep 17 15:04:47.213452 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:36786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/"] [unique_id "aqxV7xFTPRVSLOsRVhrrOgAAATA"]
[Thu Sep 17 15:04:47.222502 2026] [security2:error] [pid 955873:tid 956082] [client 85.208.96.196:26808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tab-funkenwerk.com"] [uri "/id91.html"] [unique_id "aqxV7xFTPRVSLOsRVhrrOwAAAVk"]
[Thu Sep 17 15:04:47.222576 2026] [security2:error] [pid 955873:tid 956082] [client 85.208.96.196:26808] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tab-funkenwerk.com"] [uri "/id91.html"] [unique_id "aqxV7xFTPRVSLOsRVhrrOwAAAVk"]
[Thu Sep 17 15:04:47.230140 2026] [security2:error] [pid 955873:tid 956077] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/logs/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrPAAAAVQ"]
[Thu Sep 17 15:04:47.246481 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrPQAAAWs"]
[Thu Sep 17 15:04:47.246839 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:62147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrPQAAAWs"]
[Thu Sep 17 15:04:47.260562 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/store/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrQAAAARw"]
[Thu Sep 17 15:04:47.301234 2026] [security2:error] [pid 955873:tid 956009] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/vendor/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrQwAAARA"]
[Thu Sep 17 15:04:47.357547 2026] [security2:error] [pid 955873:tid 956016] [client 52.231.79.181:2032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/t.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrRgAAARc"]
[Thu Sep 17 15:04:47.374106 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/"] [unique_id "aqxV7xFTPRVSLOsRVhrrRQAAAXo"]
[Thu Sep 17 15:04:47.393183 2026] [security2:error] [pid 955873:tid 956059] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cache/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrSQAAAUI"]
[Thu Sep 17 15:04:47.444214 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/saas/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrSgAAAW8"]
[Thu Sep 17 15:04:47.454235 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/lib/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrSwAAASc"]
[Thu Sep 17 15:04:47.476876 2026] [security2:error] [pid 955873:tid 956038] [client 103.190.46.235:6127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrSAABLUE"]
[Thu Sep 17 15:04:47.520758 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:36786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/wp-includes/php-ai-client/src/"] [unique_id "aqxV7xFTPRVSLOsRVhrrTQAAAVU"]
[Thu Sep 17 15:04:47.543817 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.134.22:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrTgAAAVo"]
[Thu Sep 17 15:04:47.551003 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/client/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrTwAAAVE"]
[Thu Sep 17 15:04:47.556456 2026] [security2:error] [pid 955873:tid 956123] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailer/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrUAAAAYI"]
[Thu Sep 17 15:04:47.606866 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/resources/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrVAAAARk"]
[Thu Sep 17 15:04:47.668215 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/project/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrVgAAAUA"]
[Thu Sep 17 15:04:47.718594 2026] [security2:error] [pid 955873:tid 956112] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mail/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrWgAAAXc"]
[Thu Sep 17 15:04:47.762151 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/assets/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrWwAAAVI"]
[Thu Sep 17 15:04:47.762816 2026] [security2:error] [pid 955873:tid 956103] [client 52.231.79.181:1709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toolmix24.sinkgp.com"] [uri "/hello.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrXAAAAW4"]
[Thu Sep 17 15:04:47.764785 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/admin-panel/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrXgAAAT8"]
[Thu Sep 17 15:04:47.815357 2026] [security2:error] [pid 955873:tid 956094] [client 154.190.208.131:42122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrXwAAAWU"]
[Thu Sep 17 15:04:47.815478 2026] [security2:error] [pid 955873:tid 956094] [client 154.190.208.131:42122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrXwAAAWU"]
[Thu Sep 17 15:04:47.881108 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrVQAAAXM"]
[Thu Sep 17 15:04:47.881135 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrVQAAAXM"]
[Thu Sep 17 15:04:47.883691 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/email/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrYgAAAQ8"]
[Thu Sep 17 15:04:47.890825 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/control-panel/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrZAAAATk"]
[Thu Sep 17 15:04:47.920248 2026] [security2:error] [pid 955873:tid 956095] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/uploads/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrZgAAAWY"]
[Thu Sep 17 15:04:47.965839 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/user-panel/.env"] [unique_id "aqxV7xFTPRVSLOsRVhrrZwAAASQ"]
[Thu Sep 17 15:04:48.023842 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:36786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/AfterGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrraQAAAWo"]
[Thu Sep 17 15:04:48.023947 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:36786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/AfterGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrraQAAAWo"]
[Thu Sep 17 15:04:48.045827 2026] [security2:error] [pid 955873:tid 956088] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/smtp/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrragAAAV8"]
[Thu Sep 17 15:04:48.052420 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/node/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrbAAAARo"]
[Thu Sep 17 15:04:48.062238 2026] [security2:error] [pid 955873:tid 956060] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV7xFTPRVSLOsRVhrrZQABQ0Q"], referer: http://radtechresourcegroup.net./backup/
[Thu Sep 17 15:04:48.073391 2026] [security2:error] [pid 955873:tid 956117] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/internal/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrbQAAAXw"]
[Thu Sep 17 15:04:48.134628 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/express/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrbgAAAUs"]
[Thu Sep 17 15:04:48.209024 2026] [security2:error] [pid 955873:tid 956026] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailing/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrcwAAASE"]
[Thu Sep 17 15:04:48.218058 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/next/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrdQAAATg"]
[Thu Sep 17 15:04:48.228770 2026] [security2:error] [pid 955873:tid 956036] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/tools/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrdgAAASs"]
[Thu Sep 17 15:04:48.245809 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.134.22:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxV8BFTPRVSLOsRVhrreAAAASY"]
[Thu Sep 17 15:04:48.305001 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/BeforeGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrewAAATE"]
[Thu Sep 17 15:04:48.305097 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Events/BeforeGenerateResultEvent.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrewAAATE"]
[Thu Sep 17 15:04:48.312889 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/nuxt/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrfAAAAWg"]
[Thu Sep 17 15:04:48.371397 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/notifications/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrfQAAASk"]
[Thu Sep 17 15:04:48.395719 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/scripts/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrfwAAAYA"]
[Thu Sep 17 15:04:48.407670 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/nest/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrgAAAAUo"]
[Thu Sep 17 15:04:48.424078 2026] [security2:error] [pid 955873:tid 956005] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrgQAAAQw"]
[Thu Sep 17 15:04:48.497276 2026] [security2:error] [pid 955873:tid 956066] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/link-prefetch.min.js"] [unique_id "aqxV8BFTPRVSLOsRVhrrggAAAUk"]
[Thu Sep 17 15:04:48.532956 2026] [security2:error] [pid 955873:tid 956041] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/notify/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrhQAAATA"]
[Thu Sep 17 15:04:48.534254 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/react/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrhgAAAVk"]
[Thu Sep 17 15:04:48.551966 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/bin/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrhwAAAVQ"]
[Thu Sep 17 15:04:48.573335 2026] [security2:error] [pid 955873:tid 956021] [client 85.208.98.202:54165] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/css/email-subscribers-public.css"] [unique_id "aqxV8BFTPRVSLOsRVhrriAAAARw"]
[Thu Sep 17 15:04:48.590998 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8BFTPRVSLOsRVhrrigAAARA"]
[Thu Sep 17 15:04:48.617218 2026] [security2:error] [pid 955873:tid 956048] [client 45.131.194.118:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.194.131.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV8BFTPRVSLOsRVhrriQAAATc"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:48.618418 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/vue/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrriwAAATM"]
[Thu Sep 17 15:04:48.649389 2026] [security2:error] [pid 955873:tid 956076] [client 45.169.98.18:49490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrjAAAAVM"]
[Thu Sep 17 15:04:48.649493 2026] [security2:error] [pid 955873:tid 956076] [client 45.169.98.18:49490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrjAAAAVM"]
[Thu Sep 17 15:04:48.682180 2026] [security2:error] [pid 955873:tid 956027] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV8BFTPRVSLOsRVhrrhAABIkY"], referer: http://radtechresourcegroup.net./old/
[Thu Sep 17 15:04:48.697030 2026] [security2:error] [pid 955873:tid 956016] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sender/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrkQAAARc"]
[Thu Sep 17 15:04:48.704407 2026] [security2:error] [pid 955873:tid 956054] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sbin/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrkwAAAT0"]
[Thu Sep 17 15:04:48.762032 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/angular/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrlgAAAVc"]
[Thu Sep 17 15:04:48.776737 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8BFTPRVSLOsRVhrrlAAAAW8"]
[Thu Sep 17 15:04:48.829793 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/svelte/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmAAAAXA"]
[Thu Sep 17 15:04:48.858670 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/local/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmQAAASM"]
[Thu Sep 17 15:04:48.859895 2026] [security2:error] [pid 955873:tid 956045] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/campaign/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmgAAATQ"]
[Thu Sep 17 15:04:48.895594 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/vite/.env"] [unique_id "aqxV8BFTPRVSLOsRVhrrmwAAAUU"]
[Thu Sep 17 15:04:48.919548 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/wp-includes/php-ai-client/src/"] [unique_id "aqxV8BFTPRVSLOsRVhrrnQAAAVo"]
[Thu Sep 17 15:04:48.937388 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.134.22:33070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/site/phpinfo.php"] [unique_id "aqxV8BFTPRVSLOsRVhrroQAAAUQ"]
[Thu Sep 17 15:04:49.012672 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/portal/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrowAAARk"]
[Thu Sep 17 15:04:49.021701 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/backup/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrpAAAAUA"]
[Thu Sep 17 15:04:49.024454 2026] [security2:error] [pid 955873:tid 956101] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/newsletter/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrpQAAAWw"]
[Thu Sep 17 15:04:49.120267 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/backups/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrqQAAAWk"]
[Thu Sep 17 15:04:49.167986 2026] [security2:error] [pid 955873:tid 956094] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/dashboard/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrrwAAAWU"]
[Thu Sep 17 15:04:49.169098 2026] [security2:error] [pid 955873:tid 956040] [client 115.244.164.14:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrrAAAAS8"]
[Thu Sep 17 15:04:49.169177 2026] [security2:error] [pid 955873:tid 956040] [client 115.244.164.14:58638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrrAAAAS8"]
[Thu Sep 17 15:04:49.187278 2026] [security2:error] [pid 955873:tid 956108] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/ses/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrsAAAAXM"]
[Thu Sep 17 15:04:49.248380 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrpgAAAXc"]
[Thu Sep 17 15:04:49.248405 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrpgAAAXc"]
[Thu Sep 17 15:04:49.275614 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/old/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrtQAAAYk"]
[Thu Sep 17 15:04:49.302452 2026] [security2:error] [pid 955873:tid 956056] [client 206.189.130.172:55434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.net"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrqgABP0k"], referer: http://radtechresourcegroup.net./new/
[Thu Sep 17 15:04:49.325530 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/panel/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrtgAAATU"]
[Thu Sep 17 15:04:49.354468 2026] [security2:error] [pid 955873:tid 956012] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sendgrid/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrtwAAARM"]
[Thu Sep 17 15:04:49.390584 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/tmp/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrugAAAYY"]
[Thu Sep 17 15:04:49.392564 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/"] [unique_id "aqxV8RFTPRVSLOsRVhrruwAAAVw"]
[Thu Sep 17 15:04:49.459680 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/temp/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrvAAAAYc"]
[Thu Sep 17 15:04:49.479308 2026] [security2:error] [pid 955873:tid 956081] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/crm/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrvQAAAVg"]
[Thu Sep 17 15:04:49.495551 2026] [security2:error] [pid 955873:tid 956117] [client 20.244.34.24:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrvgAAAXw"], referer: binance.com
[Thu Sep 17 15:04:49.523767 2026] [security2:error] [pid 955873:tid 956004] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/sparkpost/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrvwAAAQs"]
[Thu Sep 17 15:04:49.534692 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/lab/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrwQAAAVA"]
[Thu Sep 17 15:04:49.549632 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/"] [unique_id "aqxV8RFTPRVSLOsRVhrrwgAAAXE"]
[Thu Sep 17 15:04:49.614513 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cronlab/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrxAAAATI"]
[Thu Sep 17 15:04:49.631650 2026] [security2:error] [pid 955873:tid 956099] [client 34.166.134.22:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxV8RFTPRVSLOsRVhrryAAAAWo"]
[Thu Sep 17 15:04:49.638052 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/erp/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrryQAAARg"]
[Thu Sep 17 15:04:49.649472 2026] [security2:error] [pid 955873:tid 956068] [client 179.6.7.127:35704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrrwAABS0s"]
[Thu Sep 17 15:04:49.685559 2026] [security2:error] [pid 955873:tid 956097] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/postmark/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrzAAAAWg"]
[Thu Sep 17 15:04:49.693574 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8RFTPRVSLOsRVhrrzQAAARU"]
[Thu Sep 17 15:04:49.711286 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cron/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrrzgAAASk"]
[Thu Sep 17 15:04:49.754059 2026] [security2:error] [pid 955873:tid 956064] [client 104.28.198.244:22541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr0gAAAUc"]
[Thu Sep 17 15:04:49.754130 2026] [security2:error] [pid 955873:tid 956064] [client 104.28.198.244:22541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr0gAAAUc"]
[Thu Sep 17 15:04:49.794091 2026] [security2:error] [pid 955873:tid 956084] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/shop/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr0wAAAVs"]
[Thu Sep 17 15:04:49.817038 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/en/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr1AAAAUo"]
[Thu Sep 17 15:04:49.850265 2026] [security2:error] [pid 955873:tid 956020] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailgun/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr1gAAARs"]
[Thu Sep 17 15:04:49.951729 2026] [security2:error] [pid 955873:tid 956124] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/store/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr2AAAAYM"]
[Thu Sep 17 15:04:49.997762 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/administrator/.env"] [unique_id "aqxV8RFTPRVSLOsRVhrr1wAAAYQ"]
[Thu Sep 17 15:04:50.015422 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr1QAAASA"]
[Thu Sep 17 15:04:50.015444 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr1QAAASA"]
[Thu Sep 17 15:04:50.016001 2026] [security2:error] [pid 955873:tid 956009] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mandrill/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr2wAAARA"]
[Thu Sep 17 15:04:50.115538 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/saas/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr4AAAAX0"]
[Thu Sep 17 15:04:50.136803 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/psnlink/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr4QAAAXQ"]
[Thu Sep 17 15:04:50.159575 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/File.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr4gAAARE"]
[Thu Sep 17 15:04:50.159639 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/DTO/File.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr4gAAARE"]
[Thu Sep 17 15:04:50.183363 2026] [security2:error] [pid 955873:tid 956080] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mailjet/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr4wAAAVc"]
[Thu Sep 17 15:04:50.261519 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/exapi/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr5wAAAXA"]
[Thu Sep 17 15:04:50.277940 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/client/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr6AAAASM"]
[Thu Sep 17 15:04:50.322538 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.134.22:55142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr6wAAAXo"]
[Thu Sep 17 15:04:50.347226 2026] [security2:error] [pid 955873:tid 956114] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/brevo/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr7QAAAXk"]
[Thu Sep 17 15:04:50.378495 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sitemaps/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr7gAAAWA"]
[Thu Sep 17 15:04:50.424993 2026] [security2:error] [pid 955873:tid 956059] [client 47.79.201.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxV8hFTPRVSLOsRVhrr3wAAAUI"], referer: https://www.google.com/
[Thu Sep 17 15:04:50.432523 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/project/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr7wAAAWM"]
[Thu Sep 17 15:04:50.442554 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:47698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/"] [unique_id "aqxV8hFTPRVSLOsRVhrr8AAAAYE"]
[Thu Sep 17 15:04:50.512359 2026] [security2:error] [pid 955873:tid 956018] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/transactional/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr8gAAARk"]
[Thu Sep 17 15:04:50.558191 2026] [security2:error] [pid 955873:tid 956101] [client 85.208.98.197:44125] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/classie.min.js"] [unique_id "aqxV8hFTPRVSLOsRVhrr9AAAAWw"]
[Thu Sep 17 15:04:50.572488 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "aqxV8hFTPRVSLOsRVhrr9QAAAWU"]
[Thu Sep 17 15:04:50.585290 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/admin-panel/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr9wAAATY"]
[Thu Sep 17 15:04:50.597531 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/"] [unique_id "aqxV8hFTPRVSLOsRVhrr9gAAAS8"]
[Thu Sep 17 15:04:50.628169 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/logs/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr-QAAAXc"]
[Thu Sep 17 15:04:50.658591 2026] [security2:error] [pid 955873:tid 956063] [client 57.141.14.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxV8RFTPRVSLOsRVhrr0AAAAUY"]
[Thu Sep 17 15:04:50.673603 2026] [security2:error] [pid 955873:tid 956056] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/bulk/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr-wAAAT8"]
[Thu Sep 17 15:04:50.717006 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cache/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrr_gAAAQ0"]
[Thu Sep 17 15:04:50.744823 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:47698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV8hFTPRVSLOsRVhrr_wAAAVI"]
[Thu Sep 17 15:04:50.751105 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/control-panel/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsAAAAAU4"]
[Thu Sep 17 15:04:50.800995 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "aqxV8hFTPRVSLOsRVhrsAQAAAW0"]
[Thu Sep 17 15:04:50.808632 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailer/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsAgAAARM"]
[Thu Sep 17 15:04:50.835647 2026] [security2:error] [pid 955873:tid 956070] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/aws/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsAwAAAU0"]
[Thu Sep 17 15:04:50.871746 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mail/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsBAAAAV0"]
[Thu Sep 17 15:04:50.903600 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/user-panel/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsBgAAATk"]
[Thu Sep 17 15:04:50.935378 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/email/.env"] [unique_id "aqxV8hFTPRVSLOsRVhrsBwAAAVY"]
[Thu Sep 17 15:04:51.002536 2026] [security2:error] [pid 955873:tid 956127] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/azure/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsCAAAAYY"]
[Thu Sep 17 15:04:51.009962 2026] [security2:error] [pid 955873:tid 956095] [client 34.166.134.22:55154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsCQAAAWY"]
[Thu Sep 17 15:04:51.019849 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/smtp/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsCgAAARI"]
[Thu Sep 17 15:04:51.059461 2026] [security2:error] [pid 955873:tid 956088] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/node/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsDQAAAV8"]
[Thu Sep 17 15:04:51.062656 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8hFTPRVSLOsRVhrsBQAAAR0"]
[Thu Sep 17 15:04:51.062684 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV8hFTPRVSLOsRVhrsBQAAAR0"]
[Thu Sep 17 15:04:51.100615 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.224.217:52114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailing/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsDwAAAX4"]
[Thu Sep 17 15:04:51.170229 2026] [security2:error] [pid 955873:tid 956117] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/gcp/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsEQAAAXw"]
[Thu Sep 17 15:04:51.205595 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:47698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/FileTypeEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsFgAAAR8"]
[Thu Sep 17 15:04:51.205682 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:47698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/FileTypeEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsFgAAAR8"]
[Thu Sep 17 15:04:51.211955 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/express/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsFwAAAXg"]
[Thu Sep 17 15:04:51.339299 2026] [security2:error] [pid 955873:tid 956014] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cloud/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsGgAAARU"]
[Thu Sep 17 15:04:51.348263 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/notifications/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsGwAAARg"]
[Thu Sep 17 15:04:51.364384 2026] [security2:error] [pid 955873:tid 956037] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "aqxV8xFTPRVSLOsRVhrsHAAAASw"]
[Thu Sep 17 15:04:51.366706 2026] [security2:error] [pid 955873:tid 956096] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/next/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsHQAAAWc"]
[Thu Sep 17 15:04:51.446504 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/notify/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsHgAAAVs"]
[Thu Sep 17 15:04:51.496268 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/MediaOrientationEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsHwAAAYM"]
[Thu Sep 17 15:04:51.496336 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/Enums/MediaOrientationEnum.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsHwAAAYM"]
[Thu Sep 17 15:04:51.504437 2026] [security2:error] [pid 955873:tid 956066] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/infrastructure/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsIAAAAUk"]
[Thu Sep 17 15:04:51.519109 2026] [security2:error] [pid 955873:tid 956041] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/nuxt/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsIQAAATA"]
[Thu Sep 17 15:04:51.564480 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sender/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsIgAAAVk"]
[Thu Sep 17 15:04:51.630897 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/campaign/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsJQAAAXs"]
[Thu Sep 17 15:04:51.671556 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/nest/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsKQAAATc"]
[Thu Sep 17 15:04:51.677317 2026] [security2:error] [pid 955873:tid 956076] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/docker/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsKwAAAVM"]
[Thu Sep 17 15:04:51.685960 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.134.22:55162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/core/phpinfo.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsLgAAAUo"]
[Thu Sep 17 15:04:51.774446 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/"] [unique_id "aqxV8xFTPRVSLOsRVhrsMQAAAXA"]
[Thu Sep 17 15:04:51.813524 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/newsletter/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsMwAAASM"]
[Thu Sep 17 15:04:51.828249 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/react/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsNAAAAVU"]
[Thu Sep 17 15:04:51.843644 2026] [security2:error] [pid 955873:tid 956083] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/k8s/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsNQAAAVo"]
[Thu Sep 17 15:04:51.859195 2026] [security2:error] [pid 955873:tid 956076] [client 216.73.163.58:30195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV8xFTPRVSLOsRVhrsMgAAAVM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:51.922315 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/ses/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsNwAAATQ"]
[Thu Sep 17 15:04:51.934786 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/"] [unique_id "aqxV8xFTPRVSLOsRVhrsNgAAAUw"]
[Thu Sep 17 15:04:51.985436 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/vue/.env"] [unique_id "aqxV8xFTPRVSLOsRVhrsOwAAAX8"]
[Thu Sep 17 15:04:52.013056 2026] [security2:error] [pid 955873:tid 956039] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/kubernetes/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsPAAAAS4"]
[Thu Sep 17 15:04:52.051538 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sendgrid/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsPQAAAU8"]
[Thu Sep 17 15:04:52.072240 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:47722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/wp-includes/php-ai-client/src/Files/"] [unique_id "aqxV9BFTPRVSLOsRVhrsPwAAAWE"]
[Thu Sep 17 15:04:52.128908 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/sparkpost/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsQAAAAXY"]
[Thu Sep 17 15:04:52.140803 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/angular/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsQQAAAWM"]
[Thu Sep 17 15:04:52.174334 2026] [security2:error] [pid 955873:tid 956122] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/terraform/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsRAAAAYE"]
[Thu Sep 17 15:04:52.247078 2026] [security2:error] [pid 955873:tid 956038] [client 156.245.246.6:50647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enolastable.com"] [uri "/index.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsSQAAAS0"], referer: https://enolastable.com
[Thu Sep 17 15:04:52.259072 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/postmark/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsSgAAATY"]
[Thu Sep 17 15:04:52.295694 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/svelte/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsSwAAAS8"]
[Thu Sep 17 15:04:52.343702 2026] [security2:error] [pid 955873:tid 956112] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/ansible/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsTQAAAXc"]
[Thu Sep 17 15:04:52.385984 2026] [security2:error] [pid 955873:tid 956016] [client 34.166.134.22:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.glassblowingbug.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsUAAAARc"]
[Thu Sep 17 15:04:52.388966 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailgun/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsUQAAAWI"]
[Thu Sep 17 15:04:52.406101 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsRgAAAWw"]
[Thu Sep 17 15:04:52.406121 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsRgAAAWw"]
[Thu Sep 17 15:04:52.449795 2026] [security2:error] [pid 955873:tid 956006] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/vite/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsUwAAAQ0"]
[Thu Sep 17 15:04:52.486017 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mandrill/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsVQAAARM"]
[Thu Sep 17 15:04:52.508149 2026] [security2:error] [pid 955873:tid 956070] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/.git/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsVwAAAU0"]
[Thu Sep 17 15:04:52.544220 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/MimeType.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsWAAAAQ8"]
[Thu Sep 17 15:04:52.544326 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Files/ValueObjects/MimeType.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsWAAAAQ8"]
[Thu Sep 17 15:04:52.566074 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mailjet/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsWQAAAV0"]
[Thu Sep 17 15:04:52.602576 2026] [security2:error] [pid 955873:tid 956110] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/backup/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsWgAAAXU"]
[Thu Sep 17 15:04:52.675129 2026] [security2:error] [pid 955873:tid 956053] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/ci/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsXQAAATw"]
[Thu Sep 17 15:04:52.675988 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/brevo/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsXgAAAV4"]
[Thu Sep 17 15:04:52.757423 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/backups/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsZgAAAXI"]
[Thu Sep 17 15:04:52.766025 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/transactional/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsaAAAAQs"]
[Thu Sep 17 15:04:52.831452 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9BFTPRVSLOsRVhrsawAAAWo"]
[Thu Sep 17 15:04:52.831757 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/bulk/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsagAAAXg"]
[Thu Sep 17 15:04:52.835710 2026] [security2:error] [pid 955873:tid 956043] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/cd/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsbAAAATI"]
[Thu Sep 17 15:04:52.872631 2026] [security2:error] [pid 955873:tid 955962] [remote 5.78.122.81:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.122.78.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beaglerescueleague.org"] [uri "/wp-admin/admin.php"] [unique_id "aqxV9BFTPRVSLOsRVhrsaQABH1g"], referer: https://beaglerescueleague.org/wp-admin/admin.php?page=backwpuponboarding
[Thu Sep 17 15:04:52.913017 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/aws/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsbQAAARU"]
[Thu Sep 17 15:04:52.918586 2026] [security2:error] [pid 955873:tid 956034] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/old/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrsbgAAASk"]
[Thu Sep 17 15:04:52.993923 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9BFTPRVSLOsRVhrsbwAAARg"]
[Thu Sep 17 15:04:52.997105 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/jenkins/.env"] [unique_id "aqxV9BFTPRVSLOsRVhrscAAAAXE"]
[Thu Sep 17 15:04:53.029281 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/azure/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrscQAAAYA"]
[Thu Sep 17 15:04:53.083073 2026] [security2:error] [pid 955873:tid 956073] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/tmp/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrscgAAAVA"]
[Thu Sep 17 15:04:53.116827 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/gcp/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsdAAAASg"]
[Thu Sep 17 15:04:53.141705 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/wp-includes/php-ai-client/src/"] [unique_id "aqxV9RFTPRVSLOsRVhrsdQAAAUc"]
[Thu Sep 17 15:04:53.158229 2026] [security2:error] [pid 955873:tid 956084] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/gitlab/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsdwAAAVs"]
[Thu Sep 17 15:04:53.202133 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cloud/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsegAAAYU"]
[Thu Sep 17 15:04:53.244291 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/temp/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsewAAAVk"]
[Thu Sep 17 15:04:53.279077 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:61272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgQAAAWc"]
[Thu Sep 17 15:04:53.279176 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:61272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgQAAAWc"]
[Thu Sep 17 15:04:53.310974 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/infrastructure/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsgwAAATc"]
[Thu Sep 17 15:04:53.319709 2026] [security2:error] [pid 955873:tid 956058] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/github/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrshAAAAUE"]
[Thu Sep 17 15:04:53.399452 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/docker/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsiwAAAX0"]
[Thu Sep 17 15:04:53.405346 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/lab/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsjAAAASM"]
[Thu Sep 17 15:04:53.467742 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgAAAARw"]
[Thu Sep 17 15:04:53.467767 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9RFTPRVSLOsRVhrsgAAAARw"]
[Thu Sep 17 15:04:53.481881 2026] [security2:error] [pid 955873:tid 956061] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/actions/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsjgAAAUQ"]
[Thu Sep 17 15:04:53.522321 2026] [security2:error] [pid 955873:tid 956069] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/k8s/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsjwAAAUw"]
[Thu Sep 17 15:04:53.567931 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cronlab/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrskAAAASI"]
[Thu Sep 17 15:04:53.609944 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/"] [unique_id "aqxV9RFTPRVSLOsRVhrskgAAAS4"]
[Thu Sep 17 15:04:53.644061 2026] [security2:error] [pid 955873:tid 956072] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/circleci/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrskwAAAU8"]
[Thu Sep 17 15:04:53.673063 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/kubernetes/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrslQAAAWA"]
[Thu Sep 17 15:04:53.720680 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cron/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsmgAAAXY"]
[Thu Sep 17 15:04:53.739477 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/terraform/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsmwAAAVc"]
[Thu Sep 17 15:04:53.774072 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/"] [unique_id "aqxV9RFTPRVSLOsRVhrsnAAAAYE"]
[Thu Sep 17 15:04:53.806087 2026] [security2:error] [pid 955873:tid 956047] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/travis/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsngAAATY"]
[Thu Sep 17 15:04:53.838158 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/ansible/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsnwAAAS8"]
[Thu Sep 17 15:04:53.874841 2026] [security2:error] [pid 955873:tid 956103] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/en/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrsogAAAW4"]
[Thu Sep 17 15:04:53.918234 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9RFTPRVSLOsRVhrspAAAATg"]
[Thu Sep 17 15:04:53.929835 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/.git/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrspQAAAYI"]
[Thu Sep 17 15:04:53.969828 2026] [security2:error] [pid 955873:tid 956046] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/buildkite/.env"] [unique_id "aqxV9RFTPRVSLOsRVhrspwAAATU"]
[Thu Sep 17 15:04:54.006277 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/ci/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsqQAAAVI"]
[Thu Sep 17 15:04:54.080391 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/cd/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsrwAAASY"]
[Thu Sep 17 15:04:54.092097 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/administrator/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsqwAAAWk"]
[Thu Sep 17 15:04:54.132355 2026] [security2:error] [pid 955873:tid 956079] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mysql/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrssQAAAVY"]
[Thu Sep 17 15:04:54.181877 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/jenkins/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrssgAAAUg"]
[Thu Sep 17 15:04:54.246397 2026] [security2:error] [pid 955873:tid 956085] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/psnlink/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrstgAAAVw"]
[Thu Sep 17 15:04:54.247451 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrsrQAAAV0"]
[Thu Sep 17 15:04:54.247470 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrsrQAAAV0"]
[Thu Sep 17 15:04:54.253785 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/gitlab/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrstwAAATk"]
[Thu Sep 17 15:04:54.301285 2026] [security2:error] [pid 955873:tid 956014] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/postgres/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsuwAAARU"]
[Thu Sep 17 15:04:54.342405 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/github/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsvwAAAUM"]
[Thu Sep 17 15:04:54.390132 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/Message.php"] [unique_id "aqxV9hFTPRVSLOsRVhrswAAAAQo"]
[Thu Sep 17 15:04:54.390242 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/Message.php"] [unique_id "aqxV9hFTPRVSLOsRVhrswAAAAQo"]
[Thu Sep 17 15:04:54.399767 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/exapi/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrswQAAASE"]
[Thu Sep 17 15:04:54.453148 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/actions/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrswgAAAWg"]
[Thu Sep 17 15:04:54.464599 2026] [security2:error] [pid 955873:tid 956064] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/mongodb/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrswwAAAUc"]
[Thu Sep 17 15:04:54.531075 2026] [core:error] [pid 955873:tid 956095] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:54.531095 2026] [core:error] [pid 955873:tid 956095] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:54.549092 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/circleci/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrsygAAAVk"]
[Thu Sep 17 15:04:54.553581 2026] [security2:error] [pid 955873:tid 956125] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sitemaps/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrszAAAAYQ"]
[Thu Sep 17 15:04:54.587987 2026] [security2:error] [pid 955873:tid 956011] [client 45.146.54.107:57459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrsxwAAARI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:54.630271 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/travis/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrszwAAASM"]
[Thu Sep 17 15:04:54.632109 2026] [security2:error] [pid 955873:tid 956005] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/redis/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs0AAAAQw"]
[Thu Sep 17 15:04:54.666571 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/MessagePart.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs0gAAAXo"]
[Thu Sep 17 15:04:54.666687 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/MessagePart.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs0gAAAXo"]
[Thu Sep 17 15:04:54.728498 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/buildkite/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs2AAAAXc"]
[Thu Sep 17 15:04:54.737779 2026] [security2:error] [pid 955873:tid 956010] [client 3.82.141.143:8040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3AAAARE"]
[Thu Sep 17 15:04:54.744136 2026] [security2:error] [pid 955873:tid 956083] [client 3.82.141.143:8108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php.save"] [unique_id "aqxV9hFTPRVSLOsRVhrs4QAAAVo"]
[Thu Sep 17 15:04:54.745241 2026] [security2:error] [pid 955873:tid 956021] [client 3.82.141.143:7930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3QAAARw"]
[Thu Sep 17 15:04:54.746004 2026] [security2:error] [pid 955873:tid 956069] [client 3.82.141.143:7972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3gAAAUw"]
[Thu Sep 17 15:04:54.746316 2026] [security2:error] [pid 955873:tid 956020] [client 3.82.141.143:7914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs3wAAARs"]
[Thu Sep 17 15:04:54.746948 2026] [security2:error] [pid 955873:tid 956076] [client 3.82.141.143:7998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs4AAAAVM"]
[Thu Sep 17 15:04:54.754933 2026] [security2:error] [pid 955873:tid 956061] [client 3.82.141.143:7886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env.bak"] [unique_id "aqxV9hFTPRVSLOsRVhrs5AAAAUQ"]
[Thu Sep 17 15:04:54.755120 2026] [security2:error] [pid 955873:tid 956062] [client 3.82.141.143:7948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs4gAAAUU"]
[Thu Sep 17 15:04:54.756044 2026] [security2:error] [pid 955873:tid 956055] [client 3.82.141.143:7960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs4wAAAT4"]
[Thu Sep 17 15:04:54.756387 2026] [security2:error] [pid 955873:tid 956120] [client 3.82.141.143:8130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs5QAAAX8"]
[Thu Sep 17 15:04:54.756953 2026] [security2:error] [pid 955873:tid 956025] [client 3.82.141.143:8184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php~"] [unique_id "aqxV9hFTPRVSLOsRVhrs5gAAASA"]
[Thu Sep 17 15:04:54.760575 2026] [security2:error] [pid 955873:tid 956089] [client 3.82.141.143:8146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs5wAAAWA"]
[Thu Sep 17 15:04:54.763197 2026] [security2:error] [pid 955873:tid 956027] [client 3.82.141.143:7860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs6AAAASI"]
[Thu Sep 17 15:04:54.763831 2026] [security2:error] [pid 955873:tid 956039] [client 3.82.141.143:7970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/web.config"] [unique_id "aqxV9hFTPRVSLOsRVhrs6gAAAS4"]
[Thu Sep 17 15:04:54.764698 2026] [security2:error] [pid 955873:tid 956054] [client 3.82.141.143:8006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs6QAAAT0"]
[Thu Sep 17 15:04:54.767783 2026] [security2:error] [pid 955873:tid 956045] [client 3.82.141.143:8042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs6wAAATQ"]
[Thu Sep 17 15:04:54.769283 2026] [security2:error] [pid 955873:tid 956032] [client 3.82.141.143:8046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7gAAASc"]
[Thu Sep 17 15:04:54.769339 2026] [security2:error] [pid 955873:tid 956111] [client 3.82.141.143:8032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7AAAAXY"]
[Thu Sep 17 15:04:54.769370 2026] [security2:error] [pid 955873:tid 956018] [client 3.82.141.143:7896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7QAAARk"]
[Thu Sep 17 15:04:54.771518 2026] [security2:error] [pid 955873:tid 956072] [client 3.82.141.143:8168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs7wAAAU8"]
[Thu Sep 17 15:04:54.775560 2026] [security2:error] [pid 955873:tid 956080] [client 3.82.141.143:8068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.subscribe.faewave.com"] [uri "/config.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs8AAAAVc"]
[Thu Sep 17 15:04:54.776131 2026] [security2:error] [pid 955873:tid 956092] [client 3.82.141.143:8090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php.old"] [unique_id "aqxV9hFTPRVSLOsRVhrs8gAAAWM"]
[Thu Sep 17 15:04:54.777689 2026] [security2:error] [pid 955873:tid 956114] [client 3.82.141.143:8104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs8QAAAXk"]
[Thu Sep 17 15:04:54.783815 2026] [security2:error] [pid 955873:tid 956122] [client 3.82.141.143:8156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9AAAAYE"]
[Thu Sep 17 15:04:54.790310 2026] [security2:error] [pid 955873:tid 956103] [client 3.82.141.143:7912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9gAAAW4"]
[Thu Sep 17 15:04:54.790337 2026] [security2:error] [pid 955873:tid 956091] [client 3.82.141.143:8044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9QAAAWI"]
[Thu Sep 17 15:04:54.795053 2026] [security2:error] [pid 955873:tid 956051] [client 3.82.141.143:7988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs9wAAATo"]
[Thu Sep 17 15:04:54.795857 2026] [security2:error] [pid 955873:tid 956007] [client 3.82.141.143:8054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs-gAAAQ4"]
[Thu Sep 17 15:04:54.797589 2026] [security2:error] [pid 955873:tid 956110] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/elasticsearch/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrs-wAAAXU"]
[Thu Sep 17 15:04:54.797614 2026] [security2:error] [pid 955873:tid 956046] [client 3.82.141.143:8200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs-QAAATU"]
[Thu Sep 17 15:04:54.799921 2026] [security2:error] [pid 955873:tid 956123] [client 3.82.141.143:7864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs_AAAAYI"]
[Thu Sep 17 15:04:54.802731 2026] [security2:error] [pid 955873:tid 956101] [client 3.82.141.143:7984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs_gAAAWw"]
[Thu Sep 17 15:04:54.802813 2026] [security2:error] [pid 955873:tid 956056] [client 3.82.141.143:8132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrs_wAAAT8"]
[Thu Sep 17 15:04:54.803376 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mysql/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrtAQAAAWQ"]
[Thu Sep 17 15:04:54.827559 2026] [security2:error] [pid 955873:tid 956042] [client 3.82.141.143:8058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.subscribe.faewave.com"] [uri "/wp-config.php.bak"] [unique_id "aqxV9hFTPRVSLOsRVhrtBwAAATE"]
[Thu Sep 17 15:04:54.828533 2026] [security2:error] [pid 955873:tid 956013] [client 3.82.141.143:8004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env.backup"] [unique_id "aqxV9hFTPRVSLOsRVhrtBgAAARQ"]
[Thu Sep 17 15:04:54.828560 2026] [security2:error] [pid 955873:tid 956090] [client 3.82.141.143:7870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.subscribe.faewave.com"] [uri "/.env.old"] [unique_id "aqxV9hFTPRVSLOsRVhrtBQAAAWE"]
[Thu Sep 17 15:04:54.829648 2026] [security2:error] [pid 955873:tid 956038] [client 3.82.141.143:8022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtBAAAAS0"]
[Thu Sep 17 15:04:54.829776 2026] [security2:error] [pid 955873:tid 956049] [client 3.82.141.143:7938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtAwAAATg"]
[Thu Sep 17 15:04:54.830273 2026] [security2:error] [pid 955873:tid 956059] [client 3.82.141.143:8080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtCAAAAUI"]
[Thu Sep 17 15:04:54.833571 2026] [security2:error] [pid 955873:tid 956104] [client 3.82.141.143:8126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtCQAAAW8"]
[Thu Sep 17 15:04:54.834925 2026] [security2:error] [pid 955873:tid 956016] [client 3.82.141.143:7852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.subscribe.faewave.com"] [uri "/index.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtCgAAARc"]
[Thu Sep 17 15:04:54.900869 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/postgres/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrtDQAAAUM"]
[Thu Sep 17 15:04:54.954092 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/ModelMessage.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtEQAAAW0"]
[Thu Sep 17 15:04:54.954168 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/ModelMessage.php"] [unique_id "aqxV9hFTPRVSLOsRVhrtEQAAAW0"]
[Thu Sep 17 15:04:54.970879 2026] [security2:error] [pid 955873:tid 956125] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/rabbitmq/.env"] [unique_id "aqxV9hFTPRVSLOsRVhrtEgAAAYQ"]
[Thu Sep 17 15:04:55.102825 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/mongodb/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtFAAAATA"]
[Thu Sep 17 15:04:55.147468 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/logs/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtFwAAAQw"]
[Thu Sep 17 15:04:55.147517 2026] [security2:error] [pid 955873:tid 956028] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/kafka/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtGAAAASM"]
[Thu Sep 17 15:04:55.166180 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/redis/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtGQAAAWU"]
[Thu Sep 17 15:04:55.230980 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/elasticsearch/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtHQAAARs"]
[Thu Sep 17 15:04:55.248263 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:47764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/UserMessage.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtHwAAAVM"]
[Thu Sep 17 15:04:55.248361 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:47764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/DTO/UserMessage.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtHwAAAVM"]
[Thu Sep 17 15:04:55.301367 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cache/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtIgAAAUU"]
[Thu Sep 17 15:04:55.309488 2026] [security2:error] [pid 955873:tid 956055] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/queue/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtIwAAAT4"]
[Thu Sep 17 15:04:55.313935 2026] [security2:error] [pid 955873:tid 956120] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/rabbitmq/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtJAAAAX8"]
[Thu Sep 17 15:04:55.389885 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/kafka/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtJQAAASA"]
[Thu Sep 17 15:04:55.419913 2026] [security2:error] [pid 955873:tid 956054] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "aqxV9xFTPRVSLOsRVhrtJgAAAT0"]
[Thu Sep 17 15:04:55.453547 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailer/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtJwAAATQ"]
[Thu Sep 17 15:04:55.471218 2026] [security2:error] [pid 955873:tid 956032] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/worker/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtKAAAASc"]
[Thu Sep 17 15:04:55.502599 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/queue/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtKQAAARk"]
[Thu Sep 17 15:04:55.531331 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:47774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/"] [unique_id "aqxV9xFTPRVSLOsRVhrtKwAAAU4"]
[Thu Sep 17 15:04:55.581616 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/worker/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtLAAAATY"]
[Thu Sep 17 15:04:55.612400 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mail/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtLQAAAVc"]
[Thu Sep 17 15:04:55.635257 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/job/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtLgAAAWM"]
[Thu Sep 17 15:04:55.648118 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "aqxV9xFTPRVSLOsRVhrtLwAAAXk"]
[Thu Sep 17 15:04:55.678241 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/job/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtMgAAAW4"]
[Thu Sep 17 15:04:55.686462 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/"] [unique_id "aqxV9xFTPRVSLOsRVhrtMQAAAYE"]
[Thu Sep 17 15:04:55.764971 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/email/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtNwAAAYI"]
[Thu Sep 17 15:04:55.770980 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/test/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtOAAAAQ0"]
[Thu Sep 17 15:04:55.801132 2026] [security2:error] [pid 955873:tid 956130] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/test/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtOgAAAYk"]
[Thu Sep 17 15:04:55.827228 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:47774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/wp-includes/php-ai-client/src/Messages/"] [unique_id "aqxV9xFTPRVSLOsRVhrtOwAAAWw"]
[Thu Sep 17 15:04:55.853141 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/qa/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtPAAAAT8"]
[Thu Sep 17 15:04:55.917600 2026] [security2:error] [pid 955873:tid 956090] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/smtp/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtPwAAAWE"]
[Thu Sep 17 15:04:55.924828 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/preview/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtQwAAAS0"]
[Thu Sep 17 15:04:55.963758 2026] [security2:error] [pid 955873:tid 956059] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/qa/.env"] [unique_id "aqxV9xFTPRVSLOsRVhrtRAAAAUI"]
[Thu Sep 17 15:04:56.011718 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/beta/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtRwAAAUA"]
[Thu Sep 17 15:04:56.028913 2026] [security2:error] [pid 955873:tid 956065] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/Total-Soft-Calendar/CSS/totalsoft.css"] [unique_id "aqxV-BFTPRVSLOsRVhrtSAAAAUg"]
[Thu Sep 17 15:04:56.073207 2026] [security2:error] [pid 955873:tid 956022] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailing/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtSQAAAR0"]
[Thu Sep 17 15:04:56.091929 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/uat/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtSgAAAXM"]
[Thu Sep 17 15:04:56.144405 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/preview/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtSwAAAVw"]
[Thu Sep 17 15:04:56.147167 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtRQAAAYc"]
[Thu Sep 17 15:04:56.147186 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV9xFTPRVSLOsRVhrtRQAAAYc"]
[Thu Sep 17 15:04:56.208850 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/stage/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtTgAAATI"]
[Thu Sep 17 15:04:56.233616 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/notifications/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtUgAAASY"]
[Thu Sep 17 15:04:56.306752 2026] [security2:error] [pid 955873:tid 956017] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/beta/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtVgAAARg"]
[Thu Sep 17 15:04:56.313076 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/development/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtVwAAAXg"]
[Thu Sep 17 15:04:56.319637 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartChannelEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtWAAAAQo"]
[Thu Sep 17 15:04:56.319735 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:47774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartChannelEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtWAAAAQo"]
[Thu Sep 17 15:04:56.381030 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/production/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtWwAAAV8"]
[Thu Sep 17 15:04:56.391945 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/notify/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtXAAAASE"]
[Thu Sep 17 15:04:56.418905 2026] [core:error] [pid 955873:tid 956067] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:56.418920 2026] [core:error] [pid 955873:tid 956067] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:04:56.468369 2026] [security2:error] [pid 955873:tid 956097] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/uat/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtXgAAAWg"]
[Thu Sep 17 15:04:56.480063 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.224.217:40334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cobblehillstudio.net"] [uri "/config/app/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtXwAAATs"]
[Thu Sep 17 15:04:56.544709 2026] [security2:error] [pid 955873:tid 956102] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sender/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtYAAAAW0"]
[Thu Sep 17 15:04:56.608081 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.224.217:40334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtYQAAAR4"]
[Thu Sep 17 15:04:56.618920 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartTypeEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtYwAAAU0"]
[Thu Sep 17 15:04:56.618994 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessagePartTypeEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtYwAAAU0"]
[Thu Sep 17 15:04:56.631256 2026] [security2:error] [pid 955873:tid 956124] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/stage/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtZgAAAYM"]
[Thu Sep 17 15:04:56.665037 2026] [security2:error] [pid 955873:tid 955973] [remote 216.73.217.142:18291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxV-BFTPRVSLOsRVhrtaAABQWM"]
[Thu Sep 17 15:04:56.702828 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/campaign/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtawAAAX0"]
[Thu Sep 17 15:04:56.796838 2026] [security2:error] [pid 955873:tid 956021] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/development/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtbgAAARw"]
[Thu Sep 17 15:04:56.857047 2026] [security2:error] [pid 955873:tid 956109] [client 127.0.0.1:46532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxV-BFTPRVSLOsRVhrtcAAAAXQ"]
[Thu Sep 17 15:04:56.857055 2026] [security2:error] [pid 955873:tid 956083] [client 74.7.241.176:49614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wxv.noo.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxV-BFTPRVSLOsRVhrtbwAAAVo"]
[Thu Sep 17 15:04:56.858240 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/newsletter/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtcQAAAVU"]
[Thu Sep 17 15:04:56.898568 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:47790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessageRoleEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtcgAAAT4"]
[Thu Sep 17 15:04:56.898645 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:47790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/MessageRoleEnum.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtcgAAAT4"]
[Thu Sep 17 15:04:56.949895 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:40350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/info.php"] [unique_id "aqxV-BFTPRVSLOsRVhrtdAAAARs"]
[Thu Sep 17 15:04:56.958241 2026] [security2:error] [pid 955873:tid 956025] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/production/.env"] [unique_id "aqxV-BFTPRVSLOsRVhrtdgAAASA"]
[Thu Sep 17 15:04:57.010016 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/ses/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtegAAATQ"]
[Thu Sep 17 15:04:57.085773 2026] [security2:error] [pid 955873:tid 956080] [client 20.244.34.24:63582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtewAAAVc"], referer: binance.com
[Thu Sep 17 15:04:57.120787 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:34768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.eltitude.co"] [uri "/___proxy_subdomain_webmail/config/app/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtfAAAAWM"]
[Thu Sep 17 15:04:57.162639 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sendgrid/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtfQAAAXk"]
[Thu Sep 17 15:04:57.190828 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/ModalityEnum.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtfgAAAW4"]
[Thu Sep 17 15:04:57.190908 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Messages/Enums/ModalityEnum.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtfgAAAW4"]
[Thu Sep 17 15:04:57.296455 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/php.php"] [unique_id "aqxV-RFTPRVSLOsRVhrthwAAAYI"]
[Thu Sep 17 15:04:57.305521 2026] [security2:error] [pid 955873:tid 956056] [client 34.95.193.102:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php"] [unique_id "aqxV-RFTPRVSLOsRVhrthgAAAT8"]
[Thu Sep 17 15:04:57.315596 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/sparkpost/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtiAAAAQ4"]
[Thu Sep 17 15:04:57.451532 2026] [security2:error] [pid 955873:tid 956037] [client 216.73.163.56:45159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtiQAAASw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:57.467841 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-RFTPRVSLOsRVhrtjwAAAVw"]
[Thu Sep 17 15:04:57.470765 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/postmark/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtkQAAAYc"]
[Thu Sep 17 15:04:57.522607 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:40364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/i.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtlAAAAV4"]
[Thu Sep 17 15:04:57.560544 2026] [security2:error] [pid 955873:tid 956086] [client 85.208.98.197:18625] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/totop.min.js"] [unique_id "aqxV-RFTPRVSLOsRVhrtlQAAAV0"]
[Thu Sep 17 15:04:57.624770 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailgun/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtlwAAAUM"]
[Thu Sep 17 15:04:57.641536 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-RFTPRVSLOsRVhrtlgAAAXg"]
[Thu Sep 17 15:04:57.777191 2026] [security2:error] [pid 955873:tid 956068] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mandrill/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtoAAAAUs"]
[Thu Sep 17 15:04:57.779823 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/wp-includes/php-ai-client/src/"] [unique_id "aqxV-RFTPRVSLOsRVhrtogAAASQ"]
[Thu Sep 17 15:04:57.790050 2026] [security2:error] [pid 955873:tid 956088] [client 34.95.193.102:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/info.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtowAAAV8"]
[Thu Sep 17 15:04:57.795602 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/pi.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtpAAAASg"]
[Thu Sep 17 15:04:57.932498 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mailjet/.env"] [unique_id "aqxV-RFTPRVSLOsRVhrtqAAAAX0"]
[Thu Sep 17 15:04:58.023350 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtqgAAAVM"]
[Thu Sep 17 15:04:58.087085 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/brevo/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtrgAAAS8"]
[Thu Sep 17 15:04:58.091530 2026] [security2:error] [pid 955873:tid 956062] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/jquery/ui/core.min.js"] [unique_id "aqxV-hFTPRVSLOsRVhrtrwAAAUU"]
[Thu Sep 17 15:04:58.120073 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtpQAAAR8"]
[Thu Sep 17 15:04:58.120101 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-RFTPRVSLOsRVhrtpQAAAR8"]
[Thu Sep 17 15:04:58.122452 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/pinfo.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtsAAAAXQ"]
[Thu Sep 17 15:04:58.242761 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/transactional/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrttwAAAUw"]
[Thu Sep 17 15:04:58.251787 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtuAAAAXc"]
[Thu Sep 17 15:04:58.257987 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/"] [unique_id "aqxV-hFTPRVSLOsRVhrtugAAAS4"]
[Thu Sep 17 15:04:58.258108 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:62741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtuQAAAUE"]
[Thu Sep 17 15:04:58.258207 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:62741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtuQAAAUE"]
[Thu Sep 17 15:04:58.288251 2026] [security2:error] [pid 955873:tid 956005] [client 34.95.193.102:43868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/php.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtuwAAAQw"]
[Thu Sep 17 15:04:58.366987 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:41344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtvwAAATc"]
[Thu Sep 17 15:04:58.372910 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:41344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtvwAAATc"]
[Thu Sep 17 15:04:58.396433 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/bulk/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtwQAAAVc"]
[Thu Sep 17 15:04:58.400723 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.224.217:40386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/test.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtwgAAASc"]
[Thu Sep 17 15:04:58.412344 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/"] [unique_id "aqxV-hFTPRVSLOsRVhrtwAAAATY"]
[Thu Sep 17 15:04:58.493746 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtwwAAATo"]
[Thu Sep 17 15:04:58.549157 2026] [security2:error] [pid 955873:tid 956090] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/aws/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtxQAAAWE"]
[Thu Sep 17 15:04:58.593575 2026] [security2:error] [pid 955873:tid 956007] [client 216.73.163.43:41291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtxAAAAQ4"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:58.655681 2026] [security2:error] [pid 955873:tid 956050] [client 5.189.145.112:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-login.php"] [unique_id "aqxV-hFTPRVSLOsRVhrtyAAAATk"], referer: binance.com
[Thu Sep 17 15:04:58.697867 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-hFTPRVSLOsRVhrtyQAAAYE"]
[Thu Sep 17 15:04:58.711564 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/azure/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtzAAAAYc"]
[Thu Sep 17 15:04:58.722339 2026] [security2:error] [pid 955873:tid 956072] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrtzQAAAU8"]
[Thu Sep 17 15:04:58.778426 2026] [security2:error] [pid 955873:tid 956049] [client 34.95.193.102:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/i.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt1wAAATg"]
[Thu Sep 17 15:04:58.854252 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.224.217:40400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/p.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt2gAAASk"]
[Thu Sep 17 15:04:58.863779 2026] [security2:error] [pid 955873:tid 956087] [client 34.154.219.249:60958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/gcp/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrt3AAAAV4"]
[Thu Sep 17 15:04:58.940081 2026] [security2:error] [pid 955873:tid 956043] [client 216.73.163.57:51655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt3wAAATI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:58.949856 2026] [security2:error] [pid 955873:tid 956022] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "aqxV-hFTPRVSLOsRVhrt4wAAAR0"]
[Thu Sep 17 15:04:59.033144 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt2QAAASU"]
[Thu Sep 17 15:04:59.033166 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-hFTPRVSLOsRVhrt2QAAASU"]
[Thu Sep 17 15:04:59.138182 2026] [security2:error] [pid 955873:tid 956031] [client 45.169.98.18:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5gAAASY"]
[Thu Sep 17 15:04:59.138298 2026] [security2:error] [pid 955873:tid 956031] [client 45.169.98.18:50427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5gAAASY"]
[Thu Sep 17 15:04:59.175729 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:47802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/OperationInterface.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5wAAASg"]
[Thu Sep 17 15:04:59.175816 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:47802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Contracts/OperationInterface.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt5wAAASg"]
[Thu Sep 17 15:04:59.178250 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "aqxV-xFTPRVSLOsRVhrt6AAAATs"]
[Thu Sep 17 15:04:59.178799 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/debug.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt6QAAAVg"]
[Thu Sep 17 15:04:59.264989 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/pi.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt7AAAAXE"]
[Thu Sep 17 15:04:59.462949 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/"] [unique_id "aqxV-xFTPRVSLOsRVhrt8QAAAVo"]
[Thu Sep 17 15:04:59.513813 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.224.217:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt8gAAARU"]
[Thu Sep 17 15:04:59.616703 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/"] [unique_id "aqxV-xFTPRVSLOsRVhrt9QAAAXQ"]
[Thu Sep 17 15:04:59.669386 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:59299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt-wAAAWU"]
[Thu Sep 17 15:04:59.669459 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:59299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxV-xFTPRVSLOsRVhrt-wAAAWU"]
[Thu Sep 17 15:04:59.677869 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "aqxV-xFTPRVSLOsRVhrt_AAAAXc"]
[Thu Sep 17 15:04:59.696709 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cloud/.env"] [unique_id "aqxV-xFTPRVSLOsRVhrt_gAAAVU"]
[Thu Sep 17 15:04:59.756348 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.193.102:43888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/pinfo.php"] [unique_id "aqxV-xFTPRVSLOsRVhruAQAAAUU"]
[Thu Sep 17 15:04:59.760412 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:47804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV-xFTPRVSLOsRVhruAgAAASA"]
[Thu Sep 17 15:04:59.851580 2026] [security2:error] [pid 955873:tid 956115] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/infrastructure/.env"] [unique_id "aqxV-xFTPRVSLOsRVhruBgAAAXo"]
[Thu Sep 17 15:04:59.854073 2026] [security2:error] [pid 955873:tid 956071] [client 67.205.2.98:36740] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.luxelivinglv.com"] [uri "/"] [unique_id "aqxV-xFTPRVSLOsRVhruBwAAAU4"]
[Thu Sep 17 15:04:59.869071 2026] [security2:error] [pid 955873:tid 956091] [client 45.146.54.111:31707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV-xFTPRVSLOsRVhruBQAAAWI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:04:59.886827 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:40420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/test/phpinfo.php"] [unique_id "aqxV-xFTPRVSLOsRVhruCAAAATY"]
[Thu Sep 17 15:04:59.907561 2026] [security2:error] [pid 955873:tid 956093] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "aqxV-xFTPRVSLOsRVhruCgAAAWQ"]
[Thu Sep 17 15:05:00.008267 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/docker/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruCwAAAYc"]
[Thu Sep 17 15:05:00.042065 2026] [security2:error] [pid 955873:tid 956122] [client 67.205.2.98:36742] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.luxelivinglv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxV_BFTPRVSLOsRVhruDAAAAYE"]
[Thu Sep 17 15:05:00.094924 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-xFTPRVSLOsRVhruCQAAAX8"]
[Thu Sep 17 15:05:00.094944 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV-xFTPRVSLOsRVhruCQAAAX8"]
[Thu Sep 17 15:05:00.139091 2026] [security2:error] [pid 955873:tid 956034] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruDQAAASk"]
[Thu Sep 17 15:05:00.156089 2026] [security2:error] [pid 955873:tid 956043] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/Total-Soft-Calendar/JS/Total-Soft-Calendar-Widget.js"] [unique_id "aqxV_BFTPRVSLOsRVhruDgAAATI"]
[Thu Sep 17 15:05:00.161704 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/k8s/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruDwAAARg"]
[Thu Sep 17 15:05:00.162946 2026] [security2:error] [pid 955873:tid 956057] [client 104.28.198.244:22864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV_BFTPRVSLOsRVhruEAAAAUA"]
[Thu Sep 17 15:05:00.233814 2026] [security2:error] [pid 955873:tid 956026] [client 67.205.2.98:36758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.205.67.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.luxelivinglv.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruFgAAASE"]
[Thu Sep 17 15:05:00.239269 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:47804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/GenerativeAiOperation.php"] [unique_id "aqxV_BFTPRVSLOsRVhruFwAAASo"]
[Thu Sep 17 15:05:00.239344 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:47804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/DTO/GenerativeAiOperation.php"] [unique_id "aqxV_BFTPRVSLOsRVhruFwAAASo"]
[Thu Sep 17 15:05:00.260018 2026] [security2:error] [pid 955873:tid 956049] [client 34.95.193.102:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/test.php"] [unique_id "aqxV_BFTPRVSLOsRVhruGQAAATg"]
[Thu Sep 17 15:05:00.323860 2026] [security2:error] [pid 955873:tid 956016] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/kubernetes/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruGgAAARc"]
[Thu Sep 17 15:05:00.342315 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxV_BFTPRVSLOsRVhruGwAAAUM"]
[Thu Sep 17 15:05:00.356741 2026] [security2:error] [pid 955873:tid 956057] [client 104.28.198.244:22864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxV_BFTPRVSLOsRVhruEAAAAUA"]
[Thu Sep 17 15:05:00.370228 2026] [security2:error] [pid 955873:tid 956085] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruHQAAAVw"]
[Thu Sep 17 15:05:00.440637 2026] [security2:error] [pid 955873:tid 956042] [client 67.205.2.98:36768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.205.67.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.luxelivinglv.com"] [uri "/index.php/wp-json/batch/v1"] [unique_id "aqxV_BFTPRVSLOsRVhruHwAAATE"]
[Thu Sep 17 15:05:00.489312 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/terraform/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruIQAAASY"]
[Thu Sep 17 15:05:00.533076 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:46998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/"] [unique_id "aqxV_BFTPRVSLOsRVhruIwAAAXE"]
[Thu Sep 17 15:05:00.601840 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruJQAAAVk"]
[Thu Sep 17 15:05:00.649013 2026] [security2:error] [pid 955873:tid 956097] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/ansible/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruJgAAAWg"]
[Thu Sep 17 15:05:00.691324 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:40444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/old/phpinfo.php"] [unique_id "aqxV_BFTPRVSLOsRVhruKQAAARE"]
[Thu Sep 17 15:05:00.695566 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/"] [unique_id "aqxV_BFTPRVSLOsRVhruKAAAAWY"]
[Thu Sep 17 15:05:00.808246 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/.git/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruLwAAAXQ"]
[Thu Sep 17 15:05:00.828258 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/core/app/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruMQAAAWU"]
[Thu Sep 17 15:05:00.834739 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:46998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/wp-includes/php-ai-client/src/Operations/"] [unique_id "aqxV_BFTPRVSLOsRVhruMgAAAUw"]
[Thu Sep 17 15:05:00.963762 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/ci/.env"] [unique_id "aqxV_BFTPRVSLOsRVhruNwAAATc"]
[Thu Sep 17 15:05:00.982608 2026] [security2:error] [pid 955873:tid 956024] [client 34.95.193.102:43908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/p.php"] [unique_id "aqxV_BFTPRVSLOsRVhruOQAAAR8"]
[Thu Sep 17 15:05:01.013243 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.224.217:42612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxV_RFTPRVSLOsRVhruOgAAAVE"]
[Thu Sep 17 15:05:01.056893 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruOwAAAT4"]
[Thu Sep 17 15:05:01.120035 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/cd/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruPQAAAUY"]
[Thu Sep 17 15:05:01.211612 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruOAAAASA"]
[Thu Sep 17 15:05:01.211636 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruOAAAASA"]
[Thu Sep 17 15:05:01.276004 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/jenkins/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruQgAAASc"]
[Thu Sep 17 15:05:01.285602 2026] [security2:error] [pid 955873:tid 956056] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/private/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruQwAAAT8"]
[Thu Sep 17 15:05:01.347165 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:42616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/public/phpinfo.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRAAAAYk"]
[Thu Sep 17 15:05:01.348866 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:46998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/OperationStateEnum.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRQAAAQ4"]
[Thu Sep 17 15:05:01.348941 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:46998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Operations/Enums/OperationStateEnum.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRQAAAQ4"]
[Thu Sep 17 15:05:01.430773 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/gitlab/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruRgAAAU4"]
[Thu Sep 17 15:05:01.479437 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.193.102:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/debug.php"] [unique_id "aqxV_RFTPRVSLOsRVhruRwAAAV0"]
[Thu Sep 17 15:05:01.516309 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruSQAAAW8"]
[Thu Sep 17 15:05:01.585604 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/github/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruSgAAATY"]
[Thu Sep 17 15:05:01.625211 2026] [security2:error] [pid 955873:tid 956064] [client 108.88.72.220:41155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV_RFTPRVSLOsRVhruSAABRwo"], referer: https://www.google.com/
[Thu Sep 17 15:05:01.626258 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:47014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxV_RFTPRVSLOsRVhruSwAAAWQ"]
[Thu Sep 17 15:05:01.744826 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/bootstrap/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruTwAAASI"]
[Thu Sep 17 15:05:01.747230 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/actions/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruUgAAATU"]
[Thu Sep 17 15:05:01.768021 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.224.217:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/php-info.php"] [unique_id "aqxV_RFTPRVSLOsRVhruVAAAASw"]
[Thu Sep 17 15:05:01.825460 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxV_RFTPRVSLOsRVhruUwAAAS4"]
[Thu Sep 17 15:05:01.905602 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/circleci/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruWQAAATI"]
[Thu Sep 17 15:05:01.965032 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:47014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/wp-includes/php-ai-client/src/"] [unique_id "aqxV_RFTPRVSLOsRVhruWwAAASo"]
[Thu Sep 17 15:05:01.972837 2026] [security2:error] [pid 955873:tid 956072] [client 34.95.193.102:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/admin/phpinfo.php"] [unique_id "aqxV_RFTPRVSLOsRVhruXAAAAU8"]
[Thu Sep 17 15:05:01.974282 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "aqxV_RFTPRVSLOsRVhruXQAAATg"]
[Thu Sep 17 15:05:02.004408 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:42630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpversion.php"] [unique_id "aqxV_hFTPRVSLOsRVhruXgAAASE"]
[Thu Sep 17 15:05:02.062274 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/travis/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruXwAAAUM"]
[Thu Sep 17 15:05:02.202142 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruZQAAAV8"]
[Thu Sep 17 15:05:02.209509 2026] [security2:error] [pid 955873:tid 956098] [client 57.141.14.91:45032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "calgarytelephone.com"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruJAABaQE"]
[Thu Sep 17 15:05:02.215962 2026] [security2:error] [pid 955873:tid 956059] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/buildkite/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruZgAAAUI"]
[Thu Sep 17 15:05:02.219082 2026] [security2:error] [pid 955873:tid 956033] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/show-hide.min.js"] [unique_id "aqxV_hFTPRVSLOsRVhruZwAAASg"]
[Thu Sep 17 15:05:02.326787 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_hFTPRVSLOsRVhruYQAAAVw"]
[Thu Sep 17 15:05:02.326809 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_hFTPRVSLOsRVhruYQAAAVw"]
[Thu Sep 17 15:05:02.361085 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:42644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/_phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhruagAAAVg"]
[Thu Sep 17 15:05:02.369803 2026] [security2:error] [pid 955873:tid 956070] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mysql/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruawAAAU0"]
[Thu Sep 17 15:05:02.430213 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrubAAAATM"]
[Thu Sep 17 15:05:02.459969 2026] [security2:error] [pid 955873:tid 956102] [client 34.95.193.102:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/test/phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhrubQAAAW0"]
[Thu Sep 17 15:05:02.466596 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/AbstractProvider.php"] [unique_id "aqxV_hFTPRVSLOsRVhrubgAAAXs"]
[Thu Sep 17 15:05:02.466701 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:47014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/AbstractProvider.php"] [unique_id "aqxV_hFTPRVSLOsRVhrubgAAAXs"]
[Thu Sep 17 15:05:02.526419 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/postgres/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrubwAAAVk"]
[Thu Sep 17 15:05:02.649873 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:42656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/old_phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhrucQAAAWg"]
[Thu Sep 17 15:05:02.657668 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/var/www/html/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrucgAAARU"]
[Thu Sep 17 15:05:02.683164 2026] [security2:error] [pid 955873:tid 956124] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/mongodb/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrudQAAAYM"]
[Thu Sep 17 15:05:02.740741 2026] [security2:error] [pid 955873:tid 956065] [client 216.73.163.52:31047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxV_hFTPRVSLOsRVhrucwAAAUg"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:02.761732 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/"] [unique_id "aqxV_hFTPRVSLOsRVhruegAAAYQ"]
[Thu Sep 17 15:05:02.836638 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/redis/.env"] [unique_id "aqxV_hFTPRVSLOsRVhruewAAAUU"]
[Thu Sep 17 15:05:02.886666 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/current/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrufAAAAR8"]
[Thu Sep 17 15:05:02.932197 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/"] [unique_id "aqxV_hFTPRVSLOsRVhrufQAAAVE"]
[Thu Sep 17 15:05:02.950397 2026] [security2:error] [pid 955873:tid 956045] [client 34.95.193.102:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/dev/phpinfo.php"] [unique_id "aqxV_hFTPRVSLOsRVhrufgAAATQ"]
[Thu Sep 17 15:05:02.951401 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/server-info.php"] [unique_id "aqxV_hFTPRVSLOsRVhrufwAAATc"]
[Thu Sep 17 15:05:02.952193 2026] [security2:error] [pid 955873:tid 956080] [client 20.244.34.24:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxV_hFTPRVSLOsRVhrugAAAAVc"], referer: binance.com
[Thu Sep 17 15:05:02.990141 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/elasticsearch/.env"] [unique_id "aqxV_hFTPRVSLOsRVhrugwAAASc"]
[Thu Sep 17 15:05:03.078943 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:47016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxV_xFTPRVSLOsRVhruhwAAAYg"]
[Thu Sep 17 15:05:03.114816 2026] [security2:error] [pid 955873:tid 956038] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/release/.env"] [unique_id "aqxV_xFTPRVSLOsRVhruiAAAAS0"]
[Thu Sep 17 15:05:03.145602 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/rabbitmq/.env"] [unique_id "aqxV_xFTPRVSLOsRVhruiQAAAYI"]
[Thu Sep 17 15:05:03.305737 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/kafka/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrujgAAAUE"]
[Thu Sep 17 15:05:03.342097 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.224.217:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/server-status.php"] [unique_id "aqxV_xFTPRVSLOsRVhrukAAAAUc"]
[Thu Sep 17 15:05:03.343690 2026] [security2:error] [pid 955873:tid 956091] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/releases/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrujwAAAWI"]
[Thu Sep 17 15:05:03.415813 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhrujAAAAW8"]
[Thu Sep 17 15:05:03.415838 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhrujAAAAW8"]
[Thu Sep 17 15:05:03.450509 2026] [security2:error] [pid 955873:tid 956009] [client 108.88.72.220:50619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhrukQABEAM"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726005457&hideliu=1&hideminor=1&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:05:03.456167 2026] [security2:error] [pid 955873:tid 956093] [client 34.95.193.102:43950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/old/phpinfo.php"] [unique_id "aqxV_xFTPRVSLOsRVhrukwAAAWQ"]
[Thu Sep 17 15:05:03.464025 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/queue/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrulAAAAR4"]
[Thu Sep 17 15:05:03.486892 2026] [security2:error] [pid 955873:tid 956115] [client 47.79.206.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxV_xFTPRVSLOsRVhruigAAAXo"], referer: https://www.google.com/
[Thu Sep 17 15:05:03.559787 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:47016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModel.php"] [unique_id "aqxV_xFTPRVSLOsRVhrulgAAAX8"]
[Thu Sep 17 15:05:03.559873 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:47016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModel.php"] [unique_id "aqxV_xFTPRVSLOsRVhrulgAAAX8"]
[Thu Sep 17 15:05:03.570998 2026] [security2:error] [pid 955873:tid 956034] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/shared/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrumAAAASk"]
[Thu Sep 17 15:05:03.619141 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/worker/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrumgAAATI"]
[Thu Sep 17 15:05:03.772795 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/job/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrusgAAAYA"]
[Thu Sep 17 15:05:03.796232 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxV_xFTPRVSLOsRVhruswAAASg"]
[Thu Sep 17 15:05:03.798422 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/deploy/.env"] [unique_id "aqxV_xFTPRVSLOsRVhrutAAAATs"]
[Thu Sep 17 15:05:03.840037 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModelMetadataDirectory.php"] [unique_id "aqxV_xFTPRVSLOsRVhrutQAAAVw"]
[Thu Sep 17 15:05:03.840117 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModelMetadataDirectory.php"] [unique_id "aqxV_xFTPRVSLOsRVhrutQAAAVw"]
[Thu Sep 17 15:05:03.925742 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/test/.env"] [unique_id "aqxV_xFTPRVSLOsRVhruugAAASQ"]
[Thu Sep 17 15:05:03.945429 2026] [security2:error] [pid 955873:tid 956098] [client 34.95.193.102:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/tmp/phpinfo.php"] [unique_id "aqxV_xFTPRVSLOsRVhruuwAAAWk"]
[Thu Sep 17 15:05:04.003946 2026] [security2:error] [pid 955873:tid 956031] [client 185.55.149.49:61895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWABFTPRVSLOsRVhruvQAAASY"]
[Thu Sep 17 15:05:04.004025 2026] [security2:error] [pid 955873:tid 956031] [client 185.55.149.49:61895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWABFTPRVSLOsRVhruvQAAASY"]
[Thu Sep 17 15:05:04.026120 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/build/.env"] [unique_id "aqxWABFTPRVSLOsRVhruvgAAAVk"]
[Thu Sep 17 15:05:04.086030 2026] [security2:error] [pid 955873:tid 956095] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/qa/.env"] [unique_id "aqxWABFTPRVSLOsRVhruvwAAAWY"]
[Thu Sep 17 15:05:04.134000 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:47030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiProvider.php"] [unique_id "aqxWABFTPRVSLOsRVhruwAAAAVA"]
[Thu Sep 17 15:05:04.134083 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:47030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiProvider.php"] [unique_id "aqxWABFTPRVSLOsRVhruwAAAAVA"]
[Thu Sep 17 15:05:04.177750 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:42684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhruwQAAARE"]
[Thu Sep 17 15:05:04.242378 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/preview/.env"] [unique_id "aqxWABFTPRVSLOsRVhruyQAAARI"]
[Thu Sep 17 15:05:04.254944 2026] [security2:error] [pid 955873:tid 956021] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/dist/.env"] [unique_id "aqxWABFTPRVSLOsRVhruygAAARw"]
[Thu Sep 17 15:05:04.284490 2026] [security2:error] [pid 955873:tid 956083] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/jquery/jquery.min.js"] [unique_id "aqxWABFTPRVSLOsRVhruzAAAAVo"]
[Thu Sep 17 15:05:04.395274 2026] [security2:error] [pid 955873:tid 956094] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/beta/.env"] [unique_id "aqxWABFTPRVSLOsRVhruzwAAAWU"]
[Thu Sep 17 15:05:04.438574 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:47038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/"] [unique_id "aqxWABFTPRVSLOsRVhru0AAAAVM"]
[Thu Sep 17 15:05:04.448873 2026] [security2:error] [pid 955873:tid 956024] [client 34.95.193.102:40030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/public/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhru0QAAAR8"]
[Thu Sep 17 15:05:04.483849 2026] [security2:error] [pid 955873:tid 956080] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/public_html/.env"] [unique_id "aqxWABFTPRVSLOsRVhru0wAAAVc"]
[Thu Sep 17 15:05:04.530853 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:42698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhru1QAAATQ"]
[Thu Sep 17 15:05:04.535979 2026] [security2:error] [pid 955873:tid 956089] [client 216.73.163.50:52373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWABFTPRVSLOsRVhru1AAAAWA"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:04.558861 2026] [security2:error] [pid 955873:tid 956087] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/uat/.env"] [unique_id "aqxWABFTPRVSLOsRVhru1gAAAV4"]
[Thu Sep 17 15:05:04.605990 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/"] [unique_id "aqxWABFTPRVSLOsRVhru1wAAAW4"]
[Thu Sep 17 15:05:04.715997 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/htdocs/.env"] [unique_id "aqxWABFTPRVSLOsRVhru3AAAAYg"]
[Thu Sep 17 15:05:04.724079 2026] [security2:error] [pid 955873:tid 956119] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/stage/.env"] [unique_id "aqxWABFTPRVSLOsRVhru3QAAAX4"]
[Thu Sep 17 15:05:04.754336 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:47038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/"] [unique_id "aqxWABFTPRVSLOsRVhru3gAAAWw"]
[Thu Sep 17 15:05:04.844859 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:42706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWABFTPRVSLOsRVhru3wAAAS0"]
[Thu Sep 17 15:05:04.894200 2026] [security2:error] [pid 955873:tid 956012] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/development/.env"] [unique_id "aqxWABFTPRVSLOsRVhru4AAAARM"]
[Thu Sep 17 15:05:04.946187 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "aqxWABFTPRVSLOsRVhru5AAAAXk"]
[Thu Sep 17 15:05:05.049513 2026] [security2:error] [pid 955873:tid 956093] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/production/.env"] [unique_id "aqxWARFTPRVSLOsRVhru5gAAAWQ"]
[Thu Sep 17 15:05:05.087297 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWABFTPRVSLOsRVhru4QAAAW8"]
[Thu Sep 17 15:05:05.087314 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWABFTPRVSLOsRVhru4QAAAW8"]
[Thu Sep 17 15:05:05.091079 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.224.217:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWARFTPRVSLOsRVhru5wAAATU"]
[Thu Sep 17 15:05:05.173939 2026] [security2:error] [pid 955873:tid 956128] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "aqxWARFTPRVSLOsRVhru6AAAAYc"]
[Thu Sep 17 15:05:05.203310 2026] [security2:error] [pid 955873:tid 956112] [client 34.154.219.249:53294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ccrmediator.com"] [uri "/config/app/.env"] [unique_id "aqxWARFTPRVSLOsRVhru6wAAAXc"]
[Thu Sep 17 15:05:05.209309 2026] [security2:error] [pid 955873:tid 956111] [client 34.95.193.102:40044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/php-info.php"] [unique_id "aqxWARFTPRVSLOsRVhru7AAAAXY"]
[Thu Sep 17 15:05:05.224491 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:47038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/ApiBasedModelInterface.php"] [unique_id "aqxWARFTPRVSLOsRVhru7wAAASk"]
[Thu Sep 17 15:05:05.224556 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:47038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/ApiBasedModelInterface.php"] [unique_id "aqxWARFTPRVSLOsRVhru7wAAASk"]
[Thu Sep 17 15:05:05.359122 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.219.249:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php"] [unique_id "aqxWARFTPRVSLOsRVhru8AAAATY"]
[Thu Sep 17 15:05:05.401727 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/live/.env"] [unique_id "aqxWARFTPRVSLOsRVhru8gAAAUo"]
[Thu Sep 17 15:05:05.447075 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.224.217:42718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWARFTPRVSLOsRVhru9AAAASw"]
[Thu Sep 17 15:05:05.528823 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/GenerateTextApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru9gAAAXA"]
[Thu Sep 17 15:05:05.528902 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/GenerateTextApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru9gAAAXA"]
[Thu Sep 17 15:05:05.629864 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "aqxWARFTPRVSLOsRVhru9wAAAV8"]
[Thu Sep 17 15:05:05.701399 2026] [security2:error] [pid 955873:tid 956049] [client 34.95.193.102:40060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpversion.php"] [unique_id "aqxWARFTPRVSLOsRVhru-gAAATg"]
[Thu Sep 17 15:05:05.799408 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxWARFTPRVSLOsRVhru_AAAAVI"]
[Thu Sep 17 15:05:05.838742 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/ListModelsApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru_QAAAR0"]
[Thu Sep 17 15:05:05.838839 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:47062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/ListModelsApiBasedProviderAvailability.php"] [unique_id "aqxWARFTPRVSLOsRVhru_QAAAR0"]
[Thu Sep 17 15:05:05.848221 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.219.249:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/info.php"] [unique_id "aqxWARFTPRVSLOsRVhru_gAAAYA"]
[Thu Sep 17 15:05:05.862420 2026] [security2:error] [pid 955873:tid 956106] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "aqxWARFTPRVSLOsRVhru_wAAAXE"]
[Thu Sep 17 15:05:06.090280 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvAwAAASs"]
[Thu Sep 17 15:05:06.114049 2026] [security2:error] [pid 955873:tid 956116] [client 110.226.207.129:36024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvAQABeys"]
[Thu Sep 17 15:05:06.126073 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:42736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php.old"] [unique_id "aqxWAhFTPRVSLOsRVhrvBQAAASM"]
[Thu Sep 17 15:05:06.126094 2026] [security2:error] [pid 955873:tid 956107] [client 216.73.163.43:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvBAAAAXI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:06.140523 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:47078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/"] [unique_id "aqxWAhFTPRVSLOsRVhrvBgAAAWY"]
[Thu Sep 17 15:05:06.188202 2026] [security2:error] [pid 955873:tid 956031] [client 34.95.193.102:40066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/_phpinfo.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvBwAAASY"]
[Thu Sep 17 15:05:06.295950 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/"] [unique_id "aqxWAhFTPRVSLOsRVhrvCwAAARE"]
[Thu Sep 17 15:05:06.322013 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.219.249:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/php.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvDAAAARg"]
[Thu Sep 17 15:05:06.322475 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/opt/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvDQAAAX0"]
[Thu Sep 17 15:05:06.413964 2026] [security2:error] [pid 955873:tid 956015] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/link-prefetch.min.js"] [unique_id "aqxWAhFTPRVSLOsRVhrvEAAAARY"]
[Thu Sep 17 15:05:06.437676 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWAhFTPRVSLOsRVhrvEQAAAVo"]
[Thu Sep 17 15:05:06.474946 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.224.217:42740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php~"] [unique_id "aqxWAhFTPRVSLOsRVhrvEgAAARI"]
[Thu Sep 17 15:05:06.551625 2026] [security2:error] [pid 955873:tid 956125] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvFQAAAYQ"]
[Thu Sep 17 15:05:06.707056 2026] [security2:error] [pid 955873:tid 956094] [client 34.95.193.102:40078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/old_phpinfo.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvHAAAAWU"]
[Thu Sep 17 15:05:06.759952 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvFgAAAVM"]
[Thu Sep 17 15:05:06.759973 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvFgAAAVM"]
[Thu Sep 17 15:05:06.791637 2026] [security2:error] [pid 955873:tid 956099] [client 34.166.129.237:34024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/symfony/.env"] [unique_id "aqxWAhFTPRVSLOsRVhrvHgAAAWo"]
[Thu Sep 17 15:05:06.800636 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.219.249:56878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/i.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvHwAAAVE"]
[Thu Sep 17 15:05:06.899927 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ModelMetadataDirectoryInterface.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvIQAAAS0"]
[Thu Sep 17 15:05:06.900059 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ModelMetadataDirectoryInterface.php"] [unique_id "aqxWAhFTPRVSLOsRVhrvIQAAAS0"]
[Thu Sep 17 15:05:06.953580 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/info.php.bak"] [unique_id "aqxWAhFTPRVSLOsRVhrvJQAAAT8"]
[Thu Sep 17 15:05:07.194412 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:47080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderAvailabilityInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvKwAAAW8"]
[Thu Sep 17 15:05:07.194493 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:47080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderAvailabilityInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvKwAAAW8"]
[Thu Sep 17 15:05:07.197366 2026] [security2:error] [pid 955873:tid 956130] [client 34.95.193.102:40094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/server-info.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvLAAAAYk"]
[Thu Sep 17 15:05:07.210400 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/phpinfo.php.save"] [unique_id "aqxWAxFTPRVSLOsRVhrvLgAAAYI"]
[Thu Sep 17 15:05:07.274176 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.219.249:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/pi.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvLwAAAR4"]
[Thu Sep 17 15:05:07.488037 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMwAAAQs"]
[Thu Sep 17 15:05:07.488141 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMwAAAQs"]
[Thu Sep 17 15:05:07.497602 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:42772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvNAAAATI"]
[Thu Sep 17 15:05:07.506187 2026] [security2:error] [pid 955873:tid 956128] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/wordpress/.env"] [unique_id "aqxWAxFTPRVSLOsRVhrvNQAAAYc"]
[Thu Sep 17 15:05:07.696572 2026] [security2:error] [pid 955873:tid 956072] [client 34.95.193.102:40106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/server-status.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvOQAAAU8"]
[Thu Sep 17 15:05:07.749464 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:56890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/pinfo.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvOwAAASE"]
[Thu Sep 17 15:05:07.759961 2026] [security2:error] [pid 955873:tid 956068] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "aqxWAxFTPRVSLOsRVhrvPAAAAUs"]
[Thu Sep 17 15:05:07.776529 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderOperationsHandlerInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPQAAAXA"]
[Thu Sep 17 15:05:07.776605 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:47112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderOperationsHandlerInterface.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPQAAAXA"]
[Thu Sep 17 15:05:07.798382 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:42780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPgAAAXg"]
[Thu Sep 17 15:05:07.995139 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cms/.env"] [unique_id "aqxWAxFTPRVSLOsRVhrvQAAAASQ"]
[Thu Sep 17 15:05:08.009445 2026] [security2:error] [pid 955873:tid 956022] [client 159.146.33.234:3450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvPwABHTg"]
[Thu Sep 17 15:05:08.020967 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:42794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvQQAAAUA"]
[Thu Sep 17 15:05:08.062386 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:47116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderWithOperationsHandlerInterface.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvQgAAATs"]
[Thu Sep 17 15:05:08.062465 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:47116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Contracts/ProviderWithOperationsHandlerInterface.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvQgAAATs"]
[Thu Sep 17 15:05:08.230607 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/drupal/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrvRwAAASs"]
[Thu Sep 17 15:05:08.231150 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.219.249:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/test.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvSAAAATM"]
[Thu Sep 17 15:05:08.323329 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvTQAAAW0"]
[Thu Sep 17 15:05:08.358241 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:47118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/"] [unique_id "aqxWBBFTPRVSLOsRVhrvUQAAATE"]
[Thu Sep 17 15:05:08.418989 2026] [security2:error] [pid 955873:tid 956118] [client 216.24.219.38:42627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/000.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvUwAAAX0"]
[Thu Sep 17 15:05:08.464873 2026] [security2:error] [pid 955873:tid 956021] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/joomla/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrvVgAAARw"]
[Thu Sep 17 15:05:08.476543 2026] [security2:error] [pid 955873:tid 956109] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/Total-Soft-Calendar/CSS/Total-Soft-Calendar-Widget.css"] [unique_id "aqxWBBFTPRVSLOsRVhrvVwAAAXQ"]
[Thu Sep 17 15:05:08.510343 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/"] [unique_id "aqxWBBFTPRVSLOsRVhrvWQAAARY"]
[Thu Sep 17 15:05:08.515099 2026] [security2:error] [pid 955873:tid 956006] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "bajansoaps.com"] [uri "/index.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMgAAAQ0"]
[Thu Sep 17 15:05:08.515125 2026] [security2:error] [pid 955873:tid 956006] [client 74.7.175.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bajansoaps.com"] [uri "/index.php"] [unique_id "aqxWAxFTPRVSLOsRVhrvMgAAAQ0"]
[Thu Sep 17 15:05:08.517573 2026] [security2:error] [pid 955873:tid 956112] [client 74.7.175.191:32940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "bajansoaps.com"] [uri "/robots.txt"] [unique_id "aqxWAxFTPRVSLOsRVhrvMAABdzY"]
[Thu Sep 17 15:05:08.546100 2026] [security2:error] [pid 955873:tid 956054] [client 208.109.3.11:55984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bluetech.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvTgAAAXs"]
[Thu Sep 17 15:05:08.652195 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:47118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWBBFTPRVSLOsRVhrvWwAAAWU"]
[Thu Sep 17 15:05:08.664695 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:42810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvXAAAATQ"]
[Thu Sep 17 15:05:08.669570 2026] [security2:error] [pid 955873:tid 956099] [client 193.36.224.113:54553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/about.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvXgAAAWo"]
[Thu Sep 17 15:05:08.672313 2026] [security2:error] [pid 955873:tid 956074] [client 34.95.193.102:40120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWBBFTPRVSLOsRVhrvYAAAAVE"]
[Thu Sep 17 15:05:08.695248 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/magento/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrvaQAAAYg"]
[Thu Sep 17 15:05:08.863411 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdAAAAWk"]
[Thu Sep 17 15:05:08.863576 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:41908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdAAAAWk"]
[Thu Sep 17 15:05:08.870444 2026] [security2:error] [pid 955873:tid 956009] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bajansoaps.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvcgAAARA"], referer: https://bajansoaps.com/robots.txt
[Thu Sep 17 15:05:08.873082 2026] [security2:error] [pid 955873:tid 956119] [client 74.7.175.191:32952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bajansoaps.com"] [uri "/robots.txt"] [unique_id "aqxWBBFTPRVSLOsRVhrvbgABfkU"], referer: https://bajansoaps.com/robots.txt
[Thu Sep 17 15:05:08.891910 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:42820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/www/phpinfo.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdQAAAW8"]
[Thu Sep 17 15:05:08.908701 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.219.249:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/p.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdgAAAX8"]
[Thu Sep 17 15:05:08.918802 2026] [security2:error] [pid 955873:tid 956034] [client 193.36.224.148:37877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvdwAAASk"]
[Thu Sep 17 15:05:08.925116 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/shopify/.env"] [unique_id "aqxWBBFTPRVSLOsRVhrveAAAARo"]
[Thu Sep 17 15:05:08.964789 2026] [security2:error] [pid 955873:tid 956046] [client 20.244.34.24:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxWBBFTPRVSLOsRVhrveQAAATU"], referer: binance.com
[Thu Sep 17 15:05:08.974600 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvcAAAAQ4"]
[Thu Sep 17 15:05:08.974623 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBBFTPRVSLOsRVhrvcAAAAQ4"]
[Thu Sep 17 15:05:09.005523 2026] [security2:error] [pid 955873:tid 956126] [client 186.105.232.15:63317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvegAAAYU"]
[Thu Sep 17 15:05:09.005619 2026] [security2:error] [pid 955873:tid 956126] [client 186.105.232.15:63317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvegAAAYU"]
[Thu Sep 17 15:05:09.126871 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:47118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvfAAAAXU"]
[Thu Sep 17 15:05:09.126954 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:47118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvfAAAAXU"]
[Thu Sep 17 15:05:09.155771 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/prestashop/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrvfQAAATI"]
[Thu Sep 17 15:05:09.166058 2026] [security2:error] [pid 955873:tid 956047] [client 34.95.193.102:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/mail/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvfgAAATY"]
[Thu Sep 17 15:05:09.269085 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.224.217:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvgQAAASo"]
[Thu Sep 17 15:05:09.386547 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/codeigniter/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrvgwAAAVQ"]
[Thu Sep 17 15:05:09.387686 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/debug.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhAAAASE"]
[Thu Sep 17 15:05:09.407420 2026] [security2:error] [pid 955873:tid 956061] [client 193.36.224.113:56739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/about.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhQAAAUQ"]
[Thu Sep 17 15:05:09.417378 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:47124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderModelsMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhgAAAV8"]
[Thu Sep 17 15:05:09.417484 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:47124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/DTO/ProviderModelsMetadata.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvhgAAAV8"]
[Thu Sep 17 15:05:09.563760 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.224.217:42840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrviAAAARc"]
[Thu Sep 17 15:05:09.625387 2026] [security2:error] [pid 955873:tid 956091] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cakephp/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrviQAAAWI"]
[Thu Sep 17 15:05:09.658470 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvjAAAAS4"]
[Thu Sep 17 15:05:09.658642 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:50996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvjAAAAS4"]
[Thu Sep 17 15:05:09.671310 2026] [security2:error] [pid 955873:tid 956082] [client 216.24.219.104:42489] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvkAAAAVk"]
[Thu Sep 17 15:05:09.677389 2026] [security2:error] [pid 955873:tid 956075] [client 34.95.193.102:40142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvkQAAAVI"]
[Thu Sep 17 15:05:09.703450 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:47128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/"] [unique_id "aqxWBRFTPRVSLOsRVhrvkwAAATM"]
[Thu Sep 17 15:05:09.722136 2026] [security2:error] [pid 955873:tid 956005] [client 40.77.167.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.breathingboxing.org"] [uri "/index.php"] [unique_id "aqxV_BFTPRVSLOsRVhruNgAAAQw"]
[Thu Sep 17 15:05:09.821574 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/site/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvlQAAATg"]
[Thu Sep 17 15:05:09.855638 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/zend/.env"] [unique_id "aqxWBRFTPRVSLOsRVhrvlwAAARg"]
[Thu Sep 17 15:05:09.869121 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/"] [unique_id "aqxWBRFTPRVSLOsRVhrvlgAAARs"]
[Thu Sep 17 15:05:09.873196 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.219.249:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvmAAAASM"]
[Thu Sep 17 15:05:09.915160 2026] [security2:error] [pid 955873:tid 956118] [client 193.36.224.169:21963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-includes/hp2.php"] [unique_id "aqxWBRFTPRVSLOsRVhrvmQAAAX0"]
[Thu Sep 17 15:05:10.030865 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:47128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWBhFTPRVSLOsRVhrvnQAAAUU"]
[Thu Sep 17 15:05:10.087882 2026] [security2:error] [pid 955873:tid 956006] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/yii/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvoAAAAQ0"]
[Thu Sep 17 15:05:10.122677 2026] [security2:error] [pid 955873:tid 956108] [client 216.73.163.55:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvnwAAAXM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:10.131906 2026] [security2:error] [pid 955873:tid 956069] [client 34.23.224.217:42860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvogAAAUw"]
[Thu Sep 17 15:05:10.174051 2026] [security2:error] [pid 955873:tid 956033] [client 34.95.193.102:40152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvpQAAASg"]
[Thu Sep 17 15:05:10.299161 2026] [security2:error] [pid 955873:tid 956073] [client 115.244.164.14:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvqQAAAVA"]
[Thu Sep 17 15:05:10.299262 2026] [security2:error] [pid 955873:tid 956073] [client 115.244.164.14:59970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvqQAAAVA"]
[Thu Sep 17 15:05:10.318803 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/laravel5/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvqgAAAUE"]
[Thu Sep 17 15:05:10.350970 2026] [security2:error] [pid 955873:tid 956076] [client 34.154.219.249:39338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvqwAAAVM"]
[Thu Sep 17 15:05:10.351775 2026] [security2:error] [pid 955873:tid 956048] [client 193.36.224.149:50437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/bless.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvrAAAATc"]
[Thu Sep 17 15:05:10.359179 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvowAAAV4"]
[Thu Sep 17 15:05:10.359199 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvowAAAV4"]
[Thu Sep 17 15:05:10.428128 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:42862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvsgAAAWA"]
[Thu Sep 17 15:05:10.501608 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ProviderTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvtgAAAYU"]
[Thu Sep 17 15:05:10.501705 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ProviderTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvtgAAAYU"]
[Thu Sep 17 15:05:10.539124 2026] [security2:error] [pid 955873:tid 956050] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/classie.min.js"] [unique_id "aqxWBhFTPRVSLOsRVhrvtwAAATk"]
[Thu Sep 17 15:05:10.550029 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvuAAAAQs"]
[Thu Sep 17 15:05:10.583970 2026] [security2:error] [pid 955873:tid 956047] [client 193.36.224.167:46673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/goods.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvuQAAATY"]
[Thu Sep 17 15:05:10.672020 2026] [security2:error] [pid 955873:tid 956115] [client 34.95.193.102:40154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvugAAAXo"]
[Thu Sep 17 15:05:10.778412 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.224.217:42874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvvgAAASc"]
[Thu Sep 17 15:05:10.781252 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "aqxWBhFTPRVSLOsRVhrvvwAAATo"]
[Thu Sep 17 15:05:10.783353 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:38416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ToolTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwAAAASw"]
[Thu Sep 17 15:05:10.783562 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:38416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Enums/ToolTypeEnum.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwAAAASw"]
[Thu Sep 17 15:05:10.853538 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.219.249:39348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwQAAASE"]
[Thu Sep 17 15:05:10.905438 2026] [security2:error] [pid 955873:tid 956106] [client 216.24.219.104:39637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/blurbs.php"] [unique_id "aqxWBhFTPRVSLOsRVhrvwgAAAXE"]
[Thu Sep 17 15:05:11.016362 2026] [security2:error] [pid 955873:tid 956057] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/v3/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrvwwAAAUA"]
[Thu Sep 17 15:05:11.070636 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWBxFTPRVSLOsRVhrvxQAAAVI"]
[Thu Sep 17 15:05:11.098046 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.224.217:39326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/core/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrvxwAAAUM"]
[Thu Sep 17 15:05:11.106206 2026] [access_compat:error] [pid 955873:tid 956036] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/travel-mosaics-16-glorious-budapest
[Thu Sep 17 15:05:11.147052 2026] [security2:error] [pid 955873:tid 956107] [client 216.24.219.32:36777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxWBxFTPRVSLOsRVhrvyQAAAXI"]
[Thu Sep 17 15:05:11.182996 2026] [security2:error] [pid 955873:tid 956039] [client 34.95.193.102:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrvzAAAAS4"]
[Thu Sep 17 15:05:11.248334 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/v1/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrvzgAAAW0"]
[Thu Sep 17 15:05:11.283083 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWBxFTPRVSLOsRVhrvzQAAAVU"]
[Thu Sep 17 15:05:11.331232 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.219.249:39362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv0AAAAS8"]
[Thu Sep 17 15:05:11.417025 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cobblehillstudio.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv0QAAATg"]
[Thu Sep 17 15:05:11.426154 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWBxFTPRVSLOsRVhrv0gAAASM"]
[Thu Sep 17 15:05:11.479564 2026] [security2:error] [pid 955873:tid 956085] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/v2/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrv1AAAAVw"]
[Thu Sep 17 15:05:11.600735 2026] [security2:error] [pid 955873:tid 956062] [client 193.36.224.219:32861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/abcd.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv1wAAAUU"]
[Thu Sep 17 15:05:11.632473 2026] [security2:error] [pid 955873:tid 956083] [client 74.7.175.173:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.ncz.ihh.mybluehost.me"] [uri "/cgi-sys/404.html"] [unique_id "aqxWBxFTPRVSLOsRVhrv2QAAAVo"]
[Thu Sep 17 15:05:11.648251 2026] [security2:error] [pid 955873:tid 956109] [client 74.7.175.173:33612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.ncz.ihh.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWBxFTPRVSLOsRVhrv1gABdFA"]
[Thu Sep 17 15:05:11.667793 2026] [security2:error] [pid 955873:tid 956118] [client 34.95.193.102:40168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php.bak"] [unique_id "aqxWBxFTPRVSLOsRVhrv2gAAAX0"]
[Thu Sep 17 15:05:11.714539 2026] [security2:error] [pid 955873:tid 956095] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/rest/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrv3wAAAWY"]
[Thu Sep 17 15:05:11.744786 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv1QAAATs"]
[Thu Sep 17 15:05:11.744807 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv1QAAATs"]
[Thu Sep 17 15:05:11.818578 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.219.249:39368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv4wAAAXY"]
[Thu Sep 17 15:05:11.880990 2026] [security2:error] [pid 955873:tid 956045] [client 104.234.19.143:43675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxWBxFTPRVSLOsRVhrv5AAAATQ"]
[Thu Sep 17 15:05:11.887747 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/"] [unique_id "aqxWBxFTPRVSLOsRVhrv5gAAAYg"]
[Thu Sep 17 15:05:11.947269 2026] [security2:error] [pid 955873:tid 956101] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/graphql/.env"] [unique_id "aqxWBxFTPRVSLOsRVhrv6AAAAWw"]
[Thu Sep 17 15:05:12.045987 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/"] [unique_id "aqxWCBFTPRVSLOsRVhrv6gAAARI"]
[Thu Sep 17 15:05:12.150948 2026] [security2:error] [pid 955873:tid 956018] [client 34.95.193.102:40172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php.old"] [unique_id "aqxWCBFTPRVSLOsRVhrv8AAAARk"]
[Thu Sep 17 15:05:12.187322 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/gateway/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrv9QAAAWE"]
[Thu Sep 17 15:05:12.190465 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWCBFTPRVSLOsRVhrv9gAAAYk"]
[Thu Sep 17 15:05:12.291474 2026] [security2:error] [pid 955873:tid 956074] [client 192.178.6.4:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv-QAAAVE"]
[Thu Sep 17 15:05:12.292183 2026] [security2:error] [pid 955873:tid 956003] [client 34.154.219.249:39380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv-gAAAQo"]
[Thu Sep 17 15:05:12.433122 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/microservice/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrwAAAAAQ4"]
[Thu Sep 17 15:05:12.488121 2026] [security2:error] [pid 955873:tid 956008] [client 193.36.224.150:28791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/dex.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwAgAAAQ8"]
[Thu Sep 17 15:05:12.526642 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv_AAAARM"]
[Thu Sep 17 15:05:12.526676 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv_AAAARM"]
[Thu Sep 17 15:05:12.609185 2026] [security2:error] [pid 955873:tid 956122] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/demo1.min.js"] [unique_id "aqxWCBFTPRVSLOsRVhrwBAAAAYE"]
[Thu Sep 17 15:05:12.656638 2026] [security2:error] [pid 955873:tid 956092] [client 34.95.193.102:40178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php~"] [unique_id "aqxWCBFTPRVSLOsRVhrwBwAAAWM"]
[Thu Sep 17 15:05:12.666187 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/service/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrwCAAAATY"]
[Thu Sep 17 15:05:12.683082 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:38426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/AbstractClientDiscoveryStrategy.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwCQAAAU8"]
[Thu Sep 17 15:05:12.683158 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Abstracts/AbstractClientDiscoveryStrategy.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwCQAAAU8"]
[Thu Sep 17 15:05:12.836082 2026] [security2:error] [pid 955873:tid 956067] [client 216.24.219.103:35087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwEgAAAUo"]
[Thu Sep 17 15:05:12.909743 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/v3/.env"] [unique_id "aqxWCBFTPRVSLOsRVhrwFAAAAVQ"]
[Thu Sep 17 15:05:12.959920 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:38440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/"] [unique_id "aqxWCBFTPRVSLOsRVhrwGAAAAXE"]
[Thu Sep 17 15:05:12.980682 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.219.249:39384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/php-info.php"] [unique_id "aqxWCBFTPRVSLOsRVhrwGgAAAVI"]
[Thu Sep 17 15:05:13.142154 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/"] [unique_id "aqxWCRFTPRVSLOsRVhrwHQAAAS4"]
[Thu Sep 17 15:05:13.143672 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/dev/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwHgAAAW0"]
[Thu Sep 17 15:05:13.167129 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.193.102:40182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/info.php.bak"] [unique_id "aqxWCRFTPRVSLOsRVhrwHwAAAUM"]
[Thu Sep 17 15:05:13.167649 2026] [security2:error] [pid 955873:tid 956022] [client 216.24.219.97:20753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/css/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwIAAAAR0"]
[Thu Sep 17 15:05:13.324033 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:38440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWCRFTPRVSLOsRVhrwJAAAARs"]
[Thu Sep 17 15:05:13.376504 2026] [security2:error] [pid 955873:tid 956081] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/api/staging/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwJgAAAVg"]
[Thu Sep 17 15:05:13.443016 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.219.249:39398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpversion.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKQAAAU4"]
[Thu Sep 17 15:05:13.480586 2026] [security2:error] [pid 955873:tid 956083] [client 193.36.224.156:37887] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKwAAAVo"]
[Thu Sep 17 15:05:13.611849 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwLQAAATs"]
[Thu Sep 17 15:05:13.660817 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKgAAAWg"]
[Thu Sep 17 15:05:13.660844 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwKgAAAWg"]
[Thu Sep 17 15:05:13.669950 2026] [security2:error] [pid 955873:tid 956116] [client 34.95.193.102:40194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/phpinfo.php.save"] [unique_id "aqxWCRFTPRVSLOsRVhrwLgAAAXs"]
[Thu Sep 17 15:05:13.823650 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:38440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/HeadersCollection.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwMQAAAYg"]
[Thu Sep 17 15:05:13.823783 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:38440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Collections/HeadersCollection.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwMQAAAYg"]
[Thu Sep 17 15:05:13.844586 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/lib/.env"] [unique_id "aqxWCRFTPRVSLOsRVhrwMgAAAWU"]
[Thu Sep 17 15:05:13.885628 2026] [security2:error] [pid 955873:tid 956031] [client 20.244.34.24:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwMwAAASY"], referer: binance.com
[Thu Sep 17 15:05:13.912483 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.219.249:39404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/_phpinfo.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwNgAAAXY"]
[Thu Sep 17 15:05:14.040775 2026] [security2:error] [pid 955873:tid 956018] [client 216.24.219.103:49323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwOgAAARk"]
[Thu Sep 17 15:05:14.076234 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/resources/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwOwAAAWE"]
[Thu Sep 17 15:05:14.106494 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:38448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/"] [unique_id "aqxWChFTPRVSLOsRVhrwPAAAAVE"]
[Thu Sep 17 15:05:14.173706 2026] [security2:error] [pid 955873:tid 956009] [client 34.95.193.102:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/staging/phpinfo.php"] [unique_id "aqxWChFTPRVSLOsRVhrwPgAAARA"]
[Thu Sep 17 15:05:14.266241 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/"] [unique_id "aqxWChFTPRVSLOsRVhrwQQAAAXM"]
[Thu Sep 17 15:05:14.329958 2026] [security2:error] [pid 955873:tid 956046] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/assets/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwQwAAATU"]
[Thu Sep 17 15:05:14.395075 2026] [security2:error] [pid 955873:tid 956104] [client 34.154.219.249:39410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWChFTPRVSLOsRVhrwRgAAAW8"]
[Thu Sep 17 15:05:14.423204 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:38448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWChFTPRVSLOsRVhrwRwAAAXU"]
[Thu Sep 17 15:05:14.527239 2026] [security2:error] [pid 955873:tid 956120] [client 216.73.163.40:32879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWChFTPRVSLOsRVhrwSQAAAX8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:14.567274 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/uploads/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwSwAAAXA"]
[Thu Sep 17 15:05:14.672377 2026] [security2:error] [pid 955873:tid 956032] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/totop.min.js"] [unique_id "aqxWChFTPRVSLOsRVhrwTAAAASc"]
[Thu Sep 17 15:05:14.673137 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.193.102:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/beta/phpinfo.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTQAAAV0"]
[Thu Sep 17 15:05:14.735575 2026] [security2:error] [pid 955873:tid 956051] [client 216.24.219.101:29579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTgAAATo"]
[Thu Sep 17 15:05:14.737626 2026] [security2:error] [pid 955873:tid 956124] [client 185.55.149.49:62500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTwAAAYM"]
[Thu Sep 17 15:05:14.737732 2026] [security2:error] [pid 955873:tid 956124] [client 185.55.149.49:62500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWChFTPRVSLOsRVhrwTwAAAYM"]
[Thu Sep 17 15:05:14.755728 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwSgAAASo"]
[Thu Sep 17 15:05:14.755747 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwSgAAASo"]
[Thu Sep 17 15:05:14.803266 2026] [security2:error] [pid 955873:tid 956063] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.hendersonlife.info"] [uri "/index.php"] [unique_id "aqxWCBFTPRVSLOsRVhrv8QAAAUY"]
[Thu Sep 17 15:05:14.803647 2026] [security2:error] [pid 955873:tid 956077] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/internal/.env"] [unique_id "aqxWChFTPRVSLOsRVhrwVAAAAVQ"]
[Thu Sep 17 15:05:14.805148 2026] [security2:error] [pid 955873:tid 956055] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.hendersonlife.info"] [uri "/index.php"] [unique_id "aqxWCRFTPRVSLOsRVhrwLAAAAT4"], referer: http://mail.hendersonlife.info/api/session/properties
[Thu Sep 17 15:05:14.876924 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.219.249:39422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/server-info.php"] [unique_id "aqxWChFTPRVSLOsRVhrwVgAAASw"]
[Thu Sep 17 15:05:14.921387 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/ClientWithOptionsInterface.php"] [unique_id "aqxWChFTPRVSLOsRVhrwVwAAASs"]
[Thu Sep 17 15:05:14.921505 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/ClientWithOptionsInterface.php"] [unique_id "aqxWChFTPRVSLOsRVhrwVwAAASs"]
[Thu Sep 17 15:05:15.037365 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/tools/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwWAAAAUI"]
[Thu Sep 17 15:05:15.139058 2026] [security2:error] [pid 955873:tid 956030] [client 216.24.219.103:51063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwWQAAASU"]
[Thu Sep 17 15:05:15.170182 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.193.102:50748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/uat/phpinfo.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwWwAAAWs"]
[Thu Sep 17 15:05:15.182806 2026] [security2:error] [pid 955873:tid 956053] [client 216.73.163.62:48143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwWgAAATw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:15.198403 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/HttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwXAAAAQw"]
[Thu Sep 17 15:05:15.198499 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:38454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/HttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwXAAAAQw"]
[Thu Sep 17 15:05:15.267463 2026] [security2:error] [pid 955873:tid 956081] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/scripts/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwYAAAAVg"]
[Thu Sep 17 15:05:15.368437 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:39438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/server-status.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYQAAAVU"]
[Thu Sep 17 15:05:15.418488 2026] [security2:error] [pid 955873:tid 956028] [client 216.24.219.102:24413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/file.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYgAAASM"]
[Thu Sep 17 15:05:15.479569 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:38458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/RequestAuthenticationInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYwAAAS8"]
[Thu Sep 17 15:05:15.479673 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:38458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/RequestAuthenticationInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwYwAAAS8"]
[Thu Sep 17 15:05:15.499336 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/bin/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwZAAAAX0"]
[Thu Sep 17 15:05:15.653902 2026] [security2:error] [pid 955873:tid 956117] [client 34.95.193.102:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/qa/phpinfo.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwZQAAAXw"]
[Thu Sep 17 15:05:15.731413 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sbin/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwZwAAAXs"]
[Thu Sep 17 15:05:15.760081 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithHttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwagAAAUk"]
[Thu Sep 17 15:05:15.760176 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithHttpTransporterInterface.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwagAAAUk"]
[Thu Sep 17 15:05:15.909568 2026] [security2:error] [pid 955873:tid 956056] [client 216.73.163.36:48715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWCxFTPRVSLOsRVhrwbgAAAT8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:15.963866 2026] [security2:error] [pid 955873:tid 956018] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "aqxWCxFTPRVSLOsRVhrwcgAAARk"]
[Thu Sep 17 15:05:16.078510 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:38474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithRequestAuthenticationInterface.php"] [unique_id "aqxWDBFTPRVSLOsRVhrweQAAASg"]
[Thu Sep 17 15:05:16.078653 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:38474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Contracts/WithRequestAuthenticationInterface.php"] [unique_id "aqxWDBFTPRVSLOsRVhrweQAAASg"]
[Thu Sep 17 15:05:16.162742 2026] [security2:error] [pid 955873:tid 956025] [client 34.95.193.102:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/preview/phpinfo.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwegAAASA"]
[Thu Sep 17 15:05:16.198039 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwewAAAUc"]
[Thu Sep 17 15:05:16.227794 2026] [security2:error] [pid 955873:tid 956009] [client 49.13.167.123:36836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.geekngamer.com"] [uri "/index.html"] [unique_id "aqxWDBFTPRVSLOsRVhrwfAAAARA"], referer: http://www.geekngamer.com
[Thu Sep 17 15:05:16.252275 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.219.249:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWDBFTPRVSLOsRVhrwfwAAAQ4"]
[Thu Sep 17 15:05:16.374424 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:38476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/"] [unique_id "aqxWDBFTPRVSLOsRVhrwggAAAR8"]
[Thu Sep 17 15:05:16.432950 2026] [security2:error] [pid 955873:tid 956110] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/dashboard/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwgwAAAXU"]
[Thu Sep 17 15:05:16.488702 2026] [security2:error] [pid 955873:tid 956112] [client 65.111.15.248:19041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.enduringwanderlust.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrweAAAAXc"]
[Thu Sep 17 15:05:16.542779 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/"] [unique_id "aqxWDBFTPRVSLOsRVhrwhgAAAU0"]
[Thu Sep 17 15:05:16.662311 2026] [security2:error] [pid 955873:tid 956128] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/panel/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwigAAAYc"]
[Thu Sep 17 15:05:16.688809 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:38476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWDBFTPRVSLOsRVhrwiwAAAU8"]
[Thu Sep 17 15:05:16.728076 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.219.249:39452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwjgAAAXk"]
[Thu Sep 17 15:05:16.733992 2026] [security2:error] [pid 955873:tid 956088] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/trigger.min.js"] [unique_id "aqxWDBFTPRVSLOsRVhrwkAAAAV8"]
[Thu Sep 17 15:05:16.791774 2026] [security2:error] [pid 955873:tid 956080] [client 20.244.34.24:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwlwAAAVc"], referer: binance.com
[Thu Sep 17 15:05:16.836734 2026] [security2:error] [pid 955873:tid 956087] [client 66.249.66.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grieveonpurpose.com"] [uri "/index.php"] [unique_id "aqxWChFTPRVSLOsRVhrwRAAAAV4"]
[Thu Sep 17 15:05:16.841912 2026] [security2:error] [pid 955873:tid 956061] [client 193.36.224.168:28343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwmgAAAUQ"]
[Thu Sep 17 15:05:16.892309 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "aqxWDBFTPRVSLOsRVhrwmwAAAVk"]
[Thu Sep 17 15:05:16.962497 2026] [security2:error] [pid 955873:tid 956016] [client 34.95.193.102:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/www/phpinfo.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwnAAAARc"]
[Thu Sep 17 15:05:16.965291 2026] [security2:error] [pid 955873:tid 956062] [client 85.208.98.197:44667] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/comment-reply.min.js"] [unique_id "aqxWDBFTPRVSLOsRVhrwnQAAAUU"]
[Thu Sep 17 15:05:17.037004 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwmQAAAWI"]
[Thu Sep 17 15:05:17.037029 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwmQAAAWI"]
[Thu Sep 17 15:05:17.124556 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/erp/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwoAAAAS4"]
[Thu Sep 17 15:05:17.171762 2026] [security2:error] [pid 955873:tid 956107] [client 45.190.220.230:12947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwngABcmM"]
[Thu Sep 17 15:05:17.175648 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/ApiKeyRequestAuthentication.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwoQAAAUo"]
[Thu Sep 17 15:05:17.175781 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:38476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/ApiKeyRequestAuthentication.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwoQAAAUo"]
[Thu Sep 17 15:05:17.197551 2026] [security2:error] [pid 955873:tid 956084] [client 216.24.219.103:40327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-mail.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwogAAAVs"]
[Thu Sep 17 15:05:17.226296 2026] [security2:error] [pid 955873:tid 956041] [client 34.154.219.249:39468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwowAAATA"]
[Thu Sep 17 15:05:17.364375 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/shop/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwqAAAAW4"]
[Thu Sep 17 15:05:17.457141 2026] [security2:error] [pid 955873:tid 956030] [client 34.95.193.102:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwqQAAASU"]
[Thu Sep 17 15:05:17.458344 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:38478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Request.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwqgAAASM"]
[Thu Sep 17 15:05:17.458430 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:38478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Request.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwqgAAASM"]
[Thu Sep 17 15:05:17.597109 2026] [security2:error] [pid 955873:tid 956125] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/store/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwrAAAAYQ"]
[Thu Sep 17 15:05:17.704775 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.219.249:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrQAAAXQ"]
[Thu Sep 17 15:05:17.727889 2026] [security2:error] [pid 955873:tid 956066] [client 216.24.219.104:42769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/ioxi-o.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrgAAAUk"]
[Thu Sep 17 15:05:17.736414 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:38480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/RequestOptions.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrwAAAVA"]
[Thu Sep 17 15:05:17.736492 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:38480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/RequestOptions.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwrwAAAVA"]
[Thu Sep 17 15:05:17.830723 2026] [security2:error] [pid 955873:tid 956018] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/saas/.env"] [unique_id "aqxWDRFTPRVSLOsRVhrwtAAAARk"]
[Thu Sep 17 15:05:17.934111 2026] [security2:error] [pid 955873:tid 956085] [client 45.146.54.106:28263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwtQAAAVw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:17.955813 2026] [security2:error] [pid 955873:tid 956056] [client 34.95.193.102:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwtgAAAT8"]
[Thu Sep 17 15:05:17.974300 2026] [security2:error] [pid 955873:tid 956033] [client 216.24.219.36:25473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxWDRFTPRVSLOsRVhrwtwAAASg"]
[Thu Sep 17 15:05:18.018247 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:38482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Response.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuAAAAT0"]
[Thu Sep 17 15:05:18.018328 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:38482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/DTO/Response.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuAAAAT0"]
[Thu Sep 17 15:05:18.045978 2026] [security2:error] [pid 955873:tid 956130] [client 162.241.226.11:20026] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "reedcustomprinting.com"] [uri "/wp-cron.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuQAAAYk"]
[Thu Sep 17 15:05:18.051801 2026] [security2:error] [pid 955873:tid 956106] [client 4.240.114.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxWDBFTPRVSLOsRVhrwlQAAAXE"], referer: binance.com
[Thu Sep 17 15:05:18.066242 2026] [security2:error] [pid 955873:tid 956074] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/client/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwugAAAVE"]
[Thu Sep 17 15:05:18.124523 2026] [security2:error] [pid 955873:tid 956044] [client 194.163.128.162:49844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwuwAAATM"], referer: binance.com
[Thu Sep 17 15:05:18.191523 2026] [security2:error] [pid 955873:tid 956079] [client 34.154.219.249:39500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwvAAAAVY"]
[Thu Sep 17 15:05:18.304933 2026] [security2:error] [pid 955873:tid 956096] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/project/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwwAAAAWc"]
[Thu Sep 17 15:05:18.313874 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:38496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/"] [unique_id "aqxWDhFTPRVSLOsRVhrwwQAAASI"]
[Thu Sep 17 15:05:18.472954 2026] [security2:error] [pid 955873:tid 956008] [client 34.95.193.102:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/site/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwxAAAAQ8"]
[Thu Sep 17 15:05:18.478837 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/"] [unique_id "aqxWDhFTPRVSLOsRVhrwwwAAAW8"]
[Thu Sep 17 15:05:18.533280 2026] [security2:error] [pid 955873:tid 956127] [client 216.24.219.88:27027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/style.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwxQAAAYY"]
[Thu Sep 17 15:05:18.543411 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/admin-panel/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwxgAAAXc"]
[Thu Sep 17 15:05:18.622086 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:38496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWDhFTPRVSLOsRVhrwyAAAARI"]
[Thu Sep 17 15:05:18.651087 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.219.249:39512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwyQAAAYE"]
[Thu Sep 17 15:05:18.778580 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/control-panel/.env"] [unique_id "aqxWDhFTPRVSLOsRVhrwzQAAATY"]
[Thu Sep 17 15:05:18.800049 2026] [security2:error] [pid 955873:tid 956128] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/modernizr.custom.min.js"] [unique_id "aqxWDhFTPRVSLOsRVhrwzgAAAYc"]
[Thu Sep 17 15:05:18.872193 2026] [security2:error] [pid 955873:tid 956086] [client 193.36.224.226:34873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/style.php"] [unique_id "aqxWDhFTPRVSLOsRVhrw0AAAAV0"]
[Thu Sep 17 15:05:18.951952 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwzAAAAWA"]
[Thu Sep 17 15:05:18.951974 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWDhFTPRVSLOsRVhrwzAAAAWA"]
[Thu Sep 17 15:05:18.983326 2026] [security2:error] [pid 955873:tid 956115] [client 34.95.193.102:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/docs/phpinfo.php"] [unique_id "aqxWDhFTPRVSLOsRVhrw0QAAAXo"]
[Thu Sep 17 15:05:19.013671 2026] [security2:error] [pid 955873:tid 956080] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/user-panel/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw1AAAAVc"]
[Thu Sep 17 15:05:19.039922 2026] [security2:error] [pid 955873:tid 956068] [client 85.208.98.197:44667] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/akismet/_inc/akismet-frontend.js"] [unique_id "aqxWDxFTPRVSLOsRVhrw1QAAAUs"]
[Thu Sep 17 15:05:19.100377 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/HttpMethodEnum.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw1wAAATE"]
[Thu Sep 17 15:05:19.100482 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/HttpMethodEnum.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw1wAAATE"]
[Thu Sep 17 15:05:19.144463 2026] [security2:error] [pid 955873:tid 956051] [client 34.154.219.249:39524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWDxFTPRVSLOsRVhrw2AAAATo"]
[Thu Sep 17 15:05:19.249822 2026] [security2:error] [pid 955873:tid 956062] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/node/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw3QAAAUU"]
[Thu Sep 17 15:05:19.351604 2026] [security2:error] [pid 955873:tid 956102] [client 146.190.145.25:56998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "greenbrickbuilders.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWDxFTPRVSLOsRVhrw3wAAAW0"]
[Thu Sep 17 15:05:19.405887 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:38498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/RequestAuthenticationMethod.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4AAAAXI"]
[Thu Sep 17 15:05:19.405980 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:38498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Enums/RequestAuthenticationMethod.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4AAAAXI"]
[Thu Sep 17 15:05:19.413236 2026] [security2:error] [pid 955873:tid 956084] [client 104.234.19.146:64915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/themes/style.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4QAAAVs"]
[Thu Sep 17 15:05:19.452164 2026] [security2:error] [pid 955873:tid 956063] [client 146.190.145.25:57004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "greenbrickbuilders.com"] [uri "/"] [unique_id "aqxWDxFTPRVSLOsRVhrw4gAAAUY"]
[Thu Sep 17 15:05:19.471647 2026] [security2:error] [pid 955873:tid 956039] [client 34.95.193.102:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw4wAAAS4"]
[Thu Sep 17 15:05:19.481598 2026] [security2:error] [pid 955873:tid 956032] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/express/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw5AAAASc"]
[Thu Sep 17 15:05:19.551007 2026] [security2:error] [pid 955873:tid 956103] [client 146.190.145.25:57014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "greenbrickbuilders.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWDxFTPRVSLOsRVhrw5QAAAW4"]
[Thu Sep 17 15:05:19.627050 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.219.249:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWDxFTPRVSLOsRVhrw6AAAAQw"]
[Thu Sep 17 15:05:19.680277 2026] [security2:error] [pid 955873:tid 956060] [client 216.24.219.20:35539] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-editor.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw6gAAAUM"]
[Thu Sep 17 15:05:19.687967 2026] [security2:error] [pid 955873:tid 956113] [client 154.190.208.131:42481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw6wAAAXg"]
[Thu Sep 17 15:05:19.688068 2026] [security2:error] [pid 955873:tid 956113] [client 154.190.208.131:42481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw6wAAAXg"]
[Thu Sep 17 15:05:19.693567 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:38500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/"] [unique_id "aqxWDxFTPRVSLOsRVhrw7AAAAQ0"]
[Thu Sep 17 15:05:19.716247 2026] [security2:error] [pid 955873:tid 956026] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/next/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw7QAAASE"]
[Thu Sep 17 15:05:19.858017 2026] [security2:error] [pid 955873:tid 956118] [client 14.186.236.226:64111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw8AABfW4"]
[Thu Sep 17 15:05:19.867306 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/"] [unique_id "aqxWDxFTPRVSLOsRVhrw8gAAATs"]
[Thu Sep 17 15:05:19.913033 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw8wAAAU4"]
[Thu Sep 17 15:05:19.913128 2026] [security2:error] [pid 955873:tid 956071] [client 186.105.232.15:63905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw8wAAAU4"]
[Thu Sep 17 15:05:19.951710 2026] [security2:error] [pid 955873:tid 956109] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/nuxt/.env"] [unique_id "aqxWDxFTPRVSLOsRVhrw9AAAAXQ"]
[Thu Sep 17 15:05:19.955301 2026] [security2:error] [pid 955873:tid 956125] [client 34.95.193.102:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWDxFTPRVSLOsRVhrw9QAAAYQ"]
[Thu Sep 17 15:05:20.013140 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:38500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWEBFTPRVSLOsRVhrw9gAAASQ"]
[Thu Sep 17 15:05:20.114419 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php~"] [unique_id "aqxWEBFTPRVSLOsRVhrw9wAAAUw"]
[Thu Sep 17 15:05:20.116492 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-AAAAUk"]
[Thu Sep 17 15:05:20.116572 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:51559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-AAAAUk"]
[Thu Sep 17 15:05:20.162214 2026] [security2:error] [pid 955873:tid 956056] [client 216.24.219.20:57117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/lufix.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-gAAAT8"]
[Thu Sep 17 15:05:20.185725 2026] [security2:error] [pid 955873:tid 956097] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/nest/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrw-wAAAWg"]
[Thu Sep 17 15:05:20.338287 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-QAAAVw"]
[Thu Sep 17 15:05:20.338310 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw-QAAAVw"]
[Thu Sep 17 15:05:20.369161 2026] [security2:error] [pid 955873:tid 956031] [client 216.73.163.57:39229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrw_wAAASY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:20.417674 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/react/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrxAAAAAT4"]
[Thu Sep 17 15:05:20.444179 2026] [security2:error] [pid 955873:tid 956106] [client 34.95.193.102:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/core/phpinfo.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxAwAAAXE"]
[Thu Sep 17 15:05:20.481074 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:38500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ClientException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxBAAAAUc"]
[Thu Sep 17 15:05:20.481156 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:38500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ClientException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxBAAAAUc"]
[Thu Sep 17 15:05:20.606190 2026] [security2:error] [pid 955873:tid 956003] [client 34.154.219.249:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/info.php.bak"] [unique_id "aqxWEBFTPRVSLOsRVhrxBgAAAQo"]
[Thu Sep 17 15:05:20.657617 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/vue/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrxBwAAAR8"]
[Thu Sep 17 15:05:20.718654 2026] [security2:error] [pid 955873:tid 956110] [client 162.241.226.11:43422] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxCQAAAXU"]
[Thu Sep 17 15:05:20.757446 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/NetworkException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxCgAAAYY"]
[Thu Sep 17 15:05:20.757534 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/NetworkException.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxCgAAAYY"]
[Thu Sep 17 15:05:20.821124 2026] [security2:error] [pid 955873:tid 956012] [client 115.244.164.14:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxDgAAARM"]
[Thu Sep 17 15:05:20.824868 2026] [security2:error] [pid 955873:tid 956012] [client 115.244.164.14:60630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxDgAAARM"]
[Thu Sep 17 15:05:20.862567 2026] [security2:error] [pid 955873:tid 956046] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/themes/journey/js/responsive-menu.min.js"] [unique_id "aqxWEBFTPRVSLOsRVhrxEAAAATU"]
[Thu Sep 17 15:05:20.895553 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/angular/.env"] [unique_id "aqxWEBFTPRVSLOsRVhrxEgAAAQs"]
[Thu Sep 17 15:05:20.918436 2026] [security2:error] [pid 955873:tid 956128] [client 216.24.219.21:27637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/txets.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxEwAAAYc"]
[Thu Sep 17 15:05:20.956671 2026] [security2:error] [pid 955873:tid 956122] [client 40.77.167.93:7810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.chriswestlake.com"] [uri "/index.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxEQABgXU"]
[Thu Sep 17 15:05:20.960527 2026] [security2:error] [pid 955873:tid 956034] [client 34.95.193.102:50870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.eltitude.co"] [uri "/includes/phpinfo.php"] [unique_id "aqxWEBFTPRVSLOsRVhrxFAAAASk"]
[Thu Sep 17 15:05:21.039843 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/RedirectException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxFQAAAS0"]
[Thu Sep 17 15:05:21.039955 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/RedirectException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxFQAAAS0"]
[Thu Sep 17 15:05:21.101353 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.219.249:56310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWERFTPRVSLOsRVhrxFgAAAWA"]
[Thu Sep 17 15:05:21.128521 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/svelte/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxGAAAATE"]
[Thu Sep 17 15:05:21.296601 2026] [security2:error] [pid 955873:tid 956088] [client 216.24.219.100:40273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxWERFTPRVSLOsRVhrxHgAAAV8"]
[Thu Sep 17 15:05:21.328876 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:45610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ResponseException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxHwAAATI"]
[Thu Sep 17 15:05:21.328967 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:45610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ResponseException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxHwAAATI"]
[Thu Sep 17 15:05:21.361066 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/vite/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxIAAAASs"]
[Thu Sep 17 15:05:21.392383 2026] [security2:error] [pid 955873:tid 956114] [client 85.208.98.197:44667] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxWERFTPRVSLOsRVhrxFwAAAXk"]
[Thu Sep 17 15:05:21.423375 2026] [authz_core:error] [pid 955873:tid 956075] [client 4.240.114.86:56504] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:05:21.569878 2026] [security2:error] [pid 955873:tid 956059] [client 34.154.219.249:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWERFTPRVSLOsRVhrxJAAAAUI"]
[Thu Sep 17 15:05:21.596722 2026] [security2:error] [pid 955873:tid 956084] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxJQAAAVs"]
[Thu Sep 17 15:05:21.750939 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:45616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ServerException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxKQAAAS4"]
[Thu Sep 17 15:05:21.751014 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:45616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Exception/ServerException.php"] [unique_id "aqxWERFTPRVSLOsRVhrxKQAAAS4"]
[Thu Sep 17 15:05:21.828627 2026] [security2:error] [pid 955873:tid 956022] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/backups/.env"] [unique_id "aqxWERFTPRVSLOsRVhrxLwAAAR0"]
[Thu Sep 17 15:05:22.008986 2026] [security2:error] [pid 955873:tid 956095] [client 193.36.224.212:55615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-admin/txets.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMQAAAWY"]
[Thu Sep 17 15:05:22.042087 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:45622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporter.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMgAAAXw"]
[Thu Sep 17 15:05:22.042166 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:45622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporter.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMgAAAXw"]
[Thu Sep 17 15:05:22.050589 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.219.249:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxMwAAAUM"]
[Thu Sep 17 15:05:22.063171 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxNAAAAU4"]
[Thu Sep 17 15:05:22.295028 2026] [security2:error] [pid 955873:tid 956020] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/tmp/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxOQAAARs"]
[Thu Sep 17 15:05:22.330794 2026] [security2:error] [pid 955873:tid 956048] [client 104.234.19.143:50819] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-includes/txets.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxOwAAATc"]
[Thu Sep 17 15:05:22.340502 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporterFactory.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxPAAAAWE"]
[Thu Sep 17 15:05:22.340572 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:45634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/HttpTransporterFactory.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxPAAAAWE"]
[Thu Sep 17 15:05:22.529352 2026] [security2:error] [pid 955873:tid 956097] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/temp/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxPgAAAWg"]
[Thu Sep 17 15:05:22.534414 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxPwAAAUw"]
[Thu Sep 17 15:05:22.589392 2026] [security2:error] [pid 955873:tid 956031] [client 20.244.34.24:62505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxQAAAASY"], referer: binance.com
[Thu Sep 17 15:05:22.621818 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:45640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/"] [unique_id "aqxWEhFTPRVSLOsRVhrxQgAAAUc"]
[Thu Sep 17 15:05:22.735251 2026] [security2:error] [pid 955873:tid 956033] [client 216.24.219.100:46229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/goods.php"] [unique_id "aqxWEhFTPRVSLOsRVhrxRQAAASg"]
[Thu Sep 17 15:05:22.763761 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/lab/.env"] [unique_id "aqxWEhFTPRVSLOsRVhrxRgAAARA"]
[Thu Sep 17 15:05:22.792782 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/"] [unique_id "aqxWEhFTPRVSLOsRVhrxRwAAAVY"]
[Thu Sep 17 15:05:22.930777 2026] [security2:error] [pid 955873:tid 956104] [client 85.208.98.202:31804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "aqxWEhFTPRVSLOsRVhrxSQAAAW8"]
[Thu Sep 17 15:05:22.933568 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:45640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWEhFTPRVSLOsRVhrxSwAAAVM"]
[Thu Sep 17 15:05:23.003897 2026] [security2:error] [pid 955873:tid 956010] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cronlab/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxTQAAARE"]
[Thu Sep 17 15:05:23.011058 2026] [security2:error] [pid 955873:tid 956019] [client 216.24.219.20:63647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/php8.php"] [unique_id "aqxWExFTPRVSLOsRVhrxTgAAARo"]
[Thu Sep 17 15:05:23.028754 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.219.249:56354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWExFTPRVSLOsRVhrxTwAAAVE"]
[Thu Sep 17 15:05:23.159001 2026] [security2:error] [pid 955873:tid 956127] [client 40.77.167.136:5692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.chriswestlake.com"] [uri "/index.php"] [unique_id "aqxWExFTPRVSLOsRVhrxUgABhno"]
[Thu Sep 17 15:05:23.168288 2026] [autoindex:error] [pid 955873:tid 956008] [client 34.178.167.214:53054] AH01276: Cannot serve directory /home1/gscqjxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:23.252649 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cron/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxVAAAATY"]
[Thu Sep 17 15:05:23.265279 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWExFTPRVSLOsRVhrxUAAAAYU"]
[Thu Sep 17 15:05:23.265304 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWExFTPRVSLOsRVhrxUAAAAYU"]
[Thu Sep 17 15:05:23.405162 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:45640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithHttpTransporterTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxWgAAARI"]
[Thu Sep 17 15:05:23.405239 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:45640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithHttpTransporterTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxWgAAARI"]
[Thu Sep 17 15:05:23.487818 2026] [security2:error] [pid 955873:tid 956065] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/en/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxXAAAAUg"]
[Thu Sep 17 15:05:23.499275 2026] [security2:error] [pid 955873:tid 956086] [client 34.154.219.249:56360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWExFTPRVSLOsRVhrxXgAAAV0"]
[Thu Sep 17 15:05:23.582417 2026] [security2:error] [pid 955873:tid 956082] [client 127.0.0.1:16106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxWExFTPRVSLOsRVhrxYAAAAVk"]
[Thu Sep 17 15:05:23.582535 2026] [security2:error] [pid 955873:tid 956042] [client 74.7.228.39:37526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.pazcreativehomes.com"] [uri "/robots.txt"] [unique_id "aqxWExFTPRVSLOsRVhrxXwABMXw"]
[Thu Sep 17 15:05:23.682565 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:45646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithRequestAuthenticationTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxZQAAAUE"]
[Thu Sep 17 15:05:23.682985 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:45646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Traits/WithRequestAuthenticationTrait.php"] [unique_id "aqxWExFTPRVSLOsRVhrxZQAAAUE"]
[Thu Sep 17 15:05:23.766515 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/administrator/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxZgAAATk"]
[Thu Sep 17 15:05:23.962095 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:45662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/"] [unique_id "aqxWExFTPRVSLOsRVhrxbAAAAW0"]
[Thu Sep 17 15:05:23.989611 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.219.249:56362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWExFTPRVSLOsRVhrxbQAAAVI"]
[Thu Sep 17 15:05:23.999518 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/psnlink/.env"] [unique_id "aqxWExFTPRVSLOsRVhrxbgAAAWM"]
[Thu Sep 17 15:05:24.122732 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/"] [unique_id "aqxWFBFTPRVSLOsRVhrxcgAAAXI"]
[Thu Sep 17 15:05:24.231638 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/exapi/.env"] [unique_id "aqxWFBFTPRVSLOsRVhrxcwAAAV4"]
[Thu Sep 17 15:05:24.260967 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:45662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/wp-includes/php-ai-client/src/Providers/Http/"] [unique_id "aqxWFBFTPRVSLOsRVhrxdQAAAXA"]
[Thu Sep 17 15:05:24.461508 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.219.249:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxfQAAAVU"]
[Thu Sep 17 15:05:24.545256 2026] [security2:error] [pid 955873:tid 956015] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sitemaps/.env"] [unique_id "aqxWFBFTPRVSLOsRVhrxgQAAARY"]
[Thu Sep 17 15:05:24.592420 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxewAAAW4"]
[Thu Sep 17 15:05:24.592441 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxewAAAW4"]
[Thu Sep 17 15:05:24.733287 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:45662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ErrorMessageExtractor.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxhgAAARs"]
[Thu Sep 17 15:05:24.733363 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:45662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ErrorMessageExtractor.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxhgAAARs"]
[Thu Sep 17 15:05:24.835173 2026] [autoindex:error] [pid 955873:tid 956106] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:24.835622 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFBFTPRVSLOsRVhrxkAAAAXE"]
[Thu Sep 17 15:05:24.837208 2026] [security2:error] [pid 955873:tid 956031] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/uploads/"] [unique_id "aqxWFBFTPRVSLOsRVhrxjgAAASY"]
[Thu Sep 17 15:05:24.934018 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.219.249:56382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWFBFTPRVSLOsRVhrxlgAAARk"]
[Thu Sep 17 15:05:24.934867 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env"] [unique_id "aqxWFBFTPRVSLOsRVhrxlQAAAQ4"]
[Thu Sep 17 15:05:25.036940 2026] [autoindex:error] [pid 955873:tid 956003] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.037391 2026] [security2:error] [pid 955873:tid 956003] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxmwAAAQo"]
[Thu Sep 17 15:05:25.043634 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:45664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ResponseUtil.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxnAAAATM"]
[Thu Sep 17 15:05:25.043737 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:45664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Http/Util/ResponseUtil.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxnAAAATM"]
[Thu Sep 17 15:05:25.044257 2026] [security2:error] [pid 955873:tid 956019] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/"] [unique_id "aqxWFBFTPRVSLOsRVhrxmQAAARo"]
[Thu Sep 17 15:05:25.095033 2026] [authz_core:error] [pid 955873:tid 956010] [client 4.240.114.86:58652] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:05:25.205869 2026] [security2:error] [pid 955873:tid 956047] [client 216.73.163.45:42053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxoQAAATY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:25.289369 2026] [autoindex:error] [pid 955873:tid 956063] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.289828 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxqAAAAUY"]
[Thu Sep 17 15:05:25.303485 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/css/"] [unique_id "aqxWFRFTPRVSLOsRVhrxpQAAASc"]
[Thu Sep 17 15:05:25.323683 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFRFTPRVSLOsRVhrxqwAAAYE"]
[Thu Sep 17 15:05:25.324006 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.129.237:38262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/logs/.env"] [unique_id "aqxWFRFTPRVSLOsRVhrxqgAAAXo"]
[Thu Sep 17 15:05:25.393146 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.219.249:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxrAAAARI"]
[Thu Sep 17 15:05:25.412448 2026] [security2:error] [pid 955873:tid 956126] [client 185.55.149.49:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxrQAAAYU"]
[Thu Sep 17 15:05:25.412558 2026] [security2:error] [pid 955873:tid 956126] [client 185.55.149.49:56772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxrQAAAYU"]
[Thu Sep 17 15:05:25.498099 2026] [autoindex:error] [pid 955873:tid 956121] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.498547 2026] [security2:error] [pid 955873:tid 956121] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxswAAAYA"]
[Thu Sep 17 15:05:25.527154 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFRFTPRVSLOsRVhrxsAAAAVk"]
[Thu Sep 17 15:05:25.531349 2026] [security2:error] [pid 955873:tid 956042] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/ID3/"] [unique_id "aqxWFRFTPRVSLOsRVhrxsQAAATE"]
[Thu Sep 17 15:05:25.666766 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWFRFTPRVSLOsRVhrxuAAAAWk"]
[Thu Sep 17 15:05:25.733855 2026] [autoindex:error] [pid 955873:tid 956014] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:25.734539 2026] [security2:error] [pid 955873:tid 956014] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxvgAAARU"]
[Thu Sep 17 15:05:25.795498 2026] [security2:error] [pid 955873:tid 956084] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/IXR/"] [unique_id "aqxWFRFTPRVSLOsRVhrxuwAAAVs"]
[Thu Sep 17 15:05:25.880450 2026] [security2:error] [pid 955873:tid 956016] [client 34.154.219.249:56398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxxAAAARc"]
[Thu Sep 17 15:05:25.970610 2026] [security2:error] [pid 955873:tid 956117] [client 168.119.53.160:48122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "i.am.tengushee.com"] [uri "/index.html"] [unique_id "aqxWFRFTPRVSLOsRVhrxywAAAXw"], referer: http://i.am.tengushee.com
[Thu Sep 17 15:05:26.022602 2026] [security2:error] [pid 955873:tid 956006] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cache/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrxzwAAAQ0"]
[Thu Sep 17 15:05:26.036357 2026] [autoindex:error] [pid 955873:tid 956109] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:26.037007 2026] [security2:error] [pid 955873:tid 956109] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFhFTPRVSLOsRVhrxzgAAAXQ"]
[Thu Sep 17 15:05:26.038127 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxwwAAAWY"]
[Thu Sep 17 15:05:26.038145 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFRFTPRVSLOsRVhrxwwAAAWY"]
[Thu Sep 17 15:05:26.038669 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/Requests/"] [unique_id "aqxWFRFTPRVSLOsRVhrxxwAAAVg"]
[Thu Sep 17 15:05:26.187640 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/"] [unique_id "aqxWFhFTPRVSLOsRVhrx0QAAAYg"]
[Thu Sep 17 15:05:26.253506 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailer/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx2QAAASY"]
[Thu Sep 17 15:05:26.261377 2026] [autoindex:error] [pid 955873:tid 956077] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:26.261843 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFhFTPRVSLOsRVhrx2AAAAVQ"]
[Thu Sep 17 15:05:26.284862 2026] [security2:error] [pid 955873:tid 956085] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxWFhFTPRVSLOsRVhrx0wAAAVw"]
[Thu Sep 17 15:05:26.352555 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/"] [unique_id "aqxWFhFTPRVSLOsRVhrx3QAAARA"]
[Thu Sep 17 15:05:26.377625 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.219.249:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx3gAAAUw"]
[Thu Sep 17 15:05:26.481585 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx4wAAARo"]
[Thu Sep 17 15:05:26.516249 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFhFTPRVSLOsRVhrx5gAAAXc"]
[Thu Sep 17 15:05:26.528863 2026] [autoindex:error] [pid 955873:tid 956049] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:26.529319 2026] [security2:error] [pid 955873:tid 956049] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWFhFTPRVSLOsRVhrx5QAAATg"]
[Thu Sep 17 15:05:26.547315 2026] [security2:error] [pid 955873:tid 956003] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/Text/"] [unique_id "aqxWFhFTPRVSLOsRVhrx3wAAAQo"]
[Thu Sep 17 15:05:26.695858 2026] [security2:error] [pid 955873:tid 955886] [remote 216.73.217.142:14717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWFhFTPRVSLOsRVhrx6wABXQw"]
[Thu Sep 17 15:05:26.720672 2026] [security2:error] [pid 955873:tid 956072] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/email/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx7gAAAU8"]
[Thu Sep 17 15:05:26.791277 2026] [security2:error] [pid 955873:tid 956124] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWFhFTPRVSLOsRVhrx9QAAAYM"]
[Thu Sep 17 15:05:26.857943 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.219.249:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx-AAAAYE"]
[Thu Sep 17 15:05:26.869577 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx6gAAAUg"]
[Thu Sep 17 15:05:26.869604 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx6gAAAUg"]
[Thu Sep 17 15:05:26.953405 2026] [security2:error] [pid 955873:tid 956046] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/smtp/.env"] [unique_id "aqxWFhFTPRVSLOsRVhrx-QAAATU"]
[Thu Sep 17 15:05:27.024441 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:45678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/ModelInterface.php"] [unique_id "aqxWFxFTPRVSLOsRVhrx_gAAAUQ"]
[Thu Sep 17 15:05:27.024525 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Contracts/ModelInterface.php"] [unique_id "aqxWFxFTPRVSLOsRVhrx_gAAAUQ"]
[Thu Sep 17 15:05:27.060970 2026] [security2:error] [pid 955873:tid 956101] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWFxFTPRVSLOsRVhrx_wAAAWw"]
[Thu Sep 17 15:05:27.183904 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailing/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryAQAAAXI"]
[Thu Sep 17 15:05:27.187007 2026] [autoindex:error] [pid 955873:tid 956104] [client 194.163.134.215:38820] AH01276: Cannot serve directory /home1/pqcmzsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:27.318103 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:45682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/"] [unique_id "aqxWFxFTPRVSLOsRVhryDQAAARc"]
[Thu Sep 17 15:05:27.342297 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.219.249:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWFxFTPRVSLOsRVhryDgAAAWk"]
[Thu Sep 17 15:05:27.414837 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/notifications/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryEQAAAUE"]
[Thu Sep 17 15:05:27.446983 2026] [security2:error] [pid 955873:tid 956117] [client 20.244.34.24:65042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxWFxFTPRVSLOsRVhryEwAAAXw"], referer: binance.com
[Thu Sep 17 15:05:27.481062 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/"] [unique_id "aqxWFxFTPRVSLOsRVhryFAAAAV4"]
[Thu Sep 17 15:05:27.580478 2026] [security2:error] [pid 955873:tid 956052] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWFxFTPRVSLOsRVhryFwAAATs"]
[Thu Sep 17 15:05:27.624532 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:45682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWFxFTPRVSLOsRVhryGgAAAWE"]
[Thu Sep 17 15:05:27.652044 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/notify/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryGwAAAYg"]
[Thu Sep 17 15:05:27.791074 2026] [security2:error] [pid 955873:tid 956029] [client 88.99.80.227:62228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.endless-chronicles.com"] [uri "/index.php"] [unique_id "aqxWFxFTPRVSLOsRVhryJwAAASQ"], referer: http://www.endless-chronicles.com
[Thu Sep 17 15:05:27.810836 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.219.249:56450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ccrmediator.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWFxFTPRVSLOsRVhryKAAAASY"]
[Thu Sep 17 15:05:27.833702 2026] [autoindex:error] [pid 955873:tid 956039] [client 34.35.44.204:45802] AH01276: Cannot serve directory /home1/omqzshmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:27.883821 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sender/.env"] [unique_id "aqxWFxFTPRVSLOsRVhryLAAAAVM"]
[Thu Sep 17 15:05:27.961791 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFxFTPRVSLOsRVhryJQAAAWc"]
[Thu Sep 17 15:05:27.961816 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWFxFTPRVSLOsRVhryJQAAAWc"]
[Thu Sep 17 15:05:28.008909 2026] [security2:error] [pid 955873:tid 956095] [client 45.146.54.112:35661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWGBFTPRVSLOsRVhryMAAAAWY"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:28.117914 2026] [security2:error] [pid 955873:tid 956008] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/campaign/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryNQAAAQ8"]
[Thu Sep 17 15:05:28.143967 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:45682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelConfig.php"] [unique_id "aqxWGBFTPRVSLOsRVhryOAAAATY"]
[Thu Sep 17 15:05:28.144052 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:45682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelConfig.php"] [unique_id "aqxWGBFTPRVSLOsRVhryOAAAATY"]
[Thu Sep 17 15:05:28.245725 2026] [security2:error] [pid 955873:tid 956121] [client 4.240.114.86:60401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-admin/includes/dvskadniwoc.php"] [unique_id "aqxWGBFTPRVSLOsRVhryPQAAAYA"], referer: binance.com
[Thu Sep 17 15:05:28.350274 2026] [security2:error] [pid 955873:tid 956011] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/newsletter/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryRQAAARI"]
[Thu Sep 17 15:05:28.422415 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:45696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelMetadata.php"] [unique_id "aqxWGBFTPRVSLOsRVhrySAAAAWo"]
[Thu Sep 17 15:05:28.422499 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:45696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelMetadata.php"] [unique_id "aqxWGBFTPRVSLOsRVhrySAAAAWo"]
[Thu Sep 17 15:05:28.584538 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/ses/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryUQAAAXg"]
[Thu Sep 17 15:05:28.589818 2026] [security2:error] [pid 955873:tid 956063] [client 47.79.207.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWGBFTPRVSLOsRVhryOgAAAUY"], referer: https://www.google.com/
[Thu Sep 17 15:05:28.629435 2026] [security2:error] [pid 955873:tid 956062] [client 216.73.163.42:54893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWGBFTPRVSLOsRVhryUgAAAUU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:28.713819 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:45706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelRequirements.php"] [unique_id "aqxWGBFTPRVSLOsRVhryVgAAASw"]
[Thu Sep 17 15:05:28.713926 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:45706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/ModelRequirements.php"] [unique_id "aqxWGBFTPRVSLOsRVhryVgAAASw"]
[Thu Sep 17 15:05:28.816001 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sendgrid/.env"] [unique_id "aqxWGBFTPRVSLOsRVhryYAAAAVo"]
[Thu Sep 17 15:05:29.007045 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:45708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/RequiredOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryaQAAAVM"]
[Thu Sep 17 15:05:29.007162 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:45708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/RequiredOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryaQAAAVM"]
[Thu Sep 17 15:05:29.033728 2026] [security2:error] [pid 955873:tid 956123] [client 168.232.161.19:4669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWGBFTPRVSLOsRVhryZQABghc"]
[Thu Sep 17 15:05:29.051858 2026] [security2:error] [pid 955873:tid 956069] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/sparkpost/.env"] [unique_id "aqxWGRFTPRVSLOsRVhrybwAAAUw"]
[Thu Sep 17 15:05:29.073566 2026] [security2:error] [pid 955873:tid 956052] [client 37.19.210.94:48767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.210.19.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lasvegaslife.info"] [uri "/xmlrpc.php"] [unique_id "aqxWGRFTPRVSLOsRVhryawAAATs"]
[Thu Sep 17 15:05:29.073723 2026] [security2:error] [pid 955873:tid 956052] [client 37.19.210.94:48767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lasvegaslife.info"] [uri "/xmlrpc.php"] [unique_id "aqxWGRFTPRVSLOsRVhryawAAATs"]
[Thu Sep 17 15:05:29.285592 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/SupportedOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryewAAASU"]
[Thu Sep 17 15:05:29.285694 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/DTO/SupportedOption.php"] [unique_id "aqxWGRFTPRVSLOsRVhryewAAASU"]
[Thu Sep 17 15:05:29.290915 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/postmark/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryfAAAATM"]
[Thu Sep 17 15:05:29.520492 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailgun/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryhQAAAV8"]
[Thu Sep 17 15:05:29.530972 2026] [security2:error] [pid 955873:tid 956082] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryiAAAAVk"]
[Thu Sep 17 15:05:29.578031 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:45728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/"] [unique_id "aqxWGRFTPRVSLOsRVhryiQAAAUs"]
[Thu Sep 17 15:05:29.737279 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/"] [unique_id "aqxWGRFTPRVSLOsRVhrykAAAAXI"]
[Thu Sep 17 15:05:29.749454 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mandrill/.env"] [unique_id "aqxWGRFTPRVSLOsRVhrylAAAARU"]
[Thu Sep 17 15:05:29.892998 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:45728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWGRFTPRVSLOsRVhrynAAAAWk"]
[Thu Sep 17 15:05:29.980008 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mailjet/.env"] [unique_id "aqxWGRFTPRVSLOsRVhryoAAAAXs"]
[Thu Sep 17 15:05:29.994079 2026] [security2:error] [pid 955873:tid 956077] [client 192.178.6.4:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWGRFTPRVSLOsRVhryoQAAAVQ"]
[Thu Sep 17 15:05:30.208927 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWGhFTPRVSLOsRVhryqwAAARs"]
[Thu Sep 17 15:05:30.212026 2026] [security2:error] [pid 955873:tid 956048] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/brevo/.env"] [unique_id "aqxWGhFTPRVSLOsRVhryrQAAATc"]
[Thu Sep 17 15:05:30.241944 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhrypgAAAYg"]
[Thu Sep 17 15:05:30.241975 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhrypgAAAYg"]
[Thu Sep 17 15:05:30.245509 2026] [security2:error] [pid 955873:tid 956028] [client 154.190.208.131:41714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhrysgAAASM"]
[Thu Sep 17 15:05:30.246034 2026] [security2:error] [pid 955873:tid 956028] [client 154.190.208.131:41714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhrysgAAASM"]
[Thu Sep 17 15:05:30.382602 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:45728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/CapabilityEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryuQAAAUw"]
[Thu Sep 17 15:05:30.382759 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:45728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/CapabilityEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryuQAAAUw"]
[Thu Sep 17 15:05:30.421090 2026] [security2:error] [pid 955873:tid 956025] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWGhFTPRVSLOsRVhryvAAAASA"]
[Thu Sep 17 15:05:30.436060 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx8wAAATo"]
[Thu Sep 17 15:05:30.436086 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWFhFTPRVSLOsRVhrx8wAAATo"]
[Thu Sep 17 15:05:30.438747 2026] [security2:error] [pid 955873:tid 956115] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxWFhFTPRVSLOsRVhrx7AAAAXo"]
[Thu Sep 17 15:05:30.443022 2026] [security2:error] [pid 955873:tid 956096] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/transactional/.env"] [unique_id "aqxWGhFTPRVSLOsRVhrywAAAAWc"]
[Thu Sep 17 15:05:30.606781 2026] [security2:error] [pid 955873:tid 956023] [client 45.169.98.18:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhryxgAAAR4"]
[Thu Sep 17 15:05:30.606852 2026] [security2:error] [pid 955873:tid 956023] [client 45.169.98.18:52126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhryxgAAAR4"]
[Thu Sep 17 15:05:30.670066 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/OptionEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryzgAAAYE"]
[Thu Sep 17 15:05:30.670146 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:58374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/Enums/OptionEnum.php"] [unique_id "aqxWGhFTPRVSLOsRVhryzgAAAYE"]
[Thu Sep 17 15:05:30.676460 2026] [security2:error] [pid 955873:tid 956012] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/bulk/.env"] [unique_id "aqxWGhFTPRVSLOsRVhryzwAAARM"]
[Thu Sep 17 15:05:30.738468 2026] [security2:error] [pid 955873:tid 956046] [client 216.73.163.48:39879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWGhFTPRVSLOsRVhry0AAAATU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:30.803512 2026] [security2:error] [pid 955873:tid 956052] [client 186.105.232.15:64488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhry1wAAATs"]
[Thu Sep 17 15:05:30.803614 2026] [security2:error] [pid 955873:tid 956052] [client 186.105.232.15:64488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGhFTPRVSLOsRVhry1wAAATs"]
[Thu Sep 17 15:05:30.911630 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/aws/.env"] [unique_id "aqxWGhFTPRVSLOsRVhry3wAAAXI"]
[Thu Sep 17 15:05:30.972779 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/"] [unique_id "aqxWGhFTPRVSLOsRVhry5AAAATk"]
[Thu Sep 17 15:05:31.013366 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhry2wAAAWo"]
[Thu Sep 17 15:05:31.013389 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGhFTPRVSLOsRVhry2wAAAWo"]
[Thu Sep 17 15:05:31.042131 2026] [security2:error] [pid 955873:tid 956072] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxWGhFTPRVSLOsRVhry2QAAAU8"]
[Thu Sep 17 15:05:31.145747 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/azure/.env"] [unique_id "aqxWGxFTPRVSLOsRVhry6gAAAXs"]
[Thu Sep 17 15:05:31.151015 2026] [security2:error] [pid 955873:tid 956077] [client 4.240.114.86:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-admin/includes/medias.php"] [unique_id "aqxWGxFTPRVSLOsRVhry6wAAAVQ"], referer: binance.com
[Thu Sep 17 15:05:31.340925 2026] [security2:error] [pid 955873:tid 956021] [client 115.244.164.14:61288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGxFTPRVSLOsRVhry9QAAARw"]
[Thu Sep 17 15:05:31.341024 2026] [security2:error] [pid 955873:tid 956021] [client 115.244.164.14:61288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWGxFTPRVSLOsRVhry9QAAARw"]
[Thu Sep 17 15:05:31.373138 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/gcp/.env"] [unique_id "aqxWGxFTPRVSLOsRVhry9wAAAS4"]
[Thu Sep 17 15:05:31.395064 2026] [security2:error] [pid 955873:tid 956067] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhry8wAAAUo"]
[Thu Sep 17 15:05:31.395084 2026] [security2:error] [pid 955873:tid 956067] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhry8wAAAUo"]
[Thu Sep 17 15:05:31.447449 2026] [security2:error] [pid 955873:tid 956071] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxWGxFTPRVSLOsRVhry8QAAAU4"]
[Thu Sep 17 15:05:31.457797 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/"] [unique_id "aqxWGxFTPRVSLOsRVhry-AAAARs"]
[Thu Sep 17 15:05:31.476011 2026] [security2:error] [pid 955873:tid 956069] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWGxFTPRVSLOsRVhry_AAAAUw"]
[Thu Sep 17 15:05:31.605894 2026] [security2:error] [pid 955873:tid 956109] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cloud/.env"] [unique_id "aqxWGxFTPRVSLOsRVhry_wAAAXQ"]
[Thu Sep 17 15:05:31.619289 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWGxFTPRVSLOsRVhrzAAAAAWg"]
[Thu Sep 17 15:05:31.739849 2026] [autoindex:error] [pid 955873:tid 956106] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:31.740300 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWGxFTPRVSLOsRVhrzBwAAAXE"]
[Thu Sep 17 15:05:31.744424 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxWGxFTPRVSLOsRVhrzAgAAASc"]
[Thu Sep 17 15:05:31.753799 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWGxFTPRVSLOsRVhrzCgAAAR4"]
[Thu Sep 17 15:05:31.833595 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/infrastructure/.env"] [unique_id "aqxWGxFTPRVSLOsRVhrzDwAAAWM"]
[Thu Sep 17 15:05:31.958008 2026] [autoindex:error] [pid 955873:tid 956046] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:31.958497 2026] [security2:error] [pid 955873:tid 956046] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWGxFTPRVSLOsRVhrzFQAAATU"]
[Thu Sep 17 15:05:31.975995 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhrzDgAAARM"]
[Thu Sep 17 15:05:31.976015 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWGxFTPRVSLOsRVhrzDgAAARM"]
[Thu Sep 17 15:05:32.007771 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxWGxFTPRVSLOsRVhrzEwAAAX4"]
[Thu Sep 17 15:05:32.063363 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzGAAAATs"]
[Thu Sep 17 15:05:32.068344 2026] [security2:error] [pid 955873:tid 956061] [client 194.163.128.162:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzGQAAAUQ"], referer: binance.com
[Thu Sep 17 15:05:32.193945 2026] [security2:error] [pid 955873:tid 956065] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzHAAAAUg"]
[Thu Sep 17 15:05:32.208367 2026] [security2:error] [pid 955873:tid 956114] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/blocks/"] [unique_id "aqxWHBFTPRVSLOsRVhrzGgAAAXk"]
[Thu Sep 17 15:05:32.213912 2026] [security2:error] [pid 955873:tid 956089] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzHQAAAWA"]
[Thu Sep 17 15:05:32.249847 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/"] [unique_id "aqxWHBFTPRVSLOsRVhrzHwAAAWs"]
[Thu Sep 17 15:05:32.298084 2026] [security2:error] [pid 955873:tid 956013] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/k8s/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzIgAAARQ"]
[Thu Sep 17 15:05:32.311132 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWHBFTPRVSLOsRVhrzIwAAAUI"]
[Thu Sep 17 15:05:32.392778 2026] [autoindex:error] [pid 955873:tid 956104] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:32.393246 2026] [security2:error] [pid 955873:tid 956104] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHBFTPRVSLOsRVhrzKQAAAW8"]
[Thu Sep 17 15:05:32.400167 2026] [security2:error] [pid 955873:tid 956113] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/certificates/"] [unique_id "aqxWHBFTPRVSLOsRVhrzJwAAAXg"]
[Thu Sep 17 15:05:32.405330 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/"] [unique_id "aqxWHBFTPRVSLOsRVhrzKgAAATE"]
[Thu Sep 17 15:05:32.412710 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzKwAAAUU"]
[Thu Sep 17 15:05:32.531423 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/kubernetes/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzLAAAASs"]
[Thu Sep 17 15:05:32.542665 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/"] [unique_id "aqxWHBFTPRVSLOsRVhrzLQAAAXw"]
[Thu Sep 17 15:05:32.566748 2026] [security2:error] [pid 955873:tid 956125] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzMAAAAYQ"]
[Thu Sep 17 15:05:32.602356 2026] [autoindex:error] [pid 955873:tid 956083] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:32.603033 2026] [security2:error] [pid 955873:tid 956083] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHBFTPRVSLOsRVhrzMgAAAVo"]
[Thu Sep 17 15:05:32.656287 2026] [security2:error] [pid 955873:tid 956037] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/customize/"] [unique_id "aqxWHBFTPRVSLOsRVhrzLgAAASw"]
[Thu Sep 17 15:05:32.656301 2026] [security2:error] [pid 955873:tid 956098] [client 47.79.200.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzJgAAAWk"], referer: https://www.google.com/
[Thu Sep 17 15:05:32.738217 2026] [security2:error] [pid 955873:tid 956020] [client 20.244.34.24:51330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzNgAAARs"], referer: binance.com
[Thu Sep 17 15:05:32.747123 2026] [security2:error] [pid 955873:tid 956043] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzNwAAATI"]
[Thu Sep 17 15:05:32.764385 2026] [security2:error] [pid 955873:tid 956041] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/terraform/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzOQAAATA"]
[Thu Sep 17 15:05:32.855890 2026] [autoindex:error] [pid 955873:tid 956018] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:32.856364 2026] [security2:error] [pid 955873:tid 956018] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHBFTPRVSLOsRVhrzPAAAARk"]
[Thu Sep 17 15:05:32.870454 2026] [security2:error] [pid 955873:tid 956069] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/fonts/"] [unique_id "aqxWHBFTPRVSLOsRVhrzOgAAAUw"]
[Thu Sep 17 15:05:32.878258 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzMwAAAWE"]
[Thu Sep 17 15:05:32.878276 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHBFTPRVSLOsRVhrzMwAAAWE"]
[Thu Sep 17 15:05:32.912470 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzPgAAAWQ"]
[Thu Sep 17 15:05:32.995024 2026] [security2:error] [pid 955873:tid 956025] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/ansible/.env"] [unique_id "aqxWHBFTPRVSLOsRVhrzQgAAASA"]
[Thu Sep 17 15:05:33.015459 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzQwAAASQ"]
[Thu Sep 17 15:05:33.015562 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:58378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzQwAAASQ"]
[Thu Sep 17 15:05:33.087075 2026] [security2:error] [pid 955873:tid 956051] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzRwAAATo"]
[Thu Sep 17 15:05:33.099794 2026] [autoindex:error] [pid 955873:tid 956084] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:33.100433 2026] [security2:error] [pid 955873:tid 956084] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHRFTPRVSLOsRVhrzRgAAAVs"]
[Thu Sep 17 15:05:33.104860 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/images/"] [unique_id "aqxWHRFTPRVSLOsRVhrzRAAAAR8"]
[Thu Sep 17 15:05:33.163406 2026] [security2:error] [pid 955873:tid 956006] [client 104.28.198.244:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzSQAAAQ0"]
[Thu Sep 17 15:05:33.163535 2026] [security2:error] [pid 955873:tid 956006] [client 104.28.198.244:22548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzSQAAAQ0"]
[Thu Sep 17 15:05:33.224827 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/.git/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzSwAAAS8"]
[Thu Sep 17 15:05:33.287298 2026] [security2:error] [pid 955873:tid 955906] [remote 40.77.167.51:28882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzSgABZyA"]
[Thu Sep 17 15:05:33.289637 2026] [autoindex:error] [pid 955873:tid 956054] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:33.290108 2026] [security2:error] [pid 955873:tid 956054] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHRFTPRVSLOsRVhrzUAAAAT0"]
[Thu Sep 17 15:05:33.296617 2026] [security2:error] [pid 955873:tid 956110] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/.well-known/"] [unique_id "aqxWHRFTPRVSLOsRVhrzTQAAAXU"]
[Thu Sep 17 15:05:33.348713 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationOperationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzVQAAAVU"]
[Thu Sep 17 15:05:33.348804 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:58390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationOperationModelInterface.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzVQAAAVU"]
[Thu Sep 17 15:05:33.456525 2026] [security2:error] [pid 955873:tid 956060] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/ci/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzWAAAAUM"]
[Thu Sep 17 15:05:33.496322 2026] [security2:error] [pid 955873:tid 956012] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzWwAAARM"]
[Thu Sep 17 15:05:33.633106 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/"] [unique_id "aqxWHRFTPRVSLOsRVhrzXgAAAQs"]
[Thu Sep 17 15:05:33.634723 2026] [security2:error] [pid 955873:tid 956126] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzXAAAAYU"]
[Thu Sep 17 15:05:33.634742 2026] [security2:error] [pid 955873:tid 956126] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzXAAAAYU"]
[Thu Sep 17 15:05:33.668078 2026] [security2:error] [pid 955873:tid 956082] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzXwAAAVk"]
[Thu Sep 17 15:05:33.672984 2026] [security2:error] [pid 955873:tid 956038] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/ALFA_DATA/"] [unique_id "aqxWHRFTPRVSLOsRVhrzWQAAAS0"]
[Thu Sep 17 15:05:33.689461 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/cd/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzYQAAAUQ"]
[Thu Sep 17 15:05:33.798343 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/"] [unique_id "aqxWHRFTPRVSLOsRVhrzZQAAAXI"]
[Thu Sep 17 15:05:33.887658 2026] [security2:error] [pid 955873:tid 956114] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzaQAAAXk"]
[Thu Sep 17 15:05:33.924919 2026] [security2:error] [pid 955873:tid 956089] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/jenkins/.env"] [unique_id "aqxWHRFTPRVSLOsRVhrzbAAAAWA"]
[Thu Sep 17 15:05:33.936905 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWHRFTPRVSLOsRVhrzbQAAAUY"]
[Thu Sep 17 15:05:34.015983 2026] [security2:error] [pid 955873:tid 956092] [client 216.73.163.66:26029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzbgAAAWM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:34.026815 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzagAAAUA"]
[Thu Sep 17 15:05:34.026835 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHRFTPRVSLOsRVhrzagAAAUA"]
[Thu Sep 17 15:05:34.042051 2026] [security2:error] [pid 955873:tid 956072] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzcAAAAU8"]
[Thu Sep 17 15:05:34.042063 2026] [security2:error] [pid 955873:tid 956065] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/.well-knownold/"] [unique_id "aqxWHRFTPRVSLOsRVhrzZwAAAUg"]
[Thu Sep 17 15:05:34.156575 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/gitlab/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzcgAAATE"]
[Thu Sep 17 15:05:34.206550 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzcwAAAUU"]
[Thu Sep 17 15:05:34.262330 2026] [autoindex:error] [pid 955873:tid 956077] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:34.262839 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHhFTPRVSLOsRVhrzdwAAAVQ"]
[Thu Sep 17 15:05:34.269178 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzcQAAAWo"]
[Thu Sep 17 15:05:34.269197 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzcQAAAWo"]
[Thu Sep 17 15:05:34.274098 2026] [security2:error] [pid 955873:tid 956050] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxWHhFTPRVSLOsRVhrzdAAAATk"]
[Thu Sep 17 15:05:34.393332 2026] [security2:error] [pid 955873:tid 956098] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/github/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzewAAAWk"]
[Thu Sep 17 15:05:34.413938 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/"] [unique_id "aqxWHhFTPRVSLOsRVhrzfQAAASI"]
[Thu Sep 17 15:05:34.471190 2026] [cgid:error] [pid 955873:tid 956067] [client 139.28.219.68:0] AH01265: stderr from /home3/ncfwbqmy/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:05:34.471634 2026] [security2:error] [pid 955873:tid 956067] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWHhFTPRVSLOsRVhrzgAAAAUo"]
[Thu Sep 17 15:05:34.497724 2026] [security2:error] [pid 955873:tid 956048] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzgQAAATc"]
[Thu Sep 17 15:05:34.497908 2026] [security2:error] [pid 955873:tid 956127] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-bin/"] [unique_id "aqxWHhFTPRVSLOsRVhrzfgAAAYY"]
[Thu Sep 17 15:05:34.581570 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/"] [unique_id "aqxWHhFTPRVSLOsRVhrzgwAAATA"]
[Thu Sep 17 15:05:34.625894 2026] [security2:error] [pid 955873:tid 956018] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/actions/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzhAAAARk"]
[Thu Sep 17 15:05:34.720346 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/"] [unique_id "aqxWHhFTPRVSLOsRVhrziAAAAUw"]
[Thu Sep 17 15:05:34.724109 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrziQAAAWE"]
[Thu Sep 17 15:05:34.829114 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzhwAAAXA"]
[Thu Sep 17 15:05:34.829138 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzhwAAAXA"]
[Thu Sep 17 15:05:34.858783 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/circleci/.env"] [unique_id "aqxWHhFTPRVSLOsRVhrzjQAAAU4"]
[Thu Sep 17 15:05:34.905605 2026] [security2:error] [pid 955873:tid 956123] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index/"] [unique_id "aqxWHhFTPRVSLOsRVhrzhQAAAYI"]
[Thu Sep 17 15:05:34.997969 2026] [authz_core:error] [pid 955873:tid 956081] [client 4.240.114.86:64733] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/maint/error_log, referer: binance.com
[Thu Sep 17 15:05:35.085730 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzkAAAAWQ"]
[Thu Sep 17 15:05:35.085751 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWHhFTPRVSLOsRVhrzkAAAAWQ"]
[Thu Sep 17 15:05:35.095904 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/travis/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzlQAAARA"]
[Thu Sep 17 15:05:35.150920 2026] [security2:error] [pid 955873:tid 956115] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzlwAAAXo"]
[Thu Sep 17 15:05:35.225683 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzmAAAAUc"]
[Thu Sep 17 15:05:35.225798 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzmAAAAUc"]
[Thu Sep 17 15:05:35.266464 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzlgAAAR8"]
[Thu Sep 17 15:05:35.266497 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzlgAAAR8"]
[Thu Sep 17 15:05:35.302761 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/id/"] [unique_id "aqxWHxFTPRVSLOsRVhrzkgAAATo"]
[Thu Sep 17 15:05:35.318059 2026] [security2:error] [pid 955873:tid 956106] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzngAAAXE"]
[Thu Sep 17 15:05:35.329989 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/buildkite/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrznwAAAVI"]
[Thu Sep 17 15:05:35.510061 2026] [security2:error] [pid 955873:tid 956118] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzqAAAAX0"]
[Thu Sep 17 15:05:35.532785 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationOperationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzqQAAATM"]
[Thu Sep 17 15:05:35.532885 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:58412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGenerationOperationModelInterface.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzqQAAATM"]
[Thu Sep 17 15:05:35.562856 2026] [security2:error] [pid 955873:tid 956030] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mysql/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzqgAAASU"]
[Thu Sep 17 15:05:35.623546 2026] [security2:error] [pid 955873:tid 956121] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzpwAAAYA"]
[Thu Sep 17 15:05:35.623572 2026] [security2:error] [pid 955873:tid 956121] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrzpwAAAYA"]
[Thu Sep 17 15:05:35.642719 2026] [security2:error] [pid 955873:tid 956119] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWHxFTPRVSLOsRVhrzqwAAAX4"]
[Thu Sep 17 15:05:35.698769 2026] [security2:error] [pid 955873:tid 956008] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/www/"] [unique_id "aqxWHxFTPRVSLOsRVhrzpQAAAQ8"]
[Thu Sep 17 15:05:35.715135 2026] [security2:error] [pid 955873:tid 956056] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzrAAAAT8"]
[Thu Sep 17 15:05:35.798220 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/postgres/.env"] [unique_id "aqxWHxFTPRVSLOsRVhrzsAAAAW4"]
[Thu Sep 17 15:05:35.821682 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/"] [unique_id "aqxWHxFTPRVSLOsRVhrzsQAAAVk"]
[Thu Sep 17 15:05:35.925622 2026] [security2:error] [pid 955873:tid 956052] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWHxFTPRVSLOsRVhrztQAAATs"]
[Thu Sep 17 15:05:36.016049 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrztAAAAXY"]
[Thu Sep 17 15:05:36.016073 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWHxFTPRVSLOsRVhrztAAAAXY"]
[Thu Sep 17 15:05:36.028285 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/"] [unique_id "aqxWIBFTPRVSLOsRVhrztgAAARg"]
[Thu Sep 17 15:05:36.029255 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/mongodb/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzuAAAAXI"]
[Thu Sep 17 15:05:36.037120 2026] [security2:error] [pid 955873:tid 956046] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/web/"] [unique_id "aqxWHxFTPRVSLOsRVhrzsgAAATU"]
[Thu Sep 17 15:05:36.068726 2026] [security2:error] [pid 955873:tid 956066] [client 45.131.194.118:48889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrztwAAAUk"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:36.130422 2026] [security2:error] [pid 955873:tid 956035] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzuQAAASo"]
[Thu Sep 17 15:05:36.175924 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWIBFTPRVSLOsRVhrzuwAAARc"]
[Thu Sep 17 15:05:36.182359 2026] [security2:error] [pid 955873:tid 956061] [client 185.55.149.49:57497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzugAAAUQ"]
[Thu Sep 17 15:05:36.182448 2026] [security2:error] [pid 955873:tid 956061] [client 185.55.149.49:57497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzugAAAUQ"]
[Thu Sep 17 15:05:36.264910 2026] [security2:error] [pid 955873:tid 956013] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/redis/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzwgAAARQ"]
[Thu Sep 17 15:05:36.364820 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzvwAAAVc"]
[Thu Sep 17 15:05:36.364845 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzvwAAAVc"]
[Thu Sep 17 15:05:36.417454 2026] [security2:error] [pid 955873:tid 956070] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/uploads/"] [unique_id "aqxWIBFTPRVSLOsRVhrzvAAAAU0"]
[Thu Sep 17 15:05:36.496572 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/elasticsearch/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzxQAAAXg"]
[Thu Sep 17 15:05:36.543978 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzxwAAAUU"]
[Thu Sep 17 15:05:36.700011 2026] [security2:error] [pid 955873:tid 956058] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrzywAAAUE"]
[Thu Sep 17 15:05:36.704037 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzxgAAATE"]
[Thu Sep 17 15:05:36.704073 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzxgAAATE"]
[Thu Sep 17 15:05:36.726796 2026] [security2:error] [pid 955873:tid 956122] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/rabbitmq/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrz0AAAAYE"]
[Thu Sep 17 15:05:36.733557 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzygAAAYQ"]
[Thu Sep 17 15:05:36.733581 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrzygAAAYQ"]
[Thu Sep 17 15:05:36.761646 2026] [security2:error] [pid 955873:tid 956022] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/upload/"] [unique_id "aqxWIBFTPRVSLOsRVhrzyAAAAR0"]
[Thu Sep 17 15:05:36.849274 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/"] [unique_id "aqxWIBFTPRVSLOsRVhrz1wAAAUo"]
[Thu Sep 17 15:05:36.890932 2026] [security2:error] [pid 955873:tid 956039] [client 47.79.200.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrz1gAAAS4"], referer: https://www.google.com/
[Thu Sep 17 15:05:36.900543 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrz2gAAARs"]
[Thu Sep 17 15:05:36.957546 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/kafka/.env"] [unique_id "aqxWIBFTPRVSLOsRVhrz3wAAAWE"]
[Thu Sep 17 15:05:37.018046 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/"] [unique_id "aqxWIBFTPRVSLOsRVhrz4AAAAXA"]
[Thu Sep 17 15:05:37.122163 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz4wAAAQ4"]
[Thu Sep 17 15:05:37.164839 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/"] [unique_id "aqxWIRFTPRVSLOsRVhrz5AAAASA"]
[Thu Sep 17 15:05:37.190275 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/queue/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz5QAAATQ"]
[Thu Sep 17 15:05:37.217838 2026] [security2:error] [pid 955873:tid 956018] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrz3gAAARk"]
[Thu Sep 17 15:05:37.217866 2026] [security2:error] [pid 955873:tid 956018] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIBFTPRVSLOsRVhrz3gAAARk"]
[Thu Sep 17 15:05:37.236838 2026] [security2:error] [pid 955873:tid 956043] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/uploads/"] [unique_id "aqxWIBFTPRVSLOsRVhrz2wAAATI"]
[Thu Sep 17 15:05:37.333049 2026] [security2:error] [pid 955873:tid 956109] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz7AAAAXQ"]
[Thu Sep 17 15:05:37.421171 2026] [security2:error] [pid 955873:tid 956110] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/worker/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz8AAAAXU"]
[Thu Sep 17 15:05:37.517322 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz6wAAAUc"]
[Thu Sep 17 15:05:37.517347 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz6wAAAUc"]
[Thu Sep 17 15:05:37.552549 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz7wAAATo"]
[Thu Sep 17 15:05:37.552576 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz7wAAATo"]
[Thu Sep 17 15:05:37.561100 2026] [security2:error] [pid 955873:tid 956040] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz8gAAAS8"]
[Thu Sep 17 15:05:37.573010 2026] [security2:error] [pid 955873:tid 956054] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Admin/uploads/"] [unique_id "aqxWIRFTPRVSLOsRVhrz7QAAAT0"]
[Thu Sep 17 15:05:37.585152 2026] [security2:error] [pid 955873:tid 956055] [client 66.249.77.225:60040] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "gallery.littlethingspr.com"] [uri "/robots.txt"] [unique_id "aqxWIRFTPRVSLOsRVhrz8wAAAT4"]
[Thu Sep 17 15:05:37.667310 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/job/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz9wAAATM"]
[Thu Sep 17 15:05:37.667765 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz-AAAASU"]
[Thu Sep 17 15:05:37.667851 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:58426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhrz-AAAASU"]
[Thu Sep 17 15:05:37.726143 2026] [security2:error] [pid 955873:tid 956005] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWIRFTPRVSLOsRVhrz-wAAAQw"]
[Thu Sep 17 15:05:37.899155 2026] [security2:error] [pid 955873:tid 956126] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/test/.env"] [unique_id "aqxWIRFTPRVSLOsRVhr0BAAAAYU"]
[Thu Sep 17 15:05:37.916352 2026] [security2:error] [pid 955873:tid 956068] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWIRFTPRVSLOsRVhr0BQAAAUs"]
[Thu Sep 17 15:05:37.963038 2026] [security2:error] [pid 955873:tid 956052] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0AQAAATs"]
[Thu Sep 17 15:05:37.963066 2026] [security2:error] [pid 955873:tid 956052] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0AQAAATs"]
[Thu Sep 17 15:05:37.978422 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationOperationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0BgAAAQs"]
[Thu Sep 17 15:05:37.978549 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:58430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationOperationModelInterface.php"] [unique_id "aqxWIRFTPRVSLOsRVhr0BgAAAQs"]
[Thu Sep 17 15:05:38.003319 2026] [security2:error] [pid 955873:tid 956008] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/"] [unique_id "aqxWIRFTPRVSLOsRVhrz_gAAAQ8"]
[Thu Sep 17 15:05:38.093143 2026] [security2:error] [pid 955873:tid 956107] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0BwAAAXI"]
[Thu Sep 17 15:05:38.135321 2026] [security2:error] [pid 955873:tid 956038] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/qa/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0CAAAAS0"]
[Thu Sep 17 15:05:38.139121 2026] [security2:error] [pid 955873:tid 956046] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0CQAAATU"]
[Thu Sep 17 15:05:38.310200 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/"] [unique_id "aqxWIhFTPRVSLOsRVhr0DAAAAUA"]
[Thu Sep 17 15:05:38.313321 2026] [security2:error] [pid 955873:tid 956063] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0DQAAAUY"]
[Thu Sep 17 15:05:38.364840 2026] [security2:error] [pid 955873:tid 956124] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/preview/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0DwAAAYM"]
[Thu Sep 17 15:05:38.413679 2026] [security2:error] [pid 955873:tid 956091] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0EAAAAWI"]
[Thu Sep 17 15:05:38.478731 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/"] [unique_id "aqxWIhFTPRVSLOsRVhr0EQAAAV0"]
[Thu Sep 17 15:05:38.526548 2026] [security2:error] [pid 955873:tid 956100] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0EgAAAWs"]
[Thu Sep 17 15:05:38.599437 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/beta/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0FgAAATE"]
[Thu Sep 17 15:05:38.621569 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWIhFTPRVSLOsRVhr0FwAAAYQ"]
[Thu Sep 17 15:05:38.692967 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0GAAAASs"]
[Thu Sep 17 15:05:38.697218 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0FQAAAUE"]
[Thu Sep 17 15:05:38.697237 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0FQAAAUE"]
[Thu Sep 17 15:05:38.712700 2026] [security2:error] [pid 955873:tid 956014] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0GQAAARU"]
[Thu Sep 17 15:05:38.756723 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/images/"] [unique_id "aqxWIhFTPRVSLOsRVhr0EwAAAWo"]
[Thu Sep 17 15:05:38.833470 2026] [security2:error] [pid 955873:tid 956079] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/uat/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0HgAAAVY"]
[Thu Sep 17 15:05:38.957410 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0HAAAAUo"]
[Thu Sep 17 15:05:38.957435 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIhFTPRVSLOsRVhr0HAAAAUo"]
[Thu Sep 17 15:05:38.968791 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0IQAAARs"]
[Thu Sep 17 15:05:38.992888 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWIhFTPRVSLOsRVhr0IwAAAWE"]
[Thu Sep 17 15:05:39.070861 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/stage/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0JQAAAQo"]
[Thu Sep 17 15:05:39.122172 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/"] [unique_id "aqxWIxFTPRVSLOsRVhr0KAAAARw"]
[Thu Sep 17 15:05:39.160490 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0JAAAAXA"]
[Thu Sep 17 15:05:39.160511 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0JAAAAXA"]
[Thu Sep 17 15:05:39.187655 2026] [security2:error] [pid 955873:tid 956123] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0KgAAAYI"]
[Thu Sep 17 15:05:39.223789 2026] [security2:error] [pid 955873:tid 956127] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/assets/"] [unique_id "aqxWIhFTPRVSLOsRVhr0HwAAAYY"]
[Thu Sep 17 15:05:39.243063 2026] [security2:error] [pid 955873:tid 956006] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0LAAAAQ0"]
[Thu Sep 17 15:05:39.282703 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/"] [unique_id "aqxWIxFTPRVSLOsRVhr0LwAAATQ"]
[Thu Sep 17 15:05:39.304901 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0MQAAARo"]
[Thu Sep 17 15:05:39.345414 2026] [security2:error] [pid 955873:tid 956109] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0MgAAAXQ"]
[Thu Sep 17 15:05:39.439009 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/"] [unique_id "aqxWIxFTPRVSLOsRVhr0MwAAAXM"]
[Thu Sep 17 15:05:39.516677 2026] [security2:error] [pid 955873:tid 956084] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0NQAAAVs"]
[Thu Sep 17 15:05:39.518515 2026] [security2:error] [pid 955873:tid 956110] [client 20.244.34.24:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0NgAAAXU"], referer: binance.com
[Thu Sep 17 15:05:39.537399 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/production/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0NwAAATg"]
[Thu Sep 17 15:05:39.779007 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:58512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.chadstall.com"] [uri "/___proxy_subdomain_cpanel/config/app/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0QgAAAX0"]
[Thu Sep 17 15:05:39.809450 2026] [security2:error] [pid 955873:tid 956005] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0RQAAAQw"]
[Thu Sep 17 15:05:39.822632 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0OAAAAR4"]
[Thu Sep 17 15:05:39.822675 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0OAAAAR4"]
[Thu Sep 17 15:05:39.929414 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0QAAAAXc"]
[Thu Sep 17 15:05:39.929447 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0QAAAAXc"]
[Thu Sep 17 15:05:39.963471 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionModelInterface.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0RwAAAUs"]
[Thu Sep 17 15:05:39.963603 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:58442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionModelInterface.php"] [unique_id "aqxWIxFTPRVSLOsRVhr0RwAAAUs"]
[Thu Sep 17 15:05:39.965198 2026] [security2:error] [pid 955873:tid 956052] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWIxFTPRVSLOsRVhr0SAAAATs"]
[Thu Sep 17 15:05:39.992909 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxWIxFTPRVSLOsRVhr0PAAAATo"]
[Thu Sep 17 15:05:40.012956 2026] [security2:error] [pid 955873:tid 956008] [client 34.166.129.237:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0SQAAAQ8"]
[Thu Sep 17 15:05:40.072381 2026] [security2:error] [pid 955873:tid 956012] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0SgAAARM"]
[Thu Sep 17 15:05:40.121403 2026] [security2:error] [pid 955873:tid 956088] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0SwAAAV8"]
[Thu Sep 17 15:05:40.279774 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionOperationModelInterface.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0UgAAAWA"]
[Thu Sep 17 15:05:40.279884 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpeechConversionOperationModelInterface.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0UgAAAWA"]
[Thu Sep 17 15:05:40.317316 2026] [security2:error] [pid 955873:tid 956080] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0VgAAAVc"]
[Thu Sep 17 15:05:40.321694 2026] [security2:error] [pid 955873:tid 956035] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0TgAAASo"]
[Thu Sep 17 15:05:40.321725 2026] [security2:error] [pid 955873:tid 956035] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0TgAAASo"]
[Thu Sep 17 15:05:40.355895 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0VwAAAUY"]
[Thu Sep 17 15:05:40.365708 2026] [security2:error] [pid 955873:tid 956046] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/upload/image/"] [unique_id "aqxWJBFTPRVSLOsRVhr0TAAAATU"]
[Thu Sep 17 15:05:40.478771 2026] [security2:error] [pid 955873:tid 956120] [client 34.178.167.214:53054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0WQAAAX8"]
[Thu Sep 17 15:05:40.575204 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/"] [unique_id "aqxWJBFTPRVSLOsRVhr0XQAAATE"]
[Thu Sep 17 15:05:40.638626 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0XwAAARU"]
[Thu Sep 17 15:05:40.695732 2026] [security2:error] [pid 955873:tid 956094] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0XAAAAWU"]
[Thu Sep 17 15:05:40.695751 2026] [security2:error] [pid 955873:tid 956094] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0XAAAAWU"]
[Thu Sep 17 15:05:40.706185 2026] [security2:error] [pid 955873:tid 956086] [client 34.166.129.237:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/info.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0YAAAAV0"]
[Thu Sep 17 15:05:40.733289 2026] [security2:error] [pid 955873:tid 956059] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/assets/images/"] [unique_id "aqxWJBFTPRVSLOsRVhr0WgAAAUI"]
[Thu Sep 17 15:05:40.763698 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/"] [unique_id "aqxWJBFTPRVSLOsRVhr0YQAAAVY"]
[Thu Sep 17 15:05:40.767912 2026] [security2:error] [pid 955873:tid 956124] [client 154.190.208.131:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0ZAAAAYM"]
[Thu Sep 17 15:05:40.775728 2026] [security2:error] [pid 955873:tid 956124] [client 154.190.208.131:42290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0ZAAAAYM"]
[Thu Sep 17 15:05:40.913439 2026] [security2:error] [pid 955873:tid 956021] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWJBFTPRVSLOsRVhr0bgAAARw"]
[Thu Sep 17 15:05:40.929954 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/wp-includes/php-ai-client/src/Providers/Models/"] [unique_id "aqxWJBFTPRVSLOsRVhr0cQAAAXk"]
[Thu Sep 17 15:05:40.996980 2026] [authz_core:error] [pid 955873:tid 956006] [client 4.240.114.86:51574] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-admin/maint/error_log, referer: binance.com
[Thu Sep 17 15:05:41.051365 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0cAAAAVg"]
[Thu Sep 17 15:05:41.051387 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJBFTPRVSLOsRVhr0cAAAAVg"]
[Thu Sep 17 15:05:41.059085 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:52691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0cwAAAYI"]
[Thu Sep 17 15:05:41.059164 2026] [security2:error] [pid 955873:tid 956123] [client 45.169.98.18:52691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0cwAAAYI"]
[Thu Sep 17 15:05:41.073530 2026] [security2:error] [pid 955873:tid 956003] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Public/"] [unique_id "aqxWJBFTPRVSLOsRVhr0bAAAAQo"]
[Thu Sep 17 15:05:41.094264 2026] [security2:error] [pid 955873:tid 956022] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0dQAAAR0"]
[Thu Sep 17 15:05:41.189844 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0dwAAAU4"]
[Thu Sep 17 15:05:41.261060 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0dAAAATA"]
[Thu Sep 17 15:05:41.261082 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0dAAAATA"]
[Thu Sep 17 15:05:41.390057 2026] [security2:error] [pid 955873:tid 956049] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0fwAAATg"]
[Thu Sep 17 15:05:41.391210 2026] [security2:error] [pid 955873:tid 956110] [client 74.7.228.3:41556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "mail.cqf.sfu.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWJRFTPRVSLOsRVhr0fgAAAXU"]
[Thu Sep 17 15:05:41.396808 2026] [security2:error] [pid 955873:tid 956019] [client 34.166.129.237:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/php.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0gAAAARo"]
[Thu Sep 17 15:05:41.409930 2026] [security2:error] [pid 955873:tid 956075] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0fAAAAVI"]
[Thu Sep 17 15:05:41.409948 2026] [security2:error] [pid 955873:tid 956075] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0fAAAAVI"]
[Thu Sep 17 15:05:41.420272 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/"] [unique_id "aqxWJRFTPRVSLOsRVhr0gQAAAYc"]
[Thu Sep 17 15:05:41.458745 2026] [security2:error] [pid 955873:tid 956009] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/vendor/"] [unique_id "aqxWJRFTPRVSLOsRVhr0egAAARA"]
[Thu Sep 17 15:05:41.464530 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0gwAAAQw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:05:41.469695 2026] [security2:error] [pid 955873:tid 956118] [client 74.7.228.3:41556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.cqf.sfu.mybluehost.me"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxWJRFTPRVSLOsRVhr0ggAAAX0"], referer: https://mail.cqf.sfu.mybluehost.me/robots.txt
[Thu Sep 17 15:05:41.576287 2026] [security2:error] [pid 955873:tid 956064] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0hQAAAUc"]
[Thu Sep 17 15:05:41.584860 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/"] [unique_id "aqxWJRFTPRVSLOsRVhr0hAAAAT4"]
[Thu Sep 17 15:05:41.734440 2026] [security2:error] [pid 955873:tid 956007] [client 186.105.232.15:65073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iwAAAQ4"]
[Thu Sep 17 15:05:41.734538 2026] [security2:error] [pid 955873:tid 956007] [client 186.105.232.15:65073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iwAAAQ4"]
[Thu Sep 17 15:05:41.741710 2026] [security2:error] [pid 955873:tid 956052] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0jAAAATs"]
[Thu Sep 17 15:05:41.742489 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/"] [unique_id "aqxWJRFTPRVSLOsRVhr0jQAAAQs"]
[Thu Sep 17 15:05:41.775747 2026] [security2:error] [pid 955873:tid 956073] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWJRFTPRVSLOsRVhr0kQAAAVA"]
[Thu Sep 17 15:05:41.779049 2026] [security2:error] [pid 955873:tid 956044] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iAAAATM"]
[Thu Sep 17 15:05:41.779067 2026] [security2:error] [pid 955873:tid 956044] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0iAAAATM"]
[Thu Sep 17 15:05:41.807051 2026] [security2:error] [pid 955873:tid 956082] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/local/"] [unique_id "aqxWJRFTPRVSLOsRVhr0hgAAAVk"]
[Thu Sep 17 15:05:41.926160 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lAAAARI"]
[Thu Sep 17 15:05:41.926241 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:61952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lAAAARI"]
[Thu Sep 17 15:05:42.020569 2026] [security2:error] [pid 955873:tid 956048] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0mAAAATc"]
[Thu Sep 17 15:05:42.022373 2026] [security2:error] [pid 955873:tid 956080] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0mQAAAVc"]
[Thu Sep 17 15:05:42.098773 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.129.237:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/i.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0mgAAASY"]
[Thu Sep 17 15:05:42.116556 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0kwAAARM"]
[Thu Sep 17 15:05:42.116575 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0kwAAARM"]
[Thu Sep 17 15:05:42.123891 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lwAAAXI"]
[Thu Sep 17 15:05:42.123924 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJRFTPRVSLOsRVhr0lwAAAXI"]
[Thu Sep 17 15:05:42.151390 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/modules/"] [unique_id "aqxWJRFTPRVSLOsRVhr0lQAAAX4"]
[Thu Sep 17 15:05:42.257892 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0oQAAASg"]
[Thu Sep 17 15:05:42.257988 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:56600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0oQAAASg"]
[Thu Sep 17 15:05:42.276432 2026] [security2:error] [pid 955873:tid 956120] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0owAAAX8"]
[Thu Sep 17 15:05:42.295682 2026] [security2:error] [pid 955873:tid 956050] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0pgAAATk"]
[Thu Sep 17 15:05:42.378489 2026] [security2:error] [pid 955873:tid 956057] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.essencestudiosdance.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "aqxWJhFTPRVSLOsRVhr0qgAAAUA"]
[Thu Sep 17 15:05:42.406003 2026] [security2:error] [pid 955873:tid 956072] [client 74.7.228.63:47760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.essencestudiosdance.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxWJhFTPRVSLOsRVhr0pAABTz8"]
[Thu Sep 17 15:05:42.430245 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0rAAAAXs"]
[Thu Sep 17 15:05:42.552022 2026] [security2:error] [pid 955873:tid 956014] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0qwAAARU"]
[Thu Sep 17 15:05:42.552045 2026] [security2:error] [pid 955873:tid 956014] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0qwAAARU"]
[Thu Sep 17 15:05:42.566789 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:56610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationOperationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0rQAAAWo"]
[Thu Sep 17 15:05:42.566905 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:56610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationOperationModelInterface.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0rQAAAWo"]
[Thu Sep 17 15:05:42.570985 2026] [security2:error] [pid 955873:tid 956113] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0rgAAAXg"]
[Thu Sep 17 15:05:42.573470 2026] [security2:error] [pid 955873:tid 956092] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Site/"] [unique_id "aqxWJhFTPRVSLOsRVhr0qAAAAWM"]
[Thu Sep 17 15:05:42.594017 2026] [security2:error] [pid 955873:tid 956079] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0rwAAAVY"]
[Thu Sep 17 15:05:42.762739 2026] [security2:error] [pid 955873:tid 956085] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0tQAAAVw"]
[Thu Sep 17 15:05:42.782506 2026] [security2:error] [pid 955873:tid 956086] [client 34.166.129.237:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/pi.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0twAAAV0"]
[Thu Sep 17 15:05:42.848008 2026] [security2:error] [pid 955873:tid 956053] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWJhFTPRVSLOsRVhr0xAAAATw"]
[Thu Sep 17 15:05:42.855290 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:56618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/"] [unique_id "aqxWJhFTPRVSLOsRVhr0xQAAAVg"]
[Thu Sep 17 15:05:42.891169 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0tAAAASc"]
[Thu Sep 17 15:05:42.891193 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJhFTPRVSLOsRVhr0tAAAASc"]
[Thu Sep 17 15:05:42.898599 2026] [security2:error] [pid 955873:tid 956028] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/system/"] [unique_id "aqxWJhFTPRVSLOsRVhr0sgAAASM"]
[Thu Sep 17 15:05:43.049568 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr0xwAAAWg"]
[Thu Sep 17 15:05:43.053106 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/"] [unique_id "aqxWJxFTPRVSLOsRVhr0xgAAAR0"]
[Thu Sep 17 15:05:43.124961 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr0ygAAAXQ"]
[Thu Sep 17 15:05:43.191098 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/wp-includes/php-ai-client/src/Providers/"] [unique_id "aqxWJxFTPRVSLOsRVhr0ywAAAXo"]
[Thu Sep 17 15:05:43.227018 2026] [security2:error] [pid 955873:tid 956108] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr0zAAAAXM"]
[Thu Sep 17 15:05:43.265001 2026] [security2:error] [pid 955873:tid 956110] [client 45.146.54.111:40125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00AAAAXU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:43.367953 2026] [security2:error] [pid 955873:tid 955948] [remote 45.239.10.81:37646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr0zwABW0o"]
[Thu Sep 17 15:05:43.405686 2026] [security2:error] [pid 955873:tid 956087] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr01AAAAV4"]
[Thu Sep 17 15:05:43.466341 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr01gAAAWQ"]
[Thu Sep 17 15:05:43.498162 2026] [security2:error] [pid 955873:tid 956049] [client 34.166.129.237:44576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/pinfo.php"] [unique_id "aqxWJxFTPRVSLOsRVhr01wAAATg"]
[Thu Sep 17 15:05:43.530954 2026] [security2:error] [pid 955873:tid 956025] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr01QAAASA"]
[Thu Sep 17 15:05:43.530976 2026] [security2:error] [pid 955873:tid 956025] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr01QAAASA"]
[Thu Sep 17 15:05:43.591384 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00wAAAUM"]
[Thu Sep 17 15:05:43.591405 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00wAAAUM"]
[Thu Sep 17 15:05:43.683316 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr02gAAAXc"]
[Thu Sep 17 15:05:43.720504 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/template/"] [unique_id "aqxWJxFTPRVSLOsRVhr0yAAAAXA"]
[Thu Sep 17 15:05:43.731220 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr02wAAAQ4"]
[Thu Sep 17 15:05:43.737751 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleImageGenerationModel.php"] [unique_id "aqxWJxFTPRVSLOsRVhr03AAAAQs"]
[Thu Sep 17 15:05:43.737822 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleImageGenerationModel.php"] [unique_id "aqxWJxFTPRVSLOsRVhr03AAAAQs"]
[Thu Sep 17 15:05:43.870930 2026] [security2:error] [pid 955873:tid 956020] [client 194.163.128.162:54845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxWJxFTPRVSLOsRVhr04AAAARs"], referer: binance.com
[Thu Sep 17 15:05:43.957584 2026] [security2:error] [pid 955873:tid 956088] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr05QAAAV8"]
[Thu Sep 17 15:05:43.984082 2026] [security2:error] [pid 955873:tid 956103] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWJxFTPRVSLOsRVhr05gAAAW4"]
[Thu Sep 17 15:05:44.022604 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleModelMetadataDirectory.php"] [unique_id "aqxWKBFTPRVSLOsRVhr05wAAARM"]
[Thu Sep 17 15:05:44.022693 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:56632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleModelMetadataDirectory.php"] [unique_id "aqxWKBFTPRVSLOsRVhr05wAAARM"]
[Thu Sep 17 15:05:44.052420 2026] [security2:error] [pid 955873:tid 956056] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr05AAAAT8"]
[Thu Sep 17 15:05:44.052437 2026] [security2:error] [pid 955873:tid 956056] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr05AAAAT8"]
[Thu Sep 17 15:05:44.188306 2026] [security2:error] [pid 955873:tid 956119] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr06AAAAX4"]
[Thu Sep 17 15:05:44.202804 2026] [security2:error] [pid 955873:tid 956111] [client 34.166.129.237:44582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/test.php"] [unique_id "aqxWKBFTPRVSLOsRVhr06QAAAXY"]
[Thu Sep 17 15:05:44.232934 2026] [security2:error] [pid 955873:tid 956066] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr06gAAAUk"]
[Thu Sep 17 15:05:44.255616 2026] [security2:error] [pid 955873:tid 956011] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/shop/"] [unique_id "aqxWJxFTPRVSLOsRVhr04gAAARI"]
[Thu Sep 17 15:05:44.312828 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleTextGenerationModel.php"] [unique_id "aqxWKBFTPRVSLOsRVhr07QAAATk"]
[Thu Sep 17 15:05:44.312896 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompatibleTextGenerationModel.php"] [unique_id "aqxWKBFTPRVSLOsRVhr07QAAATk"]
[Thu Sep 17 15:05:44.495561 2026] [security2:error] [pid 955873:tid 956036] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr09AAAASs"]
[Thu Sep 17 15:05:44.507749 2026] [security2:error] [pid 955873:tid 956117] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr09QAAAXw"]
[Thu Sep 17 15:05:44.577097 2026] [security2:error] [pid 955873:tid 956122] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr08wAAAYE"]
[Thu Sep 17 15:05:44.577126 2026] [security2:error] [pid 955873:tid 956122] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr08wAAAYE"]
[Thu Sep 17 15:05:44.623764 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ProviderRegistry.php"] [unique_id "aqxWKBFTPRVSLOsRVhr09gAAARY"]
[Thu Sep 17 15:05:44.623853 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:56658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Providers/ProviderRegistry.php"] [unique_id "aqxWKBFTPRVSLOsRVhr09gAAARY"]
[Thu Sep 17 15:05:44.675437 2026] [security2:error] [pid 955873:tid 956062] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/files/"] [unique_id "aqxWKBFTPRVSLOsRVhr07wAAAUU"]
[Thu Sep 17 15:05:44.697869 2026] [security2:error] [pid 955873:tid 956099] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr09wAAAWo"]
[Thu Sep 17 15:05:44.773435 2026] [security2:error] [pid 955873:tid 956092] [client 20.244.34.24:58117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxWKBFTPRVSLOsRVhr0-AAAAWM"], referer: binance.com
[Thu Sep 17 15:05:44.783286 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr0-QAAAUI"]
[Thu Sep 17 15:05:44.856398 2026] [security2:error] [pid 955873:tid 956067] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWKBFTPRVSLOsRVhr0_AAAAUo"]
[Thu Sep 17 15:05:44.916094 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKBFTPRVSLOsRVhr1BwAAATQ"]
[Thu Sep 17 15:05:45.031976 2026] [security2:error] [pid 955873:tid 956096] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1CwAAAWc"]
[Thu Sep 17 15:05:45.059921 2026] [security2:error] [pid 955873:tid 956043] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1DQAAATI"]
[Thu Sep 17 15:05:45.091192 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKRFTPRVSLOsRVhr1DAAAASI"]
[Thu Sep 17 15:05:45.106752 2026] [security2:error] [pid 955873:tid 956085] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr1AgAAAVw"]
[Thu Sep 17 15:05:45.106775 2026] [security2:error] [pid 955873:tid 956085] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKBFTPRVSLOsRVhr1AgAAAVw"]
[Thu Sep 17 15:05:45.107957 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/editor/"] [unique_id "aqxWKBFTPRVSLOsRVhr0_QAAAUY"]
[Thu Sep 17 15:05:45.217610 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.129.237:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/p.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1FAAAAVI"]
[Thu Sep 17 15:05:45.221263 2026] [security2:error] [pid 955873:tid 956087] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1FQAAAV4"]
[Thu Sep 17 15:05:45.235704 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/wp-includes/php-ai-client/src/"] [unique_id "aqxWKRFTPRVSLOsRVhr1FgAAASU"]
[Thu Sep 17 15:05:45.335374 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1GwAAAQw"]
[Thu Sep 17 15:05:45.385581 2026] [security2:error] [pid 955873:tid 956052] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1IgAAATs"]
[Thu Sep 17 15:05:45.416695 2026] [security2:error] [pid 955873:tid 956098] [client 4.240.114.86:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-login.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1HgAAAWk"], referer: binance.com
[Thu Sep 17 15:05:45.446970 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1GgAAAXE"]
[Thu Sep 17 15:05:45.446991 2026] [security2:error] [pid 955873:tid 956106] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1GgAAAXE"]
[Thu Sep 17 15:05:45.549502 2026] [security2:error] [pid 955873:tid 956049] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/include/"] [unique_id "aqxWKRFTPRVSLOsRVhr1FwAAATg"]
[Thu Sep 17 15:05:45.554914 2026] [security2:error] [pid 955873:tid 956088] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1IwAAAV8"]
[Thu Sep 17 15:05:45.610920 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1JQAAAW4"]
[Thu Sep 17 15:05:45.653531 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1IQAAAQ4"]
[Thu Sep 17 15:05:45.653553 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1IQAAAQ4"]
[Thu Sep 17 15:05:45.794008 2026] [security2:error] [pid 955873:tid 956066] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1KwAAAUk"]
[Thu Sep 17 15:05:45.825381 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/"] [unique_id "aqxWKRFTPRVSLOsRVhr1LwAAAUs"]
[Thu Sep 17 15:05:45.878948 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1KgAAAX4"]
[Thu Sep 17 15:05:45.878972 2026] [security2:error] [pid 955873:tid 956119] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1KgAAAX4"]
[Thu Sep 17 15:05:45.884811 2026] [security2:error] [pid 955873:tid 956042] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1MwAAATE"]
[Thu Sep 17 15:05:45.909324 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.129.237:44596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/debug.php"] [unique_id "aqxWKRFTPRVSLOsRVhr1NAAAAXI"]
[Thu Sep 17 15:05:45.909604 2026] [security2:error] [pid 955873:tid 956037] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/Assets/"] [unique_id "aqxWKRFTPRVSLOsRVhr1JwAAASw"]
[Thu Sep 17 15:05:45.972756 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWKRFTPRVSLOsRVhr1NgAAAWE"]
[Thu Sep 17 15:05:45.989301 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/"] [unique_id "aqxWKRFTPRVSLOsRVhr1NwAAAVM"]
[Thu Sep 17 15:05:46.136049 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKhFTPRVSLOsRVhr1OwAAAVo"]
[Thu Sep 17 15:05:46.160801 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1PAAAASk"]
[Thu Sep 17 15:05:46.184529 2026] [security2:error] [pid 955873:tid 956099] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1PQAAAWo"]
[Thu Sep 17 15:05:46.215955 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1OgAAAVQ"]
[Thu Sep 17 15:05:46.215973 2026] [security2:error] [pid 955873:tid 956077] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1OgAAAVQ"]
[Thu Sep 17 15:05:46.355043 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/images/stories/"] [unique_id "aqxWKhFTPRVSLOsRVhr1OAAAAUE"]
[Thu Sep 17 15:05:46.397738 2026] [security2:error] [pid 955873:tid 956067] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1QgAAAUo"]
[Thu Sep 17 15:05:46.438798 2026] [security2:error] [pid 955873:tid 956086] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1QwAAAV0"]
[Thu Sep 17 15:05:46.491019 2026] [security2:error] [pid 955873:tid 956120] [client 216.73.163.58:27915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1RAAAAX8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:46.498097 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1PgAAAWI"]
[Thu Sep 17 15:05:46.498117 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1PgAAAWI"]
[Thu Sep 17 15:05:46.561949 2026] [security2:error] [pid 955873:tid 956121] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1SAAAAYA"]
[Thu Sep 17 15:05:46.622225 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.129.237:44600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1SgAAAUI"]
[Thu Sep 17 15:05:46.645581 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/ResultInterface.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1SwAAARE"]
[Thu Sep 17 15:05:46.645722 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:56662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Contracts/ResultInterface.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1SwAAARE"]
[Thu Sep 17 15:05:46.681894 2026] [security2:error] [pid 955873:tid 956069] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1RwAAAUw"]
[Thu Sep 17 15:05:46.681917 2026] [security2:error] [pid 955873:tid 956069] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1RwAAAUw"]
[Thu Sep 17 15:05:46.714804 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1TAAAAWU"]
[Thu Sep 17 15:05:46.761206 2026] [security2:error] [pid 955873:tid 956045] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/plugins/"] [unique_id "aqxWKhFTPRVSLOsRVhr1RQAAATQ"]
[Thu Sep 17 15:05:46.823876 2026] [security2:error] [pid 955873:tid 956053] [client 66.249.66.45:42489] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "memorytrackspodcast.com"] [uri "/robots.txt"] [unique_id "aqxWKhFTPRVSLOsRVhr1UAAAATw"]
[Thu Sep 17 15:05:46.834548 2026] [security2:error] [pid 955873:tid 956027] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1UwAAASI"]
[Thu Sep 17 15:05:46.943898 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1VgAAAWc"]
[Thu Sep 17 15:05:46.944848 2026] [security2:error] [pid 955873:tid 956096] [client 185.55.149.49:58168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1VgAAAWc"]
[Thu Sep 17 15:05:46.981363 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/"] [unique_id "aqxWKhFTPRVSLOsRVhr1WQAAAWA"]
[Thu Sep 17 15:05:46.990210 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWKhFTPRVSLOsRVhr1WwAAAU4"]
[Thu Sep 17 15:05:47.067931 2026] [security2:error] [pid 955873:tid 956104] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1XAAAAW8"]
[Thu Sep 17 15:05:47.117532 2026] [security2:error] [pid 955873:tid 956097] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1WgAAAWg"]
[Thu Sep 17 15:05:47.117554 2026] [security2:error] [pid 955873:tid 956097] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKhFTPRVSLOsRVhr1WgAAAWg"]
[Thu Sep 17 15:05:47.150994 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/"] [unique_id "aqxWKxFTPRVSLOsRVhr1XgAAAXU"]
[Thu Sep 17 15:05:47.151253 2026] [security2:error] [pid 955873:tid 956128] [client 74.7.230.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rallyspin.com"] [uri "/index.php"] [unique_id "aqxWJxFTPRVSLOsRVhr00gABhz0"]
[Thu Sep 17 15:05:47.204182 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/php/"] [unique_id "aqxWKhFTPRVSLOsRVhr1VwAAAYQ"]
[Thu Sep 17 15:05:47.221869 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1XwAAAR4"]
[Thu Sep 17 15:05:47.264791 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1YwAAAXc"]
[Thu Sep 17 15:05:47.320401 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:56676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWKxFTPRVSLOsRVhr1ZAAAAVs"]
[Thu Sep 17 15:05:47.354028 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.129.237:44608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1aAAAAXk"]
[Thu Sep 17 15:05:47.412983 2026] [autoindex:error] [pid 955873:tid 956004] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:47.413697 2026] [security2:error] [pid 955873:tid 956004] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/css/"] [unique_id "aqxWKxFTPRVSLOsRVhr1aQAAAQs"]
[Thu Sep 17 15:05:47.422923 2026] [security2:error] [pid 955873:tid 956118] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1bQAAAX0"]
[Thu Sep 17 15:05:47.540732 2026] [security2:error] [pid 955873:tid 956044] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1cgAAATM"]
[Thu Sep 17 15:05:47.586736 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1dgAAAQ4"]
[Thu Sep 17 15:05:47.653224 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1cQAAAW4"]
[Thu Sep 17 15:05:47.653249 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1cQAAAW4"]
[Thu Sep 17 15:05:47.806725 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1eAAAARg"]
[Thu Sep 17 15:05:47.806751 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1eAAAARg"]
[Thu Sep 17 15:05:47.817740 2026] [security2:error] [pid 955873:tid 956033] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1fQAAASg"]
[Thu Sep 17 15:05:47.824321 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/Candidate.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1fgAAATE"]
[Thu Sep 17 15:05:47.824402 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/Candidate.php"] [unique_id "aqxWKxFTPRVSLOsRVhr1fgAAATE"]
[Thu Sep 17 15:05:47.827007 2026] [security2:error] [pid 955873:tid 956048] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxWKxFTPRVSLOsRVhr1cwAAATc"]
[Thu Sep 17 15:05:47.873587 2026] [security2:error] [pid 955873:tid 956072] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWKxFTPRVSLOsRVhr1gQAAAU8"]
[Thu Sep 17 15:05:48.017305 2026] [autoindex:error] [pid 955873:tid 956117] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:48.017743 2026] [security2:error] [pid 955873:tid 956117] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLBFTPRVSLOsRVhr1hgAAAXw"]
[Thu Sep 17 15:05:48.023626 2026] [security2:error] [pid 955873:tid 956036] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/cache/"] [unique_id "aqxWKxFTPRVSLOsRVhr1hAAAASs"]
[Thu Sep 17 15:05:48.053920 2026] [security2:error] [pid 955873:tid 956068] [client 34.166.129.237:44612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1hwAAAUs"]
[Thu Sep 17 15:05:48.091497 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1jgAAASk"]
[Thu Sep 17 15:05:48.107670 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:56688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/GenerativeAiResult.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1jwAAAUU"]
[Thu Sep 17 15:05:48.107750 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:56688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/GenerativeAiResult.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1jwAAAUU"]
[Thu Sep 17 15:05:48.150981 2026] [security2:error] [pid 955873:tid 956077] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1kgAAAVQ"]
[Thu Sep 17 15:05:48.170735 2026] [security2:error] [pid 955873:tid 956012] [client 216.73.163.59:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1kAAAARM"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:48.226812 2026] [autoindex:error] [pid 955873:tid 956130] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:48.227260 2026] [security2:error] [pid 955873:tid 956130] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/maint/"] [unique_id "aqxWLBFTPRVSLOsRVhr1kwAAAYk"]
[Thu Sep 17 15:05:48.368772 2026] [security2:error] [pid 955873:tid 956079] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1mAAAAVY"]
[Thu Sep 17 15:05:48.392755 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/TokenUsage.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1mwAAAYA"]
[Thu Sep 17 15:05:48.392831 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:56702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/DTO/TokenUsage.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1mwAAAYA"]
[Thu Sep 17 15:05:48.468428 2026] [security2:error] [pid 955873:tid 956010] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1nQAAARE"]
[Thu Sep 17 15:05:48.470582 2026] [security2:error] [pid 955873:tid 956069] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1ngAAAUw"]
[Thu Sep 17 15:05:48.522067 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1nAAAASc"]
[Thu Sep 17 15:05:48.522086 2026] [security2:error] [pid 955873:tid 956032] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1nAAAASc"]
[Thu Sep 17 15:05:48.551738 2026] [security2:error] [pid 955873:tid 956092] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxWLBFTPRVSLOsRVhr1mQAAAWM"]
[Thu Sep 17 15:05:48.623928 2026] [security2:error] [pid 955873:tid 956053] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1ogAAATw"]
[Thu Sep 17 15:05:48.689694 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/"] [unique_id "aqxWLBFTPRVSLOsRVhr1pwAAAWA"]
[Thu Sep 17 15:05:48.717515 2026] [security2:error] [pid 955873:tid 956115] [client 34.35.44.204:45802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1qAAAAXo"]
[Thu Sep 17 15:05:48.744975 2026] [security2:error] [pid 955873:tid 956123] [client 34.166.129.237:44624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWLBFTPRVSLOsRVhr1qQAAAYI"]
[Thu Sep 17 15:05:48.786698 2026] [autoindex:error] [pid 955873:tid 956029] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:48.787140 2026] [security2:error] [pid 955873:tid 956029] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLBFTPRVSLOsRVhr1rAAAASQ"]
[Thu Sep 17 15:05:48.788148 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1rQAAAWg"]
[Thu Sep 17 15:05:48.794848 2026] [security2:error] [pid 955873:tid 956071] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/assets/"] [unique_id "aqxWLBFTPRVSLOsRVhr1qgAAAU4"]
[Thu Sep 17 15:05:48.842488 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/"] [unique_id "aqxWLBFTPRVSLOsRVhr1sAAAAYc"]
[Thu Sep 17 15:05:48.943049 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWLBFTPRVSLOsRVhr1tgAAAR4"]
[Thu Sep 17 15:05:49.006652 2026] [autoindex:error] [pid 955873:tid 956047] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.007144 2026] [security2:error] [pid 955873:tid 956047] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLBFTPRVSLOsRVhr1uQAAATY"]
[Thu Sep 17 15:05:49.009110 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxWLBFTPRVSLOsRVhr1twAAAXc"]
[Thu Sep 17 15:05:49.013821 2026] [security2:error] [pid 955873:tid 956028] [client 4.240.114.86:55860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-login.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1ugAAASM"], referer: binance.com
[Thu Sep 17 15:05:49.081628 2026] [security2:error] [pid 955873:tid 956085] [client 45.146.54.112:40837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1vgAAAVw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:49.103579 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/wp-includes/php-ai-client/src/Results/"] [unique_id "aqxWLRFTPRVSLOsRVhr1wAAAAQs"]
[Thu Sep 17 15:05:49.122506 2026] [security2:error] [pid 955873:tid 956061] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr1wgAAAUQ"]
[Thu Sep 17 15:05:49.303431 2026] [autoindex:error] [pid 955873:tid 956040] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.303911 2026] [security2:error] [pid 955873:tid 956040] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLRFTPRVSLOsRVhr1ygAAAS8"]
[Thu Sep 17 15:05:49.353149 2026] [security2:error] [pid 955873:tid 956103] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr1ywAAAW4"]
[Thu Sep 17 15:05:49.392088 2026] [security2:error] [pid 955873:tid 956025] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/block-supports/"] [unique_id "aqxWLRFTPRVSLOsRVhr1xAAAASA"]
[Thu Sep 17 15:05:49.442774 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1yQAAASE"]
[Thu Sep 17 15:05:49.442794 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLRFTPRVSLOsRVhr1yQAAASE"]
[Thu Sep 17 15:05:49.449751 2026] [security2:error] [pid 955873:tid 956102] [client 34.166.129.237:44626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWLRFTPRVSLOsRVhr10gAAAW0"]
[Thu Sep 17 15:05:49.553182 2026] [security2:error] [pid 955873:tid 956017] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr11AAAARg"]
[Thu Sep 17 15:05:49.556515 2026] [security2:error] [pid 955873:tid 956082] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr11QAAAVk"]
[Thu Sep 17 15:05:49.586454 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/FinishReasonEnum.php"] [unique_id "aqxWLRFTPRVSLOsRVhr12AAAATE"]
[Thu Sep 17 15:05:49.586565 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:56704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Results/Enums/FinishReasonEnum.php"] [unique_id "aqxWLRFTPRVSLOsRVhr12AAAATE"]
[Thu Sep 17 15:05:49.617316 2026] [autoindex:error] [pid 955873:tid 956080] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.618065 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLRFTPRVSLOsRVhr12QAAAVc"]
[Thu Sep 17 15:05:49.634905 2026] [security2:error] [pid 955873:tid 956033] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/html-api/"] [unique_id "aqxWLRFTPRVSLOsRVhr11gAAASg"]
[Thu Sep 17 15:05:49.696413 2026] [security2:error] [pid 955873:tid 956117] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr14AAAAXw"]
[Thu Sep 17 15:05:49.809230 2026] [autoindex:error] [pid 955873:tid 956068] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:49.809744 2026] [security2:error] [pid 955873:tid 956068] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLRFTPRVSLOsRVhr14wAAAUs"]
[Thu Sep 17 15:05:49.811682 2026] [security2:error] [pid 955873:tid 956070] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/js/"] [unique_id "aqxWLRFTPRVSLOsRVhr14QAAAU0"]
[Thu Sep 17 15:05:49.835750 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr15AAAAWs"]
[Thu Sep 17 15:05:49.844253 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWLRFTPRVSLOsRVhr15QAAATk"]
[Thu Sep 17 15:05:49.871423 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/"] [unique_id "aqxWLRFTPRVSLOsRVhr15gAAARM"]
[Thu Sep 17 15:05:49.935205 2026] [security2:error] [pid 955873:tid 956058] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWLRFTPRVSLOsRVhr16QAAAUE"]
[Thu Sep 17 15:05:50.001999 2026] [security2:error] [pid 955873:tid 956086] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWLhFTPRVSLOsRVhr17gAAAV0"]
[Thu Sep 17 15:05:50.018675 2026] [autoindex:error] [pid 955873:tid 956116] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:50.019155 2026] [security2:error] [pid 955873:tid 956116] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLhFTPRVSLOsRVhr17wAAAXs"]
[Thu Sep 17 15:05:50.039282 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/"] [unique_id "aqxWLhFTPRVSLOsRVhr18AAAAVY"]
[Thu Sep 17 15:05:50.107184 2026] [security2:error] [pid 955873:tid 956091] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/php-compat/"] [unique_id "aqxWLRFTPRVSLOsRVhr17AAAAWI"]
[Thu Sep 17 15:05:50.114107 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr18wAAAWU"]
[Thu Sep 17 15:05:50.147334 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.129.237:44640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWLhFTPRVSLOsRVhr19gAAAVo"]
[Thu Sep 17 15:05:50.171269 2026] [security2:error] [pid 955873:tid 956027] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr1-gAAASI"]
[Thu Sep 17 15:05:50.198460 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/wp-includes/php-ai-client/src/"] [unique_id "aqxWLhFTPRVSLOsRVhr1_AAAAWA"]
[Thu Sep 17 15:05:50.349346 2026] [autoindex:error] [pid 955873:tid 956029] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:50.349842 2026] [security2:error] [pid 955873:tid 956029] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLhFTPRVSLOsRVhr2AQAAASQ"]
[Thu Sep 17 15:05:50.351997 2026] [security2:error] [pid 955873:tid 956096] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxWLhFTPRVSLOsRVhr1_wAAAWc"]
[Thu Sep 17 15:05:50.356947 2026] [security2:error] [pid 955873:tid 956104] [client 20.244.34.24:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2AwAAAW8"], referer: binance.com
[Thu Sep 17 15:05:50.361796 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWLhFTPRVSLOsRVhr2BAAAAU4"]
[Thu Sep 17 15:05:50.390130 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2BQAAAQw"]
[Thu Sep 17 15:05:50.395316 2026] [security2:error] [pid 955873:tid 956021] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2BgAAARw"]
[Thu Sep 17 15:05:50.532225 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2AgAAAWg"]
[Thu Sep 17 15:05:50.532250 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2AgAAAWg"]
[Thu Sep 17 15:05:50.606408 2026] [security2:error] [pid 955873:tid 956108] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2DAAAAXM"]
[Thu Sep 17 15:05:50.660315 2026] [security2:error] [pid 955873:tid 956055] [client 162.241.226.11:17456] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWLhFTPRVSLOsRVhr2DwAAAT4"]
[Thu Sep 17 15:05:50.665390 2026] [autoindex:error] [pid 955873:tid 956084] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:50.666090 2026] [security2:error] [pid 955873:tid 956084] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLhFTPRVSLOsRVhr2EgAAAVs"]
[Thu Sep 17 15:05:50.670555 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2EwAAAXQ"]
[Thu Sep 17 15:05:50.676513 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/"] [unique_id "aqxWLhFTPRVSLOsRVhr2FAAAAWk"]
[Thu Sep 17 15:05:50.710007 2026] [security2:error] [pid 955873:tid 956124] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/pomo/"] [unique_id "aqxWLhFTPRVSLOsRVhr2DQAAAYM"]
[Thu Sep 17 15:05:50.846087 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/"] [unique_id "aqxWLhFTPRVSLOsRVhr2GgAAAV8"]
[Thu Sep 17 15:05:50.861732 2026] [security2:error] [pid 955873:tid 956106] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2HQAAAXE"]
[Thu Sep 17 15:05:50.947391 2026] [security2:error] [pid 955873:tid 956026] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWLhFTPRVSLOsRVhr2JQAAASE"]
[Thu Sep 17 15:05:50.989202 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/wp-includes/php-ai-client/src/Tools/"] [unique_id "aqxWLhFTPRVSLOsRVhr2JgAAARk"]
[Thu Sep 17 15:05:51.056711 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2KAAAAYY"]
[Thu Sep 17 15:05:51.142292 2026] [security2:error] [pid 955873:tid 956066] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2JwAAAUk"]
[Thu Sep 17 15:05:51.142314 2026] [security2:error] [pid 955873:tid 956066] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2JwAAAUk"]
[Thu Sep 17 15:05:51.179368 2026] [security2:error] [pid 955873:tid 956016] [client 34.166.129.237:44656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/php-info.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2LQAAARc"]
[Thu Sep 17 15:05:51.226628 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2MAAAAWw"]
[Thu Sep 17 15:05:51.240092 2026] [security2:error] [pid 955873:tid 956076] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2MQAAAVM"]
[Thu Sep 17 15:05:51.291712 2026] [security2:error] [pid 955873:tid 956044] [client 154.190.208.131:41595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2NAAAATM"]
[Thu Sep 17 15:05:51.291856 2026] [security2:error] [pid 955873:tid 956044] [client 154.190.208.131:41595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2NAAAATM"]
[Thu Sep 17 15:05:51.300568 2026] [security2:error] [pid 955873:tid 956051] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/random_compat/"] [unique_id "aqxWLhFTPRVSLOsRVhr2IQAAATo"]
[Thu Sep 17 15:05:51.330775 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2LAAAAX4"]
[Thu Sep 17 15:05:51.330794 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2LAAAAX4"]
[Thu Sep 17 15:05:51.472208 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionCall.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2PAAAAUE"]
[Thu Sep 17 15:05:51.472292 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionCall.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2PAAAAUE"]
[Thu Sep 17 15:05:51.494980 2026] [security2:error] [pid 955873:tid 956074] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2PwAAAVE"]
[Thu Sep 17 15:05:51.503443 2026] [security2:error] [pid 955873:tid 956121] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2QQAAAYA"]
[Thu Sep 17 15:05:51.510846 2026] [autoindex:error] [pid 955873:tid 956081] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:51.511294 2026] [security2:error] [pid 955873:tid 956081] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWLxFTPRVSLOsRVhr2QAAAAVg"]
[Thu Sep 17 15:05:51.512914 2026] [security2:error] [pid 955873:tid 956113] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/rest-api/"] [unique_id "aqxWLxFTPRVSLOsRVhr2PQAAAXg"]
[Thu Sep 17 15:05:51.546527 2026] [security2:error] [pid 955873:tid 956107] [client 45.169.98.18:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2RQAAAXI"]
[Thu Sep 17 15:05:51.546608 2026] [security2:error] [pid 955873:tid 956107] [client 45.169.98.18:53256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2RQAAAXI"]
[Thu Sep 17 15:05:51.766540 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionDeclaration.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2UwAAAYc"]
[Thu Sep 17 15:05:51.766651 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionDeclaration.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2UwAAAYc"]
[Thu Sep 17 15:05:51.782068 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2VAAAAQw"]
[Thu Sep 17 15:05:51.794860 2026] [security2:error] [pid 955873:tid 956019] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2VQAAARo"]
[Thu Sep 17 15:05:51.796543 2026] [security2:error] [pid 955873:tid 956087] [client 216.73.163.75:43469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2SwAAAV4"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:51.876979 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.129.237:44662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpversion.php"] [unique_id "aqxWLxFTPRVSLOsRVhr2VgAAAXo"]
[Thu Sep 17 15:05:51.989442 2026] [security2:error] [pid 955873:tid 956108] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWLxFTPRVSLOsRVhr2WgAAAXM"]
[Thu Sep 17 15:05:52.059689 2026] [security2:error] [pid 955873:tid 956055] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2WwAAAT4"]
[Thu Sep 17 15:05:52.076869 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:49560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionResponse.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2XgAAAVs"]
[Thu Sep 17 15:05:52.076959 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:49560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/FunctionResponse.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2XgAAAVs"]
[Thu Sep 17 15:05:52.104777 2026] [autoindex:error] [pid 955873:tid 956043] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.105270 2026] [security2:error] [pid 955873:tid 956043] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2XwAAATI"]
[Thu Sep 17 15:05:52.106548 2026] [security2:error] [pid 955873:tid 956028] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxWMBFTPRVSLOsRVhr2XAAAASM"]
[Thu Sep 17 15:05:52.195198 2026] [security2:error] [pid 955873:tid 956046] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2YwAAATU"]
[Thu Sep 17 15:05:52.336870 2026] [security2:error] [pid 955873:tid 956106] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2ZgAAAXE"]
[Thu Sep 17 15:05:52.379939 2026] [security2:error] [pid 955873:tid 956118] [client 194.163.128.162:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2bAAAAX0"], referer: binance.com
[Thu Sep 17 15:05:52.380065 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/WebSearch.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2bQAAAW4"]
[Thu Sep 17 15:05:52.380128 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:49566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/src/Tools/DTO/WebSearch.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2bQAAAW4"]
[Thu Sep 17 15:05:52.403089 2026] [autoindex:error] [pid 955873:tid 956031] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.403528 2026] [security2:error] [pid 955873:tid 956031] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2bwAAASY"]
[Thu Sep 17 15:05:52.436585 2026] [security2:error] [pid 955873:tid 956085] [client 115.244.164.14:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2cAAAAVw"]
[Thu Sep 17 15:05:52.436645 2026] [security2:error] [pid 955873:tid 956085] [client 115.244.164.14:62616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2cAAAAVw"]
[Thu Sep 17 15:05:52.451629 2026] [security2:error] [pid 955873:tid 956026] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxWMBFTPRVSLOsRVhr2ZwAAASE"]
[Thu Sep 17 15:05:52.458680 2026] [security2:error] [pid 955873:tid 956007] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2cQAAAQ4"]
[Thu Sep 17 15:05:52.581124 2026] [security2:error] [pid 955873:tid 956025] [client 34.166.129.237:35462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/_phpinfo.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2dwAAASA"]
[Thu Sep 17 15:05:52.613730 2026] [security2:error] [pid 955873:tid 956082] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2eAAAAVk"]
[Thu Sep 17 15:05:52.664706 2026] [security2:error] [pid 955873:tid 956016] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2ewAAARc"]
[Thu Sep 17 15:05:52.664911 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWMBFTPRVSLOsRVhr2fAAAAT0"]
[Thu Sep 17 15:05:52.665277 2026] [fcgid:warn] [pid 955873:tid 956099] (70014)End of file found: [client 66.132.186.206:1892] mod_fcgid: can't get data from http client
[Thu Sep 17 15:05:52.667876 2026] [security2:error] [pid 955873:tid 956088] [client 186.105.232.15:49261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2fgAAAV8"]
[Thu Sep 17 15:05:52.669829 2026] [security2:error] [pid 955873:tid 956088] [client 186.105.232.15:49261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWMBFTPRVSLOsRVhr2fgAAAV8"]
[Thu Sep 17 15:05:52.704467 2026] [autoindex:error] [pid 955873:tid 956076] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.704922 2026] [security2:error] [pid 955873:tid 956076] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2gwAAAVM"]
[Thu Sep 17 15:05:52.734260 2026] [security2:error] [pid 955873:tid 956066] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/style-engine/"] [unique_id "aqxWMBFTPRVSLOsRVhr2eQAAAUk"]
[Thu Sep 17 15:05:52.741861 2026] [security2:error] [pid 955873:tid 956111] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWMBFTPRVSLOsRVhr2hQAAAXY"]
[Thu Sep 17 15:05:52.860612 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWMBFTPRVSLOsRVhr2igAAAQs"]
[Thu Sep 17 15:05:52.890788 2026] [security2:error] [pid 955873:tid 956105] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2iwAAAXA"]
[Thu Sep 17 15:05:52.900207 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWMBFTPRVSLOsRVhr2jgAAARI"]
[Thu Sep 17 15:05:52.923151 2026] [autoindex:error] [pid 955873:tid 956100] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:52.923645 2026] [security2:error] [pid 955873:tid 956100] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMBFTPRVSLOsRVhr2jwAAAWs"]
[Thu Sep 17 15:05:52.934280 2026] [security2:error] [pid 955873:tid 956122] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWMBFTPRVSLOsRVhr2kAAAAYE"]
[Thu Sep 17 15:05:52.982258 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxWMBFTPRVSLOsRVhr2jAAAAXc"]
[Thu Sep 17 15:05:53.028616 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/wp-includes/php-ai-client/"] [unique_id "aqxWMRFTPRVSLOsRVhr2kQAAARM"]
[Thu Sep 17 15:05:53.158792 2026] [security2:error] [pid 955873:tid 956121] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2lwAAAYA"]
[Thu Sep 17 15:05:53.167795 2026] [security2:error] [pid 955873:tid 956081] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2mAAAAVg"]
[Thu Sep 17 15:05:53.247440 2026] [autoindex:error] [pid 955873:tid 956107] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:53.248132 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWMRFTPRVSLOsRVhr2nAAAAXI"]
[Thu Sep 17 15:05:53.263184 2026] [security2:error] [pid 955873:tid 956120] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-includes/widgets/"] [unique_id "aqxWMRFTPRVSLOsRVhr2mgAAAX8"]
[Thu Sep 17 15:05:53.268519 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.129.237:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2ogAAATk"]
[Thu Sep 17 15:05:53.336416 2026] [security2:error] [pid 955873:tid 956053] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2pQAAATw"]
[Thu Sep 17 15:05:53.360508 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2mQAAAV0"]
[Thu Sep 17 15:05:53.360528 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2mQAAAV0"]
[Thu Sep 17 15:05:53.469214 2026] [security2:error] [pid 955873:tid 956013] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2qAAAARQ"]
[Thu Sep 17 15:05:53.473677 2026] [autoindex:error] [pid 955873:tid 956030] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:53.474128 2026] [security2:error] [pid 955873:tid 956030] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxWMRFTPRVSLOsRVhr2pwAAASU"]
[Thu Sep 17 15:05:53.506119 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/"] [unique_id "aqxWMRFTPRVSLOsRVhr2rAAAAWg"]
[Thu Sep 17 15:05:53.509568 2026] [security2:error] [pid 955873:tid 956096] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2rQAAAWc"]
[Thu Sep 17 15:05:53.669275 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/"] [unique_id "aqxWMRFTPRVSLOsRVhr2rgAAAUg"]
[Thu Sep 17 15:05:53.702810 2026] [autoindex:error] [pid 955873:tid 956063] [client 139.28.219.68:60668] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:53.703286 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/css/colors/"] [unique_id "aqxWMRFTPRVSLOsRVhr2rwAAAUY"]
[Thu Sep 17 15:05:53.704309 2026] [security2:error] [pid 955873:tid 956055] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2swAAAT4"]
[Thu Sep 17 15:05:53.746983 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2tAAAAXQ"]
[Thu Sep 17 15:05:53.823959 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWMRFTPRVSLOsRVhr2twAAARE"]
[Thu Sep 17 15:05:53.924111 2026] [security2:error] [pid 955873:tid 956056] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWMRFTPRVSLOsRVhr2vwAAAT8"]
[Thu Sep 17 15:05:53.974112 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.129.237:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/server-info.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2wQAAATI"]
[Thu Sep 17 15:05:54.024382 2026] [security2:error] [pid 955873:tid 956102] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr2xAAAAW0"]
[Thu Sep 17 15:05:54.079227 2026] [security2:error] [pid 955873:tid 956103] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2vgAAAW4"]
[Thu Sep 17 15:05:54.079248 2026] [security2:error] [pid 955873:tid 956103] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2vgAAAW4"]
[Thu Sep 17 15:05:54.100179 2026] [security2:error] [pid 955873:tid 956114] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/images/slider/"] [unique_id "aqxWMRFTPRVSLOsRVhr2vAAAAXk"]
[Thu Sep 17 15:05:54.113267 2026] [security2:error] [pid 955873:tid 956118] [client 216.73.163.58:38607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWMhFTPRVSLOsRVhr2yQAAAX0"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:54.182376 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2wAAAASY"]
[Thu Sep 17 15:05:54.182402 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMRFTPRVSLOsRVhr2wAAAASY"]
[Thu Sep 17 15:05:54.223803 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr2ygAAAYY"]
[Thu Sep 17 15:05:54.301335 2026] [security2:error] [pid 955873:tid 956061] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr20gAAAUQ"]
[Thu Sep 17 15:05:54.324902 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWMhFTPRVSLOsRVhr21AAAAVM"]
[Thu Sep 17 15:05:54.418885 2026] [security2:error] [pid 955873:tid 956090] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr21gAAAWE"]
[Thu Sep 17 15:05:54.467564 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr22QAAARI"]
[Thu Sep 17 15:05:54.495471 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWMhFTPRVSLOsRVhr22AAAAXA"]
[Thu Sep 17 15:05:54.548307 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr21QAAAXY"]
[Thu Sep 17 15:05:54.548330 2026] [security2:error] [pid 955873:tid 956111] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr21QAAAXY"]
[Thu Sep 17 15:05:54.572099 2026] [security2:error] [pid 955873:tid 956100] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr22wAAAWs"]
[Thu Sep 17 15:05:54.604865 2026] [security2:error] [pid 955873:tid 956119] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr23gAAAX4"]
[Thu Sep 17 15:05:54.624991 2026] [security2:error] [pid 955873:tid 956016] [client 139.28.219.68:60668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxWMhFTPRVSLOsRVhr2zgAAARc"]
[Thu Sep 17 15:05:54.631271 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr23wAAAVQ"]
[Thu Sep 17 15:05:54.635379 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/wp-includes/php-ai-client/third-party/Http/"] [unique_id "aqxWMhFTPRVSLOsRVhr24AAAAU8"]
[Thu Sep 17 15:05:54.663514 2026] [security2:error] [pid 955873:tid 956068] [client 34.166.129.237:35480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/server-status.php"] [unique_id "aqxWMhFTPRVSLOsRVhr24wAAAUs"]
[Thu Sep 17 15:05:54.726113 2026] [security2:error] [pid 955873:tid 956004] [client 216.73.163.67:22165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr25QAAAQs"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:54.789850 2026] [security2:error] [pid 955873:tid 956116] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr26QAAAXs"]
[Thu Sep 17 15:05:54.829439 2026] [security2:error] [pid 955873:tid 956081] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr26gAAAVg"]
[Thu Sep 17 15:05:54.880739 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr27AAAASk"]
[Thu Sep 17 15:05:54.956514 2026] [security2:error] [pid 955873:tid 956117] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWMhFTPRVSLOsRVhr27wAAAXw"]
[Thu Sep 17 15:05:54.980734 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr26AAAARM"]
[Thu Sep 17 15:05:54.980758 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr26AAAARM"]
[Thu Sep 17 15:05:55.060686 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr28QAAATk"]
[Thu Sep 17 15:05:55.092488 2026] [security2:error] [pid 955873:tid 956089] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr28AAAAWA"]
[Thu Sep 17 15:05:55.092507 2026] [security2:error] [pid 955873:tid 956089] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMhFTPRVSLOsRVhr28AAAAWA"]
[Thu Sep 17 15:05:55.134707 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/ClassDiscovery.php"] [unique_id "aqxWMxFTPRVSLOsRVhr29AAAASQ"]
[Thu Sep 17 15:05:55.134798 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:49570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/ClassDiscovery.php"] [unique_id "aqxWMxFTPRVSLOsRVhr29AAAASQ"]
[Thu Sep 17 15:05:55.135303 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr28gAAAVI"]
[Thu Sep 17 15:05:55.160763 2026] [security2:error] [pid 955873:tid 956086] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr29gAAAV0"]
[Thu Sep 17 15:05:55.259834 2026] [security2:error] [pid 955873:tid 956083] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr2-gAAAVo"]
[Thu Sep 17 15:05:55.288903 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr2_AAAASI"]
[Thu Sep 17 15:05:55.374405 2026] [security2:error] [pid 955873:tid 956096] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/sites/default/files/"] [unique_id "aqxWMhFTPRVSLOsRVhr27QAAAWU"]
[Thu Sep 17 15:05:55.421528 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3AAAAATA"]
[Thu Sep 17 15:05:55.421629 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:49572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3AAAAATA"]
[Thu Sep 17 15:05:55.438642 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3AwAAAUY"]
[Thu Sep 17 15:05:55.457558 2026] [security2:error] [pid 955873:tid 956028] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3BwAAASM"]
[Thu Sep 17 15:05:55.642070 2026] [security2:error] [pid 955873:tid 956060] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3CgAAAUM"]
[Thu Sep 17 15:05:55.655503 2026] [security2:error] [pid 955873:tid 956102] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3CwAAAW0"]
[Thu Sep 17 15:05:55.710102 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:49582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/"] [unique_id "aqxWMxFTPRVSLOsRVhr3EwAAAS8"]
[Thu Sep 17 15:05:55.714860 2026] [security2:error] [pid 955873:tid 956015] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3FQAAARY"]
[Thu Sep 17 15:05:55.811907 2026] [security2:error] [pid 955873:tid 956088] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3GgAAAV8"]
[Thu Sep 17 15:05:55.825604 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3EgAAARg"]
[Thu Sep 17 15:05:55.825627 2026] [security2:error] [pid 955873:tid 956017] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWMxFTPRVSLOsRVhr3EgAAARg"]
[Thu Sep 17 15:05:55.842368 2026] [security2:error] [pid 955873:tid 956007] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxWMxFTPRVSLOsRVhr3DgAAAQ4"]
[Thu Sep 17 15:05:55.875157 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/"] [unique_id "aqxWMxFTPRVSLOsRVhr3GwAAASg"]
[Thu Sep 17 15:05:55.926645 2026] [security2:error] [pid 955873:tid 956076] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3HAAAAVM"]
[Thu Sep 17 15:05:55.950707 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.129.237:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWMxFTPRVSLOsRVhr3HQAAATM"]
[Thu Sep 17 15:05:55.965768 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3HgAAASE"]
[Thu Sep 17 15:05:55.990490 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWMxFTPRVSLOsRVhr3HwAAARs"]
[Thu Sep 17 15:05:56.019900 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:49582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWNBFTPRVSLOsRVhr3IQAAARk"]
[Thu Sep 17 15:05:56.122211 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3JQAAARI"]
[Thu Sep 17 15:05:56.170909 2026] [security2:error] [pid 955873:tid 956111] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3JwAAAXY"]
[Thu Sep 17 15:05:56.184813 2026] [security2:error] [pid 955873:tid 956090] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JAAAAWE"]
[Thu Sep 17 15:05:56.184836 2026] [security2:error] [pid 955873:tid 956090] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JAAAAWE"]
[Thu Sep 17 15:05:56.230642 2026] [security2:error] [pid 955873:tid 956080] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxWNBFTPRVSLOsRVhr3IAAAAVc"]
[Thu Sep 17 15:05:56.269805 2026] [security2:error] [pid 955873:tid 956119] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3KgAAAX4"]
[Thu Sep 17 15:05:56.279899 2026] [security2:error] [pid 955873:tid 956130] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3KwAAAYk"]
[Thu Sep 17 15:05:56.354614 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JgAAAXA"]
[Thu Sep 17 15:05:56.354638 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3JgAAAXA"]
[Thu Sep 17 15:05:56.417248 2026] [security2:error] [pid 955873:tid 956006] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3MAAAAQ0"]
[Thu Sep 17 15:05:56.433123 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3MgAAATc"]
[Thu Sep 17 15:05:56.520225 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:49582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/ClassInstantiationFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3NAAAAUU"]
[Thu Sep 17 15:05:56.520354 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:49582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/ClassInstantiationFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3NAAAAUU"]
[Thu Sep 17 15:05:56.542573 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3MQAAAXc"]
[Thu Sep 17 15:05:56.542593 2026] [security2:error] [pid 955873:tid 956112] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3MQAAAXc"]
[Thu Sep 17 15:05:56.547680 2026] [security2:error] [pid 955873:tid 956074] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3NQAAAVE"]
[Thu Sep 17 15:05:56.584733 2026] [security2:error] [pid 955873:tid 956116] [client 47.39.232.109:59653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3MwABe30"], referer: https://www.endless-chronicles.com/cdbbec328e5cc574586e0b446e67b334.ogg
[Thu Sep 17 15:05:56.590892 2026] [security2:error] [pid 955873:tid 956121] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3NgAAAYA"]
[Thu Sep 17 15:05:56.599751 2026] [security2:error] [pid 955873:tid 956072] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/components/"] [unique_id "aqxWNBFTPRVSLOsRVhr3LgAAAU8"]
[Thu Sep 17 15:05:56.652876 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.129.237:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3NwAAATQ"]
[Thu Sep 17 15:05:56.744523 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3OgAAAWI"]
[Thu Sep 17 15:05:56.788216 2026] [security2:error] [pid 955873:tid 956092] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3QQAAAWM"]
[Thu Sep 17 15:05:56.808729 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/DiscoveryFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3QgAAAWA"]
[Thu Sep 17 15:05:56.808858 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:49592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/DiscoveryFailedException.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3QgAAAWA"]
[Thu Sep 17 15:05:56.824055 2026] [security2:error] [pid 955873:tid 956029] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3RAAAASQ"]
[Thu Sep 17 15:05:56.903127 2026] [security2:error] [pid 955873:tid 956086] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWNBFTPRVSLOsRVhr3RQAAAV0"]
[Thu Sep 17 15:05:56.906299 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3PgAAAYQ"]
[Thu Sep 17 15:05:56.906328 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNBFTPRVSLOsRVhr3PgAAAYQ"]
[Thu Sep 17 15:05:56.939944 2026] [security2:error] [pid 955873:tid 956012] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/admin/uploads/images/"] [unique_id "aqxWNBFTPRVSLOsRVhr3PAAAARM"]
[Thu Sep 17 15:05:57.056618 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3RwAAASI"]
[Thu Sep 17 15:05:57.098457 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NoCandidateFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3SQAAAV4"]
[Thu Sep 17 15:05:57.098545 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:49608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NoCandidateFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3SQAAAV4"]
[Thu Sep 17 15:05:57.102683 2026] [security2:error] [pid 955873:tid 956019] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3SwAAARo"]
[Thu Sep 17 15:05:57.216583 2026] [security2:error] [pid 955873:tid 956101] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3TQAAAWw"]
[Thu Sep 17 15:05:57.240042 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3TAAAAUA"]
[Thu Sep 17 15:05:57.240066 2026] [security2:error] [pid 955873:tid 956057] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3TAAAAUA"]
[Thu Sep 17 15:05:57.253258 2026] [security2:error] [pid 955873:tid 956096] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxWNRFTPRVSLOsRVhr3SAAAAWc"]
[Thu Sep 17 15:05:57.358759 2026] [security2:error] [pid 955873:tid 956021] [client 34.166.129.237:35504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3UgAAARw"]
[Thu Sep 17 15:05:57.371554 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3UwAAASM"]
[Thu Sep 17 15:05:57.376060 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NotFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3VAAAAYc"]
[Thu Sep 17 15:05:57.376142 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:49614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NotFoundException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3VAAAAYc"]
[Thu Sep 17 15:05:57.379137 2026] [security2:error] [pid 955873:tid 956032] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3VQAAASc"]
[Thu Sep 17 15:05:57.446799 2026] [autoindex:error] [pid 955873:tid 956108] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:57.447256 2026] [security2:error] [pid 955873:tid 956108] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWNRFTPRVSLOsRVhr3WAAAAXM"]
[Thu Sep 17 15:05:57.487281 2026] [security2:error] [pid 955873:tid 956005] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/fonts/"] [unique_id "aqxWNRFTPRVSLOsRVhr3VgAAAQw"]
[Thu Sep 17 15:05:57.526580 2026] [security2:error] [pid 955873:tid 956053] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3WQAAATw"]
[Thu Sep 17 15:05:57.569900 2026] [security2:error] [pid 955873:tid 956047] [client 34.178.167.214:47996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3WgAAATY"]
[Thu Sep 17 15:05:57.658240 2026] [security2:error] [pid 955873:tid 956120] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3XAAAAX8"]
[Thu Sep 17 15:05:57.664524 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:49628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/PuliUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3XwAAAUM"]
[Thu Sep 17 15:05:57.664596 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:49628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/PuliUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3XwAAAUM"]
[Thu Sep 17 15:05:57.685999 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3YQAAATU"]
[Thu Sep 17 15:05:57.733402 2026] [security2:error] [pid 955873:tid 956106] [client 185.55.149.49:53358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YgAAAXE"]
[Thu Sep 17 15:05:57.733486 2026] [security2:error] [pid 955873:tid 956106] [client 185.55.149.49:53358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YgAAAXE"]
[Thu Sep 17 15:05:57.810865 2026] [security2:error] [pid 955873:tid 956124] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YAAAAYM"]
[Thu Sep 17 15:05:57.810886 2026] [security2:error] [pid 955873:tid 956124] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3YAAAAYM"]
[Thu Sep 17 15:05:57.836357 2026] [security2:error] [pid 955873:tid 956059] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxWNRFTPRVSLOsRVhr3XQAAAUI"]
[Thu Sep 17 15:05:57.839600 2026] [security2:error] [pid 955873:tid 956061] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3ZgAAAUQ"]
[Thu Sep 17 15:05:57.936643 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3aAAAAWk"]
[Thu Sep 17 15:05:57.959757 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/StrategyUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3aQAAAQ4"]
[Thu Sep 17 15:05:57.959862 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:49638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Exception/StrategyUnavailableException.php"] [unique_id "aqxWNRFTPRVSLOsRVhr3aQAAAQ4"]
[Thu Sep 17 15:05:57.993102 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWNRFTPRVSLOsRVhr3agAAAVk"]
[Thu Sep 17 15:05:58.065969 2026] [security2:error] [pid 955873:tid 956031] [client 34.166.129.237:35508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3bgAAASY"]
[Thu Sep 17 15:05:58.148544 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3bwAAATM"]
[Thu Sep 17 15:05:58.149372 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3bQAAAR8"]
[Thu Sep 17 15:05:58.149388 2026] [security2:error] [pid 955873:tid 956024] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3bQAAAR8"]
[Thu Sep 17 15:05:58.214003 2026] [security2:error] [pid 955873:tid 956018] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3cQAAARk"]
[Thu Sep 17 15:05:58.215896 2026] [security2:error] [pid 955873:tid 956127] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxWNhFTPRVSLOsRVhr3awAAAYY"]
[Thu Sep 17 15:05:58.239829 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr17FactoryDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3cwAAARI"]
[Thu Sep 17 15:05:58.239931 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:49640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr17FactoryDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3cwAAARI"]
[Thu Sep 17 15:05:58.304095 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3eQAAASo"]
[Thu Sep 17 15:05:58.461632 2026] [security2:error] [pid 955873:tid 956066] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3fwAAAUk"]
[Thu Sep 17 15:05:58.462019 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3gAAAATc"]
[Thu Sep 17 15:05:58.493783 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3gQAAAU4"]
[Thu Sep 17 15:05:58.530442 2026] [security2:error] [pid 955873:tid 956006] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3fgAAAQ0"]
[Thu Sep 17 15:05:58.530461 2026] [security2:error] [pid 955873:tid 956006] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3fgAAAQ0"]
[Thu Sep 17 15:05:58.532182 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:49646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr18ClientDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3ggAAAQs"]
[Thu Sep 17 15:05:58.532260 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:49646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Psr18ClientDiscovery.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3ggAAAQs"]
[Thu Sep 17 15:05:58.571733 2026] [security2:error] [pid 955873:tid 956062] [client 216.73.163.52:31947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3gwAAAUU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:05:58.572316 2026] [security2:error] [pid 955873:tid 956105] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wordpress/"] [unique_id "aqxWNhFTPRVSLOsRVhr3fAAAAXA"]
[Thu Sep 17 15:05:58.619489 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3hAAAAUE"]
[Thu Sep 17 15:05:58.712763 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3hgAAAXs"]
[Thu Sep 17 15:05:58.752849 2026] [security2:error] [pid 955873:tid 956073] [client 34.166.129.237:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3iQAAAVA"]
[Thu Sep 17 15:05:58.766551 2026] [security2:error] [pid 955873:tid 956072] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3igAAAU8"]
[Thu Sep 17 15:05:58.778314 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3iwAAATQ"]
[Thu Sep 17 15:05:58.824190 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:49662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/"] [unique_id "aqxWNhFTPRVSLOsRVhr3jAAAAWI"]
[Thu Sep 17 15:05:58.920474 2026] [security2:error] [pid 955873:tid 956126] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3jwAAAYU"]
[Thu Sep 17 15:05:58.934858 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWNhFTPRVSLOsRVhr3kAAAAWM"]
[Thu Sep 17 15:05:58.983757 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/"] [unique_id "aqxWNhFTPRVSLOsRVhr3kQAAAWA"]
[Thu Sep 17 15:05:59.044871 2026] [security2:error] [pid 955873:tid 956075] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3kgAAAVI"]
[Thu Sep 17 15:05:59.055563 2026] [security2:error] [pid 955873:tid 956074] [client 210.222.43.21:49199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWNhFTPRVSLOsRVhr3jgAAAVE"], referer: http://talent-in-borders.com/TEST
[Thu Sep 17 15:05:59.088279 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3lAAAAXI"]
[Thu Sep 17 15:05:59.111410 2026] [autoindex:error] [pid 955873:tid 956125] [client 139.28.219.68:41578] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:59.111922 2026] [security2:error] [pid 955873:tid 956125] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/images/"] [unique_id "aqxWNxFTPRVSLOsRVhr3kwAAAYQ"]
[Thu Sep 17 15:05:59.127016 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:49662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/wp-includes/php-ai-client/third-party/Http/Discovery/"] [unique_id "aqxWNxFTPRVSLOsRVhr3lQAAAUo"]
[Thu Sep 17 15:05:59.224106 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3lgAAATk"]
[Thu Sep 17 15:05:59.241442 2026] [security2:error] [pid 955873:tid 956013] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3lwAAARQ"]
[Thu Sep 17 15:05:59.243623 2026] [security2:error] [pid 955873:tid 956025] [client 194.163.128.162:59809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.128.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wildamerika.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3mAAAASA"], referer: binance.com
[Thu Sep 17 15:05:59.311906 2026] [autoindex:error] [pid 955873:tid 956030] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:05:59.312615 2026] [security2:error] [pid 955873:tid 956030] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWNxFTPRVSLOsRVhr3oAAAASU"]
[Thu Sep 17 15:05:59.314170 2026] [security2:error] [pid 955873:tid 956087] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxWNxFTPRVSLOsRVhr3nQAAAV4"]
[Thu Sep 17 15:05:59.328101 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3oQAAAUY"]
[Thu Sep 17 15:05:59.401163 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3owAAATI"]
[Thu Sep 17 15:05:59.438137 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.129.237:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3pQAAAWU"]
[Thu Sep 17 15:05:59.460670 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3nAAAASI"]
[Thu Sep 17 15:05:59.460694 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3nAAAASI"]
[Thu Sep 17 15:05:59.478605 2026] [security2:error] [pid 955873:tid 956021] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3qAAAARw"]
[Thu Sep 17 15:05:59.495821 2026] [security2:error] [pid 955873:tid 956028] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3qQAAASM"]
[Thu Sep 17 15:05:59.497644 2026] [security2:error] [pid 955873:tid 956052] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxWNxFTPRVSLOsRVhr3pgAAATs"]
[Thu Sep 17 15:05:59.556264 2026] [security2:error] [pid 955873:tid 956055] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3qgAAAT4"]
[Thu Sep 17 15:05:59.604754 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rAAAAUw"]
[Thu Sep 17 15:05:59.604823 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:49662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rAAAAUw"]
[Thu Sep 17 15:05:59.605286 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3qwAAAVU"]
[Thu Sep 17 15:05:59.682058 2026] [security2:error] [pid 955873:tid 956047] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3sAAAATY"]
[Thu Sep 17 15:05:59.709385 2026] [security2:error] [pid 955873:tid 956056] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3sQAAAT8"]
[Thu Sep 17 15:05:59.803583 2026] [security2:error] [pid 955873:tid 956053] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rwAAATw"]
[Thu Sep 17 15:05:59.803604 2026] [security2:error] [pid 955873:tid 956053] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3rwAAATw"]
[Thu Sep 17 15:05:59.885439 2026] [security2:error] [pid 955873:tid 956104] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3twAAAW8"]
[Thu Sep 17 15:05:59.885466 2026] [security2:error] [pid 955873:tid 956061] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3uQAAAUQ"]
[Thu Sep 17 15:05:59.885465 2026] [security2:error] [pid 955873:tid 956088] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWNxFTPRVSLOsRVhr3uAAAAV8"]
[Thu Sep 17 15:05:59.885495 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonPsr17ClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3ugAAAUI"]
[Thu Sep 17 15:05:59.885558 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:57610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonPsr17ClassesStrategy.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3ugAAAUI"]
[Thu Sep 17 15:05:59.948757 2026] [security2:error] [pid 955873:tid 956005] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/js/"] [unique_id "aqxWNxFTPRVSLOsRVhr3rQAAAQw"]
[Thu Sep 17 15:05:59.957606 2026] [security2:error] [pid 955873:tid 956032] [client 181.137.97.243:35936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "greenbrickbuilders.com"] [uri "/robots.txt"] [unique_id "aqxWNxFTPRVSLOsRVhr3uwAAASc"]
[Thu Sep 17 15:06:00.040250 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3vQAAAQ4"]
[Thu Sep 17 15:06:00.112631 2026] [security2:error] [pid 955873:tid 956102] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3wAAAAW0"]
[Thu Sep 17 15:06:00.137535 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.129.237:35524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWOBFTPRVSLOsRVhr3wgAAARg"]
[Thu Sep 17 15:06:00.160294 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/DiscoveryStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3xAAAASY"]
[Thu Sep 17 15:06:00.160399 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:57622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/DiscoveryStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3xAAAASY"]
[Thu Sep 17 15:06:00.162538 2026] [security2:error] [pid 955873:tid 956010] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3xQAAARE"]
[Thu Sep 17 15:06:00.194400 2026] [security2:error] [pid 955873:tid 956024] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3xgAAAR8"]
[Thu Sep 17 15:06:00.208525 2026] [security2:error] [pid 955873:tid 956008] [client 47.39.232.109:51255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3wwABDxI"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726025143&hideliu=1&hideminor=1&limit=100&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:06:00.269894 2026] [security2:error] [pid 955873:tid 956082] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3wQAAAVk"]
[Thu Sep 17 15:06:00.269917 2026] [security2:error] [pid 955873:tid 956082] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr3wQAAAVk"]
[Thu Sep 17 15:06:00.299802 2026] [security2:error] [pid 955873:tid 956011] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3yAAAARI"]
[Thu Sep 17 15:06:00.324980 2026] [security2:error] [pid 955873:tid 956076] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxWOBFTPRVSLOsRVhr3vgAAAVM"]
[Thu Sep 17 15:06:00.351505 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr3ygAAASo"]
[Thu Sep 17 15:06:00.438219 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:57624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/PuliBetaStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr30QAAAXY"]
[Thu Sep 17 15:06:00.438321 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:57624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/PuliBetaStrategy.php"] [unique_id "aqxWOBFTPRVSLOsRVhr30QAAAXY"]
[Thu Sep 17 15:06:00.438955 2026] [security2:error] [pid 955873:tid 956070] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr30AAAAU0"]
[Thu Sep 17 15:06:00.460887 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr30wAAARs"]
[Thu Sep 17 15:06:00.487812 2026] [autoindex:error] [pid 955873:tid 955896] [remote 93.152.209.11:36278] AH01276: Cannot serve directory /home1/ykkcnqmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:00.508046 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:40412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr32gAAAU8"]
[Thu Sep 17 15:06:00.582421 2026] [security2:error] [pid 955873:tid 956071] [client 47.79.201.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr30gAAAU4"], referer: https://www.google.com/
[Thu Sep 17 15:06:00.635432 2026] [security2:error] [pid 955873:tid 956073] [client 139.28.219.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr32QAAAVA"]
[Thu Sep 17 15:06:00.635459 2026] [security2:error] [pid 955873:tid 956073] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr32QAAAVA"]
[Thu Sep 17 15:06:00.642031 2026] [security2:error] [pid 955873:tid 956058] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxWOBFTPRVSLOsRVhr31wAAAUE"]
[Thu Sep 17 15:06:00.676634 2026] [security2:error] [pid 955873:tid 956067] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr33AAAAUo"]
[Thu Sep 17 15:06:00.716014 2026] [security2:error] [pid 955873:tid 956025] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr33QAAASA"]
[Thu Sep 17 15:06:00.725423 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/"] [unique_id "aqxWOBFTPRVSLOsRVhr33gAAASU"]
[Thu Sep 17 15:06:00.798309 2026] [authz_core:error] [pid 955873:tid 956026] [client 4.240.114.86:61816] AH01630: client denied by server configuration: /home2/loseyov0/public_html/staging-paltals/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:06:00.828340 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.129.237:35526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWOBFTPRVSLOsRVhr35gAAASQ"]
[Thu Sep 17 15:06:00.828644 2026] [security2:error] [pid 955873:tid 956043] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr35QAAATI"]
[Thu Sep 17 15:06:00.884279 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/"] [unique_id "aqxWOBFTPRVSLOsRVhr36AAAASI"]
[Thu Sep 17 15:06:00.934262 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:41578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr34wAAAUY"]
[Thu Sep 17 15:06:00.934288 2026] [security2:error] [pid 955873:tid 956063] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr34wAAAUY"]
[Thu Sep 17 15:06:00.977016 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr37AAAAR4"]
[Thu Sep 17 15:06:00.992637 2026] [security2:error] [pid 955873:tid 956069] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWOBFTPRVSLOsRVhr37gAAAUw"]
[Thu Sep 17 15:06:01.025610 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWORFTPRVSLOsRVhr38AAAAVU"]
[Thu Sep 17 15:06:01.090883 2026] [security2:error] [pid 955873:tid 956084] [client 31.37.3.225:48884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWOBFTPRVSLOsRVhr37QABWxo"]
[Thu Sep 17 15:06:01.132712 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWORFTPRVSLOsRVhr38wAAAX8"]
[Thu Sep 17 15:06:01.149703 2026] [security2:error] [pid 955873:tid 956060] [client 85.208.98.202:42871] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thevagabondhiker.com"] [uri "/wp-content/plugins/email-subscribers/lite/public/js/email-subscribers-public.js"] [unique_id "aqxWORFTPRVSLOsRVhr39AAAAUM"]
[Thu Sep 17 15:06:01.160010 2026] [security2:error] [pid 955873:tid 956083] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWORFTPRVSLOsRVhr39QAAAVo"]
[Thu Sep 17 15:06:01.269915 2026] [security2:error] [pid 955873:tid 956081] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWORFTPRVSLOsRVhr39wAAAVg"]
[Thu Sep 17 15:06:01.286824 2026] [security2:error] [pid 955873:tid 956106] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWORFTPRVSLOsRVhr3-AAAAXE"]
[Thu Sep 17 15:06:01.301811 2026] [security2:error] [pid 955873:tid 956110] [client 20.244.34.24:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxWORFTPRVSLOsRVhr3-QAAAXU"], referer: binance.com
[Thu Sep 17 15:06:01.358518 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr39gAAATU"]
[Thu Sep 17 15:06:01.358543 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr39gAAATU"]
[Thu Sep 17 15:06:01.362935 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWORFTPRVSLOsRVhr3_gAAAS4"]
[Thu Sep 17 15:06:01.441523 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4AQAAAQ4"]
[Thu Sep 17 15:06:01.512639 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.129.237:35530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php~"] [unique_id "aqxWORFTPRVSLOsRVhr4BQAAAX0"]
[Thu Sep 17 15:06:01.517006 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/"] [unique_id "aqxWORFTPRVSLOsRVhr4BgAAAS8"]
[Thu Sep 17 15:06:01.546321 2026] [security2:error] [pid 955873:tid 956017] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4CAAAARg"]
[Thu Sep 17 15:06:01.594941 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4CQAAATM"]
[Thu Sep 17 15:06:01.660524 2026] [security2:error] [pid 955873:tid 956019] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/network/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr38gAAARo"]
[Thu Sep 17 15:06:01.667112 2026] [security2:error] [pid 955873:tid 956008] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4CwAAAQ8"]
[Thu Sep 17 15:06:01.685406 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/"] [unique_id "aqxWORFTPRVSLOsRVhr4CgAAAR8"]
[Thu Sep 17 15:06:01.740812 2026] [security2:error] [pid 955873:tid 955889] [remote 216.73.217.142:14717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWORFTPRVSLOsRVhr4DgABRw8"]
[Thu Sep 17 15:06:01.751610 2026] [security2:error] [pid 955873:tid 956009] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4DwAAARA"]
[Thu Sep 17 15:06:01.820548 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:42319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWORFTPRVSLOsRVhr4EAAAAWk"]
[Thu Sep 17 15:06:01.824536 2026] [security2:error] [pid 955873:tid 956015] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4EQAAARY"]
[Thu Sep 17 15:06:01.824966 2026] [security2:error] [pid 955873:tid 956098] [client 154.190.208.131:42319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWORFTPRVSLOsRVhr4EAAAAWk"]
[Thu Sep 17 15:06:01.829430 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/wp-includes/php-ai-client/third-party/Nyholm/"] [unique_id "aqxWORFTPRVSLOsRVhr4EwAAASo"]
[Thu Sep 17 15:06:01.858641 2026] [security2:error] [pid 955873:tid 956042] [client 47.79.201.157:21202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4DQAAATE"], referer: https://www.google.com/
[Thu Sep 17 15:06:01.916571 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4FwAAAVc"]
[Thu Sep 17 15:06:01.944180 2026] [security2:error] [pid 955873:tid 956111] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWORFTPRVSLOsRVhr4GQAAAXY"]
[Thu Sep 17 15:06:02.035987 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:53820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4GwAAAUk"]
[Thu Sep 17 15:06:02.036931 2026] [security2:error] [pid 955873:tid 956066] [client 45.169.98.18:53820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4GwAAAUk"]
[Thu Sep 17 15:06:02.070739 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4HAAAAUU"]
[Thu Sep 17 15:06:02.103606 2026] [security2:error] [pid 955873:tid 956077] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4HQAAAVQ"]
[Thu Sep 17 15:06:02.201469 2026] [security2:error] [pid 955873:tid 956020] [client 34.166.129.237:35214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/info.php.bak"] [unique_id "aqxWOhFTPRVSLOsRVhr4HwAAARs"]
[Thu Sep 17 15:06:02.214006 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4GgAAATc"]
[Thu Sep 17 15:06:02.214036 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4GgAAATc"]
[Thu Sep 17 15:06:02.214778 2026] [security2:error] [pid 955873:tid 956096] [client 2a01:7e03::2000:e4ff:fed3:3768:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entrustcounseling.com"] [uri "/wp-login.php"] [unique_id "aqxWNxFTPRVSLOsRVhr3pAABZwM"], referer: https://www.google.com/
[Thu Sep 17 15:06:02.226077 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4IAAAAYE"]
[Thu Sep 17 15:06:02.281186 2026] [security2:error] [pid 955873:tid 956045] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4IQAAATQ"]
[Thu Sep 17 15:06:02.358657 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/"] [unique_id "aqxWOhFTPRVSLOsRVhr4JQAAAU4"]
[Thu Sep 17 15:06:02.378676 2026] [security2:error] [pid 955873:tid 956079] [client 139.28.219.68:55978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/network/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4HgAAAVY"]
[Thu Sep 17 15:06:02.379288 2026] [security2:error] [pid 955873:tid 956018] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4JwAAARk"]
[Thu Sep 17 15:06:02.382266 2026] [security2:error] [pid 955873:tid 956089] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4KAAAAWA"]
[Thu Sep 17 15:06:02.505866 2026] [security2:error] [pid 955873:tid 956068] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4KgAAAUs"]
[Thu Sep 17 15:06:02.520979 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/"] [unique_id "aqxWOhFTPRVSLOsRVhr4KQAAAVA"]
[Thu Sep 17 15:06:02.531567 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4LAAAAUE"]
[Thu Sep 17 15:06:02.660874 2026] [security2:error] [pid 955873:tid 956013] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4MQAAARQ"]
[Thu Sep 17 15:06:02.663202 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/wp-includes/php-ai-client/third-party/Nyholm/Psr7/"] [unique_id "aqxWOhFTPRVSLOsRVhr4MgAAASU"]
[Thu Sep 17 15:06:02.684549 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4MwAAAWo"]
[Thu Sep 17 15:06:02.792255 2026] [security2:error] [pid 955873:tid 956107] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/user/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4MAAAAXI"]
[Thu Sep 17 15:06:02.792457 2026] [security2:error] [pid 955873:tid 956094] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4NQAAAWU"]
[Thu Sep 17 15:06:02.836799 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4OAAAAUY"]
[Thu Sep 17 15:06:02.892390 2026] [security2:error] [pid 955873:tid 956025] [client 34.166.129.237:35220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWOhFTPRVSLOsRVhr4OgAAASA"]
[Thu Sep 17 15:06:02.942652 2026] [security2:error] [pid 955873:tid 956065] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4OwAAAUg"]
[Thu Sep 17 15:06:02.974658 2026] [security2:error] [pid 955873:tid 956026] [client 115.244.164.14:63481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4PQAAASE"]
[Thu Sep 17 15:06:02.974814 2026] [security2:error] [pid 955873:tid 956026] [client 115.244.164.14:63481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4PQAAASE"]
[Thu Sep 17 15:06:02.989376 2026] [security2:error] [pid 955873:tid 956087] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWOhFTPRVSLOsRVhr4PgAAAV4"]
[Thu Sep 17 15:06:03.000965 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4NwAAASI"]
[Thu Sep 17 15:06:03.000987 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4NwAAASI"]
[Thu Sep 17 15:06:03.048272 2026] [security2:error] [pid 955873:tid 956086] [client 2a01:7e03::2000:e4ff:fed3:3768:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entrustcounseling.com"] [uri "/wp-login.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4KwABXR4"]
[Thu Sep 17 15:06:03.056838 2026] [security2:error] [pid 955873:tid 956128] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4PwAAAYc"]
[Thu Sep 17 15:06:03.143540 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4QQAAATY"]
[Thu Sep 17 15:06:03.144343 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/HttplugFactory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4QgAAATg"]
[Thu Sep 17 15:06:03.144430 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:57634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/HttplugFactory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4QgAAATg"]
[Thu Sep 17 15:06:03.149520 2026] [security2:error] [pid 955873:tid 956055] [client 139.28.219.68:55978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/user/index.php"] [unique_id "aqxWOhFTPRVSLOsRVhr4PAAAAT4"]
[Thu Sep 17 15:06:03.211641 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4RAAAAYg"]
[Thu Sep 17 15:06:03.221069 2026] [security2:error] [pid 955873:tid 956056] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4RQAAAT8"]
[Thu Sep 17 15:06:03.297590 2026] [security2:error] [pid 955873:tid 956106] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4SgAAAXE"]
[Thu Sep 17 15:06:03.423353 2026] [security2:error] [pid 955873:tid 956039] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4TgAAAS4"]
[Thu Sep 17 15:06:03.429808 2026] [security2:error] [pid 955873:tid 956124] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4TwAAAYM"]
[Thu Sep 17 15:06:03.430399 2026] [security2:error] [pid 955873:tid 956061] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/"] [unique_id "aqxWOxFTPRVSLOsRVhr4SwAAAUQ"]
[Thu Sep 17 15:06:03.430985 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/Psr17Factory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4UAAAAQ4"]
[Thu Sep 17 15:06:03.431082 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Factory/Psr17Factory.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4UAAAAQ4"]
[Thu Sep 17 15:06:03.457006 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4UQAAAS8"]
[Thu Sep 17 15:06:03.508071 2026] [security2:error] [pid 955873:tid 956034] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4UgAAASk"]
[Thu Sep 17 15:06:03.586108 2026] [security2:error] [pid 955873:tid 956104] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4VQAAAW8"]
[Thu Sep 17 15:06:03.596446 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.129.237:35226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WAAAAUI"]
[Thu Sep 17 15:06:03.597546 2026] [security2:error] [pid 955873:tid 956115] [client 178.20.43.173:60708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4SAAAAXo"], referer: https://berenice-vaucher.com/thank-you-for-your-comment/
[Thu Sep 17 15:06:03.618848 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4WgAAARo"]
[Thu Sep 17 15:06:03.619993 2026] [security2:error] [pid 955873:tid 956117] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WQAAAXw"]
[Thu Sep 17 15:06:03.630211 2026] [security2:error] [pid 955873:tid 956102] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/plugins/"] [unique_id "aqxWOxFTPRVSLOsRVhr4VgAAAW0"]
[Thu Sep 17 15:06:03.666010 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WwAAAVo"]
[Thu Sep 17 15:06:03.666126 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:49838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4WwAAAVo"]
[Thu Sep 17 15:06:03.734075 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/MessageTrait.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4XgAAAUc"]
[Thu Sep 17 15:06:03.734171 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:57654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/MessageTrait.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4XgAAAUc"]
[Thu Sep 17 15:06:03.738770 2026] [security2:error] [pid 955873:tid 956005] [client 36.50.43.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "greenbrickbuilders.com"] [uri "/index.php"] [unique_id "aqxWORFTPRVSLOsRVhr4AAAAAQw"]
[Thu Sep 17 15:06:03.780827 2026] [security2:error] [pid 955873:tid 956036] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4XwAAASs"]
[Thu Sep 17 15:06:03.784439 2026] [security2:error] [pid 955873:tid 956082] [client 181.94.90.36:44650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4XAABWSk"]
[Thu Sep 17 15:06:03.786520 2026] [security2:error] [pid 955873:tid 956080] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4YAAAAVc"]
[Thu Sep 17 15:06:03.816992 2026] [security2:error] [pid 955873:tid 956004] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4ZAAAAQs"]
[Thu Sep 17 15:06:03.817030 2026] [security2:error] [pid 955873:tid 956062] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4ZgAAAUU"]
[Thu Sep 17 15:06:03.819544 2026] [security2:error] [pid 955873:tid 956090] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/themes/"] [unique_id "aqxWOxFTPRVSLOsRVhr4YQAAAWE"]
[Thu Sep 17 15:06:03.944113 2026] [security2:error] [pid 955873:tid 956020] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWOxFTPRVSLOsRVhr4aQAAARs"]
[Thu Sep 17 15:06:04.015836 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:57666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Request.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4awAAAWc"]
[Thu Sep 17 15:06:04.015924 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:57666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Request.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4awAAAWc"]
[Thu Sep 17 15:06:04.023493 2026] [autoindex:error] [pid 955873:tid 956048] [client 139.28.219.68:41578] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:04.024000 2026] [security2:error] [pid 955873:tid 956048] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/includes/"] [unique_id "aqxWOxFTPRVSLOsRVhr4agAAATc"]
[Thu Sep 17 15:06:04.052350 2026] [security2:error] [pid 955873:tid 956088] [client 2a01:7e03::2000:e4ff:fed3:3768:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entrustcounseling.com"] [uri "/index.php"] [unique_id "aqxWOxFTPRVSLOsRVhr4VAABXyg"], referer: https://duckduckgo.com/
[Thu Sep 17 15:06:04.069656 2026] [security2:error] [pid 955873:tid 956127] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4bAAAAYY"]
[Thu Sep 17 15:06:04.108274 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4bQAAAWA"]
[Thu Sep 17 15:06:04.124628 2026] [security2:error] [pid 955873:tid 956016] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4bgAAARc"]
[Thu Sep 17 15:06:04.269063 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4cgAAAVI"]
[Thu Sep 17 15:06:04.280354 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.129.237:35240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4cwAAATQ"]
[Thu Sep 17 15:06:04.292691 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/RequestTrait.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4dAAAAWM"]
[Thu Sep 17 15:06:04.292774 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:57676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/RequestTrait.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4dAAAAWM"]
[Thu Sep 17 15:06:04.319114 2026] [security2:error] [pid 955873:tid 956022] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4eAAAAR0"]
[Thu Sep 17 15:06:04.341580 2026] [security2:error] [pid 955873:tid 956079] [client 16.216.88.236:43008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4bwABVi0"]
[Thu Sep 17 15:06:04.350229 2026] [security2:error] [pid 955873:tid 956073] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/index.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4cAAAAVA"]
[Thu Sep 17 15:06:04.352187 2026] [security2:error] [pid 955873:tid 956125] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4eQAAAYQ"]
[Thu Sep 17 15:06:04.428029 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4ewAAASw"]
[Thu Sep 17 15:06:04.569354 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:57690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Response.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4gAAAAYA"]
[Thu Sep 17 15:06:04.569453 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:57690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Response.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4gAAAAYA"]
[Thu Sep 17 15:06:04.584381 2026] [security2:error] [pid 955873:tid 956043] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4gQAAATI"]
[Thu Sep 17 15:06:04.637283 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4ggAAAR4"]
[Thu Sep 17 15:06:04.654191 2026] [security2:error] [pid 955873:tid 956025] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4gwAAASA"]
[Thu Sep 17 15:06:04.715825 2026] [security2:error] [pid 955873:tid 956099] [client 139.28.219.68:55978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-admin/index.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4fwAAAWo"]
[Thu Sep 17 15:06:04.736941 2026] [security2:error] [pid 955873:tid 956026] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4hAAAASE"]
[Thu Sep 17 15:06:04.850217 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/ServerRequest.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4hwAAAV0"]
[Thu Sep 17 15:06:04.850314 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:57704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/ServerRequest.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4hwAAAV0"]
[Thu Sep 17 15:06:04.890061 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4igAAAWQ"]
[Thu Sep 17 15:06:04.891226 2026] [security2:error] [pid 955873:tid 956047] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4iwAAATY"]
[Thu Sep 17 15:06:04.914897 2026] [security2:error] [pid 955873:tid 956049] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWPBFTPRVSLOsRVhr4jAAAATg"]
[Thu Sep 17 15:06:04.984348 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.129.237:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWPBFTPRVSLOsRVhr4kAAAASI"]
[Thu Sep 17 15:06:05.010040 2026] [autoindex:error] [pid 955873:tid 956120] [client 139.28.219.68:0] AH01276: Cannot serve directory /home3/ncfwbqmy/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:05.010561 2026] [security2:error] [pid 955873:tid 956120] [client 139.28.219.68:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ncf.wbq.mybluehost.me"] [uri "/cgi-sys/403.html"] [unique_id "aqxWPBFTPRVSLOsRVhr4kQAAAX8"]
[Thu Sep 17 15:06:05.020933 2026] [security2:error] [pid 955873:tid 956055] [client 139.28.219.68:41578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "ncf.wbq.mybluehost.me"] [uri "/wp-content/upgrade/"] [unique_id "aqxWPBFTPRVSLOsRVhr4jQAAAT4"]
[Thu Sep 17 15:06:05.051133 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4lAAAATU"]
[Thu Sep 17 15:06:05.085856 2026] [security2:error] [pid 955873:tid 956028] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4lQAAASM"]
[Thu Sep 17 15:06:05.144560 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Stream.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4lwAAAQ4"]
[Thu Sep 17 15:06:05.144666 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:57710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Stream.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4lwAAAQ4"]
[Thu Sep 17 15:06:05.199927 2026] [security2:error] [pid 955873:tid 956033] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4mAAAASg"]
[Thu Sep 17 15:06:05.217434 2026] [security2:error] [pid 955873:tid 956034] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4mgAAASk"]
[Thu Sep 17 15:06:05.318920 2026] [security2:error] [pid 955873:tid 956059] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4nQAAAUI"]
[Thu Sep 17 15:06:05.372126 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4oAAAAYI"]
[Thu Sep 17 15:06:05.423450 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/StreamTrait.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4owAAAT0"]
[Thu Sep 17 15:06:05.423548 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:57712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/StreamTrait.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4owAAAT0"]
[Thu Sep 17 15:06:05.479173 2026] [security2:error] [pid 955873:tid 956024] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4pAAAAR8"]
[Thu Sep 17 15:06:05.514200 2026] [security2:error] [pid 955873:tid 956083] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4pQAAAVo"]
[Thu Sep 17 15:06:05.527304 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4pgAAARI"]
[Thu Sep 17 15:06:05.670011 2026] [security2:error] [pid 955873:tid 956008] [client 34.166.129.237:35254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4qAAAAQ8"]
[Thu Sep 17 15:06:05.685320 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4qQAAATE"]
[Thu Sep 17 15:06:05.705958 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:57724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/UploadedFile.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4qgAAASs"]
[Thu Sep 17 15:06:05.706047 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:57724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/UploadedFile.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4qgAAASs"]
[Thu Sep 17 15:06:05.754897 2026] [security2:error] [pid 955873:tid 956062] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4rQAAAUU"]
[Thu Sep 17 15:06:05.754897 2026] [security2:error] [pid 955873:tid 956004] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4rAAAAQs"]
[Thu Sep 17 15:06:05.839310 2026] [security2:error] [pid 955873:tid 956100] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4sQAAAWs"]
[Thu Sep 17 15:06:05.983891 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Uri.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4uQAAAYY"]
[Thu Sep 17 15:06:05.983988 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Nyholm/Psr7/Uri.php"] [unique_id "aqxWPRFTPRVSLOsRVhr4uQAAAYY"]
[Thu Sep 17 15:06:05.992297 2026] [security2:error] [pid 955873:tid 956089] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWPRFTPRVSLOsRVhr4ugAAAWA"]
[Thu Sep 17 15:06:06.028596 2026] [security2:error] [pid 955873:tid 956068] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4uwAAAUs"]
[Thu Sep 17 15:06:06.149098 2026] [security2:error] [pid 955873:tid 956079] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4wAAAAVY"]
[Thu Sep 17 15:06:06.168908 2026] [security2:error] [pid 955873:tid 956006] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4wgAAAQ0"]
[Thu Sep 17 15:06:06.271798 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWPhFTPRVSLOsRVhr4wwAAATI"]
[Thu Sep 17 15:06:06.302776 2026] [security2:error] [pid 955873:tid 956107] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4xAAAAXI"]
[Thu Sep 17 15:06:06.306425 2026] [security2:error] [pid 955873:tid 956091] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4xQAAAWI"]
[Thu Sep 17 15:06:06.363976 2026] [security2:error] [pid 955873:tid 956074] [client 34.166.129.237:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWPhFTPRVSLOsRVhr4yQAAAVE"]
[Thu Sep 17 15:06:06.419791 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4ywAAAR4"]
[Thu Sep 17 15:06:06.455211 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWPhFTPRVSLOsRVhr4zAAAAUg"]
[Thu Sep 17 15:06:06.461768 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4zQAAAWo"]
[Thu Sep 17 15:06:06.585033 2026] [security2:error] [pid 955873:tid 956128] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr4zgAAAYc"]
[Thu Sep 17 15:06:06.598494 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/wp-includes/php-ai-client/third-party/"] [unique_id "aqxWPhFTPRVSLOsRVhr4zwAAAWQ"]
[Thu Sep 17 15:06:06.621202 2026] [security2:error] [pid 955873:tid 956057] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr40AAAAUA"]
[Thu Sep 17 15:06:06.622071 2026] [security2:error] [pid 955873:tid 956067] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr40QAAAUo"]
[Thu Sep 17 15:06:06.700291 2026] [security2:error] [pid 955873:tid 956026] [client 104.28.198.244:22661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWPhFTPRVSLOsRVhr40wAAASE"]
[Thu Sep 17 15:06:06.702632 2026] [authz_core:error] [pid 955873:tid 956037] [client 4.240.114.86:64631] AH01630: client denied by server configuration: /home2/loseyov0/public_html/staging-paltals/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:06:06.731056 2026] [security2:error] [pid 955873:tid 955929] [remote 216.73.217.142:14717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWPhFTPRVSLOsRVhr41AABdDc"]
[Thu Sep 17 15:06:06.779035 2026] [security2:error] [pid 955873:tid 956060] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr41wAAAUM"]
[Thu Sep 17 15:06:06.828584 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr42gAAAS4"]
[Thu Sep 17 15:06:06.864125 2026] [security2:error] [pid 955873:tid 956061] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr42wAAAUQ"]
[Thu Sep 17 15:06:06.883511 2026] [security2:error] [pid 955873:tid 956026] [client 104.28.198.244:22661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWPhFTPRVSLOsRVhr40wAAASE"]
[Thu Sep 17 15:06:06.928001 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPhFTPRVSLOsRVhr41gAAAXg"]
[Thu Sep 17 15:06:06.928021 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPhFTPRVSLOsRVhr41gAAAXg"]
[Thu Sep 17 15:06:06.935973 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWPhFTPRVSLOsRVhr43gAAASQ"]
[Thu Sep 17 15:06:07.040270 2026] [security2:error] [pid 955873:tid 956010] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr44QAAARE"]
[Thu Sep 17 15:06:07.068370 2026] [security2:error] [pid 955873:tid 956124] [client 34.166.129.237:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWPxFTPRVSLOsRVhr44gAAAYM"]
[Thu Sep 17 15:06:07.089075 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr44wAAARo"]
[Thu Sep 17 15:06:07.109340 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/"] [unique_id "aqxWPxFTPRVSLOsRVhr45QAAAW0"]
[Thu Sep 17 15:06:07.128454 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.221.252:45188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWPxFTPRVSLOsRVhr45gAAAVo"]
[Thu Sep 17 15:06:07.144992 2026] [security2:error] [pid 955873:tid 956011] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr45wAAARI"]
[Thu Sep 17 15:06:07.242400 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr46QAAASY"]
[Thu Sep 17 15:06:07.268222 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/"] [unique_id "aqxWPxFTPRVSLOsRVhr46gAAARY"]
[Thu Sep 17 15:06:07.358703 2026] [security2:error] [pid 955873:tid 956008] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr48gAAAQ8"]
[Thu Sep 17 15:06:07.399099 2026] [security2:error] [pid 955873:tid 956119] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr49AAAAX4"]
[Thu Sep 17 15:06:07.423538 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr49QAAASs"]
[Thu Sep 17 15:06:07.458800 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWPxFTPRVSLOsRVhr49wAAAVc"]
[Thu Sep 17 15:06:07.521414 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr4-gAAAXs"]
[Thu Sep 17 15:06:07.561550 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr4_AAAAU8"]
[Thu Sep 17 15:06:07.702282 2026] [security2:error] [pid 955873:tid 956096] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr4_wAAAWc"]
[Thu Sep 17 15:06:07.717802 2026] [security2:error] [pid 955873:tid 956068] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5AAAAAUs"]
[Thu Sep 17 15:06:07.777456 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.129.237:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWPxFTPRVSLOsRVhr5AwAAAVM"]
[Thu Sep 17 15:06:07.787199 2026] [security2:error] [pid 955873:tid 956075] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5BQAAAVI"]
[Thu Sep 17 15:06:07.800259 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPxFTPRVSLOsRVhr4_QAAAYY"]
[Thu Sep 17 15:06:07.800275 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWPxFTPRVSLOsRVhr4_QAAAYY"]
[Thu Sep 17 15:06:07.836392 2026] [security2:error] [pid 955873:tid 956090] [client 34.166.221.252:45200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWPxFTPRVSLOsRVhr5CAAAAWE"]
[Thu Sep 17 15:06:07.877138 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5CgAAAUE"]
[Thu Sep 17 15:06:07.979853 2026] [security2:error] [pid 955873:tid 956070] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWPxFTPRVSLOsRVhr5DgAAAU0"]
[Thu Sep 17 15:06:08.035708 2026] [security2:error] [pid 955873:tid 956013] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5EAAAARQ"]
[Thu Sep 17 15:06:08.052193 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/EventDispatcherInterface.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5EQAAATI"]
[Thu Sep 17 15:06:08.052294 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/EventDispatcher/EventDispatcherInterface.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5EQAAATI"]
[Thu Sep 17 15:06:08.178192 2026] [security2:error] [pid 955873:tid 956074] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5EwAAAVE"]
[Thu Sep 17 15:06:08.190951 2026] [security2:error] [pid 955873:tid 956025] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5FAAAASA"]
[Thu Sep 17 15:06:08.256442 2026] [security2:error] [pid 955873:tid 956099] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5FQAAAWo"]
[Thu Sep 17 15:06:08.338954 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQBFTPRVSLOsRVhr5GQAAARk"]
[Thu Sep 17 15:06:08.346800 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5GgAAAVU"]
[Thu Sep 17 15:06:08.422398 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5HQAAAWQ"]
[Thu Sep 17 15:06:08.429872 2026] [security2:error] [pid 955873:tid 956023] [client 185.55.149.49:53979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5HgAAAR4"]
[Thu Sep 17 15:06:08.429959 2026] [security2:error] [pid 955873:tid 956023] [client 185.55.149.49:53979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5HgAAAR4"]
[Thu Sep 17 15:06:08.461123 2026] [security2:error] [pid 955873:tid 956091] [client 216.73.163.69:39637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5GwAAAWI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:08.505551 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5IAAAATg"]
[Thu Sep 17 15:06:08.512994 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQBFTPRVSLOsRVhr5HwAAAR0"]
[Thu Sep 17 15:06:08.530803 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.221.252:45206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWQBFTPRVSLOsRVhr5IQAAATs"]
[Thu Sep 17 15:06:08.532439 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5IgAAAWU"]
[Thu Sep 17 15:06:08.659645 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWQBFTPRVSLOsRVhr5IwAAAX8"]
[Thu Sep 17 15:06:08.661072 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5JAAAASw"]
[Thu Sep 17 15:06:08.778967 2026] [security2:error] [pid 955873:tid 956060] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5JgAAAUM"]
[Thu Sep 17 15:06:08.813032 2026] [security2:error] [pid 955873:tid 956113] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5KAAAAXg"]
[Thu Sep 17 15:06:08.871968 2026] [security2:error] [pid 955873:tid 956056] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5JwAAAT8"]
[Thu Sep 17 15:06:08.964785 2026] [security2:error] [pid 955873:tid 956003] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5LQAAAQo"]
[Thu Sep 17 15:06:08.978211 2026] [security2:error] [pid 955873:tid 956110] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWQBFTPRVSLOsRVhr5LgAAAXU"]
[Thu Sep 17 15:06:08.990877 2026] [security2:error] [pid 955873:tid 956126] [client 20.244.34.24:54274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5LwAAAYU"], referer: binance.com
[Thu Sep 17 15:06:09.002701 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5KQAAAX0"]
[Thu Sep 17 15:06:09.002727 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQBFTPRVSLOsRVhr5KQAAAX0"]
[Thu Sep 17 15:06:09.131734 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5MAAAAYg"]
[Thu Sep 17 15:06:09.141566 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5MQAAAQ4"]
[Thu Sep 17 15:06:09.149457 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/"] [unique_id "aqxWQRFTPRVSLOsRVhr5MgAAAX4"]
[Thu Sep 17 15:06:09.155066 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5MwAAASs"]
[Thu Sep 17 15:06:09.285922 2026] [security2:error] [pid 955873:tid 956062] [client 4.240.114.86:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5NgAAAUU"], referer: binance.com
[Thu Sep 17 15:06:09.303165 2026] [security2:error] [pid 955873:tid 956004] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5OAAAAQs"]
[Thu Sep 17 15:06:09.321394 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/"] [unique_id "aqxWQRFTPRVSLOsRVhr5NwAAAWk"]
[Thu Sep 17 15:06:09.347321 2026] [security2:error] [pid 955873:tid 956081] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5OwAAAVg"]
[Thu Sep 17 15:06:09.433728 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5PQAAARs"]
[Thu Sep 17 15:06:09.460638 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5PgAAAU8"]
[Thu Sep 17 15:06:09.463159 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQRFTPRVSLOsRVhr5PwAAAYI"]
[Thu Sep 17 15:06:09.465513 2026] [security2:error] [pid 955873:tid 956041] [client 34.166.221.252:45216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.energynowspa.com"] [uri "/"] [unique_id "aqxWQRFTPRVSLOsRVhr5QAAAATA"]
[Thu Sep 17 15:06:09.549010 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.129.237:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5QQAAAW8"]
[Thu Sep 17 15:06:09.585338 2026] [security2:error] [pid 955873:tid 956042] [client 220.181.108.159:64550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nlfephrata.org"] [uri "/index.php"] [unique_id "aqxWPxFTPRVSLOsRVhr49gABMT8"]
[Thu Sep 17 15:06:09.590591 2026] [security2:error] [pid 955873:tid 956017] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5RgAAARg"]
[Thu Sep 17 15:06:09.613420 2026] [security2:error] [pid 955873:tid 956090] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5SgAAAWE"]
[Thu Sep 17 15:06:09.709658 2026] [security2:error] [pid 955873:tid 956125] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5TQAAAYQ"]
[Thu Sep 17 15:06:09.770434 2026] [security2:error] [pid 955873:tid 956048] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5TgAAATc"]
[Thu Sep 17 15:06:09.792020 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5SQAAAYY"]
[Thu Sep 17 15:06:09.792045 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5SQAAAYY"]
[Thu Sep 17 15:06:09.804865 2026] [security2:error] [pid 955873:tid 956016] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5TwAAARc"]
[Thu Sep 17 15:06:09.932267 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:57760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientExceptionInterface.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5VAAAAXI"]
[Thu Sep 17 15:06:09.932346 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:57760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientExceptionInterface.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5VAAAAXI"]
[Thu Sep 17 15:06:09.941149 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWQRFTPRVSLOsRVhr5VQAAAVE"]
[Thu Sep 17 15:06:10.013325 2026] [security2:error] [pid 955873:tid 956077] [client 216.73.163.39:24317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWQRFTPRVSLOsRVhr5VgAAAVQ"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:10.028989 2026] [security2:error] [pid 955873:tid 956086] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5WQAAAV0"]
[Thu Sep 17 15:06:10.094702 2026] [security2:error] [pid 955873:tid 956023] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5WgAAAR4"]
[Thu Sep 17 15:06:10.213573 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:34860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5XAAAAWI"]
[Thu Sep 17 15:06:10.213654 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:34860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/ClientInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5XAAAAWI"]
[Thu Sep 17 15:06:10.229102 2026] [security2:error] [pid 955873:tid 956099] [client 34.166.129.237:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5XQAAAWo"]
[Thu Sep 17 15:06:10.231376 2026] [security2:error] [pid 955873:tid 956128] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5XgAAAYc"]
[Thu Sep 17 15:06:10.247120 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5XwAAATg"]
[Thu Sep 17 15:06:10.401432 2026] [security2:error] [pid 955873:tid 956120] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5agAAAX8"]
[Thu Sep 17 15:06:10.478302 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5bAAAAS4"]
[Thu Sep 17 15:06:10.540117 2026] [security2:error] [pid 955873:tid 956028] [client 34.35.44.204:51016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5bQAAASM"]
[Thu Sep 17 15:06:10.560915 2026] [security2:error] [pid 955873:tid 956021] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5bgAAARw"]
[Thu Sep 17 15:06:10.715244 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5cwAAARI"]
[Thu Sep 17 15:06:10.761823 2026] [security2:error] [pid 955873:tid 956031] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5dAAAASY"]
[Thu Sep 17 15:06:10.810552 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/NetworkExceptionInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5dQAAAQo"]
[Thu Sep 17 15:06:10.810633 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/NetworkExceptionInterface.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5dQAAAQo"]
[Thu Sep 17 15:06:10.872165 2026] [security2:error] [pid 955873:tid 956032] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5eQAAASc"]
[Thu Sep 17 15:06:10.936692 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:35318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWQhFTPRVSLOsRVhr5ewAAAR8"]
[Thu Sep 17 15:06:10.945499 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWQhFTPRVSLOsRVhr5fAAAAYg"]
[Thu Sep 17 15:06:11.024897 2026] [security2:error] [pid 955873:tid 956009] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5fQAAARA"]
[Thu Sep 17 15:06:11.101543 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/RequestExceptionInterface.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5fwAAAVc"]
[Thu Sep 17 15:06:11.101635 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Client/RequestExceptionInterface.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5fwAAAVc"]
[Thu Sep 17 15:06:11.180087 2026] [security2:error] [pid 955873:tid 956071] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5gQAAAU4"]
[Thu Sep 17 15:06:11.336416 2026] [security2:error] [pid 955873:tid 956066] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5gwAAAUk"]
[Thu Sep 17 15:06:11.352780 2026] [security2:error] [pid 955873:tid 956111] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5hAAAAXY"]
[Thu Sep 17 15:06:11.367970 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5hQAAASs"]
[Thu Sep 17 15:06:11.386616 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:34880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/"] [unique_id "aqxWQxFTPRVSLOsRVhr5iAAAAYk"]
[Thu Sep 17 15:06:11.490510 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5jQAAARg"]
[Thu Sep 17 15:06:11.562230 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/"] [unique_id "aqxWQxFTPRVSLOsRVhr5jgAAAWE"]
[Thu Sep 17 15:06:11.620349 2026] [security2:error] [pid 955873:tid 956084] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5kQAAAVs"]
[Thu Sep 17 15:06:11.620972 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.129.237:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5kgAAATE"]
[Thu Sep 17 15:06:11.639294 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5kwAAAXc"]
[Thu Sep 17 15:06:11.644129 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5lAAAAYE"]
[Thu Sep 17 15:06:11.702941 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:34880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/wp-includes/php-ai-client/third-party/Psr/Http/"] [unique_id "aqxWQxFTPRVSLOsRVhr5lQAAAVI"]
[Thu Sep 17 15:06:11.858991 2026] [security2:error] [pid 955873:tid 956070] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5mgAAAU0"]
[Thu Sep 17 15:06:11.902725 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5oAAAATk"]
[Thu Sep 17 15:06:11.911068 2026] [security2:error] [pid 955873:tid 956043] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWQxFTPRVSLOsRVhr5oQAAATI"]
[Thu Sep 17 15:06:12.020925 2026] [security2:error] [pid 955873:tid 956074] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5ogAAAVE"]
[Thu Sep 17 15:06:12.026067 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5nwAAAXA"]
[Thu Sep 17 15:06:12.026083 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWQxFTPRVSLOsRVhr5nwAAAXA"]
[Thu Sep 17 15:06:12.163549 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:34880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/MessageInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5qAAAAVU"]
[Thu Sep 17 15:06:12.163635 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:34880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/MessageInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5qAAAAVU"]
[Thu Sep 17 15:06:12.179730 2026] [security2:error] [pid 955873:tid 956064] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5qwAAAUc"]
[Thu Sep 17 15:06:12.182987 2026] [security2:error] [pid 955873:tid 956108] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5rAAAAXM"]
[Thu Sep 17 15:06:12.186889 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5rQAAAWI"]
[Thu Sep 17 15:06:12.305116 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.129.237:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5sQAAAV4"]
[Thu Sep 17 15:06:12.350628 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5sgAAAXQ"]
[Thu Sep 17 15:06:12.365999 2026] [security2:error] [pid 955873:tid 956039] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5tQAAAS4"]
[Thu Sep 17 15:06:12.372472 2026] [security2:error] [pid 955873:tid 956018] [client 156.245.246.112:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xrx.sgh.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5swAAARk"], referer: https://xrx.sgh.mybluehost.me
[Thu Sep 17 15:06:12.452039 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestFactoryInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5tgAAAUA"]
[Thu Sep 17 15:06:12.452121 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:34894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestFactoryInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5tgAAAUA"]
[Thu Sep 17 15:06:12.455053 2026] [security2:error] [pid 955873:tid 956113] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5twAAAXg"]
[Thu Sep 17 15:06:12.534894 2026] [security2:error] [pid 955873:tid 956027] [client 45.169.98.18:54387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5vAAAASI"]
[Thu Sep 17 15:06:12.534959 2026] [security2:error] [pid 955873:tid 956027] [client 45.169.98.18:54387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5vAAAASI"]
[Thu Sep 17 15:06:12.604931 2026] [security2:error] [pid 955873:tid 956019] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5vwAAARo"]
[Thu Sep 17 15:06:12.727973 2026] [security2:error] [pid 955873:tid 956031] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr5wgAAASY"]
[Thu Sep 17 15:06:12.738030 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5xAAAASc"]
[Thu Sep 17 15:06:12.738133 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/RequestInterface.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5xAAAASc"]
[Thu Sep 17 15:06:12.934295 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.239.243:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr50QAAAWk"]
[Thu Sep 17 15:06:12.936199 2026] [security2:error] [pid 955873:tid 956081] [client 34.178.167.214:34608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gsc.qjx.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr50gAAAVg"]
[Thu Sep 17 15:06:12.971503 2026] [security2:error] [pid 955873:tid 956118] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWRBFTPRVSLOsRVhr50AAAAX0"], referer: http://alrayancont.com/Telerik.Web.UI.WebResource.axd?type=rau
[Thu Sep 17 15:06:12.985384 2026] [security2:error] [pid 955873:tid 956062] [client 216.73.163.46:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWRBFTPRVSLOsRVhr5zgAAAUU"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:12.988977 2026] [security2:error] [pid 955873:tid 956024] [client 34.166.129.237:37142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWRBFTPRVSLOsRVhr50wAAAR8"]
[Thu Sep 17 15:06:13.000844 2026] [security2:error] [pid 955873:tid 956066] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWRBFTPRVSLOsRVhr51AAAAUk"]
[Thu Sep 17 15:06:13.023066 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:34910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51gAAAXY"]
[Thu Sep 17 15:06:13.023161 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:34910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51gAAAXY"]
[Thu Sep 17 15:06:13.028364 2026] [security2:error] [pid 955873:tid 956054] [client 154.190.208.131:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51wAAAT0"]
[Thu Sep 17 15:06:13.035373 2026] [security2:error] [pid 955873:tid 956054] [client 154.190.208.131:41597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr51wAAAT0"]
[Thu Sep 17 15:06:13.273339 2026] [security2:error] [pid 955873:tid 956005] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr52gAAAQw"]
[Thu Sep 17 15:06:13.305438 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr53AAAATM"]
[Thu Sep 17 15:06:13.305516 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ResponseInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr53AAAATM"]
[Thu Sep 17 15:06:13.322023 2026] [security2:error] [pid 955873:tid 956104] [client 34.178.167.214:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWRRFTPRVSLOsRVhr52wAAAW8"]
[Thu Sep 17 15:06:13.399779 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr54QAAARg"]
[Thu Sep 17 15:06:13.552938 2026] [security2:error] [pid 955873:tid 956070] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr54wAAAU0"]
[Thu Sep 17 15:06:13.558852 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr55AAAATk"]
[Thu Sep 17 15:06:13.589332 2026] [security2:error] [pid 955873:tid 956014] [client 115.244.164.14:64227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr55gAAARU"]
[Thu Sep 17 15:06:13.589409 2026] [security2:error] [pid 955873:tid 956014] [client 115.244.164.14:64227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRRFTPRVSLOsRVhr55gAAARU"]
[Thu Sep 17 15:06:13.606615 2026] [security2:error] [pid 955873:tid 956016] [client 134.185.85.61:51986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "wheresmymap.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxWRRFTPRVSLOsRVhr55wAAARc"]
[Thu Sep 17 15:06:13.609613 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:34924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr56AAAAXI"]
[Thu Sep 17 15:06:13.609685 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:34924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestFactoryInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr56AAAAXI"]
[Thu Sep 17 15:06:13.684188 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.129.237:37152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.chadstall.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWRRFTPRVSLOsRVhr56gAAAVI"]
[Thu Sep 17 15:06:13.713269 2026] [security2:error] [pid 955873:tid 956065] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr56wAAAUg"]
[Thu Sep 17 15:06:13.824560 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr58AAAAR4"]
[Thu Sep 17 15:06:13.866449 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWRRFTPRVSLOsRVhr58QAAAVQ"]
[Thu Sep 17 15:06:13.893768 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:34936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr58gAAAYc"]
[Thu Sep 17 15:06:13.894146 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:34936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/ServerRequestInterface.php"] [unique_id "aqxWRRFTPRVSLOsRVhr58gAAAYc"]
[Thu Sep 17 15:06:13.986965 2026] [security2:error] [pid 955873:tid 956055] [client 134.185.85.61:57859] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "wheresmymap.com"] [uri "/media/system/js/core.js"] [unique_id "aqxWRRFTPRVSLOsRVhr59wAAAT4"]
[Thu Sep 17 15:06:14.019504 2026] [security2:error] [pid 955873:tid 956076] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr5-AAAAVM"]
[Thu Sep 17 15:06:14.097564 2026] [security2:error] [pid 955873:tid 956018] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr5-gAAARk"]
[Thu Sep 17 15:06:14.175801 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr5-wAAAXk"]
[Thu Sep 17 15:06:14.180202 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:34944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr5_AAAAXg"]
[Thu Sep 17 15:06:14.180286 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:34944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr5_AAAAXg"]
[Thu Sep 17 15:06:14.268558 2026] [security2:error] [pid 955873:tid 956103] [client 34.178.167.214:50264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWRhFTPRVSLOsRVhr5_gAAAW4"]
[Thu Sep 17 15:06:14.338820 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6AgAAATU"]
[Thu Sep 17 15:06:14.369397 2026] [security2:error] [pid 955873:tid 956120] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6AwAAAX8"]
[Thu Sep 17 15:06:14.461235 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:34954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6BgAAAYA"]
[Thu Sep 17 15:06:14.461322 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:34954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/StreamInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6BgAAAYA"]
[Thu Sep 17 15:06:14.492566 2026] [security2:error] [pid 955873:tid 956069] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6BwAAAUw"]
[Thu Sep 17 15:06:14.513777 2026] [security2:error] [pid 955873:tid 956061] [client 186.105.232.15:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6CAAAAUQ"]
[Thu Sep 17 15:06:14.513911 2026] [security2:error] [pid 955873:tid 956061] [client 186.105.232.15:50400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6CAAAAUQ"]
[Thu Sep 17 15:06:14.641451 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6CgAAAUI"]
[Thu Sep 17 15:06:14.644466 2026] [security2:error] [pid 955873:tid 956083] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6CwAAAVo"]
[Thu Sep 17 15:06:14.739029 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:34970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6DQAAASQ"]
[Thu Sep 17 15:06:14.739121 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:34970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileFactoryInterface.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6DQAAASQ"]
[Thu Sep 17 15:06:14.799513 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6DgAAAS8"]
[Thu Sep 17 15:06:14.913276 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6EwAAAWw"]
[Thu Sep 17 15:06:14.960426 2026] [security2:error] [pid 955873:tid 956004] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWRhFTPRVSLOsRVhr6FQAAAQs"]
[Thu Sep 17 15:06:14.988354 2026] [security2:error] [pid 955873:tid 956117] [client 34.178.167.214:50278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6FwAAAXw"]
[Thu Sep 17 15:06:15.038105 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6GAAAAQo"]
[Thu Sep 17 15:06:15.038202 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:34974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UploadedFileInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6GAAAAQo"]
[Thu Sep 17 15:06:15.101752 2026] [security2:error] [pid 955873:tid 956071] [client 189.141.236.123:57426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWRhFTPRVSLOsRVhr6FgABTlg"]
[Thu Sep 17 15:06:15.113678 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6GwAAAYI"]
[Thu Sep 17 15:06:15.185095 2026] [security2:error] [pid 955873:tid 956041] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6HgAAATA"]
[Thu Sep 17 15:06:15.276209 2026] [security2:error] [pid 955873:tid 956035] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6HwAAASo"]
[Thu Sep 17 15:06:15.336586 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriFactoryInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6JAAAAUs"]
[Thu Sep 17 15:06:15.336697 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:34986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriFactoryInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6JAAAAUs"]
[Thu Sep 17 15:06:15.429680 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6KAAAAQw"]
[Thu Sep 17 15:06:15.461420 2026] [security2:error] [pid 955873:tid 956112] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6KwAAAXc"]
[Thu Sep 17 15:06:15.507627 2026] [security2:error] [pid 955873:tid 956115] [client 216.73.163.60:53887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.163.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6KQAAAXo"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:15.585592 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6LQAAAUE"]
[Thu Sep 17 15:06:15.636209 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6LwAAARc"]
[Thu Sep 17 15:06:15.636293 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:34994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/Http/Message/UriInterface.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6LwAAARc"]
[Thu Sep 17 15:06:15.738583 2026] [security2:error] [pid 955873:tid 956074] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6MAAAAVE"]
[Thu Sep 17 15:06:15.743308 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6MQAAAVI"]
[Thu Sep 17 15:06:15.828107 2026] [security2:error] [pid 955873:tid 956050] [client 34.178.167.214:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6NgAAATk"]
[Thu Sep 17 15:06:15.842908 2026] [security2:error] [pid 955873:tid 956107] [client 216.73.163.57:50717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6MwAAAXI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:15.897331 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWRxFTPRVSLOsRVhr6OQAAAVQ"]
[Thu Sep 17 15:06:15.917124 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:35000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/"] [unique_id "aqxWRxFTPRVSLOsRVhr6OgAAAXM"]
[Thu Sep 17 15:06:16.010568 2026] [security2:error] [pid 955873:tid 956067] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6PQAAAUo"]
[Thu Sep 17 15:06:16.055971 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6PgAAAWM"]
[Thu Sep 17 15:06:16.078079 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/"] [unique_id "aqxWSBFTPRVSLOsRVhr6PwAAAXQ"]
[Thu Sep 17 15:06:16.103084 2026] [security2:error] [pid 955873:tid 956076] [client 20.244.34.24:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6QgAAAVM"], referer: binance.com
[Thu Sep 17 15:06:16.172030 2026] [security2:error] [pid 955873:tid 956119] [client 143.14.6.18:17824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6IAAAAX4"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:16.182557 2026] [security2:error] [pid 955873:tid 956098] [client 216.75.132.105:59940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWRxFTPRVSLOsRVhr6HQAAAWk"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:16.213503 2026] [security2:error] [pid 955873:tid 956064] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6RQAAAUc"]
[Thu Sep 17 15:06:16.218078 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:35000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/wp-includes/php-ai-client/third-party/Psr/"] [unique_id "aqxWSBFTPRVSLOsRVhr6RgAAAXk"]
[Thu Sep 17 15:06:16.293392 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6SQAAAW4"]
[Thu Sep 17 15:06:16.365930 2026] [security2:error] [pid 955873:tid 956034] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6TwAAASk"]
[Thu Sep 17 15:06:16.520870 2026] [security2:error] [pid 955873:tid 956049] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6UwAAATg"]
[Thu Sep 17 15:06:16.555598 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6TgAAARw"]
[Thu Sep 17 15:06:16.555618 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6TgAAARw"]
[Thu Sep 17 15:06:16.570038 2026] [security2:error] [pid 955873:tid 956059] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6VQAAAUI"]
[Thu Sep 17 15:06:16.677897 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6WQAAASY"]
[Thu Sep 17 15:06:16.693078 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:35000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/CacheInterface.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6WgAAASc"]
[Thu Sep 17 15:06:16.693152 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:35000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-ai-client/third-party/Psr/SimpleCache/CacheInterface.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6WgAAASc"]
[Thu Sep 17 15:06:16.723373 2026] [security2:error] [pid 955873:tid 956094] [client 34.178.167.214:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWSBFTPRVSLOsRVhr6XAAAAWU"]
[Thu Sep 17 15:06:16.833121 2026] [security2:error] [pid 955873:tid 956106] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6YgAAAXE"]
[Thu Sep 17 15:06:16.847543 2026] [security2:error] [pid 955873:tid 956004] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6YwAAAQs"]
[Thu Sep 17 15:06:16.971819 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxWSBFTPRVSLOsRVhr6agAAAR8"]
[Thu Sep 17 15:06:16.985775 2026] [security2:error] [pid 955873:tid 956066] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWSBFTPRVSLOsRVhr6bAAAAUk"]
[Thu Sep 17 15:06:17.128615 2026] [security2:error] [pid 955873:tid 956068] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6cwAAAUs"]
[Thu Sep 17 15:06:17.134420 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxWSRFTPRVSLOsRVhr6cQAAAYk"]
[Thu Sep 17 15:06:17.142696 2026] [security2:error] [pid 955873:tid 956038] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6dAAAAS0"]
[Thu Sep 17 15:06:17.243997 2026] [security2:error] [pid 955873:tid 956117] [client 216.75.132.105:59954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6cgAAAXw"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:17.274271 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/wp-includes/"] [unique_id "aqxWSRFTPRVSLOsRVhr6eAAAAWc"]
[Thu Sep 17 15:06:17.295440 2026] [security2:error] [pid 955873:tid 956122] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6egAAAYE"]
[Thu Sep 17 15:06:17.406736 2026] [security2:error] [pid 955873:tid 956085] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6ggAAAVw"]
[Thu Sep 17 15:06:17.410181 2026] [security2:error] [pid 955873:tid 956054] [client 143.14.6.18:17834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6ewAAAT0"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:17.429161 2026] [security2:error] [pid 955873:tid 956115] [client 181.1.121.73:56371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6fgABelw"]
[Thu Sep 17 15:06:17.451292 2026] [security2:error] [pid 955873:tid 956007] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6hQAAAQ4"]
[Thu Sep 17 15:06:17.609568 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6hAAAATI"]
[Thu Sep 17 15:06:17.609590 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6hAAAATI"]
[Thu Sep 17 15:06:17.610209 2026] [security2:error] [pid 955873:tid 956067] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6iwAAAUo"]
[Thu Sep 17 15:06:17.659220 2026] [security2:error] [pid 955873:tid 956014] [client 34.178.167.214:50294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6jAAAARU"]
[Thu Sep 17 15:06:17.686887 2026] [security2:error] [pid 955873:tid 956088] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6jgAAAV8"]
[Thu Sep 17 15:06:17.751173 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:35010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6jwAAASw"]
[Thu Sep 17 15:06:17.751285 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxWSRFTPRVSLOsRVhr6jwAAASw"]
[Thu Sep 17 15:06:17.771241 2026] [security2:error] [pid 955873:tid 956078] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6kAAAAVU"]
[Thu Sep 17 15:06:17.934530 2026] [security2:error] [pid 955873:tid 956098] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6mAAAAWk"]
[Thu Sep 17 15:06:17.967853 2026] [security2:error] [pid 955873:tid 956057] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWSRFTPRVSLOsRVhr6mgAAAUA"]
[Thu Sep 17 15:06:18.048689 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:35020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable-deprecated.php"] [unique_id "aqxWShFTPRVSLOsRVhr6nAAAAX8"]
[Thu Sep 17 15:06:18.048782 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:35020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable-deprecated.php"] [unique_id "aqxWShFTPRVSLOsRVhr6nAAAAX8"]
[Thu Sep 17 15:06:18.094809 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6nQAAATU"]
[Thu Sep 17 15:06:18.245782 2026] [security2:error] [pid 955873:tid 956087] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6ogAAAV4"]
[Thu Sep 17 15:06:18.254600 2026] [security2:error] [pid 955873:tid 956019] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6owAAARo"]
[Thu Sep 17 15:06:18.300171 2026] [security2:error] [pid 955873:tid 956121] [client 34.178.167.214:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWShFTPRVSLOsRVhr6pgAAAYA"]
[Thu Sep 17 15:06:18.344513 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable.php"] [unique_id "aqxWShFTPRVSLOsRVhr6qQAAARY"]
[Thu Sep 17 15:06:18.344608 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pluggable.php"] [unique_id "aqxWShFTPRVSLOsRVhr6qQAAARY"]
[Thu Sep 17 15:06:18.415045 2026] [security2:error] [pid 955873:tid 956031] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6qgAAASY"]
[Thu Sep 17 15:06:18.522792 2026] [security2:error] [pid 955873:tid 956020] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6rgAAARs"]
[Thu Sep 17 15:06:18.568606 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6sAAAAVc"]
[Thu Sep 17 15:06:18.636357 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:35038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxWShFTPRVSLOsRVhr6sQAAASs"]
[Thu Sep 17 15:06:18.731190 2026] [security2:error] [pid 955873:tid 956118] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6sgAAAX0"]
[Thu Sep 17 15:06:18.792841 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxWShFTPRVSLOsRVhr6tgAAAS0"]
[Thu Sep 17 15:06:18.796216 2026] [security2:error] [pid 955873:tid 956051] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6uAAAATo"]
[Thu Sep 17 15:06:18.862118 2026] [security2:error] [pid 955873:tid 956102] [client 4.240.114.86:54268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxWShFTPRVSLOsRVhr6uQAAAW0"], referer: binance.com
[Thu Sep 17 15:06:18.889092 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWShFTPRVSLOsRVhr6vAAAATM"]
[Thu Sep 17 15:06:18.940648 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/wp-includes/"] [unique_id "aqxWShFTPRVSLOsRVhr6vgAAAYg"]
[Thu Sep 17 15:06:19.047064 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr61AAAASg"]
[Thu Sep 17 15:06:19.067862 2026] [security2:error] [pid 955873:tid 956007] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr61QAAAQ4"]
[Thu Sep 17 15:06:19.102313 2026] [security2:error] [pid 955873:tid 956104] [client 185.55.149.49:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWSxFTPRVSLOsRVhr62QAAAW8"]
[Thu Sep 17 15:06:19.105089 2026] [security2:error] [pid 955873:tid 956104] [client 185.55.149.49:54596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWSxFTPRVSLOsRVhr62QAAAW8"]
[Thu Sep 17 15:06:19.106195 2026] [security2:error] [pid 955873:tid 956065] [client 34.178.167.214:50302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWSxFTPRVSLOsRVhr62wAAAUg"]
[Thu Sep 17 15:06:19.200306 2026] [security2:error] [pid 955873:tid 956050] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr63wAAATk"]
[Thu Sep 17 15:06:19.286167 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr61wAAAYY"]
[Thu Sep 17 15:06:19.286199 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr61wAAAYY"]
[Thu Sep 17 15:06:19.339925 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr65QAAAVU"]
[Thu Sep 17 15:06:19.360429 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr65wAAAWM"]
[Thu Sep 17 15:06:19.431555 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:35038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/entry.php"] [unique_id "aqxWSxFTPRVSLOsRVhr66QAAAX4"]
[Thu Sep 17 15:06:19.431629 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:35038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/entry.php"] [unique_id "aqxWSxFTPRVSLOsRVhr66QAAAX4"]
[Thu Sep 17 15:06:19.520129 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr66wAAAXk"]
[Thu Sep 17 15:06:19.612413 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr67QAAAW4"]
[Thu Sep 17 15:06:19.684078 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr67gAAATU"]
[Thu Sep 17 15:06:19.712430 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:35054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/mo.php"] [unique_id "aqxWSxFTPRVSLOsRVhr67wAAASk"]
[Thu Sep 17 15:06:19.712534 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:35054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/mo.php"] [unique_id "aqxWSxFTPRVSLOsRVhr67wAAASk"]
[Thu Sep 17 15:06:19.788858 2026] [security2:error] [pid 955873:tid 956035] [client 45.131.194.119:42199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.194.131.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWShFTPRVSLOsRVhr6swAAASo"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:19.837439 2026] [security2:error] [pid 955873:tid 956028] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr69gAAASM"]
[Thu Sep 17 15:06:19.850342 2026] [security2:error] [pid 955873:tid 956120] [client 34.178.167.214:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWSxFTPRVSLOsRVhr6-QAAAX8"]
[Thu Sep 17 15:06:19.890995 2026] [security2:error] [pid 955873:tid 956079] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr6-gAAAVY"]
[Thu Sep 17 15:06:19.963347 2026] [security2:error] [pid 955873:tid 956081] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr69QAAAVg"], referer: http://alrayancont.com/solr/#/
[Thu Sep 17 15:06:19.994710 2026] [security2:error] [pid 955873:tid 956073] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWSxFTPRVSLOsRVhr6_wAAAVA"]
[Thu Sep 17 15:06:20.003777 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:51334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/plural-forms.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7AAAAARY"]
[Thu Sep 17 15:06:20.003867 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:51334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/plural-forms.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7AAAAARY"]
[Thu Sep 17 15:06:20.069858 2026] [security2:error] [pid 955873:tid 956054] [client 39.34.162.59:38304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWSxFTPRVSLOsRVhr6_gAAAT0"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:20.149373 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7BQAAASQ"]
[Thu Sep 17 15:06:20.150981 2026] [security2:error] [pid 955873:tid 956012] [client 181.166.70.135:47328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7AQAAARM"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:20.169392 2026] [security2:error] [pid 955873:tid 956061] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7BgAAAUQ"]
[Thu Sep 17 15:06:20.301650 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/po.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7CQAAAYQ"]
[Thu Sep 17 15:06:20.301766 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/po.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7CQAAAYQ"]
[Thu Sep 17 15:06:20.305974 2026] [security2:error] [pid 955873:tid 956072] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7CgAAAU8"]
[Thu Sep 17 15:06:20.442829 2026] [security2:error] [pid 955873:tid 956036] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7HwAAASs"]
[Thu Sep 17 15:06:20.459969 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7IgAAAYc"]
[Thu Sep 17 15:06:20.511779 2026] [security2:error] [pid 955873:tid 956024] [client 45.146.54.107:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7IQAAAR8"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:20.589037 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/streams.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7JgAAAW0"]
[Thu Sep 17 15:06:20.589142 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:51358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/streams.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7JgAAAW0"]
[Thu Sep 17 15:06:20.613217 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7JwAAATM"]
[Thu Sep 17 15:06:20.715763 2026] [security2:error] [pid 955873:tid 956033] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7KwAAASg"]
[Thu Sep 17 15:06:20.771061 2026] [security2:error] [pid 955873:tid 956112] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7LQAAAXc"]
[Thu Sep 17 15:06:20.807446 2026] [security2:error] [pid 955873:tid 956011] [client 34.178.167.214:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7LwAAARI"]
[Thu Sep 17 15:06:20.820725 2026] [security2:error] [pid 955873:tid 956123] [client 216.73.163.59:44293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7LgAAAYI"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:20.879812 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:51374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/translations.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7MwAAAYE"]
[Thu Sep 17 15:06:20.879922 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:51374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/translations.php"] [unique_id "aqxWTBFTPRVSLOsRVhr7MwAAAYE"]
[Thu Sep 17 15:06:20.928605 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7NwAAAVI"]
[Thu Sep 17 15:06:20.988417 2026] [security2:error] [pid 955873:tid 956077] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWTBFTPRVSLOsRVhr7OAAAAVQ"]
[Thu Sep 17 15:06:21.085299 2026] [security2:error] [pid 955873:tid 956014] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7OQAAARU"]
[Thu Sep 17 15:06:21.165151 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:51388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxWTRFTPRVSLOsRVhr7OwAAAWs"]
[Thu Sep 17 15:06:21.239418 2026] [security2:error] [pid 955873:tid 956045] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7PgAAATQ"]
[Thu Sep 17 15:06:21.261312 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7PwAAAWk"]
[Thu Sep 17 15:06:21.342155 2026] [authz_core:error] [pid 955873:tid 956088] [client 143.244.57.120:57096] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/error_log
[Thu Sep 17 15:06:21.353029 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxWTRFTPRVSLOsRVhr7QAAAAV8"]
[Thu Sep 17 15:06:21.393921 2026] [security2:error] [pid 955873:tid 956057] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7RgAAAUA"]
[Thu Sep 17 15:06:21.493032 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:51388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/wp-includes/"] [unique_id "aqxWTRFTPRVSLOsRVhr7SgAAATU"]
[Thu Sep 17 15:06:21.534182 2026] [security2:error] [pid 955873:tid 956055] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7TAAAAT4"]
[Thu Sep 17 15:06:21.554750 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7TQAAASI"]
[Thu Sep 17 15:06:21.710645 2026] [security2:error] [pid 955873:tid 956021] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7VAAAARw"]
[Thu Sep 17 15:06:21.717813 2026] [security2:error] [pid 955873:tid 956121] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7UwAAAYA"], referer: http://alrayancont.com/login.do
[Thu Sep 17 15:06:21.746746 2026] [security2:error] [pid 955873:tid 956026] [client 34.178.167.214:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7VQAAASE"]
[Thu Sep 17 15:06:21.807085 2026] [security2:error] [pid 955873:tid 956054] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7VgAAAT0"]
[Thu Sep 17 15:06:21.852205 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7TgAAATw"]
[Thu Sep 17 15:06:21.852235 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7TgAAATw"]
[Thu Sep 17 15:06:21.865746 2026] [security2:error] [pid 955873:tid 956042] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWTRFTPRVSLOsRVhr7WwAAATE"]
[Thu Sep 17 15:06:21.989244 2026] [security2:error] [pid 955873:tid 956052] [client 213.231.6.109:38854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7XAAAATs"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:21.997453 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-request.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7XwAAAYQ"]
[Thu Sep 17 15:06:21.997560 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:51388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-request.php"] [unique_id "aqxWTRFTPRVSLOsRVhr7XwAAAYQ"]
[Thu Sep 17 15:06:22.019580 2026] [security2:error] [pid 955873:tid 956020] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7YAAAARs"]
[Thu Sep 17 15:06:22.085419 2026] [security2:error] [pid 955873:tid 956008] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7YQAAAQ8"]
[Thu Sep 17 15:06:22.174287 2026] [security2:error] [pid 955873:tid 956093] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7YwAAAWQ"]
[Thu Sep 17 15:06:22.285196 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:51396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-response.php"] [unique_id "aqxWThFTPRVSLOsRVhr7aQAAAUs"]
[Thu Sep 17 15:06:22.285303 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:51396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-response.php"] [unique_id "aqxWThFTPRVSLOsRVhr7aQAAAUs"]
[Thu Sep 17 15:06:22.331228 2026] [security2:error] [pid 955873:tid 956003] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7awAAAQo"]
[Thu Sep 17 15:06:22.358261 2026] [security2:error] [pid 955873:tid 956102] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7bAAAAW0"]
[Thu Sep 17 15:06:22.491109 2026] [security2:error] [pid 955873:tid 956085] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7cgAAAVw"]
[Thu Sep 17 15:06:22.564812 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-server.php"] [unique_id "aqxWThFTPRVSLOsRVhr7dwAAAWw"]
[Thu Sep 17 15:06:22.564910 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/class-wp-rest-server.php"] [unique_id "aqxWThFTPRVSLOsRVhr7dwAAAWw"]
[Thu Sep 17 15:06:22.568135 2026] [security2:error] [pid 955873:tid 956040] [client 34.178.167.214:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWThFTPRVSLOsRVhr7eAAAAS8"]
[Thu Sep 17 15:06:22.580283 2026] [security2:error] [pid 955873:tid 956090] [client 20.244.34.24:61052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxWThFTPRVSLOsRVhr7eQAAAWE"], referer: binance.com
[Thu Sep 17 15:06:22.629984 2026] [security2:error] [pid 955873:tid 956050] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7fQAAATk"]
[Thu Sep 17 15:06:22.645935 2026] [security2:error] [pid 955873:tid 956127] [client 34.154.239.243:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7fgAAAYY"]
[Thu Sep 17 15:06:22.806421 2026] [security2:error] [pid 955873:tid 956092] [client 34.154.239.243:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWThFTPRVSLOsRVhr7gQAAAWM"]
[Thu Sep 17 15:06:22.842610 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:51416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxWThFTPRVSLOsRVhr7gwAAARg"]
[Thu Sep 17 15:06:22.902855 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWThFTPRVSLOsRVhr7hAAAAWk"]
[Thu Sep 17 15:06:23.016598 2026] [security2:error] [pid 955873:tid 956045] [client 45.169.98.18:54949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWThFTPRVSLOsRVhr7iQAAATQ"]
[Thu Sep 17 15:06:23.016754 2026] [security2:error] [pid 955873:tid 956045] [client 45.169.98.18:54949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWThFTPRVSLOsRVhr7iQAAATQ"]
[Thu Sep 17 15:06:23.043177 2026] [authz_core:error] [pid 955873:tid 956018] [client 143.244.57.120:57096] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/endpoints/error_log
[Thu Sep 17 15:06:23.056442 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxWTxFTPRVSLOsRVhr7igAAARk"]
[Thu Sep 17 15:06:23.176186 2026] [security2:error] [pid 955873:tid 956064] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWTxFTPRVSLOsRVhr7jAAAAUc"]
[Thu Sep 17 15:06:23.196137 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:51416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/wp-includes/rest-api/"] [unique_id "aqxWTxFTPRVSLOsRVhr7jQAAAVg"]
[Thu Sep 17 15:06:23.248219 2026] [security2:error] [pid 955873:tid 956055] [client 34.178.167.214:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7lAAAAT4"]
[Thu Sep 17 15:06:23.314819 2026] [security2:error] [pid 955873:tid 956079] [client 34.154.239.243:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7nAAAAVY"]
[Thu Sep 17 15:06:23.450756 2026] [security2:error] [pid 955873:tid 956072] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWTxFTPRVSLOsRVhr7oQAAAU8"]
[Thu Sep 17 15:06:23.545567 2026] [security2:error] [pid 955873:tid 956013] [client 157.100.203.16:51280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7oAAAARQ"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:06:23.556110 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7ngAAAYk"]
[Thu Sep 17 15:06:23.556132 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:57096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7ngAAAYk"]
[Thu Sep 17 15:06:23.699175 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7qwAAAWc"]
[Thu Sep 17 15:06:23.699324 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:51416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7qwAAAWc"]
[Thu Sep 17 15:06:23.728624 2026] [security2:error] [pid 955873:tid 956126] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWTxFTPRVSLOsRVhr7rAAAAYU"]
[Thu Sep 17 15:06:23.806128 2026] [security2:error] [pid 955873:tid 956062] [client 34.154.239.243:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7rwAAAUU"]
[Thu Sep 17 15:06:23.981684 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7xAAAAVU"]
[Thu Sep 17 15:06:23.981790 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7xAAAAVU"]
[Thu Sep 17 15:06:24.003501 2026] [security2:error] [pid 955873:tid 956108] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr7xwAAAXM"]
[Thu Sep 17 15:06:24.043054 2026] [security2:error] [pid 955873:tid 956005] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWTxFTPRVSLOsRVhr7xQAAAQw"], referer: http://alrayancont.com/api/session/properties
[Thu Sep 17 15:06:24.125341 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:64872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr7zwAAARE"]
[Thu Sep 17 15:06:24.125458 2026] [security2:error] [pid 955873:tid 956010] [client 115.244.164.14:64872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr7zwAAARE"]
[Thu Sep 17 15:06:24.165146 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWUBFTPRVSLOsRVhr70gAAAXs"]
[Thu Sep 17 15:06:24.260445 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr70wAAAYA"]
[Thu Sep 17 15:06:24.260565 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr70wAAAYA"]
[Thu Sep 17 15:06:24.276475 2026] [security2:error] [pid 955873:tid 956019] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr71QAAARo"]
[Thu Sep 17 15:06:24.290757 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:52074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWUBFTPRVSLOsRVhr71gAAAXk"]
[Thu Sep 17 15:06:24.307379 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:42201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr71wAAAXA"]
[Thu Sep 17 15:06:24.307491 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:42201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWUBFTPRVSLOsRVhr71wAAAXA"]
[Thu Sep 17 15:06:24.538602 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr74QAAAR4"]
[Thu Sep 17 15:06:24.538697 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:51450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr74QAAAR4"]
[Thu Sep 17 15:06:24.548222 2026] [security2:error] [pid 955873:tid 956004] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr74gAAAQs"]
[Thu Sep 17 15:06:24.775273 2026] [security2:error] [pid 955873:tid 956026] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWUBFTPRVSLOsRVhr75QAAASE"], referer: http://alrayancont.com/showLogin.cc
[Thu Sep 17 15:06:24.780108 2026] [security2:error] [pid 955873:tid 956125] [client 34.154.239.243:52082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWUBFTPRVSLOsRVhr76AAAAYQ"]
[Thu Sep 17 15:06:24.815024 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr76QAAAYg"]
[Thu Sep 17 15:06:24.815130 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxWUBFTPRVSLOsRVhr76QAAAYg"]
[Thu Sep 17 15:06:24.821540 2026] [security2:error] [pid 955873:tid 956044] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWUBFTPRVSLOsRVhr76gAAATM"]
[Thu Sep 17 15:06:25.004811 2026] [security2:error] [pid 955873:tid 956016] [client 104.28.198.244:22835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr79QAAARc"]
[Thu Sep 17 15:06:25.004923 2026] [security2:error] [pid 955873:tid 956016] [client 104.28.198.244:22835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr79QAAARc"]
[Thu Sep 17 15:06:25.090112 2026] [security2:error] [pid 955873:tid 956020] [client 34.178.167.214:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWURFTPRVSLOsRVhr7-AAAARs"]
[Thu Sep 17 15:06:25.092037 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr7-QAAAVU"]
[Thu Sep 17 15:06:25.092119 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr7-QAAAVU"]
[Thu Sep 17 15:06:25.098997 2026] [security2:error] [pid 955873:tid 956107] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWURFTPRVSLOsRVhr7-gAAAXI"]
[Thu Sep 17 15:06:25.248222 2026] [security2:error] [pid 955873:tid 956014] [client 34.154.239.243:52086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWURFTPRVSLOsRVhr7_gAAARU"]
[Thu Sep 17 15:06:25.315880 2026] [security2:error] [pid 955873:tid 956076] [client 37.39.223.21:53341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWURFTPRVSLOsRVhr7_AABU0E"]
[Thu Sep 17 15:06:25.372890 2026] [security2:error] [pid 955873:tid 956086] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWURFTPRVSLOsRVhr7_wAAAV0"]
[Thu Sep 17 15:06:25.376368 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AAAAAW4"]
[Thu Sep 17 15:06:25.376472 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AAAAAW4"]
[Thu Sep 17 15:06:25.403156 2026] [security2:error] [pid 955873:tid 956050] [client 186.105.232.15:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AgAAATk"]
[Thu Sep 17 15:06:25.403255 2026] [security2:error] [pid 955873:tid 956050] [client 186.105.232.15:50976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWURFTPRVSLOsRVhr8AgAAATk"]
[Thu Sep 17 15:06:25.650490 2026] [security2:error] [pid 955873:tid 956115] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWURFTPRVSLOsRVhr8DgAAAXo"]
[Thu Sep 17 15:06:25.677036 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8DwAAAYA"]
[Thu Sep 17 15:06:25.677135 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8DwAAAYA"]
[Thu Sep 17 15:06:25.729467 2026] [security2:error] [pid 955873:tid 956010] [client 34.154.239.243:52094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWURFTPRVSLOsRVhr8EwAAARE"]
[Thu Sep 17 15:06:25.923335 2026] [security2:error] [pid 955873:tid 956124] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWURFTPRVSLOsRVhr8FgAAAYM"]
[Thu Sep 17 15:06:25.950595 2026] [security2:error] [pid 955873:tid 956027] [client 34.178.167.214:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWURFTPRVSLOsRVhr8GQAAASI"]
[Thu Sep 17 15:06:25.965965 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8GgAAAU8"]
[Thu Sep 17 15:06:25.966066 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxWURFTPRVSLOsRVhr8GgAAAU8"]
[Thu Sep 17 15:06:26.195895 2026] [security2:error] [pid 955873:tid 956066] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWUhFTPRVSLOsRVhr8IgAAAUk"]
[Thu Sep 17 15:06:26.260448 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KQAAAYg"]
[Thu Sep 17 15:06:26.260520 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:51506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KQAAAYg"]
[Thu Sep 17 15:06:26.421772 2026] [security2:error] [pid 955873:tid 956013] [client 34.154.239.243:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KwAAARQ"]
[Thu Sep 17 15:06:26.468404 2026] [security2:error] [pid 955873:tid 956056] [client 94.54.188.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8KAAAAT8"]
[Thu Sep 17 15:06:26.471764 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWUhFTPRVSLOsRVhr8LAAAAXQ"]
[Thu Sep 17 15:06:26.546326 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8LwAAAWU"]
[Thu Sep 17 15:06:26.546474 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:51516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8LwAAAWU"]
[Thu Sep 17 15:06:26.744815 2026] [security2:error] [pid 955873:tid 956117] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWUhFTPRVSLOsRVhr8NAAAAXw"]
[Thu Sep 17 15:06:26.766009 2026] [security2:error] [pid 955873:tid 956009] [client 34.178.167.214:57862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8NQAAARA"]
[Thu Sep 17 15:06:26.829409 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8OAAAAUU"]
[Thu Sep 17 15:06:26.829546 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:51528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8OAAAAUU"]
[Thu Sep 17 15:06:26.897167 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.239.243:52112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8PAAAAVk"]
[Thu Sep 17 15:06:27.018682 2026] [security2:error] [pid 955873:tid 956050] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWUxFTPRVSLOsRVhr8QgAAATk"]
[Thu Sep 17 15:06:27.055227 2026] [security2:error] [pid 955873:tid 956069] [client 45.146.54.109:30495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adventuresofapril.com"] [uri "/wp-login.php"] [unique_id "aqxWUhFTPRVSLOsRVhr8QAAAAUw"], referer: https://adventuresofapril.com/wp-admin/
[Thu Sep 17 15:06:27.111310 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8RAAAAV4"]
[Thu Sep 17 15:06:27.111434 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:51540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8RAAAAV4"]
[Thu Sep 17 15:06:27.291491 2026] [security2:error] [pid 955873:tid 956064] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWUxFTPRVSLOsRVhr8SAAAAUc"]
[Thu Sep 17 15:06:27.360543 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.239.243:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8SQAAASg"]
[Thu Sep 17 15:06:27.397254 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8TAAAAQw"]
[Thu Sep 17 15:06:27.397339 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:51548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8TAAAAQw"]
[Thu Sep 17 15:06:27.565833 2026] [security2:error] [pid 955873:tid 956032] [client 34.35.44.204:33144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omq.zsh.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWUxFTPRVSLOsRVhr8VwAAASc"]
[Thu Sep 17 15:06:27.690098 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:51556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8WgAAAWA"]
[Thu Sep 17 15:06:27.690219 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:51556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8WgAAAWA"]
[Thu Sep 17 15:06:27.747696 2026] [security2:error] [pid 955873:tid 956080] [client 94.54.188.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8VgAAAVc"]
[Thu Sep 17 15:06:27.763224 2026] [security2:error] [pid 955873:tid 956010] [client 34.178.167.214:57874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8XAAAARE"]
[Thu Sep 17 15:06:27.849821 2026] [security2:error] [pid 955873:tid 956085] [client 34.154.239.243:52120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8YQAAAVw"]
[Thu Sep 17 15:06:27.886734 2026] [security2:error] [pid 955873:tid 956118] [client 34.35.44.204:33144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8XgAAAX0"]
[Thu Sep 17 15:06:27.979149 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8ZAAAAQ0"]
[Thu Sep 17 15:06:27.979286 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxWUxFTPRVSLOsRVhr8ZAAAAQ0"]
[Thu Sep 17 15:06:28.206721 2026] [security2:error] [pid 955873:tid 956129] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8agAAAYg"], referer: http://alrayancont.com/console
[Thu Sep 17 15:06:28.271932 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8awAAATs"]
[Thu Sep 17 15:06:28.272042 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:51572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8awAAATs"]
[Thu Sep 17 15:06:28.337906 2026] [security2:error] [pid 955873:tid 956058] [client 34.154.239.243:36212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8bAAAAUE"]
[Thu Sep 17 15:06:28.459847 2026] [security2:error] [pid 955873:tid 956090] [client 20.244.34.24:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8bwAAAWE"], referer: binance.com
[Thu Sep 17 15:06:28.551429 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8cwAAARc"]
[Thu Sep 17 15:06:28.551544 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:51584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8cwAAARc"]
[Thu Sep 17 15:06:28.659504 2026] [security2:error] [pid 955873:tid 956094] [client 34.178.167.214:57882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8dQAAAWU"]
[Thu Sep 17 15:06:28.683644 2026] [security2:error] [pid 955873:tid 956071] [client 154.160.1.216:64942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8dAABTkQ"]
[Thu Sep 17 15:06:28.724690 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:47890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8dgAAAVU"]
[Thu Sep 17 15:06:28.801013 2026] [security2:error] [pid 955873:tid 956123] [client 34.154.239.243:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8eAAAAYI"]
[Thu Sep 17 15:06:28.826499 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8eQAAAVk"]
[Thu Sep 17 15:06:28.826601 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:51590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxWVBFTPRVSLOsRVhr8eQAAAVk"]
[Thu Sep 17 15:06:29.104220 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8hgAAAW4"]
[Thu Sep 17 15:06:29.104320 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:51606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8hgAAAW4"]
[Thu Sep 17 15:06:29.291990 2026] [security2:error] [pid 955873:tid 956033] [client 34.154.239.243:36218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8kwAAASg"]
[Thu Sep 17 15:06:29.317109 2026] [core:error] [pid 955873:tid 956063] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:29.317127 2026] [core:error] [pid 955873:tid 956063] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:29.401185 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8mAAAARE"]
[Thu Sep 17 15:06:29.401297 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:51620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8mAAAARE"]
[Thu Sep 17 15:06:29.562777 2026] [security2:error] [pid 955873:tid 956028] [client 34.35.44.204:45522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8pAAAASM"]
[Thu Sep 17 15:06:29.610469 2026] [security2:error] [pid 955873:tid 956054] [client 34.178.167.214:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8pgAAAT0"]
[Thu Sep 17 15:06:29.685978 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8qwAAASs"]
[Thu Sep 17 15:06:29.686085 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:51634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8qwAAASs"]
[Thu Sep 17 15:06:29.767248 2026] [security2:error] [pid 955873:tid 956128] [client 34.154.239.243:36226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8rQAAAYc"]
[Thu Sep 17 15:06:29.958916 2026] [security2:error] [pid 955873:tid 956112] [client 185.55.149.49:53242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tAAAAXc"]
[Thu Sep 17 15:06:29.959022 2026] [security2:error] [pid 955873:tid 956112] [client 185.55.149.49:53242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tAAAAXc"]
[Thu Sep 17 15:06:29.972779 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tQAAAW8"]
[Thu Sep 17 15:06:29.972872 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxWVRFTPRVSLOsRVhr8tQAAAW8"]
[Thu Sep 17 15:06:30.255897 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:33022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8vQAAAWk"]
[Thu Sep 17 15:06:30.255994 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:33022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8vQAAAWk"]
[Thu Sep 17 15:06:30.337977 2026] [security2:error] [pid 955873:tid 956076] [client 34.178.167.214:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8wAAAAVM"]
[Thu Sep 17 15:06:30.376628 2026] [security2:error] [pid 955873:tid 956062] [client 34.35.44.204:45538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8wQAAAUU"]
[Thu Sep 17 15:06:30.464642 2026] [security2:error] [pid 955873:tid 956011] [client 34.154.239.243:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8xQAAARI"]
[Thu Sep 17 15:06:30.562005 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8yAAAAWs"]
[Thu Sep 17 15:06:30.562136 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8yAAAAWs"]
[Thu Sep 17 15:06:30.871032 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8zQAAATo"]
[Thu Sep 17 15:06:30.871153 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8zQAAATo"]
[Thu Sep 17 15:06:30.933533 2026] [security2:error] [pid 955873:tid 956091] [client 34.154.239.243:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWVhFTPRVSLOsRVhr8zgAAAWI"]
[Thu Sep 17 15:06:31.156550 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr81gAAAVw"]
[Thu Sep 17 15:06:31.156653 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:33048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr81gAAAVw"]
[Thu Sep 17 15:06:31.195953 2026] [security2:error] [pid 955873:tid 956073] [client 34.35.44.204:45544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWVxFTPRVSLOsRVhr81wAAAVA"]
[Thu Sep 17 15:06:31.407352 2026] [security2:error] [pid 955873:tid 956029] [client 34.154.239.243:36262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWVxFTPRVSLOsRVhr84AAAASQ"]
[Thu Sep 17 15:06:31.443595 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr84wAAAQo"]
[Thu Sep 17 15:06:31.443697 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:33056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr84wAAAQo"]
[Thu Sep 17 15:06:31.657532 2026] [security2:error] [pid 955873:tid 955974] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.backup"] [unique_id "aqxWVxFTPRVSLOsRVhr88QABTWQ"]
[Thu Sep 17 15:06:31.657540 2026] [security2:error] [pid 955873:tid 955970] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.bak"] [unique_id "aqxWVxFTPRVSLOsRVhr87wABTWA"]
[Thu Sep 17 15:06:31.658476 2026] [security2:error] [pid 955873:tid 955970] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.old"] [unique_id "aqxWVxFTPRVSLOsRVhr88gABTWA"]
[Thu Sep 17 15:06:31.660254 2026] [security2:error] [pid 955873:tid 955979] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env"] [unique_id "aqxWVxFTPRVSLOsRVhr8-gABTWk"]
[Thu Sep 17 15:06:31.728188 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:33058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr8_QAAAVo"]
[Thu Sep 17 15:06:31.728298 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:33058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxWVxFTPRVSLOsRVhr8_QAAAVo"]
[Thu Sep 17 15:06:31.855703 2026] [security2:error] [pid 955873:tid 956096] [client 34.178.167.214:57902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWVxFTPRVSLOsRVhr8_wAAAWc"]
[Thu Sep 17 15:06:31.907025 2026] [security2:error] [pid 955873:tid 956112] [client 34.154.239.243:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWVxFTPRVSLOsRVhr9AgAAAXc"]
[Thu Sep 17 15:06:31.910305 2026] [security2:error] [pid 955873:tid 956017] [client 74.7.175.183:36776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.hoffman412.org"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxWVxFTPRVSLOsRVhr9AQAAARg"]
[Thu Sep 17 15:06:31.956766 2026] [security2:error] [pid 955873:tid 956048] [client 45.156.129.166:57556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWVxFTPRVSLOsRVhr9AAAAATc"], referer: http://alrayancont.com/index.jsp
[Thu Sep 17 15:06:32.013872 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:33072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9BwAAAWU"]
[Thu Sep 17 15:06:32.013979 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:33072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9BwAAAWU"]
[Thu Sep 17 15:06:32.021164 2026] [security2:error] [pid 955873:tid 956104] [client 34.35.44.204:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9CAAAAW8"]
[Thu Sep 17 15:06:32.141739 2026] [security2:error] [pid 955873:tid 955991] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env~"] [unique_id "aqxWWBFTPRVSLOsRVhr9DgABYXU"]
[Thu Sep 17 15:06:32.141750 2026] [security2:error] [pid 955873:tid 955988] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.swp"] [unique_id "aqxWWBFTPRVSLOsRVhr9DwABYXI"]
[Thu Sep 17 15:06:32.160927 2026] [security2:error] [pid 955873:tid 955994] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/.env.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9DAABYXg"]
[Thu Sep 17 15:06:32.283104 2026] [security2:error] [pid 955873:tid 955981] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/app/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9HQABU2s"]
[Thu Sep 17 15:06:32.283110 2026] [security2:error] [pid 955873:tid 955998] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/backend/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9GQABU3w"]
[Thu Sep 17 15:06:32.283122 2026] [security2:error] [pid 955873:tid 955980] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/api/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9HwABU2o"]
[Thu Sep 17 15:06:32.293762 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9IAAAAUU"]
[Thu Sep 17 15:06:32.293832 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:33074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9IAAAAUU"]
[Thu Sep 17 15:06:32.336756 2026] [security2:error] [pid 955873:tid 956000] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/server/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9IQABXX4"]
[Thu Sep 17 15:06:32.378080 2026] [security2:error] [pid 955873:tid 956022] [client 207.180.11.123:18526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/gallery_med-150x150.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9IgAAAR0"]
[Thu Sep 17 15:06:32.381020 2026] [security2:error] [pid 955873:tid 956011] [client 216.75.132.234:17332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/betty-150x150.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9IwAAARI"]
[Thu Sep 17 15:06:32.384682 2026] [security2:error] [pid 955873:tid 956046] [client 34.154.239.243:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9JAAAATU"]
[Thu Sep 17 15:06:32.405329 2026] [security2:error] [pid 955873:tid 956050] [client 49.13.164.148:27042] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxWWBFTPRVSLOsRVhr9JgAAATk"], referer: https://faewave.com
[Thu Sep 17 15:06:32.450832 2026] [security2:error] [pid 955873:tid 956037] [client 143.20.253.251:44246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/gallery_children2-253x310.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9JwAAASw"]
[Thu Sep 17 15:06:32.474307 2026] [security2:error] [pid 955873:tid 956055] [client 207.180.11.251:26104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2017/04/00000314-150x150.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9LgAAAT4"]
[Thu Sep 17 15:06:32.484684 2026] [security2:error] [pid 955873:tid 956001] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/config/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9LwABOn8"]
[Thu Sep 17 15:06:32.486966 2026] [security2:error] [pid 955873:tid 955875] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/var/www/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MwABcAE"]
[Thu Sep 17 15:06:32.487003 2026] [security2:error] [pid 955873:tid 955884] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/web/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NQABcAo"]
[Thu Sep 17 15:06:32.487003 2026] [security2:error] [pid 955873:tid 955886] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/laravel/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NAABcAw"]
[Thu Sep 17 15:06:32.487029 2026] [security2:error] [pid 955873:tid 955885] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/var/www/html/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MgABcAs"]
[Thu Sep 17 15:06:32.487052 2026] [security2:error] [pid 955873:tid 955882] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/client/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NwABcAg"]
[Thu Sep 17 15:06:32.487077 2026] [security2:error] [pid 955873:tid 955887] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/public/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MAABcA0"]
[Thu Sep 17 15:06:32.487075 2026] [security2:error] [pid 955873:tid 955874] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/src/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9MQABcAA"]
[Thu Sep 17 15:06:32.487142 2026] [security2:error] [pid 955873:tid 955881] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/frontend/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9NgABcAc"]
[Thu Sep 17 15:06:32.501958 2026] [security2:error] [pid 955873:tid 956091] [client 216.75.132.234:17334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/children-253x310.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9OAAAAWI"]
[Thu Sep 17 15:06:32.546930 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:47726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9OQAAAYY"]
[Thu Sep 17 15:06:32.565222 2026] [security2:error] [pid 955873:tid 956061] [client 143.20.253.251:44262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/gallery_comdev2-150x150.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9OwAAAUQ"]
[Thu Sep 17 15:06:32.576454 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9PAAAASA"]
[Thu Sep 17 15:06:32.576494 2026] [security2:error] [pid 955873:tid 956004] [client 4.240.114.86:60733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9PQAAAQs"], referer: binance.com
[Thu Sep 17 15:06:32.576607 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9PAAAASA"]
[Thu Sep 17 15:06:32.629540 2026] [security2:error] [pid 955873:tid 955891] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/application/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9PgABQBE"]
[Thu Sep 17 15:06:32.633640 2026] [security2:error] [pid 955873:tid 955883] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/prod/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QAABLQk"]
[Thu Sep 17 15:06:32.633649 2026] [security2:error] [pid 955873:tid 955892] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/backup/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9RAABLRI"]
[Thu Sep 17 15:06:32.633722 2026] [security2:error] [pid 955873:tid 955896] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/dev/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QwABLRY"]
[Thu Sep 17 15:06:32.633751 2026] [security2:error] [pid 955873:tid 955897] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/staging/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9RgABLRc"]
[Thu Sep 17 15:06:32.633757 2026] [security2:error] [pid 955873:tid 955894] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/back/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9RQABLRQ"]
[Thu Sep 17 15:06:32.633786 2026] [security2:error] [pid 955873:tid 955890] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/production/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QQABLRA"]
[Thu Sep 17 15:06:32.633790 2026] [security2:error] [pid 955873:tid 955888] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/apps/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9PwABLQ4"]
[Thu Sep 17 15:06:32.634253 2026] [security2:error] [pid 955873:tid 955893] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/cms/.env"] [unique_id "aqxWWBFTPRVSLOsRVhr9QgABLRM"]
[Thu Sep 17 15:06:32.662300 2026] [security2:error] [pid 955873:tid 956085] [client 143.14.6.71:26816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2016/10/IMG_0243-Small-Large-253x310.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9SAAAAVw"]
[Thu Sep 17 15:06:32.691156 2026] [security2:error] [pid 955873:tid 956114] [client 143.14.6.249:51776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/subpage-EngCamp-253x310.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9SQAAAXk"]
[Thu Sep 17 15:06:32.753687 2026] [core:error] [pid 955873:tid 956027] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:32.753710 2026] [core:error] [pid 955873:tid 956027] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:32.758978 2026] [security2:error] [pid 955873:tid 956010] [client 143.14.6.71:26824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2015/09/summer_camp-253x310.jpeg"] [unique_id "aqxWWBFTPRVSLOsRVhr9TgAAARE"]
[Thu Sep 17 15:06:32.758979 2026] [security2:error] [pid 955873:tid 956111] [client 143.14.6.41:65146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/beta15/wp-content/uploads/2016/10/P1020289-253x310.jpg"] [unique_id "aqxWWBFTPRVSLOsRVhr9TQAAAXY"]
[Thu Sep 17 15:06:32.860196 2026] [security2:error] [pid 955873:tid 956063] [client 34.35.44.204:45562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9UgAAAUY"]
[Thu Sep 17 15:06:32.875338 2026] [security2:error] [pid 955873:tid 956107] [client 43.130.9.111:47394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.9.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php/Breath"] [unique_id "aqxWWBFTPRVSLOsRVhr9UwAAAXI"]
[Thu Sep 17 15:06:32.884159 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9VQAAAVc"]
[Thu Sep 17 15:06:32.885425 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:33084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9VgAAAT8"]
[Thu Sep 17 15:06:32.885499 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:33084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9VgAAAT8"]
[Thu Sep 17 15:06:32.937613 2026] [security2:error] [pid 955873:tid 956119] [client 24.159.185.48:64602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWWBFTPRVSLOsRVhr9UAABfhs"]
[Thu Sep 17 15:06:33.171614 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:33086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9XQAAAVE"]
[Thu Sep 17 15:06:33.171723 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:33086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9XQAAAVE"]
[Thu Sep 17 15:06:33.297423 2026] [security2:error] [pid 955873:tid 956093] [client 34.178.167.214:47734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9XwAAAWQ"]
[Thu Sep 17 15:06:33.454076 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:33088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ZwAAAXU"]
[Thu Sep 17 15:06:33.454192 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:33088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ZwAAAXU"]
[Thu Sep 17 15:06:33.499618 2026] [security2:error] [pid 955873:tid 956082] [client 45.169.98.18:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9aQAAAVk"]
[Thu Sep 17 15:06:33.499783 2026] [security2:error] [pid 955873:tid 956082] [client 45.169.98.18:55506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9aQAAAVk"]
[Thu Sep 17 15:06:33.741356 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9eQAAATo"]
[Thu Sep 17 15:06:33.741492 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9eQAAATo"]
[Thu Sep 17 15:06:33.798113 2026] [security2:error] [pid 955873:tid 956040] [client 34.154.239.243:36312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWWRFTPRVSLOsRVhr9fQAAAS8"]
[Thu Sep 17 15:06:33.969880 2026] [security2:error] [pid 955873:tid 956057] [client 34.35.44.204:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9hgAAAUA"]
[Thu Sep 17 15:06:34.022676 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9igAAAXk"]
[Thu Sep 17 15:06:34.022801 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9igAAAXk"]
[Thu Sep 17 15:06:34.276533 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:36320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9lAAAASI"]
[Thu Sep 17 15:06:34.317109 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:33108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9mQAAAXI"]
[Thu Sep 17 15:06:34.317265 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:33108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9mQAAAXI"]
[Thu Sep 17 15:06:34.317749 2026] [security2:error] [pid 955873:tid 956025] [client 34.178.167.214:47736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9mgAAASA"]
[Thu Sep 17 15:06:34.366911 2026] [security2:error] [pid 955873:tid 955906] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/admin-app/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9nwABOCA"]
[Thu Sep 17 15:06:34.367141 2026] [security2:error] [pid 955873:tid 955877] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/old/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9nAABOAM"]
[Thu Sep 17 15:06:34.367160 2026] [security2:error] [pid 955873:tid 955895] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/test/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9ngABOBU"]
[Thu Sep 17 15:06:34.367290 2026] [security2:error] [pid 955873:tid 955899] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/new/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9mwABOBk"]
[Thu Sep 17 15:06:34.369189 2026] [security2:error] [pid 955873:tid 955898] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/node-api/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9owABOBg"]
[Thu Sep 17 15:06:34.370579 2026] [security2:error] [pid 955873:tid 955908] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/api-backend/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9nQABOCI"]
[Thu Sep 17 15:06:34.370701 2026] [security2:error] [pid 955873:tid 955971] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/public_html/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9oAABOGE"]
[Thu Sep 17 15:06:34.370748 2026] [security2:error] [pid 955873:tid 955909] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/current/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9ogABOCM"]
[Thu Sep 17 15:06:34.419633 2026] [authz_core:error] [pid 955873:tid 956111] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:06:34.425547 2026] [security2:error] [pid 955873:tid 955904] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/administrator/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9oQABOB4"]
[Thu Sep 17 15:06:34.511201 2026] [security2:error] [pid 955873:tid 955915] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qAABdCk"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955911] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/aws/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9rQABdCU"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955914] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/stripe/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9pwABdCg"]
[Thu Sep 17 15:06:34.511204 2026] [security2:error] [pid 955873:tid 955903] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.docker/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qgABdB0"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955905] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/server/backend/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9rAABdB8"]
[Thu Sep 17 15:06:34.511200 2026] [security2:error] [pid 955873:tid 955907] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/server/api/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qwABdCE"]
[Thu Sep 17 15:06:34.511247 2026] [security2:error] [pid 955873:tid 955910] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.aws/.env"] [unique_id "aqxWWhFTPRVSLOsRVhr9qQABdCQ"]
[Thu Sep 17 15:06:34.611574 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9sgAAAW8"]
[Thu Sep 17 15:06:34.611692 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:33114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9sgAAAW8"]
[Thu Sep 17 15:06:34.688305 2026] [security2:error] [pid 955873:tid 956128] [client 115.244.164.14:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9tQAAAYc"]
[Thu Sep 17 15:06:34.688416 2026] [security2:error] [pid 955873:tid 956128] [client 115.244.164.14:65514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9tQAAAYc"]
[Thu Sep 17 15:06:34.774565 2026] [security2:error] [pid 955873:tid 956015] [client 34.154.239.243:36322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9tgAAARY"]
[Thu Sep 17 15:06:34.786543 2026] [security2:error] [pid 955873:tid 956074] [client 34.35.44.204:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9twAAAVE"]
[Thu Sep 17 15:06:34.894169 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9uQAAAWs"]
[Thu Sep 17 15:06:34.894288 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:33130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9uQAAAWs"]
[Thu Sep 17 15:06:34.945397 2026] [security2:error] [pid 955873:tid 956077] [client 34.178.167.214:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9uwAAAVQ"]
[Thu Sep 17 15:06:35.056028 2026] [security2:error] [pid 955873:tid 956087] [client 24.159.185.48:51701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9vAABXjA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&hideliu=1&hidemyself=1&target=The_Lord_Of_Dwarves&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:06:35.147587 2026] [security2:error] [pid 955873:tid 956089] [client 20.244.34.24:51400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9xwAAAWA"], referer: binance.com
[Thu Sep 17 15:06:35.178242 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9yQAAAXk"]
[Thu Sep 17 15:06:35.178391 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:33132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9yQAAAXk"]
[Thu Sep 17 15:06:35.197988 2026] [security2:error] [pid 955873:tid 955923] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/v1/.env"] [unique_id "aqxWWxFTPRVSLOsRVhr9ygABRTE"]
[Thu Sep 17 15:06:35.251176 2026] [security2:error] [pid 955873:tid 956004] [client 34.154.239.243:36330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr9zQAAAQs"]
[Thu Sep 17 15:06:35.374921 2026] [security2:error] [pid 955873:tid 955931] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/v2/.env"] [unique_id "aqxWWxFTPRVSLOsRVhr9zwABIjk"]
[Thu Sep 17 15:06:35.468343 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:33134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr90wAAASs"]
[Thu Sep 17 15:06:35.468479 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:33134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr90wAAASs"]
[Thu Sep 17 15:06:35.555979 2026] [security2:error] [pid 955873:tid 956044] [client 34.178.167.214:47746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr91wAAATM"]
[Thu Sep 17 15:06:35.566708 2026] [core:error] [pid 955873:tid 956008] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:35.566735 2026] [core:error] [pid 955873:tid 956008] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:35.610383 2026] [security2:error] [pid 955873:tid 956115] [client 34.35.44.204:45584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr93AAAAXo"]
[Thu Sep 17 15:06:35.720423 2026] [security2:error] [pid 955873:tid 956021] [client 34.154.239.243:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWWxFTPRVSLOsRVhr94AAAARw"]
[Thu Sep 17 15:06:35.775449 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:33140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr95QAAAR4"]
[Thu Sep 17 15:06:35.775559 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:33140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxWWxFTPRVSLOsRVhr95QAAAR4"]
[Thu Sep 17 15:06:35.837116 2026] [security2:error] [pid 955873:tid 956111] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWWxFTPRVSLOsRVhr94wAAAXY"], referer: http://alrayancont.com/WebInterface/
[Thu Sep 17 15:06:36.056621 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr96QAAARY"]
[Thu Sep 17 15:06:36.056773 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr96QAAARY"]
[Thu Sep 17 15:06:36.190648 2026] [security2:error] [pid 955873:tid 956082] [client 34.154.239.243:36354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWXBFTPRVSLOsRVhr97gAAAVk"]
[Thu Sep 17 15:06:36.201705 2026] [security2:error] [pid 955873:tid 955929] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/v3/.env"] [unique_id "aqxWXBFTPRVSLOsRVhr97wABVDc"]
[Thu Sep 17 15:06:36.281194 2026] [security2:error] [pid 955873:tid 956046] [client 34.178.167.214:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWXBFTPRVSLOsRVhr98gAAATU"]
[Thu Sep 17 15:06:36.296062 2026] [security2:error] [pid 955873:tid 956128] [client 186.105.232.15:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr98wAAAYc"]
[Thu Sep 17 15:06:36.296205 2026] [security2:error] [pid 955873:tid 956128] [client 186.105.232.15:51552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr98wAAAYc"]
[Thu Sep 17 15:06:36.350031 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99QAAATo"]
[Thu Sep 17 15:06:36.350205 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:33164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99QAAATo"]
[Thu Sep 17 15:06:36.353128 2026] [security2:error] [pid 955873:tid 955930] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/media/.env"] [unique_id "aqxWXBFTPRVSLOsRVhr99gABezg"]
[Thu Sep 17 15:06:36.381617 2026] [security2:error] [pid 955873:tid 956085] [client 104.28.198.244:22531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99wAAAVw"]
[Thu Sep 17 15:06:36.382107 2026] [security2:error] [pid 955873:tid 956085] [client 104.28.198.244:22531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr99wAAAVw"]
[Thu Sep 17 15:06:36.414405 2026] [autoindex:error] [pid 955873:tid 956121] [client 172.239.147.162:57389] AH01276: Cannot serve directory /home3/dieselr1/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:06:36.448413 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:45590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWXBFTPRVSLOsRVhr9-gAAAWs"]
[Thu Sep 17 15:06:36.635081 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:33180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr9_wAAAUs"]
[Thu Sep 17 15:06:36.635191 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:33180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr9_wAAAUs"]
[Thu Sep 17 15:06:36.674704 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWXBFTPRVSLOsRVhr-AAAAAXk"]
[Thu Sep 17 15:06:36.926111 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:33196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BAAAATw"]
[Thu Sep 17 15:06:36.926260 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:33196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BAAAATw"]
[Thu Sep 17 15:06:36.970318 2026] [security2:error] [pid 955873:tid 956062] [client 154.190.208.131:41578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BQAAAUU"]
[Thu Sep 17 15:06:36.974803 2026] [security2:error] [pid 955873:tid 956062] [client 154.190.208.131:41578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWXBFTPRVSLOsRVhr-BQAAAUU"]
[Thu Sep 17 15:06:37.047648 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWXRFTPRVSLOsRVhr-BwAAAWg"]
[Thu Sep 17 15:06:37.197215 2026] [security2:error] [pid 955873:tid 956080] [client 34.154.239.243:36368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWXRFTPRVSLOsRVhr-CgAAAVc"]
[Thu Sep 17 15:06:37.218444 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:33200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxWXRFTPRVSLOsRVhr-DAAAAWo"]
[Thu Sep 17 15:06:37.281822 2026] [security2:error] [pid 955873:tid 956025] [client 34.35.44.204:45600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWXRFTPRVSLOsRVhr-EgAAASA"]
[Thu Sep 17 15:06:37.370686 2026] [security2:error] [pid 955873:tid 956059] [client 52.167.144.221:44734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxWWxFTPRVSLOsRVhr93QABQic"]
[Thu Sep 17 15:06:37.658204 2026] [authz_core:error] [pid 955873:tid 956023] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/fields/error_log
[Thu Sep 17 15:06:37.659518 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxWXRFTPRVSLOsRVhr-GgAAAR4"]
[Thu Sep 17 15:06:37.674091 2026] [security2:error] [pid 955873:tid 956109] [client 34.154.239.243:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWXRFTPRVSLOsRVhr-IgAAAXQ"]
[Thu Sep 17 15:06:37.803170 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/wp-includes/rest-api/"] [unique_id "aqxWXRFTPRVSLOsRVhr-JQAAARY"]
[Thu Sep 17 15:06:37.813262 2026] [authz_core:error] [pid 955873:tid 956104] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:06:38.019413 2026] [security2:error] [pid 955873:tid 956070] [client 34.178.167.214:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWXhFTPRVSLOsRVhr-LAAAAU0"]
[Thu Sep 17 15:06:38.101069 2026] [security2:error] [pid 955873:tid 956093] [client 34.35.44.204:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-MAAAAWQ"]
[Thu Sep 17 15:06:38.126970 2026] [security2:error] [pid 955873:tid 956073] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-LgAAAVA"], referer: http://alrayancont.com/identity
[Thu Sep 17 15:06:38.152108 2026] [security2:error] [pid 955873:tid 956014] [client 34.154.239.243:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWXhFTPRVSLOsRVhr-MgAAARU"]
[Thu Sep 17 15:06:38.174503 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWXRFTPRVSLOsRVhr-KAAAASw"]
[Thu Sep 17 15:06:38.174526 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWXRFTPRVSLOsRVhr-KAAAASw"]
[Thu Sep 17 15:06:38.426183 2026] [security2:error] [pid 955873:tid 956061] [client 127.0.0.1:14324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxWXhFTPRVSLOsRVhr-OgAAAUQ"]
[Thu Sep 17 15:06:38.426387 2026] [security2:error] [pid 955873:tid 956033] [client 74.7.175.134:36944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.findproductivity.com"] [uri "/robots.txt"] [unique_id "aqxWXhFTPRVSLOsRVhr-OQABKEY"]
[Thu Sep 17 15:06:38.449091 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-PAAAAWI"]
[Thu Sep 17 15:06:38.449231 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:33200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-PAAAAWI"]
[Thu Sep 17 15:06:38.616378 2026] [security2:error] [pid 955873:tid 956005] [client 34.154.239.243:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWXhFTPRVSLOsRVhr-QQAAAQw"]
[Thu Sep 17 15:06:38.725098 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-RgAAAWg"]
[Thu Sep 17 15:06:38.725197 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-RgAAAWg"]
[Thu Sep 17 15:06:38.912573 2026] [security2:error] [pid 955873:tid 956003] [client 34.35.44.204:45606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWXhFTPRVSLOsRVhr-SQAAAQo"]
[Thu Sep 17 15:06:39.003261 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-SwAAASA"]
[Thu Sep 17 15:06:39.003372 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:33212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-SwAAASA"]
[Thu Sep 17 15:06:39.088435 2026] [security2:error] [pid 955873:tid 956099] [client 34.154.239.243:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-TgAAAWo"]
[Thu Sep 17 15:06:39.097670 2026] [security2:error] [pid 955873:tid 956129] [client 34.178.167.214:47776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWXxFTPRVSLOsRVhr-UAAAAYg"]
[Thu Sep 17 15:06:39.291967 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:33218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-VQAAARQ"]
[Thu Sep 17 15:06:39.292083 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:33218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-VQAAARQ"]
[Thu Sep 17 15:06:39.387285 2026] [security2:error] [pid 955873:tid 956096] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrayancont.com"] [uri "/index.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-VgAAAWc"], referer: http://alrayancont.com/cgi-bin/authLogin.cgi
[Thu Sep 17 15:06:39.480203 2026] [security2:error] [pid 955873:tid 956012] [client 142.93.254.125:57696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9dwAAARM"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480203 2026] [security2:error] [pid 955873:tid 956108] [client 192.241.158.95:54234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ggAAAXM"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480574 2026] [security2:error] [pid 955873:tid 956088] [client 157.245.81.142:38880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWhFTPRVSLOsRVhr9iQAAAV8"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480725 2026] [security2:error] [pid 955873:tid 956069] [client 157.245.81.142:38864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9eAAAAUw"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480729 2026] [security2:error] [pid 955873:tid 956067] [client 142.93.123.56:58848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9fAAAAUo"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.480872 2026] [security2:error] [pid 955873:tid 956007] [client 147.182.134.140:52514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9ewAAAQ4"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.561205 2026] [security2:error] [pid 955873:tid 956063] [client 34.154.239.243:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-XwAAAUY"]
[Thu Sep 17 15:06:39.577319 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-YAAAAWE"]
[Thu Sep 17 15:06:39.577474 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:33228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-YAAAAWE"]
[Thu Sep 17 15:06:39.594914 2026] [security2:error] [pid 955873:tid 956123] [client 198.211.116.252:34128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9cwAAAYI"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.598768 2026] [security2:error] [pid 955873:tid 956050] [client 157.230.48.236:40228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9hwAAATk"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.600702 2026] [security2:error] [pid 955873:tid 956065] [client 137.184.142.69:51932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9cQAAAUg"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:39.725359 2026] [security2:error] [pid 955873:tid 956109] [client 34.35.44.204:43678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWXxFTPRVSLOsRVhr-ZQAAAXQ"]
[Thu Sep 17 15:06:39.790627 2026] [security2:error] [pid 955873:tid 956046] [client 74.7.230.46:38870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.kolind.com"] [uri "/robots.txt"] [unique_id "aqxWXxFTPRVSLOsRVhr-ZgABNUU"]
[Thu Sep 17 15:06:39.849068 2026] [security2:error] [pid 955873:tid 956008] [client 34.178.167.214:47782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWXxFTPRVSLOsRVhr-aAAAAQ8"]
[Thu Sep 17 15:06:39.879440 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:48618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxWXxFTPRVSLOsRVhr-agAAARU"]
[Thu Sep 17 15:06:40.032473 2026] [authz_core:error] [pid 955873:tid 956064] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/search/error_log
[Thu Sep 17 15:06:40.033495 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxWYBFTPRVSLOsRVhr-bgAAAUc"]
[Thu Sep 17 15:06:40.041922 2026] [security2:error] [pid 955873:tid 956037] [client 34.154.239.243:55510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-bwAAASw"]
[Thu Sep 17 15:06:40.179546 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:48618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/wp-includes/rest-api/"] [unique_id "aqxWYBFTPRVSLOsRVhr-cgAAAQs"]
[Thu Sep 17 15:06:40.274628 2026] [security2:error] [pid 955873:tid 956086] [client 178.128.145.39:41482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWWRFTPRVSLOsRVhr9hQAAAV0"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:40.541476 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-eAAAAUU"]
[Thu Sep 17 15:06:40.541499 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-eAAAAUU"]
[Thu Sep 17 15:06:40.545514 2026] [security2:error] [pid 955873:tid 956097] [client 34.178.167.214:47786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-gAAAAWg"]
[Thu Sep 17 15:06:40.550174 2026] [security2:error] [pid 955873:tid 956027] [client 34.154.239.243:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-gQAAASI"]
[Thu Sep 17 15:06:40.680918 2026] [security2:error] [pid 955873:tid 956117] [client 185.55.149.49:53914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-hwAAAXw"]
[Thu Sep 17 15:06:40.681037 2026] [security2:error] [pid 955873:tid 956117] [client 185.55.149.49:53914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-hwAAAXw"]
[Thu Sep 17 15:06:40.681804 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:48618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-iAAAAXw"]
[Thu Sep 17 15:06:40.681875 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:48618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-iAAAAXw"]
[Thu Sep 17 15:06:40.714032 2026] [security2:error] [pid 955873:tid 956112] [client 4.240.114.86:64631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-igAAAXc"], referer: binance.com
[Thu Sep 17 15:06:40.814224 2026] [security2:error] [pid 955873:tid 956023] [client 34.35.44.204:43686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-jwAAAR4"]
[Thu Sep 17 15:06:40.873317 2026] [security2:error] [pid 955873:tid 956124] [client 45.156.129.164:58684] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "aqxWYBFTPRVSLOsRVhr-kwAAAYM"]
[Thu Sep 17 15:06:40.974571 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-lgAAAVg"]
[Thu Sep 17 15:06:40.974695 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:48628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxWYBFTPRVSLOsRVhr-lgAAAVg"]
[Thu Sep 17 15:06:41.035399 2026] [security2:error] [pid 955873:tid 956022] [client 34.154.239.243:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-mQAAAR0"]
[Thu Sep 17 15:06:41.053279 2026] [security2:error] [pid 955873:tid 955959] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.git/config.bak"] [unique_id "aqxWYRFTPRVSLOsRVhr-oAABVlU"]
[Thu Sep 17 15:06:41.166494 2026] [security2:error] [pid 955873:tid 956110] [client 34.178.167.214:47790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-pAAAAXU"]
[Thu Sep 17 15:06:41.245129 2026] [security2:error] [pid 955873:tid 955957] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.aws/credentials.bak"] [unique_id "aqxWYRFTPRVSLOsRVhr-qQABOlM"]
[Thu Sep 17 15:06:41.262745 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:48638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-rwAAAWQ"]
[Thu Sep 17 15:06:41.262858 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:48638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-rwAAAWQ"]
[Thu Sep 17 15:06:41.447865 2026] [security2:error] [pid 955873:tid 955979] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/.ssh/id_rsa"] [unique_id "aqxWYRFTPRVSLOsRVhr-uAABT2k"]
[Thu Sep 17 15:06:41.447871 2026] [security2:error] [pid 955873:tid 955970] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/id_rsa"] [unique_id "aqxWYRFTPRVSLOsRVhr-uwABT2A"]
[Thu Sep 17 15:06:41.507574 2026] [security2:error] [pid 955873:tid 956077] [client 34.154.239.243:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-vgAAAVQ"]
[Thu Sep 17 15:06:41.563189 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:48644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-wQAAAWI"]
[Thu Sep 17 15:06:41.563302 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:48644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-wQAAAWI"]
[Thu Sep 17 15:06:41.587239 2026] [security2:error] [pid 955873:tid 956005] [client 216.73.160.161:29555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gothataway.ca"] [uri "/wp-login.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-vQAAAQw"]
[Thu Sep 17 15:06:41.647367 2026] [security2:error] [pid 955873:tid 956119] [client 216.73.160.163:40471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gothataway.ca"] [uri "/wp-login.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-wgAAAX4"]
[Thu Sep 17 15:06:41.648140 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:43690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-yAAAARU"]
[Thu Sep 17 15:06:41.849276 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:48658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-0QAAAV0"]
[Thu Sep 17 15:06:41.849364 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:48658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-0QAAAV0"]
[Thu Sep 17 15:06:41.961386 2026] [security2:error] [pid 955873:tid 956004] [client 34.178.167.214:47802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-1wAAAQs"]
[Thu Sep 17 15:06:41.977769 2026] [security2:error] [pid 955873:tid 956114] [client 34.154.239.243:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWYRFTPRVSLOsRVhr-2AAAAXk"]
[Thu Sep 17 15:06:42.012991 2026] [security2:error] [pid 955873:tid 956056] [client 3.82.141.143:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "aqxWYhFTPRVSLOsRVhr-3AAAAT8"]
[Thu Sep 17 15:06:42.029059 2026] [security2:error] [pid 955873:tid 956084] [client 3.82.141.143:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "aqxWYhFTPRVSLOsRVhr-7gAAAVs"]
[Thu Sep 17 15:06:42.032836 2026] [security2:error] [pid 955873:tid 956126] [client 3.82.141.143:19276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "aqxWYhFTPRVSLOsRVhr-8wAAAYU"]
[Thu Sep 17 15:06:42.033739 2026] [security2:error] [pid 955873:tid 956030] [client 3.82.141.143:19610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php.old"] [unique_id "aqxWYhFTPRVSLOsRVhr-_QAAASU"]
[Thu Sep 17 15:06:42.034464 2026] [security2:error] [pid 955873:tid 956010] [client 3.82.141.143:19482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/web.config"] [unique_id "aqxWYhFTPRVSLOsRVhr--QAAARE"]
[Thu Sep 17 15:06:42.035033 2026] [security2:error] [pid 955873:tid 956094] [client 3.82.141.143:19662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php~"] [unique_id "aqxWYhFTPRVSLOsRVhr_AAAAAWU"]
[Thu Sep 17 15:06:42.040670 2026] [security2:error] [pid 955873:tid 956096] [client 3.82.141.143:19632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php.save"] [unique_id "aqxWYhFTPRVSLOsRVhr_DwAAAWc"]
[Thu Sep 17 15:06:42.040929 2026] [security2:error] [pid 955873:tid 956112] [client 3.82.141.143:19612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_DgAAAXc"]
[Thu Sep 17 15:06:42.044638 2026] [security2:error] [pid 955873:tid 956088] [client 3.82.141.143:19306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rpimanufacturing.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "aqxWYhFTPRVSLOsRVhr_EgAAAV8"]
[Thu Sep 17 15:06:42.045676 2026] [security2:error] [pid 955873:tid 956067] [client 3.82.141.143:19472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rpimanufacturing.com"] [uri "/config.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_FQAAAUo"]
[Thu Sep 17 15:06:42.050261 2026] [security2:error] [pid 955873:tid 956018] [client 3.82.141.143:19622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.rpimanufacturing.com"] [uri "/wp-config.php.bak"] [unique_id "aqxWYhFTPRVSLOsRVhr_FgAAARk"]
[Thu Sep 17 15:06:42.056580 2026] [core:error] [pid 955873:tid 956065] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.056592 2026] [core:error] [pid 955873:tid 956065] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.125233 2026] [core:error] [pid 955873:tid 956128] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.125251 2026] [core:error] [pid 955873:tid 956128] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.129979 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxWYhFTPRVSLOsRVhr_IAAAAQ8"]
[Thu Sep 17 15:06:42.173997 2026] [core:error] [pid 955873:tid 956019] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.174016 2026] [core:error] [pid 955873:tid 956019] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.176121 2026] [core:error] [pid 955873:tid 956077] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.176137 2026] [core:error] [pid 955873:tid 956077] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.178625 2026] [core:error] [pid 955873:tid 956127] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.178649 2026] [core:error] [pid 955873:tid 956127] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.180092 2026] [core:error] [pid 955873:tid 956075] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.180105 2026] [core:error] [pid 955873:tid 956075] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.182031 2026] [core:error] [pid 955873:tid 956037] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.182049 2026] [core:error] [pid 955873:tid 956037] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185425 2026] [core:error] [pid 955873:tid 956119] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185440 2026] [core:error] [pid 955873:tid 956119] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185782 2026] [core:error] [pid 955873:tid 956005] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.185794 2026] [core:error] [pid 955873:tid 956005] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.188219 2026] [core:error] [pid 955873:tid 956033] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.188232 2026] [core:error] [pid 955873:tid 956033] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.192972 2026] [core:error] [pid 955873:tid 956014] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.192985 2026] [core:error] [pid 955873:tid 956014] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.193088 2026] [core:error] [pid 955873:tid 956043] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.193104 2026] [core:error] [pid 955873:tid 956043] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.195790 2026] [core:error] [pid 955873:tid 956026] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.195802 2026] [core:error] [pid 955873:tid 956026] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196228 2026] [core:error] [pid 955873:tid 956086] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196236 2026] [core:error] [pid 955873:tid 956086] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196441 2026] [core:error] [pid 955873:tid 956098] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.196450 2026] [core:error] [pid 955873:tid 956098] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198074 2026] [core:error] [pid 955873:tid 956057] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198090 2026] [core:error] [pid 955873:tid 956057] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198466 2026] [core:error] [pid 955873:tid 956074] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198474 2026] [core:error] [pid 955873:tid 956074] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198578 2026] [core:error] [pid 955873:tid 956122] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.198587 2026] [core:error] [pid 955873:tid 956122] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227875 2026] [core:error] [pid 955873:tid 956030] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227895 2026] [core:error] [pid 955873:tid 956030] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227962 2026] [core:error] [pid 955873:tid 956069] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227970 2026] [core:error] [pid 955873:tid 956069] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.227995 2026] [core:error] [pid 955873:tid 956056] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.228003 2026] [core:error] [pid 955873:tid 956056] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.228051 2026] [core:error] [pid 955873:tid 956099] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.228059 2026] [core:error] [pid 955873:tid 956099] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:06:42.259999 2026] [security2:error] [pid 955873:tid 956128] [client 45.156.129.164:58694] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "aqxWYhFTPRVSLOsRVhr_OQAAAYc"]
[Thu Sep 17 15:06:42.292115 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxWYhFTPRVSLOsRVhr_PAAAAUc"]
[Thu Sep 17 15:06:42.432209 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/wp-includes/"] [unique_id "aqxWYhFTPRVSLOsRVhr_RgAAASE"]
[Thu Sep 17 15:06:42.465423 2026] [security2:error] [pid 955873:tid 956017] [client 34.154.239.243:55564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_RwAAARg"]
[Thu Sep 17 15:06:42.481813 2026] [security2:error] [pid 955873:tid 956094] [client 34.35.44.204:43692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_SAAAAWU"]
[Thu Sep 17 15:06:42.604975 2026] [security2:error] [pid 955873:tid 956013] [client 20.244.34.24:55373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_TgAAARQ"], referer: binance.com
[Thu Sep 17 15:06:42.777190 2026] [security2:error] [pid 955873:tid 956122] [client 34.178.167.214:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_UwAAAYE"]
[Thu Sep 17 15:06:42.781199 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_TQAAAX8"]
[Thu Sep 17 15:06:42.781221 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_TQAAAX8"]
[Thu Sep 17 15:06:42.917722 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_WwAAAS8"]
[Thu Sep 17 15:06:42.917823 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-index.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_WwAAAS8"]
[Thu Sep 17 15:06:42.948223 2026] [security2:error] [pid 955873:tid 956025] [client 34.154.239.243:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWYhFTPRVSLOsRVhr_XQAAASA"]
[Thu Sep 17 15:06:43.196416 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:48678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-provider.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_ZQAAARY"]
[Thu Sep 17 15:06:43.196512 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:48678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-provider.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_ZQAAARY"]
[Thu Sep 17 15:06:43.205778 2026] [security2:error] [pid 955873:tid 956051] [client 45.156.129.164:58700] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "aqxWYxFTPRVSLOsRVhr_ZgAAATo"]
[Thu Sep 17 15:06:43.212112 2026] [security2:error] [pid 955873:tid 955887] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_aAABcA0"]
[Thu Sep 17 15:06:43.310241 2026] [security2:error] [pid 955873:tid 956110] [client 34.35.44.204:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_bQAAAXU"]
[Thu Sep 17 15:06:43.428900 2026] [security2:error] [pid 955873:tid 956093] [client 34.154.239.243:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cAAAAWQ"]
[Thu Sep 17 15:06:43.446476 2026] [security2:error] [pid 955873:tid 956059] [client 34.178.167.214:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cQAAAUI"]
[Thu Sep 17 15:06:43.481066 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-registry.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cgAAAWs"]
[Thu Sep 17 15:06:43.481170 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:48690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-registry.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_cgAAAWs"]
[Thu Sep 17 15:06:43.516399 2026] [security2:error] [pid 955873:tid 956085] [client 196.117.51.2:51262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_bwABXBI"]
[Thu Sep 17 15:06:43.704305 2026] [security2:error] [pid 955873:tid 955902] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/aws.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_gAABRRw"]
[Thu Sep 17 15:06:43.770080 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:48698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-renderer.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_hQAAAR0"]
[Thu Sep 17 15:06:43.770217 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:48698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-renderer.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_hQAAAR0"]
[Thu Sep 17 15:06:43.849616 2026] [security2:error] [pid 955873:tid 955895] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/stripe.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_iQABKBU"]
[Thu Sep 17 15:06:43.851306 2026] [security2:error] [pid 955873:tid 955899] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/mail.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_iwABKBk"]
[Thu Sep 17 15:06:43.851348 2026] [security2:error] [pid 955873:tid 955906] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/config.inc.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_jQABKCA"]
[Thu Sep 17 15:06:43.851450 2026] [security2:error] [pid 955873:tid 955908] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/config/nexmo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_jgABKCI"]
[Thu Sep 17 15:06:43.872231 2026] [security2:error] [pid 955873:tid 956116] [client 165.227.81.25:49414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_eQAAAXs"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:43.897667 2026] [security2:error] [pid 955873:tid 956124] [client 68.183.24.99:39320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_egAAAYM"], referer: http://golovefoundation.org/
[Thu Sep 17 15:06:43.921531 2026] [security2:error] [pid 955873:tid 956075] [client 34.154.239.243:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_kgAAAVI"]
[Thu Sep 17 15:06:43.982323 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:56065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_kwAAAQw"]
[Thu Sep 17 15:06:43.982435 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:56065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWYxFTPRVSLOsRVhr_kwAAAQw"]
[Thu Sep 17 15:06:44.061612 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:48714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-stylesheet.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mQAAAVs"]
[Thu Sep 17 15:06:44.061773 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:48714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps-stylesheet.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mQAAAVs"]
[Thu Sep 17 15:06:44.135271 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:43722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mgAAAWw"]
[Thu Sep 17 15:06:44.189429 2026] [security2:error] [pid 955873:tid 955900] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php.bak"] [unique_id "aqxWZBFTPRVSLOsRVhr_nAABeBo"]
[Thu Sep 17 15:06:44.189429 2026] [security2:error] [pid 955873:tid 955907] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php.new"] [unique_id "aqxWZBFTPRVSLOsRVhr_ngABeCE"]
[Thu Sep 17 15:06:44.189430 2026] [security2:error] [pid 955873:tid 955905] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php.old"] [unique_id "aqxWZBFTPRVSLOsRVhr_nQABeB8"]
[Thu Sep 17 15:06:44.189928 2026] [security2:error] [pid 955873:tid 955915] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/.wp-config.php.swp"] [unique_id "aqxWZBFTPRVSLOsRVhr_nwABeCk"]
[Thu Sep 17 15:06:44.189944 2026] [security2:error] [pid 955873:tid 955904] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-config.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_mwABeB4"]
[Thu Sep 17 15:06:44.214656 2026] [security2:error] [pid 955873:tid 956086] [client 45.156.129.167:25378] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxWZBFTPRVSLOsRVhr_oAAAAV0"]
[Thu Sep 17 15:06:44.327712 2026] [security2:error] [pid 955873:tid 955903] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/wp-content/mysql.sql"] [unique_id "aqxWZBFTPRVSLOsRVhr_pwABZx0"]
[Thu Sep 17 15:06:44.336968 2026] [security2:error] [pid 955873:tid 956031] [client 34.178.167.214:58268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_qQAAASY"]
[Thu Sep 17 15:06:44.344027 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:48722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_rAAAARQ"]
[Thu Sep 17 15:06:44.344092 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:48722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/class-wp-sitemaps.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_rAAAARQ"]
[Thu Sep 17 15:06:44.389409 2026] [security2:error] [pid 955873:tid 956057] [client 34.154.239.243:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_rwAAAUA"]
[Thu Sep 17 15:06:44.400498 2026] [security2:error] [pid 955873:tid 956106] [client 127.0.0.1:25386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxWZBFTPRVSLOsRVhr_rgAAAXE"]
[Thu Sep 17 15:06:44.400675 2026] [security2:error] [pid 955873:tid 956112] [client 74.7.175.164:52996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.ybo.gqk.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWZBFTPRVSLOsRVhr_rQABdys"]
[Thu Sep 17 15:06:44.669972 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:48732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxWZBFTPRVSLOsRVhr_tQAAAQ4"]
[Thu Sep 17 15:06:44.704232 2026] [security2:error] [pid 955873:tid 955927] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/terraform.tfstate.backup"] [unique_id "aqxWZBFTPRVSLOsRVhr_vQABKzU"]
[Thu Sep 17 15:06:44.781957 2026] [security2:error] [pid 955873:tid 956097] [client 37.139.53.124:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "golovefoundation.org"] [uri "/wp-login.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_uAAAAWg"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:06:44.833970 2026] [authz_core:error] [pid 955873:tid 956056] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sitemaps/providers/error_log
[Thu Sep 17 15:06:44.834814 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxWZBFTPRVSLOsRVhr_xQAAAT8"]
[Thu Sep 17 15:06:44.853310 2026] [security2:error] [pid 955873:tid 956044] [client 34.154.239.243:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_zAAAATM"]
[Thu Sep 17 15:06:44.887922 2026] [security2:error] [pid 955873:tid 956046] [client 4.240.114.86:50431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_zQAAATU"], referer: binance.com
[Thu Sep 17 15:06:44.932048 2026] [security2:error] [pid 955873:tid 956038] [client 34.178.167.214:58284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_zgAAAS0"]
[Thu Sep 17 15:06:44.957748 2026] [security2:error] [pid 955873:tid 956040] [client 34.35.44.204:43726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_0AAAAS8"]
[Thu Sep 17 15:06:44.980628 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:48732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/wp-includes/sitemaps/"] [unique_id "aqxWZBFTPRVSLOsRVhr_0gAAATQ"]
[Thu Sep 17 15:06:45.043808 2026] [security2:error] [pid 955873:tid 956049] [client 66.132.186.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "162.241.8.124"] [uri "/index.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_xwAAATg"]
[Thu Sep 17 15:06:45.264690 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:49780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_3wAAAXU"]
[Thu Sep 17 15:06:45.264834 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:49780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_3wAAAXU"]
[Thu Sep 17 15:06:45.317337 2026] [security2:error] [pid 955873:tid 956020] [client 34.154.239.243:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.waa.nmb.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_4gAAARs"]
[Thu Sep 17 15:06:45.394981 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_1QAAAWQ"]
[Thu Sep 17 15:06:45.395005 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_1QAAAWQ"]
[Thu Sep 17 15:06:45.410634 2026] [security2:error] [pid 955873:tid 956087] [client 154.190.208.131:42096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_5gAAAV4"]
[Thu Sep 17 15:06:45.415163 2026] [security2:error] [pid 955873:tid 956087] [client 154.190.208.131:42096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_5gAAAV4"]
[Thu Sep 17 15:06:45.541125 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_7gAAAT4"]
[Thu Sep 17 15:06:45.541234 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:48732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_7gAAAT4"]
[Thu Sep 17 15:06:45.726497 2026] [security2:error] [pid 955873:tid 956127] [client 34.178.167.214:58286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWZRFTPRVSLOsRVhr_9AAAAYY"]
[Thu Sep 17 15:06:45.817113 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:48736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxWZRFTPRVSLOsRVhr__gAAAXI"]
[Thu Sep 17 15:06:45.817209 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:48736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxWZRFTPRVSLOsRVhr__gAAAXI"]
[Thu Sep 17 15:06:45.991672 2026] [security2:error] [pid 955873:tid 956117] [client 74.7.244.38:35176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bnb.sib.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWZRFTPRVSLOsRVhoABgABfEM"]
[Thu Sep 17 15:06:46.050263 2026] [security2:error] [pid 955873:tid 956069] [client 40.77.167.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ritamayblog.com"] [uri "/index.php"] [unique_id "aqxWZBFTPRVSLOsRVhr_xAAAAUw"]
[Thu Sep 17 15:06:46.107439 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxWZhFTPRVSLOsRVhoADQAAAUo"]
[Thu Sep 17 15:06:46.107529 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:48750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxWZhFTPRVSLOsRVhoADQAAAUo"]
[Thu Sep 17 15:06:46.359509 2026] [security2:error] [pid 955873:tid 956103] [client 34.35.44.204:43736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWZhFTPRVSLOsRVhoAFwAAAW4"]
[Thu Sep 17 15:06:46.402344 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxWZhFTPRVSLOsRVhoAJgAAARA"]
[Thu Sep 17 15:06:46.420285 2026] [security2:error] [pid 955873:tid 956045] [client 34.178.167.214:58288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAJwAAATQ"]
[Thu Sep 17 15:06:46.572872 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxWZhFTPRVSLOsRVhoAMQAAAWM"]
[Thu Sep 17 15:06:46.598989 2026] [security2:error] [pid 955873:tid 956119] [client 45.156.129.167:15738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "aqxWZhFTPRVSLOsRVhoAPwAAAX4"]
[Thu Sep 17 15:06:46.737181 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/wp-includes/"] [unique_id "aqxWZhFTPRVSLOsRVhoASgAAASk"]
[Thu Sep 17 15:06:46.776540 2026] [security2:error] [pid 955873:tid 956073] [client 74.7.241.136:56614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.hdu.jxc.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxWZhFTPRVSLOsRVhoATAAAAVA"]
[Thu Sep 17 15:06:47.066853 2026] [security2:error] [pid 955873:tid 956010] [client 41.56.188.14:29052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAUQABEVw"]
[Thu Sep 17 15:06:47.101609 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAUAAAAVs"]
[Thu Sep 17 15:06:47.101645 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWZhFTPRVSLOsRVhoAUAAAAVs"]
[Thu Sep 17 15:06:47.185656 2026] [security2:error] [pid 955873:tid 956101] [client 34.35.44.204:43738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAVwAAAWw"]
[Thu Sep 17 15:06:47.247819 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxWZxFTPRVSLOsRVhoAXAAAAVY"]
[Thu Sep 17 15:06:47.253311 2026] [security2:error] [pid 955873:tid 956055] [client 104.28.198.244:22780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAXQAAAT4"]
[Thu Sep 17 15:06:47.253459 2026] [security2:error] [pid 955873:tid 956055] [client 104.28.198.244:22780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAXQAAAT4"]
[Thu Sep 17 15:06:47.304515 2026] [security2:error] [pid 955873:tid 955983] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAawABVW0"]
[Thu Sep 17 15:06:47.304548 2026] [security2:error] [pid 955873:tid 955986] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/info.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAbQABVXA"]
[Thu Sep 17 15:06:47.350826 2026] [security2:error] [pid 955873:tid 956017] [client 34.178.167.214:58302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAbgAAARg"]
[Thu Sep 17 15:06:47.375309 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:52157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAcAAAAWU"]
[Thu Sep 17 15:06:47.385625 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:52157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAcAAAAWU"]
[Thu Sep 17 15:06:47.388805 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxWZxFTPRVSLOsRVhoAcQAAAW0"]
[Thu Sep 17 15:06:47.468736 2026] [security2:error] [pid 955873:tid 955992] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAegABM3Y"]
[Thu Sep 17 15:06:47.468750 2026] [security2:error] [pid 955873:tid 955998] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/infophp.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAdQABM3w"]
[Thu Sep 17 15:06:47.468786 2026] [security2:error] [pid 955873:tid 955994] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/php.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAeQABM3g"]
[Thu Sep 17 15:06:47.468807 2026] [security2:error] [pid 955873:tid 955996] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/api/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAfAABM3o"]
[Thu Sep 17 15:06:47.468839 2026] [security2:error] [pid 955873:tid 956001] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/public/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAfQABM38"]
[Thu Sep 17 15:06:47.468859 2026] [security2:error] [pid 955873:tid 955990] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/infos.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAdAABM3Q"]
[Thu Sep 17 15:06:47.468896 2026] [security2:error] [pid 955873:tid 955980] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/php-info.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAeAABM2o"]
[Thu Sep 17 15:06:47.468941 2026] [security2:error] [pid 955873:tid 955982] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/php_info.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAcwABM2w"]
[Thu Sep 17 15:06:47.468964 2026] [security2:error] [pid 955873:tid 955969] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/admin_phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAewABM18"]
[Thu Sep 17 15:06:47.468967 2026] [security2:error] [pid 955873:tid 955984] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.229.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cyberpunkonline.net"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAdwABM24"]
[Thu Sep 17 15:06:47.535226 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAggAAAS8"]
[Thu Sep 17 15:06:47.535317 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:48766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAggAAAS8"]
[Thu Sep 17 15:06:47.622913 2026] [security2:error] [pid 955873:tid 956025] [client 45.156.129.166:41386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "aqxWZxFTPRVSLOsRVhoAhAAAASA"]
[Thu Sep 17 15:06:47.817060 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAjQAAAUs"]
[Thu Sep 17 15:06:47.817186 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:48770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAjQAAAUs"]
[Thu Sep 17 15:06:48.018149 2026] [security2:error] [pid 955873:tid 956046] [client 34.35.44.204:43748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAlAAAATU"]
[Thu Sep 17 15:06:48.122079 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:48784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxWaBFTPRVSLOsRVhoAlgAAAXM"]
[Thu Sep 17 15:06:48.214740 2026] [security2:error] [pid 955873:tid 956116] [client 34.178.167.214:58316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAoQAAAXs"]
[Thu Sep 17 15:06:48.276967 2026] [authz_core:error] [pid 955873:tid 956003] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/lib/error_log
[Thu Sep 17 15:06:48.281578 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxWaBFTPRVSLOsRVhoAowAAAQo"]
[Thu Sep 17 15:06:48.328352 2026] [security2:error] [pid 955873:tid 955883] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/database.sql"] [unique_id "aqxWaBFTPRVSLOsRVhoAqwABMgk"]
[Thu Sep 17 15:06:48.382000 2026] [security2:error] [pid 955873:tid 956124] [client 4.240.114.86:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAswAAAYM"], referer: binance.com
[Thu Sep 17 15:06:48.420073 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:48784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/wp-includes/sodium_compat/"] [unique_id "aqxWaBFTPRVSLOsRVhoAtQAAAV0"]
[Thu Sep 17 15:06:48.778020 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAvQAAASY"]
[Thu Sep 17 15:06:48.778047 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAvQAAASY"]
[Thu Sep 17 15:06:48.841561 2026] [security2:error] [pid 955873:tid 956081] [client 34.35.44.204:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAxQAAAVg"]
[Thu Sep 17 15:06:48.896062 2026] [security2:error] [pid 955873:tid 956057] [client 34.178.167.214:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAxwAAAUA"]
[Thu Sep 17 15:06:48.917588 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAyAAAAQ4"]
[Thu Sep 17 15:06:48.917756 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:48784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxWaBFTPRVSLOsRVhoAyAAAAQ4"]
[Thu Sep 17 15:06:49.099680 2026] [security2:error] [pid 955873:tid 956083] [client 45.156.129.166:41402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/groma-canary-not-a-real-plugin/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoAzQAAAVo"]
[Thu Sep 17 15:06:49.204984 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:48786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxWaRFTPRVSLOsRVhoA0AAAASc"]
[Thu Sep 17 15:06:49.205126 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:48786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxWaRFTPRVSLOsRVhoA0AAAASc"]
[Thu Sep 17 15:06:49.227297 2026] [security2:error] [pid 955873:tid 956040] [client 45.156.129.165:55552] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA0wAAAS8"]
[Thu Sep 17 15:06:49.227491 2026] [security2:error] [pid 955873:tid 956096] [client 45.156.129.164:38680] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1AAAAWc"]
[Thu Sep 17 15:06:49.227699 2026] [security2:error] [pid 955873:tid 956038] [client 45.156.129.164:38670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1QAAAS0"]
[Thu Sep 17 15:06:49.240302 2026] [security2:error] [pid 955873:tid 956103] [client 45.156.129.164:38692] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1gAAAW4"]
[Thu Sep 17 15:06:49.240947 2026] [security2:error] [pid 955873:tid 956109] [client 45.156.129.167:15740] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA1wAAAXQ"]
[Thu Sep 17 15:06:49.247270 2026] [security2:error] [pid 955873:tid 956106] [client 45.156.129.164:38704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA2QAAAXE"]
[Thu Sep 17 15:06:49.256252 2026] [security2:error] [pid 955873:tid 956009] [client 45.156.129.166:41404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA2gAAARA"]
[Thu Sep 17 15:06:49.257764 2026] [security2:error] [pid 955873:tid 956090] [client 45.156.129.165:55556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA2wAAAWE"]
[Thu Sep 17 15:06:49.263308 2026] [security2:error] [pid 955873:tid 956045] [client 45.156.129.165:55566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3AAAATQ"]
[Thu Sep 17 15:06:49.263443 2026] [security2:error] [pid 955873:tid 956025] [client 45.156.129.166:41416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3QAAASA"]
[Thu Sep 17 15:06:49.264000 2026] [security2:error] [pid 955873:tid 956016] [client 45.156.129.164:38720] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3gAAARc"]
[Thu Sep 17 15:06:49.268474 2026] [security2:error] [pid 955873:tid 956063] [client 45.156.129.166:41412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA3wAAAUY"]
[Thu Sep 17 15:06:49.271685 2026] [security2:error] [pid 955873:tid 956085] [client 45.156.129.164:38736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4AAAAVw"]
[Thu Sep 17 15:06:49.273074 2026] [security2:error] [pid 955873:tid 956118] [client 45.156.129.165:55578] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4QAAAX0"]
[Thu Sep 17 15:06:49.280187 2026] [security2:error] [pid 955873:tid 956110] [client 45.156.129.165:55580] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4gAAAXU"]
[Thu Sep 17 15:06:49.289808 2026] [security2:error] [pid 955873:tid 956068] [client 45.156.129.165:55594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA4wAAAUs"]
[Thu Sep 17 15:06:49.292286 2026] [security2:error] [pid 955873:tid 956092] [client 45.156.129.167:15748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5AAAAWM"]
[Thu Sep 17 15:06:49.299337 2026] [security2:error] [pid 955873:tid 956125] [client 45.156.129.164:38748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5QAAAYQ"]
[Thu Sep 17 15:06:49.305629 2026] [security2:error] [pid 955873:tid 956064] [client 45.156.129.167:15742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5gAAAUc"]
[Thu Sep 17 15:06:49.305807 2026] [security2:error] [pid 955873:tid 956042] [client 45.156.129.167:15762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA5wAAATE"]
[Thu Sep 17 15:06:49.306028 2026] [security2:error] [pid 955873:tid 956119] [client 45.156.129.164:38764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6AAAAX4"]
[Thu Sep 17 15:06:49.311414 2026] [security2:error] [pid 955873:tid 956074] [client 45.156.129.165:55606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6QAAAVE"]
[Thu Sep 17 15:06:49.317885 2026] [security2:error] [pid 955873:tid 956020] [client 45.156.129.167:15770] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6gAAARs"]
[Thu Sep 17 15:06:49.322806 2026] [security2:error] [pid 955873:tid 956046] [client 45.156.129.164:38772] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA6wAAATU"]
[Thu Sep 17 15:06:49.322917 2026] [security2:error] [pid 955873:tid 956015] [client 45.156.129.167:15768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7AAAARY"]
[Thu Sep 17 15:06:49.322996 2026] [security2:error] [pid 955873:tid 956108] [client 45.156.129.165:55596] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7QAAAXM"]
[Thu Sep 17 15:06:49.327546 2026] [security2:error] [pid 955873:tid 956071] [client 45.156.129.166:41436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7gAAAU4"]
[Thu Sep 17 15:06:49.333987 2026] [security2:error] [pid 955873:tid 956075] [client 45.156.129.167:15800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA7wAAAVI"]
[Thu Sep 17 15:06:49.337207 2026] [security2:error] [pid 955873:tid 956116] [client 45.156.129.166:41420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8AAAAXs"]
[Thu Sep 17 15:06:49.338809 2026] [security2:error] [pid 955873:tid 956073] [client 45.156.129.167:15816] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8QAAAVA"]
[Thu Sep 17 15:06:49.343495 2026] [security2:error] [pid 955873:tid 956126] [client 45.156.129.164:38788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8gAAAYU"]
[Thu Sep 17 15:06:49.343603 2026] [security2:error] [pid 955873:tid 956029] [client 45.156.129.165:55614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA8wAAASQ"]
[Thu Sep 17 15:06:49.345161 2026] [security2:error] [pid 955873:tid 956091] [client 45.156.129.166:41446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9AAAAWI"]
[Thu Sep 17 15:06:49.350004 2026] [security2:error] [pid 955873:tid 956043] [client 45.156.129.165:55610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9QAAATI"]
[Thu Sep 17 15:06:49.350753 2026] [security2:error] [pid 955873:tid 956123] [client 45.156.129.164:38786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9gAAAYI"]
[Thu Sep 17 15:06:49.353908 2026] [security2:error] [pid 955873:tid 956080] [client 45.156.129.167:15784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA9wAAAVc"]
[Thu Sep 17 15:06:49.356376 2026] [security2:error] [pid 955873:tid 956124] [client 45.156.129.164:38792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-AAAAYM"]
[Thu Sep 17 15:06:49.359505 2026] [security2:error] [pid 955873:tid 956086] [client 45.156.129.165:55640] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-QAAAV0"]
[Thu Sep 17 15:06:49.360346 2026] [security2:error] [pid 955873:tid 956006] [client 45.156.129.165:55632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-gAAAQ0"]
[Thu Sep 17 15:06:49.361977 2026] [security2:error] [pid 955873:tid 956028] [client 45.156.129.165:55622] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA-wAAASM"]
[Thu Sep 17 15:06:49.362796 2026] [security2:error] [pid 955873:tid 956010] [client 45.156.129.164:38814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA_AAAARE"]
[Thu Sep 17 15:06:49.371385 2026] [security2:error] [pid 955873:tid 956088] [client 45.156.129.164:38844] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA_QAAAV8"]
[Thu Sep 17 15:06:49.375932 2026] [security2:error] [pid 955873:tid 956105] [client 45.156.129.164:38800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoA_gAAAXA"]
[Thu Sep 17 15:06:49.383128 2026] [security2:error] [pid 955873:tid 956024] [client 45.156.129.164:38830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAAAAAR8"]
[Thu Sep 17 15:06:49.390566 2026] [security2:error] [pid 955873:tid 956079] [client 45.156.129.165:55642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAQAAAVY"]
[Thu Sep 17 15:06:49.395117 2026] [security2:error] [pid 955873:tid 956026] [client 45.156.129.166:41448] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAgAAASE"]
[Thu Sep 17 15:06:49.399873 2026] [security2:error] [pid 955873:tid 956062] [client 45.156.129.166:41458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBAwAAAUU"]
[Thu Sep 17 15:06:49.407902 2026] [security2:error] [pid 955873:tid 956057] [client 45.156.129.165:55648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBBAAAAUA"]
[Thu Sep 17 15:06:49.416044 2026] [security2:error] [pid 955873:tid 956054] [client 45.156.129.164:38824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBBQAAAT0"]
[Thu Sep 17 15:06:49.454286 2026] [security2:error] [pid 955873:tid 956030] [client 45.156.129.164:38856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBBwAAASU"]
[Thu Sep 17 15:06:49.494886 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:48802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBCQAAAWo"]
[Thu Sep 17 15:06:49.494982 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:48802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBCQAAAWo"]
[Thu Sep 17 15:06:49.608110 2026] [security2:error] [pid 955873:tid 956023] [client 34.178.167.214:58332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBCgAAAR4"]
[Thu Sep 17 15:06:49.616397 2026] [security2:error] [pid 955873:tid 956103] [client 45.156.129.165:55662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "aqxWaRFTPRVSLOsRVhoBCwAAAW4"]
[Thu Sep 17 15:06:49.672263 2026] [security2:error] [pid 955873:tid 956078] [client 34.35.44.204:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBDQAAAVU"]
[Thu Sep 17 15:06:49.776771 2026] [security2:error] [pid 955873:tid 956085] [client 37.139.53.124:52317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWZxFTPRVSLOsRVhoAkQAAARY"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:06:49.785827 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:48810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBEwAAATg"]
[Thu Sep 17 15:06:49.785930 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:48810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBEwAAATg"]
[Thu Sep 17 15:06:50.072091 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:38180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBGQAAAYQ"]
[Thu Sep 17 15:06:50.072214 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:38180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBGQAAAYQ"]
[Thu Sep 17 15:06:50.082072 2026] [security2:error] [pid 955873:tid 956022] [client 20.244.34.24:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxWahFTPRVSLOsRVhoBGgAAAR0"], referer: binance.com
[Thu Sep 17 15:06:50.304260 2026] [security2:error] [pid 955873:tid 956046] [client 162.241.226.11:50220] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWahFTPRVSLOsRVhoBHgAAATU"]
[Thu Sep 17 15:06:50.316354 2026] [security2:error] [pid 955873:tid 956093] [client 4.240.114.86:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxWahFTPRVSLOsRVhoBHwAAAWQ"], referer: binance.com
[Thu Sep 17 15:06:50.319473 2026] [security2:error] [pid 955873:tid 956068] [client 181.46.66.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWaRFTPRVSLOsRVhoBFQAAAUs"], referer: https://devilsarmynetwork.com
[Thu Sep 17 15:06:50.328767 2026] [security2:error] [pid 955873:tid 956075] [client 169.58.198.243:51544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/shell/about.php"] [unique_id "aqxWahFTPRVSLOsRVhoBIAAAAVI"], referer: www.google.com
[Thu Sep 17 15:06:50.358874 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:38190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxWahFTPRVSLOsRVhoBJwAAAU0"]
[Thu Sep 17 15:06:50.358994 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:38190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxWahFTPRVSLOsRVhoBJwAAAU0"]
[Thu Sep 17 15:06:50.400835 2026] [security2:error] [pid 955873:tid 956074] [client 34.178.167.214:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.167.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gsc.qjx.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWahFTPRVSLOsRVhoBKAAAAVE"]
[Thu Sep 17 15:06:50.495531 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:36432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWahFTPRVSLOsRVhoBLwAAARU"]
[Thu Sep 17 15:06:50.672234 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:38194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxWahFTPRVSLOsRVhoBOAAAAVY"]
[Thu Sep 17 15:06:50.672354 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:38194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxWahFTPRVSLOsRVhoBOAAAAVY"]
[Thu Sep 17 15:06:50.682775 2026] [security2:error] [pid 955873:tid 955888] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/localhost.sql"] [unique_id "aqxWahFTPRVSLOsRVhoBOwABIQ4"]
[Thu Sep 17 15:06:50.961219 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:38208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBRQAAAXg"]
[Thu Sep 17 15:06:50.961341 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:38208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxWahFTPRVSLOsRVhoBRQAAAXg"]
[Thu Sep 17 15:06:51.125114 2026] [security2:error] [pid 955873:tid 956027] [client 78.161.201.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWahFTPRVSLOsRVhoBQgAAASI"]
[Thu Sep 17 15:06:51.246112 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBSAAAAT8"]
[Thu Sep 17 15:06:51.246219 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:38216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBSAAAAT8"]
[Thu Sep 17 15:06:51.337364 2026] [security2:error] [pid 955873:tid 956069] [client 34.35.44.204:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWaxFTPRVSLOsRVhoBTwAAAUw"]
[Thu Sep 17 15:06:51.352074 2026] [security2:error] [pid 955873:tid 956012] [client 185.55.149.49:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBUAAAARM"]
[Thu Sep 17 15:06:51.352185 2026] [security2:error] [pid 955873:tid 956012] [client 185.55.149.49:61280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBUAAAARM"]
[Thu Sep 17 15:06:51.530430 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxWaxFTPRVSLOsRVhoBUwAAASs"]
[Thu Sep 17 15:06:51.588869 2026] [security2:error] [pid 955873:tid 956106] [client 45.156.129.167:15834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "aqxWaxFTPRVSLOsRVhoBVwAAAXE"]
[Thu Sep 17 15:06:51.684846 2026] [authz_core:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/error_log
[Thu Sep 17 15:06:51.693225 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxWaxFTPRVSLOsRVhoBWAAAAVU"]
[Thu Sep 17 15:06:51.834778 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:38226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/wp-includes/sodium_compat/"] [unique_id "aqxWaxFTPRVSLOsRVhoBZAAAAR0"]
[Thu Sep 17 15:06:51.857956 2026] [security2:error] [pid 955873:tid 955917] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/backend-api/.env"] [unique_id "aqxWaxFTPRVSLOsRVhoBZwABLCs"]
[Thu Sep 17 15:06:52.150265 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWbBFTPRVSLOsRVhoBbwAAAWs"]
[Thu Sep 17 15:06:52.176229 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBawAAAVM"]
[Thu Sep 17 15:06:52.176261 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBawAAAVM"]
[Thu Sep 17 15:06:52.277705 2026] [security2:error] [pid 955873:tid 955920] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/sql/.env"] [unique_id "aqxWbBFTPRVSLOsRVhoBdAABZC4"]
[Thu Sep 17 15:06:52.277895 2026] [security2:error] [pid 955873:tid 955926] [remote 34.52.229.253:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cyberpunkonline.net"] [uri "/db.bak"] [unique_id "aqxWbBFTPRVSLOsRVhoBdQABZDQ"]
[Thu Sep 17 15:06:52.315650 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxWbBFTPRVSLOsRVhoBfAAAATo"]
[Thu Sep 17 15:06:52.315746 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxWbBFTPRVSLOsRVhoBfAAAATo"]
[Thu Sep 17 15:06:52.594540 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:38232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWbBFTPRVSLOsRVhoBiAAAARE"]
[Thu Sep 17 15:06:52.759578 2026] [authz_core:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/error_log
[Thu Sep 17 15:06:52.787889 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWbBFTPRVSLOsRVhoBjwAAARo"]
[Thu Sep 17 15:06:52.927732 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:38232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxWbBFTPRVSLOsRVhoBmQAAAXo"]
[Thu Sep 17 15:06:52.972505 2026] [security2:error] [pid 955873:tid 956024] [client 34.35.44.204:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWbBFTPRVSLOsRVhoBngAAAR8"]
[Thu Sep 17 15:06:53.240303 2026] [security2:error] [pid 955873:tid 956058] [client 4.240.114.86:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBpgAAAUE"], referer: binance.com
[Thu Sep 17 15:06:53.278089 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBogAAATw"]
[Thu Sep 17 15:06:53.278114 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBogAAATw"]
[Thu Sep 17 15:06:53.418498 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:38232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBrgAAARM"]
[Thu Sep 17 15:06:53.418606 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:38232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBrgAAARM"]
[Thu Sep 17 15:06:53.428110 2026] [security2:error] [pid 955873:tid 956040] [client 45.156.129.167:15860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "aqxWbRFTPRVSLOsRVhoBsAAAAS8"]
[Thu Sep 17 15:06:53.719458 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:38234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBugAAAVs"]
[Thu Sep 17 15:06:53.719571 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:38234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxWbRFTPRVSLOsRVhoBugAAAVs"]
[Thu Sep 17 15:06:53.834167 2026] [security2:error] [pid 955873:tid 956009] [client 34.35.44.204:36466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWbRFTPRVSLOsRVhoBwQAAARA"]
[Thu Sep 17 15:06:54.011545 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:38250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxWbhFTPRVSLOsRVhoBxwAAAVM"]
[Thu Sep 17 15:06:54.167985 2026] [authz_core:error] [pid 955873:tid 956119] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/ChaCha20/error_log
[Thu Sep 17 15:06:54.170608 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxWbhFTPRVSLOsRVhoByQAAAX4"]
[Thu Sep 17 15:06:54.311814 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:38250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWbhFTPRVSLOsRVhoB0QAAAV0"]
[Thu Sep 17 15:06:54.402418 2026] [security2:error] [pid 955873:tid 956124] [client 181.45.133.126:7100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB0AABg00"]
[Thu Sep 17 15:06:54.452101 2026] [security2:error] [pid 955873:tid 956077] [client 37.139.53.124:52741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWaxFTPRVSLOsRVhoBaQAAATs"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:06:54.458129 2026] [security2:error] [pid 955873:tid 956010] [client 45.169.98.18:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB1QAAARE"]
[Thu Sep 17 15:06:54.458233 2026] [security2:error] [pid 955873:tid 956010] [client 45.169.98.18:56733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB1QAAARE"]
[Thu Sep 17 15:06:54.646624 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB0wAAAYU"]
[Thu Sep 17 15:06:54.646649 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB0wAAAYU"]
[Thu Sep 17 15:06:54.676138 2026] [security2:error] [pid 955873:tid 956104] [client 34.35.44.204:36468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWbhFTPRVSLOsRVhoB2QAAAW8"]
[Thu Sep 17 15:06:54.825076 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:38250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB4AAAAX8"]
[Thu Sep 17 15:06:54.825181 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:38250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB4AAAAX8"]
[Thu Sep 17 15:06:54.841805 2026] [security2:error] [pid 955873:tid 956105] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWbhFTPRVSLOsRVhoB1wABcE8"]
[Thu Sep 17 15:06:55.125225 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:38256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB5AAAAUg"]
[Thu Sep 17 15:06:55.125332 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:38256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB5AAAAUg"]
[Thu Sep 17 15:06:55.168997 2026] [security2:error] [pid 955873:tid 956130] [client 45.156.129.165:55668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxWbxFTPRVSLOsRVhoB5QAAAYk"]
[Thu Sep 17 15:06:55.292978 2026] [autoindex:error] [pid 955873:tid 956055] [client 34.178.167.214:45048] AH01276: Cannot serve directory /home1/gscqjxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:06:55.401598 2026] [security2:error] [pid 955873:tid 956127] [client 4.240.114.86:55669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB7QAAAYY"], referer: binance.com
[Thu Sep 17 15:06:55.415669 2026] [security2:error] [pid 955873:tid 956026] [client 169.58.198.243:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB8AAAASE"], referer: www.google.com
[Thu Sep 17 15:06:55.415675 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB7wAAAUk"]
[Thu Sep 17 15:06:55.415789 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:38264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB7wAAAUk"]
[Thu Sep 17 15:06:55.500856 2026] [security2:error] [pid 955873:tid 956042] [client 34.35.44.204:36482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB9AAAATE"]
[Thu Sep 17 15:06:55.696025 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxWbxFTPRVSLOsRVhoB-AAAAW4"]
[Thu Sep 17 15:06:55.785327 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB-wAAATM"]
[Thu Sep 17 15:06:55.785431 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:50422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB-wAAATM"]
[Thu Sep 17 15:06:55.851274 2026] [authz_core:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/error_log
[Thu Sep 17 15:06:55.859680 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxWbxFTPRVSLOsRVhoB_QAAASw"]
[Thu Sep 17 15:06:55.950809 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:41333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoCAwAAASs"]
[Thu Sep 17 15:06:55.950957 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:41333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWbxFTPRVSLOsRVhoCAwAAASs"]
[Thu Sep 17 15:06:56.002803 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWcBFTPRVSLOsRVhoCBQAAASc"]
[Thu Sep 17 15:06:56.042616 2026] [fcgid:warn] [pid 955873:tid 956041] (70014)End of file found: [client 199.45.155.30:41016] mod_fcgid: can't get data from http client
[Thu Sep 17 15:06:56.323690 2026] [security2:error] [pid 955873:tid 956125] [client 45.156.129.166:47282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "aqxWcBFTPRVSLOsRVhoCDwAAAYQ"]
[Thu Sep 17 15:06:56.340215 2026] [security2:error] [pid 955873:tid 956128] [client 47.79.202.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWbxFTPRVSLOsRVhoCBAAAAYc"], referer: https://www.google.com/
[Thu Sep 17 15:06:56.348841 2026] [security2:error] [pid 955873:tid 956098] [client 34.35.44.204:36494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCEAAAAWk"]
[Thu Sep 17 15:06:56.356350 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCCQAAAXE"]
[Thu Sep 17 15:06:56.356389 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCCQAAAXE"]
[Thu Sep 17 15:06:56.516186 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCFQAAAUM"]
[Thu Sep 17 15:06:56.516348 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCFQAAAUM"]
[Thu Sep 17 15:06:56.759418 2026] [security2:error] [pid 955873:tid 956019] [client 194.163.128.162:57229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wildamerika.com"] [uri "/index.php"] [unique_id "aqxWbxFTPRVSLOsRVhoB_gAAARo"], referer: binance.com
[Thu Sep 17 15:06:56.783700 2026] [security2:error] [pid 955873:tid 956052] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCBwABO1A"]
[Thu Sep 17 15:06:56.880825 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:38286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxWcBFTPRVSLOsRVhoCIQAAAXc"]
[Thu Sep 17 15:06:56.993711 2026] [security2:error] [pid 955873:tid 956014] [client 191.92.189.134:55798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWcBFTPRVSLOsRVhoCIAABFUo"]
[Thu Sep 17 15:06:57.038401 2026] [authz_core:error] [pid 955873:tid 956101] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/error_log
[Thu Sep 17 15:06:57.042574 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxWcRFTPRVSLOsRVhoCIgAAAWw"]
[Thu Sep 17 15:06:57.171048 2026] [security2:error] [pid 955873:tid 956079] [client 34.35.44.204:36508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCJgAAAVY"]
[Thu Sep 17 15:06:57.180564 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:38286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxWcRFTPRVSLOsRVhoCJwAAAXA"]
[Thu Sep 17 15:06:57.346527 2026] [security2:error] [pid 955873:tid 956065] [client 45.156.129.164:59664] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "aqxWcRFTPRVSLOsRVhoCMAAAAUg"]
[Thu Sep 17 15:06:57.535448 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCLwAAAYg"]
[Thu Sep 17 15:06:57.535472 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCLwAAAYg"]
[Thu Sep 17 15:06:57.725926 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCNwAAATE"]
[Thu Sep 17 15:06:57.726074 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:38286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCNwAAATE"]
[Thu Sep 17 15:06:57.782158 2026] [security2:error] [pid 955873:tid 956061] [client 104.28.198.244:22674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCOAAAAUQ"]
[Thu Sep 17 15:06:57.782299 2026] [security2:error] [pid 955873:tid 956061] [client 104.28.198.244:22674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCOAAAAUQ"]
[Thu Sep 17 15:06:57.991788 2026] [security2:error] [pid 955873:tid 956053] [client 34.35.44.204:36512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWcRFTPRVSLOsRVhoCPgAAATw"]
[Thu Sep 17 15:06:58.010256 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:38292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWchFTPRVSLOsRVhoCPwAAATg"]
[Thu Sep 17 15:06:58.010338 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:38292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWchFTPRVSLOsRVhoCPwAAATg"]
[Thu Sep 17 15:06:58.136420 2026] [security2:error] [pid 955873:tid 956037] [client 4.240.114.86:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxWchFTPRVSLOsRVhoCQgAAASw"], referer: binance.com
[Thu Sep 17 15:06:58.296620 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWchFTPRVSLOsRVhoCQwAAASs"]
[Thu Sep 17 15:06:58.296775 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:38308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWchFTPRVSLOsRVhoCQwAAASs"]
[Thu Sep 17 15:06:58.307818 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:52744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWchFTPRVSLOsRVhoCRwAAASQ"]
[Thu Sep 17 15:06:58.307923 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:52744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWchFTPRVSLOsRVhoCRwAAASQ"]
[Thu Sep 17 15:06:58.575948 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWchFTPRVSLOsRVhoCUQAAATo"]
[Thu Sep 17 15:06:58.576062 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:38316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWchFTPRVSLOsRVhoCUQAAATo"]
[Thu Sep 17 15:06:58.837677 2026] [security2:error] [pid 955873:tid 956046] [client 34.35.44.204:36528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWAAAATU"]
[Thu Sep 17 15:06:58.838764 2026] [security2:error] [pid 955873:tid 956119] [client 17.166.153.136:39682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWchFTPRVSLOsRVhoCUgABfmM"]
[Thu Sep 17 15:06:58.880920 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:38322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWwAAARo"]
[Thu Sep 17 15:06:58.881035 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:38322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWwAAARo"]
[Thu Sep 17 15:06:58.922803 2026] [security2:error] [pid 955873:tid 956057] [client 127.0.0.1:14636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxWchFTPRVSLOsRVhoCXAAAAUA"]
[Thu Sep 17 15:06:58.922839 2026] [security2:error] [pid 955873:tid 956080] [client 74.7.241.141:49594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.owp.dxd.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWchFTPRVSLOsRVhoCWgABV2k"]
[Thu Sep 17 15:06:59.092756 2026] [security2:error] [pid 955873:tid 956079] [client 20.244.34.24:53042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCZQAAAVY"], referer: binance.com
[Thu Sep 17 15:06:59.119648 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:58382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWcxFTPRVSLOsRVhoCZgAAATI"]
[Thu Sep 17 15:06:59.173203 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:38334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCZwAAAR8"]
[Thu Sep 17 15:06:59.173317 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:38334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCZwAAAR8"]
[Thu Sep 17 15:06:59.199740 2026] [security2:error] [pid 955873:tid 956006] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWchFTPRVSLOsRVhoCWQABDWY"]
[Thu Sep 17 15:06:59.259402 2026] [security2:error] [pid 955873:tid 956113] [client 45.156.129.164:59668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "aqxWcxFTPRVSLOsRVhoCagAAAXg"]
[Thu Sep 17 15:06:59.404920 2026] [security2:error] [pid 955873:tid 956007] [client 169.58.198.243:53018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCbgAAAQ4"], referer: www.google.com
[Thu Sep 17 15:06:59.432638 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:58390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWcxFTPRVSLOsRVhoCbwAAAYk"]
[Thu Sep 17 15:06:59.457188 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:38346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCcAAAARs"]
[Thu Sep 17 15:06:59.457283 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:38346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCcAAAARs"]
[Thu Sep 17 15:06:59.658884 2026] [security2:error] [pid 955873:tid 956058] [client 34.35.44.204:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCeAAAAUE"]
[Thu Sep 17 15:06:59.747709 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:38352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCeQAAAUw"]
[Thu Sep 17 15:06:59.747829 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:38352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCeQAAAUw"]
[Thu Sep 17 15:06:59.797797 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:58392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWcxFTPRVSLOsRVhoCfwAAAYA"]
[Thu Sep 17 15:06:59.828831 2026] [security2:error] [pid 955873:tid 956034] [client 4.240.114.86:57709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxWcxFTPRVSLOsRVhoCggAAASk"], referer: binance.com
[Thu Sep 17 15:07:00.044366 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxWdBFTPRVSLOsRVhoChgAAATM"]
[Thu Sep 17 15:07:00.044517 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxWdBFTPRVSLOsRVhoChgAAATM"]
[Thu Sep 17 15:07:00.232063 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:58400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.coblersen.com"] [uri "/"] [unique_id "aqxWdBFTPRVSLOsRVhoCiQAAASA"]
[Thu Sep 17 15:07:00.332470 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCjwAAAU4"]
[Thu Sep 17 15:07:00.332579 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCjwAAAU4"]
[Thu Sep 17 15:07:00.530282 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env"] [unique_id "aqxWdBFTPRVSLOsRVhoClQAAAU8"]
[Thu Sep 17 15:07:00.615677 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:40778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxWdBFTPRVSLOsRVhoClwAAATo"]
[Thu Sep 17 15:07:00.686808 2026] [security2:error] [pid 955873:tid 956100] [client 34.35.44.204:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCmgAAAWs"]
[Thu Sep 17 15:07:00.722823 2026] [security2:error] [pid 955873:tid 956046] [client 34.166.221.252:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCmwAAATU"]
[Thu Sep 17 15:07:00.771408 2026] [authz_core:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Poly1305/error_log
[Thu Sep 17 15:07:00.773276 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxWdBFTPRVSLOsRVhoCnQAAARo"]
[Thu Sep 17 15:07:00.931711 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:40778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxWdBFTPRVSLOsRVhoCowAAAQ8"]
[Thu Sep 17 15:07:01.083878 2026] [security2:error] [pid 955873:tid 956035] [client 88.136.135.42:58966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWdBFTPRVSLOsRVhoCpwABKnk"]
[Thu Sep 17 15:07:01.106267 2026] [security2:error] [pid 955873:tid 956101] [client 45.156.129.166:47290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alrayancont.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxWdRFTPRVSLOsRVhoCrQAAAWw"]
[Thu Sep 17 15:07:01.218132 2026] [security2:error] [pid 955873:tid 956098] [client 45.66.42.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "compassalpha.com"] [uri "/index.php"] [unique_id "aqxWdBFTPRVSLOsRVhoClgAAAWk"], referer: https://compassalpha.com
[Thu Sep 17 15:07:01.324184 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCrAAAARU"]
[Thu Sep 17 15:07:01.324209 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCrAAAARU"]
[Thu Sep 17 15:07:01.333424 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.bak"] [unique_id "aqxWdRFTPRVSLOsRVhoCuAAAAVg"]
[Thu Sep 17 15:07:01.420823 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.221.252:49982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/info.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCuwAAAXA"]
[Thu Sep 17 15:07:01.447004 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.backup"] [unique_id "aqxWdRFTPRVSLOsRVhoCvAAAARs"]
[Thu Sep 17 15:07:01.461944 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCvgAAAVQ"]
[Thu Sep 17 15:07:01.462039 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCvgAAAVQ"]
[Thu Sep 17 15:07:01.505857 2026] [security2:error] [pid 955873:tid 956124] [client 34.35.44.204:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCwAAAAYM"]
[Thu Sep 17 15:07:01.626470 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.old"] [unique_id "aqxWdRFTPRVSLOsRVhoCxAAAAWA"]
[Thu Sep 17 15:07:01.790360 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCyQAAAS8"]
[Thu Sep 17 15:07:01.790479 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCyQAAAS8"]
[Thu Sep 17 15:07:01.819756 2026] [security2:error] [pid 955873:tid 956011] [client 57.141.14.101:27076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCxgABEm8"]
[Thu Sep 17 15:07:01.861956 2026] [security2:error] [pid 955873:tid 956110] [client 37.139.53.124:53034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxWdRFTPRVSLOsRVhoCswAAAYQ"], referer: https://golovefoundation.org/wp-login.php?action=register
[Thu Sep 17 15:07:02.056704 2026] [security2:error] [pid 955873:tid 956049] [client 185.55.149.49:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0gAAATg"]
[Thu Sep 17 15:07:02.056832 2026] [security2:error] [pid 955873:tid 956049] [client 185.55.149.49:61947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0gAAATg"]
[Thu Sep 17 15:07:02.082242 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0wAAAS0"]
[Thu Sep 17 15:07:02.082355 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC0wAAAS0"]
[Thu Sep 17 15:07:02.117127 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.221.252:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/php.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC1AAAATM"]
[Thu Sep 17 15:07:02.276459 2026] [security2:error] [pid 955873:tid 955998] [remote 216.73.217.142:24319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWdhFTPRVSLOsRVhoC2AABMHw"]
[Thu Sep 17 15:07:02.345799 2026] [security2:error] [pid 955873:tid 956015] [client 34.35.44.204:52600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC2gAAARY"]
[Thu Sep 17 15:07:02.380840 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:40812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC3QAAAVw"]
[Thu Sep 17 15:07:02.380968 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:40812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC3QAAAVw"]
[Thu Sep 17 15:07:02.672833 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC6QAAATs"]
[Thu Sep 17 15:07:02.672944 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC6QAAATs"]
[Thu Sep 17 15:07:02.820397 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.221.252:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/i.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC8AAAAXI"]
[Thu Sep 17 15:07:02.838083 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env.swp"] [unique_id "aqxWdhFTPRVSLOsRVhoC8gAAAVA"]
[Thu Sep 17 15:07:02.938644 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.env~"] [unique_id "aqxWdhFTPRVSLOsRVhoC9gAAAXA"]
[Thu Sep 17 15:07:02.966081 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC-wAAAWc"]
[Thu Sep 17 15:07:02.966220 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxWdhFTPRVSLOsRVhoC-wAAAWc"]
[Thu Sep 17 15:07:03.194855 2026] [security2:error] [pid 955873:tid 956014] [client 34.35.44.204:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDBwAAARU"]
[Thu Sep 17 15:07:03.228671 2026] [security2:error] [pid 955873:tid 956040] [client 4.240.114.86:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDCQAAAS8"], referer: binance.com
[Thu Sep 17 15:07:03.350613 2026] [security2:error] [pid 955873:tid 956059] [client 169.58.198.243:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/ph-file-manager/wp-file.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDAAAAUI"], referer: www.google.com
[Thu Sep 17 15:07:03.370686 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:40846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDQAAAXU"]
[Thu Sep 17 15:07:03.370833 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:40846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDQAAAXU"]
[Thu Sep 17 15:07:03.446699 2026] [autoindex:error] [pid 955873:tid 956011] [client 45.55.41.71:49602] AH01276: Cannot serve directory /home1/kgrvnlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:03.501299 2026] [security2:error] [pid 955873:tid 956065] [client 31.206.188.182:7878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDDwABSF8"]
[Thu Sep 17 15:07:03.503711 2026] [security2:error] [pid 955873:tid 956067] [client 78.161.201.82:53556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qyg.ygn.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDBAABSm4"]
[Thu Sep 17 15:07:03.524132 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.221.252:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/pi.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDGAAAAQ4"]
[Thu Sep 17 15:07:03.668251 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDGwAAAXY"]
[Thu Sep 17 15:07:03.668362 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDGwAAAXY"]
[Thu Sep 17 15:07:03.844791 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/app/.env"] [unique_id "aqxWdxFTPRVSLOsRVhoDIAAAAYU"]
[Thu Sep 17 15:07:03.927283 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/apps/.env"] [unique_id "aqxWdxFTPRVSLOsRVhoDKAAAAVY"]
[Thu Sep 17 15:07:03.967036 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDKgAAATs"]
[Thu Sep 17 15:07:03.967152 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxWdxFTPRVSLOsRVhoDKgAAATs"]
[Thu Sep 17 15:07:04.021670 2026] [security2:error] [pid 955873:tid 956080] [client 34.35.44.204:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDKwAAAVc"]
[Thu Sep 17 15:07:04.038706 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDLAAAAR8"]
[Thu Sep 17 15:07:04.135525 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/web/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDMQAAAVQ"]
[Thu Sep 17 15:07:04.204708 2026] [security2:error] [pid 955873:tid 956027] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/site/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDMwAAASI"]
[Thu Sep 17 15:07:04.210691 2026] [security2:error] [pid 955873:tid 956120] [client 34.166.221.252:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/pinfo.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDNAAAAX8"]
[Thu Sep 17 15:07:04.250956 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:40872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxWeBFTPRVSLOsRVhoDNQAAAUw"]
[Thu Sep 17 15:07:04.276230 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/public/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDOAAAAT4"]
[Thu Sep 17 15:07:04.389244 2026] [security2:error] [pid 955873:tid 956083] [client 4.240.114.86:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDPAAAAVo"], referer: binance.com
[Thu Sep 17 15:07:04.423306 2026] [authz_core:error] [pid 955873:tid 956102] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/error_log
[Thu Sep 17 15:07:04.430792 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxWeBFTPRVSLOsRVhoDPQAAAW0"]
[Thu Sep 17 15:07:04.453575 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/backend/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDQQAAATY"]
[Thu Sep 17 15:07:04.521345 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/server/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDSQAAAUQ"]
[Thu Sep 17 15:07:04.575517 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:40872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/wp-includes/sodium_compat/"] [unique_id "aqxWeBFTPRVSLOsRVhoDSgAAAWE"]
[Thu Sep 17 15:07:04.626945 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/frontend/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDSwAAAXU"]
[Thu Sep 17 15:07:04.715530 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/src/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDTQAAASY"]
[Thu Sep 17 15:07:04.809312 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/core/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDTwAAAYc"]
[Thu Sep 17 15:07:04.853524 2026] [security2:error] [pid 955873:tid 956071] [client 34.35.44.204:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDUAAAAU4"]
[Thu Sep 17 15:07:04.902460 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/core/app/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDVAAAAQ4"]
[Thu Sep 17 15:07:04.937389 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.221.252:38282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/test.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDVQAAASQ"]
[Thu Sep 17 15:07:04.950514 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDTgAAATg"]
[Thu Sep 17 15:07:04.950548 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDTgAAATg"]
[Thu Sep 17 15:07:04.957338 2026] [security2:error] [pid 955873:tid 956009] [client 45.169.98.18:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDVwAAARA"]
[Thu Sep 17 15:07:04.957473 2026] [security2:error] [pid 955873:tid 956009] [client 45.169.98.18:57295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWeBFTPRVSLOsRVhoDVwAAARA"]
[Thu Sep 17 15:07:04.981785 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/config/.env"] [unique_id "aqxWeBFTPRVSLOsRVhoDWAAAATA"]
[Thu Sep 17 15:07:05.066110 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/private/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDWQAAARY"]
[Thu Sep 17 15:07:05.100180 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDWgAAAXY"]
[Thu Sep 17 15:07:05.100290 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:40872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDWgAAAXY"]
[Thu Sep 17 15:07:05.129106 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/application/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDXAAAAVw"]
[Thu Sep 17 15:07:05.259467 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/bootstrap/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDXgAAAYU"]
[Thu Sep 17 15:07:05.345365 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/database/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDYQAAAVY"]
[Thu Sep 17 15:07:05.402930 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWeRFTPRVSLOsRVhoDZwAAASo"]
[Thu Sep 17 15:07:05.439062 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/storage/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDaQAAAQ8"]
[Thu Sep 17 15:07:05.547432 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/var/www/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDagAAAXA"]
[Thu Sep 17 15:07:05.607015 2026] [authz_core:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/error_log
[Thu Sep 17 15:07:05.644516 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWeRFTPRVSLOsRVhoDawAAAWQ"]
[Thu Sep 17 15:07:05.666339 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/var/www/html/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDcQAAAW8"]
[Thu Sep 17 15:07:05.680203 2026] [security2:error] [pid 955873:tid 956006] [client 34.35.44.204:52644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDcwAAAQ0"]
[Thu Sep 17 15:07:05.740774 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/current/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDdgAAARk"]
[Thu Sep 17 15:07:05.785746 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/wp-includes/sodium_compat/src/"] [unique_id "aqxWeRFTPRVSLOsRVhoDdwAAAYQ"]
[Thu Sep 17 15:07:05.834030 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/release/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDeAAAAVg"]
[Thu Sep 17 15:07:05.865764 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.221.252:38296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/p.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDegAAAYg"]
[Thu Sep 17 15:07:05.930031 2026] [security2:error] [pid 955873:tid 956087] [client 45.156.128.66:12428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travisklassen.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDbgABXhE"]
[Thu Sep 17 15:07:05.935994 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/releases/.env"] [unique_id "aqxWeRFTPRVSLOsRVhoDfwAAAS8"]
[Thu Sep 17 15:07:06.014251 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/shared/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDgQAAATE"]
[Thu Sep 17 15:07:06.041060 2026] [security2:error] [pid 955873:tid 956120] [client 57.141.14.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reddomconstruction.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDdQAAAX8"]
[Thu Sep 17 15:07:06.149330 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/deploy/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDigAAAUs"]
[Thu Sep 17 15:07:06.159573 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDfAAAATY"]
[Thu Sep 17 15:07:06.159597 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWeRFTPRVSLOsRVhoDfAAAATY"]
[Thu Sep 17 15:07:06.209747 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/build/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDjAAAAU0"]
[Thu Sep 17 15:07:06.293155 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/dist/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDjwAAAUk"]
[Thu Sep 17 15:07:06.300610 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxWehFTPRVSLOsRVhoDkAAAASc"]
[Thu Sep 17 15:07:06.405588 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/public_html/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDkgAAAU4"]
[Thu Sep 17 15:07:06.410913 2026] [security2:error] [pid 955873:tid 956028] [client 115.244.164.14:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDkwAAASM"]
[Thu Sep 17 15:07:06.411014 2026] [security2:error] [pid 955873:tid 956028] [client 115.244.164.14:51076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDkwAAASM"]
[Thu Sep 17 15:07:06.456799 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxWehFTPRVSLOsRVhoDlAAAAUo"]
[Thu Sep 17 15:07:06.480736 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/htdocs/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDlwAAAQ4"]
[Thu Sep 17 15:07:06.498335 2026] [security2:error] [pid 955873:tid 956056] [client 45.156.128.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travisklassen.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDjQAAAT8"]
[Thu Sep 17 15:07:06.518506 2026] [security2:error] [pid 955873:tid 956128] [client 34.35.44.204:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.44.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omq.zsh.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWehFTPRVSLOsRVhoDmAAAAYc"]
[Thu Sep 17 15:07:06.561246 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.221.252:38298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/debug.php"] [unique_id "aqxWehFTPRVSLOsRVhoDmgAAAUc"]
[Thu Sep 17 15:07:06.567063 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/www/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDmwAAATA"]
[Thu Sep 17 15:07:06.604105 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWehFTPRVSLOsRVhoDnwAAAVk"]
[Thu Sep 17 15:07:06.649393 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/html/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDoQAAAT0"]
[Thu Sep 17 15:07:06.688983 2026] [security2:error] [pid 955873:tid 956055] [client 194.163.128.162:60391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wildamerika.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDogAAAT4"], referer: binance.com
[Thu Sep 17 15:07:06.724799 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/live/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDowAAAQw"]
[Thu Sep 17 15:07:06.811876 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/prod/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDpwAAAYU"]
[Thu Sep 17 15:07:06.847436 2026] [security2:error] [pid 955873:tid 956118] [client 154.190.208.131:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDqgAAAX0"]
[Thu Sep 17 15:07:06.847566 2026] [security2:error] [pid 955873:tid 956118] [client 154.190.208.131:41658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWehFTPRVSLOsRVhoDqgAAAX0"]
[Thu Sep 17 15:07:06.860192 2026] [security2:error] [pid 955873:tid 956111] [client 104.207.47.59:13715] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWehFTPRVSLOsRVhoDqwAAAXY"]
[Thu Sep 17 15:07:06.875373 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/dev/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDrQAAAWU"]
[Thu Sep 17 15:07:06.955196 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/staging/.env"] [unique_id "aqxWehFTPRVSLOsRVhoDsQAAAWI"]
[Thu Sep 17 15:07:06.988526 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDpAAAAUg"]
[Thu Sep 17 15:07:06.988559 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWehFTPRVSLOsRVhoDpAAAAUg"]
[Thu Sep 17 15:07:07.015186 2026] [autoindex:error] [pid 955873:tid 955902] [remote 93.152.209.11:46060] AH01276: Cannot serve directory /home1/ymjxogmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:07.074917 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/opt/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDuwAAAWQ"]
[Thu Sep 17 15:07:07.134611 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:40888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoDvwAAARQ"]
[Thu Sep 17 15:07:07.134744 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:40888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoDvwAAARQ"]
[Thu Sep 17 15:07:07.137876 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/laravel/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDwAAAAXo"]
[Thu Sep 17 15:07:07.251008 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/symfony/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDwgAAATI"]
[Thu Sep 17 15:07:07.267401 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.221.252:38306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWexFTPRVSLOsRVhoDwwAAAXA"]
[Thu Sep 17 15:07:07.345180 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/wordpress/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDyAAAAV4"]
[Thu Sep 17 15:07:07.413281 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxWexFTPRVSLOsRVhoDyQAAAS8"]
[Thu Sep 17 15:07:07.413426 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxWexFTPRVSLOsRVhoDyQAAAS8"]
[Thu Sep 17 15:07:07.458007 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/wp/.env"] [unique_id "aqxWexFTPRVSLOsRVhoDzQAAAXU"]
[Thu Sep 17 15:07:07.497880 2026] [security2:error] [pid 955873:tid 956120] [client 20.244.34.24:62961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxWexFTPRVSLOsRVhoDzwAAAX8"], referer: binance.com
[Thu Sep 17 15:07:07.572259 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cms/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD1QAAARM"]
[Thu Sep 17 15:07:07.590524 2026] [security2:error] [pid 955873:tid 956039] [client 77.232.40.141:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.40.232.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxWexFTPRVSLOsRVhoD0wAAAS4"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:07:07.590628 2026] [security2:error] [pid 955873:tid 956039] [client 77.232.40.141:59898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxWexFTPRVSLOsRVhoD0wAAAS4"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:07:07.644599 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/drupal/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD2gAAAWE"]
[Thu Sep 17 15:07:07.689357 2026] [security2:error] [pid 955873:tid 956121] [client 45.156.128.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "travisklassen.com"] [uri "/index.php"] [unique_id "aqxWexFTPRVSLOsRVhoD1AAAAYA"], referer: http://travisklassen.com/favicon.ico
[Thu Sep 17 15:07:07.716641 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/joomla/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD3AAAAUk"]
[Thu Sep 17 15:07:07.817938 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.224.217:58408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/magento/.env"] [unique_id "aqxWexFTPRVSLOsRVhoD3gAAASs"]
[Thu Sep 17 15:07:07.893747 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoD4QAAATg"]
[Thu Sep 17 15:07:07.893843 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:40910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxWexFTPRVSLOsRVhoD4QAAATg"]
[Thu Sep 17 15:07:07.953065 2026] [security2:error] [pid 955873:tid 956032] [client 34.166.221.252:38312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWexFTPRVSLOsRVhoD4gAAASc"]
[Thu Sep 17 15:07:08.134483 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/shopify/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD6gAAAXc"]
[Thu Sep 17 15:07:08.178155 2026] [security2:error] [pid 955873:tid 956033] [client 4.240.114.86:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD7AAAASg"], referer: binance.com
[Thu Sep 17 15:07:08.228832 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/prestashop/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD7QAAATc"]
[Thu Sep 17 15:07:08.252700 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD7gAAAYU"]
[Thu Sep 17 15:07:08.252799 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD7gAAAYU"]
[Thu Sep 17 15:07:08.304254 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/codeigniter/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD8QAAATs"]
[Thu Sep 17 15:07:08.378988 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cakephp/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD8wAAAXY"]
[Thu Sep 17 15:07:08.487286 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/zend/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD-wAAAV8"]
[Thu Sep 17 15:07:08.559030 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:40918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD_QAAAUE"]
[Thu Sep 17 15:07:08.559125 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:40918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxWfBFTPRVSLOsRVhoD_QAAAUE"]
[Thu Sep 17 15:07:08.561842 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/yii/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoD_gAAAVQ"]
[Thu Sep 17 15:07:08.643008 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/laravel5/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoEAAAAAR8"]
[Thu Sep 17 15:07:08.649879 2026] [security2:error] [pid 955873:tid 956123] [client 34.166.221.252:38324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWfBFTPRVSLOsRVhoEAQAAAYI"]
[Thu Sep 17 15:07:08.752241 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/v1/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoEBAAAAYY"]
[Thu Sep 17 15:07:08.871589 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/v2/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoEBgAAARk"]
[Thu Sep 17 15:07:08.875077 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:40924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxWfBFTPRVSLOsRVhoEBwAAAXk"]
[Thu Sep 17 15:07:08.962877 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/v3/.env"] [unique_id "aqxWfBFTPRVSLOsRVhoECwAAAWk"]
[Thu Sep 17 15:07:09.038250 2026] [authz_core:error] [pid 955873:tid 956026] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/AES/error_log
[Thu Sep 17 15:07:09.040944 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxWfRFTPRVSLOsRVhoEDgAAASE"]
[Thu Sep 17 15:07:09.185344 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWfRFTPRVSLOsRVhoEDwAAAS8"]
[Thu Sep 17 15:07:09.331765 2026] [security2:error] [pid 955873:tid 956081] [client 186.105.232.15:53335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFQAAAVg"]
[Thu Sep 17 15:07:09.331874 2026] [security2:error] [pid 955873:tid 956081] [client 186.105.232.15:53335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFQAAAVg"]
[Thu Sep 17 15:07:09.335948 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.221.252:38332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFgAAARU"]
[Thu Sep 17 15:07:09.389137 2026] [security2:error] [pid 955873:tid 956008] [client 4.240.114.86:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.staging.paltals.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFwAAAQ8"], referer: binance.com
[Thu Sep 17 15:07:09.433201 2026] [fcgid:warn] [pid 955873:tid 956047] (70014)End of file found: [client 66.132.172.223:28590] mod_fcgid: can't get data from http client
[Thu Sep 17 15:07:09.578462 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFAAAARM"]
[Thu Sep 17 15:07:09.578492 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEFAAAARM"]
[Thu Sep 17 15:07:09.719179 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEIwAAASk"]
[Thu Sep 17 15:07:09.719324 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:40924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxWfRFTPRVSLOsRVhoEIwAAASk"]
[Thu Sep 17 15:07:09.902943 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/v1/.env"] [unique_id "aqxWfRFTPRVSLOsRVhoEKgAAAYc"]
[Thu Sep 17 15:07:09.999653 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/v2/.env"] [unique_id "aqxWfRFTPRVSLOsRVhoELAAAAUQ"]
[Thu Sep 17 15:07:10.007279 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxWfhFTPRVSLOsRVhoELgAAARY"]
[Thu Sep 17 15:07:10.007385 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:35184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxWfhFTPRVSLOsRVhoELgAAARY"]
[Thu Sep 17 15:07:10.023726 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.221.252:38346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWfhFTPRVSLOsRVhoELwAAAQs"]
[Thu Sep 17 15:07:10.088540 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/rest/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEMwAAAUU"]
[Thu Sep 17 15:07:10.159056 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/graphql/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoENQAAAYg"]
[Thu Sep 17 15:07:10.272439 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/gateway/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoENwAAAXc"]
[Thu Sep 17 15:07:10.291849 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEOQAAAT4"]
[Thu Sep 17 15:07:10.291978 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:35192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEOQAAAT4"]
[Thu Sep 17 15:07:10.328947 2026] [security2:error] [pid 955873:tid 956104] [client 104.207.47.59:44283] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWfhFTPRVSLOsRVhoEOwAAAW8"]
[Thu Sep 17 15:07:10.422934 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/microservice/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEPwAAAYU"]
[Thu Sep 17 15:07:10.559523 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/service/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEQgAAAX0"]
[Thu Sep 17 15:07:10.578302 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:35208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEQwAAAWc"]
[Thu Sep 17 15:07:10.578406 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:35208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxWfhFTPRVSLOsRVhoEQwAAAWc"]
[Thu Sep 17 15:07:10.678737 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/v3/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoERQAAAXY"]
[Thu Sep 17 15:07:10.709043 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.221.252:38360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWfhFTPRVSLOsRVhoERgAAARA"]
[Thu Sep 17 15:07:10.744420 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/dev/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoESQAAAV8"]
[Thu Sep 17 15:07:10.841191 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/api/staging/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoETQAAAR8"]
[Thu Sep 17 15:07:10.870402 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:35212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxWfhFTPRVSLOsRVhoETgAAAYI"]
[Thu Sep 17 15:07:10.922719 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/vendor/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEUQAAARQ"]
[Thu Sep 17 15:07:10.993487 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/lib/.env"] [unique_id "aqxWfhFTPRVSLOsRVhoEVQAAAXI"]
[Thu Sep 17 15:07:11.031326 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxWfxFTPRVSLOsRVhoEVgAAAXg"]
[Thu Sep 17 15:07:11.102339 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/resources/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEWwAAASE"]
[Thu Sep 17 15:07:11.102740 2026] [core:error] [pid 955873:tid 956043] [client 69.171.231.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:11.102754 2026] [core:error] [pid 955873:tid 956043] [client 69.171.231.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:11.181117 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:35212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWfxFTPRVSLOsRVhoEXAAAARc"]
[Thu Sep 17 15:07:11.229234 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/assets/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEXwAAATw"]
[Thu Sep 17 15:07:11.338014 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/uploads/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEYgAAAQ8"]
[Thu Sep 17 15:07:11.414893 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/internal/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEZQAAAYQ"]
[Thu Sep 17 15:07:11.514968 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/tools/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEZgAAAYA"]
[Thu Sep 17 15:07:11.547633 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEYQAAASY"]
[Thu Sep 17 15:07:11.547655 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEYQAAASY"]
[Thu Sep 17 15:07:11.575449 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/scripts/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEaAAAARM"]
[Thu Sep 17 15:07:11.644011 2026] [security2:error] [pid 955873:tid 956028] [client 34.166.221.252:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/php-info.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbAAAASM"]
[Thu Sep 17 15:07:11.657670 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/bin/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEbQAAARs"]
[Thu Sep 17 15:07:11.695085 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:35212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbgAAAQ4"]
[Thu Sep 17 15:07:11.695221 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:35212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbgAAAQ4"]
[Thu Sep 17 15:07:11.727555 2026] [security2:error] [pid 955873:tid 956101] [client 20.255.75.24:1028] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hopmanchaissconsulting.com"] [uri "/1.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbwAAAWw"]
[Thu Sep 17 15:07:11.727699 2026] [security2:error] [pid 955873:tid 956101] [client 20.255.75.24:1028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/1.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEbwAAAWw"]
[Thu Sep 17 15:07:11.737495 2026] [security2:error] [pid 955873:tid 956124] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sbin/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEcQAAAYM"]
[Thu Sep 17 15:07:11.740820 2026] [autoindex:error] [pid 955873:tid 956117] [client 34.35.44.204:43892] AH01276: Cannot serve directory /home1/omqzshmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:11.788584 2026] [security2:error] [pid 955873:tid 956010] [client 169.58.198.243:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/root-file-manager/wp-file.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEcwAAARE"], referer: www.google.com
[Thu Sep 17 15:07:11.843568 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/local/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEdAAAARY"]
[Thu Sep 17 15:07:11.939536 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/portal/.env"] [unique_id "aqxWfxFTPRVSLOsRVhoEdQAAAUU"]
[Thu Sep 17 15:07:11.985614 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEdgAAAVo"]
[Thu Sep 17 15:07:11.985786 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxWfxFTPRVSLOsRVhoEdgAAAVo"]
[Thu Sep 17 15:07:12.040633 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/dashboard/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEegAAAT8"]
[Thu Sep 17 15:07:12.113583 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEfgAAAW4"]
[Thu Sep 17 15:07:12.147751 2026] [security2:error] [pid 955873:tid 956050] [client 20.255.75.24:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/new.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEgAAAATk"]
[Thu Sep 17 15:07:12.233796 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/crm/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEgwAAATc"]
[Thu Sep 17 15:07:12.272490 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEiAAAAYU"]
[Thu Sep 17 15:07:12.272586 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:35234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEiAAAAYU"]
[Thu Sep 17 15:07:12.298392 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/erp/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEiwAAAVY"]
[Thu Sep 17 15:07:12.324642 2026] [security2:error] [pid 955873:tid 956033] [client 34.166.221.252:38382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpversion.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEjgAAASg"]
[Thu Sep 17 15:07:12.349950 2026] [security2:error] [pid 955873:tid 956089] [client 84.33.131.77:54890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEhgABYCM"]
[Thu Sep 17 15:07:12.409094 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/shop/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEkAAAAXY"]
[Thu Sep 17 15:07:12.488021 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/store/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEkQAAARg"]
[Thu Sep 17 15:07:12.558128 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/saas/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoElgAAAVI"]
[Thu Sep 17 15:07:12.561392 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:35236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxWgBFTPRVSLOsRVhoElwAAARQ"]
[Thu Sep 17 15:07:12.631579 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/client/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEmgAAARk"]
[Thu Sep 17 15:07:12.637681 2026] [security2:error] [pid 955873:tid 956009] [client 20.255.75.24:1034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/num.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEmwAAARA"]
[Thu Sep 17 15:07:12.729319 2026] [security2:error] [pid 955873:tid 956088] [client 185.55.149.49:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEngAAAV8"]
[Thu Sep 17 15:07:12.729338 2026] [authz_core:error] [pid 955873:tid 956094] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/ChaCha20/error_log
[Thu Sep 17 15:07:12.729410 2026] [security2:error] [pid 955873:tid 956088] [client 185.55.149.49:62643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEngAAAV8"]
[Thu Sep 17 15:07:12.731115 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxWgBFTPRVSLOsRVhoEnQAAAWU"]
[Thu Sep 17 15:07:12.732985 2026] [security2:error] [pid 955873:tid 956086] [client 134.185.85.61:55592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thehivetribe.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxWgBFTPRVSLOsRVhoEnwAAAV0"]
[Thu Sep 17 15:07:12.733611 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/project/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEoAAAASE"]
[Thu Sep 17 15:07:12.757486 2026] [security2:error] [pid 955873:tid 956115] [client 4.240.114.86:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEogAAAXo"], referer: binance.com
[Thu Sep 17 15:07:12.803744 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/admin-panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEpQAAAVc"]
[Thu Sep 17 15:07:12.878584 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:35236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWgBFTPRVSLOsRVhoEpwAAAWM"]
[Thu Sep 17 15:07:12.900034 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/control-panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEqAAAAWE"]
[Thu Sep 17 15:07:12.986783 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/user-panel/.env"] [unique_id "aqxWgBFTPRVSLOsRVhoEqgAAAS0"]
[Thu Sep 17 15:07:13.018141 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.221.252:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/_phpinfo.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEqwAAAS8"]
[Thu Sep 17 15:07:13.115165 2026] [security2:error] [pid 955873:tid 956007] [client 134.185.85.61:58408] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thehivetribe.com"] [uri "/media/system/js/core.js"] [unique_id "aqxWgRFTPRVSLOsRVhoEsQAAAQ4"]
[Thu Sep 17 15:07:13.141896 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/node/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEtgAAAXw"]
[Thu Sep 17 15:07:13.233135 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/express/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEuQAAAYc"]
[Thu Sep 17 15:07:13.236405 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgRFTPRVSLOsRVhoErAAAARI"]
[Thu Sep 17 15:07:13.236421 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgRFTPRVSLOsRVhoErAAAARI"]
[Thu Sep 17 15:07:13.250528 2026] [autoindex:error] [pid 955873:tid 956049] [client 20.255.75.24:0] AH01276: Cannot serve directory /home2/hopmanch/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:07:13.301148 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/next/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEuwAAAVk"]
[Thu Sep 17 15:07:13.374729 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/nuxt/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEvAAAAUY"]
[Thu Sep 17 15:07:13.378600 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEvQAAAVo"]
[Thu Sep 17 15:07:13.378702 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEvQAAAVo"]
[Thu Sep 17 15:07:13.430084 2026] [security2:error] [pid 955873:tid 956112] [client 20.255.75.24:1041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/admin.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEvgAAAXc"]
[Thu Sep 17 15:07:13.444609 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/nest/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEvwAAAT4"]
[Thu Sep 17 15:07:13.569226 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/react/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoEwgAAAU0"]
[Thu Sep 17 15:07:13.666939 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/vue/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoExwAAAXE"]
[Thu Sep 17 15:07:13.667243 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEyAAAAXY"]
[Thu Sep 17 15:07:13.667317 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEyAAAAXY"]
[Thu Sep 17 15:07:13.713516 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.221.252:38398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWgRFTPRVSLOsRVhoEzQAAAW4"]
[Thu Sep 17 15:07:13.772275 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/angular/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoE0AAAARQ"]
[Thu Sep 17 15:07:13.853623 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/svelte/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoE0gAAAVM"]
[Thu Sep 17 15:07:13.860878 2026] [security2:error] [pid 955873:tid 956079] [client 104.207.47.59:41923] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWgRFTPRVSLOsRVhoE0wAAAVY"]
[Thu Sep 17 15:07:13.933871 2026] [security2:error] [pid 955873:tid 956075] [client 20.255.75.24:1047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/13.php"] [unique_id "aqxWgRFTPRVSLOsRVhoE1QAAAVI"]
[Thu Sep 17 15:07:13.946895 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxWgRFTPRVSLOsRVhoE1wAAARo"]
[Thu Sep 17 15:07:13.947046 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:35260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxWgRFTPRVSLOsRVhoE1wAAARo"]
[Thu Sep 17 15:07:13.998523 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/vite/.env"] [unique_id "aqxWgRFTPRVSLOsRVhoE2AAAAXI"]
[Thu Sep 17 15:07:14.053194 2026] [security2:error] [pid 955873:tid 956093] [client 20.244.34.24:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxWghFTPRVSLOsRVhoE2QAAAWQ"], referer: binance.com
[Thu Sep 17 15:07:14.117907 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/backup/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE3QAAATI"]
[Thu Sep 17 15:07:14.193108 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/backups/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE5AAAAVg"]
[Thu Sep 17 15:07:14.225069 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:35268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxWghFTPRVSLOsRVhoE5wAAAYY"]
[Thu Sep 17 15:07:14.261374 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/old/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE6QAAAWE"]
[Thu Sep 17 15:07:14.315849 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoE6AAAAXU"]
[Thu Sep 17 15:07:14.338060 2026] [security2:error] [pid 955873:tid 956032] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgBFTPRVSLOsRVhoEjwABJwM"], referer: http://cfbpp.org/wordpress/
[Thu Sep 17 15:07:14.352746 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/tmp/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE6wAAASY"]
[Thu Sep 17 15:07:14.391898 2026] [authz_core:error] [pid 955873:tid 956098] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Curve25519/error_log
[Thu Sep 17 15:07:14.397922 2026] [security2:error] [pid 955873:tid 956115] [client 34.166.221.252:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/server-info.php"] [unique_id "aqxWghFTPRVSLOsRVhoE7QAAAXo"]
[Thu Sep 17 15:07:14.403092 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxWghFTPRVSLOsRVhoE7AAAAWk"]
[Thu Sep 17 15:07:14.417553 2026] [security2:error] [pid 955873:tid 956092] [client 20.255.75.24:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/222.php"] [unique_id "aqxWghFTPRVSLOsRVhoE8AAAAWM"]
[Thu Sep 17 15:07:14.434492 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/temp/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE8wAAARM"]
[Thu Sep 17 15:07:14.527250 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/lab/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE9QAAAQ4"]
[Thu Sep 17 15:07:14.542442 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:35268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWghFTPRVSLOsRVhoE9gAAAXw"]
[Thu Sep 17 15:07:14.602610 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE9wAAARE"]
[Thu Sep 17 15:07:14.618561 2026] [security2:error] [pid 955873:tid 956034] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoE9AABKSg"], referer: http://cfbpp.org/wp/
[Thu Sep 17 15:07:14.621808 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cronlab/.env"] [unique_id "aqxWghFTPRVSLOsRVhoE-gAAATg"]
[Thu Sep 17 15:07:14.718781 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cron/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFBAAAAUU"]
[Thu Sep 17 15:07:14.796701 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/en/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFCQAAAT4"]
[Thu Sep 17 15:07:14.858647 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFBwAAAUY"]
[Thu Sep 17 15:07:14.898422 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/administrator/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFCgAAAYE"]
[Thu Sep 17 15:07:14.933124 2026] [security2:error] [pid 955873:tid 956022] [client 20.255.75.24:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/aa.php"] [unique_id "aqxWghFTPRVSLOsRVhoFDAAAAR0"]
[Thu Sep 17 15:07:14.950645 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFAwAAAUo"]
[Thu Sep 17 15:07:14.950685 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFAwAAAUo"]
[Thu Sep 17 15:07:14.968701 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/psnlink/.env"] [unique_id "aqxWghFTPRVSLOsRVhoFDwAAATQ"]
[Thu Sep 17 15:07:15.082500 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.221.252:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/server-status.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFFAAAAYg"]
[Thu Sep 17 15:07:15.085479 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWghFTPRVSLOsRVhoFEQAAAUI"]
[Thu Sep 17 15:07:15.089406 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFFgAAAVs"]
[Thu Sep 17 15:07:15.089503 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:35268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFFgAAAVs"]
[Thu Sep 17 15:07:15.111594 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/exapi/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFFwAAAYU"]
[Thu Sep 17 15:07:15.177283 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sitemaps/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFGgAAAUc"]
[Thu Sep 17 15:07:15.182557 2026] [security2:error] [pid 955873:tid 956106] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFEgABcSQ"], referer: http://cfbpp.org/new/
[Thu Sep 17 15:07:15.337857 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFIQAAARk"]
[Thu Sep 17 15:07:15.370594 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:35276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxWgxFTPRVSLOsRVhoFJQAAAXA"]
[Thu Sep 17 15:07:15.435700 2026] [security2:error] [pid 955873:tid 956019] [client 20.255.75.24:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/abcd.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFKwAAARo"]
[Thu Sep 17 15:07:15.435939 2026] [security2:error] [pid 955873:tid 956060] [client 45.169.98.18:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFLAAAAUM"]
[Thu Sep 17 15:07:15.436040 2026] [security2:error] [pid 955873:tid 956060] [client 45.169.98.18:57850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFLAAAAUM"]
[Thu Sep 17 15:07:15.456499 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/logs/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFLQAAAYQ"]
[Thu Sep 17 15:07:15.462543 2026] [security2:error] [pid 955873:tid 956086] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFIwABXS4"], referer: http://cfbpp.org/old/
[Thu Sep 17 15:07:15.541274 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxWgxFTPRVSLOsRVhoFLwAAAS0"]
[Thu Sep 17 15:07:15.549195 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFLgAAASE"]
[Thu Sep 17 15:07:15.568963 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cache/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFMQAAAXU"]
[Thu Sep 17 15:07:15.608116 2026] [security2:error] [pid 955873:tid 956025] [client 47.79.201.238:51880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFJgAAASA"], referer: https://www.google.com/
[Thu Sep 17 15:07:15.668399 2026] [security2:error] [pid 955873:tid 956039] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailer/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFOAAAAS4"]
[Thu Sep 17 15:07:15.686652 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:35276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxWgxFTPRVSLOsRVhoFOQAAAQ4"]
[Thu Sep 17 15:07:15.755509 2026] [security2:error] [pid 955873:tid 956115] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFNQABejI"], referer: http://cfbpp.org/blog/
[Thu Sep 17 15:07:15.759680 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mail/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFPAAAARE"]
[Thu Sep 17 15:07:15.820444 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/email/.env"] [unique_id "aqxWgxFTPRVSLOsRVhoFPwAAAUQ"]
[Thu Sep 17 15:07:15.848645 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFPQAAASs"]
[Thu Sep 17 15:07:15.925845 2026] [security2:error] [pid 955873:tid 956030] [client 20.255.75.24:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/about.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFRAAAASU"]
[Thu Sep 17 15:07:16.029699 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/smtp/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFSAAAAT0"]
[Thu Sep 17 15:07:16.031593 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFQQAAAQs"]
[Thu Sep 17 15:07:16.031610 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFQQAAAQs"]
[Thu Sep 17 15:07:16.045035 2026] [security2:error] [pid 955873:tid 956101] [client 107.170.69.53:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cfbpp.org"] [uri "/index.php"] [unique_id "aqxWgxFTPRVSLOsRVhoFQwABbC8"], referer: http://cfbpp.org/backup/
[Thu Sep 17 15:07:16.145603 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFSgAAATk"]
[Thu Sep 17 15:07:16.164087 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.224.217:40472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailing/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFTwAAATQ"]
[Thu Sep 17 15:07:16.176223 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFUQAAAYg"]
[Thu Sep 17 15:07:16.176346 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFUQAAAYg"]
[Thu Sep 17 15:07:16.274785 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.221.252:56670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWhBFTPRVSLOsRVhoFVQAAATo"]
[Thu Sep 17 15:07:16.349136 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWhBFTPRVSLOsRVhoFVgAAATU"]
[Thu Sep 17 15:07:16.363699 2026] [security2:error] [pid 955873:tid 956126] [client 169.58.198.243:55107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/plugins/wp-help/mini.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFVwAAAYU"], referer: www.google.com
[Thu Sep 17 15:07:16.425556 2026] [security2:error] [pid 955873:tid 956109] [client 20.255.75.24:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/admin.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFWQAAAXQ"]
[Thu Sep 17 15:07:16.452442 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWhBFTPRVSLOsRVhoFWwAAARQ"]
[Thu Sep 17 15:07:16.459192 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFXAAAAQ0"]
[Thu Sep 17 15:07:16.459282 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:35292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFXAAAAQ0"]
[Thu Sep 17 15:07:16.472388 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/notifications/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFXQAAATA"]
[Thu Sep 17 15:07:16.554051 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/notify/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFYAAAASg"]
[Thu Sep 17 15:07:16.630681 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sender/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFZgAAAWA"]
[Thu Sep 17 15:07:16.661653 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFYQAAAVY"]
[Thu Sep 17 15:07:16.718683 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/campaign/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFZwAAAWQ"]
[Thu Sep 17 15:07:16.740613 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWhBFTPRVSLOsRVhoFaAAAATI"]
[Thu Sep 17 15:07:16.746376 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFaQAAARk"]
[Thu Sep 17 15:07:16.746461 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFaQAAARk"]
[Thu Sep 17 15:07:16.789384 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/newsletter/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFagAAAW8"]
[Thu Sep 17 15:07:16.852123 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/ses/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFbgAAAVg"]
[Thu Sep 17 15:07:16.907902 2026] [security2:error] [pid 955873:tid 956058] [client 20.255.75.24:1040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/adminfuns.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFcgAAAUE"]
[Thu Sep 17 15:07:16.923730 2026] [core:error] [pid 955873:tid 956019] [client 74.7.175.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:16.923745 2026] [core:error] [pid 955873:tid 956019] [client 74.7.175.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:07:16.923871 2026] [security2:error] [pid 955873:tid 956019] [client 74.7.175.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.grieveonpurpose.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFcwAAARo"]
[Thu Sep 17 15:07:16.930872 2026] [security2:error] [pid 955873:tid 956105] [client 74.7.175.153:37866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.grieveonpurpose.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxWhBFTPRVSLOsRVhoFcAABcCw"]
[Thu Sep 17 15:07:16.935643 2026] [security2:error] [pid 955873:tid 956107] [client 115.244.164.14:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFdAAAAXI"]
[Thu Sep 17 15:07:16.935772 2026] [security2:error] [pid 955873:tid 956107] [client 115.244.164.14:51730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFdAAAAXI"]
[Thu Sep 17 15:07:16.938447 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFbwAAAWI"]
[Thu Sep 17 15:07:16.952145 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sendgrid/.env"] [unique_id "aqxWhBFTPRVSLOsRVhoFdQAAAW0"]
[Thu Sep 17 15:07:16.958210 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.221.252:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWhBFTPRVSLOsRVhoFdgAAAWU"]
[Thu Sep 17 15:07:17.037729 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:35322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFdwAAASE"]
[Thu Sep 17 15:07:17.037883 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:35322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFdwAAASE"]
[Thu Sep 17 15:07:17.057607 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/sparkpost/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFeQAAAYk"]
[Thu Sep 17 15:07:17.174413 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/postmark/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFgwAAAWM"]
[Thu Sep 17 15:07:17.200939 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFfwAAAWk"]
[Thu Sep 17 15:07:17.274134 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailgun/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFhQAAARE"]
[Thu Sep 17 15:07:17.274343 2026] [security2:error] [pid 955873:tid 956121] [client 187.20.37.14:57938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFgQABgDw"]
[Thu Sep 17 15:07:17.281710 2026] [security2:error] [pid 955873:tid 956110] [client 104.207.47.59:60361] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWhRFTPRVSLOsRVhoFhgAAAXU"]
[Thu Sep 17 15:07:17.298172 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.190.5:40924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhRFTPRVSLOsRVhoFiQAAAQo"]
[Thu Sep 17 15:07:17.314367 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFigAAATg"]
[Thu Sep 17 15:07:17.314432 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:35324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFigAAATg"]
[Thu Sep 17 15:07:17.349696 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mandrill/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFjQAAASs"]
[Thu Sep 17 15:07:17.368127 2026] [security2:error] [pid 955873:tid 956060] [client 154.190.208.131:42245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFjwAAAUM"]
[Thu Sep 17 15:07:17.368232 2026] [security2:error] [pid 955873:tid 956060] [client 154.190.208.131:42245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFjwAAAUM"]
[Thu Sep 17 15:07:17.395010 2026] [security2:error] [pid 955873:tid 956039] [client 20.255.75.24:1035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFkAAAAS4"]
[Thu Sep 17 15:07:17.468447 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mailjet/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFkwAAASU"]
[Thu Sep 17 15:07:17.547589 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFlAAAAT8"]
[Thu Sep 17 15:07:17.560244 2026] [security2:error] [pid 955873:tid 956048] [client 4.240.114.86:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFmAAAATc"], referer: binance.com
[Thu Sep 17 15:07:17.589500 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFmQAAAYc"]
[Thu Sep 17 15:07:17.589614 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:35334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFmQAAAYc"]
[Thu Sep 17 15:07:17.604624 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/brevo/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFmgAAATM"]
[Thu Sep 17 15:07:17.652419 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.221.252:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFngAAASI"]
[Thu Sep 17 15:07:17.676128 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/transactional/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFoQAAAUk"]
[Thu Sep 17 15:07:17.764265 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/bulk/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFowAAAVo"]
[Thu Sep 17 15:07:17.792305 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFogAAATo"]
[Thu Sep 17 15:07:17.833588 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/aws/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFpQAAAXQ"]
[Thu Sep 17 15:07:17.889327 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqAAAAUc"]
[Thu Sep 17 15:07:17.889436 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:35340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqAAAAUc"]
[Thu Sep 17 15:07:17.899523 2026] [security2:error] [pid 955873:tid 956057] [client 20.255.75.24:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/ae.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqQAAAUA"]
[Thu Sep 17 15:07:17.946046 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/azure/.env"] [unique_id "aqxWhRFTPRVSLOsRVhoFqwAAAXE"]
[Thu Sep 17 15:07:18.008826 2026] [security2:error] [pid 955873:tid 956020] [client 34.166.190.5:40930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhhFTPRVSLOsRVhoFrAAAARs"]
[Thu Sep 17 15:07:18.014982 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhRFTPRVSLOsRVhoFqgAAATA"]
[Thu Sep 17 15:07:18.079197 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/gcp/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFrgAAAXg"]
[Thu Sep 17 15:07:18.152031 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cloud/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFsQAAAVw"]
[Thu Sep 17 15:07:18.176130 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFuAAAAR0"]
[Thu Sep 17 15:07:18.176225 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:35350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFuAAAAR0"]
[Thu Sep 17 15:07:18.247567 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/infrastructure/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFuwAAAUE"]
[Thu Sep 17 15:07:18.272590 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFuQAAAVg"]
[Thu Sep 17 15:07:18.338260 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.221.252:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFvgAAATI"]
[Thu Sep 17 15:07:18.344378 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/docker/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFvwAAAV0"]
[Thu Sep 17 15:07:18.411059 2026] [security2:error] [pid 955873:tid 956080] [client 20.255.75.24:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/akcc.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFwAAAAVc"]
[Thu Sep 17 15:07:18.416916 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/k8s/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFwQAAAW0"]
[Thu Sep 17 15:07:18.454061 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFxAAAAYk"]
[Thu Sep 17 15:07:18.454205 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFxAAAAYk"]
[Thu Sep 17 15:07:18.512629 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/kubernetes/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFxgAAAVQ"]
[Thu Sep 17 15:07:18.577564 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhhFTPRVSLOsRVhoFxQAAASA"]
[Thu Sep 17 15:07:18.581313 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/terraform/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFyAAAAWg"]
[Thu Sep 17 15:07:18.713774 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/ansible/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoFzgAAAYY"]
[Thu Sep 17 15:07:18.724990 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.190.5:40938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhhFTPRVSLOsRVhoFzwAAAWM"]
[Thu Sep 17 15:07:18.742796 2026] [security2:error] [pid 955873:tid 956116] [client 51.161.128.55:34020] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ritamayblog.com"] [uri "/mail"] [unique_id "aqxWhhFTPRVSLOsRVhoF0QAAAXs"]
[Thu Sep 17 15:07:18.749077 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:35372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF0gAAASs"]
[Thu Sep 17 15:07:18.749162 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:35372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF0gAAASs"]
[Thu Sep 17 15:07:18.760265 2026] [security2:error] [pid 955873:tid 956099] [client 51.161.128.55:34026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ritamayblog.com"] [uri "/webmail"] [unique_id "aqxWhhFTPRVSLOsRVhoF1AAAAWo"]
[Thu Sep 17 15:07:18.760265 2026] [security2:error] [pid 955873:tid 956047] [client 51.161.128.55:34032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.ritamayblog.com"] [uri "/"] [unique_id "aqxWhhFTPRVSLOsRVhoF1QAAATY"]
[Thu Sep 17 15:07:18.817248 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/.git/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoF1gAAAU4"]
[Thu Sep 17 15:07:18.856926 2026] [security2:error] [pid 955873:tid 956030] [client 192.178.6.3:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF1wAAASU"]
[Thu Sep 17 15:07:18.920855 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/ci/.env"] [unique_id "aqxWhhFTPRVSLOsRVhoF2AAAAWw"]
[Thu Sep 17 15:07:18.931773 2026] [security2:error] [pid 955873:tid 956039] [client 20.255.75.24:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/bak.php"] [unique_id "aqxWhhFTPRVSLOsRVhoF2QAAAS4"]
[Thu Sep 17 15:07:19.010165 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/cd/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF2wAAAUY"]
[Thu Sep 17 15:07:19.036386 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.221.252:56706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF3AAAAT4"]
[Thu Sep 17 15:07:19.049040 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:35374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxWhxFTPRVSLOsRVhoF3QAAAVk"]
[Thu Sep 17 15:07:19.151685 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/jenkins/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF4AAAAUI"]
[Thu Sep 17 15:07:19.206948 2026] [authz_core:error] [pid 955873:tid 956046] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Poly1305/error_log
[Thu Sep 17 15:07:19.208153 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxWhxFTPRVSLOsRVhoF4gAAATU"]
[Thu Sep 17 15:07:19.238131 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF4QAAATk"]
[Thu Sep 17 15:07:19.240412 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/gitlab/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF5QAAAR8"]
[Thu Sep 17 15:07:19.266442 2026] [security2:error] [pid 955873:tid 956044] [client 51.161.128.55:34044] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.ritamayblog.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "aqxWhxFTPRVSLOsRVhoF5gAAATM"]
[Thu Sep 17 15:07:19.331554 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/github/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF5wAAAYg"]
[Thu Sep 17 15:07:19.356264 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:35374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWhxFTPRVSLOsRVhoF6gAAARQ"]
[Thu Sep 17 15:07:19.403675 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/actions/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF7wAAARA"]
[Thu Sep 17 15:07:19.423564 2026] [security2:error] [pid 955873:tid 956126] [client 20.255.75.24:1066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/cc.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF8QAAAYU"]
[Thu Sep 17 15:07:19.484230 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF7gAAASw"]
[Thu Sep 17 15:07:19.538110 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/circleci/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF9AAAAUE"]
[Thu Sep 17 15:07:19.625510 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/travis/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoF-AAAAXA"]
[Thu Sep 17 15:07:19.659980 2026] [security2:error] [pid 955873:tid 956091] [client 34.166.190.5:40946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/"] [unique_id "aqxWhxFTPRVSLOsRVhoF_AAAAWI"]
[Thu Sep 17 15:07:19.702054 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/buildkite/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoGAAAAARk"]
[Thu Sep 17 15:07:19.703695 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF8wAAAVw"]
[Thu Sep 17 15:07:19.703730 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF8wAAAVw"]
[Thu Sep 17 15:07:19.724023 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.221.252:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGAwAAAXg"]
[Thu Sep 17 15:07:19.773060 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoF_wAAATI"]
[Thu Sep 17 15:07:19.846861 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGBAAAAUg"]
[Thu Sep 17 15:07:19.846982 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:35374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGBAAAAUg"]
[Thu Sep 17 15:07:19.849324 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mysql/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoGBQAAAYI"]
[Thu Sep 17 15:07:19.904294 2026] [security2:error] [pid 955873:tid 956120] [client 20.255.75.24:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/chosen.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGCgAAAX8"]
[Thu Sep 17 15:07:19.954845 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/postgres/.env"] [unique_id "aqxWhxFTPRVSLOsRVhoGDQAAAQ4"]
[Thu Sep 17 15:07:19.988226 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWhxFTPRVSLOsRVhoGCwAAAV4"]
[Thu Sep 17 15:07:20.022078 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/mongodb/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGDgAAAYA"]
[Thu Sep 17 15:07:20.106002 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWiBFTPRVSLOsRVhoGFAAAAXM"]
[Thu Sep 17 15:07:20.121580 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGFQAAAUM"]
[Thu Sep 17 15:07:20.121688 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:37218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGFQAAAUM"]
[Thu Sep 17 15:07:20.165182 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/redis/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGFwAAASU"]
[Thu Sep 17 15:07:20.185903 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWiBFTPRVSLOsRVhoGGQAAATg"]
[Thu Sep 17 15:07:20.196535 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:53937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGGAAAAVU"]
[Thu Sep 17 15:07:20.196698 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:53937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGGAAAAVU"]
[Thu Sep 17 15:07:20.223066 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/elasticsearch/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGHAAAAXU"]
[Thu Sep 17 15:07:20.300957 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/rabbitmq/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGJgAAAUk"]
[Thu Sep 17 15:07:20.365803 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGJQAAAYc"]
[Thu Sep 17 15:07:20.376271 2026] [security2:error] [pid 955873:tid 956100] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/kafka/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGKAAAAWs"]
[Thu Sep 17 15:07:20.385989 2026] [security2:error] [pid 955873:tid 956010] [client 20.255.75.24:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/classwithtostring.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGKQAAARE"]
[Thu Sep 17 15:07:20.401665 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGLQAAAVs"]
[Thu Sep 17 15:07:20.401767 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:37222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGLQAAAVs"]
[Thu Sep 17 15:07:20.413395 2026] [security2:error] [pid 955873:tid 956056] [client 34.166.221.252:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWiBFTPRVSLOsRVhoGLgAAAT8"]
[Thu Sep 17 15:07:20.435972 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/queue/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGMAAAAUA"]
[Thu Sep 17 15:07:20.530459 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/worker/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGNQAAASg"]
[Thu Sep 17 15:07:20.582625 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGNAAAAXc"]
[Thu Sep 17 15:07:20.584991 2026] [security2:error] [pid 955873:tid 956041] [client 162.241.226.11:60196] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGNgAAATA"]
[Thu Sep 17 15:07:20.592701 2026] [security2:error] [pid 955873:tid 956099] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGFgABakI"]
[Thu Sep 17 15:07:20.601120 2026] [security2:error] [pid 955873:tid 956079] [client 4.240.114.86:52001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGOQAAAVY"], referer: binance.com
[Thu Sep 17 15:07:20.614977 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/job/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGPAAAAUQ"]
[Thu Sep 17 15:07:20.641445 2026] [security2:error] [pid 955873:tid 956109] [client 104.207.47.59:59971] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWiBFTPRVSLOsRVhoGPgAAAXQ"]
[Thu Sep 17 15:07:20.680543 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:37226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxWiBFTPRVSLOsRVhoGRQAAAWI"]
[Thu Sep 17 15:07:20.684557 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/test/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGRwAAAVw"]
[Thu Sep 17 15:07:20.780339 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGSAAAAV0"]
[Thu Sep 17 15:07:20.815945 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/qa/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGSwAAAYk"]
[Thu Sep 17 15:07:20.846305 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxWiBFTPRVSLOsRVhoGTAAAAUg"]
[Thu Sep 17 15:07:20.881285 2026] [security2:error] [pid 955873:tid 956038] [client 20.255.75.24:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/wp-signup.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGTwAAAS0"]
[Thu Sep 17 15:07:20.901206 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/preview/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGUgAAASA"]
[Thu Sep 17 15:07:20.987667 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:37226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxWiBFTPRVSLOsRVhoGVgAAAXo"]
[Thu Sep 17 15:07:20.987889 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/beta/.env"] [unique_id "aqxWiBFTPRVSLOsRVhoGVQAAATs"]
[Thu Sep 17 15:07:21.015433 2026] [security2:error] [pid 955873:tid 956103] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWiBFTPRVSLOsRVhoGPwABbkg"]
[Thu Sep 17 15:07:21.066164 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/uat/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGWQAAAVA"]
[Thu Sep 17 15:07:21.106921 2026] [security2:error] [pid 955873:tid 956074] [client 34.166.221.252:56730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWiRFTPRVSLOsRVhoGXAAAAVE"]
[Thu Sep 17 15:07:21.131493 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/stage/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGYwAAAWw"]
[Thu Sep 17 15:07:21.219885 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/development/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGagAAAQw"]
[Thu Sep 17 15:07:21.221155 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGYAAAAVU"]
[Thu Sep 17 15:07:21.342758 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGYQAAAXU"]
[Thu Sep 17 15:07:21.342789 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGYQAAAXU"]
[Thu Sep 17 15:07:21.350078 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/production/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGdAAAAVs"]
[Thu Sep 17 15:07:21.392341 2026] [security2:error] [pid 955873:tid 956027] [client 20.255.75.24:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/doc.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGdgAAASI"]
[Thu Sep 17 15:07:21.457100 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGdQAAASQ"]
[Thu Sep 17 15:07:21.459318 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:42828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.coblersen.com"] [uri "/config/app/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGfAAAASg"]
[Thu Sep 17 15:07:21.514484 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:37226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGfQAAAYU"]
[Thu Sep 17 15:07:21.514592 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:37226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGfQAAAYU"]
[Thu Sep 17 15:07:21.554154 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.224.217:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGfgAAARw"]
[Thu Sep 17 15:07:21.571544 2026] [security2:error] [pid 955873:tid 956099] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGfwAAAWo"]
[Thu Sep 17 15:07:21.679167 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGhgAAASo"]
[Thu Sep 17 15:07:21.740503 2026] [security2:error] [pid 955873:tid 956118] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGewAAAX0"]
[Thu Sep 17 15:07:21.752264 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGhwAAARk"]
[Thu Sep 17 15:07:21.784134 2026] [security2:error] [pid 955873:tid 956051] [client 34.166.221.252:56738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php~"] [unique_id "aqxWiRFTPRVSLOsRVhoGiAAAATo"]
[Thu Sep 17 15:07:21.797997 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:37242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGiwAAAQs"]
[Thu Sep 17 15:07:21.798088 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:37242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGiwAAAQs"]
[Thu Sep 17 15:07:21.812784 2026] [security2:error] [pid 955873:tid 956012] [client 169.58.198.243:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/themes/travel/issue.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGjAAAARM"], referer: www.google.com
[Thu Sep 17 15:07:21.824279 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGjgAAARI"]
[Thu Sep 17 15:07:21.846522 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.224.217:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/info.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGkgAAAXA"]
[Thu Sep 17 15:07:21.897527 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGlQAAAVI"]
[Thu Sep 17 15:07:21.905978 2026] [security2:error] [pid 955873:tid 956091] [client 20.255.75.24:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/edit.php"] [unique_id "aqxWiRFTPRVSLOsRVhoGlgAAAWI"]
[Thu Sep 17 15:07:21.941751 2026] [access_compat:error] [pid 955873:tid 956111] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/comments
[Thu Sep 17 15:07:21.960809 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWiRFTPRVSLOsRVhoGnQAAAUg"]
[Thu Sep 17 15:07:22.075075 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxWihFTPRVSLOsRVhoGoQAAATE"]
[Thu Sep 17 15:07:22.075175 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxWihFTPRVSLOsRVhoGoQAAATE"]
[Thu Sep 17 15:07:22.178887 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/php.php"] [unique_id "aqxWihFTPRVSLOsRVhoGpwAAAVQ"]
[Thu Sep 17 15:07:22.187566 2026] [security2:error] [pid 955873:tid 956038] [client 24.49.37.67:40409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWihFTPRVSLOsRVhoGngABLVI"]
[Thu Sep 17 15:07:22.324894 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWihFTPRVSLOsRVhoGqQAAAXM"]
[Thu Sep 17 15:07:22.362136 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:37264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxWihFTPRVSLOsRVhoGtQAAAWs"]
[Thu Sep 17 15:07:22.362232 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:37264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxWihFTPRVSLOsRVhoGtQAAAWs"]
[Thu Sep 17 15:07:22.394869 2026] [security2:error] [pid 955873:tid 956070] [client 20.255.75.24:1065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/worksec.php"] [unique_id "aqxWihFTPRVSLOsRVhoGtgAAAU0"]
[Thu Sep 17 15:07:22.447625 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGtwAAAR8"]
[Thu Sep 17 15:07:22.459980 2026] [security2:error] [pid 955873:tid 956047] [client 104.248.203.175:54068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxWihFTPRVSLOsRVhoGsgABNko"], referer: http://mail.darfieldearthship.com/old/
[Thu Sep 17 15:07:22.485397 2026] [security2:error] [pid 955873:tid 956116] [client 34.166.221.252:56752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/info.php.bak"] [unique_id "aqxWihFTPRVSLOsRVhoGuQAAAXs"]
[Thu Sep 17 15:07:22.525889 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGugAAASQ"]
[Thu Sep 17 15:07:22.607993 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGvwAAAS8"]
[Thu Sep 17 15:07:22.649061 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxWihFTPRVSLOsRVhoGwgAAAUw"]
[Thu Sep 17 15:07:22.649173 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:37266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxWihFTPRVSLOsRVhoGwgAAAUw"]
[Thu Sep 17 15:07:22.669068 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/i.php"] [unique_id "aqxWihFTPRVSLOsRVhoGxAAAASg"]
[Thu Sep 17 15:07:22.678267 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGxgAAASw"]
[Thu Sep 17 15:07:22.715371 2026] [security2:error] [pid 955873:tid 956099] [client 127.0.0.1:58452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxWihFTPRVSLOsRVhoGxQAAAWo"]
[Thu Sep 17 15:07:22.716254 2026] [security2:error] [pid 955873:tid 956126] [client 74.7.230.0:48616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.kuh.cvd.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWihFTPRVSLOsRVhoGwwABhT4"]
[Thu Sep 17 15:07:22.769220 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGyAAAAX0"]
[Thu Sep 17 15:07:22.853287 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWihFTPRVSLOsRVhoGzgAAAXA"]
[Thu Sep 17 15:07:22.877166 2026] [security2:error] [pid 955873:tid 956061] [client 20.255.75.24:1061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/ultra.php"] [unique_id "aqxWihFTPRVSLOsRVhoGzwAAAUQ"]
[Thu Sep 17 15:07:22.903566 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.224.217:58992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/pi.php"] [unique_id "aqxWihFTPRVSLOsRVhoG0AAAAVY"]
[Thu Sep 17 15:07:22.918262 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWihFTPRVSLOsRVhoG0QAAAV0"]
[Thu Sep 17 15:07:22.957720 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:37276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxWihFTPRVSLOsRVhoG0gAAAWI"]
[Thu Sep 17 15:07:22.957826 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:37276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxWihFTPRVSLOsRVhoG0gAAAWI"]
[Thu Sep 17 15:07:23.001780 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG0wAAAWE"]
[Thu Sep 17 15:07:23.106705 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG2gAAAUg"]
[Thu Sep 17 15:07:23.169729 2026] [security2:error] [pid 955873:tid 956075] [client 34.166.221.252:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWixFTPRVSLOsRVhoG4gAAAVI"]
[Thu Sep 17 15:07:23.169899 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG4AAAASE"]
[Thu Sep 17 15:07:23.177099 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/pinfo.php"] [unique_id "aqxWixFTPRVSLOsRVhoG4wAAAXY"]
[Thu Sep 17 15:07:23.247219 2026] [security2:error] [pid 955873:tid 956101] [client 122.14.226.11:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "revelinfear.com"] [uri "/robots.txt"] [unique_id "aqxWixFTPRVSLOsRVhoG5AAAAWw"]
[Thu Sep 17 15:07:23.260003 2026] [security2:error] [pid 955873:tid 956052] [client 104.248.203.175:54068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoG4QABO2k"], referer: http://mail.darfieldearthship.com/blog/
[Thu Sep 17 15:07:23.261620 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:37282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWixFTPRVSLOsRVhoG5QAAAW4"]
[Thu Sep 17 15:07:23.263591 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG5gAAASU"]
[Thu Sep 17 15:07:23.350798 2026] [security2:error] [pid 955873:tid 956038] [client 20.255.75.24:1051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/gecko.php"] [unique_id "aqxWixFTPRVSLOsRVhoG7AAAAS0"]
[Thu Sep 17 15:07:23.351726 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG6wAAARU"]
[Thu Sep 17 15:07:23.401536 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWixFTPRVSLOsRVhoG7gAAAVA"]
[Thu Sep 17 15:07:23.401685 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:55542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWixFTPRVSLOsRVhoG7gAAAVA"]
[Thu Sep 17 15:07:23.442437 2026] [authz_core:error] [pid 955873:tid 956100] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/error_log
[Thu Sep 17 15:07:23.467050 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWixFTPRVSLOsRVhoG8AAAAWs"]
[Thu Sep 17 15:07:23.474706 2026] [security2:error] [pid 955873:tid 956072] [client 157.90.156.63:63806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoG8gAAAU8"], referer: https://eris.media
[Thu Sep 17 15:07:23.503970 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG8wAAATg"]
[Thu Sep 17 15:07:23.520132 2026] [security2:error] [pid 955873:tid 956110] [client 4.240.114.86:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxWixFTPRVSLOsRVhoG9QAAAXU"], referer: binance.com
[Thu Sep 17 15:07:23.566980 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.224.217:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/test.php"] [unique_id "aqxWixFTPRVSLOsRVhoG-AAAAXg"]
[Thu Sep 17 15:07:23.573397 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG-gAAAVs"]
[Thu Sep 17 15:07:23.605241 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:37282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/wp-includes/sodium_compat/src/"] [unique_id "aqxWixFTPRVSLOsRVhoG_QAAATk"]
[Thu Sep 17 15:07:23.652007 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWixFTPRVSLOsRVhoG_wAAASQ"]
[Thu Sep 17 15:07:23.660032 2026] [security2:error] [pid 955873:tid 956044] [client 104.248.203.175:54068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoG-QABM2A"], referer: http://mail.darfieldearthship.com/backup/
[Thu Sep 17 15:07:23.742397 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHAQAAAV8"]
[Thu Sep 17 15:07:23.799701 2026] [security2:error] [pid 955873:tid 956126] [client 96.126.117.175:38218] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1452"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.bejackson.com"] [uri "/"] [unique_id "aqxWixFTPRVSLOsRVhoHBQAAAYU"]
[Thu Sep 17 15:07:23.818489 2026] [security2:error] [pid 955873:tid 956041] [client 24.49.37.67:57153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoHAAABMGU"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818001109&hideliu=1&hideminor=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:07:23.821183 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHBwAAAX0"]
[Thu Sep 17 15:07:23.823273 2026] [security2:error] [pid 955873:tid 956045] [client 20.255.75.24:1068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/goods.php"] [unique_id "aqxWixFTPRVSLOsRVhoHCAAAATQ"]
[Thu Sep 17 15:07:23.864160 2026] [security2:error] [pid 955873:tid 956057] [client 34.166.221.252:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWixFTPRVSLOsRVhoHCQAAAUA"]
[Thu Sep 17 15:07:23.920654 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHCgAAAT4"]
[Thu Sep 17 15:07:23.935601 2026] [security2:error] [pid 955873:tid 956015] [client 104.207.47.59:35261] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWixFTPRVSLOsRVhoHCwAAARY"]
[Thu Sep 17 15:07:23.951076 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoHAgAAAQ0"]
[Thu Sep 17 15:07:23.951101 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWixFTPRVSLOsRVhoHAgAAAQ0"]
[Thu Sep 17 15:07:23.994142 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWixFTPRVSLOsRVhoHDgAAARk"]
[Thu Sep 17 15:07:24.040346 2026] [security2:error] [pid 955873:tid 956112] [client 34.166.228.3:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHEQAAAXc"]
[Thu Sep 17 15:07:24.068188 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHEgAAATo"]
[Thu Sep 17 15:07:24.078813 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.224.217:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/p.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHEwAAAQs"]
[Thu Sep 17 15:07:24.088466 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:37282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHFgAAARM"]
[Thu Sep 17 15:07:24.088576 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:37282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHFgAAARM"]
[Thu Sep 17 15:07:24.136254 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHHAAAAV0"]
[Thu Sep 17 15:07:24.211899 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHIAAAARg"]
[Thu Sep 17 15:07:24.274801 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHJAAAAWw"]
[Thu Sep 17 15:07:24.316118 2026] [security2:error] [pid 955873:tid 956034] [client 20.255.75.24:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/man.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHJQAAASk"]
[Thu Sep 17 15:07:24.367862 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHKQAAAXM"]
[Thu Sep 17 15:07:24.373744 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.224.217:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/debug.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHKgAAAXY"]
[Thu Sep 17 15:07:24.380431 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHKwAAAVM"]
[Thu Sep 17 15:07:24.380536 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:37290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHKwAAAVM"]
[Thu Sep 17 15:07:24.452125 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHLQAAAS0"]
[Thu Sep 17 15:07:24.525460 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHLwAAAVQ"]
[Thu Sep 17 15:07:24.543730 2026] [security2:error] [pid 955873:tid 956078] [client 34.166.221.252:40236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHMAAAAVU"]
[Thu Sep 17 15:07:24.573618 2026] [security2:error] [pid 955873:tid 956120] [client 49.13.134.145:54624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxWjBFTPRVSLOsRVhoHMQAAAX8"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:07:24.616504 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHNgAAAU8"]
[Thu Sep 17 15:07:24.650748 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.224.217:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHNwAAAUo"]
[Thu Sep 17 15:07:24.678013 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:37298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxWjBFTPRVSLOsRVhoHOAAAAR8"]
[Thu Sep 17 15:07:24.687285 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHOQAAATY"]
[Thu Sep 17 15:07:24.741846 2026] [security2:error] [pid 955873:tid 956121] [client 34.166.228.3:33386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHOgAAAYA"]
[Thu Sep 17 15:07:24.770367 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHPAAAATk"]
[Thu Sep 17 15:07:24.840654 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHPgAAAQo"]
[Thu Sep 17 15:07:24.848417 2026] [authz_core:error] [pid 955873:tid 956092] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/ChaCha20/error_log
[Thu Sep 17 15:07:24.850983 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxWjBFTPRVSLOsRVhoHPQAAAWM"]
[Thu Sep 17 15:07:24.853172 2026] [security2:error] [pid 955873:tid 956070] [client 20.255.75.24:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/wp-settings.php"] [unique_id "aqxWjBFTPRVSLOsRVhoHPwAAAU0"]
[Thu Sep 17 15:07:24.917430 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWjBFTPRVSLOsRVhoHQAAAAYg"]
[Thu Sep 17 15:07:24.974675 2026] [fcgid:warn] [pid 955873:tid 956127] (70014)End of file found: [client 66.132.186.206:9022] mod_fcgid: can't get data from http client
[Thu Sep 17 15:07:24.995856 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:37298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWjBFTPRVSLOsRVhoHRgAAAX0"]
[Thu Sep 17 15:07:25.003553 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:46184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHSAAAARY"]
[Thu Sep 17 15:07:25.045575 2026] [security2:error] [pid 955873:tid 956130] [client 49.13.134.145:54626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxWjRFTPRVSLOsRVhoHSQAAAYk"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:07:25.056104 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/test/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHSgAAASg"]
[Thu Sep 17 15:07:25.244014 2026] [security2:error] [pid 955873:tid 956006] [client 34.166.221.252:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHUQAAAQ0"]
[Thu Sep 17 15:07:25.326417 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHVQAAAV0"]
[Thu Sep 17 15:07:25.361133 2026] [security2:error] [pid 955873:tid 956012] [client 20.255.75.24:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/k.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHVwAAARM"]
[Thu Sep 17 15:07:25.373220 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.224.217:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHWAAAATI"]
[Thu Sep 17 15:07:25.375524 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHTQAAATo"]
[Thu Sep 17 15:07:25.375544 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHTQAAATo"]
[Thu Sep 17 15:07:25.419744 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHWgAAARg"]
[Thu Sep 17 15:07:25.436922 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.228.3:33394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHWwAAAUQ"]
[Thu Sep 17 15:07:25.507316 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHXQAAAXo"]
[Thu Sep 17 15:07:25.522302 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHXwAAAW4"]
[Thu Sep 17 15:07:25.522405 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:37298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHXwAAAW4"]
[Thu Sep 17 15:07:25.584974 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHYgAAASY"]
[Thu Sep 17 15:07:25.655848 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHaAAAAXY"]
[Thu Sep 17 15:07:25.687913 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.224.217:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/old/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHagAAASc"]
[Thu Sep 17 15:07:25.733766 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHawAAATc"]
[Thu Sep 17 15:07:25.804906 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHbwAAAR8"]
[Thu Sep 17 15:07:25.805080 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHcAAAATY"]
[Thu Sep 17 15:07:25.805171 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:37314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHcAAAATY"]
[Thu Sep 17 15:07:25.864804 2026] [security2:error] [pid 955873:tid 956038] [client 20.255.75.24:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/autoload_classmap.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHdgAAAS0"]
[Thu Sep 17 15:07:25.931921 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHggAAAS4"]
[Thu Sep 17 15:07:25.936169 2026] [security2:error] [pid 955873:tid 956039] [client 45.169.98.18:58410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHggAAAS4"]
[Thu Sep 17 15:07:25.937120 2026] [security2:error] [pid 955873:tid 956122] [client 34.166.221.252:40256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWjRFTPRVSLOsRVhoHgwAAAYE"]
[Thu Sep 17 15:07:25.944544 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWjRFTPRVSLOsRVhoHhAAAAQo"]
[Thu Sep 17 15:07:26.017034 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHhwAAAV8"]
[Thu Sep 17 15:07:26.086386 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:37322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHigAAAWo"]
[Thu Sep 17 15:07:26.086502 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:37322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHigAAAWo"]
[Thu Sep 17 15:07:26.090850 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHjAAAAT0"]
[Thu Sep 17 15:07:26.093920 2026] [autoindex:error] [pid 955873:tid 956034] [client 4.240.114.86:54312] AH01276: Cannot serve directory /home2/ftlbllcn/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:07:26.100852 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.224.217:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHjQAAASQ"]
[Thu Sep 17 15:07:26.117731 2026] [security2:error] [pid 955873:tid 956028] [client 34.166.228.3:33396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHjgAAASM"]
[Thu Sep 17 15:07:26.158195 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHkQAAATA"]
[Thu Sep 17 15:07:26.280272 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHlwAAARA"]
[Thu Sep 17 15:07:26.363707 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHmAAAAWE"]
[Thu Sep 17 15:07:26.375783 2026] [security2:error] [pid 955873:tid 956114] [client 20.255.75.24:1075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/profile.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHmQAAAXk"]
[Thu Sep 17 15:07:26.386512 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:37332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxWjhFTPRVSLOsRVhoHmgAAARs"]
[Thu Sep 17 15:07:26.420495 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.224.217:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/public/phpinfo.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHnwAAAYk"]
[Thu Sep 17 15:07:26.461973 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHowAAATo"]
[Thu Sep 17 15:07:26.545225 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHpgAAAT8"]
[Thu Sep 17 15:07:26.546903 2026] [authz_core:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Curve25519/error_log
[Thu Sep 17 15:07:26.556305 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxWjhFTPRVSLOsRVhoHpQAAARo"]
[Thu Sep 17 15:07:26.663945 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHqQAAAQ8"]
[Thu Sep 17 15:07:26.669870 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.221.252:40260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHqwAAAUE"]
[Thu Sep 17 15:07:26.703478 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:37332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWjhFTPRVSLOsRVhoHrQAAASo"]
[Thu Sep 17 15:07:26.742378 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHrgAAASY"]
[Thu Sep 17 15:07:26.745354 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.224.217:59088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/php-info.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHsAAAAUI"]
[Thu Sep 17 15:07:26.812872 2026] [security2:error] [pid 955873:tid 956026] [client 34.166.228.3:33406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHsgAAASE"]
[Thu Sep 17 15:07:26.820560 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHswAAASc"]
[Thu Sep 17 15:07:26.907348 2026] [security2:error] [pid 955873:tid 956080] [client 20.255.75.24:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/server.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHuQAAAVc"]
[Thu Sep 17 15:07:26.915753 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWjhFTPRVSLOsRVhoHugAAAVQ"]
[Thu Sep 17 15:07:27.044036 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHvQAAASA"]
[Thu Sep 17 15:07:27.048672 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpversion.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHvgAAAUU"]
[Thu Sep 17 15:07:27.068523 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHuAAAATc"]
[Thu Sep 17 15:07:27.068553 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjhFTPRVSLOsRVhoHuAAAATc"]
[Thu Sep 17 15:07:27.135873 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHxgAAAVs"]
[Thu Sep 17 15:07:27.206615 2026] [security2:error] [pid 955873:tid 956060] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHyQAAAUM"]
[Thu Sep 17 15:07:27.215450 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:37332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHygAAAXg"]
[Thu Sep 17 15:07:27.215600 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:37332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHygAAAXg"]
[Thu Sep 17 15:07:27.294118 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoHzAAAATM"]
[Thu Sep 17 15:07:27.371510 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.221.252:40268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoHzwAAATk"]
[Thu Sep 17 15:07:27.411230 2026] [security2:error] [pid 955873:tid 956073] [client 20.255.75.24:1031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/shell.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH0AAAAVA"]
[Thu Sep 17 15:07:27.430021 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.224.217:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/_phpinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH0QAAAYg"]
[Thu Sep 17 15:07:27.431471 2026] [security2:error] [pid 955873:tid 956027] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH0gAAASI"]
[Thu Sep 17 15:07:27.487750 2026] [security2:error] [pid 955873:tid 956087] [client 115.244.164.14:52371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH1AAAAV4"]
[Thu Sep 17 15:07:27.487889 2026] [security2:error] [pid 955873:tid 956087] [client 115.244.164.14:52371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH1AAAAV4"]
[Thu Sep 17 15:07:27.498906 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.228.3:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH1gAAAQo"]
[Thu Sep 17 15:07:27.502006 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH1wAAASM"]
[Thu Sep 17 15:07:27.502386 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:37338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxWjxFTPRVSLOsRVhoH2AAAASw"]
[Thu Sep 17 15:07:27.588918 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH3AAAAUA"]
[Thu Sep 17 15:07:27.669974 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxWjxFTPRVSLOsRVhoH3wAAAYc"]
[Thu Sep 17 15:07:27.714996 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH4gAAAXc"]
[Thu Sep 17 15:07:27.768833 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.224.217:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/old_phpinfo.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH5AAAAWE"]
[Thu Sep 17 15:07:27.805157 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH5QAAATI"]
[Thu Sep 17 15:07:27.819457 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:37338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxWjxFTPRVSLOsRVhoH5gAAATo"]
[Thu Sep 17 15:07:27.917955 2026] [security2:error] [pid 955873:tid 956012] [client 20.255.75.24:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/t.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH6AAAARM"]
[Thu Sep 17 15:07:27.925218 2026] [security2:error] [pid 955873:tid 956056] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWjxFTPRVSLOsRVhoH6QAAAT8"]
[Thu Sep 17 15:07:28.024347 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH7wAAAVw"]
[Thu Sep 17 15:07:28.056603 2026] [security2:error] [pid 955873:tid 956007] [client 34.166.221.252:40280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8AAAAQ4"]
[Thu Sep 17 15:07:28.073536 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:41493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8QAAAXA"]
[Thu Sep 17 15:07:28.073724 2026] [security2:error] [pid 955873:tid 956105] [client 154.190.208.131:41493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8QAAAXA"]
[Thu Sep 17 15:07:28.085625 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.224.217:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/server-info.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH8wAAAYQ"]
[Thu Sep 17 15:07:28.124356 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH9QAAASc"]
[Thu Sep 17 15:07:28.179836 2026] [security2:error] [pid 955873:tid 956115] [client 4.240.114.86:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH9wAAAXo"], referer: binance.com
[Thu Sep 17 15:07:28.183205 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH-AAAAWU"]
[Thu Sep 17 15:07:28.194299 2026] [security2:error] [pid 955873:tid 956035] [client 34.166.228.3:33420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH-gAAASo"]
[Thu Sep 17 15:07:28.209923 2026] [security2:error] [pid 955873:tid 955908] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoH_QABfyI"]
[Thu Sep 17 15:07:28.216490 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH6gAAAUE"]
[Thu Sep 17 15:07:28.216521 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWjxFTPRVSLOsRVhoH6gAAAUE"]
[Thu Sep 17 15:07:28.259025 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIAwAAAVQ"]
[Thu Sep 17 15:07:28.311014 2026] [security2:error] [pid 955873:tid 956072] [client 74.7.175.182:56044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hz2b27bgxqptl.dov.wxt.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxWkBFTPRVSLOsRVhoIBgAAAU8"]
[Thu Sep 17 15:07:28.311069 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH-wABfxM"]
[Thu Sep 17 15:07:28.315019 2026] [security2:error] [pid 955873:tid 955907] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.bak"] [unique_id "aqxWkBFTPRVSLOsRVhoICwABfyE"]
[Thu Sep 17 15:07:28.316705 2026] [security2:error] [pid 955873:tid 955915] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.backup"] [unique_id "aqxWkBFTPRVSLOsRVhoIBwABfyk"]
[Thu Sep 17 15:07:28.320574 2026] [security2:error] [pid 955873:tid 955915] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.old"] [unique_id "aqxWkBFTPRVSLOsRVhoIDwABfyk"]
[Thu Sep 17 15:07:28.338830 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIAAABfwY"]
[Thu Sep 17 15:07:28.339547 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIAQABfyI"]
[Thu Sep 17 15:07:28.340305 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH_wABfw4"]
[Thu Sep 17 15:07:28.340533 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH_AABfxg"]
[Thu Sep 17 15:07:28.350155 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoH_gABfyA"]
[Thu Sep 17 15:07:28.352325 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIEAAAAVs"]
[Thu Sep 17 15:07:28.358485 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEQAAAUg"]
[Thu Sep 17 15:07:28.358692 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:37338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEQAAAUg"]
[Thu Sep 17 15:07:28.368498 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/server-status.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEgAAATc"]
[Thu Sep 17 15:07:28.399217 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIDAABfx0"]
[Thu Sep 17 15:07:28.422057 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIFAAAAVU"]
[Thu Sep 17 15:07:28.426174 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoICQABfyU"]
[Thu Sep 17 15:07:28.427041 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIDgABfyE"]
[Thu Sep 17 15:07:28.434039 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIDQABfyo"]
[Thu Sep 17 15:07:28.435038 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoICgABfx8"]
[Thu Sep 17 15:07:28.438194 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoICAABfxM"]
[Thu Sep 17 15:07:28.438257 2026] [security2:error] [pid 955873:tid 956063] [client 20.255.75.24:1352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hopmanchaissconsulting.com"] [uri "/hello.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIFQAAAUY"]
[Thu Sep 17 15:07:28.479002 2026] [security2:error] [pid 955873:tid 956120] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIEwABfzA"]
[Thu Sep 17 15:07:28.501217 2026] [security2:error] [pid 955873:tid 955923] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env~"] [unique_id "aqxWkBFTPRVSLOsRVhoIGgABMzE"]
[Thu Sep 17 15:07:28.506262 2026] [security2:error] [pid 955873:tid 955900] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/.env.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIGQABMxo"]
[Thu Sep 17 15:07:28.520936 2026] [security2:error] [pid 955873:tid 955919] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.swp"] [unique_id "aqxWkBFTPRVSLOsRVhoIGwABMy0"]
[Thu Sep 17 15:07:28.527461 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIHQAAAXI"]
[Thu Sep 17 15:07:28.579246 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIFwABMys"]
[Thu Sep 17 15:07:28.582914 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIGAABMyQ"]
[Thu Sep 17 15:07:28.600391 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIHAABMzQ"]
[Thu Sep 17 15:07:28.607782 2026] [security2:error] [pid 955873:tid 955927] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/api/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIJAABMzU"]
[Thu Sep 17 15:07:28.608250 2026] [security2:error] [pid 955873:tid 955934] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/app/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIJgABMzw"]
[Thu Sep 17 15:07:28.630585 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIKQAAATk"]
[Thu Sep 17 15:07:28.642544 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:37340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIKgAAARQ"]
[Thu Sep 17 15:07:28.642702 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:37340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIKgAAARQ"]
[Thu Sep 17 15:07:28.653300 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIHwABMzI"]
[Thu Sep 17 15:07:28.654324 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIHgABMy4"]
[Thu Sep 17 15:07:28.654472 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIIAABMzc"]
[Thu Sep 17 15:07:28.662025 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIIgABMzg"]
[Thu Sep 17 15:07:28.666159 2026] [security2:error] [pid 955873:tid 956109] [client 169.58.198.243:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lukercpa.com"] [uri "/wp-content/themes/jaida/lang.php"] [unique_id "aqxWkBFTPRVSLOsRVhoILgAAAXQ"], referer: www.google.com
[Thu Sep 17 15:07:28.670595 2026] [security2:error] [pid 955873:tid 955932] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/backend/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoILwABMzo"]
[Thu Sep 17 15:07:28.683035 2026] [security2:error] [pid 955873:tid 955945] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/server/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIMgABM0c"]
[Thu Sep 17 15:07:28.688455 2026] [security2:error] [pid 955873:tid 955912] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/config/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIMwABMyY"]
[Thu Sep 17 15:07:28.703191 2026] [security2:error] [pid 955873:tid 955947] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/src/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoINAABM0k"]
[Thu Sep 17 15:07:28.703510 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIKAABMzY"]
[Thu Sep 17 15:07:28.708776 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoINQAAAT0"]
[Thu Sep 17 15:07:28.751636 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIMAABM0U"]
[Thu Sep 17 15:07:28.754090 2026] [security2:error] [pid 955873:tid 956044] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIMQABMzM"]
[Thu Sep 17 15:07:28.760591 2026] [security2:error] [pid 955873:tid 955939] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/web/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoINwABhkE"]
[Thu Sep 17 15:07:28.763318 2026] [security2:error] [pid 955873:tid 955938] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/client/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIOAABCkA"]
[Thu Sep 17 15:07:28.772909 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.221.252:40286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIOQAAAXw"]
[Thu Sep 17 15:07:28.781987 2026] [security2:error] [pid 955873:tid 955937] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/frontend/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIOgABJD8"]
[Thu Sep 17 15:07:28.789809 2026] [security2:error] [pid 955873:tid 955933] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/var/www/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIOwABIzs"]
[Thu Sep 17 15:07:28.789847 2026] [security2:error] [pid 955873:tid 955944] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/public/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIPAABI0Y"]
[Thu Sep 17 15:07:28.839147 2026] [security2:error] [pid 955873:tid 955904] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/var/www/html/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQQABMB4"]
[Thu Sep 17 15:07:28.839163 2026] [security2:error] [pid 955873:tid 955889] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/application/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIPwABMA8"]
[Thu Sep 17 15:07:28.839166 2026] [security2:error] [pid 955873:tid 955940] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/laravel/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQAABMEI"]
[Thu Sep 17 15:07:28.845763 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQwAAAVk"]
[Thu Sep 17 15:07:28.845843 2026] [security2:error] [pid 955873:tid 955879] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/apps/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIQgABNAU"]
[Thu Sep 17 15:07:28.850644 2026] [security2:error] [pid 955873:tid 955949] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/back/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRAABPks"]
[Thu Sep 17 15:07:28.865151 2026] [security2:error] [pid 955873:tid 955931] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/backup/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRQABGTk"]
[Thu Sep 17 15:07:28.870198 2026] [security2:error] [pid 955873:tid 955941] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/cms/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRgABYEM"]
[Thu Sep 17 15:07:28.885561 2026] [security2:error] [pid 955873:tid 955913] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/prod/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIRwABHCc"]
[Thu Sep 17 15:07:28.885591 2026] [security2:error] [pid 955873:tid 955946] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/dev/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoISAABHEg"]
[Thu Sep 17 15:07:28.933442 2026] [security2:error] [pid 955873:tid 955963] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/production/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoITQABWFk"]
[Thu Sep 17 15:07:28.934143 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoITgAAAYc"]
[Thu Sep 17 15:07:28.936143 2026] [security2:error] [pid 955873:tid 955942] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/staging/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoITwABWEQ"]
[Thu Sep 17 15:07:28.942331 2026] [security2:error] [pid 955873:tid 955959] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/test/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIUAABd1U"]
[Thu Sep 17 15:07:28.945314 2026] [security2:error] [pid 955873:tid 955956] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/old/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIUQABeVI"]
[Thu Sep 17 15:07:28.963851 2026] [security2:error] [pid 955873:tid 955955] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/new/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIVAABO1E"]
[Thu Sep 17 15:07:28.970281 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:37348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIVwAAARs"]
[Thu Sep 17 15:07:28.970388 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:37348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxWkBFTPRVSLOsRVhoIVwAAARs"]
[Thu Sep 17 15:07:28.971365 2026] [security2:error] [pid 955873:tid 955936] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/api-backend/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIVQABRz4"]
[Thu Sep 17 15:07:28.971396 2026] [security2:error] [pid 955873:tid 955948] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/node-api/.env"] [unique_id "aqxWkBFTPRVSLOsRVhoIVgABR0o"]
[Thu Sep 17 15:07:29.022367 2026] [security2:error] [pid 955873:tid 955950] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/admin-app/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIWgABZ0w"]
[Thu Sep 17 15:07:29.022375 2026] [security2:error] [pid 955873:tid 955960] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/public_html/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIWwABZ1Y"]
[Thu Sep 17 15:07:29.026622 2026] [security2:error] [pid 955873:tid 955979] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/current/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXQABZ2k"]
[Thu Sep 17 15:07:29.027363 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXgAAAQs"]
[Thu Sep 17 15:07:29.030633 2026] [security2:error] [pid 955873:tid 955964] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/server/api/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXwABZ1o"]
[Thu Sep 17 15:07:29.047706 2026] [security2:error] [pid 955873:tid 955954] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/server/backend/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIYQABZ1A"]
[Thu Sep 17 15:07:29.051108 2026] [security2:error] [pid 955873:tid 955970] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.docker/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIYgABZ2A"]
[Thu Sep 17 15:07:29.067677 2026] [security2:error] [pid 955873:tid 955975] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/aws/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIYwABZ2U"]
[Thu Sep 17 15:07:29.067762 2026] [security2:error] [pid 955873:tid 955961] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIZAABZ1c"]
[Thu Sep 17 15:07:29.091355 2026] [security2:error] [pid 955873:tid 955968] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/administrator/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIXAABZ14"]
[Thu Sep 17 15:07:29.115190 2026] [security2:error] [pid 955873:tid 955966] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.aws/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIZwABHlw"]
[Thu Sep 17 15:07:29.118171 2026] [security2:error] [pid 955873:tid 955973] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/stripe/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIaAABGGM"]
[Thu Sep 17 15:07:29.141216 2026] [security2:error] [pid 955873:tid 956061] [client 34.166.228.3:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIawAAAUQ"]
[Thu Sep 17 15:07:29.145961 2026] [security2:error] [pid 955873:tid 955884] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/v1/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbAABgwo"]
[Thu Sep 17 15:07:29.154584 2026] [security2:error] [pid 955873:tid 955995] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/v3/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbQABg3k"]
[Thu Sep 17 15:07:29.154640 2026] [security2:error] [pid 955873:tid 955991] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/v2/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbgABg3U"]
[Thu Sep 17 15:07:29.155494 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIbwAAARo"]
[Thu Sep 17 15:07:29.207101 2026] [security2:error] [pid 955873:tid 955972] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/media/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIdwABg2I"]
[Thu Sep 17 15:07:29.214565 2026] [security2:error] [pid 955873:tid 956124] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIaQABg3E"]
[Thu Sep 17 15:07:29.214973 2026] [security2:error] [pid 955873:tid 956124] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIagABg2c"]
[Thu Sep 17 15:07:29.238051 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIgAAAAQw"]
[Thu Sep 17 15:07:29.284464 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIgQAAATE"]
[Thu Sep 17 15:07:29.284608 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:37358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIgQAAATE"]
[Thu Sep 17 15:07:29.300882 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWkRFTPRVSLOsRVhoIggAAASA"]
[Thu Sep 17 15:07:29.337593 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIhAAAATg"]
[Thu Sep 17 15:07:29.407430 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIhgAAAXM"]
[Thu Sep 17 15:07:29.432328 2026] [security2:error] [pid 955873:tid 955969] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.git/config.bak"] [unique_id "aqxWkRFTPRVSLOsRVhoIkAABSF8"]
[Thu Sep 17 15:07:29.452707 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.221.252:40302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWkRFTPRVSLOsRVhoImQAAAU4"]
[Thu Sep 17 15:07:29.501112 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoInQAAATk"]
[Thu Sep 17 15:07:29.573754 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:37362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIogAAASk"]
[Thu Sep 17 15:07:29.573859 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:37362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIogAAASk"]
[Thu Sep 17 15:07:29.593337 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIpAAAAV4"]
[Thu Sep 17 15:07:29.615570 2026] [security2:error] [pid 955873:tid 955935] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.aws/credentials.bak"] [unique_id "aqxWkRFTPRVSLOsRVhoIqwABiD0"]
[Thu Sep 17 15:07:29.618096 2026] [security2:error] [pid 955873:tid 955874] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/id_rsa"] [unique_id "aqxWkRFTPRVSLOsRVhoIsAABiAA"]
[Thu Sep 17 15:07:29.618631 2026] [security2:error] [pid 955873:tid 955875] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.ssh/id_rsa"] [unique_id "aqxWkRFTPRVSLOsRVhoIrwABiAE"]
[Thu Sep 17 15:07:29.627282 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.224.217:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIuQAAAV8"]
[Thu Sep 17 15:07:29.674102 2026] [security2:error] [pid 955873:tid 956113] [client 57.141.14.33:45090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoImAABeHM"]
[Thu Sep 17 15:07:29.678750 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIvwAAARA"]
[Thu Sep 17 15:07:29.706133 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoItgABiH0"]
[Thu Sep 17 15:07:29.707952 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoItAABiBQ"]
[Thu Sep 17 15:07:29.708082 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIqgABiAg"]
[Thu Sep 17 15:07:29.708164 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIqQABiAc"]
[Thu Sep 17 15:07:29.708303 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIrQABiA0"]
[Thu Sep 17 15:07:29.711810 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIrAABiBE"]
[Thu Sep 17 15:07:29.720076 2026] [security2:error] [pid 955873:tid 956129] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIrgABiBY"]
[Thu Sep 17 15:07:29.776125 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIwQAAARI"]
[Thu Sep 17 15:07:29.826409 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.228.3:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIywAAAXw"]
[Thu Sep 17 15:07:29.875832 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzAAAAV0"]
[Thu Sep 17 15:07:29.875964 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:43954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzAAAAV0"]
[Thu Sep 17 15:07:29.879601 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoIzQAAATs"]
[Thu Sep 17 15:07:29.886726 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIyQABL3c"]
[Thu Sep 17 15:07:29.886833 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIxwABL2E"]
[Thu Sep 17 15:07:29.886933 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIygABLyk"]
[Thu Sep 17 15:07:29.887008 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIxQABLxU"]
[Thu Sep 17 15:07:29.889118 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIxgABLyM"]
[Thu Sep 17 15:07:29.952169 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWkRFTPRVSLOsRVhoI1QAAAYk"]
[Thu Sep 17 15:07:29.968312 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI0gABLxk"]
[Thu Sep 17 15:07:29.968637 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI0wABLyA"]
[Thu Sep 17 15:07:29.969139 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzwABLw4"]
[Thu Sep 17 15:07:29.969629 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoIzgABLwY"]
[Thu Sep 17 15:07:29.971538 2026] [security2:error] [pid 955873:tid 956040] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI0QABLxg"]
[Thu Sep 17 15:07:30.012955 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI2wAAAVg"]
[Thu Sep 17 15:07:30.039117 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoI3QAAAR4"]
[Thu Sep 17 15:07:30.064539 2026] [security2:error] [pid 955873:tid 956043] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI2QABMio"]
[Thu Sep 17 15:07:30.064685 2026] [security2:error] [pid 955873:tid 956043] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkRFTPRVSLOsRVhoI2AABMiE"]
[Thu Sep 17 15:07:30.066679 2026] [security2:error] [pid 955873:tid 955917] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI4gABaSs"]
[Thu Sep 17 15:07:30.113098 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoI6gAAARo"]
[Thu Sep 17 15:07:30.141081 2026] [security2:error] [pid 955873:tid 956064] [client 34.166.221.252:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI9QAAAUc"]
[Thu Sep 17 15:07:30.150915 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI4wABaTQ"]
[Thu Sep 17 15:07:30.153312 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI5QABaTU"]
[Thu Sep 17 15:07:30.159010 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-wAAAT8"]
[Thu Sep 17 15:07:30.159159 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:43968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-wAAAT8"]
[Thu Sep 17 15:07:30.170529 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI5wABaTI"]
[Thu Sep 17 15:07:30.208892 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJAwAAAR0"]
[Thu Sep 17 15:07:30.245013 2026] [security2:error] [pid 955873:tid 955933] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/aws.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJBQABaTs"]
[Thu Sep 17 15:07:30.246693 2026] [security2:error] [pid 955873:tid 955904] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/stripe.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJBgABaR4"]
[Thu Sep 17 15:07:30.249117 2026] [security2:error] [pid 955873:tid 955940] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/mail.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJCAABaUI"]
[Thu Sep 17 15:07:30.250788 2026] [security2:error] [pid 955873:tid 955879] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/config.inc.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJCQABaQU"]
[Thu Sep 17 15:07:30.260971 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-AABaUU"]
[Thu Sep 17 15:07:30.263372 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI9gABaTY"]
[Thu Sep 17 15:07:30.267190 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-QABaTM"]
[Thu Sep 17 15:07:30.268216 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI9wABaUk"]
[Thu Sep 17 15:07:30.272865 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI-gABaUE"]
[Thu Sep 17 15:07:30.287918 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoI_gABaUA"]
[Thu Sep 17 15:07:30.291870 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJDAAAATY"]
[Thu Sep 17 15:07:30.302496 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.224.217:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJDQAAASA"]
[Thu Sep 17 15:07:30.326232 2026] [security2:error] [pid 955873:tid 956098] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJBwABaQ8"]
[Thu Sep 17 15:07:30.361530 2026] [security2:error] [pid 955873:tid 955931] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/config/nexmo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJEgABVTk"]
[Thu Sep 17 15:07:30.391775 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJFAAAATU"]
[Thu Sep 17 15:07:30.425739 2026] [security2:error] [pid 955873:tid 955963] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJGAABVVk"]
[Thu Sep 17 15:07:30.426510 2026] [security2:error] [pid 955873:tid 955942] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php.bak"] [unique_id "aqxWkhFTPRVSLOsRVhoJGQABVUQ"]
[Thu Sep 17 15:07:30.428806 2026] [security2:error] [pid 955873:tid 955959] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php.old"] [unique_id "aqxWkhFTPRVSLOsRVhoJGwABVVU"]
[Thu Sep 17 15:07:30.428806 2026] [security2:error] [pid 955873:tid 955956] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.php.new"] [unique_id "aqxWkhFTPRVSLOsRVhoJGgABVVI"]
[Thu Sep 17 15:07:30.431047 2026] [security2:error] [pid 955873:tid 955962] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/.wp-config.php.swp"] [unique_id "aqxWkhFTPRVSLOsRVhoJHAABVVg"]
[Thu Sep 17 15:07:30.436564 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJEQABVSc"]
[Thu Sep 17 15:07:30.438059 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJEAABVSw"]
[Thu Sep 17 15:07:30.441738 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJDwABVUM"]
[Thu Sep 17 15:07:30.447292 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHwAAAUY"]
[Thu Sep 17 15:07:30.447385 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:43972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHwAAAUY"]
[Thu Sep 17 15:07:30.447907 2026] [security2:error] [pid 955873:tid 955948] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/wp-content/mysql.sql"] [unique_id "aqxWkhFTPRVSLOsRVhoJIAABVUo"]
[Thu Sep 17 15:07:30.475363 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJJQAAAS0"]
[Thu Sep 17 15:07:30.515234 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHQABVVE"]
[Thu Sep 17 15:07:30.520925 2026] [security2:error] [pid 955873:tid 956078] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJHgABVT4"]
[Thu Sep 17 15:07:30.533428 2026] [security2:error] [pid 955873:tid 956106] [client 34.166.228.3:33442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJJwAAAXE"]
[Thu Sep 17 15:07:30.613241 2026] [security2:error] [pid 955873:tid 955966] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/terraform.tfstate.backup"] [unique_id "aqxWkhFTPRVSLOsRVhoJMQABhlw"]
[Thu Sep 17 15:07:30.622137 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJOAAAAQo"]
[Thu Sep 17 15:07:30.626768 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.224.217:59186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJOQAAAXQ"]
[Thu Sep 17 15:07:30.698842 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJNAABhnk"]
[Thu Sep 17 15:07:30.699064 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJMgABhmM"]
[Thu Sep 17 15:07:30.699905 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJQwAAASw"]
[Thu Sep 17 15:07:30.700447 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJNgABhmI"]
[Thu Sep 17 15:07:30.704039 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJNwABhnI"]
[Thu Sep 17 15:07:30.705497 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJMAABhl4"]
[Thu Sep 17 15:07:30.714241 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJOgABhm8"]
[Thu Sep 17 15:07:30.738548 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:43986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJRgAAAUI"]
[Thu Sep 17 15:07:30.738700 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:43986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJRgAAAUI"]
[Thu Sep 17 15:07:30.766047 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJPQABhnE"]
[Thu Sep 17 15:07:30.771948 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJRwAAARE"]
[Thu Sep 17 15:07:30.774379 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJQgABhnY"]
[Thu Sep 17 15:07:30.780218 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJQAABhnA"]
[Thu Sep 17 15:07:30.783588 2026] [security2:error] [pid 955873:tid 956127] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJRAABhmY"]
[Thu Sep 17 15:07:30.851013 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.221.252:40332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJTAAAAUo"]
[Thu Sep 17 15:07:30.862835 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJSQABEHg"]
[Thu Sep 17 15:07:30.862933 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJSAABEGg"]
[Thu Sep 17 15:07:30.888361 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJVAAAAT4"]
[Thu Sep 17 15:07:30.930464 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJTQABEG4"]
[Thu Sep 17 15:07:30.930545 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJTgABEGQ"]
[Thu Sep 17 15:07:30.964835 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWkhFTPRVSLOsRVhoJXgAAARI"]
[Thu Sep 17 15:07:30.971775 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJUwABEF8"]
[Thu Sep 17 15:07:30.993504 2026] [security2:error] [pid 955873:tid 956018] [client 34.23.224.217:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJYAAAARk"]
[Thu Sep 17 15:07:31.022296 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJYQAAAVk"]
[Thu Sep 17 15:07:31.022415 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:43998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJYQAAAVk"]
[Thu Sep 17 15:07:31.023553 2026] [security2:error] [pid 955873:tid 956009] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkhFTPRVSLOsRVhoJWgABEGw"]
[Thu Sep 17 15:07:31.041254 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJYgAAAXs"]
[Thu Sep 17 15:07:31.067236 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:54669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJagAAATA"]
[Thu Sep 17 15:07:31.067356 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:54669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJagAAATA"]
[Thu Sep 17 15:07:31.132054 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJaQABOxw"]
[Thu Sep 17 15:07:31.133506 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJZgABOwQ"]
[Thu Sep 17 15:07:31.135026 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJZwABOxs"]
[Thu Sep 17 15:07:31.147471 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJbQABOwE"]
[Thu Sep 17 15:07:31.157776 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJdQAAAQs"]
[Thu Sep 17 15:07:31.218419 2026] [security2:error] [pid 955873:tid 956117] [client 34.166.228.3:33454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJegAAAXw"]
[Thu Sep 17 15:07:31.224639 2026] [security2:error] [pid 955873:tid 955914] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJfAABOyg"]
[Thu Sep 17 15:07:31.240042 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJfQAAAYA"]
[Thu Sep 17 15:07:31.267161 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJbgABO3M"]
[Thu Sep 17 15:07:31.291788 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJbwABOxQ"]
[Thu Sep 17 15:07:31.293976 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.224.217:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxWkxFTPRVSLOsRVhoJfwAAARM"]
[Thu Sep 17 15:07:31.295573 2026] [security2:error] [pid 955873:tid 955997] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/info.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJgAABO3s"]
[Thu Sep 17 15:07:31.309731 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJcQABOwg"]
[Thu Sep 17 15:07:31.312345 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJcgABOwc"]
[Thu Sep 17 15:07:31.313522 2026] [security2:error] [pid 955873:tid 955971] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/php_info.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJgQABO2E"]
[Thu Sep 17 15:07:31.313546 2026] [security2:error] [pid 955873:tid 955993] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/infos.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJggABO3c"]
[Thu Sep 17 15:07:31.314124 2026] [security2:error] [pid 955873:tid 955915] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/php.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJgwABOyk"]
[Thu Sep 17 15:07:31.319181 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJdAABOxE"]
[Thu Sep 17 15:07:31.320656 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhAAAAUk"]
[Thu Sep 17 15:07:31.320764 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhAAAAUk"]
[Thu Sep 17 15:07:31.328254 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJdgABOxY"]
[Thu Sep 17 15:07:31.329418 2026] [security2:error] [pid 955873:tid 955909] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/php-info.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhgABOyM"]
[Thu Sep 17 15:07:31.329447 2026] [security2:error] [pid 955873:tid 955908] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/infophp.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhwABOyI"]
[Thu Sep 17 15:07:31.332462 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJewABOwI"]
[Thu Sep 17 15:07:31.332914 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJeQABOxA"]
[Thu Sep 17 15:07:31.336096 2026] [security2:error] [pid 955873:tid 956052] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJfgABOwM"]
[Thu Sep 17 15:07:31.343848 2026] [security2:error] [pid 955873:tid 956089] [client 104.28.198.244:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJiAAAAWA"]
[Thu Sep 17 15:07:31.343951 2026] [security2:error] [pid 955873:tid 956089] [client 104.28.198.244:22919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJiAAAAWA"]
[Thu Sep 17 15:07:31.387299 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJigAAAUE"]
[Thu Sep 17 15:07:31.448683 2026] [security2:error] [pid 955873:tid 955899] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJjwABZRk"]
[Thu Sep 17 15:07:31.457502 2026] [security2:error] [pid 955873:tid 956072] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJkAAAAU8"]
[Thu Sep 17 15:07:31.472071 2026] [security2:error] [pid 955873:tid 955906] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/admin/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJkQABZSA"]
[Thu Sep 17 15:07:31.475840 2026] [security2:error] [pid 955873:tid 955888] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/admin_phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJkgABZQ4"]
[Thu Sep 17 15:07:31.488775 2026] [security2:error] [pid 955873:tid 956094] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJiwABZR0"]
[Thu Sep 17 15:07:31.489779 2026] [security2:error] [pid 955873:tid 955880] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/api/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJkwABOAY"]
[Thu Sep 17 15:07:31.491820 2026] [security2:error] [pid 955873:tid 955898] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/public/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJlAABHRg"]
[Thu Sep 17 15:07:31.514205 2026] [security2:error] [pid 955873:tid 955917] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/database.sql"] [unique_id "aqxWkxFTPRVSLOsRVhoJnQABdSs"]
[Thu Sep 17 15:07:31.526674 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJnwAAASQ"]
[Thu Sep 17 15:07:31.542965 2026] [security2:error] [pid 955873:tid 956035] [client 34.166.221.252:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJogAAASo"]
[Thu Sep 17 15:07:31.576425 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJlwABdRM"]
[Thu Sep 17 15:07:31.579324 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJlQABdSU"]
[Thu Sep 17 15:07:31.583037 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmAABdTA"]
[Thu Sep 17 15:07:31.586434 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmwABdSo"]
[Thu Sep 17 15:07:31.588235 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmQABdRo"]
[Thu Sep 17 15:07:31.589728 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJnAABdSE"]
[Thu Sep 17 15:07:31.592261 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJngABdS0"]
[Thu Sep 17 15:07:31.592378 2026] [security2:error] [pid 955873:tid 956110] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJmgABdTE"]
[Thu Sep 17 15:07:31.597222 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJpgAAAR8"]
[Thu Sep 17 15:07:31.613468 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:44018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJpwAAATc"]
[Thu Sep 17 15:07:31.613561 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:44018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJpwAAATc"]
[Thu Sep 17 15:07:31.638041 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.224.217:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php.old"] [unique_id "aqxWkxFTPRVSLOsRVhoJqQAAAWw"]
[Thu Sep 17 15:07:31.703460 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJrQAAAU4"]
[Thu Sep 17 15:07:31.710176 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJqAABSEc"]
[Thu Sep 17 15:07:31.734823 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJqgABSDo"]
[Thu Sep 17 15:07:31.736286 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJrAABSDg"]
[Thu Sep 17 15:07:31.752396 2026] [security2:error] [pid 955873:tid 956065] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJrgABSDQ"]
[Thu Sep 17 15:07:31.763451 2026] [security2:error] [pid 955873:tid 955933] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/wp-config.backup.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtwABgTs"]
[Thu Sep 17 15:07:31.793537 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJvQAAAU0"]
[Thu Sep 17 15:07:31.840083 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtAABgTc"]
[Thu Sep 17 15:07:31.840228 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtQABgSY"]
[Thu Sep 17 15:07:31.840297 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJuAABgR4"]
[Thu Sep 17 15:07:31.843739 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJtgABgS8"]
[Thu Sep 17 15:07:31.847618 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJuQABgUY"]
[Thu Sep 17 15:07:31.851678 2026] [security2:error] [pid 955873:tid 956122] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJugABgUI"]
[Thu Sep 17 15:07:31.876639 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJwAAAARQ"]
[Thu Sep 17 15:07:31.912841 2026] [security2:error] [pid 955873:tid 956105] [client 34.166.228.3:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJwwAAAXA"]
[Thu Sep 17 15:07:31.923339 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:44020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxWkxFTPRVSLOsRVhoJxgAAAS0"]
[Thu Sep 17 15:07:31.952644 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWkxFTPRVSLOsRVhoJygAAAWI"]
[Thu Sep 17 15:07:31.993954 2026] [security2:error] [pid 955873:tid 956027] [client 4.240.114.86:57759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJzQAAASI"], referer: binance.com
[Thu Sep 17 15:07:32.021484 2026] [authz_core:error] [pid 955873:tid 955963] [remote 45.138.12.28:59012] AH01630: client denied by server configuration: /home3/sherrym6/public_html/.htpasswd
[Thu Sep 17 15:07:32.021560 2026] [security2:error] [pid 955873:tid 955952] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/vendor/.env"] [unique_id "aqxWlBFTPRVSLOsRVhoJzwABY04"]
[Thu Sep 17 15:07:32.060074 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.224.217:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php~"] [unique_id "aqxWlBFTPRVSLOsRVhoJ1gAAAXE"]
[Thu Sep 17 15:07:32.074409 2026] [security2:error] [pid 955873:tid 955962] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "counsellingincambridge.ca"] [uri "/sites/default/settings.local.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ2QABY1g"]
[Thu Sep 17 15:07:32.085023 2026] [authz_core:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Poly1305/error_log
[Thu Sep 17 15:07:32.086295 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ2AAAAV8"]
[Thu Sep 17 15:07:32.148151 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ1wAAAXQ"]
[Thu Sep 17 15:07:32.182569 2026] [security2:error] [pid 955873:tid 956010] [client 34.74.242.206:41744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4AAAARE"]
[Thu Sep 17 15:07:32.182682 2026] [security2:error] [pid 955873:tid 956010] [client 34.74.242.206:41744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4AAAARE"]
[Thu Sep 17 15:07:32.202977 2026] [security2:error] [pid 955873:tid 955948] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/panel/.env"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4QABY0o"]
[Thu Sep 17 15:07:32.203337 2026] [security2:error] [pid 955873:tid 955950] [remote 45.138.12.28:59012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "counsellingincambridge.ca"] [uri "/.env.local.swp"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4wABY0w"]
[Thu Sep 17 15:07:32.232196 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:44020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ5AAAAYY"]
[Thu Sep 17 15:07:32.256691 2026] [security2:error] [pid 955873:tid 956079] [client 34.166.221.252:40350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ5wAAAVY"]
[Thu Sep 17 15:07:32.290568 2026] [security2:error] [pid 955873:tid 956075] [client 34.74.242.206:41728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stevenreedcollins.com"] [uri "/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ6AAAAVI"]
[Thu Sep 17 15:07:32.290738 2026] [security2:error] [pid 955873:tid 956075] [client 34.74.242.206:41728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "stevenreedcollins.com"] [uri "/"] [unique_id "aqxWlBFTPRVSLOsRVhoJ6AAAAVI"]
[Thu Sep 17 15:07:32.293734 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJvgABYzY"]
[Thu Sep 17 15:07:32.298543 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJvwABYzM"]
[Thu Sep 17 15:07:32.322912 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJwQABY0k"]
[Thu Sep 17 15:07:32.337687 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJyQABYzk"]
[Thu Sep 17 15:07:32.338619 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ0wABY1I"]
[Thu Sep 17 15:07:32.339079 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJywABY0g"]
[Thu Sep 17 15:07:32.339439 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJzAABY08"]
[Thu Sep 17 15:07:32.339552 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJxQABYy4"]
[Thu Sep 17 15:07:32.342337 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ0gABY1U"]
[Thu Sep 17 15:07:32.364814 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ3QABY0M"]
[Thu Sep 17 15:07:32.367277 2026] [security2:error] [pid 955873:tid 956092] [client 45.138.12.28:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ4gABY1Y"]
[Thu Sep 17 15:07:32.422871 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.224.217:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/info.php.bak"] [unique_id "aqxWlBFTPRVSLOsRVhoJ7wAAAX0"]
[Thu Sep 17 15:07:32.591307 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ8AAAAUA"]
[Thu Sep 17 15:07:32.607411 2026] [security2:error] [pid 955873:tid 956039] [client 34.166.228.3:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ9AAAAS4"]
[Thu Sep 17 15:07:32.618395 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ7QAAAYc"]
[Thu Sep 17 15:07:32.618426 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ7QAAAYc"]
[Thu Sep 17 15:07:32.662267 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.224.217:50248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/phpinfo.php.save"] [unique_id "aqxWlBFTPRVSLOsRVhoJ9wAAAVg"]
[Thu Sep 17 15:07:32.701028 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.195.25:42144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWlBFTPRVSLOsRVhoJ-wAAARM"]
[Thu Sep 17 15:07:32.762721 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ_wAAATE"]
[Thu Sep 17 15:07:32.762841 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:44020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxWlBFTPRVSLOsRVhoJ_wAAATE"]
[Thu Sep 17 15:07:32.953618 2026] [security2:error] [pid 955873:tid 956052] [client 34.166.221.252:40360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.energynowspa.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoKAgAAATs"]
[Thu Sep 17 15:07:32.984917 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.224.217:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxWlBFTPRVSLOsRVhoKAwAAAVo"]
[Thu Sep 17 15:07:33.009614 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKBAAAAVQ"]
[Thu Sep 17 15:07:33.091234 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKBQAAAXY"]
[Thu Sep 17 15:07:33.162154 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:44036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKCgAAAYQ"]
[Thu Sep 17 15:07:33.162252 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:44036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKCgAAAYQ"]
[Thu Sep 17 15:07:33.199292 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKDAAAAR8"]
[Thu Sep 17 15:07:33.292387 2026] [security2:error] [pid 955873:tid 956072] [client 34.166.228.3:55126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKDQAAAU8"]
[Thu Sep 17 15:07:33.300252 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKDwAAARc"]
[Thu Sep 17 15:07:33.304290 2026] [cgid:error] [pid 955873:tid 955970] [remote 172.225.228.23:37424] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:07:33.327046 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.224.217:50258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKEAAAATc"]
[Thu Sep 17 15:07:33.371739 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKEQAAAUg"]
[Thu Sep 17 15:07:33.458781 2026] [security2:error] [pid 955873:tid 956084] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKEwAAAVs"]
[Thu Sep 17 15:07:33.465556 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:44044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxWlRFTPRVSLOsRVhoKFAAAAYE"]
[Thu Sep 17 15:07:33.528274 2026] [security2:error] [pid 955873:tid 956105] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKFwAAAXA"]
[Thu Sep 17 15:07:33.622541 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKHQAAASw"]
[Thu Sep 17 15:07:33.639469 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxWlRFTPRVSLOsRVhoKHgAAAQ0"]
[Thu Sep 17 15:07:33.693792 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKIQAAAXQ"]
[Thu Sep 17 15:07:33.764080 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.224.217:50262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKJQAAAV4"]
[Thu Sep 17 15:07:33.765069 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKJAAAAXg"]
[Thu Sep 17 15:07:33.786771 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:44044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxWlRFTPRVSLOsRVhoKJgAAAYY"]
[Thu Sep 17 15:07:33.833052 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKKQAAAWQ"]
[Thu Sep 17 15:07:33.899549 2026] [security2:error] [pid 955873:tid 956009] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKLQAAARA"]
[Thu Sep 17 15:07:33.973979 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWlRFTPRVSLOsRVhoKMwAAARs"]
[Thu Sep 17 15:07:33.984874 2026] [security2:error] [pid 955873:tid 956010] [client 34.166.228.3:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKNAAAARE"]
[Thu Sep 17 15:07:34.037148 2026] [security2:error] [pid 955873:tid 956102] [client 185.55.149.49:56378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKNgAAAW0"]
[Thu Sep 17 15:07:34.037301 2026] [security2:error] [pid 955873:tid 956102] [client 185.55.149.49:56378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKNgAAAW0"]
[Thu Sep 17 15:07:34.042811 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKNwAAARY"]
[Thu Sep 17 15:07:34.094783 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.224.217:50266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKOgAAASM"]
[Thu Sep 17 15:07:34.127993 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKPQAAAUo"]
[Thu Sep 17 15:07:34.159211 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKMAAAAV0"]
[Thu Sep 17 15:07:34.159235 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWlRFTPRVSLOsRVhoKMAAAAV0"]
[Thu Sep 17 15:07:34.253249 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKQgAAATE"]
[Thu Sep 17 15:07:34.305190 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKQwAAAUk"]
[Thu Sep 17 15:07:34.305295 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKQwAAAUk"]
[Thu Sep 17 15:07:34.331475 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKRgAAAQw"]
[Thu Sep 17 15:07:34.366842 2026] [security2:error] [pid 955873:tid 956064] [client 74.7.244.19:42578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azclassicbronco.org"] [uri "/index.php"] [unique_id "aqxWkxFTPRVSLOsRVhoJhQABRxU"]
[Thu Sep 17 15:07:34.419528 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKVAAAAVo"]
[Thu Sep 17 15:07:34.447880 2026] [security2:error] [pid 955873:tid 956069] [client 138.0.33.64:7854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKRAABTAo"]
[Thu Sep 17 15:07:34.451942 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.224.217:50270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKYwAAASg"]
[Thu Sep 17 15:07:34.507741 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKZQAAAXU"]
[Thu Sep 17 15:07:34.587762 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKZwAAAWU"]
[Thu Sep 17 15:07:34.602919 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:44060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKaQAAAVE"]
[Thu Sep 17 15:07:34.603026 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:44060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKaQAAAVE"]
[Thu Sep 17 15:07:34.677088 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKbQAAAVU"]
[Thu Sep 17 15:07:34.732736 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.224.217:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/www/phpinfo.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKdAAAAUU"]
[Thu Sep 17 15:07:34.750013 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKdQAAAV8"]
[Thu Sep 17 15:07:34.844357 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKegAAASY"]
[Thu Sep 17 15:07:34.898110 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:44066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKfQAAAUs"]
[Thu Sep 17 15:07:34.898218 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:44066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKfQAAAUs"]
[Thu Sep 17 15:07:34.918602 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKfwAAATM"]
[Thu Sep 17 15:07:34.960831 2026] [security2:error] [pid 955873:tid 956011] [client 34.166.228.3:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKgwAAARI"]
[Thu Sep 17 15:07:34.988062 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWlhFTPRVSLOsRVhoKhAAAARw"]
[Thu Sep 17 15:07:35.055643 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKhQAAAUI"]
[Thu Sep 17 15:07:35.100362 2026] [security2:error] [pid 955873:tid 956109] [client 74.125.212.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxWlhFTPRVSLOsRVhoKdgAAAXQ"]
[Thu Sep 17 15:07:35.141253 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.224.217:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKkgAAAWI"]
[Thu Sep 17 15:07:35.149805 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKlAAAARs"]
[Thu Sep 17 15:07:35.196737 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:44082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKmQAAAQ8"]
[Thu Sep 17 15:07:35.196854 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:44082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKmQAAAQ8"]
[Thu Sep 17 15:07:35.211992 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKmgAAATI"]
[Thu Sep 17 15:07:35.279379 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKowAAARo"]
[Thu Sep 17 15:07:35.337231 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKpgAAAXw"]
[Thu Sep 17 15:07:35.339494 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.224.217:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKpwAAATE"]
[Thu Sep 17 15:07:35.411255 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKqgAAAT4"]
[Thu Sep 17 15:07:35.486264 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:44094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKrQAAAYA"]
[Thu Sep 17 15:07:35.486373 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:44094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKrQAAAYA"]
[Thu Sep 17 15:07:35.494108 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKrgAAAVo"]
[Thu Sep 17 15:07:35.499824 2026] [security2:error] [pid 955873:tid 956054] [client 4.240.114.86:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKrwAAAT0"], referer: binance.com
[Thu Sep 17 15:07:35.565298 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKsQAAAQ4"]
[Thu Sep 17 15:07:35.626103 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKuAAAATo"]
[Thu Sep 17 15:07:35.645452 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.228.3:55146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKuQAAAS8"]
[Thu Sep 17 15:07:35.649104 2026] [security2:error] [pid 955873:tid 956077] [client 34.23.224.217:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/site/phpinfo.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKugAAAVQ"]
[Thu Sep 17 15:07:35.710105 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKuwAAAWw"]
[Thu Sep 17 15:07:35.764490 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKwAAAASk"]
[Thu Sep 17 15:07:35.764586 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:44102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxWlxFTPRVSLOsRVhoKwAAAASk"]
[Thu Sep 17 15:07:35.794368 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKwwAAAVE"]
[Thu Sep 17 15:07:35.880771 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKxwAAAXE"]
[Thu Sep 17 15:07:35.963363 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWlxFTPRVSLOsRVhoKyQAAAUU"]
[Thu Sep 17 15:07:36.045984 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoKywAAASU"]
[Thu Sep 17 15:07:36.060188 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxWmBFTPRVSLOsRVhoKzQAAASA"]
[Thu Sep 17 15:07:36.060279 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:44114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxWmBFTPRVSLOsRVhoKzQAAASA"]
[Thu Sep 17 15:07:36.104013 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK0gAAAUs"]
[Thu Sep 17 15:07:36.171716 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK2AAAAWM"]
[Thu Sep 17 15:07:36.257783 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK2wAAAVA"]
[Thu Sep 17 15:07:36.332034 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK3wAAARQ"]
[Thu Sep 17 15:07:36.337938 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.228.3:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4AAAAV4"]
[Thu Sep 17 15:07:36.351440 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4QAAASI"]
[Thu Sep 17 15:07:36.351513 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:44118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4QAAASI"]
[Thu Sep 17 15:07:36.396211 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK5AAAAWE"]
[Thu Sep 17 15:07:36.446466 2026] [security2:error] [pid 955873:tid 956109] [client 45.169.98.18:58968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK5gAAAXQ"]
[Thu Sep 17 15:07:36.446578 2026] [security2:error] [pid 955873:tid 956109] [client 45.169.98.18:58968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK5gAAAXQ"]
[Thu Sep 17 15:07:36.454577 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK5wAAARY"]
[Thu Sep 17 15:07:36.456610 2026] [security2:error] [pid 955873:tid 956123] [client 103.99.250.210:59974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK4wABgns"]
[Thu Sep 17 15:07:36.529293 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK6wAAASM"]
[Thu Sep 17 15:07:36.633418 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK8AAAAVw"]
[Thu Sep 17 15:07:36.666930 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK8gAAASc"]
[Thu Sep 17 15:07:36.667023 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:44124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxWmBFTPRVSLOsRVhoK8gAAASc"]
[Thu Sep 17 15:07:36.715951 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK9gAAAXw"]
[Thu Sep 17 15:07:36.794998 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoK_gAAAVc"]
[Thu Sep 17 15:07:36.853369 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoLAgAAAUc"]
[Thu Sep 17 15:07:36.915679 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoLBQAAAQ4"]
[Thu Sep 17 15:07:36.965558 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:44130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxWmBFTPRVSLOsRVhoLBwAAAXU"]
[Thu Sep 17 15:07:36.974441 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWmBFTPRVSLOsRVhoLCAAAATo"]
[Thu Sep 17 15:07:37.022267 2026] [security2:error] [pid 955873:tid 956023] [client 34.166.228.3:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLCgAAAR4"]
[Thu Sep 17 15:07:37.032894 2026] [security2:error] [pid 955873:tid 956029] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLCwAAASQ"]
[Thu Sep 17 15:07:37.107427 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLDwAAAXs"]
[Thu Sep 17 15:07:37.133918 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxWmRFTPRVSLOsRVhoLEQAAAUM"]
[Thu Sep 17 15:07:37.213481 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLFgAAAXM"]
[Thu Sep 17 15:07:37.279437 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:44130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/wp-includes/sodium_compat/src/"] [unique_id "aqxWmRFTPRVSLOsRVhoLFwAAAUg"]
[Thu Sep 17 15:07:37.290974 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLGQAAAUY"]
[Thu Sep 17 15:07:37.405146 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLIgAAASA"]
[Thu Sep 17 15:07:37.490677 2026] [security2:error] [pid 955873:tid 956100] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLKAAAAWs"]
[Thu Sep 17 15:07:37.553018 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLKgAAAWM"]
[Thu Sep 17 15:07:37.620749 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:46078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWmRFTPRVSLOsRVhoLMQAAAXc"]
[Thu Sep 17 15:07:37.647986 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLIwAAASY"]
[Thu Sep 17 15:07:37.648016 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLIwAAASY"]
[Thu Sep 17 15:07:37.692858 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLNAAAARQ"]
[Thu Sep 17 15:07:37.710199 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.228.3:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLNgAAATM"]
[Thu Sep 17 15:07:37.792179 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:44130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLOgAAARE"]
[Thu Sep 17 15:07:37.792273 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:44130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLOgAAARE"]
[Thu Sep 17 15:07:37.824802 2026] [security2:error] [pid 955873:tid 956102] [client 2.139.26.243:53223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mtbclubdecampo.com"] [uri "/ruta.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLOQAAAW0"]
[Thu Sep 17 15:07:37.948915 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLQgAAARg"]
[Thu Sep 17 15:07:37.973413 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLRAAAARI"]
[Thu Sep 17 15:07:37.973499 2026] [security2:error] [pid 955873:tid 956011] [client 115.244.164.14:52992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmRFTPRVSLOsRVhoLRAAAARI"]
[Thu Sep 17 15:07:38.070558 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLRwAAAT4"]
[Thu Sep 17 15:07:38.070656 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:44134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLRwAAAT4"]
[Thu Sep 17 15:07:38.243214 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:46094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLTwAAAUE"]
[Thu Sep 17 15:07:38.373418 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLVwAAASQ"]
[Thu Sep 17 15:07:38.373539 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:44146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLVwAAASQ"]
[Thu Sep 17 15:07:38.432084 2026] [security2:error] [pid 955873:tid 956119] [client 34.166.228.3:55198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLWQAAAX4"]
[Thu Sep 17 15:07:38.531216 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.195.25:46108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLXQAAARc"]
[Thu Sep 17 15:07:38.669349 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLYgAAAUk"]
[Thu Sep 17 15:07:38.669469 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:44148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLYgAAAUk"]
[Thu Sep 17 15:07:38.771554 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:46114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLZQAAATA"]
[Thu Sep 17 15:07:38.847213 2026] [security2:error] [pid 955873:tid 956116] [client 154.190.208.131:42083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLaAAAAXs"]
[Thu Sep 17 15:07:38.847309 2026] [security2:error] [pid 955873:tid 956116] [client 154.190.208.131:42083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWmhFTPRVSLOsRVhoLaAAAAXs"]
[Thu Sep 17 15:07:38.965790 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:44156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxWmhFTPRVSLOsRVhoLawAAAWM"]
[Thu Sep 17 15:07:39.025093 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLbAAAAU0"]
[Thu Sep 17 15:07:39.142591 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxWmxFTPRVSLOsRVhoLcAAAAVk"]
[Thu Sep 17 15:07:39.287628 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:44156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/wp-includes/"] [unique_id "aqxWmxFTPRVSLOsRVhoLdgAAAVs"]
[Thu Sep 17 15:07:39.321013 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLeAAAAS0"]
[Thu Sep 17 15:07:39.604701 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.228.3:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWmxFTPRVSLOsRVhoLhwAAARg"]
[Thu Sep 17 15:07:39.638473 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLfAAAAXk"]
[Thu Sep 17 15:07:39.638498 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLfAAAAXk"]
[Thu Sep 17 15:07:39.715203 2026] [security2:error] [pid 955873:tid 956076] [client 5.189.145.112:60320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiansoncampusnlc.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLjAAAAVM"], referer: binance.com
[Thu Sep 17 15:07:39.751825 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLjgAAARI"]
[Thu Sep 17 15:07:39.786087 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLkQAAAQw"]
[Thu Sep 17 15:07:39.786197 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:44156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLkQAAAQw"]
[Thu Sep 17 15:07:39.809671 2026] [security2:error] [pid 955873:tid 956123] [client 47.79.200.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLfQAAAYI"], referer: https://www.google.com/
[Thu Sep 17 15:07:39.865196 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:46146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLkwAAATs"]
[Thu Sep 17 15:07:39.920067 2026] [security2:error] [pid 955873:tid 956115] [client 4.240.114.86:62072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLlgAAAXo"], referer: binance.com
[Thu Sep 17 15:07:40.073440 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLngAAAVQ"]
[Thu Sep 17 15:07:40.073572 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLngAAAVQ"]
[Thu Sep 17 15:07:40.085091 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLnwAAAXU"]
[Thu Sep 17 15:07:40.293787 2026] [security2:error] [pid 955873:tid 956023] [client 34.166.228.3:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLpgAAAR4"]
[Thu Sep 17 15:07:40.367629 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLqAAAAWA"]
[Thu Sep 17 15:07:40.367742 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:40794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLqAAAAWA"]
[Thu Sep 17 15:07:40.381153 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLqgAAASo"]
[Thu Sep 17 15:07:40.645514 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:40802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLuQAAAWQ"]
[Thu Sep 17 15:07:40.645614 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:40802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLuQAAAWQ"]
[Thu Sep 17 15:07:40.654105 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLugAAAU0"]
[Thu Sep 17 15:07:40.858247 2026] [security2:error] [pid 955873:tid 956054] [client 104.207.47.59:24523] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWnBFTPRVSLOsRVhoLvwAAAT0"]
[Thu Sep 17 15:07:40.888531 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLwQAAAWI"]
[Thu Sep 17 15:07:40.982278 2026] [security2:error] [pid 955873:tid 956087] [client 34.166.228.3:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWnBFTPRVSLOsRVhoLxAAAAV4"]
[Thu Sep 17 15:07:41.026158 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxWnRFTPRVSLOsRVhoLyAAAAWc"]
[Thu Sep 17 15:07:41.026278 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:40806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxWnRFTPRVSLOsRVhoLyAAAAWc"]
[Thu Sep 17 15:07:41.077515 2026] [security2:error] [pid 955873:tid 956061] [client 205.217.233.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxWmxFTPRVSLOsRVhoLggAAAUQ"], referer: https://instagram.com/
[Thu Sep 17 15:07:41.163863 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoLzAAAARY"]
[Thu Sep 17 15:07:41.313510 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:40812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL0gAAAWk"]
[Thu Sep 17 15:07:41.313601 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:40812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL0gAAAWk"]
[Thu Sep 17 15:07:41.441476 2026] [security2:error] [pid 955873:tid 956127] [client 34.23.195.25:53858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL1AAAAYY"]
[Thu Sep 17 15:07:41.599515 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:40816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxWnRFTPRVSLOsRVhoL2QAAAYk"]
[Thu Sep 17 15:07:41.645363 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:53868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL2gAAATk"]
[Thu Sep 17 15:07:41.672807 2026] [security2:error] [pid 955873:tid 956003] [client 34.166.228.3:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL2wAAAQo"]
[Thu Sep 17 15:07:41.759640 2026] [authz_core:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/theme-compat/error_log
[Thu Sep 17 15:07:41.765869 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxWnRFTPRVSLOsRVhoL3wAAAXU"]
[Thu Sep 17 15:07:41.924162 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:40816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/wp-includes/"] [unique_id "aqxWnRFTPRVSLOsRVhoL5QAAAUM"]
[Thu Sep 17 15:07:42.053768 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL6AAAAUg"]
[Thu Sep 17 15:07:42.070021 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:55337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL6wAAASQ"]
[Thu Sep 17 15:07:42.071045 2026] [security2:error] [pid 955873:tid 956029] [client 186.105.232.15:55337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL6wAAASQ"]
[Thu Sep 17 15:07:42.204059 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL9wAAATg"]
[Thu Sep 17 15:07:42.273013 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL7AAAAV8"]
[Thu Sep 17 15:07:42.273037 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL7AAAAV8"]
[Thu Sep 17 15:07:42.304818 2026] [security2:error] [pid 955873:tid 955926] [remote 216.73.217.142:24319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWnhFTPRVSLOsRVhoL-QABPDQ"]
[Thu Sep 17 15:07:42.371350 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.228.3:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL-wAAAW8"]
[Thu Sep 17 15:07:42.416995 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/comments.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL_AAAAWo"]
[Thu Sep 17 15:07:42.417099 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:40816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/comments.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL_AAAAWo"]
[Thu Sep 17 15:07:42.461923 2026] [security2:error] [pid 955873:tid 956105] [client 47.79.200.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL9QAAAXA"], referer: https://www.google.com/
[Thu Sep 17 15:07:42.468172 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.195.25:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWnhFTPRVSLOsRVhoL_gAAAYU"]
[Thu Sep 17 15:07:42.680856 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:53900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMAwAAAT0"]
[Thu Sep 17 15:07:42.709358 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:40824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-404.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMCAAAAXc"]
[Thu Sep 17 15:07:42.709481 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:40824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-404.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMCAAAAXc"]
[Thu Sep 17 15:07:42.890831 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:53910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWnhFTPRVSLOsRVhoMEAAAATI"]
[Thu Sep 17 15:07:43.058111 2026] [security2:error] [pid 955873:tid 956012] [client 34.166.228.3:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFAAAARM"]
[Thu Sep 17 15:07:43.062976 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:40830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-content.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFQAAATE"]
[Thu Sep 17 15:07:43.063069 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:40830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed-content.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFQAAATE"]
[Thu Sep 17 15:07:43.211505 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:53926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMFwAAAQw"]
[Thu Sep 17 15:07:43.281822 2026] [security2:error] [pid 955873:tid 956004] [client 44.239.144.77:50821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxWnRFTPRVSLOsRVhoL1QAAAQs"], referer: http://worthtranslations.com/OLD
[Thu Sep 17 15:07:43.370540 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:40840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMHAAAAXo"]
[Thu Sep 17 15:07:43.370671 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:40840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMHAAAAXo"]
[Thu Sep 17 15:07:43.665263 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:40844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer-embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMJwAAAUM"]
[Thu Sep 17 15:07:43.665356 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:40844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer-embed.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMJwAAAUM"]
[Thu Sep 17 15:07:43.757230 2026] [security2:error] [pid 955873:tid 956103] [client 34.166.228.3:42648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWnxFTPRVSLOsRVhoMKQAAAW4"]
[Thu Sep 17 15:07:43.892143 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:53940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMMgAAAVw"]
[Thu Sep 17 15:07:43.958803 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:40854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMNQAAAVk"]
[Thu Sep 17 15:07:43.958889 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:40854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/footer.php"] [unique_id "aqxWnxFTPRVSLOsRVhoMNQAAAVk"]
[Thu Sep 17 15:07:44.000960 2026] [security2:error] [pid 955873:tid 956068] [client 4.240.114.86:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMNgAAAUs"], referer: binance.com
[Thu Sep 17 15:07:44.076549 2026] [security2:error] [pid 955873:tid 956062] [client 104.207.47.59:55109] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxWoBFTPRVSLOsRVhoMOQAAAUU"]
[Thu Sep 17 15:07:44.242744 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header-embed.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMQAAAAUk"]
[Thu Sep 17 15:07:44.242846 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header-embed.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMQAAAAUk"]
[Thu Sep 17 15:07:44.339211 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMQQAAAWQ"]
[Thu Sep 17 15:07:44.422544 2026] [access_compat:error] [pid 955873:tid 956091] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/alice-behind-the-mirror
[Thu Sep 17 15:07:44.439311 2026] [security2:error] [pid 955873:tid 956094] [client 34.166.228.3:42652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWoBFTPRVSLOsRVhoMSwAAAWU"]
[Thu Sep 17 15:07:44.536231 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:40880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMUgAAAX0"]
[Thu Sep 17 15:07:44.536319 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:40880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/header.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMUgAAAX0"]
[Thu Sep 17 15:07:44.606019 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMUQAAARs"]
[Thu Sep 17 15:07:44.718625 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWoBFTPRVSLOsRVhoMWwAAAWk"]
[Thu Sep 17 15:07:44.821204 2026] [security2:error] [pid 955873:tid 956032] [client 185.55.149.49:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYQAAASc"]
[Thu Sep 17 15:07:44.821315 2026] [security2:error] [pid 955873:tid 956032] [client 185.55.149.49:57092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYQAAASc"]
[Thu Sep 17 15:07:44.826691 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:40886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/sidebar.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYgAAAQs"]
[Thu Sep 17 15:07:44.826781 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:40886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/sidebar.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYgAAAQs"]
[Thu Sep 17 15:07:44.941308 2026] [security2:error] [pid 955873:tid 956064] [client 24.163.167.215:42134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMYAABR0Y"]
[Thu Sep 17 15:07:44.941788 2026] [security2:error] [pid 955873:tid 956011] [client 210.222.43.21:52971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWoBFTPRVSLOsRVhoMXQAAARI"], referer: http://talent-in-borders.com/demo
[Thu Sep 17 15:07:45.022043 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.195.25:53944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMZwAAAXo"]
[Thu Sep 17 15:07:45.103769 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMcwAAAT4"]
[Thu Sep 17 15:07:45.103859 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMcwAAAT4"]
[Thu Sep 17 15:07:45.126228 2026] [security2:error] [pid 955873:tid 956121] [client 34.166.228.3:42668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWoRFTPRVSLOsRVhoMdAAAAYA"]
[Thu Sep 17 15:07:45.342382 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.195.25:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMiQAAASg"]
[Thu Sep 17 15:07:45.389749 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMjQAAAU4"]
[Thu Sep 17 15:07:45.389843 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMjQAAAU4"]
[Thu Sep 17 15:07:45.595076 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMkQAAATg"]
[Thu Sep 17 15:07:45.693217 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMkwAAASU"]
[Thu Sep 17 15:07:45.693312 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:40916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMkwAAASU"]
[Thu Sep 17 15:07:45.810445 2026] [security2:error] [pid 955873:tid 956062] [client 34.166.228.3:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWoRFTPRVSLOsRVhoMmQAAAUU"]
[Thu Sep 17 15:07:45.815203 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMmgAAAXI"]
[Thu Sep 17 15:07:45.980456 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:40930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMoAAAAVs"]
[Thu Sep 17 15:07:45.980556 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:40930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMoAAAAVs"]
[Thu Sep 17 15:07:46.069368 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:53974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWohFTPRVSLOsRVhoMpQAAAS0"]
[Thu Sep 17 15:07:46.192295 2026] [security2:error] [pid 955873:tid 956088] [client 192.81.217.115:37842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxWoRFTPRVSLOsRVhoMnwAAAV8"], referer: https://www.thevagabondhiker.com/
[Thu Sep 17 15:07:46.276889 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxWohFTPRVSLOsRVhoMsQAAARY"]
[Thu Sep 17 15:07:46.276995 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:40946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxWohFTPRVSLOsRVhoMsQAAARY"]
[Thu Sep 17 15:07:46.291881 2026] [security2:error] [pid 955873:tid 956076] [client 34.23.195.25:53984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWohFTPRVSLOsRVhoMsgAAAVM"]
[Thu Sep 17 15:07:46.303463 2026] [security2:error] [pid 955873:tid 956104] [client 24.163.167.215:42135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWohFTPRVSLOsRVhoMqwABbyc"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726062022&hideanons=1&limit=100&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:07:46.491421 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.228.3:42686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWohFTPRVSLOsRVhoMuwAAARg"]
[Thu Sep 17 15:07:46.521318 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWohFTPRVSLOsRVhoMvAAAAXg"]
[Thu Sep 17 15:07:46.574874 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:40956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxWohFTPRVSLOsRVhoMvQAAARo"]
[Thu Sep 17 15:07:46.748353 2026] [authz_core:error] [pid 955873:tid 956022] [client 143.244.57.120:42860] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/widgets/error_log
[Thu Sep 17 15:07:46.751936 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxWohFTPRVSLOsRVhoMwgAAAR0"]
[Thu Sep 17 15:07:46.762100 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:54012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWohFTPRVSLOsRVhoMwwAAAT4"]
[Thu Sep 17 15:07:46.842515 2026] [security2:error] [pid 955873:tid 956075] [client 57.141.14.31:27414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxWohFTPRVSLOsRVhoMwQABUj4"]
[Thu Sep 17 15:07:46.900316 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:40956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/wp-includes/"] [unique_id "aqxWohFTPRVSLOsRVhoMzAAAAXM"]
[Thu Sep 17 15:07:46.904786 2026] [security2:error] [pid 955873:tid 956034] [client 45.169.98.18:59529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWohFTPRVSLOsRVhoMzQAAASk"]
[Thu Sep 17 15:07:46.904872 2026] [security2:error] [pid 955873:tid 956034] [client 45.169.98.18:59529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWohFTPRVSLOsRVhoMzQAAASk"]
[Thu Sep 17 15:07:47.012527 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWoxFTPRVSLOsRVhoM0AAAAV0"]
[Thu Sep 17 15:07:47.187142 2026] [security2:error] [pid 955873:tid 956071] [client 34.166.228.3:42698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM2gAAAU4"]
[Thu Sep 17 15:07:47.262312 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:54026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWoxFTPRVSLOsRVhoM2wAAAXs"]
[Thu Sep 17 15:07:47.344092 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM0wAAAVU"]
[Thu Sep 17 15:07:47.344114 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:42860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM0wAAAVU"]
[Thu Sep 17 15:07:47.485298 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-nav-menu-widget.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM6wAAAUI"]
[Thu Sep 17 15:07:47.485407 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:40956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-nav-menu-widget.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM6wAAAUI"]
[Thu Sep 17 15:07:47.526460 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:54038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM7AAAAUQ"]
[Thu Sep 17 15:07:47.760761 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:40972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-archives.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM-wAAAYk"]
[Thu Sep 17 15:07:47.760889 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:40972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-archives.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM-wAAAYk"]
[Thu Sep 17 15:07:47.787238 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.195.25:54050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM_gAAAUc"]
[Thu Sep 17 15:07:47.883933 2026] [security2:error] [pid 955873:tid 956004] [client 34.166.228.3:42700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWoxFTPRVSLOsRVhoNBAAAAQs"]
[Thu Sep 17 15:07:47.948699 2026] [security2:error] [pid 955873:tid 956113] [client 162.241.226.11:10908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWoxFTPRVSLOsRVhoM-AAAAXg"]
[Thu Sep 17 15:07:48.061468 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNCgAAAT4"]
[Thu Sep 17 15:07:48.061602 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:40978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNCgAAAT4"]
[Thu Sep 17 15:07:48.086110 2026] [security2:error] [pid 955873:tid 956052] [client 104.207.47.59:49135] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWpBFTPRVSLOsRVhoNDAAAATs"]
[Thu Sep 17 15:07:48.109681 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:54054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNDgAAAR0"]
[Thu Sep 17 15:07:48.201224 2026] [security2:error] [pid 955873:tid 956048] [client 162.241.226.11:10918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNCQAAATc"]
[Thu Sep 17 15:07:48.339640 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-calendar.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNFwAAAS8"]
[Thu Sep 17 15:07:48.339785 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:40980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-calendar.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNFwAAAS8"]
[Thu Sep 17 15:07:48.360880 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:54056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNGgAAAV0"]
[Thu Sep 17 15:07:48.394690 2026] [security2:error] [pid 955873:tid 956089] [client 185.104.184.228:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.184.104.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNGwAAAWA"]
[Thu Sep 17 15:07:48.394791 2026] [security2:error] [pid 955873:tid 956089] [client 185.104.184.228:54802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNGwAAAWA"]
[Thu Sep 17 15:07:48.589294 2026] [security2:error] [pid 955873:tid 956124] [client 34.166.228.3:42710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIAAAAYM"]
[Thu Sep 17 15:07:48.593381 2026] [security2:error] [pid 955873:tid 956065] [client 115.244.164.14:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIQAAAUg"]
[Thu Sep 17 15:07:48.593453 2026] [security2:error] [pid 955873:tid 956065] [client 115.244.164.14:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIQAAAUg"]
[Thu Sep 17 15:07:48.623437 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.195.25:54062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNIwAAATw"]
[Thu Sep 17 15:07:48.628180 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:40988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-categories.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNJAAAAXs"]
[Thu Sep 17 15:07:48.628266 2026] [security2:error] [pid 955873:tid 956116] [client 143.244.57.120:40988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-categories.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNJAAAAXs"]
[Thu Sep 17 15:07:48.642847 2026] [security2:error] [pid 955873:tid 956118] [client 200.8.108.97:48402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNHAAAAX0"], referer: https://www.thevagabondhiker.com/
[Thu Sep 17 15:07:48.890643 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:54066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNLAAAAQ0"]
[Thu Sep 17 15:07:48.915534 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:41004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-custom-html.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNMAAAAWU"]
[Thu Sep 17 15:07:48.915624 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:41004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-custom-html.php"] [unique_id "aqxWpBFTPRVSLOsRVhoNMAAAAWU"]
[Thu Sep 17 15:07:49.020784 2026] [security2:error] [pid 955873:tid 956119] [client 4.240.114.86:50757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNNAAAAX4"], referer: binance.com
[Thu Sep 17 15:07:49.126492 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNOgAAAUQ"]
[Thu Sep 17 15:07:49.201508 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:41014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-links.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNPAAAAWg"]
[Thu Sep 17 15:07:49.201587 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:41014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-links.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNPAAAAWg"]
[Thu Sep 17 15:07:49.291188 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.228.3:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNPwAAASI"]
[Thu Sep 17 15:07:49.318997 2026] [security2:error] [pid 955873:tid 956045] [client 154.190.208.131:41320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNQAAAATQ"]
[Thu Sep 17 15:07:49.323675 2026] [security2:error] [pid 955873:tid 956045] [client 154.190.208.131:41320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNQAAAATQ"]
[Thu Sep 17 15:07:49.410873 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:54086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNRAAAARE"]
[Thu Sep 17 15:07:49.498229 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:41018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-audio.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNSAAAAXg"]
[Thu Sep 17 15:07:49.498309 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:41018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-audio.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNSAAAAXg"]
[Thu Sep 17 15:07:49.700602 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNUgAAATU"]
[Thu Sep 17 15:07:49.780936 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:41030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-gallery.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNVAAAAS4"]
[Thu Sep 17 15:07:49.781026 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:41030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-gallery.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNVAAAAS4"]
[Thu Sep 17 15:07:49.906124 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.195.25:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNWAAAAVI"]
[Thu Sep 17 15:07:49.974484 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.228.3:42730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNWgAAATE"]
[Thu Sep 17 15:07:50.057801 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:35508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-image.php"] [unique_id "aqxWphFTPRVSLOsRVhoNXwAAAXE"]
[Thu Sep 17 15:07:50.057904 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:35508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-image.php"] [unique_id "aqxWphFTPRVSLOsRVhoNXwAAAXE"]
[Thu Sep 17 15:07:50.060083 2026] [security2:error] [pid 955873:tid 956023] [client 47.79.206.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWpRFTPRVSLOsRVhoNTwAAAR4"], referer: https://www.google.com/
[Thu Sep 17 15:07:50.209652 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.195.25:54110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNZQAAAWA"]
[Thu Sep 17 15:07:50.214979 2026] [authz_core:error] [pid 955873:tid 956099] [client 20.244.34.24:60285] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:07:50.363053 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-video.php"] [unique_id "aqxWphFTPRVSLOsRVhoNagAAAVQ"]
[Thu Sep 17 15:07:50.363174 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:35518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media-video.php"] [unique_id "aqxWphFTPRVSLOsRVhoNagAAAVQ"]
[Thu Sep 17 15:07:50.502530 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.195.25:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNbgAAARw"]
[Thu Sep 17 15:07:50.667327 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.228.3:42734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNcwAAAX0"]
[Thu Sep 17 15:07:50.678800 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media.php"] [unique_id "aqxWphFTPRVSLOsRVhoNdAAAAWU"]
[Thu Sep 17 15:07:50.678892 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:35520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-media.php"] [unique_id "aqxWphFTPRVSLOsRVhoNdAAAAWU"]
[Thu Sep 17 15:07:50.805084 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:32998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWphFTPRVSLOsRVhoNegAAATI"]
[Thu Sep 17 15:07:50.971285 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-meta.php"] [unique_id "aqxWphFTPRVSLOsRVhoNfwAAASM"]
[Thu Sep 17 15:07:50.971377 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:35528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-meta.php"] [unique_id "aqxWphFTPRVSLOsRVhoNfwAAASM"]
[Thu Sep 17 15:07:51.049929 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afw.noo.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNggAAAS0"]
[Thu Sep 17 15:07:51.261918 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-pages.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNiAAAAXY"]
[Thu Sep 17 15:07:51.262018 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-pages.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNiAAAAXY"]
[Thu Sep 17 15:07:51.353792 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.228.3:42740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNiwAAAW8"]
[Thu Sep 17 15:07:51.520666 2026] [security2:error] [pid 955873:tid 956112] [client 104.207.47.59:11721] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWpxFTPRVSLOsRVhoNkAAAAXc"]
[Thu Sep 17 15:07:51.549720 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-comments.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNkwAAAYg"]
[Thu Sep 17 15:07:51.549821 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:35552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-comments.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNkwAAAYg"]
[Thu Sep 17 15:07:51.826493 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-posts.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNogAAAYk"]
[Thu Sep 17 15:07:51.826575 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-recent-posts.php"] [unique_id "aqxWpxFTPRVSLOsRVhoNogAAAYk"]
[Thu Sep 17 15:07:52.052041 2026] [security2:error] [pid 955873:tid 956042] [client 34.166.228.3:42746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNqwAAATE"]
[Thu Sep 17 15:07:52.103742 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-rss.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNsQAAAWo"]
[Thu Sep 17 15:07:52.103829 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:35580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-rss.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNsQAAAWo"]
[Thu Sep 17 15:07:52.387450 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-search.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNvgAAARw"]
[Thu Sep 17 15:07:52.387621 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:35584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-search.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNvgAAARw"]
[Thu Sep 17 15:07:52.675288 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-tag-cloud.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNzQAAARk"]
[Thu Sep 17 15:07:52.675377 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:35588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-tag-cloud.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNzQAAARk"]
[Thu Sep 17 15:07:52.737277 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.228.3:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN0QAAARg"]
[Thu Sep 17 15:07:52.979309 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:35598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-text.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1QAAAXk"]
[Thu Sep 17 15:07:52.979407 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:35598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-text.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1QAAAXk"]
[Thu Sep 17 15:07:52.988450 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1wAAAVU"]
[Thu Sep 17 15:07:52.989632 2026] [security2:error] [pid 955873:tid 956078] [client 186.105.232.15:55986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqBFTPRVSLOsRVhoN1wAAAVU"]
[Thu Sep 17 15:07:53.268470 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/"] [unique_id "aqxWqRFTPRVSLOsRVhoN4AAAAUM"]
[Thu Sep 17 15:07:53.367777 2026] [security2:error] [pid 955873:tid 955892] [remote 57.141.14.91:47582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "timalba.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN4gABDhI"], referer: https://timalba.com/?i=88029249987600
[Thu Sep 17 15:07:53.431190 2026] [security2:error] [pid 955873:tid 956085] [client 34.166.228.3:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN5gAAAVw"]
[Thu Sep 17 15:07:53.520388 2026] [security2:error] [pid 955873:tid 956011] [client 104.28.198.244:22539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN6QAAARI"]
[Thu Sep 17 15:07:53.520527 2026] [security2:error] [pid 955873:tid 956011] [client 104.28.198.244:22539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN6QAAARI"]
[Thu Sep 17 15:07:53.658797 2026] [security2:error] [pid 955873:tid 956123] [client 4.240.114.86:53239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxWqRFTPRVSLOsRVhoN6wAAAYI"], referer: binance.com
[Thu Sep 17 15:07:53.763918 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/"] [unique_id "aqxWqRFTPRVSLOsRVhoN7AAAAWw"]
[Thu Sep 17 15:07:53.904165 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/"] [unique_id "aqxWqRFTPRVSLOsRVhoN8wAAAYY"]
[Thu Sep 17 15:07:54.139408 2026] [security2:error] [pid 955873:tid 956016] [client 34.166.228.3:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWqhFTPRVSLOsRVhoN-QAAARc"]
[Thu Sep 17 15:07:54.175453 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/"] [unique_id "aqxWqhFTPRVSLOsRVhoN9wAAAQo"]
[Thu Sep 17 15:07:54.318957 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/wp-includes/css/"] [unique_id "aqxWqhFTPRVSLOsRVhoN_wAAAVg"]
[Thu Sep 17 15:07:54.532532 2026] [security2:error] [pid 955873:tid 956088] [client 104.207.47.59:46981] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWqhFTPRVSLOsRVhoOBQAAAV8"]
[Thu Sep 17 15:07:54.675122 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqhFTPRVSLOsRVhoOAAAAAWA"]
[Thu Sep 17 15:07:54.675147 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqhFTPRVSLOsRVhoOAAAAAWA"]
[Thu Sep 17 15:07:54.852093 2026] [security2:error] [pid 955873:tid 956009] [client 34.166.228.3:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWqhFTPRVSLOsRVhoOFAAAARA"]
[Thu Sep 17 15:07:54.954697 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/base-styles/"] [unique_id "aqxWqhFTPRVSLOsRVhoOGAAAAWk"]
[Thu Sep 17 15:07:55.111218 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/base-styles/"] [unique_id "aqxWqxFTPRVSLOsRVhoOGgAAAXo"]
[Thu Sep 17 15:07:55.170426 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.224.217:54902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOIgAAATA"]
[Thu Sep 17 15:07:55.257698 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/base-styles/wp-includes/css/dist/"] [unique_id "aqxWqxFTPRVSLOsRVhoOJwAAAW8"]
[Thu Sep 17 15:07:55.521748 2026] [security2:error] [pid 955873:tid 956067] [client 57.141.14.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "timalba.com"] [uri "/index.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOJQAAAUo"], referer: https://timalba.com/?i=88029249987600
[Thu Sep 17 15:07:55.529567 2026] [security2:error] [pid 955873:tid 956027] [client 34.166.228.3:55210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOMAAAASI"]
[Thu Sep 17 15:07:55.531692 2026] [security2:error] [pid 955873:tid 956076] [client 185.55.149.49:50062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOMQAAAVM"]
[Thu Sep 17 15:07:55.531790 2026] [security2:error] [pid 955873:tid 956076] [client 185.55.149.49:50062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOMQAAAVM"]
[Thu Sep 17 15:07:55.587522 2026] [security2:error] [pid 955873:tid 956024] [client 4.240.114.86:52349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.paltals.com"] [uri "/index.php"] [unique_id "aqxWqBFTPRVSLOsRVhoNuwAAAR8"], referer: binance.com
[Thu Sep 17 15:07:55.672715 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOKgAAAX8"]
[Thu Sep 17 15:07:55.672739 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWqxFTPRVSLOsRVhoOKgAAAX8"]
[Thu Sep 17 15:07:55.820460 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-directory/"] [unique_id "aqxWqxFTPRVSLOsRVhoOPAAAAVY"]
[Thu Sep 17 15:07:55.978575 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-directory/"] [unique_id "aqxWqxFTPRVSLOsRVhoOQAAAAUY"]
[Thu Sep 17 15:07:56.121583 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-directory/wp-includes/css/dist/"] [unique_id "aqxWrBFTPRVSLOsRVhoORQAAAVk"]
[Thu Sep 17 15:07:56.205696 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.228.3:55214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gnq.aze.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOSwAAAT4"]
[Thu Sep 17 15:07:56.457165 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOUQAAAR0"]
[Thu Sep 17 15:07:56.457187 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOUQAAAR0"]
[Thu Sep 17 15:07:56.598078 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-editor/"] [unique_id "aqxWrBFTPRVSLOsRVhoOWQAAAWU"]
[Thu Sep 17 15:07:56.641151 2026] [security2:error] [pid 955873:tid 956017] [client 192.178.6.3:46297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxWrBFTPRVSLOsRVhoOXAAAARg"]
[Thu Sep 17 15:07:56.770913 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-editor/"] [unique_id "aqxWrBFTPRVSLOsRVhoOYwAAAWI"]
[Thu Sep 17 15:07:56.920265 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-editor/wp-includes/css/dist/"] [unique_id "aqxWrBFTPRVSLOsRVhoOaQAAAWg"]
[Thu Sep 17 15:07:57.094966 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.224.217:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOcAAAAVc"]
[Thu Sep 17 15:07:57.185111 2026] [security2:error] [pid 955873:tid 956111] [client 104.238.222.26:59643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centerforfederaljusticereform.org"] [uri "/wp-login.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOdgAAAXY"]
[Thu Sep 17 15:07:57.258006 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoObwAAAUM"]
[Thu Sep 17 15:07:57.258035 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoObwAAAUM"]
[Thu Sep 17 15:07:57.378806 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:60077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOggAAAQw"]
[Thu Sep 17 15:07:57.378942 2026] [security2:error] [pid 955873:tid 956005] [client 45.169.98.18:60077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOggAAAQw"]
[Thu Sep 17 15:07:57.402150 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "aqxWrRFTPRVSLOsRVhoOhgAAAYk"]
[Thu Sep 17 15:07:57.421546 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.224.217:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOiAAAAR8"]
[Thu Sep 17 15:07:57.576003 2026] [security2:error] [pid 955873:tid 956014] [client 104.207.47.59:65213] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWrRFTPRVSLOsRVhoOkAAAARU"]
[Thu Sep 17 15:07:57.579172 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "aqxWrRFTPRVSLOsRVhoOjgAAAU8"]
[Thu Sep 17 15:07:57.588439 2026] [security2:error] [pid 955873:tid 956121] [client 4.240.114.86:55460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOkQAAAYA"], referer: binance.com
[Thu Sep 17 15:07:57.708613 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.224.217:54930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/core/phpinfo.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOoQAAATg"]
[Thu Sep 17 15:07:57.721399 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/block-library/wp-includes/css/dist/"] [unique_id "aqxWrRFTPRVSLOsRVhoOogAAAV8"]
[Thu Sep 17 15:07:58.062301 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOpgAAATI"]
[Thu Sep 17 15:07:58.062322 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrRFTPRVSLOsRVhoOpgAAATI"]
[Thu Sep 17 15:07:58.113619 2026] [security2:error] [pid 955873:tid 956021] [client 34.23.224.217:54946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.224.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.coblersen.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxWrhFTPRVSLOsRVhoOrgAAARw"]
[Thu Sep 17 15:07:58.204946 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/commands/"] [unique_id "aqxWrhFTPRVSLOsRVhoOswAAAYU"]
[Thu Sep 17 15:07:58.358409 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/commands/"] [unique_id "aqxWrhFTPRVSLOsRVhoOuAAAAWc"]
[Thu Sep 17 15:07:58.499411 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/commands/wp-includes/css/dist/"] [unique_id "aqxWrhFTPRVSLOsRVhoOvQAAAXw"]
[Thu Sep 17 15:07:58.816547 2026] [security2:error] [pid 955873:tid 956111] [client 179.125.154.246:40555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWrhFTPRVSLOsRVhoOyQABdhk"]
[Thu Sep 17 15:07:59.063647 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrhFTPRVSLOsRVhoO0QAAAVM"]
[Thu Sep 17 15:07:59.063688 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrhFTPRVSLOsRVhoO0QAAAVM"]
[Thu Sep 17 15:07:59.233509 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/components/"] [unique_id "aqxWrxFTPRVSLOsRVhoO6QAAAXg"]
[Thu Sep 17 15:07:59.348836 2026] [security2:error] [pid 955873:tid 956129] [client 115.244.164.14:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO7gAAAYg"]
[Thu Sep 17 15:07:59.348910 2026] [security2:error] [pid 955873:tid 956129] [client 115.244.164.14:54280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO7gAAAYg"]
[Thu Sep 17 15:07:59.392543 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/components/"] [unique_id "aqxWrxFTPRVSLOsRVhoO8AAAASQ"]
[Thu Sep 17 15:07:59.533785 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/components/wp-includes/css/dist/"] [unique_id "aqxWrxFTPRVSLOsRVhoO9wAAAV8"]
[Thu Sep 17 15:07:59.802182 2026] [security2:error] [pid 955873:tid 956040] [client 154.190.208.131:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoPAwAAAS8"]
[Thu Sep 17 15:07:59.805052 2026] [security2:error] [pid 955873:tid 956040] [client 154.190.208.131:41908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWrxFTPRVSLOsRVhoPAwAAAS8"]
[Thu Sep 17 15:07:59.861610 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO_wAAASA"]
[Thu Sep 17 15:07:59.861630 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWrxFTPRVSLOsRVhoO_wAAASA"]
[Thu Sep 17 15:08:00.022476 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/customize-widgets/"] [unique_id "aqxWsBFTPRVSLOsRVhoPCwAAATI"]
[Thu Sep 17 15:08:00.180627 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/customize-widgets/"] [unique_id "aqxWsBFTPRVSLOsRVhoPEQAAAQ0"]
[Thu Sep 17 15:08:00.330569 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/customize-widgets/wp-includes/css/dist/"] [unique_id "aqxWsBFTPRVSLOsRVhoPGAAAARA"]
[Thu Sep 17 15:08:00.674553 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsBFTPRVSLOsRVhoPIAAAAW4"]
[Thu Sep 17 15:08:00.674574 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsBFTPRVSLOsRVhoPIAAAAW4"]
[Thu Sep 17 15:08:00.780930 2026] [security2:error] [pid 955873:tid 956115] [client 104.207.47.59:53203] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWsBFTPRVSLOsRVhoPLQAAAXo"]
[Thu Sep 17 15:08:00.825864 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "aqxWsBFTPRVSLOsRVhoPLgAAASg"]
[Thu Sep 17 15:08:00.928346 2026] [security2:error] [pid 955873:tid 956106] [client 34.94.67.131:55458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWsBFTPRVSLOsRVhoPMwAAAXE"]
[Thu Sep 17 15:08:00.985929 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "aqxWsBFTPRVSLOsRVhoPNAAAAXg"]
[Thu Sep 17 15:08:01.128145 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-post/wp-includes/css/dist/"] [unique_id "aqxWsRFTPRVSLOsRVhoPNwAAARc"]
[Thu Sep 17 15:08:01.290587 2026] [security2:error] [pid 955873:tid 956082] [client 34.94.67.131:38740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPQQAAAVk"]
[Thu Sep 17 15:08:01.371628 2026] [security2:error] [pid 955873:tid 956077] [client 177.100.7.127:48418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPPgABVBM"]
[Thu Sep 17 15:08:01.537376 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPPwAAAUg"]
[Thu Sep 17 15:08:01.537403 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPPwAAAUg"]
[Thu Sep 17 15:08:01.678732 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-site/"] [unique_id "aqxWsRFTPRVSLOsRVhoPRgAAAUs"]
[Thu Sep 17 15:08:01.733108 2026] [security2:error] [pid 955873:tid 956049] [client 34.94.67.131:38742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPSwAAATg"]
[Thu Sep 17 15:08:01.846504 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-site/"] [unique_id "aqxWsRFTPRVSLOsRVhoPTgAAAUk"]
[Thu Sep 17 15:08:01.865271 2026] [security2:error] [pid 955873:tid 956022] [client 145.239.10.137:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxshee.com"] [uri "/wsunch.php"] [unique_id "aqxWsRFTPRVSLOsRVhoPTwAAAR0"], referer: http://foxshee.com/wsunch.php
[Thu Sep 17 15:08:01.987133 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-site/wp-includes/css/dist/"] [unique_id "aqxWsRFTPRVSLOsRVhoPUgAAASA"]
[Thu Sep 17 15:08:02.091098 2026] [security2:error] [pid 955873:tid 956017] [client 4.240.114.86:57867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxWshFTPRVSLOsRVhoPVQAAARg"], referer: binance.com
[Thu Sep 17 15:08:02.244216 2026] [security2:error] [pid 955873:tid 956098] [client 34.94.67.131:38748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWshFTPRVSLOsRVhoPXQAAAWk"]
[Thu Sep 17 15:08:02.355440 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPVgAAARw"]
[Thu Sep 17 15:08:02.355464 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPVgAAARw"]
[Thu Sep 17 15:08:02.520004 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-widgets/"] [unique_id "aqxWshFTPRVSLOsRVhoPZAAAAU0"]
[Thu Sep 17 15:08:02.677977 2026] [security2:error] [pid 955873:tid 956052] [client 34.94.67.131:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWshFTPRVSLOsRVhoPbgAAATs"]
[Thu Sep 17 15:08:02.678549 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-widgets/"] [unique_id "aqxWshFTPRVSLOsRVhoPbAAAARY"]
[Thu Sep 17 15:08:02.821585 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/edit-widgets/wp-includes/css/dist/"] [unique_id "aqxWshFTPRVSLOsRVhoPdgAAAXY"]
[Thu Sep 17 15:08:03.162801 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPeAAAAR8"]
[Thu Sep 17 15:08:03.162824 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWshFTPRVSLOsRVhoPeAAAAR8"]
[Thu Sep 17 15:08:03.220190 2026] [security2:error] [pid 955873:tid 956100] [client 34.94.67.131:38758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPggAAAWs"]
[Thu Sep 17 15:08:03.303967 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/editor/"] [unique_id "aqxWsxFTPRVSLOsRVhoPhQAAAYE"]
[Thu Sep 17 15:08:03.457893 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/editor/"] [unique_id "aqxWsxFTPRVSLOsRVhoPigAAAUU"]
[Thu Sep 17 15:08:03.557774 2026] [security2:error] [pid 955873:tid 956071] [client 34.94.67.131:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPjQAAAU4"]
[Thu Sep 17 15:08:03.598731 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/editor/wp-includes/css/dist/"] [unique_id "aqxWsxFTPRVSLOsRVhoPkAAAATg"]
[Thu Sep 17 15:08:03.793903 2026] [security2:error] [pid 955873:tid 956116] [client 104.207.47.59:54493] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "threadalittlelight.com"] [uri "/"] [unique_id "aqxWsxFTPRVSLOsRVhoPmQAAAXs"]
[Thu Sep 17 15:08:03.817011 2026] [security2:error] [pid 955873:tid 956089] [client 34.94.67.131:38770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPmgAAAWA"]
[Thu Sep 17 15:08:03.932883 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPlwAAAVI"]
[Thu Sep 17 15:08:03.932906 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWsxFTPRVSLOsRVhoPlwAAAVI"]
[Thu Sep 17 15:08:04.069540 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:56587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPngAAAWU"]
[Thu Sep 17 15:08:04.069646 2026] [security2:error] [pid 955873:tid 956094] [client 186.105.232.15:56587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPngAAAWU"]
[Thu Sep 17 15:08:04.073441 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/format-library/"] [unique_id "aqxWtBFTPRVSLOsRVhoPoAAAATI"]
[Thu Sep 17 15:08:04.239182 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/format-library/"] [unique_id "aqxWtBFTPRVSLOsRVhoPpgAAARA"]
[Thu Sep 17 15:08:04.380033 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/format-library/wp-includes/css/dist/"] [unique_id "aqxWtBFTPRVSLOsRVhoPqgAAAU0"]
[Thu Sep 17 15:08:04.724655 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPrAAAAVo"]
[Thu Sep 17 15:08:04.724690 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPrAAAAVo"]
[Thu Sep 17 15:08:04.865804 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/list-reusable-blocks/"] [unique_id "aqxWtBFTPRVSLOsRVhoPuAAAAXo"]
[Thu Sep 17 15:08:04.980056 2026] [security2:error] [pid 955873:tid 956085] [client 34.94.67.131:38782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWtBFTPRVSLOsRVhoPugAAAVw"]
[Thu Sep 17 15:08:05.019914 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/list-reusable-blocks/"] [unique_id "aqxWtRFTPRVSLOsRVhoPvAAAAQ4"]
[Thu Sep 17 15:08:05.168468 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/list-reusable-blocks/wp-includes/css/dist/"] [unique_id "aqxWtRFTPRVSLOsRVhoPwAAAAUQ"]
[Thu Sep 17 15:08:05.284914 2026] [security2:error] [pid 955873:tid 956103] [client 34.94.67.131:38794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWtRFTPRVSLOsRVhoPxAAAAW4"]
[Thu Sep 17 15:08:05.518230 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtRFTPRVSLOsRVhoPxQAAARU"]
[Thu Sep 17 15:08:05.518259 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtRFTPRVSLOsRVhoPxQAAARU"]
[Thu Sep 17 15:08:05.664251 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/media-utils/"] [unique_id "aqxWtRFTPRVSLOsRVhoPzAAAAVM"]
[Thu Sep 17 15:08:05.724623 2026] [security2:error] [pid 955873:tid 956064] [client 4.240.114.86:59728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxWtRFTPRVSLOsRVhoP0AAAAUc"], referer: binance.com
[Thu Sep 17 15:08:05.790464 2026] [security2:error] [pid 955873:tid 956023] [client 34.94.67.131:38802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWtRFTPRVSLOsRVhoP1AAAAR4"]
[Thu Sep 17 15:08:05.828419 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/media-utils/"] [unique_id "aqxWtRFTPRVSLOsRVhoP1QAAAQ8"]
[Thu Sep 17 15:08:05.968798 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/media-utils/wp-includes/css/dist/"] [unique_id "aqxWtRFTPRVSLOsRVhoP1wAAAUo"]
[Thu Sep 17 15:08:06.182273 2026] [security2:error] [pid 955873:tid 956051] [client 185.55.149.49:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP4AAAATo"]
[Thu Sep 17 15:08:06.182415 2026] [security2:error] [pid 955873:tid 956051] [client 185.55.149.49:50670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP4AAAATo"]
[Thu Sep 17 15:08:06.220939 2026] [security2:error] [pid 955873:tid 956109] [client 34.94.67.131:38806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWthFTPRVSLOsRVhoP5QAAAXQ"]
[Thu Sep 17 15:08:06.314354 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP3QAAAR0"]
[Thu Sep 17 15:08:06.314375 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP3QAAAR0"]
[Thu Sep 17 15:08:06.454426 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/notices/"] [unique_id "aqxWthFTPRVSLOsRVhoP6gAAAX4"]
[Thu Sep 17 15:08:06.600218 2026] [security2:error] [pid 955873:tid 956021] [client 34.94.67.131:38822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWthFTPRVSLOsRVhoP7gAAARw"]
[Thu Sep 17 15:08:06.609444 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/notices/"] [unique_id "aqxWthFTPRVSLOsRVhoP7QAAARs"]
[Thu Sep 17 15:08:06.754303 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/notices/wp-includes/css/dist/"] [unique_id "aqxWthFTPRVSLOsRVhoP9wAAASM"]
[Thu Sep 17 15:08:06.771617 2026] [security2:error] [pid 955873:tid 956006] [client 104.207.47.59:13915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/wp-ticket/readme.txt"] [unique_id "aqxWthFTPRVSLOsRVhoP-AAAAQ0"]
[Thu Sep 17 15:08:06.792567 2026] [security2:error] [pid 955873:tid 956124] [client 104.28.198.244:22877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP-QAAAYM"]
[Thu Sep 17 15:08:06.973351 2026] [security2:error] [pid 955873:tid 956124] [client 104.28.198.244:22877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxWthFTPRVSLOsRVhoP-QAAAYM"]
[Thu Sep 17 15:08:07.082788 2026] [security2:error] [pid 955873:tid 956007] [client 34.94.67.131:38832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQCQAAAQ4"]
[Thu Sep 17 15:08:07.104999 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP_QAAASg"]
[Thu Sep 17 15:08:07.105021 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWthFTPRVSLOsRVhoP_QAAASg"]
[Thu Sep 17 15:08:07.245841 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/nux/"] [unique_id "aqxWtxFTPRVSLOsRVhoQDwAAAVY"]
[Thu Sep 17 15:08:07.275696 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env"] [unique_id "aqxWtxFTPRVSLOsRVhoQEQAAAV4"]
[Thu Sep 17 15:08:07.399742 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/nux/"] [unique_id "aqxWtxFTPRVSLOsRVhoQFgAAAWQ"]
[Thu Sep 17 15:08:07.448440 2026] [security2:error] [pid 955873:tid 956016] [client 34.94.67.131:38840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQGQAAARc"]
[Thu Sep 17 15:08:07.540436 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/nux/wp-includes/css/dist/"] [unique_id "aqxWtxFTPRVSLOsRVhoQHQAAAQ8"]
[Thu Sep 17 15:08:07.804109 2026] [security2:error] [pid 955873:tid 956113] [client 45.76.255.99:60918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQJAABeEs"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:08:07.864880 2026] [security2:error] [pid 955873:tid 956035] [client 45.169.98.18:60636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQLQAAASo"]
[Thu Sep 17 15:08:07.865003 2026] [security2:error] [pid 955873:tid 956035] [client 45.169.98.18:60636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQLQAAASo"]
[Thu Sep 17 15:08:07.866671 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxWtxFTPRVSLOsRVhoQLAAAAUk"]
[Thu Sep 17 15:08:07.873628 2026] [security2:error] [pid 955873:tid 956032] [client 78.47.98.55:48074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQJwAAASc"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:08:07.892542 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQIwAAAU4"]
[Thu Sep 17 15:08:07.892567 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQIwAAAU4"]
[Thu Sep 17 15:08:07.936483 2026] [security2:error] [pid 955873:tid 956109] [client 34.94.67.131:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWtxFTPRVSLOsRVhoQMAAAAXQ"]
[Thu Sep 17 15:08:07.937693 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxWtxFTPRVSLOsRVhoQLwAAASA"]
[Thu Sep 17 15:08:08.034583 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/patterns/"] [unique_id "aqxWuBFTPRVSLOsRVhoQMwAAAWo"]
[Thu Sep 17 15:08:08.063009 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxWuBFTPRVSLOsRVhoQNQAAAT0"]
[Thu Sep 17 15:08:08.106505 2026] [security2:error] [pid 955873:tid 956119] [client 34.94.67.131:38854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQNwAAAX4"]
[Thu Sep 17 15:08:08.153193 2026] [security2:error] [pid 955873:tid 956125] [client 45.76.255.99:60924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQNgABhEo"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821171306&hideliu=1&hidemyself=1&limit=100&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:08.193199 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/patterns/"] [unique_id "aqxWuBFTPRVSLOsRVhoQPAAAAWg"]
[Thu Sep 17 15:08:08.334374 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/patterns/wp-includes/css/dist/"] [unique_id "aqxWuBFTPRVSLOsRVhoQQQAAAVo"]
[Thu Sep 17 15:08:08.452272 2026] [security2:error] [pid 955873:tid 956078] [client 34.94.67.131:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQSAAAAVU"]
[Thu Sep 17 15:08:08.508790 2026] [security2:error] [pid 955873:tid 956017] [client 78.47.98.55:48076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQQgAAARg"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:08:08.692784 2026] [security2:error] [pid 955873:tid 956124] [client 34.94.67.131:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQUwAAAYM"]
[Thu Sep 17 15:08:08.711899 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQSQAAAUM"]
[Thu Sep 17 15:08:08.711926 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQSQAAAUM"]
[Thu Sep 17 15:08:08.857863 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/preferences/"] [unique_id "aqxWuBFTPRVSLOsRVhoQVwAAAVY"]
[Thu Sep 17 15:08:08.989179 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxWuBFTPRVSLOsRVhoQWwAAAYI"]
[Thu Sep 17 15:08:09.018650 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/preferences/"] [unique_id "aqxWuBFTPRVSLOsRVhoQXQAAAWQ"]
[Thu Sep 17 15:08:09.049609 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.env~"] [unique_id "aqxWuRFTPRVSLOsRVhoQXgAAAUE"]
[Thu Sep 17 15:08:09.084222 2026] [security2:error] [pid 955873:tid 956112] [client 68.55.134.110:41523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWuBFTPRVSLOsRVhoQWgABd1g"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:08:09.110097 2026] [security2:error] [pid 955873:tid 956003] [client 34.94.67.131:38888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQYAAAAQo"]
[Thu Sep 17 15:08:09.158846 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/preferences/wp-includes/css/dist/"] [unique_id "aqxWuRFTPRVSLOsRVhoQYgAAAT8"]
[Thu Sep 17 15:08:09.433039 2026] [security2:error] [pid 955873:tid 956130] [client 4.240.114.86:61306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.paltals.com"] [uri "/index.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQaQAAAYk"], referer: binance.com
[Thu Sep 17 15:08:09.523568 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQagAAAS4"]
[Thu Sep 17 15:08:09.523596 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQagAAAS4"]
[Thu Sep 17 15:08:09.541847 2026] [security2:error] [pid 955873:tid 956067] [client 34.94.67.131:38890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQcgAAAUo"]
[Thu Sep 17 15:08:09.655887 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQdwAAAXs"]
[Thu Sep 17 15:08:09.662725 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQeQAAAX0"]
[Thu Sep 17 15:08:09.662819 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:35604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQeQAAAX0"]
[Thu Sep 17 15:08:09.745513 2026] [security2:error] [pid 955873:tid 956075] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQgAAAAVI"]
[Thu Sep 17 15:08:09.749965 2026] [security2:error] [pid 955873:tid 956113] [client 104.207.47.59:27023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/wp-automatic/readme.txt"] [unique_id "aqxWuRFTPRVSLOsRVhoQgQAAAXg"]
[Thu Sep 17 15:08:09.771045 2026] [security2:error] [pid 955873:tid 956068] [client 115.244.164.14:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQggAAAUs"]
[Thu Sep 17 15:08:09.771136 2026] [security2:error] [pid 955873:tid 956068] [client 115.244.164.14:54916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQggAAAUs"]
[Thu Sep 17 15:08:09.819491 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQhwAAAX4"]
[Thu Sep 17 15:08:09.893403 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQjAAAAWI"]
[Thu Sep 17 15:08:09.941424 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "aqxWuRFTPRVSLOsRVhoQjgAAARA"]
[Thu Sep 17 15:08:09.956392 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxWuRFTPRVSLOsRVhoQjwAAAXY"]
[Thu Sep 17 15:08:09.967161 2026] [security2:error] [pid 955873:tid 956059] [client 4.240.114.86:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxWuRFTPRVSLOsRVhoQkAAAAUI"], referer: binance.com
[Thu Sep 17 15:08:10.023849 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQkgAAAWc"]
[Thu Sep 17 15:08:10.084936 2026] [security2:error] [pid 955873:tid 956115] [client 68.55.134.110:45351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQkQABelo"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821171306&hideliu=1&hidemyself=1&limit=100&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:10.103534 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "aqxWuhFTPRVSLOsRVhoQlAAAAVU"]
[Thu Sep 17 15:08:10.160004 2026] [security2:error] [pid 955873:tid 956050] [client 34.94.67.131:37016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWuhFTPRVSLOsRVhoQlwAAATk"]
[Thu Sep 17 15:08:10.176972 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQmAAAAVA"]
[Thu Sep 17 15:08:10.238704 2026] [security2:error] [pid 955873:tid 956005] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQnQAAAQw"]
[Thu Sep 17 15:08:10.249603 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/reusable-blocks/wp-includes/css/dist/"] [unique_id "aqxWuhFTPRVSLOsRVhoQngAAARI"]
[Thu Sep 17 15:08:10.304759 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQowAAAV4"]
[Thu Sep 17 15:08:10.363244 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQpgAAAYE"]
[Thu Sep 17 15:08:10.456263 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQrAAAAVw"]
[Thu Sep 17 15:08:10.556655 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQrgAAATg"]
[Thu Sep 17 15:08:10.572623 2026] [security2:error] [pid 955873:tid 956120] [client 34.94.67.131:37032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQrwAAAX8"]
[Thu Sep 17 15:08:10.589654 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQqAAAAXU"]
[Thu Sep 17 15:08:10.589689 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQqAAAAXU"]
[Thu Sep 17 15:08:10.665165 2026] [security2:error] [pid 955873:tid 956067] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQtwAAAUo"]
[Thu Sep 17 15:08:10.701873 2026] [security2:error] [pid 955873:tid 956092] [client 154.190.208.131:42500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQvAAAAWM"]
[Thu Sep 17 15:08:10.714651 2026] [security2:error] [pid 955873:tid 956092] [client 154.190.208.131:42500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQvAAAAWM"]
[Thu Sep 17 15:08:10.724508 2026] [security2:error] [pid 955873:tid 956065] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQvQAAAUg"]
[Thu Sep 17 15:08:10.747231 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/theme/"] [unique_id "aqxWuhFTPRVSLOsRVhoQvgAAAVI"]
[Thu Sep 17 15:08:10.799484 2026] [security2:error] [pid 955873:tid 956068] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQvwAAAUs"]
[Thu Sep 17 15:08:10.829911 2026] [security2:error] [pid 955873:tid 956071] [client 34.94.67.131:37038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWuhFTPRVSLOsRVhoQwQAAAU4"]
[Thu Sep 17 15:08:10.863589 2026] [security2:error] [pid 955873:tid 956126] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQwwAAAYU"]
[Thu Sep 17 15:08:10.900889 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/theme/"] [unique_id "aqxWuhFTPRVSLOsRVhoQxAAAAX4"]
[Thu Sep 17 15:08:10.978523 2026] [security2:error] [pid 955873:tid 956089] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxWuhFTPRVSLOsRVhoQxgAAAWA"]
[Thu Sep 17 15:08:11.039388 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/theme/wp-includes/css/dist/"] [unique_id "aqxWuxFTPRVSLOsRVhoQyAAAARw"]
[Thu Sep 17 15:08:11.053390 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQyQAAAXM"]
[Thu Sep 17 15:08:11.135586 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQzQAAAQ0"]
[Thu Sep 17 15:08:11.210731 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ1AAAATI"]
[Thu Sep 17 15:08:11.256841 2026] [security2:error] [pid 955873:tid 956019] [client 34.94.67.131:37054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoQ1wAAARo"]
[Thu Sep 17 15:08:11.275908 2026] [security2:error] [pid 955873:tid 956042] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ2QAAATE"]
[Thu Sep 17 15:08:11.343185 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ4AAAAXI"]
[Thu Sep 17 15:08:11.392623 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoQ0gAAAXY"]
[Thu Sep 17 15:08:11.392651 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoQ0gAAAXY"]
[Thu Sep 17 15:08:11.430523 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoQ5AAAAXE"]
[Thu Sep 17 15:08:11.530499 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/widgets/"] [unique_id "aqxWuxFTPRVSLOsRVhoRAQAAAWQ"]
[Thu Sep 17 15:08:11.535558 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRAgAAAUE"]
[Thu Sep 17 15:08:11.582833 2026] [security2:error] [pid 955873:tid 956054] [client 34.94.67.131:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRBQAAAT0"]
[Thu Sep 17 15:08:11.602444 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRBgAAAVc"]
[Thu Sep 17 15:08:11.660944 2026] [security2:error] [pid 955873:tid 956070] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRCQAAAU0"]
[Thu Sep 17 15:08:11.684321 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/widgets/"] [unique_id "aqxWuxFTPRVSLOsRVhoRCgAAARE"]
[Thu Sep 17 15:08:11.724143 2026] [authz_core:error] [pid 955873:tid 956037] [client 20.244.34.24:51773] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:08:11.753362 2026] [security2:error] [pid 955873:tid 956088] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRDgAAAV8"]
[Thu Sep 17 15:08:11.786638 2026] [security2:error] [pid 955873:tid 956129] [client 34.166.190.5:58882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRDwAAAYg"]
[Thu Sep 17 15:08:11.821699 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoREAAAAUA"]
[Thu Sep 17 15:08:11.822604 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/css/dist/widgets/wp-includes/css/dist/"] [unique_id "aqxWuxFTPRVSLOsRVhoREQAAAXk"]
[Thu Sep 17 15:08:11.847302 2026] [security2:error] [pid 955873:tid 956008] [client 34.94.67.131:37066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRFAAAAQ8"]
[Thu Sep 17 15:08:11.913205 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRFgAAAXU"]
[Thu Sep 17 15:08:11.977456 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxWuxFTPRVSLOsRVhoRGwAAAVk"]
[Thu Sep 17 15:08:12.040341 2026] [security2:error] [pid 955873:tid 956066] [client 34.94.67.131:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWvBFTPRVSLOsRVhoRHAAAAUk"]
[Thu Sep 17 15:08:12.060625 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRHgAAAWM"]
[Thu Sep 17 15:08:12.120490 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRIQAAAXg"]
[Thu Sep 17 15:08:12.164041 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRGQAAASc"]
[Thu Sep 17 15:08:12.164066 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWuxFTPRVSLOsRVhoRGQAAASc"]
[Thu Sep 17 15:08:12.194765 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRKAAAAWk"]
[Thu Sep 17 15:08:12.243291 2026] [security2:error] [pid 955873:tid 956022] [client 34.94.67.131:37072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxWvBFTPRVSLOsRVhoRKgAAAR0"]
[Thu Sep 17 15:08:12.307648 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxWvBFTPRVSLOsRVhoRKwAAAXw"]
[Thu Sep 17 15:08:12.312724 2026] [security2:error] [pid 955873:tid 956125] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRLAAAAYQ"]
[Thu Sep 17 15:08:12.392656 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRMAAAAXM"]
[Thu Sep 17 15:08:12.468591 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxWvBFTPRVSLOsRVhoRNQAAAYY"]
[Thu Sep 17 15:08:12.472236 2026] [security2:error] [pid 955873:tid 956047] [client 34.166.190.5:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWvBFTPRVSLOsRVhoRNgAAATY"]
[Thu Sep 17 15:08:12.495470 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRNwAAAXQ"]
[Thu Sep 17 15:08:12.574471 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoROQAAARQ"]
[Thu Sep 17 15:08:12.585200 2026] [core:error] [pid 955873:tid 955887] [remote 43.128.104.113:45748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:12.585218 2026] [core:error] [pid 955873:tid 955887] [remote 43.128.104.113:45748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:12.614479 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:42188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/module.tag.lyrics3.php"] [unique_id "aqxWvBFTPRVSLOsRVhoROwAAATA"]
[Thu Sep 17 15:08:12.614588 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:42188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/ID3/module.tag.lyrics3.php"] [unique_id "aqxWvBFTPRVSLOsRVhoROwAAATA"]
[Thu Sep 17 15:08:12.626553 2026] [security2:error] [pid 955873:tid 956018] [client 104.207.47.59:51133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxWvBFTPRVSLOsRVhoRPAAAARk"]
[Thu Sep 17 15:08:12.643900 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:33228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRPwAAAWI"]
[Thu Sep 17 15:08:12.704649 2026] [security2:error] [pid 955873:tid 956077] [client 34.94.67.131:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxWvBFTPRVSLOsRVhoRQwAAAVQ"]
[Thu Sep 17 15:08:12.902542 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxWvBFTPRVSLOsRVhoRRwAAASE"]
[Thu Sep 17 15:08:12.932153 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRSAAAAVo"]
[Thu Sep 17 15:08:13.000166 2026] [security2:error] [pid 955873:tid 956123] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxWvBFTPRVSLOsRVhoRSQAAAYI"]
[Thu Sep 17 15:08:13.054289 2026] [authz_core:error] [pid 955873:tid 956036] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/IXR/error_log
[Thu Sep 17 15:08:13.059406 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxWvRFTPRVSLOsRVhoRTAAAASs"]
[Thu Sep 17 15:08:13.066586 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRTQAAAUQ"]
[Thu Sep 17 15:08:13.082903 2026] [security2:error] [pid 955873:tid 956017] [client 34.94.67.131:37088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxWvRFTPRVSLOsRVhoRTwAAARg"]
[Thu Sep 17 15:08:13.135381 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRUgAAAQo"]
[Thu Sep 17 15:08:13.160677 2026] [security2:error] [pid 955873:tid 956033] [client 34.166.190.5:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRVAAAASg"]
[Thu Sep 17 15:08:13.201738 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxWvRFTPRVSLOsRVhoRVgAAAT8"]
[Thu Sep 17 15:08:13.221418 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRVwAAAYc"]
[Thu Sep 17 15:08:13.300420 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRWgAAAR4"]
[Thu Sep 17 15:08:13.361213 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxWvRFTPRVSLOsRVhoRWwAAAS0"]
[Thu Sep 17 15:08:13.385311 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRXAAAASw"]
[Thu Sep 17 15:08:13.454818 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRXgAAAQ8"]
[Thu Sep 17 15:08:13.491868 2026] [security2:error] [pid 955873:tid 956049] [client 4.240.114.86:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRXwAAATg"], referer: binance.com
[Thu Sep 17 15:08:13.521407 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/"] [unique_id "aqxWvRFTPRVSLOsRVhoRYAAAAT4"]
[Thu Sep 17 15:08:13.523122 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRYQAAAVw"]
[Thu Sep 17 15:08:13.590800 2026] [security2:error] [pid 955873:tid 956064] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRYwAAAUc"]
[Thu Sep 17 15:08:13.623148 2026] [security2:error] [pid 955873:tid 956120] [client 34.94.67.131:37094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxWvRFTPRVSLOsRVhoRZAAAAX8"]
[Thu Sep 17 15:08:13.650391 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRaAAAAUk"]
[Thu Sep 17 15:08:13.670992 2026] [authz_core:error] [pid 955873:tid 956092] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/library/error_log
[Thu Sep 17 15:08:13.672211 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/"] [unique_id "aqxWvRFTPRVSLOsRVhoRagAAAWM"]
[Thu Sep 17 15:08:13.711535 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRawAAAXg"]
[Thu Sep 17 15:08:13.794858 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRbQAAASo"]
[Thu Sep 17 15:08:13.827021 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/wp-includes/Requests/"] [unique_id "aqxWvRFTPRVSLOsRVhoRbgAAASQ"]
[Thu Sep 17 15:08:13.839865 2026] [security2:error] [pid 955873:tid 956012] [client 34.166.190.5:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRbwAAARM"]
[Thu Sep 17 15:08:13.855397 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRcAAAAWk"]
[Thu Sep 17 15:08:13.946683 2026] [security2:error] [pid 955873:tid 956046] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxWvRFTPRVSLOsRVhoRdQAAATU"]
[Thu Sep 17 15:08:14.033265 2026] [security2:error] [pid 955873:tid 956089] [client 34.94.67.131:37100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRdwAAAWA"]
[Thu Sep 17 15:08:14.039222 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoReQAAARs"]
[Thu Sep 17 15:08:14.152538 2026] [security2:error] [pid 955873:tid 956028] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRfAAAASM"]
[Thu Sep 17 15:08:14.181374 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRdgAAARw"]
[Thu Sep 17 15:08:14.181403 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvRFTPRVSLOsRVhoRdgAAARw"]
[Thu Sep 17 15:08:14.245533 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRfgAAAQ0"]
[Thu Sep 17 15:08:14.314618 2026] [security2:error] [pid 955873:tid 956016] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRgQAAARc"]
[Thu Sep 17 15:08:14.326746 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/Requests.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRggAAAWc"]
[Thu Sep 17 15:08:14.326829 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/library/Requests.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRggAAAWc"]
[Thu Sep 17 15:08:14.341236 2026] [security2:error] [pid 955873:tid 956013] [client 34.94.67.131:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRgwAAARQ"]
[Thu Sep 17 15:08:14.403059 2026] [security2:error] [pid 955873:tid 956041] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRhQAAATA"]
[Thu Sep 17 15:08:14.476344 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRhwAAAYA"]
[Thu Sep 17 15:08:14.522039 2026] [security2:error] [pid 955873:tid 956045] [client 34.166.190.5:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRiQAAATQ"]
[Thu Sep 17 15:08:14.534040 2026] [core:error] [pid 955873:tid 955915] [remote 120.227.18.209:6693] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:14.534056 2026] [core:error] [pid 955873:tid 955915] [remote 120.227.18.209:6693] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:14.561402 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRiwAAAVY"]
[Thu Sep 17 15:08:14.612469 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/"] [unique_id "aqxWvhFTPRVSLOsRVhoRjgAAARo"]
[Thu Sep 17 15:08:14.621770 2026] [security2:error] [pid 955873:tid 956087] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRjwAAAV4"]
[Thu Sep 17 15:08:14.631692 2026] [security2:error] [pid 955873:tid 956111] [client 34.94.67.131:37116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRkAAAAXY"]
[Thu Sep 17 15:08:14.687782 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRkwAAAVo"]
[Thu Sep 17 15:08:14.771637 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRlwAAAV0"]
[Thu Sep 17 15:08:14.774571 2026] [authz_core:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/error_log
[Thu Sep 17 15:08:14.806251 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/"] [unique_id "aqxWvhFTPRVSLOsRVhoRlAAAAWQ"]
[Thu Sep 17 15:08:14.831324 2026] [security2:error] [pid 955873:tid 956061] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRmAAAAUQ"]
[Thu Sep 17 15:08:14.920920 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRmgAAAXc"]
[Thu Sep 17 15:08:14.948601 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:42210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/wp-includes/Requests/"] [unique_id "aqxWvhFTPRVSLOsRVhoRmwAAARg"]
[Thu Sep 17 15:08:14.995315 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxWvhFTPRVSLOsRVhoRnwAAAVA"]
[Thu Sep 17 15:08:15.088397 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRpAAAAR4"]
[Thu Sep 17 15:08:15.099301 2026] [security2:error] [pid 955873:tid 956104] [client 186.105.232.15:57189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRpQAAAW8"]
[Thu Sep 17 15:08:15.099421 2026] [security2:error] [pid 955873:tid 956104] [client 186.105.232.15:57189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRpQAAAW8"]
[Thu Sep 17 15:08:15.119238 2026] [security2:error] [pid 955873:tid 956128] [client 87.110.34.78:55968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRngABhyM"]
[Thu Sep 17 15:08:15.187630 2026] [security2:error] [pid 955873:tid 956100] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRqAAAAWs"]
[Thu Sep 17 15:08:15.202511 2026] [security2:error] [pid 955873:tid 956054] [client 34.94.67.131:37122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRqQAAAT0"]
[Thu Sep 17 15:08:15.208317 2026] [security2:error] [pid 955873:tid 956056] [client 34.166.190.5:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRqgAAAT8"]
[Thu Sep 17 15:08:15.216410 2026] [security2:error] [pid 955873:tid 956103] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWvhFTPRVSLOsRVhoRoAAAAW4"]
[Thu Sep 17 15:08:15.278264 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRrgAAAQ8"]
[Thu Sep 17 15:08:15.289408 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRowAAAU0"]
[Thu Sep 17 15:08:15.289429 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRowAAAU0"]
[Thu Sep 17 15:08:15.359725 2026] [security2:error] [pid 955873:tid 956110] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRsAAAAXU"]
[Thu Sep 17 15:08:15.433469 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRtQAAAUg"]
[Thu Sep 17 15:08:15.433551 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:42210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRtQAAAUg"]
[Thu Sep 17 15:08:15.438392 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRtgAAAXg"]
[Thu Sep 17 15:08:15.524672 2026] [security2:error] [pid 955873:tid 956039] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRuQAAAS4"]
[Thu Sep 17 15:08:15.621067 2026] [security2:error] [pid 955873:tid 956050] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRvAAAATk"]
[Thu Sep 17 15:08:15.629169 2026] [security2:error] [pid 955873:tid 956130] [client 34.94.67.131:37126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRvwAAAYk"]
[Thu Sep 17 15:08:15.684631 2026] [security2:error] [pid 955873:tid 956029] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRuAABJAQ"], referer: http://heromakers.org/new/
[Thu Sep 17 15:08:15.705941 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRwgAAAWA"]
[Thu Sep 17 15:08:15.713282 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRxAAAAXM"]
[Thu Sep 17 15:08:15.714244 2026] [security2:error] [pid 955873:tid 956034] [client 143.244.57.120:42216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "aqxWvxFTPRVSLOsRVhoRxQAAASk"]
[Thu Sep 17 15:08:15.794306 2026] [security2:error] [pid 955873:tid 956118] [client 104.207.47.59:37385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/gamipress/readme.txt"] [unique_id "aqxWvxFTPRVSLOsRVhoRzAAAAX0"]
[Thu Sep 17 15:08:15.819125 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoRzgAAAWc"]
[Thu Sep 17 15:08:15.866906 2026] [authz_core:error] [pid 955873:tid 956013] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Auth/error_log
[Thu Sep 17 15:08:15.868029 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "aqxWvxFTPRVSLOsRVhoR0QAAARQ"]
[Thu Sep 17 15:08:15.909071 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.190.5:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWvxFTPRVSLOsRVhoR0wAAAXk"]
[Thu Sep 17 15:08:15.910281 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoR0gAAAXI"]
[Thu Sep 17 15:08:15.972182 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxWvxFTPRVSLOsRVhoR1QAAARI"]
[Thu Sep 17 15:08:16.027082 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:42216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/wp-includes/Requests/src/"] [unique_id "aqxWwBFTPRVSLOsRVhoR1gAAAYY"]
[Thu Sep 17 15:08:16.033338 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWvxFTPRVSLOsRVhoRzwAAAX4"]
[Thu Sep 17 15:08:16.052406 2026] [security2:error] [pid 955873:tid 956025] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR1wAAASA"]
[Thu Sep 17 15:08:16.141226 2026] [security2:error] [pid 955873:tid 956019] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR3AAAARo"]
[Thu Sep 17 15:08:16.236039 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR5AAAAWQ"]
[Thu Sep 17 15:08:16.268328 2026] [security2:error] [pid 955873:tid 956051] [client 34.94.67.131:37130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR5QAAATo"]
[Thu Sep 17 15:08:16.312960 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR6QAAAS8"]
[Thu Sep 17 15:08:16.381378 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR4gAAAQw"]
[Thu Sep 17 15:08:16.381399 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR4gAAAQw"]
[Thu Sep 17 15:08:16.400845 2026] [security2:error] [pid 955873:tid 956007] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR4wAAAQ4"]
[Thu Sep 17 15:08:16.434181 2026] [security2:error] [pid 955873:tid 956073] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR6wAAAVA"]
[Thu Sep 17 15:08:16.521000 2026] [security2:error] [pid 955873:tid 956097] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR8AAAAWg"]
[Thu Sep 17 15:08:16.522643 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/Basic.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8QAAAUA"]
[Thu Sep 17 15:08:16.522753 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:42216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Auth/Basic.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8QAAAUA"]
[Thu Sep 17 15:08:16.561499 2026] [security2:error] [pid 955873:tid 956124] [client 162.241.226.11:35398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR6gAAAYM"]
[Thu Sep 17 15:08:16.582438 2026] [security2:error] [pid 955873:tid 956023] [client 34.94.67.131:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8wAAAR4"]
[Thu Sep 17 15:08:16.607789 2026] [security2:error] [pid 955873:tid 956085] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR-AAAAVw"]
[Thu Sep 17 15:08:16.667570 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR_AAAAVc"]
[Thu Sep 17 15:08:16.697567 2026] [security2:error] [pid 955873:tid 956030] [client 4.240.114.86:65534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR_gAAASU"], referer: binance.com
[Thu Sep 17 15:08:16.732783 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoR_wAAAUE"]
[Thu Sep 17 15:08:16.767452 2026] [security2:error] [pid 955873:tid 956008] [client 162.241.226.11:35404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR9AAAAQ8"]
[Thu Sep 17 15:08:16.773442 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoR8gAAASw"]
[Thu Sep 17 15:08:16.802990 2026] [security2:error] [pid 955873:tid 956069] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoSAwAAAUw"]
[Thu Sep 17 15:08:16.812993 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:51340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBAAAAXU"]
[Thu Sep 17 15:08:16.813289 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:51340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBAAAAXU"]
[Thu Sep 17 15:08:16.815485 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Autoload.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBQAAASY"]
[Thu Sep 17 15:08:16.815559 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Autoload.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBQAAASY"]
[Thu Sep 17 15:08:16.834651 2026] [security2:error] [pid 955873:tid 956098] [client 34.166.190.5:35362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSBgAAAWk"]
[Thu Sep 17 15:08:16.878514 2026] [security2:error] [pid 955873:tid 956044] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoSCAAAATM"]
[Thu Sep 17 15:08:16.917202 2026] [security2:error] [pid 955873:tid 956075] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSAQABUhg"], referer: http://heromakers.org/wordpress/
[Thu Sep 17 15:08:16.970454 2026] [security2:error] [pid 955873:tid 956053] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxWwBFTPRVSLOsRVhoSDQAAATw"]
[Thu Sep 17 15:08:16.984186 2026] [security2:error] [pid 955873:tid 956029] [client 34.94.67.131:37134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSDgAAASQ"]
[Thu Sep 17 15:08:17.055581 2026] [security2:error] [pid 955873:tid 956020] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSFAAAARs"]
[Thu Sep 17 15:08:17.103691 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:42236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Capability.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSFgAAATI"]
[Thu Sep 17 15:08:17.103780 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:42236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Capability.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSFgAAATI"]
[Thu Sep 17 15:08:17.106123 2026] [security2:error] [pid 955873:tid 956050] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwBFTPRVSLOsRVhoSCwAAATk"]
[Thu Sep 17 15:08:17.154140 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSGQAAARI"]
[Thu Sep 17 15:08:17.227780 2026] [security2:error] [pid 955873:tid 956015] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSIgAAARY"]
[Thu Sep 17 15:08:17.300560 2026] [security2:error] [pid 955873:tid 956014] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSJgAAARU"]
[Thu Sep 17 15:08:17.362484 2026] [security2:error] [pid 955873:tid 955916] [remote 216.73.217.142:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWwRFTPRVSLOsRVhoSJwABOio"]
[Thu Sep 17 15:08:17.363027 2026] [security2:error] [pid 955873:tid 956028] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSHgABIxM"], referer: http://heromakers.org/old/
[Thu Sep 17 15:08:17.395146 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:42250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSKAAAAUQ"]
[Thu Sep 17 15:08:17.395232 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:42250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSKAAAAUQ"]
[Thu Sep 17 15:08:17.397860 2026] [security2:error] [pid 955873:tid 956040] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSKQAAAS8"]
[Thu Sep 17 15:08:17.439235 2026] [security2:error] [pid 955873:tid 956086] [client 34.94.67.131:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSKgAAAV0"]
[Thu Sep 17 15:08:17.454082 2026] [security2:error] [pid 955873:tid 956087] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSIwAAAV4"]
[Thu Sep 17 15:08:17.484763 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSLwAAASs"]
[Thu Sep 17 15:08:17.525252 2026] [security2:error] [pid 955873:tid 956083] [client 34.166.190.5:35378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSMQAAAVo"]
[Thu Sep 17 15:08:17.562666 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSNQAAAW4"]
[Thu Sep 17 15:08:17.650796 2026] [security2:error] [pid 955873:tid 956124] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSOwAAAYM"]
[Thu Sep 17 15:08:17.687988 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:42258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/"] [unique_id "aqxWwRFTPRVSLOsRVhoSPAAAAU8"]
[Thu Sep 17 15:08:17.706192 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSPgAAAR4"]
[Thu Sep 17 15:08:17.780474 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSQAAAASE"]
[Thu Sep 17 15:08:17.792840 2026] [security2:error] [pid 955873:tid 956038] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSNgAAAS0"]
[Thu Sep 17 15:08:17.803064 2026] [security2:error] [pid 955873:tid 956003] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSOgABCho"], referer: http://heromakers.org/backup/
[Thu Sep 17 15:08:17.832513 2026] [security2:error] [pid 955873:tid 956052] [client 45.137.215.217:60729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.215.137.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seandaviddeezyn.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSQwAAATs"], referer: https://seandaviddeezyn.com/
[Thu Sep 17 15:08:17.834029 2026] [security2:error] [pid 955873:tid 956085] [client 34.94.67.131:37148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSRAAAAVw"]
[Thu Sep 17 15:08:17.839987 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/"] [unique_id "aqxWwRFTPRVSLOsRVhoSQgAAAVc"]
[Thu Sep 17 15:08:17.845647 2026] [security2:error] [pid 955873:tid 956033] [client 177.55.205.211:8006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWwRFTPRVSLOsRVhoSPwABKCE"]
[Thu Sep 17 15:08:17.847160 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.bak"] [unique_id "aqxWwRFTPRVSLOsRVhoSRQAAAUo"]
[Thu Sep 17 15:08:17.854485 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSRgAAASU"]
[Thu Sep 17 15:08:17.907850 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.backup"] [unique_id "aqxWwRFTPRVSLOsRVhoSRwAAAQ8"]
[Thu Sep 17 15:08:17.962357 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxWwRFTPRVSLOsRVhoSSwAAAU4"]
[Thu Sep 17 15:08:17.979848 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:42258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/wp-includes/Requests/src/"] [unique_id "aqxWwRFTPRVSLOsRVhoSTQAAAYc"]
[Thu Sep 17 15:08:18.024207 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSTgAAAWk"]
[Thu Sep 17 15:08:18.085329 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSUAAAATc"]
[Thu Sep 17 15:08:18.173375 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSVwAAASk"]
[Thu Sep 17 15:08:18.225325 2026] [security2:error] [pid 955873:tid 956035] [client 34.166.190.5:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSWQAAASo"]
[Thu Sep 17 15:08:18.251282 2026] [security2:error] [pid 955873:tid 956066] [client 46.101.94.213:47732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "heromakers.org"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSTwABSTE"], referer: http://heromakers.org/wp/
[Thu Sep 17 15:08:18.252167 2026] [security2:error] [pid 955873:tid 956118] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSWgAAAX0"]
[Thu Sep 17 15:08:18.265194 2026] [security2:error] [pid 955873:tid 956109] [client 34.94.67.131:37162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSWwAAAXQ"]
[Thu Sep 17 15:08:18.313969 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSUQAAATM"]
[Thu Sep 17 15:08:18.313990 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSUQAAATM"]
[Thu Sep 17 15:08:18.329858 2026] [security2:error] [pid 955873:tid 956090] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSXQAAAWE"]
[Thu Sep 17 15:08:18.344345 2026] [security2:error] [pid 955873:tid 956130] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSVQAAAYk"]
[Thu Sep 17 15:08:18.349254 2026] [security2:error] [pid 955873:tid 956029] [client 45.169.98.18:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSXgAAASQ"]
[Thu Sep 17 15:08:18.349680 2026] [security2:error] [pid 955873:tid 956029] [client 45.169.98.18:61202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSXgAAASQ"]
[Thu Sep 17 15:08:18.416095 2026] [security2:error] [pid 955873:tid 956043] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.old"] [unique_id "aqxWwhFTPRVSLOsRVhoSXwAAATI"]
[Thu Sep 17 15:08:18.422438 2026] [security2:error] [pid 955873:tid 956091] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSYAAAAWI"]
[Thu Sep 17 15:08:18.453719 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:42258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/Jar.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSYQAAATE"]
[Thu Sep 17 15:08:18.453795 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:42258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Cookie/Jar.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSYQAAATE"]
[Thu Sep 17 15:08:18.501671 2026] [security2:error] [pid 955873:tid 956024] [client 77.232.40.141:61786] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ojorojomusic.com"] [uri "/why-did-rock-music-get-popular/"] [unique_id "aqxWwhFTPRVSLOsRVhoSZwAAAR8"]
[Thu Sep 17 15:08:18.513189 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSaAAAAVY"]
[Thu Sep 17 15:08:18.583320 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSbAAAATY"]
[Thu Sep 17 15:08:18.672517 2026] [security2:error] [pid 955873:tid 956007] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoScgAAAQ4"]
[Thu Sep 17 15:08:18.696607 2026] [security2:error] [pid 955873:tid 956121] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSZQAAAYA"]
[Thu Sep 17 15:08:18.717461 2026] [security2:error] [pid 955873:tid 956127] [client 104.207.47.59:52579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/userswp/readme.txt"] [unique_id "aqxWwhFTPRVSLOsRVhoScwAAAYY"]
[Thu Sep 17 15:08:18.742362 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxWwhFTPRVSLOsRVhoSdAAAARg"]
[Thu Sep 17 15:08:18.757002 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSdQAAAUU"]
[Thu Sep 17 15:08:18.757079 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:42270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSdQAAAUU"]
[Thu Sep 17 15:08:18.892157 2026] [security2:error] [pid 955873:tid 956097] [client 34.94.67.131:37170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSfwAAAWg"]
[Thu Sep 17 15:08:18.910235 2026] [security2:error] [pid 955873:tid 956086] [client 34.166.190.5:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSgAAAAV0"]
[Thu Sep 17 15:08:19.037564 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:42284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/"] [unique_id "aqxWwxFTPRVSLOsRVhoSiAAAAVw"]
[Thu Sep 17 15:08:19.051981 2026] [security2:error] [pid 955873:tid 956103] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoSfQAAAW4"]
[Thu Sep 17 15:08:19.052626 2026] [security2:error] [pid 955873:tid 956080] [client 34.23.195.25:48786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSiQAAAVc"]
[Thu Sep 17 15:08:19.190563 2026] [security2:error] [pid 955873:tid 956052] [client 104.154.81.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxWwhFTPRVSLOsRVhoShwAAATs"]
[Thu Sep 17 15:08:19.194000 2026] [authz_core:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Exception/error_log
[Thu Sep 17 15:08:19.210478 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/"] [unique_id "aqxWwxFTPRVSLOsRVhoSkgAAAXU"]
[Thu Sep 17 15:08:19.311446 2026] [security2:error] [pid 955873:tid 956117] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSlgAAAXw"]
[Thu Sep 17 15:08:19.328010 2026] [security2:error] [pid 955873:tid 956032] [client 34.94.67.131:37172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSmAAAASc"]
[Thu Sep 17 15:08:19.349914 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:42284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/wp-includes/Requests/src/"] [unique_id "aqxWwxFTPRVSLOsRVhoSmQAAARs"]
[Thu Sep 17 15:08:19.384418 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSmgAAAXM"]
[Thu Sep 17 15:08:19.385536 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSjwAAASw"]
[Thu Sep 17 15:08:19.476654 2026] [security2:error] [pid 955873:tid 956099] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSoAAAAWo"]
[Thu Sep 17 15:08:19.591780 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSpwAAAR0"]
[Thu Sep 17 15:08:19.595679 2026] [security2:error] [pid 955873:tid 956044] [client 34.166.190.5:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSqAAAATM"]
[Thu Sep 17 15:08:19.601214 2026] [security2:error] [pid 955873:tid 956009] [client 4.240.114.86:50832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSqQAAARA"], referer: binance.com
[Thu Sep 17 15:08:19.664481 2026] [security2:error] [pid 955873:tid 956079] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSrQAAAVY"]
[Thu Sep 17 15:08:19.705870 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSoQAAASQ"]
[Thu Sep 17 15:08:19.705896 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSoQAAASQ"]
[Thu Sep 17 15:08:19.733680 2026] [security2:error] [pid 955873:tid 956047] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSsAAAATY"]
[Thu Sep 17 15:08:19.743110 2026] [security2:error] [pid 955873:tid 956064] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoSpQAAAUc"]
[Thu Sep 17 15:08:19.819930 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSswAAAWQ"]
[Thu Sep 17 15:08:19.843685 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/ArgumentCount.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStgAAAXk"]
[Thu Sep 17 15:08:19.843774 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/ArgumentCount.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStgAAAXk"]
[Thu Sep 17 15:08:19.866616 2026] [security2:error] [pid 955873:tid 956051] [client 34.94.67.131:58794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqc.mgx.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStwAAATo"]
[Thu Sep 17 15:08:19.894128 2026] [security2:error] [pid 955873:tid 956004] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSuAAAAQs"]
[Thu Sep 17 15:08:19.963348 2026] [security2:error] [pid 955873:tid 956017] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxWwxFTPRVSLOsRVhoSuQAAARg"]
[Thu Sep 17 15:08:20.036903 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSvAAAARM"]
[Thu Sep 17 15:08:20.060504 2026] [security2:error] [pid 955873:tid 956011] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWwxFTPRVSLOsRVhoStQAAARI"]
[Thu Sep 17 15:08:20.113978 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSvQAAAWw"]
[Thu Sep 17 15:08:20.124452 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSvwAAARo"]
[Thu Sep 17 15:08:20.124533 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSvwAAARo"]
[Thu Sep 17 15:08:20.219962 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSxgAAAYE"]
[Thu Sep 17 15:08:20.278715 2026] [security2:error] [pid 955873:tid 956104] [client 34.166.190.5:35406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSxwAAAW8"]
[Thu Sep 17 15:08:20.297283 2026] [security2:error] [pid 955873:tid 956003] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSyAAAAQo"]
[Thu Sep 17 15:08:20.347929 2026] [security2:error] [pid 955873:tid 956023] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSwQAAAR4"]
[Thu Sep 17 15:08:20.365702 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoSywAAASg"]
[Thu Sep 17 15:08:20.374433 2026] [security2:error] [pid 955873:tid 956085] [client 34.95.188.156:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSyQAAAVw"]
[Thu Sep 17 15:08:20.379540 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSzQAAAWU"]
[Thu Sep 17 15:08:20.379605 2026] [security2:error] [pid 955873:tid 956094] [client 115.244.164.14:55532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxBFTPRVSLOsRVhoSzQAAAWU"]
[Thu Sep 17 15:08:20.415565 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:53648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/"] [unique_id "aqxWxBFTPRVSLOsRVhoSzgAAAQ8"]
[Thu Sep 17 15:08:20.459739 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS0gAAASY"]
[Thu Sep 17 15:08:20.543058 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS1QAAATc"]
[Thu Sep 17 15:08:20.580719 2026] [authz_core:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Exception/Http/error_log
[Thu Sep 17 15:08:20.596084 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/"] [unique_id "aqxWxBFTPRVSLOsRVhoS1gAAAXU"]
[Thu Sep 17 15:08:20.602995 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS1wAAASo"]
[Thu Sep 17 15:08:20.668371 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS0wAAARE"]
[Thu Sep 17 15:08:20.674523 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS3QAAAXQ"]
[Thu Sep 17 15:08:20.739581 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:53648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/wp-includes/Requests/src/Exception/"] [unique_id "aqxWxBFTPRVSLOsRVhoS4gAAAVg"]
[Thu Sep 17 15:08:20.740595 2026] [security2:error] [pid 955873:tid 956057] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS4wAAAUA"]
[Thu Sep 17 15:08:20.859739 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.188.156:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/info.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS6AAAAUM"]
[Thu Sep 17 15:08:20.869862 2026] [security2:error] [pid 955873:tid 956039] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS6QAAAS4"]
[Thu Sep 17 15:08:20.959453 2026] [security2:error] [pid 955873:tid 956022] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxWxBFTPRVSLOsRVhoS7AAAAR0"]
[Thu Sep 17 15:08:20.967575 2026] [security2:error] [pid 955873:tid 956130] [client 34.166.190.5:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS7QAAAYk"]
[Thu Sep 17 15:08:20.980625 2026] [security2:error] [pid 955873:tid 956125] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS5AAAAYQ"]
[Thu Sep 17 15:08:21.058808 2026] [security2:error] [pid 955873:tid 956116] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoS9AAAAXs"]
[Thu Sep 17 15:08:21.112231 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:52532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS6gAAATE"]
[Thu Sep 17 15:08:21.112256 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS6gAAATE"]
[Thu Sep 17 15:08:21.132239 2026] [security2:error] [pid 955873:tid 956093] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoS-AAAAWQ"]
[Thu Sep 17 15:08:21.191352 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoS_QAAAT4"]
[Thu Sep 17 15:08:21.225284 2026] [security2:error] [pid 955873:tid 956099] [client 154.190.208.131:41747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS_gAAAWo"]
[Thu Sep 17 15:08:21.225472 2026] [security2:error] [pid 955873:tid 956099] [client 154.190.208.131:41747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS_gAAAWo"]
[Thu Sep 17 15:08:21.252578 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status304.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTAAAAATo"]
[Thu Sep 17 15:08:21.252727 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:53648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status304.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTAAAAATo"]
[Thu Sep 17 15:08:21.283133 2026] [security2:error] [pid 955873:tid 956045] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTAwAAATQ"]
[Thu Sep 17 15:08:21.317862 2026] [security2:error] [pid 955873:tid 956040] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS9gAAAS8"]
[Thu Sep 17 15:08:21.332580 2026] [security2:error] [pid 955873:tid 956029] [client 40.77.167.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoS8QAAASQ"]
[Thu Sep 17 15:08:21.349416 2026] [security2:error] [pid 955873:tid 956087] [client 34.95.188.156:55200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/php.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTBwAAAV4"]
[Thu Sep 17 15:08:21.354219 2026] [security2:error] [pid 955873:tid 956011] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTCQAAARI"]
[Thu Sep 17 15:08:21.500466 2026] [security2:error] [pid 955873:tid 956023] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTCwAAAR4"]
[Thu Sep 17 15:08:21.530059 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:53662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status305.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTDQAAAVc"]
[Thu Sep 17 15:08:21.530155 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:53662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status305.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTDQAAAVc"]
[Thu Sep 17 15:08:21.573458 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTEgAAAWU"]
[Thu Sep 17 15:08:21.663911 2026] [security2:error] [pid 955873:tid 956070] [client 34.166.190.5:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTGQAAAU0"]
[Thu Sep 17 15:08:21.676950 2026] [security2:error] [pid 955873:tid 956031] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTGgAAASY"]
[Thu Sep 17 15:08:21.731322 2026] [security2:error] [pid 955873:tid 956082] [client 104.207.47.59:12363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "threadalittlelight.com"] [uri "/wp-content/plugins/bookingpress-appointment-booking/readme.txt"] [unique_id "aqxWxRFTPRVSLOsRVhoTHgAAAVk"]
[Thu Sep 17 15:08:21.775411 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTEQAAAT0"]
[Thu Sep 17 15:08:21.787469 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTIAAAARE"]
[Thu Sep 17 15:08:21.816148 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:53664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status306.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTIQAAASc"]
[Thu Sep 17 15:08:21.816272 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:53664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status306.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTIQAAASc"]
[Thu Sep 17 15:08:21.842447 2026] [security2:error] [pid 955873:tid 956052] [client 34.95.188.156:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/i.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTIgAAATs"]
[Thu Sep 17 15:08:21.886139 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTJAAAAYg"]
[Thu Sep 17 15:08:21.993342 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxWxRFTPRVSLOsRVhoTKgAAAXc"]
[Thu Sep 17 15:08:22.099383 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:53670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status400.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTOQAAAR8"]
[Thu Sep 17 15:08:22.099516 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:53670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status400.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTOQAAAR8"]
[Thu Sep 17 15:08:22.100961 2026] [security2:error] [pid 955873:tid 956059] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTOgAAAUI"]
[Thu Sep 17 15:08:22.179118 2026] [security2:error] [pid 955873:tid 956058] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTQQAAAUE"]
[Thu Sep 17 15:08:22.193526 2026] [security2:error] [pid 955873:tid 956111] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxRFTPRVSLOsRVhoTKQAAAXY"]
[Thu Sep 17 15:08:22.277864 2026] [security2:error] [pid 955873:tid 956012] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTRQAAARM"]
[Thu Sep 17 15:08:22.319022 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env.swp"] [unique_id "aqxWxhFTPRVSLOsRVhoTRwAAAXI"]
[Thu Sep 17 15:08:22.339172 2026] [security2:error] [pid 955873:tid 956096] [client 34.95.188.156:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/pi.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTSAAAAWc"]
[Thu Sep 17 15:08:22.371120 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.env~"] [unique_id "aqxWxhFTPRVSLOsRVhoTTAAAATY"]
[Thu Sep 17 15:08:22.374004 2026] [security2:error] [pid 955873:tid 956021] [client 134.185.85.61:49969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "ppfc.net"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxWxhFTPRVSLOsRVhoTTQAAARw"]
[Thu Sep 17 15:08:22.374886 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTTgAAAWw"]
[Thu Sep 17 15:08:22.383326 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status401.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTTwAAARo"]
[Thu Sep 17 15:08:22.383399 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:53678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status401.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTTwAAARo"]
[Thu Sep 17 15:08:22.500553 2026] [security2:error] [pid 955873:tid 956122] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTVAAAAYE"]
[Thu Sep 17 15:08:22.587437 2026] [security2:error] [pid 955873:tid 956103] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTWQAAAW4"]
[Thu Sep 17 15:08:22.610528 2026] [security2:error] [pid 955873:tid 956080] [client 34.166.190.5:35430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTWgAAAVc"]
[Thu Sep 17 15:08:22.666429 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status402.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTXQAAAUo"]
[Thu Sep 17 15:08:22.666566 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status402.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTXQAAAUo"]
[Thu Sep 17 15:08:22.676531 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTXgAAASU"]
[Thu Sep 17 15:08:22.716896 2026] [security2:error] [pid 955873:tid 956104] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTVQAAAW8"]
[Thu Sep 17 15:08:22.752758 2026] [security2:error] [pid 955873:tid 956120] [client 134.185.85.61:62432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "ppfc.net"] [uri "/media/system/js/core.js"] [unique_id "aqxWxhFTPRVSLOsRVhoTYAAAAX8"]
[Thu Sep 17 15:08:22.781161 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTYgAAATc"]
[Thu Sep 17 15:08:22.824291 2026] [security2:error] [pid 955873:tid 956094] [client 34.95.188.156:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/pinfo.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTZAAAAWU"]
[Thu Sep 17 15:08:22.874921 2026] [security2:error] [pid 955873:tid 956035] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTZQAAASo"]
[Thu Sep 17 15:08:22.955173 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status403.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTaQAAAUk"]
[Thu Sep 17 15:08:22.955268 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:53700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status403.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTaQAAAUk"]
[Thu Sep 17 15:08:22.958908 2026] [security2:error] [pid 955873:tid 956010] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxWxhFTPRVSLOsRVhoTawAAARE"]
[Thu Sep 17 15:08:22.980634 2026] [security2:error] [pid 955873:tid 956078] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTRgABVVo"], referer: http://eco-tech.vn/wp/
[Thu Sep 17 15:08:23.048762 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTbwAAATs"]
[Thu Sep 17 15:08:23.095383 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxhFTPRVSLOsRVhoTZgAAAT0"]
[Thu Sep 17 15:08:23.167376 2026] [security2:error] [pid 955873:tid 956115] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTdQAAAXo"]
[Thu Sep 17 15:08:23.252955 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:53704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status404.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTeAAAAWI"]
[Thu Sep 17 15:08:23.253055 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:53704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status404.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTeAAAAWI"]
[Thu Sep 17 15:08:23.305461 2026] [security2:error] [pid 955873:tid 956036] [client 34.95.188.156:55246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/test.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTfAAAASs"]
[Thu Sep 17 15:08:23.308886 2026] [security2:error] [pid 955873:tid 956118] [client 34.166.190.5:56038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTfgAAAX0"]
[Thu Sep 17 15:08:23.326606 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTgAAAAXM"]
[Thu Sep 17 15:08:23.414773 2026] [security2:error] [pid 955873:tid 956024] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTgwAAAR8"]
[Thu Sep 17 15:08:23.509458 2026] [core:error] [pid 955873:tid 956000] [remote 180.153.197.114:47586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.509475 2026] [core:error] [pid 955873:tid 956000] [remote 180.153.197.114:47586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.510981 2026] [core:error] [pid 955873:tid 955991] [remote 180.153.197.67:35940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.510992 2026] [core:error] [pid 955873:tid 955991] [remote 180.153.197.67:35940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.chabelo.com/robots.txt
[Thu Sep 17 15:08:23.516091 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTiAAAATo"]
[Thu Sep 17 15:08:23.530618 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status405.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTiQAAAR0"]
[Thu Sep 17 15:08:23.530723 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:53714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status405.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTiQAAAR0"]
[Thu Sep 17 15:08:23.585290 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTiwAAATI"]
[Thu Sep 17 15:08:23.597680 2026] [security2:error] [pid 955873:tid 956079] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTggAAAVY"]
[Thu Sep 17 15:08:23.721997 2026] [security2:error] [pid 955873:tid 956083] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTkAAAAVo"]
[Thu Sep 17 15:08:23.812331 2026] [security2:error] [pid 955873:tid 956121] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTlAAAAYA"]
[Thu Sep 17 15:08:23.816561 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:53720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status406.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTlQAAAXI"]
[Thu Sep 17 15:08:23.816640 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:53720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status406.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTlQAAAXI"]
[Thu Sep 17 15:08:23.890099 2026] [security2:error] [pid 955873:tid 956119] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTmAAAAX4"]
[Thu Sep 17 15:08:23.923609 2026] [security2:error] [pid 955873:tid 956106] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTjwABcVs"], referer: http://eco-tech.vn/wordpress/
[Thu Sep 17 15:08:23.965259 2026] [security2:error] [pid 955873:tid 956019] [client 34.95.188.156:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/p.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTmQAAARo"]
[Thu Sep 17 15:08:23.982933 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxWxxFTPRVSLOsRVhoTnQAAAS0"]
[Thu Sep 17 15:08:24.006359 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.190.5:56040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTngAAASQ"]
[Thu Sep 17 15:08:24.086543 2026] [security2:error] [pid 955873:tid 956104] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTowAAAW8"]
[Thu Sep 17 15:08:24.108850 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status407.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTpAAAAU0"]
[Thu Sep 17 15:08:24.108960 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status407.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTpAAAAU0"]
[Thu Sep 17 15:08:24.174830 2026] [security2:error] [pid 955873:tid 956021] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWxxFTPRVSLOsRVhoTmgAAARw"]
[Thu Sep 17 15:08:24.217440 2026] [security2:error] [pid 955873:tid 956124] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTqwAAAYM"]
[Thu Sep 17 15:08:24.289978 2026] [security2:error] [pid 955873:tid 956114] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTrQAAAXk"]
[Thu Sep 17 15:08:24.354322 2026] [security2:error] [pid 955873:tid 956113] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTrgAAAXg"]
[Thu Sep 17 15:08:24.397023 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:53730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status408.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTrwAAATs"]
[Thu Sep 17 15:08:24.397124 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:53730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status408.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTrwAAATs"]
[Thu Sep 17 15:08:24.442432 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:38278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTrAAAASo"]
[Thu Sep 17 15:08:24.464975 2026] [security2:error] [pid 955873:tid 956010] [client 34.95.188.156:39846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/debug.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTsgAAARE"]
[Thu Sep 17 15:08:24.511422 2026] [security2:error] [pid 955873:tid 956109] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTswAAAXQ"]
[Thu Sep 17 15:08:24.606902 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTtgAAASE"]
[Thu Sep 17 15:08:24.686606 2026] [security2:error] [pid 955873:tid 956082] [client 34.166.190.5:56054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTvAAAAVk"]
[Thu Sep 17 15:08:24.695159 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status409.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTvgAAARQ"]
[Thu Sep 17 15:08:24.695247 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status409.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTvgAAARQ"]
[Thu Sep 17 15:08:24.712521 2026] [security2:error] [pid 955873:tid 956130] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTvwAAAYk"]
[Thu Sep 17 15:08:24.833420 2026] [security2:error] [pid 955873:tid 956128] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTuAAAAYc"]
[Thu Sep 17 15:08:24.864527 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:48794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxWyBFTPRVSLOsRVhoTwQAAASw"]
[Thu Sep 17 15:08:24.948410 2026] [security2:error] [pid 955873:tid 956034] [client 34.23.195.25:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTxAAAASk"]
[Thu Sep 17 15:08:24.974644 2026] [security2:error] [pid 955873:tid 956006] [client 34.95.188.156:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTxgAAAQ0"]
[Thu Sep 17 15:08:25.045450 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status410.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTyAAAAWQ"]
[Thu Sep 17 15:08:25.045560 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status410.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTyAAAAWQ"]
[Thu Sep 17 15:08:25.172348 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyBFTPRVSLOsRVhoTxQAAAUA"]
[Thu Sep 17 15:08:25.277642 2026] [security2:error] [pid 955873:tid 956017] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/app/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoTzgAAARg"]
[Thu Sep 17 15:08:25.279719 2026] [security2:error] [pid 955873:tid 956027] [client 40.77.167.67:1721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kimleightpc.com"] [uri "/index.php"] [unique_id "aqxWxBFTPRVSLOsRVhoS5wABIkY"]
[Thu Sep 17 15:08:25.331969 2026] [security2:error] [pid 955873:tid 956092] [client 34.23.195.25:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/info.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTzwAAAWM"]
[Thu Sep 17 15:08:25.334521 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:53756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status411.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT0AAAAUg"]
[Thu Sep 17 15:08:25.334644 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:53756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status411.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT0AAAAUg"]
[Thu Sep 17 15:08:25.339064 2026] [security2:error] [pid 955873:tid 956075] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/apps/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT0QAAAVI"]
[Thu Sep 17 15:08:25.387011 2026] [security2:error] [pid 955873:tid 956116] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT0wAAAXs"]
[Thu Sep 17 15:08:25.393664 2026] [security2:error] [pid 955873:tid 956022] [client 34.166.190.5:56058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT1AAAAR0"]
[Thu Sep 17 15:08:25.414074 2026] [security2:error] [pid 955873:tid 956051] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWyRFTPRVSLOsRVhoTyQABOmY"], referer: http://eco-tech.vn/backup/
[Thu Sep 17 15:08:25.471776 2026] [security2:error] [pid 955873:tid 956004] [client 34.95.188.156:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/test/phpinfo.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT1QAAAQs"]
[Thu Sep 17 15:08:25.484630 2026] [security2:error] [pid 955873:tid 956101] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/web/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT1gAAAWw"]
[Thu Sep 17 15:08:25.547979 2026] [security2:error] [pid 955873:tid 956042] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/site/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT1wAAATE"]
[Thu Sep 17 15:08:25.633618 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:53758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status412.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT2wAAAYE"]
[Thu Sep 17 15:08:25.633735 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:53758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status412.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT2wAAAYE"]
[Thu Sep 17 15:08:25.687553 2026] [security2:error] [pid 955873:tid 956038] [client 34.23.195.25:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/php.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT3QAAAS0"]
[Thu Sep 17 15:08:25.693018 2026] [security2:error] [pid 955873:tid 956029] [client 23.120.8.137:54163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT2QABJAo"]
[Thu Sep 17 15:08:25.710408 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/public/.env"] [unique_id "aqxWyRFTPRVSLOsRVhoT3wAAAQ8"]
[Thu Sep 17 15:08:25.931039 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:53764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status413.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT5AAAAX8"]
[Thu Sep 17 15:08:25.931141 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:53764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status413.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT5AAAAX8"]
[Thu Sep 17 15:08:25.980954 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.188.156:39876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT5gAAAUU"]
[Thu Sep 17 15:08:26.042307 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxWyRFTPRVSLOsRVhoT4wAAAUs"]
[Thu Sep 17 15:08:26.062343 2026] [security2:error] [pid 955873:tid 956048] [client 34.23.195.25:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/i.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT5wAAATc"]
[Thu Sep 17 15:08:26.098197 2026] [security2:error] [pid 955873:tid 956067] [client 34.166.190.5:56064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT6wAAAUo"]
[Thu Sep 17 15:08:26.144462 2026] [security2:error] [pid 955873:tid 956127] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/backend/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT7gAAAYY"]
[Thu Sep 17 15:08:26.224938 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:53770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status414.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT8QAAAYI"]
[Thu Sep 17 15:08:26.225048 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:53770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status414.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT8QAAAYI"]
[Thu Sep 17 15:08:26.257681 2026] [security2:error] [pid 955873:tid 956113] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/server/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT8wAAAXg"]
[Thu Sep 17 15:08:26.338631 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/frontend/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT9QAAARE"]
[Thu Sep 17 15:08:26.371387 2026] [security2:error] [pid 955873:tid 956052] [client 34.23.195.25:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT9gAAATs"]
[Thu Sep 17 15:08:26.422012 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/src/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT-QAAAYg"]
[Thu Sep 17 15:08:26.422499 2026] [security2:error] [pid 955873:tid 956089] [client 186.105.232.15:57791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT-gAAAWA"]
[Thu Sep 17 15:08:26.422604 2026] [security2:error] [pid 955873:tid 956089] [client 186.105.232.15:57791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT-gAAAWA"]
[Thu Sep 17 15:08:26.455597 2026] [security2:error] [pid 955873:tid 956114] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT7AABeVQ"], referer: http://eco-tech.vn/new/
[Thu Sep 17 15:08:26.483182 2026] [security2:error] [pid 955873:tid 956013] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/core/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT_AAAARQ"]
[Thu Sep 17 15:08:26.486891 2026] [security2:error] [pid 955873:tid 956086] [client 34.95.188.156:39882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/old/phpinfo.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT_QAAAV0"]
[Thu Sep 17 15:08:26.513385 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:53784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status415.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT_gAAAYk"]
[Thu Sep 17 15:08:26.513505 2026] [security2:error] [pid 955873:tid 956130] [client 143.244.57.120:53784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status415.php"] [unique_id "aqxWyhFTPRVSLOsRVhoT_gAAAYk"]
[Thu Sep 17 15:08:26.554259 2026] [security2:error] [pid 955873:tid 956125] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/core/app/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoT_wAAAYQ"]
[Thu Sep 17 15:08:26.655358 2026] [security2:error] [pid 955873:tid 956049] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/config/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUAQAAATg"]
[Thu Sep 17 15:08:26.737589 2026] [security2:error] [pid 955873:tid 956036] [client 34.23.195.25:54222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUBAAAASs"]
[Thu Sep 17 15:08:26.775871 2026] [security2:error] [pid 955873:tid 956006] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/private/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUBQAAAQ0"]
[Thu Sep 17 15:08:26.805162 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status416.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUBwAAAWQ"]
[Thu Sep 17 15:08:26.805328 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:53786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status416.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUBwAAAWQ"]
[Thu Sep 17 15:08:26.895285 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/application/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUCAAAAUA"]
[Thu Sep 17 15:08:26.983420 2026] [security2:error] [pid 955873:tid 956079] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/bootstrap/.env"] [unique_id "aqxWyhFTPRVSLOsRVhoUCQAAAVY"]
[Thu Sep 17 15:08:26.994082 2026] [security2:error] [pid 955873:tid 956043] [client 34.23.195.25:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/test.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUCgAAATI"]
[Thu Sep 17 15:08:26.994891 2026] [security2:error] [pid 955873:tid 956058] [client 34.95.188.156:39894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWyhFTPRVSLOsRVhoUCwAAAUE"]
[Thu Sep 17 15:08:27.072758 2026] [security2:error] [pid 955873:tid 956045] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/database/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUDQAAATQ"]
[Thu Sep 17 15:08:27.100433 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status417.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUDgAAAVo"]
[Thu Sep 17 15:08:27.100560 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:53802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status417.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUDgAAAVo"]
[Thu Sep 17 15:08:27.133332 2026] [security2:error] [pid 955873:tid 956087] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/storage/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUEAAAAV4"]
[Thu Sep 17 15:08:27.209154 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/var/www/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUEQAAAQw"]
[Thu Sep 17 15:08:27.294960 2026] [security2:error] [pid 955873:tid 956060] [client 34.166.190.5:56074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWyxFTPRVSLOsRVhoUFQAAAUM"]
[Thu Sep 17 15:08:27.368361 2026] [security2:error] [pid 955873:tid 956106] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/var/www/html/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUGAAAAXE"]
[Thu Sep 17 15:08:27.369891 2026] [security2:error] [pid 955873:tid 955983] [remote 216.73.217.142:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxWyxFTPRVSLOsRVhoUGQABdm0"]
[Thu Sep 17 15:08:27.395535 2026] [security2:error] [pid 955873:tid 956055] [client 34.23.195.25:54246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/p.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUGgAAAT4"]
[Thu Sep 17 15:08:27.397719 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:53808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status418.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUGwAAAQs"]
[Thu Sep 17 15:08:27.397817 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:53808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status418.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUGwAAAQs"]
[Thu Sep 17 15:08:27.492243 2026] [security2:error] [pid 955873:tid 956042] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/current/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUHQAAATE"]
[Thu Sep 17 15:08:27.495189 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.188.156:39896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/public/phpinfo.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUHgAAAWs"]
[Thu Sep 17 15:08:27.558312 2026] [security2:error] [pid 955873:tid 956116] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUEwABe38"], referer: http://eco-tech.vn/old/
[Thu Sep 17 15:08:27.575962 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:56115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUIAAAAVA"]
[Thu Sep 17 15:08:27.576072 2026] [security2:error] [pid 955873:tid 956073] [client 185.55.149.49:56115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUIAAAAVA"]
[Thu Sep 17 15:08:27.581465 2026] [security2:error] [pid 955873:tid 956011] [client 23.120.8.137:38047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUHwABEj0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821160102&hideanons=1&hidebots=0&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:27.584433 2026] [security2:error] [pid 955873:tid 956038] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/release/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUIQAAAS0"]
[Thu Sep 17 15:08:27.643834 2026] [security2:error] [pid 955873:tid 956029] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/releases/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUIgAAASQ"]
[Thu Sep 17 15:08:27.649175 2026] [security2:error] [pid 955873:tid 956008] [client 4.240.114.86:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUIwAAAQ8"], referer: binance.com
[Thu Sep 17 15:08:27.665637 2026] [security2:error] [pid 955873:tid 956047] [client 40.77.167.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUHAAAATY"]
[Thu Sep 17 15:08:27.686678 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status428.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUJAAAAU0"]
[Thu Sep 17 15:08:27.686760 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:53812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status428.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUJAAAAU0"]
[Thu Sep 17 15:08:27.711915 2026] [security2:error] [pid 955873:tid 956120] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/shared/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUJgAAAX8"]
[Thu Sep 17 15:08:27.798531 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/deploy/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUKAAAAUs"]
[Thu Sep 17 15:08:27.871940 2026] [security2:error] [pid 955873:tid 956062] [client 34.23.195.25:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUKQAAAUU"]
[Thu Sep 17 15:08:27.916753 2026] [security2:error] [pid 955873:tid 956061] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/build/.env"] [unique_id "aqxWyxFTPRVSLOsRVhoUKgAAAUQ"]
[Thu Sep 17 15:08:27.969265 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status429.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUKwAAAUo"]
[Thu Sep 17 15:08:27.969359 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:53820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status429.php"] [unique_id "aqxWyxFTPRVSLOsRVhoUKwAAAUo"]
[Thu Sep 17 15:08:27.985814 2026] [security2:error] [pid 955873:tid 956069] [client 34.166.190.5:56088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxWyxFTPRVSLOsRVhoULAAAAUw"]
[Thu Sep 17 15:08:28.007138 2026] [security2:error] [pid 955873:tid 956127] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/dist/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoULgAAAYY"]
[Thu Sep 17 15:08:28.106356 2026] [security2:error] [pid 955873:tid 956109] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/public_html/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUNQAAAXQ"]
[Thu Sep 17 15:08:28.157011 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/htdocs/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUOAAAAYg"]
[Thu Sep 17 15:08:28.179230 2026] [security2:error] [pid 955873:tid 956114] [client 34.95.188.156:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/php-info.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUOQAAAXk"]
[Thu Sep 17 15:08:28.225023 2026] [security2:error] [pid 955873:tid 956082] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/www/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUOgAAAVk"]
[Thu Sep 17 15:08:28.247541 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUPAAAASE"]
[Thu Sep 17 15:08:28.251860 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status431.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUPQAAARQ"]
[Thu Sep 17 15:08:28.251958 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:53824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status431.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUPQAAARQ"]
[Thu Sep 17 15:08:28.311194 2026] [security2:error] [pid 955873:tid 956115] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/html/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUPgAAAXo"]
[Thu Sep 17 15:08:28.403051 2026] [security2:error] [pid 955873:tid 956117] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/live/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUQQAAAXw"]
[Thu Sep 17 15:08:28.471973 2026] [security2:error] [pid 955873:tid 956030] [client 167.172.62.181:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eco-tech.vn"] [uri "/index.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUOwABJWA"], referer: http://eco-tech.vn/blog/
[Thu Sep 17 15:08:28.507255 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/prod/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoURQAAATA"]
[Thu Sep 17 15:08:28.533985 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status500.php"] [unique_id "aqxWzBFTPRVSLOsRVhoURgAAAX0"]
[Thu Sep 17 15:08:28.534064 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:53826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status500.php"] [unique_id "aqxWzBFTPRVSLOsRVhoURgAAAX0"]
[Thu Sep 17 15:08:28.578438 2026] [security2:error] [pid 955873:tid 956014] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/dev/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoURwAAARU"]
[Thu Sep 17 15:08:28.637966 2026] [security2:error] [pid 955873:tid 956049] [client 34.23.195.25:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUSQAAATg"]
[Thu Sep 17 15:08:28.675506 2026] [security2:error] [pid 955873:tid 956081] [client 34.95.188.156:39900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpversion.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUSgAAAVg"]
[Thu Sep 17 15:08:28.679418 2026] [security2:error] [pid 955873:tid 956088] [client 34.166.190.5:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUSwAAAV8"]
[Thu Sep 17 15:08:28.760273 2026] [security2:error] [pid 955873:tid 956093] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/staging/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUTAAAAWQ"]
[Thu Sep 17 15:08:28.822247 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status501.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTQAAAUA"]
[Thu Sep 17 15:08:28.822348 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:53842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status501.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTQAAAUA"]
[Thu Sep 17 15:08:28.847099 2026] [security2:error] [pid 955873:tid 956016] [client 45.169.98.18:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTgAAARc"]
[Thu Sep 17 15:08:28.847192 2026] [security2:error] [pid 955873:tid 956016] [client 45.169.98.18:61773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUTgAAARc"]
[Thu Sep 17 15:08:28.858847 2026] [security2:error] [pid 955873:tid 956059] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/opt/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUTwAAAUI"]
[Thu Sep 17 15:08:28.901075 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxWzBFTPRVSLOsRVhoUUgAAAXM"]
[Thu Sep 17 15:08:28.913263 2026] [security2:error] [pid 955873:tid 956017] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/laravel/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUVAAAARg"]
[Thu Sep 17 15:08:28.980631 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/symfony/.env"] [unique_id "aqxWzBFTPRVSLOsRVhoUVQAAAQw"]
[Thu Sep 17 15:08:29.106624 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:53846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status502.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUVgAAAXE"]
[Thu Sep 17 15:08:29.106727 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:53846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status502.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUVgAAAXE"]
[Thu Sep 17 15:08:29.159278 2026] [security2:error] [pid 955873:tid 956060] [client 34.95.188.156:39902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/_phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUVwAAAUM"]
[Thu Sep 17 15:08:29.196371 2026] [security2:error] [pid 955873:tid 956111] [client 34.23.195.25:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUWAAAAXY"]
[Thu Sep 17 15:08:29.315782 2026] [security2:error] [pid 955873:tid 956042] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/wordpress/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUXgAAATE"]
[Thu Sep 17 15:08:29.361841 2026] [security2:error] [pid 955873:tid 956055] [client 34.166.190.5:56116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUYAAAAT4"]
[Thu Sep 17 15:08:29.386631 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/wp/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUYgAAATY"]
[Thu Sep 17 15:08:29.393120 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status503.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUYwAAAQ4"]
[Thu Sep 17 15:08:29.393207 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:53862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status503.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUYwAAAQ4"]
[Thu Sep 17 15:08:29.485568 2026] [security2:error] [pid 955873:tid 956051] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cms/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUZQAAATo"]
[Thu Sep 17 15:08:29.577454 2026] [security2:error] [pid 955873:tid 956021] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/drupal/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUZgAAARw"]
[Thu Sep 17 15:08:29.579158 2026] [security2:error] [pid 955873:tid 956096] [client 34.23.195.25:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUZwAAAWc"]
[Thu Sep 17 15:08:29.653233 2026] [security2:error] [pid 955873:tid 956053] [client 34.95.188.156:39904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/old_phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUaAAAATw"]
[Thu Sep 17 15:08:29.678865 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:53876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status504.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUaQAAAWg"]
[Thu Sep 17 15:08:29.678958 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:53876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status504.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUaQAAAWg"]
[Thu Sep 17 15:08:29.688645 2026] [security2:error] [pid 955873:tid 956062] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/joomla/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUagAAAUU"]
[Thu Sep 17 15:08:29.774560 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/magento/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUawAAAUo"]
[Thu Sep 17 15:08:29.827732 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/shopify/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUbwAAASo"]
[Thu Sep 17 15:08:29.880981 2026] [security2:error] [pid 955873:tid 956071] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/prestashop/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUcgAAAU4"]
[Thu Sep 17 15:08:29.918903 2026] [security2:error] [pid 955873:tid 956074] [client 34.23.195.25:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUdAAAAVE"]
[Thu Sep 17 15:08:29.959944 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:39508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status505.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUdQAAAS4"]
[Thu Sep 17 15:08:29.960055 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:39508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status505.php"] [unique_id "aqxWzRFTPRVSLOsRVhoUdQAAAS4"]
[Thu Sep 17 15:08:29.973058 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/codeigniter/.env"] [unique_id "aqxWzRFTPRVSLOsRVhoUdgAAASw"]
[Thu Sep 17 15:08:30.021546 2026] [security2:error] [pid 955873:tid 956006] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cakephp/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUdwAAAQ0"]
[Thu Sep 17 15:08:30.057652 2026] [security2:error] [pid 955873:tid 956113] [client 34.166.190.5:56120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUeAAAAXg"]
[Thu Sep 17 15:08:30.067768 2026] [security2:error] [pid 955873:tid 956129] [client 45.115.26.203:48800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUegAAAYg"]
[Thu Sep 17 15:08:30.133645 2026] [security2:error] [pid 955873:tid 956082] [client 45.115.26.203:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/i.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUhgAAAVk"]
[Thu Sep 17 15:08:30.133672 2026] [security2:error] [pid 955873:tid 956015] [client 45.115.26.203:48982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/php_info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUhwAAARY"]
[Thu Sep 17 15:08:30.134115 2026] [security2:error] [pid 955873:tid 956013] [client 45.115.26.203:48950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/app/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUggAAARQ"]
[Thu Sep 17 15:08:30.134801 2026] [security2:error] [pid 955873:tid 956086] [client 45.115.26.203:48956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.bak"] [unique_id "aqxWzhFTPRVSLOsRVhoUiQAAAV0"]
[Thu Sep 17 15:08:30.135813 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/zend/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUigAAAXI"]
[Thu Sep 17 15:08:30.136871 2026] [security2:error] [pid 955873:tid 956102] [client 45.115.26.203:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/php-info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUkgAAAW0"]
[Thu Sep 17 15:08:30.137570 2026] [security2:error] [pid 955873:tid 956030] [client 45.115.26.203:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/test.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUlAAAASU"]
[Thu Sep 17 15:08:30.138417 2026] [security2:error] [pid 955873:tid 956118] [client 45.115.26.203:48980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUlQAAAX0"]
[Thu Sep 17 15:08:30.138503 2026] [security2:error] [pid 955873:tid 956041] [client 45.115.26.203:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUlwAAATA"]
[Thu Sep 17 15:08:30.138917 2026] [security2:error] [pid 955873:tid 956101] [client 45.115.26.203:49054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.backup"] [unique_id "aqxWzhFTPRVSLOsRVhoUlgAAAWw"]
[Thu Sep 17 15:08:30.139183 2026] [security2:error] [pid 955873:tid 956072] [client 45.115.26.203:48994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/pi.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUnQAAAU8"]
[Thu Sep 17 15:08:30.147650 2026] [security2:error] [pid 955873:tid 956125] [client 45.115.26.203:49010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/api/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUoQAAAYQ"]
[Thu Sep 17 15:08:30.149645 2026] [security2:error] [pid 955873:tid 956084] [client 34.95.188.156:39916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/server-info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUpgAAAVs"]
[Thu Sep 17 15:08:30.151622 2026] [security2:error] [pid 955873:tid 956049] [client 45.115.26.203:48928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/src/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUqwAAATg"]
[Thu Sep 17 15:08:30.151957 2026] [security2:error] [pid 955873:tid 956105] [client 45.115.26.203:49024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env~"] [unique_id "aqxWzhFTPRVSLOsRVhoUrAAAAXA"]
[Thu Sep 17 15:08:30.152442 2026] [security2:error] [pid 955873:tid 956128] [client 45.115.26.203:48834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUrQAAAYc"]
[Thu Sep 17 15:08:30.185617 2026] [security2:error] [pid 955873:tid 956088] [client 45.115.26.203:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.starrjoyblog.com"] [uri "/_phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUswAAAV8"]
[Thu Sep 17 15:08:30.193324 2026] [security2:error] [pid 955873:tid 956073] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/yii/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUtAAAAVA"]
[Thu Sep 17 15:08:30.220657 2026] [security2:error] [pid 955873:tid 956029] [client 45.115.26.203:48800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.old"] [unique_id "aqxWzhFTPRVSLOsRVhoUvAAAASQ"]
[Thu Sep 17 15:08:30.221364 2026] [security2:error] [pid 955873:tid 956093] [client 45.115.26.203:49062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/.env.swp"] [unique_id "aqxWzhFTPRVSLOsRVhoUvQAAAWQ"]
[Thu Sep 17 15:08:30.229006 2026] [security2:error] [pid 955873:tid 956059] [client 45.115.26.203:49076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.starrjoyblog.com"] [uri "/backend/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoUwQAAAUI"]
[Thu Sep 17 15:08:30.242904 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status511.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUyQAAAWU"]
[Thu Sep 17 15:08:30.243043 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/Status511.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUyQAAAWU"]
[Thu Sep 17 15:08:30.296502 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/laravel5/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU0wAAASo"]
[Thu Sep 17 15:08:30.361280 2026] [security2:error] [pid 955873:tid 956082] [client 34.23.195.25:54316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU1gAAAVk"]
[Thu Sep 17 15:08:30.388202 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/v1/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU2AAAAW0"]
[Thu Sep 17 15:08:30.404951 2026] [security2:error] [pid 955873:tid 956121] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUowAAAYA"]
[Thu Sep 17 15:08:30.410254 2026] [security2:error] [pid 955873:tid 956116] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUsgAAAXs"]
[Thu Sep 17 15:08:30.425003 2026] [security2:error] [pid 955873:tid 956024] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUuAAAAR8"]
[Thu Sep 17 15:08:30.449569 2026] [security2:error] [pid 955873:tid 956087] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUogAAAV4"]
[Thu Sep 17 15:08:30.524436 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/StatusUnknown.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU3QAAAWU"]
[Thu Sep 17 15:08:30.524541 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Http/StatusUnknown.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU3QAAAWU"]
[Thu Sep 17 15:08:30.533000 2026] [security2:error] [pid 955873:tid 956021] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/v2/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU3gAAARw"]
[Thu Sep 17 15:08:30.574398 2026] [access_compat:error] [pid 955873:tid 956117] [client 45.115.26.203:48936] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Thu Sep 17 15:08:30.633874 2026] [security2:error] [pid 955873:tid 956007] [client 34.95.188.156:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/server-status.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU4wAAAQ4"]
[Thu Sep 17 15:08:30.721768 2026] [security2:error] [pid 955873:tid 956009] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/v3/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU5gAAARA"]
[Thu Sep 17 15:08:30.729878 2026] [authz_core:error] [pid 955873:tid 956023] [client 20.244.34.24:51045] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:08:30.784955 2026] [security2:error] [pid 955873:tid 956066] [client 34.23.195.25:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU5wAAAUk"]
[Thu Sep 17 15:08:30.800553 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:39526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/InvalidArgument.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6AAAAXg"]
[Thu Sep 17 15:08:30.800620 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:39526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/InvalidArgument.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6AAAAXg"]
[Thu Sep 17 15:08:30.810534 2026] [security2:error] [pid 955873:tid 956059] [client 34.166.190.5:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6QAAAUI"]
[Thu Sep 17 15:08:30.814199 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/v1/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU6gAAARc"]
[Thu Sep 17 15:08:30.856168 2026] [security2:error] [pid 955873:tid 956096] [client 115.244.164.14:56166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6wAAAWc"]
[Thu Sep 17 15:08:30.856246 2026] [security2:error] [pid 955873:tid 956096] [client 115.244.164.14:56166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU6wAAAWc"]
[Thu Sep 17 15:08:30.947439 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/v2/.env"] [unique_id "aqxWzhFTPRVSLOsRVhoU7gAAAXI"]
[Thu Sep 17 15:08:31.056843 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/rest/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU8QAAATA"]
[Thu Sep 17 15:08:31.072961 2026] [security2:error] [pid 955873:tid 956030] [client 34.23.195.25:47512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU8wAAASU"]
[Thu Sep 17 15:08:31.078998 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:39538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU9QAAAWw"]
[Thu Sep 17 15:08:31.079080 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:39538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU9QAAAWw"]
[Thu Sep 17 15:08:31.251505 2026] [security2:error] [pid 955873:tid 956060] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/graphql/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU-AAAAUM"]
[Thu Sep 17 15:08:31.257864 2026] [security2:error] [pid 955873:tid 956011] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUugAAARI"]
[Thu Sep 17 15:08:31.275569 2026] [security2:error] [pid 955873:tid 956126] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUtQAAAYU"]
[Thu Sep 17 15:08:31.279750 2026] [security2:error] [pid 955873:tid 956003] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUvwAAAQo"]
[Thu Sep 17 15:08:31.294085 2026] [security2:error] [pid 955873:tid 956051] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUxwAAATo"]
[Thu Sep 17 15:08:31.298218 2026] [security2:error] [pid 955873:tid 956012] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUzQAAARM"]
[Thu Sep 17 15:08:31.301959 2026] [security2:error] [pid 955873:tid 956070] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUxQAAAU0"]
[Thu Sep 17 15:08:31.315704 2026] [security2:error] [pid 955873:tid 956104] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUxgAAAW8"]
[Thu Sep 17 15:08:31.320082 2026] [security2:error] [pid 955873:tid 956038] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUwwAAAS0"]
[Thu Sep 17 15:08:31.322830 2026] [security2:error] [pid 955873:tid 956064] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUywAAAUc"]
[Thu Sep 17 15:08:31.325572 2026] [security2:error] [pid 955873:tid 956111] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/gateway/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU-gAAAXY"]
[Thu Sep 17 15:08:31.325607 2026] [security2:error] [pid 955873:tid 956047] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUwgAAATY"]
[Thu Sep 17 15:08:31.326811 2026] [security2:error] [pid 955873:tid 956008] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoUzAAAAQ8"]
[Thu Sep 17 15:08:31.372499 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "aqxWzxFTPRVSLOsRVhoU-wAAAWk"]
[Thu Sep 17 15:08:31.379863 2026] [security2:error] [pid 955873:tid 956062] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU0gAAAUU"]
[Thu Sep 17 15:08:31.383115 2026] [security2:error] [pid 955873:tid 956033] [client 34.23.195.25:47524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxWzxFTPRVSLOsRVhoU_QAAASg"]
[Thu Sep 17 15:08:31.398507 2026] [security2:error] [pid 955873:tid 956085] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxWzhFTPRVSLOsRVhoU1QAAAVw"]
[Thu Sep 17 15:08:31.403503 2026] [security2:error] [pid 955873:tid 956031] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/microservice/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoU_wAAASY"]
[Thu Sep 17 15:08:31.481239 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/service/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVAAAAARc"]
[Thu Sep 17 15:08:31.497049 2026] [security2:error] [pid 955873:tid 956101] [client 34.95.188.156:39938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxWzxFTPRVSLOsRVhoVAQAAAWw"]
[Thu Sep 17 15:08:31.498394 2026] [security2:error] [pid 955873:tid 956050] [client 34.166.190.5:56134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxWzxFTPRVSLOsRVhoVAgAAATk"]
[Thu Sep 17 15:08:31.599494 2026] [security2:error] [pid 955873:tid 956060] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/v3/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVEwAAAUM"]
[Thu Sep 17 15:08:31.653509 2026] [security2:error] [pid 955873:tid 956105] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/dev/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVFAAAAXA"]
[Thu Sep 17 15:08:31.713267 2026] [security2:error] [pid 955873:tid 956087] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/api/staging/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVFgAAAV4"]
[Thu Sep 17 15:08:31.727764 2026] [security2:error] [pid 955873:tid 956108] [client 34.23.195.25:47538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxWzxFTPRVSLOsRVhoVFwAAAXM"]
[Thu Sep 17 15:08:31.780600 2026] [security2:error] [pid 955873:tid 956029] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/vendor/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVGAAAASQ"]
[Thu Sep 17 15:08:31.819696 2026] [authz_core:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Exception/Transport/error_log
[Thu Sep 17 15:08:31.821803 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "aqxWzxFTPRVSLOsRVhoVGQAAAUE"]
[Thu Sep 17 15:08:31.878424 2026] [core:error] [pid 955873:tid 956032] [client 173.252.70.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:31.878446 2026] [core:error] [pid 955873:tid 956032] [client 173.252.70.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:31.944451 2026] [security2:error] [pid 955873:tid 956040] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/lib/.env"] [unique_id "aqxWzxFTPRVSLOsRVhoVJAAAAS8"]
[Thu Sep 17 15:08:31.962244 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/wp-includes/Requests/src/Exception/"] [unique_id "aqxWzxFTPRVSLOsRVhoVJgAAAUs"]
[Thu Sep 17 15:08:31.983524 2026] [security2:error] [pid 955873:tid 956005] [client 162.62.213.165:35108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.213.62.162.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxWzxFTPRVSLOsRVhoVIwAAAQw"]
[Thu Sep 17 15:08:31.999100 2026] [security2:error] [pid 955873:tid 956104] [client 34.95.188.156:39952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxWzxFTPRVSLOsRVhoVJwAAAW8"]
[Thu Sep 17 15:08:32.029419 2026] [security2:error] [pid 955873:tid 956025] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/resources/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVKAAAASA"]
[Thu Sep 17 15:08:32.116833 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/assets/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVKwAAAUo"]
[Thu Sep 17 15:08:32.181546 2026] [security2:error] [pid 955873:tid 956046] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/uploads/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVLAAAATU"]
[Thu Sep 17 15:08:32.197193 2026] [security2:error] [pid 955873:tid 956111] [client 34.166.190.5:56138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxW0BFTPRVSLOsRVhoVLQAAAXY"]
[Thu Sep 17 15:08:32.227586 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:47540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVLgAAAQ8"]
[Thu Sep 17 15:08:32.274281 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/internal/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVMAAAAX4"]
[Thu Sep 17 15:08:32.309523 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVKgAAAUQ"]
[Thu Sep 17 15:08:32.309552 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVKgAAAUQ"]
[Thu Sep 17 15:08:32.373054 2026] [security2:error] [pid 955873:tid 956074] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/tools/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVMQAAAVE"]
[Thu Sep 17 15:08:32.422974 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVMgAAATc"]
[Thu Sep 17 15:08:32.423068 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVMgAAATc"]
[Thu Sep 17 15:08:32.482905 2026] [security2:error] [pid 955873:tid 956006] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/scripts/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVNQAAAQ0"]
[Thu Sep 17 15:08:32.495573 2026] [security2:error] [pid 955873:tid 956054] [client 34.95.188.156:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVNwAAAT0"]
[Thu Sep 17 15:08:32.535504 2026] [security2:error] [pid 955873:tid 956023] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/bin/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVOgAAAR4"]
[Thu Sep 17 15:08:32.617335 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:39544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/Curl.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVQQAAATQ"]
[Thu Sep 17 15:08:32.617475 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Exception/Transport/Curl.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVQQAAATQ"]
[Thu Sep 17 15:08:32.668499 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sbin/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVRAAAAW0"]
[Thu Sep 17 15:08:32.728929 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/local/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVRwAAAWA"]
[Thu Sep 17 15:08:32.799368 2026] [security2:error] [pid 955873:tid 956011] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/portal/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVSQAAARI"]
[Thu Sep 17 15:08:32.842651 2026] [security2:error] [pid 955873:tid 956037] [client 34.23.195.25:47544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxW0BFTPRVSLOsRVhoVSgAAASw"]
[Thu Sep 17 15:08:32.882350 2026] [security2:error] [pid 955873:tid 956125] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/dashboard/.env"] [unique_id "aqxW0BFTPRVSLOsRVhoVSwAAAYQ"]
[Thu Sep 17 15:08:32.896341 2026] [security2:error] [pid 955873:tid 956107] [client 34.166.190.5:56148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxW0BFTPRVSLOsRVhoVTQAAAXI"]
[Thu Sep 17 15:08:32.899967 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/HookManager.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVTgAAAXM"]
[Thu Sep 17 15:08:32.900074 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:39560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/HookManager.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVTgAAAXM"]
[Thu Sep 17 15:08:32.988264 2026] [security2:error] [pid 955873:tid 956055] [client 4.240.114.86:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVUwAAAT4"], referer: binance.com
[Thu Sep 17 15:08:32.989844 2026] [security2:error] [pid 955873:tid 956114] [client 34.95.188.156:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxW0BFTPRVSLOsRVhoVVAAAAXk"]
[Thu Sep 17 15:08:33.021204 2026] [security2:error] [pid 955873:tid 956084] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/panel/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVVQAAAVs"]
[Thu Sep 17 15:08:33.108787 2026] [security2:error] [pid 955873:tid 956032] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/crm/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVVwAAASc"]
[Thu Sep 17 15:08:33.162737 2026] [security2:error] [pid 955873:tid 956128] [client 34.23.195.25:47554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVWQAAAYc"]
[Thu Sep 17 15:08:33.208204 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:39568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Hooks.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVWwAAAWY"]
[Thu Sep 17 15:08:33.208299 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:39568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Hooks.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVWwAAAWY"]
[Thu Sep 17 15:08:33.227683 2026] [security2:error] [pid 955873:tid 956019] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/erp/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVXAAAARo"]
[Thu Sep 17 15:08:33.301362 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/shop/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVXQAAAUs"]
[Thu Sep 17 15:08:33.366101 2026] [security2:error] [pid 955873:tid 956067] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/store/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVXgAAAUo"]
[Thu Sep 17 15:08:33.474195 2026] [security2:error] [pid 955873:tid 956007] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/saas/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVYgAAAQ4"]
[Thu Sep 17 15:08:33.496391 2026] [security2:error] [pid 955873:tid 956104] [client 34.95.188.156:39976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVYwAAAW8"]
[Thu Sep 17 15:08:33.503961 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/IdnaEncoder.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVZAAAAWU"]
[Thu Sep 17 15:08:33.504025 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/IdnaEncoder.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVZAAAAWU"]
[Thu Sep 17 15:08:33.514779 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:47568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVZQAAAQ8"]
[Thu Sep 17 15:08:33.565085 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/client/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVZwAAAX4"]
[Thu Sep 17 15:08:33.602190 2026] [security2:error] [pid 955873:tid 956076] [client 34.166.190.5:48094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxW0RFTPRVSLOsRVhoVaQAAAVM"]
[Thu Sep 17 15:08:33.684807 2026] [security2:error] [pid 955873:tid 956061] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/project/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVagAAAUQ"]
[Thu Sep 17 15:08:33.798504 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:39588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ipv6.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVbAAAATI"]
[Thu Sep 17 15:08:33.798580 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:39588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ipv6.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVbAAAATI"]
[Thu Sep 17 15:08:33.878494 2026] [security2:error] [pid 955873:tid 956048] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/admin-panel/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVbQAAATc"]
[Thu Sep 17 15:08:33.926493 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:47570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxW0RFTPRVSLOsRVhoVbgAAAWk"]
[Thu Sep 17 15:08:33.953384 2026] [security2:error] [pid 955873:tid 956031] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/control-panel/.env"] [unique_id "aqxW0RFTPRVSLOsRVhoVbwAAASY"]
[Thu Sep 17 15:08:34.005993 2026] [security2:error] [pid 955873:tid 956062] [client 34.95.188.156:32884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVcgAAAUU"]
[Thu Sep 17 15:08:34.013738 2026] [security2:error] [pid 955873:tid 956109] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/user-panel/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVcwAAAXQ"]
[Thu Sep 17 15:08:34.088114 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:39604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Iri.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVdQAAAX8"]
[Thu Sep 17 15:08:34.088199 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:39604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Iri.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVdQAAAX8"]
[Thu Sep 17 15:08:34.119206 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/node/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVdgAAAYg"]
[Thu Sep 17 15:08:34.233188 2026] [security2:error] [pid 955873:tid 956009] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/express/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVdwAAARA"]
[Thu Sep 17 15:08:34.250481 2026] [autoindex:error] [pid 955873:tid 956066] [client 169.58.43.159:59256] AH01276: Cannot serve directory /home1/kolindco/public_html/t2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:08:34.300481 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.190.5:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxW0hFTPRVSLOsRVhoVegAAASs"]
[Thu Sep 17 15:08:34.340926 2026] [security2:error] [pid 955873:tid 956112] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/next/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVewAAAXc"]
[Thu Sep 17 15:08:34.351128 2026] [security2:error] [pid 955873:tid 956081] [client 34.23.195.25:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVfAAAAVg"]
[Thu Sep 17 15:08:34.385213 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Port.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVfQAAAUM"]
[Thu Sep 17 15:08:34.385283 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Port.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVfQAAAUM"]
[Thu Sep 17 15:08:34.421916 2026] [security2:error] [pid 955873:tid 956028] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/nuxt/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVfgAAASM"]
[Thu Sep 17 15:08:34.513026 2026] [security2:error] [pid 955873:tid 956078] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/nest/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVfwAAAVU"]
[Thu Sep 17 15:08:34.525103 2026] [security2:error] [pid 955873:tid 956089] [client 34.95.188.156:32888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxW0hFTPRVSLOsRVhoVggAAAWA"]
[Thu Sep 17 15:08:34.577471 2026] [security2:error] [pid 955873:tid 956107] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/react/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVgwAAAXI"]
[Thu Sep 17 15:08:34.671855 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVhgAAASQ"]
[Thu Sep 17 15:08:34.671943 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:39616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy.php"] [unique_id "aqxW0hFTPRVSLOsRVhoVhgAAASQ"]
[Thu Sep 17 15:08:34.701756 2026] [security2:error] [pid 955873:tid 956051] [client 34.23.195.25:47592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxW0hFTPRVSLOsRVhoViQAAATo"]
[Thu Sep 17 15:08:34.773520 2026] [security2:error] [pid 955873:tid 956118] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/vue/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVigAAAX0"]
[Thu Sep 17 15:08:34.863050 2026] [security2:error] [pid 955873:tid 956012] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/angular/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVjAAAARM"]
[Thu Sep 17 15:08:34.913022 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxW0hFTPRVSLOsRVhoVjQAAASc"]
[Thu Sep 17 15:08:34.919704 2026] [security2:error] [pid 955873:tid 956128] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/svelte/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVjgAAAYc"]
[Thu Sep 17 15:08:34.974143 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/"] [unique_id "aqxW0hFTPRVSLOsRVhoVkgAAAXU"]
[Thu Sep 17 15:08:34.976321 2026] [security2:error] [pid 955873:tid 956095] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/vite/.env"] [unique_id "aqxW0hFTPRVSLOsRVhoVkwAAAWY"]
[Thu Sep 17 15:08:35.002394 2026] [security2:error] [pid 955873:tid 956058] [client 34.166.190.5:48112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVlgAAAUE"]
[Thu Sep 17 15:08:35.038796 2026] [security2:error] [pid 955873:tid 956057] [client 34.95.188.156:32900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php.old"] [unique_id "aqxW0xFTPRVSLOsRVhoVlwAAAUA"]
[Thu Sep 17 15:08:35.051043 2026] [security2:error] [pid 955873:tid 956040] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/backup/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVmAAAAS8"]
[Thu Sep 17 15:08:35.133425 2026] [authz_core:error] [pid 955873:tid 956101] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Proxy/error_log
[Thu Sep 17 15:08:35.134690 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/"] [unique_id "aqxW0xFTPRVSLOsRVhoVmQAAAWw"]
[Thu Sep 17 15:08:35.157139 2026] [security2:error] [pid 955873:tid 956103] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/backups/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVmgAAAW4"]
[Thu Sep 17 15:08:35.170777 2026] [security2:error] [pid 955873:tid 956004] [client 192.178.6.3:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVmwAAAQs"]
[Thu Sep 17 15:08:35.225963 2026] [security2:error] [pid 955873:tid 956094] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/old/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVnQAAAWU"]
[Thu Sep 17 15:08:35.284359 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/wp-includes/Requests/src/"] [unique_id "aqxW0xFTPRVSLOsRVhoVoAAAAVM"]
[Thu Sep 17 15:08:35.304559 2026] [security2:error] [pid 955873:tid 956086] [client 34.23.195.25:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxW0xFTPRVSLOsRVhoVoQAAAV0"]
[Thu Sep 17 15:08:35.347096 2026] [security2:error] [pid 955873:tid 956061] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/tmp/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVogAAAUQ"]
[Thu Sep 17 15:08:35.476415 2026] [security2:error] [pid 955873:tid 956049] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/temp/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVpgAAATg"]
[Thu Sep 17 15:08:35.534762 2026] [security2:error] [pid 955873:tid 956085] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/lab/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVrAAAAVw"]
[Thu Sep 17 15:08:35.541375 2026] [security2:error] [pid 955873:tid 956071] [client 34.95.188.156:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php~"] [unique_id "aqxW0xFTPRVSLOsRVhoVrQAAAU4"]
[Thu Sep 17 15:08:35.604469 2026] [security2:error] [pid 955873:tid 956098] [client 34.23.195.25:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxW0xFTPRVSLOsRVhoVsAAAAWk"]
[Thu Sep 17 15:08:35.631690 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVpQAAAVE"]
[Thu Sep 17 15:08:35.631717 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVpQAAAVE"]
[Thu Sep 17 15:08:35.649222 2026] [security2:error] [pid 955873:tid 956035] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cronlab/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVsQAAASo"]
[Thu Sep 17 15:08:35.649504 2026] [security2:error] [pid 955873:tid 955881] [remote 47.128.111.227:29896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.comicsutra.com"] [uri "/robots.txt"] [unique_id "aqxW0xFTPRVSLOsRVhoVsgABPQc"]
[Thu Sep 17 15:08:35.698632 2026] [security2:error] [pid 955873:tid 956043] [client 34.166.190.5:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVtAAAATI"]
[Thu Sep 17 15:08:35.752899 2026] [security2:error] [pid 955873:tid 956100] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cron/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVtQAAAWs"]
[Thu Sep 17 15:08:35.772946 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/Http.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVtgAAASI"]
[Thu Sep 17 15:08:35.773057 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Proxy/Http.php"] [unique_id "aqxW0xFTPRVSLOsRVhoVtgAAASI"]
[Thu Sep 17 15:08:35.816251 2026] [security2:error] [pid 955873:tid 956124] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/en/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVtwAAAYM"]
[Thu Sep 17 15:08:35.905652 2026] [security2:error] [pid 955873:tid 956006] [client 34.23.195.25:47636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxW0xFTPRVSLOsRVhoVuQAAAQ0"]
[Thu Sep 17 15:08:35.954502 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/administrator/.env"] [unique_id "aqxW0xFTPRVSLOsRVhoVuAAAATA"]
[Thu Sep 17 15:08:36.007099 2026] [security2:error] [pid 955873:tid 956105] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/psnlink/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoVvQAAAXA"]
[Thu Sep 17 15:08:36.034883 2026] [security2:error] [pid 955873:tid 956009] [client 34.95.188.156:32930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/info.php.bak"] [unique_id "aqxW1BFTPRVSLOsRVhoVvwAAARA"]
[Thu Sep 17 15:08:36.062765 2026] [security2:error] [pid 955873:tid 956037] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/exapi/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoVwAAAASw"]
[Thu Sep 17 15:08:36.065507 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:39628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Requests.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVwQAAAWA"]
[Thu Sep 17 15:08:36.065581 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:39628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Requests.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVwQAAAWA"]
[Thu Sep 17 15:08:36.155474 2026] [security2:error] [pid 955873:tid 956113] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sitemaps/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoVwgAAAXg"]
[Thu Sep 17 15:08:36.212249 2026] [security2:error] [pid 955873:tid 956107] [client 34.23.195.25:47650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxW1BFTPRVSLOsRVhoVwwAAAXI"]
[Thu Sep 17 15:08:36.358963 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:39642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVygAAAW0"]
[Thu Sep 17 15:08:36.359057 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:39642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVygAAAW0"]
[Thu Sep 17 15:08:36.411433 2026] [security2:error] [pid 955873:tid 956029] [client 34.166.190.5:48130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVywAAASQ"]
[Thu Sep 17 15:08:36.505004 2026] [security2:error] [pid 955873:tid 956032] [client 34.23.195.25:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxW1BFTPRVSLOsRVhoV0AAAASc"]
[Thu Sep 17 15:08:36.538870 2026] [security2:error] [pid 955873:tid 956042] [client 34.95.188.156:32944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/phpinfo.php.save"] [unique_id "aqxW1BFTPRVSLOsRVhoV0QAAATE"]
[Thu Sep 17 15:08:36.557568 2026] [security2:error] [pid 955873:tid 956106] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW1BFTPRVSLOsRVhoVyQAAAXE"]
[Thu Sep 17 15:08:36.659314 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/"] [unique_id "aqxW1BFTPRVSLOsRVhoV0gAAAUs"]
[Thu Sep 17 15:08:36.757215 2026] [security2:error] [pid 955873:tid 956101] [client 34.23.195.25:47672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxW1BFTPRVSLOsRVhoV1gAAAWw"]
[Thu Sep 17 15:08:36.815194 2026] [authz_core:error] [pid 955873:tid 956096] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Response/error_log
[Thu Sep 17 15:08:36.816024 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/"] [unique_id "aqxW1BFTPRVSLOsRVhoV2gAAAWc"]
[Thu Sep 17 15:08:36.937296 2026] [security2:error] [pid 955873:tid 956013] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW1BFTPRVSLOsRVhoV1QAAARQ"]
[Thu Sep 17 15:08:36.960165 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:39652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/wp-includes/Requests/src/"] [unique_id "aqxW1BFTPRVSLOsRVhoV2wAAAW8"]
[Thu Sep 17 15:08:36.995531 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:44334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/logs/.env"] [unique_id "aqxW1BFTPRVSLOsRVhoV3AAAAQ8"]
[Thu Sep 17 15:08:37.027094 2026] [security2:error] [pid 955873:tid 956077] [client 4.240.114.86:60277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV4AAAAVQ"], referer: binance.com
[Thu Sep 17 15:08:37.035405 2026] [security2:error] [pid 955873:tid 956094] [client 34.23.195.25:47678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV4QAAAWU"]
[Thu Sep 17 15:08:37.038546 2026] [security2:error] [pid 955873:tid 956067] [client 34.95.188.156:32958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV4gAAAUo"]
[Thu Sep 17 15:08:37.105412 2026] [security2:error] [pid 955873:tid 956127] [client 186.105.232.15:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5AAAAYY"]
[Thu Sep 17 15:08:37.105598 2026] [security2:error] [pid 955873:tid 956127] [client 186.105.232.15:58398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5AAAAYY"]
[Thu Sep 17 15:08:37.114453 2026] [security2:error] [pid 955873:tid 956015] [client 34.166.190.5:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5QAAARY"]
[Thu Sep 17 15:08:37.160092 2026] [security2:error] [pid 955873:tid 956014] [client 134.185.85.61:51231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxW1RFTPRVSLOsRVhoV5wAAARU"]
[Thu Sep 17 15:08:37.231841 2026] [security2:error] [pid 955873:tid 956020] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cache/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV6gAAARs"]
[Thu Sep 17 15:08:37.288207 2026] [security2:error] [pid 955873:tid 956071] [client 34.23.195.25:47694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV6wAAAU4"]
[Thu Sep 17 15:08:37.326408 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5gAAAWM"]
[Thu Sep 17 15:08:37.326440 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV5gAAAWM"]
[Thu Sep 17 15:08:37.341026 2026] [security2:error] [pid 955873:tid 956059] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailer/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV7AAAAUI"]
[Thu Sep 17 15:08:37.430081 2026] [security2:error] [pid 955873:tid 956045] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mail/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV8AAAATQ"]
[Thu Sep 17 15:08:37.479414 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:39652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/Headers.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV8gAAARc"]
[Thu Sep 17 15:08:37.479524 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:39652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Response/Headers.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV8gAAARc"]
[Thu Sep 17 15:08:37.489423 2026] [security2:error] [pid 955873:tid 956019] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/email/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV8wAAARo"]
[Thu Sep 17 15:08:37.533871 2026] [security2:error] [pid 955873:tid 956026] [client 34.23.195.25:47706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV9AAAASE"]
[Thu Sep 17 15:08:37.537470 2026] [security2:error] [pid 955873:tid 956006] [client 134.185.85.61:58119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.com"] [uri "/media/system/js/core.js"] [unique_id "aqxW1RFTPRVSLOsRVhoV9QAAAQ0"]
[Thu Sep 17 15:08:37.540869 2026] [security2:error] [pid 955873:tid 956100] [client 34.95.188.156:32966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV9gAAAWs"]
[Thu Sep 17 15:08:37.621178 2026] [security2:error] [pid 955873:tid 956063] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/smtp/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV-AAAAUY"]
[Thu Sep 17 15:08:37.692002 2026] [security2:error] [pid 955873:tid 956031] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailing/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV-QAAASY"]
[Thu Sep 17 15:08:37.754111 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:39660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Session.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_AAAATc"]
[Thu Sep 17 15:08:37.754171 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:39660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Session.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_AAAATc"]
[Thu Sep 17 15:08:37.772317 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/notifications/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoV_QAAAWA"]
[Thu Sep 17 15:08:37.796081 2026] [security2:error] [pid 955873:tid 956066] [client 34.166.190.5:48148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_wAAAUk"]
[Thu Sep 17 15:08:37.861571 2026] [security2:error] [pid 955873:tid 956081] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/notify/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoWAgAAAVg"]
[Thu Sep 17 15:08:37.875046 2026] [security2:error] [pid 955873:tid 956087] [client 186.189.85.137:41528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW1RFTPRVSLOsRVhoV_gABXgA"]
[Thu Sep 17 15:08:37.879107 2026] [security2:error] [pid 955873:tid 956078] [client 34.23.195.25:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxW1RFTPRVSLOsRVhoWAwAAAVU"]
[Thu Sep 17 15:08:37.935088 2026] [security2:error] [pid 955873:tid 956130] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sender/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoWBQAAAYk"]
[Thu Sep 17 15:08:37.999946 2026] [security2:error] [pid 955873:tid 956122] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/campaign/.env"] [unique_id "aqxW1RFTPRVSLOsRVhoWBwAAAYE"]
[Thu Sep 17 15:08:38.025994 2026] [security2:error] [pid 955873:tid 956018] [client 34.95.188.156:32972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWCAAAARk"]
[Thu Sep 17 15:08:38.029491 2026] [security2:error] [pid 955873:tid 956055] [client 114.119.140.115:61437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tab-funkenwerk.com"] [uri "/id79.html"] [unique_id "aqxW1hFTPRVSLOsRVhoWCQAAAT4"], referer: https://www.diyaudio.com/community/threads/john-curls-blowtorch-preamplifier-part-iii.318975/post-5601815
[Thu Sep 17 15:08:38.054373 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ssl.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWCgAAAUM"]
[Thu Sep 17 15:08:38.054457 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:39674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Ssl.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWCgAAAUM"]
[Thu Sep 17 15:08:38.083392 2026] [security2:error] [pid 955873:tid 956072] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/newsletter/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWCwAAAU8"]
[Thu Sep 17 15:08:38.181122 2026] [security2:error] [pid 955873:tid 956012] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/ses/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWDAAAARM"]
[Thu Sep 17 15:08:38.187169 2026] [security2:error] [pid 955873:tid 956038] [client 185.55.149.49:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWDQAAAS0"]
[Thu Sep 17 15:08:38.187253 2026] [security2:error] [pid 955873:tid 956038] [client 185.55.149.49:56979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWDQAAAS0"]
[Thu Sep 17 15:08:38.268633 2026] [security2:error] [pid 955873:tid 956102] [client 34.23.195.25:47718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWEQAAAW0"]
[Thu Sep 17 15:08:38.269554 2026] [security2:error] [pid 955873:tid 956108] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sendgrid/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWEgAAAXM"]
[Thu Sep 17 15:08:38.356116 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/sparkpost/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWFAAAATY"]
[Thu Sep 17 15:08:38.362107 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWFQAAAUs"]
[Thu Sep 17 15:08:38.362202 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:39688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWFQAAAUs"]
[Thu Sep 17 15:08:38.440591 2026] [security2:error] [pid 955873:tid 956096] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/postmark/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWGAAAAWc"]
[Thu Sep 17 15:08:38.497384 2026] [security2:error] [pid 955873:tid 956017] [client 34.166.190.5:48150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWGwAAARg"]
[Thu Sep 17 15:08:38.515516 2026] [security2:error] [pid 955873:tid 956040] [client 34.95.188.156:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWHAAAAS8"]
[Thu Sep 17 15:08:38.585089 2026] [security2:error] [pid 955873:tid 956013] [client 34.23.195.25:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWHQAAARQ"]
[Thu Sep 17 15:08:38.609691 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailgun/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWHgAAAQ8"]
[Thu Sep 17 15:08:38.667515 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:39704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/"] [unique_id "aqxW1hFTPRVSLOsRVhoWIgAAAWU"]
[Thu Sep 17 15:08:38.738792 2026] [security2:error] [pid 955873:tid 956049] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mandrill/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWJQAAATg"]
[Thu Sep 17 15:08:38.818084 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mailjet/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWKAAAARE"]
[Thu Sep 17 15:08:38.819775 2026] [authz_core:error] [pid 955873:tid 956035] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/Requests/src/Transport/error_log
[Thu Sep 17 15:08:38.821220 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/"] [unique_id "aqxW1hFTPRVSLOsRVhoWJwAAASo"]
[Thu Sep 17 15:08:38.889299 2026] [security2:error] [pid 955873:tid 956054] [client 34.23.195.25:47734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWLAAAAT0"]
[Thu Sep 17 15:08:38.939490 2026] [security2:error] [pid 955873:tid 956033] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/brevo/.env"] [unique_id "aqxW1hFTPRVSLOsRVhoWLQAAASg"]
[Thu Sep 17 15:08:38.958087 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:39704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/wp-includes/Requests/src/"] [unique_id "aqxW1hFTPRVSLOsRVhoWLgAAAX8"]
[Thu Sep 17 15:08:39.009149 2026] [security2:error] [pid 955873:tid 956023] [client 34.95.188.156:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWLwAAAR4"]
[Thu Sep 17 15:08:39.039027 2026] [security2:error] [pid 955873:tid 956059] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/transactional/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWMAAAAUI"]
[Thu Sep 17 15:08:39.117501 2026] [security2:error] [pid 955873:tid 956129] [client 34.23.195.25:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWMQAAAYg"]
[Thu Sep 17 15:08:39.127265 2026] [security2:error] [pid 955873:tid 956019] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/bulk/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWMwAAARo"]
[Thu Sep 17 15:08:39.200373 2026] [security2:error] [pid 955873:tid 956092] [client 34.166.190.5:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWNAAAAWM"]
[Thu Sep 17 15:08:39.205146 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/aws/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWNQAAATA"]
[Thu Sep 17 15:08:39.311147 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWMgAAARc"]
[Thu Sep 17 15:08:39.311172 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWMgAAARc"]
[Thu Sep 17 15:08:39.317188 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWNgAAAQ0"]
[Thu Sep 17 15:08:39.317268 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:62575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWNgAAAQ0"]
[Thu Sep 17 15:08:39.348477 2026] [security2:error] [pid 955873:tid 956082] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/azure/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWOAAAAVk"]
[Thu Sep 17 15:08:39.392435 2026] [security2:error] [pid 955873:tid 956084] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/gcp/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWOwAAAVs"]
[Thu Sep 17 15:08:39.427089 2026] [security2:error] [pid 955873:tid 956063] [client 34.23.195.25:47754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWPwAAAUY"]
[Thu Sep 17 15:08:39.448050 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:39704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Curl.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWQAAAAQo"]
[Thu Sep 17 15:08:39.448127 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:39704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Curl.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWQAAAAQo"]
[Thu Sep 17 15:08:39.502128 2026] [security2:error] [pid 955873:tid 956126] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cloud/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWQgAAAYU"]
[Thu Sep 17 15:08:39.520108 2026] [security2:error] [pid 955873:tid 956050] [client 34.95.188.156:32978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/www/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWRAAAATk"]
[Thu Sep 17 15:08:39.572654 2026] [security2:error] [pid 955873:tid 956081] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/infrastructure/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWRQAAAVg"]
[Thu Sep 17 15:08:39.663840 2026] [security2:error] [pid 955873:tid 956114] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/docker/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWRgAAAXk"]
[Thu Sep 17 15:08:39.714017 2026] [security2:error] [pid 955873:tid 956112] [client 34.23.195.25:47764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWRwAAAXc"]
[Thu Sep 17 15:08:39.732502 2026] [security2:error] [pid 955873:tid 956030] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/k8s/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWSAAAASU"]
[Thu Sep 17 15:08:39.758817 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:39708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Fsockopen.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWSQAAAYE"]
[Thu Sep 17 15:08:39.758922 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:39708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Transport/Fsockopen.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWSQAAAYE"]
[Thu Sep 17 15:08:39.799082 2026] [security2:error] [pid 955873:tid 956055] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/kubernetes/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWTAAAAT4"]
[Thu Sep 17 15:08:39.905453 2026] [security2:error] [pid 955873:tid 956036] [client 34.166.190.5:48160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW1xFTPRVSLOsRVhoWTwAAASs"]
[Thu Sep 17 15:08:39.911682 2026] [security2:error] [pid 955873:tid 956097] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/terraform/.env"] [unique_id "aqxW1xFTPRVSLOsRVhoWUAAAAWg"]
[Thu Sep 17 15:08:40.007244 2026] [security2:error] [pid 955873:tid 956108] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/ansible/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWUwAAAXM"]
[Thu Sep 17 15:08:40.009939 2026] [security2:error] [pid 955873:tid 956113] [client 34.95.188.156:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWVAAAAXg"]
[Thu Sep 17 15:08:40.050899 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:33910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "aqxW2BFTPRVSLOsRVhoWVQAAATY"]
[Thu Sep 17 15:08:40.064562 2026] [security2:error] [pid 955873:tid 956106] [client 34.23.195.25:47778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWVgAAAXE"]
[Thu Sep 17 15:08:40.083876 2026] [security2:error] [pid 955873:tid 956004] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/.git/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWWAAAAQs"]
[Thu Sep 17 15:08:40.169406 2026] [security2:error] [pid 955873:tid 956091] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/ci/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWWQAAAWI"]
[Thu Sep 17 15:08:40.204825 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "aqxW2BFTPRVSLOsRVhoWWgAAAUA"]
[Thu Sep 17 15:08:40.285795 2026] [security2:error] [pid 955873:tid 956088] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/cd/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWXQAAAV8"]
[Thu Sep 17 15:08:40.342599 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:33910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/wp-includes/Requests/src/"] [unique_id "aqxW2BFTPRVSLOsRVhoWYAAAAS8"]
[Thu Sep 17 15:08:40.350559 2026] [security2:error] [pid 955873:tid 956025] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/jenkins/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWYQAAASA"]
[Thu Sep 17 15:08:40.399644 2026] [security2:error] [pid 955873:tid 956077] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/gitlab/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWZAAAAVQ"]
[Thu Sep 17 15:08:40.428063 2026] [security2:error] [pid 955873:tid 956008] [client 34.23.195.25:47790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.afx.ypv.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWZwAAAQ8"]
[Thu Sep 17 15:08:40.491590 2026] [security2:error] [pid 955873:tid 956127] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/github/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWawAAAYY"]
[Thu Sep 17 15:08:40.497056 2026] [security2:error] [pid 955873:tid 956007] [client 34.95.188.156:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWbAAAAQ4"]
[Thu Sep 17 15:08:40.524809 2026] [security2:error] [pid 955873:tid 956117] [client 45.234.11.65:12969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWZQABfDU"]
[Thu Sep 17 15:08:40.567165 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/actions/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWbwAAAT0"]
[Thu Sep 17 15:08:40.587345 2026] [security2:error] [pid 955873:tid 956013] [client 34.166.190.5:48168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWcAAAARQ"]
[Thu Sep 17 15:08:40.621822 2026] [security2:error] [pid 955873:tid 956039] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/circleci/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWcwAAAS4"]
[Thu Sep 17 15:08:40.685444 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWagAAARw"]
[Thu Sep 17 15:08:40.685466 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWagAAARw"]
[Thu Sep 17 15:08:40.698101 2026] [security2:error] [pid 955873:tid 956092] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/travis/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWdgAAAWM"]
[Thu Sep 17 15:08:40.784061 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/buildkite/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWeQAAARc"]
[Thu Sep 17 15:08:40.832574 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:33910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/CaseInsensitiveDictionary.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWfQAAATc"]
[Thu Sep 17 15:08:40.832653 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:33910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/CaseInsensitiveDictionary.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWfQAAATc"]
[Thu Sep 17 15:08:40.837628 2026] [security2:error] [pid 955873:tid 956065] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mysql/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWfgAAAUg"]
[Thu Sep 17 15:08:40.950990 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/postgres/.env"] [unique_id "aqxW2BFTPRVSLOsRVhoWggAAAQw"]
[Thu Sep 17 15:08:40.988194 2026] [security2:error] [pid 955873:tid 956084] [client 34.95.188.156:33002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/site/phpinfo.php"] [unique_id "aqxW2BFTPRVSLOsRVhoWhAAAAVs"]
[Thu Sep 17 15:08:41.092607 2026] [security2:error] [pid 955873:tid 956078] [client 4.240.114.86:62253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWhQAAAVU"], referer: binance.com
[Thu Sep 17 15:08:41.126032 2026] [security2:error] [pid 955873:tid 956051] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/mongodb/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWhwAAATo"]
[Thu Sep 17 15:08:41.127710 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:33918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/FilteredIterator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWiAAAAXc"]
[Thu Sep 17 15:08:41.127783 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:33918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/FilteredIterator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWiAAAAXc"]
[Thu Sep 17 15:08:41.187868 2026] [security2:error] [pid 955873:tid 956018] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/redis/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWigAAARk"]
[Thu Sep 17 15:08:41.272513 2026] [security2:error] [pid 955873:tid 956089] [client 34.166.190.5:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWjAAAAWA"]
[Thu Sep 17 15:08:41.297028 2026] [security2:error] [pid 955873:tid 956072] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/elasticsearch/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWjgAAAU8"]
[Thu Sep 17 15:08:41.377893 2026] [security2:error] [pid 955873:tid 956038] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/rabbitmq/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWkwAAAS0"]
[Thu Sep 17 15:08:41.403748 2026] [security2:error] [pid 955873:tid 956031] [client 115.244.164.14:56794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlAAAASY"]
[Thu Sep 17 15:08:41.403855 2026] [security2:error] [pid 955873:tid 956031] [client 115.244.164.14:56794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlAAAASY"]
[Thu Sep 17 15:08:41.418885 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/InputValidator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlQAAAWg"]
[Thu Sep 17 15:08:41.418984 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Requests/src/Utility/InputValidator.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWlQAAAWg"]
[Thu Sep 17 15:08:41.441790 2026] [security2:error] [pid 955873:tid 956058] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/kafka/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWlgAAAUE"]
[Thu Sep 17 15:08:41.475755 2026] [security2:error] [pid 955873:tid 956130] [client 34.95.188.156:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWmAAAAYk"]
[Thu Sep 17 15:08:41.526270 2026] [security2:error] [pid 955873:tid 956047] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/queue/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWmgAAATY"]
[Thu Sep 17 15:08:41.595326 2026] [security2:error] [pid 955873:tid 956004] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/worker/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWnAAAAQs"]
[Thu Sep 17 15:08:41.666789 2026] [security2:error] [pid 955873:tid 956096] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/job/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWnwAAAWc"]
[Thu Sep 17 15:08:41.701604 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:33928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxW2RFTPRVSLOsRVhoWowAAAV4"]
[Thu Sep 17 15:08:41.731210 2026] [security2:error] [pid 955873:tid 956052] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/test/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWpgAAATs"]
[Thu Sep 17 15:08:41.781165 2026] [security2:error] [pid 955873:tid 956025] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/qa/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWpwAAASA"]
[Thu Sep 17 15:08:41.865061 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxW2RFTPRVSLOsRVhoWqQAAAQ8"]
[Thu Sep 17 15:08:41.898798 2026] [security2:error] [pid 955873:tid 956085] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/preview/.env"] [unique_id "aqxW2RFTPRVSLOsRVhoWrwAAAVw"]
[Thu Sep 17 15:08:41.977355 2026] [security2:error] [pid 955873:tid 956040] [client 34.166.190.5:48174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWswAAAS8"]
[Thu Sep 17 15:08:41.979538 2026] [security2:error] [pid 955873:tid 956077] [client 34.95.188.156:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW2RFTPRVSLOsRVhoWtAAAAVQ"]
[Thu Sep 17 15:08:42.005307 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:33928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/autoloader.php"] [unique_id "aqxW2hFTPRVSLOsRVhoWtQAAAWQ"]
[Thu Sep 17 15:08:42.005411 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:33928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/autoloader.php"] [unique_id "aqxW2hFTPRVSLOsRVhoWtQAAAWQ"]
[Thu Sep 17 15:08:42.006716 2026] [security2:error] [pid 955873:tid 956010] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/beta/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWtwAAARE"]
[Thu Sep 17 15:08:42.065641 2026] [security2:error] [pid 955873:tid 956033] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/uat/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWuQAAASg"]
[Thu Sep 17 15:08:42.161514 2026] [security2:error] [pid 955873:tid 956118] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/stage/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWvQAAAX0"]
[Thu Sep 17 15:08:42.226352 2026] [security2:error] [pid 955873:tid 956092] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/development/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWwwAAAWM"]
[Thu Sep 17 15:08:42.295702 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:33944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/"] [unique_id "aqxW2hFTPRVSLOsRVhoWyAAAAWY"]
[Thu Sep 17 15:08:42.309349 2026] [security2:error] [pid 955873:tid 956022] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/production/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoWygAAAR0"]
[Thu Sep 17 15:08:42.426286 2026] [security2:error] [pid 955873:tid 956028] [client 35.222.223.233:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kidsandlifeot.com"] [uri "/config/app/.env"] [unique_id "aqxW2hFTPRVSLOsRVhoW0QAAASM"]
[Thu Sep 17 15:08:42.445476 2026] [authz_core:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/library/error_log
[Thu Sep 17 15:08:42.453038 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/"] [unique_id "aqxW2hFTPRVSLOsRVhoW0gAAAVU"]
[Thu Sep 17 15:08:42.484764 2026] [security2:error] [pid 955873:tid 956003] [client 34.95.188.156:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW1gAAAQo"]
[Thu Sep 17 15:08:42.525782 2026] [security2:error] [pid 955873:tid 956060] [client 35.222.223.233:44340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW1wAAAUM"]
[Thu Sep 17 15:08:42.544783 2026] [security2:error] [pid 955873:tid 956026] [client 47.79.200.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxW2hFTPRVSLOsRVhoWxgAAASE"], referer: https://www.google.com/
[Thu Sep 17 15:08:42.618934 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:33944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/wp-includes/SimplePie/"] [unique_id "aqxW2hFTPRVSLOsRVhoW2QAAAWg"]
[Thu Sep 17 15:08:42.676584 2026] [security2:error] [pid 955873:tid 956114] [client 34.166.190.5:48186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW2wAAAXk"]
[Thu Sep 17 15:08:42.680047 2026] [security2:error] [pid 955873:tid 956048] [client 104.28.198.244:22781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3AAAATc"]
[Thu Sep 17 15:08:42.680126 2026] [security2:error] [pid 955873:tid 956048] [client 104.28.198.244:22781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3AAAATc"]
[Thu Sep 17 15:08:42.860932 2026] [security2:error] [pid 955873:tid 956080] [client 35.222.223.233:38960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/info.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW4AAAAVc"]
[Thu Sep 17 15:08:42.968171 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3QAAAVA"]
[Thu Sep 17 15:08:42.968193 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW3QAAAVA"]
[Thu Sep 17 15:08:42.994281 2026] [security2:error] [pid 955873:tid 956128] [client 34.95.188.156:33052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/core/phpinfo.php"] [unique_id "aqxW2hFTPRVSLOsRVhoW5gAAAYc"]
[Thu Sep 17 15:08:43.117474 2026] [security2:error] [pid 955873:tid 956104] [client 35.222.223.233:38976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/php.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW5wAAAW8"]
[Thu Sep 17 15:08:43.130478 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:33944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW6AAAATE"]
[Thu Sep 17 15:08:43.130579 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:33944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW6AAAATE"]
[Thu Sep 17 15:08:43.362382 2026] [security2:error] [pid 955873:tid 956115] [client 154.190.208.131:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW7QAAAXo"]
[Thu Sep 17 15:08:43.362501 2026] [security2:error] [pid 955873:tid 956115] [client 154.190.208.131:41597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW7QAAAXo"]
[Thu Sep 17 15:08:43.375726 2026] [security2:error] [pid 955873:tid 956098] [client 34.166.190.5:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW7gAAAWk"]
[Thu Sep 17 15:08:43.421288 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:33952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW2xFTPRVSLOsRVhoW8AAAARg"]
[Thu Sep 17 15:08:43.432687 2026] [security2:error] [pid 955873:tid 956094] [client 35.222.223.233:38978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/i.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW8gAAAWU"]
[Thu Sep 17 15:08:43.490518 2026] [security2:error] [pid 955873:tid 956035] [client 34.95.188.156:33062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.188.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ftlbllc.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW8wAAASo"]
[Thu Sep 17 15:08:43.572568 2026] [security2:error] [pid 955873:tid 956071] [client 162.241.226.11:20366] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW9AAAAU4"]
[Thu Sep 17 15:08:43.579302 2026] [authz_core:error] [pid 955873:tid 956121] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/library/SimplePie/error_log
[Thu Sep 17 15:08:43.630287 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW2xFTPRVSLOsRVhoW9QAAAYA"]
[Thu Sep 17 15:08:43.769281 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:33952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/wp-includes/SimplePie/library/"] [unique_id "aqxW2xFTPRVSLOsRVhoW-QAAARY"]
[Thu Sep 17 15:08:43.776813 2026] [security2:error] [pid 955873:tid 956086] [client 207.46.13.231:8523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thehivetribe.com"] [uri "/index.php"] [unique_id "aqxW1hFTPRVSLOsRVhoWHwABXUk"]
[Thu Sep 17 15:08:43.956679 2026] [security2:error] [pid 955873:tid 956005] [client 35.222.223.233:38986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/pi.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW_wAAAQw"]
[Thu Sep 17 15:08:44.079738 2026] [security2:error] [pid 955873:tid 956014] [client 34.166.190.5:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.jxz.hgv.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXBgAAARU"]
[Thu Sep 17 15:08:44.155861 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW_gAAASM"]
[Thu Sep 17 15:08:44.155882 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW2xFTPRVSLOsRVhoW_gAAASM"]
[Thu Sep 17 15:08:44.231997 2026] [security2:error] [pid 955873:tid 956119] [client 35.222.223.233:38992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/pinfo.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXCQAAAX4"]
[Thu Sep 17 15:08:44.298632 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:33952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Author.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXCgAAAXM"]
[Thu Sep 17 15:08:44.298745 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:33952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Author.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXCgAAAXM"]
[Thu Sep 17 15:08:44.311006 2026] [security2:error] [pid 955873:tid 955951] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.bak"] [unique_id "aqxW3BFTPRVSLOsRVhoXDAABJU0"]
[Thu Sep 17 15:08:44.311014 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.backup"] [unique_id "aqxW3BFTPRVSLOsRVhoXDQABJUw"]
[Thu Sep 17 15:08:44.312015 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.old"] [unique_id "aqxW3BFTPRVSLOsRVhoXEQABJUw"]
[Thu Sep 17 15:08:44.321457 2026] [security2:error] [pid 955873:tid 955955] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXGgABJVE"]
[Thu Sep 17 15:08:44.581610 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:38996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/test.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXJAAAAUs"]
[Thu Sep 17 15:08:44.586786 2026] [security2:error] [pid 955873:tid 955960] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/.env.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXIQABJVY"]
[Thu Sep 17 15:08:44.591869 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:33960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXJQAAAUA"]
[Thu Sep 17 15:08:44.591932 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:33960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache.php"] [unique_id "aqxW3BFTPRVSLOsRVhoXJQAAAUA"]
[Thu Sep 17 15:08:44.598398 2026] [security2:error] [pid 955873:tid 955963] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env~"] [unique_id "aqxW3BFTPRVSLOsRVhoXJgABO1k"]
[Thu Sep 17 15:08:44.632916 2026] [security2:error] [pid 955873:tid 956000] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.env.swp"] [unique_id "aqxW3BFTPRVSLOsRVhoXJwABXn4"]
[Thu Sep 17 15:08:44.863876 2026] [security2:error] [pid 955873:tid 955980] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/api/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXMQABVGo"]
[Thu Sep 17 15:08:44.863876 2026] [security2:error] [pid 955873:tid 955973] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/app/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXMgABVGM"]
[Thu Sep 17 15:08:44.882094 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:33964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/"] [unique_id "aqxW3BFTPRVSLOsRVhoXNAAAAWc"]
[Thu Sep 17 15:08:44.929718 2026] [security2:error] [pid 955873:tid 955978] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/backend/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXOgABRGg"]
[Thu Sep 17 15:08:44.943885 2026] [security2:error] [pid 955873:tid 955884] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/config/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPQABZAo"]
[Thu Sep 17 15:08:44.943908 2026] [security2:error] [pid 955873:tid 955883] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/client/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXQAABZAk"]
[Thu Sep 17 15:08:44.943930 2026] [security2:error] [pid 955873:tid 955987] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/src/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPAABZHE"]
[Thu Sep 17 15:08:44.943950 2026] [security2:error] [pid 955873:tid 955998] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/web/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPwABZHw"]
[Thu Sep 17 15:08:44.943968 2026] [security2:error] [pid 955873:tid 955961] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/server/.env"] [unique_id "aqxW3BFTPRVSLOsRVhoXPgABZFc"]
[Thu Sep 17 15:08:45.001999 2026] [security2:error] [pid 955873:tid 955958] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/public/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXQgABEVQ"]
[Thu Sep 17 15:08:45.001999 2026] [security2:error] [pid 955873:tid 955979] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/frontend/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXQQABEWk"]
[Thu Sep 17 15:08:45.014563 2026] [security2:error] [pid 955873:tid 955994] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/var/www/html/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXRAABeng"]
[Thu Sep 17 15:08:45.014684 2026] [security2:error] [pid 955873:tid 955985] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/var/www/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXRQABem8"]
[Thu Sep 17 15:08:45.015162 2026] [security2:error] [pid 955873:tid 955885] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/laravel/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXRgABegs"]
[Thu Sep 17 15:08:45.024057 2026] [security2:error] [pid 955873:tid 955983] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/application/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXSAABhm0"]
[Thu Sep 17 15:08:45.056850 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/"] [unique_id "aqxW3RFTPRVSLOsRVhoXRwAAAWk"]
[Thu Sep 17 15:08:45.069156 2026] [security2:error] [pid 955873:tid 956001] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/apps/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXSgABfH8"]
[Thu Sep 17 15:08:45.069157 2026] [security2:error] [pid 955873:tid 955984] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/back/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXSwABfG4"]
[Thu Sep 17 15:08:45.069201 2026] [security2:error] [pid 955873:tid 955935] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/backup/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXTAABfD0"]
[Thu Sep 17 15:08:45.070590 2026] [security2:error] [pid 955873:tid 955974] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/cms/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXTQABfGQ"]
[Thu Sep 17 15:08:45.078728 2026] [security2:error] [pid 955873:tid 955957] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/dev/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXTwABSlM"]
[Thu Sep 17 15:08:45.079703 2026] [security2:error] [pid 955873:tid 955966] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/test/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUwABSlw"]
[Thu Sep 17 15:08:45.079766 2026] [security2:error] [pid 955873:tid 955977] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/production/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUAABSmc"]
[Thu Sep 17 15:08:45.079789 2026] [security2:error] [pid 955873:tid 955970] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/staging/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUgABSmA"]
[Thu Sep 17 15:08:45.079836 2026] [security2:error] [pid 955873:tid 955892] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/prod/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXUQABShI"]
[Thu Sep 17 15:08:45.079867 2026] [security2:error] [pid 955873:tid 955886] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/old/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXVAABSgw"]
[Thu Sep 17 15:08:45.137510 2026] [security2:error] [pid 955873:tid 955897] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/node-api/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXVwABRhc"]
[Thu Sep 17 15:08:45.137526 2026] [security2:error] [pid 955873:tid 955982] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/new/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXVgABRmw"]
[Thu Sep 17 15:08:45.149283 2026] [security2:error] [pid 955873:tid 955967] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/api-backend/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWAABKl0"]
[Thu Sep 17 15:08:45.149769 2026] [security2:error] [pid 955873:tid 955990] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/admin-app/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWQABKnQ"]
[Thu Sep 17 15:08:45.158503 2026] [security2:error] [pid 955873:tid 955999] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/public_html/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWwABKn0"]
[Thu Sep 17 15:08:45.194630 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:33964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW3RFTPRVSLOsRVhoXXQAAAT0"]
[Thu Sep 17 15:08:45.204190 2026] [security2:error] [pid 955873:tid 955875] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/current/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXXgABKgE"]
[Thu Sep 17 15:08:45.204734 2026] [security2:error] [pid 955873:tid 955887] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/server/api/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXXwABKg0"]
[Thu Sep 17 15:08:45.204768 2026] [security2:error] [pid 955873:tid 955986] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/server/backend/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYAABKnA"]
[Thu Sep 17 15:08:45.205402 2026] [security2:error] [pid 955873:tid 955901] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.docker/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYQABKhs"]
[Thu Sep 17 15:08:45.213337 2026] [security2:error] [pid 955873:tid 955914] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYgABKig"]
[Thu Sep 17 15:08:45.213388 2026] [security2:error] [pid 955873:tid 955902] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/administrator/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXWgABKhw"]
[Thu Sep 17 15:08:45.213939 2026] [security2:error] [pid 955873:tid 955989] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/aws/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXYwABKnM"]
[Thu Sep 17 15:08:45.214630 2026] [security2:error] [pid 955873:tid 955997] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/stripe/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXZQABKns"]
[Thu Sep 17 15:08:45.214742 2026] [security2:error] [pid 955873:tid 955969] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.aws/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXZAABKl8"]
[Thu Sep 17 15:08:45.273342 2026] [security2:error] [pid 955873:tid 955894] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/v2/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXawABGxQ"]
[Thu Sep 17 15:08:45.273376 2026] [security2:error] [pid 955873:tid 955891] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/v1/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXbAABGxE"]
[Thu Sep 17 15:08:45.284899 2026] [security2:error] [pid 955873:tid 955971] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/v3/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXbQABfWE"]
[Thu Sep 17 15:08:45.285372 2026] [security2:error] [pid 955873:tid 955909] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/media/.env"] [unique_id "aqxW3RFTPRVSLOsRVhoXbgABfSM"]
[Thu Sep 17 15:08:45.324613 2026] [security2:error] [pid 955873:tid 956094] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXTgAAAWU"]
[Thu Sep 17 15:08:45.378951 2026] [security2:error] [pid 955873:tid 956019] [client 134.185.85.61:59020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "agingwellcoaching.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxW3RFTPRVSLOsRVhoXfgAAARo"]
[Thu Sep 17 15:08:45.402120 2026] [security2:error] [pid 955873:tid 956016] [client 35.222.223.233:39006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/p.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXgwAAARc"]
[Thu Sep 17 15:08:45.408471 2026] [security2:error] [pid 955873:tid 955917] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.git/config.bak"] [unique_id "aqxW3RFTPRVSLOsRVhoXhQABDis"]
[Thu Sep 17 15:08:45.491573 2026] [security2:error] [pid 955873:tid 955923] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.aws/credentials.bak"] [unique_id "aqxW3RFTPRVSLOsRVhoXkAABEDE"]
[Thu Sep 17 15:08:45.497006 2026] [security2:error] [pid 955873:tid 955922] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/.ssh/id_rsa"] [unique_id "aqxW3RFTPRVSLOsRVhoXlQABOTA"]
[Thu Sep 17 15:08:45.497038 2026] [security2:error] [pid 955873:tid 955937] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/id_rsa"] [unique_id "aqxW3RFTPRVSLOsRVhoXlgABOT8"]
[Thu Sep 17 15:08:45.614102 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXcAAAATQ"]
[Thu Sep 17 15:08:45.614123 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXcAAAATQ"]
[Thu Sep 17 15:08:45.711171 2026] [security2:error] [pid 955873:tid 956072] [client 4.240.114.86:64622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXswAAAU8"], referer: binance.com
[Thu Sep 17 15:08:45.756346 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:33964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Base.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXtwAAAQs"]
[Thu Sep 17 15:08:45.756439 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:33964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Base.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXtwAAAQs"]
[Thu Sep 17 15:08:45.765479 2026] [security2:error] [pid 955873:tid 956030] [client 134.185.85.61:63416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "agingwellcoaching.com"] [uri "/media/system/js/core.js"] [unique_id "aqxW3RFTPRVSLOsRVhoXuAAAASU"]
[Thu Sep 17 15:08:45.776126 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXvwABQEw"]
[Thu Sep 17 15:08:45.805576 2026] [security2:error] [pid 955873:tid 956069] [client 35.222.223.233:39020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/debug.php"] [unique_id "aqxW3RFTPRVSLOsRVhoXxAAAAUw"]
[Thu Sep 17 15:08:45.912220 2026] [security2:error] [pid 955873:tid 955991] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/aws.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX0wABZ3U"]
[Thu Sep 17 15:08:45.916212 2026] [security2:error] [pid 955873:tid 955988] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/stripe.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX1QABUXI"]
[Thu Sep 17 15:08:45.920247 2026] [security2:error] [pid 955873:tid 955995] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/mail.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX1wABZHk"]
[Thu Sep 17 15:08:45.922649 2026] [security2:error] [pid 955873:tid 955973] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/config.inc.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX2AABEWM"]
[Thu Sep 17 15:08:45.990264 2026] [security2:error] [pid 955873:tid 955968] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/nexmo.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX2wABd14"]
[Thu Sep 17 15:08:45.994929 2026] [security2:error] [pid 955873:tid 955976] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/wp-config.php"] [unique_id "aqxW3RFTPRVSLOsRVhoX3gABfGY"]
[Thu Sep 17 15:08:46.023684 2026] [security2:error] [pid 955873:tid 955884] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eris.media"] [uri "/wp-config.php.bak"] [unique_id "aqxW3hFTPRVSLOsRVhoX3wABSgo"]
[Thu Sep 17 15:08:46.046106 2026] [security2:error] [pid 955873:tid 955883] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eris.media"] [uri "/wp-config.php.old"] [unique_id "aqxW3hFTPRVSLOsRVhoX4AABNQk"]
[Thu Sep 17 15:08:46.046851 2026] [security2:error] [pid 955873:tid 955987] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eris.media"] [uri "/wp-config.php.new"] [unique_id "aqxW3hFTPRVSLOsRVhoX4QABL3E"]
[Thu Sep 17 15:08:46.050330 2026] [security2:error] [pid 955873:tid 955998] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/.wp-config.php.swp"] [unique_id "aqxW3hFTPRVSLOsRVhoX4gABWXw"]
[Thu Sep 17 15:08:46.054825 2026] [security2:error] [pid 955873:tid 955958] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/wp-content/mysql.sql"] [unique_id "aqxW3hFTPRVSLOsRVhoX5QABOFQ"]
[Thu Sep 17 15:08:46.060061 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/DB.php"] [unique_id "aqxW3hFTPRVSLOsRVhoX6gAAAUY"]
[Thu Sep 17 15:08:46.060141 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:33976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/DB.php"] [unique_id "aqxW3hFTPRVSLOsRVhoX6gAAAUY"]
[Thu Sep 17 15:08:46.104070 2026] [security2:error] [pid 955873:tid 956017] [client 35.222.223.233:39024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoX7gAAARg"]
[Thu Sep 17 15:08:46.129784 2026] [security2:error] [pid 955873:tid 955935] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/terraform.tfstate.backup"] [unique_id "aqxW3hFTPRVSLOsRVhoX8AABUz0"]
[Thu Sep 17 15:08:46.354248 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:33978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/File.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYGAAAARA"]
[Thu Sep 17 15:08:46.354326 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:33978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/File.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYGAAAARA"]
[Thu Sep 17 15:08:46.418724 2026] [security2:error] [pid 955873:tid 956041] [client 35.222.223.233:39036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/test/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYHgAAATA"]
[Thu Sep 17 15:08:46.555281 2026] [security2:error] [pid 955873:tid 955916] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYLwABcio"]
[Thu Sep 17 15:08:46.584278 2026] [security2:error] [pid 955873:tid 955922] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/info.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYMgABPDA"]
[Thu Sep 17 15:08:46.610885 2026] [security2:error] [pid 955873:tid 955937] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/infos.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYMwABWz8"]
[Thu Sep 17 15:08:46.614091 2026] [security2:error] [pid 955873:tid 955907] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/php_info.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNAABISE"]
[Thu Sep 17 15:08:46.614537 2026] [security2:error] [pid 955873:tid 955924] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/php.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNQABITI"]
[Thu Sep 17 15:08:46.615328 2026] [security2:error] [pid 955873:tid 955927] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/php-info.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNwABIzU"]
[Thu Sep 17 15:08:46.615352 2026] [security2:error] [pid 955873:tid 955945] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/infophp.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYNgABI0c"]
[Thu Sep 17 15:08:46.618414 2026] [security2:error] [pid 955873:tid 955932] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYOQABEjo"]
[Thu Sep 17 15:08:46.620041 2026] [security2:error] [pid 955873:tid 955926] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/admin/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYOgABEjQ"]
[Thu Sep 17 15:08:46.620775 2026] [security2:error] [pid 955873:tid 955930] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/admin_phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYOwABEjg"]
[Thu Sep 17 15:08:46.622352 2026] [security2:error] [pid 955873:tid 955943] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/api/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPAABEkU"]
[Thu Sep 17 15:08:46.630456 2026] [security2:error] [pid 955873:tid 955879] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/public/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPQABVgU"]
[Thu Sep 17 15:08:46.639259 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:33994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcache.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPgAAAWY"]
[Thu Sep 17 15:08:46.639320 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:33994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcache.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYPgAAAWY"]
[Thu Sep 17 15:08:46.735750 2026] [security2:error] [pid 955873:tid 956120] [client 35.222.223.233:39046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYRQAAAX8"]
[Thu Sep 17 15:08:46.758094 2026] [security2:error] [pid 955873:tid 955933] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/database.sql"] [unique_id "aqxW3hFTPRVSLOsRVhoYSAABJDs"]
[Thu Sep 17 15:08:46.862212 2026] [security2:error] [pid 955873:tid 955951] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/web.config.txt"] [unique_id "aqxW3hFTPRVSLOsRVhoYWAABLU0"]
[Thu Sep 17 15:08:46.893723 2026] [security2:error] [pid 955873:tid 955950] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/dbdump.sql"] [unique_id "aqxW3hFTPRVSLOsRVhoYWQABT0w"]
[Thu Sep 17 15:08:46.900122 2026] [security2:error] [pid 955873:tid 955956] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/privatekey.key"] [unique_id "aqxW3hFTPRVSLOsRVhoYWwABglI"]
[Thu Sep 17 15:08:46.989769 2026] [security2:error] [pid 955873:tid 955991] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config/config.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYZwABOnU"]
[Thu Sep 17 15:08:46.992629 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcached.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYagAAAVc"]
[Thu Sep 17 15:08:46.992748 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:34010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Memcached.php"] [unique_id "aqxW3hFTPRVSLOsRVhoYagAAAVc"]
[Thu Sep 17 15:08:47.042002 2026] [security2:error] [pid 955873:tid 955895] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/lms/.env"] [unique_id "aqxW3xFTPRVSLOsRVhoYbwABSxU"]
[Thu Sep 17 15:08:47.042839 2026] [security2:error] [pid 955873:tid 955973] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eris.media"] [uri "/wp-content/uploads/backup.sql"] [unique_id "aqxW3xFTPRVSLOsRVhoYcAABS2M"]
[Thu Sep 17 15:08:47.043011 2026] [security2:error] [pid 955873:tid 955980] [remote 34.62.82.165:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.82.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eris.media"] [uri "/config.php.old"] [unique_id "aqxW3xFTPRVSLOsRVhoYcQABS2o"]
[Thu Sep 17 15:08:47.159618 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:39060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/old/phpinfo.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYdwAAAUA"]
[Thu Sep 17 15:08:47.272999 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/MySQL.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYeQAAAWo"]
[Thu Sep 17 15:08:47.273094 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:34014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/MySQL.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYeQAAAWo"]
[Thu Sep 17 15:08:47.355795 2026] [security2:error] [pid 955873:tid 956064] [client 66.249.66.43:36849] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "memorytrackspodcast.com"] [uri "/robots.txt"] [unique_id "aqxW3xFTPRVSLOsRVhoYfAAAAUc"]
[Thu Sep 17 15:08:47.426694 2026] [security2:error] [pid 955873:tid 956074] [client 35.222.223.233:39066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYggAAAVE"]
[Thu Sep 17 15:08:47.434699 2026] [authz_core:error] [pid 955873:tid 956048] [client 20.244.34.24:51890] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:08:47.566882 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Redis.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYhgAAASc"]
[Thu Sep 17 15:08:47.566961 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:34030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Cache/Redis.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYhgAAASc"]
[Thu Sep 17 15:08:47.681405 2026] [security2:error] [pid 955873:tid 956054] [client 35.222.223.233:39078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/public/phpinfo.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYiAAAAT0"]
[Thu Sep 17 15:08:47.857468 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:34034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Caption.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYjAAAAWw"]
[Thu Sep 17 15:08:47.857544 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:34034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Caption.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYjAAAAWw"]
[Thu Sep 17 15:08:48.111499 2026] [security2:error] [pid 955873:tid 956091] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW3xFTPRVSLOsRVhoYkAAAAWI"]
[Thu Sep 17 15:08:48.163365 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Category.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlAAAATM"]
[Thu Sep 17 15:08:48.163453 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:34040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Category.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlAAAATM"]
[Thu Sep 17 15:08:48.172158 2026] [security2:error] [pid 955873:tid 956043] [client 186.105.232.15:59003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlQAAATI"]
[Thu Sep 17 15:08:48.172270 2026] [security2:error] [pid 955873:tid 956043] [client 186.105.232.15:59003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlQAAATI"]
[Thu Sep 17 15:08:48.197865 2026] [security2:error] [pid 955873:tid 956122] [client 35.222.223.233:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/php-info.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYlgAAAYE"]
[Thu Sep 17 15:08:48.442524 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/"] [unique_id "aqxW4BFTPRVSLOsRVhoYmQAAAUM"]
[Thu Sep 17 15:08:48.537423 2026] [access_compat:error] [pid 955873:tid 956121] [client 159.69.14.102:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/prehistoric-tales
[Thu Sep 17 15:08:48.568233 2026] [security2:error] [pid 955873:tid 956023] [client 35.222.223.233:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpversion.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYngAAAR4"]
[Thu Sep 17 15:08:48.609972 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/"] [unique_id "aqxW4BFTPRVSLOsRVhoYnwAAAVY"]
[Thu Sep 17 15:08:48.748768 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW4BFTPRVSLOsRVhoYpgAAAQ0"]
[Thu Sep 17 15:08:48.784141 2026] [security2:error] [pid 955873:tid 956022] [client 35.222.223.233:38730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/_phpinfo.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYpwAAAR0"]
[Thu Sep 17 15:08:48.978938 2026] [security2:error] [pid 955873:tid 956037] [client 185.55.149.49:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYrAAAASw"]
[Thu Sep 17 15:08:48.979045 2026] [security2:error] [pid 955873:tid 956037] [client 185.55.149.49:49838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYrAAAASw"]
[Thu Sep 17 15:08:49.090333 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYqwAAAX4"]
[Thu Sep 17 15:08:49.090359 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4BFTPRVSLOsRVhoYqwAAAX4"]
[Thu Sep 17 15:08:49.168049 2026] [security2:error] [pid 955873:tid 956012] [client 35.222.223.233:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/old_phpinfo.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYrgAAARM"]
[Thu Sep 17 15:08:49.229852 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/"] [unique_id "aqxW4RFTPRVSLOsRVhoYrwAAAXk"]
[Thu Sep 17 15:08:49.280523 2026] [security2:error] [pid 955873:tid 956068] [client 4.240.114.86:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYsAAAAUs"], referer: binance.com
[Thu Sep 17 15:08:49.387251 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/"] [unique_id "aqxW4RFTPRVSLOsRVhoYswAAAVg"]
[Thu Sep 17 15:08:49.419010 2026] [security2:error] [pid 955873:tid 956030] [client 35.222.223.233:38744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/server-info.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYtQAAASU"]
[Thu Sep 17 15:08:49.525390 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/wp-includes/SimplePie/library/SimplePie/Content/"] [unique_id "aqxW4RFTPRVSLOsRVhoYuAAAAUA"]
[Thu Sep 17 15:08:49.699245 2026] [security2:error] [pid 955873:tid 956099] [client 35.222.223.233:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/server-status.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYuwAAAWo"]
[Thu Sep 17 15:08:49.815157 2026] [security2:error] [pid 955873:tid 956064] [client 45.169.98.18:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYvAAAAUc"]
[Thu Sep 17 15:08:49.815263 2026] [security2:error] [pid 955873:tid 956064] [client 45.169.98.18:63248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYvAAAAUc"]
[Thu Sep 17 15:08:49.858181 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYugAAAVE"]
[Thu Sep 17 15:08:49.858203 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4RFTPRVSLOsRVhoYugAAAVE"]
[Thu Sep 17 15:08:50.021118 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:34050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/Sniffer.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYwAAAAVk"]
[Thu Sep 17 15:08:50.021212 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:34050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Content/Type/Sniffer.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYwAAAAVk"]
[Thu Sep 17 15:08:50.084946 2026] [security2:error] [pid 955873:tid 956039] [client 162.241.226.11:51364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYxAAAAS4"]
[Thu Sep 17 15:08:50.281993 2026] [security2:error] [pid 955873:tid 956063] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYwwAAAUY"]
[Thu Sep 17 15:08:50.312079 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Copyright.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYyQAAASA"]
[Thu Sep 17 15:08:50.312177 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:42194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Copyright.php"] [unique_id "aqxW4hFTPRVSLOsRVhoYyQAAASA"]
[Thu Sep 17 15:08:50.593628 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Core.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY1AAAATk"]
[Thu Sep 17 15:08:50.593748 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Core.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY1AAAATk"]
[Thu Sep 17 15:08:50.629266 2026] [security2:error] [pid 955873:tid 956088] [client 35.222.223.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY0wAAAV8"]
[Thu Sep 17 15:08:50.769428 2026] [security2:error] [pid 955873:tid 956126] [client 35.222.223.233:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxW4hFTPRVSLOsRVhoY1QAAAYU"]
[Thu Sep 17 15:08:50.874056 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Credit.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY2AAAATw"]
[Thu Sep 17 15:08:50.874142 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Credit.php"] [unique_id "aqxW4hFTPRVSLOsRVhoY2AAAATw"]
[Thu Sep 17 15:08:51.017954 2026] [security2:error] [pid 955873:tid 956089] [client 35.222.223.233:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY2wAAAWA"]
[Thu Sep 17 15:08:51.165300 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/"] [unique_id "aqxW4xFTPRVSLOsRVhoY3AAAASM"]
[Thu Sep 17 15:08:51.314094 2026] [security2:error] [pid 955873:tid 956015] [client 114.119.129.200:43515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vancouvermodernportraits.com"] [uri "/"] [unique_id "aqxW4xFTPRVSLOsRVhoY3gAAARY"], referer: https://www.vancouvermodernportraits.com/
[Thu Sep 17 15:08:51.326369 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/"] [unique_id "aqxW4xFTPRVSLOsRVhoY3QAAASE"]
[Thu Sep 17 15:08:51.333273 2026] [security2:error] [pid 955873:tid 956065] [client 35.222.223.233:38774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY3wAAAUg"]
[Thu Sep 17 15:08:51.470982 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW4xFTPRVSLOsRVhoY4gAAASQ"]
[Thu Sep 17 15:08:51.624771 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:38776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY5QAAAW0"]
[Thu Sep 17 15:08:51.716485 2026] [authz_core:error] [pid 955873:tid 956122] [client 5.189.145.112:62235] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:08:51.803506 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY5AAAAVU"]
[Thu Sep 17 15:08:51.803529 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY5AAAAVU"]
[Thu Sep 17 15:08:51.892780 2026] [security2:error] [pid 955873:tid 956051] [client 35.222.223.233:38786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY6gAAATo"]
[Thu Sep 17 15:08:51.945291 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/"] [unique_id "aqxW4xFTPRVSLOsRVhoY6wAAAQs"]
[Thu Sep 17 15:08:51.987385 2026] [security2:error] [pid 955873:tid 956072] [client 115.244.164.14:57426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY7gAAAU8"]
[Thu Sep 17 15:08:51.987447 2026] [security2:error] [pid 955873:tid 956072] [client 115.244.164.14:57426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW4xFTPRVSLOsRVhoY7gAAAU8"]
[Thu Sep 17 15:08:52.103126 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/"] [unique_id "aqxW5BFTPRVSLOsRVhoY8AAAAUw"]
[Thu Sep 17 15:08:52.169593 2026] [security2:error] [pid 955873:tid 956097] [client 162.241.226.11:25040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/wp-cron.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY8wAAAWg"]
[Thu Sep 17 15:08:52.246729 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/wp-includes/SimplePie/library/SimplePie/Decode/"] [unique_id "aqxW5BFTPRVSLOsRVhoY9QAAATY"]
[Thu Sep 17 15:08:52.417174 2026] [security2:error] [pid 955873:tid 956057] [client 35.222.223.233:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY_wAAAUA"]
[Thu Sep 17 15:08:52.583307 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY_AAAAVk"]
[Thu Sep 17 15:08:52.583332 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5BFTPRVSLOsRVhoY_AAAAVk"]
[Thu Sep 17 15:08:52.728903 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/Entities.php"] [unique_id "aqxW5BFTPRVSLOsRVhoZAQAAAXY"]
[Thu Sep 17 15:08:52.729012 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:42206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Decode/HTML/Entities.php"] [unique_id "aqxW5BFTPRVSLOsRVhoZAQAAAXY"]
[Thu Sep 17 15:08:52.812130 2026] [security2:error] [pid 955873:tid 956062] [client 35.222.223.233:38814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxW5BFTPRVSLOsRVhoZAgAAAUU"]
[Thu Sep 17 15:08:53.017918 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Enclosure.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZBwAAARo"]
[Thu Sep 17 15:08:53.018032 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:42218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Enclosure.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZBwAAARo"]
[Thu Sep 17 15:08:53.071147 2026] [autoindex:error] [pid 955873:tid 956016] [client 104.219.251.70:50692] AH01276: Cannot serve directory /home4/gcpmanag/public_html/website_a0c825a6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:08:53.212640 2026] [security2:error] [pid 955873:tid 956075] [client 35.222.223.233:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php.old"] [unique_id "aqxW5RFTPRVSLOsRVhoZCgAAAVI"]
[Thu Sep 17 15:08:53.307440 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Exception.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZDgAAATk"]
[Thu Sep 17 15:08:53.307546 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:42228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Exception.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZDgAAATk"]
[Thu Sep 17 15:08:53.324784 2026] [security2:error] [pid 955873:tid 956088] [client 4.240.114.86:52443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZDwAAAV8"], referer: binance.com
[Thu Sep 17 15:08:53.521724 2026] [security2:error] [pid 955873:tid 956021] [client 162.241.226.11:25050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/wp-cron.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZFAAAARw"]
[Thu Sep 17 15:08:53.560259 2026] [security2:error] [pid 955873:tid 956100] [client 35.222.223.233:38820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php~"] [unique_id "aqxW5RFTPRVSLOsRVhoZFQAAAWs"]
[Thu Sep 17 15:08:53.598237 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/File.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZFgAAATw"]
[Thu Sep 17 15:08:53.598339 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:42242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/File.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZFgAAATw"]
[Thu Sep 17 15:08:53.742565 2026] [security2:error] [pid 955873:tid 956033] [client 35.198.113.100:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZEwABKGw"]
[Thu Sep 17 15:08:53.854791 2026] [security2:error] [pid 955873:tid 956018] [client 35.222.223.233:38824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/info.php.bak"] [unique_id "aqxW5RFTPRVSLOsRVhoZGgAAARk"]
[Thu Sep 17 15:08:53.888837 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:42254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/"] [unique_id "aqxW5RFTPRVSLOsRVhoZHQAAAQw"]
[Thu Sep 17 15:08:53.901540 2026] [security2:error] [pid 955873:tid 955875] [remote 40.77.167.18:35798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "talent-in-borders.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZHgABHQE"], referer: https://talent-in-borders.com/lindsey-stirling-2026-snow-waltz-holiday-tour/
[Thu Sep 17 15:08:53.903915 2026] [security2:error] [pid 955873:tid 956084] [client 24.96.123.201:32949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW5RFTPRVSLOsRVhoZGAABW10"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:08:54.043059 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/"] [unique_id "aqxW5hFTPRVSLOsRVhoZIAAAAX8"]
[Thu Sep 17 15:08:54.127264 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZIQAAAWY"]
[Thu Sep 17 15:08:54.127353 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:42194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZIQAAAWY"]
[Thu Sep 17 15:08:54.145827 2026] [security2:error] [pid 955873:tid 956055] [client 35.222.223.233:38826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/phpinfo.php.save"] [unique_id "aqxW5hFTPRVSLOsRVhoZIgAAAT4"]
[Thu Sep 17 15:08:54.183467 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:42254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW5hFTPRVSLOsRVhoZIwAAAUk"]
[Thu Sep 17 15:08:54.439844 2026] [security2:error] [pid 955873:tid 956113] [client 35.222.223.233:38838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZKQAAAXg"]
[Thu Sep 17 15:08:54.515463 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZJgAAAYE"]
[Thu Sep 17 15:08:54.515482 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZJgAAAYE"]
[Thu Sep 17 15:08:54.656755 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/Parser.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZLQAAAXc"]
[Thu Sep 17 15:08:54.656877 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:42254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/HTTP/Parser.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZLQAAAXc"]
[Thu Sep 17 15:08:54.703314 2026] [security2:error] [pid 955873:tid 956077] [client 35.222.223.233:38840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZLgAAAVQ"]
[Thu Sep 17 15:08:54.922640 2026] [security2:error] [pid 955873:tid 956037] [client 193.36.224.219:65425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/000.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZMgAAASw"]
[Thu Sep 17 15:08:54.970893 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/IRI.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZNgAAAUs"]
[Thu Sep 17 15:08:54.970994 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:42270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/IRI.php"] [unique_id "aqxW5hFTPRVSLOsRVhoZNgAAAUs"]
[Thu Sep 17 15:08:55.009594 2026] [security2:error] [pid 955873:tid 956096] [client 35.222.223.233:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZNwAAAWc"]
[Thu Sep 17 15:08:55.256104 2026] [security2:error] [pid 955873:tid 956064] [client 35.222.223.233:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOQAAAUc"]
[Thu Sep 17 15:08:55.262431 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Item.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOgAAAVk"]
[Thu Sep 17 15:08:55.262510 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:42282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Item.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOgAAAVk"]
[Thu Sep 17 15:08:55.269339 2026] [security2:error] [pid 955873:tid 956040] [client 193.36.224.168:35273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/about.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZOwAAAS8"]
[Thu Sep 17 15:08:55.338655 2026] [security2:error] [pid 955873:tid 956062] [client 20.244.34.24:57795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZPQAAAUU"], referer: binance.com
[Thu Sep 17 15:08:55.562087 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Locator.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZQQAAARc"]
[Thu Sep 17 15:08:55.562328 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Locator.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZQQAAARc"]
[Thu Sep 17 15:08:55.580156 2026] [security2:error] [pid 955873:tid 956020] [client 35.222.223.233:38858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZQgAAARs"]
[Thu Sep 17 15:08:55.859263 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Misc.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZSQAAAV8"]
[Thu Sep 17 15:08:55.859361 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:42298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Misc.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZSQAAAV8"]
[Thu Sep 17 15:08:55.896593 2026] [security2:error] [pid 955873:tid 956129] [client 35.222.223.233:38874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/www/phpinfo.php"] [unique_id "aqxW5xFTPRVSLOsRVhoZTAAAAYg"]
[Thu Sep 17 15:08:56.174357 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:42304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/"] [unique_id "aqxW6BFTPRVSLOsRVhoZUQAAATM"]
[Thu Sep 17 15:08:56.301079 2026] [security2:error] [pid 955873:tid 956100] [client 35.222.223.233:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZUgAAAWs"]
[Thu Sep 17 15:08:56.333062 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/"] [unique_id "aqxW6BFTPRVSLOsRVhoZUwAAATw"]
[Thu Sep 17 15:08:56.478038 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:42304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW6BFTPRVSLOsRVhoZWAAAARU"]
[Thu Sep 17 15:08:56.618047 2026] [security2:error] [pid 955873:tid 956036] [client 193.36.224.170:23053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWQAAASs"]
[Thu Sep 17 15:08:56.643567 2026] [security2:error] [pid 955873:tid 956033] [client 35.222.223.233:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWwAAASg"]
[Thu Sep 17 15:08:56.812548 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWgAAASs"]
[Thu Sep 17 15:08:56.812573 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZWgAAASs"]
[Thu Sep 17 15:08:56.858329 2026] [security2:error] [pid 955873:tid 956084] [client 216.24.219.103:30703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/about.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZYAAAAVs"]
[Thu Sep 17 15:08:56.962482 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/IPv6.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZZQAAASY"]
[Thu Sep 17 15:08:56.962581 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:42304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Net/IPv6.php"] [unique_id "aqxW6BFTPRVSLOsRVhoZZQAAASY"]
[Thu Sep 17 15:08:57.017544 2026] [security2:error] [pid 955873:tid 956108] [client 4.240.114.86:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZZwAAAXM"], referer: binance.com
[Thu Sep 17 15:08:57.032966 2026] [security2:error] [pid 955873:tid 956102] [client 35.222.223.233:38888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/site/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZaAAAAW0"]
[Thu Sep 17 15:08:57.256375 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:42318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/"] [unique_id "aqxW6RFTPRVSLOsRVhoZaQAAAXk"]
[Thu Sep 17 15:08:57.264231 2026] [security2:error] [pid 955873:tid 956056] [client 35.222.223.233:38902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZagAAAT8"]
[Thu Sep 17 15:08:57.381382 2026] [security2:error] [pid 955873:tid 956030] [client 216.24.219.97:21985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZawAAASU"]
[Thu Sep 17 15:08:57.426088 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/"] [unique_id "aqxW6RFTPRVSLOsRVhoZbQAAARM"]
[Thu Sep 17 15:08:57.468953 2026] [security2:error] [pid 955873:tid 956097] [client 35.222.223.233:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZcwAAAWg"]
[Thu Sep 17 15:08:57.567016 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:42318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW6RFTPRVSLOsRVhoZdgAAATY"]
[Thu Sep 17 15:08:57.638831 2026] [security2:error] [pid 955873:tid 956054] [client 193.36.224.219:38045] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-includes/hp2.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZdwAAAT0"]
[Thu Sep 17 15:08:57.768275 2026] [security2:error] [pid 955873:tid 956013] [client 35.222.223.233:33874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZfQAAARQ"]
[Thu Sep 17 15:08:57.891999 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZegAAAW8"]
[Thu Sep 17 15:08:57.892032 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZegAAAW8"]
[Thu Sep 17 15:08:58.042407 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/Date.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZhQAAARc"]
[Thu Sep 17 15:08:58.042530 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:42318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parse/Date.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZhQAAARc"]
[Thu Sep 17 15:08:58.180007 2026] [security2:error] [pid 955873:tid 956093] [client 172.86.81.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hendersonlife.info"] [uri "/index.php"] [unique_id "aqxW6RFTPRVSLOsRVhoZfAAAAWQ"], referer: http://hendersonlife.info/.git/config
[Thu Sep 17 15:08:58.222643 2026] [security2:error] [pid 955873:tid 956105] [client 35.222.223.233:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/core/phpinfo.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZjQAAAXA"]
[Thu Sep 17 15:08:58.286995 2026] [security2:error] [pid 955873:tid 956021] [client 193.36.224.222:41803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/bless.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZjwAAARw"]
[Thu Sep 17 15:08:58.328745 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parser.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZkgAAAUM"]
[Thu Sep 17 15:08:58.328860 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Parser.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZkgAAAUM"]
[Thu Sep 17 15:08:58.394260 2026] [security2:error] [pid 955873:tid 956009] [client 24.96.123.201:60723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZkAABECA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260611193227&hideliu=1&hidemyself=1&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:08:58.530893 2026] [security2:error] [pid 955873:tid 956073] [client 35.222.223.233:33890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.223.222.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kidsandlifeot.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmAAAAVA"]
[Thu Sep 17 15:08:58.613797 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Rating.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmwAAAVs"]
[Thu Sep 17 15:08:58.613897 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:42324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Rating.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmwAAAVs"]
[Thu Sep 17 15:08:58.714464 2026] [security2:error] [pid 955873:tid 956056] [client 216.24.219.37:25331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/goods.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZoQAAAT8"]
[Thu Sep 17 15:08:58.901672 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:42332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Registry.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZpAAAAQo"]
[Thu Sep 17 15:08:58.901794 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:42332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Registry.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZpAAAAQo"]
[Thu Sep 17 15:08:58.973030 2026] [security2:error] [pid 955873:tid 956005] [client 193.36.224.149:60867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/blurbs.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZpgAAAQw"]
[Thu Sep 17 15:08:59.024716 2026] [security2:error] [pid 955873:tid 956004] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZowAAAQs"]
[Thu Sep 17 15:08:59.091814 2026] [core:error] [pid 955873:tid 956087] [client 195.96.139.110:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:59.091841 2026] [core:error] [pid 955873:tid 956087] [client 195.96.139.110:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:08:59.129450 2026] [security2:error] [pid 955873:tid 956030] [client 186.105.232.15:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrQAAASU"]
[Thu Sep 17 15:08:59.131277 2026] [security2:error] [pid 955873:tid 956030] [client 186.105.232.15:59594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrQAAASU"]
[Thu Sep 17 15:08:59.164639 2026] [security2:error] [pid 955873:tid 956065] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pfa.ccv.mybluehost.me"] [uri "/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZmQAAAUg"]
[Thu Sep 17 15:08:59.164877 2026] [security2:error] [pid 955873:tid 956113] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pfa.ccv.mybluehost.me"] [uri "/index.php"] [unique_id "aqxW6hFTPRVSLOsRVhoZogAAAXg"]
[Thu Sep 17 15:08:59.182033 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Restriction.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrwAAATc"]
[Thu Sep 17 15:08:59.182120 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:42344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Restriction.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZrwAAATc"]
[Thu Sep 17 15:08:59.249447 2026] [security2:error] [pid 955873:tid 956052] [client 104.234.19.143:41469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZsAAAATs"]
[Thu Sep 17 15:08:59.306024 2026] [security2:error] [pid 955873:tid 956068] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZqgAAAUs"]
[Thu Sep 17 15:08:59.463027 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:42348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Sanitize.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtAAAAXA"]
[Thu Sep 17 15:08:59.463157 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:42348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Sanitize.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtAAAAXA"]
[Thu Sep 17 15:08:59.541974 2026] [security2:error] [pid 955873:tid 956122] [client 185.55.149.49:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtQAAAYE"]
[Thu Sep 17 15:08:59.542067 2026] [security2:error] [pid 955873:tid 956122] [client 185.55.149.49:52703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtQAAAYE"]
[Thu Sep 17 15:08:59.584389 2026] [security2:error] [pid 955873:tid 956103] [client 193.36.224.108:49879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/abcd.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZtgAAAW4"]
[Thu Sep 17 15:08:59.618062 2026] [security2:error] [pid 955873:tid 956008] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZswAAAQ8"]
[Thu Sep 17 15:08:59.776366 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Source.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZuwAAAUM"]
[Thu Sep 17 15:08:59.776470 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:42350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/Source.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZuwAAAUM"]
[Thu Sep 17 15:08:59.949631 2026] [security2:error] [pid 955873:tid 956083] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZugAAAVo"]
[Thu Sep 17 15:09:00.000969 2026] [security2:error] [pid 955873:tid 956079] [client 193.36.224.116:59785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxW6xFTPRVSLOsRVhoZvgAAAVY"]
[Thu Sep 17 15:09:00.054944 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/"] [unique_id "aqxW7BFTPRVSLOsRVhoZwgAAAWs"]
[Thu Sep 17 15:09:00.216681 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/"] [unique_id "aqxW7BFTPRVSLOsRVhoZwwAAASM"]
[Thu Sep 17 15:09:00.217295 2026] [security2:error] [pid 955873:tid 956020] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZwQAAARs"]
[Thu Sep 17 15:09:00.286569 2026] [security2:error] [pid 955873:tid 956033] [client 45.169.98.18:63813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZxgAAASg"]
[Thu Sep 17 15:09:00.286997 2026] [security2:error] [pid 955873:tid 956033] [client 45.169.98.18:63813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZxgAAASg"]
[Thu Sep 17 15:09:00.335968 2026] [security2:error] [pid 955873:tid 956084] [client 216.24.219.21:57537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/dex.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZyAAAAVs"]
[Thu Sep 17 15:09:00.357697 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/wp-includes/SimplePie/library/SimplePie/"] [unique_id "aqxW7BFTPRVSLOsRVhoZygAAASY"]
[Thu Sep 17 15:09:00.493310 2026] [security2:error] [pid 955873:tid 956124] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZxwAAAYM"]
[Thu Sep 17 15:09:00.728640 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZzQAAATo"]
[Thu Sep 17 15:09:00.728673 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZzQAAATo"]
[Thu Sep 17 15:09:00.791596 2026] [security2:error] [pid 955873:tid 956069] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZzgAAAUw"]
[Thu Sep 17 15:09:00.868546 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3AAAAQs"]
[Thu Sep 17 15:09:00.896868 2026] [security2:error] [pid 955873:tid 956087] [client 4.240.114.86:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3gAAAV4"], referer: binance.com
[Thu Sep 17 15:09:00.931259 2026] [security2:error] [pid 955873:tid 956090] [client 216.24.219.88:53881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3wAAAWE"]
[Thu Sep 17 15:09:00.971845 2026] [security2:error] [pid 955873:tid 956071] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jcktax.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ2AAAAU4"], referer: https://pfa.ccv.mybluehost.me/api/session/properties
[Thu Sep 17 15:09:00.971845 2026] [security2:error] [pid 955873:tid 956005] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jcktax.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ2QAAAQw"], referer: http://pfa.ccv.mybluehost.me/api/session/properties
[Thu Sep 17 15:09:01.041519 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/"] [unique_id "aqxW7RFTPRVSLOsRVhoZ4QAAAUg"]
[Thu Sep 17 15:09:01.126963 2026] [security2:error] [pid 955873:tid 956115] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7BFTPRVSLOsRVhoZ3QAAAXo"]
[Thu Sep 17 15:09:01.179014 2026] [security2:error] [pid 955873:tid 956026] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/wp-includes/SimplePie/library/SimplePie/XML/"] [unique_id "aqxW7RFTPRVSLOsRVhoZ4wAAASE"]
[Thu Sep 17 15:09:01.438107 2026] [security2:error] [pid 955873:tid 956112] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ5gAAAXc"]
[Thu Sep 17 15:09:01.560201 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ6wAAAWQ"]
[Thu Sep 17 15:09:01.560306 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ6wAAAWQ"]
[Thu Sep 17 15:09:01.697539 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/Parser.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ9AAAAWI"]
[Thu Sep 17 15:09:01.697679 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/XML/Declaration/Parser.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ9AAAAWI"]
[Thu Sep 17 15:09:01.805841 2026] [security2:error] [pid 955873:tid 956078] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ8AAAAVU"]
[Thu Sep 17 15:09:01.985926 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/gzdecode.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ_gAAAVo"]
[Thu Sep 17 15:09:01.986032 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:47380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/library/SimplePie/gzdecode.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ_gAAAVo"]
[Thu Sep 17 15:09:02.097899 2026] [security2:error] [pid 955873:tid 956053] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7RFTPRVSLOsRVhoZ_QAAATw"]
[Thu Sep 17 15:09:02.120290 2026] [security2:error] [pid 955873:tid 955922] [remote 47.128.98.144:21510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cobblehillstudio.net"] [uri "/robots.txt"] [unique_id "aqxW7hFTPRVSLOsRVhoaAAABcjA"]
[Thu Sep 17 15:09:02.264919 2026] [security2:error] [pid 955873:tid 956011] [client 40.87.20.23:28172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "dfdub.com"] [uri "/"] [unique_id "aqxW7hFTPRVSLOsRVhoaBwAAARI"]
[Thu Sep 17 15:09:02.274390 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:47392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/"] [unique_id "aqxW7hFTPRVSLOsRVhoaCQAAASM"]
[Thu Sep 17 15:09:02.325912 2026] [security2:error] [pid 955873:tid 956031] [client 40.87.20.23:28172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=:"] [hostname "dfdub.com"] [uri "/"] [unique_id "aqxW7hFTPRVSLOsRVhoaCgAAASY"]
[Thu Sep 17 15:09:02.403894 2026] [security2:error] [pid 955873:tid 956121] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaAwAAAYA"]
[Thu Sep 17 15:09:02.424420 2026] [security2:error] [pid 955873:tid 956114] [client 193.36.224.222:33031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/css/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDAAAAXk"]
[Thu Sep 17 15:09:02.434687 2026] [authz_core:error] [pid 955873:tid 956095] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/src/error_log
[Thu Sep 17 15:09:02.477815 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/"] [unique_id "aqxW7hFTPRVSLOsRVhoaCwAAAWY"]
[Thu Sep 17 15:09:02.589412 2026] [security2:error] [pid 955873:tid 956020] [client 115.244.164.14:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDwAAARs"]
[Thu Sep 17 15:09:02.589519 2026] [security2:error] [pid 955873:tid 956020] [client 115.244.164.14:58065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDwAAARs"]
[Thu Sep 17 15:09:02.625277 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:47392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/wp-includes/SimplePie/"] [unique_id "aqxW7hFTPRVSLOsRVhoaEQAAAVA"]
[Thu Sep 17 15:09:02.715129 2026] [security2:error] [pid 955873:tid 956056] [client 176.134.14.88:3765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaEAABPzI"]
[Thu Sep 17 15:09:02.715403 2026] [security2:error] [pid 955873:tid 956043] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaDgAAATI"]
[Thu Sep 17 15:09:02.969585 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaHwAAAWE"]
[Thu Sep 17 15:09:02.969620 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaHwAAAWE"]
[Thu Sep 17 15:09:03.041719 2026] [security2:error] [pid 955873:tid 956067] [client 216.24.219.36:52153] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaIQAAAUo"]
[Thu Sep 17 15:09:03.059352 2026] [security2:error] [pid 955873:tid 956077] [client 35.222.223.233:33904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxW7hFTPRVSLOsRVhoaIAAAAVQ"]
[Thu Sep 17 15:09:03.109621 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Author.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaIgAAAXo"]
[Thu Sep 17 15:09:03.109778 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:47392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Author.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaIgAAAXo"]
[Thu Sep 17 15:09:03.398577 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:47400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaJwAAARc"]
[Thu Sep 17 15:09:03.398669 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:47400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaJwAAARc"]
[Thu Sep 17 15:09:03.412625 2026] [security2:error] [pid 955873:tid 956092] [client 193.36.224.226:38311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaKAAAAWM"]
[Thu Sep 17 15:09:03.700404 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:47410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/"] [unique_id "aqxW7xFTPRVSLOsRVhoaLAAAAYE"]
[Thu Sep 17 15:09:03.707385 2026] [security2:error] [pid 955873:tid 956111] [client 216.24.219.102:23435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaLQAAAXY"]
[Thu Sep 17 15:09:03.853342 2026] [authz_core:error] [pid 955873:tid 956057] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/src/Cache/error_log
[Thu Sep 17 15:09:03.860987 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/"] [unique_id "aqxW7xFTPRVSLOsRVhoaMQAAAUA"]
[Thu Sep 17 15:09:04.001732 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:47410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/wp-includes/SimplePie/src/"] [unique_id "aqxW8BFTPRVSLOsRVhoaNAAAAV8"]
[Thu Sep 17 15:09:04.125948 2026] [security2:error] [pid 955873:tid 956075] [client 193.36.224.150:40341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaNQAAAVI"]
[Thu Sep 17 15:09:04.251472 2026] [security2:error] [pid 955873:tid 956098] [client 4.240.114.86:58602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaOwAAAWk"], referer: binance.com
[Thu Sep 17 15:09:04.327803 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaOAAAARg"]
[Thu Sep 17 15:09:04.327832 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaOAAAARg"]
[Thu Sep 17 15:09:04.469861 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:47410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Base.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaPgAAAWs"]
[Thu Sep 17 15:09:04.470003 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:47410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Base.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaPgAAAWs"]
[Thu Sep 17 15:09:04.671819 2026] [security2:error] [pid 955873:tid 956007] [client 193.36.224.212:41815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/file.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaPwAAAQ4"]
[Thu Sep 17 15:09:04.764490 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/BaseDataCache.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaQwAAAYM"]
[Thu Sep 17 15:09:04.764586 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:47420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/BaseDataCache.php"] [unique_id "aqxW8BFTPRVSLOsRVhoaQwAAAYM"]
[Thu Sep 17 15:09:05.069843 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:47424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/CallableNameFilter.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaRQAAAX0"]
[Thu Sep 17 15:09:05.069944 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:47424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/CallableNameFilter.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaRQAAAX0"]
[Thu Sep 17 15:09:05.123532 2026] [security2:error] [pid 955873:tid 956041] [client 193.36.224.149:65499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaRgAAATA"]
[Thu Sep 17 15:09:05.377607 2026] [security2:error] [pid 955873:tid 956025] [client 5.102.173.71:56448] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxW7xFTPRVSLOsRVhoaMwAAASA"]
[Thu Sep 17 15:09:05.380903 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DB.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTQAAAWo"]
[Thu Sep 17 15:09:05.381012 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:47430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DB.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTQAAAWo"]
[Thu Sep 17 15:09:05.458999 2026] [security2:error] [pid 955873:tid 956038] [client 154.190.208.131:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTgAAAS0"]
[Thu Sep 17 15:09:05.459100 2026] [security2:error] [pid 955873:tid 956038] [client 154.190.208.131:41450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTgAAAS0"]
[Thu Sep 17 15:09:05.507248 2026] [security2:error] [pid 955873:tid 956087] [client 193.36.224.148:48949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-mail.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaTwAAAV4"]
[Thu Sep 17 15:09:05.676231 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DataCache.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaUQAAAU0"]
[Thu Sep 17 15:09:05.676350 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:47432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/DataCache.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaUQAAAU0"]
[Thu Sep 17 15:09:05.802276 2026] [security2:error] [pid 955873:tid 956109] [client 193.36.224.146:55871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/ioxi-o.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaVQAAAXQ"]
[Thu Sep 17 15:09:05.944361 2026] [security2:error] [pid 955873:tid 956030] [client 157.20.87.107:59913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaVAABJR4"]
[Thu Sep 17 15:09:05.976017 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/File.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaWAAAAYQ"]
[Thu Sep 17 15:09:05.976147 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/File.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaWAAAAYQ"]
[Thu Sep 17 15:09:06.051496 2026] [authz_core:error] [pid 955873:tid 956020] [client 5.189.145.112:60688] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:09:06.242587 2026] [security2:error] [pid 955873:tid 956042] [client 5.102.173.71:56448] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxW8RFTPRVSLOsRVhoaUAAAATE"]
[Thu Sep 17 15:09:06.257718 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcache.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaXQAAAUQ"]
[Thu Sep 17 15:09:06.257808 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:47454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcache.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaXQAAAUQ"]
[Thu Sep 17 15:09:06.294827 2026] [security2:error] [pid 955873:tid 956016] [client 104.234.19.146:38797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaXwAAARc"]
[Thu Sep 17 15:09:06.300465 2026] [security2:error] [pid 955873:tid 956092] [client 20.244.34.24:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaYQAAAWM"], referer: binance.com
[Thu Sep 17 15:09:06.534204 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:47464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcached.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaYgAAAVk"]
[Thu Sep 17 15:09:06.534295 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:47464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Memcached.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaYgAAAVk"]
[Thu Sep 17 15:09:06.815179 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/MySQL.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaagAAAQ8"]
[Thu Sep 17 15:09:06.815279 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:47480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/MySQL.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaagAAAQ8"]
[Thu Sep 17 15:09:06.851469 2026] [security2:error] [pid 955873:tid 956117] [client 193.36.224.152:39827] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/style.php"] [unique_id "aqxW8hFTPRVSLOsRVhoaawAAAXw"]
[Thu Sep 17 15:09:07.097646 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:47484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/NameFilter.php"] [unique_id "aqxW8xFTPRVSLOsRVhoabQAAAVE"]
[Thu Sep 17 15:09:07.097777 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:47484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/NameFilter.php"] [unique_id "aqxW8xFTPRVSLOsRVhoabQAAAVE"]
[Thu Sep 17 15:09:07.350912 2026] [security2:error] [pid 955873:tid 956086] [client 193.36.224.151:44667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/style.php"] [unique_id "aqxW8xFTPRVSLOsRVhoacQAAAV0"]
[Thu Sep 17 15:09:07.391562 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Psr16.php"] [unique_id "aqxW8xFTPRVSLOsRVhoacgAAARA"]
[Thu Sep 17 15:09:07.391674 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Psr16.php"] [unique_id "aqxW8xFTPRVSLOsRVhoacgAAARA"]
[Thu Sep 17 15:09:07.676852 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:47504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Redis.php"] [unique_id "aqxW8xFTPRVSLOsRVhoadQAAAUM"]
[Thu Sep 17 15:09:07.677018 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:47504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Cache/Redis.php"] [unique_id "aqxW8xFTPRVSLOsRVhoadQAAAUM"]
[Thu Sep 17 15:09:07.723594 2026] [security2:error] [pid 955873:tid 956014] [client 193.36.224.168:64323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/themes/style.php"] [unique_id "aqxW8xFTPRVSLOsRVhoaewAAARU"]
[Thu Sep 17 15:09:07.959032 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:47516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Caption.php"] [unique_id "aqxW8xFTPRVSLOsRVhoafQAAARM"]
[Thu Sep 17 15:09:07.959141 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:47516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Caption.php"] [unique_id "aqxW8xFTPRVSLOsRVhoafQAAARM"]
[Thu Sep 17 15:09:08.260043 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Category.php"] [unique_id "aqxW9BFTPRVSLOsRVhoaggAAAU8"]
[Thu Sep 17 15:09:08.260147 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Category.php"] [unique_id "aqxW9BFTPRVSLOsRVhoaggAAAU8"]
[Thu Sep 17 15:09:08.419544 2026] [security2:error] [pid 955873:tid 956054] [client 193.36.224.226:24183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-editor.php"] [unique_id "aqxW9BFTPRVSLOsRVhoahgAAAT0"]
[Thu Sep 17 15:09:08.542009 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/"] [unique_id "aqxW9BFTPRVSLOsRVhoaigAAAQw"]
[Thu Sep 17 15:09:08.707760 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/"] [unique_id "aqxW9BFTPRVSLOsRVhoaiwAAAS0"]
[Thu Sep 17 15:09:08.759073 2026] [security2:error] [pid 955873:tid 956109] [client 104.234.19.143:31787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/lufix.php"] [unique_id "aqxW9BFTPRVSLOsRVhoajwAAAXQ"]
[Thu Sep 17 15:09:08.851560 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/wp-includes/SimplePie/src/"] [unique_id "aqxW9BFTPRVSLOsRVhoakAAAAUc"]
[Thu Sep 17 15:09:08.952959 2026] [security2:error] [pid 955873:tid 956113] [client 4.240.114.86:61353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxW9BFTPRVSLOsRVhoalAAAAXg"], referer: binance.com
[Thu Sep 17 15:09:09.089034 2026] [security2:error] [pid 955873:tid 956044] [client 193.36.224.148:28647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/txets.php"] [unique_id "aqxW9RFTPRVSLOsRVhoalwAAATM"]
[Thu Sep 17 15:09:09.100895 2026] [security2:error] [pid 955873:tid 956125] [client 162.241.226.11:52654] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxW9RFTPRVSLOsRVhoalgAAAYQ"]
[Thu Sep 17 15:09:09.195449 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9BFTPRVSLOsRVhoalQAAAUg"]
[Thu Sep 17 15:09:09.195475 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9BFTPRVSLOsRVhoalQAAAUg"]
[Thu Sep 17 15:09:09.343122 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/"] [unique_id "aqxW9RFTPRVSLOsRVhoangAAAUQ"]
[Thu Sep 17 15:09:09.355474 2026] [security2:error] [pid 955873:tid 956092] [client 193.36.224.148:29017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxW9RFTPRVSLOsRVhoanwAAAWM"]
[Thu Sep 17 15:09:09.396071 2026] [security2:error] [pid 955873:tid 956058] [client 162.241.226.11:32906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxW9BFTPRVSLOsRVhoahAAAAUw"]
[Thu Sep 17 15:09:09.432497 2026] [security2:error] [pid 955873:tid 956013] [client 80.189.24.86:41297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoanQABFC4"]
[Thu Sep 17 15:09:09.502484 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/"] [unique_id "aqxW9RFTPRVSLOsRVhoaogAAAUs"]
[Thu Sep 17 15:09:09.644379 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/wp-includes/SimplePie/src/Content/"] [unique_id "aqxW9RFTPRVSLOsRVhoapAAAAT4"]
[Thu Sep 17 15:09:09.734317 2026] [security2:error] [pid 955873:tid 956062] [client 216.24.219.37:47511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-admin/txets.php"] [unique_id "aqxW9RFTPRVSLOsRVhoapgAAAUU"]
[Thu Sep 17 15:09:09.978410 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoaqAAAAVU"]
[Thu Sep 17 15:09:09.978434 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoaqAAAAVU"]
[Thu Sep 17 15:09:10.082218 2026] [security2:error] [pid 955873:tid 956008] [client 186.105.232.15:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoarwAAAQ8"]
[Thu Sep 17 15:09:10.082334 2026] [security2:error] [pid 955873:tid 956008] [client 186.105.232.15:60191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoarwAAAQ8"]
[Thu Sep 17 15:09:10.120119 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:47534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/Sniffer.php"] [unique_id "aqxW9hFTPRVSLOsRVhoasAAAAXc"]
[Thu Sep 17 15:09:10.120224 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:47534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Content/Type/Sniffer.php"] [unique_id "aqxW9hFTPRVSLOsRVhoasAAAAXc"]
[Thu Sep 17 15:09:10.286422 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoatAAAAXU"]
[Thu Sep 17 15:09:10.286575 2026] [security2:error] [pid 955873:tid 956110] [client 185.55.149.49:53330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoatAAAAXU"]
[Thu Sep 17 15:09:10.291777 2026] [security2:error] [pid 955873:tid 956007] [client 216.24.219.101:61905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/wp-includes/txets.php"] [unique_id "aqxW9hFTPRVSLOsRVhoatQAAAQ4"]
[Thu Sep 17 15:09:10.401037 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Copyright.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauAAAAYA"]
[Thu Sep 17 15:09:10.401142 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:59180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Copyright.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauAAAAYA"]
[Thu Sep 17 15:09:10.543285 2026] [security2:error] [pid 955873:tid 956118] [client 162.241.226.11:32916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxW9RFTPRVSLOsRVhoaoQAAAYY"]
[Thu Sep 17 15:09:10.692961 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Credit.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauwAAATA"]
[Thu Sep 17 15:09:10.693044 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:59188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Credit.php"] [unique_id "aqxW9hFTPRVSLOsRVhoauwAAATA"]
[Thu Sep 17 15:09:10.803578 2026] [security2:error] [pid 955873:tid 956043] [client 45.169.98.18:64370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoavwAAATI"]
[Thu Sep 17 15:09:10.804097 2026] [security2:error] [pid 955873:tid 956043] [client 45.169.98.18:64370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxW9hFTPRVSLOsRVhoavwAAATI"]
[Thu Sep 17 15:09:10.979487 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Enclosure.php"] [unique_id "aqxW9hFTPRVSLOsRVhoawQAAASM"]
[Thu Sep 17 15:09:10.979570 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:59192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Enclosure.php"] [unique_id "aqxW9hFTPRVSLOsRVhoawQAAASM"]
[Thu Sep 17 15:09:11.266383 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Exception.php"] [unique_id "aqxW9xFTPRVSLOsRVhoaygAAAYQ"]
[Thu Sep 17 15:09:11.266478 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:59194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Exception.php"] [unique_id "aqxW9xFTPRVSLOsRVhoaygAAAYQ"]
[Thu Sep 17 15:09:11.542031 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/File.php"] [unique_id "aqxW9xFTPRVSLOsRVhoazQAAATg"]
[Thu Sep 17 15:09:11.542105 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/File.php"] [unique_id "aqxW9xFTPRVSLOsRVhoazQAAATg"]
[Thu Sep 17 15:09:11.824198 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:59212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Gzdecode.php"] [unique_id "aqxW9xFTPRVSLOsRVhoa0gAAAWM"]
[Thu Sep 17 15:09:11.824308 2026] [security2:error] [pid 955873:tid 956092] [client 143.244.57.120:59212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Gzdecode.php"] [unique_id "aqxW9xFTPRVSLOsRVhoa0gAAAWM"]
[Thu Sep 17 15:09:12.134549 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:59224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/"] [unique_id "aqxW-BFTPRVSLOsRVhoa1gAAAQ0"]
[Thu Sep 17 15:09:12.297897 2026] [authz_core:error] [pid 955873:tid 956062] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/SimplePie/src/HTTP/error_log
[Thu Sep 17 15:09:12.302297 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/"] [unique_id "aqxW-BFTPRVSLOsRVhoa2gAAAUU"]
[Thu Sep 17 15:09:12.445295 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:59224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/wp-includes/SimplePie/src/"] [unique_id "aqxW-BFTPRVSLOsRVhoa3gAAASU"]
[Thu Sep 17 15:09:12.810436 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa4QAAAX4"]
[Thu Sep 17 15:09:12.810466 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa4QAAAX4"]
[Thu Sep 17 15:09:12.951701 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Client.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa8QAAAYU"]
[Thu Sep 17 15:09:12.951865 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Client.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa8QAAAYU"]
[Thu Sep 17 15:09:12.956509 2026] [security2:error] [pid 955873:tid 956015] [client 127.0.0.1:40804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxW-BFTPRVSLOsRVhoa8AAAARY"]
[Thu Sep 17 15:09:12.956581 2026] [security2:error] [pid 955873:tid 956022] [client 127.0.0.1:40802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.showtimeeventsvb.com"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxW-BFTPRVSLOsRVhoa7gAAAR0"]
[Thu Sep 17 15:09:12.956749 2026] [security2:error] [pid 955873:tid 956007] [client 74.7.228.8:47762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.showtimeeventsvb.com"] [uri "/robots.txt"] [unique_id "aqxW-BFTPRVSLOsRVhoa7QABDnI"]
[Thu Sep 17 15:09:12.960422 2026] [security2:error] [pid 955873:tid 956081] [client 4.240.114.86:63463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa8gAAAVg"], referer: binance.com
[Thu Sep 17 15:09:12.983708 2026] [security2:error] [pid 955873:tid 956104] [client 181.232.231.164:38465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxW-BFTPRVSLOsRVhoa7AABb1s"]
[Thu Sep 17 15:09:13.124272 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa9wAAAXU"]
[Thu Sep 17 15:09:13.124348 2026] [security2:error] [pid 955873:tid 956110] [client 115.244.164.14:58717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa9wAAAXU"]
[Thu Sep 17 15:09:13.238080 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:59234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/ClientException.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa-gAAAXE"]
[Thu Sep 17 15:09:13.238176 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:59234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/ClientException.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa-gAAAXE"]
[Thu Sep 17 15:09:13.266541 2026] [security2:error] [pid 955873:tid 955973] [remote 47.128.31.238:59768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cobblehillstudio.net"] [uri "/robots.txt"] [unique_id "aqxW-RFTPRVSLOsRVhoa-wABdmM"]
[Thu Sep 17 15:09:13.543896 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/FileClient.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa_gAAAVM"]
[Thu Sep 17 15:09:13.543979 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:59236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/FileClient.php"] [unique_id "aqxW-RFTPRVSLOsRVhoa_gAAAVM"]
[Thu Sep 17 15:09:13.822459 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:59252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Parser.php"] [unique_id "aqxW-RFTPRVSLOsRVhobAwAAAU4"]
[Thu Sep 17 15:09:13.822554 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:59252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Parser.php"] [unique_id "aqxW-RFTPRVSLOsRVhobAwAAAU4"]
[Thu Sep 17 15:09:13.924506 2026] [security2:error] [pid 955873:tid 956045] [client 216.24.219.38:20953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/goods.php"] [unique_id "aqxW-RFTPRVSLOsRVhobBgAAATQ"]
[Thu Sep 17 15:09:14.098107 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr7Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobBwAAATg"]
[Thu Sep 17 15:09:14.098197 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:59260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr7Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobBwAAATg"]
[Thu Sep 17 15:09:14.375983 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr18Client.php"] [unique_id "aqxW-hFTPRVSLOsRVhobDwAAAUg"]
[Thu Sep 17 15:09:14.376090 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:59264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Psr18Client.php"] [unique_id "aqxW-hFTPRVSLOsRVhobDwAAAUg"]
[Thu Sep 17 15:09:14.619315 2026] [security2:error] [pid 955873:tid 956032] [client 104.28.198.244:22581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-hFTPRVSLOsRVhobFAAAASc"]
[Thu Sep 17 15:09:14.663595 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/RawTextResponse.php"] [unique_id "aqxW-hFTPRVSLOsRVhobGQAAASU"]
[Thu Sep 17 15:09:14.663717 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:59274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/RawTextResponse.php"] [unique_id "aqxW-hFTPRVSLOsRVhobGQAAASU"]
[Thu Sep 17 15:09:14.777321 2026] [security2:error] [pid 955873:tid 956032] [client 104.28.198.244:22581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxW-hFTPRVSLOsRVhobFAAAASc"]
[Thu Sep 17 15:09:14.989487 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobIAAAAW4"]
[Thu Sep 17 15:09:14.989612 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:59282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/HTTP/Response.php"] [unique_id "aqxW-hFTPRVSLOsRVhobIAAAAW4"]
[Thu Sep 17 15:09:15.275024 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/IRI.php"] [unique_id "aqxW-xFTPRVSLOsRVhobIwAAAYU"]
[Thu Sep 17 15:09:15.275131 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:59298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/IRI.php"] [unique_id "aqxW-xFTPRVSLOsRVhobIwAAAYU"]
[Thu Sep 17 15:09:15.288121 2026] [security2:error] [pid 955873:tid 956022] [client 216.24.219.89:52145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "larskolind.net"] [uri "/php8.php"] [unique_id "aqxW-xFTPRVSLOsRVhobJgAAAR0"]
[Thu Sep 17 15:09:15.576399 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Item.php"] [unique_id "aqxW-xFTPRVSLOsRVhobKgAAAVA"]
[Thu Sep 17 15:09:15.576494 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:59310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Item.php"] [unique_id "aqxW-xFTPRVSLOsRVhobKgAAAVA"]
[Thu Sep 17 15:09:15.876713 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Locator.php"] [unique_id "aqxW-xFTPRVSLOsRVhobLQAAAXM"]
[Thu Sep 17 15:09:15.876814 2026] [security2:error] [pid 955873:tid 956108] [client 143.244.57.120:59318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Locator.php"] [unique_id "aqxW-xFTPRVSLOsRVhobLQAAAXM"]
[Thu Sep 17 15:09:16.154399 2026] [security2:error] [pid 955873:tid 956123] [client 4.240.114.86:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxW_BFTPRVSLOsRVhobMgAAAYI"], referer: binance.com
[Thu Sep 17 15:09:16.161343 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Misc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobMwAAAWo"]
[Thu Sep 17 15:09:16.161426 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:59322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Misc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobMwAAAWo"]
[Thu Sep 17 15:09:16.356465 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobOQAAATc"]
[Thu Sep 17 15:09:16.356562 2026] [security2:error] [pid 955873:tid 956048] [client 154.190.208.131:42049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxW_BFTPRVSLOsRVhobOQAAATc"]
[Thu Sep 17 15:09:16.457952 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:59330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/"] [unique_id "aqxW_BFTPRVSLOsRVhobOwAAAYQ"]
[Thu Sep 17 15:09:16.611602 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/"] [unique_id "aqxW_BFTPRVSLOsRVhobPgAAAXg"]
[Thu Sep 17 15:09:16.665163 2026] [security2:error] [pid 955873:tid 956056] [client 95.108.213.138:32948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mtbclubdecampo.com"] [uri "/BlogMTB/index.php"] [unique_id "aqxW_BFTPRVSLOsRVhobPQABPws"]
[Thu Sep 17 15:09:16.755162 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:59330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/wp-includes/SimplePie/src/"] [unique_id "aqxW_BFTPRVSLOsRVhobQwAAATk"]
[Thu Sep 17 15:09:16.927180 2026] [security2:error] [pid 955873:tid 956047] [client 40.87.20.23:61434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "dfwservicesllc.com"] [uri "/"] [unique_id "aqxW_BFTPRVSLOsRVhobRgAAATY"]
[Thu Sep 17 15:09:16.993422 2026] [security2:error] [pid 955873:tid 956013] [client 40.87.20.23:61434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=:"] [hostname "dfwservicesllc.com"] [uri "/"] [unique_id "aqxW_BFTPRVSLOsRVhobRwAAARQ"]
[Thu Sep 17 15:09:17.019328 2026] [security2:error] [pid 955873:tid 956051] [client 20.244.34.24:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxW_RFTPRVSLOsRVhobSAAAATo"], referer: binance.com
[Thu Sep 17 15:09:17.107455 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_BFTPRVSLOsRVhobRQAAARc"]
[Thu Sep 17 15:09:17.107482 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_BFTPRVSLOsRVhobRQAAARc"]
[Thu Sep 17 15:09:17.250118 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:59330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/IPv6.php"] [unique_id "aqxW_RFTPRVSLOsRVhobTAAAAVk"]
[Thu Sep 17 15:09:17.250214 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:59330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Net/IPv6.php"] [unique_id "aqxW_RFTPRVSLOsRVhobTAAAAVk"]
[Thu Sep 17 15:09:17.528716 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:59340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/"] [unique_id "aqxW_RFTPRVSLOsRVhobUgAAAVI"]
[Thu Sep 17 15:09:17.686709 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/"] [unique_id "aqxW_RFTPRVSLOsRVhobVAAAARk"]
[Thu Sep 17 15:09:17.824645 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:59340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/wp-includes/SimplePie/src/"] [unique_id "aqxW_RFTPRVSLOsRVhobXQAAAVg"]
[Thu Sep 17 15:09:18.152486 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_RFTPRVSLOsRVhobYQAAASg"]
[Thu Sep 17 15:09:18.152512 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxW_RFTPRVSLOsRVhobYQAAASg"]
[Thu Sep 17 15:09:18.293854 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/Date.php"] [unique_id "aqxW_hFTPRVSLOsRVhobZgAAASI"]
[Thu Sep 17 15:09:18.293923 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:59340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parse/Date.php"] [unique_id "aqxW_hFTPRVSLOsRVhobZgAAASI"]
[Thu Sep 17 15:09:18.363175 2026] [security2:error] [pid 955873:tid 955966] [remote 16.216.88.153:28672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.88.216.16.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/lgz-members-only-resources/"] [unique_id "aqxW_hFTPRVSLOsRVhobZwABNVw"]
[Thu Sep 17 15:09:18.583222 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parser.php"] [unique_id "aqxW_hFTPRVSLOsRVhobaQAAAXk"]
[Thu Sep 17 15:09:18.583297 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:59348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Parser.php"] [unique_id "aqxW_hFTPRVSLOsRVhobaQAAAXk"]
[Thu Sep 17 15:09:18.870193 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Rating.php"] [unique_id "aqxW_hFTPRVSLOsRVhobbwAAARg"]
[Thu Sep 17 15:09:18.870289 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:59362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Rating.php"] [unique_id "aqxW_hFTPRVSLOsRVhobbwAAARg"]
[Thu Sep 17 15:09:19.124851 2026] [security2:error] [pid 955873:tid 956037] [client 17.166.233.26:53490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mtbclubdecampo.com"] [uri "/BlogMTB/index.php"] [unique_id "aqxW_xFTPRVSLOsRVhobcwABLGc"]
[Thu Sep 17 15:09:19.158722 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Registry.php"] [unique_id "aqxW_xFTPRVSLOsRVhobdQAAAVs"]
[Thu Sep 17 15:09:19.158810 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:59376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Registry.php"] [unique_id "aqxW_xFTPRVSLOsRVhobdQAAAVs"]
[Thu Sep 17 15:09:19.454729 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/RegistryAware.php"] [unique_id "aqxW_xFTPRVSLOsRVhobegAAAVw"]
[Thu Sep 17 15:09:19.454828 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:59380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/RegistryAware.php"] [unique_id "aqxW_xFTPRVSLOsRVhobegAAAVw"]
[Thu Sep 17 15:09:19.756357 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:59396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Restriction.php"] [unique_id "aqxW_xFTPRVSLOsRVhobfQAAARc"]
[Thu Sep 17 15:09:19.756471 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:59396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Restriction.php"] [unique_id "aqxW_xFTPRVSLOsRVhobfQAAARc"]
[Thu Sep 17 15:09:20.034122 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Sanitize.php"] [unique_id "aqxXABFTPRVSLOsRVhobfwAAATM"]
[Thu Sep 17 15:09:20.034208 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:50456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Sanitize.php"] [unique_id "aqxXABFTPRVSLOsRVhobfwAAATM"]
[Thu Sep 17 15:09:20.315644 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/SimplePie.php"] [unique_id "aqxXABFTPRVSLOsRVhobggAAAWE"]
[Thu Sep 17 15:09:20.315756 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:50464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/SimplePie.php"] [unique_id "aqxXABFTPRVSLOsRVhobggAAAWE"]
[Thu Sep 17 15:09:20.360322 2026] [security2:error] [pid 955873:tid 956129] [client 4.240.114.86:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxXABFTPRVSLOsRVhobhAAAAYg"], referer: binance.com
[Thu Sep 17 15:09:20.604724 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:50474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Source.php"] [unique_id "aqxXABFTPRVSLOsRVhobiAAAAWU"]
[Thu Sep 17 15:09:20.604809 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:50474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/Source.php"] [unique_id "aqxXABFTPRVSLOsRVhobiAAAAWU"]
[Thu Sep 17 15:09:20.690914 2026] [authz_core:error] [pid 955873:tid 956077] [client 169.58.197.253:59493] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:09:20.883852 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/"] [unique_id "aqxXABFTPRVSLOsRVhobkAAAAVU"]
[Thu Sep 17 15:09:21.040505 2026] [security2:error] [pid 955873:tid 956089] [client 185.55.149.49:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkgAAAWA"]
[Thu Sep 17 15:09:21.040597 2026] [security2:error] [pid 955873:tid 956089] [client 185.55.149.49:59061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkgAAAWA"]
[Thu Sep 17 15:09:21.041168 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/"] [unique_id "aqxXARFTPRVSLOsRVhobkQAAAWY"]
[Thu Sep 17 15:09:21.046389 2026] [security2:error] [pid 955873:tid 956053] [client 186.105.232.15:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkwAAATw"]
[Thu Sep 17 15:09:21.046453 2026] [security2:error] [pid 955873:tid 956053] [client 186.105.232.15:60801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhobkwAAATw"]
[Thu Sep 17 15:09:21.180262 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/wp-includes/SimplePie/src/"] [unique_id "aqxXARFTPRVSLOsRVhoblAAAAVo"]
[Thu Sep 17 15:09:21.276437 2026] [security2:error] [pid 955873:tid 956079] [client 45.169.98.18:64936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhoblwAAAVY"]
[Thu Sep 17 15:09:21.276527 2026] [security2:error] [pid 955873:tid 956079] [client 45.169.98.18:64936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXARFTPRVSLOsRVhoblwAAAVY"]
[Thu Sep 17 15:09:21.510132 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXARFTPRVSLOsRVhobmgAAATU"]
[Thu Sep 17 15:09:21.510158 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXARFTPRVSLOsRVhobmgAAATU"]
[Thu Sep 17 15:09:21.654928 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/"] [unique_id "aqxXARFTPRVSLOsRVhoboAAAAWs"]
[Thu Sep 17 15:09:21.987471 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/"] [unique_id "aqxXARFTPRVSLOsRVhobqAAAAT0"]
[Thu Sep 17 15:09:22.085269 2026] [core:error] [pid 955873:tid 956123] [client 142.93.220.18:48766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.085286 2026] [core:error] [pid 955873:tid 956123] [client 142.93.220.18:48766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.140320 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/wp-includes/SimplePie/src/XML/"] [unique_id "aqxXAhFTPRVSLOsRVhobqwAAAUI"]
[Thu Sep 17 15:09:22.481310 2026] [security2:error] [pid 955873:tid 956016] [client 5.58.77.106:39088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXAhFTPRVSLOsRVhobtAABF3A"]
[Thu Sep 17 15:09:22.481501 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAhFTPRVSLOsRVhobrwAAAVw"]
[Thu Sep 17 15:09:22.481514 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAhFTPRVSLOsRVhobrwAAAVw"]
[Thu Sep 17 15:09:22.625389 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/Parser.php"] [unique_id "aqxXAhFTPRVSLOsRVhobuQAAAUw"]
[Thu Sep 17 15:09:22.625495 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:50484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/SimplePie/src/XML/Declaration/Parser.php"] [unique_id "aqxXAhFTPRVSLOsRVhobuQAAAUw"]
[Thu Sep 17 15:09:22.849046 2026] [core:error] [pid 955873:tid 956068] [client 142.93.220.18:48780] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.849065 2026] [core:error] [pid 955873:tid 956068] [client 142.93.220.18:48780] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:22.913722 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/"] [unique_id "aqxXAhFTPRVSLOsRVhobwgAAAXo"]
[Thu Sep 17 15:09:23.082137 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/"] [unique_id "aqxXAxFTPRVSLOsRVhobxAAAAT4"]
[Thu Sep 17 15:09:23.219985 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "aqxXAxFTPRVSLOsRVhobyAAAAXw"]
[Thu Sep 17 15:09:23.353304 2026] [core:error] [pid 955873:tid 956081] [client 142.93.220.18:48784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.353323 2026] [core:error] [pid 955873:tid 956081] [client 142.93.220.18:48784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.379082 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "aqxXAxFTPRVSLOsRVhobzAAAARI"]
[Thu Sep 17 15:09:23.519023 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/wp-includes/Text/"] [unique_id "aqxXAxFTPRVSLOsRVhobzgAAASQ"]
[Thu Sep 17 15:09:23.705302 2026] [security2:error] [pid 955873:tid 956127] [client 210.222.43.21:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhobzwAAAYY"], referer: http://talent-in-borders.com/bc
[Thu Sep 17 15:09:23.727317 2026] [security2:error] [pid 955873:tid 956022] [client 115.244.164.14:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0QAAAR0"]
[Thu Sep 17 15:09:23.727407 2026] [security2:error] [pid 955873:tid 956022] [client 115.244.164.14:59359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0QAAAR0"]
[Thu Sep 17 15:09:23.857775 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0AAAAWA"]
[Thu Sep 17 15:09:23.857797 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhob0AAAAWA"]
[Thu Sep 17 15:09:23.969795 2026] [core:error] [pid 955873:tid 956120] [client 142.93.220.18:48794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.969814 2026] [core:error] [pid 955873:tid 956120] [client 142.93.220.18:48794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:23.998224 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "aqxXAxFTPRVSLOsRVhob2AAAAXE"]
[Thu Sep 17 15:09:24.167014 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "aqxXBBFTPRVSLOsRVhob3AAAATU"]
[Thu Sep 17 15:09:24.322191 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/wp-includes/Text/Diff/"] [unique_id "aqxXBBFTPRVSLOsRVhob4AAAAXc"]
[Thu Sep 17 15:09:24.463129 2026] [core:error] [pid 955873:tid 956038] [client 142.93.220.18:48806] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:24.463152 2026] [core:error] [pid 955873:tid 956038] [client 142.93.220.18:48806] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:24.658491 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBBFTPRVSLOsRVhob4wAAAR8"]
[Thu Sep 17 15:09:24.658515 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBBFTPRVSLOsRVhob4wAAAR8"]
[Thu Sep 17 15:09:24.797958 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:50496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/native.php"] [unique_id "aqxXBBFTPRVSLOsRVhob5wAAAXg"]
[Thu Sep 17 15:09:24.798054 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:50496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/native.php"] [unique_id "aqxXBBFTPRVSLOsRVhob5wAAAXg"]
[Thu Sep 17 15:09:24.884914 2026] [security2:error] [pid 955873:tid 956017] [client 20.244.34.24:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXBBFTPRVSLOsRVhob6QAAARg"], referer: binance.com
[Thu Sep 17 15:09:24.932854 2026] [core:error] [pid 955873:tid 956023] [client 142.93.220.18:48808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:24.932873 2026] [core:error] [pid 955873:tid 956023] [client 142.93.220.18:48808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:09:25.079824 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:50498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/shell.php"] [unique_id "aqxXBRFTPRVSLOsRVhob7gAAAQo"]
[Thu Sep 17 15:09:25.079939 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:50498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/shell.php"] [unique_id "aqxXBRFTPRVSLOsRVhob7gAAAQo"]
[Thu Sep 17 15:09:25.366776 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:50510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/string.php"] [unique_id "aqxXBRFTPRVSLOsRVhob9wAAAVk"]
[Thu Sep 17 15:09:25.366888 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:50510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/string.php"] [unique_id "aqxXBRFTPRVSLOsRVhob9wAAAVk"]
[Thu Sep 17 15:09:25.676858 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/xdiff.php"] [unique_id "aqxXBRFTPRVSLOsRVhob_AAAAVQ"]
[Thu Sep 17 15:09:25.676977 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:50514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Engine/xdiff.php"] [unique_id "aqxXBRFTPRVSLOsRVhob_AAAAVQ"]
[Thu Sep 17 15:09:25.829579 2026] [security2:error] [pid 955873:tid 956049] [client 4.240.114.86:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxXBRFTPRVSLOsRVhocAQAAATg"], referer: binance.com
[Thu Sep 17 15:09:25.961794 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer.php"] [unique_id "aqxXBRFTPRVSLOsRVhocBAAAASQ"]
[Thu Sep 17 15:09:25.961947 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer.php"] [unique_id "aqxXBRFTPRVSLOsRVhocBAAAASQ"]
[Thu Sep 17 15:09:26.005879 2026] [security2:error] [pid 955873:tid 956025] [client 74.7.241.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jewishgrimsby.com"] [uri "/index.php"] [unique_id "aqxXARFTPRVSLOsRVhoblgABIA0"]
[Thu Sep 17 15:09:26.170895 2026] [security2:error] [pid 955873:tid 956015] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocBgAAARY"]
[Thu Sep 17 15:09:26.243226 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:50536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXBhFTPRVSLOsRVhocCwAAAVY"]
[Thu Sep 17 15:09:26.243449 2026] [security2:error] [pid 955873:tid 956083] [client 45.175.15.193:35214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocCgABWho"]
[Thu Sep 17 15:09:26.399789 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXBhFTPRVSLOsRVhocDgAAARM"]
[Thu Sep 17 15:09:26.543940 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:50536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/wp-includes/Text/Diff/"] [unique_id "aqxXBhFTPRVSLOsRVhocEQAAASM"]
[Thu Sep 17 15:09:26.629793 2026] [security2:error] [pid 955873:tid 956103] [client 74.7.228.50:56530] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "30daychallenge.toolsforthejourney.com"] [uri "/index.php"] [unique_id "aqxXBBFTPRVSLOsRVhob6AABbgA"]
[Thu Sep 17 15:09:26.778646 2026] [security2:error] [pid 955873:tid 956112] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env"] [unique_id "aqxXBhFTPRVSLOsRVhocEwAAAXc"]
[Thu Sep 17 15:09:26.866172 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocEgAAARw"]
[Thu Sep 17 15:09:26.866202 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBhFTPRVSLOsRVhocEgAAARw"]
[Thu Sep 17 15:09:26.914119 2026] [security2:error] [pid 955873:tid 956108] [client 154.190.208.131:42639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXBhFTPRVSLOsRVhocGAAAAXM"]
[Thu Sep 17 15:09:26.917933 2026] [security2:error] [pid 955873:tid 956108] [client 154.190.208.131:42639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXBhFTPRVSLOsRVhocGAAAAXM"]
[Thu Sep 17 15:09:27.007210 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:50536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/inline.php"] [unique_id "aqxXBxFTPRVSLOsRVhocGQAAAU4"]
[Thu Sep 17 15:09:27.007351 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:50536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/inline.php"] [unique_id "aqxXBxFTPRVSLOsRVhocGQAAAU4"]
[Thu Sep 17 15:09:27.092138 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocGgAAAVE"]
[Thu Sep 17 15:09:27.294464 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxXBxFTPRVSLOsRVhocHgAAAUM"]
[Thu Sep 17 15:09:27.376139 2026] [security2:error] [pid 955873:tid 956037] [client 169.58.27.94:37501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.27.58.169.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "showtimeeventsvb.com"] [uri "/wp-login.php"] [unique_id "aqxXBxFTPRVSLOsRVhocIAAAASw"]
[Thu Sep 17 15:09:27.411558 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocHwAAATE"]
[Thu Sep 17 15:09:27.617326 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocIQAAAUI"]
[Thu Sep 17 15:09:27.617347 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocIQAAAUI"]
[Thu Sep 17 15:09:27.727966 2026] [security2:error] [pid 955873:tid 956085] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocJAAAAVw"]
[Thu Sep 17 15:09:27.764223 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxXBxFTPRVSLOsRVhocKAAAAQw"]
[Thu Sep 17 15:09:28.056952 2026] [security2:error] [pid 955873:tid 956069] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocLgAAAUw"]
[Thu Sep 17 15:09:28.090848 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocLQAAAVk"]
[Thu Sep 17 15:09:28.090872 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXBxFTPRVSLOsRVhocLQAAAVk"]
[Thu Sep 17 15:09:28.143981 2026] [security2:error] [pid 955873:tid 956070] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXAxFTPRVSLOsRVhob1gABTU8"], referer: http://ourstraytribe.com/blog/
[Thu Sep 17 15:09:28.212585 2026] [security2:error] [pid 955873:tid 956043] [client 104.28.198.244:22783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCBFTPRVSLOsRVhocMgAAATI"]
[Thu Sep 17 15:09:28.212690 2026] [security2:error] [pid 955873:tid 956043] [client 104.28.198.244:22783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCBFTPRVSLOsRVhocMgAAATI"]
[Thu Sep 17 15:09:28.235776 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxXCBFTPRVSLOsRVhocNAAAAUs"]
[Thu Sep 17 15:09:28.331489 2026] [security2:error] [pid 955873:tid 956008] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocMwABDzo"], referer: http://ourstraytribe.com/backup/
[Thu Sep 17 15:09:28.392828 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocOgAAAWE"]
[Thu Sep 17 15:09:28.507380 2026] [security2:error] [pid 955873:tid 956098] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocQQABaTU"], referer: http://ourstraytribe.com/wp/
[Thu Sep 17 15:09:28.597839 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocPgAAAV0"]
[Thu Sep 17 15:09:28.597863 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocPgAAAV0"]
[Thu Sep 17 15:09:28.724326 2026] [security2:error] [pid 955873:tid 956081] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocRQABWEU"], referer: http://ourstraytribe.com/wordpress/
[Thu Sep 17 15:09:28.725769 2026] [security2:error] [pid 955873:tid 956011] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocRgAAARI"]
[Thu Sep 17 15:09:28.742847 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxXCBFTPRVSLOsRVhocRwAAASQ"]
[Thu Sep 17 15:09:28.895604 2026] [security2:error] [pid 955873:tid 956033] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocSwABKBA"], referer: http://ourstraytribe.com/old/
[Thu Sep 17 15:09:28.909846 2026] [authz_core:error] [pid 955873:tid 956127] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-content/mu-plugins/error_log
[Thu Sep 17 15:09:28.910622 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxXCBFTPRVSLOsRVhocTgAAAYY"]
[Thu Sep 17 15:09:28.976544 2026] [security2:error] [pid 955873:tid 956079] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.bak"] [unique_id "aqxXCBFTPRVSLOsRVhocUgAAAVY"]
[Thu Sep 17 15:09:29.053046 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/sso.php"] [unique_id "aqxXCRFTPRVSLOsRVhocVgAAATU"]
[Thu Sep 17 15:09:29.053154 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:50550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/mu-plugins/sso.php"] [unique_id "aqxXCRFTPRVSLOsRVhocVgAAATU"]
[Thu Sep 17 15:09:29.061344 2026] [security2:error] [pid 955873:tid 956117] [client 162.241.226.11:42670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocTAAAAXw"]
[Thu Sep 17 15:09:29.090241 2026] [security2:error] [pid 955873:tid 956083] [client 157.245.172.210:44682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCBFTPRVSLOsRVhocUwABWgU"], referer: http://ourstraytribe.com/new/
[Thu Sep 17 15:09:29.217726 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.backup"] [unique_id "aqxXCRFTPRVSLOsRVhocWwAAAXQ"]
[Thu Sep 17 15:09:29.240102 2026] [security2:error] [pid 955873:tid 956119] [client 162.241.226.11:42672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxXCRFTPRVSLOsRVhocVwAAAX4"]
[Thu Sep 17 15:09:29.330472 2026] [security2:error] [pid 955873:tid 956076] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXCRFTPRVSLOsRVhocXAAAAVM"]
[Thu Sep 17 15:09:29.489971 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXCRFTPRVSLOsRVhocYwAAATc"]
[Thu Sep 17 15:09:29.535320 2026] [security2:error] [pid 955873:tid 956060] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCRFTPRVSLOsRVhocYgAAAUM"]
[Thu Sep 17 15:09:29.629226 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/blocks/"] [unique_id "aqxXCRFTPRVSLOsRVhocZQAAAW0"]
[Thu Sep 17 15:09:29.768891 2026] [security2:error] [pid 955873:tid 956107] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.old"] [unique_id "aqxXCRFTPRVSLOsRVhocZwAAAXI"]
[Thu Sep 17 15:09:29.781051 2026] [security2:error] [pid 955873:tid 956039] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxXCRFTPRVSLOsRVhocZgAAAS4"]
[Thu Sep 17 15:09:29.920680 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxXCRFTPRVSLOsRVhocawAAATk"]
[Thu Sep 17 15:09:30.072976 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxXChFTPRVSLOsRVhocbQAAAUg"]
[Thu Sep 17 15:09:30.080124 2026] [security2:error] [pid 955873:tid 956041] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhocbAAAATA"]
[Thu Sep 17 15:09:30.210818 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/"] [unique_id "aqxXChFTPRVSLOsRVhocbwAAATo"]
[Thu Sep 17 15:09:30.371801 2026] [authz_core:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/customize/error_log
[Thu Sep 17 15:09:30.386409 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:52728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/"] [unique_id "aqxXChFTPRVSLOsRVhocdAAAAUE"]
[Thu Sep 17 15:09:30.391405 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhoccgAAAVk"]
[Thu Sep 17 15:09:30.528087 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-control.php"] [unique_id "aqxXChFTPRVSLOsRVhoceAAAAUs"]
[Thu Sep 17 15:09:30.528200 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:50566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-control.php"] [unique_id "aqxXChFTPRVSLOsRVhoceAAAAUs"]
[Thu Sep 17 15:09:30.713620 2026] [security2:error] [pid 955873:tid 956052] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhocewAAATs"]
[Thu Sep 17 15:09:30.811828 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:55060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-setting.php"] [unique_id "aqxXChFTPRVSLOsRVhocfwAAAWk"]
[Thu Sep 17 15:09:30.811925 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:55060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-image-setting.php"] [unique_id "aqxXChFTPRVSLOsRVhocfwAAAWk"]
[Thu Sep 17 15:09:31.029074 2026] [security2:error] [pid 955873:tid 956075] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXChFTPRVSLOsRVhocgAAAAVI"]
[Thu Sep 17 15:09:31.093339 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-position-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocggAAARE"]
[Thu Sep 17 15:09:31.093433 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:55068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-background-position-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocggAAARE"]
[Thu Sep 17 15:09:31.192069 2026] [security2:error] [pid 955873:tid 956080] [client 4.240.114.86:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxXCxFTPRVSLOsRVhocgwAAAVc"], referer: binance.com
[Thu Sep 17 15:09:31.340886 2026] [security2:error] [pid 955873:tid 956007] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCxFTPRVSLOsRVhochQAAAQ4"]
[Thu Sep 17 15:09:31.373719 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-code-editor-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhociAAAATM"]
[Thu Sep 17 15:09:31.373824 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:55084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-code-editor-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhociAAAATM"]
[Thu Sep 17 15:09:31.657626 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:55098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-color-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjAAAAXE"]
[Thu Sep 17 15:09:31.657745 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:55098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-color-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjAAAAXE"]
[Thu Sep 17 15:09:31.663468 2026] [security2:error] [pid 955873:tid 956062] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCxFTPRVSLOsRVhociwAAAUU"]
[Thu Sep 17 15:09:31.750424 2026] [security2:error] [pid 955873:tid 956055] [client 45.169.98.18:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjQAAAT4"]
[Thu Sep 17 15:09:31.750527 2026] [security2:error] [pid 955873:tid 956055] [client 45.169.98.18:65496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjQAAAT4"]
[Thu Sep 17 15:09:31.754744 2026] [security2:error] [pid 955873:tid 956120] [client 185.55.149.49:54157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjgAAAX8"]
[Thu Sep 17 15:09:31.754818 2026] [security2:error] [pid 955873:tid 956120] [client 185.55.149.49:54157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhocjgAAAX8"]
[Thu Sep 17 15:09:31.964875 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhockwAAARw"]
[Thu Sep 17 15:09:31.964966 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:55100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aqxXCxFTPRVSLOsRVhockwAAARw"]
[Thu Sep 17 15:09:31.972183 2026] [security2:error] [pid 955873:tid 956019] [client 186.105.232.15:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhoclAAAARo"]
[Thu Sep 17 15:09:31.972285 2026] [security2:error] [pid 955873:tid 956019] [client 186.105.232.15:61391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXCxFTPRVSLOsRVhoclAAAARo"]
[Thu Sep 17 15:09:31.972852 2026] [security2:error] [pid 955873:tid 956083] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXCxFTPRVSLOsRVhockgAAAVo"]
[Thu Sep 17 15:09:32.277685 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-custom-css-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocmAAAAYI"]
[Thu Sep 17 15:09:32.277802 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:55116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-custom-css-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocmAAAAYI"]
[Thu Sep 17 15:09:32.289614 2026] [security2:error] [pid 955873:tid 956097] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhoclwAAAWg"]
[Thu Sep 17 15:09:32.432318 2026] [security2:error] [pid 955873:tid 956074] [client 177.245.246.91:10340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhocnAABUTk"]
[Thu Sep 17 15:09:32.561012 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-date-time-control.php"] [unique_id "aqxXDBFTPRVSLOsRVhocoAAAAR8"]
[Thu Sep 17 15:09:32.561134 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:55128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-date-time-control.php"] [unique_id "aqxXDBFTPRVSLOsRVhocoAAAAR8"]
[Thu Sep 17 15:09:32.616320 2026] [security2:error] [pid 955873:tid 956026] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhocnwAAASE"]
[Thu Sep 17 15:09:32.851461 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-filter-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocpgAAAQw"]
[Thu Sep 17 15:09:32.851558 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:55140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-filter-setting.php"] [unique_id "aqxXDBFTPRVSLOsRVhocpgAAAQw"]
[Thu Sep 17 15:09:32.931391 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDBFTPRVSLOsRVhocpwAAAUg"]
[Thu Sep 17 15:09:33.137118 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocsgAAAUs"]
[Thu Sep 17 15:09:33.137230 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocsgAAAUs"]
[Thu Sep 17 15:09:33.245905 2026] [security2:error] [pid 955873:tid 956069] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDRFTPRVSLOsRVhocswAAAUw"]
[Thu Sep 17 15:09:33.446301 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:55148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-setting.php"] [unique_id "aqxXDRFTPRVSLOsRVhocuQAAARQ"]
[Thu Sep 17 15:09:33.446397 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:55148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-header-image-setting.php"] [unique_id "aqxXDRFTPRVSLOsRVhocuQAAARQ"]
[Thu Sep 17 15:09:33.487134 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env.swp"] [unique_id "aqxXDRFTPRVSLOsRVhocugAAAYc"]
[Thu Sep 17 15:09:33.721804 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.env~"] [unique_id "aqxXDRFTPRVSLOsRVhocvwAAAV0"]
[Thu Sep 17 15:09:33.732303 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:55152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocwAAAARU"]
[Thu Sep 17 15:09:33.732416 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:55152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-image-control.php"] [unique_id "aqxXDRFTPRVSLOsRVhocwAAAARU"]
[Thu Sep 17 15:09:34.015706 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-media-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhocxwAAAR0"]
[Thu Sep 17 15:09:34.015820 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:55158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-media-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhocxwAAAR0"]
[Thu Sep 17 15:09:34.048017 2026] [security2:error] [pid 955873:tid 956056] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDRFTPRVSLOsRVhocxgAAAT8"]
[Thu Sep 17 15:09:34.281613 2026] [security2:error] [pid 955873:tid 956127] [client 115.244.164.14:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0AAAAYY"]
[Thu Sep 17 15:09:34.281725 2026] [security2:error] [pid 955873:tid 956127] [client 115.244.164.14:59997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0AAAAYY"]
[Thu Sep 17 15:09:34.311309 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:55160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0gAAAYA"]
[Thu Sep 17 15:09:34.311449 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:55160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0gAAAYA"]
[Thu Sep 17 15:09:34.371942 2026] [security2:error] [pid 955873:tid 956104] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc0QAAAW8"]
[Thu Sep 17 15:09:34.605341 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc2wAAAUA"]
[Thu Sep 17 15:09:34.605429 2026] [security2:error] [pid 955873:tid 956057] [client 143.244.57.120:55170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc2wAAAUA"]
[Thu Sep 17 15:09:34.692026 2026] [security2:error] [pid 955873:tid 956076] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc3AAAAVM"]
[Thu Sep 17 15:09:34.902425 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc5QAAAW0"]
[Thu Sep 17 15:09:34.902559 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:55178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-control.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc5QAAAW0"]
[Thu Sep 17 15:09:35.011266 2026] [security2:error] [pid 955873:tid 956005] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc6QAAAQw"]
[Thu Sep 17 15:09:35.147066 2026] [security2:error] [pid 955873:tid 956085] [client 176.29.238.12:2270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc6wABXE0"]
[Thu Sep 17 15:09:35.185796 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-setting.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc7AAAAUs"]
[Thu Sep 17 15:09:35.185901 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:55186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-item-setting.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc7AAAAUs"]
[Thu Sep 17 15:09:35.337541 2026] [security2:error] [pid 955873:tid 956061] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc7QAAAUQ"]
[Thu Sep 17 15:09:35.469401 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:55200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-location-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc9QAAASY"]
[Thu Sep 17 15:09:35.469509 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:55200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-location-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc9QAAASY"]
[Thu Sep 17 15:09:35.656029 2026] [security2:error] [pid 955873:tid 956010] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc9wAAARE"]
[Thu Sep 17 15:09:35.761601 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:55214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-locations-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc-AAAASc"]
[Thu Sep 17 15:09:35.761737 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:55214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-locations-control.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc-AAAASc"]
[Thu Sep 17 15:09:35.973972 2026] [security2:error] [pid 955873:tid 956126] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc-wAAAYU"]
[Thu Sep 17 15:09:36.062508 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-name-control.php"] [unique_id "aqxXEBFTPRVSLOsRVhoc_wAAAWE"]
[Thu Sep 17 15:09:36.062627 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:55216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-name-control.php"] [unique_id "aqxXEBFTPRVSLOsRVhoc_wAAAWE"]
[Thu Sep 17 15:09:36.211381 2026] [security2:error] [pid 955873:tid 956110] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/app/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodAQAAAXU"]
[Thu Sep 17 15:09:36.349381 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-section.php"] [unique_id "aqxXEBFTPRVSLOsRVhodBAAAAX8"]
[Thu Sep 17 15:09:36.349486 2026] [security2:error] [pid 955873:tid 956120] [client 143.244.57.120:55218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-section.php"] [unique_id "aqxXEBFTPRVSLOsRVhodBAAAAX8"]
[Thu Sep 17 15:09:36.451370 2026] [security2:error] [pid 955873:tid 956121] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/apps/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodBgAAAYA"]
[Thu Sep 17 15:09:36.653912 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-setting.php"] [unique_id "aqxXEBFTPRVSLOsRVhodCAAAARo"]
[Thu Sep 17 15:09:36.654038 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:55224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-setting.php"] [unique_id "aqxXEBFTPRVSLOsRVhodCAAAARo"]
[Thu Sep 17 15:09:36.689146 2026] [security2:error] [pid 955873:tid 956007] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodCQAAAQ4"]
[Thu Sep 17 15:09:36.774344 2026] [security2:error] [pid 955873:tid 956128] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mythicexpeditionspress.com"] [uri "/index.php"] [unique_id "aqxXDxFTPRVSLOsRVhoc8wAAAYc"]
[Thu Sep 17 15:09:36.781878 2026] [security2:error] [pid 955873:tid 956122] [client 74.7.230.49:46274] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mythicexpeditionspress.com"] [uri "/robots.txt"] [unique_id "aqxXDxFTPRVSLOsRVhoc7wABgUw"]
[Thu Sep 17 15:09:36.855576 2026] [security2:error] [pid 955873:tid 956127] [client 104.28.198.244:22790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXEBFTPRVSLOsRVhodDgAAAYY"]
[Thu Sep 17 15:09:36.855692 2026] [security2:error] [pid 955873:tid 956127] [client 104.28.198.244:22790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXEBFTPRVSLOsRVhodDgAAAYY"]
[Thu Sep 17 15:09:36.927900 2026] [security2:error] [pid 955873:tid 956054] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/web/.env"] [unique_id "aqxXEBFTPRVSLOsRVhodEAAAAT0"]
[Thu Sep 17 15:09:36.937711 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menus-panel.php"] [unique_id "aqxXEBFTPRVSLOsRVhodEQAAAU8"]
[Thu Sep 17 15:09:36.937839 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:55234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-nav-menus-panel.php"] [unique_id "aqxXEBFTPRVSLOsRVhodEQAAAU8"]
[Thu Sep 17 15:09:37.109746 2026] [security2:error] [pid 955873:tid 956071] [client 4.240.114.86:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxXERFTPRVSLOsRVhodEwAAAU4"], referer: binance.com
[Thu Sep 17 15:09:37.167176 2026] [security2:error] [pid 955873:tid 956018] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/site/.env"] [unique_id "aqxXERFTPRVSLOsRVhodFAAAARk"]
[Thu Sep 17 15:09:37.215544 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-control.php"] [unique_id "aqxXERFTPRVSLOsRVhodFQAAAXg"]
[Thu Sep 17 15:09:37.215651 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:55248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-control.php"] [unique_id "aqxXERFTPRVSLOsRVhodFQAAAXg"]
[Thu Sep 17 15:09:37.400040 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/public/.env"] [unique_id "aqxXERFTPRVSLOsRVhodGgAAATE"]
[Thu Sep 17 15:09:37.496421 2026] [security2:error] [pid 955873:tid 956057] [client 154.190.208.131:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXERFTPRVSLOsRVhodGwAAAUA"]
[Thu Sep 17 15:09:37.497959 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-section.php"] [unique_id "aqxXERFTPRVSLOsRVhodHAAAAUg"]
[Thu Sep 17 15:09:37.498097 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:55264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-new-menu-section.php"] [unique_id "aqxXERFTPRVSLOsRVhodHAAAAUg"]
[Thu Sep 17 15:09:37.505984 2026] [security2:error] [pid 955873:tid 956057] [client 154.190.208.131:41886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXERFTPRVSLOsRVhodGwAAAUA"]
[Thu Sep 17 15:09:37.595764 2026] [security2:error] [pid 955873:tid 956095] [client 52.167.144.54:64468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxXDhFTPRVSLOsRVhoc2AABZi4"]
[Thu Sep 17 15:09:37.722459 2026] [security2:error] [pid 955873:tid 956058] [client 35.244.43.255:34652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXERFTPRVSLOsRVhodHwAAAUE"]
[Thu Sep 17 15:09:37.776578 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-partial.php"] [unique_id "aqxXERFTPRVSLOsRVhodIwAAAUk"]
[Thu Sep 17 15:09:37.776681 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:55272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-partial.php"] [unique_id "aqxXERFTPRVSLOsRVhodIwAAAUk"]
[Thu Sep 17 15:09:37.963940 2026] [security2:error] [pid 955873:tid 956101] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/backend/.env"] [unique_id "aqxXERFTPRVSLOsRVhodKAAAAWw"]
[Thu Sep 17 15:09:38.083932 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-selective-refresh.php"] [unique_id "aqxXEhFTPRVSLOsRVhodKQAAASI"]
[Thu Sep 17 15:09:38.084015 2026] [security2:error] [pid 955873:tid 956027] [client 143.244.57.120:55278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-selective-refresh.php"] [unique_id "aqxXEhFTPRVSLOsRVhodKQAAASI"]
[Thu Sep 17 15:09:38.202850 2026] [security2:error] [pid 955873:tid 956049] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/server/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodKgAAATg"]
[Thu Sep 17 15:09:38.373455 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-sidebar-section.php"] [unique_id "aqxXEhFTPRVSLOsRVhodMAAAAYU"]
[Thu Sep 17 15:09:38.373542 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:55280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-sidebar-section.php"] [unique_id "aqxXEhFTPRVSLOsRVhodMAAAAYU"]
[Thu Sep 17 15:09:38.442011 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/frontend/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodMgAAAWA"]
[Thu Sep 17 15:09:38.653210 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-site-icon-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodNQAAAYM"]
[Thu Sep 17 15:09:38.653307 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:55288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-site-icon-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodNQAAAYM"]
[Thu Sep 17 15:09:38.678671 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/src/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodNwAAASA"]
[Thu Sep 17 15:09:38.797937 2026] [security2:error] [pid 955873:tid 956052] [client 47.79.200.121:22650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXEhFTPRVSLOsRVhodNAAAATs"], referer: https://www.google.com/
[Thu Sep 17 15:09:38.915280 2026] [security2:error] [pid 955873:tid 956103] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/core/.env"] [unique_id "aqxXEhFTPRVSLOsRVhodOwAAAW4"]
[Thu Sep 17 15:09:38.964864 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-theme-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodPwAAATo"]
[Thu Sep 17 15:09:38.964987 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:55294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-theme-control.php"] [unique_id "aqxXEhFTPRVSLOsRVhodPwAAATo"]
[Thu Sep 17 15:09:39.153729 2026] [security2:error] [pid 955873:tid 956106] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/core/app/.env"] [unique_id "aqxXExFTPRVSLOsRVhodQQAAAXE"]
[Thu Sep 17 15:09:39.254983 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-panel.php"] [unique_id "aqxXExFTPRVSLOsRVhodQwAAARM"]
[Thu Sep 17 15:09:39.255063 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:55310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-panel.php"] [unique_id "aqxXExFTPRVSLOsRVhodQwAAARM"]
[Thu Sep 17 15:09:39.392674 2026] [security2:error] [pid 955873:tid 956096] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/config/.env"] [unique_id "aqxXExFTPRVSLOsRVhodSAAAAWc"]
[Thu Sep 17 15:09:39.562125 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-section.php"] [unique_id "aqxXExFTPRVSLOsRVhodTAAAARk"]
[Thu Sep 17 15:09:39.562214 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:55312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-themes-section.php"] [unique_id "aqxXExFTPRVSLOsRVhodTAAAARk"]
[Thu Sep 17 15:09:39.627824 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/private/.env"] [unique_id "aqxXExFTPRVSLOsRVhodTQAAAXY"]
[Thu Sep 17 15:09:39.843266 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-upload-control.php"] [unique_id "aqxXExFTPRVSLOsRVhodTwAAASs"]
[Thu Sep 17 15:09:39.843374 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:55320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-customize-upload-control.php"] [unique_id "aqxXExFTPRVSLOsRVhodTwAAASs"]
[Thu Sep 17 15:09:39.864858 2026] [security2:error] [pid 955873:tid 956102] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/application/.env"] [unique_id "aqxXExFTPRVSLOsRVhodUgAAAW0"]
[Thu Sep 17 15:09:40.100769 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/bootstrap/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodVQAAAUg"]
[Thu Sep 17 15:09:40.128752 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:52908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-sidebar-block-editor-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodVgAAATY"]
[Thu Sep 17 15:09:40.128836 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:52908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-sidebar-block-editor-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodVgAAATY"]
[Thu Sep 17 15:09:40.337894 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/database/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodWAAAAVE"]
[Thu Sep 17 15:09:40.406620 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXAAAAR8"]
[Thu Sep 17 15:09:40.406728 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXAAAAR8"]
[Thu Sep 17 15:09:40.574979 2026] [security2:error] [pid 955873:tid 956050] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/storage/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodXgAAATk"]
[Thu Sep 17 15:09:40.698894 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:52932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-form-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXwAAAVs"]
[Thu Sep 17 15:09:40.699005 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:52932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/customize/class-wp-widget-form-customize-control.php"] [unique_id "aqxXFBFTPRVSLOsRVhodXwAAAVs"]
[Thu Sep 17 15:09:40.808281 2026] [security2:error] [pid 955873:tid 956115] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/var/www/.env"] [unique_id "aqxXFBFTPRVSLOsRVhodYAAAAXo"]
[Thu Sep 17 15:09:40.979356 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:52934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxXFBFTPRVSLOsRVhodZgAAAVQ"]
[Thu Sep 17 15:09:41.040834 2026] [security2:error] [pid 955873:tid 956061] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/var/www/html/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodaAAAAUQ"]
[Thu Sep 17 15:09:41.273233 2026] [security2:error] [pid 955873:tid 956091] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/current/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodbQAAAWI"]
[Thu Sep 17 15:09:41.487403 2026] [security2:error] [pid 955873:tid 956082] [client 34.87.188.48:60676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "blacksaabath.theworldinc.com"] [uri "/"] [unique_id "aqxXFRFTPRVSLOsRVhodcQAAAVk"]
[Thu Sep 17 15:09:41.511970 2026] [security2:error] [pid 955873:tid 956079] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/release/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodcwAAAVY"]
[Thu Sep 17 15:09:41.554007 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxXFRFTPRVSLOsRVhoddAAAAQs"]
[Thu Sep 17 15:09:41.719337 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxXFRFTPRVSLOsRVhodeAAAAW4"]
[Thu Sep 17 15:09:41.719435 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxXFRFTPRVSLOsRVhodeAAAAW4"]
[Thu Sep 17 15:09:41.751755 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/releases/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodegAAARw"]
[Thu Sep 17 15:09:41.995200 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/shared/.env"] [unique_id "aqxXFRFTPRVSLOsRVhodfwAAAYc"]
[Thu Sep 17 15:09:42.002230 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxXFhFTPRVSLOsRVhodgAAAATQ"]
[Thu Sep 17 15:09:42.002308 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:52940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxXFhFTPRVSLOsRVhodgAAAATQ"]
[Thu Sep 17 15:09:42.237452 2026] [security2:error] [pid 955873:tid 956078] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/deploy/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodhAAAAVU"]
[Thu Sep 17 15:09:42.259964 2026] [security2:error] [pid 955873:tid 956096] [client 45.169.98.18:49983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhgAAAWc"]
[Thu Sep 17 15:09:42.260067 2026] [security2:error] [pid 955873:tid 956096] [client 45.169.98.18:49983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhgAAAWc"]
[Thu Sep 17 15:09:42.265547 2026] [security2:error] [pid 955873:tid 956059] [client 35.204.107.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.brownsdailydose.com"] [uri "/index.php"] [unique_id "aqxXFhFTPRVSLOsRVhodgwAAAUI"], referer: http://www.brownsdailydose.com/robots.txt
[Thu Sep 17 15:09:42.293122 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhwAAAU0"]
[Thu Sep 17 15:09:42.293197 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:52954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxXFhFTPRVSLOsRVhodhwAAAU0"]
[Thu Sep 17 15:09:42.399947 2026] [authz_core:error] [pid 955873:tid 956029] [client 169.58.197.253:60858] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:09:42.433313 2026] [security2:error] [pid 955873:tid 956054] [client 185.55.149.49:54778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodjwAAAT0"]
[Thu Sep 17 15:09:42.433406 2026] [security2:error] [pid 955873:tid 956054] [client 185.55.149.49:54778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodjwAAAT0"]
[Thu Sep 17 15:09:42.475967 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/build/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodkAAAAXY"]
[Thu Sep 17 15:09:42.598917 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxXFhFTPRVSLOsRVhodkgAAASs"]
[Thu Sep 17 15:09:42.599004 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxXFhFTPRVSLOsRVhodkgAAASs"]
[Thu Sep 17 15:09:42.715985 2026] [security2:error] [pid 955873:tid 956092] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/dist/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodlQAAAWM"]
[Thu Sep 17 15:09:42.846818 2026] [security2:error] [pid 955873:tid 956069] [client 186.105.232.15:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodmgAAAUw"]
[Thu Sep 17 15:09:42.846943 2026] [security2:error] [pid 955873:tid 956069] [client 186.105.232.15:61972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXFhFTPRVSLOsRVhodmgAAAUw"]
[Thu Sep 17 15:09:42.896084 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxXFhFTPRVSLOsRVhodnAAAAQw"]
[Thu Sep 17 15:09:42.896193 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:52974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxXFhFTPRVSLOsRVhodnAAAAQw"]
[Thu Sep 17 15:09:42.952502 2026] [security2:error] [pid 955873:tid 956035] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/public_html/.env"] [unique_id "aqxXFhFTPRVSLOsRVhodnQAAASo"]
[Thu Sep 17 15:09:43.192689 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/htdocs/.env"] [unique_id "aqxXFxFTPRVSLOsRVhodoAAAAWY"]
[Thu Sep 17 15:09:43.209490 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/"] [unique_id "aqxXFxFTPRVSLOsRVhodoQAAARs"]
[Thu Sep 17 15:09:43.404247 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/"] [unique_id "aqxXFxFTPRVSLOsRVhodqQAAARQ"]
[Thu Sep 17 15:09:43.430439 2026] [security2:error] [pid 955873:tid 956049] [client 4.240.114.86:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxXFxFTPRVSLOsRVhodrQAAATg"], referer: binance.com
[Thu Sep 17 15:09:43.432435 2026] [security2:error] [pid 955873:tid 956077] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/www/.env"] [unique_id "aqxXFxFTPRVSLOsRVhodrgAAAVQ"]
[Thu Sep 17 15:09:43.546641 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/crystal/"] [unique_id "aqxXFxFTPRVSLOsRVhodrwAAAVI"]
[Thu Sep 17 15:09:43.669148 2026] [security2:error] [pid 955873:tid 956006] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/html/.env"] [unique_id "aqxXFxFTPRVSLOsRVhodsQAAAQ0"]
[Thu Sep 17 15:09:43.702200 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/crystal/"] [unique_id "aqxXFxFTPRVSLOsRVhodsgAAAWI"]
[Thu Sep 17 15:09:43.842855 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/crystal/wp-includes/images/"] [unique_id "aqxXFxFTPRVSLOsRVhodtgAAASg"]
[Thu Sep 17 15:09:43.856378 2026] [security2:error] [pid 955873:tid 956080] [client 191.30.92.32:50076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXFxFTPRVSLOsRVhodswABV24"]
[Thu Sep 17 15:09:43.919283 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/live/.env"] [unique_id "aqxXFxFTPRVSLOsRVhoduwAAAR0"]
[Thu Sep 17 15:09:44.156287 2026] [security2:error] [pid 955873:tid 956019] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/prod/.env"] [unique_id "aqxXGBFTPRVSLOsRVhodvQAAARo"]
[Thu Sep 17 15:09:44.236375 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodvAAAATo"]
[Thu Sep 17 15:09:44.236408 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodvAAAATo"]
[Thu Sep 17 15:09:44.324170 2026] [security2:error] [pid 955873:tid 956045] [client 52.167.144.231:11083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodwAABNHg"]
[Thu Sep 17 15:09:44.392851 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/dev/.env"] [unique_id "aqxXGBFTPRVSLOsRVhodwwAAAXM"]
[Thu Sep 17 15:09:44.519127 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/icon-library/"] [unique_id "aqxXGBFTPRVSLOsRVhodxgAAAXk"]
[Thu Sep 17 15:09:44.607319 2026] [security2:error] [pid 955873:tid 956037] [client 91.56.35.230:42435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tlpsoftware.arrowake.com"] [uri "/index.php"] [unique_id "aqxXFRFTPRVSLOsRVhoddgABLAk"], referer: http://tlpsoftware.arrowake.com/robots.txt
[Thu Sep 17 15:09:44.631976 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/staging/.env"] [unique_id "aqxXGBFTPRVSLOsRVhodywAAAXQ"]
[Thu Sep 17 15:09:44.728937 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/icon-library/"] [unique_id "aqxXGBFTPRVSLOsRVhodzAAAAXY"]
[Thu Sep 17 15:09:44.824581 2026] [security2:error] [pid 955873:tid 956039] [client 115.244.164.14:60627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXGBFTPRVSLOsRVhod0AAAAS4"]
[Thu Sep 17 15:09:44.824684 2026] [security2:error] [pid 955873:tid 956039] [client 115.244.164.14:60627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXGBFTPRVSLOsRVhod0AAAAS4"]
[Thu Sep 17 15:09:44.864734 2026] [security2:error] [pid 955873:tid 956076] [client 127.0.0.1:54542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vls.tjo.mybluehost.me"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXGBFTPRVSLOsRVhod0QAAAVM"]
[Thu Sep 17 15:09:44.864733 2026] [security2:error] [pid 955873:tid 956102] [client 127.0.0.1:54554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXGBFTPRVSLOsRVhod0gAAAW0"]
[Thu Sep 17 15:09:44.864817 2026] [security2:error] [pid 955873:tid 956088] [client 74.7.228.3:42826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vls.tjo.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxXGBFTPRVSLOsRVhodzwABXxI"]
[Thu Sep 17 15:09:44.871887 2026] [security2:error] [pid 955873:tid 956057] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/opt/.env"] [unique_id "aqxXGBFTPRVSLOsRVhod0wAAAUA"]
[Thu Sep 17 15:09:44.874343 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/icon-library/wp-includes/images/"] [unique_id "aqxXGBFTPRVSLOsRVhod1AAAAUg"]
[Thu Sep 17 15:09:45.114497 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/laravel/.env"] [unique_id "aqxXGRFTPRVSLOsRVhod2QAAATE"]
[Thu Sep 17 15:09:45.300482 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod2AAAASU"]
[Thu Sep 17 15:09:45.300510 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod2AAAASU"]
[Thu Sep 17 15:09:45.353194 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:34652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/symfony/.env"] [unique_id "aqxXGRFTPRVSLOsRVhod3QAAAV4"]
[Thu Sep 17 15:09:45.441738 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/media/"] [unique_id "aqxXGRFTPRVSLOsRVhod4QAAAVI"]
[Thu Sep 17 15:09:45.603069 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/media/"] [unique_id "aqxXGRFTPRVSLOsRVhod4wAAATA"]
[Thu Sep 17 15:09:45.756019 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/media/wp-includes/images/"] [unique_id "aqxXGRFTPRVSLOsRVhod5wAAAWQ"]
[Thu Sep 17 15:09:46.102343 2026] [security2:error] [pid 955873:tid 956015] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/wordpress/.env"] [unique_id "aqxXGhFTPRVSLOsRVhod7wAAARY"]
[Thu Sep 17 15:09:46.134871 2026] [security2:error] [pid 955873:tid 956081] [client 103.58.74.95:56180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhod7gABWHQ"]
[Thu Sep 17 15:09:46.146029 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod7AAAAWI"]
[Thu Sep 17 15:09:46.146057 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGRFTPRVSLOsRVhod7AAAAWI"]
[Thu Sep 17 15:09:46.164629 2026] [security2:error] [pid 955873:tid 956008] [client 5.189.145.112:54457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxXGhFTPRVSLOsRVhod8QAAAQ8"], referer: binance.com
[Thu Sep 17 15:09:46.288393 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/smilies/"] [unique_id "aqxXGhFTPRVSLOsRVhod8gAAATs"]
[Thu Sep 17 15:09:46.360348 2026] [security2:error] [pid 955873:tid 956011] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/wp/.env"] [unique_id "aqxXGhFTPRVSLOsRVhod9AAAARI"]
[Thu Sep 17 15:09:46.456417 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/smilies/"] [unique_id "aqxXGhFTPRVSLOsRVhod-AAAAX4"]
[Thu Sep 17 15:09:46.530250 2026] [security2:error] [pid 955873:tid 956018] [client 52.167.144.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxXGBFTPRVSLOsRVhodzQAAARk"]
[Thu Sep 17 15:09:46.597805 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/images/smilies/wp-includes/images/"] [unique_id "aqxXGhFTPRVSLOsRVhod-wAAAYg"]
[Thu Sep 17 15:09:46.617460 2026] [security2:error] [pid 955873:tid 956051] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cms/.env"] [unique_id "aqxXGhFTPRVSLOsRVhod_AAAATo"]
[Thu Sep 17 15:09:46.646781 2026] [security2:error] [pid 955873:tid 956062] [client 162.241.226.11:56334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhod-QAAAUU"]
[Thu Sep 17 15:09:46.804713 2026] [security2:error] [pid 955873:tid 956110] [client 162.241.226.11:56348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhod_wAAAXU"]
[Thu Sep 17 15:09:46.868348 2026] [security2:error] [pid 955873:tid 956059] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/drupal/.env"] [unique_id "aqxXGhFTPRVSLOsRVhoeAwAAAUI"]
[Thu Sep 17 15:09:46.943798 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhoeAQAAAU8"]
[Thu Sep 17 15:09:46.943830 2026] [security2:error] [pid 955873:tid 956072] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGhFTPRVSLOsRVhoeAQAAAU8"]
[Thu Sep 17 15:09:47.098073 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/.well-known/"] [unique_id "aqxXGxFTPRVSLOsRVhoeBwAAAXQ"]
[Thu Sep 17 15:09:47.116423 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/joomla/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeCAAAAXY"]
[Thu Sep 17 15:09:47.249580 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxXGxFTPRVSLOsRVhoeCQAAAWc"]
[Thu Sep 17 15:09:47.368071 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/magento/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeCgAAAU4"]
[Thu Sep 17 15:09:47.390303 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/ALFA_DATA/"] [unique_id "aqxXGxFTPRVSLOsRVhoeDQAAARM"]
[Thu Sep 17 15:09:47.616364 2026] [security2:error] [pid 955873:tid 956088] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/shopify/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeEQAAAV8"]
[Thu Sep 17 15:09:47.725784 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGxFTPRVSLOsRVhoeEAAAAW0"]
[Thu Sep 17 15:09:47.725817 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXGxFTPRVSLOsRVhoeEAAAAW0"]
[Thu Sep 17 15:09:47.866800 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/.well-knownold/"] [unique_id "aqxXGxFTPRVSLOsRVhoeFAAAASo"]
[Thu Sep 17 15:09:47.867367 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/prestashop/.env"] [unique_id "aqxXGxFTPRVSLOsRVhoeEwAAAQo"]
[Thu Sep 17 15:09:48.047903 2026] [access_compat:error] [pid 955873:tid 956063] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/requests
[Thu Sep 17 15:09:48.116396 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/codeigniter/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeHAAAAVE"]
[Thu Sep 17 15:09:48.200604 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeGgAAARg"]
[Thu Sep 17 15:09:48.200631 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeGgAAARg"]
[Thu Sep 17 15:09:48.242847 2026] [security2:error] [pid 955873:tid 956031] [client 4.240.114.86:56141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeIAAAASY"], referer: binance.com
[Thu Sep 17 15:09:48.353568 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxXHBFTPRVSLOsRVhoeIQAAAWs"]
[Thu Sep 17 15:09:48.365608 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cakephp/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeIgAAAV0"]
[Thu Sep 17 15:09:48.494075 2026] [security2:error] [pid 955873:tid 956049] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/cgi-bin/"] [unique_id "aqxXHBFTPRVSLOsRVhoeJgAAATg"]
[Thu Sep 17 15:09:48.613583 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/zend/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeKgAAASA"]
[Thu Sep 17 15:09:48.642677 2026] [cgid:error] [pid 955873:tid 956033] [client 143.244.57.120:47574] AH01265: stderr from /home1/endurin2/public_html/seedboxpress/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:09:48.643138 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.seedboxpress.com"] [uri "/cgi-bin/"] [unique_id "aqxXHBFTPRVSLOsRVhoeKwAAASg"]
[Thu Sep 17 15:09:48.794973 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/index/"] [unique_id "aqxXHBFTPRVSLOsRVhoeLwAAATs"]
[Thu Sep 17 15:09:48.862370 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/yii/.env"] [unique_id "aqxXHBFTPRVSLOsRVhoeMgAAAWE"]
[Thu Sep 17 15:09:48.873823 2026] [security2:error] [pid 955873:tid 956077] [client 154.190.208.131:42491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNAAAAVQ"]
[Thu Sep 17 15:09:48.879273 2026] [security2:error] [pid 955873:tid 956077] [client 154.190.208.131:42491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNAAAAVQ"]
[Thu Sep 17 15:09:49.109842 2026] [security2:error] [pid 955873:tid 956040] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/laravel5/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoeOQAAAS8"]
[Thu Sep 17 15:09:49.131152 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNwAAAW4"]
[Thu Sep 17 15:09:49.131179 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHBFTPRVSLOsRVhoeNwAAAW4"]
[Thu Sep 17 15:09:49.272304 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/id/"] [unique_id "aqxXHRFTPRVSLOsRVhoePQAAAQ4"]
[Thu Sep 17 15:09:49.357576 2026] [security2:error] [pid 955873:tid 956051] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/v1/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoePgAAATo"]
[Thu Sep 17 15:09:49.599512 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeQgAAAS0"]
[Thu Sep 17 15:09:49.599538 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeQgAAAS0"]
[Thu Sep 17 15:09:49.610871 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/v2/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoeSQAAASM"]
[Thu Sep 17 15:09:49.740282 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/www/"] [unique_id "aqxXHRFTPRVSLOsRVhoeSgAAASQ"]
[Thu Sep 17 15:09:49.867084 2026] [security2:error] [pid 955873:tid 956076] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/v3/.env"] [unique_id "aqxXHRFTPRVSLOsRVhoeSwAAAVM"]
[Thu Sep 17 15:09:50.085293 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeTQAAAVw"]
[Thu Sep 17 15:09:50.085320 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHRFTPRVSLOsRVhoeTQAAAVw"]
[Thu Sep 17 15:09:50.115802 2026] [security2:error] [pid 955873:tid 956105] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/v1/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoebQAAAXA"]
[Thu Sep 17 15:09:50.230365 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/web/"] [unique_id "aqxXHhFTPRVSLOsRVhoecAAAAVg"]
[Thu Sep 17 15:09:50.371585 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/v2/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoedAAAAWE"]
[Thu Sep 17 15:09:50.587208 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoedQAAARA"]
[Thu Sep 17 15:09:50.587233 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoedQAAARA"]
[Thu Sep 17 15:09:50.624371 2026] [security2:error] [pid 955873:tid 956101] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/rest/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoeegAAAWw"]
[Thu Sep 17 15:09:50.730773 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/uploads/"] [unique_id "aqxXHhFTPRVSLOsRVhoeewAAAS8"]
[Thu Sep 17 15:09:50.877166 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/graphql/.env"] [unique_id "aqxXHhFTPRVSLOsRVhoefgAAAWY"]
[Thu Sep 17 15:09:51.061282 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoefQAAAXE"]
[Thu Sep 17 15:09:51.061306 2026] [security2:error] [pid 955873:tid 956106] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHhFTPRVSLOsRVhoefQAAAXE"]
[Thu Sep 17 15:09:51.133179 2026] [security2:error] [pid 955873:tid 956059] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/gateway/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoeggAAAUI"]
[Thu Sep 17 15:09:51.221989 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/upload/"] [unique_id "aqxXHxFTPRVSLOsRVhoegwAAAYI"]
[Thu Sep 17 15:09:51.385758 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/microservice/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoehwAAAXg"]
[Thu Sep 17 15:09:51.554253 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoehAAAAXQ"]
[Thu Sep 17 15:09:51.554276 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoehAAAAXQ"]
[Thu Sep 17 15:09:51.631761 2026] [security2:error] [pid 955873:tid 956070] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/service/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoejQAAAU0"]
[Thu Sep 17 15:09:51.697693 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/uploads/"] [unique_id "aqxXHxFTPRVSLOsRVhoejgAAAR8"]
[Thu Sep 17 15:09:51.885087 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/v3/.env"] [unique_id "aqxXHxFTPRVSLOsRVhoekwAAAU4"]
[Thu Sep 17 15:09:52.043391 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoekAAAAYQ"]
[Thu Sep 17 15:09:52.043419 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXHxFTPRVSLOsRVhoekAAAAYQ"]
[Thu Sep 17 15:09:52.131088 2026] [security2:error] [pid 955873:tid 956100] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/dev/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoelQAAAWs"]
[Thu Sep 17 15:09:52.190709 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Admin/uploads/"] [unique_id "aqxXIBFTPRVSLOsRVhoemQAAAV0"]
[Thu Sep 17 15:09:52.249231 2026] [security2:error] [pid 955873:tid 956122] [client 216.73.160.164:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "talent-in-borders.com"] [uri "/wp-login.php"] [unique_id "aqxXIBFTPRVSLOsRVhoelwAAAYE"]
[Thu Sep 17 15:09:52.303146 2026] [security2:error] [pid 955873:tid 956045] [client 45.8.19.105:42125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.19.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "talent-in-borders.com"] [uri "/wp-login.php"] [unique_id "aqxXIBFTPRVSLOsRVhoemAAAATQ"]
[Thu Sep 17 15:09:52.379011 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/api/staging/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoenAAAAUg"]
[Thu Sep 17 15:09:52.532812 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoemgAAATw"]
[Thu Sep 17 15:09:52.532840 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoemgAAATw"]
[Thu Sep 17 15:09:52.629694 2026] [security2:error] [pid 955873:tid 956033] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/vendor/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoeowAAASg"]
[Thu Sep 17 15:09:52.682137 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/"] [unique_id "aqxXIBFTPRVSLOsRVhoepgAAAWA"]
[Thu Sep 17 15:09:52.688444 2026] [security2:error] [pid 955873:tid 956008] [client 5.189.145.112:53722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxXIBFTPRVSLOsRVhoepwAAAQ8"], referer: binance.com
[Thu Sep 17 15:09:52.736119 2026] [security2:error] [pid 955873:tid 956041] [client 45.169.98.18:50603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqQAAATA"]
[Thu Sep 17 15:09:52.736247 2026] [security2:error] [pid 955873:tid 956041] [client 45.169.98.18:50603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqQAAATA"]
[Thu Sep 17 15:09:52.877947 2026] [security2:error] [pid 955873:tid 956115] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/lib/.env"] [unique_id "aqxXIBFTPRVSLOsRVhoerAAAAXo"]
[Thu Sep 17 15:09:52.997105 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqgAAAYU"]
[Thu Sep 17 15:09:52.997136 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqgAAAYU"]
[Thu Sep 17 15:09:53.104043 2026] [security2:error] [pid 955873:tid 956077] [client 4.240.114.86:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxXIRFTPRVSLOsRVhoerwAAAVQ"], referer: binance.com
[Thu Sep 17 15:09:53.107029 2026] [security2:error] [pid 955873:tid 956080] [client 185.55.149.49:53003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoesAAAAVc"]
[Thu Sep 17 15:09:53.107133 2026] [security2:error] [pid 955873:tid 956080] [client 185.55.149.49:53003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoesAAAAVc"]
[Thu Sep 17 15:09:53.129447 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/resources/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoesQAAAQo"]
[Thu Sep 17 15:09:53.380433 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/assets/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoeuQAAATc"]
[Thu Sep 17 15:09:53.463422 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/index.php"] [unique_id "aqxXIRFTPRVSLOsRVhoesgAAAVs"]
[Thu Sep 17 15:09:53.626603 2026] [security2:error] [pid 955873:tid 956078] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/uploads/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoexwAAAVU"]
[Thu Sep 17 15:09:53.644810 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:47574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxXIRFTPRVSLOsRVhoexgAAAXw"]
[Thu Sep 17 15:09:53.644950 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:47574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxXIRFTPRVSLOsRVhoexgAAAXw"]
[Thu Sep 17 15:09:53.669028 2026] [security2:error] [pid 955873:tid 956042] [client 186.105.232.15:62577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoeyAAAATE"]
[Thu Sep 17 15:09:53.669211 2026] [security2:error] [pid 955873:tid 956042] [client 186.105.232.15:62577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIRFTPRVSLOsRVhoeyAAAATE"]
[Thu Sep 17 15:09:53.794083 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/images/"] [unique_id "aqxXIRFTPRVSLOsRVhoezgAAASM"]
[Thu Sep 17 15:09:53.868274 2026] [security2:error] [pid 955873:tid 956043] [client 177.10.15.94:3697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXIRFTPRVSLOsRVhoezAABMkU"]
[Thu Sep 17 15:09:53.876966 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/internal/.env"] [unique_id "aqxXIRFTPRVSLOsRVhoe0gAAAXQ"]
[Thu Sep 17 15:09:54.128199 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/tools/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe2AAAAU4"]
[Thu Sep 17 15:09:54.383359 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/scripts/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe4AAAAUg"]
[Thu Sep 17 15:09:54.394853 2026] [security2:error] [pid 955873:tid 956027] [client 17.166.155.60:56252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mybeloved.camera"] [uri "/index.php"] [unique_id "aqxXIBFTPRVSLOsRVhoeqwABIj8"]
[Thu Sep 17 15:09:54.459944 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe2gAAATk"]
[Thu Sep 17 15:09:54.459969 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe2gAAATk"]
[Thu Sep 17 15:09:54.635524 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/bin/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe5gAAAS4"]
[Thu Sep 17 15:09:54.742727 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/assets/"] [unique_id "aqxXIhFTPRVSLOsRVhoe6AAAAWI"]
[Thu Sep 17 15:09:54.806297 2026] [security2:error] [pid 955873:tid 956041] [client 177.10.15.94:3697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe5wABMAU"]
[Thu Sep 17 15:09:54.884501 2026] [security2:error] [pid 955873:tid 956049] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sbin/.env"] [unique_id "aqxXIhFTPRVSLOsRVhoe7QAAATg"]
[Thu Sep 17 15:09:55.084112 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe7gAAAXo"]
[Thu Sep 17 15:09:55.084140 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIhFTPRVSLOsRVhoe7gAAAXo"]
[Thu Sep 17 15:09:55.134590 2026] [security2:error] [pid 955873:tid 956090] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/local/.env"] [unique_id "aqxXIxFTPRVSLOsRVhoe7wAAAWE"]
[Thu Sep 17 15:09:55.228500 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxXIxFTPRVSLOsRVhoe8AAAAVQ"]
[Thu Sep 17 15:09:55.381199 2026] [security2:error] [pid 955873:tid 956004] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/portal/.env"] [unique_id "aqxXIxFTPRVSLOsRVhoe-AAAAQs"]
[Thu Sep 17 15:09:55.438997 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe-wAAATM"]
[Thu Sep 17 15:09:55.439133 2026] [security2:error] [pid 955873:tid 956044] [client 115.244.164.14:61266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe-wAAATM"]
[Thu Sep 17 15:09:55.579500 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe9wAAAX4"]
[Thu Sep 17 15:09:55.579526 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhoe9wAAAX4"]
[Thu Sep 17 15:09:55.628826 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/dashboard/.env"] [unique_id "aqxXIxFTPRVSLOsRVhoe_AAAAV4"]
[Thu Sep 17 15:09:55.720935 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/upload/image/"] [unique_id "aqxXIxFTPRVSLOsRVhoe_gAAAYY"]
[Thu Sep 17 15:09:55.879968 2026] [security2:error] [pid 955873:tid 956106] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/panel/.env"] [unique_id "aqxXIxFTPRVSLOsRVhofBwAAAXE"]
[Thu Sep 17 15:09:56.053306 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhofBgAAARA"]
[Thu Sep 17 15:09:56.053336 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXIxFTPRVSLOsRVhofBgAAARA"]
[Thu Sep 17 15:09:56.124506 2026] [security2:error] [pid 955873:tid 956104] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/crm/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofCAAAAW8"]
[Thu Sep 17 15:09:56.195668 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/assets/images/"] [unique_id "aqxXJBFTPRVSLOsRVhofDAAAAW4"]
[Thu Sep 17 15:09:56.339610 2026] [security2:error] [pid 955873:tid 956040] [client 47.79.207.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofCwAAAS8"], referer: https://www.google.com/
[Thu Sep 17 15:09:56.370457 2026] [security2:error] [pid 955873:tid 956125] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/erp/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofFQAAAYQ"]
[Thu Sep 17 15:09:56.534519 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofEwAAAR8"]
[Thu Sep 17 15:09:56.534547 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofEwAAAR8"]
[Thu Sep 17 15:09:56.584328 2026] [core:error] [pid 955873:tid 956035] [client 184.154.76.35:56886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=www.goldroadholdings.com&yahoo.com
[Thu Sep 17 15:09:56.584349 2026] [core:error] [pid 955873:tid 956035] [client 184.154.76.35:56886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=www.goldroadholdings.com&yahoo.com
[Thu Sep 17 15:09:56.617496 2026] [security2:error] [pid 955873:tid 956092] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/shop/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofHAAAAWM"]
[Thu Sep 17 15:09:56.676276 2026] [security2:error] [pid 955873:tid 956065] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Public/"] [unique_id "aqxXJBFTPRVSLOsRVhofHQAAAUg"]
[Thu Sep 17 15:09:56.871770 2026] [security2:error] [pid 955873:tid 956033] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/store/.env"] [unique_id "aqxXJBFTPRVSLOsRVhofIgAAASg"]
[Thu Sep 17 15:09:56.952958 2026] [security2:error] [pid 955873:tid 956075] [client 104.28.198.244:23020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIwAAAVI"]
[Thu Sep 17 15:09:56.953048 2026] [security2:error] [pid 955873:tid 956075] [client 104.28.198.244:23020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIwAAAVI"]
[Thu Sep 17 15:09:57.009490 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIQAAATw"]
[Thu Sep 17 15:09:57.009518 2026] [security2:error] [pid 955873:tid 956053] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJBFTPRVSLOsRVhofIQAAATw"]
[Thu Sep 17 15:09:57.117683 2026] [security2:error] [pid 955873:tid 956008] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/saas/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofJAAAAQ8"]
[Thu Sep 17 15:09:57.150274 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/vendor/"] [unique_id "aqxXJRFTPRVSLOsRVhofJgAAASY"]
[Thu Sep 17 15:09:57.370948 2026] [security2:error] [pid 955873:tid 956010] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/client/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofKwAAARE"]
[Thu Sep 17 15:09:57.499671 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofKAAAATA"]
[Thu Sep 17 15:09:57.499697 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofKAAAATA"]
[Thu Sep 17 15:09:57.618541 2026] [security2:error] [pid 955873:tid 956057] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/project/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofLAAAAUA"]
[Thu Sep 17 15:09:57.641131 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/local/"] [unique_id "aqxXJRFTPRVSLOsRVhofLQAAAUo"]
[Thu Sep 17 15:09:57.868287 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/admin-panel/.env"] [unique_id "aqxXJRFTPRVSLOsRVhofMwAAATc"]
[Thu Sep 17 15:09:57.983963 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofMAAAAWE"]
[Thu Sep 17 15:09:57.983988 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJRFTPRVSLOsRVhofMAAAAWE"]
[Thu Sep 17 15:09:58.118712 2026] [security2:error] [pid 955873:tid 956129] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/control-panel/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofOAAAAYg"]
[Thu Sep 17 15:09:58.129705 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/modules/"] [unique_id "aqxXJhFTPRVSLOsRVhofOQAAAYU"]
[Thu Sep 17 15:09:58.364645 2026] [security2:error] [pid 955873:tid 956026] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/user-panel/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofRAAAASE"]
[Thu Sep 17 15:09:58.471404 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofPwAAAQ4"]
[Thu Sep 17 15:09:58.471430 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofPwAAAQ4"]
[Thu Sep 17 15:09:58.615334 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/node/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofRgAAAWY"]
[Thu Sep 17 15:09:58.635425 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Site/"] [unique_id "aqxXJhFTPRVSLOsRVhofRwAAASU"]
[Thu Sep 17 15:09:58.871364 2026] [security2:error] [pid 955873:tid 956018] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/express/.env"] [unique_id "aqxXJhFTPRVSLOsRVhofTAAAARk"]
[Thu Sep 17 15:09:58.976188 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofSgAAATI"]
[Thu Sep 17 15:09:58.976227 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJhFTPRVSLOsRVhofSgAAATI"]
[Thu Sep 17 15:09:59.120757 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/system/"] [unique_id "aqxXJxFTPRVSLOsRVhofTgAAATE"]
[Thu Sep 17 15:09:59.121953 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/next/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofTwAAARw"]
[Thu Sep 17 15:09:59.371977 2026] [security2:error] [pid 955873:tid 956123] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/nuxt/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofVAAAAYI"]
[Thu Sep 17 15:09:59.460695 2026] [security2:error] [pid 955873:tid 956014] [client 5.189.145.112:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxXJxFTPRVSLOsRVhofVQAAARU"], referer: binance.com
[Thu Sep 17 15:09:59.478304 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofUAAAAS8"]
[Thu Sep 17 15:09:59.478330 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofUAAAAS8"]
[Thu Sep 17 15:09:59.552007 2026] [security2:error] [pid 955873:tid 956114] [client 4.240.114.86:63166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxXJxFTPRVSLOsRVhofVgAAAXk"], referer: binance.com
[Thu Sep 17 15:09:59.620801 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/template/"] [unique_id "aqxXJxFTPRVSLOsRVhofVwAAAUs"]
[Thu Sep 17 15:09:59.624368 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/nest/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofWAAAAYc"]
[Thu Sep 17 15:09:59.832297 2026] [security2:error] [pid 955873:tid 956006] [client 154.190.208.131:41754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJxFTPRVSLOsRVhofXQAAAQ0"]
[Thu Sep 17 15:09:59.832801 2026] [security2:error] [pid 955873:tid 956006] [client 154.190.208.131:41754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXJxFTPRVSLOsRVhofXQAAAQ0"]
[Thu Sep 17 15:09:59.870193 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/react/.env"] [unique_id "aqxXJxFTPRVSLOsRVhofXgAAAUg"]
[Thu Sep 17 15:09:59.947871 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofWQAAARg"]
[Thu Sep 17 15:09:59.947896 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofWQAAARg"]
[Thu Sep 17 15:10:00.121538 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/shop/"] [unique_id "aqxXKBFTPRVSLOsRVhofYQAAAQ8"]
[Thu Sep 17 15:10:00.128501 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/vue/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofYgAAAWA"]
[Thu Sep 17 15:10:00.376890 2026] [security2:error] [pid 955873:tid 956023] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/angular/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofbAAAAR4"]
[Thu Sep 17 15:10:00.458723 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofZAAAAWc"]
[Thu Sep 17 15:10:00.458753 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofZAAAAWc"]
[Thu Sep 17 15:10:00.600314 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/files/"] [unique_id "aqxXKBFTPRVSLOsRVhofbgAAARM"]
[Thu Sep 17 15:10:00.629293 2026] [security2:error] [pid 955873:tid 956072] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/svelte/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofbwAAAU8"]
[Thu Sep 17 15:10:00.901372 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/vite/.env"] [unique_id "aqxXKBFTPRVSLOsRVhofdQAAATc"]
[Thu Sep 17 15:10:00.952480 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofcAAAAWs"]
[Thu Sep 17 15:10:00.952503 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKBFTPRVSLOsRVhofcAAAAWs"]
[Thu Sep 17 15:10:01.094792 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/editor/"] [unique_id "aqxXKRFTPRVSLOsRVhofdgAAASs"]
[Thu Sep 17 15:10:01.151921 2026] [security2:error] [pid 955873:tid 956083] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/backup/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofdwAAAVo"]
[Thu Sep 17 15:10:01.397869 2026] [security2:error] [pid 955873:tid 956127] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/backups/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofggAAAYY"]
[Thu Sep 17 15:10:01.479489 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhoffAAAASA"]
[Thu Sep 17 15:10:01.479515 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhoffAAAASA"]
[Thu Sep 17 15:10:01.628686 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/include/"] [unique_id "aqxXKRFTPRVSLOsRVhofhgAAAWY"]
[Thu Sep 17 15:10:01.655853 2026] [security2:error] [pid 955873:tid 956101] [client 162.241.226.11:34540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofgQAAAWw"]
[Thu Sep 17 15:10:01.656179 2026] [security2:error] [pid 955873:tid 956073] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/old/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofhwAAAVA"]
[Thu Sep 17 15:10:01.892580 2026] [security2:error] [pid 955873:tid 956117] [client 162.241.226.11:34554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofiAAAAXw"]
[Thu Sep 17 15:10:01.906578 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/tmp/.env"] [unique_id "aqxXKRFTPRVSLOsRVhofkQAAAXQ"]
[Thu Sep 17 15:10:02.019652 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofigAAAS0"]
[Thu Sep 17 15:10:02.019710 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKRFTPRVSLOsRVhofigAAAS0"]
[Thu Sep 17 15:10:02.158070 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/temp/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofnwAAARw"]
[Thu Sep 17 15:10:02.166889 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/Assets/"] [unique_id "aqxXKhFTPRVSLOsRVhofoAAAAYI"]
[Thu Sep 17 15:10:02.404790 2026] [security2:error] [pid 955873:tid 956024] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/lab/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofqwAAAR8"]
[Thu Sep 17 15:10:02.524640 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofqAAAAUs"]
[Thu Sep 17 15:10:02.524677 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofqAAAAUs"]
[Thu Sep 17 15:10:02.656511 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cronlab/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofsgAAAYE"]
[Thu Sep 17 15:10:02.687469 2026] [security2:error] [pid 955873:tid 956046] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/images/stories/"] [unique_id "aqxXKhFTPRVSLOsRVhofswAAATU"]
[Thu Sep 17 15:10:02.760816 2026] [security2:error] [pid 955873:tid 956050] [client 189.110.229.241:35765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofsQABOWg"]
[Thu Sep 17 15:10:02.906138 2026] [security2:error] [pid 955873:tid 956081] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cron/.env"] [unique_id "aqxXKhFTPRVSLOsRVhofuQAAAVg"]
[Thu Sep 17 15:10:03.057641 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofuAAAAWA"]
[Thu Sep 17 15:10:03.057679 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKhFTPRVSLOsRVhofuAAAAWA"]
[Thu Sep 17 15:10:03.151994 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/en/.env"] [unique_id "aqxXKxFTPRVSLOsRVhofvQAAAVk"]
[Thu Sep 17 15:10:03.198055 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/plugins/"] [unique_id "aqxXKxFTPRVSLOsRVhofwgAAARQ"]
[Thu Sep 17 15:10:03.214127 2026] [security2:error] [pid 955873:tid 956098] [client 45.169.98.18:51161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhofxgAAAWk"]
[Thu Sep 17 15:10:03.214225 2026] [security2:error] [pid 955873:tid 956098] [client 45.169.98.18:51161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhofxgAAAWk"]
[Thu Sep 17 15:10:03.471422 2026] [security2:error] [pid 955873:tid 956056] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/administrator/.env"] [unique_id "aqxXKxFTPRVSLOsRVhogDgAAAT8"]
[Thu Sep 17 15:10:03.496605 2026] [security2:error] [pid 955873:tid 956033] [client 172.226.166.151:26405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxXJxFTPRVSLOsRVhofXwABKCw"]
[Thu Sep 17 15:10:03.555306 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhofzwAAARI"]
[Thu Sep 17 15:10:03.555332 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhofzwAAARI"]
[Thu Sep 17 15:10:03.672448 2026] [security2:error] [pid 955873:tid 956106] [client 189.110.229.241:35765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhogEwABcTU"]
[Thu Sep 17 15:10:03.696620 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/php/"] [unique_id "aqxXKxFTPRVSLOsRVhogFAAAAVc"]
[Thu Sep 17 15:10:03.719412 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/psnlink/.env"] [unique_id "aqxXKxFTPRVSLOsRVhogFQAAASA"]
[Thu Sep 17 15:10:03.787387 2026] [security2:error] [pid 955873:tid 956016] [client 185.55.149.49:53751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhogFwAAARc"]
[Thu Sep 17 15:10:03.787531 2026] [security2:error] [pid 955873:tid 956016] [client 185.55.149.49:53751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXKxFTPRVSLOsRVhogFwAAARc"]
[Thu Sep 17 15:10:03.969320 2026] [security2:error] [pid 955873:tid 956102] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/exapi/.env"] [unique_id "aqxXKxFTPRVSLOsRVhogHwAAAW0"]
[Thu Sep 17 15:10:04.050261 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhogGwAAAT4"]
[Thu Sep 17 15:10:04.050286 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXKxFTPRVSLOsRVhogGwAAAT4"]
[Thu Sep 17 15:10:04.198066 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/"] [unique_id "aqxXLBFTPRVSLOsRVhogIAAAARk"]
[Thu Sep 17 15:10:04.220559 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sitemaps/.env"] [unique_id "aqxXLBFTPRVSLOsRVhogIQAAAXg"]
[Thu Sep 17 15:10:04.544480 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/"] [unique_id "aqxXLBFTPRVSLOsRVhogJQAAAU0"]
[Thu Sep 17 15:10:04.585944 2026] [security2:error] [pid 955873:tid 956021] [client 35.244.43.255:49880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogJwAAARw"]
[Thu Sep 17 15:10:04.689997 2026] [security2:error] [pid 955873:tid 956063] [client 192.178.15.197:62676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sfvhbt.org"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogKQAAAUY"]
[Thu Sep 17 15:10:04.692686 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxXLBFTPRVSLOsRVhogMQAAASM"]
[Thu Sep 17 15:10:04.709253 2026] [security2:error] [pid 955873:tid 956047] [client 186.105.232.15:63171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLBFTPRVSLOsRVhogMgAAATY"]
[Thu Sep 17 15:10:04.709390 2026] [security2:error] [pid 955873:tid 956047] [client 186.105.232.15:63171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLBFTPRVSLOsRVhogMgAAATY"]
[Thu Sep 17 15:10:04.931773 2026] [security2:error] [pid 955873:tid 956045] [client 35.244.43.255:49880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogNgAAATQ"]
[Thu Sep 17 15:10:05.144229 2026] [security2:error] [pid 955873:tid 956085] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxXLBFTPRVSLOsRVhogNwAAAVw"]
[Thu Sep 17 15:10:05.181899 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:49880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/logs/.env"] [unique_id "aqxXLRFTPRVSLOsRVhogOQAAAU4"]
[Thu Sep 17 15:10:05.288095 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/wp-admin/css/"] [unique_id "aqxXLRFTPRVSLOsRVhogQQAAAYM"]
[Thu Sep 17 15:10:05.662493 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLRFTPRVSLOsRVhogSgAAATs"]
[Thu Sep 17 15:10:05.662516 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLRFTPRVSLOsRVhogSgAAATs"]
[Thu Sep 17 15:10:05.823899 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxXLRFTPRVSLOsRVhogUQAAAXA"]
[Thu Sep 17 15:10:05.918322 2026] [security2:error] [pid 955873:tid 956072] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cache/.env"] [unique_id "aqxXLRFTPRVSLOsRVhogVQAAAU8"]
[Thu Sep 17 15:10:06.011630 2026] [security2:error] [pid 955873:tid 956077] [client 115.244.164.14:61893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLhFTPRVSLOsRVhogVwAAAVQ"]
[Thu Sep 17 15:10:06.011745 2026] [security2:error] [pid 955873:tid 956077] [client 115.244.164.14:61893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXLhFTPRVSLOsRVhogVwAAAVQ"]
[Thu Sep 17 15:10:06.034907 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxXLRFTPRVSLOsRVhogVgAAAYY"]
[Thu Sep 17 15:10:06.151931 2026] [security2:error] [pid 955873:tid 956068] [client 172.226.166.151:26591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxXLBFTPRVSLOsRVhogOAABSz8"]
[Thu Sep 17 15:10:06.155793 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailer/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogWQAAATc"]
[Thu Sep 17 15:10:06.178211 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/wp-admin/css/colors/"] [unique_id "aqxXLhFTPRVSLOsRVhogWgAAASA"]
[Thu Sep 17 15:10:06.236012 2026] [authz_core:error] [pid 955873:tid 956008] [client 169.58.197.253:62258] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:10:06.396656 2026] [security2:error] [pid 955873:tid 956073] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mail/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogYQAAAVA"]
[Thu Sep 17 15:10:06.525500 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLhFTPRVSLOsRVhogXgAAAQs"]
[Thu Sep 17 15:10:06.525533 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLhFTPRVSLOsRVhogXgAAAQs"]
[Thu Sep 17 15:10:06.566214 2026] [security2:error] [pid 955873:tid 956005] [client 4.240.114.86:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxXLhFTPRVSLOsRVhogZwAAAQw"], referer: binance.com
[Thu Sep 17 15:10:06.641520 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/email/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogaAAAAV0"]
[Thu Sep 17 15:10:06.674486 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxXLhFTPRVSLOsRVhogagAAARk"]
[Thu Sep 17 15:10:06.678274 2026] [security2:error] [pid 955873:tid 956049] [client 210.222.43.21:49883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXLhFTPRVSLOsRVhogZAAAATg"], referer: http://talent-in-borders.com/www
[Thu Sep 17 15:10:06.881264 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxXLhFTPRVSLOsRVhogbQAAASQ"]
[Thu Sep 17 15:10:06.887112 2026] [security2:error] [pid 955873:tid 956070] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/smtp/.env"] [unique_id "aqxXLhFTPRVSLOsRVhogbwAAAU0"]
[Thu Sep 17 15:10:07.023806 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/wp-admin/css/colors/"] [unique_id "aqxXLxFTPRVSLOsRVhogcAAAAQ0"]
[Thu Sep 17 15:10:07.131622 2026] [security2:error] [pid 955873:tid 956045] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailing/.env"] [unique_id "aqxXLxFTPRVSLOsRVhogcQAAATQ"]
[Thu Sep 17 15:10:07.375891 2026] [security2:error] [pid 955873:tid 956050] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/notifications/.env"] [unique_id "aqxXLxFTPRVSLOsRVhogdwAAATk"]
[Thu Sep 17 15:10:07.376471 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLxFTPRVSLOsRVhogcgAAAYQ"]
[Thu Sep 17 15:10:07.376489 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXLxFTPRVSLOsRVhogcgAAAYQ"]
[Thu Sep 17 15:10:07.526757 2026] [security2:error] [pid 955873:tid 956089] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxXLxFTPRVSLOsRVhogewAAAWA"]
[Thu Sep 17 15:10:07.620355 2026] [security2:error] [pid 955873:tid 956013] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/notify/.env"] [unique_id "aqxXLxFTPRVSLOsRVhoggQAAARQ"]
[Thu Sep 17 15:10:07.865968 2026] [security2:error] [pid 955873:tid 956056] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sender/.env"] [unique_id "aqxXLxFTPRVSLOsRVhogjAAAAT8"]
[Thu Sep 17 15:10:07.907626 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxXLxFTPRVSLOsRVhogigAAAYg"]
[Thu Sep 17 15:10:08.049302 2026] [security2:error] [pid 955873:tid 956061] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/wp-admin/css/colors/"] [unique_id "aqxXMBFTPRVSLOsRVhogjQAAAUQ"]
[Thu Sep 17 15:10:08.113217 2026] [security2:error] [pid 955873:tid 956127] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/campaign/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogjgAAAYY"]
[Thu Sep 17 15:10:08.357980 2026] [security2:error] [pid 955873:tid 956112] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/newsletter/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogmgAAAXc"]
[Thu Sep 17 15:10:08.430448 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMBFTPRVSLOsRVhogkgAAATc"]
[Thu Sep 17 15:10:08.430476 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMBFTPRVSLOsRVhogkgAAATc"]
[Thu Sep 17 15:10:08.549733 2026] [security2:error] [pid 955873:tid 956077] [client 104.28.198.244:22766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMBFTPRVSLOsRVhogoAAAAVQ"]
[Thu Sep 17 15:10:08.549880 2026] [security2:error] [pid 955873:tid 956077] [client 104.28.198.244:22766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMBFTPRVSLOsRVhogoAAAAVQ"]
[Thu Sep 17 15:10:08.572926 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxXMBFTPRVSLOsRVhogoQAAARg"]
[Thu Sep 17 15:10:08.600994 2026] [security2:error] [pid 955873:tid 956097] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/ses/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogogAAAWg"]
[Thu Sep 17 15:10:08.769418 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxXMBFTPRVSLOsRVhogpAAAAWY"]
[Thu Sep 17 15:10:08.806767 2026] [security2:error] [pid 955873:tid 956064] [client 5.189.145.112:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxXMBFTPRVSLOsRVhogpQAAAUc"], referer: binance.com
[Thu Sep 17 15:10:08.842809 2026] [security2:error] [pid 955873:tid 956093] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sendgrid/.env"] [unique_id "aqxXMBFTPRVSLOsRVhogpwAAAWQ"]
[Thu Sep 17 15:10:08.912557 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/wp-admin/css/colors/"] [unique_id "aqxXMBFTPRVSLOsRVhogqgAAARs"]
[Thu Sep 17 15:10:09.084013 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/sparkpost/.env"] [unique_id "aqxXMRFTPRVSLOsRVhogrgAAASM"]
[Thu Sep 17 15:10:09.256449 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogrAAAAYI"]
[Thu Sep 17 15:10:09.256473 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogrAAAAYI"]
[Thu Sep 17 15:10:09.328279 2026] [security2:error] [pid 955873:tid 956045] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/postmark/.env"] [unique_id "aqxXMRFTPRVSLOsRVhogsgAAATQ"]
[Thu Sep 17 15:10:09.397367 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxXMRFTPRVSLOsRVhoguAAAAV8"]
[Thu Sep 17 15:10:09.563352 2026] [security2:error] [pid 955873:tid 956082] [client 172.59.160.160:11223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.auxotech.com"] [uri "/cpc/theme/load_page.php"] [unique_id "aqxXMRFTPRVSLOsRVhoguQABWVI"], referer: https://www.auxotech.com/cpc/
[Thu Sep 17 15:10:09.569869 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailgun/.env"] [unique_id "aqxXMRFTPRVSLOsRVhoguwAAAYE"]
[Thu Sep 17 15:10:09.599187 2026] [security2:error] [pid 955873:tid 956013] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxXMRFTPRVSLOsRVhogugAAARQ"]
[Thu Sep 17 15:10:09.742287 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/wp-admin/css/colors/"] [unique_id "aqxXMRFTPRVSLOsRVhogvgAAAUM"]
[Thu Sep 17 15:10:09.814690 2026] [security2:error] [pid 955873:tid 956105] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mandrill/.env"] [unique_id "aqxXMRFTPRVSLOsRVhogvwAAAXA"]
[Thu Sep 17 15:10:10.064977 2026] [security2:error] [pid 955873:tid 956126] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mailjet/.env"] [unique_id "aqxXMhFTPRVSLOsRVhogxAAAAYU"]
[Thu Sep 17 15:10:10.080305 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogwgAAAWs"]
[Thu Sep 17 15:10:10.080332 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMRFTPRVSLOsRVhogwgAAAWs"]
[Thu Sep 17 15:10:10.225226 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxXMhFTPRVSLOsRVhogxQAAAVs"]
[Thu Sep 17 15:10:10.308139 2026] [security2:error] [pid 955873:tid 956012] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/brevo/.env"] [unique_id "aqxXMhFTPRVSLOsRVhogyAAAARM"]
[Thu Sep 17 15:10:10.466090 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxXMhFTPRVSLOsRVhogzQAAAYY"]
[Thu Sep 17 15:10:10.551023 2026] [security2:error] [pid 955873:tid 956080] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/transactional/.env"] [unique_id "aqxXMhFTPRVSLOsRVhog0QAAAVc"]
[Thu Sep 17 15:10:10.626485 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/wp-admin/css/colors/"] [unique_id "aqxXMhFTPRVSLOsRVhog0gAAAWU"]
[Thu Sep 17 15:10:10.696530 2026] [security2:error] [pid 955873:tid 956090] [client 154.190.208.131:42354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1AAAAWE"]
[Thu Sep 17 15:10:10.696668 2026] [security2:error] [pid 955873:tid 956090] [client 154.190.208.131:42354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1AAAAWE"]
[Thu Sep 17 15:10:10.794891 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/bulk/.env"] [unique_id "aqxXMhFTPRVSLOsRVhog1wAAAS4"]
[Thu Sep 17 15:10:11.023940 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1gAAATM"]
[Thu Sep 17 15:10:11.023965 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMhFTPRVSLOsRVhog1gAAATM"]
[Thu Sep 17 15:10:11.040868 2026] [security2:error] [pid 955873:tid 956099] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/aws/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog5gAAAWo"]
[Thu Sep 17 15:10:11.167144 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxXMxFTPRVSLOsRVhog6gAAAWQ"]
[Thu Sep 17 15:10:11.283033 2026] [security2:error] [pid 955873:tid 956007] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/azure/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog7wAAAQ4"]
[Thu Sep 17 15:10:11.414939 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxXMxFTPRVSLOsRVhog8wAAAU0"]
[Thu Sep 17 15:10:11.522601 2026] [security2:error] [pid 955873:tid 956103] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/gcp/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog-AAAAW4"]
[Thu Sep 17 15:10:11.556244 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/wp-admin/css/colors/"] [unique_id "aqxXMxFTPRVSLOsRVhog-QAAASo"]
[Thu Sep 17 15:10:11.718257 2026] [security2:error] [pid 955873:tid 956042] [client 4.240.114.86:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxXMxFTPRVSLOsRVhog-wAAATE"], referer: binance.com
[Thu Sep 17 15:10:11.763923 2026] [security2:error] [pid 955873:tid 956114] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cloud/.env"] [unique_id "aqxXMxFTPRVSLOsRVhog_AAAAXk"]
[Thu Sep 17 15:10:11.897815 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMxFTPRVSLOsRVhog-gAAATY"]
[Thu Sep 17 15:10:11.897844 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXMxFTPRVSLOsRVhog-gAAATY"]
[Thu Sep 17 15:10:12.007050 2026] [security2:error] [pid 955873:tid 956107] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/infrastructure/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohBgAAAXI"]
[Thu Sep 17 15:10:12.040348 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxXNBFTPRVSLOsRVhohCQAAAU4"]
[Thu Sep 17 15:10:12.248855 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/docker/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohDAAAAYE"]
[Thu Sep 17 15:10:12.267645 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxXNBFTPRVSLOsRVhohCwAAAR4"]
[Thu Sep 17 15:10:12.492858 2026] [security2:error] [pid 955873:tid 956119] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/k8s/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohFAAAAX4"]
[Thu Sep 17 15:10:12.505806 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/wp-admin/css/colors/"] [unique_id "aqxXNBFTPRVSLOsRVhohFQAAARM"]
[Thu Sep 17 15:10:12.737021 2026] [security2:error] [pid 955873:tid 956014] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/kubernetes/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohGAAAARU"]
[Thu Sep 17 15:10:12.857757 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNBFTPRVSLOsRVhohFwAAAYY"]
[Thu Sep 17 15:10:12.857781 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNBFTPRVSLOsRVhohFwAAAYY"]
[Thu Sep 17 15:10:12.978616 2026] [security2:error] [pid 955873:tid 956048] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/terraform/.env"] [unique_id "aqxXNBFTPRVSLOsRVhohLwAAATc"]
[Thu Sep 17 15:10:12.998776 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxXNBFTPRVSLOsRVhohMQAAAXw"]
[Thu Sep 17 15:10:13.223999 2026] [security2:error] [pid 955873:tid 956095] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/ansible/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohNwAAAWY"]
[Thu Sep 17 15:10:13.359856 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:56620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohMwAAASU"]
[Thu Sep 17 15:10:13.359892 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohMwAAASU"]
[Thu Sep 17 15:10:13.370137 2026] [security2:error] [pid 955873:tid 956058] [client 177.10.23.92:50650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohOwABQQI"]
[Thu Sep 17 15:10:13.472857 2026] [security2:error] [pid 955873:tid 956118] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/.git/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohQQAAAX0"]
[Thu Sep 17 15:10:13.507409 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/cache/"] [unique_id "aqxXNRFTPRVSLOsRVhohQgAAARw"]
[Thu Sep 17 15:10:13.652629 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/cache/index.html"] [unique_id "aqxXNRFTPRVSLOsRVhohRwAAAXk"]
[Thu Sep 17 15:10:13.719310 2026] [security2:error] [pid 955873:tid 956075] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/ci/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohSQAAAVI"]
[Thu Sep 17 15:10:13.737082 2026] [security2:error] [pid 955873:tid 956081] [client 45.169.98.18:51725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNRFTPRVSLOsRVhohSgAAAVg"]
[Thu Sep 17 15:10:13.737236 2026] [security2:error] [pid 955873:tid 956081] [client 45.169.98.18:51725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNRFTPRVSLOsRVhohSgAAAVg"]
[Thu Sep 17 15:10:13.825914 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/"] [unique_id "aqxXNRFTPRVSLOsRVhohSwAAASc"]
[Thu Sep 17 15:10:13.964781 2026] [security2:error] [pid 955873:tid 956088] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/cd/.env"] [unique_id "aqxXNRFTPRVSLOsRVhohUwAAAV8"]
[Thu Sep 17 15:10:14.036801 2026] [authz_core:error] [pid 955873:tid 956121] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-admin/maint/error_log
[Thu Sep 17 15:10:14.041206 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/"] [unique_id "aqxXNRFTPRVSLOsRVhohVAAAAYA"]
[Thu Sep 17 15:10:14.205965 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/jenkins/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohVgAAAWA"]
[Thu Sep 17 15:10:14.216964 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aqxXNhFTPRVSLOsRVhohWAAAAYI"]
[Thu Sep 17 15:10:14.217088 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:52988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aqxXNhFTPRVSLOsRVhohWAAAAYI"]
[Thu Sep 17 15:10:14.256992 2026] [security2:error] [pid 955873:tid 956006] [client 177.10.23.92:50650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXNhFTPRVSLOsRVhohVQABDWc"]
[Thu Sep 17 15:10:14.445871 2026] [security2:error] [pid 955873:tid 956027] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/gitlab/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohXQAAASI"]
[Thu Sep 17 15:10:14.498417 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:45164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxXNhFTPRVSLOsRVhohXgAAATA"]
[Thu Sep 17 15:10:14.500599 2026] [security2:error] [pid 955873:tid 956045] [client 185.55.149.49:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXNhFTPRVSLOsRVhohXwAAATQ"]
[Thu Sep 17 15:10:14.500715 2026] [security2:error] [pid 955873:tid 956045] [client 185.55.149.49:54458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXNhFTPRVSLOsRVhohXwAAATQ"]
[Thu Sep 17 15:10:14.643802 2026] [authz_core:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-content/plugins/akismet/
[Thu Sep 17 15:10:14.645066 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxXNhFTPRVSLOsRVhohYQAAAVE"]
[Thu Sep 17 15:10:14.690969 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/github/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohYgAAAR0"]
[Thu Sep 17 15:10:14.791351 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:45164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/"] [unique_id "aqxXNhFTPRVSLOsRVhohYwAAARM"]
[Thu Sep 17 15:10:14.939876 2026] [security2:error] [pid 955873:tid 956036] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/actions/.env"] [unique_id "aqxXNhFTPRVSLOsRVhohZwAAASs"]
[Thu Sep 17 15:10:14.962105 2026] [security2:error] [pid 955873:tid 956060] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/"] [unique_id "aqxXNhFTPRVSLOsRVhohaAAAAUM"]
[Thu Sep 17 15:10:15.109256 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/icon-library-manifest.php"] [unique_id "aqxXNxFTPRVSLOsRVhohbwAAARU"]
[Thu Sep 17 15:10:15.109398 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:45164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/icon-library-manifest.php"] [unique_id "aqxXNxFTPRVSLOsRVhohbwAAARU"]
[Thu Sep 17 15:10:15.183466 2026] [security2:error] [pid 955873:tid 956104] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/circleci/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohcAAAAW8"]
[Thu Sep 17 15:10:15.400366 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:45168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/script-modules-packages.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdAAAAWw"]
[Thu Sep 17 15:10:15.400501 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:45168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/assets/script-modules-packages.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdAAAAWw"]
[Thu Sep 17 15:10:15.436335 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/travis/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohdQAAAS4"]
[Thu Sep 17 15:10:15.641332 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:63760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdwAAAVo"]
[Thu Sep 17 15:10:15.643721 2026] [security2:error] [pid 955873:tid 956083] [client 186.105.232.15:63760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohdwAAAVo"]
[Thu Sep 17 15:10:15.677044 2026] [security2:error] [pid 955873:tid 956102] [client 143.244.57.120:45170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxXNxFTPRVSLOsRVhoheQAAAW0"]
[Thu Sep 17 15:10:15.678585 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/buildkite/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohewAAAV4"]
[Thu Sep 17 15:10:15.847408 2026] [authz_core:error] [pid 955873:tid 956109] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/block-patterns/error_log
[Thu Sep 17 15:10:15.850039 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxXNxFTPRVSLOsRVhohfwAAAXQ"]
[Thu Sep 17 15:10:15.921622 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mysql/.env"] [unique_id "aqxXNxFTPRVSLOsRVhohhgAAAXM"]
[Thu Sep 17 15:10:15.922923 2026] [security2:error] [pid 955873:tid 956026] [client 156.192.234.52:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohgwAAASE"]
[Thu Sep 17 15:10:15.923040 2026] [security2:error] [pid 955873:tid 956026] [client 156.192.234.52:58434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXNxFTPRVSLOsRVhohgwAAASE"]
[Thu Sep 17 15:10:15.987065 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-accent-bg.php"] [unique_id "aqxXNxFTPRVSLOsRVhohhwAAASU"]
[Thu Sep 17 15:10:15.987195 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:45170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-accent-bg.php"] [unique_id "aqxXNxFTPRVSLOsRVhohhwAAASU"]
[Thu Sep 17 15:10:16.165607 2026] [security2:error] [pid 955873:tid 956124] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/postgres/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohiQAAAYM"]
[Thu Sep 17 15:10:16.275956 2026] [security2:error] [pid 955873:tid 956042] [client 66.249.66.196:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kopecdental.com"] [uri "/index.php"] [unique_id "aqxXNRFTPRVSLOsRVhohSAAAATE"]
[Thu Sep 17 15:10:16.277784 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:45182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-black-bg.php"] [unique_id "aqxXOBFTPRVSLOsRVhohiwAAAWQ"]
[Thu Sep 17 15:10:16.277902 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:45182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-black-bg.php"] [unique_id "aqxXOBFTPRVSLOsRVhohiwAAAWQ"]
[Thu Sep 17 15:10:16.410409 2026] [security2:error] [pid 955873:tid 956025] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/mongodb/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohjwAAASA"]
[Thu Sep 17 15:10:16.522045 2026] [security2:error] [pid 955873:tid 956035] [client 115.244.164.14:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOBFTPRVSLOsRVhohkwAAASo"]
[Thu Sep 17 15:10:16.522155 2026] [security2:error] [pid 955873:tid 956035] [client 115.244.164.14:62533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOBFTPRVSLOsRVhohkwAAASo"]
[Thu Sep 17 15:10:16.572477 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered-with-extras.php"] [unique_id "aqxXOBFTPRVSLOsRVhohlAAAAYA"]
[Thu Sep 17 15:10:16.572620 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:45188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered-with-extras.php"] [unique_id "aqxXOBFTPRVSLOsRVhohlAAAAYA"]
[Thu Sep 17 15:10:16.654355 2026] [security2:error] [pid 955873:tid 956047] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/redis/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohlQAAATY"]
[Thu Sep 17 15:10:16.865320 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered.php"] [unique_id "aqxXOBFTPRVSLOsRVhohmgAAARk"]
[Thu Sep 17 15:10:16.865455 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:45190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay-centered.php"] [unique_id "aqxXOBFTPRVSLOsRVhohmgAAARk"]
[Thu Sep 17 15:10:16.896158 2026] [security2:error] [pid 955873:tid 956017] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/elasticsearch/.env"] [unique_id "aqxXOBFTPRVSLOsRVhohmwAAARg"]
[Thu Sep 17 15:10:17.019602 2026] [security2:error] [pid 955873:tid 956006] [client 57.141.14.78:38378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXOBFTPRVSLOsRVhohlwABDV0"]
[Thu Sep 17 15:10:17.137499 2026] [security2:error] [pid 955873:tid 956122] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/rabbitmq/.env"] [unique_id "aqxXORFTPRVSLOsRVhohngAAAYE"]
[Thu Sep 17 15:10:17.161338 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:45196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay.php"] [unique_id "aqxXORFTPRVSLOsRVhohnwAAAUU"]
[Thu Sep 17 15:10:17.161471 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:45196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/navigation-overlay.php"] [unique_id "aqxXORFTPRVSLOsRVhohnwAAAUU"]
[Thu Sep 17 15:10:17.379179 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/kafka/.env"] [unique_id "aqxXORFTPRVSLOsRVhohowAAAR0"]
[Thu Sep 17 15:10:17.469339 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:45200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-grid-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohpQAAAVk"]
[Thu Sep 17 15:10:17.469471 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:45200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-grid-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohpQAAAVk"]
[Thu Sep 17 15:10:17.619589 2026] [security2:error] [pid 955873:tid 956014] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/queue/.env"] [unique_id "aqxXORFTPRVSLOsRVhohqQAAARU"]
[Thu Sep 17 15:10:17.733260 2026] [security2:error] [pid 955873:tid 956105] [client 5.189.145.112:56062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxXORFTPRVSLOsRVhohqgAAAXA"], referer: binance.com
[Thu Sep 17 15:10:17.858882 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/worker/.env"] [unique_id "aqxXORFTPRVSLOsRVhohrQAAAS4"]
[Thu Sep 17 15:10:17.870330 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:45214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-large-title-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohrgAAAUY"]
[Thu Sep 17 15:10:17.870424 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:45214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-large-title-posts.php"] [unique_id "aqxXORFTPRVSLOsRVhohrgAAAUY"]
[Thu Sep 17 15:10:18.099764 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/job/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohswAAAQo"]
[Thu Sep 17 15:10:18.125383 2026] [security2:error] [pid 955873:tid 956104] [client 104.28.198.244:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtAAAAW8"]
[Thu Sep 17 15:10:18.125540 2026] [security2:error] [pid 955873:tid 956104] [client 104.28.198.244:22657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtAAAAW8"]
[Thu Sep 17 15:10:18.165542 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:45220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-medium-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtgAAARc"]
[Thu Sep 17 15:10:18.165669 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:45220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-medium-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohtgAAARc"]
[Thu Sep 17 15:10:18.342987 2026] [security2:error] [pid 955873:tid 956066] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/test/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohvAAAAUk"]
[Thu Sep 17 15:10:18.462820 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-offset-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohvgAAAWY"]
[Thu Sep 17 15:10:18.462932 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:45228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-offset-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohvgAAAWY"]
[Thu Sep 17 15:10:18.577768 2026] [security2:error] [pid 955873:tid 956050] [client 37.59.21.100:56202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.churchinirving.org"] [uri "/index.php"] [unique_id "aqxXORFTPRVSLOsRVhohoAAAATk"]
[Thu Sep 17 15:10:18.590907 2026] [security2:error] [pid 955873:tid 956030] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/qa/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohvwAAASU"]
[Thu Sep 17 15:10:18.718550 2026] [security2:error] [pid 955873:tid 956079] [client 4.240.114.86:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxXOhFTPRVSLOsRVhohwQAAAVY"], referer: binance.com
[Thu Sep 17 15:10:18.780095 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:45238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-small-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohwwAAAXo"]
[Thu Sep 17 15:10:18.780190 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:45238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-small-posts.php"] [unique_id "aqxXOhFTPRVSLOsRVhohwwAAAXo"]
[Thu Sep 17 15:10:18.835440 2026] [security2:error] [pid 955873:tid 956011] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/preview/.env"] [unique_id "aqxXOhFTPRVSLOsRVhohxQAAARI"]
[Thu Sep 17 15:10:18.875293 2026] [security2:error] [pid 955873:tid 956124] [client 134.185.85.61:51236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "coachmancrafts.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxXOhFTPRVSLOsRVhohxwAAAYM"]
[Thu Sep 17 15:10:19.074172 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:45240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-standard-posts.php"] [unique_id "aqxXOxFTPRVSLOsRVhohygAAASA"]
[Thu Sep 17 15:10:19.074297 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:45240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/query-standard-posts.php"] [unique_id "aqxXOxFTPRVSLOsRVhohygAAASA"]
[Thu Sep 17 15:10:19.078376 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/beta/.env"] [unique_id "aqxXOxFTPRVSLOsRVhohywAAAV0"]
[Thu Sep 17 15:10:19.253861 2026] [security2:error] [pid 955873:tid 956125] [client 134.185.85.61:52119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "coachmancrafts.com"] [uri "/media/system/js/core.js"] [unique_id "aqxXOxFTPRVSLOsRVhohzAAAAYQ"]
[Thu Sep 17 15:10:19.325759 2026] [security2:error] [pid 955873:tid 956009] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/uat/.env"] [unique_id "aqxXOxFTPRVSLOsRVhohzwAAARA"]
[Thu Sep 17 15:10:19.377259 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:45250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/social-links-shared-background-color.php"] [unique_id "aqxXOxFTPRVSLOsRVhoh0wAAAWc"]
[Thu Sep 17 15:10:19.377359 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:45250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-patterns/social-links-shared-background-color.php"] [unique_id "aqxXOxFTPRVSLOsRVhoh0wAAAWc"]
[Thu Sep 17 15:10:19.572026 2026] [security2:error] [pid 955873:tid 956006] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/stage/.env"] [unique_id "aqxXOxFTPRVSLOsRVhoh2wAAAQ0"]
[Thu Sep 17 15:10:19.683110 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:45252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxXOxFTPRVSLOsRVhoh3AAAAR4"]
[Thu Sep 17 15:10:19.817037 2026] [security2:error] [pid 955873:tid 956062] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/development/.env"] [unique_id "aqxXOxFTPRVSLOsRVhoh3gAAAUU"]
[Thu Sep 17 15:10:19.844780 2026] [authz_core:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/block-supports/error_log
[Thu Sep 17 15:10:19.848180 2026] [security2:error] [pid 955873:tid 956074] [client 143.244.57.120:56620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxXOxFTPRVSLOsRVhoh3wAAAVE"]
[Thu Sep 17 15:10:20.004937 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/anchor.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh5gAAAYY"]
[Thu Sep 17 15:10:20.005068 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:45252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/anchor.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh5gAAAYY"]
[Thu Sep 17 15:10:20.059381 2026] [security2:error] [pid 955873:tid 956060] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/production/.env"] [unique_id "aqxXPBFTPRVSLOsRVhoh5wAAAUM"]
[Thu Sep 17 15:10:20.288389 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:36066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/aria-label.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh6AAAAVA"]
[Thu Sep 17 15:10:20.288515 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:36066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/aria-label.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh6AAAAVA"]
[Thu Sep 17 15:10:20.300804 2026] [security2:error] [pid 955873:tid 956072] [client 35.244.43.255:60962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sqlerudition.com"] [uri "/config/app/.env"] [unique_id "aqxXPBFTPRVSLOsRVhoh6QAAAU8"]
[Thu Sep 17 15:10:20.541606 2026] [security2:error] [pid 955873:tid 956087] [client 35.244.43.255:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh8QAAAV4"]
[Thu Sep 17 15:10:20.575480 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/auto-register.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh8gAAAXw"]
[Thu Sep 17 15:10:20.575620 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/auto-register.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh8gAAAXw"]
[Thu Sep 17 15:10:20.876796 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/background.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh-AAAASU"]
[Thu Sep 17 15:10:20.876906 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/background.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh-AAAASU"]
[Thu Sep 17 15:10:20.984584 2026] [security2:error] [pid 955873:tid 956078] [client 192.178.15.161:52788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxXPBFTPRVSLOsRVhoh9QAAAVU"]
[Thu Sep 17 15:10:21.172468 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:36098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-style-variations.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh-wAAARs"]
[Thu Sep 17 15:10:21.172606 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:36098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-style-variations.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh-wAAARs"]
[Thu Sep 17 15:10:21.246197 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:41614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh_wAAAWY"]
[Thu Sep 17 15:10:21.246317 2026] [security2:error] [pid 955873:tid 956095] [client 154.190.208.131:41614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXPRFTPRVSLOsRVhoh_wAAAWY"]
[Thu Sep 17 15:10:21.258580 2026] [security2:error] [pid 955873:tid 956037] [client 35.244.43.255:37870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/info.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiAQAAASw"]
[Thu Sep 17 15:10:21.459350 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-visibility.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiBQAAAS0"]
[Thu Sep 17 15:10:21.459459 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:36112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/block-visibility.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiBQAAAS0"]
[Thu Sep 17 15:10:21.741233 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:36124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/border.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiCAAAAUI"]
[Thu Sep 17 15:10:21.741379 2026] [security2:error] [pid 955873:tid 956059] [client 143.244.57.120:36124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/border.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiCAAAAUI"]
[Thu Sep 17 15:10:21.777854 2026] [security2:error] [pid 955873:tid 956086] [client 57.141.14.51:64950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiBwABXQA"]
[Thu Sep 17 15:10:21.965426 2026] [security2:error] [pid 955873:tid 956042] [client 35.244.43.255:37886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/php.php"] [unique_id "aqxXPRFTPRVSLOsRVhoiDQAAATE"]
[Thu Sep 17 15:10:22.030362 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/custom-css.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDgAAAYA"]
[Thu Sep 17 15:10:22.030506 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:36126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/custom-css.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDgAAAYA"]
[Thu Sep 17 15:10:22.320540 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/dimensions.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDwAAARg"]
[Thu Sep 17 15:10:22.320644 2026] [security2:error] [pid 955873:tid 956017] [client 143.244.57.120:36138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/dimensions.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiDwAAARg"]
[Thu Sep 17 15:10:22.598406 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/duotone.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiFQAAAYU"]
[Thu Sep 17 15:10:22.598541 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:36144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/duotone.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiFQAAAYU"]
[Thu Sep 17 15:10:22.673414 2026] [security2:error] [pid 955873:tid 956111] [client 35.244.43.255:37888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/i.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiFwAAAXY"]
[Thu Sep 17 15:10:22.882893 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/elements.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiHQAAAR0"]
[Thu Sep 17 15:10:22.883007 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/elements.php"] [unique_id "aqxXPhFTPRVSLOsRVhoiHQAAAR0"]
[Thu Sep 17 15:10:23.161305 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:36172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/layout.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiIAAAAYY"]
[Thu Sep 17 15:10:23.161438 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:36172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/layout.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiIAAAAYY"]
[Thu Sep 17 15:10:23.276907 2026] [security2:error] [pid 955873:tid 956039] [client 104.243.33.53:57668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "travisklassen.com"] [uri "/.env"] [unique_id "aqxXPxFTPRVSLOsRVhoiJgAAAS4"]
[Thu Sep 17 15:10:23.414568 2026] [security2:error] [pid 955873:tid 956101] [client 35.244.43.255:37896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/pi.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiLAAAAWw"]
[Thu Sep 17 15:10:23.461786 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:36176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/position.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiLQAAAUk"]
[Thu Sep 17 15:10:23.461908 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:36176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/position.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiLQAAAUk"]
[Thu Sep 17 15:10:23.740226 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:36192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/settings.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiMQAAAUc"]
[Thu Sep 17 15:10:23.740351 2026] [security2:error] [pid 955873:tid 956064] [client 143.244.57.120:36192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/settings.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiMQAAAUc"]
[Thu Sep 17 15:10:24.028300 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:36208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/shadow.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiNgAAATc"]
[Thu Sep 17 15:10:24.028406 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:36208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/shadow.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiNgAAATc"]
[Thu Sep 17 15:10:24.034555 2026] [security2:error] [pid 955873:tid 956118] [client 4.240.114.86:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiNwAAAX0"], referer: binance.com
[Thu Sep 17 15:10:24.075518 2026] [security2:error] [pid 955873:tid 956030] [client 193.56.116.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxXPxFTPRVSLOsRVhoiNQABJTQ"]
[Thu Sep 17 15:10:24.150476 2026] [security2:error] [pid 955873:tid 956129] [client 35.244.43.255:37900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/pinfo.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOAAAAYg"]
[Thu Sep 17 15:10:24.206194 2026] [security2:error] [pid 955873:tid 956078] [client 45.169.98.18:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOgAAAVU"]
[Thu Sep 17 15:10:24.206314 2026] [security2:error] [pid 955873:tid 956078] [client 45.169.98.18:52292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOgAAAVU"]
[Thu Sep 17 15:10:24.306445 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:36224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/spacing.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOwAAAT4"]
[Thu Sep 17 15:10:24.306588 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:36224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/spacing.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiOwAAAT4"]
[Thu Sep 17 15:10:24.591848 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/states.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiQgAAAWQ"]
[Thu Sep 17 15:10:24.591963 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:36232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/states.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiQgAAAWQ"]
[Thu Sep 17 15:10:24.885441 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:36244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiRQAAASA"]
[Thu Sep 17 15:10:24.885556 2026] [security2:error] [pid 955873:tid 956025] [client 143.244.57.120:36244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/block-supports/utils.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiRQAAASA"]
[Thu Sep 17 15:10:24.892147 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:37246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/test.php"] [unique_id "aqxXQBFTPRVSLOsRVhoiRwAAASM"]
[Thu Sep 17 15:10:25.167558 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:36246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxXQRFTPRVSLOsRVhoiSQAAAXk"]
[Thu Sep 17 15:10:25.291399 2026] [security2:error] [pid 955873:tid 956052] [client 185.55.149.49:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiTAAAATs"]
[Thu Sep 17 15:10:25.291520 2026] [security2:error] [pid 955873:tid 956052] [client 185.55.149.49:57900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiTAAAATs"]
[Thu Sep 17 15:10:25.620856 2026] [autoindex:error] [pid 955873:tid 956010] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:25.621609 2026] [security2:error] [pid 955873:tid 956010] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/cgi-sys/403.html"] [unique_id "aqxXQRFTPRVSLOsRVhoiVAAAARE"]
[Thu Sep 17 15:10:25.626060 2026] [authz_core:error] [pid 955873:tid 956123] [client 143.244.57.120:40074] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/html-api/error_log
[Thu Sep 17 15:10:25.629714 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxXQRFTPRVSLOsRVhoiVQAAAYI"]
[Thu Sep 17 15:10:25.779587 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-active-formatting-elements.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiWQAAATQ"]
[Thu Sep 17 15:10:25.779755 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:36246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-active-formatting-elements.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiWQAAATQ"]
[Thu Sep 17 15:10:25.826056 2026] [autoindex:error] [pid 955873:tid 956014] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:25.826736 2026] [security2:error] [pid 955873:tid 956014] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/"] [unique_id "aqxXQRFTPRVSLOsRVhoiWwAAARU"]
[Thu Sep 17 15:10:25.837202 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:37256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiVwAAAWA"]
[Thu Sep 17 15:10:25.908394 2026] [security2:error] [pid 955873:tid 956041] [client 114.10.146.139:62936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiWgABMB4"]
[Thu Sep 17 15:10:25.976987 2026] [security2:error] [pid 955873:tid 956127] [client 162.241.226.11:39054] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiXwAAAYY"]
[Thu Sep 17 15:10:26.001014 2026] [security2:error] [pid 955873:tid 956085] [client 34.44.196.215:12176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxXQRFTPRVSLOsRVhoiUQABXC0"]
[Thu Sep 17 15:10:26.018315 2026] [autoindex:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.018845 2026] [security2:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/css/"] [unique_id "aqxXQhFTPRVSLOsRVhoiYAAAAS4"]
[Thu Sep 17 15:10:26.070973 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:36252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-attribute-token.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYQAAARY"]
[Thu Sep 17 15:10:26.071106 2026] [security2:error] [pid 955873:tid 956015] [client 143.244.57.120:36252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-attribute-token.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYQAAARY"]
[Thu Sep 17 15:10:26.072479 2026] [security2:error] [pid 955873:tid 956003] [client 35.244.43.255:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/p.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYgAAAQo"]
[Thu Sep 17 15:10:26.226013 2026] [autoindex:error] [pid 955873:tid 956057] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.226540 2026] [security2:error] [pid 955873:tid 956057] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxXQhFTPRVSLOsRVhoiZAAAAUA"]
[Thu Sep 17 15:10:26.288589 2026] [security2:error] [pid 955873:tid 956105] [client 156.192.234.52:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZQAAAXA"]
[Thu Sep 17 15:10:26.292367 2026] [security2:error] [pid 955873:tid 956105] [client 156.192.234.52:59296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZQAAAXA"]
[Thu Sep 17 15:10:26.364271 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-decoder.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZwAAAUU"]
[Thu Sep 17 15:10:26.364407 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:36256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-decoder.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiZwAAAUU"]
[Thu Sep 17 15:10:26.417481 2026] [autoindex:error] [pid 955873:tid 956104] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.418133 2026] [security2:error] [pid 955873:tid 956104] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxXQhFTPRVSLOsRVhoiaAAAAW8"]
[Thu Sep 17 15:10:26.457438 2026] [security2:error] [pid 955873:tid 956016] [client 34.44.196.215:12176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiYwABFzs"]
[Thu Sep 17 15:10:26.569991 2026] [ssl:error] [pid 955873:tid 956126] [client 199.45.154.55:40656] AH02032: Hostname box5305.bluehost.com (default host as no SNI was provided) and hostname mail.daprayer.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Sep 17 15:10:26.616642 2026] [autoindex:error] [pid 955873:tid 956108] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.617234 2026] [security2:error] [pid 955873:tid 956108] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxXQhFTPRVSLOsRVhoibgAAAXM"]
[Thu Sep 17 15:10:26.654193 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:36272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-doctype-info.php"] [unique_id "aqxXQhFTPRVSLOsRVhoicAAAAUY"]
[Thu Sep 17 15:10:26.654309 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:36272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-doctype-info.php"] [unique_id "aqxXQhFTPRVSLOsRVhoicAAAAUY"]
[Thu Sep 17 15:10:26.790737 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:37260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/debug.php"] [unique_id "aqxXQhFTPRVSLOsRVhoicQAAAXQ"]
[Thu Sep 17 15:10:26.821201 2026] [autoindex:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:26.821684 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxXQhFTPRVSLOsRVhoicgAAATc"]
[Thu Sep 17 15:10:26.902746 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:64354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoieAAAAUE"]
[Thu Sep 17 15:10:26.902849 2026] [security2:error] [pid 955873:tid 956058] [client 186.105.232.15:64354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQhFTPRVSLOsRVhoieAAAAUE"]
[Thu Sep 17 15:10:26.919224 2026] [security2:error] [pid 955873:tid 956084] [client 5.189.145.112:49264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxXQhFTPRVSLOsRVhoieQAAAVs"], referer: binance.com
[Thu Sep 17 15:10:26.936436 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-open-elements.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiewAAAYg"]
[Thu Sep 17 15:10:26.936531 2026] [security2:error] [pid 955873:tid 956129] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-open-elements.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiewAAAYg"]
[Thu Sep 17 15:10:27.026400 2026] [autoindex:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:27.027090 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/Text/"] [unique_id "aqxXQxFTPRVSLOsRVhoifAAAAXc"]
[Thu Sep 17 15:10:27.069302 2026] [security2:error] [pid 955873:tid 956043] [client 57.141.14.108:20558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXQhFTPRVSLOsRVhoiegABMkk"]
[Thu Sep 17 15:10:27.107392 2026] [security2:error] [pid 955873:tid 956118] [client 115.244.164.14:63359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQxFTPRVSLOsRVhoifgAAAX0"]
[Thu Sep 17 15:10:27.107478 2026] [security2:error] [pid 955873:tid 956118] [client 115.244.164.14:63359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXQxFTPRVSLOsRVhoifgAAAX0"]
[Thu Sep 17 15:10:27.223482 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor-state.php"] [unique_id "aqxXQxFTPRVSLOsRVhoigwAAAYc"]
[Thu Sep 17 15:10:27.223597 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:36294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor-state.php"] [unique_id "aqxXQxFTPRVSLOsRVhoigwAAAYc"]
[Thu Sep 17 15:10:27.432711 2026] [security2:error] [pid 955873:tid 956037] [client 34.44.196.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "devilsarmynetwork.com"] [uri "/index.php"] [unique_id "aqxXQxFTPRVSLOsRVhoifwAAASw"]
[Thu Sep 17 15:10:27.501490 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:36310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor.php"] [unique_id "aqxXQxFTPRVSLOsRVhoihwAAAVg"]
[Thu Sep 17 15:10:27.501588 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:36310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-processor.php"] [unique_id "aqxXQxFTPRVSLOsRVhoihwAAAVg"]
[Thu Sep 17 15:10:27.513890 2026] [security2:error] [pid 955873:tid 956038] [client 35.244.43.255:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXQxFTPRVSLOsRVhoiiAAAAS0"]
[Thu Sep 17 15:10:27.793170 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-span.php"] [unique_id "aqxXQxFTPRVSLOsRVhoijgAAARk"]
[Thu Sep 17 15:10:27.793307 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:36316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-span.php"] [unique_id "aqxXQxFTPRVSLOsRVhoijgAAARk"]
[Thu Sep 17 15:10:27.887876 2026] [authz_core:error] [pid 955873:tid 956098] [client 169.58.197.253:63629] AH01630: client denied by server configuration: /home3/sportsg2/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:10:28.076958 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-stack-event.php"] [unique_id "aqxXRBFTPRVSLOsRVhoikAAAARE"]
[Thu Sep 17 15:10:28.077112 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:36326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-stack-event.php"] [unique_id "aqxXRBFTPRVSLOsRVhoikAAAARE"]
[Thu Sep 17 15:10:28.247100 2026] [security2:error] [pid 955873:tid 956121] [client 35.244.43.255:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXRBFTPRVSLOsRVhoilwAAAYA"]
[Thu Sep 17 15:10:28.366190 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-tag-processor.php"] [unique_id "aqxXRBFTPRVSLOsRVhoimAAAAR0"]
[Thu Sep 17 15:10:28.366270 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-tag-processor.php"] [unique_id "aqxXRBFTPRVSLOsRVhoimAAAAR0"]
[Thu Sep 17 15:10:28.643275 2026] [security2:error] [pid 955873:tid 956087] [client 4.240.114.86:64244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxXRBFTPRVSLOsRVhoioAAAAV4"], referer: binance.com
[Thu Sep 17 15:10:28.654454 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-text-replacement.php"] [unique_id "aqxXRBFTPRVSLOsRVhoioQAAAXw"]
[Thu Sep 17 15:10:28.654568 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:36346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-text-replacement.php"] [unique_id "aqxXRBFTPRVSLOsRVhoioQAAAXw"]
[Thu Sep 17 15:10:28.714815 2026] [security2:error] [pid 955873:tid 956077] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXQxFTPRVSLOsRVhoiggAAAVQ"]
[Thu Sep 17 15:10:28.714843 2026] [security2:error] [pid 955873:tid 956077] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXQxFTPRVSLOsRVhoiggAAAVQ"]
[Thu Sep 17 15:10:28.937928 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:36356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-token.php"] [unique_id "aqxXRBFTPRVSLOsRVhoipwAAAXQ"]
[Thu Sep 17 15:10:28.938046 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:36356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-token.php"] [unique_id "aqxXRBFTPRVSLOsRVhoipwAAAXQ"]
[Thu Sep 17 15:10:28.975897 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXRBFTPRVSLOsRVhoiqAAAAXM"]
[Thu Sep 17 15:10:29.112089 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqQAAATc"]
[Thu Sep 17 15:10:29.112114 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqQAAATc"]
[Thu Sep 17 15:10:29.224934 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:36372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-unsupported-exception.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqwAAAVs"]
[Thu Sep 17 15:10:29.225057 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:36372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/class-wp-html-unsupported-exception.php"] [unique_id "aqxXRRFTPRVSLOsRVhoiqwAAAVs"]
[Thu Sep 17 15:10:29.403943 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoirAAAAXo"]
[Thu Sep 17 15:10:29.403972 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRRFTPRVSLOsRVhoirAAAAXo"]
[Thu Sep 17 15:10:29.512387 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:36380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/html5-named-character-references.php"] [unique_id "aqxXRRFTPRVSLOsRVhoisAAAATI"]
[Thu Sep 17 15:10:29.512508 2026] [security2:error] [pid 955873:tid 956043] [client 143.244.57.120:36380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/html-api/html5-named-character-references.php"] [unique_id "aqxXRRFTPRVSLOsRVhoisAAAATI"]
[Thu Sep 17 15:10:29.604482 2026] [autoindex:error] [pid 955873:tid 956099] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:29.605007 2026] [security2:error] [pid 955873:tid 956099] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxXRRFTPRVSLOsRVhoisgAAAWo"]
[Thu Sep 17 15:10:29.695212 2026] [security2:error] [pid 955873:tid 956033] [client 35.244.43.255:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXRRFTPRVSLOsRVhoitAAAASg"]
[Thu Sep 17 15:10:29.793970 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/"] [unique_id "aqxXRRFTPRVSLOsRVhoitQAAAX0"]
[Thu Sep 17 15:10:29.818878 2026] [autoindex:error] [pid 955873:tid 956128] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:29.819331 2026] [security2:error] [pid 955873:tid 956128] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxXRRFTPRVSLOsRVhoitgAAAYc"]
[Thu Sep 17 15:10:30.021113 2026] [security2:error] [pid 955873:tid 956050] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxXRhFTPRVSLOsRVhoiwAAAATk"]
[Thu Sep 17 15:10:30.052944 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/"] [unique_id "aqxXRRFTPRVSLOsRVhoivQAAASw"]
[Thu Sep 17 15:10:30.219172 2026] [autoindex:error] [pid 955873:tid 956081] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:30.219714 2026] [security2:error] [pid 955873:tid 956081] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxXRhFTPRVSLOsRVhoiwgAAAVg"]
[Thu Sep 17 15:10:30.353549 2026] [security2:error] [pid 955873:tid 956114] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/codemirror/"] [unique_id "aqxXRhFTPRVSLOsRVhoixQAAAXk"]
[Thu Sep 17 15:10:30.424987 2026] [autoindex:error] [pid 955873:tid 956113] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:30.425500 2026] [security2:error] [pid 955873:tid 956113] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/customize/"] [unique_id "aqxXRhFTPRVSLOsRVhoixgAAAXg"]
[Thu Sep 17 15:10:30.427976 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXRhFTPRVSLOsRVhoixwAAAV0"]
[Thu Sep 17 15:10:30.509727 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/codemirror/"] [unique_id "aqxXRhFTPRVSLOsRVhoiygAAATs"]
[Thu Sep 17 15:10:30.651942 2026] [security2:error] [pid 955873:tid 956119] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/codemirror/wp-includes/js/"] [unique_id "aqxXRhFTPRVSLOsRVhoiywAAAX4"]
[Thu Sep 17 15:10:30.844235 2026] [autoindex:error] [pid 955873:tid 956092] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:30.844735 2026] [security2:error] [pid 955873:tid 956092] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxXRhFTPRVSLOsRVhoi2AAAAWM"]
[Thu Sep 17 15:10:31.023995 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRhFTPRVSLOsRVhoi1wAAARA"]
[Thu Sep 17 15:10:31.024022 2026] [security2:error] [pid 955873:tid 956009] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRhFTPRVSLOsRVhoi1wAAARA"]
[Thu Sep 17 15:10:31.032808 2026] [autoindex:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:31.033296 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/images/"] [unique_id "aqxXRxFTPRVSLOsRVhoi2wAAAXU"]
[Thu Sep 17 15:10:31.226725 2026] [autoindex:error] [pid 955873:tid 956047] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:31.227188 2026] [security2:error] [pid 955873:tid 956047] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/.well-known/"] [unique_id "aqxXRxFTPRVSLOsRVhoi3gAAATY"]
[Thu Sep 17 15:10:31.298033 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/crop/"] [unique_id "aqxXRxFTPRVSLOsRVhoi5QAAAQo"]
[Thu Sep 17 15:10:31.455407 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/crop/"] [unique_id "aqxXRxFTPRVSLOsRVhoi6gAAARo"]
[Thu Sep 17 15:10:31.511561 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi6AAAAXY"]
[Thu Sep 17 15:10:31.511590 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi6AAAAXY"]
[Thu Sep 17 15:10:31.618361 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/crop/wp-includes/js/"] [unique_id "aqxXRxFTPRVSLOsRVhoi7gAAARc"]
[Thu Sep 17 15:10:31.695652 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:42208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8AAAASs"]
[Thu Sep 17 15:10:31.706680 2026] [security2:error] [pid 955873:tid 956036] [client 154.190.208.131:42208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8AAAASs"]
[Thu Sep 17 15:10:31.784571 2026] [security2:error] [pid 955873:tid 956105] [client 195.2.78.191:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.78.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi9wAAAXA"], referer: https://melissa-gonzales.com/
[Thu Sep 17 15:10:31.794804 2026] [autoindex:error] [pid 955873:tid 956010] [client 43.164.133.138:59022] AH01276: Cannot serve directory /home3/stayatsc/public_html/wp-content/plugins/the-events-calendar/build/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.schillinghausmuenster.com/wp-content/plugins/the-events-calendar/build/js
[Thu Sep 17 15:10:31.807132 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8gAAAYU"]
[Thu Sep 17 15:10:31.807159 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi8gAAAYU"]
[Thu Sep 17 15:10:31.995867 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi9gAAAXQ"]
[Thu Sep 17 15:10:31.995894 2026] [security2:error] [pid 955873:tid 956109] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi9gAAAXQ"]
[Thu Sep 17 15:10:32.004426 2026] [autoindex:error] [pid 955873:tid 956084] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:32.004922 2026] [security2:error] [pid 955873:tid 956084] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxXRxFTPRVSLOsRVhoi_QAAAVs"]
[Thu Sep 17 15:10:32.147165 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/"] [unique_id "aqxXSBFTPRVSLOsRVhoi_wAAAWU"]
[Thu Sep 17 15:10:32.163955 2026] [security2:error] [pid 955873:tid 956063] [client 151.247.123.109:49355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.dieselrepair.shop"] [uri "/wp-login.php"] [unique_id "aqxXRxFTPRVSLOsRVhoi-wAAAUY"], referer: https://www.dieselrepair.shop/diesel-service-locator/
[Thu Sep 17 15:10:32.208030 2026] [cgid:error] [pid 955873:tid 956035] [client 82.102.18.118:35210] AH01265: stderr from /home2/frenchz8/public_html/website_beaa9689/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:10:32.208512 2026] [security2:error] [pid 955873:tid 956035] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/cgi-bin/"] [unique_id "aqxXSBFTPRVSLOsRVhojAAAAASo"]
[Thu Sep 17 15:10:32.388973 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/"] [unique_id "aqxXSBFTPRVSLOsRVhojAQAAARs"]
[Thu Sep 17 15:10:32.501996 2026] [security2:error] [pid 955873:tid 956055] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojBAAAAT4"]
[Thu Sep 17 15:10:32.502022 2026] [security2:error] [pid 955873:tid 956055] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojBAAAAT4"]
[Thu Sep 17 15:10:32.541320 2026] [security2:error] [pid 955873:tid 956033] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/wp-includes/js/"] [unique_id "aqxXSBFTPRVSLOsRVhojCgAAASg"]
[Thu Sep 17 15:10:32.579826 2026] [security2:error] [pid 955873:tid 956118] [client 4.240.114.86:50273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDAAAAX0"], referer: binance.com
[Thu Sep 17 15:10:32.847275 2026] [security2:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDwAAASw"]
[Thu Sep 17 15:10:32.847309 2026] [security2:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDwAAASw"]
[Thu Sep 17 15:10:32.946930 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDgAAATk"]
[Thu Sep 17 15:10:32.946956 2026] [security2:error] [pid 955873:tid 956050] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojDgAAATk"]
[Thu Sep 17 15:10:33.084991 2026] [security2:error] [pid 955873:tid 956098] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/development/"] [unique_id "aqxXSRFTPRVSLOsRVhojHAAAAWk"]
[Thu Sep 17 15:10:33.116101 2026] [security2:error] [pid 955873:tid 956005] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojGQAAAQw"]
[Thu Sep 17 15:10:33.116143 2026] [security2:error] [pid 955873:tid 956005] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojGQAAAQw"]
[Thu Sep 17 15:10:33.242172 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/development/"] [unique_id "aqxXSRFTPRVSLOsRVhojIAAAAU0"]
[Thu Sep 17 15:10:33.248811 2026] [security2:error] [pid 955873:tid 956073] [client 35.244.43.255:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXSRFTPRVSLOsRVhojIQAAAVA"]
[Thu Sep 17 15:10:33.267490 2026] [security2:error] [pid 955873:tid 956093] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXSBFTPRVSLOsRVhojFQAAAWQ"]
[Thu Sep 17 15:10:33.393003 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/development/wp-includes/js/dist/"] [unique_id "aqxXSRFTPRVSLOsRVhojKQAAAYE"]
[Thu Sep 17 15:10:33.411157 2026] [security2:error] [pid 955873:tid 956121] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojKAAAAYA"]
[Thu Sep 17 15:10:33.411177 2026] [security2:error] [pid 955873:tid 956121] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojKAAAAYA"]
[Thu Sep 17 15:10:33.701748 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLgAAAQ0"]
[Thu Sep 17 15:10:33.701785 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLgAAAQ0"]
[Thu Sep 17 15:10:33.737519 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLQAAAVY"]
[Thu Sep 17 15:10:33.737543 2026] [security2:error] [pid 955873:tid 956079] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojLQAAAVY"]
[Thu Sep 17 15:10:33.919847 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/"] [unique_id "aqxXSRFTPRVSLOsRVhojOAAAAR0"]
[Thu Sep 17 15:10:34.004123 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojNwAAAVk"]
[Thu Sep 17 15:10:34.004157 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojNwAAAVk"]
[Thu Sep 17 15:10:34.056167 2026] [security2:error] [pid 955873:tid 956015] [client 35.244.43.255:37312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXSRFTPRVSLOsRVhojOgAAARY"]
[Thu Sep 17 15:10:34.158152 2026] [security2:error] [pid 955873:tid 956010] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/"] [unique_id "aqxXShFTPRVSLOsRVhojOwAAARE"]
[Thu Sep 17 15:10:34.294041 2026] [security2:error] [pid 955873:tid 956039] [client 35.244.43.255:37312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/php-info.php"] [unique_id "aqxXShFTPRVSLOsRVhojPgAAAS4"]
[Thu Sep 17 15:10:34.296993 2026] [security2:error] [pid 955873:tid 956030] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/wp-includes/js/dist/"] [unique_id "aqxXShFTPRVSLOsRVhojPwAAASU"]
[Thu Sep 17 15:10:34.306384 2026] [security2:error] [pid 955873:tid 956089] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojPQAAAWA"]
[Thu Sep 17 15:10:34.306408 2026] [security2:error] [pid 955873:tid 956089] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojPQAAAWA"]
[Thu Sep 17 15:10:34.606811 2026] [security2:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRgAAAR8"]
[Thu Sep 17 15:10:34.606839 2026] [security2:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRgAAAR8"]
[Thu Sep 17 15:10:34.638273 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRQAAAUw"]
[Thu Sep 17 15:10:34.638298 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojRQAAAUw"]
[Thu Sep 17 15:10:34.653267 2026] [security2:error] [pid 955873:tid 956041] [client 5.189.145.112:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxXShFTPRVSLOsRVhojSAAAATA"], referer: binance.com
[Thu Sep 17 15:10:34.716423 2026] [security2:error] [pid 955873:tid 956094] [client 45.169.98.18:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXShFTPRVSLOsRVhojSQAAAWU"]
[Thu Sep 17 15:10:34.716530 2026] [security2:error] [pid 955873:tid 956094] [client 45.169.98.18:52849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXShFTPRVSLOsRVhojSQAAAWU"]
[Thu Sep 17 15:10:34.821482 2026] [security2:error] [pid 955873:tid 956020] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/a11y/"] [unique_id "aqxXShFTPRVSLOsRVhojSwAAARs"]
[Thu Sep 17 15:10:34.920730 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojSgAAAXc"]
[Thu Sep 17 15:10:34.920759 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXShFTPRVSLOsRVhojSgAAAXc"]
[Thu Sep 17 15:10:34.968968 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/a11y/index.js"] [unique_id "aqxXShFTPRVSLOsRVhojUQAAARI"]
[Thu Sep 17 15:10:35.053798 2026] [security2:error] [pid 955873:tid 956043] [client 35.244.43.255:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpversion.php"] [unique_id "aqxXSxFTPRVSLOsRVhojVQAAATI"]
[Thu Sep 17 15:10:35.108182 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/abilities/"] [unique_id "aqxXSxFTPRVSLOsRVhojVwAAAT0"]
[Thu Sep 17 15:10:35.215987 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojWAAAAWY"]
[Thu Sep 17 15:10:35.216017 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojWAAAAWY"]
[Thu Sep 17 15:10:35.392605 2026] [security2:error] [pid 955873:tid 956075] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/abilities/index.js"] [unique_id "aqxXSxFTPRVSLOsRVhojWQAAAVI"]
[Thu Sep 17 15:10:35.489422 2026] [security2:error] [pid 955873:tid 956128] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env"] [unique_id "aqxXSxFTPRVSLOsRVhojXwAAAYc"]
[Thu Sep 17 15:10:35.508929 2026] [security2:error] [pid 955873:tid 956052] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojXAAAATs"]
[Thu Sep 17 15:10:35.508963 2026] [security2:error] [pid 955873:tid 956052] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojXAAAATs"]
[Thu Sep 17 15:10:35.667946 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/"] [unique_id "aqxXSxFTPRVSLOsRVhojYgAAAQw"]
[Thu Sep 17 15:10:35.761457 2026] [security2:error] [pid 955873:tid 956049] [client 35.244.43.255:60702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/_phpinfo.php"] [unique_id "aqxXSxFTPRVSLOsRVhojZAAAATg"]
[Thu Sep 17 15:10:35.830887 2026] [security2:error] [pid 955873:tid 956091] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/"] [unique_id "aqxXSxFTPRVSLOsRVhojZQAAAWI"]
[Thu Sep 17 15:10:35.933146 2026] [security2:error] [pid 955873:tid 956032] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojZgAAASc"]
[Thu Sep 17 15:10:35.933171 2026] [security2:error] [pid 955873:tid 956032] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojZgAAASc"]
[Thu Sep 17 15:10:35.955745 2026] [security2:error] [pid 955873:tid 956092] [client 185.55.149.49:58533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXSxFTPRVSLOsRVhojaQAAAWM"]
[Thu Sep 17 15:10:35.955900 2026] [security2:error] [pid 955873:tid 956092] [client 185.55.149.49:58533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXSxFTPRVSLOsRVhojaQAAAWM"]
[Thu Sep 17 15:10:35.972704 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/wp-includes/js/dist/script-modules/"] [unique_id "aqxXSxFTPRVSLOsRVhojawAAAXU"]
[Thu Sep 17 15:10:36.096338 2026] [security2:error] [pid 955873:tid 956098] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXSxFTPRVSLOsRVhojYQAAAWk"]
[Thu Sep 17 15:10:36.230833 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbQAAAX8"]
[Thu Sep 17 15:10:36.230857 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbQAAAX8"]
[Thu Sep 17 15:10:36.331295 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbgAAATY"]
[Thu Sep 17 15:10:36.331318 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojbgAAATY"]
[Thu Sep 17 15:10:36.470488 2026] [security2:error] [pid 955873:tid 956045] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/"] [unique_id "aqxXTBFTPRVSLOsRVhojcwAAATQ"]
[Thu Sep 17 15:10:36.486344 2026] [security2:error] [pid 955873:tid 956006] [client 35.244.43.255:60718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXTBFTPRVSLOsRVhojdAAAAQ0"]
[Thu Sep 17 15:10:36.505004 2026] [security2:error] [pid 955873:tid 956088] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojcAAAAV8"]
[Thu Sep 17 15:10:36.505030 2026] [security2:error] [pid 955873:tid 956088] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojcAAAAV8"]
[Thu Sep 17 15:10:36.655724 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/"] [unique_id "aqxXTBFTPRVSLOsRVhojdQAAAU4"]
[Thu Sep 17 15:10:36.800609 2026] [security2:error] [pid 955873:tid 956101] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/wp-includes/js/dist/script-modules/block-editor/"] [unique_id "aqxXTBFTPRVSLOsRVhojeQAAAWw"]
[Thu Sep 17 15:10:36.812266 2026] [security2:error] [pid 955873:tid 956046] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojdwAAATU"]
[Thu Sep 17 15:10:36.812291 2026] [security2:error] [pid 955873:tid 956046] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojdwAAATU"]
[Thu Sep 17 15:10:36.845714 2026] [security2:error] [pid 955873:tid 956079] [client 156.192.234.52:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTBFTPRVSLOsRVhojegAAAVY"]
[Thu Sep 17 15:10:36.845848 2026] [security2:error] [pid 955873:tid 956079] [client 156.192.234.52:59947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTBFTPRVSLOsRVhojegAAAVY"]
[Thu Sep 17 15:10:37.108806 2026] [security2:error] [pid 955873:tid 956105] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojfwAAAXA"]
[Thu Sep 17 15:10:37.108845 2026] [security2:error] [pid 955873:tid 956105] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojfwAAAXA"]
[Thu Sep 17 15:10:37.135783 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojfQAAAT8"]
[Thu Sep 17 15:10:37.135810 2026] [security2:error] [pid 955873:tid 956056] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXTBFTPRVSLOsRVhojfQAAAT8"]
[Thu Sep 17 15:10:37.186213 2026] [security2:error] [pid 955873:tid 956072] [client 4.240.114.86:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxXTRFTPRVSLOsRVhojgwAAAU8"], referer: binance.com
[Thu Sep 17 15:10:37.217042 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:60730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/server-info.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhQAAAVk"]
[Thu Sep 17 15:10:37.277951 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/fit-text-frontend.min.asset.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhwAAATE"]
[Thu Sep 17 15:10:37.278063 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:36386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-editor/utils/fit-text-frontend.min.asset.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhwAAATE"]
[Thu Sep 17 15:10:37.419306 2026] [security2:error] [pid 955873:tid 956065] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojiAAAAUg"]
[Thu Sep 17 15:10:37.419329 2026] [security2:error] [pid 955873:tid 956065] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojiAAAAUg"]
[Thu Sep 17 15:10:37.562816 2026] [security2:error] [pid 955873:tid 956008] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXTRFTPRVSLOsRVhojjQAAAQ8"]
[Thu Sep 17 15:10:37.602515 2026] [security2:error] [pid 955873:tid 956023] [client 115.244.164.14:64080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjwAAAR4"]
[Thu Sep 17 15:10:37.602596 2026] [security2:error] [pid 955873:tid 956023] [client 115.244.164.14:64080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjwAAAR4"]
[Thu Sep 17 15:10:37.681454 2026] [security2:error] [pid 955873:tid 956057] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojhgAAAUA"]
[Thu Sep 17 15:10:37.693982 2026] [security2:error] [pid 955873:tid 956109] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjgAAAXQ"]
[Thu Sep 17 15:10:37.694017 2026] [security2:error] [pid 955873:tid 956109] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojjgAAAXQ"]
[Thu Sep 17 15:10:37.777562 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXTRFTPRVSLOsRVhojkAAAAWU"]
[Thu Sep 17 15:10:37.915306 2026] [security2:error] [pid 955873:tid 956099] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/wp-includes/js/dist/script-modules/"] [unique_id "aqxXTRFTPRVSLOsRVhojlAAAAWo"]
[Thu Sep 17 15:10:37.947489 2026] [security2:error] [pid 955873:tid 956035] [client 35.244.43.255:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/server-status.php"] [unique_id "aqxXTRFTPRVSLOsRVhojlQAAASo"]
[Thu Sep 17 15:10:37.978406 2026] [security2:error] [pid 955873:tid 956064] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojkQAAAUc"]
[Thu Sep 17 15:10:37.978436 2026] [security2:error] [pid 955873:tid 956064] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojkQAAAUc"]
[Thu Sep 17 15:10:38.051260 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:64948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXThFTPRVSLOsRVhojlwAAATA"]
[Thu Sep 17 15:10:38.051374 2026] [security2:error] [pid 955873:tid 956041] [client 186.105.232.15:64948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXThFTPRVSLOsRVhojlwAAATA"]
[Thu Sep 17 15:10:38.286211 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmQAAARI"]
[Thu Sep 17 15:10:38.286239 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmQAAARI"]
[Thu Sep 17 15:10:38.337445 2026] [security2:error] [pid 955873:tid 956021] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmwAAARw"]
[Thu Sep 17 15:10:38.337467 2026] [security2:error] [pid 955873:tid 956021] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojmwAAARw"]
[Thu Sep 17 15:10:38.429271 2026] [security2:error] [pid 955873:tid 956124] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/"] [unique_id "aqxXThFTPRVSLOsRVhojogAAAYM"]
[Thu Sep 17 15:10:38.476413 2026] [security2:error] [pid 955873:tid 956051] [client 172.86.81.177:51412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxXTRFTPRVSLOsRVhojiQAAATo"], referer: http://mail.thephoenixprojects.org/.git/config
[Thu Sep 17 15:10:38.589239 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/"] [unique_id "aqxXThFTPRVSLOsRVhojpAAAAXg"]
[Thu Sep 17 15:10:38.609431 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojowAAAWY"]
[Thu Sep 17 15:10:38.609456 2026] [security2:error] [pid 955873:tid 956095] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojowAAAWY"]
[Thu Sep 17 15:10:38.735058 2026] [security2:error] [pid 955873:tid 956005] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXThFTPRVSLOsRVhojqAAAAQw"]
[Thu Sep 17 15:10:38.845198 2026] [security2:error] [pid 955873:tid 956050] [client 35.244.43.255:60754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojpwAAATk"]
[Thu Sep 17 15:10:38.904651 2026] [security2:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojqgAAATg"]
[Thu Sep 17 15:10:38.904713 2026] [security2:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojqgAAATg"]
[Thu Sep 17 15:10:39.073072 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojrAAAASc"]
[Thu Sep 17 15:10:39.073102 2026] [security2:error] [pid 955873:tid 956032] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojrAAAASc"]
[Thu Sep 17 15:10:39.169352 2026] [security2:error] [pid 955873:tid 956053] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXThFTPRVSLOsRVhojqQAAATw"]
[Thu Sep 17 15:10:39.181097 2026] [security2:error] [pid 955873:tid 956107] [client 35.244.43.255:60754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsAAAAXI"]
[Thu Sep 17 15:10:39.210608 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsQAAAVA"]
[Thu Sep 17 15:10:39.210636 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsQAAAVA"]
[Thu Sep 17 15:10:39.217398 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/view.min.asset.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsgAAAWQ"]
[Thu Sep 17 15:10:39.217480 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:60412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/accordion/view.min.asset.php"] [unique_id "aqxXTxFTPRVSLOsRVhojsgAAAWQ"]
[Thu Sep 17 15:10:39.434412 2026] [security2:error] [pid 955873:tid 956059] [client 35.244.43.255:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXTxFTPRVSLOsRVhojtgAAAUI"]
[Thu Sep 17 15:10:39.515243 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojtQAAAQ0"]
[Thu Sep 17 15:10:39.515272 2026] [security2:error] [pid 955873:tid 956006] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojtQAAAQ0"]
[Thu Sep 17 15:10:39.554954 2026] [security2:error] [pid 955873:tid 956090] [client 143.244.57.120:60422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/"] [unique_id "aqxXTxFTPRVSLOsRVhojuQAAAWE"]
[Thu Sep 17 15:10:39.599388 2026] [security2:error] [pid 955873:tid 956013] [client 190.114.33.243:30544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojuAABFAI"]
[Thu Sep 17 15:10:39.725091 2026] [security2:error] [pid 955873:tid 956016] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/"] [unique_id "aqxXTxFTPRVSLOsRVhojvQAAARc"]
[Thu Sep 17 15:10:39.793333 2026] [security2:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojvgAAAWw"]
[Thu Sep 17 15:10:39.793354 2026] [security2:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojvgAAAWw"]
[Thu Sep 17 15:10:39.839608 2026] [security2:error] [pid 955873:tid 956015] [client 127.0.0.1:40822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXTxFTPRVSLOsRVhojxAAAARY"]
[Thu Sep 17 15:10:39.839608 2026] [security2:error] [pid 955873:tid 956036] [client 74.7.228.32:37262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tazbodywork.com"] [uri "/robots.txt"] [unique_id "aqxXTxFTPRVSLOsRVhojwwAAASs"]
[Thu Sep 17 15:10:39.863134 2026] [security2:error] [pid 955873:tid 956022] [client 143.244.57.120:60422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXTxFTPRVSLOsRVhojyAAAAR0"]
[Thu Sep 17 15:10:40.098843 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojzQAAAYY"]
[Thu Sep 17 15:10:40.098868 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXTxFTPRVSLOsRVhojzQAAAYY"]
[Thu Sep 17 15:10:40.173018 2026] [security2:error] [pid 955873:tid 956082] [client 35.244.43.255:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj0QAAAVk"]
[Thu Sep 17 15:10:40.219616 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhojzwAAAWg"]
[Thu Sep 17 15:10:40.219644 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhojzwAAAWg"]
[Thu Sep 17 15:10:40.356757 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/view.min.asset.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj1AAAARM"]
[Thu Sep 17 15:10:40.356873 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:60422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/file/view.min.asset.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj1AAAARM"]
[Thu Sep 17 15:10:40.401878 2026] [security2:error] [pid 955873:tid 956102] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj0gAAAW0"]
[Thu Sep 17 15:10:40.401909 2026] [security2:error] [pid 955873:tid 956102] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj0gAAAW0"]
[Thu Sep 17 15:10:40.637140 2026] [security2:error] [pid 955873:tid 956115] [client 143.244.57.120:56126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/"] [unique_id "aqxXUBFTPRVSLOsRVhoj2gAAAXo"]
[Thu Sep 17 15:10:40.697518 2026] [security2:error] [pid 955873:tid 956025] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj2QAAASA"]
[Thu Sep 17 15:10:40.697543 2026] [security2:error] [pid 955873:tid 956025] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj2QAAASA"]
[Thu Sep 17 15:10:40.808220 2026] [security2:error] [pid 955873:tid 956008] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj1QAAAQ8"]
[Thu Sep 17 15:10:40.809381 2026] [security2:error] [pid 955873:tid 956035] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/"] [unique_id "aqxXUBFTPRVSLOsRVhoj2wAAASo"]
[Thu Sep 17 15:10:40.891678 2026] [security2:error] [pid 955873:tid 956057] [client 35.244.43.255:60770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj3AAAAUA"]
[Thu Sep 17 15:10:40.949156 2026] [security2:error] [pid 955873:tid 956041] [client 143.244.57.120:56126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXUBFTPRVSLOsRVhoj3gAAATA"]
[Thu Sep 17 15:10:41.020545 2026] [security2:error] [pid 955873:tid 956129] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj3QAAAYg"]
[Thu Sep 17 15:10:41.020574 2026] [security2:error] [pid 955873:tid 956129] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXUBFTPRVSLOsRVhoj3QAAAYg"]
[Thu Sep 17 15:10:41.256400 2026] [autoindex:error] [pid 955873:tid 956118] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:41.257550 2026] [security2:error] [pid 955873:tid 956118] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/css/"] [unique_id "aqxXURFTPRVSLOsRVhoj4gAAAX0"]
[Thu Sep 17 15:10:41.282912 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj4QAAATM"]
[Thu Sep 17 15:10:41.282937 2026] [security2:error] [pid 955873:tid 956044] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj4QAAATM"]
[Thu Sep 17 15:10:41.421639 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/view.min.asset.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5AAAAXg"]
[Thu Sep 17 15:10:41.421755 2026] [security2:error] [pid 955873:tid 956113] [client 143.244.57.120:56126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/form/view.min.asset.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5AAAAXg"]
[Thu Sep 17 15:10:41.531566 2026] [security2:error] [pid 955873:tid 956051] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5QAAATo"]
[Thu Sep 17 15:10:41.531596 2026] [security2:error] [pid 955873:tid 956051] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj5QAAATo"]
[Thu Sep 17 15:10:41.613270 2026] [security2:error] [pid 955873:tid 956026] [client 35.244.43.255:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXURFTPRVSLOsRVhoj6gAAASE"]
[Thu Sep 17 15:10:41.712441 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:56136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/"] [unique_id "aqxXURFTPRVSLOsRVhoj7QAAASQ"]
[Thu Sep 17 15:10:41.719003 2026] [security2:error] [pid 955873:tid 956106] [client 212.200.27.78:37492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj6QABcRw"]
[Thu Sep 17 15:10:41.830693 2026] [security2:error] [pid 955873:tid 956038] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj7gAAAS0"]
[Thu Sep 17 15:10:41.830733 2026] [security2:error] [pid 955873:tid 956038] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj7gAAAS0"]
[Thu Sep 17 15:10:41.878572 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/"] [unique_id "aqxXURFTPRVSLOsRVhoj7wAAAW4"]
[Thu Sep 17 15:10:41.929549 2026] [security2:error] [pid 955873:tid 956009] [client 5.189.145.112:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxXURFTPRVSLOsRVhoj8AAAARA"], referer: binance.com
[Thu Sep 17 15:10:42.016874 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXUhFTPRVSLOsRVhoj9AAAAYQ"]
[Thu Sep 17 15:10:42.088365 2026] [autoindex:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.088879 2026] [security2:error] [pid 955873:tid 956049] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/maint/"] [unique_id "aqxXUhFTPRVSLOsRVhoj8wAAATg"]
[Thu Sep 17 15:10:42.137470 2026] [security2:error] [pid 955873:tid 956054] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXURFTPRVSLOsRVhoj7AAAAT0"]
[Thu Sep 17 15:10:42.219826 2026] [security2:error] [pid 955873:tid 956033] [client 154.190.208.131:41520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj-AAAASg"]
[Thu Sep 17 15:10:42.220165 2026] [security2:error] [pid 955873:tid 956033] [client 154.190.208.131:41520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj-AAAASg"]
[Thu Sep 17 15:10:42.328199 2026] [security2:error] [pid 955873:tid 956098] [client 35.244.43.255:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj-gAAAWk"]
[Thu Sep 17 15:10:42.335466 2026] [authz_core:error] [pid 955873:tid 956107] [client 82.102.18.118:35210] AH01630: client denied by server configuration: /home2/frenchz8/public_html/website_beaa9689/wp-content/plugins/akismet/
[Thu Sep 17 15:10:42.336806 2026] [security2:error] [pid 955873:tid 956107] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxXUhFTPRVSLOsRVhoj-wAAAXI"]
[Thu Sep 17 15:10:42.374333 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj9wAAAUs"]
[Thu Sep 17 15:10:42.374360 2026] [security2:error] [pid 955873:tid 956068] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUhFTPRVSLOsRVhoj9wAAAUs"]
[Thu Sep 17 15:10:42.518370 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/view.min.asset.php"] [unique_id "aqxXUhFTPRVSLOsRVhokAAAAAYE"]
[Thu Sep 17 15:10:42.518470 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/image/view.min.asset.php"] [unique_id "aqxXUhFTPRVSLOsRVhokAAAAAYE"]
[Thu Sep 17 15:10:42.525556 2026] [autoindex:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.526096 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/assets/"] [unique_id "aqxXUhFTPRVSLOsRVhoj_gAAAXU"]
[Thu Sep 17 15:10:42.718048 2026] [autoindex:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.718551 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxXUhFTPRVSLOsRVhokBQAAAXY"]
[Thu Sep 17 15:10:42.798637 2026] [security2:error] [pid 955873:tid 956117] [client 143.244.57.120:56152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/"] [unique_id "aqxXUhFTPRVSLOsRVhokBgAAAXw"]
[Thu Sep 17 15:10:42.921308 2026] [autoindex:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:42.922103 2026] [security2:error] [pid 955873:tid 956101] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxXUhFTPRVSLOsRVhokBwAAAWw"]
[Thu Sep 17 15:10:42.960107 2026] [security2:error] [pid 955873:tid 956105] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/"] [unique_id "aqxXUhFTPRVSLOsRVhokCAAAAXA"]
[Thu Sep 17 15:10:43.060943 2026] [security2:error] [pid 955873:tid 956079] [client 35.244.43.255:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXUxFTPRVSLOsRVhokDQAAAVY"]
[Thu Sep 17 15:10:43.099166 2026] [security2:error] [pid 955873:tid 956047] [client 143.244.57.120:56152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXUxFTPRVSLOsRVhokDgAAATY"]
[Thu Sep 17 15:10:43.261136 2026] [security2:error] [pid 955873:tid 956048] [client 4.240.114.86:56239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxXUxFTPRVSLOsRVhokEgAAATc"], referer: binance.com
[Thu Sep 17 15:10:43.366099 2026] [autoindex:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.366652 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxXUxFTPRVSLOsRVhokFwAAAVk"]
[Thu Sep 17 15:10:43.443726 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUxFTPRVSLOsRVhokEQAAAUk"]
[Thu Sep 17 15:10:43.443758 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXUxFTPRVSLOsRVhokEQAAAUk"]
[Thu Sep 17 15:10:43.444041 2026] [security2:error] [pid 955873:tid 956022] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXUxFTPRVSLOsRVhokCwAAAR0"]
[Thu Sep 17 15:10:43.541188 2026] [autoindex:error] [pid 955873:tid 956012] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.541753 2026] [security2:error] [pid 955873:tid 956012] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/js/"] [unique_id "aqxXUxFTPRVSLOsRVhokGgAAARM"]
[Thu Sep 17 15:10:43.617346 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:56152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/view.min.asset.php"] [unique_id "aqxXUxFTPRVSLOsRVhokHAAAAVs"]
[Thu Sep 17 15:10:43.617496 2026] [security2:error] [pid 955873:tid 956084] [client 143.244.57.120:56152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/view.min.asset.php"] [unique_id "aqxXUxFTPRVSLOsRVhokHAAAAVs"]
[Thu Sep 17 15:10:43.736263 2026] [autoindex:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.736736 2026] [security2:error] [pid 955873:tid 956024] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxXUxFTPRVSLOsRVhokHQAAAR8"]
[Thu Sep 17 15:10:43.898441 2026] [security2:error] [pid 955873:tid 956011] [client 143.244.57.120:56164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/"] [unique_id "aqxXUxFTPRVSLOsRVhokIQAAARI"]
[Thu Sep 17 15:10:43.949505 2026] [security2:error] [pid 955873:tid 956030] [client 35.244.43.255:60806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXUxFTPRVSLOsRVhokIwAAASU"]
[Thu Sep 17 15:10:43.955459 2026] [autoindex:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:43.956220 2026] [security2:error] [pid 955873:tid 956037] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxXUxFTPRVSLOsRVhokIgAAASw"]
[Thu Sep 17 15:10:44.033276 2026] [security2:error] [pid 955873:tid 956052] [client 3.82.141.143:54918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php~"] [unique_id "aqxXVBFTPRVSLOsRVhokMgAAATs"]
[Thu Sep 17 15:10:44.033368 2026] [security2:error] [pid 955873:tid 956051] [client 3.82.141.143:54900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php"] [unique_id "aqxXVBFTPRVSLOsRVhokMAAAATo"]
[Thu Sep 17 15:10:44.033943 2026] [security2:error] [pid 955873:tid 956026] [client 3.82.141.143:54904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php.save"] [unique_id "aqxXVBFTPRVSLOsRVhokMwAAASE"]
[Thu Sep 17 15:10:44.034751 2026] [security2:error] [pid 955873:tid 956038] [client 3.82.141.143:54912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXVBFTPRVSLOsRVhokNgAAAS0"]
[Thu Sep 17 15:10:44.036462 2026] [security2:error] [pid 955873:tid 956029] [client 3.82.141.143:54736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/config.php"] [unique_id "aqxXVBFTPRVSLOsRVhokOAAAASQ"]
[Thu Sep 17 15:10:44.046944 2026] [security2:error] [pid 955873:tid 956096] [client 3.82.141.143:54902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.pabellondealtatecnologia.com"] [uri "/wp-config.php.old"] [unique_id "aqxXVBFTPRVSLOsRVhokSAAAAWc"]
[Thu Sep 17 15:10:44.065169 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/"] [unique_id "aqxXVBFTPRVSLOsRVhokOQAAAQo"]
[Thu Sep 17 15:10:44.143415 2026] [autoindex:error] [pid 955873:tid 956083] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:44.143925 2026] [security2:error] [pid 955873:tid 956083] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxXVBFTPRVSLOsRVhokVQAAAVo"]
[Thu Sep 17 15:10:44.277403 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:56164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVBFTPRVSLOsRVhokVgAAAUE"]
[Thu Sep 17 15:10:44.503107 2026] [security2:error] [pid 955873:tid 956064] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env.bak"] [unique_id "aqxXVBFTPRVSLOsRVhokWQAAAUc"]
[Thu Sep 17 15:10:44.534001 2026] [security2:error] [pid 955873:tid 956078] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokVwAAAVU"]
[Thu Sep 17 15:10:44.534023 2026] [security2:error] [pid 955873:tid 956078] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokVwAAAVU"]
[Thu Sep 17 15:10:44.636167 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokWAAAAUY"]
[Thu Sep 17 15:10:44.636214 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokWAAAAUY"]
[Thu Sep 17 15:10:44.662118 2026] [security2:error] [pid 955873:tid 956094] [client 35.244.43.255:47332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXVBFTPRVSLOsRVhokYwAAAWU"]
[Thu Sep 17 15:10:44.726889 2026] [autoindex:error] [pid 955873:tid 956076] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:44.727445 2026] [security2:error] [pid 955873:tid 956076] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxXVBFTPRVSLOsRVhokZAAAAVM"]
[Thu Sep 17 15:10:44.773498 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:56164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/view.min.asset.php"] [unique_id "aqxXVBFTPRVSLOsRVhokZQAAARo"]
[Thu Sep 17 15:10:44.773604 2026] [security2:error] [pid 955873:tid 956019] [client 143.244.57.120:56164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/playlist/view.min.asset.php"] [unique_id "aqxXVBFTPRVSLOsRVhokZQAAARo"]
[Thu Sep 17 15:10:44.786934 2026] [security2:error] [pid 955873:tid 956044] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env.backup"] [unique_id "aqxXVBFTPRVSLOsRVhokZgAAATM"]
[Thu Sep 17 15:10:44.951703 2026] [autoindex:error] [pid 955873:tid 956093] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:44.952208 2026] [security2:error] [pid 955873:tid 956093] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxXVBFTPRVSLOsRVhokZwAAAWQ"]
[Thu Sep 17 15:10:45.062221 2026] [security2:error] [pid 955873:tid 956096] [client 143.244.57.120:56172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/"] [unique_id "aqxXVRFTPRVSLOsRVhokbQAAAWc"]
[Thu Sep 17 15:10:45.128541 2026] [autoindex:error] [pid 955873:tid 956003] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.129029 2026] [security2:error] [pid 955873:tid 956003] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxXVRFTPRVSLOsRVhokbgAAAQo"]
[Thu Sep 17 15:10:45.170329 2026] [security2:error] [pid 955873:tid 956080] [client 45.169.98.18:53403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVRFTPRVSLOsRVhokcAAAAVc"]
[Thu Sep 17 15:10:45.170429 2026] [security2:error] [pid 955873:tid 956080] [client 45.169.98.18:53403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVRFTPRVSLOsRVhokcAAAAVc"]
[Thu Sep 17 15:10:45.238761 2026] [security2:error] [pid 955873:tid 956014] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/"] [unique_id "aqxXVRFTPRVSLOsRVhokcwAAARU"]
[Thu Sep 17 15:10:45.379163 2026] [security2:error] [pid 955873:tid 956095] [client 143.244.57.120:56172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVRFTPRVSLOsRVhokeAAAAWY"]
[Thu Sep 17 15:10:45.381782 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php~"] [unique_id "aqxXVRFTPRVSLOsRVhokeQAAAXg"]
[Thu Sep 17 15:10:45.409503 2026] [autoindex:error] [pid 955873:tid 956079] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.410054 2026] [security2:error] [pid 955873:tid 956079] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxXVRFTPRVSLOsRVhokegAAAVY"]
[Thu Sep 17 15:10:45.425528 2026] [security2:error] [pid 955873:tid 956090] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXVBFTPRVSLOsRVhokaAAAAWE"]
[Thu Sep 17 15:10:45.633224 2026] [autoindex:error] [pid 955873:tid 956054] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.633772 2026] [security2:error] [pid 955873:tid 956054] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxXVRFTPRVSLOsRVhokgQAAAT0"]
[Thu Sep 17 15:10:45.739479 2026] [security2:error] [pid 955873:tid 956089] [client 169.58.197.253:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxXVRFTPRVSLOsRVhokgwAAAWA"], referer: binance.com
[Thu Sep 17 15:10:45.772551 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVRFTPRVSLOsRVhokfwAAAYU"]
[Thu Sep 17 15:10:45.772575 2026] [security2:error] [pid 955873:tid 956126] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVRFTPRVSLOsRVhokfwAAAYU"]
[Thu Sep 17 15:10:45.773982 2026] [security2:error] [pid 955873:tid 956123] [client 45.18.242.176:36767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXVRFTPRVSLOsRVhokggABgms"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:10:45.841111 2026] [autoindex:error] [pid 955873:tid 956067] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:45.841611 2026] [security2:error] [pid 955873:tid 956067] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxXVRFTPRVSLOsRVhokhgAAAUo"]
[Thu Sep 17 15:10:45.916930 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:56172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/view.min.asset.php"] [unique_id "aqxXVRFTPRVSLOsRVhokigAAAUE"]
[Thu Sep 17 15:10:45.917034 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:56172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/query/view.min.asset.php"] [unique_id "aqxXVRFTPRVSLOsRVhokigAAAUE"]
[Thu Sep 17 15:10:46.072653 2026] [autoindex:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:46.073174 2026] [security2:error] [pid 955873:tid 956039] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxXVhFTPRVSLOsRVhokkgAAAS4"]
[Thu Sep 17 15:10:46.109617 2026] [security2:error] [pid 955873:tid 956075] [client 35.244.43.255:47346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/info.php.bak"] [unique_id "aqxXVhFTPRVSLOsRVhoklgAAAVI"]
[Thu Sep 17 15:10:46.197951 2026] [security2:error] [pid 955873:tid 956097] [client 143.244.57.120:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/"] [unique_id "aqxXVhFTPRVSLOsRVhokmQAAAWg"]
[Thu Sep 17 15:10:46.341199 2026] [autoindex:error] [pid 955873:tid 956023] [client 82.102.18.118:35210] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:46.341679 2026] [security2:error] [pid 955873:tid 956023] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxXVhFTPRVSLOsRVhokmwAAAR4"]
[Thu Sep 17 15:10:46.349737 2026] [security2:error] [pid 955873:tid 956114] [client 34.32.117.146:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env.old"] [unique_id "aqxXVhFTPRVSLOsRVhoknQAAAXk"]
[Thu Sep 17 15:10:46.355815 2026] [security2:error] [pid 955873:tid 956112] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/"] [unique_id "aqxXVhFTPRVSLOsRVhoknAAAAXc"]
[Thu Sep 17 15:10:46.499751 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVhFTPRVSLOsRVhokngAAAS8"]
[Thu Sep 17 15:10:46.641134 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokoQAAAYY"]
[Thu Sep 17 15:10:46.641164 2026] [security2:error] [pid 955873:tid 956127] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokoQAAAYY"]
[Thu Sep 17 15:10:46.648564 2026] [security2:error] [pid 955873:tid 956042] [client 185.55.149.49:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqwAAATE"]
[Thu Sep 17 15:10:46.648680 2026] [security2:error] [pid 955873:tid 956042] [client 185.55.149.49:59179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqwAAATE"]
[Thu Sep 17 15:10:46.843496 2026] [security2:error] [pid 955873:tid 956076] [client 35.244.43.255:47362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXVhFTPRVSLOsRVhoksAAAAVM"]
[Thu Sep 17 15:10:46.868753 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqgAAARw"]
[Thu Sep 17 15:10:46.868781 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqgAAARw"]
[Thu Sep 17 15:10:46.940132 2026] [security2:error] [pid 955873:tid 956011] [client 82.102.18.118:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokrwAAARI"]
[Thu Sep 17 15:10:46.940155 2026] [security2:error] [pid 955873:tid 956011] [client 82.102.18.118:35210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokrwAAARI"]
[Thu Sep 17 15:10:47.007082 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:56178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/view.min.asset.php"] [unique_id "aqxXVxFTPRVSLOsRVhokswAAATo"]
[Thu Sep 17 15:10:47.007224 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/view.min.asset.php"] [unique_id "aqxXVxFTPRVSLOsRVhokswAAATo"]
[Thu Sep 17 15:10:47.070297 2026] [security2:error] [pid 955873:tid 956020] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokqQAAARs"]
[Thu Sep 17 15:10:47.110727 2026] [security2:error] [pid 955873:tid 956013] [client 127.0.0.1:10392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxXVxFTPRVSLOsRVhoktgAAARQ"]
[Thu Sep 17 15:10:47.110733 2026] [security2:error] [pid 955873:tid 956029] [client 74.7.244.9:43658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.newyearworks.com"] [uri "/robots.txt"] [unique_id "aqxXVxFTPRVSLOsRVhoktAAAASQ"]
[Thu Sep 17 15:10:47.290801 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:56180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/"] [unique_id "aqxXVxFTPRVSLOsRVhokuwAAAS0"]
[Thu Sep 17 15:10:47.396995 2026] [security2:error] [pid 955873:tid 956028] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhokugAAASM"]
[Thu Sep 17 15:10:47.397023 2026] [security2:error] [pid 955873:tid 956028] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhokugAAASM"]
[Thu Sep 17 15:10:47.399559 2026] [security2:error] [pid 955873:tid 956052] [client 156.192.234.52:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVxFTPRVSLOsRVhokwwAAATs"]
[Thu Sep 17 15:10:47.399688 2026] [security2:error] [pid 955873:tid 956052] [client 156.192.234.52:60558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXVxFTPRVSLOsRVhokwwAAATs"]
[Thu Sep 17 15:10:47.451205 2026] [security2:error] [pid 955873:tid 956081] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/"] [unique_id "aqxXVxFTPRVSLOsRVhokxQAAAVg"]
[Thu Sep 17 15:10:47.568034 2026] [security2:error] [pid 955873:tid 956086] [client 35.244.43.255:47376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXVxFTPRVSLOsRVhokzgAAAV0"]
[Thu Sep 17 15:10:47.593010 2026] [security2:error] [pid 955873:tid 956004] [client 143.244.57.120:56180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/wp-includes/js/dist/script-modules/block-library/"] [unique_id "aqxXVxFTPRVSLOsRVhokzwAAAQs"]
[Thu Sep 17 15:10:47.839522 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0AAAAVA"]
[Thu Sep 17 15:10:47.839553 2026] [security2:error] [pid 955873:tid 956073] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0AAAAVA"]
[Thu Sep 17 15:10:47.922222 2026] [security2:error] [pid 955873:tid 956097] [client 45.18.242.176:44589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0wABaDA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=3&hideliu=1&limit=100&target=VOC_Company&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:10:47.986357 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0QAAAYQ"]
[Thu Sep 17 15:10:47.986382 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0QAAAYQ"]
[Thu Sep 17 15:10:48.119800 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok2wAAAXo"]
[Thu Sep 17 15:10:48.119833 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok2wAAAXo"]
[Thu Sep 17 15:10:48.126314 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/view.min.asset.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4QAAAYE"]
[Thu Sep 17 15:10:48.126416 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:56180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/block-library/tabs/view.min.asset.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4QAAAYE"]
[Thu Sep 17 15:10:48.181484 2026] [security2:error] [pid 955873:tid 956024] [client 115.244.164.14:64718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4gAAAR8"]
[Thu Sep 17 15:10:48.181584 2026] [security2:error] [pid 955873:tid 956024] [client 115.244.164.14:64718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWBFTPRVSLOsRVhok4gAAAR8"]
[Thu Sep 17 15:10:48.215926 2026] [security2:error] [pid 955873:tid 956102] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhok0gAAAW0"]
[Thu Sep 17 15:10:48.305866 2026] [security2:error] [pid 955873:tid 956074] [client 35.244.43.255:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXWBFTPRVSLOsRVhok5QAAAVE"]
[Thu Sep 17 15:10:48.413037 2026] [security2:error] [pid 955873:tid 956041] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok5AAAATA"]
[Thu Sep 17 15:10:48.413061 2026] [security2:error] [pid 955873:tid 956041] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok5AAAATA"]
[Thu Sep 17 15:10:48.415814 2026] [security2:error] [pid 955873:tid 956051] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/boot/"] [unique_id "aqxXWBFTPRVSLOsRVhok7QAAATo"]
[Thu Sep 17 15:10:48.573358 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/boot/index.js"] [unique_id "aqxXWBFTPRVSLOsRVhok9QAAASQ"]
[Thu Sep 17 15:10:48.736089 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok-AAAAX8"]
[Thu Sep 17 15:10:48.736126 2026] [security2:error] [pid 955873:tid 956120] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok-AAAAX8"]
[Thu Sep 17 15:10:48.852573 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/connectors/"] [unique_id "aqxXWBFTPRVSLOsRVhok_AAAAU4"]
[Thu Sep 17 15:10:48.999795 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/connectors/index.js"] [unique_id "aqxXWBFTPRVSLOsRVhok_wAAAYI"]
[Thu Sep 17 15:10:49.025142 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok_gAAAYU"]
[Thu Sep 17 15:10:49.025174 2026] [security2:error] [pid 955873:tid 956126] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok_gAAAYU"]
[Thu Sep 17 15:10:49.036407 2026] [security2:error] [pid 955873:tid 956028] [client 35.244.43.255:47392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXWRFTPRVSLOsRVholBQAAASM"]
[Thu Sep 17 15:10:49.050057 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:49163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWRFTPRVSLOsRVholBgAAAWs"]
[Thu Sep 17 15:10:49.050802 2026] [security2:error] [pid 955873:tid 956100] [client 186.105.232.15:49163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXWRFTPRVSLOsRVholBgAAAWs"]
[Thu Sep 17 15:10:49.151735 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/content-types/"] [unique_id "aqxXWRFTPRVSLOsRVholCwAAAV4"]
[Thu Sep 17 15:10:49.318705 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholEAAAAXo"]
[Thu Sep 17 15:10:49.318741 2026] [security2:error] [pid 955873:tid 956115] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholEAAAAXo"]
[Thu Sep 17 15:10:49.351196 2026] [security2:error] [pid 955873:tid 956015] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXWBFTPRVSLOsRVhok_QAAARY"]
[Thu Sep 17 15:10:49.443525 2026] [security2:error] [pid 955873:tid 956103] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/content-types/index.js"] [unique_id "aqxXWRFTPRVSLOsRVholEwAAAW4"]
[Thu Sep 17 15:10:49.624974 2026] [security2:error] [pid 955873:tid 956010] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholGAAAARE"]
[Thu Sep 17 15:10:49.624993 2026] [security2:error] [pid 955873:tid 956010] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholGAAAARE"]
[Thu Sep 17 15:10:49.664688 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/core-abilities/"] [unique_id "aqxXWRFTPRVSLOsRVholJAAAARw"]
[Thu Sep 17 15:10:49.765302 2026] [security2:error] [pid 955873:tid 956044] [client 35.244.43.255:47408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXWRFTPRVSLOsRVholJQAAATM"]
[Thu Sep 17 15:10:49.818607 2026] [security2:error] [pid 955873:tid 956077] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/core-abilities/index.js"] [unique_id "aqxXWRFTPRVSLOsRVholJgAAAVQ"]
[Thu Sep 17 15:10:49.951262 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholJwAAAVk"]
[Thu Sep 17 15:10:49.951298 2026] [security2:error] [pid 955873:tid 956082] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWRFTPRVSLOsRVholJwAAAVk"]
[Thu Sep 17 15:10:50.022599 2026] [security2:error] [pid 955873:tid 956080] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/dashboard-init/"] [unique_id "aqxXWhFTPRVSLOsRVholLQAAAVc"]
[Thu Sep 17 15:10:50.177708 2026] [security2:error] [pid 955873:tid 956093] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/dashboard-init/index.js"] [unique_id "aqxXWhFTPRVSLOsRVholMAAAAWQ"]
[Thu Sep 17 15:10:50.227212 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholLwAAAXc"]
[Thu Sep 17 15:10:50.227243 2026] [security2:error] [pid 955873:tid 956112] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholLwAAAXc"]
[Thu Sep 17 15:10:50.265030 2026] [security2:error] [pid 955873:tid 956118] [client 74.7.230.38:37302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXVhFTPRVSLOsRVhokrgABfR0"]
[Thu Sep 17 15:10:50.285461 2026] [security2:error] [pid 955873:tid 956083] [client 5.189.145.112:64219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxXWhFTPRVSLOsRVholMQAAAVo"], referer: binance.com
[Thu Sep 17 15:10:50.329316 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/edit-site-init/"] [unique_id "aqxXWhFTPRVSLOsRVholMgAAASw"]
[Thu Sep 17 15:10:50.457203 2026] [autoindex:error] [pid 955873:tid 956036] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:50.457760 2026] [security2:error] [pid 955873:tid 956036] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/images/"] [unique_id "aqxXWhFTPRVSLOsRVholMwAAASs"]
[Thu Sep 17 15:10:50.476811 2026] [security2:error] [pid 955873:tid 956071] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/edit-site-init/index.js"] [unique_id "aqxXWhFTPRVSLOsRVholNAAAAU4"]
[Thu Sep 17 15:10:50.488478 2026] [security2:error] [pid 955873:tid 956038] [client 35.244.43.255:47414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXWhFTPRVSLOsRVholNQAAAS0"]
[Thu Sep 17 15:10:50.628350 2026] [security2:error] [pid 955873:tid 956086] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity-router/"] [unique_id "aqxXWhFTPRVSLOsRVholOwAAAV0"]
[Thu Sep 17 15:10:50.640040 2026] [autoindex:error] [pid 955873:tid 956048] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:50.640580 2026] [security2:error] [pid 955873:tid 956048] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxXWhFTPRVSLOsRVholOgAAATc"]
[Thu Sep 17 15:10:50.779845 2026] [security2:error] [pid 955873:tid 956028] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity-router/index.js"] [unique_id "aqxXWhFTPRVSLOsRVholPgAAASM"]
[Thu Sep 17 15:10:50.822534 2026] [security2:error] [pid 955873:tid 956079] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholQAAAAVY"]
[Thu Sep 17 15:10:50.929243 2026] [security2:error] [pid 955873:tid 956100] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity/"] [unique_id "aqxXWhFTPRVSLOsRVholQQAAAWs"]
[Thu Sep 17 15:10:51.057311 2026] [security2:error] [pid 955873:tid 956050] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholOQAAATk"]
[Thu Sep 17 15:10:51.097143 2026] [security2:error] [pid 955873:tid 956073] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/interactivity/index.js"] [unique_id "aqxXWxFTPRVSLOsRVholRgAAAVA"]
[Thu Sep 17 15:10:51.135487 2026] [security2:error] [pid 955873:tid 956009] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholQwAAARA"]
[Thu Sep 17 15:10:51.135512 2026] [security2:error] [pid 955873:tid 956009] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholQwAAARA"]
[Thu Sep 17 15:10:51.219216 2026] [security2:error] [pid 955873:tid 956113] [client 35.244.43.255:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXWxFTPRVSLOsRVholSQAAAXg"]
[Thu Sep 17 15:10:51.245629 2026] [security2:error] [pid 955873:tid 956125] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/latex-to-mathml/"] [unique_id "aqxXWxFTPRVSLOsRVholSgAAAYQ"]
[Thu Sep 17 15:10:51.247365 2026] [security2:error] [pid 955873:tid 956091] [client 66.248.203.10:19236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxXWhFTPRVSLOsRVholPQAAAWI"], referer: https://sucuri.net
[Thu Sep 17 15:10:51.401037 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/latex-to-mathml/index.js"] [unique_id "aqxXWxFTPRVSLOsRVholTgAAAUo"]
[Thu Sep 17 15:10:51.530305 2026] [security2:error] [pid 955873:tid 956124] [client 74.7.244.7:58828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.alexandernovelist.com"] [uri "/index.php"] [unique_id "aqxXVxFTPRVSLOsRVhokvwABgzo"]
[Thu Sep 17 15:10:51.554233 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/lazy-editor/"] [unique_id "aqxXWxFTPRVSLOsRVholVAAAAS8"]
[Thu Sep 17 15:10:51.744544 2026] [security2:error] [pid 955873:tid 956056] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholVwAAAT8"]
[Thu Sep 17 15:10:51.744575 2026] [security2:error] [pid 955873:tid 956056] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholVwAAAT8"]
[Thu Sep 17 15:10:51.747624 2026] [security2:error] [pid 955873:tid 956088] [client 192.175.54.146:48002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxXWxFTPRVSLOsRVholWAAAAV8"]
[Thu Sep 17 15:10:51.756357 2026] [security2:error] [pid 955873:tid 956024] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/lazy-editor/index.js"] [unique_id "aqxXWxFTPRVSLOsRVholWQAAAR8"]
[Thu Sep 17 15:10:51.900631 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/registry.php"] [unique_id "aqxXWxFTPRVSLOsRVholWwAAAQo"]
[Thu Sep 17 15:10:51.900769 2026] [security2:error] [pid 955873:tid 956003] [client 143.244.57.120:56182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/registry.php"] [unique_id "aqxXWxFTPRVSLOsRVholWwAAAQo"]
[Thu Sep 17 15:10:51.947513 2026] [security2:error] [pid 955873:tid 956065] [client 35.244.43.255:47444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXWxFTPRVSLOsRVholXAAAAUg"]
[Thu Sep 17 15:10:52.179772 2026] [security2:error] [pid 955873:tid 956069] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/route/"] [unique_id "aqxXXBFTPRVSLOsRVholYgAAAUw"]
[Thu Sep 17 15:10:52.304091 2026] [security2:error] [pid 955873:tid 956019] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholYwAAARo"]
[Thu Sep 17 15:10:52.304119 2026] [security2:error] [pid 955873:tid 956019] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholYwAAARo"]
[Thu Sep 17 15:10:52.333404 2026] [security2:error] [pid 955873:tid 956007] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/route/index.js"] [unique_id "aqxXXBFTPRVSLOsRVholZwAAAQ4"]
[Thu Sep 17 15:10:52.435338 2026] [security2:error] [pid 955873:tid 956094] [client 206.81.7.52:36624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.timalba.com"] [uri "/.env"] [unique_id "aqxXXBFTPRVSLOsRVholaAAAAWU"]
[Thu Sep 17 15:10:52.476009 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/"] [unique_id "aqxXXBFTPRVSLOsRVholbAAAAYA"]
[Thu Sep 17 15:10:52.611972 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholbgAAAXY"]
[Thu Sep 17 15:10:52.611997 2026] [security2:error] [pid 955873:tid 956111] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholbgAAAXY"]
[Thu Sep 17 15:10:52.641339 2026] [security2:error] [pid 955873:tid 956054] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/"] [unique_id "aqxXXBFTPRVSLOsRVholcgAAAT0"]
[Thu Sep 17 15:10:52.700155 2026] [security2:error] [pid 955873:tid 956017] [client 35.244.43.255:47450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXXBFTPRVSLOsRVholdQAAARg"]
[Thu Sep 17 15:10:52.786045 2026] [security2:error] [pid 955873:tid 956037] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/wp-includes/js/dist/script-modules/"] [unique_id "aqxXXBFTPRVSLOsRVholdgAAASw"]
[Thu Sep 17 15:10:52.906462 2026] [security2:error] [pid 955873:tid 956020] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholaQAAARs"]
[Thu Sep 17 15:10:53.152410 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholeQAAAS0"]
[Thu Sep 17 15:10:53.152441 2026] [security2:error] [pid 955873:tid 956038] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholeQAAAS0"]
[Thu Sep 17 15:10:53.189812 2026] [security2:error] [pid 955873:tid 956085] [client 154.190.208.131:42238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXRFTPRVSLOsRVholfgAAAVw"]
[Thu Sep 17 15:10:53.189966 2026] [security2:error] [pid 955873:tid 956085] [client 154.190.208.131:42238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXRFTPRVSLOsRVholfgAAAVw"]
[Thu Sep 17 15:10:53.307343 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/loader.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholfwAAAQ0"]
[Thu Sep 17 15:10:53.307464 2026] [security2:error] [pid 955873:tid 956006] [client 143.244.57.120:51832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/loader.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholfwAAAQ0"]
[Thu Sep 17 15:10:53.400448 2026] [security2:error] [pid 955873:tid 956036] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxXXBFTPRVSLOsRVholeAAAASs"]
[Thu Sep 17 15:10:53.418123 2026] [security2:error] [pid 955873:tid 956108] [client 35.244.43.255:47458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXXRFTPRVSLOsRVholgQAAAXM"]
[Thu Sep 17 15:10:53.419304 2026] [security2:error] [pid 955873:tid 956092] [client 162.241.226.11:17502] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXXRFTPRVSLOsRVholgAAAAWM"]
[Thu Sep 17 15:10:53.587171 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:51846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/worker.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholhQAAAUk"]
[Thu Sep 17 15:10:53.587325 2026] [security2:error] [pid 955873:tid 956066] [client 143.244.57.120:51846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/video-conversion/worker.min.asset.php"] [unique_id "aqxXXRFTPRVSLOsRVholhQAAAUk"]
[Thu Sep 17 15:10:53.899933 2026] [security2:error] [pid 955873:tid 956055] [client 143.244.57.120:51850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/"] [unique_id "aqxXXRFTPRVSLOsRVholiQAAAT4"]
[Thu Sep 17 15:10:54.078807 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/"] [unique_id "aqxXXhFTPRVSLOsRVholkQAAAUo"]
[Thu Sep 17 15:10:54.122247 2026] [security2:error] [pid 955873:tid 956091] [client 35.244.43.255:47474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXXhFTPRVSLOsRVhollAAAAWI"]
[Thu Sep 17 15:10:54.264918 2026] [security2:error] [pid 955873:tid 956068] [client 82.102.18.118:57262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholkwAAAUs"]
[Thu Sep 17 15:10:54.266640 2026] [security2:error] [pid 955873:tid 956023] [client 143.244.57.120:51850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/wp-includes/js/dist/script-modules/"] [unique_id "aqxXXhFTPRVSLOsRVholmgAAAR4"]
[Thu Sep 17 15:10:54.558835 2026] [security2:error] [pid 955873:tid 956102] [client 105.154.201.209:40178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholnwABbQU"]
[Thu Sep 17 15:10:54.560540 2026] [security2:error] [pid 955873:tid 956126] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholkgAAAYU"]
[Thu Sep 17 15:10:54.620615 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholngAAAV8"]
[Thu Sep 17 15:10:54.620643 2026] [security2:error] [pid 955873:tid 956088] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholngAAAV8"]
[Thu Sep 17 15:10:54.760850 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:51850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/loader.min.asset.php"] [unique_id "aqxXXhFTPRVSLOsRVholqAAAAYY"]
[Thu Sep 17 15:10:54.760966 2026] [security2:error] [pid 955873:tid 956127] [client 143.244.57.120:51850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/loader.min.asset.php"] [unique_id "aqxXXhFTPRVSLOsRVholqAAAAYY"]
[Thu Sep 17 15:10:54.834769 2026] [security2:error] [pid 955873:tid 956114] [client 35.244.43.255:45776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXXhFTPRVSLOsRVholqgAAAXk"]
[Thu Sep 17 15:10:55.061478 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/worker.min.asset.php"] [unique_id "aqxXXxFTPRVSLOsRVholsQAAAYA"]
[Thu Sep 17 15:10:55.061591 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:51856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/vips/worker.min.asset.php"] [unique_id "aqxXXxFTPRVSLOsRVholsQAAAYA"]
[Thu Sep 17 15:10:55.091468 2026] [security2:error] [pid 955873:tid 956027] [client 82.102.18.118:57264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXXxFTPRVSLOsRVholswAAASI"]
[Thu Sep 17 15:10:55.091598 2026] [security2:error] [pid 955873:tid 956027] [client 82.102.18.118:57264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXXxFTPRVSLOsRVholswAAASI"]
[Thu Sep 17 15:10:55.372501 2026] [security2:error] [pid 955873:tid 956082] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/workflow/"] [unique_id "aqxXXxFTPRVSLOsRVholtwAAAVk"]
[Thu Sep 17 15:10:55.478299 2026] [security2:error] [pid 955873:tid 956030] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxXXxFTPRVSLOsRVholtgAAASU"]
[Thu Sep 17 15:10:55.530761 2026] [security2:error] [pid 955873:tid 956058] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/script-modules/workflow/index.js"] [unique_id "aqxXXxFTPRVSLOsRVholvQAAAUE"]
[Thu Sep 17 15:10:55.576255 2026] [security2:error] [pid 955873:tid 956052] [client 35.244.43.255:45782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXXxFTPRVSLOsRVholvwAAATs"]
[Thu Sep 17 15:10:55.668923 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXxFTPRVSLOsRVholwgAAAQ0"]
[Thu Sep 17 15:10:55.669147 2026] [security2:error] [pid 955873:tid 956006] [client 45.169.98.18:53962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXXxFTPRVSLOsRVholwgAAAQ0"]
[Thu Sep 17 15:10:55.669948 2026] [security2:error] [pid 955873:tid 956036] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/vendor/"] [unique_id "aqxXXxFTPRVSLOsRVholwwAAASs"]
[Thu Sep 17 15:10:55.804602 2026] [security2:error] [pid 955873:tid 956086] [client 82.102.18.118:57262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxXXxFTPRVSLOsRVholwAAAAV0"]
[Thu Sep 17 15:10:55.845044 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/vendor/"] [unique_id "aqxXXxFTPRVSLOsRVholxgAAAVU"]
[Thu Sep 17 15:10:55.983949 2026] [security2:error] [pid 955873:tid 956087] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/dist/vendor/wp-includes/js/dist/"] [unique_id "aqxXXxFTPRVSLOsRVholyAAAAV4"]
[Thu Sep 17 15:10:56.243783 2026] [security2:error] [pid 955873:tid 956072] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXXxFTPRVSLOsRVholxQAAAU8"]
[Thu Sep 17 15:10:56.280716 2026] [security2:error] [pid 955873:tid 956125] [client 35.244.43.255:45790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/core/phpinfo.php"] [unique_id "aqxXYBFTPRVSLOsRVholzwAAAYQ"]
[Thu Sep 17 15:10:56.332040 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVholzAAAAUo"]
[Thu Sep 17 15:10:56.332064 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVholzAAAAUo"]
[Thu Sep 17 15:10:56.348425 2026] [security2:error] [pid 955873:tid 956040] [client 179.214.126.150:7587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cherryfox.co.uk"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVhollwAAAS8"]
[Thu Sep 17 15:10:56.399289 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYBFTPRVSLOsRVhol0gAAAXU"]
[Thu Sep 17 15:10:56.399447 2026] [security2:error] [pid 955873:tid 956110] [client 82.102.18.118:57030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYBFTPRVSLOsRVhol0gAAAXU"]
[Thu Sep 17 15:10:56.482188 2026] [security2:error] [pid 955873:tid 956107] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "aqxXYBFTPRVSLOsRVhol1AAAAXI"]
[Thu Sep 17 15:10:56.622332 2026] [security2:error] [pid 955873:tid 956042] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol2QAAATE"]
[Thu Sep 17 15:10:56.639534 2026] [security2:error] [pid 955873:tid 956042] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "aqxXYBFTPRVSLOsRVhol2gAAATE"]
[Thu Sep 17 15:10:56.779024 2026] [security2:error] [pid 955873:tid 956018] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/imgareaselect/wp-includes/js/"] [unique_id "aqxXYBFTPRVSLOsRVhol3gAAARk"]
[Thu Sep 17 15:10:56.825791 2026] [security2:error] [pid 955873:tid 956069] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol4AAAAUw"]
[Thu Sep 17 15:10:56.937747 2026] [security2:error] [pid 955873:tid 956088] [client 41.100.35.51:52290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol3wABXw8"]
[Thu Sep 17 15:10:57.004593 2026] [security2:error] [pid 955873:tid 956109] [client 35.244.43.255:45804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.43.244.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxXYRFTPRVSLOsRVhol5wAAAXQ"]
[Thu Sep 17 15:10:57.016128 2026] [security2:error] [pid 955873:tid 956021] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/themes/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol5gAAARw"]
[Thu Sep 17 15:10:57.120255 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol4gAAAUY"]
[Thu Sep 17 15:10:57.120282 2026] [security2:error] [pid 955873:tid 956063] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYBFTPRVSLOsRVhol4gAAAUY"]
[Thu Sep 17 15:10:57.262972 2026] [security2:error] [pid 955873:tid 956111] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jcrop/"] [unique_id "aqxXYRFTPRVSLOsRVhol8AAAAXY"]
[Thu Sep 17 15:10:57.264527 2026] [autoindex:error] [pid 955873:tid 956022] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:57.265030 2026] [security2:error] [pid 955873:tid 956022] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/includes/"] [unique_id "aqxXYRFTPRVSLOsRVhol7QAAAR0"]
[Thu Sep 17 15:10:57.408219 2026] [security2:error] [pid 955873:tid 956099] [client 185.55.149.49:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhol8wAAAWo"]
[Thu Sep 17 15:10:57.408368 2026] [security2:error] [pid 955873:tid 956099] [client 185.55.149.49:51231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhol8wAAAWo"]
[Thu Sep 17 15:10:57.417730 2026] [security2:error] [pid 955873:tid 956029] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jcrop/"] [unique_id "aqxXYRFTPRVSLOsRVhol8gAAASQ"]
[Thu Sep 17 15:10:57.455618 2026] [security2:error] [pid 955873:tid 956118] [client 176.29.170.228:11356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "noanimalsaswaste.org"] [uri "/index.php"] [unique_id "aqxXXhFTPRVSLOsRVholjgAAAX0"]
[Thu Sep 17 15:10:57.565292 2026] [security2:error] [pid 955873:tid 956123] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jcrop/wp-includes/js/"] [unique_id "aqxXYRFTPRVSLOsRVhol-gAAAYI"]
[Thu Sep 17 15:10:57.598364 2026] [security2:error] [pid 955873:tid 956003] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol9gAAAQo"]
[Thu Sep 17 15:10:57.635945 2026] [security2:error] [pid 955873:tid 956106] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol7wAAAXE"]
[Thu Sep 17 15:10:57.677030 2026] [security2:error] [pid 955873:tid 956058] [client 5.189.145.112:56991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_QAAAUE"], referer: binance.com
[Thu Sep 17 15:10:57.824859 2026] [security2:error] [pid 955873:tid 956037] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_wAAASw"]
[Thu Sep 17 15:10:57.911351 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_gAAAYc"]
[Thu Sep 17 15:10:57.911378 2026] [security2:error] [pid 955873:tid 956128] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhol_gAAAYc"]
[Thu Sep 17 15:10:57.935761 2026] [security2:error] [pid 955873:tid 956030] [client 156.192.234.52:61164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhomAgAAASU"]
[Thu Sep 17 15:10:57.937144 2026] [security2:error] [pid 955873:tid 956030] [client 156.192.234.52:61164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYRFTPRVSLOsRVhomAgAAASU"]
[Thu Sep 17 15:10:57.939711 2026] [security2:error] [pid 955873:tid 956036] [client 82.102.18.118:57262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-admin/index.php"] [unique_id "aqxXYRFTPRVSLOsRVhomAAAAASs"]
[Thu Sep 17 15:10:58.060827 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/"] [unique_id "aqxXYhFTPRVSLOsRVhomCAAAAVU"]
[Thu Sep 17 15:10:58.144431 2026] [security2:error] [pid 955873:tid 956098] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomCQAAAWk"]
[Thu Sep 17 15:10:58.226035 2026] [security2:error] [pid 955873:tid 956012] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/"] [unique_id "aqxXYhFTPRVSLOsRVhomDAAAARM"]
[Thu Sep 17 15:10:58.364822 2026] [security2:error] [pid 955873:tid 956110] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/wp-includes/js/"] [unique_id "aqxXYhFTPRVSLOsRVhomFAAAAXU"]
[Thu Sep 17 15:10:58.454231 2026] [security2:error] [pid 955873:tid 956124] [client 82.102.18.118:57036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYhFTPRVSLOsRVhomHAAAAYM"]
[Thu Sep 17 15:10:58.454389 2026] [security2:error] [pid 955873:tid 956124] [client 82.102.18.118:57036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/wp-login.php"] [unique_id "aqxXYhFTPRVSLOsRVhomHAAAAYM"]
[Thu Sep 17 15:10:58.468229 2026] [security2:error] [pid 955873:tid 956071] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomFQAAAU4"]
[Thu Sep 17 15:10:58.657687 2026] [autoindex:error] [pid 955873:tid 956008] [client 82.102.18.118:35066] AH01276: Cannot serve directory /home2/frenchz8/public_html/website_beaa9689/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:10:58.658471 2026] [security2:error] [pid 955873:tid 956008] [client 82.102.18.118:35066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-beaa9689.frenchtutoringfun.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxXYhFTPRVSLOsRVhomJAAAAQ8"]
[Thu Sep 17 15:10:58.702039 2026] [security2:error] [pid 955873:tid 956055] [client 115.244.164.14:65350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYhFTPRVSLOsRVhomJQAAAT4"]
[Thu Sep 17 15:10:58.702180 2026] [security2:error] [pid 955873:tid 956055] [client 115.244.164.14:65350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXYhFTPRVSLOsRVhomJQAAAT4"]
[Thu Sep 17 15:10:58.733436 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomIAAAAYE"]
[Thu Sep 17 15:10:58.733465 2026] [security2:error] [pid 955873:tid 956122] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomIAAAAYE"]
[Thu Sep 17 15:10:58.786825 2026] [security2:error] [pid 955873:tid 956018] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomJgAAARk"]
[Thu Sep 17 15:10:58.858275 2026] [security2:error] [pid 955873:tid 956056] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXYhFTPRVSLOsRVhomGwAAAT8"]
[Thu Sep 17 15:10:58.899936 2026] [security2:error] [pid 955873:tid 956021] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/ui/"] [unique_id "aqxXYhFTPRVSLOsRVhomKAAAARw"]
[Thu Sep 17 15:10:59.104145 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/ui/"] [unique_id "aqxXYxFTPRVSLOsRVhomMQAAAYA"]
[Thu Sep 17 15:10:59.112112 2026] [security2:error] [pid 955873:tid 956089] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomMAAAAWA"]
[Thu Sep 17 15:10:59.250493 2026] [security2:error] [pid 955873:tid 956104] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/jquery/ui/wp-includes/js/jquery/"] [unique_id "aqxXYxFTPRVSLOsRVhomNAAAAW8"]
[Thu Sep 17 15:10:59.435067 2026] [security2:error] [pid 955873:tid 956029] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomNQAAASQ"]
[Thu Sep 17 15:10:59.596438 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomNgAAAWU"]
[Thu Sep 17 15:10:59.596464 2026] [security2:error] [pid 955873:tid 956094] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomNgAAAWU"]
[Thu Sep 17 15:10:59.737043 2026] [security2:error] [pid 955873:tid 956052] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/"] [unique_id "aqxXYxFTPRVSLOsRVhomPwAAATs"]
[Thu Sep 17 15:10:59.772237 2026] [security2:error] [pid 955873:tid 956020] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomPQAAARs"]
[Thu Sep 17 15:10:59.903601 2026] [security2:error] [pid 955873:tid 956048] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/"] [unique_id "aqxXYxFTPRVSLOsRVhomQAAAATc"]
[Thu Sep 17 15:11:00.034292 2026] [security2:error] [pid 955873:tid 956031] [client 45.12.3.130:53635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.3.12.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vinoviaggio.com"] [uri "/images/images/cache.php"] [unique_id "aqxXZBFTPRVSLOsRVhomRAAAASY"]
[Thu Sep 17 15:11:00.039483 2026] [security2:error] [pid 955873:tid 956117] [client 186.105.232.15:49769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZBFTPRVSLOsRVhomRQAAAXw"]
[Thu Sep 17 15:11:00.039800 2026] [security2:error] [pid 955873:tid 956117] [client 186.105.232.15:49769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZBFTPRVSLOsRVhomRQAAAXw"]
[Thu Sep 17 15:11:00.045089 2026] [security2:error] [pid 955873:tid 956083] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/wp-includes/js/"] [unique_id "aqxXZBFTPRVSLOsRVhomRwAAAVo"]
[Thu Sep 17 15:11:00.090827 2026] [security2:error] [pid 955873:tid 956128] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomQwAAAYc"]
[Thu Sep 17 15:11:00.101507 2026] [security2:error] [pid 955873:tid 956058] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomPgAAAUE"]
[Thu Sep 17 15:11:00.418720 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSQAAAVU"]
[Thu Sep 17 15:11:00.418742 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSQAAAVU"]
[Thu Sep 17 15:11:00.421160 2026] [security2:error] [pid 955873:tid 956105] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSwAAAXA"]
[Thu Sep 17 15:11:00.558747 2026] [security2:error] [pid 955873:tid 956040] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/renderers/"] [unique_id "aqxXZBFTPRVSLOsRVhomUQAAAS8"]
[Thu Sep 17 15:11:00.625855 2026] [security2:error] [pid 955873:tid 956018] [client 3.82.141.143:30628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXZBFTPRVSLOsRVhomZwAAARk"]
[Thu Sep 17 15:11:00.626643 2026] [security2:error] [pid 955873:tid 956070] [client 3.82.141.143:30434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/config.php"] [unique_id "aqxXZBFTPRVSLOsRVhomaAAAAU0"]
[Thu Sep 17 15:11:00.630085 2026] [security2:error] [pid 955873:tid 956035] [client 3.82.141.143:30622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php"] [unique_id "aqxXZBFTPRVSLOsRVhomagAAASo"]
[Thu Sep 17 15:11:00.630681 2026] [security2:error] [pid 955873:tid 956042] [client 3.82.141.143:30644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php.old"] [unique_id "aqxXZBFTPRVSLOsRVhomawAAATE"]
[Thu Sep 17 15:11:00.633848 2026] [security2:error] [pid 955873:tid 956033] [client 3.82.141.143:30662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php~"] [unique_id "aqxXZBFTPRVSLOsRVhomcgAAASg"]
[Thu Sep 17 15:11:00.635550 2026] [security2:error] [pid 955873:tid 956062] [client 3.82.141.143:30650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.mtbclubdecampo.com"] [uri "/wp-config.php.save"] [unique_id "aqxXZBFTPRVSLOsRVhomeAAAAUU"]
[Thu Sep 17 15:11:00.739606 2026] [security2:error] [pid 955873:tid 956121] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/renderers/"] [unique_id "aqxXZBFTPRVSLOsRVhomfQAAAYA"]
[Thu Sep 17 15:11:00.745724 2026] [security2:error] [pid 955873:tid 956068] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomfAAAAUs"]
[Thu Sep 17 15:11:00.882883 2026] [security2:error] [pid 955873:tid 956118] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/mediaelement/renderers/wp-includes/js/mediaelement/"] [unique_id "aqxXZBFTPRVSLOsRVhomgAAAAX0"]
[Thu Sep 17 15:11:00.967637 2026] [security2:error] [pid 955873:tid 956014] [client 144.76.22.53:37344] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomSgAAARU"]
[Thu Sep 17 15:11:01.092903 2026] [security2:error] [pid 955873:tid 956123] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomggAAAYI"]
[Thu Sep 17 15:11:01.272870 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhQAAASY"]
[Thu Sep 17 15:11:01.272894 2026] [security2:error] [pid 955873:tid 956031] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhQAAASY"]
[Thu Sep 17 15:11:01.291879 2026] [security2:error] [pid 955873:tid 956095] [client 104.28.198.244:23021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhwAAAWY"]
[Thu Sep 17 15:11:01.382002 2026] [security2:error] [pid 955873:tid 956080] [client 34.32.117.146:45086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXZBFTPRVSLOsRVhomfwAAAVc"]
[Thu Sep 17 15:11:01.419208 2026] [security2:error] [pid 955873:tid 956078] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/plupload/"] [unique_id "aqxXZRFTPRVSLOsRVhomkAAAAVU"]
[Thu Sep 17 15:11:01.442232 2026] [security2:error] [pid 955873:tid 956009] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhomiwAAARA"]
[Thu Sep 17 15:11:01.472422 2026] [security2:error] [pid 955873:tid 956095] [client 104.28.198.244:23021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXZRFTPRVSLOsRVhomhwAAAWY"]
[Thu Sep 17 15:11:01.588532 2026] [security2:error] [pid 955873:tid 956070] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/plupload/"] [unique_id "aqxXZRFTPRVSLOsRVhomlQAAAU0"]
[Thu Sep 17 15:11:01.623264 2026] [security2:error] [pid 955873:tid 956105] [client 114.119.156.134:64407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jumpplot.com"] [uri "/about-us"] [unique_id "aqxXZRFTPRVSLOsRVhommAAAAXA"], referer: https://jumpplot.com/about-us
[Thu Sep 17 15:11:01.738387 2026] [security2:error] [pid 955873:tid 956062] [client 143.244.57.120:51858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/plupload/wp-includes/js/"] [unique_id "aqxXZRFTPRVSLOsRVhommgAAAUU"]
[Thu Sep 17 15:11:01.771688 2026] [security2:error] [pid 955873:tid 956035] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhommQAAASo"]
[Thu Sep 17 15:11:02.052780 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00493: SIGUSR1 received.  Doing graceful restart
[Thu Sep 17 15:11:02.093311 2026] [security2:error] [pid 955873:tid 956022] [client 35.244.43.255:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXZhFTPRVSLOsRVhomnQAAAR0"]
[Thu Sep 17 15:11:02.177439 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhommwAAAUo"]
[Thu Sep 17 15:11:02.177470 2026] [security2:error] [pid 955873:tid 956067] [client 143.244.57.120:40074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXZRFTPRVSLOsRVhommwAAAUo"]
[Thu Sep 17 15:11:03.197894 2026] [security2:error] [pid 955873:tid 956112] [client 47.79.201.54:14000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxXZhFTPRVSLOsRVhomngAAAXc"], referer: https://www.google.com/
[Thu Sep 17 15:11:03.200683 2026] [:notice] [pid 955834:tid 955834] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 955834 stopped
[Thu Sep 17 15:11:04.604465 2026] [security2:error] [pid 955873:tid 956096] [client 40.77.167.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.realdubrovnikexperience.com"] [uri "/index.php"] [unique_id "aqxXYxFTPRVSLOsRVhomOQAAAWc"]
[Thu Sep 17 15:11:05.868315 2026] [lsapi:notice] [pid 907280:tid 907280] mod_lsapi:  version 1.1-92
[Thu Sep 17 15:11:05.873741 2026] [:notice] [pid 971056:tid 971056] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 971056 started
[Thu Sep 17 15:11:05.923070 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tylerblantonmusic.tylerblanton.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.930287 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: deraiz-mx.xavierlopezmiranda.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.959368 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ahmedteleb.tasameem-eg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.961839 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fst-i.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.962414 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fstsprinkler.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.966394 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: southislandpie.southislandpie.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.978727 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardashphotography.reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.989211 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcp-u.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.989795 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.990786 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reedcustomprinting.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.991365 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpphotorestoration.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.991769 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpmobileartscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:05.992574 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rjglobalhq.com.rebeccamerzius.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.022179 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mermco.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.022575 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ad1homes.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.023125 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-7b36017a.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.026052 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-3f11e808.livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.041968 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: api.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.042322 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: admin.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.057429 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: hamzaabdulhaq.gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.071517 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: site.tengushee.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.093589 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ayfertbarak.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.094075 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: becorenovation.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.094429 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: agent-immobilier.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.097049 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sqlerudition.commutervibe.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.099517 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bothe-net.cyber21.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.115063 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: troopkcampcadet.campcadetmontco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.116887 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vedur-app.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.117384 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: weather-is.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.117896 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tengja-net.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.118369 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bookin-city.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.118847 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-c557c2bf.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.119338 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-1a493541.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.119856 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitlinwhittington.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.120217 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jarrodandcaitlin-us.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.140277 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b2133dcc.idautovic.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.160495 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wellfedhealth.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.161333 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wear-out.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.164327 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vogito-inno.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.179597 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: thegoatmentality.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.190426 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.201432 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rpimanufacturing.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.202031 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rosebar.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.205949 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: revelinfear.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.207436 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.216919 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pazcreativehomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.218937 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pagepress.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.227749 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nikistepanianmft.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.229893 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nexgenimplant.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.238226 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mengesphotos.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.239748 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mdlzbenefits.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.242160 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: macmanagement.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.247284 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: lifepointechurchga.org:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.254820 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.257283 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kbmautomation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.261014 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jminner.photo:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.265435 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: janetaylor.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.266544 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.283080 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.294550 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ffwdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.295435 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: evansilver.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.296788 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ericbabin.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.300112 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ellenhirshberg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.312546 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: comfortspecialist.info:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.319283 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: biggselectrical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.320528 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.321516 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.322321 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bvpowersports.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.322732 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buliblog.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.323293 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buildingpro.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.325809 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bodylanguageohio.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.340628 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: afbaco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.341533 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: abelardpsychotherapy.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.398410 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b0f84876.robertsinteractive.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.404093 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tracertgame-com.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.404657 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-f2c0397e.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.406603 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-19b382b5.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.445745 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: marinabelous.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.457730 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: houlaentertainment.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.483592 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:11:06.499156 2026] [qos:notice] [pid 907280:tid 907280] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Sep 17 15:11:06.754472 2026] [http2:info] [pid 907280:tid 907280] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Thu Sep 17 15:11:06.759318 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Sep 17 15:11:06.759332 2026] [core:notice] [pid 907280:tid 907280] AH00094: Command line: '/usr/sbin/httpd'
[Thu Sep 17 15:11:07.811323 2026] [http2:info] [pid 971102:tid 971102] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:11:07.832047 2026] [security2:error] [pid 971102:tid 971240] [client 5.189.145.112:59293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxXa-cL08BTTQixEnowbAAAAAY"], referer: binance.com
[Thu Sep 17 15:11:07.832855 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/swfupload/"] [unique_id "aqxXa-cL08BTTQixEnowagAAAAM"]
[Thu Sep 17 15:11:07.833717 2026] [security2:error] [pid 971102:tid 971246] [client 162.241.226.11:29432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alloracart.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxXa-cL08BTTQixEnowbgAAAAw"]
[Thu Sep 17 15:11:07.834793 2026] [security2:error] [pid 971102:tid 971254] [client 137.131.43.163:58903] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milehighmuse.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxXa-cL08BTTQixEnowbwAAABQ"]
[Thu Sep 17 15:11:07.875445 2026] [security2:error] [pid 971102:tid 971274] [client 137.131.43.163:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.43.131.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "milehighmuse.com"] [uri "/xmlrpc.php"] [unique_id "aqxXa-cL08BTTQixEnoweQAAACg"]
[Thu Sep 17 15:11:07.880508 2026] [authz_core:error] [pid 971102:tid 971275] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:11:07.972061 2026] [security2:error] [pid 971102:tid 971262] [client 45.169.98.18:54513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXa-cL08BTTQixEnowiAAAABw"]
[Thu Sep 17 15:11:07.972210 2026] [security2:error] [pid 971102:tid 971262] [client 45.169.98.18:54513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXa-cL08BTTQixEnowiAAAABw"]
[Thu Sep 17 15:11:08.024224 2026] [security2:error] [pid 971102:tid 971253] [client 114.119.151.67:36623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenniferniesslein.com"] [uri "/feed"] [unique_id "aqxXbOcL08BTTQixEnowjgAAABM"], referer: https://jenniferniesslein.com/feed
[Thu Sep 17 15:11:08.067446 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.env~"] [unique_id "aqxXbOcL08BTTQixEnowkQAAAB0"]
[Thu Sep 17 15:11:08.140867 2026] [security2:error] [pid 971102:tid 971283] [client 185.55.149.49:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowlgAAADE"]
[Thu Sep 17 15:11:08.140985 2026] [security2:error] [pid 971102:tid 971283] [client 185.55.149.49:51867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowlgAAADE"]
[Thu Sep 17 15:11:08.258448 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowmgAAAAg"]
[Thu Sep 17 15:11:08.258579 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:41546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowmgAAAAg"]
[Thu Sep 17 15:11:08.322101 2026] [security2:error] [pid 971102:tid 971105] [remote 57.141.14.47:45464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxXa-cL08BTTQixEnowcwAAIAE"]
[Thu Sep 17 15:11:08.455175 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/swfupload/"] [unique_id "aqxXbOcL08BTTQixEnowngAAAEU"]
[Thu Sep 17 15:11:08.531095 2026] [security2:error] [pid 971102:tid 971305] [client 156.192.234.52:61777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowowAAAEc"]
[Thu Sep 17 15:11:08.531245 2026] [security2:error] [pid 971102:tid 971305] [client 156.192.234.52:61777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbOcL08BTTQixEnowowAAAEc"]
[Thu Sep 17 15:11:08.600197 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/swfupload/wp-includes/js/"] [unique_id "aqxXbOcL08BTTQixEnowpAAAAGY"]
[Thu Sep 17 15:11:08.703901 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowlwAAAE0"]
[Thu Sep 17 15:11:08.752487 2026] [security2:error] [pid 971102:tid 971267] [client 47.79.200.222:61496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowpgAAACE"], referer: https://www.google.com/
[Thu Sep 17 15:11:09.103103 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowpwAAAGw"]
[Thu Sep 17 15:11:09.103131 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbOcL08BTTQixEnowpwAAAGw"]
[Thu Sep 17 15:11:09.312051 2026] [security2:error] [pid 971102:tid 971352] [client 115.244.164.14:49606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbecL08BTTQixEnowtgAAAHY"]
[Thu Sep 17 15:11:09.312210 2026] [security2:error] [pid 971102:tid 971352] [client 115.244.164.14:49606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbecL08BTTQixEnowtgAAAHY"]
[Thu Sep 17 15:11:09.420796 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/thickbox/"] [unique_id "aqxXbecL08BTTQixEnowugAAAAw"]
[Thu Sep 17 15:11:09.582317 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/thickbox/"] [unique_id "aqxXbecL08BTTQixEnowwAAAACg"]
[Thu Sep 17 15:11:09.728180 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/thickbox/wp-includes/js/"] [unique_id "aqxXbecL08BTTQixEnowwgAAADM"]
[Thu Sep 17 15:11:10.070102 2026] [security2:error] [pid 971102:tid 971275] [client 135.135.37.144:58147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXbecL08BTTQixEnowyQAAACk"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:11:10.091838 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbecL08BTTQixEnowxgAAAD0"]
[Thu Sep 17 15:11:10.091862 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbecL08BTTQixEnowxgAAAD0"]
[Thu Sep 17 15:11:10.240473 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/"] [unique_id "aqxXbucL08BTTQixEnowzAAAAEY"]
[Thu Sep 17 15:11:10.241839 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXbecL08BTTQixEnowxQAAADw"]
[Thu Sep 17 15:11:10.242751 2026] [security2:error] [pid 971102:tid 971259] [client 137.131.43.163:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.43.131.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "milehighmuse.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnowzQAAABk"]
[Thu Sep 17 15:11:10.242844 2026] [security2:error] [pid 971102:tid 971259] [client 137.131.43.163:51640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "milehighmuse.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnowzQAAABk"]
[Thu Sep 17 15:11:10.421432 2026] [security2:error] [pid 971102:tid 971300] [client 135.135.37.144:58147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXbucL08BTTQixEnowzwAAAEI"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:11:10.458881 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/"] [unique_id "aqxXbucL08BTTQixEnow0AAAADc"]
[Thu Sep 17 15:11:10.602501 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/wp-includes/js/"] [unique_id "aqxXbucL08BTTQixEnow0wAAAEo"]
[Thu Sep 17 15:11:10.886802 2026] [security2:error] [pid 971102:tid 971290] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env"] [unique_id "aqxXbucL08BTTQixEnow1QAAADg"]
[Thu Sep 17 15:11:10.935219 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbucL08BTTQixEnow1AAAAEs"]
[Thu Sep 17 15:11:10.935241 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXbucL08BTTQixEnow1AAAAEs"]
[Thu Sep 17 15:11:10.989964 2026] [security2:error] [pid 971102:tid 971276] [client 104.28.198.244:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnow1wAAACo"]
[Thu Sep 17 15:11:10.990141 2026] [security2:error] [pid 971102:tid 971276] [client 104.28.198.244:22715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXbucL08BTTQixEnow1wAAACo"]
[Thu Sep 17 15:11:11.048655 2026] [security2:error] [pid 971102:tid 971314] [client 162.241.226.11:29436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alloracart.com"] [uri "/wp-cron.php"] [unique_id "aqxXb-cL08BTTQixEnow2gAAAFA"]
[Thu Sep 17 15:11:11.059311 2026] [security2:error] [pid 971102:tid 971240] [client 186.105.232.15:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXb-cL08BTTQixEnow2QAAAAY"]
[Thu Sep 17 15:11:11.059440 2026] [security2:error] [pid 971102:tid 971240] [client 186.105.232.15:50358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXb-cL08BTTQixEnow2QAAAAY"]
[Thu Sep 17 15:11:11.080327 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "aqxXb-cL08BTTQixEnow3AAAAAg"]
[Thu Sep 17 15:11:11.180088 2026] [security2:error] [pid 971102:tid 971310] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXbucL08BTTQixEnow1gAAAEw"]
[Thu Sep 17 15:11:11.241316 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "aqxXb-cL08BTTQixEnow3gAAAFU"]
[Thu Sep 17 15:11:11.360701 2026] [security2:error] [pid 971102:tid 971327] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow3wAAAF0"]
[Thu Sep 17 15:11:11.384254 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/langs/wp-includes/js/tinymce/"] [unique_id "aqxXb-cL08BTTQixEnow4QAAAF4"]
[Thu Sep 17 15:11:11.533077 2026] [security2:error] [pid 971102:tid 971329] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4gAAAF8"]
[Thu Sep 17 15:11:11.712091 2026] [security2:error] [pid 971102:tid 971280] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow5AAAAC4"]
[Thu Sep 17 15:11:11.719317 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4AAAAFg"]
[Thu Sep 17 15:11:11.722474 2026] [security2:error] [pid 971102:tid 971331] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4wAAAGE"]
[Thu Sep 17 15:11:11.722487 2026] [security2:error] [pid 971102:tid 971331] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow4wAAAGE"]
[Thu Sep 17 15:11:11.867355 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXb-cL08BTTQixEnow5wAAAGU"]
[Thu Sep 17 15:11:11.877715 2026] [security2:error] [pid 971102:tid 971293] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXb-cL08BTTQixEnow5gAAADs"]
[Thu Sep 17 15:11:11.967091 2026] [security2:error] [pid 971102:tid 971336] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env.backup"] [unique_id "aqxXb-cL08BTTQixEnow6QAAAGY"]
[Thu Sep 17 15:11:12.007115 2026] [security2:error] [pid 971102:tid 971323] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env.bak"] [unique_id "aqxXcOcL08BTTQixEnow6gAAAFk"]
[Thu Sep 17 15:11:12.047577 2026] [security2:error] [pid 971102:tid 971321] [client 144.172.93.238:13974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mindmappower.com"] [uri "/.env.old"] [unique_id "aqxXcOcL08BTTQixEnow7AAAAFc"]
[Thu Sep 17 15:11:12.155130 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcOcL08BTTQixEnow6wAAAFs"]
[Thu Sep 17 15:11:12.191275 2026] [security2:error] [pid 971102:tid 971337] [client 144.172.93.238:13974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxXcOcL08BTTQixEnow7QAAAGc"]
[Thu Sep 17 15:11:12.267112 2026] [security2:error] [pid 971102:tid 971320] [client 144.172.93.238:13974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.93.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mindmappower.com"] [uri "/.env.php"] [unique_id "aqxXcOcL08BTTQixEnow7wAAAFY"]
[Thu Sep 17 15:11:12.297602 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wp-includes/js/tinymce/"] [unique_id "aqxXcOcL08BTTQixEnow8AAAAGg"]
[Thu Sep 17 15:11:12.629322 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcOcL08BTTQixEnow9AAAACY"]
[Thu Sep 17 15:11:12.629355 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcOcL08BTTQixEnow9AAAACY"]
[Thu Sep 17 15:11:12.759628 2026] [security2:error] [pid 971102:tid 971352] [client 144.172.93.238:1656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.93.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mindmappower.com"] [uri "/.env.php"] [unique_id "aqxXcOcL08BTTQixEnoxAQAAAHY"]
[Thu Sep 17 15:11:12.762830 2026] [authz_core:error] [pid 971102:tid 971250] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:11:12.770418 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/charmap/"] [unique_id "aqxXcOcL08BTTQixEnoxAgAAAA8"]
[Thu Sep 17 15:11:12.843578 2026] [security2:error] [pid 971102:tid 971265] [client 162.241.226.11:43206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alloracart.com"] [uri "/wp-cron.php"] [unique_id "aqxXcOcL08BTTQixEnoxAwAAAB8"]
[Thu Sep 17 15:11:12.940658 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/charmap/"] [unique_id "aqxXcOcL08BTTQixEnoxBgAAABs"]
[Thu Sep 17 15:11:13.120596 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/charmap/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcecL08BTTQixEnoxCAAAAHg"]
[Thu Sep 17 15:11:13.450462 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcecL08BTTQixEnoxDAAAAHQ"]
[Thu Sep 17 15:11:13.450486 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcecL08BTTQixEnoxDAAAAHQ"]
[Thu Sep 17 15:11:13.594170 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXcecL08BTTQixEnoxCwAAADI"]
[Thu Sep 17 15:11:13.594931 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/colorpicker/"] [unique_id "aqxXcecL08BTTQixEnoxEAAAAA0"]
[Thu Sep 17 15:11:13.982034 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/colorpicker/"] [unique_id "aqxXcecL08BTTQixEnoxFgAAAB4"]
[Thu Sep 17 15:11:14.138731 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/colorpicker/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcucL08BTTQixEnoxGgAAAAc"]
[Thu Sep 17 15:11:14.472124 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxGwAAAD8"]
[Thu Sep 17 15:11:14.472152 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxGwAAAD8"]
[Thu Sep 17 15:11:14.615626 2026] [security2:error] [pid 971102:tid 971278] [client 154.190.208.131:42174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXcucL08BTTQixEnoxIQAAACw"]
[Thu Sep 17 15:11:14.615742 2026] [security2:error] [pid 971102:tid 971278] [client 154.190.208.131:42174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXcucL08BTTQixEnoxIQAAACw"]
[Thu Sep 17 15:11:14.619955 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/"] [unique_id "aqxXcucL08BTTQixEnoxIgAAADQ"]
[Thu Sep 17 15:11:14.781527 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/"] [unique_id "aqxXcucL08BTTQixEnoxJQAAAEw"]
[Thu Sep 17 15:11:14.931258 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXcucL08BTTQixEnoxJwAAAFU"]
[Thu Sep 17 15:11:15.015005 2026] [core:crit] [pid 971102:tid 971251] (13)Permission denied: [client 43.157.43.147:35982] AH00529: /home1/awesone8/public_html/comicsutra.com/cs/news/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/awesone8/public_html/comicsutra.com/cs/news/' is executable
[Thu Sep 17 15:11:15.080745 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxJAAAACA"]
[Thu Sep 17 15:11:15.091274 2026] [security2:error] [pid 971102:tid 971327] [client 200.26.224.146:47034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXcucL08BTTQixEnoxKQAAXRg"], referer: https://www.yahoo.com/
[Thu Sep 17 15:11:15.138053 2026] [security2:error] [pid 971102:tid 971329] [client 34.94.67.131:54016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXc-cL08BTTQixEnoxLwAAAF8"]
[Thu Sep 17 15:11:15.309349 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxLgAAAEc"]
[Thu Sep 17 15:11:15.309371 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxLgAAAEc"]
[Thu Sep 17 15:11:15.451320 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aqxXc-cL08BTTQixEnoxMgAAAGQ"]
[Thu Sep 17 15:11:15.610384 2026] [security2:error] [pid 971102:tid 971337] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aqxXc-cL08BTTQixEnoxNgAAAGc"]
[Thu Sep 17 15:11:15.645312 2026] [security2:error] [pid 971102:tid 971336] [client 34.94.67.131:54024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXc-cL08BTTQixEnoxOAAAAGY"]
[Thu Sep 17 15:11:15.735819 2026] [authz_core:error] [pid 971102:tid 971338] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:11:15.753457 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/wp-includes/js/tinymce/plugins/compat3x/"] [unique_id "aqxXc-cL08BTTQixEnoxPAAAAHE"]
[Thu Sep 17 15:11:15.813005 2026] [security2:error] [pid 971102:tid 971257] [client 5.189.145.112:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxXc-cL08BTTQixEnoxPgAAABc"], referer: binance.com
[Thu Sep 17 15:11:15.901964 2026] [security2:error] [pid 971102:tid 971358] [client 34.94.67.131:54040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXc-cL08BTTQixEnoxQQAAAHw"]
[Thu Sep 17 15:11:16.047252 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/app/.env"] [unique_id "aqxXdOcL08BTTQixEnoxRAAAAHk"]
[Thu Sep 17 15:11:16.100788 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxQgAAAHs"]
[Thu Sep 17 15:11:16.100812 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXc-cL08BTTQixEnoxQgAAAHs"]
[Thu Sep 17 15:11:16.245156 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/directionality/"] [unique_id "aqxXdOcL08BTTQixEnoxRQAAAAw"]
[Thu Sep 17 15:11:16.327574 2026] [security2:error] [pid 971102:tid 971274] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/apps/.env"] [unique_id "aqxXdOcL08BTTQixEnoxRgAAACg"]
[Thu Sep 17 15:11:16.402610 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/directionality/"] [unique_id "aqxXdOcL08BTTQixEnoxSQAAAC0"]
[Thu Sep 17 15:11:16.435565 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.67.131:54046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.sqlerudition.com"] [uri "/"] [unique_id "aqxXdOcL08BTTQixEnoxTAAAAAA"]
[Thu Sep 17 15:11:16.531655 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/.env"] [unique_id "aqxXdOcL08BTTQixEnoxTgAAADk"]
[Thu Sep 17 15:11:16.550317 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/directionality/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXdOcL08BTTQixEnoxTwAAABw"]
[Thu Sep 17 15:11:16.651561 2026] [security2:error] [pid 971102:tid 971245] [client 45.169.98.18:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXdOcL08BTTQixEnoxUAAAAAs"]
[Thu Sep 17 15:11:16.653601 2026] [security2:error] [pid 971102:tid 971245] [client 45.169.98.18:55068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXdOcL08BTTQixEnoxUAAAAAs"]
[Thu Sep 17 15:11:16.805288 2026] [security2:error] [pid 971102:tid 971254] [client 200.26.224.146:47044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXdOcL08BTTQixEnoxVAAAFB4"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821112553&hidebots=0&hideliu=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:11:16.907407 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdOcL08BTTQixEnoxUgAAABY"]
[Thu Sep 17 15:11:16.907430 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdOcL08BTTQixEnoxUgAAABY"]
[Thu Sep 17 15:11:17.023929 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/web/.env"] [unique_id "aqxXdecL08BTTQixEnoxXwAAAEA"]
[Thu Sep 17 15:11:17.123823 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/"] [unique_id "aqxXdecL08BTTQixEnoxYQAAAEs"]
[Thu Sep 17 15:11:17.248995 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/site/.env"] [unique_id "aqxXdecL08BTTQixEnoxZAAAAE8"]
[Thu Sep 17 15:11:17.284194 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/"] [unique_id "aqxXdecL08BTTQixEnoxZQAAAFA"]
[Thu Sep 17 15:11:17.336775 2026] [security2:error] [pid 971102:tid 971259] [client 104.234.32.52:28651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "clarkcountyclothing.com"] [uri "/index.php"] [unique_id "aqxXcucL08BTTQixEnoxIwAAABk"]
[Thu Sep 17 15:11:17.480356 2026] [security2:error] [pid 971102:tid 971318] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXdecL08BTTQixEnoxawAAAFQ"]
[Thu Sep 17 15:11:17.562846 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/public/.env"] [unique_id "aqxXdecL08BTTQixEnoxbwAAABE"]
[Thu Sep 17 15:11:17.845737 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdecL08BTTQixEnoxcQAAAF0"]
[Thu Sep 17 15:11:17.845761 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXdecL08BTTQixEnoxcQAAAF0"]
[Thu Sep 17 15:11:17.987000 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/hr/"] [unique_id "aqxXdecL08BTTQixEnoxewAAABU"]
[Thu Sep 17 15:11:18.150452 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/hr/"] [unique_id "aqxXducL08BTTQixEnoxfQAAAHA"]
[Thu Sep 17 15:11:18.176919 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.117.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXdecL08BTTQixEnoxcwAAADY"]
[Thu Sep 17 15:11:18.302037 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/hr/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXducL08BTTQixEnoxgAAAAFs"]
[Thu Sep 17 15:11:18.609340 2026] [security2:error] [pid 971102:tid 971140] [remote 162.241.226.11:0] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1441"] [id "9009999"] [msg "8 char spam"] [hostname "playify.work"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aqxXducL08BTTQixEnoxiAAAISQ"]
[Thu Sep 17 15:11:18.630919 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXducL08BTTQixEnoxhQAAAE0"]
[Thu Sep 17 15:11:18.630939 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXducL08BTTQixEnoxhQAAAE0"]
[Thu Sep 17 15:11:18.777712 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/image/"] [unique_id "aqxXducL08BTTQixEnoxjwAAAAM"]
[Thu Sep 17 15:11:18.889234 2026] [security2:error] [pid 971102:tid 971289] [client 185.55.149.49:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXducL08BTTQixEnoxkAAAADc"]
[Thu Sep 17 15:11:18.889323 2026] [security2:error] [pid 971102:tid 971289] [client 185.55.149.49:52494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXducL08BTTQixEnoxkAAAADc"]
[Thu Sep 17 15:11:18.931072 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/image/"] [unique_id "aqxXducL08BTTQixEnoxlAAAACc"]
[Thu Sep 17 15:11:19.018566 2026] [security2:error] [pid 971102:tid 971274] [client 192.178.6.5:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxXd-cL08BTTQixEnoxlwAAACg"]
[Thu Sep 17 15:11:19.074364 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/image/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXd-cL08BTTQixEnoxmgAAAHc"]
[Thu Sep 17 15:11:19.139854 2026] [security2:error] [pid 971102:tid 971344] [client 156.192.234.52:62361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxmwAAAG4"]
[Thu Sep 17 15:11:19.139972 2026] [security2:error] [pid 971102:tid 971344] [client 156.192.234.52:62361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxmwAAAG4"]
[Thu Sep 17 15:11:19.163474 2026] [security2:error] [pid 971102:tid 971349] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/backend/.env"] [unique_id "aqxXd-cL08BTTQixEnoxnAAAAHM"]
[Thu Sep 17 15:11:19.402505 2026] [security2:error] [pid 971102:tid 971350] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/server/.env"] [unique_id "aqxXd-cL08BTTQixEnoxpQAAAHQ"]
[Thu Sep 17 15:11:19.408500 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxnwAAAAs"]
[Thu Sep 17 15:11:19.408519 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxnwAAAAs"]
[Thu Sep 17 15:11:19.552043 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/link/"] [unique_id "aqxXd-cL08BTTQixEnoxrwAAAEk"]
[Thu Sep 17 15:11:19.553826 2026] [authz_core:error] [pid 971102:tid 971294] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:11:19.593963 2026] [security2:error] [pid 971102:tid 971339] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/frontend/.env"] [unique_id "aqxXd-cL08BTTQixEnoxsQAAAGk"]
[Thu Sep 17 15:11:19.708364 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/link/"] [unique_id "aqxXd-cL08BTTQixEnoxtAAAADU"]
[Thu Sep 17 15:11:19.850432 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/link/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXd-cL08BTTQixEnoxtwAAAFA"]
[Thu Sep 17 15:11:19.872702 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxuAAAAB4"]
[Thu Sep 17 15:11:19.872783 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXd-cL08BTTQixEnoxuAAAAB4"]
[Thu Sep 17 15:11:20.028471 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/src/.env"] [unique_id "aqxXeOcL08BTTQixEnoxvgAAAH0"]
[Thu Sep 17 15:11:20.194042 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxvQAAACo"]
[Thu Sep 17 15:11:20.194067 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXd-cL08BTTQixEnoxvQAAACo"]
[Thu Sep 17 15:11:20.234210 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/core/.env"] [unique_id "aqxXeOcL08BTTQixEnoxxAAAACU"]
[Thu Sep 17 15:11:20.338517 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/lists/"] [unique_id "aqxXeOcL08BTTQixEnoxxwAAAAk"]
[Thu Sep 17 15:11:20.403928 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/core/app/.env"] [unique_id "aqxXeOcL08BTTQixEnoxygAAAEc"]
[Thu Sep 17 15:11:20.493896 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/lists/"] [unique_id "aqxXeOcL08BTTQixEnoxzgAAAGQ"]
[Thu Sep 17 15:11:20.625161 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/config/.env"] [unique_id "aqxXeOcL08BTTQixEnox0AAAADs"]
[Thu Sep 17 15:11:20.637994 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/lists/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXeOcL08BTTQixEnox0QAAAFE"]
[Thu Sep 17 15:11:20.850883 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/private/.env"] [unique_id "aqxXeOcL08BTTQixEnox2QAAAFg"]
[Thu Sep 17 15:11:20.995385 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeOcL08BTTQixEnox1AAAAGg"]
[Thu Sep 17 15:11:20.995418 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeOcL08BTTQixEnox1AAAAGg"]
[Thu Sep 17 15:11:21.107598 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/application/.env"] [unique_id "aqxXeecL08BTTQixEnox3wAAAEY"]
[Thu Sep 17 15:11:21.137493 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/media/"] [unique_id "aqxXeecL08BTTQixEnox4QAAAHw"]
[Thu Sep 17 15:11:21.312912 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/media/"] [unique_id "aqxXeecL08BTTQixEnox5QAAAEI"]
[Thu Sep 17 15:11:21.354998 2026] [security2:error] [pid 971102:tid 971299] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/bootstrap/.env"] [unique_id "aqxXeecL08BTTQixEnox5wAAAEE"]
[Thu Sep 17 15:11:21.456193 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/media/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXeecL08BTTQixEnox7QAAABs"]
[Thu Sep 17 15:11:21.571387 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/database/.env"] [unique_id "aqxXeecL08BTTQixEnox7wAAAHc"]
[Thu Sep 17 15:11:21.753404 2026] [security2:error] [pid 971102:tid 971250] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/storage/.env"] [unique_id "aqxXeecL08BTTQixEnox9AAAABA"]
[Thu Sep 17 15:11:21.819434 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeecL08BTTQixEnox8QAAAG4"]
[Thu Sep 17 15:11:21.819461 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeecL08BTTQixEnox8QAAAG4"]
[Thu Sep 17 15:11:21.939926 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/var/www/.env"] [unique_id "aqxXeecL08BTTQixEnox9wAAAA0"]
[Thu Sep 17 15:11:21.961632 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/paste/"] [unique_id "aqxXeecL08BTTQixEnox-QAAAHQ"]
[Thu Sep 17 15:11:22.088722 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXeucL08BTTQixEnox_QAAAH8"]
[Thu Sep 17 15:11:22.088822 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:50941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXeucL08BTTQixEnox_QAAAH8"]
[Thu Sep 17 15:11:22.122175 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/paste/"] [unique_id "aqxXeucL08BTTQixEnox_gAAACM"]
[Thu Sep 17 15:11:22.141127 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/var/www/html/.env"] [unique_id "aqxXeucL08BTTQixEnox_wAAAEk"]
[Thu Sep 17 15:11:22.266017 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/paste/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXeucL08BTTQixEnoyAgAAAGk"]
[Thu Sep 17 15:11:22.511069 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/current/.env"] [unique_id "aqxXeucL08BTTQixEnoyCQAAAFA"]
[Thu Sep 17 15:11:22.542606 2026] [security2:error] [pid 971102:tid 971259] [client 138.68.188.115:59236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfdub.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXeucL08BTTQixEnoyCwAAABk"]
[Thu Sep 17 15:11:22.602044 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeucL08BTTQixEnoyBQAAAAI"]
[Thu Sep 17 15:11:22.602064 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXeucL08BTTQixEnoyBQAAAAI"]
[Thu Sep 17 15:11:22.711893 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/release/.env"] [unique_id "aqxXeucL08BTTQixEnoyEAAAAAg"]
[Thu Sep 17 15:11:22.743393 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/tabfocus/"] [unique_id "aqxXeucL08BTTQixEnoyEgAAABE"]
[Thu Sep 17 15:11:22.846992 2026] [security2:error] [pid 971102:tid 971329] [client 138.68.188.115:59239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfdub.com"] [uri "/"] [unique_id "aqxXeucL08BTTQixEnoyEwAAAF8"]
[Thu Sep 17 15:11:22.898178 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/tabfocus/"] [unique_id "aqxXeucL08BTTQixEnoyFQAAAGI"]
[Thu Sep 17 15:11:23.042712 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/tabfocus/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXe-cL08BTTQixEnoyGQAAAEc"]
[Thu Sep 17 15:11:23.138588 2026] [security2:error] [pid 971102:tid 971335] [client 138.68.188.115:59242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfdub.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXe-cL08BTTQixEnoyGwAAAGU"]
[Thu Sep 17 15:11:23.161886 2026] [security2:error] [pid 971102:tid 971312] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/releases/.env"] [unique_id "aqxXe-cL08BTTQixEnoyHAAAAE4"]
[Thu Sep 17 15:11:23.378804 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyHQAAAGQ"]
[Thu Sep 17 15:11:23.378828 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyHQAAAGQ"]
[Thu Sep 17 15:11:23.484007 2026] [security2:error] [pid 971102:tid 971243] [client 195.2.84.198:56372] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.84.198" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kopecdental.com"] [uri "/wp-comments-post.php"] [unique_id "aqxXe-cL08BTTQixEnoyJQAAAAk"], referer: https://kopecdental.com/2015/04/11/april-is-national-oral-health-month/
[Thu Sep 17 15:11:23.484169 2026] [security2:error] [pid 971102:tid 971243] [client 195.2.84.198:56372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kopecdental.com"] [uri "/wp-comments-post.php"] [unique_id "aqxXe-cL08BTTQixEnoyJQAAAAk"], referer: https://kopecdental.com/2015/04/11/april-is-national-oral-health-month/
[Thu Sep 17 15:11:23.524122 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/textcolor/"] [unique_id "aqxXe-cL08BTTQixEnoyJgAAABg"]
[Thu Sep 17 15:11:23.530926 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/shared/.env"] [unique_id "aqxXe-cL08BTTQixEnoyJwAAAG8"]
[Thu Sep 17 15:11:23.587354 2026] [security2:error] [pid 971102:tid 971341] [client 5.189.145.112:60978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxXe-cL08BTTQixEnoyKAAAAGs"], referer: binance.com
[Thu Sep 17 15:11:23.671416 2026] [security2:error] [pid 971102:tid 971304] [client 4.240.114.86:61771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxXe-cL08BTTQixEnoyKwAAAEY"], referer: binance.com
[Thu Sep 17 15:11:23.682537 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/textcolor/"] [unique_id "aqxXe-cL08BTTQixEnoyKgAAAGg"]
[Thu Sep 17 15:11:23.756394 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/deploy/.env"] [unique_id "aqxXe-cL08BTTQixEnoyLgAAAHE"]
[Thu Sep 17 15:11:23.823596 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/textcolor/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXe-cL08BTTQixEnoyMAAAAA8"]
[Thu Sep 17 15:11:23.937511 2026] [security2:error] [pid 971102:tid 971324] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/build/.env"] [unique_id "aqxXe-cL08BTTQixEnoyNAAAAFo"]
[Thu Sep 17 15:11:24.143291 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/dist/.env"] [unique_id "aqxXfOcL08BTTQixEnoyOwAAAEg"]
[Thu Sep 17 15:11:24.151451 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyNQAAAAM"]
[Thu Sep 17 15:11:24.151479 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXe-cL08BTTQixEnoyNQAAAAM"]
[Thu Sep 17 15:11:24.321487 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wordpress/"] [unique_id "aqxXfOcL08BTTQixEnoyPwAAAHs"]
[Thu Sep 17 15:11:24.361343 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/public_html/.env"] [unique_id "aqxXfOcL08BTTQixEnoyQgAAAAw"]
[Thu Sep 17 15:11:24.488226 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wordpress/"] [unique_id "aqxXfOcL08BTTQixEnoyRwAAADI"]
[Thu Sep 17 15:11:24.602250 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/htdocs/.env"] [unique_id "aqxXfOcL08BTTQixEnoySwAAAEk"]
[Thu Sep 17 15:11:24.630284 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wordpress/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXfOcL08BTTQixEnoyTwAAABM"]
[Thu Sep 17 15:11:24.935751 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/www/.env"] [unique_id "aqxXfOcL08BTTQixEnoyVwAAABo"]
[Thu Sep 17 15:11:24.988323 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfOcL08BTTQixEnoyUwAAADE"]
[Thu Sep 17 15:11:24.988350 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfOcL08BTTQixEnoyUwAAADE"]
[Thu Sep 17 15:11:25.129227 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpautoresize/"] [unique_id "aqxXfecL08BTTQixEnoyXAAAAEs"]
[Thu Sep 17 15:11:25.154774 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/html/.env"] [unique_id "aqxXfecL08BTTQixEnoyXQAAABE"]
[Thu Sep 17 15:11:25.166312 2026] [security2:error] [pid 971102:tid 971275] [client 154.190.208.131:41459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXfecL08BTTQixEnoyXgAAACk"]
[Thu Sep 17 15:11:25.166385 2026] [security2:error] [pid 971102:tid 971275] [client 154.190.208.131:41459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXfecL08BTTQixEnoyXgAAACk"]
[Thu Sep 17 15:11:25.289569 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpautoresize/"] [unique_id "aqxXfecL08BTTQixEnoyYAAAAF8"]
[Thu Sep 17 15:11:25.432603 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpautoresize/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXfecL08BTTQixEnoyZQAAAEc"]
[Thu Sep 17 15:11:25.441907 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/live/.env"] [unique_id "aqxXfecL08BTTQixEnoyZgAAADM"]
[Thu Sep 17 15:11:25.619468 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/prod/.env"] [unique_id "aqxXfecL08BTTQixEnoyagAAACA"]
[Thu Sep 17 15:11:25.765862 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfecL08BTTQixEnoyZwAAAE4"]
[Thu Sep 17 15:11:25.765886 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfecL08BTTQixEnoyZwAAAE4"]
[Thu Sep 17 15:11:25.806637 2026] [security2:error] [pid 971102:tid 971258] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/dev/.env"] [unique_id "aqxXfecL08BTTQixEnoybAAAABg"]
[Thu Sep 17 15:11:25.926615 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpdialogs/"] [unique_id "aqxXfecL08BTTQixEnoycAAAAFg"]
[Thu Sep 17 15:11:26.088116 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpdialogs/"] [unique_id "aqxXfucL08BTTQixEnoycgAAADs"]
[Thu Sep 17 15:11:26.201916 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/staging/.env"] [unique_id "aqxXfucL08BTTQixEnoydQAAAFs"]
[Thu Sep 17 15:11:26.229087 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpdialogs/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXfucL08BTTQixEnoydgAAAFc"]
[Thu Sep 17 15:11:26.495857 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/opt/.env"] [unique_id "aqxXfucL08BTTQixEnoyfQAAAHk"]
[Thu Sep 17 15:11:26.564143 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfucL08BTTQixEnoyeQAAAHw"]
[Thu Sep 17 15:11:26.564163 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXfucL08BTTQixEnoyeQAAAHw"]
[Thu Sep 17 15:11:26.658815 2026] [security2:error] [pid 971102:tid 971299] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/laravel/.env"] [unique_id "aqxXfucL08BTTQixEnoygAAAAEE"]
[Thu Sep 17 15:11:26.726160 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpeditimage/"] [unique_id "aqxXfucL08BTTQixEnoygQAAACc"]
[Thu Sep 17 15:11:26.848240 2026] [security2:error] [pid 971102:tid 971315] [client 49.51.196.42:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.196.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mycarydentist.com"] [uri "/index.php"] [unique_id "aqxXfucL08BTTQixEnoygwAAAFE"]
[Thu Sep 17 15:11:26.882233 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpeditimage/"] [unique_id "aqxXfucL08BTTQixEnoyhAAAABc"]
[Thu Sep 17 15:11:27.025894 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpeditimage/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXf-cL08BTTQixEnoyigAAAAw"]
[Thu Sep 17 15:11:27.117304 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/symfony/.env"] [unique_id "aqxXf-cL08BTTQixEnoyjQAAAH0"]
[Thu Sep 17 15:11:27.148461 2026] [security2:error] [pid 971102:tid 971357] [client 45.169.98.18:55627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXf-cL08BTTQixEnoyjgAAAHs"]
[Thu Sep 17 15:11:27.148575 2026] [security2:error] [pid 971102:tid 971357] [client 45.169.98.18:55627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXf-cL08BTTQixEnoyjgAAAHs"]
[Thu Sep 17 15:11:27.359626 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoyjwAAABw"]
[Thu Sep 17 15:11:27.359655 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoyjwAAABw"]
[Thu Sep 17 15:11:27.375395 2026] [fcgid:warn] [pid 971102:tid 971344] (70014)End of file found: [client 106.63.26.7:16959] mod_fcgid: can't get data from http client
[Thu Sep 17 15:11:27.411815 2026] [security2:error] [pid 971102:tid 971238] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/wordpress/.env"] [unique_id "aqxXf-cL08BTTQixEnoylQAAAAQ"]
[Thu Sep 17 15:11:27.508211 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpemoji/"] [unique_id "aqxXf-cL08BTTQixEnoymQAAACM"]
[Thu Sep 17 15:11:27.576236 2026] [security2:error] [pid 971102:tid 971279] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/wp/.env"] [unique_id "aqxXf-cL08BTTQixEnoymgAAAC0"]
[Thu Sep 17 15:11:27.663161 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpemoji/"] [unique_id "aqxXf-cL08BTTQixEnoynAAAADw"]
[Thu Sep 17 15:11:27.799413 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cms/.env"] [unique_id "aqxXf-cL08BTTQixEnoyngAAAAs"]
[Thu Sep 17 15:11:27.807682 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpemoji/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXf-cL08BTTQixEnoynwAAACQ"]
[Thu Sep 17 15:11:27.936981 2026] [security2:error] [pid 971102:tid 971308] [client 4.240.114.86:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxXf-cL08BTTQixEnoypQAAAEo"], referer: binance.com
[Thu Sep 17 15:11:28.092867 2026] [security2:error] [pid 971102:tid 971339] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/drupal/.env"] [unique_id "aqxXgOcL08BTTQixEnoyrQAAAGk"]
[Thu Sep 17 15:11:28.160257 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoypwAAAE8"]
[Thu Sep 17 15:11:28.160284 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXf-cL08BTTQixEnoypwAAAE8"]
[Thu Sep 17 15:11:28.304009 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpgallery/"] [unique_id "aqxXgOcL08BTTQixEnoysQAAADU"]
[Thu Sep 17 15:11:28.305779 2026] [security2:error] [pid 971102:tid 971287] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/joomla/.env"] [unique_id "aqxXgOcL08BTTQixEnoysgAAADU"]
[Thu Sep 17 15:11:28.322888 2026] [security2:error] [pid 971102:tid 971314] [client 52.167.144.170:27320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxXgOcL08BTTQixEnoyqQAAUEA"]
[Thu Sep 17 15:11:28.465196 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpgallery/"] [unique_id "aqxXgOcL08BTTQixEnoyuAAAAEc"]
[Thu Sep 17 15:11:28.532185 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/magento/.env"] [unique_id "aqxXgOcL08BTTQixEnoyuQAAADM"]
[Thu Sep 17 15:11:28.627401 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpgallery/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgOcL08BTTQixEnoyuwAAACw"]
[Thu Sep 17 15:11:28.747762 2026] [security2:error] [pid 971102:tid 971337] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/shopify/.env"] [unique_id "aqxXgOcL08BTTQixEnoyvgAAAGc"]
[Thu Sep 17 15:11:28.810249 2026] [security2:error] [pid 971102:tid 971334] [client 198.211.117.118:52610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgOcL08BTTQixEnoywQAAAGQ"]
[Thu Sep 17 15:11:28.950894 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgOcL08BTTQixEnoyvwAAAA4"]
[Thu Sep 17 15:11:28.950917 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgOcL08BTTQixEnoyvwAAAA4"]
[Thu Sep 17 15:11:29.009610 2026] [security2:error] [pid 971102:tid 971320] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/prestashop/.env"] [unique_id "aqxXgecL08BTTQixEnoyygAAAFY"]
[Thu Sep 17 15:11:29.031319 2026] [security2:error] [pid 971102:tid 971322] [client 198.211.117.118:52624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoyzAAAAFg"]
[Thu Sep 17 15:11:29.092221 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wplink/"] [unique_id "aqxXgecL08BTTQixEnoyzgAAAEY"]
[Thu Sep 17 15:11:29.253508 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wplink/"] [unique_id "aqxXgecL08BTTQixEnoy0AAAAHA"]
[Thu Sep 17 15:11:29.260061 2026] [security2:error] [pid 971102:tid 971340] [client 198.211.117.118:52640] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy0QAAAGo"]
[Thu Sep 17 15:11:29.260312 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/codeigniter/.env"] [unique_id "aqxXgecL08BTTQixEnoy0gAAAHE"]
[Thu Sep 17 15:11:29.407629 2026] [security2:error] [pid 971102:tid 971261] [client 185.117.225.169:33542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "www.idautovic.com"] [uri "/robots.txt"] [unique_id "aqxXgecL08BTTQixEnoy1AAAABs"]
[Thu Sep 17 15:11:29.426006 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wplink/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgecL08BTTQixEnoy1wAAAEg"]
[Thu Sep 17 15:11:29.481396 2026] [security2:error] [pid 971102:tid 971295] [client 198.211.117.118:52644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy2wAAAD0"]
[Thu Sep 17 15:11:29.555995 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cakephp/.env"] [unique_id "aqxXgecL08BTTQixEnoy3AAAAAA"]
[Thu Sep 17 15:11:29.594413 2026] [security2:error] [pid 971102:tid 971311] [client 185.55.149.49:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy3wAAAE0"]
[Thu Sep 17 15:11:29.594516 2026] [security2:error] [pid 971102:tid 971311] [client 185.55.149.49:59605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy3wAAAE0"]
[Thu Sep 17 15:11:29.644700 2026] [security2:error] [pid 971102:tid 971355] [client 156.192.234.52:62961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy4AAAAHk"]
[Thu Sep 17 15:11:29.646154 2026] [security2:error] [pid 971102:tid 971355] [client 156.192.234.52:62961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgecL08BTTQixEnoy4AAAAHk"]
[Thu Sep 17 15:11:29.690673 2026] [security2:error] [pid 971102:tid 971357] [client 198.211.117.118:52648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy4QAAAHs"]
[Thu Sep 17 15:11:29.744972 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgecL08BTTQixEnoy3QAAADk"]
[Thu Sep 17 15:11:29.744991 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgecL08BTTQixEnoy3QAAADk"]
[Thu Sep 17 15:11:29.783780 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/zend/.env"] [unique_id "aqxXgecL08BTTQixEnoy4gAAAHc"]
[Thu Sep 17 15:11:29.886949 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wptextpattern/"] [unique_id "aqxXgecL08BTTQixEnoy5wAAAC0"]
[Thu Sep 17 15:11:29.916739 2026] [security2:error] [pid 971102:tid 971344] [client 198.211.117.118:52658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "relvnv.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxXgecL08BTTQixEnoy6gAAAG4"]
[Thu Sep 17 15:11:29.996738 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/yii/.env"] [unique_id "aqxXgecL08BTTQixEnoy7gAAAAo"]
[Thu Sep 17 15:11:30.045719 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wptextpattern/"] [unique_id "aqxXgucL08BTTQixEnoy8AAAAAs"]
[Thu Sep 17 15:11:30.188618 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wptextpattern/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgucL08BTTQixEnoy8wAAAH4"]
[Thu Sep 17 15:11:30.212178 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/laravel5/.env"] [unique_id "aqxXgucL08BTTQixEnoy9AAAABI"]
[Thu Sep 17 15:11:30.391054 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/v1/.env"] [unique_id "aqxXgucL08BTTQixEnoy_gAAAA0"]
[Thu Sep 17 15:11:30.465132 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgucL08BTTQixEnozAAAAAB4"]
[Thu Sep 17 15:11:30.465258 2026] [security2:error] [pid 971102:tid 971264] [client 115.244.164.14:50904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXgucL08BTTQixEnozAAAAAB4"]
[Thu Sep 17 15:11:30.528387 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgucL08BTTQixEnoy-gAAADg"]
[Thu Sep 17 15:11:30.528408 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXgucL08BTTQixEnoy-gAAADg"]
[Thu Sep 17 15:11:30.567633 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/v2/.env"] [unique_id "aqxXgucL08BTTQixEnozAgAAAFI"]
[Thu Sep 17 15:11:30.675805 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpview/"] [unique_id "aqxXgucL08BTTQixEnozBQAAABM"]
[Thu Sep 17 15:11:30.809231 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/v3/.env"] [unique_id "aqxXgucL08BTTQixEnozCAAAAFA"]
[Thu Sep 17 15:11:30.843916 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpview/"] [unique_id "aqxXgucL08BTTQixEnozCQAAAEc"]
[Thu Sep 17 15:11:30.986822 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/plugins/wpview/wp-includes/js/tinymce/plugins/"] [unique_id "aqxXgucL08BTTQixEnozEwAAACw"]
[Thu Sep 17 15:11:31.010210 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/v1/.env"] [unique_id "aqxXg-cL08BTTQixEnozFAAAAGY"]
[Thu Sep 17 15:11:31.187837 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/v2/.env"] [unique_id "aqxXg-cL08BTTQixEnozGQAAAA4"]
[Thu Sep 17 15:11:31.318897 2026] [security2:error] [pid 971102:tid 971342] [client 5.189.145.112:62156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxXg-cL08BTTQixEnozHAAAAGw"], referer: binance.com
[Thu Sep 17 15:11:31.335128 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozFwAAAGQ"]
[Thu Sep 17 15:11:31.335149 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozFwAAAGQ"]
[Thu Sep 17 15:11:31.350254 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/rest/.env"] [unique_id "aqxXg-cL08BTTQixEnozHgAAAFs"]
[Thu Sep 17 15:11:31.358901 2026] [security2:error] [pid 971102:tid 971254] [client 157.55.39.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXgucL08BTTQixEnozEAAAABQ"]
[Thu Sep 17 15:11:31.477676 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/"] [unique_id "aqxXg-cL08BTTQixEnozJgAAAEE"]
[Thu Sep 17 15:11:31.653064 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/graphql/.env"] [unique_id "aqxXg-cL08BTTQixEnozKAAAAEg"]
[Thu Sep 17 15:11:31.681506 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/"] [unique_id "aqxXg-cL08BTTQixEnozKQAAAAM"]
[Thu Sep 17 15:11:31.805272 2026] [security2:error] [pid 971102:tid 971257] [client 138.199.7.239:1344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxXg-cL08BTTQixEnozKgAAF0w"]
[Thu Sep 17 15:11:31.826944 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wp-includes/js/tinymce/"] [unique_id "aqxXg-cL08BTTQixEnozLQAAAAw"]
[Thu Sep 17 15:11:31.945841 2026] [security2:error] [pid 971102:tid 971356] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/gateway/.env"] [unique_id "aqxXg-cL08BTTQixEnozNQAAAHo"]
[Thu Sep 17 15:11:32.152845 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozNgAAACc"]
[Thu Sep 17 15:11:32.152862 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXg-cL08BTTQixEnozNgAAACc"]
[Thu Sep 17 15:11:32.199157 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/microservice/.env"] [unique_id "aqxXhOcL08BTTQixEnozOgAAAHc"]
[Thu Sep 17 15:11:32.322790 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhOcL08BTTQixEnozPAAAAG8"]
[Thu Sep 17 15:11:32.471092 2026] [security2:error] [pid 971102:tid 971279] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/service/.env"] [unique_id "aqxXhOcL08BTTQixEnozQgAAAC0"]
[Thu Sep 17 15:11:32.483767 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhOcL08BTTQixEnozQQAAADs"]
[Thu Sep 17 15:11:32.627222 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/wp-includes/js/tinymce/skins/"] [unique_id "aqxXhOcL08BTTQixEnozRAAAADI"]
[Thu Sep 17 15:11:32.744473 2026] [security2:error] [pid 971102:tid 971296] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/v3/.env"] [unique_id "aqxXhOcL08BTTQixEnozSgAAAD4"]
[Thu Sep 17 15:11:32.890949 2026] [security2:error] [pid 971102:tid 971269] [client 186.105.232.15:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXhOcL08BTTQixEnozUgAAACM"]
[Thu Sep 17 15:11:32.891061 2026] [security2:error] [pid 971102:tid 971269] [client 186.105.232.15:51548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXhOcL08BTTQixEnozUgAAACM"]
[Thu Sep 17 15:11:32.928075 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/dev/.env"] [unique_id "aqxXhOcL08BTTQixEnozVAAAAGM"]
[Thu Sep 17 15:11:32.956136 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhOcL08BTTQixEnozSwAAAH8"]
[Thu Sep 17 15:11:32.956156 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhOcL08BTTQixEnozSwAAAH8"]
[Thu Sep 17 15:11:33.091977 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/api/staging/.env"] [unique_id "aqxXhecL08BTTQixEnozWgAAAEA"]
[Thu Sep 17 15:11:33.111077 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/fonts/"] [unique_id "aqxXhecL08BTTQixEnozWwAAAAg"]
[Thu Sep 17 15:11:33.278445 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/fonts/"] [unique_id "aqxXhecL08BTTQixEnozXgAAAGI"]
[Thu Sep 17 15:11:33.424615 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/fonts/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhecL08BTTQixEnozYgAAAGY"]
[Thu Sep 17 15:11:33.470516 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/vendor/.env"] [unique_id "aqxXhecL08BTTQixEnozZQAAAFU"]
[Thu Sep 17 15:11:33.688832 2026] [security2:error] [pid 971102:tid 971342] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/lib/.env"] [unique_id "aqxXhecL08BTTQixEnozagAAAGw"]
[Thu Sep 17 15:11:33.767845 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhecL08BTTQixEnozZwAAAE4"]
[Thu Sep 17 15:11:33.767868 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhecL08BTTQixEnozZwAAAE4"]
[Thu Sep 17 15:11:33.792873 2026] [security2:error] [pid 971102:tid 971325] [client 223.109.252.148:36606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "talent-in-borders.com"] [uri "/tag/beacon/"] [unique_id "aqxXhecL08BTTQixEnozbAAAAFs"]
[Thu Sep 17 15:11:33.792981 2026] [security2:error] [pid 971102:tid 971325] [client 223.109.252.148:36606] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "talent-in-borders.com"] [uri "/tag/beacon/"] [unique_id "aqxXhecL08BTTQixEnozbAAAAFs"]
[Thu Sep 17 15:11:33.904973 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:53482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/resources/.env"] [unique_id "aqxXhecL08BTTQixEnozcwAAACY"]
[Thu Sep 17 15:11:33.922275 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "aqxXhecL08BTTQixEnozdAAAAFY"]
[Thu Sep 17 15:11:34.081992 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "aqxXhucL08BTTQixEnozewAAABc"]
[Thu Sep 17 15:11:34.226948 2026] [security2:error] [pid 971102:tid 971267] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "aqxXhucL08BTTQixEnozggAAACE"]
[Thu Sep 17 15:11:34.262773 2026] [security2:error] [pid 971102:tid 971277] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxXhucL08BTTQixEnozhQAAACs"]
[Thu Sep 17 15:11:34.305749 2026] [security2:error] [pid 971102:tid 971295] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxXhucL08BTTQixEnozeQAAPVg"]
[Thu Sep 17 15:11:34.409583 2026] [security2:error] [pid 971102:tid 971245] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozlgAAAAs"], referer: https://cpcalendars.sav.yiu.mybluehost.me/robots.txt
[Thu Sep 17 15:11:34.417602 2026] [security2:error] [pid 971102:tid 971262] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozjAAAHF4"], referer: https://cpcalendars.sav.yiu.mybluehost.me/robots.txt
[Thu Sep 17 15:11:34.480087 2026] [security2:error] [pid 971102:tid 971250] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/assets/.env"] [unique_id "aqxXhucL08BTTQixEnozmwAAABA"]
[Thu Sep 17 15:11:34.524827 2026] [security2:error] [pid 971102:tid 971318] [client 4.240.114.86:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxXhucL08BTTQixEnozngAAAFQ"], referer: binance.com
[Thu Sep 17 15:11:34.549166 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhucL08BTTQixEnozjgAAAC0"]
[Thu Sep 17 15:11:34.549187 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXhucL08BTTQixEnozjgAAAC0"]
[Thu Sep 17 15:11:34.557974 2026] [security2:error] [pid 971102:tid 971316] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnoznwAAAFI"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.604975 2026] [security2:error] [pid 971102:tid 971269] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozmAAAI2I"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.634570 2026] [security2:error] [pid 971102:tid 971283] [client 74.7.230.40:53718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.freemarkjordan.com"] [uri "/robots.txt"] [unique_id "aqxXhucL08BTTQixEnozoQAAADE"]
[Thu Sep 17 15:11:34.672531 2026] [security2:error] [pid 971102:tid 971240] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/uploads/.env"] [unique_id "aqxXhucL08BTTQixEnozpgAAAAY"]
[Thu Sep 17 15:11:34.675595 2026] [security2:error] [pid 971102:tid 971242] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozpwAAAAg"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.678747 2026] [security2:error] [pid 971102:tid 971354] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozpAAAeGU"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.719526 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/"] [unique_id "aqxXhucL08BTTQixEnozqgAAADg"]
[Thu Sep 17 15:11:34.839971 2026] [security2:error] [pid 971102:tid 971275] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozrwAAACk"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.905250 2026] [security2:error] [pid 971102:tid 971264] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozqwAAHmY"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:34.996962 2026] [security2:error] [pid 971102:tid 971351] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnozuQAAAHU"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:35.011540 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/internal/.env"] [unique_id "aqxXh-cL08BTTQixEnozugAAAAE"]
[Thu Sep 17 15:11:35.035241 2026] [security2:error] [pid 971102:tid 971304] [client 74.7.228.54:35502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.sav.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxXhucL08BTTQixEnoztQAARmk"], referer: https://cpcalendars.sav.yiu.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:11:35.039617 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/"] [unique_id "aqxXh-cL08BTTQixEnozuwAAAF4"]
[Thu Sep 17 15:11:35.181734 2026] [security2:error] [pid 971102:tid 971261] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/tools/.env"] [unique_id "aqxXh-cL08BTTQixEnozwwAAABs"]
[Thu Sep 17 15:11:35.193956 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/wp-includes/js/tinymce/skins/"] [unique_id "aqxXh-cL08BTTQixEnozxQAAADw"]
[Thu Sep 17 15:11:35.203813 2026] [autoindex:error] [pid 971102:tid 971268] [client 106.63.26.14:63368] AH01276: Cannot serve directory /home1/vxmhuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://vxm.hui.mybluehost.me/
[Thu Sep 17 15:11:35.519242 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXh-cL08BTTQixEnozyQAAAFk"]
[Thu Sep 17 15:11:35.519265 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXh-cL08BTTQixEnozyQAAAFk"]
[Thu Sep 17 15:11:35.547317 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/scripts/.env"] [unique_id "aqxXh-cL08BTTQixEnoz1QAAAAs"]
[Thu Sep 17 15:11:35.658525 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/"] [unique_id "aqxXh-cL08BTTQixEnoz2QAAADI"]
[Thu Sep 17 15:11:35.701957 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXh-cL08BTTQixEnoz3AAAABc"]
[Thu Sep 17 15:11:35.704954 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXh-cL08BTTQixEnoz3AAAABc"]
[Thu Sep 17 15:11:35.839045 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/"] [unique_id "aqxXh-cL08BTTQixEnoz4QAAACg"]
[Thu Sep 17 15:11:35.976491 2026] [security2:error] [pid 971102:tid 971269] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/bin/.env"] [unique_id "aqxXh-cL08BTTQixEnoz5wAAACM"]
[Thu Sep 17 15:11:35.981353 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/skins/wordpress/images/wp-includes/js/tinymce/skins/wordpress/"] [unique_id "aqxXh-cL08BTTQixEnoz6AAAADE"]
[Thu Sep 17 15:11:36.169963 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sbin/.env"] [unique_id "aqxXiOcL08BTTQixEnoz7QAAAB0"]
[Thu Sep 17 15:11:36.320248 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiOcL08BTTQixEnoz6wAAAEA"]
[Thu Sep 17 15:11:36.320273 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiOcL08BTTQixEnoz6wAAAEA"]
[Thu Sep 17 15:11:36.394711 2026] [security2:error] [pid 971102:tid 971360] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/local/.env"] [unique_id "aqxXiOcL08BTTQixEno0BgAAAH4"]
[Thu Sep 17 15:11:36.466488 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiOcL08BTTQixEno0BwAAAEM"]
[Thu Sep 17 15:11:36.582861 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/portal/.env"] [unique_id "aqxXiOcL08BTTQixEno0DAAAAEg"]
[Thu Sep 17 15:11:36.713214 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiOcL08BTTQixEno0DQAAACk"]
[Thu Sep 17 15:11:36.786085 2026] [security2:error] [pid 971102:tid 971327] [client 167.235.143.113:46336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxXiOcL08BTTQixEno0EgAAAF0"], referer: https://faewave.com
[Thu Sep 17 15:11:36.812089 2026] [log_config:warn] [pid 955873:tid 956130] (32)Broken pipe: [client 198.71.60.165:54714] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log
[Thu Sep 17 15:11:36.812106 2026] [log_config:warn] [pid 955873:tid 956130] (32)Broken pipe: [client 198.71.60.165:54714] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log
[Thu Sep 17 15:11:36.868757 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/wp-includes/js/tinymce/"] [unique_id "aqxXiOcL08BTTQixEno0FgAAAAw"]
[Thu Sep 17 15:11:37.010305 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/dashboard/.env"] [unique_id "aqxXiecL08BTTQixEno0IAAAAGg"]
[Thu Sep 17 15:11:37.176235 2026] [security2:error] [pid 971102:tid 971335] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/panel/.env"] [unique_id "aqxXiecL08BTTQixEno0LgAAAGU"]
[Thu Sep 17 15:11:37.211766 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0IQAAACY"]
[Thu Sep 17 15:11:37.211786 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0IQAAACY"]
[Thu Sep 17 15:11:37.357948 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "aqxXiecL08BTTQixEno0PwAAAHk"]
[Thu Sep 17 15:11:37.524458 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "aqxXiecL08BTTQixEno0SAAAAHE"]
[Thu Sep 17 15:11:37.547474 2026] [security2:error] [pid 971102:tid 971310] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/crm/.env"] [unique_id "aqxXiecL08BTTQixEno0SgAAAEw"]
[Thu Sep 17 15:11:37.642895 2026] [security2:error] [pid 971102:tid 971258] [client 45.169.98.18:56193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXiecL08BTTQixEno0UgAAABg"]
[Thu Sep 17 15:11:37.642977 2026] [security2:error] [pid 971102:tid 971258] [client 45.169.98.18:56193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXiecL08BTTQixEno0UgAAABg"]
[Thu Sep 17 15:11:37.677641 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/inlite/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiecL08BTTQixEno0VgAAAG4"]
[Thu Sep 17 15:11:37.816508 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/erp/.env"] [unique_id "aqxXiecL08BTTQixEno0WAAAAAo"]
[Thu Sep 17 15:11:37.985773 2026] [security2:error] [pid 971102:tid 971240] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/shop/.env"] [unique_id "aqxXiecL08BTTQixEno0YAAAAAY"]
[Thu Sep 17 15:11:38.023831 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0WQAAABM"]
[Thu Sep 17 15:11:38.023854 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiecL08BTTQixEno0WQAAABM"]
[Thu Sep 17 15:11:38.166858 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/modern/"] [unique_id "aqxXiucL08BTTQixEno0YwAAAAI"]
[Thu Sep 17 15:11:38.240270 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/store/.env"] [unique_id "aqxXiucL08BTTQixEno0ZAAAAHg"]
[Thu Sep 17 15:11:38.336324 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/modern/"] [unique_id "aqxXiucL08BTTQixEno0aQAAAEk"]
[Thu Sep 17 15:11:38.472566 2026] [security2:error] [pid 971102:tid 971265] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/saas/.env"] [unique_id "aqxXiucL08BTTQixEno0dQAAAB8"]
[Thu Sep 17 15:11:38.489890 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/themes/modern/wp-includes/js/tinymce/themes/"] [unique_id "aqxXiucL08BTTQixEno0dgAAACw"]
[Thu Sep 17 15:11:38.538046 2026] [security2:error] [pid 971102:tid 971275] [client 5.189.145.112:59535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxXiucL08BTTQixEno0dwAAACk"], referer: binance.com
[Thu Sep 17 15:11:38.677749 2026] [security2:error] [pid 971102:tid 971322] [client 4.240.114.86:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXiucL08BTTQixEno0fwAAAFg"], referer: binance.com
[Thu Sep 17 15:11:38.715879 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/client/.env"] [unique_id "aqxXiucL08BTTQixEno0ggAAAAw"]
[Thu Sep 17 15:11:38.830531 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiucL08BTTQixEno0egAAAGw"]
[Thu Sep 17 15:11:38.830559 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXiucL08BTTQixEno0egAAAGw"]
[Thu Sep 17 15:11:38.911623 2026] [security2:error] [pid 971102:tid 971300] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/project/.env"] [unique_id "aqxXiucL08BTTQixEno0iQAAAEI"]
[Thu Sep 17 15:11:38.970204 2026] [security2:error] [pid 971102:tid 971152] [remote 216.73.217.142:51408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxXiucL08BTTQixEno0iwAAPDA"]
[Thu Sep 17 15:11:38.972087 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "aqxXiucL08BTTQixEno0jAAAADw"]
[Thu Sep 17 15:11:39.065586 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/admin-panel/.env"] [unique_id "aqxXi-cL08BTTQixEno0kAAAACY"]
[Thu Sep 17 15:11:39.123751 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "aqxXi-cL08BTTQixEno0kwAAAEU"]
[Thu Sep 17 15:11:39.240532 2026] [security2:error] [pid 971102:tid 971351] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/control-panel/.env"] [unique_id "aqxXi-cL08BTTQixEno0lgAAAHU"]
[Thu Sep 17 15:11:39.270548 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:43512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/utils/wp-includes/js/tinymce/"] [unique_id "aqxXi-cL08BTTQixEno0mQAAAHM"]
[Thu Sep 17 15:11:39.280905 2026] [security2:error] [pid 971102:tid 971243] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0kgAAAAk"]
[Thu Sep 17 15:11:39.460138 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/user-panel/.env"] [unique_id "aqxXi-cL08BTTQixEno0ogAAAAA"]
[Thu Sep 17 15:11:39.629465 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0oAAAAG8"]
[Thu Sep 17 15:11:39.629489 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:45918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0oAAAAG8"]
[Thu Sep 17 15:11:39.810319 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/node/.env"] [unique_id "aqxXi-cL08BTTQixEno0qAAAAFI"]
[Thu Sep 17 15:11:39.840897 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env"] [unique_id "aqxXi-cL08BTTQixEno0qQAAADQ"]
[Thu Sep 17 15:11:39.910843 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:37244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "aqxXi-cL08BTTQixEno0rQAAAEo"]
[Thu Sep 17 15:11:39.910937 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:37244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "aqxXi-cL08BTTQixEno0rQAAAEo"]
[Thu Sep 17 15:11:40.021306 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/express/.env"] [unique_id "aqxXjOcL08BTTQixEno0sAAAAE8"]
[Thu Sep 17 15:11:40.186037 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:37254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxXjOcL08BTTQixEno0twAAADE"]
[Thu Sep 17 15:11:40.187033 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0rgAAAA0"]
[Thu Sep 17 15:11:40.193056 2026] [security2:error] [pid 971102:tid 971277] [client 156.192.234.52:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0uAAAACs"]
[Thu Sep 17 15:11:40.194500 2026] [security2:error] [pid 971102:tid 971277] [client 156.192.234.52:63566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0uAAAACs"]
[Thu Sep 17 15:11:40.253958 2026] [security2:error] [pid 971102:tid 971354] [client 74.7.241.182:53512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.commcapusa.gcpmanagement.com"] [uri "/robots.txt"] [unique_id "aqxXjOcL08BTTQixEno0uQAAeDQ"]
[Thu Sep 17 15:11:40.267241 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/next/.env"] [unique_id "aqxXjOcL08BTTQixEno0ugAAAEc"]
[Thu Sep 17 15:11:40.342160 2026] [security2:error] [pid 971102:tid 971274] [client 185.55.149.49:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0vQAAACg"]
[Thu Sep 17 15:11:40.342310 2026] [security2:error] [pid 971102:tid 971274] [client 185.55.149.49:60236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno0vQAAACg"]
[Thu Sep 17 15:11:40.420296 2026] [security2:error] [pid 971102:tid 971278] [client 34.94.67.131:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php"] [unique_id "aqxXjOcL08BTTQixEno0wwAAACw"]
[Thu Sep 17 15:11:40.490485 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/nuxt/.env"] [unique_id "aqxXjOcL08BTTQixEno0xAAAADg"]
[Thu Sep 17 15:11:40.564703 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjOcL08BTTQixEno0vgAAAE0"]
[Thu Sep 17 15:11:40.632408 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxXjOcL08BTTQixEno0xgAAACk"]
[Thu Sep 17 15:11:40.743256 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/nest/.env"] [unique_id "aqxXjOcL08BTTQixEno0yAAAAB4"]
[Thu Sep 17 15:11:40.770052 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxXjOcL08BTTQixEno0yQAAAE4"]
[Thu Sep 17 15:11:40.770169 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:37254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/php-compat/readonly.php"] [unique_id "aqxXjOcL08BTTQixEno0yQAAAE4"]
[Thu Sep 17 15:11:40.925563 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjOcL08BTTQixEno0xwAAAF0"]
[Thu Sep 17 15:11:40.933893 2026] [security2:error] [pid 971102:tid 971259] [client 34.94.67.131:47580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/info.php"] [unique_id "aqxXjOcL08BTTQixEno0zAAAABk"]
[Thu Sep 17 15:11:40.960840 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/react/.env"] [unique_id "aqxXjOcL08BTTQixEno00AAAAAU"]
[Thu Sep 17 15:11:40.990501 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:51537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno00gAAAGY"]
[Thu Sep 17 15:11:40.990608 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:51537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXjOcL08BTTQixEno00gAAAGY"]
[Thu Sep 17 15:11:40.998852 2026] [security2:error] [pid 971102:tid 971357] [client 204.14.250.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxXi-cL08BTTQixEno0mwAAAHs"], referer: https://instagram.com/
[Thu Sep 17 15:11:41.070116 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:37258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxXjecL08BTTQixEno01gAAAGU"]
[Thu Sep 17 15:11:41.166257 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/vue/.env"] [unique_id "aqxXjecL08BTTQixEno02QAAACY"]
[Thu Sep 17 15:11:41.230699 2026] [authz_core:error] [pid 971102:tid 971359] [client 143.244.57.120:59052] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/PHPMailer/error_log
[Thu Sep 17 15:11:41.234435 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxXjecL08BTTQixEno02wAAAH0"]
[Thu Sep 17 15:11:41.258104 2026] [security2:error] [pid 971102:tid 971249] [client 34.94.67.131:47596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/php.php"] [unique_id "aqxXjecL08BTTQixEno03AAAAA8"]
[Thu Sep 17 15:11:41.293616 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjecL08BTTQixEno01wAAAGo"]
[Thu Sep 17 15:11:41.376999 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/angular/.env"] [unique_id "aqxXjecL08BTTQixEno03QAAAHk"]
[Thu Sep 17 15:11:41.380336 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxXjecL08BTTQixEno03gAAADk"]
[Thu Sep 17 15:11:41.380468 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxXjecL08BTTQixEno03gAAADk"]
[Thu Sep 17 15:11:41.530797 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/svelte/.env"] [unique_id "aqxXjecL08BTTQixEno05QAAADA"]
[Thu Sep 17 15:11:41.630074 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.67.131:47612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/i.php"] [unique_id "aqxXjecL08BTTQixEno05wAAAGk"]
[Thu Sep 17 15:11:41.650527 2026] [core:error] [pid 971102:tid 971163] [remote 74.7.175.151:52860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:11:41.650549 2026] [core:error] [pid 971102:tid 971163] [remote 74.7.175.151:52860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:11:41.650807 2026] [security2:error] [pid 971102:tid 971324] [client 74.7.175.151:52860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-529af5fc.qat.qby.mybluehost.me"] [uri "/website_529af5fc/index.php"] [unique_id "aqxXjecL08BTTQixEno06AAAWjs"]
[Thu Sep 17 15:11:41.652096 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjecL08BTTQixEno04gAAAHE"]
[Thu Sep 17 15:11:41.663157 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxXjecL08BTTQixEno06QAAAHw"]
[Thu Sep 17 15:11:41.663242 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxXjecL08BTTQixEno06QAAAHw"]
[Thu Sep 17 15:11:41.741221 2026] [security2:error] [pid 971102:tid 971279] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/vite/.env"] [unique_id "aqxXjecL08BTTQixEno06gAAAC0"]
[Thu Sep 17 15:11:41.954818 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxXjecL08BTTQixEno08QAAAD0"]
[Thu Sep 17 15:11:41.954915 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:37278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxXjecL08BTTQixEno08QAAAD0"]
[Thu Sep 17 15:11:42.007714 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjecL08BTTQixEno07AAAADQ"]
[Thu Sep 17 15:11:42.028643 2026] [security2:error] [pid 971102:tid 971240] [client 34.94.67.131:47614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/pi.php"] [unique_id "aqxXjucL08BTTQixEno09QAAAAY"]
[Thu Sep 17 15:11:42.080554 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/backup/.env"] [unique_id "aqxXjucL08BTTQixEno09gAAACs"]
[Thu Sep 17 15:11:42.165565 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.bak"] [unique_id "aqxXjucL08BTTQixEno09wAAABY"]
[Thu Sep 17 15:11:42.184614 2026] [security2:error] [pid 971102:tid 971309] [client 220.181.108.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxXjOcL08BTTQixEno0tAAAAEs"]
[Thu Sep 17 15:11:42.243632 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXjucL08BTTQixEno0-AAAACU"]
[Thu Sep 17 15:11:42.243743 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:37280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxXjucL08BTTQixEno0-AAAACU"]
[Thu Sep 17 15:11:42.310162 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/backups/.env"] [unique_id "aqxXjucL08BTTQixEno0-QAAAAc"]
[Thu Sep 17 15:11:42.323906 2026] [security2:error] [pid 971102:tid 971348] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.backup"] [unique_id "aqxXjucL08BTTQixEno0-gAAAHI"]
[Thu Sep 17 15:11:42.479758 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/old/.env"] [unique_id "aqxXjucL08BTTQixEno1AAAAACk"]
[Thu Sep 17 15:11:42.527598 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxXjucL08BTTQixEno1AQAAAA4"]
[Thu Sep 17 15:11:42.544217 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.67.131:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/pinfo.php"] [unique_id "aqxXjucL08BTTQixEno1AgAAAEg"]
[Thu Sep 17 15:11:42.645049 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/tmp/.env"] [unique_id "aqxXjucL08BTTQixEno1BAAAAAw"]
[Thu Sep 17 15:11:42.685282 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxXjucL08BTTQixEno1BQAAAE4"]
[Thu Sep 17 15:11:42.730638 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjucL08BTTQixEno0_wAAAFw"]
[Thu Sep 17 15:11:42.828290 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/random_compat/"] [unique_id "aqxXjucL08BTTQixEno1BwAAAGY"]
[Thu Sep 17 15:11:42.880160 2026] [security2:error] [pid 971102:tid 971353] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.old"] [unique_id "aqxXjucL08BTTQixEno1DAAAAHc"]
[Thu Sep 17 15:11:42.913723 2026] [security2:error] [pid 971102:tid 971319] [client 34.94.67.131:47626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/test.php"] [unique_id "aqxXjucL08BTTQixEno1DgAAAFU"]
[Thu Sep 17 15:11:43.140863 2026] [security2:error] [pid 971102:tid 971249] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/temp/.env"] [unique_id "aqxXj-cL08BTTQixEno1GAAAAA8"]
[Thu Sep 17 15:11:43.199402 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjucL08BTTQixEno1EQAAADM"]
[Thu Sep 17 15:11:43.199440 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXjucL08BTTQixEno1EQAAADM"]
[Thu Sep 17 15:11:43.228336 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXj-cL08BTTQixEno1EgAAAFE"]
[Thu Sep 17 15:11:43.485556 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxXj-cL08BTTQixEno1IwAAADc"]
[Thu Sep 17 15:11:43.506303 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/lab/.env"] [unique_id "aqxXj-cL08BTTQixEno1JgAAADA"]
[Thu Sep 17 15:11:43.535279 2026] [security2:error] [pid 971102:tid 971324] [client 34.94.67.131:47640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/p.php"] [unique_id "aqxXj-cL08BTTQixEno1JwAAAFo"]
[Thu Sep 17 15:11:43.581589 2026] [security2:error] [pid 971102:tid 971352] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXj-cL08BTTQixEno1HQAAAHY"]
[Thu Sep 17 15:11:43.647471 2026] [authz_core:error] [pid 971102:tid 971351] [client 143.244.57.120:59052] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/error_log
[Thu Sep 17 15:11:43.658296 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxXj-cL08BTTQixEno1KQAAAHU"]
[Thu Sep 17 15:11:43.667781 2026] [security2:error] [pid 971102:tid 971252] [client 51.8.102.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.arhitecturabuzau.ro"] [uri "/index.php"] [unique_id "aqxXiucL08BTTQixEno0bwAAABI"]
[Thu Sep 17 15:11:43.843259 2026] [security2:error] [pid 971102:tid 971318] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxXj-cL08BTTQixEno1LgAAAFQ"]
[Thu Sep 17 15:11:43.856624 2026] [security2:error] [pid 971102:tid 971321] [client 34.94.67.131:47646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/debug.php"] [unique_id "aqxXj-cL08BTTQixEno1LwAAAFc"]
[Thu Sep 17 15:11:43.886799 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cronlab/.env"] [unique_id "aqxXj-cL08BTTQixEno1MQAAAFA"]
[Thu Sep 17 15:11:43.929968 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXj-cL08BTTQixEno1KwAAAEo"]
[Thu Sep 17 15:11:44.055797 2026] [security2:error] [pid 971102:tid 971262] [client 186.105.232.15:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkOcL08BTTQixEno1OgAAABw"]
[Thu Sep 17 15:11:44.055899 2026] [security2:error] [pid 971102:tid 971262] [client 186.105.232.15:52165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkOcL08BTTQixEno1OgAAABw"]
[Thu Sep 17 15:11:44.147624 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cron/.env"] [unique_id "aqxXkOcL08BTTQixEno1PQAAAGM"]
[Thu Sep 17 15:11:44.238514 2026] [authz_core:error] [pid 971102:tid 971305] [client 143.244.57.120:59052] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/endpoints/error_log
[Thu Sep 17 15:11:44.248398 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "aqxXkOcL08BTTQixEno1PgAAAEc"]
[Thu Sep 17 15:11:44.274202 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1OwAAAF8"]
[Thu Sep 17 15:11:44.311346 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.67.131:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXkOcL08BTTQixEno1QAAAAEk"]
[Thu Sep 17 15:11:44.352006 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/en/.env"] [unique_id "aqxXkOcL08BTTQixEno1QgAAADg"]
[Thu Sep 17 15:11:44.421332 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/wp-includes/rest-api/"] [unique_id "aqxXkOcL08BTTQixEno1RgAAAB8"]
[Thu Sep 17 15:11:44.630884 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1RwAAAE0"]
[Thu Sep 17 15:11:44.710353 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/administrator/.env"] [unique_id "aqxXkOcL08BTTQixEno1TAAAAB4"]
[Thu Sep 17 15:11:44.764226 2026] [security2:error] [pid 971102:tid 971259] [client 34.94.67.131:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXkOcL08BTTQixEno1TwAAABk"]
[Thu Sep 17 15:11:44.783553 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1SwAAADU"]
[Thu Sep 17 15:11:44.783580 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1SwAAADU"]
[Thu Sep 17 15:11:44.928593 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxXkOcL08BTTQixEno1VgAAAC4"]
[Thu Sep 17 15:11:44.928753 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:37294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-categories-controller.php"] [unique_id "aqxXkOcL08BTTQixEno1VgAAAC4"]
[Thu Sep 17 15:11:44.997592 2026] [security2:error] [pid 971102:tid 971292] [client 34.94.67.131:47686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXkOcL08BTTQixEno1WgAAADo"]
[Thu Sep 17 15:11:45.087301 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkOcL08BTTQixEno1UwAAAAU"]
[Thu Sep 17 15:11:45.197550 2026] [security2:error] [pid 971102:tid 971267] [client 34.94.67.131:47694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXkecL08BTTQixEno1XQAAACE"]
[Thu Sep 17 15:11:45.204685 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:37308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxXkecL08BTTQixEno1XgAAADc"]
[Thu Sep 17 15:11:45.204797 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:37308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-list-controller.php"] [unique_id "aqxXkecL08BTTQixEno1XgAAADc"]
[Thu Sep 17 15:11:45.438048 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkecL08BTTQixEno1XwAAAFk"]
[Thu Sep 17 15:11:45.493607 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:37318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxXkecL08BTTQixEno1ZQAAAHY"]
[Thu Sep 17 15:11:45.493747 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:37318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-abilities-v1-run-controller.php"] [unique_id "aqxXkecL08BTTQixEno1ZQAAAHY"]
[Thu Sep 17 15:11:45.581747 2026] [security2:error] [pid 971102:tid 971302] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/psnlink/.env"] [unique_id "aqxXkecL08BTTQixEno1agAAAEQ"]
[Thu Sep 17 15:11:45.717494 2026] [security2:error] [pid 971102:tid 971279] [client 34.94.67.131:47702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXkecL08BTTQixEno1bQAAAC0"]
[Thu Sep 17 15:11:45.754129 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/exapi/.env"] [unique_id "aqxXkecL08BTTQixEno1bgAAACQ"]
[Thu Sep 17 15:11:45.776764 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxXkecL08BTTQixEno1bwAAADI"]
[Thu Sep 17 15:11:45.776854 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:37330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-application-passwords-controller.php"] [unique_id "aqxXkecL08BTTQixEno1bwAAADI"]
[Thu Sep 17 15:11:45.795211 2026] [security2:error] [pid 971102:tid 971296] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkecL08BTTQixEno1awAAAD4"]
[Thu Sep 17 15:11:45.950593 2026] [security2:error] [pid 971102:tid 971318] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sitemaps/.env"] [unique_id "aqxXkecL08BTTQixEno1cgAAAFQ"]
[Thu Sep 17 15:11:46.065957 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:37346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxXkucL08BTTQixEno1dQAAADE"]
[Thu Sep 17 15:11:46.066078 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:37346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-attachments-controller.php"] [unique_id "aqxXkucL08BTTQixEno1dQAAADE"]
[Thu Sep 17 15:11:46.143691 2026] [security2:error] [pid 971102:tid 971321] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkecL08BTTQixEno1cwAAAFc"]
[Thu Sep 17 15:11:46.241991 2026] [security2:error] [pid 971102:tid 971301] [client 154.190.208.131:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkucL08BTTQixEno1dwAAAEM"]
[Thu Sep 17 15:11:46.244801 2026] [security2:error] [pid 971102:tid 971301] [client 154.190.208.131:42440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXkucL08BTTQixEno1dwAAAEM"]
[Thu Sep 17 15:11:46.287496 2026] [security2:error] [pid 971102:tid 971308] [client 34.94.67.131:47718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXkucL08BTTQixEno1eAAAAEo"]
[Thu Sep 17 15:11:46.391254 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:37350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxXkucL08BTTQixEno1fgAAAAY"]
[Thu Sep 17 15:11:46.391405 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:37350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-autosaves-controller.php"] [unique_id "aqxXkucL08BTTQixEno1fgAAAAY"]
[Thu Sep 17 15:11:46.489914 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkucL08BTTQixEno1ewAAAGM"]
[Thu Sep 17 15:11:46.671397 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:55132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXkucL08BTTQixEno1dgAAAA0"]
[Thu Sep 17 15:11:46.686159 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxXkucL08BTTQixEno1hQAAACo"]
[Thu Sep 17 15:11:46.686257 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:37354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-directory-controller.php"] [unique_id "aqxXkucL08BTTQixEno1hQAAACo"]
[Thu Sep 17 15:11:46.715342 2026] [security2:error] [pid 971102:tid 971322] [client 34.94.67.131:47728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/php-info.php"] [unique_id "aqxXkucL08BTTQixEno1hgAAAFg"]
[Thu Sep 17 15:11:46.825996 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXkucL08BTTQixEno1ggAAADg"]
[Thu Sep 17 15:11:46.984100 2026] [security2:error] [pid 971102:tid 971330] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env.swp"] [unique_id "aqxXkucL08BTTQixEno1iQAAAGA"]
[Thu Sep 17 15:11:46.998264 2026] [security2:error] [pid 971102:tid 971327] [client 34.94.67.131:47738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpversion.php"] [unique_id "aqxXkucL08BTTQixEno1iwAAAF0"]
[Thu Sep 17 15:11:47.024968 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jAAAABk"]
[Thu Sep 17 15:11:47.025090 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-pattern-categories-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jAAAABk"]
[Thu Sep 17 15:11:47.138990 2026] [security2:error] [pid 971102:tid 971287] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.env~"] [unique_id "aqxXk-cL08BTTQixEno1jQAAADU"]
[Thu Sep 17 15:11:47.315227 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:37376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jwAAACA"]
[Thu Sep 17 15:11:47.315331 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:37376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-patterns-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1jwAAACA"]
[Thu Sep 17 15:11:47.325838 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.67.131:47750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/_phpinfo.php"] [unique_id "aqxXk-cL08BTTQixEno1kAAAAC4"]
[Thu Sep 17 15:11:47.486833 2026] [security2:error] [pid 971102:tid 971300] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1jgAAAEI"]
[Thu Sep 17 15:11:47.646279 2026] [security2:error] [pid 971102:tid 971249] [client 34.94.67.131:47756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXk-cL08BTTQixEno1lwAAAA8"]
[Thu Sep 17 15:11:47.659420 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1mwAAADk"]
[Thu Sep 17 15:11:47.659524 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-renderer-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1mwAAADk"]
[Thu Sep 17 15:11:47.837492 2026] [security2:error] [pid 971102:tid 971299] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1lgAAAEE"]
[Thu Sep 17 15:11:47.972937 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1uwAAAAM"]
[Thu Sep 17 15:11:47.973050 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:37392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-block-types-controller.php"] [unique_id "aqxXk-cL08BTTQixEno1uwAAAAM"]
[Thu Sep 17 15:11:48.050044 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.67.131:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/server-info.php"] [unique_id "aqxXlOcL08BTTQixEno1wQAAAHE"]
[Thu Sep 17 15:11:48.130562 2026] [security2:error] [pid 971102:tid 971351] [client 45.169.98.18:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlOcL08BTTQixEno1xQAAAHU"]
[Thu Sep 17 15:11:48.130657 2026] [security2:error] [pid 971102:tid 971351] [client 45.169.98.18:56855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlOcL08BTTQixEno1xQAAAHU"]
[Thu Sep 17 15:11:48.186949 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.117.146:55132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1nQAAAHk"]
[Thu Sep 17 15:11:48.192125 2026] [security2:error] [pid 971102:tid 971302] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXk-cL08BTTQixEno1vAAAAEQ"]
[Thu Sep 17 15:11:48.289554 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:37398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxXlOcL08BTTQixEno1yAAAAFA"]
[Thu Sep 17 15:11:48.289650 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:37398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-blocks-controller.php"] [unique_id "aqxXlOcL08BTTQixEno1yAAAAFA"]
[Thu Sep 17 15:11:48.488015 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.67.131:47768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/server-status.php"] [unique_id "aqxXlOcL08BTTQixEno10QAAAEM"]
[Thu Sep 17 15:11:48.543636 2026] [security2:error] [pid 971102:tid 971321] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlOcL08BTTQixEno1yQAAAFc"]
[Thu Sep 17 15:11:48.590502 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:37408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxXlOcL08BTTQixEno11gAAAEA"]
[Thu Sep 17 15:11:48.590588 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:37408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php"] [unique_id "aqxXlOcL08BTTQixEno11gAAAEA"]
[Thu Sep 17 15:11:48.878151 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:37416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxXlOcL08BTTQixEno14gAAAHc"]
[Thu Sep 17 15:11:48.878295 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:37416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-controller.php"] [unique_id "aqxXlOcL08BTTQixEno14gAAAHc"]
[Thu Sep 17 15:11:48.883102 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlOcL08BTTQixEno13AAAADY"]
[Thu Sep 17 15:11:48.944947 2026] [security2:error] [pid 971102:tid 971335] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/logs/.env"] [unique_id "aqxXlOcL08BTTQixEno15wAAAGU"]
[Thu Sep 17 15:11:49.120477 2026] [security2:error] [pid 971102:tid 971320] [client 34.94.67.131:47782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXlecL08BTTQixEno19wAAAFY"]
[Thu Sep 17 15:11:49.168391 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxXlecL08BTTQixEno1-gAAADk"]
[Thu Sep 17 15:11:49.168486 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:37428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-edit-site-export-controller.php"] [unique_id "aqxXlecL08BTTQixEno1-gAAADk"]
[Thu Sep 17 15:11:49.226843 2026] [security2:error] [pid 971102:tid 971334] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlecL08BTTQixEno18AAAAGQ"]
[Thu Sep 17 15:11:49.256039 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cache/.env"] [unique_id "aqxXlecL08BTTQixEno1_QAAAHs"]
[Thu Sep 17 15:11:49.450416 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailer/.env"] [unique_id "aqxXlecL08BTTQixEno2BAAAAHA"]
[Thu Sep 17 15:11:49.453830 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxXlecL08BTTQixEno2BQAAABc"]
[Thu Sep 17 15:11:49.453910 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:37434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-collections-controller.php"] [unique_id "aqxXlecL08BTTQixEno2BQAAABc"]
[Thu Sep 17 15:11:49.473675 2026] [security2:error] [pid 971102:tid 971343] [client 5.189.145.112:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxXlecL08BTTQixEno2BgAAAG0"], referer: binance.com
[Thu Sep 17 15:11:49.576164 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlecL08BTTQixEno1_wAAAAs"]
[Thu Sep 17 15:11:49.636755 2026] [security2:error] [pid 971102:tid 971325] [client 34.94.67.131:47788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXlecL08BTTQixEno2DgAAAFs"]
[Thu Sep 17 15:11:49.719191 2026] [security2:error] [pid 971102:tid 971295] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mail/.env"] [unique_id "aqxXlecL08BTTQixEno2DwAAAD0"]
[Thu Sep 17 15:11:49.731285 2026] [security2:error] [pid 971102:tid 971258] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/app/.env"] [unique_id "aqxXlecL08BTTQixEno2EAAAABg"]
[Thu Sep 17 15:11:49.755112 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxXlecL08BTTQixEno2EQAAAD4"]
[Thu Sep 17 15:11:49.755191 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-faces-controller.php"] [unique_id "aqxXlecL08BTTQixEno2EQAAAD4"]
[Thu Sep 17 15:11:49.827577 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "aqxXlecL08BTTQixEno2FAAAAEU"]
[Thu Sep 17 15:11:49.868593 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/email/.env"] [unique_id "aqxXlecL08BTTQixEno2GAAAAFA"]
[Thu Sep 17 15:11:49.887573 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/apps/.env"] [unique_id "aqxXlecL08BTTQixEno2GQAAABw"]
[Thu Sep 17 15:11:50.035532 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxXlucL08BTTQixEno2HwAAAHI"]
[Thu Sep 17 15:11:50.035636 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:47018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-font-families-controller.php"] [unique_id "aqxXlucL08BTTQixEno2HwAAAHI"]
[Thu Sep 17 15:11:50.036413 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env"] [unique_id "aqxXlucL08BTTQixEno2IAAAYgg"]
[Thu Sep 17 15:11:50.037783 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2IwAAYgo"]
[Thu Sep 17 15:11:50.037847 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2IgAAYgk"]
[Thu Sep 17 15:11:50.037982 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2IQAAYgc"]
[Thu Sep 17 15:11:50.038029 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2JQAAYhE"]
[Thu Sep 17 15:11:50.038139 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2JAAAYgs"]
[Thu Sep 17 15:11:50.038223 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2JgAAYgg"]
[Thu Sep 17 15:11:50.038567 2026] [security2:error] [pid 971102:tid 971113] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.backup"] [unique_id "aqxXlucL08BTTQixEno2JwAAYgk"]
[Thu Sep 17 15:11:50.038885 2026] [security2:error] [pid 971102:tid 971121] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.old"] [unique_id "aqxXlucL08BTTQixEno2KQAAYhE"]
[Thu Sep 17 15:11:50.038913 2026] [security2:error] [pid 971102:tid 971111] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.bak"] [unique_id "aqxXlucL08BTTQixEno2KgAAYgc"]
[Thu Sep 17 15:11:50.039504 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2KAAAYgo"]
[Thu Sep 17 15:11:50.040009 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LgAAYhc"]
[Thu Sep 17 15:11:50.040088 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LwAAYhk"]
[Thu Sep 17 15:11:50.040141 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2KwAAYgs"]
[Thu Sep 17 15:11:50.040447 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LQAAYhg"]
[Thu Sep 17 15:11:50.040480 2026] [security2:error] [pid 971102:tid 971332] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2LAAAYgg"]
[Thu Sep 17 15:11:50.045282 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/.env"] [unique_id "aqxXlucL08BTTQixEno2MAAAAEA"]
[Thu Sep 17 15:11:50.157641 2026] [security2:error] [pid 971102:tid 971241] [client 34.94.67.131:43776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXlucL08BTTQixEno2NQAAAAc"]
[Thu Sep 17 15:11:50.200862 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/web/.env"] [unique_id "aqxXlucL08BTTQixEno2NwAAAFg"]
[Thu Sep 17 15:11:50.275684 2026] [security2:error] [pid 971102:tid 971133] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/.env.php"] [unique_id "aqxXlucL08BTTQixEno2PAAACB0"]
[Thu Sep 17 15:11:50.277170 2026] [security2:error] [pid 971102:tid 971137] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env~"] [unique_id "aqxXlucL08BTTQixEno2PgAACCE"]
[Thu Sep 17 15:11:50.277173 2026] [security2:error] [pid 971102:tid 971136] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.swp"] [unique_id "aqxXlucL08BTTQixEno2OwAACCA"]
[Thu Sep 17 15:11:50.278292 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2OgAACBs"]
[Thu Sep 17 15:11:50.278711 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2PwAACCI"]
[Thu Sep 17 15:11:50.278759 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2QQAACCQ"]
[Thu Sep 17 15:11:50.278828 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2PQAACBw"]
[Thu Sep 17 15:11:50.278866 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2OQAACB4"]
[Thu Sep 17 15:11:50.278897 2026] [security2:error] [pid 971102:tid 971242] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2QAAACB8"]
[Thu Sep 17 15:11:50.318083 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:47020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxXlucL08BTTQixEno2QgAAABo"]
[Thu Sep 17 15:11:50.318181 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:47020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-controller.php"] [unique_id "aqxXlucL08BTTQixEno2QgAAABo"]
[Thu Sep 17 15:11:50.356759 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/site/.env"] [unique_id "aqxXlucL08BTTQixEno2QwAAAH8"]
[Thu Sep 17 15:11:50.391905 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/smtp/.env"] [unique_id "aqxXlucL08BTTQixEno2RAAAAB4"]
[Thu Sep 17 15:11:50.393371 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.67.131:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXlucL08BTTQixEno2RgAAAEg"]
[Thu Sep 17 15:11:50.488604 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/api/.env"] [unique_id "aqxXlucL08BTTQixEno2TwAAICY"]
[Thu Sep 17 15:11:50.488647 2026] [security2:error] [pid 971102:tid 971148] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/server/.env"] [unique_id "aqxXlucL08BTTQixEno2VAAAICw"]
[Thu Sep 17 15:11:50.488685 2026] [security2:error] [pid 971102:tid 971145] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/app/.env"] [unique_id "aqxXlucL08BTTQixEno2TAAAICk"]
[Thu Sep 17 15:11:50.488714 2026] [security2:error] [pid 971102:tid 971156] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/public/.env"] [unique_id "aqxXlucL08BTTQixEno2WgAAIDQ"]
[Thu Sep 17 15:11:50.488747 2026] [security2:error] [pid 971102:tid 971149] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/backend/.env"] [unique_id "aqxXlucL08BTTQixEno2UgAAIC0"]
[Thu Sep 17 15:11:50.488786 2026] [security2:error] [pid 971102:tid 971150] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/config/.env"] [unique_id "aqxXlucL08BTTQixEno2VQAAIC4"]
[Thu Sep 17 15:11:50.488813 2026] [security2:error] [pid 971102:tid 971157] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/frontend/.env"] [unique_id "aqxXlucL08BTTQixEno2WQAAIDU"]
[Thu Sep 17 15:11:50.488838 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/web/.env"] [unique_id "aqxXlucL08BTTQixEno2VwAAIDI"]
[Thu Sep 17 15:11:50.488855 2026] [security2:error] [pid 971102:tid 971153] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/src/.env"] [unique_id "aqxXlucL08BTTQixEno2VgAAIDE"]
[Thu Sep 17 15:11:50.488915 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/var/www/.env"] [unique_id "aqxXlucL08BTTQixEno2WwAAIDY"]
[Thu Sep 17 15:11:50.488980 2026] [security2:error] [pid 971102:tid 971155] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/client/.env"] [unique_id "aqxXlucL08BTTQixEno2WAAAIDM"]
[Thu Sep 17 15:11:50.490053 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2TQAAIBU"]
[Thu Sep 17 15:11:50.490524 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2UAAAICg"]
[Thu Sep 17 15:11:50.490566 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2UQAAICo"]
[Thu Sep 17 15:11:50.490615 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2TgAAICs"]
[Thu Sep 17 15:11:50.491110 2026] [security2:error] [pid 971102:tid 971266] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2UwAAIDA"]
[Thu Sep 17 15:11:50.513362 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/public/.env"] [unique_id "aqxXlucL08BTTQixEno2XAAAAH0"]
[Thu Sep 17 15:11:50.601906 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxXlucL08BTTQixEno2XwAAAFE"]
[Thu Sep 17 15:11:50.601982 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:47032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-global-styles-revisions-controller.php"] [unique_id "aqxXlucL08BTTQixEno2XwAAAFE"]
[Thu Sep 17 15:11:50.676140 2026] [security2:error] [pid 971102:tid 971141] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/var/www/html/.env"] [unique_id "aqxXlucL08BTTQixEno2YwAAViU"]
[Thu Sep 17 15:11:50.682870 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/backup/.env"] [unique_id "aqxXlucL08BTTQixEno2ZgAAETk"]
[Thu Sep 17 15:11:50.682902 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/laravel/.env"] [unique_id "aqxXlucL08BTTQixEno2ZQAAETc"]
[Thu Sep 17 15:11:50.682925 2026] [security2:error] [pid 971102:tid 971166] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/application/.env"] [unique_id "aqxXlucL08BTTQixEno2aAAAET4"]
[Thu Sep 17 15:11:50.682945 2026] [security2:error] [pid 971102:tid 971163] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/back/.env"] [unique_id "aqxXlucL08BTTQixEno2agAAETs"]
[Thu Sep 17 15:11:50.682948 2026] [security2:error] [pid 971102:tid 971164] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/apps/.env"] [unique_id "aqxXlucL08BTTQixEno2ZwAAETw"]
[Thu Sep 17 15:11:50.683043 2026] [security2:error] [pid 971102:tid 971162] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/prod/.env"] [unique_id "aqxXlucL08BTTQixEno2awAAETo"]
[Thu Sep 17 15:11:50.683048 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/production/.env"] [unique_id "aqxXlucL08BTTQixEno2bAAAEUE"]
[Thu Sep 17 15:11:50.683356 2026] [security2:error] [pid 971102:tid 971165] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/cms/.env"] [unique_id "aqxXlucL08BTTQixEno2aQAAET0"]
[Thu Sep 17 15:11:50.683481 2026] [security2:error] [pid 971102:tid 971167] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/dev/.env"] [unique_id "aqxXlucL08BTTQixEno2bQAAET8"]
[Thu Sep 17 15:11:50.683557 2026] [security2:error] [pid 971102:tid 971151] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/staging/.env"] [unique_id "aqxXlucL08BTTQixEno2bgAAES8"]
[Thu Sep 17 15:11:50.683586 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/test/.env"] [unique_id "aqxXlucL08BTTQixEno2bwAAEUI"]
[Thu Sep 17 15:11:50.683602 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/new/.env"] [unique_id "aqxXlucL08BTTQixEno2cQAAETc"]
[Thu Sep 17 15:11:50.683629 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/old/.env"] [unique_id "aqxXlucL08BTTQixEno2cAAAETk"]
[Thu Sep 17 15:11:50.683703 2026] [security2:error] [pid 971102:tid 971166] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/node-api/.env"] [unique_id "aqxXlucL08BTTQixEno2cwAAET4"]
[Thu Sep 17 15:11:50.683727 2026] [security2:error] [pid 971102:tid 971164] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/api-backend/.env"] [unique_id "aqxXlucL08BTTQixEno2dAAAETw"]
[Thu Sep 17 15:11:50.683917 2026] [security2:error] [pid 971102:tid 971297] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailing/.env"] [unique_id "aqxXlucL08BTTQixEno2cgAAAD8"]
[Thu Sep 17 15:11:50.763830 2026] [security2:error] [pid 971102:tid 971291] [client 34.94.67.131:43796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXlucL08BTTQixEno2dwAAADk"]
[Thu Sep 17 15:11:50.816356 2026] [security2:error] [pid 971102:tid 971273] [client 156.192.234.52:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlucL08BTTQixEno2eAAAACc"]
[Thu Sep 17 15:11:50.817574 2026] [security2:error] [pid 971102:tid 971273] [client 156.192.234.52:64206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXlucL08BTTQixEno2eAAAACc"]
[Thu Sep 17 15:11:50.858636 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.0.94:37294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXlucL08BTTQixEno2YQAAAA4"]
[Thu Sep 17 15:11:50.863328 2026] [security2:error] [pid 971102:tid 971178] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/admin-app/.env"] [unique_id "aqxXlucL08BTTQixEno2ewAAPEo"]
[Thu Sep 17 15:11:50.868797 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxXlucL08BTTQixEno2ggAAXks"]
[Thu Sep 17 15:11:50.868845 2026] [security2:error] [pid 971102:tid 971182] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/server/backend/.env"] [unique_id "aqxXlucL08BTTQixEno2gAAAXk4"]
[Thu Sep 17 15:11:50.868845 2026] [security2:error] [pid 971102:tid 971177] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/server/api/.env"] [unique_id "aqxXlucL08BTTQixEno2fwAAXkk"]
[Thu Sep 17 15:11:50.868871 2026] [security2:error] [pid 971102:tid 971184] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.aws/.env"] [unique_id "aqxXlucL08BTTQixEno2hAAAXlA"]
[Thu Sep 17 15:11:50.868889 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/public_html/.env"] [unique_id "aqxXlucL08BTTQixEno2fQAAXkg"]
[Thu Sep 17 15:11:50.868897 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/aws/.env"] [unique_id "aqxXlucL08BTTQixEno2gwAAXlM"]
[Thu Sep 17 15:11:50.868937 2026] [security2:error] [pid 971102:tid 971180] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/current/.env"] [unique_id "aqxXlucL08BTTQixEno2fgAAXkw"]
[Thu Sep 17 15:11:50.868936 2026] [security2:error] [pid 971102:tid 971181] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.docker/.env"] [unique_id "aqxXlucL08BTTQixEno2gQAAXk0"]
[Thu Sep 17 15:11:50.868995 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/stripe/.env"] [unique_id "aqxXlucL08BTTQixEno2hQAAXlE"]
[Thu Sep 17 15:11:50.869686 2026] [security2:error] [pid 971102:tid 971182] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/v2/.env"] [unique_id "aqxXlucL08BTTQixEno2iQAAXk4"]
[Thu Sep 17 15:11:50.869702 2026] [security2:error] [pid 971102:tid 971177] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/v1/.env"] [unique_id "aqxXlucL08BTTQixEno2iAAAXkk"]
[Thu Sep 17 15:11:50.869746 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/v3/.env"] [unique_id "aqxXlucL08BTTQixEno2igAAXlE"]
[Thu Sep 17 15:11:50.871018 2026] [security2:error] [pid 971102:tid 971328] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2hgAAXlI"]
[Thu Sep 17 15:11:50.871070 2026] [security2:error] [pid 971102:tid 971328] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXlucL08BTTQixEno2hwAAXlQ"]
[Thu Sep 17 15:11:50.896195 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxXlucL08BTTQixEno2iwAAAHs"]
[Thu Sep 17 15:11:50.896270 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:47044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icon-collections-controller.php"] [unique_id "aqxXlucL08BTTQixEno2iwAAAHs"]
[Thu Sep 17 15:11:50.938201 2026] [security2:error] [pid 971102:tid 971143] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/administrator/.env"] [unique_id "aqxXlucL08BTTQixEno2fAAAXic"]
[Thu Sep 17 15:11:50.939239 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/notifications/.env"] [unique_id "aqxXlucL08BTTQixEno2jwAAAHA"]
[Thu Sep 17 15:11:51.014492 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/backend/.env"] [unique_id "aqxXl-cL08BTTQixEno2kQAAAAE"]
[Thu Sep 17 15:11:51.051744 2026] [security2:error] [pid 971102:tid 971183] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/media/.env"] [unique_id "aqxXl-cL08BTTQixEno2kgAAWk8"]
[Thu Sep 17 15:11:51.056072 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2kwAAeVg"]
[Thu Sep 17 15:11:51.057701 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.git/config.bak"] [unique_id "aqxXl-cL08BTTQixEno2nwAAeWw"]
[Thu Sep 17 15:11:51.058783 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2nAAAeWA"]
[Thu Sep 17 15:11:51.058921 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lAAAeVo"]
[Thu Sep 17 15:11:51.058956 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lwAAeVg"]
[Thu Sep 17 15:11:51.059041 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lQAAeVY"]
[Thu Sep 17 15:11:51.059076 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2lgAAeVw"]
[Thu Sep 17 15:11:51.059110 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mAAAeWU"]
[Thu Sep 17 15:11:51.059144 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mQAAeWE"]
[Thu Sep 17 15:11:51.059181 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mgAAeVk"]
[Thu Sep 17 15:11:51.059276 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2nQAAeVs"]
[Thu Sep 17 15:11:51.059310 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2oAAAeW4"]
[Thu Sep 17 15:11:51.059376 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2mwAAeWY"]
[Thu Sep 17 15:11:51.059412 2026] [security2:error] [pid 971102:tid 971355] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2ngAAeWo"]
[Thu Sep 17 15:11:51.083305 2026] [security2:error] [pid 971102:tid 971344] [client 185.55.149.49:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno2ogAAAG4"]
[Thu Sep 17 15:11:51.083408 2026] [security2:error] [pid 971102:tid 971344] [client 185.55.149.49:50551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno2ogAAAG4"]
[Thu Sep 17 15:11:51.125082 2026] [security2:error] [pid 971102:tid 971302] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2pAAARGQ"]
[Thu Sep 17 15:11:51.147911 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/notify/.env"] [unique_id "aqxXl-cL08BTTQixEno2pQAAAHw"]
[Thu Sep 17 15:11:51.167893 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/server/.env"] [unique_id "aqxXl-cL08BTTQixEno2pgAAAFk"]
[Thu Sep 17 15:11:51.181418 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:47048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2qAAAABg"]
[Thu Sep 17 15:11:51.181483 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:47048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-icons-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2qAAAABg"]
[Thu Sep 17 15:11:51.236861 2026] [security2:error] [pid 971102:tid 971303] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2qwAARV8"]
[Thu Sep 17 15:11:51.240119 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rAAAUGc"]
[Thu Sep 17 15:11:51.241566 2026] [security2:error] [pid 971102:tid 971219] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxXl-cL08BTTQixEno2tQAAUHI"]
[Thu Sep 17 15:11:51.241630 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxXl-cL08BTTQixEno2sQAAUGs"]
[Thu Sep 17 15:11:51.241744 2026] [security2:error] [pid 971102:tid 971218] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/id_rsa"] [unique_id "aqxXl-cL08BTTQixEno2tgAAUHE"]
[Thu Sep 17 15:11:51.242186 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rQAAUF0"]
[Thu Sep 17 15:11:51.242645 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rgAAUGk"]
[Thu Sep 17 15:11:51.242761 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2sAAAUGg"]
[Thu Sep 17 15:11:51.242910 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2tAAAUHA"]
[Thu Sep 17 15:11:51.242957 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2sgAAUFc"]
[Thu Sep 17 15:11:51.243094 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2uAAAUG0"]
[Thu Sep 17 15:11:51.243175 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2uQAAUAA"]
[Thu Sep 17 15:11:51.243204 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2rwAAUGI"]
[Thu Sep 17 15:11:51.243248 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2swAAUG8"]
[Thu Sep 17 15:11:51.243274 2026] [security2:error] [pid 971102:tid 971314] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2twAAUHo"]
[Thu Sep 17 15:11:51.243306 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.67.131:43810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXl-cL08BTTQixEno2ugAAAD4"]
[Thu Sep 17 15:11:51.311131 2026] [security2:error] [pid 971102:tid 971310] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2vAAATDg"]
[Thu Sep 17 15:11:51.321126 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/frontend/.env"] [unique_id "aqxXl-cL08BTTQixEno2vQAAAEc"]
[Thu Sep 17 15:11:51.412226 2026] [security2:error] [pid 971102:tid 971348] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sender/.env"] [unique_id "aqxXl-cL08BTTQixEno2vwAAAHI"]
[Thu Sep 17 15:11:51.423488 2026] [security2:error] [pid 971102:tid 971298] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wAAAQHQ"]
[Thu Sep 17 15:11:51.425705 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wQAAKH4"]
[Thu Sep 17 15:11:51.427520 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xQAAKHk"]
[Thu Sep 17 15:11:51.427620 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xAAAKHc"]
[Thu Sep 17 15:11:51.427671 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wgAAKAQ"]
[Thu Sep 17 15:11:51.427718 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2wwAAKAM"]
[Thu Sep 17 15:11:51.428104 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2yAAAKHY"]
[Thu Sep 17 15:11:51.428193 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xgAAKAU"]
[Thu Sep 17 15:11:51.428230 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2zgAAKAE"]
[Thu Sep 17 15:11:51.428269 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2xwAAKHU"]
[Thu Sep 17 15:11:51.428312 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2zAAAKAY"]
[Thu Sep 17 15:11:51.428391 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2ywAAKHM"]
[Thu Sep 17 15:11:51.428426 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2yQAAKAI"]
[Thu Sep 17 15:11:51.428510 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2zQAAKHg"]
[Thu Sep 17 15:11:51.428537 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2ygAAKH0"]
[Thu Sep 17 15:11:51.430980 2026] [security2:error] [pid 971102:tid 971261] [client 162.241.226.11:32768] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXl-cL08BTTQixEno2vgAAABs"]
[Thu Sep 17 15:11:51.469541 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2zwAAABY"]
[Thu Sep 17 15:11:51.469656 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-items-controller.php"] [unique_id "aqxXl-cL08BTTQixEno2zwAAABY"]
[Thu Sep 17 15:11:51.483873 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/src/.env"] [unique_id "aqxXl-cL08BTTQixEno20AAAAAo"]
[Thu Sep 17 15:11:51.505224 2026] [security2:error] [pid 971102:tid 971349] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno20QAAcww"]
[Thu Sep 17 15:11:51.582134 2026] [security2:error] [pid 971102:tid 971263] [client 115.244.164.14:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno21gAAAB0"]
[Thu Sep 17 15:11:51.582222 2026] [security2:error] [pid 971102:tid 971263] [client 115.244.164.14:52169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXl-cL08BTTQixEno21gAAAB0"]
[Thu Sep 17 15:11:51.601869 2026] [security2:error] [pid 971102:tid 971283] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/campaign/.env"] [unique_id "aqxXl-cL08BTTQixEno21wAAADE"]
[Thu Sep 17 15:11:51.613060 2026] [security2:error] [pid 971102:tid 971269] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22AAAIw4"]
[Thu Sep 17 15:11:51.616871 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22QAAJBA"]
[Thu Sep 17 15:11:51.618156 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22wAAJBM"]
[Thu Sep 17 15:11:51.618208 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno22gAAJBY"]
[Thu Sep 17 15:11:51.618280 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23QAAJBI"]
[Thu Sep 17 15:11:51.618500 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23AAAJA8"]
[Thu Sep 17 15:11:51.618681 2026] [security2:error] [pid 971102:tid 971270] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23gAAJA0"]
[Thu Sep 17 15:11:51.623090 2026] [security2:error] [pid 971102:tid 971111] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config.php"] [unique_id "aqxXl-cL08BTTQixEno24QAAFQc"]
[Thu Sep 17 15:11:51.625033 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno25QAAFQs"]
[Thu Sep 17 15:11:51.625150 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno25gAAFRg"]
[Thu Sep 17 15:11:51.625218 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno23wAAFQk"]
[Thu Sep 17 15:11:51.625253 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno24gAAFQo"]
[Thu Sep 17 15:11:51.625288 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno24wAAFRc"]
[Thu Sep 17 15:11:51.625716 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno24AAAFRE"]
[Thu Sep 17 15:11:51.625754 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno25AAAFRk"]
[Thu Sep 17 15:11:51.638199 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/core/.env"] [unique_id "aqxXl-cL08BTTQixEno25wAAAFg"]
[Thu Sep 17 15:11:51.691876 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno26gAATgg"]
[Thu Sep 17 15:11:51.726173 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.67.131:43820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXl-cL08BTTQixEno27QAAAEM"]
[Thu Sep 17 15:11:51.777681 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxXl-cL08BTTQixEno27gAAAEg"]
[Thu Sep 17 15:11:51.777839 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menu-locations-controller.php"] [unique_id "aqxXl-cL08BTTQixEno27gAAAEg"]
[Thu Sep 17 15:11:51.793950 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/core/app/.env"] [unique_id "aqxXl-cL08BTTQixEno27wAAAFw"]
[Thu Sep 17 15:11:51.799146 2026] [security2:error] [pid 971102:tid 971319] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28AAAVX8"]
[Thu Sep 17 15:11:51.802905 2026] [security2:error] [pid 971102:tid 971259] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28QAAGRQ"]
[Thu Sep 17 15:11:51.803734 2026] [security2:error] [pid 971102:tid 971138] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/aws.php"] [unique_id "aqxXl-cL08BTTQixEno29gAAKyI"]
[Thu Sep 17 15:11:51.805170 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28wAAKyA"]
[Thu Sep 17 15:11:51.805216 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno29AAAKyE"]
[Thu Sep 17 15:11:51.805474 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno28gAAKx0"]
[Thu Sep 17 15:11:51.805519 2026] [security2:error] [pid 971102:tid 971277] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno29QAAKxs"]
[Thu Sep 17 15:11:51.807961 2026] [security2:error] [pid 971102:tid 971327] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno29wAAXSQ"]
[Thu Sep 17 15:11:51.809217 2026] [security2:error] [pid 971102:tid 971130] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/config.inc.php"] [unique_id "aqxXl-cL08BTTQixEno2-wAAZRo"]
[Thu Sep 17 15:11:51.809236 2026] [security2:error] [pid 971102:tid 971148] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/nexmo.php"] [unique_id "aqxXl-cL08BTTQixEno2_QAAZSw"]
[Thu Sep 17 15:11:51.809271 2026] [security2:error] [pid 971102:tid 971134] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/stripe.php"] [unique_id "aqxXl-cL08BTTQixEno2-AAAZR4"]
[Thu Sep 17 15:11:51.809296 2026] [security2:error] [pid 971102:tid 971135] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/config/mail.php"] [unique_id "aqxXl-cL08BTTQixEno2-gAAZR8"]
[Thu Sep 17 15:11:51.810582 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2_gAAZSk"]
[Thu Sep 17 15:11:51.810757 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2_AAAZSY"]
[Thu Sep 17 15:11:51.810808 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno2-QAAZRw"]
[Thu Sep 17 15:11:51.848638 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/newsletter/.env"] [unique_id "aqxXl-cL08BTTQixEno2_wAAAFI"]
[Thu Sep 17 15:11:51.878335 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3AAAAOjQ"]
[Thu Sep 17 15:11:51.948371 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/config/.env"] [unique_id "aqxXl-cL08BTTQixEno3AQAAADg"]
[Thu Sep 17 15:11:51.982343 2026] [security2:error] [pid 971102:tid 971149] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "perimetry.com"] [uri "/wp-config.php.old"] [unique_id "aqxXl-cL08BTTQixEno3BQAABC0"]
[Thu Sep 17 15:11:51.982343 2026] [security2:error] [pid 971102:tid 971153] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "perimetry.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXl-cL08BTTQixEno3BgAABDE"]
[Thu Sep 17 15:11:51.982390 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/wp-config.php"] [unique_id "aqxXl-cL08BTTQixEno3BAAABDI"]
[Thu Sep 17 15:11:51.983281 2026] [security2:error] [pid 971102:tid 971157] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "perimetry.com"] [uri "/wp-config.php.new"] [unique_id "aqxXl-cL08BTTQixEno3BwAAVjU"]
[Thu Sep 17 15:11:51.983610 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxXl-cL08BTTQixEno3CAAAVjY"]
[Thu Sep 17 15:11:51.986934 2026] [security2:error] [pid 971102:tid 971251] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3CgAAERU"]
[Thu Sep 17 15:11:51.987001 2026] [security2:error] [pid 971102:tid 971251] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3CQAAETM"]
[Thu Sep 17 15:11:51.988538 2026] [security2:error] [pid 971102:tid 971146] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxXl-cL08BTTQixEno3CwAAPyo"]
[Thu Sep 17 15:11:51.990438 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxXl-cL08BTTQixEno3EgAAP0E"]
[Thu Sep 17 15:11:51.991104 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DQAAPyg"]
[Thu Sep 17 15:11:51.991276 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3EAAAP0Y"]
[Thu Sep 17 15:11:51.991407 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DgAAPyU"]
[Thu Sep 17 15:11:51.991490 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DwAAPzA"]
[Thu Sep 17 15:11:51.991536 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3DAAAPys"]
[Thu Sep 17 15:11:51.991677 2026] [security2:error] [pid 971102:tid 971297] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXl-cL08BTTQixEno3EQAAP0U"]
[Thu Sep 17 15:11:52.053854 2026] [security2:error] [pid 971102:tid 971273] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/ses/.env"] [unique_id "aqxXmOcL08BTTQixEno3FQAAACc"]
[Thu Sep 17 15:11:52.069016 2026] [security2:error] [pid 971102:tid 971334] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3FwAAZEA"]
[Thu Sep 17 15:11:52.071745 2026] [security2:error] [pid 971102:tid 971282] [client 34.94.67.131:43826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXmOcL08BTTQixEno3GAAAADA"]
[Thu Sep 17 15:11:52.094691 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3GQAAACI"]
[Thu Sep 17 15:11:52.094768 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-menus-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3GQAAACI"]
[Thu Sep 17 15:11:52.101786 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/private/.env"] [unique_id "aqxXmOcL08BTTQixEno3GwAAADw"]
[Thu Sep 17 15:11:52.199100 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JQAASTw"]
[Thu Sep 17 15:11:52.199219 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IgAASS8"]
[Thu Sep 17 15:11:52.199332 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HgAAST0"]
[Thu Sep 17 15:11:52.199362 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HwAASUM"]
[Thu Sep 17 15:11:52.199390 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HQAAST8"]
[Thu Sep 17 15:11:52.199428 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IAAASTc"]
[Thu Sep 17 15:11:52.199452 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IwAASTk"]
[Thu Sep 17 15:11:52.199528 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3IQAASTs"]
[Thu Sep 17 15:11:52.199552 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3HAAASUI"]
[Thu Sep 17 15:11:52.199579 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JAAAST4"]
[Thu Sep 17 15:11:52.199603 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JgAASUo"]
[Thu Sep 17 15:11:52.199626 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3JwAASUs"]
[Thu Sep 17 15:11:52.199649 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3KQAASVU"]
[Thu Sep 17 15:11:52.199685 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3KAAASUc"]
[Thu Sep 17 15:11:52.199718 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3KgAASVA"]
[Thu Sep 17 15:11:52.227166 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "aqxXmOcL08BTTQixEno3KwAAABA"]
[Thu Sep 17 15:11:52.252741 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/application/.env"] [unique_id "aqxXmOcL08BTTQixEno3LQAAAHA"]
[Thu Sep 17 15:11:52.252806 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3LAAAZkg"]
[Thu Sep 17 15:11:52.284333 2026] [security2:error] [pid 971102:tid 971328] [client 34.94.67.131:43828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php~"] [unique_id "aqxXmOcL08BTTQixEno3LgAAAF4"]
[Thu Sep 17 15:11:52.305969 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sendgrid/.env"] [unique_id "aqxXmOcL08BTTQixEno3LwAAABc"]
[Thu Sep 17 15:11:52.372487 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3MAAAAG8"]
[Thu Sep 17 15:11:52.372555 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-navigation-fallback-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3MAAAAG8"]
[Thu Sep 17 15:11:52.386445 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3MwAAfkw"]
[Thu Sep 17 15:11:52.386511 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NAAAfkQ"]
[Thu Sep 17 15:11:52.386547 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NwAAflE"]
[Thu Sep 17 15:11:52.386630 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3MQAAflM"]
[Thu Sep 17 15:11:52.386684 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3MgAAfk0"]
[Thu Sep 17 15:11:52.386730 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NQAAfkk"]
[Thu Sep 17 15:11:52.386765 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PAAAfk8"]
[Thu Sep 17 15:11:52.386830 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3NgAAfk4"]
[Thu Sep 17 15:11:52.386905 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OAAAflQ"]
[Thu Sep 17 15:11:52.386937 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OgAAfic"]
[Thu Sep 17 15:11:52.386973 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PQAAfl4"]
[Thu Sep 17 15:11:52.387004 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PgAAfmw"]
[Thu Sep 17 15:11:52.387038 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3PwAAfmA"]
[Thu Sep 17 15:11:52.387111 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OQAAflI"]
[Thu Sep 17 15:11:52.387145 2026] [security2:error] [pid 971102:tid 971360] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3OwAAfiM"]
[Thu Sep 17 15:11:52.405107 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/bootstrap/.env"] [unique_id "aqxXmOcL08BTTQixEno3QAAAAGo"]
[Thu Sep 17 15:11:52.436563 2026] [security2:error] [pid 971102:tid 971351] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmOcL08BTTQixEno3QQAAdVg"]
[Thu Sep 17 15:11:52.455034 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "aqxXmOcL08BTTQixEno3QgAAAHc"]
[Thu Sep 17 15:11:52.546196 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/sparkpost/.env"] [unique_id "aqxXmOcL08BTTQixEno3SAAAABI"]
[Thu Sep 17 15:11:52.548177 2026] [security2:error] [pid 971102:tid 971350] [client 40.88.21.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxXlecL08BTTQixEno2DQAAAHQ"], referer: http://frenchtutoringfun.com/favicon.ico
[Thu Sep 17 15:11:52.559899 2026] [security2:error] [pid 971102:tid 971289] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/database/.env"] [unique_id "aqxXmOcL08BTTQixEno3SQAAADc"]
[Thu Sep 17 15:11:52.671411 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:47088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3TQAAADs"]
[Thu Sep 17 15:11:52.671516 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:47088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-pattern-directory-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3TQAAADs"]
[Thu Sep 17 15:11:52.716487 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/storage/.env"] [unique_id "aqxXmOcL08BTTQixEno3UAAAAGM"]
[Thu Sep 17 15:11:52.779769 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.67.131:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/info.php.bak"] [unique_id "aqxXmOcL08BTTQixEno3VQAAAFA"]
[Thu Sep 17 15:11:52.783841 2026] [security2:error] [pid 971102:tid 971237] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/postmark/.env"] [unique_id "aqxXmOcL08BTTQixEno3VgAAAAM"]
[Thu Sep 17 15:11:52.868856 2026] [security2:error] [pid 971102:tid 971309] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/var/www/.env"] [unique_id "aqxXmOcL08BTTQixEno3VwAAAEs"]
[Thu Sep 17 15:11:52.958505 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3WAAAACU"]
[Thu Sep 17 15:11:52.958588 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-plugins-controller.php"] [unique_id "aqxXmOcL08BTTQixEno3WAAAACU"]
[Thu Sep 17 15:11:52.975697 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "aqxXmOcL08BTTQixEno3WQAAABY"]
[Thu Sep 17 15:11:52.993330 2026] [security2:error] [pid 971102:tid 971236] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailgun/.env"] [unique_id "aqxXmOcL08BTTQixEno3WgAAAAI"]
[Thu Sep 17 15:11:53.006073 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3agAACmk"]
[Thu Sep 17 15:11:53.007479 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3WwAAClk"]
[Thu Sep 17 15:11:53.007642 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YgAACmo"]
[Thu Sep 17 15:11:53.007840 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XwAACls"]
[Thu Sep 17 15:11:53.007880 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XAAAClY"]
[Thu Sep 17 15:11:53.007921 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XQAAClw"]
[Thu Sep 17 15:11:53.007959 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3XgAACmE"]
[Thu Sep 17 15:11:53.007991 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YAAACm4"]
[Thu Sep 17 15:11:53.008023 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YQAACmY"]
[Thu Sep 17 15:11:53.008054 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3YwAACmQ"]
[Thu Sep 17 15:11:53.008087 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZQAACl8"]
[Thu Sep 17 15:11:53.008121 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZAAACmc"]
[Thu Sep 17 15:11:53.008162 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZgAACnI"]
[Thu Sep 17 15:11:53.008192 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ZwAACms"]
[Thu Sep 17 15:11:53.008226 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3aQAACl0"]
[Thu Sep 17 15:11:53.008704 2026] [security2:error] [pid 971102:tid 971244] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3aAAACnE"]
[Thu Sep 17 15:11:53.027767 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/var/www/html/.env"] [unique_id "aqxXmecL08BTTQixEno3bQAAAB0"]
[Thu Sep 17 15:11:53.120834 2026] [security2:error] [pid 971102:tid 971300] [client 34.94.67.131:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXmecL08BTTQixEno3cAAAAEI"]
[Thu Sep 17 15:11:53.183887 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/current/.env"] [unique_id "aqxXmecL08BTTQixEno3cwAAAAc"]
[Thu Sep 17 15:11:53.189838 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/info.php"] [unique_id "aqxXmecL08BTTQixEno3dQAADW0"]
[Thu Sep 17 15:11:53.191377 2026] [security2:error] [pid 971102:tid 971247] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3dAAADXA"]
[Thu Sep 17 15:11:53.192083 2026] [security2:error] [pid 971102:tid 971192] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/infos.php"] [unique_id "aqxXmecL08BTTQixEno3dgAATlc"]
[Thu Sep 17 15:11:53.192139 2026] [security2:error] [pid 971102:tid 971104] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/php_info.php"] [unique_id "aqxXmecL08BTTQixEno3dwAATgA"]
[Thu Sep 17 15:11:53.192174 2026] [security2:error] [pid 971102:tid 971227] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/php-info.php"] [unique_id "aqxXmecL08BTTQixEno3eQAATno"]
[Thu Sep 17 15:11:53.192219 2026] [security2:error] [pid 971102:tid 971216] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/php.php"] [unique_id "aqxXmecL08BTTQixEno3eAAATm8"]
[Thu Sep 17 15:11:53.192227 2026] [security2:error] [pid 971102:tid 971203] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/infophp.php"] [unique_id "aqxXmecL08BTTQixEno3egAATmI"]
[Thu Sep 17 15:11:53.192276 2026] [security2:error] [pid 971102:tid 971160] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3ewAATjg"]
[Thu Sep 17 15:11:53.192338 2026] [security2:error] [pid 971102:tid 971204] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/api/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3fgAATmM"]
[Thu Sep 17 15:11:53.192373 2026] [security2:error] [pid 971102:tid 971231] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3fQAATn4"]
[Thu Sep 17 15:11:53.192393 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3fwAATnk"]
[Thu Sep 17 15:11:53.192401 2026] [security2:error] [pid 971102:tid 971107] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3gQAATgM"]
[Thu Sep 17 15:11:53.193711 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3fAAATnQ"]
[Thu Sep 17 15:11:53.193752 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3gAAATgQ"]
[Thu Sep 17 15:11:53.193805 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3gwAATnY"]
[Thu Sep 17 15:11:53.251058 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mandrill/.env"] [unique_id "aqxXmecL08BTTQixEno3igAAABM"]
[Thu Sep 17 15:11:53.281263 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxXmecL08BTTQixEno3jAAAACs"]
[Thu Sep 17 15:11:53.281355 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:47094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-statuses-controller.php"] [unique_id "aqxXmecL08BTTQixEno3jAAAACs"]
[Thu Sep 17 15:11:53.338147 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/release/.env"] [unique_id "aqxXmecL08BTTQixEno3jQAAADM"]
[Thu Sep 17 15:11:53.353172 2026] [security2:error] [pid 971102:tid 971330] [client 34.94.67.131:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3jgAAAGA"]
[Thu Sep 17 15:11:53.374362 2026] [security2:error] [pid 971102:tid 971230] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/database.sql"] [unique_id "aqxXmecL08BTTQixEno3lQAAKn0"]
[Thu Sep 17 15:11:53.374994 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kAAAKgU"]
[Thu Sep 17 15:11:53.375172 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3jwAAKnU"]
[Thu Sep 17 15:11:53.377261 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kQAAKgY"]
[Thu Sep 17 15:11:53.377310 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kgAAKgI"]
[Thu Sep 17 15:11:53.377339 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3kwAAKnM"]
[Thu Sep 17 15:11:53.377364 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3lAAAKng"]
[Thu Sep 17 15:11:53.377394 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3lgAAKgw"]
[Thu Sep 17 15:11:53.377419 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mAAAKg4"]
[Thu Sep 17 15:11:53.377443 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3lwAAKns"]
[Thu Sep 17 15:11:53.377467 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mQAAKhA"]
[Thu Sep 17 15:11:53.377491 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mgAAKhY"]
[Thu Sep 17 15:11:53.377514 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3mwAAKhM"]
[Thu Sep 17 15:11:53.377541 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3nQAAKgU"]
[Thu Sep 17 15:11:53.377584 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3nAAAKhI"]
[Thu Sep 17 15:11:53.379551 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ngAAKg0"]
[Thu Sep 17 15:11:53.425622 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:22785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXmecL08BTTQixEno3owAAADQ"]
[Thu Sep 17 15:11:53.425781 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:22785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXmecL08BTTQixEno3owAAADQ"]
[Thu Sep 17 15:11:53.426087 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mailjet/.env"] [unique_id "aqxXmecL08BTTQixEno3ogAAADg"]
[Thu Sep 17 15:11:53.497321 2026] [security2:error] [pid 971102:tid 971297] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/releases/.env"] [unique_id "aqxXmecL08BTTQixEno3pgAAAD8"]
[Thu Sep 17 15:11:53.558227 2026] [security2:error] [pid 971102:tid 971115] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/wp-config.backup.php"] [unique_id "aqxXmecL08BTTQixEno3qAAADws"]
[Thu Sep 17 15:11:53.561033 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3pwAADwc"]
[Thu Sep 17 15:11:53.561125 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3qQAADxg"]
[Thu Sep 17 15:11:53.561720 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rgAADwg"]
[Thu Sep 17 15:11:53.561963 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3qgAADwk"]
[Thu Sep 17 15:11:53.562155 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rAAADxE"]
[Thu Sep 17 15:11:53.562245 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3qwAADxc"]
[Thu Sep 17 15:11:53.562295 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rQAADxk"]
[Thu Sep 17 15:11:53.562331 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3sAAAD38"]
[Thu Sep 17 15:11:53.562368 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3sgAADyI"]
[Thu Sep 17 15:11:53.562520 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3rwAADxQ"]
[Thu Sep 17 15:11:53.562566 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3swAADyA"]
[Thu Sep 17 15:11:53.562633 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3sQAADyE"]
[Thu Sep 17 15:11:53.562685 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3tAAADx0"]
[Thu Sep 17 15:11:53.562737 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3tQAADxs"]
[Thu Sep 17 15:11:53.563532 2026] [security2:error] [pid 971102:tid 971249] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3tgAADyQ"]
[Thu Sep 17 15:11:53.575512 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxXmecL08BTTQixEno3uQAAAGQ"]
[Thu Sep 17 15:11:53.575593 2026] [security2:error] [pid 971102:tid 971334] [client 143.244.57.120:47104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-post-types-controller.php"] [unique_id "aqxXmecL08BTTQixEno3uQAAAGQ"]
[Thu Sep 17 15:11:53.584826 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/brevo/.env"] [unique_id "aqxXmecL08BTTQixEno3ugAAADA"]
[Thu Sep 17 15:11:53.626579 2026] [security2:error] [pid 971102:tid 971273] [client 34.94.67.131:43868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3uwAAACc"]
[Thu Sep 17 15:11:53.654174 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/shared/.env"] [unique_id "aqxXmecL08BTTQixEno3vQAAAGg"]
[Thu Sep 17 15:11:53.744779 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3vwAAZiw"]
[Thu Sep 17 15:11:53.745571 2026] [security2:error] [pid 971102:tid 971135] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/vendor/.env"] [unique_id "aqxXmecL08BTTQixEno3wQAAZh8"]
[Thu Sep 17 15:11:53.746066 2026] [security2:error] [pid 971102:tid 971150] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perimetry.com"] [uri "/sites/default/settings.local.php"] [unique_id "aqxXmecL08BTTQixEno3yAAAZi4"]
[Thu Sep 17 15:11:53.746103 2026] [authz_core:error] [pid 971102:tid 971145] [remote 45.138.12.28:54158] AH01630: client denied by server configuration: /home1/perimev0/public_html/.htpasswd
[Thu Sep 17 15:11:53.746436 2026] [security2:error] [pid 971102:tid 971149] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/panel/.env"] [unique_id "aqxXmecL08BTTQixEno3yQAAZi0"]
[Thu Sep 17 15:11:53.747400 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "perimetry.com"] [uri "/.env.local.swp"] [unique_id "aqxXmecL08BTTQixEno3ygAAZjI"]
[Thu Sep 17 15:11:53.747701 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3wAAAZh4"]
[Thu Sep 17 15:11:53.747873 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xwAAZh8"]
[Thu Sep 17 15:11:53.747936 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3wwAAZiY"]
[Thu Sep 17 15:11:53.748018 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xAAAZhw"]
[Thu Sep 17 15:11:53.748084 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xgAAZnw"]
[Thu Sep 17 15:11:53.748144 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3xQAAZjQ"]
[Thu Sep 17 15:11:53.748472 2026] [security2:error] [pid 971102:tid 971336] [client 45.138.12.28:54158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxXmecL08BTTQixEno3ywAAZjU"]
[Thu Sep 17 15:11:53.810471 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/deploy/.env"] [unique_id "aqxXmecL08BTTQixEno3zAAAABc"]
[Thu Sep 17 15:11:53.834155 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/transactional/.env"] [unique_id "aqxXmecL08BTTQixEno3zgAAADk"]
[Thu Sep 17 15:11:53.866451 2026] [security2:error] [pid 971102:tid 971328] [client 34.94.67.131:43882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXmecL08BTTQixEno3zwAAAF4"]
[Thu Sep 17 15:11:53.871002 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxXmecL08BTTQixEno30AAAAG8"]
[Thu Sep 17 15:11:53.871076 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php"] [unique_id "aqxXmecL08BTTQixEno30AAAAG8"]
[Thu Sep 17 15:11:53.965564 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/build/.env"] [unique_id "aqxXmecL08BTTQixEno31gAAAAE"]
[Thu Sep 17 15:11:54.079938 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/bulk/.env"] [unique_id "aqxXmucL08BTTQixEno33AAAADs"]
[Thu Sep 17 15:11:54.122353 2026] [security2:error] [pid 971102:tid 971243] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/dist/.env"] [unique_id "aqxXmucL08BTTQixEno33QAAAAk"]
[Thu Sep 17 15:11:54.152162 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxXmucL08BTTQixEno33gAAAGs"]
[Thu Sep 17 15:11:54.152260 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-revisions-controller.php"] [unique_id "aqxXmucL08BTTQixEno33gAAAGs"]
[Thu Sep 17 15:11:54.291747 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/public_html/.env"] [unique_id "aqxXmucL08BTTQixEno35wAAAEA"]
[Thu Sep 17 15:11:54.318197 2026] [security2:error] [pid 971102:tid 971314] [client 50.67.73.198:58658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxXmucL08BTTQixEno34wAAUCg"]
[Thu Sep 17 15:11:54.319543 2026] [security2:error] [pid 971102:tid 971314] [client 50.67.73.198:58658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxXmucL08BTTQixEno34gAAUEE"]
[Thu Sep 17 15:11:54.400627 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/aws/.env"] [unique_id "aqxXmucL08BTTQixEno38AAAABY"]
[Thu Sep 17 15:11:54.447713 2026] [security2:error] [pid 971102:tid 971267] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/htdocs/.env"] [unique_id "aqxXmucL08BTTQixEno38QAAACE"]
[Thu Sep 17 15:11:54.462293 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxXmucL08BTTQixEno38wAAAB8"]
[Thu Sep 17 15:11:54.462402 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-search-controller.php"] [unique_id "aqxXmucL08BTTQixEno38wAAAB8"]
[Thu Sep 17 15:11:54.545525 2026] [security2:error] [pid 971102:tid 971236] [client 34.94.67.131:43898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXmucL08BTTQixEno39gAAAAI"]
[Thu Sep 17 15:11:54.603601 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/www/.env"] [unique_id "aqxXmucL08BTTQixEno3-gAAABo"]
[Thu Sep 17 15:11:54.750779 2026] [security2:error] [pid 971102:tid 971335] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/azure/.env"] [unique_id "aqxXmucL08BTTQixEno4AQAAAGU"]
[Thu Sep 17 15:11:54.767533 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/html/.env"] [unique_id "aqxXmucL08BTTQixEno4AgAAAFI"]
[Thu Sep 17 15:11:54.831571 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:47150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxXmucL08BTTQixEno4BQAAADE"]
[Thu Sep 17 15:11:54.831655 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:47150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-settings-controller.php"] [unique_id "aqxXmucL08BTTQixEno4BQAAADE"]
[Thu Sep 17 15:11:54.925441 2026] [security2:error] [pid 971102:tid 971268] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/live/.env"] [unique_id "aqxXmucL08BTTQixEno4CAAAACI"]
[Thu Sep 17 15:11:55.014578 2026] [security2:error] [pid 971102:tid 971264] [client 186.105.232.15:52766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXm-cL08BTTQixEno4DAAAAB4"]
[Thu Sep 17 15:11:55.014703 2026] [security2:error] [pid 971102:tid 971264] [client 186.105.232.15:52766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXm-cL08BTTQixEno4DAAAAB4"]
[Thu Sep 17 15:11:55.052483 2026] [security2:error] [pid 971102:tid 971346] [client 5.189.145.112:64709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxXm-cL08BTTQixEno4DQAAAHA"], referer: binance.com
[Thu Sep 17 15:11:55.070828 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/gcp/.env"] [unique_id "aqxXm-cL08BTTQixEno4DgAAAGY"]
[Thu Sep 17 15:11:55.080166 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/prod/.env"] [unique_id "aqxXm-cL08BTTQixEno4DwAAABc"]
[Thu Sep 17 15:11:55.103740 2026] [security2:error] [pid 971102:tid 971248] [client 34.94.67.131:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXm-cL08BTTQixEno4EAAAAA4"]
[Thu Sep 17 15:11:55.123085 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:47156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4FAAAAH4"]
[Thu Sep 17 15:11:55.123161 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:47156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-sidebars-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4FAAAAH4"]
[Thu Sep 17 15:11:55.129045 2026] [autoindex:error] [pid 971102:tid 971357] [client 157.66.54.188:55162] AH01276: Cannot serve directory /home4/jthomps4/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:11:55.241138 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/dev/.env"] [unique_id "aqxXm-cL08BTTQixEno4GgAAAHw"]
[Thu Sep 17 15:11:55.285038 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cloud/.env"] [unique_id "aqxXm-cL08BTTQixEno4GwAAADY"]
[Thu Sep 17 15:11:55.367717 2026] [security2:error] [pid 971102:tid 971279] [client 34.94.67.131:43918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXm-cL08BTTQixEno4HAAAAC0"]
[Thu Sep 17 15:11:55.395053 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/staging/.env"] [unique_id "aqxXm-cL08BTTQixEno4HQAAADs"]
[Thu Sep 17 15:11:55.399511 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:47168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4HgAAAAk"]
[Thu Sep 17 15:11:55.399571 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:47168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-site-health-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4HgAAAAk"]
[Thu Sep 17 15:11:55.478824 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/infrastructure/.env"] [unique_id "aqxXm-cL08BTTQixEno4IwAAAEc"]
[Thu Sep 17 15:11:55.550689 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/opt/.env"] [unique_id "aqxXm-cL08BTTQixEno4JQAAAAw"]
[Thu Sep 17 15:11:55.679196 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:47184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4KwAAAEI"]
[Thu Sep 17 15:11:55.679298 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:47184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-taxonomies-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4KwAAAEI"]
[Thu Sep 17 15:11:55.710288 2026] [security2:error] [pid 971102:tid 971347] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/laravel/.env"] [unique_id "aqxXm-cL08BTTQixEno4LgAAAHE"]
[Thu Sep 17 15:11:55.713345 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/docker/.env"] [unique_id "aqxXm-cL08BTTQixEno4LwAAACU"]
[Thu Sep 17 15:11:55.777678 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.67.131:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXm-cL08BTTQixEno4MQAAAC4"]
[Thu Sep 17 15:11:55.867322 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/symfony/.env"] [unique_id "aqxXm-cL08BTTQixEno4NAAAAFw"]
[Thu Sep 17 15:11:55.969293 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:47192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4NQAAAFU"]
[Thu Sep 17 15:11:55.969378 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:47192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-autosaves-controller.php"] [unique_id "aqxXm-cL08BTTQixEno4NQAAAFU"]
[Thu Sep 17 15:11:56.149148 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/k8s/.env"] [unique_id "aqxXnOcL08BTTQixEno4OwAAAH8"]
[Thu Sep 17 15:11:56.151632 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.67.131:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4PAAAACA"]
[Thu Sep 17 15:11:56.214586 2026] [autoindex:error] [pid 971102:tid 971359] [client 157.66.54.188:55162] AH01276: Cannot serve directory /home4/jthomps4/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:11:56.247541 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:47202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4PgAAAHo"]
[Thu Sep 17 15:11:56.247632 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:47202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-template-revisions-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4PgAAAHo"]
[Thu Sep 17 15:11:56.322874 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/wordpress/.env"] [unique_id "aqxXnOcL08BTTQixEno4QgAAAFI"]
[Thu Sep 17 15:11:56.394201 2026] [security2:error] [pid 971102:tid 971297] [client 34.32.117.146:55132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/kubernetes/.env"] [unique_id "aqxXnOcL08BTTQixEno4RgAAAD8"]
[Thu Sep 17 15:11:56.473751 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/wp/.env"] [unique_id "aqxXnOcL08BTTQixEno4RwAAABM"]
[Thu Sep 17 15:11:56.512269 2026] [security2:error] [pid 971102:tid 971285] [client 210.222.43.21:64921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXnOcL08BTTQixEno4RQAAADM"], referer: http://talent-in-borders.com/WWW
[Thu Sep 17 15:11:56.518420 2026] [security2:error] [pid 971102:tid 971286] [client 34.94.67.131:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4SQAAADQ"]
[Thu Sep 17 15:11:56.560043 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:47212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4TAAAAGI"]
[Thu Sep 17 15:11:56.560136 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:47212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-templates-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4TAAAAGI"]
[Thu Sep 17 15:11:56.622641 2026] [security2:error] [pid 971102:tid 971320] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cms/.env"] [unique_id "aqxXnOcL08BTTQixEno4UQAAAFY"]
[Thu Sep 17 15:11:56.710234 2026] [security2:error] [pid 971102:tid 971277] [client 154.190.208.131:41708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnOcL08BTTQixEno4UwAAACs"]
[Thu Sep 17 15:11:56.714352 2026] [security2:error] [pid 971102:tid 971277] [client 154.190.208.131:41708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnOcL08BTTQixEno4UwAAACs"]
[Thu Sep 17 15:11:56.751913 2026] [security2:error] [pid 971102:tid 971328] [client 34.94.67.131:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4VQAAAF4"]
[Thu Sep 17 15:11:56.773512 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/drupal/.env"] [unique_id "aqxXnOcL08BTTQixEno4VgAAAGo"]
[Thu Sep 17 15:11:56.853513 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:47214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4VwAAAFk"]
[Thu Sep 17 15:11:56.853598 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:47214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-terms-controller.php"] [unique_id "aqxXnOcL08BTTQixEno4VwAAAFk"]
[Thu Sep 17 15:11:56.856113 2026] [security2:error] [pid 971102:tid 971235] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "aqxXnOcL08BTTQixEno4WAAAAAE"]
[Thu Sep 17 15:11:56.924712 2026] [security2:error] [pid 971102:tid 971252] [client 34.94.67.131:43948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXnOcL08BTTQixEno4XAAAABI"]
[Thu Sep 17 15:11:56.926645 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/joomla/.env"] [unique_id "aqxXnOcL08BTTQixEno4XQAAADY"]
[Thu Sep 17 15:11:57.075878 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/magento/.env"] [unique_id "aqxXnecL08BTTQixEno4YQAAAHg"]
[Thu Sep 17 15:11:57.084886 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "aqxXnecL08BTTQixEno4YwAAAG8"]
[Thu Sep 17 15:11:57.169414 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxXnecL08BTTQixEno4ZAAAADk"]
[Thu Sep 17 15:11:57.169499 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-themes-controller.php"] [unique_id "aqxXnecL08BTTQixEno4ZAAAADk"]
[Thu Sep 17 15:11:57.174839 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/terraform/.env"] [unique_id "aqxXnecL08BTTQixEno4ZQAAAFE"]
[Thu Sep 17 15:11:57.223979 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/shopify/.env"] [unique_id "aqxXnecL08BTTQixEno4ZwAAAEA"]
[Thu Sep 17 15:11:57.261213 2026] [security2:error] [pid 971102:tid 971341] [client 34.94.67.131:43962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXnecL08BTTQixEno4aAAAAGs"]
[Thu Sep 17 15:11:57.372760 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/prestashop/.env"] [unique_id "aqxXnecL08BTTQixEno4bQAAAEo"]
[Thu Sep 17 15:11:57.473897 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxXnecL08BTTQixEno4cAAAAB8"]
[Thu Sep 17 15:11:57.474032 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:47224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-url-details-controller.php"] [unique_id "aqxXnecL08BTTQixEno4cAAAAB8"]
[Thu Sep 17 15:11:57.512070 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.67.131:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/core/phpinfo.php"] [unique_id "aqxXnecL08BTTQixEno4cQAAAHM"]
[Thu Sep 17 15:11:57.521909 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/codeigniter/.env"] [unique_id "aqxXnecL08BTTQixEno4cgAAAE8"]
[Thu Sep 17 15:11:57.575241 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/ansible/.env"] [unique_id "aqxXnecL08BTTQixEno4cwAAAAc"]
[Thu Sep 17 15:11:57.675776 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cakephp/.env"] [unique_id "aqxXnecL08BTTQixEno4eAAAAFw"]
[Thu Sep 17 15:11:57.737023 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.67.131:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sqlerudition.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxXnecL08BTTQixEno4egAAAAA"]
[Thu Sep 17 15:11:57.744986 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/.git/.env"] [unique_id "aqxXnecL08BTTQixEno4ewAAACQ"]
[Thu Sep 17 15:11:57.754542 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxXnecL08BTTQixEno4fQAAAD0"]
[Thu Sep 17 15:11:57.754621 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:47232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php"] [unique_id "aqxXnecL08BTTQixEno4fQAAAD0"]
[Thu Sep 17 15:11:57.825688 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/zend/.env"] [unique_id "aqxXnecL08BTTQixEno4gAAAAH0"]
[Thu Sep 17 15:11:57.932320 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/ci/.env"] [unique_id "aqxXnecL08BTTQixEno4gQAAAG0"]
[Thu Sep 17 15:11:57.951511 2026] [security2:error] [pid 971102:tid 971361] [client 114.119.132.183:64547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtbclubdecampo.com"] [uri "/Rutas/Alto_Tajo/alto_tajo.plt"] [unique_id "aqxXnecL08BTTQixEno4ggAAAH8"], referer: https://mtbclubdecampo.com/Rutas/Alto_Tajo/alto_tajo.plt
[Thu Sep 17 15:11:57.975366 2026] [security2:error] [pid 971102:tid 971330] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/yii/.env"] [unique_id "aqxXnecL08BTTQixEno4gwAAAGA"]
[Thu Sep 17 15:11:58.072974 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:47234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxXnucL08BTTQixEno4hwAAAEs"]
[Thu Sep 17 15:11:58.073075 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:47234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-view-config-controller.php"] [unique_id "aqxXnucL08BTTQixEno4hwAAAEs"]
[Thu Sep 17 15:11:58.129995 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/laravel5/.env"] [unique_id "aqxXnucL08BTTQixEno4iwAAABM"]
[Thu Sep 17 15:11:58.181721 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/cd/.env"] [unique_id "aqxXnucL08BTTQixEno4jAAAAGI"]
[Thu Sep 17 15:11:58.284916 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/v1/.env"] [unique_id "aqxXnucL08BTTQixEno4jwAAAEk"]
[Thu Sep 17 15:11:58.362045 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxXnucL08BTTQixEno4kQAAACI"]
[Thu Sep 17 15:11:58.362156 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:47248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widget-types-controller.php"] [unique_id "aqxXnucL08BTTQixEno4kQAAACI"]
[Thu Sep 17 15:11:58.390340 2026] [security2:error] [pid 971102:tid 971269] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/jenkins/.env"] [unique_id "aqxXnucL08BTTQixEno4kwAAACM"]
[Thu Sep 17 15:11:58.443431 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/v2/.env"] [unique_id "aqxXnucL08BTTQixEno4mQAAAHs"]
[Thu Sep 17 15:11:58.602170 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/v3/.env"] [unique_id "aqxXnucL08BTTQixEno4rQAAAHk"]
[Thu Sep 17 15:11:58.647591 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxXnucL08BTTQixEno4sgAAAHU"]
[Thu Sep 17 15:11:58.647687 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:47260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/endpoints/class-wp-rest-widgets-controller.php"] [unique_id "aqxXnucL08BTTQixEno4sgAAAHU"]
[Thu Sep 17 15:11:58.647901 2026] [security2:error] [pid 971102:tid 971250] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/gitlab/.env"] [unique_id "aqxXnucL08BTTQixEno4sQAAABA"]
[Thu Sep 17 15:11:58.754104 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/v1/.env"] [unique_id "aqxXnucL08BTTQixEno4ugAAABw"]
[Thu Sep 17 15:11:58.809640 2026] [security2:error] [pid 971102:tid 971259] [client 45.169.98.18:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnucL08BTTQixEno4vQAAABk"]
[Thu Sep 17 15:11:58.809779 2026] [security2:error] [pid 971102:tid 971259] [client 45.169.98.18:57415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXnucL08BTTQixEno4vQAAABk"]
[Thu Sep 17 15:11:58.816720 2026] [security2:error] [pid 971102:tid 971344] [client 157.66.54.188:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.54.66.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qja.nnk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "aqxXnucL08BTTQixEno4uAAAAG4"]
[Thu Sep 17 15:11:58.818955 2026] [security2:error] [pid 971102:tid 971314] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/github/.env"] [unique_id "aqxXnucL08BTTQixEno4xgAAAFA"]
[Thu Sep 17 15:11:58.906976 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/v2/.env"] [unique_id "aqxXnucL08BTTQixEno4yAAAAAw"]
[Thu Sep 17 15:11:58.932011 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:47266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxXnucL08BTTQixEno4ywAAAEc"]
[Thu Sep 17 15:11:59.059199 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/rest/.env"] [unique_id "aqxXn-cL08BTTQixEno41QAAAFg"]
[Thu Sep 17 15:11:59.106859 2026] [security2:error] [pid 971102:tid 971274] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/actions/.env"] [unique_id "aqxXn-cL08BTTQixEno42AAAACg"]
[Thu Sep 17 15:11:59.219745 2026] [security2:error] [pid 971102:tid 971350] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/graphql/.env"] [unique_id "aqxXn-cL08BTTQixEno44AAAAHQ"]
[Thu Sep 17 15:11:59.263943 2026] [security2:error] [pid 971102:tid 971242] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno43QAAAAg"]
[Thu Sep 17 15:11:59.277204 2026] [security2:error] [pid 971102:tid 971283] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/circleci/.env"] [unique_id "aqxXn-cL08BTTQixEno44gAAADE"]
[Thu Sep 17 15:11:59.368447 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/gateway/.env"] [unique_id "aqxXn-cL08BTTQixEno45QAAAG0"]
[Thu Sep 17 15:11:59.387547 2026] [authz_core:error] [pid 971102:tid 971263] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/fields/error_log
[Thu Sep 17 15:11:59.389426 2026] [security2:error] [pid 971102:tid 971263] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "aqxXn-cL08BTTQixEno45AAAAB0"]
[Thu Sep 17 15:11:59.499904 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/travis/.env"] [unique_id "aqxXn-cL08BTTQixEno47AAAAE0"]
[Thu Sep 17 15:11:59.518275 2026] [security2:error] [pid 971102:tid 971238] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/microservice/.env"] [unique_id "aqxXn-cL08BTTQixEno47QAAAAQ"]
[Thu Sep 17 15:11:59.533983 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:47266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/wp-includes/rest-api/"] [unique_id "aqxXn-cL08BTTQixEno47gAAAF8"]
[Thu Sep 17 15:11:59.615196 2026] [security2:error] [pid 971102:tid 971335] [client 162.241.226.11:40806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxXnucL08BTTQixEno4rAAAAGo"]
[Thu Sep 17 15:11:59.675309 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/buildkite/.env"] [unique_id "aqxXn-cL08BTTQixEno49AAAACY"]
[Thu Sep 17 15:11:59.683630 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/service/.env"] [unique_id "aqxXn-cL08BTTQixEno49QAAAEk"]
[Thu Sep 17 15:11:59.747958 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "aqxXn-cL08BTTQixEno4-QAAACM"]
[Thu Sep 17 15:11:59.822837 2026] [security2:error] [pid 971102:tid 971294] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno49wAAADw"]
[Thu Sep 17 15:11:59.837196 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/v3/.env"] [unique_id "aqxXn-cL08BTTQixEno4-wAAAHs"]
[Thu Sep 17 15:11:59.912427 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno48wAAAGg"]
[Thu Sep 17 15:11:59.912451 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno48wAAAGg"]
[Thu Sep 17 15:11:59.923997 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mysql/.env"] [unique_id "aqxXn-cL08BTTQixEno4_QAAACs"]
[Thu Sep 17 15:11:59.984559 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/apps/.env"] [unique_id "aqxXn-cL08BTTQixEno4_gAAABc"]
[Thu Sep 17 15:11:59.995336 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/dev/.env"] [unique_id "aqxXn-cL08BTTQixEno4_wAAABE"]
[Thu Sep 17 15:12:00.147936 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/api/staging/.env"] [unique_id "aqxXoOcL08BTTQixEno5AgAAABU"]
[Thu Sep 17 15:12:00.201494 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:47266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5FAAAABw"]
[Thu Sep 17 15:12:00.201586 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:47266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-comment-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5FAAAABw"]
[Thu Sep 17 15:12:00.218311 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "aqxXoOcL08BTTQixEno5FQAAADs"]
[Thu Sep 17 15:12:00.272280 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/postgres/.env"] [unique_id "aqxXoOcL08BTTQixEno5FwAAABI"]
[Thu Sep 17 15:12:00.298135 2026] [security2:error] [pid 971102:tid 971288] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoOcL08BTTQixEno5FgAAADY"]
[Thu Sep 17 15:12:00.299411 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/vendor/.env"] [unique_id "aqxXoOcL08BTTQixEno5GAAAAG8"]
[Thu Sep 17 15:12:00.447703 2026] [security2:error] [pid 971102:tid 971314] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/web/.env"] [unique_id "aqxXoOcL08BTTQixEno5HQAAAFA"]
[Thu Sep 17 15:12:00.452769 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/lib/.env"] [unique_id "aqxXoOcL08BTTQixEno5HgAAAEA"]
[Thu Sep 17 15:12:00.488096 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5HwAAAGs"]
[Thu Sep 17 15:12:00.488207 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:47642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5HwAAAGs"]
[Thu Sep 17 15:12:00.615546 2026] [security2:error] [pid 971102:tid 971310] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/resources/.env"] [unique_id "aqxXoOcL08BTTQixEno5IQAAAEw"]
[Thu Sep 17 15:12:00.659867 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/mongodb/.env"] [unique_id "aqxXoOcL08BTTQixEno5IgAAAAw"]
[Thu Sep 17 15:12:00.675027 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/site/.env"] [unique_id "aqxXoOcL08BTTQixEno5JQAAADU"]
[Thu Sep 17 15:12:00.765363 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:47652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5JwAAABs"]
[Thu Sep 17 15:12:00.765476 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:47652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-post-meta-fields.php"] [unique_id "aqxXoOcL08BTTQixEno5JwAAABs"]
[Thu Sep 17 15:12:00.769507 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/assets/.env"] [unique_id "aqxXoOcL08BTTQixEno5KAAAAEc"]
[Thu Sep 17 15:12:00.825626 2026] [security2:error] [pid 971102:tid 971268] [client 162.241.226.11:40812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxXn-cL08BTTQixEno4-AAAACI"]
[Thu Sep 17 15:12:00.870712 2026] [security2:error] [pid 971102:tid 971323] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoOcL08BTTQixEno5NAAAAFk"]
[Thu Sep 17 15:12:00.903582 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/public/.env"] [unique_id "aqxXoOcL08BTTQixEno5NwAAAAc"]
[Thu Sep 17 15:12:00.921734 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/uploads/.env"] [unique_id "aqxXoOcL08BTTQixEno5OAAAADI"]
[Thu Sep 17 15:12:00.972980 2026] [security2:error] [pid 971102:tid 971326] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/redis/.env"] [unique_id "aqxXoOcL08BTTQixEno5OQAAAFw"]
[Thu Sep 17 15:12:01.066389 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5OgAAABY"]
[Thu Sep 17 15:12:01.066545 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:47662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-term-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5OgAAABY"]
[Thu Sep 17 15:12:01.073931 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/internal/.env"] [unique_id "aqxXoecL08BTTQixEno5OwAAAFg"]
[Thu Sep 17 15:12:01.224841 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/tools/.env"] [unique_id "aqxXoecL08BTTQixEno5RgAAAAg"]
[Thu Sep 17 15:12:01.225790 2026] [security2:error] [pid 971102:tid 971358] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoecL08BTTQixEno5PQAAAHw"]
[Thu Sep 17 15:12:01.271616 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/elasticsearch/.env"] [unique_id "aqxXoecL08BTTQixEno5SAAAABo"]
[Thu Sep 17 15:12:01.337034 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:64822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5SQAAAFc"]
[Thu Sep 17 15:12:01.337965 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:64822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5SQAAAFc"]
[Thu Sep 17 15:12:01.353249 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5SgAAAA0"]
[Thu Sep 17 15:12:01.353357 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:47670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/fields/class-wp-rest-user-meta-fields.php"] [unique_id "aqxXoecL08BTTQixEno5SgAAAA0"]
[Thu Sep 17 15:12:01.376430 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/scripts/.env"] [unique_id "aqxXoecL08BTTQixEno5SwAAACQ"]
[Thu Sep 17 15:12:01.407767 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "aqxXoecL08BTTQixEno5TAAAACw"]
[Thu Sep 17 15:12:01.527203 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/bin/.env"] [unique_id "aqxXoecL08BTTQixEno5TwAAAG0"]
[Thu Sep 17 15:12:01.636022 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/server/.env"] [unique_id "aqxXoecL08BTTQixEno5UgAAAE0"]
[Thu Sep 17 15:12:01.636574 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:47674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxXoecL08BTTQixEno5UwAAAFI"]
[Thu Sep 17 15:12:01.675636 2026] [security2:error] [pid 971102:tid 971312] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sbin/.env"] [unique_id "aqxXoecL08BTTQixEno5VAAAAE4"]
[Thu Sep 17 15:12:01.693169 2026] [security2:error] [pid 971102:tid 971239] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoecL08BTTQixEno5UQAAAAU"]
[Thu Sep 17 15:12:01.745452 2026] [security2:error] [pid 971102:tid 971263] [client 185.55.149.49:64646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5VwAAAB0"]
[Thu Sep 17 15:12:01.746461 2026] [security2:error] [pid 971102:tid 971263] [client 185.55.149.49:64646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXoecL08BTTQixEno5VwAAAB0"]
[Thu Sep 17 15:12:01.798199 2026] [authz_core:error] [pid 971102:tid 971286] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/rest-api/search/error_log
[Thu Sep 17 15:12:01.799419 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/"] [unique_id "aqxXoecL08BTTQixEno5WQAAADQ"]
[Thu Sep 17 15:12:01.826825 2026] [security2:error] [pid 971102:tid 971273] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/local/.env"] [unique_id "aqxXoecL08BTTQixEno5WgAAACc"]
[Thu Sep 17 15:12:01.842931 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/rabbitmq/.env"] [unique_id "aqxXoecL08BTTQixEno5WwAAACY"]
[Thu Sep 17 15:12:01.864331 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/frontend/.env"] [unique_id "aqxXoecL08BTTQixEno5XAAAACM"]
[Thu Sep 17 15:12:01.941307 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:47674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/wp-includes/rest-api/"] [unique_id "aqxXoecL08BTTQixEno5XwAAAGI"]
[Thu Sep 17 15:12:01.981871 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/portal/.env"] [unique_id "aqxXoecL08BTTQixEno5YAAAAGg"]
[Thu Sep 17 15:12:02.096621 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/src/.env"] [unique_id "aqxXoucL08BTTQixEno5ZAAAADg"]
[Thu Sep 17 15:12:02.116626 2026] [security2:error] [pid 971102:tid 971253] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/kafka/.env"] [unique_id "aqxXoucL08BTTQixEno5ZQAAABM"]
[Thu Sep 17 15:12:02.131621 2026] [security2:error] [pid 971102:tid 971307] [client 115.244.164.14:52805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoucL08BTTQixEno5ZgAAAEk"]
[Thu Sep 17 15:12:02.131764 2026] [security2:error] [pid 971102:tid 971307] [client 115.244.164.14:52805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXoucL08BTTQixEno5ZgAAAEk"]
[Thu Sep 17 15:12:02.133336 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/dashboard/.env"] [unique_id "aqxXoucL08BTTQixEno5ZwAAABE"]
[Thu Sep 17 15:12:02.285246 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/panel/.env"] [unique_id "aqxXoucL08BTTQixEno5awAAACk"]
[Thu Sep 17 15:12:02.308944 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5YgAAADM"]
[Thu Sep 17 15:12:02.308977 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5YgAAADM"]
[Thu Sep 17 15:12:02.314009 2026] [security2:error] [pid 971102:tid 971355] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5agAAAHk"]
[Thu Sep 17 15:12:02.324844 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/core/.env"] [unique_id "aqxXoucL08BTTQixEno5bAAAAFY"]
[Thu Sep 17 15:12:02.399701 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/queue/.env"] [unique_id "aqxXoucL08BTTQixEno5bQAAABw"]
[Thu Sep 17 15:12:02.435988 2026] [security2:error] [pid 971102:tid 971288] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/crm/.env"] [unique_id "aqxXoucL08BTTQixEno5bwAAADY"]
[Thu Sep 17 15:12:02.454196 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5cAAAAG8"]
[Thu Sep 17 15:12:02.454275 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:47674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-format-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5cAAAAG8"]
[Thu Sep 17 15:12:02.558301 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/core/app/.env"] [unique_id "aqxXoucL08BTTQixEno5dwAAADU"]
[Thu Sep 17 15:12:02.586315 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/erp/.env"] [unique_id "aqxXoucL08BTTQixEno5eAAAAA4"]
[Thu Sep 17 15:12:02.613281 2026] [security2:error] [pid 971102:tid 971310] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5dgAAAEw"]
[Thu Sep 17 15:12:02.621082 2026] [security2:error] [pid 971102:tid 971268] [client 5.189.145.112:52547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxXoucL08BTTQixEno5eQAAACI"], referer: binance.com
[Thu Sep 17 15:12:02.731552 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5egAAACU"]
[Thu Sep 17 15:12:02.731653 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:47680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-post-search-handler.php"] [unique_id "aqxXoucL08BTTQixEno5egAAACU"]
[Thu Sep 17 15:12:02.737790 2026] [security2:error] [pid 971102:tid 971280] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/shop/.env"] [unique_id "aqxXoucL08BTTQixEno5ewAAAC4"]
[Thu Sep 17 15:12:02.791842 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "aqxXoucL08BTTQixEno5fgAAAAM"]
[Thu Sep 17 15:12:02.887200 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/store/.env"] [unique_id "aqxXoucL08BTTQixEno5gAAAAEo"]
[Thu Sep 17 15:12:03.020670 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/private/.env"] [unique_id "aqxXo-cL08BTTQixEno5hQAAAAI"]
[Thu Sep 17 15:12:03.027562 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/worker/.env"] [unique_id "aqxXo-cL08BTTQixEno5hgAAAAA"]
[Thu Sep 17 15:12:03.027754 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:47682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5hwAAAE8"]
[Thu Sep 17 15:12:03.027823 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:47682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5hwAAAE8"]
[Thu Sep 17 15:12:03.039798 2026] [security2:error] [pid 971102:tid 971303] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/saas/.env"] [unique_id "aqxXo-cL08BTTQixEno5iAAAAEU"]
[Thu Sep 17 15:12:03.058361 2026] [security2:error] [pid 971102:tid 971256] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXoucL08BTTQixEno5hAAAABY"]
[Thu Sep 17 15:12:03.192158 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/client/.env"] [unique_id "aqxXo-cL08BTTQixEno5jAAAABo"]
[Thu Sep 17 15:12:03.240474 2026] [security2:error] [pid 971102:tid 971359] [client 84.233.195.159:63819] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXo-cL08BTTQixEno5kQAAAH0"]
[Thu Sep 17 15:12:03.249105 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/application/.env"] [unique_id "aqxXo-cL08BTTQixEno5kgAAAFc"]
[Thu Sep 17 15:12:03.279755 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/job/.env"] [unique_id "aqxXo-cL08BTTQixEno5kwAAAA0"]
[Thu Sep 17 15:12:03.316705 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:47684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5lQAAAFs"]
[Thu Sep 17 15:12:03.316780 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:47684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/rest-api/search/class-wp-rest-term-search-handler.php"] [unique_id "aqxXo-cL08BTTQixEno5lQAAAFs"]
[Thu Sep 17 15:12:03.340904 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/project/.env"] [unique_id "aqxXo-cL08BTTQixEno5lwAAAEY"]
[Thu Sep 17 15:12:03.394356 2026] [security2:error] [pid 971102:tid 971343] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXo-cL08BTTQixEno5lgAAAG0"]
[Thu Sep 17 15:12:03.478975 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/bootstrap/.env"] [unique_id "aqxXo-cL08BTTQixEno5mwAAAHM"]
[Thu Sep 17 15:12:03.497114 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/admin-panel/.env"] [unique_id "aqxXo-cL08BTTQixEno5nAAAAAU"]
[Thu Sep 17 15:12:03.497114 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/test/.env"] [unique_id "aqxXo-cL08BTTQixEno5nQAAAGo"]
[Thu Sep 17 15:12:03.613716 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxXo-cL08BTTQixEno5nwAAADQ"]
[Thu Sep 17 15:12:03.651149 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/control-panel/.env"] [unique_id "aqxXo-cL08BTTQixEno5oAAAACY"]
[Thu Sep 17 15:12:03.682090 2026] [security2:error] [pid 971102:tid 971273] [client 162.241.226.11:16956] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxXo-cL08BTTQixEno5oQAAACc"]
[Thu Sep 17 15:12:03.707214 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/database/.env"] [unique_id "aqxXo-cL08BTTQixEno5pAAAAEg"]
[Thu Sep 17 15:12:03.737669 2026] [security2:error] [pid 971102:tid 971263] [client 84.233.195.149:52335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXo-cL08BTTQixEno5pQAAAB0"]
[Thu Sep 17 15:12:03.765976 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/qa/.env"] [unique_id "aqxXo-cL08BTTQixEno5qAAAAF8"]
[Thu Sep 17 15:12:03.773294 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxXo-cL08BTTQixEno5pgAAAH8"]
[Thu Sep 17 15:12:03.813621 2026] [security2:error] [pid 971102:tid 971296] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/user-panel/.env"] [unique_id "aqxXo-cL08BTTQixEno5qgAAAD4"]
[Thu Sep 17 15:12:03.911571 2026] [security2:error] [pid 971102:tid 971327] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXo-cL08BTTQixEno5qwAAAF0"]
[Thu Sep 17 15:12:03.917180 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxXo-cL08BTTQixEno5rAAAABU"]
[Thu Sep 17 15:12:03.934543 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/storage/.env"] [unique_id "aqxXo-cL08BTTQixEno5rQAAAHU"]
[Thu Sep 17 15:12:03.969898 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/node/.env"] [unique_id "aqxXo-cL08BTTQixEno5rgAAAHs"]
[Thu Sep 17 15:12:04.073480 2026] [authz_core:error] [pid 971102:tid 971318] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sitemaps/providers/error_log
[Thu Sep 17 15:12:04.074289 2026] [security2:error] [pid 971102:tid 971318] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/"] [unique_id "aqxXpOcL08BTTQixEno5sgAAAFQ"]
[Thu Sep 17 15:12:04.078418 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/preview/.env"] [unique_id "aqxXpOcL08BTTQixEno5swAAABw"]
[Thu Sep 17 15:12:04.121137 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/express/.env"] [unique_id "aqxXpOcL08BTTQixEno5twAAAG8"]
[Thu Sep 17 15:12:04.158133 2026] [core:error] [pid 971102:tid 971314] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:04.158150 2026] [core:error] [pid 971102:tid 971314] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:04.164624 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/.env"] [unique_id "aqxXpOcL08BTTQixEno5uwAAAEA"]
[Thu Sep 17 15:12:04.224322 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/wp-includes/sitemaps/"] [unique_id "aqxXpOcL08BTTQixEno5vgAAABg"]
[Thu Sep 17 15:12:04.245225 2026] [security2:error] [pid 971102:tid 971293] [client 84.233.195.157:54932] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpOcL08BTTQixEno5wAAAADs"]
[Thu Sep 17 15:12:04.275601 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/next/.env"] [unique_id "aqxXpOcL08BTTQixEno5wQAAAHg"]
[Thu Sep 17 15:12:04.350291 2026] [security2:error] [pid 971102:tid 971287] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno5wgAAADU"]
[Thu Sep 17 15:12:04.396713 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/html/.env"] [unique_id "aqxXpOcL08BTTQixEno5xAAAABs"]
[Thu Sep 17 15:12:04.428616 2026] [security2:error] [pid 971102:tid 971264] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/nuxt/.env"] [unique_id "aqxXpOcL08BTTQixEno5xQAAAB4"]
[Thu Sep 17 15:12:04.469497 2026] [security2:error] [pid 971102:tid 971328] [client 57.141.14.108:65094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxXo-cL08BTTQixEno5qQAAXhM"]
[Thu Sep 17 15:12:04.469724 2026] [security2:error] [pid 971102:tid 971243] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/beta/.env"] [unique_id "aqxXpOcL08BTTQixEno5yQAAAAk"]
[Thu Sep 17 15:12:04.554409 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno5wwAAABI"]
[Thu Sep 17 15:12:04.554432 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno5wwAAABI"]
[Thu Sep 17 15:12:04.587710 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/nest/.env"] [unique_id "aqxXpOcL08BTTQixEno5ygAAADI"]
[Thu Sep 17 15:12:04.630482 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/current/.env"] [unique_id "aqxXpOcL08BTTQixEno5zwAAADE"]
[Thu Sep 17 15:12:04.697415 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxXpOcL08BTTQixEno50QAAACg"]
[Thu Sep 17 15:12:04.697547 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-posts.php"] [unique_id "aqxXpOcL08BTTQixEno50QAAACg"]
[Thu Sep 17 15:12:04.743459 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/react/.env"] [unique_id "aqxXpOcL08BTTQixEno51gAAAE8"]
[Thu Sep 17 15:12:04.759834 2026] [security2:error] [pid 971102:tid 971322] [client 84.233.195.153:57872] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpOcL08BTTQixEno52AAAAFg"]
[Thu Sep 17 15:12:04.782654 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/uat/.env"] [unique_id "aqxXpOcL08BTTQixEno52QAAABY"]
[Thu Sep 17 15:12:04.815766 2026] [security2:error] [pid 971102:tid 971234] [client 157.66.54.188:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxXpOcL08BTTQixEno51QAAAAA"]
[Thu Sep 17 15:12:04.865529 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/release/.env"] [unique_id "aqxXpOcL08BTTQixEno52gAAABo"]
[Thu Sep 17 15:12:04.876488 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.130.148:44820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXpOcL08BTTQixEno52wAAAGk"]
[Thu Sep 17 15:12:04.892611 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/vue/.env"] [unique_id "aqxXpOcL08BTTQixEno53AAAAH0"]
[Thu Sep 17 15:12:04.963354 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/stage/.env"] [unique_id "aqxXpOcL08BTTQixEno53gAAAFU"]
[Thu Sep 17 15:12:04.978975 2026] [security2:error] [pid 971102:tid 971240] [client 104.28.198.244:22856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpOcL08BTTQixEno53QAAAAY"]
[Thu Sep 17 15:12:04.979090 2026] [security2:error] [pid 971102:tid 971240] [client 104.28.198.244:22856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpOcL08BTTQixEno53QAAAAY"]
[Thu Sep 17 15:12:04.982070 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxXpOcL08BTTQixEno53wAAACw"]
[Thu Sep 17 15:12:04.982167 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:47708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-taxonomies.php"] [unique_id "aqxXpOcL08BTTQixEno53wAAACw"]
[Thu Sep 17 15:12:05.048201 2026] [security2:error] [pid 971102:tid 971343] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/angular/.env"] [unique_id "aqxXpecL08BTTQixEno54AAAAG0"]
[Thu Sep 17 15:12:05.093811 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/releases/.env"] [unique_id "aqxXpecL08BTTQixEno54wAAAEM"]
[Thu Sep 17 15:12:05.178651 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/development/.env"] [unique_id "aqxXpecL08BTTQixEno55AAAAGo"]
[Thu Sep 17 15:12:05.207507 2026] [security2:error] [pid 971102:tid 971330] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/svelte/.env"] [unique_id "aqxXpecL08BTTQixEno55wAAAGA"]
[Thu Sep 17 15:12:05.249800 2026] [security2:error] [pid 971102:tid 971244] [client 84.233.195.152:53379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpecL08BTTQixEno56wAAAAo"]
[Thu Sep 17 15:12:05.264387 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxXpecL08BTTQixEno57QAAAEg"]
[Thu Sep 17 15:12:05.264466 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:47718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sitemaps/providers/class-wp-sitemaps-users.php"] [unique_id "aqxXpecL08BTTQixEno57QAAAEg"]
[Thu Sep 17 15:12:05.326185 2026] [security2:error] [pid 971102:tid 971277] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/shared/.env"] [unique_id "aqxXpecL08BTTQixEno59AAAACs"]
[Thu Sep 17 15:12:05.362299 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/vite/.env"] [unique_id "aqxXpecL08BTTQixEno59QAAAF8"]
[Thu Sep 17 15:12:05.474828 2026] [security2:error] [pid 971102:tid 971336] [client 169.58.197.253:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxXpecL08BTTQixEno5-QAAAGY"], referer: binance.com
[Thu Sep 17 15:12:05.508405 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/production/.env"] [unique_id "aqxXpecL08BTTQixEno5-gAAABU"]
[Thu Sep 17 15:12:05.524832 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/backup/.env"] [unique_id "aqxXpecL08BTTQixEno5-wAAADw"]
[Thu Sep 17 15:12:05.561905 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/deploy/.env"] [unique_id "aqxXpecL08BTTQixEno6AAAAAFQ"]
[Thu Sep 17 15:12:05.563958 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.130.148:44826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXpecL08BTTQixEno6AQAAAAc"]
[Thu Sep 17 15:12:05.571987 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:47720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxXpecL08BTTQixEno6AgAAABw"]
[Thu Sep 17 15:12:05.678409 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/backups/.env"] [unique_id "aqxXpecL08BTTQixEno6BgAAADg"]
[Thu Sep 17 15:12:05.733190 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:59750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "makingreligionhealthy.com"] [uri "/config/app/.env"] [unique_id "aqxXpecL08BTTQixEno6CQAAADs"]
[Thu Sep 17 15:12:05.733306 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxXpecL08BTTQixEno6CAAAAFo"]
[Thu Sep 17 15:12:05.736933 2026] [security2:error] [pid 971102:tid 971345] [client 84.233.195.155:52438] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXpecL08BTTQixEno6CwAAAG8"]
[Thu Sep 17 15:12:05.790133 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/build/.env"] [unique_id "aqxXpecL08BTTQixEno6DgAAADU"]
[Thu Sep 17 15:12:05.833059 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/old/.env"] [unique_id "aqxXpecL08BTTQixEno6EAAAAEc"]
[Thu Sep 17 15:12:05.877058 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:47720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxXpecL08BTTQixEno6EgAAAEo"]
[Thu Sep 17 15:12:05.914367 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpecL08BTTQixEno6EwAAAFY"]
[Thu Sep 17 15:12:05.914450 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:53362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpecL08BTTQixEno6EwAAAFY"]
[Thu Sep 17 15:12:05.987140 2026] [security2:error] [pid 971102:tid 971280] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/tmp/.env"] [unique_id "aqxXpecL08BTTQixEno6FgAAAC4"]
[Thu Sep 17 15:12:06.022286 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/dist/.env"] [unique_id "aqxXpucL08BTTQixEno6GAAAADI"]
[Thu Sep 17 15:12:06.025079 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/LICENSE"] [unique_id "aqxXpucL08BTTQixEno6GQAAACg"]
[Thu Sep 17 15:12:06.041409 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.117.146:59750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php"] [unique_id "aqxXpecL08BTTQixEno6FwAAABI"]
[Thu Sep 17 15:12:06.137066 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/temp/.env"] [unique_id "aqxXpucL08BTTQixEno6GgAAAGM"]
[Thu Sep 17 15:12:06.167839 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:47720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxXpucL08BTTQixEno6GwAAAHc"]
[Thu Sep 17 15:12:06.167908 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:47720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/autoload-php7.php"] [unique_id "aqxXpucL08BTTQixEno6GwAAAHc"]
[Thu Sep 17 15:12:06.249205 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/public_html/.env"] [unique_id "aqxXpucL08BTTQixEno6HwAAAD0"]
[Thu Sep 17 15:12:06.250276 2026] [core:error] [pid 971102:tid 971303] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:06.250288 2026] [core:error] [pid 971102:tid 971303] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:06.250375 2026] [security2:error] [pid 971102:tid 971303] [client 74.7.175.159:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sweetvictories.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "aqxXpucL08BTTQixEno6HgAAAEU"]
[Thu Sep 17 15:12:06.252379 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.130.148:44830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXpucL08BTTQixEno6IAAAADE"]
[Thu Sep 17 15:12:06.255878 2026] [security2:error] [pid 971102:tid 971359] [client 74.7.175.159:33754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sweetvictories.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxXpucL08BTTQixEno6HAAAfSA"]
[Thu Sep 17 15:12:06.293433 2026] [security2:error] [pid 971102:tid 971309] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/lab/.env"] [unique_id "aqxXpucL08BTTQixEno6IwAAAEs"]
[Thu Sep 17 15:12:06.375990 2026] [security2:error] [pid 971102:tid 971348] [client 114.198.138.124:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpucL08BTTQixEno6MAAAAHI"]
[Thu Sep 17 15:12:06.376143 2026] [security2:error] [pid 971102:tid 971348] [client 114.198.138.124:59880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXpucL08BTTQixEno6MAAAAHI"]
[Thu Sep 17 15:12:06.442558 2026] [security2:error] [pid 971102:tid 971237] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cronlab/.env"] [unique_id "aqxXpucL08BTTQixEno6PAAAAAM"]
[Thu Sep 17 15:12:06.455717 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxXpucL08BTTQixEno6PQAAAGU"]
[Thu Sep 17 15:12:06.477192 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/htdocs/.env"] [unique_id "aqxXpucL08BTTQixEno6QAAAAGA"]
[Thu Sep 17 15:12:06.604627 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cron/.env"] [unique_id "aqxXpucL08BTTQixEno6SAAAACY"]
[Thu Sep 17 15:12:06.606504 2026] [authz_core:error] [pid 971102:tid 971296] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/lib/error_log
[Thu Sep 17 15:12:06.608206 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/"] [unique_id "aqxXpucL08BTTQixEno6RAAAAD4"]
[Thu Sep 17 15:12:06.705856 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/www/.env"] [unique_id "aqxXpucL08BTTQixEno6SwAAAHU"]
[Thu Sep 17 15:12:06.752127 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/wp-includes/sodium_compat/"] [unique_id "aqxXpucL08BTTQixEno6TAAAAEE"]
[Thu Sep 17 15:12:06.759611 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/en/.env"] [unique_id "aqxXpucL08BTTQixEno6TQAAAH8"]
[Thu Sep 17 15:12:06.764317 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:50458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/info.php"] [unique_id "aqxXpucL08BTTQixEno6TgAAACs"]
[Thu Sep 17 15:12:06.937688 2026] [security2:error] [pid 971102:tid 971315] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/html/.env"] [unique_id "aqxXpucL08BTTQixEno6WgAAAFE"]
[Thu Sep 17 15:12:06.975193 2026] [security2:error] [pid 971102:tid 971259] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/administrator/.env"] [unique_id "aqxXpucL08BTTQixEno6VgAAABk"]
[Thu Sep 17 15:12:07.084146 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpucL08BTTQixEno6UgAAAF0"]
[Thu Sep 17 15:12:07.084167 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXpucL08BTTQixEno6UgAAAF0"]
[Thu Sep 17 15:12:07.132220 2026] [security2:error] [pid 971102:tid 971352] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/psnlink/.env"] [unique_id "aqxXp-cL08BTTQixEno6YQAAAHY"]
[Thu Sep 17 15:12:07.172235 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/live/.env"] [unique_id "aqxXp-cL08BTTQixEno6YgAAAGs"]
[Thu Sep 17 15:12:07.224972 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxXp-cL08BTTQixEno6YwAAABQ"]
[Thu Sep 17 15:12:07.225047 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:47730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/constants.php"] [unique_id "aqxXp-cL08BTTQixEno6YwAAABQ"]
[Thu Sep 17 15:12:07.283320 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/exapi/.env"] [unique_id "aqxXp-cL08BTTQixEno6ZAAAAFk"]
[Thu Sep 17 15:12:07.338017 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:07.338030 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:07.347128 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXp-cL08BTTQixEno6ZQAAACo"]
[Thu Sep 17 15:12:07.347216 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:42300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXp-cL08BTTQixEno6ZQAAACo"]
[Thu Sep 17 15:12:07.402447 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/prod/.env"] [unique_id "aqxXp-cL08BTTQixEno6agAAAFY"]
[Thu Sep 17 15:12:07.434546 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sitemaps/.env"] [unique_id "aqxXp-cL08BTTQixEno6awAAADI"]
[Thu Sep 17 15:12:07.473552 2026] [security2:error] [pid 971102:tid 971281] [client 34.32.117.146:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/php.php"] [unique_id "aqxXp-cL08BTTQixEno6bAAAAC8"]
[Thu Sep 17 15:12:07.514907 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxXp-cL08BTTQixEno6bQAAACg"]
[Thu Sep 17 15:12:07.514973 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:47742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/namespaced.php"] [unique_id "aqxXp-cL08BTTQixEno6bQAAACg"]
[Thu Sep 17 15:12:07.629677 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/dev/.env"] [unique_id "aqxXp-cL08BTTQixEno6dQAAAA0"]
[Thu Sep 17 15:12:07.718635 2026] [security2:error] [pid 971102:tid 971321] [client 198.20.67.197:41326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6dwAAAFc"]
[Thu Sep 17 15:12:07.718777 2026] [security2:error] [pid 971102:tid 971321] [client 198.20.67.197:41326] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6dwAAAFc"]
[Thu Sep 17 15:12:07.763363 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:37346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6cwAAABo"]
[Thu Sep 17 15:12:07.803491 2026] [security2:error] [pid 971102:tid 971151] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env"] [unique_id "aqxXp-cL08BTTQixEno6egAAOi8"]
[Thu Sep 17 15:12:07.806393 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxXp-cL08BTTQixEno6gAAAADk"]
[Thu Sep 17 15:12:07.806471 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat.php"] [unique_id "aqxXp-cL08BTTQixEno6gAAAADk"]
[Thu Sep 17 15:12:07.858150 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/staging/.env"] [unique_id "aqxXp-cL08BTTQixEno6hwAAAG0"]
[Thu Sep 17 15:12:07.888475 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6eQAAOjw"]
[Thu Sep 17 15:12:07.890430 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fgAAOj0"]
[Thu Sep 17 15:12:07.890575 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fQAAOkc"]
[Thu Sep 17 15:12:07.890623 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6ewAAOks"]
[Thu Sep 17 15:12:07.890676 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fAAAOj8"]
[Thu Sep 17 15:12:07.891626 2026] [security2:error] [pid 971102:tid 971175] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.old"] [unique_id "aqxXp-cL08BTTQixEno6jQAAOkc"]
[Thu Sep 17 15:12:07.891626 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.bak"] [unique_id "aqxXp-cL08BTTQixEno6jAAAOks"]
[Thu Sep 17 15:12:07.892089 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6fwAAOi8"]
[Thu Sep 17 15:12:07.892780 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.backup"] [unique_id "aqxXp-cL08BTTQixEno6kAAAOlM"]
[Thu Sep 17 15:12:07.972299 2026] [security2:error] [pid 971102:tid 971237] [client 198.20.67.197:41340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/faqs.php"] [unique_id "aqxXp-cL08BTTQixEno6lgAAAAM"]
[Thu Sep 17 15:12:07.972444 2026] [security2:error] [pid 971102:tid 971237] [client 198.20.67.197:41340] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/faqs.php"] [unique_id "aqxXp-cL08BTTQixEno6lgAAAAM"]
[Thu Sep 17 15:12:07.976052 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6jgAAOic"]
[Thu Sep 17 15:12:07.976209 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6iwAAOj0"]
[Thu Sep 17 15:12:07.976273 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6kgAAOkc"]
[Thu Sep 17 15:12:07.978796 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6igAAOjw"]
[Thu Sep 17 15:12:07.978872 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6jwAAOks"]
[Thu Sep 17 15:12:07.979227 2026] [security2:error] [pid 971102:tid 971292] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6kQAAOk4"]
[Thu Sep 17 15:12:08.039464 2026] [security2:error] [pid 971102:tid 971304] [client 198.20.67.197:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/windows.php"] [unique_id "aqxXqOcL08BTTQixEno6mAAAAEY"]
[Thu Sep 17 15:12:08.039575 2026] [security2:error] [pid 971102:tid 971304] [client 198.20.67.197:41352] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/windows.php"] [unique_id "aqxXqOcL08BTTQixEno6mAAAAEY"]
[Thu Sep 17 15:12:08.065294 2026] [security2:error] [pid 971102:tid 971335] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6lwAAZU8"]
[Thu Sep 17 15:12:08.068401 2026] [security2:error] [pid 971102:tid 971184] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/.env.php"] [unique_id "aqxXqOcL08BTTQixEno6mgAAW1A"]
[Thu Sep 17 15:12:08.070486 2026] [security2:error] [pid 971102:tid 971180] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env~"] [unique_id "aqxXqOcL08BTTQixEno6mwAAW0w"]
[Thu Sep 17 15:12:08.070495 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.swp"] [unique_id "aqxXqOcL08BTTQixEno6nAAAW0g"]
[Thu Sep 17 15:12:08.088561 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:47762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno6oAAAAEM"]
[Thu Sep 17 15:12:08.088722 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:47762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php72compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno6oAAAAEM"]
[Thu Sep 17 15:12:08.090197 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/opt/.env"] [unique_id "aqxXqOcL08BTTQixEno6oQAAACE"]
[Thu Sep 17 15:12:08.109671 2026] [security2:error] [pid 971102:tid 971263] [client 198.20.67.197:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/roofing.php"] [unique_id "aqxXqOcL08BTTQixEno6ogAAAB0"]
[Thu Sep 17 15:12:08.109850 2026] [security2:error] [pid 971102:tid 971263] [client 198.20.67.197:41354] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/roofing.php"] [unique_id "aqxXqOcL08BTTQixEno6ogAAAB0"]
[Thu Sep 17 15:12:08.124149 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.130.148:44844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/"] [unique_id "aqxXqOcL08BTTQixEno6owAAAHI"]
[Thu Sep 17 15:12:08.129404 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.0.94:37346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXp-cL08BTTQixEno6lAAAACA"]
[Thu Sep 17 15:12:08.147869 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6nwAAWzo"]
[Thu Sep 17 15:12:08.147984 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6ngAAW2A"]
[Thu Sep 17 15:12:08.148021 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6mQAAW00"]
[Thu Sep 17 15:12:08.148187 2026] [security2:error] [pid 971102:tid 971325] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6nQAAW14"]
[Thu Sep 17 15:12:08.159724 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/api/.env"] [unique_id "aqxXqOcL08BTTQixEno6pAAATkI"]
[Thu Sep 17 15:12:08.159784 2026] [security2:error] [pid 971102:tid 971190] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/app/.env"] [unique_id "aqxXqOcL08BTTQixEno6pgAATlU"]
[Thu Sep 17 15:12:08.161632 2026] [security2:error] [pid 971102:tid 971205] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/backend/.env"] [unique_id "aqxXqOcL08BTTQixEno6qgAATmQ"]
[Thu Sep 17 15:12:08.169621 2026] [security2:error] [pid 971102:tid 971285] [client 198.20.67.197:41358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/testimonials.php"] [unique_id "aqxXqOcL08BTTQixEno6rAAAADM"]
[Thu Sep 17 15:12:08.169785 2026] [security2:error] [pid 971102:tid 971285] [client 198.20.67.197:41358] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/testimonials.php"] [unique_id "aqxXqOcL08BTTQixEno6rAAAADM"]
[Thu Sep 17 15:12:08.233126 2026] [security2:error] [pid 971102:tid 971355] [client 198.20.67.197:41364] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chiext.net"] [uri "/style.css"] [unique_id "aqxXqOcL08BTTQixEno6rQAAAHk"]
[Thu Sep 17 15:12:08.237645 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6qQAATlo"]
[Thu Sep 17 15:12:08.237751 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6pwAATlQ"]
[Thu Sep 17 15:12:08.237850 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6pQAATiM"]
[Thu Sep 17 15:12:08.238162 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6qwAATmU"]
[Thu Sep 17 15:12:08.239419 2026] [security2:error] [pid 971102:tid 971312] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6qAAATjs"]
[Thu Sep 17 15:12:08.248905 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/server/.env"] [unique_id "aqxXqOcL08BTTQixEno6rwAAJmk"]
[Thu Sep 17 15:12:08.250012 2026] [security2:error] [pid 971102:tid 971186] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/src/.env"] [unique_id "aqxXqOcL08BTTQixEno6sAAAJlI"]
[Thu Sep 17 15:12:08.250022 2026] [security2:error] [pid 971102:tid 971211] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/config/.env"] [unique_id "aqxXqOcL08BTTQixEno6sQAAJmo"]
[Thu Sep 17 15:12:08.280504 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.0.94:37346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/logs/.env"] [unique_id "aqxXqOcL08BTTQixEno6sgAAAHw"]
[Thu Sep 17 15:12:08.319484 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/laravel/.env"] [unique_id "aqxXqOcL08BTTQixEno6swAAAGY"]
[Thu Sep 17 15:12:08.325989 2026] [security2:error] [pid 971102:tid 971272] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6rgAAJlg"]
[Thu Sep 17 15:12:08.327926 2026] [security2:error] [pid 971102:tid 971194] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/web/.env"] [unique_id "aqxXqOcL08BTTQixEno6tgAAdVk"]
[Thu Sep 17 15:12:08.327957 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/frontend/.env"] [unique_id "aqxXqOcL08BTTQixEno6tQAAdVw"]
[Thu Sep 17 15:12:08.327990 2026] [security2:error] [pid 971102:tid 971219] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/public/.env"] [unique_id "aqxXqOcL08BTTQixEno6twAAdXI"]
[Thu Sep 17 15:12:08.327990 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/client/.env"] [unique_id "aqxXqOcL08BTTQixEno6tAAAdWw"]
[Thu Sep 17 15:12:08.343129 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/var/www/.env"] [unique_id "aqxXqOcL08BTTQixEno6vAAASWs"]
[Thu Sep 17 15:12:08.343181 2026] [security2:error] [pid 971102:tid 971191] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/var/www/html/.env"] [unique_id "aqxXqOcL08BTTQixEno6ugAASVY"]
[Thu Sep 17 15:12:08.343193 2026] [security2:error] [pid 971102:tid 971208] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/laravel/.env"] [unique_id "aqxXqOcL08BTTQixEno6uwAASWc"]
[Thu Sep 17 15:12:08.344596 2026] [security2:error] [pid 971102:tid 971299] [client 198.20.67.197:41372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/contact.php"] [unique_id "aqxXqOcL08BTTQixEno6vQAAAEE"]
[Thu Sep 17 15:12:08.344683 2026] [security2:error] [pid 971102:tid 971299] [client 198.20.67.197:41372] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/contact.php"] [unique_id "aqxXqOcL08BTTQixEno6vQAAAEE"]
[Thu Sep 17 15:12:08.388106 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:47776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxXqOcL08BTTQixEno6vgAAADw"]
[Thu Sep 17 15:12:08.388174 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:47776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat.php"] [unique_id "aqxXqOcL08BTTQixEno6vgAAADw"]
[Thu Sep 17 15:12:08.411711 2026] [security2:error] [pid 971102:tid 971257] [client 198.20.67.197:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/sidinggutters.php"] [unique_id "aqxXqOcL08BTTQixEno6vwAAABc"]
[Thu Sep 17 15:12:08.411777 2026] [security2:error] [pid 971102:tid 971257] [client 198.20.67.197:41388] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/sidinggutters.php"] [unique_id "aqxXqOcL08BTTQixEno6vwAAABc"]
[Thu Sep 17 15:12:08.417939 2026] [security2:error] [pid 971102:tid 971198] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/application/.env"] [unique_id "aqxXqOcL08BTTQixEno6wQAAe10"]
[Thu Sep 17 15:12:08.417970 2026] [security2:error] [pid 971102:tid 971218] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/back/.env"] [unique_id "aqxXqOcL08BTTQixEno6wgAAe3E"]
[Thu Sep 17 15:12:08.417973 2026] [security2:error] [pid 971102:tid 971217] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/backup/.env"] [unique_id "aqxXqOcL08BTTQixEno6wwAAe3A"]
[Thu Sep 17 15:12:08.417999 2026] [security2:error] [pid 971102:tid 971207] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/apps/.env"] [unique_id "aqxXqOcL08BTTQixEno6wAAAe2Y"]
[Thu Sep 17 15:12:08.419334 2026] [security2:error] [pid 971102:tid 971104] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/cms/.env"] [unique_id "aqxXqOcL08BTTQixEno6xAAAUQA"]
[Thu Sep 17 15:12:08.427876 2026] [security2:error] [pid 971102:tid 971192] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/dev/.env"] [unique_id "aqxXqOcL08BTTQixEno6xQAAOFc"]
[Thu Sep 17 15:12:08.428639 2026] [security2:error] [pid 971102:tid 971216] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/prod/.env"] [unique_id "aqxXqOcL08BTTQixEno6xgAAO28"]
[Thu Sep 17 15:12:08.429394 2026] [security2:error] [pid 971102:tid 971196] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/production/.env"] [unique_id "aqxXqOcL08BTTQixEno6xwAAO1s"]
[Thu Sep 17 15:12:08.474784 2026] [security2:error] [pid 971102:tid 971324] [client 198.20.67.197:41400] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chiext.net"] [uri "/home-styles.css"] [unique_id "aqxXqOcL08BTTQixEno6yQAAAFo"]
[Thu Sep 17 15:12:08.510506 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/staging/.env"] [unique_id "aqxXqOcL08BTTQixEno6ygAAc20"]
[Thu Sep 17 15:12:08.512150 2026] [security2:error] [pid 971102:tid 971231] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/new/.env"] [unique_id "aqxXqOcL08BTTQixEno6ywAAc34"]
[Thu Sep 17 15:12:08.512167 2026] [security2:error] [pid 971102:tid 971227] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/old/.env"] [unique_id "aqxXqOcL08BTTQixEno6zQAAc3o"]
[Thu Sep 17 15:12:08.512199 2026] [security2:error] [pid 971102:tid 971204] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/node-api/.env"] [unique_id "aqxXqOcL08BTTQixEno6zgAAc2M"]
[Thu Sep 17 15:12:08.512207 2026] [security2:error] [pid 971102:tid 971160] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/test/.env"] [unique_id "aqxXqOcL08BTTQixEno6zAAAczg"]
[Thu Sep 17 15:12:08.525939 2026] [security2:error] [pid 971102:tid 971230] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/admin-app/.env"] [unique_id "aqxXqOcL08BTTQixEno60AAAD30"]
[Thu Sep 17 15:12:08.526002 2026] [security2:error] [pid 971102:tid 971200] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/api-backend/.env"] [unique_id "aqxXqOcL08BTTQixEno6zwAAD18"]
[Thu Sep 17 15:12:08.526522 2026] [security2:error] [pid 971102:tid 971209] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/administrator/.env"] [unique_id "aqxXqOcL08BTTQixEno60QAAD2g"]
[Thu Sep 17 15:12:08.547620 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:38994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/symfony/.env"] [unique_id "aqxXqOcL08BTTQixEno60gAAADU"]
[Thu Sep 17 15:12:08.565071 2026] [security2:error] [pid 971102:tid 971344] [client 84.233.195.150:54254] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqOcL08BTTQixEno60wAAAG4"]
[Thu Sep 17 15:12:08.591647 2026] [security2:error] [pid 971102:tid 971327] [client 198.20.67.197:41414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/financing.php"] [unique_id "aqxXqOcL08BTTQixEno61AAAAF0"]
[Thu Sep 17 15:12:08.591754 2026] [security2:error] [pid 971102:tid 971327] [client 198.20.67.197:41414] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/financing.php"] [unique_id "aqxXqOcL08BTTQixEno61AAAAF0"]
[Thu Sep 17 15:12:08.598912 2026] [security2:error] [pid 971102:tid 971223] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/server/backend/.env"] [unique_id "aqxXqOcL08BTTQixEno61QAAZHY"]
[Thu Sep 17 15:12:08.598946 2026] [security2:error] [pid 971102:tid 971105] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/current/.env"] [unique_id "aqxXqOcL08BTTQixEno61wAAZAE"]
[Thu Sep 17 15:12:08.598945 2026] [security2:error] [pid 971102:tid 971225] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/server/api/.env"] [unique_id "aqxXqOcL08BTTQixEno62AAAZHg"]
[Thu Sep 17 15:12:08.598978 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/public_html/.env"] [unique_id "aqxXqOcL08BTTQixEno61gAAZHk"]
[Thu Sep 17 15:12:08.599557 2026] [security2:error] [pid 971102:tid 971221] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.docker/.env"] [unique_id "aqxXqOcL08BTTQixEno62QAAZHQ"]
[Thu Sep 17 15:12:08.652882 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:35134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/i.php"] [unique_id "aqxXqOcL08BTTQixEno62gAAAF8"]
[Thu Sep 17 15:12:08.653074 2026] [security2:error] [pid 971102:tid 971317] [client 198.20.67.197:41428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chiext.net"] [uri "/claims.php"] [unique_id "aqxXqOcL08BTTQixEno62wAAAFM"]
[Thu Sep 17 15:12:08.653152 2026] [security2:error] [pid 971102:tid 971317] [client 198.20.67.197:41428] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.chiext.net"] [uri "/claims.php"] [unique_id "aqxXqOcL08BTTQixEno62wAAAFM"]
[Thu Sep 17 15:12:08.675817 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:47788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno63AAAAB4"]
[Thu Sep 17 15:12:08.675928 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:47788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/php84compat_const.php"] [unique_id "aqxXqOcL08BTTQixEno63AAAAB4"]
[Thu Sep 17 15:12:08.702738 2026] [security2:error] [pid 971102:tid 971220] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/stripe/.env"] [unique_id "aqxXqOcL08BTTQixEno63gAAJXM"]
[Thu Sep 17 15:12:08.702791 2026] [security2:error] [pid 971102:tid 971108] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/aws/.env"] [unique_id "aqxXqOcL08BTTQixEno63wAAJQQ"]
[Thu Sep 17 15:12:08.702803 2026] [security2:error] [pid 971102:tid 971224] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxXqOcL08BTTQixEno64AAAJXc"]
[Thu Sep 17 15:12:08.702813 2026] [security2:error] [pid 971102:tid 971107] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.aws/.env"] [unique_id "aqxXqOcL08BTTQixEno63QAAJQM"]
[Thu Sep 17 15:12:08.711841 2026] [security2:error] [pid 971102:tid 971106] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/v2/.env"] [unique_id "aqxXqOcL08BTTQixEno64wAAJQI"]
[Thu Sep 17 15:12:08.711851 2026] [security2:error] [pid 971102:tid 971116] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/v1/.env"] [unique_id "aqxXqOcL08BTTQixEno65AAAJQw"]
[Thu Sep 17 15:12:08.717135 2026] [security2:error] [pid 971102:tid 971215] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/v3/.env"] [unique_id "aqxXqOcL08BTTQixEno65gAAJW4"]
[Thu Sep 17 15:12:08.717181 2026] [security2:error] [pid 971102:tid 971118] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/media/.env"] [unique_id "aqxXqOcL08BTTQixEno65QAAJQ4"]
[Thu Sep 17 15:12:08.724792 2026] [security2:error] [pid 971102:tid 971341] [client 198.20.67.197:41432] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chiext.net"] [uri "/js.js"] [unique_id "aqxXqOcL08BTTQixEno66QAAAGs"]
[Thu Sep 17 15:12:08.743096 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cache/.env"] [unique_id "aqxXqOcL08BTTQixEno67AAAABw"]
[Thu Sep 17 15:12:08.789775 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno64QAAJXU"]
[Thu Sep 17 15:12:08.793697 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno65wAAJWI"]
[Thu Sep 17 15:12:08.794229 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno64gAAJQY"]
[Thu Sep 17 15:12:08.825161 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.130.148:44852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxXqOcL08BTTQixEno69AAAABs"]
[Thu Sep 17 15:12:08.871004 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno67wAAJQU"]
[Thu Sep 17 15:12:08.871141 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno67QAAJRY"]
[Thu Sep 17 15:12:08.872405 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno68AAAJXs"]
[Thu Sep 17 15:12:08.873006 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno67gAAJRA"]
[Thu Sep 17 15:12:08.880113 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno68QAAJQ8"]
[Thu Sep 17 15:12:08.896495 2026] [security2:error] [pid 971102:tid 971281] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailer/.env"] [unique_id "aqxXqOcL08BTTQixEno6_AAAAC8"]
[Thu Sep 17 15:12:08.899487 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.git/config.bak"] [unique_id "aqxXqOcL08BTTQixEno6_gAAFQg"]
[Thu Sep 17 15:12:08.962061 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:47798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxXqOcL08BTTQixEno6_wAAAHE"]
[Thu Sep 17 15:12:08.962234 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:47798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/ristretto255.php"] [unique_id "aqxXqOcL08BTTQixEno6_wAAAHE"]
[Thu Sep 17 15:12:08.972949 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno69wAAFQc"]
[Thu Sep 17 15:12:08.973073 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-QAAFQo"]
[Thu Sep 17 15:12:08.977007 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno69gAAFRM"]
[Thu Sep 17 15:12:08.978040 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-AAAFRI"]
[Thu Sep 17 15:12:08.989482 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-gAAFRc"]
[Thu Sep 17 15:12:08.989591 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6_QAAFRE"]
[Thu Sep 17 15:12:08.992778 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno6-wAAFQk"]
[Thu Sep 17 15:12:09.051250 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mail/.env"] [unique_id "aqxXqecL08BTTQixEno7CQAAAEA"]
[Thu Sep 17 15:12:09.053075 2026] [security2:error] [pid 971102:tid 971284] [client 84.233.195.157:55858] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqecL08BTTQixEno7CgAAADI"]
[Thu Sep 17 15:12:09.062766 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno7AQAAFX8"]
[Thu Sep 17 15:12:09.062877 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno7AAAAFRg"]
[Thu Sep 17 15:12:09.063005 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqOcL08BTTQixEno7AgAAFQs"]
[Thu Sep 17 15:12:09.066805 2026] [security2:error] [pid 971102:tid 971153] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxXqecL08BTTQixEno7EQAAFTE"]
[Thu Sep 17 15:12:09.092158 2026] [security2:error] [pid 971102:tid 971274] [client 45.169.98.18:57970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXqecL08BTTQixEno7EwAAACg"]
[Thu Sep 17 15:12:09.092266 2026] [security2:error] [pid 971102:tid 971274] [client 45.169.98.18:57970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXqecL08BTTQixEno7EwAAACg"]
[Thu Sep 17 15:12:09.097715 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.097730 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.138194 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7DQAAFSE"]
[Thu Sep 17 15:12:09.138349 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7DAAAFSw"]
[Thu Sep 17 15:12:09.142174 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7DgAAFRs"]
[Thu Sep 17 15:12:09.143145 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7CwAAFRQ"]
[Thu Sep 17 15:12:09.163163 2026] [security2:error] [pid 971102:tid 971145] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/id_rsa"] [unique_id "aqxXqecL08BTTQixEno7GAAAFSk"]
[Thu Sep 17 15:12:09.163290 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxXqecL08BTTQixEno7GQAAFTI"]
[Thu Sep 17 15:12:09.168038 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7EgAAFSQ"]
[Thu Sep 17 15:12:09.205344 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/email/.env"] [unique_id "aqxXqecL08BTTQixEno7HQAAABo"]
[Thu Sep 17 15:12:09.242052 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/wordpress/.env"] [unique_id "aqxXqecL08BTTQixEno7HgAAAAA"]
[Thu Sep 17 15:12:09.269440 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxXqecL08BTTQixEno7IwAAADk"]
[Thu Sep 17 15:12:09.269614 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:47800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/sodium_compat.php"] [unique_id "aqxXqecL08BTTQixEno7IwAAADk"]
[Thu Sep 17 15:12:09.282280 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7FwAAFR4"]
[Thu Sep 17 15:12:09.282445 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7FgAAFS0"]
[Thu Sep 17 15:12:09.301556 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7GgAAFR8"]
[Thu Sep 17 15:12:09.304518 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7GwAAFSY"]
[Thu Sep 17 15:12:09.306998 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7HAAAFRw"]
[Thu Sep 17 15:12:09.346579 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7IAAAFXw"]
[Thu Sep 17 15:12:09.349737 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7IQAAFS4"]
[Thu Sep 17 15:12:09.355017 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7HwAAFR0"]
[Thu Sep 17 15:12:09.364751 2026] [security2:error] [pid 971102:tid 971246] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/smtp/.env"] [unique_id "aqxXqecL08BTTQixEno7LQAAAAw"]
[Thu Sep 17 15:12:09.368797 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7IgAAFRo"]
[Thu Sep 17 15:12:09.416787 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7JQAAFTQ"]
[Thu Sep 17 15:12:09.416907 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KQAAFUE"]
[Thu Sep 17 15:12:09.418325 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7JwAAFSg"]
[Thu Sep 17 15:12:09.418961 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KAAAFTY"]
[Thu Sep 17 15:12:09.433334 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KwAAFTM"]
[Thu Sep 17 15:12:09.437005 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7LAAAFUU"]
[Thu Sep 17 15:12:09.452890 2026] [security2:error] [pid 971102:tid 971255] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7KgAAFSo"]
[Thu Sep 17 15:12:09.474373 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/wp/.env"] [unique_id "aqxXqecL08BTTQixEno7MgAAADo"]
[Thu Sep 17 15:12:09.490591 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:35140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/pi.php"] [unique_id "aqxXqecL08BTTQixEno7NAAAAFU"]
[Thu Sep 17 15:12:09.522183 2026] [security2:error] [pid 971102:tid 971340] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailing/.env"] [unique_id "aqxXqecL08BTTQixEno7NwAAAGo"]
[Thu Sep 17 15:12:09.551648 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7MQAAAys"]
[Thu Sep 17 15:12:09.551751 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7MAAAAxU"]
[Thu Sep 17 15:12:09.563031 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:47816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxXqecL08BTTQixEno7PQAAAAs"]
[Thu Sep 17 15:12:09.563144 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:47816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/lib/stream-xchacha20.php"] [unique_id "aqxXqecL08BTTQixEno7PQAAAAs"]
[Thu Sep 17 15:12:09.573578 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7MwAAAyU"]
[Thu Sep 17 15:12:09.573892 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7NgAAAzA"]
[Thu Sep 17 15:12:09.575347 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7NQAAA0Y"]
[Thu Sep 17 15:12:09.611457 2026] [security2:error] [pid 971102:tid 971238] [client 84.233.195.154:54117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqecL08BTTQixEno7QgAAAAQ"]
[Thu Sep 17 15:12:09.629357 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7OgAAAzk"]
[Thu Sep 17 15:12:09.629444 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7OwAAA0M"]
[Thu Sep 17 15:12:09.629527 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7OQAAA0A"]
[Thu Sep 17 15:12:09.639352 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config.php"] [unique_id "aqxXqecL08BTTQixEno7RQAAA1M"]
[Thu Sep 17 15:12:09.644154 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7PAAAAz4"]
[Thu Sep 17 15:12:09.678904 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/notifications/.env"] [unique_id "aqxXqecL08BTTQixEno7RgAAAEg"]
[Thu Sep 17 15:12:09.709902 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cms/.env"] [unique_id "aqxXqecL08BTTQixEno7RwAAACw"]
[Thu Sep 17 15:12:09.825077 2026] [security2:error] [pid 971102:tid 971267] [client 5.189.145.112:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxXqecL08BTTQixEno7UgAAACE"], referer: binance.com
[Thu Sep 17 15:12:09.833806 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/notify/.env"] [unique_id "aqxXqecL08BTTQixEno7VQAAAB0"]
[Thu Sep 17 15:12:09.842519 2026] [core:error] [pid 971102:tid 971348] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.842536 2026] [core:error] [pid 971102:tid 971348] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:09.851792 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:47826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxXqecL08BTTQixEno7WQAAAGg"]
[Thu Sep 17 15:12:09.945136 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/drupal/.env"] [unique_id "aqxXqecL08BTTQixEno7XAAAAD4"]
[Thu Sep 17 15:12:09.988210 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sender/.env"] [unique_id "aqxXqecL08BTTQixEno7XgAAAGY"]
[Thu Sep 17 15:12:10.008153 2026] [authz_core:error] [pid 971102:tid 971351] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/error_log
[Thu Sep 17 15:12:10.014332 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxXqecL08BTTQixEno7YQAAAHU"]
[Thu Sep 17 15:12:10.109327 2026] [security2:error] [pid 971102:tid 971289] [client 84.233.195.151:64673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqucL08BTTQixEno7ZAAAADc"]
[Thu Sep 17 15:12:10.142908 2026] [security2:error] [pid 971102:tid 971257] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/campaign/.env"] [unique_id "aqxXqucL08BTTQixEno7ZgAAABc"]
[Thu Sep 17 15:12:10.158481 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:47826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/wp-includes/sodium_compat/"] [unique_id "aqxXqucL08BTTQixEno7aAAAAEQ"]
[Thu Sep 17 15:12:10.176376 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env"] [unique_id "aqxXqucL08BTTQixEno7agAAAHs"]
[Thu Sep 17 15:12:10.176869 2026] [security2:error] [pid 971102:tid 971315] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/joomla/.env"] [unique_id "aqxXqucL08BTTQixEno7awAAAFE"]
[Thu Sep 17 15:12:10.295972 2026] [security2:error] [pid 971102:tid 971249] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/newsletter/.env"] [unique_id "aqxXqucL08BTTQixEno7bwAAAA8"]
[Thu Sep 17 15:12:10.299625 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7PgAAA0o"]
[Thu Sep 17 15:12:10.302515 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7QAAAA0Q"]
[Thu Sep 17 15:12:10.312754 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7PwAAAz8"]
[Thu Sep 17 15:12:10.322952 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7QQAAA1E"]
[Thu Sep 17 15:12:10.328369 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7QwAAA0k"]
[Thu Sep 17 15:12:10.328868 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7RAAAAy8"]
[Thu Sep 17 15:12:10.330210 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.117.146:35144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/pinfo.php"] [unique_id "aqxXqucL08BTTQixEno7dQAAADw"]
[Thu Sep 17 15:12:10.363078 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SgAAA0c"]
[Thu Sep 17 15:12:10.363195 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SAAAAyc"]
[Thu Sep 17 15:12:10.365427 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SQAAAz0"]
[Thu Sep 17 15:12:10.379367 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7SwAAAzw"]
[Thu Sep 17 15:12:10.386260 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7TAAAA0s"]
[Thu Sep 17 15:12:10.386411 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7TwAAA04"]
[Thu Sep 17 15:12:10.388107 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7UQAAA08"]
[Thu Sep 17 15:12:10.391549 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7UAAAAzc"]
[Thu Sep 17 15:12:10.391727 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7VAAAA0w"]
[Thu Sep 17 15:12:10.403708 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/magento/.env"] [unique_id "aqxXqucL08BTTQixEno7egAAAEc"]
[Thu Sep 17 15:12:10.415035 2026] [security2:error] [pid 971102:tid 971237] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqecL08BTTQixEno7UwAAA1A"]
[Thu Sep 17 15:12:10.447677 2026] [security2:error] [pid 971102:tid 971341] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/ses/.env"] [unique_id "aqxXqucL08BTTQixEno7fgAAAGs"]
[Thu Sep 17 15:12:10.511073 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/aws.php"] [unique_id "aqxXqucL08BTTQixEno7gwAAFEI"]
[Thu Sep 17 15:12:10.511093 2026] [security2:error] [pid 971102:tid 971205] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/stripe.php"] [unique_id "aqxXqucL08BTTQixEno7hQAAFGQ"]
[Thu Sep 17 15:12:10.526403 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7cAAAACM"]
[Thu Sep 17 15:12:10.526427 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7cAAAACM"]
[Thu Sep 17 15:12:10.557257 2026] [security2:error] [pid 971102:tid 971195] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/mail.php"] [unique_id "aqxXqucL08BTTQixEno7iwAAFFo"]
[Thu Sep 17 15:12:10.557264 2026] [security2:error] [pid 971102:tid 971139] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/config.inc.php"] [unique_id "aqxXqucL08BTTQixEno7igAAFCM"]
[Thu Sep 17 15:12:10.559167 2026] [security2:error] [pid 971102:tid 971163] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/config/nexmo.php"] [unique_id "aqxXqucL08BTTQixEno7jQAAFDs"]
[Thu Sep 17 15:12:10.578754 2026] [security2:error] [pid 971102:tid 971211] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/wp-config.php"] [unique_id "aqxXqucL08BTTQixEno7kQAAFGo"]
[Thu Sep 17 15:12:10.582408 2026] [security2:error] [pid 971102:tid 971193] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sqlerudition.com"] [uri "/wp-config.php.bak"] [unique_id "aqxXqucL08BTTQixEno7kgAAFFg"]
[Thu Sep 17 15:12:10.582408 2026] [security2:error] [pid 971102:tid 971194] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sqlerudition.com"] [uri "/wp-config.php.old"] [unique_id "aqxXqucL08BTTQixEno7kwAAFFk"]
[Thu Sep 17 15:12:10.586622 2026] [security2:error] [pid 971102:tid 971235] [client 84.233.195.155:54258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXqucL08BTTQixEno7lAAAAAE"]
[Thu Sep 17 15:12:10.599297 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7gQAAFE0"]
[Thu Sep 17 15:12:10.599480 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7ggAAFFU"]
[Thu Sep 17 15:12:10.599557 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7hAAAFF4"]
[Thu Sep 17 15:12:10.600529 2026] [security2:error] [pid 971102:tid 971360] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sendgrid/.env"] [unique_id "aqxXqucL08BTTQixEno7lgAAAH4"]
[Thu Sep 17 15:12:10.600703 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxXqucL08BTTQixEno7lQAAAC8"]
[Thu Sep 17 15:12:10.601729 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sqlerudition.com"] [uri "/wp-config.php.new"] [unique_id "aqxXqucL08BTTQixEno7lwAAFFw"]
[Thu Sep 17 15:12:10.623726 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxXqucL08BTTQixEno7mAAAAHE"]
[Thu Sep 17 15:12:10.632008 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/shopify/.env"] [unique_id "aqxXqucL08BTTQixEno7mQAAAF4"]
[Thu Sep 17 15:12:10.645481 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7iQAAFFQ"]
[Thu Sep 17 15:12:10.645622 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7jAAAFGU"]
[Thu Sep 17 15:12:10.661380 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7kAAAFFI"]
[Thu Sep 17 15:12:10.669695 2026] [security2:error] [pid 971102:tid 971254] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7jwAAFGk"]
[Thu Sep 17 15:12:10.678240 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxXqucL08BTTQixEno7mwAAADI"]
[Thu Sep 17 15:12:10.678333 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:47826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Compat.php"] [unique_id "aqxXqucL08BTTQixEno7mwAAADI"]
[Thu Sep 17 15:12:10.688062 2026] [core:error] [pid 971102:tid 971298] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:10.688077 2026] [core:error] [pid 971102:tid 971298] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:10.694584 2026] [security2:error] [pid 971102:tid 971219] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxXqucL08BTTQixEno7nQAAKHI"]
[Thu Sep 17 15:12:10.706705 2026] [security2:error] [pid 971102:tid 971320] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxXqucL08BTTQixEno7nwAAAFY"]
[Thu Sep 17 15:12:10.752553 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxXqucL08BTTQixEno7owAAKGs"]
[Thu Sep 17 15:12:10.763375 2026] [security2:error] [pid 971102:tid 971333] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/sparkpost/.env"] [unique_id "aqxXqucL08BTTQixEno7pAAAAGM"]
[Thu Sep 17 15:12:10.783331 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7ngAAKGw"]
[Thu Sep 17 15:12:10.786751 2026] [security2:error] [pid 971102:tid 971192] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxXqucL08BTTQixEno7qgAAKFc"]
[Thu Sep 17 15:12:10.859727 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/prestashop/.env"] [unique_id "aqxXqucL08BTTQixEno7tAAAADk"]
[Thu Sep 17 15:12:10.916412 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/postmark/.env"] [unique_id "aqxXqucL08BTTQixEno7ugAAAFI"]
[Thu Sep 17 15:12:10.978842 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:51372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXqucL08BTTQixEno7wQAAAHA"]
[Thu Sep 17 15:12:11.071354 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailgun/.env"] [unique_id "aqxXq-cL08BTTQixEno7xQAAAFs"]
[Thu Sep 17 15:12:11.081894 2026] [security2:error] [pid 971102:tid 971255] [client 84.233.195.160:63291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sweetlifelowermills.com"] [uri "/"] [unique_id "aqxXq-cL08BTTQixEno7xgAAABU"]
[Thu Sep 17 15:12:11.085469 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/codeigniter/.env"] [unique_id "aqxXq-cL08BTTQixEno7xwAAAGc"]
[Thu Sep 17 15:12:11.148031 2026] [authz_core:error] [pid 971102:tid 971307] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/error_log
[Thu Sep 17 15:12:11.164854 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXq-cL08BTTQixEno7zQAAAEk"]
[Thu Sep 17 15:12:11.229189 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mandrill/.env"] [unique_id "aqxXq-cL08BTTQixEno70AAAACQ"]
[Thu Sep 17 15:12:11.309994 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:51372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/wp-includes/sodium_compat/namespaced/"] [unique_id "aqxXq-cL08BTTQixEno70gAAADc"]
[Thu Sep 17 15:12:11.319127 2026] [security2:error] [pid 971102:tid 971302] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cakephp/.env"] [unique_id "aqxXq-cL08BTTQixEno71AAAAEQ"]
[Thu Sep 17 15:12:11.330905 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7ogAAKGc"]
[Thu Sep 17 15:12:11.339946 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7oQAAKFY"]
[Thu Sep 17 15:12:11.352314 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7pwAAKHA"]
[Thu Sep 17 15:12:11.357077 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7pQAAKF0"]
[Thu Sep 17 15:12:11.365246 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7vAAAKH0"]
[Thu Sep 17 15:12:11.365401 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7sQAAKG0"]
[Thu Sep 17 15:12:11.368222 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7uQAAKDg"]
[Thu Sep 17 15:12:11.370513 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7sgAAKHo"]
[Thu Sep 17 15:12:11.372645 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7wAAAKGg"]
[Thu Sep 17 15:12:11.373793 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7pgAAKHE"]
[Thu Sep 17 15:12:11.374082 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7qAAAKGY"]
[Thu Sep 17 15:12:11.380281 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7tgAAKGM"]
[Thu Sep 17 15:12:11.386379 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7qQAAKAA"]
[Thu Sep 17 15:12:11.387142 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7qwAAKG8"]
[Thu Sep 17 15:12:11.389110 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mailjet/.env"] [unique_id "aqxXq-cL08BTTQixEno71wAAADs"]
[Thu Sep 17 15:12:11.389416 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7sAAAKH4"]
[Thu Sep 17 15:12:11.406801 2026] [security2:error] [pid 971102:tid 971274] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXqucL08BTTQixEno7vgAAKF8"]
[Thu Sep 17 15:12:11.470037 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxXq-cL08BTTQixEno74QAAAAM"]
[Thu Sep 17 15:12:11.495793 2026] [security2:error] [pid 971102:tid 971352] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.env~"] [unique_id "aqxXq-cL08BTTQixEno74wAAAHY"]
[Thu Sep 17 15:12:11.551747 2026] [core:error] [pid 971102:tid 971329] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:11.551773 2026] [core:error] [pid 971102:tid 971329] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:11.551808 2026] [security2:error] [pid 971102:tid 971341] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/brevo/.env"] [unique_id "aqxXq-cL08BTTQixEno77gAAAGs"]
[Thu Sep 17 15:12:11.551850 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/zend/.env"] [unique_id "aqxXq-cL08BTTQixEno76gAAAAk"]
[Thu Sep 17 15:12:11.680123 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno73AAAAG8"]
[Thu Sep 17 15:12:11.680144 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno73AAAAG8"]
[Thu Sep 17 15:12:11.714123 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/transactional/.env"] [unique_id "aqxXq-cL08BTTQixEno7-gAAAGI"]
[Thu Sep 17 15:12:11.783634 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/yii/.env"] [unique_id "aqxXq-cL08BTTQixEno7_QAAAEA"]
[Thu Sep 17 15:12:11.835487 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxXq-cL08BTTQixEno7_wAAAFw"]
[Thu Sep 17 15:12:11.835585 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/BLAKE2b.php"] [unique_id "aqxXq-cL08BTTQixEno7_wAAAFw"]
[Thu Sep 17 15:12:11.867876 2026] [security2:error] [pid 971102:tid 971259] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/bulk/.env"] [unique_id "aqxXq-cL08BTTQixEno8AQAAABk"]
[Thu Sep 17 15:12:11.910388 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/test.php"] [unique_id "aqxXq-cL08BTTQixEno8BAAAACY"]
[Thu Sep 17 15:12:11.990708 2026] [security2:error] [pid 971102:tid 971261] [client 156.192.234.52:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXq-cL08BTTQixEno8CAAAABs"]
[Thu Sep 17 15:12:11.990796 2026] [security2:error] [pid 971102:tid 971261] [client 156.192.234.52:65436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXq-cL08BTTQixEno8CAAAABs"]
[Thu Sep 17 15:12:12.009064 2026] [security2:error] [pid 971102:tid 971250] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxXrOcL08BTTQixEno8CQAAABA"]
[Thu Sep 17 15:12:12.010219 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/laravel5/.env"] [unique_id "aqxXrOcL08BTTQixEno8CgAAAAI"]
[Thu Sep 17 15:12:12.025464 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/aws/.env"] [unique_id "aqxXrOcL08BTTQixEno8CwAAAF0"]
[Thu Sep 17 15:12:12.032371 2026] [security2:error] [pid 971102:tid 971258] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxXrOcL08BTTQixEno8DAAAABg"]
[Thu Sep 17 15:12:12.055362 2026] [security2:error] [pid 971102:tid 971313] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxXrOcL08BTTQixEno8DQAAAE8"]
[Thu Sep 17 15:12:12.080303 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxXrOcL08BTTQixEno8EAAAAEs"]
[Thu Sep 17 15:12:12.105117 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxXrOcL08BTTQixEno8EQAAAFI"]
[Thu Sep 17 15:12:12.120529 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:51386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxXrOcL08BTTQixEno8EgAAADo"]
[Thu Sep 17 15:12:12.120593 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:51386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20.php"] [unique_id "aqxXrOcL08BTTQixEno8EgAAADo"]
[Thu Sep 17 15:12:12.127552 2026] [security2:error] [pid 971102:tid 971251] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxXrOcL08BTTQixEno8EwAAABE"]
[Thu Sep 17 15:12:12.176853 2026] [security2:error] [pid 971102:tid 971346] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/azure/.env"] [unique_id "aqxXrOcL08BTTQixEno8FgAAAHA"]
[Thu Sep 17 15:12:12.219499 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxXrOcL08BTTQixEno8GQAAAEg"]
[Thu Sep 17 15:12:12.236793 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/v1/.env"] [unique_id "aqxXrOcL08BTTQixEno8GgAAACc"]
[Thu Sep 17 15:12:12.237989 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxXrOcL08BTTQixEno8GwAAABw"]
[Thu Sep 17 15:12:12.256026 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxXrOcL08BTTQixEno8HAAAAHo"]
[Thu Sep 17 15:12:12.275221 2026] [security2:error] [pid 971102:tid 971348] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxXrOcL08BTTQixEno8HwAAAHI"]
[Thu Sep 17 15:12:12.293734 2026] [security2:error] [pid 971102:tid 971325] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxXrOcL08BTTQixEno8IQAAAFs"]
[Thu Sep 17 15:12:12.296794 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno76wAANgM"]
[Thu Sep 17 15:12:12.298527 2026] [security2:error] [pid 971102:tid 971221] [remote 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno75gAANnQ"]
[Thu Sep 17 15:12:12.300331 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno77AAANgw"]
[Thu Sep 17 15:12:12.308532 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno77QAANnc"]
[Thu Sep 17 15:12:12.312218 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno76AAANgQ"]
[Thu Sep 17 15:12:12.313111 2026] [security2:error] [pid 971102:tid 971337] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxXrOcL08BTTQixEno8JgAAAGc"]
[Thu Sep 17 15:12:12.314651 2026] [core:error] [pid 971102:tid 971285] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:12.314676 2026] [core:error] [pid 971102:tid 971285] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:12.322481 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78wAANmI"]
[Thu Sep 17 15:12:12.329043 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/gcp/.env"] [unique_id "aqxXrOcL08BTTQixEno8KgAAAEY"]
[Thu Sep 17 15:12:12.331723 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno75wAANnM"]
[Thu Sep 17 15:12:12.332524 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78QAANnU"]
[Thu Sep 17 15:12:12.333668 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno77wAANm4"]
[Thu Sep 17 15:12:12.337907 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78AAANg4"]
[Thu Sep 17 15:12:12.340370 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79QAANhY"]
[Thu Sep 17 15:12:12.340484 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79AAANgY"]
[Thu Sep 17 15:12:12.341444 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxXrOcL08BTTQixEno8KwAAAHU"]
[Thu Sep 17 15:12:12.343539 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno75QAANnk"]
[Thu Sep 17 15:12:12.349596 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79gAANgU"]
[Thu Sep 17 15:12:12.362472 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno79wAANns"]
[Thu Sep 17 15:12:12.363902 2026] [security2:error] [pid 971102:tid 971246] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxXrOcL08BTTQixEno8LQAAAAw"]
[Thu Sep 17 15:12:12.365033 2026] [security2:error] [pid 971102:tid 971288] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXq-cL08BTTQixEno78gAANgI"]
[Thu Sep 17 15:12:12.394937 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxXrOcL08BTTQixEno8LgAAAGY"]
[Thu Sep 17 15:12:12.408074 2026] [security2:error] [pid 971102:tid 971307] [client 143.244.57.120:51392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxXrOcL08BTTQixEno8LwAAAEk"]
[Thu Sep 17 15:12:12.418330 2026] [security2:error] [pid 971102:tid 971335] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxXrOcL08BTTQixEno8MAAAAGU"]
[Thu Sep 17 15:12:12.431504 2026] [security2:error] [pid 971102:tid 971253] [client 185.55.149.49:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8MQAAABM"]
[Thu Sep 17 15:12:12.431583 2026] [security2:error] [pid 971102:tid 971253] [client 185.55.149.49:65281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8MQAAABM"]
[Thu Sep 17 15:12:12.441960 2026] [security2:error] [pid 971102:tid 971266] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxXrOcL08BTTQixEno8MgAAACA"]
[Thu Sep 17 15:12:12.470073 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/v2/.env"] [unique_id "aqxXrOcL08BTTQixEno8MwAAAH8"]
[Thu Sep 17 15:12:12.471179 2026] [security2:error] [pid 971102:tid 971289] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxXrOcL08BTTQixEno8NAAAADc"]
[Thu Sep 17 15:12:12.486011 2026] [security2:error] [pid 971102:tid 971302] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cloud/.env"] [unique_id "aqxXrOcL08BTTQixEno8OAAAAEQ"]
[Thu Sep 17 15:12:12.491522 2026] [security2:error] [pid 971102:tid 971315] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxXrOcL08BTTQixEno8OwAAAFE"]
[Thu Sep 17 15:12:12.525066 2026] [security2:error] [pid 971102:tid 971274] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxXrOcL08BTTQixEno8QgAAACg"]
[Thu Sep 17 15:12:12.550439 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxXrOcL08BTTQixEno8QwAAAFA"]
[Thu Sep 17 15:12:12.567644 2026] [security2:error] [pid 971102:tid 971123] [remote 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8NwAAexM"]
[Thu Sep 17 15:12:12.568523 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8NgAAewo"]
[Thu Sep 17 15:12:12.570103 2026] [security2:error] [pid 971102:tid 971352] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxXrOcL08BTTQixEno8RQAAAHY"]
[Thu Sep 17 15:12:12.570513 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8NQAAewc"]
[Thu Sep 17 15:12:12.576444 2026] [authz_core:error] [pid 971102:tid 971305] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/ChaCha20/error_log
[Thu Sep 17 15:12:12.577907 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "aqxXrOcL08BTTQixEno8RAAAAEc"]
[Thu Sep 17 15:12:12.588400 2026] [security2:error] [pid 971102:tid 971349] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxXrOcL08BTTQixEno8RgAAAHM"]
[Thu Sep 17 15:12:12.589016 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8OQAAexI"]
[Thu Sep 17 15:12:12.589388 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8OgAAexc"]
[Thu Sep 17 15:12:12.594344 2026] [security2:error] [pid 971102:tid 971319] [client 208.109.3.10:37738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8FwAAAFU"]
[Thu Sep 17 15:12:12.602325 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8PQAAexE"]
[Thu Sep 17 15:12:12.605042 2026] [security2:error] [pid 971102:tid 971317] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxXrOcL08BTTQixEno8SAAAAFM"]
[Thu Sep 17 15:12:12.607371 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8PgAAewk"]
[Thu Sep 17 15:12:12.607788 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8PwAAeyA"]
[Thu Sep 17 15:12:12.610537 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8QQAAexg"]
[Thu Sep 17 15:12:12.610866 2026] [security2:error] [pid 971102:tid 971357] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8QAAAexk"]
[Thu Sep 17 15:12:12.626014 2026] [security2:error] [pid 971102:tid 971341] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxXrOcL08BTTQixEno8SQAAAGs"]
[Thu Sep 17 15:12:12.636026 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/infrastructure/.env"] [unique_id "aqxXrOcL08BTTQixEno8SgAAADA"]
[Thu Sep 17 15:12:12.647339 2026] [security2:error] [pid 971102:tid 971275] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxXrOcL08BTTQixEno8SwAAACk"]
[Thu Sep 17 15:12:12.662238 2026] [security2:error] [pid 971102:tid 971360] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxXrOcL08BTTQixEno8VQAAAH4"]
[Thu Sep 17 15:12:12.681051 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxXrOcL08BTTQixEno8VgAAAC8"]
[Thu Sep 17 15:12:12.698017 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/v3/.env"] [unique_id "aqxXrOcL08BTTQixEno8VwAAAG8"]
[Thu Sep 17 15:12:12.702719 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxXrOcL08BTTQixEno8WQAAAF4"]
[Thu Sep 17 15:12:12.718668 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxXrOcL08BTTQixEno8XAAAAHE"]
[Thu Sep 17 15:12:12.725903 2026] [security2:error] [pid 971102:tid 971270] [client 115.244.164.14:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8XQAAACQ"]
[Thu Sep 17 15:12:12.725998 2026] [security2:error] [pid 971102:tid 971270] [client 115.244.164.14:53448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrOcL08BTTQixEno8XQAAACQ"]
[Thu Sep 17 15:12:12.734920 2026] [security2:error] [pid 971102:tid 971294] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxXrOcL08BTTQixEno8XgAAADw"]
[Thu Sep 17 15:12:12.741671 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:51392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXrOcL08BTTQixEno8XwAAADI"]
[Thu Sep 17 15:12:12.755317 2026] [security2:error] [pid 971102:tid 971256] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxXrOcL08BTTQixEno8YQAAABY"]
[Thu Sep 17 15:12:12.773719 2026] [security2:error] [pid 971102:tid 971290] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxXrOcL08BTTQixEno8ZAAAADg"]
[Thu Sep 17 15:12:12.785702 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/docker/.env"] [unique_id "aqxXrOcL08BTTQixEno8ZwAAADQ"]
[Thu Sep 17 15:12:12.795957 2026] [security2:error] [pid 971102:tid 971298] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxXrOcL08BTTQixEno8aQAAAEA"]
[Thu Sep 17 15:12:12.796567 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/phpinfo.php"] [unique_id "aqxXrOcL08BTTQixEno8awAAKiY"]
[Thu Sep 17 15:12:12.799058 2026] [security2:error] [pid 971102:tid 971229] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/info.php"] [unique_id "aqxXrOcL08BTTQixEno8bQAAKnw"]
[Thu Sep 17 15:12:12.812061 2026] [security2:error] [pid 971102:tid 971239] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxXrOcL08BTTQixEno8bgAAAAU"]
[Thu Sep 17 15:12:12.828615 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxXrOcL08BTTQixEno8cAAAAFw"]
[Thu Sep 17 15:12:12.844450 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxXrOcL08BTTQixEno8cwAAACY"]
[Thu Sep 17 15:12:12.859802 2026] [security2:error] [pid 971102:tid 971353] [client 8.228.10.213:33680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxXrOcL08BTTQixEno8dAAAAHc"]
[Thu Sep 17 15:12:12.882065 2026] [security2:error] [pid 971102:tid 971265] [client 197.200.250.116:42728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8WAAAAB8"]
[Thu Sep 17 15:12:12.925177 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/v1/.env"] [unique_id "aqxXrOcL08BTTQixEno8dgAAABA"]
[Thu Sep 17 15:12:12.928513 2026] [security2:error] [pid 971102:tid 971261] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxXrOcL08BTTQixEno8dwAAABs"]
[Thu Sep 17 15:12:12.935270 2026] [security2:error] [pid 971102:tid 971258] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/k8s/.env"] [unique_id "aqxXrOcL08BTTQixEno8ewAAABg"]
[Thu Sep 17 15:12:12.951193 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxXrOcL08BTTQixEno8fgAAAEs"]
[Thu Sep 17 15:12:12.975896 2026] [security2:error] [pid 971102:tid 971130] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/infos.php"] [unique_id "aqxXrOcL08BTTQixEno8gQAAKho"]
[Thu Sep 17 15:12:12.978096 2026] [security2:error] [pid 971102:tid 971334] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxXrOcL08BTTQixEno8ggAAAGQ"]
[Thu Sep 17 15:12:12.978977 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/php_info.php"] [unique_id "aqxXrOcL08BTTQixEno8gwAAKkE"]
[Thu Sep 17 15:12:13.001165 2026] [security2:error] [pid 971102:tid 971292] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxXrOcL08BTTQixEno8hAAAADo"]
[Thu Sep 17 15:12:13.025423 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxXrecL08BTTQixEno8hwAAAHA"]
[Thu Sep 17 15:12:13.050274 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxXrecL08BTTQixEno8iAAAAGk"]
[Thu Sep 17 15:12:13.078515 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxXrecL08BTTQixEno8iQAAAG0"]
[Thu Sep 17 15:12:13.091242 2026] [security2:error] [pid 971102:tid 971306] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/kubernetes/.env"] [unique_id "aqxXrecL08BTTQixEno8igAAAEg"]
[Thu Sep 17 15:12:13.101432 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxXrecL08BTTQixEno8jAAAAAQ"]
[Thu Sep 17 15:12:13.103887 2026] [core:error] [pid 971102:tid 971278] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:13.103908 2026] [core:error] [pid 971102:tid 971278] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:13.114294 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8dQAAAGM"]
[Thu Sep 17 15:12:13.114316 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8dQAAAGM"]
[Thu Sep 17 15:12:13.125118 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxXrecL08BTTQixEno8jQAAABw"]
[Thu Sep 17 15:12:13.151952 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/v2/.env"] [unique_id "aqxXrecL08BTTQixEno8kAAAAD0"]
[Thu Sep 17 15:12:13.151965 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxXrecL08BTTQixEno8jwAAAHo"]
[Thu Sep 17 15:12:13.154836 2026] [security2:error] [pid 971102:tid 971144] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/php.php"] [unique_id "aqxXrecL08BTTQixEno8kQAAKig"]
[Thu Sep 17 15:12:13.157818 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/php-info.php"] [unique_id "aqxXrecL08BTTQixEno8kgAAKjY"]
[Thu Sep 17 15:12:13.174062 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxXrecL08BTTQixEno8kwAAAEI"]
[Thu Sep 17 15:12:13.199572 2026] [security2:error] [pid 971102:tid 971267] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxXrecL08BTTQixEno8lAAAACE"]
[Thu Sep 17 15:12:13.221911 2026] [security2:error] [pid 971102:tid 971279] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxXrecL08BTTQixEno8lwAAAC0"]
[Thu Sep 17 15:12:13.223412 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.117.146:35160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8TgAAAAc"]
[Thu Sep 17 15:12:13.243623 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxXrecL08BTTQixEno8mAAAADM"]
[Thu Sep 17 15:12:13.251036 2026] [security2:error] [pid 971102:tid 971338] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/terraform/.env"] [unique_id "aqxXrecL08BTTQixEno8mQAAAGg"]
[Thu Sep 17 15:12:13.257114 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxXrecL08BTTQixEno8mgAAAE4"]
[Thu Sep 17 15:12:13.257247 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:51392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/Ctx.php"] [unique_id "aqxXrecL08BTTQixEno8mgAAAE4"]
[Thu Sep 17 15:12:13.273253 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxXrecL08BTTQixEno8mwAAABI"]
[Thu Sep 17 15:12:13.297251 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxXrecL08BTTQixEno8nAAAAEY"]
[Thu Sep 17 15:12:13.310048 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UQAAKjE"]
[Thu Sep 17 15:12:13.310169 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UgAAKiE"]
[Thu Sep 17 15:12:13.310219 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8VAAAKiw"]
[Thu Sep 17 15:12:13.310332 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UwAAKn8"]
[Thu Sep 17 15:12:13.310384 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8TwAAKgs"]
[Thu Sep 17 15:12:13.310573 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8UAAAKg0"]
[Thu Sep 17 15:12:13.319945 2026] [security2:error] [pid 971102:tid 971342] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxXrecL08BTTQixEno8ngAAAGw"]
[Thu Sep 17 15:12:13.334936 2026] [security2:error] [pid 971102:tid 971173] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/infophp.php"] [unique_id "aqxXrecL08BTTQixEno8oAAAKkU"]
[Thu Sep 17 15:12:13.342976 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxXrecL08BTTQixEno8ogAAAB0"]
[Thu Sep 17 15:12:13.356823 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8aAAAKi0"]
[Thu Sep 17 15:12:13.356952 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8agAAKh8"]
[Thu Sep 17 15:12:13.357940 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8bAAAKhw"]
[Thu Sep 17 15:12:13.359007 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8YgAAKik"]
[Thu Sep 17 15:12:13.359261 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8YAAAKhQ"]
[Thu Sep 17 15:12:13.360555 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8ZQAAKh4"]
[Thu Sep 17 15:12:13.366475 2026] [security2:error] [pid 971102:tid 971291] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxXrecL08BTTQixEno8owAAADk"]
[Thu Sep 17 15:12:13.372374 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8ZgAAKiQ"]
[Thu Sep 17 15:12:13.372473 2026] [security2:error] [pid 971102:tid 971296] [client 74.7.230.60:49382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "4p4x.com"] [uri "/robots.txt"] [unique_id "aqxXrecL08BTTQixEno8pAAAAD4"]
[Thu Sep 17 15:12:13.373564 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8YwAAKjI"]
[Thu Sep 17 15:12:13.379174 2026] [security2:error] [pid 971102:tid 971288] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/rest/.env"] [unique_id "aqxXrecL08BTTQixEno8pQAAADY"]
[Thu Sep 17 15:12:13.388825 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxXrecL08BTTQixEno8pgAAAGY"]
[Thu Sep 17 15:12:13.414910 2026] [security2:error] [pid 971102:tid 971253] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxXrecL08BTTQixEno8pwAAABM"]
[Thu Sep 17 15:12:13.414963 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/ansible/.env"] [unique_id "aqxXrecL08BTTQixEno8qAAAACA"]
[Thu Sep 17 15:12:13.429362 2026] [security2:error] [pid 971102:tid 971276] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8oQAAKio"]
[Thu Sep 17 15:12:13.438264 2026] [security2:error] [pid 971102:tid 971361] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxXrecL08BTTQixEno8qwAAAH8"]
[Thu Sep 17 15:12:13.449522 2026] [security2:error] [pid 971102:tid 971316] [client 47.79.200.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxXrOcL08BTTQixEno8gAAAAFI"], referer: https://www.google.com/
[Thu Sep 17 15:12:13.461411 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxXrecL08BTTQixEno8rAAAAHw"]
[Thu Sep 17 15:12:13.485220 2026] [security2:error] [pid 971102:tid 971257] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxXrecL08BTTQixEno8rwAAABc"]
[Thu Sep 17 15:12:13.489561 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8sAAAPxU"]
[Thu Sep 17 15:12:13.489581 2026] [security2:error] [pid 971102:tid 971141] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8sgAAPyU"]
[Thu Sep 17 15:12:13.489590 2026] [security2:error] [pid 971102:tid 971147] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8sQAAPys"]
[Thu Sep 17 15:12:13.489878 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/api/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8swAAPxU"]
[Thu Sep 17 15:12:13.489951 2026] [security2:error] [pid 971102:tid 971152] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXrecL08BTTQixEno8tAAAPzA"]
[Thu Sep 17 15:12:13.510528 2026] [security2:error] [pid 971102:tid 971274] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxXrecL08BTTQixEno8tgAAACg"]
[Thu Sep 17 15:12:13.532866 2026] [security2:error] [pid 971102:tid 971352] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxXrecL08BTTQixEno8uwAAAHY"]
[Thu Sep 17 15:12:13.547059 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:51394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXrecL08BTTQixEno8wgAAAHM"]
[Thu Sep 17 15:12:13.547219 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:51394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXrecL08BTTQixEno8wgAAAHM"]
[Thu Sep 17 15:12:13.554218 2026] [security2:error] [pid 971102:tid 971172] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/database.sql"] [unique_id "aqxXrecL08BTTQixEno8wwAAGkQ"]
[Thu Sep 17 15:12:13.556426 2026] [security2:error] [pid 971102:tid 971249] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxXrecL08BTTQixEno8xQAAAA8"]
[Thu Sep 17 15:12:13.570217 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/.git/.env"] [unique_id "aqxXrecL08BTTQixEno8xgAAAFU"]
[Thu Sep 17 15:12:13.579211 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxXrecL08BTTQixEno8xwAAAHs"]
[Thu Sep 17 15:12:13.593823 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8tQAAGjk"]
[Thu Sep 17 15:12:13.610964 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/graphql/.env"] [unique_id "aqxXrecL08BTTQixEno8yQAAAF8"]
[Thu Sep 17 15:12:13.611312 2026] [security2:error] [pid 971102:tid 971282] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxXrecL08BTTQixEno8ygAAADA"]
[Thu Sep 17 15:12:13.627576 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vgAAGj4"]
[Thu Sep 17 15:12:13.627715 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vAAAGkA"]
[Thu Sep 17 15:12:13.627814 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8wQAAGko"]
[Thu Sep 17 15:12:13.627855 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vwAAGkg"]
[Thu Sep 17 15:12:13.630462 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8vQAAGlM"]
[Thu Sep 17 15:12:13.630590 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8wAAAGiI"]
[Thu Sep 17 15:12:13.638308 2026] [security2:error] [pid 971102:tid 971275] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxXrecL08BTTQixEno8zQAAACk"]
[Thu Sep 17 15:12:13.649942 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8xAAAGj8"]
[Thu Sep 17 15:12:13.673849 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxXrecL08BTTQixEno80wAAAAE"]
[Thu Sep 17 15:12:13.696597 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8ywAAGlE"]
[Thu Sep 17 15:12:13.702325 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxXrecL08BTTQixEno81AAAAF4"]
[Thu Sep 17 15:12:13.729888 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxXrecL08BTTQixEno81gAAACM"]
[Thu Sep 17 15:12:13.731579 2026] [security2:error] [pid 971102:tid 971254] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/ci/.env"] [unique_id "aqxXrecL08BTTQixEno81wAAABQ"]
[Thu Sep 17 15:12:13.750440 2026] [security2:error] [pid 971102:tid 971290] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxXrecL08BTTQixEno82QAAADg"]
[Thu Sep 17 15:12:13.772291 2026] [security2:error] [pid 971102:tid 971286] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxXrecL08BTTQixEno82gAAADQ"]
[Thu Sep 17 15:12:13.793934 2026] [security2:error] [pid 971102:tid 971298] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxXrecL08BTTQixEno83AAAAEA"]
[Thu Sep 17 15:12:13.807124 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/wp-config.backup.php"] [unique_id "aqxXrecL08BTTQixEno83wAAGjc"]
[Thu Sep 17 15:12:13.809369 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.130.148:44884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "aqxXrecL08BTTQixEno84QAAAAk"]
[Thu Sep 17 15:12:13.819097 2026] [security2:error] [pid 971102:tid 971239] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxXrecL08BTTQixEno85QAAAAU"]
[Thu Sep 17 15:12:13.843747 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxXrecL08BTTQixEno86AAAAFw"]
[Thu Sep 17 15:12:13.843829 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:51398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519.php"] [unique_id "aqxXrecL08BTTQixEno86AAAAFw"]
[Thu Sep 17 15:12:13.844207 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxXrecL08BTTQixEno85wAAACY"]
[Thu Sep 17 15:12:13.844927 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/gateway/.env"] [unique_id "aqxXrecL08BTTQixEno86QAAAHc"]
[Thu Sep 17 15:12:13.866411 2026] [security2:error] [pid 971102:tid 971261] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxXrecL08BTTQixEno87AAAABs"]
[Thu Sep 17 15:12:13.887373 2026] [security2:error] [pid 971102:tid 971258] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxXrecL08BTTQixEno87gAAABg"]
[Thu Sep 17 15:12:13.888200 2026] [security2:error] [pid 971102:tid 971309] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/cd/.env"] [unique_id "aqxXrecL08BTTQixEno87wAAAEs"]
[Thu Sep 17 15:12:13.908626 2026] [security2:error] [pid 971102:tid 971264] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxXrecL08BTTQixEno88AAAAB4"]
[Thu Sep 17 15:12:13.930988 2026] [security2:error] [pid 971102:tid 971248] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxXrecL08BTTQixEno89AAAAA4"]
[Thu Sep 17 15:12:13.952844 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxXrecL08BTTQixEno89QAAAHA"]
[Thu Sep 17 15:12:13.974305 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxXrecL08BTTQixEno89wAAAGk"]
[Thu Sep 17 15:12:13.997391 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxXrecL08BTTQixEno8-wAAAEo"]
[Thu Sep 17 15:12:14.018643 2026] [security2:error] [pid 971102:tid 971320] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxXrucL08BTTQixEno8_AAAAFY"]
[Thu Sep 17 15:12:14.041929 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxXrucL08BTTQixEno8_QAAAEg"]
[Thu Sep 17 15:12:14.043145 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.130.148:44884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "aqxXrucL08BTTQixEno8_gAAAH0"]
[Thu Sep 17 15:12:14.048407 2026] [security2:error] [pid 971102:tid 971238] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/jenkins/.env"] [unique_id "aqxXrucL08BTTQixEno8_wAAAAQ"]
[Thu Sep 17 15:12:14.067113 2026] [security2:error] [pid 971102:tid 971278] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxXrucL08BTTQixEno9AAAAACw"]
[Thu Sep 17 15:12:14.071984 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/microservice/.env"] [unique_id "aqxXrucL08BTTQixEno9AQAAAAs"]
[Thu Sep 17 15:12:14.076786 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.117.146:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/p.php"] [unique_id "aqxXrucL08BTTQixEno9AwAAAGI"]
[Thu Sep 17 15:12:14.089254 2026] [security2:error] [pid 971102:tid 971311] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxXrucL08BTTQixEno9BAAAAE0"]
[Thu Sep 17 15:12:14.111946 2026] [security2:error] [pid 971102:tid 971273] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxXrucL08BTTQixEno9BQAAACc"]
[Thu Sep 17 15:12:14.125575 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxXrucL08BTTQixEno9BgAAAGM"]
[Thu Sep 17 15:12:14.146068 2026] [security2:error] [pid 971102:tid 971322] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxXrucL08BTTQixEno9BwAAAFg"]
[Thu Sep 17 15:12:14.166807 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxXrucL08BTTQixEno9CgAAAHo"]
[Thu Sep 17 15:12:14.190972 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxXrucL08BTTQixEno9DAAAAEI"]
[Thu Sep 17 15:12:14.206271 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/gitlab/.env"] [unique_id "aqxXrucL08BTTQixEno9DQAAAAg"]
[Thu Sep 17 15:12:14.215739 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxXrucL08BTTQixEno9DwAAAFk"]
[Thu Sep 17 15:12:14.238319 2026] [security2:error] [pid 971102:tid 971267] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxXrucL08BTTQixEno9EAAAACE"]
[Thu Sep 17 15:12:14.261172 2026] [security2:error] [pid 971102:tid 971348] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxXrucL08BTTQixEno9EQAAAHI"]
[Thu Sep 17 15:12:14.288167 2026] [security2:error] [pid 971102:tid 971325] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxXrucL08BTTQixEno9FQAAAFs"]
[Thu Sep 17 15:12:14.293530 2026] [authz_core:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/error_log
[Thu Sep 17 15:12:14.298844 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/service/.env"] [unique_id "aqxXrucL08BTTQixEno9FgAAABU"]
[Thu Sep 17 15:12:14.304793 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxXrucL08BTTQixEno9EgAAADU"]
[Thu Sep 17 15:12:14.313151 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxXrucL08BTTQixEno9FwAAADM"]
[Thu Sep 17 15:12:14.322158 2026] [security2:error] [pid 971102:tid 971283] [client 209.59.91.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9CwAAADE"], referer: http://m.facebook.com
[Thu Sep 17 15:12:14.332613 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8zgAAGkk"]
[Thu Sep 17 15:12:14.332754 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno80gAAGj0"]
[Thu Sep 17 15:12:14.344843 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno80QAAGic"]
[Thu Sep 17 15:12:14.345088 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxXrucL08BTTQixEno9GAAAABI"]
[Thu Sep 17 15:12:14.350108 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8zwAAGkc"]
[Thu Sep 17 15:12:14.352389 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno80AAAGi8"]
[Thu Sep 17 15:12:14.361651 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/github/.env"] [unique_id "aqxXrucL08BTTQixEno9GgAAACU"]
[Thu Sep 17 15:12:14.363831 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno82wAAGk4"]
[Thu Sep 17 15:12:14.364001 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno83QAAGk8"]
[Thu Sep 17 15:12:14.364372 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno87QAAGjs"]
[Thu Sep 17 15:12:14.364524 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno84AAAGks"]
[Thu Sep 17 15:12:14.366237 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno84wAAGkI"]
[Thu Sep 17 15:12:14.367508 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno83gAAGkw"]
[Thu Sep 17 15:12:14.368854 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno85gAAGlo"]
[Thu Sep 17 15:12:14.369259 2026] [security2:error] [pid 971102:tid 971205] [remote 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno85AAAGmQ"]
[Thu Sep 17 15:12:14.375547 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxXrucL08BTTQixEno9HAAAAB0"]
[Thu Sep 17 15:12:14.381200 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno84gAAGlA"]
[Thu Sep 17 15:12:14.384945 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno8-gAAGlg"]
[Thu Sep 17 15:12:14.386948 2026] [security2:error] [pid 971102:tid 971260] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrecL08BTTQixEno82AAAGjw"]
[Thu Sep 17 15:12:14.400355 2026] [security2:error] [pid 971102:tid 971288] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxXrucL08BTTQixEno9HgAAADY"]
[Thu Sep 17 15:12:14.401814 2026] [core:error] [pid 971102:tid 971291] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:14.401827 2026] [core:error] [pid 971102:tid 971291] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:14.425384 2026] [security2:error] [pid 971102:tid 971276] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxXrucL08BTTQixEno9HwAAACo"]
[Thu Sep 17 15:12:14.445166 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXrucL08BTTQixEno9IQAAAH8"]
[Thu Sep 17 15:12:14.447514 2026] [security2:error] [pid 971102:tid 971335] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxXrucL08BTTQixEno9IgAAAGU"]
[Thu Sep 17 15:12:14.467099 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxXrucL08BTTQixEno9IwAAAFI"]
[Thu Sep 17 15:12:14.485957 2026] [security2:error] [pid 971102:tid 971302] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxXrucL08BTTQixEno9JAAAAEQ"]
[Thu Sep 17 15:12:14.522999 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxXrucL08BTTQixEno9JwAAAHw"]
[Thu Sep 17 15:12:14.524820 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/v3/.env"] [unique_id "aqxXrucL08BTTQixEno9KAAAABc"]
[Thu Sep 17 15:12:14.525524 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/actions/.env"] [unique_id "aqxXrucL08BTTQixEno9KgAAAE8"]
[Thu Sep 17 15:12:14.564104 2026] [security2:error] [pid 971102:tid 971208] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sqlerudition.com"] [uri "/sites/default/settings.local.php"] [unique_id "aqxXrucL08BTTQixEno9NgAAUWc"]
[Thu Sep 17 15:12:14.565054 2026] [security2:error] [pid 971102:tid 971162] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/vendor/.env"] [unique_id "aqxXrucL08BTTQixEno9MQAAUTo"]
[Thu Sep 17 15:12:14.565181 2026] [security2:error] [pid 971102:tid 971355] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxXrucL08BTTQixEno9NwAAAHk"]
[Thu Sep 17 15:12:14.565868 2026] [authz_core:error] [pid 971102:tid 971213] [remote 45.138.12.28:33672] AH01630: client denied by server configuration: /home4/drivihap/public_html/sqlerudition/.htpasswd
[Thu Sep 17 15:12:14.594064 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxXrucL08BTTQixEno9OgAAAFA"]
[Thu Sep 17 15:12:14.595810 2026] [security2:error] [pid 971102:tid 971354] [client 104.28.198.244:22911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrucL08BTTQixEno9OwAAAHg"]
[Thu Sep 17 15:12:14.595956 2026] [security2:error] [pid 971102:tid 971354] [client 104.28.198.244:22911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXrucL08BTTQixEno9OwAAAHg"]
[Thu Sep 17 15:12:14.613299 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9JgAAUV4"]
[Thu Sep 17 15:12:14.618890 2026] [security2:error] [pid 971102:tid 971301] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxXrucL08BTTQixEno9PAAAAEM"]
[Thu Sep 17 15:12:14.678731 2026] [security2:error] [pid 971102:tid 971319] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxXrucL08BTTQixEno9PQAAAFU"]
[Thu Sep 17 15:12:14.680806 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/circleci/.env"] [unique_id "aqxXrucL08BTTQixEno9PgAAAHs"]
[Thu Sep 17 15:12:14.707367 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxXrucL08BTTQixEno9PwAAAA0"]
[Thu Sep 17 15:12:14.726700 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxXrucL08BTTQixEno9QAAAACs"]
[Thu Sep 17 15:12:14.747184 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxXrucL08BTTQixEno9RAAAAHU"]
[Thu Sep 17 15:12:14.747235 2026] [security2:error] [pid 971102:tid 971198] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/panel/.env"] [unique_id "aqxXrucL08BTTQixEno9RgAAUV0"]
[Thu Sep 17 15:12:14.749996 2026] [security2:error] [pid 971102:tid 971274] [client 5.255.106.237:51448] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.daristore.com"] [uri "/"] [unique_id "aqxXrucL08BTTQixEno9SAAAACg"]
[Thu Sep 17 15:12:14.751743 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/dev/.env"] [unique_id "aqxXrucL08BTTQixEno9SQAAADA"]
[Thu Sep 17 15:12:14.775336 2026] [security2:error] [pid 971102:tid 971305] [client 5.255.106.237:51462] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "daristore.com"] [uri "/mail"] [unique_id "aqxXrucL08BTTQixEno9SgAAAEc"]
[Thu Sep 17 15:12:14.787362 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9OQAAAD8"]
[Thu Sep 17 15:12:14.787378 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9OQAAAD8"]
[Thu Sep 17 15:12:14.795232 2026] [security2:error] [pid 971102:tid 971349] [client 5.255.106.237:51482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.daristore.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "aqxXrucL08BTTQixEno9TAAAAHM"]
[Thu Sep 17 15:12:14.796144 2026] [security2:error] [pid 971102:tid 971249] [client 5.255.106.237:51476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "daristore.com"] [uri "/webmail"] [unique_id "aqxXrucL08BTTQixEno9TQAAAA8"]
[Thu Sep 17 15:12:14.798171 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.28:33672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "sqlerudition.com"] [uri "/.env.local.swp"] [unique_id "aqxXrucL08BTTQixEno9TgAAUW0"]
[Thu Sep 17 15:12:14.837163 2026] [security2:error] [pid 971102:tid 971328] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/travis/.env"] [unique_id "aqxXrucL08BTTQixEno9UQAAAF4"]
[Thu Sep 17 15:12:14.917064 2026] [security2:error] [pid 971102:tid 971284] [client 8.228.10.213:37436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxXrucL08BTTQixEno9UwAAADI"]
[Thu Sep 17 15:12:14.927184 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxXrucL08BTTQixEno9VQAAACM"]
[Thu Sep 17 15:12:14.927272 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:51408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Fe.php"] [unique_id "aqxXrucL08BTTQixEno9VQAAACM"]
[Thu Sep 17 15:12:14.962591 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/debug.php"] [unique_id "aqxXrucL08BTTQixEno9VgAAAF8"]
[Thu Sep 17 15:12:14.978948 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/api/staging/.env"] [unique_id "aqxXrucL08BTTQixEno9VwAAAEU"]
[Thu Sep 17 15:12:14.987892 2026] [security2:error] [pid 971102:tid 971243] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxXrucL08BTTQixEno9WAAAAAk"]
[Thu Sep 17 15:12:14.990039 2026] [security2:error] [pid 971102:tid 971261] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/buildkite/.env"] [unique_id "aqxXrucL08BTTQixEno9WQAAABs"]
[Thu Sep 17 15:12:15.026099 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxXr-cL08BTTQixEno9WgAAAEs"]
[Thu Sep 17 15:12:15.052468 2026] [security2:error] [pid 971102:tid 971292] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxXr-cL08BTTQixEno9XQAAADo"]
[Thu Sep 17 15:12:15.082772 2026] [security2:error] [pid 971102:tid 971318] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxXr-cL08BTTQixEno9XgAAAFQ"]
[Thu Sep 17 15:12:15.105926 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxXr-cL08BTTQixEno9XwAAAEo"]
[Thu Sep 17 15:12:15.116293 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.130.148:60306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "aqxXr-cL08BTTQixEno9YAAAADw"]
[Thu Sep 17 15:12:15.136091 2026] [security2:error] [pid 971102:tid 971334] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxXr-cL08BTTQixEno9YQAAAGQ"]
[Thu Sep 17 15:12:15.146760 2026] [security2:error] [pid 971102:tid 971359] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mysql/.env"] [unique_id "aqxXr-cL08BTTQixEno9YgAAAH0"]
[Thu Sep 17 15:12:15.160136 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxXr-cL08BTTQixEno9YwAAAAQ"]
[Thu Sep 17 15:12:15.177725 2026] [security2:error] [pid 971102:tid 971327] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxXr-cL08BTTQixEno9ZAAAAF0"]
[Thu Sep 17 15:12:15.201651 2026] [security2:error] [pid 971102:tid 971278] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxXr-cL08BTTQixEno9ZQAAACw"]
[Thu Sep 17 15:12:15.204227 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/vendor/.env"] [unique_id "aqxXr-cL08BTTQixEno9ZgAAABE"]
[Thu Sep 17 15:12:15.217554 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxXr-cL08BTTQixEno9ZwAAAAs"]
[Thu Sep 17 15:12:15.221685 2026] [security2:error] [pid 971102:tid 971324] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxXr-cL08BTTQixEno9aAAAAFo"]
[Thu Sep 17 15:12:15.251478 2026] [security2:error] [pid 971102:tid 971332] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxXr-cL08BTTQixEno9aQAAAGI"]
[Thu Sep 17 15:12:15.257866 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9JQAAUVU"]
[Thu Sep 17 15:12:15.260600 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9KQAAUVw"]
[Thu Sep 17 15:12:15.274598 2026] [security2:error] [pid 971102:tid 971250] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxXr-cL08BTTQixEno9agAAABA"]
[Thu Sep 17 15:12:15.297790 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxXr-cL08BTTQixEno9awAAAAY"]
[Thu Sep 17 15:12:15.299709 2026] [security2:error] [pid 971102:tid 971265] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/postgres/.env"] [unique_id "aqxXr-cL08BTTQixEno9bAAAAB8"]
[Thu Sep 17 15:12:15.299801 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9KwAAUVQ"]
[Thu Sep 17 15:12:15.302845 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9NAAAUWs"]
[Thu Sep 17 15:12:15.303085 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LQAAUVI"]
[Thu Sep 17 15:12:15.303140 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LAAAUWU"]
[Thu Sep 17 15:12:15.303873 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LwAAUVc"]
[Thu Sep 17 15:12:15.304145 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9MAAAUWA"]
[Thu Sep 17 15:12:15.304185 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9MgAAUXI"]
[Thu Sep 17 15:12:15.304218 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9LgAAUWk"]
[Thu Sep 17 15:12:15.304257 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9OAAAUVY"]
[Thu Sep 17 15:12:15.306530 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9NQAAUVs"]
[Thu Sep 17 15:12:15.316166 2026] [security2:error] [pid 971102:tid 971273] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxXr-cL08BTTQixEno9bgAAACc"]
[Thu Sep 17 15:12:15.333289 2026] [security2:error] [pid 971102:tid 971333] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxXr-cL08BTTQixEno9bwAAAGM"]
[Thu Sep 17 15:12:15.349152 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9RQAAUXA"]
[Thu Sep 17 15:12:15.349239 2026] [security2:error] [pid 971102:tid 971315] [client 45.138.12.28:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxXrucL08BTTQixEno9RwAAUX0"]
[Thu Sep 17 15:12:15.351540 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxXr-cL08BTTQixEno9cQAAABw"]
[Thu Sep 17 15:12:15.368799 2026] [security2:error] [pid 971102:tid 971295] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxXr-cL08BTTQixEno9dAAAAD0"]
[Thu Sep 17 15:12:15.371246 2026] [authz_core:error] [pid 971102:tid 971344] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/error_log
[Thu Sep 17 15:12:15.373357 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/"] [unique_id "aqxXr-cL08BTTQixEno9cwAAAG4"]
[Thu Sep 17 15:12:15.384715 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxXr-cL08BTTQixEno9eQAAAFk"]
[Thu Sep 17 15:12:15.386442 2026] [core:error] [pid 971102:tid 971234] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:15.386455 2026] [core:error] [pid 971102:tid 971234] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:15.407194 2026] [security2:error] [pid 971102:tid 971255] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxXr-cL08BTTQixEno9fAAAABU"]
[Thu Sep 17 15:12:15.425044 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxXr-cL08BTTQixEno9fQAAADM"]
[Thu Sep 17 15:12:15.429735 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/lib/.env"] [unique_id "aqxXr-cL08BTTQixEno9fgAAAGg"]
[Thu Sep 17 15:12:15.448948 2026] [security2:error] [pid 971102:tid 971312] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxXr-cL08BTTQixEno9gAAAAE4"]
[Thu Sep 17 15:12:15.449754 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/mongodb/.env"] [unique_id "aqxXr-cL08BTTQixEno9gQAAABI"]
[Thu Sep 17 15:12:15.475037 2026] [security2:error] [pid 971102:tid 971337] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxXr-cL08BTTQixEno9ggAAAGc"]
[Thu Sep 17 15:12:15.498592 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxXr-cL08BTTQixEno9gwAAAB0"]
[Thu Sep 17 15:12:15.518645 2026] [security2:error] [pid 971102:tid 971296] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxXr-cL08BTTQixEno9hAAAAD4"]
[Thu Sep 17 15:12:15.521476 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/wp-includes/sodium_compat/namespaced/Core/Curve25519/"] [unique_id "aqxXr-cL08BTTQixEno9hQAAABo"]
[Thu Sep 17 15:12:15.542802 2026] [security2:error] [pid 971102:tid 971288] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxXr-cL08BTTQixEno9hgAAADY"]
[Thu Sep 17 15:12:15.567613 2026] [security2:error] [pid 971102:tid 971291] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxXr-cL08BTTQixEno9hwAAADk"]
[Thu Sep 17 15:12:15.596413 2026] [security2:error] [pid 971102:tid 971325] [client 34.32.117.146:35186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXr-cL08BTTQixEno9iAAAAFs"]
[Thu Sep 17 15:12:15.597336 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxXr-cL08BTTQixEno9iQAAAGY"]
[Thu Sep 17 15:12:15.616747 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/redis/.env"] [unique_id "aqxXr-cL08BTTQixEno9igAAAAc"]
[Thu Sep 17 15:12:15.631881 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxXr-cL08BTTQixEno9iwAAAEk"]
[Thu Sep 17 15:12:15.662765 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/resources/.env"] [unique_id "aqxXr-cL08BTTQixEno9jQAAAGU"]
[Thu Sep 17 15:12:15.669883 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxXr-cL08BTTQixEno9jwAAAHw"]
[Thu Sep 17 15:12:15.694625 2026] [security2:error] [pid 971102:tid 971257] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxXr-cL08BTTQixEno9kQAAABc"]
[Thu Sep 17 15:12:15.725369 2026] [security2:error] [pid 971102:tid 971313] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxXr-cL08BTTQixEno9kgAAAE8"]
[Thu Sep 17 15:12:15.747371 2026] [security2:error] [pid 971102:tid 971355] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxXr-cL08BTTQixEno9kwAAAHk"]
[Thu Sep 17 15:12:15.771944 2026] [security2:error] [pid 971102:tid 971352] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/elasticsearch/.env"] [unique_id "aqxXr-cL08BTTQixEno9lAAAAHY"]
[Thu Sep 17 15:12:15.782754 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxXr-cL08BTTQixEno9lQAAAFA"]
[Thu Sep 17 15:12:15.803520 2026] [security2:error] [pid 971102:tid 971266] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxXr-cL08BTTQixEno9lgAAACA"]
[Thu Sep 17 15:12:15.824817 2026] [security2:error] [pid 971102:tid 971319] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxXr-cL08BTTQixEno9mAAAAFU"]
[Thu Sep 17 15:12:15.851567 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxXr-cL08BTTQixEno9mgAAAHs"]
[Thu Sep 17 15:12:15.860831 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXr-cL08BTTQixEno9jgAAAFI"]
[Thu Sep 17 15:12:15.860850 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXr-cL08BTTQixEno9jgAAAFI"]
[Thu Sep 17 15:12:15.873423 2026] [security2:error] [pid 971102:tid 971340] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxXr-cL08BTTQixEno9mwAAAGo"]
[Thu Sep 17 15:12:15.890754 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxXr-cL08BTTQixEno9nQAAAEY"]
[Thu Sep 17 15:12:15.898584 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/assets/.env"] [unique_id "aqxXr-cL08BTTQixEno9ngAAAA0"]
[Thu Sep 17 15:12:15.907197 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxXr-cL08BTTQixEno9nwAAAHU"]
[Thu Sep 17 15:12:15.921029 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/rabbitmq/.env"] [unique_id "aqxXr-cL08BTTQixEno9owAAAEc"]
[Thu Sep 17 15:12:15.923918 2026] [security2:error] [pid 971102:tid 971341] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxXr-cL08BTTQixEno9pAAAAGs"]
[Thu Sep 17 15:12:15.946814 2026] [security2:error] [pid 971102:tid 971293] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxXr-cL08BTTQixEno9pQAAADs"]
[Thu Sep 17 15:12:15.974135 2026] [security2:error] [pid 971102:tid 971349] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxXr-cL08BTTQixEno9pgAAAHM"]
[Thu Sep 17 15:12:15.993300 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxXr-cL08BTTQixEno9pwAAAAE"]
[Thu Sep 17 15:12:16.017435 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxXsOcL08BTTQixEno9qAAAAF4"]
[Thu Sep 17 15:12:16.024154 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:51418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXsOcL08BTTQixEno9qQAAACQ"]
[Thu Sep 17 15:12:16.024221 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXsOcL08BTTQixEno9qQAAACQ"]
[Thu Sep 17 15:12:16.034081 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxXsOcL08BTTQixEno9qgAAAAo"]
[Thu Sep 17 15:12:16.050822 2026] [security2:error] [pid 971102:tid 971256] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxXsOcL08BTTQixEno9qwAAABY"]
[Thu Sep 17 15:12:16.070285 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/kafka/.env"] [unique_id "aqxXsOcL08BTTQixEno9rAAAADI"]
[Thu Sep 17 15:12:16.071631 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxXsOcL08BTTQixEno9rQAAACM"]
[Thu Sep 17 15:12:16.094947 2026] [security2:error] [pid 971102:tid 971286] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxXsOcL08BTTQixEno9rgAAADQ"]
[Thu Sep 17 15:12:16.111741 2026] [security2:error] [pid 971102:tid 971239] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxXsOcL08BTTQixEno9rwAAAAU"]
[Thu Sep 17 15:12:16.127926 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/uploads/.env"] [unique_id "aqxXsOcL08BTTQixEno9sAAAAFw"]
[Thu Sep 17 15:12:16.138964 2026] [security2:error] [pid 971102:tid 971353] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxXsOcL08BTTQixEno9swAAAHc"]
[Thu Sep 17 15:12:16.155942 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxXsOcL08BTTQixEno9tAAAAEU"]
[Thu Sep 17 15:12:16.181786 2026] [security2:error] [pid 971102:tid 971261] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxXsOcL08BTTQixEno9tQAAABs"]
[Thu Sep 17 15:12:16.201958 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxXsOcL08BTTQixEno9tgAAAEs"]
[Thu Sep 17 15:12:16.219028 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxXsOcL08BTTQixEno9uQAAAGk"]
[Thu Sep 17 15:12:16.219748 2026] [security2:error] [pid 971102:tid 971318] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/queue/.env"] [unique_id "aqxXsOcL08BTTQixEno9ugAAAFQ"]
[Thu Sep 17 15:12:16.247260 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxXsOcL08BTTQixEno9uwAAAHE"]
[Thu Sep 17 15:12:16.250805 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:16.250823 2026] [core:error] [pid 971102:tid 971308] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:16.267150 2026] [security2:error] [pid 971102:tid 971280] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxXsOcL08BTTQixEno9vQAAAC4"]
[Thu Sep 17 15:12:16.285137 2026] [security2:error] [pid 971102:tid 971259] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxXsOcL08BTTQixEno9vwAAABk"]
[Thu Sep 17 15:12:16.311204 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXsOcL08BTTQixEno9wgAAAEg"]
[Thu Sep 17 15:12:16.311334 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:51420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXsOcL08BTTQixEno9wgAAAEg"]
[Thu Sep 17 15:12:16.319136 2026] [security2:error] [pid 971102:tid 971359] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxXsOcL08BTTQixEno9xAAAAH0"]
[Thu Sep 17 15:12:16.343542 2026] [security2:error] [pid 971102:tid 971327] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxXsOcL08BTTQixEno9xQAAAF0"]
[Thu Sep 17 15:12:16.360943 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/internal/.env"] [unique_id "aqxXsOcL08BTTQixEno9xgAAACw"]
[Thu Sep 17 15:12:16.361083 2026] [security2:error] [pid 971102:tid 971251] [client 8.228.10.213:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxXsOcL08BTTQixEno9xwAAABE"]
[Thu Sep 17 15:12:16.371789 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/worker/.env"] [unique_id "aqxXsOcL08BTTQixEno9yAAAAAs"]
[Thu Sep 17 15:12:16.378114 2026] [security2:error] [pid 971102:tid 971324] [client 8.228.10.213:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxXsOcL08BTTQixEno9yQAAAFo"]
[Thu Sep 17 15:12:16.400260 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.117.146:35200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXsOcL08BTTQixEno9ygAAACY"]
[Thu Sep 17 15:12:16.446346 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.10.213:37458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/info.php"] [unique_id "aqxXsOcL08BTTQixEno9zAAAAAY"]
[Thu Sep 17 15:12:16.509107 2026] [security2:error] [pid 971102:tid 971295] [client 8.228.10.213:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/php.php"] [unique_id "aqxXsOcL08BTTQixEno9zgAAAD0"]
[Thu Sep 17 15:12:16.522130 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/job/.env"] [unique_id "aqxXsOcL08BTTQixEno9zwAAAAA"]
[Thu Sep 17 15:12:16.573922 2026] [security2:error] [pid 971102:tid 971255] [client 8.228.10.213:37472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/i.php"] [unique_id "aqxXsOcL08BTTQixEno90QAAABU"]
[Thu Sep 17 15:12:16.591776 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/tools/.env"] [unique_id "aqxXsOcL08BTTQixEno90gAAADU"]
[Thu Sep 17 15:12:16.602189 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:51434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXsOcL08BTTQixEno90wAAAEI"]
[Thu Sep 17 15:12:16.602280 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:51434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXsOcL08BTTQixEno90wAAAEI"]
[Thu Sep 17 15:12:16.640771 2026] [security2:error] [pid 971102:tid 971338] [client 8.228.10.213:37478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxXsOcL08BTTQixEno91AAAAGg"]
[Thu Sep 17 15:12:16.672874 2026] [security2:error] [pid 971102:tid 971312] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/test/.env"] [unique_id "aqxXsOcL08BTTQixEno91QAAAE4"]
[Thu Sep 17 15:12:16.714767 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.10.213:37488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxXsOcL08BTTQixEno91gAAABI"]
[Thu Sep 17 15:12:16.773363 2026] [security2:error] [pid 971102:tid 971250] [client 186.105.232.15:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno92AAAABA"]
[Thu Sep 17 15:12:16.773510 2026] [security2:error] [pid 971102:tid 971250] [client 186.105.232.15:53971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno92AAAABA"]
[Thu Sep 17 15:12:16.801162 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.10.213:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/test.php"] [unique_id "aqxXsOcL08BTTQixEno92QAAAGY"]
[Thu Sep 17 15:12:16.818616 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/scripts/.env"] [unique_id "aqxXsOcL08BTTQixEno92gAAABM"]
[Thu Sep 17 15:12:16.822461 2026] [security2:error] [pid 971102:tid 971356] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/qa/.env"] [unique_id "aqxXsOcL08BTTQixEno93AAAAHo"]
[Thu Sep 17 15:12:16.883453 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXsOcL08BTTQixEno94wAAAHk"]
[Thu Sep 17 15:12:16.883590 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:51448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXsOcL08BTTQixEno94wAAAHk"]
[Thu Sep 17 15:12:16.929340 2026] [security2:error] [pid 971102:tid 971263] [client 114.198.138.124:60441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno95AAAAB0"]
[Thu Sep 17 15:12:16.929457 2026] [security2:error] [pid 971102:tid 971263] [client 114.198.138.124:60441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsOcL08BTTQixEno95AAAAB0"]
[Thu Sep 17 15:12:16.935948 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/p.php"] [unique_id "aqxXsOcL08BTTQixEno95QAAAFA"]
[Thu Sep 17 15:12:16.974060 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/preview/.env"] [unique_id "aqxXsOcL08BTTQixEno96AAAAHs"]
[Thu Sep 17 15:12:17.003498 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxXsecL08BTTQixEno96QAAAFI"]
[Thu Sep 17 15:12:17.045614 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/bin/.env"] [unique_id "aqxXsecL08BTTQixEno96gAAAHU"]
[Thu Sep 17 15:12:17.052992 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.10.213:37526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno96wAAAA0"]
[Thu Sep 17 15:12:17.125384 2026] [security2:error] [pid 971102:tid 971349] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/beta/.env"] [unique_id "aqxXsecL08BTTQixEno97AAAAHM"]
[Thu Sep 17 15:12:17.130260 2026] [security2:error] [pid 971102:tid 971274] [client 8.228.10.213:37534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno97QAAACg"]
[Thu Sep 17 15:12:17.160869 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXsecL08BTTQixEno97gAAAF4"]
[Thu Sep 17 15:12:17.160987 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:51460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXsecL08BTTQixEno97gAAAF4"]
[Thu Sep 17 15:12:17.204898 2026] [security2:error] [pid 971102:tid 971270] [client 8.228.10.213:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno97wAAACQ"]
[Thu Sep 17 15:12:17.268380 2026] [security2:error] [pid 971102:tid 971254] [client 8.228.10.213:37550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno98wAAABQ"]
[Thu Sep 17 15:12:17.275265 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sbin/.env"] [unique_id "aqxXsecL08BTTQixEno99AAAACM"]
[Thu Sep 17 15:12:17.275905 2026] [security2:error] [pid 971102:tid 971290] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/uat/.env"] [unique_id "aqxXsecL08BTTQixEno99QAAADg"]
[Thu Sep 17 15:12:17.286734 2026] [core:error] [pid 971102:tid 971286] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:17.286749 2026] [core:error] [pid 971102:tid 971286] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:17.314844 2026] [security2:error] [pid 971102:tid 971305] [client 34.32.117.146:35206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno99wAAAEc"]
[Thu Sep 17 15:12:17.342770 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.10.213:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno9-AAAAEU"]
[Thu Sep 17 15:12:17.403796 2026] [security2:error] [pid 971102:tid 971347] [client 8.228.10.213:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno9_AAAAHE"]
[Thu Sep 17 15:12:17.426885 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/stage/.env"] [unique_id "aqxXsecL08BTTQixEno9_QAAAF8"]
[Thu Sep 17 15:12:17.472927 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:51462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxXsecL08BTTQixEno9_gAAAC4"]
[Thu Sep 17 15:12:17.473031 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:51462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Curve25519/H.php"] [unique_id "aqxXsecL08BTTQixEno9_gAAAC4"]
[Thu Sep 17 15:12:17.501985 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/local/.env"] [unique_id "aqxXsecL08BTTQixEno-AAAAAGQ"]
[Thu Sep 17 15:12:17.556376 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxXsecL08BTTQixEno-AwAAAAQ"]
[Thu Sep 17 15:12:17.577726 2026] [security2:error] [pid 971102:tid 971272] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/development/.env"] [unique_id "aqxXsecL08BTTQixEno-BAAAACY"]
[Thu Sep 17 15:12:17.628483 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.10.213:37598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxXsecL08BTTQixEno-BgAAAAY"]
[Thu Sep 17 15:12:17.687977 2026] [security2:error] [pid 971102:tid 971234] [client 8.228.10.213:37614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno-BwAAAAA"]
[Thu Sep 17 15:12:17.735208 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/portal/.env"] [unique_id "aqxXsecL08BTTQixEno-CAAAACE"]
[Thu Sep 17 15:12:17.736798 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/production/.env"] [unique_id "aqxXsecL08BTTQixEno-CQAAABU"]
[Thu Sep 17 15:12:17.762072 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxXsecL08BTTQixEno-CwAAAAg"]
[Thu Sep 17 15:12:17.762173 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:51468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Ed25519.php"] [unique_id "aqxXsecL08BTTQixEno-CwAAAAg"]
[Thu Sep 17 15:12:17.780429 2026] [security2:error] [pid 971102:tid 971287] [client 8.228.10.213:37628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxXsecL08BTTQixEno-DAAAADU"]
[Thu Sep 17 15:12:17.780571 2026] [security2:error] [pid 971102:tid 971318] [client 154.190.208.131:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsecL08BTTQixEno-DQAAAFQ"]
[Thu Sep 17 15:12:17.788415 2026] [security2:error] [pid 971102:tid 971318] [client 154.190.208.131:41559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXsecL08BTTQixEno-DQAAAFQ"]
[Thu Sep 17 15:12:17.840415 2026] [security2:error] [pid 971102:tid 971350] [client 8.228.10.213:37642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxXsecL08BTTQixEno-EAAAAHQ"]
[Thu Sep 17 15:12:17.890540 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.0.94:41438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seedboxpress.com"] [uri "/config/app/.env"] [unique_id "aqxXsecL08BTTQixEno-EgAAAG8"]
[Thu Sep 17 15:12:17.905350 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.10.213:37654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxXsecL08BTTQixEno-EwAAAAM"]
[Thu Sep 17 15:12:17.961805 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/dashboard/.env"] [unique_id "aqxXsecL08BTTQixEno-FQAAABo"]
[Thu Sep 17 15:12:18.055732 2026] [security2:error] [pid 971102:tid 971307] [client 34.32.0.94:41438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-GAAAAEk"]
[Thu Sep 17 15:12:18.078541 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:51476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxXsucL08BTTQixEno-GwAAAHo"]
[Thu Sep 17 15:12:18.078632 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:51476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HChaCha20.php"] [unique_id "aqxXsucL08BTTQixEno-GwAAAHo"]
[Thu Sep 17 15:12:18.137184 2026] [security2:error] [pid 971102:tid 971314] [client 8.228.10.213:37664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXsucL08BTTQixEno-IAAAAFA"]
[Thu Sep 17 15:12:18.192227 2026] [security2:error] [pid 971102:tid 971304] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/panel/.env"] [unique_id "aqxXsucL08BTTQixEno-JQAAAEY"]
[Thu Sep 17 15:12:18.206999 2026] [security2:error] [pid 971102:tid 971340] [client 8.228.10.213:37672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-JgAAAGo"]
[Thu Sep 17 15:12:18.221617 2026] [core:error] [pid 971102:tid 971341] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.221635 2026] [core:error] [pid 971102:tid 971341] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.293420 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.10.213:37684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-KQAAAAE"]
[Thu Sep 17 15:12:18.340193 2026] [autoindex:error] [pid 971102:tid 971351] [client 172.239.147.162:59116] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:12:18.342810 2026] [security2:error] [pid 971102:tid 971263] [client 34.32.117.146:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-LQAAAB0"]
[Thu Sep 17 15:12:18.353203 2026] [security2:error] [pid 971102:tid 971317] [client 8.228.10.213:37690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-LwAAAFM"]
[Thu Sep 17 15:12:18.356028 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxXsucL08BTTQixEno-MAAAAEQ"]
[Thu Sep 17 15:12:18.356107 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:51484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/HSalsa20.php"] [unique_id "aqxXsucL08BTTQixEno-MAAAAEQ"]
[Thu Sep 17 15:12:18.403656 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.10.213:37700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-MgAAAFw"]
[Thu Sep 17 15:12:18.421738 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/crm/.env"] [unique_id "aqxXsucL08BTTQixEno-MwAAAAk"]
[Thu Sep 17 15:12:18.485781 2026] [security2:error] [pid 971102:tid 971248] [client 8.228.10.213:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-NwAAAA4"]
[Thu Sep 17 15:12:18.537180 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.0.94:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/info.php"] [unique_id "aqxXsucL08BTTQixEno-OQAAADQ"]
[Thu Sep 17 15:12:18.568068 2026] [security2:error] [pid 971102:tid 971296] [client 8.228.10.213:37728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxXsucL08BTTQixEno-OgAAAD4"]
[Thu Sep 17 15:12:18.646812 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.10.213:37734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxXsucL08BTTQixEno-PAAAAEg"]
[Thu Sep 17 15:12:18.651289 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/erp/.env"] [unique_id "aqxXsucL08BTTQixEno-PQAAAH0"]
[Thu Sep 17 15:12:18.665197 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxXsucL08BTTQixEno-PgAAAEs"]
[Thu Sep 17 15:12:18.665318 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:51486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305.php"] [unique_id "aqxXsucL08BTTQixEno-PgAAAEs"]
[Thu Sep 17 15:12:18.723183 2026] [security2:error] [pid 971102:tid 971245] [client 8.228.10.213:41992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxXsucL08BTTQixEno-PwAAAAs"]
[Thu Sep 17 15:12:18.782383 2026] [security2:error] [pid 971102:tid 971320] [client 8.228.10.213:42008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxXsucL08BTTQixEno-QwAAAFY"]
[Thu Sep 17 15:12:18.874142 2026] [security2:error] [pid 971102:tid 971299] [client 8.228.10.213:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxXsucL08BTTQixEno-SwAAAEE"]
[Thu Sep 17 15:12:18.879087 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/shop/.env"] [unique_id "aqxXsucL08BTTQixEno-TAAAAAg"]
[Thu Sep 17 15:12:18.925411 2026] [security2:error] [pid 971102:tid 971300] [client 82.102.18.118:46406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxXsucL08BTTQixEno-TQAAAEI"]
[Thu Sep 17 15:12:18.954269 2026] [security2:error] [pid 971102:tid 971350] [client 8.228.10.213:42028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxXsucL08BTTQixEno-UQAAAHQ"]
[Thu Sep 17 15:12:18.967292 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxXsucL08BTTQixEno-UwAAAAM"]
[Thu Sep 17 15:12:18.970878 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.970897 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:18.993582 2026] [security2:error] [pid 971102:tid 971234] [client 34.32.0.94:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/php.php"] [unique_id "aqxXsucL08BTTQixEno-VQAAAAA"]
[Thu Sep 17 15:12:19.037983 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.10.213:42030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-WQAAAG0"]
[Thu Sep 17 15:12:19.105552 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/store/.env"] [unique_id "aqxXs-cL08BTTQixEno-WwAAAHo"]
[Thu Sep 17 15:12:19.121510 2026] [authz_core:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/namespaced/Core/Poly1305/error_log
[Thu Sep 17 15:12:19.122377 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/"] [unique_id "aqxXs-cL08BTTQixEno-XAAAAEA"]
[Thu Sep 17 15:12:19.134760 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.10.213:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-XQAAAEk"]
[Thu Sep 17 15:12:19.192388 2026] [security2:error] [pid 971102:tid 971301] [client 5.189.145.112:58623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxXs-cL08BTTQixEno-XgAAAEM"], referer: binance.com
[Thu Sep 17 15:12:19.208469 2026] [security2:error] [pid 971102:tid 971354] [client 8.228.10.213:42048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-XwAAAHg"]
[Thu Sep 17 15:12:19.265897 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "aqxXs-cL08BTTQixEno-YAAAADs"]
[Thu Sep 17 15:12:19.292985 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.10.213:42058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-YQAAAHs"]
[Thu Sep 17 15:12:19.293844 2026] [security2:error] [pid 971102:tid 971236] [client 34.32.117.146:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-YgAAAAI"]
[Thu Sep 17 15:12:19.332452 2026] [security2:error] [pid 971102:tid 971282] [client 82.102.18.118:45184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxXs-cL08BTTQixEno-YwAAADA"]
[Thu Sep 17 15:12:19.333226 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/saas/.env"] [unique_id "aqxXs-cL08BTTQixEno-ZgAAACg"]
[Thu Sep 17 15:12:19.361845 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.10.213:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-cgAAAF4"]
[Thu Sep 17 15:12:19.428261 2026] [security2:error] [pid 971102:tid 971355] [client 8.228.10.213:42082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-dQAAAHk"]
[Thu Sep 17 15:12:19.456668 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.0.94:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/i.php"] [unique_id "aqxXs-cL08BTTQixEno-dgAAABI"]
[Thu Sep 17 15:12:19.492870 2026] [security2:error] [pid 971102:tid 971317] [client 8.228.10.213:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-eAAAAFM"]
[Thu Sep 17 15:12:19.576537 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/client/.env"] [unique_id "aqxXs-cL08BTTQixEno-eQAAAAk"]
[Thu Sep 17 15:12:19.586751 2026] [security2:error] [pid 971102:tid 971305] [client 8.228.10.213:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-egAAAEc"]
[Thu Sep 17 15:12:19.592011 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXs-cL08BTTQixEno-ewAAAB0"]
[Thu Sep 17 15:12:19.592105 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXs-cL08BTTQixEno-ewAAAB0"]
[Thu Sep 17 15:12:19.649333 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXs-cL08BTTQixEno-dAAAAE0"]
[Thu Sep 17 15:12:19.649355 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXs-cL08BTTQixEno-dAAAAE0"]
[Thu Sep 17 15:12:19.668519 2026] [security2:error] [pid 971102:tid 971358] [client 8.228.10.213:42114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-fAAAAHw"]
[Thu Sep 17 15:12:19.685926 2026] [security2:error] [pid 971102:tid 971329] [client 82.102.18.118:45200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxXs-cL08BTTQixEno-fwAAAF8"]
[Thu Sep 17 15:12:19.731039 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.10.213:42126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-gAAAAFI"]
[Thu Sep 17 15:12:19.742664 2026] [core:error] [pid 971102:tid 971259] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:19.742680 2026] [core:error] [pid 971102:tid 971259] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:19.790509 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxXs-cL08BTTQixEno-ggAAAD4"]
[Thu Sep 17 15:12:19.790614 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:51498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Poly1305/State.php"] [unique_id "aqxXs-cL08BTTQixEno-ggAAAD4"]
[Thu Sep 17 15:12:19.808867 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/project/.env"] [unique_id "aqxXs-cL08BTTQixEno-hAAAAGQ"]
[Thu Sep 17 15:12:19.814025 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.10.213:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-hQAAAAo"]
[Thu Sep 17 15:12:19.890583 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.10.213:42150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-hwAAAAQ"]
[Thu Sep 17 15:12:19.911980 2026] [security2:error] [pid 971102:tid 971239] [client 34.32.0.94:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/pi.php"] [unique_id "aqxXs-cL08BTTQixEno-iwAAAAU"]
[Thu Sep 17 15:12:19.962236 2026] [security2:error] [pid 971102:tid 971292] [client 8.228.10.213:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.10.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.wlx.hwd.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxXs-cL08BTTQixEno-kAAAADo"]
[Thu Sep 17 15:12:20.035311 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/admin-panel/.env"] [unique_id "aqxXtOcL08BTTQixEno-kwAAAEE"]
[Thu Sep 17 15:12:20.056985 2026] [security2:error] [pid 971102:tid 971242] [client 82.102.18.118:45204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtOcL08BTTQixEno-lAAAAAg"]
[Thu Sep 17 15:12:20.078053 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxXtOcL08BTTQixEno-lQAAADU"]
[Thu Sep 17 15:12:20.078172 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Salsa20.php"] [unique_id "aqxXtOcL08BTTQixEno-lQAAADU"]
[Thu Sep 17 15:12:20.190890 2026] [security2:error] [pid 971102:tid 971332] [client 34.32.117.146:41878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXtOcL08BTTQixEno-ngAAAGI"]
[Thu Sep 17 15:12:20.261801 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/control-panel/.env"] [unique_id "aqxXtOcL08BTTQixEno-pwAAAFs"]
[Thu Sep 17 15:12:20.360451 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/pinfo.php"] [unique_id "aqxXtOcL08BTTQixEno-rAAAACo"]
[Thu Sep 17 15:12:20.373635 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxXtOcL08BTTQixEno-rgAAABM"]
[Thu Sep 17 15:12:20.373733 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:56514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/SipHash.php"] [unique_id "aqxXtOcL08BTTQixEno-rgAAABM"]
[Thu Sep 17 15:12:20.406043 2026] [security2:error] [pid 971102:tid 971314] [client 82.102.18.118:45220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtOcL08BTTQixEno-sAAAAFA"]
[Thu Sep 17 15:12:20.413915 2026] [security2:error] [pid 971102:tid 971360] [client 159.65.113.230:60711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "snowhillstokes.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXtOcL08BTTQixEno-sQAAAH4"]
[Thu Sep 17 15:12:20.489291 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/user-panel/.env"] [unique_id "aqxXtOcL08BTTQixEno-tgAAAD8"]
[Thu Sep 17 15:12:20.542214 2026] [core:error] [pid 971102:tid 971289] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:20.542233 2026] [core:error] [pid 971102:tid 971289] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:20.653699 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxXtOcL08BTTQixEno-wgAAAE0"]
[Thu Sep 17 15:12:20.653781 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:56526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Util.php"] [unique_id "aqxXtOcL08BTTQixEno-wgAAAE0"]
[Thu Sep 17 15:12:20.673783 2026] [security2:error] [pid 971102:tid 971250] [client 148.227.121.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxXs-cL08BTTQixEno-WgAAABA"], referer: https://darfieldearthship.com/
[Thu Sep 17 15:12:20.716896 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/node/.env"] [unique_id "aqxXtOcL08BTTQixEno-xgAAAA8"]
[Thu Sep 17 15:12:20.722443 2026] [security2:error] [pid 971102:tid 971361] [client 159.65.113.230:60714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "snowhillstokes.org"] [uri "/"] [unique_id "aqxXtOcL08BTTQixEno-xwAAAH8"]
[Thu Sep 17 15:12:20.772013 2026] [security2:error] [pid 971102:tid 971334] [client 82.102.18.118:45224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtOcL08BTTQixEno-zQAAAGQ"]
[Thu Sep 17 15:12:20.810753 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.0.94:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/test.php"] [unique_id "aqxXtOcL08BTTQixEno-0AAAAA4"]
[Thu Sep 17 15:12:20.937422 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxXtOcL08BTTQixEno-4QAAAF0"]
[Thu Sep 17 15:12:20.937547 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:56542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/X25519.php"] [unique_id "aqxXtOcL08BTTQixEno-4QAAAF0"]
[Thu Sep 17 15:12:20.944571 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/express/.env"] [unique_id "aqxXtOcL08BTTQixEno-4wAAAEI"]
[Thu Sep 17 15:12:21.004247 2026] [security2:error] [pid 971102:tid 971234] [client 52.231.79.181:1873] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/1.php"] [unique_id "aqxXtecL08BTTQixEno-6gAAAAA"]
[Thu Sep 17 15:12:21.004355 2026] [security2:error] [pid 971102:tid 971234] [client 52.231.79.181:1873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/1.php"] [unique_id "aqxXtecL08BTTQixEno-6gAAAAA"]
[Thu Sep 17 15:12:21.061048 2026] [security2:error] [pid 971102:tid 971298] [client 159.65.113.230:60718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "snowhillstokes.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXtecL08BTTQixEno-6wAAAEA"]
[Thu Sep 17 15:12:21.141156 2026] [security2:error] [pid 971102:tid 971325] [client 52.231.79.181:1895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/new.php"] [unique_id "aqxXtecL08BTTQixEno-7gAAAFs"]
[Thu Sep 17 15:12:21.143000 2026] [security2:error] [pid 971102:tid 971258] [client 82.102.18.118:45226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtecL08BTTQixEno-7wAAABg"]
[Thu Sep 17 15:12:21.173018 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/next/.env"] [unique_id "aqxXtecL08BTTQixEno-8AAAAGA"]
[Thu Sep 17 15:12:21.219523 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxXtecL08BTTQixEno-8wAAAEQ"]
[Thu Sep 17 15:12:21.219602 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:56546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/XChaCha20.php"] [unique_id "aqxXtecL08BTTQixEno-8wAAAEQ"]
[Thu Sep 17 15:12:21.331963 2026] [core:error] [pid 971102:tid 971270] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:21.331982 2026] [core:error] [pid 971102:tid 971270] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:21.381745 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.117.146:41884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXtOcL08BTTQixEno-3wAAAHw"]
[Thu Sep 17 15:12:21.399607 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/nuxt/.env"] [unique_id "aqxXtecL08BTTQixEno-_gAAABA"]
[Thu Sep 17 15:12:21.474382 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.0.94:52470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXtecL08BTTQixEno-9AAAAA0"]
[Thu Sep 17 15:12:21.497587 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxXtecL08BTTQixEno-_wAAACA"]
[Thu Sep 17 15:12:21.497687 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:56552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/Xsalsa20.php"] [unique_id "aqxXtecL08BTTQixEno-_wAAACA"]
[Thu Sep 17 15:12:21.502710 2026] [security2:error] [pid 971102:tid 971279] [client 82.102.18.118:28527] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtecL08BTTQixEno_AAAAAC0"]
[Thu Sep 17 15:12:21.540247 2026] [security2:error] [pid 971102:tid 971280] [client 52.231.79.181:1893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/num.php"] [unique_id "aqxXtecL08BTTQixEno_AQAAAC4"]
[Thu Sep 17 15:12:21.623299 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/p.php"] [unique_id "aqxXtecL08BTTQixEno_BAAAAFI"]
[Thu Sep 17 15:12:21.625494 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/nest/.env"] [unique_id "aqxXtecL08BTTQixEno_BQAAADQ"]
[Thu Sep 17 15:12:21.788315 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxXtecL08BTTQixEno_BwAAABc"]
[Thu Sep 17 15:12:21.788396 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:56558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/Crypto.php"] [unique_id "aqxXtecL08BTTQixEno_BwAAABc"]
[Thu Sep 17 15:12:21.851052 2026] [security2:error] [pid 971102:tid 971248] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/react/.env"] [unique_id "aqxXtecL08BTTQixEno_CgAAAA4"]
[Thu Sep 17 15:12:21.865113 2026] [security2:error] [pid 971102:tid 971308] [client 82.102.18.118:45244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtecL08BTTQixEno_CwAAAEo"]
[Thu Sep 17 15:12:22.068553 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.068571 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.073195 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxXtucL08BTTQixEno_EwAAAHQ"]
[Thu Sep 17 15:12:22.073265 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/namespaced/File.php"] [unique_id "aqxXtucL08BTTQixEno_EwAAAHQ"]
[Thu Sep 17 15:12:22.084418 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/vue/.env"] [unique_id "aqxXtucL08BTTQixEno_FAAAAEI"]
[Thu Sep 17 15:12:22.090486 2026] [security2:error] [pid 971102:tid 971291] [client 52.231.79.181:1880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/admin.php"] [unique_id "aqxXtucL08BTTQixEno_FQAAADk"]
[Thu Sep 17 15:12:22.102516 2026] [security2:error] [pid 971102:tid 971303] [client 34.32.0.94:52474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/debug.php"] [unique_id "aqxXtucL08BTTQixEno_FgAAAEU"]
[Thu Sep 17 15:12:22.227863 2026] [security2:error] [pid 971102:tid 971332] [client 82.102.18.118:45250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtucL08BTTQixEno_FwAAAGI"]
[Thu Sep 17 15:12:22.311911 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/angular/.env"] [unique_id "aqxXtucL08BTTQixEno_GQAAAAA"]
[Thu Sep 17 15:12:22.357419 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:56580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxXtucL08BTTQixEno_GwAAABo"]
[Thu Sep 17 15:12:22.512749 2026] [security2:error] [pid 971102:tid 971268] [client 52.231.79.181:1868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/13.php"] [unique_id "aqxXtucL08BTTQixEno_JAAAACI"]
[Thu Sep 17 15:12:22.522006 2026] [security2:error] [pid 971102:tid 971271] [client 156.192.234.52:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXtucL08BTTQixEno_JQAAACU"]
[Thu Sep 17 15:12:22.524196 2026] [authz_core:error] [pid 971102:tid 971310] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/error_log
[Thu Sep 17 15:12:22.524273 2026] [security2:error] [pid 971102:tid 971271] [client 156.192.234.52:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXtucL08BTTQixEno_JQAAACU"]
[Thu Sep 17 15:12:22.529384 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/"] [unique_id "aqxXtucL08BTTQixEno_IwAAAEw"]
[Thu Sep 17 15:12:22.537784 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/svelte/.env"] [unique_id "aqxXtucL08BTTQixEno_JgAAAEA"]
[Thu Sep 17 15:12:22.571243 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.0.94:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxXtucL08BTTQixEno_KQAAAAs"]
[Thu Sep 17 15:12:22.583392 2026] [security2:error] [pid 971102:tid 971335] [client 82.102.18.118:45262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtucL08BTTQixEno_KgAAAGU"]
[Thu Sep 17 15:12:22.672102 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:56580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/wp-includes/sodium_compat/"] [unique_id "aqxXtucL08BTTQixEno_LQAAAGA"]
[Thu Sep 17 15:12:22.773433 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/vite/.env"] [unique_id "aqxXtucL08BTTQixEno_MwAAAHk"]
[Thu Sep 17 15:12:22.825904 2026] [core:error] [pid 971102:tid 971353] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.825930 2026] [core:error] [pid 971102:tid 971353] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:22.899229 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.117.146:41884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/php-info.php"] [unique_id "aqxXtucL08BTTQixEno_OwAAADs"]
[Thu Sep 17 15:12:22.943821 2026] [security2:error] [pid 971102:tid 971284] [client 82.102.18.118:45264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxXtucL08BTTQixEno_PAAAADI"]
[Thu Sep 17 15:12:22.946491 2026] [security2:error] [pid 971102:tid 971290] [client 52.231.79.181:1875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/222.php"] [unique_id "aqxXtucL08BTTQixEno_PQAAADg"]
[Thu Sep 17 15:12:23.000053 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/backup/.env"] [unique_id "aqxXtucL08BTTQixEno_QQAAABA"]
[Thu Sep 17 15:12:23.016743 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXtucL08BTTQixEno_NQAAAAk"]
[Thu Sep 17 15:12:23.016763 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXtucL08BTTQixEno_NQAAAAk"]
[Thu Sep 17 15:12:23.030885 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.0.94:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/test/phpinfo.php"] [unique_id "aqxXt-cL08BTTQixEno_QgAAAF8"]
[Thu Sep 17 15:12:23.121320 2026] [security2:error] [pid 971102:tid 971288] [client 185.55.149.49:54292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RAAAADY"]
[Thu Sep 17 15:12:23.121440 2026] [security2:error] [pid 971102:tid 971288] [client 185.55.149.49:54292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RAAAADY"]
[Thu Sep 17 15:12:23.158313 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:56580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxXt-cL08BTTQixEno_RQAAAHI"]
[Thu Sep 17 15:12:23.158398 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:56580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Compat.php"] [unique_id "aqxXt-cL08BTTQixEno_RQAAAHI"]
[Thu Sep 17 15:12:23.226790 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/backups/.env"] [unique_id "aqxXt-cL08BTTQixEno_RgAAAC4"]
[Thu Sep 17 15:12:23.272426 2026] [security2:error] [pid 971102:tid 971339] [client 115.244.164.14:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RwAAAGk"]
[Thu Sep 17 15:12:23.272503 2026] [security2:error] [pid 971102:tid 971339] [client 115.244.164.14:54106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXt-cL08BTTQixEno_RwAAAGk"]
[Thu Sep 17 15:12:23.290092 2026] [security2:error] [pid 971102:tid 971269] [client 82.102.18.118:45274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxXt-cL08BTTQixEno_SAAAACM"]
[Thu Sep 17 15:12:23.378580 2026] [security2:error] [pid 971102:tid 971319] [client 52.231.79.181:1876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/aa.php"] [unique_id "aqxXt-cL08BTTQixEno_TAAAAFU"]
[Thu Sep 17 15:12:23.449618 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXt-cL08BTTQixEno_TQAAACs"]
[Thu Sep 17 15:12:23.457518 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/old/.env"] [unique_id "aqxXt-cL08BTTQixEno_TgAAABc"]
[Thu Sep 17 15:12:23.484713 2026] [security2:error] [pid 971102:tid 971361] [client 34.32.0.94:52496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxXt-cL08BTTQixEno_TwAAAH8"]
[Thu Sep 17 15:12:23.615464 2026] [authz_core:error] [pid 971102:tid 971256] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/error_log
[Thu Sep 17 15:12:23.644673 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXt-cL08BTTQixEno_VQAAABY"]
[Thu Sep 17 15:12:23.653160 2026] [security2:error] [pid 971102:tid 971352] [client 82.102.18.118:45282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxXt-cL08BTTQixEno_VgAAAHY"]
[Thu Sep 17 15:12:23.686520 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/tmp/.env"] [unique_id "aqxXt-cL08BTTQixEno_WAAAAFk"]
[Thu Sep 17 15:12:23.687396 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:23.687410 2026] [core:error] [pid 971102:tid 971327] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:23.691856 2026] [security2:error] [pid 971102:tid 971248] [client 34.32.117.146:41896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpversion.php"] [unique_id "aqxXt-cL08BTTQixEno_WQAAAA4"]
[Thu Sep 17 15:12:23.786321 2026] [security2:error] [pid 971102:tid 971349] [client 47.79.206.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.npae.net"] [uri "/index.php"] [unique_id "aqxXt-cL08BTTQixEno_QwAAAHM"], referer: https://www.google.com/
[Thu Sep 17 15:12:23.792334 2026] [security2:error] [pid 971102:tid 971262] [client 52.231.79.181:1882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/abcd.php"] [unique_id "aqxXt-cL08BTTQixEno_WwAAABw"]
[Thu Sep 17 15:12:23.793420 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/wp-includes/sodium_compat/src/"] [unique_id "aqxXt-cL08BTTQixEno_XAAAAEU"]
[Thu Sep 17 15:12:23.913769 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/temp/.env"] [unique_id "aqxXt-cL08BTTQixEno_YgAAAGw"]
[Thu Sep 17 15:12:23.939163 2026] [security2:error] [pid 971102:tid 971350] [client 34.32.0.94:52510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/old/phpinfo.php"] [unique_id "aqxXt-cL08BTTQixEno_ZAAAAHQ"]
[Thu Sep 17 15:12:23.942342 2026] [security2:error] [pid 971102:tid 971276] [client 134.185.85.61:56329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thechurchinirving.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxXt-cL08BTTQixEno_ZQAAACo"]
[Thu Sep 17 15:12:24.026750 2026] [security2:error] [pid 971102:tid 971240] [client 82.102.18.118:45292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuOcL08BTTQixEno_awAAAAY"]
[Thu Sep 17 15:12:24.140540 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/lab/.env"] [unique_id "aqxXuOcL08BTTQixEno_bwAAABg"]
[Thu Sep 17 15:12:24.144336 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXt-cL08BTTQixEno_YwAAADw"]
[Thu Sep 17 15:12:24.144351 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXt-cL08BTTQixEno_YwAAADw"]
[Thu Sep 17 15:12:24.229498 2026] [security2:error] [pid 971102:tid 971299] [client 52.231.79.181:1860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/about.php"] [unique_id "aqxXuOcL08BTTQixEno_cQAAAEE"]
[Thu Sep 17 15:12:24.283173 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxXuOcL08BTTQixEno_dAAAACk"]
[Thu Sep 17 15:12:24.325891 2026] [security2:error] [pid 971102:tid 971354] [client 134.185.85.61:62792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "thechurchinirving.com"] [uri "/media/system/js/core.js"] [unique_id "aqxXuOcL08BTTQixEno_dwAAAHg"]
[Thu Sep 17 15:12:24.375747 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cronlab/.env"] [unique_id "aqxXuOcL08BTTQixEno_egAAAFM"]
[Thu Sep 17 15:12:24.380839 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.130.148:42952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "aqxXuOcL08BTTQixEno_fAAAAGs"]
[Thu Sep 17 15:12:24.396610 2026] [security2:error] [pid 971102:tid 971353] [client 82.102.18.118:45294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuOcL08BTTQixEno_fQAAAHc"]
[Thu Sep 17 15:12:24.401828 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.0.94:35860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxXuOcL08BTTQixEno_fgAAADA"]
[Thu Sep 17 15:12:24.446122 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/"] [unique_id "aqxXuOcL08BTTQixEno_fwAAACg"]
[Thu Sep 17 15:12:24.589984 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXuOcL08BTTQixEno_hwAAADs"]
[Thu Sep 17 15:12:24.605983 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cron/.env"] [unique_id "aqxXuOcL08BTTQixEno_iAAAAB8"]
[Thu Sep 17 15:12:24.613028 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.130.148:42952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "aqxXuOcL08BTTQixEno_iQAAADI"]
[Thu Sep 17 15:12:24.637270 2026] [security2:error] [pid 971102:tid 971270] [client 52.231.79.181:1878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/admin.php"] [unique_id "aqxXuOcL08BTTQixEno_igAAACQ"]
[Thu Sep 17 15:12:24.667752 2026] [security2:error] [pid 971102:tid 971356] [client 34.32.117.146:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/_phpinfo.php"] [unique_id "aqxXuOcL08BTTQixEno_iwAAAHo"]
[Thu Sep 17 15:12:24.766836 2026] [security2:error] [pid 971102:tid 971266] [client 82.102.18.118:45298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuOcL08BTTQixEno_jQAAACA"]
[Thu Sep 17 15:12:24.836151 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/en/.env"] [unique_id "aqxXuOcL08BTTQixEno_kAAAABs"]
[Thu Sep 17 15:12:24.852830 2026] [security2:error] [pid 971102:tid 971247] [client 34.32.0.94:35868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/public/phpinfo.php"] [unique_id "aqxXuOcL08BTTQixEno_lQAAAA0"]
[Thu Sep 17 15:12:24.900527 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:24.900554 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:24.918060 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXuOcL08BTTQixEno_jAAAAF4"]
[Thu Sep 17 15:12:24.918078 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXuOcL08BTTQixEno_jAAAAF4"]
[Thu Sep 17 15:12:25.053131 2026] [security2:error] [pid 971102:tid 971296] [client 52.231.79.181:1864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/adminfuns.php"] [unique_id "aqxXuecL08BTTQixEno_mAAAAD4"]
[Thu Sep 17 15:12:25.059200 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxXuecL08BTTQixEno_mQAAAFY"]
[Thu Sep 17 15:12:25.059269 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:56582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State128L.php"] [unique_id "aqxXuecL08BTTQixEno_mQAAAFY"]
[Thu Sep 17 15:12:25.082542 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/administrator/.env"] [unique_id "aqxXuecL08BTTQixEno_mgAAABU"]
[Thu Sep 17 15:12:25.123894 2026] [security2:error] [pid 971102:tid 971238] [client 82.102.18.118:45302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pbandgrace.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxXuecL08BTTQixEno_mwAAAAQ"]
[Thu Sep 17 15:12:25.310015 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/psnlink/.env"] [unique_id "aqxXuecL08BTTQixEno_nQAAAF0"]
[Thu Sep 17 15:12:25.348394 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxXuecL08BTTQixEno_oAAAAAM"]
[Thu Sep 17 15:12:25.348495 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:56594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS/State256.php"] [unique_id "aqxXuecL08BTTQixEno_oAAAAAM"]
[Thu Sep 17 15:12:25.457539 2026] [security2:error] [pid 971102:tid 971292] [client 52.231.79.181:1896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxXuecL08BTTQixEno_owAAADo"]
[Thu Sep 17 15:12:25.510032 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.0.94:35876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXuecL08BTTQixEno_ngAAABY"]
[Thu Sep 17 15:12:25.536545 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/exapi/.env"] [unique_id "aqxXuecL08BTTQixEno_pAAAAGc"]
[Thu Sep 17 15:12:25.626222 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxXuecL08BTTQixEno_rQAAAHQ"]
[Thu Sep 17 15:12:25.626319 2026] [security2:error] [pid 971102:tid 971350] [client 143.244.57.120:56602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS128L.php"] [unique_id "aqxXuecL08BTTQixEno_rQAAAHQ"]
[Thu Sep 17 15:12:25.667062 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:35876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/php-info.php"] [unique_id "aqxXuecL08BTTQixEno_rgAAACo"]
[Thu Sep 17 15:12:25.744041 2026] [security2:error] [pid 971102:tid 971357] [client 34.32.117.146:41902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXuecL08BTTQixEno_sAAAAHs"]
[Thu Sep 17 15:12:25.764250 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sitemaps/.env"] [unique_id "aqxXuecL08BTTQixEno_sQAAAH4"]
[Thu Sep 17 15:12:25.874123 2026] [security2:error] [pid 971102:tid 971281] [client 52.231.79.181:1918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/ae.php"] [unique_id "aqxXuecL08BTTQixEno_tQAAAC8"]
[Thu Sep 17 15:12:25.908042 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:25.908059 2026] [core:error] [pid 971102:tid 971258] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:25.911885 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:56616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxXuecL08BTTQixEno_twAAAGA"]
[Thu Sep 17 15:12:25.911984 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:56616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AEGIS256.php"] [unique_id "aqxXuecL08BTTQixEno_twAAAGA"]
[Thu Sep 17 15:12:26.157327 2026] [security2:error] [pid 971102:tid 971252] [client 34.32.0.94:35884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpversion.php"] [unique_id "aqxXuucL08BTTQixEno_uwAAABI"]
[Thu Sep 17 15:12:26.182523 2026] [security2:error] [pid 971102:tid 971239] [client 104.28.198.244:22831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXuucL08BTTQixEno_vQAAAAU"]
[Thu Sep 17 15:12:26.182656 2026] [security2:error] [pid 971102:tid 971239] [client 104.28.198.244:22831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxXuucL08BTTQixEno_vQAAAAU"]
[Thu Sep 17 15:12:26.184153 2026] [security2:error] [pid 971102:tid 971282] [client 172.86.81.177:50098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ravenindustries-net.geekngamer.com"] [uri "/index.php"] [unique_id "aqxXuucL08BTTQixEno_vAAAADA"]
[Thu Sep 17 15:12:26.208597 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxXuucL08BTTQixEno_vgAAADU"]
[Thu Sep 17 15:12:26.208704 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:56628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES.php"] [unique_id "aqxXuucL08BTTQixEno_vgAAADU"]
[Thu Sep 17 15:12:26.233567 2026] [security2:error] [pid 971102:tid 971259] [client 5.189.145.112:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxXuucL08BTTQixEno_vwAAABk"], referer: binance.com
[Thu Sep 17 15:12:26.277877 2026] [security2:error] [pid 971102:tid 971341] [client 52.231.79.181:1914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/akcc.php"] [unique_id "aqxXuucL08BTTQixEno_wAAAAGs"]
[Thu Sep 17 15:12:26.560563 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:56644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxXuucL08BTTQixEno_ygAAACQ"]
[Thu Sep 17 15:12:26.570670 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:41906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/server-info.php"] [unique_id "aqxXuucL08BTTQixEno_ywAAAE8"]
[Thu Sep 17 15:12:26.623590 2026] [security2:error] [pid 971102:tid 971355] [client 34.32.0.94:35898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/_phpinfo.php"] [unique_id "aqxXuucL08BTTQixEno_zQAAAHk"]
[Thu Sep 17 15:12:26.674093 2026] [security2:error] [pid 971102:tid 971359] [client 52.231.79.181:1881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/bak.php"] [unique_id "aqxXuucL08BTTQixEno_0AAAAH0"]
[Thu Sep 17 15:12:26.717492 2026] [authz_core:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/AES/error_log
[Thu Sep 17 15:12:26.718736 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/"] [unique_id "aqxXuucL08BTTQixEno_0wAAACs"]
[Thu Sep 17 15:12:26.730805 2026] [core:error] [pid 971102:tid 971257] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:26.730821 2026] [core:error] [pid 971102:tid 971257] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:26.852409 2026] [security2:error] [pid 971102:tid 971279] [client 34.31.203.120:1072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxXuucL08BTTQixEno_zAAALSs"]
[Thu Sep 17 15:12:26.867451 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:56644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXuucL08BTTQixEno_2AAAADQ"]
[Thu Sep 17 15:12:26.970878 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:54762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/logs/.env"] [unique_id "aqxXuucL08BTTQixEno_2wAAABU"]
[Thu Sep 17 15:12:27.089207 2026] [security2:error] [pid 971102:tid 971251] [client 34.32.0.94:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/old_phpinfo.php"] [unique_id "aqxXu-cL08BTTQixEno_4QAAABE"]
[Thu Sep 17 15:12:27.138969 2026] [security2:error] [pid 971102:tid 971316] [client 34.31.203.120:1072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxXuucL08BTTQixEno_2QAAUhU"]
[Thu Sep 17 15:12:27.247637 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_3QAAAAI"]
[Thu Sep 17 15:12:27.247674 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_3QAAAAI"]
[Thu Sep 17 15:12:27.387477 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxXu-cL08BTTQixEno_6wAAABw"]
[Thu Sep 17 15:12:27.387582 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:56644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Block.php"] [unique_id "aqxXu-cL08BTTQixEno_6wAAABw"]
[Thu Sep 17 15:12:27.506728 2026] [core:error] [pid 971102:tid 971240] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:27.506751 2026] [core:error] [pid 971102:tid 971240] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:27.545130 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/server-info.php"] [unique_id "aqxXu-cL08BTTQixEno_9AAAACo"]
[Thu Sep 17 15:12:27.561588 2026] [security2:error] [pid 971102:tid 971278] [client 114.198.138.124:61229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_9gAAACw"]
[Thu Sep 17 15:12:27.561691 2026] [security2:error] [pid 971102:tid 971278] [client 114.198.138.124:61229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_9gAAACw"]
[Thu Sep 17 15:12:27.590590 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.117.146:41914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/server-status.php"] [unique_id "aqxXu-cL08BTTQixEno_9wAAADk"]
[Thu Sep 17 15:12:27.653883 2026] [security2:error] [pid 971102:tid 971300] [client 173.252.95.13:36688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_7QAAAEI"]
[Thu Sep 17 15:12:27.654220 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cache/.env"] [unique_id "aqxXu-cL08BTTQixEno_-QAAAEA"]
[Thu Sep 17 15:12:27.660682 2026] [security2:error] [pid 971102:tid 971358] [client 186.105.232.15:54686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_-AAAAHw"]
[Thu Sep 17 15:12:27.660794 2026] [security2:error] [pid 971102:tid 971358] [client 186.105.232.15:54686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXu-cL08BTTQixEno_-AAAAHw"]
[Thu Sep 17 15:12:27.674075 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxXu-cL08BTTQixEno_-gAAAGo"]
[Thu Sep 17 15:12:27.674166 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:56646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/Expanded.php"] [unique_id "aqxXu-cL08BTTQixEno_-gAAAGo"]
[Thu Sep 17 15:12:27.680715 2026] [security2:error] [pid 971102:tid 971260] [client 52.231.79.181:1866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/cc.php"] [unique_id "aqxXu-cL08BTTQixEno_-wAAABo"]
[Thu Sep 17 15:12:27.758984 2026] [security2:error] [pid 971102:tid 971325] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxXu-cL08BTTQixEno_9QAAAFs"]
[Thu Sep 17 15:12:27.882022 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailer/.env"] [unique_id "aqxXu-cL08BTTQixEnpAAwAAAB0"]
[Thu Sep 17 15:12:27.956958 2026] [security2:error] [pid 971102:tid 971265] [client 159.223.126.126:48882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXu-cL08BTTQixEnpABAAAAB8"]
[Thu Sep 17 15:12:27.969519 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxXu-cL08BTTQixEnpABQAAABA"]
[Thu Sep 17 15:12:27.969647 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:56652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/AES/KeySchedule.php"] [unique_id "aqxXu-cL08BTTQixEnpABQAAABA"]
[Thu Sep 17 15:12:28.001599 2026] [security2:error] [pid 971102:tid 971341] [client 34.32.0.94:35934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/server-status.php"] [unique_id "aqxXvOcL08BTTQixEnpABgAAAGs"]
[Thu Sep 17 15:12:28.076394 2026] [security2:error] [pid 971102:tid 971290] [client 52.231.79.181:1856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/chosen.php"] [unique_id "aqxXvOcL08BTTQixEnpABwAAADg"]
[Thu Sep 17 15:12:28.114329 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mail/.env"] [unique_id "aqxXvOcL08BTTQixEnpACAAAABM"]
[Thu Sep 17 15:12:28.190614 2026] [security2:error] [pid 971102:tid 971305] [client 159.223.126.126:48886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpACQAAAEc"]
[Thu Sep 17 15:12:28.219593 2026] [security2:error] [pid 971102:tid 971275] [client 78.46.190.63:16960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpACgAAACk"], referer: https://eris.media
[Thu Sep 17 15:12:28.232492 2026] [core:error] [pid 971102:tid 971347] [client 34.166.130.148:42986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:28.232508 2026] [core:error] [pid 971102:tid 971347] [client 34.166.130.148:42986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:28.266345 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxXvOcL08BTTQixEnpADgAAAGg"]
[Thu Sep 17 15:12:28.266458 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:56668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/BLAKE2b.php"] [unique_id "aqxXvOcL08BTTQixEnpADgAAAGg"]
[Thu Sep 17 15:12:28.300590 2026] [security2:error] [pid 971102:tid 971284] [client 154.190.208.131:42160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvOcL08BTTQixEnpADwAAADI"]
[Thu Sep 17 15:12:28.312294 2026] [security2:error] [pid 971102:tid 971284] [client 154.190.208.131:42160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvOcL08BTTQixEnpADwAAADI"]
[Thu Sep 17 15:12:28.353108 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/email/.env"] [unique_id "aqxXvOcL08BTTQixEnpAEwAAAFU"]
[Thu Sep 17 15:12:28.410291 2026] [security2:error] [pid 971102:tid 971359] [client 159.223.126.126:48892] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpAFQAAAH0"]
[Thu Sep 17 15:12:28.497116 2026] [security2:error] [pid 971102:tid 971277] [client 52.231.79.181:1871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/classwithtostring.php"] [unique_id "aqxXvOcL08BTTQixEnpAGgAAACs"]
[Thu Sep 17 15:12:28.565306 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:56684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxXvOcL08BTTQixEnpAGwAAAEo"]
[Thu Sep 17 15:12:28.582985 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/smtp/.env"] [unique_id "aqxXvOcL08BTTQixEnpAHAAAAFY"]
[Thu Sep 17 15:12:28.642605 2026] [security2:error] [pid 971102:tid 971279] [client 159.223.126.126:48906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpAHQAAAC0"]
[Thu Sep 17 15:12:28.671657 2026] [security2:error] [pid 971102:tid 971293] [client 34.32.0.94:35944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpAFwAAADs"]
[Thu Sep 17 15:12:28.720141 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/"] [unique_id "aqxXvOcL08BTTQixEnpAHwAAADE"]
[Thu Sep 17 15:12:28.817355 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailing/.env"] [unique_id "aqxXvOcL08BTTQixEnpAIQAAAHI"]
[Thu Sep 17 15:12:28.850624 2026] [security2:error] [pid 971102:tid 971268] [client 159.223.126.126:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvOcL08BTTQixEnpAJAAAACI"]
[Thu Sep 17 15:12:28.871006 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:56684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXvOcL08BTTQixEnpAJgAAAAI"]
[Thu Sep 17 15:12:28.909629 2026] [security2:error] [pid 971102:tid 971327] [client 52.231.79.181:1891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-signup.php"] [unique_id "aqxXvOcL08BTTQixEnpAKQAAAF0"]
[Thu Sep 17 15:12:28.925602 2026] [security2:error] [pid 971102:tid 971313] [client 34.32.117.146:60076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpAGQAAAE8"]
[Thu Sep 17 15:12:28.970438 2026] [core:error] [pid 971102:tid 971343] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:28.970457 2026] [core:error] [pid 971102:tid 971343] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:29.014187 2026] [security2:error] [pid 971102:tid 971292] [client 34.32.0.94:35944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvOcL08BTTQixEnpAIwAAADo"]
[Thu Sep 17 15:12:29.052668 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/notifications/.env"] [unique_id "aqxXvecL08BTTQixEnpALwAAAFg"]
[Thu Sep 17 15:12:29.058648 2026] [security2:error] [pid 971102:tid 971240] [client 159.223.126.126:48916] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "tab-funkenwerk.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxXvecL08BTTQixEnpAMAAAAAY"]
[Thu Sep 17 15:12:29.163705 2026] [security2:error] [pid 971102:tid 971278] [client 34.32.0.94:35944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXvecL08BTTQixEnpAMwAAACw"]
[Thu Sep 17 15:12:29.281476 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/notify/.env"] [unique_id "aqxXvecL08BTTQixEnpAOAAAAEE"]
[Thu Sep 17 15:12:29.320098 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvecL08BTTQixEnpAMQAAAGA"]
[Thu Sep 17 15:12:29.320121 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvecL08BTTQixEnpAMQAAAGA"]
[Thu Sep 17 15:12:29.323406 2026] [security2:error] [pid 971102:tid 971300] [client 52.231.79.181:1888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/doc.php"] [unique_id "aqxXvecL08BTTQixEnpAOwAAAEI"]
[Thu Sep 17 15:12:29.463896 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:56684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxXvecL08BTTQixEnpAQAAAABI"]
[Thu Sep 17 15:12:29.463997 2026] [security2:error] [pid 971102:tid 971252] [client 143.244.57.120:56684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/Original.php"] [unique_id "aqxXvecL08BTTQixEnpAQAAAABI"]
[Thu Sep 17 15:12:29.516507 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sender/.env"] [unique_id "aqxXvecL08BTTQixEnpAQQAAACg"]
[Thu Sep 17 15:12:29.641705 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.0.94:35958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXvecL08BTTQixEnpARgAAADA"]
[Thu Sep 17 15:12:29.741213 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxXvecL08BTTQixEnpASQAAAG8"]
[Thu Sep 17 15:12:29.741316 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:56698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Base64/UrlSafe.php"] [unique_id "aqxXvecL08BTTQixEnpASQAAAG8"]
[Thu Sep 17 15:12:29.745415 2026] [security2:error] [pid 971102:tid 971344] [client 52.231.79.181:1872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/edit.php"] [unique_id "aqxXvecL08BTTQixEnpASgAAAG4"]
[Thu Sep 17 15:12:29.749379 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/campaign/.env"] [unique_id "aqxXvecL08BTTQixEnpASwAAAGI"]
[Thu Sep 17 15:12:29.751049 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:29.751061 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:29.982243 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/newsletter/.env"] [unique_id "aqxXvecL08BTTQixEnpAVAAAACA"]
[Thu Sep 17 15:12:30.020758 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxXvucL08BTTQixEnpAVQAAAFo"]
[Thu Sep 17 15:12:30.020883 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:36266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20.php"] [unique_id "aqxXvucL08BTTQixEnpAVQAAAFo"]
[Thu Sep 17 15:12:30.073656 2026] [security2:error] [pid 971102:tid 971246] [client 45.169.98.18:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvucL08BTTQixEnpAVgAAAAw"]
[Thu Sep 17 15:12:30.073784 2026] [security2:error] [pid 971102:tid 971246] [client 45.169.98.18:59099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXvucL08BTTQixEnpAVgAAAAw"]
[Thu Sep 17 15:12:30.111062 2026] [security2:error] [pid 971102:tid 971280] [client 34.32.0.94:35964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXvucL08BTTQixEnpAVwAAAC4"]
[Thu Sep 17 15:12:30.150014 2026] [security2:error] [pid 971102:tid 971261] [client 52.231.79.181:1857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/worksec.php"] [unique_id "aqxXvucL08BTTQixEnpAWgAAABs"]
[Thu Sep 17 15:12:30.159584 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.117.146:60076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxXvecL08BTTQixEnpATQAAACk"]
[Thu Sep 17 15:12:30.213649 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/ses/.env"] [unique_id "aqxXvucL08BTTQixEnpAXAAAABU"]
[Thu Sep 17 15:12:30.298907 2026] [security2:error] [pid 971102:tid 971333] [client 88.99.80.227:43570] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxXvucL08BTTQixEnpAXgAAAGM"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:12:30.314729 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxXvucL08BTTQixEnpAYQAAAHI"]
[Thu Sep 17 15:12:30.447735 2026] [security2:error] [pid 971102:tid 971265] [client 47.79.206.108:15722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxXvucL08BTTQixEnpAXQAAAB8"], referer: https://www.google.com/
[Thu Sep 17 15:12:30.449253 2026] [fcgid:warn] [pid 971102:tid 971244] (70014)End of file found: [client 66.132.224.237:33594] mod_fcgid: can't get data from http client
[Thu Sep 17 15:12:30.449280 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sendgrid/.env"] [unique_id "aqxXvucL08BTTQixEnpAZAAAAE8"]
[Thu Sep 17 15:12:30.453421 2026] [security2:error] [pid 971102:tid 971304] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "aqxXvucL08BTTQixEnpAZgAAAEY"]
[Thu Sep 17 15:12:30.476958 2026] [authz_core:error] [pid 971102:tid 971343] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/ChaCha20/error_log
[Thu Sep 17 15:12:30.479557 2026] [security2:error] [pid 971102:tid 971343] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/"] [unique_id "aqxXvucL08BTTQixEnpAZwAAAG0"]
[Thu Sep 17 15:12:30.573459 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXvucL08BTTQixEnpAaAAAAF0"]
[Thu Sep 17 15:12:30.581967 2026] [security2:error] [pid 971102:tid 971352] [client 52.231.79.181:1867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/ultra.php"] [unique_id "aqxXvucL08BTTQixEnpAaQAAAHY"]
[Thu Sep 17 15:12:30.632758 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXvucL08BTTQixEnpAagAAAC8"]
[Thu Sep 17 15:12:30.681740 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/sparkpost/.env"] [unique_id "aqxXvucL08BTTQixEnpAawAAADo"]
[Thu Sep 17 15:12:30.683433 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "aqxXvucL08BTTQixEnpAbAAAADw"]
[Thu Sep 17 15:12:30.780471 2026] [security2:error] [pid 971102:tid 971264] [client 88.99.80.227:43572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxXvucL08BTTQixEnpAbwAAAB4"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:12:30.911400 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "aqxXvucL08BTTQixEnpAdgAAABo"]
[Thu Sep 17 15:12:30.914448 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/postmark/.env"] [unique_id "aqxXvucL08BTTQixEnpAdwAAAD8"]
[Thu Sep 17 15:12:30.959576 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvucL08BTTQixEnpAcAAAAFg"]
[Thu Sep 17 15:12:30.959595 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXvucL08BTTQixEnpAcAAAAFg"]
[Thu Sep 17 15:12:30.987288 2026] [security2:error] [pid 971102:tid 971291] [client 52.231.79.181:1885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/gecko.php"] [unique_id "aqxXvucL08BTTQixEnpAeAAAADk"]
[Thu Sep 17 15:12:31.006719 2026] [security2:error] [pid 971102:tid 971256] [client 34.32.117.146:60076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxXv-cL08BTTQixEnpAeQAAABY"]
[Thu Sep 17 15:12:31.018311 2026] [security2:error] [pid 971102:tid 971358] [client 34.32.0.94:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXv-cL08BTTQixEnpAegAAAHw"]
[Thu Sep 17 15:12:31.103542 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxXv-cL08BTTQixEnpAfAAAAEI"]
[Thu Sep 17 15:12:31.103618 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/Ctx.php"] [unique_id "aqxXv-cL08BTTQixEnpAfAAAAEI"]
[Thu Sep 17 15:12:31.139775 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "aqxXv-cL08BTTQixEnpAfQAAACg"]
[Thu Sep 17 15:12:31.142184 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailgun/.env"] [unique_id "aqxXv-cL08BTTQixEnpAfgAAADU"]
[Thu Sep 17 15:12:31.281184 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.221.252:43406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXv-cL08BTTQixEnpAfwAAAGs"]
[Thu Sep 17 15:12:31.367422 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "aqxXv-cL08BTTQixEnpAhAAAADA"]
[Thu Sep 17 15:12:31.368823 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mandrill/.env"] [unique_id "aqxXv-cL08BTTQixEnpAhQAAADg"]
[Thu Sep 17 15:12:31.381135 2026] [security2:error] [pid 971102:tid 971250] [client 52.231.79.181:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/goods.php"] [unique_id "aqxXv-cL08BTTQixEnpAhgAAABA"]
[Thu Sep 17 15:12:31.381634 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXv-cL08BTTQixEnpAhwAAABM"]
[Thu Sep 17 15:12:31.381719 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/ChaCha20/IetfCtx.php"] [unique_id "aqxXv-cL08BTTQixEnpAhwAAABM"]
[Thu Sep 17 15:12:31.479565 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.0.94:35994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXv-cL08BTTQixEnpAiAAAAHg"]
[Thu Sep 17 15:12:31.595859 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mailjet/.env"] [unique_id "aqxXv-cL08BTTQixEnpAigAAAAU"]
[Thu Sep 17 15:12:31.595862 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.130.148:43004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "aqxXv-cL08BTTQixEnpAiQAAACQ"]
[Thu Sep 17 15:12:31.657794 2026] [security2:error] [pid 971102:tid 971345] [client 34.32.117.146:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxXv-cL08BTTQixEnpAjAAAAG8"]
[Thu Sep 17 15:12:31.664487 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:36290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxXv-cL08BTTQixEnpAjQAAAHs"]
[Thu Sep 17 15:12:31.664570 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:36290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519.php"] [unique_id "aqxXv-cL08BTTQixEnpAjQAAAHs"]
[Thu Sep 17 15:12:31.808915 2026] [security2:error] [pid 971102:tid 971259] [client 52.231.79.181:1859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/man.php"] [unique_id "aqxXv-cL08BTTQixEnpAkwAAABk"]
[Thu Sep 17 15:12:31.808948 2026] [authz_core:error] [pid 971102:tid 971249] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:31.822080 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/brevo/.env"] [unique_id "aqxXv-cL08BTTQixEnpAlQAAAGY"]
[Thu Sep 17 15:12:31.849895 2026] [core:error] [pid 971102:tid 971324] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:31.849909 2026] [core:error] [pid 971102:tid 971324] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:31.927123 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXv-cL08BTTQixEnpAmgAAAAE"]
[Thu Sep 17 15:12:31.948724 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:36302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxXv-cL08BTTQixEnpAmwAAACk"]
[Thu Sep 17 15:12:31.963433 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.221.252:43422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXv-cL08BTTQixEnpAnAAAAGQ"]
[Thu Sep 17 15:12:32.052072 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/transactional/.env"] [unique_id "aqxXwOcL08BTTQixEnpAnQAAADI"]
[Thu Sep 17 15:12:32.102209 2026] [authz_core:error] [pid 971102:tid 971279] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Curve25519/error_log
[Thu Sep 17 15:12:32.109199 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxXwOcL08BTTQixEnpAngAAAC0"]
[Thu Sep 17 15:12:32.233641 2026] [security2:error] [pid 971102:tid 971318] [client 52.231.79.181:1874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-settings.php"] [unique_id "aqxXwOcL08BTTQixEnpAoAAAAFQ"]
[Thu Sep 17 15:12:32.254098 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:36302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXwOcL08BTTQixEnpAogAAACI"]
[Thu Sep 17 15:12:32.286415 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/bulk/.env"] [unique_id "aqxXwOcL08BTTQixEnpApQAAACU"]
[Thu Sep 17 15:12:32.392106 2026] [security2:error] [pid 971102:tid 971323] [client 34.32.0.94:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXwOcL08BTTQixEnpAqgAAAFk"]
[Thu Sep 17 15:12:32.514429 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/aws/.env"] [unique_id "aqxXwOcL08BTTQixEnpArAAAADw"]
[Thu Sep 17 15:12:32.589876 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "aqxXwOcL08BTTQixEnpAsgAAAEo"]
[Thu Sep 17 15:12:32.618195 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwOcL08BTTQixEnpAqQAAAA4"]
[Thu Sep 17 15:12:32.618218 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwOcL08BTTQixEnpAqQAAAA4"]
[Thu Sep 17 15:12:32.629180 2026] [security2:error] [pid 971102:tid 971292] [client 52.231.79.181:1912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/k.php"] [unique_id "aqxXwOcL08BTTQixEnpAtQAAADo"]
[Thu Sep 17 15:12:32.658517 2026] [security2:error] [pid 971102:tid 971237] [client 34.32.117.146:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxXwOcL08BTTQixEnpAtgAAAAM"]
[Thu Sep 17 15:12:32.742484 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/azure/.env"] [unique_id "aqxXwOcL08BTTQixEnpAtwAAAHw"]
[Thu Sep 17 15:12:32.760797 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxXwOcL08BTTQixEnpAuAAAAFs"]
[Thu Sep 17 15:12:32.760934 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:36302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Fe.php"] [unique_id "aqxXwOcL08BTTQixEnpAuAAAAFs"]
[Thu Sep 17 15:12:32.770456 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.221.252:43434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXwOcL08BTTQixEnpAuQAAAB4"]
[Thu Sep 17 15:12:32.823211 2026] [security2:error] [pid 971102:tid 971288] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "aqxXwOcL08BTTQixEnpAvQAAADY"]
[Thu Sep 17 15:12:32.853580 2026] [security2:error] [pid 971102:tid 971291] [client 34.32.0.94:36020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php~"] [unique_id "aqxXwOcL08BTTQixEnpAvgAAADk"]
[Thu Sep 17 15:12:32.955282 2026] [security2:error] [pid 971102:tid 971250] [client 5.189.145.112:61269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxXwOcL08BTTQixEnpAwAAAABA"], referer: binance.com
[Thu Sep 17 15:12:32.970355 2026] [security2:error] [pid 971102:tid 971285] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/gcp/.env"] [unique_id "aqxXwOcL08BTTQixEnpAwQAAADM"]
[Thu Sep 17 15:12:33.026939 2026] [security2:error] [pid 971102:tid 971272] [client 52.231.79.181:1870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/autoload_classmap.php"] [unique_id "aqxXwecL08BTTQixEnpAwgAAACY"]
[Thu Sep 17 15:12:33.053205 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "aqxXwecL08BTTQixEnpAwwAAAGI"]
[Thu Sep 17 15:12:33.057988 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:36314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxXwecL08BTTQixEnpAxQAAAFM"]
[Thu Sep 17 15:12:33.075277 2026] [security2:error] [pid 971102:tid 971322] [client 156.192.234.52:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpAxgAAAFg"]
[Thu Sep 17 15:12:33.076757 2026] [security2:error] [pid 971102:tid 971322] [client 156.192.234.52:50247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpAxgAAAFg"]
[Thu Sep 17 15:12:33.095194 2026] [security2:error] [pid 971102:tid 971170] [remote 216.73.217.142:38405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxXwecL08BTTQixEnpAxAAAGkI"]
[Thu Sep 17 15:12:33.197842 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cloud/.env"] [unique_id "aqxXwecL08BTTQixEnpAxwAAAEs"]
[Thu Sep 17 15:12:33.219098 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/"] [unique_id "aqxXwecL08BTTQixEnpAyAAAAHo"]
[Thu Sep 17 15:12:33.284511 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "aqxXwecL08BTTQixEnpAyQAAADQ"]
[Thu Sep 17 15:12:33.317902 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/info.php.bak"] [unique_id "aqxXwecL08BTTQixEnpAygAAACQ"]
[Thu Sep 17 15:12:33.362048 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:36314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/wp-includes/sodium_compat/src/Core/Curve25519/"] [unique_id "aqxXwecL08BTTQixEnpAzQAAAGk"]
[Thu Sep 17 15:12:33.423241 2026] [security2:error] [pid 971102:tid 971328] [client 52.231.79.181:1879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/profile.php"] [unique_id "aqxXwecL08BTTQixEnpAzgAAAF4"]
[Thu Sep 17 15:12:33.427022 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/infrastructure/.env"] [unique_id "aqxXwecL08BTTQixEnpAzwAAACM"]
[Thu Sep 17 15:12:33.450337 2026] [security2:error] [pid 971102:tid 971289] [client 34.32.117.146:60114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxXwecL08BTTQixEnpA0QAAADc"]
[Thu Sep 17 15:12:33.514910 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "aqxXwecL08BTTQixEnpA1AAAAF8"]
[Thu Sep 17 15:12:33.655132 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/docker/.env"] [unique_id "aqxXwecL08BTTQixEnpA2AAAAFY"]
[Thu Sep 17 15:12:33.696195 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwecL08BTTQixEnpA0wAAAA0"]
[Thu Sep 17 15:12:33.696218 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXwecL08BTTQixEnpA0wAAAA0"]
[Thu Sep 17 15:12:33.713163 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.221.252:43446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/"] [unique_id "aqxXwecL08BTTQixEnpA2QAAACo"]
[Thu Sep 17 15:12:33.745919 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/core/app/.env"] [unique_id "aqxXwecL08BTTQixEnpA2gAAABU"]
[Thu Sep 17 15:12:33.759399 2026] [security2:error] [pid 971102:tid 971280] [client 185.55.149.49:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA2wAAAC4"]
[Thu Sep 17 15:12:33.759492 2026] [security2:error] [pid 971102:tid 971280] [client 185.55.149.49:54929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA2wAAAC4"]
[Thu Sep 17 15:12:33.777805 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:36038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXwecL08BTTQixEnpA3AAAADI"]
[Thu Sep 17 15:12:33.822606 2026] [security2:error] [pid 971102:tid 971302] [client 52.231.79.181:1862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/server.php"] [unique_id "aqxXwecL08BTTQixEnpA3wAAAEQ"]
[Thu Sep 17 15:12:33.824705 2026] [security2:error] [pid 971102:tid 971246] [client 115.244.164.14:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA4AAAAAw"]
[Thu Sep 17 15:12:33.824784 2026] [security2:error] [pid 971102:tid 971246] [client 115.244.164.14:54762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXwecL08BTTQixEnpA4AAAAAw"]
[Thu Sep 17 15:12:33.837081 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:36314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXwecL08BTTQixEnpA4QAAAHI"]
[Thu Sep 17 15:12:33.837153 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:36314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Cached.php"] [unique_id "aqxXwecL08BTTQixEnpA4QAAAHI"]
[Thu Sep 17 15:12:33.882538 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/k8s/.env"] [unique_id "aqxXwecL08BTTQixEnpA4gAAAB8"]
[Thu Sep 17 15:12:33.979488 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "aqxXwecL08BTTQixEnpA5wAAAG0"]
[Thu Sep 17 15:12:33.980095 2026] [security2:error] [pid 971102:tid 971321] [client 162.241.226.11:47980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mechapteriaao.org"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxXwecL08BTTQixEnpA5gAAAFc"]
[Thu Sep 17 15:12:34.111422 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/kubernetes/.env"] [unique_id "aqxXwucL08BTTQixEnpA7QAAABE"]
[Thu Sep 17 15:12:34.171265 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXwucL08BTTQixEnpA8AAAADo"]
[Thu Sep 17 15:12:34.171386 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:36316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P1p1.php"] [unique_id "aqxXwucL08BTTQixEnpA8AAAADo"]
[Thu Sep 17 15:12:34.212259 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/private/.env"] [unique_id "aqxXwucL08BTTQixEnpA8QAAAHw"]
[Thu Sep 17 15:12:34.226632 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxXwucL08BTTQixEnpA8gAAACs"]
[Thu Sep 17 15:12:34.232104 2026] [security2:error] [pid 971102:tid 971316] [client 52.231.79.181:1902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/shell.php"] [unique_id "aqxXwucL08BTTQixEnpA8wAAAFI"]
[Thu Sep 17 15:12:34.235873 2026] [security2:error] [pid 971102:tid 971294] [client 34.32.0.94:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXwucL08BTTQixEnpA9AAAADw"]
[Thu Sep 17 15:12:34.338850 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/terraform/.env"] [unique_id "aqxXwucL08BTTQixEnpA9wAAAGA"]
[Thu Sep 17 15:12:34.451905 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "aqxXwucL08BTTQixEnpA-gAAAEk"]
[Thu Sep 17 15:12:34.461460 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:36332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXwucL08BTTQixEnpA-wAAADk"]
[Thu Sep 17 15:12:34.461542 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:36332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P2.php"] [unique_id "aqxXwucL08BTTQixEnpA-wAAADk"]
[Thu Sep 17 15:12:34.565392 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/ansible/.env"] [unique_id "aqxXwucL08BTTQixEnpA_wAAAB0"]
[Thu Sep 17 15:12:34.644085 2026] [security2:error] [pid 971102:tid 971238] [client 52.231.79.181:1903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/t.php"] [unique_id "aqxXwucL08BTTQixEnpBAQAAAAQ"]
[Thu Sep 17 15:12:34.688794 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/bootstrap/.env"] [unique_id "aqxXwucL08BTTQixEnpBAwAAAHg"]
[Thu Sep 17 15:12:34.700225 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.0.94:47512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXwucL08BTTQixEnpBBAAAAFE"]
[Thu Sep 17 15:12:34.769208 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXwucL08BTTQixEnpBBgAAAG4"]
[Thu Sep 17 15:12:34.769324 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:36334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/P3.php"] [unique_id "aqxXwucL08BTTQixEnpBBgAAAG4"]
[Thu Sep 17 15:12:34.793710 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/.git/.env"] [unique_id "aqxXwucL08BTTQixEnpBBwAAACY"]
[Thu Sep 17 15:12:34.920128 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "aqxXwucL08BTTQixEnpBDAAAAAU"]
[Thu Sep 17 15:12:35.021468 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/ci/.env"] [unique_id "aqxXw-cL08BTTQixEnpBDgAAAGk"]
[Thu Sep 17 15:12:35.044220 2026] [security2:error] [pid 971102:tid 971300] [client 52.231.79.181:1906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/hello.php"] [unique_id "aqxXw-cL08BTTQixEnpBDwAAAEI"]
[Thu Sep 17 15:12:35.071469 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXw-cL08BTTQixEnpBEgAAACM"]
[Thu Sep 17 15:12:35.071569 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/Precomp.php"] [unique_id "aqxXw-cL08BTTQixEnpBEgAAACM"]
[Thu Sep 17 15:12:35.152514 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "aqxXw-cL08BTTQixEnpBFAAAAF8"]
[Thu Sep 17 15:12:35.153793 2026] [security2:error] [pid 971102:tid 971270] [client 34.32.0.94:47514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXw-cL08BTTQixEnpBFQAAACQ"]
[Thu Sep 17 15:12:35.248626 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/cd/.env"] [unique_id "aqxXw-cL08BTTQixEnpBGAAAAGQ"]
[Thu Sep 17 15:12:35.278130 2026] [security2:error] [pid 971102:tid 971336] [client 34.32.117.146:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxXw-cL08BTTQixEnpBGgAAAGY"]
[Thu Sep 17 15:12:35.387178 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "aqxXw-cL08BTTQixEnpBHgAAAHk"]
[Thu Sep 17 15:12:35.422655 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxXw-cL08BTTQixEnpBIAAAAA0"]
[Thu Sep 17 15:12:35.422773 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:36358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/H.php"] [unique_id "aqxXw-cL08BTTQixEnpBIAAAAA0"]
[Thu Sep 17 15:12:35.475158 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/jenkins/.env"] [unique_id "aqxXw-cL08BTTQixEnpBIQAAAC4"]
[Thu Sep 17 15:12:35.606279 2026] [security2:error] [pid 971102:tid 971276] [client 34.32.0.94:47528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXw-cL08BTTQixEnpBJAAAACo"]
[Thu Sep 17 15:12:35.620873 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/var/www/html/.env"] [unique_id "aqxXw-cL08BTTQixEnpBJQAAAE8"]
[Thu Sep 17 15:12:35.705142 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:36360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxXw-cL08BTTQixEnpBKQAAAFc"]
[Thu Sep 17 15:12:35.705241 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:36360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ed25519.php"] [unique_id "aqxXw-cL08BTTQixEnpBKQAAAFc"]
[Thu Sep 17 15:12:35.705927 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/gitlab/.env"] [unique_id "aqxXw-cL08BTTQixEnpBKAAAAG0"]
[Thu Sep 17 15:12:35.857869 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/current/.env"] [unique_id "aqxXw-cL08BTTQixEnpBKwAAAFQ"]
[Thu Sep 17 15:12:35.893381 2026] [security2:error] [pid 971102:tid 971266] [client 34.32.117.146:60148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxXw-cL08BTTQixEnpBLgAAACA"]
[Thu Sep 17 15:12:35.933438 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/github/.env"] [unique_id "aqxXw-cL08BTTQixEnpBLwAAAC0"]
[Thu Sep 17 15:12:35.991842 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxXw-cL08BTTQixEnpBMAAAAAs"]
[Thu Sep 17 15:12:35.991935 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:36364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HChaCha20.php"] [unique_id "aqxXw-cL08BTTQixEnpBMAAAAAs"]
[Thu Sep 17 15:12:36.054980 2026] [security2:error] [pid 971102:tid 971262] [client 34.32.0.94:47540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXxOcL08BTTQixEnpBMQAAABw"]
[Thu Sep 17 15:12:36.089733 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/release/.env"] [unique_id "aqxXxOcL08BTTQixEnpBNQAAACk"]
[Thu Sep 17 15:12:36.168277 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/actions/.env"] [unique_id "aqxXxOcL08BTTQixEnpBOAAAAEU"]
[Thu Sep 17 15:12:36.286521 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxXxOcL08BTTQixEnpBOgAAACs"]
[Thu Sep 17 15:12:36.286604 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:36376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/HSalsa20.php"] [unique_id "aqxXxOcL08BTTQixEnpBOgAAACs"]
[Thu Sep 17 15:12:36.322899 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/releases/.env"] [unique_id "aqxXxOcL08BTTQixEnpBOwAAAFI"]
[Thu Sep 17 15:12:36.401950 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/circleci/.env"] [unique_id "aqxXxOcL08BTTQixEnpBPQAAAGU"]
[Thu Sep 17 15:12:36.534520 2026] [security2:error] [pid 971102:tid 971295] [client 34.32.0.94:47544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXxOcL08BTTQixEnpBQQAAAD0"]
[Thu Sep 17 15:12:36.557015 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/shared/.env"] [unique_id "aqxXxOcL08BTTQixEnpBQgAAAB0"]
[Thu Sep 17 15:12:36.572987 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxXxOcL08BTTQixEnpBRQAAAC8"]
[Thu Sep 17 15:12:36.573085 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:36384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305.php"] [unique_id "aqxXxOcL08BTTQixEnpBRQAAAC8"]
[Thu Sep 17 15:12:36.629678 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/travis/.env"] [unique_id "aqxXxOcL08BTTQixEnpBRwAAADA"]
[Thu Sep 17 15:12:36.669418 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.117.146:60154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php.old"] [unique_id "aqxXxOcL08BTTQixEnpBSgAAAAo"]
[Thu Sep 17 15:12:36.791681 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/deploy/.env"] [unique_id "aqxXxOcL08BTTQixEnpBSwAAACw"]
[Thu Sep 17 15:12:36.860904 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:36400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxXxOcL08BTTQixEnpBTwAAAFE"]
[Thu Sep 17 15:12:36.862935 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/buildkite/.env"] [unique_id "aqxXxOcL08BTTQixEnpBUAAAAG4"]
[Thu Sep 17 15:12:37.015590 2026] [security2:error] [pid 971102:tid 971285] [client 34.32.0.94:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXxecL08BTTQixEnpBVAAAADM"]
[Thu Sep 17 15:12:37.024507 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/build/.env"] [unique_id "aqxXxecL08BTTQixEnpBVgAAAHs"]
[Thu Sep 17 15:12:37.037569 2026] [authz_core:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core/Poly1305/error_log
[Thu Sep 17 15:12:37.038958 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/"] [unique_id "aqxXxecL08BTTQixEnpBVQAAAHo"]
[Thu Sep 17 15:12:37.081435 2026] [authz_core:error] [pid 971102:tid 971338] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:37.097283 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mysql/.env"] [unique_id "aqxXxecL08BTTQixEnpBXAAAAEI"]
[Thu Sep 17 15:12:37.122429 2026] [security2:error] [pid 971102:tid 971322] [client 162.241.226.11:47982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mechapteriaao.org"] [uri "/wp-cron.php"] [unique_id "aqxXxecL08BTTQixEnpBXwAAAFg"]
[Thu Sep 17 15:12:37.183004 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:36400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXxecL08BTTQixEnpBYQAAAEE"]
[Thu Sep 17 15:12:37.259049 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/dist/.env"] [unique_id "aqxXxecL08BTTQixEnpBYgAAAGY"]
[Thu Sep 17 15:12:37.329337 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/postgres/.env"] [unique_id "aqxXxecL08BTTQixEnpBYwAAAGw"]
[Thu Sep 17 15:12:37.457624 2026] [security2:error] [pid 971102:tid 971261] [client 34.32.117.146:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php~"] [unique_id "aqxXxecL08BTTQixEnpBaAAAABs"]
[Thu Sep 17 15:12:37.486569 2026] [security2:error] [pid 971102:tid 971235] [client 34.32.0.94:47562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXxecL08BTTQixEnpBaQAAAAE"]
[Thu Sep 17 15:12:37.492345 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/public_html/.env"] [unique_id "aqxXxecL08BTTQixEnpBagAAAFY"]
[Thu Sep 17 15:12:37.550412 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXxecL08BTTQixEnpBZAAAAF4"]
[Thu Sep 17 15:12:37.550439 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXxecL08BTTQixEnpBZAAAAF4"]
[Thu Sep 17 15:12:37.557591 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/mongodb/.env"] [unique_id "aqxXxecL08BTTQixEnpBbAAAAHE"]
[Thu Sep 17 15:12:37.725006 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/htdocs/.env"] [unique_id "aqxXxecL08BTTQixEnpBcgAAACo"]
[Thu Sep 17 15:12:37.726270 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:36400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxXxecL08BTTQixEnpBcwAAADs"]
[Thu Sep 17 15:12:37.726346 2026] [security2:error] [pid 971102:tid 971293] [client 143.244.57.120:36400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Poly1305/State.php"] [unique_id "aqxXxecL08BTTQixEnpBcwAAADs"]
[Thu Sep 17 15:12:37.785367 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/redis/.env"] [unique_id "aqxXxecL08BTTQixEnpBdAAAAH0"]
[Thu Sep 17 15:12:37.945624 2026] [security2:error] [pid 971102:tid 971249] [client 34.32.0.94:47568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXxecL08BTTQixEnpBdgAAAA8"]
[Thu Sep 17 15:12:37.958932 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "aqxXxecL08BTTQixEnpBdwAAACE"]
[Thu Sep 17 15:12:38.003314 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:36402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxXxucL08BTTQixEnpBegAAACI"]
[Thu Sep 17 15:12:38.003424 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:36402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Ristretto255.php"] [unique_id "aqxXxucL08BTTQixEnpBegAAACI"]
[Thu Sep 17 15:12:38.012363 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/elasticsearch/.env"] [unique_id "aqxXxucL08BTTQixEnpBewAAAEw"]
[Thu Sep 17 15:12:38.041269 2026] [security2:error] [pid 971102:tid 971311] [client 114.198.138.124:61850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBfAAAAE0"]
[Thu Sep 17 15:12:38.041360 2026] [security2:error] [pid 971102:tid 971311] [client 114.198.138.124:61850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBfAAAAE0"]
[Thu Sep 17 15:12:38.191795 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "aqxXxucL08BTTQixEnpBfwAAAEU"]
[Thu Sep 17 15:12:38.240603 2026] [security2:error] [pid 971102:tid 971304] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/rabbitmq/.env"] [unique_id "aqxXxucL08BTTQixEnpBggAAAEY"]
[Thu Sep 17 15:12:38.285246 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:36408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxXxucL08BTTQixEnpBgwAAAAI"]
[Thu Sep 17 15:12:38.285327 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:36408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Salsa20.php"] [unique_id "aqxXxucL08BTTQixEnpBgwAAAAI"]
[Thu Sep 17 15:12:38.384613 2026] [security2:error] [pid 971102:tid 971275] [client 34.32.117.146:38348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/info.php.bak"] [unique_id "aqxXxucL08BTTQixEnpBhwAAACk"]
[Thu Sep 17 15:12:38.410073 2026] [security2:error] [pid 971102:tid 971316] [client 34.32.0.94:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXxucL08BTTQixEnpBiAAAAFI"]
[Thu Sep 17 15:12:38.421621 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/live/.env"] [unique_id "aqxXxucL08BTTQixEnpBiwAAAE4"]
[Thu Sep 17 15:12:38.468187 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/kafka/.env"] [unique_id "aqxXxucL08BTTQixEnpBjgAAABQ"]
[Thu Sep 17 15:12:38.564858 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:36418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxXxucL08BTTQixEnpBkgAAABg"]
[Thu Sep 17 15:12:38.566609 2026] [security2:error] [pid 971102:tid 971191] [remote 216.73.217.142:38405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxXxucL08BTTQixEnpBkwAANFY"]
[Thu Sep 17 15:12:38.651004 2026] [security2:error] [pid 971102:tid 971306] [client 162.241.226.11:47984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mechapteriaao.org"] [uri "/wp-cron.php"] [unique_id "aqxXxucL08BTTQixEnpBlwAAAEg"]
[Thu Sep 17 15:12:38.651300 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "aqxXxucL08BTTQixEnpBmAAAABM"]
[Thu Sep 17 15:12:38.700490 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/queue/.env"] [unique_id "aqxXxucL08BTTQixEnpBmQAAADg"]
[Thu Sep 17 15:12:38.719034 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/"] [unique_id "aqxXxucL08BTTQixEnpBmgAAAFE"]
[Thu Sep 17 15:12:38.731206 2026] [security2:error] [pid 971102:tid 971335] [client 186.105.232.15:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBmwAAAGU"]
[Thu Sep 17 15:12:38.731351 2026] [security2:error] [pid 971102:tid 971335] [client 186.105.232.15:55351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBmwAAAGU"]
[Thu Sep 17 15:12:38.841376 2026] [security2:error] [pid 971102:tid 971341] [client 154.190.208.131:41410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBngAAAGs"]
[Thu Sep 17 15:12:38.846701 2026] [security2:error] [pid 971102:tid 971341] [client 154.190.208.131:41410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxXxucL08BTTQixEnpBngAAAGs"]
[Thu Sep 17 15:12:38.858756 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:36418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/wp-includes/sodium_compat/src/Core/"] [unique_id "aqxXxucL08BTTQixEnpBnwAAABo"]
[Thu Sep 17 15:12:38.868414 2026] [security2:error] [pid 971102:tid 971344] [client 34.32.0.94:47578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxXxucL08BTTQixEnpBoAAAAG4"]
[Thu Sep 17 15:12:38.881499 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "aqxXxucL08BTTQixEnpBoQAAAHs"]
[Thu Sep 17 15:12:38.927797 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/worker/.env"] [unique_id "aqxXxucL08BTTQixEnpBpQAAAEc"]
[Thu Sep 17 15:12:39.121480 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "aqxXx-cL08BTTQixEnpBrAAAAAU"]
[Thu Sep 17 15:12:39.158057 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/job/.env"] [unique_id "aqxXx-cL08BTTQixEnpBrQAAAGY"]
[Thu Sep 17 15:12:39.224617 2026] [security2:error] [pid 971102:tid 971269] [client 34.32.117.146:38356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/phpinfo.php.save"] [unique_id "aqxXx-cL08BTTQixEnpBswAAACM"]
[Thu Sep 17 15:12:39.242384 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXx-cL08BTTQixEnpBpwAAAFo"]
[Thu Sep 17 15:12:39.242409 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXx-cL08BTTQixEnpBpwAAAFo"]
[Thu Sep 17 15:12:39.319403 2026] [security2:error] [pid 971102:tid 971342] [client 34.32.0.94:47590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxXx-cL08BTTQixEnpBtgAAAGw"]
[Thu Sep 17 15:12:39.355590 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/opt/.env"] [unique_id "aqxXx-cL08BTTQixEnpBtwAAAHE"]
[Thu Sep 17 15:12:39.387401 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/test/.env"] [unique_id "aqxXx-cL08BTTQixEnpBuQAAADI"]
[Thu Sep 17 15:12:39.422812 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:36418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxXx-cL08BTTQixEnpBugAAAEQ"]
[Thu Sep 17 15:12:39.422914 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:36418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SecretStream/State.php"] [unique_id "aqxXx-cL08BTTQixEnpBugAAAEQ"]
[Thu Sep 17 15:12:39.585498 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "aqxXx-cL08BTTQixEnpBxgAAAA8"]
[Thu Sep 17 15:12:39.614382 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/qa/.env"] [unique_id "aqxXx-cL08BTTQixEnpByAAAAFQ"]
[Thu Sep 17 15:12:39.725210 2026] [authz_core:error] [pid 971102:tid 971327] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:12:39.783471 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.0.94:47602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/core/phpinfo.php"] [unique_id "aqxXx-cL08BTTQixEnpBzgAAAE0"]
[Thu Sep 17 15:12:39.826445 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/symfony/.env"] [unique_id "aqxXx-cL08BTTQixEnpBzwAAAAM"]
[Thu Sep 17 15:12:39.841816 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/preview/.env"] [unique_id "aqxXx-cL08BTTQixEnpB0AAAAC0"]
[Thu Sep 17 15:12:39.866865 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxXx-cL08BTTQixEnpB0QAAAEY"]
[Thu Sep 17 15:12:39.866993 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:36424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/SipHash.php"] [unique_id "aqxXx-cL08BTTQixEnpB0QAAAEY"]
[Thu Sep 17 15:12:39.931170 2026] [security2:error] [pid 971102:tid 971255] [client 34.32.117.146:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxXx-cL08BTTQixEnpB0gAAABU"]
[Thu Sep 17 15:12:40.057995 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/wordpress/.env"] [unique_id "aqxXyOcL08BTTQixEnpB2wAAAFI"]
[Thu Sep 17 15:12:40.069059 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/beta/.env"] [unique_id "aqxXyOcL08BTTQixEnpB3AAAAE4"]
[Thu Sep 17 15:12:40.145151 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:36054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxXyOcL08BTTQixEnpB3gAAABQ"]
[Thu Sep 17 15:12:40.145266 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:36054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/Util.php"] [unique_id "aqxXyOcL08BTTQixEnpB3gAAABQ"]
[Thu Sep 17 15:12:40.256073 2026] [security2:error] [pid 971102:tid 971308] [client 34.32.0.94:47604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seedboxpress.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxXyOcL08BTTQixEnpB4AAAAEo"]
[Thu Sep 17 15:12:40.297241 2026] [security2:error] [pid 971102:tid 971281] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "aqxXyOcL08BTTQixEnpB4gAAAC8"]
[Thu Sep 17 15:12:40.297241 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/uat/.env"] [unique_id "aqxXyOcL08BTTQixEnpB4QAAADA"]
[Thu Sep 17 15:12:40.424622 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxXyOcL08BTTQixEnpB5AAAABM"]
[Thu Sep 17 15:12:40.424760 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/X25519.php"] [unique_id "aqxXyOcL08BTTQixEnpB5AAAABM"]
[Thu Sep 17 15:12:40.527596 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/stage/.env"] [unique_id "aqxXyOcL08BTTQixEnpB6AAAACY"]
[Thu Sep 17 15:12:40.533445 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cms/.env"] [unique_id "aqxXyOcL08BTTQixEnpB6QAAAGI"]
[Thu Sep 17 15:12:40.554806 2026] [security2:error] [pid 971102:tid 971325] [client 45.169.98.18:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXyOcL08BTTQixEnpB6gAAAFs"]
[Thu Sep 17 15:12:40.554948 2026] [security2:error] [pid 971102:tid 971325] [client 45.169.98.18:59659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxXyOcL08BTTQixEnpB6gAAAFs"]
[Thu Sep 17 15:12:40.683963 2026] [security2:error] [pid 971102:tid 971315] [client 34.32.117.146:38366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxXyOcL08BTTQixEnpB7AAAAFE"]
[Thu Sep 17 15:12:40.702850 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:36074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxXyOcL08BTTQixEnpB7gAAAGg"]
[Thu Sep 17 15:12:40.702927 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:36074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XChaCha20.php"] [unique_id "aqxXyOcL08BTTQixEnpB7gAAAGg"]
[Thu Sep 17 15:12:40.721723 2026] [security2:error] [pid 971102:tid 971287] [client 5.189.145.112:64170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxXyOcL08BTTQixEnpB8gAAADU"], referer: binance.com
[Thu Sep 17 15:12:40.743973 2026] [access_compat:error] [pid 971102:tid 971339] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/jixo-5-mask-parade-collectors-edition
[Thu Sep 17 15:12:40.754794 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/development/.env"] [unique_id "aqxXyOcL08BTTQixEnpB9QAAAFM"]
[Thu Sep 17 15:12:40.767510 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/drupal/.env"] [unique_id "aqxXyOcL08BTTQixEnpB9gAAACQ"]
[Thu Sep 17 15:12:40.935397 2026] [security2:error] [pid 971102:tid 971260] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyOcL08BTTQixEnpB8QAAABo"]
[Thu Sep 17 15:12:40.981168 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxXyOcL08BTTQixEnpB-gAAABc"]
[Thu Sep 17 15:12:40.981280 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core/XSalsa20.php"] [unique_id "aqxXyOcL08BTTQixEnpB-gAAABc"]
[Thu Sep 17 15:12:40.982413 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/production/.env"] [unique_id "aqxXyOcL08BTTQixEnpB-wAAAFo"]
[Thu Sep 17 15:12:41.000903 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/joomla/.env"] [unique_id "aqxXyOcL08BTTQixEnpB_QAAABs"]
[Thu Sep 17 15:12:41.210249 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.194.17:55576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/___proxy_subdomain_cpcalendars/config/app/.env"] [unique_id "aqxXyecL08BTTQixEnpCAgAAAHE"]
[Thu Sep 17 15:12:41.231510 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/magento/.env"] [unique_id "aqxXyecL08BTTQixEnpCBAAAAHU"]
[Thu Sep 17 15:12:41.262844 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:36100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXyecL08BTTQixEnpCBwAAAB8"]
[Thu Sep 17 15:12:41.321441 2026] [security2:error] [pid 971102:tid 971349] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpB_wAAAHM"]
[Thu Sep 17 15:12:41.422186 2026] [authz_core:error] [pid 971102:tid 971299] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/error_log
[Thu Sep 17 15:12:41.436441 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.194.17:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php"] [unique_id "aqxXyecL08BTTQixEnpCCwAAAA8"]
[Thu Sep 17 15:12:41.445869 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXyecL08BTTQixEnpCCgAAAEE"]
[Thu Sep 17 15:12:41.464537 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.117.146:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxXyecL08BTTQixEnpCDQAAADI"]
[Thu Sep 17 15:12:41.464537 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/shopify/.env"] [unique_id "aqxXyecL08BTTQixEnpCDAAAACE"]
[Thu Sep 17 15:12:41.586044 2026] [autoindex:error] [pid 971102:tid 971276] [client 104.252.111.195:34234] AH01276: Cannot serve directory /home4/wisdomel/public_html/enchantedpapers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:12:41.598887 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:36100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/wp-includes/sodium_compat/src/"] [unique_id "aqxXyecL08BTTQixEnpCFgAAAA0"]
[Thu Sep 17 15:12:41.640056 2026] [security2:error] [pid 971102:tid 971126] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxXyecL08BTTQixEnpCFwAADhY"]
[Thu Sep 17 15:12:41.679858 2026] [security2:error] [pid 971102:tid 971310] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCDgAAAEw"]
[Thu Sep 17 15:12:41.697743 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/prestashop/.env"] [unique_id "aqxXyecL08BTTQixEnpCGAAAAHY"]
[Thu Sep 17 15:12:41.931538 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/codeigniter/.env"] [unique_id "aqxXyecL08BTTQixEnpCHQAAAGM"]
[Thu Sep 17 15:12:41.951150 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCGgAAAE0"]
[Thu Sep 17 15:12:41.951177 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCGgAAAE0"]
[Thu Sep 17 15:12:42.048813 2026] [security2:error] [pid 971102:tid 971304] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCGwAAAEY"]
[Thu Sep 17 15:12:42.097231 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:36100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxXyucL08BTTQixEnpCIgAAAGo"]
[Thu Sep 17 15:12:42.097354 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:36100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/BLAKE2b.php"] [unique_id "aqxXyucL08BTTQixEnpCIgAAAGo"]
[Thu Sep 17 15:12:42.103416 2026] [security2:error] [pid 971102:tid 971277] [client 34.32.117.146:38374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxXyucL08BTTQixEnpCIwAAACs"]
[Thu Sep 17 15:12:42.119395 2026] [security2:error] [pid 971102:tid 971246] [client 34.166.194.17:38190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/info.php"] [unique_id "aqxXyucL08BTTQixEnpCJAAAAAw"]
[Thu Sep 17 15:12:42.162361 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cakephp/.env"] [unique_id "aqxXyucL08BTTQixEnpCJwAAADk"]
[Thu Sep 17 15:12:42.385902 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxXyucL08BTTQixEnpCKwAAABM"]
[Thu Sep 17 15:12:42.386029 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:36114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20.php"] [unique_id "aqxXyucL08BTTQixEnpCKwAAABM"]
[Thu Sep 17 15:12:42.402987 2026] [security2:error] [pid 971102:tid 971271] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyucL08BTTQixEnpCKQAAACU"]
[Thu Sep 17 15:12:42.406169 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/zend/.env"] [unique_id "aqxXyucL08BTTQixEnpCLAAAACw"]
[Thu Sep 17 15:12:42.639231 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/yii/.env"] [unique_id "aqxXyucL08BTTQixEnpCMwAAADU"]
[Thu Sep 17 15:12:42.694118 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:36118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxXyucL08BTTQixEnpCNwAAACc"]
[Thu Sep 17 15:12:42.775799 2026] [security2:error] [pid 971102:tid 971244] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyucL08BTTQixEnpCMQAAAAo"]
[Thu Sep 17 15:12:42.820252 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.194.17:38200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/php.php"] [unique_id "aqxXyucL08BTTQixEnpCOQAAAHo"]
[Thu Sep 17 15:12:42.854930 2026] [authz_core:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/ChaCha20/error_log
[Thu Sep 17 15:12:42.856998 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/"] [unique_id "aqxXyucL08BTTQixEnpCOgAAACQ"]
[Thu Sep 17 15:12:42.872994 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/laravel5/.env"] [unique_id "aqxXyucL08BTTQixEnpCOwAAAAU"]
[Thu Sep 17 15:12:42.975907 2026] [security2:error] [pid 971102:tid 971329] [client 34.32.117.146:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxXyucL08BTTQixEnpCQAAAAF8"]
[Thu Sep 17 15:12:43.005156 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:36118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXy-cL08BTTQixEnpCQgAAAFo"]
[Thu Sep 17 15:12:43.106921 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "aqxXy-cL08BTTQixEnpCQwAAAEA"]
[Thu Sep 17 15:12:43.123875 2026] [security2:error] [pid 971102:tid 971322] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXyucL08BTTQixEnpCPAAAAFg"]
[Thu Sep 17 15:12:43.318025 2026] [authz_core:error] [pid 971102:tid 971345] [client 20.244.34.24:50174] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:43.341309 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "aqxXy-cL08BTTQixEnpCSwAAAB8"]
[Thu Sep 17 15:12:43.374483 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCRgAAAEI"]
[Thu Sep 17 15:12:43.374507 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCRgAAAEI"]
[Thu Sep 17 15:12:43.482537 2026] [security2:error] [pid 971102:tid 971351] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCSQAAAHU"]
[Thu Sep 17 15:12:43.513363 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.194.17:38212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/i.php"] [unique_id "aqxXy-cL08BTTQixEnpCUAAAAGw"]
[Thu Sep 17 15:12:43.521592 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxXy-cL08BTTQixEnpCUQAAAA8"]
[Thu Sep 17 15:12:43.521722 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:36118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/Ctx.php"] [unique_id "aqxXy-cL08BTTQixEnpCUQAAAA8"]
[Thu Sep 17 15:12:43.578019 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/v3/.env"] [unique_id "aqxXy-cL08BTTQixEnpCUwAAADI"]
[Thu Sep 17 15:12:43.670084 2026] [authz_core:error] [pid 971102:tid 971242] [client 4.240.114.86:0] AH01630: client denied by server configuration: /home2/reedartg/public_html/reedcustomprinting/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:12:43.704140 2026] [security2:error] [pid 971102:tid 971319] [client 34.32.117.146:38388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/www/phpinfo.php"] [unique_id "aqxXy-cL08BTTQixEnpCWwAAAFU"]
[Thu Sep 17 15:12:43.704476 2026] [security2:error] [pid 971102:tid 971302] [client 156.192.234.52:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXy-cL08BTTQixEnpCWgAAAEQ"]
[Thu Sep 17 15:12:43.704619 2026] [security2:error] [pid 971102:tid 971302] [client 156.192.234.52:50856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxXy-cL08BTTQixEnpCWgAAAEQ"]
[Thu Sep 17 15:12:43.813782 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:36132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxXy-cL08BTTQixEnpCXwAAAE0"]
[Thu Sep 17 15:12:43.813808 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/v1/.env"] [unique_id "aqxXy-cL08BTTQixEnpCXgAAAGM"]
[Thu Sep 17 15:12:43.813876 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:36132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/ChaCha20/IetfCtx.php"] [unique_id "aqxXy-cL08BTTQixEnpCXwAAAE0"]
[Thu Sep 17 15:12:43.830323 2026] [security2:error] [pid 971102:tid 971259] [client 40.77.167.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wheresmymap.com"] [uri "/index.php"] [unique_id "aqxXyecL08BTTQixEnpCEwAAABk"]
[Thu Sep 17 15:12:43.874961 2026] [security2:error] [pid 971102:tid 971327] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXy-cL08BTTQixEnpCVwAAAF0"]
[Thu Sep 17 15:12:44.055893 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/v2/.env"] [unique_id "aqxXzOcL08BTTQixEnpCZQAAAAA"]
[Thu Sep 17 15:12:44.103278 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:36140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxXzOcL08BTTQixEnpCZgAAAH0"]
[Thu Sep 17 15:12:44.103391 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:36140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519.php"] [unique_id "aqxXzOcL08BTTQixEnpCZgAAAH0"]
[Thu Sep 17 15:12:44.209796 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:38214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/pi.php"] [unique_id "aqxXzOcL08BTTQixEnpCbAAAAEM"]
[Thu Sep 17 15:12:44.265626 2026] [security2:error] [pid 971102:tid 971268] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpCZAAAACI"]
[Thu Sep 17 15:12:44.288776 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/rest/.env"] [unique_id "aqxXzOcL08BTTQixEnpCcAAAAFs"]
[Thu Sep 17 15:12:44.362252 2026] [security2:error] [pid 971102:tid 971361] [client 115.244.164.14:55416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCdQAAAH8"]
[Thu Sep 17 15:12:44.362421 2026] [security2:error] [pid 971102:tid 971361] [client 115.244.164.14:55416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCdQAAAH8"]
[Thu Sep 17 15:12:44.385818 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxXzOcL08BTTQixEnpCdgAAAG4"]
[Thu Sep 17 15:12:44.432292 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:55570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCeQAAAAk"]
[Thu Sep 17 15:12:44.433882 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:55570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxXzOcL08BTTQixEnpCeQAAAAk"]
[Thu Sep 17 15:12:44.521222 2026] [security2:error] [pid 971102:tid 971289] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/graphql/.env"] [unique_id "aqxXzOcL08BTTQixEnpCfQAAADc"]
[Thu Sep 17 15:12:44.545415 2026] [authz_core:error] [pid 971102:tid 971290] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Curve25519/error_log
[Thu Sep 17 15:12:44.554962 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxXzOcL08BTTQixEnpCfgAAADg"]
[Thu Sep 17 15:12:44.641960 2026] [security2:error] [pid 971102:tid 971295] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpCdwAAAD0"]
[Thu Sep 17 15:12:44.693344 2026] [security2:error] [pid 971102:tid 971354] [client 34.32.117.146:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxXzOcL08BTTQixEnpCgAAAAHg"]
[Thu Sep 17 15:12:44.695494 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxXzOcL08BTTQixEnpCgQAAAF8"]
[Thu Sep 17 15:12:44.754986 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/gateway/.env"] [unique_id "aqxXzOcL08BTTQixEnpCggAAAFo"]
[Thu Sep 17 15:12:44.768260 2026] [fcgid:warn] [pid 971102:tid 971261] (70014)End of file found: [client 66.132.224.237:29952] mod_fcgid: can't get data from http client
[Thu Sep 17 15:12:44.908545 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.194.17:38222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/pinfo.php"] [unique_id "aqxXzOcL08BTTQixEnpChgAAAHA"]
[Thu Sep 17 15:12:44.986524 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/microservice/.env"] [unique_id "aqxXzOcL08BTTQixEnpCigAAABA"]
[Thu Sep 17 15:12:45.056416 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpChQAAAFg"]
[Thu Sep 17 15:12:45.056438 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpChQAAAFg"]
[Thu Sep 17 15:12:45.083422 2026] [security2:error] [pid 971102:tid 971298] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzOcL08BTTQixEnpChAAAAEA"]
[Thu Sep 17 15:12:45.193948 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxXzecL08BTTQixEnpCjgAAAHU"]
[Thu Sep 17 15:12:45.194101 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Fe.php"] [unique_id "aqxXzecL08BTTQixEnpCjgAAAHU"]
[Thu Sep 17 15:12:45.216916 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/service/.env"] [unique_id "aqxXzecL08BTTQixEnpCjwAAAGw"]
[Thu Sep 17 15:12:45.448676 2026] [security2:error] [pid 971102:tid 971314] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/v3/.env"] [unique_id "aqxXzecL08BTTQixEnpClQAAAFA"]
[Thu Sep 17 15:12:45.455420 2026] [security2:error] [pid 971102:tid 971284] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCkAAAADI"]
[Thu Sep 17 15:12:45.478739 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:36152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxXzecL08BTTQixEnpClgAAABE"]
[Thu Sep 17 15:12:45.604433 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.194.17:38236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/test.php"] [unique_id "aqxXzecL08BTTQixEnpClwAAAHY"]
[Thu Sep 17 15:12:45.639005 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "aqxXzecL08BTTQixEnpCmgAAABw"]
[Thu Sep 17 15:12:45.680321 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/dev/.env"] [unique_id "aqxXzecL08BTTQixEnpCngAAAHM"]
[Thu Sep 17 15:12:45.781852 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:36152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/wp-includes/sodium_compat/src/Core32/Curve25519/"] [unique_id "aqxXzecL08BTTQixEnpCnwAAABU"]
[Thu Sep 17 15:12:45.819037 2026] [security2:error] [pid 971102:tid 971241] [client 34.32.0.94:47618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCmAAAAAc"]
[Thu Sep 17 15:12:45.855038 2026] [security2:error] [pid 971102:tid 971245] [client 34.32.117.146:38402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxXzecL08BTTQixEnpCoQAAAAs"]
[Thu Sep 17 15:12:45.912677 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/api/staging/.env"] [unique_id "aqxXzecL08BTTQixEnpCowAAAF0"]
[Thu Sep 17 15:12:46.143536 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "aqxXzucL08BTTQixEnpCrAAAADA"]
[Thu Sep 17 15:12:46.194917 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCpAAAACs"]
[Thu Sep 17 15:12:46.194943 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxXzecL08BTTQixEnpCpAAAACs"]
[Thu Sep 17 15:12:46.376373 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/lib/.env"] [unique_id "aqxXzucL08BTTQixEnpCtAAAACU"]
[Thu Sep 17 15:12:46.429832 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:36152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxXzucL08BTTQixEnpCtQAAADM"]
[Thu Sep 17 15:12:46.430006 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:36152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Cached.php"] [unique_id "aqxXzucL08BTTQixEnpCtQAAADM"]
[Thu Sep 17 15:12:46.580513 2026] [autoindex:error] [pid 971102:tid 971156] [remote 93.152.209.11:24946] AH01276: Cannot serve directory /home1/ggwqjxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:12:46.612989 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/resources/.env"] [unique_id "aqxXzucL08BTTQixEnpCuwAAACg"]
[Thu Sep 17 15:12:46.717165 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:36166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxXzucL08BTTQixEnpCvQAAADg"]
[Thu Sep 17 15:12:46.717290 2026] [security2:error] [pid 971102:tid 971290] [client 143.244.57.120:36166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P1p1.php"] [unique_id "aqxXzucL08BTTQixEnpCvQAAADg"]
[Thu Sep 17 15:12:46.780666 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.194.17:38248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/p.php"] [unique_id "aqxXzucL08BTTQixEnpCvwAAAAU"]
[Thu Sep 17 15:12:46.840054 2026] [security2:error] [pid 971102:tid 971289] [client 34.32.117.146:38416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/site/phpinfo.php"] [unique_id "aqxXzucL08BTTQixEnpCwAAAADc"]
[Thu Sep 17 15:12:46.844172 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/assets/.env"] [unique_id "aqxXzucL08BTTQixEnpCwQAAAFw"]
[Thu Sep 17 15:12:47.000345 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxXzucL08BTTQixEnpCxQAAABc"]
[Thu Sep 17 15:12:47.000456 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:36174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P2.php"] [unique_id "aqxXzucL08BTTQixEnpCxQAAABc"]
[Thu Sep 17 15:12:47.073111 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/uploads/.env"] [unique_id "aqxXz-cL08BTTQixEnpCxwAAAEA"]
[Thu Sep 17 15:12:47.278655 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxXz-cL08BTTQixEnpCzgAAACM"]
[Thu Sep 17 15:12:47.278777 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:36188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/P3.php"] [unique_id "aqxXz-cL08BTTQixEnpCzgAAACM"]
[Thu Sep 17 15:12:47.304965 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/internal/.env"] [unique_id "aqxXz-cL08BTTQixEnpC0AAAAFY"]
[Thu Sep 17 15:12:47.460709 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.194.17:41712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/debug.php"] [unique_id "aqxXz-cL08BTTQixEnpC1QAAAA8"]
[Thu Sep 17 15:12:47.525772 2026] [security2:error] [pid 971102:tid 971286] [client 34.32.117.146:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxXz-cL08BTTQixEnpC2AAAADQ"]
[Thu Sep 17 15:12:47.542171 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/tools/.env"] [unique_id "aqxXz-cL08BTTQixEnpC3gAAAAg"]
[Thu Sep 17 15:12:47.773458 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:36194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxXz-cL08BTTQixEnpC7AAAAAc"]
[Thu Sep 17 15:12:47.773567 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:36194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/Precomp.php"] [unique_id "aqxXz-cL08BTTQixEnpC7AAAAAc"]
[Thu Sep 17 15:12:47.775314 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/scripts/.env"] [unique_id "aqxXz-cL08BTTQixEnpC7QAAAFc"]
[Thu Sep 17 15:12:47.794838 2026] [security2:error] [pid 971102:tid 971248] [client 5.189.145.112:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxXz-cL08BTTQixEnpC7gAAAA4"], referer: binance.com
[Thu Sep 17 15:12:48.008608 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/bin/.env"] [unique_id "aqxX0OcL08BTTQixEnpC9gAAAG0"]
[Thu Sep 17 15:12:48.014751 2026] [security2:error] [pid 971102:tid 971316] [client 4.240.114.86:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX0OcL08BTTQixEnpC-AAAAFI"], referer: binance.com
[Thu Sep 17 15:12:48.079699 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:36198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxX0OcL08BTTQixEnpC_AAAADY"]
[Thu Sep 17 15:12:48.079830 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:36198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/H.php"] [unique_id "aqxX0OcL08BTTQixEnpC_AAAADY"]
[Thu Sep 17 15:12:48.175415 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.194.17:41720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxX0OcL08BTTQixEnpDAAAAABg"]
[Thu Sep 17 15:12:48.246622 2026] [security2:error] [pid 971102:tid 971281] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sbin/.env"] [unique_id "aqxX0OcL08BTTQixEnpDAgAAAC8"]
[Thu Sep 17 15:12:48.321775 2026] [security2:error] [pid 971102:tid 971282] [client 34.32.117.146:59692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxX0OcL08BTTQixEnpDAwAAADA"]
[Thu Sep 17 15:12:48.368839 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:36200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxX0OcL08BTTQixEnpDCAAAAEc"]
[Thu Sep 17 15:12:48.368951 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:36200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Ed25519.php"] [unique_id "aqxX0OcL08BTTQixEnpDCAAAAEc"]
[Thu Sep 17 15:12:48.390083 2026] [security2:error] [pid 971102:tid 971291] [client 208.109.3.10:20164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxX0OcL08BTTQixEnpC9wAAADk"]
[Thu Sep 17 15:12:48.480040 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "aqxX0OcL08BTTQixEnpDDAAAAGI"]
[Thu Sep 17 15:12:48.526264 2026] [security2:error] [pid 971102:tid 971317] [client 40.77.167.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wheresmymap.com"] [uri "/index.php"] [unique_id "aqxX0OcL08BTTQixEnpDCQAAAFM"]
[Thu Sep 17 15:12:48.658173 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:36202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxX0OcL08BTTQixEnpDGwAAAGU"]
[Thu Sep 17 15:12:48.658273 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:36202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HChaCha20.php"] [unique_id "aqxX0OcL08BTTQixEnpDGwAAAGU"]
[Thu Sep 17 15:12:48.696715 2026] [security2:error] [pid 971102:tid 971243] [client 114.198.138.124:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0OcL08BTTQixEnpDHAAAAAk"]
[Thu Sep 17 15:12:48.696809 2026] [security2:error] [pid 971102:tid 971243] [client 114.198.138.124:56717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0OcL08BTTQixEnpDHAAAAAk"]
[Thu Sep 17 15:12:48.713560 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "aqxX0OcL08BTTQixEnpDHQAAAD0"]
[Thu Sep 17 15:12:48.864954 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.194.17:41736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/test/phpinfo.php"] [unique_id "aqxX0OcL08BTTQixEnpDIQAAAAU"]
[Thu Sep 17 15:12:48.950221 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/dashboard/.env"] [unique_id "aqxX0OcL08BTTQixEnpDJAAAAF4"]
[Thu Sep 17 15:12:48.970406 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:36204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxX0OcL08BTTQixEnpDJwAAABs"]
[Thu Sep 17 15:12:48.970505 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:36204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/HSalsa20.php"] [unique_id "aqxX0OcL08BTTQixEnpDJwAAABs"]
[Thu Sep 17 15:12:49.070548 2026] [access_compat:error] [pid 971102:tid 971309] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/category
[Thu Sep 17 15:12:49.184057 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/panel/.env"] [unique_id "aqxX0ecL08BTTQixEnpDMQAAAHY"]
[Thu Sep 17 15:12:49.256253 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:36210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxX0ecL08BTTQixEnpDMwAAACk"]
[Thu Sep 17 15:12:49.256361 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:36210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int32.php"] [unique_id "aqxX0ecL08BTTQixEnpDMwAAACk"]
[Thu Sep 17 15:12:49.349849 2026] [security2:error] [pid 971102:tid 971280] [client 104.28.198.244:22819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDNwAAAC4"]
[Thu Sep 17 15:12:49.349995 2026] [security2:error] [pid 971102:tid 971280] [client 104.28.198.244:22819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDNwAAAC4"]
[Thu Sep 17 15:12:49.365081 2026] [security2:error] [pid 971102:tid 971340] [client 154.190.208.131:42012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDOAAAAGo"]
[Thu Sep 17 15:12:49.365235 2026] [security2:error] [pid 971102:tid 971340] [client 154.190.208.131:42012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDOAAAAGo"]
[Thu Sep 17 15:12:49.416641 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "aqxX0ecL08BTTQixEnpDOwAAAAs"]
[Thu Sep 17 15:12:49.563285 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.194.17:41744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxX0ecL08BTTQixEnpDQgAAAAY"]
[Thu Sep 17 15:12:49.567445 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxX0ecL08BTTQixEnpDQwAAADw"]
[Thu Sep 17 15:12:49.567532 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:36216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Int64.php"] [unique_id "aqxX0ecL08BTTQixEnpDQwAAADw"]
[Thu Sep 17 15:12:49.646423 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/erp/.env"] [unique_id "aqxX0ecL08BTTQixEnpDRQAAAEo"]
[Thu Sep 17 15:12:49.723805 2026] [security2:error] [pid 971102:tid 971303] [client 186.105.232.15:56005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDSwAAAEU"]
[Thu Sep 17 15:12:49.723928 2026] [security2:error] [pid 971102:tid 971303] [client 186.105.232.15:56005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0ecL08BTTQixEnpDSwAAAEU"]
[Thu Sep 17 15:12:49.867511 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:60350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxX0ecL08BTTQixEnpDTwAAAF0"]
[Thu Sep 17 15:12:49.867632 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:60350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305.php"] [unique_id "aqxX0ecL08BTTQixEnpDTwAAAF0"]
[Thu Sep 17 15:12:49.878097 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/shop/.env"] [unique_id "aqxX0ecL08BTTQixEnpDUAAAACU"]
[Thu Sep 17 15:12:50.113319 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.130.148:43016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/store/.env"] [unique_id "aqxX0ucL08BTTQixEnpDVgAAAFM"]
[Thu Sep 17 15:12:50.164943 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:60354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxX0ucL08BTTQixEnpDWgAAACQ"]
[Thu Sep 17 15:12:50.259383 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.194.17:41756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/old/phpinfo.php"] [unique_id "aqxX0ucL08BTTQixEnpDXAAAAHw"]
[Thu Sep 17 15:12:50.323598 2026] [security2:error] [pid 971102:tid 971242] [client 34.32.117.146:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxX0ecL08BTTQixEnpDNAAAAAg"]
[Thu Sep 17 15:12:50.350817 2026] [authz_core:error] [pid 971102:tid 971278] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/sodium_compat/src/Core32/Poly1305/error_log
[Thu Sep 17 15:12:50.352773 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/"] [unique_id "aqxX0ucL08BTTQixEnpDXgAAACw"]
[Thu Sep 17 15:12:50.494535 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:60354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxX0ucL08BTTQixEnpDYgAAAFw"]
[Thu Sep 17 15:12:50.808226 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/saas/.env"] [unique_id "aqxX0ucL08BTTQixEnpDbwAAABo"]
[Thu Sep 17 15:12:50.838563 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX0ucL08BTTQixEnpDZQAAAF8"]
[Thu Sep 17 15:12:50.838588 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX0ucL08BTTQixEnpDZQAAAF8"]
[Thu Sep 17 15:12:50.942993 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.194.17:41770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxX0ucL08BTTQixEnpDdAAAAEA"]
[Thu Sep 17 15:12:50.986637 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxX0ucL08BTTQixEnpDeAAAAHU"]
[Thu Sep 17 15:12:50.986762 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Poly1305/State.php"] [unique_id "aqxX0ucL08BTTQixEnpDeAAAAHU"]
[Thu Sep 17 15:12:51.015484 2026] [security2:error] [pid 971102:tid 971309] [client 45.169.98.18:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0-cL08BTTQixEnpDewAAAEs"]
[Thu Sep 17 15:12:51.015608 2026] [security2:error] [pid 971102:tid 971309] [client 45.169.98.18:60212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX0-cL08BTTQixEnpDewAAAEs"]
[Thu Sep 17 15:12:51.039240 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/client/.env"] [unique_id "aqxX0-cL08BTTQixEnpDfAAAAC4"]
[Thu Sep 17 15:12:51.047973 2026] [security2:error] [pid 971102:tid 971320] [client 34.32.117.146:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/core/phpinfo.php"] [unique_id "aqxX0-cL08BTTQixEnpDfQAAAFY"]
[Thu Sep 17 15:12:51.193752 2026] [security2:error] [pid 971102:tid 971343] [client 157.230.170.38:58733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "iradtech.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX0-cL08BTTQixEnpDhAAAAG0"]
[Thu Sep 17 15:12:51.236711 2026] [security2:error] [pid 971102:tid 971288] [client 157.230.170.38:58735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "iradtech.com"] [uri "/"] [unique_id "aqxX0-cL08BTTQixEnpDhQAAADY"]
[Thu Sep 17 15:12:51.263574 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxX0-cL08BTTQixEnpDhwAAABM"]
[Thu Sep 17 15:12:51.263690 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:60370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Salsa20.php"] [unique_id "aqxX0-cL08BTTQixEnpDhwAAABM"]
[Thu Sep 17 15:12:51.270278 2026] [security2:error] [pid 971102:tid 971235] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/project/.env"] [unique_id "aqxX0-cL08BTTQixEnpDiAAAAAE"]
[Thu Sep 17 15:12:51.288632 2026] [security2:error] [pid 971102:tid 971308] [client 157.230.170.38:58739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "iradtech.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX0-cL08BTTQixEnpDigAAAEo"]
[Thu Sep 17 15:12:51.500246 2026] [security2:error] [pid 971102:tid 971248] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/admin-panel/.env"] [unique_id "aqxX0-cL08BTTQixEnpDkAAAAA4"]
[Thu Sep 17 15:12:51.643363 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:41772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/public/phpinfo.php"] [unique_id "aqxX0-cL08BTTQixEnpDlAAAAH0"]
[Thu Sep 17 15:12:51.669125 2026] [security2:error] [pid 971102:tid 971302] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX0-cL08BTTQixEnpDiwAARG0"], referer: http://www.makingreligionhealthy.com/old/
[Thu Sep 17 15:12:51.676305 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:60378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxX0-cL08BTTQixEnpDmQAAAH8"]
[Thu Sep 17 15:12:51.731410 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/control-panel/.env"] [unique_id "aqxX0-cL08BTTQixEnpDnAAAAGg"]
[Thu Sep 17 15:12:51.833620 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/"] [unique_id "aqxX0-cL08BTTQixEnpDngAAAFM"]
[Thu Sep 17 15:12:51.885705 2026] [security2:error] [pid 971102:tid 971311] [client 34.32.117.146:59720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.117.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makingreligionhealthy.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxX0-cL08BTTQixEnpDoQAAAE0"]
[Thu Sep 17 15:12:51.964679 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/user-panel/.env"] [unique_id "aqxX0-cL08BTTQixEnpDpQAAABg"]
[Thu Sep 17 15:12:51.973978 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:60378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/wp-includes/sodium_compat/src/Core32/"] [unique_id "aqxX0-cL08BTTQixEnpDpwAAAAI"]
[Thu Sep 17 15:12:52.194824 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/node/.env"] [unique_id "aqxX1OcL08BTTQixEnpDrQAAAD8"]
[Thu Sep 17 15:12:52.337300 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDqQAAACQ"]
[Thu Sep 17 15:12:52.337330 2026] [security2:error] [pid 971102:tid 971270] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDqQAAACQ"]
[Thu Sep 17 15:12:52.429176 2026] [security2:error] [pid 971102:tid 971298] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/express/.env"] [unique_id "aqxX1OcL08BTTQixEnpDuQAAAEA"]
[Thu Sep 17 15:12:52.432349 2026] [security2:error] [pid 971102:tid 971356] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDqgAAemU"], referer: https://www.makingreligionhealthy.com/old/
[Thu Sep 17 15:12:52.488779 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxX1OcL08BTTQixEnpDvQAAAFU"]
[Thu Sep 17 15:12:52.488878 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SecretStream/State.php"] [unique_id "aqxX1OcL08BTTQixEnpDvQAAAFU"]
[Thu Sep 17 15:12:52.642100 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.194.17:41780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/php-info.php"] [unique_id "aqxX1OcL08BTTQixEnpDwwAAAEs"]
[Thu Sep 17 15:12:52.659598 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/next/.env"] [unique_id "aqxX1OcL08BTTQixEnpDxQAAAFY"]
[Thu Sep 17 15:12:52.775255 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:60390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxX1OcL08BTTQixEnpDzwAAAAs"]
[Thu Sep 17 15:12:52.775381 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:60390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/SipHash.php"] [unique_id "aqxX1OcL08BTTQixEnpDzwAAAAs"]
[Thu Sep 17 15:12:52.888980 2026] [security2:error] [pid 971102:tid 971288] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/nuxt/.env"] [unique_id "aqxX1OcL08BTTQixEnpD0wAAADY"]
[Thu Sep 17 15:12:53.063478 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxX1ecL08BTTQixEnpD1wAAAAQ"]
[Thu Sep 17 15:12:53.063597 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/Util.php"] [unique_id "aqxX1ecL08BTTQixEnpD1wAAAAQ"]
[Thu Sep 17 15:12:53.083291 2026] [security2:error] [pid 971102:tid 971257] [client 57.141.14.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reddomconstruction.com"] [uri "/index.php"] [unique_id "aqxX1OcL08BTTQixEnpDzQAAABc"]
[Thu Sep 17 15:12:53.125995 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/nest/.env"] [unique_id "aqxX1ecL08BTTQixEnpD2wAAACE"]
[Thu Sep 17 15:12:53.360690 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.194.17:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpversion.php"] [unique_id "aqxX1ecL08BTTQixEnpD5gAAAF0"]
[Thu Sep 17 15:12:53.365346 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/react/.env"] [unique_id "aqxX1ecL08BTTQixEnpD5wAAAGg"]
[Thu Sep 17 15:12:53.371629 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxX1ecL08BTTQixEnpD6AAAAFM"]
[Thu Sep 17 15:12:53.371802 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/X25519.php"] [unique_id "aqxX1ecL08BTTQixEnpD6AAAAFM"]
[Thu Sep 17 15:12:53.430084 2026] [security2:error] [pid 971102:tid 971332] [client 162.241.226.11:57976] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxX1ecL08BTTQixEnpD6QAAAGI"]
[Thu Sep 17 15:12:53.599260 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/vue/.env"] [unique_id "aqxX1ecL08BTTQixEnpD8AAAADA"]
[Thu Sep 17 15:12:53.663996 2026] [security2:error] [pid 971102:tid 971244] [client 143.244.57.120:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxX1ecL08BTTQixEnpD8gAAAAo"]
[Thu Sep 17 15:12:53.664122 2026] [security2:error] [pid 971102:tid 971244] [client 143.244.57.120:60420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XChaCha20.php"] [unique_id "aqxX1ecL08BTTQixEnpD8gAAAAo"]
[Thu Sep 17 15:12:53.831168 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/angular/.env"] [unique_id "aqxX1ecL08BTTQixEnpD9AAAADI"]
[Thu Sep 17 15:12:53.941552 2026] [security2:error] [pid 971102:tid 971242] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1ecL08BTTQixEnpD8wAACGE"], referer: http://www.makingreligionhealthy.com/wordpress/
[Thu Sep 17 15:12:53.978786 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxX1ecL08BTTQixEnpD_QAAAGY"]
[Thu Sep 17 15:12:53.978894 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:60436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Core32/XSalsa20.php"] [unique_id "aqxX1ecL08BTTQixEnpD_QAAAGY"]
[Thu Sep 17 15:12:54.042621 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/_phpinfo.php"] [unique_id "aqxX1ucL08BTTQixEnpD_wAAAD8"]
[Thu Sep 17 15:12:54.061433 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/svelte/.env"] [unique_id "aqxX1ucL08BTTQixEnpEAAAAAHo"]
[Thu Sep 17 15:12:54.259873 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxX1ucL08BTTQixEnpEDAAAAFk"]
[Thu Sep 17 15:12:54.259965 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto.php"] [unique_id "aqxX1ucL08BTTQixEnpEDAAAAFk"]
[Thu Sep 17 15:12:54.296561 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/vite/.env"] [unique_id "aqxX1ucL08BTTQixEnpEDgAAAHY"]
[Thu Sep 17 15:12:54.314774 2026] [security2:error] [pid 971102:tid 971353] [client 156.192.234.52:51466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEDwAAAHc"]
[Thu Sep 17 15:12:54.316957 2026] [security2:error] [pid 971102:tid 971353] [client 156.192.234.52:51466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEDwAAAHc"]
[Thu Sep 17 15:12:54.381972 2026] [security2:error] [pid 971102:tid 971351] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1ucL08BTTQixEnpEAgAAdW8"], referer: https://www.makingreligionhealthy.com/wordpress/
[Thu Sep 17 15:12:54.408197 2026] [security2:error] [pid 971102:tid 971239] [client 43.173.178.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxX1ucL08BTTQixEnpECgAAAAU"]
[Thu Sep 17 15:12:54.533892 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "aqxX1ucL08BTTQixEnpEGAAAACY"]
[Thu Sep 17 15:12:54.540175 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxX1ucL08BTTQixEnpEGQAAAFc"]
[Thu Sep 17 15:12:54.540302 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/Crypto32.php"] [unique_id "aqxX1ucL08BTTQixEnpEGQAAAFc"]
[Thu Sep 17 15:12:54.695580 2026] [security2:error] [pid 971102:tid 971251] [client 205.169.39.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ulm.iln.mybluehost.me"] [uri "/~jminnerp/index.php"] [unique_id "aqxX0ucL08BTTQixEnpDcwAAABE"], referer: https://ulm.iln.mybluehost.me/website_8c974a43/
[Thu Sep 17 15:12:54.743362 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.194.17:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/old_phpinfo.php"] [unique_id "aqxX1ucL08BTTQixEnpEIwAAAEo"]
[Thu Sep 17 15:12:54.772442 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/backups/.env"] [unique_id "aqxX1ucL08BTTQixEnpEJQAAAGM"]
[Thu Sep 17 15:12:54.846930 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxX1ucL08BTTQixEnpEJwAAAFM"]
[Thu Sep 17 15:12:54.847069 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:60452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/File.php"] [unique_id "aqxX1ucL08BTTQixEnpEJwAAAFM"]
[Thu Sep 17 15:12:54.923872 2026] [security2:error] [pid 971102:tid 971267] [client 115.244.164.14:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEKgAAACE"]
[Thu Sep 17 15:12:54.923987 2026] [security2:error] [pid 971102:tid 971267] [client 115.244.164.14:56072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX1ucL08BTTQixEnpEKgAAACE"]
[Thu Sep 17 15:12:54.951746 2026] [security2:error] [pid 971102:tid 971361] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1ucL08BTTQixEnpEIAAAfww"], referer: http://www.makingreligionhealthy.com/backup/
[Thu Sep 17 15:12:55.002844 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "aqxX1-cL08BTTQixEnpEMQAAADA"]
[Thu Sep 17 15:12:55.065485 2026] [security2:error] [pid 971102:tid 971325] [client 185.55.149.49:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX1-cL08BTTQixEnpEMwAAAFs"]
[Thu Sep 17 15:12:55.065613 2026] [security2:error] [pid 971102:tid 971325] [client 185.55.149.49:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX1-cL08BTTQixEnpEMwAAAFs"]
[Thu Sep 17 15:12:55.125589 2026] [security2:error] [pid 971102:tid 971284] [client 143.244.57.120:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxX1-cL08BTTQixEnpENgAAADI"]
[Thu Sep 17 15:12:55.233303 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/tmp/.env"] [unique_id "aqxX1-cL08BTTQixEnpEOwAAADQ"]
[Thu Sep 17 15:12:55.282438 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/"] [unique_id "aqxX1-cL08BTTQixEnpEQAAAAEA"]
[Thu Sep 17 15:12:55.332639 2026] [security2:error] [pid 971102:tid 971299] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpENAAAQQU"], referer: https://www.makingreligionhealthy.com/backup/
[Thu Sep 17 15:12:55.425049 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/wp-includes/sodium_compat/src/"] [unique_id "aqxX1-cL08BTTQixEnpERQAAAE4"]
[Thu Sep 17 15:12:55.435925 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.194.17:41818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/server-info.php"] [unique_id "aqxX1-cL08BTTQixEnpERgAAAHQ"]
[Thu Sep 17 15:12:55.464518 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/temp/.env"] [unique_id "aqxX1-cL08BTTQixEnpESgAAAFk"]
[Thu Sep 17 15:12:55.479894 2026] [security2:error] [pid 971102:tid 971293] [client 43.165.198.224:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.198.165.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showtimeeventsvb.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxX1-cL08BTTQixEnpERwAAADs"]
[Thu Sep 17 15:12:55.697372 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/lab/.env"] [unique_id "aqxX1-cL08BTTQixEnpEWQAAAHM"]
[Thu Sep 17 15:12:55.836430 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpEUgAAAAw"]
[Thu Sep 17 15:12:55.836455 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpEUgAAAAw"]
[Thu Sep 17 15:12:55.913516 2026] [security2:error] [pid 971102:tid 971250] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX1-cL08BTTQixEnpEVAAAEAg"], referer: http://www.makingreligionhealthy.com/blog/
[Thu Sep 17 15:12:55.927389 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cronlab/.env"] [unique_id "aqxX1-cL08BTTQixEnpEXgAAABU"]
[Thu Sep 17 15:12:55.974096 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxX1-cL08BTTQixEnpEYwAAABk"]
[Thu Sep 17 15:12:55.974208 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/PHP52/SplFixedArray.php"] [unique_id "aqxX1-cL08BTTQixEnpEYwAAABk"]
[Thu Sep 17 15:12:56.117978 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/server-status.php"] [unique_id "aqxX2OcL08BTTQixEnpEZwAAAEM"]
[Thu Sep 17 15:12:56.165804 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cron/.env"] [unique_id "aqxX2OcL08BTTQixEnpEaAAAAGk"]
[Thu Sep 17 15:12:56.257834 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxX2OcL08BTTQixEnpEagAAAFU"]
[Thu Sep 17 15:12:56.257933 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:60466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/sodium_compat/src/SodiumException.php"] [unique_id "aqxX2OcL08BTTQixEnpEagAAAFU"]
[Thu Sep 17 15:12:56.400777 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/en/.env"] [unique_id "aqxX2OcL08BTTQixEnpEcAAAAGg"]
[Thu Sep 17 15:12:56.541148 2026] [security2:error] [pid 971102:tid 971236] [client 143.244.57.120:60478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxX2OcL08BTTQixEnpEdgAAAAI"]
[Thu Sep 17 15:12:56.619905 2026] [security2:error] [pid 971102:tid 971325] [client 5.189.145.112:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxX2OcL08BTTQixEnpEeQAAAFs"], referer: binance.com
[Thu Sep 17 15:12:56.690431 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/administrator/.env"] [unique_id "aqxX2OcL08BTTQixEnpEegAAABQ"]
[Thu Sep 17 15:12:56.736500 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxX2OcL08BTTQixEnpEfQAAACg"]
[Thu Sep 17 15:12:56.854850 2026] [security2:error] [pid 971102:tid 971244] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2OcL08BTTQixEnpEeAAACiY"], referer: http://www.makingreligionhealthy.com/wp/
[Thu Sep 17 15:12:56.874643 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:60478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxX2OcL08BTTQixEnpEgwAAADQ"]
[Thu Sep 17 15:12:56.874779 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:60478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-declarations.php"] [unique_id "aqxX2OcL08BTTQixEnpEgwAAADQ"]
[Thu Sep 17 15:12:56.920925 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/psnlink/.env"] [unique_id "aqxX2OcL08BTTQixEnpEhQAAAE8"]
[Thu Sep 17 15:12:57.014561 2026] [security2:error] [pid 971102:tid 971350] [client 43.156.79.172:55880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.79.156.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxX2OcL08BTTQixEnpEiQAAAHQ"]
[Thu Sep 17 15:12:57.155396 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxX2ecL08BTTQixEnpEjwAAAF8"]
[Thu Sep 17 15:12:57.155489 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rule.php"] [unique_id "aqxX2ecL08BTTQixEnpEjwAAAF8"]
[Thu Sep 17 15:12:57.155759 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/exapi/.env"] [unique_id "aqxX2ecL08BTTQixEnpEjgAAADs"]
[Thu Sep 17 15:12:57.228184 2026] [security2:error] [pid 971102:tid 971312] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2OcL08BTTQixEnpEiAAATjY"], referer: https://www.makingreligionhealthy.com/wp/
[Thu Sep 17 15:12:57.385616 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.130.148:52020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sitemaps/.env"] [unique_id "aqxX2ecL08BTTQixEnpElwAAAG8"]
[Thu Sep 17 15:12:57.423803 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.194.17:41836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxX2ecL08BTTQixEnpEmQAAACQ"]
[Thu Sep 17 15:12:57.445062 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:60494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxX2ecL08BTTQixEnpEmwAAAAY"]
[Thu Sep 17 15:12:57.445163 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.120:60494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-css-rules-store.php"] [unique_id "aqxX2ecL08BTTQixEnpEmwAAAAY"]
[Thu Sep 17 15:12:57.671932 2026] [security2:error] [pid 971102:tid 971223] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxX2ecL08BTTQixEnpEowAALHY"]
[Thu Sep 17 15:12:57.683616 2026] [core:error] [pid 971102:tid 971265] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:57.683632 2026] [core:error] [pid 971102:tid 971265] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:57.726342 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxX2ecL08BTTQixEnpEpQAAACs"]
[Thu Sep 17 15:12:57.726463 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine-processor.php"] [unique_id "aqxX2ecL08BTTQixEnpEpQAAACs"]
[Thu Sep 17 15:12:57.738963 2026] [security2:error] [pid 971102:tid 971351] [client 161.35.164.148:52080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2ecL08BTTQixEnpEngAAdSg"], referer: http://www.makingreligionhealthy.com/new/
[Thu Sep 17 15:12:57.950116 2026] [security2:error] [pid 971102:tid 971259] [client 104.28.198.244:22605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2ecL08BTTQixEnpEqQAAABk"]
[Thu Sep 17 15:12:58.025620 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxX2ucL08BTTQixEnpErgAAAHk"]
[Thu Sep 17 15:12:58.025768 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:60512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/style-engine/class-wp-style-engine.php"] [unique_id "aqxX2ucL08BTTQixEnpErgAAAHk"]
[Thu Sep 17 15:12:58.104247 2026] [security2:error] [pid 971102:tid 971271] [client 161.35.164.148:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxX2ecL08BTTQixEnpEqAAAJS0"], referer: https://www.makingreligionhealthy.com/new/
[Thu Sep 17 15:12:58.105374 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.194.17:45248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxX2ucL08BTTQixEnpEsAAAAG0"]
[Thu Sep 17 15:12:58.139883 2026] [security2:error] [pid 971102:tid 971259] [client 104.28.198.244:22605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2ecL08BTTQixEnpEqQAAABk"]
[Thu Sep 17 15:12:58.311429 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:60516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxX2ucL08BTTQixEnpEuwAAADE"]
[Thu Sep 17 15:12:58.428291 2026] [core:error] [pid 971102:tid 971334] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:58.428312 2026] [core:error] [pid 971102:tid 971334] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:12:58.470606 2026] [authz_core:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/theme-compat/error_log
[Thu Sep 17 15:12:58.475861 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxX2ucL08BTTQixEnpEwwAAAEA"]
[Thu Sep 17 15:12:58.649965 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxX2ucL08BTTQixEnpEzQAAAFk"]
[Thu Sep 17 15:12:58.791224 2026] [security2:error] [pid 971102:tid 971293] [client 52.167.144.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wheresmymap.com"] [uri "/index.php"] [unique_id "aqxX2ucL08BTTQixEnpEywAAADs"]
[Thu Sep 17 15:12:58.801894 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.194.17:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxX2ucL08BTTQixEnpE1AAAAEU"]
[Thu Sep 17 15:12:58.806729 2026] [authz_core:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-includes/widgets/error_log
[Thu Sep 17 15:12:58.811331 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxX2ucL08BTTQixEnpE0wAAAG8"]
[Thu Sep 17 15:12:58.954159 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX2ucL08BTTQixEnpE2AAAACk"]
[Thu Sep 17 15:12:58.954272 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:60516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX2ucL08BTTQixEnpE2AAAACk"]
[Thu Sep 17 15:12:58.985054 2026] [authz_core:error] [pid 971102:tid 971330] [client 20.244.34.24:63142] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:12:59.124212 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/logs/.env"] [unique_id "aqxX2-cL08BTTQixEnpE4AAAAAY"]
[Thu Sep 17 15:12:59.264319 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX2-cL08BTTQixEnpE5wAAAAk"]
[Thu Sep 17 15:12:59.291654 2026] [security2:error] [pid 971102:tid 971246] [client 114.198.138.124:57341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE6QAAAAw"]
[Thu Sep 17 15:12:59.291776 2026] [security2:error] [pid 971102:tid 971246] [client 114.198.138.124:57341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE6QAAAAw"]
[Thu Sep 17 15:12:59.354908 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cache/.env"] [unique_id "aqxX2-cL08BTTQixEnpE6gAAABM"]
[Thu Sep 17 15:12:59.491624 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX2-cL08BTTQixEnpE7QAAAAQ"]
[Thu Sep 17 15:12:59.495287 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.194.17:45268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxX2-cL08BTTQixEnpE8gAAAEM"]
[Thu Sep 17 15:12:59.584159 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailer/.env"] [unique_id "aqxX2-cL08BTTQixEnpE9QAAAFs"]
[Thu Sep 17 15:12:59.586475 2026] [security2:error] [pid 971102:tid 971291] [client 43.166.245.120:48260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.245.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "groverpdx.net"] [uri "/wp-login.php"] [unique_id "aqxX2-cL08BTTQixEnpE8wAAADk"], referer: https://groverpdx.net/
[Thu Sep 17 15:12:59.631183 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxX2-cL08BTTQixEnpE9gAAAG4"]
[Thu Sep 17 15:12:59.677723 2026] [security2:error] [pid 971102:tid 971140] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxX2-cL08BTTQixEnpE9wAALiQ"]
[Thu Sep 17 15:12:59.815306 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "aqxX2-cL08BTTQixEnpE-wAAAHg"]
[Thu Sep 17 15:12:59.856746 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE_AAAAGg"]
[Thu Sep 17 15:12:59.856849 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX2-cL08BTTQixEnpE_AAAAGg"]
[Thu Sep 17 15:13:00.043436 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/email/.env"] [unique_id "aqxX3OcL08BTTQixEnpFAQAAACg"]
[Thu Sep 17 15:13:00.043733 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxX2-cL08BTTQixEnpE-QAAAEo"]
[Thu Sep 17 15:13:00.175166 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.194.17:45278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxX3OcL08BTTQixEnpFAgAAAGY"]
[Thu Sep 17 15:13:00.225141 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxX3OcL08BTTQixEnpFBgAAAF8"]
[Thu Sep 17 15:13:00.282583 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/smtp/.env"] [unique_id "aqxX3OcL08BTTQixEnpFBwAAAC0"]
[Thu Sep 17 15:13:00.418706 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aqxX3OcL08BTTQixEnpFCgAAAFk"]
[Thu Sep 17 15:13:00.516557 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailing/.env"] [unique_id "aqxX3OcL08BTTQixEnpFDwAAAHw"]
[Thu Sep 17 15:13:00.567999 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/blue/wp-admin/css/colors/"] [unique_id "aqxX3OcL08BTTQixEnpFEAAAADM"]
[Thu Sep 17 15:13:00.709056 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3OcL08BTTQixEnpFGAAAAFY"]
[Thu Sep 17 15:13:00.709166 2026] [security2:error] [pid 971102:tid 971320] [client 186.105.232.15:56606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3OcL08BTTQixEnpFGAAAAFY"]
[Thu Sep 17 15:13:00.751188 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/notifications/.env"] [unique_id "aqxX3OcL08BTTQixEnpFGgAAAEc"]
[Thu Sep 17 15:13:00.864401 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.194.17:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxX3OcL08BTTQixEnpFHwAAAF0"]
[Thu Sep 17 15:13:00.916568 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3OcL08BTTQixEnpFFwAAABg"]
[Thu Sep 17 15:13:00.916591 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3OcL08BTTQixEnpFFwAAABg"]
[Thu Sep 17 15:13:00.984949 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/notify/.env"] [unique_id "aqxX3OcL08BTTQixEnpFIQAAAAY"]
[Thu Sep 17 15:13:01.089025 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxX3ecL08BTTQixEnpFJQAAACs"]
[Thu Sep 17 15:13:01.216993 2026] [security2:error] [pid 971102:tid 971268] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sender/.env"] [unique_id "aqxX3ecL08BTTQixEnpFLQAAACI"]
[Thu Sep 17 15:13:01.423092 2026] [security2:error] [pid 971102:tid 971319] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "aqxX3ecL08BTTQixEnpFMAAAAFU"]
[Thu Sep 17 15:13:01.448460 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/campaign/.env"] [unique_id "aqxX3ecL08BTTQixEnpFMwAAAFI"]
[Thu Sep 17 15:13:01.535149 2026] [security2:error] [pid 971102:tid 971261] [client 45.169.98.18:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3ecL08BTTQixEnpFNwAAABs"]
[Thu Sep 17 15:13:01.535311 2026] [security2:error] [pid 971102:tid 971261] [client 45.169.98.18:60782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX3ecL08BTTQixEnpFNwAAABs"]
[Thu Sep 17 15:13:01.554109 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:45310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxX3ecL08BTTQixEnpFOAAAABM"]
[Thu Sep 17 15:13:01.564657 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/coffee/wp-admin/css/colors/"] [unique_id "aqxX3ecL08BTTQixEnpFOgAAAAQ"]
[Thu Sep 17 15:13:01.680582 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/newsletter/.env"] [unique_id "aqxX3ecL08BTTQixEnpFPAAAADk"]
[Thu Sep 17 15:13:01.919246 2026] [security2:error] [pid 971102:tid 971244] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/ses/.env"] [unique_id "aqxX3ecL08BTTQixEnpFRQAAAAo"]
[Thu Sep 17 15:13:01.922111 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ecL08BTTQixEnpFQAAAADU"]
[Thu Sep 17 15:13:01.922131 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ecL08BTTQixEnpFQAAAADU"]
[Thu Sep 17 15:13:02.069704 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX3ucL08BTTQixEnpFSQAAAHI"]
[Thu Sep 17 15:13:02.154028 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sendgrid/.env"] [unique_id "aqxX3ucL08BTTQixEnpFSwAAAE0"]
[Thu Sep 17 15:13:02.249947 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.194.17:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php.old"] [unique_id "aqxX3ucL08BTTQixEnpFUQAAAEo"]
[Thu Sep 17 15:13:02.271597 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxX3ucL08BTTQixEnpFTwAAAEA"]
[Thu Sep 17 15:13:02.391806 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/sparkpost/.env"] [unique_id "aqxX3ucL08BTTQixEnpFVQAAAEw"]
[Thu Sep 17 15:13:02.419180 2026] [security2:error] [pid 971102:tid 971295] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ectoplasm/wp-admin/css/colors/"] [unique_id "aqxX3ucL08BTTQixEnpFVgAAAD0"]
[Thu Sep 17 15:13:02.600679 2026] [security2:error] [pid 971102:tid 971347] [client 5.189.145.112:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxX3ucL08BTTQixEnpFXAAAAHE"], referer: binance.com
[Thu Sep 17 15:13:02.628780 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/postmark/.env"] [unique_id "aqxX3ucL08BTTQixEnpFXgAAACo"]
[Thu Sep 17 15:13:02.757023 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ucL08BTTQixEnpFWwAAAEU"]
[Thu Sep 17 15:13:02.757054 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3ucL08BTTQixEnpFWwAAAEU"]
[Thu Sep 17 15:13:02.862192 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailgun/.env"] [unique_id "aqxX3ucL08BTTQixEnpFYwAAAF4"]
[Thu Sep 17 15:13:02.900838 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxX3ucL08BTTQixEnpFZgAAAGA"]
[Thu Sep 17 15:13:02.949132 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.194.17:45328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php~"] [unique_id "aqxX3ucL08BTTQixEnpFZwAAAD8"]
[Thu Sep 17 15:13:03.091779 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "aqxX3-cL08BTTQixEnpFagAAADo"]
[Thu Sep 17 15:13:03.093727 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mandrill/.env"] [unique_id "aqxX3-cL08BTTQixEnpFbAAAAEE"]
[Thu Sep 17 15:13:03.240113 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/light/wp-admin/css/colors/"] [unique_id "aqxX3-cL08BTTQixEnpFcQAAAGU"]
[Thu Sep 17 15:13:03.336370 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mailjet/.env"] [unique_id "aqxX3-cL08BTTQixEnpFcwAAACY"]
[Thu Sep 17 15:13:03.570009 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3-cL08BTTQixEnpFdQAAAHo"]
[Thu Sep 17 15:13:03.570038 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX3-cL08BTTQixEnpFdQAAAHo"]
[Thu Sep 17 15:13:03.572472 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/brevo/.env"] [unique_id "aqxX3-cL08BTTQixEnpFegAAAB8"]
[Thu Sep 17 15:13:03.642924 2026] [security2:error] [pid 971102:tid 971268] [client 34.166.194.17:45332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/info.php.bak"] [unique_id "aqxX3-cL08BTTQixEnpFfAAAACI"]
[Thu Sep 17 15:13:03.715254 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxX3-cL08BTTQixEnpFfQAAAFI"]
[Thu Sep 17 15:13:03.808901 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/transactional/.env"] [unique_id "aqxX3-cL08BTTQixEnpFgQAAAAQ"]
[Thu Sep 17 15:13:03.919349 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aqxX3-cL08BTTQixEnpFhQAAAGk"]
[Thu Sep 17 15:13:03.963112 2026] [security2:error] [pid 971102:tid 971325] [client 4.240.114.86:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxX3-cL08BTTQixEnpFigAAAFs"], referer: binance.com
[Thu Sep 17 15:13:04.043273 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/bulk/.env"] [unique_id "aqxX4OcL08BTTQixEnpFjAAAABY"]
[Thu Sep 17 15:13:04.062879 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/midnight/wp-admin/css/colors/"] [unique_id "aqxX4OcL08BTTQixEnpFjQAAAB4"]
[Thu Sep 17 15:13:04.282029 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/aws/.env"] [unique_id "aqxX4OcL08BTTQixEnpFkgAAAHg"]
[Thu Sep 17 15:13:04.334605 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.194.17:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/phpinfo.php.save"] [unique_id "aqxX4OcL08BTTQixEnpFlAAAAEg"]
[Thu Sep 17 15:13:04.429725 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4OcL08BTTQixEnpFkAAAABo"]
[Thu Sep 17 15:13:04.429758 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4OcL08BTTQixEnpFkAAAABo"]
[Thu Sep 17 15:13:04.521769 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/azure/.env"] [unique_id "aqxX4OcL08BTTQixEnpFlwAAAE0"]
[Thu Sep 17 15:13:04.574961 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxX4OcL08BTTQixEnpFngAAADA"]
[Thu Sep 17 15:13:04.756020 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/gcp/.env"] [unique_id "aqxX4OcL08BTTQixEnpFpAAAAAM"]
[Thu Sep 17 15:13:04.771953 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aqxX4OcL08BTTQixEnpFogAAAEw"]
[Thu Sep 17 15:13:04.916899 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/modern/wp-admin/css/colors/"] [unique_id "aqxX4OcL08BTTQixEnpFpgAAAAc"]
[Thu Sep 17 15:13:04.949230 2026] [security2:error] [pid 971102:tid 971298] [client 156.192.234.52:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4OcL08BTTQixEnpFpwAAAEA"]
[Thu Sep 17 15:13:04.949814 2026] [security2:error] [pid 971102:tid 971298] [client 156.192.234.52:52078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4OcL08BTTQixEnpFpwAAAEA"]
[Thu Sep 17 15:13:04.993168 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cloud/.env"] [unique_id "aqxX4OcL08BTTQixEnpFqAAAAG0"]
[Thu Sep 17 15:13:05.019857 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.194.17:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxX4ecL08BTTQixEnpFqwAAAF8"]
[Thu Sep 17 15:13:05.236745 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/infrastructure/.env"] [unique_id "aqxX4ecL08BTTQixEnpFsgAAAEU"]
[Thu Sep 17 15:13:05.261624 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFrgAAACo"]
[Thu Sep 17 15:13:05.261642 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFrgAAACo"]
[Thu Sep 17 15:13:05.405990 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxX4ecL08BTTQixEnpFuAAAAD8"]
[Thu Sep 17 15:13:05.470062 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "aqxX4ecL08BTTQixEnpFvwAAACM"]
[Thu Sep 17 15:13:05.506395 2026] [security2:error] [pid 971102:tid 971353] [client 115.244.164.14:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFwQAAAHc"]
[Thu Sep 17 15:13:05.506537 2026] [security2:error] [pid 971102:tid 971353] [client 115.244.164.14:56732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFwQAAAHc"]
[Thu Sep 17 15:13:05.615546 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "aqxX4ecL08BTTQixEnpFxAAAACc"]
[Thu Sep 17 15:13:05.703160 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/k8s/.env"] [unique_id "aqxX4ecL08BTTQixEnpFxQAAADs"]
[Thu Sep 17 15:13:05.706717 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.194.17:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxX4ecL08BTTQixEnpFxgAAAEk"]
[Thu Sep 17 15:13:05.760537 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/ocean/wp-admin/css/colors/"] [unique_id "aqxX4ecL08BTTQixEnpFxwAAAHk"]
[Thu Sep 17 15:13:05.803899 2026] [security2:error] [pid 971102:tid 971335] [client 185.55.149.49:65220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFyQAAAGU"]
[Thu Sep 17 15:13:05.804005 2026] [security2:error] [pid 971102:tid 971335] [client 185.55.149.49:65220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX4ecL08BTTQixEnpFyQAAAGU"]
[Thu Sep 17 15:13:05.935022 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/kubernetes/.env"] [unique_id "aqxX4ecL08BTTQixEnpFywAAAHA"]
[Thu Sep 17 15:13:06.114581 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:59746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFygAAAA8"]
[Thu Sep 17 15:13:06.114607 2026] [security2:error] [pid 971102:tid 971249] [client 143.244.57.120:59746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4ecL08BTTQixEnpFygAAAA8"]
[Thu Sep 17 15:13:06.171734 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/terraform/.env"] [unique_id "aqxX4ucL08BTTQixEnpF0QAAABY"]
[Thu Sep 17 15:13:06.282831 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxX4ucL08BTTQixEnpF1gAAAA4"]
[Thu Sep 17 15:13:06.392321 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.194.17:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxX4ucL08BTTQixEnpF1wAAAH8"]
[Thu Sep 17 15:13:06.405301 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/ansible/.env"] [unique_id "aqxX4ucL08BTTQixEnpF2AAAAAA"]
[Thu Sep 17 15:13:06.638232 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.git/.env"] [unique_id "aqxX4ucL08BTTQixEnpF3QAAAEg"]
[Thu Sep 17 15:13:06.815121 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aqxX4ucL08BTTQixEnpF4AAAAHg"]
[Thu Sep 17 15:13:06.871771 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/ci/.env"] [unique_id "aqxX4ucL08BTTQixEnpF4wAAAHU"]
[Thu Sep 17 15:13:06.970955 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/css/colors/sunrise/wp-admin/css/colors/"] [unique_id "aqxX4ucL08BTTQixEnpF5AAAAC8"]
[Thu Sep 17 15:13:07.047747 2026] [security2:error] [pid 971102:tid 971311] [client 216.73.216.134:40683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.caitlinannemack.com"] [uri "/shop.php/sitemap624.xml"] [unique_id "aqxX4-cL08BTTQixEnpF6AAAAE0"]
[Thu Sep 17 15:13:07.084429 2026] [security2:error] [pid 971102:tid 971260] [client 34.166.194.17:45370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxX4-cL08BTTQixEnpF6gAAABo"]
[Thu Sep 17 15:13:07.106165 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cd/.env"] [unique_id "aqxX4-cL08BTTQixEnpF6wAAAEo"]
[Thu Sep 17 15:13:07.323755 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpF7AAAADA"]
[Thu Sep 17 15:13:07.323784 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpF7AAAADA"]
[Thu Sep 17 15:13:07.339742 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/jenkins/.env"] [unique_id "aqxX4-cL08BTTQixEnpF8QAAAAM"]
[Thu Sep 17 15:13:07.536317 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:23000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4-cL08BTTQixEnpF9wAAACg"]
[Thu Sep 17 15:13:07.536464 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:23000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX4-cL08BTTQixEnpF9wAAACg"]
[Thu Sep 17 15:13:07.575343 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/gitlab/.env"] [unique_id "aqxX4-cL08BTTQixEnpF-AAAAE4"]
[Thu Sep 17 15:13:07.607182 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/images/slider/"] [unique_id "aqxX4-cL08BTTQixEnpF_AAAADM"]
[Thu Sep 17 15:13:07.771041 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.194.17:40696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxX4-cL08BTTQixEnpGAgAAAHY"]
[Thu Sep 17 15:13:07.809294 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/github/.env"] [unique_id "aqxX4-cL08BTTQixEnpGAwAAAAU"]
[Thu Sep 17 15:13:07.962519 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpGAQAAAGo"]
[Thu Sep 17 15:13:07.962542 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX4-cL08BTTQixEnpGAQAAAGo"]
[Thu Sep 17 15:13:08.041758 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/actions/.env"] [unique_id "aqxX5OcL08BTTQixEnpGCgAAAC0"]
[Thu Sep 17 15:13:08.055388 2026] [autoindex:error] [pid 971102:tid 971313] [client 194.163.128.162:59977] AH01276: Cannot serve directory /home1/commopo9/public_html/thezoeline/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:13:08.110411 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxX5OcL08BTTQixEnpGCwAAACU"]
[Thu Sep 17 15:13:08.280423 2026] [security2:error] [pid 971102:tid 971314] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/circleci/.env"] [unique_id "aqxX5OcL08BTTQixEnpGEQAAAFA"]
[Thu Sep 17 15:13:08.461708 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGEAAAAB8"]
[Thu Sep 17 15:13:08.461738 2026] [security2:error] [pid 971102:tid 971265] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGEAAAAB8"]
[Thu Sep 17 15:13:08.469473 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.194.17:40710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/www/phpinfo.php"] [unique_id "aqxX5OcL08BTTQixEnpGFgAAAH0"]
[Thu Sep 17 15:13:08.538462 2026] [security2:error] [pid 971102:tid 971267] [client 134.185.85.61:62746] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "luxelivinglv.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxX5OcL08BTTQixEnpGFwAAACE"]
[Thu Sep 17 15:13:08.586387 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/travis/.env"] [unique_id "aqxX5OcL08BTTQixEnpGGAAAADw"]
[Thu Sep 17 15:13:08.636938 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/sites/default/files/"] [unique_id "aqxX5OcL08BTTQixEnpGGQAAAGM"]
[Thu Sep 17 15:13:08.928070 2026] [security2:error] [pid 971102:tid 971283] [client 134.185.85.61:55851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "luxelivinglv.com"] [uri "/media/system/js/core.js"] [unique_id "aqxX5OcL08BTTQixEnpGIAAAADE"]
[Thu Sep 17 15:13:08.961872 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/buildkite/.env"] [unique_id "aqxX5OcL08BTTQixEnpGIgAAAAA"]
[Thu Sep 17 15:13:08.976149 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGHgAAAA4"]
[Thu Sep 17 15:13:08.976172 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5OcL08BTTQixEnpGHgAAAA4"]
[Thu Sep 17 15:13:09.088329 2026] [security2:error] [pid 971102:tid 971255] [client 169.58.197.253:57273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxX5ecL08BTTQixEnpGKAAAABU"], referer: binance.com
[Thu Sep 17 15:13:09.120883 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxX5ecL08BTTQixEnpGKQAAAH4"]
[Thu Sep 17 15:13:09.147467 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.194.17:40720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxX5ecL08BTTQixEnpGKgAAABQ"]
[Thu Sep 17 15:13:09.306742 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mysql/.env"] [unique_id "aqxX5ecL08BTTQixEnpGMAAAAAs"]
[Thu Sep 17 15:13:09.467475 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGLgAAAB4"]
[Thu Sep 17 15:13:09.467492 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGLgAAAB4"]
[Thu Sep 17 15:13:09.573953 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/postgres/.env"] [unique_id "aqxX5ecL08BTTQixEnpGNQAAABw"]
[Thu Sep 17 15:13:09.619845 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxX5ecL08BTTQixEnpGNgAAAGw"]
[Thu Sep 17 15:13:09.848928 2026] [security2:error] [pid 971102:tid 971308] [client 34.166.194.17:40736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxX5ecL08BTTQixEnpGOQAAAEo"]
[Thu Sep 17 15:13:09.889274 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/mongodb/.env"] [unique_id "aqxX5ecL08BTTQixEnpGPAAAADA"]
[Thu Sep 17 15:13:09.916979 2026] [security2:error] [pid 971102:tid 971341] [client 114.198.138.124:57967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ecL08BTTQixEnpGPgAAAGs"]
[Thu Sep 17 15:13:09.917074 2026] [security2:error] [pid 971102:tid 971341] [client 114.198.138.124:57967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ecL08BTTQixEnpGPgAAAGs"]
[Thu Sep 17 15:13:09.962301 2026] [security2:error] [pid 971102:tid 971235] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGOAAAAAE"]
[Thu Sep 17 15:13:09.962324 2026] [security2:error] [pid 971102:tid 971235] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ecL08BTTQixEnpGOAAAAAE"]
[Thu Sep 17 15:13:10.106795 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/components/"] [unique_id "aqxX5ucL08BTTQixEnpGQwAAAE4"]
[Thu Sep 17 15:13:10.221366 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/redis/.env"] [unique_id "aqxX5ucL08BTTQixEnpGSAAAAEU"]
[Thu Sep 17 15:13:10.466205 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGSgAAAHE"]
[Thu Sep 17 15:13:10.466231 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGSgAAAHE"]
[Thu Sep 17 15:13:10.478363 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/elasticsearch/.env"] [unique_id "aqxX5ucL08BTTQixEnpGTwAAACc"]
[Thu Sep 17 15:13:10.543065 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.194.17:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/site/phpinfo.php"] [unique_id "aqxX5ucL08BTTQixEnpGUQAAABg"]
[Thu Sep 17 15:13:10.616846 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/admin/uploads/images/"] [unique_id "aqxX5ucL08BTTQixEnpGUgAAAHY"]
[Thu Sep 17 15:13:10.750077 2026] [security2:error] [pid 971102:tid 971357] [client 154.190.208.131:41874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ucL08BTTQixEnpGWQAAAHs"]
[Thu Sep 17 15:13:10.750166 2026] [security2:error] [pid 971102:tid 971357] [client 154.190.208.131:41874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5ucL08BTTQixEnpGWQAAAHs"]
[Thu Sep 17 15:13:10.768506 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/rabbitmq/.env"] [unique_id "aqxX5ucL08BTTQixEnpGWwAAAEE"]
[Thu Sep 17 15:13:10.823907 2026] [security2:error] [pid 971102:tid 971295] [client 216.144.225.2:51479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "techsol360.com"] [uri "/.env"] [unique_id "aqxX5ucL08BTTQixEnpGXAAAAD0"]
[Thu Sep 17 15:13:10.891427 2026] [security2:error] [pid 971102:tid 971277] [client 5.189.145.112:50111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxX5ucL08BTTQixEnpGXQAAACs"], referer: binance.com
[Thu Sep 17 15:13:10.983804 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGWgAAAHc"]
[Thu Sep 17 15:13:10.983842 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5ucL08BTTQixEnpGWgAAAHc"]
[Thu Sep 17 15:13:11.065402 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/kafka/.env"] [unique_id "aqxX5-cL08BTTQixEnpGYwAAACE"]
[Thu Sep 17 15:13:11.076623 2026] [security2:error] [pid 971102:tid 971294] [client 216.144.225.2:58151] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "techsol360.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "aqxX5-cL08BTTQixEnpGZAAAADw"]
[Thu Sep 17 15:13:11.129959 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxX5-cL08BTTQixEnpGZQAAAAQ"]
[Thu Sep 17 15:13:11.234254 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.194.17:40744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxX5-cL08BTTQixEnpGaQAAAB8"]
[Thu Sep 17 15:13:11.298957 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/queue/.env"] [unique_id "aqxX5-cL08BTTQixEnpGbAAAAGk"]
[Thu Sep 17 15:13:11.467614 2026] [security2:error] [pid 971102:tid 971335] [client 54.152.77.108:34096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rocketboxcreative.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGbwAAZRA"]
[Thu Sep 17 15:13:11.491352 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGawAAABs"]
[Thu Sep 17 15:13:11.491375 2026] [security2:error] [pid 971102:tid 971261] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGawAAABs"]
[Thu Sep 17 15:13:11.585766 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/worker/.env"] [unique_id "aqxX5-cL08BTTQixEnpGeAAAAAI"]
[Thu Sep 17 15:13:11.652376 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/fonts/"] [unique_id "aqxX5-cL08BTTQixEnpGfAAAAHg"]
[Thu Sep 17 15:13:11.723127 2026] [security2:error] [pid 971102:tid 971118] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxX5-cL08BTTQixEnpGfgAAJQ4"]
[Thu Sep 17 15:13:11.808628 2026] [security2:error] [pid 971102:tid 971248] [client 186.105.232.15:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5-cL08BTTQixEnpGgAAAAA4"]
[Thu Sep 17 15:13:11.808769 2026] [security2:error] [pid 971102:tid 971248] [client 186.105.232.15:57202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX5-cL08BTTQixEnpGgAAAAA4"]
[Thu Sep 17 15:13:11.849632 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/job/.env"] [unique_id "aqxX5-cL08BTTQixEnpGgQAAADQ"]
[Thu Sep 17 15:13:11.929327 2026] [security2:error] [pid 971102:tid 971260] [client 111.225.149.191:28940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/"] [unique_id "aqxX5-cL08BTTQixEnpGggAAABo"]
[Thu Sep 17 15:13:11.937219 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.194.17:40760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxX5-cL08BTTQixEnpGgwAAABw"]
[Thu Sep 17 15:13:11.995821 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGfwAAAHI"]
[Thu Sep 17 15:13:11.995841 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX5-cL08BTTQixEnpGfwAAAHI"]
[Thu Sep 17 15:13:12.003395 2026] [security2:error] [pid 971102:tid 971324] [client 45.169.98.18:61336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6OcL08BTTQixEnpGhwAAAFo"]
[Thu Sep 17 15:13:12.004461 2026] [security2:error] [pid 971102:tid 971324] [client 45.169.98.18:61336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6OcL08BTTQixEnpGhwAAAFo"]
[Thu Sep 17 15:13:12.122312 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/test/.env"] [unique_id "aqxX6OcL08BTTQixEnpGiQAAAEw"]
[Thu Sep 17 15:13:12.144771 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxX6OcL08BTTQixEnpGigAAAEI"]
[Thu Sep 17 15:13:12.340872 2026] [authz_core:error] [pid 971102:tid 971325] [client 20.244.34.24:57076] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:13:12.358831 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/qa/.env"] [unique_id "aqxX6OcL08BTTQixEnpGlwAAAAg"]
[Thu Sep 17 15:13:12.529035 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6OcL08BTTQixEnpGkQAAAF8"]
[Thu Sep 17 15:13:12.529058 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6OcL08BTTQixEnpGkQAAAF8"]
[Thu Sep 17 15:13:12.592451 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/preview/.env"] [unique_id "aqxX6OcL08BTTQixEnpGnwAAADs"]
[Thu Sep 17 15:13:12.635129 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.194.17:40762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxX6OcL08BTTQixEnpGoAAAAG4"]
[Thu Sep 17 15:13:12.674803 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxX6OcL08BTTQixEnpGoQAAAF0"]
[Thu Sep 17 15:13:12.823573 2026] [security2:error] [pid 971102:tid 971246] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/beta/.env"] [unique_id "aqxX6OcL08BTTQixEnpGqAAAAAw"]
[Thu Sep 17 15:13:12.879540 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxX6OcL08BTTQixEnpGpwAAAE8"]
[Thu Sep 17 15:13:13.022988 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/"] [unique_id "aqxX6ecL08BTTQixEnpGsAAAACs"]
[Thu Sep 17 15:13:13.056282 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/uat/.env"] [unique_id "aqxX6ecL08BTTQixEnpGswAAABA"]
[Thu Sep 17 15:13:13.256533 2026] [security2:error] [pid 971102:tid 971320] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/"] [unique_id "aqxX6ecL08BTTQixEnpGtAAAAFY"]
[Thu Sep 17 15:13:13.288382 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/stage/.env"] [unique_id "aqxX6ecL08BTTQixEnpGuQAAAA8"]
[Thu Sep 17 15:13:13.312105 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.194.17:40766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/core/phpinfo.php"] [unique_id "aqxX6ecL08BTTQixEnpGugAAAHc"]
[Thu Sep 17 15:13:13.402729 2026] [security2:error] [pid 971102:tid 971278] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/wp-content/plugins/contact-form-7/"] [unique_id "aqxX6ecL08BTTQixEnpGuwAAACw"]
[Thu Sep 17 15:13:13.518535 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "aqxX6ecL08BTTQixEnpGvgAAACk"]
[Thu Sep 17 15:13:13.757329 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ecL08BTTQixEnpGwQAAABk"]
[Thu Sep 17 15:13:13.757356 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ecL08BTTQixEnpGwQAAABk"]
[Thu Sep 17 15:13:13.759082 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/production/.env"] [unique_id "aqxX6ecL08BTTQixEnpGxQAAAEg"]
[Thu Sep 17 15:13:13.918705 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/admin.php"] [unique_id "aqxX6ecL08BTTQixEnpGxgAAAA0"]
[Thu Sep 17 15:13:13.918827 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/admin.php"] [unique_id "aqxX6ecL08BTTQixEnpGxgAAAA0"]
[Thu Sep 17 15:13:13.987793 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.130.148:47154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/config/app/.env"] [unique_id "aqxX6ecL08BTTQixEnpGyQAAAHg"]
[Thu Sep 17 15:13:13.995246 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.194.17:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.194.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexgenimplant.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxX6ecL08BTTQixEnpGywAAABM"]
[Thu Sep 17 15:13:14.198904 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:46800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/edit-contact-form.php"] [unique_id "aqxX6ucL08BTTQixEnpGzQAAAB4"]
[Thu Sep 17 15:13:14.199002 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:46800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/edit-contact-form.php"] [unique_id "aqxX6ucL08BTTQixEnpGzQAAAB4"]
[Thu Sep 17 15:13:14.237360 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.130.148:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxX6ucL08BTTQixEnpGzgAAAFc"]
[Thu Sep 17 15:13:14.474534 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:46810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/"] [unique_id "aqxX6ucL08BTTQixEnpG3AAAAFs"]
[Thu Sep 17 15:13:14.705968 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/"] [unique_id "aqxX6ucL08BTTQixEnpG3wAAAAc"]
[Thu Sep 17 15:13:14.723451 2026] [security2:error] [pid 971102:tid 971127] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxX6ucL08BTTQixEnpG4gAAFhc"]
[Thu Sep 17 15:13:14.848131 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:46810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/wp-content/plugins/contact-form-7/admin/"] [unique_id "aqxX6ucL08BTTQixEnpG4wAAAG4"]
[Thu Sep 17 15:13:14.916993 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.130.148:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/info.php"] [unique_id "aqxX6ucL08BTTQixEnpG5QAAABg"]
[Thu Sep 17 15:13:15.199942 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ucL08BTTQixEnpG6gAAAGo"]
[Thu Sep 17 15:13:15.199979 2026] [security2:error] [pid 971102:tid 971340] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX6ucL08BTTQixEnpG6gAAAGo"]
[Thu Sep 17 15:13:15.329940 2026] [security2:error] [pid 971102:tid 971307] [client 34.122.149.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxX6-cL08BTTQixEnpG8AAAAEk"]
[Thu Sep 17 15:13:15.337390 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:46810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/admin-functions.php"] [unique_id "aqxX6-cL08BTTQixEnpG9wAAAEE"]
[Thu Sep 17 15:13:15.337523 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:46810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/admin-functions.php"] [unique_id "aqxX6-cL08BTTQixEnpG9wAAAEE"]
[Thu Sep 17 15:13:15.510123 2026] [security2:error] [pid 971102:tid 971246] [client 156.192.234.52:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6-cL08BTTQixEnpG_wAAAAw"]
[Thu Sep 17 15:13:15.510342 2026] [security2:error] [pid 971102:tid 971246] [client 156.192.234.52:52698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX6-cL08BTTQixEnpG_wAAAAw"]
[Thu Sep 17 15:13:15.614979 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:46820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/class-contact-forms-list-table.php"] [unique_id "aqxX6-cL08BTTQixEnpHBAAAADY"]
[Thu Sep 17 15:13:15.615089 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:46820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/class-contact-forms-list-table.php"] [unique_id "aqxX6-cL08BTTQixEnpHBAAAADY"]
[Thu Sep 17 15:13:15.615370 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.130.148:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/php.php"] [unique_id "aqxX6-cL08BTTQixEnpHBQAAAH0"]
[Thu Sep 17 15:13:15.906161 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:46836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/config-validator.php"] [unique_id "aqxX6-cL08BTTQixEnpHDQAAAA4"]
[Thu Sep 17 15:13:15.906261 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:46836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/config-validator.php"] [unique_id "aqxX6-cL08BTTQixEnpHDQAAAA4"]
[Thu Sep 17 15:13:16.030320 2026] [security2:error] [pid 971102:tid 971354] [client 115.244.164.14:57386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHEgAAAHg"]
[Thu Sep 17 15:13:16.030415 2026] [security2:error] [pid 971102:tid 971354] [client 115.244.164.14:57386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHEgAAAHg"]
[Thu Sep 17 15:13:16.188990 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:46848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/css/"] [unique_id "aqxX7OcL08BTTQixEnpHFgAAAFo"]
[Thu Sep 17 15:13:16.314121 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.130.148:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/i.php"] [unique_id "aqxX7OcL08BTTQixEnpHGgAAAHI"]
[Thu Sep 17 15:13:16.371798 2026] [security2:error] [pid 971102:tid 971350] [client 169.58.197.253:57735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxX7OcL08BTTQixEnpHHQAAAHQ"], referer: binance.com
[Thu Sep 17 15:13:16.377267 2026] [security2:error] [pid 971102:tid 971298] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/css/"] [unique_id "aqxX7OcL08BTTQixEnpHHAAAAEA"]
[Thu Sep 17 15:13:16.477738 2026] [security2:error] [pid 971102:tid 971244] [client 185.55.149.49:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHIgAAAAo"]
[Thu Sep 17 15:13:16.477851 2026] [security2:error] [pid 971102:tid 971244] [client 185.55.149.49:49805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX7OcL08BTTQixEnpHIgAAAAo"]
[Thu Sep 17 15:13:16.521038 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:46848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/css/wp-content/plugins/contact-form-7/admin/includes/"] [unique_id "aqxX7OcL08BTTQixEnpHIwAAAHw"]
[Thu Sep 17 15:13:16.561565 2026] [security2:error] [pid 971102:tid 971322] [client 216.73.216.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.casualchessclub.com"] [uri "/index.php"] [unique_id "aqxX6ucL08BTTQixEnpG3gAAAFg"]
[Thu Sep 17 15:13:16.859616 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7OcL08BTTQixEnpHJwAAAF0"]
[Thu Sep 17 15:13:16.859642 2026] [security2:error] [pid 971102:tid 971327] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7OcL08BTTQixEnpHJwAAAF0"]
[Thu Sep 17 15:13:17.001674 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/editor.php"] [unique_id "aqxX7ecL08BTTQixEnpHMgAAACs"]
[Thu Sep 17 15:13:17.001789 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:46848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/editor.php"] [unique_id "aqxX7ecL08BTTQixEnpHMgAAACs"]
[Thu Sep 17 15:13:17.004611 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.130.148:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxX7ecL08BTTQixEnpHMwAAAGc"]
[Thu Sep 17 15:13:17.282113 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/help-tabs.php"] [unique_id "aqxX7ecL08BTTQixEnpHOQAAAFI"]
[Thu Sep 17 15:13:17.282231 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:46858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/help-tabs.php"] [unique_id "aqxX7ecL08BTTQixEnpHOQAAAFI"]
[Thu Sep 17 15:13:17.466283 2026] [security2:error] [pid 971102:tid 971149] [remote 47.128.29.159:36708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "techsol360.com"] [uri "/robots.txt"] [unique_id "aqxX7ecL08BTTQixEnpHPgAAYy0"]
[Thu Sep 17 15:13:17.536911 2026] [security2:error] [pid 971102:tid 971246] [client 4.240.114.86:49738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxX7ecL08BTTQixEnpHQAAAAAw"], referer: binance.com
[Thu Sep 17 15:13:17.608938 2026] [security2:error] [pid 971102:tid 971288] [client 143.244.57.120:46860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/js/"] [unique_id "aqxX7ecL08BTTQixEnpHQwAAADY"]
[Thu Sep 17 15:13:17.755349 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.130.148:35426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxX7ecL08BTTQixEnpHRgAAAHA"]
[Thu Sep 17 15:13:17.780863 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/js/index.js"] [unique_id "aqxX7ecL08BTTQixEnpHRwAAAEs"]
[Thu Sep 17 15:13:17.875645 2026] [security2:error] [pid 971102:tid 971257] [client 5.189.145.112:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxX7ecL08BTTQixEnpHTAAAABc"], referer: binance.com
[Thu Sep 17 15:13:17.933568 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:46860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/tag-generator.php"] [unique_id "aqxX7ecL08BTTQixEnpHTQAAABM"]
[Thu Sep 17 15:13:17.933719 2026] [security2:error] [pid 971102:tid 971253] [client 143.244.57.120:46860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/tag-generator.php"] [unique_id "aqxX7ecL08BTTQixEnpHTQAAABM"]
[Thu Sep 17 15:13:18.187568 2026] [security2:error] [pid 971102:tid 971307] [client 169.58.197.253:57813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ppfc.net"] [uri "/index.php"] [unique_id "aqxX7ecL08BTTQixEnpHNwAAAEk"], referer: binance.com
[Thu Sep 17 15:13:18.259619 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:46872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/welcome-panel.php"] [unique_id "aqxX7ucL08BTTQixEnpHVgAAABw"]
[Thu Sep 17 15:13:18.259763 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:46872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/admin/includes/welcome-panel.php"] [unique_id "aqxX7ucL08BTTQixEnpHVgAAABw"]
[Thu Sep 17 15:13:18.447973 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.130.148:35434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/test.php"] [unique_id "aqxX7ucL08BTTQixEnpHWwAAAFc"]
[Thu Sep 17 15:13:18.790524 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/assets/"] [unique_id "aqxX7ucL08BTTQixEnpHZAAAAHw"]
[Thu Sep 17 15:13:18.957599 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/assets/"] [unique_id "aqxX7ucL08BTTQixEnpHaAAAAF8"]
[Thu Sep 17 15:13:19.102842 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/assets/wp-content/plugins/contact-form-7/"] [unique_id "aqxX7-cL08BTTQixEnpHbgAAACo"]
[Thu Sep 17 15:13:19.222438 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:19.222456 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:19.502996 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7-cL08BTTQixEnpHcgAAAGY"]
[Thu Sep 17 15:13:19.503018 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX7-cL08BTTQixEnpHcgAAAGY"]
[Thu Sep 17 15:13:19.655755 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX7-cL08BTTQixEnpHhAAAAEc"]
[Thu Sep 17 15:13:19.752775 2026] [security2:error] [pid 971102:tid 971333] [client 4.240.114.86:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxX7-cL08BTTQixEnpHiQAAAGM"], referer: binance.com
[Thu Sep 17 15:13:19.874741 2026] [security2:error] [pid 971102:tid 971359] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX7-cL08BTTQixEnpHiwAAAH0"]
[Thu Sep 17 15:13:19.922244 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:35444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/p.php"] [unique_id "aqxX7-cL08BTTQixEnpHjQAAAA8"]
[Thu Sep 17 15:13:20.020711 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/wp-content/plugins/contact-form-7/"] [unique_id "aqxX8OcL08BTTQixEnpHlgAAAAQ"]
[Thu Sep 17 15:13:20.382451 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8OcL08BTTQixEnpHmgAAAAs"]
[Thu Sep 17 15:13:20.382478 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8OcL08BTTQixEnpHmgAAAAs"]
[Thu Sep 17 15:13:20.528166 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/block-editor/"] [unique_id "aqxX8OcL08BTTQixEnpHqQAAAEQ"]
[Thu Sep 17 15:13:20.680738 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/block-editor/index.js"] [unique_id "aqxX8OcL08BTTQixEnpHqgAAAE4"]
[Thu Sep 17 15:13:20.731602 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.130.148:35458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxX8OcL08BTTQixEnpHrAAAAHI"]
[Thu Sep 17 15:13:20.755421 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/uploads/"] [unique_id "aqxX8OcL08BTTQixEnpHrwAAADA"]
[Thu Sep 17 15:13:20.803380 2026] [security2:error] [pid 971102:tid 971308] [client 114.198.138.124:58605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8OcL08BTTQixEnpHsQAAAEo"]
[Thu Sep 17 15:13:20.803514 2026] [security2:error] [pid 971102:tid 971308] [client 114.198.138.124:58605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8OcL08BTTQixEnpHsQAAAEo"]
[Thu Sep 17 15:13:20.826641 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:46884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/capabilities.php"] [unique_id "aqxX8OcL08BTTQixEnpHsgAAABY"]
[Thu Sep 17 15:13:20.826768 2026] [security2:error] [pid 971102:tid 971256] [client 143.244.57.120:46884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/capabilities.php"] [unique_id "aqxX8OcL08BTTQixEnpHsgAAABY"]
[Thu Sep 17 15:13:21.103277 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:37694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/"] [unique_id "aqxX8ecL08BTTQixEnpHuAAAAC8"]
[Thu Sep 17 15:13:21.266603 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/"] [unique_id "aqxX8ecL08BTTQixEnpHvAAAAGY"]
[Thu Sep 17 15:13:21.268788 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:42479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ecL08BTTQixEnpHuwAAAAg"]
[Thu Sep 17 15:13:21.268867 2026] [security2:error] [pid 971102:tid 971242] [client 154.190.208.131:42479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ecL08BTTQixEnpHuwAAAAg"]
[Thu Sep 17 15:13:21.419623 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:37694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX8ecL08BTTQixEnpHwAAAAEc"]
[Thu Sep 17 15:13:21.433618 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.130.148:35470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxX8ecL08BTTQixEnpHxAAAACM"]
[Thu Sep 17 15:13:21.581050 2026] [core:error] [pid 971102:tid 971299] [client 74.7.228.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:21.581073 2026] [core:error] [pid 971102:tid 971299] [client 74.7.228.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:21.581198 2026] [security2:error] [pid 971102:tid 971299] [client 74.7.228.18:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "test.jcktax.com"] [uri "/home4/jcktaxco/public_html/index.php"] [unique_id "aqxX8ecL08BTTQixEnpHygAAAEE"]
[Thu Sep 17 15:13:21.589375 2026] [security2:error] [pid 971102:tid 971303] [client 74.7.228.18:56118] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "test.jcktax.com"] [uri "/robots.txt"] [unique_id "aqxX8ecL08BTTQixEnpHxgAARTk"]
[Thu Sep 17 15:13:21.735911 2026] [autoindex:error] [pid 971102:tid 971243] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:21.736444 2026] [security2:error] [pid 971102:tid 971243] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/cgi-sys/403.html"] [unique_id "aqxX8ecL08BTTQixEnpHzQAAAAk"]
[Thu Sep 17 15:13:21.748526 2026] [security2:error] [pid 971102:tid 971291] [client 180.102.110.140:34788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.amecoegypt.com"] [uri "/"] [unique_id "aqxX8ecL08BTTQixEnpH0AAAADk"]
[Thu Sep 17 15:13:21.748610 2026] [security2:error] [pid 971102:tid 971291] [client 180.102.110.140:34788] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.amecoegypt.com"] [uri "/"] [unique_id "aqxX8ecL08BTTQixEnpH0AAAADk"]
[Thu Sep 17 15:13:21.770141 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8ecL08BTTQixEnpHyQAAAHc"]
[Thu Sep 17 15:13:21.770170 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX8ecL08BTTQixEnpHyQAAAHc"]
[Thu Sep 17 15:13:21.909653 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:37694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/actions.php"] [unique_id "aqxX8ecL08BTTQixEnpH0wAAAEg"]
[Thu Sep 17 15:13:21.909783 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:37694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/actions.php"] [unique_id "aqxX8ecL08BTTQixEnpH0wAAAEg"]
[Thu Sep 17 15:13:22.063887 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/"] [unique_id "aqxX8ucL08BTTQixEnpH2QAAAE0"]
[Thu Sep 17 15:13:22.121184 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.130.148:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxX8ucL08BTTQixEnpH2gAAAGQ"]
[Thu Sep 17 15:13:22.191152 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:37698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/additional-settings.php"] [unique_id "aqxX8ucL08BTTQixEnpH3AAAAGg"]
[Thu Sep 17 15:13:22.191280 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:37698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/additional-settings.php"] [unique_id "aqxX8ucL08BTTQixEnpH3AAAAGg"]
[Thu Sep 17 15:13:22.317543 2026] [autoindex:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:22.318185 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/"] [unique_id "aqxX8ucL08BTTQixEnpH4AAAAHY"]
[Thu Sep 17 15:13:22.474735 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/form.php"] [unique_id "aqxX8ucL08BTTQixEnpH5gAAADM"]
[Thu Sep 17 15:13:22.474828 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:37706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/form.php"] [unique_id "aqxX8ucL08BTTQixEnpH5gAAADM"]
[Thu Sep 17 15:13:22.476239 2026] [security2:error] [pid 971102:tid 971240] [client 45.169.98.18:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH6AAAAAY"]
[Thu Sep 17 15:13:22.476337 2026] [security2:error] [pid 971102:tid 971240] [client 45.169.98.18:61992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH6AAAAAY"]
[Thu Sep 17 15:13:22.523331 2026] [security2:error] [pid 971102:tid 971268] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/css/"] [unique_id "aqxX8ucL08BTTQixEnpH6gAAACI"]
[Thu Sep 17 15:13:22.728495 2026] [autoindex:error] [pid 971102:tid 971251] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:22.729039 2026] [security2:error] [pid 971102:tid 971251] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/css/"] [unique_id "aqxX8ucL08BTTQixEnpH7gAAABE"]
[Thu Sep 17 15:13:22.776780 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/mail.php"] [unique_id "aqxX8ucL08BTTQixEnpH8gAAAHw"]
[Thu Sep 17 15:13:22.776895 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:37720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/mail.php"] [unique_id "aqxX8ucL08BTTQixEnpH8gAAAHw"]
[Thu Sep 17 15:13:22.806393 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.130.148:35484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxX8ucL08BTTQixEnpH9AAAAA0"]
[Thu Sep 17 15:13:22.894841 2026] [security2:error] [pid 971102:tid 971317] [client 186.105.232.15:57803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH9wAAAFM"]
[Thu Sep 17 15:13:22.894982 2026] [security2:error] [pid 971102:tid 971317] [client 186.105.232.15:57803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX8ucL08BTTQixEnpH9wAAAFM"]
[Thu Sep 17 15:13:22.943615 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/ID3/"] [unique_id "aqxX8ucL08BTTQixEnpH-QAAAEo"]
[Thu Sep 17 15:13:23.069813 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/messages.php"] [unique_id "aqxX8-cL08BTTQixEnpH_QAAAHU"]
[Thu Sep 17 15:13:23.069932 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:37722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/messages.php"] [unique_id "aqxX8-cL08BTTQixEnpH_QAAAHU"]
[Thu Sep 17 15:13:23.134036 2026] [autoindex:error] [pid 971102:tid 971280] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:23.134860 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/ID3/"] [unique_id "aqxX8-cL08BTTQixEnpH_wAAAC4"]
[Thu Sep 17 15:13:23.259829 2026] [security2:error] [pid 971102:tid 971281] [client 169.58.197.253:58223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxX8-cL08BTTQixEnpIAgAAAC8"], referer: binance.com
[Thu Sep 17 15:13:23.362191 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/IXR/"] [unique_id "aqxX8-cL08BTTQixEnpIBgAAAAg"]
[Thu Sep 17 15:13:23.365083 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:37734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/validator.php"] [unique_id "aqxX8-cL08BTTQixEnpIBwAAACg"]
[Thu Sep 17 15:13:23.365206 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.120:37734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/config-validator/validator.php"] [unique_id "aqxX8-cL08BTTQixEnpIBwAAACg"]
[Thu Sep 17 15:13:23.384601 2026] [security2:error] [pid 971102:tid 971304] [client 4.240.114.86:53018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxX8-cL08BTTQixEnpICAAAAEY"], referer: binance.com
[Thu Sep 17 15:13:23.498227 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.130.148:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxX8-cL08BTTQixEnpIDgAAABg"]
[Thu Sep 17 15:13:23.541521 2026] [autoindex:error] [pid 971102:tid 971270] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:23.542122 2026] [security2:error] [pid 971102:tid 971270] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/IXR/"] [unique_id "aqxX8-cL08BTTQixEnpIEAAAACQ"]
[Thu Sep 17 15:13:23.583270 2026] [security2:error] [pid 971102:tid 971326] [client 204.14.249.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxX8-cL08BTTQixEnpICwAAAFw"], referer: https://instagram.com/
[Thu Sep 17 15:13:23.739185 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Requests/"] [unique_id "aqxX8-cL08BTTQixEnpIEwAAAD0"]
[Thu Sep 17 15:13:23.767936 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:37744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-functions.php"] [unique_id "aqxX8-cL08BTTQixEnpIFgAAAFI"]
[Thu Sep 17 15:13:23.768059 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:37744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-functions.php"] [unique_id "aqxX8-cL08BTTQixEnpIFgAAAFI"]
[Thu Sep 17 15:13:23.911225 2026] [security2:error] [pid 971102:tid 971330] [client 169.58.197.253:58254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ppfc.net"] [uri "/index.php"] [unique_id "aqxX8-cL08BTTQixEnpIFwAAAGA"], referer: binance.com
[Thu Sep 17 15:13:23.948176 2026] [autoindex:error] [pid 971102:tid 971238] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:23.949326 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Requests/"] [unique_id "aqxX8-cL08BTTQixEnpIGwAAAAQ"]
[Thu Sep 17 15:13:24.062678 2026] [cgid:error] [pid 971102:tid 971211] [remote 104.28.40.132:50191] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:13:24.066119 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:37756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-template.php"] [unique_id "aqxX9OcL08BTTQixEnpIIQAAACk"]
[Thu Sep 17 15:13:24.066229 2026] [security2:error] [pid 971102:tid 971275] [client 143.244.57.120:37756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form-template.php"] [unique_id "aqxX9OcL08BTTQixEnpIIQAAACk"]
[Thu Sep 17 15:13:24.180778 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.130.148:37182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxX9OcL08BTTQixEnpIIgAAAC0"]
[Thu Sep 17 15:13:24.208344 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxX9OcL08BTTQixEnpIIwAAACE"]
[Thu Sep 17 15:13:24.364194 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:37772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form.php"] [unique_id "aqxX9OcL08BTTQixEnpIKQAAAAs"]
[Thu Sep 17 15:13:24.364304 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:37772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/contact-form.php"] [unique_id "aqxX9OcL08BTTQixEnpIKQAAAAs"]
[Thu Sep 17 15:13:24.457656 2026] [autoindex:error] [pid 971102:tid 971240] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:24.458158 2026] [security2:error] [pid 971102:tid 971240] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxX9OcL08BTTQixEnpILQAAAAY"]
[Thu Sep 17 15:13:24.646714 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/controller.php"] [unique_id "aqxX9OcL08BTTQixEnpIMwAAABU"]
[Thu Sep 17 15:13:24.646824 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:37786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/controller.php"] [unique_id "aqxX9OcL08BTTQixEnpIMwAAABU"]
[Thu Sep 17 15:13:24.680682 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/"] [unique_id "aqxX9OcL08BTTQixEnpINAAAAEw"]
[Thu Sep 17 15:13:24.864650 2026] [autoindex:error] [pid 971102:tid 971256] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:24.865185 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/"] [unique_id "aqxX9OcL08BTTQixEnpIOwAAABY"]
[Thu Sep 17 15:13:24.896397 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.130.148:37198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxX9OcL08BTTQixEnpIPAAAAB4"]
[Thu Sep 17 15:13:24.971931 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:37796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/"] [unique_id "aqxX9OcL08BTTQixEnpIQQAAADA"]
[Thu Sep 17 15:13:25.075122 2026] [security2:error] [pid 971102:tid 971348] [client 5.189.145.112:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxX9ecL08BTTQixEnpIQwAAAHI"], referer: binance.com
[Thu Sep 17 15:13:25.133279 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/"] [unique_id "aqxX9ecL08BTTQixEnpIRQAAAHo"]
[Thu Sep 17 15:13:25.163309 2026] [security2:error] [pid 971102:tid 971300] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxX9ecL08BTTQixEnpIRwAAAEI"]
[Thu Sep 17 15:13:25.254649 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.221.252:42016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxX9ecL08BTTQixEnpISgAAAFo"]
[Thu Sep 17 15:13:25.278406 2026] [security2:error] [pid 971102:tid 971336] [client 143.244.57.120:37796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX9ecL08BTTQixEnpISwAAAGY"]
[Thu Sep 17 15:13:25.410814 2026] [security2:error] [pid 971102:tid 971269] [client 192.178.6.4:38469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxX9ecL08BTTQixEnpITgAAACM"]
[Thu Sep 17 15:13:25.606086 2026] [core:error] [pid 971102:tid 971243] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:25.606106 2026] [core:error] [pid 971102:tid 971243] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:25.654367 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpIUQAAAAw"]
[Thu Sep 17 15:13:25.654400 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpIUQAAAAw"]
[Thu Sep 17 15:13:25.798406 2026] [security2:error] [pid 971102:tid 971257] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpITAAAAAg"]
[Thu Sep 17 15:13:25.798430 2026] [security2:error] [pid 971102:tid 971257] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpITAAAAAg"]
[Thu Sep 17 15:13:25.825497 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/file.php"] [unique_id "aqxX9ecL08BTTQixEnpIZQAAAC0"]
[Thu Sep 17 15:13:25.825604 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:37796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/file.php"] [unique_id "aqxX9ecL08BTTQixEnpIZQAAAC0"]
[Thu Sep 17 15:13:25.877622 2026] [authz_core:error] [pid 971102:tid 971258] [client 20.244.34.24:54639] AH01630: client denied by server configuration: /home3/airmacin/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:13:25.937077 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.221.252:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/info.php"] [unique_id "aqxX9ecL08BTTQixEnpIaQAAACk"]
[Thu Sep 17 15:13:26.054772 2026] [security2:error] [pid 971102:tid 971283] [client 156.192.234.52:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIbQAAADE"]
[Thu Sep 17 15:13:26.060120 2026] [security2:error] [pid 971102:tid 971283] [client 156.192.234.52:53294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIbQAAADE"]
[Thu Sep 17 15:13:26.113336 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/filesystem.php"] [unique_id "aqxX9ucL08BTTQixEnpIbgAAABA"]
[Thu Sep 17 15:13:26.113482 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:37800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/filesystem.php"] [unique_id "aqxX9ucL08BTTQixEnpIbgAAABA"]
[Thu Sep 17 15:13:26.194423 2026] [security2:error] [pid 971102:tid 971259] [client 162.241.226.11:15670] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxX9ucL08BTTQixEnpIbwAAABk"]
[Thu Sep 17 15:13:26.295734 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:37206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxX9ucL08BTTQixEnpIcAAAADs"]
[Thu Sep 17 15:13:26.333458 2026] [security2:error] [pid 971102:tid 971317] [client 157.230.228.220:59451] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ocdpeers.seandaviddeezyn.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX9ucL08BTTQixEnpIcwAAAFM"]
[Thu Sep 17 15:13:26.353631 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxX9ucL08BTTQixEnpIdQAAAH4"]
[Thu Sep 17 15:13:26.420165 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:37804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tag.php"] [unique_id "aqxX9ucL08BTTQixEnpIdwAAADU"]
[Thu Sep 17 15:13:26.420316 2026] [security2:error] [pid 971102:tid 971287] [client 143.244.57.120:37804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tag.php"] [unique_id "aqxX9ucL08BTTQixEnpIdwAAADU"]
[Thu Sep 17 15:13:26.479271 2026] [security2:error] [pid 971102:tid 971244] [client 157.230.228.220:59453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ocdpeers.seandaviddeezyn.com"] [uri "/"] [unique_id "aqxX9ucL08BTTQixEnpIegAAAAo"]
[Thu Sep 17 15:13:26.576680 2026] [security2:error] [pid 971102:tid 971321] [client 115.244.164.14:58040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIfAAAAFc"]
[Thu Sep 17 15:13:26.576812 2026] [security2:error] [pid 971102:tid 971321] [client 115.244.164.14:58040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxX9ucL08BTTQixEnpIfAAAAFc"]
[Thu Sep 17 15:13:26.635557 2026] [security2:error] [pid 971102:tid 971343] [client 157.230.228.220:59454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ocdpeers.seandaviddeezyn.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxX9ucL08BTTQixEnpIfQAAAG0"]
[Thu Sep 17 15:13:26.639199 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.221.252:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/php.php"] [unique_id "aqxX9ucL08BTTQixEnpIfgAAABM"]
[Thu Sep 17 15:13:26.712758 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:37816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tags-manager.php"] [unique_id "aqxX9ucL08BTTQixEnpIgwAAAEI"]
[Thu Sep 17 15:13:26.712856 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:37816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/form-tags-manager.php"] [unique_id "aqxX9ucL08BTTQixEnpIgwAAAEI"]
[Thu Sep 17 15:13:26.995782 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.130.148:37210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxX9ucL08BTTQixEnpIigAAAF8"]
[Thu Sep 17 15:13:26.997126 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/formatting.php"] [unique_id "aqxX9ucL08BTTQixEnpIiwAAAD4"]
[Thu Sep 17 15:13:26.997224 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:37820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/formatting.php"] [unique_id "aqxX9ucL08BTTQixEnpIiwAAAD4"]
[Thu Sep 17 15:13:27.014320 2026] [security2:error] [pid 971102:tid 971304] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ucL08BTTQixEnpIhwAAAEY"]
[Thu Sep 17 15:13:27.014348 2026] [security2:error] [pid 971102:tid 971304] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9ucL08BTTQixEnpIhwAAAEY"]
[Thu Sep 17 15:13:27.229192 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:59539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX9-cL08BTTQixEnpIjwAAAAk"]
[Thu Sep 17 15:13:27.229306 2026] [security2:error] [pid 971102:tid 971243] [client 185.55.149.49:59539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxX9-cL08BTTQixEnpIjwAAAAk"]
[Thu Sep 17 15:13:27.284031 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/functions.php"] [unique_id "aqxX9-cL08BTTQixEnpIkgAAAA4"]
[Thu Sep 17 15:13:27.284146 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/functions.php"] [unique_id "aqxX9-cL08BTTQixEnpIkgAAAA4"]
[Thu Sep 17 15:13:27.324858 2026] [security2:error] [pid 971102:tid 971274] [client 34.166.221.252:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/i.php"] [unique_id "aqxX9-cL08BTTQixEnpIlAAAACg"]
[Thu Sep 17 15:13:27.458749 2026] [security2:error] [pid 971102:tid 971355] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxX9-cL08BTTQixEnpIlwAAAHk"]
[Thu Sep 17 15:13:27.562000 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:37830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/html-formatter.php"] [unique_id "aqxX9-cL08BTTQixEnpImQAAAD8"]
[Thu Sep 17 15:13:27.562152 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:37830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/html-formatter.php"] [unique_id "aqxX9-cL08BTTQixEnpImQAAAD8"]
[Thu Sep 17 15:13:27.724211 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.130.148:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxX9-cL08BTTQixEnpImwAAAAQ"]
[Thu Sep 17 15:13:27.805025 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9-cL08BTTQixEnpImgAAAC0"]
[Thu Sep 17 15:13:27.805052 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX9-cL08BTTQixEnpImgAAAC0"]
[Thu Sep 17 15:13:27.838213 2026] [security2:error] [pid 971102:tid 971298] [client 167.99.159.16:33358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX9ecL08BTTQixEnpIVwAAAEA"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:27.863440 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/integration.php"] [unique_id "aqxX9-cL08BTTQixEnpIoAAAABk"]
[Thu Sep 17 15:13:27.863532 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:37842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/integration.php"] [unique_id "aqxX9-cL08BTTQixEnpIoAAAABk"]
[Thu Sep 17 15:13:28.025840 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.221.252:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxX-OcL08BTTQixEnpIpAAAAHY"]
[Thu Sep 17 15:13:28.166521 2026] [security2:error] [pid 971102:tid 971254] [client 143.244.57.120:37856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/js/"] [unique_id "aqxX-OcL08BTTQixEnpIpQAAABQ"]
[Thu Sep 17 15:13:28.250967 2026] [security2:error] [pid 971102:tid 971255] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxX-OcL08BTTQixEnpIpwAAABU"]
[Thu Sep 17 15:13:28.332097 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/js/index.js"] [unique_id "aqxX-OcL08BTTQixEnpIqwAAAG8"]
[Thu Sep 17 15:13:28.414434 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.130.148:37232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxX-OcL08BTTQixEnpIrAAAAAU"]
[Thu Sep 17 15:13:28.429506 2026] [autoindex:error] [pid 971102:tid 971312] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:28.430058 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxX-OcL08BTTQixEnpIrQAAAE4"]
[Thu Sep 17 15:13:28.490625 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/l10n.php"] [unique_id "aqxX-OcL08BTTQixEnpIsAAAABE"]
[Thu Sep 17 15:13:28.490755 2026] [security2:error] [pid 971102:tid 971251] [client 143.244.57.120:37856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/l10n.php"] [unique_id "aqxX-OcL08BTTQixEnpIsAAAABE"]
[Thu Sep 17 15:13:28.729915 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxX-OcL08BTTQixEnpItAAAADU"]
[Thu Sep 17 15:13:28.730193 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.221.252:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxX-OcL08BTTQixEnpItQAAAGc"]
[Thu Sep 17 15:13:28.756874 2026] [security2:error] [pid 971102:tid 971358] [client 104.28.198.244:22706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX-OcL08BTTQixEnpItgAAAHw"]
[Thu Sep 17 15:13:28.757038 2026] [security2:error] [pid 971102:tid 971358] [client 104.28.198.244:22706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxX-OcL08BTTQixEnpItgAAAHw"]
[Thu Sep 17 15:13:28.786271 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:37870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail-tag.php"] [unique_id "aqxX-OcL08BTTQixEnpIuQAAAE8"]
[Thu Sep 17 15:13:28.786369 2026] [security2:error] [pid 971102:tid 971313] [client 143.244.57.120:37870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail-tag.php"] [unique_id "aqxX-OcL08BTTQixEnpIuQAAAE8"]
[Thu Sep 17 15:13:29.018644 2026] [autoindex:error] [pid 971102:tid 971272] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:29.019162 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxX-ecL08BTTQixEnpIvQAAACY"]
[Thu Sep 17 15:13:29.131990 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.130.148:37244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxX-ecL08BTTQixEnpIwAAAAB4"]
[Thu Sep 17 15:13:29.133008 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:37872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail.php"] [unique_id "aqxX-ecL08BTTQixEnpIwQAAAHI"]
[Thu Sep 17 15:13:29.133093 2026] [security2:error] [pid 971102:tid 971348] [client 143.244.57.120:37872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/mail.php"] [unique_id "aqxX-ecL08BTTQixEnpIwQAAAHI"]
[Thu Sep 17 15:13:29.240476 2026] [security2:error] [pid 971102:tid 971323] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/blocks/"] [unique_id "aqxX-ecL08BTTQixEnpIwgAAAFk"]
[Thu Sep 17 15:13:29.243956 2026] [security2:error] [pid 971102:tid 971341] [client 167.99.159.16:33366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX-ecL08BTTQixEnpIvwAAAGs"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:29.423307 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:37880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pipe.php"] [unique_id "aqxX-ecL08BTTQixEnpIxgAAAFg"]
[Thu Sep 17 15:13:29.423454 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:37880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pipe.php"] [unique_id "aqxX-ecL08BTTQixEnpIxgAAAFg"]
[Thu Sep 17 15:13:29.424266 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.221.252:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/test.php"] [unique_id "aqxX-ecL08BTTQixEnpIyAAAAAM"]
[Thu Sep 17 15:13:29.435653 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxX-ecL08BTTQixEnpIxwAAAAA"]
[Thu Sep 17 15:13:29.638647 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/certificates/"] [unique_id "aqxX-ecL08BTTQixEnpIzwAAAGM"]
[Thu Sep 17 15:13:29.714274 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pocket-holder.php"] [unique_id "aqxX-ecL08BTTQixEnpI0AAAAA4"]
[Thu Sep 17 15:13:29.714382 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.120:37892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/pocket-holder.php"] [unique_id "aqxX-ecL08BTTQixEnpI0AAAAA4"]
[Thu Sep 17 15:13:29.781984 2026] [security2:error] [pid 971102:tid 971273] [client 20.244.34.24:58401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxX-ecL08BTTQixEnpI0wAAACc"], referer: binance.com
[Thu Sep 17 15:13:29.834904 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.130.148:37246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxX-ecL08BTTQixEnpI1AAAADo"]
[Thu Sep 17 15:13:29.868751 2026] [autoindex:error] [pid 971102:tid 971274] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:29.869256 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/certificates/"] [unique_id "aqxX-ecL08BTTQixEnpI1QAAACg"]
[Thu Sep 17 15:13:30.003770 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/rest-api.php"] [unique_id "aqxX-ucL08BTTQixEnpI2wAAAHs"]
[Thu Sep 17 15:13:30.003878 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:35440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/rest-api.php"] [unique_id "aqxX-ucL08BTTQixEnpI2wAAAHs"]
[Thu Sep 17 15:13:30.138596 2026] [security2:error] [pid 971102:tid 971265] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/customize/"] [unique_id "aqxX-ucL08BTTQixEnpI3QAAAB8"]
[Thu Sep 17 15:13:30.295960 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:35454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/shortcodes.php"] [unique_id "aqxX-ucL08BTTQixEnpI4gAAAH8"]
[Thu Sep 17 15:13:30.296071 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:35454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/shortcodes.php"] [unique_id "aqxX-ucL08BTTQixEnpI4gAAAH8"]
[Thu Sep 17 15:13:30.351278 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.221.252:35624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/p.php"] [unique_id "aqxX-ucL08BTTQixEnpI5AAAABw"]
[Thu Sep 17 15:13:30.363008 2026] [autoindex:error] [pid 971102:tid 971250] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:30.363610 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/customize/"] [unique_id "aqxX-ucL08BTTQixEnpI4wAAABA"]
[Thu Sep 17 15:13:30.576525 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:35458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/special-mail-tags.php"] [unique_id "aqxX-ucL08BTTQixEnpI6wAAAGw"]
[Thu Sep 17 15:13:30.576649 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.120:35458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/special-mail-tags.php"] [unique_id "aqxX-ucL08BTTQixEnpI6wAAAGw"]
[Thu Sep 17 15:13:30.605736 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:30.605757 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:30.636279 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/fonts/"] [unique_id "aqxX-ucL08BTTQixEnpI7QAAAGg"]
[Thu Sep 17 15:13:30.842761 2026] [autoindex:error] [pid 971102:tid 971317] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:30.843271 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/fonts/"] [unique_id "aqxX-ucL08BTTQixEnpI8QAAAFM"]
[Thu Sep 17 15:13:30.862006 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/submission.php"] [unique_id "aqxX-ucL08BTTQixEnpI8gAAAH4"]
[Thu Sep 17 15:13:30.862124 2026] [security2:error] [pid 971102:tid 971360] [client 143.244.57.120:35474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/submission.php"] [unique_id "aqxX-ucL08BTTQixEnpI8gAAAH4"]
[Thu Sep 17 15:13:31.038740 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.221.252:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxX--cL08BTTQixEnpI9gAAAHA"]
[Thu Sep 17 15:13:31.045971 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/images/"] [unique_id "aqxX--cL08BTTQixEnpI9wAAAAo"]
[Thu Sep 17 15:13:31.085779 2026] [autoindex:error] [pid 971102:tid 971271] [client 106.63.26.22:6955] AH01276: Cannot serve directory /home1/vxmhuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:31.151051 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/"] [unique_id "aqxX--cL08BTTQixEnpI-QAAAFE"]
[Thu Sep 17 15:13:31.169248 2026] [security2:error] [pid 971102:tid 971313] [client 169.58.197.253:58755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxX--cL08BTTQixEnpI-gAAAE8"], referer: binance.com
[Thu Sep 17 15:13:31.319131 2026] [autoindex:error] [pid 971102:tid 971348] [client 85.204.70.116:40012] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:31.319764 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/images/"] [unique_id "aqxX--cL08BTTQixEnpI_QAAAHI"]
[Thu Sep 17 15:13:31.329851 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/"] [unique_id "aqxX--cL08BTTQixEnpI_AAAACY"]
[Thu Sep 17 15:13:31.428395 2026] [core:error] [pid 971102:tid 971260] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:31.428415 2026] [core:error] [pid 971102:tid 971260] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:31.475038 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/wp-content/plugins/contact-form-7/includes/"] [unique_id "aqxX--cL08BTTQixEnpJCgAAAAA"]
[Thu Sep 17 15:13:31.550997 2026] [autoindex:error] [pid 971102:tid 971330] [client 85.204.70.116:60250] AH01276: Cannot serve directory /home1/zainridg/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:31.551989 2026] [security2:error] [pid 971102:tid 971330] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/.well-known/"] [unique_id "aqxX--cL08BTTQixEnpJCwAAAGA"]
[Thu Sep 17 15:13:31.715943 2026] [security2:error] [pid 971102:tid 971256] [client 34.166.221.252:35640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxX--cL08BTTQixEnpJEAAAABY"]
[Thu Sep 17 15:13:31.770026 2026] [security2:error] [pid 971102:tid 971286] [client 154.190.208.131:41737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJEgAAADQ"]
[Thu Sep 17 15:13:31.770147 2026] [security2:error] [pid 971102:tid 971286] [client 154.190.208.131:41737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJEgAAADQ"]
[Thu Sep 17 15:13:31.820126 2026] [security2:error] [pid 971102:tid 971273] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/ALFA_DATA/"] [unique_id "aqxX--cL08BTTQixEnpJFQAAACc"]
[Thu Sep 17 15:13:31.852641 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX--cL08BTTQixEnpJDgAAAGM"]
[Thu Sep 17 15:13:31.852671 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX--cL08BTTQixEnpJDgAAAGM"]
[Thu Sep 17 15:13:31.863284 2026] [security2:error] [pid 971102:tid 971351] [client 114.198.138.124:59231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJFgAAAHU"]
[Thu Sep 17 15:13:31.863600 2026] [security2:error] [pid 971102:tid 971351] [client 114.198.138.124:59231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxX--cL08BTTQixEnpJFgAAAHU"]
[Thu Sep 17 15:13:32.001646 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/js/"] [unique_id "aqxX_OcL08BTTQixEnpJGQAAAE0"]
[Thu Sep 17 15:13:32.144688 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.130.148:37272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxX_OcL08BTTQixEnpJHAAAAHs"]
[Thu Sep 17 15:13:32.157216 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/js/index.js"] [unique_id "aqxX_OcL08BTTQixEnpJHQAAACo"]
[Thu Sep 17 15:13:32.170041 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJGwAAAEc"]
[Thu Sep 17 15:13:32.170066 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJGwAAAEc"]
[Thu Sep 17 15:13:32.301982 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/"] [unique_id "aqxX_OcL08BTTQixEnpJIAAAADw"]
[Thu Sep 17 15:13:32.427251 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.221.252:35648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxX_OcL08BTTQixEnpJIgAAAGk"]
[Thu Sep 17 15:13:32.474290 2026] [security2:error] [pid 971102:tid 971262] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/"] [unique_id "aqxX_OcL08BTTQixEnpJIwAAABw"]
[Thu Sep 17 15:13:32.535224 2026] [security2:error] [pid 971102:tid 971309] [client 5.189.145.112:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxX_OcL08BTTQixEnpJKAAAAEs"], referer: binance.com
[Thu Sep 17 15:13:32.623040 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/wp-content/plugins/contact-form-7/includes/swv/"] [unique_id "aqxX_OcL08BTTQixEnpJKQAAAEI"]
[Thu Sep 17 15:13:32.637619 2026] [security2:error] [pid 971102:tid 971302] [client 181.91.87.22:19225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJJwAAAEQ"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:32.851024 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.130.148:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxX_OcL08BTTQixEnpJLQAAAAs"]
[Thu Sep 17 15:13:32.979766 2026] [security2:error] [pid 971102:tid 971320] [client 45.169.98.18:62740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_OcL08BTTQixEnpJMAAAAFY"]
[Thu Sep 17 15:13:32.979870 2026] [security2:error] [pid 971102:tid 971320] [client 45.169.98.18:62740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_OcL08BTTQixEnpJMAAAAFY"]
[Thu Sep 17 15:13:32.997219 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJLAAAAEM"]
[Thu Sep 17 15:13:32.997243 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_OcL08BTTQixEnpJLAAAAEM"]
[Thu Sep 17 15:13:33.023999 2026] [security2:error] [pid 971102:tid 971291] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/.well-knownold/"] [unique_id "aqxX_ecL08BTTQixEnpJMQAAADk"]
[Thu Sep 17 15:13:33.118026 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.221.252:35650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxX_ecL08BTTQixEnpJMwAAAG8"]
[Thu Sep 17 15:13:33.141463 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/abstract-rules.php"] [unique_id "aqxX_ecL08BTTQixEnpJNAAAAFM"]
[Thu Sep 17 15:13:33.141575 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:35476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/abstract-rules.php"] [unique_id "aqxX_ecL08BTTQixEnpJNAAAAFM"]
[Thu Sep 17 15:13:33.403940 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJNQAAAEE"]
[Thu Sep 17 15:13:33.403970 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJNQAAAEE"]
[Thu Sep 17 15:13:33.430761 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:35480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/"] [unique_id "aqxX_ecL08BTTQixEnpJOQAAAFE"]
[Thu Sep 17 15:13:33.477030 2026] [security2:error] [pid 971102:tid 971271] [client 74.7.175.174:42126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gmx.zga.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxX_ecL08BTTQixEnpJPAAAACU"]
[Thu Sep 17 15:13:33.552985 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.130.148:37284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxX_ecL08BTTQixEnpJPwAAAHw"]
[Thu Sep 17 15:13:33.603648 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/"] [unique_id "aqxX_ecL08BTTQixEnpJQAAAAB4"]
[Thu Sep 17 15:13:33.747496 2026] [security2:error] [pid 971102:tid 971324] [client 143.244.57.120:35480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/wp-content/plugins/contact-form-7/includes/swv/php/"] [unique_id "aqxX_ecL08BTTQixEnpJQgAAAFo"]
[Thu Sep 17 15:13:33.807304 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.221.252:35664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxX_ecL08BTTQixEnpJQwAAAHg"]
[Thu Sep 17 15:13:33.808371 2026] [security2:error] [pid 971102:tid 971237] [client 4.240.114.86:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxX_ecL08BTTQixEnpJRAAAAAM"], referer: binance.com
[Thu Sep 17 15:13:33.866079 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.116:60250] AH01276: Cannot serve directory /home1/zainridg/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:13:33.866570 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxX_ecL08BTTQixEnpJRQAAACA"]
[Thu Sep 17 15:13:33.933169 2026] [security2:error] [pid 971102:tid 971343] [client 186.105.232.15:58403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_ecL08BTTQixEnpJSQAAAG0"]
[Thu Sep 17 15:13:33.933277 2026] [security2:error] [pid 971102:tid 971343] [client 186.105.232.15:58403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxX_ecL08BTTQixEnpJSQAAAG0"]
[Thu Sep 17 15:13:34.090404 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJRgAAAGA"]
[Thu Sep 17 15:13:34.090428 2026] [security2:error] [pid 971102:tid 971330] [client 143.244.57.120:51514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxX_ecL08BTTQixEnpJRgAAAGA"]
[Thu Sep 17 15:13:34.128108 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/cgi-bin/"] [unique_id "aqxX_ucL08BTTQixEnpJTwAAABY"]
[Thu Sep 17 15:13:34.233884 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:35480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/all.php"] [unique_id "aqxX_ucL08BTTQixEnpJUgAAAF8"]
[Thu Sep 17 15:13:34.233986 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:35480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/all.php"] [unique_id "aqxX_ucL08BTTQixEnpJUgAAAF8"]
[Thu Sep 17 15:13:34.256760 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.130.148:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxX_ucL08BTTQixEnpJUwAAAFg"]
[Thu Sep 17 15:13:34.340670 2026] [cgid:error] [pid 971102:tid 971281] [client 85.204.70.116:40012] AH01265: stderr from /home1/zainridg/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:13:34.341181 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/cgi-bin/"] [unique_id "aqxX_ucL08BTTQixEnpJVgAAAC8"]
[Thu Sep 17 15:13:34.518007 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.221.252:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxX_ucL08BTTQixEnpJXgAAADo"]
[Thu Sep 17 15:13:34.524866 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/any.php"] [unique_id "aqxX_ucL08BTTQixEnpJXwAAAE0"]
[Thu Sep 17 15:13:34.524992 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.120:35490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/any.php"] [unique_id "aqxX_ucL08BTTQixEnpJXwAAAE0"]
[Thu Sep 17 15:13:34.539483 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/index/"] [unique_id "aqxX_ucL08BTTQixEnpJYAAAABg"]
[Thu Sep 17 15:13:34.819346 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:35492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/date.php"] [unique_id "aqxX_ucL08BTTQixEnpJZQAAABc"]
[Thu Sep 17 15:13:34.819452 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:35492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/date.php"] [unique_id "aqxX_ucL08BTTQixEnpJZQAAABc"]
[Thu Sep 17 15:13:34.979079 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.130.148:45594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxX_ucL08BTTQixEnpJaQAAAH0"]
[Thu Sep 17 15:13:35.113292 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/dayofweek.php"] [unique_id "aqxX_-cL08BTTQixEnpJawAAAEQ"]
[Thu Sep 17 15:13:35.113405 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:35496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/dayofweek.php"] [unique_id "aqxX_-cL08BTTQixEnpJawAAAEQ"]
[Thu Sep 17 15:13:35.216813 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.221.252:36870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxX_-cL08BTTQixEnpJbAAAAEs"]
[Thu Sep 17 15:13:35.404134 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/email.php"] [unique_id "aqxX_-cL08BTTQixEnpJbgAAABA"]
[Thu Sep 17 15:13:35.404305 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:35512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/email.php"] [unique_id "aqxX_-cL08BTTQixEnpJbgAAABA"]
[Thu Sep 17 15:13:35.538970 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_-cL08BTTQixEnpJbQAAADg"]
[Thu Sep 17 15:13:35.538993 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxX_-cL08BTTQixEnpJbQAAADg"]
[Thu Sep 17 15:13:35.626826 2026] [security2:error] [pid 971102:tid 971284] [client 179.36.194.118:60394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxX_-cL08BTTQixEnpJcwAAADI"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:13:35.683669 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.130.148:45602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxX_-cL08BTTQixEnpJdgAAAAY"]
[Thu Sep 17 15:13:35.693318 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/enum.php"] [unique_id "aqxX_-cL08BTTQixEnpJdwAAAGU"]
[Thu Sep 17 15:13:35.693429 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/enum.php"] [unique_id "aqxX_-cL08BTTQixEnpJdwAAAGU"]
[Thu Sep 17 15:13:35.982350 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/file.php"] [unique_id "aqxX_-cL08BTTQixEnpJfAAAAHA"]
[Thu Sep 17 15:13:35.982468 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:35520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/file.php"] [unique_id "aqxX_-cL08BTTQixEnpJfAAAAHA"]
[Thu Sep 17 15:13:36.159566 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.221.252:36886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxYAOcL08BTTQixEnpJgAAAAFs"]
[Thu Sep 17 15:13:36.247673 2026] [security2:error] [pid 971102:tid 971327] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/id/"] [unique_id "aqxYAOcL08BTTQixEnpJgQAAAF0"]
[Thu Sep 17 15:13:36.273521 2026] [security2:error] [pid 971102:tid 971267] [client 143.244.57.120:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxdate.php"] [unique_id "aqxYAOcL08BTTQixEnpJggAAACE"]
[Thu Sep 17 15:13:36.273618 2026] [security2:error] [pid 971102:tid 971267] [client 143.244.57.120:35528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxdate.php"] [unique_id "aqxYAOcL08BTTQixEnpJggAAACE"]
[Thu Sep 17 15:13:36.388171 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:45610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYAOcL08BTTQixEnpJhwAAAA8"]
[Thu Sep 17 15:13:36.571483 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxfilesize.php"] [unique_id "aqxYAOcL08BTTQixEnpJjAAAAEU"]
[Thu Sep 17 15:13:36.571605 2026] [security2:error] [pid 971102:tid 971303] [client 143.244.57.120:35542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxfilesize.php"] [unique_id "aqxYAOcL08BTTQixEnpJjAAAAEU"]
[Thu Sep 17 15:13:36.572258 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAOcL08BTTQixEnpJiAAAABo"]
[Thu Sep 17 15:13:36.572276 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAOcL08BTTQixEnpJiAAAABo"]
[Thu Sep 17 15:13:36.592185 2026] [security2:error] [pid 971102:tid 971324] [client 185.191.171.11:22742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tab-funkenwerk.com"] [uri "/index.html"] [unique_id "aqxYAOcL08BTTQixEnpJjQAAAFo"]
[Thu Sep 17 15:13:36.592331 2026] [security2:error] [pid 971102:tid 971324] [client 185.191.171.11:22742] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tab-funkenwerk.com"] [uri "/index.html"] [unique_id "aqxYAOcL08BTTQixEnpJjQAAAFo"]
[Thu Sep 17 15:13:36.655172 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:53885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAOcL08BTTQixEnpJjgAAAFA"]
[Thu Sep 17 15:13:36.655700 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:53885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAOcL08BTTQixEnpJjgAAAFA"]
[Thu Sep 17 15:13:36.858550 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.221.252:36902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxYAOcL08BTTQixEnpJlQAAACA"]
[Thu Sep 17 15:13:36.864356 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:35548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxitems.php"] [unique_id "aqxYAOcL08BTTQixEnpJlgAAAEY"]
[Thu Sep 17 15:13:36.864471 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:35548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxitems.php"] [unique_id "aqxYAOcL08BTTQixEnpJlgAAAEY"]
[Thu Sep 17 15:13:37.093919 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.130.148:45620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYAecL08BTTQixEnpJnAAAAD0"]
[Thu Sep 17 15:13:37.141768 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/www/"] [unique_id "aqxYAecL08BTTQixEnpJnQAAACg"]
[Thu Sep 17 15:13:37.154305 2026] [security2:error] [pid 971102:tid 971241] [client 115.244.164.14:58701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJngAAAAc"]
[Thu Sep 17 15:13:37.154487 2026] [security2:error] [pid 971102:tid 971241] [client 115.244.164.14:58701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJngAAAAc"]
[Thu Sep 17 15:13:37.155678 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxlength.php"] [unique_id "aqxYAecL08BTTQixEnpJnwAAAF4"]
[Thu Sep 17 15:13:37.155766 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxlength.php"] [unique_id "aqxYAecL08BTTQixEnpJnwAAAF4"]
[Thu Sep 17 15:13:37.455830 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:35568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxnumber.php"] [unique_id "aqxYAecL08BTTQixEnpJpwAAAGk"]
[Thu Sep 17 15:13:37.455939 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:35568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/maxnumber.php"] [unique_id "aqxYAecL08BTTQixEnpJpwAAAGk"]
[Thu Sep 17 15:13:37.497005 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAecL08BTTQixEnpJoAAAAEc"]
[Thu Sep 17 15:13:37.497033 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAecL08BTTQixEnpJoAAAAEc"]
[Thu Sep 17 15:13:37.522983 2026] [access_compat:error] [pid 971102:tid 971288] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/category
[Thu Sep 17 15:13:37.543987 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.221.252:36914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxYAecL08BTTQixEnpJrQAAAHs"]
[Thu Sep 17 15:13:37.544138 2026] [security2:error] [pid 971102:tid 971351] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bridge2lifeteenhomes.org"] [uri "/index.php"] [unique_id "aqxX_ucL08BTTQixEnpJVwAAAHU"]
[Thu Sep 17 15:13:37.546297 2026] [security2:error] [pid 971102:tid 971349] [client 74.7.228.63:37840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bridge2lifeteenhomes.org"] [uri "/robots.txt"] [unique_id "aqxX_ucL08BTTQixEnpJUAAAcwM"]
[Thu Sep 17 15:13:37.743063 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:35570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/mindate.php"] [unique_id "aqxYAecL08BTTQixEnpJrwAAAFI"]
[Thu Sep 17 15:13:37.743197 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:35570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/mindate.php"] [unique_id "aqxYAecL08BTTQixEnpJrwAAAFI"]
[Thu Sep 17 15:13:37.784910 2026] [security2:error] [pid 971102:tid 971277] [client 34.166.130.148:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYAecL08BTTQixEnpJsAAAACs"]
[Thu Sep 17 15:13:37.903967 2026] [security2:error] [pid 971102:tid 971127] [remote 45.157.54.43:10760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtQAAcRc"]
[Thu Sep 17 15:13:37.904214 2026] [security2:error] [pid 971102:tid 971347] [client 45.157.54.43:10760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtQAAcRc"]
[Thu Sep 17 15:13:37.931101 2026] [security2:error] [pid 971102:tid 971275] [client 185.55.149.49:60237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtgAAACk"]
[Thu Sep 17 15:13:37.931218 2026] [security2:error] [pid 971102:tid 971275] [client 185.55.149.49:60237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYAecL08BTTQixEnpJtgAAACk"]
[Thu Sep 17 15:13:37.951498 2026] [security2:error] [pid 971102:tid 971356] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/web/"] [unique_id "aqxYAecL08BTTQixEnpJuQAAAHo"]
[Thu Sep 17 15:13:38.038688 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minfilesize.php"] [unique_id "aqxYAucL08BTTQixEnpJuwAAACc"]
[Thu Sep 17 15:13:38.038851 2026] [security2:error] [pid 971102:tid 971273] [client 143.244.57.120:35582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minfilesize.php"] [unique_id "aqxYAucL08BTTQixEnpJuwAAACc"]
[Thu Sep 17 15:13:38.110437 2026] [security2:error] [pid 971102:tid 971315] [client 147.182.136.147:57301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxYAucL08BTTQixEnpJvAAAAFE"]
[Thu Sep 17 15:13:38.223362 2026] [security2:error] [pid 971102:tid 971337] [client 34.166.221.252:36920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxYAucL08BTTQixEnpJvgAAAGc"]
[Thu Sep 17 15:13:38.260345 2026] [security2:error] [pid 971102:tid 971350] [client 147.182.136.147:57321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/"] [unique_id "aqxYAucL08BTTQixEnpJvwAAAHQ"]
[Thu Sep 17 15:13:38.317032 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:35592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minitems.php"] [unique_id "aqxYAucL08BTTQixEnpJwwAAADc"]
[Thu Sep 17 15:13:38.317140 2026] [security2:error] [pid 971102:tid 971289] [client 143.244.57.120:35592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minitems.php"] [unique_id "aqxYAucL08BTTQixEnpJwwAAADc"]
[Thu Sep 17 15:13:38.407352 2026] [security2:error] [pid 971102:tid 971260] [client 147.182.136.147:57328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxYAucL08BTTQixEnpJxQAAABo"]
[Thu Sep 17 15:13:38.485337 2026] [security2:error] [pid 971102:tid 971129] [remote 45.157.54.43:11542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAucL08BTTQixEnpJyQAAChk"]
[Thu Sep 17 15:13:38.485518 2026] [security2:error] [pid 971102:tid 971244] [client 45.157.54.43:11542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kippremote.com"] [uri "/xmlrpc.php"] [unique_id "aqxYAucL08BTTQixEnpJyQAAChk"]
[Thu Sep 17 15:13:38.488620 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.130.148:45646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYAucL08BTTQixEnpJygAAADs"]
[Thu Sep 17 15:13:38.587243 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAucL08BTTQixEnpJxgAAAFo"]
[Thu Sep 17 15:13:38.587272 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYAucL08BTTQixEnpJxgAAAFo"]
[Thu Sep 17 15:13:38.610132 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:35600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minlength.php"] [unique_id "aqxYAucL08BTTQixEnpJzQAAAC0"]
[Thu Sep 17 15:13:38.610255 2026] [security2:error] [pid 971102:tid 971279] [client 143.244.57.120:35600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minlength.php"] [unique_id "aqxYAucL08BTTQixEnpJzQAAAC0"]
[Thu Sep 17 15:13:38.904775 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minnumber.php"] [unique_id "aqxYAucL08BTTQixEnpJ0wAAAF4"]
[Thu Sep 17 15:13:38.904907 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:35616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/minnumber.php"] [unique_id "aqxYAucL08BTTQixEnpJ0wAAAF4"]
[Thu Sep 17 15:13:38.904979 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.221.252:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxYAucL08BTTQixEnpJ1AAAAFk"]
[Thu Sep 17 15:13:38.943061 2026] [security2:error] [pid 971102:tid 971292] [client 5.189.145.112:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxYAucL08BTTQixEnpJ1QAAADo"], referer: binance.com
[Thu Sep 17 15:13:38.990554 2026] [security2:error] [pid 971102:tid 971326] [client 210.222.43.21:57826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYAucL08BTTQixEnpJ0AAAAFw"], referer: http://talent-in-borders.com/Www
[Thu Sep 17 15:13:39.143455 2026] [security2:error] [pid 971102:tid 971322] [client 4.240.114.86:56404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxYA-cL08BTTQixEnpJ2wAAAFg"], referer: binance.com
[Thu Sep 17 15:13:39.193181 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:35618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/number.php"] [unique_id "aqxYA-cL08BTTQixEnpJ3gAAAEc"]
[Thu Sep 17 15:13:39.193277 2026] [security2:error] [pid 971102:tid 971305] [client 143.244.57.120:35618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/number.php"] [unique_id "aqxYA-cL08BTTQixEnpJ3gAAAEc"]
[Thu Sep 17 15:13:39.198905 2026] [security2:error] [pid 971102:tid 971280] [client 34.166.130.148:45654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYA-cL08BTTQixEnpJ3wAAAC4"]
[Thu Sep 17 15:13:39.296221 2026] [security2:error] [pid 971102:tid 971229] [remote 216.73.217.142:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYA-cL08BTTQixEnpJ4wAABHw"]
[Thu Sep 17 15:13:39.474809 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:35620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/required.php"] [unique_id "aqxYA-cL08BTTQixEnpJ7AAAAEI"]
[Thu Sep 17 15:13:39.474933 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:35620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/required.php"] [unique_id "aqxYA-cL08BTTQixEnpJ7AAAAEI"]
[Thu Sep 17 15:13:39.515982 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/uploads/"] [unique_id "aqxYA-cL08BTTQixEnpJ7QAAAEQ"]
[Thu Sep 17 15:13:39.598058 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.221.252:36938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8AAAADQ"]
[Thu Sep 17 15:13:39.756825 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/requiredfile.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8wAAAGU"]
[Thu Sep 17 15:13:39.756927 2026] [security2:error] [pid 971102:tid 971335] [client 143.244.57.120:35628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/requiredfile.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8wAAAGU"]
[Thu Sep 17 15:13:39.893894 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.130.148:45658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYA-cL08BTTQixEnpJ-wAAAFI"]
[Thu Sep 17 15:13:39.894155 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8gAAAAs"]
[Thu Sep 17 15:13:39.894173 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ8gAAAAs"]
[Thu Sep 17 15:13:40.089988 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:49000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/stepnumber.php"] [unique_id "aqxYBOcL08BTTQixEnpJ_wAAAE4"]
[Thu Sep 17 15:13:40.090111 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:49000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/stepnumber.php"] [unique_id "aqxYBOcL08BTTQixEnpJ_wAAAE4"]
[Thu Sep 17 15:13:40.356910 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/upload/"] [unique_id "aqxYBOcL08BTTQixEnpKAwAAABM"]
[Thu Sep 17 15:13:40.382477 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:49008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/tel.php"] [unique_id "aqxYBOcL08BTTQixEnpKBAAAAB4"]
[Thu Sep 17 15:13:40.382642 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:49008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/tel.php"] [unique_id "aqxYBOcL08BTTQixEnpKBAAAAB4"]
[Thu Sep 17 15:13:40.593881 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.130.148:45660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYBOcL08BTTQixEnpKDAAAAEw"]
[Thu Sep 17 15:13:40.673810 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:49020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/time.php"] [unique_id "aqxYBOcL08BTTQixEnpKDQAAAAA"]
[Thu Sep 17 15:13:40.673950 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:49020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/time.php"] [unique_id "aqxYBOcL08BTTQixEnpKDQAAAAA"]
[Thu Sep 17 15:13:40.691109 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBOcL08BTTQixEnpKCQAAABo"]
[Thu Sep 17 15:13:40.691136 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBOcL08BTTQixEnpKCQAAABo"]
[Thu Sep 17 15:13:40.760016 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.221.252:36952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYBOcL08BTTQixEnpKDgAAAG0"]
[Thu Sep 17 15:13:40.851768 2026] [security2:error] [pid 971102:tid 971321] [client 93.92.20.248:45325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxYBOcL08BTTQixEnpKEQAAAFc"]
[Thu Sep 17 15:13:40.957762 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/url.php"] [unique_id "aqxYBOcL08BTTQixEnpKFQAAAHg"]
[Thu Sep 17 15:13:40.957908 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:49028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/php/rules/url.php"] [unique_id "aqxYBOcL08BTTQixEnpKFQAAAHg"]
[Thu Sep 17 15:13:41.107903 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/uploads/"] [unique_id "aqxYBecL08BTTQixEnpKGgAAAD0"]
[Thu Sep 17 15:13:41.260795 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/schema-holder.php"] [unique_id "aqxYBecL08BTTQixEnpKGwAAADo"]
[Thu Sep 17 15:13:41.260906 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.120:49044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/schema-holder.php"] [unique_id "aqxYBecL08BTTQixEnpKGwAAADo"]
[Thu Sep 17 15:13:41.281818 2026] [security2:error] [pid 971102:tid 971265] [client 169.58.197.253:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sportsgirlkat.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxYBecL08BTTQixEnpKHAAAAB8"], referer: binance.com
[Thu Sep 17 15:13:41.294646 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.130.148:45666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYBecL08BTTQixEnpKHQAAAA8"]
[Thu Sep 17 15:13:41.463945 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.221.252:36958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxYBecL08BTTQixEnpKJgAAAFk"]
[Thu Sep 17 15:13:41.469876 2026] [security2:error] [pid 971102:tid 971250] [client 5.69.109.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ6QAAABA"]
[Thu Sep 17 15:13:41.470481 2026] [security2:error] [pid 971102:tid 971240] [client 153.132.77.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYAecL08BTTQixEnpJtAAAAAY"]
[Thu Sep 17 15:13:41.500043 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBecL08BTTQixEnpKHgAAAAE"]
[Thu Sep 17 15:13:41.500072 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBecL08BTTQixEnpKHgAAAAE"]
[Thu Sep 17 15:13:41.502204 2026] [security2:error] [pid 971102:tid 971353] [client 95.70.165.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYAOcL08BTTQixEnpJlwAAAHc"]
[Thu Sep 17 15:13:41.504878 2026] [security2:error] [pid 971102:tid 971355] [client 130.193.230.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxYA-cL08BTTQixEnpJ6AAAAHk"]
[Thu Sep 17 15:13:41.571611 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:49046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/script-loader.php"] [unique_id "aqxYBecL08BTTQixEnpKKgAAADQ"]
[Thu Sep 17 15:13:41.571751 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.120:49046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/script-loader.php"] [unique_id "aqxYBecL08BTTQixEnpKKgAAADQ"]
[Thu Sep 17 15:13:41.851263 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:49052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/swv.php"] [unique_id "aqxYBecL08BTTQixEnpKLgAAAG8"]
[Thu Sep 17 15:13:41.851384 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.120:49052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/swv.php"] [unique_id "aqxYBecL08BTTQixEnpKLgAAAG8"]
[Thu Sep 17 15:13:41.956524 2026] [security2:error] [pid 971102:tid 971319] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Admin/uploads/"] [unique_id "aqxYBecL08BTTQixEnpKMwAAAFU"]
[Thu Sep 17 15:13:41.964245 2026] [access_compat:error] [pid 971102:tid 971287] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/ancient-jewels-the-mayan-legacy
[Thu Sep 17 15:13:41.987117 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.130.148:45670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYBecL08BTTQixEnpKOQAAAGU"]
[Thu Sep 17 15:13:42.171842 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/upgrade.php"] [unique_id "aqxYBucL08BTTQixEnpKQAAAABo"]
[Thu Sep 17 15:13:42.171989 2026] [security2:error] [pid 971102:tid 971260] [client 143.244.57.120:49068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/upgrade.php"] [unique_id "aqxYBucL08BTTQixEnpKQAAAABo"]
[Thu Sep 17 15:13:42.177426 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.221.252:36962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYBucL08BTTQixEnpKQQAAACU"]
[Thu Sep 17 15:13:42.288680 2026] [security2:error] [pid 971102:tid 971124] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYBucL08BTTQixEnpKQwAACxQ"]
[Thu Sep 17 15:13:42.308869 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKPgAAAD4"]
[Thu Sep 17 15:13:42.308906 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKPgAAAD4"]
[Thu Sep 17 15:13:42.325414 2026] [security2:error] [pid 971102:tid 971282] [client 154.190.208.131:42343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKRAAAADA"]
[Thu Sep 17 15:13:42.325537 2026] [security2:error] [pid 971102:tid 971282] [client 154.190.208.131:42343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKRAAAADA"]
[Thu Sep 17 15:13:42.508734 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation-functions.php"] [unique_id "aqxYBucL08BTTQixEnpKSQAAAEY"]
[Thu Sep 17 15:13:42.508887 2026] [security2:error] [pid 971102:tid 971304] [client 143.244.57.120:49084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation-functions.php"] [unique_id "aqxYBucL08BTTQixEnpKSQAAAEY"]
[Thu Sep 17 15:13:42.664109 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:60250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/"] [unique_id "aqxYBucL08BTTQixEnpKTAAAABs"]
[Thu Sep 17 15:13:42.709408 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.130.148:45684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYBucL08BTTQixEnpKTQAAAGs"]
[Thu Sep 17 15:13:42.793751 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation.php"] [unique_id "aqxYBucL08BTTQixEnpKTgAAAHw"]
[Thu Sep 17 15:13:42.793872 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:49086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/includes/validation.php"] [unique_id "aqxYBucL08BTTQixEnpKTgAAAHw"]
[Thu Sep 17 15:13:42.806955 2026] [security2:error] [pid 971102:tid 971344] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKSwAAbgs"], referer: http://missglitterteaches.com/new/
[Thu Sep 17 15:13:42.862657 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.221.252:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYBucL08BTTQixEnpKUgAAAEE"]
[Thu Sep 17 15:13:42.923955 2026] [security2:error] [pid 971102:tid 971248] [client 114.198.138.124:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKVQAAAA4"]
[Thu Sep 17 15:13:42.924173 2026] [security2:error] [pid 971102:tid 971248] [client 114.198.138.124:58162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYBucL08BTTQixEnpKVQAAAA4"]
[Thu Sep 17 15:13:42.996875 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKUwAAAHY"]
[Thu Sep 17 15:13:42.996903 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:40012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKUwAAAHY"]
[Thu Sep 17 15:13:43.092387 2026] [security2:error] [pid 971102:tid 971297] [client 143.244.57.120:49090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/languages/"] [unique_id "aqxYB-cL08BTTQixEnpKWgAAAD8"]
[Thu Sep 17 15:13:43.246628 2026] [security2:error] [pid 971102:tid 971359] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYBucL08BTTQixEnpKWAAAfSw"], referer: http://missglitterteaches.com/wordpress/
[Thu Sep 17 15:13:43.308237 2026] [security2:error] [pid 971102:tid 971306] [client 4.240.114.86:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reedcustomprinting.com"] [uri "/wp-includes/fonts/party.php"] [unique_id "aqxYB-cL08BTTQixEnpKXwAAAEg"], referer: binance.com
[Thu Sep 17 15:13:43.422261 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.130.148:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYB-cL08BTTQixEnpKYwAAAHc"]
[Thu Sep 17 15:13:43.472455 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:63364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYB-cL08BTTQixEnpKZQAAADg"]
[Thu Sep 17 15:13:43.472562 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:63364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYB-cL08BTTQixEnpKZQAAADg"]
[Thu Sep 17 15:13:43.553679 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.221.252:36972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYB-cL08BTTQixEnpKagAAADQ"]
[Thu Sep 17 15:13:43.583977 2026] [security2:error] [pid 971102:tid 971288] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKYgAANis"], referer: http://missglitterteaches.com/wp/
[Thu Sep 17 15:13:43.641206 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/languages/"] [unique_id "aqxYB-cL08BTTQixEnpKbAAAABg"]
[Thu Sep 17 15:13:43.788526 2026] [security2:error] [pid 971102:tid 971264] [client 143.244.57.120:49090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/languages/wp-content/plugins/contact-form-7/"] [unique_id "aqxYB-cL08BTTQixEnpKcAAAAB4"]
[Thu Sep 17 15:13:44.005896 2026] [security2:error] [pid 971102:tid 971346] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKbgAAcA0"], referer: http://missglitterteaches.com/old/
[Thu Sep 17 15:13:44.126900 2026] [security2:error] [pid 971102:tid 971269] [client 34.166.130.148:47218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYCOcL08BTTQixEnpKegAAACM"]
[Thu Sep 17 15:13:44.195370 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKdQAAAC8"]
[Thu Sep 17 15:13:44.195407 2026] [security2:error] [pid 971102:tid 971281] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYB-cL08BTTQixEnpKdQAAAC8"]
[Thu Sep 17 15:13:44.244387 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.221.252:40192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYCOcL08BTTQixEnpKfQAAACY"]
[Thu Sep 17 15:13:44.378637 2026] [security2:error] [pid 971102:tid 971234] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYCOcL08BTTQixEnpKewAAABU"], referer: http://missglitterteaches.com/blog/
[Thu Sep 17 15:13:44.523201 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/load.php"] [unique_id "aqxYCOcL08BTTQixEnpKhwAAAF8"]
[Thu Sep 17 15:13:44.523310 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:49090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/load.php"] [unique_id "aqxYCOcL08BTTQixEnpKhwAAAF8"]
[Thu Sep 17 15:13:44.722972 2026] [security2:error] [pid 971102:tid 971282] [client 137.184.51.177:58434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxYCOcL08BTTQixEnpKhgAAMEA"], referer: http://missglitterteaches.com/backup/
[Thu Sep 17 15:13:44.821294 2026] [security2:error] [pid 971102:tid 971360] [client 186.105.232.15:58994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYCOcL08BTTQixEnpKiAAAAH4"]
[Thu Sep 17 15:13:44.821402 2026] [security2:error] [pid 971102:tid 971360] [client 186.105.232.15:58994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYCOcL08BTTQixEnpKiAAAAH4"]
[Thu Sep 17 15:13:44.839314 2026] [security2:error] [pid 971102:tid 971332] [client 34.166.130.148:47230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYCOcL08BTTQixEnpKjQAAAGI"]
[Thu Sep 17 15:13:44.856678 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:49106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYCOcL08BTTQixEnpKjgAAAAs"]
[Thu Sep 17 15:13:44.939512 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.221.252:40194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYCOcL08BTTQixEnpKkQAAAF4"]
[Thu Sep 17 15:13:45.062134 2026] [security2:error] [pid 971102:tid 971341] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYCOcL08BTTQixEnpKlAAAAGs"]
[Thu Sep 17 15:13:45.202507 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:49106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/wp-content/plugins/contact-form-7/"] [unique_id "aqxYCecL08BTTQixEnpKlgAAAEE"]
[Thu Sep 17 15:13:45.531289 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.130.148:47244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYCecL08BTTQixEnpKrAAAABE"]
[Thu Sep 17 15:13:45.595472 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCecL08BTTQixEnpKpgAAAHU"]
[Thu Sep 17 15:13:45.595492 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCecL08BTTQixEnpKpgAAAHU"]
[Thu Sep 17 15:13:45.623455 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.221.252:40208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYCecL08BTTQixEnpKrgAAAHk"]
[Thu Sep 17 15:13:45.740978 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/acceptance.php"] [unique_id "aqxYCecL08BTTQixEnpKsAAAACs"]
[Thu Sep 17 15:13:45.741094 2026] [security2:error] [pid 971102:tid 971277] [client 143.244.57.120:49106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/acceptance.php"] [unique_id "aqxYCecL08BTTQixEnpKsAAAACs"]
[Thu Sep 17 15:13:45.965857 2026] [security2:error] [pid 971102:tid 971246] [client 17.166.154.156:56940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYCecL08BTTQixEnpKsQAADEk"]
[Thu Sep 17 15:13:46.027921 2026] [security2:error] [pid 971102:tid 971309] [client 143.244.57.120:49112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/"] [unique_id "aqxYCucL08BTTQixEnpKvgAAAEs"]
[Thu Sep 17 15:13:46.133918 2026] [security2:error] [pid 971102:tid 971284] [client 5.189.145.112:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxYCucL08BTTQixEnpKwAAAADI"], referer: binance.com
[Thu Sep 17 15:13:46.184594 2026] [security2:error] [pid 971102:tid 971179] [remote 128.1.120.151:41188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "mavenme.com"] [uri "/"] [unique_id "aqxYCucL08BTTQixEnpKxQAABEs"]
[Thu Sep 17 15:13:46.188503 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/"] [unique_id "aqxYCucL08BTTQixEnpKwgAAAHA"]
[Thu Sep 17 15:13:46.206771 2026] [core:error] [pid 971102:tid 971314] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:46.206786 2026] [core:error] [pid 971102:tid 971314] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:46.245311 2026] [security2:error] [pid 971102:tid 971267] [client 34.166.130.148:47248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYCucL08BTTQixEnpKxwAAACE"]
[Thu Sep 17 15:13:46.321245 2026] [security2:error] [pid 971102:tid 971285] [client 34.166.221.252:40216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYCucL08BTTQixEnpKyAAAADM"]
[Thu Sep 17 15:13:46.330038 2026] [security2:error] [pid 971102:tid 971271] [client 143.244.57.120:49112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYCucL08BTTQixEnpKyQAAACU"]
[Thu Sep 17 15:13:46.685186 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCucL08BTTQixEnpKzgAAAFc"]
[Thu Sep 17 15:13:46.685213 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYCucL08BTTQixEnpKzgAAAFc"]
[Thu Sep 17 15:13:46.838642 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:49112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/akismet.php"] [unique_id "aqxYCucL08BTTQixEnpK5QAAAFs"]
[Thu Sep 17 15:13:46.838772 2026] [security2:error] [pid 971102:tid 971325] [client 143.244.57.120:49112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/akismet.php"] [unique_id "aqxYCucL08BTTQixEnpK5QAAAFs"]
[Thu Sep 17 15:13:46.932036 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.130.148:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYCucL08BTTQixEnpK6AAAAEk"]
[Thu Sep 17 15:13:47.011476 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.221.252:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYC-cL08BTTQixEnpK7QAAAF4"]
[Thu Sep 17 15:13:47.115704 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/service.php"] [unique_id "aqxYC-cL08BTTQixEnpK8AAAABk"]
[Thu Sep 17 15:13:47.115824 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:49126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/akismet/service.php"] [unique_id "aqxYC-cL08BTTQixEnpK8AAAABk"]
[Thu Sep 17 15:13:47.235465 2026] [security2:error] [pid 971102:tid 971324] [client 156.192.234.52:54513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpK8gAAAFo"]
[Thu Sep 17 15:13:47.236120 2026] [security2:error] [pid 971102:tid 971324] [client 156.192.234.52:54513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpK8gAAAFo"]
[Thu Sep 17 15:13:47.395714 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/checkbox.php"] [unique_id "aqxYC-cL08BTTQixEnpK9gAAAC4"]
[Thu Sep 17 15:13:47.395830 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.120:49136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/checkbox.php"] [unique_id "aqxYC-cL08BTTQixEnpK9gAAAC4"]
[Thu Sep 17 15:13:47.615945 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.130.148:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYC-cL08BTTQixEnpK_QAAABA"]
[Thu Sep 17 15:13:47.684525 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.120:49142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/"] [unique_id "aqxYC-cL08BTTQixEnpLAQAAAHA"]
[Thu Sep 17 15:13:47.699801 2026] [security2:error] [pid 971102:tid 971306] [client 115.244.164.14:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpLAgAAAEg"]
[Thu Sep 17 15:13:47.699916 2026] [security2:error] [pid 971102:tid 971306] [client 115.244.164.14:59356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYC-cL08BTTQixEnpLAgAAAEg"]
[Thu Sep 17 15:13:47.704410 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.221.252:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYC-cL08BTTQixEnpLAwAAAHo"]
[Thu Sep 17 15:13:47.873591 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/"] [unique_id "aqxYC-cL08BTTQixEnpLBwAAADM"]
[Thu Sep 17 15:13:48.017087 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:49142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYDOcL08BTTQixEnpLDAAAAAA"]
[Thu Sep 17 15:13:48.319545 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.130.148:47282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYDOcL08BTTQixEnpLEwAAACo"]
[Thu Sep 17 15:13:48.386194 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYDOcL08BTTQixEnpLDQAAAF8"]
[Thu Sep 17 15:13:48.386216 2026] [security2:error] [pid 971102:tid 971329] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYDOcL08BTTQixEnpLDQAAAF8"]
[Thu Sep 17 15:13:48.388735 2026] [security2:error] [pid 971102:tid 971303] [client 34.166.221.252:40246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYDOcL08BTTQixEnpLFgAAAEU"]
[Thu Sep 17 15:13:48.482457 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:36168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zainridgecondo.org"] [uri "/wp-admin/index.php"] [unique_id "aqxYCOcL08BTTQixEnpKfAAAAEo"]
[Thu Sep 17 15:13:48.536652 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/constant-contact.php"] [unique_id "aqxYDOcL08BTTQixEnpLHAAAAAM"]
[Thu Sep 17 15:13:48.536829 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.120:49142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/constant-contact/constant-contact.php"] [unique_id "aqxYDOcL08BTTQixEnpLHAAAAAM"]
[Thu Sep 17 15:13:48.647033 2026] [security2:error] [pid 971102:tid 971295] [client 185.55.149.49:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYDOcL08BTTQixEnpLHwAAAD0"]
[Thu Sep 17 15:13:48.647162 2026] [security2:error] [pid 971102:tid 971295] [client 185.55.149.49:63956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYDOcL08BTTQixEnpLHwAAAD0"]
[Thu Sep 17 15:13:48.703459 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:36168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYDOcL08BTTQixEnpLIAAAAAc"]
[Thu Sep 17 15:13:48.703633 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:36168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYDOcL08BTTQixEnpLIAAAAAc"]
[Thu Sep 17 15:13:48.832975 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:49152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/count.php"] [unique_id "aqxYDOcL08BTTQixEnpLIQAAAGk"]
[Thu Sep 17 15:13:48.833109 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:49152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/count.php"] [unique_id "aqxYDOcL08BTTQixEnpLIQAAAGk"]
[Thu Sep 17 15:13:49.013149 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.130.148:47286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.130.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.esy.noo.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYDecL08BTTQixEnpLJAAAAFw"]
[Thu Sep 17 15:13:49.095450 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.221.252:40256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYDecL08BTTQixEnpLJwAAAAk"]
[Thu Sep 17 15:13:49.134046 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:49158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/date.php"] [unique_id "aqxYDecL08BTTQixEnpLKAAAADE"]
[Thu Sep 17 15:13:49.134175 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:49158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/date.php"] [unique_id "aqxYDecL08BTTQixEnpLKAAAADE"]
[Thu Sep 17 15:13:49.148939 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/images/"] [unique_id "aqxYDecL08BTTQixEnpLKQAAAE8"]
[Thu Sep 17 15:13:49.308141 2026] [security2:error] [pid 971102:tid 971207] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYDecL08BTTQixEnpLKgAALmY"]
[Thu Sep 17 15:13:49.410516 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/disallowed-list.php"] [unique_id "aqxYDecL08BTTQixEnpLKwAAAHY"]
[Thu Sep 17 15:13:49.410626 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:49172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/disallowed-list.php"] [unique_id "aqxYDecL08BTTQixEnpLKwAAAHY"]
[Thu Sep 17 15:13:49.440888 2026] [security2:error] [pid 971102:tid 971249] [client 71.164.83.186:55130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "copichristianschool.org"] [uri "/.env"] [unique_id "aqxYDecL08BTTQixEnpLLgAAAA8"]
[Thu Sep 17 15:13:49.699746 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:49174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/doi-helper.php"] [unique_id "aqxYDecL08BTTQixEnpLMAAAABc"]
[Thu Sep 17 15:13:49.699873 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:49174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/doi-helper.php"] [unique_id "aqxYDecL08BTTQixEnpLMAAAABc"]
[Thu Sep 17 15:13:49.726251 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47292] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:49.726270 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47292] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:49.808930 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.221.252:40262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYDecL08BTTQixEnpLMwAAAH0"]
[Thu Sep 17 15:13:49.810413 2026] [security2:error] [pid 971102:tid 971222] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYDecL08BTTQixEnpLNAAAf3U"]
[Thu Sep 17 15:13:49.824078 2026] [security2:error] [pid 971102:tid 971262] [client 71.164.83.186:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "copichurch.org"] [uri "/.env"] [unique_id "aqxYDecL08BTTQixEnpLNQAAABw"]
[Thu Sep 17 15:13:49.990637 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/file.php"] [unique_id "aqxYDecL08BTTQixEnpLOQAAAFA"]
[Thu Sep 17 15:13:49.990759 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:34208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/file.php"] [unique_id "aqxYDecL08BTTQixEnpLOQAAAFA"]
[Thu Sep 17 15:13:50.021550 2026] [fcgid:warn] [pid 971102:tid 971278] (70014)End of file found: [client 152.32.158.219:48908] mod_fcgid: can't get data from http client
[Thu Sep 17 15:13:50.078895 2026] [security2:error] [pid 971102:tid 971351] [client 162.241.226.11:50624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.snowhillstokes.org"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxYDucL08BTTQixEnpLPAAAAHU"]
[Thu Sep 17 15:13:50.202229 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYDecL08BTTQixEnpLMgAAAGU"]
[Thu Sep 17 15:13:50.202257 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYDecL08BTTQixEnpLMgAAAGU"]
[Thu Sep 17 15:13:50.279050 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:34218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/flamingo.php"] [unique_id "aqxYDucL08BTTQixEnpLPgAAADM"]
[Thu Sep 17 15:13:50.279167 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:34218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/flamingo.php"] [unique_id "aqxYDucL08BTTQixEnpLPgAAADM"]
[Thu Sep 17 15:13:50.434356 2026] [core:error] [pid 971102:tid 971287] [client 34.166.130.148:47294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:50.434377 2026] [core:error] [pid 971102:tid 971287] [client 34.166.130.148:47294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:50.492472 2026] [security2:error] [pid 971102:tid 971242] [client 34.166.221.252:40270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYDucL08BTTQixEnpLRgAAAAg"]
[Thu Sep 17 15:13:50.564461 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/hidden.php"] [unique_id "aqxYDucL08BTTQixEnpLRwAAABU"]
[Thu Sep 17 15:13:50.564571 2026] [security2:error] [pid 971102:tid 971255] [client 143.244.57.120:34220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/hidden.php"] [unique_id "aqxYDucL08BTTQixEnpLRwAAABU"]
[Thu Sep 17 15:13:50.845121 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/listo.php"] [unique_id "aqxYDucL08BTTQixEnpLUAAAADA"]
[Thu Sep 17 15:13:50.845237 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/listo.php"] [unique_id "aqxYDucL08BTTQixEnpLUAAAADA"]
[Thu Sep 17 15:13:50.915200 2026] [security2:error] [pid 971102:tid 971265] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/assets/"] [unique_id "aqxYDucL08BTTQixEnpLUwAAAB8"]
[Thu Sep 17 15:13:50.980934 2026] [security2:error] [pid 971102:tid 971268] [client 104.28.198.244:22841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYDucL08BTTQixEnpLVgAAACI"]
[Thu Sep 17 15:13:50.981067 2026] [security2:error] [pid 971102:tid 971268] [client 104.28.198.244:22841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYDucL08BTTQixEnpLVgAAACI"]
[Thu Sep 17 15:13:51.120586 2026] [core:error] [pid 971102:tid 971237] [client 34.166.130.148:47300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.120606 2026] [core:error] [pid 971102:tid 971237] [client 34.166.130.148:47300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.122791 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/number.php"] [unique_id "aqxYD-cL08BTTQixEnpLWwAAAF4"]
[Thu Sep 17 15:13:51.122886 2026] [security2:error] [pid 971102:tid 971328] [client 143.244.57.120:34236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/number.php"] [unique_id "aqxYD-cL08BTTQixEnpLWwAAAF4"]
[Thu Sep 17 15:13:51.207241 2026] [security2:error] [pid 971102:tid 971330] [client 34.166.221.252:40280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYD-cL08BTTQixEnpLXAAAAGA"]
[Thu Sep 17 15:13:51.413262 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/quiz.php"] [unique_id "aqxYD-cL08BTTQixEnpLXgAAAA0"]
[Thu Sep 17 15:13:51.413356 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:34246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/quiz.php"] [unique_id "aqxYD-cL08BTTQixEnpLXgAAAA0"]
[Thu Sep 17 15:13:51.415835 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLWQAAAA4"]
[Thu Sep 17 15:13:51.415862 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLWQAAAA4"]
[Thu Sep 17 15:13:51.708043 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:34262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/really-simple-captcha.php"] [unique_id "aqxYD-cL08BTTQixEnpLYwAAACY"]
[Thu Sep 17 15:13:51.708152 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:34262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/really-simple-captcha.php"] [unique_id "aqxYD-cL08BTTQixEnpLYwAAACY"]
[Thu Sep 17 15:13:51.727505 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxYD-cL08BTTQixEnpLZQAAACA"]
[Thu Sep 17 15:13:51.757485 2026] [security2:error] [pid 971102:tid 971235] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLYgAAATo"]
[Thu Sep 17 15:13:51.837317 2026] [core:error] [pid 971102:tid 971312] [client 34.166.130.148:47302] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.837344 2026] [core:error] [pid 971102:tid 971312] [client 34.166.130.148:47302] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:51.888251 2026] [security2:error] [pid 971102:tid 971277] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLZwAAKw4"]
[Thu Sep 17 15:13:51.920805 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.221.252:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYD-cL08BTTQixEnpLawAAAGs"]
[Thu Sep 17 15:13:51.987099 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:34266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/recaptcha/"] [unique_id "aqxYD-cL08BTTQixEnpLbwAAABA"]
[Thu Sep 17 15:13:52.097784 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLbgAAADg"]
[Thu Sep 17 15:13:52.097811 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYD-cL08BTTQixEnpLbgAAADg"]
[Thu Sep 17 15:13:52.147574 2026] [security2:error] [pid 971102:tid 971361] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/recaptcha/index.js"] [unique_id "aqxYEOcL08BTTQixEnpLcwAAAH8"]
[Thu Sep 17 15:13:52.152497 2026] [security2:error] [pid 971102:tid 971288] [client 23.251.146.115:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLcgAANhY"]
[Thu Sep 17 15:13:52.284446 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/reflection.php"] [unique_id "aqxYEOcL08BTTQixEnpLdgAAADw"]
[Thu Sep 17 15:13:52.284567 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/reflection.php"] [unique_id "aqxYEOcL08BTTQixEnpLdgAAADw"]
[Thu Sep 17 15:13:52.364528 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/upload/image/"] [unique_id "aqxYEOcL08BTTQixEnpLdwAAAFA"]
[Thu Sep 17 15:13:52.504477 2026] [security2:error] [pid 971102:tid 971347] [client 173.252.69.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcktax.com"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLewAAAHE"]
[Thu Sep 17 15:13:52.533719 2026] [core:error] [pid 971102:tid 971264] [client 34.166.130.148:47306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:52.533738 2026] [core:error] [pid 971102:tid 971264] [client 34.166.130.148:47306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:52.562590 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:34282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/response.php"] [unique_id "aqxYEOcL08BTTQixEnpLgwAAAAg"]
[Thu Sep 17 15:13:52.562738 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:34282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/response.php"] [unique_id "aqxYEOcL08BTTQixEnpLgwAAAAg"]
[Thu Sep 17 15:13:52.619037 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.221.252:40312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYEOcL08BTTQixEnpLhAAAAHU"]
[Thu Sep 17 15:13:52.679447 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLgAAAADM"]
[Thu Sep 17 15:13:52.679480 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEOcL08BTTQixEnpLgAAAADM"]
[Thu Sep 17 15:13:52.768025 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:58829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLhgAAAGQ"]
[Thu Sep 17 15:13:52.768130 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:58829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLhgAAAGQ"]
[Thu Sep 17 15:13:52.833672 2026] [security2:error] [pid 971102:tid 971274] [client 154.190.208.131:41604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLjAAAACg"]
[Thu Sep 17 15:13:52.835815 2026] [security2:error] [pid 971102:tid 971274] [client 154.190.208.131:41604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEOcL08BTTQixEnpLjAAAACg"]
[Thu Sep 17 15:13:52.850008 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/assets/images/"] [unique_id "aqxYEOcL08BTTQixEnpLkAAAAAc"]
[Thu Sep 17 15:13:52.860272 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/select.php"] [unique_id "aqxYEOcL08BTTQixEnpLkgAAAGk"]
[Thu Sep 17 15:13:52.860359 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/select.php"] [unique_id "aqxYEOcL08BTTQixEnpLkgAAAGk"]
[Thu Sep 17 15:13:53.150276 2026] [security2:error] [pid 971102:tid 971247] [client 162.241.226.11:11226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.snowhillstokes.org"] [uri "/wp-cron.php"] [unique_id "aqxYEecL08BTTQixEnpLmgAAAA0"]
[Thu Sep 17 15:13:53.179489 2026] [security2:error] [pid 971102:tid 971358] [client 143.244.57.120:34294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/"] [unique_id "aqxYEecL08BTTQixEnpLnAAAAHw"]
[Thu Sep 17 15:13:53.234682 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:47312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.234718 2026] [core:error] [pid 971102:tid 971256] [client 34.166.130.148:47312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.303521 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.221.252:40314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYEecL08BTTQixEnpLngAAAHg"]
[Thu Sep 17 15:13:53.320937 2026] [security2:error] [pid 971102:tid 971127] [remote 216.73.217.142:34337] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxYEecL08BTTQixEnpLnwAAJRc"]
[Thu Sep 17 15:13:53.346212 2026] [security2:error] [pid 971102:tid 971266] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/"] [unique_id "aqxYEecL08BTTQixEnpLoAAAACA"]
[Thu Sep 17 15:13:53.484858 2026] [security2:error] [pid 971102:tid 971291] [client 143.244.57.120:34294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYEecL08BTTQixEnpLqAAAADk"]
[Thu Sep 17 15:13:53.582911 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLoQAAAAE"]
[Thu Sep 17 15:13:53.582937 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLoQAAAAE"]
[Thu Sep 17 15:13:53.759239 2026] [security2:error] [pid 971102:tid 971288] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Public/"] [unique_id "aqxYEecL08BTTQixEnpLrAAAADY"]
[Thu Sep 17 15:13:53.833928 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLqQAAABA"]
[Thu Sep 17 15:13:53.833961 2026] [security2:error] [pid 971102:tid 971250] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLqQAAABA"]
[Thu Sep 17 15:13:53.921148 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.921169 2026] [core:error] [pid 971102:tid 971319] [client 34.166.130.148:47320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:53.957075 2026] [security2:error] [pid 971102:tid 971359] [client 45.169.98.18:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEecL08BTTQixEnpLsQAAAH0"]
[Thu Sep 17 15:13:53.957285 2026] [security2:error] [pid 971102:tid 971359] [client 45.169.98.18:63915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYEecL08BTTQixEnpLsQAAAH0"]
[Thu Sep 17 15:13:53.975484 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:34294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/contact-form-properties.php"] [unique_id "aqxYEecL08BTTQixEnpLtQAAAHY"]
[Thu Sep 17 15:13:53.975617 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:34294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/contact-form-properties.php"] [unique_id "aqxYEecL08BTTQixEnpLtQAAAHY"]
[Thu Sep 17 15:13:53.991666 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.221.252:40324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYEecL08BTTQixEnpLtgAAADw"]
[Thu Sep 17 15:13:54.088645 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLsgAAAEg"]
[Thu Sep 17 15:13:54.088689 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEecL08BTTQixEnpLsgAAAEg"]
[Thu Sep 17 15:13:54.209772 2026] [security2:error] [pid 971102:tid 971264] [client 5.189.145.112:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxYEucL08BTTQixEnpLuwAAAB4"], referer: binance.com
[Thu Sep 17 15:13:54.255492 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:34308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/doi.php"] [unique_id "aqxYEucL08BTTQixEnpLvAAAAHM"]
[Thu Sep 17 15:13:54.255613 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:34308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/doi.php"] [unique_id "aqxYEucL08BTTQixEnpLvAAAAHM"]
[Thu Sep 17 15:13:54.338958 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/vendor/"] [unique_id "aqxYEucL08BTTQixEnpLvQAAAEU"]
[Thu Sep 17 15:13:54.532264 2026] [security2:error] [pid 971102:tid 971318] [client 162.241.226.11:11232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.snowhillstokes.org"] [uri "/wp-cron.php"] [unique_id "aqxYEucL08BTTQixEnpLwgAAAFQ"]
[Thu Sep 17 15:13:54.532507 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:34320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/sendinblue.php"] [unique_id "aqxYEucL08BTTQixEnpLwwAAAGI"]
[Thu Sep 17 15:13:54.532587 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.120:34320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/sendinblue.php"] [unique_id "aqxYEucL08BTTQixEnpLwwAAAGI"]
[Thu Sep 17 15:13:54.632124 2026] [core:error] [pid 971102:tid 971296] [client 34.166.130.148:47692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:54.632148 2026] [core:error] [pid 971102:tid 971296] [client 34.166.130.148:47692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:54.690125 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.221.252:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYEucL08BTTQixEnpLyAAAACo"]
[Thu Sep 17 15:13:54.708492 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEucL08BTTQixEnpLwQAAAGw"]
[Thu Sep 17 15:13:54.708524 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYEucL08BTTQixEnpLwQAAAGw"]
[Thu Sep 17 15:13:54.816230 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/service.php"] [unique_id "aqxYEucL08BTTQixEnpLywAAADA"]
[Thu Sep 17 15:13:54.816355 2026] [security2:error] [pid 971102:tid 971282] [client 143.244.57.120:34336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/sendinblue/service.php"] [unique_id "aqxYEucL08BTTQixEnpLywAAADA"]
[Thu Sep 17 15:13:54.915283 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/local/"] [unique_id "aqxYEucL08BTTQixEnpL0AAAAC0"]
[Thu Sep 17 15:13:55.102634 2026] [security2:error] [pid 971102:tid 971245] [client 143.244.57.120:34342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/stripe/"] [unique_id "aqxYE-cL08BTTQixEnpL1wAAAAs"]
[Thu Sep 17 15:13:55.258894 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/stripe/index.js"] [unique_id "aqxYE-cL08BTTQixEnpL2QAAAAk"]
[Thu Sep 17 15:13:55.281197 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL2AAAAGM"]
[Thu Sep 17 15:13:55.281228 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL2AAAAGM"]
[Thu Sep 17 15:13:55.339855 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:47694] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:55.339875 2026] [core:error] [pid 971102:tid 971326] [client 34.166.130.148:47694] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:55.384016 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.221.252:46200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYE-cL08BTTQixEnpL3gAAAA0"]
[Thu Sep 17 15:13:55.396752 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:34342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/submit.php"] [unique_id "aqxYE-cL08BTTQixEnpL3wAAAEI"]
[Thu Sep 17 15:13:55.396859 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.120:34342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/submit.php"] [unique_id "aqxYE-cL08BTTQixEnpL3wAAAEI"]
[Thu Sep 17 15:13:55.505168 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/modules/"] [unique_id "aqxYE-cL08BTTQixEnpL5QAAAAo"]
[Thu Sep 17 15:13:55.691611 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/text.php"] [unique_id "aqxYE-cL08BTTQixEnpL6QAAABc"]
[Thu Sep 17 15:13:55.691782 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:34344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/text.php"] [unique_id "aqxYE-cL08BTTQixEnpL6QAAABc"]
[Thu Sep 17 15:13:55.798797 2026] [security2:error] [pid 971102:tid 971313] [client 40.77.167.71:35608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL5gAATyg"]
[Thu Sep 17 15:13:55.806880 2026] [security2:error] [pid 971102:tid 971270] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL5wAAACQ"]
[Thu Sep 17 15:13:55.806905 2026] [security2:error] [pid 971102:tid 971270] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYE-cL08BTTQixEnpL5wAAACQ"]
[Thu Sep 17 15:13:55.978983 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:34360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/textarea.php"] [unique_id "aqxYE-cL08BTTQixEnpL8AAAAFM"]
[Thu Sep 17 15:13:55.979079 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:34360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/textarea.php"] [unique_id "aqxYE-cL08BTTQixEnpL8AAAAFM"]
[Thu Sep 17 15:13:56.027376 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Site/"] [unique_id "aqxYFOcL08BTTQixEnpL8gAAACE"]
[Thu Sep 17 15:13:56.049845 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:47702] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.049862 2026] [core:error] [pid 971102:tid 971288] [client 34.166.130.148:47702] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.083726 2026] [security2:error] [pid 971102:tid 971359] [client 34.166.221.252:46216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYFOcL08BTTQixEnpL9QAAAH0"]
[Thu Sep 17 15:13:56.167811 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFOcL08BTTQixEnpL9gAAAH8"]
[Thu Sep 17 15:13:56.169688 2026] [security2:error] [pid 971102:tid 971361] [client 186.105.232.15:59598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFOcL08BTTQixEnpL9gAAAH8"]
[Thu Sep 17 15:13:56.272108 2026] [security2:error] [pid 971102:tid 971242] [client 143.244.57.120:34368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/"] [unique_id "aqxYFOcL08BTTQixEnpL-AAAAAg"]
[Thu Sep 17 15:13:56.382083 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpL9wAAAC8"]
[Thu Sep 17 15:13:56.382111 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpL9wAAAC8"]
[Thu Sep 17 15:13:56.430688 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/"] [unique_id "aqxYFOcL08BTTQixEnpL-QAAAFE"]
[Thu Sep 17 15:13:56.581385 2026] [security2:error] [pid 971102:tid 971285] [client 143.244.57.120:34368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/wp-content/plugins/contact-form-7/modules/"] [unique_id "aqxYFOcL08BTTQixEnpL_gAAADM"]
[Thu Sep 17 15:13:56.604517 2026] [security2:error] [pid 971102:tid 971246] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/system/"] [unique_id "aqxYFOcL08BTTQixEnpL_wAAAAw"]
[Thu Sep 17 15:13:56.659817 2026] [security2:error] [pid 971102:tid 971322] [client 104.234.19.145:62019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/000.php"] [unique_id "aqxYFOcL08BTTQixEnpMAAAAAFg"]
[Thu Sep 17 15:13:56.746198 2026] [core:error] [pid 971102:tid 971351] [client 34.166.130.148:47706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.746221 2026] [core:error] [pid 971102:tid 971351] [client 34.166.130.148:47706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:56.768070 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.221.252:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYFOcL08BTTQixEnpMBAAAAD0"]
[Thu Sep 17 15:13:56.926054 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMAgAAAHs"]
[Thu Sep 17 15:13:56.926079 2026] [security2:error] [pid 971102:tid 971357] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMAgAAAHs"]
[Thu Sep 17 15:13:56.972419 2026] [security2:error] [pid 971102:tid 971286] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMBQAAADQ"]
[Thu Sep 17 15:13:56.972446 2026] [security2:error] [pid 971102:tid 971286] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFOcL08BTTQixEnpMBQAAADQ"]
[Thu Sep 17 15:13:57.070853 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:34368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/service.php"] [unique_id "aqxYFecL08BTTQixEnpMDQAAAFc"]
[Thu Sep 17 15:13:57.070955 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:34368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/service.php"] [unique_id "aqxYFecL08BTTQixEnpMDQAAAFc"]
[Thu Sep 17 15:13:57.159564 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/template/"] [unique_id "aqxYFecL08BTTQixEnpMDwAAAGY"]
[Thu Sep 17 15:13:57.244624 2026] [security2:error] [pid 971102:tid 971132] [remote 216.73.217.142:21738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:loknya. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxYFecL08BTTQixEnpMEgAAVBw"]
[Thu Sep 17 15:13:57.365501 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/turnstile.php"] [unique_id "aqxYFecL08BTTQixEnpMFgAAAGg"]
[Thu Sep 17 15:13:57.365620 2026] [security2:error] [pid 971102:tid 971338] [client 143.244.57.120:34374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/modules/turnstile/turnstile.php"] [unique_id "aqxYFecL08BTTQixEnpMFgAAAGg"]
[Thu Sep 17 15:13:57.453638 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.221.252:46244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.eng.qoc.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYFecL08BTTQixEnpMGAAAAB8"]
[Thu Sep 17 15:13:57.459225 2026] [core:error] [pid 971102:tid 971282] [client 34.166.130.148:47720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:57.459240 2026] [core:error] [pid 971102:tid 971282] [client 34.166.130.148:47720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:57.496927 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMFAAAAAM"]
[Thu Sep 17 15:13:57.496952 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMFAAAAAM"]
[Thu Sep 17 15:13:57.652722 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/shop/"] [unique_id "aqxYFecL08BTTQixEnpMHwAAABQ"]
[Thu Sep 17 15:13:57.654840 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/uninstall.php"] [unique_id "aqxYFecL08BTTQixEnpMIAAAAGk"]
[Thu Sep 17 15:13:57.654936 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:34384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/uninstall.php"] [unique_id "aqxYFecL08BTTQixEnpMIAAAAGk"]
[Thu Sep 17 15:13:57.880954 2026] [security2:error] [pid 971102:tid 971333] [client 156.192.234.52:55117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFecL08BTTQixEnpMLgAAAGM"]
[Thu Sep 17 15:13:57.881093 2026] [security2:error] [pid 971102:tid 971333] [client 156.192.234.52:55117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFecL08BTTQixEnpMLgAAAGM"]
[Thu Sep 17 15:13:57.937368 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:34396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/wp-contact-form-7.php"] [unique_id "aqxYFecL08BTTQixEnpMLwAAABg"]
[Thu Sep 17 15:13:57.937538 2026] [security2:error] [pid 971102:tid 971258] [client 143.244.57.120:34396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/contact-form-7/wp-contact-form-7.php"] [unique_id "aqxYFecL08BTTQixEnpMLwAAABg"]
[Thu Sep 17 15:13:57.997266 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMKQAAAGs"]
[Thu Sep 17 15:13:57.997292 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFecL08BTTQixEnpMKQAAAGs"]
[Thu Sep 17 15:13:58.010012 2026] [security2:error] [pid 971102:tid 971239] [client 193.36.224.116:36435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/about.php"] [unique_id "aqxYFucL08BTTQixEnpMNQAAAAU"]
[Thu Sep 17 15:13:58.148134 2026] [core:error] [pid 971102:tid 971290] [client 34.166.130.148:47728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.148154 2026] [core:error] [pid 971102:tid 971290] [client 34.166.130.148:47728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.211904 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/files/"] [unique_id "aqxYFucL08BTTQixEnpMOwAAAAQ"]
[Thu Sep 17 15:13:58.213354 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wordpress/"] [unique_id "aqxYFucL08BTTQixEnpMPAAAAHE"]
[Thu Sep 17 15:13:58.265447 2026] [security2:error] [pid 971102:tid 971242] [client 104.234.19.147:29005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxYFucL08BTTQixEnpMPwAAAAg"]
[Thu Sep 17 15:13:58.327995 2026] [security2:error] [pid 971102:tid 971319] [client 115.244.164.14:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFucL08BTTQixEnpMQQAAAFU"]
[Thu Sep 17 15:13:58.328084 2026] [security2:error] [pid 971102:tid 971319] [client 115.244.164.14:60016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYFucL08BTTQixEnpMQQAAAFU"]
[Thu Sep 17 15:13:58.400642 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wordpress/"] [unique_id "aqxYFucL08BTTQixEnpMRAAAAFg"]
[Thu Sep 17 15:13:58.447285 2026] [security2:error] [pid 971102:tid 971329] [client 162.241.226.11:16634] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxYFucL08BTTQixEnpMRgAAAF8"]
[Thu Sep 17 15:13:58.503453 2026] [security2:error] [pid 971102:tid 971287] [client 216.24.219.19:42493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxYFucL08BTTQixEnpMSgAAADU"]
[Thu Sep 17 15:13:58.557277 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/images/"] [unique_id "aqxYFucL08BTTQixEnpMSwAAAD4"]
[Thu Sep 17 15:13:58.589304 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMRwAAACw"]
[Thu Sep 17 15:13:58.589336 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMRwAAACw"]
[Thu Sep 17 15:13:58.754756 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/editor/"] [unique_id "aqxYFucL08BTTQixEnpMTwAAAEs"]
[Thu Sep 17 15:13:58.788033 2026] [security2:error] [pid 971102:tid 971330] [client 104.234.19.152:45283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxYFucL08BTTQixEnpMUAAAAGA"]
[Thu Sep 17 15:13:58.850569 2026] [core:error] [pid 971102:tid 971321] [client 34.166.130.148:47744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.850587 2026] [core:error] [pid 971102:tid 971321] [client 34.166.130.148:47744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:58.853836 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/images/"] [unique_id "aqxYFucL08BTTQixEnpMTgAAAFk"]
[Thu Sep 17 15:13:58.992300 2026] [security2:error] [pid 971102:tid 971283] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYFucL08BTTQixEnpMWQAAADE"]
[Thu Sep 17 15:13:59.071011 2026] [security2:error] [pid 971102:tid 971358] [client 193.36.224.149:60025] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxYF-cL08BTTQixEnpMWwAAAHw"]
[Thu Sep 17 15:13:59.085796 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMVgAAABk"]
[Thu Sep 17 15:13:59.085825 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYFucL08BTTQixEnpMVgAAABk"]
[Thu Sep 17 15:13:59.255750 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/include/"] [unique_id "aqxYF-cL08BTTQixEnpMYAAAACk"]
[Thu Sep 17 15:13:59.345856 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMXQAAAAk"]
[Thu Sep 17 15:13:59.345888 2026] [security2:error] [pid 971102:tid 971243] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMXQAAAAk"]
[Thu Sep 17 15:13:59.395343 2026] [security2:error] [pid 971102:tid 971272] [client 193.36.224.148:65063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/bless.php"] [unique_id "aqxYF-cL08BTTQixEnpMYgAAACY"]
[Thu Sep 17 15:13:59.424220 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:52293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYF-cL08BTTQixEnpMZQAAAAM"]
[Thu Sep 17 15:13:59.424313 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:52293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYF-cL08BTTQixEnpMZQAAAAM"]
[Thu Sep 17 15:13:59.483553 2026] [security2:error] [pid 971102:tid 971326] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxYF-cL08BTTQixEnpMbAAAAFw"]
[Thu Sep 17 15:13:59.600754 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMZwAAAEo"]
[Thu Sep 17 15:13:59.600784 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMZwAAAEo"]
[Thu Sep 17 15:13:59.605133 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:59.605152 2026] [core:error] [pid 971102:tid 971345] [client 34.166.130.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:13:59.699030 2026] [security2:error] [pid 971102:tid 971317] [client 216.24.219.104:34591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/goods.php"] [unique_id "aqxYF-cL08BTTQixEnpMeAAAAFM"]
[Thu Sep 17 15:13:59.827648 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/Assets/"] [unique_id "aqxYF-cL08BTTQixEnpMegAAAH8"]
[Thu Sep 17 15:13:59.837020 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMcwAAAHY"]
[Thu Sep 17 15:13:59.837042 2026] [security2:error] [pid 971102:tid 971352] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYF-cL08BTTQixEnpMcwAAAHY"]
[Thu Sep 17 15:14:00.017911 2026] [security2:error] [pid 971102:tid 971315] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/js/"] [unique_id "aqxYGOcL08BTTQixEnpMfwAAAFE"]
[Thu Sep 17 15:14:00.128035 2026] [security2:error] [pid 971102:tid 971249] [client 102.129.223.92:3765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.223.129.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vedur.app"] [uri "/wp-login.php"] [unique_id "aqxYGOcL08BTTQixEnpMgQAAAA8"], referer: http://vedur.app
[Thu Sep 17 15:14:00.179036 2026] [security2:error] [pid 971102:tid 971335] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgAAAAGU"]
[Thu Sep 17 15:14:00.179061 2026] [security2:error] [pid 971102:tid 971335] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgAAAAGU"]
[Thu Sep 17 15:14:00.350712 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgwAAAA0"]
[Thu Sep 17 15:14:00.350734 2026] [security2:error] [pid 971102:tid 971247] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMgwAAAA0"]
[Thu Sep 17 15:14:00.361516 2026] [security2:error] [pid 971102:tid 971279] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/images/stories/"] [unique_id "aqxYGOcL08BTTQixEnpMiAAAAC0"]
[Thu Sep 17 15:14:00.489517 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYGOcL08BTTQixEnpMiwAAAHU"]
[Thu Sep 17 15:14:00.510269 2026] [security2:error] [pid 971102:tid 971289] [client 104.28.198.244:22805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYGOcL08BTTQixEnpMjQAAADc"]
[Thu Sep 17 15:14:00.510364 2026] [security2:error] [pid 971102:tid 971289] [client 104.28.198.244:22805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYGOcL08BTTQixEnpMjQAAADc"]
[Thu Sep 17 15:14:00.693080 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMjwAAABY"]
[Thu Sep 17 15:14:00.693104 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMjwAAABY"]
[Thu Sep 17 15:14:00.770308 2026] [authz_core:error] [pid 971102:tid 971282] [client 169.58.197.253:60574] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:14:00.889639 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMkgAAABk"]
[Thu Sep 17 15:14:00.889668 2026] [security2:error] [pid 971102:tid 971259] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGOcL08BTTQixEnpMkgAAABk"]
[Thu Sep 17 15:14:00.909334 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/plugins/"] [unique_id "aqxYGOcL08BTTQixEnpMmAAAACA"]
[Thu Sep 17 15:14:00.980838 2026] [security2:error] [pid 971102:tid 971324] [client 216.24.219.20:32177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/blurbs.php"] [unique_id "aqxYGOcL08BTTQixEnpMnAAAAFo"]
[Thu Sep 17 15:14:01.028796 2026] [security2:error] [pid 971102:tid 971344] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYGecL08BTTQixEnpMnQAAAG4"]
[Thu Sep 17 15:14:01.267267 2026] [security2:error] [pid 971102:tid 971270] [client 104.234.19.143:51971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxYGecL08BTTQixEnpMpgAAACQ"]
[Thu Sep 17 15:14:01.287308 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMogAAAAo"]
[Thu Sep 17 15:14:01.287336 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMogAAAAo"]
[Thu Sep 17 15:14:01.430230 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMowAAAGM"]
[Thu Sep 17 15:14:01.430256 2026] [security2:error] [pid 971102:tid 971333] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMowAAAGM"]
[Thu Sep 17 15:14:01.451517 2026] [security2:error] [pid 971102:tid 971305] [client 47.79.200.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMoAAAAEc"], referer: https://www.google.com/
[Thu Sep 17 15:14:01.494911 2026] [core:error] [pid 971102:tid 971171] [remote 57.141.14.66:25080] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:01.494927 2026] [core:error] [pid 971102:tid 971171] [remote 57.141.14.66:25080] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:01.521202 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/php/"] [unique_id "aqxYGecL08BTTQixEnpMqwAAAGk"]
[Thu Sep 17 15:14:01.571296 2026] [security2:error] [pid 971102:tid 971317] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/meta/"] [unique_id "aqxYGecL08BTTQixEnpMrQAAAFM"]
[Thu Sep 17 15:14:01.762420 2026] [security2:error] [pid 971102:tid 971145] [remote 216.73.217.142:21738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxYGecL08BTTQixEnpMsQAAFyk"]
[Thu Sep 17 15:14:01.791981 2026] [security2:error] [pid 971102:tid 971359] [client 216.24.219.97:54485] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/abcd.php"] [unique_id "aqxYGecL08BTTQixEnpMtQAAAH0"]
[Thu Sep 17 15:14:01.793990 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/meta/"] [unique_id "aqxYGecL08BTTQixEnpMrwAAAAA"]
[Thu Sep 17 15:14:01.869061 2026] [security2:error] [pid 971102:tid 971306] [client 192.178.6.5:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYGecL08BTTQixEnpMtwAAAEg"]
[Thu Sep 17 15:14:01.886233 2026] [security2:error] [pid 971102:tid 971240] [client 85.204.70.116:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMsAAAAAY"]
[Thu Sep 17 15:14:01.886258 2026] [security2:error] [pid 971102:tid 971240] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYGecL08BTTQixEnpMsAAAAAY"]
[Thu Sep 17 15:14:01.934974 2026] [security2:error] [pid 971102:tid 971347] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/network/"] [unique_id "aqxYGecL08BTTQixEnpMuAAAAHE"]
[Thu Sep 17 15:14:02.055445 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/"] [unique_id "aqxYGucL08BTTQixEnpMvAAAABA"]
[Thu Sep 17 15:14:02.311893 2026] [autoindex:error] [pid 971102:tid 971299] [client 85.204.70.116:36182] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:02.312580 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/"] [unique_id "aqxYGucL08BTTQixEnpMvwAAAEE"]
[Thu Sep 17 15:14:02.352457 2026] [security2:error] [pid 971102:tid 971322] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxYGucL08BTTQixEnpMvQAAAFg"]
[Thu Sep 17 15:14:02.532742 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxYGucL08BTTQixEnpMxQAAACo"]
[Thu Sep 17 15:14:02.701260 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYGucL08BTTQixEnpMxwAAAFk"]
[Thu Sep 17 15:14:02.701406 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.120:60850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYGucL08BTTQixEnpMxwAAAFk"]
[Thu Sep 17 15:14:02.743062 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.116:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/twentytwenty/index.php"] [unique_id "aqxYGucL08BTTQixEnpMyAAAAHQ"]
[Thu Sep 17 15:14:02.846921 2026] [security2:error] [pid 971102:tid 971321] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/user/"] [unique_id "aqxYGucL08BTTQixEnpMzQAAAFc"]
[Thu Sep 17 15:14:02.924022 2026] [security2:error] [pid 971102:tid 971260] [client 216.24.219.38:30619] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxYGucL08BTTQixEnpMzwAAABo"]
[Thu Sep 17 15:14:02.958913 2026] [security2:error] [pid 971102:tid 971286] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/cache/"] [unique_id "aqxYGucL08BTTQixEnpM0QAAADQ"]
[Thu Sep 17 15:14:03.103093 2026] [security2:error] [pid 971102:tid 971266] [client 5.189.145.112:57924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxYG-cL08BTTQixEnpM1AAAACA"], referer: binance.com
[Thu Sep 17 15:14:03.400237 2026] [security2:error] [pid 971102:tid 971311] [client 193.36.224.116:28211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/dex.php"] [unique_id "aqxYG-cL08BTTQixEnpM1wAAAE0"]
[Thu Sep 17 15:14:03.480710 2026] [security2:error] [pid 971102:tid 971262] [client 114.198.138.124:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM3AAAABw"]
[Thu Sep 17 15:14:03.480844 2026] [security2:error] [pid 971102:tid 971262] [client 114.198.138.124:59483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM3AAAABw"]
[Thu Sep 17 15:14:03.539052 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:54580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxYG-cL08BTTQixEnpM1gAAACI"]
[Thu Sep 17 15:14:03.686242 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:54580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYG-cL08BTTQixEnpM4AAAAGk"]
[Thu Sep 17 15:14:03.686355 2026] [security2:error] [pid 971102:tid 971339] [client 143.244.57.120:54580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYG-cL08BTTQixEnpM4AAAAGk"]
[Thu Sep 17 15:14:03.689822 2026] [security2:error] [pid 971102:tid 971255] [client 4.240.114.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxYGucL08BTTQixEnpMzAAAABU"], referer: binance.com
[Thu Sep 17 15:14:03.699875 2026] [security2:error] [pid 971102:tid 971288] [client 104.234.19.146:58973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxYG-cL08BTTQixEnpM4QAAADY"]
[Thu Sep 17 15:14:03.793907 2026] [security2:error] [pid 971102:tid 971272] [client 154.190.208.131:42209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM4gAAACY"]
[Thu Sep 17 15:14:03.794058 2026] [security2:error] [pid 971102:tid 971272] [client 154.190.208.131:42209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYG-cL08BTTQixEnpM4gAAACY"]
[Thu Sep 17 15:14:03.831306 2026] [security2:error] [pid 971102:tid 971234] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/"] [unique_id "aqxYG-cL08BTTQixEnpM4wAAAAA"]
[Thu Sep 17 15:14:03.966880 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYG-cL08BTTQixEnpM3QAAAAk"]
[Thu Sep 17 15:14:03.966910 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYG-cL08BTTQixEnpM3QAAAAk"]
[Thu Sep 17 15:14:04.014727 2026] [security2:error] [pid 971102:tid 971346] [client 216.24.219.35:31065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM5wAAAHA"]
[Thu Sep 17 15:14:04.274399 2026] [security2:error] [pid 971102:tid 971354] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM7QAAAHg"]
[Thu Sep 17 15:14:04.322025 2026] [security2:error] [pid 971102:tid 971264] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/maint/"] [unique_id "aqxYHOcL08BTTQixEnpM7gAAAB4"]
[Thu Sep 17 15:14:04.418335 2026] [security2:error] [pid 971102:tid 971349] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/"] [unique_id "aqxYHOcL08BTTQixEnpM8AAAAHM"]
[Thu Sep 17 15:14:04.421657 2026] [security2:error] [pid 971102:tid 971238] [client 45.169.98.18:64465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYHOcL08BTTQixEnpM8QAAAAQ"]
[Thu Sep 17 15:14:04.421754 2026] [security2:error] [pid 971102:tid 971238] [client 45.169.98.18:64465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYHOcL08BTTQixEnpM8QAAAAQ"]
[Thu Sep 17 15:14:04.500689 2026] [security2:error] [pid 971102:tid 971353] [client 216.24.219.103:55127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM9AAAAHc"]
[Thu Sep 17 15:14:04.557214 2026] [autoindex:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:04.557779 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/maint/"] [unique_id "aqxYHOcL08BTTQixEnpM9QAAAHY"]
[Thu Sep 17 15:14:04.569181 2026] [security2:error] [pid 971102:tid 971310] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM9wAAAEw"]
[Thu Sep 17 15:14:04.700324 2026] [security2:error] [pid 971102:tid 971304] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM-QAARlE"], referer: http://envisionfilmvideo.com/new/
[Thu Sep 17 15:14:04.707876 2026] [security2:error] [pid 971102:tid 971299] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/"] [unique_id "aqxYHOcL08BTTQixEnpM-gAAAEE"]
[Thu Sep 17 15:14:04.761623 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYHOcL08BTTQixEnpM-wAAADM"]
[Thu Sep 17 15:14:04.783337 2026] [security2:error] [pid 971102:tid 971343] [client 193.36.224.149:39357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM_QAAAG0"]
[Thu Sep 17 15:14:04.857260 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/themes/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM_wAAAD4"]
[Thu Sep 17 15:14:04.872082 2026] [security2:error] [pid 971102:tid 971251] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHOcL08BTTQixEnpM_gAAEUk"], referer: http://envisionfilmvideo.com/old/
[Thu Sep 17 15:14:04.953570 2026] [authz_core:error] [pid 971102:tid 971247] [client 85.204.70.116:45598] AH01630: client denied by server configuration: /home1/zainridg/public_html/wp-content/plugins/akismet/
[Thu Sep 17 15:14:04.954152 2026] [security2:error] [pid 971102:tid 971247] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYHOcL08BTTQixEnpNAwAAAA0"]
[Thu Sep 17 15:14:04.995360 2026] [security2:error] [pid 971102:tid 971269] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYHOcL08BTTQixEnpNBQAAACM"]
[Thu Sep 17 15:14:05.163340 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/assets/"] [unique_id "aqxYHecL08BTTQixEnpNCQAAAHQ"]
[Thu Sep 17 15:14:05.187086 2026] [security2:error] [pid 971102:tid 971283] [client 193.36.224.219:41563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/index.php"] [unique_id "aqxYHecL08BTTQixEnpNCgAAADE"]
[Thu Sep 17 15:14:05.206780 2026] [authz_core:error] [pid 971102:tid 971351] [client 143.244.57.120:54596] AH01630: client denied by server configuration: /home1/endurin2/public_html/seedboxpress/wp-admin/includes/error_log
[Thu Sep 17 15:14:05.232446 2026] [security2:error] [pid 971102:tid 971358] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHecL08BTTQixEnpNCwAAfFo"], referer: http://envisionfilmvideo.com/backup/
[Thu Sep 17 15:14:05.275438 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYHecL08BTTQixEnpNCAAAAHU"]
[Thu Sep 17 15:14:05.342279 2026] [autoindex:error] [pid 971102:tid 971357] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:05.342773 2026] [security2:error] [pid 971102:tid 971357] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/assets/"] [unique_id "aqxYHecL08BTTQixEnpNEAAAAHs"]
[Thu Sep 17 15:14:05.402176 2026] [security2:error] [pid 971102:tid 971321] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHecL08BTTQixEnpNEQAAVyc"], referer: http://envisionfilmvideo.com/wp/
[Thu Sep 17 15:14:05.537022 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYHecL08BTTQixEnpNFQAAAGY"]
[Thu Sep 17 15:14:05.548565 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/privacy-tools.php"] [unique_id "aqxYHecL08BTTQixEnpNGAAAADw"]
[Thu Sep 17 15:14:05.548678 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:34400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/privacy-tools.php"] [unique_id "aqxYHecL08BTTQixEnpNGAAAADw"]
[Thu Sep 17 15:14:05.578439 2026] [security2:error] [pid 971102:tid 971286] [client 162.243.43.138:46680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxYHecL08BTTQixEnpNFgAANGo"], referer: http://envisionfilmvideo.com/wordpress/
[Thu Sep 17 15:14:05.589512 2026] [security2:error] [pid 971102:tid 971254] [client 193.36.224.212:44169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxYHecL08BTTQixEnpNGQAAABQ"]
[Thu Sep 17 15:14:05.761608 2026] [autoindex:error] [pid 971102:tid 971344] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:05.762170 2026] [security2:error] [pid 971102:tid 971344] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYHecL08BTTQixEnpNGgAAAG4"]
[Thu Sep 17 15:14:05.814151 2026] [security2:error] [pid 971102:tid 971303] [client 216.24.219.102:41135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/file.php"] [unique_id "aqxYHecL08BTTQixEnpNGwAAAEU"]
[Thu Sep 17 15:14:05.879052 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:33804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/schema.php"] [unique_id "aqxYHecL08BTTQixEnpNHAAAAFA"]
[Thu Sep 17 15:14:05.879155 2026] [security2:error] [pid 971102:tid 971314] [client 143.244.57.120:33804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/schema.php"] [unique_id "aqxYHecL08BTTQixEnpNHAAAAFA"]
[Thu Sep 17 15:14:05.958921 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYHecL08BTTQixEnpNHgAAAG8"]
[Thu Sep 17 15:14:06.074813 2026] [security2:error] [pid 971102:tid 971334] [client 193.36.224.167:36809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxYHucL08BTTQixEnpNIgAAAGQ"]
[Thu Sep 17 15:14:06.178612 2026] [autoindex:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:06.179093 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYHucL08BTTQixEnpNJQAAAGI"]
[Thu Sep 17 15:14:06.226676 2026] [security2:error] [pid 971102:tid 971239] [client 2.104.60.34:49732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "copiwestcoast.org"] [uri "/.env"] [unique_id "aqxYHucL08BTTQixEnpNKAAAAAU"]
[Thu Sep 17 15:14:06.303525 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:33808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/screen.php"] [unique_id "aqxYHucL08BTTQixEnpNKgAAACY"]
[Thu Sep 17 15:14:06.303627 2026] [security2:error] [pid 971102:tid 971272] [client 143.244.57.120:33808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/screen.php"] [unique_id "aqxYHucL08BTTQixEnpNKgAAACY"]
[Thu Sep 17 15:14:06.306202 2026] [security2:error] [pid 971102:tid 971243] [client 193.36.224.146:41191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-mail.php"] [unique_id "aqxYHucL08BTTQixEnpNKwAAAAk"]
[Thu Sep 17 15:14:06.340888 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/html-api/"] [unique_id "aqxYHucL08BTTQixEnpNLAAAAAA"]
[Thu Sep 17 15:14:06.565344 2026] [autoindex:error] [pid 971102:tid 971346] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:06.565822 2026] [security2:error] [pid 971102:tid 971346] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/html-api/"] [unique_id "aqxYHucL08BTTQixEnpNMAAAAHA"]
[Thu Sep 17 15:14:06.572387 2026] [security2:error] [pid 971102:tid 971355] [client 104.234.19.147:64285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/ioxi-o.php"] [unique_id "aqxYHucL08BTTQixEnpNMQAAAHk"]
[Thu Sep 17 15:14:06.599793 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/theme-install.php"] [unique_id "aqxYHucL08BTTQixEnpNMgAAAEQ"]
[Thu Sep 17 15:14:06.599862 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.120:33814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/theme-install.php"] [unique_id "aqxYHucL08BTTQixEnpNMgAAAEQ"]
[Thu Sep 17 15:14:06.742077 2026] [security2:error] [pid 971102:tid 971264] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/js/"] [unique_id "aqxYHucL08BTTQixEnpNNQAAAB4"]
[Thu Sep 17 15:14:06.792881 2026] [security2:error] [pid 971102:tid 971292] [client 104.234.19.145:51101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxYHucL08BTTQixEnpNOQAAADo"]
[Thu Sep 17 15:14:06.819396 2026] [security2:error] [pid 971102:tid 971238] [client 4.240.114.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxYHucL08BTTQixEnpNOAAAAAQ"], referer: binance.com
[Thu Sep 17 15:14:06.893224 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:33830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/translation-install.php"] [unique_id "aqxYHucL08BTTQixEnpNPAAAAEM"]
[Thu Sep 17 15:14:06.893338 2026] [security2:error] [pid 971102:tid 971301] [client 143.244.57.120:33830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/translation-install.php"] [unique_id "aqxYHucL08BTTQixEnpNPAAAAEM"]
[Thu Sep 17 15:14:06.949189 2026] [autoindex:error] [pid 971102:tid 971348] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:06.949681 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/js/"] [unique_id "aqxYHucL08BTTQixEnpNPQAAAHI"]
[Thu Sep 17 15:14:07.096501 2026] [security2:error] [pid 971102:tid 971287] [client 193.36.224.148:49651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/style.php"] [unique_id "aqxYH-cL08BTTQixEnpNRAAAADU"]
[Thu Sep 17 15:14:07.137885 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYH-cL08BTTQixEnpNRQAAAFE"]
[Thu Sep 17 15:14:07.174332 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:33834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/update-core.php"] [unique_id "aqxYH-cL08BTTQixEnpNRgAAAE4"]
[Thu Sep 17 15:14:07.174415 2026] [security2:error] [pid 971102:tid 971312] [client 143.244.57.120:33834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/update-core.php"] [unique_id "aqxYH-cL08BTTQixEnpNRgAAAE4"]
[Thu Sep 17 15:14:07.344928 2026] [security2:error] [pid 971102:tid 971310] [client 186.105.232.15:60198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYH-cL08BTTQixEnpNSQAAAEw"]
[Thu Sep 17 15:14:07.345029 2026] [security2:error] [pid 971102:tid 971310] [client 186.105.232.15:60198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYH-cL08BTTQixEnpNSQAAAEw"]
[Thu Sep 17 15:14:07.348425 2026] [autoindex:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:07.349184 2026] [security2:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYH-cL08BTTQixEnpNSAAAACU"]
[Thu Sep 17 15:14:07.371739 2026] [security2:error] [pid 971102:tid 971278] [client 74.7.230.0:37532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.rwz.qhz.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "aqxYH-cL08BTTQixEnpNSgAAACw"]
[Thu Sep 17 15:14:07.468597 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:33842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/upgrade.php"] [unique_id "aqxYH-cL08BTTQixEnpNTAAAACo"]
[Thu Sep 17 15:14:07.468717 2026] [security2:error] [pid 971102:tid 971276] [client 143.244.57.120:33842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/includes/upgrade.php"] [unique_id "aqxYH-cL08BTTQixEnpNTAAAACo"]
[Thu Sep 17 15:14:07.489121 2026] [security2:error] [pid 971102:tid 971342] [client 104.234.19.151:34767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/style.php"] [unique_id "aqxYH-cL08BTTQixEnpNTgAAAGw"]
[Thu Sep 17 15:14:07.564869 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYH-cL08BTTQixEnpNUAAAAHw"]
[Thu Sep 17 15:14:07.729055 2026] [security2:error] [pid 971102:tid 971265] [client 193.36.224.226:39457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxYH-cL08BTTQixEnpNUgAAAB8"]
[Thu Sep 17 15:14:07.756989 2026] [security2:error] [pid 971102:tid 971316] [client 143.244.57.120:33844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/"] [unique_id "aqxYH-cL08BTTQixEnpNVAAAAFI"]
[Thu Sep 17 15:14:07.764312 2026] [autoindex:error] [pid 971102:tid 971277] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:07.765025 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYH-cL08BTTQixEnpNUwAAACs"]
[Thu Sep 17 15:14:07.954134 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/pomo/"] [unique_id "aqxYH-cL08BTTQixEnpNVwAAABQ"]
[Thu Sep 17 15:14:08.132840 2026] [security2:error] [pid 971102:tid 971248] [client 128.242.183.58:18891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.churchinirving.org"] [uri "/index.php"] [unique_id "aqxYIOcL08BTTQixEnpNWAAAAA4"]
[Thu Sep 17 15:14:08.143455 2026] [autoindex:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:08.144024 2026] [security2:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/pomo/"] [unique_id "aqxYIOcL08BTTQixEnpNYAAAADc"]
[Thu Sep 17 15:14:08.191386 2026] [security2:error] [pid 971102:tid 971294] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.seedboxpress.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYH-cL08BTTQixEnpNVgAAADw"]
[Thu Sep 17 15:14:08.332049 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYIOcL08BTTQixEnpNYwAAACI"]
[Thu Sep 17 15:14:08.332163 2026] [security2:error] [pid 971102:tid 971268] [client 143.244.57.120:54596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxYIOcL08BTTQixEnpNYwAAACI"]
[Thu Sep 17 15:14:08.332164 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/random_compat/"] [unique_id "aqxYIOcL08BTTQixEnpNYgAAABM"]
[Thu Sep 17 15:14:08.471906 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.120:33844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.seedboxpress.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxYIOcL08BTTQixEnpNZQAAABc"]
[Thu Sep 17 15:14:08.479465 2026] [security2:error] [pid 971102:tid 971282] [client 156.192.234.52:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNZgAAADA"]
[Thu Sep 17 15:14:08.480880 2026] [security2:error] [pid 971102:tid 971282] [client 156.192.234.52:55732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNZgAAADA"]
[Thu Sep 17 15:14:08.583123 2026] [security2:error] [pid 971102:tid 971288] [client 193.36.224.108:60381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-editor.php"] [unique_id "aqxYIOcL08BTTQixEnpNawAAADY"]
[Thu Sep 17 15:14:08.719372 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYIOcL08BTTQixEnpNagAAAGI"]
[Thu Sep 17 15:14:08.719393 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYIOcL08BTTQixEnpNagAAAGI"]
[Thu Sep 17 15:14:08.828902 2026] [security2:error] [pid 971102:tid 971305] [client 115.244.164.14:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNbgAAAEc"]
[Thu Sep 17 15:14:08.828994 2026] [security2:error] [pid 971102:tid 971305] [client 115.244.164.14:60670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYIOcL08BTTQixEnpNbgAAAEc"]
[Thu Sep 17 15:14:08.915445 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.120:54602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.seedboxpress.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxYIOcL08BTTQixEnpNbwAAAEg"]
[Thu Sep 17 15:14:08.950140 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYIOcL08BTTQixEnpNcQAAAHg"]
[Thu Sep 17 15:14:09.124196 2026] [autoindex:error] [pid 971102:tid 971347] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:09.124711 2026] [security2:error] [pid 971102:tid 971347] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYIecL08BTTQixEnpNdQAAAHE"]
[Thu Sep 17 15:14:09.315778 2026] [security2:error] [pid 971102:tid 971284] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYIecL08BTTQixEnpNeAAAADI"]
[Thu Sep 17 15:14:09.538371 2026] [autoindex:error] [pid 971102:tid 971287] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:09.538897 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYIecL08BTTQixEnpNqwAAADU"]
[Thu Sep 17 15:14:09.826716 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYIecL08BTTQixEnpN2gAAACw"]
[Thu Sep 17 15:14:10.024487 2026] [autoindex:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:10.024960 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYIucL08BTTQixEnpN8gAAAHw"]
[Thu Sep 17 15:14:10.076683 2026] [security2:error] [pid 971102:tid 971240] [client 185.55.149.49:52937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYIucL08BTTQixEnpN9AAAAAY"]
[Thu Sep 17 15:14:10.076794 2026] [security2:error] [pid 971102:tid 971240] [client 185.55.149.49:52937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYIucL08BTTQixEnpN9AAAAAY"]
[Thu Sep 17 15:14:10.241645 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYIucL08BTTQixEnpN9gAAACs"]
[Thu Sep 17 15:14:10.354148 2026] [security2:error] [pid 971102:tid 971350] [client 193.36.224.206:63797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/lufix.php"] [unique_id "aqxYIucL08BTTQixEnpN9wAAAHQ"]
[Thu Sep 17 15:14:10.432389 2026] [autoindex:error] [pid 971102:tid 971340] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:10.432895 2026] [security2:error] [pid 971102:tid 971340] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYIucL08BTTQixEnpN-AAAAGo"]
[Thu Sep 17 15:14:10.671224 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYIucL08BTTQixEnpN_AAAACA"]
[Thu Sep 17 15:14:10.692685 2026] [security2:error] [pid 971102:tid 971324] [client 193.36.224.182:62787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/txets.php"] [unique_id "aqxYIucL08BTTQixEnpN_QAAAFo"]
[Thu Sep 17 15:14:10.724837 2026] [security2:error] [pid 971102:tid 971248] [client 5.189.145.112:56290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxYIucL08BTTQixEnpN_gAAAA4"], referer: binance.com
[Thu Sep 17 15:14:10.844224 2026] [autoindex:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:10.844837 2026] [security2:error] [pid 971102:tid 971289] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYIucL08BTTQixEnpOAQAAADc"]
[Thu Sep 17 15:14:10.962574 2026] [security2:error] [pid 971102:tid 971352] [client 5.178.15.127:2635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYIucL08BTTQixEnpN_wAAAHY"]
[Thu Sep 17 15:14:11.044860 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/widgets/"] [unique_id "aqxYI-cL08BTTQixEnpOCAAAAE0"]
[Thu Sep 17 15:14:11.056105 2026] [autoindex:error] [pid 971102:tid 971294] [client 212.156.70.154:15213] AH01276: Cannot serve directory /home1/hbnxuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:11.122168 2026] [security2:error] [pid 971102:tid 971256] [client 193.36.224.168:21363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxYI-cL08BTTQixEnpOCwAAABY"]
[Thu Sep 17 15:14:11.243767 2026] [autoindex:error] [pid 971102:tid 971253] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:11.244388 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-includes/widgets/"] [unique_id "aqxYI-cL08BTTQixEnpODAAAABM"]
[Thu Sep 17 15:14:11.440368 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYI-cL08BTTQixEnpODwAAADA"]
[Thu Sep 17 15:14:11.679737 2026] [autoindex:error] [pid 971102:tid 971333] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:11.680465 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYI-cL08BTTQixEnpOEwAAAGM"]
[Thu Sep 17 15:14:11.850868 2026] [security2:error] [pid 971102:tid 971332] [client 193.36.224.152:40603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxYI-cL08BTTQixEnpOGQAAAGI"]
[Thu Sep 17 15:14:11.928592 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYI-cL08BTTQixEnpOGwAAAAA"]
[Thu Sep 17 15:14:12.182735 2026] [autoindex:error] [pid 971102:tid 971245] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:12.183203 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYJOcL08BTTQixEnpOHwAAAAs"]
[Thu Sep 17 15:14:12.337493 2026] [security2:error] [pid 971102:tid 971355] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/images/slider/"] [unique_id "aqxYJOcL08BTTQixEnpOIgAAAHk"]
[Thu Sep 17 15:14:12.753480 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJOcL08BTTQixEnpOJgAAAF8"]
[Thu Sep 17 15:14:12.753506 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJOcL08BTTQixEnpOJgAAAF8"]
[Thu Sep 17 15:14:12.959684 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxYJOcL08BTTQixEnpOKAAAABA"]
[Thu Sep 17 15:14:13.249542 2026] [security2:error] [pid 971102:tid 971310] [client 216.24.219.20:31219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxYJecL08BTTQixEnpOLQAAAEw"]
[Thu Sep 17 15:14:13.269042 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOLAAAAAg"]
[Thu Sep 17 15:14:13.269064 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOLAAAAAg"]
[Thu Sep 17 15:14:13.485087 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/sites/default/files/"] [unique_id "aqxYJecL08BTTQixEnpOMQAAAH4"]
[Thu Sep 17 15:14:13.796064 2026] [security2:error] [pid 971102:tid 971319] [client 104.234.19.148:31127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/goods.php"] [unique_id "aqxYJecL08BTTQixEnpONAAAAFU"]
[Thu Sep 17 15:14:13.864729 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOMwAAAHw"]
[Thu Sep 17 15:14:13.864753 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOMwAAAHw"]
[Thu Sep 17 15:14:13.940844 2026] [security2:error] [pid 971102:tid 971357] [client 20.244.34.24:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxYJecL08BTTQixEnpONQAAAHs"], referer: binance.com
[Thu Sep 17 15:14:14.045028 2026] [security2:error] [pid 971102:tid 971281] [client 114.198.138.124:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOOQAAAC8"]
[Thu Sep 17 15:14:14.045126 2026] [security2:error] [pid 971102:tid 971281] [client 114.198.138.124:60316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOOQAAAC8"]
[Thu Sep 17 15:14:14.052755 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxYJucL08BTTQixEnpOOgAAAHU"]
[Thu Sep 17 15:14:14.393574 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJucL08BTTQixEnpOOwAAAEs"]
[Thu Sep 17 15:14:14.393599 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJucL08BTTQixEnpOOwAAAEs"]
[Thu Sep 17 15:14:14.927288 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:65030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOPwAAADg"]
[Thu Sep 17 15:14:14.927436 2026] [security2:error] [pid 971102:tid 971290] [client 45.169.98.18:65030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJucL08BTTQixEnpOPwAAADg"]
[Thu Sep 17 15:14:15.054846 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:41478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJ-cL08BTTQixEnpOQwAAAGg"]
[Thu Sep 17 15:14:15.063921 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:41478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYJ-cL08BTTQixEnpOQwAAAGg"]
[Thu Sep 17 15:14:15.247326 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxYJ-cL08BTTQixEnpORAAAAEU"]
[Thu Sep 17 15:14:15.567502 2026] [security2:error] [pid 971102:tid 971348] [client 34.44.142.114:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxYJecL08BTTQixEnpOLgAAcm0"]
[Thu Sep 17 15:14:15.590640 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpORQAAAHY"]
[Thu Sep 17 15:14:15.590684 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpORQAAAHY"]
[Thu Sep 17 15:14:15.772075 2026] [security2:error] [pid 971102:tid 971345] [client 104.234.19.146:22735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "georgehamp.com"] [uri "/php8.php"] [unique_id "aqxYJ-cL08BTTQixEnpOTgAAAG8"]
[Thu Sep 17 15:14:15.786272 2026] [security2:error] [pid 971102:tid 971326] [client 34.44.142.114:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpOTAAAXGA"]
[Thu Sep 17 15:14:15.823276 2026] [security2:error] [pid 971102:tid 971273] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/components/"] [unique_id "aqxYJ-cL08BTTQixEnpOTwAAACc"]
[Thu Sep 17 15:14:16.091712 2026] [security2:error] [pid 971102:tid 971318] [client 34.44.142.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxYJ-cL08BTTQixEnpOVAAAAFQ"]
[Thu Sep 17 15:14:16.174226 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOWAAAAD0"]
[Thu Sep 17 15:14:16.174247 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOWAAAAD0"]
[Thu Sep 17 15:14:16.341844 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/admin/uploads/images/"] [unique_id "aqxYKOcL08BTTQixEnpOXAAAAEg"]
[Thu Sep 17 15:14:16.674560 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOYAAAABs"]
[Thu Sep 17 15:14:16.674584 2026] [security2:error] [pid 971102:tid 971261] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKOcL08BTTQixEnpOYAAAABs"]
[Thu Sep 17 15:14:16.854253 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxYKOcL08BTTQixEnpOZgAAAAQ"]
[Thu Sep 17 15:14:17.017124 2026] [security2:error] [pid 971102:tid 971312] [client 5.189.145.112:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxYKecL08BTTQixEnpObAAAAE4"], referer: binance.com
[Thu Sep 17 15:14:17.052298 2026] [autoindex:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/plugins/classic-editor/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:17.052816 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxYKecL08BTTQixEnpObgAAAH8"]
[Thu Sep 17 15:14:17.235256 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/fonts/"] [unique_id "aqxYKecL08BTTQixEnpObwAAAD4"]
[Thu Sep 17 15:14:17.564476 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOdAAAAAc"]
[Thu Sep 17 15:14:17.564496 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOdAAAAAc"]
[Thu Sep 17 15:14:17.745456 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxYKecL08BTTQixEnpOewAAACo"]
[Thu Sep 17 15:14:18.052076 2026] [authz_core:error] [pid 971102:tid 971323] [client 169.58.197.253:61646] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:14:18.082556 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOfQAAAC8"]
[Thu Sep 17 15:14:18.082581 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKecL08BTTQixEnpOfQAAAC8"]
[Thu Sep 17 15:14:18.263418 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxYKucL08BTTQixEnpOhQAAAEs"]
[Thu Sep 17 15:14:18.314150 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:60805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYKucL08BTTQixEnpOhgAAAHs"]
[Thu Sep 17 15:14:18.315205 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:60805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYKucL08BTTQixEnpOhgAAAHs"]
[Thu Sep 17 15:14:18.578707 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKucL08BTTQixEnpOiwAAAGg"]
[Thu Sep 17 15:14:18.578739 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYKucL08BTTQixEnpOiwAAAGg"]
[Thu Sep 17 15:14:18.754032 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wordpress/"] [unique_id "aqxYKucL08BTTQixEnpOkAAAAE0"]
[Thu Sep 17 15:14:19.040294 2026] [security2:error] [pid 971102:tid 971294] [client 156.192.234.52:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmQAAADw"]
[Thu Sep 17 15:14:19.040878 2026] [security2:error] [pid 971102:tid 971294] [client 156.192.234.52:56353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmQAAADw"]
[Thu Sep 17 15:14:19.171767 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYK-cL08BTTQixEnpOmAAAABk"]
[Thu Sep 17 15:14:19.171792 2026] [security2:error] [pid 971102:tid 971259] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYK-cL08BTTQixEnpOmAAAABk"]
[Thu Sep 17 15:14:19.391234 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:61329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmgAAAGY"]
[Thu Sep 17 15:14:19.391331 2026] [security2:error] [pid 971102:tid 971336] [client 115.244.164.14:61329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYK-cL08BTTQixEnpOmgAAAGY"]
[Thu Sep 17 15:14:20.152242 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/images/"] [unique_id "aqxYLOcL08BTTQixEnpOqgAAAHg"]
[Thu Sep 17 15:14:20.384800 2026] [autoindex:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:20.385319 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/images/"] [unique_id "aqxYLOcL08BTTQixEnpOqwAAAH8"]
[Thu Sep 17 15:14:20.542573 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYLOcL08BTTQixEnpOrwAAAAE"]
[Thu Sep 17 15:14:20.602416 2026] [fcgid:warn] [pid 971102:tid 971335] (70014)End of file found: [client 167.94.146.56:40888] mod_fcgid: can't get data from http client
[Thu Sep 17 15:14:20.891835 2026] [security2:error] [pid 971102:tid 971284] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLOcL08BTTQixEnpOsQAAADI"]
[Thu Sep 17 15:14:20.891871 2026] [security2:error] [pid 971102:tid 971284] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLOcL08BTTQixEnpOsQAAADI"]
[Thu Sep 17 15:14:20.952896 2026] [security2:error] [pid 971102:tid 971296] [client 185.55.149.49:51630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYLOcL08BTTQixEnpOswAAAD4"]
[Thu Sep 17 15:14:20.953040 2026] [security2:error] [pid 971102:tid 971296] [client 185.55.149.49:51630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYLOcL08BTTQixEnpOswAAAD4"]
[Thu Sep 17 15:14:21.147510 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxYLecL08BTTQixEnpOtwAAADo"]
[Thu Sep 17 15:14:21.467825 2026] [security2:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOugAAACU"]
[Thu Sep 17 15:14:21.467849 2026] [security2:error] [pid 971102:tid 971271] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOugAAACU"]
[Thu Sep 17 15:14:21.721277 2026] [security2:error] [pid 971102:tid 971343] [client 104.28.198.244:22700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYLecL08BTTQixEnpOxgAAAG0"]
[Thu Sep 17 15:14:21.721359 2026] [security2:error] [pid 971102:tid 971343] [client 104.28.198.244:22700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYLecL08BTTQixEnpOxgAAAG0"]
[Thu Sep 17 15:14:21.740063 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/js/"] [unique_id "aqxYLecL08BTTQixEnpOxwAAACs"]
[Thu Sep 17 15:14:21.756054 2026] [security2:error] [pid 971102:tid 971186] [remote 216.73.217.142:21738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYLecL08BTTQixEnpOyQAAD1I"]
[Thu Sep 17 15:14:22.068201 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOygAAABo"]
[Thu Sep 17 15:14:22.068227 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYLecL08BTTQixEnpOygAAABo"]
[Thu Sep 17 15:14:22.336097 2026] [security2:error] [pid 971102:tid 971344] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYLucL08BTTQixEnpO0QAAAG4"]
[Thu Sep 17 15:14:22.540391 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/plugins/woocommerce/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:22.540925 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYLucL08BTTQixEnpO1wAAACA"]
[Thu Sep 17 15:14:22.748154 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYLucL08BTTQixEnpO2gAAAH0"]
[Thu Sep 17 15:14:23.019711 2026] [autoindex:error] [pid 971102:tid 971280] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/plugins/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:23.020186 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYL-cL08BTTQixEnpO3gAAAC4"]
[Thu Sep 17 15:14:23.190029 2026] [core:error] [pid 971102:tid 971333] [client 31.56.58.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:23.190046 2026] [core:error] [pid 971102:tid 971333] [client 31.56.58.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:23.216844 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/meta/"] [unique_id "aqxYL-cL08BTTQixEnpO5QAAAGs"]
[Thu Sep 17 15:14:23.564255 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.116:45598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO5gAAAEQ"]
[Thu Sep 17 15:14:23.564278 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO5gAAAEQ"]
[Thu Sep 17 15:14:23.738930 2026] [security2:error] [pid 971102:tid 971307] [client 35.198.113.100:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO6QAASWU"]
[Thu Sep 17 15:14:23.741881 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/network/"] [unique_id "aqxYL-cL08BTTQixEnpO7gAAAAE"]
[Thu Sep 17 15:14:24.081944 2026] [security2:error] [pid 971102:tid 971299] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/network/index.php"] [unique_id "aqxYL-cL08BTTQixEnpO8AAAAEE"]
[Thu Sep 17 15:14:24.135175 2026] [security2:error] [pid 971102:tid 971258] [client 37.231.33.242:62867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYMOcL08BTTQixEnpO8wAAGAw"]
[Thu Sep 17 15:14:24.242973 2026] [security2:error] [pid 971102:tid 971245] [client 5.189.145.112:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxYMOcL08BTTQixEnpO-wAAAAs"], referer: binance.com
[Thu Sep 17 15:14:24.316748 2026] [security2:error] [pid 971102:tid 971251] [client 134.185.85.61:49430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "tengushee.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYMOcL08BTTQixEnpO_AAAABE"]
[Thu Sep 17 15:14:24.685682 2026] [security2:error] [pid 971102:tid 971276] [client 114.198.138.124:63121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMOcL08BTTQixEnpPAgAAACo"]
[Thu Sep 17 15:14:24.685775 2026] [security2:error] [pid 971102:tid 971276] [client 114.198.138.124:63121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMOcL08BTTQixEnpPAgAAACo"]
[Thu Sep 17 15:14:24.717596 2026] [security2:error] [pid 971102:tid 971313] [client 134.185.85.61:57115] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "tengushee.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYMOcL08BTTQixEnpPAwAAAE8"]
[Thu Sep 17 15:14:25.306840 2026] [security2:error] [pid 971102:tid 971270] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPIAAAJAo"]
[Thu Sep 17 15:14:25.368848 2026] [security2:error] [pid 971102:tid 971343] [client 85.204.70.116:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMecL08BTTQixEnpPIgAAAG0"]
[Thu Sep 17 15:14:25.368975 2026] [security2:error] [pid 971102:tid 971343] [client 85.204.70.116:44594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMecL08BTTQixEnpPIgAAAG0"]
[Thu Sep 17 15:14:25.438788 2026] [security2:error] [pid 971102:tid 971311] [client 45.169.98.18:49205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPIwAAAE0"]
[Thu Sep 17 15:14:25.438891 2026] [security2:error] [pid 971102:tid 971311] [client 45.169.98.18:49205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPIwAAAE0"]
[Thu Sep 17 15:14:25.476212 2026] [security2:error] [pid 971102:tid 971144] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env"] [unique_id "aqxYMecL08BTTQixEnpPJAAAHCg"]
[Thu Sep 17 15:14:25.476646 2026] [security2:error] [pid 971102:tid 971154] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.bak"] [unique_id "aqxYMecL08BTTQixEnpPLgAAHDI"]
[Thu Sep 17 15:14:25.476651 2026] [security2:error] [pid 971102:tid 971228] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.old"] [unique_id "aqxYMecL08BTTQixEnpPKwAAHHs"]
[Thu Sep 17 15:14:25.476672 2026] [security2:error] [pid 971102:tid 971149] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.backup"] [unique_id "aqxYMecL08BTTQixEnpPLQAAHC0"]
[Thu Sep 17 15:14:25.529544 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/user/"] [unique_id "aqxYMecL08BTTQixEnpPTAAAAAQ"]
[Thu Sep 17 15:14:25.581605 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:42077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPUQAAAHY"]
[Thu Sep 17 15:14:25.586142 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:42077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYMecL08BTTQixEnpPUQAAAHY"]
[Thu Sep 17 15:14:25.633439 2026] [security2:error] [pid 971102:tid 971115] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/.env.php"] [unique_id "aqxYMecL08BTTQixEnpPUwAAHAs"]
[Thu Sep 17 15:14:25.653475 2026] [security2:error] [pid 971102:tid 971295] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRAAAAD0"]
[Thu Sep 17 15:14:25.655746 2026] [security2:error] [pid 971102:tid 971291] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPQwAAADk"]
[Thu Sep 17 15:14:25.658591 2026] [security2:error] [pid 971102:tid 971256] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPQgAAABY"]
[Thu Sep 17 15:14:25.668803 2026] [security2:error] [pid 971102:tid 971341] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRwAAAGs"]
[Thu Sep 17 15:14:25.668803 2026] [security2:error] [pid 971102:tid 971354] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRQAAAHg"]
[Thu Sep 17 15:14:25.671175 2026] [security2:error] [pid 971102:tid 971302] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPSAAAAEQ"]
[Thu Sep 17 15:14:25.671683 2026] [security2:error] [pid 971102:tid 971334] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPSgAAAGQ"]
[Thu Sep 17 15:14:25.672121 2026] [security2:error] [pid 971102:tid 971261] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPRgAAABs"]
[Thu Sep 17 15:14:25.679452 2026] [security2:error] [pid 971102:tid 971237] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPTQAAAAM"]
[Thu Sep 17 15:14:25.680373 2026] [security2:error] [pid 971102:tid 971257] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPSwAAABc"]
[Thu Sep 17 15:14:25.684011 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPTgAAAB4"]
[Thu Sep 17 15:14:25.691096 2026] [security2:error] [pid 971102:tid 971312] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPTwAAAE4"]
[Thu Sep 17 15:14:25.769239 2026] [security2:error] [pid 971102:tid 971111] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env~"] [unique_id "aqxYMecL08BTTQixEnpPXQAAHAc"]
[Thu Sep 17 15:14:25.770665 2026] [security2:error] [pid 971102:tid 971268] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPWQAAACI"]
[Thu Sep 17 15:14:25.770708 2026] [security2:error] [pid 971102:tid 971239] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPWgAAAAU"]
[Thu Sep 17 15:14:25.770784 2026] [security2:error] [pid 971102:tid 971279] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPWwAAAC0"]
[Thu Sep 17 15:14:25.801718 2026] [security2:error] [pid 971102:tid 971132] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.env.swp"] [unique_id "aqxYMecL08BTTQixEnpPXgAAHBw"]
[Thu Sep 17 15:14:25.900850 2026] [security2:error] [pid 971102:tid 971269] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/user/index.php"] [unique_id "aqxYMecL08BTTQixEnpPXAAAACM"]
[Thu Sep 17 15:14:25.933007 2026] [security2:error] [pid 971102:tid 971240] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPYQAAAAY"]
[Thu Sep 17 15:14:25.933968 2026] [security2:error] [pid 971102:tid 971138] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/backend/.env"] [unique_id "aqxYMecL08BTTQixEnpPagAAHCI"]
[Thu Sep 17 15:14:25.933988 2026] [security2:error] [pid 971102:tid 971171] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/app/.env"] [unique_id "aqxYMecL08BTTQixEnpPaAAAHEM"]
[Thu Sep 17 15:14:25.934055 2026] [security2:error] [pid 971102:tid 971108] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/api/.env"] [unique_id "aqxYMecL08BTTQixEnpPZgAAHAQ"]
[Thu Sep 17 15:14:26.235543 2026] [security2:error] [pid 971102:tid 971145] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/src/.env"] [unique_id "aqxYMucL08BTTQixEnpPgQAAHCk"]
[Thu Sep 17 15:14:26.235559 2026] [security2:error] [pid 971102:tid 971161] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/config/.env"] [unique_id "aqxYMucL08BTTQixEnpPggAAHDk"]
[Thu Sep 17 15:14:26.235582 2026] [security2:error] [pid 971102:tid 971168] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/server/.env"] [unique_id "aqxYMucL08BTTQixEnpPgAAAHEA"]
[Thu Sep 17 15:14:26.235603 2026] [security2:error] [pid 971102:tid 971188] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/web/.env"] [unique_id "aqxYMucL08BTTQixEnpPgwAAHFM"]
[Thu Sep 17 15:14:26.235684 2026] [security2:error] [pid 971102:tid 971174] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/client/.env"] [unique_id "aqxYMucL08BTTQixEnpPhAAAHEY"]
[Thu Sep 17 15:14:26.236587 2026] [security2:error] [pid 971102:tid 971172] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/public/.env"] [unique_id "aqxYMucL08BTTQixEnpPhgAAHEQ"]
[Thu Sep 17 15:14:26.236645 2026] [security2:error] [pid 971102:tid 971167] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/frontend/.env"] [unique_id "aqxYMucL08BTTQixEnpPhQAAHD8"]
[Thu Sep 17 15:14:26.236683 2026] [security2:error] [pid 971102:tid 971165] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/var/www/.env"] [unique_id "aqxYMucL08BTTQixEnpPhwAAHD0"]
[Thu Sep 17 15:14:26.236729 2026] [security2:error] [pid 971102:tid 971175] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/var/www/html/.env"] [unique_id "aqxYMucL08BTTQixEnpPiAAAHEc"]
[Thu Sep 17 15:14:26.324622 2026] [security2:error] [pid 971102:tid 971248] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPdgAAAA4"]
[Thu Sep 17 15:14:26.327293 2026] [security2:error] [pid 971102:tid 971340] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPeQAAAGo"]
[Thu Sep 17 15:14:26.328639 2026] [security2:error] [pid 971102:tid 971321] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPegAAAFc"]
[Thu Sep 17 15:14:26.328851 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPdwAAABQ"]
[Thu Sep 17 15:14:26.329649 2026] [security2:error] [pid 971102:tid 971246] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPeAAAAAw"]
[Thu Sep 17 15:14:26.330440 2026] [security2:error] [pid 971102:tid 971260] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPdQAAABo"]
[Thu Sep 17 15:14:26.334072 2026] [security2:error] [pid 971102:tid 971338] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMecL08BTTQixEnpPfAAAAGg"]
[Thu Sep 17 15:14:26.370269 2026] [security2:error] [pid 971102:tid 971137] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/apps/.env"] [unique_id "aqxYMucL08BTTQixEnpPiwAAKSE"]
[Thu Sep 17 15:14:26.370294 2026] [security2:error] [pid 971102:tid 971185] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/application/.env"] [unique_id "aqxYMucL08BTTQixEnpPigAAKVE"]
[Thu Sep 17 15:14:26.370313 2026] [security2:error] [pid 971102:tid 971177] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/back/.env"] [unique_id "aqxYMucL08BTTQixEnpPjAAAKUk"]
[Thu Sep 17 15:14:26.370355 2026] [security2:error] [pid 971102:tid 971179] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/backup/.env"] [unique_id "aqxYMucL08BTTQixEnpPjQAAKUs"]
[Thu Sep 17 15:14:26.370385 2026] [security2:error] [pid 971102:tid 971152] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/laravel/.env"] [unique_id "aqxYMucL08BTTQixEnpPiQAAKTA"]
[Thu Sep 17 15:14:26.370817 2026] [security2:error] [pid 971102:tid 971113] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/prod/.env"] [unique_id "aqxYMucL08BTTQixEnpPkAAAKQk"]
[Thu Sep 17 15:14:26.370849 2026] [security2:error] [pid 971102:tid 971182] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/dev/.env"] [unique_id "aqxYMucL08BTTQixEnpPjwAAKU4"]
[Thu Sep 17 15:14:26.370855 2026] [security2:error] [pid 971102:tid 971195] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/production/.env"] [unique_id "aqxYMucL08BTTQixEnpPkQAAKVo"]
[Thu Sep 17 15:14:26.371029 2026] [security2:error] [pid 971102:tid 971159] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/cms/.env"] [unique_id "aqxYMucL08BTTQixEnpPjgAAKTc"]
[Thu Sep 17 15:14:26.460412 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMucL08BTTQixEnpPlAAAAH0"]
[Thu Sep 17 15:14:26.460511 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:44610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYMucL08BTTQixEnpPlAAAAH0"]
[Thu Sep 17 15:14:26.465578 2026] [security2:error] [pid 971102:tid 971211] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/staging/.env"] [unique_id "aqxYMucL08BTTQixEnpPlQAAPWo"]
[Thu Sep 17 15:14:26.467855 2026] [security2:error] [pid 971102:tid 971170] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/test/.env"] [unique_id "aqxYMucL08BTTQixEnpPlgAAOUI"]
[Thu Sep 17 15:14:26.469785 2026] [security2:error] [pid 971102:tid 971164] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/old/.env"] [unique_id "aqxYMucL08BTTQixEnpPlwAAFjw"]
[Thu Sep 17 15:14:26.505401 2026] [security2:error] [pid 971102:tid 971180] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/admin-app/.env"] [unique_id "aqxYMucL08BTTQixEnpPmwAAZUw"]
[Thu Sep 17 15:14:26.505464 2026] [security2:error] [pid 971102:tid 971151] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/node-api/.env"] [unique_id "aqxYMucL08BTTQixEnpPmAAAZS8"]
[Thu Sep 17 15:14:26.505490 2026] [security2:error] [pid 971102:tid 971183] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/new/.env"] [unique_id "aqxYMucL08BTTQixEnpPmQAAZU8"]
[Thu Sep 17 15:14:26.505525 2026] [security2:error] [pid 971102:tid 971205] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/api-backend/.env"] [unique_id "aqxYMucL08BTTQixEnpPmgAAZWQ"]
[Thu Sep 17 15:14:26.505841 2026] [security2:error] [pid 971102:tid 971213] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/current/.env"] [unique_id "aqxYMucL08BTTQixEnpPngAAZWw"]
[Thu Sep 17 15:14:26.505897 2026] [security2:error] [pid 971102:tid 971201] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.aws/.env"] [unique_id "aqxYMucL08BTTQixEnpPpAAAZWA"]
[Thu Sep 17 15:14:26.505941 2026] [security2:error] [pid 971102:tid 971189] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/public_html/.env"] [unique_id "aqxYMucL08BTTQixEnpPnQAAZVQ"]
[Thu Sep 17 15:14:26.505941 2026] [security2:error] [pid 971102:tid 971181] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/server/backend/.env"] [unique_id "aqxYMucL08BTTQixEnpPoAAAZU0"]
[Thu Sep 17 15:14:26.505953 2026] [security2:error] [pid 971102:tid 971193] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/aws/.env"] [unique_id "aqxYMucL08BTTQixEnpPogAAZVg"]
[Thu Sep 17 15:14:26.506004 2026] [security2:error] [pid 971102:tid 971198] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/server/api/.env"] [unique_id "aqxYMucL08BTTQixEnpPnwAAZV0"]
[Thu Sep 17 15:14:26.506018 2026] [security2:error] [pid 971102:tid 971210] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.docker/.env"] [unique_id "aqxYMucL08BTTQixEnpPoQAAZWk"]
[Thu Sep 17 15:14:26.506035 2026] [security2:error] [pid 971102:tid 971214] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxYMucL08BTTQixEnpPowAAZW0"]
[Thu Sep 17 15:14:26.537306 2026] [security2:error] [pid 971102:tid 971184] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/administrator/.env"] [unique_id "aqxYMucL08BTTQixEnpPnAAAZVA"]
[Thu Sep 17 15:14:26.600464 2026] [security2:error] [pid 971102:tid 971197] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/stripe/.env"] [unique_id "aqxYMucL08BTTQixEnpPpwAAO1w"]
[Thu Sep 17 15:14:26.639776 2026] [security2:error] [pid 971102:tid 971222] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/v3/.env"] [unique_id "aqxYMucL08BTTQixEnpPsAAAXHU"]
[Thu Sep 17 15:14:26.639791 2026] [security2:error] [pid 971102:tid 971192] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/v1/.env"] [unique_id "aqxYMucL08BTTQixEnpPrgAAXFc"]
[Thu Sep 17 15:14:26.639875 2026] [security2:error] [pid 971102:tid 971207] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/media/.env"] [unique_id "aqxYMucL08BTTQixEnpPsQAAXGY"]
[Thu Sep 17 15:14:26.639891 2026] [security2:error] [pid 971102:tid 971230] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/v2/.env"] [unique_id "aqxYMucL08BTTQixEnpPrwAAXH0"]
[Thu Sep 17 15:14:26.642691 2026] [security2:error] [pid 971102:tid 971250] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/"] [unique_id "aqxYMucL08BTTQixEnpPugAAABA"]
[Thu Sep 17 15:14:26.655586 2026] [security2:error] [pid 971102:tid 971235] [client 151.63.101.195:63293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYMucL08BTTQixEnpPpQAAAXA"]
[Thu Sep 17 15:14:26.745826 2026] [security2:error] [pid 971102:tid 971354] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPrQAAAHg"]
[Thu Sep 17 15:14:26.751202 2026] [security2:error] [pid 971102:tid 971341] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPrAAAAGs"]
[Thu Sep 17 15:14:26.775428 2026] [security2:error] [pid 971102:tid 971107] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.git/config.bak"] [unique_id "aqxYMucL08BTTQixEnpP0QAAXAM"]
[Thu Sep 17 15:14:26.794678 2026] [security2:error] [pid 971102:tid 971329] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPwwAAAF8"]
[Thu Sep 17 15:14:26.797185 2026] [security2:error] [pid 971102:tid 971245] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPxQAAAAs"]
[Thu Sep 17 15:14:26.798875 2026] [security2:error] [pid 971102:tid 971318] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPxgAAAFQ"]
[Thu Sep 17 15:14:26.811178 2026] [security2:error] [pid 971102:tid 971288] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPyAAAADY"]
[Thu Sep 17 15:14:26.814209 2026] [security2:error] [pid 971102:tid 971251] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPyQAAABE"]
[Thu Sep 17 15:14:26.816065 2026] [security2:error] [pid 971102:tid 971237] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPywAAAAM"]
[Thu Sep 17 15:14:26.821958 2026] [security2:error] [pid 971102:tid 971332] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPygAAAGI"]
[Thu Sep 17 15:14:26.853638 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/index.php"] [unique_id "aqxYMucL08BTTQixEnpP2gAAAEg"]
[Thu Sep 17 15:14:26.854579 2026] [security2:error] [pid 971102:tid 971333] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpPzAAAAGM"]
[Thu Sep 17 15:14:26.893418 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP0wAAAB4"]
[Thu Sep 17 15:14:26.910574 2026] [security2:error] [pid 971102:tid 971308] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP1wAAAEo"]
[Thu Sep 17 15:14:26.927128 2026] [security2:error] [pid 971102:tid 971304] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP2QAAAEY"]
[Thu Sep 17 15:14:26.927475 2026] [security2:error] [pid 971102:tid 971247] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP2AAAAA0"]
[Thu Sep 17 15:14:26.957417 2026] [security2:error] [pid 971102:tid 971215] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxYMucL08BTTQixEnpP7QAAXG4"]
[Thu Sep 17 15:14:27.037430 2026] [security2:error] [pid 971102:tid 971110] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxYM-cL08BTTQixEnpQAgAAXAY"]
[Thu Sep 17 15:14:27.049323 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/"] [unique_id "aqxYM-cL08BTTQixEnpQBAAAAE8"]
[Thu Sep 17 15:14:27.052773 2026] [security2:error] [pid 971102:tid 971209] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/id_rsa"] [unique_id "aqxYM-cL08BTTQixEnpQBgAAXGg"]
[Thu Sep 17 15:14:27.247629 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQFAAAACk"]
[Thu Sep 17 15:14:27.320887 2026] [security2:error] [pid 971102:tid 971324] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP5AAAAFo"]
[Thu Sep 17 15:14:27.338957 2026] [security2:error] [pid 971102:tid 971289] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP6QAAADc"]
[Thu Sep 17 15:14:27.366788 2026] [security2:error] [pid 971102:tid 971270] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP9QAAACQ"]
[Thu Sep 17 15:14:27.367045 2026] [security2:error] [pid 971102:tid 971321] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP9gAAAFc"]
[Thu Sep 17 15:14:27.367574 2026] [security2:error] [pid 971102:tid 971246] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP9wAAAAw"]
[Thu Sep 17 15:14:27.369081 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP-AAAABQ"]
[Thu Sep 17 15:14:27.372037 2026] [security2:error] [pid 971102:tid 971327] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP-gAAAF0"]
[Thu Sep 17 15:14:27.377795 2026] [security2:error] [pid 971102:tid 971348] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpP_gAAAHI"]
[Thu Sep 17 15:14:27.378758 2026] [security2:error] [pid 971102:tid 971260] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYMucL08BTTQixEnpP-QAAABo"]
[Thu Sep 17 15:14:27.379546 2026] [security2:error] [pid 971102:tid 971311] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQAwAAAE0"]
[Thu Sep 17 15:14:27.380993 2026] [security2:error] [pid 971102:tid 971282] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQDAAAADA"]
[Thu Sep 17 15:14:27.382607 2026] [security2:error] [pid 971102:tid 971323] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQEwAAAFk"]
[Thu Sep 17 15:14:27.435403 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/"] [unique_id "aqxYM-cL08BTTQixEnpQGwAAAE4"]
[Thu Sep 17 15:14:27.570037 2026] [security2:error] [pid 971102:tid 971332] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQIwAAAGI"]
[Thu Sep 17 15:14:27.585152 2026] [security2:error] [pid 971102:tid 971268] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQJQAAACI"]
[Thu Sep 17 15:14:27.623819 2026] [security2:error] [pid 971102:tid 971358] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQKAAAAHw"]
[Thu Sep 17 15:14:27.639741 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/themes/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQRAAAAAA"]
[Thu Sep 17 15:14:27.707137 2026] [security2:error] [pid 971102:tid 971153] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config.php"] [unique_id "aqxYM-cL08BTTQixEnpQSwAAXDE"]
[Thu Sep 17 15:14:27.862016 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/includes/"] [unique_id "aqxYM-cL08BTTQixEnpQXAAAABw"]
[Thu Sep 17 15:14:28.069149 2026] [autoindex:error] [pid 971102:tid 971246] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:28.069702 2026] [security2:error] [pid 971102:tid 971246] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/includes/"] [unique_id "aqxYNOcL08BTTQixEnpQZgAAAAw"]
[Thu Sep 17 15:14:28.114326 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "aqxYNOcL08BTTQixEnpQaQAAATk"]
[Thu Sep 17 15:14:28.114334 2026] [security2:error] [pid 971102:tid 971168] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "aqxYNOcL08BTTQixEnpQbgAAAUA"]
[Thu Sep 17 15:14:28.115190 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "aqxYNOcL08BTTQixEnpQbwAAATk"]
[Thu Sep 17 15:14:28.159156 2026] [security2:error] [pid 971102:tid 971176] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "aqxYNOcL08BTTQixEnpQeAAAAUg"]
[Thu Sep 17 15:14:28.252587 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/"] [unique_id "aqxYNOcL08BTTQixEnpQeQAAAE0"]
[Thu Sep 17 15:14:28.273335 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxYNOcL08BTTQixEnpQfwAAMEk"]
[Thu Sep 17 15:14:28.277717 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxYNOcL08BTTQixEnpQfgAAMFE"]
[Thu Sep 17 15:14:28.278824 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQOwAAAB4"]
[Thu Sep 17 15:14:28.285389 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxYNOcL08BTTQixEnpQgAAAMEk"]
[Thu Sep 17 15:14:28.286603 2026] [security2:error] [pid 971102:tid 971320] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQPAAAAFY"]
[Thu Sep 17 15:14:28.295191 2026] [security2:error] [pid 971102:tid 971178] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxYNOcL08BTTQixEnpQiQAAMEo"]
[Thu Sep 17 15:14:28.297998 2026] [security2:error] [pid 971102:tid 971349] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQPgAAAHM"]
[Thu Sep 17 15:14:28.303613 2026] [security2:error] [pid 971102:tid 971247] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQQQAAAA0"]
[Thu Sep 17 15:14:28.304414 2026] [security2:error] [pid 971102:tid 971296] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQQwAAAD4"]
[Thu Sep 17 15:14:28.305319 2026] [security2:error] [pid 971102:tid 971308] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQPwAAAEo"]
[Thu Sep 17 15:14:28.317490 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQQgAAADg"]
[Thu Sep 17 15:14:28.341566 2026] [security2:error] [pid 971102:tid 971273] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQRQAAACc"]
[Thu Sep 17 15:14:28.384770 2026] [security2:error] [pid 971102:tid 971353] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQVAAAAHc"]
[Thu Sep 17 15:14:28.384771 2026] [security2:error] [pid 971102:tid 971238] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQXQAAAAQ"]
[Thu Sep 17 15:14:28.385225 2026] [security2:error] [pid 971102:tid 971361] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQSgAAAH8"]
[Thu Sep 17 15:14:28.398398 2026] [security2:error] [pid 971102:tid 971359] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQXgAAAH0"]
[Thu Sep 17 15:14:28.400282 2026] [security2:error] [pid 971102:tid 971275] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQXwAAACk"]
[Thu Sep 17 15:14:28.403212 2026] [security2:error] [pid 971102:tid 971321] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQZwAAAFc"]
[Thu Sep 17 15:14:28.403718 2026] [security2:error] [pid 971102:tid 971283] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQYAAAADE"]
[Thu Sep 17 15:14:28.407075 2026] [security2:error] [pid 971102:tid 971278] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYM-cL08BTTQixEnpQUQAAACw"]
[Thu Sep 17 15:14:28.465722 2026] [security2:error] [pid 971102:tid 971201] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/aws.php"] [unique_id "aqxYNOcL08BTTQixEnpQkwAAXGA"]
[Thu Sep 17 15:14:28.465731 2026] [security2:error] [pid 971102:tid 971181] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/stripe.php"] [unique_id "aqxYNOcL08BTTQixEnpQlQAAXE0"]
[Thu Sep 17 15:14:28.471436 2026] [security2:error] [pid 971102:tid 971184] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "aqxYNOcL08BTTQixEnpQmQAAZlA"]
[Thu Sep 17 15:14:28.471576 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "aqxYNOcL08BTTQixEnpQnQAAZlw"]
[Thu Sep 17 15:14:28.496728 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/.env.php"] [unique_id "aqxYNOcL08BTTQixEnpQmgAAZmk"]
[Thu Sep 17 15:14:28.524004 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/.env.php"] [unique_id "aqxYNOcL08BTTQixEnpQpAAANDs"]
[Thu Sep 17 15:14:28.539039 2026] [security2:error] [pid 971102:tid 971200] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxYNOcL08BTTQixEnpQqAAAUl8"]
[Thu Sep 17 15:14:28.542809 2026] [security2:error] [pid 971102:tid 971196] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/mail.php"] [unique_id "aqxYNOcL08BTTQixEnpQqgAAXFs"]
[Thu Sep 17 15:14:28.542842 2026] [security2:error] [pid 971102:tid 971120] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/config.inc.php"] [unique_id "aqxYNOcL08BTTQixEnpQqwAAXBA"]
[Thu Sep 17 15:14:28.547602 2026] [security2:error] [pid 971102:tid 971216] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/config/nexmo.php"] [unique_id "aqxYNOcL08BTTQixEnpQrgAAXG8"]
[Thu Sep 17 15:14:28.551707 2026] [security2:error] [pid 971102:tid 971106] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/wp-config.php"] [unique_id "aqxYNOcL08BTTQixEnpQsQAAXAI"]
[Thu Sep 17 15:14:28.585010 2026] [security2:error] [pid 971102:tid 971136] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxYNOcL08BTTQixEnpQtwAAACA"]
[Thu Sep 17 15:14:28.596221 2026] [security2:error] [pid 971102:tid 971110] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ivorygarlock.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYNOcL08BTTQixEnpQugAAXAY"]
[Thu Sep 17 15:14:28.599189 2026] [security2:error] [pid 971102:tid 971105] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ivorygarlock.com"] [uri "/wp-config.php.old"] [unique_id "aqxYNOcL08BTTQixEnpQuwAAXAE"]
[Thu Sep 17 15:14:28.599645 2026] [security2:error] [pid 971102:tid 971209] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ivorygarlock.com"] [uri "/wp-config.php.new"] [unique_id "aqxYNOcL08BTTQixEnpQvAAAXGg"]
[Thu Sep 17 15:14:28.601044 2026] [security2:error] [pid 971102:tid 971191] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYNOcL08BTTQixEnpQwAAAXFY"]
[Thu Sep 17 15:14:28.601628 2026] [security2:error] [pid 971102:tid 971118] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "aqxYNOcL08BTTQixEnpQvwAAEQ4"]
[Thu Sep 17 15:14:28.601748 2026] [security2:error] [pid 971102:tid 971204] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "aqxYNOcL08BTTQixEnpQvQAAEWM"]
[Thu Sep 17 15:14:28.613896 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.zainridgecondo.org"] [uri "/wp-admin/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQjwAAAH4"]
[Thu Sep 17 15:14:28.621915 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "aqxYNOcL08BTTQixEnpQxQAAEQg"]
[Thu Sep 17 15:14:28.644003 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "aqxYNOcL08BTTQixEnpQyAAAEQU"]
[Thu Sep 17 15:14:28.644054 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "aqxYNOcL08BTTQixEnpQzAAAEWE"]
[Thu Sep 17 15:14:28.644125 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "aqxYNOcL08BTTQixEnpQygAAESQ"]
[Thu Sep 17 15:14:28.644153 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "aqxYNOcL08BTTQixEnpQyQAAEWs"]
[Thu Sep 17 15:14:28.657369 2026] [security2:error] [pid 971102:tid 971285] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQpwAAADM"]
[Thu Sep 17 15:14:28.675576 2026] [security2:error] [pid 971102:tid 971261] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQtQAAABs"]
[Thu Sep 17 15:14:28.676558 2026] [security2:error] [pid 971102:tid 971218] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ0AAAdXE"]
[Thu Sep 17 15:14:28.676677 2026] [security2:error] [pid 971102:tid 971142] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "aqxYNOcL08BTTQixEnpQzwAAdSY"]
[Thu Sep 17 15:14:28.681226 2026] [security2:error] [pid 971102:tid 971356] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQtAAAAHo"]
[Thu Sep 17 15:14:28.681758 2026] [security2:error] [pid 971102:tid 971160] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ1QAAPTg"]
[Thu Sep 17 15:14:28.681899 2026] [security2:error] [pid 971102:tid 971224] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ1gAAHHc"]
[Thu Sep 17 15:14:28.682067 2026] [security2:error] [pid 971102:tid 971119] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxYNOcL08BTTQixEnpQ0gAAXA8"]
[Thu Sep 17 15:14:28.695726 2026] [security2:error] [pid 971102:tid 971104] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ2QAAJAA"]
[Thu Sep 17 15:14:28.703449 2026] [security2:error] [pid 971102:tid 971206] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ2wAABmU"]
[Thu Sep 17 15:14:28.723982 2026] [security2:error] [pid 971102:tid 971334] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQwQAAAGQ"]
[Thu Sep 17 15:14:28.739906 2026] [security2:error] [pid 971102:tid 971231] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ5QAAbH4"]
[Thu Sep 17 15:14:28.740003 2026] [security2:error] [pid 971102:tid 971114] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ5gAAbAo"]
[Thu Sep 17 15:14:28.752606 2026] [security2:error] [pid 971102:tid 971158] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ5wAAEDY"]
[Thu Sep 17 15:14:28.754654 2026] [security2:error] [pid 971102:tid 971288] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQxwAAADY"]
[Thu Sep 17 15:14:28.772028 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ6QAARDI"]
[Thu Sep 17 15:14:28.775501 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ6gAAczE"]
[Thu Sep 17 15:14:28.782547 2026] [security2:error] [pid 971102:tid 971174] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ6wAAPkY"]
[Thu Sep 17 15:14:28.782601 2026] [security2:error] [pid 971102:tid 971134] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7QAAPh4"]
[Thu Sep 17 15:14:28.782643 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7wAAPgc"]
[Thu Sep 17 15:14:28.782643 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7gAAPkQ"]
[Thu Sep 17 15:14:28.782918 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ7AAAPlM"]
[Thu Sep 17 15:14:28.795961 2026] [security2:error] [pid 971102:tid 971167] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ8gAAeD8"]
[Thu Sep 17 15:14:28.804929 2026] [security2:error] [pid 971102:tid 971175] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ9QAAL0c"]
[Thu Sep 17 15:14:28.815366 2026] [security2:error] [pid 971102:tid 971176] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ9wAAF0g"]
[Thu Sep 17 15:14:28.815499 2026] [security2:error] [pid 971102:tid 971150] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxYNOcL08BTTQixEnpQ9gAAXC4"]
[Thu Sep 17 15:14:28.829117 2026] [security2:error] [pid 971102:tid 971139] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxYNOcL08BTTQixEnpQ_QAAeSM"]
[Thu Sep 17 15:14:28.839676 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxYNOcL08BTTQixEnpRAQAAOg0"]
[Thu Sep 17 15:14:28.852050 2026] [security2:error] [pid 971102:tid 971157] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBgAAUTU"]
[Thu Sep 17 15:14:28.852062 2026] [security2:error] [pid 971102:tid 971179] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "aqxYNOcL08BTTQixEnpRAwAAUUs"]
[Thu Sep 17 15:14:28.852122 2026] [security2:error] [pid 971102:tid 971164] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBAAAUTw"]
[Thu Sep 17 15:14:28.852128 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBQAAUQQ"]
[Thu Sep 17 15:14:28.852188 2026] [security2:error] [pid 971102:tid 971170] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "aqxYNOcL08BTTQixEnpRBwAAUUI"]
[Thu Sep 17 15:14:28.993717 2026] [security2:error] [pid 971102:tid 971229] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxYNOcL08BTTQixEnpRHQAAC3w"]
[Thu Sep 17 15:14:29.008148 2026] [security2:error] [pid 971102:tid 971159] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "aqxYNecL08BTTQixEnpRHgAAaDc"]
[Thu Sep 17 15:14:29.008178 2026] [security2:error] [pid 971102:tid 971144] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRHwAAaCg"]
[Thu Sep 17 15:14:29.008224 2026] [security2:error] [pid 971102:tid 971149] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "aqxYNecL08BTTQixEnpRKgAAaC0"]
[Thu Sep 17 15:14:29.008274 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "aqxYNecL08BTTQixEnpRLQAAaCI"]
[Thu Sep 17 15:14:29.008279 2026] [security2:error] [pid 971102:tid 971113] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "aqxYNecL08BTTQixEnpRKAAAaAk"]
[Thu Sep 17 15:14:29.008316 2026] [security2:error] [pid 971102:tid 971146] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRJAAAaCo"]
[Thu Sep 17 15:14:29.008318 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "aqxYNecL08BTTQixEnpRIQAAaBU"]
[Thu Sep 17 15:14:29.008353 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRJQAAaBs"]
[Thu Sep 17 15:14:29.008413 2026] [security2:error] [pid 971102:tid 971129] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "aqxYNecL08BTTQixEnpRLAAAaBk"]
[Thu Sep 17 15:14:29.008414 2026] [security2:error] [pid 971102:tid 971211] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRIwAAaGo"]
[Thu Sep 17 15:14:29.008440 2026] [security2:error] [pid 971102:tid 971135] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "aqxYNecL08BTTQixEnpRJgAAaB8"]
[Thu Sep 17 15:14:29.008474 2026] [security2:error] [pid 971102:tid 971195] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "aqxYNecL08BTTQixEnpRIAAAaFo"]
[Thu Sep 17 15:14:29.008480 2026] [security2:error] [pid 971102:tid 971152] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "aqxYNecL08BTTQixEnpRIgAAaDA"]
[Thu Sep 17 15:14:29.043842 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxYNecL08BTTQixEnpRMAAAIUk"]
[Thu Sep 17 15:14:29.043901 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxYNecL08BTTQixEnpRLwAAIUM"]
[Thu Sep 17 15:14:29.043904 2026] [security2:error] [pid 971102:tid 971205] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxYNecL08BTTQixEnpRMwAAIWQ"]
[Thu Sep 17 15:14:29.043936 2026] [security2:error] [pid 971102:tid 971201] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxYNecL08BTTQixEnpRMgAAIWA"]
[Thu Sep 17 15:14:29.043958 2026] [security2:error] [pid 971102:tid 971181] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxYNecL08BTTQixEnpRMQAAIU0"]
[Thu Sep 17 15:14:29.060623 2026] [security2:error] [pid 971102:tid 971182] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "aqxYNecL08BTTQixEnpRJwAAaE4"]
[Thu Sep 17 15:14:29.132122 2026] [security2:error] [pid 971102:tid 971184] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxYNecL08BTTQixEnpRNgAAU1A"]
[Thu Sep 17 15:14:29.168474 2026] [security2:error] [pid 971102:tid 971143] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxYNecL08BTTQixEnpRPgAAQCc"]
[Thu Sep 17 15:14:29.168476 2026] [security2:error] [pid 971102:tid 971193] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/back/.env"] [unique_id "aqxYNecL08BTTQixEnpROgAAQFg"]
[Thu Sep 17 15:14:29.168504 2026] [security2:error] [pid 971102:tid 971192] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxYNecL08BTTQixEnpRQAAAQFc"]
[Thu Sep 17 15:14:29.168576 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxYNecL08BTTQixEnpRPQAAQHg"]
[Thu Sep 17 15:14:29.168576 2026] [security2:error] [pid 971102:tid 971198] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxYNecL08BTTQixEnpRPwAAQF0"]
[Thu Sep 17 15:14:29.168609 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxYNecL08BTTQixEnpROQAAQGk"]
[Thu Sep 17 15:14:29.168609 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxYNecL08BTTQixEnpRPAAAQG0"]
[Thu Sep 17 15:14:29.168624 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "aqxYNecL08BTTQixEnpRQQAAEzs"]
[Thu Sep 17 15:14:29.168806 2026] [security2:error] [pid 971102:tid 971207] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxYNecL08BTTQixEnpROwAAQGY"]
[Thu Sep 17 15:14:29.220502 2026] [security2:error] [pid 971102:tid 971222] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "aqxYNecL08BTTQixEnpRSQAAWHU"]
[Thu Sep 17 15:14:29.220613 2026] [security2:error] [pid 971102:tid 971186] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "aqxYNecL08BTTQixEnpRUQAAWFI"]
[Thu Sep 17 15:14:29.224769 2026] [security2:error] [pid 971102:tid 971191] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "aqxYNecL08BTTQixEnpRUwAAFFY"]
[Thu Sep 17 15:14:29.243417 2026] [security2:error] [pid 971102:tid 971204] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxYNecL08BTTQixEnpRWAAAFmM"]
[Thu Sep 17 15:14:29.243455 2026] [security2:error] [pid 971102:tid 971118] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxYNecL08BTTQixEnpRVAAAFg4"]
[Thu Sep 17 15:14:29.243502 2026] [security2:error] [pid 971102:tid 971194] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/node-api/.env"] [unique_id "aqxYNecL08BTTQixEnpRVgAAFlk"]
[Thu Sep 17 15:14:29.243505 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/api-backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRVQAAFgg"]
[Thu Sep 17 15:14:29.243573 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/new/.env"] [unique_id "aqxYNecL08BTTQixEnpRVwAAFl4"]
[Thu Sep 17 15:14:29.284941 2026] [security2:error] [pid 971102:tid 971276] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQzgAAACo"]
[Thu Sep 17 15:14:29.310897 2026] [security2:error] [pid 971102:tid 971326] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ0wAAXBY"]
[Thu Sep 17 15:14:29.331609 2026] [security2:error] [pid 971102:tid 971289] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ2gAAADc"]
[Thu Sep 17 15:14:29.342449 2026] [security2:error] [pid 971102:tid 971327] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ3AAAAF0"]
[Thu Sep 17 15:14:29.392378 2026] [security2:error] [pid 971102:tid 971304] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpREAAAAEY"]
[Thu Sep 17 15:14:29.393444 2026] [security2:error] [pid 971102:tid 971318] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRQgAAAFQ"]
[Thu Sep 17 15:14:29.396448 2026] [security2:error] [pid 971102:tid 971330] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpRCgAAAGA"]
[Thu Sep 17 15:14:29.396945 2026] [security2:error] [pid 971102:tid 971278] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpRGAAAACw"]
[Thu Sep 17 15:14:29.397989 2026] [security2:error] [pid 971102:tid 971283] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpREwAAADE"]
[Thu Sep 17 15:14:29.398349 2026] [security2:error] [pid 971102:tid 971359] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpREQAAAH0"]
[Thu Sep 17 15:14:29.401214 2026] [security2:error] [pid 971102:tid 971280] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpQ9AAAAC4"]
[Thu Sep 17 15:14:29.402444 2026] [security2:error] [pid 971102:tid 971313] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXAAAAE8"]
[Thu Sep 17 15:14:29.422351 2026] [security2:error] [pid 971102:tid 971242] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNOcL08BTTQixEnpRAAAAAAg"]
[Thu Sep 17 15:14:29.432998 2026] [security2:error] [pid 971102:tid 971282] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXgAAADA"]
[Thu Sep 17 15:14:29.435919 2026] [security2:error] [pid 971102:tid 971350] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXQAAAHQ"]
[Thu Sep 17 15:14:29.441138 2026] [security2:error] [pid 971102:tid 971345] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRXwAAAG8"]
[Thu Sep 17 15:14:29.509966 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYNecL08BTTQixEnpRbgAAAAM"]
[Thu Sep 17 15:14:29.510051 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.116:44616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zainridgecondo.org"] [uri "/wp-login.php"] [unique_id "aqxYNecL08BTTQixEnpRbgAAAAM"]
[Thu Sep 17 15:14:29.528720 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxYNecL08BTTQixEnpRdgAADU8"]
[Thu Sep 17 15:14:29.528721 2026] [security2:error] [pid 971102:tid 971206] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/server/api/.env"] [unique_id "aqxYNecL08BTTQixEnpRegAADWU"]
[Thu Sep 17 15:14:29.528797 2026] [security2:error] [pid 971102:tid 971162] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.docker/.env"] [unique_id "aqxYNecL08BTTQixEnpReQAADTo"]
[Thu Sep 17 15:14:29.528837 2026] [security2:error] [pid 971102:tid 971224] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/admin-app/.env"] [unique_id "aqxYNecL08BTTQixEnpRcgAADXc"]
[Thu Sep 17 15:14:29.528868 2026] [security2:error] [pid 971102:tid 971208] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxYNecL08BTTQixEnpRcQAADWc"]
[Thu Sep 17 15:14:29.528885 2026] [security2:error] [pid 971102:tid 971151] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/server/backend/.env"] [unique_id "aqxYNecL08BTTQixEnpRdAAADS8"]
[Thu Sep 17 15:14:29.528974 2026] [security2:error] [pid 971102:tid 971116] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxYNecL08BTTQixEnpReAAADQw"]
[Thu Sep 17 15:14:29.563903 2026] [security2:error] [pid 971102:tid 971174] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRhgAAOEY"]
[Thu Sep 17 15:14:29.564004 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxYNecL08BTTQixEnpRiAAAODE"]
[Thu Sep 17 15:14:29.564084 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxYNecL08BTTQixEnpRiwAAOFM"]
[Thu Sep 17 15:14:29.564106 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.docker/laravel/app/.env"] [unique_id "aqxYNecL08BTTQixEnpRjAAAODI"]
[Thu Sep 17 15:14:29.564123 2026] [security2:error] [pid 971102:tid 971230] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxYNecL08BTTQixEnpRjQAAOH0"]
[Thu Sep 17 15:14:29.564176 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/stripe/.env"] [unique_id "aqxYNecL08BTTQixEnpRiQAAOAc"]
[Thu Sep 17 15:14:29.568683 2026] [security2:error] [pid 971102:tid 971249] [client 186.105.232.15:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRjwAAAA8"]
[Thu Sep 17 15:14:29.568769 2026] [security2:error] [pid 971102:tid 971249] [client 186.105.232.15:61401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRjwAAAA8"]
[Thu Sep 17 15:14:29.570924 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:56953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRkAAAAEw"]
[Thu Sep 17 15:14:29.571555 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:56953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNecL08BTTQixEnpRkAAAAEw"]
[Thu Sep 17 15:14:29.602868 2026] [security2:error] [pid 971102:tid 971342] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRawAAAGw"]
[Thu Sep 17 15:14:29.604204 2026] [security2:error] [pid 971102:tid 971264] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRbAAAAB4"]
[Thu Sep 17 15:14:29.680321 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/.env.php"] [unique_id "aqxYNecL08BTTQixEnpRpAAAVw0"]
[Thu Sep 17 15:14:29.684531 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/credentials.bak"] [unique_id "aqxYNecL08BTTQixEnpRqQAACwQ"]
[Thu Sep 17 15:14:29.693393 2026] [security2:error] [pid 971102:tid 971159] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "aqxYNecL08BTTQixEnpRrQAAaDc"]
[Thu Sep 17 15:14:29.693402 2026] [security2:error] [pid 971102:tid 971229] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "aqxYNecL08BTTQixEnpRsgAAaHw"]
[Thu Sep 17 15:14:29.694626 2026] [security2:error] [pid 971102:tid 971137] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "aqxYNecL08BTTQixEnpRsQAAaCE"]
[Thu Sep 17 15:14:29.699977 2026] [security2:error] [pid 971102:tid 971152] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/.ssh/id_rsa"] [unique_id "aqxYNecL08BTTQixEnpRwQAARzA"]
[Thu Sep 17 15:14:29.700823 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/id_rsa"] [unique_id "aqxYNecL08BTTQixEnpRwgAAR1E"]
[Thu Sep 17 15:14:29.735154 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.116:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/upgrade/"] [unique_id "aqxYNecL08BTTQixEnpRywAAADU"]
[Thu Sep 17 15:14:29.752202 2026] [security2:error] [pid 971102:tid 971205] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxYNecL08BTTQixEnpRzgAAB2Q"]
[Thu Sep 17 15:14:29.899858 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/media/.env"] [unique_id "aqxYNecL08BTTQixEnpR4AAALGk"]
[Thu Sep 17 15:14:29.901740 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "aqxYNecL08BTTQixEnpR4QAAX20"]
[Thu Sep 17 15:14:29.901759 2026] [security2:error] [pid 971102:tid 971207] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "aqxYNecL08BTTQixEnpR4gAAX2Y"]
[Thu Sep 17 15:14:29.957956 2026] [autoindex:error] [pid 971102:tid 971359] [client 85.204.70.116:45598] AH01276: Cannot serve directory /home1/zainridg/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:29.959137 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.116:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.zainridgecondo.org"] [uri "/wp-content/upgrade/"] [unique_id "aqxYNecL08BTTQixEnpR6AAAAH0"]
[Thu Sep 17 15:14:29.986420 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "aqxYNecL08BTTQixEnpR7QAAUl4"]
[Thu Sep 17 15:14:30.002219 2026] [security2:error] [pid 971102:tid 971298] [client 115.244.164.14:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNucL08BTTQixEnpR7gAAAEA"]
[Thu Sep 17 15:14:30.002315 2026] [security2:error] [pid 971102:tid 971298] [client 115.244.164.14:61983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYNucL08BTTQixEnpR7gAAAEA"]
[Thu Sep 17 15:14:30.045337 2026] [security2:error] [pid 971102:tid 971190] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "aqxYNucL08BTTQixEnpR9QAAEVU"]
[Thu Sep 17 15:14:30.090725 2026] [security2:error] [pid 971102:tid 971107] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "aqxYNucL08BTTQixEnpR-wAALQM"]
[Thu Sep 17 15:14:30.233509 2026] [security2:error] [pid 971102:tid 971123] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "aqxYNucL08BTTQixEnpR_QAAChM"]
[Thu Sep 17 15:14:30.233543 2026] [security2:error] [pid 971102:tid 971209] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/server/.env"] [unique_id "aqxYNucL08BTTQixEnpR_gAACmg"]
[Thu Sep 17 15:14:30.288419 2026] [security2:error] [pid 971102:tid 971292] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRmwAAADo"]
[Thu Sep 17 15:14:30.360197 2026] [security2:error] [pid 971102:tid 971273] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRoAAAACc"]
[Thu Sep 17 15:14:30.361978 2026] [security2:error] [pid 971102:tid 971339] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRnwAAAGk"]
[Thu Sep 17 15:14:30.372807 2026] [security2:error] [pid 971102:tid 971332] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRngAAAGI"]
[Thu Sep 17 15:14:30.382676 2026] [security2:error] [pid 971102:tid 971325] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRogAAAFs"]
[Thu Sep 17 15:14:30.384895 2026] [security2:error] [pid 971102:tid 971344] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRoQAAAG4"]
[Thu Sep 17 15:14:30.385991 2026] [security2:error] [pid 971102:tid 971168] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/src/.env"] [unique_id "aqxYNucL08BTTQixEnpSBgAABkA"]
[Thu Sep 17 15:14:30.392807 2026] [security2:error] [pid 971102:tid 971268] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRzQAAACI"]
[Thu Sep 17 15:14:30.396524 2026] [security2:error] [pid 971102:tid 971276] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRzAAAACo"]
[Thu Sep 17 15:14:30.397406 2026] [security2:error] [pid 971102:tid 971353] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRpQAAAHc"]
[Thu Sep 17 15:14:30.397975 2026] [security2:error] [pid 971102:tid 971330] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpR3QAAAGA"]
[Thu Sep 17 15:14:30.401300 2026] [security2:error] [pid 971102:tid 971289] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRzwAAADc"]
[Thu Sep 17 15:14:30.401895 2026] [security2:error] [pid 971102:tid 971253] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRyAAAABM"]
[Thu Sep 17 15:14:30.408804 2026] [security2:error] [pid 971102:tid 971256] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRygAAABY"]
[Thu Sep 17 15:14:30.410909 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRyQAAABQ"]
[Thu Sep 17 15:14:30.416848 2026] [security2:error] [pid 971102:tid 971318] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpR1wAAAFQ"]
[Thu Sep 17 15:14:30.428969 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/web/.env"] [unique_id "aqxYNucL08BTTQixEnpSDgAARAU"]
[Thu Sep 17 15:14:30.429077 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/client/.env"] [unique_id "aqxYNucL08BTTQixEnpSDwAARFw"]
[Thu Sep 17 15:14:30.446192 2026] [security2:error] [pid 971102:tid 971284] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpR8gAAADI"]
[Thu Sep 17 15:14:30.446449 2026] [security2:error] [pid 971102:tid 971133] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config.php"] [unique_id "aqxYNucL08BTTQixEnpSEgAADR0"]
[Thu Sep 17 15:14:30.485144 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/frontend/.env"] [unique_id "aqxYNucL08BTTQixEnpSFQAAHiQ"]
[Thu Sep 17 15:14:30.512172 2026] [security2:error] [pid 971102:tid 971162] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSHAAAXDo"]
[Thu Sep 17 15:14:30.528155 2026] [security2:error] [pid 971102:tid 971208] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/info.php"] [unique_id "aqxYNucL08BTTQixEnpSHwAAXGc"]
[Thu Sep 17 15:14:30.533031 2026] [security2:error] [pid 971102:tid 971151] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/infos.php"] [unique_id "aqxYNucL08BTTQixEnpSIAAAXC8"]
[Thu Sep 17 15:14:30.535988 2026] [security2:error] [pid 971102:tid 971116] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/php.php"] [unique_id "aqxYNucL08BTTQixEnpSIgAAXAw"]
[Thu Sep 17 15:14:30.535996 2026] [security2:error] [pid 971102:tid 971119] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/php_info.php"] [unique_id "aqxYNucL08BTTQixEnpSIwAAXA8"]
[Thu Sep 17 15:14:30.537648 2026] [security2:error] [pid 971102:tid 971128] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/infophp.php"] [unique_id "aqxYNucL08BTTQixEnpSJgAAXBg"]
[Thu Sep 17 15:14:30.537706 2026] [security2:error] [pid 971102:tid 971156] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/php-info.php"] [unique_id "aqxYNucL08BTTQixEnpSJQAAXDQ"]
[Thu Sep 17 15:14:30.545648 2026] [security2:error] [pid 971102:tid 971115] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSKgAAXAs"]
[Thu Sep 17 15:14:30.548914 2026] [security2:error] [pid 971102:tid 971114] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSLQAAXAo"]
[Thu Sep 17 15:14:30.562129 2026] [security2:error] [pid 971102:tid 971174] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSLgAAXEY"]
[Thu Sep 17 15:14:30.571942 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/public/.env"] [unique_id "aqxYNucL08BTTQixEnpSMQAAQlM"]
[Thu Sep 17 15:14:30.578550 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSEwAAADg"]
[Thu Sep 17 15:14:30.635006 2026] [security2:error] [pid 971102:tid 971167] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSOgAAXD8"]
[Thu Sep 17 15:14:30.646366 2026] [security2:error] [pid 971102:tid 971104] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYNucL08BTTQixEnpSOwAAXAA"]
[Thu Sep 17 15:14:30.650715 2026] [security2:error] [pid 971102:tid 971357] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSKQAAAHs"]
[Thu Sep 17 15:14:30.688560 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/.env"] [unique_id "aqxYNucL08BTTQixEnpSTwAALlE"]
[Thu Sep 17 15:14:30.697124 2026] [security2:error] [pid 971102:tid 971177] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/database.sql"] [unique_id "aqxYNucL08BTTQixEnpSUAAAXEk"]
[Thu Sep 17 15:14:30.725730 2026] [security2:error] [pid 971102:tid 971211] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/aws.php"] [unique_id "aqxYNucL08BTTQixEnpSUwAAG2o"]
[Thu Sep 17 15:14:30.732341 2026] [security2:error] [pid 971102:tid 971122] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/var/www/html/.env"] [unique_id "aqxYNucL08BTTQixEnpSVwAAKRI"]
[Thu Sep 17 15:14:30.774184 2026] [security2:error] [pid 971102:tid 971160] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/laravel/.env"] [unique_id "aqxYNucL08BTTQixEnpSXwAAZTg"]
[Thu Sep 17 15:14:30.774418 2026] [security2:error] [pid 971102:tid 971149] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/application/.env"] [unique_id "aqxYNucL08BTTQixEnpSYAAAZS0"]
[Thu Sep 17 15:14:30.793915 2026] [security2:error] [pid 971102:tid 971135] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/stripe.php"] [unique_id "aqxYNucL08BTTQixEnpSZwAAJB8"]
[Thu Sep 17 15:14:30.794404 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/mail.php"] [unique_id "aqxYNucL08BTTQixEnpSaQAAJBU"]
[Thu Sep 17 15:14:30.820298 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/config.inc.php"] [unique_id "aqxYNucL08BTTQixEnpSbQAAThs"]
[Thu Sep 17 15:14:30.837441 2026] [security2:error] [pid 971102:tid 971201] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/apps/.env"] [unique_id "aqxYNucL08BTTQixEnpSdAAAWWA"]
[Thu Sep 17 15:14:30.840252 2026] [security2:error] [pid 971102:tid 971182] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config/nexmo.php"] [unique_id "aqxYNucL08BTTQixEnpSdQAAGU4"]
[Thu Sep 17 15:14:30.933890 2026] [security2:error] [pid 971102:tid 971258] [client 189.203.228.241:21134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYNucL08BTTQixEnpSbgAAGBk"]
[Thu Sep 17 15:14:30.935885 2026] [security2:error] [pid 971102:tid 971210] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYNucL08BTTQixEnpSewAABmk"]
[Thu Sep 17 15:14:30.936266 2026] [security2:error] [pid 971102:tid 971222] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php"] [unique_id "aqxYNucL08BTTQixEnpSegAABnU"]
[Thu Sep 17 15:14:30.941116 2026] [security2:error] [pid 971102:tid 971193] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php.old"] [unique_id "aqxYNucL08BTTQixEnpSfAAAa1g"]
[Thu Sep 17 15:14:31.038512 2026] [security2:error] [pid 971102:tid 971192] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.apkpaw.com"] [uri "/wp-config.php.new"] [unique_id "aqxYN-cL08BTTQixEnpSgAAAU1c"]
[Thu Sep 17 15:14:31.038881 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYN-cL08BTTQixEnpSggAAUzs"]
[Thu Sep 17 15:14:31.045442 2026] [security2:error] [pid 971102:tid 971120] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/back/.env"] [unique_id "aqxYN-cL08BTTQixEnpSgwAAbxA"]
[Thu Sep 17 15:14:31.045462 2026] [security2:error] [pid 971102:tid 971196] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/backup/.env"] [unique_id "aqxYN-cL08BTTQixEnpShAAAb1s"]
[Thu Sep 17 15:14:31.069347 2026] [security2:error] [pid 971102:tid 971191] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/cms/.env"] [unique_id "aqxYN-cL08BTTQixEnpShwAAbVY"]
[Thu Sep 17 15:14:31.081899 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "aqxYN-cL08BTTQixEnpSigAAL14"]
[Thu Sep 17 15:14:31.187383 2026] [security2:error] [pid 971102:tid 971126] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/dev/.env"] [unique_id "aqxYN-cL08BTTQixEnpSkQAAZBY"]
[Thu Sep 17 15:14:31.187431 2026] [security2:error] [pid 971102:tid 971220] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/prod/.env"] [unique_id "aqxYN-cL08BTTQixEnpSkgAAZHM"]
[Thu Sep 17 15:14:31.227822 2026] [security2:error] [pid 971102:tid 971110] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "aqxYN-cL08BTTQixEnpSkwAAIQY"]
[Thu Sep 17 15:14:31.298931 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSOQAAADg"]
[Thu Sep 17 15:14:31.299029 2026] [security2:error] [pid 971102:tid 971288] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSOAAAADY"]
[Thu Sep 17 15:14:31.300862 2026] [security2:error] [pid 971102:tid 971307] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSNwAAAEk"]
[Thu Sep 17 15:14:31.339774 2026] [security2:error] [pid 971102:tid 971232] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/staging/.env"] [unique_id "aqxYN-cL08BTTQixEnpSmQAAWH8"]
[Thu Sep 17 15:14:31.340877 2026] [security2:error] [pid 971102:tid 971209] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/production/.env"] [unique_id "aqxYN-cL08BTTQixEnpSmgAAWGg"]
[Thu Sep 17 15:14:31.397798 2026] [security2:error] [pid 971102:tid 971244] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSXAAAAAo"]
[Thu Sep 17 15:14:31.399520 2026] [security2:error] [pid 971102:tid 971251] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSUgAAABE"]
[Thu Sep 17 15:14:31.401899 2026] [security2:error] [pid 971102:tid 971234] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSWgAAAAA"]
[Thu Sep 17 15:14:31.402784 2026] [security2:error] [pid 971102:tid 971339] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSawAAAGk"]
[Thu Sep 17 15:14:31.405947 2026] [security2:error] [pid 971102:tid 971347] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSVgAAAHE"]
[Thu Sep 17 15:14:31.407093 2026] [security2:error] [pid 971102:tid 971295] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSWwAAAD0"]
[Thu Sep 17 15:14:31.417353 2026] [security2:error] [pid 971102:tid 971351] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSUQAAAHU"]
[Thu Sep 17 15:14:31.420495 2026] [security2:error] [pid 971102:tid 971279] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSWQAAAC0"]
[Thu Sep 17 15:14:31.421014 2026] [security2:error] [pid 971102:tid 971273] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSagAAACc"]
[Thu Sep 17 15:14:31.425906 2026] [security2:error] [pid 971102:tid 971325] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSeAAAAFs"]
[Thu Sep 17 15:14:31.430085 2026] [security2:error] [pid 971102:tid 971331] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSbAAAAGE"]
[Thu Sep 17 15:14:31.433324 2026] [security2:error] [pid 971102:tid 971350] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSeQAAAHQ"]
[Thu Sep 17 15:14:31.549361 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/test/.env"] [unique_id "aqxYN-cL08BTTQixEnpSpwAAcDk"]
[Thu Sep 17 15:14:31.549423 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/old/.env"] [unique_id "aqxYN-cL08BTTQixEnpSqAAAcEM"]
[Thu Sep 17 15:14:31.586108 2026] [security2:error] [pid 971102:tid 971109] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.240.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivorygarlock.com"] [uri "/admin_dev.php"] [unique_id "aqxYN-cL08BTTQixEnpStwAAXAU"]
[Thu Sep 17 15:14:31.589545 2026] [security2:error] [pid 971102:tid 971212] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.sh_history"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/.sh_history"] [unique_id "aqxYN-cL08BTTQixEnpSvwAAXGs"]
[Thu Sep 17 15:14:31.591315 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/new/.env"] [unique_id "aqxYN-cL08BTTQixEnpSwAAAWlQ"]
[Thu Sep 17 15:14:31.591576 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/node-api/.env"] [unique_id "aqxYN-cL08BTTQixEnpSwQAAWgg"]
[Thu Sep 17 15:14:31.631348 2026] [security2:error] [pid 971102:tid 971336] [client 185.55.149.49:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYN-cL08BTTQixEnpS0AAAAGY"]
[Thu Sep 17 15:14:31.631476 2026] [security2:error] [pid 971102:tid 971336] [client 185.55.149.49:60635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYN-cL08BTTQixEnpS0AAAAGY"]
[Thu Sep 17 15:14:31.724515 2026] [security2:error] [pid 971102:tid 971115] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/opt/.env"] [unique_id "aqxYN-cL08BTTQixEnpS3gAAXAs"]
[Thu Sep 17 15:14:31.729025 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/api-backend/.env"] [unique_id "aqxYN-cL08BTTQixEnpS5gAAalM"]
[Thu Sep 17 15:14:31.729060 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/admin-app/.env"] [unique_id "aqxYN-cL08BTTQixEnpS5wAAajE"]
[Thu Sep 17 15:14:31.735435 2026] [security2:error] [pid 971102:tid 971294] [client 160.177.85.210:38056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxYNecL08BTTQixEnpRowAAPD4"], referer: https://www.enolastable.com/2021/07/16/what-inspired-the-table/
[Thu Sep 17 15:14:31.853789 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/aws/.env"] [unique_id "aqxYN-cL08BTTQixEnpS9gAACkk"]
[Thu Sep 17 15:14:31.853792 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/server/backend/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_wAACkQ"]
[Thu Sep 17 15:14:31.853864 2026] [security2:error] [pid 971102:tid 971104] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/public_html/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-AAACgA"]
[Thu Sep 17 15:14:31.853867 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/current/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-QAACiw"]
[Thu Sep 17 15:14:31.853867 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.aws/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-gAACgQ"]
[Thu Sep 17 15:14:31.853915 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/stripe/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_AAACk8"]
[Thu Sep 17 15:14:31.853954 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.docker/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_QAAClE"]
[Thu Sep 17 15:14:31.853993 2026] [security2:error] [pid 971102:tid 971215] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/server/api/.env"] [unique_id "aqxYN-cL08BTTQixEnpS9wAACm4"]
[Thu Sep 17 15:14:31.854003 2026] [security2:error] [pid 971102:tid 971213] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/administrator/.env"] [unique_id "aqxYN-cL08BTTQixEnpS_gAACmw"]
[Thu Sep 17 15:14:31.854034 2026] [security2:error] [pid 971102:tid 971130] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.docker/laravel/app/.env"] [unique_id "aqxYN-cL08BTTQixEnpS-wAACho"]
[Thu Sep 17 15:14:31.901960 2026] [security2:error] [pid 971102:tid 971261] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS1AAAG2E"], referer: http://www.talent-in-borders.com/wp/
[Thu Sep 17 15:14:31.951525 2026] [security2:error] [pid 971102:tid 971217] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/v1/.env"] [unique_id "aqxYN-cL08BTTQixEnpTCwAALXA"]
[Thu Sep 17 15:14:31.998103 2026] [security2:error] [pid 971102:tid 971201] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/v2/.env"] [unique_id "aqxYN-cL08BTTQixEnpTDQAAEGA"]
[Thu Sep 17 15:14:31.998130 2026] [security2:error] [pid 971102:tid 971182] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/v3/.env"] [unique_id "aqxYN-cL08BTTQixEnpTDgAAEE4"]
[Thu Sep 17 15:14:31.999225 2026] [security2:error] [pid 971102:tid 971173] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/media/.env"] [unique_id "aqxYN-cL08BTTQixEnpTDwAAEEU"]
[Thu Sep 17 15:14:32.042703 2026] [security2:error] [pid 971102:tid 971305] [client 65.21.44.205:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.edmagik.com"] [uri "/index.php"] [unique_id "aqxYNucL08BTTQixEnpSVQAAAEc"]
[Thu Sep 17 15:14:32.072456 2026] [security2:error] [pid 971102:tid 971266] [client 65.21.44.205:59488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.edmagik.com"] [uri "/robots.txt"] [unique_id "aqxYNucL08BTTQixEnpSIQAAACA"]
[Thu Sep 17 15:14:32.141547 2026] [security2:error] [pid 971102:tid 971219] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.git/config.bak"] [unique_id "aqxYOOcL08BTTQixEnpTKgAAEHI"]
[Thu Sep 17 15:14:32.205992 2026] [security2:error] [pid 971102:tid 971247] [client 5.189.145.112:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxYOOcL08BTTQixEnpTLgAAAA0"], referer: binance.com
[Thu Sep 17 15:14:32.313096 2026] [security2:error] [pid 971102:tid 971345] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzAAAAG8"]
[Thu Sep 17 15:14:32.313784 2026] [security2:error] [pid 971102:tid 971293] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSygAAADs"]
[Thu Sep 17 15:14:32.315365 2026] [security2:error] [pid 971102:tid 971258] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSxQAAABg"]
[Thu Sep 17 15:14:32.325174 2026] [security2:error] [pid 971102:tid 971353] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSywAAAHc"]
[Thu Sep 17 15:14:32.329199 2026] [security2:error] [pid 971102:tid 971253] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzgAAABM"]
[Thu Sep 17 15:14:32.336167 2026] [security2:error] [pid 971102:tid 971309] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzQAAAEs"]
[Thu Sep 17 15:14:32.354995 2026] [security2:error] [pid 971102:tid 971343] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpSzwAAAG0"]
[Thu Sep 17 15:14:32.400154 2026] [security2:error] [pid 971102:tid 971245] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS7QAAAAs"]
[Thu Sep 17 15:14:32.400408 2026] [security2:error] [pid 971102:tid 971248] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS9AAAAA4"]
[Thu Sep 17 15:14:32.407332 2026] [security2:error] [pid 971102:tid 971307] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS7gAAAEk"]
[Thu Sep 17 15:14:32.411026 2026] [security2:error] [pid 971102:tid 971290] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS7AAAADg"]
[Thu Sep 17 15:14:32.411429 2026] [security2:error] [pid 971102:tid 971326] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpTAwAAXHo"]
[Thu Sep 17 15:14:32.416099 2026] [security2:error] [pid 971102:tid 971319] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS6wAAAFU"]
[Thu Sep 17 15:14:32.417722 2026] [security2:error] [pid 971102:tid 971254] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS8gAAABQ"]
[Thu Sep 17 15:14:32.421833 2026] [security2:error] [pid 971102:tid 971326] [client 35.240.58.49:52314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpTDAAAXBs"]
[Thu Sep 17 15:14:32.434998 2026] [security2:error] [pid 971102:tid 971349] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYN-cL08BTTQixEnpS8wAAAHM"]
[Thu Sep 17 15:14:32.452710 2026] [security2:error] [pid 971102:tid 971139] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/db_backup.sql"] [unique_id "aqxYOOcL08BTTQixEnpTQAAAXCM"]
[Thu Sep 17 15:14:32.475178 2026] [security2:error] [pid 971102:tid 971150] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.aws/credentials.bak"] [unique_id "aqxYOOcL08BTTQixEnpTSgAAbi4"]
[Thu Sep 17 15:14:32.475189 2026] [security2:error] [pid 971102:tid 971195] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/.ssh/id_rsa"] [unique_id "aqxYOOcL08BTTQixEnpTRgAAblo"]
[Thu Sep 17 15:14:32.475238 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/id_rsa"] [unique_id "aqxYOOcL08BTTQixEnpTRQAAbng"]
[Thu Sep 17 15:14:32.478194 2026] [security2:error] [pid 971102:tid 971169] [remote 35.240.58.49:52314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivorygarlock.com"] [uri "/local/.env"] [unique_id "aqxYOOcL08BTTQixEnpTTQAAXEE"]
[Thu Sep 17 15:14:32.619450 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpTYQAAZVw"]
[Thu Sep 17 15:14:32.628574 2026] [security2:error] [pid 971102:tid 971261] [client 65.21.44.205:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.edmagik.com"] [uri "/wp"] [unique_id "aqxYOOcL08BTTQixEnpTYgAAABs"]
[Thu Sep 17 15:14:32.635307 2026] [security2:error] [pid 971102:tid 971240] [client 65.21.44.205:59502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.edmagik.com"] [uri "/wp"] [unique_id "aqxYOOcL08BTTQixEnpTWQAAAAY"]
[Thu Sep 17 15:14:32.640069 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/info.php"] [unique_id "aqxYOOcL08BTTQixEnpTZQAAZVQ"]
[Thu Sep 17 15:14:32.684818 2026] [security2:error] [pid 971102:tid 971287] [client 167.172.76.13:56456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTTgAANXw"], referer: https://www.talent-in-borders.com/wp/
[Thu Sep 17 15:14:32.721646 2026] [security2:error] [pid 971102:tid 971322] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTVwAAAFg"]
[Thu Sep 17 15:14:32.721989 2026] [security2:error] [pid 971102:tid 971251] [client 35.240.58.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTVgAAABE"]
[Thu Sep 17 15:14:32.787427 2026] [security2:error] [pid 971102:tid 971347] [client 171.96.135.239:61435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTYwAAcRc"]
[Thu Sep 17 15:14:32.923098 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/infos.php"] [unique_id "aqxYOOcL08BTTQixEnpTeAAAB1M"]
[Thu Sep 17 15:14:32.928311 2026] [security2:error] [pid 971102:tid 971166] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/php_info.php"] [unique_id "aqxYOOcL08BTTQixEnpTewAAWT4"]
[Thu Sep 17 15:14:32.928329 2026] [security2:error] [pid 971102:tid 971164] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/php.php"] [unique_id "aqxYOOcL08BTTQixEnpTfAAAWTw"]
[Thu Sep 17 15:14:32.928357 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/php-info.php"] [unique_id "aqxYOOcL08BTTQixEnpTfQAAWTI"]
[Thu Sep 17 15:14:32.928383 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/infophp.php"] [unique_id "aqxYOOcL08BTTQixEnpTfgAAWQc"]
[Thu Sep 17 15:14:32.951287 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpTggAAf1E"]
[Thu Sep 17 15:14:32.951305 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpTgQAAf08"]
[Thu Sep 17 15:14:32.951339 2026] [security2:error] [pid 971102:tid 971215] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpThAAAf24"]
[Thu Sep 17 15:14:32.951364 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpThQAAfyw"]
[Thu Sep 17 15:14:32.951410 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYOOcL08BTTQixEnpThgAAfwQ"]
[Thu Sep 17 15:14:33.095788 2026] [security2:error] [pid 971102:tid 971181] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/database.sql"] [unique_id "aqxYOecL08BTTQixEnpTmQAATE0"]
[Thu Sep 17 15:14:33.111940 2026] [security2:error] [pid 971102:tid 971143] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config.php"] [unique_id "aqxYOecL08BTTQixEnpTnAAAOic"]
[Thu Sep 17 15:14:33.243354 2026] [security2:error] [pid 971102:tid 971309] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOecL08BTTQixEnpTlQAAS2A"], referer: http://www.talent-in-borders.com/new/
[Thu Sep 17 15:14:33.307364 2026] [security2:error] [pid 971102:tid 971358] [client 65.21.44.205:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.edmagik.com"] [uri "/wp/index.php"] [unique_id "aqxYOOcL08BTTQixEnpTdAAAAHw"]
[Thu Sep 17 15:14:33.309381 2026] [security2:error] [pid 971102:tid 971284] [client 65.21.44.205:59502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.edmagik.com"] [uri "/wp/"] [unique_id "aqxYOOcL08BTTQixEnpTagAAADI"]
[Thu Sep 17 15:14:33.347627 2026] [security2:error] [pid 971102:tid 971327] [client 104.28.198.244:22961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYOecL08BTTQixEnpTsQAAAF0"]
[Thu Sep 17 15:14:33.347736 2026] [security2:error] [pid 971102:tid 971327] [client 104.28.198.244:22961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYOecL08BTTQixEnpTsQAAAF0"]
[Thu Sep 17 15:14:33.463291 2026] [security2:error] [pid 971102:tid 971216] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.bak"] [unique_id "aqxYOecL08BTTQixEnpTvgAAQ28"]
[Thu Sep 17 15:14:33.463301 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.backup"] [unique_id "aqxYOecL08BTTQixEnpTugAAQxE"]
[Thu Sep 17 15:14:33.464583 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.old"] [unique_id "aqxYOecL08BTTQixEnpTwQAAQxE"]
[Thu Sep 17 15:14:33.465559 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env"] [unique_id "aqxYOecL08BTTQixEnpTyAAAQxE"]
[Thu Sep 17 15:14:33.497110 2026] [security2:error] [pid 971102:tid 971128] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/.env.production.php"] [unique_id "aqxYOecL08BTTQixEnpTzQAAXxg"]
[Thu Sep 17 15:14:33.518785 2026] [security2:error] [pid 971102:tid 971114] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.git/config.bak"] [unique_id "aqxYOecL08BTTQixEnpT0QAAYgo"]
[Thu Sep 17 15:14:33.535918 2026] [security2:error] [pid 971102:tid 971145] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/aws.php"] [unique_id "aqxYOecL08BTTQixEnpT0gAABSk"]
[Thu Sep 17 15:14:33.585198 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "aqxYOecL08BTTQixEnpT2AAADng"]
[Thu Sep 17 15:14:33.598801 2026] [security2:error] [pid 971102:tid 971169] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/test.config.php"] [unique_id "aqxYOecL08BTTQixEnpT2QAADkE"]
[Thu Sep 17 15:14:33.653635 2026] [security2:error] [pid 971102:tid 971136] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.php"] [unique_id "aqxYOecL08BTTQixEnpT3gAAQyA"]
[Thu Sep 17 15:14:33.654223 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env~"] [unique_id "aqxYOecL08BTTQixEnpT3wAAQyI"]
[Thu Sep 17 15:14:33.664865 2026] [security2:error] [pid 971102:tid 971226] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.swp"] [unique_id "aqxYOecL08BTTQixEnpT4gAAQ3k"]
[Thu Sep 17 15:14:33.680485 2026] [security2:error] [pid 971102:tid 971144] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/stripe.php"] [unique_id "aqxYOecL08BTTQixEnpT5AAAKSg"]
[Thu Sep 17 15:14:33.680506 2026] [security2:error] [pid 971102:tid 971168] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/mail.php"] [unique_id "aqxYOecL08BTTQixEnpT5QAAKUA"]
[Thu Sep 17 15:14:33.680550 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/nexmo.php"] [unique_id "aqxYOecL08BTTQixEnpT5gAAKTk"]
[Thu Sep 17 15:14:33.680557 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config/config.inc.php"] [unique_id "aqxYOecL08BTTQixEnpT6wAAKVQ"]
[Thu Sep 17 15:14:33.703420 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/config.json.php"] [unique_id "aqxYOecL08BTTQixEnpT7AAAeiQ"]
[Thu Sep 17 15:14:33.797861 2026] [security2:error] [pid 971102:tid 971280] [client 47.79.201.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOecL08BTTQixEnpTtgAAAC4"], referer: https://www.google.com/
[Thu Sep 17 15:14:33.798973 2026] [security2:error] [pid 971102:tid 971223] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/aws_settings.php"] [unique_id "aqxYOecL08BTTQixEnpT8wAAcnY"]
[Thu Sep 17 15:14:33.799704 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.apkpaw.com"] [uri "/___proxy_subdomain_cpcontacts/react-app/.env"] [unique_id "aqxYOecL08BTTQixEnpT9gAAcms"]
[Thu Sep 17 15:14:33.838891 2026] [security2:error] [pid 971102:tid 971132] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php"] [unique_id "aqxYOecL08BTTQixEnpT-AAARRw"]
[Thu Sep 17 15:14:33.870392 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYOecL08BTTQixEnpT-gAAVQU"]
[Thu Sep 17 15:14:33.902907 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php.old"] [unique_id "aqxYOecL08BTTQixEnpUAgAARFM"]
[Thu Sep 17 15:14:33.905275 2026] [security2:error] [pid 971102:tid 971166] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.aws/credentials.bak"] [unique_id "aqxYOecL08BTTQixEnpUAwAANz4"]
[Thu Sep 17 15:14:34.005670 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.apkpaw.com"] [uri "/wp-config.php.new"] [unique_id "aqxYOucL08BTTQixEnpUDgAAZEQ"]
[Thu Sep 17 15:14:34.007414 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apkpaw.com"] [uri "/api/info.php"] [unique_id "aqxYOucL08BTTQixEnpUDwAAZ0k"]
[Thu Sep 17 15:14:34.079089 2026] [security2:error] [pid 971102:tid 971122] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYOucL08BTTQixEnpUFwAABBI"]
[Thu Sep 17 15:14:34.083445 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/id_rsa"] [unique_id "aqxYOucL08BTTQixEnpUGQAANhU"]
[Thu Sep 17 15:14:34.083504 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_rsa"] [unique_id "aqxYOucL08BTTQixEnpUGAAANmE"]
[Thu Sep 17 15:14:34.112347 2026] [security2:error] [pid 971102:tid 971349] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOecL08BTTQixEnpUCQAAc08"], referer: http://www.talent-in-borders.com/wordpress/
[Thu Sep 17 15:14:34.147935 2026] [security2:error] [pid 971102:tid 971135] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/api/.env"] [unique_id "aqxYOucL08BTTQixEnpUIgAAQx8"]
[Thu Sep 17 15:14:34.343120 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/wp-content/mysql.sql"] [unique_id "aqxYOucL08BTTQixEnpUKgAADW0"]
[Thu Sep 17 15:14:34.449168 2026] [security2:error] [pid 971102:tid 971314] [client 167.172.76.13:56456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYOucL08BTTQixEnpUKQAAUEU"], referer: https://www.talent-in-borders.com/wordpress/
[Thu Sep 17 15:14:34.604683 2026] [security2:error] [pid 971102:tid 971228] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/app/.env"] [unique_id "aqxYOucL08BTTQixEnpUSgAAQ3s"]
[Thu Sep 17 15:14:34.655827 2026] [security2:error] [pid 971102:tid 971206] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/terraform.tfstate.backup"] [unique_id "aqxYOucL08BTTQixEnpUTwAAMmU"]
[Thu Sep 17 15:14:34.753256 2026] [security2:error] [pid 971102:tid 971121] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/backend/.env"] [unique_id "aqxYOucL08BTTQixEnpUWgAAQxE"]
[Thu Sep 17 15:14:34.758110 2026] [security2:error] [pid 971102:tid 971351] [client 37.139.53.80:55535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxYOucL08BTTQixEnpUVwAAAHU"], referer: https://www.norifon.com/index.php
[Thu Sep 17 15:14:34.903943 2026] [security2:error] [pid 971102:tid 971114] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/.env"] [unique_id "aqxYOucL08BTTQixEnpUYgAAYgo"]
[Thu Sep 17 15:14:34.904000 2026] [security2:error] [pid 971102:tid 971145] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/src/.env"] [unique_id "aqxYOucL08BTTQixEnpUZgAAYik"]
[Thu Sep 17 15:14:34.904006 2026] [security2:error] [pid 971102:tid 971209] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/web/.env"] [unique_id "aqxYOucL08BTTQixEnpUZQAAYmg"]
[Thu Sep 17 15:14:34.904045 2026] [security2:error] [pid 971102:tid 971221] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/client/.env"] [unique_id "aqxYOucL08BTTQixEnpUZwAAYnQ"]
[Thu Sep 17 15:14:34.904061 2026] [security2:error] [pid 971102:tid 971151] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/config/.env"] [unique_id "aqxYOucL08BTTQixEnpUYwAAYi8"]
[Thu Sep 17 15:14:34.904063 2026] [security2:error] [pid 971102:tid 971225] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/frontend/.env"] [unique_id "aqxYOucL08BTTQixEnpUaAAAYng"]
[Thu Sep 17 15:14:34.904115 2026] [security2:error] [pid 971102:tid 971195] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/public/.env"] [unique_id "aqxYOucL08BTTQixEnpUZAAAYlo"]
[Thu Sep 17 15:14:34.904115 2026] [security2:error] [pid 971102:tid 971169] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/var/www/.env"] [unique_id "aqxYOucL08BTTQixEnpUaQAAYkE"]
[Thu Sep 17 15:14:34.996259 2026] [security2:error] [pid 971102:tid 971144] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/var/www/html/.env"] [unique_id "aqxYOucL08BTTQixEnpUdQAAMSg"]
[Thu Sep 17 15:14:35.018522 2026] [security2:error] [pid 971102:tid 971134] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/laravel/.env"] [unique_id "aqxYO-cL08BTTQixEnpUdwAACx4"]
[Thu Sep 17 15:14:35.027870 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/application/.env"] [unique_id "aqxYO-cL08BTTQixEnpUfAAAIyQ"]
[Thu Sep 17 15:14:35.028579 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/apps/.env"] [unique_id "aqxYO-cL08BTTQixEnpUfQAAI1w"]
[Thu Sep 17 15:14:35.048731 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config.php"] [unique_id "aqxYO-cL08BTTQixEnpUfwAAUQ0"]
[Thu Sep 17 15:14:35.056808 2026] [security2:error] [pid 971102:tid 971157] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/back/.env"] [unique_id "aqxYO-cL08BTTQixEnpUgQAAKTU"]
[Thu Sep 17 15:14:35.066744 2026] [security2:error] [pid 971102:tid 971166] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/test/.env"] [unique_id "aqxYO-cL08BTTQixEnpUjgAACD4"]
[Thu Sep 17 15:14:35.066792 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/staging/.env"] [unique_id "aqxYO-cL08BTTQixEnpUigAACFM"]
[Thu Sep 17 15:14:35.066853 2026] [security2:error] [pid 971102:tid 971203] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/production/.env"] [unique_id "aqxYO-cL08BTTQixEnpUjAAACGI"]
[Thu Sep 17 15:14:35.066869 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/prod/.env"] [unique_id "aqxYO-cL08BTTQixEnpUiwAACAU"]
[Thu Sep 17 15:14:35.066869 2026] [security2:error] [pid 971102:tid 971155] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/dev/.env"] [unique_id "aqxYO-cL08BTTQixEnpUiAAACDM"]
[Thu Sep 17 15:14:35.066911 2026] [security2:error] [pid 971102:tid 971218] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/old/.env"] [unique_id "aqxYO-cL08BTTQixEnpUjQAACHE"]
[Thu Sep 17 15:14:35.066936 2026] [security2:error] [pid 971102:tid 971132] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/backup/.env"] [unique_id "aqxYO-cL08BTTQixEnpUiQAACBw"]
[Thu Sep 17 15:14:35.067138 2026] [security2:error] [pid 971102:tid 971127] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/cms/.env"] [unique_id "aqxYO-cL08BTTQixEnpUhwAACBc"]
[Thu Sep 17 15:14:35.289464 2026] [security2:error] [pid 971102:tid 971313] [client 114.198.138.124:63756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpUnAAAAE8"]
[Thu Sep 17 15:14:35.289630 2026] [security2:error] [pid 971102:tid 971313] [client 114.198.138.124:63756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpUnAAAAE8"]
[Thu Sep 17 15:14:35.305482 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/api-backend/.env"] [unique_id "aqxYO-cL08BTTQixEnpUnwAAFDE"]
[Thu Sep 17 15:14:35.305531 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/new/.env"] [unique_id "aqxYO-cL08BTTQixEnpUnQAAFEk"]
[Thu Sep 17 15:14:35.305585 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/admin-app/.env"] [unique_id "aqxYO-cL08BTTQixEnpUoAAAFCw"]
[Thu Sep 17 15:14:35.305589 2026] [security2:error] [pid 971102:tid 971215] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/node-api/.env"] [unique_id "aqxYO-cL08BTTQixEnpUngAAFG4"]
[Thu Sep 17 15:14:35.305925 2026] [security2:error] [pid 971102:tid 971108] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/administrator/.env"] [unique_id "aqxYO-cL08BTTQixEnpUoQAAFAQ"]
[Thu Sep 17 15:14:35.464727 2026] [security2:error] [pid 971102:tid 971211] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.docker/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpAAAN2o"]
[Thu Sep 17 15:14:35.464735 2026] [security2:error] [pid 971102:tid 971181] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/stripe/.env"] [unique_id "aqxYO-cL08BTTQixEnpUqAAAN00"]
[Thu Sep 17 15:14:35.464842 2026] [security2:error] [pid 971102:tid 971104] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpgAANwA"]
[Thu Sep 17 15:14:35.464851 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.aws/.env"] [unique_id "aqxYO-cL08BTTQixEnpUqQAAN08"]
[Thu Sep 17 15:14:35.464871 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/api/.env"] [unique_id "aqxYO-cL08BTTQixEnpUqgAANxU"]
[Thu Sep 17 15:14:35.464880 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/backend/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpwAAN2E"]
[Thu Sep 17 15:14:35.464982 2026] [security2:error] [pid 971102:tid 971130] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/aws/.env"] [unique_id "aqxYO-cL08BTTQixEnpUogAANxo"]
[Thu Sep 17 15:14:35.464983 2026] [security2:error] [pid 971102:tid 971122] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/public_html/.env"] [unique_id "aqxYO-cL08BTTQixEnpUowAANxI"]
[Thu Sep 17 15:14:35.464999 2026] [security2:error] [pid 971102:tid 971213] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/current/.env"] [unique_id "aqxYO-cL08BTTQixEnpUpQAAN2w"]
[Thu Sep 17 15:14:35.514990 2026] [security2:error] [pid 971102:tid 971198] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/mail.php"] [unique_id "aqxYO-cL08BTTQixEnpUugAAZ10"]
[Thu Sep 17 15:14:35.515002 2026] [security2:error] [pid 971102:tid 971220] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/nexmo.php"] [unique_id "aqxYO-cL08BTTQixEnpUvwAAZ3M"]
[Thu Sep 17 15:14:35.515022 2026] [security2:error] [pid 971102:tid 971204] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/stripe.php"] [unique_id "aqxYO-cL08BTTQixEnpUuwAAZ2M"]
[Thu Sep 17 15:14:35.515046 2026] [security2:error] [pid 971102:tid 971186] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/config.inc.php"] [unique_id "aqxYO-cL08BTTQixEnpUwgAAZ1I"]
[Thu Sep 17 15:14:35.515090 2026] [security2:error] [pid 971102:tid 971123] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config/aws.php"] [unique_id "aqxYO-cL08BTTQixEnpUwAAAZxM"]
[Thu Sep 17 15:14:35.600123 2026] [security2:error] [pid 971102:tid 971228] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v2/.env"] [unique_id "aqxYO-cL08BTTQixEnpUygAAJns"]
[Thu Sep 17 15:14:35.600294 2026] [security2:error] [pid 971102:tid 971165] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/media/.env"] [unique_id "aqxYO-cL08BTTQixEnpUzQAAJj0"]
[Thu Sep 17 15:14:35.600298 2026] [security2:error] [pid 971102:tid 971199] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v3/.env"] [unique_id "aqxYO-cL08BTTQixEnpUyAAAJl4"]
[Thu Sep 17 15:14:35.600321 2026] [security2:error] [pid 971102:tid 971196] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v1/.env"] [unique_id "aqxYO-cL08BTTQixEnpUyQAAJls"]
[Thu Sep 17 15:14:35.630200 2026] [security2:error] [pid 971102:tid 971190] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php"] [unique_id "aqxYO-cL08BTTQixEnpU1QAALFU"]
[Thu Sep 17 15:14:35.655863 2026] [security2:error] [pid 971102:tid 971110] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYO-cL08BTTQixEnpU1wAAPQY"]
[Thu Sep 17 15:14:35.660619 2026] [security2:error] [pid 971102:tid 971227] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php.old"] [unique_id "aqxYO-cL08BTTQixEnpU2AAAAXo"]
[Thu Sep 17 15:14:35.674770 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.apkpaw.com"] [uri "/wp-config.php.new"] [unique_id "aqxYO-cL08BTTQixEnpU3wAALRs"]
[Thu Sep 17 15:14:35.675036 2026] [security2:error] [pid 971102:tid 971232] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYO-cL08BTTQixEnpU3gAALX8"]
[Thu Sep 17 15:14:35.675830 2026] [security2:error] [pid 971102:tid 971106] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/wp-content/mysql.sql"] [unique_id "aqxYO-cL08BTTQixEnpU3QAALQI"]
[Thu Sep 17 15:14:35.738904 2026] [security2:error] [pid 971102:tid 971150] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.git/config.bak"] [unique_id "aqxYO-cL08BTTQixEnpU8wAAWC4"]
[Thu Sep 17 15:14:35.768809 2026] [security2:error] [pid 971102:tid 971152] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/terraform.tfstate.backup"] [unique_id "aqxYO-cL08BTTQixEnpU-AAALTA"]
[Thu Sep 17 15:14:35.891011 2026] [security2:error] [pid 971102:tid 971299] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYO-cL08BTTQixEnpU6wAAQWg"], referer: http://www.talent-in-borders.com/blog/
[Thu Sep 17 15:14:35.907035 2026] [security2:error] [pid 971102:tid 971251] [client 45.169.98.18:50131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpVAQAAABE"]
[Thu Sep 17 15:14:35.907128 2026] [security2:error] [pid 971102:tid 971251] [client 45.169.98.18:50131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYO-cL08BTTQixEnpVAQAAABE"]
[Thu Sep 17 15:14:36.145517 2026] [security2:error] [pid 971102:tid 971273] [client 154.190.208.131:41331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYPOcL08BTTQixEnpVCAAAACc"]
[Thu Sep 17 15:14:36.145685 2026] [security2:error] [pid 971102:tid 971273] [client 154.190.208.131:41331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYPOcL08BTTQixEnpVCAAAACc"]
[Thu Sep 17 15:14:36.250856 2026] [security2:error] [pid 971102:tid 971161] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/php.php"] [unique_id "aqxYPOcL08BTTQixEnpVFgAAfzk"]
[Thu Sep 17 15:14:36.250871 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/infos.php"] [unique_id "aqxYPOcL08BTTQixEnpVFwAAf1Q"]
[Thu Sep 17 15:14:36.250902 2026] [security2:error] [pid 971102:tid 971127] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVFQAAfxc"]
[Thu Sep 17 15:14:36.250924 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/info.php"] [unique_id "aqxYPOcL08BTTQixEnpVEwAAf0M"]
[Thu Sep 17 15:14:36.250951 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/php_info.php"] [unique_id "aqxYPOcL08BTTQixEnpVGAAAf2s"]
[Thu Sep 17 15:14:36.397418 2026] [security2:error] [pid 971102:tid 971164] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVIwAAajw"]
[Thu Sep 17 15:14:36.397428 2026] [security2:error] [pid 971102:tid 971223] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/infophp.php"] [unique_id "aqxYPOcL08BTTQixEnpVIgAAanY"]
[Thu Sep 17 15:14:36.397455 2026] [security2:error] [pid 971102:tid 971162] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVJQAAajo"]
[Thu Sep 17 15:14:36.397480 2026] [security2:error] [pid 971102:tid 971229] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/php-info.php"] [unique_id "aqxYPOcL08BTTQixEnpVIQAAanw"]
[Thu Sep 17 15:14:36.397508 2026] [security2:error] [pid 971102:tid 971156] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVHwAAajQ"]
[Thu Sep 17 15:14:36.397518 2026] [security2:error] [pid 971102:tid 971154] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVJAAAajI"]
[Thu Sep 17 15:14:36.451059 2026] [security2:error] [pid 971102:tid 971142] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYPOcL08BTTQixEnpVKwAAKyY"]
[Thu Sep 17 15:14:36.540837 2026] [security2:error] [pid 971102:tid 971116] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/database.sql"] [unique_id "aqxYPOcL08BTTQixEnpVNAAARgw"]
[Thu Sep 17 15:14:36.739652 2026] [security2:error] [pid 971102:tid 971359] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYPOcL08BTTQixEnpVSwAAfS0"], referer: http://www.talent-in-borders.com/old/
[Thu Sep 17 15:14:37.065579 2026] [security2:error] [pid 971102:tid 971131] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxYPecL08BTTQixEnpVcQAABBs"]
[Thu Sep 17 15:14:37.065636 2026] [security2:error] [pid 971102:tid 971180] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxYPecL08BTTQixEnpVcwAABEw"]
[Thu Sep 17 15:14:37.070727 2026] [security2:error] [pid 971102:tid 971106] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/.env.production.php"] [unique_id "aqxYPecL08BTTQixEnpVdwAANgI"]
[Thu Sep 17 15:14:37.070818 2026] [security2:error] [pid 971102:tid 971119] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/config.json.php"] [unique_id "aqxYPecL08BTTQixEnpVfwAANg8"]
[Thu Sep 17 15:14:37.071031 2026] [security2:error] [pid 971102:tid 971133] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/aws_settings.php"] [unique_id "aqxYPecL08BTTQixEnpVggAANh0"]
[Thu Sep 17 15:14:37.071595 2026] [security2:error] [pid 971102:tid 971207] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/test.config.php"] [unique_id "aqxYPecL08BTTQixEnpVeQAANmY"]
[Thu Sep 17 15:14:37.071605 2026] [security2:error] [pid 971102:tid 971107] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/fe/.env"] [unique_id "aqxYPecL08BTTQixEnpVfgAANgM"]
[Thu Sep 17 15:14:37.072061 2026] [security2:error] [pid 971102:tid 971178] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.apkpaw.com"] [uri "/___proxy_subdomain_cpcalendars/react-app/.env"] [unique_id "aqxYPecL08BTTQixEnpVgwAANko"]
[Thu Sep 17 15:14:37.221804 2026] [security2:error] [pid 971102:tid 971145] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/id_rsa"] [unique_id "aqxYPecL08BTTQixEnpVigAAKCk"]
[Thu Sep 17 15:14:37.268502 2026] [security2:error] [pid 971102:tid 971140] [remote 34.140.132.132:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.apkpaw.com"] [uri "/api/info.php"] [unique_id "aqxYPecL08BTTQixEnpVnwAAASQ"]
[Thu Sep 17 15:14:37.448245 2026] [security2:error] [pid 971102:tid 971223] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpVuQAADXY"]
[Thu Sep 17 15:14:37.539775 2026] [security2:error] [pid 971102:tid 971112] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/info.php"] [unique_id "aqxYPecL08BTTQixEnpVwAAAZQg"]
[Thu Sep 17 15:14:37.563687 2026] [security2:error] [pid 971102:tid 971142] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/infos.php"] [unique_id "aqxYPecL08BTTQixEnpVxAAAYyY"]
[Thu Sep 17 15:14:37.588580 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/php_info.php"] [unique_id "aqxYPecL08BTTQixEnpVxQAAbFE"]
[Thu Sep 17 15:14:37.596051 2026] [security2:error] [pid 971102:tid 971111] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/php.php"] [unique_id "aqxYPecL08BTTQixEnpVxgAAOwc"]
[Thu Sep 17 15:14:37.612200 2026] [security2:error] [pid 971102:tid 971294] [client 167.172.76.13:45216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYPecL08BTTQixEnpVvAAAPHw"], referer: http://www.talent-in-borders.com/backup/
[Thu Sep 17 15:14:37.638966 2026] [security2:error] [pid 971102:tid 971148] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/infophp.php"] [unique_id "aqxYPecL08BTTQixEnpVyQAASCw"]
[Thu Sep 17 15:14:37.639032 2026] [security2:error] [pid 971102:tid 971177] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/php-info.php"] [unique_id "aqxYPecL08BTTQixEnpVygAASEk"]
[Thu Sep 17 15:14:37.705607 2026] [security2:error] [pid 971102:tid 971153] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpVzAAAezE"]
[Thu Sep 17 15:14:37.761880 2026] [security2:error] [pid 971102:tid 971125] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV1wAADxU"]
[Thu Sep 17 15:14:37.761904 2026] [security2:error] [pid 971102:tid 971172] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV2AAAD0Q"]
[Thu Sep 17 15:14:37.761953 2026] [security2:error] [pid 971102:tid 971208] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV1QAAD2c"]
[Thu Sep 17 15:14:37.761990 2026] [security2:error] [pid 971102:tid 971183] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYPecL08BTTQixEnpV2QAAD08"]
[Thu Sep 17 15:14:37.945298 2026] [security2:error] [pid 971102:tid 971205] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/database.sql"] [unique_id "aqxYPecL08BTTQixEnpV5wAAPmQ"]
[Thu Sep 17 15:14:37.966732 2026] [security2:error] [pid 971102:tid 971355] [client 167.172.76.13:56456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYPecL08BTTQixEnpV3gAAeRM"], referer: https://www.talent-in-borders.com/backup/
[Thu Sep 17 15:14:38.109615 2026] [security2:error] [pid 971102:tid 971350] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYPecL08BTTQixEnpV3wAAAHQ"]
[Thu Sep 17 15:14:38.186277 2026] [security2:error] [pid 971102:tid 971308] [client 192.178.6.3:52003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYPucL08BTTQixEnpWAAAAAEo"]
[Thu Sep 17 15:14:38.207764 2026] [security2:error] [pid 971102:tid 971165] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config.php"] [unique_id "aqxYPucL08BTTQixEnpWBAAAOD0"]
[Thu Sep 17 15:14:38.233922 2026] [security2:error] [pid 971102:tid 971216] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/.env.production.php"] [unique_id "aqxYPucL08BTTQixEnpWDgAAFG8"]
[Thu Sep 17 15:14:38.265647 2026] [security2:error] [pid 971102:tid 971194] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/fe/.env"] [unique_id "aqxYPucL08BTTQixEnpWEgAALlk"]
[Thu Sep 17 15:14:38.277233 2026] [security2:error] [pid 971102:tid 971167] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/test.config.php"] [unique_id "aqxYPucL08BTTQixEnpWEwAALj8"]
[Thu Sep 17 15:14:38.305077 2026] [security2:error] [pid 971102:tid 971302] [client 34.55.12.4:62988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cjs.gdz.mybluehost.me"] [uri "/.env"] [unique_id "aqxYPucL08BTTQixEnpWFQAAAEQ"]
[Thu Sep 17 15:14:38.328911 2026] [security2:error] [pid 971102:tid 971196] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/config.json.php"] [unique_id "aqxYPucL08BTTQixEnpWFgAAcls"]
[Thu Sep 17 15:14:38.367395 2026] [security2:error] [pid 971102:tid 971169] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/aws.php"] [unique_id "aqxYPucL08BTTQixEnpWGQAAZ0E"]
[Thu Sep 17 15:14:38.368497 2026] [security2:error] [pid 971102:tid 971128] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/stripe.php"] [unique_id "aqxYPucL08BTTQixEnpWHwAAZxg"]
[Thu Sep 17 15:14:38.373779 2026] [security2:error] [pid 971102:tid 971136] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.apkpaw.com"] [uri "/___proxy_subdomain_webdisk/react-app/.env"] [unique_id "aqxYPucL08BTTQixEnpWIQAABCA"]
[Thu Sep 17 15:14:38.386467 2026] [security2:error] [pid 971102:tid 971230] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/aws_settings.php"] [unique_id "aqxYPucL08BTTQixEnpWIgAAW30"]
[Thu Sep 17 15:14:38.494156 2026] [security2:error] [pid 971102:tid 971163] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/mail.php"] [unique_id "aqxYPucL08BTTQixEnpWKAAACTs"]
[Thu Sep 17 15:14:38.680959 2026] [security2:error] [pid 971102:tid 971157] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/config.inc.php"] [unique_id "aqxYPucL08BTTQixEnpWPgAAaTU"]
[Thu Sep 17 15:14:38.680990 2026] [security2:error] [pid 971102:tid 971150] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/nexmo.php"] [unique_id "aqxYPucL08BTTQixEnpWOgAAaS4"]
[Thu Sep 17 15:14:38.681020 2026] [security2:error] [pid 971102:tid 971188] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php"] [unique_id "aqxYPucL08BTTQixEnpWPQAAaVM"]
[Thu Sep 17 15:14:38.737997 2026] [security2:error] [pid 971102:tid 971171] [remote 34.140.132.132:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.apkpaw.com"] [uri "/api/info.php"] [unique_id "aqxYPucL08BTTQixEnpWQQAAVEM"]
[Thu Sep 17 15:14:38.766513 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYPucL08BTTQixEnpWRwAAbyI"]
[Thu Sep 17 15:14:38.766513 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.old"] [unique_id "aqxYPucL08BTTQixEnpWSAAAbwU"]
[Thu Sep 17 15:14:38.767501 2026] [security2:error] [pid 971102:tid 971279] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYPucL08BTTQixEnpWLAAAAC0"]
[Thu Sep 17 15:14:38.767970 2026] [security2:error] [pid 971102:tid 971218] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.new"] [unique_id "aqxYPucL08BTTQixEnpWSgAAEXE"]
[Thu Sep 17 15:14:38.768232 2026] [security2:error] [pid 971102:tid 971203] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYPucL08BTTQixEnpWSQAAEWI"]
[Thu Sep 17 15:14:38.769106 2026] [security2:error] [pid 971102:tid 971170] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxYPucL08BTTQixEnpWTgAAEUI"]
[Thu Sep 17 15:14:38.819957 2026] [security2:error] [pid 971102:tid 971185] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxYPucL08BTTQixEnpWVAAAZVE"]
[Thu Sep 17 15:14:39.117928 2026] [security2:error] [pid 971102:tid 971330] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYPucL08BTTQixEnpWWgAAAGA"]
[Thu Sep 17 15:14:39.679337 2026] [security2:error] [pid 971102:tid 971351] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYP-cL08BTTQixEnpWdAAAAHU"]
[Thu Sep 17 15:14:39.845879 2026] [security2:error] [pid 971102:tid 971242] [client 5.189.145.112:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxYP-cL08BTTQixEnpWfAAAAAg"], referer: binance.com
[Thu Sep 17 15:14:40.195512 2026] [security2:error] [pid 971102:tid 971307] [client 156.192.234.52:57555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWiwAAAEk"]
[Thu Sep 17 15:14:40.195602 2026] [security2:error] [pid 971102:tid 971307] [client 156.192.234.52:57555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWiwAAAEk"]
[Thu Sep 17 15:14:40.238666 2026] [security2:error] [pid 971102:tid 971356] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYQOcL08BTTQixEnpWiQAAAHo"]
[Thu Sep 17 15:14:40.431170 2026] [security2:error] [pid 971102:tid 971165] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWnQAAaD0"]
[Thu Sep 17 15:14:40.471866 2026] [security2:error] [pid 971102:tid 971118] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php_info.php"] [unique_id "aqxYQOcL08BTTQixEnpWpQAAFA4"]
[Thu Sep 17 15:14:40.471888 2026] [security2:error] [pid 971102:tid 971214] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/info.php"] [unique_id "aqxYQOcL08BTTQixEnpWqQAAFG0"]
[Thu Sep 17 15:14:40.471924 2026] [security2:error] [pid 971102:tid 971191] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php-info.php"] [unique_id "aqxYQOcL08BTTQixEnpWpwAAFFY"]
[Thu Sep 17 15:14:40.471943 2026] [security2:error] [pid 971102:tid 971146] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWqwAAFCo"]
[Thu Sep 17 15:14:40.471974 2026] [security2:error] [pid 971102:tid 971224] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/infos.php"] [unique_id "aqxYQOcL08BTTQixEnpWqAAAFHc"]
[Thu Sep 17 15:14:40.471987 2026] [security2:error] [pid 971102:tid 971137] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/infophp.php"] [unique_id "aqxYQOcL08BTTQixEnpWqgAAFCE"]
[Thu Sep 17 15:14:40.472009 2026] [security2:error] [pid 971102:tid 971174] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php.php"] [unique_id "aqxYQOcL08BTTQixEnpWpAAAFEY"]
[Thu Sep 17 15:14:40.488453 2026] [security2:error] [pid 971102:tid 971259] [client 115.244.164.14:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWrQAAABk"]
[Thu Sep 17 15:14:40.488511 2026] [security2:error] [pid 971102:tid 971259] [client 115.244.164.14:62634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWrQAAABk"]
[Thu Sep 17 15:14:40.517896 2026] [security2:error] [pid 971102:tid 971298] [client 104.234.53.18:54053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxYQOcL08BTTQixEnpWrAAAAEA"]
[Thu Sep 17 15:14:40.570597 2026] [security2:error] [pid 971102:tid 971106] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWsgAAQwI"]
[Thu Sep 17 15:14:40.570620 2026] [security2:error] [pid 971102:tid 971190] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWswAAQ1U"]
[Thu Sep 17 15:14:40.570669 2026] [security2:error] [pid 971102:tid 971216] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWrwAAQ28"]
[Thu Sep 17 15:14:40.570687 2026] [security2:error] [pid 971102:tid 971232] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYQOcL08BTTQixEnpWrgAAQ38"]
[Thu Sep 17 15:14:40.608160 2026] [security2:error] [pid 971102:tid 971173] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/database.sql"] [unique_id "aqxYQOcL08BTTQixEnpWvAAANEU"]
[Thu Sep 17 15:14:40.790369 2026] [security2:error] [pid 971102:tid 971324] [client 186.105.232.15:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWyQAAAFo"]
[Thu Sep 17 15:14:40.790468 2026] [security2:error] [pid 971102:tid 971324] [client 186.105.232.15:61991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQOcL08BTTQixEnpWyQAAAFo"]
[Thu Sep 17 15:14:40.941462 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tidynapa.com.nickdunne.com"] [uri "/index.php"] [unique_id "aqxYQOcL08BTTQixEnpWywAAAAk"]
[Thu Sep 17 15:14:41.159109 2026] [security2:error] [pid 971102:tid 971212] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/test.config.php"] [unique_id "aqxYQecL08BTTQixEnpW3AAAAGs"]
[Thu Sep 17 15:14:41.159133 2026] [security2:error] [pid 971102:tid 971117] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.production.php"] [unique_id "aqxYQecL08BTTQixEnpW4AAAAA0"]
[Thu Sep 17 15:14:41.159973 2026] [security2:error] [pid 971102:tid 971189] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/fe/.env"] [unique_id "aqxYQecL08BTTQixEnpW3gAAAFQ"]
[Thu Sep 17 15:14:41.357412 2026] [security2:error] [pid 971102:tid 971109] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/aws_settings.php"] [unique_id "aqxYQecL08BTTQixEnpW5AAAZQU"]
[Thu Sep 17 15:14:41.357439 2026] [security2:error] [pid 971102:tid 971197] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config.json.php"] [unique_id "aqxYQecL08BTTQixEnpW6AAAZVw"]
[Thu Sep 17 15:14:41.358476 2026] [security2:error] [pid 971102:tid 971138] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/react-app/.env"] [unique_id "aqxYQecL08BTTQixEnpW5wAAZSI"]
[Thu Sep 17 15:14:42.492483 2026] [security2:error] [pid 971102:tid 971310] [client 185.55.149.49:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYQucL08BTTQixEnpXEQAAAEw"]
[Thu Sep 17 15:14:42.494521 2026] [security2:error] [pid 971102:tid 971310] [client 185.55.149.49:61285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYQucL08BTTQixEnpXEQAAAEw"]
[Thu Sep 17 15:14:42.525649 2026] [security2:error] [pid 971102:tid 971303] [client 127.0.0.1:55912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxYQucL08BTTQixEnpXEAAAAEU"]
[Thu Sep 17 15:14:42.525783 2026] [security2:error] [pid 971102:tid 971329] [client 74.7.244.39:43476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.oem.izd.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYQucL08BTTQixEnpXDwAAXzI"]
[Thu Sep 17 15:14:42.770768 2026] [security2:error] [pid 971102:tid 971202] [remote 34.140.132.132:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/api/info.php"] [unique_id "aqxYQucL08BTTQixEnpXJAAAMmE"]
[Thu Sep 17 15:14:43.827769 2026] [security2:error] [pid 971102:tid 971274] [client 212.63.124.56:22283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxYQ-cL08BTTQixEnpXTgAAKE8"], referer: https://www.enolastable.com/2021/07/16/what-inspired-the-table/
[Thu Sep 17 15:14:43.945481 2026] [security2:error] [pid 971102:tid 971283] [client 104.28.198.244:22992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQ-cL08BTTQixEnpXUAAAADE"]
[Thu Sep 17 15:14:43.945626 2026] [security2:error] [pid 971102:tid 971283] [client 104.28.198.244:22992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYQ-cL08BTTQixEnpXUAAAADE"]
[Thu Sep 17 15:14:44.934456 2026] [security2:error] [pid 971102:tid 971286] [client 84.54.44.204:51542] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "84.54.44.204" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "daprayer.com"] [uri "/wp-comments-post.php"] [unique_id "aqxYROcL08BTTQixEnpXWwAAADQ"], referer: https://daprayer.com/baby-e-the-birth-story/
[Thu Sep 17 15:14:44.934547 2026] [security2:error] [pid 971102:tid 971286] [client 84.54.44.204:51542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "daprayer.com"] [uri "/wp-comments-post.php"] [unique_id "aqxYROcL08BTTQixEnpXWwAAADQ"], referer: https://daprayer.com/baby-e-the-birth-story/
[Thu Sep 17 15:14:45.803440 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRecL08BTTQixEnpXcAAAAF0"]
[Thu Sep 17 15:14:45.803552 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:60669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRecL08BTTQixEnpXcAAAAF0"]
[Thu Sep 17 15:14:46.408585 2026] [security2:error] [pid 971102:tid 971340] [client 45.169.98.18:50690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXfAAAAGo"]
[Thu Sep 17 15:14:46.408691 2026] [security2:error] [pid 971102:tid 971340] [client 45.169.98.18:50690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXfAAAAGo"]
[Thu Sep 17 15:14:46.573371 2026] [security2:error] [pid 971102:tid 971206] [remote 111.225.149.178:60450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joeledmundanderson.com"] [uri "/"] [unique_id "aqxYRucL08BTTQixEnpXfgAAIGU"]
[Thu Sep 17 15:14:46.603433 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXgQAAACo"]
[Thu Sep 17 15:14:46.603527 2026] [security2:error] [pid 971102:tid 971276] [client 154.190.208.131:41931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYRucL08BTTQixEnpXgQAAACo"]
[Thu Sep 17 15:14:47.998527 2026] [security2:error] [pid 971102:tid 971316] [client 5.189.145.112:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxYR-cL08BTTQixEnpXlwAAAFI"], referer: binance.com
[Thu Sep 17 15:14:48.218189 2026] [security2:error] [pid 971102:tid 971264] [client 216.73.216.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxYSOcL08BTTQixEnpXngAAAB4"]
[Thu Sep 17 15:14:48.779998 2026] [security2:error] [pid 971102:tid 971283] [client 32.223.98.46:54863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYSOcL08BTTQixEnpXrgAAMQM"]
[Thu Sep 17 15:14:50.180350 2026] [core:error] [pid 971102:tid 971254] [client 138.246.253.24:57814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:50.180370 2026] [core:error] [pid 971102:tid 971254] [client 138.246.253.24:57814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:14:50.716222 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:58163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYSucL08BTTQixEnpXwgAAAEw"]
[Thu Sep 17 15:14:50.716796 2026] [security2:error] [pid 971102:tid 971310] [client 156.192.234.52:58163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYSucL08BTTQixEnpXwgAAAEw"]
[Thu Sep 17 15:14:50.819131 2026] [security2:error] [pid 971102:tid 971320] [client 32.223.98.46:54905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYSucL08BTTQixEnpXwwAAVio"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260522203933&hideliu=1&hidemyself=1&limit=250&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:14:51.120602 2026] [security2:error] [pid 971102:tid 971243] [client 115.244.164.14:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.164.244.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpXzQAAAAk"]
[Thu Sep 17 15:14:51.120745 2026] [security2:error] [pid 971102:tid 971243] [client 115.244.164.14:63045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "energynowspa.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpXzQAAAAk"]
[Thu Sep 17 15:14:51.638999 2026] [security2:error] [pid 971102:tid 971327] [client 186.105.232.15:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpX1QAAAF0"]
[Thu Sep 17 15:14:51.639115 2026] [security2:error] [pid 971102:tid 971327] [client 186.105.232.15:62592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYS-cL08BTTQixEnpX1QAAAF0"]
[Thu Sep 17 15:14:51.999418 2026] [security2:error] [pid 971102:tid 971255] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/uploads/"] [unique_id "aqxYS-cL08BTTQixEnpX2wAAABU"]
[Thu Sep 17 15:14:52.075423 2026] [security2:error] [pid 971102:tid 971321] [client 20.244.34.24:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxYTOcL08BTTQixEnpX3gAAAFc"], referer: binance.com
[Thu Sep 17 15:14:52.208169 2026] [security2:error] [pid 971102:tid 971248] [client 143.244.57.121:39470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTOcL08BTTQixEnpX4AAAAA4"]
[Thu Sep 17 15:14:52.536389 2026] [security2:error] [pid 971102:tid 971351] [client 143.244.57.121:39482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.idautovic.com"] [uri "/xmlrpc.php"] [unique_id "aqxYTOcL08BTTQixEnpX4wAAAHU"]
[Thu Sep 17 15:14:52.607621 2026] [autoindex:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:52.608352 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-sys/403.html"] [unique_id "aqxYTOcL08BTTQixEnpX5wAAAHQ"]
[Thu Sep 17 15:14:52.720282 2026] [security2:error] [pid 971102:tid 971329] [client 45.179.29.134:17092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYTOcL08BTTQixEnpX6AAAXxA"]
[Thu Sep 17 15:14:52.758127 2026] [security2:error] [pid 971102:tid 971285] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/"] [unique_id "aqxYTOcL08BTTQixEnpX6wAAADM"]
[Thu Sep 17 15:14:52.825602 2026] [cgid:error] [pid 971102:tid 971340] [client 66.249.93.225:47853] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:14:52.920245 2026] [autoindex:error] [pid 971102:tid 971298] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:52.920898 2026] [security2:error] [pid 971102:tid 971298] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/"] [unique_id "aqxYTOcL08BTTQixEnpX7gAAAEA"]
[Thu Sep 17 15:14:53.071325 2026] [security2:error] [pid 971102:tid 971344] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/css/"] [unique_id "aqxYTecL08BTTQixEnpX8AAAAG4"]
[Thu Sep 17 15:14:53.226179 2026] [autoindex:error] [pid 971102:tid 971310] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:53.226677 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/css/"] [unique_id "aqxYTecL08BTTQixEnpX-QAAAEw"]
[Thu Sep 17 15:14:53.250435 2026] [security2:error] [pid 971102:tid 971286] [client 143.244.57.121:39496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTecL08BTTQixEnpX-wAAADQ"]
[Thu Sep 17 15:14:53.264041 2026] [security2:error] [pid 971102:tid 971345] [client 185.55.149.49:64611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYTecL08BTTQixEnpX_AAAAG8"]
[Thu Sep 17 15:14:53.264131 2026] [security2:error] [pid 971102:tid 971345] [client 185.55.149.49:64611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYTecL08BTTQixEnpX_AAAAG8"]
[Thu Sep 17 15:14:53.528869 2026] [security2:error] [pid 971102:tid 971355] [client 143.244.57.121:39504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTecL08BTTQixEnpYBAAAAHk"]
[Thu Sep 17 15:14:53.599562 2026] [security2:error] [pid 971102:tid 971318] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxYTecL08BTTQixEnpYCQAAAFQ"]
[Thu Sep 17 15:14:53.647967 2026] [security2:error] [pid 971102:tid 971341] [client 47.79.200.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYTecL08BTTQixEnpX_wAAAGs"], referer: https://www.google.com/
[Thu Sep 17 15:14:53.757154 2026] [autoindex:error] [pid 971102:tid 971360] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:53.757653 2026] [security2:error] [pid 971102:tid 971360] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/ID3/"] [unique_id "aqxYTecL08BTTQixEnpYCwAAAH4"]
[Thu Sep 17 15:14:53.822873 2026] [security2:error] [pid 971102:tid 971237] [client 143.244.57.121:39508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTecL08BTTQixEnpYDAAAAAM"]
[Thu Sep 17 15:14:53.905859 2026] [security2:error] [pid 971102:tid 971289] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxYTecL08BTTQixEnpYDgAAADc"]
[Thu Sep 17 15:14:54.070082 2026] [autoindex:error] [pid 971102:tid 971302] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:54.070576 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/IXR/"] [unique_id "aqxYTucL08BTTQixEnpYDwAAAEQ"]
[Thu Sep 17 15:14:54.107914 2026] [security2:error] [pid 971102:tid 971241] [client 143.244.57.121:39516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTucL08BTTQixEnpYEgAAAAc"]
[Thu Sep 17 15:14:54.224370 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxYTucL08BTTQixEnpYFAAAAEo"]
[Thu Sep 17 15:14:54.410862 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.121:39526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTucL08BTTQixEnpYFgAAACg"]
[Thu Sep 17 15:14:54.414651 2026] [autoindex:error] [pid 971102:tid 971311] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:54.415132 2026] [security2:error] [pid 971102:tid 971311] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Requests/"] [unique_id "aqxYTucL08BTTQixEnpYFQAAAE0"]
[Thu Sep 17 15:14:54.534859 2026] [security2:error] [pid 971102:tid 971296] [client 104.28.198.244:22780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYTucL08BTTQixEnpYGQAAAD4"]
[Thu Sep 17 15:14:54.534971 2026] [security2:error] [pid 971102:tid 971296] [client 104.28.198.244:22780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYTucL08BTTQixEnpYGQAAAD4"]
[Thu Sep 17 15:14:54.596948 2026] [security2:error] [pid 971102:tid 971343] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxYTucL08BTTQixEnpYHQAAAG0"]
[Thu Sep 17 15:14:54.702000 2026] [security2:error] [pid 971102:tid 971280] [client 143.244.57.121:39528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxYTucL08BTTQixEnpYIAAAAC4"]
[Thu Sep 17 15:14:54.755764 2026] [autoindex:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:54.756289 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/SimplePie/"] [unique_id "aqxYTucL08BTTQixEnpYIQAAADg"]
[Thu Sep 17 15:14:54.910802 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/"] [unique_id "aqxYTucL08BTTQixEnpYIwAAACs"]
[Thu Sep 17 15:14:55.007947 2026] [security2:error] [pid 971102:tid 971323] [client 143.244.57.121:39542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYJQAAAFk"]
[Thu Sep 17 15:14:55.075166 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:55.075820 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/"] [unique_id "aqxYT-cL08BTTQixEnpYKAAAACA"]
[Thu Sep 17 15:14:55.222975 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "aqxYT-cL08BTTQixEnpYKgAAAFs"]
[Thu Sep 17 15:14:55.307391 2026] [security2:error] [pid 971102:tid 971356] [client 143.244.57.121:39544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYKwAAAHo"]
[Thu Sep 17 15:14:55.511436 2026] [security2:error] [pid 971102:tid 971275] [client 200.42.105.146:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYT-cL08BTTQixEnpYLwAAKTs"]
[Thu Sep 17 15:14:55.628213 2026] [security2:error] [pid 971102:tid 971240] [client 143.244.57.121:39554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYOAAAAAY"]
[Thu Sep 17 15:14:55.917073 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.121:39564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxYT-cL08BTTQixEnpYOwAAAAQ"]
[Thu Sep 17 15:14:56.132926 2026] [security2:error] [pid 971102:tid 971316] [client 5.189.145.112:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/config.php"] [unique_id "aqxYUOcL08BTTQixEnpYQgAAAFI"], referer: binance.com
[Thu Sep 17 15:14:56.223677 2026] [security2:error] [pid 971102:tid 971342] [client 143.244.57.121:39566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUOcL08BTTQixEnpYRAAAAGw"]
[Thu Sep 17 15:14:56.248602 2026] [security2:error] [pid 971102:tid 971168] [remote 157.55.39.8:17891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtbclubdecampo.com"] [uri "/navas.php"] [unique_id "aqxYUOcL08BTTQixEnpYRQAAf0A"]
[Thu Sep 17 15:14:56.482706 2026] [security2:error] [pid 971102:tid 971293] [client 114.198.138.124:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYRwAAADs"]
[Thu Sep 17 15:14:56.482811 2026] [security2:error] [pid 971102:tid 971293] [client 114.198.138.124:61388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYRwAAADs"]
[Thu Sep 17 15:14:56.528709 2026] [security2:error] [pid 971102:tid 971332] [client 143.244.57.121:39580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUOcL08BTTQixEnpYSAAAAGI"]
[Thu Sep 17 15:14:56.822504 2026] [security2:error] [pid 971102:tid 971241] [client 134.185.85.61:51219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "rickanddonnaproctor.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYUOcL08BTTQixEnpYTwAAAAc"]
[Thu Sep 17 15:14:56.822565 2026] [security2:error] [pid 971102:tid 971308] [client 143.244.57.121:39582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUOcL08BTTQixEnpYTgAAAEo"]
[Thu Sep 17 15:14:56.879898 2026] [security2:error] [pid 971102:tid 971289] [client 45.169.98.18:51255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYUAAAADc"]
[Thu Sep 17 15:14:56.880911 2026] [security2:error] [pid 971102:tid 971289] [client 45.169.98.18:51255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUOcL08BTTQixEnpYUAAAADc"]
[Thu Sep 17 15:14:57.041588 2026] [autoindex:error] [pid 971102:tid 971136] [remote 93.152.209.11:21850] AH01276: Cannot serve directory /home1/yrtoccmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:57.112911 2026] [security2:error] [pid 971102:tid 971274] [client 143.244.57.121:39584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.idautovic.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxYUecL08BTTQixEnpYVgAAACg"]
[Thu Sep 17 15:14:57.143354 2026] [security2:error] [pid 971102:tid 971333] [client 44.239.144.77:60669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxYUecL08BTTQixEnpYUQAAAGM"], referer: http://worthtranslations.com/oldsite
[Thu Sep 17 15:14:57.192646 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUecL08BTTQixEnpYWAAAABc"]
[Thu Sep 17 15:14:57.200321 2026] [security2:error] [pid 971102:tid 971321] [client 134.185.85.61:57299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "rickanddonnaproctor.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYUecL08BTTQixEnpYWQAAAFc"]
[Thu Sep 17 15:14:57.200351 2026] [security2:error] [pid 971102:tid 971257] [client 154.190.208.131:42543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYUecL08BTTQixEnpYWAAAABc"]
[Thu Sep 17 15:14:57.658748 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYT-cL08BTTQixEnpYLgAAAFE"]
[Thu Sep 17 15:14:57.658779 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYT-cL08BTTQixEnpYLgAAAFE"]
[Thu Sep 17 15:14:57.943053 2026] [security2:error] [pid 971102:tid 971298] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "aqxYUecL08BTTQixEnpYZAAAAEA"]
[Thu Sep 17 15:14:58.387290 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYUucL08BTTQixEnpYaAAAAHM"]
[Thu Sep 17 15:14:58.387312 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYUucL08BTTQixEnpYaAAAAHM"]
[Thu Sep 17 15:14:58.542204 2026] [security2:error] [pid 971102:tid 971322] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "aqxYUucL08BTTQixEnpYbgAAAFg"]
[Thu Sep 17 15:14:58.711499 2026] [security2:error] [pid 971102:tid 971265] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/ninja-forms/index.php"] [unique_id "aqxYUucL08BTTQixEnpYcwAAAB8"]
[Thu Sep 17 15:14:58.856526 2026] [security2:error] [pid 971102:tid 971334] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxYUucL08BTTQixEnpYdAAAAGQ"]
[Thu Sep 17 15:14:59.012620 2026] [autoindex:error] [pid 971102:tid 971253] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:59.013211 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/mu-plugins/"] [unique_id "aqxYUucL08BTTQixEnpYdQAAABM"]
[Thu Sep 17 15:14:59.094978 2026] [security2:error] [pid 971102:tid 971316] [client 20.244.34.24:49582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxYU-cL08BTTQixEnpYdgAAAFI"], referer: binance.com
[Thu Sep 17 15:14:59.191642 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxYU-cL08BTTQixEnpYegAAABo"]
[Thu Sep 17 15:14:59.351169 2026] [autoindex:error] [pid 971102:tid 971332] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:59.351689 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "aqxYU-cL08BTTQixEnpYggAAAGI"]
[Thu Sep 17 15:14:59.498140 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/blocks/"] [unique_id "aqxYU-cL08BTTQixEnpYhAAAAAM"]
[Thu Sep 17 15:14:59.655819 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "aqxYU-cL08BTTQixEnpYigAAAGs"]
[Thu Sep 17 15:14:59.805180 2026] [security2:error] [pid 971102:tid 971333] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxYU-cL08BTTQixEnpYjwAAAGM"]
[Thu Sep 17 15:14:59.960175 2026] [autoindex:error] [pid 971102:tid 971248] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:14:59.960650 2026] [security2:error] [pid 971102:tid 971248] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/certificates/"] [unique_id "aqxYU-cL08BTTQixEnpYlAAAAA4"]
[Thu Sep 17 15:15:00.108090 2026] [security2:error] [pid 971102:tid 971328] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/customize/"] [unique_id "aqxYVOcL08BTTQixEnpYmAAAAF4"]
[Thu Sep 17 15:15:00.262643 2026] [autoindex:error] [pid 971102:tid 971351] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:00.263131 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/customize/"] [unique_id "aqxYVOcL08BTTQixEnpYnQAAAHU"]
[Thu Sep 17 15:15:00.363645 2026] [security2:error] [pid 971102:tid 971283] [client 74.7.175.152:58020] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nebulous-llc.com"] [uri "/robots.txt"] [unique_id "aqxYVOcL08BTTQixEnpYngAAMTY"]
[Thu Sep 17 15:15:00.408551 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxYVOcL08BTTQixEnpYpAAAACs"]
[Thu Sep 17 15:15:00.571573 2026] [autoindex:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:00.572122 2026] [security2:error] [pid 971102:tid 971266] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/fonts/"] [unique_id "aqxYVOcL08BTTQixEnpYqwAAACA"]
[Thu Sep 17 15:15:00.719779 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/images/"] [unique_id "aqxYVOcL08BTTQixEnpYrwAAACk"]
[Thu Sep 17 15:15:00.904708 2026] [autoindex:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:00.905208 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/images/"] [unique_id "aqxYVOcL08BTTQixEnpYtQAAAGk"]
[Thu Sep 17 15:15:00.911395 2026] [security2:error] [pid 971102:tid 971317] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYVOcL08BTTQixEnpYsgAAAFM"]
[Thu Sep 17 15:15:01.107787 2026] [autoindex:error] [pid 971102:tid 971319] [client 85.204.70.96:33034] AH01276: Cannot serve directory /home2/savemor0/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:01.108250 2026] [security2:error] [pid 971102:tid 971319] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/.well-known/"] [unique_id "aqxYVecL08BTTQixEnpYugAAAFU"]
[Thu Sep 17 15:15:01.255491 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/ALFA_DATA/"] [unique_id "aqxYVecL08BTTQixEnpYuwAAADA"]
[Thu Sep 17 15:15:01.352821 2026] [security2:error] [pid 971102:tid 971244] [client 156.192.234.52:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVecL08BTTQixEnpYvgAAAAo"]
[Thu Sep 17 15:15:01.352901 2026] [security2:error] [pid 971102:tid 971244] [client 156.192.234.52:59023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVecL08BTTQixEnpYvgAAAAo"]
[Thu Sep 17 15:15:01.564343 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpYvwAAAGw"]
[Thu Sep 17 15:15:01.564374 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpYvwAAAGw"]
[Thu Sep 17 15:15:01.714793 2026] [security2:error] [pid 971102:tid 971247] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/.well-knownold/"] [unique_id "aqxYVecL08BTTQixEnpYyAAAAA0"]
[Thu Sep 17 15:15:01.761220 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env"] [unique_id "aqxYVecL08BTTQixEnpYyQAAAAk"]
[Thu Sep 17 15:15:01.910085 2026] [security2:error] [pid 971102:tid 971245] [client 104.248.203.175:60404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYUecL08BTTQixEnpYYAAAC1Q"], referer: http://mail.get-hope.org/wordpress/
[Thu Sep 17 15:15:02.035118 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpY0gAAAAc"]
[Thu Sep 17 15:15:02.035142 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVecL08BTTQixEnpY0gAAAAc"]
[Thu Sep 17 15:15:02.196298 2026] [autoindex:error] [pid 971102:tid 971262] [client 85.204.70.96:33034] AH01276: Cannot serve directory /home2/savemor0/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:02.196836 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/.well-known/acme-challenge/"] [unique_id "aqxYVucL08BTTQixEnpY2wAAABw"]
[Thu Sep 17 15:15:02.200356 2026] [security2:error] [pid 971102:tid 971296] [client 192.178.6.3:43542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYVucL08BTTQixEnpY3QAAAD4"]
[Thu Sep 17 15:15:02.264465 2026] [security2:error] [pid 971102:tid 971324] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY2gAAAFo"]
[Thu Sep 17 15:15:02.341983 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-bin/"] [unique_id "aqxYVucL08BTTQixEnpY5QAAAEU"]
[Thu Sep 17 15:15:02.530015 2026] [cgid:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] AH01265: stderr from /home2/savemor0/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Sep 17 15:15:02.530561 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-bin/"] [unique_id "aqxYVucL08BTTQixEnpY6wAAAHQ"]
[Thu Sep 17 15:15:02.697736 2026] [security2:error] [pid 971102:tid 971300] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY6gAAAEI"]
[Thu Sep 17 15:15:02.702999 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/index/"] [unique_id "aqxYVucL08BTTQixEnpY7QAAAD0"]
[Thu Sep 17 15:15:02.872005 2026] [security2:error] [pid 971102:tid 971359] [client 186.105.232.15:63174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVucL08BTTQixEnpY7gAAAH0"]
[Thu Sep 17 15:15:02.872151 2026] [security2:error] [pid 971102:tid 971359] [client 186.105.232.15:63174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYVucL08BTTQixEnpY7gAAAH0"]
[Thu Sep 17 15:15:02.895450 2026] [security2:error] [pid 971102:tid 971290] [client 104.248.203.175:60404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY3wAAOCY"], referer: http://mail.get-hope.org/old/
[Thu Sep 17 15:15:03.060191 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY7wAAACk"]
[Thu Sep 17 15:15:03.060213 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYVucL08BTTQixEnpY7wAAACk"]
[Thu Sep 17 15:15:03.210086 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpY9QAAAEg"]
[Thu Sep 17 15:15:03.212870 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/id/"] [unique_id "aqxYV-cL08BTTQixEnpY9wAAABQ"]
[Thu Sep 17 15:15:03.538328 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpY_AAAAGk"]
[Thu Sep 17 15:15:03.538355 2026] [security2:error] [pid 971102:tid 971339] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpY_AAAAGk"]
[Thu Sep 17 15:15:03.656473 2026] [security2:error] [pid 971102:tid 971239] [client 212.200.122.55:57208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZAQAABSw"], referer: https://www.enolastable.com/2022/11/
[Thu Sep 17 15:15:03.681103 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZAAAAAHY"]
[Thu Sep 17 15:15:03.697336 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/www/"] [unique_id "aqxYV-cL08BTTQixEnpZAgAAAHc"]
[Thu Sep 17 15:15:03.979164 2026] [security2:error] [pid 971102:tid 971354] [client 5.189.145.112:49627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxYV-cL08BTTQixEnpZCwAAAHg"], referer: binance.com
[Thu Sep 17 15:15:03.987387 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZBAAAAAA"]
[Thu Sep 17 15:15:03.987406 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYV-cL08BTTQixEnpZBAAAAAA"]
[Thu Sep 17 15:15:03.995899 2026] [security2:error] [pid 971102:tid 971301] [client 185.55.149.49:65305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYV-cL08BTTQixEnpZDAAAAEM"]
[Thu Sep 17 15:15:03.995978 2026] [security2:error] [pid 971102:tid 971301] [client 185.55.149.49:65305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYV-cL08BTTQixEnpZDAAAAEM"]
[Thu Sep 17 15:15:04.139719 2026] [security2:error] [pid 971102:tid 971278] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/web/"] [unique_id "aqxYWOcL08BTTQixEnpZEAAAACw"]
[Thu Sep 17 15:15:04.177299 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZDwAAAHA"]
[Thu Sep 17 15:15:04.240795 2026] [autoindex:error] [pid 971102:tid 971312] [client 20.244.34.24:53325] AH01276: Cannot serve directory /home1/wxxngamy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:15:04.443318 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZEgAAABY"]
[Thu Sep 17 15:15:04.443343 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZEgAAABY"]
[Thu Sep 17 15:15:04.596978 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/uploads/"] [unique_id "aqxYWOcL08BTTQixEnpZGwAAACg"]
[Thu Sep 17 15:15:04.643526 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZGAAAAAc"]
[Thu Sep 17 15:15:04.650221 2026] [security2:error] [pid 971102:tid 971248] [client 20.244.34.24:54179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxYWOcL08BTTQixEnpZHAAAAA4"], referer: binance.com
[Thu Sep 17 15:15:04.883428 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZHwAAACY"]
[Thu Sep 17 15:15:04.883459 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWOcL08BTTQixEnpZHwAAACY"]
[Thu Sep 17 15:15:04.929484 2026] [security2:error] [pid 971102:tid 971246] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxYWOcL08BTTQixEnpZJgAAAAw"]
[Thu Sep 17 15:15:05.046110 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/upload/"] [unique_id "aqxYWecL08BTTQixEnpZKAAAAEU"]
[Thu Sep 17 15:15:05.073002 2026] [security2:error] [pid 971102:tid 971302] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxYWecL08BTTQixEnpZKQAAAEQ"]
[Thu Sep 17 15:15:05.394188 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZLAAAAFs"]
[Thu Sep 17 15:15:05.394214 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZLAAAAFs"]
[Thu Sep 17 15:15:05.414021 2026] [security2:error] [pid 971102:tid 971266] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZLQAAACA"]
[Thu Sep 17 15:15:05.438500 2026] [access_compat:error] [pid 971102:tid 971286] [client 78.46.218.89:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/elven-legend-8-the-wicked-gears-collectors-edition
[Thu Sep 17 15:15:05.540906 2026] [security2:error] [pid 971102:tid 971298] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/uploads/"] [unique_id "aqxYWecL08BTTQixEnpZNgAAAEA"]
[Thu Sep 17 15:15:05.620831 2026] [security2:error] [pid 971102:tid 971319] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxYWecL08BTTQixEnpZOQAAAFU"]
[Thu Sep 17 15:15:05.833128 2026] [security2:error] [pid 971102:tid 971239] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZPAAAAAU"]
[Thu Sep 17 15:15:05.833159 2026] [security2:error] [pid 971102:tid 971239] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZPAAAAAU"]
[Thu Sep 17 15:15:05.914008 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWecL08BTTQixEnpZQAAAABM"]
[Thu Sep 17 15:15:05.990592 2026] [security2:error] [pid 971102:tid 971301] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Admin/uploads/"] [unique_id "aqxYWecL08BTTQixEnpZRQAAAEM"]
[Thu Sep 17 15:15:06.279866 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZRwAAAFA"]
[Thu Sep 17 15:15:06.279892 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZRwAAAFA"]
[Thu Sep 17 15:15:06.405402 2026] [security2:error] [pid 971102:tid 971344] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZSgAAAG4"]
[Thu Sep 17 15:15:06.437438 2026] [security2:error] [pid 971102:tid 971274] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/"] [unique_id "aqxYWucL08BTTQixEnpZUQAAACg"]
[Thu Sep 17 15:15:06.722583 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZVQAAABw"]
[Thu Sep 17 15:15:06.722611 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZVQAAABw"]
[Thu Sep 17 15:15:06.917911 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYWucL08BTTQixEnpZWAAAABg"]
[Thu Sep 17 15:15:06.989737 2026] [security2:error] [pid 971102:tid 971246] [client 162.241.226.11:42902] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxYWucL08BTTQixEnpZYQAAAAw"]
[Thu Sep 17 15:15:07.105753 2026] [security2:error] [pid 971102:tid 971307] [client 114.198.138.124:62032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZYwAAAEk"]
[Thu Sep 17 15:15:07.105841 2026] [security2:error] [pid 971102:tid 971307] [client 114.198.138.124:62032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZYwAAAEk"]
[Thu Sep 17 15:15:07.332657 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYW-cL08BTTQixEnpZZwAAAEE"]
[Thu Sep 17 15:15:07.375421 2026] [security2:error] [pid 971102:tid 971338] [client 45.169.98.18:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZbAAAAGg"]
[Thu Sep 17 15:15:07.375531 2026] [security2:error] [pid 971102:tid 971338] [client 45.169.98.18:51818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZbAAAAGg"]
[Thu Sep 17 15:15:07.392128 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYWucL08BTTQixEnpZXgAAAHU"]
[Thu Sep 17 15:15:07.626348 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYW-cL08BTTQixEnpZdAAAADg"]
[Thu Sep 17 15:15:07.626472 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:39318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYW-cL08BTTQixEnpZdAAAADg"]
[Thu Sep 17 15:15:07.675580 2026] [security2:error] [pid 971102:tid 971325] [client 154.190.208.131:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZeAAAAFs"]
[Thu Sep 17 15:15:07.680098 2026] [security2:error] [pid 971102:tid 971325] [client 154.190.208.131:41794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYW-cL08BTTQixEnpZeAAAAFs"]
[Thu Sep 17 15:15:07.770371 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/images/"] [unique_id "aqxYW-cL08BTTQixEnpZegAAACE"]
[Thu Sep 17 15:15:07.914129 2026] [security2:error] [pid 971102:tid 971339] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYW-cL08BTTQixEnpZeQAAAGk"]
[Thu Sep 17 15:15:08.363809 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZhAAAAHA"]
[Thu Sep 17 15:15:08.627150 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZhQAAAFM"]
[Thu Sep 17 15:15:08.627176 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZhQAAAFM"]
[Thu Sep 17 15:15:08.721920 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZjwAAAFw"]
[Thu Sep 17 15:15:08.910420 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/assets/"] [unique_id "aqxYXOcL08BTTQixEnpZmwAAAEQ"]
[Thu Sep 17 15:15:09.031914 2026] [core:error] [pid 971102:tid 971315] [client 74.7.230.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:09.031933 2026] [core:error] [pid 971102:tid 971315] [client 74.7.230.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:09.032053 2026] [security2:error] [pid 971102:tid 971315] [client 74.7.230.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.athikerrev.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "aqxYXecL08BTTQixEnpZogAAAFE"]
[Thu Sep 17 15:15:09.033743 2026] [security2:error] [pid 971102:tid 971279] [client 74.7.230.17:34942] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.athikerrev.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxYXOcL08BTTQixEnpZnwAALVg"]
[Thu Sep 17 15:15:09.060952 2026] [security2:error] [pid 971102:tid 971271] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZmgAAACU"]
[Thu Sep 17 15:15:09.344486 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZowAAAHQ"]
[Thu Sep 17 15:15:09.344513 2026] [security2:error] [pid 971102:tid 971290] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZowAAAHQ"]
[Thu Sep 17 15:15:09.487496 2026] [security2:error] [pid 971102:tid 971295] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZrAAAAD0"]
[Thu Sep 17 15:15:09.493547 2026] [security2:error] [pid 971102:tid 971349] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "aqxYXecL08BTTQixEnpZsQAAAHM"]
[Thu Sep 17 15:15:09.786143 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZuAAAAHg"]
[Thu Sep 17 15:15:09.786163 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZuAAAAHg"]
[Thu Sep 17 15:15:09.897532 2026] [security2:error] [pid 971102:tid 971256] [client 20.244.34.24:58049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxYXecL08BTTQixEnpZxgAAABY"], referer: binance.com
[Thu Sep 17 15:15:09.930163 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/upload/image/"] [unique_id "aqxYXecL08BTTQixEnpZxwAAAGY"]
[Thu Sep 17 15:15:09.950964 2026] [security2:error] [pid 971102:tid 971260] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXecL08BTTQixEnpZvgAAABo"]
[Thu Sep 17 15:15:10.241242 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZygAAAD4"]
[Thu Sep 17 15:15:10.241266 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZygAAAD4"]
[Thu Sep 17 15:15:10.410380 2026] [security2:error] [pid 971102:tid 971342] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/assets/images/"] [unique_id "aqxYXucL08BTTQixEnpZ0QAAAGw"]
[Thu Sep 17 15:15:10.524272 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZzwAAAFw"]
[Thu Sep 17 15:15:10.710680 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZ1AAAACY"]
[Thu Sep 17 15:15:10.710713 2026] [security2:error] [pid 971102:tid 971272] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZ1AAAACY"]
[Thu Sep 17 15:15:10.757599 2026] [security2:error] [pid 971102:tid 971317] [client 104.248.203.175:48070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYXucL08BTTQixEnpZyQAAU3o"], referer: http://mail.get-hope.org/blog/
[Thu Sep 17 15:15:10.990160 2026] [security2:error] [pid 971102:tid 971275] [client 5.189.145.112:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxYXucL08BTTQixEnpZ3QAAACk"], referer: binance.com
[Thu Sep 17 15:15:11.032265 2026] [security2:error] [pid 971102:tid 971250] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxYX-cL08BTTQixEnpZ3wAAABA"]
[Thu Sep 17 15:15:11.049945 2026] [authz_core:error] [pid 971102:tid 971337] [client 172.239.147.162:51217] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-content/uploads/wpcf7_uploads/, referer: binance.com
[Thu Sep 17 15:15:11.119800 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.env~"] [unique_id "aqxYX-cL08BTTQixEnpZ4QAAAFk"]
[Thu Sep 17 15:15:11.163232 2026] [security2:error] [pid 971102:tid 971270] [client 74.7.175.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.asrendering.com.au"] [uri "/index.php"] [unique_id "aqxYXOcL08BTTQixEnpZngAAACQ"]
[Thu Sep 17 15:15:11.205431 2026] [security2:error] [pid 971102:tid 971324] [client 74.7.175.141:37522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.asrendering.com.au"] [uri "/robots.txt"] [unique_id "aqxYXOcL08BTTQixEnpZnAAAWgw"]
[Thu Sep 17 15:15:11.350039 2026] [security2:error] [pid 971102:tid 971340] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Public/"] [unique_id "aqxYX-cL08BTTQixEnpZ6gAAAGo"]
[Thu Sep 17 15:15:11.490520 2026] [security2:error] [pid 971102:tid 971357] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ5wAAAHs"]
[Thu Sep 17 15:15:11.647264 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ7QAAACE"]
[Thu Sep 17 15:15:11.647284 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ7QAAACE"]
[Thu Sep 17 15:15:11.806769 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/vendor/"] [unique_id "aqxYX-cL08BTTQixEnpZ8wAAADo"]
[Thu Sep 17 15:15:11.843099 2026] [security2:error] [pid 971102:tid 971325] [client 156.192.234.52:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYX-cL08BTTQixEnpZ9AAAAFs"]
[Thu Sep 17 15:15:11.843217 2026] [security2:error] [pid 971102:tid 971325] [client 156.192.234.52:59733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYX-cL08BTTQixEnpZ9AAAAFs"]
[Thu Sep 17 15:15:12.017069 2026] [security2:error] [pid 971102:tid 971277] [client 104.248.203.175:48070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ6wAAK3s"], referer: http://mail.get-hope.org/wp/
[Thu Sep 17 15:15:12.097578 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ-wAAAEw"]
[Thu Sep 17 15:15:12.097604 2026] [security2:error] [pid 971102:tid 971310] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ-wAAAEw"]
[Thu Sep 17 15:15:12.166944 2026] [security2:error] [pid 971102:tid 971239] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpZ_QAAAAU"]
[Thu Sep 17 15:15:12.246991 2026] [security2:error] [pid 971102:tid 971331] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/local/"] [unique_id "aqxYYOcL08BTTQixEnpaAgAAAGE"]
[Thu Sep 17 15:15:12.561554 2026] [security2:error] [pid 971102:tid 971321] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaCwAAAFc"]
[Thu Sep 17 15:15:12.561578 2026] [security2:error] [pid 971102:tid 971321] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaCwAAAFc"]
[Thu Sep 17 15:15:12.577594 2026] [autoindex:error] [pid 971102:tid 971285] [client 105.113.91.150:7441] AH01276: Cannot serve directory /home1/afbacoco/public_html/windyisland/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://allbacklinkschecker.website/dir/link-outreach-services-232789
[Thu Sep 17 15:15:12.631634 2026] [security2:error] [pid 971102:tid 971333] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaDAAAAGM"]
[Thu Sep 17 15:15:12.708094 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/modules/"] [unique_id "aqxYYOcL08BTTQixEnpaEQAAAE4"]
[Thu Sep 17 15:15:12.970436 2026] [security2:error] [pid 971102:tid 971244] [client 104.248.203.175:48070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.get-hope.org"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaBQAACmY"], referer: http://mail.get-hope.org/new/
[Thu Sep 17 15:15:13.029431 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaFAAAAHI"]
[Thu Sep 17 15:15:13.029454 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYOcL08BTTQixEnpaFAAAAHI"]
[Thu Sep 17 15:15:13.196315 2026] [security2:error] [pid 971102:tid 971308] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Site/"] [unique_id "aqxYYecL08BTTQixEnpaGwAAAEo"]
[Thu Sep 17 15:15:13.210655 2026] [security2:error] [pid 971102:tid 971334] [client 44.252.126.63:8295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxYX-cL08BTTQixEnpZ7wAAAGQ"]
[Thu Sep 17 15:15:13.486720 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaHQAAAEU"]
[Thu Sep 17 15:15:13.486753 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaHQAAAEU"]
[Thu Sep 17 15:15:13.562538 2026] [security2:error] [pid 971102:tid 971315] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaJgAAAFE"]
[Thu Sep 17 15:15:13.578336 2026] [authz_core:error] [pid 971102:tid 971343] [client 172.239.147.162:53756] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-content/uploads/wpcf7_uploads/, referer: binance.com
[Thu Sep 17 15:15:13.632833 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/system/"] [unique_id "aqxYYecL08BTTQixEnpaKQAAAC4"]
[Thu Sep 17 15:15:13.957684 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaLgAAAEg"]
[Thu Sep 17 15:15:13.957721 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaLgAAAEg"]
[Thu Sep 17 15:15:13.980361 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaLwAAAF4"]
[Thu Sep 17 15:15:14.105057 2026] [security2:error] [pid 971102:tid 971354] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/template/"] [unique_id "aqxYYucL08BTTQixEnpaOAAAAHg"]
[Thu Sep 17 15:15:14.105082 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaOQAAAHs"]
[Thu Sep 17 15:15:14.105164 2026] [security2:error] [pid 971102:tid 971357] [client 186.105.232.15:63758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaOQAAAHs"]
[Thu Sep 17 15:15:14.213854 2026] [security2:error] [pid 971102:tid 971251] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxYYucL08BTTQixEnpaPAAAABE"]
[Thu Sep 17 15:15:14.331741 2026] [security2:error] [pid 971102:tid 971314] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxYYucL08BTTQixEnpaPwAAAFA"]
[Thu Sep 17 15:15:14.395306 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYucL08BTTQixEnpaPQAAAHY"]
[Thu Sep 17 15:15:14.395331 2026] [security2:error] [pid 971102:tid 971352] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYYucL08BTTQixEnpaPQAAAHY"]
[Thu Sep 17 15:15:14.419629 2026] [security2:error] [pid 971102:tid 971333] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxYYucL08BTTQixEnpaQwAAAGM"]
[Thu Sep 17 15:15:14.519522 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxYYucL08BTTQixEnpaRQAAAAE"]
[Thu Sep 17 15:15:14.592326 2026] [security2:error] [pid 971102:tid 971330] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/shop/"] [unique_id "aqxYYucL08BTTQixEnpaSQAAAGA"]
[Thu Sep 17 15:15:14.611427 2026] [security2:error] [pid 971102:tid 971278] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxYYucL08BTTQixEnpaSgAAACw"]
[Thu Sep 17 15:15:14.699165 2026] [core:error] [pid 971102:tid 971296] [client 35.185.138.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:14.699183 2026] [core:error] [pid 971102:tid 971296] [client 35.185.138.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:14.699290 2026] [security2:error] [pid 971102:tid 971296] [client 35.185.138.72:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.sahlan.24eastyard.com"] [uri "/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/home2/loseyov0/public_html/index.php/sahlan/.git/config"] [unique_id "aqxYYucL08BTTQixEnpaSwAAAD4"]
[Thu Sep 17 15:15:14.705178 2026] [security2:error] [pid 971102:tid 971245] [client 35.185.138.72:60656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.sahlan.24eastyard.com"] [uri "/.git/config"] [unique_id "aqxYYucL08BTTQixEnpaRwAAAAs"]
[Thu Sep 17 15:15:14.723517 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:23029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTAAAADQ"]
[Thu Sep 17 15:15:14.723595 2026] [security2:error] [pid 971102:tid 971286] [client 104.28.198.244:23029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTAAAADQ"]
[Thu Sep 17 15:15:14.735643 2026] [security2:error] [pid 971102:tid 971348] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxYYucL08BTTQixEnpaTQAAAHI"]
[Thu Sep 17 15:15:14.818472 2026] [security2:error] [pid 971102:tid 971312] [client 185.55.149.49:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTgAAAE4"]
[Thu Sep 17 15:15:14.818570 2026] [security2:error] [pid 971102:tid 971312] [client 185.55.149.49:49896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYYucL08BTTQixEnpaTgAAAE4"]
[Thu Sep 17 15:15:15.037682 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYYucL08BTTQixEnpaUwAAAFw"]
[Thu Sep 17 15:15:15.154048 2026] [security2:error] [pid 971102:tid 971318] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaVgAAAFQ"]
[Thu Sep 17 15:15:15.154068 2026] [security2:error] [pid 971102:tid 971318] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaVgAAAFQ"]
[Thu Sep 17 15:15:15.303193 2026] [security2:error] [pid 971102:tid 971249] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/files/"] [unique_id "aqxYY-cL08BTTQixEnpaWwAAAA8"]
[Thu Sep 17 15:15:15.346434 2026] [security2:error] [pid 971102:tid 971315] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxYY-cL08BTTQixEnpaXgAAAFE"]
[Thu Sep 17 15:15:15.382459 2026] [security2:error] [pid 971102:tid 971282] [client 210.222.43.21:49378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaWgAAADA"], referer: http://talent-in-borders.com/2021
[Thu Sep 17 15:15:15.442251 2026] [security2:error] [pid 971102:tid 971271] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxYY-cL08BTTQixEnpaYQAAACU"]
[Thu Sep 17 15:15:15.563651 2026] [security2:error] [pid 971102:tid 971329] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxYY-cL08BTTQixEnpaZQAAAF8"]
[Thu Sep 17 15:15:15.633680 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaYgAAABM"]
[Thu Sep 17 15:15:15.633710 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpaYgAAABM"]
[Thu Sep 17 15:15:15.654142 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxYY-cL08BTTQixEnpaZwAAAC0"]
[Thu Sep 17 15:15:15.671171 2026] [security2:error] [pid 971102:tid 971289] [client 49.13.24.81:4846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYYecL08BTTQixEnpaKwAAADc"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:15:15.770639 2026] [security2:error] [pid 971102:tid 971340] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxYY-cL08BTTQixEnpaaAAAAGo"]
[Thu Sep 17 15:15:15.804831 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/editor/"] [unique_id "aqxYY-cL08BTTQixEnpabAAAAC8"]
[Thu Sep 17 15:15:15.851836 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxYY-cL08BTTQixEnpabgAAAAY"]
[Thu Sep 17 15:15:15.958314 2026] [security2:error] [pid 971102:tid 971327] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxYY-cL08BTTQixEnpadAAAAF0"]
[Thu Sep 17 15:15:16.061251 2026] [security2:error] [pid 971102:tid 971290] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxYZOcL08BTTQixEnpadwAAADg"]
[Thu Sep 17 15:15:16.091053 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpacgAAADo"]
[Thu Sep 17 15:15:16.091084 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYY-cL08BTTQixEnpacgAAADo"]
[Thu Sep 17 15:15:16.164347 2026] [security2:error] [pid 971102:tid 971295] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxYZOcL08BTTQixEnpaeQAAAD0"]
[Thu Sep 17 15:15:16.237824 2026] [security2:error] [pid 971102:tid 971278] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxYZOcL08BTTQixEnpaegAAACw"]
[Thu Sep 17 15:15:16.238877 2026] [security2:error] [pid 971102:tid 971335] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/include/"] [unique_id "aqxYZOcL08BTTQixEnpaewAAAGU"]
[Thu Sep 17 15:15:16.258040 2026] [security2:error] [pid 971102:tid 971300] [client 49.13.24.81:19406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnpaeAAAAEI"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:15:16.292082 2026] [security2:error] [pid 971102:tid 971268] [client 3.82.141.143:36162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php.save"] [unique_id "aqxYZOcL08BTTQixEnpagQAAACI"]
[Thu Sep 17 15:15:16.292322 2026] [security2:error] [pid 971102:tid 971313] [client 3.82.141.143:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.meatlessmusings.com"] [uri "/config.php"] [unique_id "aqxYZOcL08BTTQixEnpaggAAAE8"]
[Thu Sep 17 15:15:16.296879 2026] [proxy_http:error] [pid 971102:tid 971353] (20014)Internal error (specific information not available): [client 3.82.141.143:35872] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.296893 2026] [proxy:error] [pid 971102:tid 971353] [client 3.82.141.143:35872] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.local
[Thu Sep 17 15:15:16.302042 2026] [proxy_http:error] [pid 971102:tid 971235] (20014)Internal error (specific information not available): [client 3.82.141.143:36112] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.302062 2026] [proxy:error] [pid 971102:tid 971235] [client 3.82.141.143:36112] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.netrc
[Thu Sep 17 15:15:16.303765 2026] [security2:error] [pid 971102:tid 971286] [client 3.82.141.143:36184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php~"] [unique_id "aqxYZOcL08BTTQixEnpaigAAADQ"]
[Thu Sep 17 15:15:16.306954 2026] [proxy_http:error] [pid 971102:tid 971361] (20014)Internal error (specific information not available): [client 3.82.141.143:36010] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.306967 2026] [proxy:error] [pid 971102:tid 971361] [client 3.82.141.143:36010] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/web.config
[Thu Sep 17 15:15:16.307021 2026] [security2:error] [pid 971102:tid 971260] [client 3.82.141.143:36154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php.old"] [unique_id "aqxYZOcL08BTTQixEnpalAAAABo"]
[Thu Sep 17 15:15:16.318751 2026] [proxy_http:error] [pid 971102:tid 971274] (20014)Internal error (specific information not available): [client 3.82.141.143:36070] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.318764 2026] [proxy:error] [pid 971102:tid 971274] [client 3.82.141.143:36070] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.aws/config
[Thu Sep 17 15:15:16.318985 2026] [security2:error] [pid 971102:tid 971348] [client 3.82.141.143:36176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYZOcL08BTTQixEnpapAAAAHI"]
[Thu Sep 17 15:15:16.319355 2026] [security2:error] [pid 971102:tid 971273] [client 3.82.141.143:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.meatlessmusings.com"] [uri "/wp-config.php"] [unique_id "aqxYZOcL08BTTQixEnpapQAAACc"]
[Thu Sep 17 15:15:16.323423 2026] [proxy_http:error] [pid 971102:tid 971331] (20014)Internal error (specific information not available): [client 3.82.141.143:35924] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.323433 2026] [proxy:error] [pid 971102:tid 971331] [client 3.82.141.143:35924] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.bak
[Thu Sep 17 15:15:16.334236 2026] [proxy_http:error] [pid 971102:tid 971296] (20014)Internal error (specific information not available): [client 3.82.141.143:35894] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.334247 2026] [proxy:error] [pid 971102:tid 971296] [client 3.82.141.143:35894] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.staging
[Thu Sep 17 15:15:16.338919 2026] [proxy_http:error] [pid 971102:tid 971319] (20014)Internal error (specific information not available): [client 3.82.141.143:35998] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.338934 2026] [proxy:error] [pid 971102:tid 971319] [client 3.82.141.143:35998] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/secret.json
[Thu Sep 17 15:15:16.343050 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxYZOcL08BTTQixEnpaqAAAAFw"]
[Thu Sep 17 15:15:16.349778 2026] [proxy_http:error] [pid 971102:tid 971320] (20014)Internal error (specific information not available): [client 3.82.141.143:35946] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.349794 2026] [proxy:error] [pid 971102:tid 971320] [client 3.82.141.143:35946] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/config.json
[Thu Sep 17 15:15:16.354504 2026] [proxy_http:error] [pid 971102:tid 971241] (20014)Internal error (specific information not available): [client 3.82.141.143:36022] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.354516 2026] [proxy:error] [pid 971102:tid 971241] [client 3.82.141.143:36022] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/application.yml
[Thu Sep 17 15:15:16.359189 2026] [proxy_http:error] [pid 971102:tid 971321] (20014)Internal error (specific information not available): [client 3.82.141.143:35944] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.359206 2026] [proxy:error] [pid 971102:tid 971321] [client 3.82.141.143:35944] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.dist
[Thu Sep 17 15:15:16.363759 2026] [proxy_http:error] [pid 971102:tid 971347] (20014)Internal error (specific information not available): [client 3.82.141.143:36146] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.363774 2026] [proxy:error] [pid 971102:tid 971347] [client 3.82.141.143:36146] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.git-credentials
[Thu Sep 17 15:15:16.369122 2026] [proxy_http:error] [pid 971102:tid 971262] (20014)Internal error (specific information not available): [client 3.82.141.143:36086] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.369139 2026] [proxy:error] [pid 971102:tid 971262] [client 3.82.141.143:36086] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.s3cfg
[Thu Sep 17 15:15:16.374180 2026] [proxy_http:error] [pid 971102:tid 971266] (20014)Internal error (specific information not available): [client 3.82.141.143:36126] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.374194 2026] [proxy:error] [pid 971102:tid 971266] [client 3.82.141.143:36126] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.gitlab-ci.yml
[Thu Sep 17 15:15:16.379093 2026] [proxy_http:error] [pid 971102:tid 971336] (20014)Internal error (specific information not available): [client 3.82.141.143:35984] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.379106 2026] [proxy:error] [pid 971102:tid 971336] [client 3.82.141.143:35984] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/settings.json
[Thu Sep 17 15:15:16.384381 2026] [proxy_http:error] [pid 971102:tid 971342] (20014)Internal error (specific information not available): [client 3.82.141.143:35932] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.384393 2026] [proxy:error] [pid 971102:tid 971342] [client 3.82.141.143:35932] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.save
[Thu Sep 17 15:15:16.389201 2026] [proxy_http:error] [pid 971102:tid 971274] (20014)Internal error (specific information not available): [client 3.82.141.143:36070] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.389216 2026] [proxy:error] [pid 971102:tid 971274] [client 3.82.141.143:36070] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Thu Sep 17 15:15:16.394339 2026] [proxy_http:error] [pid 971102:tid 971331] (20014)Internal error (specific information not available): [client 3.82.141.143:35924] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:15:16.394351 2026] [proxy:error] [pid 971102:tid 971331] [client 3.82.141.143:35924] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Thu Sep 17 15:15:16.398473 2026] [security2:error] [pid 971102:tid 971284] [client 24.250.150.202:57311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYZOcL08BTTQixEnpafAAAMl4"]
[Thu Sep 17 15:15:16.442639 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxYZOcL08BTTQixEnparwAAAFk"]
[Thu Sep 17 15:15:16.519235 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxYZOcL08BTTQixEnpaswAAAAY"]
[Thu Sep 17 15:15:16.536270 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnparAAAAFM"]
[Thu Sep 17 15:15:16.536292 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnparAAAAFM"]
[Thu Sep 17 15:15:16.598802 2026] [security2:error] [pid 971102:tid 971356] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxYZOcL08BTTQixEnpatAAAAHo"]
[Thu Sep 17 15:15:16.696331 2026] [security2:error] [pid 971102:tid 971293] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/Assets/"] [unique_id "aqxYZOcL08BTTQixEnpatwAAADs"]
[Thu Sep 17 15:15:16.720880 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxYZOcL08BTTQixEnpauAAAAEg"]
[Thu Sep 17 15:15:16.868304 2026] [security2:error] [pid 971102:tid 971267] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxYZOcL08BTTQixEnpauwAAACE"]
[Thu Sep 17 15:15:16.977069 2026] [security2:error] [pid 971102:tid 971335] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxYZOcL08BTTQixEnpavwAAAGU"]
[Thu Sep 17 15:15:16.978278 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnpauQAAACs"]
[Thu Sep 17 15:15:16.978298 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZOcL08BTTQixEnpauQAAACs"]
[Thu Sep 17 15:15:17.082040 2026] [security2:error] [pid 971102:tid 971325] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxYZecL08BTTQixEnpawgAAAFs"]
[Thu Sep 17 15:15:17.123620 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/images/stories/"] [unique_id "aqxYZecL08BTTQixEnpaxAAAAE8"]
[Thu Sep 17 15:15:17.162241 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxYZecL08BTTQixEnpaxgAAAAk"]
[Thu Sep 17 15:15:17.240601 2026] [security2:error] [pid 971102:tid 971348] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxYZecL08BTTQixEnpaxwAAAHI"]
[Thu Sep 17 15:15:17.259990 2026] [security2:error] [pid 971102:tid 971322] [client 20.244.34.24:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.34.244.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "airmacinc.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxYZecL08BTTQixEnpaygAAAFg"], referer: binance.com
[Thu Sep 17 15:15:17.322201 2026] [security2:error] [pid 971102:tid 971314] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxYZecL08BTTQixEnpazQAAAFA"]
[Thu Sep 17 15:15:17.393319 2026] [security2:error] [pid 971102:tid 971305] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxYZecL08BTTQixEnpa0QAAAEc"]
[Thu Sep 17 15:15:17.458610 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpaywAAACo"]
[Thu Sep 17 15:15:17.458628 2026] [security2:error] [pid 971102:tid 971276] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpaywAAACo"]
[Thu Sep 17 15:15:17.469087 2026] [security2:error] [pid 971102:tid 971248] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxYZecL08BTTQixEnpa0wAAAA4"]
[Thu Sep 17 15:15:17.562353 2026] [security2:error] [pid 971102:tid 971291] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxYZecL08BTTQixEnpa1QAAADk"]
[Thu Sep 17 15:15:17.610411 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/plugins/"] [unique_id "aqxYZecL08BTTQixEnpa1gAAAAo"]
[Thu Sep 17 15:15:17.633054 2026] [security2:error] [pid 971102:tid 971274] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxYZecL08BTTQixEnpa1wAAACg"]
[Thu Sep 17 15:15:17.732237 2026] [security2:error] [pid 971102:tid 971296] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxYZecL08BTTQixEnpa3AAAAD4"]
[Thu Sep 17 15:15:17.813916 2026] [security2:error] [pid 971102:tid 971347] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxYZecL08BTTQixEnpa3wAAAHE"]
[Thu Sep 17 15:15:17.827861 2026] [security2:error] [pid 971102:tid 971319] [client 24.250.150.202:42873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYZecL08BTTQixEnpa3QAAVSA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821163557&hideanons=1&limit=500&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:15:17.866185 2026] [security2:error] [pid 971102:tid 971245] [client 114.198.138.124:62680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa4wAAAAs"]
[Thu Sep 17 15:15:17.866312 2026] [security2:error] [pid 971102:tid 971245] [client 114.198.138.124:62680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa4wAAAAs"]
[Thu Sep 17 15:15:17.875154 2026] [security2:error] [pid 971102:tid 971284] [client 45.169.98.18:52381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa5AAAADI"]
[Thu Sep 17 15:15:17.875288 2026] [security2:error] [pid 971102:tid 971284] [client 45.169.98.18:52381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZecL08BTTQixEnpa5AAAADI"]
[Thu Sep 17 15:15:17.892673 2026] [security2:error] [pid 971102:tid 971320] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpa3gAAAFY"]
[Thu Sep 17 15:15:17.892705 2026] [security2:error] [pid 971102:tid 971320] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpa3gAAAFY"]
[Thu Sep 17 15:15:17.919752 2026] [security2:error] [pid 971102:tid 971336] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxYZecL08BTTQixEnpa5QAAAGY"]
[Thu Sep 17 15:15:18.015821 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxYZucL08BTTQixEnpa5wAAAEY"]
[Thu Sep 17 15:15:18.046883 2026] [security2:error] [pid 971102:tid 971249] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/php/"] [unique_id "aqxYZucL08BTTQixEnpa6AAAAA8"]
[Thu Sep 17 15:15:18.128249 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxYZucL08BTTQixEnpa6gAAAFk"]
[Thu Sep 17 15:15:18.143419 2026] [security2:error] [pid 971102:tid 971234] [client 172.239.147.162:61390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxYZecL08BTTQixEnpa2AAAAAA"], referer: binance.com
[Thu Sep 17 15:15:18.202258 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxYZucL08BTTQixEnpa7AAAAEE"]
[Thu Sep 17 15:15:18.295257 2026] [security2:error] [pid 971102:tid 971275] [client 34.95.61.66:36144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxYZucL08BTTQixEnpa7gAAACk"]
[Thu Sep 17 15:15:18.338533 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.96:35964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZucL08BTTQixEnpa7QAAAF8"]
[Thu Sep 17 15:15:18.338558 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZucL08BTTQixEnpa7QAAAF8"]
[Thu Sep 17 15:15:18.495973 2026] [security2:error] [pid 971102:tid 971301] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/"] [unique_id "aqxYZucL08BTTQixEnpa-QAAAEM"]
[Thu Sep 17 15:15:18.651445 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxYZucL08BTTQixEnpa-wAAADw"]
[Thu Sep 17 15:15:18.688182 2026] [autoindex:error] [pid 971102:tid 971332] [client 85.204.70.96:35964] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:18.688686 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/"] [unique_id "aqxYZucL08BTTQixEnpa-gAAAGI"]
[Thu Sep 17 15:15:18.759650 2026] [security2:error] [pid 971102:tid 971290] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxYZucL08BTTQixEnpa_AAAADg"]
[Thu Sep 17 15:15:18.842846 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "aqxYZucL08BTTQixEnpa_QAAAEs"]
[Thu Sep 17 15:15:18.862880 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxYZucL08BTTQixEnpa_gAAAEg"]
[Thu Sep 17 15:15:19.000965 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:35964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/twentytwenty/index.php"] [unique_id "aqxYZucL08BTTQixEnpbAwAAAFs"]
[Thu Sep 17 15:15:19.011778 2026] [security2:error] [pid 971102:tid 971292] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbBAAAADo"]
[Thu Sep 17 15:15:19.147266 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/cache/"] [unique_id "aqxYZ-cL08BTTQixEnpbCAAAAHc"]
[Thu Sep 17 15:15:19.158817 2026] [security2:error] [pid 971102:tid 971251] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbCQAAABE"]
[Thu Sep 17 15:15:19.248709 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbCwAAAHA"]
[Thu Sep 17 15:15:19.255149 2026] [security2:error] [pid 971102:tid 971270] [client 154.190.208.131:42444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZ-cL08BTTQixEnpbDAAAACQ"]
[Thu Sep 17 15:15:19.255215 2026] [security2:error] [pid 971102:tid 971270] [client 154.190.208.131:42444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYZ-cL08BTTQixEnpbDAAAACQ"]
[Thu Sep 17 15:15:19.346340 2026] [security2:error] [pid 971102:tid 971272] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbDQAAACY"]
[Thu Sep 17 15:15:19.457729 2026] [security2:error] [pid 971102:tid 971246] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbDwAAAAw"]
[Thu Sep 17 15:15:19.528973 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbEQAAABg"]
[Thu Sep 17 15:15:19.621249 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbFAAAADU"]
[Thu Sep 17 15:15:19.715495 2026] [security2:error] [pid 971102:tid 971296] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbGAAAAD4"]
[Thu Sep 17 15:15:19.795114 2026] [security2:error] [pid 971102:tid 971260] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbGgAAABo"]
[Thu Sep 17 15:15:19.925607 2026] [security2:error] [pid 971102:tid 971284] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxYZ-cL08BTTQixEnpbGwAAADI"]
[Thu Sep 17 15:15:20.004627 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZ-cL08BTTQixEnpbEgAAAE4"]
[Thu Sep 17 15:15:20.004650 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYZ-cL08BTTQixEnpbEgAAAE4"]
[Thu Sep 17 15:15:20.006893 2026] [security2:error] [pid 971102:tid 971239] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxYaOcL08BTTQixEnpbHQAAAAU"]
[Thu Sep 17 15:15:20.100814 2026] [security2:error] [pid 971102:tid 971342] [client 5.189.145.112:57399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxYaOcL08BTTQixEnpbHgAAAGw"], referer: binance.com
[Thu Sep 17 15:15:20.105535 2026] [security2:error] [pid 971102:tid 971266] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxYaOcL08BTTQixEnpbHwAAACA"]
[Thu Sep 17 15:15:20.194906 2026] [security2:error] [pid 971102:tid 971330] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxYaOcL08BTTQixEnpbJQAAAGA"]
[Thu Sep 17 15:15:20.237299 2026] [authz_core:error] [pid 971102:tid 971245] [client 172.239.147.162:57278] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:20.293804 2026] [security2:error] [pid 971102:tid 971249] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxYaOcL08BTTQixEnpbJgAAAA8"]
[Thu Sep 17 15:15:20.385705 2026] [security2:error] [pid 971102:tid 971351] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxYaOcL08BTTQixEnpbJwAAAHU"]
[Thu Sep 17 15:15:20.478341 2026] [security2:error] [pid 971102:tid 971271] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxYaOcL08BTTQixEnpbKgAAACU"]
[Thu Sep 17 15:15:20.505221 2026] [security2:error] [pid 971102:tid 971337] [client 172.239.147.162:63347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxYaOcL08BTTQixEnpbKAAAAGc"], referer: binance.com
[Thu Sep 17 15:15:20.527582 2026] [security2:error] [pid 971102:tid 971234] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/maint/"] [unique_id "aqxYaOcL08BTTQixEnpbKwAAAAA"]
[Thu Sep 17 15:15:20.553256 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxYaOcL08BTTQixEnpbLAAAAEE"]
[Thu Sep 17 15:15:20.659268 2026] [security2:error] [pid 971102:tid 971307] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxYaOcL08BTTQixEnpbMQAAAEk"]
[Thu Sep 17 15:15:20.731796 2026] [autoindex:error] [pid 971102:tid 971329] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:20.732286 2026] [security2:error] [pid 971102:tid 971329] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/maint/"] [unique_id "aqxYaOcL08BTTQixEnpbMgAAAF8"]
[Thu Sep 17 15:15:20.786867 2026] [security2:error] [pid 971102:tid 971242] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxYaOcL08BTTQixEnpbNAAAAAg"]
[Thu Sep 17 15:15:20.876310 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxYaOcL08BTTQixEnpbNQAAAC0"]
[Thu Sep 17 15:15:20.889571 2026] [security2:error] [pid 971102:tid 971302] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYaOcL08BTTQixEnpbNgAAAEQ"]
[Thu Sep 17 15:15:21.023588 2026] [security2:error] [pid 971102:tid 971356] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxYaecL08BTTQixEnpbOAAAAHo"]
[Thu Sep 17 15:15:21.034635 2026] [authz_core:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] AH01630: client denied by server configuration: /home2/savemor0/public_html/wp-content/plugins/akismet/
[Thu Sep 17 15:15:21.035525 2026] [security2:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "aqxYaecL08BTTQixEnpbOQAAADw"]
[Thu Sep 17 15:15:21.162914 2026] [security2:error] [pid 971102:tid 971335] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxYaecL08BTTQixEnpbPwAAAGU"]
[Thu Sep 17 15:15:21.194742 2026] [security2:error] [pid 971102:tid 971350] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/assets/"] [unique_id "aqxYaecL08BTTQixEnpbQQAAAHQ"]
[Thu Sep 17 15:15:21.242548 2026] [security2:error] [pid 971102:tid 971238] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxYaecL08BTTQixEnpbQwAAAAQ"]
[Thu Sep 17 15:15:21.352517 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxYaecL08BTTQixEnpbRQAAAHA"]
[Thu Sep 17 15:15:21.354360 2026] [autoindex:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:21.354837 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/assets/"] [unique_id "aqxYaecL08BTTQixEnpbRAAAAFA"]
[Thu Sep 17 15:15:21.426861 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxYaecL08BTTQixEnpbRgAAAHY"]
[Thu Sep 17 15:15:21.506396 2026] [security2:error] [pid 971102:tid 971326] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYaecL08BTTQixEnpbSQAAAFw"]
[Thu Sep 17 15:15:21.534895 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxYaecL08BTTQixEnpbSgAAADU"]
[Thu Sep 17 15:15:21.616905 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxYaecL08BTTQixEnpbTwAAAAc"]
[Thu Sep 17 15:15:21.659164 2026] [autoindex:error] [pid 971102:tid 971260] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:21.659677 2026] [security2:error] [pid 971102:tid 971260] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-patterns/"] [unique_id "aqxYaecL08BTTQixEnpbVAAAABo"]
[Thu Sep 17 15:15:21.707789 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxYaecL08BTTQixEnpbWAAAAAo"]
[Thu Sep 17 15:15:21.804111 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxYaecL08BTTQixEnpbWQAAAE4"]
[Thu Sep 17 15:15:21.808112 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYaecL08BTTQixEnpbWgAAACs"]
[Thu Sep 17 15:15:21.879975 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxYaecL08BTTQixEnpbWwAAAFQ"]
[Thu Sep 17 15:15:21.964520 2026] [autoindex:error] [pid 971102:tid 971358] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:21.965031 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/block-supports/"] [unique_id "aqxYaecL08BTTQixEnpbXAAAAHw"]
[Thu Sep 17 15:15:22.010091 2026] [security2:error] [pid 971102:tid 971331] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxYaucL08BTTQixEnpbXQAAAGE"]
[Thu Sep 17 15:15:22.090416 2026] [security2:error] [pid 971102:tid 971342] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxYaucL08BTTQixEnpbYQAAAGw"]
[Thu Sep 17 15:15:22.110140 2026] [security2:error] [pid 971102:tid 971334] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxYaucL08BTTQixEnpbZAAAAGQ"]
[Thu Sep 17 15:15:22.173622 2026] [authz_core:error] [pid 971102:tid 971336] [client 172.239.147.162:59412] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:22.174878 2026] [security2:error] [pid 971102:tid 971249] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxYaucL08BTTQixEnpbaAAAAA8"]
[Thu Sep 17 15:15:22.268795 2026] [security2:error] [pid 971102:tid 971282] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxYaucL08BTTQixEnpbagAAADA"]
[Thu Sep 17 15:15:22.274744 2026] [autoindex:error] [pid 971102:tid 971323] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:22.275393 2026] [security2:error] [pid 971102:tid 971323] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/html-api/"] [unique_id "aqxYaucL08BTTQixEnpbaQAAAFk"]
[Thu Sep 17 15:15:22.363967 2026] [security2:error] [pid 971102:tid 971257] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxYaucL08BTTQixEnpbawAAABc"]
[Thu Sep 17 15:15:22.389201 2026] [security2:error] [pid 971102:tid 971293] [client 156.192.234.52:60329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYaucL08BTTQixEnpbbQAAADs"]
[Thu Sep 17 15:15:22.389297 2026] [security2:error] [pid 971102:tid 971293] [client 156.192.234.52:60329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYaucL08BTTQixEnpbbQAAADs"]
[Thu Sep 17 15:15:22.420525 2026] [security2:error] [pid 971102:tid 971337] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/js/"] [unique_id "aqxYaucL08BTTQixEnpbbgAAAGc"]
[Thu Sep 17 15:15:22.441517 2026] [security2:error] [pid 971102:tid 971234] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxYaucL08BTTQixEnpbbwAAAAA"]
[Thu Sep 17 15:15:22.520882 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxYaucL08BTTQixEnpbcAAAAEE"]
[Thu Sep 17 15:15:22.574932 2026] [autoindex:error] [pid 971102:tid 971349] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:22.575440 2026] [security2:error] [pid 971102:tid 971349] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/js/"] [unique_id "aqxYaucL08BTTQixEnpbcQAAAHM"]
[Thu Sep 17 15:15:22.630999 2026] [security2:error] [pid 971102:tid 971341] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxYaucL08BTTQixEnpbdgAAAGs"]
[Thu Sep 17 15:15:22.708107 2026] [security2:error] [pid 971102:tid 971330] [client 212.195.220.248:54847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYaucL08BTTQixEnpbcwAAYFE"]
[Thu Sep 17 15:15:22.719928 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYaucL08BTTQixEnpbeQAAAAg"]
[Thu Sep 17 15:15:22.724089 2026] [security2:error] [pid 971102:tid 971247] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxYaucL08BTTQixEnpbegAAAA0"]
[Thu Sep 17 15:15:22.796920 2026] [security2:error] [pid 971102:tid 971327] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxYaucL08BTTQixEnpbewAAAF0"]
[Thu Sep 17 15:15:22.903313 2026] [autoindex:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:22.903788 2026] [security2:error] [pid 971102:tid 971288] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxYaucL08BTTQixEnpbfgAAADY"]
[Thu Sep 17 15:15:22.903858 2026] [security2:error] [pid 971102:tid 971294] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/php-compat/"] [unique_id "aqxYaucL08BTTQixEnpbfQAAADw"]
[Thu Sep 17 15:15:22.985516 2026] [security2:error] [pid 971102:tid 971345] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxYaucL08BTTQixEnpbfwAAAG8"]
[Thu Sep 17 15:15:23.050248 2026] [security2:error] [pid 971102:tid 971306] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYa-cL08BTTQixEnpbggAAAEg"]
[Thu Sep 17 15:15:23.068681 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxYa-cL08BTTQixEnpbgwAAAAY"]
[Thu Sep 17 15:15:23.159889 2026] [security2:error] [pid 971102:tid 971309] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxYa-cL08BTTQixEnpbiAAAAEs"]
[Thu Sep 17 15:15:23.202684 2026] [autoindex:error] [pid 971102:tid 971328] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:23.203183 2026] [security2:error] [pid 971102:tid 971328] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "aqxYa-cL08BTTQixEnpbiQAAAF4"]
[Thu Sep 17 15:15:23.253495 2026] [security2:error] [pid 971102:tid 971301] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxYa-cL08BTTQixEnpbjAAAAEM"]
[Thu Sep 17 15:15:23.275881 2026] [authz_core:error] [pid 971102:tid 971335] [client 172.239.147.162:59946] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:23.348584 2026] [security2:error] [pid 971102:tid 971313] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxYa-cL08BTTQixEnpbjQAAAE8"]
[Thu Sep 17 15:15:23.369396 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxYa-cL08BTTQixEnpbjgAAAAk"]
[Thu Sep 17 15:15:23.451868 2026] [security2:error] [pid 971102:tid 971251] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxYa-cL08BTTQixEnpbjwAAABE"]
[Thu Sep 17 15:15:23.504908 2026] [autoindex:error] [pid 971102:tid 971322] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:23.505403 2026] [security2:error] [pid 971102:tid 971322] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/pomo/"] [unique_id "aqxYa-cL08BTTQixEnpbkQAAAFg"]
[Thu Sep 17 15:15:23.534407 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxYa-cL08BTTQixEnpbkgAAAHA"]
[Thu Sep 17 15:15:23.610320 2026] [security2:error] [pid 971102:tid 971361] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxYa-cL08BTTQixEnpblgAAAH8"]
[Thu Sep 17 15:15:23.654261 2026] [security2:error] [pid 971102:tid 971268] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/random_compat/"] [unique_id "aqxYa-cL08BTTQixEnpbmAAAACI"]
[Thu Sep 17 15:15:23.685653 2026] [security2:error] [pid 971102:tid 971360] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxYa-cL08BTTQixEnpbmgAAAH4"]
[Thu Sep 17 15:15:23.761424 2026] [security2:error] [pid 971102:tid 971355] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxYa-cL08BTTQixEnpbmwAAAHk"]
[Thu Sep 17 15:15:23.844542 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxYa-cL08BTTQixEnpbnwAAAFw"]
[Thu Sep 17 15:15:23.924090 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxYa-cL08BTTQixEnpboAAAAAc"]
[Thu Sep 17 15:15:24.017878 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxYbOcL08BTTQixEnpboQAAAAo"]
[Thu Sep 17 15:15:24.092873 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYa-cL08BTTQixEnpbnQAAACo"]
[Thu Sep 17 15:15:24.092896 2026] [security2:error] [pid 971102:tid 971256] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYa-cL08BTTQixEnpbnQAAACo"]
[Thu Sep 17 15:15:24.103404 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxYbOcL08BTTQixEnpbpQAAAE4"]
[Thu Sep 17 15:15:24.201347 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxYbOcL08BTTQixEnpbqgAAAFQ"]
[Thu Sep 17 15:15:24.243715 2026] [security2:error] [pid 971102:tid 971358] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYbOcL08BTTQixEnpbrgAAAHw"]
[Thu Sep 17 15:15:24.303070 2026] [security2:error] [pid 971102:tid 971334] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxYbOcL08BTTQixEnpbrwAAAGQ"]
[Thu Sep 17 15:15:24.309256 2026] [security2:error] [pid 971102:tid 971331] [client 74.7.244.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.revelinfear.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "aqxYbOcL08BTTQixEnpbsAAAAGE"]
[Thu Sep 17 15:15:24.321238 2026] [security2:error] [pid 971102:tid 971246] [client 74.7.244.33:57572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.revelinfear.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxYbOcL08BTTQixEnpbpgAADDI"]
[Thu Sep 17 15:15:24.393213 2026] [security2:error] [pid 971102:tid 971250] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxYbOcL08BTTQixEnpbtAAAABA"]
[Thu Sep 17 15:15:24.403459 2026] [autoindex:error] [pid 971102:tid 971262] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:24.403967 2026] [security2:error] [pid 971102:tid 971262] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/rest-api/"] [unique_id "aqxYbOcL08BTTQixEnpbswAAABw"]
[Thu Sep 17 15:15:24.486172 2026] [security2:error] [pid 971102:tid 971293] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxYbOcL08BTTQixEnpbtQAAADs"]
[Thu Sep 17 15:15:24.557195 2026] [security2:error] [pid 971102:tid 971337] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYbOcL08BTTQixEnpbtgAAAGc"]
[Thu Sep 17 15:15:24.579220 2026] [security2:error] [pid 971102:tid 971349] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxYbOcL08BTTQixEnpbtwAAAHM"]
[Thu Sep 17 15:15:24.657295 2026] [security2:error] [pid 971102:tid 971343] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxYbOcL08BTTQixEnpbugAAAG0"]
[Thu Sep 17 15:15:24.715376 2026] [autoindex:error] [pid 971102:tid 971253] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:24.715919 2026] [security2:error] [pid 971102:tid 971253] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sitemaps/"] [unique_id "aqxYbOcL08BTTQixEnpbvAAAABM"]
[Thu Sep 17 15:15:24.733390 2026] [security2:error] [pid 971102:tid 971359] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxYbOcL08BTTQixEnpbvQAAAH0"]
[Thu Sep 17 15:15:24.813451 2026] [security2:error] [pid 971102:tid 971330] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxYbOcL08BTTQixEnpbwAAAAGA"]
[Thu Sep 17 15:15:24.839969 2026] [authz_core:error] [pid 971102:tid 971271] [client 172.239.147.162:58545] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:15:24.864761 2026] [security2:error] [pid 971102:tid 971247] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYbOcL08BTTQixEnpbwQAAAA0"]
[Thu Sep 17 15:15:24.917054 2026] [security2:error] [pid 971102:tid 971239] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxYbOcL08BTTQixEnpbwgAAAAU"]
[Thu Sep 17 15:15:24.991005 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxYbOcL08BTTQixEnpbxQAAADw"]
[Thu Sep 17 15:15:25.016495 2026] [autoindex:error] [pid 971102:tid 971267] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:25.016950 2026] [security2:error] [pid 971102:tid 971267] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aqxYbecL08BTTQixEnpbxgAAACE"]
[Thu Sep 17 15:15:25.076682 2026] [security2:error] [pid 971102:tid 971309] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxYbecL08BTTQixEnpbxwAAAEs"]
[Thu Sep 17 15:15:25.196574 2026] [security2:error] [pid 971102:tid 971243] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYbecL08BTTQixEnpbzQAAAAk"]
[Thu Sep 17 15:15:25.254676 2026] [security2:error] [pid 971102:tid 971325] [client 191.179.68.110:2358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYbecL08BTTQixEnpbywAAWzo"]
[Thu Sep 17 15:15:25.350183 2026] [autoindex:error] [pid 971102:tid 971251] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:25.350720 2026] [security2:error] [pid 971102:tid 971251] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/style-engine/"] [unique_id "aqxYbecL08BTTQixEnpb0QAAABE"]
[Thu Sep 17 15:15:25.370523 2026] [security2:error] [pid 971102:tid 971242] [client 186.105.232.15:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb0gAAAAg"]
[Thu Sep 17 15:15:25.370627 2026] [security2:error] [pid 971102:tid 971242] [client 186.105.232.15:64343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb0gAAAAg"]
[Thu Sep 17 15:15:25.516016 2026] [security2:error] [pid 971102:tid 971361] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYbecL08BTTQixEnpb0wAAAH8"]
[Thu Sep 17 15:15:25.527680 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxYbecL08BTTQixEnpbzAAAAEY"]
[Thu Sep 17 15:15:25.540317 2026] [security2:error] [pid 971102:tid 971281] [client 185.55.149.49:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb1AAAAC8"]
[Thu Sep 17 15:15:25.540426 2026] [security2:error] [pid 971102:tid 971281] [client 185.55.149.49:64031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYbecL08BTTQixEnpb1AAAAC8"]
[Thu Sep 17 15:15:25.605761 2026] [security2:error] [pid 971102:tid 971305] [client 127.0.0.1:51234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYbecL08BTTQixEnpb1gAAAEc"]
[Thu Sep 17 15:15:25.605793 2026] [security2:error] [pid 971102:tid 971300] [client 74.7.241.190:50212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tth.pdv.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYbecL08BTTQixEnpb1QAAQkQ"]
[Thu Sep 17 15:15:25.634623 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxYbecL08BTTQixEnpb2wAAAHY"]
[Thu Sep 17 15:15:25.702183 2026] [autoindex:error] [pid 971102:tid 971296] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:25.702747 2026] [security2:error] [pid 971102:tid 971296] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/theme-compat/"] [unique_id "aqxYbecL08BTTQixEnpb3gAAAD4"]
[Thu Sep 17 15:15:25.711077 2026] [security2:error] [pid 971102:tid 971255] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxYbecL08BTTQixEnpb3wAAABU"]
[Thu Sep 17 15:15:25.800109 2026] [security2:error] [pid 971102:tid 971286] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxYbecL08BTTQixEnpb4QAAADQ"]
[Thu Sep 17 15:15:25.855077 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxYbecL08BTTQixEnpb4gAAABg"]
[Thu Sep 17 15:15:26.010998 2026] [autoindex:error] [pid 971102:tid 971244] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:26.011511 2026] [security2:error] [pid 971102:tid 971244] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-includes/widgets/"] [unique_id "aqxYbecL08BTTQixEnpb6QAAAAo"]
[Thu Sep 17 15:15:26.039778 2026] [fcgid:warn] [pid 971102:tid 971312] (70014)End of file found: [client 118.26.105.144:45362] mod_fcgid: can't get data from http client
[Thu Sep 17 15:15:26.114993 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYbecL08BTTQixEnpb5gAAAAc"]
[Thu Sep 17 15:15:26.169478 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYbucL08BTTQixEnpb8AAAACs"]
[Thu Sep 17 15:15:26.360011 2026] [autoindex:error] [pid 971102:tid 971351] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:26.360542 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "aqxYbucL08BTTQixEnpb-AAAAHU"]
[Thu Sep 17 15:15:26.503561 2026] [security2:error] [pid 971102:tid 971359] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYbucL08BTTQixEnpb_QAAAH0"]
[Thu Sep 17 15:15:26.601471 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYbucL08BTTQixEnpb_AAAAEE"]
[Thu Sep 17 15:15:26.726899 2026] [security2:error] [pid 971102:tid 971275] [client 34.95.61.66:40046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxYbucL08BTTQixEnpcBwAAACk"]
[Thu Sep 17 15:15:26.735818 2026] [autoindex:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:26.736355 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/css/colors/"] [unique_id "aqxYbucL08BTTQixEnpcBQAAADE"]
[Thu Sep 17 15:15:26.758592 2026] [security2:error] [pid 971102:tid 971291] [client 57.141.14.64:25766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYbucL08BTTQixEnpcAQAAOU4"]
[Thu Sep 17 15:15:26.900400 2026] [security2:error] [pid 971102:tid 971345] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/images/slider/"] [unique_id "aqxYbucL08BTTQixEnpcCQAAAG8"]
[Thu Sep 17 15:15:27.017137 2026] [security2:error] [pid 971102:tid 971267] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxYb-cL08BTTQixEnpcDAAAACE"]
[Thu Sep 17 15:15:27.062994 2026] [security2:error] [pid 971102:tid 971130] [remote 216.73.217.142:43100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYb-cL08BTTQixEnpcDwAABho"]
[Thu Sep 17 15:15:27.088029 2026] [security2:error] [pid 971102:tid 971273] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxYb-cL08BTTQixEnpcEQAAACc"]
[Thu Sep 17 15:15:27.166979 2026] [security2:error] [pid 971102:tid 971348] [client 5.189.145.112:52195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxYb-cL08BTTQixEnpcFAAAAHI"], referer: binance.com
[Thu Sep 17 15:15:27.169250 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxYb-cL08BTTQixEnpcFQAAAF4"]
[Thu Sep 17 15:15:27.203361 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcDQAAAGg"]
[Thu Sep 17 15:15:27.203386 2026] [security2:error] [pid 971102:tid 971338] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcDQAAAGg"]
[Thu Sep 17 15:15:27.244658 2026] [security2:error] [pid 971102:tid 971325] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxYb-cL08BTTQixEnpcFwAAAFs"]
[Thu Sep 17 15:15:27.315862 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxYb-cL08BTTQixEnpcGQAAABQ"]
[Thu Sep 17 15:15:27.355594 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:33034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "aqxYb-cL08BTTQixEnpcGgAAAHc"]
[Thu Sep 17 15:15:27.394410 2026] [security2:error] [pid 971102:tid 971313] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxYb-cL08BTTQixEnpcGwAAAE8"]
[Thu Sep 17 15:15:27.500544 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxYb-cL08BTTQixEnpcHwAAAEY"]
[Thu Sep 17 15:15:27.587271 2026] [security2:error] [pid 971102:tid 971305] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxYb-cL08BTTQixEnpcIgAAAEc"]
[Thu Sep 17 15:15:27.651997 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcIAAAAC8"]
[Thu Sep 17 15:15:27.652018 2026] [security2:error] [pid 971102:tid 971281] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcIAAAAC8"]
[Thu Sep 17 15:15:27.663772 2026] [security2:error] [pid 971102:tid 971314] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxYb-cL08BTTQixEnpcKQAAAFA"]
[Thu Sep 17 15:15:27.751965 2026] [security2:error] [pid 971102:tid 971360] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxYb-cL08BTTQixEnpcKgAAAH4"]
[Thu Sep 17 15:15:27.824514 2026] [security2:error] [pid 971102:tid 971344] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxYb-cL08BTTQixEnpcKwAAAG4"]
[Thu Sep 17 15:15:27.903535 2026] [security2:error] [pid 971102:tid 971308] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxYb-cL08BTTQixEnpcLAAAAEo"]
[Thu Sep 17 15:15:27.951360 2026] [security2:error] [pid 971102:tid 971317] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/sites/default/files/"] [unique_id "aqxYb-cL08BTTQixEnpcLwAAAFM"]
[Thu Sep 17 15:15:27.984529 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxYb-cL08BTTQixEnpcMgAAAE4"]
[Thu Sep 17 15:15:28.070777 2026] [security2:error] [pid 971102:tid 971358] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxYcOcL08BTTQixEnpcNAAAAHw"]
[Thu Sep 17 15:15:28.141037 2026] [security2:error] [pid 971102:tid 971250] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxYcOcL08BTTQixEnpcOQAAABA"]
[Thu Sep 17 15:15:28.235565 2026] [security2:error] [pid 971102:tid 971276] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxYcOcL08BTTQixEnpcPgAAACo"]
[Thu Sep 17 15:15:28.249866 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcNwAAADA"]
[Thu Sep 17 15:15:28.249887 2026] [security2:error] [pid 971102:tid 971282] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcNwAAADA"]
[Thu Sep 17 15:15:28.307366 2026] [security2:error] [pid 971102:tid 971237] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxYb-cL08BTTQixEnpcJAAAAAM"]
[Thu Sep 17 15:15:28.334949 2026] [security2:error] [pid 971102:tid 971257] [client 45.169.98.18:52943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcQwAAABc"]
[Thu Sep 17 15:15:28.335065 2026] [security2:error] [pid 971102:tid 971257] [client 45.169.98.18:52943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcQwAAABc"]
[Thu Sep 17 15:15:28.346883 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxYcOcL08BTTQixEnpcRQAAABM"]
[Thu Sep 17 15:15:28.404083 2026] [security2:error] [pid 971102:tid 971330] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/controller/extension/extension/"] [unique_id "aqxYcOcL08BTTQixEnpcRgAAAGA"]
[Thu Sep 17 15:15:28.425562 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxYcOcL08BTTQixEnpcSQAAAC0"]
[Thu Sep 17 15:15:28.528715 2026] [security2:error] [pid 971102:tid 971247] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxYcOcL08BTTQixEnpcSwAAAA0"]
[Thu Sep 17 15:15:28.601094 2026] [security2:error] [pid 971102:tid 971329] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxYcOcL08BTTQixEnpcTgAAAF8"]
[Thu Sep 17 15:15:28.687550 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxYcOcL08BTTQixEnpcUgAAADw"]
[Thu Sep 17 15:15:28.703206 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcTAAAAFE"]
[Thu Sep 17 15:15:28.703227 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcTAAAAFE"]
[Thu Sep 17 15:15:28.750371 2026] [security2:error] [pid 971102:tid 971262] [client 154.190.208.131:41739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcVAAAABw"]
[Thu Sep 17 15:15:28.754956 2026] [security2:error] [pid 971102:tid 971262] [client 154.190.208.131:41739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcOcL08BTTQixEnpcVAAAABw"]
[Thu Sep 17 15:15:28.801215 2026] [security2:error] [pid 971102:tid 971307] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxYcOcL08BTTQixEnpcVQAAAEk"]
[Thu Sep 17 15:15:28.856263 2026] [security2:error] [pid 971102:tid 971273] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "aqxYcOcL08BTTQixEnpcWAAAACc"]
[Thu Sep 17 15:15:28.876843 2026] [security2:error] [pid 971102:tid 971348] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxYcOcL08BTTQixEnpcWgAAAHI"]
[Thu Sep 17 15:15:28.977512 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxYcOcL08BTTQixEnpcWwAAAF4"]
[Thu Sep 17 15:15:29.058250 2026] [security2:error] [pid 971102:tid 971301] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxYcecL08BTTQixEnpcXQAAAEM"]
[Thu Sep 17 15:15:29.130454 2026] [security2:error] [pid 971102:tid 971285] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxYcecL08BTTQixEnpcYQAAADM"]
[Thu Sep 17 15:15:29.172602 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcXAAAAFo"]
[Thu Sep 17 15:15:29.172628 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcOcL08BTTQixEnpcXAAAAFo"]
[Thu Sep 17 15:15:29.215844 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxYcecL08BTTQixEnpcYwAAAHc"]
[Thu Sep 17 15:15:29.320645 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxYcecL08BTTQixEnpcZAAAAEY"]
[Thu Sep 17 15:15:29.327791 2026] [security2:error] [pid 971102:tid 971309] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/components/"] [unique_id "aqxYcecL08BTTQixEnpcZQAAAEs"]
[Thu Sep 17 15:15:29.397940 2026] [security2:error] [pid 971102:tid 971255] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxYcecL08BTTQixEnpcaAAAABU"]
[Thu Sep 17 15:15:29.491389 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxYcecL08BTTQixEnpcagAAAHY"]
[Thu Sep 17 15:15:29.557139 2026] [security2:error] [pid 971102:tid 971289] [client 114.198.138.124:63339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcecL08BTTQixEnpcawAAADc"]
[Thu Sep 17 15:15:29.557240 2026] [security2:error] [pid 971102:tid 971289] [client 114.198.138.124:63339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYcecL08BTTQixEnpcawAAADc"]
[Thu Sep 17 15:15:29.573631 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxYcecL08BTTQixEnpcbAAAAAE"]
[Thu Sep 17 15:15:29.623179 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpcaQAAAGI"]
[Thu Sep 17 15:15:29.623197 2026] [security2:error] [pid 971102:tid 971332] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpcaQAAAGI"]
[Thu Sep 17 15:15:29.666531 2026] [security2:error] [pid 971102:tid 971344] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxYcecL08BTTQixEnpccQAAAG4"]
[Thu Sep 17 15:15:29.734903 2026] [security2:error] [pid 971102:tid 971308] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxYcecL08BTTQixEnpccwAAAEo"]
[Thu Sep 17 15:15:29.782270 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/admin/uploads/images/"] [unique_id "aqxYcecL08BTTQixEnpcdQAAAEU"]
[Thu Sep 17 15:15:29.824892 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxYcecL08BTTQixEnpcdgAAAAo"]
[Thu Sep 17 15:15:29.900079 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxYcecL08BTTQixEnpceAAAAFQ"]
[Thu Sep 17 15:15:29.991998 2026] [security2:error] [pid 971102:tid 971270] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxYcecL08BTTQixEnpcfQAAACQ"]
[Thu Sep 17 15:15:30.073785 2026] [security2:error] [pid 971102:tid 971354] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxYcucL08BTTQixEnpcfwAAAHg"]
[Thu Sep 17 15:15:30.078560 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpceQAAACs"]
[Thu Sep 17 15:15:30.078579 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcecL08BTTQixEnpceQAAACs"]
[Thu Sep 17 15:15:30.169478 2026] [security2:error] [pid 971102:tid 971319] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxYcucL08BTTQixEnpcgwAAAFU"]
[Thu Sep 17 15:15:30.222762 2026] [security2:error] [pid 971102:tid 971246] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "aqxYcucL08BTTQixEnpchgAAAAw"]
[Thu Sep 17 15:15:30.231035 2026] [security2:error] [pid 971102:tid 971260] [client 172.239.147.162:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-login.php"] [unique_id "aqxYcucL08BTTQixEnpchQAAABo"], referer: binance.com
[Thu Sep 17 15:15:30.258763 2026] [security2:error] [pid 971102:tid 971261] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxYcucL08BTTQixEnpcnAAAABs"]
[Thu Sep 17 15:15:30.348777 2026] [security2:error] [pid 971102:tid 971342] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxYcucL08BTTQixEnpcngAAAGw"]
[Thu Sep 17 15:15:30.424167 2026] [security2:error] [pid 971102:tid 971337] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxYcucL08BTTQixEnpcoAAAAGc"]
[Thu Sep 17 15:15:30.498248 2026] [security2:error] [pid 971102:tid 971257] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxYcucL08BTTQixEnpcoQAAABc"]
[Thu Sep 17 15:15:30.498720 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcnwAAAAM"]
[Thu Sep 17 15:15:30.498746 2026] [security2:error] [pid 971102:tid 971237] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcnwAAAAM"]
[Thu Sep 17 15:15:30.595066 2026] [security2:error] [pid 971102:tid 971334] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxYcucL08BTTQixEnpcogAAAGQ"]
[Thu Sep 17 15:15:30.641734 2026] [security2:error] [pid 971102:tid 971326] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/fonts/"] [unique_id "aqxYcucL08BTTQixEnpcpgAAAFw"]
[Thu Sep 17 15:15:30.682786 2026] [security2:error] [pid 971102:tid 971320] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxYcucL08BTTQixEnpcqAAAAFY"]
[Thu Sep 17 15:15:30.766939 2026] [security2:error] [pid 971102:tid 971245] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxYcucL08BTTQixEnpcqQAAAAs"]
[Thu Sep 17 15:15:30.838979 2026] [security2:error] [pid 971102:tid 971356] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxYcucL08BTTQixEnpcqwAAAHo"]
[Thu Sep 17 15:15:30.915531 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcqgAAADE"]
[Thu Sep 17 15:15:30.915557 2026] [security2:error] [pid 971102:tid 971283] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYcucL08BTTQixEnpcqgAAADE"]
[Thu Sep 17 15:15:30.928356 2026] [security2:error] [pid 971102:tid 971264] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxYcucL08BTTQixEnpcrAAAAB4"]
[Thu Sep 17 15:15:31.029040 2026] [security2:error] [pid 971102:tid 971341] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxYc-cL08BTTQixEnpcrQAAAGs"]
[Thu Sep 17 15:15:31.087149 2026] [security2:error] [pid 971102:tid 971307] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "aqxYc-cL08BTTQixEnpcsQAAAEk"]
[Thu Sep 17 15:15:31.166937 2026] [security2:error] [pid 971102:tid 971274] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxYc-cL08BTTQixEnpctgAAACg"]
[Thu Sep 17 15:15:31.241778 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxYc-cL08BTTQixEnpcuQAAAF4"]
[Thu Sep 17 15:15:31.330784 2026] [security2:error] [pid 971102:tid 971285] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxYc-cL08BTTQixEnpcugAAADM"]
[Thu Sep 17 15:15:31.388516 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpcuAAAAHI"]
[Thu Sep 17 15:15:31.388539 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpcuAAAAHI"]
[Thu Sep 17 15:15:31.425780 2026] [security2:error] [pid 971102:tid 971238] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxYc-cL08BTTQixEnpcvAAAAAQ"]
[Thu Sep 17 15:15:31.497387 2026] [security2:error] [pid 971102:tid 971240] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxYc-cL08BTTQixEnpcvwAAAAY"]
[Thu Sep 17 15:15:31.534415 2026] [security2:error] [pid 971102:tid 971304] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "aqxYc-cL08BTTQixEnpcwgAAAEY"]
[Thu Sep 17 15:15:31.596925 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxYc-cL08BTTQixEnpcywAAABQ"]
[Thu Sep 17 15:15:31.676834 2026] [security2:error] [pid 971102:tid 971335] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxYc-cL08BTTQixEnpc0AAAAGU"]
[Thu Sep 17 15:15:31.752419 2026] [security2:error] [pid 971102:tid 971352] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxYc-cL08BTTQixEnpc1AAAAHY"]
[Thu Sep 17 15:15:31.815873 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpczwAAAEc"]
[Thu Sep 17 15:15:31.815896 2026] [security2:error] [pid 971102:tid 971305] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYc-cL08BTTQixEnpczwAAAEc"]
[Thu Sep 17 15:15:31.827577 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxYc-cL08BTTQixEnpc1gAAAAE"]
[Thu Sep 17 15:15:31.913991 2026] [security2:error] [pid 971102:tid 971332] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxYc-cL08BTTQixEnpc2AAAAGI"]
[Thu Sep 17 15:15:31.966724 2026] [security2:error] [pid 971102:tid 971268] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wordpress/"] [unique_id "aqxYc-cL08BTTQixEnpc2QAAACI"]
[Thu Sep 17 15:15:31.988193 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxYc-cL08BTTQixEnpc2wAAAAo"]
[Thu Sep 17 15:15:32.069917 2026] [security2:error] [pid 971102:tid 971318] [client 34.95.61.66:52418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxYdOcL08BTTQixEnpc3AAAAFQ"]
[Thu Sep 17 15:15:32.074766 2026] [security2:error] [pid 971102:tid 971317] [client 172.239.147.162:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-login.php"] [unique_id "aqxYdOcL08BTTQixEnpc3QAAAFM"], referer: binance.com
[Thu Sep 17 15:15:32.165423 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:52418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxYdOcL08BTTQixEnpc4wAAABg"]
[Thu Sep 17 15:15:32.244625 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdOcL08BTTQixEnpc3gAAAAc"]
[Thu Sep 17 15:15:32.244647 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdOcL08BTTQixEnpc3gAAAAc"]
[Thu Sep 17 15:15:32.395397 2026] [security2:error] [pid 971102:tid 971336] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/images/"] [unique_id "aqxYdOcL08BTTQixEnpc6AAAAGY"]
[Thu Sep 17 15:15:32.412273 2026] [security2:error] [pid 971102:tid 971357] [client 34.95.61.66:43686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/info.php"] [unique_id "aqxYdOcL08BTTQixEnpc6QAAAHs"]
[Thu Sep 17 15:15:32.421206 2026] [security2:error] [pid 971102:tid 971339] [client 172.239.147.162:59851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-login.php"] [unique_id "aqxYdOcL08BTTQixEnpc6gAAAGk"], referer: binance.com
[Thu Sep 17 15:15:32.598183 2026] [autoindex:error] [pid 971102:tid 971287] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:32.598742 2026] [security2:error] [pid 971102:tid 971287] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/images/"] [unique_id "aqxYdOcL08BTTQixEnpc7AAAADU"]
[Thu Sep 17 15:15:32.703676 2026] [security2:error] [pid 971102:tid 971343] [client 34.95.61.66:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/php.php"] [unique_id "aqxYdOcL08BTTQixEnpc8gAAAG0"]
[Thu Sep 17 15:15:32.743756 2026] [security2:error] [pid 971102:tid 971320] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYdOcL08BTTQixEnpc8wAAAFY"]
[Thu Sep 17 15:15:32.906961 2026] [security2:error] [pid 971102:tid 971284] [client 74.7.241.145:46600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.popcup.com"] [uri "/robots.txt"] [unique_id "aqxYdOcL08BTTQixEnpc-AAAMlM"]
[Thu Sep 17 15:15:32.907154 2026] [autoindex:error] [pid 971102:tid 971242] [client 85.204.70.96:44200] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:32.907582 2026] [security2:error] [pid 971102:tid 971242] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "aqxYdOcL08BTTQixEnpc9wAAAAg"]
[Thu Sep 17 15:15:32.972068 2026] [security2:error] [pid 971102:tid 971299] [client 34.95.61.66:43702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/i.php"] [unique_id "aqxYdOcL08BTTQixEnpc-gAAAEE"]
[Thu Sep 17 15:15:32.990893 2026] [security2:error] [pid 971102:tid 971237] [client 156.192.234.52:60929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYdOcL08BTTQixEnpc-wAAAAM"]
[Thu Sep 17 15:15:32.992202 2026] [security2:error] [pid 971102:tid 971237] [client 156.192.234.52:60929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYdOcL08BTTQixEnpc-wAAAAM"]
[Thu Sep 17 15:15:33.056452 2026] [security2:error] [pid 971102:tid 971315] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "aqxYdecL08BTTQixEnpdAQAAAFE"]
[Thu Sep 17 15:15:33.210945 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "aqxYdecL08BTTQixEnpdCAAAAFo"]
[Thu Sep 17 15:15:33.229825 2026] [security2:error] [pid 971102:tid 971328] [client 34.95.61.66:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxYdecL08BTTQixEnpdCQAAAF4"]
[Thu Sep 17 15:15:33.356035 2026] [security2:error] [pid 971102:tid 971238] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/js/"] [unique_id "aqxYdecL08BTTQixEnpdCwAAAAQ"]
[Thu Sep 17 15:15:33.444370 2026] [core:error] [pid 971102:tid 971300] [client 199.19.226.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:33.444387 2026] [core:error] [pid 971102:tid 971300] [client 199.19.226.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:33.497543 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.61.66:43716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxYdecL08BTTQixEnpdFAAAAHA"]
[Thu Sep 17 15:15:33.635010 2026] [security2:error] [pid 971102:tid 971290] [client 66.249.66.76:63652] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.freemarkjordan.com"] [uri "/robots.txt"] [unique_id "aqxYdecL08BTTQixEnpdGgAAADg"]
[Thu Sep 17 15:15:33.643558 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdEwAAAAE"]
[Thu Sep 17 15:15:33.643583 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdEwAAAAE"]
[Thu Sep 17 15:15:33.770440 2026] [security2:error] [pid 971102:tid 971303] [client 34.95.61.66:43724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/test.php"] [unique_id "aqxYdecL08BTTQixEnpdHQAAAEU"]
[Thu Sep 17 15:15:33.787219 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "aqxYdecL08BTTQixEnpdHgAAAE4"]
[Thu Sep 17 15:15:34.060099 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdIAAAABg"]
[Thu Sep 17 15:15:34.060121 2026] [security2:error] [pid 971102:tid 971258] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYdecL08BTTQixEnpdIAAAABg"]
[Thu Sep 17 15:15:34.206283 2026] [security2:error] [pid 971102:tid 971257] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "aqxYducL08BTTQixEnpdMgAAABc"]
[Thu Sep 17 15:15:34.244768 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdJAAAAAc"]
[Thu Sep 17 15:15:34.387864 2026] [security2:error] [pid 971102:tid 971260] [client 74.7.244.47:41974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcalendars.saherihbaisha.com"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxYducL08BTTQixEnpdNwAAABo"]
[Thu Sep 17 15:15:34.409185 2026] [security2:error] [pid 971102:tid 971323] [client 34.95.61.66:43740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/p.php"] [unique_id "aqxYducL08BTTQixEnpdOAAAAFk"]
[Thu Sep 17 15:15:34.501873 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdNQAAAC4"]
[Thu Sep 17 15:15:34.501899 2026] [security2:error] [pid 971102:tid 971280] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdNQAAAC4"]
[Thu Sep 17 15:15:34.646738 2026] [security2:error] [pid 971102:tid 971245] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/meta/"] [unique_id "aqxYducL08BTTQixEnpdTgAAAAs"]
[Thu Sep 17 15:15:34.683623 2026] [security2:error] [pid 971102:tid 971324] [client 172.239.147.162:52002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-login.php"] [unique_id "aqxYducL08BTTQixEnpdUQAAAFo"], referer: binance.com
[Thu Sep 17 15:15:34.684348 2026] [security2:error] [pid 971102:tid 971315] [client 34.95.61.66:43748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxYducL08BTTQixEnpdUwAAAFE"]
[Thu Sep 17 15:15:34.926456 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:44200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdYQAAAFs"]
[Thu Sep 17 15:15:34.926479 2026] [security2:error] [pid 971102:tid 971325] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdYQAAAFs"]
[Thu Sep 17 15:15:34.986292 2026] [security2:error] [pid 971102:tid 971321] [client 34.95.61.66:43754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxYducL08BTTQixEnpdYgAAAFc"]
[Thu Sep 17 15:15:35.074246 2026] [security2:error] [pid 971102:tid 971264] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/network/"] [unique_id "aqxYd-cL08BTTQixEnpdaQAAAB4"]
[Thu Sep 17 15:15:35.242891 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.61.66:43768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxYd-cL08BTTQixEnpdbgAAADw"]
[Thu Sep 17 15:15:35.359802 2026] [security2:error] [pid 971102:tid 971251] [client 5.189.145.112:65063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxYd-cL08BTTQixEnpdcAAAABE"], referer: binance.com
[Thu Sep 17 15:15:35.381267 2026] [security2:error] [pid 971102:tid 971254] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/network/index.php"] [unique_id "aqxYd-cL08BTTQixEnpdbAAAABQ"]
[Thu Sep 17 15:15:35.495133 2026] [core:error] [pid 971102:tid 971346] [client 177.136.231.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:35.495151 2026] [core:error] [pid 971102:tid 971346] [client 177.136.231.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:35.512302 2026] [security2:error] [pid 971102:tid 971282] [client 34.95.61.66:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxYd-cL08BTTQixEnpdegAAADA"]
[Thu Sep 17 15:15:35.522053 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYd-cL08BTTQixEnpdewAAAFA"]
[Thu Sep 17 15:15:35.522127 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:44200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYd-cL08BTTQixEnpdewAAAFA"]
[Thu Sep 17 15:15:35.664204 2026] [security2:error] [pid 971102:tid 971312] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/user/"] [unique_id "aqxYd-cL08BTTQixEnpdgAAAAE4"]
[Thu Sep 17 15:15:35.804714 2026] [security2:error] [pid 971102:tid 971281] [client 34.95.61.66:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxYd-cL08BTTQixEnpdgQAAAC8"]
[Thu Sep 17 15:15:35.830956 2026] [security2:error] [pid 971102:tid 971307] [client 65.109.83.100:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nickdunne.com"] [uri "/index.php"] [unique_id "aqxYducL08BTTQixEnpdTQAASWM"]
[Thu Sep 17 15:15:35.862447 2026] [security2:error] [pid 971102:tid 971255] [client 112.86.225.42:46448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rocketboxcreative.com"] [uri "/"] [unique_id "aqxYd-cL08BTTQixEnpdgwAAABU"]
[Thu Sep 17 15:15:35.862561 2026] [security2:error] [pid 971102:tid 971255] [client 112.86.225.42:46448] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.rocketboxcreative.com"] [uri "/"] [unique_id "aqxYd-cL08BTTQixEnpdgwAAABU"]
[Thu Sep 17 15:15:36.160797 2026] [security2:error] [pid 971102:tid 971241] [client 34.95.61.66:43802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYeOcL08BTTQixEnpdmQAAAAc"]
[Thu Sep 17 15:15:36.217659 2026] [security2:error] [pid 971102:tid 971257] [client 185.55.149.49:64692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdnwAAABc"]
[Thu Sep 17 15:15:36.217827 2026] [security2:error] [pid 971102:tid 971257] [client 185.55.149.49:64692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdnwAAABc"]
[Thu Sep 17 15:15:36.254417 2026] [security2:error] [pid 971102:tid 971351] [client 85.204.70.96:51750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/user/index.php"] [unique_id "aqxYeOcL08BTTQixEnpdlAAAAHU"]
[Thu Sep 17 15:15:36.390746 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:51750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeOcL08BTTQixEnpdoQAAACk"]
[Thu Sep 17 15:15:36.390853 2026] [security2:error] [pid 971102:tid 971275] [client 85.204.70.96:51750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeOcL08BTTQixEnpdoQAAACk"]
[Thu Sep 17 15:15:36.412146 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxYeOcL08BTTQixEnpdogAAABM"]
[Thu Sep 17 15:15:36.538381 2026] [security2:error] [pid 971102:tid 971331] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/"] [unique_id "aqxYeOcL08BTTQixEnpdpAAAAGE"]
[Thu Sep 17 15:15:36.694712 2026] [security2:error] [pid 971102:tid 971234] [client 186.105.232.15:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdpwAAAAA"]
[Thu Sep 17 15:15:36.697350 2026] [security2:error] [pid 971102:tid 971234] [client 186.105.232.15:64943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeOcL08BTTQixEnpdpwAAAAA"]
[Thu Sep 17 15:15:36.943448 2026] [security2:error] [pid 971102:tid 971334] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYeOcL08BTTQixEnpdqwAAAGQ"]
[Thu Sep 17 15:15:36.993909 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env"] [unique_id "aqxYeOcL08BTTQixEnpdsgAAb20"]
[Thu Sep 17 15:15:37.000746 2026] [security2:error] [pid 971102:tid 971341] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/index.php"] [unique_id "aqxYeOcL08BTTQixEnpdrgAAAGs"]
[Thu Sep 17 15:15:37.003031 2026] [security2:error] [pid 971102:tid 971146] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.old"] [unique_id "aqxYeOcL08BTTQixEnpdtwAAbyo"]
[Thu Sep 17 15:15:37.005512 2026] [security2:error] [pid 971102:tid 971207] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.backup"] [unique_id "aqxYeOcL08BTTQixEnpduwAAb2Y"]
[Thu Sep 17 15:15:37.005674 2026] [security2:error] [pid 971102:tid 971135] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.bak"] [unique_id "aqxYeOcL08BTTQixEnpdvAAAbx8"]
[Thu Sep 17 15:15:37.037994 2026] [security2:error] [pid 971102:tid 971359] [client 104.28.198.244:22839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeecL08BTTQixEnpdvwAAAH0"]
[Thu Sep 17 15:15:37.038129 2026] [security2:error] [pid 971102:tid 971359] [client 104.28.198.244:22839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeecL08BTTQixEnpdvwAAAH0"]
[Thu Sep 17 15:15:37.158990 2026] [security2:error] [pid 971102:tid 971324] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/"] [unique_id "aqxYeecL08BTTQixEnpdxQAAAFo"]
[Thu Sep 17 15:15:37.186622 2026] [security2:error] [pid 971102:tid 971306] [client 34.95.61.66:43834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxYeecL08BTTQixEnpdxgAAAEg"]
[Thu Sep 17 15:15:37.318776 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxYeecL08BTTQixEnpd0QAAAHc"]
[Thu Sep 17 15:15:37.364472 2026] [security2:error] [pid 971102:tid 971196] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env~"] [unique_id "aqxYeecL08BTTQixEnpd1gAAW1s"]
[Thu Sep 17 15:15:37.374691 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/.env.php"] [unique_id "aqxYeecL08BTTQixEnpd1AAAW0E"]
[Thu Sep 17 15:15:37.449327 2026] [security2:error] [pid 971102:tid 971321] [client 34.95.61.66:43840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxYeecL08BTTQixEnpd2QAAAFc"]
[Thu Sep 17 15:15:37.463386 2026] [security2:error] [pid 971102:tid 971294] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/"] [unique_id "aqxYeecL08BTTQixEnpd2gAAADw"]
[Thu Sep 17 15:15:37.514913 2026] [security2:error] [pid 971102:tid 971243] [client 112.196.8.34:61472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYeecL08BTTQixEnpd2AAACSg"]
[Thu Sep 17 15:15:37.531398 2026] [security2:error] [pid 971102:tid 971140] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.env.swp"] [unique_id "aqxYeecL08BTTQixEnpd2wAANiQ"]
[Thu Sep 17 15:15:37.541608 2026] [security2:error] [pid 971102:tid 971200] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/api/.env"] [unique_id "aqxYeecL08BTTQixEnpd4QAAFF8"]
[Thu Sep 17 15:15:37.618493 2026] [security2:error] [pid 971102:tid 971295] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/themes/index.php"] [unique_id "aqxYeecL08BTTQixEnpd4gAAAD0"]
[Thu Sep 17 15:15:37.716935 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/backend/.env"] [unique_id "aqxYeecL08BTTQixEnpd6AAAYnk"]
[Thu Sep 17 15:15:37.716945 2026] [security2:error] [pid 971102:tid 971188] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/app/.env"] [unique_id "aqxYeecL08BTTQixEnpd5gAAYlM"]
[Thu Sep 17 15:15:37.719445 2026] [security2:error] [pid 971102:tid 971350] [client 34.95.61.66:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxYeecL08BTTQixEnpd6gAAAHQ"]
[Thu Sep 17 15:15:37.724565 2026] [security2:error] [pid 971102:tid 971109] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/server/.env"] [unique_id "aqxYeecL08BTTQixEnpd7AAAMAU"]
[Thu Sep 17 15:15:37.724627 2026] [security2:error] [pid 971102:tid 971138] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/web/.env"] [unique_id "aqxYeecL08BTTQixEnpd7wAAMCI"]
[Thu Sep 17 15:15:37.724678 2026] [security2:error] [pid 971102:tid 971105] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/frontend/.env"] [unique_id "aqxYeecL08BTTQixEnpd8QAAMAE"]
[Thu Sep 17 15:15:37.724730 2026] [security2:error] [pid 971102:tid 971218] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/client/.env"] [unique_id "aqxYeecL08BTTQixEnpd8AAAMHE"]
[Thu Sep 17 15:15:37.724732 2026] [security2:error] [pid 971102:tid 971117] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/config/.env"] [unique_id "aqxYeecL08BTTQixEnpd7QAAMA0"]
[Thu Sep 17 15:15:37.724767 2026] [security2:error] [pid 971102:tid 971150] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/src/.env"] [unique_id "aqxYeecL08BTTQixEnpd7gAAMC4"]
[Thu Sep 17 15:15:37.724885 2026] [security2:error] [pid 971102:tid 971166] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/public/.env"] [unique_id "aqxYeecL08BTTQixEnpd8gAAMD4"]
[Thu Sep 17 15:15:37.728408 2026] [security2:error] [pid 971102:tid 971170] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/var/www/.env"] [unique_id "aqxYeecL08BTTQixEnpd8wAAMEI"]
[Thu Sep 17 15:15:37.728456 2026] [security2:error] [pid 971102:tid 971158] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/var/www/html/.env"] [unique_id "aqxYeecL08BTTQixEnpd9AAAMDY"]
[Thu Sep 17 15:15:37.764108 2026] [security2:error] [pid 971102:tid 971314] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYeecL08BTTQixEnpd9QAAAFA"]
[Thu Sep 17 15:15:37.902977 2026] [security2:error] [pid 971102:tid 971171] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/laravel/.env"] [unique_id "aqxYeecL08BTTQixEnpd-QAAH0M"]
[Thu Sep 17 15:15:37.902995 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/application/.env"] [unique_id "aqxYeecL08BTTQixEnpd-AAAH1w"]
[Thu Sep 17 15:15:37.907452 2026] [security2:error] [pid 971102:tid 971151] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/apps/.env"] [unique_id "aqxYeecL08BTTQixEnpd-gAAeS8"]
[Thu Sep 17 15:15:37.907506 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/back/.env"] [unique_id "aqxYeecL08BTTQixEnpd-wAAeUg"]
[Thu Sep 17 15:15:37.912790 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/backup/.env"] [unique_id "aqxYeecL08BTTQixEnpd_AAAIlE"]
[Thu Sep 17 15:15:37.913137 2026] [security2:error] [pid 971102:tid 971175] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/cms/.env"] [unique_id "aqxYeecL08BTTQixEnpd_QAAIkc"]
[Thu Sep 17 15:15:37.913201 2026] [security2:error] [pid 971102:tid 971156] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/dev/.env"] [unique_id "aqxYeecL08BTTQixEnpd_gAAIjQ"]
[Thu Sep 17 15:15:37.913221 2026] [security2:error] [pid 971102:tid 971139] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/staging/.env"] [unique_id "aqxYeecL08BTTQixEnpeAQAAIiM"]
[Thu Sep 17 15:15:37.913272 2026] [security2:error] [pid 971102:tid 971189] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/production/.env"] [unique_id "aqxYeecL08BTTQixEnpeAAAAIlQ"]
[Thu Sep 17 15:15:37.913282 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/prod/.env"] [unique_id "aqxYeecL08BTTQixEnpd_wAAIks"]
[Thu Sep 17 15:15:37.913326 2026] [security2:error] [pid 971102:tid 971203] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/new/.env"] [unique_id "aqxYeecL08BTTQixEnpeAwAAImI"]
[Thu Sep 17 15:15:37.913358 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/test/.env"] [unique_id "aqxYeecL08BTTQixEnpeAgAAIjk"]
[Thu Sep 17 15:15:37.913358 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/old/.env"] [unique_id "aqxYeecL08BTTQixEnpeBAAAIiY"]
[Thu Sep 17 15:15:37.913895 2026] [security2:error] [pid 971102:tid 971223] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/api-backend/.env"] [unique_id "aqxYeecL08BTTQixEnpeBgAAInY"]
[Thu Sep 17 15:15:37.914008 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/node-api/.env"] [unique_id "aqxYeecL08BTTQixEnpeBQAAIgg"]
[Thu Sep 17 15:15:37.914843 2026] [security2:error] [pid 971102:tid 971154] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/admin-app/.env"] [unique_id "aqxYeecL08BTTQixEnpeBwAAIjI"]
[Thu Sep 17 15:15:37.961481 2026] [autoindex:error] [pid 971102:tid 971292] [client 85.204.70.96:51754] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:37.961979 2026] [security2:error] [pid 971102:tid 971292] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/includes/"] [unique_id "aqxYeecL08BTTQixEnpeCAAAADo"]
[Thu Sep 17 15:15:37.994793 2026] [security2:error] [pid 971102:tid 971244] [client 34.95.61.66:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxYeecL08BTTQixEnpeCQAAAAo"]
[Thu Sep 17 15:15:38.090831 2026] [security2:error] [pid 971102:tid 971111] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/public_html/.env"] [unique_id "aqxYeucL08BTTQixEnpeDgAASQc"]
[Thu Sep 17 15:15:38.102218 2026] [security2:error] [pid 971102:tid 971143] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/aws/.env"] [unique_id "aqxYeucL08BTTQixEnpeFAAASSc"]
[Thu Sep 17 15:15:38.102269 2026] [security2:error] [pid 971102:tid 971202] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/stripe/.env"] [unique_id "aqxYeucL08BTTQixEnpeFQAASWE"]
[Thu Sep 17 15:15:38.102292 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/server/backend/.env"] [unique_id "aqxYeucL08BTTQixEnpeEQAASWw"]
[Thu Sep 17 15:15:38.102309 2026] [security2:error] [pid 971102:tid 971162] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/server/api/.env"] [unique_id "aqxYeucL08BTTQixEnpeDwAASTo"]
[Thu Sep 17 15:15:38.102315 2026] [security2:error] [pid 971102:tid 971198] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/current/.env"] [unique_id "aqxYeucL08BTTQixEnpeEAAASV0"]
[Thu Sep 17 15:15:38.102347 2026] [security2:error] [pid 971102:tid 971155] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.docker/.env"] [unique_id "aqxYeucL08BTTQixEnpeEgAASTM"]
[Thu Sep 17 15:15:38.102368 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxYeucL08BTTQixEnpeEwAASRU"]
[Thu Sep 17 15:15:38.102424 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.aws/.env"] [unique_id "aqxYeucL08BTTQixEnpeFwAASWk"]
[Thu Sep 17 15:15:38.102434 2026] [security2:error] [pid 971102:tid 971127] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/v2/.env"] [unique_id "aqxYeucL08BTTQixEnpeGgAASRc"]
[Thu Sep 17 15:15:38.102442 2026] [security2:error] [pid 971102:tid 971215] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/v1/.env"] [unique_id "aqxYeucL08BTTQixEnpeGQAASW4"]
[Thu Sep 17 15:15:38.106418 2026] [security2:error] [pid 971102:tid 971177] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/v3/.env"] [unique_id "aqxYeucL08BTTQixEnpeGwAASUk"]
[Thu Sep 17 15:15:38.106516 2026] [security2:error] [pid 971102:tid 971148] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/media/.env"] [unique_id "aqxYeucL08BTTQixEnpeHAAASSw"]
[Thu Sep 17 15:15:38.111651 2026] [security2:error] [pid 971102:tid 971303] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/"] [unique_id "aqxYeucL08BTTQixEnpeHQAAAEU"]
[Thu Sep 17 15:15:38.144398 2026] [security2:error] [pid 971102:tid 971229] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/administrator/.env"] [unique_id "aqxYeucL08BTTQixEnpeDQAASXw"]
[Thu Sep 17 15:15:38.238125 2026] [security2:error] [pid 971102:tid 971356] [client 43.165.125.66:36070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeIgAAAHo"]
[Thu Sep 17 15:15:38.251021 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.61.66:43858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxYeucL08BTTQixEnpeJQAAABg"]
[Thu Sep 17 15:15:38.258594 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeGAAASWo"]
[Thu Sep 17 15:15:38.258768 2026] [security2:error] [pid 971102:tid 971307] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeFgAASUQ"]
[Thu Sep 17 15:15:38.285602 2026] [security2:error] [pid 971102:tid 971206] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.git/config.bak"] [unique_id "aqxYeucL08BTTQixEnpeMwAAbWU"]
[Thu Sep 17 15:15:38.419187 2026] [security2:error] [pid 971102:tid 971241] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "savemoneyspendwisely.com"] [uri "/wp-admin/index.php"] [unique_id "aqxYeucL08BTTQixEnpeJgAAAAc"]
[Thu Sep 17 15:15:38.460674 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeNgAAaRM"]
[Thu Sep 17 15:15:38.473691 2026] [security2:error] [pid 971102:tid 971181] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxYeucL08BTTQixEnpePwAAaU0"]
[Thu Sep 17 15:15:38.477968 2026] [security2:error] [pid 971102:tid 971119] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/id_rsa"] [unique_id "aqxYeucL08BTTQixEnpeRgAAaQ8"]
[Thu Sep 17 15:15:38.477971 2026] [security2:error] [pid 971102:tid 971104] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxYeucL08BTTQixEnpeRAAAaQA"]
[Thu Sep 17 15:15:38.565389 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeucL08BTTQixEnpeSQAAACs"]
[Thu Sep 17 15:15:38.565575 2026] [security2:error] [pid 971102:tid 971277] [client 85.204.70.96:51754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "savemoneyspendwisely.com"] [uri "/wp-login.php"] [unique_id "aqxYeucL08BTTQixEnpeSQAAACs"]
[Thu Sep 17 15:15:38.575746 2026] [security2:error] [pid 971102:tid 971246] [client 34.95.61.66:43868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxYeucL08BTTQixEnpeSgAAAAw"]
[Thu Sep 17 15:15:38.605493 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpePAAAaWc"]
[Thu Sep 17 15:15:38.630807 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeRwAAaXU"]
[Thu Sep 17 15:15:38.633626 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeOgAAaS0"]
[Thu Sep 17 15:15:38.642805 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeQAAAaRs"]
[Thu Sep 17 15:15:38.648325 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeSAAAaQ4"]
[Thu Sep 17 15:15:38.656457 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeQwAAaWA"]
[Thu Sep 17 15:15:38.714283 2026] [security2:error] [pid 971102:tid 971334] [client 85.204.70.96:60606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "savemoneyspendwisely.com"] [uri "/wp-content/upgrade/"] [unique_id "aqxYeucL08BTTQixEnpeWwAAAGQ"]
[Thu Sep 17 15:15:38.826841 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeucL08BTTQixEnpeYQAAAAg"]
[Thu Sep 17 15:15:38.827355 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:53509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYeucL08BTTQixEnpeYQAAAAg"]
[Thu Sep 17 15:15:38.916481 2026] [security2:error] [pid 971102:tid 971269] [client 43.173.173.85:47262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.tab-funkenwerk.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxYeucL08BTTQixEnpeZwAAACM"], referer: https://www.tab-funkenwerk.org/
[Thu Sep 17 15:15:39.062566 2026] [security2:error] [pid 971102:tid 971324] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeaAAAAFo"]
[Thu Sep 17 15:15:39.154241 2026] [autoindex:error] [pid 971102:tid 971353] [client 85.204.70.96:51766] AH01276: Cannot serve directory /home2/savemor0/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:15:39.154918 2026] [security2:error] [pid 971102:tid 971353] [client 85.204.70.96:51766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "savemoneyspendwisely.com"] [uri "/cgi-sys/403.html"] [unique_id "aqxYe-cL08BTTQixEnpeagAAAHc"]
[Thu Sep 17 15:15:39.280576 2026] [security2:error] [pid 971102:tid 971328] [client 114.198.138.124:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebgAAAF4"]
[Thu Sep 17 15:15:39.281843 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeTQAAaRQ"]
[Thu Sep 17 15:15:39.283815 2026] [security2:error] [pid 971102:tid 971328] [client 114.198.138.124:52664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebgAAAF4"]
[Thu Sep 17 15:15:39.284581 2026] [security2:error] [pid 971102:tid 971280] [client 154.190.208.131:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebwAAAC4"]
[Thu Sep 17 15:15:39.284740 2026] [security2:error] [pid 971102:tid 971280] [client 154.190.208.131:42452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYe-cL08BTTQixEnpebwAAAC4"]
[Thu Sep 17 15:15:39.298201 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeUAAAaUw"]
[Thu Sep 17 15:15:39.314494 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeUQAAaXo"]
[Thu Sep 17 15:15:39.318182 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeUwAAaUo"]
[Thu Sep 17 15:15:39.318492 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeVgAAaRY"]
[Thu Sep 17 15:15:39.326501 2026] [security2:error] [pid 971102:tid 971238] [client 184.82.86.122:42128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYe-cL08BTTQixEnpebQAABFY"]
[Thu Sep 17 15:15:39.347680 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeVwAAaR0"]
[Thu Sep 17 15:15:39.348977 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeVQAAaVk"]
[Thu Sep 17 15:15:39.350050 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeWQAAaRE"]
[Thu Sep 17 15:15:39.352709 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeWAAAaUY"]
[Thu Sep 17 15:15:39.362513 2026] [security2:error] [pid 971102:tid 971284] [client 169.58.197.253:50279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeIQAAADI"], referer: binance.com
[Thu Sep 17 15:15:39.426325 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeYwAAaQw"]
[Thu Sep 17 15:15:39.438313 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeYgAAaQM"]
[Thu Sep 17 15:15:39.438532 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeXgAAaW0"]
[Thu Sep 17 15:15:39.439889 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeXwAAaWY"]
[Thu Sep 17 15:15:39.454667 2026] [security2:error] [pid 971102:tid 971339] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYeucL08BTTQixEnpeZAAAaSo"]
[Thu Sep 17 15:15:39.478032 2026] [security2:error] [pid 971102:tid 971337] [client 169.58.197.253:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ppfc.net"] [uri "/wp-login.php"] [unique_id "aqxYe-cL08BTTQixEnpedQAAAGc"], referer: binance.com
[Thu Sep 17 15:15:39.532135 2026] [security2:error] [pid 971102:tid 971221] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config.php"] [unique_id "aqxYe-cL08BTTQixEnpeggAAUnQ"]
[Thu Sep 17 15:15:39.579686 2026] [security2:error] [pid 971102:tid 971288] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpedAAAADY"]
[Thu Sep 17 15:15:39.771773 2026] [security2:error] [pid 971102:tid 971355] [client 34.95.61.66:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYe-cL08BTTQixEnpejQAAAHk"]
[Thu Sep 17 15:15:40.038297 2026] [security2:error] [pid 971102:tid 971259] [client 34.95.61.66:52616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnpelgAAABk"]
[Thu Sep 17 15:15:40.299065 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeeAAAUn8"]
[Thu Sep 17 15:15:40.299320 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpedwAAUm8"]
[Thu Sep 17 15:15:40.315612 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeegAAUhg"]
[Thu Sep 17 15:15:40.318591 2026] [security2:error] [pid 971102:tid 971322] [client 34.95.61.66:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnpemwAAAFg"]
[Thu Sep 17 15:15:40.332871 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeewAAUng"]
[Thu Sep 17 15:15:40.340042 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpefQAAUlo"]
[Thu Sep 17 15:15:40.343563 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpefAAAUkU"]
[Thu Sep 17 15:15:40.359196 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpegQAAUls"]
[Thu Sep 17 15:15:40.361185 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpefwAAUj8"]
[Thu Sep 17 15:15:40.370088 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpegAAAUik"]
[Thu Sep 17 15:15:40.389615 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeigAAUjA"]
[Thu Sep 17 15:15:40.391490 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpeiQAAUl8"]
[Thu Sep 17 15:15:40.393595 2026] [security2:error] [pid 971102:tid 971316] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYe-cL08BTTQixEnpehgAAUiQ"]
[Thu Sep 17 15:15:40.483568 2026] [security2:error] [pid 971102:tid 971168] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/aws.php"] [unique_id "aqxYfOcL08BTTQixEnpeowAAJUA"]
[Thu Sep 17 15:15:40.518671 2026] [security2:error] [pid 971102:tid 971197] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/stripe.php"] [unique_id "aqxYfOcL08BTTQixEnpepQAAJVw"]
[Thu Sep 17 15:15:40.526144 2026] [security2:error] [pid 971102:tid 971176] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/mail.php"] [unique_id "aqxYfOcL08BTTQixEnpepwAAJUg"]
[Thu Sep 17 15:15:40.542486 2026] [security2:error] [pid 971102:tid 971185] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/config.inc.php"] [unique_id "aqxYfOcL08BTTQixEnpeqAAAJVE"]
[Thu Sep 17 15:15:40.555147 2026] [security2:error] [pid 971102:tid 971189] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/config/nexmo.php"] [unique_id "aqxYfOcL08BTTQixEnpeqwAAJVQ"]
[Thu Sep 17 15:15:40.570301 2026] [security2:error] [pid 971102:tid 971270] [client 34.95.61.66:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnperAAAACQ"]
[Thu Sep 17 15:15:40.576732 2026] [security2:error] [pid 971102:tid 971203] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/wp-config.php"] [unique_id "aqxYfOcL08BTTQixEnperwAAJWI"]
[Thu Sep 17 15:15:40.609083 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeogAAJTU"]
[Thu Sep 17 15:15:40.630143 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpepAAAJUM"]
[Thu Sep 17 15:15:40.633682 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYfOcL08BTTQixEnpesAAAJTk"]
[Thu Sep 17 15:15:40.635045 2026] [security2:error] [pid 971102:tid 971142] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.old"] [unique_id "aqxYfOcL08BTTQixEnpesQAAJSY"]
[Thu Sep 17 15:15:40.635046 2026] [security2:error] [pid 971102:tid 971223] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.new"] [unique_id "aqxYfOcL08BTTQixEnpesgAAJXY"]
[Thu Sep 17 15:15:40.640406 2026] [security2:error] [pid 971102:tid 971112] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxYfOcL08BTTQixEnpeswAAJQg"]
[Thu Sep 17 15:15:40.650430 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpepgAAJS8"]
[Thu Sep 17 15:15:40.669441 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeqQAAJUc"]
[Thu Sep 17 15:15:40.700023 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnperQAAJSM"]
[Thu Sep 17 15:15:40.711338 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxYfOcL08BTTQixEnpeuwAAJWw"]
[Thu Sep 17 15:15:40.790592 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpetwAAJQc"]
[Thu Sep 17 15:15:40.818793 2026] [security2:error] [pid 971102:tid 971127] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxYfOcL08BTTQixEnpexQAAJRc"]
[Thu Sep 17 15:15:40.846247 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.61.66:52640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYfOcL08BTTQixEnpeywAAAC0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:15:40.851025 2026] [deflate:error] [pid 971102:tid 971361] (104)Connection reset by peer: [client 34.23.195.25:46434] AH10298: failed reading from PIPE bucket
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:15:41.087605 2026] [deflate:error] [pid 971102:tid 971242] (104)Connection reset by peer: [client 34.23.195.25:46438] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:15:41.103992 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.61.66:52650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYfecL08BTTQixEnpe1QAAADU"]
[Thu Sep 17 15:15:41.316502 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpevQAAJV0"]
[Thu Sep 17 15:15:41.333786 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpevgAAJTo"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:15:41.334902 2026] [deflate:error] [pid 971102:tid 971245] (104)Connection reset by peer: [client 34.23.195.25:46440] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:15:41.353037 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpewAAAJTM"]
[Thu Sep 17 15:15:41.363020 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpewQAAJRU"]
[Thu Sep 17 15:15:41.373193 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.61.66:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYfecL08BTTQixEnpe3wAAAHc"]
[Thu Sep 17 15:15:41.408821 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpewgAAJWk"]
[Thu Sep 17 15:15:41.412602 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpezwAAJVI"]
[Thu Sep 17 15:15:41.416909 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpexAAAJW4"]
[Thu Sep 17 15:15:41.417919 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpexwAAJSw"]
[Thu Sep 17 15:15:41.418050 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpexgAAJUk"]
[Thu Sep 17 15:15:41.418094 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeyAAAJVc"]
[Thu Sep 17 15:15:41.428441 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpeygAAJXI"]
[Thu Sep 17 15:15:41.456179 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpezgAAJWQ"]
[Thu Sep 17 15:15:41.462716 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfOcL08BTTQixEnpezAAAJWo"]
[Thu Sep 17 15:15:41.471637 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe0gAAJU8"]
[Thu Sep 17 15:15:41.650810 2026] [security2:error] [pid 971102:tid 971261] [client 34.95.61.66:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYfecL08BTTQixEnpe-QAAABs"]
[Thu Sep 17 15:15:41.754511 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env"] [unique_id "aqxYfecL08BTTQixEnpe_AAAADA"]
[Thu Sep 17 15:15:41.909218 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.61.66:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYfecL08BTTQixEnpfAQAAAAk"]
[Thu Sep 17 15:15:42.077107 2026] [security2:error] [pid 971102:tid 971222] [remote 216.73.217.142:12689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYfucL08BTTQixEnpfCAAAL3U"]
[Thu Sep 17 15:15:42.186057 2026] [security2:error] [pid 971102:tid 971308] [client 34.95.61.66:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYfucL08BTTQixEnpfEgAAAEo"]
[Thu Sep 17 15:15:42.370973 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe4AAAJTg"]
[Thu Sep 17 15:15:42.380897 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe4gAAJQs"]
[Thu Sep 17 15:15:42.395113 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe5gAAJRI"]
[Thu Sep 17 15:15:42.416088 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe7gAAJU0"]
[Thu Sep 17 15:15:42.419108 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe9wAAJRk"]
[Thu Sep 17 15:15:42.419712 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe6QAAJXM"]
[Thu Sep 17 15:15:42.419982 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe5wAAJWM"]
[Thu Sep 17 15:15:42.420086 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe6gAAJTw"]
[Thu Sep 17 15:15:42.420325 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe7QAAJQA"]
[Thu Sep 17 15:15:42.420462 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe9AAAJQY"]
[Thu Sep 17 15:15:42.423416 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe-AAAJWc"]
[Thu Sep 17 15:15:42.424251 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe6wAAJVg"]
[Thu Sep 17 15:15:42.435139 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe7AAAJRM"]
[Thu Sep 17 15:15:42.435771 2026] [security2:error] [pid 971102:tid 971271] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfecL08BTTQixEnpe8gAAJXA"]
[Thu Sep 17 15:15:42.477686 2026] [security2:error] [pid 971102:tid 971331] [client 34.95.61.66:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYfucL08BTTQixEnpfGwAAAGE"]
[Thu Sep 17 15:15:42.810771 2026] [security2:error] [pid 971102:tid 971283] [client 34.95.61.66:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYfucL08BTTQixEnpfMQAAADE"]
[Thu Sep 17 15:15:43.005156 2026] [security2:error] [pid 971102:tid 971121] [remote 45.157.54.43:59543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYfucL08BTTQixEnpfMwAAZBE"]
[Thu Sep 17 15:15:43.005370 2026] [security2:error] [pid 971102:tid 971334] [client 45.157.54.43:59543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYfucL08BTTQixEnpfMwAAZBE"]
[Thu Sep 17 15:15:43.107603 2026] [security2:error] [pid 971102:tid 971291] [client 34.95.61.66:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfNgAAADk"]
[Thu Sep 17 15:15:43.405604 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfGQAAKRs"]
[Thu Sep 17 15:15:43.405922 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfHgAAKVU"]
[Thu Sep 17 15:15:43.406009 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfKQAAKRQ"]
[Thu Sep 17 15:15:43.406159 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfGgAAKQ4"]
[Thu Sep 17 15:15:43.406270 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfJwAAKXo"]
[Thu Sep 17 15:15:43.406902 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfIgAAKXc"]
[Thu Sep 17 15:15:43.407141 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfKgAAKUw"]
[Thu Sep 17 15:15:43.407576 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfKAAAKUo"]
[Thu Sep 17 15:15:43.433770 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.61.66:52724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfPAAAAHc"]
[Thu Sep 17 15:15:43.447036 2026] [security2:error] [pid 971102:tid 971146] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfQwAAKSo"]
[Thu Sep 17 15:15:43.453742 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYfucL08BTTQixEnpfMAAAKVk"]
[Thu Sep 17 15:15:43.571162 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:61522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYf-cL08BTTQixEnpfRwAAAAg"]
[Thu Sep 17 15:15:43.571304 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:61522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYf-cL08BTTQixEnpfRwAAAAg"]
[Thu Sep 17 15:15:43.589485 2026] [security2:error] [pid 971102:tid 971159] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/info.php"] [unique_id "aqxYf-cL08BTTQixEnpfSAAAKTc"]
[Thu Sep 17 15:15:43.604857 2026] [security2:error] [pid 971102:tid 971251] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.bak"] [unique_id "aqxYf-cL08BTTQixEnpfSQAAABE"]
[Thu Sep 17 15:15:43.659647 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.backup"] [unique_id "aqxYf-cL08BTTQixEnpfTAAAAEw"]
[Thu Sep 17 15:15:43.706269 2026] [security2:error] [pid 971102:tid 971345] [client 34.95.61.66:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfTgAAAG8"]
[Thu Sep 17 15:15:43.768500 2026] [security2:error] [pid 971102:tid 971136] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/infos.php"] [unique_id "aqxYf-cL08BTTQixEnpfUwAAKSA"]
[Thu Sep 17 15:15:43.768593 2026] [security2:error] [pid 971102:tid 971134] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/php_info.php"] [unique_id "aqxYf-cL08BTTQixEnpfUgAAKR4"]
[Thu Sep 17 15:15:43.770428 2026] [security2:error] [pid 971102:tid 971212] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/php-info.php"] [unique_id "aqxYf-cL08BTTQixEnpfVQAAKWs"]
[Thu Sep 17 15:15:43.770454 2026] [security2:error] [pid 971102:tid 971226] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/infophp.php"] [unique_id "aqxYf-cL08BTTQixEnpfVgAAKXk"]
[Thu Sep 17 15:15:43.770486 2026] [security2:error] [pid 971102:tid 971138] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/api/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfWwAAKSI"]
[Thu Sep 17 15:15:43.770514 2026] [security2:error] [pid 971102:tid 971163] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfVwAAKTs"]
[Thu Sep 17 15:15:43.770523 2026] [security2:error] [pid 971102:tid 971120] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/php.php"] [unique_id "aqxYf-cL08BTTQixEnpfVAAAKRA"]
[Thu Sep 17 15:15:43.770557 2026] [security2:error] [pid 971102:tid 971230] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfWAAAKX0"]
[Thu Sep 17 15:15:43.770568 2026] [security2:error] [pid 971102:tid 971109] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfWQAAKQU"]
[Thu Sep 17 15:15:43.828291 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.old"] [unique_id "aqxYf-cL08BTTQixEnpfXAAAAGI"]
[Thu Sep 17 15:15:43.947993 2026] [security2:error] [pid 971102:tid 971169] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfYAAAKUE"]
[Thu Sep 17 15:15:43.984069 2026] [security2:error] [pid 971102:tid 971290] [client 34.95.61.66:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYf-cL08BTTQixEnpfYQAAADg"]
[Thu Sep 17 15:15:44.129475 2026] [security2:error] [pid 971102:tid 971196] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/database.sql"] [unique_id "aqxYgOcL08BTTQixEnpfcQAAKVs"]
[Thu Sep 17 15:15:44.227343 2026] [security2:error] [pid 971102:tid 971145] [remote 45.157.54.43:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYgOcL08BTTQixEnpfeQAANik"]
[Thu Sep 17 15:15:44.227506 2026] [security2:error] [pid 971102:tid 971288] [client 45.157.54.43:61105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYgOcL08BTTQixEnpfeQAANik"]
[Thu Sep 17 15:15:44.288594 2026] [security2:error] [pid 971102:tid 971214] [remote 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfPQAAKW0"]
[Thu Sep 17 15:15:44.294219 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfPwAAKQw"]
[Thu Sep 17 15:15:44.294886 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfQAAAKWY"]
[Thu Sep 17 15:15:44.295023 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfPgAAKQM"]
[Thu Sep 17 15:15:44.295678 2026] [security2:error] [pid 971102:tid 971343] [client 34.95.61.66:52742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYgOcL08BTTQixEnpffAAAAG0"]
[Thu Sep 17 15:15:44.298090 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfQQAAKSU"]
[Thu Sep 17 15:15:44.301072 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfQgAAKXQ"]
[Thu Sep 17 15:15:44.410293 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYf-cL08BTTQixEnpfWgAAKVM"]
[Thu Sep 17 15:15:44.410415 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfawAAKW8"]
[Thu Sep 17 15:15:44.413060 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfbQAAKV4"]
[Thu Sep 17 15:15:44.413138 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfagAAKX8"]
[Thu Sep 17 15:15:44.413234 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfcAAAKVo"]
[Thu Sep 17 15:15:44.422831 2026] [security2:error] [pid 971102:tid 971316] [client 209.141.32.143:50890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gridmodita.com"] [uri "/wp-content/plugins/jetformbuilder/readme.txt"] [unique_id "aqxYgOcL08BTTQixEnpfgwAAAFI"]
[Thu Sep 17 15:15:44.427020 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfbgAAKRg"]
[Thu Sep 17 15:15:44.431026 2026] [security2:error] [pid 971102:tid 971275] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfcgAAKUU"]
[Thu Sep 17 15:15:44.444425 2026] [security2:error] [pid 971102:tid 971105] [remote 47.128.23.119:40140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joeledmundanderson.com"] [uri "/robots.txt"] [unique_id "aqxYgOcL08BTTQixEnpfhgAADAE"]
[Thu Sep 17 15:15:44.554760 2026] [security2:error] [pid 971102:tid 971256] [client 34.95.61.66:52756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYgOcL08BTTQixEnpfkgAAABY"]
[Thu Sep 17 15:15:44.595182 2026] [security2:error] [pid 971102:tid 971179] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/lib/.env"] [unique_id "aqxYgOcL08BTTQixEnpfmQAAf0s"]
[Thu Sep 17 15:15:44.607417 2026] [security2:error] [pid 971102:tid 971157] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thehivetribe.com"] [uri "/wp-config.php.txt"] [unique_id "aqxYgOcL08BTTQixEnpfmwAAfzU"]
[Thu Sep 17 15:15:44.611266 2026] [security2:error] [pid 971102:tid 971161] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/ses/.env"] [unique_id "aqxYgOcL08BTTQixEnpfnQAAfzk"]
[Thu Sep 17 15:15:44.832220 2026] [security2:error] [pid 971102:tid 971320] [client 34.95.61.66:52762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYgOcL08BTTQixEnpfrAAAAFY"]
[Thu Sep 17 15:15:45.184896 2026] [security2:error] [pid 971102:tid 971339] [client 34.95.61.66:52774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYgecL08BTTQixEnpfsgAAAGk"]
[Thu Sep 17 15:15:45.278998 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfigAAf0I"]
[Thu Sep 17 15:15:45.280070 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfjAAAfz4"]
[Thu Sep 17 15:15:45.287292 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfiwAAfzY"]
[Thu Sep 17 15:15:45.287513 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfiQAAfy4"]
[Thu Sep 17 15:15:45.291287 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfjQAAf0A"]
[Thu Sep 17 15:15:45.307947 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfjgAAfw0"]
[Thu Sep 17 15:15:45.391501 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfmAAAfzQ"]
[Thu Sep 17 15:15:45.391743 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfmgAAf2I"]
[Thu Sep 17 15:15:45.392157 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfnwAAf3Y"]
[Thu Sep 17 15:15:45.392280 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfnAAAf0M"]
[Thu Sep 17 15:15:45.400858 2026] [security2:error] [pid 971102:tid 971361] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgOcL08BTTQixEnpfpwAAfy8"]
[Thu Sep 17 15:15:45.442857 2026] [security2:error] [pid 971102:tid 971213] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/.git/config~"] [unique_id "aqxYgecL08BTTQixEnpfugAACWw"]
[Thu Sep 17 15:15:45.449506 2026] [security2:error] [pid 971102:tid 971305] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env.swp"] [unique_id "aqxYgecL08BTTQixEnpfvgAAAEc"]
[Thu Sep 17 15:15:45.507426 2026] [security2:error] [pid 971102:tid 971360] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.env~"] [unique_id "aqxYgecL08BTTQixEnpfxQAAAH4"]
[Thu Sep 17 15:15:45.571418 2026] [security2:error] [pid 971102:tid 971210] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thehivetribe.com"] [uri "/sites/default/settings.php.swp"] [unique_id "aqxYgecL08BTTQixEnpfywAACWk"]
[Thu Sep 17 15:15:45.572356 2026] [security2:error] [pid 971102:tid 971209] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/yii/.env"] [unique_id "aqxYgecL08BTTQixEnpfygAACWg"]
[Thu Sep 17 15:15:45.572564 2026] [security2:error] [pid 971102:tid 971125] [remote 45.138.12.30:47986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thehivetribe.com"] [uri "/www.bak"] [unique_id "aqxYgecL08BTTQixEnpfyQAACRU"]
[Thu Sep 17 15:15:45.589207 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfuwAACQc"]
[Thu Sep 17 15:15:45.594861 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfvQAACRc"]
[Thu Sep 17 15:15:45.598528 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfuQAACWE"]
[Thu Sep 17 15:15:45.603023 2026] [security2:error] [pid 971102:tid 971292] [client 34.95.61.66:52778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYgecL08BTTQixEnpfzwAAADo"]
[Thu Sep 17 15:15:45.610283 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfwQAACUQ"]
[Thu Sep 17 15:15:45.612840 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfvwAACQQ"]
[Thu Sep 17 15:15:45.613281 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfwAAACXw"]
[Thu Sep 17 15:15:45.618906 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfwwAACU4"]
[Thu Sep 17 15:15:45.631773 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfxAAACTo"]
[Thu Sep 17 15:15:45.926451 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.61.66:52794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYgecL08BTTQixEnpf3AAAABM"]
[Thu Sep 17 15:15:45.935219 2026] [security2:error] [pid 971102:tid 971315] [client 5.189.145.112:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxYgecL08BTTQixEnpf3QAAAFE"], referer: binance.com
[Thu Sep 17 15:15:46.228161 2026] [security2:error] [pid 971102:tid 971257] [client 34.95.61.66:52796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYgucL08BTTQixEnpf7QAAABc"]
[Thu Sep 17 15:15:46.345988 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfzAAACVI"]
[Thu Sep 17 15:15:46.352405 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpfzQAACW4"]
[Thu Sep 17 15:15:46.368468 2026] [security2:error] [pid 971102:tid 971353] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/app/.env"] [unique_id "aqxYgucL08BTTQixEnpf8QAAAHc"]
[Thu Sep 17 15:15:46.404876 2026] [security2:error] [pid 971102:tid 971243] [client 45.138.12.30:47986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thehivetribe.com"] [uri "/index.php"] [unique_id "aqxYgecL08BTTQixEnpf0AAACSw"]
[Thu Sep 17 15:15:46.434795 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/apps/.env"] [unique_id "aqxYgucL08BTTQixEnpf8wAAAFo"]
[Thu Sep 17 15:15:46.499650 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/.env"] [unique_id "aqxYgucL08BTTQixEnpf9AAAAAs"]
[Thu Sep 17 15:15:46.529803 2026] [security2:error] [pid 971102:tid 971283] [client 34.95.61.66:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYgucL08BTTQixEnpf9wAAADE"]
[Thu Sep 17 15:15:46.582346 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/web/.env"] [unique_id "aqxYgucL08BTTQixEnpf-AAAACg"]
[Thu Sep 17 15:15:46.644933 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/site/.env"] [unique_id "aqxYgucL08BTTQixEnpf-wAAAG8"]
[Thu Sep 17 15:15:46.708578 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/public/.env"] [unique_id "aqxYgucL08BTTQixEnpf_QAAACs"]
[Thu Sep 17 15:15:46.824345 2026] [security2:error] [pid 971102:tid 971261] [client 34.95.61.66:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7556e278.qat.qby.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYgucL08BTTQixEnpgAgAAABs"]
[Thu Sep 17 15:15:46.895303 2026] [security2:error] [pid 971102:tid 971348] [client 185.55.149.49:65398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYgucL08BTTQixEnpgBAAAAHI"]
[Thu Sep 17 15:15:46.896752 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/backend/.env"] [unique_id "aqxYgucL08BTTQixEnpgAwAAAD4"]
[Thu Sep 17 15:15:46.900983 2026] [security2:error] [pid 971102:tid 971348] [client 185.55.149.49:65398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYgucL08BTTQixEnpgBAAAAHI"]
[Thu Sep 17 15:15:46.905140 2026] [security2:error] [pid 971102:tid 971284] [client 60.243.209.155:49584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYgucL08BTTQixEnpgAAAAMmQ"]
[Thu Sep 17 15:15:46.954522 2026] [security2:error] [pid 971102:tid 971349] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/server/.env"] [unique_id "aqxYgucL08BTTQixEnpgBQAAAHM"]
[Thu Sep 17 15:15:47.012276 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/frontend/.env"] [unique_id "aqxYg-cL08BTTQixEnpgBgAAABQ"]
[Thu Sep 17 15:15:47.077426 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/src/.env"] [unique_id "aqxYg-cL08BTTQixEnpgCQAAAFg"]
[Thu Sep 17 15:15:47.133462 2026] [security2:error] [pid 971102:tid 971360] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/core/.env"] [unique_id "aqxYg-cL08BTTQixEnpgDQAAAH4"]
[Thu Sep 17 15:15:47.193721 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/core/app/.env"] [unique_id "aqxYg-cL08BTTQixEnpgEgAAAFU"]
[Thu Sep 17 15:15:47.249588 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/config/.env"] [unique_id "aqxYg-cL08BTTQixEnpgFAAAAHE"]
[Thu Sep 17 15:15:47.311168 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/private/.env"] [unique_id "aqxYg-cL08BTTQixEnpgFgAAAGU"]
[Thu Sep 17 15:15:47.369225 2026] [security2:error] [pid 971102:tid 971294] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/application/.env"] [unique_id "aqxYg-cL08BTTQixEnpgGQAAADw"]
[Thu Sep 17 15:15:47.434414 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/bootstrap/.env"] [unique_id "aqxYg-cL08BTTQixEnpgHQAAAB8"]
[Thu Sep 17 15:15:47.494100 2026] [security2:error] [pid 971102:tid 971352] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/database/.env"] [unique_id "aqxYg-cL08BTTQixEnpgIQAAAHY"]
[Thu Sep 17 15:15:47.554767 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/storage/.env"] [unique_id "aqxYg-cL08BTTQixEnpgJAAAAE4"]
[Thu Sep 17 15:15:47.564453 2026] [security2:error] [pid 971102:tid 971328] [client 169.58.197.253:50944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxYg-cL08BTTQixEnpgHwAAAF4"], referer: binance.com
[Thu Sep 17 15:15:47.610562 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/var/www/.env"] [unique_id "aqxYg-cL08BTTQixEnpgJwAAAFI"]
[Thu Sep 17 15:15:47.674821 2026] [security2:error] [pid 971102:tid 971293] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/var/www/html/.env"] [unique_id "aqxYg-cL08BTTQixEnpgLgAAADs"]
[Thu Sep 17 15:15:47.733394 2026] [security2:error] [pid 971102:tid 971252] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/current/.env"] [unique_id "aqxYg-cL08BTTQixEnpgMQAAABI"]
[Thu Sep 17 15:15:47.774945 2026] [security2:error] [pid 971102:tid 971270] [client 186.105.232.15:65534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYg-cL08BTTQixEnpgMwAAACQ"]
[Thu Sep 17 15:15:47.777512 2026] [security2:error] [pid 971102:tid 971270] [client 186.105.232.15:65534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYg-cL08BTTQixEnpgMwAAACQ"]
[Thu Sep 17 15:15:47.788153 2026] [security2:error] [pid 971102:tid 971346] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/release/.env"] [unique_id "aqxYg-cL08BTTQixEnpgNAAAAHA"]
[Thu Sep 17 15:15:47.844839 2026] [security2:error] [pid 971102:tid 971304] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/releases/.env"] [unique_id "aqxYg-cL08BTTQixEnpgNQAAAEY"]
[Thu Sep 17 15:15:47.902397 2026] [security2:error] [pid 971102:tid 971325] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/shared/.env"] [unique_id "aqxYg-cL08BTTQixEnpgNwAAAFs"]
[Thu Sep 17 15:15:47.959624 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/deploy/.env"] [unique_id "aqxYg-cL08BTTQixEnpgOQAAAG4"]
[Thu Sep 17 15:15:48.013668 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/build/.env"] [unique_id "aqxYhOcL08BTTQixEnpgOwAAAEw"]
[Thu Sep 17 15:15:48.068900 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/dist/.env"] [unique_id "aqxYhOcL08BTTQixEnpgPQAAAEE"]
[Thu Sep 17 15:15:48.123008 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/public_html/.env"] [unique_id "aqxYhOcL08BTTQixEnpgPwAAAFY"]
[Thu Sep 17 15:15:48.177922 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/htdocs/.env"] [unique_id "aqxYhOcL08BTTQixEnpgQgAAAEI"]
[Thu Sep 17 15:15:48.232988 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/www/.env"] [unique_id "aqxYhOcL08BTTQixEnpgRQAAADE"]
[Thu Sep 17 15:15:48.251305 2026] [security2:error] [pid 971102:tid 971160] [remote 45.157.54.43:63797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhOcL08BTTQixEnpgRgAAZzg"]
[Thu Sep 17 15:15:48.251471 2026] [security2:error] [pid 971102:tid 971337] [client 45.157.54.43:63797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhOcL08BTTQixEnpgRgAAZzg"]
[Thu Sep 17 15:15:48.287030 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/html/.env"] [unique_id "aqxYhOcL08BTTQixEnpgRwAAAGo"]
[Thu Sep 17 15:15:48.341074 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/live/.env"] [unique_id "aqxYhOcL08BTTQixEnpgSQAAAC4"]
[Thu Sep 17 15:15:48.397032 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/prod/.env"] [unique_id "aqxYhOcL08BTTQixEnpgSwAAAB4"]
[Thu Sep 17 15:15:48.457008 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/dev/.env"] [unique_id "aqxYhOcL08BTTQixEnpgTAAAAGk"]
[Thu Sep 17 15:15:48.511570 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/staging/.env"] [unique_id "aqxYhOcL08BTTQixEnpgTQAAAEg"]
[Thu Sep 17 15:15:48.580237 2026] [security2:error] [pid 971102:tid 971242] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/opt/.env"] [unique_id "aqxYhOcL08BTTQixEnpgTgAAAAg"]
[Thu Sep 17 15:15:48.639724 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/laravel/.env"] [unique_id "aqxYhOcL08BTTQixEnpgUQAAAD4"]
[Thu Sep 17 15:15:48.701332 2026] [security2:error] [pid 971102:tid 971361] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/symfony/.env"] [unique_id "aqxYhOcL08BTTQixEnpgVgAAAH8"]
[Thu Sep 17 15:15:48.765099 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/wordpress/.env"] [unique_id "aqxYhOcL08BTTQixEnpgWQAAAAY"]
[Thu Sep 17 15:15:48.819833 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/wp/.env"] [unique_id "aqxYhOcL08BTTQixEnpgWgAAAFA"]
[Thu Sep 17 15:15:48.874971 2026] [security2:error] [pid 971102:tid 971286] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cms/.env"] [unique_id "aqxYhOcL08BTTQixEnpgWwAAADQ"]
[Thu Sep 17 15:15:48.933371 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.195.25:46444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/drupal/.env"] [unique_id "aqxYhOcL08BTTQixEnpgXQAAAHE"]
[Thu Sep 17 15:15:49.108396 2026] [security2:error] [pid 971102:tid 971327] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/joomla/.env"] [unique_id "aqxYhecL08BTTQixEnpgYAAAAF0"]
[Thu Sep 17 15:15:49.166073 2026] [security2:error] [pid 971102:tid 971352] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/magento/.env"] [unique_id "aqxYhecL08BTTQixEnpgZAAAAHY"]
[Thu Sep 17 15:15:49.227372 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/shopify/.env"] [unique_id "aqxYhecL08BTTQixEnpgZQAAAE4"]
[Thu Sep 17 15:15:49.282803 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/prestashop/.env"] [unique_id "aqxYhecL08BTTQixEnpgZwAAAF4"]
[Thu Sep 17 15:15:49.311177 2026] [security2:error] [pid 971102:tid 971281] [client 45.169.98.18:54066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgaAAAAC8"]
[Thu Sep 17 15:15:49.311269 2026] [security2:error] [pid 971102:tid 971281] [client 45.169.98.18:54066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgaAAAAC8"]
[Thu Sep 17 15:15:49.340905 2026] [security2:error] [pid 971102:tid 971247] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/codeigniter/.env"] [unique_id "aqxYhecL08BTTQixEnpgaQAAAA0"]
[Thu Sep 17 15:15:49.396465 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cakephp/.env"] [unique_id "aqxYhecL08BTTQixEnpgagAAAFM"]
[Thu Sep 17 15:15:49.451325 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/zend/.env"] [unique_id "aqxYhecL08BTTQixEnpgawAAAEo"]
[Thu Sep 17 15:15:49.511531 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/yii/.env"] [unique_id "aqxYhecL08BTTQixEnpgbgAAADk"]
[Thu Sep 17 15:15:49.567607 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/laravel5/.env"] [unique_id "aqxYhecL08BTTQixEnpgcQAAADU"]
[Thu Sep 17 15:15:49.586434 2026] [security2:error] [pid 971102:tid 971269] [client 138.246.253.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "radtechresourcesgroup.com"] [uri "/index.php"] [unique_id "aqxYgucL08BTTQixEnpf7gAAACM"]
[Thu Sep 17 15:15:49.622587 2026] [security2:error] [pid 971102:tid 971356] [client 186.209.201.184:12023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYhecL08BTTQixEnpgbQAAenM"]
[Thu Sep 17 15:15:49.627386 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/v1/.env"] [unique_id "aqxYhecL08BTTQixEnpgcgAAACQ"]
[Thu Sep 17 15:15:49.696115 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/v2/.env"] [unique_id "aqxYhecL08BTTQixEnpgdgAAACk"]
[Thu Sep 17 15:15:49.754704 2026] [security2:error] [pid 971102:tid 971343] [client 154.190.208.131:41734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgeAAAAG0"]
[Thu Sep 17 15:15:49.754872 2026] [security2:error] [pid 971102:tid 971343] [client 154.190.208.131:41734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgeAAAAG0"]
[Thu Sep 17 15:15:49.761458 2026] [security2:error] [pid 971102:tid 971272] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/v3/.env"] [unique_id "aqxYhecL08BTTQixEnpgeQAAACY"]
[Thu Sep 17 15:15:49.823855 2026] [security2:error] [pid 971102:tid 971325] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/v1/.env"] [unique_id "aqxYhecL08BTTQixEnpgewAAAFs"]
[Thu Sep 17 15:15:49.887869 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/v2/.env"] [unique_id "aqxYhecL08BTTQixEnpgfQAAAHg"]
[Thu Sep 17 15:15:49.889463 2026] [security2:error] [pid 971102:tid 971273] [client 114.198.138.124:53302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgfAAAACc"]
[Thu Sep 17 15:15:49.889561 2026] [security2:error] [pid 971102:tid 971273] [client 114.198.138.124:53302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYhecL08BTTQixEnpgfAAAACc"]
[Thu Sep 17 15:15:49.946495 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/rest/.env"] [unique_id "aqxYhecL08BTTQixEnpgfwAAAFw"]
[Thu Sep 17 15:15:50.013234 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/graphql/.env"] [unique_id "aqxYhucL08BTTQixEnpgggAAAEI"]
[Thu Sep 17 15:15:50.077399 2026] [security2:error] [pid 971102:tid 971301] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/gateway/.env"] [unique_id "aqxYhucL08BTTQixEnpggwAAAEM"]
[Thu Sep 17 15:15:50.142424 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/microservice/.env"] [unique_id "aqxYhucL08BTTQixEnpghgAAAG8"]
[Thu Sep 17 15:15:50.208244 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/service/.env"] [unique_id "aqxYhucL08BTTQixEnpgiwAAADY"]
[Thu Sep 17 15:15:50.269938 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/v3/.env"] [unique_id "aqxYhucL08BTTQixEnpgjAAAAEk"]
[Thu Sep 17 15:15:50.333452 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/dev/.env"] [unique_id "aqxYhucL08BTTQixEnpgkQAAAHQ"]
[Thu Sep 17 15:15:50.392365 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/api/staging/.env"] [unique_id "aqxYhucL08BTTQixEnpglAAAAAE"]
[Thu Sep 17 15:15:50.457830 2026] [security2:error] [pid 971102:tid 971242] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/vendor/.env"] [unique_id "aqxYhucL08BTTQixEnpglwAAAAg"]
[Thu Sep 17 15:15:50.524085 2026] [security2:error] [pid 971102:tid 971361] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/lib/.env"] [unique_id "aqxYhucL08BTTQixEnpgmgAAAH8"]
[Thu Sep 17 15:15:50.583320 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/resources/.env"] [unique_id "aqxYhucL08BTTQixEnpgnAAAAA8"]
[Thu Sep 17 15:15:50.637650 2026] [security2:error] [pid 971102:tid 971259] [client 5.189.145.112:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxYhucL08BTTQixEnpgnwAAABk"], referer: binance.com
[Thu Sep 17 15:15:50.640469 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/assets/.env"] [unique_id "aqxYhucL08BTTQixEnpgoAAAAD0"]
[Thu Sep 17 15:15:50.697481 2026] [security2:error] [pid 971102:tid 971292] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/uploads/.env"] [unique_id "aqxYhucL08BTTQixEnpgowAAADo"]
[Thu Sep 17 15:15:50.764281 2026] [security2:error] [pid 971102:tid 971355] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/internal/.env"] [unique_id "aqxYhucL08BTTQixEnpgpgAAAHk"]
[Thu Sep 17 15:15:50.778581 2026] [security2:error] [pid 971102:tid 971244] [client 45.115.26.203:56124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/ta/index.php"] [unique_id "aqxYhucL08BTTQixEnpgqQAAAAo"]
[Thu Sep 17 15:15:50.824184 2026] [security2:error] [pid 971102:tid 971357] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/tools/.env"] [unique_id "aqxYhucL08BTTQixEnpgrQAAAHs"]
[Thu Sep 17 15:15:50.881738 2026] [security2:error] [pid 971102:tid 971309] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/scripts/.env"] [unique_id "aqxYhucL08BTTQixEnpgrgAAAEs"]
[Thu Sep 17 15:15:50.938929 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/bin/.env"] [unique_id "aqxYhucL08BTTQixEnpgrwAAAF4"]
[Thu Sep 17 15:15:50.994450 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sbin/.env"] [unique_id "aqxYhucL08BTTQixEnpgsgAAAE8"]
[Thu Sep 17 15:15:51.053602 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/local/.env"] [unique_id "aqxYh-cL08BTTQixEnpgtAAAAFM"]
[Thu Sep 17 15:15:51.059455 2026] [security2:error] [pid 971102:tid 971304] [client 103.131.71.44:53455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "airmacinc.com"] [uri "/index.php"] [unique_id "aqxYhecL08BTTQixEnpggQAAAEY"]
[Thu Sep 17 15:15:51.115544 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/portal/.env"] [unique_id "aqxYh-cL08BTTQixEnpgtQAAACA"]
[Thu Sep 17 15:15:51.175091 2026] [security2:error] [pid 971102:tid 971331] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/dashboard/.env"] [unique_id "aqxYh-cL08BTTQixEnpgugAAAGE"]
[Thu Sep 17 15:15:51.233919 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpguwAAADU"]
[Thu Sep 17 15:15:51.301929 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/crm/.env"] [unique_id "aqxYh-cL08BTTQixEnpgvQAAAAA"]
[Thu Sep 17 15:15:51.323486 2026] [cgid:error] [pid 971102:tid 971121] [remote 82.90.231.111:50634] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:15:51.362741 2026] [security2:error] [pid 971102:tid 971356] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/erp/.env"] [unique_id "aqxYh-cL08BTTQixEnpgvwAAAHo"]
[Thu Sep 17 15:15:51.418446 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/shop/.env"] [unique_id "aqxYh-cL08BTTQixEnpgwQAAACk"]
[Thu Sep 17 15:15:51.479796 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/store/.env"] [unique_id "aqxYh-cL08BTTQixEnpgwgAAAH0"]
[Thu Sep 17 15:15:51.535953 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/saas/.env"] [unique_id "aqxYh-cL08BTTQixEnpgwwAAAHg"]
[Thu Sep 17 15:15:51.595394 2026] [security2:error] [pid 971102:tid 971255] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/client/.env"] [unique_id "aqxYh-cL08BTTQixEnpgxAAAABU"]
[Thu Sep 17 15:15:51.649795 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/project/.env"] [unique_id "aqxYh-cL08BTTQixEnpgyAAAAG4"]
[Thu Sep 17 15:15:51.704281 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/admin-panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpgygAAAFw"]
[Thu Sep 17 15:15:51.762421 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/control-panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpgzQAAADY"]
[Thu Sep 17 15:15:51.825869 2026] [security2:error] [pid 971102:tid 971302] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/user-panel/.env"] [unique_id "aqxYh-cL08BTTQixEnpgzgAAAEQ"]
[Thu Sep 17 15:15:51.883524 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/node/.env"] [unique_id "aqxYh-cL08BTTQixEnpg0QAAAFY"]
[Thu Sep 17 15:15:51.942111 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/express/.env"] [unique_id "aqxYh-cL08BTTQixEnpg0gAAAAE"]
[Thu Sep 17 15:15:52.003141 2026] [security2:error] [pid 971102:tid 971238] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/next/.env"] [unique_id "aqxYiOcL08BTTQixEnpg0wAAAAQ"]
[Thu Sep 17 15:15:52.061599 2026] [security2:error] [pid 971102:tid 971243] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/nuxt/.env"] [unique_id "aqxYiOcL08BTTQixEnpg1QAAAAk"]
[Thu Sep 17 15:15:52.075254 2026] [security2:error] [pid 971102:tid 971106] [remote 216.73.217.142:19084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxYiOcL08BTTQixEnpg1gAABgI"]
[Thu Sep 17 15:15:52.093450 2026] [security2:error] [pid 971102:tid 971137] [remote 45.157.54.43:11840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiOcL08BTTQixEnpg2QAAYCE"]
[Thu Sep 17 15:15:52.093558 2026] [security2:error] [pid 971102:tid 971330] [client 45.157.54.43:11840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pbandgrace.teachingdifferently.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiOcL08BTTQixEnpg2QAAYCE"]
[Thu Sep 17 15:15:52.121157 2026] [security2:error] [pid 971102:tid 971261] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/nest/.env"] [unique_id "aqxYiOcL08BTTQixEnpg2gAAABs"]
[Thu Sep 17 15:15:52.186067 2026] [security2:error] [pid 971102:tid 971348] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/react/.env"] [unique_id "aqxYiOcL08BTTQixEnpg4QAAAHI"]
[Thu Sep 17 15:15:52.243968 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/vue/.env"] [unique_id "aqxYiOcL08BTTQixEnpg4gAAACs"]
[Thu Sep 17 15:15:52.300195 2026] [security2:error] [pid 971102:tid 971267] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/angular/.env"] [unique_id "aqxYiOcL08BTTQixEnpg4wAAACE"]
[Thu Sep 17 15:15:52.356501 2026] [security2:error] [pid 971102:tid 971250] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/svelte/.env"] [unique_id "aqxYiOcL08BTTQixEnpg5wAAABA"]
[Thu Sep 17 15:15:52.417771 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/vite/.env"] [unique_id "aqxYiOcL08BTTQixEnpg6AAAABQ"]
[Thu Sep 17 15:15:52.448020 2026] [security2:error] [pid 971102:tid 971339] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxYiOcL08BTTQixEnpg5gAAAGk"]
[Thu Sep 17 15:15:52.473643 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/backup/.env"] [unique_id "aqxYiOcL08BTTQixEnpg6QAAAEU"]
[Thu Sep 17 15:15:52.529365 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/backups/.env"] [unique_id "aqxYiOcL08BTTQixEnpg6gAAABM"]
[Thu Sep 17 15:15:52.564510 2026] [security2:error] [pid 971102:tid 971360] [client 212.28.179.189:34514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cpanel-box5305.bluehost.com"] [uri "/___proxy_subdomain_webmail/.azure/.env"] [unique_id "aqxYiOcL08BTTQixEnpg7gAAAH4"]
[Thu Sep 17 15:15:52.587460 2026] [security2:error] [pid 971102:tid 971352] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/old/.env"] [unique_id "aqxYiOcL08BTTQixEnpg8QAAAHY"]
[Thu Sep 17 15:15:52.646785 2026] [security2:error] [pid 971102:tid 971281] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/tmp/.env"] [unique_id "aqxYiOcL08BTTQixEnpg9AAAAC8"]
[Thu Sep 17 15:15:52.708404 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/temp/.env"] [unique_id "aqxYiOcL08BTTQixEnpg-QAAADM"]
[Thu Sep 17 15:15:52.768631 2026] [security2:error] [pid 971102:tid 971304] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/lab/.env"] [unique_id "aqxYiOcL08BTTQixEnpg-gAAAEY"]
[Thu Sep 17 15:15:52.824982 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cronlab/.env"] [unique_id "aqxYiOcL08BTTQixEnpg-wAAABc"]
[Thu Sep 17 15:15:52.890879 2026] [security2:error] [pid 971102:tid 971258] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cron/.env"] [unique_id "aqxYiOcL08BTTQixEnpg_AAAABg"]
[Thu Sep 17 15:15:52.953367 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/en/.env"] [unique_id "aqxYiOcL08BTTQixEnpg_gAAAAA"]
[Thu Sep 17 15:15:53.066979 2026] [security2:error] [pid 971102:tid 971246] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/administrator/.env"] [unique_id "aqxYiecL08BTTQixEnpg_wAAAAw"]
[Thu Sep 17 15:15:53.126731 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/psnlink/.env"] [unique_id "aqxYiecL08BTTQixEnphBAAAACk"]
[Thu Sep 17 15:15:53.185688 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/exapi/.env"] [unique_id "aqxYiecL08BTTQixEnphBgAAAGQ"]
[Thu Sep 17 15:15:53.241922 2026] [security2:error] [pid 971102:tid 971343] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sitemaps/.env"] [unique_id "aqxYiecL08BTTQixEnphCAAAAG0"]
[Thu Sep 17 15:15:53.380520 2026] [security2:error] [pid 971102:tid 971355] [client 170.83.212.197:62992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYiecL08BTTQixEnphCQAAAHk"]
[Thu Sep 17 15:15:53.502374 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/logs/.env"] [unique_id "aqxYiecL08BTTQixEnphFAAAAEw"]
[Thu Sep 17 15:15:53.575011 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cache/.env"] [unique_id "aqxYiecL08BTTQixEnphFgAAAHQ"]
[Thu Sep 17 15:15:53.588970 2026] [security2:error] [pid 971102:tid 971302] [client 74.7.175.133:51312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-02c52488.qat.qby.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYiecL08BTTQixEnphFwAARHc"]
[Thu Sep 17 15:15:53.634627 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailer/.env"] [unique_id "aqxYiecL08BTTQixEnphGQAAAB4"]
[Thu Sep 17 15:15:53.706130 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mail/.env"] [unique_id "aqxYiecL08BTTQixEnphGgAAAGo"]
[Thu Sep 17 15:15:53.776564 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.195.25:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/email/.env"] [unique_id "aqxYiecL08BTTQixEnphHwAAAEg"]
[Thu Sep 17 15:15:53.822370 2026] [security2:error] [pid 971102:tid 971330] [client 5.189.145.112:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxYiecL08BTTQixEnphIAAAAGA"], referer: binance.com
[Thu Sep 17 15:15:53.885633 2026] [core:error] [pid 971102:tid 971267] [client 74.7.244.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:53.885655 2026] [core:error] [pid 971102:tid 971267] [client 74.7.244.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:15:53.885806 2026] [security2:error] [pid 971102:tid 971267] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "aqxYiecL08BTTQixEnphJgAAACE"]
[Thu Sep 17 15:15:53.896641 2026] [security2:error] [pid 971102:tid 971261] [client 74.7.244.49:57860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxYiecL08BTTQixEnphIQAAGyo"]
[Thu Sep 17 15:15:53.963259 2026] [security2:error] [pid 971102:tid 971320] [client 212.28.179.189:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cpanel-box5305.bluehost.com"] [uri "/___proxy_subdomain_webmail/backend/api/.env"] [unique_id "aqxYiecL08BTTQixEnphKQAAAFY"]
[Thu Sep 17 15:15:53.988475 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/smtp/.env"] [unique_id "aqxYiecL08BTTQixEnphKgAAAGg"]
[Thu Sep 17 15:15:54.052666 2026] [security2:error] [pid 971102:tid 971284] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailing/.env"] [unique_id "aqxYiucL08BTTQixEnphLQAAADI"]
[Thu Sep 17 15:15:54.072119 2026] [security2:error] [pid 971102:tid 971243] [client 172.239.147.162:51794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxYiecL08BTTQixEnphJwAAAAk"], referer: binance.com
[Thu Sep 17 15:15:54.112597 2026] [security2:error] [pid 971102:tid 971357] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/notifications/.env"] [unique_id "aqxYiucL08BTTQixEnphMAAAAHs"]
[Thu Sep 17 15:15:54.113092 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiucL08BTTQixEnphMQAAAAg"]
[Thu Sep 17 15:15:54.114418 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:62130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYiucL08BTTQixEnphMQAAAAg"]
[Thu Sep 17 15:15:54.177472 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/notify/.env"] [unique_id "aqxYiucL08BTTQixEnphNQAAAF4"]
[Thu Sep 17 15:15:54.240338 2026] [security2:error] [pid 971102:tid 971305] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sender/.env"] [unique_id "aqxYiucL08BTTQixEnphNwAAAEc"]
[Thu Sep 17 15:15:54.307936 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/campaign/.env"] [unique_id "aqxYiucL08BTTQixEnphOAAAADM"]
[Thu Sep 17 15:15:54.374038 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/newsletter/.env"] [unique_id "aqxYiucL08BTTQixEnphOgAAAAs"]
[Thu Sep 17 15:15:54.438600 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/ses/.env"] [unique_id "aqxYiucL08BTTQixEnphPQAAAFg"]
[Thu Sep 17 15:15:54.501556 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sendgrid/.env"] [unique_id "aqxYiucL08BTTQixEnphPwAAAAA"]
[Thu Sep 17 15:15:54.562333 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/sparkpost/.env"] [unique_id "aqxYiucL08BTTQixEnphQAAAAGs"]
[Thu Sep 17 15:15:54.641785 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/postmark/.env"] [unique_id "aqxYiucL08BTTQixEnphRAAAAEo"]
[Thu Sep 17 15:15:54.720166 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailgun/.env"] [unique_id "aqxYiucL08BTTQixEnphRwAAACk"]
[Thu Sep 17 15:15:54.782285 2026] [security2:error] [pid 971102:tid 971271] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mandrill/.env"] [unique_id "aqxYiucL08BTTQixEnphSQAAACU"]
[Thu Sep 17 15:15:54.845690 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mailjet/.env"] [unique_id "aqxYiucL08BTTQixEnphSgAAAGQ"]
[Thu Sep 17 15:15:54.922306 2026] [security2:error] [pid 971102:tid 971325] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/brevo/.env"] [unique_id "aqxYiucL08BTTQixEnphTAAAAFs"]
[Thu Sep 17 15:15:54.989968 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/transactional/.env"] [unique_id "aqxYiucL08BTTQixEnphTQAAACQ"]
[Thu Sep 17 15:15:55.051496 2026] [security2:error] [pid 971102:tid 971353] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/bulk/.env"] [unique_id "aqxYi-cL08BTTQixEnphTwAAAHc"]
[Thu Sep 17 15:15:55.113863 2026] [security2:error] [pid 971102:tid 971355] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/aws/.env"] [unique_id "aqxYi-cL08BTTQixEnphUgAAAHk"]
[Thu Sep 17 15:15:55.168111 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/azure/.env"] [unique_id "aqxYi-cL08BTTQixEnphVwAAACw"]
[Thu Sep 17 15:15:55.227031 2026] [security2:error] [pid 971102:tid 971247] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/gcp/.env"] [unique_id "aqxYi-cL08BTTQixEnphWAAAAA0"]
[Thu Sep 17 15:15:55.294268 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cloud/.env"] [unique_id "aqxYi-cL08BTTQixEnphWgAAABo"]
[Thu Sep 17 15:15:55.349041 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/infrastructure/.env"] [unique_id "aqxYi-cL08BTTQixEnphXAAAAHQ"]
[Thu Sep 17 15:15:55.404446 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/docker/.env"] [unique_id "aqxYi-cL08BTTQixEnphXgAAAGo"]
[Thu Sep 17 15:15:55.436585 2026] [security2:error] [pid 971102:tid 971337] [client 172.239.147.162:64189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxYi-cL08BTTQixEnphXQAAAGc"], referer: binance.com
[Thu Sep 17 15:15:55.466063 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/k8s/.env"] [unique_id "aqxYi-cL08BTTQixEnphYAAAAEg"]
[Thu Sep 17 15:15:55.523310 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/kubernetes/.env"] [unique_id "aqxYi-cL08BTTQixEnphYgAAAAY"]
[Thu Sep 17 15:15:55.537843 2026] [security2:error] [pid 971102:tid 971344] [client 212.28.179.189:55462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cpanel-box5305.bluehost.com"] [uri "/___proxy_subdomain_webmail/backend/app/.env"] [unique_id "aqxYi-cL08BTTQixEnphZAAAAG4"]
[Thu Sep 17 15:15:55.578769 2026] [security2:error] [pid 971102:tid 971342] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/terraform/.env"] [unique_id "aqxYi-cL08BTTQixEnphZQAAAGw"]
[Thu Sep 17 15:15:55.638978 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/ansible/.env"] [unique_id "aqxYi-cL08BTTQixEnphawAAAD0"]
[Thu Sep 17 15:15:55.700243 2026] [security2:error] [pid 971102:tid 971289] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/.git/.env"] [unique_id "aqxYi-cL08BTTQixEnphbgAAADc"]
[Thu Sep 17 15:15:55.760516 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/ci/.env"] [unique_id "aqxYi-cL08BTTQixEnphcAAAAGk"]
[Thu Sep 17 15:15:55.815965 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/cd/.env"] [unique_id "aqxYi-cL08BTTQixEnphcQAAABQ"]
[Thu Sep 17 15:15:55.879083 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/jenkins/.env"] [unique_id "aqxYi-cL08BTTQixEnphcgAAAFU"]
[Thu Sep 17 15:15:55.953870 2026] [security2:error] [pid 971102:tid 971305] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/gitlab/.env"] [unique_id "aqxYi-cL08BTTQixEnphcwAAAEc"]
[Thu Sep 17 15:15:56.016682 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/github/.env"] [unique_id "aqxYjOcL08BTTQixEnphdAAAAFo"]
[Thu Sep 17 15:15:56.077942 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/actions/.env"] [unique_id "aqxYjOcL08BTTQixEnphdQAAAFM"]
[Thu Sep 17 15:15:56.147174 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/circleci/.env"] [unique_id "aqxYjOcL08BTTQixEnphdwAAAAs"]
[Thu Sep 17 15:15:56.206460 2026] [security2:error] [pid 971102:tid 971290] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/travis/.env"] [unique_id "aqxYjOcL08BTTQixEnphegAAADg"]
[Thu Sep 17 15:15:56.272963 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/buildkite/.env"] [unique_id "aqxYjOcL08BTTQixEnphfAAAAGU"]
[Thu Sep 17 15:15:56.334648 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mysql/.env"] [unique_id "aqxYjOcL08BTTQixEnphfQAAAFE"]
[Thu Sep 17 15:15:56.393529 2026] [security2:error] [pid 971102:tid 971327] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/postgres/.env"] [unique_id "aqxYjOcL08BTTQixEnphfgAAAF0"]
[Thu Sep 17 15:15:56.454416 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/mongodb/.env"] [unique_id "aqxYjOcL08BTTQixEnphgAAAAGs"]
[Thu Sep 17 15:15:56.532760 2026] [security2:error] [pid 971102:tid 971293] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/redis/.env"] [unique_id "aqxYjOcL08BTTQixEnphhAAAADs"]
[Thu Sep 17 15:15:56.596653 2026] [security2:error] [pid 971102:tid 971271] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/elasticsearch/.env"] [unique_id "aqxYjOcL08BTTQixEnphhQAAACU"]
[Thu Sep 17 15:15:56.660216 2026] [security2:error] [pid 971102:tid 971333] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/rabbitmq/.env"] [unique_id "aqxYjOcL08BTTQixEnphiAAAAGM"]
[Thu Sep 17 15:15:56.718619 2026] [security2:error] [pid 971102:tid 971358] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/kafka/.env"] [unique_id "aqxYjOcL08BTTQixEnphigAAAHw"]
[Thu Sep 17 15:15:56.775506 2026] [security2:error] [pid 971102:tid 971276] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/queue/.env"] [unique_id "aqxYjOcL08BTTQixEnphiwAAACo"]
[Thu Sep 17 15:15:56.843979 2026] [security2:error] [pid 971102:tid 971356] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/worker/.env"] [unique_id "aqxYjOcL08BTTQixEnphjQAAAHo"]
[Thu Sep 17 15:15:56.904992 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/job/.env"] [unique_id "aqxYjOcL08BTTQixEnphkQAAAFI"]
[Thu Sep 17 15:15:56.964436 2026] [security2:error] [pid 971102:tid 971272] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/test/.env"] [unique_id "aqxYjOcL08BTTQixEnphlAAAACY"]
[Thu Sep 17 15:15:56.982840 2026] [security2:error] [pid 971102:tid 971336] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYiucL08BTTQixEnphSwAAZms"], referer: http://vagabondhiker.com/wordpress/
[Thu Sep 17 15:15:57.012511 2026] [security2:error] [pid 971102:tid 971247] [client 24.10.245.213:35123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYjOcL08BTTQixEnphkAAADVs"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:15:57.024789 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.80.249:60764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxYjecL08BTTQixEnphlQAAADY"]
[Thu Sep 17 15:15:57.028022 2026] [security2:error] [pid 971102:tid 971279] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/qa/.env"] [unique_id "aqxYjecL08BTTQixEnphlgAAAC0"]
[Thu Sep 17 15:15:57.083710 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/preview/.env"] [unique_id "aqxYjecL08BTTQixEnphmQAAAEI"]
[Thu Sep 17 15:15:57.125455 2026] [security2:error] [pid 971102:tid 971294] [client 104.28.198.244:22828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphmwAAADw"]
[Thu Sep 17 15:15:57.125626 2026] [security2:error] [pid 971102:tid 971294] [client 104.28.198.244:22828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphmwAAADw"]
[Thu Sep 17 15:15:57.152090 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/beta/.env"] [unique_id "aqxYjecL08BTTQixEnphnAAAAD4"]
[Thu Sep 17 15:15:57.224512 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/uat/.env"] [unique_id "aqxYjecL08BTTQixEnphogAAACs"]
[Thu Sep 17 15:15:57.268266 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.80.249:60770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxYjecL08BTTQixEnphpgAAAAE"]
[Thu Sep 17 15:15:57.278968 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/stage/.env"] [unique_id "aqxYjecL08BTTQixEnphpwAAAFY"]
[Thu Sep 17 15:15:57.350335 2026] [security2:error] [pid 971102:tid 971244] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/development/.env"] [unique_id "aqxYjecL08BTTQixEnphqAAAAAo"]
[Thu Sep 17 15:15:57.407874 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/production/.env"] [unique_id "aqxYjecL08BTTQixEnphqgAAAGg"]
[Thu Sep 17 15:15:57.458713 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.80.249:60784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxYjecL08BTTQixEnphqwAAACg"]
[Thu Sep 17 15:15:57.483202 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.195.25:51014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.agape-film.com"] [uri "/config/app/.env"] [unique_id "aqxYjecL08BTTQixEnphrAAAAEU"]
[Thu Sep 17 15:15:57.530947 2026] [security2:error] [pid 971102:tid 971351] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYjecL08BTTQixEnphrQAAdWY"], referer: https://vagabondhiker.com/wordpress/
[Thu Sep 17 15:15:57.538720 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.195.25:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php"] [unique_id "aqxYjecL08BTTQixEnphrwAAABM"]
[Thu Sep 17 15:15:57.651204 2026] [security2:error] [pid 971102:tid 971323] [client 185.55.149.49:54977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphsgAAAFk"]
[Thu Sep 17 15:15:57.651315 2026] [security2:error] [pid 971102:tid 971323] [client 185.55.149.49:54977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYjecL08BTTQixEnphsgAAAFk"]
[Thu Sep 17 15:15:57.713371 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.195.25:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/info.php"] [unique_id "aqxYjecL08BTTQixEnphuAAAADM"]
[Thu Sep 17 15:15:57.750447 2026] [security2:error] [pid 971102:tid 971331] [client 34.23.80.249:60792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.doodlesatheart.com"] [uri "/"] [unique_id "aqxYjecL08BTTQixEnphuQAAAGE"]
[Thu Sep 17 15:15:57.897359 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.195.25:51026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/php.php"] [unique_id "aqxYjecL08BTTQixEnphvQAAAGU"]
[Thu Sep 17 15:15:57.946461 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env"] [unique_id "aqxYjecL08BTTQixEnphwAAAABc"]
[Thu Sep 17 15:15:57.973248 2026] [security2:error] [pid 971102:tid 971251] [client 24.10.245.213:34591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYjecL08BTTQixEnphvwAAETA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818054740&hideanons=1&hideminor=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:15:58.065973 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.195.25:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/i.php"] [unique_id "aqxYjucL08BTTQixEnphxAAAACA"]
[Thu Sep 17 15:15:58.243645 2026] [security2:error] [pid 971102:tid 971255] [client 34.23.195.25:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/pi.php"] [unique_id "aqxYjucL08BTTQixEnphzgAAABU"]
[Thu Sep 17 15:15:58.439579 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.195.25:51068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/pinfo.php"] [unique_id "aqxYjucL08BTTQixEnph2AAAAEI"]
[Thu Sep 17 15:15:58.641936 2026] [security2:error] [pid 971102:tid 971318] [client 34.23.195.25:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/test.php"] [unique_id "aqxYjucL08BTTQixEnph4AAAAFQ"]
[Thu Sep 17 15:15:58.686839 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.bak"] [unique_id "aqxYjucL08BTTQixEnph4wAAAHE"]
[Thu Sep 17 15:15:58.727465 2026] [security2:error] [pid 971102:tid 971337] [client 186.105.232.15:49741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjucL08BTTQixEnph5gAAAGc"]
[Thu Sep 17 15:15:58.727585 2026] [security2:error] [pid 971102:tid 971337] [client 186.105.232.15:49741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYjucL08BTTQixEnph5gAAAGc"]
[Thu Sep 17 15:15:58.741248 2026] [security2:error] [pid 971102:tid 971258] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.backup"] [unique_id "aqxYjucL08BTTQixEnph5wAAABg"]
[Thu Sep 17 15:15:58.884247 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.old"] [unique_id "aqxYjucL08BTTQixEnph7gAAAB8"]
[Thu Sep 17 15:15:58.895342 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.195.25:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/p.php"] [unique_id "aqxYjucL08BTTQixEnph8AAAAE4"]
[Thu Sep 17 15:15:59.081248 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.195.25:51108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/debug.php"] [unique_id "aqxYj-cL08BTTQixEnpiAAAAABc"]
[Thu Sep 17 15:15:59.204155 2026] [security2:error] [pid 971102:tid 971311] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiBgAATUU"], referer: http://vagabondhiker.com/backup/
[Thu Sep 17 15:15:59.281765 2026] [security2:error] [pid 971102:tid 971348] [client 34.23.195.25:51116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiCQAAAHI"]
[Thu Sep 17 15:15:59.416127 2026] [security2:error] [pid 971102:tid 971260] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiDQAAGgE"], referer: https://vagabondhiker.com/backup/
[Thu Sep 17 15:15:59.420445 2026] [security2:error] [pid 971102:tid 971336] [client 162.241.226.11:46670] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxYj-cL08BTTQixEnpiDwAAAGY"]
[Thu Sep 17 15:15:59.463864 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.195.25:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/test/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiEgAAAEk"]
[Thu Sep 17 15:15:59.679061 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.195.25:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiGgAAACs"]
[Thu Sep 17 15:15:59.781469 2026] [security2:error] [pid 971102:tid 971345] [client 45.169.98.18:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYj-cL08BTTQixEnpiHwAAAG8"]
[Thu Sep 17 15:15:59.781586 2026] [security2:error] [pid 971102:tid 971345] [client 45.169.98.18:54630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYj-cL08BTTQixEnpiHwAAAG8"]
[Thu Sep 17 15:15:59.788565 2026] [security2:error] [pid 971102:tid 971295] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiHQAAPVw"], referer: http://vagabondhiker.com/new/
[Thu Sep 17 15:15:59.798571 2026] [security2:error] [pid 971102:tid 971344] [client 111.172.6.214:62807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5305.bluehost.com"] [uri "/index.cgi"] [unique_id "aqxYj-cL08BTTQixEnpiHgAAAG4"]
[Thu Sep 17 15:15:59.879530 2026] [security2:error] [pid 971102:tid 971250] [client 34.23.195.25:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/old/phpinfo.php"] [unique_id "aqxYj-cL08BTTQixEnpiIwAAABA"]
[Thu Sep 17 15:15:59.995249 2026] [security2:error] [pid 971102:tid 971253] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYj-cL08BTTQixEnpiJQAAE0s"], referer: https://vagabondhiker.com/new/
[Thu Sep 17 15:16:00.048735 2026] [security2:error] [pid 971102:tid 971337] [client 34.23.195.25:51174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYkOcL08BTTQixEnpiKAAAAGc"]
[Thu Sep 17 15:16:00.247473 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.195.25:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYkOcL08BTTQixEnpiMQAAACg"]
[Thu Sep 17 15:16:00.330926 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiOAAAAGg"]
[Thu Sep 17 15:16:00.331046 2026] [security2:error] [pid 971102:tid 971338] [client 154.190.208.131:42375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiOAAAAGg"]
[Thu Sep 17 15:16:00.366964 2026] [security2:error] [pid 971102:tid 971302] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkOcL08BTTQixEnpiNwAARDk"], referer: http://vagabondhiker.com/wp/
[Thu Sep 17 15:16:00.475643 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env.swp"] [unique_id "aqxYkOcL08BTTQixEnpiPwAAAFA"]
[Thu Sep 17 15:16:00.510790 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.195.25:51190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/php-info.php"] [unique_id "aqxYkOcL08BTTQixEnpiQAAAAHU"]
[Thu Sep 17 15:16:00.543593 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiQwAAAF0"]
[Thu Sep 17 15:16:00.543733 2026] [security2:error] [pid 971102:tid 971327] [client 114.198.138.124:53950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYkOcL08BTTQixEnpiQwAAAF0"]
[Thu Sep 17 15:16:00.545286 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.env~"] [unique_id "aqxYkOcL08BTTQixEnpiQgAAADA"]
[Thu Sep 17 15:16:00.574424 2026] [security2:error] [pid 971102:tid 971311] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkOcL08BTTQixEnpiQQAATSQ"], referer: https://vagabondhiker.com/wp/
[Thu Sep 17 15:16:00.697883 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:39408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpversion.php"] [unique_id "aqxYkOcL08BTTQixEnpiUgAAAFI"]
[Thu Sep 17 15:16:00.745685 2026] [security2:error] [pid 971102:tid 971235] [client 5.189.145.112:53240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxYkOcL08BTTQixEnpiWAAAAAE"], referer: binance.com
[Thu Sep 17 15:16:00.877152 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.195.25:39414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/_phpinfo.php"] [unique_id "aqxYkOcL08BTTQixEnpiZAAAAD0"]
[Thu Sep 17 15:16:00.929749 2026] [security2:error] [pid 971102:tid 971361] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkOcL08BTTQixEnpiZgAAf1Q"], referer: http://vagabondhiker.com/blog/
[Thu Sep 17 15:16:01.031925 2026] [security2:error] [pid 971102:tid 971274] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxYkecL08BTTQixEnpicgAAACg"]
[Thu Sep 17 15:16:01.056564 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.195.25:39422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/old_phpinfo.php"] [unique_id "aqxYkecL08BTTQixEnpidQAAABY"]
[Thu Sep 17 15:16:01.134519 2026] [security2:error] [pid 971102:tid 971287] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkecL08BTTQixEnpidwAANUc"], referer: https://vagabondhiker.com/blog/
[Thu Sep 17 15:16:01.223550 2026] [security2:error] [pid 971102:tid 971251] [client 34.23.195.25:39432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/server-info.php"] [unique_id "aqxYkecL08BTTQixEnpihgAAABE"]
[Thu Sep 17 15:16:01.296845 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/app/.env"] [unique_id "aqxYkecL08BTTQixEnpijwAAAHg"]
[Thu Sep 17 15:16:01.357747 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/apps/.env"] [unique_id "aqxYkecL08BTTQixEnpikgAAAEU"]
[Thu Sep 17 15:16:01.402409 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.195.25:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/server-status.php"] [unique_id "aqxYkecL08BTTQixEnpilgAAAFo"]
[Thu Sep 17 15:16:01.415531 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/.env"] [unique_id "aqxYkecL08BTTQixEnpilwAAAGs"]
[Thu Sep 17 15:16:01.473453 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxYkecL08BTTQixEnpinQAAAC4"]
[Thu Sep 17 15:16:01.475618 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/web/.env"] [unique_id "aqxYkecL08BTTQixEnpingAAAAY"]
[Thu Sep 17 15:16:01.491437 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxYkecL08BTTQixEnpinwAAAEM"]
[Thu Sep 17 15:16:01.501795 2026] [security2:error] [pid 971102:tid 971286] [client 164.92.170.149:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkecL08BTTQixEnpimwAANEI"], referer: http://vagabondhiker.com/old/
[Thu Sep 17 15:16:01.534708 2026] [security2:error] [pid 971102:tid 971279] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/site/.env"] [unique_id "aqxYkecL08BTTQixEnpiogAAAC0"]
[Thu Sep 17 15:16:01.580285 2026] [security2:error] [pid 971102:tid 971318] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxYkecL08BTTQixEnpipQAAAFQ"]
[Thu Sep 17 15:16:01.598724 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/public/.env"] [unique_id "aqxYkecL08BTTQixEnpiqAAAAEI"]
[Thu Sep 17 15:16:01.710755 2026] [security2:error] [pid 971102:tid 971347] [client 164.92.170.149:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxYkecL08BTTQixEnpisAAAcTY"], referer: https://vagabondhiker.com/old/
[Thu Sep 17 15:16:01.802473 2026] [security2:error] [pid 971102:tid 971241] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/backend/.env"] [unique_id "aqxYkecL08BTTQixEnpiuwAAAAc"]
[Thu Sep 17 15:16:01.860943 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/server/.env"] [unique_id "aqxYkecL08BTTQixEnpivwAAADU"]
[Thu Sep 17 15:16:01.895778 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.195.25:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYkecL08BTTQixEnpiwQAAAFA"]
[Thu Sep 17 15:16:01.920185 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/frontend/.env"] [unique_id "aqxYkecL08BTTQixEnpiwgAAADA"]
[Thu Sep 17 15:16:01.981336 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/src/.env"] [unique_id "aqxYkecL08BTTQixEnpixgAAAF8"]
[Thu Sep 17 15:16:02.042091 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/core/.env"] [unique_id "aqxYkucL08BTTQixEnpiywAAAFg"]
[Thu Sep 17 15:16:02.081555 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.195.25:39464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi0AAAAH0"]
[Thu Sep 17 15:16:02.107492 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/core/app/.env"] [unique_id "aqxYkucL08BTTQixEnpi0wAAAB0"]
[Thu Sep 17 15:16:02.166511 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/config/.env"] [unique_id "aqxYkucL08BTTQixEnpi2wAAAGs"]
[Thu Sep 17 15:16:02.225213 2026] [security2:error] [pid 971102:tid 971268] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/private/.env"] [unique_id "aqxYkucL08BTTQixEnpi3QAAACI"]
[Thu Sep 17 15:16:02.255739 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.195.25:39472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi4QAAADE"]
[Thu Sep 17 15:16:02.284020 2026] [security2:error] [pid 971102:tid 971271] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/application/.env"] [unique_id "aqxYkucL08BTTQixEnpi5QAAACU"]
[Thu Sep 17 15:16:02.322983 2026] [security2:error] [pid 971102:tid 971316] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYkucL08BTTQixEnpi2QAAUg0"], referer: http://www.radtechresourcegroup.com/backup/
[Thu Sep 17 15:16:02.344725 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/bootstrap/.env"] [unique_id "aqxYkucL08BTTQixEnpi6QAAAAU"]
[Thu Sep 17 15:16:02.417557 2026] [security2:error] [pid 971102:tid 971318] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/database/.env"] [unique_id "aqxYkucL08BTTQixEnpi6wAAAFQ"]
[Thu Sep 17 15:16:02.446040 2026] [security2:error] [pid 971102:tid 971244] [client 34.23.195.25:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi7QAAAAo"]
[Thu Sep 17 15:16:02.477898 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/storage/.env"] [unique_id "aqxYkucL08BTTQixEnpi8AAAAAM"]
[Thu Sep 17 15:16:02.507184 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxYkucL08BTTQixEnpi8gAAAH8"]
[Thu Sep 17 15:16:02.523067 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxYkucL08BTTQixEnpi8wAAAGk"]
[Thu Sep 17 15:16:02.537384 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/var/www/.env"] [unique_id "aqxYkucL08BTTQixEnpi9AAAAFU"]
[Thu Sep 17 15:16:02.596386 2026] [security2:error] [pid 971102:tid 971360] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/var/www/html/.env"] [unique_id "aqxYkucL08BTTQixEnpi-AAAAH4"]
[Thu Sep 17 15:16:02.622393 2026] [security2:error] [pid 971102:tid 971356] [client 34.23.195.25:39490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpi-wAAAHo"]
[Thu Sep 17 15:16:02.655723 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/current/.env"] [unique_id "aqxYkucL08BTTQixEnpi_wAAADk"]
[Thu Sep 17 15:16:02.721162 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/release/.env"] [unique_id "aqxYkucL08BTTQixEnpjBQAAAFE"]
[Thu Sep 17 15:16:02.785704 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/releases/.env"] [unique_id "aqxYkucL08BTTQixEnpjBwAAADU"]
[Thu Sep 17 15:16:02.787763 2026] [security2:error] [pid 971102:tid 971241] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYkucL08BTTQixEnpi_gAABzQ"], referer: http://www.radtechresourcegroup.com/new/
[Thu Sep 17 15:16:02.835128 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.195.25:39502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYkucL08BTTQixEnpjCwAAABY"]
[Thu Sep 17 15:16:02.847123 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/shared/.env"] [unique_id "aqxYkucL08BTTQixEnpjDAAAAEo"]
[Thu Sep 17 15:16:02.910984 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/deploy/.env"] [unique_id "aqxYkucL08BTTQixEnpjDQAAAHU"]
[Thu Sep 17 15:16:02.977878 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/build/.env"] [unique_id "aqxYkucL08BTTQixEnpjEQAAAF8"]
[Thu Sep 17 15:16:03.003090 2026] [security2:error] [pid 971102:tid 971276] [client 34.23.195.25:39506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxYk-cL08BTTQixEnpjEwAAACo"]
[Thu Sep 17 15:16:03.037715 2026] [security2:error] [pid 971102:tid 971261] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/dist/.env"] [unique_id "aqxYk-cL08BTTQixEnpjFQAAABs"]
[Thu Sep 17 15:16:03.092691 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/public_html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjHAAAAGo"]
[Thu Sep 17 15:16:03.112681 2026] [security2:error] [pid 971102:tid 971336] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxYk-cL08BTTQixEnpjHgAAAGY"]
[Thu Sep 17 15:16:03.133102 2026] [security2:error] [pid 971102:tid 971262] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxYk-cL08BTTQixEnpjIAAAABw"]
[Thu Sep 17 15:16:03.140112 2026] [authz_core:error] [pid 971102:tid 971343] [client 172.239.147.162:62345] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:03.147418 2026] [security2:error] [pid 971102:tid 971267] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxYk-cL08BTTQixEnpjIgAAACE"]
[Thu Sep 17 15:16:03.150228 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/htdocs/.env"] [unique_id "aqxYk-cL08BTTQixEnpjIwAAAA8"]
[Thu Sep 17 15:16:03.163810 2026] [security2:error] [pid 971102:tid 971273] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxYk-cL08BTTQixEnpjJAAAACc"]
[Thu Sep 17 15:16:03.184997 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxYk-cL08BTTQixEnpjJQAAAEg"]
[Thu Sep 17 15:16:03.186387 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.195.25:39520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php.old"] [unique_id "aqxYk-cL08BTTQixEnpjJgAAACk"]
[Thu Sep 17 15:16:03.200244 2026] [security2:error] [pid 971102:tid 971268] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxYk-cL08BTTQixEnpjJwAAACI"]
[Thu Sep 17 15:16:03.207793 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/www/.env"] [unique_id "aqxYk-cL08BTTQixEnpjKAAAADE"]
[Thu Sep 17 15:16:03.247903 2026] [security2:error] [pid 971102:tid 971272] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYk-cL08BTTQixEnpjGgAAJkM"], referer: http://www.radtechresourcegroup.com/wordpress/
[Thu Sep 17 15:16:03.268270 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjLQAAAC4"]
[Thu Sep 17 15:16:03.282390 2026] [security2:error] [pid 971102:tid 971288] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxYk-cL08BTTQixEnpjLgAAADY"]
[Thu Sep 17 15:16:03.296045 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxYk-cL08BTTQixEnpjLwAAAEM"]
[Thu Sep 17 15:16:03.316529 2026] [security2:error] [pid 971102:tid 971264] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxYk-cL08BTTQixEnpjMAAAAB4"]
[Thu Sep 17 15:16:03.327906 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/live/.env"] [unique_id "aqxYk-cL08BTTQixEnpjMgAAAAU"]
[Thu Sep 17 15:16:03.329709 2026] [security2:error] [pid 971102:tid 971330] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxYk-cL08BTTQixEnpjMwAAAGA"]
[Thu Sep 17 15:16:03.343051 2026] [security2:error] [pid 971102:tid 971318] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxYk-cL08BTTQixEnpjNgAAAFQ"]
[Thu Sep 17 15:16:03.355267 2026] [security2:error] [pid 971102:tid 971316] [client 34.23.195.25:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php~"] [unique_id "aqxYk-cL08BTTQixEnpjNwAAAFI"]
[Thu Sep 17 15:16:03.376959 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxYk-cL08BTTQixEnpjOQAAAD4"]
[Thu Sep 17 15:16:03.386617 2026] [security2:error] [pid 971102:tid 971295] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/prod/.env"] [unique_id "aqxYk-cL08BTTQixEnpjOgAAAD0"]
[Thu Sep 17 15:16:03.408343 2026] [security2:error] [pid 971102:tid 971244] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxYk-cL08BTTQixEnpjPAAAAAo"]
[Thu Sep 17 15:16:03.444446 2026] [security2:error] [pid 971102:tid 971237] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxYk-cL08BTTQixEnpjPQAAAAM"]
[Thu Sep 17 15:16:03.446282 2026] [security2:error] [pid 971102:tid 971250] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/dev/.env"] [unique_id "aqxYk-cL08BTTQixEnpjPgAAABA"]
[Thu Sep 17 15:16:03.477615 2026] [authz_core:error] [pid 971102:tid 971240] [client 172.239.147.162:56593] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:03.480933 2026] [security2:error] [pid 971102:tid 971337] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQAAAAGc"]
[Thu Sep 17 15:16:03.495060 2026] [security2:error] [pid 971102:tid 971305] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQQAAAEc"]
[Thu Sep 17 15:16:03.513403 2026] [security2:error] [pid 971102:tid 971299] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQgAAAEE"]
[Thu Sep 17 15:16:03.514959 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/staging/.env"] [unique_id "aqxYk-cL08BTTQixEnpjQwAAABQ"]
[Thu Sep 17 15:16:03.529910 2026] [security2:error] [pid 971102:tid 971285] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxYk-cL08BTTQixEnpjRAAAADM"]
[Thu Sep 17 15:16:03.535929 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.195.25:39538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/info.php.bak"] [unique_id "aqxYk-cL08BTTQixEnpjRQAAAGQ"]
[Thu Sep 17 15:16:03.545340 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxYk-cL08BTTQixEnpjRgAAAGk"]
[Thu Sep 17 15:16:03.560404 2026] [security2:error] [pid 971102:tid 971258] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSAAAABg"]
[Thu Sep 17 15:16:03.576473 2026] [security2:error] [pid 971102:tid 971323] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSQAAAFk"]
[Thu Sep 17 15:16:03.577560 2026] [security2:error] [pid 971102:tid 971304] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/opt/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSgAAAEY"]
[Thu Sep 17 15:16:03.592609 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxYk-cL08BTTQixEnpjSwAAAHE"]
[Thu Sep 17 15:16:03.607734 2026] [security2:error] [pid 971102:tid 971289] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxYk-cL08BTTQixEnpjTAAAADc"]
[Thu Sep 17 15:16:03.623232 2026] [security2:error] [pid 971102:tid 971356] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxYk-cL08BTTQixEnpjTQAAAHo"]
[Thu Sep 17 15:16:03.637884 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/laravel/.env"] [unique_id "aqxYk-cL08BTTQixEnpjTwAAADk"]
[Thu Sep 17 15:16:03.641403 2026] [security2:error] [pid 971102:tid 971342] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxYk-cL08BTTQixEnpjUAAAAGw"]
[Thu Sep 17 15:16:03.664641 2026] [security2:error] [pid 971102:tid 971313] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxYk-cL08BTTQixEnpjUgAAAE8"]
[Thu Sep 17 15:16:03.687735 2026] [security2:error] [pid 971102:tid 971242] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxYk-cL08BTTQixEnpjVAAAAAg"]
[Thu Sep 17 15:16:03.698158 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/symfony/.env"] [unique_id "aqxYk-cL08BTTQixEnpjVQAAAFE"]
[Thu Sep 17 15:16:03.711787 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.195.25:39540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/phpinfo.php.save"] [unique_id "aqxYk-cL08BTTQixEnpjVgAAACQ"]
[Thu Sep 17 15:16:03.713770 2026] [security2:error] [pid 971102:tid 971319] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYk-cL08BTTQixEnpjRwAAVTI"], referer: http://www.radtechresourcegroup.com/blog/
[Thu Sep 17 15:16:03.719145 2026] [security2:error] [pid 971102:tid 971287] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjVwAAADU"]
[Thu Sep 17 15:16:03.744417 2026] [security2:error] [pid 971102:tid 971332] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxYk-cL08BTTQixEnpjWAAAAGI"]
[Thu Sep 17 15:16:03.760807 2026] [security2:error] [pid 971102:tid 971335] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/wordpress/.env"] [unique_id "aqxYk-cL08BTTQixEnpjWgAAAGU"]
[Thu Sep 17 15:16:03.762508 2026] [security2:error] [pid 971102:tid 971293] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxYk-cL08BTTQixEnpjWwAAADs"]
[Thu Sep 17 15:16:03.790787 2026] [security2:error] [pid 971102:tid 971256] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXAAAABY"]
[Thu Sep 17 15:16:03.809503 2026] [security2:error] [pid 971102:tid 971308] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXQAAAEo"]
[Thu Sep 17 15:16:03.822486 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/wp/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXgAAAFA"]
[Thu Sep 17 15:16:03.826493 2026] [security2:error] [pid 971102:tid 971351] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxYk-cL08BTTQixEnpjXwAAAHU"]
[Thu Sep 17 15:16:03.841346 2026] [security2:error] [pid 971102:tid 971355] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxYk-cL08BTTQixEnpjYAAAAHk"]
[Thu Sep 17 15:16:03.863065 2026] [security2:error] [pid 971102:tid 971251] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxYk-cL08BTTQixEnpjYQAAABE"]
[Thu Sep 17 15:16:03.876566 2026] [security2:error] [pid 971102:tid 971327] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxYk-cL08BTTQixEnpjYwAAAF0"]
[Thu Sep 17 15:16:03.883160 2026] [security2:error] [pid 971102:tid 971331] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cms/.env"] [unique_id "aqxYk-cL08BTTQixEnpjZAAAAGE"]
[Thu Sep 17 15:16:03.885267 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.195.25:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxYk-cL08BTTQixEnpjZQAAADA"]
[Thu Sep 17 15:16:03.897562 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxYk-cL08BTTQixEnpjZgAAAHM"]
[Thu Sep 17 15:16:03.922557 2026] [security2:error] [pid 971102:tid 971257] [client 34.94.22.173:40380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxYk-cL08BTTQixEnpjZwAAABc"]
[Thu Sep 17 15:16:03.946841 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/drupal/.env"] [unique_id "aqxYk-cL08BTTQixEnpjaAAAAF8"]
[Thu Sep 17 15:16:04.014103 2026] [security2:error] [pid 971102:tid 971348] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/joomla/.env"] [unique_id "aqxYlOcL08BTTQixEnpjagAAAHI"]
[Thu Sep 17 15:16:04.025496 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxYlOcL08BTTQixEnpjbAAAACA"]
[Thu Sep 17 15:16:04.050806 2026] [security2:error] [pid 971102:tid 971353] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxYlOcL08BTTQixEnpjbQAAAHc"]
[Thu Sep 17 15:16:04.060469 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.195.25:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjbgAAAAA"]
[Thu Sep 17 15:16:04.074775 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/magento/.env"] [unique_id "aqxYlOcL08BTTQixEnpjcAAAAB0"]
[Thu Sep 17 15:16:04.075314 2026] [security2:error] [pid 971102:tid 971260] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxYlOcL08BTTQixEnpjbwAAABo"]
[Thu Sep 17 15:16:04.096969 2026] [security2:error] [pid 971102:tid 971346] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxYlOcL08BTTQixEnpjcQAAAHA"]
[Thu Sep 17 15:16:04.130673 2026] [security2:error] [pid 971102:tid 971359] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxYlOcL08BTTQixEnpjcgAAAH0"]
[Thu Sep 17 15:16:04.169901 2026] [security2:error] [pid 971102:tid 971345] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxYlOcL08BTTQixEnpjdgAAAG8"]
[Thu Sep 17 15:16:04.172898 2026] [security2:error] [pid 971102:tid 971322] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYlOcL08BTTQixEnpjawAAWGU"], referer: http://www.radtechresourcegroup.com/old/
[Thu Sep 17 15:16:04.197748 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxYlOcL08BTTQixEnpjdwAAAEk"]
[Thu Sep 17 15:16:04.227297 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxYlOcL08BTTQixEnpjeQAAAEg"]
[Thu Sep 17 15:16:04.250804 2026] [security2:error] [pid 971102:tid 971268] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxYlOcL08BTTQixEnpjegAAACI"]
[Thu Sep 17 15:16:04.254055 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.195.25:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjewAAAA8"]
[Thu Sep 17 15:16:04.273159 2026] [security2:error] [pid 971102:tid 971283] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxYlOcL08BTTQixEnpjfAAAADE"]
[Thu Sep 17 15:16:04.281567 2026] [security2:error] [pid 971102:tid 971273] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/shopify/.env"] [unique_id "aqxYlOcL08BTTQixEnpjfgAAACc"]
[Thu Sep 17 15:16:04.296474 2026] [security2:error] [pid 971102:tid 971290] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxYlOcL08BTTQixEnpjfwAAADg"]
[Thu Sep 17 15:16:04.318111 2026] [security2:error] [pid 971102:tid 971277] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxYlOcL08BTTQixEnpjgQAAACs"]
[Thu Sep 17 15:16:04.339972 2026] [security2:error] [pid 971102:tid 971344] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxYlOcL08BTTQixEnpjgwAAAG4"]
[Thu Sep 17 15:16:04.340772 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/prestashop/.env"] [unique_id "aqxYlOcL08BTTQixEnpjhAAAACw"]
[Thu Sep 17 15:16:04.363026 2026] [security2:error] [pid 971102:tid 971321] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjhQAAAFc"]
[Thu Sep 17 15:16:04.396898 2026] [security2:error] [pid 971102:tid 971350] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjhgAAAHQ"]
[Thu Sep 17 15:16:04.404976 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/codeigniter/.env"] [unique_id "aqxYlOcL08BTTQixEnpjiAAAAFo"]
[Thu Sep 17 15:16:04.416533 2026] [security2:error] [pid 971102:tid 971341] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxYlOcL08BTTQixEnpjiQAAAGs"]
[Thu Sep 17 15:16:04.436981 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjigAAAEM"]
[Thu Sep 17 15:16:04.443942 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.195.25:39574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjiwAAAAE"]
[Thu Sep 17 15:16:04.458561 2026] [security2:error] [pid 971102:tid 971239] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjjAAAAAU"]
[Thu Sep 17 15:16:04.468595 2026] [security2:error] [pid 971102:tid 971318] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cakephp/.env"] [unique_id "aqxYlOcL08BTTQixEnpjjQAAAFQ"]
[Thu Sep 17 15:16:04.481492 2026] [security2:error] [pid 971102:tid 971316] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxYlOcL08BTTQixEnpjjgAAAFI"]
[Thu Sep 17 15:16:04.509207 2026] [security2:error] [pid 971102:tid 971286] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkAAAADQ"]
[Thu Sep 17 15:16:04.530997 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/zend/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkQAAAF4"]
[Thu Sep 17 15:16:04.537065 2026] [security2:error] [pid 971102:tid 971237] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkgAAAAM"]
[Thu Sep 17 15:16:04.559360 2026] [security2:error] [pid 971102:tid 971250] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxYlOcL08BTTQixEnpjkwAAABA"]
[Thu Sep 17 15:16:04.584670 2026] [security2:error] [pid 971102:tid 971305] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxYlOcL08BTTQixEnpjlAAAAEc"]
[Thu Sep 17 15:16:04.590523 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/yii/.env"] [unique_id "aqxYlOcL08BTTQixEnpjlQAAAEE"]
[Thu Sep 17 15:16:04.591461 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:62733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYlOcL08BTTQixEnpjlgAAAAs"]
[Thu Sep 17 15:16:04.592840 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:62733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYlOcL08BTTQixEnpjlgAAAAs"]
[Thu Sep 17 15:16:04.608811 2026] [security2:error] [pid 971102:tid 971254] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxYlOcL08BTTQixEnpjlwAAABQ"]
[Thu Sep 17 15:16:04.633380 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxYlOcL08BTTQixEnpjmAAAAH8"]
[Thu Sep 17 15:16:04.635869 2026] [security2:error] [pid 971102:tid 971337] [client 34.23.195.25:39580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjmQAAAGc"]
[Thu Sep 17 15:16:04.649019 2026] [security2:error] [pid 971102:tid 971296] [client 209.38.197.191:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.radtechresourcegroup.com"] [uri "/index.php"] [unique_id "aqxYlOcL08BTTQixEnpjjwAAPhc"], referer: http://www.radtechresourcegroup.com/wp/
[Thu Sep 17 15:16:04.650131 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/laravel5/.env"] [unique_id "aqxYlOcL08BTTQixEnpjmwAAAGQ"]
[Thu Sep 17 15:16:04.653072 2026] [security2:error] [pid 971102:tid 971339] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxYlOcL08BTTQixEnpjnAAAAGk"]
[Thu Sep 17 15:16:04.678529 2026] [security2:error] [pid 971102:tid 971323] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxYlOcL08BTTQixEnpjoAAAAFk"]
[Thu Sep 17 15:16:04.703339 2026] [authz_core:error] [pid 971102:tid 971330] [client 172.239.147.162:51894] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:04.712107 2026] [security2:error] [pid 971102:tid 971243] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxYlOcL08BTTQixEnpjogAAAAk"]
[Thu Sep 17 15:16:04.712107 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjoQAAAHE"]
[Thu Sep 17 15:16:04.739301 2026] [security2:error] [pid 971102:tid 971289] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxYlOcL08BTTQixEnpjowAAADc"]
[Thu Sep 17 15:16:04.760347 2026] [security2:error] [pid 971102:tid 971356] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxYlOcL08BTTQixEnpjpAAAAHo"]
[Thu Sep 17 15:16:04.766984 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjpQAAADk"]
[Thu Sep 17 15:16:04.788822 2026] [security2:error] [pid 971102:tid 971342] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxYlOcL08BTTQixEnpjpgAAAGw"]
[Thu Sep 17 15:16:04.814420 2026] [security2:error] [pid 971102:tid 971313] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxYlOcL08BTTQixEnpjqAAAAE8"]
[Thu Sep 17 15:16:04.830444 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/v3/.env"] [unique_id "aqxYlOcL08BTTQixEnpjqgAAAAY"]
[Thu Sep 17 15:16:04.838324 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.195.25:39596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/www/phpinfo.php"] [unique_id "aqxYlOcL08BTTQixEnpjqwAAABM"]
[Thu Sep 17 15:16:04.847424 2026] [security2:error] [pid 971102:tid 971360] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrAAAAH4"]
[Thu Sep 17 15:16:04.868810 2026] [security2:error] [pid 971102:tid 971242] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrQAAAAg"]
[Thu Sep 17 15:16:04.891366 2026] [security2:error] [pid 971102:tid 971312] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrgAAAE4"]
[Thu Sep 17 15:16:04.892490 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/v1/.env"] [unique_id "aqxYlOcL08BTTQixEnpjrwAAAFE"]
[Thu Sep 17 15:16:04.918405 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxYlOcL08BTTQixEnpjsAAAACQ"]
[Thu Sep 17 15:16:04.947804 2026] [security2:error] [pid 971102:tid 971319] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxYlOcL08BTTQixEnpjsQAAAFU"]
[Thu Sep 17 15:16:04.951957 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/v2/.env"] [unique_id "aqxYlOcL08BTTQixEnpjsgAAADU"]
[Thu Sep 17 15:16:04.971470 2026] [security2:error] [pid 971102:tid 971293] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxYlOcL08BTTQixEnpjtAAAADs"]
[Thu Sep 17 15:16:04.989967 2026] [security2:error] [pid 971102:tid 971265] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxYlOcL08BTTQixEnpjtQAAAB8"]
[Thu Sep 17 15:16:05.005463 2026] [security2:error] [pid 971102:tid 971252] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/rest/.env"] [unique_id "aqxYlecL08BTTQixEnpjtgAAABI"]
[Thu Sep 17 15:16:05.011259 2026] [security2:error] [pid 971102:tid 971308] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjtwAAAEo"]
[Thu Sep 17 15:16:05.015927 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.195.25:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpjuAAAAGI"]
[Thu Sep 17 15:16:05.031500 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxYlecL08BTTQixEnpjuQAAAFA"]
[Thu Sep 17 15:16:05.055600 2026] [security2:error] [pid 971102:tid 971351] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxYlecL08BTTQixEnpjugAAAHU"]
[Thu Sep 17 15:16:05.067831 2026] [security2:error] [pid 971102:tid 971355] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/graphql/.env"] [unique_id "aqxYlecL08BTTQixEnpjuwAAAHk"]
[Thu Sep 17 15:16:05.082223 2026] [security2:error] [pid 971102:tid 971327] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxYlecL08BTTQixEnpjvAAAAF0"]
[Thu Sep 17 15:16:05.107767 2026] [security2:error] [pid 971102:tid 971311] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxYlecL08BTTQixEnpjvQAAAE0"]
[Thu Sep 17 15:16:05.122630 2026] [security2:error] [pid 971102:tid 971282] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/gateway/.env"] [unique_id "aqxYlecL08BTTQixEnpjvwAAADA"]
[Thu Sep 17 15:16:05.123690 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxYlecL08BTTQixEnpjwAAAAHM"]
[Thu Sep 17 15:16:05.128606 2026] [cgid:error] [pid 971102:tid 971331] [client 66.132.172.221:5310] AH01265: stderr from /home3/sportsg2/public_html/website_3f56e26b/cgi-bin/: attempt to invoke directory as script, referer: http://mail.katcornetta.com:80/cgi-bin
[Thu Sep 17 15:16:05.143387 2026] [security2:error] [pid 971102:tid 971338] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxYlecL08BTTQixEnpjwgAAAGg"]
[Thu Sep 17 15:16:05.175946 2026] [security2:error] [pid 971102:tid 971269] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxYlecL08BTTQixEnpjxQAAACM"]
[Thu Sep 17 15:16:05.180280 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/microservice/.env"] [unique_id "aqxYlecL08BTTQixEnpjxgAAAF8"]
[Thu Sep 17 15:16:05.191264 2026] [security2:error] [pid 971102:tid 971241] [client 34.23.195.25:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpjxwAAAAc"]
[Thu Sep 17 15:16:05.206552 2026] [security2:error] [pid 971102:tid 971261] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjyQAAABs"]
[Thu Sep 17 15:16:05.224948 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjzQAAACA"]
[Thu Sep 17 15:16:05.233912 2026] [security2:error] [pid 971102:tid 971255] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/service/.env"] [unique_id "aqxYlecL08BTTQixEnpjzgAAABU"]
[Thu Sep 17 15:16:05.235682 2026] [authz_core:error] [pid 971102:tid 971251] [client 172.239.147.162:64138] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:16:05.244959 2026] [security2:error] [pid 971102:tid 971340] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxYlecL08BTTQixEnpjzwAAAGo"]
[Thu Sep 17 15:16:05.264619 2026] [security2:error] [pid 971102:tid 971260] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxYlecL08BTTQixEnpj0gAAABo"]
[Thu Sep 17 15:16:05.281374 2026] [security2:error] [pid 971102:tid 971292] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxYlecL08BTTQixEnpj1AAAADo"]
[Thu Sep 17 15:16:05.288252 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/v3/.env"] [unique_id "aqxYlecL08BTTQixEnpj1QAAAEw"]
[Thu Sep 17 15:16:05.299510 2026] [security2:error] [pid 971102:tid 971359] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxYlecL08BTTQixEnpj1gAAAH0"]
[Thu Sep 17 15:16:05.328864 2026] [security2:error] [pid 971102:tid 971322] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxYlecL08BTTQixEnpj1wAAAFg"]
[Thu Sep 17 15:16:05.349214 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxYlecL08BTTQixEnpj2AAAAEk"]
[Thu Sep 17 15:16:05.350728 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/dev/.env"] [unique_id "aqxYlecL08BTTQixEnpj2QAAAEg"]
[Thu Sep 17 15:16:05.366236 2026] [security2:error] [pid 971102:tid 971268] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxYlecL08BTTQixEnpj2gAAACI"]
[Thu Sep 17 15:16:05.378496 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.195.25:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/site/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpj2wAAAG8"]
[Thu Sep 17 15:16:05.398410 2026] [security2:error] [pid 971102:tid 971275] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxYlecL08BTTQixEnpj3AAAACk"]
[Thu Sep 17 15:16:05.414092 2026] [security2:error] [pid 971102:tid 971273] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/api/staging/.env"] [unique_id "aqxYlecL08BTTQixEnpj3QAAACc"]
[Thu Sep 17 15:16:05.418150 2026] [security2:error] [pid 971102:tid 971290] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxYlecL08BTTQixEnpj3gAAADg"]
[Thu Sep 17 15:16:05.443240 2026] [security2:error] [pid 971102:tid 971272] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxYlecL08BTTQixEnpj3wAAACY"]
[Thu Sep 17 15:16:05.468005 2026] [security2:error] [pid 971102:tid 971358] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxYlecL08BTTQixEnpj4AAAAHw"]
[Thu Sep 17 15:16:05.468498 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/vendor/.env"] [unique_id "aqxYlecL08BTTQixEnpj4QAAACs"]
[Thu Sep 17 15:16:05.486505 2026] [security2:error] [pid 971102:tid 971344] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxYlecL08BTTQixEnpj4gAAAG4"]
[Thu Sep 17 15:16:05.517845 2026] [security2:error] [pid 971102:tid 971294] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxYlecL08BTTQixEnpj4wAAADw"]
[Thu Sep 17 15:16:05.523931 2026] [security2:error] [pid 971102:tid 971321] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/lib/.env"] [unique_id "aqxYlecL08BTTQixEnpj5AAAAFc"]
[Thu Sep 17 15:16:05.536085 2026] [security2:error] [pid 971102:tid 971238] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxYlecL08BTTQixEnpj5gAAAAQ"]
[Thu Sep 17 15:16:05.563154 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.195.25:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpj6AAAACw"]
[Thu Sep 17 15:16:05.565164 2026] [security2:error] [pid 971102:tid 971262] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxYlecL08BTTQixEnpj6QAAABw"]
[Thu Sep 17 15:16:05.581842 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/resources/.env"] [unique_id "aqxYlecL08BTTQixEnpj6gAAAHQ"]
[Thu Sep 17 15:16:05.601637 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxYlecL08BTTQixEnpj6wAAAC4"]
[Thu Sep 17 15:16:05.623066 2026] [security2:error] [pid 971102:tid 971324] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxYlecL08BTTQixEnpj7AAAAFo"]
[Thu Sep 17 15:16:05.634919 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/assets/.env"] [unique_id "aqxYlecL08BTTQixEnpj8AAAAAE"]
[Thu Sep 17 15:16:05.645930 2026] [security2:error] [pid 971102:tid 971318] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxYlecL08BTTQixEnpj8QAAAFQ"]
[Thu Sep 17 15:16:05.662677 2026] [security2:error] [pid 971102:tid 971295] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxYlecL08BTTQixEnpj8wAAAD0"]
[Thu Sep 17 15:16:05.678463 2026] [security2:error] [pid 971102:tid 971244] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxYlecL08BTTQixEnpj9AAAAAo"]
[Thu Sep 17 15:16:05.688311 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/uploads/.env"] [unique_id "aqxYlecL08BTTQixEnpj9gAAAF4"]
[Thu Sep 17 15:16:05.722501 2026] [security2:error] [pid 971102:tid 971250] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxYlecL08BTTQixEnpj9wAAABA"]
[Thu Sep 17 15:16:05.745252 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/internal/.env"] [unique_id "aqxYlecL08BTTQixEnpj-AAAAEE"]
[Thu Sep 17 15:16:05.748597 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.195.25:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpj-QAAAAM"]
[Thu Sep 17 15:16:05.751985 2026] [security2:error] [pid 971102:tid 971245] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxYlecL08BTTQixEnpj-gAAAAs"]
[Thu Sep 17 15:16:05.776448 2026] [security2:error] [pid 971102:tid 971254] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxYlecL08BTTQixEnpj-wAAABQ"]
[Thu Sep 17 15:16:05.797402 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxYlecL08BTTQixEnpj_AAAAH8"]
[Thu Sep 17 15:16:05.809998 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/tools/.env"] [unique_id "aqxYlecL08BTTQixEnpj_QAAAD4"]
[Thu Sep 17 15:16:05.886697 2026] [security2:error] [pid 971102:tid 971342] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/scripts/.env"] [unique_id "aqxYlecL08BTTQixEnpkAgAAAGw"]
[Thu Sep 17 15:16:05.934430 2026] [security2:error] [pid 971102:tid 971302] [client 34.23.195.25:39658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYlecL08BTTQixEnpkBgAAAEQ"]
[Thu Sep 17 15:16:05.952240 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/bin/.env"] [unique_id "aqxYlecL08BTTQixEnpkBwAAAFw"]
[Thu Sep 17 15:16:05.952550 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:41856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxYlecL08BTTQixEnpkCAAAACQ"]
[Thu Sep 17 15:16:06.006954 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sbin/.env"] [unique_id "aqxYlucL08BTTQixEnpkCQAAAB8"]
[Thu Sep 17 15:16:06.026948 2026] [security2:error] [pid 971102:tid 971293] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxYlucL08BTTQixEnpkCgAAADs"]
[Thu Sep 17 15:16:06.052755 2026] [security2:error] [pid 971102:tid 971325] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxYlucL08BTTQixEnpkCwAAAFs"]
[Thu Sep 17 15:16:06.112749 2026] [security2:error] [pid 971102:tid 971285] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/local/.env"] [unique_id "aqxYlucL08BTTQixEnpkDAAAADM"]
[Thu Sep 17 15:16:06.116425 2026] [security2:error] [pid 971102:tid 971256] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxYlucL08BTTQixEnpkDQAAABY"]
[Thu Sep 17 15:16:06.129388 2026] [security2:error] [pid 971102:tid 971258] [client 34.23.195.25:39668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/core/phpinfo.php"] [unique_id "aqxYlucL08BTTQixEnpkDgAAABg"]
[Thu Sep 17 15:16:06.132550 2026] [security2:error] [pid 971102:tid 971252] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxYlucL08BTTQixEnpkDwAAABI"]
[Thu Sep 17 15:16:06.147910 2026] [security2:error] [pid 971102:tid 971332] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxYlucL08BTTQixEnpkEQAAAGI"]
[Thu Sep 17 15:16:06.163450 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxYlucL08BTTQixEnpkEgAAAFA"]
[Thu Sep 17 15:16:06.165914 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/portal/.env"] [unique_id "aqxYlucL08BTTQixEnpkEwAAAHU"]
[Thu Sep 17 15:16:06.179762 2026] [security2:error] [pid 971102:tid 971355] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxYlucL08BTTQixEnpkFAAAAHk"]
[Thu Sep 17 15:16:06.197426 2026] [security2:error] [pid 971102:tid 971282] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxYlucL08BTTQixEnpkFwAAADA"]
[Thu Sep 17 15:16:06.211821 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxYlucL08BTTQixEnpkGAAAAHM"]
[Thu Sep 17 15:16:06.224732 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/dashboard/.env"] [unique_id "aqxYlucL08BTTQixEnpkGQAAAGg"]
[Thu Sep 17 15:16:06.235646 2026] [security2:error] [pid 971102:tid 971335] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxYlucL08BTTQixEnpkGgAAAGU"]
[Thu Sep 17 15:16:06.260987 2026] [security2:error] [pid 971102:tid 971241] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxYlucL08BTTQixEnpkHAAAAAc"]
[Thu Sep 17 15:16:06.286937 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkHQAAACA"]
[Thu Sep 17 15:16:06.289480 2026] [security2:error] [pid 971102:tid 971255] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxYlucL08BTTQixEnpkHgAAABU"]
[Thu Sep 17 15:16:06.298039 2026] [security2:error] [pid 971102:tid 971269] [client 34.23.195.25:39684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.195.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.agape-film.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxYlucL08BTTQixEnpkIAAAACM"]
[Thu Sep 17 15:16:06.306953 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxYlucL08BTTQixEnpkIQAAAAA"]
[Thu Sep 17 15:16:06.327140 2026] [security2:error] [pid 971102:tid 971260] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxYlucL08BTTQixEnpkIgAAABo"]
[Thu Sep 17 15:16:06.344159 2026] [security2:error] [pid 971102:tid 971310] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxYlucL08BTTQixEnpkJAAAAEw"]
[Thu Sep 17 15:16:06.348110 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/crm/.env"] [unique_id "aqxYlucL08BTTQixEnpkJQAAAH0"]
[Thu Sep 17 15:16:06.364142 2026] [security2:error] [pid 971102:tid 971336] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxYlucL08BTTQixEnpkJgAAAGY"]
[Thu Sep 17 15:16:06.387897 2026] [security2:error] [pid 971102:tid 971257] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxYlucL08BTTQixEnpkJwAAABc"]
[Thu Sep 17 15:16:06.415314 2026] [security2:error] [pid 971102:tid 971307] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxYlucL08BTTQixEnpkKAAAAEk"]
[Thu Sep 17 15:16:06.415462 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/erp/.env"] [unique_id "aqxYlucL08BTTQixEnpkKQAAAEg"]
[Thu Sep 17 15:16:06.442450 2026] [security2:error] [pid 971102:tid 971249] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxYlucL08BTTQixEnpkKgAAAA8"]
[Thu Sep 17 15:16:06.465648 2026] [security2:error] [pid 971102:tid 971283] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxYlucL08BTTQixEnpkKwAAADE"]
[Thu Sep 17 15:16:06.467418 2026] [security2:error] [pid 971102:tid 971345] [client 143.244.57.121:35398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxYlucL08BTTQixEnpkLAAAAG8"]
[Thu Sep 17 15:16:06.480954 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/shop/.env"] [unique_id "aqxYlucL08BTTQixEnpkLgAAACk"]
[Thu Sep 17 15:16:06.483075 2026] [security2:error] [pid 971102:tid 971273] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxYlucL08BTTQixEnpkLwAAACc"]
[Thu Sep 17 15:16:06.505924 2026] [security2:error] [pid 971102:tid 971272] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxYlucL08BTTQixEnpkMgAAACY"]
[Thu Sep 17 15:16:06.521707 2026] [security2:error] [pid 971102:tid 971277] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxYlucL08BTTQixEnpkMwAAACs"]
[Thu Sep 17 15:16:06.535837 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/store/.env"] [unique_id "aqxYlucL08BTTQixEnpkNAAAAG4"]
[Thu Sep 17 15:16:06.538809 2026] [security2:error] [pid 971102:tid 971294] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxYlucL08BTTQixEnpkNQAAADw"]
[Thu Sep 17 15:16:06.555419 2026] [security2:error] [pid 971102:tid 971238] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxYlucL08BTTQixEnpkNwAAAAQ"]
[Thu Sep 17 15:16:06.603046 2026] [security2:error] [pid 971102:tid 971288] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxYlucL08BTTQixEnpkOAAAADY"]
[Thu Sep 17 15:16:06.604827 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/saas/.env"] [unique_id "aqxYlucL08BTTQixEnpkOQAAAFY"]
[Thu Sep 17 15:16:06.631067 2026] [security2:error] [pid 971102:tid 971350] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxYlucL08BTTQixEnpkPQAAAHQ"]
[Thu Sep 17 15:16:06.658515 2026] [security2:error] [pid 971102:tid 971341] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxYlucL08BTTQixEnpkQAAAAGs"]
[Thu Sep 17 15:16:06.675374 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/client/.env"] [unique_id "aqxYlucL08BTTQixEnpkQgAAAB0"]
[Thu Sep 17 15:16:06.701791 2026] [security2:error] [pid 971102:tid 971353] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxYlucL08BTTQixEnpkRQAAAHc"]
[Thu Sep 17 15:16:06.723542 2026] [security2:error] [pid 971102:tid 971316] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxYlucL08BTTQixEnpkSAAAAFI"]
[Thu Sep 17 15:16:06.748343 2026] [security2:error] [pid 971102:tid 971286] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxYlucL08BTTQixEnpkSgAAADQ"]
[Thu Sep 17 15:16:06.750882 2026] [security2:error] [pid 971102:tid 971328] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/project/.env"] [unique_id "aqxYlucL08BTTQixEnpkSwAAAF4"]
[Thu Sep 17 15:16:06.769588 2026] [security2:error] [pid 971102:tid 971250] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxYlucL08BTTQixEnpkTAAAABA"]
[Thu Sep 17 15:16:06.792471 2026] [security2:error] [pid 971102:tid 971237] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxYlucL08BTTQixEnpkTgAAAAM"]
[Thu Sep 17 15:16:06.803858 2026] [security2:error] [pid 971102:tid 971361] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/admin-panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkUAAAAH8"]
[Thu Sep 17 15:16:06.819952 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxYlucL08BTTQixEnpkUQAAAD4"]
[Thu Sep 17 15:16:06.831513 2026] [security2:error] [pid 971102:tid 971337] [client 143.244.57.121:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seattleboating.interlinck.com"] [uri "/xmlrpc.php"] [unique_id "aqxYlucL08BTTQixEnpkUgAAAGc"]
[Thu Sep 17 15:16:06.840481 2026] [security2:error] [pid 971102:tid 971239] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxYlucL08BTTQixEnpkUwAAAAU"]
[Thu Sep 17 15:16:06.857786 2026] [security2:error] [pid 971102:tid 971334] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxYlucL08BTTQixEnpkVQAAAGQ"]
[Thu Sep 17 15:16:06.857786 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/control-panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkVAAAAGk"]
[Thu Sep 17 15:16:06.883652 2026] [security2:error] [pid 971102:tid 971243] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxYlucL08BTTQixEnpkWgAAAAk"]
[Thu Sep 17 15:16:06.904890 2026] [security2:error] [pid 971102:tid 971357] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxYlucL08BTTQixEnpkXAAAAHs"]
[Thu Sep 17 15:16:06.919684 2026] [security2:error] [pid 971102:tid 971253] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/user-panel/.env"] [unique_id "aqxYlucL08BTTQixEnpkXwAAABM"]
[Thu Sep 17 15:16:06.921433 2026] [security2:error] [pid 971102:tid 971360] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxYlucL08BTTQixEnpkYAAAAH4"]
[Thu Sep 17 15:16:06.951455 2026] [security2:error] [pid 971102:tid 971312] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxYlucL08BTTQixEnpkYQAAAE4"]
[Thu Sep 17 15:16:06.975334 2026] [security2:error] [pid 971102:tid 971326] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/node/.env"] [unique_id "aqxYlucL08BTTQixEnpkYwAAAFw"]
[Thu Sep 17 15:16:06.985805 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxYlucL08BTTQixEnpkZAAAACQ"]
[Thu Sep 17 15:16:07.025403 2026] [security2:error] [pid 971102:tid 971287] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxYl-cL08BTTQixEnpkZgAAADU"]
[Thu Sep 17 15:16:07.028675 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/express/.env"] [unique_id "aqxYl-cL08BTTQixEnpkZwAAAEI"]
[Thu Sep 17 15:16:07.055761 2026] [security2:error] [pid 971102:tid 971325] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxYl-cL08BTTQixEnpkawAAAFs"]
[Thu Sep 17 15:16:07.076156 2026] [security2:error] [pid 971102:tid 971256] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxYl-cL08BTTQixEnpkbQAAABY"]
[Thu Sep 17 15:16:07.081810 2026] [security2:error] [pid 971102:tid 971252] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/next/.env"] [unique_id "aqxYl-cL08BTTQixEnpkbwAAABI"]
[Thu Sep 17 15:16:07.103545 2026] [security2:error] [pid 971102:tid 971314] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxYl-cL08BTTQixEnpkcgAAAFA"]
[Thu Sep 17 15:16:07.120812 2026] [security2:error] [pid 971102:tid 971259] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxYl-cL08BTTQixEnpkdAAAABk"]
[Thu Sep 17 15:16:07.140919 2026] [security2:error] [pid 971102:tid 971335] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxYl-cL08BTTQixEnpkeAAAAGU"]
[Thu Sep 17 15:16:07.140920 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/nuxt/.env"] [unique_id "aqxYl-cL08BTTQixEnpkdwAAAGg"]
[Thu Sep 17 15:16:07.158175 2026] [security2:error] [pid 971102:tid 971340] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxYl-cL08BTTQixEnpkfAAAAGo"]
[Thu Sep 17 15:16:07.182783 2026] [security2:error] [pid 971102:tid 971269] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxYl-cL08BTTQixEnpkfQAAACM"]
[Thu Sep 17 15:16:07.195389 2026] [security2:error] [pid 971102:tid 971234] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/nest/.env"] [unique_id "aqxYl-cL08BTTQixEnpkfgAAAAA"]
[Thu Sep 17 15:16:07.205791 2026] [security2:error] [pid 971102:tid 971261] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxYl-cL08BTTQixEnpkgAAAABs"]
[Thu Sep 17 15:16:07.228344 2026] [security2:error] [pid 971102:tid 971310] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxYl-cL08BTTQixEnpkggAAAEw"]
[Thu Sep 17 15:16:07.252359 2026] [security2:error] [pid 971102:tid 971274] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxYl-cL08BTTQixEnpkhAAAACg"]
[Thu Sep 17 15:16:07.255590 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/react/.env"] [unique_id "aqxYl-cL08BTTQixEnpkhgAAABc"]
[Thu Sep 17 15:16:07.267174 2026] [security2:error] [pid 971102:tid 971311] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxYl-cL08BTTQixEnpkiAAAAE0"]
[Thu Sep 17 15:16:07.268149 2026] [security2:error] [pid 971102:tid 971246] [client 143.244.57.121:35412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxYl-cL08BTTQixEnpkiQAAAAw"]
[Thu Sep 17 15:16:07.284040 2026] [security2:error] [pid 971102:tid 971322] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxYl-cL08BTTQixEnpkigAAAFg"]
[Thu Sep 17 15:16:07.313859 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/vue/.env"] [unique_id "aqxYl-cL08BTTQixEnpkiwAAAEk"]
[Thu Sep 17 15:16:07.314183 2026] [security2:error] [pid 971102:tid 971306] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjAAAAEg"]
[Thu Sep 17 15:16:07.342029 2026] [security2:error] [pid 971102:tid 971345] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjQAAAG8"]
[Thu Sep 17 15:16:07.367548 2026] [security2:error] [pid 971102:tid 971275] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjgAAACk"]
[Thu Sep 17 15:16:07.371061 2026] [security2:error] [pid 971102:tid 971273] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/angular/.env"] [unique_id "aqxYl-cL08BTTQixEnpkjwAAACc"]
[Thu Sep 17 15:16:07.383312 2026] [security2:error] [pid 971102:tid 971251] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkAAAABE"]
[Thu Sep 17 15:16:07.407946 2026] [security2:error] [pid 971102:tid 971272] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkQAAACY"]
[Thu Sep 17 15:16:07.425611 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/svelte/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkgAAAG4"]
[Thu Sep 17 15:16:07.427358 2026] [security2:error] [pid 971102:tid 971294] [client 34.94.22.173:41858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.formalheresy.org"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxYl-cL08BTTQixEnpkkwAAADw"]
[Thu Sep 17 15:16:07.466843 2026] [security2:error] [pid 971102:tid 971238] [client 34.94.22.173:41858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php"] [unique_id "aqxYl-cL08BTTQixEnpklgAAAAQ"]
[Thu Sep 17 15:16:07.480215 2026] [security2:error] [pid 971102:tid 971301] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/vite/.env"] [unique_id "aqxYl-cL08BTTQixEnpkmAAAAEM"]
[Thu Sep 17 15:16:07.534908 2026] [security2:error] [pid 971102:tid 971244] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/backup/.env"] [unique_id "aqxYl-cL08BTTQixEnpkmgAAAAo"]
[Thu Sep 17 15:16:07.542963 2026] [security2:error] [pid 971102:tid 971263] [client 34.94.22.173:41864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/info.php"] [unique_id "aqxYl-cL08BTTQixEnpkngAAAB0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:16:07.606160 2026] [security2:error] [pid 971102:tid 971245] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/backups/.env"] [unique_id "aqxYl-cL08BTTQixEnpkoAAAAAs"]
[Thu Sep 17 15:16:07.636116 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.121:35424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxYl-cL08BTTQixEnpkpAAAAD4"]
[Thu Sep 17 15:16:07.649723 2026] [security2:error] [pid 971102:tid 971361] [client 34.94.22.173:41872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/php.php"] [unique_id "aqxYl-cL08BTTQixEnpkpwAAAH8"]
[Thu Sep 17 15:16:07.659359 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/old/.env"] [unique_id "aqxYl-cL08BTTQixEnpkqQAAAGQ"]
[Thu Sep 17 15:16:07.715222 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.22.173:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/i.php"] [unique_id "aqxYl-cL08BTTQixEnpkqgAAAHE"]
[Thu Sep 17 15:16:07.723200 2026] [security2:error] [pid 971102:tid 971346] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/tmp/.env"] [unique_id "aqxYl-cL08BTTQixEnpkqwAAAHA"]
[Thu Sep 17 15:16:07.778534 2026] [security2:error] [pid 971102:tid 971247] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/temp/.env"] [unique_id "aqxYl-cL08BTTQixEnpkrQAAAA0"]
[Thu Sep 17 15:16:07.800796 2026] [security2:error] [pid 971102:tid 971235] [client 34.94.22.173:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/pi.php"] [unique_id "aqxYl-cL08BTTQixEnpkrgAAAAE"]
[Thu Sep 17 15:16:07.834630 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/lab/.env"] [unique_id "aqxYl-cL08BTTQixEnpkrwAAAAY"]
[Thu Sep 17 15:16:07.860918 2026] [security2:error] [pid 971102:tid 971289] [client 172.239.147.162:63903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxYl-cL08BTTQixEnpksAAAADc"], referer: binance.com
[Thu Sep 17 15:16:07.895020 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cronlab/.env"] [unique_id "aqxYl-cL08BTTQixEnpksQAAAE4"]
[Thu Sep 17 15:16:07.900195 2026] [security2:error] [pid 971102:tid 971279] [client 34.94.22.173:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/pinfo.php"] [unique_id "aqxYl-cL08BTTQixEnpksgAAAC0"]
[Thu Sep 17 15:16:07.912752 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.121:35428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxYl-cL08BTTQixEnpkswAAAEQ"]
[Thu Sep 17 15:16:07.951065 2026] [security2:error] [pid 971102:tid 971287] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cron/.env"] [unique_id "aqxYl-cL08BTTQixEnpktQAAADU"]
[Thu Sep 17 15:16:07.979988 2026] [security2:error] [pid 971102:tid 971319] [client 34.94.22.173:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/test.php"] [unique_id "aqxYl-cL08BTTQixEnpktgAAAFU"]
[Thu Sep 17 15:16:08.006387 2026] [security2:error] [pid 971102:tid 971293] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/en/.env"] [unique_id "aqxYmOcL08BTTQixEnpktwAAADs"]
[Thu Sep 17 15:16:08.093861 2026] [security2:error] [pid 971102:tid 971269] [client 34.94.22.173:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/p.php"] [unique_id "aqxYmOcL08BTTQixEnpkwQAAACM"]
[Thu Sep 17 15:16:08.118395 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/administrator/.env"] [unique_id "aqxYmOcL08BTTQixEnpkuwAAAGI"]
[Thu Sep 17 15:16:08.174814 2026] [security2:error] [pid 971102:tid 971359] [client 34.94.22.173:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/debug.php"] [unique_id "aqxYmOcL08BTTQixEnpkxgAAAH0"]
[Thu Sep 17 15:16:08.179593 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/psnlink/.env"] [unique_id "aqxYmOcL08BTTQixEnpkxwAAABc"]
[Thu Sep 17 15:16:08.206551 2026] [security2:error] [pid 971102:tid 971311] [client 143.244.57.121:35436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmOcL08BTTQixEnpkyAAAAE0"]
[Thu Sep 17 15:16:08.236287 2026] [security2:error] [pid 971102:tid 971265] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/exapi/.env"] [unique_id "aqxYmOcL08BTTQixEnpkyQAAAB8"]
[Thu Sep 17 15:16:08.244635 2026] [security2:error] [pid 971102:tid 971246] [client 34.94.22.173:41914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpkygAAAAw"]
[Thu Sep 17 15:16:08.290893 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sitemaps/.env"] [unique_id "aqxYmOcL08BTTQixEnpkywAAAFg"]
[Thu Sep 17 15:16:08.295633 2026] [security2:error] [pid 971102:tid 971340] [client 185.55.149.49:55636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpkzAAAAGo"]
[Thu Sep 17 15:16:08.295732 2026] [security2:error] [pid 971102:tid 971340] [client 185.55.149.49:55636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpkzAAAAGo"]
[Thu Sep 17 15:16:08.364197 2026] [security2:error] [pid 971102:tid 971295] [client 34.94.22.173:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/test/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk0AAAAD0"]
[Thu Sep 17 15:16:08.461386 2026] [security2:error] [pid 971102:tid 971343] [client 34.94.22.173:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/dev/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk1AAAAG0"]
[Thu Sep 17 15:16:08.499953 2026] [security2:error] [pid 971102:tid 971238] [client 143.244.57.121:35448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmOcL08BTTQixEnpk1wAAAAQ"]
[Thu Sep 17 15:16:08.537611 2026] [security2:error] [pid 971102:tid 971356] [client 162.241.226.11:56808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "caninecompanionsltd.org"] [uri "/index.php"] [unique_id "aqxYmOcL08BTTQixEnpkzQAAAHo"]
[Thu Sep 17 15:16:08.540565 2026] [security2:error] [pid 971102:tid 971320] [client 34.94.22.173:41948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/old/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk2AAAAFY"]
[Thu Sep 17 15:16:08.607502 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:22735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpk2wAAACg"]
[Thu Sep 17 15:16:08.607682 2026] [security2:error] [pid 971102:tid 971274] [client 104.28.198.244:22735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmOcL08BTTQixEnpk2wAAACg"]
[Thu Sep 17 15:16:08.621824 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/logs/.env"] [unique_id "aqxYmOcL08BTTQixEnpk3AAAAB4"]
[Thu Sep 17 15:16:08.626528 2026] [security2:error] [pid 971102:tid 971351] [client 34.94.22.173:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk3QAAAHU"]
[Thu Sep 17 15:16:08.682634 2026] [security2:error] [pid 971102:tid 971331] [client 20.244.34.24:50883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "airmacinc.com"] [uri "/index.php"] [unique_id "aqxYmOcL08BTTQixEnpk3gAAAGE"], referer: binance.com
[Thu Sep 17 15:16:08.684914 2026] [security2:error] [pid 971102:tid 971263] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cache/.env"] [unique_id "aqxYmOcL08BTTQixEnpk4QAAAB0"]
[Thu Sep 17 15:16:08.704248 2026] [security2:error] [pid 971102:tid 971329] [client 34.94.22.173:41968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/public/phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk4wAAAF8"]
[Thu Sep 17 15:16:08.748005 2026] [security2:error] [pid 971102:tid 971324] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailer/.env"] [unique_id "aqxYmOcL08BTTQixEnpk5AAAAFo"]
[Thu Sep 17 15:16:08.765117 2026] [security2:error] [pid 971102:tid 971341] [client 162.241.226.11:56824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "caninecompanionsltd.org"] [uri "/index.php"] [unique_id "aqxYmOcL08BTTQixEnpk2gAAAGs"]
[Thu Sep 17 15:16:08.807135 2026] [security2:error] [pid 971102:tid 971296] [client 143.244.57.121:35450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmOcL08BTTQixEnpk5wAAAD4"]
[Thu Sep 17 15:16:08.809934 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mail/.env"] [unique_id "aqxYmOcL08BTTQixEnpk6AAAAAM"]
[Thu Sep 17 15:16:08.879809 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/email/.env"] [unique_id "aqxYmOcL08BTTQixEnpk6gAAAC4"]
[Thu Sep 17 15:16:08.881328 2026] [security2:error] [pid 971102:tid 971284] [client 34.94.22.173:41984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/php-info.php"] [unique_id "aqxYmOcL08BTTQixEnpk6wAAADI"]
[Thu Sep 17 15:16:08.895132 2026] [security2:error] [pid 971102:tid 971291] [client 157.85.210.148:3962] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.sqlerudition.com"] [uri "/wp-content/plugins/give/readme.txt"] [unique_id "aqxYmOcL08BTTQixEnpk7AAAADk"]
[Thu Sep 17 15:16:08.944339 2026] [security2:error] [pid 971102:tid 971235] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/smtp/.env"] [unique_id "aqxYmOcL08BTTQixEnpk7wAAAAE"]
[Thu Sep 17 15:16:08.951854 2026] [security2:error] [pid 971102:tid 971247] [client 34.94.22.173:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpversion.php"] [unique_id "aqxYmOcL08BTTQixEnpk8AAAAA0"]
[Thu Sep 17 15:16:08.985151 2026] [security2:error] [pid 971102:tid 971240] [client 5.189.145.112:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxYmOcL08BTTQixEnpk8gAAAAY"], referer: binance.com
[Thu Sep 17 15:16:08.999217 2026] [security2:error] [pid 971102:tid 971271] [client 34.94.22.173:42006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/_phpinfo.php"] [unique_id "aqxYmOcL08BTTQixEnpk8wAAACU"]
[Thu Sep 17 15:16:09.007035 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.80.249:58064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailing/.env"] [unique_id "aqxYmecL08BTTQixEnpk9AAAAE8"]
[Thu Sep 17 15:16:09.066896 2026] [security2:error] [pid 971102:tid 971289] [client 34.94.22.173:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/old_phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnpk9QAAADc"]
[Thu Sep 17 15:16:09.078269 2026] [security2:error] [pid 971102:tid 971268] [client 102.178.123.34:36558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYmOcL08BTTQixEnpk8QAAIk8"]
[Thu Sep 17 15:16:09.103236 2026] [security2:error] [pid 971102:tid 971302] [client 143.244.57.121:35466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmecL08BTTQixEnpk9gAAAEQ"]
[Thu Sep 17 15:16:09.164713 2026] [security2:error] [pid 971102:tid 971270] [client 34.94.22.173:42038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/server-info.php"] [unique_id "aqxYmecL08BTTQixEnpk-QAAACQ"]
[Thu Sep 17 15:16:09.243437 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/notifications/.env"] [unique_id "aqxYmecL08BTTQixEnpk-gAAAFU"]
[Thu Sep 17 15:16:09.247097 2026] [security2:error] [pid 971102:tid 971252] [client 34.94.22.173:42048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/server-status.php"] [unique_id "aqxYmecL08BTTQixEnpk-wAAABI"]
[Thu Sep 17 15:16:09.278332 2026] [security2:error] [pid 971102:tid 971242] [client 172.239.147.162:63899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxYmecL08BTTQixEnpk_AAAAAg"], referer: binance.com
[Thu Sep 17 15:16:09.297596 2026] [security2:error] [pid 971102:tid 971338] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/notify/.env"] [unique_id "aqxYmecL08BTTQixEnpk_gAAAGg"]
[Thu Sep 17 15:16:09.369238 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sender/.env"] [unique_id "aqxYmecL08BTTQixEnpk_wAAABo"]
[Thu Sep 17 15:16:09.413483 2026] [security2:error] [pid 971102:tid 971257] [client 143.244.57.121:35472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmecL08BTTQixEnplAwAAABc"]
[Thu Sep 17 15:16:09.445820 2026] [security2:error] [pid 971102:tid 971283] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/campaign/.env"] [unique_id "aqxYmecL08BTTQixEnplBQAAADE"]
[Thu Sep 17 15:16:09.459753 2026] [security2:error] [pid 971102:tid 971265] [client 157.85.210.148:6520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.210.85.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sqlerudition.com"] [uri "/wp-content/plugins/give/give.php"] [unique_id "aqxYmecL08BTTQixEnplBgAAAB8"]
[Thu Sep 17 15:16:09.512276 2026] [security2:error] [pid 971102:tid 971306] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/newsletter/.env"] [unique_id "aqxYmecL08BTTQixEnplCgAAAEg"]
[Thu Sep 17 15:16:09.517558 2026] [security2:error] [pid 971102:tid 971261] [client 34.94.22.173:42050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYmecL08BTTQixEnplCwAAABs"]
[Thu Sep 17 15:16:09.568147 2026] [security2:error] [pid 971102:tid 971321] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/ses/.env"] [unique_id "aqxYmecL08BTTQixEnplDAAAAFc"]
[Thu Sep 17 15:16:09.616239 2026] [security2:error] [pid 971102:tid 971296] [client 34.94.22.173:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/mail/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplDwAAAD4"]
[Thu Sep 17 15:16:09.630949 2026] [security2:error] [pid 971102:tid 971277] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sendgrid/.env"] [unique_id "aqxYmecL08BTTQixEnplEAAAACs"]
[Thu Sep 17 15:16:09.688894 2026] [security2:error] [pid 971102:tid 971249] [client 45.115.26.203:48766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env"] [unique_id "aqxYmecL08BTTQixEnplFgAAAA8"]
[Thu Sep 17 15:16:09.689040 2026] [security2:error] [pid 971102:tid 971347] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/sparkpost/.env"] [unique_id "aqxYmecL08BTTQixEnplFwAAAHE"]
[Thu Sep 17 15:16:09.689600 2026] [security2:error] [pid 971102:tid 971323] [client 34.94.22.173:42068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplGAAAAFk"]
[Thu Sep 17 15:16:09.710564 2026] [security2:error] [pid 971102:tid 971346] [client 143.244.57.121:35488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmecL08BTTQixEnplHAAAAHA"]
[Thu Sep 17 15:16:09.730669 2026] [security2:error] [pid 971102:tid 971275] [client 45.115.26.203:49032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplIQAAACk"]
[Thu Sep 17 15:16:09.730687 2026] [security2:error] [pid 971102:tid 971294] [client 45.115.26.203:49080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/_phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplHQAAADw"]
[Thu Sep 17 15:16:09.730726 2026] [security2:error] [pid 971102:tid 971292] [client 45.115.26.203:49048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/i.php"] [unique_id "aqxYmecL08BTTQixEnplHwAAADo"]
[Thu Sep 17 15:16:09.730752 2026] [security2:error] [pid 971102:tid 971272] [client 45.115.26.203:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/php_info.php"] [unique_id "aqxYmecL08BTTQixEnplIwAAACY"]
[Thu Sep 17 15:16:09.731845 2026] [security2:error] [pid 971102:tid 971345] [client 45.115.26.203:48970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/app/.env"] [unique_id "aqxYmecL08BTTQixEnplIgAAAG8"]
[Thu Sep 17 15:16:09.732021 2026] [security2:error] [pid 971102:tid 971266] [client 45.115.26.203:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/info.php"] [unique_id "aqxYmecL08BTTQixEnplJQAAACA"]
[Thu Sep 17 15:16:09.732313 2026] [security2:error] [pid 971102:tid 971290] [client 45.115.26.203:48954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/backend/.env"] [unique_id "aqxYmecL08BTTQixEnplJgAAADg"]
[Thu Sep 17 15:16:09.735169 2026] [security2:error] [pid 971102:tid 971344] [client 45.115.26.203:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/pi.php"] [unique_id "aqxYmecL08BTTQixEnplKAAAAG4"]
[Thu Sep 17 15:16:09.735762 2026] [security2:error] [pid 971102:tid 971295] [client 45.115.26.203:48900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.backup"] [unique_id "aqxYmecL08BTTQixEnplKQAAAD0"]
[Thu Sep 17 15:16:09.743577 2026] [security2:error] [pid 971102:tid 971250] [client 45.115.26.203:48966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/api/.env"] [unique_id "aqxYmecL08BTTQixEnplMgAAABA"]
[Thu Sep 17 15:16:09.743692 2026] [security2:error] [pid 971102:tid 971288] [client 45.115.26.203:48974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/src/.env"] [unique_id "aqxYmecL08BTTQixEnplOAAAADY"]
[Thu Sep 17 15:16:09.743813 2026] [security2:error] [pid 971102:tid 971301] [client 45.115.26.203:48790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env"] [unique_id "aqxYmecL08BTTQixEnplNgAAAEM"]
[Thu Sep 17 15:16:09.744037 2026] [security2:error] [pid 971102:tid 971308] [client 45.115.26.203:48938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.swp"] [unique_id "aqxYmecL08BTTQixEnplNwAAAEo"]
[Thu Sep 17 15:16:09.744161 2026] [security2:error] [pid 971102:tid 971351] [client 45.115.26.203:48934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env~"] [unique_id "aqxYmecL08BTTQixEnplOgAAAHU"]
[Thu Sep 17 15:16:09.744203 2026] [security2:error] [pid 971102:tid 971263] [client 45.115.26.203:48906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.bak"] [unique_id "aqxYmecL08BTTQixEnplNQAAAB0"]
[Thu Sep 17 15:16:09.746206 2026] [security2:error] [pid 971102:tid 971264] [client 45.115.26.203:48912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.old"] [unique_id "aqxYmecL08BTTQixEnplOwAAAB4"]
[Thu Sep 17 15:16:09.750841 2026] [security2:error] [pid 971102:tid 971353] [client 34.94.22.173:42080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplPgAAAHc"]
[Thu Sep 17 15:16:09.758787 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/postmark/.env"] [unique_id "aqxYmecL08BTTQixEnplPwAAAHg"]
[Thu Sep 17 15:16:09.785511 2026] [security2:error] [pid 971102:tid 971361] [client 45.115.26.203:49058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/test.php"] [unique_id "aqxYmecL08BTTQixEnplQQAAAH8"]
[Thu Sep 17 15:16:09.788472 2026] [security2:error] [pid 971102:tid 971358] [client 45.115.26.203:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/php-info.php"] [unique_id "aqxYmecL08BTTQixEnplQgAAAHw"]
[Thu Sep 17 15:16:09.806346 2026] [security2:error] [pid 971102:tid 971237] [client 172.239.147.162:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxYmecL08BTTQixEnplQwAAAAM"], referer: binance.com
[Thu Sep 17 15:16:09.819296 2026] [security2:error] [pid 971102:tid 971247] [client 34.94.22.173:42088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplRAAAAA0"]
[Thu Sep 17 15:16:09.824862 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailgun/.env"] [unique_id "aqxYmecL08BTTQixEnplRQAAAAY"]
[Thu Sep 17 15:16:09.888496 2026] [security2:error] [pid 971102:tid 971302] [client 34.94.22.173:42100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYmecL08BTTQixEnplSQAAAEQ"]
[Thu Sep 17 15:16:09.889342 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mandrill/.env"] [unique_id "aqxYmecL08BTTQixEnplSAAAAFA"]
[Thu Sep 17 15:16:09.946176 2026] [security2:error] [pid 971102:tid 971276] [client 34.94.22.173:42108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php.bak"] [unique_id "aqxYmecL08BTTQixEnplTAAAACo"]
[Thu Sep 17 15:16:09.949355 2026] [security2:error] [pid 971102:tid 971323] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mailjet/.env"] [unique_id "aqxYmecL08BTTQixEnplTQAAAFk"]
[Thu Sep 17 15:16:09.955856 2026] [security2:error] [pid 971102:tid 971322] [client 186.105.232.15:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmecL08BTTQixEnplSwAAAFg"]
[Thu Sep 17 15:16:09.955957 2026] [security2:error] [pid 971102:tid 971322] [client 186.105.232.15:50326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmecL08BTTQixEnplSwAAAFg"]
[Thu Sep 17 15:16:10.001560 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.121:35504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplUQAAADo"]
[Thu Sep 17 15:16:10.005513 2026] [security2:error] [pid 971102:tid 971280] [client 34.94.22.173:42120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php.old"] [unique_id "aqxYmucL08BTTQixEnplUgAAAC4"]
[Thu Sep 17 15:16:10.014915 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/brevo/.env"] [unique_id "aqxYmucL08BTTQixEnplUwAAACk"]
[Thu Sep 17 15:16:10.076852 2026] [security2:error] [pid 971102:tid 971345] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/transactional/.env"] [unique_id "aqxYmucL08BTTQixEnplVQAAAG8"]
[Thu Sep 17 15:16:10.089592 2026] [security2:error] [pid 971102:tid 971284] [client 34.94.22.173:42128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php~"] [unique_id "aqxYmucL08BTTQixEnplVgAAADI"]
[Thu Sep 17 15:16:10.139117 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/bulk/.env"] [unique_id "aqxYmucL08BTTQixEnplVwAAAFY"]
[Thu Sep 17 15:16:10.158583 2026] [access_compat:error] [pid 971102:tid 971350] [client 45.115.26.203:49114] AH01797: client denied by server configuration: /home3/mikemil2/public_html/server-status
[Thu Sep 17 15:16:10.183173 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/info.php.bak"] [unique_id "aqxYmucL08BTTQixEnplXQAAAHM"]
[Thu Sep 17 15:16:10.196005 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/aws/.env"] [unique_id "aqxYmucL08BTTQixEnplXgAAAFM"]
[Thu Sep 17 15:16:10.252305 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/azure/.env"] [unique_id "aqxYmucL08BTTQixEnplXwAAAEo"]
[Thu Sep 17 15:16:10.260775 2026] [security2:error] [pid 971102:tid 971301] [client 34.94.22.173:42156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/phpinfo.php.save"] [unique_id "aqxYmucL08BTTQixEnplYAAAAEM"]
[Thu Sep 17 15:16:10.278814 2026] [security2:error] [pid 971102:tid 971344] [client 45.169.98.18:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmucL08BTTQixEnplYQAAAG4"]
[Thu Sep 17 15:16:10.278906 2026] [security2:error] [pid 971102:tid 971344] [client 45.169.98.18:55188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYmucL08BTTQixEnplYQAAAG4"]
[Thu Sep 17 15:16:10.310494 2026] [security2:error] [pid 971102:tid 971331] [client 143.244.57.121:43626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplYgAAAGE"]
[Thu Sep 17 15:16:10.320918 2026] [security2:error] [pid 971102:tid 971262] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/gcp/.env"] [unique_id "aqxYmucL08BTTQixEnplYwAAABw"]
[Thu Sep 17 15:16:10.342458 2026] [security2:error] [pid 971102:tid 971264] [client 34.94.22.173:42162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/staging/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplZQAAAB4"]
[Thu Sep 17 15:16:10.393306 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cloud/.env"] [unique_id "aqxYmucL08BTTQixEnplaQAAABY"]
[Thu Sep 17 15:16:10.409270 2026] [security2:error] [pid 971102:tid 971358] [client 34.94.22.173:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/beta/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplagAAAHw"]
[Thu Sep 17 15:16:10.450179 2026] [security2:error] [pid 971102:tid 971240] [client 192.178.6.3:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxYmucL08BTTQixEnplawAAAAY"]
[Thu Sep 17 15:16:10.458151 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/infrastructure/.env"] [unique_id "aqxYmucL08BTTQixEnplbAAAAE8"]
[Thu Sep 17 15:16:10.468654 2026] [security2:error] [pid 971102:tid 971271] [client 34.94.22.173:42176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/uat/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplbgAAACU"]
[Thu Sep 17 15:16:10.529713 2026] [security2:error] [pid 971102:tid 971289] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/docker/.env"] [unique_id "aqxYmucL08BTTQixEnplbwAAADc"]
[Thu Sep 17 15:16:10.565897 2026] [security2:error] [pid 971102:tid 971303] [client 34.94.22.173:42178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/qa/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplcAAAAEU"]
[Thu Sep 17 15:16:10.589161 2026] [security2:error] [pid 971102:tid 971312] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/k8s/.env"] [unique_id "aqxYmucL08BTTQixEnplcQAAAE4"]
[Thu Sep 17 15:16:10.615986 2026] [security2:error] [pid 971102:tid 971300] [client 143.244.57.121:43636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplcwAAAEI"]
[Thu Sep 17 15:16:10.654961 2026] [security2:error] [pid 971102:tid 971242] [client 34.94.22.173:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/preview/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnpleAAAAAg"]
[Thu Sep 17 15:16:10.678788 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/kubernetes/.env"] [unique_id "aqxYmucL08BTTQixEnplewAAABo"]
[Thu Sep 17 15:16:10.739186 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/terraform/.env"] [unique_id "aqxYmucL08BTTQixEnplfAAAAGI"]
[Thu Sep 17 15:16:10.753061 2026] [security2:error] [pid 971102:tid 971254] [client 34.94.22.173:42198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/www/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplfQAAABQ"]
[Thu Sep 17 15:16:10.804215 2026] [security2:error] [pid 971102:tid 971327] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/ansible/.env"] [unique_id "aqxYmucL08BTTQixEnplfgAAAF0"]
[Thu Sep 17 15:16:10.841216 2026] [security2:error] [pid 971102:tid 971283] [client 34.94.22.173:42204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplfwAAADE"]
[Thu Sep 17 15:16:10.894207 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/.git/.env"] [unique_id "aqxYmucL08BTTQixEnplgwAAAFE"]
[Thu Sep 17 15:16:10.916813 2026] [security2:error] [pid 971102:tid 971306] [client 143.244.57.121:43644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxYmucL08BTTQixEnplhQAAAEg"]
[Thu Sep 17 15:16:10.930186 2026] [security2:error] [pid 971102:tid 971246] [client 34.94.22.173:42218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYmucL08BTTQixEnplhgAAAAw"]
[Thu Sep 17 15:16:10.959019 2026] [security2:error] [pid 971102:tid 971281] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/ci/.env"] [unique_id "aqxYmucL08BTTQixEnplhwAAAC8"]
[Thu Sep 17 15:16:11.012149 2026] [security2:error] [pid 971102:tid 971321] [client 34.94.22.173:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/site/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnpliAAAAFc"]
[Thu Sep 17 15:16:11.018295 2026] [security2:error] [pid 971102:tid 971328] [client 172.239.147.162:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxYm-cL08BTTQixEnpliQAAAF4"], referer: binance.com
[Thu Sep 17 15:16:11.019794 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/cd/.env"] [unique_id "aqxYm-cL08BTTQixEnpligAAAGQ"]
[Thu Sep 17 15:16:11.082554 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/jenkins/.env"] [unique_id "aqxYm-cL08BTTQixEnpliwAAAA8"]
[Thu Sep 17 15:16:11.122037 2026] [security2:error] [pid 971102:tid 971347] [client 34.94.22.173:42240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/docs/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnpljAAAAHE"]
[Thu Sep 17 15:16:11.141501 2026] [security2:error] [pid 971102:tid 971322] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/gitlab/.env"] [unique_id "aqxYm-cL08BTTQixEnpljwAAAFg"]
[Thu Sep 17 15:16:11.172780 2026] [security2:error] [pid 971102:tid 971343] [client 114.198.138.124:54587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplkQAAAG0"]
[Thu Sep 17 15:16:11.172873 2026] [security2:error] [pid 971102:tid 971343] [client 114.198.138.124:54587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplkQAAAG0"]
[Thu Sep 17 15:16:11.210038 2026] [security2:error] [pid 971102:tid 971292] [client 143.244.57.121:43652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxYm-cL08BTTQixEnplkgAAADo"]
[Thu Sep 17 15:16:11.211979 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/github/.env"] [unique_id "aqxYm-cL08BTTQixEnplkwAAAC4"]
[Thu Sep 17 15:16:11.216766 2026] [security2:error] [pid 971102:tid 971243] [client 34.94.22.173:42252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnpllQAAAAk"]
[Thu Sep 17 15:16:11.274161 2026] [security2:error] [pid 971102:tid 971284] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/actions/.env"] [unique_id "aqxYm-cL08BTTQixEnpllgAAADI"]
[Thu Sep 17 15:16:11.295501 2026] [security2:error] [pid 971102:tid 971266] [client 34.94.22.173:42266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnplmAAAACA"]
[Thu Sep 17 15:16:11.335099 2026] [security2:error] [pid 971102:tid 971310] [client 154.190.208.131:41682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplmQAAAEw"]
[Thu Sep 17 15:16:11.339521 2026] [security2:error] [pid 971102:tid 971310] [client 154.190.208.131:41682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYm-cL08BTTQixEnplmQAAAEw"]
[Thu Sep 17 15:16:11.340469 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/circleci/.env"] [unique_id "aqxYm-cL08BTTQixEnplmwAAAHQ"]
[Thu Sep 17 15:16:11.373326 2026] [security2:error] [pid 971102:tid 971349] [client 34.94.22.173:42278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/core/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnplnAAAAHM"]
[Thu Sep 17 15:16:11.399298 2026] [security2:error] [pid 971102:tid 971288] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/travis/.env"] [unique_id "aqxYm-cL08BTTQixEnplnQAAADY"]
[Thu Sep 17 15:16:11.444300 2026] [security2:error] [pid 971102:tid 971234] [client 34.94.22.173:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formalheresy.org"] [uri "/includes/phpinfo.php"] [unique_id "aqxYm-cL08BTTQixEnploQAAAAA"]
[Thu Sep 17 15:16:11.464727 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/buildkite/.env"] [unique_id "aqxYm-cL08BTTQixEnplowAAAHU"]
[Thu Sep 17 15:16:11.500614 2026] [security2:error] [pid 971102:tid 971353] [client 143.244.57.121:43660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seattleboating.interlinck.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxYm-cL08BTTQixEnplpAAAAHc"]
[Thu Sep 17 15:16:11.523223 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mysql/.env"] [unique_id "aqxYm-cL08BTTQixEnplpwAAACw"]
[Thu Sep 17 15:16:11.602949 2026] [security2:error] [pid 971102:tid 971256] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/postgres/.env"] [unique_id "aqxYm-cL08BTTQixEnplrAAAABY"]
[Thu Sep 17 15:16:11.671363 2026] [security2:error] [pid 971102:tid 971237] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/mongodb/.env"] [unique_id "aqxYm-cL08BTTQixEnplsQAAAAM"]
[Thu Sep 17 15:16:11.760112 2026] [security2:error] [pid 971102:tid 971289] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/redis/.env"] [unique_id "aqxYm-cL08BTTQixEnpltwAAADc"]
[Thu Sep 17 15:16:11.845416 2026] [security2:error] [pid 971102:tid 971270] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/elasticsearch/.env"] [unique_id "aqxYm-cL08BTTQixEnplvgAAACQ"]
[Thu Sep 17 15:16:11.886023 2026] [security2:error] [pid 971102:tid 971303] [client 91.73.4.138:58849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYm-cL08BTTQixEnpluQAARWA"]
[Thu Sep 17 15:16:11.911863 2026] [security2:error] [pid 971102:tid 971286] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/rabbitmq/.env"] [unique_id "aqxYm-cL08BTTQixEnplwQAAADQ"]
[Thu Sep 17 15:16:11.977640 2026] [security2:error] [pid 971102:tid 971359] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/kafka/.env"] [unique_id "aqxYm-cL08BTTQixEnplwgAAAH0"]
[Thu Sep 17 15:16:12.058814 2026] [security2:error] [pid 971102:tid 971254] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/queue/.env"] [unique_id "aqxYnOcL08BTTQixEnplxQAAABQ"]
[Thu Sep 17 15:16:12.121789 2026] [security2:error] [pid 971102:tid 971340] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/worker/.env"] [unique_id "aqxYnOcL08BTTQixEnplzAAAAGo"]
[Thu Sep 17 15:16:12.166393 2026] [security2:error] [pid 971102:tid 971258] [client 169.58.197.253:52315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ppfc.net"] [uri "/wp-login.php"] [unique_id "aqxYnOcL08BTTQixEnpl0AAAABg"], referer: binance.com
[Thu Sep 17 15:16:12.195373 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/job/.env"] [unique_id "aqxYnOcL08BTTQixEnpl1QAAAD4"]
[Thu Sep 17 15:16:12.259451 2026] [security2:error] [pid 971102:tid 971321] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/test/.env"] [unique_id "aqxYnOcL08BTTQixEnpl1wAAAFc"]
[Thu Sep 17 15:16:12.325951 2026] [security2:error] [pid 971102:tid 971334] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/qa/.env"] [unique_id "aqxYnOcL08BTTQixEnpl2AAAAGQ"]
[Thu Sep 17 15:16:12.341857 2026] [security2:error] [pid 971102:tid 971293] [client 172.239.147.162:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxYnOcL08BTTQixEnpl2QAAADs"], referer: binance.com
[Thu Sep 17 15:16:12.390601 2026] [security2:error] [pid 971102:tid 971249] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/preview/.env"] [unique_id "aqxYnOcL08BTTQixEnpl3QAAAA8"]
[Thu Sep 17 15:16:12.455265 2026] [security2:error] [pid 971102:tid 971343] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/beta/.env"] [unique_id "aqxYnOcL08BTTQixEnpl3gAAAG0"]
[Thu Sep 17 15:16:12.527570 2026] [security2:error] [pid 971102:tid 971280] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/uat/.env"] [unique_id "aqxYnOcL08BTTQixEnpl3wAAAC4"]
[Thu Sep 17 15:16:12.606343 2026] [security2:error] [pid 971102:tid 971243] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/stage/.env"] [unique_id "aqxYnOcL08BTTQixEnpl4QAAAAk"]
[Thu Sep 17 15:16:12.611821 2026] [security2:error] [pid 971102:tid 971328] [client 172.239.147.162:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxYnOcL08BTTQixEnpl4gAAAF4"], referer: binance.com
[Thu Sep 17 15:16:12.679545 2026] [security2:error] [pid 971102:tid 971284] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/development/.env"] [unique_id "aqxYnOcL08BTTQixEnpl5QAAADI"]
[Thu Sep 17 15:16:12.742005 2026] [security2:error] [pid 971102:tid 971320] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/production/.env"] [unique_id "aqxYnOcL08BTTQixEnpl6QAAAFY"]
[Thu Sep 17 15:16:12.822517 2026] [security2:error] [pid 971102:tid 971291] [client 34.23.80.249:58066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.doodlesatheart.com"] [uri "/config/app/.env"] [unique_id "aqxYnOcL08BTTQixEnpl7QAAADk"]
[Thu Sep 17 15:16:12.835670 2026] [security2:error] [pid 971102:tid 971355] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYm-cL08BTTQixEnplsAAAeUY"], referer: http://sharlotbott.com/wordpress/
[Thu Sep 17 15:16:12.896747 2026] [security2:error] [pid 971102:tid 971272] [client 34.23.80.249:58066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php"] [unique_id "aqxYnOcL08BTTQixEnpl7gAAACY"]
[Thu Sep 17 15:16:13.005846 2026] [security2:error] [pid 971102:tid 971234] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnOcL08BTTQixEnpl8AAAABQ"], referer: http://sharlotbott.com/old/
[Thu Sep 17 15:16:13.099446 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:58104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/info.php"] [unique_id "aqxYnecL08BTTQixEnpl8wAAAGs"]
[Thu Sep 17 15:16:13.177630 2026] [security2:error] [pid 971102:tid 971247] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpl9gAADXo"], referer: http://sharlotbott.com/new/
[Thu Sep 17 15:16:13.309743 2026] [security2:error] [pid 971102:tid 971278] [client 34.23.80.249:58120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/php.php"] [unique_id "aqxYnecL08BTTQixEnpl_AAAACw"]
[Thu Sep 17 15:16:13.561722 2026] [security2:error] [pid 971102:tid 971330] [client 34.23.80.249:58122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/i.php"] [unique_id "aqxYnecL08BTTQixEnpmAAAAAGA"]
[Thu Sep 17 15:16:13.659360 2026] [security2:error] [pid 971102:tid 971275] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmAQAAKVk"], referer: http://sharlotbott.com/backup/
[Thu Sep 17 15:16:13.792726 2026] [security2:error] [pid 971102:tid 971268] [client 34.23.80.249:58126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/pi.php"] [unique_id "aqxYnecL08BTTQixEnpmCQAAACI"]
[Thu Sep 17 15:16:13.831075 2026] [security2:error] [pid 971102:tid 971270] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmCgAAJCA"], referer: http://sharlotbott.com/blog/
[Thu Sep 17 15:16:14.014968 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/pinfo.php"] [unique_id "aqxYnucL08BTTQixEnpmFAAAAAU"]
[Thu Sep 17 15:16:14.019371 2026] [security2:error] [pid 971102:tid 971254] [client 45.55.194.205:33826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharlotbott.com"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmEQAAFBA"], referer: http://sharlotbott.com/wp/
[Thu Sep 17 15:16:14.166268 2026] [security2:error] [pid 971102:tid 971242] [client 172.239.147.162:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxYnucL08BTTQixEnpmFQAAAAg"], referer: binance.com
[Thu Sep 17 15:16:14.239071 2026] [security2:error] [pid 971102:tid 971315] [client 34.23.80.249:58144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/test.php"] [unique_id "aqxYnucL08BTTQixEnpmHAAAAFE"]
[Thu Sep 17 15:16:14.322375 2026] [security2:error] [pid 971102:tid 971323] [client 169.58.197.253:52400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxYnucL08BTTQixEnpmGQAAAFk"], referer: binance.com
[Thu Sep 17 15:16:14.507845 2026] [security2:error] [pid 971102:tid 971321] [client 172.239.147.162:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxYnucL08BTTQixEnpmJAAAAFc"], referer: binance.com
[Thu Sep 17 15:16:14.593165 2026] [security2:error] [pid 971102:tid 971310] [client 34.23.80.249:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/p.php"] [unique_id "aqxYnucL08BTTQixEnpmJwAAAEw"]
[Thu Sep 17 15:16:14.763544 2026] [security2:error] [pid 971102:tid 971261] [client 20.244.34.24:55491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.airmacinc.com"] [uri "/index.php"] [unique_id "aqxYnucL08BTTQixEnpmLgAAABs"], referer: binance.com
[Thu Sep 17 15:16:14.800933 2026] [security2:error] [pid 971102:tid 971274] [client 34.23.80.249:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/debug.php"] [unique_id "aqxYnucL08BTTQixEnpmMwAAACg"]
[Thu Sep 17 15:16:14.863636 2026] [security2:error] [pid 971102:tid 971305] [client 123.26.183.108:57546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYnucL08BTTQixEnpmMAAAR20"]
[Thu Sep 17 15:16:15.001456 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.80.249:58164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmNQAAAB4"]
[Thu Sep 17 15:16:15.137454 2026] [security2:error] [pid 971102:tid 971234] [client 156.192.234.52:63346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYn-cL08BTTQixEnpmOAAAAAA"]
[Thu Sep 17 15:16:15.139640 2026] [security2:error] [pid 971102:tid 971234] [client 156.192.234.52:63346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYn-cL08BTTQixEnpmOAAAAAA"]
[Thu Sep 17 15:16:15.213320 2026] [security2:error] [pid 971102:tid 971240] [client 34.23.80.249:58176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/test/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmOgAAAAY"]
[Thu Sep 17 15:16:15.441353 2026] [security2:error] [pid 971102:tid 971303] [client 34.23.80.249:58182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmPgAAAEU"]
[Thu Sep 17 15:16:15.645168 2026] [security2:error] [pid 971102:tid 971260] [client 34.23.80.249:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/old/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmRQAAABo"]
[Thu Sep 17 15:16:15.815003 2026] [security2:error] [pid 971102:tid 971242] [client 172.239.147.162:54405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxYn-cL08BTTQixEnpmSAAAAAg"], referer: binance.com
[Thu Sep 17 15:16:15.861134 2026] [security2:error] [pid 971102:tid 971323] [client 34.23.80.249:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYn-cL08BTTQixEnpmSQAAAFk"]
[Thu Sep 17 15:16:16.082527 2026] [security2:error] [pid 971102:tid 971257] [client 34.23.80.249:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/public/phpinfo.php"] [unique_id "aqxYoOcL08BTTQixEnpmTAAAABc"]
[Thu Sep 17 15:16:16.379497 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.80.249:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/php-info.php"] [unique_id "aqxYoOcL08BTTQixEnpmVgAAACA"]
[Thu Sep 17 15:16:16.416448 2026] [security2:error] [pid 971102:tid 971255] [client 172.239.147.162:50485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxYoOcL08BTTQixEnpmVwAAABU"], referer: binance.com
[Thu Sep 17 15:16:16.488903 2026] [security2:error] [pid 971102:tid 971334] [client 158.140.173.55:37244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYoOcL08BTTQixEnpmVQAAZF4"]
[Thu Sep 17 15:16:16.555669 2026] [security2:error] [pid 971102:tid 971250] [client 5.189.145.112:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxYoOcL08BTTQixEnpmWwAAABA"], referer: binance.com
[Thu Sep 17 15:16:16.560154 2026] [security2:error] [pid 971102:tid 971350] [client 34.23.80.249:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpversion.php"] [unique_id "aqxYoOcL08BTTQixEnpmXAAAAHQ"]
[Thu Sep 17 15:16:16.774720 2026] [security2:error] [pid 971102:tid 971279] [client 209.38.197.191:54488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.recessionnews.org"] [uri "/index.php"] [unique_id "aqxYnecL08BTTQixEnpmCAAAAC0"]
[Thu Sep 17 15:16:16.795956 2026] [security2:error] [pid 971102:tid 971336] [client 34.23.80.249:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/_phpinfo.php"] [unique_id "aqxYoOcL08BTTQixEnpmYgAAAGY"]
[Thu Sep 17 15:16:17.015155 2026] [security2:error] [pid 971102:tid 971329] [client 34.23.80.249:58240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/old_phpinfo.php"] [unique_id "aqxYoecL08BTTQixEnpmZwAAAF8"]
[Thu Sep 17 15:16:17.200784 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/server-info.php"] [unique_id "aqxYoecL08BTTQixEnpmcAAAAFU"]
[Thu Sep 17 15:16:17.229811 2026] [security2:error] [pid 971102:tid 971278] [client 209.38.197.191:54500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recessionnews.org"] [uri "/index.php"] [unique_id "aqxYoecL08BTTQixEnpmawAAACw"], referer: http://www.recessionnews.org/backup/
[Thu Sep 17 15:16:17.373061 2026] [security2:error] [pid 971102:tid 971275] [client 34.23.80.249:58252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/server-status.php"] [unique_id "aqxYoecL08BTTQixEnpmdQAAACk"]
[Thu Sep 17 15:16:17.620717 2026] [security2:error] [pid 971102:tid 971289] [client 209.38.197.191:54488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.recessionnews.org"] [uri "/index.php"] [unique_id "aqxYoecL08BTTQixEnpmdgAAADc"]
[Thu Sep 17 15:16:18.043750 2026] [security2:error] [pid 971102:tid 971257] [client 172.239.147.162:65278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxYoucL08BTTQixEnpmjwAAABc"], referer: binance.com
[Thu Sep 17 15:16:18.044842 2026] [security2:error] [pid 971102:tid 971276] [client 34.23.80.249:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYoucL08BTTQixEnpmkAAAACo"]
[Thu Sep 17 15:16:18.239098 2026] [security2:error] [pid 971102:tid 971314] [client 34.23.80.249:58272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmmgAAAFA"]
[Thu Sep 17 15:16:18.307239 2026] [security2:error] [pid 971102:tid 971285] [client 172.239.147.162:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxYoucL08BTTQixEnpmnQAAADM"], referer: binance.com
[Thu Sep 17 15:16:18.432484 2026] [security2:error] [pid 971102:tid 971317] [client 34.23.80.249:58274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmngAAAFM"]
[Thu Sep 17 15:16:18.627475 2026] [security2:error] [pid 971102:tid 971354] [client 34.23.80.249:58290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmoAAAAHg"]
[Thu Sep 17 15:16:18.799678 2026] [security2:error] [pid 971102:tid 971246] [client 34.23.80.249:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmpgAAAAw"]
[Thu Sep 17 15:16:18.989094 2026] [security2:error] [pid 971102:tid 971301] [client 34.23.80.249:58308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYoucL08BTTQixEnpmqwAAAEM"]
[Thu Sep 17 15:16:19.177288 2026] [security2:error] [pid 971102:tid 971313] [client 34.23.80.249:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxYo-cL08BTTQixEnpmrAAAAE8"]
[Thu Sep 17 15:16:19.216829 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:56449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYo-cL08BTTQixEnpmsAAAAAM"]
[Thu Sep 17 15:16:19.216941 2026] [security2:error] [pid 971102:tid 971237] [client 185.55.149.49:56449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYo-cL08BTTQixEnpmsAAAAAM"]
[Thu Sep 17 15:16:19.239703 2026] [security2:error] [pid 971102:tid 971335] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tcc.anl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxYoucL08BTTQixEnpmkgAAAGU"]
[Thu Sep 17 15:16:19.249328 2026] [security2:error] [pid 971102:tid 971306] [client 74.7.230.1:48596] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tcc.anl.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxYoecL08BTTQixEnpmjAAASFE"]
[Thu Sep 17 15:16:19.352441 2026] [security2:error] [pid 971102:tid 971299] [client 34.23.80.249:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php.old"] [unique_id "aqxYo-cL08BTTQixEnpmtAAAAEE"]
[Thu Sep 17 15:16:19.546784 2026] [security2:error] [pid 971102:tid 971323] [client 34.23.80.249:58350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php~"] [unique_id "aqxYo-cL08BTTQixEnpmtwAAAFk"]
[Thu Sep 17 15:16:19.752131 2026] [security2:error] [pid 971102:tid 971332] [client 34.23.80.249:58366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/info.php.bak"] [unique_id "aqxYo-cL08BTTQixEnpmuwAAAGI"]
[Thu Sep 17 15:16:19.958353 2026] [security2:error] [pid 971102:tid 971266] [client 34.23.80.249:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/phpinfo.php.save"] [unique_id "aqxYo-cL08BTTQixEnpmvQAAACA"]
[Thu Sep 17 15:16:20.003089 2026] [cgid:error] [pid 971102:tid 971168] [remote 200.231.6.3:52494] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:16:20.086131 2026] [security2:error] [pid 971102:tid 971245] [client 172.239.147.162:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxYpOcL08BTTQixEnpmxQAAAAs"], referer: binance.com
[Thu Sep 17 15:16:20.169527 2026] [security2:error] [pid 971102:tid 971308] [client 34.23.80.249:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpmyQAAAEo"]
[Thu Sep 17 15:16:20.245307 2026] [security2:error] [pid 971102:tid 971250] [client 57.141.14.74:20444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxYpOcL08BTTQixEnpmwwAAEDQ"]
[Thu Sep 17 15:16:20.268482 2026] [security2:error] [pid 971102:tid 971279] [client 172.239.147.162:59827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxYpOcL08BTTQixEnpmzQAAAC0"], referer: binance.com
[Thu Sep 17 15:16:20.330701 2026] [security2:error] [pid 971102:tid 971330] [client 178.20.44.82:52490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYpOcL08BTTQixEnpmygAAAGA"], referer: https://joeledmundanderson.com/understanding-genesis-11-the-tower-of-babel-and-yet-one-more-genealogy/
[Thu Sep 17 15:16:20.383903 2026] [security2:error] [pid 971102:tid 971341] [client 34.23.80.249:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpmzwAAAGs"]
[Thu Sep 17 15:16:20.607532 2026] [security2:error] [pid 971102:tid 971344] [client 34.23.80.249:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpm0QAAAG4"]
[Thu Sep 17 15:16:20.785283 2026] [security2:error] [pid 971102:tid 971307] [client 34.23.80.249:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpm1QAAAEk"]
[Thu Sep 17 15:16:20.803652 2026] [security2:error] [pid 971102:tid 971356] [client 45.169.98.18:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpOcL08BTTQixEnpm1gAAAHo"]
[Thu Sep 17 15:16:20.803803 2026] [security2:error] [pid 971102:tid 971356] [client 45.169.98.18:55752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpOcL08BTTQixEnpm1gAAAHo"]
[Thu Sep 17 15:16:20.966451 2026] [security2:error] [pid 971102:tid 971346] [client 34.23.80.249:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxYpOcL08BTTQixEnpm2gAAAHA"]
[Thu Sep 17 15:16:21.047396 2026] [security2:error] [pid 971102:tid 971319] [client 186.105.232.15:50912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm3QAAAFU"]
[Thu Sep 17 15:16:21.047570 2026] [security2:error] [pid 971102:tid 971319] [client 186.105.232.15:50912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm3QAAAFU"]
[Thu Sep 17 15:16:21.208709 2026] [security2:error] [pid 971102:tid 971264] [client 34.23.80.249:58416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/www/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm4QAAAB4"]
[Thu Sep 17 15:16:21.422871 2026] [security2:error] [pid 971102:tid 971239] [client 34.23.80.249:58428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm5AAAAAU"]
[Thu Sep 17 15:16:21.601935 2026] [security2:error] [pid 971102:tid 971209] [remote 111.225.149.173:50206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/friedrich-nietzsche-the-enlightenment-christianity-and-the-philosopher-of-the-hammer/"] [unique_id "aqxYpecL08BTTQixEnpm7AAAf2g"]
[Thu Sep 17 15:16:21.622929 2026] [security2:error] [pid 971102:tid 971281] [client 34.23.80.249:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm7QAAAC8"]
[Thu Sep 17 15:16:21.768755 2026] [security2:error] [pid 971102:tid 971254] [client 154.190.208.131:42317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm9QAAABQ"]
[Thu Sep 17 15:16:21.771566 2026] [security2:error] [pid 971102:tid 971254] [client 154.190.208.131:42317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm9QAAABQ"]
[Thu Sep 17 15:16:21.839589 2026] [security2:error] [pid 971102:tid 971302] [client 34.23.80.249:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/site/phpinfo.php"] [unique_id "aqxYpecL08BTTQixEnpm9gAAAEQ"]
[Thu Sep 17 15:16:21.944948 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm-gAAAGo"]
[Thu Sep 17 15:16:21.945080 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:55227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYpecL08BTTQixEnpm-gAAAGo"]
[Thu Sep 17 15:16:22.020980 2026] [security2:error] [pid 971102:tid 971351] [client 34.23.80.249:49418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpm_AAAAHU"]
[Thu Sep 17 15:16:22.133313 2026] [security2:error] [pid 971102:tid 971308] [client 35.238.4.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYpecL08BTTQixEnpm-QAAAEo"]
[Thu Sep 17 15:16:22.163207 2026] [security2:error] [pid 971102:tid 971320] [client 74.7.241.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.cfbpp.org"] [uri "/index.php"] [unique_id "aqxYoucL08BTTQixEnpmjgAAAFY"]
[Thu Sep 17 15:16:22.176603 2026] [security2:error] [pid 971102:tid 971318] [client 74.7.241.148:36676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.cfbpp.org"] [uri "/robots.txt"] [unique_id "aqxYoecL08BTTQixEnpmggAAVDk"]
[Thu Sep 17 15:16:22.199917 2026] [security2:error] [pid 971102:tid 971339] [client 34.23.80.249:49430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnAgAAAGk"]
[Thu Sep 17 15:16:22.396763 2026] [security2:error] [pid 971102:tid 971300] [client 34.23.80.249:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnDgAAAEI"]
[Thu Sep 17 15:16:22.597296 2026] [security2:error] [pid 971102:tid 971319] [client 34.23.80.249:49440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/core/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnEQAAAFU"]
[Thu Sep 17 15:16:22.657112 2026] [security2:error] [pid 971102:tid 971271] [client 172.239.147.162:61788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxYpucL08BTTQixEnpnFQAAACU"], referer: binance.com
[Thu Sep 17 15:16:22.663824 2026] [security2:error] [pid 971102:tid 971268] [client 172.239.147.162:58585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxYpucL08BTTQixEnpnFgAAACI"], referer: binance.com
[Thu Sep 17 15:16:22.816482 2026] [security2:error] [pid 971102:tid 971296] [client 34.23.80.249:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.80.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.doodlesatheart.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxYpucL08BTTQixEnpnGQAAAD4"]
[Thu Sep 17 15:16:23.726264 2026] [security2:error] [pid 971102:tid 971235] [client 20.244.34.24:62980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "airmacinc.com"] [uri "/index.php"] [unique_id "aqxYp-cL08BTTQixEnpnNwAAAAE"], referer: binance.com
[Thu Sep 17 15:16:23.932281 2026] [autoindex:error] [pid 971102:tid 971353] [client 40.87.20.23:3638] AH01276: Cannot serve directory /home1/ditkuemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:16:23.981737 2026] [security2:error] [pid 971102:tid 971305] [client 5.189.145.112:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxYp-cL08BTTQixEnpnQwAAAEc"], referer: binance.com
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:16:25.534110 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:55039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxYqecL08BTTQixEnpndgAAABY"], referer: binance.com
[Thu Sep 17 15:16:25.546357 2026] [security2:error] [pid 971102:tid 971346] [client 172.239.147.162:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxYqecL08BTTQixEnpndwAAAHA"], referer: binance.com
[Thu Sep 17 15:16:25.673853 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:63985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYqecL08BTTQixEnpnewAAAFc"]
[Thu Sep 17 15:16:25.674038 2026] [security2:error] [pid 971102:tid 971321] [client 156.192.234.52:63985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYqecL08BTTQixEnpnewAAAFc"]
[Thu Sep 17 15:16:26.242925 2026] [security2:error] [pid 971102:tid 971277] [client 24.10.29.245:34919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYqucL08BTTQixEnpniAAAKxA"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:16:26.932142 2026] [security2:error] [pid 971102:tid 971358] [client 172.239.147.162:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxYqucL08BTTQixEnpnlQAAAHw"], referer: binance.com
[Thu Sep 17 15:16:26.976890 2026] [security2:error] [pid 971102:tid 971228] [remote 47.128.115.43:56524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "endless-chronicles.com"] [uri "/robots.txt"] [unique_id "aqxYqucL08BTTQixEnpnlgAAL3s"]
[Thu Sep 17 15:16:27.532036 2026] [security2:error] [pid 971102:tid 971237] [client 172.239.147.162:53857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxYq-cL08BTTQixEnpnqQAAAAM"], referer: binance.com
[Thu Sep 17 15:16:27.830016 2026] [security2:error] [pid 971102:tid 971256] [client 24.10.29.245:58489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYq-cL08BTTQixEnpnrAAAFkE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818153512&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:16:28.708896 2026] [security2:error] [pid 971102:tid 971239] [client 172.239.147.162:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxYrOcL08BTTQixEnpnvAAAAAU"], referer: binance.com
[Thu Sep 17 15:16:29.105738 2026] [security2:error] [pid 971102:tid 971302] [client 172.239.147.162:54751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxYrecL08BTTQixEnpnyAAAAEQ"], referer: binance.com
[Thu Sep 17 15:16:30.004650 2026] [security2:error] [pid 971102:tid 971349] [client 185.55.149.49:64900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYrucL08BTTQixEnpn1AAAAHM"]
[Thu Sep 17 15:16:30.004770 2026] [security2:error] [pid 971102:tid 971349] [client 185.55.149.49:64900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYrucL08BTTQixEnpn1AAAAHM"]
[Thu Sep 17 15:16:30.696872 2026] [security2:error] [pid 971102:tid 971283] [client 172.239.147.162:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxYrucL08BTTQixEnpn5AAAADE"], referer: binance.com
[Thu Sep 17 15:16:31.243110 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYr-cL08BTTQixEnpn7gAAACY"]
[Thu Sep 17 15:16:31.243265 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYr-cL08BTTQixEnpn7gAAACY"]
[Thu Sep 17 15:16:31.314401 2026] [security2:error] [pid 971102:tid 971255] [client 5.189.145.112:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxYr-cL08BTTQixEnpn7wAAABU"], referer: binance.com
[Thu Sep 17 15:16:31.352724 2026] [security2:error] [pid 971102:tid 971267] [client 172.239.147.162:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxYr-cL08BTTQixEnpn8gAAACE"], referer: binance.com
[Thu Sep 17 15:16:31.858930 2026] [core:error] [pid 971102:tid 971250] [client 162.55.55.199:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:31.858956 2026] [core:error] [pid 971102:tid 971250] [client 162.55.55.199:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:32.144035 2026] [security2:error] [pid 971102:tid 971280] [client 186.105.232.15:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoAQAAAC4"]
[Thu Sep 17 15:16:32.144184 2026] [security2:error] [pid 971102:tid 971280] [client 186.105.232.15:51512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoAQAAAC4"]
[Thu Sep 17 15:16:32.253621 2026] [security2:error] [pid 971102:tid 971336] [client 154.190.208.131:42633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoBQAAAGY"]
[Thu Sep 17 15:16:32.253780 2026] [security2:error] [pid 971102:tid 971336] [client 154.190.208.131:42633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoBQAAAGY"]
[Thu Sep 17 15:16:32.477087 2026] [security2:error] [pid 971102:tid 971234] [client 172.239.147.162:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxYsOcL08BTTQixEnpoEQAAAAA"], referer: binance.com
[Thu Sep 17 15:16:32.557171 2026] [security2:error] [pid 971102:tid 971357] [client 114.198.138.124:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoFwAAAHs"]
[Thu Sep 17 15:16:32.557341 2026] [security2:error] [pid 971102:tid 971357] [client 114.198.138.124:55864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsOcL08BTTQixEnpoFwAAAHs"]
[Thu Sep 17 15:16:32.970015 2026] [security2:error] [pid 971102:tid 971139] [remote 182.10.99.112:1396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYsOcL08BTTQixEnpoHwAAJCM"]
[Thu Sep 17 15:16:33.515017 2026] [security2:error] [pid 971102:tid 971261] [client 172.239.147.162:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxYsecL08BTTQixEnpoKQAAABs"], referer: binance.com
[Thu Sep 17 15:16:33.653042 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:38438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYsecL08BTTQixEnpoLAAAAAI"]
[Thu Sep 17 15:16:33.657219 2026] [security2:error] [pid 971102:tid 971361] [client 103.131.71.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxYsOcL08BTTQixEnpoFQAAAH8"]
[Thu Sep 17 15:16:33.810103 2026] [security2:error] [pid 971102:tid 971323] [client 172.239.147.162:50797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxYsecL08BTTQixEnpoLgAAAFk"], referer: binance.com
[Thu Sep 17 15:16:33.893861 2026] [security2:error] [pid 971102:tid 971237] [client 162.241.226.11:33296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxYsOcL08BTTQixEnpoGgAAAAM"]
[Thu Sep 17 15:16:34.050794 2026] [security2:error] [pid 971102:tid 971310] [client 34.97.30.29:58432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoNgAAAEw"]
[Thu Sep 17 15:16:34.063142 2026] [security2:error] [pid 971102:tid 971171] [remote 173.239.211.244:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edmagik.com"] [uri "/wp-login.php"] [unique_id "aqxYsucL08BTTQixEnpoNAAAZEM"]
[Thu Sep 17 15:16:34.080804 2026] [security2:error] [pid 971102:tid 971257] [client 189.63.146.109:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.146.63.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavilladesantaclaus.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsecL08BTTQixEnpoMgAAABc"]
[Thu Sep 17 15:16:34.080985 2026] [security2:error] [pid 971102:tid 971257] [client 189.63.146.109:56306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lavilladesantaclaus.com"] [uri "/xmlrpc.php"] [unique_id "aqxYsecL08BTTQixEnpoMgAAABc"]
[Thu Sep 17 15:16:34.104335 2026] [security2:error] [pid 971102:tid 971151] [remote 45.92.229.1:26727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/wp-login.php"] [unique_id "aqxYsucL08BTTQixEnpoNwAAOC8"]
[Thu Sep 17 15:16:34.357709 2026] [security2:error] [pid 971102:tid 971246] [client 139.99.25.135:62042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoOgAAAAw"]
[Thu Sep 17 15:16:34.421459 2026] [security2:error] [pid 971102:tid 971278] [client 34.97.30.29:58436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoPAAAACw"]
[Thu Sep 17 15:16:34.798367 2026] [security2:error] [pid 971102:tid 971307] [client 139.99.25.135:62149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYsucL08BTTQixEnpoRgAAAEk"]
[Thu Sep 17 15:16:34.943310 2026] [security2:error] [pid 971102:tid 971247] [client 172.239.147.162:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxYsucL08BTTQixEnpoTAAAAA0"], referer: binance.com
[Thu Sep 17 15:16:34.960022 2026] [security2:error] [pid 971102:tid 971234] [client 162.241.226.11:33310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxYsecL08BTTQixEnpoMQAAAAA"]
[Thu Sep 17 15:16:35.058022 2026] [security2:error] [pid 971102:tid 971325] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYsucL08BTTQixEnpoSwAAAFs"]
[Thu Sep 17 15:16:35.314458 2026] [security2:error] [pid 971102:tid 971254] [client 34.97.30.29:58442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.ahmedteleb.com"] [uri "/"] [unique_id "aqxYs-cL08BTTQixEnpoUQAAABQ"]
[Thu Sep 17 15:16:35.444806 2026] [security2:error] [pid 971102:tid 971358] [client 20.255.75.24:1033] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tesselessetbooks.com"] [uri "/1.php"] [unique_id "aqxYs-cL08BTTQixEnpoWAAAAHw"]
[Thu Sep 17 15:16:35.444923 2026] [security2:error] [pid 971102:tid 971358] [client 20.255.75.24:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/1.php"] [unique_id "aqxYs-cL08BTTQixEnpoWAAAAHw"]
[Thu Sep 17 15:16:35.627413 2026] [security2:error] [pid 971102:tid 971250] [client 139.99.25.135:62337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYs-cL08BTTQixEnpoWgAAABA"]
[Thu Sep 17 15:16:35.683095 2026] [security2:error] [pid 971102:tid 971276] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env"] [unique_id "aqxYs-cL08BTTQixEnpoWwAAACo"]
[Thu Sep 17 15:16:35.808641 2026] [core:error] [pid 971102:tid 971251] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:35.808685 2026] [core:error] [pid 971102:tid 971251] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:16:35.926757 2026] [security2:error] [pid 971102:tid 971361] [client 20.255.75.24:1364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/new.php"] [unique_id "aqxYs-cL08BTTQixEnpoZgAAAH8"]
[Thu Sep 17 15:16:35.943497 2026] [security2:error] [pid 971102:tid 971350] [client 172.239.147.162:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxYs-cL08BTTQixEnpoaAAAAHQ"], referer: binance.com
[Thu Sep 17 15:16:35.958110 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYs-cL08BTTQixEnpoYgAAAA8"]
[Thu Sep 17 15:16:36.065889 2026] [security2:error] [pid 971102:tid 971284] [client 139.99.25.135:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/"] [unique_id "aqxYtOcL08BTTQixEnpobAAAADI"]
[Thu Sep 17 15:16:36.211934 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:64627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYtOcL08BTTQixEnpocQAAAFA"]
[Thu Sep 17 15:16:36.213143 2026] [security2:error] [pid 971102:tid 971314] [client 156.192.234.52:64627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYtOcL08BTTQixEnpocQAAAFA"]
[Thu Sep 17 15:16:36.413742 2026] [security2:error] [pid 971102:tid 971296] [client 20.255.75.24:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/num.php"] [unique_id "aqxYtOcL08BTTQixEnpoewAAAD4"]
[Thu Sep 17 15:16:36.418101 2026] [security2:error] [pid 971102:tid 971315] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtOcL08BTTQixEnpodAAAAFE"]
[Thu Sep 17 15:16:36.491026 2026] [security2:error] [pid 971102:tid 971316] [client 139.99.25.135:62532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.25.99.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.talent-in-borders.com"] [uri "/runtime/archive/xz.php"] [unique_id "aqxYtOcL08BTTQixEnpofgAAAFI"]
[Thu Sep 17 15:16:36.593858 2026] [security2:error] [pid 971102:tid 971345] [client 41.210.157.227:47437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYtOcL08BTTQixEnpofQAAbzk"]
[Thu Sep 17 15:16:36.691587 2026] [security2:error] [pid 971102:tid 971244] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtOcL08BTTQixEnpoggAAAAo"]
[Thu Sep 17 15:16:37.080315 2026] [security2:error] [pid 971102:tid 971327] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtOcL08BTTQixEnpoiQAAAF0"]
[Thu Sep 17 15:16:37.106001 2026] [security2:error] [pid 971102:tid 971338] [client 20.255.75.24:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/admin.php"] [unique_id "aqxYtecL08BTTQixEnpokAAAAGg"]
[Thu Sep 17 15:16:37.461048 2026] [security2:error] [pid 971102:tid 971320] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtecL08BTTQixEnpolgAAAFY"]
[Thu Sep 17 15:16:37.546757 2026] [security2:error] [pid 971102:tid 971272] [client 172.239.147.162:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxYtecL08BTTQixEnponAAAACY"], referer: binance.com
[Thu Sep 17 15:16:37.553887 2026] [security2:error] [pid 971102:tid 971323] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "aqxYtecL08BTTQixEnponQAAAFk"]
[Thu Sep 17 15:16:37.611594 2026] [security2:error] [pid 971102:tid 971259] [client 20.255.75.24:1359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/13.php"] [unique_id "aqxYtecL08BTTQixEnpongAAABk"]
[Thu Sep 17 15:16:37.834522 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtecL08BTTQixEnpoogAAAA8"]
[Thu Sep 17 15:16:37.892392 2026] [security2:error] [pid 971102:tid 971281] [client 172.239.147.162:56257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxYtecL08BTTQixEnpoqQAAAC8"], referer: binance.com
[Thu Sep 17 15:16:37.962710 2026] [security2:error] [pid 971102:tid 971286] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.bak"] [unique_id "aqxYtecL08BTTQixEnporQAAADQ"]
[Thu Sep 17 15:16:38.082723 2026] [security2:error] [pid 971102:tid 971241] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.backup"] [unique_id "aqxYtucL08BTTQixEnposwAAAAc"]
[Thu Sep 17 15:16:38.096516 2026] [security2:error] [pid 971102:tid 971300] [client 20.255.75.24:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/222.php"] [unique_id "aqxYtucL08BTTQixEnpotQAAAEI"]
[Thu Sep 17 15:16:38.330300 2026] [security2:error] [pid 971102:tid 971270] [client 5.189.145.112:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxYtucL08BTTQixEnpougAAACQ"], referer: binance.com
[Thu Sep 17 15:16:38.338868 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtucL08BTTQixEnpouAAAABg"]
[Thu Sep 17 15:16:38.432073 2026] [security2:error] [pid 971102:tid 971345] [client 74.7.175.166:49460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "www.escribirglobal.gocbeglobal.com"] [uri "/robots.txt"] [unique_id "aqxYtucL08BTTQixEnpovgAAb24"]
[Thu Sep 17 15:16:38.564973 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.old"] [unique_id "aqxYtucL08BTTQixEnpowAAAAFw"]
[Thu Sep 17 15:16:38.589725 2026] [security2:error] [pid 971102:tid 971245] [client 20.255.75.24:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/aa.php"] [unique_id "aqxYtucL08BTTQixEnpowQAAAAs"]
[Thu Sep 17 15:16:38.915040 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYtucL08BTTQixEnpoxQAAAHc"]
[Thu Sep 17 15:16:39.104744 2026] [security2:error] [pid 971102:tid 971295] [client 20.255.75.24:1357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/abcd.php"] [unique_id "aqxYt-cL08BTTQixEnpo1QAAAD0"]
[Thu Sep 17 15:16:39.201838 2026] [security2:error] [pid 971102:tid 971272] [client 134.185.85.61:54138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "clarkcountyclothing.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYt-cL08BTTQixEnpo2QAAACY"]
[Thu Sep 17 15:16:39.215278 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYt-cL08BTTQixEnpo1gAAAC0"]
[Thu Sep 17 15:16:39.249034 2026] [security2:error] [pid 971102:tid 971250] [client 172.239.147.162:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxYt-cL08BTTQixEnpo2wAAABA"], referer: binance.com
[Thu Sep 17 15:16:39.270309 2026] [security2:error] [pid 971102:tid 971320] [client 172.239.147.162:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxYt-cL08BTTQixEnpo3AAAAFY"], referer: binance.com
[Thu Sep 17 15:16:39.357908 2026] [security2:error] [pid 971102:tid 971288] [client 104.28.198.244:22906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYt-cL08BTTQixEnpo4AAAADY"]
[Thu Sep 17 15:16:39.358028 2026] [security2:error] [pid 971102:tid 971288] [client 104.28.198.244:22906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYt-cL08BTTQixEnpo4AAAADY"]
[Thu Sep 17 15:16:39.454348 2026] [security2:error] [pid 971102:tid 971347] [client 34.74.242.206:41745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxYt-cL08BTTQixEnpo5gAAAHE"]
[Thu Sep 17 15:16:39.454460 2026] [security2:error] [pid 971102:tid 971347] [client 34.74.242.206:41745] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxYt-cL08BTTQixEnpo5gAAAHE"]
[Thu Sep 17 15:16:39.560161 2026] [security2:error] [pid 971102:tid 971317] [client 34.74.242.206:41736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stevenreedcollins.com"] [uri "/"] [unique_id "aqxYt-cL08BTTQixEnpo6AAAAFM"]
[Thu Sep 17 15:16:39.560271 2026] [security2:error] [pid 971102:tid 971317] [client 34.74.242.206:41736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.stevenreedcollins.com"] [uri "/"] [unique_id "aqxYt-cL08BTTQixEnpo6AAAAFM"]
[Thu Sep 17 15:16:39.584603 2026] [security2:error] [pid 971102:tid 971281] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYt-cL08BTTQixEnpo5wAAAC8"]
[Thu Sep 17 15:16:39.589756 2026] [security2:error] [pid 971102:tid 971256] [client 134.185.85.61:64882] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "clarkcountyclothing.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYt-cL08BTTQixEnpo6wAAABY"]
[Thu Sep 17 15:16:39.632086 2026] [security2:error] [pid 971102:tid 971319] [client 20.255.75.24:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/about.php"] [unique_id "aqxYt-cL08BTTQixEnpo8AAAAFU"]
[Thu Sep 17 15:16:39.829516 2026] [autoindex:error] [pid 971102:tid 971269] [client 34.24.217.248:60024] AH01276: Cannot serve directory /home1/haatpamy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:16:39.870714 2026] [security2:error] [pid 971102:tid 971315] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYt-cL08BTTQixEnpo9gAAAFE"]
[Thu Sep 17 15:16:39.885103 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYt-cL08BTTQixEnpo-wAAAG4"]
[Thu Sep 17 15:16:39.895264 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "aqxYt-cL08BTTQixEnpo_AAAAFg"]
[Thu Sep 17 15:16:40.049450 2026] [security2:error] [pid 971102:tid 971234] [client 34.24.217.248:60038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYuOcL08BTTQixEnppBwAAAAA"]
[Thu Sep 17 15:16:40.116685 2026] [security2:error] [pid 971102:tid 971348] [client 20.255.75.24:1034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/admin.php"] [unique_id "aqxYuOcL08BTTQixEnppCAAAAHI"]
[Thu Sep 17 15:16:40.126545 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "aqxYuOcL08BTTQixEnppCQAAAHU"]
[Thu Sep 17 15:16:40.152272 2026] [security2:error] [pid 971102:tid 971247] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppAwAAAA0"]
[Thu Sep 17 15:16:40.212554 2026] [security2:error] [pid 971102:tid 971283] [client 34.24.217.248:60048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYuOcL08BTTQixEnppCwAAADE"]
[Thu Sep 17 15:16:40.219420 2026] [security2:error] [pid 971102:tid 971261] [client 171.8.87.141:45406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppCgAAGxw"]
[Thu Sep 17 15:16:40.451959 2026] [security2:error] [pid 971102:tid 971276] [client 34.24.217.248:60062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/"] [unique_id "aqxYuOcL08BTTQixEnppGgAAACo"]
[Thu Sep 17 15:16:40.502777 2026] [security2:error] [pid 971102:tid 971350] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppFAAAAHQ"]
[Thu Sep 17 15:16:40.589183 2026] [security2:error] [pid 971102:tid 971279] [client 103.131.71.35:64017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "norifon.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppHAAAAC0"]
[Thu Sep 17 15:16:40.605123 2026] [security2:error] [pid 971102:tid 971360] [client 20.255.75.24:1349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/adminfuns.php"] [unique_id "aqxYuOcL08BTTQixEnppIQAAAH4"]
[Thu Sep 17 15:16:40.620891 2026] [security2:error] [pid 971102:tid 971323] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env"] [unique_id "aqxYuOcL08BTTQixEnppIgAAAFk"]
[Thu Sep 17 15:16:40.646411 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "aqxYuOcL08BTTQixEnppIwAAAAc"]
[Thu Sep 17 15:16:40.658206 2026] [security2:error] [pid 971102:tid 971288] [client 34.172.22.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppHQAAADY"]
[Thu Sep 17 15:16:40.711505 2026] [security2:error] [pid 971102:tid 971305] [client 185.55.149.49:49301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYuOcL08BTTQixEnppJwAAAEc"]
[Thu Sep 17 15:16:40.711641 2026] [security2:error] [pid 971102:tid 971305] [client 185.55.149.49:49301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYuOcL08BTTQixEnppJwAAAEc"]
[Thu Sep 17 15:16:40.901133 2026] [security2:error] [pid 971102:tid 971265] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuOcL08BTTQixEnppKwAAAB8"]
[Thu Sep 17 15:16:41.025753 2026] [security2:error] [pid 971102:tid 971329] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxYuecL08BTTQixEnppNQAAAF8"]
[Thu Sep 17 15:16:41.081015 2026] [security2:error] [pid 971102:tid 971282] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxYuecL08BTTQixEnppOAAAADA"]
[Thu Sep 17 15:16:41.106261 2026] [security2:error] [pid 971102:tid 971269] [client 20.255.75.24:1047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxYuecL08BTTQixEnppOQAAACM"]
[Thu Sep 17 15:16:41.198588 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxYuecL08BTTQixEnppPQAAAAk"]
[Thu Sep 17 15:16:41.219818 2026] [security2:error] [pid 971102:tid 971240] [client 172.239.147.162:63738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxYuecL08BTTQixEnppQAAAAAY"], referer: binance.com
[Thu Sep 17 15:16:41.254304 2026] [security2:error] [pid 971102:tid 971274] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuecL08BTTQixEnppOgAAACg"]
[Thu Sep 17 15:16:41.591087 2026] [security2:error] [pid 971102:tid 971361] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuecL08BTTQixEnppUQAAAH8"]
[Thu Sep 17 15:16:41.634089 2026] [security2:error] [pid 971102:tid 971260] [client 20.255.75.24:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/ae.php"] [unique_id "aqxYuecL08BTTQixEnppWQAAABo"]
[Thu Sep 17 15:16:41.740437 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuecL08BTTQixEnppXQAAACY"]
[Thu Sep 17 15:16:41.740554 2026] [security2:error] [pid 971102:tid 971272] [client 45.169.98.18:56975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuecL08BTTQixEnppXQAAACY"]
[Thu Sep 17 15:16:41.829128 2026] [security2:error] [pid 971102:tid 971349] [client 216.73.161.135:27483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/wp-login.php"] [unique_id "aqxYuecL08BTTQixEnppXwAAAHM"]
[Thu Sep 17 15:16:41.950937 2026] [security2:error] [pid 971102:tid 971280] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuecL08BTTQixEnppZQAAAC4"]
[Thu Sep 17 15:16:41.985379 2026] [security2:error] [pid 971102:tid 971342] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxYuecL08BTTQixEnppbAAAAGw"]
[Thu Sep 17 15:16:42.059180 2026] [security2:error] [pid 971102:tid 971256] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.env~"] [unique_id "aqxYuucL08BTTQixEnppbQAAABY"]
[Thu Sep 17 15:16:42.155668 2026] [security2:error] [pid 971102:tid 971246] [client 20.255.75.24:1346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/akcc.php"] [unique_id "aqxYuucL08BTTQixEnppdgAAAAw"]
[Thu Sep 17 15:16:42.164457 2026] [security2:error] [pid 971102:tid 971334] [client 172.239.147.162:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxYuucL08BTTQixEnppdwAAAGQ"], referer: binance.com
[Thu Sep 17 15:16:42.373498 2026] [security2:error] [pid 971102:tid 971275] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuucL08BTTQixEnppfAAAACk"]
[Thu Sep 17 15:16:42.516229 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env.swp"] [unique_id "aqxYuucL08BTTQixEnpphwAAAHU"]
[Thu Sep 17 15:16:42.566539 2026] [security2:error] [pid 971102:tid 971293] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxYuucL08BTTQixEnppiAAAADs"]
[Thu Sep 17 15:16:42.631192 2026] [security2:error] [pid 971102:tid 971332] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxYuucL08BTTQixEnppiwAAAGI"]
[Thu Sep 17 15:16:42.646543 2026] [security2:error] [pid 971102:tid 971268] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.env~"] [unique_id "aqxYuucL08BTTQixEnppjAAAACI"]
[Thu Sep 17 15:16:42.682566 2026] [security2:error] [pid 971102:tid 971346] [client 20.255.75.24:1347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/bak.php"] [unique_id "aqxYuucL08BTTQixEnppjwAAAHA"]
[Thu Sep 17 15:16:42.692878 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxYuucL08BTTQixEnppkAAAAHQ"]
[Thu Sep 17 15:16:42.751705 2026] [security2:error] [pid 971102:tid 971324] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxYuucL08BTTQixEnppkwAAAFo"]
[Thu Sep 17 15:16:42.777359 2026] [security2:error] [pid 971102:tid 971243] [client 154.190.208.131:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuucL08BTTQixEnpplgAAAAk"]
[Thu Sep 17 15:16:42.778195 2026] [security2:error] [pid 971102:tid 971243] [client 154.190.208.131:41920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYuucL08BTTQixEnpplgAAAAk"]
[Thu Sep 17 15:16:42.833112 2026] [security2:error] [pid 971102:tid 971253] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxYuucL08BTTQixEnppmQAAABM"]
[Thu Sep 17 15:16:42.897730 2026] [security2:error] [pid 971102:tid 971235] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxYuucL08BTTQixEnppnAAAAAE"]
[Thu Sep 17 15:16:42.934622 2026] [security2:error] [pid 971102:tid 971264] [client 159.69.158.189:32662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxYuucL08BTTQixEnppoAAAAB4"], referer: https://faewave.com
[Thu Sep 17 15:16:42.940050 2026] [security2:error] [pid 971102:tid 971338] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYuucL08BTTQixEnppmAAAAGg"]
[Thu Sep 17 15:16:43.029561 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxYu-cL08BTTQixEnppowAAAC8"]
[Thu Sep 17 15:16:43.040294 2026] [security2:error] [pid 971102:tid 971308] [client 51.161.128.55:45778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "argentumequitycapital.com"] [uri "/webmail"] [unique_id "aqxYu-cL08BTTQixEnpppAAAAEo"]
[Thu Sep 17 15:16:43.054310 2026] [security2:error] [pid 971102:tid 971358] [client 51.161.128.55:45792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "argentumequitycapital.com"] [uri "/mail"] [unique_id "aqxYu-cL08BTTQixEnpppQAAAHw"]
[Thu Sep 17 15:16:43.067430 2026] [security2:error] [pid 971102:tid 971294] [client 51.161.128.55:45808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.argentumequitycapital.com"] [uri "/"] [unique_id "aqxYu-cL08BTTQixEnpppgAAADw"]
[Thu Sep 17 15:16:43.092041 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxYu-cL08BTTQixEnppqQAAABk"]
[Thu Sep 17 15:16:43.152052 2026] [security2:error] [pid 971102:tid 971277] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxYu-cL08BTTQixEnppqwAAACs"]
[Thu Sep 17 15:16:43.209708 2026] [security2:error] [pid 971102:tid 971252] [client 20.255.75.24:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/cc.php"] [unique_id "aqxYu-cL08BTTQixEnpprwAAABI"]
[Thu Sep 17 15:16:43.212760 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxYu-cL08BTTQixEnppsAAAAFE"]
[Thu Sep 17 15:16:43.224331 2026] [security2:error] [pid 971102:tid 971255] [client 51.161.128.55:45814] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.argentumequitycapital.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "aqxYu-cL08BTTQixEnppswAAABU"]
[Thu Sep 17 15:16:43.238902 2026] [security2:error] [pid 971102:tid 971314] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYu-cL08BTTQixEnppqgAAAFA"]
[Thu Sep 17 15:16:43.257405 2026] [security2:error] [pid 971102:tid 971236] [client 114.198.138.124:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnpptgAAAAI"]
[Thu Sep 17 15:16:43.257493 2026] [security2:error] [pid 971102:tid 971236] [client 114.198.138.124:62289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnpptgAAAAI"]
[Thu Sep 17 15:16:43.281183 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxYu-cL08BTTQixEnpptwAAAGA"]
[Thu Sep 17 15:16:43.313266 2026] [security2:error] [pid 971102:tid 971360] [client 172.239.147.162:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxYu-cL08BTTQixEnppuAAAAH4"], referer: binance.com
[Thu Sep 17 15:16:43.343007 2026] [security2:error] [pid 971102:tid 971322] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxYu-cL08BTTQixEnppuQAAAFg"]
[Thu Sep 17 15:16:43.401477 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxYu-cL08BTTQixEnppwAAAAFQ"]
[Thu Sep 17 15:16:43.456727 2026] [security2:error] [pid 971102:tid 971295] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxYu-cL08BTTQixEnppxgAAAD0"]
[Thu Sep 17 15:16:43.474678 2026] [security2:error] [pid 971102:tid 971288] [client 186.105.232.15:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnppyAAAADY"]
[Thu Sep 17 15:16:43.474832 2026] [security2:error] [pid 971102:tid 971288] [client 186.105.232.15:52121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYu-cL08BTTQixEnppyAAAADY"]
[Thu Sep 17 15:16:43.513277 2026] [security2:error] [pid 971102:tid 971239] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxYu-cL08BTTQixEnppygAAAAU"]
[Thu Sep 17 15:16:43.564757 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYu-cL08BTTQixEnppxAAAAHU"]
[Thu Sep 17 15:16:43.568854 2026] [security2:error] [pid 971102:tid 971332] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxYu-cL08BTTQixEnppywAAAGI"]
[Thu Sep 17 15:16:43.595609 2026] [security2:error] [pid 971102:tid 971312] [client 172.239.147.162:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxYu-cL08BTTQixEnppzgAAAE4"], referer: binance.com
[Thu Sep 17 15:16:43.624616 2026] [security2:error] [pid 971102:tid 971359] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxYu-cL08BTTQixEnppzwAAAH0"]
[Thu Sep 17 15:16:43.680079 2026] [security2:error] [pid 971102:tid 971307] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxYu-cL08BTTQixEnpp0QAAAEk"]
[Thu Sep 17 15:16:43.714544 2026] [security2:error] [pid 971102:tid 971325] [client 20.255.75.24:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/chosen.php"] [unique_id "aqxYu-cL08BTTQixEnpp0wAAAFs"]
[Thu Sep 17 15:16:43.734810 2026] [security2:error] [pid 971102:tid 971289] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxYu-cL08BTTQixEnpp1gAAADc"]
[Thu Sep 17 15:16:43.791279 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxYu-cL08BTTQixEnpp2gAAAC8"]
[Thu Sep 17 15:16:43.846541 2026] [security2:error] [pid 971102:tid 971308] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxYu-cL08BTTQixEnpp2wAAAEo"]
[Thu Sep 17 15:16:43.903339 2026] [security2:error] [pid 971102:tid 971341] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxYu-cL08BTTQixEnpp3wAAAGs"]
[Thu Sep 17 15:16:43.960413 2026] [security2:error] [pid 971102:tid 971327] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxYu-cL08BTTQixEnpp4QAAAF0"]
[Thu Sep 17 15:16:44.021533 2026] [security2:error] [pid 971102:tid 971280] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxYvOcL08BTTQixEnpp5gAAAC4"]
[Thu Sep 17 15:16:44.082635 2026] [security2:error] [pid 971102:tid 971354] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxYvOcL08BTTQixEnpp6QAAAHg"]
[Thu Sep 17 15:16:44.149527 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxYvOcL08BTTQixEnpp7QAAAG4"]
[Thu Sep 17 15:16:44.209642 2026] [security2:error] [pid 971102:tid 971252] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYvOcL08BTTQixEnpp6wAAABI"]
[Thu Sep 17 15:16:44.211901 2026] [security2:error] [pid 971102:tid 971306] [client 20.255.75.24:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/classwithtostring.php"] [unique_id "aqxYvOcL08BTTQixEnpp7wAAAEg"]
[Thu Sep 17 15:16:44.213706 2026] [security2:error] [pid 971102:tid 971255] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxYvOcL08BTTQixEnpp8AAAABU"]
[Thu Sep 17 15:16:44.281357 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxYvOcL08BTTQixEnpp8QAAAGQ"]
[Thu Sep 17 15:16:44.311456 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "aqxYvOcL08BTTQixEnpp8gAAABA"]
[Thu Sep 17 15:16:44.360738 2026] [security2:error] [pid 971102:tid 971328] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxYvOcL08BTTQixEnpp8wAAAF4"]
[Thu Sep 17 15:16:44.425710 2026] [security2:error] [pid 971102:tid 971237] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxYvOcL08BTTQixEnpp9gAAAAM"]
[Thu Sep 17 15:16:44.489465 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxYvOcL08BTTQixEnpp-gAAAAo"]
[Thu Sep 17 15:16:44.547182 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "aqxYvOcL08BTTQixEnpp-wAAABc"]
[Thu Sep 17 15:16:44.551414 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxYvOcL08BTTQixEnpp_AAAAGA"]
[Thu Sep 17 15:16:44.560589 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYvOcL08BTTQixEnpp9wAAAHM"]
[Thu Sep 17 15:16:44.611702 2026] [security2:error] [pid 971102:tid 971321] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxYvOcL08BTTQixEnpqAAAAAFc"]
[Thu Sep 17 15:16:44.669539 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxYvOcL08BTTQixEnpqAQAAACA"]
[Thu Sep 17 15:16:44.731161 2026] [security2:error] [pid 971102:tid 971360] [client 20.255.75.24:1345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/wp-signup.php"] [unique_id "aqxYvOcL08BTTQixEnpqAwAAAH4"]
[Thu Sep 17 15:16:44.733133 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/app/.env"] [unique_id "aqxYvOcL08BTTQixEnpqBAAAAHI"]
[Thu Sep 17 15:16:44.733147 2026] [security2:error] [pid 971102:tid 971302] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxYvOcL08BTTQixEnpqBQAAAEQ"]
[Thu Sep 17 15:16:44.793857 2026] [security2:error] [pid 971102:tid 971288] [client 69.130.172.199:39029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYvOcL08BTTQixEnpqAgAANhM"], referer: https://www.google.com/
[Thu Sep 17 15:16:44.793884 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxYvOcL08BTTQixEnpqCAAAACc"], referer: binance.com
[Thu Sep 17 15:16:44.794975 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxYvOcL08BTTQixEnpqCQAAAHU"]
[Thu Sep 17 15:16:44.853335 2026] [security2:error] [pid 971102:tid 971311] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxYvOcL08BTTQixEnpqCwAAAE0"]
[Thu Sep 17 15:16:44.855825 2026] [security2:error] [pid 971102:tid 971234] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/apps/.env"] [unique_id "aqxYvOcL08BTTQixEnpqDAAAAAA"]
[Thu Sep 17 15:16:44.876443 2026] [security2:error] [pid 971102:tid 971283] [client 172.239.147.162:62906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxYvOcL08BTTQixEnpqDQAAADE"], referer: binance.com
[Thu Sep 17 15:16:44.913622 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxYvOcL08BTTQixEnpqEAAAAAk"]
[Thu Sep 17 15:16:44.977042 2026] [security2:error] [pid 971102:tid 971326] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxYvOcL08BTTQixEnpqEQAAAFw"]
[Thu Sep 17 15:16:44.980976 2026] [security2:error] [pid 971102:tid 971313] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/.env"] [unique_id "aqxYvOcL08BTTQixEnpqEwAAAE8"]
[Thu Sep 17 15:16:45.038253 2026] [security2:error] [pid 971102:tid 971260] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxYvecL08BTTQixEnpqFAAAABo"]
[Thu Sep 17 15:16:45.101473 2026] [security2:error] [pid 971102:tid 971245] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxYvecL08BTTQixEnpqGQAAAAs"]
[Thu Sep 17 15:16:45.105288 2026] [security2:error] [pid 971102:tid 971325] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/web/.env"] [unique_id "aqxYvecL08BTTQixEnpqGgAAAFs"]
[Thu Sep 17 15:16:45.163399 2026] [security2:error] [pid 971102:tid 971272] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxYvecL08BTTQixEnpqHgAAACY"]
[Thu Sep 17 15:16:45.224182 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxYvecL08BTTQixEnpqHwAAAHc"]
[Thu Sep 17 15:16:45.229320 2026] [security2:error] [pid 971102:tid 971264] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/site/.env"] [unique_id "aqxYvecL08BTTQixEnpqIAAAAB4"]
[Thu Sep 17 15:16:45.235409 2026] [security2:error] [pid 971102:tid 971235] [client 20.255.75.24:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/doc.php"] [unique_id "aqxYvecL08BTTQixEnpqIQAAAAE"]
[Thu Sep 17 15:16:45.286350 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxYvecL08BTTQixEnpqIgAAAC8"]
[Thu Sep 17 15:16:45.360963 2026] [security2:error] [pid 971102:tid 971356] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/public/.env"] [unique_id "aqxYvecL08BTTQixEnpqJQAAAHo"]
[Thu Sep 17 15:16:45.469813 2026] [security2:error] [pid 971102:tid 971261] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxYvecL08BTTQixEnpqLwAAABs"]
[Thu Sep 17 15:16:45.524476 2026] [security2:error] [pid 971102:tid 971354] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxYvecL08BTTQixEnpqMwAAAHg"]
[Thu Sep 17 15:16:45.579449 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxYvecL08BTTQixEnpqNQAAAG4"]
[Thu Sep 17 15:16:45.636280 2026] [security2:error] [pid 971102:tid 971336] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxYvecL08BTTQixEnpqNgAAAGY"]
[Thu Sep 17 15:16:45.641013 2026] [security2:error] [pid 971102:tid 971271] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYvecL08BTTQixEnpqMgAAACU"]
[Thu Sep 17 15:16:45.690892 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxYvecL08BTTQixEnpqNwAAAGQ"]
[Thu Sep 17 15:16:45.747780 2026] [security2:error] [pid 971102:tid 971269] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxYvecL08BTTQixEnpqPAAAACM"]
[Thu Sep 17 15:16:45.755943 2026] [security2:error] [pid 971102:tid 971252] [client 20.255.75.24:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/edit.php"] [unique_id "aqxYvecL08BTTQixEnpqPQAAABI"]
[Thu Sep 17 15:16:45.785987 2026] [security2:error] [pid 971102:tid 971319] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/backend/.env"] [unique_id "aqxYvecL08BTTQixEnpqPgAAAFU"]
[Thu Sep 17 15:16:45.806125 2026] [security2:error] [pid 971102:tid 971292] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxYvecL08BTTQixEnpqPwAAADo"]
[Thu Sep 17 15:16:45.860966 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxYvecL08BTTQixEnpqQAAAAAo"]
[Thu Sep 17 15:16:45.904459 2026] [security2:error] [pid 971102:tid 971267] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/server/.env"] [unique_id "aqxYvecL08BTTQixEnpqRwAAACE"]
[Thu Sep 17 15:16:45.915394 2026] [security2:error] [pid 971102:tid 971290] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxYvecL08BTTQixEnpqSAAAADg"]
[Thu Sep 17 15:16:45.974064 2026] [security2:error] [pid 971102:tid 971337] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxYvecL08BTTQixEnpqSwAAAGc"]
[Thu Sep 17 15:16:46.025567 2026] [security2:error] [pid 971102:tid 971340] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/frontend/.env"] [unique_id "aqxYvucL08BTTQixEnpqTQAAAGo"]
[Thu Sep 17 15:16:46.027788 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxYvucL08BTTQixEnpqTgAAACA"]
[Thu Sep 17 15:16:46.068213 2026] [security2:error] [pid 971102:tid 971318] [client 69.130.172.199:33147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYvecL08BTTQixEnpqTAAAVFU"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260612184752&hidebots=0&hideliu=1&hidemyself=1&target=The_God-Emperor&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:16:46.126030 2026] [security2:error] [pid 971102:tid 971285] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxYvucL08BTTQixEnpqUAAAADM"]
[Thu Sep 17 15:16:46.149478 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/src/.env"] [unique_id "aqxYvucL08BTTQixEnpqUQAAAAI"]
[Thu Sep 17 15:16:46.181333 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxYvucL08BTTQixEnpqVAAAAHU"]
[Thu Sep 17 15:16:46.197029 2026] [security2:error] [pid 971102:tid 971275] [client 172.239.147.162:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxYvucL08BTTQixEnpqVgAAACk"], referer: binance.com
[Thu Sep 17 15:16:46.244896 2026] [security2:error] [pid 971102:tid 971296] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxYvucL08BTTQixEnpqWwAAAD4"]
[Thu Sep 17 15:16:46.270345 2026] [security2:error] [pid 971102:tid 971283] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/core/.env"] [unique_id "aqxYvucL08BTTQixEnpqXAAAADE"]
[Thu Sep 17 15:16:46.290895 2026] [security2:error] [pid 971102:tid 971345] [client 20.255.75.24:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/worksec.php"] [unique_id "aqxYvucL08BTTQixEnpqXQAAAG8"]
[Thu Sep 17 15:16:46.307909 2026] [security2:error] [pid 971102:tid 971323] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxYvucL08BTTQixEnpqXgAAAFk"]
[Thu Sep 17 15:16:46.375254 2026] [security2:error] [pid 971102:tid 971329] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxYvucL08BTTQixEnpqXwAAAF8"]
[Thu Sep 17 15:16:46.398875 2026] [security2:error] [pid 971102:tid 971313] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/core/app/.env"] [unique_id "aqxYvucL08BTTQixEnpqYgAAAE8"]
[Thu Sep 17 15:16:46.442555 2026] [security2:error] [pid 971102:tid 971358] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxYvucL08BTTQixEnpqZgAAAHw"]
[Thu Sep 17 15:16:46.502477 2026] [security2:error] [pid 971102:tid 971301] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxYvucL08BTTQixEnpqbgAAAEM"]
[Thu Sep 17 15:16:46.523743 2026] [security2:error] [pid 971102:tid 971343] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/config/.env"] [unique_id "aqxYvucL08BTTQixEnpqbwAAAG0"]
[Thu Sep 17 15:16:46.530590 2026] [security2:error] [pid 971102:tid 971234] [client 172.239.147.162:58607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxYvucL08BTTQixEnpqcQAAAAA"], referer: binance.com
[Thu Sep 17 15:16:46.546598 2026] [security2:error] [pid 971102:tid 971249] [client 3.82.141.143:39094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env.old"] [unique_id "aqxYvucL08BTTQixEnpqcgAAAA8"]
[Thu Sep 17 15:16:46.558396 2026] [security2:error] [pid 971102:tid 971324] [client 3.82.141.143:39056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env"] [unique_id "aqxYvucL08BTTQixEnpqdgAAAFo"]
[Thu Sep 17 15:16:46.560979 2026] [security2:error] [pid 971102:tid 971274] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxYvucL08BTTQixEnpqewAAACg"]
[Thu Sep 17 15:16:46.569046 2026] [security2:error] [pid 971102:tid 971287] [client 3.82.141.143:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/config.php"] [unique_id "aqxYvucL08BTTQixEnpqigAAADU"]
[Thu Sep 17 15:16:46.570483 2026] [security2:error] [pid 971102:tid 971272] [client 3.82.141.143:39098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env.bak"] [unique_id "aqxYvucL08BTTQixEnpqiwAAACY"]
[Thu Sep 17 15:16:46.576748 2026] [security2:error] [pid 971102:tid 971261] [client 3.82.141.143:39362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php~"] [unique_id "aqxYvucL08BTTQixEnpqnAAAABs"]
[Thu Sep 17 15:16:46.578798 2026] [security2:error] [pid 971102:tid 971306] [client 3.82.141.143:39394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php"] [unique_id "aqxYvucL08BTTQixEnpqoAAAAEg"]
[Thu Sep 17 15:16:46.579140 2026] [security2:error] [pid 971102:tid 971327] [client 3.82.141.143:39216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYvucL08BTTQixEnpqoQAAAF0"]
[Thu Sep 17 15:16:46.579930 2026] [security2:error] [pid 971102:tid 971241] [client 3.82.141.143:39260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php.old"] [unique_id "aqxYvucL08BTTQixEnpqpAAAAAc"]
[Thu Sep 17 15:16:46.580147 2026] [security2:error] [pid 971102:tid 971310] [client 3.82.141.143:39128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/web.config"] [unique_id "aqxYvucL08BTTQixEnpqowAAAEw"]
[Thu Sep 17 15:16:46.597789 2026] [security2:error] [pid 971102:tid 971344] [client 3.82.141.143:39374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/.env.backup"] [unique_id "aqxYvucL08BTTQixEnpqqwAAAG4"]
[Thu Sep 17 15:16:46.613200 2026] [security2:error] [pid 971102:tid 971348] [client 3.82.141.143:39094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.musingsofa50yearoldboy.com"] [uri "/wp-config.php.save"] [unique_id "aqxYvucL08BTTQixEnpqtwAAAHI"]
[Thu Sep 17 15:16:46.626767 2026] [security2:error] [pid 971102:tid 971247] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxYvucL08BTTQixEnpquQAAAA0"]
[Thu Sep 17 15:16:46.661165 2026] [security2:error] [pid 971102:tid 971273] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/private/.env"] [unique_id "aqxYvucL08BTTQixEnpqvAAAACc"]
[Thu Sep 17 15:16:46.690514 2026] [security2:error] [pid 971102:tid 971313] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxYvucL08BTTQixEnpqvQAAAE8"]
[Thu Sep 17 15:16:46.750734 2026] [security2:error] [pid 971102:tid 971314] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxYvucL08BTTQixEnpqvgAAAFA"]
[Thu Sep 17 15:16:46.780446 2026] [security2:error] [pid 971102:tid 971349] [client 20.255.75.24:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/ultra.php"] [unique_id "aqxYvucL08BTTQixEnpqvwAAAHM"]
[Thu Sep 17 15:16:46.786477 2026] [security2:error] [pid 971102:tid 971272] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/application/.env"] [unique_id "aqxYvucL08BTTQixEnpqwAAAACY"]
[Thu Sep 17 15:16:46.810125 2026] [security2:error] [pid 971102:tid 971306] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxYvucL08BTTQixEnpqwQAAAEg"]
[Thu Sep 17 15:16:46.847477 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:65232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYvucL08BTTQixEnpqwgAAAAs"]
[Thu Sep 17 15:16:46.850446 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:65232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYvucL08BTTQixEnpqwgAAAAs"]
[Thu Sep 17 15:16:46.869726 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxYvucL08BTTQixEnpqwwAAADw"]
[Thu Sep 17 15:16:46.913499 2026] [security2:error] [pid 971102:tid 971305] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/bootstrap/.env"] [unique_id "aqxYvucL08BTTQixEnpqxAAAAEc"]
[Thu Sep 17 15:16:46.927891 2026] [security2:error] [pid 971102:tid 971235] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxYvucL08BTTQixEnpqyAAAAAE"]
[Thu Sep 17 15:16:46.953863 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "aqxYvucL08BTTQixEnpqywAAAFI"]
[Thu Sep 17 15:16:46.982710 2026] [security2:error] [pid 971102:tid 971361] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxYvucL08BTTQixEnpqzAAAAH8"]
[Thu Sep 17 15:16:47.038754 2026] [security2:error] [pid 971102:tid 971345] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/database/.env"] [unique_id "aqxYv-cL08BTTQixEnpqzgAAAG8"]
[Thu Sep 17 15:16:47.041045 2026] [security2:error] [pid 971102:tid 971323] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxYv-cL08BTTQixEnpqzwAAAFk"]
[Thu Sep 17 15:16:47.095608 2026] [security2:error] [pid 971102:tid 971319] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxYv-cL08BTTQixEnpq0AAAAFU"]
[Thu Sep 17 15:16:47.153391 2026] [security2:error] [pid 971102:tid 971240] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxYv-cL08BTTQixEnpq1AAAAAY"]
[Thu Sep 17 15:16:47.158152 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/storage/.env"] [unique_id "aqxYv-cL08BTTQixEnpq1QAAABM"]
[Thu Sep 17 15:16:47.182721 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/apps/.env"] [unique_id "aqxYv-cL08BTTQixEnpq1gAAAD4"]
[Thu Sep 17 15:16:47.210951 2026] [security2:error] [pid 971102:tid 971281] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxYv-cL08BTTQixEnpq2AAAAC8"]
[Thu Sep 17 15:16:47.249750 2026] [security2:error] [pid 971102:tid 971335] [client 20.255.75.24:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/gecko.php"] [unique_id "aqxYv-cL08BTTQixEnpq2wAAAGU"]
[Thu Sep 17 15:16:47.257059 2026] [security2:error] [pid 971102:tid 971288] [client 104.188.154.142:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYvucL08BTTQixEnpqWgAANhs"]
[Thu Sep 17 15:16:47.266293 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxYv-cL08BTTQixEnpq3AAAAGA"]
[Thu Sep 17 15:16:47.278132 2026] [security2:error] [pid 971102:tid 971259] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/var/www/.env"] [unique_id "aqxYv-cL08BTTQixEnpq3QAAABk"]
[Thu Sep 17 15:16:47.324989 2026] [security2:error] [pid 971102:tid 971301] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxYv-cL08BTTQixEnpq3gAAAEM"]
[Thu Sep 17 15:16:47.381529 2026] [security2:error] [pid 971102:tid 971242] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxYv-cL08BTTQixEnpq4AAAAAg"]
[Thu Sep 17 15:16:47.399877 2026] [security2:error] [pid 971102:tid 971257] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/var/www/html/.env"] [unique_id "aqxYv-cL08BTTQixEnpq4QAAABc"]
[Thu Sep 17 15:16:47.411682 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "aqxYv-cL08BTTQixEnpq4gAAAG0"]
[Thu Sep 17 15:16:47.416008 2026] [security2:error] [pid 971102:tid 971227] [remote 104.188.154.142:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYvucL08BTTQixEnpqWAAANno"]
[Thu Sep 17 15:16:47.417562 2026] [security2:error] [pid 971102:tid 971146] [remote 104.188.154.142:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxYvucL08BTTQixEnpqWQAANio"]
[Thu Sep 17 15:16:47.437630 2026] [security2:error] [pid 971102:tid 971251] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxYv-cL08BTTQixEnpq5QAAABE"]
[Thu Sep 17 15:16:47.495012 2026] [security2:error] [pid 971102:tid 971290] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxYv-cL08BTTQixEnpq6gAAADg"]
[Thu Sep 17 15:16:47.521189 2026] [security2:error] [pid 971102:tid 971270] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/current/.env"] [unique_id "aqxYv-cL08BTTQixEnpq6wAAACQ"]
[Thu Sep 17 15:16:47.549001 2026] [security2:error] [pid 971102:tid 971324] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7AAAAFo"]
[Thu Sep 17 15:16:47.603176 2026] [security2:error] [pid 971102:tid 971264] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7QAAAB4"]
[Thu Sep 17 15:16:47.640109 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/web/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7gAAABI"]
[Thu Sep 17 15:16:47.641894 2026] [security2:error] [pid 971102:tid 971287] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/release/.env"] [unique_id "aqxYv-cL08BTTQixEnpq7wAAADU"]
[Thu Sep 17 15:16:47.658272 2026] [security2:error] [pid 971102:tid 971349] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxYv-cL08BTTQixEnpq8AAAAHM"]
[Thu Sep 17 15:16:47.718558 2026] [security2:error] [pid 971102:tid 971342] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxYv-cL08BTTQixEnpq8QAAAGw"]
[Thu Sep 17 15:16:47.761122 2026] [security2:error] [pid 971102:tid 971303] [client 20.255.75.24:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/goods.php"] [unique_id "aqxYv-cL08BTTQixEnpq9AAAAEU"]
[Thu Sep 17 15:16:47.762079 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/releases/.env"] [unique_id "aqxYv-cL08BTTQixEnpq8wAAABg"]
[Thu Sep 17 15:16:47.772101 2026] [security2:error] [pid 971102:tid 971246] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxYv-cL08BTTQixEnpq9QAAAAw"]
[Thu Sep 17 15:16:47.826423 2026] [security2:error] [pid 971102:tid 971327] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxYv-cL08BTTQixEnpq9gAAAF0"]
[Thu Sep 17 15:16:47.869220 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/site/.env"] [unique_id "aqxYv-cL08BTTQixEnpq9wAAADs"]
[Thu Sep 17 15:16:47.905157 2026] [security2:error] [pid 971102:tid 971347] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxYv-cL08BTTQixEnpq-AAAAHE"]
[Thu Sep 17 15:16:47.944936 2026] [security2:error] [pid 971102:tid 971340] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/shared/.env"] [unique_id "aqxYv-cL08BTTQixEnpq-QAAAGo"]
[Thu Sep 17 15:16:47.956835 2026] [security2:error] [pid 971102:tid 971280] [client 172.239.147.162:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxYv-cL08BTTQixEnpq-gAAAC4"], referer: binance.com
[Thu Sep 17 15:16:47.960097 2026] [security2:error] [pid 971102:tid 971255] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxYv-cL08BTTQixEnpq_AAAABU"]
[Thu Sep 17 15:16:48.016053 2026] [security2:error] [pid 971102:tid 971260] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxYwOcL08BTTQixEnpq_wAAABo"]
[Thu Sep 17 15:16:48.064855 2026] [security2:error] [pid 971102:tid 971241] [client 172.239.147.162:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxYwOcL08BTTQixEnprAwAAAAc"], referer: binance.com
[Thu Sep 17 15:16:48.071185 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxYwOcL08BTTQixEnprBAAAAGg"]
[Thu Sep 17 15:16:48.072636 2026] [security2:error] [pid 971102:tid 971317] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/deploy/.env"] [unique_id "aqxYwOcL08BTTQixEnprBQAAAFM"]
[Thu Sep 17 15:16:48.108086 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/public/.env"] [unique_id "aqxYwOcL08BTTQixEnprBgAAAD0"]
[Thu Sep 17 15:16:48.132314 2026] [security2:error] [pid 971102:tid 971336] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxYwOcL08BTTQixEnprBwAAAGY"]
[Thu Sep 17 15:16:48.186986 2026] [security2:error] [pid 971102:tid 971282] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxYwOcL08BTTQixEnprCgAAADA"]
[Thu Sep 17 15:16:48.197482 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/build/.env"] [unique_id "aqxYwOcL08BTTQixEnprCwAAAC0"]
[Thu Sep 17 15:16:48.241199 2026] [security2:error] [pid 971102:tid 971341] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxYwOcL08BTTQixEnprDQAAAGs"]
[Thu Sep 17 15:16:48.298946 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxYwOcL08BTTQixEnprDwAAAHU"]
[Thu Sep 17 15:16:48.301425 2026] [security2:error] [pid 971102:tid 971245] [client 20.255.75.24:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/man.php"] [unique_id "aqxYwOcL08BTTQixEnprEAAAAAs"]
[Thu Sep 17 15:16:48.321730 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/dist/.env"] [unique_id "aqxYwOcL08BTTQixEnprEgAAAFw"]
[Thu Sep 17 15:16:48.354105 2026] [security2:error] [pid 971102:tid 971305] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxYwOcL08BTTQixEnprFQAAAEc"]
[Thu Sep 17 15:16:48.409487 2026] [security2:error] [pid 971102:tid 971273] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxYwOcL08BTTQixEnprFwAAACc"]
[Thu Sep 17 15:16:48.441637 2026] [security2:error] [pid 971102:tid 971345] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/public_html/.env"] [unique_id "aqxYwOcL08BTTQixEnprGQAAAG8"]
[Thu Sep 17 15:16:48.464212 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxYwOcL08BTTQixEnprGgAAAAk"]
[Thu Sep 17 15:16:48.528898 2026] [security2:error] [pid 971102:tid 971253] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxYwOcL08BTTQixEnprHgAAABM"]
[Thu Sep 17 15:16:48.586652 2026] [security2:error] [pid 971102:tid 971289] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxYwOcL08BTTQixEnprIAAAADc"]
[Thu Sep 17 15:16:48.589793 2026] [security2:error] [pid 971102:tid 971244] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/htdocs/.env"] [unique_id "aqxYwOcL08BTTQixEnprIQAAAAo"]
[Thu Sep 17 15:16:48.623576 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "aqxYwOcL08BTTQixEnprIgAAADo"]
[Thu Sep 17 15:16:48.643478 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxYwOcL08BTTQixEnprIwAAABk"]
[Thu Sep 17 15:16:48.698606 2026] [security2:error] [pid 971102:tid 971343] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxYwOcL08BTTQixEnprJwAAAG0"]
[Thu Sep 17 15:16:48.728217 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/www/.env"] [unique_id "aqxYwOcL08BTTQixEnprKAAAAEQ"]
[Thu Sep 17 15:16:48.767758 2026] [security2:error] [pid 971102:tid 971271] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxYwOcL08BTTQixEnprKQAAACU"]
[Thu Sep 17 15:16:48.811194 2026] [security2:error] [pid 971102:tid 971335] [client 20.255.75.24:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/wp-settings.php"] [unique_id "aqxYwOcL08BTTQixEnprKgAAAGU"]
[Thu Sep 17 15:16:48.829930 2026] [security2:error] [pid 971102:tid 971314] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxYwOcL08BTTQixEnprKwAAAFA"]
[Thu Sep 17 15:16:48.850760 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/html/.env"] [unique_id "aqxYwOcL08BTTQixEnprLAAAAA8"]
[Thu Sep 17 15:16:48.852079 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/server/.env"] [unique_id "aqxYwOcL08BTTQixEnprLQAAACw"]
[Thu Sep 17 15:16:48.885973 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxYwOcL08BTTQixEnprLgAAAHc"]
[Thu Sep 17 15:16:48.942359 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxYwOcL08BTTQixEnprMAAAACQ"]
[Thu Sep 17 15:16:48.975475 2026] [security2:error] [pid 971102:tid 971264] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/live/.env"] [unique_id "aqxYwOcL08BTTQixEnprMQAAAB4"]
[Thu Sep 17 15:16:48.993484 2026] [security2:error] [pid 971102:tid 971267] [client 34.154.67.31:46072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env"] [unique_id "aqxYwOcL08BTTQixEnprMgAAACE"]
[Thu Sep 17 15:16:48.998048 2026] [security2:error] [pid 971102:tid 971269] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxYwOcL08BTTQixEnprMwAAACM"]
[Thu Sep 17 15:16:49.056780 2026] [security2:error] [pid 971102:tid 971252] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxYwecL08BTTQixEnprNwAAABI"]
[Thu Sep 17 15:16:49.084872 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/frontend/.env"] [unique_id "aqxYwecL08BTTQixEnprOAAAADU"]
[Thu Sep 17 15:16:49.103559 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/prod/.env"] [unique_id "aqxYwecL08BTTQixEnprOQAAAHM"]
[Thu Sep 17 15:16:49.118087 2026] [security2:error] [pid 971102:tid 971261] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxYwecL08BTTQixEnprOgAAABs"]
[Thu Sep 17 15:16:49.242595 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxYwecL08BTTQixEnprQQAAAG4"]
[Thu Sep 17 15:16:49.242601 2026] [security2:error] [pid 971102:tid 971260] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/dev/.env"] [unique_id "aqxYwecL08BTTQixEnprQgAAABo"]
[Thu Sep 17 15:16:49.301914 2026] [security2:error] [pid 971102:tid 971284] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxYwecL08BTTQixEnprRQAAADI"]
[Thu Sep 17 15:16:49.308625 2026] [security2:error] [pid 971102:tid 971272] [client 20.255.75.24:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/k.php"] [unique_id "aqxYwecL08BTTQixEnprRgAAACY"]
[Thu Sep 17 15:16:49.315350 2026] [security2:error] [pid 971102:tid 971241] [client 134.185.85.61:63592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxYwecL08BTTQixEnprRwAAAAc"]
[Thu Sep 17 15:16:49.317636 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/src/.env"] [unique_id "aqxYwecL08BTTQixEnprSAAAAGg"]
[Thu Sep 17 15:16:49.363804 2026] [security2:error] [pid 971102:tid 971299] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxYwecL08BTTQixEnprSQAAAEE"]
[Thu Sep 17 15:16:49.367848 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/staging/.env"] [unique_id "aqxYwecL08BTTQixEnprSwAAAHk"]
[Thu Sep 17 15:16:49.398923 2026] [security2:error] [pid 971102:tid 971306] [client 172.239.147.162:53808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-filter-sentinel.php"] [unique_id "aqxYwecL08BTTQixEnprTAAAAEg"], referer: binance.com
[Thu Sep 17 15:16:49.423987 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxYwecL08BTTQixEnprTQAAAFE"]
[Thu Sep 17 15:16:49.499163 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/opt/.env"] [unique_id "aqxYwecL08BTTQixEnprTwAAAHU"]
[Thu Sep 17 15:16:49.549463 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/core/.env"] [unique_id "aqxYwecL08BTTQixEnprUAAAAFw"]
[Thu Sep 17 15:16:49.570581 2026] [security2:error] [pid 971102:tid 971310] [client 216.244.91.82:65193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxYwecL08BTTQixEnprQwAAAEw"]
[Thu Sep 17 15:16:49.607372 2026] [security2:error] [pid 971102:tid 971356] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxYwecL08BTTQixEnprVQAAAHo"]
[Thu Sep 17 15:16:49.623388 2026] [security2:error] [pid 971102:tid 971350] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/laravel/.env"] [unique_id "aqxYwecL08BTTQixEnprVgAAAHQ"]
[Thu Sep 17 15:16:49.664901 2026] [security2:error] [pid 971102:tid 971312] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxYwecL08BTTQixEnprVwAAAE4"]
[Thu Sep 17 15:16:49.711305 2026] [security2:error] [pid 971102:tid 971237] [client 134.185.85.61:60547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/media/system/js/core.js"] [unique_id "aqxYwecL08BTTQixEnprXAAAAAM"]
[Thu Sep 17 15:16:49.722396 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxYwecL08BTTQixEnprXgAAADw"]
[Thu Sep 17 15:16:49.747557 2026] [security2:error] [pid 971102:tid 971273] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/symfony/.env"] [unique_id "aqxYwecL08BTTQixEnprXwAAACc"]
[Thu Sep 17 15:16:49.783224 2026] [security2:error] [pid 971102:tid 971346] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/core/app/.env"] [unique_id "aqxYwecL08BTTQixEnprYAAAAHA"]
[Thu Sep 17 15:16:49.783655 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxYwecL08BTTQixEnprYQAAAGQ"]
[Thu Sep 17 15:16:49.793432 2026] [security2:error] [pid 971102:tid 971305] [client 20.255.75.24:1041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/autoload_classmap.php"] [unique_id "aqxYwecL08BTTQixEnprYgAAAEc"]
[Thu Sep 17 15:16:49.850563 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxYwecL08BTTQixEnprZAAAAFQ"]
[Thu Sep 17 15:16:49.875327 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/wordpress/.env"] [unique_id "aqxYwecL08BTTQixEnprZgAAAF4"]
[Thu Sep 17 15:16:49.909702 2026] [security2:error] [pid 971102:tid 971243] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxYwecL08BTTQixEnprZwAAAAk"]
[Thu Sep 17 15:16:49.969743 2026] [security2:error] [pid 971102:tid 971313] [client 34.24.217.248:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxYwecL08BTTQixEnpraAAAAE8"]
[Thu Sep 17 15:16:50.001472 2026] [security2:error] [pid 971102:tid 971296] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/wp/.env"] [unique_id "aqxYwecL08BTTQixEnpraQAAAD4"]
[Thu Sep 17 15:16:50.017822 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "aqxYwucL08BTTQixEnpragAAAH4"]
[Thu Sep 17 15:16:50.126737 2026] [security2:error] [pid 971102:tid 971266] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cms/.env"] [unique_id "aqxYwucL08BTTQixEnprawAAACA"]
[Thu Sep 17 15:16:50.144201 2026] [security2:error] [pid 971102:tid 971289] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxYwucL08BTTQixEnprbAAAADc"]
[Thu Sep 17 15:16:50.199499 2026] [security2:error] [pid 971102:tid 971320] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxYwucL08BTTQixEnprcAAAAFY"]
[Thu Sep 17 15:16:50.252198 2026] [security2:error] [pid 971102:tid 971271] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/private/.env"] [unique_id "aqxYwucL08BTTQixEnprdQAAACU"]
[Thu Sep 17 15:16:50.254239 2026] [security2:error] [pid 971102:tid 971242] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxYwucL08BTTQixEnprdwAAAAg"]
[Thu Sep 17 15:16:50.259316 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/drupal/.env"] [unique_id "aqxYwucL08BTTQixEnpreAAAABE"]
[Thu Sep 17 15:16:50.271609 2026] [security2:error] [pid 971102:tid 971277] [client 20.255.75.24:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/profile.php"] [unique_id "aqxYwucL08BTTQixEnpreQAAACs"]
[Thu Sep 17 15:16:50.310072 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxYwucL08BTTQixEnpregAAAGA"]
[Thu Sep 17 15:16:50.365605 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxYwucL08BTTQixEnprgQAAACQ"]
[Thu Sep 17 15:16:50.393554 2026] [security2:error] [pid 971102:tid 971267] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/joomla/.env"] [unique_id "aqxYwucL08BTTQixEnprggAAACE"]
[Thu Sep 17 15:16:50.421404 2026] [security2:error] [pid 971102:tid 971349] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxYwucL08BTTQixEnprgwAAAHM"]
[Thu Sep 17 15:16:50.476743 2026] [security2:error] [pid 971102:tid 971263] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxYwucL08BTTQixEnprhwAAAB0"]
[Thu Sep 17 15:16:50.480607 2026] [security2:error] [pid 971102:tid 971278] [client 172.239.147.162:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxYwucL08BTTQixEnpriAAAACw"], referer: binance.com
[Thu Sep 17 15:16:50.486167 2026] [security2:error] [pid 971102:tid 971258] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/application/.env"] [unique_id "aqxYwucL08BTTQixEnpriQAAABg"]
[Thu Sep 17 15:16:50.523772 2026] [security2:error] [pid 971102:tid 971293] [client 34.97.30.29:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/magento/.env"] [unique_id "aqxYwucL08BTTQixEnprjAAAADs"]
[Thu Sep 17 15:16:50.532469 2026] [security2:error] [pid 971102:tid 971236] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxYwucL08BTTQixEnprjQAAAAI"]
[Thu Sep 17 15:16:50.587840 2026] [security2:error] [pid 971102:tid 971284] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxYwucL08BTTQixEnprjgAAADI"]
[Thu Sep 17 15:16:50.638267 2026] [security2:error] [pid 971102:tid 971264] [client 172.239.147.162:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxYwucL08BTTQixEnprkAAAAB4"], referer: binance.com
[Thu Sep 17 15:16:50.647972 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxYwucL08BTTQixEnprkQAAAGg"]
[Thu Sep 17 15:16:50.707226 2026] [security2:error] [pid 971102:tid 971262] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxYwucL08BTTQixEnprlgAAABw"]
[Thu Sep 17 15:16:50.713575 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bootstrap/.env"] [unique_id "aqxYwucL08BTTQixEnprmQAAAEg"]
[Thu Sep 17 15:16:50.761552 2026] [security2:error] [pid 971102:tid 971272] [client 20.255.75.24:1051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/server.php"] [unique_id "aqxYwucL08BTTQixEnprmgAAACY"]
[Thu Sep 17 15:16:50.764044 2026] [security2:error] [pid 971102:tid 971348] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxYwucL08BTTQixEnprmwAAAHI"]
[Thu Sep 17 15:16:50.820706 2026] [security2:error] [pid 971102:tid 971280] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxYwucL08BTTQixEnprnAAAAC4"]
[Thu Sep 17 15:16:50.876710 2026] [security2:error] [pid 971102:tid 971354] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxYwucL08BTTQixEnprnQAAAHg"]
[Thu Sep 17 15:16:50.912287 2026] [security2:error] [pid 971102:tid 971276] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/shopify/.env"] [unique_id "aqxYwucL08BTTQixEnprnwAAACo"]
[Thu Sep 17 15:16:50.933435 2026] [security2:error] [pid 971102:tid 971329] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxYwucL08BTTQixEnproAAAAF8"]
[Thu Sep 17 15:16:50.947759 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/database/.env"] [unique_id "aqxYwucL08BTTQixEnproQAAAHo"]
[Thu Sep 17 15:16:50.988584 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxYwucL08BTTQixEnprowAAAHQ"]
[Thu Sep 17 15:16:51.036737 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/prestashop/.env"] [unique_id "aqxYw-cL08BTTQixEnprpQAAAAM"]
[Thu Sep 17 15:16:51.044061 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxYw-cL08BTTQixEnprpgAAADw"]
[Thu Sep 17 15:16:51.101637 2026] [security2:error] [pid 971102:tid 971273] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxYw-cL08BTTQixEnprqAAAACc"]
[Thu Sep 17 15:16:51.156085 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxYw-cL08BTTQixEnprrAAAAFQ"]
[Thu Sep 17 15:16:51.156086 2026] [security2:error] [pid 971102:tid 971305] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/codeigniter/.env"] [unique_id "aqxYw-cL08BTTQixEnprqwAAAEc"]
[Thu Sep 17 15:16:51.175804 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/storage/.env"] [unique_id "aqxYw-cL08BTTQixEnprrgAAAF4"]
[Thu Sep 17 15:16:51.211844 2026] [security2:error] [pid 971102:tid 971361] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxYw-cL08BTTQixEnprsAAAAH8"]
[Thu Sep 17 15:16:51.245288 2026] [security2:error] [pid 971102:tid 971358] [client 20.255.75.24:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/shell.php"] [unique_id "aqxYw-cL08BTTQixEnprtAAAAHw"]
[Thu Sep 17 15:16:51.268413 2026] [security2:error] [pid 971102:tid 971291] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxYw-cL08BTTQixEnprtgAAADk"]
[Thu Sep 17 15:16:51.286319 2026] [security2:error] [pid 971102:tid 971313] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cakephp/.env"] [unique_id "aqxYw-cL08BTTQixEnprtwAAAE8"]
[Thu Sep 17 15:16:51.326009 2026] [security2:error] [pid 971102:tid 971300] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxYw-cL08BTTQixEnpruAAAAEI"]
[Thu Sep 17 15:16:51.382263 2026] [security2:error] [pid 971102:tid 971360] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxYw-cL08BTTQixEnpruQAAAH4"]
[Thu Sep 17 15:16:51.409860 2026] [security2:error] [pid 971102:tid 971281] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/var/www/.env"] [unique_id "aqxYw-cL08BTTQixEnprugAAAC8"]
[Thu Sep 17 15:16:51.416280 2026] [security2:error] [pid 971102:tid 971320] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/zend/.env"] [unique_id "aqxYw-cL08BTTQixEnprvAAAAFY"]
[Thu Sep 17 15:16:51.438166 2026] [security2:error] [pid 971102:tid 971331] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxYw-cL08BTTQixEnprvQAAAGE"]
[Thu Sep 17 15:16:51.493943 2026] [security2:error] [pid 971102:tid 971254] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxYw-cL08BTTQixEnprvwAAABQ"]
[Thu Sep 17 15:16:51.502725 2026] [security2:error] [pid 971102:tid 971319] [client 185.55.149.49:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYw-cL08BTTQixEnprvgAAAFU"]
[Thu Sep 17 15:16:51.502842 2026] [security2:error] [pid 971102:tid 971319] [client 185.55.149.49:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYw-cL08BTTQixEnprvgAAAFU"]
[Thu Sep 17 15:16:51.551222 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/yii/.env"] [unique_id "aqxYw-cL08BTTQixEnprwAAAAEQ"]
[Thu Sep 17 15:16:51.554290 2026] [security2:error] [pid 971102:tid 971257] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxYw-cL08BTTQixEnprwQAAABc"]
[Thu Sep 17 15:16:51.565540 2026] [security2:error] [pid 971102:tid 971244] [client 162.241.226.11:23990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYw-cL08BTTQixEnpruwAAAAo"]
[Thu Sep 17 15:16:51.617765 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxYw-cL08BTTQixEnprwwAAACQ"]
[Thu Sep 17 15:16:51.643327 2026] [security2:error] [pid 971102:tid 971259] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/var/www/html/.env"] [unique_id "aqxYw-cL08BTTQixEnprxgAAABk"]
[Thu Sep 17 15:16:51.674681 2026] [security2:error] [pid 971102:tid 971286] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/laravel5/.env"] [unique_id "aqxYw-cL08BTTQixEnpryAAAADQ"]
[Thu Sep 17 15:16:51.684824 2026] [security2:error] [pid 971102:tid 971342] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxYw-cL08BTTQixEnpryQAAAGw"]
[Thu Sep 17 15:16:51.742138 2026] [security2:error] [pid 971102:tid 971327] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxYw-cL08BTTQixEnprzgAAAF0"]
[Thu Sep 17 15:16:51.758580 2026] [security2:error] [pid 971102:tid 971277] [client 20.255.75.24:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/t.php"] [unique_id "aqxYw-cL08BTTQixEnpr0AAAACs"]
[Thu Sep 17 15:16:51.786157 2026] [security2:error] [pid 971102:tid 971292] [client 172.239.147.162:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxYw-cL08BTTQixEnpr0QAAADo"], referer: binance.com
[Thu Sep 17 15:16:51.797596 2026] [security2:error] [pid 971102:tid 971347] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/v1/.env"] [unique_id "aqxYw-cL08BTTQixEnpr0gAAAHE"]
[Thu Sep 17 15:16:51.801702 2026] [security2:error] [pid 971102:tid 971314] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxYw-cL08BTTQixEnpr0wAAAFA"]
[Thu Sep 17 15:16:51.810860 2026] [security2:error] [pid 971102:tid 971269] [client 162.241.226.11:24004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYw-cL08BTTQixEnprxAAAACM"]
[Thu Sep 17 15:16:51.830331 2026] [security2:error] [pid 971102:tid 971249] [client 172.239.147.162:58812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-icon-collections-registry.php"] [unique_id "aqxYw-cL08BTTQixEnpr1QAAAA8"], referer: binance.com
[Thu Sep 17 15:16:51.857461 2026] [security2:error] [pid 971102:tid 971344] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxYw-cL08BTTQixEnpr1gAAAG4"]
[Thu Sep 17 15:16:51.876873 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/current/.env"] [unique_id "aqxYw-cL08BTTQixEnpr1wAAAAc"]
[Thu Sep 17 15:16:51.913575 2026] [security2:error] [pid 971102:tid 971317] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxYw-cL08BTTQixEnpr2AAAAFM"]
[Thu Sep 17 15:16:51.916236 2026] [security2:error] [pid 971102:tid 971321] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/v2/.env"] [unique_id "aqxYw-cL08BTTQixEnpr2QAAAFc"]
[Thu Sep 17 15:16:51.969619 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxYw-cL08BTTQixEnpr2gAAAGk"]
[Thu Sep 17 15:16:52.025014 2026] [security2:error] [pid 971102:tid 971295] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxYxOcL08BTTQixEnpr3QAAAD0"]
[Thu Sep 17 15:16:52.036382 2026] [security2:error] [pid 971102:tid 971262] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/v3/.env"] [unique_id "aqxYxOcL08BTTQixEnpr3gAAABw"]
[Thu Sep 17 15:16:52.090866 2026] [security2:error] [pid 971102:tid 971355] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxYxOcL08BTTQixEnpr4QAAAHk"]
[Thu Sep 17 15:16:52.095759 2026] [security2:error] [pid 971102:tid 971188] [remote 216.73.217.142:60157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxYxOcL08BTTQixEnpr4gAAVFM"]
[Thu Sep 17 15:16:52.104889 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/release/.env"] [unique_id "aqxYxOcL08BTTQixEnpr4wAAAH8"]
[Thu Sep 17 15:16:52.147070 2026] [security2:error] [pid 971102:tid 971308] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxYxOcL08BTTQixEnpr5QAAAEo"]
[Thu Sep 17 15:16:52.160027 2026] [security2:error] [pid 971102:tid 971275] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/v1/.env"] [unique_id "aqxYxOcL08BTTQixEnpr6AAAACk"]
[Thu Sep 17 15:16:52.202121 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxYxOcL08BTTQixEnpr6gAAAFE"]
[Thu Sep 17 15:16:52.215727 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxYxOcL08BTTQixEnpr6wAAAGY"]
[Thu Sep 17 15:16:52.222310 2026] [security2:error] [pid 971102:tid 971348] [client 45.169.98.18:57541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxOcL08BTTQixEnpr7AAAAHI"]
[Thu Sep 17 15:16:52.222395 2026] [security2:error] [pid 971102:tid 971348] [client 45.169.98.18:57541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxOcL08BTTQixEnpr7AAAAHI"]
[Thu Sep 17 15:16:52.238953 2026] [security2:error] [pid 971102:tid 971272] [client 20.255.75.24:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tesselessetbooks.com"] [uri "/hello.php"] [unique_id "aqxYxOcL08BTTQixEnpr7QAAACY"]
[Thu Sep 17 15:16:52.259011 2026] [security2:error] [pid 971102:tid 971280] [client 3.82.141.143:20710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php.save"] [unique_id "aqxYxOcL08BTTQixEnpr8AAAAC4"]
[Thu Sep 17 15:16:52.260026 2026] [security2:error] [pid 971102:tid 971240] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxYxOcL08BTTQixEnpr7gAAAAY"]
[Thu Sep 17 15:16:52.270549 2026] [security2:error] [pid 971102:tid 971237] [client 3.82.141.143:20632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/config.php"] [unique_id "aqxYxOcL08BTTQixEnpr8wAAAAM"]
[Thu Sep 17 15:16:52.271458 2026] [security2:error] [pid 971102:tid 971299] [client 3.82.141.143:20510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env"] [unique_id "aqxYxOcL08BTTQixEnpr8gAAAEE"]
[Thu Sep 17 15:16:52.271489 2026] [security2:error] [pid 971102:tid 971354] [client 3.82.141.143:20674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php.old"] [unique_id "aqxYxOcL08BTTQixEnpr9wAAAHg"]
[Thu Sep 17 15:16:52.271493 2026] [security2:error] [pid 971102:tid 971245] [client 3.82.141.143:20706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php~"] [unique_id "aqxYxOcL08BTTQixEnpr-AAAAAs"]
[Thu Sep 17 15:16:52.271760 2026] [security2:error] [pid 971102:tid 971310] [client 3.82.141.143:20694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-config.php"] [unique_id "aqxYxOcL08BTTQixEnpr9gAAAEw"]
[Thu Sep 17 15:16:52.271977 2026] [security2:error] [pid 971102:tid 971276] [client 3.82.141.143:20606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env.bak"] [unique_id "aqxYxOcL08BTTQixEnpr9AAAACo"]
[Thu Sep 17 15:16:52.272598 2026] [security2:error] [pid 971102:tid 971256] [client 3.82.141.143:20588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env.old"] [unique_id "aqxYxOcL08BTTQixEnpr-QAAABY"]
[Thu Sep 17 15:16:52.284239 2026] [security2:error] [pid 971102:tid 971300] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/v2/.env"] [unique_id "aqxYxOcL08BTTQixEnpsAgAAAEI"]
[Thu Sep 17 15:16:52.299434 2026] [security2:error] [pid 971102:tid 971358] [client 3.82.141.143:20682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanacking.com"] [uri "/wp-config.php.bak"] [unique_id "aqxYxOcL08BTTQixEnpsBAAAAHw"]
[Thu Sep 17 15:16:52.305462 2026] [security2:error] [pid 971102:tid 971285] [client 3.82.141.143:20572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/.env.backup"] [unique_id "aqxYxOcL08BTTQixEnpsBQAAADM"]
[Thu Sep 17 15:16:52.316933 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxYxOcL08BTTQixEnpsBgAAACA"]
[Thu Sep 17 15:16:52.343486 2026] [security2:error] [pid 971102:tid 971320] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/releases/.env"] [unique_id "aqxYxOcL08BTTQixEnpsCAAAAFY"]
[Thu Sep 17 15:16:52.374271 2026] [security2:error] [pid 971102:tid 971251] [client 34.154.67.31:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxYxOcL08BTTQixEnpsCgAAABE"]
[Thu Sep 17 15:16:52.375463 2026] [security2:error] [pid 971102:tid 971307] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxYxOcL08BTTQixEnpsCwAAAEk"]
[Thu Sep 17 15:16:52.405197 2026] [security2:error] [pid 971102:tid 971341] [client 3.82.141.143:20668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr7wAAAGs"]
[Thu Sep 17 15:16:52.405278 2026] [security2:error] [pid 971102:tid 971270] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/rest/.env"] [unique_id "aqxYxOcL08BTTQixEnpsDwAAACQ"]
[Thu Sep 17 15:16:52.410682 2026] [security2:error] [pid 971102:tid 971350] [client 3.82.141.143:20506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr_QAAAHQ"]
[Thu Sep 17 15:16:52.410768 2026] [security2:error] [pid 971102:tid 971265] [client 3.82.141.143:20526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr9QAAAB8"]
[Thu Sep 17 15:16:52.411477 2026] [security2:error] [pid 971102:tid 971351] [client 3.82.141.143:20612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr-gAAAHU"]
[Thu Sep 17 15:16:52.411764 2026] [security2:error] [pid 971102:tid 971305] [client 3.82.141.143:20558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsAAAAAEc"]
[Thu Sep 17 15:16:52.412128 2026] [security2:error] [pid 971102:tid 971294] [client 3.82.141.143:20602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr_AAAADw"]
[Thu Sep 17 15:16:52.413486 2026] [security2:error] [pid 971102:tid 971273] [client 3.82.141.143:20622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr_gAAACc"]
[Thu Sep 17 15:16:52.426755 2026] [security2:error] [pid 971102:tid 971328] [client 3.82.141.143:20542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsAwAAAF4"]
[Thu Sep 17 15:16:52.432163 2026] [security2:error] [pid 971102:tid 971337] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxYxOcL08BTTQixEnpsEgAAAGc"]
[Thu Sep 17 15:16:52.468744 2026] [security2:error] [pid 971102:tid 971274] [client 3.82.141.143:20736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsBwAAACg"]
[Thu Sep 17 15:16:52.491365 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxYxOcL08BTTQixEnpsEwAAABk"]
[Thu Sep 17 15:16:52.526273 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/graphql/.env"] [unique_id "aqxYxOcL08BTTQixEnpsGAAAAHM"]
[Thu Sep 17 15:16:52.549304 2026] [security2:error] [pid 971102:tid 971271] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxYxOcL08BTTQixEnpsIAAAACU"]
[Thu Sep 17 15:16:52.560070 2026] [security2:error] [pid 971102:tid 971284] [client 3.82.141.143:20558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "alanacking.com"] [uri "/web.config"] [unique_id "aqxYxOcL08BTTQixEnpsLAAAADI"]
[Thu Sep 17 15:16:52.579797 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shared/.env"] [unique_id "aqxYxOcL08BTTQixEnpsLgAAAAU"]
[Thu Sep 17 15:16:52.608699 2026] [security2:error] [pid 971102:tid 971317] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxYxOcL08BTTQixEnpsMAAAAFM"]
[Thu Sep 17 15:16:52.649115 2026] [security2:error] [pid 971102:tid 971303] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/gateway/.env"] [unique_id "aqxYxOcL08BTTQixEnpsMQAAAEU"]
[Thu Sep 17 15:16:52.665619 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxYxOcL08BTTQixEnpsMgAAAGk"]
[Thu Sep 17 15:16:52.721798 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxYxOcL08BTTQixEnpsNQAAAFQ"]
[Thu Sep 17 15:16:52.774535 2026] [security2:error] [pid 971102:tid 971336] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/microservice/.env"] [unique_id "aqxYxOcL08BTTQixEnpsNgAAAGY"]
[Thu Sep 17 15:16:52.777531 2026] [security2:error] [pid 971102:tid 971348] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxYxOcL08BTTQixEnpsNwAAAHI"]
[Thu Sep 17 15:16:52.810880 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/deploy/.env"] [unique_id "aqxYxOcL08BTTQixEnpsOAAAAAY"]
[Thu Sep 17 15:16:52.839144 2026] [security2:error] [pid 971102:tid 971306] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxYxOcL08BTTQixEnpsOQAAAEg"]
[Thu Sep 17 15:16:52.893312 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/service/.env"] [unique_id "aqxYxOcL08BTTQixEnpsOwAAAHw"]
[Thu Sep 17 15:16:52.895433 2026] [security2:error] [pid 971102:tid 971296] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxYxOcL08BTTQixEnpsPAAAAD4"]
[Thu Sep 17 15:16:52.951148 2026] [security2:error] [pid 971102:tid 971234] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxYxOcL08BTTQixEnpsPgAAAAA"]
[Thu Sep 17 15:16:52.967595 2026] [security2:error] [pid 971102:tid 971315] [client 172.239.147.162:56661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxYxOcL08BTTQixEnpsPwAAAFE"], referer: binance.com
[Thu Sep 17 15:16:53.008925 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxYxecL08BTTQixEnpsQAAAACA"]
[Thu Sep 17 15:16:53.023200 2026] [security2:error] [pid 971102:tid 971254] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/v3/.env"] [unique_id "aqxYxecL08BTTQixEnpsQQAAABQ"]
[Thu Sep 17 15:16:53.045300 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/build/.env"] [unique_id "aqxYxecL08BTTQixEnpsQgAAAFU"]
[Thu Sep 17 15:16:53.060281 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:46126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxYxecL08BTTQixEnpsQwAAADM"]
[Thu Sep 17 15:16:53.072449 2026] [security2:error] [pid 971102:tid 971302] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxYxecL08BTTQixEnpsRAAAAEQ"]
[Thu Sep 17 15:16:53.136798 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxYxecL08BTTQixEnpsRQAAAAo"]
[Thu Sep 17 15:16:53.152515 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/dev/.env"] [unique_id "aqxYxecL08BTTQixEnpsRgAAABE"]
[Thu Sep 17 15:16:53.194060 2026] [security2:error] [pid 971102:tid 971270] [client 34.24.217.248:49236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxYxecL08BTTQixEnpsSQAAACQ"]
[Thu Sep 17 15:16:53.251732 2026] [security2:error] [pid 971102:tid 971294] [client 34.24.217.248:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxYxecL08BTTQixEnpsTQAAADw"]
[Thu Sep 17 15:16:53.257555 2026] [security2:error] [pid 971102:tid 971243] [client 3.82.141.143:20794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsFQAAAAk"]
[Thu Sep 17 15:16:53.261016 2026] [security2:error] [pid 971102:tid 971326] [client 154.190.208.131:42527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsTgAAAFw"]
[Thu Sep 17 15:16:53.261159 2026] [security2:error] [pid 971102:tid 971326] [client 154.190.208.131:42527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsTgAAAFw"]
[Thu Sep 17 15:16:53.276269 2026] [security2:error] [pid 971102:tid 971316] [client 3.82.141.143:20746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsGQAAAFI"]
[Thu Sep 17 15:16:53.279291 2026] [security2:error] [pid 971102:tid 971337] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/api/staging/.env"] [unique_id "aqxYxecL08BTTQixEnpsTwAAAGc"]
[Thu Sep 17 15:16:53.281999 2026] [security2:error] [pid 971102:tid 971259] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dist/.env"] [unique_id "aqxYxecL08BTTQixEnpsUAAAABk"]
[Thu Sep 17 15:16:53.287143 2026] [security2:error] [pid 971102:tid 971290] [client 3.82.141.143:20640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsHgAAADg"]
[Thu Sep 17 15:16:53.287206 2026] [security2:error] [pid 971102:tid 971312] [client 3.82.141.143:20786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsHwAAAE4"]
[Thu Sep 17 15:16:53.289044 2026] [security2:error] [pid 971102:tid 971286] [client 3.82.141.143:20668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsGgAAADQ"]
[Thu Sep 17 15:16:53.302777 2026] [security2:error] [pid 971102:tid 971277] [client 3.82.141.143:20606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsIQAAACs"]
[Thu Sep 17 15:16:53.303387 2026] [security2:error] [pid 971102:tid 971292] [client 3.82.141.143:20510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsIgAAADo"]
[Thu Sep 17 15:16:53.304336 2026] [security2:error] [pid 971102:tid 971332] [client 3.82.141.143:20770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsFwAAAGI"]
[Thu Sep 17 15:16:53.312000 2026] [security2:error] [pid 971102:tid 971282] [client 3.82.141.143:20814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJQAAADA"]
[Thu Sep 17 15:16:53.323216 2026] [security2:error] [pid 971102:tid 971278] [client 3.82.141.143:20602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsKwAAACw"]
[Thu Sep 17 15:16:53.325607 2026] [security2:error] [pid 971102:tid 971359] [client 3.82.141.143:20816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJAAAAH0"]
[Thu Sep 17 15:16:53.325744 2026] [security2:error] [pid 971102:tid 971260] [client 3.82.141.143:20588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJwAAABo"]
[Thu Sep 17 15:16:53.336292 2026] [security2:error] [pid 971102:tid 971269] [client 3.82.141.143:20652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpsJgAAACM"]
[Thu Sep 17 15:16:53.408507 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/vendor/.env"] [unique_id "aqxYxecL08BTTQixEnpsVAAAAAI"]
[Thu Sep 17 15:16:53.428280 2026] [security2:error] [pid 971102:tid 971258] [client 34.24.217.248:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/info.php"] [unique_id "aqxYxecL08BTTQixEnpsVgAAABg"]
[Thu Sep 17 15:16:53.480533 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxYxecL08BTTQixEnpsWAAAACc"], referer: binance.com
[Thu Sep 17 15:16:53.515504 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/public_html/.env"] [unique_id "aqxYxecL08BTTQixEnpsWQAAAAU"]
[Thu Sep 17 15:16:53.527866 2026] [security2:error] [pid 971102:tid 971327] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/lib/.env"] [unique_id "aqxYxecL08BTTQixEnpsWgAAAF0"]
[Thu Sep 17 15:16:53.611180 2026] [security2:error] [pid 971102:tid 971263] [client 34.24.217.248:49254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/php.php"] [unique_id "aqxYxecL08BTTQixEnpsXgAAAB0"]
[Thu Sep 17 15:16:53.655041 2026] [security2:error] [pid 971102:tid 971295] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/resources/.env"] [unique_id "aqxYxecL08BTTQixEnpsYQAAAD0"]
[Thu Sep 17 15:16:53.753597 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/htdocs/.env"] [unique_id "aqxYxecL08BTTQixEnpsZwAAAEg"]
[Thu Sep 17 15:16:53.787622 2026] [security2:error] [pid 971102:tid 971280] [client 34.24.217.248:49266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/i.php"] [unique_id "aqxYxecL08BTTQixEnpsbAAAAC4"]
[Thu Sep 17 15:16:53.796786 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/assets/.env"] [unique_id "aqxYxecL08BTTQixEnpsbQAAAC0"]
[Thu Sep 17 15:16:53.842299 2026] [security2:error] [pid 971102:tid 971317] [client 114.198.138.124:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsbwAAAFM"]
[Thu Sep 17 15:16:53.842384 2026] [security2:error] [pid 971102:tid 971317] [client 114.198.138.124:62935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxecL08BTTQixEnpsbwAAAFM"]
[Thu Sep 17 15:16:53.871676 2026] [security2:error] [pid 971102:tid 971238] [client 193.124.20.178:55590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxYxOcL08BTTQixEnpr5AAAAAQ"], referer: https://bigsisterteams.com/contact/
[Thu Sep 17 15:16:53.918169 2026] [security2:error] [pid 971102:tid 971266] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/uploads/.env"] [unique_id "aqxYxecL08BTTQixEnpscQAAACA"]
[Thu Sep 17 15:16:53.934335 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env"] [unique_id "aqxYxecL08BTTQixEnpscgAAAFY"]
[Thu Sep 17 15:16:53.973888 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxYxecL08BTTQixEnpscwAAAFE"]
[Thu Sep 17 15:16:53.989678 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/www/.env"] [unique_id "aqxYxecL08BTTQixEnpsdAAAAFU"]
[Thu Sep 17 15:16:54.048284 2026] [security2:error] [pid 971102:tid 971356] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/internal/.env"] [unique_id "aqxYxucL08BTTQixEnpseAAAAHo"]
[Thu Sep 17 15:16:54.049249 2026] [security2:error] [pid 971102:tid 971261] [client 172.239.147.162:53233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxYxucL08BTTQixEnpseQAAABs"], referer: binance.com
[Thu Sep 17 15:16:54.160941 2026] [security2:error] [pid 971102:tid 971313] [client 34.24.217.248:49278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxYxucL08BTTQixEnpsfAAAAE8"]
[Thu Sep 17 15:16:54.183385 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/tools/.env"] [unique_id "aqxYxucL08BTTQixEnpsfwAAAEM"]
[Thu Sep 17 15:16:54.225603 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/html/.env"] [unique_id "aqxYxucL08BTTQixEnpsgQAAAEc"]
[Thu Sep 17 15:16:54.318370 2026] [security2:error] [pid 971102:tid 971312] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/scripts/.env"] [unique_id "aqxYxucL08BTTQixEnpsiAAAAE4"]
[Thu Sep 17 15:16:54.348612 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/test.php"] [unique_id "aqxYxucL08BTTQixEnpsiQAAAHQ"]
[Thu Sep 17 15:16:54.381870 2026] [security2:error] [pid 971102:tid 971292] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.bak"] [unique_id "aqxYxucL08BTTQixEnpsiwAAADo"]
[Thu Sep 17 15:16:54.456350 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.backup"] [unique_id "aqxYxucL08BTTQixEnpsjAAAACU"]
[Thu Sep 17 15:16:54.458614 2026] [security2:error] [pid 971102:tid 971347] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/live/.env"] [unique_id "aqxYxucL08BTTQixEnpsjQAAAHE"]
[Thu Sep 17 15:16:54.459134 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/bin/.env"] [unique_id "aqxYxucL08BTTQixEnpsjgAAABg"]
[Thu Sep 17 15:16:54.586510 2026] [security2:error] [pid 971102:tid 971264] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.old"] [unique_id "aqxYxucL08BTTQixEnpskQAAAB4"]
[Thu Sep 17 15:16:54.589281 2026] [security2:error] [pid 971102:tid 971341] [client 34.24.217.248:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/p.php"] [unique_id "aqxYxucL08BTTQixEnpskwAAAGs"]
[Thu Sep 17 15:16:54.591291 2026] [security2:error] [pid 971102:tid 971307] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sbin/.env"] [unique_id "aqxYxucL08BTTQixEnpslAAAAEk"]
[Thu Sep 17 15:16:54.700933 2026] [security2:error] [pid 971102:tid 971331] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/prod/.env"] [unique_id "aqxYxucL08BTTQixEnpsnQAAAGE"]
[Thu Sep 17 15:16:54.723029 2026] [security2:error] [pid 971102:tid 971295] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/local/.env"] [unique_id "aqxYxucL08BTTQixEnpsnwAAAD0"]
[Thu Sep 17 15:16:54.733963 2026] [security2:error] [pid 971102:tid 971277] [client 186.105.232.15:52718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxucL08BTTQixEnpsoAAAACs"]
[Thu Sep 17 15:16:54.734087 2026] [security2:error] [pid 971102:tid 971277] [client 186.105.232.15:52718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxYxucL08BTTQixEnpsoAAAACs"]
[Thu Sep 17 15:16:54.773539 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxYxucL08BTTQixEnpsowAAAGk"]
[Thu Sep 17 15:16:54.847703 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/portal/.env"] [unique_id "aqxYxucL08BTTQixEnpsqAAAAA8"]
[Thu Sep 17 15:16:54.935813 2026] [security2:error] [pid 971102:tid 971306] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dev/.env"] [unique_id "aqxYxucL08BTTQixEnpsqwAAAEg"]
[Thu Sep 17 15:16:54.937824 2026] [security2:error] [pid 971102:tid 971240] [client 34.24.217.248:49304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxYxucL08BTTQixEnpsrAAAAAY"]
[Thu Sep 17 15:16:54.977204 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/dashboard/.env"] [unique_id "aqxYxucL08BTTQixEnpsrQAAAC0"]
[Thu Sep 17 15:16:55.104388 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/panel/.env"] [unique_id "aqxYx-cL08BTTQixEnpssQAAAGw"]
[Thu Sep 17 15:16:55.123498 2026] [security2:error] [pid 971102:tid 971358] [client 34.24.217.248:49306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnpssgAAAHw"]
[Thu Sep 17 15:16:55.169914 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/staging/.env"] [unique_id "aqxYx-cL08BTTQixEnpstAAAAFM"]
[Thu Sep 17 15:16:55.237925 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/crm/.env"] [unique_id "aqxYx-cL08BTTQixEnpsuAAAAAQ"]
[Thu Sep 17 15:16:55.305389 2026] [security2:error] [pid 971102:tid 971266] [client 34.24.217.248:49322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnpsuwAAACA"]
[Thu Sep 17 15:16:55.323862 2026] [security2:error] [pid 971102:tid 971315] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env.swp"] [unique_id "aqxYx-cL08BTTQixEnpsvAAAAFE"]
[Thu Sep 17 15:16:55.326134 2026] [security2:error] [pid 971102:tid 971296] [client 172.239.147.162:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxYx-cL08BTTQixEnpsvQAAAD4"], referer: binance.com
[Thu Sep 17 15:16:55.365399 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/erp/.env"] [unique_id "aqxYx-cL08BTTQixEnpswgAAAHk"]
[Thu Sep 17 15:16:55.378878 2026] [security2:error] [pid 971102:tid 971345] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.env~"] [unique_id "aqxYx-cL08BTTQixEnpswwAAAG8"]
[Thu Sep 17 15:16:55.404512 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/opt/.env"] [unique_id "aqxYx-cL08BTTQixEnpsxQAAABs"]
[Thu Sep 17 15:16:55.448464 2026] [security2:error] [pid 971102:tid 971254] [client 172.239.147.162:59119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxYx-cL08BTTQixEnpsxwAAABQ"], referer: binance.com
[Thu Sep 17 15:16:55.490939 2026] [security2:error] [pid 971102:tid 971242] [client 34.24.217.248:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnpsyQAAAAg"]
[Thu Sep 17 15:16:55.500130 2026] [security2:error] [pid 971102:tid 971243] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/shop/.env"] [unique_id "aqxYx-cL08BTTQixEnpsygAAAAk"]
[Thu Sep 17 15:16:55.628362 2026] [security2:error] [pid 971102:tid 971292] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/store/.env"] [unique_id "aqxYx-cL08BTTQixEnpszgAAADo"]
[Thu Sep 17 15:16:55.636531 2026] [security2:error] [pid 971102:tid 971324] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/laravel/.env"] [unique_id "aqxYx-cL08BTTQixEnpszwAAAFo"]
[Thu Sep 17 15:16:55.668875 2026] [security2:error] [pid 971102:tid 971259] [client 34.24.217.248:49346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnps0QAAABk"]
[Thu Sep 17 15:16:55.755470 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/saas/.env"] [unique_id "aqxYx-cL08BTTQixEnps1gAAAHU"]
[Thu Sep 17 15:16:55.845096 2026] [security2:error] [pid 971102:tid 971271] [client 34.24.217.248:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxYx-cL08BTTQixEnps3AAAACU"]
[Thu Sep 17 15:16:55.864640 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.218.131:48952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/symfony/.env"] [unique_id "aqxYx-cL08BTTQixEnps4AAAACc"]
[Thu Sep 17 15:16:55.881617 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/client/.env"] [unique_id "aqxYx-cL08BTTQixEnps4QAAAF4"]
[Thu Sep 17 15:16:55.892394 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/app/.env"] [unique_id "aqxYx-cL08BTTQixEnps4gAAAFA"]
[Thu Sep 17 15:16:55.948619 2026] [security2:error] [pid 971102:tid 971341] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/apps/.env"] [unique_id "aqxYx-cL08BTTQixEnps5QAAAGs"]
[Thu Sep 17 15:16:56.000796 2026] [security2:error] [pid 971102:tid 971339] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/project/.env"] [unique_id "aqxYx-cL08BTTQixEnps6AAAAGk"]
[Thu Sep 17 15:16:56.001828 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/.env"] [unique_id "aqxYyOcL08BTTQixEnps6QAAADY"]
[Thu Sep 17 15:16:56.067633 2026] [security2:error] [pid 971102:tid 971249] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/web/.env"] [unique_id "aqxYyOcL08BTTQixEnps7QAAAA8"]
[Thu Sep 17 15:16:56.068584 2026] [security2:error] [pid 971102:tid 971318] [client 34.24.217.248:49358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxYyOcL08BTTQixEnps7gAAAFQ"]
[Thu Sep 17 15:16:56.121883 2026] [security2:error] [pid 971102:tid 971321] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/admin-panel/.env"] [unique_id "aqxYyOcL08BTTQixEnps7wAAAFc"]
[Thu Sep 17 15:16:56.135589 2026] [security2:error] [pid 971102:tid 971287] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/site/.env"] [unique_id "aqxYyOcL08BTTQixEnps8AAAADU"]
[Thu Sep 17 15:16:56.207538 2026] [security2:error] [pid 971102:tid 971240] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/public/.env"] [unique_id "aqxYyOcL08BTTQixEnps9AAAAAY"]
[Thu Sep 17 15:16:56.229360 2026] [security2:error] [pid 971102:tid 971257] [client 34.24.217.248:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxYyOcL08BTTQixEnps9QAAABc"]
[Thu Sep 17 15:16:56.249080 2026] [security2:error] [pid 971102:tid 971334] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/control-panel/.env"] [unique_id "aqxYyOcL08BTTQixEnps9gAAAGQ"]
[Thu Sep 17 15:16:56.334405 2026] [security2:error] [pid 971102:tid 971256] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/backend/.env"] [unique_id "aqxYyOcL08BTTQixEnps-AAAABY"]
[Thu Sep 17 15:16:56.377870 2026] [security2:error] [pid 971102:tid 971349] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/user-panel/.env"] [unique_id "aqxYyOcL08BTTQixEnps_AAAAHM"]
[Thu Sep 17 15:16:56.392055 2026] [security2:error] [pid 971102:tid 971317] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/server/.env"] [unique_id "aqxYyOcL08BTTQixEnps_QAAAFM"]
[Thu Sep 17 15:16:56.407748 2026] [security2:error] [pid 971102:tid 971360] [client 34.24.217.248:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxYyOcL08BTTQixEnps_gAAAH4"]
[Thu Sep 17 15:16:56.454565 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/frontend/.env"] [unique_id "aqxYyOcL08BTTQixEnps_wAAAGY"]
[Thu Sep 17 15:16:56.504448 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/node/.env"] [unique_id "aqxYyOcL08BTTQixEnptAAAAAAQ"]
[Thu Sep 17 15:16:56.505167 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/src/.env"] [unique_id "aqxYyOcL08BTTQixEnptAQAAAFY"]
[Thu Sep 17 15:16:56.512422 2026] [security2:error] [pid 971102:tid 971276] [client 172.239.147.162:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxYyOcL08BTTQixEnptAgAAACo"], referer: binance.com
[Thu Sep 17 15:16:56.565878 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/wordpress/.env"] [unique_id "aqxYyOcL08BTTQixEnptAwAAAC0"]
[Thu Sep 17 15:16:56.568177 2026] [security2:error] [pid 971102:tid 971319] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/core/.env"] [unique_id "aqxYyOcL08BTTQixEnptBAAAAFU"]
[Thu Sep 17 15:16:56.597108 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxYyOcL08BTTQixEnptBQAAAFE"]
[Thu Sep 17 15:16:56.622364 2026] [security2:error] [pid 971102:tid 971285] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/core/app/.env"] [unique_id "aqxYyOcL08BTTQixEnptBgAAADM"]
[Thu Sep 17 15:16:56.638923 2026] [security2:error] [pid 971102:tid 971323] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/express/.env"] [unique_id "aqxYyOcL08BTTQixEnptBwAAAFk"]
[Thu Sep 17 15:16:56.654688 2026] [security2:error] [pid 971102:tid 971335] [client 172.239.147.162:58658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxYyOcL08BTTQixEnptCAAAAGU"], referer: binance.com
[Thu Sep 17 15:16:56.677592 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/config/.env"] [unique_id "aqxYyOcL08BTTQixEnptCgAAADE"]
[Thu Sep 17 15:16:56.734719 2026] [security2:error] [pid 971102:tid 971313] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/private/.env"] [unique_id "aqxYyOcL08BTTQixEnptDQAAAE8"]
[Thu Sep 17 15:16:56.761584 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/next/.env"] [unique_id "aqxYyOcL08BTTQixEnptDgAAAEM"]
[Thu Sep 17 15:16:56.778458 2026] [security2:error] [pid 971102:tid 971254] [client 34.24.217.248:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxYyOcL08BTTQixEnptDwAAABQ"]
[Thu Sep 17 15:16:56.787488 2026] [security2:error] [pid 971102:tid 971255] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/application/.env"] [unique_id "aqxYyOcL08BTTQixEnptEAAAABU"]
[Thu Sep 17 15:16:56.799721 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/wp/.env"] [unique_id "aqxYyOcL08BTTQixEnptEQAAAAA"]
[Thu Sep 17 15:16:56.840868 2026] [security2:error] [pid 971102:tid 971305] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/bootstrap/.env"] [unique_id "aqxYyOcL08BTTQixEnptFAAAAEc"]
[Thu Sep 17 15:16:56.884974 2026] [security2:error] [pid 971102:tid 971354] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/nuxt/.env"] [unique_id "aqxYyOcL08BTTQixEnptGAAAAHg"]
[Thu Sep 17 15:16:56.910426 2026] [security2:error] [pid 971102:tid 971343] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/database/.env"] [unique_id "aqxYyOcL08BTTQixEnptHAAAAG0"]
[Thu Sep 17 15:16:56.947682 2026] [security2:error] [pid 971102:tid 971350] [client 34.24.217.248:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxYyOcL08BTTQixEnptHQAAAHQ"]
[Thu Sep 17 15:16:56.961487 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/storage/.env"] [unique_id "aqxYyOcL08BTTQixEnptHgAAABk"]
[Thu Sep 17 15:16:57.005172 2026] [security2:error] [pid 971102:tid 971311] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/nest/.env"] [unique_id "aqxYyecL08BTTQixEnptIAAAAE0"]
[Thu Sep 17 15:16:57.023410 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/var/www/.env"] [unique_id "aqxYyecL08BTTQixEnptIgAAACU"]
[Thu Sep 17 15:16:57.036105 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cms/.env"] [unique_id "aqxYyecL08BTTQixEnptIwAAACc"]
[Thu Sep 17 15:16:57.081488 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/var/www/html/.env"] [unique_id "aqxYyecL08BTTQixEnptJAAAAEE"]
[Thu Sep 17 15:16:57.106446 2026] [security2:error] [pid 971102:tid 971351] [client 181.232.156.2:63654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYyecL08BTTQixEnptIQAAdSc"]
[Thu Sep 17 15:16:57.139103 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/react/.env"] [unique_id "aqxYyecL08BTTQixEnptJgAAABg"]
[Thu Sep 17 15:16:57.141827 2026] [security2:error] [pid 971102:tid 971289] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/current/.env"] [unique_id "aqxYyecL08BTTQixEnptJwAAADc"]
[Thu Sep 17 15:16:57.199613 2026] [security2:error] [pid 971102:tid 971295] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/release/.env"] [unique_id "aqxYyecL08BTTQixEnptKwAAAD0"]
[Thu Sep 17 15:16:57.239157 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxYyecL08BTTQixEnptMQAAAGg"]
[Thu Sep 17 15:16:57.265361 2026] [security2:error] [pid 971102:tid 971249] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/vue/.env"] [unique_id "aqxYyecL08BTTQixEnptNwAAAA8"]
[Thu Sep 17 15:16:57.268428 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/releases/.env"] [unique_id "aqxYyecL08BTTQixEnptOAAAAFQ"]
[Thu Sep 17 15:16:57.271719 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/drupal/.env"] [unique_id "aqxYyecL08BTTQixEnptOQAAADk"]
[Thu Sep 17 15:16:57.333404 2026] [security2:error] [pid 971102:tid 971257] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/shared/.env"] [unique_id "aqxYyecL08BTTQixEnptOgAAABc"]
[Thu Sep 17 15:16:57.387129 2026] [security2:error] [pid 971102:tid 971310] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/deploy/.env"] [unique_id "aqxYyecL08BTTQixEnptQAAAAEw"]
[Thu Sep 17 15:16:57.396251 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/angular/.env"] [unique_id "aqxYyecL08BTTQixEnptQwAAAAs"]
[Thu Sep 17 15:16:57.413467 2026] [security2:error] [pid 971102:tid 971322] [client 34.24.217.248:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptRQAAAFg"]
[Thu Sep 17 15:16:57.450163 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/build/.env"] [unique_id "aqxYyecL08BTTQixEnptSQAAAGY"]
[Thu Sep 17 15:16:57.465947 2026] [security2:error] [pid 971102:tid 971328] [client 156.192.234.52:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYyecL08BTTQixEnptTAAAAF4"]
[Thu Sep 17 15:16:57.466545 2026] [security2:error] [pid 971102:tid 971328] [client 156.192.234.52:49481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxYyecL08BTTQixEnptTAAAAF4"]
[Thu Sep 17 15:16:57.506623 2026] [security2:error] [pid 971102:tid 971285] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/joomla/.env"] [unique_id "aqxYyecL08BTTQixEnptTgAAADM"]
[Thu Sep 17 15:16:57.529131 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/svelte/.env"] [unique_id "aqxYyecL08BTTQixEnptUAAAAHk"]
[Thu Sep 17 15:16:57.530206 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/dist/.env"] [unique_id "aqxYyecL08BTTQixEnptUQAAADE"]
[Thu Sep 17 15:16:57.582951 2026] [security2:error] [pid 971102:tid 971335] [client 34.24.217.248:49432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptVAAAAGU"]
[Thu Sep 17 15:16:57.593711 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/public_html/.env"] [unique_id "aqxYyecL08BTTQixEnptVQAAACQ"]
[Thu Sep 17 15:16:57.654942 2026] [security2:error] [pid 971102:tid 971242] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/vite/.env"] [unique_id "aqxYyecL08BTTQixEnptVgAAAAg"]
[Thu Sep 17 15:16:57.666305 2026] [security2:error] [pid 971102:tid 971234] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/htdocs/.env"] [unique_id "aqxYyecL08BTTQixEnptVwAAAAA"]
[Thu Sep 17 15:16:57.729026 2026] [security2:error] [pid 971102:tid 971286] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/www/.env"] [unique_id "aqxYyecL08BTTQixEnptWQAAADQ"]
[Thu Sep 17 15:16:57.740258 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/magento/.env"] [unique_id "aqxYyecL08BTTQixEnptXAAAABw"]
[Thu Sep 17 15:16:57.763297 2026] [security2:error] [pid 971102:tid 971274] [client 34.24.217.248:49436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptXQAAACg"]
[Thu Sep 17 15:16:57.774268 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/backup/.env"] [unique_id "aqxYyecL08BTTQixEnptXwAAAHc"]
[Thu Sep 17 15:16:57.791293 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/html/.env"] [unique_id "aqxYyecL08BTTQixEnptYAAAACU"]
[Thu Sep 17 15:16:57.843234 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/live/.env"] [unique_id "aqxYyecL08BTTQixEnptYQAAAEE"]
[Thu Sep 17 15:16:57.897941 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/prod/.env"] [unique_id "aqxYyecL08BTTQixEnptZQAAAFA"]
[Thu Sep 17 15:16:57.929787 2026] [security2:error] [pid 971102:tid 971295] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/backups/.env"] [unique_id "aqxYyecL08BTTQixEnptbAAAAD0"]
[Thu Sep 17 15:16:57.949748 2026] [security2:error] [pid 971102:tid 971250] [client 172.239.147.162:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxYyecL08BTTQixEnptbQAAABA"], referer: binance.com
[Thu Sep 17 15:16:57.954250 2026] [security2:error] [pid 971102:tid 971351] [client 34.24.217.248:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxYyecL08BTTQixEnptbgAAAHU"]
[Thu Sep 17 15:16:57.974141 2026] [security2:error] [pid 971102:tid 971338] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/dev/.env"] [unique_id "aqxYyecL08BTTQixEnptbwAAAGg"]
[Thu Sep 17 15:16:57.976372 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shopify/.env"] [unique_id "aqxYyecL08BTTQixEnptcAAAABI"]
[Thu Sep 17 15:16:58.040826 2026] [security2:error] [pid 971102:tid 971267] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/staging/.env"] [unique_id "aqxYyucL08BTTQixEnptcwAAACE"]
[Thu Sep 17 15:16:58.056307 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/old/.env"] [unique_id "aqxYyucL08BTTQixEnptdAAAAHI"]
[Thu Sep 17 15:16:58.100126 2026] [security2:error] [pid 971102:tid 971332] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/opt/.env"] [unique_id "aqxYyucL08BTTQixEnptdQAAAGI"]
[Thu Sep 17 15:16:58.137307 2026] [security2:error] [pid 971102:tid 971244] [client 34.24.217.248:49448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxYyucL08BTTQixEnptdwAAAAo"]
[Thu Sep 17 15:16:58.153008 2026] [security2:error] [pid 971102:tid 971249] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/laravel/.env"] [unique_id "aqxYyucL08BTTQixEnpteAAAAA8"]
[Thu Sep 17 15:16:58.177100 2026] [security2:error] [pid 971102:tid 971243] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/tmp/.env"] [unique_id "aqxYyucL08BTTQixEnpteQAAAAk"]
[Thu Sep 17 15:16:58.206680 2026] [security2:error] [pid 971102:tid 971321] [client 35.202.49.146:48544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/symfony/.env"] [unique_id "aqxYyucL08BTTQixEnptegAAAFc"]
[Thu Sep 17 15:16:58.213800 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/prestashop/.env"] [unique_id "aqxYyucL08BTTQixEnptewAAADU"]
[Thu Sep 17 15:16:58.305358 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/temp/.env"] [unique_id "aqxYyucL08BTTQixEnptgAAAAAs"]
[Thu Sep 17 15:16:58.329255 2026] [security2:error] [pid 971102:tid 971334] [client 34.24.217.248:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxYyucL08BTTQixEnptggAAAGQ"]
[Thu Sep 17 15:16:58.387852 2026] [security2:error] [pid 971102:tid 971349] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/wordpress/.env"] [unique_id "aqxYyucL08BTTQixEnpthwAAAHM"]
[Thu Sep 17 15:16:58.429785 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/lab/.env"] [unique_id "aqxYyucL08BTTQixEnptjAAAAF4"]
[Thu Sep 17 15:16:58.439746 2026] [security2:error] [pid 971102:tid 971296] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/wp/.env"] [unique_id "aqxYyucL08BTTQixEnptjQAAAD4"]
[Thu Sep 17 15:16:58.452469 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/codeigniter/.env"] [unique_id "aqxYyucL08BTTQixEnptjgAAAFU"]
[Thu Sep 17 15:16:58.479137 2026] [security2:error] [pid 971102:tid 971322] [client 172.239.147.162:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxYyucL08BTTQixEnptjwAAAFg"], referer: binance.com
[Thu Sep 17 15:16:58.514092 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cms/.env"] [unique_id "aqxYyucL08BTTQixEnptkAAAADE"]
[Thu Sep 17 15:16:58.516018 2026] [security2:error] [pid 971102:tid 971315] [client 34.24.217.248:49470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxYyucL08BTTQixEnptkQAAAFE"]
[Thu Sep 17 15:16:58.553546 2026] [security2:error] [pid 971102:tid 971320] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cronlab/.env"] [unique_id "aqxYyucL08BTTQixEnptkgAAAFY"]
[Thu Sep 17 15:16:58.569358 2026] [security2:error] [pid 971102:tid 971335] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/drupal/.env"] [unique_id "aqxYyucL08BTTQixEnptkwAAAGU"]
[Thu Sep 17 15:16:58.629379 2026] [security2:error] [pid 971102:tid 971323] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/joomla/.env"] [unique_id "aqxYyucL08BTTQixEnptlwAAAFk"]
[Thu Sep 17 15:16:58.689295 2026] [security2:error] [pid 971102:tid 971303] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cron/.env"] [unique_id "aqxYyucL08BTTQixEnptmgAAAEU"]
[Thu Sep 17 15:16:58.691091 2026] [security2:error] [pid 971102:tid 971255] [client 34.24.217.248:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxYyucL08BTTQixEnptnAAAABU"]
[Thu Sep 17 15:16:58.691958 2026] [security2:error] [pid 971102:tid 971265] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/magento/.env"] [unique_id "aqxYyucL08BTTQixEnptmwAAAB8"]
[Thu Sep 17 15:16:58.693183 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cakephp/.env"] [unique_id "aqxYyucL08BTTQixEnptnQAAAEc"]
[Thu Sep 17 15:16:58.727676 2026] [security2:error] [pid 971102:tid 971247] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxYyecL08BTTQixEnptHwAAAA0"]
[Thu Sep 17 15:16:58.748947 2026] [security2:error] [pid 971102:tid 971262] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/shopify/.env"] [unique_id "aqxYyucL08BTTQixEnptogAAABw"]
[Thu Sep 17 15:16:58.807544 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/prestashop/.env"] [unique_id "aqxYyucL08BTTQixEnptowAAABk"]
[Thu Sep 17 15:16:58.808226 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/en/.env"] [unique_id "aqxYyucL08BTTQixEnptpAAAAHw"]
[Thu Sep 17 15:16:58.856964 2026] [security2:error] [pid 971102:tid 971273] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/codeigniter/.env"] [unique_id "aqxYyucL08BTTQixEnptpwAAACc"]
[Thu Sep 17 15:16:58.863736 2026] [security2:error] [pid 971102:tid 971354] [client 5.49.0.22:60112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxYyucL08BTTQixEnptoQAAeGU"]
[Thu Sep 17 15:16:58.864217 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:49474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxYyucL08BTTQixEnptqAAAAHc"]
[Thu Sep 17 15:16:58.903549 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cakephp/.env"] [unique_id "aqxYyucL08BTTQixEnptqgAAAFA"]
[Thu Sep 17 15:16:58.926806 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/zend/.env"] [unique_id "aqxYyucL08BTTQixEnptqwAAAHQ"]
[Thu Sep 17 15:16:58.934499 2026] [security2:error] [pid 971102:tid 971357] [client 34.154.67.31:40584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxYyucL08BTTQixEnptrAAAAHs"]
[Thu Sep 17 15:16:58.949445 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/zend/.env"] [unique_id "aqxYyucL08BTTQixEnptrgAAAGc"]
[Thu Sep 17 15:16:59.003748 2026] [security2:error] [pid 971102:tid 971300] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/yii/.env"] [unique_id "aqxYy-cL08BTTQixEnptrwAAAEI"]
[Thu Sep 17 15:16:59.029187 2026] [security2:error] [pid 971102:tid 971250] [client 34.24.217.248:49484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxYy-cL08BTTQixEnptsQAAABA"]
[Thu Sep 17 15:16:59.048783 2026] [security2:error] [pid 971102:tid 971277] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/laravel5/.env"] [unique_id "aqxYy-cL08BTTQixEnptsgAAACs"]
[Thu Sep 17 15:16:59.054935 2026] [security2:error] [pid 971102:tid 971359] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/administrator/.env"] [unique_id "aqxYyucL08BTTQixEnptrQAAAH0"]
[Thu Sep 17 15:16:59.090892 2026] [security2:error] [pid 971102:tid 971260] [client 34.154.67.31:40584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.env~"] [unique_id "aqxYy-cL08BTTQixEnptswAAABo"]
[Thu Sep 17 15:16:59.101739 2026] [security2:error] [pid 971102:tid 971267] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/v1/.env"] [unique_id "aqxYy-cL08BTTQixEnpttAAAACE"]
[Thu Sep 17 15:16:59.155052 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/v2/.env"] [unique_id "aqxYy-cL08BTTQixEnpttQAAAE4"]
[Thu Sep 17 15:16:59.156346 2026] [security2:error] [pid 971102:tid 971316] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/yii/.env"] [unique_id "aqxYy-cL08BTTQixEnpttgAAAFI"]
[Thu Sep 17 15:16:59.183985 2026] [security2:error] [pid 971102:tid 971341] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/psnlink/.env"] [unique_id "aqxYy-cL08BTTQixEnptuQAAAGs"]
[Thu Sep 17 15:16:59.202196 2026] [security2:error] [pid 971102:tid 971339] [client 34.24.217.248:49498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnptvAAAAGk"]
[Thu Sep 17 15:16:59.210436 2026] [security2:error] [pid 971102:tid 971332] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/v3/.env"] [unique_id "aqxYy-cL08BTTQixEnptvQAAAGI"]
[Thu Sep 17 15:16:59.268985 2026] [security2:error] [pid 971102:tid 971321] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/v1/.env"] [unique_id "aqxYy-cL08BTTQixEnptwwAAAFc"]
[Thu Sep 17 15:16:59.307227 2026] [security2:error] [pid 971102:tid 971293] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/exapi/.env"] [unique_id "aqxYy-cL08BTTQixEnptxQAAADs"]
[Thu Sep 17 15:16:59.317711 2026] [security2:error] [pid 971102:tid 971287] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/v2/.env"] [unique_id "aqxYy-cL08BTTQixEnptxgAAADU"]
[Thu Sep 17 15:16:59.374049 2026] [security2:error] [pid 971102:tid 971269] [client 34.24.217.248:49504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnptyAAAACM"]
[Thu Sep 17 15:16:59.394145 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/laravel5/.env"] [unique_id "aqxYy-cL08BTTQixEnptyQAAAAc"]
[Thu Sep 17 15:16:59.396115 2026] [security2:error] [pid 971102:tid 971236] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/rest/.env"] [unique_id "aqxYy-cL08BTTQixEnptygAAAAI"]
[Thu Sep 17 15:16:59.437454 2026] [security2:error] [pid 971102:tid 971278] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sitemaps/.env"] [unique_id "aqxYy-cL08BTTQixEnptywAAACw"]
[Thu Sep 17 15:16:59.454595 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/graphql/.env"] [unique_id "aqxYy-cL08BTTQixEnptzAAAAAs"]
[Thu Sep 17 15:16:59.529976 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/gateway/.env"] [unique_id "aqxYy-cL08BTTQixEnptzgAAADY"]
[Thu Sep 17 15:16:59.561825 2026] [security2:error] [pid 971102:tid 971317] [client 34.24.217.248:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnpt0gAAAFM"]
[Thu Sep 17 15:16:59.576702 2026] [security2:error] [pid 971102:tid 971328] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/microservice/.env"] [unique_id "aqxYy-cL08BTTQixEnpt0wAAAF4"]
[Thu Sep 17 15:16:59.624855 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v1/.env"] [unique_id "aqxYy-cL08BTTQixEnpt1QAAACo"]
[Thu Sep 17 15:16:59.627887 2026] [security2:error] [pid 971102:tid 971280] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/service/.env"] [unique_id "aqxYy-cL08BTTQixEnpt1gAAAC4"]
[Thu Sep 17 15:16:59.673584 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/v3/.env"] [unique_id "aqxYy-cL08BTTQixEnpt3QAAAFY"]
[Thu Sep 17 15:16:59.714905 2026] [security2:error] [pid 971102:tid 971349] [client 172.239.147.162:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxYy-cL08BTTQixEnpt3wAAAHM"], referer: binance.com
[Thu Sep 17 15:16:59.727769 2026] [security2:error] [pid 971102:tid 971323] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/dev/.env"] [unique_id "aqxYy-cL08BTTQixEnpt4gAAAFk"]
[Thu Sep 17 15:16:59.728600 2026] [security2:error] [pid 971102:tid 971282] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYy-cL08BTTQixEnpt1AAAADA"]
[Thu Sep 17 15:16:59.732918 2026] [security2:error] [pid 971102:tid 971301] [client 34.24.217.248:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnpt5AAAAEM"]
[Thu Sep 17 15:16:59.773210 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/api/staging/.env"] [unique_id "aqxYy-cL08BTTQixEnpt6gAAAFo"]
[Thu Sep 17 15:16:59.819951 2026] [security2:error] [pid 971102:tid 971326] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/vendor/.env"] [unique_id "aqxYy-cL08BTTQixEnpt6wAAAFw"]
[Thu Sep 17 15:16:59.857488 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v2/.env"] [unique_id "aqxYy-cL08BTTQixEnpt7gAAABs"]
[Thu Sep 17 15:16:59.865140 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/lib/.env"] [unique_id "aqxYy-cL08BTTQixEnpt8AAAAHw"]
[Thu Sep 17 15:16:59.908250 2026] [security2:error] [pid 971102:tid 971286] [client 34.24.217.248:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxYy-cL08BTTQixEnpt9QAAADQ"]
[Thu Sep 17 15:16:59.912830 2026] [security2:error] [pid 971102:tid 971353] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/resources/.env"] [unique_id "aqxYy-cL08BTTQixEnpt9gAAAHc"]
[Thu Sep 17 15:16:59.971060 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/assets/.env"] [unique_id "aqxYy-cL08BTTQixEnpt-QAAAGc"]
[Thu Sep 17 15:17:00.049026 2026] [security2:error] [pid 971102:tid 971250] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/uploads/.env"] [unique_id "aqxYzOcL08BTTQixEnpt_wAAABA"]
[Thu Sep 17 15:17:00.081428 2026] [security2:error] [pid 971102:tid 971300] [client 34.24.217.248:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuAQAAAEI"]
[Thu Sep 17 15:17:00.092120 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v3/.env"] [unique_id "aqxYzOcL08BTTQixEnpuAwAAADo"]
[Thu Sep 17 15:17:00.100008 2026] [security2:error] [pid 971102:tid 971267] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/internal/.env"] [unique_id "aqxYzOcL08BTTQixEnpuBQAAACE"]
[Thu Sep 17 15:17:00.156883 2026] [security2:error] [pid 971102:tid 971239] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/tools/.env"] [unique_id "aqxYzOcL08BTTQixEnpuCQAAAAU"]
[Thu Sep 17 15:17:00.222368 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/scripts/.env"] [unique_id "aqxYzOcL08BTTQixEnpuCgAAAAo"]
[Thu Sep 17 15:17:00.235111 2026] [security2:error] [pid 971102:tid 971316] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuCAAAAFI"]
[Thu Sep 17 15:17:00.280538 2026] [security2:error] [pid 971102:tid 971237] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/bin/.env"] [unique_id "aqxYzOcL08BTTQixEnpuEgAAAAM"]
[Thu Sep 17 15:17:00.283099 2026] [security2:error] [pid 971102:tid 971338] [client 34.24.217.248:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuEwAAAGg"]
[Thu Sep 17 15:17:00.326539 2026] [security2:error] [pid 971102:tid 971336] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v1/.env"] [unique_id "aqxYzOcL08BTTQixEnpuFgAAAGY"]
[Thu Sep 17 15:17:00.332868 2026] [security2:error] [pid 971102:tid 971317] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sbin/.env"] [unique_id "aqxYzOcL08BTTQixEnpuFwAAAFM"]
[Thu Sep 17 15:17:00.376774 2026] [security2:error] [pid 971102:tid 971238] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/local/.env"] [unique_id "aqxYzOcL08BTTQixEnpuHAAAAAQ"]
[Thu Sep 17 15:17:00.413021 2026] [security2:error] [pid 971102:tid 971355] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/logs/.env"] [unique_id "aqxYzOcL08BTTQixEnpuHgAAAHk"]
[Thu Sep 17 15:17:00.423072 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/portal/.env"] [unique_id "aqxYzOcL08BTTQixEnpuHwAAAEg"]
[Thu Sep 17 15:17:00.458572 2026] [security2:error] [pid 971102:tid 971322] [client 34.24.217.248:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuIgAAAFg"]
[Thu Sep 17 15:17:00.484628 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/dashboard/.env"] [unique_id "aqxYzOcL08BTTQixEnpuJQAAADA"]
[Thu Sep 17 15:17:00.531273 2026] [security2:error] [pid 971102:tid 971361] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/panel/.env"] [unique_id "aqxYzOcL08BTTQixEnpuJgAAAH8"]
[Thu Sep 17 15:17:00.532467 2026] [security2:error] [pid 971102:tid 971265] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cache/.env"] [unique_id "aqxYzOcL08BTTQixEnpuJwAAAB8"]
[Thu Sep 17 15:17:00.557618 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v2/.env"] [unique_id "aqxYzOcL08BTTQixEnpuKAAAAE8"]
[Thu Sep 17 15:17:00.594097 2026] [security2:error] [pid 971102:tid 971262] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/crm/.env"] [unique_id "aqxYzOcL08BTTQixEnpuLQAAABw"]
[Thu Sep 17 15:17:00.620167 2026] [security2:error] [pid 971102:tid 971296] [client 34.24.217.248:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuLwAAAD4"]
[Thu Sep 17 15:17:00.645824 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/erp/.env"] [unique_id "aqxYzOcL08BTTQixEnpuMAAAABk"]
[Thu Sep 17 15:17:00.654748 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailer/.env"] [unique_id "aqxYzOcL08BTTQixEnpuMQAAAHw"]
[Thu Sep 17 15:17:00.722372 2026] [security2:error] [pid 971102:tid 971285] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuMgAAM04"], referer: http://slimmtech.com/blog/
[Thu Sep 17 15:17:00.723757 2026] [security2:error] [pid 971102:tid 971286] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/shop/.env"] [unique_id "aqxYzOcL08BTTQixEnpuMwAAADQ"]
[Thu Sep 17 15:17:00.759545 2026] [security2:error] [pid 971102:tid 971299] [client 5.188.86.234:33344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/blog/wp-login.php"] [unique_id "aqxYzOcL08BTTQixEnpuNwAAAEE"]
[Thu Sep 17 15:17:00.769143 2026] [security2:error] [pid 971102:tid 971350] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/store/.env"] [unique_id "aqxYzOcL08BTTQixEnpuPAAAAHQ"]
[Thu Sep 17 15:17:00.777618 2026] [security2:error] [pid 971102:tid 971357] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mail/.env"] [unique_id "aqxYzOcL08BTTQixEnpuPQAAAHs"]
[Thu Sep 17 15:17:00.786345 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/rest/.env"] [unique_id "aqxYzOcL08BTTQixEnpuPwAAAG4"]
[Thu Sep 17 15:17:00.794446 2026] [security2:error] [pid 971102:tid 971353] [client 34.24.217.248:57966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuQAAAAHc"]
[Thu Sep 17 15:17:00.821795 2026] [security2:error] [pid 971102:tid 971252] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/saas/.env"] [unique_id "aqxYzOcL08BTTQixEnpuQQAAABI"]
[Thu Sep 17 15:17:00.848821 2026] [security2:error] [pid 971102:tid 971250] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuQgAAEEQ"], referer: http://slimmtech.com/wordpress/
[Thu Sep 17 15:17:00.878673 2026] [security2:error] [pid 971102:tid 971300] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/client/.env"] [unique_id "aqxYzOcL08BTTQixEnpuRAAAAEI"]
[Thu Sep 17 15:17:00.898442 2026] [security2:error] [pid 971102:tid 971292] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/email/.env"] [unique_id "aqxYzOcL08BTTQixEnpuRQAAADo"]
[Thu Sep 17 15:17:00.931724 2026] [security2:error] [pid 971102:tid 971275] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/project/.env"] [unique_id "aqxYzOcL08BTTQixEnpuSAAAACk"]
[Thu Sep 17 15:17:00.966565 2026] [security2:error] [pid 971102:tid 971325] [client 34.24.217.248:57982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxYzOcL08BTTQixEnpuSQAAAFs"]
[Thu Sep 17 15:17:00.974429 2026] [security2:error] [pid 971102:tid 971348] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzOcL08BTTQixEnpuSgAAclA"], referer: http://slimmtech.com/wp/
[Thu Sep 17 15:17:00.992538 2026] [security2:error] [pid 971102:tid 971239] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/admin-panel/.env"] [unique_id "aqxYzOcL08BTTQixEnpuSwAAAAU"]
[Thu Sep 17 15:17:01.014949 2026] [security2:error] [pid 971102:tid 971240] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/graphql/.env"] [unique_id "aqxYzecL08BTTQixEnpuTAAAAAY"]
[Thu Sep 17 15:17:01.017388 2026] [security2:error] [pid 971102:tid 971307] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/smtp/.env"] [unique_id "aqxYzecL08BTTQixEnpuTQAAAEk"]
[Thu Sep 17 15:17:01.070090 2026] [security2:error] [pid 971102:tid 971359] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/control-panel/.env"] [unique_id "aqxYzecL08BTTQixEnpuTwAAAH0"]
[Thu Sep 17 15:17:01.114015 2026] [security2:error] [pid 971102:tid 971318] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzecL08BTTQixEnpuUgAAVH4"], referer: http://slimmtech.com/old/
[Thu Sep 17 15:17:01.118648 2026] [security2:error] [pid 971102:tid 971293] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/user-panel/.env"] [unique_id "aqxYzecL08BTTQixEnpuUwAAADs"]
[Thu Sep 17 15:17:01.137649 2026] [security2:error] [pid 971102:tid 971351] [client 34.97.30.29:43948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailing/.env"] [unique_id "aqxYzecL08BTTQixEnpuVAAAAHU"]
[Thu Sep 17 15:17:01.137655 2026] [security2:error] [pid 971102:tid 971321] [client 34.24.217.248:57988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxYzecL08BTTQixEnpuVQAAAFc"]
[Thu Sep 17 15:17:01.181318 2026] [security2:error] [pid 971102:tid 971287] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/node/.env"] [unique_id "aqxYzecL08BTTQixEnpuVgAAADU"]
[Thu Sep 17 15:17:01.212173 2026] [security2:error] [pid 971102:tid 971211] [remote 5.188.86.234:46260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/blog/wp-login.php"] [unique_id "aqxYzecL08BTTQixEnpuWAAAJWo"]
[Thu Sep 17 15:17:01.228118 2026] [security2:error] [pid 971102:tid 971338] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/express/.env"] [unique_id "aqxYzecL08BTTQixEnpuWQAAAGg"]
[Thu Sep 17 15:17:01.248149 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gateway/.env"] [unique_id "aqxYzecL08BTTQixEnpuWgAAABc"]
[Thu Sep 17 15:17:01.250549 2026] [security2:error] [pid 971102:tid 971272] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzecL08BTTQixEnpuXAAAJmQ"], referer: http://slimmtech.com/backup/
[Thu Sep 17 15:17:01.289965 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/next/.env"] [unique_id "aqxYzecL08BTTQixEnpuYwAAADY"]
[Thu Sep 17 15:17:01.313447 2026] [security2:error] [pid 971102:tid 971274] [client 34.24.217.248:58000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxYzecL08BTTQixEnpuZAAAACg"]
[Thu Sep 17 15:17:01.344116 2026] [security2:error] [pid 971102:tid 971334] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/nuxt/.env"] [unique_id "aqxYzecL08BTTQixEnpuZgAAAGQ"]
[Thu Sep 17 15:17:01.392124 2026] [security2:error] [pid 971102:tid 971355] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/nest/.env"] [unique_id "aqxYzecL08BTTQixEnpuawAAAHk"]
[Thu Sep 17 15:17:01.437867 2026] [security2:error] [pid 971102:tid 971323] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/react/.env"] [unique_id "aqxYzecL08BTTQixEnpubQAAAFk"]
[Thu Sep 17 15:17:01.467592 2026] [security2:error] [pid 971102:tid 971317] [client 172.239.147.162:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxYzecL08BTTQixEnpubwAAAFM"], referer: binance.com
[Thu Sep 17 15:17:01.477767 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/microservice/.env"] [unique_id "aqxYzecL08BTTQixEnpucAAAAEM"]
[Thu Sep 17 15:17:01.477900 2026] [security2:error] [pid 971102:tid 971330] [client 34.24.217.248:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.217.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.haa.tpa.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxYzecL08BTTQixEnpucQAAAGA"]
[Thu Sep 17 15:17:01.493905 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/vue/.env"] [unique_id "aqxYzecL08BTTQixEnpucgAAACQ"]
[Thu Sep 17 15:17:01.503485 2026] [security2:error] [pid 971102:tid 971281] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/notifications/.env"] [unique_id "aqxYzecL08BTTQixEnpucwAAAC8"]
[Thu Sep 17 15:17:01.526406 2026] [security2:error] [pid 971102:tid 971303] [client 167.71.243.84:44654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slimmtech.com"] [uri "/index.php"] [unique_id "aqxYzecL08BTTQixEnpudAAARRw"], referer: http://slimmtech.com/new/
[Thu Sep 17 15:17:01.550372 2026] [security2:error] [pid 971102:tid 971342] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/angular/.env"] [unique_id "aqxYzecL08BTTQixEnpudQAAAGw"]
[Thu Sep 17 15:17:01.599709 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/svelte/.env"] [unique_id "aqxYzecL08BTTQixEnpudwAAAFo"]
[Thu Sep 17 15:17:01.622159 2026] [security2:error] [pid 971102:tid 971262] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/notify/.env"] [unique_id "aqxYzecL08BTTQixEnpuewAAABw"]
[Thu Sep 17 15:17:01.624645 2026] [security2:error] [pid 971102:tid 971237] [client 104.28.198.244:22589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzecL08BTTQixEnpufAAAAAM"]
[Thu Sep 17 15:17:01.624748 2026] [security2:error] [pid 971102:tid 971237] [client 104.28.198.244:22589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzecL08BTTQixEnpufAAAAAM"]
[Thu Sep 17 15:17:01.639162 2026] [security2:error] [pid 971102:tid 971326] [client 127.0.0.1:23396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYzecL08BTTQixEnpuegAAAFw"]
[Thu Sep 17 15:17:01.639166 2026] [security2:error] [pid 971102:tid 971313] [client 127.0.0.1:23380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.buliblog.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYzecL08BTTQixEnpueQAAAE8"]
[Thu Sep 17 15:17:01.639264 2026] [security2:error] [pid 971102:tid 971243] [client 74.7.228.58:34334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.buliblog.com"] [uri "/robots.txt"] [unique_id "aqxYzecL08BTTQixEnpueAAACTE"]
[Thu Sep 17 15:17:01.648322 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/vite/.env"] [unique_id "aqxYzecL08BTTQixEnpufQAAAHw"]
[Thu Sep 17 15:17:01.691778 2026] [security2:error] [pid 971102:tid 971247] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/backup/.env"] [unique_id "aqxYzecL08BTTQixEnpufwAAAA0"]
[Thu Sep 17 15:17:01.706015 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/service/.env"] [unique_id "aqxYzecL08BTTQixEnpugwAAADw"]
[Thu Sep 17 15:17:01.734390 2026] [security2:error] [pid 971102:tid 971263] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/backups/.env"] [unique_id "aqxYzecL08BTTQixEnpuhAAAAB0"]
[Thu Sep 17 15:17:01.741898 2026] [security2:error] [pid 971102:tid 971234] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sender/.env"] [unique_id "aqxYzecL08BTTQixEnpuhQAAAAA"]
[Thu Sep 17 15:17:01.784677 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/old/.env"] [unique_id "aqxYzecL08BTTQixEnpuigAAAFY"]
[Thu Sep 17 15:17:01.834838 2026] [security2:error] [pid 971102:tid 971315] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/tmp/.env"] [unique_id "aqxYzecL08BTTQixEnpulQAAAFE"]
[Thu Sep 17 15:17:01.865586 2026] [security2:error] [pid 971102:tid 971343] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/campaign/.env"] [unique_id "aqxYzecL08BTTQixEnpulgAAAG0"]
[Thu Sep 17 15:17:01.877549 2026] [security2:error] [pid 971102:tid 971277] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/temp/.env"] [unique_id "aqxYzecL08BTTQixEnpulwAAACs"]
[Thu Sep 17 15:17:01.924984 2026] [security2:error] [pid 971102:tid 971289] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/lab/.env"] [unique_id "aqxYzecL08BTTQixEnpumwAAADc"]
[Thu Sep 17 15:17:01.934263 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v3/.env"] [unique_id "aqxYzecL08BTTQixEnpunQAAAE4"]
[Thu Sep 17 15:17:01.980953 2026] [security2:error] [pid 971102:tid 971353] [client 172.239.147.162:59599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxYzecL08BTTQixEnpuoAAAAHc"], referer: binance.com
[Thu Sep 17 15:17:01.981273 2026] [security2:error] [pid 971102:tid 971348] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cronlab/.env"] [unique_id "aqxYzecL08BTTQixEnpunwAAAHI"]
[Thu Sep 17 15:17:01.996448 2026] [security2:error] [pid 971102:tid 971240] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/newsletter/.env"] [unique_id "aqxYzecL08BTTQixEnpuoQAAAAY"]
[Thu Sep 17 15:17:02.036841 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cron/.env"] [unique_id "aqxYzucL08BTTQixEnpuowAAAAo"]
[Thu Sep 17 15:17:02.086051 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/en/.env"] [unique_id "aqxYzucL08BTTQixEnpupgAAAFQ"]
[Thu Sep 17 15:17:02.115756 2026] [security2:error] [pid 971102:tid 971287] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/ses/.env"] [unique_id "aqxYzucL08BTTQixEnpuqwAAADU"]
[Thu Sep 17 15:17:02.164048 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/dev/.env"] [unique_id "aqxYzucL08BTTQixEnpurwAAACY"]
[Thu Sep 17 15:17:02.181876 2026] [security2:error] [pid 971102:tid 971339] [client 185.55.149.49:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpusgAAAGk"]
[Thu Sep 17 15:17:02.181961 2026] [security2:error] [pid 971102:tid 971339] [client 185.55.149.49:59480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpusgAAAGk"]
[Thu Sep 17 15:17:02.192391 2026] [security2:error] [pid 971102:tid 971236] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/administrator/.env"] [unique_id "aqxYzucL08BTTQixEnpurQAAAAI"]
[Thu Sep 17 15:17:02.234491 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sendgrid/.env"] [unique_id "aqxYzucL08BTTQixEnputAAAAAs"]
[Thu Sep 17 15:17:02.247258 2026] [security2:error] [pid 971102:tid 971354] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/psnlink/.env"] [unique_id "aqxYzucL08BTTQixEnputwAAAHg"]
[Thu Sep 17 15:17:02.304296 2026] [security2:error] [pid 971102:tid 971301] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/exapi/.env"] [unique_id "aqxYzucL08BTTQixEnpuuwAAAEM"]
[Thu Sep 17 15:17:02.360073 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/sparkpost/.env"] [unique_id "aqxYzucL08BTTQixEnpuwgAAABM"]
[Thu Sep 17 15:17:02.360124 2026] [security2:error] [pid 971102:tid 971235] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sitemaps/.env"] [unique_id "aqxYzucL08BTTQixEnpuwQAAAAE"]
[Thu Sep 17 15:17:02.408067 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/staging/.env"] [unique_id "aqxYzucL08BTTQixEnpuyAAAAFU"]
[Thu Sep 17 15:17:02.474800 2026] [security2:error] [pid 971102:tid 971305] [client 127.0.0.1:60170] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxYzucL08BTTQixEnpuzAAAAEc"]
[Thu Sep 17 15:17:02.474819 2026] [security2:error] [pid 971102:tid 971290] [client 74.7.244.45:56524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tlschulmanlaw.com"] [uri "/robots.txt"] [unique_id "aqxYzucL08BTTQixEnpuywAAADg"]
[Thu Sep 17 15:17:02.479460 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/postmark/.env"] [unique_id "aqxYzucL08BTTQixEnpuzwAAAAM"]
[Thu Sep 17 15:17:02.553372 2026] [security2:error] [pid 971102:tid 971346] [client 103.131.71.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tab-funkenwerk.org"] [uri "/index.php"] [unique_id "aqxYzucL08BTTQixEnpuxwAAAHA"]
[Thu Sep 17 15:17:02.558182 2026] [security2:error] [pid 971102:tid 971261] [client 35.202.49.146:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/logs/.env"] [unique_id "aqxYzucL08BTTQixEnpu0QAAABs"]
[Thu Sep 17 15:17:02.600290 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailgun/.env"] [unique_id "aqxYzucL08BTTQixEnpu0gAAABg"]
[Thu Sep 17 15:17:02.607542 2026] [security2:error] [pid 971102:tid 971238] [client 172.239.147.162:49187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxYzucL08BTTQixEnpu1AAAAAQ"], referer: binance.com
[Thu Sep 17 15:17:02.622128 2026] [autoindex:error] [pid 971102:tid 971273] [client 34.24.217.248:58034] AH01276: Cannot serve directory /home1/haatpamy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:17:02.645282 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vendor/.env"] [unique_id "aqxYzucL08BTTQixEnpu1wAAAD4"]
[Thu Sep 17 15:17:02.709406 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpu2QAAAB0"]
[Thu Sep 17 15:17:02.709516 2026] [security2:error] [pid 971102:tid 971263] [client 45.169.98.18:58099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxYzucL08BTTQixEnpu2QAAAB0"]
[Thu Sep 17 15:17:02.720354 2026] [security2:error] [pid 971102:tid 971252] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mandrill/.env"] [unique_id "aqxYzucL08BTTQixEnpu2gAAABI"]
[Thu Sep 17 15:17:02.763761 2026] [security2:error] [pid 971102:tid 971315] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cache/.env"] [unique_id "aqxYzucL08BTTQixEnpu3gAAAFE"]
[Thu Sep 17 15:17:02.812802 2026] [security2:error] [pid 971102:tid 971347] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailer/.env"] [unique_id "aqxYzucL08BTTQixEnpu4QAAAHE"]
[Thu Sep 17 15:17:02.848044 2026] [security2:error] [pid 971102:tid 971304] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mailjet/.env"] [unique_id "aqxYzucL08BTTQixEnpu4gAAAEY"]
[Thu Sep 17 15:17:02.862240 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxYzucL08BTTQixEnpu4wAAAB4"]
[Thu Sep 17 15:17:02.870126 2026] [security2:error] [pid 971102:tid 971353] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mail/.env"] [unique_id "aqxYzucL08BTTQixEnpu5AAAAHc"]
[Thu Sep 17 15:17:02.881367 2026] [security2:error] [pid 971102:tid 971239] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/lib/.env"] [unique_id "aqxYzucL08BTTQixEnpu5gAAAAU"]
[Thu Sep 17 15:17:02.927238 2026] [security2:error] [pid 971102:tid 971360] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/email/.env"] [unique_id "aqxYzucL08BTTQixEnpu6QAAAH4"]
[Thu Sep 17 15:17:02.969172 2026] [security2:error] [pid 971102:tid 971256] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/brevo/.env"] [unique_id "aqxYzucL08BTTQixEnpu6wAAABY"]
[Thu Sep 17 15:17:02.988032 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/smtp/.env"] [unique_id "aqxYzucL08BTTQixEnpu7AAAAFQ"]
[Thu Sep 17 15:17:03.017101 2026] [security2:error] [pid 971102:tid 971350] [client 172.239.147.162:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxYz-cL08BTTQixEnpu7wAAAHQ"], referer: binance.com
[Thu Sep 17 15:17:03.031177 2026] [security2:error] [pid 971102:tid 971236] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxYz-cL08BTTQixEnpu8QAAAAI"]
[Thu Sep 17 15:17:03.043753 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailing/.env"] [unique_id "aqxYz-cL08BTTQixEnpu8wAAAAs"]
[Thu Sep 17 15:17:03.090409 2026] [security2:error] [pid 971102:tid 971354] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/transactional/.env"] [unique_id "aqxYz-cL08BTTQixEnpu9AAAAHg"]
[Thu Sep 17 15:17:03.097252 2026] [security2:error] [pid 971102:tid 971334] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/notifications/.env"] [unique_id "aqxYz-cL08BTTQixEnpu9QAAAGQ"]
[Thu Sep 17 15:17:03.116617 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/resources/.env"] [unique_id "aqxYz-cL08BTTQixEnpu9wAAAHk"]
[Thu Sep 17 15:17:03.146736 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/notify/.env"] [unique_id "aqxYz-cL08BTTQixEnpu-AAAADY"]
[Thu Sep 17 15:17:03.189906 2026] [security2:error] [pid 971102:tid 971322] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxYz-cL08BTTQixEnpu-gAAAFg"]
[Thu Sep 17 15:17:03.195276 2026] [security2:error] [pid 971102:tid 971278] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sender/.env"] [unique_id "aqxYz-cL08BTTQixEnpu-wAAACw"]
[Thu Sep 17 15:17:03.195651 2026] [security2:error] [pid 971102:tid 971336] [client 43.172.196.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxYz-cL08BTTQixEnpu8gAAAGY"]
[Thu Sep 17 15:17:03.210808 2026] [security2:error] [pid 971102:tid 971316] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/bulk/.env"] [unique_id "aqxYz-cL08BTTQixEnpu_AAAAFI"]
[Thu Sep 17 15:17:03.242643 2026] [security2:error] [pid 971102:tid 971253] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/campaign/.env"] [unique_id "aqxYz-cL08BTTQixEnpvAAAAABM"]
[Thu Sep 17 15:17:03.288579 2026] [security2:error] [pid 971102:tid 971260] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/newsletter/.env"] [unique_id "aqxYz-cL08BTTQixEnpvAwAAABo"]
[Thu Sep 17 15:17:03.331020 2026] [security2:error] [pid 971102:tid 971328] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/aws/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBAAAAF4"]
[Thu Sep 17 15:17:03.332921 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/ses/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBQAAACQ"]
[Thu Sep 17 15:17:03.345092 2026] [security2:error] [pid 971102:tid 971255] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBgAAABU"]
[Thu Sep 17 15:17:03.345406 2026] [security2:error] [pid 971102:tid 971327] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/assets/.env"] [unique_id "aqxYz-cL08BTTQixEnpvBwAAAF0"]
[Thu Sep 17 15:17:03.376255 2026] [security2:error] [pid 971102:tid 971345] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sendgrid/.env"] [unique_id "aqxYz-cL08BTTQixEnpvCAAAAG8"]
[Thu Sep 17 15:17:03.420647 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/sparkpost/.env"] [unique_id "aqxYz-cL08BTTQixEnpvCQAAAFo"]
[Thu Sep 17 15:17:03.450102 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/azure/.env"] [unique_id "aqxYz-cL08BTTQixEnpvCgAAAFw"]
[Thu Sep 17 15:17:03.473098 2026] [security2:error] [pid 971102:tid 971246] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/postmark/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDAAAAAw"]
[Thu Sep 17 15:17:03.499832 2026] [security2:error] [pid 971102:tid 971340] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDQAAAGo"]
[Thu Sep 17 15:17:03.523141 2026] [security2:error] [pid 971102:tid 971259] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailgun/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDgAAABk"]
[Thu Sep 17 15:17:03.571335 2026] [security2:error] [pid 971102:tid 971358] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/gcp/.env"] [unique_id "aqxYz-cL08BTTQixEnpvDwAAAHw"]
[Thu Sep 17 15:17:03.575934 2026] [security2:error] [pid 971102:tid 971329] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/uploads/.env"] [unique_id "aqxYz-cL08BTTQixEnpvEAAAAF8"]
[Thu Sep 17 15:17:03.576384 2026] [security2:error] [pid 971102:tid 971262] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mandrill/.env"] [unique_id "aqxYz-cL08BTTQixEnpvEQAAABw"]
[Thu Sep 17 15:17:03.626303 2026] [security2:error] [pid 971102:tid 971286] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mailjet/.env"] [unique_id "aqxYz-cL08BTTQixEnpvFQAAADQ"]
[Thu Sep 17 15:17:03.660792 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:40654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxYz-cL08BTTQixEnpvFwAAADM"]
[Thu Sep 17 15:17:03.680964 2026] [security2:error] [pid 971102:tid 971271] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/brevo/.env"] [unique_id "aqxYz-cL08BTTQixEnpvGAAAACU"]
[Thu Sep 17 15:17:03.695453 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cloud/.env"] [unique_id "aqxYz-cL08BTTQixEnpvGQAAAAQ"]
[Thu Sep 17 15:17:03.737995 2026] [security2:error] [pid 971102:tid 971351] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/transactional/.env"] [unique_id "aqxYz-cL08BTTQixEnpvGgAAAHU"]
[Thu Sep 17 15:17:03.784788 2026] [security2:error] [pid 971102:tid 971234] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/bulk/.env"] [unique_id "aqxYz-cL08BTTQixEnpvHQAAAAA"]
[Thu Sep 17 15:17:03.806307 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/internal/.env"] [unique_id "aqxYz-cL08BTTQixEnpvIAAAAD4"]
[Thu Sep 17 15:17:03.827765 2026] [security2:error] [pid 971102:tid 971250] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/aws/.env"] [unique_id "aqxYz-cL08BTTQixEnpvJAAAABA"]
[Thu Sep 17 15:17:03.844353 2026] [security2:error] [pid 971102:tid 971357] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/infrastructure/.env"] [unique_id "aqxYz-cL08BTTQixEnpvJQAAAHs"]
[Thu Sep 17 15:17:03.895506 2026] [security2:error] [pid 971102:tid 971343] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/azure/.env"] [unique_id "aqxYz-cL08BTTQixEnpvJgAAAG0"]
[Thu Sep 17 15:17:03.947421 2026] [security2:error] [pid 971102:tid 971292] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/gcp/.env"] [unique_id "aqxYz-cL08BTTQixEnpvKAAAADo"]
[Thu Sep 17 15:17:03.976486 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/docker/.env"] [unique_id "aqxYz-cL08BTTQixEnpvLAAAABE"]
[Thu Sep 17 15:17:04.001149 2026] [security2:error] [pid 971102:tid 971341] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cloud/.env"] [unique_id "aqxY0OcL08BTTQixEnpvLQAAAGs"]
[Thu Sep 17 15:17:04.041121 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/tools/.env"] [unique_id "aqxY0OcL08BTTQixEnpvLgAAAHc"]
[Thu Sep 17 15:17:04.053770 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/infrastructure/.env"] [unique_id "aqxY0OcL08BTTQixEnpvLwAAAGc"]
[Thu Sep 17 15:17:04.097907 2026] [security2:error] [pid 971102:tid 971244] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/k8s/.env"] [unique_id "aqxY0OcL08BTTQixEnpvMAAAAAo"]
[Thu Sep 17 15:17:04.107200 2026] [security2:error] [pid 971102:tid 971360] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/docker/.env"] [unique_id "aqxY0OcL08BTTQixEnpvMQAAAH4"]
[Thu Sep 17 15:17:04.159578 2026] [security2:error] [pid 971102:tid 971333] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/k8s/.env"] [unique_id "aqxY0OcL08BTTQixEnpvNAAAAGM"]
[Thu Sep 17 15:17:04.207348 2026] [security2:error] [pid 971102:tid 971318] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/kubernetes/.env"] [unique_id "aqxY0OcL08BTTQixEnpvNQAAAFQ"]
[Thu Sep 17 15:17:04.226952 2026] [security2:error] [pid 971102:tid 971287] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/kubernetes/.env"] [unique_id "aqxY0OcL08BTTQixEnpvNgAAADU"]
[Thu Sep 17 15:17:04.257461 2026] [security2:error] [pid 971102:tid 971295] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/terraform/.env"] [unique_id "aqxY0OcL08BTTQixEnpvOwAAAD0"]
[Thu Sep 17 15:17:04.278276 2026] [security2:error] [pid 971102:tid 971236] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/scripts/.env"] [unique_id "aqxY0OcL08BTTQixEnpvQQAAAAI"]
[Thu Sep 17 15:17:04.286998 2026] [security2:error] [pid 971102:tid 971252] [client 154.190.208.131:41793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvQAAAABI"]
[Thu Sep 17 15:17:04.287104 2026] [security2:error] [pid 971102:tid 971252] [client 154.190.208.131:41793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvQAAAABI"]
[Thu Sep 17 15:17:04.307909 2026] [security2:error] [pid 971102:tid 971354] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/ansible/.env"] [unique_id "aqxY0OcL08BTTQixEnpvQwAAAHg"]
[Thu Sep 17 15:17:04.327878 2026] [security2:error] [pid 971102:tid 971254] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRAAAABQ"]
[Thu Sep 17 15:17:04.352403 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/terraform/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRQAAAEQ"]
[Thu Sep 17 15:17:04.359027 2026] [security2:error] [pid 971102:tid 971332] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/.git/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRgAAAGI"]
[Thu Sep 17 15:17:04.410518 2026] [security2:error] [pid 971102:tid 971310] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/ci/.env"] [unique_id "aqxY0OcL08BTTQixEnpvRwAAAEw"]
[Thu Sep 17 15:17:04.477491 2026] [security2:error] [pid 971102:tid 971278] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/cd/.env"] [unique_id "aqxY0OcL08BTTQixEnpvSQAAACw"]
[Thu Sep 17 15:17:04.477491 2026] [security2:error] [pid 971102:tid 971322] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/ansible/.env"] [unique_id "aqxY0OcL08BTTQixEnpvSgAAAFg"]
[Thu Sep 17 15:17:04.484215 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxY0OcL08BTTQixEnpvSwAAAGY"]
[Thu Sep 17 15:17:04.512426 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bin/.env"] [unique_id "aqxY0OcL08BTTQixEnpvTAAAACY"]
[Thu Sep 17 15:17:04.528473 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/jenkins/.env"] [unique_id "aqxY0OcL08BTTQixEnpvTgAAADA"]
[Thu Sep 17 15:17:04.535872 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvTQAAAGQ"]
[Thu Sep 17 15:17:04.535944 2026] [security2:error] [pid 971102:tid 971334] [client 114.198.138.124:63587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0OcL08BTTQixEnpvTQAAAGQ"]
[Thu Sep 17 15:17:04.586087 2026] [security2:error] [pid 971102:tid 971301] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/gitlab/.env"] [unique_id "aqxY0OcL08BTTQixEnpvUAAAAEM"]
[Thu Sep 17 15:17:04.604288 2026] [security2:error] [pid 971102:tid 971235] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/.git/.env"] [unique_id "aqxY0OcL08BTTQixEnpvUgAAAAE"]
[Thu Sep 17 15:17:04.634543 2026] [security2:error] [pid 971102:tid 971260] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/github/.env"] [unique_id "aqxY0OcL08BTTQixEnpvVgAAABo"]
[Thu Sep 17 15:17:04.641530 2026] [security2:error] [pid 971102:tid 971303] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxY0OcL08BTTQixEnpvWAAAAEU"]
[Thu Sep 17 15:17:04.688504 2026] [security2:error] [pid 971102:tid 971319] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/actions/.env"] [unique_id "aqxY0OcL08BTTQixEnpvWgAAAFU"]
[Thu Sep 17 15:17:04.726586 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/ci/.env"] [unique_id "aqxY0OcL08BTTQixEnpvXQAAAGw"]
[Thu Sep 17 15:17:04.732878 2026] [security2:error] [pid 971102:tid 971280] [client 172.239.147.162:57580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxY0OcL08BTTQixEnpvXgAAAC4"], referer: binance.com
[Thu Sep 17 15:17:04.736077 2026] [security2:error] [pid 971102:tid 971345] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/circleci/.env"] [unique_id "aqxY0OcL08BTTQixEnpvXwAAAG8"]
[Thu Sep 17 15:17:04.742275 2026] [security2:error] [pid 971102:tid 971257] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sbin/.env"] [unique_id "aqxY0OcL08BTTQixEnpvYAAAABc"]
[Thu Sep 17 15:17:04.787570 2026] [security2:error] [pid 971102:tid 971305] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/travis/.env"] [unique_id "aqxY0OcL08BTTQixEnpvYwAAAEc"]
[Thu Sep 17 15:17:04.794438 2026] [security2:error] [pid 971102:tid 971324] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxY0OcL08BTTQixEnpvZAAAAFo"]
[Thu Sep 17 15:17:04.847431 2026] [security2:error] [pid 971102:tid 971330] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/buildkite/.env"] [unique_id "aqxY0OcL08BTTQixEnpvZgAAAGA"]
[Thu Sep 17 15:17:04.855460 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/cd/.env"] [unique_id "aqxY0OcL08BTTQixEnpvZwAAAAM"]
[Thu Sep 17 15:17:04.903724 2026] [security2:error] [pid 971102:tid 971346] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mysql/.env"] [unique_id "aqxY0OcL08BTTQixEnpvaAAAAHA"]
[Thu Sep 17 15:17:04.950348 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxY0OcL08BTTQixEnpvagAAACU"]
[Thu Sep 17 15:17:04.976506 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/local/.env"] [unique_id "aqxY0OcL08BTTQixEnpvawAAABs"]
[Thu Sep 17 15:17:04.976684 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/postgres/.env"] [unique_id "aqxY0OcL08BTTQixEnpvbAAAAEE"]
[Thu Sep 17 15:17:04.988789 2026] [security2:error] [pid 971102:tid 971238] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/jenkins/.env"] [unique_id "aqxY0OcL08BTTQixEnpvbgAAAAQ"]
[Thu Sep 17 15:17:05.021552 2026] [security2:error] [pid 971102:tid 971269] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/mongodb/.env"] [unique_id "aqxY0ecL08BTTQixEnpvcgAAACM"]
[Thu Sep 17 15:17:05.074555 2026] [security2:error] [pid 971102:tid 971296] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/redis/.env"] [unique_id "aqxY0ecL08BTTQixEnpvcwAAAD4"]
[Thu Sep 17 15:17:05.105269 2026] [security2:error] [pid 971102:tid 971250] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxY0ecL08BTTQixEnpvdAAAABA"]
[Thu Sep 17 15:17:05.107441 2026] [fcgid:warn] [pid 971102:tid 971263] (70014)End of file found: [client 118.193.32.119:33584] mod_fcgid: can't get data from http client
[Thu Sep 17 15:17:05.122738 2026] [security2:error] [pid 971102:tid 971331] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/elasticsearch/.env"] [unique_id "aqxY0ecL08BTTQixEnpvdgAAAGE"]
[Thu Sep 17 15:17:05.132362 2026] [security2:error] [pid 971102:tid 971343] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/gitlab/.env"] [unique_id "aqxY0ecL08BTTQixEnpvdwAAAG0"]
[Thu Sep 17 15:17:05.183065 2026] [security2:error] [pid 971102:tid 971251] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/rabbitmq/.env"] [unique_id "aqxY0ecL08BTTQixEnpvegAAABE"]
[Thu Sep 17 15:17:05.208915 2026] [security2:error] [pid 971102:tid 971273] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/portal/.env"] [unique_id "aqxY0ecL08BTTQixEnpvewAAACc"]
[Thu Sep 17 15:17:05.226355 2026] [security2:error] [pid 971102:tid 971242] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/kafka/.env"] [unique_id "aqxY0ecL08BTTQixEnpvfAAAAAg"]
[Thu Sep 17 15:17:05.257321 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxY0ecL08BTTQixEnpvfgAAAB4"]
[Thu Sep 17 15:17:05.263863 2026] [security2:error] [pid 971102:tid 971304] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/github/.env"] [unique_id "aqxY0ecL08BTTQixEnpvfwAAAEY"]
[Thu Sep 17 15:17:05.278845 2026] [security2:error] [pid 971102:tid 971353] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/queue/.env"] [unique_id "aqxY0ecL08BTTQixEnpvgAAAAHc"]
[Thu Sep 17 15:17:05.338042 2026] [security2:error] [pid 971102:tid 971337] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/worker/.env"] [unique_id "aqxY0ecL08BTTQixEnpvggAAAGc"]
[Thu Sep 17 15:17:05.386097 2026] [security2:error] [pid 971102:tid 971300] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/actions/.env"] [unique_id "aqxY0ecL08BTTQixEnpvgwAAAEI"]
[Thu Sep 17 15:17:05.394138 2026] [security2:error] [pid 971102:tid 971333] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/job/.env"] [unique_id "aqxY0ecL08BTTQixEnpvhAAAAGM"]
[Thu Sep 17 15:17:05.409396 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxY0ecL08BTTQixEnpvhgAAADU"]
[Thu Sep 17 15:17:05.445913 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/test/.env"] [unique_id "aqxY0ecL08BTTQixEnpviAAAAAs"]
[Thu Sep 17 15:17:05.445913 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dashboard/.env"] [unique_id "aqxY0ecL08BTTQixEnpvhwAAABI"]
[Thu Sep 17 15:17:05.498004 2026] [security2:error] [pid 971102:tid 971339] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/qa/.env"] [unique_id "aqxY0ecL08BTTQixEnpvjAAAAGk"]
[Thu Sep 17 15:17:05.529063 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/circleci/.env"] [unique_id "aqxY0ecL08BTTQixEnpvjQAAAC0"]
[Thu Sep 17 15:17:05.548888 2026] [security2:error] [pid 971102:tid 971240] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/preview/.env"] [unique_id "aqxY0ecL08BTTQixEnpvjgAAAAY"]
[Thu Sep 17 15:17:05.555126 2026] [security2:error] [pid 971102:tid 971244] [client 172.239.147.162:55584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxY0ecL08BTTQixEnpvjwAAAAo"], referer: binance.com
[Thu Sep 17 15:17:05.566314 2026] [security2:error] [pid 971102:tid 971352] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxY0ecL08BTTQixEnpvkAAAAHY"]
[Thu Sep 17 15:17:05.599230 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/beta/.env"] [unique_id "aqxY0ecL08BTTQixEnpvkgAAAEg"]
[Thu Sep 17 15:17:05.646251 2026] [security2:error] [pid 971102:tid 971309] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/uat/.env"] [unique_id "aqxY0ecL08BTTQixEnpvkwAAAEs"]
[Thu Sep 17 15:17:05.668310 2026] [security2:error] [pid 971102:tid 971322] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/travis/.env"] [unique_id "aqxY0ecL08BTTQixEnpvlQAAAFg"]
[Thu Sep 17 15:17:05.681209 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/panel/.env"] [unique_id "aqxY0ecL08BTTQixEnpvlgAAACw"]
[Thu Sep 17 15:17:05.686074 2026] [security2:error] [pid 971102:tid 971348] [client 186.105.232.15:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0ecL08BTTQixEnpvlwAAAHI"]
[Thu Sep 17 15:17:05.686176 2026] [security2:error] [pid 971102:tid 971348] [client 186.105.232.15:53296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0ecL08BTTQixEnpvlwAAAHI"]
[Thu Sep 17 15:17:05.694654 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/stage/.env"] [unique_id "aqxY0ecL08BTTQixEnpvmAAAAGY"]
[Thu Sep 17 15:17:05.719212 2026] [security2:error] [pid 971102:tid 971272] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxY0ecL08BTTQixEnpvmQAAACY"]
[Thu Sep 17 15:17:05.740219 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/development/.env"] [unique_id "aqxY0ecL08BTTQixEnpvmgAAADA"]
[Thu Sep 17 15:17:05.794043 2026] [security2:error] [pid 971102:tid 971253] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/production/.env"] [unique_id "aqxY0ecL08BTTQixEnpvpgAAABM"]
[Thu Sep 17 15:17:05.801799 2026] [security2:error] [pid 971102:tid 971235] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/buildkite/.env"] [unique_id "aqxY0ecL08BTTQixEnpvpwAAAAE"]
[Thu Sep 17 15:17:05.837524 2026] [security2:error] [pid 971102:tid 971303] [client 35.202.49.146:42104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.geekngamer.com"] [uri "/config/app/.env"] [unique_id "aqxY0ecL08BTTQixEnpvuAAAAEU"]
[Thu Sep 17 15:17:05.872916 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxY0ecL08BTTQixEnpvuQAAACQ"]
[Thu Sep 17 15:17:05.895054 2026] [security2:error] [pid 971102:tid 971288] [client 35.202.49.146:42104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php"] [unique_id "aqxY0ecL08BTTQixEnpvugAAADY"]
[Thu Sep 17 15:17:05.911477 2026] [security2:error] [pid 971102:tid 971319] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/crm/.env"] [unique_id "aqxY0ecL08BTTQixEnpvuwAAAFU"]
[Thu Sep 17 15:17:05.922726 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mysql/.env"] [unique_id "aqxY0ecL08BTTQixEnpvvgAAAGw"]
[Thu Sep 17 15:17:06.026902 2026] [security2:error] [pid 971102:tid 971276] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxY0ucL08BTTQixEnpvzAAAACo"]
[Thu Sep 17 15:17:06.042837 2026] [security2:error] [pid 971102:tid 971330] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/postgres/.env"] [unique_id "aqxY0ucL08BTTQixEnpvzQAAAGA"]
[Thu Sep 17 15:17:06.063634 2026] [security2:error] [pid 971102:tid 971256] [client 8.29.0.172:58301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY0ecL08BTTQixEnpvvwAAFik"]
[Thu Sep 17 15:17:06.071864 2026] [security2:error] [pid 971102:tid 971290] [client 35.202.49.146:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/info.php"] [unique_id "aqxY0ucL08BTTQixEnpvzwAAADg"]
[Thu Sep 17 15:17:06.140333 2026] [security2:error] [pid 971102:tid 971358] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/erp/.env"] [unique_id "aqxY0ucL08BTTQixEnpv2QAAAHw"]
[Thu Sep 17 15:17:06.161484 2026] [security2:error] [pid 971102:tid 971294] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/mongodb/.env"] [unique_id "aqxY0ucL08BTTQixEnpv4wAAADw"]
[Thu Sep 17 15:17:06.178449 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxY0ucL08BTTQixEnpv5QAAADM"]
[Thu Sep 17 15:17:06.211706 2026] [security2:error] [pid 971102:tid 971241] [client 35.202.49.146:35246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/php.php"] [unique_id "aqxY0ucL08BTTQixEnpv6AAAAAc"]
[Thu Sep 17 15:17:06.292299 2026] [security2:error] [pid 971102:tid 971263] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/redis/.env"] [unique_id "aqxY0ucL08BTTQixEnpv7gAAAB0"]
[Thu Sep 17 15:17:06.332022 2026] [security2:error] [pid 971102:tid 971343] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxY0ucL08BTTQixEnpv8AAAAG0"]
[Thu Sep 17 15:17:06.369872 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shop/.env"] [unique_id "aqxY0ucL08BTTQixEnpv8gAAAHU"]
[Thu Sep 17 15:17:06.397848 2026] [security2:error] [pid 971102:tid 971283] [client 35.202.49.146:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/i.php"] [unique_id "aqxY0ucL08BTTQixEnpv9AAAADE"]
[Thu Sep 17 15:17:06.421686 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/elasticsearch/.env"] [unique_id "aqxY0ucL08BTTQixEnpv-AAAAHc"]
[Thu Sep 17 15:17:06.485011 2026] [security2:error] [pid 971102:tid 971307] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxY0ucL08BTTQixEnpwCAAAAEk"]
[Thu Sep 17 15:17:06.531046 2026] [security2:error] [pid 971102:tid 971333] [client 35.202.49.146:35256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/pi.php"] [unique_id "aqxY0ucL08BTTQixEnpwCwAAAGM"]
[Thu Sep 17 15:17:06.549476 2026] [security2:error] [pid 971102:tid 971310] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/rabbitmq/.env"] [unique_id "aqxY0ucL08BTTQixEnpwDAAAAEw"]
[Thu Sep 17 15:17:06.605489 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/store/.env"] [unique_id "aqxY0ucL08BTTQixEnpwDQAAAHY"]
[Thu Sep 17 15:17:06.638024 2026] [security2:error] [pid 971102:tid 971318] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxY0ucL08BTTQixEnpwDgAAAFQ"]
[Thu Sep 17 15:17:06.669817 2026] [security2:error] [pid 971102:tid 971309] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/kafka/.env"] [unique_id "aqxY0ucL08BTTQixEnpwEQAAAEs"]
[Thu Sep 17 15:17:06.674219 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:35262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/pinfo.php"] [unique_id "aqxY0ucL08BTTQixEnpwEgAAAEg"]
[Thu Sep 17 15:17:06.777995 2026] [security2:error] [pid 971102:tid 971339] [client 172.239.147.162:49980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxY0ucL08BTTQixEnpwEwAAAGk"], referer: binance.com
[Thu Sep 17 15:17:06.790790 2026] [security2:error] [pid 971102:tid 971334] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxY0ucL08BTTQixEnpwFAAAAGQ"]
[Thu Sep 17 15:17:06.791340 2026] [security2:error] [pid 971102:tid 971335] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/queue/.env"] [unique_id "aqxY0ucL08BTTQixEnpwFQAAAGU"]
[Thu Sep 17 15:17:06.821009 2026] [security2:error] [pid 971102:tid 971282] [client 35.202.49.146:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/test.php"] [unique_id "aqxY0ucL08BTTQixEnpwFgAAADA"]
[Thu Sep 17 15:17:06.840698 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/saas/.env"] [unique_id "aqxY0ucL08BTTQixEnpwGAAAAGg"]
[Thu Sep 17 15:17:06.939715 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/worker/.env"] [unique_id "aqxY0ucL08BTTQixEnpwGQAAAEM"]
[Thu Sep 17 15:17:06.952280 2026] [security2:error] [pid 971102:tid 971268] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxY0ucL08BTTQixEnpwGwAAACI"]
[Thu Sep 17 15:17:06.995407 2026] [security2:error] [pid 971102:tid 971260] [client 35.202.49.146:35288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY0ucL08BTTQixEnpwHgAAABo"]
[Thu Sep 17 15:17:07.058295 2026] [security2:error] [pid 971102:tid 971327] [client 35.202.49.146:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/p.php"] [unique_id "aqxY0-cL08BTTQixEnpwIwAAAF0"]
[Thu Sep 17 15:17:07.062567 2026] [security2:error] [pid 971102:tid 971345] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/job/.env"] [unique_id "aqxY0-cL08BTTQixEnpwJAAAAG8"]
[Thu Sep 17 15:17:07.073572 2026] [security2:error] [pid 971102:tid 971289] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/client/.env"] [unique_id "aqxY0-cL08BTTQixEnpwJQAAADc"]
[Thu Sep 17 15:17:07.105512 2026] [security2:error] [pid 971102:tid 971324] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxY0-cL08BTTQixEnpwJwAAAFo"]
[Thu Sep 17 15:17:07.189120 2026] [security2:error] [pid 971102:tid 971259] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/test/.env"] [unique_id "aqxY0-cL08BTTQixEnpwKwAAABk"]
[Thu Sep 17 15:17:07.208124 2026] [security2:error] [pid 971102:tid 971290] [client 35.202.49.146:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/debug.php"] [unique_id "aqxY0-cL08BTTQixEnpwLAAAADg"]
[Thu Sep 17 15:17:07.262477 2026] [security2:error] [pid 971102:tid 971350] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxY0-cL08BTTQixEnpwLgAAAHQ"]
[Thu Sep 17 15:17:07.314613 2026] [security2:error] [pid 971102:tid 971326] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/qa/.env"] [unique_id "aqxY0-cL08BTTQixEnpwLwAAAFw"]
[Thu Sep 17 15:17:07.318813 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/project/.env"] [unique_id "aqxY0-cL08BTTQixEnpwMAAAABs"]
[Thu Sep 17 15:17:07.365322 2026] [security2:error] [pid 971102:tid 971238] [client 35.202.49.146:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwNAAAAAQ"]
[Thu Sep 17 15:17:07.435743 2026] [security2:error] [pid 971102:tid 971314] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/preview/.env"] [unique_id "aqxY0-cL08BTTQixEnpwOAAAAFA"]
[Thu Sep 17 15:17:07.436007 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxY0-cL08BTTQixEnpwOQAAAHU"]
[Thu Sep 17 15:17:07.526085 2026] [security2:error] [pid 971102:tid 971320] [client 35.202.49.146:35314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/test/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwQAAAAFY"]
[Thu Sep 17 15:17:07.552240 2026] [security2:error] [pid 971102:tid 971355] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/admin-panel/.env"] [unique_id "aqxY0-cL08BTTQixEnpwQQAAAHk"]
[Thu Sep 17 15:17:07.556810 2026] [security2:error] [pid 971102:tid 971341] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/beta/.env"] [unique_id "aqxY0-cL08BTTQixEnpwQgAAAGs"]
[Thu Sep 17 15:17:07.562867 2026] [security2:error] [pid 971102:tid 971305] [client 8.29.0.172:44045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY0-cL08BTTQixEnpwPAAAR0I"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260615191631&hideliu=1&hideminor=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:17:07.593485 2026] [security2:error] [pid 971102:tid 971251] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxY0-cL08BTTQixEnpwRAAAABE"]
[Thu Sep 17 15:17:07.665019 2026] [security2:error] [pid 971102:tid 971249] [client 35.202.49.146:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwRQAAAA8"]
[Thu Sep 17 15:17:07.677422 2026] [security2:error] [pid 971102:tid 971255] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/uat/.env"] [unique_id "aqxY0-cL08BTTQixEnpwRgAAABU"]
[Thu Sep 17 15:17:07.736644 2026] [security2:error] [pid 971102:tid 971262] [client 185.46.77.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxY0ucL08BTTQixEnpv4gAAABw"], referer: https://kidsandlifeot.com/
[Thu Sep 17 15:17:07.745862 2026] [security2:error] [pid 971102:tid 971279] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxY0-cL08BTTQixEnpwSQAAAC0"]
[Thu Sep 17 15:17:07.786485 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/control-panel/.env"] [unique_id "aqxY0-cL08BTTQixEnpwSgAAAHY"]
[Thu Sep 17 15:17:07.807778 2026] [security2:error] [pid 971102:tid 971318] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/stage/.env"] [unique_id "aqxY0-cL08BTTQixEnpwSwAAAFQ"]
[Thu Sep 17 15:17:07.835371 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:35326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/old/phpinfo.php"] [unique_id "aqxY0-cL08BTTQixEnpwTAAAAAo"]
[Thu Sep 17 15:17:07.906237 2026] [security2:error] [pid 971102:tid 971278] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxY0-cL08BTTQixEnpwTgAAACw"]
[Thu Sep 17 15:17:07.938313 2026] [security2:error] [pid 971102:tid 971252] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/development/.env"] [unique_id "aqxY0-cL08BTTQixEnpwUQAAABI"]
[Thu Sep 17 15:17:07.974163 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:50093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0-cL08BTTQixEnpwUgAAAAg"]
[Thu Sep 17 15:17:07.975526 2026] [security2:error] [pid 971102:tid 971242] [client 156.192.234.52:50093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY0-cL08BTTQixEnpwUgAAAAg"]
[Thu Sep 17 15:17:08.019451 2026] [security2:error] [pid 971102:tid 971336] [client 35.202.49.146:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwVQAAAGY"]
[Thu Sep 17 15:17:08.021366 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/user-panel/.env"] [unique_id "aqxY1OcL08BTTQixEnpwVgAAADA"]
[Thu Sep 17 15:17:08.062699 2026] [security2:error] [pid 971102:tid 971299] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxY1OcL08BTTQixEnpwWQAAAEE"]
[Thu Sep 17 15:17:08.064225 2026] [security2:error] [pid 971102:tid 971338] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/production/.env"] [unique_id "aqxY1OcL08BTTQixEnpwWgAAAGg"]
[Thu Sep 17 15:17:08.188675 2026] [security2:error] [pid 971102:tid 971317] [client 34.97.30.29:57602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ahmedteleb.com"] [uri "/config/app/.env"] [unique_id "aqxY1OcL08BTTQixEnpwWwAAAFM"]
[Thu Sep 17 15:17:08.191156 2026] [security2:error] [pid 971102:tid 971253] [client 35.202.49.146:35338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/public/phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwXAAAABM"]
[Thu Sep 17 15:17:08.214822 2026] [security2:error] [pid 971102:tid 971289] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxY1OcL08BTTQixEnpwYAAAADc"]
[Thu Sep 17 15:17:08.254853 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/node/.env"] [unique_id "aqxY1OcL08BTTQixEnpwYQAAADg"]
[Thu Sep 17 15:17:08.325696 2026] [security2:error] [pid 971102:tid 971247] [client 34.97.30.29:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwYwAAAA0"]
[Thu Sep 17 15:17:08.333750 2026] [security2:error] [pid 971102:tid 971319] [client 35.202.49.146:35350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY1OcL08BTTQixEnpwZAAAAFU"]
[Thu Sep 17 15:17:08.368834 2026] [security2:error] [pid 971102:tid 971344] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxY1OcL08BTTQixEnpwZQAAAG4"]
[Thu Sep 17 15:17:08.379593 2026] [security2:error] [pid 971102:tid 971270] [client 35.202.49.146:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/php-info.php"] [unique_id "aqxY1OcL08BTTQixEnpwZwAAACQ"]
[Thu Sep 17 15:17:08.488762 2026] [security2:error] [pid 971102:tid 971286] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/express/.env"] [unique_id "aqxY1OcL08BTTQixEnpwaAAAADQ"]
[Thu Sep 17 15:17:08.522296 2026] [security2:error] [pid 971102:tid 971346] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxY1OcL08BTTQixEnpwawAAAHA"]
[Thu Sep 17 15:17:08.548179 2026] [security2:error] [pid 971102:tid 971285] [client 35.202.49.146:35360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpversion.php"] [unique_id "aqxY1OcL08BTTQixEnpwbwAAADM"]
[Thu Sep 17 15:17:08.677225 2026] [security2:error] [pid 971102:tid 971243] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxY1OcL08BTTQixEnpwcwAAAAk"]
[Thu Sep 17 15:17:08.705797 2026] [security2:error] [pid 971102:tid 971237] [client 35.202.49.146:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/_phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpwdAAAAAM"]
[Thu Sep 17 15:17:08.714067 2026] [security2:error] [pid 971102:tid 971261] [client 34.97.30.29:42442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/info.php"] [unique_id "aqxY1OcL08BTTQixEnpwdgAAABs"]
[Thu Sep 17 15:17:08.723598 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/next/.env"] [unique_id "aqxY1OcL08BTTQixEnpwdwAAAB0"]
[Thu Sep 17 15:17:08.835332 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxY1OcL08BTTQixEnpweAAAAB4"]
[Thu Sep 17 15:17:08.862342 2026] [security2:error] [pid 971102:tid 971314] [client 35.202.49.146:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/old_phpinfo.php"] [unique_id "aqxY1OcL08BTTQixEnpweQAAAFA"]
[Thu Sep 17 15:17:08.949268 2026] [security2:error] [pid 971102:tid 971331] [client 172.239.147.162:57475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxY1OcL08BTTQixEnpwfAAAAGE"], referer: binance.com
[Thu Sep 17 15:17:08.958221 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/nuxt/.env"] [unique_id "aqxY1OcL08BTTQixEnpwfwAAAGs"]
[Thu Sep 17 15:17:08.991362 2026] [security2:error] [pid 971102:tid 971251] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxY1OcL08BTTQixEnpwgQAAABE"]
[Thu Sep 17 15:17:09.038379 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/server-info.php"] [unique_id "aqxY1ecL08BTTQixEnpwggAAAE4"]
[Thu Sep 17 15:17:09.090972 2026] [security2:error] [pid 971102:tid 971277] [client 34.97.30.29:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/php.php"] [unique_id "aqxY1ecL08BTTQixEnpwhQAAACs"]
[Thu Sep 17 15:17:09.147137 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxY1ecL08BTTQixEnpwhgAAADU"]
[Thu Sep 17 15:17:09.190137 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/nest/.env"] [unique_id "aqxY1ecL08BTTQixEnpwhwAAAAs"]
[Thu Sep 17 15:17:09.196498 2026] [security2:error] [pid 971102:tid 971295] [client 35.202.49.146:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/server-status.php"] [unique_id "aqxY1ecL08BTTQixEnpwiAAAAD0"]
[Thu Sep 17 15:17:09.300208 2026] [security2:error] [pid 971102:tid 971354] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxY1ecL08BTTQixEnpwigAAAHg"]
[Thu Sep 17 15:17:09.363713 2026] [security2:error] [pid 971102:tid 971254] [client 35.202.49.146:35404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY1ecL08BTTQixEnpwiwAAABQ"]
[Thu Sep 17 15:17:09.419931 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/react/.env"] [unique_id "aqxY1ecL08BTTQixEnpwjgAAADI"]
[Thu Sep 17 15:17:09.452415 2026] [security2:error] [pid 971102:tid 971318] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxY1ecL08BTTQixEnpwkQAAAFQ"]
[Thu Sep 17 15:17:09.457774 2026] [security2:error] [pid 971102:tid 971244] [client 35.202.49.146:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY1ecL08BTTQixEnpwkgAAAAo"]
[Thu Sep 17 15:17:09.462781 2026] [security2:error] [pid 971102:tid 971321] [client 34.97.30.29:42464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/i.php"] [unique_id "aqxY1ecL08BTTQixEnpwkwAAAFc"]
[Thu Sep 17 15:17:09.590136 2026] [security2:error] [pid 971102:tid 971278] [client 35.202.49.146:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxY1ecL08BTTQixEnpwlgAAACw"]
[Thu Sep 17 15:17:09.595293 2026] [security2:error] [pid 971102:tid 971361] [client 172.239.147.162:50221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxY1ecL08BTTQixEnpwlwAAAH8"], referer: binance.com
[Thu Sep 17 15:17:09.609003 2026] [security2:error] [pid 971102:tid 971349] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxY1ecL08BTTQixEnpwmQAAAHM"]
[Thu Sep 17 15:17:09.649788 2026] [security2:error] [pid 971102:tid 971315] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vue/.env"] [unique_id "aqxY1ecL08BTTQixEnpwmgAAAFE"]
[Thu Sep 17 15:17:09.741854 2026] [security2:error] [pid 971102:tid 971335] [client 35.202.49.146:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY1ecL08BTTQixEnpwnAAAAGU"]
[Thu Sep 17 15:17:09.766163 2026] [security2:error] [pid 971102:tid 971299] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxY1ecL08BTTQixEnpwnQAAAEE"]
[Thu Sep 17 15:17:09.852897 2026] [security2:error] [pid 971102:tid 971336] [client 34.97.30.29:42476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/pi.php"] [unique_id "aqxY1ecL08BTTQixEnpwnwAAAGY"]
[Thu Sep 17 15:17:09.878974 2026] [security2:error] [pid 971102:tid 971301] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/angular/.env"] [unique_id "aqxY1ecL08BTTQixEnpwoQAAAEM"]
[Thu Sep 17 15:17:09.904889 2026] [security2:error] [pid 971102:tid 971325] [client 35.202.49.146:35428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY1ecL08BTTQixEnpwpQAAAFs"]
[Thu Sep 17 15:17:09.929714 2026] [security2:error] [pid 971102:tid 971311] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxY1ecL08BTTQixEnpwpgAAAE0"]
[Thu Sep 17 15:17:09.931818 2026] [security2:error] [pid 971102:tid 971317] [client 127.0.0.1:60206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxY1ecL08BTTQixEnpwpAAAAFM"]
[Thu Sep 17 15:17:09.931908 2026] [security2:error] [pid 971102:tid 971256] [client 74.7.241.158:42994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wtff.net"] [uri "/robots.txt"] [unique_id "aqxY1ecL08BTTQixEnpwogAAFjI"]
[Thu Sep 17 15:17:10.052779 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY1ucL08BTTQixEnpwqgAAAFo"]
[Thu Sep 17 15:17:10.084183 2026] [security2:error] [pid 971102:tid 971340] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxY1ucL08BTTQixEnpwrQAAAGo"]
[Thu Sep 17 15:17:10.107766 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/svelte/.env"] [unique_id "aqxY1ucL08BTTQixEnpwrgAAAA0"]
[Thu Sep 17 15:17:10.212381 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:35442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY1ucL08BTTQixEnpwsgAAAHw"]
[Thu Sep 17 15:17:10.245555 2026] [security2:error] [pid 971102:tid 971345] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxY1ucL08BTTQixEnpwtAAAAG8"]
[Thu Sep 17 15:17:10.281533 2026] [security2:error] [pid 971102:tid 971344] [client 34.97.30.29:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/pinfo.php"] [unique_id "aqxY1ucL08BTTQixEnpwtQAAAG4"]
[Thu Sep 17 15:17:10.337554 2026] [security2:error] [pid 971102:tid 971243] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vite/.env"] [unique_id "aqxY1ucL08BTTQixEnpwtwAAAAk"]
[Thu Sep 17 15:17:10.378231 2026] [security2:error] [pid 971102:tid 971250] [client 35.202.49.146:35448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxY1ucL08BTTQixEnpwuAAAABA"]
[Thu Sep 17 15:17:10.398071 2026] [security2:error] [pid 971102:tid 971269] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxY1ucL08BTTQixEnpwuQAAACM"]
[Thu Sep 17 15:17:10.507030 2026] [security2:error] [pid 971102:tid 971238] [client 172.239.147.162:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxY1ucL08BTTQixEnpwwwAAAAQ"], referer: binance.com
[Thu Sep 17 15:17:10.535831 2026] [security2:error] [pid 971102:tid 971281] [client 35.202.49.146:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php.old"] [unique_id "aqxY1ucL08BTTQixEnpwxQAAAC8"]
[Thu Sep 17 15:17:10.553103 2026] [security2:error] [pid 971102:tid 971331] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxY1ucL08BTTQixEnpwxwAAAGE"]
[Thu Sep 17 15:17:10.582404 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backup/.env"] [unique_id "aqxY1ucL08BTTQixEnpwyAAAAEc"]
[Thu Sep 17 15:17:10.682859 2026] [security2:error] [pid 971102:tid 971236] [client 34.97.30.29:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/test.php"] [unique_id "aqxY1ucL08BTTQixEnpwygAAAAI"]
[Thu Sep 17 15:17:10.710026 2026] [security2:error] [pid 971102:tid 971337] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxY1ucL08BTTQixEnpwywAAAGc"]
[Thu Sep 17 15:17:10.716678 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:35480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php~"] [unique_id "aqxY1ucL08BTTQixEnpwzAAAAE4"]
[Thu Sep 17 15:17:10.817348 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backups/.env"] [unique_id "aqxY1ucL08BTTQixEnpwzgAAAAA"]
[Thu Sep 17 15:17:10.862641 2026] [security2:error] [pid 971102:tid 971307] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxY1ucL08BTTQixEnpwzwAAAEk"]
[Thu Sep 17 15:17:10.870759 2026] [security2:error] [pid 971102:tid 971245] [client 35.202.49.146:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/info.php.bak"] [unique_id "aqxY1ucL08BTTQixEnpw0AAAAAs"]
[Thu Sep 17 15:17:11.014872 2026] [security2:error] [pid 971102:tid 971353] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxY1-cL08BTTQixEnpw1wAAAHc"]
[Thu Sep 17 15:17:11.026440 2026] [security2:error] [pid 971102:tid 971357] [client 35.202.49.146:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/phpinfo.php.save"] [unique_id "aqxY1-cL08BTTQixEnpw2AAAAHs"]
[Thu Sep 17 15:17:11.051873 2026] [security2:error] [pid 971102:tid 971318] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/old/.env"] [unique_id "aqxY1-cL08BTTQixEnpw2QAAAFQ"]
[Thu Sep 17 15:17:11.172833 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxY1-cL08BTTQixEnpw3QAAAH8"]
[Thu Sep 17 15:17:11.175747 2026] [security2:error] [pid 971102:tid 971252] [client 35.202.49.146:35514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw3gAAABI"]
[Thu Sep 17 15:17:11.209035 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY1-cL08BTTQixEnpw4AAAAE8"]
[Thu Sep 17 15:17:11.209143 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY1-cL08BTTQixEnpw4AAAAE8"]
[Thu Sep 17 15:17:11.287554 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/tmp/.env"] [unique_id "aqxY1-cL08BTTQixEnpw5AAAAGU"]
[Thu Sep 17 15:17:11.300515 2026] [security2:error] [pid 971102:tid 971322] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY1-cL08BTTQixEnpw3wAAAFg"]
[Thu Sep 17 15:17:11.327405 2026] [security2:error] [pid 971102:tid 971235] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxY1-cL08BTTQixEnpw5gAAAAE"]
[Thu Sep 17 15:17:11.345334 2026] [security2:error] [pid 971102:tid 971299] [client 35.202.49.146:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw6AAAAEE"]
[Thu Sep 17 15:17:11.492886 2026] [security2:error] [pid 971102:tid 971247] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxY1-cL08BTTQixEnpw8AAAAA0"]
[Thu Sep 17 15:17:11.515908 2026] [security2:error] [pid 971102:tid 971324] [client 35.202.49.146:35524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw8gAAAFo"]
[Thu Sep 17 15:17:11.524137 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/temp/.env"] [unique_id "aqxY1-cL08BTTQixEnpw8wAAAG8"]
[Thu Sep 17 15:17:11.575547 2026] [security2:error] [pid 971102:tid 971243] [client 34.97.30.29:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/p.php"] [unique_id "aqxY1-cL08BTTQixEnpw9gAAAAk"]
[Thu Sep 17 15:17:11.655817 2026] [security2:error] [pid 971102:tid 971319] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxY1-cL08BTTQixEnpw-AAAAFU"]
[Thu Sep 17 15:17:11.686503 2026] [security2:error] [pid 971102:tid 971263] [client 35.202.49.146:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpw-gAAAB0"]
[Thu Sep 17 15:17:11.766250 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/lab/.env"] [unique_id "aqxY1-cL08BTTQixEnpw_QAAADs"]
[Thu Sep 17 15:17:11.819368 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxY1-cL08BTTQixEnpxAAAAAB4"]
[Thu Sep 17 15:17:11.835714 2026] [security2:error] [pid 971102:tid 971236] [client 35.202.49.146:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxY1-cL08BTTQixEnpxAQAAAAI"]
[Thu Sep 17 15:17:11.865318 2026] [security2:error] [pid 971102:tid 971326] [client 172.239.147.162:50027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxY1-cL08BTTQixEnpxBAAAAFw"], referer: binance.com
[Thu Sep 17 15:17:11.971927 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:42512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/debug.php"] [unique_id "aqxY1-cL08BTTQixEnpxBwAAAGw"]
[Thu Sep 17 15:17:11.976115 2026] [security2:error] [pid 971102:tid 971275] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxY1-cL08BTTQixEnpxCAAAACk"]
[Thu Sep 17 15:17:12.000985 2026] [security2:error] [pid 971102:tid 971297] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cronlab/.env"] [unique_id "aqxY1-cL08BTTQixEnpxCwAAAD8"]
[Thu Sep 17 15:17:12.009904 2026] [security2:error] [pid 971102:tid 971276] [client 35.202.49.146:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/www/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxDAAAACo"]
[Thu Sep 17 15:17:12.128807 2026] [security2:error] [pid 971102:tid 971356] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxY2OcL08BTTQixEnpxEAAAAHo"]
[Thu Sep 17 15:17:12.169765 2026] [security2:error] [pid 971102:tid 971279] [client 35.202.49.146:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxEgAAAC0"]
[Thu Sep 17 15:17:12.236151 2026] [security2:error] [pid 971102:tid 971310] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cron/.env"] [unique_id "aqxY2OcL08BTTQixEnpxFAAAAEw"]
[Thu Sep 17 15:17:12.282932 2026] [security2:error] [pid 971102:tid 971272] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxY2OcL08BTTQixEnpxFQAAACY"]
[Thu Sep 17 15:17:12.333042 2026] [security2:error] [pid 971102:tid 971306] [client 35.202.49.146:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxGAAAAEg"]
[Thu Sep 17 15:17:12.369088 2026] [security2:error] [pid 971102:tid 971254] [client 34.97.30.29:42524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxGQAAABQ"]
[Thu Sep 17 15:17:12.435238 2026] [security2:error] [pid 971102:tid 971286] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxY2OcL08BTTQixEnpxGgAAADQ"]
[Thu Sep 17 15:17:12.465535 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/en/.env"] [unique_id "aqxY2OcL08BTTQixEnpxGwAAAGg"]
[Thu Sep 17 15:17:12.479879 2026] [security2:error] [pid 971102:tid 971335] [client 35.202.49.146:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/site/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxHQAAAGU"]
[Thu Sep 17 15:17:12.588969 2026] [security2:error] [pid 971102:tid 971256] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxY2OcL08BTTQixEnpxIwAAABY"]
[Thu Sep 17 15:17:12.639117 2026] [security2:error] [pid 971102:tid 971317] [client 35.202.49.146:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxJAAAAFM"]
[Thu Sep 17 15:17:12.713559 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/administrator/.env"] [unique_id "aqxY2OcL08BTTQixEnpxJgAAADw"]
[Thu Sep 17 15:17:12.737893 2026] [security2:error] [pid 971102:tid 971260] [client 34.97.30.29:42540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/test/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxJwAAABo"]
[Thu Sep 17 15:17:12.741706 2026] [security2:error] [pid 971102:tid 971332] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxY2OcL08BTTQixEnpxKAAAAGI"]
[Thu Sep 17 15:17:12.803606 2026] [security2:error] [pid 971102:tid 971358] [client 35.202.49.146:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxKgAAAHw"]
[Thu Sep 17 15:17:12.885380 2026] [security2:error] [pid 971102:tid 971360] [client 185.55.149.49:60119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY2OcL08BTTQixEnpxLAAAAH4"]
[Thu Sep 17 15:17:12.885493 2026] [security2:error] [pid 971102:tid 971360] [client 185.55.149.49:60119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY2OcL08BTTQixEnpxLAAAAH4"]
[Thu Sep 17 15:17:12.900030 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxY2OcL08BTTQixEnpxLQAAACU"]
[Thu Sep 17 15:17:12.944391 2026] [security2:error] [pid 971102:tid 971345] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/psnlink/.env"] [unique_id "aqxY2OcL08BTTQixEnpxLgAAAG8"]
[Thu Sep 17 15:17:12.961790 2026] [security2:error] [pid 971102:tid 971285] [client 35.202.49.146:35608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxY2OcL08BTTQixEnpxMQAAADM"]
[Thu Sep 17 15:17:13.052743 2026] [security2:error] [pid 971102:tid 971237] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxY2ecL08BTTQixEnpxNQAAAAM"]
[Thu Sep 17 15:17:13.118038 2026] [security2:error] [pid 971102:tid 971238] [client 35.202.49.146:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/core/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxOQAAAAQ"]
[Thu Sep 17 15:17:13.128115 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:42552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxOgAAAEQ"]
[Thu Sep 17 15:17:13.174763 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/exapi/.env"] [unique_id "aqxY2ecL08BTTQixEnpxQAAAAD4"]
[Thu Sep 17 15:17:13.188734 2026] [security2:error] [pid 971102:tid 971330] [client 45.169.98.18:58663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ecL08BTTQixEnpxQwAAAGA"]
[Thu Sep 17 15:17:13.188839 2026] [security2:error] [pid 971102:tid 971330] [client 45.169.98.18:58663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ecL08BTTQixEnpxQwAAAGA"]
[Thu Sep 17 15:17:13.206338 2026] [security2:error] [pid 971102:tid 971290] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxY2ecL08BTTQixEnpxRAAAADg"]
[Thu Sep 17 15:17:13.238187 2026] [security2:error] [pid 971102:tid 971140] [remote 111.225.148.157:26768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/"] [unique_id "aqxY2ecL08BTTQixEnpxRgAAHiQ"]
[Thu Sep 17 15:17:13.276998 2026] [security2:error] [pid 971102:tid 971312] [client 35.202.49.146:35614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.49.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.geekngamer.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxSAAAAE4"]
[Thu Sep 17 15:17:13.360716 2026] [security2:error] [pid 971102:tid 971333] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxY2ecL08BTTQixEnpxTAAAAGM"]
[Thu Sep 17 15:17:13.407105 2026] [security2:error] [pid 971102:tid 971278] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sitemaps/.env"] [unique_id "aqxY2ecL08BTTQixEnpxTgAAACw"]
[Thu Sep 17 15:17:13.423589 2026] [security2:error] [pid 971102:tid 971252] [client 134.185.85.61:64652] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "slimmtech.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxY2ecL08BTTQixEnpxUQAAABI"]
[Thu Sep 17 15:17:13.446868 2026] [security2:error] [pid 971102:tid 971258] [client 35.202.49.146:35628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.geekngamer.com"] [uri "/index.php"] [unique_id "aqxY2ecL08BTTQixEnpxVgAAABg"]
[Thu Sep 17 15:17:13.506057 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:42564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/old/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxXAAAAHI"]
[Thu Sep 17 15:17:13.535387 2026] [security2:error] [pid 971102:tid 971286] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxY2ecL08BTTQixEnpxXgAAADQ"]
[Thu Sep 17 15:17:13.615073 2026] [security2:error] [pid 971102:tid 971315] [client 172.239.147.162:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxY2ecL08BTTQixEnpxYwAAAFE"], referer: binance.com
[Thu Sep 17 15:17:13.688517 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxY2ecL08BTTQixEnpxaQAAAGY"]
[Thu Sep 17 15:17:13.805685 2026] [security2:error] [pid 971102:tid 971360] [client 134.185.85.61:61214] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "slimmtech.com"] [uri "/media/system/js/core.js"] [unique_id "aqxY2ecL08BTTQixEnpxegAAAH4"]
[Thu Sep 17 15:17:13.844961 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxY2ecL08BTTQixEnpxfQAAADM"]
[Thu Sep 17 15:17:13.875581 2026] [security2:error] [pid 971102:tid 971332] [client 34.97.30.29:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY2ecL08BTTQixEnpxfwAAAGI"]
[Thu Sep 17 15:17:14.004292 2026] [security2:error] [pid 971102:tid 971320] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxY2ucL08BTTQixEnpxiQAAAFY"]
[Thu Sep 17 15:17:14.161304 2026] [security2:error] [pid 971102:tid 971236] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxY2ucL08BTTQixEnpxkAAAAAI"]
[Thu Sep 17 15:17:14.197966 2026] [security2:error] [pid 971102:tid 971342] [client 34.166.218.131:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/logs/.env"] [unique_id "aqxY2ucL08BTTQixEnpxkgAAAGw"]
[Thu Sep 17 15:17:14.247704 2026] [security2:error] [pid 971102:tid 971282] [client 34.97.30.29:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/public/phpinfo.php"] [unique_id "aqxY2ucL08BTTQixEnpxkwAAADA"]
[Thu Sep 17 15:17:14.315681 2026] [security2:error] [pid 971102:tid 971266] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxY2ucL08BTTQixEnpxmAAAACA"]
[Thu Sep 17 15:17:14.407155 2026] [security2:error] [pid 971102:tid 971129] [remote 110.249.202.132:61972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christiansoncampusnlc.com"] [uri "/"] [unique_id "aqxY2ucL08BTTQixEnpxmgAAKRk"]
[Thu Sep 17 15:17:14.468346 2026] [security2:error] [pid 971102:tid 971244] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxY2ucL08BTTQixEnpxnQAAAAo"]
[Thu Sep 17 15:17:14.620814 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxY2ucL08BTTQixEnpxpgAAAHU"]
[Thu Sep 17 15:17:14.704485 2026] [security2:error] [pid 971102:tid 971278] [client 172.239.147.162:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxY2ucL08BTTQixEnpxqwAAACw"], referer: binance.com
[Thu Sep 17 15:17:14.781854 2026] [security2:error] [pid 971102:tid 971301] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxY2ucL08BTTQixEnpxrAAAAEM"]
[Thu Sep 17 15:17:14.785468 2026] [security2:error] [pid 971102:tid 971316] [client 154.190.208.131:42403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ucL08BTTQixEnpxrgAAAFI"]
[Thu Sep 17 15:17:14.794894 2026] [security2:error] [pid 971102:tid 971316] [client 154.190.208.131:42403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2ucL08BTTQixEnpxrgAAAFI"]
[Thu Sep 17 15:17:14.830564 2026] [security2:error] [pid 971102:tid 971354] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY2ucL08BTTQixEnpxqQAAAHg"]
[Thu Sep 17 15:17:14.890634 2026] [security2:error] [pid 971102:tid 971335] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cache/.env"] [unique_id "aqxY2ucL08BTTQixEnpxsAAAAGU"]
[Thu Sep 17 15:17:14.936840 2026] [security2:error] [pid 971102:tid 971256] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxY2ucL08BTTQixEnpxsQAAABY"]
[Thu Sep 17 15:17:15.093380 2026] [security2:error] [pid 971102:tid 971247] [client 34.97.30.29:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/php-info.php"] [unique_id "aqxY2-cL08BTTQixEnpxtgAAAA0"]
[Thu Sep 17 15:17:15.099382 2026] [security2:error] [pid 971102:tid 971272] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxY2-cL08BTTQixEnpxtwAAACY"]
[Thu Sep 17 15:17:15.119816 2026] [security2:error] [pid 971102:tid 971292] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailer/.env"] [unique_id "aqxY2-cL08BTTQixEnpxuQAAADo"]
[Thu Sep 17 15:17:15.135432 2026] [security2:error] [pid 971102:tid 971303] [client 172.239.147.162:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxY2-cL08BTTQixEnpxugAAAEU"], referer: binance.com
[Thu Sep 17 15:17:15.214860 2026] [security2:error] [pid 971102:tid 971245] [client 192.71.12.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxY2ucL08BTTQixEnpxlwAAAAs"], referer: http://iradtech.com/robots.txt
[Thu Sep 17 15:17:15.252959 2026] [security2:error] [pid 971102:tid 971241] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxY2-cL08BTTQixEnpxvQAAAAc"]
[Thu Sep 17 15:17:15.349519 2026] [security2:error] [pid 971102:tid 971267] [client 114.198.138.124:64235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2-cL08BTTQixEnpxwAAAACE"]
[Thu Sep 17 15:17:15.349610 2026] [security2:error] [pid 971102:tid 971267] [client 114.198.138.124:64235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY2-cL08BTTQixEnpxwAAAACE"]
[Thu Sep 17 15:17:15.351019 2026] [security2:error] [pid 971102:tid 971263] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mail/.env"] [unique_id "aqxY2-cL08BTTQixEnpxvwAAAB0"]
[Thu Sep 17 15:17:15.407170 2026] [security2:error] [pid 971102:tid 971269] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxY2-cL08BTTQixEnpxxgAAACM"]
[Thu Sep 17 15:17:15.473008 2026] [security2:error] [pid 971102:tid 971285] [client 34.97.30.29:59770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpversion.php"] [unique_id "aqxY2-cL08BTTQixEnpxyQAAADM"]
[Thu Sep 17 15:17:15.520108 2026] [security2:error] [pid 971102:tid 971319] [client 93.152.209.11:43096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.commonearthjc.com"] [uri "/.env"] [unique_id "aqxY2-cL08BTTQixEnpxzgAAAFU"]
[Thu Sep 17 15:17:15.560139 2026] [security2:error] [pid 971102:tid 971273] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxY2-cL08BTTQixEnpx0QAAACc"]
[Thu Sep 17 15:17:15.585623 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/email/.env"] [unique_id "aqxY2-cL08BTTQixEnpx0gAAAHs"]
[Thu Sep 17 15:17:15.704249 2026] [security2:error] [pid 971102:tid 971106] [remote 93.152.209.11:34704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.commonearthjc.com"] [uri "/.env"] [unique_id "aqxY2-cL08BTTQixEnpx1gAAZAI"]
[Thu Sep 17 15:17:15.714180 2026] [security2:error] [pid 971102:tid 971309] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxY2-cL08BTTQixEnpx2AAAAEs"]
[Thu Sep 17 15:17:15.815330 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/smtp/.env"] [unique_id "aqxY2-cL08BTTQixEnpx3gAAABs"]
[Thu Sep 17 15:17:15.845746 2026] [security2:error] [pid 971102:tid 971314] [client 34.97.30.29:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/_phpinfo.php"] [unique_id "aqxY2-cL08BTTQixEnpx3wAAAFA"]
[Thu Sep 17 15:17:15.874266 2026] [security2:error] [pid 971102:tid 971266] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxY2-cL08BTTQixEnpx4AAAACA"]
[Thu Sep 17 15:17:16.031651 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxY3OcL08BTTQixEnpx6gAAAH8"]
[Thu Sep 17 15:17:16.048637 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailing/.env"] [unique_id "aqxY3OcL08BTTQixEnpx6wAAABQ"]
[Thu Sep 17 15:17:16.260966 2026] [security2:error] [pid 971102:tid 971279] [client 34.97.30.29:59792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/old_phpinfo.php"] [unique_id "aqxY3OcL08BTTQixEnpx7wAAAC0"]
[Thu Sep 17 15:17:16.287697 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/notifications/.env"] [unique_id "aqxY3OcL08BTTQixEnpx8gAAADU"]
[Thu Sep 17 15:17:16.354593 2026] [fcgid:warn] [pid 971102:tid 971329] (70014)End of file found: [client 152.32.215.226:44956] mod_fcgid: can't get data from http client
[Thu Sep 17 15:17:16.433336 2026] [security2:error] [pid 971102:tid 971352] [client 114.119.134.110:56779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.silverstaterealty.com"] [uri "/robots.txt"] [unique_id "aqxY3OcL08BTTQixEnpx-QAAAHY"], referer: https://www.silverstaterealty.com/robots.txt
[Thu Sep 17 15:17:16.507255 2026] [security2:error] [pid 971102:tid 971354] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxY3OcL08BTTQixEnpx_wAAAHg"]
[Thu Sep 17 15:17:16.533397 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/notify/.env"] [unique_id "aqxY3OcL08BTTQixEnpyAAAAAFc"]
[Thu Sep 17 15:17:16.637992 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3OcL08BTTQixEnpyBAAAABg"]
[Thu Sep 17 15:17:16.638140 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:53901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3OcL08BTTQixEnpyBAAAABg"]
[Thu Sep 17 15:17:16.641295 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:59804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/server-info.php"] [unique_id "aqxY3OcL08BTTQixEnpyBQAAABM"]
[Thu Sep 17 15:17:16.663847 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxY3OcL08BTTQixEnpyBgAAADw"]
[Thu Sep 17 15:17:16.664776 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:56420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3OcL08BTTQixEnpyBwAAABo"]
[Thu Sep 17 15:17:16.716645 2026] [security2:error] [pid 971102:tid 971280] [client 172.239.147.162:60513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxY3OcL08BTTQixEnpyCAAAAC4"], referer: binance.com
[Thu Sep 17 15:17:16.771083 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sender/.env"] [unique_id "aqxY3OcL08BTTQixEnpyCgAAAAc"]
[Thu Sep 17 15:17:16.826841 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxY3OcL08BTTQixEnpyCwAAACU"]
[Thu Sep 17 15:17:16.983671 2026] [security2:error] [pid 971102:tid 971285] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxY3OcL08BTTQixEnpyEAAAADM"]
[Thu Sep 17 15:17:17.007507 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/campaign/.env"] [unique_id "aqxY3ecL08BTTQixEnpyFAAAADE"]
[Thu Sep 17 15:17:17.014091 2026] [security2:error] [pid 971102:tid 971263] [client 179.6.165.237:6510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY3OcL08BTTQixEnpyDAAAHSE"]
[Thu Sep 17 15:17:17.035206 2026] [security2:error] [pid 971102:tid 971239] [client 172.239.147.162:60539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxY3ecL08BTTQixEnpyFwAAAAU"], referer: binance.com
[Thu Sep 17 15:17:17.056176 2026] [security2:error] [pid 971102:tid 971267] [client 34.97.30.29:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/server-status.php"] [unique_id "aqxY3ecL08BTTQixEnpyGQAAACE"]
[Thu Sep 17 15:17:17.140647 2026] [security2:error] [pid 971102:tid 971257] [client 34.151.157.242:56436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3ecL08BTTQixEnpyHwAAABc"]
[Thu Sep 17 15:17:17.144550 2026] [security2:error] [pid 971102:tid 971334] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxY3ecL08BTTQixEnpyIAAAAGQ"]
[Thu Sep 17 15:17:17.181835 2026] [security2:error] [pid 971102:tid 971302] [client 136.116.35.245:59724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "moorekuehn.com"] [uri "/.env"] [unique_id "aqxY3ecL08BTTQixEnpyIgAAAEQ"]
[Thu Sep 17 15:17:17.244263 2026] [security2:error] [pid 971102:tid 971270] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/newsletter/.env"] [unique_id "aqxY3ecL08BTTQixEnpyJAAAACQ"]
[Thu Sep 17 15:17:17.268131 2026] [security2:error] [pid 971102:tid 971320] [client 5.133.215.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxY3ecL08BTTQixEnpyGgAAAFY"], referer: http://iradtech.com/llms.txt
[Thu Sep 17 15:17:17.312429 2026] [security2:error] [pid 971102:tid 971261] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxY3ecL08BTTQixEnpyJgAAABs"]
[Thu Sep 17 15:17:17.415457 2026] [security2:error] [pid 971102:tid 971288] [client 136.116.35.245:52760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "moorekuehn.com"] [uri "/.env"] [unique_id "aqxY3ecL08BTTQixEnpyJwAAADY"]
[Thu Sep 17 15:17:17.471792 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxY3ecL08BTTQixEnpyLAAAAHU"]
[Thu Sep 17 15:17:17.480722 2026] [security2:error] [pid 971102:tid 971254] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ses/.env"] [unique_id "aqxY3ecL08BTTQixEnpyLQAAABQ"]
[Thu Sep 17 15:17:17.606999 2026] [security2:error] [pid 971102:tid 971312] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY3ecL08BTTQixEnpyMAAAAE4"]
[Thu Sep 17 15:17:17.617514 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:56446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3ecL08BTTQixEnpyMgAAABI"]
[Thu Sep 17 15:17:17.627974 2026] [security2:error] [pid 971102:tid 971277] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxY3ecL08BTTQixEnpyNAAAACs"]
[Thu Sep 17 15:17:17.717221 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sendgrid/.env"] [unique_id "aqxY3ecL08BTTQixEnpyNQAAAGk"]
[Thu Sep 17 15:17:17.784992 2026] [security2:error] [pid 971102:tid 971295] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxY3ecL08BTTQixEnpyOAAAAD0"]
[Thu Sep 17 15:17:17.943648 2026] [security2:error] [pid 971102:tid 971299] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxY3ecL08BTTQixEnpyPQAAAEE"]
[Thu Sep 17 15:17:17.953156 2026] [security2:error] [pid 971102:tid 971321] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sparkpost/.env"] [unique_id "aqxY3ecL08BTTQixEnpyQAAAAFc"]
[Thu Sep 17 15:17:18.109766 2026] [security2:error] [pid 971102:tid 971301] [client 34.97.30.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ahmedteleb.com"] [uri "/index.php"] [unique_id "aqxY3ecL08BTTQixEnpyRAAAAEM"]
[Thu Sep 17 15:17:18.121859 2026] [security2:error] [pid 971102:tid 971258] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxY3ucL08BTTQixEnpySgAAABg"]
[Thu Sep 17 15:17:18.193621 2026] [security2:error] [pid 971102:tid 971291] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/postmark/.env"] [unique_id "aqxY3ucL08BTTQixEnpyTQAAADk"]
[Thu Sep 17 15:17:18.280302 2026] [security2:error] [pid 971102:tid 971268] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxY3ucL08BTTQixEnpyTgAAACI"]
[Thu Sep 17 15:17:18.302706 2026] [security2:error] [pid 971102:tid 971306] [client 34.97.30.29:59816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY3ucL08BTTQixEnpyUAAAAEg"]
[Thu Sep 17 15:17:18.424122 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailgun/.env"] [unique_id "aqxY3ucL08BTTQixEnpyUQAAAG4"]
[Thu Sep 17 15:17:18.439493 2026] [security2:error] [pid 971102:tid 971319] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxY3ucL08BTTQixEnpyUgAAAFU"]
[Thu Sep 17 15:17:18.480749 2026] [security2:error] [pid 971102:tid 971289] [client 172.239.147.162:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxY3ucL08BTTQixEnpyVgAAADc"], referer: binance.com
[Thu Sep 17 15:17:18.553214 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3ucL08BTTQixEnpyWgAAAAs"]
[Thu Sep 17 15:17:18.555376 2026] [security2:error] [pid 971102:tid 971245] [client 156.192.234.52:50724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY3ucL08BTTQixEnpyWgAAAAs"]
[Thu Sep 17 15:17:18.597783 2026] [security2:error] [pid 971102:tid 971350] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxY3ucL08BTTQixEnpyXAAAAHQ"]
[Thu Sep 17 15:17:18.654967 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mandrill/.env"] [unique_id "aqxY3ucL08BTTQixEnpyXwAAAGQ"]
[Thu Sep 17 15:17:18.719480 2026] [security2:error] [pid 971102:tid 971331] [client 34.97.30.29:59828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxY3ucL08BTTQixEnpyYgAAAGE"]
[Thu Sep 17 15:17:18.760519 2026] [security2:error] [pid 971102:tid 971243] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxY3ucL08BTTQixEnpyYwAAAAk"]
[Thu Sep 17 15:17:18.887377 2026] [security2:error] [pid 971102:tid 971326] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailjet/.env"] [unique_id "aqxY3ucL08BTTQixEnpyZwAAAFw"]
[Thu Sep 17 15:17:18.917589 2026] [security2:error] [pid 971102:tid 971264] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxY3ucL08BTTQixEnpyaQAAAB4"]
[Thu Sep 17 15:17:19.023711 2026] [security2:error] [pid 971102:tid 971269] [client 91.95.13.55:51638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY3ucL08BTTQixEnpyaAAAI3c"]
[Thu Sep 17 15:17:19.089124 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxY3-cL08BTTQixEnpybgAAADY"]
[Thu Sep 17 15:17:19.120561 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/brevo/.env"] [unique_id "aqxY3-cL08BTTQixEnpybwAAABw"]
[Thu Sep 17 15:17:19.150161 2026] [security2:error] [pid 971102:tid 971266] [client 34.97.30.29:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY3-cL08BTTQixEnpycAAAACA"]
[Thu Sep 17 15:17:19.183158 2026] [security2:error] [pid 971102:tid 971358] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY3ucL08BTTQixEnpyTAAAAHw"]
[Thu Sep 17 15:17:19.209992 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY3OcL08BTTQixEnpyAgAAACo"]
[Thu Sep 17 15:17:19.245884 2026] [security2:error] [pid 971102:tid 971313] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxY3-cL08BTTQixEnpydQAAAE8"]
[Thu Sep 17 15:17:19.350970 2026] [security2:error] [pid 971102:tid 971272] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/transactional/.env"] [unique_id "aqxY3-cL08BTTQixEnpydwAAACY"]
[Thu Sep 17 15:17:19.405334 2026] [security2:error] [pid 971102:tid 971301] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxY3-cL08BTTQixEnpyhAAAAEM"]
[Thu Sep 17 15:17:19.500069 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:56448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "agingwellcounseling.com"] [uri "/"] [unique_id "aqxY3-cL08BTTQixEnpyiwAAAEo"]
[Thu Sep 17 15:17:19.522889 2026] [security2:error] [pid 971102:tid 971279] [client 3.82.141.143:28768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyegAAAC0"]
[Thu Sep 17 15:17:19.526037 2026] [security2:error] [pid 971102:tid 971287] [client 3.82.141.143:28736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfAAAADU"]
[Thu Sep 17 15:17:19.527339 2026] [security2:error] [pid 971102:tid 971317] [client 3.82.141.143:28724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfgAAAFM"]
[Thu Sep 17 15:17:19.533981 2026] [security2:error] [pid 971102:tid 971349] [client 3.82.141.143:28716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpygAAAAHM"]
[Thu Sep 17 15:17:19.534244 2026] [security2:error] [pid 971102:tid 971310] [client 3.82.141.143:28696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfQAAAEw"]
[Thu Sep 17 15:17:19.537031 2026] [security2:error] [pid 971102:tid 971316] [client 3.82.141.143:28732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyfwAAAFI"]
[Thu Sep 17 15:17:19.538425 2026] [security2:error] [pid 971102:tid 971242] [client 3.82.141.143:28704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyeQAAAAg"]
[Thu Sep 17 15:17:19.540711 2026] [security2:error] [pid 971102:tid 971253] [client 34.97.30.29:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY3-cL08BTTQixEnpykQAAABM"]
[Thu Sep 17 15:17:19.549337 2026] [security2:error] [pid 971102:tid 971295] [client 3.82.141.143:28714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpygQAAAD0"]
[Thu Sep 17 15:17:19.549380 2026] [security2:error] [pid 971102:tid 971329] [client 3.82.141.143:28758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyggAAAF8"]
[Thu Sep 17 15:17:19.553047 2026] [security2:error] [pid 971102:tid 971347] [client 3.82.141.143:28684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyeAAAAHE"]
[Thu Sep 17 15:17:19.558877 2026] [security2:error] [pid 971102:tid 971355] [client 3.82.141.143:28738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpygwAAAHk"]
[Thu Sep 17 15:17:19.563943 2026] [security2:error] [pid 971102:tid 971241] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxY3-cL08BTTQixEnpylQAAAAc"]
[Thu Sep 17 15:17:19.566521 2026] [security2:error] [pid 971102:tid 971339] [client 3.82.141.143:28710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpyewAAAGk"]
[Thu Sep 17 15:17:19.581710 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bulk/.env"] [unique_id "aqxY3-cL08BTTQixEnpylgAAAH4"]
[Thu Sep 17 15:17:19.670164 2026] [security2:error] [pid 971102:tid 971289] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env"] [unique_id "aqxY3-cL08BTTQixEnpynAAAADc"]
[Thu Sep 17 15:17:19.726111 2026] [security2:error] [pid 971102:tid 971257] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxY3-cL08BTTQixEnpynwAAABc"]
[Thu Sep 17 15:17:19.812573 2026] [security2:error] [pid 971102:tid 971331] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/aws/.env"] [unique_id "aqxY3-cL08BTTQixEnpyoAAAAGE"]
[Thu Sep 17 15:17:19.834738 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:55431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxY3-cL08BTTQixEnpyowAAABY"], referer: binance.com
[Thu Sep 17 15:17:19.889099 2026] [security2:error] [pid 971102:tid 971320] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxY3-cL08BTTQixEnpypgAAAFY"]
[Thu Sep 17 15:17:19.928650 2026] [security2:error] [pid 971102:tid 971237] [client 34.97.30.29:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY3-cL08BTTQixEnpypwAAAAM"]
[Thu Sep 17 15:17:19.960988 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY3-cL08BTTQixEnpypAAAAAA"]
[Thu Sep 17 15:17:19.974183 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env"] [unique_id "aqxY3-cL08BTTQixEnpyqgAAAHs"]
[Thu Sep 17 15:17:20.050359 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/azure/.env"] [unique_id "aqxY4OcL08BTTQixEnpyrAAAAHo"]
[Thu Sep 17 15:17:20.052490 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxY4OcL08BTTQixEnpyrQAAADY"]
[Thu Sep 17 15:17:20.211918 2026] [security2:error] [pid 971102:tid 971302] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxY4OcL08BTTQixEnpytAAAAEQ"]
[Thu Sep 17 15:17:20.280817 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gcp/.env"] [unique_id "aqxY4OcL08BTTQixEnpyvQAAAGM"]
[Thu Sep 17 15:17:20.304164 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpysQAAAEU"]
[Thu Sep 17 15:17:20.345784 2026] [security2:error] [pid 971102:tid 971325] [client 34.97.30.29:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY4OcL08BTTQixEnpywAAAAFs"]
[Thu Sep 17 15:17:20.369265 2026] [security2:error] [pid 971102:tid 971338] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxY4OcL08BTTQixEnpywQAAAGg"]
[Thu Sep 17 15:17:20.412375 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpyvgAAADA"]
[Thu Sep 17 15:17:20.511173 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cloud/.env"] [unique_id "aqxY4OcL08BTTQixEnpyxgAAAC0"]
[Thu Sep 17 15:17:20.551714 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxY4OcL08BTTQixEnpyxwAAADU"]
[Thu Sep 17 15:17:20.705556 2026] [security2:error] [pid 971102:tid 971268] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxY4OcL08BTTQixEnpyzwAAACI"]
[Thu Sep 17 15:17:20.725337 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpyzQAAABM"]
[Thu Sep 17 15:17:20.728643 2026] [security2:error] [pid 971102:tid 971310] [client 34.97.30.29:59874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxY4OcL08BTTQixEnpy0QAAAEw"]
[Thu Sep 17 15:17:20.740878 2026] [security2:error] [pid 971102:tid 971241] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/infrastructure/.env"] [unique_id "aqxY4OcL08BTTQixEnpy0gAAAAc"]
[Thu Sep 17 15:17:20.768874 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpyzgAAADg"]
[Thu Sep 17 15:17:20.870260 2026] [security2:error] [pid 971102:tid 971263] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxY4OcL08BTTQixEnpy1wAAAB0"]
[Thu Sep 17 15:17:20.971762 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/docker/.env"] [unique_id "aqxY4OcL08BTTQixEnpy4QAAAHQ"]
[Thu Sep 17 15:17:21.012698 2026] [security2:error] [pid 971102:tid 971319] [client 92.99.250.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpy1QAAAFU"]
[Thu Sep 17 15:17:21.034284 2026] [security2:error] [pid 971102:tid 971260] [client 34.154.67.31:52832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxY4ecL08BTTQixEnpy5QAAABo"]
[Thu Sep 17 15:17:21.043840 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpy2wAAAC8"]
[Thu Sep 17 15:17:21.086073 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4OcL08BTTQixEnpy3wAAAAs"]
[Thu Sep 17 15:17:21.149405 2026] [security2:error] [pid 971102:tid 971334] [client 34.97.30.29:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php.old"] [unique_id "aqxY4ecL08BTTQixEnpy6gAAAGQ"]
[Thu Sep 17 15:17:21.200861 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/k8s/.env"] [unique_id "aqxY4ecL08BTTQixEnpy7gAAAD4"]
[Thu Sep 17 15:17:21.382188 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpy9AAAAAM"]
[Thu Sep 17 15:17:21.430856 2026] [security2:error] [pid 971102:tid 971312] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/kubernetes/.env"] [unique_id "aqxY4ecL08BTTQixEnpzAAAAAE4"]
[Thu Sep 17 15:17:21.436851 2026] [security2:error] [pid 971102:tid 971288] [client 162.241.226.11:10278] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxY4ecL08BTTQixEnpy_AAAADY"]
[Thu Sep 17 15:17:21.442425 2026] [security2:error] [pid 971102:tid 971249] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpy9gAAAA8"]
[Thu Sep 17 15:17:21.559979 2026] [security2:error] [pid 971102:tid 971302] [client 34.97.30.29:59890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php~"] [unique_id "aqxY4ecL08BTTQixEnpzCQAAAEQ"]
[Thu Sep 17 15:17:21.661848 2026] [security2:error] [pid 971102:tid 971299] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/terraform/.env"] [unique_id "aqxY4ecL08BTTQixEnpzEAAAAEE"]
[Thu Sep 17 15:17:21.742503 2026] [security2:error] [pid 971102:tid 971286] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpzDwAAADQ"]
[Thu Sep 17 15:17:21.794511 2026] [security2:error] [pid 971102:tid 971321] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpzEQAAAFc"]
[Thu Sep 17 15:17:21.898082 2026] [security2:error] [pid 971102:tid 971295] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ansible/.env"] [unique_id "aqxY4ecL08BTTQixEnpzGAAAAD0"]
[Thu Sep 17 15:17:21.898559 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.bak"] [unique_id "aqxY4ecL08BTTQixEnpzGQAAAF8"]
[Thu Sep 17 15:17:22.000832 2026] [security2:error] [pid 971102:tid 971272] [client 34.97.30.29:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/info.php.bak"] [unique_id "aqxY4ecL08BTTQixEnpzIwAAACY"]
[Thu Sep 17 15:17:22.003714 2026] [security2:error] [pid 971102:tid 971291] [client 172.239.147.162:64506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxY4ucL08BTTQixEnpzJQAAADk"], referer: binance.com
[Thu Sep 17 15:17:22.020371 2026] [security2:error] [pid 971102:tid 971276] [client 103.131.71.43:52719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxY4ecL08BTTQixEnpzGwAAACo"]
[Thu Sep 17 15:17:22.049611 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.backup"] [unique_id "aqxY4ucL08BTTQixEnpzJgAAADg"]
[Thu Sep 17 15:17:22.130372 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.git/.env"] [unique_id "aqxY4ucL08BTTQixEnpzLAAAAHI"]
[Thu Sep 17 15:17:22.208867 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzKQAAADE"]
[Thu Sep 17 15:17:22.257575 2026] [security2:error] [pid 971102:tid 971274] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxY4ucL08BTTQixEnpzMQAAACg"]
[Thu Sep 17 15:17:22.366320 2026] [security2:error] [pid 971102:tid 971328] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ci/.env"] [unique_id "aqxY4ucL08BTTQixEnpzNAAAAF4"]
[Thu Sep 17 15:17:22.373754 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.bak"] [unique_id "aqxY4ucL08BTTQixEnpzNQAAAAs"]
[Thu Sep 17 15:17:22.413444 2026] [security2:error] [pid 971102:tid 971246] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxY4ucL08BTTQixEnpzNwAAAAw"]
[Thu Sep 17 15:17:22.433306 2026] [security2:error] [pid 971102:tid 971244] [client 92.99.250.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzJwAAAAo"]
[Thu Sep 17 15:17:22.444458 2026] [security2:error] [pid 971102:tid 971265] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzMwAAAB8"]
[Thu Sep 17 15:17:22.480139 2026] [security2:error] [pid 971102:tid 971331] [client 34.97.30.29:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/phpinfo.php.save"] [unique_id "aqxY4ucL08BTTQixEnpzPAAAAGE"]
[Thu Sep 17 15:17:22.544088 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.backup"] [unique_id "aqxY4ucL08BTTQixEnpzPQAAAGs"]
[Thu Sep 17 15:17:22.570845 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxY4ucL08BTTQixEnpzPgAAACQ"]
[Thu Sep 17 15:17:22.600266 2026] [security2:error] [pid 971102:tid 971234] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cd/.env"] [unique_id "aqxY4ucL08BTTQixEnpzQAAAAAA"]
[Thu Sep 17 15:17:22.627471 2026] [security2:error] [pid 971102:tid 971258] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.old"] [unique_id "aqxY4ucL08BTTQixEnpzRAAAABg"]
[Thu Sep 17 15:17:22.728840 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxY4ucL08BTTQixEnpzSAAAADY"]
[Thu Sep 17 15:17:22.828684 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzSQAAAE4"]
[Thu Sep 17 15:17:22.830951 2026] [security2:error] [pid 971102:tid 971333] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/jenkins/.env"] [unique_id "aqxY4ucL08BTTQixEnpzTQAAAGM"]
[Thu Sep 17 15:17:22.902960 2026] [security2:error] [pid 971102:tid 971302] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxY4ucL08BTTQixEnpzTwAAAEQ"]
[Thu Sep 17 15:17:22.917714 2026] [security2:error] [pid 971102:tid 971261] [client 34.97.30.29:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxY4ucL08BTTQixEnpzUQAAABs"]
[Thu Sep 17 15:17:22.933632 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4ucL08BTTQixEnpzTgAAACk"]
[Thu Sep 17 15:17:22.994083 2026] [security2:error] [pid 971102:tid 971262] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.old"] [unique_id "aqxY4ucL08BTTQixEnpzVQAAABw"]
[Thu Sep 17 15:17:23.060953 2026] [security2:error] [pid 971102:tid 971352] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxY4-cL08BTTQixEnpzVwAAAHY"]
[Thu Sep 17 15:17:23.060953 2026] [security2:error] [pid 971102:tid 971338] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gitlab/.env"] [unique_id "aqxY4-cL08BTTQixEnpzWAAAAGg"]
[Thu Sep 17 15:17:23.225450 2026] [security2:error] [pid 971102:tid 971279] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxY4-cL08BTTQixEnpzXwAAAC0"]
[Thu Sep 17 15:17:23.256806 2026] [security2:error] [pid 971102:tid 971294] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzXQAAADw"]
[Thu Sep 17 15:17:23.302992 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/github/.env"] [unique_id "aqxY4-cL08BTTQixEnpzYwAAADU"]
[Thu Sep 17 15:17:23.351197 2026] [security2:error] [pid 971102:tid 971273] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzYAAAACc"]
[Thu Sep 17 15:17:23.381832 2026] [security2:error] [pid 971102:tid 971323] [client 34.97.30.29:59928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxY4-cL08BTTQixEnpzZwAAAFk"]
[Thu Sep 17 15:17:23.382765 2026] [security2:error] [pid 971102:tid 971321] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxY4-cL08BTTQixEnpzZgAAAFc"]
[Thu Sep 17 15:17:23.532710 2026] [security2:error] [pid 971102:tid 971290] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/actions/.env"] [unique_id "aqxY4-cL08BTTQixEnpzcQAAADg"]
[Thu Sep 17 15:17:23.536720 2026] [security2:error] [pid 971102:tid 971316] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxY4-cL08BTTQixEnpzcgAAAFI"]
[Thu Sep 17 15:17:23.578770 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzbAAAAF8"]
[Thu Sep 17 15:17:23.648359 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzcwAAAHI"]
[Thu Sep 17 15:17:23.657677 2026] [security2:error] [pid 971102:tid 971250] [client 185.55.149.49:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzdwAAABA"]
[Thu Sep 17 15:17:23.657784 2026] [security2:error] [pid 971102:tid 971250] [client 185.55.149.49:53594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzdwAAABA"]
[Thu Sep 17 15:17:23.678544 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:59230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzegAAAAg"]
[Thu Sep 17 15:17:23.678651 2026] [security2:error] [pid 971102:tid 971242] [client 45.169.98.18:59230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY4-cL08BTTQixEnpzegAAAAg"]
[Thu Sep 17 15:17:23.692083 2026] [security2:error] [pid 971102:tid 971238] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxY4-cL08BTTQixEnpzewAAAAQ"]
[Thu Sep 17 15:17:23.766436 2026] [security2:error] [pid 971102:tid 971251] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/circleci/.env"] [unique_id "aqxY4-cL08BTTQixEnpzgAAAABE"]
[Thu Sep 17 15:17:23.850576 2026] [security2:error] [pid 971102:tid 971296] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxY4-cL08BTTQixEnpzhAAAAD4"]
[Thu Sep 17 15:17:23.868360 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxY4-cL08BTTQixEnpzhgAAAAs"]
[Thu Sep 17 15:17:23.891217 2026] [security2:error] [pid 971102:tid 971244] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzgQAAAAo"]
[Thu Sep 17 15:17:23.944845 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxY4-cL08BTTQixEnpziAAAABY"], referer: binance.com
[Thu Sep 17 15:17:23.983486 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY4-cL08BTTQixEnpzhwAAAFY"]
[Thu Sep 17 15:17:23.997382 2026] [security2:error] [pid 971102:tid 971341] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/travis/.env"] [unique_id "aqxY4-cL08BTTQixEnpziwAAAGs"]
[Thu Sep 17 15:17:24.007462 2026] [security2:error] [pid 971102:tid 971322] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxY5OcL08BTTQixEnpzjAAAAFg"]
[Thu Sep 17 15:17:24.161513 2026] [security2:error] [pid 971102:tid 971240] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxY5OcL08BTTQixEnpzlgAAAAY"]
[Thu Sep 17 15:17:24.171973 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzkQAAACA"]
[Thu Sep 17 15:17:24.227530 2026] [security2:error] [pid 971102:tid 971277] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/buildkite/.env"] [unique_id "aqxY5OcL08BTTQixEnpznQAAACs"]
[Thu Sep 17 15:17:24.279434 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzmwAAAEY"]
[Thu Sep 17 15:17:24.316273 2026] [security2:error] [pid 971102:tid 971275] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxY5OcL08BTTQixEnpzogAAACk"]
[Thu Sep 17 15:17:24.325774 2026] [security2:error] [pid 971102:tid 971342] [client 34.97.30.29:57008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxY5OcL08BTTQixEnpzowAAAGw"]
[Thu Sep 17 15:17:24.438954 2026] [security2:error] [pid 971102:tid 971261] [client 92.99.250.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzoQAAABs"]
[Thu Sep 17 15:17:24.458445 2026] [security2:error] [pid 971102:tid 971353] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mysql/.env"] [unique_id "aqxY5OcL08BTTQixEnpzrAAAAHc"]
[Thu Sep 17 15:17:24.468517 2026] [security2:error] [pid 971102:tid 971302] [client 172.239.147.162:62473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxY5OcL08BTTQixEnpzrQAAAEQ"], referer: binance.com
[Thu Sep 17 15:17:24.469840 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxY5OcL08BTTQixEnpzrgAAADw"]
[Thu Sep 17 15:17:24.504242 2026] [security2:error] [pid 971102:tid 971280] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzqwAAAC4"]
[Thu Sep 17 15:17:24.636258 2026] [security2:error] [pid 971102:tid 971355] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxY5OcL08BTTQixEnpzuAAAAHk"]
[Thu Sep 17 15:17:24.688696 2026] [security2:error] [pid 971102:tid 971286] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpztgAAADQ"]
[Thu Sep 17 15:17:24.696139 2026] [security2:error] [pid 971102:tid 971354] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/postgres/.env"] [unique_id "aqxY5OcL08BTTQixEnpzuQAAAHg"]
[Thu Sep 17 15:17:24.793831 2026] [security2:error] [pid 971102:tid 971348] [client 34.97.30.29:57010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxY5OcL08BTTQixEnpzvgAAAHI"]
[Thu Sep 17 15:17:24.805460 2026] [security2:error] [pid 971102:tid 971310] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxY5OcL08BTTQixEnpzvwAAAEw"]
[Thu Sep 17 15:17:24.871481 2026] [security2:error] [pid 971102:tid 971251] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzvQAAABE"]
[Thu Sep 17 15:17:24.937601 2026] [security2:error] [pid 971102:tid 971344] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mongodb/.env"] [unique_id "aqxY5OcL08BTTQixEnpzxQAAAG4"]
[Thu Sep 17 15:17:24.965328 2026] [security2:error] [pid 971102:tid 971322] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxY5OcL08BTTQixEnpzxwAAAFg"]
[Thu Sep 17 15:17:25.103151 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5OcL08BTTQixEnpzyQAAAGs"]
[Thu Sep 17 15:17:25.126018 2026] [security2:error] [pid 971102:tid 971278] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxY5ecL08BTTQixEnpz0gAAACw"]
[Thu Sep 17 15:17:25.168850 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/redis/.env"] [unique_id "aqxY5ecL08BTTQixEnpz1AAAAB4"]
[Thu Sep 17 15:17:25.228161 2026] [security2:error] [pid 971102:tid 971258] [client 34.97.30.29:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/www/phpinfo.php"] [unique_id "aqxY5ecL08BTTQixEnpz2AAAABg"]
[Thu Sep 17 15:17:25.243402 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz0wAAACA"]
[Thu Sep 17 15:17:25.284130 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxY5ecL08BTTQixEnpz2gAAAH8"]
[Thu Sep 17 15:17:25.306911 2026] [security2:error] [pid 971102:tid 971246] [client 154.190.208.131:41661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnpz3QAAAAw"]
[Thu Sep 17 15:17:25.310561 2026] [security2:error] [pid 971102:tid 971246] [client 154.190.208.131:41661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnpz3QAAAAw"]
[Thu Sep 17 15:17:25.319779 2026] [security2:error] [pid 971102:tid 971245] [client 24.162.197.107:37225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz1wAACwg"]
[Thu Sep 17 15:17:25.398364 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/elasticsearch/.env"] [unique_id "aqxY5ecL08BTTQixEnpz4AAAABs"]
[Thu Sep 17 15:17:25.449949 2026] [security2:error] [pid 971102:tid 971287] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxY5ecL08BTTQixEnpz5wAAADU"]
[Thu Sep 17 15:17:25.464611 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz3gAAAFs"]
[Thu Sep 17 15:17:25.578138 2026] [security2:error] [pid 971102:tid 971273] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz6gAAACc"]
[Thu Sep 17 15:17:25.605129 2026] [security2:error] [pid 971102:tid 971253] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxY5ecL08BTTQixEnpz7wAAABM"]
[Thu Sep 17 15:17:25.631056 2026] [security2:error] [pid 971102:tid 971350] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/rabbitmq/.env"] [unique_id "aqxY5ecL08BTTQixEnpz8QAAAHQ"]
[Thu Sep 17 15:17:25.648607 2026] [security2:error] [pid 971102:tid 971303] [client 34.97.30.29:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxY5ecL08BTTQixEnpz8wAAAEU"]
[Thu Sep 17 15:17:25.762839 2026] [security2:error] [pid 971102:tid 971241] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxY5ecL08BTTQixEnpz-wAAAAc"]
[Thu Sep 17 15:17:25.827418 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz9gAAACY"]
[Thu Sep 17 15:17:25.861856 2026] [security2:error] [pid 971102:tid 971268] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/kafka/.env"] [unique_id "aqxY5ecL08BTTQixEnp0AQAAACI"]
[Thu Sep 17 15:17:25.875137 2026] [security2:error] [pid 971102:tid 971355] [client 114.198.138.124:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnp0AwAAAHk"]
[Thu Sep 17 15:17:25.875301 2026] [security2:error] [pid 971102:tid 971355] [client 114.198.138.124:64865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5ecL08BTTQixEnp0AwAAAHk"]
[Thu Sep 17 15:17:25.919510 2026] [security2:error] [pid 971102:tid 971256] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxY5ecL08BTTQixEnp0BwAAABY"]
[Thu Sep 17 15:17:25.980918 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnp0AAAAABI"]
[Thu Sep 17 15:17:25.994918 2026] [security2:error] [pid 971102:tid 971348] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5ecL08BTTQixEnpz_AAAckI"]
[Thu Sep 17 15:17:26.075545 2026] [security2:error] [pid 971102:tid 971237] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxY5ucL08BTTQixEnp0EgAAAAM"]
[Thu Sep 17 15:17:26.098011 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/queue/.env"] [unique_id "aqxY5ucL08BTTQixEnp0FgAAACA"]
[Thu Sep 17 15:17:26.111522 2026] [security2:error] [pid 971102:tid 971357] [client 34.97.30.29:57036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxY5ucL08BTTQixEnp0FwAAAHs"]
[Thu Sep 17 15:17:26.170824 2026] [security2:error] [pid 971102:tid 971341] [client 47.79.4.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0DgAAAGs"]
[Thu Sep 17 15:17:26.224081 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0GAAAAEM"]
[Thu Sep 17 15:17:26.231376 2026] [security2:error] [pid 971102:tid 971246] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxY5ucL08BTTQixEnp0HwAAAAw"]
[Thu Sep 17 15:17:26.294118 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0HQAAACk"]
[Thu Sep 17 15:17:26.328707 2026] [security2:error] [pid 971102:tid 971262] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/worker/.env"] [unique_id "aqxY5ucL08BTTQixEnp0IAAAABw"]
[Thu Sep 17 15:17:26.377060 2026] [security2:error] [pid 971102:tid 971360] [client 172.239.147.162:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxY5ucL08BTTQixEnp0JQAAAH4"], referer: binance.com
[Thu Sep 17 15:17:26.389351 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxY5ucL08BTTQixEnp0JwAAADw"]
[Thu Sep 17 15:17:26.468973 2026] [security2:error] [pid 971102:tid 971350] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env.swp"] [unique_id "aqxY5ucL08BTTQixEnp0LAAAAHQ"]
[Thu Sep 17 15:17:26.551236 2026] [security2:error] [pid 971102:tid 971356] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxY5ucL08BTTQixEnp0NAAAAHo"]
[Thu Sep 17 15:17:26.552733 2026] [security2:error] [pid 971102:tid 971353] [client 34.97.30.29:57052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/site/phpinfo.php"] [unique_id "aqxY5ucL08BTTQixEnp0NgAAAHc"]
[Thu Sep 17 15:17:26.558065 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/job/.env"] [unique_id "aqxY5ucL08BTTQixEnp0NwAAABA"]
[Thu Sep 17 15:17:26.562009 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0KwAAABM"]
[Thu Sep 17 15:17:26.578763 2026] [security2:error] [pid 971102:tid 971321] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0JgAAVyM"]
[Thu Sep 17 15:17:26.620041 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.env~"] [unique_id "aqxY5ucL08BTTQixEnp0OAAAADo"]
[Thu Sep 17 15:17:26.661090 2026] [security2:error] [pid 971102:tid 971254] [client 202.46.62.14:37426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0MgAAFDU"]
[Thu Sep 17 15:17:26.715833 2026] [security2:error] [pid 971102:tid 971347] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxY5ucL08BTTQixEnp0OwAAAHE"]
[Thu Sep 17 15:17:26.787770 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/test/.env"] [unique_id "aqxY5ucL08BTTQixEnp0QAAAAHY"]
[Thu Sep 17 15:17:26.871731 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0PgAAAEg"]
[Thu Sep 17 15:17:26.878218 2026] [security2:error] [pid 971102:tid 971355] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxY5ucL08BTTQixEnp0RAAAAHk"]
[Thu Sep 17 15:17:26.986381 2026] [security2:error] [pid 971102:tid 971251] [client 34.97.30.29:57062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxY5ucL08BTTQixEnp0SQAAABE"]
[Thu Sep 17 15:17:27.018028 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/qa/.env"] [unique_id "aqxY5-cL08BTTQixEnp0TAAAAGk"]
[Thu Sep 17 15:17:27.034409 2026] [security2:error] [pid 971102:tid 971283] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxY5-cL08BTTQixEnp0TQAAADE"]
[Thu Sep 17 15:17:27.039246 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0RQAAAB0"]
[Thu Sep 17 15:17:27.071521 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env.swp"] [unique_id "aqxY5-cL08BTTQixEnp0TwAAACw"]
[Thu Sep 17 15:17:27.089097 2026] [security2:error] [pid 971102:tid 971346] [client 172.239.147.162:52073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxY5-cL08BTTQixEnp0UAAAAHA"], referer: binance.com
[Thu Sep 17 15:17:27.090495 2026] [security2:error] [pid 971102:tid 971235] [client 24.162.197.107:45317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0SwAAAQ0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821154343&hideanons=1&limit=500&target=The_Lord_Of_Dwarves&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:17:27.179915 2026] [security2:error] [pid 971102:tid 971285] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY5ucL08BTTQixEnp0SAAAMy8"]
[Thu Sep 17 15:17:27.187837 2026] [security2:error] [pid 971102:tid 971312] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxY5-cL08BTTQixEnp0UwAAAE4"]
[Thu Sep 17 15:17:27.226570 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.env~"] [unique_id "aqxY5-cL08BTTQixEnp0VgAAAEk"]
[Thu Sep 17 15:17:27.249742 2026] [security2:error] [pid 971102:tid 971322] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/preview/.env"] [unique_id "aqxY5-cL08BTTQixEnp0WgAAAFg"]
[Thu Sep 17 15:17:27.344981 2026] [security2:error] [pid 971102:tid 971288] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxY5-cL08BTTQixEnp0XAAAADY"]
[Thu Sep 17 15:17:27.346045 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0WwAAAFA"]
[Thu Sep 17 15:17:27.414114 2026] [security2:error] [pid 971102:tid 971245] [client 34.97.30.29:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxY5-cL08BTTQixEnp0YAAAAAs"]
[Thu Sep 17 15:17:27.481488 2026] [security2:error] [pid 971102:tid 971293] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/beta/.env"] [unique_id "aqxY5-cL08BTTQixEnp0YgAAADs"]
[Thu Sep 17 15:17:27.501009 2026] [security2:error] [pid 971102:tid 971327] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxY5-cL08BTTQixEnp0YwAAAF0"]
[Thu Sep 17 15:17:27.539546 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0YQAAAGE"]
[Thu Sep 17 15:17:27.637488 2026] [security2:error] [pid 971102:tid 971315] [client 186.105.232.15:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5-cL08BTTQixEnp0bQAAAFE"]
[Thu Sep 17 15:17:27.637641 2026] [security2:error] [pid 971102:tid 971315] [client 186.105.232.15:54622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY5-cL08BTTQixEnp0bQAAAFE"]
[Thu Sep 17 15:17:27.658451 2026] [security2:error] [pid 971102:tid 971305] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxY5-cL08BTTQixEnp0cwAAAEc"]
[Thu Sep 17 15:17:27.712496 2026] [security2:error] [pid 971102:tid 971253] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/uat/.env"] [unique_id "aqxY5-cL08BTTQixEnp0dgAAABM"]
[Thu Sep 17 15:17:27.753467 2026] [security2:error] [pid 971102:tid 971284] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0aAAAADI"]
[Thu Sep 17 15:17:27.814251 2026] [security2:error] [pid 971102:tid 971336] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxY5-cL08BTTQixEnp0ewAAAGY"]
[Thu Sep 17 15:17:27.836572 2026] [security2:error] [pid 971102:tid 971274] [client 34.97.30.29:57072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxY5-cL08BTTQixEnp0fAAAACg"]
[Thu Sep 17 15:17:27.881519 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0egAAADo"]
[Thu Sep 17 15:17:27.944052 2026] [security2:error] [pid 971102:tid 971296] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/stage/.env"] [unique_id "aqxY5-cL08BTTQixEnp0gAAAAD4"]
[Thu Sep 17 15:17:27.962172 2026] [security2:error] [pid 971102:tid 971239] [client 172.239.147.162:58328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxY5-cL08BTTQixEnp0ggAAAAU"], referer: binance.com
[Thu Sep 17 15:17:27.971098 2026] [security2:error] [pid 971102:tid 971355] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxY5-cL08BTTQixEnp0gwAAAHk"]
[Thu Sep 17 15:17:28.041317 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY5-cL08BTTQixEnp0gQAAACY"]
[Thu Sep 17 15:17:28.127505 2026] [security2:error] [pid 971102:tid 971310] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxY6OcL08BTTQixEnp0jgAAAEw"]
[Thu Sep 17 15:17:28.176344 2026] [security2:error] [pid 971102:tid 971264] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/development/.env"] [unique_id "aqxY6OcL08BTTQixEnp0kAAAAB4"]
[Thu Sep 17 15:17:28.186259 2026] [security2:error] [pid 971102:tid 971249] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0iwAAAA8"]
[Thu Sep 17 15:17:28.283164 2026] [security2:error] [pid 971102:tid 971341] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxY6OcL08BTTQixEnp0kwAAAGs"]
[Thu Sep 17 15:17:28.306903 2026] [security2:error] [pid 971102:tid 971235] [client 34.97.30.29:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/core/phpinfo.php"] [unique_id "aqxY6OcL08BTTQixEnp0lgAAAAE"]
[Thu Sep 17 15:17:28.321192 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:56412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0kQAAACU"]
[Thu Sep 17 15:17:28.407383 2026] [security2:error] [pid 971102:tid 971340] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/production/.env"] [unique_id "aqxY6OcL08BTTQixEnp0mgAAAGo"]
[Thu Sep 17 15:17:28.443179 2026] [security2:error] [pid 971102:tid 971269] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxY6OcL08BTTQixEnp0mwAAACM"]
[Thu Sep 17 15:17:28.462354 2026] [security2:error] [pid 971102:tid 971307] [client 172.239.147.162:57212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wp-view-config-data.php"] [unique_id "aqxY6OcL08BTTQixEnp0nQAAAEk"], referer: binance.com
[Thu Sep 17 15:17:28.509031 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0mQAAAFA"]
[Thu Sep 17 15:17:28.603378 2026] [security2:error] [pid 971102:tid 971359] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0pQAAAH0"]
[Thu Sep 17 15:17:28.607355 2026] [security2:error] [pid 971102:tid 971281] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxY6OcL08BTTQixEnp0qAAAAC8"]
[Thu Sep 17 15:17:28.612790 2026] [security2:error] [pid 971102:tid 971312] [client 202.46.62.118:2212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0oAAAAE4"]
[Thu Sep 17 15:17:28.637646 2026] [security2:error] [pid 971102:tid 971305] [client 34.166.218.131:47948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/config/app/.env"] [unique_id "aqxY6OcL08BTTQixEnp0qwAAAEc"]
[Thu Sep 17 15:17:28.705640 2026] [security2:error] [pid 971102:tid 971331] [client 34.97.30.29:57084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.30.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ahmedteleb.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxY6OcL08BTTQixEnp0rQAAAGE"]
[Thu Sep 17 15:17:28.764415 2026] [security2:error] [pid 971102:tid 971286] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxY6OcL08BTTQixEnp0rwAAADQ"]
[Thu Sep 17 15:17:28.774156 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:56458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0rAAAABA"]
[Thu Sep 17 15:17:28.882975 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.218.131:47948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxY6OcL08BTTQixEnp0twAAAAQ"]
[Thu Sep 17 15:17:28.917354 2026] [security2:error] [pid 971102:tid 971274] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxY6OcL08BTTQixEnp0ugAAACg"]
[Thu Sep 17 15:17:28.938201 2026] [security2:error] [pid 971102:tid 971287] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0tgAAADU"]
[Thu Sep 17 15:17:29.076529 2026] [security2:error] [pid 971102:tid 971259] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxY6ecL08BTTQixEnp0xAAAABk"]
[Thu Sep 17 15:17:29.105875 2026] [security2:error] [pid 971102:tid 971309] [client 79.177.151.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxY6OcL08BTTQixEnp0wQAAAEs"], referer: https://languageandsociety.co.il/wp-content/uploads/2022/12/conf15_short_3-7-2016.pdf?utm_source=chatgpt.com
[Thu Sep 17 15:17:29.122391 2026] [security2:error] [pid 971102:tid 971265] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/app/.env"] [unique_id "aqxY6ecL08BTTQixEnp0xwAAAB8"]
[Thu Sep 17 15:17:29.153439 2026] [security2:error] [pid 971102:tid 971342] [client 156.192.234.52:51350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY6ecL08BTTQixEnp0ywAAAGw"]
[Thu Sep 17 15:17:29.154836 2026] [security2:error] [pid 971102:tid 971342] [client 156.192.234.52:51350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY6ecL08BTTQixEnp0ywAAAGw"]
[Thu Sep 17 15:17:29.229323 2026] [security2:error] [pid 971102:tid 971255] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxY6ecL08BTTQixEnp0zgAAABU"]
[Thu Sep 17 15:17:29.247237 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6ecL08BTTQixEnp0ygAAAEg"]
[Thu Sep 17 15:17:29.279142 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/apps/.env"] [unique_id "aqxY6ecL08BTTQixEnp00AAAAAI"]
[Thu Sep 17 15:17:29.389458 2026] [security2:error] [pid 971102:tid 971243] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxY6ecL08BTTQixEnp01AAAAAk"]
[Thu Sep 17 15:17:29.437483 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/.env"] [unique_id "aqxY6ecL08BTTQixEnp03gAAAAE"]
[Thu Sep 17 15:17:29.468004 2026] [access_compat:error] [pid 971102:tid 971252] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/jixo-5-mask-parade-collectors-edition
[Thu Sep 17 15:17:29.545113 2026] [core:error] [pid 971102:tid 971348] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:17:29.545136 2026] [core:error] [pid 971102:tid 971348] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:17:29.546963 2026] [security2:error] [pid 971102:tid 971327] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxY6ecL08BTTQixEnp06wAAAF0"]
[Thu Sep 17 15:17:29.564702 2026] [security2:error] [pid 971102:tid 971251] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6ecL08BTTQixEnp03wAAABE"]
[Thu Sep 17 15:17:29.580626 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.218.131:50086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/info.php"] [unique_id "aqxY6ecL08BTTQixEnp07QAAAA8"]
[Thu Sep 17 15:17:29.605372 2026] [security2:error] [pid 971102:tid 971335] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/web/.env"] [unique_id "aqxY6ecL08BTTQixEnp07gAAAGU"]
[Thu Sep 17 15:17:29.702360 2026] [security2:error] [pid 971102:tid 971305] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxY6ecL08BTTQixEnp08QAAAEc"]
[Thu Sep 17 15:17:29.718785 2026] [security2:error] [pid 971102:tid 971313] [client 92.99.250.61:34050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aau.oxd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY6ecL08BTTQixEnp06QAAT10"]
[Thu Sep 17 15:17:29.758479 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/site/.env"] [unique_id "aqxY6ecL08BTTQixEnp09AAAAFI"]
[Thu Sep 17 15:17:29.779302 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/app/.env"] [unique_id "aqxY6ecL08BTTQixEnp09QAAAFw"]
[Thu Sep 17 15:17:29.856401 2026] [security2:error] [pid 971102:tid 971282] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxY6ecL08BTTQixEnp0_AAAADA"]
[Thu Sep 17 15:17:29.913846 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/public/.env"] [unique_id "aqxY6ecL08BTTQixEnp0_wAAABo"]
[Thu Sep 17 15:17:29.940764 2026] [security2:error] [pid 971102:tid 971238] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/apps/.env"] [unique_id "aqxY6ecL08BTTQixEnp1AAAAAAQ"]
[Thu Sep 17 15:17:30.009307 2026] [security2:error] [pid 971102:tid 971350] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxY6ucL08BTTQixEnp1CAAAAHQ"]
[Thu Sep 17 15:17:30.095930 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/.env"] [unique_id "aqxY6ucL08BTTQixEnp1EAAAAHs"]
[Thu Sep 17 15:17:30.164369 2026] [security2:error] [pid 971102:tid 971292] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxY6ucL08BTTQixEnp1EwAAADo"]
[Thu Sep 17 15:17:30.208292 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY6ucL08BTTQixEnp1DwAAAAg"]
[Thu Sep 17 15:17:30.272102 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.218.131:39532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/php.php"] [unique_id "aqxY6ucL08BTTQixEnp1FwAAAFM"]
[Thu Sep 17 15:17:30.272251 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/web/.env"] [unique_id "aqxY6ucL08BTTQixEnp1FgAAAAY"]
[Thu Sep 17 15:17:30.323194 2026] [security2:error] [pid 971102:tid 971297] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxY6ucL08BTTQixEnp1GwAAAD8"]
[Thu Sep 17 15:17:30.349358 2026] [security2:error] [pid 971102:tid 971342] [client 172.239.147.162:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxY6ucL08BTTQixEnp1HAAAAGw"], referer: binance.com
[Thu Sep 17 15:17:30.396042 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/backend/.env"] [unique_id "aqxY6ucL08BTTQixEnp1IQAAAB4"]
[Thu Sep 17 15:17:30.400121 2026] [authz_core:error] [pid 971102:tid 971267] [client 5.189.145.112:51627] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:30.427867 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/site/.env"] [unique_id "aqxY6ucL08BTTQixEnp1IgAAAEU"]
[Thu Sep 17 15:17:30.450335 2026] [security2:error] [pid 971102:tid 971334] [client 172.239.147.162:57999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxY6ucL08BTTQixEnp1IwAAAGQ"], referer: binance.com
[Thu Sep 17 15:17:30.494095 2026] [security2:error] [pid 971102:tid 971328] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxY6ucL08BTTQixEnp1JwAAAF4"]
[Thu Sep 17 15:17:30.552034 2026] [security2:error] [pid 971102:tid 971257] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/server/.env"] [unique_id "aqxY6ucL08BTTQixEnp1KgAAABc"]
[Thu Sep 17 15:17:30.596275 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/public/.env"] [unique_id "aqxY6ucL08BTTQixEnp1LQAAACU"]
[Thu Sep 17 15:17:30.648907 2026] [security2:error] [pid 971102:tid 971351] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxY6ucL08BTTQixEnp1MAAAAHU"]
[Thu Sep 17 15:17:30.708801 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/frontend/.env"] [unique_id "aqxY6ucL08BTTQixEnp1MQAAAAA"]
[Thu Sep 17 15:17:30.812235 2026] [security2:error] [pid 971102:tid 971341] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxY6ucL08BTTQixEnp1NgAAAGs"]
[Thu Sep 17 15:17:30.861708 2026] [security2:error] [pid 971102:tid 971289] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/src/.env"] [unique_id "aqxY6ucL08BTTQixEnp1NwAAADc"]
[Thu Sep 17 15:17:30.962165 2026] [security2:error] [pid 971102:tid 971249] [client 34.166.218.131:39546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/i.php"] [unique_id "aqxY6ucL08BTTQixEnp1PAAAAA8"]
[Thu Sep 17 15:17:30.971774 2026] [security2:error] [pid 971102:tid 971359] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxY6ucL08BTTQixEnp1PQAAAH0"]
[Thu Sep 17 15:17:31.000507 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY6ucL08BTTQixEnp1OQAAAFE"]
[Thu Sep 17 15:17:31.013268 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/core/.env"] [unique_id "aqxY6-cL08BTTQixEnp1QAAAAGA"]
[Thu Sep 17 15:17:31.125406 2026] [security2:error] [pid 971102:tid 971260] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxY6-cL08BTTQixEnp1RQAAABo"]
[Thu Sep 17 15:17:31.168142 2026] [security2:error] [pid 971102:tid 971238] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/core/app/.env"] [unique_id "aqxY6-cL08BTTQixEnp1RgAAAAQ"]
[Thu Sep 17 15:17:31.185709 2026] [security2:error] [pid 971102:tid 971244] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/backend/.env"] [unique_id "aqxY6-cL08BTTQixEnp1SAAAAAo"]
[Thu Sep 17 15:17:31.279440 2026] [security2:error] [pid 971102:tid 971259] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxY6-cL08BTTQixEnp1TAAAABk"]
[Thu Sep 17 15:17:31.304434 2026] [security2:error] [pid 971102:tid 971350] [client 127.0.0.1:10178] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxY6-cL08BTTQixEnp1SwAAAHQ"]
[Thu Sep 17 15:17:31.304455 2026] [security2:error] [pid 971102:tid 971302] [client 74.7.175.161:48914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.comfortspecialist.info"] [uri "/robots.txt"] [unique_id "aqxY6-cL08BTTQixEnp1SgAARH4"]
[Thu Sep 17 15:17:31.329935 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/config/.env"] [unique_id "aqxY6-cL08BTTQixEnp1TQAAAHs"]
[Thu Sep 17 15:17:31.347096 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/server/.env"] [unique_id "aqxY6-cL08BTTQixEnp1TgAAAD4"]
[Thu Sep 17 15:17:31.433933 2026] [security2:error] [pid 971102:tid 971319] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxY6-cL08BTTQixEnp1UgAAAFU"]
[Thu Sep 17 15:17:31.489168 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/private/.env"] [unique_id "aqxY6-cL08BTTQixEnp1VgAAAAY"]
[Thu Sep 17 15:17:31.503967 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/frontend/.env"] [unique_id "aqxY6-cL08BTTQixEnp1VwAAAAU"]
[Thu Sep 17 15:17:31.588722 2026] [security2:error] [pid 971102:tid 971310] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxY6-cL08BTTQixEnp1XAAAAEw"]
[Thu Sep 17 15:17:31.643562 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/application/.env"] [unique_id "aqxY6-cL08BTTQixEnp1XgAAAAM"]
[Thu Sep 17 15:17:31.657776 2026] [security2:error] [pid 971102:tid 971255] [client 34.166.218.131:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxY6-cL08BTTQixEnp1XwAAABU"]
[Thu Sep 17 15:17:31.659100 2026] [security2:error] [pid 971102:tid 971241] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/src/.env"] [unique_id "aqxY6-cL08BTTQixEnp1YAAAAAc"]
[Thu Sep 17 15:17:31.742305 2026] [security2:error] [pid 971102:tid 971267] [client 34.154.67.31:52836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxY6-cL08BTTQixEnp1YwAAACE"]
[Thu Sep 17 15:17:31.797065 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/bootstrap/.env"] [unique_id "aqxY6-cL08BTTQixEnp1ZwAAAEU"]
[Thu Sep 17 15:17:31.816017 2026] [security2:error] [pid 971102:tid 971334] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/core/.env"] [unique_id "aqxY6-cL08BTTQixEnp1aAAAAGQ"]
[Thu Sep 17 15:17:31.897632 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxY6-cL08BTTQixEnp1agAAACU"]
[Thu Sep 17 15:17:31.966900 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/database/.env"] [unique_id "aqxY6-cL08BTTQixEnp1bgAAAB0"]
[Thu Sep 17 15:17:31.977554 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/core/app/.env"] [unique_id "aqxY6-cL08BTTQixEnp1cAAAAHI"]
[Thu Sep 17 15:17:32.155189 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/config/.env"] [unique_id "aqxY7OcL08BTTQixEnp1eQAAAGs"]
[Thu Sep 17 15:17:32.158847 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/storage/.env"] [unique_id "aqxY7OcL08BTTQixEnp1egAAAE4"]
[Thu Sep 17 15:17:32.321046 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/var/www/.env"] [unique_id "aqxY7OcL08BTTQixEnp1fAAAAEc"]
[Thu Sep 17 15:17:32.363582 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:39564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxY7OcL08BTTQixEnp1fQAAADw"]
[Thu Sep 17 15:17:32.365099 2026] [security2:error] [pid 971102:tid 971304] [client 34.154.67.31:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/info.php"] [unique_id "aqxY7OcL08BTTQixEnp1fwAAAEY"]
[Thu Sep 17 15:17:32.365651 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/private/.env"] [unique_id "aqxY7OcL08BTTQixEnp1fgAAAE8"]
[Thu Sep 17 15:17:32.429254 2026] [security2:error] [pid 971102:tid 971261] [client 172.239.147.162:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxY7OcL08BTTQixEnp1ggAAABs"], referer: binance.com
[Thu Sep 17 15:17:32.493375 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/var/www/html/.env"] [unique_id "aqxY7OcL08BTTQixEnp1hAAAAGA"]
[Thu Sep 17 15:17:32.536509 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/application/.env"] [unique_id "aqxY7OcL08BTTQixEnp1igAAACw"]
[Thu Sep 17 15:17:32.603958 2026] [security2:error] [pid 971102:tid 971315] [client 172.239.147.162:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxY7OcL08BTTQixEnp1iwAAAFE"], referer: binance.com
[Thu Sep 17 15:17:32.674267 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/current/.env"] [unique_id "aqxY7OcL08BTTQixEnp1jgAAAGY"]
[Thu Sep 17 15:17:32.723098 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/bootstrap/.env"] [unique_id "aqxY7OcL08BTTQixEnp1jwAAAG4"]
[Thu Sep 17 15:17:32.855704 2026] [security2:error] [pid 971102:tid 971279] [client 34.154.67.31:34764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/php.php"] [unique_id "aqxY7OcL08BTTQixEnp1kQAAAC0"]
[Thu Sep 17 15:17:32.877856 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/release/.env"] [unique_id "aqxY7OcL08BTTQixEnp1kgAAAD4"]
[Thu Sep 17 15:17:32.900922 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/database/.env"] [unique_id "aqxY7OcL08BTTQixEnp1kwAAAH4"]
[Thu Sep 17 15:17:33.047278 2026] [security2:error] [pid 971102:tid 971273] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/releases/.env"] [unique_id "aqxY7ecL08BTTQixEnp1mAAAACc"]
[Thu Sep 17 15:17:33.056215 2026] [security2:error] [pid 971102:tid 971302] [client 34.166.218.131:39568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/test.php"] [unique_id "aqxY7ecL08BTTQixEnp1mQAAAEQ"]
[Thu Sep 17 15:17:33.078997 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/storage/.env"] [unique_id "aqxY7ecL08BTTQixEnp1mwAAADA"]
[Thu Sep 17 15:17:33.165338 2026] [security2:error] [pid 971102:tid 971323] [client 157.90.156.63:19016] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxY7ecL08BTTQixEnp1nQAAAFk"], referer: https://eris.media
[Thu Sep 17 15:17:33.245167 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/var/www/.env"] [unique_id "aqxY7ecL08BTTQixEnp1ngAAAAU"]
[Thu Sep 17 15:17:33.250358 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/shared/.env"] [unique_id "aqxY7ecL08BTTQixEnp1nwAAAA0"]
[Thu Sep 17 15:17:33.331089 2026] [security2:error] [pid 971102:tid 971240] [client 34.154.67.31:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/i.php"] [unique_id "aqxY7ecL08BTTQixEnp1ogAAAAY"]
[Thu Sep 17 15:17:33.404978 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/var/www/html/.env"] [unique_id "aqxY7ecL08BTTQixEnp1owAAAB4"]
[Thu Sep 17 15:17:33.415150 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/deploy/.env"] [unique_id "aqxY7ecL08BTTQixEnp1pAAAAAg"]
[Thu Sep 17 15:17:33.520603 2026] [security2:error] [pid 971102:tid 971284] [client 104.28.198.244:22762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ecL08BTTQixEnp1qAAAADI"]
[Thu Sep 17 15:17:33.520728 2026] [security2:error] [pid 971102:tid 971284] [client 104.28.198.244:22762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ecL08BTTQixEnp1qAAAADI"]
[Thu Sep 17 15:17:33.572531 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/current/.env"] [unique_id "aqxY7ecL08BTTQixEnp1qwAAAAk"]
[Thu Sep 17 15:17:33.621550 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/build/.env"] [unique_id "aqxY7ecL08BTTQixEnp1rQAAABY"]
[Thu Sep 17 15:17:33.681431 2026] [security2:error] [pid 971102:tid 971272] [client 172.239.147.162:55405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxY7ecL08BTTQixEnp1sQAAACY"], referer: binance.com
[Thu Sep 17 15:17:33.738802 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/release/.env"] [unique_id "aqxY7ecL08BTTQixEnp1swAAAEg"]
[Thu Sep 17 15:17:33.790010 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/dist/.env"] [unique_id "aqxY7ecL08BTTQixEnp1tgAAABM"]
[Thu Sep 17 15:17:33.795490 2026] [security2:error] [pid 971102:tid 971257] [client 34.154.67.31:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxY7ecL08BTTQixEnp1twAAABc"]
[Thu Sep 17 15:17:33.919366 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/releases/.env"] [unique_id "aqxY7ecL08BTTQixEnp1ugAAAGs"]
[Thu Sep 17 15:17:33.955674 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/public_html/.env"] [unique_id "aqxY7ecL08BTTQixEnp1vAAAAHE"]
[Thu Sep 17 15:17:34.006068 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.208.101:41724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY7ucL08BTTQixEnp1vwAAAEk"]
[Thu Sep 17 15:17:34.061968 2026] [security2:error] [pid 971102:tid 971261] [client 34.166.218.131:39584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/p.php"] [unique_id "aqxY7ucL08BTTQixEnp1wQAAABs"]
[Thu Sep 17 15:17:34.087766 2026] [security2:error] [pid 971102:tid 971359] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/shared/.env"] [unique_id "aqxY7ucL08BTTQixEnp1wgAAAH0"]
[Thu Sep 17 15:17:34.109572 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/htdocs/.env"] [unique_id "aqxY7ucL08BTTQixEnp1wwAAAFw"]
[Thu Sep 17 15:17:34.136713 2026] [security2:error] [pid 971102:tid 971305] [client 172.239.147.162:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxY7ucL08BTTQixEnp1xQAAAEc"], referer: binance.com
[Thu Sep 17 15:17:34.152975 2026] [security2:error] [pid 971102:tid 971294] [client 45.169.98.18:59793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp1xwAAADw"]
[Thu Sep 17 15:17:34.153075 2026] [security2:error] [pid 971102:tid 971294] [client 45.169.98.18:59793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp1xwAAADw"]
[Thu Sep 17 15:17:34.255761 2026] [security2:error] [pid 971102:tid 971330] [client 34.154.67.31:34804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxY7ucL08BTTQixEnp1zAAAAGA"]
[Thu Sep 17 15:17:34.283667 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/www/.env"] [unique_id "aqxY7ucL08BTTQixEnp1zQAAAD0"]
[Thu Sep 17 15:17:34.305354 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/deploy/.env"] [unique_id "aqxY7ucL08BTTQixEnp1zgAAAG4"]
[Thu Sep 17 15:17:34.365807 2026] [security2:error] [pid 971102:tid 971308] [client 185.55.149.49:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp10AAAAEo"]
[Thu Sep 17 15:17:34.365914 2026] [security2:error] [pid 971102:tid 971308] [client 185.55.149.49:54225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY7ucL08BTTQixEnp10AAAAEo"]
[Thu Sep 17 15:17:34.443280 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/html/.env"] [unique_id "aqxY7ucL08BTTQixEnp10QAAAG0"]
[Thu Sep 17 15:17:34.470220 2026] [security2:error] [pid 971102:tid 971259] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/build/.env"] [unique_id "aqxY7ucL08BTTQixEnp10wAAABk"]
[Thu Sep 17 15:17:34.611354 2026] [security2:error] [pid 971102:tid 971329] [client 78.46.190.63:55926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxY7ucL08BTTQixEnp12AAAAF8"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:17:34.619004 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/live/.env"] [unique_id "aqxY7ucL08BTTQixEnp12QAAAEQ"]
[Thu Sep 17 15:17:34.639025 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/dist/.env"] [unique_id "aqxY7ucL08BTTQixEnp12gAAADA"]
[Thu Sep 17 15:17:34.698709 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.208.101:55870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY7ucL08BTTQixEnp13gAAAFI"]
[Thu Sep 17 15:17:34.752332 2026] [security2:error] [pid 971102:tid 971273] [client 34.154.67.31:34806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/test.php"] [unique_id "aqxY7ucL08BTTQixEnp13wAAACc"]
[Thu Sep 17 15:17:34.757653 2026] [security2:error] [pid 971102:tid 971245] [client 34.166.218.131:39598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxY7ucL08BTTQixEnp14AAAAAs"]
[Thu Sep 17 15:17:34.778484 2026] [security2:error] [pid 971102:tid 971317] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/prod/.env"] [unique_id "aqxY7ucL08BTTQixEnp14QAAAFM"]
[Thu Sep 17 15:17:34.812793 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/public_html/.env"] [unique_id "aqxY7ucL08BTTQixEnp14gAAAFo"]
[Thu Sep 17 15:17:34.849472 2026] [security2:error] [pid 971102:tid 971254] [client 44.239.144.77:55346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxY7OcL08BTTQixEnp1lwAAABQ"], referer: http://worthtranslations.com/new
[Thu Sep 17 15:17:34.934330 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/dev/.env"] [unique_id "aqxY7ucL08BTTQixEnp15gAAAAM"]
[Thu Sep 17 15:17:34.984327 2026] [security2:error] [pid 971102:tid 971267] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/htdocs/.env"] [unique_id "aqxY7ucL08BTTQixEnp16wAAACE"]
[Thu Sep 17 15:17:35.066701 2026] [security2:error] [pid 971102:tid 971349] [client 34.95.173.223:52796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php"] [unique_id "aqxY7-cL08BTTQixEnp17AAAAHM"]
[Thu Sep 17 15:17:35.087495 2026] [security2:error] [pid 971102:tid 971319] [client 78.46.190.63:55940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxY7-cL08BTTQixEnp17QAAAFU"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:17:35.108833 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/staging/.env"] [unique_id "aqxY7-cL08BTTQixEnp17wAAAAk"]
[Thu Sep 17 15:17:35.187292 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/www/.env"] [unique_id "aqxY7-cL08BTTQixEnp18QAAAHU"]
[Thu Sep 17 15:17:35.243226 2026] [security2:error] [pid 971102:tid 971256] [client 172.239.147.162:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxY7-cL08BTTQixEnp19gAAABY"], referer: binance.com
[Thu Sep 17 15:17:35.261918 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/opt/.env"] [unique_id "aqxY7-cL08BTTQixEnp19wAAABM"]
[Thu Sep 17 15:17:35.359839 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/html/.env"] [unique_id "aqxY7-cL08BTTQixEnp1-AAAACs"]
[Thu Sep 17 15:17:35.399986 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.208.101:55884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY7-cL08BTTQixEnp1-QAAACY"]
[Thu Sep 17 15:17:35.423139 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/laravel/.env"] [unique_id "aqxY7-cL08BTTQixEnp1-gAAAAE"]
[Thu Sep 17 15:17:35.460973 2026] [security2:error] [pid 971102:tid 971309] [client 34.166.218.131:39608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxY7-cL08BTTQixEnp1-wAAAEs"]
[Thu Sep 17 15:17:35.529795 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/live/.env"] [unique_id "aqxY7-cL08BTTQixEnp1_gAAACQ"]
[Thu Sep 17 15:17:35.578066 2026] [security2:error] [pid 971102:tid 971266] [client 34.95.173.223:42246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/info.php"] [unique_id "aqxY7-cL08BTTQixEnp2AQAAACA"]
[Thu Sep 17 15:17:35.586053 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:56412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/symfony/.env"] [unique_id "aqxY7-cL08BTTQixEnp2AgAAAHE"]
[Thu Sep 17 15:17:35.657401 2026] [security2:error] [pid 971102:tid 971236] [client 172.239.147.162:61566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxY7-cL08BTTQixEnp2AwAAAAI"], referer: binance.com
[Thu Sep 17 15:17:35.687336 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/prod/.env"] [unique_id "aqxY7-cL08BTTQixEnp2BQAAAE8"]
[Thu Sep 17 15:17:35.754418 2026] [security2:error] [pid 971102:tid 971246] [client 34.154.67.31:34818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/p.php"] [unique_id "aqxY7-cL08BTTQixEnp2CAAAAAw"]
[Thu Sep 17 15:17:35.857850 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/dev/.env"] [unique_id "aqxY7-cL08BTTQixEnp2DAAAADo"]
[Thu Sep 17 15:17:35.858377 2026] [security2:error] [pid 971102:tid 971327] [client 154.190.208.131:42269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7-cL08BTTQixEnp2DQAAAF0"]
[Thu Sep 17 15:17:35.864574 2026] [security2:error] [pid 971102:tid 971327] [client 154.190.208.131:42269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY7-cL08BTTQixEnp2DQAAAF0"]
[Thu Sep 17 15:17:36.023172 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/staging/.env"] [unique_id "aqxY8OcL08BTTQixEnp2EgAAAEo"]
[Thu Sep 17 15:17:36.067380 2026] [security2:error] [pid 971102:tid 971330] [client 34.95.173.223:42260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/php.php"] [unique_id "aqxY8OcL08BTTQixEnp2EwAAAGA"]
[Thu Sep 17 15:17:36.110890 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/wordpress/.env"] [unique_id "aqxY8OcL08BTTQixEnp2FwAAACw"]
[Thu Sep 17 15:17:36.140928 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.218.131:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxY8OcL08BTTQixEnp2GAAAAFs"]
[Thu Sep 17 15:17:36.194618 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/opt/.env"] [unique_id "aqxY8OcL08BTTQixEnp2GwAAAH4"]
[Thu Sep 17 15:17:36.234699 2026] [security2:error] [pid 971102:tid 971343] [client 34.154.67.31:34508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxY8OcL08BTTQixEnp2HQAAAG0"]
[Thu Sep 17 15:17:36.277371 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/wp/.env"] [unique_id "aqxY8OcL08BTTQixEnp2HgAAAEQ"]
[Thu Sep 17 15:17:36.348092 2026] [security2:error] [pid 971102:tid 971296] [client 172.239.147.162:57447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxY8OcL08BTTQixEnp2IQAAAD4"], referer: binance.com
[Thu Sep 17 15:17:36.362891 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/laravel/.env"] [unique_id "aqxY8OcL08BTTQixEnp2IgAAAAs"]
[Thu Sep 17 15:17:36.448527 2026] [security2:error] [pid 971102:tid 971237] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cms/.env"] [unique_id "aqxY8OcL08BTTQixEnp2JAAAAAM"]
[Thu Sep 17 15:17:36.540461 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.208.101:55898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/"] [unique_id "aqxY8OcL08BTTQixEnp2KAAAAEU"]
[Thu Sep 17 15:17:36.553650 2026] [security2:error] [pid 971102:tid 971349] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/symfony/.env"] [unique_id "aqxY8OcL08BTTQixEnp2KQAAAHM"]
[Thu Sep 17 15:17:36.566745 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.173.223:42268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/i.php"] [unique_id "aqxY8OcL08BTTQixEnp2KgAAABQ"]
[Thu Sep 17 15:17:36.585427 2026] [security2:error] [pid 971102:tid 971251] [client 114.198.138.124:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8OcL08BTTQixEnp2KwAAABE"]
[Thu Sep 17 15:17:36.585520 2026] [security2:error] [pid 971102:tid 971251] [client 114.198.138.124:65504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8OcL08BTTQixEnp2KwAAABE"]
[Thu Sep 17 15:17:36.627003 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/drupal/.env"] [unique_id "aqxY8OcL08BTTQixEnp2LQAAADY"]
[Thu Sep 17 15:17:36.717008 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/wordpress/.env"] [unique_id "aqxY8OcL08BTTQixEnp2LwAAAEY"]
[Thu Sep 17 15:17:36.719902 2026] [security2:error] [pid 971102:tid 971271] [client 34.154.67.31:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxY8OcL08BTTQixEnp2MAAAACU"]
[Thu Sep 17 15:17:36.799638 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/joomla/.env"] [unique_id "aqxY8OcL08BTTQixEnp2MgAAABM"]
[Thu Sep 17 15:17:36.829082 2026] [security2:error] [pid 971102:tid 971352] [client 34.166.218.131:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxY8OcL08BTTQixEnp2NQAAAHY"]
[Thu Sep 17 15:17:36.903870 2026] [security2:error] [pid 971102:tid 971301] [client 217.138.10.135:15352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.10.138.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxY8OcL08BTTQixEnp2NgAAAEM"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:17:36.904020 2026] [security2:error] [pid 971102:tid 971301] [client 217.138.10.135:15352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxY8OcL08BTTQixEnp2NgAAAEM"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:17:36.907103 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/wp/.env"] [unique_id "aqxY8OcL08BTTQixEnp2NwAAAAY"]
[Thu Sep 17 15:17:36.971294 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/magento/.env"] [unique_id "aqxY8OcL08BTTQixEnp2OAAAACs"]
[Thu Sep 17 15:17:37.068923 2026] [security2:error] [pid 971102:tid 971354] [client 34.95.173.223:42274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/pi.php"] [unique_id "aqxY8ecL08BTTQixEnp2OwAAAHg"]
[Thu Sep 17 15:17:37.092964 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cms/.env"] [unique_id "aqxY8ecL08BTTQixEnp2PAAAACA"]
[Thu Sep 17 15:17:37.129044 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/shopify/.env"] [unique_id "aqxY8ecL08BTTQixEnp2PwAAAE8"]
[Thu Sep 17 15:17:37.198232 2026] [security2:error] [pid 971102:tid 971361] [client 34.154.67.31:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2QQAAAH8"]
[Thu Sep 17 15:17:37.254677 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env"] [unique_id "aqxY8ecL08BTTQixEnp2QgAAAAE"]
[Thu Sep 17 15:17:37.277092 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/drupal/.env"] [unique_id "aqxY8ecL08BTTQixEnp2QwAAAFw"]
[Thu Sep 17 15:17:37.285698 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/prestashop/.env"] [unique_id "aqxY8ecL08BTTQixEnp2RAAAAEc"]
[Thu Sep 17 15:17:37.442604 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/joomla/.env"] [unique_id "aqxY8ecL08BTTQixEnp2RgAAABA"]
[Thu Sep 17 15:17:37.449294 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/codeigniter/.env"] [unique_id "aqxY8ecL08BTTQixEnp2RwAAADo"]
[Thu Sep 17 15:17:37.514328 2026] [security2:error] [pid 971102:tid 971294] [client 172.239.147.162:59902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxY8ecL08BTTQixEnp2SgAAADw"], referer: binance.com
[Thu Sep 17 15:17:37.522484 2026] [security2:error] [pid 971102:tid 971252] [client 34.166.218.131:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2SwAAABI"]
[Thu Sep 17 15:17:37.553596 2026] [security2:error] [pid 971102:tid 971264] [client 34.95.173.223:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/pinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2TgAAAB4"]
[Thu Sep 17 15:17:37.623684 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/magento/.env"] [unique_id "aqxY8ecL08BTTQixEnp2UAAAAHk"]
[Thu Sep 17 15:17:37.632317 2026] [security2:error] [pid 971102:tid 971337] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cakephp/.env"] [unique_id "aqxY8ecL08BTTQixEnp2UQAAAGc"]
[Thu Sep 17 15:17:37.633218 2026] [security2:error] [pid 971102:tid 971110] [remote 111.225.148.196:24980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/224-Scavenger-Hunt-300x225.jpg"] [unique_id "aqxY8ecL08BTTQixEnp2UgAAXQY"]
[Thu Sep 17 15:17:37.683801 2026] [security2:error] [pid 971102:tid 971234] [client 34.154.67.31:34532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxY8ecL08BTTQixEnp2UwAAAAA"]
[Thu Sep 17 15:17:37.809172 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/zend/.env"] [unique_id "aqxY8ecL08BTTQixEnp2VwAAAF8"]
[Thu Sep 17 15:17:37.963693 2026] [security2:error] [pid 971102:tid 971317] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/yii/.env"] [unique_id "aqxY8ecL08BTTQixEnp2XwAAAFM"]
[Thu Sep 17 15:17:38.040440 2026] [security2:error] [pid 971102:tid 971262] [client 34.95.173.223:42296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/test.php"] [unique_id "aqxY8ucL08BTTQixEnp2YgAAABw"]
[Thu Sep 17 15:17:38.129408 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/laravel5/.env"] [unique_id "aqxY8ucL08BTTQixEnp2ZwAAAGY"]
[Thu Sep 17 15:17:38.143623 2026] [security2:error] [pid 971102:tid 971344] [client 34.154.67.31:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2aAAAAG4"]
[Thu Sep 17 15:17:38.177582 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/shopify/.env"] [unique_id "aqxY8ucL08BTTQixEnp2aQAAAAU"]
[Thu Sep 17 15:17:38.219297 2026] [security2:error] [pid 971102:tid 971283] [client 34.166.218.131:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2bAAAADE"]
[Thu Sep 17 15:17:38.300209 2026] [security2:error] [pid 971102:tid 971346] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/v1/.env"] [unique_id "aqxY8ucL08BTTQixEnp2bgAAAHA"]
[Thu Sep 17 15:17:38.375791 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/prestashop/.env"] [unique_id "aqxY8ucL08BTTQixEnp2cAAAAB0"]
[Thu Sep 17 15:17:38.450257 2026] [security2:error] [pid 971102:tid 971288] [client 172.239.147.162:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxY8ucL08BTTQixEnp2cgAAADY"], referer: binance.com
[Thu Sep 17 15:17:38.469168 2026] [security2:error] [pid 971102:tid 971352] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/v2/.env"] [unique_id "aqxY8ucL08BTTQixEnp2dQAAAHY"]
[Thu Sep 17 15:17:38.515481 2026] [security2:error] [pid 971102:tid 971297] [client 186.105.232.15:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8ucL08BTTQixEnp2dgAAAD8"]
[Thu Sep 17 15:17:38.515671 2026] [security2:error] [pid 971102:tid 971297] [client 186.105.232.15:55279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8ucL08BTTQixEnp2dgAAAD8"]
[Thu Sep 17 15:17:38.535410 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/codeigniter/.env"] [unique_id "aqxY8ucL08BTTQixEnp2eAAAAEM"]
[Thu Sep 17 15:17:38.633522 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/v3/.env"] [unique_id "aqxY8ucL08BTTQixEnp2ewAAAAg"]
[Thu Sep 17 15:17:38.634679 2026] [security2:error] [pid 971102:tid 971274] [client 34.154.67.31:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2fAAAACg"]
[Thu Sep 17 15:17:38.714352 2026] [security2:error] [pid 971102:tid 971345] [client 34.95.173.223:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/p.php"] [unique_id "aqxY8ucL08BTTQixEnp2gwAAAG8"]
[Thu Sep 17 15:17:38.723608 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cakephp/.env"] [unique_id "aqxY8ucL08BTTQixEnp2hAAAAE8"]
[Thu Sep 17 15:17:38.803112 2026] [security2:error] [pid 971102:tid 971361] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/v1/.env"] [unique_id "aqxY8ucL08BTTQixEnp2hQAAAH8"]
[Thu Sep 17 15:17:38.901052 2026] [security2:error] [pid 971102:tid 971238] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/zend/.env"] [unique_id "aqxY8ucL08BTTQixEnp2iQAAAAQ"]
[Thu Sep 17 15:17:38.919505 2026] [security2:error] [pid 971102:tid 971266] [client 34.166.218.131:39642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxY8ucL08BTTQixEnp2igAAACA"]
[Thu Sep 17 15:17:38.959139 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/v2/.env"] [unique_id "aqxY8ucL08BTTQixEnp2jAAAAFE"]
[Thu Sep 17 15:17:39.078527 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/yii/.env"] [unique_id "aqxY8-cL08BTTQixEnp2jwAAAF0"]
[Thu Sep 17 15:17:39.105969 2026] [security2:error] [pid 971102:tid 971292] [client 34.154.67.31:34564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxY8-cL08BTTQixEnp2kAAAADo"]
[Thu Sep 17 15:17:39.118171 2026] [security2:error] [pid 971102:tid 971268] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/rest/.env"] [unique_id "aqxY8-cL08BTTQixEnp2kQAAACI"]
[Thu Sep 17 15:17:39.130434 2026] [autoindex:error] [pid 971102:tid 971355] [client 164.92.74.247:46866] AH01276: Cannot serve directory /home1/zcktjlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:17:39.167317 2026] [security2:error] [pid 971102:tid 971341] [client 172.239.147.162:57625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxY8-cL08BTTQixEnp2kwAAAGs"], referer: binance.com
[Thu Sep 17 15:17:39.215801 2026] [security2:error] [pid 971102:tid 971337] [client 34.95.173.223:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/debug.php"] [unique_id "aqxY8-cL08BTTQixEnp2lAAAAGc"]
[Thu Sep 17 15:17:39.238940 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/laravel5/.env"] [unique_id "aqxY8-cL08BTTQixEnp2lwAAAH4"]
[Thu Sep 17 15:17:39.281026 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/graphql/.env"] [unique_id "aqxY8-cL08BTTQixEnp2mQAAABU"]
[Thu Sep 17 15:17:39.425638 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/v1/.env"] [unique_id "aqxY8-cL08BTTQixEnp2ngAAAD0"]
[Thu Sep 17 15:17:39.441371 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/gateway/.env"] [unique_id "aqxY8-cL08BTTQixEnp2nwAAAGY"]
[Thu Sep 17 15:17:39.441579 2026] [security2:error] [pid 971102:tid 971245] [client 45.187.111.151:38229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY8-cL08BTTQixEnp2mgAACz0"]
[Thu Sep 17 15:17:39.585174 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/v2/.env"] [unique_id "aqxY8-cL08BTTQixEnp2pgAAAFY"]
[Thu Sep 17 15:17:39.597585 2026] [security2:error] [pid 971102:tid 971349] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/microservice/.env"] [unique_id "aqxY8-cL08BTTQixEnp2pwAAAHM"]
[Thu Sep 17 15:17:39.757189 2026] [security2:error] [pid 971102:tid 971279] [client 34.95.173.223:42312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxY8-cL08BTTQixEnp2sAAAAC0"]
[Thu Sep 17 15:17:39.762215 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/service/.env"] [unique_id "aqxY8-cL08BTTQixEnp2swAAABY"]
[Thu Sep 17 15:17:39.762240 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/v3/.env"] [unique_id "aqxY8-cL08BTTQixEnp2sgAAACU"]
[Thu Sep 17 15:17:39.773967 2026] [security2:error] [pid 971102:tid 971236] [client 156.192.234.52:51972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8-cL08BTTQixEnp2sQAAAAI"]
[Thu Sep 17 15:17:39.774090 2026] [security2:error] [pid 971102:tid 971236] [client 156.192.234.52:51972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY8-cL08BTTQixEnp2sQAAAAI"]
[Thu Sep 17 15:17:39.901332 2026] [security2:error] [pid 971102:tid 971348] [client 34.166.218.131:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxY8-cL08BTTQixEnp2tQAAAHI"]
[Thu Sep 17 15:17:39.923104 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/v1/.env"] [unique_id "aqxY8-cL08BTTQixEnp2tgAAAAY"]
[Thu Sep 17 15:17:39.924567 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/v3/.env"] [unique_id "aqxY8-cL08BTTQixEnp2twAAAEY"]
[Thu Sep 17 15:17:40.074259 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/v2/.env"] [unique_id "aqxY9OcL08BTTQixEnp2uQAAAAg"]
[Thu Sep 17 15:17:40.084878 2026] [security2:error] [pid 971102:tid 971345] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/dev/.env"] [unique_id "aqxY9OcL08BTTQixEnp2uwAAAG8"]
[Thu Sep 17 15:17:40.103092 2026] [security2:error] [pid 971102:tid 971258] [client 34.154.67.31:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxY9OcL08BTTQixEnp2vAAAABg"]
[Thu Sep 17 15:17:40.157239 2026] [security2:error] [pid 971102:tid 971361] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxY9OcL08BTTQixEnp2vQAAAH8"]
[Thu Sep 17 15:17:40.231083 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/rest/.env"] [unique_id "aqxY9OcL08BTTQixEnp2wQAAACY"]
[Thu Sep 17 15:17:40.239144 2026] [security2:error] [pid 971102:tid 971246] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/api/staging/.env"] [unique_id "aqxY9OcL08BTTQixEnp2wgAAAAw"]
[Thu Sep 17 15:17:40.244715 2026] [security2:error] [pid 971102:tid 971285] [client 34.95.173.223:42322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/test/phpinfo.php"] [unique_id "aqxY9OcL08BTTQixEnp2wwAAADM"]
[Thu Sep 17 15:17:40.383969 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/graphql/.env"] [unique_id "aqxY9OcL08BTTQixEnp2yQAAAFE"]
[Thu Sep 17 15:17:40.389063 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxY9OcL08BTTQixEnp2ygAAAF4"]
[Thu Sep 17 15:17:40.397966 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/vendor/.env"] [unique_id "aqxY9OcL08BTTQixEnp2ywAAACs"]
[Thu Sep 17 15:17:40.540874 2026] [security2:error] [pid 971102:tid 971261] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/gateway/.env"] [unique_id "aqxY9OcL08BTTQixEnp2zQAAABs"]
[Thu Sep 17 15:17:40.559625 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/lib/.env"] [unique_id "aqxY9OcL08BTTQixEnp2zgAAAHk"]
[Thu Sep 17 15:17:40.567984 2026] [security2:error] [pid 971102:tid 971311] [client 172.239.147.162:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxY9OcL08BTTQixEnp2zwAAAE0"], referer: binance.com
[Thu Sep 17 15:17:40.583718 2026] [security2:error] [pid 971102:tid 971294] [client 34.154.67.31:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxY9OcL08BTTQixEnp20AAAADw"]
[Thu Sep 17 15:17:40.588500 2026] [security2:error] [pid 971102:tid 971238] [client 34.166.218.131:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxY9OcL08BTTQixEnp20QAAAAQ"]
[Thu Sep 17 15:17:40.707423 2026] [security2:error] [pid 971102:tid 971286] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/microservice/.env"] [unique_id "aqxY9OcL08BTTQixEnp21wAAADQ"]
[Thu Sep 17 15:17:40.715562 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/resources/.env"] [unique_id "aqxY9OcL08BTTQixEnp22QAAAC8"]
[Thu Sep 17 15:17:40.750336 2026] [security2:error] [pid 971102:tid 971307] [client 34.95.173.223:42330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxY9OcL08BTTQixEnp22gAAAEk"]
[Thu Sep 17 15:17:40.858492 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/service/.env"] [unique_id "aqxY9OcL08BTTQixEnp23gAAAD0"]
[Thu Sep 17 15:17:40.868174 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/assets/.env"] [unique_id "aqxY9OcL08BTTQixEnp23wAAAAs"]
[Thu Sep 17 15:17:40.906356 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxY9OcL08BTTQixEnp24AAAACc"], referer: binance.com
[Thu Sep 17 15:17:40.995309 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxY9OcL08BTTQixEnp24wAAAAM"]
[Thu Sep 17 15:17:41.014368 2026] [security2:error] [pid 971102:tid 971349] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/v3/.env"] [unique_id "aqxY9ecL08BTTQixEnp25AAAAHM"]
[Thu Sep 17 15:17:41.025082 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/uploads/.env"] [unique_id "aqxY9ecL08BTTQixEnp25QAAADE"]
[Thu Sep 17 15:17:41.100673 2026] [security2:error] [pid 971102:tid 971324] [client 34.154.67.31:34598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp25gAAAFo"]
[Thu Sep 17 15:17:41.169087 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/dev/.env"] [unique_id "aqxY9ecL08BTTQixEnp26QAAAGI"]
[Thu Sep 17 15:17:41.181343 2026] [security2:error] [pid 971102:tid 971279] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/internal/.env"] [unique_id "aqxY9ecL08BTTQixEnp26wAAAC0"]
[Thu Sep 17 15:17:41.267855 2026] [security2:error] [pid 971102:tid 971346] [client 34.95.173.223:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/old/phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp28gAAAHA"]
[Thu Sep 17 15:17:41.291838 2026] [security2:error] [pid 971102:tid 971247] [client 34.166.218.131:48754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp28wAAAA0"]
[Thu Sep 17 15:17:41.332576 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/api/staging/.env"] [unique_id "aqxY9ecL08BTTQixEnp29QAAADY"]
[Thu Sep 17 15:17:41.342745 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/tools/.env"] [unique_id "aqxY9ecL08BTTQixEnp29gAAAFA"]
[Thu Sep 17 15:17:41.487799 2026] [security2:error] [pid 971102:tid 971297] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/vendor/.env"] [unique_id "aqxY9ecL08BTTQixEnp2-gAAAD8"]
[Thu Sep 17 15:17:41.501944 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/scripts/.env"] [unique_id "aqxY9ecL08BTTQixEnp2-wAAAGE"]
[Thu Sep 17 15:17:41.579171 2026] [security2:error] [pid 971102:tid 971338] [client 34.154.67.31:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp2_QAAAGg"]
[Thu Sep 17 15:17:41.651485 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/lib/.env"] [unique_id "aqxY9ecL08BTTQixEnp2_wAAAAg"]
[Thu Sep 17 15:17:41.660695 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/bin/.env"] [unique_id "aqxY9ecL08BTTQixEnp3AQAAAHE"]
[Thu Sep 17 15:17:41.761676 2026] [security2:error] [pid 971102:tid 971253] [client 34.95.173.223:42354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxY9ecL08BTTQixEnp3BwAAABM"]
[Thu Sep 17 15:17:41.779498 2026] [security2:error] [pid 971102:tid 971274] [client 189.168.49.126:59613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY9ecL08BTTQixEnp3AAAAKCo"]
[Thu Sep 17 15:17:41.809796 2026] [security2:error] [pid 971102:tid 971354] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/resources/.env"] [unique_id "aqxY9ecL08BTTQixEnp3CgAAAHg"]
[Thu Sep 17 15:17:41.812922 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sbin/.env"] [unique_id "aqxY9ecL08BTTQixEnp3CwAAACA"]
[Thu Sep 17 15:17:41.964855 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/assets/.env"] [unique_id "aqxY9ecL08BTTQixEnp3DgAAAF0"]
[Thu Sep 17 15:17:41.967390 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/local/.env"] [unique_id "aqxY9ecL08BTTQixEnp3DwAAABI"]
[Thu Sep 17 15:17:41.968123 2026] [security2:error] [pid 971102:tid 971316] [client 74.7.175.189:36630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hbz.rgg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxY8ecL08BTTQixEnp2WgAAUmA"]
[Thu Sep 17 15:17:42.007785 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.218.131:48762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxY9ucL08BTTQixEnp3EQAAACk"]
[Thu Sep 17 15:17:42.052742 2026] [security2:error] [pid 971102:tid 971328] [client 34.154.67.31:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxY9ucL08BTTQixEnp3EgAAAF4"]
[Thu Sep 17 15:17:42.116953 2026] [security2:error] [pid 971102:tid 971227] [remote 216.73.217.142:15074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxY9ucL08BTTQixEnp3FQAAG3o"]
[Thu Sep 17 15:17:42.125675 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/uploads/.env"] [unique_id "aqxY9ucL08BTTQixEnp3FgAAAGA"]
[Thu Sep 17 15:17:42.126386 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/portal/.env"] [unique_id "aqxY9ucL08BTTQixEnp3FwAAAEs"]
[Thu Sep 17 15:17:42.265908 2026] [security2:error] [pid 971102:tid 971268] [client 34.95.173.223:42366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/public/phpinfo.php"] [unique_id "aqxY9ucL08BTTQixEnp3HQAAACI"]
[Thu Sep 17 15:17:42.282008 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/internal/.env"] [unique_id "aqxY9ucL08BTTQixEnp3HgAAABU"]
[Thu Sep 17 15:17:42.282273 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/dashboard/.env"] [unique_id "aqxY9ucL08BTTQixEnp3HwAAAEk"]
[Thu Sep 17 15:17:42.433151 2026] [security2:error] [pid 971102:tid 971329] [client 172.239.147.162:55505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/icons.php"] [unique_id "aqxY9ucL08BTTQixEnp3IgAAAF8"], referer: binance.com
[Thu Sep 17 15:17:42.436167 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/panel/.env"] [unique_id "aqxY9ucL08BTTQixEnp3IwAAAHs"]
[Thu Sep 17 15:17:42.439149 2026] [security2:error] [pid 971102:tid 971262] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/tools/.env"] [unique_id "aqxY9ucL08BTTQixEnp3JAAAABw"]
[Thu Sep 17 15:17:42.517703 2026] [security2:error] [pid 971102:tid 971265] [client 34.154.67.31:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxY9ucL08BTTQixEnp3KQAAAB8"]
[Thu Sep 17 15:17:42.590881 2026] [security2:error] [pid 971102:tid 971280] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/crm/.env"] [unique_id "aqxY9ucL08BTTQixEnp3LQAAAC4"]
[Thu Sep 17 15:17:42.595066 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/scripts/.env"] [unique_id "aqxY9ucL08BTTQixEnp3LwAAAG0"]
[Thu Sep 17 15:17:42.714813 2026] [security2:error] [pid 971102:tid 971237] [client 34.166.218.131:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxY9ucL08BTTQixEnp3MwAAAAM"]
[Thu Sep 17 15:17:42.748226 2026] [security2:error] [pid 971102:tid 971352] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/erp/.env"] [unique_id "aqxY9ucL08BTTQixEnp3NQAAAHY"]
[Thu Sep 17 15:17:42.751985 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/bin/.env"] [unique_id "aqxY9ucL08BTTQixEnp3NgAAAGw"]
[Thu Sep 17 15:17:42.908189 2026] [security2:error] [pid 971102:tid 971339] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sbin/.env"] [unique_id "aqxY9ucL08BTTQixEnp3OwAAAGk"]
[Thu Sep 17 15:17:42.909239 2026] [security2:error] [pid 971102:tid 971257] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/shop/.env"] [unique_id "aqxY9ucL08BTTQixEnp3PAAAABc"]
[Thu Sep 17 15:17:42.928158 2026] [security2:error] [pid 971102:tid 971353] [client 34.95.173.223:42368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/php-info.php"] [unique_id "aqxY9ucL08BTTQixEnp3PgAAAHc"]
[Thu Sep 17 15:17:43.026877 2026] [security2:error] [pid 971102:tid 971301] [client 57.141.14.51:58956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxY9ucL08BTTQixEnp3OQAAQ3k"]
[Thu Sep 17 15:17:43.064500 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/store/.env"] [unique_id "aqxY9-cL08BTTQixEnp3RAAAAFw"]
[Thu Sep 17 15:17:43.064504 2026] [security2:error] [pid 971102:tid 971345] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/local/.env"] [unique_id "aqxY9-cL08BTTQixEnp3QwAAAG8"]
[Thu Sep 17 15:17:43.228189 2026] [security2:error] [pid 971102:tid 971354] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/saas/.env"] [unique_id "aqxY9-cL08BTTQixEnp3SwAAAHg"]
[Thu Sep 17 15:17:43.228230 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/portal/.env"] [unique_id "aqxY9-cL08BTTQixEnp3TAAAACA"]
[Thu Sep 17 15:17:43.383167 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/client/.env"] [unique_id "aqxY9-cL08BTTQixEnp3UwAAAE8"]
[Thu Sep 17 15:17:43.385633 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/dashboard/.env"] [unique_id "aqxY9-cL08BTTQixEnp3VAAAABo"]
[Thu Sep 17 15:17:43.421782 2026] [security2:error] [pid 971102:tid 971254] [client 34.95.173.223:42374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpversion.php"] [unique_id "aqxY9-cL08BTTQixEnp3VQAAABQ"]
[Thu Sep 17 15:17:43.422557 2026] [security2:error] [pid 971102:tid 971246] [client 34.166.218.131:48776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxY9-cL08BTTQixEnp3VgAAAAw"]
[Thu Sep 17 15:17:43.563546 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/panel/.env"] [unique_id "aqxY9-cL08BTTQixEnp3WwAAAEc"]
[Thu Sep 17 15:17:43.563546 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/project/.env"] [unique_id "aqxY9-cL08BTTQixEnp3WgAAAEs"]
[Thu Sep 17 15:17:43.725255 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/admin-panel/.env"] [unique_id "aqxY9-cL08BTTQixEnp3YgAAAEo"]
[Thu Sep 17 15:17:43.725288 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/crm/.env"] [unique_id "aqxY9-cL08BTTQixEnp3YwAAABA"]
[Thu Sep 17 15:17:43.885894 2026] [security2:error] [pid 971102:tid 971329] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/control-panel/.env"] [unique_id "aqxY9-cL08BTTQixEnp3ZgAAAF8"]
[Thu Sep 17 15:17:43.888725 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/erp/.env"] [unique_id "aqxY9-cL08BTTQixEnp3ZwAAAHs"]
[Thu Sep 17 15:17:43.931626 2026] [security2:error] [pid 971102:tid 971291] [client 34.95.173.223:42384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/_phpinfo.php"] [unique_id "aqxY9-cL08BTTQixEnp3aAAAADk"]
[Thu Sep 17 15:17:44.044846 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/user-panel/.env"] [unique_id "aqxY-OcL08BTTQixEnp3aQAAAFY"]
[Thu Sep 17 15:17:44.057180 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/shop/.env"] [unique_id "aqxY-OcL08BTTQixEnp3agAAAG0"]
[Thu Sep 17 15:17:44.062974 2026] [security2:error] [pid 971102:tid 971273] [client 34.154.67.31:34656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY-OcL08BTTQixEnp3awAAACc"]
[Thu Sep 17 15:17:44.108109 2026] [security2:error] [pid 971102:tid 971355] [client 172.239.147.162:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxY-OcL08BTTQixEnp3bAAAAHk"], referer: binance.com
[Thu Sep 17 15:17:44.198686 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/node/.env"] [unique_id "aqxY-OcL08BTTQixEnp3dAAAAA0"]
[Thu Sep 17 15:17:44.213403 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/store/.env"] [unique_id "aqxY-OcL08BTTQixEnp3dgAAADY"]
[Thu Sep 17 15:17:44.352295 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/express/.env"] [unique_id "aqxY-OcL08BTTQixEnp3ewAAAFo"]
[Thu Sep 17 15:17:44.363257 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/saas/.env"] [unique_id "aqxY-OcL08BTTQixEnp3fAAAAG4"]
[Thu Sep 17 15:17:44.429021 2026] [security2:error] [pid 971102:tid 971321] [client 34.95.173.223:37220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/old_phpinfo.php"] [unique_id "aqxY-OcL08BTTQixEnp3fwAAAFc"]
[Thu Sep 17 15:17:44.512113 2026] [security2:error] [pid 971102:tid 971358] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/next/.env"] [unique_id "aqxY-OcL08BTTQixEnp3gwAAAHw"]
[Thu Sep 17 15:17:44.519927 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/client/.env"] [unique_id "aqxY-OcL08BTTQixEnp3hQAAAEM"]
[Thu Sep 17 15:17:44.542602 2026] [security2:error] [pid 971102:tid 971297] [client 34.154.67.31:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxY-OcL08BTTQixEnp3hgAAAD8"]
[Thu Sep 17 15:17:44.657994 2026] [security2:error] [pid 971102:tid 971353] [client 45.169.98.18:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-OcL08BTTQixEnp3iQAAAHc"]
[Thu Sep 17 15:17:44.658142 2026] [security2:error] [pid 971102:tid 971353] [client 45.169.98.18:60358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-OcL08BTTQixEnp3iQAAAHc"]
[Thu Sep 17 15:17:44.666655 2026] [security2:error] [pid 971102:tid 971326] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/nuxt/.env"] [unique_id "aqxY-OcL08BTTQixEnp3igAAAFw"]
[Thu Sep 17 15:17:44.678078 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/project/.env"] [unique_id "aqxY-OcL08BTTQixEnp3iwAAABM"]
[Thu Sep 17 15:17:44.694592 2026] [security2:error] [pid 971102:tid 971235] [client 34.166.218.131:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY-OcL08BTTQixEnp3jgAAAAE"]
[Thu Sep 17 15:17:44.745374 2026] [security2:error] [pid 971102:tid 971267] [client 172.239.147.162:60181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/json-schema.php"] [unique_id "aqxY-OcL08BTTQixEnp3kAAAACE"], referer: binance.com
[Thu Sep 17 15:17:44.825321 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/nest/.env"] [unique_id "aqxY-OcL08BTTQixEnp3kQAAACY"]
[Thu Sep 17 15:17:44.843208 2026] [security2:error] [pid 971102:tid 971317] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/admin-panel/.env"] [unique_id "aqxY-OcL08BTTQixEnp3kgAAAFM"]
[Thu Sep 17 15:17:44.945719 2026] [security2:error] [pid 971102:tid 971313] [client 34.95.173.223:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/server-info.php"] [unique_id "aqxY-OcL08BTTQixEnp3lgAAAE8"]
[Thu Sep 17 15:17:44.981540 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/react/.env"] [unique_id "aqxY-OcL08BTTQixEnp3lwAAACs"]
[Thu Sep 17 15:17:45.003210 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/control-panel/.env"] [unique_id "aqxY-ecL08BTTQixEnp3mAAAAF4"]
[Thu Sep 17 15:17:45.011686 2026] [security2:error] [pid 971102:tid 971327] [client 34.154.67.31:34664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3mQAAAF0"]
[Thu Sep 17 15:17:45.061980 2026] [security2:error] [pid 971102:tid 971359] [client 185.55.149.49:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY-ecL08BTTQixEnp3nQAAAH0"]
[Thu Sep 17 15:17:45.062095 2026] [security2:error] [pid 971102:tid 971359] [client 185.55.149.49:54897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxY-ecL08BTTQixEnp3nQAAAH0"]
[Thu Sep 17 15:17:45.089647 2026] [security2:error] [pid 971102:tid 971251] [client 216.73.217.138:33114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nlfephrata.org"] [uri "/index.php"] [unique_id "aqxY9ucL08BTTQixEnp3MAAAEQU"]
[Thu Sep 17 15:17:45.135727 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/vue/.env"] [unique_id "aqxY-ecL08BTTQixEnp3owAAACw"]
[Thu Sep 17 15:17:45.157947 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/user-panel/.env"] [unique_id "aqxY-ecL08BTTQixEnp3pAAAAEk"]
[Thu Sep 17 15:17:45.293472 2026] [security2:error] [pid 971102:tid 971337] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/angular/.env"] [unique_id "aqxY-ecL08BTTQixEnp3qwAAAGc"]
[Thu Sep 17 15:17:45.320113 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/node/.env"] [unique_id "aqxY-ecL08BTTQixEnp3rAAAAE4"]
[Thu Sep 17 15:17:45.384900 2026] [security2:error] [pid 971102:tid 971361] [client 34.166.218.131:48786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3rQAAAH8"]
[Thu Sep 17 15:17:45.432945 2026] [security2:error] [pid 971102:tid 971289] [client 34.95.173.223:37232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/server-status.php"] [unique_id "aqxY-ecL08BTTQixEnp3rgAAADc"]
[Thu Sep 17 15:17:45.450109 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/svelte/.env"] [unique_id "aqxY-ecL08BTTQixEnp3rwAAAG0"]
[Thu Sep 17 15:17:45.465130 2026] [security2:error] [pid 971102:tid 971329] [client 172.239.147.162:50438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxY-ecL08BTTQixEnp3sAAAAF8"], referer: binance.com
[Thu Sep 17 15:17:45.483000 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/express/.env"] [unique_id "aqxY-ecL08BTTQixEnp3sQAAAHk"]
[Thu Sep 17 15:17:45.513286 2026] [security2:error] [pid 971102:tid 971357] [client 34.154.67.31:34678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3sgAAAHs"]
[Thu Sep 17 15:17:45.612747 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxY-ecL08BTTQixEnp3swAAAFk"]
[Thu Sep 17 15:17:45.613285 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/vite/.env"] [unique_id "aqxY-ecL08BTTQixEnp3tAAAAH4"]
[Thu Sep 17 15:17:45.646374 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/next/.env"] [unique_id "aqxY-ecL08BTTQixEnp3tQAAAA0"]
[Thu Sep 17 15:17:45.770335 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/backup/.env"] [unique_id "aqxY-ecL08BTTQixEnp3uQAAAFo"]
[Thu Sep 17 15:17:45.808864 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/nuxt/.env"] [unique_id "aqxY-ecL08BTTQixEnp3ugAAAGY"]
[Thu Sep 17 15:17:45.847560 2026] [security2:error] [pid 971102:tid 971331] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.env~"] [unique_id "aqxY-ecL08BTTQixEnp3vAAAAGE"]
[Thu Sep 17 15:17:45.930969 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/backups/.env"] [unique_id "aqxY-ecL08BTTQixEnp3vQAAACU"]
[Thu Sep 17 15:17:45.965385 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/nest/.env"] [unique_id "aqxY-ecL08BTTQixEnp3vwAAABY"]
[Thu Sep 17 15:17:45.999073 2026] [security2:error] [pid 971102:tid 971321] [client 34.154.67.31:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY-ecL08BTTQixEnp3wAAAAFc"]
[Thu Sep 17 15:17:46.088823 2026] [security2:error] [pid 971102:tid 971339] [client 34.166.218.131:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp3wgAAAGk"]
[Thu Sep 17 15:17:46.090765 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/old/.env"] [unique_id "aqxY-ucL08BTTQixEnp3wwAAAEM"]
[Thu Sep 17 15:17:46.140056 2026] [security2:error] [pid 971102:tid 971284] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/react/.env"] [unique_id "aqxY-ucL08BTTQixEnp3xgAAADI"]
[Thu Sep 17 15:17:46.205029 2026] [authz_core:error] [pid 971102:tid 971303] [client 5.189.145.112:56782] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:46.248748 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/tmp/.env"] [unique_id "aqxY-ucL08BTTQixEnp3zAAAAEY"]
[Thu Sep 17 15:17:46.288544 2026] [security2:error] [pid 971102:tid 971326] [client 34.95.173.223:37236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxY-ucL08BTTQixEnp3zQAAAFw"]
[Thu Sep 17 15:17:46.295081 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/vue/.env"] [unique_id "aqxY-ucL08BTTQixEnp3zgAAABM"]
[Thu Sep 17 15:17:46.405429 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:41534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-ucL08BTTQixEnp30QAAAHY"]
[Thu Sep 17 15:17:46.405531 2026] [security2:error] [pid 971102:tid 971352] [client 154.190.208.131:41534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxY-ucL08BTTQixEnp30QAAAHY"]
[Thu Sep 17 15:17:46.414687 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/temp/.env"] [unique_id "aqxY-ucL08BTTQixEnp30gAAABo"]
[Thu Sep 17 15:17:46.463807 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/angular/.env"] [unique_id "aqxY-ucL08BTTQixEnp31AAAACY"]
[Thu Sep 17 15:17:46.478074 2026] [security2:error] [pid 971102:tid 971235] [client 34.154.67.31:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp31gAAAAE"]
[Thu Sep 17 15:17:46.574767 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/lab/.env"] [unique_id "aqxY-ucL08BTTQixEnp33AAAAE8"]
[Thu Sep 17 15:17:46.622655 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/svelte/.env"] [unique_id "aqxY-ucL08BTTQixEnp33gAAAF0"]
[Thu Sep 17 15:17:46.687468 2026] [security2:error] [pid 971102:tid 971244] [client 172.239.147.162:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxY-ucL08BTTQixEnp34QAAAAo"], referer: binance.com
[Thu Sep 17 15:17:46.732553 2026] [security2:error] [pid 971102:tid 971311] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cronlab/.env"] [unique_id "aqxY-ucL08BTTQixEnp34wAAAE0"]
[Thu Sep 17 15:17:46.779076 2026] [security2:error] [pid 971102:tid 971277] [client 34.95.173.223:37248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp35wAAACs"]
[Thu Sep 17 15:17:46.780177 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/vite/.env"] [unique_id "aqxY-ucL08BTTQixEnp36AAAACw"]
[Thu Sep 17 15:17:46.796023 2026] [security2:error] [pid 971102:tid 971325] [client 34.166.218.131:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY-ucL08BTTQixEnp36QAAAFs"]
[Thu Sep 17 15:17:46.898166 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cron/.env"] [unique_id "aqxY-ucL08BTTQixEnp36wAAAEQ"]
[Thu Sep 17 15:17:46.940533 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/backup/.env"] [unique_id "aqxY-ucL08BTTQixEnp37QAAAB4"]
[Thu Sep 17 15:17:46.949088 2026] [security2:error] [pid 971102:tid 971307] [client 34.154.67.31:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxY-ucL08BTTQixEnp37wAAAEk"]
[Thu Sep 17 15:17:47.056474 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/en/.env"] [unique_id "aqxY--cL08BTTQixEnp38AAAADg"]
[Thu Sep 17 15:17:47.092049 2026] [security2:error] [pid 971102:tid 971282] [client 114.198.138.124:55745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY--cL08BTTQixEnp38QAAADA"]
[Thu Sep 17 15:17:47.092151 2026] [security2:error] [pid 971102:tid 971282] [client 114.198.138.124:55745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxY--cL08BTTQixEnp38QAAADA"]
[Thu Sep 17 15:17:47.096097 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/backups/.env"] [unique_id "aqxY--cL08BTTQixEnp38gAAAC8"]
[Thu Sep 17 15:17:47.258463 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/old/.env"] [unique_id "aqxY--cL08BTTQixEnp3-QAAADo"]
[Thu Sep 17 15:17:47.268445 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.173.223:37252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxY--cL08BTTQixEnp3_QAAAAk"]
[Thu Sep 17 15:17:47.318636 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/administrator/.env"] [unique_id "aqxY--cL08BTTQixEnp3-gAAADY"]
[Thu Sep 17 15:17:47.425067 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/tmp/.env"] [unique_id "aqxY--cL08BTTQixEnp4BAAAAAA"]
[Thu Sep 17 15:17:47.433475 2026] [security2:error] [pid 971102:tid 971323] [client 34.154.67.31:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxY--cL08BTTQixEnp4BQAAAFk"]
[Thu Sep 17 15:17:47.445578 2026] [security2:error] [pid 971102:tid 971310] [client 172.239.147.162:55399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxY--cL08BTTQixEnp4BgAAAEw"], referer: binance.com
[Thu Sep 17 15:17:47.485466 2026] [security2:error] [pid 971102:tid 971350] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/psnlink/.env"] [unique_id "aqxY--cL08BTTQixEnp4CAAAAHQ"]
[Thu Sep 17 15:17:47.486357 2026] [security2:error] [pid 971102:tid 971357] [client 34.166.218.131:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY--cL08BTTQixEnp4CQAAAHs"]
[Thu Sep 17 15:17:47.580938 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/temp/.env"] [unique_id "aqxY--cL08BTTQixEnp4CwAAAFI"]
[Thu Sep 17 15:17:47.658863 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/exapi/.env"] [unique_id "aqxY--cL08BTTQixEnp4DwAAAEY"]
[Thu Sep 17 15:17:47.745632 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/lab/.env"] [unique_id "aqxY--cL08BTTQixEnp4FAAAABM"]
[Thu Sep 17 15:17:47.757031 2026] [security2:error] [pid 971102:tid 971303] [client 34.95.173.223:37258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxY--cL08BTTQixEnp4FQAAAEU"]
[Thu Sep 17 15:17:47.811543 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sitemaps/.env"] [unique_id "aqxY--cL08BTTQixEnp4FgAAACA"]
[Thu Sep 17 15:17:47.902715 2026] [security2:error] [pid 971102:tid 971326] [client 34.154.67.31:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxY--cL08BTTQixEnp4GwAAAFw"]
[Thu Sep 17 15:17:47.905488 2026] [security2:error] [pid 971102:tid 971272] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cronlab/.env"] [unique_id "aqxY--cL08BTTQixEnp4HAAAACY"]
[Thu Sep 17 15:17:48.058169 2026] [security2:error] [pid 971102:tid 971274] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cron/.env"] [unique_id "aqxY_OcL08BTTQixEnp4IQAAACg"]
[Thu Sep 17 15:17:48.106171 2026] [security2:error] [pid 971102:tid 971306] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY--cL08BTTQixEnp4IAAAAEg"]
[Thu Sep 17 15:17:48.167088 2026] [security2:error] [pid 971102:tid 971313] [client 34.166.218.131:48818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY_OcL08BTTQixEnp4LQAAAE8"]
[Thu Sep 17 15:17:48.216006 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/en/.env"] [unique_id "aqxY_OcL08BTTQixEnp4MwAAAB4"]
[Thu Sep 17 15:17:48.242085 2026] [security2:error] [pid 971102:tid 971309] [client 34.95.173.223:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxY_OcL08BTTQixEnp4NQAAAEs"]
[Thu Sep 17 15:17:48.280183 2026] [security2:error] [pid 971102:tid 971359] [client 192.178.6.4:61863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxY_OcL08BTTQixEnp4NAAAAH0"]
[Thu Sep 17 15:17:48.368522 2026] [security2:error] [pid 971102:tid 971330] [client 34.154.67.31:51848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxY_OcL08BTTQixEnp4NgAAAGA"]
[Thu Sep 17 15:17:48.372099 2026] [security2:error] [pid 971102:tid 971250] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/administrator/.env"] [unique_id "aqxY_OcL08BTTQixEnp4NwAAABA"]
[Thu Sep 17 15:17:48.515504 2026] [security2:error] [pid 971102:tid 971320] [client 162.241.226.11:42776] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxY_OcL08BTTQixEnp4PAAAAFY"]
[Thu Sep 17 15:17:48.532678 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/psnlink/.env"] [unique_id "aqxY_OcL08BTTQixEnp4PgAAADY"]
[Thu Sep 17 15:17:48.537564 2026] [security2:error] [pid 971102:tid 971332] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxY_OcL08BTTQixEnp4PwAAAGI"]
[Thu Sep 17 15:17:48.578363 2026] [security2:error] [pid 971102:tid 971361] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxY_OcL08BTTQixEnp4OgAAAH8"]
[Thu Sep 17 15:17:48.683656 2026] [security2:error] [pid 971102:tid 971323] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/exapi/.env"] [unique_id "aqxY_OcL08BTTQixEnp4QQAAAFk"]
[Thu Sep 17 15:17:48.727794 2026] [security2:error] [pid 971102:tid 971283] [client 34.95.173.223:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxY_OcL08BTTQixEnp4QwAAADE"]
[Thu Sep 17 15:17:48.769979 2026] [security2:error] [pid 971102:tid 971357] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxY_OcL08BTTQixEnp4RAAAAHs"]
[Thu Sep 17 15:17:48.780989 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:51992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/logs/.env"] [unique_id "aqxY_OcL08BTTQixEnp4RQAAACU"]
[Thu Sep 17 15:17:48.837727 2026] [security2:error] [pid 971102:tid 971360] [client 34.154.67.31:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxY_OcL08BTTQixEnp4RwAAAH4"]
[Thu Sep 17 15:17:48.847187 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sitemaps/.env"] [unique_id "aqxY_OcL08BTTQixEnp4SAAAAHI"]
[Thu Sep 17 15:17:48.870064 2026] [security2:error] [pid 971102:tid 971343] [client 34.166.218.131:48826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxY_OcL08BTTQixEnp4SQAAAG0"]
[Thu Sep 17 15:17:48.886120 2026] [security2:error] [pid 971102:tid 971305] [client 172.239.147.162:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxY_OcL08BTTQixEnp4SgAAAEc"], referer: binance.com
[Thu Sep 17 15:17:49.003946 2026] [security2:error] [pid 971102:tid 971329] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxY_ecL08BTTQixEnp4TAAAAF8"]
[Thu Sep 17 15:17:49.028716 2026] [security2:error] [pid 971102:tid 971341] [client 190.5.36.152:52504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY_OcL08BTTQixEnp4SwAAa0g"]
[Thu Sep 17 15:17:49.227998 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY_ecL08BTTQixEnp4UgAAABM"]
[Thu Sep 17 15:17:49.230451 2026] [security2:error] [pid 971102:tid 971304] [client 34.95.173.223:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxY_ecL08BTTQixEnp4WwAAAEY"]
[Thu Sep 17 15:17:49.235885 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxY_ecL08BTTQixEnp4XAAAAFw"]
[Thu Sep 17 15:17:49.276123 2026] [security2:error] [pid 971102:tid 971303] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cache/.env"] [unique_id "aqxY_ecL08BTTQixEnp4XgAAAEU"]
[Thu Sep 17 15:17:49.302261 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:51860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxY_ecL08BTTQixEnp4XwAAACQ"]
[Thu Sep 17 15:17:49.432759 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailer/.env"] [unique_id "aqxY_ecL08BTTQixEnp4ZQAAACk"]
[Thu Sep 17 15:17:49.471835 2026] [security2:error] [pid 971102:tid 971311] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxY_ecL08BTTQixEnp4ZwAAAE0"]
[Thu Sep 17 15:17:49.548961 2026] [security2:error] [pid 971102:tid 971356] [client 34.166.218.131:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxY_ecL08BTTQixEnp4aAAAAHo"]
[Thu Sep 17 15:17:49.597400 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mail/.env"] [unique_id "aqxY_ecL08BTTQixEnp4awAAAEs"]
[Thu Sep 17 15:17:49.614823 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:55928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ecL08BTTQixEnp4bAAAABg"]
[Thu Sep 17 15:17:49.614943 2026] [security2:error] [pid 971102:tid 971258] [client 186.105.232.15:55928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ecL08BTTQixEnp4bAAAABg"]
[Thu Sep 17 15:17:49.709162 2026] [security2:error] [pid 971102:tid 971237] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxY_ecL08BTTQixEnp4cgAAAAM"]
[Thu Sep 17 15:17:49.732368 2026] [security2:error] [pid 971102:tid 971264] [client 34.95.173.223:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php.old"] [unique_id "aqxY_ecL08BTTQixEnp4cwAAAB4"]
[Thu Sep 17 15:17:49.754975 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/email/.env"] [unique_id "aqxY_ecL08BTTQixEnp4dgAAACw"]
[Thu Sep 17 15:17:49.782832 2026] [security2:error] [pid 971102:tid 971285] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxY_ecL08BTTQixEnp4cQAAADM"]
[Thu Sep 17 15:17:49.915706 2026] [security2:error] [pid 971102:tid 971290] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/smtp/.env"] [unique_id "aqxY_ecL08BTTQixEnp4fAAAADg"]
[Thu Sep 17 15:17:50.012919 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/logs/.env"] [unique_id "aqxY_ucL08BTTQixEnp4gAAAAFY"]
[Thu Sep 17 15:17:50.076536 2026] [security2:error] [pid 971102:tid 971358] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailing/.env"] [unique_id "aqxY_ucL08BTTQixEnp4gwAAAHw"]
[Thu Sep 17 15:17:50.156846 2026] [security2:error] [pid 971102:tid 971281] [client 34.154.67.31:51872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxY_ucL08BTTQixEnp4iwAAAC8"]
[Thu Sep 17 15:17:50.170223 2026] [security2:error] [pid 971102:tid 971240] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cache/.env"] [unique_id "aqxY_ucL08BTTQixEnp4jQAAAAY"]
[Thu Sep 17 15:17:50.209765 2026] [security2:error] [pid 971102:tid 971289] [client 172.239.147.162:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxY_ucL08BTTQixEnp4kAAAADc"], referer: binance.com
[Thu Sep 17 15:17:50.228776 2026] [security2:error] [pid 971102:tid 971292] [client 34.95.173.223:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php~"] [unique_id "aqxY_ucL08BTTQixEnp4kQAAADo"]
[Thu Sep 17 15:17:50.234236 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/notifications/.env"] [unique_id "aqxY_ucL08BTTQixEnp4kgAAAG4"]
[Thu Sep 17 15:17:50.241626 2026] [security2:error] [pid 971102:tid 971265] [client 34.166.218.131:55728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxY_ucL08BTTQixEnp4kwAAAB8"]
[Thu Sep 17 15:17:50.266367 2026] [security2:error] [pid 971102:tid 971250] [client 156.192.234.52:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ucL08BTTQixEnp4lAAAABA"]
[Thu Sep 17 15:17:50.269496 2026] [security2:error] [pid 971102:tid 971250] [client 156.192.234.52:52587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxY_ucL08BTTQixEnp4lAAAABA"]
[Thu Sep 17 15:17:50.333558 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailer/.env"] [unique_id "aqxY_ucL08BTTQixEnp4lQAAAEc"]
[Thu Sep 17 15:17:50.350008 2026] [security2:error] [pid 971102:tid 971321] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY_ucL08BTTQixEnp4lgAAAFc"]
[Thu Sep 17 15:17:50.402436 2026] [security2:error] [pid 971102:tid 971310] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/notify/.env"] [unique_id "aqxY_ucL08BTTQixEnp4lwAAAEw"]
[Thu Sep 17 15:17:50.484123 2026] [security2:error] [pid 971102:tid 971338] [client 185.213.175.37:38354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env"] [unique_id "aqxY_ucL08BTTQixEnp4mAAAAGg"]
[Thu Sep 17 15:17:50.486643 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mail/.env"] [unique_id "aqxY_ucL08BTTQixEnp4mQAAABM"]
[Thu Sep 17 15:17:50.563326 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sender/.env"] [unique_id "aqxY_ucL08BTTQixEnp4mwAAAFo"]
[Thu Sep 17 15:17:50.580927 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxY_ucL08BTTQixEnp4nAAAAAE"]
[Thu Sep 17 15:17:50.598207 2026] [security2:error] [pid 971102:tid 971303] [client 185.213.175.37:38370] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxY_ucL08BTTQixEnp4nQAAAEU"]
[Thu Sep 17 15:17:50.645386 2026] [security2:error] [pid 971102:tid 971341] [client 34.154.67.31:51878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxY_ucL08BTTQixEnp4oAAAAGs"]
[Thu Sep 17 15:17:50.649935 2026] [security2:error] [pid 971102:tid 971352] [client 185.213.175.37:38354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxY_ucL08BTTQixEnp4oQAAAHY"]
[Thu Sep 17 15:17:50.650948 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/email/.env"] [unique_id "aqxY_ucL08BTTQixEnp4ogAAAAI"]
[Thu Sep 17 15:17:50.654593 2026] [security2:error] [pid 971102:tid 971328] [client 74.7.241.151:42240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.oqz.eln.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxY_ucL08BTTQixEnp4nwAAAF4"]
[Thu Sep 17 15:17:50.716765 2026] [security2:error] [pid 971102:tid 971272] [client 34.95.173.223:37304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/info.php.bak"] [unique_id "aqxY_ucL08BTTQixEnp4pQAAACY"]
[Thu Sep 17 15:17:50.718823 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/campaign/.env"] [unique_id "aqxY_ucL08BTTQixEnp4pgAAAAg"]
[Thu Sep 17 15:17:50.807426 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/smtp/.env"] [unique_id "aqxY_ucL08BTTQixEnp4qQAAAEI"]
[Thu Sep 17 15:17:50.809026 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxY_ucL08BTTQixEnp4qgAAACs"]
[Thu Sep 17 15:17:50.896095 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/newsletter/.env"] [unique_id "aqxY_ucL08BTTQixEnp4rAAAABo"]
[Thu Sep 17 15:17:50.905990 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:38354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production"] [unique_id "aqxY_ucL08BTTQixEnp4rQAAABQ"]
[Thu Sep 17 15:17:50.906112 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:38354] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production"] [unique_id "aqxY_ucL08BTTQixEnp4rQAAABQ"]
[Thu Sep 17 15:17:50.921853 2026] [security2:error] [pid 971102:tid 971351] [client 34.166.218.131:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxY_ucL08BTTQixEnp4rgAAAHU"]
[Thu Sep 17 15:17:50.970801 2026] [security2:error] [pid 971102:tid 971311] [client 34.151.157.242:52000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailing/.env"] [unique_id "aqxY_ucL08BTTQixEnp4rwAAAE0"]
[Thu Sep 17 15:17:51.042364 2026] [security2:error] [pid 971102:tid 971309] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxY_-cL08BTTQixEnp4sgAAAEs"]
[Thu Sep 17 15:17:51.051868 2026] [security2:error] [pid 971102:tid 971266] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/ses/.env"] [unique_id "aqxY_-cL08BTTQixEnp4swAAACA"]
[Thu Sep 17 15:17:51.101571 2026] [security2:error] [pid 971102:tid 971259] [client 34.154.67.31:51890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxY_-cL08BTTQixEnp4tAAAABk"]
[Thu Sep 17 15:17:51.139387 2026] [security2:error] [pid 971102:tid 971315] [client 116.111.164.228:38506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxY_-cL08BTTQixEnp4sAAAUWU"]
[Thu Sep 17 15:17:51.172077 2026] [security2:error] [pid 971102:tid 971322] [client 185.213.175.37:38386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxY_-cL08BTTQixEnp4tQAAAFg"]
[Thu Sep 17 15:17:51.216994 2026] [security2:error] [pid 971102:tid 971285] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sendgrid/.env"] [unique_id "aqxY_-cL08BTTQixEnp4uAAAADM"]
[Thu Sep 17 15:17:51.240826 2026] [security2:error] [pid 971102:tid 971258] [client 34.95.173.223:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/phpinfo.php.save"] [unique_id "aqxY_-cL08BTTQixEnp4ugAAABg"]
[Thu Sep 17 15:17:51.277677 2026] [security2:error] [pid 971102:tid 971313] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxY_-cL08BTTQixEnp4uwAAAE8"]
[Thu Sep 17 15:17:51.377438 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/sparkpost/.env"] [unique_id "aqxY_-cL08BTTQixEnp4vgAAAFs"]
[Thu Sep 17 15:17:51.440496 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/notifications/.env"] [unique_id "aqxY_-cL08BTTQixEnp4wAAAAD4"]
[Thu Sep 17 15:17:51.445927 2026] [security2:error] [pid 971102:tid 971243] [client 185.213.175.37:38386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxY_-cL08BTTQixEnp4wQAAAAk"]
[Thu Sep 17 15:17:51.507557 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxY_-cL08BTTQixEnp4wwAAAGY"]
[Thu Sep 17 15:17:51.533259 2026] [security2:error] [pid 971102:tid 971241] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/postmark/.env"] [unique_id "aqxY_-cL08BTTQixEnp4xQAAAAc"]
[Thu Sep 17 15:17:51.569108 2026] [security2:error] [pid 971102:tid 971358] [client 34.154.67.31:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxY_-cL08BTTQixEnp4xwAAAHw"]
[Thu Sep 17 15:17:51.588944 2026] [security2:error] [pid 971102:tid 971252] [client 185.213.175.37:38376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY_-cL08BTTQixEnp4yQAAABI"]
[Thu Sep 17 15:17:51.589064 2026] [security2:error] [pid 971102:tid 971252] [client 185.213.175.37:38376] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxY_-cL08BTTQixEnp4yQAAABI"]
[Thu Sep 17 15:17:51.591097 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/notify/.env"] [unique_id "aqxY_-cL08BTTQixEnp4ywAAAA0"]
[Thu Sep 17 15:17:51.612533 2026] [security2:error] [pid 971102:tid 971307] [client 34.166.218.131:55744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxY_-cL08BTTQixEnp4zQAAAEk"]
[Thu Sep 17 15:17:51.691051 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailgun/.env"] [unique_id "aqxY_-cL08BTTQixEnp40AAAAD0"]
[Thu Sep 17 15:17:51.725350 2026] [security2:error] [pid 971102:tid 971281] [client 185.213.175.37:38386] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxY_-cL08BTTQixEnp40QAAAC8"]
[Thu Sep 17 15:17:51.727396 2026] [security2:error] [pid 971102:tid 971312] [client 34.95.173.223:37318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxY_-cL08BTTQixEnp40gAAAE4"]
[Thu Sep 17 15:17:51.736609 2026] [security2:error] [pid 971102:tid 971289] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxY_-cL08BTTQixEnp41QAAADc"]
[Thu Sep 17 15:17:51.749982 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sender/.env"] [unique_id "aqxY_-cL08BTTQixEnp41gAAABY"]
[Thu Sep 17 15:17:51.852122 2026] [security2:error] [pid 971102:tid 971348] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mandrill/.env"] [unique_id "aqxY_-cL08BTTQixEnp41wAAAHI"]
[Thu Sep 17 15:17:51.916118 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/campaign/.env"] [unique_id "aqxY_-cL08BTTQixEnp42AAAADE"]
[Thu Sep 17 15:17:51.977349 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxY_-cL08BTTQixEnp42QAAAFk"]
[Thu Sep 17 15:17:52.017634 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mailjet/.env"] [unique_id "aqxZAOcL08BTTQixEnp42gAAAHk"]
[Thu Sep 17 15:17:52.034710 2026] [security2:error] [pid 971102:tid 971234] [client 185.213.175.37:38396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.save"] [unique_id "aqxZAOcL08BTTQixEnp42wAAAAA"]
[Thu Sep 17 15:17:52.034815 2026] [security2:error] [pid 971102:tid 971234] [client 185.213.175.37:38396] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.save"] [unique_id "aqxZAOcL08BTTQixEnp42wAAAAA"]
[Thu Sep 17 15:17:52.045296 2026] [security2:error] [pid 971102:tid 971343] [client 34.154.67.31:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp43AAAAG0"]
[Thu Sep 17 15:17:52.069819 2026] [security2:error] [pid 971102:tid 971338] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/newsletter/.env"] [unique_id "aqxZAOcL08BTTQixEnp43QAAAGg"]
[Thu Sep 17 15:17:52.180493 2026] [security2:error] [pid 971102:tid 971282] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/brevo/.env"] [unique_id "aqxZAOcL08BTTQixEnp44wAAADA"]
[Thu Sep 17 15:17:52.182933 2026] [security2:error] [pid 971102:tid 971257] [client 185.213.175.37:38408] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.staging"] [unique_id "aqxZAOcL08BTTQixEnp45QAAABc"]
[Thu Sep 17 15:17:52.210255 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxZAOcL08BTTQixEnp46QAAAHA"]
[Thu Sep 17 15:17:52.220072 2026] [security2:error] [pid 971102:tid 971329] [client 34.95.173.223:37326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp47AAAAF8"]
[Thu Sep 17 15:17:52.223628 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/ses/.env"] [unique_id "aqxZAOcL08BTTQixEnp47QAAAFI"]
[Thu Sep 17 15:17:52.307017 2026] [security2:error] [pid 971102:tid 971349] [client 34.166.218.131:55746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp48gAAAHM"]
[Thu Sep 17 15:17:52.321745 2026] [security2:error] [pid 971102:tid 971236] [client 185.213.175.37:38410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.test"] [unique_id "aqxZAOcL08BTTQixEnp48wAAAAI"]
[Thu Sep 17 15:17:52.321888 2026] [security2:error] [pid 971102:tid 971236] [client 185.213.175.37:38410] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.test"] [unique_id "aqxZAOcL08BTTQixEnp48wAAAAI"]
[Thu Sep 17 15:17:52.343468 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/transactional/.env"] [unique_id "aqxZAOcL08BTTQixEnp49AAAAF4"]
[Thu Sep 17 15:17:52.387192 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sendgrid/.env"] [unique_id "aqxZAOcL08BTTQixEnp49wAAAHE"]
[Thu Sep 17 15:17:52.443825 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxZAOcL08BTTQixEnp4-QAAACs"]
[Thu Sep 17 15:17:52.501589 2026] [security2:error] [pid 971102:tid 971260] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/bulk/.env"] [unique_id "aqxZAOcL08BTTQixEnp4-gAAABo"]
[Thu Sep 17 15:17:52.533749 2026] [security2:error] [pid 971102:tid 971267] [client 185.213.175.37:38422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.txt"] [unique_id "aqxZAOcL08BTTQixEnp4_wAAACE"]
[Thu Sep 17 15:17:52.543185 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/sparkpost/.env"] [unique_id "aqxZAOcL08BTTQixEnp5AAAAACk"]
[Thu Sep 17 15:17:52.547114 2026] [security2:error] [pid 971102:tid 971306] [client 34.154.67.31:51914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp5AQAAAEg"]
[Thu Sep 17 15:17:52.662975 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/aws/.env"] [unique_id "aqxZAOcL08BTTQixEnp5AgAAACo"]
[Thu Sep 17 15:17:52.666895 2026] [security2:error] [pid 971102:tid 971266] [client 185.213.175.37:38408] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app.env"] [unique_id "aqxZAOcL08BTTQixEnp5BAAAACA"]
[Thu Sep 17 15:17:52.674189 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxZAOcL08BTTQixEnp5BgAAAHo"]
[Thu Sep 17 15:17:52.708274 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/postmark/.env"] [unique_id "aqxZAOcL08BTTQixEnp5BwAAAFE"]
[Thu Sep 17 15:17:52.714950 2026] [security2:error] [pid 971102:tid 971354] [client 34.95.173.223:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp5CAAAAHg"]
[Thu Sep 17 15:17:52.818251 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/azure/.env"] [unique_id "aqxZAOcL08BTTQixEnp5DQAAACw"]
[Thu Sep 17 15:17:52.860814 2026] [security2:error] [pid 971102:tid 971258] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailgun/.env"] [unique_id "aqxZAOcL08BTTQixEnp5DgAAABg"]
[Thu Sep 17 15:17:52.901782 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxZAOcL08BTTQixEnp5EAAAABw"]
[Thu Sep 17 15:17:52.977446 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/gcp/.env"] [unique_id "aqxZAOcL08BTTQixEnp5EQAAAB4"]
[Thu Sep 17 15:17:52.992454 2026] [security2:error] [pid 971102:tid 971279] [client 34.166.218.131:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxZAOcL08BTTQixEnp5FAAAAC0"]
[Thu Sep 17 15:17:53.019504 2026] [security2:error] [pid 971102:tid 971318] [client 34.154.67.31:51926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5FgAAAFQ"]
[Thu Sep 17 15:17:53.020265 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mandrill/.env"] [unique_id "aqxZAecL08BTTQixEnp5FQAAAFs"]
[Thu Sep 17 15:17:53.129249 2026] [security2:error] [pid 971102:tid 971243] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxZAecL08BTTQixEnp5GgAAAAk"]
[Thu Sep 17 15:17:53.129248 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cloud/.env"] [unique_id "aqxZAecL08BTTQixEnp5GQAAAD4"]
[Thu Sep 17 15:17:53.130084 2026] [security2:error] [pid 971102:tid 971271] [client 185.213.175.37:38436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/secrets.env"] [unique_id "aqxZAecL08BTTQixEnp5GwAAACU"]
[Thu Sep 17 15:17:53.130146 2026] [security2:error] [pid 971102:tid 971271] [client 185.213.175.37:38436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/secrets.env"] [unique_id "aqxZAecL08BTTQixEnp5GwAAACU"]
[Thu Sep 17 15:17:53.177435 2026] [security2:error] [pid 971102:tid 971241] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mailjet/.env"] [unique_id "aqxZAecL08BTTQixEnp5HAAAAAc"]
[Thu Sep 17 15:17:53.202164 2026] [security2:error] [pid 971102:tid 971245] [client 34.95.173.223:37344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5HgAAAAs"]
[Thu Sep 17 15:17:53.213335 2026] [security2:error] [pid 971102:tid 971290] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.uat"] [unique_id "aqxZAecL08BTTQixEnp5HwAAADg"]
[Thu Sep 17 15:17:53.267574 2026] [security2:error] [pid 971102:tid 971293] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.orig"] [unique_id "aqxZAecL08BTTQixEnp5IwAAADs"]
[Thu Sep 17 15:17:53.280174 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/infrastructure/.env"] [unique_id "aqxZAecL08BTTQixEnp5JAAAAD0"]
[Thu Sep 17 15:17:53.330681 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/brevo/.env"] [unique_id "aqxZAecL08BTTQixEnp5JQAAAC8"]
[Thu Sep 17 15:17:53.362806 2026] [security2:error] [pid 971102:tid 971289] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxZAecL08BTTQixEnp5JgAAADc"]
[Thu Sep 17 15:17:53.403423 2026] [security2:error] [pid 971102:tid 971344] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.copy"] [unique_id "aqxZAecL08BTTQixEnp5JwAAAG4"]
[Thu Sep 17 15:17:53.446793 2026] [security2:error] [pid 971102:tid 971360] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/docker/.env"] [unique_id "aqxZAecL08BTTQixEnp5KAAAAH4"]
[Thu Sep 17 15:17:53.484672 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/transactional/.env"] [unique_id "aqxZAecL08BTTQixEnp5KQAAAGI"]
[Thu Sep 17 15:17:53.506950 2026] [security2:error] [pid 971102:tid 971312] [client 34.154.67.31:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5KgAAAE4"]
[Thu Sep 17 15:17:53.599491 2026] [security2:error] [pid 971102:tid 971321] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxZAecL08BTTQixEnp5LAAAAFc"]
[Thu Sep 17 15:17:53.622538 2026] [security2:error] [pid 971102:tid 971299] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/k8s/.env"] [unique_id "aqxZAecL08BTTQixEnp5LQAAAEE"]
[Thu Sep 17 15:17:53.646440 2026] [security2:error] [pid 971102:tid 971308] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/bulk/.env"] [unique_id "aqxZAecL08BTTQixEnp5LwAAAEo"]
[Thu Sep 17 15:17:53.679304 2026] [security2:error] [pid 971102:tid 971250] [client 34.166.218.131:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5MwAAABA"]
[Thu Sep 17 15:17:53.691080 2026] [security2:error] [pid 971102:tid 971305] [client 34.95.173.223:37346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5NAAAAEc"]
[Thu Sep 17 15:17:53.779340 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/kubernetes/.env"] [unique_id "aqxZAecL08BTTQixEnp5NgAAAHk"]
[Thu Sep 17 15:17:53.800951 2026] [security2:error] [pid 971102:tid 971353] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/aws/.env"] [unique_id "aqxZAecL08BTTQixEnp5OQAAAHc"]
[Thu Sep 17 15:17:53.828495 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxZAecL08BTTQixEnp5OgAAAEY"]
[Thu Sep 17 15:17:53.841774 2026] [security2:error] [pid 971102:tid 971346] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.local.bak"] [unique_id "aqxZAecL08BTTQixEnp5PQAAAHA"]
[Thu Sep 17 15:17:53.936085 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/terraform/.env"] [unique_id "aqxZAecL08BTTQixEnp5QAAAAAU"]
[Thu Sep 17 15:17:53.954840 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/azure/.env"] [unique_id "aqxZAecL08BTTQixEnp5QgAAAF4"]
[Thu Sep 17 15:17:53.989003 2026] [security2:error] [pid 971102:tid 971303] [client 34.154.67.31:51948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZAecL08BTTQixEnp5RAAAAEU"]
[Thu Sep 17 15:17:54.065621 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxZAucL08BTTQixEnp5RQAAAAo"]
[Thu Sep 17 15:17:54.100827 2026] [security2:error] [pid 971102:tid 971319] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/ansible/.env"] [unique_id "aqxZAucL08BTTQixEnp5RwAAAFU"]
[Thu Sep 17 15:17:54.111678 2026] [security2:error] [pid 971102:tid 971347] [client 185.213.175.37:38438] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.staging.local"] [unique_id "aqxZAucL08BTTQixEnp5SAAAAHE"]
[Thu Sep 17 15:17:54.111734 2026] [security2:error] [pid 971102:tid 971277] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/gcp/.env"] [unique_id "aqxZAucL08BTTQixEnp5SQAAACs"]
[Thu Sep 17 15:17:54.198128 2026] [security2:error] [pid 971102:tid 971263] [client 34.95.173.223:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5TQAAAB0"]
[Thu Sep 17 15:17:54.265396 2026] [security2:error] [pid 971102:tid 971260] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.prod.bak"] [unique_id "aqxZAucL08BTTQixEnp5TgAAABo"]
[Thu Sep 17 15:17:54.267355 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/.git/.env"] [unique_id "aqxZAucL08BTTQixEnp5TwAAAHU"]
[Thu Sep 17 15:17:54.271303 2026] [security2:error] [pid 971102:tid 971267] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cloud/.env"] [unique_id "aqxZAucL08BTTQixEnp5UAAAACE"]
[Thu Sep 17 15:17:54.301306 2026] [security2:error] [pid 971102:tid 971275] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxZAucL08BTTQixEnp5UgAAACk"]
[Thu Sep 17 15:17:54.381181 2026] [security2:error] [pid 971102:tid 971300] [client 34.166.218.131:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5VAAAAEI"]
[Thu Sep 17 15:17:54.432322 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/infrastructure/.env"] [unique_id "aqxZAucL08BTTQixEnp5VwAAAFA"]
[Thu Sep 17 15:17:54.443054 2026] [security2:error] [pid 971102:tid 971315] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/ci/.env"] [unique_id "aqxZAucL08BTTQixEnp5WAAAAFE"]
[Thu Sep 17 15:17:54.467641 2026] [security2:error] [pid 971102:tid 971270] [client 34.154.67.31:51960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5WgAAACQ"]
[Thu Sep 17 15:17:54.489554 2026] [security2:error] [pid 971102:tid 971249] [client 66.249.66.199:40488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nlfephrata.org"] [uri "/index.php"] [unique_id "aqxZAucL08BTTQixEnp5UQAAAA8"]
[Thu Sep 17 15:17:54.533040 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxZAucL08BTTQixEnp5XAAAAFw"]
[Thu Sep 17 15:17:54.542960 2026] [security2:error] [pid 971102:tid 971361] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.development.old"] [unique_id "aqxZAucL08BTTQixEnp5XQAAAH8"]
[Thu Sep 17 15:17:54.595579 2026] [security2:error] [pid 971102:tid 971333] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/docker/.env"] [unique_id "aqxZAucL08BTTQixEnp5YAAAAGM"]
[Thu Sep 17 15:17:54.606790 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/cd/.env"] [unique_id "aqxZAucL08BTTQixEnp5YQAAABU"]
[Thu Sep 17 15:17:54.670526 2026] [security2:error] [pid 971102:tid 971318] [client 185.213.175.37:38438] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker.env"] [unique_id "aqxZAucL08BTTQixEnp5YgAAAFQ"]
[Thu Sep 17 15:17:54.684557 2026] [security2:error] [pid 971102:tid 971294] [client 34.95.173.223:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5YwAAADw"]
[Thu Sep 17 15:17:54.761807 2026] [security2:error] [pid 971102:tid 971245] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/k8s/.env"] [unique_id "aqxZAucL08BTTQixEnp5agAAAAs"]
[Thu Sep 17 15:17:54.768610 2026] [security2:error] [pid 971102:tid 971252] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/jenkins/.env"] [unique_id "aqxZAucL08BTTQixEnp5awAAABI"]
[Thu Sep 17 15:17:54.768620 2026] [security2:error] [pid 971102:tid 971290] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxZAucL08BTTQixEnp5bAAAADg"]
[Thu Sep 17 15:17:54.924910 2026] [security2:error] [pid 971102:tid 971331] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxZAucL08BTTQixEnp5bgAAAGE"]
[Thu Sep 17 15:17:54.924933 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/kubernetes/.env"] [unique_id "aqxZAucL08BTTQixEnp5bwAAADo"]
[Thu Sep 17 15:17:54.929615 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxZAucL08BTTQixEnp5cAAAACc"], referer: binance.com
[Thu Sep 17 15:17:54.942502 2026] [security2:error] [pid 971102:tid 971344] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/gitlab/.env"] [unique_id "aqxZAucL08BTTQixEnp5cQAAAG4"]
[Thu Sep 17 15:17:54.954770 2026] [security2:error] [pid 971102:tid 971358] [client 34.154.67.31:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZAucL08BTTQixEnp5cgAAAHw"]
[Thu Sep 17 15:17:55.002205 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxZA-cL08BTTQixEnp5cwAAAA0"]
[Thu Sep 17 15:17:55.063716 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxZA-cL08BTTQixEnp5dQAAAHI"]
[Thu Sep 17 15:17:55.070454 2026] [security2:error] [pid 971102:tid 971334] [client 34.166.218.131:55780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5dgAAAGQ"]
[Thu Sep 17 15:17:55.097488 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/terraform/.env"] [unique_id "aqxZA-cL08BTTQixEnp5dwAAAGI"]
[Thu Sep 17 15:17:55.100549 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/github/.env"] [unique_id "aqxZA-cL08BTTQixEnp5eAAAAE4"]
[Thu Sep 17 15:17:55.132623 2026] [security2:error] [pid 971102:tid 971265] [client 45.169.98.18:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5eQAAAB8"]
[Thu Sep 17 15:17:55.132757 2026] [security2:error] [pid 971102:tid 971265] [client 45.169.98.18:60915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5eQAAAB8"]
[Thu Sep 17 15:17:55.189266 2026] [security2:error] [pid 971102:tid 971360] [client 34.95.173.223:37714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5fgAAAH4"]
[Thu Sep 17 15:17:55.207386 2026] [security2:error] [pid 971102:tid 971323] [client 185.213.175.37:38438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxZA-cL08BTTQixEnp5gQAAAFk"]
[Thu Sep 17 15:17:55.207486 2026] [security2:error] [pid 971102:tid 971323] [client 185.213.175.37:38438] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxZA-cL08BTTQixEnp5gQAAAFk"]
[Thu Sep 17 15:17:55.229847 2026] [security2:error] [pid 971102:tid 971339] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxZA-cL08BTTQixEnp5gwAAAGk"]
[Thu Sep 17 15:17:55.257885 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/ansible/.env"] [unique_id "aqxZA-cL08BTTQixEnp5hAAAAEM"]
[Thu Sep 17 15:17:55.262561 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/actions/.env"] [unique_id "aqxZA-cL08BTTQixEnp5hQAAAEc"]
[Thu Sep 17 15:17:55.344726 2026] [security2:error] [pid 971102:tid 971353] [client 185.213.175.37:38428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxZA-cL08BTTQixEnp5hwAAAHc"]
[Thu Sep 17 15:17:55.415859 2026] [security2:error] [pid 971102:tid 971287] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/.git/.env"] [unique_id "aqxZA-cL08BTTQixEnp5iQAAADU"]
[Thu Sep 17 15:17:55.419354 2026] [security2:error] [pid 971102:tid 971280] [client 34.154.67.31:51984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5igAAAC4"]
[Thu Sep 17 15:17:55.420091 2026] [authz_core:error] [pid 971102:tid 971299] [client 172.239.147.162:51966] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:55.424510 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/circleci/.env"] [unique_id "aqxZA-cL08BTTQixEnp5iwAAAAU"]
[Thu Sep 17 15:17:55.465686 2026] [security2:error] [pid 971102:tid 971303] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jAAAAEU"]
[Thu Sep 17 15:17:55.482923 2026] [security2:error] [pid 971102:tid 971329] [client 185.213.175.37:38444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/admin/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jQAAAF8"]
[Thu Sep 17 15:17:55.589868 2026] [security2:error] [pid 971102:tid 971244] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/ci/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jgAAAAo"]
[Thu Sep 17 15:17:55.611305 2026] [security2:error] [pid 971102:tid 971319] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/travis/.env"] [unique_id "aqxZA-cL08BTTQixEnp5jwAAAFU"]
[Thu Sep 17 15:17:55.635582 2026] [security2:error] [pid 971102:tid 971272] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config"] [unique_id "aqxZA-cL08BTTQixEnp5kQAAACY"]
[Thu Sep 17 15:17:55.676211 2026] [security2:error] [pid 971102:tid 971235] [client 34.95.173.223:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5lQAAAAE"]
[Thu Sep 17 15:17:55.696554 2026] [security2:error] [pid 971102:tid 971351] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxZA-cL08BTTQixEnp5lgAAAHU"]
[Thu Sep 17 15:17:55.752706 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/cd/.env"] [unique_id "aqxZA-cL08BTTQixEnp5lwAAACk"]
[Thu Sep 17 15:17:55.763258 2026] [security2:error] [pid 971102:tid 971284] [client 34.166.218.131:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5mAAAADI"]
[Thu Sep 17 15:17:55.780716 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/buildkite/.env"] [unique_id "aqxZA-cL08BTTQixEnp5mwAAAEI"]
[Thu Sep 17 15:17:55.818238 2026] [security2:error] [pid 971102:tid 971286] [client 185.55.149.49:53496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5nAAAADQ"]
[Thu Sep 17 15:17:55.818342 2026] [security2:error] [pid 971102:tid 971286] [client 185.55.149.49:53496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZA-cL08BTTQixEnp5nAAAADQ"]
[Thu Sep 17 15:17:55.903335 2026] [security2:error] [pid 971102:tid 971267] [client 34.154.67.31:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.67.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.waa.nmb.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZA-cL08BTTQixEnp5nwAAACE"]
[Thu Sep 17 15:17:55.929652 2026] [security2:error] [pid 971102:tid 971297] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/jenkins/.env"] [unique_id "aqxZA-cL08BTTQixEnp5oQAAAD8"]
[Thu Sep 17 15:17:55.930844 2026] [security2:error] [pid 971102:tid 971270] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxZA-cL08BTTQixEnp5ogAAACQ"]
[Thu Sep 17 15:17:55.931458 2026] [security2:error] [pid 971102:tid 971259] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.js"] [unique_id "aqxZA-cL08BTTQixEnp5owAAABk"]
[Thu Sep 17 15:17:55.949109 2026] [security2:error] [pid 971102:tid 971311] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mysql/.env"] [unique_id "aqxZA-cL08BTTQixEnp5pAAAAE0"]
[Thu Sep 17 15:17:56.060046 2026] [security2:error] [pid 971102:tid 971253] [client 185.213.175.37:38444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.js"] [unique_id "aqxZBOcL08BTTQixEnp5pQAAABM"]
[Thu Sep 17 15:17:56.089355 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/gitlab/.env"] [unique_id "aqxZBOcL08BTTQixEnp5pwAAACo"]
[Thu Sep 17 15:17:56.112056 2026] [security2:error] [pid 971102:tid 971337] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/postgres/.env"] [unique_id "aqxZBOcL08BTTQixEnp5qAAAAGc"]
[Thu Sep 17 15:17:56.161890 2026] [security2:error] [pid 971102:tid 971350] [client 34.95.173.223:37730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZBOcL08BTTQixEnp5qwAAAHQ"]
[Thu Sep 17 15:17:56.163298 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxZBOcL08BTTQixEnp5rAAAABw"]
[Thu Sep 17 15:17:56.201284 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.py"] [unique_id "aqxZBOcL08BTTQixEnp5rQAAABQ"]
[Thu Sep 17 15:17:56.225856 2026] [security2:error] [pid 971102:tid 971217] [remote 110.249.201.128:65354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/better-watch-out-better-not-cry-ken-ham-is-coming-to-town-part-1/"] [unique_id "aqxZBOcL08BTTQixEnp5rwAAG3A"]
[Thu Sep 17 15:17:56.259132 2026] [security2:error] [pid 971102:tid 971296] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/github/.env"] [unique_id "aqxZBOcL08BTTQixEnp5sAAAAD4"]
[Thu Sep 17 15:17:56.275043 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/mongodb/.env"] [unique_id "aqxZBOcL08BTTQixEnp5sQAAAFY"]
[Thu Sep 17 15:17:56.396892 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxZBOcL08BTTQixEnp5twAAAC8"]
[Thu Sep 17 15:17:56.425618 2026] [security2:error] [pid 971102:tid 971293] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/actions/.env"] [unique_id "aqxZBOcL08BTTQixEnp5uAAAADs"]
[Thu Sep 17 15:17:56.441941 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/redis/.env"] [unique_id "aqxZBOcL08BTTQixEnp5uQAAABY"]
[Thu Sep 17 15:17:56.452407 2026] [security2:error] [pid 971102:tid 971294] [client 34.166.218.131:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZBOcL08BTTQixEnp5ugAAADw"]
[Thu Sep 17 15:17:56.549304 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp5vAAAAE8"]
[Thu Sep 17 15:17:56.549453 2026] [security2:error] [pid 971102:tid 971313] [client 104.28.198.244:22664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp5vAAAAE8"]
[Thu Sep 17 15:17:56.588200 2026] [security2:error] [pid 971102:tid 971269] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/circleci/.env"] [unique_id "aqxZBOcL08BTTQixEnp5vQAAACM"]
[Thu Sep 17 15:17:56.598819 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZBOcL08BTTQixEnp5vwAAAGE"]
[Thu Sep 17 15:17:56.627198 2026] [security2:error] [pid 971102:tid 971344] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxZBOcL08BTTQixEnp5wAAAAG4"]
[Thu Sep 17 15:17:56.652221 2026] [security2:error] [pid 971102:tid 971243] [client 34.95.173.223:37732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZBOcL08BTTQixEnp5wgAAAAk"]
[Thu Sep 17 15:17:56.741119 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/travis/.env"] [unique_id "aqxZBOcL08BTTQixEnp5xgAAAE4"]
[Thu Sep 17 15:17:56.755376 2026] [security2:error] [pid 971102:tid 971265] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZBOcL08BTTQixEnp5yAAAAB8"]
[Thu Sep 17 15:17:56.857598 2026] [security2:error] [pid 971102:tid 971291] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxZBOcL08BTTQixEnp5zAAAADk"]
[Thu Sep 17 15:17:56.899042 2026] [security2:error] [pid 971102:tid 971343] [client 185.213.175.37:38444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config/production.json"] [unique_id "aqxZBOcL08BTTQixEnp5zgAAAG0"]
[Thu Sep 17 15:17:56.902844 2026] [security2:error] [pid 971102:tid 971304] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/buildkite/.env"] [unique_id "aqxZBOcL08BTTQixEnp50QAAAEY"]
[Thu Sep 17 15:17:56.904792 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:42140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp50wAAADY"]
[Thu Sep 17 15:17:56.911814 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:42140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBOcL08BTTQixEnp50wAAADY"]
[Thu Sep 17 15:17:56.923049 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/kafka/.env"] [unique_id "aqxZBOcL08BTTQixEnp51AAAAGw"]
[Thu Sep 17 15:17:56.990788 2026] [security2:error] [pid 971102:tid 971358] [client 210.222.43.21:63746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZBOcL08BTTQixEnp5ywAAAHw"], referer: http://talent-in-borders.com/main
[Thu Sep 17 15:17:57.039006 2026] [security2:error] [pid 971102:tid 971346] [client 194.46.238.145:59884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZBOcL08BTTQixEnp51QAAcFY"]
[Thu Sep 17 15:17:57.057482 2026] [security2:error] [pid 971102:tid 971299] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mysql/.env"] [unique_id "aqxZBecL08BTTQixEnp52QAAAEE"]
[Thu Sep 17 15:17:57.085029 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxZBecL08BTTQixEnp52wAAAEo"]
[Thu Sep 17 15:17:57.085037 2026] [security2:error] [pid 971102:tid 971328] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/queue/.env"] [unique_id "aqxZBecL08BTTQixEnp53AAAAF4"]
[Thu Sep 17 15:17:57.129565 2026] [security2:error] [pid 971102:tid 971282] [client 34.166.218.131:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp53gAAADA"]
[Thu Sep 17 15:17:57.150443 2026] [security2:error] [pid 971102:tid 971287] [client 34.95.173.223:37742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp54QAAADU"]
[Thu Sep 17 15:17:57.194439 2026] [authz_core:error] [pid 971102:tid 971280] [client 172.239.147.162:64024] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:17:57.209808 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/postgres/.env"] [unique_id "aqxZBecL08BTTQixEnp56AAAAB0"]
[Thu Sep 17 15:17:57.236174 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/worker/.env"] [unique_id "aqxZBecL08BTTQixEnp56QAAAAE"]
[Thu Sep 17 15:17:57.312299 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxZBecL08BTTQixEnp57QAAAHo"]
[Thu Sep 17 15:17:57.371026 2026] [security2:error] [pid 971102:tid 971297] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/mongodb/.env"] [unique_id "aqxZBecL08BTTQixEnp58AAAAD8"]
[Thu Sep 17 15:17:57.400783 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/job/.env"] [unique_id "aqxZBecL08BTTQixEnp58QAAACQ"]
[Thu Sep 17 15:17:57.531714 2026] [security2:error] [pid 971102:tid 971278] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/redis/.env"] [unique_id "aqxZBecL08BTTQixEnp5-AAAACw"]
[Thu Sep 17 15:17:57.539664 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxZBecL08BTTQixEnp5-gAAAFw"]
[Thu Sep 17 15:17:57.560647 2026] [security2:error] [pid 971102:tid 971361] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/test/.env"] [unique_id "aqxZBecL08BTTQixEnp5-wAAAH8"]
[Thu Sep 17 15:17:57.633203 2026] [security2:error] [pid 971102:tid 971324] [client 34.95.173.223:37750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp5_gAAAFo"]
[Thu Sep 17 15:17:57.682124 2026] [security2:error] [pid 971102:tid 971325] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZBecL08BTTQixEnp6AgAAAFs"]
[Thu Sep 17 15:17:57.718115 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/qa/.env"] [unique_id "aqxZBecL08BTTQixEnp6BAAAAFY"]
[Thu Sep 17 15:17:57.768816 2026] [security2:error] [pid 971102:tid 971241] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxZBecL08BTTQixEnp6BQAAAAc"]
[Thu Sep 17 15:17:57.808674 2026] [security2:error] [pid 971102:tid 971276] [client 34.166.218.131:55802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZBecL08BTTQixEnp6BgAAACo"]
[Thu Sep 17 15:17:57.837853 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZBecL08BTTQixEnp6BwAAAD0"]
[Thu Sep 17 15:17:57.850116 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBecL08BTTQixEnp6CAAAAGo"]
[Thu Sep 17 15:17:57.850201 2026] [security2:error] [pid 971102:tid 971340] [client 114.198.138.124:56402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZBecL08BTTQixEnp6CAAAAGo"]
[Thu Sep 17 15:17:57.878142 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/preview/.env"] [unique_id "aqxZBecL08BTTQixEnp6CgAAAC8"]
[Thu Sep 17 15:17:57.992842 2026] [security2:error] [pid 971102:tid 971256] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/kafka/.env"] [unique_id "aqxZBecL08BTTQixEnp6DgAAABY"]
[Thu Sep 17 15:17:58.004116 2026] [security2:error] [pid 971102:tid 971294] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxZBucL08BTTQixEnp6DwAAADw"]
[Thu Sep 17 15:17:58.073711 2026] [security2:error] [pid 971102:tid 971331] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/beta/.env"] [unique_id "aqxZBucL08BTTQixEnp6EgAAAGE"]
[Thu Sep 17 15:17:58.120018 2026] [security2:error] [pid 971102:tid 971293] [client 34.95.173.223:37752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.christiansoncampusnlc.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZBucL08BTTQixEnp6FAAAADs"]
[Thu Sep 17 15:17:58.146195 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/serviceAccountKey.json"] [unique_id "aqxZBucL08BTTQixEnp6FQAAAHI"]
[Thu Sep 17 15:17:58.148040 2026] [security2:error] [pid 971102:tid 971345] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/queue/.env"] [unique_id "aqxZBucL08BTTQixEnp6FgAAAG8"]
[Thu Sep 17 15:17:58.235842 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/uat/.env"] [unique_id "aqxZBucL08BTTQixEnp6GQAAAE4"]
[Thu Sep 17 15:17:58.239079 2026] [security2:error] [pid 971102:tid 971265] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxZBucL08BTTQixEnp6GgAAAB8"]
[Thu Sep 17 15:17:58.313904 2026] [security2:error] [pid 971102:tid 971357] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/worker/.env"] [unique_id "aqxZBucL08BTTQixEnp6GwAAAHs"]
[Thu Sep 17 15:17:58.393580 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/stage/.env"] [unique_id "aqxZBucL08BTTQixEnp6IQAAAEc"]
[Thu Sep 17 15:17:58.469368 2026] [security2:error] [pid 971102:tid 971288] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/job/.env"] [unique_id "aqxZBucL08BTTQixEnp6JQAAADY"]
[Thu Sep 17 15:17:58.472445 2026] [security2:error] [pid 971102:tid 971240] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxZBucL08BTTQixEnp6JwAAAAY"]
[Thu Sep 17 15:17:58.506208 2026] [security2:error] [pid 971102:tid 971360] [client 34.166.218.131:55814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZBucL08BTTQixEnp6KAAAAH4"]
[Thu Sep 17 15:17:58.550461 2026] [security2:error] [pid 971102:tid 971316] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/development/.env"] [unique_id "aqxZBucL08BTTQixEnp6KQAAAFI"]
[Thu Sep 17 15:17:58.627115 2026] [security2:error] [pid 971102:tid 971346] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/test/.env"] [unique_id "aqxZBucL08BTTQixEnp6LAAAAHA"]
[Thu Sep 17 15:17:58.700385 2026] [security2:error] [pid 971102:tid 971236] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxZBucL08BTTQixEnp6MAAAAAI"]
[Thu Sep 17 15:17:58.703844 2026] [security2:error] [pid 971102:tid 971280] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/production/.env"] [unique_id "aqxZBucL08BTTQixEnp6MgAAAC4"]
[Thu Sep 17 15:17:58.720892 2026] [security2:error] [pid 971102:tid 971341] [client 185.213.175.37:38428] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.git/HEAD"] [unique_id "aqxZBucL08BTTQixEnp6MwAAAGs"]
[Thu Sep 17 15:17:58.784851 2026] [security2:error] [pid 971102:tid 971235] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/qa/.env"] [unique_id "aqxZBucL08BTTQixEnp6NQAAAAE"]
[Thu Sep 17 15:17:58.857097 2026] [security2:error] [pid 971102:tid 971314] [client 34.151.157.242:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcoaching.com"] [uri "/config/app/.env"] [unique_id "aqxZBucL08BTTQixEnp6OAAAAFA"]
[Thu Sep 17 15:17:58.928986 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.208.101:55904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxZBucL08BTTQixEnp6OwAAAEg"]
[Thu Sep 17 15:17:58.935672 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/preview/.env"] [unique_id "aqxZBucL08BTTQixEnp6PAAAACQ"]
[Thu Sep 17 15:17:59.018216 2026] [security2:error] [pid 971102:tid 971319] [client 34.151.157.242:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6RQAAAFU"]
[Thu Sep 17 15:17:59.027854 2026] [security2:error] [pid 971102:tid 971284] [client 185.213.175.37:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/wp-config.php"] [unique_id "aqxZBucL08BTTQixEnp6PwAAADI"]
[Thu Sep 17 15:17:59.086371 2026] [security2:error] [pid 971102:tid 971253] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/beta/.env"] [unique_id "aqxZB-cL08BTTQixEnp6SAAAABM"]
[Thu Sep 17 15:17:59.131274 2026] [security2:error] [pid 971102:tid 971309] [client 185.213.175.37:38444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/wp-config.php.bak"] [unique_id "aqxZB-cL08BTTQixEnp6SwAAAEs"]
[Thu Sep 17 15:17:59.193308 2026] [security2:error] [pid 971102:tid 971311] [client 34.166.218.131:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6TwAAAE0"]
[Thu Sep 17 15:17:59.237781 2026] [security2:error] [pid 971102:tid 971359] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/uat/.env"] [unique_id "aqxZB-cL08BTTQixEnp6UgAAAH0"]
[Thu Sep 17 15:17:59.389047 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/stage/.env"] [unique_id "aqxZB-cL08BTTQixEnp6VQAAADo"]
[Thu Sep 17 15:17:59.405184 2026] [security2:error] [pid 971102:tid 971295] [client 200.104.130.167:38298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZB-cL08BTTQixEnp6UwAAPSo"]
[Thu Sep 17 15:17:59.440264 2026] [authz_core:error] [pid 971102:tid 971245] [client 172.239.147.162:49436] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:17:59.477157 2026] [security2:error] [pid 971102:tid 971294] [client 34.151.157.242:39118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/info.php"] [unique_id "aqxZB-cL08BTTQixEnp6WQAAADw"]
[Thu Sep 17 15:17:59.540708 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/development/.env"] [unique_id "aqxZB-cL08BTTQixEnp6XQAAAEk"]
[Thu Sep 17 15:17:59.602853 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config/database.yml"] [unique_id "aqxZB-cL08BTTQixEnp6XgAAAHI"]
[Thu Sep 17 15:17:59.611300 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxZB-cL08BTTQixEnp6XwAAACM"]
[Thu Sep 17 15:17:59.692118 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/production/.env"] [unique_id "aqxZB-cL08BTTQixEnp6ZAAAAEc"]
[Thu Sep 17 15:17:59.738186 2026] [security2:error] [pid 971102:tid 971355] [client 185.213.175.37:44048] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker-compose.yml"] [unique_id "aqxZB-cL08BTTQixEnp6ZgAAAHk"]
[Thu Sep 17 15:17:59.821740 2026] [security2:error] [pid 971102:tid 971291] [client 172.239.147.162:56842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxZB-cL08BTTQixEnp6aQAAADk"], referer: binance.com
[Thu Sep 17 15:17:59.838479 2026] [security2:error] [pid 971102:tid 971304] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxZB-cL08BTTQixEnp6agAAAEY"]
[Thu Sep 17 15:17:59.842927 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agingwellcounseling.com"] [uri "/config/app/.env"] [unique_id "aqxZB-cL08BTTQixEnp6awAAAGw"]
[Thu Sep 17 15:17:59.876718 2026] [security2:error] [pid 971102:tid 971317] [client 34.166.218.131:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6bQAAAFM"]
[Thu Sep 17 15:17:59.907651 2026] [security2:error] [pid 971102:tid 971302] [client 185.213.175.37:44048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/config"] [unique_id "aqxZB-cL08BTTQixEnp6bgAAAEQ"]
[Thu Sep 17 15:17:59.907793 2026] [security2:error] [pid 971102:tid 971302] [client 185.213.175.37:44048] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/config"] [unique_id "aqxZB-cL08BTTQixEnp6bgAAAEQ"]
[Thu Sep 17 15:17:59.927557 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:39124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/php.php"] [unique_id "aqxZB-cL08BTTQixEnp6bwAAAAA"]
[Thu Sep 17 15:17:59.992677 2026] [security2:error] [pid 971102:tid 971343] [client 34.151.157.242:50394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php"] [unique_id "aqxZB-cL08BTTQixEnp6dAAAAG0"]
[Thu Sep 17 15:18:00.065261 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxZCOcL08BTTQixEnp6dQAAAHA"]
[Thu Sep 17 15:18:00.076703 2026] [security2:error] [pid 971102:tid 971310] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/settings"] [unique_id "aqxZCOcL08BTTQixEnp6dgAAAEw"]
[Thu Sep 17 15:18:00.247947 2026] [security2:error] [pid 971102:tid 971263] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/v1/config"] [unique_id "aqxZCOcL08BTTQixEnp6ewAAAB0"]
[Thu Sep 17 15:18:00.293935 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxZCOcL08BTTQixEnp6fAAAAEI"]
[Thu Sep 17 15:18:00.390501 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:39134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/i.php"] [unique_id "aqxZCOcL08BTTQixEnp6fgAAAGs"]
[Thu Sep 17 15:18:00.425483 2026] [security2:error] [pid 971102:tid 971244] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/v1/settings"] [unique_id "aqxZCOcL08BTTQixEnp6fwAAAAo"]
[Thu Sep 17 15:18:00.452127 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:39140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/info.php"] [unique_id "aqxZCOcL08BTTQixEnp6gAAAAHU"]
[Thu Sep 17 15:18:00.476376 2026] [security2:error] [pid 971102:tid 971328] [client 186.105.232.15:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6gQAAAF4"]
[Thu Sep 17 15:18:00.476477 2026] [security2:error] [pid 971102:tid 971328] [client 186.105.232.15:56486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6gQAAAF4"]
[Thu Sep 17 15:18:00.528050 2026] [security2:error] [pid 971102:tid 971354] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxZCOcL08BTTQixEnp6hgAAAHg"]
[Thu Sep 17 15:18:00.570997 2026] [security2:error] [pid 971102:tid 971287] [client 34.166.218.131:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZCOcL08BTTQixEnp6hwAAADU"]
[Thu Sep 17 15:18:00.606704 2026] [security2:error] [pid 971102:tid 971284] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/openapi.json"] [unique_id "aqxZCOcL08BTTQixEnp6iAAAADI"]
[Thu Sep 17 15:18:00.758936 2026] [security2:error] [pid 971102:tid 971327] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxZCOcL08BTTQixEnp6jQAAAF0"]
[Thu Sep 17 15:18:00.799023 2026] [security2:error] [pid 971102:tid 971296] [client 185.213.175.37:44058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/id_rsa"] [unique_id "aqxZCOcL08BTTQixEnp6jgAAAD4"]
[Thu Sep 17 15:18:00.849787 2026] [security2:error] [pid 971102:tid 971309] [client 34.151.157.242:39154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/pi.php"] [unique_id "aqxZCOcL08BTTQixEnp6kAAAAEs"]
[Thu Sep 17 15:18:00.862750 2026] [security2:error] [pid 971102:tid 971238] [client 156.192.234.52:53201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6kgAAAAQ"]
[Thu Sep 17 15:18:00.863428 2026] [security2:error] [pid 971102:tid 971238] [client 156.192.234.52:53201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZCOcL08BTTQixEnp6kgAAAAQ"]
[Thu Sep 17 15:18:00.902852 2026] [security2:error] [pid 971102:tid 971324] [client 34.151.157.242:39168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/php.php"] [unique_id "aqxZCOcL08BTTQixEnp6kwAAAFo"]
[Thu Sep 17 15:18:00.985239 2026] [security2:error] [pid 971102:tid 971322] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxZCOcL08BTTQixEnp6lQAAAFg"]
[Thu Sep 17 15:18:00.985769 2026] [security2:error] [pid 971102:tid 971340] [client 185.213.175.37:44058] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/id_ed25519"] [unique_id "aqxZCOcL08BTTQixEnp6lAAAAGo"]
[Thu Sep 17 15:18:00.995412 2026] [authz_core:error] [pid 971102:tid 971261] [client 172.239.147.162:51958] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:01.211168 2026] [security2:error] [pid 971102:tid 971344] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxZCecL08BTTQixEnp6oQAAAG4"]
[Thu Sep 17 15:18:01.251382 2026] [security2:error] [pid 971102:tid 971275] [client 34.166.218.131:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xge.txw.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZCecL08BTTQixEnp6ogAAACk"]
[Thu Sep 17 15:18:01.301598 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:39184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/pinfo.php"] [unique_id "aqxZCecL08BTTQixEnp6pQAAAFY"]
[Thu Sep 17 15:18:01.357078 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/i.php"] [unique_id "aqxZCecL08BTTQixEnp6qAAAAAk"]
[Thu Sep 17 15:18:01.393538 2026] [security2:error] [pid 971102:tid 971269] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/log"] [unique_id "aqxZCecL08BTTQixEnp6qQAAACM"]
[Thu Sep 17 15:18:01.441276 2026] [security2:error] [pid 971102:tid 971312] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxZCecL08BTTQixEnp6qgAAAE4"]
[Thu Sep 17 15:18:01.672530 2026] [security2:error] [pid 971102:tid 971332] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxZCecL08BTTQixEnp6sgAAAGI"]
[Thu Sep 17 15:18:01.787666 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:39198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/test.php"] [unique_id "aqxZCecL08BTTQixEnp6tgAAAGw"]
[Thu Sep 17 15:18:01.830727 2026] [security2:error] [pid 971102:tid 971339] [client 34.151.157.242:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/pi.php"] [unique_id "aqxZCecL08BTTQixEnp6uAAAAGk"]
[Thu Sep 17 15:18:01.843322 2026] [security2:error] [pid 971102:tid 971234] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app.log"] [unique_id "aqxZCecL08BTTQixEnp6uQAAAAA"]
[Thu Sep 17 15:18:01.900222 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxZCecL08BTTQixEnp6ugAAAG0"]
[Thu Sep 17 15:18:02.128085 2026] [security2:error] [pid 971102:tid 971255] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxZCucL08BTTQixEnp6wgAAABU"]
[Thu Sep 17 15:18:02.234563 2026] [security2:error] [pid 971102:tid 971308] [client 172.239.147.162:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxZCucL08BTTQixEnp6yQAAAEo"], referer: binance.com
[Thu Sep 17 15:18:02.281133 2026] [security2:error] [pid 971102:tid 971328] [client 62.113.113.162:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.113.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/thank_you.php"] [unique_id "aqxZCucL08BTTQixEnp6zAAAAF4"], referer: http://chicagolandexteriorsinc.com/thank_you.php
[Thu Sep 17 15:18:02.285842 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:39228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/pinfo.php"] [unique_id "aqxZCucL08BTTQixEnp6zgAAAEI"]
[Thu Sep 17 15:18:02.309302 2026] [security2:error] [pid 971102:tid 971306] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/_profiler/phpinfo"] [unique_id "aqxZCucL08BTTQixEnp6zwAAAEg"]
[Thu Sep 17 15:18:02.315604 2026] [security2:error] [pid 971102:tid 971314] [client 172.239.147.162:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxZCucL08BTTQixEnp60AAAAFA"], referer: binance.com
[Thu Sep 17 15:18:02.354920 2026] [security2:error] [pid 971102:tid 971270] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxZCucL08BTTQixEnp60QAAACQ"]
[Thu Sep 17 15:18:02.401593 2026] [security2:error] [pid 971102:tid 971242] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZCucL08BTTQixEnp6zQAAAAg"]
[Thu Sep 17 15:18:02.585167 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxZCucL08BTTQixEnp62AAAAFw"]
[Thu Sep 17 15:18:02.717447 2026] [security2:error] [pid 971102:tid 971350] [client 34.151.157.242:39220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/p.php"] [unique_id "aqxZCucL08BTTQixEnp63wAAAHQ"]
[Thu Sep 17 15:18:02.750569 2026] [security2:error] [pid 971102:tid 971327] [client 34.151.157.242:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/test.php"] [unique_id "aqxZCucL08BTTQixEnp64gAAAF0"]
[Thu Sep 17 15:18:02.819081 2026] [security2:error] [pid 971102:tid 971318] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxZCucL08BTTQixEnp65QAAAFQ"]
[Thu Sep 17 15:18:02.830837 2026] [security2:error] [pid 971102:tid 971335] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/dump.sql"] [unique_id "aqxZCucL08BTTQixEnp65gAAAGU"]
[Thu Sep 17 15:18:03.050713 2026] [security2:error] [pid 971102:tid 971293] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxZC-cL08BTTQixEnp66gAAADs"]
[Thu Sep 17 15:18:03.063015 2026] [security2:error] [pid 971102:tid 971272] [client 62.113.113.162:64151] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "62.113.113.162" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "chicagolandexteriorsinc.com"] [uri "/contact.php"] [unique_id "aqxZC-cL08BTTQixEnp66wAAACY"], referer: http://chicagolandexteriorsinc.com/contact.php
[Thu Sep 17 15:18:03.172701 2026] [security2:error] [pid 971102:tid 971345] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backup.sql"] [unique_id "aqxZC-cL08BTTQixEnp68wAAAG8"]
[Thu Sep 17 15:18:03.177972 2026] [security2:error] [pid 971102:tid 971275] [client 34.151.157.242:54498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/debug.php"] [unique_id "aqxZC-cL08BTTQixEnp69AAAACk"]
[Thu Sep 17 15:18:03.277822 2026] [security2:error] [pid 971102:tid 971257] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxZC-cL08BTTQixEnp6-gAAABc"]
[Thu Sep 17 15:18:03.356733 2026] [security2:error] [pid 971102:tid 971312] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZC-cL08BTTQixEnp6-QAAAE4"]
[Thu Sep 17 15:18:03.451478 2026] [security2:error] [pid 971102:tid 971321] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/db.sql"] [unique_id "aqxZC-cL08BTTQixEnp6_QAAAFc"]
[Thu Sep 17 15:18:03.509284 2026] [security2:error] [pid 971102:tid 971333] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxZC-cL08BTTQixEnp6_wAAAGM"]
[Thu Sep 17 15:18:03.643064 2026] [security2:error] [pid 971102:tid 971330] [client 34.151.157.242:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZC-cL08BTTQixEnp7BQAAAGA"]
[Thu Sep 17 15:18:03.663815 2026] [security2:error] [pid 971102:tid 971283] [client 34.151.157.242:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/p.php"] [unique_id "aqxZC-cL08BTTQixEnp7BgAAADE"]
[Thu Sep 17 15:18:03.761281 2026] [security2:error] [pid 971102:tid 971244] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxZC-cL08BTTQixEnp7DAAAAAo"]
[Thu Sep 17 15:18:03.764001 2026] [security2:error] [pid 971102:tid 971351] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/database.sql"] [unique_id "aqxZC-cL08BTTQixEnp7DQAAAHU"]
[Thu Sep 17 15:18:03.845345 2026] [security2:error] [pid 971102:tid 971282] [client 172.239.147.162:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxZC-cL08BTTQixEnp7EAAAADA"], referer: binance.com
[Thu Sep 17 15:18:03.897043 2026] [authz_core:error] [pid 971102:tid 971337] [client 5.189.145.112:61686] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:03.987734 2026] [security2:error] [pid 971102:tid 971286] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxZC-cL08BTTQixEnp7GQAAADQ"]
[Thu Sep 17 15:18:04.073229 2026] [security2:error] [pid 971102:tid 971287] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production.old"] [unique_id "aqxZDOcL08BTTQixEnp7JAAAADU"]
[Thu Sep 17 15:18:04.137718 2026] [security2:error] [pid 971102:tid 971259] [client 34.151.157.242:54528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZDOcL08BTTQixEnp7JgAAABk"]
[Thu Sep 17 15:18:04.142556 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:54544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/debug.php"] [unique_id "aqxZDOcL08BTTQixEnp7JwAAACQ"]
[Thu Sep 17 15:18:04.225433 2026] [security2:error] [pid 971102:tid 971285] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxZDOcL08BTTQixEnp7OQAAADM"]
[Thu Sep 17 15:18:04.260143 2026] [security2:error] [pid 971102:tid 971329] [client 172.239.147.162:59533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxZDOcL08BTTQixEnp7OwAAAF8"], referer: binance.com
[Thu Sep 17 15:18:04.457142 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxZDOcL08BTTQixEnp7TQAAABI"]
[Thu Sep 17 15:18:04.633225 2026] [security2:error] [pid 971102:tid 971322] [client 34.151.157.242:54556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZDOcL08BTTQixEnp7TgAAAFg"]
[Thu Sep 17 15:18:04.654763 2026] [security2:error] [pid 971102:tid 971340] [client 34.151.157.242:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZDOcL08BTTQixEnp7TwAAAGo"]
[Thu Sep 17 15:18:04.689409 2026] [security2:error] [pid 971102:tid 971277] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxZDOcL08BTTQixEnp7UQAAACs"]
[Thu Sep 17 15:18:04.918012 2026] [security2:error] [pid 971102:tid 971235] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxZDOcL08BTTQixEnp7YAAAAAE"]
[Thu Sep 17 15:18:05.012149 2026] [security2:error] [pid 971102:tid 971251] [client 104.28.198.244:22803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7agAAABE"]
[Thu Sep 17 15:18:05.080827 2026] [security2:error] [pid 971102:tid 971275] [client 185.213.175.37:44062] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/v1/keys"] [unique_id "aqxZDecL08BTTQixEnp7bAAAACk"]
[Thu Sep 17 15:18:05.150679 2026] [security2:error] [pid 971102:tid 971323] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxZDecL08BTTQixEnp7bQAAAFk"]
[Thu Sep 17 15:18:05.157203 2026] [security2:error] [pid 971102:tid 971243] [client 34.151.157.242:54572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7bwAAAAk"]
[Thu Sep 17 15:18:05.157219 2026] [security2:error] [pid 971102:tid 971292] [client 34.151.157.242:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7bgAAADo"]
[Thu Sep 17 15:18:05.209855 2026] [security2:error] [pid 971102:tid 971251] [client 104.28.198.244:22803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7agAAABE"]
[Thu Sep 17 15:18:05.406205 2026] [security2:error] [pid 971102:tid 971269] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxZDecL08BTTQixEnp7cwAAACM"]
[Thu Sep 17 15:18:05.612322 2026] [security2:error] [pid 971102:tid 971332] [client 45.169.98.18:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7gAAAAGI"]
[Thu Sep 17 15:18:05.612460 2026] [security2:error] [pid 971102:tid 971332] [client 45.169.98.18:61474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZDecL08BTTQixEnp7gAAAAGI"]
[Thu Sep 17 15:18:05.633803 2026] [security2:error] [pid 971102:tid 971279] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxZDecL08BTTQixEnp7ggAAAC0"]
[Thu Sep 17 15:18:05.657651 2026] [security2:error] [pid 971102:tid 971302] [client 34.151.157.242:54600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7gwAAAEQ"]
[Thu Sep 17 15:18:05.670459 2026] [security2:error] [pid 971102:tid 971273] [client 172.239.147.162:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxZDecL08BTTQixEnp7hAAAACc"], referer: binance.com
[Thu Sep 17 15:18:05.675892 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZDecL08BTTQixEnp7hQAAAGw"]
[Thu Sep 17 15:18:05.800772 2026] [security2:error] [pid 971102:tid 971339] [client 172.239.147.162:59030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxZDecL08BTTQixEnp7iAAAAGk"], referer: binance.com
[Thu Sep 17 15:18:05.861196 2026] [security2:error] [pid 971102:tid 971236] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxZDecL08BTTQixEnp7jwAAAAI"]
[Thu Sep 17 15:18:06.118335 2026] [security2:error] [pid 971102:tid 971356] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxZDucL08BTTQixEnp7mQAAAHo"]
[Thu Sep 17 15:18:06.203208 2026] [security2:error] [pid 971102:tid 971259] [client 34.151.157.242:54614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZDucL08BTTQixEnp7mwAAABk"]
[Thu Sep 17 15:18:06.242672 2026] [security2:error] [pid 971102:tid 971270] [client 34.151.157.242:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZDucL08BTTQixEnp7nQAAACQ"]
[Thu Sep 17 15:18:06.348587 2026] [security2:error] [pid 971102:tid 971252] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxZDucL08BTTQixEnp7oQAAABI"]
[Thu Sep 17 15:18:06.560695 2026] [security2:error] [pid 971102:tid 971258] [client 185.55.149.49:54214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZDucL08BTTQixEnp7pgAAABg"]
[Thu Sep 17 15:18:06.560818 2026] [security2:error] [pid 971102:tid 971258] [client 185.55.149.49:54214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZDucL08BTTQixEnp7pgAAABg"]
[Thu Sep 17 15:18:06.579110 2026] [security2:error] [pid 971102:tid 971326] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxZDucL08BTTQixEnp7pwAAAFw"]
[Thu Sep 17 15:18:06.602102 2026] [security2:error] [pid 971102:tid 971278] [client 185.213.175.37:44062] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/cgi/printenv"] [unique_id "aqxZDucL08BTTQixEnp7qAAAACw"]
[Thu Sep 17 15:18:06.779849 2026] [security2:error] [pid 971102:tid 971264] [client 34.151.157.242:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZDucL08BTTQixEnp7qwAAAB4"]
[Thu Sep 17 15:18:06.810835 2026] [security2:error] [pid 971102:tid 971295] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxZDucL08BTTQixEnp7rwAAAD0"]
[Thu Sep 17 15:18:06.854978 2026] [security2:error] [pid 971102:tid 971235] [client 201.252.128.60:35713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZDucL08BTTQixEnp7qgAAAXw"]
[Thu Sep 17 15:18:06.912131 2026] [security2:error] [pid 971102:tid 971336] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZDucL08BTTQixEnp7rgAAAGY"]
[Thu Sep 17 15:18:07.041324 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:44066] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/application_default_credentials.json"] [unique_id "aqxZD-cL08BTTQixEnp7tgAAABQ"]
[Thu Sep 17 15:18:07.047170 2026] [security2:error] [pid 971102:tid 971305] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxZD-cL08BTTQixEnp7twAAAEc"]
[Thu Sep 17 15:18:07.206384 2026] [security2:error] [pid 971102:tid 971312] [client 185.213.175.37:44066] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.aws/config"] [unique_id "aqxZD-cL08BTTQixEnp7wAAAAE4"]
[Thu Sep 17 15:18:07.278436 2026] [security2:error] [pid 971102:tid 971271] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxZD-cL08BTTQixEnp7wQAAACU"]
[Thu Sep 17 15:18:07.290109 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZD-cL08BTTQixEnp7wgAAAHk"]
[Thu Sep 17 15:18:07.303072 2026] [security2:error] [pid 971102:tid 971276] [client 34.151.157.242:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/php-info.php"] [unique_id "aqxZD-cL08BTTQixEnp7wwAAACo"]
[Thu Sep 17 15:18:07.495303 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:41385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZD-cL08BTTQixEnp7yQAAADY"]
[Thu Sep 17 15:18:07.495786 2026] [security2:error] [pid 971102:tid 971288] [client 154.190.208.131:41385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZD-cL08BTTQixEnp7yQAAADY"]
[Thu Sep 17 15:18:07.511103 2026] [security2:error] [pid 971102:tid 971302] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxZD-cL08BTTQixEnp7ygAAAEQ"]
[Thu Sep 17 15:18:07.661860 2026] [security2:error] [pid 971102:tid 971342] [client 172.239.147.162:51503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxZD-cL08BTTQixEnp7zAAAAGw"], referer: binance.com
[Thu Sep 17 15:18:07.702413 2026] [security2:error] [pid 971102:tid 971279] [client 172.239.147.162:51956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxZD-cL08BTTQixEnp7zQAAAC0"], referer: binance.com
[Thu Sep 17 15:18:07.742518 2026] [security2:error] [pid 971102:tid 971300] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxZD-cL08BTTQixEnp7zgAAAEI"]
[Thu Sep 17 15:18:07.786146 2026] [security2:error] [pid 971102:tid 971274] [client 185.213.175.37:44066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/n8n"] [unique_id "aqxZD-cL08BTTQixEnp70QAAACg"]
[Thu Sep 17 15:18:07.786253 2026] [security2:error] [pid 971102:tid 971274] [client 185.213.175.37:44066] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/n8n"] [unique_id "aqxZD-cL08BTTQixEnp70QAAACg"]
[Thu Sep 17 15:18:07.813362 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:54642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpversion.php"] [unique_id "aqxZD-cL08BTTQixEnp71AAAAAI"]
[Thu Sep 17 15:18:07.974219 2026] [security2:error] [pid 971102:tid 971328] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxZD-cL08BTTQixEnp72gAAAF4"]
[Thu Sep 17 15:18:08.093337 2026] [security2:error] [pid 971102:tid 971325] [client 185.213.175.37:44072] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker-compose.yaml"] [unique_id "aqxZEOcL08BTTQixEnp74gAAAFs"]
[Thu Sep 17 15:18:08.125962 2026] [security2:error] [pid 971102:tid 971247] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZEOcL08BTTQixEnp74AAAAA0"]
[Thu Sep 17 15:18:08.206237 2026] [security2:error] [pid 971102:tid 971262] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxZEOcL08BTTQixEnp75gAAABw"]
[Thu Sep 17 15:18:08.315950 2026] [security2:error] [pid 971102:tid 971239] [client 34.151.157.242:54652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/_phpinfo.php"] [unique_id "aqxZEOcL08BTTQixEnp76gAAAAU"]
[Thu Sep 17 15:18:08.426025 2026] [security2:error] [pid 971102:tid 971245] [client 185.213.175.37:44072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/docker-compose.yaml.bak"] [unique_id "aqxZEOcL08BTTQixEnp78AAAAAs"]
[Thu Sep 17 15:18:08.436071 2026] [security2:error] [pid 971102:tid 971316] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxZEOcL08BTTQixEnp78QAAAFI"]
[Thu Sep 17 15:18:08.448835 2026] [security2:error] [pid 971102:tid 971263] [client 34.151.157.242:54640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/php-info.php"] [unique_id "aqxZEOcL08BTTQixEnp78gAAAB0"]
[Thu Sep 17 15:18:08.503568 2026] [security2:error] [pid 971102:tid 971258] [client 114.198.138.124:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZEOcL08BTTQixEnp79QAAABg"]
[Thu Sep 17 15:18:08.503706 2026] [security2:error] [pid 971102:tid 971258] [client 114.198.138.124:57054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZEOcL08BTTQixEnp79QAAABg"]
[Thu Sep 17 15:18:08.642034 2026] [security2:error] [pid 971102:tid 971307] [client 176.166.138.255:51826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZEOcL08BTTQixEnp79gAAST4"]
[Thu Sep 17 15:18:08.668666 2026] [security2:error] [pid 971102:tid 971305] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxZEOcL08BTTQixEnp7_gAAAEc"]
[Thu Sep 17 15:18:08.748477 2026] [security2:error] [pid 971102:tid 971331] [client 185.213.175.37:44072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.env.production.yaml"] [unique_id "aqxZEOcL08BTTQixEnp8AAAAAGE"]
[Thu Sep 17 15:18:08.814907 2026] [security2:error] [pid 971102:tid 971254] [client 34.151.157.242:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZEOcL08BTTQixEnp8BgAAABQ"]
[Thu Sep 17 15:18:08.911845 2026] [security2:error] [pid 971102:tid 971346] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxZEOcL08BTTQixEnp8CQAAAHA"]
[Thu Sep 17 15:18:08.938495 2026] [security2:error] [pid 971102:tid 971271] [client 34.151.157.242:54682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpversion.php"] [unique_id "aqxZEOcL08BTTQixEnp8CwAAACU"]
[Thu Sep 17 15:18:09.143664 2026] [security2:error] [pid 971102:tid 971297] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxZEecL08BTTQixEnp8EgAAAD8"]
[Thu Sep 17 15:18:09.296095 2026] [security2:error] [pid 971102:tid 971332] [client 34.151.157.242:54688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/server-info.php"] [unique_id "aqxZEecL08BTTQixEnp8FQAAAGI"]
[Thu Sep 17 15:18:09.378780 2026] [security2:error] [pid 971102:tid 971306] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxZEecL08BTTQixEnp8HAAAAEg"]
[Thu Sep 17 15:18:09.428568 2026] [security2:error] [pid 971102:tid 971314] [client 172.239.147.162:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxZEecL08BTTQixEnp8HgAAAFA"], referer: binance.com
[Thu Sep 17 15:18:09.441812 2026] [security2:error] [pid 971102:tid 971255] [client 34.151.157.242:54700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/_phpinfo.php"] [unique_id "aqxZEecL08BTTQixEnp8HwAAABU"]
[Thu Sep 17 15:18:09.604626 2026] [security2:error] [pid 971102:tid 971259] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxZEecL08BTTQixEnp8IwAAABk"]
[Thu Sep 17 15:18:09.698297 2026] [security2:error] [pid 971102:tid 971347] [client 185.213.175.37:48390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/aws/credentials.json"] [unique_id "aqxZEecL08BTTQixEnp8JgAAAHE"]
[Thu Sep 17 15:18:09.797750 2026] [security2:error] [pid 971102:tid 971268] [client 34.151.157.242:54704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/server-status.php"] [unique_id "aqxZEecL08BTTQixEnp8KwAAACI"]
[Thu Sep 17 15:18:09.831160 2026] [security2:error] [pid 971102:tid 971308] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxZEecL08BTTQixEnp8LgAAAEo"]
[Thu Sep 17 15:18:09.935275 2026] [security2:error] [pid 971102:tid 971301] [client 34.151.157.242:54718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZEecL08BTTQixEnp8NgAAAEM"]
[Thu Sep 17 15:18:10.057191 2026] [security2:error] [pid 971102:tid 971249] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxZEucL08BTTQixEnp8OAAAAA8"]
[Thu Sep 17 15:18:10.092762 2026] [security2:error] [pid 971102:tid 971316] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.aws/credentials.json"] [unique_id "aqxZEucL08BTTQixEnp8OQAAAFI"]
[Thu Sep 17 15:18:10.285449 2026] [security2:error] [pid 971102:tid 971294] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxZEucL08BTTQixEnp8RgAAADw"]
[Thu Sep 17 15:18:10.327770 2026] [security2:error] [pid 971102:tid 971348] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app-config.json"] [unique_id "aqxZEucL08BTTQixEnp8TQAAAHI"]
[Thu Sep 17 15:18:10.409651 2026] [security2:error] [pid 971102:tid 971326] [client 43.173.173.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8QgAAAFw"]
[Thu Sep 17 15:18:10.429409 2026] [security2:error] [pid 971102:tid 971305] [client 34.151.157.242:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/server-info.php"] [unique_id "aqxZEucL08BTTQixEnp8UwAAAEc"]
[Thu Sep 17 15:18:10.476844 2026] [security2:error] [pid 971102:tid 971320] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8TwAAAFY"]
[Thu Sep 17 15:18:10.480288 2026] [security2:error] [pid 971102:tid 971276] [client 43.173.174.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8TgAAACo"]
[Thu Sep 17 15:18:10.511935 2026] [security2:error] [pid 971102:tid 971324] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxZEucL08BTTQixEnp8VgAAAFo"]
[Thu Sep 17 15:18:10.597407 2026] [security2:error] [pid 971102:tid 971332] [client 3.82.141.143:37532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/web.config"] [unique_id "aqxZEucL08BTTQixEnp8XQAAAGI"]
[Thu Sep 17 15:18:10.607252 2026] [security2:error] [pid 971102:tid 971274] [client 3.82.141.143:37464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php"] [unique_id "aqxZEucL08BTTQixEnp8ZQAAACg"]
[Thu Sep 17 15:18:10.607545 2026] [security2:error] [pid 971102:tid 971247] [client 3.82.141.143:37446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rcpphotorestoration.com"] [uri "/config.php"] [unique_id "aqxZEucL08BTTQixEnp8ZwAAAA0"]
[Thu Sep 17 15:18:10.608898 2026] [security2:error] [pid 971102:tid 971282] [client 3.82.141.143:37632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env.bak"] [unique_id "aqxZEucL08BTTQixEnp8YgAAADA"]
[Thu Sep 17 15:18:10.626912 2026] [security2:error] [pid 971102:tid 971240] [client 3.82.141.143:37466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php~"] [unique_id "aqxZEucL08BTTQixEnp8cgAAAAY"]
[Thu Sep 17 15:18:10.627066 2026] [security2:error] [pid 971102:tid 971283] [client 3.82.141.143:37564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php.old"] [unique_id "aqxZEucL08BTTQixEnp8dQAAADE"]
[Thu Sep 17 15:18:10.629136 2026] [security2:error] [pid 971102:tid 971297] [client 3.82.141.143:37584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env.backup"] [unique_id "aqxZEucL08BTTQixEnp8dAAAAD8"]
[Thu Sep 17 15:18:10.645014 2026] [security2:error] [pid 971102:tid 971259] [client 3.82.141.143:37604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php.bak"] [unique_id "aqxZEucL08BTTQixEnp8eQAAABk"]
[Thu Sep 17 15:18:10.646430 2026] [security2:error] [pid 971102:tid 971306] [client 3.82.141.143:37600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env"] [unique_id "aqxZEucL08BTTQixEnp8egAAAEg"]
[Thu Sep 17 15:18:10.659371 2026] [security2:error] [pid 971102:tid 971329] [client 3.82.141.143:37532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.rcpphotorestoration.com"] [uri "/wp-config.php.save"] [unique_id "aqxZEucL08BTTQixEnp8ewAAAF8"]
[Thu Sep 17 15:18:10.666190 2026] [security2:error] [pid 971102:tid 971280] [client 3.82.141.143:37356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.rcpphotorestoration.com"] [uri "/.env.old"] [unique_id "aqxZEucL08BTTQixEnp8ggAAAC4"]
[Thu Sep 17 15:18:10.740601 2026] [security2:error] [pid 971102:tid 971307] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxZEucL08BTTQixEnp8gwAAAEk"]
[Thu Sep 17 15:18:10.788099 2026] [security2:error] [pid 971102:tid 971253] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/server-config.json"] [unique_id "aqxZEucL08BTTQixEnp8hwAAABM"]
[Thu Sep 17 15:18:10.905238 2026] [security2:error] [pid 971102:tid 971281] [client 34.151.157.242:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/server-status.php"] [unique_id "aqxZEucL08BTTQixEnp8kAAAAC8"]
[Thu Sep 17 15:18:10.985251 2026] [security2:error] [pid 971102:tid 971351] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZEucL08BTTQixEnp8jgAAAHU"]
[Thu Sep 17 15:18:10.986877 2026] [security2:error] [pid 971102:tid 971279] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxZEucL08BTTQixEnp8kQAAAC0"]
[Thu Sep 17 15:18:10.997133 2026] [security2:error] [pid 971102:tid 971315] [client 185.213.175.37:48392] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/settings.json"] [unique_id "aqxZEucL08BTTQixEnp8kgAAAFE"]
[Thu Sep 17 15:18:11.161523 2026] [security2:error] [pid 971102:tid 971341] [client 34.151.157.242:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZE-cL08BTTQixEnp8mQAAAGs"]
[Thu Sep 17 15:18:11.221134 2026] [security2:error] [pid 971102:tid 971298] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxZE-cL08BTTQixEnp8mwAAAEA"]
[Thu Sep 17 15:18:11.407806 2026] [security2:error] [pid 971102:tid 971350] [client 185.213.175.37:48392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/configuration.json"] [unique_id "aqxZE-cL08BTTQixEnp8pAAAAHQ"]
[Thu Sep 17 15:18:11.407930 2026] [security2:error] [pid 971102:tid 971350] [client 185.213.175.37:48392] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/configuration.json"] [unique_id "aqxZE-cL08BTTQixEnp8pAAAAHQ"]
[Thu Sep 17 15:18:11.453358 2026] [security2:error] [pid 971102:tid 971238] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxZE-cL08BTTQixEnp8pwAAAAQ"]
[Thu Sep 17 15:18:11.497568 2026] [security2:error] [pid 971102:tid 971241] [client 186.105.232.15:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8qwAAAAc"]
[Thu Sep 17 15:18:11.497671 2026] [security2:error] [pid 971102:tid 971241] [client 186.105.232.15:57043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8qwAAAAc"]
[Thu Sep 17 15:18:11.520555 2026] [security2:error] [pid 971102:tid 971337] [client 156.192.234.52:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8rgAAAGc"]
[Thu Sep 17 15:18:11.523567 2026] [security2:error] [pid 971102:tid 971337] [client 156.192.234.52:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZE-cL08BTTQixEnp8rgAAAGc"]
[Thu Sep 17 15:18:11.650333 2026] [security2:error] [pid 971102:tid 971235] [client 85.204.70.90:52506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lemuspools.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxZE-cL08BTTQixEnp8sQAAAAE"]
[Thu Sep 17 15:18:11.663982 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZE-cL08BTTQixEnp8sgAAAE8"]
[Thu Sep 17 15:18:11.685337 2026] [security2:error] [pid 971102:tid 971345] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxZE-cL08BTTQixEnp8tAAAAG8"]
[Thu Sep 17 15:18:11.808424 2026] [security2:error] [pid 971102:tid 971267] [client 185.213.175.37:48396] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/conf.json"] [unique_id "aqxZE-cL08BTTQixEnp8tgAAACE"]
[Thu Sep 17 15:18:11.919400 2026] [security2:error] [pid 971102:tid 971234] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxZE-cL08BTTQixEnp8vQAAAAA"]
[Thu Sep 17 15:18:11.940390 2026] [security2:error] [pid 971102:tid 971264] [client 172.239.147.162:62125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxZE-cL08BTTQixEnp8vgAAAB4"], referer: binance.com
[Thu Sep 17 15:18:11.958576 2026] [security2:error] [pid 971102:tid 971307] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZE-cL08BTTQixEnp8uAAAAEk"]
[Thu Sep 17 15:18:11.976982 2026] [security2:error] [pid 971102:tid 971254] [client 185.213.175.37:48396] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/conf/config.json"] [unique_id "aqxZE-cL08BTTQixEnp8wAAAABQ"]
[Thu Sep 17 15:18:12.036784 2026] [security2:error] [pid 971102:tid 971256] [client 185.213.175.37:48400] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/settings.json"] [unique_id "aqxZFOcL08BTTQixEnp8wQAAABY"]
[Thu Sep 17 15:18:12.151462 2026] [security2:error] [pid 971102:tid 971343] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxZFOcL08BTTQixEnp8yAAAAG0"]
[Thu Sep 17 15:18:12.188074 2026] [security2:error] [pid 971102:tid 971346] [client 34.151.157.242:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZFOcL08BTTQixEnp8yQAAAHA"]
[Thu Sep 17 15:18:12.265316 2026] [security2:error] [pid 971102:tid 971348] [client 85.204.70.90:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxZFOcL08BTTQixEnp8ygAAAHI"]
[Thu Sep 17 15:18:12.383178 2026] [security2:error] [pid 971102:tid 971273] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxZFOcL08BTTQixEnp8zgAAACc"]
[Thu Sep 17 15:18:12.616636 2026] [security2:error] [pid 971102:tid 971329] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxZFOcL08BTTQixEnp88AAAAF8"]
[Thu Sep 17 15:18:12.675430 2026] [security2:error] [pid 971102:tid 971236] [client 34.151.157.242:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZFOcL08BTTQixEnp89gAAAAI"]
[Thu Sep 17 15:18:12.742847 2026] [security2:error] [pid 971102:tid 971291] [client 34.151.157.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZFOcL08BTTQixEnp88QAAADk"]
[Thu Sep 17 15:18:12.761363 2026] [autoindex:error] [pid 971102:tid 971304] [client 45.115.26.203:49230] AH01276: Cannot serve directory /home1/awesone8/public_html/risingstarspress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:18:12.846380 2026] [security2:error] [pid 971102:tid 971337] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxZFOcL08BTTQixEnp9EAAAAGc"]
[Thu Sep 17 15:18:12.953892 2026] [security2:error] [pid 971102:tid 971313] [client 34.151.157.242:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZFOcL08BTTQixEnp9EwAAAE8"]
[Thu Sep 17 15:18:13.080471 2026] [security2:error] [pid 971102:tid 971336] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxZFecL08BTTQixEnp9FgAAAGY"]
[Thu Sep 17 15:18:13.176101 2026] [security2:error] [pid 971102:tid 971295] [client 34.151.157.242:42474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9HgAAAD0"]
[Thu Sep 17 15:18:13.257370 2026] [security2:error] [pid 971102:tid 971307] [client 172.239.147.162:59251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxZFecL08BTTQixEnp9HwAAAEk"], referer: binance.com
[Thu Sep 17 15:18:13.289503 2026] [security2:error] [pid 971102:tid 971324] [client 185.213.175.37:48418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.json"] [unique_id "aqxZFecL08BTTQixEnp9IAAAAFo"]
[Thu Sep 17 15:18:13.289646 2026] [security2:error] [pid 971102:tid 971324] [client 185.213.175.37:48418] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/env.json"] [unique_id "aqxZFecL08BTTQixEnp9IAAAAFo"]
[Thu Sep 17 15:18:13.310426 2026] [security2:error] [pid 971102:tid 971272] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxZFecL08BTTQixEnp9IQAAACY"]
[Thu Sep 17 15:18:13.483415 2026] [security2:error] [pid 971102:tid 971347] [client 34.151.157.242:42488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9LAAAAHE"]
[Thu Sep 17 15:18:13.540637 2026] [security2:error] [pid 971102:tid 971281] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxZFecL08BTTQixEnp9LgAAAC8"]
[Thu Sep 17 15:18:13.687985 2026] [security2:error] [pid 971102:tid 971342] [client 34.151.157.242:42504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9NAAAAGw"]
[Thu Sep 17 15:18:13.720987 2026] [security2:error] [pid 971102:tid 971351] [client 185.213.175.37:48402] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/environment.json"] [unique_id "aqxZFecL08BTTQixEnp9NwAAAHU"]
[Thu Sep 17 15:18:13.773710 2026] [security2:error] [pid 971102:tid 971287] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxZFecL08BTTQixEnp9OQAAADU"]
[Thu Sep 17 15:18:13.831975 2026] [security2:error] [pid 971102:tid 971257] [client 46.101.77.15:53470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZE-cL08BTTQixEnp8vwAAFxA"], referer: http://newspace.us./blog/
[Thu Sep 17 15:18:13.999195 2026] [security2:error] [pid 971102:tid 971355] [client 34.151.157.242:42506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZFecL08BTTQixEnp9RAAAAHk"]
[Thu Sep 17 15:18:14.005868 2026] [security2:error] [pid 971102:tid 971247] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxZFucL08BTTQixEnp9RQAAAA0"]
[Thu Sep 17 15:18:14.174734 2026] [security2:error] [pid 971102:tid 971255] [client 46.101.77.15:53470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZFucL08BTTQixEnp9RwAAFSc"], referer: http://newspace.us./backup/
[Thu Sep 17 15:18:14.207048 2026] [security2:error] [pid 971102:tid 971300] [client 34.151.157.242:42518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZFucL08BTTQixEnp9TwAAAEI"]
[Thu Sep 17 15:18:14.294241 2026] [security2:error] [pid 971102:tid 971263] [client 8.228.208.101:44280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxZFucL08BTTQixEnp9UAAAAB0"]
[Thu Sep 17 15:18:14.497800 2026] [security2:error] [pid 971102:tid 971234] [client 34.151.157.242:42520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZFucL08BTTQixEnp9WgAAAAA"]
[Thu Sep 17 15:18:15.202633 2026] [security2:error] [pid 971102:tid 971298] [client 118.179.125.113:4220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZF-cL08BTTQixEnp9WwAAQEI"]
[Thu Sep 17 15:18:15.225908 2026] [http2:info] [pid 1012520:tid 1012520] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:18:15.244251 2026] [security2:error] [pid 1012520:tid 1012657] [client 185.213.175.37:48454] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/secret.json"] [unique_id "aqxZFwpXMN3p_zkwXf2M8QAAAIs"]
[Thu Sep 17 15:18:15.404162 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.151.157.242:42532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZFwpXMN3p_zkwXf2M-gAAAIc"]
[Thu Sep 17 15:18:15.409512 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.151.157.242:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZFwpXMN3p_zkwXf2M-wAAAI0"]
[Thu Sep 17 15:18:15.454150 2026] [security2:error] [pid 1012520:tid 1012652] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZFwpXMN3p_zkwXf2M-QAAhgA"], referer: http://newspace.us./wordpress/
[Thu Sep 17 15:18:15.480788 2026] [security2:error] [pid 1012520:tid 1012662] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxZFwpXMN3p_zkwXf2M_QAAAJA"]
[Thu Sep 17 15:18:15.713336 2026] [security2:error] [pid 1012520:tid 1012684] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxZFwpXMN3p_zkwXf2NBwAAAKY"]
[Thu Sep 17 15:18:15.835191 2026] [security2:error] [pid 1012520:tid 1012689] [client 185.213.175.37:48472] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/api/keys.json"] [unique_id "aqxZFwpXMN3p_zkwXf2NCgAAAKs"]
[Thu Sep 17 15:18:15.899973 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.151.157.242:42568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZFwpXMN3p_zkwXf2NDgAAAKc"]
[Thu Sep 17 15:18:15.926223 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.151.157.242:42552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php~"] [unique_id "aqxZFwpXMN3p_zkwXf2NEgAAAKg"]
[Thu Sep 17 15:18:15.966085 2026] [security2:error] [pid 1012520:tid 1012696] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZFwpXMN3p_zkwXf2NDwAAsgM"], referer: http://newspace.us./new/
[Thu Sep 17 15:18:16.058286 2026] [fcgid:warn] [pid 1012520:tid 1012708] (70014)End of file found: [client 66.132.224.230:18838] mod_fcgid: can't get data from http client
[Thu Sep 17 15:18:16.076786 2026] [security2:error] [pid 1012520:tid 1012710] [client 85.204.70.90:58700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGQAAAMA"]
[Thu Sep 17 15:18:16.076923 2026] [security2:error] [pid 1012520:tid 1012710] [client 85.204.70.90:58700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGQAAAMA"]
[Thu Sep 17 15:18:16.099756 2026] [security2:error] [pid 1012520:tid 1012703] [client 45.169.98.18:62192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGgAAALk"]
[Thu Sep 17 15:18:16.099867 2026] [security2:error] [pid 1012520:tid 1012703] [client 45.169.98.18:62192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGApXMN3p_zkwXf2NGgAAALk"]
[Thu Sep 17 15:18:16.389601 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.151.157.242:42572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZGApXMN3p_zkwXf2NJwAAAM4"]
[Thu Sep 17 15:18:16.401565 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.151.157.242:42580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/info.php.bak"] [unique_id "aqxZGApXMN3p_zkwXf2NKQAAANA"]
[Thu Sep 17 15:18:16.710796 2026] [security2:error] [pid 1012520:tid 1012752] [client 185.213.175.37:48472] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.netrc"] [unique_id "aqxZGApXMN3p_zkwXf2NLgAAAOo"]
[Thu Sep 17 15:18:16.719226 2026] [security2:error] [pid 1012520:tid 1012753] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxZGApXMN3p_zkwXf2NMAAAAOs"]
[Thu Sep 17 15:18:16.721270 2026] [security2:error] [pid 1012520:tid 1012532] [remote 195.3.220.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.220.3.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beartoothagilityclub.com"] [uri "/.well-known/acme-challenge/wp-firewall.php"] [unique_id "aqxZGApXMN3p_zkwXf2NLwAA6Ao"]
[Thu Sep 17 15:18:16.914428 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.151.157.242:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZGApXMN3p_zkwXf2NNgAAAO4"]
[Thu Sep 17 15:18:16.928860 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.151.157.242:42590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZGApXMN3p_zkwXf2NNwAAAO8"]
[Thu Sep 17 15:18:16.951372 2026] [security2:error] [pid 1012520:tid 1012764] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxZGApXMN3p_zkwXf2NOgAAAPY"]
[Thu Sep 17 15:18:17.016375 2026] [security2:error] [pid 1012520:tid 1012766] [client 185.213.175.37:48472] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/google-services.json"] [unique_id "aqxZGQpXMN3p_zkwXf2NPQAAAPg"]
[Thu Sep 17 15:18:17.183770 2026] [security2:error] [pid 1012520:tid 1012773] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NPwAA_ww"], referer: http://newspace.us./old/
[Thu Sep 17 15:18:17.185048 2026] [security2:error] [pid 1012520:tid 1012657] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NQgAAAIs"]
[Thu Sep 17 15:18:17.231128 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.55.149.49:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NQwAAAPk"]
[Thu Sep 17 15:18:17.231235 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.55.149.49:54928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NQwAAAPk"]
[Thu Sep 17 15:18:17.354558 2026] [security2:error] [pid 1012520:tid 1012537] [remote 195.3.220.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.220.3.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beartoothagilityclub.com"] [uri "/.well-known/acme-challenge/222.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NSQAAmw8"]
[Thu Sep 17 15:18:17.391385 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.151.157.242:42604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NSwAAAI0"]
[Thu Sep 17 15:18:17.414488 2026] [security2:error] [pid 1012520:tid 1012676] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NTgAAAJ4"]
[Thu Sep 17 15:18:17.437085 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.151.157.242:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php~"] [unique_id "aqxZGQpXMN3p_zkwXf2NUQAAAJU"]
[Thu Sep 17 15:18:17.513178 2026] [security2:error] [pid 1012520:tid 1012687] [client 46.101.77.15:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NUwAAqRA"], referer: http://newspace.us./wp/
[Thu Sep 17 15:18:17.641585 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NVAAAAKw"]
[Thu Sep 17 15:18:17.657160 2026] [security2:error] [pid 1012520:tid 1012685] [client 185.213.175.37:48466] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/application.properties"] [unique_id "aqxZGQpXMN3p_zkwXf2NVwAAAKc"]
[Thu Sep 17 15:18:17.874957 2026] [security2:error] [pid 1012520:tid 1012704] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxZGQpXMN3p_zkwXf2NWQAAALo"]
[Thu Sep 17 15:18:17.890616 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.151.157.242:42622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZGQpXMN3p_zkwXf2NWgAAALA"]
[Thu Sep 17 15:18:17.907644 2026] [security2:error] [pid 1012520:tid 1012700] [client 185.213.175.37:48454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/application.yml.bak"] [unique_id "aqxZGQpXMN3p_zkwXf2NWwAAALY"]
[Thu Sep 17 15:18:17.922248 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.151.157.242:42624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/info.php.bak"] [unique_id "aqxZGQpXMN3p_zkwXf2NXAAAAKg"]
[Thu Sep 17 15:18:18.026037 2026] [security2:error] [pid 1012520:tid 1012689] [client 154.190.208.131:41997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NXgAAAKs"]
[Thu Sep 17 15:18:18.026169 2026] [security2:error] [pid 1012520:tid 1012689] [client 154.190.208.131:41997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NXgAAAKs"]
[Thu Sep 17 15:18:18.112646 2026] [security2:error] [pid 1012520:tid 1012710] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NXwAAAMA"]
[Thu Sep 17 15:18:18.320993 2026] [security2:error] [pid 1012520:tid 1012715] [client 128.201.185.153:57792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NZAAAxRM"]
[Thu Sep 17 15:18:18.345377 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NZgAAAJ0"]
[Thu Sep 17 15:18:18.388348 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.151.157.242:42628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NZwAAALc"]
[Thu Sep 17 15:18:18.390556 2026] [security2:error] [pid 1012520:tid 1012719] [client 185.213.175.37:48454] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.yml"] [unique_id "aqxZGgpXMN3p_zkwXf2NaAAAAMk"]
[Thu Sep 17 15:18:18.408905 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.151.157.242:42634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZGgpXMN3p_zkwXf2NagAAAMc"]
[Thu Sep 17 15:18:18.421679 2026] [authz_core:error] [pid 1012520:tid 1012678] [client 172.239.147.162:62409] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:18:18.574223 2026] [security2:error] [pid 1012520:tid 1012726] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NbQAAANA"]
[Thu Sep 17 15:18:18.613814 2026] [security2:error] [pid 1012520:tid 1012670] [client 185.213.175.37:48438] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/config.toml"] [unique_id "aqxZGgpXMN3p_zkwXf2NbwAAAJg"]
[Thu Sep 17 15:18:18.802891 2026] [security2:error] [pid 1012520:tid 1012742] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxZGgpXMN3p_zkwXf2NdAAAAOA"]
[Thu Sep 17 15:18:18.859530 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.151.157.242:42636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NdgAAANc"]
[Thu Sep 17 15:18:18.895784 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.151.157.242:42646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZGgpXMN3p_zkwXf2NdwAAAN8"]
[Thu Sep 17 15:18:19.010950 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NeAAAAOE"]
[Thu Sep 17 15:18:19.011096 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:57688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NeAAAAOE"]
[Thu Sep 17 15:18:19.030336 2026] [security2:error] [pid 1012520:tid 1012747] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NeQAAAOU"]
[Thu Sep 17 15:18:19.126930 2026] [authz_core:error] [pid 1012520:tid 1012716] [client 5.189.145.112:63023] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:19.257841 2026] [security2:error] [pid 1012520:tid 1012766] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NgAAAAPg"]
[Thu Sep 17 15:18:19.336854 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.151.157.242:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NhAAAAO8"]
[Thu Sep 17 15:18:19.405129 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.151.157.242:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NhwAAAPc"]
[Thu Sep 17 15:18:19.485149 2026] [security2:error] [pid 1012520:tid 1012768] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NiwAAAPo"]
[Thu Sep 17 15:18:19.622896 2026] [authz_core:error] [pid 1012520:tid 1012651] [client 185.213.175.37:48438] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Thu Sep 17 15:18:19.702537 2026] [authz_core:error] [pid 1012520:tid 1012666] [client 172.239.147.162:60129] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:18:19.713706 2026] [security2:error] [pid 1012520:tid 1012677] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NlQAAAJ8"]
[Thu Sep 17 15:18:19.827866 2026] [security2:error] [pid 1012520:tid 1012679] [client 185.213.175.37:48438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/token.json"] [unique_id "aqxZGwpXMN3p_zkwXf2NlgAAAKE"]
[Thu Sep 17 15:18:19.828022 2026] [security2:error] [pid 1012520:tid 1012679] [client 185.213.175.37:48438] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/token.json"] [unique_id "aqxZGwpXMN3p_zkwXf2NlgAAAKE"]
[Thu Sep 17 15:18:19.830639 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.151.157.242:42676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NlwAAAJE"]
[Thu Sep 17 15:18:19.890900 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.151.157.242:42680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NmQAAAKQ"]
[Thu Sep 17 15:18:19.943446 2026] [security2:error] [pid 1012520:tid 1012688] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxZGwpXMN3p_zkwXf2NnAAAAKo"]
[Thu Sep 17 15:18:20.168648 2026] [security2:error] [pid 1012520:tid 1012686] [client 127.0.0.1:17636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxZHApXMN3p_zkwXf2NoQAAAKg"]
[Thu Sep 17 15:18:20.168685 2026] [security2:error] [pid 1012520:tid 1012700] [client 127.0.0.1:17622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.starrjoyblog.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxZHApXMN3p_zkwXf2NoAAAALY"]
[Thu Sep 17 15:18:20.168965 2026] [security2:error] [pid 1012520:tid 1012694] [client 74.7.228.2:33370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.starrjoyblog.com"] [uri "/robots.txt"] [unique_id "aqxZHApXMN3p_zkwXf2NnwAAsB0"]
[Thu Sep 17 15:18:20.175856 2026] [security2:error] [pid 1012520:tid 1012689] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NpQAAAKs"]
[Thu Sep 17 15:18:20.335414 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.151.157.242:42692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NqAAAALw"]
[Thu Sep 17 15:18:20.372741 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.151.157.242:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NqQAAAJA"]
[Thu Sep 17 15:18:20.408734 2026] [security2:error] [pid 1012520:tid 1012715] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NqgAAAMU"]
[Thu Sep 17 15:18:20.501270 2026] [security2:error] [pid 1012520:tid 1012652] [client 185.213.175.37:46788] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/credentials.yml"] [unique_id "aqxZHApXMN3p_zkwXf2NrwAAAIY"]
[Thu Sep 17 15:18:20.638571 2026] [security2:error] [pid 1012520:tid 1012678] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NsQAAAKA"]
[Thu Sep 17 15:18:20.671544 2026] [security2:error] [pid 1012520:tid 1012725] [client 185.213.175.37:46794] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/.git/HEAD"] [unique_id "aqxZHApXMN3p_zkwXf2NsgAAAM8"]
[Thu Sep 17 15:18:20.820195 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.151.157.242:42704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NtQAAALs"]
[Thu Sep 17 15:18:20.835843 2026] [security2:error] [pid 1012520:tid 1012722] [client 185.213.175.37:46794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/.git/HEAD"] [unique_id "aqxZHApXMN3p_zkwXf2NtwAAAMw"]
[Thu Sep 17 15:18:20.835965 2026] [security2:error] [pid 1012520:tid 1012722] [client 185.213.175.37:46794] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/app/.git/HEAD"] [unique_id "aqxZHApXMN3p_zkwXf2NtwAAAMw"]
[Thu Sep 17 15:18:20.869052 2026] [security2:error] [pid 1012520:tid 1012736] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxZHApXMN3p_zkwXf2NuQAAANo"]
[Thu Sep 17 15:18:20.872615 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.151.157.242:42706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZHApXMN3p_zkwXf2NugAAAM0"]
[Thu Sep 17 15:18:21.096293 2026] [security2:error] [pid 1012520:tid 1012731] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2NvQAAANU"]
[Thu Sep 17 15:18:21.252840 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.168.200.72:19441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "freeofgravity.com"] [uri "/index.php"] [unique_id "aqxZGwpXMN3p_zkwXf2NnQAAAKI"]
[Thu Sep 17 15:18:21.298730 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.151.157.242:42708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2NxQAAAOQ"]
[Thu Sep 17 15:18:21.323584 2026] [security2:error] [pid 1012520:tid 1012757] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2NxgAAAO8"]
[Thu Sep 17 15:18:21.350947 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.151.157.242:42718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2NxwAAAJc"]
[Thu Sep 17 15:18:21.429003 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.246.241.88:42496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHQpXMN3p_zkwXf2NyAAAAPw"]
[Thu Sep 17 15:18:21.448686 2026] [security2:error] [pid 1012520:tid 1012772] [client 185.213.175.37:46788] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sew.hwe.mybluehost.me"] [uri "/backend/.git/HEAD"] [unique_id "aqxZHQpXMN3p_zkwXf2NygAAAP4"]
[Thu Sep 17 15:18:21.500197 2026] [authz_core:error] [pid 1012520:tid 1012765] [client 172.239.147.162:50694] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:21.553425 2026] [security2:error] [pid 1012520:tid 1012778] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2NzQAAAQQ"]
[Thu Sep 17 15:18:21.763899 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.151.157.242:42722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2N0QAAAIs"]
[Thu Sep 17 15:18:21.784558 2026] [security2:error] [pid 1012520:tid 1012776] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxZHQpXMN3p_zkwXf2N0gAAAQI"]
[Thu Sep 17 15:18:21.825627 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.151.157.242:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZHQpXMN3p_zkwXf2N0wAAAIU"]
[Thu Sep 17 15:18:22.010888 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N2AAAAKw"]
[Thu Sep 17 15:18:22.055435 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.246.241.88:37342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHgpXMN3p_zkwXf2N2QAAAKk"]
[Thu Sep 17 15:18:22.081119 2026] [security2:error] [pid 1012520:tid 1012677] [client 156.192.234.52:54452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N2gAAAJ8"]
[Thu Sep 17 15:18:22.081733 2026] [security2:error] [pid 1012520:tid 1012677] [client 156.192.234.52:54452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N2gAAAJ8"]
[Thu Sep 17 15:18:22.223066 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.151.157.242:42744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N5gAAAKo"]
[Thu Sep 17 15:18:22.239552 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N5wAAALQ"]
[Thu Sep 17 15:18:22.300158 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.151.157.242:42752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N6QAAALo"]
[Thu Sep 17 15:18:22.469188 2026] [security2:error] [pid 1012520:tid 1012718] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N6wAAAMg"]
[Thu Sep 17 15:18:22.697858 2026] [security2:error] [pid 1012520:tid 1012722] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N8AAAAMw"]
[Thu Sep 17 15:18:22.723023 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.151.157.242:42768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N8wAAAM8"]
[Thu Sep 17 15:18:22.756710 2026] [security2:error] [pid 1012520:tid 1012562] [remote 122.14.226.13:29030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christiansoncampusnlc.com"] [uri "/robots.txt"] [unique_id "aqxZHgpXMN3p_zkwXf2N9AAAkSg"]
[Thu Sep 17 15:18:22.793725 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.151.157.242:42782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N9gAAALs"]
[Thu Sep 17 15:18:22.833703 2026] [security2:error] [pid 1012520:tid 1012661] [client 186.105.232.15:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N-QAAAI8"]
[Thu Sep 17 15:18:22.833891 2026] [security2:error] [pid 1012520:tid 1012661] [client 186.105.232.15:57617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZHgpXMN3p_zkwXf2N-QAAAI8"]
[Thu Sep 17 15:18:22.926289 2026] [security2:error] [pid 1012520:tid 1012733] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxZHgpXMN3p_zkwXf2N_wAAANc"]
[Thu Sep 17 15:18:22.953032 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:37356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHgpXMN3p_zkwXf2OAgAAANo"]
[Thu Sep 17 15:18:22.956111 2026] [authz_core:error] [pid 1012520:tid 1012734] [client 172.239.147.162:51074] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:18:23.169132 2026] [security2:error] [pid 1012520:tid 1012757] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2OCAAAAO8"]
[Thu Sep 17 15:18:23.174189 2026] [security2:error] [pid 1012520:tid 1012724] [client 185.219.41.85:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.219.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OBgAAAM4"]
[Thu Sep 17 15:18:23.198952 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.151.157.242:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OCQAAAPg"]
[Thu Sep 17 15:18:23.285592 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.151.157.242:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OCwAAAOo"]
[Thu Sep 17 15:18:23.402407 2026] [security2:error] [pid 1012520:tid 1012770] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2ODAAAAPw"]
[Thu Sep 17 15:18:23.632246 2026] [security2:error] [pid 1012520:tid 1012676] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2OEwAAAJ4"]
[Thu Sep 17 15:18:23.690378 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.151.157.242:57824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcoaching.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OFwAAAQI"]
[Thu Sep 17 15:18:23.757701 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.151.157.242:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OGQAAAIU"]
[Thu Sep 17 15:18:23.813531 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.246.241.88:37364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.teall.net"] [uri "/"] [unique_id "aqxZHwpXMN3p_zkwXf2OJwAAAIc"]
[Thu Sep 17 15:18:23.864379 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxZHwpXMN3p_zkwXf2OKAAAAKw"]
[Thu Sep 17 15:18:24.097015 2026] [security2:error] [pid 1012520:tid 1012704] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxZIApXMN3p_zkwXf2ONAAAALo"]
[Thu Sep 17 15:18:24.328961 2026] [security2:error] [pid 1012520:tid 1012681] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxZIApXMN3p_zkwXf2OQAAAAKM"]
[Thu Sep 17 15:18:24.357096 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIApXMN3p_zkwXf2ONQAAALQ"]
[Thu Sep 17 15:18:24.364525 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.151.157.242:57860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZIApXMN3p_zkwXf2OQQAAAKs"]
[Thu Sep 17 15:18:24.503454 2026] [security2:error] [pid 1012520:tid 1012696] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env"] [unique_id "aqxZIApXMN3p_zkwXf2ORAAAALI"]
[Thu Sep 17 15:18:24.525946 2026] [security2:error] [pid 1012520:tid 1012702] [client 172.239.147.162:59307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxZIApXMN3p_zkwXf2ORQAAALg"], referer: binance.com
[Thu Sep 17 15:18:24.561417 2026] [security2:error] [pid 1012520:tid 1012707] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxZIApXMN3p_zkwXf2ORgAAAL0"]
[Thu Sep 17 15:18:24.794629 2026] [security2:error] [pid 1012520:tid 1012680] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxZIApXMN3p_zkwXf2OWwAAAKI"]
[Thu Sep 17 15:18:24.806243 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIApXMN3p_zkwXf2OTwAAAIw"]
[Thu Sep 17 15:18:24.841766 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.151.157.242:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZIApXMN3p_zkwXf2OXwAAANY"]
[Thu Sep 17 15:18:25.028427 2026] [security2:error] [pid 1012520:tid 1012766] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OaAAAAPg"]
[Thu Sep 17 15:18:25.113157 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIApXMN3p_zkwXf2OZwAAAPA"]
[Thu Sep 17 15:18:25.254147 2026] [fcgid:warn] [pid 1012520:tid 1012745] (70014)End of file found: [client 45.43.62.37:48526] mod_fcgid: can't get data from http client
[Thu Sep 17 15:18:25.261360 2026] [security2:error] [pid 1012520:tid 1012666] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2ObwAAAJQ"]
[Thu Sep 17 15:18:25.338136 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.151.157.242:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.157.151.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agingwellcounseling.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OcwAAAQE"]
[Thu Sep 17 15:18:25.377641 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OcAAAAQQ"]
[Thu Sep 17 15:18:25.490773 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OdQAAAKw"]
[Thu Sep 17 15:18:25.645852 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OdgAAAJI"]
[Thu Sep 17 15:18:25.726567 2026] [security2:error] [pid 1012520:tid 1012697] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OiAAAALM"]
[Thu Sep 17 15:18:25.806975 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.bak"] [unique_id "aqxZIQpXMN3p_zkwXf2OiwAAALY"]
[Thu Sep 17 15:18:25.833997 2026] [security2:error] [pid 1012520:tid 1012631] [remote 110.249.202.161:55560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/outlines"] [unique_id "aqxZIQpXMN3p_zkwXf2OjQAAqW0"]
[Thu Sep 17 15:18:25.915607 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OiQAAALw"]
[Thu Sep 17 15:18:25.934923 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OigAAAJ8"]
[Thu Sep 17 15:18:25.961970 2026] [security2:error] [pid 1012520:tid 1012671] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxZIQpXMN3p_zkwXf2OkAAAAJk"]
[Thu Sep 17 15:18:25.961989 2026] [security2:error] [pid 1012520:tid 1012668] [client 172.239.147.162:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxZIQpXMN3p_zkwXf2OkQAAAJY"], referer: binance.com
[Thu Sep 17 15:18:26.006683 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.backup"] [unique_id "aqxZIgpXMN3p_zkwXf2OkgAAALE"]
[Thu Sep 17 15:18:26.180684 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OkwAAALA"]
[Thu Sep 17 15:18:26.196353 2026] [security2:error] [pid 1012520:tid 1012702] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OlwAAALg"]
[Thu Sep 17 15:18:26.356367 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OmwAAAMw"]
[Thu Sep 17 15:18:26.436551 2026] [security2:error] [pid 1012520:tid 1012744] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OnQAAAOI"]
[Thu Sep 17 15:18:26.442494 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OnAAAAMQ"]
[Thu Sep 17 15:18:26.480444 2026] [security2:error] [pid 1012520:tid 1012652] [client 104.28.198.244:22649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OngAAAIY"]
[Thu Sep 17 15:18:26.480621 2026] [security2:error] [pid 1012520:tid 1012652] [client 104.28.198.244:22649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OngAAAIY"]
[Thu Sep 17 15:18:26.512090 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.old"] [unique_id "aqxZIgpXMN3p_zkwXf2OoAAAANU"]
[Thu Sep 17 15:18:26.584385 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.169.98.18:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OoQAAAME"]
[Thu Sep 17 15:18:26.584494 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.169.98.18:62916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OoQAAAME"]
[Thu Sep 17 15:18:26.602353 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OnwAAALs"]
[Thu Sep 17 15:18:26.664897 2026] [security2:error] [pid 1012520:tid 1012736] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OpwAAANo"]
[Thu Sep 17 15:18:26.699539 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OogAAANc"]
[Thu Sep 17 15:18:26.865769 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OqQAAAPY"]
[Thu Sep 17 15:18:26.898097 2026] [security2:error] [pid 1012520:tid 1012740] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxZIgpXMN3p_zkwXf2OrgAAAN4"]
[Thu Sep 17 15:18:26.972238 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OrQAAAMc"]
[Thu Sep 17 15:18:27.130900 2026] [security2:error] [pid 1012520:tid 1012766] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OtwAAAPg"]
[Thu Sep 17 15:18:27.131122 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OtAAAAM4"]
[Thu Sep 17 15:18:27.163193 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.192.52.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZIgpXMN3p_zkwXf2OswAAAO8"]
[Thu Sep 17 15:18:27.261122 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OugAAAJc"]
[Thu Sep 17 15:18:27.356299 2026] [security2:error] [pid 1012520:tid 1012745] [client 172.239.147.162:50021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OwgAAAOM"], referer: binance.com
[Thu Sep 17 15:18:27.370921 2026] [security2:error] [pid 1012520:tid 1012777] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OwwAAAQM"]
[Thu Sep 17 15:18:27.404045 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OvwAAAJo"]
[Thu Sep 17 15:18:27.527192 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OxAAAAOA"]
[Thu Sep 17 15:18:27.607075 2026] [security2:error] [pid 1012520:tid 1012737] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OyAAAANs"]
[Thu Sep 17 15:18:27.691048 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OxwAAANQ"]
[Thu Sep 17 15:18:27.825003 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OygAAAJ4"]
[Thu Sep 17 15:18:27.841980 2026] [security2:error] [pid 1012520:tid 1012651] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxZIwpXMN3p_zkwXf2OzgAAAIU"]
[Thu Sep 17 15:18:27.851898 2026] [security2:error] [pid 1012520:tid 1012683] [client 185.219.41.85:56794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZHwpXMN3p_zkwXf2OKQAAAKU"]
[Thu Sep 17 15:18:27.897847 2026] [security2:error] [pid 1012520:tid 1012727] [client 185.55.149.49:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZIwpXMN3p_zkwXf2O0gAAANE"]
[Thu Sep 17 15:18:27.897969 2026] [security2:error] [pid 1012520:tid 1012727] [client 185.55.149.49:63648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZIwpXMN3p_zkwXf2O0gAAANE"]
[Thu Sep 17 15:18:27.964051 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2OzwAAAN8"]
[Thu Sep 17 15:18:28.074182 2026] [security2:error] [pid 1012520:tid 1012762] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O2QAAAPQ"]
[Thu Sep 17 15:18:28.101300 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.151.157.242:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcoaching.com"] [uri "/index.php"] [unique_id "aqxZIwpXMN3p_zkwXf2O1gAAANA"]
[Thu Sep 17 15:18:28.231063 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2O2gAAALM"]
[Thu Sep 17 15:18:28.307557 2026] [security2:error] [pid 1012520:tid 1012708] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O3AAAAL4"]
[Thu Sep 17 15:18:28.520904 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2O3gAAAIg"]
[Thu Sep 17 15:18:28.550422 2026] [security2:error] [pid 1012520:tid 1012702] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O6AAAALg"]
[Thu Sep 17 15:18:28.593235 2026] [security2:error] [pid 1012520:tid 1012700] [client 154.190.208.131:42601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJApXMN3p_zkwXf2O6QAAALY"]
[Thu Sep 17 15:18:28.593405 2026] [security2:error] [pid 1012520:tid 1012700] [client 154.190.208.131:42601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJApXMN3p_zkwXf2O6QAAALY"]
[Thu Sep 17 15:18:28.784175 2026] [security2:error] [pid 1012520:tid 1012652] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxZJApXMN3p_zkwXf2O8AAAAIY"]
[Thu Sep 17 15:18:28.795842 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2O7wAAANw"]
[Thu Sep 17 15:18:28.805943 2026] [security2:error] [pid 1012520:tid 1012751] [client 172.239.147.162:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxZJApXMN3p_zkwXf2O8wAAAOk"], referer: binance.com
[Thu Sep 17 15:18:29.022291 2026] [security2:error] [pid 1012520:tid 1012717] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PIgAAAMc"]
[Thu Sep 17 15:18:29.053728 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJApXMN3p_zkwXf2PFgAAAPY"]
[Thu Sep 17 15:18:29.257235 2026] [security2:error] [pid 1012520:tid 1012666] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PKQAAAJQ"]
[Thu Sep 17 15:18:29.309542 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PJwAAAI4"]
[Thu Sep 17 15:18:29.488731 2026] [security2:error] [pid 1012520:tid 1012670] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PMwAAAJg"]
[Thu Sep 17 15:18:29.552367 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env.swp"] [unique_id "aqxZJQpXMN3p_zkwXf2PNAAAAMs"]
[Thu Sep 17 15:18:29.560064 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.151.157.242:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PMgAAAMY"]
[Thu Sep 17 15:18:29.719578 2026] [security2:error] [pid 1012520:tid 1012762] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PPAAAAPQ"]
[Thu Sep 17 15:18:29.765801 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.env~"] [unique_id "aqxZJQpXMN3p_zkwXf2PPQAAAKQ"]
[Thu Sep 17 15:18:29.866317 2026] [security2:error] [pid 1012520:tid 1012651] [client 114.198.138.124:58347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PPwAAAIU"]
[Thu Sep 17 15:18:29.866482 2026] [security2:error] [pid 1012520:tid 1012651] [client 114.198.138.124:58347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PPwAAAIU"]
[Thu Sep 17 15:18:29.952633 2026] [security2:error] [pid 1012520:tid 1012689] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxZJQpXMN3p_zkwXf2PQwAAAKs"]
[Thu Sep 17 15:18:29.971867 2026] [security2:error] [pid 1012520:tid 1012677] [client 5.189.145.112:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxZJQpXMN3p_zkwXf2PRQAAAJ8"], referer: binance.com
[Thu Sep 17 15:18:30.185574 2026] [security2:error] [pid 1012520:tid 1012735] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxZJgpXMN3p_zkwXf2PTAAAANk"]
[Thu Sep 17 15:18:30.419296 2026] [security2:error] [pid 1012520:tid 1012729] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxZJgpXMN3p_zkwXf2PWAAAANM"]
[Thu Sep 17 15:18:30.655594 2026] [security2:error] [pid 1012520:tid 1012740] [client 8.228.208.101:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxZJgpXMN3p_zkwXf2PYgAAAN4"]
[Thu Sep 17 15:18:30.786895 2026] [security2:error] [pid 1012520:tid 1012760] [client 69.165.67.149:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.67.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "danielstepniak.com"] [uri "/index.php"] [unique_id "aqxZJgpXMN3p_zkwXf2PZwAAAPI"], referer: https://danielstepniak.com
[Thu Sep 17 15:18:30.923655 2026] [security2:error] [pid 1012520:tid 1012658] [client 8.228.208.101:43644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxZJgpXMN3p_zkwXf2PbAAAAIw"]
[Thu Sep 17 15:18:30.986168 2026] [security2:error] [pid 1012520:tid 1012666] [client 185.219.41.85:33480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.219.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZJgpXMN3p_zkwXf2PcgAAAJQ"]
[Thu Sep 17 15:18:31.197311 2026] [security2:error] [pid 1012520:tid 1012701] [client 37.139.53.7:53756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "authorsandrasmith.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PgwAAALc"], referer: https://authorsandrasmith.com/?page_id=5
[Thu Sep 17 15:18:31.197411 2026] [security2:error] [pid 1012520:tid 1012701] [client 37.139.53.7:53756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "authorsandrasmith.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PgwAAALc"], referer: https://authorsandrasmith.com/?page_id=5
[Thu Sep 17 15:18:31.405539 2026] [security2:error] [pid 1012520:tid 1012765] [client 31.215.13.14:60304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PiQAA91w"]
[Thu Sep 17 15:18:31.595008 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/app/.env"] [unique_id "aqxZJwpXMN3p_zkwXf2PjwAAAPQ"]
[Thu Sep 17 15:18:31.718155 2026] [security2:error] [pid 1012520:tid 1012741] [client 8.228.208.101:43840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/info.php"] [unique_id "aqxZJwpXMN3p_zkwXf2PkAAAAN8"]
[Thu Sep 17 15:18:31.844453 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/apps/.env"] [unique_id "aqxZJwpXMN3p_zkwXf2PkQAAAPs"]
[Thu Sep 17 15:18:32.045062 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PmAAAAJ8"]
[Thu Sep 17 15:18:32.282222 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/web/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PoAAAAL8"]
[Thu Sep 17 15:18:32.349173 2026] [security2:error] [pid 1012520:tid 1012753] [client 185.219.41.85:56822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZKApXMN3p_zkwXf2PlwAAAOs"]
[Thu Sep 17 15:18:32.425473 2026] [security2:error] [pid 1012520:tid 1012715] [client 8.228.208.101:43856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/php.php"] [unique_id "aqxZKApXMN3p_zkwXf2PqQAAAMU"]
[Thu Sep 17 15:18:32.464697 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/site/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PqgAAAMw"]
[Thu Sep 17 15:18:32.624951 2026] [security2:error] [pid 1012520:tid 1012671] [client 156.192.234.52:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKApXMN3p_zkwXf2PsQAAAJk"]
[Thu Sep 17 15:18:32.625510 2026] [security2:error] [pid 1012520:tid 1012671] [client 156.192.234.52:55082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKApXMN3p_zkwXf2PsQAAAJk"]
[Thu Sep 17 15:18:32.640935 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/public/.env"] [unique_id "aqxZKApXMN3p_zkwXf2PsgAAALw"]
[Thu Sep 17 15:18:33.000089 2026] [core:error] [pid 1012520:tid 1012699] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:33.000117 2026] [core:error] [pid 1012520:tid 1012699] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:33.122680 2026] [security2:error] [pid 1012520:tid 1012717] [client 8.228.208.101:43866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/i.php"] [unique_id "aqxZKQpXMN3p_zkwXf2PuwAAAMc"]
[Thu Sep 17 15:18:33.176153 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/backend/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2PvAAAAPA"]
[Thu Sep 17 15:18:33.219557 2026] [security2:error] [pid 1012520:tid 1012636] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.bak"] [unique_id "aqxZKQpXMN3p_zkwXf2PwgAA73I"]
[Thu Sep 17 15:18:33.219582 2026] [security2:error] [pid 1012520:tid 1012635] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.backup"] [unique_id "aqxZKQpXMN3p_zkwXf2PvwAA73E"]
[Thu Sep 17 15:18:33.220511 2026] [security2:error] [pid 1012520:tid 1012636] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.old"] [unique_id "aqxZKQpXMN3p_zkwXf2PwwAA73I"]
[Thu Sep 17 15:18:33.462645 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/server/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P5wAAAPc"]
[Thu Sep 17 15:18:33.537573 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4AAAAPE"]
[Thu Sep 17 15:18:33.537573 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3QAAAIs"]
[Thu Sep 17 15:18:33.537578 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3wAAAKo"]
[Thu Sep 17 15:18:33.537588 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3gAAAOA"]
[Thu Sep 17 15:18:33.537617 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4gAAAOM"]
[Thu Sep 17 15:18:33.537702 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P5AAAAJE"]
[Thu Sep 17 15:18:33.537987 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4QAAALc"]
[Thu Sep 17 15:18:33.538357 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P2gAAANg"]
[Thu Sep 17 15:18:33.538500 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P4wAAAMs"]
[Thu Sep 17 15:18:33.540201 2026] [security2:error] [pid 1012520:tid 1012522] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/.env.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P6wAA7wA"]
[Thu Sep 17 15:18:33.540967 2026] [security2:error] [pid 1012520:tid 1012636] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P7AAA73I"]
[Thu Sep 17 15:18:33.557542 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P2wAAAJg"]
[Thu Sep 17 15:18:33.558144 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P2QAAAJs"]
[Thu Sep 17 15:18:33.573422 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P3AAAAPo"]
[Thu Sep 17 15:18:33.628922 2026] [authz_core:error] [pid 1012520:tid 1012761] [client 172.239.147.162:49455] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:33.689491 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/frontend/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P9gAAAIg"]
[Thu Sep 17 15:18:33.785341 2026] [security2:error] [pid 1012520:tid 1012683] [client 186.105.232.15:58172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-AAAAKU"]
[Thu Sep 17 15:18:33.785431 2026] [security2:error] [pid 1012520:tid 1012683] [client 186.105.232.15:58172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-AAAAKU"]
[Thu Sep 17 15:18:33.806912 2026] [security2:error] [pid 1012520:tid 1012687] [client 8.228.208.101:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-gAAAKk"]
[Thu Sep 17 15:18:33.928524 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/src/.env"] [unique_id "aqxZKQpXMN3p_zkwXf2P_AAAANo"]
[Thu Sep 17 15:18:33.948918 2026] [security2:error] [pid 1012520:tid 1012524] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env~"] [unique_id "aqxZKQpXMN3p_zkwXf2P_gAA7wI"]
[Thu Sep 17 15:18:33.948927 2026] [security2:error] [pid 1012520:tid 1012528] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.env.swp"] [unique_id "aqxZKQpXMN3p_zkwXf2P_wAA7wY"]
[Thu Sep 17 15:18:34.002360 2026] [security2:error] [pid 1012520:tid 1012695] [client 37.0.160.87:44632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P-wAAsQU"]
[Thu Sep 17 15:18:34.104765 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/core/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QFAAAANI"]
[Thu Sep 17 15:18:34.325449 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.61.219.136:32009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QFwAAAPk"]
[Thu Sep 17 15:18:34.325715 2026] [security2:error] [pid 1012520:tid 1012767] [client 185.61.219.136:32009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QFwAAAPk"]
[Thu Sep 17 15:18:34.328635 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/core/app/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QGAAAAOY"]
[Thu Sep 17 15:18:34.393274 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QDQAAALA"]
[Thu Sep 17 15:18:34.393833 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QEQAAAKg"]
[Thu Sep 17 15:18:34.393919 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P9AAAAMI"]
[Thu Sep 17 15:18:34.394030 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QDwAAAJ0"]
[Thu Sep 17 15:18:34.394055 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QDgAAAMo"]
[Thu Sep 17 15:18:34.395379 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QEgAAAN4"]
[Thu Sep 17 15:18:34.397833 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2QEAAAAKI"]
[Thu Sep 17 15:18:34.400710 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKQpXMN3p_zkwXf2P9QAAAOI"]
[Thu Sep 17 15:18:34.493476 2026] [security2:error] [pid 1012520:tid 1012773] [client 8.228.208.101:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QGwAAAP8"]
[Thu Sep 17 15:18:34.497494 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/config/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QHAAAAKw"]
[Thu Sep 17 15:18:34.645309 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/private/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QHgAAAK4"]
[Thu Sep 17 15:18:34.744780 2026] [security2:error] [pid 1012520:tid 1012755] [client 114.119.151.83:39925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ccrmediator.com"] [uri "/continuum"] [unique_id "aqxZKgpXMN3p_zkwXf2QIAAAAO0"], referer: https://ccrmediator.com/blog/
[Thu Sep 17 15:18:34.813761 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/application/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QIQAAAJg"]
[Thu Sep 17 15:18:34.838059 2026] [security2:error] [pid 1012520:tid 1012541] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/backend/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QJgAAmxM"]
[Thu Sep 17 15:18:34.838072 2026] [security2:error] [pid 1012520:tid 1012538] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/app/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QIwAAmxA"]
[Thu Sep 17 15:18:34.838099 2026] [security2:error] [pid 1012520:tid 1012543] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/server/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKAAAmxU"]
[Thu Sep 17 15:18:34.838189 2026] [security2:error] [pid 1012520:tid 1012537] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/api/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QIgAAmw8"]
[Thu Sep 17 15:18:34.838217 2026] [security2:error] [pid 1012520:tid 1012542] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/config/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKQAAmxQ"]
[Thu Sep 17 15:18:34.838263 2026] [security2:error] [pid 1012520:tid 1012544] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/src/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKgAAmxY"]
[Thu Sep 17 15:18:34.838287 2026] [security2:error] [pid 1012520:tid 1012547] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/web/.env"] [unique_id "aqxZKgpXMN3p_zkwXf2QKwAAmxk"]
[Thu Sep 17 15:18:34.851225 2026] [autoindex:error] [pid 1012520:tid 1012741] [client 51.4.104.8:55555] AH01276: Cannot serve directory /home1/kurtshul/public_html/website_122f4dbc/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:18:35.031144 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QMAAAAOg"]
[Thu Sep 17 15:18:35.033809 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QMQAAALY"]
[Thu Sep 17 15:18:35.041223 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/bootstrap/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QNgAAAPM"]
[Thu Sep 17 15:18:35.068378 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZKgpXMN3p_zkwXf2QMgAAAL8"]
[Thu Sep 17 15:18:35.142297 2026] [security2:error] [pid 1012520:tid 1012561] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/prod/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRwAAxCc"]
[Thu Sep 17 15:18:35.142359 2026] [security2:error] [pid 1012520:tid 1012556] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/dev/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRgAAxCI"]
[Thu Sep 17 15:18:35.142358 2026] [security2:error] [pid 1012520:tid 1012558] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/back/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQwAAxCQ"]
[Thu Sep 17 15:18:35.142422 2026] [security2:error] [pid 1012520:tid 1012551] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/laravel/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQAAAxB0"]
[Thu Sep 17 15:18:35.142422 2026] [security2:error] [pid 1012520:tid 1012562] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/apps/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQgAAxCg"]
[Thu Sep 17 15:18:35.142451 2026] [security2:error] [pid 1012520:tid 1012553] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/frontend/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPAAAxB8"]
[Thu Sep 17 15:18:35.142502 2026] [security2:error] [pid 1012520:tid 1012545] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/backup/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRAAAxBc"]
[Thu Sep 17 15:18:35.142502 2026] [security2:error] [pid 1012520:tid 1012549] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/var/www/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QOwAAxBs"]
[Thu Sep 17 15:18:35.142508 2026] [security2:error] [pid 1012520:tid 1012550] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/public/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPgAAxBw"]
[Thu Sep 17 15:18:35.142534 2026] [security2:error] [pid 1012520:tid 1012554] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/application/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QQQAAxCA"]
[Thu Sep 17 15:18:35.142538 2026] [security2:error] [pid 1012520:tid 1012555] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/var/www/html/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPQAAxCE"]
[Thu Sep 17 15:18:35.142570 2026] [security2:error] [pid 1012520:tid 1012546] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/client/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QPwAAxBg"]
[Thu Sep 17 15:18:35.142595 2026] [security2:error] [pid 1012520:tid 1012557] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/cms/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QRQAAxCM"]
[Thu Sep 17 15:18:35.187978 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.228.208.101:43882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/test.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QSAAAALQ"]
[Thu Sep 17 15:18:35.221606 2026] [security2:error] [pid 1012520:tid 1012777] [client 185.61.219.136:35457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QSQAAAQM"], referer: https://www.google.com
[Thu Sep 17 15:18:35.256647 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/database/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QSwAAANQ"]
[Thu Sep 17 15:18:35.425097 2026] [security2:error] [pid 1012520:tid 1012706] [client 190.114.37.77:13648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QTAAAvCU"]
[Thu Sep 17 15:18:35.446962 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/storage/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QTwAAALE"]
[Thu Sep 17 15:18:35.455567 2026] [core:error] [pid 1012520:tid 1012656] [client 51.4.104.8:56594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:35.455588 2026] [core:error] [pid 1012520:tid 1012656] [client 51.4.104.8:56594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:35.676797 2026] [security2:error] [pid 1012520:tid 1012574] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/aws/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYwAAsjQ"]
[Thu Sep 17 15:18:35.676793 2026] [security2:error] [pid 1012520:tid 1012570] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.docker/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYQAAsjA"]
[Thu Sep 17 15:18:35.676796 2026] [security2:error] [pid 1012520:tid 1012639] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/old/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVAAAsnU"]
[Thu Sep 17 15:18:35.676841 2026] [security2:error] [pid 1012520:tid 1012573] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/server/backend/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYAAAsjM"]
[Thu Sep 17 15:18:35.676851 2026] [security2:error] [pid 1012520:tid 1012568] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/api-backend/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWgAAsi4"]
[Thu Sep 17 15:18:35.676897 2026] [security2:error] [pid 1012520:tid 1012579] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/server/api/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXwAAsjk"]
[Thu Sep 17 15:18:35.676897 2026] [security2:error] [pid 1012520:tid 1012576] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QYgAAsjY"]
[Thu Sep 17 15:18:35.676936 2026] [security2:error] [pid 1012520:tid 1012564] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/production/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVgAAsio"]
[Thu Sep 17 15:18:35.676936 2026] [security2:error] [pid 1012520:tid 1012572] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/test/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVwAAsjI"]
[Thu Sep 17 15:18:35.676945 2026] [security2:error] [pid 1012520:tid 1012571] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/admin-app/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWwAAsjE"]
[Thu Sep 17 15:18:35.676982 2026] [security2:error] [pid 1012520:tid 1012540] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/new/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWAAAshI"]
[Thu Sep 17 15:18:35.677012 2026] [security2:error] [pid 1012520:tid 1012575] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/current/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXgAAsjU"]
[Thu Sep 17 15:18:35.677063 2026] [security2:error] [pid 1012520:tid 1012552] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/staging/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QVQAAsh4"]
[Thu Sep 17 15:18:35.677089 2026] [security2:error] [pid 1012520:tid 1012580] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/public_html/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXQAAsjo"]
[Thu Sep 17 15:18:35.677106 2026] [security2:error] [pid 1012520:tid 1012567] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/node-api/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QWQAAsi0"]
[Thu Sep 17 15:18:35.689241 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/var/www/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QZAAAAOU"]
[Thu Sep 17 15:18:35.704676 2026] [security2:error] [pid 1012520:tid 1012569] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/administrator/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QXAAAsi8"]
[Thu Sep 17 15:18:35.873801 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/var/www/html/.env"] [unique_id "aqxZKwpXMN3p_zkwXf2QaQAAAJ0"]
[Thu Sep 17 15:18:35.895292 2026] [authz_core:error] [pid 1012520:tid 1012659] [client 172.239.147.162:56518] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:35.940196 2026] [security2:error] [pid 1012520:tid 1012697] [client 104.28.198.244:22537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QcAAAALM"]
[Thu Sep 17 15:18:35.940327 2026] [security2:error] [pid 1012520:tid 1012697] [client 104.28.198.244:22537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZKwpXMN3p_zkwXf2QcAAAALM"]
[Thu Sep 17 15:18:36.097368 2026] [security2:error] [pid 1012520:tid 1012694] [client 185.61.219.136:21717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZLApXMN3p_zkwXf2QcwAAALA"], referer: https://www.google.com
[Thu Sep 17 15:18:36.104340 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/current/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QdAAAAMY"]
[Thu Sep 17 15:18:36.109139 2026] [security2:error] [pid 1012520:tid 1012712] [client 51.4.104.8:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.104.4.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.kurtshuler.com"] [uri "/wp-login.php"] [unique_id "aqxZLApXMN3p_zkwXf2QcgAAAMI"]
[Thu Sep 17 15:18:36.196307 2026] [security2:error] [pid 1012520:tid 1012581] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/v1/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QegAA8Ts"]
[Thu Sep 17 15:18:36.196387 2026] [security2:error] [pid 1012520:tid 1012582] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/v3/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QewAA8Tw"]
[Thu Sep 17 15:18:36.196447 2026] [security2:error] [pid 1012520:tid 1012577] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.aws/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QdQAA8Tc"]
[Thu Sep 17 15:18:36.196473 2026] [security2:error] [pid 1012520:tid 1012566] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/stripe/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QeAAA8Sw"]
[Thu Sep 17 15:18:36.196593 2026] [security2:error] [pid 1012520:tid 1012586] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/media/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QfAAA8UA"]
[Thu Sep 17 15:18:36.196623 2026] [security2:error] [pid 1012520:tid 1012584] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/v2/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QdwAA8T4"]
[Thu Sep 17 15:18:36.302810 2026] [security2:error] [pid 1012520:tid 1012692] [client 8.228.208.101:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/p.php"] [unique_id "aqxZLApXMN3p_zkwXf2QmQAAAK4"]
[Thu Sep 17 15:18:36.328950 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/release/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QmwAAAM4"]
[Thu Sep 17 15:18:36.410111 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkAAAAKQ"]
[Thu Sep 17 15:18:36.413469 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QjwAAANE"]
[Thu Sep 17 15:18:36.414969 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkQAAAPQ"]
[Thu Sep 17 15:18:36.420744 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkgAAANs"]
[Thu Sep 17 15:18:36.420914 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlAAAAP4"]
[Thu Sep 17 15:18:36.421521 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlQAAAO8"]
[Thu Sep 17 15:18:36.426458 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QkwAAAIk"]
[Thu Sep 17 15:18:36.428075 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlgAAAM0"]
[Thu Sep 17 15:18:36.455577 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QlwAAAKw"]
[Thu Sep 17 15:18:36.455861 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QmAAAAQQ"]
[Thu Sep 17 15:18:36.508390 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/releases/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QogAAAIU"]
[Thu Sep 17 15:18:36.529407 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QngAAAJ8"]
[Thu Sep 17 15:18:36.691187 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/shared/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QpgAAAPU"]
[Thu Sep 17 15:18:36.716124 2026] [core:error] [pid 1012520:tid 1012707] [client 51.4.104.8:59011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:36.716140 2026] [core:error] [pid 1012520:tid 1012707] [client 51.4.104.8:59011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:36.899756 2026] [security2:error] [pid 1012520:tid 1012605] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.git/config.bak"] [unique_id "aqxZLApXMN3p_zkwXf2QsgAA1FM"]
[Thu Sep 17 15:18:36.951244 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/deploy/.env"] [unique_id "aqxZLApXMN3p_zkwXf2QvAAAANM"]
[Thu Sep 17 15:18:36.966282 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QqwAAAL4"]
[Thu Sep 17 15:18:36.992313 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.228.208.101:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxZLApXMN3p_zkwXf2QvwAAALQ"]
[Thu Sep 17 15:18:37.055615 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QuQAAAOU"]
[Thu Sep 17 15:18:37.057615 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QuwAAAJU"]
[Thu Sep 17 15:18:37.062707 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QugAAAPg"]
[Thu Sep 17 15:18:37.064715 2026] [security2:error] [pid 1012520:tid 1012699] [client 45.169.98.18:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QwwAAALU"]
[Thu Sep 17 15:18:37.066585 2026] [security2:error] [pid 1012520:tid 1012699] [client 45.169.98.18:63499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QwwAAALU"]
[Thu Sep 17 15:18:37.067312 2026] [security2:error] [pid 1012520:tid 1012658] [client 74.7.230.10:43932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "blu.uua.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxZLQpXMN3p_zkwXf2QwgAAjFU"]
[Thu Sep 17 15:18:37.149111 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/build/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2QxgAAAPc"]
[Thu Sep 17 15:18:37.295454 2026] [authz_core:error] [pid 1012520:tid 1012774] [client 172.239.147.162:60344] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:18:37.297475 2026] [security2:error] [pid 1012520:tid 1012720] [client 51.4.104.8:59895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.104.4.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.kurtshuler.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q0AAAAMo"]
[Thu Sep 17 15:18:37.308111 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/dist/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q0QAAAPQ"]
[Thu Sep 17 15:18:37.337425 2026] [security2:error] [pid 1012520:tid 1012760] [client 186.33.67.131:54512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QyQAA8lk"]
[Thu Sep 17 15:18:37.378279 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2QywAAAK8"]
[Thu Sep 17 15:18:37.407569 2026] [security2:error] [pid 1012520:tid 1012732] [client 5.189.145.112:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q1gAAANY"], referer: binance.com
[Thu Sep 17 15:18:37.502946 2026] [security2:error] [pid 1012520:tid 1012654] [client 185.61.219.136:11275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxZLApXMN3p_zkwXf2QvgAAAIg"], referer: https://www.google.com
[Thu Sep 17 15:18:37.542891 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/public_html/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q2wAAAQE"]
[Thu Sep 17 15:18:37.547554 2026] [security2:error] [pid 1012520:tid 1012688] [client 74.7.230.1:36776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.qwr.qfv.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxZLQpXMN3p_zkwXf2Q3AAAAKo"]
[Thu Sep 17 15:18:37.591798 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q2AAAAJg"]
[Thu Sep 17 15:18:37.698598 2026] [security2:error] [pid 1012520:tid 1012741] [client 8.228.208.101:43920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q4wAAAN8"]
[Thu Sep 17 15:18:37.710327 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/htdocs/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q5AAAAJs"]
[Thu Sep 17 15:18:37.752390 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q4gAAAJQ"]
[Thu Sep 17 15:18:37.753227 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLQpXMN3p_zkwXf2Q4QAAAMs"]
[Thu Sep 17 15:18:37.907874 2026] [core:error] [pid 1012520:tid 1012725] [client 51.4.104.8:60667] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:37.907893 2026] [core:error] [pid 1012520:tid 1012725] [client 51.4.104.8:60667] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:37.940914 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/www/.env"] [unique_id "aqxZLQpXMN3p_zkwXf2Q6AAAANw"]
[Thu Sep 17 15:18:38.186939 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/html/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2Q-QAAAJ4"]
[Thu Sep 17 15:18:38.238608 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q9gAAANI"]
[Thu Sep 17 15:18:38.240693 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q9QAAAMA"]
[Thu Sep 17 15:18:38.259485 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q9wAAANM"]
[Thu Sep 17 15:18:38.386029 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.228.208.101:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxZLgpXMN3p_zkwXf2Q-gAAAJ0"]
[Thu Sep 17 15:18:38.397463 2026] [security2:error] [pid 1012520:tid 1012620] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxZLgpXMN3p_zkwXf2Q_AAAoGI"]
[Thu Sep 17 15:18:38.397504 2026] [security2:error] [pid 1012520:tid 1012631] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/id_rsa"] [unique_id "aqxZLgpXMN3p_zkwXf2RAAAAoG0"]
[Thu Sep 17 15:18:38.397521 2026] [security2:error] [pid 1012520:tid 1012617] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxZLgpXMN3p_zkwXf2Q_gAAoF8"]
[Thu Sep 17 15:18:38.399593 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/live/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RBQAAALw"]
[Thu Sep 17 15:18:38.551524 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RDwAAAMk"]
[Thu Sep 17 15:18:38.552248 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RDgAAALg"]
[Thu Sep 17 15:18:38.552249 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2REAAAAN4"]
[Thu Sep 17 15:18:38.574376 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RDQAAAKk"]
[Thu Sep 17 15:18:38.587082 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RFgAAAMY"]
[Thu Sep 17 15:18:38.604472 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/prod/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RGwAAAKU"]
[Thu Sep 17 15:18:38.662597 2026] [security2:error] [pid 1012520:tid 1012694] [client 185.55.149.49:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLAAAALA"]
[Thu Sep 17 15:18:38.662736 2026] [security2:error] [pid 1012520:tid 1012694] [client 185.55.149.49:64319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLAAAALA"]
[Thu Sep 17 15:18:38.778432 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/dev/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RPgAAAME"]
[Thu Sep 17 15:18:38.793955 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RJwAAAI8"]
[Thu Sep 17 15:18:38.807156 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLQAAAIg"]
[Thu Sep 17 15:18:38.812190 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RLgAAALY"]
[Thu Sep 17 15:18:38.812235 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RKAAAANg"]
[Thu Sep 17 15:18:38.866021 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RNQAAAJg"]
[Thu Sep 17 15:18:38.890965 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2ROQAAAJo"]
[Thu Sep 17 15:18:38.948985 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/staging/.env"] [unique_id "aqxZLgpXMN3p_zkwXf2RUAAAAOw"]
[Thu Sep 17 15:18:38.957699 2026] [security2:error] [pid 1012520:tid 1012531] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RUQAA8gk"]
[Thu Sep 17 15:18:39.017070 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRAAAAMw"]
[Thu Sep 17 15:18:39.081320 2026] [security2:error] [pid 1012520:tid 1012735] [client 8.228.208.101:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZgAAANk"]
[Thu Sep 17 15:18:39.115131 2026] [security2:error] [pid 1012520:tid 1012657] [client 154.190.208.131:41863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZwAAAIs"]
[Thu Sep 17 15:18:39.115249 2026] [security2:error] [pid 1012520:tid 1012657] [client 154.190.208.131:41863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZwAAAIs"]
[Thu Sep 17 15:18:39.148374 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/opt/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RaQAAAJU"]
[Thu Sep 17 15:18:39.262955 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRgAAAMs"]
[Thu Sep 17 15:18:39.278629 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRQAAAIU"]
[Thu Sep 17 15:18:39.300090 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RTgAAAOE"]
[Thu Sep 17 15:18:39.301077 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RSAAAANQ"]
[Thu Sep 17 15:18:39.307397 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RRwAAAMg"]
[Thu Sep 17 15:18:39.313414 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/laravel/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RcwAAAM4"]
[Thu Sep 17 15:18:39.423042 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RVwAAAO4"]
[Thu Sep 17 15:18:39.423275 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RXwAAAPU"]
[Thu Sep 17 15:18:39.426204 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RcAAAAIo"]
[Thu Sep 17 15:18:39.427129 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RZQAAAQM"]
[Thu Sep 17 15:18:39.427377 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RcQAAAMI"]
[Thu Sep 17 15:18:39.435967 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RYgAAAMQ"]
[Thu Sep 17 15:18:39.457363 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RcgAAANU"]
[Thu Sep 17 15:18:39.512954 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/symfony/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2ReAAAAJw"]
[Thu Sep 17 15:18:39.549957 2026] [security2:error] [pid 1012520:tid 1012558] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/aws.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RfgAAiSQ"]
[Thu Sep 17 15:18:39.576609 2026] [security2:error] [pid 1012520:tid 1012545] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/mail.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RgwAAiRc"]
[Thu Sep 17 15:18:39.576614 2026] [security2:error] [pid 1012520:tid 1012549] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/config.inc.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RhQAAiRs"]
[Thu Sep 17 15:18:39.576633 2026] [security2:error] [pid 1012520:tid 1012562] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/stripe.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RggAAiSg"]
[Thu Sep 17 15:18:39.602431 2026] [security2:error] [pid 1012520:tid 1012554] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/config/nexmo.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RiAAAiSA"]
[Thu Sep 17 15:18:39.681088 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/wordpress/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RjwAAAOA"]
[Thu Sep 17 15:18:39.698785 2026] [security2:error] [pid 1012520:tid 1012557] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/wp-config.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RkgAAiSM"]
[Thu Sep 17 15:18:39.712878 2026] [security2:error] [pid 1012520:tid 1012559] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.bak"] [unique_id "aqxZLwpXMN3p_zkwXf2RlgAAiSU"]
[Thu Sep 17 15:18:39.712882 2026] [security2:error] [pid 1012520:tid 1012570] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.new"] [unique_id "aqxZLwpXMN3p_zkwXf2RmAAAiTA"]
[Thu Sep 17 15:18:39.712884 2026] [security2:error] [pid 1012520:tid 1012639] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.old"] [unique_id "aqxZLwpXMN3p_zkwXf2RlwAAiXU"]
[Thu Sep 17 15:18:39.713242 2026] [security2:error] [pid 1012520:tid 1012574] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxZLwpXMN3p_zkwXf2RmQAAiTQ"]
[Thu Sep 17 15:18:39.766295 2026] [security2:error] [pid 1012520:tid 1012663] [client 8.228.208.101:43948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RmwAAAJE"]
[Thu Sep 17 15:18:39.766786 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RigAAAJs"]
[Thu Sep 17 15:18:39.846471 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RlQAAAPM"]
[Thu Sep 17 15:18:39.849197 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RkQAAAMU"]
[Thu Sep 17 15:18:39.851611 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RkwAAAOw"]
[Thu Sep 17 15:18:39.857435 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RlAAAANw"]
[Thu Sep 17 15:18:39.871031 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RmgAAAMc"]
[Thu Sep 17 15:18:39.899929 2026] [security2:error] [pid 1012520:tid 1012579] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxZLwpXMN3p_zkwXf2RoAAAiTk"]
[Thu Sep 17 15:18:39.923198 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/wp/.env"] [unique_id "aqxZLwpXMN3p_zkwXf2RpQAAAIs"]
[Thu Sep 17 15:18:39.957987 2026] [authz_core:error] [pid 1012520:tid 1012710] [client 172.239.147.162:51268] AH01630: client denied by server configuration: /home3/cowboywi/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:18:40.081346 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cms/.env"] [unique_id "aqxZMApXMN3p_zkwXf2RsQAAAOY"]
[Thu Sep 17 15:18:40.235532 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/drupal/.env"] [unique_id "aqxZMApXMN3p_zkwXf2RuAAAAN4"]
[Thu Sep 17 15:18:40.247463 2026] [security2:error] [pid 1012520:tid 1012552] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxZMApXMN3p_zkwXf2RuQAAiR4"]
[Thu Sep 17 15:18:40.300343 2026] [security2:error] [pid 1012520:tid 1012568] [remote 34.156.22.151:55556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RogAAiS4"]
[Thu Sep 17 15:18:40.304653 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZLwpXMN3p_zkwXf2RpgAAAPs"]
[Thu Sep 17 15:18:40.383477 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RtQAAAMk"]
[Thu Sep 17 15:18:40.452315 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZMApXMN3p_zkwXf2R0AAAAKw"]
[Thu Sep 17 15:18:40.467569 2026] [security2:error] [pid 1012520:tid 1012756] [client 85.208.96.203:36112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thehivetribe.com"] [uri "/robots.txt"] [unique_id "aqxZMApXMN3p_zkwXf2R0QAAAO4"]
[Thu Sep 17 15:18:40.467706 2026] [security2:error] [pid 1012520:tid 1012756] [client 85.208.96.203:36112] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thehivetribe.com"] [uri "/robots.txt"] [unique_id "aqxZMApXMN3p_zkwXf2R0QAAAO4"]
[Thu Sep 17 15:18:40.505279 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:54786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMApXMN3p_zkwXf2R1AAAAOE"]
[Thu Sep 17 15:18:40.505384 2026] [security2:error] [pid 1012520:tid 1012743] [client 114.198.138.124:54786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMApXMN3p_zkwXf2R1AAAAOE"]
[Thu Sep 17 15:18:40.506946 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RvgAAAM4"]
[Thu Sep 17 15:18:40.527004 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RxwAAAOI"]
[Thu Sep 17 15:18:40.536247 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RzAAAANE"]
[Thu Sep 17 15:18:40.549732 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2RzQAAAMY"]
[Thu Sep 17 15:18:40.558405 2026] [security2:error] [pid 1012520:tid 1012704] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/joomla/.env"] [unique_id "aqxZMApXMN3p_zkwXf2R1gAAALo"]
[Thu Sep 17 15:18:40.663713 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R1QAAAMI"]
[Thu Sep 17 15:18:40.732035 2026] [security2:error] [pid 1012520:tid 1012711] [client 85.208.96.196:62232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thehivetribe.com"] [uri "/"] [unique_id "aqxZMApXMN3p_zkwXf2R3AAAAME"]
[Thu Sep 17 15:18:40.732174 2026] [security2:error] [pid 1012520:tid 1012711] [client 85.208.96.196:62232] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thehivetribe.com"] [uri "/"] [unique_id "aqxZMApXMN3p_zkwXf2R3AAAAME"]
[Thu Sep 17 15:18:40.791460 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R2wAAAO0"]
[Thu Sep 17 15:18:40.803507 2026] [security2:error] [pid 1012520:tid 1012733] [client 57.141.14.33:43684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxZLgpXMN3p_zkwXf2RGgAA13I"]
[Thu Sep 17 15:18:40.804394 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.246.241.88:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/magento/.env"] [unique_id "aqxZMApXMN3p_zkwXf2R5AAAALA"]
[Thu Sep 17 15:18:40.918561 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R4wAAALY"]
[Thu Sep 17 15:18:40.953503 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMApXMN3p_zkwXf2R5QAAAOA"]
[Thu Sep 17 15:18:40.963736 2026] [security2:error] [pid 1012520:tid 1012736] [client 134.185.85.61:55237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "groverpdx.net"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxZMApXMN3p_zkwXf2R6QAAANo"]
[Thu Sep 17 15:18:41.135801 2026] [security2:error] [pid 1012520:tid 1012673] [client 8.228.208.101:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R_gAAAJs"]
[Thu Sep 17 15:18:41.145021 2026] [authz_core:error] [pid 1012520:tid 1012764] [client 43.130.102.7:60732] AH01630: client denied by server configuration: /home4/glassbl4/public_html/fireflyhotglass/glass/wp-content/plugins/events-manager/multilingual/error_log
[Thu Sep 17 15:18:41.244547 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R_QAAAOU"]
[Thu Sep 17 15:18:41.244552 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R-gAAAM8"]
[Thu Sep 17 15:18:41.244555 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R_AAAAIs"]
[Thu Sep 17 15:18:41.249195 2026] [security2:error] [pid 1012520:tid 1012761] [client 185.61.219.136:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SBQAAAPM"]
[Thu Sep 17 15:18:41.249289 2026] [security2:error] [pid 1012520:tid 1012761] [client 185.61.219.136:62981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SBQAAAPM"]
[Thu Sep 17 15:18:41.249503 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R-AAAAJQ"]
[Thu Sep 17 15:18:41.262310 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2R-wAAAKI"]
[Thu Sep 17 15:18:41.347360 2026] [security2:error] [pid 1012520:tid 1012730] [client 134.185.85.61:50054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "groverpdx.net"] [uri "/media/system/js/core.js"] [unique_id "aqxZMQpXMN3p_zkwXf2SDgAAANQ"]
[Thu Sep 17 15:18:41.460675 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SDQAAANI"]
[Thu Sep 17 15:18:41.542634 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/shopify/.env"] [unique_id "aqxZMQpXMN3p_zkwXf2SLwAAAMs"]
[Thu Sep 17 15:18:41.624760 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SGwAAAKw"]
[Thu Sep 17 15:18:41.704908 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SLgAAAOM"]
[Thu Sep 17 15:18:41.720505 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMAAAAOc"]
[Thu Sep 17 15:18:41.726521 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNAAAALk"]
[Thu Sep 17 15:18:41.728054 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMwAAAQI"]
[Thu Sep 17 15:18:41.732824 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMgAAANA"]
[Thu Sep 17 15:18:41.732926 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNQAAANY"]
[Thu Sep 17 15:18:41.746494 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNwAAAPE"]
[Thu Sep 17 15:18:41.747211 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SMQAAAMo"]
[Thu Sep 17 15:18:41.759213 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SNgAAAPc"]
[Thu Sep 17 15:18:41.769263 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/prestashop/.env"] [unique_id "aqxZMQpXMN3p_zkwXf2SQAAAAOw"]
[Thu Sep 17 15:18:41.774200 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SOwAAAJk"]
[Thu Sep 17 15:18:41.915153 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/codeigniter/.env"] [unique_id "aqxZMQpXMN3p_zkwXf2STgAAAM8"]
[Thu Sep 17 15:18:41.957361 2026] [security2:error] [pid 1012520:tid 1012624] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/info.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SWAAA3GY"]
[Thu Sep 17 15:18:41.957369 2026] [security2:error] [pid 1012520:tid 1012623] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/phpinfo.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SVgAA3GU"]
[Thu Sep 17 15:18:41.965408 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SRAAAAPY"]
[Thu Sep 17 15:18:42.051063 2026] [security2:error] [pid 1012520:tid 1012626] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/infos.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYQAA3Gg"]
[Thu Sep 17 15:18:42.072004 2026] [security2:error] [pid 1012520:tid 1012642] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/php.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYwAA3Hg"]
[Thu Sep 17 15:18:42.071999 2026] [security2:error] [pid 1012520:tid 1012643] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/php_info.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYgAA3Hk"]
[Thu Sep 17 15:18:42.098759 2026] [security2:error] [pid 1012520:tid 1012652] [client 172.239.147.162:49923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZgAAAIY"], referer: binance.com
[Thu Sep 17 15:18:42.106654 2026] [security2:error] [pid 1012520:tid 1012632] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/php-info.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZwAA3G4"]
[Thu Sep 17 15:18:42.106692 2026] [security2:error] [pid 1012520:tid 1012634] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/infophp.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SaAAA3HA"]
[Thu Sep 17 15:18:42.115451 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cakephp/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SaQAAANI"]
[Thu Sep 17 15:18:42.127150 2026] [security2:error] [pid 1012520:tid 1012686] [client 185.61.219.136:39779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SawAAAKg"], referer: https://www.google.com
[Thu Sep 17 15:18:42.194233 2026] [security2:error] [pid 1012520:tid 1012525] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2ScAAA3AM"]
[Thu Sep 17 15:18:42.222953 2026] [security2:error] [pid 1012520:tid 1012637] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2ScwAA3HM"]
[Thu Sep 17 15:18:42.223017 2026] [security2:error] [pid 1012520:tid 1012633] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdAAA3G8"]
[Thu Sep 17 15:18:42.242160 2026] [security2:error] [pid 1012520:tid 1012644] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/api/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdQAA3Ho"]
[Thu Sep 17 15:18:42.242192 2026] [security2:error] [pid 1012520:tid 1012616] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdgAA3F4"]
[Thu Sep 17 15:18:42.270852 2026] [security2:error] [pid 1012520:tid 1012718] [client 8.228.208.101:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SdwAAAMg"]
[Thu Sep 17 15:18:42.284757 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SWwAAAOY"]
[Thu Sep 17 15:18:42.287630 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMQpXMN3p_zkwXf2SXAAAAL8"]
[Thu Sep 17 15:18:42.315520 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/zend/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SegAAAMk"]
[Thu Sep 17 15:18:42.339656 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SXgAAAN8"]
[Thu Sep 17 15:18:42.339684 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SYAAAAPs"]
[Thu Sep 17 15:18:42.386524 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZQAAAJU"]
[Thu Sep 17 15:18:42.387287 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SagAAANQ"]
[Thu Sep 17 15:18:42.396072 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SZAAAAKo"]
[Thu Sep 17 15:18:42.464802 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SeAAAAKU"]
[Thu Sep 17 15:18:42.514005 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SggAAAOc"]
[Thu Sep 17 15:18:42.520285 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SjAAAANc"]
[Thu Sep 17 15:18:42.536610 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/yii/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SkgAAANo"]
[Thu Sep 17 15:18:42.549017 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SjwAAALY"]
[Thu Sep 17 15:18:42.551681 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SkAAAAJ8"]
[Thu Sep 17 15:18:42.668512 2026] [security2:error] [pid 1012520:tid 1012544] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/database.sql"] [unique_id "aqxZMgpXMN3p_zkwXf2SlQAA2RY"]
[Thu Sep 17 15:18:42.833151 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SogAAAJc"]
[Thu Sep 17 15:18:42.833847 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SoQAAAPY"]
[Thu Sep 17 15:18:42.862504 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SpAAAALg"]
[Thu Sep 17 15:18:42.864227 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SowAAALw"]
[Thu Sep 17 15:18:42.864553 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/laravel5/.env"] [unique_id "aqxZMgpXMN3p_zkwXf2SuAAAANI"]
[Thu Sep 17 15:18:42.872104 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SpwAAAOs"]
[Thu Sep 17 15:18:42.878248 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SpgAAAOQ"]
[Thu Sep 17 15:18:42.907710 2026] [security2:error] [pid 1012520:tid 1012533] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/env.backup"] [unique_id "aqxZMgpXMN3p_zkwXf2SvQAA2Qs"]
[Thu Sep 17 15:18:42.952231 2026] [security2:error] [pid 1012520:tid 1012771] [client 8.228.208.101:41266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SwwAAAP0"]
[Thu Sep 17 15:18:42.999772 2026] [security2:error] [pid 1012520:tid 1012725] [client 185.61.219.136:53763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.219.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-login.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SxgAAAM8"], referer: https://www.google.com
[Thu Sep 17 15:18:43.001822 2026] [security2:error] [pid 1012520:tid 1012562] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.com"] [uri "/configuration.php.old"] [unique_id "aqxZMwpXMN3p_zkwXf2SyAAA2Sg"]
[Thu Sep 17 15:18:43.011584 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/v1/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2SzgAAAQQ"]
[Thu Sep 17 15:18:43.128894 2026] [security2:error] [pid 1012520:tid 1012693] [client 156.192.234.52:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S1gAAAK8"]
[Thu Sep 17 15:18:43.130047 2026] [security2:error] [pid 1012520:tid 1012693] [client 156.192.234.52:55708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S1gAAAK8"]
[Thu Sep 17 15:18:43.186921 2026] [security2:error] [pid 1012520:tid 1012548] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/kyc/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S2QAA2Ro"]
[Thu Sep 17 15:18:43.187102 2026] [security2:error] [pid 1012520:tid 1012574] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/site.bak"] [unique_id "aqxZMwpXMN3p_zkwXf2S2AAA2TQ"]
[Thu Sep 17 15:18:43.210091 2026] [security2:error] [pid 1012520:tid 1012553] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.com"] [uri "/wp-config.php.save"] [unique_id "aqxZMwpXMN3p_zkwXf2S3wAA2R8"]
[Thu Sep 17 15:18:43.213974 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/v2/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S4QAAAKU"]
[Thu Sep 17 15:18:43.372205 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2StgAAAIY"]
[Thu Sep 17 15:18:43.405568 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SvAAAAPs"]
[Thu Sep 17 15:18:43.408826 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5AAAAQE"]
[Thu Sep 17 15:18:43.410773 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SvgAAAN0"]
[Thu Sep 17 15:18:43.411743 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S0QAAAOM"]
[Thu Sep 17 15:18:43.411909 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5gAAAOc"]
[Thu Sep 17 15:18:43.411970 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SxQAAAPI"]
[Thu Sep 17 15:18:43.412052 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5wAAANc"]
[Thu Sep 17 15:18:43.416066 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/v3/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S8QAAAJI"]
[Thu Sep 17 15:18:43.416298 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SuQAAAP4"]
[Thu Sep 17 15:18:43.417554 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMgpXMN3p_zkwXf2SugAAAKg"]
[Thu Sep 17 15:18:43.425506 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S5QAAAJ4"]
[Thu Sep 17 15:18:43.598500 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/v1/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S8wAAAN4"]
[Thu Sep 17 15:18:43.636967 2026] [security2:error] [pid 1012520:tid 1012658] [client 8.228.208.101:41280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S9AAAAIw"]
[Thu Sep 17 15:18:43.639865 2026] [security2:error] [pid 1012520:tid 1012576] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/mysql.sql"] [unique_id "aqxZMwpXMN3p_zkwXf2S9gAAlzY"]
[Thu Sep 17 15:18:43.681135 2026] [security2:error] [pid 1012520:tid 1012572] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/node/api/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S-gAAlzI"]
[Thu Sep 17 15:18:43.750679 2026] [security2:error] [pid 1012520:tid 1012552] [remote 34.156.22.151:55556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.com"] [uri "/gcp/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2S_wAAlx4"]
[Thu Sep 17 15:18:43.852676 2026] [security2:error] [pid 1012520:tid 1012713] [client 169.58.197.253:61737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ppfc.net"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S6AAAAMM"], referer: binance.com
[Thu Sep 17 15:18:43.882193 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2S-wAAANE"]
[Thu Sep 17 15:18:43.938208 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2TAgAAAOo"]
[Thu Sep 17 15:18:43.939372 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/v2/.env"] [unique_id "aqxZMwpXMN3p_zkwXf2TCgAAAL8"]
[Thu Sep 17 15:18:43.949526 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.156.22.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.com"] [uri "/index.php"] [unique_id "aqxZMwpXMN3p_zkwXf2TAwAAAKA"]
[Thu Sep 17 15:18:44.240886 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/rest/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TDgAAAQQ"]
[Thu Sep 17 15:18:44.324334 2026] [security2:error] [pid 1012520:tid 1012719] [client 8.228.208.101:41288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxZNApXMN3p_zkwXf2TEQAAAMk"]
[Thu Sep 17 15:18:44.406701 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/graphql/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TEgAAAKc"]
[Thu Sep 17 15:18:44.590873 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/gateway/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TGAAAAOU"]
[Thu Sep 17 15:18:44.662986 2026] [security2:error] [pid 1012520:tid 1012682] [client 185.61.219.136:47769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxZNApXMN3p_zkwXf2TDwAAAKQ"], referer: https://www.google.com
[Thu Sep 17 15:18:44.761208 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/microservice/.env"] [unique_id "aqxZNApXMN3p_zkwXf2TGgAAAJY"]
[Thu Sep 17 15:18:44.988832 2026] [security2:error] [pid 1012520:tid 1012745] [client 5.189.145.112:49766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxZNApXMN3p_zkwXf2THwAAAOM"], referer: binance.com
[Thu Sep 17 15:18:45.018139 2026] [security2:error] [pid 1012520:tid 1012765] [client 8.228.208.101:41302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TIAAAAPc"]
[Thu Sep 17 15:18:45.038858 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/service/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TIwAAANc"]
[Thu Sep 17 15:18:45.121774 2026] [security2:error] [pid 1012520:tid 1012758] [client 186.105.232.15:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TKAAAAPA"]
[Thu Sep 17 15:18:45.121922 2026] [security2:error] [pid 1012520:tid 1012758] [client 186.105.232.15:58745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TKAAAAPA"]
[Thu Sep 17 15:18:45.151485 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TJAAAAJk"]
[Thu Sep 17 15:18:45.255988 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/v3/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TKwAAALk"]
[Thu Sep 17 15:18:45.512014 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/dev/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TMQAAAMI"]
[Thu Sep 17 15:18:45.693395 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/api/staging/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TNgAAAIk"]
[Thu Sep 17 15:18:45.704142 2026] [security2:error] [pid 1012520:tid 1012772] [client 8.228.208.101:41310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxZNQpXMN3p_zkwXf2TNwAAAP4"]
[Thu Sep 17 15:18:45.922734 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/vendor/.env"] [unique_id "aqxZNQpXMN3p_zkwXf2TPQAAAOE"]
[Thu Sep 17 15:18:46.088700 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TQAAAAKE"]
[Thu Sep 17 15:18:46.160334 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/lib/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TQgAAALE"]
[Thu Sep 17 15:18:46.391418 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/resources/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TSgAAAJM"]
[Thu Sep 17 15:18:46.511168 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNgpXMN3p_zkwXf2TRwAAAL8"]
[Thu Sep 17 15:18:46.625120 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/assets/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TUwAAAM8"]
[Thu Sep 17 15:18:46.790337 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/uploads/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TVgAAAPU"]
[Thu Sep 17 15:18:46.941386 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/internal/.env"] [unique_id "aqxZNgpXMN3p_zkwXf2TXAAAAIc"]
[Thu Sep 17 15:18:47.045708 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNgpXMN3p_zkwXf2TXQAAAKc"]
[Thu Sep 17 15:18:47.160871 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/tools/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TZQAAANY"]
[Thu Sep 17 15:18:47.296422 2026] [security2:error] [pid 1012520:tid 1012739] [client 8.228.208.101:41318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZNwpXMN3p_zkwXf2TawAAAN0"]
[Thu Sep 17 15:18:47.316789 2026] [security2:error] [pid 1012520:tid 1012668] [client 69.165.72.150:50151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.72.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xom.dyz.mybluehost.me"] [uri "/index.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TbAAAAJY"], referer: https://mail.xom.dyz.mybluehost.me
[Thu Sep 17 15:18:47.380048 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TagAAAJ8"]
[Thu Sep 17 15:18:47.401436 2026] [core:error] [pid 1012520:tid 1012749] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:47.401456 2026] [core:error] [pid 1012520:tid 1012749] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:18:47.425242 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/scripts/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TcgAAAL0"]
[Thu Sep 17 15:18:47.567718 2026] [security2:error] [pid 1012520:tid 1012723] [client 45.169.98.18:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TeAAAAM0"]
[Thu Sep 17 15:18:47.569643 2026] [security2:error] [pid 1012520:tid 1012723] [client 45.169.98.18:64064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TeAAAAM0"]
[Thu Sep 17 15:18:47.595374 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/bin/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TeQAAAKg"]
[Thu Sep 17 15:18:47.765201 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TewAAAJ4"]
[Thu Sep 17 15:18:47.876823 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sbin/.env"] [unique_id "aqxZNwpXMN3p_zkwXf2TfgAAAI0"]
[Thu Sep 17 15:18:47.998838 2026] [security2:error] [pid 1012520:tid 1012721] [client 8.228.208.101:41334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxZNwpXMN3p_zkwXf2TggAAAMs"]
[Thu Sep 17 15:18:48.067576 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/local/.env"] [unique_id "aqxZOApXMN3p_zkwXf2ThAAAALg"]
[Thu Sep 17 15:18:48.218115 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/portal/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TiAAAAMM"]
[Thu Sep 17 15:18:48.297248 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOApXMN3p_zkwXf2ThwAAAP8"]
[Thu Sep 17 15:18:48.464011 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/dashboard/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TjgAAAM4"]
[Thu Sep 17 15:18:48.580269 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOApXMN3p_zkwXf2TjwAAAOo"]
[Thu Sep 17 15:18:48.634626 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/panel/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TkwAAAK0"]
[Thu Sep 17 15:18:48.679685 2026] [security2:error] [pid 1012520:tid 1012695] [client 8.228.208.101:41340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZOApXMN3p_zkwXf2TlAAAALE"]
[Thu Sep 17 15:18:48.786735 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.bak"] [unique_id "aqxZOApXMN3p_zkwXf2TlgAAAOs"]
[Thu Sep 17 15:18:48.833833 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/crm/.env"] [unique_id "aqxZOApXMN3p_zkwXf2TmQAAANI"]
[Thu Sep 17 15:18:49.007887 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.backup"] [unique_id "aqxZOQpXMN3p_zkwXf2TnAAAAIg"]
[Thu Sep 17 15:18:49.120340 2026] [security2:error] [pid 1012520:tid 1012684] [client 134.185.85.61:60496] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "vagabondhiker.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxZOQpXMN3p_zkwXf2ToQAAAKY"]
[Thu Sep 17 15:18:49.150460 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/erp/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TogAAANQ"]
[Thu Sep 17 15:18:49.371796 2026] [security2:error] [pid 1012520:tid 1012685] [client 8.228.208.101:41350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TpgAAAKc"]
[Thu Sep 17 15:18:49.393545 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/shop/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TpwAAAI8"]
[Thu Sep 17 15:18:49.429978 2026] [security2:error] [pid 1012520:tid 1012719] [client 185.55.149.49:55773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TqQAAAMk"]
[Thu Sep 17 15:18:49.430072 2026] [security2:error] [pid 1012520:tid 1012719] [client 185.55.149.49:55773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TqQAAAMk"]
[Thu Sep 17 15:18:49.504156 2026] [security2:error] [pid 1012520:tid 1012756] [client 134.185.85.61:62907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "vagabondhiker.com"] [uri "/media/system/js/core.js"] [unique_id "aqxZOQpXMN3p_zkwXf2TqwAAAO4"]
[Thu Sep 17 15:18:49.615708 2026] [security2:error] [pid 1012520:tid 1012699] [client 154.190.208.131:42453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TrgAAALU"]
[Thu Sep 17 15:18:49.625171 2026] [security2:error] [pid 1012520:tid 1012699] [client 154.190.208.131:42453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOQpXMN3p_zkwXf2TrgAAALU"]
[Thu Sep 17 15:18:49.630867 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/store/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TrwAAAPI"]
[Thu Sep 17 15:18:49.825597 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/saas/.env"] [unique_id "aqxZOQpXMN3p_zkwXf2TsgAAALM"]
[Thu Sep 17 15:18:50.005447 2026] [security2:error] [pid 1012520:tid 1012589] [remote 110.249.202.193:43382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/130-Zoom-meeting.jpg"] [unique_id "aqxZOgpXMN3p_zkwXf2TtwAAuUM"]
[Thu Sep 17 15:18:50.037351 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/client/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TuQAAAPs"]
[Thu Sep 17 15:18:50.075817 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.228.208.101:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TugAAAJ0"]
[Thu Sep 17 15:18:50.207844 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/project/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TvgAAAOI"]
[Thu Sep 17 15:18:50.414925 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/admin-panel/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TwAAAANw"]
[Thu Sep 17 15:18:50.561279 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/control-panel/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TwwAAANk"]
[Thu Sep 17 15:18:50.706744 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TxgAAALg"]
[Thu Sep 17 15:18:50.792063 2026] [security2:error] [pid 1012520:tid 1012700] [client 8.228.208.101:41360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TzAAAALY"]
[Thu Sep 17 15:18:50.895272 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/user-panel/.env"] [unique_id "aqxZOgpXMN3p_zkwXf2TzwAAAJM"]
[Thu Sep 17 15:18:51.064934 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.old"] [unique_id "aqxZOwpXMN3p_zkwXf2T1QAAALE"]
[Thu Sep 17 15:18:51.073429 2026] [security2:error] [pid 1012520:tid 1012727] [client 114.198.138.124:55431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T1wAAANE"]
[Thu Sep 17 15:18:51.073505 2026] [security2:error] [pid 1012520:tid 1012727] [client 114.198.138.124:55431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T1wAAANE"]
[Thu Sep 17 15:18:51.163961 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/node/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T2gAAAPM"]
[Thu Sep 17 15:18:51.232961 2026] [security2:error] [pid 1012520:tid 1012778] [client 5.189.145.112:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T2wAAAQQ"], referer: binance.com
[Thu Sep 17 15:18:51.330983 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/express/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T4gAAAPc"]
[Thu Sep 17 15:18:51.456203 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T5AAAAKM"]
[Thu Sep 17 15:18:51.481479 2026] [security2:error] [pid 1012520:tid 1012690] [client 8.228.208.101:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxZOwpXMN3p_zkwXf2T6wAAAKw"]
[Thu Sep 17 15:18:51.501545 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/next/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T7AAAAJw"]
[Thu Sep 17 15:18:51.742696 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/nuxt/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T8gAAAKs"]
[Thu Sep 17 15:18:51.841806 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T8QAAAIY"]
[Thu Sep 17 15:18:52.001504 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/nest/.env"] [unique_id "aqxZOwpXMN3p_zkwXf2T9gAAAPk"]
[Thu Sep 17 15:18:52.169802 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPApXMN3p_zkwXf2T-wAAAPA"]
[Thu Sep 17 15:18:52.172872 2026] [security2:error] [pid 1012520:tid 1012775] [client 8.228.208.101:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxZPApXMN3p_zkwXf2UAgAAAQE"]
[Thu Sep 17 15:18:52.293174 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/react/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UBgAAAJ0"]
[Thu Sep 17 15:18:52.449014 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/vue/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UDQAAAIo"]
[Thu Sep 17 15:18:52.523018 2026] [security2:error] [pid 1012520:tid 1012743] [client 41.109.147.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TywAAAOE"]
[Thu Sep 17 15:18:52.526425 2026] [security2:error] [pid 1012520:tid 1012754] [client 148.230.161.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZOwpXMN3p_zkwXf2T4wAAAOw"]
[Thu Sep 17 15:18:52.568626 2026] [security2:error] [pid 1012520:tid 1012768] [client 172.239.147.162:59457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxZPApXMN3p_zkwXf2UEwAAAPo"], referer: binance.com
[Thu Sep 17 15:18:52.576136 2026] [security2:error] [pid 1012520:tid 1012565] [remote 87.81.226.99:7067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.npae.net"] [uri "/index.php"] [unique_id "aqxZOgpXMN3p_zkwXf2TuwAA8Ss"]
[Thu Sep 17 15:18:52.630874 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPApXMN3p_zkwXf2UEAAAANw"]
[Thu Sep 17 15:18:52.652480 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/angular/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UFAAAAJQ"]
[Thu Sep 17 15:18:52.835960 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/svelte/.env"] [unique_id "aqxZPApXMN3p_zkwXf2UFQAAAK0"]
[Thu Sep 17 15:18:52.871146 2026] [security2:error] [pid 1012520:tid 1012720] [client 8.228.208.101:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxZPApXMN3p_zkwXf2UGgAAAMo"]
[Thu Sep 17 15:18:52.999697 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPApXMN3p_zkwXf2UGwAAAQQ"]
[Thu Sep 17 15:18:53.028318 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/vite/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UIAAAAN4"]
[Thu Sep 17 15:18:53.185527 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/backup/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UJQAAAO8"]
[Thu Sep 17 15:18:53.439525 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UKgAAAIg"]
[Thu Sep 17 15:18:53.462171 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/backups/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2ULgAAAO4"]
[Thu Sep 17 15:18:53.556456 2026] [security2:error] [pid 1012520:tid 1012689] [client 8.228.208.101:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxZPQpXMN3p_zkwXf2ULwAAAKs"]
[Thu Sep 17 15:18:53.683764 2026] [security2:error] [pid 1012520:tid 1012747] [client 156.192.234.52:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UNwAAAOU"]
[Thu Sep 17 15:18:53.683935 2026] [security2:error] [pid 1012520:tid 1012747] [client 156.192.234.52:56340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UNwAAAOU"]
[Thu Sep 17 15:18:53.693382 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/old/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UOAAAAMI"]
[Thu Sep 17 15:18:53.771524 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UNgAAAOM"]
[Thu Sep 17 15:18:53.809065 2026] [security2:error] [pid 1012520:tid 1012668] [client 92.208.182.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UMgAAAJY"]
[Thu Sep 17 15:18:53.861431 2026] [security2:error] [pid 1012520:tid 1012696] [client 182.10.99.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZPQpXMN3p_zkwXf2UOwAAALI"]
[Thu Sep 17 15:18:53.958787 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/tmp/.env"] [unique_id "aqxZPQpXMN3p_zkwXf2UQwAAAIo"]
[Thu Sep 17 15:18:54.125047 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2URQAAANk"]
[Thu Sep 17 15:18:54.135726 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/temp/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2URgAAAOk"]
[Thu Sep 17 15:18:54.262140 2026] [security2:error] [pid 1012520:tid 1012743] [client 8.228.208.101:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxZPgpXMN3p_zkwXf2USQAAAOE"]
[Thu Sep 17 15:18:54.331082 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/lab/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2USwAAAJs"]
[Thu Sep 17 15:18:54.339531 2026] [security2:error] [pid 1012520:tid 1012721] [client 210.222.43.21:63813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2URwAAAMs"], referer: http://talent-in-borders.com/old-site
[Thu Sep 17 15:18:54.466291 2026] [authz_core:error] [pid 1012520:tid 1012706] [client 172.239.147.162:56649] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:54.526763 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cronlab/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2UVgAAAMw"]
[Thu Sep 17 15:18:54.550005 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2UUwAAALY"]
[Thu Sep 17 15:18:54.715739 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cron/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2UWgAAAK0"]
[Thu Sep 17 15:18:54.864055 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPgpXMN3p_zkwXf2UXQAAAMo"]
[Thu Sep 17 15:18:54.941427 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/en/.env"] [unique_id "aqxZPgpXMN3p_zkwXf2UYAAAAPc"]
[Thu Sep 17 15:18:54.953794 2026] [security2:error] [pid 1012520:tid 1012651] [client 8.228.208.101:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxZPgpXMN3p_zkwXf2UZAAAAIU"]
[Thu Sep 17 15:18:55.172493 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/administrator/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UaAAAAKY"]
[Thu Sep 17 15:18:55.245788 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UagAAAOo"]
[Thu Sep 17 15:18:55.346103 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/psnlink/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UbAAAAQA"]
[Thu Sep 17 15:18:55.480396 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env.swp"] [unique_id "aqxZPwpXMN3p_zkwXf2UcgAAANQ"]
[Thu Sep 17 15:18:55.481591 2026] [security2:error] [pid 1012520:tid 1012766] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UcwAA-G4"], referer: http://mezcalt.xavierlopezmiranda.com/new/
[Thu Sep 17 15:18:55.521816 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/exapi/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UdwAAAJE"]
[Thu Sep 17 15:18:55.614503 2026] [security2:error] [pid 1012520:tid 1012677] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UewAAnwM"], referer: http://mezcalt.xavierlopezmiranda.com/wordpress/
[Thu Sep 17 15:18:55.650466 2026] [security2:error] [pid 1012520:tid 1012746] [client 8.228.208.101:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UfAAAAOQ"]
[Thu Sep 17 15:18:55.667831 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.env~"] [unique_id "aqxZPwpXMN3p_zkwXf2UfgAAAMc"]
[Thu Sep 17 15:18:55.683534 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sitemaps/.env"] [unique_id "aqxZPwpXMN3p_zkwXf2UgAAAAKI"]
[Thu Sep 17 15:18:55.746574 2026] [security2:error] [pid 1012520:tid 1012662] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UgQAAkHM"], referer: http://mezcalt.xavierlopezmiranda.com/wp/
[Thu Sep 17 15:18:55.879285 2026] [security2:error] [pid 1012520:tid 1012769] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UhAAA-3o"], referer: http://mezcalt.xavierlopezmiranda.com/old/
[Thu Sep 17 15:18:55.914956 2026] [security2:error] [pid 1012520:tid 1012682] [client 186.105.232.15:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UiQAAAKQ"]
[Thu Sep 17 15:18:55.915111 2026] [security2:error] [pid 1012520:tid 1012682] [client 186.105.232.15:59348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UiQAAAKQ"]
[Thu Sep 17 15:18:56.013700 2026] [security2:error] [pid 1012520:tid 1012772] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UjgAA_mw"], referer: http://mezcalt.xavierlopezmiranda.com/blog/
[Thu Sep 17 15:18:56.020125 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UiAAAAIo"]
[Thu Sep 17 15:18:56.038877 2026] [security2:error] [pid 1012520:tid 1012697] [client 40.77.167.73:15478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nlfephrata.org"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UgwAAs28"]
[Thu Sep 17 15:18:56.145774 2026] [security2:error] [pid 1012520:tid 1012653] [client 66.249.88.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxZPwpXMN3p_zkwXf2UdAAAAIc"]
[Thu Sep 17 15:18:56.164901 2026] [security2:error] [pid 1012520:tid 1012768] [client 137.184.51.177:46614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezcalt.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UlAAA-nE"], referer: http://mezcalt.xavierlopezmiranda.com/backup/
[Thu Sep 17 15:18:56.261203 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/logs/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UlQAAAKk"]
[Thu Sep 17 15:18:56.350060 2026] [security2:error] [pid 1012520:tid 1012692] [client 8.228.208.101:43950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxZQApXMN3p_zkwXf2UmAAAAK4"]
[Thu Sep 17 15:18:56.432876 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cache/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UmgAAANs"]
[Thu Sep 17 15:18:56.461204 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UmQAAALY"]
[Thu Sep 17 15:18:56.524451 2026] [authz_core:error] [pid 1012520:tid 1012722] [client 172.239.147.162:63512] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:18:56.597473 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailer/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UowAAANw"]
[Thu Sep 17 15:18:56.623894 2026] [security2:error] [pid 1012520:tid 1012742] [client 148.71.151.160:62626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UoQAA4GE"]
[Thu Sep 17 15:18:56.769584 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQApXMN3p_zkwXf2UqQAAANI"]
[Thu Sep 17 15:18:56.840595 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mail/.env"] [unique_id "aqxZQApXMN3p_zkwXf2UqgAAAO8"]
[Thu Sep 17 15:18:57.041944 2026] [security2:error] [pid 1012520:tid 1012651] [client 8.228.208.101:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UsgAAAIU"]
[Thu Sep 17 15:18:57.271480 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/email/.env"] [unique_id "aqxZQQpXMN3p_zkwXf2UtwAAAK8"]
[Thu Sep 17 15:18:57.450993 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UugAAAOU"]
[Thu Sep 17 15:18:57.478974 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/smtp/.env"] [unique_id "aqxZQQpXMN3p_zkwXf2UvgAAANA"]
[Thu Sep 17 15:18:57.656063 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.246.241.88:58664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailing/.env"] [unique_id "aqxZQQpXMN3p_zkwXf2UwAAAAJk"]
[Thu Sep 17 15:18:57.756466 2026] [security2:error] [pid 1012520:tid 1012652] [client 8.228.208.101:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UwwAAAIY"]
[Thu Sep 17 15:18:57.873786 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQQpXMN3p_zkwXf2UxAAAAOk"]
[Thu Sep 17 15:18:58.086220 2026] [security2:error] [pid 1012520:tid 1012731] [client 45.169.98.18:64623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2UyQAAANU"]
[Thu Sep 17 15:18:58.086339 2026] [security2:error] [pid 1012520:tid 1012731] [client 45.169.98.18:64623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2UyQAAANU"]
[Thu Sep 17 15:18:58.098684 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/app/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2UygAAAJs"]
[Thu Sep 17 15:18:58.325395 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/apps/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2UzgAAAPo"]
[Thu Sep 17 15:18:58.389037 2026] [security2:error] [pid 1012520:tid 1012719] [client 104.28.198.244:23015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U0gAAAMk"]
[Thu Sep 17 15:18:58.389161 2026] [security2:error] [pid 1012520:tid 1012719] [client 104.28.198.244:23015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U0gAAAMk"]
[Thu Sep 17 15:18:58.452152 2026] [security2:error] [pid 1012520:tid 1012685] [client 8.228.208.101:43966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U1QAAAKc"]
[Thu Sep 17 15:18:58.467355 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/notifications/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U1wAAAMU"]
[Thu Sep 17 15:18:58.488269 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U2AAAANs"]
[Thu Sep 17 15:18:58.495392 2026] [security2:error] [pid 1012520:tid 1012698] [client 213.149.61.85:9886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U0QAAtBA"]
[Thu Sep 17 15:18:58.641405 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/notify/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U2wAAAM4"]
[Thu Sep 17 15:18:58.650919 2026] [authz_core:error] [pid 1012520:tid 1012666] [client 172.239.147.162:58281] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:18:58.684799 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/web/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U3AAAAP8"]
[Thu Sep 17 15:18:58.717679 2026] [security2:error] [pid 1012520:tid 1012760] [client 172.239.147.162:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U3QAAAPI"], referer: binance.com
[Thu Sep 17 15:18:58.880926 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sender/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U3wAAAK0"]
[Thu Sep 17 15:18:58.885304 2026] [security2:error] [pid 1012520:tid 1012706] [client 103.61.184.148:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U3gAAALw"]
[Thu Sep 17 15:18:58.885436 2026] [security2:error] [pid 1012520:tid 1012706] [client 103.61.184.148:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZQgpXMN3p_zkwXf2U3gAAALw"]
[Thu Sep 17 15:18:58.944818 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/site/.env"] [unique_id "aqxZQgpXMN3p_zkwXf2U4gAAANM"]
[Thu Sep 17 15:18:59.036903 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/campaign/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U5QAAAOg"]
[Thu Sep 17 15:18:59.130994 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/public/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U5wAAAOI"]
[Thu Sep 17 15:18:59.140711 2026] [security2:error] [pid 1012520:tid 1012736] [client 8.228.208.101:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZQwpXMN3p_zkwXf2U6AAAANo"]
[Thu Sep 17 15:18:59.275941 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/newsletter/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U6gAAAKA"]
[Thu Sep 17 15:18:59.461120 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/ses/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U7QAAAPQ"]
[Thu Sep 17 15:18:59.619313 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sendgrid/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U8wAAAMY"]
[Thu Sep 17 15:18:59.656726 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZQwpXMN3p_zkwXf2U8QAAALE"]
[Thu Sep 17 15:18:59.817259 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/sparkpost/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U9AAAANQ"]
[Thu Sep 17 15:18:59.819466 2026] [security2:error] [pid 1012520:tid 1012674] [client 8.228.208.101:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZQwpXMN3p_zkwXf2U9QAAAJw"]
[Thu Sep 17 15:18:59.838874 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/backend/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U9gAAAPw"]
[Thu Sep 17 15:18:59.998874 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/postmark/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U-wAAAOM"]
[Thu Sep 17 15:18:59.998874 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/server/.env"] [unique_id "aqxZQwpXMN3p_zkwXf2U_AAAAMc"]
[Thu Sep 17 15:19:00.094342 2026] [security2:error] [pid 1012520:tid 1012739] [client 185.55.149.49:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBAAAAN0"]
[Thu Sep 17 15:19:00.094461 2026] [security2:error] [pid 1012520:tid 1012739] [client 185.55.149.49:58256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBAAAAN0"]
[Thu Sep 17 15:19:00.178843 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailgun/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VBQAAAPs"]
[Thu Sep 17 15:19:00.179594 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/frontend/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VBgAAAIY"]
[Thu Sep 17 15:19:00.198948 2026] [security2:error] [pid 1012520:tid 1012714] [client 154.190.208.131:41706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBwAAAMQ"]
[Thu Sep 17 15:19:00.200252 2026] [security2:error] [pid 1012520:tid 1012714] [client 154.190.208.131:41706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRApXMN3p_zkwXf2VBwAAAMQ"]
[Thu Sep 17 15:19:00.389780 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/src/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VCgAAALM"]
[Thu Sep 17 15:19:00.468855 2026] [authz_core:error] [pid 1012520:tid 1012766] [client 172.239.147.162:56792] AH01630: client denied by server configuration: /home1/endurin2/public_html/gennarosalamone/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:19:00.505246 2026] [security2:error] [pid 1012520:tid 1012656] [client 3.82.141.143:8244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php"] [unique_id "aqxZRApXMN3p_zkwXf2VHwAAAIo"]
[Thu Sep 17 15:19:00.506099 2026] [core:error] [pid 1012520:tid 1012773] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.506114 2026] [core:error] [pid 1012520:tid 1012773] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.509157 2026] [security2:error] [pid 1012520:tid 1012687] [client 3.82.141.143:8278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php~"] [unique_id "aqxZRApXMN3p_zkwXf2VIwAAAKk"]
[Thu Sep 17 15:19:00.509293 2026] [security2:error] [pid 1012520:tid 1012663] [client 8.228.208.101:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZRApXMN3p_zkwXf2VIgAAAJE"]
[Thu Sep 17 15:19:00.510256 2026] [core:error] [pid 1012520:tid 1012655] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.510269 2026] [core:error] [pid 1012520:tid 1012655] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.512199 2026] [core:error] [pid 1012520:tid 1012760] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.512212 2026] [core:error] [pid 1012520:tid 1012760] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.513876 2026] [security2:error] [pid 1012520:tid 1012719] [client 3.82.141.143:8260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php.bak"] [unique_id "aqxZRApXMN3p_zkwXf2VKAAAAMk"]
[Thu Sep 17 15:19:00.517618 2026] [core:error] [pid 1012520:tid 1012750] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.517633 2026] [core:error] [pid 1012520:tid 1012750] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519261 2026] [core:error] [pid 1012520:tid 1012740] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519282 2026] [core:error] [pid 1012520:tid 1012740] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519712 2026] [core:error] [pid 1012520:tid 1012686] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.519723 2026] [core:error] [pid 1012520:tid 1012686] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.520182 2026] [core:error] [pid 1012520:tid 1012664] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.520194 2026] [core:error] [pid 1012520:tid 1012664] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.522956 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mandrill/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VOAAAAM8"]
[Thu Sep 17 15:19:00.525587 2026] [security2:error] [pid 1012520:tid 1012709] [client 3.82.141.143:8024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxZRApXMN3p_zkwXf2VOgAAAL8"]
[Thu Sep 17 15:19:00.531925 2026] [core:error] [pid 1012520:tid 1012711] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.531944 2026] [core:error] [pid 1012520:tid 1012711] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.534996 2026] [security2:error] [pid 1012520:tid 1012700] [client 3.82.141.143:8258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php.old"] [unique_id "aqxZRApXMN3p_zkwXf2VQAAAALY"]
[Thu Sep 17 15:19:00.535404 2026] [security2:error] [pid 1012520:tid 1012753] [client 3.82.141.143:8130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/config.php"] [unique_id "aqxZRApXMN3p_zkwXf2VQQAAAOs"]
[Thu Sep 17 15:19:00.537410 2026] [core:error] [pid 1012520:tid 1012752] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.537426 2026] [core:error] [pid 1012520:tid 1012752] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.538802 2026] [core:error] [pid 1012520:tid 1012683] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.538813 2026] [core:error] [pid 1012520:tid 1012683] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.539374 2026] [core:error] [pid 1012520:tid 1012689] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.539383 2026] [core:error] [pid 1012520:tid 1012689] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.540038 2026] [security2:error] [pid 1012520:tid 1012679] [client 3.82.141.143:8144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/web.config"] [unique_id "aqxZRApXMN3p_zkwXf2VSQAAAKE"]
[Thu Sep 17 15:19:00.540090 2026] [security2:error] [pid 1012520:tid 1012713] [client 3.82.141.143:8004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxZRApXMN3p_zkwXf2VSAAAAMM"]
[Thu Sep 17 15:19:00.546949 2026] [security2:error] [pid 1012520:tid 1012776] [client 162.241.226.11:35656] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxZRApXMN3p_zkwXf2VMQAAAQI"]
[Thu Sep 17 15:19:00.569875 2026] [security2:error] [pid 1012520:tid 1012701] [client 3.82.141.143:8342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/wp-config.php.save"] [unique_id "aqxZRApXMN3p_zkwXf2VWQAAALc"]
[Thu Sep 17 15:19:00.571144 2026] [core:error] [pid 1012520:tid 1012733] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571157 2026] [core:error] [pid 1012520:tid 1012696] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571162 2026] [core:error] [pid 1012520:tid 1012733] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571168 2026] [core:error] [pid 1012520:tid 1012696] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571185 2026] [core:error] [pid 1012520:tid 1012672] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571192 2026] [core:error] [pid 1012520:tid 1012672] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571218 2026] [core:error] [pid 1012520:tid 1012697] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571229 2026] [core:error] [pid 1012520:tid 1012697] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571345 2026] [core:error] [pid 1012520:tid 1012777] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.571352 2026] [core:error] [pid 1012520:tid 1012777] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.572737 2026] [core:error] [pid 1012520:tid 1012714] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.572748 2026] [core:error] [pid 1012520:tid 1012714] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.575857 2026] [security2:error] [pid 1012520:tid 1012706] [client 3.82.141.143:8354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VWwAAALw"]
[Thu Sep 17 15:19:00.585346 2026] [core:error] [pid 1012520:tid 1012657] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.585361 2026] [core:error] [pid 1012520:tid 1012657] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.598272 2026] [security2:error] [pid 1012520:tid 1012712] [client 3.82.141.143:8004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.cow.jso.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxZRApXMN3p_zkwXf2VZAAAAMI"]
[Thu Sep 17 15:19:00.606953 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/core/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VZQAAAPA"]
[Thu Sep 17 15:19:00.620076 2026] [core:error] [pid 1012520:tid 1012755] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.620094 2026] [core:error] [pid 1012520:tid 1012755] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654445 2026] [core:error] [pid 1012520:tid 1012698] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654468 2026] [core:error] [pid 1012520:tid 1012698] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654917 2026] [core:error] [pid 1012520:tid 1012753] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.654933 2026] [core:error] [pid 1012520:tid 1012753] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.763137 2026] [core:error] [pid 1012520:tid 1012766] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.763157 2026] [core:error] [pid 1012520:tid 1012766] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:00.807954 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/core/app/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VbwAAAQM"]
[Thu Sep 17 15:19:00.874344 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mailjet/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VcQAAAK0"]
[Thu Sep 17 15:19:00.986114 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/config/.env"] [unique_id "aqxZRApXMN3p_zkwXf2VdQAAAJk"]
[Thu Sep 17 15:19:01.007655 2026] [security2:error] [pid 1012520:tid 1012665] [client 192.178.6.5:43607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxZRQpXMN3p_zkwXf2VdgAAAJM"]
[Thu Sep 17 15:19:01.071165 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/brevo/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VdwAAALU"]
[Thu Sep 17 15:19:01.173501 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/private/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VeAAAAJQ"]
[Thu Sep 17 15:19:01.217676 2026] [security2:error] [pid 1012520:tid 1012663] [client 8.228.208.101:51850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZRQpXMN3p_zkwXf2VeQAAAJE"]
[Thu Sep 17 15:19:01.264723 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/transactional/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VegAAANo"]
[Thu Sep 17 15:19:01.338762 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/application/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VfgAAAKc"]
[Thu Sep 17 15:19:01.459757 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/bulk/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VgQAAAJY"]
[Thu Sep 17 15:19:01.543407 2026] [security2:error] [pid 1012520:tid 1012669] [client 85.153.205.90:10122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxZRApXMN3p_zkwXf2VCQAAlwE"], referer: https://www.adventuresofapril.com
[Thu Sep 17 15:19:01.554042 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/bootstrap/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VhQAAANU"]
[Thu Sep 17 15:19:01.636796 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/aws/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VhwAAAMI"]
[Thu Sep 17 15:19:01.691249 2026] [security2:error] [pid 1012520:tid 1012763] [client 114.198.138.124:56085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRQpXMN3p_zkwXf2ViAAAAPU"]
[Thu Sep 17 15:19:01.691343 2026] [security2:error] [pid 1012520:tid 1012763] [client 114.198.138.124:56085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZRQpXMN3p_zkwXf2ViAAAAPU"]
[Thu Sep 17 15:19:01.728323 2026] [security2:error] [pid 1012520:tid 1012667] [client 172.239.147.162:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxZRQpXMN3p_zkwXf2ViQAAAJU"], referer: binance.com
[Thu Sep 17 15:19:01.784748 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/database/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VigAAAO0"]
[Thu Sep 17 15:19:01.834772 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/azure/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2ViwAAAM4"]
[Thu Sep 17 15:19:01.928302 2026] [security2:error] [pid 1012520:tid 1012758] [client 8.228.208.101:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZRQpXMN3p_zkwXf2VjgAAAPA"]
[Thu Sep 17 15:19:01.985374 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/storage/.env"] [unique_id "aqxZRQpXMN3p_zkwXf2VkQAAAOE"]
[Thu Sep 17 15:19:02.010052 2026] [security2:error] [pid 1012520:tid 1012705] [client 172.239.147.162:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxZRgpXMN3p_zkwXf2VlAAAALs"], referer: binance.com
[Thu Sep 17 15:19:02.079370 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/gcp/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VlwAAAPM"]
[Thu Sep 17 15:19:02.143625 2026] [security2:error] [pid 1012520:tid 1012530] [remote 216.73.217.142:31090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxZRgpXMN3p_zkwXf2VmAAAkgg"]
[Thu Sep 17 15:19:02.167483 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/var/www/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VmQAAAKs"]
[Thu Sep 17 15:19:02.297220 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cloud/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VmgAAAN8"]
[Thu Sep 17 15:19:02.331913 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/var/www/html/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VmwAAAMM"]
[Thu Sep 17 15:19:02.503474 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/infrastructure/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VpQAAANg"]
[Thu Sep 17 15:19:02.578909 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/current/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VpgAAAIU"]
[Thu Sep 17 15:19:02.621449 2026] [security2:error] [pid 1012520:tid 1012662] [client 8.228.208.101:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZRgpXMN3p_zkwXf2VpwAAAJA"]
[Thu Sep 17 15:19:02.705680 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/docker/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VqAAAAPw"]
[Thu Sep 17 15:19:02.794773 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/release/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VqgAAAK8"]
[Thu Sep 17 15:19:02.861987 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/k8s/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VrAAAAPg"]
[Thu Sep 17 15:19:02.946365 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/releases/.env"] [unique_id "aqxZRgpXMN3p_zkwXf2VrQAAAM8"]
[Thu Sep 17 15:19:03.079566 2026] [security2:error] [pid 1012520:tid 1012733] [client 172.239.147.162:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VswAAANc"], referer: binance.com
[Thu Sep 17 15:19:03.190710 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/shared/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VtQAAANA"]
[Thu Sep 17 15:19:03.204791 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/kubernetes/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VtgAAAOw"]
[Thu Sep 17 15:19:03.268421 2026] [security2:error] [pid 1012520:tid 1012656] [client 200.181.217.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amecoegypt.com"] [uri "/index.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VtAAAAIo"]
[Thu Sep 17 15:19:03.311434 2026] [security2:error] [pid 1012520:tid 1012750] [client 8.228.208.101:51890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VuAAAAOg"]
[Thu Sep 17 15:19:03.380121 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/terraform/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VuQAAAJg"]
[Thu Sep 17 15:19:03.439289 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/deploy/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VugAAAQE"]
[Thu Sep 17 15:19:03.562680 2026] [security2:error] [pid 1012520:tid 1012549] [remote 17.166.23.86:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.23.166.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mtbclubdecampo.com"] [uri "/BlogMTB/protegidas/consultar_usuario.php"] [unique_id "aqxZRwpXMN3p_zkwXf2VvQAA1Bs"], referer: https://www.mtbclubdecampo.com/bici2/ruta.php?id=257
[Thu Sep 17 15:19:03.585610 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/ansible/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VvwAAAPk"]
[Thu Sep 17 15:19:03.639367 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/build/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VwAAAAJQ"]
[Thu Sep 17 15:19:03.877307 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dist/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VwgAAANo"]
[Thu Sep 17 15:19:03.981164 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/.git/.env"] [unique_id "aqxZRwpXMN3p_zkwXf2VxQAAANM"]
[Thu Sep 17 15:19:04.004296 2026] [security2:error] [pid 1012520:tid 1012687] [client 8.228.208.101:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.208.228.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.xya.fwq.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZSApXMN3p_zkwXf2VxgAAAKk"]
[Thu Sep 17 15:19:04.058835 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/public_html/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VxwAAAJY"]
[Thu Sep 17 15:19:04.172206 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/ci/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VyQAAANU"]
[Thu Sep 17 15:19:04.241069 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/htdocs/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VywAAAKw"]
[Thu Sep 17 15:19:04.281335 2026] [security2:error] [pid 1012520:tid 1012692] [client 156.192.234.52:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZSApXMN3p_zkwXf2VzQAAAK4"]
[Thu Sep 17 15:19:04.281446 2026] [security2:error] [pid 1012520:tid 1012692] [client 156.192.234.52:56975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZSApXMN3p_zkwXf2VzQAAAK4"]
[Thu Sep 17 15:19:04.334281 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/cd/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VzgAAAPU"]
[Thu Sep 17 15:19:04.392848 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/www/.env"] [unique_id "aqxZSApXMN3p_zkwXf2VzwAAAJ4"]
[Thu Sep 17 15:19:04.528945 2026] [security2:error] [pid 1012520:tid 1012723] [client 119.13.212.112:47887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZSApXMN3p_zkwXf2V0AAAzSM"]
[Thu Sep 17 15:19:04.573408 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/html/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V0QAAAJU"]
[Thu Sep 17 15:19:04.587698 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/jenkins/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V0gAAAO0"]
[Thu Sep 17 15:19:04.723500 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/live/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V1wAAAOE"]
[Thu Sep 17 15:19:04.817009 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/gitlab/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V2AAAAME"]
[Thu Sep 17 15:19:04.931122 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/prod/.env"] [unique_id "aqxZSApXMN3p_zkwXf2V2QAAALE"]
[Thu Sep 17 15:19:05.035960 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/github/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V3AAAAKs"]
[Thu Sep 17 15:19:05.153972 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dev/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V3wAAAKE"]
[Thu Sep 17 15:19:05.219217 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/actions/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V4gAAAQI"]
[Thu Sep 17 15:19:05.244739 2026] [security2:error] [pid 1012520:tid 1012674] [client 172.239.147.162:61950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V5AAAAJw"], referer: binance.com
[Thu Sep 17 15:19:05.345361 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/staging/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V5QAAANg"]
[Thu Sep 17 15:19:05.392878 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/circleci/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V5gAAAIU"]
[Thu Sep 17 15:19:05.501349 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/opt/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V6wAAAKA"]
[Thu Sep 17 15:19:05.542087 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/travis/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V7AAAAI8"]
[Thu Sep 17 15:19:05.709324 2026] [security2:error] [pid 1012520:tid 1012749] [client 119.13.212.112:34201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V7gAA5xo"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260621101158&hidebots=0&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:05.727708 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/buildkite/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V9QAAAIo"]
[Thu Sep 17 15:19:05.729867 2026] [security2:error] [pid 1012520:tid 1012704] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/laravel/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V9gAAALo"]
[Thu Sep 17 15:19:05.889201 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.204.169.220:34624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/symfony/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2V_wAAANQ"]
[Thu Sep 17 15:19:05.894895 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mysql/.env"] [unique_id "aqxZSQpXMN3p_zkwXf2WAAAAAJQ"]
[Thu Sep 17 15:19:05.951410 2026] [security2:error] [pid 1012520:tid 1012756] [client 43.172.196.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V-gAAAO4"]
[Thu Sep 17 15:19:05.951532 2026] [security2:error] [pid 1012520:tid 1012655] [client 43.173.174.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZSQpXMN3p_zkwXf2V-QAAAIk"]
[Thu Sep 17 15:19:06.179588 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/postgres/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WDAAAAJ8"]
[Thu Sep 17 15:19:06.424016 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/mongodb/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WFgAAAME"]
[Thu Sep 17 15:19:06.493247 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/wordpress/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WFwAAAN4"]
[Thu Sep 17 15:19:06.581095 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/redis/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WHAAAAKU"]
[Thu Sep 17 15:19:06.706569 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/wp/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WIQAAANg"]
[Thu Sep 17 15:19:06.732285 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/elasticsearch/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WIgAAAP0"]
[Thu Sep 17 15:19:06.907516 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cms/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WKwAAAOk"]
[Thu Sep 17 15:19:06.989694 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/rabbitmq/.env"] [unique_id "aqxZSgpXMN3p_zkwXf2WLQAAALc"]
[Thu Sep 17 15:19:07.122015 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/drupal/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WMQAAAOo"]
[Thu Sep 17 15:19:07.162498 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/kafka/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WNAAAAP4"]
[Thu Sep 17 15:19:07.212191 2026] [security2:error] [pid 1012520:tid 1012672] [client 79.108.166.138:56242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sableandox.co.uk"] [uri "/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WNwAAAJo"]
[Thu Sep 17 15:19:07.270496 2026] [security2:error] [pid 1012520:tid 1012671] [client 75.153.80.107:35335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZSwpXMN3p_zkwXf2WNQAAmQ8"]
[Thu Sep 17 15:19:07.322653 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/joomla/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WOgAAAPk"]
[Thu Sep 17 15:19:07.376929 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/queue/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WPQAAAIk"]
[Thu Sep 17 15:19:07.486955 2026] [security2:error] [pid 1012520:tid 1012764] [client 172.239.147.162:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cowboywithacamera.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxZSwpXMN3p_zkwXf2WQQAAAPY"], referer: binance.com
[Thu Sep 17 15:19:07.527837 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/worker/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WQgAAAK0"]
[Thu Sep 17 15:19:07.579893 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/magento/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WQwAAAKo"]
[Thu Sep 17 15:19:07.752682 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/job/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WSQAAAKw"]
[Thu Sep 17 15:19:07.764311 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/shopify/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WSwAAAI4"]
[Thu Sep 17 15:19:07.914024 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/test/.env"] [unique_id "aqxZSwpXMN3p_zkwXf2WUAAAAKg"]
[Thu Sep 17 15:19:08.059645 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/prestashop/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WUQAAAJc"]
[Thu Sep 17 15:19:08.062456 2026] [security2:error] [pid 1012520:tid 1012668] [client 186.105.232.15:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WUgAAAJY"]
[Thu Sep 17 15:19:08.062545 2026] [security2:error] [pid 1012520:tid 1012668] [client 186.105.232.15:59947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WUgAAAJY"]
[Thu Sep 17 15:19:08.170901 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/qa/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WVQAAAJE"]
[Thu Sep 17 15:19:08.253357 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/codeigniter/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WVwAAAN8"]
[Thu Sep 17 15:19:08.340816 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/preview/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WWQAAAKM"]
[Thu Sep 17 15:19:08.468377 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cakephp/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WYAAAAM0"]
[Thu Sep 17 15:19:08.480999 2026] [security2:error] [pid 1012520:tid 1012746] [client 75.153.80.107:46051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZTApXMN3p_zkwXf2WWgAA5B4"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260621101158&hidebots=0&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:08.505229 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/beta/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WaQAAAPc"]
[Thu Sep 17 15:19:08.538284 2026] [security2:error] [pid 1012520:tid 1012769] [client 45.169.98.18:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WawAAAPs"]
[Thu Sep 17 15:19:08.538378 2026] [security2:error] [pid 1012520:tid 1012769] [client 45.169.98.18:65190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTApXMN3p_zkwXf2WawAAAPs"]
[Thu Sep 17 15:19:08.621293 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/zend/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WdwAAALk"]
[Thu Sep 17 15:19:08.661473 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/uat/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WewAAALY"]
[Thu Sep 17 15:19:08.775360 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/yii/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WfgAAAPI"]
[Thu Sep 17 15:19:08.959595 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/stage/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WgQAAAIk"]
[Thu Sep 17 15:19:08.967724 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/laravel5/.env"] [unique_id "aqxZTApXMN3p_zkwXf2WggAAAKc"]
[Thu Sep 17 15:19:09.130127 2026] [security2:error] [pid 1012520:tid 1012754] [client 103.61.184.148:49671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WhAAAAOw"]
[Thu Sep 17 15:19:09.130267 2026] [security2:error] [pid 1012520:tid 1012754] [client 103.61.184.148:49671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WhAAAAOw"]
[Thu Sep 17 15:19:09.153478 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/v1/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WhQAAAOM"]
[Thu Sep 17 15:19:09.196312 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/development/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WiQAAAJ4"]
[Thu Sep 17 15:19:09.353370 2026] [security2:error] [pid 1012520:tid 1012763] [client 172.239.147.162:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WkAAAAPU"], referer: binance.com
[Thu Sep 17 15:19:09.367109 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/v2/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WkQAAAJU"]
[Thu Sep 17 15:19:09.373619 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/production/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WkgAAAJc"]
[Thu Sep 17 15:19:09.522306 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.246.241.88:52258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.teall.net"] [uri "/config/app/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WlgAAAMM"]
[Thu Sep 17 15:19:09.557545 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/v3/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WlwAAAKM"]
[Thu Sep 17 15:19:09.718089 2026] [security2:error] [pid 1012520:tid 1012654] [client 51.8.102.37:56677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seedboxpress.com"] [uri "/index.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WlQAAiDg"]
[Thu Sep 17 15:19:09.783842 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.246.241.88:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php"] [unique_id "aqxZTQpXMN3p_zkwXf2WnwAAAI8"]
[Thu Sep 17 15:19:09.838452 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/v1/.env"] [unique_id "aqxZTQpXMN3p_zkwXf2WowAAAJM"]
[Thu Sep 17 15:19:10.063980 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/v2/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WpQAAALc"]
[Thu Sep 17 15:19:10.220423 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/rest/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WqgAAAOY"]
[Thu Sep 17 15:19:10.439122 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WqwAAANY"]
[Thu Sep 17 15:19:10.463487 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.246.241.88:47314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/info.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WsAAAAP8"]
[Thu Sep 17 15:19:10.468499 2026] [autoindex:error] [pid 1012520:tid 1012746] [client 49.36.220.170:63259] AH01276: Cannot serve directory /home1/afbacoco/public_html/rcgi/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://rcgi.us
[Thu Sep 17 15:19:10.501744 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/graphql/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WsQAAAPI"]
[Thu Sep 17 15:19:10.646282 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/gateway/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WtQAAAJk"]
[Thu Sep 17 15:19:10.801125 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/microservice/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WuAAAANQ"]
[Thu Sep 17 15:19:10.952262 2026] [security2:error] [pid 1012520:tid 1012697] [client 185.55.149.49:58894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WuwAAALM"]
[Thu Sep 17 15:19:10.952776 2026] [security2:error] [pid 1012520:tid 1012697] [client 185.55.149.49:58894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZTgpXMN3p_zkwXf2WuwAAALM"]
[Thu Sep 17 15:19:10.971757 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/service/.env"] [unique_id "aqxZTgpXMN3p_zkwXf2WvAAAANo"]
[Thu Sep 17 15:19:11.073981 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WvwAAANs"]
[Thu Sep 17 15:19:11.075595 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.246.241.88:47326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/php.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WwAAAAIk"]
[Thu Sep 17 15:19:11.129536 2026] [security2:error] [pid 1012520:tid 1012749] [client 154.190.208.131:42314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WwwAAAOc"]
[Thu Sep 17 15:19:11.153421 2026] [security2:error] [pid 1012520:tid 1012749] [client 154.190.208.131:42314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WwwAAAOc"]
[Thu Sep 17 15:19:11.155678 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/v3/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WxAAAAQQ"]
[Thu Sep 17 15:19:11.310496 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/dev/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WyAAAAO8"]
[Thu Sep 17 15:19:11.504436 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/api/staging/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2WywAAAIc"]
[Thu Sep 17 15:19:11.577521 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WyQAAAI4"]
[Thu Sep 17 15:19:11.773759 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.246.241.88:47338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/i.php"] [unique_id "aqxZTwpXMN3p_zkwXf2W1gAAAJc"]
[Thu Sep 17 15:19:11.808606 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/vendor/.env"] [unique_id "aqxZTwpXMN3p_zkwXf2W2AAAAOA"]
[Thu Sep 17 15:19:12.029595 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZTwpXMN3p_zkwXf2W2gAAAJs"]
[Thu Sep 17 15:19:12.038994 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/lib/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W2wAAAKU"]
[Thu Sep 17 15:19:12.263599 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/resources/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W5QAAAMQ"]
[Thu Sep 17 15:19:12.432261 2026] [security2:error] [pid 1012520:tid 1012662] [client 157.100.69.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "threadalittlelight.com"] [uri "/index.php"] [unique_id "aqxZTwpXMN3p_zkwXf2WvQAAAJA"], referer: https://threadalittlelight.com
[Thu Sep 17 15:19:12.451416 2026] [security2:error] [pid 1012520:tid 1012771] [client 114.198.138.124:56736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUApXMN3p_zkwXf2W6QAAAP0"]
[Thu Sep 17 15:19:12.451551 2026] [security2:error] [pid 1012520:tid 1012771] [client 114.198.138.124:56736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUApXMN3p_zkwXf2W6QAAAP0"]
[Thu Sep 17 15:19:12.459524 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.246.241.88:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/pi.php"] [unique_id "aqxZUApXMN3p_zkwXf2W6gAAALA"]
[Thu Sep 17 15:19:12.497704 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/assets/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W6wAAAOQ"]
[Thu Sep 17 15:19:12.546502 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUApXMN3p_zkwXf2W5wAAAIU"]
[Thu Sep 17 15:19:12.783193 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/uploads/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W9AAAANI"]
[Thu Sep 17 15:19:12.798913 2026] [security2:error] [pid 1012520:tid 1012733] [client 76.33.142.4:22220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZUApXMN3p_zkwXf2W8AAA10w"]
[Thu Sep 17 15:19:12.974199 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/internal/.env"] [unique_id "aqxZUApXMN3p_zkwXf2W-gAAAIk"]
[Thu Sep 17 15:19:13.022591 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUApXMN3p_zkwXf2W9QAAAJo"]
[Thu Sep 17 15:19:13.043812 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.246.241.88:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/pinfo.php"] [unique_id "aqxZUQpXMN3p_zkwXf2W_AAAANo"]
[Thu Sep 17 15:19:13.176444 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/tools/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XAAAAAKg"]
[Thu Sep 17 15:19:13.390311 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/scripts/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XBQAAAJU"]
[Thu Sep 17 15:19:13.496195 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XAwAAAMw"]
[Thu Sep 17 15:19:13.612043 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/bin/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XBwAAAK4"]
[Thu Sep 17 15:19:13.628917 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.246.241.88:37944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/test.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XCgAAAKw"]
[Thu Sep 17 15:19:13.781756 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XDAAAAOE"]
[Thu Sep 17 15:19:13.785473 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sbin/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XEAAAAKM"]
[Thu Sep 17 15:19:13.951388 2026] [security2:error] [pid 1012520:tid 1012713] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUQpXMN3p_zkwXf2XDwAAAMM"]
[Thu Sep 17 15:19:13.990875 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/local/.env"] [unique_id "aqxZUQpXMN3p_zkwXf2XEgAAAMs"]
[Thu Sep 17 15:19:14.191779 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.bak"] [unique_id "aqxZUgpXMN3p_zkwXf2XFgAAAPE"]
[Thu Sep 17 15:19:14.231070 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/portal/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XFwAAAKU"]
[Thu Sep 17 15:19:14.267330 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XGAAAAN8"]
[Thu Sep 17 15:19:14.389487 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.backup"] [unique_id "aqxZUgpXMN3p_zkwXf2XGwAAAPc"]
[Thu Sep 17 15:19:14.437568 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dashboard/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XHQAAAOo"]
[Thu Sep 17 15:19:14.497319 2026] [security2:error] [pid 1012520:tid 1012597] [remote 111.225.149.176:14842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/152-Austin-Conference-300x225.jpg"] [unique_id "aqxZUgpXMN3p_zkwXf2XHgAAu0s"]
[Thu Sep 17 15:19:14.527351 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XHAAAANg"]
[Thu Sep 17 15:19:14.545498 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.246.241.88:37956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/p.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XHwAAAMA"]
[Thu Sep 17 15:19:14.666263 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/panel/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XJQAAAPs"]
[Thu Sep 17 15:19:14.693138 2026] [security2:error] [pid 1012520:tid 1012663] [client 172.239.147.162:56687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XJwAAAJE"], referer: binance.com
[Thu Sep 17 15:19:14.810602 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XJgAAAM4"]
[Thu Sep 17 15:19:14.818748 2026] [security2:error] [pid 1012520:tid 1012714] [client 156.192.234.52:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XKgAAAMQ"]
[Thu Sep 17 15:19:14.819245 2026] [security2:error] [pid 1012520:tid 1012714] [client 156.192.234.52:57601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XKgAAAMQ"]
[Thu Sep 17 15:19:14.825273 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/crm/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XKwAAALA"]
[Thu Sep 17 15:19:14.923076 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XKAAAAP0"]
[Thu Sep 17 15:19:14.989407 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/erp/.env"] [unique_id "aqxZUgpXMN3p_zkwXf2XLQAAAKE"]
[Thu Sep 17 15:19:15.072581 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUgpXMN3p_zkwXf2XLAAAALY"]
[Thu Sep 17 15:19:15.143625 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/shop/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XMgAAAQM"]
[Thu Sep 17 15:19:15.196214 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.old"] [unique_id "aqxZUwpXMN3p_zkwXf2XNQAAAIo"]
[Thu Sep 17 15:19:15.332113 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XNgAAAMo"]
[Thu Sep 17 15:19:15.348125 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:37962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/debug.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XOQAAAPk"]
[Thu Sep 17 15:19:15.396645 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/store/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XPAAAALM"]
[Thu Sep 17 15:19:15.592334 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/saas/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XQgAAAOY"]
[Thu Sep 17 15:19:15.594106 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XPwAAAOw"]
[Thu Sep 17 15:19:15.785740 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XPgAAAKI"]
[Thu Sep 17 15:19:15.786296 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/client/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XSAAAAOU"]
[Thu Sep 17 15:19:15.856334 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZUwpXMN3p_zkwXf2XRgAAAJ8"]
[Thu Sep 17 15:19:15.966424 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/project/.env"] [unique_id "aqxZUwpXMN3p_zkwXf2XSgAAAO8"]
[Thu Sep 17 15:19:16.012019 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.bak"] [unique_id "aqxZVApXMN3p_zkwXf2XUAAAAJY"]
[Thu Sep 17 15:19:16.120367 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/admin-panel/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XUgAAAI4"]
[Thu Sep 17 15:19:16.147459 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.246.241.88:37966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxZVApXMN3p_zkwXf2XUwAAAOM"]
[Thu Sep 17 15:19:16.165194 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.backup"] [unique_id "aqxZVApXMN3p_zkwXf2XVAAAAKM"]
[Thu Sep 17 15:19:16.238480 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XUQAAAN4"]
[Thu Sep 17 15:19:16.319230 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/control-panel/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XWQAAAJM"]
[Thu Sep 17 15:19:16.423418 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XWAAAAIw"]
[Thu Sep 17 15:19:16.470958 2026] [security2:error] [pid 1012520:tid 1012657] [client 170.246.12.9:3172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XWgAAiz0"]
[Thu Sep 17 15:19:16.487501 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/user-panel/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XYAAAAOs"]
[Thu Sep 17 15:19:16.576130 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.old"] [unique_id "aqxZVApXMN3p_zkwXf2XYgAAAJs"]
[Thu Sep 17 15:19:16.683160 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/node/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XaAAAAPc"]
[Thu Sep 17 15:19:16.770794 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XYQAAAJ0"]
[Thu Sep 17 15:19:16.856839 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/express/.env"] [unique_id "aqxZVApXMN3p_zkwXf2XawAAAJA"]
[Thu Sep 17 15:19:16.857192 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.246.241.88:37974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/test/phpinfo.php"] [unique_id "aqxZVApXMN3p_zkwXf2XbAAAAOo"]
[Thu Sep 17 15:19:16.864258 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVApXMN3p_zkwXf2XagAAANg"]
[Thu Sep 17 15:19:17.005216 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/next/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XdAAAAN0"]
[Thu Sep 17 15:19:17.131288 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XdwAAAP4"]
[Thu Sep 17 15:19:17.192823 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/nuxt/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XhAAAANc"]
[Thu Sep 17 15:19:17.285237 2026] [security2:error] [pid 1012520:tid 1012768] [client 76.33.142.4:23730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XhQAA-i8"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260621101158&hidebots=0&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:17.322316 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XdQAAAP0"]
[Thu Sep 17 15:19:17.400207 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XhwAAAJg"]
[Thu Sep 17 15:19:17.452776 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/nest/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XiQAAANs"]
[Thu Sep 17 15:19:17.490934 2026] [security2:error] [pid 1012520:tid 1012703] [client 172.239.147.162:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XigAAALk"], referer: binance.com
[Thu Sep 17 15:19:17.610331 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/react/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XkQAAALM"]
[Thu Sep 17 15:19:17.666857 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XjQAAAJw"]
[Thu Sep 17 15:19:17.669910 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.246.241.88:37978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XlQAAAIg"]
[Thu Sep 17 15:19:17.802136 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XkAAAAI0"]
[Thu Sep 17 15:19:17.805332 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/vue/.env"] [unique_id "aqxZVQpXMN3p_zkwXf2XmgAAAOY"]
[Thu Sep 17 15:19:17.906846 2026] [security2:error] [pid 1012520:tid 1012720] [client 186.105.232.15:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XngAAAMo"]
[Thu Sep 17 15:19:17.906943 2026] [security2:error] [pid 1012520:tid 1012720] [client 186.105.232.15:60546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XngAAAMo"]
[Thu Sep 17 15:19:17.946370 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVQpXMN3p_zkwXf2XnAAAANQ"]
[Thu Sep 17 15:19:18.025394 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/angular/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XoQAAAK4"]
[Thu Sep 17 15:19:18.201247 2026] [core:error] [pid 1012520:tid 1012711] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:18.201270 2026] [core:error] [pid 1012520:tid 1012711] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:19:18.206523 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/svelte/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XqwAAAJM"]
[Thu Sep 17 15:19:18.218280 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.246.241.88:37982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/old/phpinfo.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrAAAAQA"]
[Thu Sep 17 15:19:18.228241 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XpgAAAN4"]
[Thu Sep 17 15:19:18.311401 2026] [security2:error] [pid 1012520:tid 1012687] [client 104.28.198.244:22630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrgAAAKk"]
[Thu Sep 17 15:19:18.405861 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/vite/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XsAAAAN8"]
[Thu Sep 17 15:19:18.436948 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XqgAAAOE"]
[Thu Sep 17 15:19:18.495697 2026] [security2:error] [pid 1012520:tid 1012687] [client 104.28.198.244:22630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrgAAAKk"]
[Thu Sep 17 15:19:18.502352 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XrwAAAKU"]
[Thu Sep 17 15:19:18.564957 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/backup/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XsQAAAMA"]
[Thu Sep 17 15:19:18.771146 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XsgAAAKw"]
[Thu Sep 17 15:19:18.796024 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/backups/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XuQAAAOo"]
[Thu Sep 17 15:19:18.945872 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/old/.env"] [unique_id "aqxZVgpXMN3p_zkwXf2XwAAAAN0"]
[Thu Sep 17 15:19:19.023652 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XugAAAPs"]
[Thu Sep 17 15:19:19.025614 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.169.98.18:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XwgAAANA"]
[Thu Sep 17 15:19:19.025727 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.169.98.18:49369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XwgAAANA"]
[Thu Sep 17 15:19:19.049305 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVgpXMN3p_zkwXf2XvwAAAO0"]
[Thu Sep 17 15:19:19.079677 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.246.241.88:37990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XwwAAANg"]
[Thu Sep 17 15:19:19.182837 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/tmp/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2XxAAAAPg"]
[Thu Sep 17 15:19:19.322277 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XxgAAAJQ"]
[Thu Sep 17 15:19:19.353099 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/temp/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2XzgAAANw"]
[Thu Sep 17 15:19:19.435165 2026] [security2:error] [pid 1012520:tid 1012714] [client 37.39.192.188:44768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XywAAxHM"]
[Thu Sep 17 15:19:19.494165 2026] [security2:error] [pid 1012520:tid 1012656] [client 172.239.147.162:57288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XzQAAAIo"], referer: binance.com
[Thu Sep 17 15:19:19.533390 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/lab/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2X0QAAAKE"]
[Thu Sep 17 15:19:19.554245 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2XzAAAAPQ"]
[Thu Sep 17 15:19:19.603295 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X0AAAALM"]
[Thu Sep 17 15:19:19.702225 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cronlab/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2X1AAAANo"]
[Thu Sep 17 15:19:19.728820 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.246.241.88:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/public/phpinfo.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X1QAAAK0"]
[Thu Sep 17 15:19:19.762057 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env.swp"] [unique_id "aqxZVwpXMN3p_zkwXf2X2AAAAOY"]
[Thu Sep 17 15:19:19.827440 2026] [security2:error] [pid 1012520:tid 1012714] [client 103.61.184.148:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X2wAAAMQ"]
[Thu Sep 17 15:19:19.827555 2026] [security2:error] [pid 1012520:tid 1012714] [client 103.61.184.148:56719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X2wAAAMQ"]
[Thu Sep 17 15:19:19.896230 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cron/.env"] [unique_id "aqxZVwpXMN3p_zkwXf2X3AAAAPE"]
[Thu Sep 17 15:19:19.921943 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.env~"] [unique_id "aqxZVwpXMN3p_zkwXf2X3QAAALw"]
[Thu Sep 17 15:19:20.004961 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZVwpXMN3p_zkwXf2X2gAAAIY"]
[Thu Sep 17 15:19:20.086062 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/en/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X3wAAAMo"]
[Thu Sep 17 15:19:20.183305 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X3gAAAKg"]
[Thu Sep 17 15:19:20.373351 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/administrator/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X5QAAAKo"]
[Thu Sep 17 15:19:20.454079 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X5gAAANE"]
[Thu Sep 17 15:19:20.485896 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X5AAAAJU"]
[Thu Sep 17 15:19:20.574816 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/psnlink/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X6QAAAO8"]
[Thu Sep 17 15:19:20.724410 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X6gAAAJY"]
[Thu Sep 17 15:19:20.778004 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/exapi/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X9AAAAPM"]
[Thu Sep 17 15:19:20.805810 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.246.241.88:38002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/php-info.php"] [unique_id "aqxZWApXMN3p_zkwXf2X9QAAAPU"]
[Thu Sep 17 15:19:20.928733 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sitemaps/.env"] [unique_id "aqxZWApXMN3p_zkwXf2X9wAAAOs"]
[Thu Sep 17 15:19:20.972029 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWApXMN3p_zkwXf2X7wAAAQA"]
[Thu Sep 17 15:19:21.075548 2026] [security2:error] [pid 1012520:tid 1012723] [client 172.239.147.162:60845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2X-AAAAM0"], referer: binance.com
[Thu Sep 17 15:19:21.164950 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.swp"] [unique_id "aqxZWQpXMN3p_zkwXf2YCgAAAPs"]
[Thu Sep 17 15:19:21.287185 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YDAAAAM4"]
[Thu Sep 17 15:19:21.291440 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YBwAAAOo"]
[Thu Sep 17 15:19:21.348292 2026] [security2:error] [pid 1012520:tid 1012755] [client 172.239.147.162:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YFgAAAO0"], referer: binance.com
[Thu Sep 17 15:19:21.353543 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env~"] [unique_id "aqxZWQpXMN3p_zkwXf2YFwAAAPg"]
[Thu Sep 17 15:19:21.438736 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.246.241.88:38018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpversion.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YGAAAAP4"]
[Thu Sep 17 15:19:21.554837 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YGQAAAI8"]
[Thu Sep 17 15:19:21.641796 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YHQAAAPI"]
[Thu Sep 17 15:19:21.694251 2026] [security2:error] [pid 1012520:tid 1012734] [client 154.190.208.131:41578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YJAAAANg"]
[Thu Sep 17 15:19:21.694337 2026] [security2:error] [pid 1012520:tid 1012734] [client 154.190.208.131:41578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YJAAAANg"]
[Thu Sep 17 15:19:21.694858 2026] [security2:error] [pid 1012520:tid 1012738] [client 185.55.149.49:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YIgAAANw"]
[Thu Sep 17 15:19:21.694924 2026] [security2:error] [pid 1012520:tid 1012738] [client 185.55.149.49:59436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YIgAAANw"]
[Thu Sep 17 15:19:21.711528 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/app/.env"] [unique_id "aqxZWQpXMN3p_zkwXf2YJQAAALA"]
[Thu Sep 17 15:19:21.829962 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWQpXMN3p_zkwXf2YIAAAALk"]
[Thu Sep 17 15:19:21.846246 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.204.169.220:35242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/logs/.env"] [unique_id "aqxZWQpXMN3p_zkwXf2YKAAAANU"]
[Thu Sep 17 15:19:21.868320 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/apps/.env"] [unique_id "aqxZWQpXMN3p_zkwXf2YKQAAAL0"]
[Thu Sep 17 15:19:22.021247 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YKwAAAIY"]
[Thu Sep 17 15:19:22.150076 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.246.241.88:50720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/_phpinfo.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YLwAAAPk"]
[Thu Sep 17 15:19:22.180883 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/web/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YMQAAAKg"]
[Thu Sep 17 15:19:22.335142 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/site/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YNQAAANE"]
[Thu Sep 17 15:19:22.359466 2026] [security2:error] [pid 1012520:tid 1012754] [client 13.140.130.193:39782] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "coblersen.com"] [uri "/default.html"] [unique_id "aqxZWgpXMN3p_zkwXf2YNwAAAOw"]
[Thu Sep 17 15:19:22.374404 2026] [security2:error] [pid 1012520:tid 1012736] [client 85.86.29.178:59982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YNgAA2hk"], referer: https://www.adventuresofapril.com
[Thu Sep 17 15:19:22.427657 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YLgAAAOA"]
[Thu Sep 17 15:19:22.489105 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/public/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YPgAAAJY"]
[Thu Sep 17 15:19:22.529649 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cache/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YPwAAALU"]
[Thu Sep 17 15:19:22.714031 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailer/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YRwAAAPc"]
[Thu Sep 17 15:19:22.755506 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.32.0.94:37438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YQwAAAI4"]
[Thu Sep 17 15:19:22.801820 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.246.241.88:50736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/old_phpinfo.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YTQAAAOs"]
[Thu Sep 17 15:19:22.868581 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mail/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YTwAAAN4"]
[Thu Sep 17 15:19:22.912018 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/backend/.env"] [unique_id "aqxZWgpXMN3p_zkwXf2YUAAAAKk"]
[Thu Sep 17 15:19:22.956639 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWgpXMN3p_zkwXf2YTAAAAMg"]
[Thu Sep 17 15:19:23.048835 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/email/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YWgAAAOI"]
[Thu Sep 17 15:19:23.077174 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/server/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YWwAAALs"]
[Thu Sep 17 15:19:23.232708 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/frontend/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YYQAAAI8"]
[Thu Sep 17 15:19:23.244546 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/smtp/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YZAAAAP0"]
[Thu Sep 17 15:19:23.266443 2026] [security2:error] [pid 1012520:tid 1012766] [client 172.239.147.162:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YZQAAAPg"], referer: binance.com
[Thu Sep 17 15:19:23.389188 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/src/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YaAAAALI"]
[Thu Sep 17 15:19:23.515190 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailing/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YcwAAAOY"]
[Thu Sep 17 15:19:23.543206 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/core/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YdAAAAPo"]
[Thu Sep 17 15:19:23.585975 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:50750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/server-info.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YdQAAAIo"]
[Thu Sep 17 15:19:23.699221 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/core/app/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YeAAAAL0"]
[Thu Sep 17 15:19:23.725309 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/notifications/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YewAAAO4"]
[Thu Sep 17 15:19:23.730643 2026] [security2:error] [pid 1012520:tid 1012678] [client 114.198.138.124:57372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YfQAAAKA"]
[Thu Sep 17 15:19:23.730777 2026] [security2:error] [pid 1012520:tid 1012678] [client 114.198.138.124:57372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YfQAAAKA"]
[Thu Sep 17 15:19:23.858449 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/config/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YgQAAAPE"]
[Thu Sep 17 15:19:23.957538 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/notify/.env"] [unique_id "aqxZWwpXMN3p_zkwXf2YgwAAAOc"]
[Thu Sep 17 15:19:23.959321 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZWwpXMN3p_zkwXf2YfAAAAQE"]
[Thu Sep 17 15:19:24.015961 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/private/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YhQAAAMI"]
[Thu Sep 17 15:19:24.122544 2026] [security2:error] [pid 1012520:tid 1012574] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YiAAAqDQ"]
[Thu Sep 17 15:19:24.123790 2026] [security2:error] [pid 1012520:tid 1012543] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.old"] [unique_id "aqxZXApXMN3p_zkwXf2YjQAAqBU"]
[Thu Sep 17 15:19:24.163548 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sender/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YlQAAAJI"]
[Thu Sep 17 15:19:24.172100 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/application/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YmAAAAJY"]
[Thu Sep 17 15:19:24.327503 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/bootstrap/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YpwAAAI4"]
[Thu Sep 17 15:19:24.331242 2026] [security2:error] [pid 1012520:tid 1012757] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YmgAAAO8"]
[Thu Sep 17 15:19:24.333020 2026] [security2:error] [pid 1012520:tid 1012702] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YlwAAALg"]
[Thu Sep 17 15:19:24.334372 2026] [security2:error] [pid 1012520:tid 1012692] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YmQAAAK4"]
[Thu Sep 17 15:19:24.335612 2026] [security2:error] [pid 1012520:tid 1012716] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YnAAAAMY"]
[Thu Sep 17 15:19:24.335645 2026] [security2:error] [pid 1012520:tid 1012747] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YlgAAAOU"]
[Thu Sep 17 15:19:24.346077 2026] [security2:error] [pid 1012520:tid 1012535] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.bak"] [unique_id "aqxZXApXMN3p_zkwXf2YqQAAqA0"]
[Thu Sep 17 15:19:24.346164 2026] [security2:error] [pid 1012520:tid 1012571] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.backup"] [unique_id "aqxZXApXMN3p_zkwXf2YrAAAqDE"]
[Thu Sep 17 15:19:24.369955 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/campaign/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YuwAAAJ0"]
[Thu Sep 17 15:19:24.433287 2026] [security2:error] [pid 1012520:tid 1012669] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YpAAAAJc"]
[Thu Sep 17 15:19:24.484605 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/database/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YxAAAAPI"]
[Thu Sep 17 15:19:24.542746 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YogAAAPM"]
[Thu Sep 17 15:19:24.565756 2026] [security2:error] [pid 1012520:tid 1012721] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvAAAAMs"]
[Thu Sep 17 15:19:24.567095 2026] [security2:error] [pid 1012520:tid 1012729] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvQAAANM"]
[Thu Sep 17 15:19:24.577645 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvgAAANA"]
[Thu Sep 17 15:19:24.596175 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwgAAALs"]
[Thu Sep 17 15:19:24.596565 2026] [security2:error] [pid 1012520:tid 1012663] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwwAAAJE"]
[Thu Sep 17 15:19:24.597645 2026] [security2:error] [pid 1012520:tid 1012744] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwAAAAOI"]
[Thu Sep 17 15:19:24.597922 2026] [security2:error] [pid 1012520:tid 1012710] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YvwAAAMA"]
[Thu Sep 17 15:19:24.598387 2026] [security2:error] [pid 1012520:tid 1012732] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXApXMN3p_zkwXf2YwQAAANY"]
[Thu Sep 17 15:19:24.610178 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/newsletter/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YxQAAAL0"]
[Thu Sep 17 15:19:24.643043 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/storage/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YxgAAAO4"]
[Thu Sep 17 15:19:24.682035 2026] [security2:error] [pid 1012520:tid 1012698] [client 172.239.147.162:53313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.147.239.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gennarosalamone.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxZXApXMN3p_zkwXf2YxwAAALQ"], referer: binance.com
[Thu Sep 17 15:19:24.756340 2026] [security2:error] [pid 1012520:tid 1012654] [client 159.89.175.243:60633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lowlandblues.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxZXApXMN3p_zkwXf2YyAAAAIg"]
[Thu Sep 17 15:19:24.761147 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.246.241.88:50760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/server-status.php"] [unique_id "aqxZXApXMN3p_zkwXf2YyQAAAOo"]
[Thu Sep 17 15:19:24.770108 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/app/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YygAAAMk"]
[Thu Sep 17 15:19:24.798345 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/var/www/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YywAAAIY"]
[Thu Sep 17 15:19:24.895234 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/ses/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YzAAAAI0"]
[Thu Sep 17 15:19:24.954652 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/var/www/html/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YzQAAAKc"]
[Thu Sep 17 15:19:24.962335 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/apps/.env"] [unique_id "aqxZXApXMN3p_zkwXf2YzgAAAPk"]
[Thu Sep 17 15:19:25.096645 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sendgrid/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y1AAAAKY"]
[Thu Sep 17 15:19:25.110642 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/current/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y1QAAALw"]
[Thu Sep 17 15:19:25.163559 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y1gAAANE"]
[Thu Sep 17 15:19:25.262382 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/sparkpost/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y2gAAAJY"]
[Thu Sep 17 15:19:25.264009 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/release/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y2wAAAMc"]
[Thu Sep 17 15:19:25.361979 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/web/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y3wAAAMY"]
[Thu Sep 17 15:19:25.418752 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/releases/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y4wAAAK8"]
[Thu Sep 17 15:19:25.426766 2026] [security2:error] [pid 1012520:tid 1012775] [client 156.192.234.52:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5AAAAQE"]
[Thu Sep 17 15:19:25.427335 2026] [security2:error] [pid 1012520:tid 1012775] [client 156.192.234.52:58239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5AAAAQE"]
[Thu Sep 17 15:19:25.470945 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/postmark/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5gAAAMg"]
[Thu Sep 17 15:19:25.552939 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/site/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y5wAAAKI"]
[Thu Sep 17 15:19:25.571107 2026] [security2:error] [pid 1012520:tid 1012585] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/api/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y8gABBD8"]
[Thu Sep 17 15:19:25.571160 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/shared/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y7gAAAJ0"]
[Thu Sep 17 15:19:25.571343 2026] [security2:error] [pid 1012520:tid 1012575] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env~"] [unique_id "aqxZXQpXMN3p_zkwXf2Y6QABBDU"]
[Thu Sep 17 15:19:25.571352 2026] [security2:error] [pid 1012520:tid 1012581] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.swp"] [unique_id "aqxZXQpXMN3p_zkwXf2Y6gABBDs"]
[Thu Sep 17 15:19:25.588526 2026] [security2:error] [pid 1012520:tid 1012573] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/.env.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y6AABBDM"]
[Thu Sep 17 15:19:25.630268 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailgun/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_AAAAPM"]
[Thu Sep 17 15:19:25.718557 2026] [security2:error] [pid 1012520:tid 1012598] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/app/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZAgABBEw"]
[Thu Sep 17 15:19:25.718574 2026] [security2:error] [pid 1012520:tid 1012587] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/backend/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZBAABBEE"]
[Thu Sep 17 15:19:25.718865 2026] [security2:error] [pid 1012520:tid 1012600] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/server/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZBwABBE4"]
[Thu Sep 17 15:19:25.725559 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/deploy/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZCQAAALI"]
[Thu Sep 17 15:19:25.742918 2026] [security2:error] [pid 1012520:tid 1012763] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y-gAAAPU"]
[Thu Sep 17 15:19:25.743540 2026] [security2:error] [pid 1012520:tid 1012677] [client 159.89.175.243:61566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.175.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lowlandblues.co"] [uri "/xmlrpc.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZAQAAAJ8"]
[Thu Sep 17 15:19:25.744970 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/public/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDAAAANg"]
[Thu Sep 17 15:19:25.793517 2026] [security2:error] [pid 1012520:tid 1012760] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_QAAAPI"]
[Thu Sep 17 15:19:25.793711 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y-wAAALY"]
[Thu Sep 17 15:19:25.809860 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mandrill/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZEAAAAMA"]
[Thu Sep 17 15:19:25.821513 2026] [security2:error] [pid 1012520:tid 1012721] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_wAAAMs"]
[Thu Sep 17 15:19:25.823603 2026] [security2:error] [pid 1012520:tid 1012670] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2Y_gAAAJg"]
[Thu Sep 17 15:19:25.825647 2026] [security2:error] [pid 1012520:tid 1012729] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZAAAAANM"]
[Thu Sep 17 15:19:25.879981 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/build/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZFAAAAPo"]
[Thu Sep 17 15:19:25.901219 2026] [security2:error] [pid 1012520:tid 1012601] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/web/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGgABBE8"]
[Thu Sep 17 15:19:25.901219 2026] [security2:error] [pid 1012520:tid 1012589] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/client/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGwABBEM"]
[Thu Sep 17 15:19:25.901238 2026] [security2:error] [pid 1012520:tid 1012584] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/src/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGAABBD4"]
[Thu Sep 17 15:19:25.901270 2026] [security2:error] [pid 1012520:tid 1012607] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/config/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZGQABBFU"]
[Thu Sep 17 15:19:25.902243 2026] [security2:error] [pid 1012520:tid 1012593] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/public/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZHQABBEc"]
[Thu Sep 17 15:19:25.902297 2026] [security2:error] [pid 1012520:tid 1012599] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/frontend/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZHAABBE0"]
[Thu Sep 17 15:19:25.905588 2026] [security2:error] [pid 1012520:tid 1012595] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/var/www/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZHgABBEk"]
[Thu Sep 17 15:19:25.919053 2026] [security2:error] [pid 1012520:tid 1012776] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDQAAAQI"]
[Thu Sep 17 15:19:25.920595 2026] [security2:error] [pid 1012520:tid 1012663] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDwAAAJE"]
[Thu Sep 17 15:19:25.922671 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXQpXMN3p_zkwXf2ZDgAAALs"]
[Thu Sep 17 15:19:25.938978 2026] [security2:error] [pid 1012520:tid 1012583] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/var/www/html/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZIgAAvz0"]
[Thu Sep 17 15:19:25.994211 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mailjet/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZJAAAAKg"]
[Thu Sep 17 15:19:26.000254 2026] [security2:error] [pid 1012520:tid 1012596] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/laravel/.env"] [unique_id "aqxZXQpXMN3p_zkwXf2ZJQAAiEo"]
[Thu Sep 17 15:19:26.002598 2026] [security2:error] [pid 1012520:tid 1012604] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/application/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZJgAA6lI"]
[Thu Sep 17 15:19:26.019972 2026] [security2:error] [pid 1012520:tid 1012603] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/apps/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKAAAhlE"]
[Thu Sep 17 15:19:26.036358 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/dist/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKQAAAI0"]
[Thu Sep 17 15:19:26.084512 2026] [security2:error] [pid 1012520:tid 1012610] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/backup/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKwAA8Vg"]
[Thu Sep 17 15:19:26.084520 2026] [security2:error] [pid 1012520:tid 1012614] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/dev/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLgAA8Vw"]
[Thu Sep 17 15:19:26.084564 2026] [security2:error] [pid 1012520:tid 1012590] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/prod/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZKgAA8UQ"]
[Thu Sep 17 15:19:26.084579 2026] [security2:error] [pid 1012520:tid 1012611] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/back/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLQAA8Vk"]
[Thu Sep 17 15:19:26.084613 2026] [security2:error] [pid 1012520:tid 1012631] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/staging/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMAAA8W0"]
[Thu Sep 17 15:19:26.084641 2026] [security2:error] [pid 1012520:tid 1012615] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/production/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLwAA8V0"]
[Thu Sep 17 15:19:26.084650 2026] [security2:error] [pid 1012520:tid 1012628] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/test/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMQAA8Wo"]
[Thu Sep 17 15:19:26.084692 2026] [security2:error] [pid 1012520:tid 1012612] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/cms/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZLAAA8Vo"]
[Thu Sep 17 15:19:26.094798 2026] [security2:error] [pid 1012520:tid 1012627] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/old/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMgAA-Wk"]
[Thu Sep 17 15:19:26.111275 2026] [security2:error] [pid 1012520:tid 1012629] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/new/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZMwAAqms"]
[Thu Sep 17 15:19:26.123532 2026] [security2:error] [pid 1012520:tid 1012565] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/node-api/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZNgAA5ys"]
[Thu Sep 17 15:19:26.123532 2026] [security2:error] [pid 1012520:tid 1012569] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/api-backend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZNQAA5y8"]
[Thu Sep 17 15:19:26.123576 2026] [security2:error] [pid 1012520:tid 1012588] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/admin-app/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZNAAA50I"]
[Thu Sep 17 15:19:26.167588 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZXgpXMN3p_zkwXf2ZOQAAALw"]
[Thu Sep 17 15:19:26.172520 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/brevo/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZOgAAANE"]
[Thu Sep 17 15:19:26.188527 2026] [security2:error] [pid 1012520:tid 1012609] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/public_html/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZPAAAxFc"]
[Thu Sep 17 15:19:26.190751 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/public_html/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZPQAAAMw"]
[Thu Sep 17 15:19:26.205708 2026] [security2:error] [pid 1012520:tid 1012623] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/current/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZPwAAxGU"]
[Thu Sep 17 15:19:26.251894 2026] [security2:error] [pid 1012520:tid 1012622] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/administrator/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZOwAAxGQ"]
[Thu Sep 17 15:19:26.269635 2026] [security2:error] [pid 1012520:tid 1012608] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/server/api/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZQwAAklY"]
[Thu Sep 17 15:19:26.269639 2026] [security2:error] [pid 1012520:tid 1012632] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZQQAAkm4"]
[Thu Sep 17 15:19:26.269715 2026] [security2:error] [pid 1012520:tid 1012624] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.docker/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRAAAkmY"]
[Thu Sep 17 15:19:26.269763 2026] [security2:error] [pid 1012520:tid 1012642] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/server/backend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZQgAAkng"]
[Thu Sep 17 15:19:26.270008 2026] [security2:error] [pid 1012520:tid 1012525] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/aws/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRQAAkgM"]
[Thu Sep 17 15:19:26.270064 2026] [security2:error] [pid 1012520:tid 1012643] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/stripe/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRwAAknk"]
[Thu Sep 17 15:19:26.270123 2026] [security2:error] [pid 1012520:tid 1012637] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.aws/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZRgAAknM"]
[Thu Sep 17 15:19:26.281707 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZJwAAAKE"]
[Thu Sep 17 15:19:26.296373 2026] [security2:error] [pid 1012520:tid 1012633] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/v1/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTQAAkm8"]
[Thu Sep 17 15:19:26.308534 2026] [security2:error] [pid 1012520:tid 1012616] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/v2/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZUAAAkl4"]
[Thu Sep 17 15:19:26.308533 2026] [security2:error] [pid 1012520:tid 1012635] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/media/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTwAAknE"]
[Thu Sep 17 15:19:26.308590 2026] [security2:error] [pid 1012520:tid 1012619] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/v3/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTgAAkmE"]
[Thu Sep 17 15:19:26.346436 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/htdocs/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZUwAAAJM"]
[Thu Sep 17 15:19:26.419428 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/transactional/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZXAAAAJo"]
[Thu Sep 17 15:19:26.489264 2026] [security2:error] [pid 1012520:tid 1012544] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.git/config.bak"] [unique_id "aqxZXgpXMN3p_zkwXf2ZdwAAkhY"]
[Thu Sep 17 15:19:26.504152 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/www/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfAAAALI"]
[Thu Sep 17 15:19:26.504168 2026] [security2:error] [pid 1012520:tid 1012660] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZVQAAAI4"]
[Thu Sep 17 15:19:26.510266 2026] [security2:error] [pid 1012520:tid 1012751] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZVAAAAOk"]
[Thu Sep 17 15:19:26.516597 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/backend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfwAAAPI"]
[Thu Sep 17 15:19:26.529512 2026] [security2:error] [pid 1012520:tid 1012764] [client 49.51.195.195:50572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZTAAAAPY"]
[Thu Sep 17 15:19:26.573697 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/bulk/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZigAAAK0"]
[Thu Sep 17 15:19:26.638398 2026] [security2:error] [pid 1012520:tid 1012740] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZXwAAAN4"]
[Thu Sep 17 15:19:26.665451 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/html/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZiwAAAPo"]
[Thu Sep 17 15:19:26.680336 2026] [security2:error] [pid 1012520:tid 1012730] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZYwAAANQ"]
[Thu Sep 17 15:19:26.696313 2026] [security2:error] [pid 1012520:tid 1012745] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfQAAAOM"]
[Thu Sep 17 15:19:26.714814 2026] [security2:error] [pid 1012520:tid 1012677] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZgwAAAJ8"]
[Thu Sep 17 15:19:26.715496 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/server/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZkAAAALs"]
[Thu Sep 17 15:19:26.719354 2026] [security2:error] [pid 1012520:tid 1012769] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZggAAAPs"]
[Thu Sep 17 15:19:26.779894 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/aws/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZmAAAAPc"]
[Thu Sep 17 15:19:26.829078 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/live/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZnAAAAIY"]
[Thu Sep 17 15:19:26.908350 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/frontend/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZqgAAAOw"]
[Thu Sep 17 15:19:26.918271 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.246.241.88:50780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZqwAAALc"]
[Thu Sep 17 15:19:26.944921 2026] [security2:error] [pid 1012520:tid 1012549] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.aws/credentials.bak"] [unique_id "aqxZXgpXMN3p_zkwXf2ZrwAAkhs"]
[Thu Sep 17 15:19:26.961255 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/azure/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZsQAAAMc"]
[Thu Sep 17 15:19:26.987271 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/prod/.env"] [unique_id "aqxZXgpXMN3p_zkwXf2ZswAAAKA"]
[Thu Sep 17 15:19:27.108521 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/src/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZtAAAAL4"]
[Thu Sep 17 15:19:27.127470 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/gcp/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZtQAAAQE"]
[Thu Sep 17 15:19:27.142081 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/dev/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZtwAAAJo"]
[Thu Sep 17 15:19:27.269614 2026] [security2:error] [pid 1012520:tid 1012734] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhAAAANg"]
[Thu Sep 17 15:19:27.278180 2026] [security2:error] [pid 1012520:tid 1012697] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZgQAAALM"]
[Thu Sep 17 15:19:27.281096 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhQAAALY"]
[Thu Sep 17 15:19:27.288501 2026] [security2:error] [pid 1012520:tid 1012670] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZiAAAAJg"]
[Thu Sep 17 15:19:27.297182 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/staging/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZvgAAAKY"]
[Thu Sep 17 15:19:27.301803 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/core/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZvwAAANM"]
[Thu Sep 17 15:19:27.304183 2026] [security2:error] [pid 1012520:tid 1012742] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZiQAAAOA"]
[Thu Sep 17 15:19:27.311491 2026] [security2:error] [pid 1012520:tid 1012738] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhwAAANw"]
[Thu Sep 17 15:19:27.312634 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cloud/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZwAAAAK0"]
[Thu Sep 17 15:19:27.336537 2026] [security2:error] [pid 1012520:tid 1012721] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZhgAAAMs"]
[Thu Sep 17 15:19:27.336537 2026] [security2:error] [pid 1012520:tid 1012741] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZfgAAAN8"]
[Thu Sep 17 15:19:27.408709 2026] [security2:error] [pid 1012520:tid 1012690] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZlQAAAKw"]
[Thu Sep 17 15:19:27.413801 2026] [security2:error] [pid 1012520:tid 1012714] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZrAAAAMQ"]
[Thu Sep 17 15:19:27.413880 2026] [security2:error] [pid 1012520:tid 1012774] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZowAAAQA"]
[Thu Sep 17 15:19:27.416254 2026] [security2:error] [pid 1012520:tid 1012709] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZlwAAAL8"]
[Thu Sep 17 15:19:27.417849 2026] [security2:error] [pid 1012520:tid 1012707] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZlgAAAL0"]
[Thu Sep 17 15:19:27.425801 2026] [security2:error] [pid 1012520:tid 1012682] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2ZvQAAAKQ"]
[Thu Sep 17 15:19:27.434787 2026] [security2:error] [pid 1012520:tid 1012679] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZsgAAAKE"]
[Thu Sep 17 15:19:27.437022 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXgpXMN3p_zkwXf2ZsAAAAME"]
[Thu Sep 17 15:19:27.450612 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/opt/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZxQAAAKI"]
[Thu Sep 17 15:19:27.466188 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/infrastructure/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2ZyQAAAJ8"]
[Thu Sep 17 15:19:27.469847 2026] [security2:error] [pid 1012520:tid 1012527] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.ssh/id_rsa"] [unique_id "aqxZXwpXMN3p_zkwXf2ZywAAkgU"]
[Thu Sep 17 15:19:27.484747 2026] [security2:error] [pid 1012520:tid 1012526] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/id_rsa"] [unique_id "aqxZXwpXMN3p_zkwXf2ZzQAAkgQ"]
[Thu Sep 17 15:19:27.495224 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/core/app/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z0gAAAKc"]
[Thu Sep 17 15:19:27.605344 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/laravel/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z2QAAAIs"]
[Thu Sep 17 15:19:27.614632 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/docker/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z2gAAAJE"]
[Thu Sep 17 15:19:27.616631 2026] [security2:error] [pid 1012520:tid 1012686] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z0AAAAKg"]
[Thu Sep 17 15:19:27.686015 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/config/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z6gAAAI0"]
[Thu Sep 17 15:19:27.766466 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.32.0.94:37438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/symfony/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z7gAAAJo"]
[Thu Sep 17 15:19:27.783621 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/k8s/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8QAAAIU"]
[Thu Sep 17 15:19:27.882963 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.246.241.88:50790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z-AAAAKo"]
[Thu Sep 17 15:19:27.883571 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/private/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z9wAAAPw"]
[Thu Sep 17 15:19:27.940401 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/kubernetes/.env"] [unique_id "aqxZXwpXMN3p_zkwXf2Z-gAAAKM"]
[Thu Sep 17 15:19:27.973634 2026] [security2:error] [pid 1012520:tid 1012732] [client 159.89.175.243:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.175.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lowlandblues.co"] [uri "/wp-login.php"] [unique_id "aqxZXwpXMN3p_zkwXf2aAAAAANY"]
[Thu Sep 17 15:19:28.076044 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/application/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aBQAAALA"]
[Thu Sep 17 15:19:28.126887 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/terraform/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aCAAAAN8"]
[Thu Sep 17 15:19:28.231495 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/wordpress/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aCwAAANM"]
[Thu Sep 17 15:19:28.267416 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/bootstrap/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aDAAAAN4"]
[Thu Sep 17 15:19:28.267647 2026] [security2:error] [pid 1012520:tid 1012698] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2ZzgAAALQ"]
[Thu Sep 17 15:19:28.306006 2026] [security2:error] [pid 1012520:tid 1012752] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1QAAAOo"]
[Thu Sep 17 15:19:28.311870 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1AAAkho"]
[Thu Sep 17 15:19:28.334241 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1wAAknU"]
[Thu Sep 17 15:19:28.336533 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z1gAAkn8"]
[Thu Sep 17 15:19:28.354007 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/ansible/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aDwAAAKE"]
[Thu Sep 17 15:19:28.383503 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/wp/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aEgAAAOI"]
[Thu Sep 17 15:19:28.415863 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z4QAAkjY"]
[Thu Sep 17 15:19:28.421087 2026] [security2:error] [pid 1012520:tid 1012678] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z3gAAAKA"]
[Thu Sep 17 15:19:28.424156 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z2wAAkjQ"]
[Thu Sep 17 15:19:28.427138 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z4gAAkhI"]
[Thu Sep 17 15:19:28.432033 2026] [security2:error] [pid 1012520:tid 1012749] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z7wAAAOc"]
[Thu Sep 17 15:19:28.433411 2026] [security2:error] [pid 1012520:tid 1012654] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8wAAAIg"]
[Thu Sep 17 15:19:28.434912 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z4AAAkic"]
[Thu Sep 17 15:19:28.435087 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z3wAAkhQ"]
[Thu Sep 17 15:19:28.441030 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8gAAkh4"]
[Thu Sep 17 15:19:28.442400 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z5AAAkjo"]
[Thu Sep 17 15:19:28.458252 2026] [security2:error] [pid 1012520:tid 1012735] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZXwpXMN3p_zkwXf2Z8AAAANk"]
[Thu Sep 17 15:19:28.463331 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/database/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aFAAAAKU"]
[Thu Sep 17 15:19:28.529100 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/.git/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aIAAAAPc"]
[Thu Sep 17 15:19:28.534511 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cms/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aIgAAAKc"]
[Thu Sep 17 15:19:28.596651 2026] [deflate:error] [pid 1012520:tid 1012766] (104)Connection reset by peer: [client 34.95.61.66:53606] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:19:28.635813 2026] [security2:error] [pid 1012520:tid 1012577] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config.php"] [unique_id "aqxZYApXMN3p_zkwXf2aNQAA7Tc"]
[Thu Sep 17 15:19:28.655725 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/storage/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aNgAAAOU"]
[Thu Sep 17 15:19:28.689286 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/drupal/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aOAAAALc"]
[Thu Sep 17 15:19:28.786830 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZYApXMN3p_zkwXf2aPQAAAM4"]
[Thu Sep 17 15:19:28.818401 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/ci/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aQQAAAI4"]
[Thu Sep 17 15:19:28.841186 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/joomla/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aRwAAAJ4"]
[Thu Sep 17 15:19:28.853891 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/var/www/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aSgAAAMA"]
[Thu Sep 17 15:19:28.863935 2026] [security2:error] [pid 1012520:tid 1012772] [client 186.105.232.15:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYApXMN3p_zkwXf2aRAAAAP4"]
[Thu Sep 17 15:19:28.864056 2026] [security2:error] [pid 1012520:tid 1012772] [client 186.105.232.15:61120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYApXMN3p_zkwXf2aRAAAAP4"]
[Thu Sep 17 15:19:28.948632 2026] [cgid:error] [pid 1012520:tid 1012725] (32)Broken pipe: [client 34.95.61.66:53610] AH02651: Error writing request body to script /usr/local/cpanel/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:19:28.990721 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/magento/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aTQAAAKY"]
[Thu Sep 17 15:19:28.991553 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cd/.env"] [unique_id "aqxZYApXMN3p_zkwXf2aTgAAAMo"]
[Thu Sep 17 15:19:29.046680 2026] [security2:error] [pid 1012520:tid 1012668] [client 37.139.53.148:60534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pger.net"] [uri "/football/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aAQAAAJY"], referer: http://pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:19:29.047001 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/var/www/html/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aUAAAANw"]
[Thu Sep 17 15:19:29.079335 2026] [deflate:error] [pid 1012520:tid 1012715] (104)Connection reset by peer: [client 34.95.61.66:53610] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:19:29.141090 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/shopify/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aUQAAAQM"]
[Thu Sep 17 15:19:29.152576 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/jenkins/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aUgAAAPI"]
[Thu Sep 17 15:19:29.243795 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/current/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aVAAAAOs"]
[Thu Sep 17 15:19:29.258016 2026] [security2:error] [pid 1012520:tid 1012721] [client 186.22.253.1:33082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aUwAAyyw"], referer: https://www.bing.com/
[Thu Sep 17 15:19:29.293737 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/prestashop/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aVQAAANs"]
[Thu Sep 17 15:19:29.333405 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/gitlab/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aVwAAAIk"]
[Thu Sep 17 15:19:29.370353 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aHQAA7S4"]
[Thu Sep 17 15:19:29.377467 2026] [security2:error] [pid 1012520:tid 1012666] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aIQAAAJQ"]
[Thu Sep 17 15:19:29.378848 2026] [security2:error] [pid 1012520:tid 1012733] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aIwAAANc"]
[Thu Sep 17 15:19:29.381821 2026] [security2:error] [pid 1012520:tid 1012759] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aJAAAAPE"]
[Thu Sep 17 15:19:29.424583 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aMwAA7UE"]
[Thu Sep 17 15:19:29.426914 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aLQAA7TM"]
[Thu Sep 17 15:19:29.426960 2026] [security2:error] [pid 1012520:tid 1012669] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aJgAAAJc"]
[Thu Sep 17 15:19:29.438186 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/release/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aXwAAAQA"]
[Thu Sep 17 15:19:29.455259 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/codeigniter/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aYAAAAOo"]
[Thu Sep 17 15:19:29.519934 2026] [security2:error] [pid 1012520:tid 1012740] [client 45.169.98.18:50291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aYgAAAN4"]
[Thu Sep 17 15:19:29.520032 2026] [security2:error] [pid 1012520:tid 1012740] [client 45.169.98.18:50291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aYgAAAN4"]
[Thu Sep 17 15:19:29.534978 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/github/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aYwAAALw"]
[Thu Sep 17 15:19:29.547596 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aZAAAAOc"]
[Thu Sep 17 15:19:29.613952 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cakephp/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aaQAAAQI"]
[Thu Sep 17 15:19:29.631768 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/releases/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2abAAAAJM"]
[Thu Sep 17 15:19:29.734307 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.246.241.88:50816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZYQpXMN3p_zkwXf2afAAAAMc"]
[Thu Sep 17 15:19:29.770117 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/zend/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2afQAAAPc"]
[Thu Sep 17 15:19:29.776949 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/actions/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2afgAAAKc"]
[Thu Sep 17 15:19:29.822896 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/shared/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2ahAAAAJE"]
[Thu Sep 17 15:19:29.922423 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/yii/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aiQAAAQE"]
[Thu Sep 17 15:19:29.925500 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/circleci/.env"] [unique_id "aqxZYQpXMN3p_zkwXf2aigAAAM4"]
[Thu Sep 17 15:19:30.022712 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/deploy/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2ajQAAAJ4"]
[Thu Sep 17 15:19:30.076470 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/laravel5/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2akQAAAKk"]
[Thu Sep 17 15:19:30.116798 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/travis/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2akgAAAOQ"]
[Thu Sep 17 15:19:30.156461 2026] [security2:error] [pid 1012520:tid 1012716] [client 66.96.214.58:38664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aXgAAAMY"]
[Thu Sep 17 15:19:30.220808 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/build/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2alwAAAIY"]
[Thu Sep 17 15:19:30.229700 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxZYgpXMN3p_zkwXf2amAAAAJo"]
[Thu Sep 17 15:19:30.232884 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/v1/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2amQAAAMk"]
[Thu Sep 17 15:19:30.257563 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aSQAAALY"]
[Thu Sep 17 15:19:30.257618 2026] [security2:error] [pid 1012520:tid 1012708] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aOgAAAL4"]
[Thu Sep 17 15:19:30.257806 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aMgAA7S0"]
[Thu Sep 17 15:19:30.257962 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aLgAA7Uw"]
[Thu Sep 17 15:19:30.257980 2026] [security2:error] [pid 1012520:tid 1012659] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aOQAAAI0"]
[Thu Sep 17 15:19:30.281491 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aNwAA7UA"]
[Thu Sep 17 15:19:30.283241 2026] [security2:error] [pid 1012520:tid 1012712] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aOwAAAMI"]
[Thu Sep 17 15:19:30.284151 2026] [security2:error] [pid 1012520:tid 1012651] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aPAAAAIU"]
[Thu Sep 17 15:19:30.296090 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/buildkite/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2amgAAAOk"]
[Thu Sep 17 15:19:30.304713 2026] [security2:error] [pid 1012520:tid 1012688] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYApXMN3p_zkwXf2aPgAAAKo"]
[Thu Sep 17 15:19:30.312458 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxZYgpXMN3p_zkwXf2amwAAALk"]
[Thu Sep 17 15:19:30.386495 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/v2/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2aoAAAAJw"]
[Thu Sep 17 15:19:30.405617 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aeQAAANA"]
[Thu Sep 17 15:19:30.405617 2026] [security2:error] [pid 1012520:tid 1012680] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aawAAAKI"]
[Thu Sep 17 15:19:30.407274 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2adwAAAMM"]
[Thu Sep 17 15:19:30.408035 2026] [security2:error] [pid 1012520:tid 1012696] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2alQAAALI"]
[Thu Sep 17 15:19:30.408620 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aZwAA7VU"]
[Thu Sep 17 15:19:30.410168 2026] [security2:error] [pid 1012520:tid 1012683] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2adAAAAKU"]
[Thu Sep 17 15:19:30.410869 2026] [security2:error] [pid 1012520:tid 1012664] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYQpXMN3p_zkwXf2aegAAAJI"]
[Thu Sep 17 15:19:30.415322 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/dist/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2aowAAAN0"]
[Thu Sep 17 15:19:30.458855 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxZYgpXMN3p_zkwXf2apAAAAIo"]
[Thu Sep 17 15:19:30.491711 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mysql/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2apgAAAMw"]
[Thu Sep 17 15:19:30.528242 2026] [security2:error] [pid 1012520:tid 1012744] [client 37.139.53.148:60720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pger.net"] [uri "/wp-login.php"] [unique_id "aqxZYgpXMN3p_zkwXf2apQAAAOI"], referer: http://www.pger.net/wp-login.php?action=register
[Thu Sep 17 15:19:30.530723 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.246.241.88:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZYgpXMN3p_zkwXf2apwAAAMs"]
[Thu Sep 17 15:19:30.539386 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/v3/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2aqQAAAOc"]
[Thu Sep 17 15:19:30.578656 2026] [security2:error] [pid 1012520:tid 1012736] [client 103.61.184.148:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYgpXMN3p_zkwXf2aqwAAANo"]
[Thu Sep 17 15:19:30.578778 2026] [security2:error] [pid 1012520:tid 1012736] [client 103.61.184.148:57642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZYgpXMN3p_zkwXf2aqwAAANo"]
[Thu Sep 17 15:19:30.604681 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/public_html/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2arQAAALQ"]
[Thu Sep 17 15:19:30.658522 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/postgres/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2arwAAAQI"]
[Thu Sep 17 15:19:30.693125 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/v1/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2asAAAAMQ"]
[Thu Sep 17 15:19:30.810522 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/htdocs/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2atQAAAJE"]
[Thu Sep 17 15:19:30.846458 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/v2/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2atgAAALs"]
[Thu Sep 17 15:19:30.847388 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mongodb/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2atwAAALc"]
[Thu Sep 17 15:19:30.852478 2026] [security2:error] [pid 1012520:tid 1012565] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/aws.php"] [unique_id "aqxZYgpXMN3p_zkwXf2auwABASs"]
[Thu Sep 17 15:19:30.852502 2026] [security2:error] [pid 1012520:tid 1012609] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/stripe.php"] [unique_id "aqxZYgpXMN3p_zkwXf2avQABAVc"]
[Thu Sep 17 15:19:30.853939 2026] [security2:error] [pid 1012520:tid 1012622] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/mail.php"] [unique_id "aqxZYgpXMN3p_zkwXf2avwABAWQ"]
[Thu Sep 17 15:19:30.864428 2026] [security2:error] [pid 1012520:tid 1012644] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/nexmo.php"] [unique_id "aqxZYgpXMN3p_zkwXf2axwABAXo"]
[Thu Sep 17 15:19:30.864494 2026] [security2:error] [pid 1012520:tid 1012624] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/config/config.inc.php"] [unique_id "aqxZYgpXMN3p_zkwXf2axQABAWY"]
[Thu Sep 17 15:19:30.888328 2026] [security2:error] [pid 1012520:tid 1012633] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php.bak"] [unique_id "aqxZYgpXMN3p_zkwXf2aywABAW8"]
[Thu Sep 17 15:19:30.888328 2026] [security2:error] [pid 1012520:tid 1012616] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php.old"] [unique_id "aqxZYgpXMN3p_zkwXf2azAABAV4"]
[Thu Sep 17 15:19:30.888801 2026] [security2:error] [pid 1012520:tid 1012637] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php"] [unique_id "aqxZYgpXMN3p_zkwXf2azQABAXM"]
[Thu Sep 17 15:19:30.977139 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2augABAS8"]
[Thu Sep 17 15:19:30.977259 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2avAABAUI"]
[Thu Sep 17 15:19:30.982329 2026] [security2:error] [pid 1012520:tid 1012655] [client 186.22.253.1:33037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a0QAAiXE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818122733&hideanons=1&limit=250&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:19:30.999233 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/rest/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2a2gAAAKY"]
[Thu Sep 17 15:19:31.001219 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/www/.env"] [unique_id "aqxZYgpXMN3p_zkwXf2a2wAAALY"]
[Thu Sep 17 15:19:31.031403 2026] [security2:error] [pid 1012520:tid 1012619] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "impact100sydneynorth.org"] [uri "/wp-config.php.new"] [unique_id "aqxZYwpXMN3p_zkwXf2a3QABAWE"]
[Thu Sep 17 15:19:31.031924 2026] [security2:error] [pid 1012520:tid 1012544] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/.wp-config.php.swp"] [unique_id "aqxZYwpXMN3p_zkwXf2a3AABARY"]
[Thu Sep 17 15:19:31.044858 2026] [security2:error] [pid 1012520:tid 1012597] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/wp-content/mysql.sql"] [unique_id "aqxZYwpXMN3p_zkwXf2a4gABAUs"]
[Thu Sep 17 15:19:31.070993 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:50830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxZYwpXMN3p_zkwXf2a5wAAAJs"]
[Thu Sep 17 15:19:31.120612 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/redis/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a6QAAAJY"]
[Thu Sep 17 15:19:31.152739 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/graphql/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a6wAAAK0"]
[Thu Sep 17 15:19:31.188128 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/html/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a8AAAAIU"]
[Thu Sep 17 15:19:31.273198 2026] [security2:error] [pid 1012520:tid 1012716] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a0wAAAMY"]
[Thu Sep 17 15:19:31.275596 2026] [security2:error] [pid 1012520:tid 1012667] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a1gAAAJU"]
[Thu Sep 17 15:19:31.276380 2026] [security2:error] [pid 1012520:tid 1012725] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a1wAAAM8"]
[Thu Sep 17 15:19:31.288793 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a8wAAAPk"]
[Thu Sep 17 15:19:31.288894 2026] [security2:error] [pid 1012520:tid 1012746] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a1QAAAOQ"]
[Thu Sep 17 15:19:31.304756 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/gateway/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a9QAAAQM"]
[Thu Sep 17 15:19:31.310855 2026] [security2:error] [pid 1012520:tid 1012652] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYgpXMN3p_zkwXf2a2AAAAIY"]
[Thu Sep 17 15:19:31.360252 2026] [security2:error] [pid 1012520:tid 1012659] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a4AAAAI0"]
[Thu Sep 17 15:19:31.363676 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a4QABAVY"]
[Thu Sep 17 15:19:31.379323 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a5QABAWc"]
[Thu Sep 17 15:19:31.380213 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/live/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a-gAAAK4"]
[Thu Sep 17 15:19:31.380704 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a5gABAXw"]
[Thu Sep 17 15:19:31.381937 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a5AABAWI"]
[Thu Sep 17 15:19:31.400325 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a7gABAXY"]
[Thu Sep 17 15:19:31.403085 2026] [security2:error] [pid 1012520:tid 1012738] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a7wAAANw"]
[Thu Sep 17 15:19:31.412693 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2a7QABAQA"]
[Thu Sep 17 15:19:31.442982 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a-wAAAKU"]
[Thu Sep 17 15:19:31.459019 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/microservice/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2a_AAAAOo"]
[Thu Sep 17 15:19:31.460391 2026] [security2:error] [pid 1012520:tid 1012626] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/terraform.tfstate.backup"] [unique_id "aqxZYwpXMN3p_zkwXf2a_wABAWg"]
[Thu Sep 17 15:19:31.541459 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxZYwpXMN3p_zkwXf2bBgAAAN0"]
[Thu Sep 17 15:19:31.569960 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/prod/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bBwAAAM0"]
[Thu Sep 17 15:19:31.602107 2026] [security2:error] [pid 1012520:tid 1012682] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bBAAAAKQ"]
[Thu Sep 17 15:19:31.610989 2026] [security2:error] [pid 1012520:tid 1012762] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bBQAAAPQ"]
[Thu Sep 17 15:19:31.613960 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/service/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bCAAAAOg"]
[Thu Sep 17 15:19:31.625596 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/kafka/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bCQAAAKE"]
[Thu Sep 17 15:19:31.626073 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.env~"] [unique_id "aqxZYwpXMN3p_zkwXf2bCgAAAIo"]
[Thu Sep 17 15:19:31.759881 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/dev/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bDAAAAOY"]
[Thu Sep 17 15:19:31.768608 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/v3/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bDQAAAJ0"]
[Thu Sep 17 15:19:31.783862 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/queue/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bDgAAAJM"]
[Thu Sep 17 15:19:31.921188 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/dev/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bOAAAAJA"]
[Thu Sep 17 15:19:31.954803 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/staging/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bPAAAALA"]
[Thu Sep 17 15:19:31.960670 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/worker/.env"] [unique_id "aqxZYwpXMN3p_zkwXf2bPQAAAJY"]
[Thu Sep 17 15:19:31.965052 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.246.241.88:50840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php.old"] [unique_id "aqxZYwpXMN3p_zkwXf2bPgAAAK8"]
[Thu Sep 17 15:19:32.079443 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/api/staging/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bQAAAAOw"]
[Thu Sep 17 15:19:32.144754 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/job/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bRAAAAPw"]
[Thu Sep 17 15:19:32.149790 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/opt/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bRQAAALM"]
[Thu Sep 17 15:19:32.195303 2026] [security2:error] [pid 1012520:tid 1012698] [client 154.190.208.131:42177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bSgAAALQ"]
[Thu Sep 17 15:19:32.196607 2026] [security2:error] [pid 1012520:tid 1012698] [client 154.190.208.131:42177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bSgAAALQ"]
[Thu Sep 17 15:19:32.234166 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/vendor/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bSwAAAMY"]
[Thu Sep 17 15:19:32.297276 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bFgAA_hk"]
[Thu Sep 17 15:19:32.308375 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/test/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bTgAAAQM"]
[Thu Sep 17 15:19:32.320767 2026] [security2:error] [pid 1012520:tid 1012523] [remote 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bEAAA_gE"]
[Thu Sep 17 15:19:32.323762 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bEQAA_mA"]
[Thu Sep 17 15:19:32.326159 2026] [security2:error] [pid 1012520:tid 1012638] [remote 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bJwAA_nQ"]
[Thu Sep 17 15:19:32.327296 2026] [security2:error] [pid 1012520:tid 1012711] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bLAAAAME"]
[Thu Sep 17 15:19:32.335872 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bUQAAAI0"]
[Thu Sep 17 15:19:32.340074 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/laravel/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bUgAAAJ4"]
[Thu Sep 17 15:19:32.342032 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bLQAAALs"]
[Thu Sep 17 15:19:32.346098 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bGwAA_ns"]
[Thu Sep 17 15:19:32.354777 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bFwAA_gk"]
[Thu Sep 17 15:19:32.390497 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/lib/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bVQAAAMA"]
[Thu Sep 17 15:19:32.413728 2026] [security2:error] [pid 1012520:tid 1012745] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bLgAAAOM"]
[Thu Sep 17 15:19:32.416652 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bVwAAANA"]
[Thu Sep 17 15:19:32.418997 2026] [security2:error] [pid 1012520:tid 1012673] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bNgAAAJs"]
[Thu Sep 17 15:19:32.422531 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bMgAAALY"]
[Thu Sep 17 15:19:32.422535 2026] [security2:error] [pid 1012520:tid 1012719] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bMQAAAMk"]
[Thu Sep 17 15:19:32.422558 2026] [security2:error] [pid 1012520:tid 1012672] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bNwAAAJo"]
[Thu Sep 17 15:19:32.422566 2026] [security2:error] [pid 1012520:tid 1012720] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bNAAAAMo"]
[Thu Sep 17 15:19:32.423113 2026] [security2:error] [pid 1012520:tid 1012655] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bMwAAAIk"]
[Thu Sep 17 15:19:32.436378 2026] [security2:error] [pid 1012520:tid 1012727] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZYwpXMN3p_zkwXf2bOQAAANE"]
[Thu Sep 17 15:19:32.461507 2026] [security2:error] [pid 1012520:tid 1012715] [client 185.55.149.49:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bWAAAAMU"]
[Thu Sep 17 15:19:32.461589 2026] [security2:error] [pid 1012520:tid 1012715] [client 185.55.149.49:60072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZZApXMN3p_zkwXf2bWAAAAMU"]
[Thu Sep 17 15:19:32.522858 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bYAAAAN0"]
[Thu Sep 17 15:19:32.532602 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:45444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/symfony/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bYwAAAM0"]
[Thu Sep 17 15:19:32.548107 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/resources/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bZgAAAPQ"]
[Thu Sep 17 15:19:32.563772 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/qa/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bZwAAAOg"]
[Thu Sep 17 15:19:32.627370 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bagAAALU"]
[Thu Sep 17 15:19:32.701806 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/assets/.env"] [unique_id "aqxZZApXMN3p_zkwXf2begAAAJk"]
[Thu Sep 17 15:19:32.712242 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bewAAAOc"]
[Thu Sep 17 15:19:32.746506 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.246.241.88:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php~"] [unique_id "aqxZZApXMN3p_zkwXf2bgAAAANk"]
[Thu Sep 17 15:19:32.787341 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bgwAAAIw"]
[Thu Sep 17 15:19:32.846823 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/preview/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bhAAAAJY"]
[Thu Sep 17 15:19:32.860701 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/uploads/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bhQAAAK8"]
[Thu Sep 17 15:19:32.998888 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxZZApXMN3p_zkwXf2bjgAAALM"]
[Thu Sep 17 15:19:33.016280 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/internal/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bjwAAAKg"]
[Thu Sep 17 15:19:33.085753 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wordpress/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkAAAAKk"]
[Thu Sep 17 15:19:33.096316 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkQAAALQ"]
[Thu Sep 17 15:19:33.110432 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/beta/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkgAAAMY"]
[Thu Sep 17 15:19:33.177432 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/tools/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bkwAAAJU"]
[Thu Sep 17 15:19:33.262307 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2blQAAAM8"]
[Thu Sep 17 15:19:33.273574 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2blgAAAOQ"]
[Thu Sep 17 15:19:33.324438 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/uat/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bmAAAAPs"]
[Thu Sep 17 15:19:33.331288 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/scripts/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bmQAAAOk"]
[Thu Sep 17 15:19:33.368613 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bmwAAAIY"]
[Thu Sep 17 15:19:33.378949 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bXAAA_hE"]
[Thu Sep 17 15:19:33.414819 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bXgAA_h0"]
[Thu Sep 17 15:19:33.418384 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bXwAA_g8"]
[Thu Sep 17 15:19:33.459639 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cms/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bngAAAP8"]
[Thu Sep 17 15:19:33.467131 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.246.241.88:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/info.php.bak"] [unique_id "aqxZZQpXMN3p_zkwXf2bnwAAAQM"]
[Thu Sep 17 15:19:33.468493 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2boAAAANg"]
[Thu Sep 17 15:19:33.483221 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/bin/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2boQAAAM4"]
[Thu Sep 17 15:19:33.517112 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/stage/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bogAAAJQ"]
[Thu Sep 17 15:19:33.547376 2026] [security2:error] [pid 1012520:tid 1012684] [client 172.239.147.162:63422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bhgAAAKY"], referer: binance.com
[Thu Sep 17 15:19:33.578141 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bpgAAANQ"]
[Thu Sep 17 15:19:33.635431 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sbin/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2brwAAAPE"]
[Thu Sep 17 15:19:33.640371 2026] [security2:error] [pid 1012520:tid 1012696] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/drupal/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bsAAAALI"]
[Thu Sep 17 15:19:33.661121 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bswAAAK4"]
[Thu Sep 17 15:19:33.668997 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/development/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2btAAAAIs"]
[Thu Sep 17 15:19:33.730964 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2btgAAAL8"]
[Thu Sep 17 15:19:33.793728 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/local/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2btwAAAKU"]
[Thu Sep 17 15:19:33.821615 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/joomla/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2buAAAAMU"]
[Thu Sep 17 15:19:33.823473 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2buQAAAJI"]
[Thu Sep 17 15:19:33.841866 2026] [security2:error] [pid 1012520:tid 1012685] [client 114.198.138.124:58019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZQpXMN3p_zkwXf2bvAAAAKc"]
[Thu Sep 17 15:19:33.841953 2026] [security2:error] [pid 1012520:tid 1012685] [client 114.198.138.124:58019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZZQpXMN3p_zkwXf2bvAAAAKc"]
[Thu Sep 17 15:19:33.856988 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/production/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bvQAAAJE"]
[Thu Sep 17 15:19:33.921382 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bvwAAAPg"]
[Thu Sep 17 15:19:33.948367 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/portal/.env"] [unique_id "aqxZZQpXMN3p_zkwXf2bwAAAALE"]
[Thu Sep 17 15:19:34.004817 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bwQAAAN0"]
[Thu Sep 17 15:19:34.009336 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/magento/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bwgAAAM0"]
[Thu Sep 17 15:19:34.031195 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.204.169.220:43534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.hopmanchaissconsulting.com"] [uri "/config/app/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bwwAAAQQ"]
[Thu Sep 17 15:19:34.074992 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bxAAAANM"]
[Thu Sep 17 15:19:34.100274 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/dashboard/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bxwAAAIc"]
[Thu Sep 17 15:19:34.153018 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2byQAAAIg"]
[Thu Sep 17 15:19:34.193276 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/shopify/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bygAAAN4"]
[Thu Sep 17 15:19:34.208976 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.204.169.220:43534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2bywAAAOE"]
[Thu Sep 17 15:19:34.254793 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/panel/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bzAAAAOc"]
[Thu Sep 17 15:19:34.257629 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bYQAA_hU"]
[Thu Sep 17 15:19:34.260252 2026] [security2:error] [pid 1012520:tid 1012656] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bawAAAIo"]
[Thu Sep 17 15:19:34.262987 2026] [security2:error] [pid 1012520:tid 1012675] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfQAAAJ0"]
[Thu Sep 17 15:19:34.263925 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bbAAA_l8"]
[Thu Sep 17 15:19:34.263944 2026] [security2:error] [pid 1012520:tid 1012553] [remote 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bZQAA_h8"]
[Thu Sep 17 15:19:34.264074 2026] [security2:error] [pid 1012520:tid 1012758] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bgQAAAPA"]
[Thu Sep 17 15:19:34.264345 2026] [security2:error] [pid 1012520:tid 1012679] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2baQAAAKE"]
[Thu Sep 17 15:19:34.265909 2026] [security2:error] [pid 1012520:tid 1012748] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfgAAAOY"]
[Thu Sep 17 15:19:34.267149 2026] [security2:error] [pid 1012520:tid 1012755] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2baAAAAO0"]
[Thu Sep 17 15:19:34.272014 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2bzQAAALw"]
[Thu Sep 17 15:19:34.273936 2026] [security2:error] [pid 1012520:tid 1012763] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfAAAAPU"]
[Thu Sep 17 15:19:34.279088 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bcQAA_jE"]
[Thu Sep 17 15:19:34.283280 2026] [security2:error] [pid 1012520:tid 1012665] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bfwAAAJM"]
[Thu Sep 17 15:19:34.304745 2026] [security2:error] [pid 1012520:tid 1012772] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZApXMN3p_zkwXf2bbQAA_g0"]
[Thu Sep 17 15:19:34.356296 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b0gAAAKs"]
[Thu Sep 17 15:19:34.374328 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/prestashop/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b1AAAALQ"]
[Thu Sep 17 15:19:34.385260 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZQpXMN3p_zkwXf2bpwAAALY"]
[Thu Sep 17 15:19:34.386721 2026] [security2:error] [pid 1012520:tid 1012727] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZQpXMN3p_zkwXf2brgAAANE"]
[Thu Sep 17 15:19:34.387739 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZQpXMN3p_zkwXf2brQAAAMM"]
[Thu Sep 17 15:19:34.409964 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/crm/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b1QAAAPs"]
[Thu Sep 17 15:19:34.445720 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b1gAAAI0"]
[Thu Sep 17 15:19:34.535543 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b6wAAALk"]
[Thu Sep 17 15:19:34.555458 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/codeigniter/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b7AAAALs"]
[Thu Sep 17 15:19:34.563216 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/erp/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b7QAAAMo"]
[Thu Sep 17 15:19:34.599257 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.246.241.88:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/phpinfo.php.save"] [unique_id "aqxZZgpXMN3p_zkwXf2b7gAAAOk"]
[Thu Sep 17 15:19:34.600184 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b3AAA6zc"]
[Thu Sep 17 15:19:34.608229 2026] [security2:error] [pid 1012520:tid 1012745] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b5wAAAOM"]
[Thu Sep 17 15:19:34.608915 2026] [security2:error] [pid 1012520:tid 1012666] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b5gAAAJQ"]
[Thu Sep 17 15:19:34.609104 2026] [security2:error] [pid 1012520:tid 1012726] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b6AAAANA"]
[Thu Sep 17 15:19:34.621237 2026] [security2:error] [pid 1012520:tid 1012710] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b5QAAAMA"]
[Thu Sep 17 15:19:34.626351 2026] [security2:error] [pid 1012520:tid 1012684] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b6QAAAKY"]
[Thu Sep 17 15:19:34.649175 2026] [security2:error] [pid 1012520:tid 1012613] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b9gAA61s"]
[Thu Sep 17 15:19:34.649218 2026] [security2:error] [pid 1012520:tid 1012563] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b-AAA6yk"]
[Thu Sep 17 15:19:34.649305 2026] [security2:error] [pid 1012520:tid 1012564] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/infos.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b-QAA6yo"]
[Thu Sep 17 15:19:34.649910 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b-gAAAJI"]
[Thu Sep 17 15:19:34.651882 2026] [security2:error] [pid 1012520:tid 1012730] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b6gAAANQ"]
[Thu Sep 17 15:19:34.717034 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/shop/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2b_wAAAM0"]
[Thu Sep 17 15:19:34.728267 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cAAAAAQQ"]
[Thu Sep 17 15:19:34.741224 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cakephp/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cAgAAAMc"]
[Thu Sep 17 15:19:34.750201 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b8QAA6zw"]
[Thu Sep 17 15:19:34.782908 2026] [security2:error] [pid 1012520:tid 1012636] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/php_info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cBAAA63I"]
[Thu Sep 17 15:19:34.797693 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cBQAAAPc"]
[Thu Sep 17 15:19:34.825655 2026] [security2:error] [pid 1012520:tid 1012695] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2b_gAAALE"]
[Thu Sep 17 15:19:34.828443 2026] [security2:error] [pid 1012520:tid 1012596] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/php.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cCgAA60o"]
[Thu Sep 17 15:19:34.828470 2026] [security2:error] [pid 1012520:tid 1012604] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/php-info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cCwAA61I"]
[Thu Sep 17 15:19:34.829147 2026] [security2:error] [pid 1012520:tid 1012606] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/infophp.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cDAAA61Q"]
[Thu Sep 17 15:19:34.830675 2026] [security2:error] [pid 1012520:tid 1012603] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cDgAA61E"]
[Thu Sep 17 15:19:34.832194 2026] [security2:error] [pid 1012520:tid 1012610] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cDwAA61g"]
[Thu Sep 17 15:19:34.832252 2026] [security2:error] [pid 1012520:tid 1012611] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/admin_phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cEAAA61k"]
[Thu Sep 17 15:19:34.832278 2026] [security2:error] [pid 1012520:tid 1012567] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/api/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cEQAA6y0"]
[Thu Sep 17 15:19:34.860535 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.204.169.220:41684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/info.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cFQAAAMQ"]
[Thu Sep 17 15:19:34.862943 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cFgAAAN4"]
[Thu Sep 17 15:19:34.870514 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/store/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cFwAAAOc"]
[Thu Sep 17 15:19:34.879101 2026] [security2:error] [pid 1012520:tid 1012589] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/public/phpinfo.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cGQAA60M"]
[Thu Sep 17 15:19:34.925453 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/zend/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cGwAAAJ0"]
[Thu Sep 17 15:19:34.949870 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxZZgpXMN3p_zkwXf2cHgAAAKE"]
[Thu Sep 17 15:19:35.016797 2026] [security2:error] [pid 1012520:tid 1012599] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/database.sql"] [unique_id "aqxZZwpXMN3p_zkwXf2cKAAA600"]
[Thu Sep 17 15:19:35.024985 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/saas/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cMAAAANs"]
[Thu Sep 17 15:19:35.032212 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cMQAAAKQ"]
[Thu Sep 17 15:19:35.109932 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/yii/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cOwAAAJM"]
[Thu Sep 17 15:19:35.154762 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cQAAAAKM"]
[Thu Sep 17 15:19:35.178145 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/client/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cQQAAANI"]
[Thu Sep 17 15:19:35.257194 2026] [security2:error] [pid 1012520:tid 1012718] [client 172.239.147.162:51980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gennarosalamone.com"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPwAAAMg"], referer: binance.com
[Thu Sep 17 15:19:35.259473 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cRgAAAPw"]
[Thu Sep 17 15:19:35.300374 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/laravel5/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cSAAAAJs"]
[Thu Sep 17 15:19:35.302737 2026] [security2:error] [pid 1012520:tid 1012752] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cAwAAAOo"]
[Thu Sep 17 15:19:35.332674 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/project/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cSgAAAPs"]
[Thu Sep 17 15:19:35.349869 2026] [security2:error] [pid 1012520:tid 1012750] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cBwAAAOg"]
[Thu Sep 17 15:19:35.357601 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cSwAAAIY"]
[Thu Sep 17 15:19:35.357964 2026] [security2:error] [pid 1012520:tid 1012739] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cBgAAAN0"]
[Thu Sep 17 15:19:35.369997 2026] [security2:error] [pid 1012520:tid 1012729] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cCQAAANM"]
[Thu Sep 17 15:19:35.428472 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cNQAAAK8"]
[Thu Sep 17 15:19:35.429109 2026] [security2:error] [pid 1012520:tid 1012697] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPAAAALM"]
[Thu Sep 17 15:19:35.430962 2026] [security2:error] [pid 1012520:tid 1012669] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cMwAAAJc"]
[Thu Sep 17 15:19:35.431046 2026] [security2:error] [pid 1012520:tid 1012735] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cNAAAANk"]
[Thu Sep 17 15:19:35.434400 2026] [security2:error] [pid 1012520:tid 1012775] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cOgAAAQE"]
[Thu Sep 17 15:19:35.436781 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cTwAAAM4"]
[Thu Sep 17 15:19:35.466729 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.204.169.220:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/php.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cUQAAANc"]
[Thu Sep 17 15:19:35.482773 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/v1/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cUwAAAMU"]
[Thu Sep 17 15:19:35.483189 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/admin-panel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cVAAAAJI"]
[Thu Sep 17 15:19:35.506519 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cVwAAAN8"]
[Thu Sep 17 15:19:35.599111 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cZAAAAN4"]
[Thu Sep 17 15:19:35.638586 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/control-panel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2ccQAAALA"]
[Thu Sep 17 15:19:35.645305 2026] [security2:error] [pid 1012520:tid 1012619] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "impact100sydneynorth.org"] [uri "/settings.php"] [unique_id "aqxZZwpXMN3p_zkwXf2ccgAA62E"]
[Thu Sep 17 15:19:35.668348 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/v2/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cdQAAAPY"]
[Thu Sep 17 15:19:35.688454 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cegAAANI"]
[Thu Sep 17 15:19:35.773458 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.246.241.88:35504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cfQAAAP4"]
[Thu Sep 17 15:19:35.787140 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cfgAAAMg"]
[Thu Sep 17 15:19:35.792495 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/user-panel/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cfwAAAJU"]
[Thu Sep 17 15:19:35.832177 2026] [security2:error] [pid 1012520:tid 1012597] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/public-api/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cgAAA60s"]
[Thu Sep 17 15:19:35.854055 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/v3/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cgwAAAOo"]
[Thu Sep 17 15:19:35.872327 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2chQAAAPo"]
[Thu Sep 17 15:19:35.950416 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/node/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2ciQAAAIY"]
[Thu Sep 17 15:19:35.953476 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxZZwpXMN3p_zkwXf2cigAAAJk"]
[Thu Sep 17 15:19:36.041606 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/v1/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cjQAAAJg"]
[Thu Sep 17 15:19:36.057301 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cjgAAANM"]
[Thu Sep 17 15:19:36.106086 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/express/.env"] [unique_id "aqxZaApXMN3p_zkwXf2ckAAAAJo"]
[Thu Sep 17 15:19:36.164488 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxZaApXMN3p_zkwXf2ckQAAAK8"]
[Thu Sep 17 15:19:36.175315 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.204.169.220:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/i.php"] [unique_id "aqxZaApXMN3p_zkwXf2ckgAAAN0"]
[Thu Sep 17 15:19:36.227565 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/v2/.env"] [unique_id "aqxZaApXMN3p_zkwXf2ckwAAANk"]
[Thu Sep 17 15:19:36.251522 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.95.61.66:53622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxZaApXMN3p_zkwXf2clAAAAJc"]
[Thu Sep 17 15:19:36.256650 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/next/.env"] [unique_id "aqxZaApXMN3p_zkwXf2clQAAAOM"]
[Thu Sep 17 15:19:36.257406 2026] [security2:error] [pid 1012520:tid 1012743] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZgpXMN3p_zkwXf2cGAAAAOE"]
[Thu Sep 17 15:19:36.258779 2026] [security2:error] [pid 1012520:tid 1012686] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPQAAAKg"]
[Thu Sep 17 15:19:36.260586 2026] [security2:error] [pid 1012520:tid 1012732] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cOQAAANY"]
[Thu Sep 17 15:19:36.263013 2026] [security2:error] [pid 1012520:tid 1012700] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cRAAAALY"]
[Thu Sep 17 15:19:36.268258 2026] [security2:error] [pid 1012520:tid 1012760] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cPgAAAPI"]
[Thu Sep 17 15:19:36.283812 2026] [security2:error] [pid 1012520:tid 1012706] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cOAAAALw"]
[Thu Sep 17 15:19:36.408574 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/nuxt/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cmQAAAIw"]
[Thu Sep 17 15:19:36.410316 2026] [security2:error] [pid 1012520:tid 1012681] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cewAAAKM"]
[Thu Sep 17 15:19:36.411323 2026] [security2:error] [pid 1012520:tid 1012665] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2ceAAAAJM"]
[Thu Sep 17 15:19:36.411620 2026] [security2:error] [pid 1012520:tid 1012608] [remote 110.249.201.132:33024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/"] [unique_id "aqxZaApXMN3p_zkwXf2cmgAAs1Y"]
[Thu Sep 17 15:19:36.412008 2026] [security2:error] [pid 1012520:tid 1012763] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cdAAAAPU"]
[Thu Sep 17 15:19:36.412234 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cYgAA62Q"]
[Thu Sep 17 15:19:36.412713 2026] [security2:error] [pid 1012520:tid 1012753] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cYAAA61c"]
[Thu Sep 17 15:19:36.412749 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/rest/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cmwAAAI8"]
[Thu Sep 17 15:19:36.413143 2026] [security2:error] [pid 1012520:tid 1012731] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cWQAAANU"]
[Thu Sep 17 15:19:36.414765 2026] [security2:error] [pid 1012520:tid 1012761] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cdgAAAPM"]
[Thu Sep 17 15:19:36.414813 2026] [security2:error] [pid 1012520:tid 1012757] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2ccwAAAO8"]
[Thu Sep 17 15:19:36.415671 2026] [security2:error] [pid 1012520:tid 1012688] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZZwpXMN3p_zkwXf2cYQAAAKo"]
[Thu Sep 17 15:19:36.420410 2026] [security2:error] [pid 1012520:tid 1012709] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cjwAAAL8"]
[Thu Sep 17 15:19:36.564837 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cnQAAAIg"]
[Thu Sep 17 15:19:36.564987 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/nest/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cngAAAJE"]
[Thu Sep 17 15:19:36.598240 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/graphql/.env"] [unique_id "aqxZaApXMN3p_zkwXf2coAAAAN4"]
[Thu Sep 17 15:19:36.639268 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxZaApXMN3p_zkwXf2coQAAALA"]
[Thu Sep 17 15:19:36.721337 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/react/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cogAAALQ"]
[Thu Sep 17 15:19:36.734934 2026] [security2:error] [pid 1012520:tid 1012630] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/nextjs-app/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cqwAAw2w"]
[Thu Sep 17 15:19:36.735001 2026] [security2:error] [pid 1012520:tid 1012522] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/web.config.old"] [unique_id "aqxZaApXMN3p_zkwXf2cqQAAwwA"]
[Thu Sep 17 15:19:36.735085 2026] [security2:error] [pid 1012520:tid 1012623] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.htpasswd.bak"] [unique_id "aqxZaApXMN3p_zkwXf2cpAAAw2U"]
[Thu Sep 17 15:19:36.747299 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cvgAAAJs"]
[Thu Sep 17 15:19:36.778283 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/gateway/.env"] [unique_id "aqxZaApXMN3p_zkwXf2cwAAAANM"]
[Thu Sep 17 15:19:36.820344 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.204.169.220:41722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/pi.php"] [unique_id "aqxZaApXMN3p_zkwXf2cygAAAPQ"]
[Thu Sep 17 15:19:36.859079 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxZaApXMN3p_zkwXf2czgAAANA"]
[Thu Sep 17 15:19:36.881813 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/vue/.env"] [unique_id "aqxZaApXMN3p_zkwXf2czwAAAJQ"]
[Thu Sep 17 15:19:36.939722 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxZaApXMN3p_zkwXf2c0QAAAI4"]
[Thu Sep 17 15:19:36.947643 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.246.241.88:35508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxZaApXMN3p_zkwXf2c0gAAAMk"]
[Thu Sep 17 15:19:36.965817 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/microservice/.env"] [unique_id "aqxZaApXMN3p_zkwXf2c0wAAAJ8"]
[Thu Sep 17 15:19:37.030764 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/angular/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c1AAAAO0"]
[Thu Sep 17 15:19:37.035626 2026] [security2:error] [pid 1012520:tid 1012662] [client 156.192.234.52:59129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c1QAAAJA"]
[Thu Sep 17 15:19:37.037096 2026] [security2:error] [pid 1012520:tid 1012662] [client 156.192.234.52:59129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c1QAAAJA"]
[Thu Sep 17 15:19:37.078081 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c2gAAAPI"]
[Thu Sep 17 15:19:37.150168 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/service/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c3AAAAOY"]
[Thu Sep 17 15:19:37.167724 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c4AAAAJY"]
[Thu Sep 17 15:19:37.182468 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/svelte/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c4gAAANg"]
[Thu Sep 17 15:19:37.201993 2026] [security2:error] [pid 1012520:tid 1012674] [client 74.7.241.138:43422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cnAAAnAM"]
[Thu Sep 17 15:19:37.202010 2026] [security2:error] [pid 1012520:tid 1012674] [client 74.7.241.138:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cnAAAnAM"]
[Thu Sep 17 15:19:37.250039 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c5wAAAPU"]
[Thu Sep 17 15:19:37.317070 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cqAAAw3Y"]
[Thu Sep 17 15:19:37.318792 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cpgAAw3w"]
[Thu Sep 17 15:19:37.320746 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2crQAAwww"]
[Thu Sep 17 15:19:37.331789 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/vite/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c6wAAAP0"]
[Thu Sep 17 15:19:37.335310 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/v3/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c7QAAAQM"]
[Thu Sep 17 15:19:37.352391 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c7gAAAME"]
[Thu Sep 17 15:19:37.352558 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c7gAAAME"]
[Thu Sep 17 15:19:37.358032 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c7wAAAP8"]
[Thu Sep 17 15:19:37.374760 2026] [security2:error] [pid 1012520:tid 1012670] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cvwAAAJg"]
[Thu Sep 17 15:19:37.382631 2026] [security2:error] [pid 1012520:tid 1012746] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cyAAAAOQ"]
[Thu Sep 17 15:19:37.382646 2026] [security2:error] [pid 1012520:tid 1012685] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxAAAAKc"]
[Thu Sep 17 15:19:37.382732 2026] [security2:error] [pid 1012520:tid 1012750] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cwgAAAOg"]
[Thu Sep 17 15:19:37.384181 2026] [security2:error] [pid 1012520:tid 1012655] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cwwAAAIk"]
[Thu Sep 17 15:19:37.389261 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxwAAAK8"]
[Thu Sep 17 15:19:37.390839 2026] [security2:error] [pid 1012520:tid 1012691] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxQAAAK0"]
[Thu Sep 17 15:19:37.392154 2026] [security2:error] [pid 1012520:tid 1012672] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cwQAAAJo"]
[Thu Sep 17 15:19:37.395877 2026] [security2:error] [pid 1012520:tid 1012705] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cxgAAALs"]
[Thu Sep 17 15:19:37.395980 2026] [security2:error] [pid 1012520:tid 1012739] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaApXMN3p_zkwXf2cyQAAAN0"]
[Thu Sep 17 15:19:37.419028 2026] [security2:error] [pid 1012520:tid 1012676] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c2wAAAJ4"]
[Thu Sep 17 15:19:37.420416 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c1wAAw3c"]
[Thu Sep 17 15:19:37.433432 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:41724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/pinfo.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c9AAAAKM"]
[Thu Sep 17 15:19:37.435178 2026] [security2:error] [pid 1012520:tid 1012713] [client 45.138.12.26:54306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c2AAAw3s"]
[Thu Sep 17 15:19:37.439422 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c9QAAAMQ"]
[Thu Sep 17 15:19:37.480878 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/backup/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c9gAAAOc"]
[Thu Sep 17 15:19:37.501506 2026] [security2:error] [pid 1012520:tid 1012602] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/.env.local.old"] [unique_id "aqxZaQpXMN3p_zkwXf2c-wAA7FA"]
[Thu Sep 17 15:19:37.513573 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c_AAAAJ0"]
[Thu Sep 17 15:19:37.516418 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/dev/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2c_gAAALA"]
[Thu Sep 17 15:19:37.579727 2026] [security2:error] [pid 1012520:tid 1012529] [remote 45.138.12.26:54306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "impact100sydneynorth.org"] [uri "/node/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dAgAA7Ac"]
[Thu Sep 17 15:19:37.603312 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dBgAAANE"]
[Thu Sep 17 15:19:37.629453 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/backups/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dBwAAAJk"]
[Thu Sep 17 15:19:37.640300 2026] [security2:error] [pid 1012520:tid 1012699] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2c_wAAALU"]
[Thu Sep 17 15:19:37.640310 2026] [security2:error] [pid 1012520:tid 1012764] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dAAAAAPY"]
[Thu Sep 17 15:19:37.697256 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/api/staging/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dCgAAAJ8"]
[Thu Sep 17 15:19:37.707977 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dDAAAAKg"]
[Thu Sep 17 15:19:37.776988 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/old/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dDwAAAIU"]
[Thu Sep 17 15:19:37.862903 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.246.241.88:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dFwAAAJs"]
[Thu Sep 17 15:19:37.877616 2026] [security2:error] [pid 1012520:tid 1012763] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dGQAAAPU"]
[Thu Sep 17 15:19:37.877719 2026] [security2:error] [pid 1012520:tid 1012763] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dGQAAAPU"]
[Thu Sep 17 15:19:37.878080 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/vendor/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dGAAAAJM"]
[Thu Sep 17 15:19:37.878181 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dGgAAALM"]
[Thu Sep 17 15:19:37.930753 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/tmp/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dGwAAAO8"]
[Thu Sep 17 15:19:38.001378 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxZaQpXMN3p_zkwXf2dHAAAAKo"]
[Thu Sep 17 15:19:38.061365 2026] [autoindex:error] [pid 1012520:tid 1012658] [client 143.110.154.194:40452] AH01276: Cannot serve directory /home1/seandav5/public_html/ocdpeers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:19:38.065931 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/lib/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dHwAAAME"]
[Thu Sep 17 15:19:38.075900 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dIAAAANc"]
[Thu Sep 17 15:19:38.078305 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/temp/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dIQAAAP8"]
[Thu Sep 17 15:19:38.126438 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.204.169.220:41730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/test.php"] [unique_id "aqxZagpXMN3p_zkwXf2dIgAAAMs"]
[Thu Sep 17 15:19:38.177965 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dIwAAALs"]
[Thu Sep 17 15:19:38.241901 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/lab/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dJAAAAIo"]
[Thu Sep 17 15:19:38.246336 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/resources/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dJQAAAN8"]
[Thu Sep 17 15:19:38.254972 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dJgAAAMU"]
[Thu Sep 17 15:19:38.374466 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dKQAAANo"]
[Thu Sep 17 15:19:38.375246 2026] [security2:error] [pid 1012520:tid 1012687] [client 45.138.12.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxZaQpXMN3p_zkwXf2dCQAAAKk"]
[Thu Sep 17 15:19:38.383520 2026] [security2:error] [pid 1012520:tid 1012765] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aqxZagpXMN3p_zkwXf2dKgAAAPc"]
[Thu Sep 17 15:19:38.383587 2026] [security2:error] [pid 1012520:tid 1012765] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aqxZagpXMN3p_zkwXf2dKgAAAPc"]
[Thu Sep 17 15:19:38.397019 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cronlab/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLAAAAOs"]
[Thu Sep 17 15:19:38.434702 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/assets/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLQAAAIg"]
[Thu Sep 17 15:19:38.465967 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLgAAAM8"]
[Thu Sep 17 15:19:38.555123 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cron/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dLwAAAMg"]
[Thu Sep 17 15:19:38.556036 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dMAAAAK4"]
[Thu Sep 17 15:19:38.624999 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/uploads/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dMgAAAOo"]
[Thu Sep 17 15:19:38.636928 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dMwAAAKA"]
[Thu Sep 17 15:19:38.712747 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/en/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dNQAAAN4"]
[Thu Sep 17 15:19:38.722724 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dNgAAALc"]
[Thu Sep 17 15:19:38.751324 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.246.241.88:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxZagpXMN3p_zkwXf2dNwAAAKU"]
[Thu Sep 17 15:19:38.820596 2026] [security2:error] [pid 1012520:tid 1012759] [client 192.178.6.4:43350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxZagpXMN3p_zkwXf2dOQAAAPE"]
[Thu Sep 17 15:19:38.824223 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/internal/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dOgAAAMc"]
[Thu Sep 17 15:19:38.827184 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dOwAAALk"]
[Thu Sep 17 15:19:38.910624 2026] [security2:error] [pid 1012520:tid 1012747] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/aa.php"] [unique_id "aqxZagpXMN3p_zkwXf2dRQAAAOU"]
[Thu Sep 17 15:19:38.910743 2026] [security2:error] [pid 1012520:tid 1012747] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/aa.php"] [unique_id "aqxZagpXMN3p_zkwXf2dRQAAAOU"]
[Thu Sep 17 15:19:38.910953 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dRAAAAPk"]
[Thu Sep 17 15:19:38.930411 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/administrator/.env"] [unique_id "aqxZagpXMN3p_zkwXf2dQQAAAO4"]
[Thu Sep 17 15:19:38.989877 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZagpXMN3p_zkwXf2dQwAAANI"]
[Thu Sep 17 15:19:39.010525 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/tools/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dRgAAAL4"]
[Thu Sep 17 15:19:39.043101 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dRwAAAL0"]
[Thu Sep 17 15:19:39.068083 2026] [security2:error] [pid 1012520:tid 1012743] [client 110.249.202.132:60230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/160-Welcome-week.jpg"] [unique_id "aqxZawpXMN3p_zkwXf2dSAAAAOE"]
[Thu Sep 17 15:19:39.084110 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/psnlink/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dSQAAAOI"]
[Thu Sep 17 15:19:39.122055 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dSgAAANA"]
[Thu Sep 17 15:19:39.195700 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/scripts/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dSwAAALg"]
[Thu Sep 17 15:19:39.221722 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dTAAAAI4"]
[Thu Sep 17 15:19:39.232205 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/exapi/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dTQAAAMk"]
[Thu Sep 17 15:19:39.255285 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.204.169.220:41742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/p.php"] [unique_id "aqxZawpXMN3p_zkwXf2dUAAAAQE"]
[Thu Sep 17 15:19:39.297062 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dUgAAALY"]
[Thu Sep 17 15:19:39.380496 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sitemaps/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dVgAAANg"]
[Thu Sep 17 15:19:39.386145 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/bin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dVwAAANY"]
[Thu Sep 17 15:19:39.413419 2026] [security2:error] [pid 1012520:tid 1012776] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/z70.php"] [unique_id "aqxZawpXMN3p_zkwXf2dWAAAAQI"]
[Thu Sep 17 15:19:39.413502 2026] [security2:error] [pid 1012520:tid 1012776] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/z70.php"] [unique_id "aqxZawpXMN3p_zkwXf2dWAAAAQI"]
[Thu Sep 17 15:19:39.430409 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dWQAAAJs"]
[Thu Sep 17 15:19:39.453668 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.246.241.88:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxZawpXMN3p_zkwXf2dWgAAAJc"]
[Thu Sep 17 15:19:39.534175 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dXQAAAO8"]
[Thu Sep 17 15:19:39.574268 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sbin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dXgAAAJY"]
[Thu Sep 17 15:19:39.627016 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dXwAAALw"]
[Thu Sep 17 15:19:39.671628 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.32.0.94:46708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZawpXMN3p_zkwXf2dXAAAAPM"]
[Thu Sep 17 15:19:39.685977 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:61708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dYwAAAKs"]
[Thu Sep 17 15:19:39.690158 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:61708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dYwAAAKs"]
[Thu Sep 17 15:19:39.738394 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dZQAAAJg"]
[Thu Sep 17 15:19:39.765785 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/local/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dZgAAAMs"]
[Thu Sep 17 15:19:39.864553 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dagAAAK8"]
[Thu Sep 17 15:19:39.867866 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.204.169.220:41746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/debug.php"] [unique_id "aqxZawpXMN3p_zkwXf2dawAAAL8"]
[Thu Sep 17 15:19:39.953098 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/portal/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dbQAAAMU"]
[Thu Sep 17 15:19:39.959520 2026] [security2:error] [pid 1012520:tid 1012737] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/f35.php"] [unique_id "aqxZawpXMN3p_zkwXf2dbgAAANs"]
[Thu Sep 17 15:19:39.959618 2026] [security2:error] [pid 1012520:tid 1012737] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/f35.php"] [unique_id "aqxZawpXMN3p_zkwXf2dbgAAANs"]
[Thu Sep 17 15:19:39.960292 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxZawpXMN3p_zkwXf2dbwAAAJI"]
[Thu Sep 17 15:19:39.988933 2026] [security2:error] [pid 1012520:tid 1012690] [client 45.169.98.18:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dcQAAAKw"]
[Thu Sep 17 15:19:39.989018 2026] [security2:error] [pid 1012520:tid 1012690] [client 45.169.98.18:50854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZawpXMN3p_zkwXf2dcQAAAKw"]
[Thu Sep 17 15:19:40.079631 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dcgAAAMY"]
[Thu Sep 17 15:19:40.097039 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.32.0.94:46708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZawpXMN3p_zkwXf2dcAAAANo"]
[Thu Sep 17 15:19:40.149318 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/dashboard/.env"] [unique_id "aqxZbApXMN3p_zkwXf2ddAAAAOw"]
[Thu Sep 17 15:19:40.164670 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxZbApXMN3p_zkwXf2ddQAAAM0"]
[Thu Sep 17 15:19:40.248834 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.246.241.88:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/www/phpinfo.php"] [unique_id "aqxZbApXMN3p_zkwXf2ddgAAAIo"]
[Thu Sep 17 15:19:40.253755 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.32.0.94:46708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/logs/.env"] [unique_id "aqxZbApXMN3p_zkwXf2ddwAAAKE"]
[Thu Sep 17 15:19:40.295635 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxZbApXMN3p_zkwXf2deAAAAIg"]
[Thu Sep 17 15:19:40.341372 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/panel/.env"] [unique_id "aqxZbApXMN3p_zkwXf2deQAAAMw"]
[Thu Sep 17 15:19:40.416938 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dfAAAAKI"]
[Thu Sep 17 15:19:40.458072 2026] [security2:error] [pid 1012520:tid 1012667] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/adminfuns.php"] [unique_id "aqxZbApXMN3p_zkwXf2dgQAAAJU"]
[Thu Sep 17 15:19:40.458152 2026] [security2:error] [pid 1012520:tid 1012667] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/adminfuns.php"] [unique_id "aqxZbApXMN3p_zkwXf2dgQAAAJU"]
[Thu Sep 17 15:19:40.520803 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.204.169.220:60010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZbApXMN3p_zkwXf2dggAAAJE"]
[Thu Sep 17 15:19:40.524722 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/crm/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dgwAAAIs"]
[Thu Sep 17 15:19:40.535302 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dhQAAAOo"]
[Thu Sep 17 15:19:40.638743 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxZbApXMN3p_zkwXf2diAAAALk"]
[Thu Sep 17 15:19:40.710126 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/erp/.env"] [unique_id "aqxZbApXMN3p_zkwXf2digAAAKY"]
[Thu Sep 17 15:19:40.710138 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cache/.env"] [unique_id "aqxZbApXMN3p_zkwXf2diQAAAN4"]
[Thu Sep 17 15:19:40.730034 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxZbApXMN3p_zkwXf2diwAAAPk"]
[Thu Sep 17 15:19:40.829385 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxZbApXMN3p_zkwXf2djQAAAJk"]
[Thu Sep 17 15:19:40.862652 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailer/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dkAAAANQ"]
[Thu Sep 17 15:19:40.899793 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/shop/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dkgAAAL0"]
[Thu Sep 17 15:19:40.956508 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxZbApXMN3p_zkwXf2dlAAAAOM"]
[Thu Sep 17 15:19:40.965784 2026] [security2:error] [pid 1012520:tid 1012744] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/av.php"] [unique_id "aqxZbApXMN3p_zkwXf2dlQAAAOI"]
[Thu Sep 17 15:19:40.965870 2026] [security2:error] [pid 1012520:tid 1012744] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/av.php"] [unique_id "aqxZbApXMN3p_zkwXf2dlQAAAOI"]
[Thu Sep 17 15:19:41.014556 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mail/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dlgAAANA"]
[Thu Sep 17 15:19:41.035933 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.246.241.88:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dmAAAALU"]
[Thu Sep 17 15:19:41.036341 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dlwAAAJQ"]
[Thu Sep 17 15:19:41.085471 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/store/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dmQAAAMk"]
[Thu Sep 17 15:19:41.110127 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dmgAAAQE"]
[Thu Sep 17 15:19:41.116147 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.204.169.220:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dmwAAAOc"]
[Thu Sep 17 15:19:41.165194 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/email/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dnQAAAO0"]
[Thu Sep 17 15:19:41.187642 2026] [security2:error] [pid 1012520:tid 1012727] [client 103.61.184.148:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dnwAAANE"]
[Thu Sep 17 15:19:41.187761 2026] [security2:error] [pid 1012520:tid 1012727] [client 103.61.184.148:58178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dnwAAANE"]
[Thu Sep 17 15:19:41.207364 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2doAAAANk"]
[Thu Sep 17 15:19:41.277997 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/saas/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2doQAAALY"]
[Thu Sep 17 15:19:41.307615 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dowAAAQI"]
[Thu Sep 17 15:19:41.317253 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/smtp/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dpAAAAJs"]
[Thu Sep 17 15:19:41.398307 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dqAAAAMI"]
[Thu Sep 17 15:19:41.465862 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/client/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dqgAAAOY"]
[Thu Sep 17 15:19:41.468100 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailing/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dqwAAANU"]
[Thu Sep 17 15:19:41.479996 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/dex.php"] [unique_id "aqxZbQpXMN3p_zkwXf2drAAAAO8"]
[Thu Sep 17 15:19:41.480108 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/dex.php"] [unique_id "aqxZbQpXMN3p_zkwXf2drAAAAO8"]
[Thu Sep 17 15:19:41.499861 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2drQAAAJY"]
[Thu Sep 17 15:19:41.606332 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2drgAAAPM"]
[Thu Sep 17 15:19:41.619716 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/notifications/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2drwAAAQM"]
[Thu Sep 17 15:19:41.652407 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/project/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dsAAAAPs"]
[Thu Sep 17 15:19:41.682367 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.246.241.88:35570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dsQAAALw"]
[Thu Sep 17 15:19:41.704307 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dsgAAANc"]
[Thu Sep 17 15:19:41.774163 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/notify/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dswAAAM4"]
[Thu Sep 17 15:19:41.798025 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dtAAAAK8"]
[Thu Sep 17 15:19:41.843404 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/admin-panel/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2duQAAAJo"]
[Thu Sep 17 15:19:41.918903 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.204.169.220:60018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZbQpXMN3p_zkwXf2duwAAAJg"]
[Thu Sep 17 15:19:41.925150 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sender/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dvAAAAJI"]
[Thu Sep 17 15:19:41.939590 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxZbQpXMN3p_zkwXf2dvwAAAKw"]
[Thu Sep 17 15:19:41.992186 2026] [security2:error] [pid 1012520:tid 1012774] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/chosen.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dwAAAAQA"]
[Thu Sep 17 15:19:41.992297 2026] [security2:error] [pid 1012520:tid 1012774] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/chosen.php"] [unique_id "aqxZbQpXMN3p_zkwXf2dwAAAAQA"]
[Thu Sep 17 15:19:42.036934 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/control-panel/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dwQAAAKQ"]
[Thu Sep 17 15:19:42.058103 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dwgAAAKk"]
[Thu Sep 17 15:19:42.077083 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/campaign/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dwwAAAPA"]
[Thu Sep 17 15:19:42.162658 2026] [security2:error] [pid 1012520:tid 1012550] [remote 216.73.217.142:2617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxZbgpXMN3p_zkwXf2dxAABBBw"]
[Thu Sep 17 15:19:42.163896 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dxQAAANo"]
[Thu Sep 17 15:19:42.223526 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/user-panel/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dxgAAAM0"]
[Thu Sep 17 15:19:42.227071 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/newsletter/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dxwAAAOs"]
[Thu Sep 17 15:19:42.273205 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dyAAAAKE"]
[Thu Sep 17 15:19:42.366367 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dywAAAJU"]
[Thu Sep 17 15:19:42.378430 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/ses/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dzAAAAPo"]
[Thu Sep 17 15:19:42.414103 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/node/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2dzgAAAOo"]
[Thu Sep 17 15:19:42.421591 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.246.241.88:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/site/phpinfo.php"] [unique_id "aqxZbgpXMN3p_zkwXf2dzwAAAOw"]
[Thu Sep 17 15:19:42.481287 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d0AAAAJ4"]
[Thu Sep 17 15:19:42.492791 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "moneysmartlatina.com"] [uri "/1.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d0QAAALc"]
[Thu Sep 17 15:19:42.492865 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/1.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d0QAAALc"]
[Thu Sep 17 15:19:42.492950 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/1.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d0QAAALc"]
[Thu Sep 17 15:19:42.529744 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sendgrid/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d0gAAAKM"]
[Thu Sep 17 15:19:42.579390 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d0wAAAPg"]
[Thu Sep 17 15:19:42.592623 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.204.169.220:60022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d1AAAAKg"]
[Thu Sep 17 15:19:42.600280 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/express/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d1QAAAPE"]
[Thu Sep 17 15:19:42.670506 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d1gAAAMc"]
[Thu Sep 17 15:19:42.679925 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/sparkpost/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d1wAAALk"]
[Thu Sep 17 15:19:42.717356 2026] [security2:error] [pid 1012520:tid 1012722] [client 154.190.208.131:41435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d2AAAAMw"]
[Thu Sep 17 15:19:42.717445 2026] [security2:error] [pid 1012520:tid 1012722] [client 154.190.208.131:41435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d2AAAAMw"]
[Thu Sep 17 15:19:42.760743 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d2wAAAKY"]
[Thu Sep 17 15:19:42.788144 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/next/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d3AAAAN4"]
[Thu Sep 17 15:19:42.831287 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/postmark/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d3gAAAPk"]
[Thu Sep 17 15:19:42.870424 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d4wAAAJk"]
[Thu Sep 17 15:19:42.949281 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d5gAAANQ"]
[Thu Sep 17 15:19:42.970951 2026] [security2:error] [pid 1012520:tid 1012675] [client 45.181.99.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "threadalittlelight.com"] [uri "/index.php"] [unique_id "aqxZbgpXMN3p_zkwXf2d5AAAAJ0"], referer: https://threadalittlelight.com
[Thu Sep 17 15:19:42.975336 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/nuxt/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d5wAAAOM"]
[Thu Sep 17 15:19:42.987242 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailgun/.env"] [unique_id "aqxZbgpXMN3p_zkwXf2d6AAAANA"]
[Thu Sep 17 15:19:43.005459 2026] [security2:error] [pid 1012520:tid 1012699] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/radio.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d6QAAALU"]
[Thu Sep 17 15:19:43.005524 2026] [security2:error] [pid 1012520:tid 1012699] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/radio.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d6QAAALU"]
[Thu Sep 17 15:19:43.080001 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d6gAAALg"]
[Thu Sep 17 15:19:43.111117 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.246.241.88:55596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d6wAAAL4"]
[Thu Sep 17 15:19:43.140835 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mandrill/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d7AAAAOc"]
[Thu Sep 17 15:19:43.162289 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/nest/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d7gAAAO0"]
[Thu Sep 17 15:19:43.192898 2026] [security2:error] [pid 1012520:tid 1012707] [client 185.55.149.49:60709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d8AAAAL0"]
[Thu Sep 17 15:19:43.192968 2026] [security2:error] [pid 1012520:tid 1012707] [client 185.55.149.49:60709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d8AAAAL0"]
[Thu Sep 17 15:19:43.193722 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d7QAAAJA"]
[Thu Sep 17 15:19:43.284644 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d8QAAANk"]
[Thu Sep 17 15:19:43.295735 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mailjet/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d8gAAAPI"]
[Thu Sep 17 15:19:43.332733 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.204.169.220:60038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d8wAAAPY"]
[Thu Sep 17 15:19:43.349160 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/react/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d9AAAALY"]
[Thu Sep 17 15:19:43.450396 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/brevo/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d-AAAAIY"]
[Thu Sep 17 15:19:43.493875 2026] [security2:error] [pid 1012520:tid 1012748] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/blacks.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d-gAAAOY"]
[Thu Sep 17 15:19:43.493961 2026] [security2:error] [pid 1012520:tid 1012748] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/blacks.php"] [unique_id "aqxZbwpXMN3p_zkwXf2d-gAAAOY"]
[Thu Sep 17 15:19:43.522482 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d-wAAANU"]
[Thu Sep 17 15:19:43.538301 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/vue/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d_AAAALM"]
[Thu Sep 17 15:19:43.603388 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/transactional/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d_gAAAJM"]
[Thu Sep 17 15:19:43.627815 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2d_wAAAPs"]
[Thu Sep 17 15:19:43.733514 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/angular/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eAQAAANc"]
[Thu Sep 17 15:19:43.769162 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/bulk/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eAgAAAKc"]
[Thu Sep 17 15:19:43.901387 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eCQAAAQA"]
[Thu Sep 17 15:19:43.915839 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/svelte/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eCgAAAKQ"]
[Thu Sep 17 15:19:43.922920 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/aws/.env"] [unique_id "aqxZbwpXMN3p_zkwXf2eCwAAAKk"]
[Thu Sep 17 15:19:43.996375 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.204.169.220:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZbwpXMN3p_zkwXf2eDwAAAJI"]
[Thu Sep 17 15:19:44.009542 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eEAAAAL8"]
[Thu Sep 17 15:19:44.044011 2026] [security2:error] [pid 1012520:tid 1012778] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/alfa.php"] [unique_id "aqxZcApXMN3p_zkwXf2eEQAAAQQ"]
[Thu Sep 17 15:19:44.044070 2026] [security2:error] [pid 1012520:tid 1012778] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/alfa.php"] [unique_id "aqxZcApXMN3p_zkwXf2eEQAAAQQ"]
[Thu Sep 17 15:19:44.080294 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/azure/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eEgAAAM0"]
[Thu Sep 17 15:19:44.094677 2026] [access_compat:error] [pid 1012520:tid 1012753] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/wedding-salon-2
[Thu Sep 17 15:19:44.101919 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/vite/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eFAAAAIo"]
[Thu Sep 17 15:19:44.112246 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eFQAAAIg"]
[Thu Sep 17 15:19:44.126402 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.246.241.88:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZcApXMN3p_zkwXf2eFgAAAM4"]
[Thu Sep 17 15:19:44.201387 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eFwAAAK4"]
[Thu Sep 17 15:19:44.230358 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/gcp/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eGQAAAPo"]
[Thu Sep 17 15:19:44.278117 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:44044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eGgAAAKs"]
[Thu Sep 17 15:19:44.288272 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/backup/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eGwAAAOo"]
[Thu Sep 17 15:19:44.381417 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cloud/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eHwAAAMA"]
[Thu Sep 17 15:19:44.474871 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/backups/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eIQAAAM8"]
[Thu Sep 17 15:19:44.531442 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/infrastructure/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eIwAAALk"]
[Thu Sep 17 15:19:44.564320 2026] [security2:error] [pid 1012520:tid 1012773] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/w.php"] [unique_id "aqxZcApXMN3p_zkwXf2eJAAAAP8"]
[Thu Sep 17 15:19:44.564382 2026] [security2:error] [pid 1012520:tid 1012773] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/w.php"] [unique_id "aqxZcApXMN3p_zkwXf2eJAAAAP8"]
[Thu Sep 17 15:19:44.571020 2026] [security2:error] [pid 1012520:tid 1012754] [client 114.198.138.124:62108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcApXMN3p_zkwXf2eIgAAAOw"]
[Thu Sep 17 15:19:44.571103 2026] [security2:error] [pid 1012520:tid 1012754] [client 114.198.138.124:62108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcApXMN3p_zkwXf2eIgAAAOw"]
[Thu Sep 17 15:19:44.620548 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eJQAAAMw"]
[Thu Sep 17 15:19:44.664078 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/old/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eJgAAAN4"]
[Thu Sep 17 15:19:44.683205 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/docker/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eJwAAAPk"]
[Thu Sep 17 15:19:44.703367 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eKQAAAJk"]
[Thu Sep 17 15:19:44.780300 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eLAAAAOQ"]
[Thu Sep 17 15:19:44.803251 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.246.241.88:55608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZcApXMN3p_zkwXf2eLgAAAKY"]
[Thu Sep 17 15:19:44.833563 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/k8s/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eLwAAAOI"]
[Thu Sep 17 15:19:44.849643 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/tmp/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eMAAAANA"]
[Thu Sep 17 15:19:44.865495 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eMgAAALU"]
[Thu Sep 17 15:19:44.898745 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZcApXMN3p_zkwXf2eLQAAAOM"]
[Thu Sep 17 15:19:44.951390 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eNwAAAMo"]
[Thu Sep 17 15:19:44.983454 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/kubernetes/.env"] [unique_id "aqxZcApXMN3p_zkwXf2eOQAAAQE"]
[Thu Sep 17 15:19:45.038213 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/temp/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eOgAAANw"]
[Thu Sep 17 15:19:45.050020 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eOwAAAOc"]
[Thu Sep 17 15:19:45.091166 2026] [security2:error] [pid 1012520:tid 1012707] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp_blog_footer.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ePAAAAL0"]
[Thu Sep 17 15:19:45.091229 2026] [security2:error] [pid 1012520:tid 1012707] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp_blog_footer.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ePAAAAL0"]
[Thu Sep 17 15:19:45.132807 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ePQAAANk"]
[Thu Sep 17 15:19:45.133628 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/terraform/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ePgAAAPI"]
[Thu Sep 17 15:19:45.162137 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.204.169.220:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/php-info.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ePwAAAPY"]
[Thu Sep 17 15:19:45.222810 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eQgAAAPQ"]
[Thu Sep 17 15:19:45.240591 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/lab/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eRAAAAIY"]
[Thu Sep 17 15:19:45.286607 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/ansible/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eRgAAAJw"]
[Thu Sep 17 15:19:45.317132 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eRwAAAMI"]
[Thu Sep 17 15:19:45.373643 2026] [security2:error] [pid 1012520:tid 1012700] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eQAAAALY"]
[Thu Sep 17 15:19:45.421693 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTAAAAP0"]
[Thu Sep 17 15:19:45.427218 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cronlab/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTQAAAJM"]
[Thu Sep 17 15:19:45.433215 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTgAAAPM"]
[Thu Sep 17 15:19:45.438033 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/.git/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eTwAAAKA"]
[Thu Sep 17 15:19:45.497570 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eUgAAAPs"]
[Thu Sep 17 15:19:45.558142 2026] [security2:error] [pid 1012520:tid 1012661] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eUAAAAI8"]
[Thu Sep 17 15:19:45.589762 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/ci/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eWAAAAI0"]
[Thu Sep 17 15:19:45.593971 2026] [security2:error] [pid 1012520:tid 1012739] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/sss.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eWQAAAN0"]
[Thu Sep 17 15:19:45.594046 2026] [security2:error] [pid 1012520:tid 1012739] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/sss.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eWQAAAN0"]
[Thu Sep 17 15:19:45.596172 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eWwAAAJg"]
[Thu Sep 17 15:19:45.611518 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cron/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eXAAAAKQ"]
[Thu Sep 17 15:19:45.644765 2026] [security2:error] [pid 1012520:tid 1012613] [remote 47.128.23.119:48504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ec235nothing.cyberpunkonline.net"] [uri "/robots.txt"] [unique_id "aqxZcQpXMN3p_zkwXf2eXQAA_Fs"]
[Thu Sep 17 15:19:45.698395 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eYQAAAJI"]
[Thu Sep 17 15:19:45.741658 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/cd/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eZAAAAM0"]
[Thu Sep 17 15:19:45.753927 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.204.169.220:60078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpversion.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eZQAAAMs"]
[Thu Sep 17 15:19:45.783347 2026] [security2:error] [pid 1012520:tid 1012716] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eXwAAAMY"]
[Thu Sep 17 15:19:45.797197 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/en/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eZwAAAPc"]
[Thu Sep 17 15:19:45.813097 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2eaAAAAIo"]
[Thu Sep 17 15:19:45.893364 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/jenkins/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ebAAAAK4"]
[Thu Sep 17 15:19:45.898669 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.246.241.88:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/core/phpinfo.php"] [unique_id "aqxZcQpXMN3p_zkwXf2ebQAAAQA"]
[Thu Sep 17 15:19:45.932741 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ebwAAAPo"]
[Thu Sep 17 15:19:45.971340 2026] [security2:error] [pid 1012520:tid 1012724] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcQpXMN3p_zkwXf2eawAAAM4"]
[Thu Sep 17 15:19:46.026746 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ecwAAAPg"]
[Thu Sep 17 15:19:46.034467 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/administrator/.env"] [unique_id "aqxZcQpXMN3p_zkwXf2ecgAAAJ4"]
[Thu Sep 17 15:19:46.043458 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/gitlab/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2edQAAAKI"]
[Thu Sep 17 15:19:46.103820 2026] [security2:error] [pid 1012520:tid 1012717] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/b8.php"] [unique_id "aqxZcgpXMN3p_zkwXf2eeAAAAMc"]
[Thu Sep 17 15:19:46.103941 2026] [security2:error] [pid 1012520:tid 1012717] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/b8.php"] [unique_id "aqxZcgpXMN3p_zkwXf2eeAAAAMc"]
[Thu Sep 17 15:19:46.167564 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eeQAAAP8"]
[Thu Sep 17 15:19:46.196934 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/github/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eegAAAOw"]
[Thu Sep 17 15:19:46.222613 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/psnlink/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eewAAAN4"]
[Thu Sep 17 15:19:46.265983 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2efAAAAPk"]
[Thu Sep 17 15:19:46.329617 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.204.169.220:60090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/_phpinfo.php"] [unique_id "aqxZcgpXMN3p_zkwXf2egQAAALk"]
[Thu Sep 17 15:19:46.352224 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/actions/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eggAAAIk"]
[Thu Sep 17 15:19:46.362825 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ehQAAAOM"]
[Thu Sep 17 15:19:46.403224 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/exapi/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ehgAAANQ"]
[Thu Sep 17 15:19:46.433855 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eiAAAAMo"]
[Thu Sep 17 15:19:46.509307 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/circleci/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eigAAAL4"]
[Thu Sep 17 15:19:46.533317 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eiwAAANw"]
[Thu Sep 17 15:19:46.589030 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sitemaps/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ejAAAAJQ"]
[Thu Sep 17 15:19:46.618312 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2ekAAAANE"]
[Thu Sep 17 15:19:46.624307 2026] [security2:error] [pid 1012520:tid 1012735] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/xex.php"] [unique_id "aqxZcgpXMN3p_zkwXf2ekQAAANk"]
[Thu Sep 17 15:19:46.624399 2026] [security2:error] [pid 1012520:tid 1012735] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/xex.php"] [unique_id "aqxZcgpXMN3p_zkwXf2ekQAAANk"]
[Thu Sep 17 15:19:46.639656 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.246.241.88:55622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.241.246.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teall.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxZcgpXMN3p_zkwXf2ekgAAAKg"]
[Thu Sep 17 15:19:46.665539 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/travis/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2elAAAAQI"]
[Thu Sep 17 15:19:46.685740 2026] [security2:error] [pid 1012520:tid 1012756] [client 156.192.234.52:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcgpXMN3p_zkwXf2elQAAAO4"]
[Thu Sep 17 15:19:46.687160 2026] [security2:error] [pid 1012520:tid 1012756] [client 156.192.234.52:59817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZcgpXMN3p_zkwXf2elQAAAO4"]
[Thu Sep 17 15:19:46.736333 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2elgAAAJc"]
[Thu Sep 17 15:19:46.811755 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2emwAAALY"]
[Thu Sep 17 15:19:46.827841 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/buildkite/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2enQAAAQM"]
[Thu Sep 17 15:19:46.892027 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2eoAAAAPs"]
[Thu Sep 17 15:19:46.915404 2026] [security2:error] [pid 1012520:tid 1012697] [client 159.203.135.232:50894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nebulous-llc.com"] [uri "/index.php"] [unique_id "aqxZcgpXMN3p_zkwXf2emgAAALM"]
[Thu Sep 17 15:19:46.984790 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mysql/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2epAAAAKc"]
[Thu Sep 17 15:19:46.984790 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxZcgpXMN3p_zkwXf2epQAAANU"]
[Thu Sep 17 15:19:47.011061 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.204.169.220:60104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZcwpXMN3p_zkwXf2epwAAAOY"]
[Thu Sep 17 15:19:47.045591 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZcgpXMN3p_zkwXf2enAAAAKo"]
[Thu Sep 17 15:19:47.067183 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eqAAAAKQ"]
[Thu Sep 17 15:19:47.127521 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ass.php"] [unique_id "aqxZcwpXMN3p_zkwXf2eqQAAAO8"]
[Thu Sep 17 15:19:47.127588 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/ass.php"] [unique_id "aqxZcwpXMN3p_zkwXf2eqQAAAO8"]
[Thu Sep 17 15:19:47.140409 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/postgres/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eqgAAAJs"]
[Thu Sep 17 15:19:47.170071 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eqwAAAPE"]
[Thu Sep 17 15:19:47.241127 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ergAAAOg"]
[Thu Sep 17 15:19:47.313600 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/mongodb/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2esAAAAK8"]
[Thu Sep 17 15:19:47.322587 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2esQAAAIo"]
[Thu Sep 17 15:19:47.399667 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2etgAAAPo"]
[Thu Sep 17 15:19:47.469681 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/redis/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2evQAAAIs"]
[Thu Sep 17 15:19:47.508974 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2evgAAAKs"]
[Thu Sep 17 15:19:47.550324 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "aqxZcwpXMN3p_zkwXf2evwAAAKM"]
[Thu Sep 17 15:19:47.591386 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.204.169.220:60116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/server-info.php"] [unique_id "aqxZcwpXMN3p_zkwXf2ewAAAAM4"]
[Thu Sep 17 15:19:47.600135 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ewQAAAIc"]
[Thu Sep 17 15:19:47.622584 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/elasticsearch/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ewwAAALc"]
[Thu Sep 17 15:19:47.640890 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/jybkxer.php"] [unique_id "aqxZcwpXMN3p_zkwXf2exAAAAME"]
[Thu Sep 17 15:19:47.640999 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/jybkxer.php"] [unique_id "aqxZcwpXMN3p_zkwXf2exAAAAME"]
[Thu Sep 17 15:19:47.665284 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZcwpXMN3p_zkwXf2euwAAAKI"]
[Thu Sep 17 15:19:47.722121 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2exwAAAMA"]
[Thu Sep 17 15:19:47.775361 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/rabbitmq/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2eyQAAAMw"]
[Thu Sep 17 15:19:47.782395 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "aqxZcwpXMN3p_zkwXf2eygAAAN4"]
[Thu Sep 17 15:19:47.853189 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ezQAAALk"]
[Thu Sep 17 15:19:47.864915 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.252.7.239:44970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/logs/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2ezgAAAIk"]
[Thu Sep 17 15:19:47.927155 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/kafka/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2e0QAAAOQ"]
[Thu Sep 17 15:19:47.971821 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxZcwpXMN3p_zkwXf2e1AAAAJk"]
[Thu Sep 17 15:19:48.068243 2026] [security2:error] [pid 1012520:tid 1012729] [client 195.2.78.191:60520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxZcwpXMN3p_zkwXf2e0wAAANM"], referer: http://sqlerudition.com/tag/tips-and-tricks/
[Thu Sep 17 15:19:48.082040 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/queue/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e2gAAAMQ"]
[Thu Sep 17 15:19:48.082040 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e2QAAANI"]
[Thu Sep 17 15:19:48.138150 2026] [security2:error] [pid 1012520:tid 1012755] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wsd.php"] [unique_id "aqxZdApXMN3p_zkwXf2e3QAAAO0"]
[Thu Sep 17 15:19:48.138284 2026] [security2:error] [pid 1012520:tid 1012755] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wsd.php"] [unique_id "aqxZdApXMN3p_zkwXf2e3QAAAO0"]
[Thu Sep 17 15:19:48.159889 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e3gAAANE"]
[Thu Sep 17 15:19:48.233478 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/worker/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e3wAAAOs"]
[Thu Sep 17 15:19:48.261089 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e4AAAAPY"]
[Thu Sep 17 15:19:48.297502 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.204.169.220:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/server-status.php"] [unique_id "aqxZdApXMN3p_zkwXf2e4gAAANw"]
[Thu Sep 17 15:19:48.299581 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "aqxZdApXMN3p_zkwXf2e4QAAAQI"]
[Thu Sep 17 15:19:48.342763 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e5gAAAL0"]
[Thu Sep 17 15:19:48.385837 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/job/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e6QAAALY"]
[Thu Sep 17 15:19:48.412217 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cache/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e6gAAANk"]
[Thu Sep 17 15:19:48.417847 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e6wAAAQM"]
[Thu Sep 17 15:19:48.515386 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e7AAAALM"]
[Thu Sep 17 15:19:48.536845 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/test/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e8AAAAKc"]
[Thu Sep 17 15:19:48.592592 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailer/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e8gAAAKo"]
[Thu Sep 17 15:19:48.626563 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e8wAAAJg"]
[Thu Sep 17 15:19:48.628683 2026] [security2:error] [pid 1012520:tid 1012712] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/media.php"] [unique_id "aqxZdApXMN3p_zkwXf2e9AAAAMI"]
[Thu Sep 17 15:19:48.628775 2026] [security2:error] [pid 1012520:tid 1012712] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/media.php"] [unique_id "aqxZdApXMN3p_zkwXf2e9AAAAMI"]
[Thu Sep 17 15:19:48.688635 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/qa/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e9wAAAKk"]
[Thu Sep 17 15:19:48.764474 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e-AAAAPU"]
[Thu Sep 17 15:19:48.781709 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mail/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e-QAAAPw"]
[Thu Sep 17 15:19:48.841099 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/preview/.env"] [unique_id "aqxZdApXMN3p_zkwXf2e_wAAAL8"]
[Thu Sep 17 15:19:48.885976 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fAAAAAOg"]
[Thu Sep 17 15:19:48.968428 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fBAAAANo"]
[Thu Sep 17 15:19:48.968469 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/email/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fBQAAAM0"]
[Thu Sep 17 15:19:48.994569 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/beta/.env"] [unique_id "aqxZdApXMN3p_zkwXf2fBgAAAPo"]
[Thu Sep 17 15:19:49.054249 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fCQAAAKs"]
[Thu Sep 17 15:19:49.139831 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fCwAAANs"]
[Thu Sep 17 15:19:49.140895 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ops.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fDAAAAPA"]
[Thu Sep 17 15:19:49.140973 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/ops.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fDAAAAPA"]
[Thu Sep 17 15:19:49.149102 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/uat/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fDQAAAJU"]
[Thu Sep 17 15:19:49.157124 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/smtp/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fDgAAAM4"]
[Thu Sep 17 15:19:49.220392 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fEgAAAKI"]
[Thu Sep 17 15:19:49.253263 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fCgAAAKM"]
[Thu Sep 17 15:19:49.296152 2026] [security2:error] [pid 1012520:tid 1012653] [client 92.72.180.217:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fDwAAhz8"]
[Thu Sep 17 15:19:49.303779 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/stage/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fGAAAAOI"]
[Thu Sep 17 15:19:49.321261 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fGgAAALU"]
[Thu Sep 17 15:19:49.339125 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailing/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fGwAAAOQ"]
[Thu Sep 17 15:19:49.417970 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fHwAAANQ"]
[Thu Sep 17 15:19:49.453642 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/development/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fIwAAANI"]
[Thu Sep 17 15:19:49.521135 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/notifications/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fJwAAAOc"]
[Thu Sep 17 15:19:49.556377 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fKQAAANE"]
[Thu Sep 17 15:19:49.567329 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.204.169.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hopmanchaissconsulting.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fJAAAAMQ"]
[Thu Sep 17 15:19:49.605704 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/production/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fLAAAAIw"]
[Thu Sep 17 15:19:49.667509 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fLgAAAJ8"]
[Thu Sep 17 15:19:49.670868 2026] [security2:error] [pid 1012520:tid 1012719] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/BDKR28WP.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fLwAAAMk"]
[Thu Sep 17 15:19:49.670965 2026] [security2:error] [pid 1012520:tid 1012719] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/BDKR28WP.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fLwAAAMk"]
[Thu Sep 17 15:19:49.702306 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/notify/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fMAAAALY"]
[Thu Sep 17 15:19:49.706838 2026] [security2:error] [pid 1012520:tid 1012776] [client 92.72.180.217:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fKwABAkA"]
[Thu Sep 17 15:19:49.723964 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.204.169.220:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZdQpXMN3p_zkwXf2fMQAAANY"]
[Thu Sep 17 15:19:49.761117 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.32.0.94:40746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.seekingtheway.net"] [uri "/config/app/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fMgAAANk"]
[Thu Sep 17 15:19:49.773224 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fNQAAAJM"]
[Thu Sep 17 15:19:49.873759 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fOgAAALM"]
[Thu Sep 17 15:19:49.882055 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sender/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fOwAAAIU"]
[Thu Sep 17 15:19:49.919774 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.32.0.94:40746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/phpinfo.php"] [unique_id "aqxZdQpXMN3p_zkwXf2fPAAAAI0"]
[Thu Sep 17 15:19:49.979984 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.95.61.66:38424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxZdQpXMN3p_zkwXf2fPwAAAOU"]
[Thu Sep 17 15:19:50.064238 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/campaign/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fQgAAANU"]
[Thu Sep 17 15:19:50.089830 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.95.61.66:38424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fRQAAAKo"]
[Thu Sep 17 15:19:50.180373 2026] [security2:error] [pid 1012520:tid 1012682] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/mac.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fRgAAAKQ"]
[Thu Sep 17 15:19:50.180492 2026] [security2:error] [pid 1012520:tid 1012682] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/mac.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fRgAAAKQ"]
[Thu Sep 17 15:19:50.247195 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/newsletter/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fRwAAAPI"]
[Thu Sep 17 15:19:50.324340 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.204.169.220:39412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fSQAAAPU"]
[Thu Sep 17 15:19:50.380518 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.32.0.94:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/info.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUAAAAP0"]
[Thu Sep 17 15:19:50.394265 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.95.61.66:53080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/info.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUQAAAN8"]
[Thu Sep 17 15:19:50.433399 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/ses/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fUgAAANg"]
[Thu Sep 17 15:19:50.474797 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.169.98.18:51411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUwAAAK8"]
[Thu Sep 17 15:19:50.474931 2026] [security2:error] [pid 1012520:tid 1012693] [client 45.169.98.18:51411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fUwAAAK8"]
[Thu Sep 17 15:19:50.616148 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sendgrid/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fVwAAAMc"]
[Thu Sep 17 15:19:50.676528 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.95.61.66:53086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/php.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fXAAAAPA"]
[Thu Sep 17 15:19:50.686338 2026] [security2:error] [pid 1012520:tid 1012703] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wmore1.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fXgAAALk"]
[Thu Sep 17 15:19:50.686408 2026] [security2:error] [pid 1012520:tid 1012703] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wmore1.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fXgAAALk"]
[Thu Sep 17 15:19:50.798807 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/sparkpost/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fYQAAAOI"]
[Thu Sep 17 15:19:50.847793 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.32.0.94:45152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/php.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fYwAAAIs"]
[Thu Sep 17 15:19:50.911863 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2faQAAAKs"]
[Thu Sep 17 15:19:50.912019 2026] [security2:error] [pid 1012520:tid 1012689] [client 186.105.232.15:62321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdgpXMN3p_zkwXf2faQAAAKs"]
[Thu Sep 17 15:19:50.934301 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.61.66:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/i.php"] [unique_id "aqxZdgpXMN3p_zkwXf2fawAAAI4"]
[Thu Sep 17 15:19:50.982191 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/postmark/.env"] [unique_id "aqxZdgpXMN3p_zkwXf2fbQAAANE"]
[Thu Sep 17 15:19:51.003698 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.204.169.220:39416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fbwAAALU"]
[Thu Sep 17 15:19:51.165307 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailgun/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2fcwAAANk"]
[Thu Sep 17 15:19:51.182277 2026] [security2:error] [pid 1012520:tid 1012752] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/z60.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fdgAAAOo"]
[Thu Sep 17 15:19:51.182393 2026] [security2:error] [pid 1012520:tid 1012752] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/z60.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fdgAAAOo"]
[Thu Sep 17 15:19:51.241883 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.95.61.66:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxZdwpXMN3p_zkwXf2feAAAAJ8"]
[Thu Sep 17 15:19:51.297961 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.32.0.94:45166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/i.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fegAAALY"]
[Thu Sep 17 15:19:51.333371 2026] [security2:error] [pid 1012520:tid 1012730] [client 104.28.198.244:22758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fewAAANQ"]
[Thu Sep 17 15:19:51.333517 2026] [security2:error] [pid 1012520:tid 1012730] [client 104.28.198.244:22758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fewAAANQ"]
[Thu Sep 17 15:19:51.349324 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mandrill/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2ffgAAAKc"]
[Thu Sep 17 15:19:51.411682 2026] [security2:error] [pid 1012520:tid 1012671] [client 195.2.78.191:52485] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.78.191" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.sqlerudition.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fgwAAAJk"], referer: https://www.sqlerudition.com/suppress-the-error-number-severity-level-and-state-number-in-the-error-output/
[Thu Sep 17 15:19:51.411818 2026] [security2:error] [pid 1012520:tid 1012671] [client 195.2.78.191:52485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sqlerudition.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fgwAAAJk"], referer: https://www.sqlerudition.com/suppress-the-error-number-severity-level-and-state-number-in-the-error-output/
[Thu Sep 17 15:19:51.532250 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mailjet/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2fhgAAAKk"]
[Thu Sep 17 15:19:51.549749 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.95.61.66:53108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fhwAAAJg"]
[Thu Sep 17 15:19:51.684150 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/pJPoKA.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fiQAAAO8"]
[Thu Sep 17 15:19:51.684268 2026] [security2:error] [pid 1012520:tid 1012757] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/pJPoKA.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fiQAAAO8"]
[Thu Sep 17 15:19:51.713498 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/brevo/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2figAAAK0"]
[Thu Sep 17 15:19:51.721983 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.204.169.220:39420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fiwAAAPw"]
[Thu Sep 17 15:19:51.754102 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:45178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/pi.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fjQAAAPE"]
[Thu Sep 17 15:19:51.755573 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "aqxZdwpXMN3p_zkwXf2fjAAAAQQ"]
[Thu Sep 17 15:19:51.889546 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.95.61.66:53116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/test.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fkQAAAP0"]
[Thu Sep 17 15:19:51.897350 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/transactional/.env"] [unique_id "aqxZdwpXMN3p_zkwXf2fkgAAANg"]
[Thu Sep 17 15:19:51.929361 2026] [security2:error] [pid 1012520:tid 1012765] [client 103.61.184.148:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fkwAAAPc"]
[Thu Sep 17 15:19:51.929454 2026] [security2:error] [pid 1012520:tid 1012765] [client 103.61.184.148:58732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZdwpXMN3p_zkwXf2fkwAAAPc"]
[Thu Sep 17 15:19:51.984512 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "aqxZdwpXMN3p_zkwXf2flQAAAMY"]
[Thu Sep 17 15:19:52.081348 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/bulk/.env"] [unique_id "aqxZeApXMN3p_zkwXf2fmgAAAM4"]
[Thu Sep 17 15:19:52.163891 2026] [security2:error] [pid 1012520:tid 1012614] [remote 216.73.217.142:9521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_25.xml"] [unique_id "aqxZeApXMN3p_zkwXf2fnQAAzFw"]
[Thu Sep 17 15:19:52.206715 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/24.php"] [unique_id "aqxZeApXMN3p_zkwXf2fngAAAPA"]
[Thu Sep 17 15:19:52.206824 2026] [security2:error] [pid 1012520:tid 1012758] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/24.php"] [unique_id "aqxZeApXMN3p_zkwXf2fngAAAPA"]
[Thu Sep 17 15:19:52.228339 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.32.0.94:45186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/pinfo.php"] [unique_id "aqxZeApXMN3p_zkwXf2foAAAAP8"]
[Thu Sep 17 15:19:52.252056 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.95.61.66:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/p.php"] [unique_id "aqxZeApXMN3p_zkwXf2fogAAAKw"]
[Thu Sep 17 15:19:52.269096 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/aws/.env"] [unique_id "aqxZeApXMN3p_zkwXf2fpAAAAIs"]
[Thu Sep 17 15:19:52.320299 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.204.169.220:39436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZeApXMN3p_zkwXf2fpQAAAME"]
[Thu Sep 17 15:19:52.457294 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/azure/.env"] [unique_id "aqxZeApXMN3p_zkwXf2frQAAAM8"]
[Thu Sep 17 15:19:52.642724 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/gcp/.env"] [unique_id "aqxZeApXMN3p_zkwXf2f8AAAAKY"]
[Thu Sep 17 15:19:52.696510 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.32.0.94:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/test.php"] [unique_id "aqxZeApXMN3p_zkwXf2f9gAAALw"]
[Thu Sep 17 15:19:52.708241 2026] [security2:error] [pid 1012520:tid 1012675] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/xxw.php"] [unique_id "aqxZeApXMN3p_zkwXf2f-AAAAJ0"]
[Thu Sep 17 15:19:52.708322 2026] [security2:error] [pid 1012520:tid 1012675] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/xxw.php"] [unique_id "aqxZeApXMN3p_zkwXf2f-AAAAJ0"]
[Thu Sep 17 15:19:52.719749 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.95.61.66:53140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxZeApXMN3p_zkwXf2f-QAAANs"]
[Thu Sep 17 15:19:52.824425 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cloud/.env"] [unique_id "aqxZeApXMN3p_zkwXf2f_AAAAKU"]
[Thu Sep 17 15:19:52.914704 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.204.169.220:39438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZeApXMN3p_zkwXf2gBAAAAP4"]
[Thu Sep 17 15:19:53.016264 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/infrastructure/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gBQAAAOQ"]
[Thu Sep 17 15:19:53.087543 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.95.61.66:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gCgAAANk"]
[Thu Sep 17 15:19:53.198883 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/docker/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gEAAAAKo"]
[Thu Sep 17 15:19:53.220109 2026] [security2:error] [pid 1012520:tid 1012755] [client 154.190.208.131:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEQAAAO0"]
[Thu Sep 17 15:19:53.220418 2026] [security2:error] [pid 1012520:tid 1012672] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/min.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEgAAAJo"]
[Thu Sep 17 15:19:53.220509 2026] [security2:error] [pid 1012520:tid 1012672] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/min.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEgAAAJo"]
[Thu Sep 17 15:19:53.226252 2026] [security2:error] [pid 1012520:tid 1012755] [client 154.190.208.131:42040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gEQAAAO0"]
[Thu Sep 17 15:19:53.280480 2026] [security2:error] [pid 1012520:tid 1012727] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/backup/"] [unique_id "aqxZeApXMN3p_zkwXf2f9wAA0Qg"], referer: http://www.24eastyard.com/backup/
[Thu Sep 17 15:19:53.360992 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:45200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gDQAAAIw"]
[Thu Sep 17 15:19:53.379920 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/k8s/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gGQAAAOg"]
[Thu Sep 17 15:19:53.418839 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.95.61.66:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gGwAAAIc"]
[Thu Sep 17 15:19:53.565491 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/kubernetes/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gHwAAAK4"]
[Thu Sep 17 15:19:53.568546 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.204.169.220:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZeQpXMN3p_zkwXf2gIAAAAIU"]
[Thu Sep 17 15:19:53.659515 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.32.0.94:45200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/p.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gIwAAAPE"]
[Thu Sep 17 15:19:53.724914 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/n30n.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gKQAAAJE"]
[Thu Sep 17 15:19:53.725039 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/n30n.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gKQAAAJE"]
[Thu Sep 17 15:19:53.738156 2026] [security2:error] [pid 1012520:tid 1012693] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/wp/"] [unique_id "aqxZeQpXMN3p_zkwXf2gKAAAryY"], referer: http://www.24eastyard.com/wp/
[Thu Sep 17 15:19:53.755628 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/terraform/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gKwAAAPo"]
[Thu Sep 17 15:19:53.802121 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.95.61.66:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gLAAAAJA"]
[Thu Sep 17 15:19:53.926480 2026] [security2:error] [pid 1012520:tid 1012734] [client 185.55.149.49:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gMAAAANg"]
[Thu Sep 17 15:19:53.926556 2026] [security2:error] [pid 1012520:tid 1012734] [client 185.55.149.49:54168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZeQpXMN3p_zkwXf2gMAAAANg"]
[Thu Sep 17 15:19:53.935778 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/ansible/.env"] [unique_id "aqxZeQpXMN3p_zkwXf2gMQAAAJU"]
[Thu Sep 17 15:19:54.102725 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.95.61.66:53178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxZegpXMN3p_zkwXf2gOQAAAP8"]
[Thu Sep 17 15:19:54.102738 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.204.169.220:39448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZegpXMN3p_zkwXf2gOAAAANI"]
[Thu Sep 17 15:19:54.113799 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.32.0.94:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/debug.php"] [unique_id "aqxZegpXMN3p_zkwXf2gOgAAAPc"]
[Thu Sep 17 15:19:54.116984 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.git/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gOwAAAJs"]
[Thu Sep 17 15:19:54.199762 2026] [security2:error] [pid 1012520:tid 1012729] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/new/"] [unique_id "aqxZegpXMN3p_zkwXf2gPwAA0yo"], referer: http://www.24eastyard.com/new/
[Thu Sep 17 15:19:54.243057 2026] [security2:error] [pid 1012520:tid 1012706] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/bnmtp.php"] [unique_id "aqxZegpXMN3p_zkwXf2gQAAAALw"]
[Thu Sep 17 15:19:54.243170 2026] [security2:error] [pid 1012520:tid 1012706] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/bnmtp.php"] [unique_id "aqxZegpXMN3p_zkwXf2gQAAAALw"]
[Thu Sep 17 15:19:54.268458 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gQQAAAJ0"]
[Thu Sep 17 15:19:54.298073 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/ci/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gQgAAAPk"]
[Thu Sep 17 15:19:54.455859 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.95.61.66:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZegpXMN3p_zkwXf2gSgAAAL4"]
[Thu Sep 17 15:19:54.478219 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cd/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gSwAAAPY"]
[Thu Sep 17 15:19:54.494894 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gTAAAAOM"]
[Thu Sep 17 15:19:54.564386 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.32.0.94:37780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxZegpXMN3p_zkwXf2gTQAAAPg"]
[Thu Sep 17 15:19:54.656632 2026] [security2:error] [pid 1012520:tid 1012661] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/wordpress/"] [unique_id "aqxZegpXMN3p_zkwXf2gUgAAj1Q"], referer: http://www.24eastyard.com/wordpress/
[Thu Sep 17 15:19:54.661578 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/jenkins/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gUwAAAOs"]
[Thu Sep 17 15:19:54.721136 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gVQAAAKA"]
[Thu Sep 17 15:19:54.728123 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.204.169.220:39464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php~"] [unique_id "aqxZegpXMN3p_zkwXf2gVwAAAMo"]
[Thu Sep 17 15:19:54.747348 2026] [security2:error] [pid 1012520:tid 1012669] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ebkid.php"] [unique_id "aqxZegpXMN3p_zkwXf2gWAAAAJc"]
[Thu Sep 17 15:19:54.747454 2026] [security2:error] [pid 1012520:tid 1012669] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/ebkid.php"] [unique_id "aqxZegpXMN3p_zkwXf2gWAAAAJc"]
[Thu Sep 17 15:19:54.814303 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.95.61.66:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxZegpXMN3p_zkwXf2gWQAAAIY"]
[Thu Sep 17 15:19:54.842783 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/gitlab/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gXgAAAJo"]
[Thu Sep 17 15:19:54.948646 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "aqxZegpXMN3p_zkwXf2gYAAAAIw"]
[Thu Sep 17 15:19:55.013575 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.32.0.94:37782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/test/phpinfo.php"] [unique_id "aqxZewpXMN3p_zkwXf2gYQAAAJg"]
[Thu Sep 17 15:19:55.023793 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/github/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gYgAAALM"]
[Thu Sep 17 15:19:55.112813 2026] [security2:error] [pid 1012520:tid 1012763] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/old/"] [unique_id "aqxZewpXMN3p_zkwXf2gZAAA9Vg"], referer: http://www.24eastyard.com/old/
[Thu Sep 17 15:19:55.175804 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/site/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gZgAAAIg"]
[Thu Sep 17 15:19:55.188727 2026] [security2:error] [pid 1012520:tid 1012709] [client 114.198.138.124:53734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZewpXMN3p_zkwXf2gZwAAAL8"]
[Thu Sep 17 15:19:55.188807 2026] [security2:error] [pid 1012520:tid 1012709] [client 114.198.138.124:53734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZewpXMN3p_zkwXf2gZwAAAL8"]
[Thu Sep 17 15:19:55.204039 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/actions/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gaQAAAM0"]
[Thu Sep 17 15:19:55.214590 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.95.61.66:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxZewpXMN3p_zkwXf2gagAAAO8"]
[Thu Sep 17 15:19:55.246673 2026] [security2:error] [pid 1012520:tid 1012739] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/133.php"] [unique_id "aqxZewpXMN3p_zkwXf2gbAAAAN0"]
[Thu Sep 17 15:19:55.246770 2026] [security2:error] [pid 1012520:tid 1012739] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/133.php"] [unique_id "aqxZewpXMN3p_zkwXf2gbAAAAN0"]
[Thu Sep 17 15:19:55.257304 2026] [authz_core:error] [pid 1012520:tid 1012733] [client 169.58.197.253:49862] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:19:55.341437 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.204.169.220:39476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/info.php.bak"] [unique_id "aqxZewpXMN3p_zkwXf2gcAAAAKk"]
[Thu Sep 17 15:19:55.386006 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/circleci/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gcgAAAMQ"]
[Thu Sep 17 15:19:55.401403 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gcwAAAJQ"]
[Thu Sep 17 15:19:55.463565 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.32.0.94:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxZewpXMN3p_zkwXf2gdgAAAQI"]
[Thu Sep 17 15:19:55.515407 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.95.61.66:53202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxZewpXMN3p_zkwXf2geAAAAIk"]
[Thu Sep 17 15:19:55.566584 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/travis/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gegAAAJA"]
[Thu Sep 17 15:19:55.569191 2026] [security2:error] [pid 1012520:tid 1012768] [client 129.212.238.116:47384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.24eastyard.com"] [uri "/index.php/blog/"] [unique_id "aqxZewpXMN3p_zkwXf2geQAA-i4"], referer: http://www.24eastyard.com/blog/
[Thu Sep 17 15:19:55.748069 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/buildkite/.env"] [unique_id "aqxZewpXMN3p_zkwXf2ghAAAAIs"]
[Thu Sep 17 15:19:55.764629 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/x33.php"] [unique_id "aqxZewpXMN3p_zkwXf2ghQAAAME"]
[Thu Sep 17 15:19:55.764764 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/x33.php"] [unique_id "aqxZewpXMN3p_zkwXf2ghQAAAME"]
[Thu Sep 17 15:19:55.827355 2026] [security2:error] [pid 1012520:tid 1012721] [client 209.59.91.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxZegpXMN3p_zkwXf2gPgAAAMs"], referer: https://instagram.com/
[Thu Sep 17 15:19:55.875670 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.95.61.66:53210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxZewpXMN3p_zkwXf2gjAAAAKI"]
[Thu Sep 17 15:19:55.877865 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gjQAAAKU"]
[Thu Sep 17 15:19:55.918235 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.32.0.94:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/old/phpinfo.php"] [unique_id "aqxZewpXMN3p_zkwXf2gjgAAAOc"]
[Thu Sep 17 15:19:55.929115 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mysql/.env"] [unique_id "aqxZewpXMN3p_zkwXf2gjwAAAM8"]
[Thu Sep 17 15:19:55.936855 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.204.169.220:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZewpXMN3p_zkwXf2gkAAAANo"]
[Thu Sep 17 15:19:56.105678 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "aqxZfApXMN3p_zkwXf2glgAAAI8"]
[Thu Sep 17 15:19:56.109944 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/postgres/.env"] [unique_id "aqxZfApXMN3p_zkwXf2glwAAAOs"]
[Thu Sep 17 15:19:56.210650 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.95.61.66:53220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxZfApXMN3p_zkwXf2gmQAAAKc"]
[Thu Sep 17 15:19:56.285935 2026] [security2:error] [pid 1012520:tid 1012688] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/kok.php"] [unique_id "aqxZfApXMN3p_zkwXf2gmgAAAKo"]
[Thu Sep 17 15:19:56.286040 2026] [security2:error] [pid 1012520:tid 1012688] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/kok.php"] [unique_id "aqxZfApXMN3p_zkwXf2gmgAAAKo"]
[Thu Sep 17 15:19:56.291270 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mongodb/.env"] [unique_id "aqxZfApXMN3p_zkwXf2gmwAAAMw"]
[Thu Sep 17 15:19:56.335863 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "aqxZfApXMN3p_zkwXf2gnwAAAJo"]
[Thu Sep 17 15:19:56.392132 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.32.0.94:37810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZfApXMN3p_zkwXf2goQAAANA"]
[Thu Sep 17 15:19:56.469199 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.247.203.201:48994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.com"] [uri "/"] [unique_id "aqxZfApXMN3p_zkwXf2gogAAANE"]
[Thu Sep 17 15:19:56.475153 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/redis/.env"] [unique_id "aqxZfApXMN3p_zkwXf2gowAAAJ8"]
[Thu Sep 17 15:19:56.496345 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.95.61.66:53224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxZfApXMN3p_zkwXf2gpAAAAMU"]
[Thu Sep 17 15:19:56.537794 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.204.169.220:39486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZfApXMN3p_zkwXf2gpwAAAJc"]
[Thu Sep 17 15:19:56.567073 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "aqxZfApXMN3p_zkwXf2gqAAAAOo"]
[Thu Sep 17 15:19:56.655900 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZfApXMN3p_zkwXf2gqQAAAOg"]
[Thu Sep 17 15:19:56.776677 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.95.61.66:53238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxZfApXMN3p_zkwXf2gqwAAAK0"]
[Thu Sep 17 15:19:56.793226 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/core/.env"] [unique_id "aqxZfApXMN3p_zkwXf2grQAAAIo"]
[Thu Sep 17 15:19:56.799394 2026] [security2:error] [pid 1012520:tid 1012666] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/cae.php"] [unique_id "aqxZfApXMN3p_zkwXf2grwAAAJQ"]
[Thu Sep 17 15:19:56.799455 2026] [security2:error] [pid 1012520:tid 1012666] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/cae.php"] [unique_id "aqxZfApXMN3p_zkwXf2grwAAAJQ"]
[Thu Sep 17 15:19:56.835836 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZfApXMN3p_zkwXf2gsgAAAQI"]
[Thu Sep 17 15:19:56.845132 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.32.0.94:37818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/public/phpinfo.php"] [unique_id "aqxZfApXMN3p_zkwXf2gswAAAL8"]
[Thu Sep 17 15:19:56.995176 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.247.203.201:49024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.com"] [uri "/"] [unique_id "aqxZfApXMN3p_zkwXf2gtwAAAPE"]
[Thu Sep 17 15:19:57.021129 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/core/app/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2guAAAAK4"]
[Thu Sep 17 15:19:57.023037 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/kafka/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2guQAAAIk"]
[Thu Sep 17 15:19:57.105050 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.247.203.201:49010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/"] [unique_id "aqxZfQpXMN3p_zkwXf2gwQAAAPI"]
[Thu Sep 17 15:19:57.154435 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.204.169.220:39500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZfQpXMN3p_zkwXf2gwwAAAQQ"]
[Thu Sep 17 15:19:57.187959 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.95.61.66:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZfQpXMN3p_zkwXf2gxQAAANg"]
[Thu Sep 17 15:19:57.217063 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/queue/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2gxwAAAP8"]
[Thu Sep 17 15:19:57.231693 2026] [security2:error] [pid 1012520:tid 1012769] [client 156.192.234.52:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZfQpXMN3p_zkwXf2gyAAAAPs"]
[Thu Sep 17 15:19:57.233048 2026] [security2:error] [pid 1012520:tid 1012769] [client 156.192.234.52:60452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZfQpXMN3p_zkwXf2gyAAAAPs"]
[Thu Sep 17 15:19:57.254107 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2gyQAAANI"]
[Thu Sep 17 15:19:57.315209 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/txets.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g0QAAAME"]
[Thu Sep 17 15:19:57.315352 2026] [security2:error] [pid 1012520:tid 1012711] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/txets.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g0QAAAME"]
[Thu Sep 17 15:19:57.399335 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/worker/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2g2AAAANo"]
[Thu Sep 17 15:19:57.420755 2026] [security2:error] [pid 1012520:tid 1012627] [remote 47.128.28.209:33730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "raz.cyberpunkonline.net"] [uri "/robots.txt"] [unique_id "aqxZfQpXMN3p_zkwXf2g2QAA9mk"]
[Thu Sep 17 15:19:57.467223 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.32.0.94:37822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g0AAAAO4"]
[Thu Sep 17 15:19:57.482304 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/private/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2g3AAAALw"]
[Thu Sep 17 15:19:57.486529 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.95.61.66:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g3QAAAOw"]
[Thu Sep 17 15:19:57.581487 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/job/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2g3gAAANw"]
[Thu Sep 17 15:19:57.601023 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.247.203.201:49034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.com"] [uri "/"] [unique_id "aqxZfQpXMN3p_zkwXf2g4gAAAM8"]
[Thu Sep 17 15:19:57.709982 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2g5AAAAIs"]
[Thu Sep 17 15:19:57.740731 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.247.203.201:49036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/"] [unique_id "aqxZfQpXMN3p_zkwXf2g5wAAAMo"]
[Thu Sep 17 15:19:57.756772 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.204.169.220:39510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g6AAAAPQ"]
[Thu Sep 17 15:19:57.761622 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.32.0.94:37822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/php-info.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g6QAAAMc"]
[Thu Sep 17 15:19:57.763376 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/test/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2g6gAAANs"]
[Thu Sep 17 15:19:57.830179 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.95.61.66:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g7AAAAME"]
[Thu Sep 17 15:19:57.837763 2026] [security2:error] [pid 1012520:tid 1012702] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp-update.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g7QAAALg"]
[Thu Sep 17 15:19:57.837867 2026] [security2:error] [pid 1012520:tid 1012702] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp-update.php"] [unique_id "aqxZfQpXMN3p_zkwXf2g7QAAALg"]
[Thu Sep 17 15:19:57.941621 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/bootstrap/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2g8QAAAKA"]
[Thu Sep 17 15:19:57.944431 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/qa/.env"] [unique_id "aqxZfQpXMN3p_zkwXf2g8gAAAKc"]
[Thu Sep 17 15:19:58.127001 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/preview/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2g9gAAAJc"]
[Thu Sep 17 15:19:58.134579 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.95.61.66:53282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZfgpXMN3p_zkwXf2g9wAAAOQ"]
[Thu Sep 17 15:19:58.168597 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/database/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2g-QAAAJg"]
[Thu Sep 17 15:19:58.208797 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.32.0.94:37828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/phpversion.php"] [unique_id "aqxZfgpXMN3p_zkwXf2g_wAAAJ8"]
[Thu Sep 17 15:19:58.308743 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/beta/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2hAgAAAKI"]
[Thu Sep 17 15:19:58.332031 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.204.169.220:39514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hBwAAAJ4"]
[Thu Sep 17 15:19:58.354068 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.247.203.201:49064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/"] [unique_id "aqxZfgpXMN3p_zkwXf2hDAAAAOo"]
[Thu Sep 17 15:19:58.359919 2026] [security2:error] [pid 1012520:tid 1012707] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/foxv10.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hDQAAAL0"]
[Thu Sep 17 15:19:58.359988 2026] [security2:error] [pid 1012520:tid 1012707] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/foxv10.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hDQAAAL0"]
[Thu Sep 17 15:19:58.360074 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.247.203.201:49048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hAAAAAJs"]
[Thu Sep 17 15:19:58.394793 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/storage/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2hDwAAAM8"]
[Thu Sep 17 15:19:58.489034 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/uat/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2hEQAAAMk"]
[Thu Sep 17 15:19:58.519399 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.95.61.66:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hFAAAAL8"]
[Thu Sep 17 15:19:58.622145 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2hHAAAAMI"]
[Thu Sep 17 15:19:58.663114 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.32.0.94:37836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/_phpinfo.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hHgAAAJQ"]
[Thu Sep 17 15:19:58.673765 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/stage/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2hIQAAALk"]
[Thu Sep 17 15:19:58.805234 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.247.203.201:49048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.com"] [uri "/"] [unique_id "aqxZfgpXMN3p_zkwXf2hJgAAAM4"]
[Thu Sep 17 15:19:58.848951 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2hKwAAAJ0"]
[Thu Sep 17 15:19:58.852758 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.95.61.66:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hLAAAANc"]
[Thu Sep 17 15:19:58.853911 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/development/.env"] [unique_id "aqxZfgpXMN3p_zkwXf2hLQAAAI4"]
[Thu Sep 17 15:19:58.882441 2026] [security2:error] [pid 1012520:tid 1012721] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/177.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hLgAAAMs"]
[Thu Sep 17 15:19:58.882550 2026] [security2:error] [pid 1012520:tid 1012721] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/177.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hLgAAAMs"]
[Thu Sep 17 15:19:58.908174 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.204.169.220:39520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hLwAAAKs"]
[Thu Sep 17 15:19:59.040107 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/production/.env"] [unique_id "aqxZfwpXMN3p_zkwXf2hMQAAAMU"]
[Thu Sep 17 15:19:59.063841 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.247.203.201:49076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZfgpXMN3p_zkwXf2hMAAAANg"]
[Thu Sep 17 15:19:59.082510 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "aqxZfwpXMN3p_zkwXf2hMwAAAME"]
[Thu Sep 17 15:19:59.131373 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.32.0.94:37844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/old_phpinfo.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hNAAAANs"]
[Thu Sep 17 15:19:59.160959 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.61.66:53308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxZfwpXMN3p_zkwXf2hNwAAAOM"]
[Thu Sep 17 15:19:59.228976 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.252.7.239:42290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/config/app/.env"] [unique_id "aqxZfwpXMN3p_zkwXf2hOAAAALw"]
[Thu Sep 17 15:19:59.313638 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/release/.env"] [unique_id "aqxZfwpXMN3p_zkwXf2hOgAAAOs"]
[Thu Sep 17 15:19:59.412533 2026] [security2:error] [pid 1012520:tid 1012653] [client 208.109.2.11:35648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluetech.com"] [uri "/index.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hMgAAAIc"]
[Thu Sep 17 15:19:59.417453 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/.env"] [unique_id "aqxZfwpXMN3p_zkwXf2hPgAAAP4"]
[Thu Sep 17 15:19:59.419620 2026] [security2:error] [pid 1012520:tid 1012777] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/hndkzla.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hQAAAAQM"]
[Thu Sep 17 15:19:59.419714 2026] [security2:error] [pid 1012520:tid 1012777] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/hndkzla.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hQAAAAQM"]
[Thu Sep 17 15:19:59.434707 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.252.7.239:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/phpinfo.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hPwAAAMw"]
[Thu Sep 17 15:19:59.447218 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.95.61.66:53324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxZfwpXMN3p_zkwXf2hQwAAAKc"]
[Thu Sep 17 15:19:59.549674 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/releases/.env"] [unique_id "aqxZfwpXMN3p_zkwXf2hRAAAAJ8"]
[Thu Sep 17 15:19:59.573126 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.247.203.201:49076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/"] [unique_id "aqxZfwpXMN3p_zkwXf2hRQAAAI8"]
[Thu Sep 17 15:19:59.594344 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.32.0.94:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/server-info.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hRgAAAIw"]
[Thu Sep 17 15:19:59.617667 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.204.169.220:39532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hRwAAAKo"]
[Thu Sep 17 15:19:59.729255 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.95.61.66:53336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxZfwpXMN3p_zkwXf2hSwAAAOg"]
[Thu Sep 17 15:19:59.738138 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hSgAAAKE"]
[Thu Sep 17 15:19:59.786616 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "aqxZfwpXMN3p_zkwXf2hTAAAAO8"]
[Thu Sep 17 15:19:59.947785 2026] [security2:error] [pid 1012520:tid 1012659] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp-9xay.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hVAAAAI0"]
[Thu Sep 17 15:19:59.947911 2026] [security2:error] [pid 1012520:tid 1012659] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp-9xay.php"] [unique_id "aqxZfwpXMN3p_zkwXf2hVAAAAI0"]
[Thu Sep 17 15:20:00.001558 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:47496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/info.php"] [unique_id "aqxZgApXMN3p_zkwXf2hVgAAAJs"]
[Thu Sep 17 15:20:00.020422 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/deploy/.env"] [unique_id "aqxZgApXMN3p_zkwXf2hVwAAAPw"]
[Thu Sep 17 15:20:00.055598 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.95.61.66:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxZgApXMN3p_zkwXf2hWgAAALY"]
[Thu Sep 17 15:20:00.077051 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.32.0.94:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/server-status.php"] [unique_id "aqxZgApXMN3p_zkwXf2hXAAAAMk"]
[Thu Sep 17 15:20:00.233390 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.204.169.220:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZgApXMN3p_zkwXf2hYAAAAJw"]
[Thu Sep 17 15:20:00.250933 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/build/.env"] [unique_id "aqxZgApXMN3p_zkwXf2hYQAAAOY"]
[Thu Sep 17 15:20:00.280147 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/.env"] [unique_id "aqxZgApXMN3p_zkwXf2hYwAAAPU"]
[Thu Sep 17 15:20:00.344327 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgApXMN3p_zkwXf2hXwAAAP0"]
[Thu Sep 17 15:20:00.364582 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.95.61.66:49630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxZgApXMN3p_zkwXf2hZAAAAN4"]
[Thu Sep 17 15:20:00.481492 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/dist/.env"] [unique_id "aqxZgApXMN3p_zkwXf2haAAAAKs"]
[Thu Sep 17 15:20:00.546079 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.252.7.239:47500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/php.php"] [unique_id "aqxZgApXMN3p_zkwXf2hbAAAAOI"]
[Thu Sep 17 15:20:00.586189 2026] [security2:error] [pid 1012520:tid 1012728] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/das.php"] [unique_id "aqxZgApXMN3p_zkwXf2hbgAAANI"]
[Thu Sep 17 15:20:00.586313 2026] [security2:error] [pid 1012520:tid 1012728] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/das.php"] [unique_id "aqxZgApXMN3p_zkwXf2hbgAAANI"]
[Thu Sep 17 15:20:00.598337 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.95.61.66:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxZgApXMN3p_zkwXf2hbwAAAMc"]
[Thu Sep 17 15:20:00.677087 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.32.0.94:37876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZgApXMN3p_zkwXf2hawAAAKQ"]
[Thu Sep 17 15:20:00.678455 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgApXMN3p_zkwXf2hagAAANM"]
[Thu Sep 17 15:20:00.711842 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "aqxZgApXMN3p_zkwXf2hcwAAAO4"]
[Thu Sep 17 15:20:00.736852 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgApXMN3p_zkwXf2hcAAAAL4"]
[Thu Sep 17 15:20:00.798928 2026] [security2:error] [pid 1012520:tid 1012734] [client 185.104.184.228:33278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/js/"] [unique_id "aqxZgApXMN3p_zkwXf2hcQAAANg"]
[Thu Sep 17 15:20:00.850820 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.204.169.220:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZgApXMN3p_zkwXf2hdQAAALU"]
[Thu Sep 17 15:20:00.917718 2026] [security2:error] [pid 1012520:tid 1012732] [client 104.28.198.244:22902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZgApXMN3p_zkwXf2hegAAANY"]
[Thu Sep 17 15:20:00.917815 2026] [security2:error] [pid 1012520:tid 1012732] [client 104.28.198.244:22902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZgApXMN3p_zkwXf2hegAAANY"]
[Thu Sep 17 15:20:00.942707 2026] [security2:error] [pid 1012520:tid 1012710] [client 45.169.98.18:51878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.98.169.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZgApXMN3p_zkwXf2hfAAAAMA"]
[Thu Sep 17 15:20:00.942803 2026] [security2:error] [pid 1012520:tid 1012710] [client 45.169.98.18:51878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "berenice-vaucher.com"] [uri "/xmlrpc.php"] [unique_id "aqxZgApXMN3p_zkwXf2hfAAAAMA"]
[Thu Sep 17 15:20:00.949610 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/htdocs/.env"] [unique_id "aqxZgApXMN3p_zkwXf2hfQAAAJo"]
[Thu Sep 17 15:20:00.954297 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.95.61.66:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxZgApXMN3p_zkwXf2hfgAAANU"]
[Thu Sep 17 15:20:00.954537 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.32.0.94:37876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.seekingtheway.net"] [uri "/index.php"] [unique_id "aqxZgApXMN3p_zkwXf2hdAAAAPg"]
[Thu Sep 17 15:20:01.092283 2026] [security2:error] [pid 1012520:tid 1012670] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/coffexium.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hgQAAAJg"]
[Thu Sep 17 15:20:01.092392 2026] [security2:error] [pid 1012520:tid 1012670] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/coffexium.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hgQAAAJg"]
[Thu Sep 17 15:20:01.098199 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.252.7.239:50118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/i.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hggAAAIc"]
[Thu Sep 17 15:20:01.104067 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.32.0.94:37876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZgQpXMN3p_zkwXf2hgwAAAJ8"]
[Thu Sep 17 15:20:01.180145 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/www/.env"] [unique_id "aqxZgQpXMN3p_zkwXf2hhgAAALM"]
[Thu Sep 17 15:20:01.256985 2026] [security2:error] [pid 1012520:tid 1012658] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hhQAAAIw"]
[Thu Sep 17 15:20:01.268972 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.95.61.66:49672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hhwAAAQE"]
[Thu Sep 17 15:20:01.284446 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hhAAAAI8"]
[Thu Sep 17 15:20:01.406001 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.204.169.220:56784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hiAAAALE"]
[Thu Sep 17 15:20:01.409434 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/html/.env"] [unique_id "aqxZgQpXMN3p_zkwXf2hiQAAAOE"]
[Thu Sep 17 15:20:01.590449 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.32.0.94:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hkAAAAJ4"]
[Thu Sep 17 15:20:01.590571 2026] [security2:error] [pid 1012520:tid 1012770] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ccc.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hkQAAAPw"]
[Thu Sep 17 15:20:01.590672 2026] [security2:error] [pid 1012520:tid 1012770] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/ccc.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hkQAAAPw"]
[Thu Sep 17 15:20:01.637636 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.95.61.66:49682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hkwAAAN0"]
[Thu Sep 17 15:20:01.642926 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/live/.env"] [unique_id "aqxZgQpXMN3p_zkwXf2hlAAAALY"]
[Thu Sep 17 15:20:01.649273 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.252.7.239:50132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/pi.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hlQAAAL0"]
[Thu Sep 17 15:20:01.665541 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hjQAAAKk"]
[Thu Sep 17 15:20:01.757776 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hkgAAAO0"]
[Thu Sep 17 15:20:01.878443 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "aqxZgQpXMN3p_zkwXf2hmQAAAMY"]
[Thu Sep 17 15:20:01.906203 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.204.169.220:56788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hmgAAAQI"]
[Thu Sep 17 15:20:01.980052 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.95.61.66:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxZgQpXMN3p_zkwXf2hnQAAAMI"]
[Thu Sep 17 15:20:02.082259 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.32.0.94:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZggpXMN3p_zkwXf2hnwAAAMg"]
[Thu Sep 17 15:20:02.110023 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "aqxZggpXMN3p_zkwXf2hoAAAAPc"]
[Thu Sep 17 15:20:02.142953 2026] [security2:error] [pid 1012520:tid 1012763] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/eod.php"] [unique_id "aqxZggpXMN3p_zkwXf2hoQAAAPU"]
[Thu Sep 17 15:20:02.143058 2026] [security2:error] [pid 1012520:tid 1012763] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/eod.php"] [unique_id "aqxZggpXMN3p_zkwXf2hoQAAAPU"]
[Thu Sep 17 15:20:02.206678 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:50134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/pinfo.php"] [unique_id "aqxZggpXMN3p_zkwXf2hogAAAOY"]
[Thu Sep 17 15:20:02.209987 2026] [security2:error] [pid 1012520:tid 1012692] [client 186.105.232.15:62911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZggpXMN3p_zkwXf2howAAAK4"]
[Thu Sep 17 15:20:02.210294 2026] [security2:error] [pid 1012520:tid 1012692] [client 186.105.232.15:62911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZggpXMN3p_zkwXf2howAAAK4"]
[Thu Sep 17 15:20:02.288458 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.95.61.66:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZggpXMN3p_zkwXf2hpgAAAP0"]
[Thu Sep 17 15:20:02.342364 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "aqxZggpXMN3p_zkwXf2hpwAAAM4"]
[Thu Sep 17 15:20:02.346387 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZggpXMN3p_zkwXf2hpAAAAJU"]
[Thu Sep 17 15:20:02.407147 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZggpXMN3p_zkwXf2hpQAAAM8"]
[Thu Sep 17 15:20:02.542594 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.32.0.94:37914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZggpXMN3p_zkwXf2hrgAAAPk"]
[Thu Sep 17 15:20:02.561434 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.204.169.220:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZggpXMN3p_zkwXf2hsAAAAJ0"]
[Thu Sep 17 15:20:02.579385 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "aqxZggpXMN3p_zkwXf2hsQAAANE"]
[Thu Sep 17 15:20:02.602628 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.95.61.66:49706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZggpXMN3p_zkwXf2hsgAAANI"]
[Thu Sep 17 15:20:02.680440 2026] [security2:error] [pid 1012520:tid 1012764] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp-fcar.php"] [unique_id "aqxZggpXMN3p_zkwXf2hswAAAPY"]
[Thu Sep 17 15:20:02.680543 2026] [security2:error] [pid 1012520:tid 1012764] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp-fcar.php"] [unique_id "aqxZggpXMN3p_zkwXf2hswAAAPY"]
[Thu Sep 17 15:20:02.782196 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.252.7.239:50140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/test.php"] [unique_id "aqxZggpXMN3p_zkwXf2htQAAAOU"]
[Thu Sep 17 15:20:02.812519 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "aqxZggpXMN3p_zkwXf2htgAAAL4"]
[Thu Sep 17 15:20:02.920383 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.95.61.66:49708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZggpXMN3p_zkwXf2huQAAANs"]
[Thu Sep 17 15:20:03.022572 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.32.0.94:37926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZgwpXMN3p_zkwXf2hvQAAANk"]
[Thu Sep 17 15:20:03.030550 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZggpXMN3p_zkwXf2huAAAANg"]
[Thu Sep 17 15:20:03.054336 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.166.228.3:41132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/symfony/.env"] [unique_id "aqxZgwpXMN3p_zkwXf2hvgAAAJc"]
[Thu Sep 17 15:20:03.097907 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/.env.bak"] [unique_id "aqxZgwpXMN3p_zkwXf2hvwAAAOQ"]
[Thu Sep 17 15:20:03.127640 2026] [security2:error] [pid 1012520:tid 1012686] [client 185.104.184.228:33278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/js/codemirror/"] [unique_id "aqxZgwpXMN3p_zkwXf2hwAAAAKg"]
[Thu Sep 17 15:20:03.226652 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.204.169.220:56806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZgwpXMN3p_zkwXf2hwwAAANU"]
[Thu Sep 17 15:20:03.226929 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/bbfvhvla.php"] [unique_id "aqxZgwpXMN3p_zkwXf2hxAAAALc"]
[Thu Sep 17 15:20:03.226996 2026] [security2:error] [pid 1012520:tid 1012701] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/bbfvhvla.php"] [unique_id "aqxZgwpXMN3p_zkwXf2hxAAAALc"]
[Thu Sep 17 15:20:03.237712 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.95.61.66:49712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZgwpXMN3p_zkwXf2hxQAAAJ8"]
[Thu Sep 17 15:20:03.278412 2026] [security2:error] [pid 1012520:tid 1012658] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/.env.backup"] [unique_id "aqxZgwpXMN3p_zkwXf2hxgAAAIw"]
[Thu Sep 17 15:20:03.496681 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.32.0.94:37930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZgwpXMN3p_zkwXf2h0wAAAOg"]
[Thu Sep 17 15:20:03.505795 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgwpXMN3p_zkwXf2hygAAAKI"]
[Thu Sep 17 15:20:03.548037 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.95.61.66:49728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZgwpXMN3p_zkwXf2h2AAAAK8"]
[Thu Sep 17 15:20:03.592729 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZgwpXMN3p_zkwXf2h0AAAALY"]
[Thu Sep 17 15:20:03.739922 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/wordpress/.env"] [unique_id "aqxZgwpXMN3p_zkwXf2h2wAAAPo"]
[Thu Sep 17 15:20:03.746935 2026] [security2:error] [pid 1012520:tid 1012771] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/hjmduqnw.php"] [unique_id "aqxZgwpXMN3p_zkwXf2h3AAAAP0"]
[Thu Sep 17 15:20:03.747045 2026] [security2:error] [pid 1012520:tid 1012771] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/hjmduqnw.php"] [unique_id "aqxZgwpXMN3p_zkwXf2h3AAAAP0"]
[Thu Sep 17 15:20:03.823632 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.95.61.66:49730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZgwpXMN3p_zkwXf2h3wAAAPI"]
[Thu Sep 17 15:20:03.851904 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZgwpXMN3p_zkwXf2hzwAAAJs"]
[Thu Sep 17 15:20:03.854781 2026] [security2:error] [pid 1012520:tid 1012528] [remote 111.225.149.167:37388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/200-Treasure-hunt-240x300.jpg"] [unique_id "aqxZgwpXMN3p_zkwXf2h4QAAzgY"]
[Thu Sep 17 15:20:03.855754 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.204.169.220:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZgwpXMN3p_zkwXf2h4gAAAMg"]
[Thu Sep 17 15:20:03.924233 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/.env.old"] [unique_id "aqxZgwpXMN3p_zkwXf2h4wAAAKs"]
[Thu Sep 17 15:20:03.937570 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/.env.bak"] [unique_id "aqxZgwpXMN3p_zkwXf2h5AAAAPQ"]
[Thu Sep 17 15:20:03.950027 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.32.0.94:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxZgwpXMN3p_zkwXf2h5QAAAJw"]
[Thu Sep 17 15:20:03.969569 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/wp/.env"] [unique_id "aqxZgwpXMN3p_zkwXf2h5gAAAJ0"]
[Thu Sep 17 15:20:04.132264 2026] [security2:error] [pid 1012520:tid 1012763] [client 154.190.208.131:42653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhApXMN3p_zkwXf2h6wAAAPU"]
[Thu Sep 17 15:20:04.132410 2026] [security2:error] [pid 1012520:tid 1012763] [client 154.190.208.131:42653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhApXMN3p_zkwXf2h6wAAAPU"]
[Thu Sep 17 15:20:04.134482 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/.env.backup"] [unique_id "aqxZhApXMN3p_zkwXf2h7AAAALs"]
[Thu Sep 17 15:20:04.153171 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.95.61.66:49738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZhApXMN3p_zkwXf2h7QAAAKw"]
[Thu Sep 17 15:20:04.198650 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "aqxZhApXMN3p_zkwXf2h7gAAAIs"]
[Thu Sep 17 15:20:04.207898 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhApXMN3p_zkwXf2h6gAAAMU"]
[Thu Sep 17 15:20:04.253703 2026] [security2:error] [pid 1012520:tid 1012733] [client 103.61.184.148:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhApXMN3p_zkwXf2h7wAAANc"]
[Thu Sep 17 15:20:04.253853 2026] [security2:error] [pid 1012520:tid 1012733] [client 103.61.184.148:59349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhApXMN3p_zkwXf2h7wAAANc"]
[Thu Sep 17 15:20:04.261119 2026] [security2:error] [pid 1012520:tid 1012753] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/0xD.php"] [unique_id "aqxZhApXMN3p_zkwXf2h8AAAAOs"]
[Thu Sep 17 15:20:04.261201 2026] [security2:error] [pid 1012520:tid 1012753] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/0xD.php"] [unique_id "aqxZhApXMN3p_zkwXf2h8AAAAOs"]
[Thu Sep 17 15:20:04.313070 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.252.7.239:50150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/p.php"] [unique_id "aqxZhApXMN3p_zkwXf2h8QAAAP8"]
[Thu Sep 17 15:20:04.374087 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.204.169.220:56828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.169.204.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hopmanchaissconsulting.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZhApXMN3p_zkwXf2h8gAAAME"]
[Thu Sep 17 15:20:04.404177 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.32.0.94:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/phpinfo.php.old"] [unique_id "aqxZhApXMN3p_zkwXf2h9QAAALw"]
[Thu Sep 17 15:20:04.426803 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/drupal/.env"] [unique_id "aqxZhApXMN3p_zkwXf2h9gAAAKM"]
[Thu Sep 17 15:20:04.493575 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhApXMN3p_zkwXf2h9AAAAMo"]
[Thu Sep 17 15:20:04.553916 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.95.61.66:49740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZhApXMN3p_zkwXf2h-gAAAMw"]
[Thu Sep 17 15:20:04.632960 2026] [security2:error] [pid 1012520:tid 1012698] [client 185.55.149.49:54870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZhApXMN3p_zkwXf2h-wAAALQ"]
[Thu Sep 17 15:20:04.633289 2026] [security2:error] [pid 1012520:tid 1012698] [client 185.55.149.49:54870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZhApXMN3p_zkwXf2h-wAAALQ"]
[Thu Sep 17 15:20:04.654308 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/joomla/.env"] [unique_id "aqxZhApXMN3p_zkwXf2h_QAAAKo"]
[Thu Sep 17 15:20:04.764489 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhApXMN3p_zkwXf2h_AAAAIc"]
[Thu Sep 17 15:20:04.774575 2026] [security2:error] [pid 1012520:tid 1012772] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/ALIepiuZMoB.php"] [unique_id "aqxZhApXMN3p_zkwXf2h_gAAAP4"]
[Thu Sep 17 15:20:04.774671 2026] [security2:error] [pid 1012520:tid 1012772] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/ALIepiuZMoB.php"] [unique_id "aqxZhApXMN3p_zkwXf2h_gAAAP4"]
[Thu Sep 17 15:20:04.858271 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.32.0.94:46656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/phpinfo.php~"] [unique_id "aqxZhApXMN3p_zkwXf2h_wAAAJ8"]
[Thu Sep 17 15:20:04.869138 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.252.7.239:50158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/debug.php"] [unique_id "aqxZhApXMN3p_zkwXf2iAAAAALM"]
[Thu Sep 17 15:20:04.882542 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/magento/.env"] [unique_id "aqxZhApXMN3p_zkwXf2iAQAAAOE"]
[Thu Sep 17 15:20:04.890520 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.95.61.66:49748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-75ec2a07.cas.ise.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZhApXMN3p_zkwXf2iBAAAAMA"]
[Thu Sep 17 15:20:04.927779 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/.env.old"] [unique_id "aqxZhApXMN3p_zkwXf2iBQAAAO8"]
[Thu Sep 17 15:20:05.111989 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/shopify/.env"] [unique_id "aqxZhQpXMN3p_zkwXf2iDgAAAJM"]
[Thu Sep 17 15:20:05.238130 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iDQAAAKk"]
[Thu Sep 17 15:20:05.283231 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/sehryhv.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iFAAAAJE"]
[Thu Sep 17 15:20:05.283360 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/sehryhv.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iFAAAAJE"]
[Thu Sep 17 15:20:05.332619 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.32.0.94:46666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/info.php.bak"] [unique_id "aqxZhQpXMN3p_zkwXf2iFwAAAOg"]
[Thu Sep 17 15:20:05.342582 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/prestashop/.env"] [unique_id "aqxZhQpXMN3p_zkwXf2iGAAAAJk"]
[Thu Sep 17 15:20:05.371561 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iEQAAAOo"]
[Thu Sep 17 15:20:05.418560 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.252.7.239:50160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iHwAAALY"]
[Thu Sep 17 15:20:05.570130 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/codeigniter/.env"] [unique_id "aqxZhQpXMN3p_zkwXf2iKgAAAM8"]
[Thu Sep 17 15:20:05.777598 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iMQAAAKw"]
[Thu Sep 17 15:20:05.778501 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.32.0.94:46682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/phpinfo.php.save"] [unique_id "aqxZhQpXMN3p_zkwXf2iOgAAAMs"]
[Thu Sep 17 15:20:05.798878 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cakephp/.env"] [unique_id "aqxZhQpXMN3p_zkwXf2iPAAAAME"]
[Thu Sep 17 15:20:05.802058 2026] [security2:error] [pid 1012520:tid 1012736] [client 114.198.138.124:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iPgAAANo"]
[Thu Sep 17 15:20:05.802152 2026] [security2:error] [pid 1012520:tid 1012736] [client 114.198.138.124:54384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iPgAAANo"]
[Thu Sep 17 15:20:05.803770 2026] [security2:error] [pid 1012520:tid 1012699] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/sallu.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iPwAAALU"]
[Thu Sep 17 15:20:05.803835 2026] [security2:error] [pid 1012520:tid 1012699] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/sallu.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iPwAAALU"]
[Thu Sep 17 15:20:05.847927 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iNQAAAMU"]
[Thu Sep 17 15:20:05.899749 2026] [security2:error] [pid 1012520:tid 1012714] [client 185.104.184.228:33278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.freeofgravity.com"] [uri "/index.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iKAAAAMQ"]
[Thu Sep 17 15:20:05.899772 2026] [security2:error] [pid 1012520:tid 1012714] [client 185.104.184.228:33278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.freeofgravity.com"] [uri "/index.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iKAAAAMQ"]
[Thu Sep 17 15:20:05.973959 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.252.7.239:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZhQpXMN3p_zkwXf2iRQAAAIk"]
[Thu Sep 17 15:20:06.026190 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/zend/.env"] [unique_id "aqxZhgpXMN3p_zkwXf2iSwAAAIw"]
[Thu Sep 17 15:20:06.170716 2026] [core:error] [pid 1012520:tid 1012742] [client 52.167.144.57:44094] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:06.170738 2026] [core:error] [pid 1012520:tid 1012742] [client 52.167.144.57:44094] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:06.230558 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.32.0.94:46686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iWAAAAMA"]
[Thu Sep 17 15:20:06.253730 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/yii/.env"] [unique_id "aqxZhgpXMN3p_zkwXf2iWgAAAPM"]
[Thu Sep 17 15:20:06.268836 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iUQAAALA"]
[Thu Sep 17 15:20:06.286205 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iUwAAAJM"]
[Thu Sep 17 15:20:06.298067 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/JYza3bd9LMT.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iXAAAAJE"]
[Thu Sep 17 15:20:06.298169 2026] [security2:error] [pid 1012520:tid 1012663] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/JYza3bd9LMT.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iXAAAAJE"]
[Thu Sep 17 15:20:06.481392 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/laravel5/.env"] [unique_id "aqxZhgpXMN3p_zkwXf2iYgAAAN4"]
[Thu Sep 17 15:20:06.523851 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.252.7.239:50174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iZQAAAOY"]
[Thu Sep 17 15:20:06.652563 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iZgAAAJU"]
[Thu Sep 17 15:20:06.667919 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhgpXMN3p_zkwXf2iZwAAAKs"]
[Thu Sep 17 15:20:06.675608 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.32.0.94:46702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxZhgpXMN3p_zkwXf2ibQAAAM4"]
[Thu Sep 17 15:20:06.709333 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "aqxZhgpXMN3p_zkwXf2ibgAAAKQ"]
[Thu Sep 17 15:20:06.798827 2026] [security2:error] [pid 1012520:tid 1012747] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/disagrsxr.php"] [unique_id "aqxZhgpXMN3p_zkwXf2ieAAAAOU"]
[Thu Sep 17 15:20:06.798906 2026] [security2:error] [pid 1012520:tid 1012747] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/disagrsxr.php"] [unique_id "aqxZhgpXMN3p_zkwXf2ieAAAAOU"]
[Thu Sep 17 15:20:06.943196 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "aqxZhgpXMN3p_zkwXf2ijwAAANs"]
[Thu Sep 17 15:20:07.031794 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhgpXMN3p_zkwXf2ijQAAAMs"]
[Thu Sep 17 15:20:07.079617 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.252.7.239:50176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZhwpXMN3p_zkwXf2imQAAAK8"]
[Thu Sep 17 15:20:07.139548 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.32.0.94:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxZhwpXMN3p_zkwXf2inAAAAJI"]
[Thu Sep 17 15:20:07.168819 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2imAAAAPg"]
[Thu Sep 17 15:20:07.172621 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "aqxZhwpXMN3p_zkwXf2inQAAAKo"]
[Thu Sep 17 15:20:07.322214 2026] [security2:error] [pid 1012520:tid 1012654] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/wp-admin/maint/fff.php"] [unique_id "aqxZhwpXMN3p_zkwXf2ipQAAAIg"]
[Thu Sep 17 15:20:07.322306 2026] [security2:error] [pid 1012520:tid 1012654] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "moneysmartlatina.com"] [uri "/wp-admin/maint/fff.php"] [unique_id "aqxZhwpXMN3p_zkwXf2ipQAAAIg"]
[Thu Sep 17 15:20:07.330276 2026] [security2:error] [pid 1012520:tid 1012662] [client 31.171.54.53:13753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2ioQAAAJA"]
[Thu Sep 17 15:20:07.409118 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/v1/.env"] [unique_id "aqxZhwpXMN3p_zkwXf2ipwAAAKI"]
[Thu Sep 17 15:20:07.578299 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2iqAAAALc"]
[Thu Sep 17 15:20:07.595384 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.32.0.94:46710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxZhwpXMN3p_zkwXf2isAAAAMo"]
[Thu Sep 17 15:20:07.602146 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2iqQAAAKk"]
[Thu Sep 17 15:20:07.626971 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZhwpXMN3p_zkwXf2isQAAAM0"]
[Thu Sep 17 15:20:07.637178 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/v2/.env"] [unique_id "aqxZhwpXMN3p_zkwXf2isgAAAIU"]
[Thu Sep 17 15:20:07.854558 2026] [security2:error] [pid 1012520:tid 1012777] [client 156.192.234.52:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhwpXMN3p_zkwXf2itAAAAQM"]
[Thu Sep 17 15:20:07.854721 2026] [security2:error] [pid 1012520:tid 1012777] [client 156.192.234.52:61089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZhwpXMN3p_zkwXf2itAAAAQM"]
[Thu Sep 17 15:20:07.865622 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/rest/.env"] [unique_id "aqxZhwpXMN3p_zkwXf2itgAAAO0"]
[Thu Sep 17 15:20:07.984111 2026] [security2:error] [pid 1012520:tid 1012749] [client 172.58.182.131:28298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2iswAA5z8"], referer: https://churchinirving.org/announcements/
[Thu Sep 17 15:20:08.079103 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.32.0.94:46716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxZiApXMN3p_zkwXf2ivQAAALI"]
[Thu Sep 17 15:20:08.089404 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2iugAAAOo"]
[Thu Sep 17 15:20:08.097426 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/graphql/.env"] [unique_id "aqxZiApXMN3p_zkwXf2ivwAAALE"]
[Thu Sep 17 15:20:08.126434 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2iuAAAAI0"]
[Thu Sep 17 15:20:08.192900 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.252.7.239:50188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZiApXMN3p_zkwXf2iwwAAAKE"]
[Thu Sep 17 15:20:08.218471 2026] [security2:error] [pid 1012520:tid 1012663] [client 162.241.226.11:11442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxZhwpXMN3p_zkwXf2irQAAAJE"]
[Thu Sep 17 15:20:08.326777 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/gateway/.env"] [unique_id "aqxZiApXMN3p_zkwXf2iyAAAAN8"]
[Thu Sep 17 15:20:08.546635 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiApXMN3p_zkwXf2iywAAAQI"]
[Thu Sep 17 15:20:08.550758 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.32.0.94:46728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/www/phpinfo.php"] [unique_id "aqxZiApXMN3p_zkwXf2i0gAAAOU"]
[Thu Sep 17 15:20:08.562550 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/microservice/.env"] [unique_id "aqxZiApXMN3p_zkwXf2i0wAAAME"]
[Thu Sep 17 15:20:08.645248 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiApXMN3p_zkwXf2i0AAAAOI"]
[Thu Sep 17 15:20:08.791074 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "aqxZiApXMN3p_zkwXf2i2AAAAMU"]
[Thu Sep 17 15:20:08.897882 2026] [security2:error] [pid 1012520:tid 1012763] [client 162.241.226.11:11456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxZiApXMN3p_zkwXf2ixAAAAPU"]
[Thu Sep 17 15:20:08.946181 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiApXMN3p_zkwXf2i2QAAAPY"]
[Thu Sep 17 15:20:08.994159 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZiApXMN3p_zkwXf2i1wAAAOw"]
[Thu Sep 17 15:20:09.013692 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.32.0.94:46734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZiQpXMN3p_zkwXf2i3AAAAOQ"]
[Thu Sep 17 15:20:09.018555 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/v3/.env"] [unique_id "aqxZiQpXMN3p_zkwXf2i3gAAAL4"]
[Thu Sep 17 15:20:09.130575 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiQpXMN3p_zkwXf2i3wAAAIY"]
[Thu Sep 17 15:20:09.245947 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/dev/.env"] [unique_id "aqxZiQpXMN3p_zkwXf2i5QAAANk"]
[Thu Sep 17 15:20:09.263340 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/.env.swp"] [unique_id "aqxZiQpXMN3p_zkwXf2i5wAAANA"]
[Thu Sep 17 15:20:09.384196 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.252.7.239:50192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/php-info.php"] [unique_id "aqxZiQpXMN3p_zkwXf2i6AAAAJ8"]
[Thu Sep 17 15:20:09.479872 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/staging/.env"] [unique_id "aqxZiQpXMN3p_zkwXf2i6QAAAOA"]
[Thu Sep 17 15:20:09.489783 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.32.0.94:46750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZiQpXMN3p_zkwXf2i6gAAANY"]
[Thu Sep 17 15:20:09.510728 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/.env~"] [unique_id "aqxZiQpXMN3p_zkwXf2i7QAAAJA"]
[Thu Sep 17 15:20:09.707930 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/vendor/.env"] [unique_id "aqxZiQpXMN3p_zkwXf2i9gAAAK0"]
[Thu Sep 17 15:20:09.733459 2026] [security2:error] [pid 1012520:tid 1012658] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiQpXMN3p_zkwXf2i8gAAAIw"]
[Thu Sep 17 15:20:09.800105 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiQpXMN3p_zkwXf2i9QAAAPw"]
[Thu Sep 17 15:20:09.936377 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/lib/.env"] [unique_id "aqxZiQpXMN3p_zkwXf2i_gAAAPc"]
[Thu Sep 17 15:20:09.937952 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.252.7.239:50202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/phpversion.php"] [unique_id "aqxZiQpXMN3p_zkwXf2i_wAAAKk"]
[Thu Sep 17 15:20:09.953872 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.32.0.94:46754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/site/phpinfo.php"] [unique_id "aqxZiQpXMN3p_zkwXf2jAAAAAIU"]
[Thu Sep 17 15:20:10.170130 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/resources/.env"] [unique_id "aqxZigpXMN3p_zkwXf2jCgAAAKE"]
[Thu Sep 17 15:20:10.242057 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZigpXMN3p_zkwXf2jCQAAAM4"]
[Thu Sep 17 15:20:10.364257 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZigpXMN3p_zkwXf2jDAAAAMg"]
[Thu Sep 17 15:20:10.401339 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/assets/.env"] [unique_id "aqxZigpXMN3p_zkwXf2jEAAAAN8"]
[Thu Sep 17 15:20:10.417438 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.32.0.94:46768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxZigpXMN3p_zkwXf2jEQAAAJ4"]
[Thu Sep 17 15:20:10.447010 2026] [authz_core:error] [pid 1012520:tid 1012719] [client 169.58.197.253:50698] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:20:10.491782 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.252.7.239:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/_phpinfo.php"] [unique_id "aqxZigpXMN3p_zkwXf2jEwAAANM"]
[Thu Sep 17 15:20:10.508272 2026] [security2:error] [pid 1012520:tid 1012660] [client 185.104.184.228:33278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.freeofgravity.com"] [uri "/index.php"] [unique_id "aqxZigpXMN3p_zkwXf2jEgAAAI4"]
[Thu Sep 17 15:20:10.508300 2026] [security2:error] [pid 1012520:tid 1012660] [client 185.104.184.228:33278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.freeofgravity.com"] [uri "/index.php"] [unique_id "aqxZigpXMN3p_zkwXf2jEgAAAI4"]
[Thu Sep 17 15:20:10.600764 2026] [security2:error] [pid 1012520:tid 1012733] [client 162.241.226.11:40954] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxZigpXMN3p_zkwXf2jGAAAANc"]
[Thu Sep 17 15:20:10.629718 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/uploads/.env"] [unique_id "aqxZigpXMN3p_zkwXf2jGwAAALw"]
[Thu Sep 17 15:20:10.648275 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/.env.swp"] [unique_id "aqxZigpXMN3p_zkwXf2jHAAAAOs"]
[Thu Sep 17 15:20:10.743568 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZigpXMN3p_zkwXf2jGgAAAMc"]
[Thu Sep 17 15:20:10.825083 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/.env~"] [unique_id "aqxZigpXMN3p_zkwXf2jHgAAAMw"]
[Thu Sep 17 15:20:10.857777 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/internal/.env"] [unique_id "aqxZigpXMN3p_zkwXf2jIwAAAKg"]
[Thu Sep 17 15:20:10.863363 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.32.0.94:46772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZigpXMN3p_zkwXf2jJAAAAPs"]
[Thu Sep 17 15:20:11.041502 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.252.7.239:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jKwAAAIY"]
[Thu Sep 17 15:20:11.086234 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/tools/.env"] [unique_id "aqxZiwpXMN3p_zkwXf2jLAAAAIc"]
[Thu Sep 17 15:20:11.127994 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jKQAAAJY"]
[Thu Sep 17 15:20:11.313109 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/scripts/.env"] [unique_id "aqxZiwpXMN3p_zkwXf2jMwAAAK0"]
[Thu Sep 17 15:20:11.322759 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.32.0.94:46788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jNAAAAJ8"]
[Thu Sep 17 15:20:11.540628 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/bin/.env"] [unique_id "aqxZiwpXMN3p_zkwXf2jOgAAALA"]
[Thu Sep 17 15:20:11.587929 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.252.7.239:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/server-info.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jPAAAAMY"]
[Thu Sep 17 15:20:11.594877 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jNwAAAM0"]
[Thu Sep 17 15:20:11.600602 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jOAAAAL0"]
[Thu Sep 17 15:20:11.769634 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sbin/.env"] [unique_id "aqxZiwpXMN3p_zkwXf2jQwAAAL8"]
[Thu Sep 17 15:20:11.792108 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.32.0.94:46798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/core/phpinfo.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jRAAAAPc"]
[Thu Sep 17 15:20:12.008639 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jSQAAAJ0"]
[Thu Sep 17 15:20:12.119634 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZiwpXMN3p_zkwXf2jRgAAAOY"]
[Thu Sep 17 15:20:12.127399 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZjApXMN3p_zkwXf2jSgAAAJQ"]
[Thu Sep 17 15:20:12.165161 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.252.7.239:49884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/server-status.php"] [unique_id "aqxZjApXMN3p_zkwXf2jUAAAAPQ"]
[Thu Sep 17 15:20:12.242700 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jUwAAAP8"]
[Thu Sep 17 15:20:12.289645 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.32.0.94:46802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.0.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seekingtheway.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxZjApXMN3p_zkwXf2jVAAAAMg"]
[Thu Sep 17 15:20:12.470774 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/dashboard/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jWQAAAQM"]
[Thu Sep 17 15:20:12.485237 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/app/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jWgAAAQQ"]
[Thu Sep 17 15:20:12.698847 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/panel/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jYAAAAMs"]
[Thu Sep 17 15:20:12.751433 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/apps/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jYwAAAPU"]
[Thu Sep 17 15:20:12.920306 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/api/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jaQAAAOQ"]
[Thu Sep 17 15:20:12.927019 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "aqxZjApXMN3p_zkwXf2jagAAAL4"]
[Thu Sep 17 15:20:12.972167 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZjApXMN3p_zkwXf2jZwAAAMU"]
[Thu Sep 17 15:20:13.036788 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZjApXMN3p_zkwXf2jZgAAAJw"]
[Thu Sep 17 15:20:13.154387 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jcQAAAJY"]
[Thu Sep 17 15:20:13.154387 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/web/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jcAAAAIs"]
[Thu Sep 17 15:20:13.188266 2026] [security2:error] [pid 1012520:tid 1012722] [client 186.105.232.15:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZjQpXMN3p_zkwXf2jcgAAAMw"]
[Thu Sep 17 15:20:13.188412 2026] [security2:error] [pid 1012520:tid 1012722] [client 186.105.232.15:63500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZjQpXMN3p_zkwXf2jcgAAAMw"]
[Thu Sep 17 15:20:13.383615 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jdgAAAKA"]
[Thu Sep 17 15:20:13.383615 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/site/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jdQAAAJo"]
[Thu Sep 17 15:20:13.383767 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZjQpXMN3p_zkwXf2jdAAAAPg"]
[Thu Sep 17 15:20:13.612949 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/public/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jggAAAJg"]
[Thu Sep 17 15:20:13.624173 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/store/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jgwAAALA"]
[Thu Sep 17 15:20:13.704347 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.252.7.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxZjQpXMN3p_zkwXf2jewAAAJc"]
[Thu Sep 17 15:20:13.852186 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/saas/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jigAAAPE"]
[Thu Sep 17 15:20:13.899755 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:49086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZjQpXMN3p_zkwXf2jiAAAAL8"]
[Thu Sep 17 15:20:13.903824 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/app/.env"] [unique_id "aqxZjQpXMN3p_zkwXf2jiwAAAQE"]
[Thu Sep 17 15:20:13.908920 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.252.7.239:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZjQpXMN3p_zkwXf2jjAAAAKU"]
[Thu Sep 17 15:20:14.079954 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jlAAAAO8"]
[Thu Sep 17 15:20:14.115866 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/apps/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jlQAAAN8"]
[Thu Sep 17 15:20:14.277172 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/backend/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jmAAAAP8"]
[Thu Sep 17 15:20:14.303463 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/api/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jmgAAAMk"]
[Thu Sep 17 15:20:14.307144 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jmwAAAO4"]
[Thu Sep 17 15:20:14.453861 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.252.7.239:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZjgpXMN3p_zkwXf2jngAAAOo"]
[Thu Sep 17 15:20:14.462333 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/server/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jnwAAAKQ"]
[Thu Sep 17 15:20:14.470932 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/web/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2joAAAAME"]
[Thu Sep 17 15:20:14.535205 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/admin-panel/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jqAAAAOI"]
[Thu Sep 17 15:20:14.564844 2026] [security2:error] [pid 1012520:tid 1012667] [client 192.178.6.4:37775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxZjgpXMN3p_zkwXf2jqQAAAJU"]
[Thu Sep 17 15:20:14.634999 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/frontend/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jrQAAANE"]
[Thu Sep 17 15:20:14.640390 2026] [security2:error] [pid 1012520:tid 1012762] [client 154.190.208.131:42031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZjgpXMN3p_zkwXf2jrgAAAPQ"]
[Thu Sep 17 15:20:14.647380 2026] [security2:error] [pid 1012520:tid 1012762] [client 154.190.208.131:42031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZjgpXMN3p_zkwXf2jrgAAAPQ"]
[Thu Sep 17 15:20:14.660619 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/site/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jsAAAAMc"]
[Thu Sep 17 15:20:14.762296 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/control-panel/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jsgAAAPY"]
[Thu Sep 17 15:20:14.831906 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/public/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jswAAAOQ"]
[Thu Sep 17 15:20:14.872862 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/src/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jtwAAAPk"]
[Thu Sep 17 15:20:14.941191 2026] [security2:error] [pid 1012520:tid 1012737] [client 103.61.184.148:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZjgpXMN3p_zkwXf2juQAAANs"]
[Thu Sep 17 15:20:14.941305 2026] [security2:error] [pid 1012520:tid 1012737] [client 103.61.184.148:59909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZjgpXMN3p_zkwXf2juQAAANs"]
[Thu Sep 17 15:20:14.989948 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/user-panel/.env"] [unique_id "aqxZjgpXMN3p_zkwXf2jvgAAAMw"]
[Thu Sep 17 15:20:15.008080 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.252.7.239:49898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZjwpXMN3p_zkwXf2jvwAAAKM"]
[Thu Sep 17 15:20:15.089160 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/core/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2jxwAAAOA"]
[Thu Sep 17 15:20:15.156705 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.247.203.201:60178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZjwpXMN3p_zkwXf2jxAAAAJI"]
[Thu Sep 17 15:20:15.219511 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2jzgAAAN0"]
[Thu Sep 17 15:20:15.264642 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/core/app/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2jzwAAALA"]
[Thu Sep 17 15:20:15.448046 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/express/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j2wAAAKs"]
[Thu Sep 17 15:20:15.469891 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/config/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j3QAAAPE"]
[Thu Sep 17 15:20:15.526932 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/backend/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j4AAAAJ0"]
[Thu Sep 17 15:20:15.562232 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.252.7.239:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZjwpXMN3p_zkwXf2j4gAAAJ8"]
[Thu Sep 17 15:20:15.662459 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/private/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j5wAAANM"]
[Thu Sep 17 15:20:15.677006 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/next/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j6gAAAPM"]
[Thu Sep 17 15:20:15.733116 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/server/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j7QAAAMA"]
[Thu Sep 17 15:20:15.801320 2026] [security2:error] [pid 1012520:tid 1012676] [client 185.55.149.49:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZjwpXMN3p_zkwXf2j7gAAAJ4"]
[Thu Sep 17 15:20:15.801424 2026] [security2:error] [pid 1012520:tid 1012676] [client 185.55.149.49:55532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZjwpXMN3p_zkwXf2j7gAAAJ4"]
[Thu Sep 17 15:20:15.813205 2026] [security2:error] [pid 1012520:tid 1012671] [client 178.20.45.128:51369] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.45.128" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "daprayer.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZjwpXMN3p_zkwXf2j7wAAAJk"], referer: https://daprayer.com/baby-e-the-birth-story/
[Thu Sep 17 15:20:15.813313 2026] [security2:error] [pid 1012520:tid 1012671] [client 178.20.45.128:51369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "daprayer.com"] [uri "/wp-comments-post.php"] [unique_id "aqxZjwpXMN3p_zkwXf2j7wAAAJk"], referer: https://daprayer.com/baby-e-the-birth-story/
[Thu Sep 17 15:20:15.842768 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/application/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j8AAAAME"]
[Thu Sep 17 15:20:15.905895 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/nuxt/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j8gAAAJU"]
[Thu Sep 17 15:20:15.932717 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/frontend/.env"] [unique_id "aqxZjwpXMN3p_zkwXf2j8wAAAQQ"]
[Thu Sep 17 15:20:16.015997 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/bootstrap/.env"] [unique_id "aqxZkApXMN3p_zkwXf2j-wAAAK4"]
[Thu Sep 17 15:20:16.119644 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.252.7.239:49922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZkApXMN3p_zkwXf2j_wAAAIo"]
[Thu Sep 17 15:20:16.135698 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/nest/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kAAAAAPk"]
[Thu Sep 17 15:20:16.155265 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/src/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kAQAAANo"]
[Thu Sep 17 15:20:16.198749 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/database/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kAgAAALY"]
[Thu Sep 17 15:20:16.284320 2026] [security2:error] [pid 1012520:tid 1012746] [client 114.198.138.124:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZkApXMN3p_zkwXf2kBQAAAOQ"]
[Thu Sep 17 15:20:16.284423 2026] [security2:error] [pid 1012520:tid 1012746] [client 114.198.138.124:55032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZkApXMN3p_zkwXf2kBQAAAOQ"]
[Thu Sep 17 15:20:16.363476 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/react/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kCAAAAIY"]
[Thu Sep 17 15:20:16.377125 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/storage/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kCQAAAN0"]
[Thu Sep 17 15:20:16.394960 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/core/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kCgAAAMo"]
[Thu Sep 17 15:20:16.550098 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/var/www/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kEgAAAKk"]
[Thu Sep 17 15:20:16.591636 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/vue/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kFAAAAPs"]
[Thu Sep 17 15:20:16.612391 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/core/app/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kFQAAANY"]
[Thu Sep 17 15:20:16.683245 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.252.7.239:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZkApXMN3p_zkwXf2kFgAAAJY"]
[Thu Sep 17 15:20:16.733226 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/var/www/html/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kFwAAANU"]
[Thu Sep 17 15:20:16.815910 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/config/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kGAAAAJ0"]
[Thu Sep 17 15:20:16.820015 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/angular/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kGQAAAJ8"]
[Thu Sep 17 15:20:16.907509 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/current/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kGgAAALE"]
[Thu Sep 17 15:20:16.991078 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/private/.env"] [unique_id "aqxZkApXMN3p_zkwXf2kHQAAAKI"]
[Thu Sep 17 15:20:17.051166 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/svelte/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kIQAAALM"]
[Thu Sep 17 15:20:17.093089 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/release/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kIgAAAMA"]
[Thu Sep 17 15:20:17.182295 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/application/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kIwAAAQE"]
[Thu Sep 17 15:20:17.216167 2026] [core:error] [pid 1012520:tid 1012758] [client 40.77.167.40:53092] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:17.216180 2026] [core:error] [pid 1012520:tid 1012758] [client 40.77.167.40:53092] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:17.240171 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.252.7.239:49946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZkQpXMN3p_zkwXf2kKAAAAMk"]
[Thu Sep 17 15:20:17.272758 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/releases/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kKQAAAJ4"]
[Thu Sep 17 15:20:17.278136 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/vite/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kKgAAAME"]
[Thu Sep 17 15:20:17.379293 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/bootstrap/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kMAAAAJU"]
[Thu Sep 17 15:20:17.440796 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/shared/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kMgAAAJM"]
[Thu Sep 17 15:20:17.506541 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kMwAAANc"]
[Thu Sep 17 15:20:17.551297 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/database/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kNgAAALw"]
[Thu Sep 17 15:20:17.647402 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/deploy/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kOQAAAMs"]
[Thu Sep 17 15:20:17.725514 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/storage/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kOgAAAMQ"]
[Thu Sep 17 15:20:17.725722 2026] [security2:error] [pid 1012520:tid 1012578] [remote 47.128.35.227:21148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "league.cyberpunkonline.net"] [uri "/robots.txt"] [unique_id "aqxZkQpXMN3p_zkwXf2kOwAArDg"]
[Thu Sep 17 15:20:17.734224 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/backups/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kPAAAANs"]
[Thu Sep 17 15:20:17.812909 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.252.7.239:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZkQpXMN3p_zkwXf2kPwAAAOw"]
[Thu Sep 17 15:20:17.828389 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/build/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kQAAAAMc"]
[Thu Sep 17 15:20:17.876934 2026] [security2:error] [pid 1012520:tid 1012778] [client 43.164.197.117:38236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.197.164.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "groverpdx.net"] [uri "/wp-login.php"] [unique_id "aqxZkQpXMN3p_zkwXf2kPgAAAQQ"], referer: https://groverpdx.net/
[Thu Sep 17 15:20:17.891198 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/var/www/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kQQAAAN4"]
[Thu Sep 17 15:20:17.960998 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "aqxZkQpXMN3p_zkwXf2kQgAAAMU"]
[Thu Sep 17 15:20:18.017459 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/dist/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kRgAAAL4"]
[Thu Sep 17 15:20:18.094647 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/var/www/html/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kSgAAAPw"]
[Thu Sep 17 15:20:18.189910 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/tmp/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kTAAAAKk"]
[Thu Sep 17 15:20:18.213035 2026] [security2:error] [pid 1012520:tid 1012651] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/public_html/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kTQAAAIU"]
[Thu Sep 17 15:20:18.284850 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/current/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kTgAAAI8"]
[Thu Sep 17 15:20:18.386652 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.252.7.239:49966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/phpinfo.php~"] [unique_id "aqxZkgpXMN3p_zkwXf2kTwAAAJs"]
[Thu Sep 17 15:20:18.419605 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/temp/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kUAAAAOA"]
[Thu Sep 17 15:20:18.457066 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/htdocs/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kUQAAAQM"]
[Thu Sep 17 15:20:18.469420 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/release/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kUgAAAKM"]
[Thu Sep 17 15:20:18.633282 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/www/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kUwAAAJY"]
[Thu Sep 17 15:20:18.646769 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/lab/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kVAAAAOg"]
[Thu Sep 17 15:20:18.668517 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/releases/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kVQAAAP0"]
[Thu Sep 17 15:20:18.843351 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/shared/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kVgAAAKg"]
[Thu Sep 17 15:20:18.873728 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cronlab/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kWQAAAJg"]
[Thu Sep 17 15:20:18.893325 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/html/.env"] [unique_id "aqxZkgpXMN3p_zkwXf2kWwAAALU"]
[Thu Sep 17 15:20:18.942838 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.252.7.239:49976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/info.php.bak"] [unique_id "aqxZkgpXMN3p_zkwXf2kXAAAAKA"]
[Thu Sep 17 15:20:19.029792 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/deploy/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kXQAAAKE"]
[Thu Sep 17 15:20:19.055648 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/live/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kXgAAAJ8"]
[Thu Sep 17 15:20:19.107369 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kXwAAALE"]
[Thu Sep 17 15:20:19.218478 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/build/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kYAAAALM"]
[Thu Sep 17 15:20:19.252017 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/prod/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kYwAAAJE"]
[Thu Sep 17 15:20:19.335524 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/en/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kZQAAANI"]
[Thu Sep 17 15:20:19.410212 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/dist/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kZgAAAQE"]
[Thu Sep 17 15:20:19.424293 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/dev/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kZwAAAPA"]
[Thu Sep 17 15:20:19.448200 2026] [security2:error] [pid 1012520:tid 1012723] [client 156.192.234.52:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZkwpXMN3p_zkwXf2kaAAAAM0"]
[Thu Sep 17 15:20:19.449634 2026] [security2:error] [pid 1012520:tid 1012723] [client 156.192.234.52:61773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZkwpXMN3p_zkwXf2kaAAAAM0"]
[Thu Sep 17 15:20:19.498676 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.252.7.239:49990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZkwpXMN3p_zkwXf2kaQAAALg"]
[Thu Sep 17 15:20:19.581629 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/public_html/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kawAAAOo"]
[Thu Sep 17 15:20:19.605676 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/staging/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kbAAAAKQ"]
[Thu Sep 17 15:20:19.621965 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kagAAAL0"]
[Thu Sep 17 15:20:19.744972 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/htdocs/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kbgAAAI0"]
[Thu Sep 17 15:20:19.807219 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/opt/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kcQAAANg"]
[Thu Sep 17 15:20:19.849150 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/psnlink/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kcgAAAP8"]
[Thu Sep 17 15:20:19.963287 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/www/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2kdwAAAPc"]
[Thu Sep 17 15:20:20.000477 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/laravel/.env"] [unique_id "aqxZkwpXMN3p_zkwXf2keAAAANM"]
[Thu Sep 17 15:20:20.052745 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.252.7.239:49998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZlApXMN3p_zkwXf2keQAAAJQ"]
[Thu Sep 17 15:20:20.089868 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/exapi/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kegAAALw"]
[Thu Sep 17 15:20:20.199874 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/html/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kewAAALQ"]
[Thu Sep 17 15:20:20.225048 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/symfony/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kfAAAAN8"]
[Thu Sep 17 15:20:20.318804 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sitemaps/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kgQAAAKw"]
[Thu Sep 17 15:20:20.383463 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/live/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kgwAAAMw"]
[Thu Sep 17 15:20:20.444926 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/wordpress/.env"] [unique_id "aqxZlApXMN3p_zkwXf2khAAAAO4"]
[Thu Sep 17 15:20:20.592586 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/prod/.env"] [unique_id "aqxZlApXMN3p_zkwXf2khwAAAQQ"]
[Thu Sep 17 15:20:20.626132 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/wp/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kiAAAAJI"]
[Thu Sep 17 15:20:20.629167 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.252.7.239:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZlApXMN3p_zkwXf2kiQAAAPQ"]
[Thu Sep 17 15:20:20.764594 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/dev/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kjQAAALc"]
[Thu Sep 17 15:20:20.824710 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/cms/.env"] [unique_id "aqxZlApXMN3p_zkwXf2kjwAAAJw"]
[Thu Sep 17 15:20:20.955886 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/staging/.env"] [unique_id "aqxZlApXMN3p_zkwXf2klQAAAOA"]
[Thu Sep 17 15:20:21.020904 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/drupal/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2klwAAAKM"]
[Thu Sep 17 15:20:21.175648 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/opt/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2kmAAAANY"]
[Thu Sep 17 15:20:21.187500 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.166.228.3:42740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/logs/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2kmQAAAP4"]
[Thu Sep 17 15:20:21.193196 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.252.7.239:40552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZlQpXMN3p_zkwXf2kmgAAAK0"]
[Thu Sep 17 15:20:21.230336 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/joomla/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2knAAAAKc"]
[Thu Sep 17 15:20:21.380280 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/laravel/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2koAAAAJ0"]
[Thu Sep 17 15:20:21.456025 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.247.203.201:49086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/magento/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2kogAAAPE"]
[Thu Sep 17 15:20:21.571400 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/symfony/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2kpAAAAJE"]
[Thu Sep 17 15:20:21.748886 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/wordpress/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2kpQAAAPA"]
[Thu Sep 17 15:20:21.751172 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.252.7.239:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZlQpXMN3p_zkwXf2kpgAAAMY"]
[Thu Sep 17 15:20:21.896855 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cache/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2kqwAAAQE"]
[Thu Sep 17 15:20:21.932978 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/wp/.env"] [unique_id "aqxZlQpXMN3p_zkwXf2krAAAAKQ"]
[Thu Sep 17 15:20:22.071513 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/shopify/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2krgAAAMA"]
[Thu Sep 17 15:20:22.105066 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cms/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2krwAAAJM"]
[Thu Sep 17 15:20:22.125747 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailer/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2ksAAAAO0"]
[Thu Sep 17 15:20:22.274970 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/drupal/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2ktwAAAI4"]
[Thu Sep 17 15:20:22.293996 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/prestashop/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kuAAAANM"]
[Thu Sep 17 15:20:22.303936 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.252.7.239:40560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZlgpXMN3p_zkwXf2kuQAAAOE"]
[Thu Sep 17 15:20:22.355744 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mail/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kugAAAJQ"]
[Thu Sep 17 15:20:22.457414 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/joomla/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kuwAAAJc"]
[Thu Sep 17 15:20:22.487975 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/codeigniter/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kvAAAAPM"]
[Thu Sep 17 15:20:22.586433 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/email/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kvQAAANo"]
[Thu Sep 17 15:20:22.642503 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.247.203.201:60178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/magento/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kvgAAAMQ"]
[Thu Sep 17 15:20:22.721915 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/cakephp/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kvwAAAMw"]
[Thu Sep 17 15:20:22.821624 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/smtp/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kwwAAAJI"]
[Thu Sep 17 15:20:22.863258 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.252.7.239:40566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZlgpXMN3p_zkwXf2kxAAAAKw"]
[Thu Sep 17 15:20:22.900506 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/zend/.env"] [unique_id "aqxZlgpXMN3p_zkwXf2kxQAAAOs"]
[Thu Sep 17 15:20:23.058394 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailing/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2kxwAAALI"]
[Thu Sep 17 15:20:23.076378 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/yii/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2kyAAAAOw"]
[Thu Sep 17 15:20:23.239134 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/shopify/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2kygAAAMc"]
[Thu Sep 17 15:20:23.257839 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/laravel5/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2kzQAAALA"]
[Thu Sep 17 15:20:23.291915 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/notifications/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2kzgAAAPU"]
[Thu Sep 17 15:20:23.411469 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/prestashop/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k0QAAAJs"]
[Thu Sep 17 15:20:23.432631 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/v1/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k0gAAAPs"]
[Thu Sep 17 15:20:23.443770 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.252.7.239:40578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZlwpXMN3p_zkwXf2k0wAAAKo"]
[Thu Sep 17 15:20:23.524717 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/notify/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k1AAAAIY"]
[Thu Sep 17 15:20:23.595420 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/codeigniter/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k1gAAAKM"]
[Thu Sep 17 15:20:23.638688 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/v2/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k1wAAAPo"]
[Thu Sep 17 15:20:23.716148 2026] [autoindex:error] [pid 1012520:tid 1012770] [client 152.32.235.107:37938] AH01276: Cannot serve directory /home1/sacyjkmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:20:23.768802 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sender/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k2wAAAJY"]
[Thu Sep 17 15:20:23.770764 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cakephp/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k3AAAAPg"]
[Thu Sep 17 15:20:23.812738 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/v3/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k3QAAAPk"]
[Thu Sep 17 15:20:23.952706 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/zend/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k3wAAAKs"]
[Thu Sep 17 15:20:23.977116 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/api/v1/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k4AAAAIk"]
[Thu Sep 17 15:20:23.997132 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/campaign/.env"] [unique_id "aqxZlwpXMN3p_zkwXf2k4QAAAK8"]
[Thu Sep 17 15:20:23.998108 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.252.7.239:40592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZlwpXMN3p_zkwXf2k4gAAAP0"]
[Thu Sep 17 15:20:24.122775 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/yii/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k4wAAAJ0"]
[Thu Sep 17 15:20:24.150823 2026] [security2:error] [pid 1012520:tid 1012658] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/api/v2/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k5AAAAIw"]
[Thu Sep 17 15:20:24.225717 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/newsletter/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k5QAAAO8"]
[Thu Sep 17 15:20:24.324327 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/laravel5/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k6QAAALE"]
[Thu Sep 17 15:20:24.334421 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/rest/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k6gAAAKA"]
[Thu Sep 17 15:20:24.409491 2026] [security2:error] [pid 1012520:tid 1012731] [client 186.105.232.15:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmApXMN3p_zkwXf2k7AAAANU"]
[Thu Sep 17 15:20:24.409609 2026] [security2:error] [pid 1012520:tid 1012731] [client 186.105.232.15:64105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmApXMN3p_zkwXf2k7AAAANU"]
[Thu Sep 17 15:20:24.463881 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/ses/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k7QAAAJg"]
[Thu Sep 17 15:20:24.488500 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/v1/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k7gAAAJE"]
[Thu Sep 17 15:20:24.519293 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/graphql/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k7wAAANI"]
[Thu Sep 17 15:20:24.561372 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.252.7.239:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZmApXMN3p_zkwXf2k8AAAALU"]
[Thu Sep 17 15:20:24.651954 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/v2/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k8QAAAMY"]
[Thu Sep 17 15:20:24.687046 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/gateway/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k8gAAALg"]
[Thu Sep 17 15:20:24.694849 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sendgrid/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k8wAAAM4"]
[Thu Sep 17 15:20:24.820385 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/v3/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k-AAAAMk"]
[Thu Sep 17 15:20:24.861545 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/microservice/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k-QAAAOU"]
[Thu Sep 17 15:20:24.923760 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sparkpost/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k-gAAAJ4"]
[Thu Sep 17 15:20:24.990732 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/api/v1/.env"] [unique_id "aqxZmApXMN3p_zkwXf2k-wAAAME"]
[Thu Sep 17 15:20:25.035257 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/service/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2k_gAAAMA"]
[Thu Sep 17 15:20:25.116383 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.252.7.239:40616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZmQpXMN3p_zkwXf2lAAAAAM0"]
[Thu Sep 17 15:20:25.130580 2026] [security2:error] [pid 1012520:tid 1012727] [client 154.190.208.131:41385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmQpXMN3p_zkwXf2lAQAAANE"]
[Thu Sep 17 15:20:25.135218 2026] [security2:error] [pid 1012520:tid 1012727] [client 154.190.208.131:41385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmQpXMN3p_zkwXf2lAQAAANE"]
[Thu Sep 17 15:20:25.152432 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/postmark/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lAgAAAOo"]
[Thu Sep 17 15:20:25.175240 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/api/v2/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lAwAAAI4"]
[Thu Sep 17 15:20:25.235722 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/api/v3/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lBAAAAOE"]
[Thu Sep 17 15:20:25.347816 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/rest/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lCQAAAPc"]
[Thu Sep 17 15:20:25.384114 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailgun/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lCgAAAMs"]
[Thu Sep 17 15:20:25.429123 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/api/dev/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lCwAAAL8"]
[Thu Sep 17 15:20:25.522079 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/graphql/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lDAAAANs"]
[Thu Sep 17 15:20:25.601110 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/api/staging/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lDgAAAQQ"]
[Thu Sep 17 15:20:25.613754 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mandrill/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lDwAAAJI"]
[Thu Sep 17 15:20:25.665895 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.252.7.239:40626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZmQpXMN3p_zkwXf2lEAAAAMw"]
[Thu Sep 17 15:20:25.677134 2026] [security2:error] [pid 1012520:tid 1012764] [client 103.61.184.148:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmQpXMN3p_zkwXf2lEQAAAPY"]
[Thu Sep 17 15:20:25.677625 2026] [security2:error] [pid 1012520:tid 1012764] [client 103.61.184.148:60469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmQpXMN3p_zkwXf2lEQAAAPY"]
[Thu Sep 17 15:20:25.705994 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/gateway/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lEgAAAKw"]
[Thu Sep 17 15:20:25.785964 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/vendor/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lFQAAANA"]
[Thu Sep 17 15:20:25.850692 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailjet/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lFgAAAO4"]
[Thu Sep 17 15:20:25.892417 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/microservice/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lFwAAAPQ"]
[Thu Sep 17 15:20:25.993647 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/lib/.env"] [unique_id "aqxZmQpXMN3p_zkwXf2lGwAAAL4"]
[Thu Sep 17 15:20:26.086966 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/service/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lHwAAAMc"]
[Thu Sep 17 15:20:26.087972 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/brevo/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lIAAAALA"]
[Thu Sep 17 15:20:26.172154 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/resources/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lIgAAAOA"]
[Thu Sep 17 15:20:26.236137 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.252.7.239:40628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZmgpXMN3p_zkwXf2lJAAAALc"]
[Thu Sep 17 15:20:26.253101 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/api/v3/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lJQAAAKo"]
[Thu Sep 17 15:20:26.320747 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/transactional/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lKQAAAIY"]
[Thu Sep 17 15:20:26.343440 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/assets/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lKgAAAN0"]
[Thu Sep 17 15:20:26.438502 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/api/dev/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lLQAAAPw"]
[Thu Sep 17 15:20:26.550704 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/bulk/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lLwAAAOg"]
[Thu Sep 17 15:20:26.552509 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/uploads/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lMAAAAKc"]
[Thu Sep 17 15:20:26.612393 2026] [security2:error] [pid 1012520:tid 1012732] [client 185.55.149.49:53672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZmgpXMN3p_zkwXf2lMQAAANY"]
[Thu Sep 17 15:20:26.612632 2026] [security2:error] [pid 1012520:tid 1012732] [client 185.55.149.49:53672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZmgpXMN3p_zkwXf2lMQAAANY"]
[Thu Sep 17 15:20:26.647055 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/api/staging/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lMwAAAIk"]
[Thu Sep 17 15:20:26.733484 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/internal/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lNAAAAP0"]
[Thu Sep 17 15:20:26.779822 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/aws/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lNwAAAIw"]
[Thu Sep 17 15:20:26.786988 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.252.7.239:40636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZmgpXMN3p_zkwXf2lOAAAAP4"]
[Thu Sep 17 15:20:26.789430 2026] [security2:error] [pid 1012520:tid 1012691] [client 114.198.138.124:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmgpXMN3p_zkwXf2lOQAAAK0"]
[Thu Sep 17 15:20:26.789520 2026] [security2:error] [pid 1012520:tid 1012691] [client 114.198.138.124:55679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZmgpXMN3p_zkwXf2lOQAAAK0"]
[Thu Sep 17 15:20:26.823720 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/vendor/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lOwAAAIg"]
[Thu Sep 17 15:20:26.913514 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/tools/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lPAAAANU"]
[Thu Sep 17 15:20:26.993909 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/lib/.env"] [unique_id "aqxZmgpXMN3p_zkwXf2lPQAAAKU"]
[Thu Sep 17 15:20:27.009923 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/azure/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lPgAAAM8"]
[Thu Sep 17 15:20:27.091303 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/scripts/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lQAAAANI"]
[Thu Sep 17 15:20:27.170293 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/resources/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lQQAAAMY"]
[Thu Sep 17 15:20:27.230160 2026] [security2:error] [pid 1012520:tid 1012744] [client 40.77.167.74:15170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "test.cellovsviolin.com"] [uri "/index.php"] [unique_id "aqxZmQpXMN3p_zkwXf2lBwAA4g4"]
[Thu Sep 17 15:20:27.243290 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/gcp/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lRAAAAPI"]
[Thu Sep 17 15:20:27.301656 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/bin/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lSgAAAL0"]
[Thu Sep 17 15:20:27.361079 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.252.7.239:40638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.7.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZmwpXMN3p_zkwXf2lSwAAAPA"]
[Thu Sep 17 15:20:27.381449 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/assets/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lTAAAAQE"]
[Thu Sep 17 15:20:27.469343 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/sbin/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lTwAAAI4"]
[Thu Sep 17 15:20:27.474420 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cloud/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lUAAAAOE"]
[Thu Sep 17 15:20:27.598347 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/uploads/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lUgAAAMg"]
[Thu Sep 17 15:20:27.657282 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/local/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lVQAAAPc"]
[Thu Sep 17 15:20:27.704024 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/infrastructure/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lVwAAANc"]
[Thu Sep 17 15:20:27.786415 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/internal/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lWAAAAJc"]
[Thu Sep 17 15:20:27.875186 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/portal/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lXAAAAMQ"]
[Thu Sep 17 15:20:27.932846 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/docker/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lXQAAANs"]
[Thu Sep 17 15:20:27.966237 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/tools/.env"] [unique_id "aqxZmwpXMN3p_zkwXf2lXwAAAQQ"]
[Thu Sep 17 15:20:28.056396 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/dashboard/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lYAAAAKw"]
[Thu Sep 17 15:20:28.167032 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/k8s/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lYgAAAOM"]
[Thu Sep 17 15:20:28.180367 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/scripts/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lYwAAAO4"]
[Thu Sep 17 15:20:28.272435 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/panel/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lagAAALA"]
[Thu Sep 17 15:20:28.387283 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/bin/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lbwAAANk"]
[Thu Sep 17 15:20:28.397611 2026] [security2:error] [pid 1012520:tid 1012730] [client 66.249.66.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/wp/index.php"] [unique_id "aqxZmgpXMN3p_zkwXf2lHgAAANQ"]
[Thu Sep 17 15:20:28.405127 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/kubernetes/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lcAAAALI"]
[Thu Sep 17 15:20:28.463574 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/crm/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lcgAAAQM"]
[Thu Sep 17 15:20:28.575025 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/sbin/.env"] [unique_id "aqxZnApXMN3p_zkwXf2ldQAAAPk"]
[Thu Sep 17 15:20:28.648152 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/terraform/.env"] [unique_id "aqxZnApXMN3p_zkwXf2ldgAAAKs"]
[Thu Sep 17 15:20:28.653353 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/erp/.env"] [unique_id "aqxZnApXMN3p_zkwXf2ldwAAAOQ"]
[Thu Sep 17 15:20:28.655709 2026] [security2:error] [pid 1012520:tid 1012559] [remote 111.225.148.254:55914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/178-Zoo-300x199.jpg"] [unique_id "aqxZnApXMN3p_zkwXf2leAAA-yU"]
[Thu Sep 17 15:20:28.752128 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/local/.env"] [unique_id "aqxZnApXMN3p_zkwXf2legAAANY"]
[Thu Sep 17 15:20:28.842612 2026] [fcgid:warn] [pid 1012520:tid 1012658] (70014)End of file found: [client 106.63.26.21:1821] mod_fcgid: can't get data from http client
[Thu Sep 17 15:20:28.875844 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/shop/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lfwAAAK0"]
[Thu Sep 17 15:20:28.887900 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/ansible/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lgQAAAJ8"]
[Thu Sep 17 15:20:28.932233 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/portal/.env"] [unique_id "aqxZnApXMN3p_zkwXf2lggAAAO8"]
[Thu Sep 17 15:20:29.015587 2026] [security2:error] [pid 1012520:tid 1012687] [client 156.192.234.52:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZnQpXMN3p_zkwXf2lgwAAAKk"]
[Thu Sep 17 15:20:29.016964 2026] [security2:error] [pid 1012520:tid 1012687] [client 156.192.234.52:62317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZnQpXMN3p_zkwXf2lgwAAAKk"]
[Thu Sep 17 15:20:29.047122 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/store/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lhAAAAKA"]
[Thu Sep 17 15:20:29.107746 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/dashboard/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lhgAAANU"]
[Thu Sep 17 15:20:29.116172 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.git/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lhwAAAJ0"]
[Thu Sep 17 15:20:29.227938 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/saas/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2ligAAAM8"]
[Thu Sep 17 15:20:29.316317 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/panel/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2ljwAAAMY"]
[Thu Sep 17 15:20:29.345997 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/ci/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lkAAAAPI"]
[Thu Sep 17 15:20:29.407424 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/client/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2llAAAAJU"]
[Thu Sep 17 15:20:29.480124 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/crm/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lmAAAAI4"]
[Thu Sep 17 15:20:29.578332 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cd/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lmQAAAOE"]
[Thu Sep 17 15:20:29.697260 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/erp/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lnAAAALw"]
[Thu Sep 17 15:20:29.700318 2026] [security2:error] [pid 1012520:tid 1012718] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/project/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lnQAAAMg"]
[Thu Sep 17 15:20:29.809802 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/jenkins/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2logAAAMs"]
[Thu Sep 17 15:20:29.878486 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/shop/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lpwAAAL8"]
[Thu Sep 17 15:20:29.920548 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/admin-panel/.env"] [unique_id "aqxZnQpXMN3p_zkwXf2lqAAAAOU"]
[Thu Sep 17 15:20:30.039429 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/gitlab/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lqwAAAOc"]
[Thu Sep 17 15:20:30.058857 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/store/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lrAAAAQQ"]
[Thu Sep 17 15:20:30.147510 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/control-panel/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lrgAAAP8"]
[Thu Sep 17 15:20:30.242356 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/saas/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lrwAAAPM"]
[Thu Sep 17 15:20:30.276229 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/github/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lswAAAIo"]
[Thu Sep 17 15:20:30.332710 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/user-panel/.env"] [unique_id "aqxZngpXMN3p_zkwXf2ltQAAAOM"]
[Thu Sep 17 15:20:30.418865 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/client/.env"] [unique_id "aqxZngpXMN3p_zkwXf2ltgAAALA"]
[Thu Sep 17 15:20:30.499787 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/node/.env"] [unique_id "aqxZngpXMN3p_zkwXf2luAAAAOs"]
[Thu Sep 17 15:20:30.512269 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/actions/.env"] [unique_id "aqxZngpXMN3p_zkwXf2luQAAANk"]
[Thu Sep 17 15:20:30.613188 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/project/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lugAAAKY"]
[Thu Sep 17 15:20:30.695145 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/express/.env"] [unique_id "aqxZngpXMN3p_zkwXf2luwAAANQ"]
[Thu Sep 17 15:20:30.747003 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/circleci/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lvAAAAI8"]
[Thu Sep 17 15:20:30.815892 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/admin-panel/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lwAAAAN4"]
[Thu Sep 17 15:20:30.942712 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/next/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lyQAAAMo"]
[Thu Sep 17 15:20:30.982453 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/travis/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lzQAAAPg"]
[Thu Sep 17 15:20:30.997188 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/control-panel/.env"] [unique_id "aqxZngpXMN3p_zkwXf2lzgAAAPY"]
[Thu Sep 17 15:20:31.146332 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/nuxt/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l0QAAAP4"]
[Thu Sep 17 15:20:31.221590 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/buildkite/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l0gAAAO8"]
[Thu Sep 17 15:20:31.238895 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/user-panel/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l0wAAAP0"]
[Thu Sep 17 15:20:31.368515 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/nest/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l2wAAAJ0"]
[Thu Sep 17 15:20:31.458766 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mysql/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l3QAAAJA"]
[Thu Sep 17 15:20:31.475675 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/node/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l3gAAAJo"]
[Thu Sep 17 15:20:31.568260 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/react/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l3wAAAPI"]
[Thu Sep 17 15:20:31.688963 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/express/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l4AAAANI"]
[Thu Sep 17 15:20:31.698380 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/postgres/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l4QAAAM4"]
[Thu Sep 17 15:20:31.766678 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/vue/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l4gAAAJE"]
[Thu Sep 17 15:20:31.889880 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/next/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l5gAAAQE"]
[Thu Sep 17 15:20:31.930488 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mongodb/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l5wAAAI0"]
[Thu Sep 17 15:20:31.949069 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/angular/.env"] [unique_id "aqxZnwpXMN3p_zkwXf2l6AAAALw"]
[Thu Sep 17 15:20:32.100067 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/nuxt/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l6QAAAOI"]
[Thu Sep 17 15:20:32.168767 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/svelte/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l6wAAAN8"]
[Thu Sep 17 15:20:32.177280 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/redis/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l7AAAANE"]
[Thu Sep 17 15:20:32.291193 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/nest/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l9AAAAJc"]
[Thu Sep 17 15:20:32.397179 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/vite/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l9wAAANM"]
[Thu Sep 17 15:20:32.418402 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/elasticsearch/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l-QAAANo"]
[Thu Sep 17 15:20:32.467646 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/react/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l-gAAAOc"]
[Thu Sep 17 15:20:32.489265 2026] [core:error] [pid 1012520:tid 1012568] [remote 216.73.216.37:34117] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:32.489281 2026] [core:error] [pid 1012520:tid 1012568] [remote 216.73.216.37:34117] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:32.590305 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/backup/.env"] [unique_id "aqxZoApXMN3p_zkwXf2l_gAAAP8"]
[Thu Sep 17 15:20:32.641869 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/vue/.env"] [unique_id "aqxZoApXMN3p_zkwXf2mAQAAALA"]
[Thu Sep 17 15:20:32.648375 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/rabbitmq/.env"] [unique_id "aqxZoApXMN3p_zkwXf2mAgAAANA"]
[Thu Sep 17 15:20:32.790226 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/backups/.env"] [unique_id "aqxZoApXMN3p_zkwXf2mBAAAALs"]
[Thu Sep 17 15:20:32.846611 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/angular/.env"] [unique_id "aqxZoApXMN3p_zkwXf2mCAAAAI8"]
[Thu Sep 17 15:20:32.882727 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/kafka/.env"] [unique_id "aqxZoApXMN3p_zkwXf2mCgAAAJw"]
[Thu Sep 17 15:20:32.968646 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/old/.env"] [unique_id "aqxZoApXMN3p_zkwXf2mCwAAAIs"]
[Thu Sep 17 15:20:33.045052 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/svelte/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mDAAAAKs"]
[Thu Sep 17 15:20:33.116818 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/queue/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mDQAAALc"]
[Thu Sep 17 15:20:33.139957 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/tmp/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mDgAAAOg"]
[Thu Sep 17 15:20:33.244355 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/vite/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mDwAAAKc"]
[Thu Sep 17 15:20:33.306229 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/temp/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mEwAAAO8"]
[Thu Sep 17 15:20:33.345810 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/worker/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mFQAAAPw"]
[Thu Sep 17 15:20:33.418554 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/backup/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mFgAAAP0"]
[Thu Sep 17 15:20:33.473888 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/lab/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mFwAAAJ0"]
[Thu Sep 17 15:20:33.575680 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/job/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mGAAAAOQ"]
[Thu Sep 17 15:20:33.593175 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/backups/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mGQAAAPQ"]
[Thu Sep 17 15:20:33.617203 2026] [security2:error] [pid 1012520:tid 1012696] [client 104.28.198.244:22670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZoQpXMN3p_zkwXf2mGwAAALI"]
[Thu Sep 17 15:20:33.617276 2026] [security2:error] [pid 1012520:tid 1012696] [client 104.28.198.244:22670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZoQpXMN3p_zkwXf2mGwAAALI"]
[Thu Sep 17 15:20:33.653198 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/cronlab/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mHAAAAJA"]
[Thu Sep 17 15:20:33.765851 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/old/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mHwAAAQA"]
[Thu Sep 17 15:20:33.807302 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mIQAAAKU"]
[Thu Sep 17 15:20:33.837549 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/cron/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mIgAAAJs"]
[Thu Sep 17 15:20:33.932953 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/tmp/.env"] [unique_id "aqxZoQpXMN3p_zkwXf2mIwAAAKg"]
[Thu Sep 17 15:20:34.034590 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/en/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mJwAAANY"]
[Thu Sep 17 15:20:34.048506 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mKAAAAMI"]
[Thu Sep 17 15:20:34.127797 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/temp/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mLAAAAJE"]
[Thu Sep 17 15:20:34.253279 2026] [fcgid:warn] [pid 1012520:tid 1012707] (70014)End of file found: [client 165.154.29.93:33398] mod_fcgid: can't get data from http client
[Thu Sep 17 15:20:34.280535 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/administrator/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mLgAAAM0"]
[Thu Sep 17 15:20:34.281327 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/preview/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mMwAAANE"]
[Thu Sep 17 15:20:34.307402 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/lab/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mNQAAAPE"]
[Thu Sep 17 15:20:34.458090 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/psnlink/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mOAAAAMk"]
[Thu Sep 17 15:20:34.481232 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cronlab/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mOQAAAJ4"]
[Thu Sep 17 15:20:34.509703 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mOgAAAMs"]
[Thu Sep 17 15:20:34.642900 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/exapi/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mOwAAAPc"]
[Thu Sep 17 15:20:34.680681 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cron/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mPAAAAOc"]
[Thu Sep 17 15:20:34.699362 2026] [core:error] [pid 1012520:tid 1012737] [client 52.167.144.221:39931] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:34.699375 2026] [core:error] [pid 1012520:tid 1012737] [client 52.167.144.221:39931] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:20:34.737945 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/uat/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mPwAAAQQ"]
[Thu Sep 17 15:20:34.826062 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/sitemaps/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mRQAAALA"]
[Thu Sep 17 15:20:34.872385 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/en/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mRgAAANA"]
[Thu Sep 17 15:20:34.968887 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "aqxZogpXMN3p_zkwXf2mRwAAAJI"]
[Thu Sep 17 15:20:35.050041 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/administrator/.env"] [unique_id "aqxZowpXMN3p_zkwXf2mSQAAAMU"]
[Thu Sep 17 15:20:35.198636 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "aqxZowpXMN3p_zkwXf2mTAAAAPM"]
[Thu Sep 17 15:20:35.201954 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.247.203.201:56936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZogpXMN3p_zkwXf2mSAAAAO4"]
[Thu Sep 17 15:20:35.221947 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/psnlink/.env"] [unique_id "aqxZowpXMN3p_zkwXf2mTQAAAIs"]
[Thu Sep 17 15:20:35.397058 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/exapi/.env"] [unique_id "aqxZowpXMN3p_zkwXf2mUQAAAKs"]
[Thu Sep 17 15:20:35.427486 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "aqxZowpXMN3p_zkwXf2mUgAAAKo"]
[Thu Sep 17 15:20:35.601277 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/sitemaps/.env"] [unique_id "aqxZowpXMN3p_zkwXf2mUwAAAMo"]
[Thu Sep 17 15:20:35.646162 2026] [security2:error] [pid 1012520:tid 1012684] [client 154.190.208.131:41999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZowpXMN3p_zkwXf2mVQAAAKY"]
[Thu Sep 17 15:20:35.655099 2026] [security2:error] [pid 1012520:tid 1012684] [client 154.190.208.131:41999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZowpXMN3p_zkwXf2mVQAAAKY"]
[Thu Sep 17 15:20:35.656232 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.166.228.3:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/config/app/.env"] [unique_id "aqxZowpXMN3p_zkwXf2mVgAAAP0"]
[Thu Sep 17 15:20:35.730013 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:56936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZowpXMN3p_zkwXf2mVAAAAPw"]
[Thu Sep 17 15:20:35.885992 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.166.228.3:43816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxZowpXMN3p_zkwXf2mWwAAANU"]
[Thu Sep 17 15:20:35.900467 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.247.203.201:56938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZowpXMN3p_zkwXf2mWgAAAPs"]
[Thu Sep 17 15:20:36.101399 2026] [security2:error] [pid 1012520:tid 1012687] [client 186.105.232.15:64706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpApXMN3p_zkwXf2mXQAAAKk"]
[Thu Sep 17 15:20:36.101498 2026] [security2:error] [pid 1012520:tid 1012687] [client 186.105.232.15:64706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpApXMN3p_zkwXf2mXQAAAKk"]
[Thu Sep 17 15:20:36.116899 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/logs/.env"] [unique_id "aqxZpApXMN3p_zkwXf2mXgAAAIk"]
[Thu Sep 17 15:20:36.276444 2026] [security2:error] [pid 1012520:tid 1012670] [client 103.61.184.148:61006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpApXMN3p_zkwXf2mZAAAAJg"]
[Thu Sep 17 15:20:36.276528 2026] [security2:error] [pid 1012520:tid 1012670] [client 103.61.184.148:61006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpApXMN3p_zkwXf2mZAAAAJg"]
[Thu Sep 17 15:20:36.279539 2026] [security2:error] [pid 1012520:tid 1012774] [client 114.119.146.41:25017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "casualchessclub.com"] [uri "/wp/wp-login.php"] [unique_id "aqxZpApXMN3p_zkwXf2mXwAAAQA"], referer: https://casualchessclub.com/wp/wp-login.php
[Thu Sep 17 15:20:36.287598 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/cache/.env"] [unique_id "aqxZpApXMN3p_zkwXf2mZgAAAJo"]
[Thu Sep 17 15:20:36.509865 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mailer/.env"] [unique_id "aqxZpApXMN3p_zkwXf2maQAAAJU"]
[Thu Sep 17 15:20:36.577253 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.166.228.3:36404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/info.php"] [unique_id "aqxZpApXMN3p_zkwXf2mawAAALk"]
[Thu Sep 17 15:20:36.579084 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:56938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZpApXMN3p_zkwXf2maAAAAQE"]
[Thu Sep 17 15:20:36.723946 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mail/.env"] [unique_id "aqxZpApXMN3p_zkwXf2mbQAAAL0"]
[Thu Sep 17 15:20:36.908030 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/email/.env"] [unique_id "aqxZpApXMN3p_zkwXf2megAAAKQ"]
[Thu Sep 17 15:20:36.986245 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/logs/.env"] [unique_id "aqxZpApXMN3p_zkwXf2mfAAAAKI"]
[Thu Sep 17 15:20:37.025618 2026] [security2:error] [pid 1012520:tid 1012698] [client 136.243.228.180:51147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.churchinirving.org"] [uri "/index.php"] [unique_id "aqxZpApXMN3p_zkwXf2mewAAALQ"]
[Thu Sep 17 15:20:37.098475 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/smtp/.env"] [unique_id "aqxZpQpXMN3p_zkwXf2mfQAAANg"]
[Thu Sep 17 15:20:37.230815 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cache/.env"] [unique_id "aqxZpQpXMN3p_zkwXf2mgAAAAQQ"]
[Thu Sep 17 15:20:37.255590 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.166.228.3:36408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/php.php"] [unique_id "aqxZpQpXMN3p_zkwXf2mgQAAAMk"]
[Thu Sep 17 15:20:37.268761 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.247.203.201:56936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mailing/.env"] [unique_id "aqxZpQpXMN3p_zkwXf2mgwAAAK4"]
[Thu Sep 17 15:20:37.316284 2026] [security2:error] [pid 1012520:tid 1012676] [client 185.55.149.49:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZpQpXMN3p_zkwXf2mhgAAAJ4"]
[Thu Sep 17 15:20:37.316380 2026] [security2:error] [pid 1012520:tid 1012676] [client 185.55.149.49:54336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZpQpXMN3p_zkwXf2mhgAAAJ4"]
[Thu Sep 17 15:20:37.435994 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mailer/.env"] [unique_id "aqxZpQpXMN3p_zkwXf2miAAAANA"]
[Thu Sep 17 15:20:37.509443 2026] [security2:error] [pid 1012520:tid 1012777] [client 114.198.138.124:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpQpXMN3p_zkwXf2migAAAQM"]
[Thu Sep 17 15:20:37.509587 2026] [security2:error] [pid 1012520:tid 1012777] [client 114.198.138.124:56327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpQpXMN3p_zkwXf2migAAAQM"]
[Thu Sep 17 15:20:37.655227 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mail/.env"] [unique_id "aqxZpQpXMN3p_zkwXf2miwAAAJQ"]
[Thu Sep 17 15:20:37.843476 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/email/.env"] [unique_id "aqxZpQpXMN3p_zkwXf2mjgAAAIs"]
[Thu Sep 17 15:20:37.921428 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/notifications/.env"] [unique_id "aqxZpQpXMN3p_zkwXf2mjwAAAOM"]
[Thu Sep 17 15:20:37.945632 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.166.228.3:36416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/i.php"] [unique_id "aqxZpQpXMN3p_zkwXf2mkAAAAL4"]
[Thu Sep 17 15:20:38.019901 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/smtp/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mkwAAAPU"]
[Thu Sep 17 15:20:38.085475 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/notify/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mlAAAAOs"]
[Thu Sep 17 15:20:38.199816 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.247.203.201:56938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mailing/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mlQAAAMo"]
[Thu Sep 17 15:20:38.271546 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/sender/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mlwAAAP0"]
[Thu Sep 17 15:20:38.456518 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/campaign/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mmwAAAJ8"]
[Thu Sep 17 15:20:38.629534 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.166.228.3:36420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxZpgpXMN3p_zkwXf2mnQAAAOY"]
[Thu Sep 17 15:20:38.643960 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/newsletter/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mngAAAJA"]
[Thu Sep 17 15:20:38.786152 2026] [autoindex:error] [pid 1012520:tid 1012544] [remote 93.152.209.11:59858] AH01276: Cannot serve directory /home1/yxpccqmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:20:38.816178 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/ses/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mogAAAQA"]
[Thu Sep 17 15:20:38.890059 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/notifications/.env"] [unique_id "aqxZpgpXMN3p_zkwXf2mpAAAAJs"]
[Thu Sep 17 15:20:39.019629 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/sendgrid/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mpQAAALk"]
[Thu Sep 17 15:20:39.088432 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/notify/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mpwAAAJk"]
[Thu Sep 17 15:20:39.204822 2026] [security2:error] [pid 1012520:tid 1012696] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/sparkpost/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mqgAAALI"]
[Thu Sep 17 15:20:39.259192 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/sender/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mqwAAAM0"]
[Thu Sep 17 15:20:39.310925 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.166.228.3:36434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxZpwpXMN3p_zkwXf2mrwAAAKM"]
[Thu Sep 17 15:20:39.383906 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/postmark/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mswAAAMA"]
[Thu Sep 17 15:20:39.446209 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/campaign/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mtwAAALs"]
[Thu Sep 17 15:20:39.507742 2026] [security2:error] [pid 1012520:tid 1012694] [client 62.216.71.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxZpwpXMN3p_zkwXf2msgAAALA"]
[Thu Sep 17 15:20:39.546584 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mailgun/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2muAAAAOA"]
[Thu Sep 17 15:20:39.636267 2026] [security2:error] [pid 1012520:tid 1012755] [client 156.192.234.52:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpwpXMN3p_zkwXf2mugAAAO0"]
[Thu Sep 17 15:20:39.636848 2026] [security2:error] [pid 1012520:tid 1012755] [client 156.192.234.52:62948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZpwpXMN3p_zkwXf2mugAAAO0"]
[Thu Sep 17 15:20:39.638746 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/newsletter/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2muwAAANs"]
[Thu Sep 17 15:20:39.724900 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mandrill/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mvgAAAL8"]
[Thu Sep 17 15:20:39.807367 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/ses/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mxQAAAPU"]
[Thu Sep 17 15:20:39.847531 2026] [security2:error] [pid 1012520:tid 1012777] [client 188.94.86.66:49663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZpwpXMN3p_zkwXf2mvwABA1M"]
[Thu Sep 17 15:20:39.899443 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mailjet/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2mxwAAAMY"]
[Thu Sep 17 15:20:39.906454 2026] [security2:error] [pid 1012520:tid 1012745] [client 62.216.71.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxZpwpXMN3p_zkwXf2mwQAAAOM"]
[Thu Sep 17 15:20:39.977183 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/sendgrid/.env"] [unique_id "aqxZpwpXMN3p_zkwXf2myAAAAOg"]
[Thu Sep 17 15:20:39.999552 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.166.228.3:36442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/test.php"] [unique_id "aqxZpwpXMN3p_zkwXf2myQAAAJw"]
[Thu Sep 17 15:20:40.082877 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/brevo/.env"] [unique_id "aqxZqApXMN3p_zkwXf2mygAAAPY"]
[Thu Sep 17 15:20:40.164051 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/sparkpost/.env"] [unique_id "aqxZqApXMN3p_zkwXf2mywAAAOw"]
[Thu Sep 17 15:20:40.292344 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/transactional/.env"] [unique_id "aqxZqApXMN3p_zkwXf2mzwAAAPw"]
[Thu Sep 17 15:20:40.338892 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/postmark/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m0AAAAKY"]
[Thu Sep 17 15:20:40.464892 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/bulk/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m0wAAAM8"]
[Thu Sep 17 15:20:40.505168 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mailgun/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m1AAAAK0"]
[Thu Sep 17 15:20:40.635105 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/aws/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m4AAAALg"]
[Thu Sep 17 15:20:40.690191 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mandrill/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m4wAAAP4"]
[Thu Sep 17 15:20:40.726549 2026] [security2:error] [pid 1012520:tid 1012732] [client 23.161.3.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxZqApXMN3p_zkwXf2m3QAAANY"]
[Thu Sep 17 15:20:40.812240 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/azure/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m6AAAAJk"]
[Thu Sep 17 15:20:40.856093 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mailjet/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m6QAAAM4"]
[Thu Sep 17 15:20:40.941418 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.166.228.3:36448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/p.php"] [unique_id "aqxZqApXMN3p_zkwXf2m8QAAAPc"]
[Thu Sep 17 15:20:40.991067 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/gcp/.env"] [unique_id "aqxZqApXMN3p_zkwXf2m8gAAAKM"]
[Thu Sep 17 15:20:41.028316 2026] [security2:error] [pid 1012520:tid 1012710] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/brevo/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2m8wAAAMA"]
[Thu Sep 17 15:20:41.029542 2026] [security2:error] [pid 1012520:tid 1012723] [client 23.161.3.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxZqApXMN3p_zkwXf2m8AAAAM0"]
[Thu Sep 17 15:20:41.161607 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/cloud/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2m-AAAALs"]
[Thu Sep 17 15:20:41.205805 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/transactional/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2m-gAAAMs"]
[Thu Sep 17 15:20:41.352221 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/infrastructure/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nAAAAAQE"]
[Thu Sep 17 15:20:41.374775 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/bulk/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nAgAAAP8"]
[Thu Sep 17 15:20:41.523697 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/docker/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nBQAAAO0"]
[Thu Sep 17 15:20:41.549864 2026] [security2:error] [pid 1012520:tid 1012656] [client 188.94.86.66:57133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZqQpXMN3p_zkwXf2nAwAAigA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726044506&hideanons=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:20:41.553837 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/aws/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nBwAAANk"]
[Thu Sep 17 15:20:41.632426 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.166.228.3:36458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxZqQpXMN3p_zkwXf2nCQAAAK4"]
[Thu Sep 17 15:20:41.737463 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/azure/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nDAAAAMY"]
[Thu Sep 17 15:20:41.762406 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/k8s/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nDQAAAOM"]
[Thu Sep 17 15:20:41.925418 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/gcp/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nEQAAAPo"]
[Thu Sep 17 15:20:41.988825 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/kubernetes/.env"] [unique_id "aqxZqQpXMN3p_zkwXf2nFAAAAP0"]
[Thu Sep 17 15:20:42.122906 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cloud/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nFgAAAOw"]
[Thu Sep 17 15:20:42.167966 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/terraform/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nGAAAAPQ"]
[Thu Sep 17 15:20:42.293815 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/infrastructure/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nHAAAAIg"]
[Thu Sep 17 15:20:42.324980 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.166.228.3:42172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxZqgpXMN3p_zkwXf2nHQAAAPY"]
[Thu Sep 17 15:20:42.347030 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/ansible/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nHgAAAIk"]
[Thu Sep 17 15:20:42.464389 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/docker/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nJQAAAJM"]
[Thu Sep 17 15:20:42.505458 2026] [security2:error] [pid 1012520:tid 1012746] [client 43.158.91.71:58730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "calgarytelephone.com"] [uri "/index.php"] [unique_id "aqxZqQpXMN3p_zkwXf2m9gAAAOQ"]
[Thu Sep 17 15:20:42.534373 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/.git/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nJwAAANY"]
[Thu Sep 17 15:20:42.639482 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/k8s/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nKQAAAJk"]
[Thu Sep 17 15:20:42.702725 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/ci/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nKgAAALY"]
[Thu Sep 17 15:20:42.818033 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/kubernetes/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nKwAAAJU"]
[Thu Sep 17 15:20:42.876984 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/cd/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nMgAAANE"]
[Thu Sep 17 15:20:42.993725 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/terraform/.env"] [unique_id "aqxZqgpXMN3p_zkwXf2nNAAAALU"]
[Thu Sep 17 15:20:43.000430 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.166.228.3:42182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxZqgpXMN3p_zkwXf2nNQAAAMg"]
[Thu Sep 17 15:20:43.070336 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/jenkins/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nNgAAAPc"]
[Thu Sep 17 15:20:43.169967 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/ansible/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nOQAAANo"]
[Thu Sep 17 15:20:43.183348 2026] [security2:error] [pid 1012520:tid 1012774] [client 104.28.198.244:22669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZqwpXMN3p_zkwXf2nOgAAAQA"]
[Thu Sep 17 15:20:43.183459 2026] [security2:error] [pid 1012520:tid 1012774] [client 104.28.198.244:22669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZqwpXMN3p_zkwXf2nOgAAAQA"]
[Thu Sep 17 15:20:43.221621 2026] [security2:error] [pid 1012520:tid 1012751] [client 168.158.230.188:34583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZqwpXMN3p_zkwXf2nOAAA6Qw"]
[Thu Sep 17 15:20:43.320291 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/gitlab/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nPgAAALA"]
[Thu Sep 17 15:20:43.360636 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/.git/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nPwAAAQE"]
[Thu Sep 17 15:20:43.491411 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/github/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nRQAAAL4"]
[Thu Sep 17 15:20:43.542310 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/ci/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nRwAAAOs"]
[Thu Sep 17 15:20:43.690680 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/actions/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nSAAAAQM"]
[Thu Sep 17 15:20:43.701372 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.166.228.3:42196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxZqwpXMN3p_zkwXf2nSQAAAJI"]
[Thu Sep 17 15:20:43.758622 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cd/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nSgAAAOM"]
[Thu Sep 17 15:20:43.875439 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/circleci/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nTQAAAPg"]
[Thu Sep 17 15:20:43.924314 2026] [fcgid:warn] [pid 1012520:tid 1012674] (70014)End of file found: [client 128.14.233.253:36522] mod_fcgid: can't get data from http client
[Thu Sep 17 15:20:43.936856 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/jenkins/.env"] [unique_id "aqxZqwpXMN3p_zkwXf2nUgAAAOA"]
[Thu Sep 17 15:20:44.047207 2026] [security2:error] [pid 1012520:tid 1012696] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/travis/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nVAAAALI"]
[Thu Sep 17 15:20:44.107819 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/gitlab/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nVQAAAPk"]
[Thu Sep 17 15:20:44.235767 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/buildkite/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nVwAAAPI"]
[Thu Sep 17 15:20:44.307959 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/github/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nWAAAAKA"]
[Thu Sep 17 15:20:44.386945 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.166.228.3:42200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxZrApXMN3p_zkwXf2nWgAAAOY"]
[Thu Sep 17 15:20:44.407254 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mysql/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nXAAAAJA"]
[Thu Sep 17 15:20:44.473296 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/actions/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nXQAAALg"]
[Thu Sep 17 15:20:44.587567 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/postgres/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nYAAAAPw"]
[Thu Sep 17 15:20:44.587986 2026] [security2:error] [pid 1012520:tid 1012717] [client 168.158.230.188:39799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZrApXMN3p_zkwXf2nXgAAx3A"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726044506&hideanons=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:20:44.639210 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/circleci/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nYQAAAI0"]
[Thu Sep 17 15:20:44.758207 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/mongodb/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nYwAAAKg"]
[Thu Sep 17 15:20:44.823083 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/travis/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nZAAAALw"]
[Thu Sep 17 15:20:44.921837 2026] [security2:error] [pid 1012520:tid 1012687] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/redis/.env"] [unique_id "aqxZrApXMN3p_zkwXf2nZQAAAKk"]
[Thu Sep 17 15:20:45.002655 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/buildkite/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2naQAAAKE"]
[Thu Sep 17 15:20:45.065151 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.166.228.3:42214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZrQpXMN3p_zkwXf2nagAAAIY"]
[Thu Sep 17 15:20:45.109193 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2nbAAAALQ"]
[Thu Sep 17 15:20:45.186241 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mysql/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2nbQAAALU"]
[Thu Sep 17 15:20:45.324836 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2ncAAAAM4"]
[Thu Sep 17 15:20:45.364823 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/postgres/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2ncQAAAPc"]
[Thu Sep 17 15:20:45.535761 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/kafka/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2newAAAJE"]
[Thu Sep 17 15:20:45.545352 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mongodb/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2nfAAAAMs"]
[Thu Sep 17 15:20:45.712551 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/redis/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2nfQAAANc"]
[Thu Sep 17 15:20:45.734869 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/queue/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2nfgAAALA"]
[Thu Sep 17 15:20:45.755190 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.166.228.3:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxZrQpXMN3p_zkwXf2nfwAAANQ"]
[Thu Sep 17 15:20:45.893540 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/elasticsearch/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2ngAAAANg"]
[Thu Sep 17 15:20:45.929258 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/worker/.env"] [unique_id "aqxZrQpXMN3p_zkwXf2ngwAAAMQ"]
[Thu Sep 17 15:20:46.099706 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/rabbitmq/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nhQAAAL4"]
[Thu Sep 17 15:20:46.102717 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/job/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nhgAAAIo"]
[Thu Sep 17 15:20:46.161378 2026] [security2:error] [pid 1012520:tid 1012775] [client 154.190.208.131:42644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZrgpXMN3p_zkwXf2nhwAAAQE"]
[Thu Sep 17 15:20:46.161502 2026] [security2:error] [pid 1012520:tid 1012775] [client 154.190.208.131:42644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZrgpXMN3p_zkwXf2nhwAAAQE"]
[Thu Sep 17 15:20:46.283036 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/kafka/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2niQAAAQM"]
[Thu Sep 17 15:20:46.285768 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/test/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nigAAAPM"]
[Thu Sep 17 15:20:46.454236 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/queue/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nkgAAAJw"]
[Thu Sep 17 15:20:46.467131 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/qa/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nkwAAAKo"]
[Thu Sep 17 15:20:46.552319 2026] [security2:error] [pid 1012520:tid 1012701] [client 162.241.226.11:24324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxZrgpXMN3p_zkwXf2njAAAALc"]
[Thu Sep 17 15:20:46.636640 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/preview/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nlgAAAPk"]
[Thu Sep 17 15:20:46.645447 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/worker/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nlwAAAP0"]
[Thu Sep 17 15:20:46.706744 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.166.228.3:42220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxZrgpXMN3p_zkwXf2nmAAAAKY"]
[Thu Sep 17 15:20:46.711299 2026] [security2:error] [pid 1012520:tid 1012697] [client 162.241.226.11:24338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxZrgpXMN3p_zkwXf2nlQAAALM"]
[Thu Sep 17 15:20:46.806195 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/beta/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nmgAAAIg"]
[Thu Sep 17 15:20:46.840921 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/job/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nmwAAAK0"]
[Thu Sep 17 15:20:46.991867 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/uat/.env"] [unique_id "aqxZrgpXMN3p_zkwXf2nnwAAAOw"]
[Thu Sep 17 15:20:46.995074 2026] [security2:error] [pid 1012520:tid 1012722] [client 103.61.184.148:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZrgpXMN3p_zkwXf2noAAAAMw"]
[Thu Sep 17 15:20:46.995151 2026] [security2:error] [pid 1012520:tid 1012722] [client 103.61.184.148:61569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZrgpXMN3p_zkwXf2noAAAAMw"]
[Thu Sep 17 15:20:47.044808 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/test/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nogAAAPw"]
[Thu Sep 17 15:20:47.158742 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/stage/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nowAAALk"]
[Thu Sep 17 15:20:47.216484 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/qa/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2npQAAAIk"]
[Thu Sep 17 15:20:47.355265 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/development/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nqAAAAJU"]
[Thu Sep 17 15:20:47.398268 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.166.228.3:42222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxZrwpXMN3p_zkwXf2nqgAAAI0"]
[Thu Sep 17 15:20:47.410269 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/preview/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nrAAAAJY"]
[Thu Sep 17 15:20:47.544854 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/production/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nrgAAALU"]
[Thu Sep 17 15:20:47.590565 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/beta/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nrwAAAO4"]
[Thu Sep 17 15:20:47.717563 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.247.203.201:42342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.com"] [uri "/config/app/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nswAAANw"]
[Thu Sep 17 15:20:47.799857 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/uat/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2ntgAAAOk"]
[Thu Sep 17 15:20:47.929778 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.247.203.201:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/phpinfo.php"] [unique_id "aqxZrwpXMN3p_zkwXf2nuQAAAPs"]
[Thu Sep 17 15:20:47.953508 2026] [security2:error] [pid 1012520:tid 1012774] [client 185.55.149.49:55033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZrwpXMN3p_zkwXf2nugAAAQA"]
[Thu Sep 17 15:20:47.953598 2026] [security2:error] [pid 1012520:tid 1012774] [client 185.55.149.49:55033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZrwpXMN3p_zkwXf2nugAAAQA"]
[Thu Sep 17 15:20:47.971105 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/stage/.env"] [unique_id "aqxZrwpXMN3p_zkwXf2nuwAAALs"]
[Thu Sep 17 15:20:48.084491 2026] [security2:error] [pid 1012520:tid 1012690] [client 186.105.232.15:65321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZsApXMN3p_zkwXf2nvgAAAKw"]
[Thu Sep 17 15:20:48.084627 2026] [security2:error] [pid 1012520:tid 1012690] [client 186.105.232.15:65321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZsApXMN3p_zkwXf2nvgAAAKw"]
[Thu Sep 17 15:20:48.100295 2026] [security2:error] [pid 1012520:tid 1012683] [client 114.198.138.124:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZsApXMN3p_zkwXf2nvwAAAKU"]
[Thu Sep 17 15:20:48.100432 2026] [security2:error] [pid 1012520:tid 1012683] [client 114.198.138.124:50596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZsApXMN3p_zkwXf2nvwAAAKU"]
[Thu Sep 17 15:20:48.103835 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.166.228.3:42238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxZsApXMN3p_zkwXf2nwAAAAKQ"]
[Thu Sep 17 15:20:48.231356 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/development/.env"] [unique_id "aqxZsApXMN3p_zkwXf2nxQAAAOo"]
[Thu Sep 17 15:20:48.409518 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/production/.env"] [unique_id "aqxZsApXMN3p_zkwXf2nyAAAAL8"]
[Thu Sep 17 15:20:48.477087 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.247.203.201:40354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/info.php"] [unique_id "aqxZsApXMN3p_zkwXf2nywAAAME"]
[Thu Sep 17 15:20:48.583744 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.247.203.201:42346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/config/app/.env"] [unique_id "aqxZsApXMN3p_zkwXf2nzgAAANs"]
[Thu Sep 17 15:20:48.766812 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:42346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/phpinfo.php"] [unique_id "aqxZsApXMN3p_zkwXf2n0QAAAQQ"]
[Thu Sep 17 15:20:48.789824 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.166.228.3:42248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxZsApXMN3p_zkwXf2n0gAAAM0"]
[Thu Sep 17 15:20:48.875672 2026] [security2:error] [pid 1012520:tid 1012696] [client 98.56.86.12:40059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZsApXMN3p_zkwXf2n0AAAsig"]
[Thu Sep 17 15:20:49.096453 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.247.203.201:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/php.php"] [unique_id "aqxZsQpXMN3p_zkwXf2n1wAAAPQ"]
[Thu Sep 17 15:20:49.200060 2026] [security2:error] [pid 1012520:tid 1012702] [client 177.24.50.182:44943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZsQpXMN3p_zkwXf2n2AAAuAU"]
[Thu Sep 17 15:20:49.389674 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.247.203.201:40368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/info.php"] [unique_id "aqxZsQpXMN3p_zkwXf2n3QAAAJc"]
[Thu Sep 17 15:20:49.474486 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.166.228.3:42250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxZsQpXMN3p_zkwXf2n4QAAAMc"]
[Thu Sep 17 15:20:49.482057 2026] [security2:error] [pid 1012520:tid 1012772] [client 152.32.215.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kmd.duj.mybluehost.me"] [uri "/index.php"] [unique_id "aqxZsQpXMN3p_zkwXf2n3AAAAP4"]
[Thu Sep 17 15:20:49.770621 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.247.203.201:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/i.php"] [unique_id "aqxZsQpXMN3p_zkwXf2n4wAAAI0"]
[Thu Sep 17 15:20:50.024439 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.247.203.201:40394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/php.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n5wAAANU"]
[Thu Sep 17 15:20:50.179942 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.166.228.3:42256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n6AAAAMg"]
[Thu Sep 17 15:20:50.203483 2026] [security2:error] [pid 1012520:tid 1012700] [client 156.192.234.52:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n6QAAALY"]
[Thu Sep 17 15:20:50.203566 2026] [security2:error] [pid 1012520:tid 1012700] [client 156.192.234.52:63566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n6QAAALY"]
[Thu Sep 17 15:20:50.439823 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.247.203.201:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/pi.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n8QAAANw"]
[Thu Sep 17 15:20:50.633921 2026] [security2:error] [pid 1012520:tid 1012732] [client 98.56.86.12:40518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n9AAA1iI"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726044506&hideanons=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:20:50.676778 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.247.203.201:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/i.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n9wAAAPc"]
[Thu Sep 17 15:20:50.975130 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.247.203.201:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/pinfo.php"] [unique_id "aqxZsgpXMN3p_zkwXf2n_wAAAKI"]
[Thu Sep 17 15:20:51.258281 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.247.203.201:43326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/pi.php"] [unique_id "aqxZswpXMN3p_zkwXf2oBAAAAQE"]
[Thu Sep 17 15:20:51.433961 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.166.228.3:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZswpXMN3p_zkwXf2oEQAAAQI"]
[Thu Sep 17 15:20:51.552291 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.247.203.201:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/test.php"] [unique_id "aqxZswpXMN3p_zkwXf2oEgAAAKs"]
[Thu Sep 17 15:20:51.807704 2026] [security2:error] [pid 1012520:tid 1012771] [client 192.220.247.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arrowake.com"] [uri "/index.php"] [unique_id "aqxZswpXMN3p_zkwXf2oDwAAAP0"]
[Thu Sep 17 15:20:51.817650 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.247.203.201:43332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/pinfo.php"] [unique_id "aqxZswpXMN3p_zkwXf2oFQAAAIs"]
[Thu Sep 17 15:20:51.851842 2026] [security2:error] [pid 1012520:tid 1012722] [client 177.101.117.113:15617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZswpXMN3p_zkwXf2oEwAAzB0"]
[Thu Sep 17 15:20:52.117775 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.166.228.3:42280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxZtApXMN3p_zkwXf2oGgAAAKA"]
[Thu Sep 17 15:20:52.291934 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.247.203.201:43342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZtApXMN3p_zkwXf2oGQAAAJM"]
[Thu Sep 17 15:20:52.400863 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.247.203.201:43356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/test.php"] [unique_id "aqxZtApXMN3p_zkwXf2oHwAAAIk"]
[Thu Sep 17 15:20:52.774854 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.247.203.201:43342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/p.php"] [unique_id "aqxZtApXMN3p_zkwXf2oJwAAAM4"]
[Thu Sep 17 15:20:52.804232 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.166.228.3:33114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZtApXMN3p_zkwXf2oKAAAAKM"]
[Thu Sep 17 15:20:53.100823 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.247.203.201:43368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZtApXMN3p_zkwXf2oLAAAAOI"]
[Thu Sep 17 15:20:53.319543 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.247.203.201:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/debug.php"] [unique_id "aqxZtQpXMN3p_zkwXf2oLQAAAPs"]
[Thu Sep 17 15:20:53.429843 2026] [security2:error] [pid 1012520:tid 1012734] [client 136.116.35.245:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "moneysmartlatina.com"] [uri "/.env"] [unique_id "aqxZtQpXMN3p_zkwXf2oMAAAANg"]
[Thu Sep 17 15:20:53.504701 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.166.228.3:33130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZtQpXMN3p_zkwXf2oNAAAAK8"]
[Thu Sep 17 15:20:53.586160 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.247.203.201:43368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/p.php"] [unique_id "aqxZtQpXMN3p_zkwXf2oNwAAAKw"]
[Thu Sep 17 15:20:53.773237 2026] [security2:error] [pid 1012520:tid 1012617] [remote 136.116.35.245:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "moneysmartlatina.com"] [uri "/.env"] [unique_id "aqxZtQpXMN3p_zkwXf2oOQAAxV8"]
[Thu Sep 17 15:20:53.918994 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.247.203.201:43394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZtQpXMN3p_zkwXf2oPAAAAJg"]
[Thu Sep 17 15:20:54.192446 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.166.228.3:33134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZtgpXMN3p_zkwXf2oQQAAAK4"]
[Thu Sep 17 15:20:54.193150 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.247.203.201:43398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/debug.php"] [unique_id "aqxZtgpXMN3p_zkwXf2oQgAAALE"]
[Thu Sep 17 15:20:54.506057 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:43404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZtgpXMN3p_zkwXf2oRwAAAL8"]
[Thu Sep 17 15:20:54.737577 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.247.203.201:43408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZtgpXMN3p_zkwXf2oSgAAAO8"]
[Thu Sep 17 15:20:54.904294 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.166.228.3:33150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZtgpXMN3p_zkwXf2oTQAAALc"]
[Thu Sep 17 15:20:55.109938 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.247.203.201:43414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZtwpXMN3p_zkwXf2oVAAAAPI"]
[Thu Sep 17 15:20:55.377786 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.247.203.201:43424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZtwpXMN3p_zkwXf2oWQAAALg"]
[Thu Sep 17 15:20:55.598239 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.166.228.3:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxZtwpXMN3p_zkwXf2oXwAAAOM"]
[Thu Sep 17 15:20:55.680823 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:43428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZtwpXMN3p_zkwXf2oYQAAAQQ"]
[Thu Sep 17 15:20:56.072793 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.247.203.201:43442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZuApXMN3p_zkwXf2oZwAAAJY"]
[Thu Sep 17 15:20:56.238819 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.247.203.201:43448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZuApXMN3p_zkwXf2oagAAAOQ"]
[Thu Sep 17 15:20:56.293346 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.166.228.3:33172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxZuApXMN3p_zkwXf2oawAAAJk"]
[Thu Sep 17 15:20:56.674306 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.247.203.201:43452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZuApXMN3p_zkwXf2ocAAAANg"]
[Thu Sep 17 15:20:56.798214 2026] [security2:error] [pid 1012520:tid 1012774] [client 154.190.208.131:41940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZuApXMN3p_zkwXf2ocgAAAQA"]
[Thu Sep 17 15:20:56.798334 2026] [security2:error] [pid 1012520:tid 1012774] [client 154.190.208.131:41940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZuApXMN3p_zkwXf2ocgAAAQA"]
[Thu Sep 17 15:20:56.974384 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.166.228.3:33176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxZuApXMN3p_zkwXf2odgAAAOo"]
[Thu Sep 17 15:20:57.031815 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.247.203.201:43468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZuQpXMN3p_zkwXf2oeQAAAK8"]
[Thu Sep 17 15:20:57.231004 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.247.203.201:43472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZuQpXMN3p_zkwXf2ogwAAAJE"]
[Thu Sep 17 15:20:57.278958 2026] [security2:error] [pid 1012520:tid 1012741] [client 152.32.215.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kmd.duj.mybluehost.me"] [uri "/index.php"] [unique_id "aqxZuQpXMN3p_zkwXf2ogAAAAN8"]
[Thu Sep 17 15:20:57.646156 2026] [security2:error] [pid 1012520:tid 1012770] [client 192.241.166.94:58576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jaymadera.com"] [uri "/index.php"] [unique_id "aqxZtwpXMN3p_zkwXf2oVgAA_DE"], referer: http://jaymadera.com/old/
[Thu Sep 17 15:20:57.669047 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.166.228.3:33190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxZuQpXMN3p_zkwXf2omQAAANs"]
[Thu Sep 17 15:20:57.750252 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.247.203.201:43488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZuQpXMN3p_zkwXf2omAAAAPM"]
[Thu Sep 17 15:20:57.796099 2026] [security2:error] [pid 1012520:tid 1012709] [client 103.61.184.148:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZuQpXMN3p_zkwXf2ooAAAAL8"]
[Thu Sep 17 15:20:57.796208 2026] [security2:error] [pid 1012520:tid 1012709] [client 103.61.184.148:62131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZuQpXMN3p_zkwXf2ooAAAAL8"]
[Thu Sep 17 15:20:57.817852 2026] [security2:error] [pid 1012520:tid 1012755] [client 165.154.29.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lumenroast.com"] [uri "/index.php"] [unique_id "aqxZuQpXMN3p_zkwXf2ofwAAAO0"], referer: http://mail.avo.jgb.mybluehost.me/favicon.ico
[Thu Sep 17 15:20:57.844779 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.247.203.201:43492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZuQpXMN3p_zkwXf2oogAAAOw"]
[Thu Sep 17 15:20:57.844901 2026] [security2:error] [pid 1012520:tid 1012748] [client 192.241.166.94:58576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jaymadera.com"] [uri "/index.php"] [unique_id "aqxZuQpXMN3p_zkwXf2onAAA5iY"], referer: http://jaymadera.com/wordpress/
[Thu Sep 17 15:20:58.032223 2026] [security2:error] [pid 1012520:tid 1012778] [client 192.241.166.94:58576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jaymadera.com"] [uri "/index.php"] [unique_id "aqxZuQpXMN3p_zkwXf2oqgABBC0"], referer: http://jaymadera.com/wp/
[Thu Sep 17 15:20:58.210765 2026] [security2:error] [pid 1012520:tid 1012677] [client 201.58.89.93:1608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZugpXMN3p_zkwXf2orQAAny4"]
[Thu Sep 17 15:20:58.223222 2026] [security2:error] [pid 1012520:tid 1012717] [client 192.241.166.94:58576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jaymadera.com"] [uri "/index.php"] [unique_id "aqxZugpXMN3p_zkwXf2osAAAx1g"], referer: http://jaymadera.com/backup/
[Thu Sep 17 15:20:58.235746 2026] [security2:error] [pid 1012520:tid 1012722] [client 35.247.203.201:43488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/php-info.php"] [unique_id "aqxZugpXMN3p_zkwXf2osQAAAMw"]
[Thu Sep 17 15:20:58.375025 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.166.228.3:33194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxZugpXMN3p_zkwXf2otgAAAIk"]
[Thu Sep 17 15:20:58.636540 2026] [security2:error] [pid 1012520:tid 1012732] [client 192.241.166.94:58576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jaymadera.com"] [uri "/index.php"] [unique_id "aqxZugpXMN3p_zkwXf2ovQAA1lE"], referer: http://jaymadera.com/new/
[Thu Sep 17 15:20:58.653577 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.247.203.201:43502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZugpXMN3p_zkwXf2ouwAAAJY"]
[Thu Sep 17 15:20:58.670998 2026] [security2:error] [pid 1012520:tid 1012669] [client 114.198.138.124:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZugpXMN3p_zkwXf2ovwAAAJc"]
[Thu Sep 17 15:20:58.671132 2026] [security2:error] [pid 1012520:tid 1012669] [client 114.198.138.124:51234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZugpXMN3p_zkwXf2ovwAAAJc"]
[Thu Sep 17 15:20:58.684510 2026] [security2:error] [pid 1012520:tid 1012746] [client 185.55.149.49:58529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZugpXMN3p_zkwXf2owAAAAOQ"]
[Thu Sep 17 15:20:58.684622 2026] [security2:error] [pid 1012520:tid 1012746] [client 185.55.149.49:58529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZugpXMN3p_zkwXf2owAAAAOQ"]
[Thu Sep 17 15:20:58.779724 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.247.203.201:43514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/phpversion.php"] [unique_id "aqxZugpXMN3p_zkwXf2owgAAALs"]
[Thu Sep 17 15:20:58.829205 2026] [security2:error] [pid 1012520:tid 1012752] [client 192.241.166.94:58576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jaymadera.com"] [uri "/index.php"] [unique_id "aqxZugpXMN3p_zkwXf2owwAA6kw"], referer: http://jaymadera.com/blog/
[Thu Sep 17 15:20:59.081236 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.166.228.3:33208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxZuwpXMN3p_zkwXf2oygAAANk"]
[Thu Sep 17 15:20:59.136183 2026] [security2:error] [pid 1012520:tid 1012628] [remote 110.249.201.253:61450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/calendar"] [unique_id "aqxZuwpXMN3p_zkwXf2ozAABAWo"]
[Thu Sep 17 15:20:59.192058 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.247.203.201:43502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/php-info.php"] [unique_id "aqxZuwpXMN3p_zkwXf2ozQAAAKY"]
[Thu Sep 17 15:20:59.511727 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.247.203.201:43526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/_phpinfo.php"] [unique_id "aqxZuwpXMN3p_zkwXf2o1wAAAP8"]
[Thu Sep 17 15:20:59.564985 2026] [security2:error] [pid 1012520:tid 1012695] [client 186.105.232.15:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZuwpXMN3p_zkwXf2o2QAAALE"]
[Thu Sep 17 15:20:59.565074 2026] [security2:error] [pid 1012520:tid 1012695] [client 186.105.232.15:49533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZuwpXMN3p_zkwXf2o2QAAALE"]
[Thu Sep 17 15:20:59.778596 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.166.228.3:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxZuwpXMN3p_zkwXf2o3AAAANs"]
[Thu Sep 17 15:20:59.821828 2026] [security2:error] [pid 1012520:tid 1012694] [client 74.7.241.177:41646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-64ec2c6a.dov.wxt.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxZuwpXMN3p_zkwXf2o3gAAALA"]
[Thu Sep 17 15:20:59.824427 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.247.203.201:43542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/phpversion.php"] [unique_id "aqxZuwpXMN3p_zkwXf2o3wAAAPM"]
[Thu Sep 17 15:21:00.241918 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.247.203.201:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZvApXMN3p_zkwXf2o7AAAAQQ"]
[Thu Sep 17 15:21:00.420880 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.247.203.201:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/_phpinfo.php"] [unique_id "aqxZvApXMN3p_zkwXf2o9QAAANE"]
[Thu Sep 17 15:21:00.422053 2026] [security2:error] [pid 1012520:tid 1012677] [client 167.172.45.115:35062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvApXMN3p_zkwXf2o7QAAAJ8"]
[Thu Sep 17 15:21:00.470815 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.166.228.3:33214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxZvApXMN3p_zkwXf2o9wAAAJs"]
[Thu Sep 17 15:21:00.754882 2026] [security2:error] [pid 1012520:tid 1012659] [client 156.192.234.52:64235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZvApXMN3p_zkwXf2o_QAAAI0"]
[Thu Sep 17 15:21:00.754976 2026] [security2:error] [pid 1012520:tid 1012659] [client 156.192.234.52:64235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZvApXMN3p_zkwXf2o_QAAAI0"]
[Thu Sep 17 15:21:00.852878 2026] [security2:error] [pid 1012520:tid 1012671] [client 167.172.45.115:35064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvApXMN3p_zkwXf2o_gAAAJk"], referer: http://www.fireflyhotglass.net/new/
[Thu Sep 17 15:21:00.854699 2026] [security2:error] [pid 1012520:tid 1012669] [client 185.187.78.128:30469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZvApXMN3p_zkwXf2o_AAAl3o"]
[Thu Sep 17 15:21:00.982518 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.247.203.201:56288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/server-info.php"] [unique_id "aqxZvApXMN3p_zkwXf2pBgAAAN4"]
[Thu Sep 17 15:21:01.147933 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.166.228.3:33222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pDQAAAOk"]
[Thu Sep 17 15:21:01.177048 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.247.203.201:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pDgAAAMs"]
[Thu Sep 17 15:21:01.588223 2026] [security2:error] [pid 1012520:tid 1012695] [client 167.172.45.115:35062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pGwAAALE"]
[Thu Sep 17 15:21:01.611255 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.247.203.201:56308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/server-status.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pHQAAAP8"]
[Thu Sep 17 15:21:01.839131 2026] [security2:error] [pid 1012520:tid 1012768] [client 167.172.45.115:35064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pHgAAAPo"], referer: http://www.fireflyhotglass.net/wordpress/
[Thu Sep 17 15:21:01.843869 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.166.228.3:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pIAAAAJw"]
[Thu Sep 17 15:21:01.951465 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:56320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/server-info.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pJAAAAPw"]
[Thu Sep 17 15:21:02.098868 2026] [access_compat:error] [pid 1012520:tid 1012665] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/the-house-of-da-vinci-enhanced
[Thu Sep 17 15:21:02.107731 2026] [security2:error] [pid 1012520:tid 1012754] [client 167.172.45.115:35062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvQpXMN3p_zkwXf2pJgAAAOw"]
[Thu Sep 17 15:21:02.394568 2026] [security2:error] [pid 1012520:tid 1012772] [client 35.247.203.201:56336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pLgAAAP4"]
[Thu Sep 17 15:21:02.394631 2026] [security2:error] [pid 1012520:tid 1012675] [client 167.172.45.115:35064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pNQAAAJ0"], referer: http://www.fireflyhotglass.net/blog/
[Thu Sep 17 15:21:02.528145 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.166.228.3:55028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pOwAAANQ"]
[Thu Sep 17 15:21:02.575074 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.247.203.201:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/server-status.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pPQAAALU"]
[Thu Sep 17 15:21:02.639001 2026] [security2:error] [pid 1012520:tid 1012756] [client 167.172.45.115:35062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pPAAAAO4"]
[Thu Sep 17 15:21:02.880791 2026] [security2:error] [pid 1012520:tid 1012746] [client 167.172.45.115:35064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pRAAAAOQ"], referer: http://www.fireflyhotglass.net/backup/
[Thu Sep 17 15:21:02.937475 2026] [security2:error] [pid 1012520:tid 1012654] [client 74.7.230.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-cc9d9bdc.kiyetec1.com"] [uri "/index.php"] [unique_id "aqxZuwpXMN3p_zkwXf2o1QAAAIg"]
[Thu Sep 17 15:21:02.942028 2026] [security2:error] [pid 1012520:tid 1012701] [client 74.7.230.46:57250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-cc9d9bdc.kiyetec1.com"] [uri "/robots.txt"] [unique_id "aqxZuwpXMN3p_zkwXf2o0gAAt0E"]
[Thu Sep 17 15:21:03.085349 2026] [security2:error] [pid 1012520:tid 1012693] [client 169.58.197.253:53845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pUAAAAK8"], referer: binance.com
[Thu Sep 17 15:21:03.088363 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.247.203.201:56336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pTQAAAJg"]
[Thu Sep 17 15:21:03.136395 2026] [security2:error] [pid 1012520:tid 1012683] [client 167.172.45.115:35062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pTwAAAKU"]
[Thu Sep 17 15:21:03.209004 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.166.228.3:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pUgAAANA"]
[Thu Sep 17 15:21:03.214611 2026] [security2:error] [pid 1012520:tid 1012734] [client 74.7.230.32:53872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "smwinternational.gocbeglobal.com"] [uri "/robots.txt"] [unique_id "aqxZvwpXMN3p_zkwXf2pUwAA2GQ"]
[Thu Sep 17 15:21:03.385461 2026] [security2:error] [pid 1012520:tid 1012753] [client 167.172.45.115:35064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pWAAAAOs"], referer: http://www.fireflyhotglass.net/old/
[Thu Sep 17 15:21:03.410779 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.247.203.201:56352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pVgAAANU"]
[Thu Sep 17 15:21:03.415636 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.247.203.201:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZvwpXMN3p_zkwXf2pWgAAAO8"]
[Thu Sep 17 15:21:03.418318 2026] [security2:error] [pid 1012520:tid 1012680] [client 74.7.175.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pSgAAAKI"]
[Thu Sep 17 15:21:03.418336 2026] [security2:error] [pid 1012520:tid 1012680] [client 74.7.175.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxZvgpXMN3p_zkwXf2pSgAAAKI"]
[Thu Sep 17 15:21:03.516095 2026] [security2:error] [pid 1012520:tid 1012774] [client 74.7.175.151:50854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sableandox.co.uk"] [uri "/robots.txt"] [unique_id "aqxZvgpXMN3p_zkwXf2pRQABAFM"]
[Thu Sep 17 15:21:03.635537 2026] [security2:error] [pid 1012520:tid 1012760] [client 167.172.45.115:35062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pXgAAAPI"]
[Thu Sep 17 15:21:03.887465 2026] [security2:error] [pid 1012520:tid 1012742] [client 167.172.45.115:35064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pZAAAAOA"], referer: http://www.fireflyhotglass.net/wp/
[Thu Sep 17 15:21:03.893566 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.166.228.3:55054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pZgAAALI"]
[Thu Sep 17 15:21:03.934528 2026] [security2:error] [pid 1012520:tid 1012702] [client 74.7.175.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pYwAAALg"], referer: https://www.sableandox.co.uk/robots.txt
[Thu Sep 17 15:21:03.946137 2026] [security2:error] [pid 1012520:tid 1012749] [client 74.7.175.151:50860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sableandox.co.uk"] [uri "/robots.txt"] [unique_id "aqxZvwpXMN3p_zkwXf2pYQAA51Y"], referer: https://www.sableandox.co.uk/robots.txt
[Thu Sep 17 15:21:03.983629 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pawAAAPw"]
[Thu Sep 17 15:21:04.028762 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.247.203.201:56352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/index.php"] [unique_id "aqxZvwpXMN3p_zkwXf2pZwAAAJM"]
[Thu Sep 17 15:21:04.429581 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.247.203.201:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZwApXMN3p_zkwXf2pdAAAALQ"]
[Thu Sep 17 15:21:04.579846 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.166.228.3:55060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxZwApXMN3p_zkwXf2peAAAANI"]
[Thu Sep 17 15:21:04.647802 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.247.203.201:56376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZwApXMN3p_zkwXf2pegAAANQ"]
[Thu Sep 17 15:21:05.068230 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.247.203.201:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZwQpXMN3p_zkwXf2pjAAAAME"]
[Thu Sep 17 15:21:05.140284 2026] [security2:error] [pid 1012520:tid 1012525] [remote 111.225.148.253:30356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.joeledmundanderson.com"] [uri "/"] [unique_id "aqxZwQpXMN3p_zkwXf2pjQAAmgM"]
[Thu Sep 17 15:21:05.250653 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.247.203.201:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZwQpXMN3p_zkwXf2pjwAAAJk"]
[Thu Sep 17 15:21:05.275081 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.166.228.3:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxZwQpXMN3p_zkwXf2pkAAAAMY"]
[Thu Sep 17 15:21:05.604146 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.247.203.201:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZwQpXMN3p_zkwXf2pmwAAAPU"]
[Thu Sep 17 15:21:05.877208 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.247.203.201:56404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZwQpXMN3p_zkwXf2pnwAAAL0"]
[Thu Sep 17 15:21:05.998378 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.166.228.3:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZwQpXMN3p_zkwXf2powAAAJw"]
[Thu Sep 17 15:21:06.228079 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZwgpXMN3p_zkwXf2prwAAAL8"]
[Thu Sep 17 15:21:06.234337 2026] [security2:error] [pid 1012520:tid 1012750] [client 93.56.132.162:37293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZwgpXMN3p_zkwXf2pqQAA6G8"]
[Thu Sep 17 15:21:06.442054 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.247.203.201:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZwgpXMN3p_zkwXf2pvgAAAIY"]
[Thu Sep 17 15:21:06.682459 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.166.228.3:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZwgpXMN3p_zkwXf2pwgAAAMc"]
[Thu Sep 17 15:21:06.758719 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.247.203.201:56428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZwgpXMN3p_zkwXf2pxQAAAL4"]
[Thu Sep 17 15:21:07.057360 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.247.203.201:56440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZwwpXMN3p_zkwXf2pzAAAAKU"]
[Thu Sep 17 15:21:07.362103 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.166.228.3:55088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxZwwpXMN3p_zkwXf2p0gAAAJk"]
[Thu Sep 17 15:21:07.370891 2026] [security2:error] [pid 1012520:tid 1012713] [client 154.190.208.131:42545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZwwpXMN3p_zkwXf2p0wAAAMM"]
[Thu Sep 17 15:21:07.370990 2026] [security2:error] [pid 1012520:tid 1012713] [client 154.190.208.131:42545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZwwpXMN3p_zkwXf2p0wAAAMM"]
[Thu Sep 17 15:21:07.453874 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.247.203.201:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZwwpXMN3p_zkwXf2p1wAAAKY"]
[Thu Sep 17 15:21:07.486554 2026] [security2:error] [pid 1012520:tid 1012688] [client 52.167.144.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxZwgpXMN3p_zkwXf2prgAAAKo"]
[Thu Sep 17 15:21:07.529927 2026] [security2:error] [pid 1012520:tid 1012721] [client 104.28.198.244:22582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.198.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZwwpXMN3p_zkwXf2p2gAAAMs"]
[Thu Sep 17 15:21:07.530039 2026] [security2:error] [pid 1012520:tid 1012721] [client 104.28.198.244:22582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allin1.com"] [uri "/xmlrpc.php"] [unique_id "aqxZwwpXMN3p_zkwXf2p2gAAAMs"]
[Thu Sep 17 15:21:07.738195 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.247.203.201:56448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZwwpXMN3p_zkwXf2p3gAAAQI"]
[Thu Sep 17 15:21:08.000716 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.247.203.201:56452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZwwpXMN3p_zkwXf2p5AAAAPw"]
[Thu Sep 17 15:21:08.047897 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.166.228.3:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.gob.izs.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxZxApXMN3p_zkwXf2p6AAAAOc"]
[Thu Sep 17 15:21:08.361103 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.247.203.201:56458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/phpinfo.php~"] [unique_id "aqxZxApXMN3p_zkwXf2p7gAAAMo"]
[Thu Sep 17 15:21:08.429052 2026] [security2:error] [pid 1012520:tid 1012750] [client 103.61.184.148:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxApXMN3p_zkwXf2p8wAAAOg"]
[Thu Sep 17 15:21:08.429167 2026] [security2:error] [pid 1012520:tid 1012750] [client 103.61.184.148:62685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxApXMN3p_zkwXf2p8wAAAOg"]
[Thu Sep 17 15:21:08.743166 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.247.203.201:56462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZxApXMN3p_zkwXf2p-AAAAI0"]
[Thu Sep 17 15:21:08.903320 2026] [security2:error] [pid 1012520:tid 1012678] [client 132.255.55.179:13872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZxApXMN3p_zkwXf2p-QAAoBc"]
[Thu Sep 17 15:21:08.968970 2026] [security2:error] [pid 1012520:tid 1012697] [client 35.247.203.201:56472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/info.php.bak"] [unique_id "aqxZxApXMN3p_zkwXf2p_wAAALM"]
[Thu Sep 17 15:21:09.300154 2026] [security2:error] [pid 1012520:tid 1012717] [client 114.198.138.124:51873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxQpXMN3p_zkwXf2qBgAAAMc"]
[Thu Sep 17 15:21:09.300255 2026] [security2:error] [pid 1012520:tid 1012717] [client 114.198.138.124:51873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxQpXMN3p_zkwXf2qBgAAAMc"]
[Thu Sep 17 15:21:09.365606 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.247.203.201:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/phpinfo.php~"] [unique_id "aqxZxQpXMN3p_zkwXf2qBwAAANk"]
[Thu Sep 17 15:21:09.422749 2026] [security2:error] [pid 1012520:tid 1012685] [client 185.55.149.49:59229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZxQpXMN3p_zkwXf2qCgAAAKc"]
[Thu Sep 17 15:21:09.425482 2026] [security2:error] [pid 1012520:tid 1012685] [client 185.55.149.49:59229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZxQpXMN3p_zkwXf2qCgAAAKc"]
[Thu Sep 17 15:21:09.556554 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.247.203.201:56494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZxQpXMN3p_zkwXf2qDgAAANg"]
[Thu Sep 17 15:21:09.957429 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.247.203.201:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/info.php.bak"] [unique_id "aqxZxQpXMN3p_zkwXf2qGAAAAPY"]
[Thu Sep 17 15:21:10.143832 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.247.203.201:36032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZxgpXMN3p_zkwXf2qGwAAAKI"]
[Thu Sep 17 15:21:10.191061 2026] [security2:error] [pid 1012520:tid 1012768] [client 169.58.197.253:54324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/abilities.php"] [unique_id "aqxZxgpXMN3p_zkwXf2qHAAAAPo"], referer: binance.com
[Thu Sep 17 15:21:10.493709 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.247.203.201:36048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZxgpXMN3p_zkwXf2qJAAAAPM"]
[Thu Sep 17 15:21:10.735485 2026] [security2:error] [pid 1012520:tid 1012707] [client 186.105.232.15:50131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxgpXMN3p_zkwXf2qKQAAAL0"]
[Thu Sep 17 15:21:10.735644 2026] [security2:error] [pid 1012520:tid 1012707] [client 186.105.232.15:50131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxgpXMN3p_zkwXf2qKQAAAL0"]
[Thu Sep 17 15:21:10.767970 2026] [security2:error] [pid 1012520:tid 1012696] [client 35.247.203.201:36064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZxgpXMN3p_zkwXf2qKwAAALI"]
[Thu Sep 17 15:21:10.985923 2026] [security2:error] [pid 1012520:tid 1012750] [client 162.241.226.11:19766] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxZxgpXMN3p_zkwXf2qNAAAAOg"]
[Thu Sep 17 15:21:11.102728 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.247.203.201:36074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZxwpXMN3p_zkwXf2qNgAAALQ"]
[Thu Sep 17 15:21:11.276405 2026] [security2:error] [pid 1012520:tid 1012660] [client 114.119.133.56:26709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mavenme.com"] [uri "/managed-services-dubai"] [unique_id "aqxZxwpXMN3p_zkwXf2qOQAAAI4"], referer: http://www.mavenme.com/managed-services-dubai
[Thu Sep 17 15:21:11.346431 2026] [security2:error] [pid 1012520:tid 1012681] [client 156.192.234.52:64905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxwpXMN3p_zkwXf2qOwAAAKM"]
[Thu Sep 17 15:21:11.347789 2026] [security2:error] [pid 1012520:tid 1012681] [client 156.192.234.52:64905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZxwpXMN3p_zkwXf2qOwAAAKM"]
[Thu Sep 17 15:21:11.408518 2026] [security2:error] [pid 1012520:tid 1012728] [client 74.7.230.63:39776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.forskel.com"] [uri "/robots.txt"] [unique_id "aqxZxwpXMN3p_zkwXf2qPQAA0gc"]
[Thu Sep 17 15:21:11.410911 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.247.203.201:36084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZxwpXMN3p_zkwXf2qPgAAAM4"]
[Thu Sep 17 15:21:11.714878 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.247.203.201:36092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZxwpXMN3p_zkwXf2qSQAAAOI"]
[Thu Sep 17 15:21:12.089044 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.247.203.201:36106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZyApXMN3p_zkwXf2qUwAAANA"]
[Thu Sep 17 15:21:12.272231 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.247.203.201:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZyApXMN3p_zkwXf2qXgAAAN8"]
[Thu Sep 17 15:21:12.720718 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.247.203.201:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZyApXMN3p_zkwXf2qawAAAIs"]
[Thu Sep 17 15:21:12.840778 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.247.203.201:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZyApXMN3p_zkwXf2qbgAAANY"]
[Thu Sep 17 15:21:13.300901 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.247.203.201:36156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZyQpXMN3p_zkwXf2qngAAAL8"]
[Thu Sep 17 15:21:13.484032 2026] [security2:error] [pid 1012520:tid 1012660] [client 162.241.226.11:50232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxZyQpXMN3p_zkwXf2qiQAAAI4"]
[Thu Sep 17 15:21:13.555391 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.247.203.201:36170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZyQpXMN3p_zkwXf2qqAAAAOE"]
[Thu Sep 17 15:21:13.725134 2026] [security2:error] [pid 1012520:tid 1012752] [client 162.241.226.11:50242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxZyQpXMN3p_zkwXf2qpwAAAOo"]
[Thu Sep 17 15:21:13.983254 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.247.203.201:36184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZyQpXMN3p_zkwXf2qtAAAALs"]
[Thu Sep 17 15:21:14.148735 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.247.203.201:36192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZygpXMN3p_zkwXf2quQAAALY"]
[Thu Sep 17 15:21:14.631605 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.247.203.201:36208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZygpXMN3p_zkwXf2qxgAAAPM"]
[Thu Sep 17 15:21:14.727569 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.247.203.201:36222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZygpXMN3p_zkwXf2qygAAAPU"]
[Thu Sep 17 15:21:15.054782 2026] [core:error] [pid 1012520:tid 1012778] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.054804 2026] [core:error] [pid 1012520:tid 1012778] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.219996 2026] [fcgid:warn] [pid 1012520:tid 1012691] (70014)End of file found: [client 152.32.215.224:57712] mod_fcgid: can't get data from http client
[Thu Sep 17 15:21:15.269850 2026] [core:error] [pid 1012520:tid 1012724] [client 34.94.205.103:33712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.269870 2026] [core:error] [pid 1012520:tid 1012724] [client 34.94.205.103:33712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.288003 2026] [security2:error] [pid 1012520:tid 1012710] [client 193.36.224.168:44083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/000.php"] [unique_id "aqxZywpXMN3p_zkwXf2q3QAAAMA"]
[Thu Sep 17 15:21:15.297354 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.247.203.201:36226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZywpXMN3p_zkwXf2q3gAAALQ"]
[Thu Sep 17 15:21:15.460453 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.247.203.201:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZywpXMN3p_zkwXf2q4QAAAPA"]
[Thu Sep 17 15:21:15.546873 2026] [core:error] [pid 1012520:tid 1012730] [client 34.94.205.103:33724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.546892 2026] [core:error] [pid 1012520:tid 1012730] [client 34.94.205.103:33724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.717589 2026] [core:error] [pid 1012520:tid 1012727] [client 34.94.205.103:33730] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.717609 2026] [core:error] [pid 1012520:tid 1012727] [client 34.94.205.103:33730] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:15.850326 2026] [security2:error] [pid 1012520:tid 1012684] [client 193.36.224.108:60263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/about.php"] [unique_id "aqxZywpXMN3p_zkwXf2q7wAAAKY"]
[Thu Sep 17 15:21:15.885831 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.247.203.201:36244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZywpXMN3p_zkwXf2q8AAAAJA"]
[Thu Sep 17 15:21:15.940362 2026] [security2:error] [pid 1012520:tid 1012560] [remote 185.226.197.42:29728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "timalba.com"] [uri "/index.php"] [unique_id "aqxZywpXMN3p_zkwXf2q7QAAqiY"]
[Thu Sep 17 15:21:16.095984 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.247.203.201:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZzApXMN3p_zkwXf2q9QAAANU"]
[Thu Sep 17 15:21:16.196874 2026] [security2:error] [pid 1012520:tid 1012694] [client 20.219.28.139:2022] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.richflaherty.com"] [uri "/1.php"] [unique_id "aqxZzApXMN3p_zkwXf2q9gAAALA"]
[Thu Sep 17 15:21:16.221468 2026] [security2:error] [pid 1012520:tid 1012776] [client 216.24.219.89:51615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxZzApXMN3p_zkwXf2q-AAAAQI"]
[Thu Sep 17 15:21:16.222509 2026] [security2:error] [pid 1012520:tid 1012694] [client 20.219.28.139:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/1.php"] [unique_id "aqxZzApXMN3p_zkwXf2q9gAAALA"]
[Thu Sep 17 15:21:16.385982 2026] [core:error] [pid 1012520:tid 1012686] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:16.386002 2026] [core:error] [pid 1012520:tid 1012686] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:16.456942 2026] [security2:error] [pid 1012520:tid 1012767] [client 20.219.28.139:2004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/new.php"] [unique_id "aqxZzApXMN3p_zkwXf2rAQAAAPk"]
[Thu Sep 17 15:21:16.472999 2026] [security2:error] [pid 1012520:tid 1012737] [client 169.58.197.253:54781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxZzApXMN3p_zkwXf2rAgAAANs"], referer: binance.com
[Thu Sep 17 15:21:16.493233 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.247.203.201:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZzApXMN3p_zkwXf2rAwAAAOw"]
[Thu Sep 17 15:21:16.711641 2026] [core:error] [pid 1012520:tid 1012653] [client 34.94.205.103:33736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:16.711669 2026] [core:error] [pid 1012520:tid 1012653] [client 34.94.205.103:33736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:16.748324 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.247.203.201:36268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZzApXMN3p_zkwXf2rCwAAANY"]
[Thu Sep 17 15:21:16.782535 2026] [security2:error] [pid 1012520:tid 1012658] [client 193.36.224.167:42157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxZzApXMN3p_zkwXf2rDQAAAIw"]
[Thu Sep 17 15:21:16.832797 2026] [security2:error] [pid 1012520:tid 1012745] [client 185.226.197.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "timalba.com"] [uri "/index.php"] [unique_id "aqxZzApXMN3p_zkwXf2rBQAAAOM"]
[Thu Sep 17 15:21:16.959360 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.94.205.103:33752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxZzApXMN3p_zkwXf2rEQAAAIg"]
[Thu Sep 17 15:21:17.034583 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.247.203.201:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rFQAAAK0"]
[Thu Sep 17 15:21:17.052417 2026] [core:error] [pid 1012520:tid 1012661] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:17.052438 2026] [core:error] [pid 1012520:tid 1012661] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:17.168837 2026] [security2:error] [pid 1012520:tid 1012724] [client 20.219.28.139:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/num.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rGAAAAM4"]
[Thu Sep 17 15:21:17.330106 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.247.203.201:36282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rKAAAALc"]
[Thu Sep 17 15:21:17.377182 2026] [security2:error] [pid 1012520:tid 1012662] [client 104.234.19.152:49569] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rKgAAAJA"]
[Thu Sep 17 15:21:17.495252 2026] [core:error] [pid 1012520:tid 1012774] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:17.495276 2026] [core:error] [pid 1012520:tid 1012774] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:17.607920 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.247.203.201:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rMQAAAKU"]
[Thu Sep 17 15:21:17.760347 2026] [security2:error] [pid 1012520:tid 1012754] [client 216.24.219.31:42951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rNgAAAOw"]
[Thu Sep 17 15:21:17.789015 2026] [security2:error] [pid 1012520:tid 1012568] [remote 111.225.148.146:48120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.christiansoncampusnlc.com"] [uri "/wp-content/uploads/2020/08/143-Healthy-Words-1-300x225.jpg"] [unique_id "aqxZzQpXMN3p_zkwXf2rOQAAsC4"]
[Thu Sep 17 15:21:17.894171 2026] [core:error] [pid 1012520:tid 1012673] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:17.894192 2026] [core:error] [pid 1012520:tid 1012673] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:17.927054 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.247.203.201:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rQQAAANs"]
[Thu Sep 17 15:21:17.975464 2026] [security2:error] [pid 1012520:tid 1012766] [client 154.190.208.131:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rRAAAAPg"]
[Thu Sep 17 15:21:17.978286 2026] [security2:error] [pid 1012520:tid 1012766] [client 154.190.208.131:41546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZzQpXMN3p_zkwXf2rRAAAAPg"]
[Thu Sep 17 15:21:18.247769 2026] [security2:error] [pid 1012520:tid 1012710] [client 193.36.224.149:64471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/bless.php"] [unique_id "aqxZzgpXMN3p_zkwXf2rTgAAAMA"]
[Thu Sep 17 15:21:18.277846 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.247.203.201:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZzgpXMN3p_zkwXf2rUQAAAOM"]
[Thu Sep 17 15:21:18.289707 2026] [core:error] [pid 1012520:tid 1012698] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:18.289729 2026] [core:error] [pid 1012520:tid 1012698] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:18.307243 2026] [security2:error] [pid 1012520:tid 1012718] [client 20.219.28.139:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/admin.php"] [unique_id "aqxZzgpXMN3p_zkwXf2rUwAAAMg"]
[Thu Sep 17 15:21:18.629793 2026] [core:error] [pid 1012520:tid 1012697] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:18.629817 2026] [core:error] [pid 1012520:tid 1012697] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:18.642328 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.247.203.201:36308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZzgpXMN3p_zkwXf2rYAAAAJQ"]
[Thu Sep 17 15:21:18.726138 2026] [security2:error] [pid 1012520:tid 1012679] [client 216.24.219.19:31297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/goods.php"] [unique_id "aqxZzgpXMN3p_zkwXf2rZgAAAKE"]
[Thu Sep 17 15:21:18.887975 2026] [core:error] [pid 1012520:tid 1012672] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:18.887994 2026] [core:error] [pid 1012520:tid 1012672] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:19.017370 2026] [security2:error] [pid 1012520:tid 1012734] [client 20.219.28.139:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/13.php"] [unique_id "aqxZzwpXMN3p_zkwXf2rdgAAANg"]
[Thu Sep 17 15:21:19.094815 2026] [security2:error] [pid 1012520:tid 1012694] [client 104.234.19.145:28695] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/blurbs.php"] [unique_id "aqxZzwpXMN3p_zkwXf2reAAAALA"]
[Thu Sep 17 15:21:19.150085 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.94.205.103:33798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxZzwpXMN3p_zkwXf2rfQAAAPc"]
[Thu Sep 17 15:21:19.159133 2026] [security2:error] [pid 1012520:tid 1012707] [client 103.61.184.148:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZzwpXMN3p_zkwXf2rgAAAAL0"]
[Thu Sep 17 15:21:19.159226 2026] [security2:error] [pid 1012520:tid 1012707] [client 103.61.184.148:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZzwpXMN3p_zkwXf2rgAAAAL0"]
[Thu Sep 17 15:21:19.178381 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.94.205.103:33798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxZzwpXMN3p_zkwXf2rgQAAAKc"]
[Thu Sep 17 15:21:19.235907 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.247.203.201:36328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.203.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thevagabondhiker.vagabondhiker.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZzwpXMN3p_zkwXf2rigAAAPU"]
[Thu Sep 17 15:21:19.264348 2026] [core:error] [pid 1012520:tid 1012766] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:19.264370 2026] [core:error] [pid 1012520:tid 1012766] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:19.510538 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.94.205.103:33814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxZzwpXMN3p_zkwXf2rlAAAAOE"]
[Thu Sep 17 15:21:19.651601 2026] [core:error] [pid 1012520:tid 1012668] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:19.651624 2026] [core:error] [pid 1012520:tid 1012668] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:19.735171 2026] [security2:error] [pid 1012520:tid 1012723] [client 20.219.28.139:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/222.php"] [unique_id "aqxZzwpXMN3p_zkwXf2roAAAAM0"]
[Thu Sep 17 15:21:19.883648 2026] [security2:error] [pid 1012520:tid 1012667] [client 104.234.19.148:44135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxZzwpXMN3p_zkwXf2rpAAAAJU"]
[Thu Sep 17 15:21:19.924742 2026] [security2:error] [pid 1012520:tid 1012660] [client 114.198.138.124:52519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZzwpXMN3p_zkwXf2rqAAAAI4"]
[Thu Sep 17 15:21:19.924864 2026] [security2:error] [pid 1012520:tid 1012660] [client 114.198.138.124:52519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZzwpXMN3p_zkwXf2rqAAAAI4"]
[Thu Sep 17 15:21:20.065889 2026] [core:error] [pid 1012520:tid 1012679] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:20.065914 2026] [core:error] [pid 1012520:tid 1012679] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:20.119289 2026] [security2:error] [pid 1012520:tid 1012697] [client 185.55.149.49:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ0ApXMN3p_zkwXf2rsQAAALM"]
[Thu Sep 17 15:21:20.119462 2026] [security2:error] [pid 1012520:tid 1012697] [client 185.55.149.49:61297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ0ApXMN3p_zkwXf2rsQAAALM"]
[Thu Sep 17 15:21:20.176266 2026] [security2:error] [pid 1012520:tid 1012683] [client 165.154.29.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lumenroast.com"] [uri "/index.php"] [unique_id "aqxZzgpXMN3p_zkwXf2rcwAAAKU"], referer: http://mail.avo.jgb.mybluehost.me/sitemap.xml
[Thu Sep 17 15:21:20.444887 2026] [security2:error] [pid 1012520:tid 1012677] [client 20.219.28.139:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/aa.php"] [unique_id "aqxZ0ApXMN3p_zkwXf2rwgAAAJ8"]
[Thu Sep 17 15:21:20.455043 2026] [core:error] [pid 1012520:tid 1012659] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:20.455068 2026] [core:error] [pid 1012520:tid 1012659] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:20.661995 2026] [security2:error] [pid 1012520:tid 1012746] [client 216.24.219.38:27609] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/abcd.php"] [unique_id "aqxZ0ApXMN3p_zkwXf2r0QAAAOQ"]
[Thu Sep 17 15:21:20.665308 2026] [core:error] [pid 1012520:tid 1012767] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:20.665328 2026] [core:error] [pid 1012520:tid 1012767] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:20.722537 2026] [security2:error] [pid 1012520:tid 1012729] [client 159.203.57.242:41486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.com"] [uri "/index.php"] [unique_id "aqxZ0ApXMN3p_zkwXf2rywAAANM"]
[Thu Sep 17 15:21:20.924138 2026] [security2:error] [pid 1012520:tid 1012691] [client 159.203.57.242:41486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.com"] [uri "/index.php"] [unique_id "aqxZ0ApXMN3p_zkwXf2r2AAAAK0"]
[Thu Sep 17 15:21:21.111722 2026] [security2:error] [pid 1012520:tid 1012705] [client 159.203.57.242:41486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.com"] [uri "/index.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2r4gAAALs"]
[Thu Sep 17 15:21:21.139880 2026] [security2:error] [pid 1012520:tid 1012724] [client 20.219.28.139:2032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/abcd.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2r5gAAAM4"]
[Thu Sep 17 15:21:21.162069 2026] [core:error] [pid 1012520:tid 1012759] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:21.162089 2026] [core:error] [pid 1012520:tid 1012759] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:21.405320 2026] [security2:error] [pid 1012520:tid 1012671] [client 216.24.219.31:44555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2r9wAAAJk"]
[Thu Sep 17 15:21:21.441878 2026] [core:error] [pid 1012520:tid 1012755] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:21.441896 2026] [core:error] [pid 1012520:tid 1012755] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:21.446062 2026] [security2:error] [pid 1012520:tid 1012743] [client 119.13.218.66:57809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2r-AAA4U8"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:21:21.828561 2026] [security2:error] [pid 1012520:tid 1012663] [client 20.219.28.139:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/about.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sFAAAAJE"]
[Thu Sep 17 15:21:21.839927 2026] [security2:error] [pid 1012520:tid 1012694] [client 159.203.57.242:41486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.com"] [uri "/index.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sDwAAALA"]
[Thu Sep 17 15:21:21.876715 2026] [security2:error] [pid 1012520:tid 1012675] [client 156.192.234.52:65528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sGAAAAJ0"]
[Thu Sep 17 15:21:21.876843 2026] [security2:error] [pid 1012520:tid 1012675] [client 156.192.234.52:65528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sGAAAAJ0"]
[Thu Sep 17 15:21:21.977386 2026] [security2:error] [pid 1012520:tid 1012707] [client 210.222.43.21:61136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sEwAAAL0"], referer: http://talent-in-borders.com/bk
[Thu Sep 17 15:21:21.983048 2026] [core:error] [pid 1012520:tid 1012654] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:21.983069 2026] [core:error] [pid 1012520:tid 1012654] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:22.034837 2026] [security2:error] [pid 1012520:tid 1012767] [client 159.203.57.242:41486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.com"] [uri "/index.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sGQAAAPk"]
[Thu Sep 17 15:21:22.205638 2026] [security2:error] [pid 1012520:tid 1012758] [client 193.36.224.156:52415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/dex.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sJwAAAPA"]
[Thu Sep 17 15:21:22.231746 2026] [security2:error] [pid 1012520:tid 1012772] [client 159.203.57.242:41486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.com"] [uri "/index.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sIgAAAP4"]
[Thu Sep 17 15:21:22.317952 2026] [security2:error] [pid 1012520:tid 1012746] [client 186.105.232.15:50719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sMAAAAOQ"]
[Thu Sep 17 15:21:22.318048 2026] [security2:error] [pid 1012520:tid 1012746] [client 186.105.232.15:50719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sMAAAAOQ"]
[Thu Sep 17 15:21:22.432333 2026] [core:error] [pid 1012520:tid 1012682] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:22.432355 2026] [core:error] [pid 1012520:tid 1012682] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:22.543425 2026] [security2:error] [pid 1012520:tid 1012769] [client 20.219.28.139:1988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/admin.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sOwAAAPs"]
[Thu Sep 17 15:21:22.627934 2026] [core:error] [pid 1012520:tid 1012700] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:22.627961 2026] [core:error] [pid 1012520:tid 1012700] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:22.778701 2026] [security2:error] [pid 1012520:tid 1012658] [client 119.13.218.66:37437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sRAAAjEc"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260612232332&hideliu=1&hideminor=1&limit=100&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:21:22.880306 2026] [security2:error] [pid 1012520:tid 1012673] [client 193.36.224.152:52639] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sSAAAAJs"]
[Thu Sep 17 15:21:22.984051 2026] [security2:error] [pid 1012520:tid 1012656] [client 169.58.197.253:55205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxZ0gpXMN3p_zkwXf2sTAAAAIo"], referer: binance.com
[Thu Sep 17 15:21:23.033307 2026] [core:error] [pid 1012520:tid 1012694] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:23.033337 2026] [core:error] [pid 1012520:tid 1012694] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:23.285832 2026] [security2:error] [pid 1012520:tid 1012699] [client 20.219.28.139:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/adminfuns.php"] [unique_id "aqxZ0wpXMN3p_zkwXf2sVQAAALU"]
[Thu Sep 17 15:21:23.465963 2026] [core:error] [pid 1012520:tid 1012738] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:23.465984 2026] [core:error] [pid 1012520:tid 1012738] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:23.698609 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.94.205.103:46074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxZ0wpXMN3p_zkwXf2sXwAAAKo"]
[Thu Sep 17 15:21:23.721142 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.94.205.103:46074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxZ0wpXMN3p_zkwXf2sYwAAAP0"]
[Thu Sep 17 15:21:23.785540 2026] [core:error] [pid 1012520:tid 1012679] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:23.785565 2026] [core:error] [pid 1012520:tid 1012679] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:23.837729 2026] [security2:error] [pid 1012520:tid 1012759] [client 216.24.219.19:27295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxZ0wpXMN3p_zkwXf2sbgAAAPE"]
[Thu Sep 17 15:21:24.001532 2026] [security2:error] [pid 1012520:tid 1012756] [client 20.219.28.139:1984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxZ1ApXMN3p_zkwXf2scgAAAO4"]
[Thu Sep 17 15:21:24.046789 2026] [security2:error] [pid 1012520:tid 1012746] [client 57.141.14.42:25496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxZ0wpXMN3p_zkwXf2sbAAA5GQ"]
[Thu Sep 17 15:21:24.160456 2026] [security2:error] [pid 1012520:tid 1012770] [client 74.7.241.149:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kavanotpreview.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sBAAAAPw"]
[Thu Sep 17 15:21:24.160490 2026] [security2:error] [pid 1012520:tid 1012770] [client 74.7.241.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kavanotpreview.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxZ0QpXMN3p_zkwXf2sBAAAAPw"]
[Thu Sep 17 15:21:24.162571 2026] [security2:error] [pid 1012520:tid 1012730] [client 74.7.241.149:54122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kavanotpreview.jwdnyc.com"] [uri "/robots.txt"] [unique_id "aqxZ0QpXMN3p_zkwXf2sAAAA1Cs"]
[Thu Sep 17 15:21:24.232552 2026] [core:error] [pid 1012520:tid 1012658] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:24.232576 2026] [core:error] [pid 1012520:tid 1012658] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:24.336543 2026] [security2:error] [pid 1012520:tid 1012684] [client 172.59.240.78:48531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ1ApXMN3p_zkwXf2sfgAApnE"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:21:24.526444 2026] [security2:error] [pid 1012520:tid 1012694] [client 74.7.241.149:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kavanotpreview.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxZ1ApXMN3p_zkwXf2siAAAALA"], referer: https://www.kavanotpreview.jwdnyc.com/robots.txt
[Thu Sep 17 15:21:24.548695 2026] [security2:error] [pid 1012520:tid 1012761] [client 74.7.241.149:54128] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kavanotpreview.jwdnyc.com"] [uri "/robots.txt"] [unique_id "aqxZ1ApXMN3p_zkwXf2shAAA82s"], referer: https://www.kavanotpreview.jwdnyc.com/robots.txt
[Thu Sep 17 15:21:24.717631 2026] [security2:error] [pid 1012520:tid 1012675] [client 20.219.28.139:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/ae.php"] [unique_id "aqxZ1ApXMN3p_zkwXf2sjQAAAJ0"]
[Thu Sep 17 15:21:24.811263 2026] [core:error] [pid 1012520:tid 1012657] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:24.811284 2026] [core:error] [pid 1012520:tid 1012657] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:25.093721 2026] [security2:error] [pid 1012520:tid 1012724] [client 104.234.19.149:46435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ1QpXMN3p_zkwXf2sowAAAM4"]
[Thu Sep 17 15:21:25.430346 2026] [security2:error] [pid 1012520:tid 1012760] [client 20.219.28.139:2007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/akcc.php"] [unique_id "aqxZ1QpXMN3p_zkwXf2stgAAAPI"]
[Thu Sep 17 15:21:25.450919 2026] [core:error] [pid 1012520:tid 1012665] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:25.450948 2026] [core:error] [pid 1012520:tid 1012665] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:25.819454 2026] [core:error] [pid 1012520:tid 1012673] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:25.819477 2026] [core:error] [pid 1012520:tid 1012673] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:26.177875 2026] [security2:error] [pid 1012520:tid 1012661] [client 20.219.28.139:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/bak.php"] [unique_id "aqxZ1gpXMN3p_zkwXf2s2QAAAI8"]
[Thu Sep 17 15:21:26.236907 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.94.205.103:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxZ1gpXMN3p_zkwXf2s3AAAANw"]
[Thu Sep 17 15:21:26.326772 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.94.205.103:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxZ1gpXMN3p_zkwXf2s3wAAAPE"]
[Thu Sep 17 15:21:26.348865 2026] [security2:error] [pid 1012520:tid 1012749] [client 193.36.224.149:47075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxZ1gpXMN3p_zkwXf2s4QAAAOc"]
[Thu Sep 17 15:21:26.353472 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.94.205.103:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxZ1gpXMN3p_zkwXf2s4gAAAOg"]
[Thu Sep 17 15:21:26.380435 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.94.205.103:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxZ1gpXMN3p_zkwXf2s4wAAAO8"]
[Thu Sep 17 15:21:26.394656 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.94.205.103:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxZ1gpXMN3p_zkwXf2s5AAAAM4"]
[Thu Sep 17 15:21:26.588762 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.94.205.103:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxZ1gpXMN3p_zkwXf2s6gAAAI4"]
[Thu Sep 17 15:21:26.742500 2026] [core:error] [pid 1012520:tid 1012683] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:26.742525 2026] [core:error] [pid 1012520:tid 1012683] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:26.797794 2026] [security2:error] [pid 1012520:tid 1012746] [client 172.59.240.78:7896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ1gpXMN3p_zkwXf2s7gAA5B0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260612232332&hideliu=1&hideminor=1&limit=100&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:21:26.921557 2026] [security2:error] [pid 1012520:tid 1012727] [client 20.219.28.139:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/cc.php"] [unique_id "aqxZ1gpXMN3p_zkwXf2s-AAAANE"]
[Thu Sep 17 15:21:26.932242 2026] [security2:error] [pid 1012520:tid 1012715] [client 216.24.219.102:55441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/index.php"] [unique_id "aqxZ1gpXMN3p_zkwXf2s-QAAAMU"]
[Thu Sep 17 15:21:27.083223 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2s_QAAALk"]
[Thu Sep 17 15:21:27.133029 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tAQAAAPc"]
[Thu Sep 17 15:21:27.255586 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tCAAAAPU"]
[Thu Sep 17 15:21:27.367889 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tCgAAAJw"]
[Thu Sep 17 15:21:27.438452 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tDAAAALw"]
[Thu Sep 17 15:21:27.468835 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tDQAAANY"]
[Thu Sep 17 15:21:27.525242 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tEAAAAJs"]
[Thu Sep 17 15:21:27.634061 2026] [security2:error] [pid 1012520:tid 1012686] [client 20.219.28.139:2044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/chosen.php"] [unique_id "aqxZ1wpXMN3p_zkwXf2tFAAAAKg"]
[Thu Sep 17 15:21:27.667590 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tFQAAAN4"]
[Thu Sep 17 15:21:27.768361 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tGQAAAME"]
[Thu Sep 17 15:21:27.832839 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tGwAAALQ"]
[Thu Sep 17 15:21:27.887981 2026] [security2:error] [pid 1012520:tid 1012761] [client 142.93.128.196:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scadalogik.com"] [uri "/index.php"] [unique_id "aqxZ1QpXMN3p_zkwXf2swgAAAPM"]
[Thu Sep 17 15:21:27.909799 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tHQAAAJI"]
[Thu Sep 17 15:21:27.954753 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxZ1wpXMN3p_zkwXf2tHwAAAKw"]
[Thu Sep 17 15:21:28.013340 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tIQAAAKE"]
[Thu Sep 17 15:21:28.038744 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tIgAAAQA"]
[Thu Sep 17 15:21:28.118920 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tJgAAAPE"]
[Thu Sep 17 15:21:28.212750 2026] [security2:error] [pid 1012520:tid 1012661] [client 142.93.128.196:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scadalogik.com"] [uri "/index.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tJAAAAI8"]
[Thu Sep 17 15:21:28.238096 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tKgAAAM4"]
[Thu Sep 17 15:21:28.263730 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tKwAAANc"]
[Thu Sep 17 15:21:28.334942 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tLgAAAP8"]
[Thu Sep 17 15:21:28.355203 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tMQAAALs"]
[Thu Sep 17 15:21:28.369157 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tNAAAAPo"]
[Thu Sep 17 15:21:28.376761 2026] [security2:error] [pid 1012520:tid 1012723] [client 20.219.28.139:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/classwithtostring.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tNQAAAM0"]
[Thu Sep 17 15:21:28.430938 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tNgAAAKU"]
[Thu Sep 17 15:21:28.444914 2026] [security2:error] [pid 1012520:tid 1012688] [client 154.190.208.131:42155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tOAAAAKo"]
[Thu Sep 17 15:21:28.445037 2026] [security2:error] [pid 1012520:tid 1012688] [client 154.190.208.131:42155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tOAAAAKo"]
[Thu Sep 17 15:21:28.518307 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tOQAAAO4"]
[Thu Sep 17 15:21:28.530954 2026] [security2:error] [pid 1012520:tid 1012758] [client 142.93.128.196:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scadalogik.com"] [uri "/index.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tMgAAAPA"]
[Thu Sep 17 15:21:28.603184 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tOwAAALY"]
[Thu Sep 17 15:21:28.639572 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tPQAAAPw"]
[Thu Sep 17 15:21:28.675869 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tPgAAAJg"]
[Thu Sep 17 15:21:28.705707 2026] [security2:error] [pid 1012520:tid 1012702] [client 54.36.150.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxZ1QpXMN3p_zkwXf2s1gAAALg"]
[Thu Sep 17 15:21:28.716426 2026] [security2:error] [pid 1012520:tid 1012729] [client 54.36.150.170:51786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "missglitterteaches.com"] [uri "/robots.txt"] [unique_id "aqxZ1QpXMN3p_zkwXf2s1AAAANM"]
[Thu Sep 17 15:21:28.736165 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tRAAAAMY"]
[Thu Sep 17 15:21:28.752199 2026] [security2:error] [pid 1012520:tid 1012719] [client 193.36.224.113:21133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tRQAAAMk"]
[Thu Sep 17 15:21:28.765077 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tRgAAAJk"]
[Thu Sep 17 15:21:28.789441 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tSgAAAK0"]
[Thu Sep 17 15:21:28.835834 2026] [security2:error] [pid 1012520:tid 1012717] [client 142.93.128.196:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scadalogik.com"] [uri "/index.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tQAAAAMc"]
[Thu Sep 17 15:21:28.850166 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tTAAAANA"]
[Thu Sep 17 15:21:28.880804 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tTQAAAJw"]
[Thu Sep 17 15:21:28.920134 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tTwAAAKk"]
[Thu Sep 17 15:21:28.987238 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxZ2ApXMN3p_zkwXf2tUwAAALw"]
[Thu Sep 17 15:21:29.032568 2026] [security2:error] [pid 1012520:tid 1012663] [client 193.36.224.149:45229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/file.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tVgAAAJE"]
[Thu Sep 17 15:21:29.058503 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tVwAAAJ0"]
[Thu Sep 17 15:21:29.064209 2026] [security2:error] [pid 1012520:tid 1012763] [client 20.219.28.139:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/wp-signup.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tWQAAAPU"]
[Thu Sep 17 15:21:29.079200 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tWgAAAJs"]
[Thu Sep 17 15:21:29.140951 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tXQAAAPg"]
[Thu Sep 17 15:21:29.226433 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tYgAAAMo"]
[Thu Sep 17 15:21:29.319698 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tagAAAKM"]
[Thu Sep 17 15:21:29.354515 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tawAAAKc"]
[Thu Sep 17 15:21:29.429713 2026] [security2:error] [pid 1012520:tid 1012771] [client 193.36.224.168:51927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tbAAAAP0"]
[Thu Sep 17 15:21:29.489365 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tbgAAAJY"]
[Thu Sep 17 15:21:29.512778 2026] [security2:error] [pid 1012520:tid 1012664] [client 142.93.128.196:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scadalogik.com"] [uri "/index.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2taQAAAJI"]
[Thu Sep 17 15:21:29.620855 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tcAAAAM4"]
[Thu Sep 17 15:21:29.639773 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tcgAAANc"]
[Thu Sep 17 15:21:29.645853 2026] [security2:error] [pid 1012520:tid 1012718] [client 54.36.150.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tZgAAAMg"]
[Thu Sep 17 15:21:29.665138 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tcwAAAP8"]
[Thu Sep 17 15:21:29.676968 2026] [security2:error] [pid 1012520:tid 1012684] [client 54.36.150.170:51800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "missglitterteaches.com"] [uri "/15-professional-goals-for-teachers-examples/"] [unique_id "aqxZ2QpXMN3p_zkwXf2tYwAAAKY"]
[Thu Sep 17 15:21:29.736912 2026] [security2:error] [pid 1012520:tid 1012757] [client 193.36.224.167:35551] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-mail.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tegAAAO8"]
[Thu Sep 17 15:21:29.765253 2026] [security2:error] [pid 1012520:tid 1012774] [client 20.219.28.139:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/doc.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tewAAAQA"]
[Thu Sep 17 15:21:29.787104 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tfAAAANI"]
[Thu Sep 17 15:21:29.837953 2026] [security2:error] [pid 1012520:tid 1012734] [client 142.93.128.196:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scadalogik.com"] [uri "/index.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tdAAAANg"]
[Thu Sep 17 15:21:29.841927 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tfgAAAOM"]
[Thu Sep 17 15:21:29.858170 2026] [security2:error] [pid 1012520:tid 1012654] [client 103.61.184.148:63806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tfwAAAIg"]
[Thu Sep 17 15:21:29.858337 2026] [security2:error] [pid 1012520:tid 1012654] [client 103.61.184.148:63806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tfwAAAIg"]
[Thu Sep 17 15:21:29.878570 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxZ2QpXMN3p_zkwXf2tgAAAAI4"]
[Thu Sep 17 15:21:30.014959 2026] [security2:error] [pid 1012520:tid 1012755] [client 187.103.86.126:39981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ2QpXMN3p_zkwXf2tgQAA7QY"]
[Thu Sep 17 15:21:30.168157 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2thgAAAOk"]
[Thu Sep 17 15:21:30.205484 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tiwAAANE"]
[Thu Sep 17 15:21:30.235611 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tjQAAAJg"]
[Thu Sep 17 15:21:30.238079 2026] [security2:error] [pid 1012520:tid 1012655] [client 216.24.219.32:53295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/ioxi-o.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2tjwAAAIk"]
[Thu Sep 17 15:21:30.260504 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tkQAAALg"]
[Thu Sep 17 15:21:30.300849 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tkgAAAMA"]
[Thu Sep 17 15:21:30.347052 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tlAAAALk"]
[Thu Sep 17 15:21:30.373313 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tlQAAAJk"]
[Thu Sep 17 15:21:30.401854 2026] [security2:error] [pid 1012520:tid 1012651] [client 47.79.7.107:43114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxZ2ApXMN3p_zkwXf2tUgAAAIU"]
[Thu Sep 17 15:21:30.468403 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tmgAAAJw"]
[Thu Sep 17 15:21:30.486054 2026] [security2:error] [pid 1012520:tid 1012665] [client 20.219.28.139:1114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/edit.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2tmwAAAJM"]
[Thu Sep 17 15:21:30.610624 2026] [security2:error] [pid 1012520:tid 1012693] [client 152.32.215.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kmd.duj.mybluehost.me"] [uri "/index.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2tmQAAAK8"]
[Thu Sep 17 15:21:30.671283 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2toAAAAJ8"]
[Thu Sep 17 15:21:30.682461 2026] [security2:error] [pid 1012520:tid 1012667] [client 114.198.138.124:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2towAAAJU"]
[Thu Sep 17 15:21:30.682581 2026] [security2:error] [pid 1012520:tid 1012667] [client 114.198.138.124:53152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2towAAAJU"]
[Thu Sep 17 15:21:30.736656 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tpQAAAPQ"]
[Thu Sep 17 15:21:30.803447 2026] [security2:error] [pid 1012520:tid 1012761] [client 216.24.219.102:37915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2tpwAAAPM"]
[Thu Sep 17 15:21:30.809493 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tqAAAALU"]
[Thu Sep 17 15:21:30.855047 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxZ2gpXMN3p_zkwXf2tqgAAAOo"]
[Thu Sep 17 15:21:30.943783 2026] [security2:error] [pid 1012520:tid 1012742] [client 185.55.149.49:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2tqwAAAOA"]
[Thu Sep 17 15:21:30.943925 2026] [security2:error] [pid 1012520:tid 1012742] [client 185.55.149.49:61726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ2gpXMN3p_zkwXf2tqwAAAOA"]
[Thu Sep 17 15:21:31.003235 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2trAAAAIs"]
[Thu Sep 17 15:21:31.037732 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2trgAAAJI"]
[Thu Sep 17 15:21:31.061083 2026] [security2:error] [pid 1012520:tid 1012666] [client 193.36.224.226:50143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/style.php"] [unique_id "aqxZ2wpXMN3p_zkwXf2trwAAAJQ"]
[Thu Sep 17 15:21:31.086675 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tsAAAAI8"]
[Thu Sep 17 15:21:31.121644 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tsQAAAM4"]
[Thu Sep 17 15:21:31.207453 2026] [security2:error] [pid 1012520:tid 1012711] [client 20.219.28.139:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/worksec.php"] [unique_id "aqxZ2wpXMN3p_zkwXf2tswAAAME"]
[Thu Sep 17 15:21:31.222445 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2ttgAAANU"]
[Thu Sep 17 15:21:31.274425 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2ttwAAAL8"]
[Thu Sep 17 15:21:31.348722 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tuQAAAOU"]
[Thu Sep 17 15:21:31.374608 2026] [security2:error] [pid 1012520:tid 1012728] [client 169.58.197.253:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxZ2wpXMN3p_zkwXf2tvQAAANI"], referer: binance.com
[Thu Sep 17 15:21:31.404983 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tvgAAAOM"]
[Thu Sep 17 15:21:31.426656 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tvwAAAM0"]
[Thu Sep 17 15:21:31.511707 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2twQAAAKo"]
[Thu Sep 17 15:21:31.588745 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2twwAAAMI"]
[Thu Sep 17 15:21:31.689916 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2txAAAAO0"]
[Thu Sep 17 15:21:31.717457 2026] [security2:error] [pid 1012520:tid 1012727] [client 216.24.219.89:35569] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/style.php"] [unique_id "aqxZ2wpXMN3p_zkwXf2tyQAAANE"]
[Thu Sep 17 15:21:31.785099 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tygAAAIk"]
[Thu Sep 17 15:21:31.859168 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tzAAAAJA"]
[Thu Sep 17 15:21:31.915691 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2tzgAAAMY"]
[Thu Sep 17 15:21:31.928263 2026] [security2:error] [pid 1012520:tid 1012743] [client 20.219.28.139:1989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/ultra.php"] [unique_id "aqxZ2wpXMN3p_zkwXf2tzwAAAOE"]
[Thu Sep 17 15:21:31.970316 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2t0AAAAI0"]
[Thu Sep 17 15:21:31.991809 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxZ2wpXMN3p_zkwXf2t0QAAAOY"]
[Thu Sep 17 15:21:32.042128 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t1QAAAMc"]
[Thu Sep 17 15:21:32.098425 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.94.205.103:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t1gAAAKA"]
[Thu Sep 17 15:21:32.236530 2026] [security2:error] [pid 1012520:tid 1012737] [client 88.183.163.51:33800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ3ApXMN3p_zkwXf2t1wAA2yQ"]
[Thu Sep 17 15:21:32.354136 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t5wAAAJs"]
[Thu Sep 17 15:21:32.486041 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t6gAAALc"]
[Thu Sep 17 15:21:32.497243 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.220.137.122:39294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/"] [unique_id "aqxZ3ApXMN3p_zkwXf2t6wAAAKg"]
[Thu Sep 17 15:21:32.557534 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t7AAAAMQ"]
[Thu Sep 17 15:21:32.611623 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t7gAAANY"]
[Thu Sep 17 15:21:32.620741 2026] [security2:error] [pid 1012520:tid 1012759] [client 20.219.28.139:2042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/gecko.php"] [unique_id "aqxZ3ApXMN3p_zkwXf2t7wAAAPE"]
[Thu Sep 17 15:21:32.692351 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t8QAAAIY"]
[Thu Sep 17 15:21:32.722732 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t8gAAAPk"]
[Thu Sep 17 15:21:32.757811 2026] [security2:error] [pid 1012520:tid 1012672] [client 156.192.234.52:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ3ApXMN3p_zkwXf2t9QAAAJo"]
[Thu Sep 17 15:21:32.759223 2026] [security2:error] [pid 1012520:tid 1012672] [client 156.192.234.52:49803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ3ApXMN3p_zkwXf2t9QAAAJo"]
[Thu Sep 17 15:21:32.763252 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t9gAAAOA"]
[Thu Sep 17 15:21:32.766414 2026] [security2:error] [pid 1012520:tid 1012685] [client 57.141.14.114:45490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxZ3ApXMN3p_zkwXf2t7QAApzw"]
[Thu Sep 17 15:21:32.794935 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t9wAAAI8"]
[Thu Sep 17 15:21:32.846322 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t-gAAAKQ"]
[Thu Sep 17 15:21:32.861511 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t-wAAAME"]
[Thu Sep 17 15:21:32.894017 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t_AAAAKY"]
[Thu Sep 17 15:21:32.964055 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxZ3ApXMN3p_zkwXf2t_QAAAOg"]
[Thu Sep 17 15:21:32.986027 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.220.137.122:39298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/"] [unique_id "aqxZ3ApXMN3p_zkwXf2uDQAAAM4"]
[Thu Sep 17 15:21:33.057400 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uDgAAAM0"]
[Thu Sep 17 15:21:33.079028 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uDwAAAOc"]
[Thu Sep 17 15:21:33.087721 2026] [security2:error] [pid 1012520:tid 1012721] [client 193.36.224.152:47021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxZ3QpXMN3p_zkwXf2uEAAAAMs"]
[Thu Sep 17 15:21:33.144772 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uFgAAAKU"]
[Thu Sep 17 15:21:33.160458 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uHQAAAKo"]
[Thu Sep 17 15:21:33.293902 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uJQAAAMY"]
[Thu Sep 17 15:21:33.308631 2026] [security2:error] [pid 1012520:tid 1012778] [client 20.219.28.139:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/goods.php"] [unique_id "aqxZ3QpXMN3p_zkwXf2uJwAAAQQ"]
[Thu Sep 17 15:21:33.309415 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uJgAAAIg"]
[Thu Sep 17 15:21:33.364895 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uKQAAAIw"]
[Thu Sep 17 15:21:33.376423 2026] [security2:error] [pid 1012520:tid 1012702] [client 216.24.219.97:65451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-editor.php"] [unique_id "aqxZ3QpXMN3p_zkwXf2uKgAAALg"]
[Thu Sep 17 15:21:33.385448 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uLAAAAMc"]
[Thu Sep 17 15:21:33.406058 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uLQAAAKA"]
[Thu Sep 17 15:21:33.485707 2026] [security2:error] [pid 1012520:tid 1012735] [client 35.220.137.122:39302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/"] [unique_id "aqxZ3QpXMN3p_zkwXf2uMAAAANk"]
[Thu Sep 17 15:21:33.489041 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uMQAAAJc"]
[Thu Sep 17 15:21:33.577055 2026] [core:error] [pid 1012520:tid 1012740] [client 74.7.241.170:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:33.577087 2026] [core:error] [pid 1012520:tid 1012740] [client 74.7.241.170:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:33.577242 2026] [security2:error] [pid 1012520:tid 1012740] [client 74.7.241.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.acc.edu.ai"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "aqxZ3QpXMN3p_zkwXf2uOgAAAN4"]
[Thu Sep 17 15:21:33.582221 2026] [security2:error] [pid 1012520:tid 1012674] [client 74.7.241.170:35566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.acc.edu.ai"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxZ3QpXMN3p_zkwXf2uNwAAnE8"]
[Thu Sep 17 15:21:33.629367 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uOwAAAQE"]
[Thu Sep 17 15:21:33.744293 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uPgAAAJ0"]
[Thu Sep 17 15:21:33.762760 2026] [security2:error] [pid 1012520:tid 1012686] [client 193.36.224.212:59289] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/lufix.php"] [unique_id "aqxZ3QpXMN3p_zkwXf2uQgAAAKg"]
[Thu Sep 17 15:21:33.784675 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uQwAAAL0"]
[Thu Sep 17 15:21:33.855002 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uRwAAAKk"]
[Thu Sep 17 15:21:33.956309 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uSwAAAMw"]
[Thu Sep 17 15:21:33.995500 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxZ3QpXMN3p_zkwXf2uTgAAAPI"]
[Thu Sep 17 15:21:34.026349 2026] [security2:error] [pid 1012520:tid 1012714] [client 20.219.28.139:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/man.php"] [unique_id "aqxZ3gpXMN3p_zkwXf2uUwAAAMQ"]
[Thu Sep 17 15:21:34.055081 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.94.205.103:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxZ3gpXMN3p_zkwXf2uVwAAAIs"]
[Thu Sep 17 15:21:34.153271 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ3gpXMN3p_zkwXf2uWAAAAOA"]
[Thu Sep 17 15:21:34.163830 2026] [core:error] [pid 1012520:tid 1012738] [client 74.7.175.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:34.163851 2026] [core:error] [pid 1012520:tid 1012738] [client 74.7.175.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:34.164015 2026] [security2:error] [pid 1012520:tid 1012738] [client 74.7.175.161:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.themommyarchives.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "aqxZ3gpXMN3p_zkwXf2uXgAAANw"]
[Thu Sep 17 15:21:34.167130 2026] [security2:error] [pid 1012520:tid 1012668] [client 74.7.175.161:47050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.themommyarchives.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxZ3gpXMN3p_zkwXf2uWQAAllM"]
[Thu Sep 17 15:21:34.181992 2026] [security2:error] [pid 1012520:tid 1012761] [client 186.105.232.15:51318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ3gpXMN3p_zkwXf2uYAAAAPM"]
[Thu Sep 17 15:21:34.182148 2026] [security2:error] [pid 1012520:tid 1012761] [client 186.105.232.15:51318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ3gpXMN3p_zkwXf2uYAAAAPM"]
[Thu Sep 17 15:21:34.188596 2026] [core:error] [pid 1012520:tid 1012709] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:34.188615 2026] [core:error] [pid 1012520:tid 1012709] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:34.328295 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.220.137.122:39312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/"] [unique_id "aqxZ3gpXMN3p_zkwXf2uYwAAAMs"]
[Thu Sep 17 15:21:34.598922 2026] [core:error] [pid 1012520:tid 1012655] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:34.598940 2026] [core:error] [pid 1012520:tid 1012655] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:34.727234 2026] [security2:error] [pid 1012520:tid 1012758] [client 20.219.28.139:2043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/wp-settings.php"] [unique_id "aqxZ3gpXMN3p_zkwXf2ucwAAAPA"]
[Thu Sep 17 15:21:34.797483 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxZ3gpXMN3p_zkwXf2ueAAAAK0"]
[Thu Sep 17 15:21:34.852629 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxZ3gpXMN3p_zkwXf2ueQAAAIU"]
[Thu Sep 17 15:21:34.901146 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxZ3gpXMN3p_zkwXf2ufQAAAJc"]
[Thu Sep 17 15:21:34.927185 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.220.137.122:39322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/.env"] [unique_id "aqxZ3gpXMN3p_zkwXf2ufwAAAMY"]
[Thu Sep 17 15:21:34.980613 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxZ3gpXMN3p_zkwXf2ugwAAAMU"]
[Thu Sep 17 15:21:35.031089 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2uhAAAALM"]
[Thu Sep 17 15:21:35.074963 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2uhgAAAN4"]
[Thu Sep 17 15:21:35.117047 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2uiQAAAMM"]
[Thu Sep 17 15:21:35.199956 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2ujQAAAQE"]
[Thu Sep 17 15:21:35.284786 2026] [security2:error] [pid 1012520:tid 1012670] [client 216.24.219.37:51923] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/txets.php"] [unique_id "aqxZ3wpXMN3p_zkwXf2ujwAAAJg"]
[Thu Sep 17 15:21:35.300672 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2ukAAAAOs"]
[Thu Sep 17 15:21:35.338336 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ3wpXMN3p_zkwXf2ujAAAAPQ"]
[Thu Sep 17 15:21:35.347196 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2ukwAAANQ"]
[Thu Sep 17 15:21:35.373174 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2ulAAAALc"]
[Thu Sep 17 15:21:35.449125 2026] [security2:error] [pid 1012520:tid 1012695] [client 20.219.28.139:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/k.php"] [unique_id "aqxZ3wpXMN3p_zkwXf2ulwAAALE"]
[Thu Sep 17 15:21:35.474722 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2umQAAAQM"]
[Thu Sep 17 15:21:35.519392 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2ungAAAPI"]
[Thu Sep 17 15:21:35.573111 2026] [security2:error] [pid 1012520:tid 1012657] [client 104.234.19.147:37761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxZ3wpXMN3p_zkwXf2uoAAAAIs"]
[Thu Sep 17 15:21:35.656307 2026] [security2:error] [pid 1012520:tid 1012652] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ3wpXMN3p_zkwXf2uoQAAAIY"]
[Thu Sep 17 15:21:35.681921 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2uowAAANU"]
[Thu Sep 17 15:21:35.720098 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2upAAAAJY"]
[Thu Sep 17 15:21:35.797385 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2upQAAAO8"]
[Thu Sep 17 15:21:35.843182 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2uqQAAAJI"]
[Thu Sep 17 15:21:35.929188 2026] [security2:error] [pid 1012520:tid 1012672] [client 193.36.224.167:47585] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxZ3wpXMN3p_zkwXf2urgAAAJo"]
[Thu Sep 17 15:21:35.948267 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2urwAAAOc"]
[Thu Sep 17 15:21:35.988238 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxZ3wpXMN3p_zkwXf2usQAAAMs"]
[Thu Sep 17 15:21:36.018750 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ3wpXMN3p_zkwXf2urAAAAOM"]
[Thu Sep 17 15:21:36.033486 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2uswAAALI"]
[Thu Sep 17 15:21:36.076120 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2utQAAAL4"]
[Thu Sep 17 15:21:36.105809 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2utgAAALs"]
[Thu Sep 17 15:21:36.166306 2026] [security2:error] [pid 1012520:tid 1012723] [client 20.219.28.139:2002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/autoload_classmap.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2uugAAAM0"]
[Thu Sep 17 15:21:36.187764 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2uuwAAAN8"]
[Thu Sep 17 15:21:36.223617 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2uvAAAAMA"]
[Thu Sep 17 15:21:36.313618 2026] [security2:error] [pid 1012520:tid 1012671] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2uwQAAAJk"]
[Thu Sep 17 15:21:36.400601 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2uxgAAALg"]
[Thu Sep 17 15:21:36.455242 2026] [security2:error] [pid 1012520:tid 1012770] [client 104.234.19.150:30075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2uxwAAAPw"]
[Thu Sep 17 15:21:36.500924 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2uywAAAMk"]
[Thu Sep 17 15:21:36.519598 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.95.212.189:34572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/phpinfo.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2uzAAAAJc"]
[Thu Sep 17 15:21:36.560809 2026] [security2:error] [pid 1012520:tid 1012737] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2uzgAAANs"]
[Thu Sep 17 15:21:36.580934 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2uzwAAAMY"]
[Thu Sep 17 15:21:36.610759 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2uzQAAAJM"]
[Thu Sep 17 15:21:36.612181 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2u0AAAAJE"]
[Thu Sep 17 15:21:36.672426 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2u0QAAAJs"]
[Thu Sep 17 15:21:36.827831 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2u1QAAAMg"]
[Thu Sep 17 15:21:36.887268 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2u2QAAAPQ"]
[Thu Sep 17 15:21:36.890962 2026] [security2:error] [pid 1012520:tid 1012740] [client 20.219.28.139:1105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/profile.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2u2gAAAN4"]
[Thu Sep 17 15:21:36.930358 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2u2AAAAOs"]
[Thu Sep 17 15:21:36.969011 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxZ4ApXMN3p_zkwXf2u2wAAAJw"]
[Thu Sep 17 15:21:37.022982 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.95.212.189:52528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/info.php"] [unique_id "aqxZ4QpXMN3p_zkwXf2u3gAAAO4"]
[Thu Sep 17 15:21:37.073523 2026] [security2:error] [pid 1012520:tid 1012735] [client 74.7.230.29:60938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.hfmfa.com"] [uri "/index.php"] [unique_id "aqxZ3gpXMN3p_zkwXf2uggAA2Ss"]
[Thu Sep 17 15:21:37.162826 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u4wAAAJ4"]
[Thu Sep 17 15:21:37.176649 2026] [security2:error] [pid 1012520:tid 1012657] [client 35.220.137.122:39322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/.env.bak"] [unique_id "aqxZ4QpXMN3p_zkwXf2u5AAAAIs"]
[Thu Sep 17 15:21:37.201360 2026] [security2:error] [pid 1012520:tid 1012689] [client 142.93.220.18:32962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxZ4ApXMN3p_zkwXf2u3AAAqwM"], referer: http://www.bonnieebsenjackson.com/wp/
[Thu Sep 17 15:21:37.206226 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u5gAAAKc"]
[Thu Sep 17 15:21:37.269790 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u6QAAAOw"]
[Thu Sep 17 15:21:37.316292 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u6gAAAL0"]
[Thu Sep 17 15:21:37.338869 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.220.137.122:39322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/.env.backup"] [unique_id "aqxZ4QpXMN3p_zkwXf2u6wAAANU"]
[Thu Sep 17 15:21:37.396851 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u8AAAAJI"]
[Thu Sep 17 15:21:37.458045 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u8gAAAOc"]
[Thu Sep 17 15:21:37.484819 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u8wAAAMs"]
[Thu Sep 17 15:21:37.524844 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.95.212.189:52534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/php.php"] [unique_id "aqxZ4QpXMN3p_zkwXf2u9AAAAKY"]
[Thu Sep 17 15:21:37.547935 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u9wAAALI"]
[Thu Sep 17 15:21:37.585699 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u-AAAAKE"]
[Thu Sep 17 15:21:37.614030 2026] [security2:error] [pid 1012520:tid 1012709] [client 20.219.28.139:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/server.php"] [unique_id "aqxZ4QpXMN3p_zkwXf2u-gAAAL8"]
[Thu Sep 17 15:21:37.635524 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u-wAAAI8"]
[Thu Sep 17 15:21:37.699757 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2u_QAAALs"]
[Thu Sep 17 15:21:37.733396 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2vAQAAAM0"]
[Thu Sep 17 15:21:37.796746 2026] [security2:error] [pid 1012520:tid 1012751] [client 216.24.219.104:29267] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/goods.php"] [unique_id "aqxZ4QpXMN3p_zkwXf2vAwAAAOk"]
[Thu Sep 17 15:21:37.838233 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2vBAAAAJk"]
[Thu Sep 17 15:21:37.919407 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxZ4QpXMN3p_zkwXf2vCQAAALk"]
[Thu Sep 17 15:21:38.013830 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.95.212.189:52540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/i.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vCwAAAPA"]
[Thu Sep 17 15:21:38.045560 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vDAAAAMk"]
[Thu Sep 17 15:21:38.139152 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.220.137.122:37514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/.env.old"] [unique_id "aqxZ4gpXMN3p_zkwXf2vDgAAALQ"]
[Thu Sep 17 15:21:38.147911 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vDwAAALA"]
[Thu Sep 17 15:21:38.255883 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vEAAAAJM"]
[Thu Sep 17 15:21:38.300552 2026] [security2:error] [pid 1012520:tid 1012662] [client 190.0.243.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "npae.net"] [uri "/index.php"] [unique_id "aqxZ4QpXMN3p_zkwXf2vAgAAAJA"], referer: https://npae.net/
[Thu Sep 17 15:21:38.305035 2026] [security2:error] [pid 1012520:tid 1012697] [client 193.36.224.108:30217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "whereismymap.com"] [uri "/php8.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vEgAAALM"]
[Thu Sep 17 15:21:38.320443 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vFQAAAPY"]
[Thu Sep 17 15:21:38.320888 2026] [security2:error] [pid 1012520:tid 1012669] [client 20.219.28.139:2021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/shell.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vFgAAAJc"]
[Thu Sep 17 15:21:38.420996 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vHAAAAPQ"]
[Thu Sep 17 15:21:38.517691 2026] [security2:error] [pid 1012520:tid 1012718] [client 216.98.214.231:19484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vGwAAyAw"]
[Thu Sep 17 15:21:38.518960 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.95.212.189:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/pi.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vHwAAAMM"]
[Thu Sep 17 15:21:38.533246 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vIAAAALw"]
[Thu Sep 17 15:21:38.676385 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vIQAAAQM"]
[Thu Sep 17 15:21:38.709293 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vIgAAAMQ"]
[Thu Sep 17 15:21:38.791050 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vIwAAANQ"]
[Thu Sep 17 15:21:38.841464 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vJgAAAPU"]
[Thu Sep 17 15:21:38.859840 2026] [security2:error] [pid 1012520:tid 1012682] [client 169.58.197.253:56151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vKQAAAKQ"], referer: binance.com
[Thu Sep 17 15:21:38.880308 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vKgAAAKc"]
[Thu Sep 17 15:21:38.969315 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxZ4gpXMN3p_zkwXf2vMQAAAJo"]
[Thu Sep 17 15:21:39.014865 2026] [security2:error] [pid 1012520:tid 1012775] [client 154.190.208.131:41415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vNQAAAQE"]
[Thu Sep 17 15:21:39.020522 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.95.212.189:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/pinfo.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vNgAAAKs"]
[Thu Sep 17 15:21:39.020978 2026] [security2:error] [pid 1012520:tid 1012775] [client 154.190.208.131:41415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vNQAAAQE"]
[Thu Sep 17 15:21:39.025879 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxZ4wpXMN3p_zkwXf2vNwAAAPI"]
[Thu Sep 17 15:21:39.030309 2026] [security2:error] [pid 1012520:tid 1012742] [client 20.219.28.139:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/t.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vOAAAAOA"]
[Thu Sep 17 15:21:39.061567 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.94.205.103:41802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alrayancont.com"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxZ4wpXMN3p_zkwXf2vOQAAAKI"]
[Thu Sep 17 15:21:39.083987 2026] [security2:error] [pid 1012520:tid 1012693] [client 152.32.215.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kmd.duj.mybluehost.me"] [uri "/index.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vLQAAAK8"]
[Thu Sep 17 15:21:39.160656 2026] [security2:error] [pid 1012520:tid 1012683] [client 142.93.220.18:32962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vOwAApQA"], referer: http://www.bonnieebsenjackson.com/backup/
[Thu Sep 17 15:21:39.209553 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.94.205.103:41802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/phpinfo.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vPQAAAPg"]
[Thu Sep 17 15:21:39.271463 2026] [security2:error] [pid 1012520:tid 1012696] [client 140.238.42.111:49567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vPgAAALI"]
[Thu Sep 17 15:21:39.351297 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.94.205.103:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/info.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vQQAAAMc"]
[Thu Sep 17 15:21:39.511500 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.95.212.189:52568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/test.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vRAAAAKo"]
[Thu Sep 17 15:21:39.703116 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.94.205.103:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/php.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vTQAAAMA"]
[Thu Sep 17 15:21:39.703975 2026] [security2:error] [pid 1012520:tid 1012651] [client 4.240.114.86:64157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxZ4gpXMN3p_zkwXf2vGAAAAIU"], referer: binance.com
[Thu Sep 17 15:21:39.722516 2026] [security2:error] [pid 1012520:tid 1012778] [client 142.93.220.18:32962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vRwABBGg"], referer: http://www.bonnieebsenjackson.com/new/
[Thu Sep 17 15:21:39.741708 2026] [security2:error] [pid 1012520:tid 1012700] [client 20.219.28.139:1124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.28.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.richflaherty.com"] [uri "/hello.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vTgAAALY"]
[Thu Sep 17 15:21:39.779096 2026] [security2:error] [pid 1012520:tid 1012658] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vSwAAAIw"]
[Thu Sep 17 15:21:39.894867 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.94.205.103:41838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/i.php"] [unique_id "aqxZ4wpXMN3p_zkwXf2vUwAAAMY"]
[Thu Sep 17 15:21:40.151259 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vXQAAAPY"]
[Thu Sep 17 15:21:40.174105 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.95.212.189:52578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/p.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vYwAAAOI"]
[Thu Sep 17 15:21:40.280217 2026] [security2:error] [pid 1012520:tid 1012762] [client 142.93.220.18:32962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vZAAA9Hc"], referer: http://www.bonnieebsenjackson.com/blog/
[Thu Sep 17 15:21:40.320252 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.94.205.103:41844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/pi.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vaQAAALc"]
[Thu Sep 17 15:21:40.498181 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.94.205.103:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/pinfo.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vcgAAANw"]
[Thu Sep 17 15:21:40.566573 2026] [security2:error] [pid 1012520:tid 1012718] [client 103.61.184.148:64368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vdAAAAMg"]
[Thu Sep 17 15:21:40.567541 2026] [security2:error] [pid 1012520:tid 1012718] [client 103.61.184.148:64368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vdAAAAMg"]
[Thu Sep 17 15:21:40.595248 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vcQAAANc"]
[Thu Sep 17 15:21:40.679363 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.95.212.189:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/debug.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vdQAAANY"]
[Thu Sep 17 15:21:40.760132 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.94.205.103:41856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/test.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vdwAAAPk"]
[Thu Sep 17 15:21:40.841512 2026] [security2:error] [pid 1012520:tid 1012749] [client 142.93.220.18:32962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vdgAA5wE"], referer: http://www.bonnieebsenjackson.com/wordpress/
[Thu Sep 17 15:21:40.880058 2026] [security2:error] [pid 1012520:tid 1012680] [client 151.255.127.164:8224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2veAAAohk"]
[Thu Sep 17 15:21:40.899476 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5ApXMN3p_zkwXf2vewAAAKY"]
[Thu Sep 17 15:21:41.103178 2026] [security2:error] [pid 1012520:tid 1012750] [client 114.198.138.124:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2viAAAAOg"]
[Thu Sep 17 15:21:41.103280 2026] [security2:error] [pid 1012520:tid 1012750] [client 114.198.138.124:58459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2viAAAAOg"]
[Thu Sep 17 15:21:41.172358 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.95.212.189:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2viQAAAPM"]
[Thu Sep 17 15:21:41.233814 2026] [core:error] [pid 1012520:tid 1012751] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:41.233838 2026] [core:error] [pid 1012520:tid 1012751] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:41.308034 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vjQAAAM8"]
[Thu Sep 17 15:21:41.406195 2026] [security2:error] [pid 1012520:tid 1012703] [client 142.93.220.18:32962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vjgAAuSg"], referer: http://www.bonnieebsenjackson.com/old/
[Thu Sep 17 15:21:41.424793 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.94.205.103:41870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/p.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vkgAAAPA"]
[Thu Sep 17 15:21:41.615168 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vlgAAAOU"]
[Thu Sep 17 15:21:41.656229 2026] [security2:error] [pid 1012520:tid 1012716] [client 185.55.149.49:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vmgAAAMY"]
[Thu Sep 17 15:21:41.656423 2026] [security2:error] [pid 1012520:tid 1012716] [client 185.55.149.49:62354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vmgAAAMY"]
[Thu Sep 17 15:21:41.663192 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.95.212.189:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vmwAAANM"]
[Thu Sep 17 15:21:41.667456 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.94.205.103:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/debug.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vnAAAAPo"]
[Thu Sep 17 15:21:41.847416 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.94.205.103:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vogAAAPQ"]
[Thu Sep 17 15:21:41.948746 2026] [security2:error] [pid 1012520:tid 1012699] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5QpXMN3p_zkwXf2vpAAAALU"]
[Thu Sep 17 15:21:42.069757 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.94.205.103:41892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/test/phpinfo.php"] [unique_id "aqxZ5gpXMN3p_zkwXf2vpgAAAJo"]
[Thu Sep 17 15:21:42.146884 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.212.189:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZ5gpXMN3p_zkwXf2vpwAAANA"]
[Thu Sep 17 15:21:42.278501 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.94.205.103:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxZ5gpXMN3p_zkwXf2vrQAAAJ4"]
[Thu Sep 17 15:21:42.400150 2026] [security2:error] [pid 1012520:tid 1012760] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5gpXMN3p_zkwXf2vrgAAAPI"]
[Thu Sep 17 15:21:42.623074 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.94.205.103:41902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZ5gpXMN3p_zkwXf2vsgAAAL0"]
[Thu Sep 17 15:21:42.665946 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.95.212.189:52630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/old/phpinfo.php"] [unique_id "aqxZ5gpXMN3p_zkwXf2vtAAAAIs"]
[Thu Sep 17 15:21:42.899148 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5gpXMN3p_zkwXf2vtwAAAMI"]
[Thu Sep 17 15:21:43.011994 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.94.205.103:41910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2vvQAAANI"]
[Thu Sep 17 15:21:43.070812 2026] [security2:error] [pid 1012520:tid 1012759] [client 156.192.234.52:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2vvgAAAPE"]
[Thu Sep 17 15:21:43.071511 2026] [security2:error] [pid 1012520:tid 1012759] [client 156.192.234.52:50434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2vvgAAAPE"]
[Thu Sep 17 15:21:43.093885 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/.env.swp"] [unique_id "aqxZ5wpXMN3p_zkwXf2vvwAAAOg"]
[Thu Sep 17 15:21:43.166803 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.212.189:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2vwAAAAMo"]
[Thu Sep 17 15:21:43.223844 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.94.205.103:41918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2vwQAAAIg"]
[Thu Sep 17 15:21:43.285241 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/.env~"] [unique_id "aqxZ5wpXMN3p_zkwXf2vwgAAANE"]
[Thu Sep 17 15:21:43.391595 2026] [core:error] [pid 1012520:tid 1012651] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:43.391616 2026] [core:error] [pid 1012520:tid 1012651] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:43.606207 2026] [security2:error] [pid 1012520:tid 1012730] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2vzAAAANQ"]
[Thu Sep 17 15:21:43.665429 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.95.212.189:52648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/public/phpinfo.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2vzgAAAPc"]
[Thu Sep 17 15:21:43.767235 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.94.205.103:57512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/php-info.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2v0wAAAJ8"]
[Thu Sep 17 15:21:43.921154 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.94.205.103:57520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/phpversion.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2v1wAAAME"]
[Thu Sep 17 15:21:43.972783 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ5wpXMN3p_zkwXf2v1gAAAJg"]
[Thu Sep 17 15:21:44.243036 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.94.205.103:57530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/_phpinfo.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v3wAAAKM"]
[Thu Sep 17 15:21:44.310266 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v3gAAAN4"]
[Thu Sep 17 15:21:44.326477 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.95.212.189:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/php-info.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v4AAAAPs"]
[Thu Sep 17 15:21:44.512107 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.94.205.103:57534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v6gAAAQM"]
[Thu Sep 17 15:21:44.577830 2026] [security2:error] [pid 1012520:tid 1012733] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v6QAAANc"]
[Thu Sep 17 15:21:44.586370 2026] [security2:error] [pid 1012520:tid 1012707] [client 140.238.42.111:49921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v6wAAAL0"]
[Thu Sep 17 15:21:44.700917 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.94.205.103:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/server-info.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v7AAAAIs"]
[Thu Sep 17 15:21:44.814904 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.95.212.189:52672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/phpversion.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v7wAAAKY"]
[Thu Sep 17 15:21:44.816477 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.220.137.122:37540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ6ApXMN3p_zkwXf2v7gAAAKI"]
[Thu Sep 17 15:21:45.093749 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.94.205.103:57560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/server-status.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2v-AAAAMc"]
[Thu Sep 17 15:21:45.217962 2026] [security2:error] [pid 1012520:tid 1012654] [client 140.238.42.111:54736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2v_AAAAIg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:45.226853 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2v-QAAAOg"]
[Thu Sep 17 15:21:45.307953 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.212.189:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/_phpinfo.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2v_wAAAI4"]
[Thu Sep 17 15:21:45.446597 2026] [core:error] [pid 1012520:tid 1012755] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:45.446617 2026] [core:error] [pid 1012520:tid 1012755] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:45.556832 2026] [security2:error] [pid 1012520:tid 1012741] [client 186.105.232.15:51937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wCgAAAN8"]
[Thu Sep 17 15:21:45.556960 2026] [security2:error] [pid 1012520:tid 1012741] [client 186.105.232.15:51937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wCgAAAN8"]
[Thu Sep 17 15:21:45.574813 2026] [security2:error] [pid 1012520:tid 1012651] [client 5.161.106.94:49448] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "www.alanpeckolick.com"] [uri "/wp-load.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wCwAAAIU"]
[Thu Sep 17 15:21:45.594555 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wCQAAAKw"]
[Thu Sep 17 15:21:45.611820 2026] [security2:error] [pid 1012520:tid 1012770] [client 140.238.42.111:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wDgAAAPw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:45.696694 2026] [core:error] [pid 1012520:tid 1012706] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:45.696724 2026] [core:error] [pid 1012520:tid 1012706] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:45.771142 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/app/.env"] [unique_id "aqxZ6QpXMN3p_zkwXf2wEgAAAPY"]
[Thu Sep 17 15:21:45.800085 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.95.212.189:52678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/old_phpinfo.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wEwAAALk"]
[Thu Sep 17 15:21:45.889837 2026] [security2:error] [pid 1012520:tid 1012694] [client 169.58.197.253:56565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/block-template.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wFAAAALA"], referer: binance.com
[Thu Sep 17 15:21:45.927448 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/apps/.env"] [unique_id "aqxZ6QpXMN3p_zkwXf2wIAAAAJE"]
[Thu Sep 17 15:21:46.001157 2026] [security2:error] [pid 1012520:tid 1012711] [client 140.238.42.111:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wLgAAAME"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:46.027078 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.94.205.103:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZ6gpXMN3p_zkwXf2wLwAAALU"]
[Thu Sep 17 15:21:46.107330 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/api/.env"] [unique_id "aqxZ6gpXMN3p_zkwXf2wMAAAAK0"]
[Thu Sep 17 15:21:46.177806 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.94.205.103:57600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wMgAAAKk"]
[Thu Sep 17 15:21:46.288235 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/web/.env"] [unique_id "aqxZ6gpXMN3p_zkwXf2wNAAAAPU"]
[Thu Sep 17 15:21:46.296248 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.95.212.189:52690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/server-info.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wNQAAANU"]
[Thu Sep 17 15:21:46.388105 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:56054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wOwAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:46.456584 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/site/.env"] [unique_id "aqxZ6gpXMN3p_zkwXf2wQAAAAL0"]
[Thu Sep 17 15:21:46.512326 2026] [security2:error] [pid 1012520:tid 1012743] [client 123.202.229.54:42258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wPAAA4So"]
[Thu Sep 17 15:21:46.580341 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.94.205.103:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wQwAAAMs"]
[Thu Sep 17 15:21:46.643454 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/public/.env"] [unique_id "aqxZ6gpXMN3p_zkwXf2wRQAAAMI"]
[Thu Sep 17 15:21:46.705721 2026] [security2:error] [pid 1012520:tid 1012745] [client 192.178.6.3:48077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wSAAAAOM"]
[Thu Sep 17 15:21:46.788329 2026] [security2:error] [pid 1012520:tid 1012772] [client 140.238.42.111:56421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wSQAAAP4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:46.811113 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.95.212.189:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/server-status.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wSgAAAKE"]
[Thu Sep 17 15:21:46.823253 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.94.205.103:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wTAAAAI0"]
[Thu Sep 17 15:21:46.951581 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ6gpXMN3p_zkwXf2wTwAAAK8"]
[Thu Sep 17 15:21:47.076194 2026] [security2:error] [pid 1012520:tid 1012698] [client 43.130.91.95:42934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.airmacinc.com"] [uri "/index.php"] [unique_id "aqxZ6QpXMN3p_zkwXf2wLQAAALQ"]
[Thu Sep 17 15:21:47.130116 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.94.205.103:57616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZ6wpXMN3p_zkwXf2wVgAAAIo"]
[Thu Sep 17 15:21:47.142434 2026] [security2:error] [pid 1012520:tid 1012690] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/backend/.env"] [unique_id "aqxZ6wpXMN3p_zkwXf2wVwAAAKw"]
[Thu Sep 17 15:21:47.170030 2026] [security2:error] [pid 1012520:tid 1012651] [client 140.238.42.111:56759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ6wpXMN3p_zkwXf2wXAAAAIU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:47.329390 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/server/.env"] [unique_id "aqxZ6wpXMN3p_zkwXf2wYQAAAJ8"]
[Thu Sep 17 15:21:47.479137 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.94.205.103:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZ6wpXMN3p_zkwXf2wZwAAAJA"]
[Thu Sep 17 15:21:47.510542 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/frontend/.env"] [unique_id "aqxZ6wpXMN3p_zkwXf2wagAAANM"]
[Thu Sep 17 15:21:47.594481 2026] [security2:error] [pid 1012520:tid 1012671] [client 140.238.42.111:57116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ6wpXMN3p_zkwXf2wbAAAAJk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:47.663764 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.95.212.189:53982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxZ6wpXMN3p_zkwXf2wbQAAALA"]
[Thu Sep 17 15:21:47.690545 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/src/.env"] [unique_id "aqxZ6wpXMN3p_zkwXf2wbgAAAPo"]
[Thu Sep 17 15:21:47.827093 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.94.205.103:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZ6wpXMN3p_zkwXf2wcwAAAIc"]
[Thu Sep 17 15:21:47.887106 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/core/.env"] [unique_id "aqxZ6wpXMN3p_zkwXf2wdgAAAP8"]
[Thu Sep 17 15:21:47.903984 2026] [authz_core:error] [pid 1012520:tid 1012700] [client 4.240.114.86:52007] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:21:47.989438 2026] [security2:error] [pid 1012520:tid 1012752] [client 140.238.42.111:57474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ6wpXMN3p_zkwXf2wgQAAAOo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:48.054896 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/core/app/.env"] [unique_id "aqxZ7ApXMN3p_zkwXf2whAAAAL0"]
[Thu Sep 17 15:21:48.159970 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.95.212.189:53984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxZ7ApXMN3p_zkwXf2whQAAAJo"]
[Thu Sep 17 15:21:48.171720 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.94.205.103:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZ7ApXMN3p_zkwXf2whgAAANA"]
[Thu Sep 17 15:21:48.230460 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/config/.env"] [unique_id "aqxZ7ApXMN3p_zkwXf2wiAAAAPg"]
[Thu Sep 17 15:21:48.238958 2026] [security2:error] [pid 1012520:tid 1012749] [client 52.28.162.93:57844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxZ7ApXMN3p_zkwXf2wiQAAAOc"], referer: https://faewave.com
[Thu Sep 17 15:21:48.380432 2026] [security2:error] [pid 1012520:tid 1012735] [client 140.238.42.111:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ7ApXMN3p_zkwXf2wjAAAANk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:48.393948 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/private/.env"] [unique_id "aqxZ7ApXMN3p_zkwXf2wjQAAAOw"]
[Thu Sep 17 15:21:48.410691 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.94.205.103:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/phpinfo.php~"] [unique_id "aqxZ7ApXMN3p_zkwXf2wjgAAALE"]
[Thu Sep 17 15:21:48.554315 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/application/.env"] [unique_id "aqxZ7ApXMN3p_zkwXf2wlAAAAI0"]
[Thu Sep 17 15:21:48.660304 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.95.212.189:53998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxZ7ApXMN3p_zkwXf2wlwAAAP4"]
[Thu Sep 17 15:21:48.695917 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.94.205.103:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/info.php.bak"] [unique_id "aqxZ7ApXMN3p_zkwXf2wmAAAAL4"]
[Thu Sep 17 15:21:48.715116 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/bootstrap/.env"] [unique_id "aqxZ7ApXMN3p_zkwXf2wmQAAAI4"]
[Thu Sep 17 15:21:48.801168 2026] [security2:error] [pid 1012520:tid 1012761] [client 140.238.42.111:58145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ7ApXMN3p_zkwXf2wnAAAAPM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:48.831749 2026] [security2:error] [pid 1012520:tid 1012737] [client 177.118.221.170:42320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ7ApXMN3p_zkwXf2wmgAA21s"]
[Thu Sep 17 15:21:48.897378 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/database/.env"] [unique_id "aqxZ7ApXMN3p_zkwXf2wnQAAAOQ"]
[Thu Sep 17 15:21:48.963004 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.94.205.103:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZ7ApXMN3p_zkwXf2woAAAALQ"]
[Thu Sep 17 15:21:49.061185 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/storage/.env"] [unique_id "aqxZ7QpXMN3p_zkwXf2wowAAAPw"]
[Thu Sep 17 15:21:49.149821 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.94.205.103:57680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wpAAAAJ8"]
[Thu Sep 17 15:21:49.159024 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.95.212.189:54008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wpQAAALs"]
[Thu Sep 17 15:21:49.207454 2026] [security2:error] [pid 1012520:tid 1012765] [client 140.238.42.111:58499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wpgAAAPc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:49.222547 2026] [security2:error] [pid 1012520:tid 1012658] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/var/www/.env"] [unique_id "aqxZ7QpXMN3p_zkwXf2wpwAAAIw"]
[Thu Sep 17 15:21:49.379527 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.94.205.103:57690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wqAAAANM"]
[Thu Sep 17 15:21:49.390840 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/var/www/html/.env"] [unique_id "aqxZ7QpXMN3p_zkwXf2wqQAAAOI"]
[Thu Sep 17 15:21:49.505251 2026] [security2:error] [pid 1012520:tid 1012668] [client 154.190.208.131:42005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wrAAAAJY"]
[Thu Sep 17 15:21:49.508073 2026] [security2:error] [pid 1012520:tid 1012668] [client 154.190.208.131:42005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wrAAAAJY"]
[Thu Sep 17 15:21:49.561954 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/current/.env"] [unique_id "aqxZ7QpXMN3p_zkwXf2wrgAAAJE"]
[Thu Sep 17 15:21:49.589042 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.94.205.103:57706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wrwAAAPo"]
[Thu Sep 17 15:21:49.612402 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:58855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wsAAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:49.655326 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.95.212.189:54022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wsQAAALA"]
[Thu Sep 17 15:21:49.730378 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/release/.env"] [unique_id "aqxZ7QpXMN3p_zkwXf2wsgAAAOU"]
[Thu Sep 17 15:21:49.813029 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.94.205.103:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZ7QpXMN3p_zkwXf2wswAAAJM"]
[Thu Sep 17 15:21:49.891530 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/releases/.env"] [unique_id "aqxZ7QpXMN3p_zkwXf2wtgAAALY"]
[Thu Sep 17 15:21:50.011600 2026] [security2:error] [pid 1012520:tid 1012773] [client 140.238.42.111:59214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2wuAAAAP8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:50.054300 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/shared/.env"] [unique_id "aqxZ7gpXMN3p_zkwXf2wvAAAANA"]
[Thu Sep 17 15:21:50.086559 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.94.205.103:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2wvwAAAOE"]
[Thu Sep 17 15:21:50.142333 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.95.212.189:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2wwQAAAL0"]
[Thu Sep 17 15:21:50.215087 2026] [security2:error] [pid 1012520:tid 1012676] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/deploy/.env"] [unique_id "aqxZ7gpXMN3p_zkwXf2wxAAAAJ4"]
[Thu Sep 17 15:21:50.382860 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.94.205.103:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2wxwAAAMs"]
[Thu Sep 17 15:21:50.399452 2026] [security2:error] [pid 1012520:tid 1012766] [client 140.238.42.111:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2wyQAAAPg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:50.416965 2026] [security2:error] [pid 1012520:tid 1012691] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/build/.env"] [unique_id "aqxZ7gpXMN3p_zkwXf2wygAAAK0"]
[Thu Sep 17 15:21:50.494953 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.94.205.103:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2w0AAAAJI"]
[Thu Sep 17 15:21:50.618708 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/dist/.env"] [unique_id "aqxZ7gpXMN3p_zkwXf2w0wAAANE"]
[Thu Sep 17 15:21:50.651312 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.212.189:54028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxZ7gpXMN3p_zkwXf2w1AAAAOM"]
[Thu Sep 17 15:21:50.766316 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.94.205.103:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2w1wAAAK4"]
[Thu Sep 17 15:21:50.801086 2026] [security2:error] [pid 1012520:tid 1012660] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/public_html/.env"] [unique_id "aqxZ7gpXMN3p_zkwXf2w2AAAAI4"]
[Thu Sep 17 15:21:50.862811 2026] [security2:error] [pid 1012520:tid 1012659] [client 140.238.42.111:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ7gpXMN3p_zkwXf2w2QAAAI0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:50.990959 2026] [security2:error] [pid 1012520:tid 1012654] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/htdocs/.env"] [unique_id "aqxZ7gpXMN3p_zkwXf2w3AAAAIg"]
[Thu Sep 17 15:21:51.098128 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.94.205.103:57754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w3gAAAL8"]
[Thu Sep 17 15:21:51.156811 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.95.212.189:54040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/phpinfo.php.old"] [unique_id "aqxZ7wpXMN3p_zkwXf2w3wAAAKA"]
[Thu Sep 17 15:21:51.190528 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/www/.env"] [unique_id "aqxZ7wpXMN3p_zkwXf2w4AAAAN8"]
[Thu Sep 17 15:21:51.208538 2026] [security2:error] [pid 1012520:tid 1012652] [client 103.61.184.148:64930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w4gAAAIY"]
[Thu Sep 17 15:21:51.208647 2026] [security2:error] [pid 1012520:tid 1012652] [client 103.61.184.148:64930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w4gAAAIY"]
[Thu Sep 17 15:21:51.271798 2026] [security2:error] [pid 1012520:tid 1012767] [client 140.238.42.111:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w4wAAAPk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:51.366519 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/html/.env"] [unique_id "aqxZ7wpXMN3p_zkwXf2w5AAAALQ"]
[Thu Sep 17 15:21:51.371798 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.94.205.103:57758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w5QAAAMk"]
[Thu Sep 17 15:21:51.544609 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/live/.env"] [unique_id "aqxZ7wpXMN3p_zkwXf2w6gAAAJA"]
[Thu Sep 17 15:21:51.621421 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.94.205.103:57764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w7QAAAIw"]
[Thu Sep 17 15:21:51.646571 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.212.189:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/phpinfo.php~"] [unique_id "aqxZ7wpXMN3p_zkwXf2w7gAAALM"]
[Thu Sep 17 15:21:51.659708 2026] [security2:error] [pid 1012520:tid 1012656] [client 140.238.42.111:60671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w7wAAAIo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:51.697275 2026] [security2:error] [pid 1012520:tid 1012669] [client 114.198.138.124:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w8gAAAJc"]
[Thu Sep 17 15:21:51.697395 2026] [security2:error] [pid 1012520:tid 1012669] [client 114.198.138.124:59108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w8gAAAJc"]
[Thu Sep 17 15:21:51.711442 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/prod/.env"] [unique_id "aqxZ7wpXMN3p_zkwXf2w9AAAAJY"]
[Thu Sep 17 15:21:51.875324 2026] [security2:error] [pid 1012520:tid 1012776] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/dev/.env"] [unique_id "aqxZ7wpXMN3p_zkwXf2w9QAAAQI"]
[Thu Sep 17 15:21:51.915656 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.94.205.103:57778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZ7wpXMN3p_zkwXf2w9gAAAJk"]
[Thu Sep 17 15:21:52.048117 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/staging/.env"] [unique_id "aqxZ8ApXMN3p_zkwXf2w-wAAAJg"]
[Thu Sep 17 15:21:52.060328 2026] [security2:error] [pid 1012520:tid 1012711] [client 140.238.42.111:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ8ApXMN3p_zkwXf2w_AAAAME"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:52.137012 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.95.212.189:54050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/info.php.bak"] [unique_id "aqxZ8ApXMN3p_zkwXf2w_QAAAOU"]
[Thu Sep 17 15:21:52.216584 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/opt/.env"] [unique_id "aqxZ8ApXMN3p_zkwXf2w_gAAAM0"]
[Thu Sep 17 15:21:52.293821 2026] [security2:error] [pid 1012520:tid 1012726] [client 185.55.149.49:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ8ApXMN3p_zkwXf2xAQAAANA"]
[Thu Sep 17 15:21:52.293953 2026] [security2:error] [pid 1012520:tid 1012726] [client 185.55.149.49:60864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ8ApXMN3p_zkwXf2xAQAAANA"]
[Thu Sep 17 15:21:52.302371 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.94.205.103:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZ8ApXMN3p_zkwXf2xAwAAAJ0"]
[Thu Sep 17 15:21:52.395619 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/laravel/.env"] [unique_id "aqxZ8ApXMN3p_zkwXf2xBAAAAKY"]
[Thu Sep 17 15:21:52.451150 2026] [security2:error] [pid 1012520:tid 1012683] [client 140.238.42.111:61321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ8ApXMN3p_zkwXf2xBQAAAKU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:52.560547 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/symfony/.env"] [unique_id "aqxZ8ApXMN3p_zkwXf2xDAAAALE"]
[Thu Sep 17 15:21:52.623492 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.95.212.189:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/phpinfo.php.save"] [unique_id "aqxZ8ApXMN3p_zkwXf2xDQAAAKI"]
[Thu Sep 17 15:21:52.738735 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/wordpress/.env"] [unique_id "aqxZ8ApXMN3p_zkwXf2xDgAAAOM"]
[Thu Sep 17 15:21:52.746979 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.94.205.103:57810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.205.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alrayancont.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZ8ApXMN3p_zkwXf2xDwAAAPU"]
[Thu Sep 17 15:21:52.836349 2026] [security2:error] [pid 1012520:tid 1012727] [client 140.238.42.111:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ8ApXMN3p_zkwXf2xEQAAANE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:52.911454 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/wp/.env"] [unique_id "aqxZ8ApXMN3p_zkwXf2xEwAAAK4"]
[Thu Sep 17 15:21:53.087022 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cms/.env"] [unique_id "aqxZ8QpXMN3p_zkwXf2xGAAAAKM"]
[Thu Sep 17 15:21:53.109303 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.95.212.189:54076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxZ8QpXMN3p_zkwXf2xGwAAAI4"]
[Thu Sep 17 15:21:53.225846 2026] [security2:error] [pid 1012520:tid 1012755] [client 140.238.42.111:62039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ8QpXMN3p_zkwXf2xHgAAAO0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:53.261887 2026] [security2:error] [pid 1012520:tid 1012737] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/drupal/.env"] [unique_id "aqxZ8QpXMN3p_zkwXf2xIgAAANs"]
[Thu Sep 17 15:21:53.423317 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/joomla/.env"] [unique_id "aqxZ8QpXMN3p_zkwXf2xKQAAAPA"]
[Thu Sep 17 15:21:53.592224 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/magento/.env"] [unique_id "aqxZ8QpXMN3p_zkwXf2xNwAAAMY"]
[Thu Sep 17 15:21:53.602738 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.95.212.189:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxZ8QpXMN3p_zkwXf2xOQAAAPY"]
[Thu Sep 17 15:21:53.610374 2026] [security2:error] [pid 1012520:tid 1012668] [client 140.238.42.111:62388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ8QpXMN3p_zkwXf2xOgAAAJY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:53.707322 2026] [security2:error] [pid 1012520:tid 1012652] [client 156.192.234.52:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ8QpXMN3p_zkwXf2xOwAAAIY"]
[Thu Sep 17 15:21:53.707926 2026] [security2:error] [pid 1012520:tid 1012652] [client 156.192.234.52:51071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ8QpXMN3p_zkwXf2xOwAAAIY"]
[Thu Sep 17 15:21:53.731653 2026] [security2:error] [pid 1012520:tid 1012739] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxZ8QpXMN3p_zkwXf2xOAAAAN0"]
[Thu Sep 17 15:21:53.762612 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/shopify/.env"] [unique_id "aqxZ8QpXMN3p_zkwXf2xPQAAAKo"]
[Thu Sep 17 15:21:53.948721 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/prestashop/.env"] [unique_id "aqxZ8QpXMN3p_zkwXf2xQgAAAKQ"]
[Thu Sep 17 15:21:54.019919 2026] [security2:error] [pid 1012520:tid 1012723] [client 140.238.42.111:62735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ8gpXMN3p_zkwXf2xRgAAAM0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:54.110079 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.95.212.189:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxZ8gpXMN3p_zkwXf2xSgAAANA"]
[Thu Sep 17 15:21:54.122794 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/codeigniter/.env"] [unique_id "aqxZ8gpXMN3p_zkwXf2xTAAAAMQ"]
[Thu Sep 17 15:21:54.203588 2026] [authz_core:error] [pid 1012520:tid 1012776] [client 4.240.114.86:55115] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:21:54.317783 2026] [security2:error] [pid 1012520:tid 1012661] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cakephp/.env"] [unique_id "aqxZ8gpXMN3p_zkwXf2xTwAAAI8"]
[Thu Sep 17 15:21:54.426497 2026] [security2:error] [pid 1012520:tid 1012717] [client 140.238.42.111:63060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ8gpXMN3p_zkwXf2xUQAAAMc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:54.491054 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/zend/.env"] [unique_id "aqxZ8gpXMN3p_zkwXf2xVAAAANg"]
[Thu Sep 17 15:21:54.599884 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.95.212.189:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxZ8gpXMN3p_zkwXf2xVwAAAPU"]
[Thu Sep 17 15:21:54.666329 2026] [security2:error] [pid 1012520:tid 1012771] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/yii/.env"] [unique_id "aqxZ8gpXMN3p_zkwXf2xWQAAAP0"]
[Thu Sep 17 15:21:54.679089 2026] [core:error] [pid 1012520:tid 1012772] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:54.679113 2026] [core:error] [pid 1012520:tid 1012772] [client 34.94.205.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:21:54.814842 2026] [security2:error] [pid 1012520:tid 1012696] [client 140.238.42.111:63400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ8gpXMN3p_zkwXf2xXwAAALI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:54.833001 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/laravel5/.env"] [unique_id "aqxZ8gpXMN3p_zkwXf2xYgAAAKA"]
[Thu Sep 17 15:21:54.996143 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/v1/.env"] [unique_id "aqxZ8gpXMN3p_zkwXf2xZwAAAOQ"]
[Thu Sep 17 15:21:55.098051 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.95.212.189:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxZ8wpXMN3p_zkwXf2xaQAAAOg"]
[Thu Sep 17 15:21:55.161261 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/v2/.env"] [unique_id "aqxZ8wpXMN3p_zkwXf2xbAAAAJE"]
[Thu Sep 17 15:21:55.177003 2026] [security2:error] [pid 1012520:tid 1012729] [client 169.58.197.253:57099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxZ8wpXMN3p_zkwXf2xbQAAANM"], referer: binance.com
[Thu Sep 17 15:21:55.229468 2026] [security2:error] [pid 1012520:tid 1012758] [client 140.238.42.111:63732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ8wpXMN3p_zkwXf2xbgAAAPA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:55.327365 2026] [security2:error] [pid 1012520:tid 1012764] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/v3/.env"] [unique_id "aqxZ8wpXMN3p_zkwXf2xbwAAAPY"]
[Thu Sep 17 15:21:55.490701 2026] [security2:error] [pid 1012520:tid 1012773] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/api/v1/.env"] [unique_id "aqxZ8wpXMN3p_zkwXf2xdQAAAP8"]
[Thu Sep 17 15:21:55.593787 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.95.212.189:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/www/phpinfo.php"] [unique_id "aqxZ8wpXMN3p_zkwXf2xdgAAAQQ"]
[Thu Sep 17 15:21:55.618747 2026] [security2:error] [pid 1012520:tid 1012730] [client 140.238.42.111:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ8wpXMN3p_zkwXf2xeAAAANQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:55.674781 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/api/v2/.env"] [unique_id "aqxZ8wpXMN3p_zkwXf2xegAAALQ"]
[Thu Sep 17 15:21:55.771919 2026] [security2:error] [pid 1012520:tid 1012712] [client 65.49.9.244:33588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "24eastyard.com"] [uri "/index.php/wp-json/"] [unique_id "aqxZ8wpXMN3p_zkwXf2xfAAAwkY"]
[Thu Sep 17 15:21:55.836975 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.220.137.122:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/rest/.env"] [unique_id "aqxZ8wpXMN3p_zkwXf2xfQAAAKQ"]
[Thu Sep 17 15:21:55.843983 2026] [security2:error] [pid 1012520:tid 1012675] [client 52.231.79.181:1613] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/1.php"] [unique_id "aqxZ8wpXMN3p_zkwXf2xfgAAAJ0"]
[Thu Sep 17 15:21:55.844088 2026] [security2:error] [pid 1012520:tid 1012675] [client 52.231.79.181:1613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/1.php"] [unique_id "aqxZ8wpXMN3p_zkwXf2xfgAAAJ0"]
[Thu Sep 17 15:21:56.010290 2026] [security2:error] [pid 1012520:tid 1012676] [client 140.238.42.111:64430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xiQAAAJ4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:56.079932 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.95.212.189:54148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xjAAAAKg"]
[Thu Sep 17 15:21:56.246548 2026] [security2:error] [pid 1012520:tid 1012763] [client 52.231.79.181:1650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/new.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xkgAAAPU"]
[Thu Sep 17 15:21:56.266220 2026] [security2:error] [pid 1012520:tid 1012756] [client 52.102.18.213:49246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xkQAAAO4"]
[Thu Sep 17 15:21:56.358480 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/graphql/.env"] [unique_id "aqxZ9ApXMN3p_zkwXf2xmgAAAI0"]
[Thu Sep 17 15:21:56.404786 2026] [security2:error] [pid 1012520:tid 1012732] [client 140.238.42.111:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xmwAAANY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:56.529337 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/gateway/.env"] [unique_id "aqxZ9ApXMN3p_zkwXf2xnAAAAO0"]
[Thu Sep 17 15:21:56.574564 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.95.212.189:54154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xngAAAJI"]
[Thu Sep 17 15:21:56.652220 2026] [security2:error] [pid 1012520:tid 1012702] [client 52.231.79.181:1651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/num.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xnwAAALg"]
[Thu Sep 17 15:21:56.702792 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/microservice/.env"] [unique_id "aqxZ9ApXMN3p_zkwXf2xoAAAAOY"]
[Thu Sep 17 15:21:56.785305 2026] [security2:error] [pid 1012520:tid 1012737] [client 140.238.42.111:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ9ApXMN3p_zkwXf2xoQAAANs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:56.860789 2026] [security2:error] [pid 1012520:tid 1012777] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/service/.env"] [unique_id "aqxZ9ApXMN3p_zkwXf2xpAAAAQM"]
[Thu Sep 17 15:21:57.057005 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/api/v3/.env"] [unique_id "aqxZ9QpXMN3p_zkwXf2xqAAAAJo"]
[Thu Sep 17 15:21:57.062546 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.95.212.189:44392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/site/phpinfo.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xqQAAAPc"]
[Thu Sep 17 15:21:57.167318 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:65391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xqwAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:57.200299 2026] [security2:error] [pid 1012520:tid 1012662] [client 52.231.79.181:1627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/admin.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xrAAAAJA"]
[Thu Sep 17 15:21:57.233268 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/api/dev/.env"] [unique_id "aqxZ9QpXMN3p_zkwXf2xrQAAAOI"]
[Thu Sep 17 15:21:57.240215 2026] [security2:error] [pid 1012520:tid 1012733] [client 186.105.232.15:52539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xsAAAANc"]
[Thu Sep 17 15:21:57.240319 2026] [security2:error] [pid 1012520:tid 1012733] [client 186.105.232.15:52539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xsAAAANc"]
[Thu Sep 17 15:21:57.371398 2026] [security2:error] [pid 1012520:tid 1012656] [client 103.190.41.43:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xsQAAinw"]
[Thu Sep 17 15:21:57.392261 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/api/staging/.env"] [unique_id "aqxZ9QpXMN3p_zkwXf2xtwAAAOs"]
[Thu Sep 17 15:21:57.555711 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.95.212.189:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xvQAAAOo"]
[Thu Sep 17 15:21:57.556186 2026] [security2:error] [pid 1012520:tid 1012751] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/vendor/.env"] [unique_id "aqxZ9QpXMN3p_zkwXf2xvAAAAOk"]
[Thu Sep 17 15:21:57.561504 2026] [security2:error] [pid 1012520:tid 1012740] [client 140.238.42.111:49316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xvgAAAN4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:57.595467 2026] [security2:error] [pid 1012520:tid 1012679] [client 52.231.79.181:1631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/13.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2xvwAAAKE"]
[Thu Sep 17 15:21:57.724173 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/lib/.env"] [unique_id "aqxZ9QpXMN3p_zkwXf2xzAAAALw"]
[Thu Sep 17 15:21:57.884183 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/resources/.env"] [unique_id "aqxZ9QpXMN3p_zkwXf2x3gAAAJw"]
[Thu Sep 17 15:21:57.953693 2026] [security2:error] [pid 1012520:tid 1012667] [client 140.238.42.111:49653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ9QpXMN3p_zkwXf2x4AAAAJU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:58.013854 2026] [security2:error] [pid 1012520:tid 1012694] [client 52.231.79.181:1485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/222.php"] [unique_id "aqxZ9gpXMN3p_zkwXf2x4gAAALA"]
[Thu Sep 17 15:21:58.040496 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/assets/.env"] [unique_id "aqxZ9gpXMN3p_zkwXf2x4wAAAKQ"]
[Thu Sep 17 15:21:58.049533 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.95.212.189:44420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxZ9gpXMN3p_zkwXf2x5AAAAMI"]
[Thu Sep 17 15:21:58.198523 2026] [security2:error] [pid 1012520:tid 1012724] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/uploads/.env"] [unique_id "aqxZ9gpXMN3p_zkwXf2x5gAAAM4"]
[Thu Sep 17 15:21:58.353923 2026] [security2:error] [pid 1012520:tid 1012687] [client 140.238.42.111:49966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ9gpXMN3p_zkwXf2x6wAAAKk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:58.356577 2026] [security2:error] [pid 1012520:tid 1012769] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/internal/.env"] [unique_id "aqxZ9gpXMN3p_zkwXf2x7AAAAPs"]
[Thu Sep 17 15:21:58.417830 2026] [security2:error] [pid 1012520:tid 1012676] [client 52.231.79.181:1614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/aa.php"] [unique_id "aqxZ9gpXMN3p_zkwXf2x7wAAAJ4"]
[Thu Sep 17 15:21:58.529382 2026] [security2:error] [pid 1012520:tid 1012731] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/tools/.env"] [unique_id "aqxZ9gpXMN3p_zkwXf2x9QAAANU"]
[Thu Sep 17 15:21:58.551485 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.212.189:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxZ9gpXMN3p_zkwXf2x-QAAAOM"]
[Thu Sep 17 15:21:58.692238 2026] [security2:error] [pid 1012520:tid 1012689] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/scripts/.env"] [unique_id "aqxZ9gpXMN3p_zkwXf2x-wAAAKs"]
[Thu Sep 17 15:21:58.745452 2026] [security2:error] [pid 1012520:tid 1012757] [client 140.238.42.111:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ9gpXMN3p_zkwXf2x_AAAAO8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:58.844651 2026] [security2:error] [pid 1012520:tid 1012749] [client 52.231.79.181:1487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/abcd.php"] [unique_id "aqxZ9gpXMN3p_zkwXf2x_wAAAOc"]
[Thu Sep 17 15:21:58.852999 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/bin/.env"] [unique_id "aqxZ9gpXMN3p_zkwXf2yAQAAAKA"]
[Thu Sep 17 15:21:59.016383 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/sbin/.env"] [unique_id "aqxZ9wpXMN3p_zkwXf2yCAAAAJI"]
[Thu Sep 17 15:21:59.046278 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.95.212.189:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/core/phpinfo.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yCgAAALI"]
[Thu Sep 17 15:21:59.133393 2026] [security2:error] [pid 1012520:tid 1012718] [client 140.238.42.111:50589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yDAAAAMg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:59.187878 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/local/.env"] [unique_id "aqxZ9wpXMN3p_zkwXf2yDQAAAPw"]
[Thu Sep 17 15:21:59.266067 2026] [security2:error] [pid 1012520:tid 1012663] [client 52.231.79.181:1494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/about.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yDwAAAJE"]
[Thu Sep 17 15:21:59.354286 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/portal/.env"] [unique_id "aqxZ9wpXMN3p_zkwXf2yEgAAAJo"]
[Thu Sep 17 15:21:59.514845 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/dashboard/.env"] [unique_id "aqxZ9wpXMN3p_zkwXf2yFQAAAOI"]
[Thu Sep 17 15:21:59.546160 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.95.212.189:44452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.212.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kippremote.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yFgAAAIw"]
[Thu Sep 17 15:21:59.549491 2026] [security2:error] [pid 1012520:tid 1012662] [client 140.238.42.111:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yFwAAAJA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:59.685344 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/panel/.env"] [unique_id "aqxZ9wpXMN3p_zkwXf2yGAAAAOs"]
[Thu Sep 17 15:21:59.699707 2026] [security2:error] [pid 1012520:tid 1012733] [client 52.231.79.181:1615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/admin.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yGgAAANc"]
[Thu Sep 17 15:21:59.853922 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/crm/.env"] [unique_id "aqxZ9wpXMN3p_zkwXf2yHAAAAPA"]
[Thu Sep 17 15:21:59.931402 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:51214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yIAAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:21:59.935205 2026] [security2:error] [pid 1012520:tid 1012713] [client 190.2.103.90:23566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxZ9wpXMN3p_zkwXf2yGwAAwzI"]
[Thu Sep 17 15:22:00.019732 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/erp/.env"] [unique_id "aqxZ-ApXMN3p_zkwXf2yIgAAAJg"]
[Thu Sep 17 15:22:00.041476 2026] [security2:error] [pid 1012520:tid 1012764] [client 154.190.208.131:42485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ-ApXMN3p_zkwXf2yIwAAAPY"]
[Thu Sep 17 15:22:00.043552 2026] [security2:error] [pid 1012520:tid 1012764] [client 154.190.208.131:42485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ-ApXMN3p_zkwXf2yIwAAAPY"]
[Thu Sep 17 15:22:00.116279 2026] [security2:error] [pid 1012520:tid 1012752] [client 52.231.79.181:1646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/adminfuns.php"] [unique_id "aqxZ-ApXMN3p_zkwXf2yJQAAAOo"]
[Thu Sep 17 15:22:00.176724 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/shop/.env"] [unique_id "aqxZ-ApXMN3p_zkwXf2yKAAAAJY"]
[Thu Sep 17 15:22:00.337411 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/store/.env"] [unique_id "aqxZ-ApXMN3p_zkwXf2yKwAAAPQ"]
[Thu Sep 17 15:22:00.343242 2026] [security2:error] [pid 1012520:tid 1012701] [client 140.238.42.111:51546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ-ApXMN3p_zkwXf2yLQAAALc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:00.499646 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/saas/.env"] [unique_id "aqxZ-ApXMN3p_zkwXf2yMQAAAMI"]
[Thu Sep 17 15:22:00.525558 2026] [security2:error] [pid 1012520:tid 1012743] [client 52.231.79.181:1634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxZ-ApXMN3p_zkwXf2yMgAAAOE"]
[Thu Sep 17 15:22:00.655522 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/client/.env"] [unique_id "aqxZ-ApXMN3p_zkwXf2yNgAAANA"]
[Thu Sep 17 15:22:00.730058 2026] [security2:error] [pid 1012520:tid 1012675] [client 140.238.42.111:51909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ-ApXMN3p_zkwXf2yOAAAAJ0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:00.816532 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/project/.env"] [unique_id "aqxZ-ApXMN3p_zkwXf2yOgAAAKg"]
[Thu Sep 17 15:22:00.923293 2026] [security2:error] [pid 1012520:tid 1012769] [client 52.231.79.181:1625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/ae.php"] [unique_id "aqxZ-ApXMN3p_zkwXf2yQgAAAPs"]
[Thu Sep 17 15:22:00.999037 2026] [security2:error] [pid 1012520:tid 1012684] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/admin-panel/.env"] [unique_id "aqxZ-ApXMN3p_zkwXf2yQwAAAKY"]
[Thu Sep 17 15:22:01.119601 2026] [security2:error] [pid 1012520:tid 1012721] [client 140.238.42.111:52302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ-QpXMN3p_zkwXf2ySgAAAMs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:01.161801 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/control-panel/.env"] [unique_id "aqxZ-QpXMN3p_zkwXf2ySwAAAO8"]
[Thu Sep 17 15:22:01.319634 2026] [security2:error] [pid 1012520:tid 1012775] [client 52.231.79.181:1638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/akcc.php"] [unique_id "aqxZ-QpXMN3p_zkwXf2yTwAAAQE"]
[Thu Sep 17 15:22:01.320420 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/user-panel/.env"] [unique_id "aqxZ-QpXMN3p_zkwXf2yTgAAALE"]
[Thu Sep 17 15:22:01.488415 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/node/.env"] [unique_id "aqxZ-QpXMN3p_zkwXf2yVQAAAPE"]
[Thu Sep 17 15:22:01.505075 2026] [security2:error] [pid 1012520:tid 1012664] [client 140.238.42.111:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ-QpXMN3p_zkwXf2yVgAAAJI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:01.650140 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/express/.env"] [unique_id "aqxZ-QpXMN3p_zkwXf2yWgAAANM"]
[Thu Sep 17 15:22:01.752202 2026] [security2:error] [pid 1012520:tid 1012718] [client 52.231.79.181:1640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/bak.php"] [unique_id "aqxZ-QpXMN3p_zkwXf2yWwAAAMg"]
[Thu Sep 17 15:22:01.819644 2026] [security2:error] [pid 1012520:tid 1012705] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/next/.env"] [unique_id "aqxZ-QpXMN3p_zkwXf2yXgAAALs"]
[Thu Sep 17 15:22:01.824936 2026] [security2:error] [pid 1012520:tid 1012748] [client 103.61.184.148:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ-QpXMN3p_zkwXf2yXwAAAOY"]
[Thu Sep 17 15:22:01.825030 2026] [security2:error] [pid 1012520:tid 1012748] [client 103.61.184.148:65488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ-QpXMN3p_zkwXf2yXwAAAOY"]
[Thu Sep 17 15:22:01.898444 2026] [security2:error] [pid 1012520:tid 1012690] [client 140.238.42.111:52948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ-QpXMN3p_zkwXf2yYAAAAKw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:01.983350 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/nuxt/.env"] [unique_id "aqxZ-QpXMN3p_zkwXf2yZQAAAL4"]
[Thu Sep 17 15:22:02.142122 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/nest/.env"] [unique_id "aqxZ-gpXMN3p_zkwXf2yagAAAMk"]
[Thu Sep 17 15:22:02.159059 2026] [security2:error] [pid 1012520:tid 1012733] [client 52.231.79.181:1609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/cc.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2yawAAANc"]
[Thu Sep 17 15:22:02.192298 2026] [security2:error] [pid 1012520:tid 1012728] [client 114.198.138.124:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2ycAAAANI"]
[Thu Sep 17 15:22:02.192416 2026] [security2:error] [pid 1012520:tid 1012728] [client 114.198.138.124:59760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2ycAAAANI"]
[Thu Sep 17 15:22:02.280507 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:53261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2ydAAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:02.311976 2026] [security2:error] [pid 1012520:tid 1012715] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/react/.env"] [unique_id "aqxZ-gpXMN3p_zkwXf2ydQAAAMU"]
[Thu Sep 17 15:22:02.356132 2026] [security2:error] [pid 1012520:tid 1012670] [client 43.173.179.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2ybwAAAJg"]
[Thu Sep 17 15:22:02.476751 2026] [security2:error] [pid 1012520:tid 1012668] [client 209.141.32.143:56714] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "groverpdx.net"] [uri "/wp-content/plugins/jetformbuilder/readme.txt"] [unique_id "aqxZ-gpXMN3p_zkwXf2yegAAAJY"]
[Thu Sep 17 15:22:02.490034 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/vue/.env"] [unique_id "aqxZ-gpXMN3p_zkwXf2yfAAAAKc"]
[Thu Sep 17 15:22:02.598056 2026] [security2:error] [pid 1012520:tid 1012700] [client 52.231.79.181:1632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/chosen.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2yfwAAALY"]
[Thu Sep 17 15:22:02.669022 2026] [security2:error] [pid 1012520:tid 1012738] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/angular/.env"] [unique_id "aqxZ-gpXMN3p_zkwXf2ygAAAANw"]
[Thu Sep 17 15:22:02.676576 2026] [security2:error] [pid 1012520:tid 1012743] [client 140.238.42.111:53574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2ygQAAAOE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:02.831656 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/svelte/.env"] [unique_id "aqxZ-gpXMN3p_zkwXf2ygwAAAM8"]
[Thu Sep 17 15:22:02.986253 2026] [security2:error] [pid 1012520:tid 1012687] [client 185.55.149.49:61564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2yiQAAAKk"]
[Thu Sep 17 15:22:02.986569 2026] [security2:error] [pid 1012520:tid 1012687] [client 185.55.149.49:61564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxZ-gpXMN3p_zkwXf2yiQAAAKk"]
[Thu Sep 17 15:22:02.991968 2026] [security2:error] [pid 1012520:tid 1012734] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/vite/.env"] [unique_id "aqxZ-gpXMN3p_zkwXf2yiwAAANg"]
[Thu Sep 17 15:22:03.001216 2026] [security2:error] [pid 1012520:tid 1012771] [client 52.231.79.181:1642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/classwithtostring.php"] [unique_id "aqxZ-wpXMN3p_zkwXf2yjAAAAP0"]
[Thu Sep 17 15:22:03.072568 2026] [security2:error] [pid 1012520:tid 1012769] [client 140.238.42.111:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ-wpXMN3p_zkwXf2ykAAAAPs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:03.165885 2026] [security2:error] [pid 1012520:tid 1012741] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/backup/.env"] [unique_id "aqxZ-wpXMN3p_zkwXf2ykQAAAN8"]
[Thu Sep 17 15:22:03.338428 2026] [security2:error] [pid 1012520:tid 1012702] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/backups/.env"] [unique_id "aqxZ-wpXMN3p_zkwXf2ylwAAALg"]
[Thu Sep 17 15:22:03.421034 2026] [security2:error] [pid 1012520:tid 1012681] [client 52.231.79.181:1606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/wp-signup.php"] [unique_id "aqxZ-wpXMN3p_zkwXf2ymAAAAKM"]
[Thu Sep 17 15:22:03.467579 2026] [security2:error] [pid 1012520:tid 1012709] [client 140.238.42.111:54232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ-wpXMN3p_zkwXf2ymwAAAL8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:03.518855 2026] [security2:error] [pid 1012520:tid 1012746] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/old/.env"] [unique_id "aqxZ-wpXMN3p_zkwXf2yngAAAOQ"]
[Thu Sep 17 15:22:03.688962 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/tmp/.env"] [unique_id "aqxZ-wpXMN3p_zkwXf2yoAAAAJE"]
[Thu Sep 17 15:22:03.820731 2026] [security2:error] [pid 1012520:tid 1012680] [client 52.231.79.181:1654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/doc.php"] [unique_id "aqxZ-wpXMN3p_zkwXf2yogAAAKI"]
[Thu Sep 17 15:22:03.871842 2026] [security2:error] [pid 1012520:tid 1012705] [client 140.238.42.111:54559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ-wpXMN3p_zkwXf2yowAAALs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:03.873311 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/temp/.env"] [unique_id "aqxZ-wpXMN3p_zkwXf2ypAAAAOI"]
[Thu Sep 17 15:22:04.043639 2026] [security2:error] [pid 1012520:tid 1012753] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/lab/.env"] [unique_id "aqxZ_ApXMN3p_zkwXf2yqQAAAOs"]
[Thu Sep 17 15:22:04.124066 2026] [security2:error] [pid 1012520:tid 1012699] [client 172.245.178.126:45286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.joeledmundanderson.com"] [uri "/wp-content/plugins/broken-link-checker/readme.txt"] [unique_id "aqxZ_ApXMN3p_zkwXf2yqwAAALU"]
[Thu Sep 17 15:22:04.213581 2026] [security2:error] [pid 1012520:tid 1012748] [client 156.192.234.52:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ_ApXMN3p_zkwXf2yrQAAAOY"]
[Thu Sep 17 15:22:04.216496 2026] [security2:error] [pid 1012520:tid 1012748] [client 156.192.234.52:51704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxZ_ApXMN3p_zkwXf2yrQAAAOY"]
[Thu Sep 17 15:22:04.223208 2026] [security2:error] [pid 1012520:tid 1012720] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cronlab/.env"] [unique_id "aqxZ_ApXMN3p_zkwXf2yrgAAAMo"]
[Thu Sep 17 15:22:04.230245 2026] [security2:error] [pid 1012520:tid 1012733] [client 52.231.79.181:1655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/edit.php"] [unique_id "aqxZ_ApXMN3p_zkwXf2yrwAAANc"]
[Thu Sep 17 15:22:04.278568 2026] [security2:error] [pid 1012520:tid 1012750] [client 140.238.42.111:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ_ApXMN3p_zkwXf2ysAAAAOg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:04.400507 2026] [security2:error] [pid 1012520:tid 1012655] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cron/.env"] [unique_id "aqxZ_ApXMN3p_zkwXf2yswAAAIk"]
[Thu Sep 17 15:22:04.474217 2026] [security2:error] [pid 1012520:tid 1012670] [client 169.58.197.253:57673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxZ_ApXMN3p_zkwXf2ytwAAAJg"], referer: binance.com
[Thu Sep 17 15:22:04.519309 2026] [security2:error] [pid 1012520:tid 1012740] [client 114.119.141.73:35143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ivorygarlock.com"] [uri "/portfolio/niagara-grape-and-wine-festival-logo"] [unique_id "aqxZ_ApXMN3p_zkwXf2yuAAAAN4"], referer: https://ivorygarlock.com/work/
[Thu Sep 17 15:22:04.568239 2026] [security2:error] [pid 1012520:tid 1012658] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/en/.env"] [unique_id "aqxZ_ApXMN3p_zkwXf2yuQAAAIw"]
[Thu Sep 17 15:22:04.663585 2026] [security2:error] [pid 1012520:tid 1012713] [client 52.231.79.181:1648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/worksec.php"] [unique_id "aqxZ_ApXMN3p_zkwXf2yuwAAAMM"]
[Thu Sep 17 15:22:04.687758 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:55305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ_ApXMN3p_zkwXf2yvAAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:04.800690 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/administrator/.env"] [unique_id "aqxZ_ApXMN3p_zkwXf2yvgAAALc"]
[Thu Sep 17 15:22:04.960748 2026] [security2:error] [pid 1012520:tid 1012682] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/psnlink/.env"] [unique_id "aqxZ_ApXMN3p_zkwXf2ywgAAAKQ"]
[Thu Sep 17 15:22:05.066913 2026] [security2:error] [pid 1012520:tid 1012738] [client 52.231.79.181:1617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/ultra.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2yxgAAANw"]
[Thu Sep 17 15:22:05.090813 2026] [security2:error] [pid 1012520:tid 1012743] [client 140.238.42.111:55623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2yxwAAAOE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:05.128636 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/exapi/.env"] [unique_id "aqxZ_QpXMN3p_zkwXf2yyQAAANA"]
[Thu Sep 17 15:22:05.287122 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/sitemaps/.env"] [unique_id "aqxZ_QpXMN3p_zkwXf2yzQAAAKg"]
[Thu Sep 17 15:22:05.473774 2026] [security2:error] [pid 1012520:tid 1012667] [client 140.238.42.111:55997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2y1QAAAJU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:05.478624 2026] [security2:error] [pid 1012520:tid 1012735] [client 52.231.79.181:1612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/gecko.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2y1gAAANk"]
[Thu Sep 17 15:22:05.615102 2026] [security2:error] [pid 1012520:tid 1012756] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2y1wAAAO4"]
[Thu Sep 17 15:22:05.862494 2026] [security2:error] [pid 1012520:tid 1012717] [client 140.238.42.111:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2y4AAAAMc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:05.902618 2026] [security2:error] [pid 1012520:tid 1012775] [client 52.231.79.181:1484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/goods.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2y4wAAAQE"]
[Thu Sep 17 15:22:05.956514 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxZ_QpXMN3p_zkwXf2y4gAAAPE"]
[Thu Sep 17 15:22:06.136357 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/logs/.env"] [unique_id "aqxZ_gpXMN3p_zkwXf2y6AAAAL4"]
[Thu Sep 17 15:22:06.256230 2026] [security2:error] [pid 1012520:tid 1012662] [client 140.238.42.111:56707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ_gpXMN3p_zkwXf2y6QAAAJA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:06.299686 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cache/.env"] [unique_id "aqxZ_gpXMN3p_zkwXf2y6wAAAMk"]
[Thu Sep 17 15:22:06.339314 2026] [security2:error] [pid 1012520:tid 1012753] [client 52.231.79.181:1629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/man.php"] [unique_id "aqxZ_gpXMN3p_zkwXf2y7AAAAOs"]
[Thu Sep 17 15:22:06.463559 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mailer/.env"] [unique_id "aqxZ_gpXMN3p_zkwXf2y8AAAAPc"]
[Thu Sep 17 15:22:06.629578 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mail/.env"] [unique_id "aqxZ_gpXMN3p_zkwXf2y8wAAAN0"]
[Thu Sep 17 15:22:06.665694 2026] [security2:error] [pid 1012520:tid 1012688] [client 140.238.42.111:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ_gpXMN3p_zkwXf2y9wAAAKo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:06.755400 2026] [security2:error] [pid 1012520:tid 1012658] [client 52.231.79.181:1628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/wp-settings.php"] [unique_id "aqxZ_gpXMN3p_zkwXf2y-QAAAIw"]
[Thu Sep 17 15:22:06.798084 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/email/.env"] [unique_id "aqxZ_gpXMN3p_zkwXf2y-gAAAPQ"]
[Thu Sep 17 15:22:06.969558 2026] [security2:error] [pid 1012520:tid 1012694] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/smtp/.env"] [unique_id "aqxZ_gpXMN3p_zkwXf2y_gAAALA"]
[Thu Sep 17 15:22:07.051079 2026] [security2:error] [pid 1012520:tid 1012701] [client 140.238.42.111:57427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ_wpXMN3p_zkwXf2zAAAAALc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:07.105292 2026] [security2:error] [pid 1012520:tid 1012665] [client 185.117.225.52:56202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "mail.ppfc.net"] [uri "/robots.txt"] [unique_id "aqxZ_wpXMN3p_zkwXf2zAQAAAJM"]
[Thu Sep 17 15:22:07.130001 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mailing/.env"] [unique_id "aqxZ_wpXMN3p_zkwXf2zAwAAAOE"]
[Thu Sep 17 15:22:07.153711 2026] [security2:error] [pid 1012520:tid 1012682] [client 52.231.79.181:1630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/k.php"] [unique_id "aqxZ_wpXMN3p_zkwXf2zBAAAAKQ"]
[Thu Sep 17 15:22:07.293733 2026] [security2:error] [pid 1012520:tid 1012727] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/notifications/.env"] [unique_id "aqxZ_wpXMN3p_zkwXf2zCgAAANE"]
[Thu Sep 17 15:22:07.444694 2026] [security2:error] [pid 1012520:tid 1012725] [client 140.238.42.111:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxZ_wpXMN3p_zkwXf2zDgAAAM8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:07.450293 2026] [security2:error] [pid 1012520:tid 1012675] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/notify/.env"] [unique_id "aqxZ_wpXMN3p_zkwXf2zDwAAAJ0"]
[Thu Sep 17 15:22:07.566210 2026] [security2:error] [pid 1012520:tid 1012667] [client 52.231.79.181:1626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/autoload_classmap.php"] [unique_id "aqxZ_wpXMN3p_zkwXf2zFwAAAJU"]
[Thu Sep 17 15:22:07.609189 2026] [security2:error] [pid 1012520:tid 1012723] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/sender/.env"] [unique_id "aqxZ_wpXMN3p_zkwXf2zGQAAAM0"]
[Thu Sep 17 15:22:07.770874 2026] [security2:error] [pid 1012520:tid 1012767] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/campaign/.env"] [unique_id "aqxZ_wpXMN3p_zkwXf2zHAAAAPk"]
[Thu Sep 17 15:22:07.822372 2026] [security2:error] [pid 1012520:tid 1012772] [client 140.238.42.111:58061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxZ_wpXMN3p_zkwXf2zHwAAAP4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:07.929923 2026] [security2:error] [pid 1012520:tid 1012732] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/newsletter/.env"] [unique_id "aqxZ_wpXMN3p_zkwXf2zIwAAANY"]
[Thu Sep 17 15:22:07.972556 2026] [security2:error] [pid 1012520:tid 1012746] [client 52.231.79.181:1482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/profile.php"] [unique_id "aqxZ_wpXMN3p_zkwXf2zJwAAAOQ"]
[Thu Sep 17 15:22:08.021110 2026] [security2:error] [pid 1012520:tid 1012663] [client 162.241.226.11:15940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ppfc.net"] [uri "/wp-content/uploads/2014/11/cropped-Youth-soccer-indiana1.jpg"] [unique_id "aqxZ_wpXMN3p_zkwXf2zJgAAAJE"]
[Thu Sep 17 15:22:08.092991 2026] [security2:error] [pid 1012520:tid 1012698] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/ses/.env"] [unique_id "aqxaAApXMN3p_zkwXf2zKQAAALQ"]
[Thu Sep 17 15:22:08.225286 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:58366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaAApXMN3p_zkwXf2zKwAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:08.251717 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/sendgrid/.env"] [unique_id "aqxaAApXMN3p_zkwXf2zLQAAANM"]
[Thu Sep 17 15:22:08.271431 2026] [security2:error] [pid 1012520:tid 1012662] [client 162.241.226.11:15946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ppfc.net"] [uri "/wp-content/uploads/2014/11/cropped-Youth-soccer-indiana1.jpg"] [unique_id "aqxaAApXMN3p_zkwXf2zLAAAAIo"]
[Thu Sep 17 15:22:08.333291 2026] [security2:error] [pid 1012520:tid 1012660] [client 162.241.226.11:15954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ppfc.net"] [uri "/wp-content/uploads/2014/11/maxresdefault.jpg"] [unique_id "aqxaAApXMN3p_zkwXf2zLgAAAMk"]
[Thu Sep 17 15:22:08.366228 2026] [security2:error] [pid 1012520:tid 1012687] [client 162.241.226.11:15970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ppfc.net"] [uri "/wp-content/uploads/2014/11/maxresdefault.jpg"] [unique_id "aqxaAApXMN3p_zkwXf2zLwAAAKw"]
[Thu Sep 17 15:22:08.398196 2026] [security2:error] [pid 1012520:tid 1012708] [client 52.231.79.181:1473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/server.php"] [unique_id "aqxaAApXMN3p_zkwXf2zMgAAAL4"]
[Thu Sep 17 15:22:08.414595 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/sparkpost/.env"] [unique_id "aqxaAApXMN3p_zkwXf2zMwAAAPc"]
[Thu Sep 17 15:22:08.586281 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/postmark/.env"] [unique_id "aqxaAApXMN3p_zkwXf2zOAAAAKo"]
[Thu Sep 17 15:22:08.623363 2026] [security2:error] [pid 1012520:tid 1012739] [client 140.238.42.111:58713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaAApXMN3p_zkwXf2zOwAAAN0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:08.756261 2026] [security2:error] [pid 1012520:tid 1012762] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mailgun/.env"] [unique_id "aqxaAApXMN3p_zkwXf2zPQAAAPQ"]
[Thu Sep 17 15:22:08.819696 2026] [security2:error] [pid 1012520:tid 1012658] [client 52.231.79.181:1506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/shell.php"] [unique_id "aqxaAApXMN3p_zkwXf2zPgAAAIw"]
[Thu Sep 17 15:22:08.928827 2026] [security2:error] [pid 1012520:tid 1012706] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mandrill/.env"] [unique_id "aqxaAApXMN3p_zkwXf2zQAAAALw"]
[Thu Sep 17 15:22:08.986419 2026] [security2:error] [pid 1012520:tid 1012750] [client 186.105.232.15:53147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaAApXMN3p_zkwXf2zQwAAAOg"]
[Thu Sep 17 15:22:08.986616 2026] [security2:error] [pid 1012520:tid 1012750] [client 186.105.232.15:53147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaAApXMN3p_zkwXf2zQwAAAOg"]
[Thu Sep 17 15:22:09.040799 2026] [security2:error] [pid 1012520:tid 1012743] [client 140.238.42.111:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaAQpXMN3p_zkwXf2zRQAAAOE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:09.089156 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mailjet/.env"] [unique_id "aqxaAQpXMN3p_zkwXf2zSAAAAMQ"]
[Thu Sep 17 15:22:09.249167 2026] [security2:error] [pid 1012520:tid 1012742] [client 52.231.79.181:1511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/t.php"] [unique_id "aqxaAQpXMN3p_zkwXf2zSwAAAOA"]
[Thu Sep 17 15:22:09.254728 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.220.137.122:40594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/brevo/.env"] [unique_id "aqxaAQpXMN3p_zkwXf2zTAAAAOw"]
[Thu Sep 17 15:22:09.421172 2026] [security2:error] [pid 1012520:tid 1012776] [client 140.238.42.111:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaAQpXMN3p_zkwXf2zUAAAAQI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:09.672948 2026] [security2:error] [pid 1012520:tid 1012771] [client 52.231.79.181:2025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifenorthshorema.sportsgirlkat.com"] [uri "/hello.php"] [unique_id "aqxaAQpXMN3p_zkwXf2zXgAAAP0"]
[Thu Sep 17 15:22:09.821023 2026] [security2:error] [pid 1012520:tid 1012778] [client 140.238.42.111:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaAQpXMN3p_zkwXf2zZAAAAQQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:09.826985 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/transactional/.env"] [unique_id "aqxaAQpXMN3p_zkwXf2zZQAAANo"]
[Thu Sep 17 15:22:09.989342 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/bulk/.env"] [unique_id "aqxaAQpXMN3p_zkwXf2zbwAAANM"]
[Thu Sep 17 15:22:10.153894 2026] [security2:error] [pid 1012520:tid 1012719] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/aws/.env"] [unique_id "aqxaAgpXMN3p_zkwXf2zdAAAAMk"]
[Thu Sep 17 15:22:10.217892 2026] [security2:error] [pid 1012520:tid 1012722] [client 140.238.42.111:60045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaAgpXMN3p_zkwXf2zdgAAAMw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:10.313412 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/azure/.env"] [unique_id "aqxaAgpXMN3p_zkwXf2zeQAAAPo"]
[Thu Sep 17 15:22:10.482831 2026] [security2:error] [pid 1012520:tid 1012708] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/gcp/.env"] [unique_id "aqxaAgpXMN3p_zkwXf2zfgAAAL4"]
[Thu Sep 17 15:22:10.608620 2026] [security2:error] [pid 1012520:tid 1012765] [client 140.238.42.111:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaAgpXMN3p_zkwXf2zgwAAAPc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:10.646373 2026] [security2:error] [pid 1012520:tid 1012679] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cloud/.env"] [unique_id "aqxaAgpXMN3p_zkwXf2zhQAAAKE"]
[Thu Sep 17 15:22:10.808672 2026] [security2:error] [pid 1012520:tid 1012711] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/infrastructure/.env"] [unique_id "aqxaAgpXMN3p_zkwXf2ziAAAAME"]
[Thu Sep 17 15:22:10.974112 2026] [security2:error] [pid 1012520:tid 1012726] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/docker/.env"] [unique_id "aqxaAgpXMN3p_zkwXf2zjwAAANA"]
[Thu Sep 17 15:22:11.021534 2026] [security2:error] [pid 1012520:tid 1012658] [client 140.238.42.111:60708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaAwpXMN3p_zkwXf2zkgAAAIw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:11.064072 2026] [security2:error] [pid 1012520:tid 1012715] [client 154.190.208.131:41865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaAwpXMN3p_zkwXf2zlAAAAMU"]
[Thu Sep 17 15:22:11.064296 2026] [security2:error] [pid 1012520:tid 1012715] [client 154.190.208.131:41865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaAwpXMN3p_zkwXf2zlAAAAMU"]
[Thu Sep 17 15:22:11.138622 2026] [security2:error] [pid 1012520:tid 1012707] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/k8s/.env"] [unique_id "aqxaAwpXMN3p_zkwXf2zlQAAAL0"]
[Thu Sep 17 15:22:11.297160 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/kubernetes/.env"] [unique_id "aqxaAwpXMN3p_zkwXf2znAAAAJw"]
[Thu Sep 17 15:22:11.338570 2026] [security2:error] [pid 1012520:tid 1012670] [client 185.117.225.52:56844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "mail.ppfc.net"] [uri "/robots.txt"] [unique_id "aqxaAwpXMN3p_zkwXf2znQAAAJg"]
[Thu Sep 17 15:22:11.427523 2026] [security2:error] [pid 1012520:tid 1012669] [client 140.238.42.111:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaAwpXMN3p_zkwXf2znwAAAJc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:11.457611 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/terraform/.env"] [unique_id "aqxaAwpXMN3p_zkwXf2zowAAAOA"]
[Thu Sep 17 15:22:11.616374 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/ansible/.env"] [unique_id "aqxaAwpXMN3p_zkwXf2zpgAAAJQ"]
[Thu Sep 17 15:22:11.777611 2026] [security2:error] [pid 1012520:tid 1012681] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/.git/.env"] [unique_id "aqxaAwpXMN3p_zkwXf2zqwAAAKM"]
[Thu Sep 17 15:22:11.830466 2026] [security2:error] [pid 1012520:tid 1012766] [client 140.238.42.111:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaAwpXMN3p_zkwXf2zsgAAAPg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:11.935808 2026] [security2:error] [pid 1012520:tid 1012774] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/ci/.env"] [unique_id "aqxaAwpXMN3p_zkwXf2ztgAAAQA"]
[Thu Sep 17 15:22:11.959718 2026] [security2:error] [pid 1012520:tid 1012693] [client 73.237.172.140:64114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaAwpXMN3p_zkwXf2zsQAAr1w"], referer: https://endless-chronicles.com/
[Thu Sep 17 15:22:12.104053 2026] [security2:error] [pid 1012520:tid 1012703] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cd/.env"] [unique_id "aqxaBApXMN3p_zkwXf2zuAAAALk"]
[Thu Sep 17 15:22:12.231364 2026] [security2:error] [pid 1012520:tid 1012663] [client 140.238.42.111:61814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaBApXMN3p_zkwXf2zuwAAAJE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:12.264610 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/jenkins/.env"] [unique_id "aqxaBApXMN3p_zkwXf2zvgAAAJI"]
[Thu Sep 17 15:22:12.402865 2026] [core:error] [pid 1012520:tid 1012775] [client 130.210.56.65:40926] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:22:12.402890 2026] [core:error] [pid 1012520:tid 1012775] [client 130.210.56.65:40926] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:22:12.420726 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/gitlab/.env"] [unique_id "aqxaBApXMN3p_zkwXf2zwgAAANM"]
[Thu Sep 17 15:22:12.578693 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/github/.env"] [unique_id "aqxaBApXMN3p_zkwXf2zxwAAAJ8"]
[Thu Sep 17 15:22:12.619388 2026] [security2:error] [pid 1012520:tid 1012660] [client 140.238.42.111:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaBApXMN3p_zkwXf2zyQAAAI4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:12.684816 2026] [security2:error] [pid 1012520:tid 1012698] [client 103.61.184.148:49643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaBApXMN3p_zkwXf2zygAAALQ"]
[Thu Sep 17 15:22:12.684906 2026] [security2:error] [pid 1012520:tid 1012698] [client 103.61.184.148:49643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaBApXMN3p_zkwXf2zygAAALQ"]
[Thu Sep 17 15:22:12.736611 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/actions/.env"] [unique_id "aqxaBApXMN3p_zkwXf2zywAAAI0"]
[Thu Sep 17 15:22:12.856986 2026] [security2:error] [pid 1012520:tid 1012671] [client 114.198.138.124:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaBApXMN3p_zkwXf2zzAAAAJk"]
[Thu Sep 17 15:22:12.857126 2026] [security2:error] [pid 1012520:tid 1012671] [client 114.198.138.124:60608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaBApXMN3p_zkwXf2zzAAAAJk"]
[Thu Sep 17 15:22:12.903623 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/circleci/.env"] [unique_id "aqxaBApXMN3p_zkwXf2zzgAAAKo"]
[Thu Sep 17 15:22:12.973995 2026] [security2:error] [pid 1012520:tid 1012668] [client 169.58.197.253:58237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxaBApXMN3p_zkwXf2z0gAAAJY"], referer: binance.com
[Thu Sep 17 15:22:13.001215 2026] [security2:error] [pid 1012520:tid 1012655] [client 140.238.42.111:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaBQpXMN3p_zkwXf2z1AAAAIk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:13.060720 2026] [security2:error] [pid 1012520:tid 1012755] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/travis/.env"] [unique_id "aqxaBQpXMN3p_zkwXf2z1gAAAO0"]
[Thu Sep 17 15:22:13.250344 2026] [security2:error] [pid 1012520:tid 1012739] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/buildkite/.env"] [unique_id "aqxaBQpXMN3p_zkwXf2z2AAAAN0"]
[Thu Sep 17 15:22:13.405361 2026] [security2:error] [pid 1012520:tid 1012743] [client 140.238.42.111:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaBQpXMN3p_zkwXf2z4QAAAOE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:13.409758 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mysql/.env"] [unique_id "aqxaBQpXMN3p_zkwXf2z4gAAAOg"]
[Thu Sep 17 15:22:13.580708 2026] [security2:error] [pid 1012520:tid 1012759] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/postgres/.env"] [unique_id "aqxaBQpXMN3p_zkwXf2z6gAAAPE"]
[Thu Sep 17 15:22:13.741490 2026] [security2:error] [pid 1012520:tid 1012749] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mongodb/.env"] [unique_id "aqxaBQpXMN3p_zkwXf2z8wAAAOc"]
[Thu Sep 17 15:22:13.754596 2026] [security2:error] [pid 1012520:tid 1012727] [client 185.55.149.49:62257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaBQpXMN3p_zkwXf2z9AAAANE"]
[Thu Sep 17 15:22:13.754711 2026] [security2:error] [pid 1012520:tid 1012727] [client 185.55.149.49:62257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaBQpXMN3p_zkwXf2z9AAAANE"]
[Thu Sep 17 15:22:13.792386 2026] [security2:error] [pid 1012520:tid 1012674] [client 140.238.42.111:63137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaBQpXMN3p_zkwXf2z9gAAAJw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:13.800432 2026] [security2:error] [pid 1012520:tid 1012665] [client 130.210.56.65:40930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "cpcontacts.jvrockworks.com"] [uri "/"] [unique_id "aqxaBQpXMN3p_zkwXf2z9wAAAJM"]
[Thu Sep 17 15:22:13.903920 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/redis/.env"] [unique_id "aqxaBQpXMN3p_zkwXf2z-gAAAM8"]
[Thu Sep 17 15:22:14.065596 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/elasticsearch/.env"] [unique_id "aqxaBgpXMN3p_zkwXf20AQAAAO8"]
[Thu Sep 17 15:22:14.192467 2026] [security2:error] [pid 1012520:tid 1012681] [client 140.238.42.111:63459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaBgpXMN3p_zkwXf20AwAAAKM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:14.228916 2026] [security2:error] [pid 1012520:tid 1012709] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/rabbitmq/.env"] [unique_id "aqxaBgpXMN3p_zkwXf20BAAAAL8"]
[Thu Sep 17 15:22:14.393001 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/kafka/.env"] [unique_id "aqxaBgpXMN3p_zkwXf20BgAAAMc"]
[Thu Sep 17 15:22:14.573279 2026] [security2:error] [pid 1012520:tid 1012713] [client 140.238.42.111:63767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaBgpXMN3p_zkwXf20CwAAAMM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:14.577658 2026] [security2:error] [pid 1012520:tid 1012683] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/queue/.env"] [unique_id "aqxaBgpXMN3p_zkwXf20DAAAAKU"]
[Thu Sep 17 15:22:14.736299 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/worker/.env"] [unique_id "aqxaBgpXMN3p_zkwXf20DgAAAOI"]
[Thu Sep 17 15:22:14.834443 2026] [security2:error] [pid 1012520:tid 1012718] [client 156.192.234.52:52347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaBgpXMN3p_zkwXf20EgAAAMg"]
[Thu Sep 17 15:22:14.835854 2026] [security2:error] [pid 1012520:tid 1012718] [client 156.192.234.52:52347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaBgpXMN3p_zkwXf20EgAAAMg"]
[Thu Sep 17 15:22:14.902886 2026] [security2:error] [pid 1012520:tid 1012677] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/job/.env"] [unique_id "aqxaBgpXMN3p_zkwXf20EwAAAJ8"]
[Thu Sep 17 15:22:14.906239 2026] [security2:error] [pid 1012520:tid 1012651] [client 93.16.234.69:58952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaBgpXMN3p_zkwXf20EAAAhWg"]
[Thu Sep 17 15:22:14.955619 2026] [security2:error] [pid 1012520:tid 1012775] [client 140.238.42.111:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaBgpXMN3p_zkwXf20GAAAAQE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:15.063783 2026] [security2:error] [pid 1012520:tid 1012758] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/test/.env"] [unique_id "aqxaBwpXMN3p_zkwXf20HAAAAPA"]
[Thu Sep 17 15:22:15.226901 2026] [security2:error] [pid 1012520:tid 1012747] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/qa/.env"] [unique_id "aqxaBwpXMN3p_zkwXf20IAAAAOU"]
[Thu Sep 17 15:22:15.340429 2026] [security2:error] [pid 1012520:tid 1012755] [client 140.238.42.111:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaBwpXMN3p_zkwXf20IgAAAO0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:15.384598 2026] [security2:error] [pid 1012520:tid 1012701] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/preview/.env"] [unique_id "aqxaBwpXMN3p_zkwXf20JAAAALc"]
[Thu Sep 17 15:22:15.543522 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/beta/.env"] [unique_id "aqxaBwpXMN3p_zkwXf20KgAAAOg"]
[Thu Sep 17 15:22:15.594810 2026] [security2:error] [pid 1012520:tid 1012760] [client 192.178.15.65:62994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "espiral.com.mx"] [uri "/index.php"] [unique_id "aqxaAgpXMN3p_zkwXf2ziQAAAPI"]
[Thu Sep 17 15:22:15.704178 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/uat/.env"] [unique_id "aqxaBwpXMN3p_zkwXf20MQAAAJc"]
[Thu Sep 17 15:22:15.726607 2026] [security2:error] [pid 1012520:tid 1012661] [client 140.238.42.111:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaBwpXMN3p_zkwXf20MwAAAI8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:15.730975 2026] [core:error] [pid 1012520:tid 1012714] [client 91.92.34.66:56570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:22:15.730997 2026] [core:error] [pid 1012520:tid 1012714] [client 91.92.34.66:56570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:22:15.872541 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/stage/.env"] [unique_id "aqxaBwpXMN3p_zkwXf20QAAAAPg"]
[Thu Sep 17 15:22:15.959436 2026] [security2:error] [pid 1012520:tid 1012757] [client 129.159.56.14:42130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.godancedurhamcom.cow.jso.mybluehost.me"] [uri "/.env"] [unique_id "aqxaBwpXMN3p_zkwXf20RAAAAO8"]
[Thu Sep 17 15:22:16.046721 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/development/.env"] [unique_id "aqxaCApXMN3p_zkwXf20RgAAALY"]
[Thu Sep 17 15:22:16.115077 2026] [security2:error] [pid 1012520:tid 1012666] [client 140.238.42.111:65040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaCApXMN3p_zkwXf20TQAAAJQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:16.209796 2026] [security2:error] [pid 1012520:tid 1012717] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/production/.env"] [unique_id "aqxaCApXMN3p_zkwXf20XQAAAMc"]
[Thu Sep 17 15:22:16.382080 2026] [security2:error] [pid 1012520:tid 1012673] [client 35.220.137.122:60234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/config/app/.env"] [unique_id "aqxaCApXMN3p_zkwXf20YAAAAJs"]
[Thu Sep 17 15:22:16.500821 2026] [security2:error] [pid 1012520:tid 1012664] [client 140.238.42.111:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaCApXMN3p_zkwXf20ZwAAAJI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:16.553836 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.220.137.122:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/phpinfo.php"] [unique_id "aqxaCApXMN3p_zkwXf20aAAAAJo"]
[Thu Sep 17 15:22:16.615057 2026] [security2:error] [pid 1012520:tid 1012680] [client 91.92.34.66:56937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.34.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goldroadholdings.com"] [uri "/wp-login.php"] [unique_id "aqxaCApXMN3p_zkwXf20agAAAKI"]
[Thu Sep 17 15:22:16.802891 2026] [security2:error] [pid 1012520:tid 1012736] [client 195.139.118.177:37274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaCApXMN3p_zkwXf20bAAA2iI"]
[Thu Sep 17 15:22:16.893631 2026] [security2:error] [pid 1012520:tid 1012753] [client 140.238.42.111:49281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaCApXMN3p_zkwXf20cAAAAOs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:17.027418 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.220.137.122:60250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/info.php"] [unique_id "aqxaCQpXMN3p_zkwXf20eQAAAPw"]
[Thu Sep 17 15:22:17.273616 2026] [security2:error] [pid 1012520:tid 1012778] [client 140.238.42.111:49597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaCQpXMN3p_zkwXf20fgAAAQQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:17.496822 2026] [security2:error] [pid 1012520:tid 1012686] [client 4.240.114.86:50065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-login.php"] [unique_id "aqxaCQpXMN3p_zkwXf20hgAAAKg"], referer: binance.com
[Thu Sep 17 15:22:17.513290 2026] [security2:error] [pid 1012520:tid 1012750] [client 35.220.137.122:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/php.php"] [unique_id "aqxaCQpXMN3p_zkwXf20iwAAAOg"]
[Thu Sep 17 15:22:17.643671 2026] [security2:error] [pid 1012520:tid 1012712] [client 91.92.34.66:57331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.34.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goldroadholdings.com"] [uri "/xmlrpc.php"] [unique_id "aqxaCQpXMN3p_zkwXf20kAAAAMI"]
[Thu Sep 17 15:22:17.650190 2026] [security2:error] [pid 1012520:tid 1012691] [client 140.238.42.111:49878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaCQpXMN3p_zkwXf20kQAAAK0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:17.894493 2026] [security2:error] [pid 1012520:tid 1012762] [client 57.141.14.40:30342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxaCQpXMN3p_zkwXf20kgAA9Dc"]
[Thu Sep 17 15:22:18.010705 2026] [security2:error] [pid 1012520:tid 1012653] [client 35.220.137.122:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/i.php"] [unique_id "aqxaCgpXMN3p_zkwXf20mQAAAIc"]
[Thu Sep 17 15:22:18.029970 2026] [security2:error] [pid 1012520:tid 1012766] [client 140.238.42.111:50176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaCgpXMN3p_zkwXf20mgAAAPg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:18.427405 2026] [security2:error] [pid 1012520:tid 1012717] [client 140.238.42.111:50455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaCgpXMN3p_zkwXf20oQAAAMc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:18.504211 2026] [security2:error] [pid 1012520:tid 1012754] [client 35.220.137.122:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/pi.php"] [unique_id "aqxaCgpXMN3p_zkwXf20pwAAAOw"]
[Thu Sep 17 15:22:18.813741 2026] [security2:error] [pid 1012520:tid 1012664] [client 140.238.42.111:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaCgpXMN3p_zkwXf20rAAAAJI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:19.018774 2026] [security2:error] [pid 1012520:tid 1012728] [client 35.220.137.122:49480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/pinfo.php"] [unique_id "aqxaCwpXMN3p_zkwXf20tAAAANI"]
[Thu Sep 17 15:22:19.223432 2026] [security2:error] [pid 1012520:tid 1012768] [client 140.238.42.111:51029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaCwpXMN3p_zkwXf20uQAAAPo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:19.424635 2026] [security2:error] [pid 1012520:tid 1012655] [client 114.119.150.228:64327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.appalachian-landscapes.com"] [uri "/portfolio-item/outdoor-living-spaces"] [unique_id "aqxaCwpXMN3p_zkwXf20uwAAAIk"], referer: http://www.appalachian-landscapes.com/portfolio-item/outdoor-living-spaces
[Thu Sep 17 15:22:19.510968 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.220.137.122:49492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/test.php"] [unique_id "aqxaCwpXMN3p_zkwXf20wQAAAJY"]
[Thu Sep 17 15:22:19.615598 2026] [security2:error] [pid 1012520:tid 1012747] [client 140.238.42.111:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaCwpXMN3p_zkwXf20wwAAAOU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:19.922565 2026] [security2:error] [pid 1012520:tid 1012729] [client 181.121.98.215:37058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "frenchtutoringfun.com"] [uri "/index.php"] [unique_id "aqxaCApXMN3p_zkwXf20aQAA0wY"]
[Thu Sep 17 15:22:19.966339 2026] [security2:error] [pid 1012520:tid 1012712] [client 169.58.197.253:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxaCwpXMN3p_zkwXf20zgAAAMI"], referer: binance.com
[Thu Sep 17 15:22:20.025728 2026] [security2:error] [pid 1012520:tid 1012726] [client 140.238.42.111:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaDApXMN3p_zkwXf200wAAANA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:20.157529 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaDApXMN3p_zkwXf201QAAAOo"]
[Thu Sep 17 15:22:20.328885 2026] [security2:error] [pid 1012520:tid 1012766] [client 35.220.137.122:49494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/p.php"] [unique_id "aqxaDApXMN3p_zkwXf202AAAAPg"]
[Thu Sep 17 15:22:20.420309 2026] [security2:error] [pid 1012520:tid 1012759] [client 140.238.42.111:51926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaDApXMN3p_zkwXf202QAAAPE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:20.832963 2026] [security2:error] [pid 1012520:tid 1012756] [client 140.238.42.111:52295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaDApXMN3p_zkwXf204gAAAO4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:20.862106 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.220.137.122:49498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/debug.php"] [unique_id "aqxaDApXMN3p_zkwXf204wAAAJQ"]
[Thu Sep 17 15:22:21.016621 2026] [security2:error] [pid 1012520:tid 1012718] [client 93.152.209.7:4000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.com"] [uri "/.env"] [unique_id "aqxaDQpXMN3p_zkwXf205wAAAMg"]
[Thu Sep 17 15:22:21.192282 2026] [security2:error] [pid 1012520:tid 1012589] [remote 93.152.209.7:27624] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.com"] [uri "/.env"] [unique_id "aqxaDQpXMN3p_zkwXf207AAA60M"]
[Thu Sep 17 15:22:21.230927 2026] [security2:error] [pid 1012520:tid 1012768] [client 93.152.209.7:4008] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.org"] [uri "/.env"] [unique_id "aqxaDQpXMN3p_zkwXf207gAAAPo"]
[Thu Sep 17 15:22:21.232463 2026] [security2:error] [pid 1012520:tid 1012680] [client 140.238.42.111:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaDQpXMN3p_zkwXf207wAAAKI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:21.327471 2026] [security2:error] [pid 1012520:tid 1012673] [client 186.105.232.15:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDQpXMN3p_zkwXf208gAAAJs"]
[Thu Sep 17 15:22:21.327673 2026] [security2:error] [pid 1012520:tid 1012673] [client 186.105.232.15:53799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDQpXMN3p_zkwXf208gAAAJs"]
[Thu Sep 17 15:22:21.366839 2026] [security2:error] [pid 1012520:tid 1012770] [client 35.220.137.122:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxaDQpXMN3p_zkwXf208wAAAPw"]
[Thu Sep 17 15:22:21.394868 2026] [security2:error] [pid 1012520:tid 1012728] [client 104.64.210.10:64914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jamescarmody.com"] [uri "/"] [unique_id "aqxaDQpXMN3p_zkwXf209AAAANI"]
[Thu Sep 17 15:22:21.404443 2026] [security2:error] [pid 1012520:tid 1012628] [remote 93.152.209.7:27640] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "breathingboxing.org"] [uri "/.env"] [unique_id "aqxaDQpXMN3p_zkwXf209gAA8Go"]
[Thu Sep 17 15:22:21.496130 2026] [security2:error] [pid 1012520:tid 1012662] [client 49.13.134.145:27692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxaDQpXMN3p_zkwXf208QAAAJA"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:22:21.629446 2026] [security2:error] [pid 1012520:tid 1012747] [client 140.238.42.111:53055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaDQpXMN3p_zkwXf20_QAAAOU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:21.635034 2026] [security2:error] [pid 1012520:tid 1012659] [client 154.190.208.131:42469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDQpXMN3p_zkwXf20_gAAAI0"]
[Thu Sep 17 15:22:21.640327 2026] [security2:error] [pid 1012520:tid 1012659] [client 154.190.208.131:42469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDQpXMN3p_zkwXf20_gAAAI0"]
[Thu Sep 17 15:22:21.814352 2026] [security2:error] [pid 1012520:tid 1012705] [client 162.241.226.11:26536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxaDQpXMN3p_zkwXf20_wAAALs"]
[Thu Sep 17 15:22:21.882847 2026] [security2:error] [pid 1012520:tid 1012729] [client 35.220.137.122:49512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/test/phpinfo.php"] [unique_id "aqxaDQpXMN3p_zkwXf21BAAAANM"]
[Thu Sep 17 15:22:22.007778 2026] [security2:error] [pid 1012520:tid 1012755] [client 162.241.226.11:26548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxaDQpXMN3p_zkwXf21AgAAAO0"]
[Thu Sep 17 15:22:22.030949 2026] [security2:error] [pid 1012520:tid 1012739] [client 140.238.42.111:53366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaDgpXMN3p_zkwXf21DQAAAN0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:22.129136 2026] [security2:error] [pid 1012520:tid 1012712] [client 49.13.134.145:27704] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxaDQpXMN3p_zkwXf21CgAAAMI"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:22:22.368347 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.220.137.122:49518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxaDgpXMN3p_zkwXf21FQAAALY"]
[Thu Sep 17 15:22:22.412301 2026] [security2:error] [pid 1012520:tid 1012773] [client 140.238.42.111:53687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaDgpXMN3p_zkwXf21FgAAAP8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:22.707700 2026] [security2:error] [pid 1012520:tid 1012754] [client 162.241.226.11:20870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.counsellingincambridge.ca"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxaDgpXMN3p_zkwXf21HAAAAOw"]
[Thu Sep 17 15:22:22.813244 2026] [security2:error] [pid 1012520:tid 1012699] [client 140.238.42.111:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaDgpXMN3p_zkwXf21HwAAALU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:22.865744 2026] [security2:error] [pid 1012520:tid 1012695] [client 35.220.137.122:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/old/phpinfo.php"] [unique_id "aqxaDgpXMN3p_zkwXf21IQAAALE"]
[Thu Sep 17 15:22:23.215623 2026] [security2:error] [pid 1012520:tid 1012768] [client 140.238.42.111:54383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaDwpXMN3p_zkwXf21JgAAAPo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:23.343788 2026] [security2:error] [pid 1012520:tid 1012677] [client 103.61.184.148:50195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDwpXMN3p_zkwXf21KQAAAJ8"]
[Thu Sep 17 15:22:23.343917 2026] [security2:error] [pid 1012520:tid 1012677] [client 103.61.184.148:50195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDwpXMN3p_zkwXf21KQAAAJ8"]
[Thu Sep 17 15:22:23.360279 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.220.137.122:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaDwpXMN3p_zkwXf21KgAAAOI"]
[Thu Sep 17 15:22:23.453030 2026] [security2:error] [pid 1012520:tid 1012707] [client 114.198.138.124:61343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDwpXMN3p_zkwXf21KwAAAL0"]
[Thu Sep 17 15:22:23.453378 2026] [security2:error] [pid 1012520:tid 1012707] [client 114.198.138.124:61343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaDwpXMN3p_zkwXf21KwAAAL0"]
[Thu Sep 17 15:22:23.586455 2026] [fcgid:warn] [pid 1012520:tid 1012720] (70014)End of file found: [client 152.32.235.107:36474] mod_fcgid: can't get data from http client
[Thu Sep 17 15:22:23.614218 2026] [security2:error] [pid 1012520:tid 1012719] [client 140.238.42.111:54717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaDwpXMN3p_zkwXf21MQAAAMk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:23.876645 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.220.137.122:49544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/public/phpinfo.php"] [unique_id "aqxaDwpXMN3p_zkwXf21OQAAAJE"]
[Thu Sep 17 15:22:23.999118 2026] [security2:error] [pid 1012520:tid 1012685] [client 140.238.42.111:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaDwpXMN3p_zkwXf21PQAAAKc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:24.409536 2026] [security2:error] [pid 1012520:tid 1012729] [client 140.238.42.111:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaEApXMN3p_zkwXf21RgAAANM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:24.495743 2026] [security2:error] [pid 1012520:tid 1012721] [client 185.55.149.49:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaEApXMN3p_zkwXf21SwAAAMs"]
[Thu Sep 17 15:22:24.495849 2026] [security2:error] [pid 1012520:tid 1012721] [client 185.55.149.49:53222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaEApXMN3p_zkwXf21SwAAAMs"]
[Thu Sep 17 15:22:24.500321 2026] [security2:error] [pid 1012520:tid 1012674] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaEApXMN3p_zkwXf21SQAAAJw"]
[Thu Sep 17 15:22:24.674140 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.220.137.122:49560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/php-info.php"] [unique_id "aqxaEApXMN3p_zkwXf21TQAAAN4"]
[Thu Sep 17 15:22:24.815388 2026] [security2:error] [pid 1012520:tid 1012761] [client 140.238.42.111:55813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaEApXMN3p_zkwXf21TwAAAPM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:25.162059 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.220.137.122:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/phpversion.php"] [unique_id "aqxaEQpXMN3p_zkwXf21VQAAALY"]
[Thu Sep 17 15:22:25.219283 2026] [security2:error] [pid 1012520:tid 1012732] [client 140.238.42.111:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaEQpXMN3p_zkwXf21VwAAANY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:25.408121 2026] [security2:error] [pid 1012520:tid 1012773] [client 156.192.234.52:52972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaEQpXMN3p_zkwXf21WgAAAP8"]
[Thu Sep 17 15:22:25.409437 2026] [security2:error] [pid 1012520:tid 1012773] [client 156.192.234.52:52972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaEQpXMN3p_zkwXf21WgAAAP8"]
[Thu Sep 17 15:22:25.446419 2026] [security2:error] [pid 1012520:tid 1012730] [client 216.73.217.36:47929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sd-yaranaturals.24eastyard.com"] [uri "/index.php/robots.txt"] [unique_id "aqxaCgpXMN3p_zkwXf20sgAA1Bg"]
[Thu Sep 17 15:22:25.613149 2026] [security2:error] [pid 1012520:tid 1012746] [client 140.238.42.111:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaEQpXMN3p_zkwXf21YQAAAOQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:25.655714 2026] [security2:error] [pid 1012520:tid 1012666] [client 35.220.137.122:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/_phpinfo.php"] [unique_id "aqxaEQpXMN3p_zkwXf21YwAAAJQ"]
[Thu Sep 17 15:22:25.861590 2026] [security2:error] [pid 1012520:tid 1012723] [client 216.73.217.36:47929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sd-yaranaturals.24eastyard.com"] [uri "/index.php/sitemap.xml"] [unique_id "aqxaEQpXMN3p_zkwXf21ZQAAzUU"]
[Thu Sep 17 15:22:25.873326 2026] [security2:error] [pid 1012520:tid 1012704] [client 162.241.226.11:20872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.counsellingincambridge.ca"] [uri "/wp-cron.php"] [unique_id "aqxaEQpXMN3p_zkwXf21ZgAAALo"]
[Thu Sep 17 15:22:26.000891 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:57021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaEgpXMN3p_zkwXf21bAAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:26.064185 2026] [security2:error] [pid 1012520:tid 1012758] [client 169.58.197.253:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxaEgpXMN3p_zkwXf21bgAAAPA"], referer: binance.com
[Thu Sep 17 15:22:26.145474 2026] [security2:error] [pid 1012520:tid 1012744] [client 35.220.137.122:49574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/old_phpinfo.php"] [unique_id "aqxaEgpXMN3p_zkwXf21cgAAAOI"]
[Thu Sep 17 15:22:26.398065 2026] [security2:error] [pid 1012520:tid 1012710] [client 140.238.42.111:57409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaEgpXMN3p_zkwXf21eQAAAMA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:26.645760 2026] [security2:error] [pid 1012520:tid 1012743] [client 35.220.137.122:49590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/server-info.php"] [unique_id "aqxaEgpXMN3p_zkwXf21gwAAAOE"]
[Thu Sep 17 15:22:26.793470 2026] [security2:error] [pid 1012520:tid 1012735] [client 140.238.42.111:57760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaEgpXMN3p_zkwXf21hwAAANk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:27.113907 2026] [security2:error] [pid 1012520:tid 1012745] [client 35.220.137.122:49606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/server-status.php"] [unique_id "aqxaEwpXMN3p_zkwXf21kwAAAOM"]
[Thu Sep 17 15:22:27.192778 2026] [security2:error] [pid 1012520:tid 1012674] [client 140.238.42.111:58083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaEwpXMN3p_zkwXf21lQAAAJw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:27.406317 2026] [security2:error] [pid 1012520:tid 1012703] [client 162.241.226.11:20888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.counsellingincambridge.ca"] [uri "/wp-cron.php"] [unique_id "aqxaEwpXMN3p_zkwXf21oQAAALk"]
[Thu Sep 17 15:22:27.594575 2026] [security2:error] [pid 1012520:tid 1012757] [client 140.238.42.111:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaEwpXMN3p_zkwXf21rQAAAO8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:27.871491 2026] [security2:error] [pid 1012520:tid 1012736] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaEwpXMN3p_zkwXf21tAAAANo"]
[Thu Sep 17 15:22:27.974768 2026] [security2:error] [pid 1012520:tid 1012719] [client 140.238.42.111:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaEwpXMN3p_zkwXf21xAAAAMk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:27.982703 2026] [security2:error] [pid 1012520:tid 1012668] [client 88.166.242.187:17410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaEwpXMN3p_zkwXf21vAAAlnM"]
[Thu Sep 17 15:22:28.211692 2026] [security2:error] [pid 1012520:tid 1012662] [client 35.220.137.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaFApXMN3p_zkwXf21ygAAAJA"]
[Thu Sep 17 15:22:28.304797 2026] [security2:error] [pid 1012520:tid 1012670] [client 138.68.136.141:36972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxaEwpXMN3p_zkwXf21uwAAmEE"], referer: http://kidsandlifeot.com/wordpress/
[Thu Sep 17 15:22:28.378132 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.220.137.122:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxaFApXMN3p_zkwXf210wAAAMs"]
[Thu Sep 17 15:22:28.389323 2026] [security2:error] [pid 1012520:tid 1012729] [client 140.238.42.111:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaFApXMN3p_zkwXf211gAAANM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:28.775468 2026] [security2:error] [pid 1012520:tid 1012717] [client 140.238.42.111:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaFApXMN3p_zkwXf215AAAAMc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:28.865125 2026] [security2:error] [pid 1012520:tid 1012757] [client 35.220.137.122:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxaFApXMN3p_zkwXf215wAAAO8"]
[Thu Sep 17 15:22:29.171725 2026] [security2:error] [pid 1012520:tid 1012707] [client 140.238.42.111:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaFQpXMN3p_zkwXf21-gAAAL0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:29.343993 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.220.137.122:32930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxaFQpXMN3p_zkwXf21_AAAAQE"]
[Thu Sep 17 15:22:29.492364 2026] [security2:error] [pid 1012520:tid 1012652] [client 138.68.136.141:36972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxaFQpXMN3p_zkwXf219QAAhgw"], referer: http://kidsandlifeot.com/old/
[Thu Sep 17 15:22:29.555454 2026] [security2:error] [pid 1012520:tid 1012750] [client 140.238.42.111:60170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaFQpXMN3p_zkwXf22AAAAAOg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:29.831769 2026] [security2:error] [pid 1012520:tid 1012685] [client 35.220.137.122:32944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxaFQpXMN3p_zkwXf22CAAAAKc"]
[Thu Sep 17 15:22:29.948233 2026] [security2:error] [pid 1012520:tid 1012762] [client 140.238.42.111:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaFQpXMN3p_zkwXf22CwAAAPQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:29.981963 2026] [security2:error] [pid 1012520:tid 1012691] [client 201.247.171.12:3375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaFQpXMN3p_zkwXf22CgAArWU"]
[Thu Sep 17 15:22:30.062585 2026] [security2:error] [pid 1012520:tid 1012710] [client 138.68.136.141:36972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxaFQpXMN3p_zkwXf22BgAAwAA"], referer: http://kidsandlifeot.com/wp/
[Thu Sep 17 15:22:30.324578 2026] [security2:error] [pid 1012520:tid 1012740] [client 35.220.137.122:32956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxaFgpXMN3p_zkwXf22JAAAAN4"]
[Thu Sep 17 15:22:30.328761 2026] [security2:error] [pid 1012520:tid 1012771] [client 140.238.42.111:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaFgpXMN3p_zkwXf22JQAAAP0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:30.386058 2026] [security2:error] [pid 1012520:tid 1012773] [client 4.240.114.86:56315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-login.php"] [unique_id "aqxaFgpXMN3p_zkwXf22JwAAAP8"], referer: binance.com
[Thu Sep 17 15:22:30.594778 2026] [security2:error] [pid 1012520:tid 1012657] [client 138.68.136.141:36972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxaFgpXMN3p_zkwXf22JgAAi3s"], referer: http://kidsandlifeot.com/blog/
[Thu Sep 17 15:22:30.608970 2026] [security2:error] [pid 1012520:tid 1012751] [client 138.246.253.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ritamayblog.com"] [uri "/index.php"] [unique_id "aqxaFQpXMN3p_zkwXf219gAAAOk"]
[Thu Sep 17 15:22:30.731093 2026] [security2:error] [pid 1012520:tid 1012739] [client 140.238.42.111:61139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaFgpXMN3p_zkwXf22NQAAAN0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:30.820556 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.220.137.122:32964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxaFgpXMN3p_zkwXf22OAAAAJI"]
[Thu Sep 17 15:22:31.124752 2026] [security2:error] [pid 1012520:tid 1012744] [client 140.238.42.111:61520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaFwpXMN3p_zkwXf22QAAAAOI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:31.133700 2026] [security2:error] [pid 1012520:tid 1012708] [client 138.68.136.141:36972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxaFgpXMN3p_zkwXf22OQAAvhU"], referer: http://kidsandlifeot.com/backup/
[Thu Sep 17 15:22:31.309475 2026] [security2:error] [pid 1012520:tid 1012667] [client 35.220.137.122:32970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxaFwpXMN3p_zkwXf22RAAAAJU"]
[Thu Sep 17 15:22:31.511625 2026] [security2:error] [pid 1012520:tid 1012753] [client 140.238.42.111:61924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaFwpXMN3p_zkwXf22SgAAAOs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:31.678310 2026] [security2:error] [pid 1012520:tid 1012668] [client 138.68.136.141:36972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kidsandlifeot.com"] [uri "/index.php"] [unique_id "aqxaFwpXMN3p_zkwXf22RgAAlhE"], referer: http://kidsandlifeot.com/new/
[Thu Sep 17 15:22:31.790346 2026] [security2:error] [pid 1012520:tid 1012748] [client 35.220.137.122:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/phpinfo.php.old"] [unique_id "aqxaFwpXMN3p_zkwXf22TwAAAOY"]
[Thu Sep 17 15:22:31.905881 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaFwpXMN3p_zkwXf22UgAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:32.171388 2026] [security2:error] [pid 1012520:tid 1012652] [client 154.190.208.131:41718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGApXMN3p_zkwXf22WAAAAIY"]
[Thu Sep 17 15:22:32.171523 2026] [security2:error] [pid 1012520:tid 1012652] [client 154.190.208.131:41718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGApXMN3p_zkwXf22WAAAAIY"]
[Thu Sep 17 15:22:32.301210 2026] [security2:error] [pid 1012520:tid 1012686] [client 35.220.137.122:32986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/phpinfo.php~"] [unique_id "aqxaGApXMN3p_zkwXf22XgAAAKg"]
[Thu Sep 17 15:22:32.318304 2026] [security2:error] [pid 1012520:tid 1012670] [client 140.238.42.111:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaGApXMN3p_zkwXf22XwAAAJg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:32.577056 2026] [security2:error] [pid 1012520:tid 1012756] [client 169.58.197.253:59571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxaGApXMN3p_zkwXf22awAAAO4"], referer: binance.com
[Thu Sep 17 15:22:32.698783 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:62967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaGApXMN3p_zkwXf22bwAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:32.785562 2026] [security2:error] [pid 1012520:tid 1012674] [client 186.105.232.15:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGApXMN3p_zkwXf22fwAAAJw"]
[Thu Sep 17 15:22:32.785727 2026] [security2:error] [pid 1012520:tid 1012674] [client 186.105.232.15:54527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGApXMN3p_zkwXf22fwAAAJw"]
[Thu Sep 17 15:22:32.811017 2026] [security2:error] [pid 1012520:tid 1012672] [client 35.220.137.122:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/info.php.bak"] [unique_id "aqxaGApXMN3p_zkwXf22gQAAAJo"]
[Thu Sep 17 15:22:33.085697 2026] [security2:error] [pid 1012520:tid 1012664] [client 140.238.42.111:63296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaGQpXMN3p_zkwXf22kQAAAJI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:33.172389 2026] [security2:error] [pid 1012520:tid 1012744] [client 162.241.226.11:16230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxaGApXMN3p_zkwXf22jwAAAOI"]
[Thu Sep 17 15:22:33.294955 2026] [security2:error] [pid 1012520:tid 1012669] [client 35.220.137.122:33008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/phpinfo.php.save"] [unique_id "aqxaGQpXMN3p_zkwXf22lAAAAJc"]
[Thu Sep 17 15:22:33.380887 2026] [security2:error] [pid 1012520:tid 1012770] [client 162.241.226.11:16236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxaGQpXMN3p_zkwXf22kwAAAPw"]
[Thu Sep 17 15:22:33.461777 2026] [security2:error] [pid 1012520:tid 1012758] [client 140.238.42.111:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaGQpXMN3p_zkwXf22mAAAAPA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:33.819138 2026] [security2:error] [pid 1012520:tid 1012668] [client 35.220.137.122:33020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxaGQpXMN3p_zkwXf22nAAAAJY"]
[Thu Sep 17 15:22:33.864994 2026] [security2:error] [pid 1012520:tid 1012671] [client 140.238.42.111:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaGQpXMN3p_zkwXf22nQAAAJk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:33.935003 2026] [security2:error] [pid 1012520:tid 1012747] [client 114.198.138.124:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGQpXMN3p_zkwXf22oAAAAOU"]
[Thu Sep 17 15:22:33.935121 2026] [security2:error] [pid 1012520:tid 1012747] [client 114.198.138.124:61987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGQpXMN3p_zkwXf22oAAAAOU"]
[Thu Sep 17 15:22:33.976008 2026] [security2:error] [pid 1012520:tid 1012726] [client 216.73.217.36:43836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-90db0d4a.24eastyard.com"] [uri "/index.php"] [unique_id "aqxaGQpXMN3p_zkwXf22ngAA0DM"]
[Thu Sep 17 15:22:34.243289 2026] [security2:error] [pid 1012520:tid 1012768] [client 103.61.184.148:50743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGgpXMN3p_zkwXf22pgAAAPo"]
[Thu Sep 17 15:22:34.243462 2026] [security2:error] [pid 1012520:tid 1012768] [client 103.61.184.148:50743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGgpXMN3p_zkwXf22pgAAAPo"]
[Thu Sep 17 15:22:34.273107 2026] [security2:error] [pid 1012520:tid 1012652] [client 140.238.42.111:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaGgpXMN3p_zkwXf22pwAAAIY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:34.320442 2026] [security2:error] [pid 1012520:tid 1012663] [client 35.220.137.122:33028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxaGgpXMN3p_zkwXf22qAAAAJE"]
[Thu Sep 17 15:22:34.675373 2026] [security2:error] [pid 1012520:tid 1012732] [client 140.238.42.111:64577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaGgpXMN3p_zkwXf22rwAAANY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:34.818920 2026] [security2:error] [pid 1012520:tid 1012712] [client 35.220.137.122:33032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxaGgpXMN3p_zkwXf22sAAAAMI"]
[Thu Sep 17 15:22:35.074564 2026] [security2:error] [pid 1012520:tid 1012769] [client 140.238.42.111:64921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaGwpXMN3p_zkwXf22twAAAPs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:35.163654 2026] [security2:error] [pid 1012520:tid 1012776] [client 185.55.149.49:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaGwpXMN3p_zkwXf22uAAAAQI"]
[Thu Sep 17 15:22:35.163784 2026] [security2:error] [pid 1012520:tid 1012776] [client 185.55.149.49:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaGwpXMN3p_zkwXf22uAAAAQI"]
[Thu Sep 17 15:22:35.206027 2026] [autoindex:error] [pid 1012520:tid 1012710] [client 152.32.235.107:39632] AH01276: Cannot serve directory /home1/sacyjkmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.sac.yjk.mybluehost.me/
[Thu Sep 17 15:22:35.305086 2026] [security2:error] [pid 1012520:tid 1012763] [client 35.220.137.122:33046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxaGwpXMN3p_zkwXf22yAAAAPU"]
[Thu Sep 17 15:22:35.429193 2026] [security2:error] [pid 1012520:tid 1012754] [client 185.121.232.229:60895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxaGQpXMN3p_zkwXf22mwAAAOw"], referer: https://zainridgecondo.org/contact-us/?contact-form-id=573&contact-form-sent=2892&contact-form-hash=0b103eee4f472da21bebbf9b8d73b30145e36f70&_wpnonce=cbc55079ff
[Thu Sep 17 15:22:35.478503 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:65244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaGwpXMN3p_zkwXf220gAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:35.812913 2026] [security2:error] [pid 1012520:tid 1012725] [client 35.220.137.122:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxaGwpXMN3p_zkwXf224AAAAM8"]
[Thu Sep 17 15:22:35.873636 2026] [security2:error] [pid 1012520:tid 1012706] [client 140.238.42.111:49169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaGwpXMN3p_zkwXf224gAAALw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:35.890897 2026] [security2:error] [pid 1012520:tid 1012700] [client 35.238.73.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxaGwpXMN3p_zkwXf223AAAALY"]
[Thu Sep 17 15:22:36.002469 2026] [security2:error] [pid 1012520:tid 1012708] [client 156.192.234.52:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGwpXMN3p_zkwXf226QAAAL4"]
[Thu Sep 17 15:22:36.002608 2026] [security2:error] [pid 1012520:tid 1012708] [client 156.192.234.52:53603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaGwpXMN3p_zkwXf226QAAAL4"]
[Thu Sep 17 15:22:36.256189 2026] [security2:error] [pid 1012520:tid 1012661] [client 140.238.42.111:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaHApXMN3p_zkwXf227gAAAI8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:36.307828 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.220.137.122:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/www/phpinfo.php"] [unique_id "aqxaHApXMN3p_zkwXf228AAAAQQ"]
[Thu Sep 17 15:22:36.638900 2026] [security2:error] [pid 1012520:tid 1012666] [client 140.238.42.111:49884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaHApXMN3p_zkwXf22-AAAAJQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:36.800588 2026] [security2:error] [pid 1012520:tid 1012692] [client 35.220.137.122:33072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxaHApXMN3p_zkwXf22-gAAAK4"]
[Thu Sep 17 15:22:37.017835 2026] [security2:error] [pid 1012520:tid 1012730] [client 140.238.42.111:50193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaHQpXMN3p_zkwXf23AQAAANQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:37.284450 2026] [security2:error] [pid 1012520:tid 1012656] [client 35.220.137.122:33080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxaHQpXMN3p_zkwXf23BwAAAIo"]
[Thu Sep 17 15:22:37.397064 2026] [security2:error] [pid 1012520:tid 1012675] [client 140.238.42.111:50493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaHQpXMN3p_zkwXf23CgAAAJ0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:37.771026 2026] [security2:error] [pid 1012520:tid 1012678] [client 35.220.137.122:33082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/site/phpinfo.php"] [unique_id "aqxaHQpXMN3p_zkwXf23EwAAAKA"]
[Thu Sep 17 15:22:37.786325 2026] [security2:error] [pid 1012520:tid 1012740] [client 140.238.42.111:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaHQpXMN3p_zkwXf23FAAAAN4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:37.897778 2026] [autoindex:error] [pid 1012520:tid 1012710] [client 34.24.239.23:37898] AH01276: Cannot serve directory /home1/isabrnmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:22:37.950943 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.24.239.23:37898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/"] [unique_id "aqxaHQpXMN3p_zkwXf23GQAAAP4"]
[Thu Sep 17 15:22:38.116341 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.24.239.23:37904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/"] [unique_id "aqxaHgpXMN3p_zkwXf23HAAAAMg"]
[Thu Sep 17 15:22:38.167217 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:51113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaHgpXMN3p_zkwXf23HwAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:38.248898 2026] [security2:error] [pid 1012520:tid 1012765] [client 35.220.137.122:52476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxaHgpXMN3p_zkwXf23IAAAAPc"]
[Thu Sep 17 15:22:38.283024 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.24.239.23:37920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/"] [unique_id "aqxaHgpXMN3p_zkwXf23IgAAAN0"]
[Thu Sep 17 15:22:38.298475 2026] [security2:error] [pid 1012520:tid 1012705] [client 49.13.24.81:34064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxaHgpXMN3p_zkwXf23IwAAALs"], referer: https://eris.media
[Thu Sep 17 15:22:38.526026 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.24.239.23:37928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/"] [unique_id "aqxaHgpXMN3p_zkwXf23KAAAALo"]
[Thu Sep 17 15:22:38.567045 2026] [security2:error] [pid 1012520:tid 1012657] [client 140.238.42.111:51423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaHgpXMN3p_zkwXf23KQAAAIs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:38.703020 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/.env"] [unique_id "aqxaHgpXMN3p_zkwXf23MQAAAJU"]
[Thu Sep 17 15:22:38.755248 2026] [security2:error] [pid 1012520:tid 1012761] [client 35.220.137.122:52478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxaHgpXMN3p_zkwXf23MwAAAPM"]
[Thu Sep 17 15:22:38.955146 2026] [security2:error] [pid 1012520:tid 1012733] [client 140.238.42.111:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaHgpXMN3p_zkwXf23OwAAANc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:39.132270 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxaHwpXMN3p_zkwXf23QgAAAJk"]
[Thu Sep 17 15:22:39.189309 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxaHwpXMN3p_zkwXf23QwAAAPY"]
[Thu Sep 17 15:22:39.241000 2026] [security2:error] [pid 1012520:tid 1012778] [client 35.220.137.122:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxaHwpXMN3p_zkwXf23RQAAAQQ"]
[Thu Sep 17 15:22:39.252787 2026] [security2:error] [pid 1012520:tid 1012590] [remote 54.39.203.220:34096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.joeledmundanderson.com"] [uri "/robots.txt"] [unique_id "aqxaHwpXMN3p_zkwXf23RwAAqkQ"]
[Thu Sep 17 15:22:39.252925 2026] [security2:error] [pid 1012520:tid 1012688] [client 54.39.203.220:34096] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.joeledmundanderson.com"] [uri "/robots.txt"] [unique_id "aqxaHwpXMN3p_zkwXf23RwAAqkQ"]
[Thu Sep 17 15:22:39.303291 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxaHwpXMN3p_zkwXf23SAAAAO0"]
[Thu Sep 17 15:22:39.334018 2026] [security2:error] [pid 1012520:tid 1012685] [client 140.238.42.111:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaHwpXMN3p_zkwXf23SgAAAKc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:39.665174 2026] [security2:error] [pid 1012520:tid 1012643] [remote 51.81.170.11:22396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.joeledmundanderson.com"] [uri "/atheist-jerry-coyne-and-yecist-ken-ham-two-peas-in-a-pod/"] [unique_id "aqxaHwpXMN3p_zkwXf23ZQAAuXk"]
[Thu Sep 17 15:22:39.665289 2026] [security2:error] [pid 1012520:tid 1012703] [client 51.81.170.11:22396] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.joeledmundanderson.com"] [uri "/atheist-jerry-coyne-and-yecist-ken-ham-two-peas-in-a-pod/"] [unique_id "aqxaHwpXMN3p_zkwXf23ZQAAuXk"]
[Thu Sep 17 15:22:39.727420 2026] [security2:error] [pid 1012520:tid 1012721] [client 35.220.137.122:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/core/phpinfo.php"] [unique_id "aqxaHwpXMN3p_zkwXf23aAAAAMs"]
[Thu Sep 17 15:22:39.730749 2026] [security2:error] [pid 1012520:tid 1012691] [client 140.238.42.111:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaHwpXMN3p_zkwXf23aQAAAK0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:40.014497 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxaIApXMN3p_zkwXf23cQAAAOk"]
[Thu Sep 17 15:22:40.074042 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/.env~"] [unique_id "aqxaIApXMN3p_zkwXf23dAAAAO8"]
[Thu Sep 17 15:22:40.109126 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaIApXMN3p_zkwXf23dQAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:40.212747 2026] [security2:error] [pid 1012520:tid 1012742] [client 35.220.137.122:52506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.137.220.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxaIApXMN3p_zkwXf23eQAAAOA"]
[Thu Sep 17 15:22:40.258907 2026] [security2:error] [pid 1012520:tid 1012723] [client 49.13.130.29:10078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxaIApXMN3p_zkwXf23ewAAAM0"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:22:40.444696 2026] [security2:error] [pid 1012520:tid 1012725] [client 98.97.34.108:50333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaIApXMN3p_zkwXf23fgAAzy8"], referer: https://www.google.com/
[Thu Sep 17 15:22:40.507931 2026] [security2:error] [pid 1012520:tid 1012736] [client 140.238.42.111:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaIApXMN3p_zkwXf23hwAAANo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:40.542807 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxaIApXMN3p_zkwXf23iAAAAPA"]
[Thu Sep 17 15:22:40.586635 2026] [security2:error] [pid 1012520:tid 1012677] [client 169.58.197.253:60054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxaIApXMN3p_zkwXf23iQAAAJ8"], referer: binance.com
[Thu Sep 17 15:22:40.598979 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxaIApXMN3p_zkwXf23iwAAALI"]
[Thu Sep 17 15:22:40.667771 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxaIApXMN3p_zkwXf23jAAAAMk"]
[Thu Sep 17 15:22:40.722994 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxaIApXMN3p_zkwXf23jwAAAMo"]
[Thu Sep 17 15:22:40.734531 2026] [security2:error] [pid 1012520:tid 1012707] [client 49.13.130.29:10086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxaIApXMN3p_zkwXf23jgAAAL0"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:22:40.780988 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxaIApXMN3p_zkwXf23kQAAAIk"]
[Thu Sep 17 15:22:40.808546 2026] [security2:error] [pid 1012520:tid 1012770] [client 98.97.34.108:50333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaIApXMN3p_zkwXf23kAAA_GI"], referer: https://endless-chronicles.com/explore/wiki/index.php?days=30&hideanons=1&limit=100&target=Oz&title=Special%3ARecentChangesLinked&userExpLevel=unregistered
[Thu Sep 17 15:22:40.811074 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIApXMN3p_zkwXf23jQAAAKI"]
[Thu Sep 17 15:22:40.838724 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxaIApXMN3p_zkwXf23lAAAAJk"]
[Thu Sep 17 15:22:40.894154 2026] [security2:error] [pid 1012520:tid 1012733] [client 140.238.42.111:53486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaIApXMN3p_zkwXf23lwAAANc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:40.964048 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxaIApXMN3p_zkwXf23nAAAAKQ"]
[Thu Sep 17 15:22:41.022371 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23nwAAAJc"]
[Thu Sep 17 15:22:41.047612 2026] [security2:error] [pid 1012520:tid 1012688] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIApXMN3p_zkwXf23nQAAAKo"]
[Thu Sep 17 15:22:41.080523 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23oQAAAKc"]
[Thu Sep 17 15:22:41.140426 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23ogAAAIY"]
[Thu Sep 17 15:22:41.201636 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23owAAAP8"]
[Thu Sep 17 15:22:41.258310 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23pQAAAOM"]
[Thu Sep 17 15:22:41.279695 2026] [security2:error] [pid 1012520:tid 1012768] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIQpXMN3p_zkwXf23pAAAAPo"]
[Thu Sep 17 15:22:41.296832 2026] [security2:error] [pid 1012520:tid 1012690] [client 140.238.42.111:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaIQpXMN3p_zkwXf23pwAAAKw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:41.313843 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23qQAAANY"]
[Thu Sep 17 15:22:41.378747 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23qgAAALQ"]
[Thu Sep 17 15:22:41.438059 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23rQAAAKE"]
[Thu Sep 17 15:22:41.497343 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23sAAAAM4"]
[Thu Sep 17 15:22:41.522506 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIQpXMN3p_zkwXf23rgAAAOo"]
[Thu Sep 17 15:22:41.553617 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23tAAAAO4"]
[Thu Sep 17 15:22:41.609972 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23tQAAAP0"]
[Thu Sep 17 15:22:41.667078 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23tgAAAK0"]
[Thu Sep 17 15:22:41.687176 2026] [security2:error] [pid 1012520:tid 1012731] [client 140.238.42.111:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaIQpXMN3p_zkwXf23uAAAANU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:41.722521 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23uQAAAMw"]
[Thu Sep 17 15:22:41.765933 2026] [security2:error] [pid 1012520:tid 1012714] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIQpXMN3p_zkwXf23twAAAMQ"]
[Thu Sep 17 15:22:41.778321 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23uwAAANw"]
[Thu Sep 17 15:22:41.834827 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23vAAAAKA"]
[Thu Sep 17 15:22:41.891154 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23vQAAAN4"]
[Thu Sep 17 15:22:41.946190 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxaIQpXMN3p_zkwXf23vwAAAO8"]
[Thu Sep 17 15:22:42.000225 2026] [security2:error] [pid 1012520:tid 1012693] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIQpXMN3p_zkwXf23vgAAAK8"]
[Thu Sep 17 15:22:42.012772 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxaIgpXMN3p_zkwXf23wwAAALE"]
[Thu Sep 17 15:22:42.067291 2026] [security2:error] [pid 1012520:tid 1012751] [client 140.238.42.111:54494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaIgpXMN3p_zkwXf23xgAAAOk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:42.068483 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxaIgpXMN3p_zkwXf23xQAAAMg"]
[Thu Sep 17 15:22:42.124455 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxaIgpXMN3p_zkwXf23xwAAAPU"]
[Thu Sep 17 15:22:42.185156 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxaIgpXMN3p_zkwXf23yQAAAMA"]
[Thu Sep 17 15:22:42.243509 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxaIgpXMN3p_zkwXf23ywAAAOA"]
[Thu Sep 17 15:22:42.248552 2026] [security2:error] [pid 1012520:tid 1012664] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIgpXMN3p_zkwXf23yAAAAJI"]
[Thu Sep 17 15:22:42.300187 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxaIgpXMN3p_zkwXf23zwAAALs"]
[Thu Sep 17 15:22:42.355565 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxaIgpXMN3p_zkwXf230QAAAIw"]
[Thu Sep 17 15:22:42.412003 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxaIgpXMN3p_zkwXf230wAAALw"]
[Thu Sep 17 15:22:42.465141 2026] [security2:error] [pid 1012520:tid 1012702] [client 140.238.42.111:54807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaIgpXMN3p_zkwXf231gAAALg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:42.471814 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxaIgpXMN3p_zkwXf232AAAAIs"]
[Thu Sep 17 15:22:42.486879 2026] [security2:error] [pid 1012520:tid 1012716] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIgpXMN3p_zkwXf230gAAAMY"]
[Thu Sep 17 15:22:42.527265 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxaIgpXMN3p_zkwXf232QAAAMc"]
[Thu Sep 17 15:22:42.590125 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxaIgpXMN3p_zkwXf233AAAAPA"]
[Thu Sep 17 15:22:42.646076 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxaIgpXMN3p_zkwXf233QAAAPk"]
[Thu Sep 17 15:22:42.701566 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxaIgpXMN3p_zkwXf233wAAAOs"]
[Thu Sep 17 15:22:42.708946 2026] [security2:error] [pid 1012520:tid 1012759] [client 154.190.208.131:42303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaIgpXMN3p_zkwXf234QAAAPE"]
[Thu Sep 17 15:22:42.709041 2026] [security2:error] [pid 1012520:tid 1012759] [client 154.190.208.131:42303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaIgpXMN3p_zkwXf234QAAAPE"]
[Thu Sep 17 15:22:42.724999 2026] [security2:error] [pid 1012520:tid 1012775] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIgpXMN3p_zkwXf233gAAAQE"]
[Thu Sep 17 15:22:42.757778 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxaIgpXMN3p_zkwXf234gAAAJA"]
[Thu Sep 17 15:22:42.813134 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxaIgpXMN3p_zkwXf234wAAAOY"]
[Thu Sep 17 15:22:42.865997 2026] [security2:error] [pid 1012520:tid 1012735] [client 140.238.42.111:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaIgpXMN3p_zkwXf235AAAANk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:42.868729 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxaIgpXMN3p_zkwXf235QAAAJY"]
[Thu Sep 17 15:22:42.926924 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxaIgpXMN3p_zkwXf235wAAAMU"]
[Thu Sep 17 15:22:42.962930 2026] [security2:error] [pid 1012520:tid 1012680] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIgpXMN3p_zkwXf235gAAAKI"]
[Thu Sep 17 15:22:42.986236 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxaIgpXMN3p_zkwXf236wAAAJQ"]
[Thu Sep 17 15:22:43.041313 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxaIwpXMN3p_zkwXf237QAAALU"]
[Thu Sep 17 15:22:43.099207 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.24.239.23:37936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxaIwpXMN3p_zkwXf237gAAALc"]
[Thu Sep 17 15:22:43.198956 2026] [security2:error] [pid 1012520:tid 1012659] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIwpXMN3p_zkwXf237wAAAI0"]
[Thu Sep 17 15:22:43.262995 2026] [security2:error] [pid 1012520:tid 1012682] [client 140.238.42.111:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaIwpXMN3p_zkwXf238gAAAKQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:43.266863 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxaIwpXMN3p_zkwXf238wAAAKo"]
[Thu Sep 17 15:22:43.336248 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxaIwpXMN3p_zkwXf239AAAAIc"]
[Thu Sep 17 15:22:43.391250 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxaIwpXMN3p_zkwXf239gAAANI"]
[Thu Sep 17 15:22:43.437518 2026] [security2:error] [pid 1012520:tid 1012670] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIwpXMN3p_zkwXf239QAAAJg"]
[Thu Sep 17 15:22:43.452644 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxaIwpXMN3p_zkwXf23-gAAAOM"]
[Thu Sep 17 15:22:43.511124 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxaIwpXMN3p_zkwXf23_AAAAQQ"]
[Thu Sep 17 15:22:43.571341 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxaIwpXMN3p_zkwXf23_QAAAJ0"]
[Thu Sep 17 15:22:43.631050 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxaIwpXMN3p_zkwXf24AAAAAKw"]
[Thu Sep 17 15:22:43.654337 2026] [security2:error] [pid 1012520:tid 1012743] [client 140.238.42.111:55841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaIwpXMN3p_zkwXf24AgAAAOE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:43.686156 2026] [security2:error] [pid 1012520:tid 1012665] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIwpXMN3p_zkwXf23_gAAAJM"]
[Thu Sep 17 15:22:43.687549 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxaIwpXMN3p_zkwXf24AwAAALQ"]
[Thu Sep 17 15:22:43.745229 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxaIwpXMN3p_zkwXf24BAAAANM"]
[Thu Sep 17 15:22:43.800859 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxaIwpXMN3p_zkwXf24BQAAAM4"]
[Thu Sep 17 15:22:43.856272 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxaIwpXMN3p_zkwXf24BwAAAJE"]
[Thu Sep 17 15:22:43.919486 2026] [security2:error] [pid 1012520:tid 1012752] [client 35.220.137.122:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.independentbeauty.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxaIwpXMN3p_zkwXf24BgAAAOo"]
[Thu Sep 17 15:22:43.929605 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxaIwpXMN3p_zkwXf24CgAAAMI"]
[Thu Sep 17 15:22:43.987347 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxaIwpXMN3p_zkwXf24DQAAANw"]
[Thu Sep 17 15:22:44.037699 2026] [security2:error] [pid 1012520:tid 1012774] [client 140.238.42.111:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaJApXMN3p_zkwXf24DgAAAQA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:44.053107 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxaJApXMN3p_zkwXf24DwAAAKA"]
[Thu Sep 17 15:22:44.118177 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxaJApXMN3p_zkwXf24EgAAAK8"]
[Thu Sep 17 15:22:44.178048 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxaJApXMN3p_zkwXf24EwAAALE"]
[Thu Sep 17 15:22:44.232451 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxaJApXMN3p_zkwXf24FAAAAMg"]
[Thu Sep 17 15:22:44.291807 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxaJApXMN3p_zkwXf24FQAAAMA"]
[Thu Sep 17 15:22:44.365696 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxaJApXMN3p_zkwXf24FwAAAOA"]
[Thu Sep 17 15:22:44.432715 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxaJApXMN3p_zkwXf24GQAAAJ4"]
[Thu Sep 17 15:22:44.442106 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:56496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaJApXMN3p_zkwXf24GwAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:44.491104 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxaJApXMN3p_zkwXf24HAAAALs"]
[Thu Sep 17 15:22:44.547485 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxaJApXMN3p_zkwXf24IgAAAJo"]
[Thu Sep 17 15:22:44.605840 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxaJApXMN3p_zkwXf24JAAAAJU"]
[Thu Sep 17 15:22:44.660026 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxaJApXMN3p_zkwXf24JgAAAJ8"]
[Thu Sep 17 15:22:44.715760 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxaJApXMN3p_zkwXf24JwAAAKM"]
[Thu Sep 17 15:22:44.743452 2026] [security2:error] [pid 1012520:tid 1012657] [client 114.198.138.124:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJApXMN3p_zkwXf24KAAAAIs"]
[Thu Sep 17 15:22:44.743564 2026] [security2:error] [pid 1012520:tid 1012657] [client 114.198.138.124:52218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJApXMN3p_zkwXf24KAAAAIs"]
[Thu Sep 17 15:22:44.775117 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxaJApXMN3p_zkwXf24KQAAAM8"]
[Thu Sep 17 15:22:44.833424 2026] [security2:error] [pid 1012520:tid 1012749] [client 140.238.42.111:56843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaJApXMN3p_zkwXf24MQAAAOc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:44.840434 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxaJApXMN3p_zkwXf24MgAAANE"]
[Thu Sep 17 15:22:44.897173 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxaJApXMN3p_zkwXf24NAAAAMo"]
[Thu Sep 17 15:22:44.952569 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxaJApXMN3p_zkwXf24NQAAAJA"]
[Thu Sep 17 15:22:44.978631 2026] [security2:error] [pid 1012520:tid 1012704] [client 186.105.232.15:55156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJApXMN3p_zkwXf24OAAAALo"]
[Thu Sep 17 15:22:44.978773 2026] [security2:error] [pid 1012520:tid 1012704] [client 186.105.232.15:55156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJApXMN3p_zkwXf24OAAAALo"]
[Thu Sep 17 15:22:45.007759 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24OQAAAI8"]
[Thu Sep 17 15:22:45.065321 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24PAAAAOg"]
[Thu Sep 17 15:22:45.118453 2026] [security2:error] [pid 1012520:tid 1012767] [client 103.61.184.148:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJQpXMN3p_zkwXf24PgAAAPk"]
[Thu Sep 17 15:22:45.118601 2026] [security2:error] [pid 1012520:tid 1012767] [client 103.61.184.148:51293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJQpXMN3p_zkwXf24PgAAAPk"]
[Thu Sep 17 15:22:45.119607 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24QQAAAKI"]
[Thu Sep 17 15:22:45.182617 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24QwAAANc"]
[Thu Sep 17 15:22:45.222553 2026] [security2:error] [pid 1012520:tid 1012715] [client 140.238.42.111:57181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaJQpXMN3p_zkwXf24RAAAAMU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:45.244440 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24RQAAANA"]
[Thu Sep 17 15:22:45.311454 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24RwAAAOQ"]
[Thu Sep 17 15:22:45.368632 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24SQAAAK4"]
[Thu Sep 17 15:22:45.423753 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24SwAAAPI"]
[Thu Sep 17 15:22:45.478845 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24TQAAANI"]
[Thu Sep 17 15:22:45.541782 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24UQAAAME"]
[Thu Sep 17 15:22:45.596754 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24UgAAAPo"]
[Thu Sep 17 15:22:45.606421 2026] [security2:error] [pid 1012520:tid 1012652] [client 140.238.42.111:57542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaJQpXMN3p_zkwXf24UwAAAIY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:45.652866 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24VAAAAOE"]
[Thu Sep 17 15:22:45.709162 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24VgAAALQ"]
[Thu Sep 17 15:22:45.767722 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24WAAAALM"]
[Thu Sep 17 15:22:45.827886 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24WQAAAJE"]
[Thu Sep 17 15:22:45.850099 2026] [security2:error] [pid 1012520:tid 1012675] [client 185.55.149.49:54487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaJQpXMN3p_zkwXf24WgAAAJ0"]
[Thu Sep 17 15:22:45.850197 2026] [security2:error] [pid 1012520:tid 1012675] [client 185.55.149.49:54487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaJQpXMN3p_zkwXf24WgAAAJ0"]
[Thu Sep 17 15:22:45.889596 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24WwAAAP0"]
[Thu Sep 17 15:22:45.945835 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxaJQpXMN3p_zkwXf24XAAAAOo"]
[Thu Sep 17 15:22:45.996615 2026] [security2:error] [pid 1012520:tid 1012651] [client 140.238.42.111:57828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaJQpXMN3p_zkwXf24YQAAAIU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:46.002136 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24YgAAAQI"]
[Thu Sep 17 15:22:46.058166 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24ZgAAALE"]
[Thu Sep 17 15:22:46.116111 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24ZwAAAN4"]
[Thu Sep 17 15:22:46.171407 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24aAAAAPU"]
[Thu Sep 17 15:22:46.232368 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24agAAAI4"]
[Thu Sep 17 15:22:46.300929 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24awAAAJ4"]
[Thu Sep 17 15:22:46.360831 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24bAAAAIo"]
[Thu Sep 17 15:22:46.397719 2026] [security2:error] [pid 1012520:tid 1012742] [client 140.238.42.111:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaJgpXMN3p_zkwXf24bQAAAOA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:46.418467 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24bgAAALs"]
[Thu Sep 17 15:22:46.477886 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24cAAAAM0"]
[Thu Sep 17 15:22:46.534666 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24dAAAALA"]
[Thu Sep 17 15:22:46.543805 2026] [security2:error] [pid 1012520:tid 1012683] [client 156.192.234.52:54232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJgpXMN3p_zkwXf24dgAAAKU"]
[Thu Sep 17 15:22:46.545187 2026] [security2:error] [pid 1012520:tid 1012683] [client 156.192.234.52:54232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaJgpXMN3p_zkwXf24dgAAAKU"]
[Thu Sep 17 15:22:46.596569 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24dwAAALg"]
[Thu Sep 17 15:22:46.643107 2026] [security2:error] [pid 1012520:tid 1012761] [client 115.76.48.215:38255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaJgpXMN3p_zkwXf24dQAA82Y"]
[Thu Sep 17 15:22:46.654429 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24eAAAALw"]
[Thu Sep 17 15:22:46.715210 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24ewAAAM8"]
[Thu Sep 17 15:22:46.774939 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24fAAAAPE"]
[Thu Sep 17 15:22:46.777034 2026] [security2:error] [pid 1012520:tid 1012758] [client 140.238.42.111:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaJgpXMN3p_zkwXf24fQAAAPA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:46.831881 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24fgAAANE"]
[Thu Sep 17 15:22:46.886064 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24fwAAAQE"]
[Thu Sep 17 15:22:46.958594 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxaJgpXMN3p_zkwXf24gQAAAL4"]
[Thu Sep 17 15:22:47.074012 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24hQAAAOY"]
[Thu Sep 17 15:22:47.130716 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24hwAAAI8"]
[Thu Sep 17 15:22:47.164923 2026] [security2:error] [pid 1012520:tid 1012704] [client 140.238.42.111:58813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaJwpXMN3p_zkwXf24iQAAALo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:47.195499 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24igAAAPY"]
[Thu Sep 17 15:22:47.270193 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24jQAAANk"]
[Thu Sep 17 15:22:47.440209 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24kwAAAIg"]
[Thu Sep 17 15:22:47.493985 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24mgAAAKQ"]
[Thu Sep 17 15:22:47.550356 2026] [security2:error] [pid 1012520:tid 1012669] [client 140.238.42.111:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaJwpXMN3p_zkwXf24nAAAAJc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:47.555649 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24nQAAAKo"]
[Thu Sep 17 15:22:47.613042 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24oAAAAJg"]
[Thu Sep 17 15:22:47.677697 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24oQAAAME"]
[Thu Sep 17 15:22:47.745936 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24owAAANY"]
[Thu Sep 17 15:22:47.809877 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.24.239.23:37950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxaJwpXMN3p_zkwXf24pAAAAL0"]
[Thu Sep 17 15:22:47.895650 2026] [fcgid:warn] [pid 1012520:tid 1012684] (70014)End of file found: [client 152.32.235.107:56220] mod_fcgid: can't get data from http client
[Thu Sep 17 15:22:47.940214 2026] [security2:error] [pid 1012520:tid 1012698] [client 140.238.42.111:59447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaJwpXMN3p_zkwXf24qQAAALQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:48.024834 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxaKApXMN3p_zkwXf24rQAAALk"]
[Thu Sep 17 15:22:48.087421 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxaKApXMN3p_zkwXf24sAAAAMI"]
[Thu Sep 17 15:22:48.144777 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxaKApXMN3p_zkwXf24swAAAJw"]
[Thu Sep 17 15:22:48.203304 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxaKApXMN3p_zkwXf24tAAAALE"]
[Thu Sep 17 15:22:48.224042 2026] [autoindex:error] [pid 1012520:tid 1012752] [client 34.92.151.55:40812] AH01276: Cannot serve directory /home1/uxzhuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:22:48.259987 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxaKApXMN3p_zkwXf24tgAAAPs"]
[Thu Sep 17 15:22:48.316256 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxaKApXMN3p_zkwXf24uQAAAI4"]
[Thu Sep 17 15:22:48.327119 2026] [security2:error] [pid 1012520:tid 1012740] [client 140.238.42.111:59756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaKApXMN3p_zkwXf24ugAAAN4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:48.370341 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxaKApXMN3p_zkwXf24uwAAAJs"]
[Thu Sep 17 15:22:48.396833 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.92.151.55:40812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "uxz.hui.mybluehost.me"] [uri "/"] [unique_id "aqxaKApXMN3p_zkwXf24vQAAAJ4"]
[Thu Sep 17 15:22:48.431426 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxaKApXMN3p_zkwXf24vgAAAP8"]
[Thu Sep 17 15:22:48.490023 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxaKApXMN3p_zkwXf24wQAAAOA"]
[Thu Sep 17 15:22:48.545121 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxaKApXMN3p_zkwXf24xgAAALA"]
[Thu Sep 17 15:22:48.606311 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxaKApXMN3p_zkwXf24yAAAALg"]
[Thu Sep 17 15:22:48.664900 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxaKApXMN3p_zkwXf24yQAAALw"]
[Thu Sep 17 15:22:48.715335 2026] [security2:error] [pid 1012520:tid 1012677] [client 140.238.42.111:60108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaKApXMN3p_zkwXf24ywAAAJ8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:48.724384 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxaKApXMN3p_zkwXf24zAAAAMc"]
[Thu Sep 17 15:22:48.790230 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxaKApXMN3p_zkwXf24zwAAAIs"]
[Thu Sep 17 15:22:48.850336 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxaKApXMN3p_zkwXf240gAAAOc"]
[Thu Sep 17 15:22:48.905089 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxaKApXMN3p_zkwXf240wAAANE"]
[Thu Sep 17 15:22:48.962181 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxaKApXMN3p_zkwXf241QAAAMk"]
[Thu Sep 17 15:22:49.001897 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.92.151.55:40814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "uxz.hui.mybluehost.me"] [uri "/"] [unique_id "aqxaKQpXMN3p_zkwXf242AAAAM8"]
[Thu Sep 17 15:22:49.021862 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxaKQpXMN3p_zkwXf243AAAAMM"]
[Thu Sep 17 15:22:49.091135 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxaKQpXMN3p_zkwXf243gAAAOg"]
[Thu Sep 17 15:22:49.106697 2026] [security2:error] [pid 1012520:tid 1012736] [client 140.238.42.111:60444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaKQpXMN3p_zkwXf243wAAANo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:49.146920 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxaKQpXMN3p_zkwXf244AAAALY"]
[Thu Sep 17 15:22:49.206564 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxaKQpXMN3p_zkwXf244gAAALc"]
[Thu Sep 17 15:22:49.253711 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.166.123.190:39758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxaKQpXMN3p_zkwXf245AAAAKk"]
[Thu Sep 17 15:22:49.261687 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxaKQpXMN3p_zkwXf245QAAAKs"]
[Thu Sep 17 15:22:49.338531 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxaKQpXMN3p_zkwXf246AAAAPw"]
[Thu Sep 17 15:22:49.364967 2026] [security2:error] [pid 1012520:tid 1012744] [client 170.80.236.31:45936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaKQpXMN3p_zkwXf244wAA4h0"]
[Thu Sep 17 15:22:49.396005 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxaKQpXMN3p_zkwXf246QAAAKI"]
[Thu Sep 17 15:22:49.456707 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxaKQpXMN3p_zkwXf246wAAAPk"]
[Thu Sep 17 15:22:49.489923 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:60778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaKQpXMN3p_zkwXf247wAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:49.512189 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxaKQpXMN3p_zkwXf248wAAAME"]
[Thu Sep 17 15:22:49.566287 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxaKQpXMN3p_zkwXf249AAAAKw"]
[Thu Sep 17 15:22:49.619872 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxaKQpXMN3p_zkwXf249gAAAI0"]
[Thu Sep 17 15:22:49.657719 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.92.151.55:40820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "uxz.hui.mybluehost.me"] [uri "/"] [unique_id "aqxaKQpXMN3p_zkwXf24-AAAAKQ"]
[Thu Sep 17 15:22:49.678350 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxaKQpXMN3p_zkwXf24-QAAAJM"]
[Thu Sep 17 15:22:49.733013 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxaKQpXMN3p_zkwXf24-wAAAKE"]
[Thu Sep 17 15:22:49.793191 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxaKQpXMN3p_zkwXf24_AAAALM"]
[Thu Sep 17 15:22:49.855064 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxaKQpXMN3p_zkwXf24_wAAAM4"]
[Thu Sep 17 15:22:49.893854 2026] [security2:error] [pid 1012520:tid 1012741] [client 140.238.42.111:61099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaKQpXMN3p_zkwXf25AQAAAN8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:49.910807 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxaKQpXMN3p_zkwXf25AgAAALQ"]
[Thu Sep 17 15:22:49.933471 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.166.123.190:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/info.php"] [unique_id "aqxaKQpXMN3p_zkwXf25AwAAANM"]
[Thu Sep 17 15:22:49.971640 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxaKQpXMN3p_zkwXf25BwAAAMw"]
[Thu Sep 17 15:22:49.976992 2026] [security2:error] [pid 1012520:tid 1012738] [client 169.58.197.253:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxaKQpXMN3p_zkwXf25CAAAANw"], referer: binance.com
[Thu Sep 17 15:22:50.029470 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25CwAAAOo"]
[Thu Sep 17 15:22:50.094933 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25DQAAAPs"]
[Thu Sep 17 15:22:50.159620 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25DwAAAMA"]
[Thu Sep 17 15:22:50.217815 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25EQAAAQA"]
[Thu Sep 17 15:22:50.275404 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25FQAAAOw"]
[Thu Sep 17 15:22:50.281994 2026] [security2:error] [pid 1012520:tid 1012731] [client 140.238.42.111:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaKgpXMN3p_zkwXf25FgAAANU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:50.331325 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25FwAAALs"]
[Thu Sep 17 15:22:50.395079 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25GQAAALA"]
[Thu Sep 17 15:22:50.411245 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.92.151.55:40826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "uxz.hui.mybluehost.me"] [uri "/"] [unique_id "aqxaKgpXMN3p_zkwXf25GgAAAJU"]
[Thu Sep 17 15:22:50.449798 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25HAAAALI"]
[Thu Sep 17 15:22:50.506045 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25IAAAAMc"]
[Thu Sep 17 15:22:50.561462 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25IgAAAMY"]
[Thu Sep 17 15:22:50.619750 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25IwAAAKM"]
[Thu Sep 17 15:22:50.624296 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.166.123.190:33488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/php.php"] [unique_id "aqxaKgpXMN3p_zkwXf25JAAAAN0"]
[Thu Sep 17 15:22:50.674475 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25JQAAAPE"]
[Thu Sep 17 15:22:50.674917 2026] [security2:error] [pid 1012520:tid 1012658] [client 140.238.42.111:61814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaKgpXMN3p_zkwXf25JgAAAIw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:50.684451 2026] [security2:error] [pid 1012520:tid 1012742] [client 62.113.113.162:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.113.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxaKgpXMN3p_zkwXf25JwAAAOA"], referer: https://melissa-gonzales.com/
[Thu Sep 17 15:22:50.728558 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25KQAAAPA"]
[Thu Sep 17 15:22:50.785497 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25KgAAANE"]
[Thu Sep 17 15:22:50.840010 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25LgAAAM8"]
[Thu Sep 17 15:22:50.897046 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25MAAAAMo"]
[Thu Sep 17 15:22:50.953839 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25MQAAANo"]
[Thu Sep 17 15:22:50.979824 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/.env"] [unique_id "aqxaKgpXMN3p_zkwXf25NAAAAQE"]
[Thu Sep 17 15:22:51.008085 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxaKwpXMN3p_zkwXf25NgAAAPY"]
[Thu Sep 17 15:22:51.063261 2026] [security2:error] [pid 1012520:tid 1012750] [client 140.238.42.111:62176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaKwpXMN3p_zkwXf25OQAAAOg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:51.063697 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxaKwpXMN3p_zkwXf25OAAAALo"]
[Thu Sep 17 15:22:51.122412 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.24.239.23:44412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxaKwpXMN3p_zkwXf25OwAAANA"]
[Thu Sep 17 15:22:51.184174 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.24.239.23:44412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxaKwpXMN3p_zkwXf25PQAAAPw"]
[Thu Sep 17 15:22:51.250204 2026] [security2:error] [pid 1012520:tid 1012746] [client 170.9.239.112:51320] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "streetwisepublicationsltd.com"] [uri "/tae"] [unique_id "aqxaKwpXMN3p_zkwXf25PwAAAOQ"], referer: http://taemp.co.uk/
[Thu Sep 17 15:22:51.306413 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.166.123.190:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/i.php"] [unique_id "aqxaKwpXMN3p_zkwXf25QAAAANk"]
[Thu Sep 17 15:22:51.364158 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.24.239.23:44426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/info.php"] [unique_id "aqxaKwpXMN3p_zkwXf25QwAAAJc"]
[Thu Sep 17 15:22:51.456565 2026] [security2:error] [pid 1012520:tid 1012766] [client 140.238.42.111:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaKwpXMN3p_zkwXf25RgAAAPg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:51.558463 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.24.239.23:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/php.php"] [unique_id "aqxaKwpXMN3p_zkwXf25TAAAAIY"]
[Thu Sep 17 15:22:51.757445 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.24.239.23:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/i.php"] [unique_id "aqxaKwpXMN3p_zkwXf25UQAAAJk"]
[Thu Sep 17 15:22:51.839047 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaKwpXMN3p_zkwXf25UgAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:51.962029 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.24.239.23:44442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxaKwpXMN3p_zkwXf25WgAAAMI"]
[Thu Sep 17 15:22:51.994131 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.166.123.190:52878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxaKwpXMN3p_zkwXf25WwAAAN8"]
[Thu Sep 17 15:22:52.163142 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.24.239.23:44456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxaLApXMN3p_zkwXf25YAAAAMQ"]
[Thu Sep 17 15:22:52.196836 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxaLApXMN3p_zkwXf25ZAAAAO8"]
[Thu Sep 17 15:22:52.224536 2026] [security2:error] [pid 1012520:tid 1012674] [client 140.238.42.111:63096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaLApXMN3p_zkwXf25ZgAAAJw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:52.360068 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.24.239.23:44462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/test.php"] [unique_id "aqxaLApXMN3p_zkwXf25bAAAAM0"]
[Thu Sep 17 15:22:52.360505 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxaLApXMN3p_zkwXf25awAAALg"]
[Thu Sep 17 15:22:52.609273 2026] [security2:error] [pid 1012520:tid 1012677] [client 140.238.42.111:63382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaLApXMN3p_zkwXf25dAAAAJ8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:52.638536 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.24.239.23:44472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/p.php"] [unique_id "aqxaLApXMN3p_zkwXf25dgAAAOA"]
[Thu Sep 17 15:22:52.690149 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.166.123.190:52886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxaLApXMN3p_zkwXf25egAAAMc"]
[Thu Sep 17 15:22:52.691756 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxaLApXMN3p_zkwXf25ewAAAM8"]
[Thu Sep 17 15:22:52.812615 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.24.239.23:44482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxaLApXMN3p_zkwXf25fgAAAMo"]
[Thu Sep 17 15:22:52.998152 2026] [security2:error] [pid 1012520:tid 1012704] [client 140.238.42.111:63674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaLApXMN3p_zkwXf25hAAAALo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:53.011922 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.24.239.23:44494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxaLQpXMN3p_zkwXf25hQAAAKs"]
[Thu Sep 17 15:22:53.165578 2026] [security2:error] [pid 1012520:tid 1012736] [client 154.190.208.131:41547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaLQpXMN3p_zkwXf25jAAAANo"]
[Thu Sep 17 15:22:53.174028 2026] [security2:error] [pid 1012520:tid 1012736] [client 154.190.208.131:41547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaLQpXMN3p_zkwXf25jAAAANo"]
[Thu Sep 17 15:22:53.211054 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.24.239.23:44498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxaLQpXMN3p_zkwXf25jgAAAQM"]
[Thu Sep 17 15:22:53.371691 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.166.123.190:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/test.php"] [unique_id "aqxaLQpXMN3p_zkwXf25kgAAAKo"]
[Thu Sep 17 15:22:53.388845 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.24.239.23:44512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxaLQpXMN3p_zkwXf25kwAAAJg"]
[Thu Sep 17 15:22:53.402134 2026] [security2:error] [pid 1012520:tid 1012679] [client 140.238.42.111:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaLQpXMN3p_zkwXf25lQAAAKE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:53.587906 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.24.239.23:44528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxaLQpXMN3p_zkwXf25oAAAAPo"]
[Thu Sep 17 15:22:53.761272 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.24.239.23:44542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaLQpXMN3p_zkwXf25owAAAOo"]
[Thu Sep 17 15:22:53.784949 2026] [security2:error] [pid 1012520:tid 1012710] [client 140.238.42.111:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaLQpXMN3p_zkwXf25pQAAAMA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:53.958623 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.24.239.23:44548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxaLQpXMN3p_zkwXf25rAAAAJ4"]
[Thu Sep 17 15:22:54.189533 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:64588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaLgpXMN3p_zkwXf25tQAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:54.194922 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.24.239.23:44554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxaLgpXMN3p_zkwXf25tgAAAKM"]
[Thu Sep 17 15:22:54.279497 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.166.123.190:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/p.php"] [unique_id "aqxaLgpXMN3p_zkwXf25uAAAALw"]
[Thu Sep 17 15:22:54.378240 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.24.239.23:44566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxaLgpXMN3p_zkwXf25uwAAAPM"]
[Thu Sep 17 15:22:54.531317 2026] [authz_core:error] [pid 1012520:tid 1012663] [client 5.189.145.112:58437] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:22:54.580644 2026] [security2:error] [pid 1012520:tid 1012661] [client 140.238.42.111:64909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaLgpXMN3p_zkwXf25xAAAAI8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:54.603889 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.24.239.23:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxaLgpXMN3p_zkwXf25xQAAAPY"]
[Thu Sep 17 15:22:54.653818 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxaLgpXMN3p_zkwXf25yAAAAL4"]
[Thu Sep 17 15:22:54.809521 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.24.239.23:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxaLgpXMN3p_zkwXf25zQAAANk"]
[Thu Sep 17 15:22:54.815857 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/.env~"] [unique_id "aqxaLgpXMN3p_zkwXf25zwAAAL8"]
[Thu Sep 17 15:22:54.966897 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.166.123.190:52912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxaLgpXMN3p_zkwXf251wAAAMM"]
[Thu Sep 17 15:22:54.967478 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaLgpXMN3p_zkwXf252AAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:54.996472 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.24.239.23:44604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxaLgpXMN3p_zkwXf253AAAAOI"]
[Thu Sep 17 15:22:55.188166 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.24.239.23:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxaLwpXMN3p_zkwXf254QAAAO0"]
[Thu Sep 17 15:22:55.363990 2026] [security2:error] [pid 1012520:tid 1012679] [client 140.238.42.111:65532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaLwpXMN3p_zkwXf255QAAAKE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:55.513163 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.24.239.23:44612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxaLwpXMN3p_zkwXf258AAAALQ"]
[Thu Sep 17 15:22:55.572135 2026] [security2:error] [pid 1012520:tid 1012722] [client 114.198.138.124:52884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaLwpXMN3p_zkwXf258gAAAMw"]
[Thu Sep 17 15:22:55.572242 2026] [security2:error] [pid 1012520:tid 1012722] [client 114.198.138.124:52884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaLwpXMN3p_zkwXf258gAAAMw"]
[Thu Sep 17 15:22:55.666389 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.166.123.190:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxaLwpXMN3p_zkwXf259QAAAJk"]
[Thu Sep 17 15:22:55.722529 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.24.239.23:44614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxaLwpXMN3p_zkwXf259wAAAQI"]
[Thu Sep 17 15:22:55.745458 2026] [security2:error] [pid 1012520:tid 1012703] [client 140.238.42.111:49457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaLwpXMN3p_zkwXf25-AAAALk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:55.747102 2026] [security2:error] [pid 1012520:tid 1012747] [client 103.61.184.148:51837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaLwpXMN3p_zkwXf25-QAAAOU"]
[Thu Sep 17 15:22:55.747171 2026] [security2:error] [pid 1012520:tid 1012747] [client 103.61.184.148:51837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaLwpXMN3p_zkwXf25-QAAAOU"]
[Thu Sep 17 15:22:55.936912 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.24.239.23:44626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxaLwpXMN3p_zkwXf26AAAAAP8"]
[Thu Sep 17 15:22:55.944670 2026] [security2:error] [pid 1012520:tid 1012721] [client 210.222.43.21:56682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxaLwpXMN3p_zkwXf25-gAAAMs"], referer: http://talent-in-borders.com/Backup
[Thu Sep 17 15:22:56.127067 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.24.239.23:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxaMApXMN3p_zkwXf26BwAAAOA"]
[Thu Sep 17 15:22:56.135530 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxaMApXMN3p_zkwXf26CAAAAOc"]
[Thu Sep 17 15:22:56.147052 2026] [security2:error] [pid 1012520:tid 1012677] [client 140.238.42.111:49785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaMApXMN3p_zkwXf26CQAAAJ8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:56.280976 2026] [security2:error] [pid 1012520:tid 1012695] [client 16.216.88.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxaLwpXMN3p_zkwXf26AQAAALE"]
[Thu Sep 17 15:22:56.297210 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxaMApXMN3p_zkwXf26DQAAAPQ"]
[Thu Sep 17 15:22:56.302829 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.24.239.23:44642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxaMApXMN3p_zkwXf26DgAAANA"]
[Thu Sep 17 15:22:56.370954 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.166.123.190:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxaMApXMN3p_zkwXf26DwAAALY"]
[Thu Sep 17 15:22:56.466598 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxaMApXMN3p_zkwXf26EwAAAKc"]
[Thu Sep 17 15:22:56.488249 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.24.239.23:44648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxaMApXMN3p_zkwXf26FAAAAJQ"]
[Thu Sep 17 15:22:56.511558 2026] [security2:error] [pid 1012520:tid 1012770] [client 185.55.149.49:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaMApXMN3p_zkwXf26GQAAAPw"]
[Thu Sep 17 15:22:56.511741 2026] [security2:error] [pid 1012520:tid 1012770] [client 185.55.149.49:61391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaMApXMN3p_zkwXf26GQAAAPw"]
[Thu Sep 17 15:22:56.539280 2026] [security2:error] [pid 1012520:tid 1012711] [client 140.238.42.111:50115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaMApXMN3p_zkwXf26GwAAAME"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:56.631691 2026] [security2:error] [pid 1012520:tid 1012764] [client 186.105.232.15:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaMApXMN3p_zkwXf26IAAAAPY"]
[Thu Sep 17 15:22:56.631801 2026] [security2:error] [pid 1012520:tid 1012764] [client 186.105.232.15:55878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaMApXMN3p_zkwXf26IAAAAPY"]
[Thu Sep 17 15:22:56.632345 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxaMApXMN3p_zkwXf26HwAAAKI"]
[Thu Sep 17 15:22:56.676647 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.24.239.23:44656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxaMApXMN3p_zkwXf26IwAAAQM"]
[Thu Sep 17 15:22:56.800603 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxaMApXMN3p_zkwXf26JQAAAJA"]
[Thu Sep 17 15:22:56.879820 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.24.239.23:44660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxaMApXMN3p_zkwXf26KAAAAO0"]
[Thu Sep 17 15:22:56.951983 2026] [security2:error] [pid 1012520:tid 1012688] [client 140.238.42.111:50415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaMApXMN3p_zkwXf26LAAAAKo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:56.970104 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxaMApXMN3p_zkwXf26MAAAALM"]
[Thu Sep 17 15:22:57.052208 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.166.123.190:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxaMQpXMN3p_zkwXf26MgAAAKY"]
[Thu Sep 17 15:22:57.085827 2026] [security2:error] [pid 1012520:tid 1012669] [client 138.246.253.24:40832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxaLwpXMN3p_zkwXf255AAAAJc"]
[Thu Sep 17 15:22:57.096391 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.24.239.23:44666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxaMQpXMN3p_zkwXf26NAAAANM"]
[Thu Sep 17 15:22:57.164289 2026] [security2:error] [pid 1012520:tid 1012766] [client 156.192.234.52:54870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaMQpXMN3p_zkwXf26NwAAAPg"]
[Thu Sep 17 15:22:57.165616 2026] [security2:error] [pid 1012520:tid 1012766] [client 156.192.234.52:54870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaMQpXMN3p_zkwXf26NwAAAPg"]
[Thu Sep 17 15:22:57.286483 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.24.239.23:44682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxaMQpXMN3p_zkwXf26OwAAAM0"]
[Thu Sep 17 15:22:57.303413 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxaMQpXMN3p_zkwXf26PAAAAIU"]
[Thu Sep 17 15:22:57.339033 2026] [security2:error] [pid 1012520:tid 1012747] [client 140.238.42.111:50743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaMQpXMN3p_zkwXf26PgAAAOU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:57.465022 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxaMQpXMN3p_zkwXf26SQAAAPM"]
[Thu Sep 17 15:22:57.479201 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.24.239.23:44698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxaMQpXMN3p_zkwXf26TAAAAOw"]
[Thu Sep 17 15:22:57.568106 2026] [security2:error] [pid 1012520:tid 1012706] [client 169.58.197.253:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxaMQpXMN3p_zkwXf26TgAAALw"], referer: binance.com
[Thu Sep 17 15:22:57.589642 2026] [security2:error] [pid 1012520:tid 1012660] [client 73.107.123.152:51739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaMQpXMN3p_zkwXf26SgAAjgY"]
[Thu Sep 17 15:22:57.635373 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxaMQpXMN3p_zkwXf26UAAAAL4"]
[Thu Sep 17 15:22:57.662835 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.24.239.23:44704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxaMQpXMN3p_zkwXf26UgAAAK8"]
[Thu Sep 17 15:22:57.735741 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.166.123.190:52936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxaMQpXMN3p_zkwXf26VAAAAJ8"]
[Thu Sep 17 15:22:57.765477 2026] [security2:error] [pid 1012520:tid 1012750] [client 140.238.42.111:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaMQpXMN3p_zkwXf26WAAAAOg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:57.796021 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxaMQpXMN3p_zkwXf26WQAAAOQ"]
[Thu Sep 17 15:22:57.848340 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.24.239.23:44532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxaMQpXMN3p_zkwXf26WwAAAPQ"]
[Thu Sep 17 15:22:57.957269 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxaMQpXMN3p_zkwXf26XQAAAME"]
[Thu Sep 17 15:22:58.057851 2026] [security2:error] [pid 1012520:tid 1012680] [client 34.24.239.23:44542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxaMgpXMN3p_zkwXf26YgAAAKI"]
[Thu Sep 17 15:22:58.127025 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxaMgpXMN3p_zkwXf26ZAAAAOE"]
[Thu Sep 17 15:22:58.163487 2026] [security2:error] [pid 1012520:tid 1012718] [client 140.238.42.111:51415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaMgpXMN3p_zkwXf26ZgAAAMg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:58.249994 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.24.239.23:44548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxaMgpXMN3p_zkwXf26ZwAAAPA"]
[Thu Sep 17 15:22:58.288260 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxaMgpXMN3p_zkwXf26agAAANg"]
[Thu Sep 17 15:22:58.428442 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.24.239.23:44552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxaMgpXMN3p_zkwXf26cAAAAN8"]
[Thu Sep 17 15:22:58.428452 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.166.123.190:52950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaMgpXMN3p_zkwXf26cQAAAJA"]
[Thu Sep 17 15:22:58.449936 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxaMgpXMN3p_zkwXf26cgAAAPs"]
[Thu Sep 17 15:22:58.473854 2026] [security2:error] [pid 1012520:tid 1012669] [client 192.178.6.3:46732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxaMgpXMN3p_zkwXf26dQAAAJc"]
[Thu Sep 17 15:22:58.560324 2026] [security2:error] [pid 1012520:tid 1012753] [client 140.238.42.111:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaMgpXMN3p_zkwXf26egAAAOs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:58.609938 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxaMgpXMN3p_zkwXf26fwAAAOM"]
[Thu Sep 17 15:22:58.630560 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.24.239.23:44566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxaMgpXMN3p_zkwXf26ggAAAIU"]
[Thu Sep 17 15:22:58.782902 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxaMgpXMN3p_zkwXf26iwAAAKk"]
[Thu Sep 17 15:22:58.838471 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.24.239.23:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxaMgpXMN3p_zkwXf26jQAAAKM"]
[Thu Sep 17 15:22:58.946316 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxaMgpXMN3p_zkwXf26kgAAANQ"]
[Thu Sep 17 15:22:58.958292 2026] [security2:error] [pid 1012520:tid 1012695] [client 140.238.42.111:52112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaMgpXMN3p_zkwXf26lQAAALE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:59.050570 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.24.239.23:44578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxaMwpXMN3p_zkwXf26nAAAANk"]
[Thu Sep 17 15:22:59.082549 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/.env"] [unique_id "aqxaMwpXMN3p_zkwXf26nQAAAPw"]
[Thu Sep 17 15:22:59.108917 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.166.123.190:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxaMwpXMN3p_zkwXf26nwAAAQQ"]
[Thu Sep 17 15:22:59.109190 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxaMwpXMN3p_zkwXf26ngAAAKQ"]
[Thu Sep 17 15:22:59.235962 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.24.239.23:44590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxaMwpXMN3p_zkwXf26pAAAAKg"]
[Thu Sep 17 15:22:59.275009 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxaMwpXMN3p_zkwXf26pgAAAPc"]
[Thu Sep 17 15:22:59.367244 2026] [security2:error] [pid 1012520:tid 1012736] [client 140.238.42.111:52461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaMwpXMN3p_zkwXf26qgAAANo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:59.437021 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxaMwpXMN3p_zkwXf26rwAAANw"]
[Thu Sep 17 15:22:59.445209 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.24.239.23:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxaMwpXMN3p_zkwXf26sAAAALU"]
[Thu Sep 17 15:22:59.600238 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxaMwpXMN3p_zkwXf26uwAAAOk"]
[Thu Sep 17 15:22:59.634654 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.24.239.23:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxaMwpXMN3p_zkwXf26vQAAAJc"]
[Thu Sep 17 15:22:59.750325 2026] [security2:error] [pid 1012520:tid 1012776] [client 140.238.42.111:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaMwpXMN3p_zkwXf26wQAAAQI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:22:59.767443 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxaMwpXMN3p_zkwXf26wgAAAP8"]
[Thu Sep 17 15:22:59.841893 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.24.239.23:44620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxaMwpXMN3p_zkwXf26xwAAAIs"]
[Thu Sep 17 15:22:59.929097 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxaMwpXMN3p_zkwXf26zAAAAMo"]
[Thu Sep 17 15:22:59.945135 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/.env.bak"] [unique_id "aqxaMwpXMN3p_zkwXf26zQAAAQE"]
[Thu Sep 17 15:23:00.006987 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/.env.backup"] [unique_id "aqxaNApXMN3p_zkwXf260QAAAKk"]
[Thu Sep 17 15:23:00.028020 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.24.239.23:44626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxaNApXMN3p_zkwXf260wAAAOA"]
[Thu Sep 17 15:23:00.039217 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.166.123.190:52966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxaNApXMN3p_zkwXf261AAAAKM"]
[Thu Sep 17 15:23:00.097253 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxaNApXMN3p_zkwXf261wAAANQ"]
[Thu Sep 17 15:23:00.160229 2026] [security2:error] [pid 1012520:tid 1012693] [client 140.238.42.111:53127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaNApXMN3p_zkwXf262wAAAK8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:00.193649 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/.env.old"] [unique_id "aqxaNApXMN3p_zkwXf263AAAANk"]
[Thu Sep 17 15:23:00.239878 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.24.239.23:44628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.239.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.isa.brn.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxaNApXMN3p_zkwXf263QAAANE"]
[Thu Sep 17 15:23:00.265107 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxaNApXMN3p_zkwXf264AAAAOI"]
[Thu Sep 17 15:23:00.431378 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxaNApXMN3p_zkwXf267wAAANg"]
[Thu Sep 17 15:23:00.474544 2026] [fcgid:warn] [pid 1012520:tid 1012699] (70014)End of file found: [client 152.32.183.236:52374] mod_fcgid: can't get data from http client
[Thu Sep 17 15:23:00.548182 2026] [security2:error] [pid 1012520:tid 1012736] [client 140.238.42.111:53479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaNApXMN3p_zkwXf26_QAAANo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:00.603912 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxaNApXMN3p_zkwXf27AAAAAMQ"]
[Thu Sep 17 15:23:00.639648 2026] [security2:error] [pid 1012520:tid 1012703] [client 209.141.32.143:33708] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "growthhacking4recruitment.com"] [uri "/wp-content/plugins/jetformbuilder/readme.txt"] [unique_id "aqxaNApXMN3p_zkwXf27AgAAALk"]
[Thu Sep 17 15:23:00.723811 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.166.123.190:52982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxaNApXMN3p_zkwXf27CQAAAJA"]
[Thu Sep 17 15:23:00.770094 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxaNApXMN3p_zkwXf27DAAAAIo"]
[Thu Sep 17 15:23:00.932940 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxaNApXMN3p_zkwXf27GQAAAL4"]
[Thu Sep 17 15:23:00.947530 2026] [security2:error] [pid 1012520:tid 1012676] [client 140.238.42.111:53807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaNApXMN3p_zkwXf27GwAAAJ4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:01.093841 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxaNQpXMN3p_zkwXf27KgAAAIY"]
[Thu Sep 17 15:23:01.121619 2026] [security2:error] [pid 1012520:tid 1012727] [client 127.0.0.1:33404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxaNQpXMN3p_zkwXf27KQAAANE"]
[Thu Sep 17 15:23:01.121708 2026] [security2:error] [pid 1012520:tid 1012770] [client 127.0.0.1:33400] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.cmf.uqc.mybluehost.me"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxaNQpXMN3p_zkwXf27KAAAAPw"]
[Thu Sep 17 15:23:01.121942 2026] [security2:error] [pid 1012520:tid 1012762] [client 74.7.228.44:58766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.cmf.uqc.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxaNQpXMN3p_zkwXf27JwAA9Eg"]
[Thu Sep 17 15:23:01.262401 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxaNQpXMN3p_zkwXf27NwAAAJM"]
[Thu Sep 17 15:23:01.333284 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:54157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaNQpXMN3p_zkwXf27PAAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:01.430646 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.166.123.190:39550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxaNQpXMN3p_zkwXf27QAAAAKQ"]
[Thu Sep 17 15:23:01.432928 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxaNQpXMN3p_zkwXf27QQAAAOk"]
[Thu Sep 17 15:23:01.516364 2026] [autoindex:error] [pid 1012520:tid 1012714] [client 34.24.239.23:44638] AH01276: Cannot serve directory /home1/isabrnmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:23:01.566012 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/.env.swp"] [unique_id "aqxaNQpXMN3p_zkwXf27SgAAAOg"]
[Thu Sep 17 15:23:01.594081 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxaNQpXMN3p_zkwXf27SwAAAP8"]
[Thu Sep 17 15:23:01.621037 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/.env~"] [unique_id "aqxaNQpXMN3p_zkwXf27TAAAAOM"]
[Thu Sep 17 15:23:01.716856 2026] [security2:error] [pid 1012520:tid 1012776] [client 140.238.42.111:54450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaNQpXMN3p_zkwXf27UAAAAQI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:01.760915 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxaNQpXMN3p_zkwXf27UgAAALA"]
[Thu Sep 17 15:23:01.924410 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxaNQpXMN3p_zkwXf27VwAAAKA"]
[Thu Sep 17 15:23:02.096552 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27ZAAAANA"]
[Thu Sep 17 15:23:02.101396 2026] [security2:error] [pid 1012520:tid 1012763] [client 140.238.42.111:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaNgpXMN3p_zkwXf27ZQAAAPU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:02.113897 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.166.123.190:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxaNgpXMN3p_zkwXf27ZwAAAPM"]
[Thu Sep 17 15:23:02.258349 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27bgAAAJs"]
[Thu Sep 17 15:23:02.399153 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/app/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27fgAAAPY"]
[Thu Sep 17 15:23:02.422521 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27gAAAANg"]
[Thu Sep 17 15:23:02.453959 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/apps/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27gQAAAMM"]
[Thu Sep 17 15:23:02.499410 2026] [security2:error] [pid 1012520:tid 1012675] [client 140.238.42.111:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaNgpXMN3p_zkwXf27hAAAAJ0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:02.509114 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/api/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27hQAAALU"]
[Thu Sep 17 15:23:02.572984 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/web/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27igAAANQ"]
[Thu Sep 17 15:23:02.580638 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27iwAAAOk"]
[Thu Sep 17 15:23:02.627781 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/site/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27jAAAAI0"]
[Thu Sep 17 15:23:02.690311 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/public/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27jgAAALk"]
[Thu Sep 17 15:23:02.743696 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27jwAAALs"]
[Thu Sep 17 15:23:02.801346 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.166.123.190:39566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxaNgpXMN3p_zkwXf27lAAAAKQ"]
[Thu Sep 17 15:23:02.890304 2026] [security2:error] [pid 1012520:tid 1012653] [client 140.238.42.111:55402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaNgpXMN3p_zkwXf27lgAAAIc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:02.906547 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27lwAAAQA"]
[Thu Sep 17 15:23:02.941330 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/backend/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27mAAAAJA"]
[Thu Sep 17 15:23:02.969954 2026] [security2:error] [pid 1012520:tid 1012710] [client 216.73.217.36:61913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sd-yaranaturals.24eastyard.com"] [uri "/index.php/robots.txt"] [unique_id "aqxaNgpXMN3p_zkwXf27kgAAwHQ"]
[Thu Sep 17 15:23:02.994841 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/server/.env"] [unique_id "aqxaNgpXMN3p_zkwXf27nQAAAIo"]
[Thu Sep 17 15:23:03.030930 2026] [autoindex:error] [pid 1012520:tid 1012729] [client 107.150.104.176:60526] AH01276: Cannot serve directory /home1/gnqazemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:23:03.048798 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/frontend/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27oQAAAIs"]
[Thu Sep 17 15:23:03.063824 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27ogAAAIU"]
[Thu Sep 17 15:23:03.103525 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/src/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27pgAAAJw"]
[Thu Sep 17 15:23:03.159610 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/core/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27qAAAAOw"]
[Thu Sep 17 15:23:03.215525 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/core/app/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27qgAAAMo"]
[Thu Sep 17 15:23:03.221948 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27qwAAAOA"]
[Thu Sep 17 15:23:03.269522 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/config/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27uwAAAJI"]
[Thu Sep 17 15:23:03.270127 2026] [security2:error] [pid 1012520:tid 1012691] [client 140.238.42.111:55699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaNwpXMN3p_zkwXf27vAAAAK0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:03.324632 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/private/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27vQAAALw"]
[Thu Sep 17 15:23:03.379049 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/application/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27zgAAAPQ"]
[Thu Sep 17 15:23:03.380382 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.92.151.55:40834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxaNwpXMN3p_zkwXf27zwAAAJs"]
[Thu Sep 17 15:23:03.434801 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/bootstrap/.env"] [unique_id "aqxaNwpXMN3p_zkwXf270AAAANI"]
[Thu Sep 17 15:23:03.477812 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.166.123.190:39580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxaNwpXMN3p_zkwXf270wAAAPU"]
[Thu Sep 17 15:23:03.489550 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/database/.env"] [unique_id "aqxaNwpXMN3p_zkwXf271AAAAOE"]
[Thu Sep 17 15:23:03.505330 2026] [security2:error] [pid 1012520:tid 1012739] [client 216.73.217.36:61913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sd-yaranaturals.24eastyard.com"] [uri "/index.php/sitemap.xml"] [unique_id "aqxaNwpXMN3p_zkwXf27zQAA3WU"]
[Thu Sep 17 15:23:03.544616 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/storage/.env"] [unique_id "aqxaNwpXMN3p_zkwXf272AAAANg"]
[Thu Sep 17 15:23:03.599906 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/var/www/.env"] [unique_id "aqxaNwpXMN3p_zkwXf273AAAANw"]
[Thu Sep 17 15:23:03.656350 2026] [security2:error] [pid 1012520:tid 1012721] [client 140.238.42.111:56023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaNwpXMN3p_zkwXf273wAAAMs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:03.658255 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/var/www/html/.env"] [unique_id "aqxaNwpXMN3p_zkwXf274AAAANQ"]
[Thu Sep 17 15:23:03.720941 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/current/.env"] [unique_id "aqxaNwpXMN3p_zkwXf275gAAAO0"]
[Thu Sep 17 15:23:03.723110 2026] [security2:error] [pid 1012520:tid 1012713] [client 103.239.15.83:50700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaNwpXMN3p_zkwXf272gAAw1M"]
[Thu Sep 17 15:23:03.780345 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/release/.env"] [unique_id "aqxaNwpXMN3p_zkwXf276AAAALs"]
[Thu Sep 17 15:23:03.837643 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/releases/.env"] [unique_id "aqxaNwpXMN3p_zkwXf276gAAAMg"]
[Thu Sep 17 15:23:03.872005 2026] [security2:error] [pid 1012520:tid 1012744] [client 209.59.76.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxaNgpXMN3p_zkwXf27cwAAAOI"], referer: http://m.facebook.com
[Thu Sep 17 15:23:03.877861 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxaNwpXMN3p_zkwXf277QAAAKE"]
[Thu Sep 17 15:23:03.891287 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/shared/.env"] [unique_id "aqxaNwpXMN3p_zkwXf277wAAANc"]
[Thu Sep 17 15:23:03.945465 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/deploy/.env"] [unique_id "aqxaNwpXMN3p_zkwXf278gAAAPA"]
[Thu Sep 17 15:23:03.999611 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/build/.env"] [unique_id "aqxaNwpXMN3p_zkwXf279QAAAQI"]
[Thu Sep 17 15:23:04.039436 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxaOApXMN3p_zkwXf27-AAAAJA"]
[Thu Sep 17 15:23:04.043985 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaOApXMN3p_zkwXf27-QAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:04.058723 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/dist/.env"] [unique_id "aqxaOApXMN3p_zkwXf27-gAAAMA"]
[Thu Sep 17 15:23:04.070866 2026] [security2:error] [pid 1012520:tid 1012724] [client 154.190.208.131:42134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOApXMN3p_zkwXf27-wAAAM4"]
[Thu Sep 17 15:23:04.079335 2026] [security2:error] [pid 1012520:tid 1012724] [client 154.190.208.131:42134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOApXMN3p_zkwXf27-wAAAM4"]
[Thu Sep 17 15:23:04.112977 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/public_html/.env"] [unique_id "aqxaOApXMN3p_zkwXf27_AAAANM"]
[Thu Sep 17 15:23:04.168535 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/htdocs/.env"] [unique_id "aqxaOApXMN3p_zkwXf27_wAAAPs"]
[Thu Sep 17 15:23:04.202168 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxaOApXMN3p_zkwXf28AAAAALA"]
[Thu Sep 17 15:23:04.226827 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/www/.env"] [unique_id "aqxaOApXMN3p_zkwXf28AgAAAL4"]
[Thu Sep 17 15:23:04.282994 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/html/.env"] [unique_id "aqxaOApXMN3p_zkwXf28BAAAAMo"]
[Thu Sep 17 15:23:04.337365 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/live/.env"] [unique_id "aqxaOApXMN3p_zkwXf28BQAAAQE"]
[Thu Sep 17 15:23:04.362314 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxaOApXMN3p_zkwXf28BgAAANA"]
[Thu Sep 17 15:23:04.391487 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/prod/.env"] [unique_id "aqxaOApXMN3p_zkwXf28DQAAAOU"]
[Thu Sep 17 15:23:04.425385 2026] [security2:error] [pid 1012520:tid 1012742] [client 140.238.42.111:56673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaOApXMN3p_zkwXf28DgAAAOA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:04.447504 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/dev/.env"] [unique_id "aqxaOApXMN3p_zkwXf28DwAAALw"]
[Thu Sep 17 15:23:04.501266 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/staging/.env"] [unique_id "aqxaOApXMN3p_zkwXf28FAAAANk"]
[Thu Sep 17 15:23:04.519400 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxaOApXMN3p_zkwXf28FQAAAKk"]
[Thu Sep 17 15:23:04.554972 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/opt/.env"] [unique_id "aqxaOApXMN3p_zkwXf28FwAAAI4"]
[Thu Sep 17 15:23:04.609988 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/laravel/.env"] [unique_id "aqxaOApXMN3p_zkwXf28GgAAANE"]
[Thu Sep 17 15:23:04.619706 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.166.123.190:39584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxaOApXMN3p_zkwXf28GwAAAKs"]
[Thu Sep 17 15:23:04.664009 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.23.198.186:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/symfony/.env"] [unique_id "aqxaOApXMN3p_zkwXf28HQAAAKc"]
[Thu Sep 17 15:23:04.682115 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxaOApXMN3p_zkwXf28HgAAALE"]
[Thu Sep 17 15:23:04.808060 2026] [security2:error] [pid 1012520:tid 1012658] [client 140.238.42.111:56983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaOApXMN3p_zkwXf28IAAAAIw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:04.829451 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/wordpress/.env"] [unique_id "aqxaOApXMN3p_zkwXf28IQAAALY"]
[Thu Sep 17 15:23:04.838748 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxaOApXMN3p_zkwXf28IgAAAOE"]
[Thu Sep 17 15:23:04.885705 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/wp/.env"] [unique_id "aqxaOApXMN3p_zkwXf28IwAAALQ"]
[Thu Sep 17 15:23:04.938962 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/cms/.env"] [unique_id "aqxaOApXMN3p_zkwXf28KgAAAMs"]
[Thu Sep 17 15:23:04.996513 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/drupal/.env"] [unique_id "aqxaOApXMN3p_zkwXf28LgAAAMM"]
[Thu Sep 17 15:23:04.999195 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxaOApXMN3p_zkwXf28LwAAALk"]
[Thu Sep 17 15:23:05.049726 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/joomla/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28MgAAAOg"]
[Thu Sep 17 15:23:05.103783 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/magento/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28MwAAAPc"]
[Thu Sep 17 15:23:05.156641 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/shopify/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28NwAAAMk"]
[Thu Sep 17 15:23:05.156641 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28NgAAAQM"]
[Thu Sep 17 15:23:05.191125 2026] [security2:error] [pid 1012520:tid 1012705] [client 140.238.42.111:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaOQpXMN3p_zkwXf28OAAAALs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:05.209930 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/prestashop/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28OQAAANo"]
[Thu Sep 17 15:23:05.257166 2026] [fcgid:warn] [pid 1012520:tid 1012744] (70014)End of file found: [client 107.150.104.176:52160] mod_fcgid: can't get data from http client
[Thu Sep 17 15:23:05.264895 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/codeigniter/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28OwAAAP8"]
[Thu Sep 17 15:23:05.318271 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28PQAAAOM"]
[Thu Sep 17 15:23:05.323070 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/cakephp/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28PgAAAQQ"]
[Thu Sep 17 15:23:05.379192 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/zend/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28PwAAALc"]
[Thu Sep 17 15:23:05.392574 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.166.123.190:39586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxaOQpXMN3p_zkwXf28QAAAAKQ"]
[Thu Sep 17 15:23:05.443968 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/yii/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28QQAAAKg"]
[Thu Sep 17 15:23:05.483106 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28QwAAAMQ"]
[Thu Sep 17 15:23:05.501708 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/laravel5/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28RgAAAQI"]
[Thu Sep 17 15:23:05.555993 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/v1/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28SAAAALM"]
[Thu Sep 17 15:23:05.559500 2026] [fcgid:warn] [pid 1012520:tid 1012672] (70014)End of file found: [client 152.32.158.219:54426] mod_fcgid: can't get data from http client
[Thu Sep 17 15:23:05.576895 2026] [security2:error] [pid 1012520:tid 1012671] [client 140.238.42.111:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaOQpXMN3p_zkwXf28SgAAAJk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:05.614205 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/v2/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28SwAAAMA"]
[Thu Sep 17 15:23:05.643654 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28TwAAALI"]
[Thu Sep 17 15:23:05.675642 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/v3/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28UAAAANM"]
[Thu Sep 17 15:23:05.738214 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/api/v1/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28UgAAAPs"]
[Thu Sep 17 15:23:05.800304 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/api/v2/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28VAAAAKA"]
[Thu Sep 17 15:23:05.811193 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28VQAAAJg"]
[Thu Sep 17 15:23:05.877362 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/rest/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28VgAAAOw"]
[Thu Sep 17 15:23:05.941726 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/graphql/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28WAAAAN8"]
[Thu Sep 17 15:23:05.971232 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxaOQpXMN3p_zkwXf28WwAAAQE"]
[Thu Sep 17 15:23:05.991943 2026] [security2:error] [pid 1012520:tid 1012674] [client 140.238.42.111:57886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaOQpXMN3p_zkwXf28XAAAAJw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:06.007475 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/gateway/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28XgAAAJI"]
[Thu Sep 17 15:23:06.069654 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/microservice/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28YAAAAK0"]
[Thu Sep 17 15:23:06.074795 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.166.123.190:39592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxaOgpXMN3p_zkwXf28YQAAAOc"]
[Thu Sep 17 15:23:06.134304 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/service/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28YgAAAJ4"]
[Thu Sep 17 15:23:06.136798 2026] [security2:error] [pid 1012520:tid 1012692] [client 114.198.138.124:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOgpXMN3p_zkwXf28ZAAAAK4"]
[Thu Sep 17 15:23:06.136891 2026] [security2:error] [pid 1012520:tid 1012692] [client 114.198.138.124:53532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOgpXMN3p_zkwXf28ZAAAAK4"]
[Thu Sep 17 15:23:06.143318 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28ZQAAAKk"]
[Thu Sep 17 15:23:06.195108 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/api/v3/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28ZwAAAKY"]
[Thu Sep 17 15:23:06.255702 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/api/dev/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28aQAAAKs"]
[Thu Sep 17 15:23:06.308078 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28awAAAPw"]
[Thu Sep 17 15:23:06.310717 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/api/staging/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28bQAAAME"]
[Thu Sep 17 15:23:06.373833 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/vendor/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28bgAAAPU"]
[Thu Sep 17 15:23:06.384266 2026] [security2:error] [pid 1012520:tid 1012727] [client 140.238.42.111:58244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaOgpXMN3p_zkwXf28bwAAANE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:06.433565 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/lib/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28cAAAAOQ"]
[Thu Sep 17 15:23:06.468158 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28cgAAAJM"]
[Thu Sep 17 15:23:06.487880 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/resources/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28dQAAAJE"]
[Thu Sep 17 15:23:06.550737 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/assets/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28dwAAAI0"]
[Thu Sep 17 15:23:06.611188 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/uploads/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28eAAAAOk"]
[Thu Sep 17 15:23:06.650389 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28egAAAM8"]
[Thu Sep 17 15:23:06.665172 2026] [security2:error] [pid 1012520:tid 1012693] [client 103.61.184.148:52407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOgpXMN3p_zkwXf28fAAAAK8"]
[Thu Sep 17 15:23:06.665278 2026] [security2:error] [pid 1012520:tid 1012693] [client 103.61.184.148:52407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOgpXMN3p_zkwXf28fAAAAK8"]
[Thu Sep 17 15:23:06.671136 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/internal/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28fQAAAPc"]
[Thu Sep 17 15:23:06.731446 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/tools/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28fgAAAMg"]
[Thu Sep 17 15:23:06.768142 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.166.123.190:39596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxaOgpXMN3p_zkwXf28jAAAAL0"]
[Thu Sep 17 15:23:06.768396 2026] [security2:error] [pid 1012520:tid 1012703] [client 140.238.42.111:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaOgpXMN3p_zkwXf28jQAAALk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:06.788744 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/scripts/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28jgAAAPg"]
[Thu Sep 17 15:23:06.813808 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28kAAAAMk"]
[Thu Sep 17 15:23:06.846943 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/bin/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28kQAAAQM"]
[Thu Sep 17 15:23:06.899481 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/sbin/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28lAAAALs"]
[Thu Sep 17 15:23:06.952355 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/local/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28lwAAAKw"]
[Thu Sep 17 15:23:06.970506 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxaOgpXMN3p_zkwXf28mwAAAQQ"]
[Thu Sep 17 15:23:06.977708 2026] [security2:error] [pid 1012520:tid 1012701] [client 169.58.197.253:61702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxaOgpXMN3p_zkwXf28nAAAALc"], referer: binance.com
[Thu Sep 17 15:23:06.988818 2026] [security2:error] [pid 1012520:tid 1012686] [client 85.204.70.90:60164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxaOgpXMN3p_zkwXf28ngAAAKg"]
[Thu Sep 17 15:23:07.006134 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/portal/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28oAAAAQA"]
[Thu Sep 17 15:23:07.058397 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/dashboard/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28pgAAANM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:23:07.112589 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/panel/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28pwAAAJ8"]
[Thu Sep 17 15:23:07.142998 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28qAAAAJg"]
[Thu Sep 17 15:23:07.153132 2026] [security2:error] [pid 1012520:tid 1012710] [client 140.238.42.111:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaOwpXMN3p_zkwXf28qQAAAMA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:07.166315 2026] [security2:error] [pid 1012520:tid 1012669] [client 185.55.149.49:62157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaOwpXMN3p_zkwXf28qgAAAJc"]
[Thu Sep 17 15:23:07.166458 2026] [security2:error] [pid 1012520:tid 1012669] [client 185.55.149.49:62157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaOwpXMN3p_zkwXf28qgAAAJc"]
[Thu Sep 17 15:23:07.167814 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/crm/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28qwAAALA"]
[Thu Sep 17 15:23:07.221698 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/erp/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28rQAAAOw"]
[Thu Sep 17 15:23:07.274912 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/shop/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28sAAAAJI"]
[Thu Sep 17 15:23:07.303956 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28sgAAAOc"]
[Thu Sep 17 15:23:07.334550 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/store/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28tAAAAOA"]
[Thu Sep 17 15:23:07.392460 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/saas/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28twAAANk"]
[Thu Sep 17 15:23:07.453398 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/client/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28uQAAAJU"]
[Thu Sep 17 15:23:07.462470 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.166.123.190:39612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxaOwpXMN3p_zkwXf28ugAAAPo"]
[Thu Sep 17 15:23:07.473159 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28uwAAANA"]
[Thu Sep 17 15:23:07.508031 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/project/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28vwAAAMY"]
[Thu Sep 17 15:23:07.544107 2026] [security2:error] [pid 1012520:tid 1012692] [client 140.238.42.111:59201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaOwpXMN3p_zkwXf28wQAAAK4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:07.571602 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/admin-panel/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28xAAAAIk"]
[Thu Sep 17 15:23:07.574538 2026] [security2:error] [pid 1012520:tid 1012775] [client 85.204.70.90:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "creacity.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOwpXMN3p_zkwXf28wwAAAQE"]
[Thu Sep 17 15:23:07.628559 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/control-panel/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28xwAAAME"]
[Thu Sep 17 15:23:07.637525 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28yAAAALE"]
[Thu Sep 17 15:23:07.682382 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/user-panel/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28ywAAAJY"]
[Thu Sep 17 15:23:07.690412 2026] [security2:error] [pid 1012520:tid 1012691] [client 156.192.234.52:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOwpXMN3p_zkwXf28zAAAAK0"]
[Thu Sep 17 15:23:07.692086 2026] [security2:error] [pid 1012520:tid 1012691] [client 156.192.234.52:55499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaOwpXMN3p_zkwXf28zAAAAK0"]
[Thu Sep 17 15:23:07.739984 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/node/.env"] [unique_id "aqxaOwpXMN3p_zkwXf28zgAAAPQ"]
[Thu Sep 17 15:23:07.805055 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/express/.env"] [unique_id "aqxaOwpXMN3p_zkwXf280QAAAPY"]
[Thu Sep 17 15:23:07.809966 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxaOwpXMN3p_zkwXf280gAAAJM"]
[Thu Sep 17 15:23:07.862229 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/next/.env"] [unique_id "aqxaOwpXMN3p_zkwXf281QAAAMs"]
[Thu Sep 17 15:23:07.920460 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/nuxt/.env"] [unique_id "aqxaOwpXMN3p_zkwXf281wAAAP0"]
[Thu Sep 17 15:23:07.931473 2026] [security2:error] [pid 1012520:tid 1012738] [client 140.238.42.111:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaOwpXMN3p_zkwXf282AAAANw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:07.972138 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxaOwpXMN3p_zkwXf283AAAAOo"]
[Thu Sep 17 15:23:07.979452 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/nest/.env"] [unique_id "aqxaOwpXMN3p_zkwXf283QAAAJ0"]
[Thu Sep 17 15:23:08.037761 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/react/.env"] [unique_id "aqxaPApXMN3p_zkwXf284AAAAMg"]
[Thu Sep 17 15:23:08.097083 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/vue/.env"] [unique_id "aqxaPApXMN3p_zkwXf285QAAAMk"]
[Thu Sep 17 15:23:08.133038 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxaPApXMN3p_zkwXf286AAAAO0"]
[Thu Sep 17 15:23:08.159324 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.166.123.190:39622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxaPApXMN3p_zkwXf287AAAAMM"]
[Thu Sep 17 15:23:08.159701 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/angular/.env"] [unique_id "aqxaPApXMN3p_zkwXf286wAAAKw"]
[Thu Sep 17 15:23:08.218700 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/svelte/.env"] [unique_id "aqxaPApXMN3p_zkwXf287QAAAKg"]
[Thu Sep 17 15:23:08.276100 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/vite/.env"] [unique_id "aqxaPApXMN3p_zkwXf288AAAAKQ"]
[Thu Sep 17 15:23:08.290744 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxaPApXMN3p_zkwXf288QAAAOM"]
[Thu Sep 17 15:23:08.308256 2026] [security2:error] [pid 1012520:tid 1012697] [client 85.204.70.90:60172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxaPApXMN3p_zkwXf288gAAALM"]
[Thu Sep 17 15:23:08.328956 2026] [security2:error] [pid 1012520:tid 1012778] [client 140.238.42.111:59856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaPApXMN3p_zkwXf288wAAAQQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:08.333218 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/backup/.env"] [unique_id "aqxaPApXMN3p_zkwXf289AAAAJo"]
[Thu Sep 17 15:23:08.387217 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/backups/.env"] [unique_id "aqxaPApXMN3p_zkwXf289QAAANM"]
[Thu Sep 17 15:23:08.444723 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/old/.env"] [unique_id "aqxaPApXMN3p_zkwXf289wAAAO4"]
[Thu Sep 17 15:23:08.453009 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxaPApXMN3p_zkwXf28-AAAAM4"]
[Thu Sep 17 15:23:08.504250 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/tmp/.env"] [unique_id "aqxaPApXMN3p_zkwXf28_QAAAM0"]
[Thu Sep 17 15:23:08.562237 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/temp/.env"] [unique_id "aqxaPApXMN3p_zkwXf28_wAAAP8"]
[Thu Sep 17 15:23:08.595439 2026] [security2:error] [pid 1012520:tid 1012701] [client 186.105.232.15:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaPApXMN3p_zkwXf29AwAAALc"]
[Thu Sep 17 15:23:08.595565 2026] [security2:error] [pid 1012520:tid 1012701] [client 186.105.232.15:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaPApXMN3p_zkwXf29AwAAALc"]
[Thu Sep 17 15:23:08.611869 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxaPApXMN3p_zkwXf29BAAAAL4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:23:08.615064 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/lab/.env"] [unique_id "aqxaPApXMN3p_zkwXf29BgAAAJI"]
[Thu Sep 17 15:23:08.671197 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/cronlab/.env"] [unique_id "aqxaPApXMN3p_zkwXf29CQAAAKM"]
[Thu Sep 17 15:23:08.734863 2026] [security2:error] [pid 1012520:tid 1012710] [client 140.238.42.111:60192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaPApXMN3p_zkwXf29DQAAAMA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:08.748032 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/cron/.env"] [unique_id "aqxaPApXMN3p_zkwXf29DgAAAPo"]
[Thu Sep 17 15:23:08.780094 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxaPApXMN3p_zkwXf29DwAAAP4"]
[Thu Sep 17 15:23:08.810961 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/en/.env"] [unique_id "aqxaPApXMN3p_zkwXf29EAAAAMY"]
[Thu Sep 17 15:23:08.838094 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.166.123.190:39630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxaPApXMN3p_zkwXf29EgAAAJc"]
[Thu Sep 17 15:23:08.893416 2026] [security2:error] [pid 1012520:tid 1012694] [client 85.204.70.90:60174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxaPApXMN3p_zkwXf29FAAAALA"]
[Thu Sep 17 15:23:08.919978 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/administrator/.env"] [unique_id "aqxaPApXMN3p_zkwXf29EwAAAQE"]
[Thu Sep 17 15:23:08.937899 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxaPApXMN3p_zkwXf29FgAAAME"]
[Thu Sep 17 15:23:08.983243 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/psnlink/.env"] [unique_id "aqxaPApXMN3p_zkwXf29GQAAAIw"]
[Thu Sep 17 15:23:09.041995 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/exapi/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29HwAAAPQ"]
[Thu Sep 17 15:23:09.098849 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/sitemaps/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29IQAAALQ"]
[Thu Sep 17 15:23:09.120972 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29IgAAAJE"]
[Thu Sep 17 15:23:09.127111 2026] [security2:error] [pid 1012520:tid 1012720] [client 140.238.42.111:60515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaPQpXMN3p_zkwXf29IwAAAMo"], referer: https://uniquespeechtechniques.com/wp-login.php
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:23:09.278949 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29LQAAAO0"]
[Thu Sep 17 15:23:09.400150 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.23.198.186:45704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/logs/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29MQAAAQI"]
[Thu Sep 17 15:23:09.444200 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29NAAAAKQ"]
[Thu Sep 17 15:23:09.471155 2026] [security2:error] [pid 1012520:tid 1012752] [client 85.204.70.90:60190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxaPQpXMN3p_zkwXf29NwAAAOo"]
[Thu Sep 17 15:23:09.504769 2026] [security2:error] [pid 1012520:tid 1012774] [client 140.238.42.111:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaPQpXMN3p_zkwXf29OwAAAQA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:09.533972 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.166.123.190:39636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxaPQpXMN3p_zkwXf29PAAAAI8"]
[Thu Sep 17 15:23:09.572277 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/cache/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29PwAAAJk"]
[Thu Sep 17 15:23:09.604815 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29QAAAAMc"]
[Thu Sep 17 15:23:09.633055 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mailer/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29QQAAAPs"]
[Thu Sep 17 15:23:09.697179 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mail/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29XAAAAL4"]
[Thu Sep 17 15:23:09.720757 2026] [authz_core:error] [pid 1012520:tid 1012736] [client 5.189.145.112:62209] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:23:09.763897 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/email/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29YQAAAIU"]
[Thu Sep 17 15:23:09.772977 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29YgAAANc"]
[Thu Sep 17 15:23:09.828301 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/smtp/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29ZQAAAIs"]
[Thu Sep 17 15:23:09.884737 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaPQpXMN3p_zkwXf29ZwAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:09.893453 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mailing/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29aAAAAJU"]
[Thu Sep 17 15:23:09.938970 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29aQAAAMA"]
[Thu Sep 17 15:23:09.957386 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/notifications/.env"] [unique_id "aqxaPQpXMN3p_zkwXf29agAAAPo"]
[Thu Sep 17 15:23:09.971403 2026] [security2:error] [pid 1012520:tid 1012681] [client 17.166.154.116:37048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxaPQpXMN3p_zkwXf29YwAAox8"]
[Thu Sep 17 15:23:10.024117 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/notify/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29dQAAAMY"]
[Thu Sep 17 15:23:10.047865 2026] [security2:error] [pid 1012520:tid 1012654] [client 85.204.70.90:60202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxaPgpXMN3p_zkwXf29dgAAAIg"]
[Thu Sep 17 15:23:10.083956 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/sender/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29egAAAJc"]
[Thu Sep 17 15:23:10.105604 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29ewAAAN8"]
[Thu Sep 17 15:23:10.146317 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/campaign/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29fQAAAK4"]
[Thu Sep 17 15:23:10.206733 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/newsletter/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29gQAAAME"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:23:10.239534 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.166.123.190:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxaPgpXMN3p_zkwXf29ggAAAKY"]
[Thu Sep 17 15:23:10.267142 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/ses/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29hAAAAOE"]
[Thu Sep 17 15:23:10.269490 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29hQAAAJY"]
[Thu Sep 17 15:23:10.301893 2026] [security2:error] [pid 1012520:tid 1012694] [client 140.238.42.111:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaPgpXMN3p_zkwXf29iQAAALA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:10.328615 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/sendgrid/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29iwAAAN0"]
[Thu Sep 17 15:23:10.388096 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/sparkpost/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29jgAAAJM"]
[Thu Sep 17 15:23:10.433235 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29kwAAAOc"]
[Thu Sep 17 15:23:10.436496 2026] [security2:error] [pid 1012520:tid 1012720] [client 134.185.85.61:55613] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "timalba.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxaPgpXMN3p_zkwXf29lAAAAMo"]
[Thu Sep 17 15:23:10.449963 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/postmark/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29lQAAAM8"]
[Thu Sep 17 15:23:10.465614 2026] [cgid:error] [pid 1012520:tid 1012746] [client 66.249.84.6:57453] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:23:10.513379 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mailgun/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29mgAAAI0"]
[Thu Sep 17 15:23:10.569734 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mandrill/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29nAAAAMg"]
[Thu Sep 17 15:23:10.605595 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29ngAAALk"]
[Thu Sep 17 15:23:10.628609 2026] [security2:error] [pid 1012520:tid 1012762] [client 85.204.70.90:60210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxaPgpXMN3p_zkwXf29oAAAAPQ"]
[Thu Sep 17 15:23:10.629720 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mailjet/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29nwAAAMk"]
[Thu Sep 17 15:23:10.686419 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/brevo/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29oQAAANI"]
[Thu Sep 17 15:23:10.698927 2026] [security2:error] [pid 1012520:tid 1012721] [client 140.238.42.111:61823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaPgpXMN3p_zkwXf29owAAAMs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:10.743793 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/transactional/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29pAAAALU"]
[Thu Sep 17 15:23:10.765870 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29pQAAALs"]
[Thu Sep 17 15:23:10.799745 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/bulk/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29pgAAAOY"]
[Thu Sep 17 15:23:10.817273 2026] [security2:error] [pid 1012520:tid 1012686] [client 134.185.85.61:59256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "timalba.com"] [uri "/media/system/js/core.js"] [unique_id "aqxaPgpXMN3p_zkwXf29pwAAAKg"]
[Thu Sep 17 15:23:10.819960 2026] [security2:error] [pid 1012520:tid 1012767] [client 216.73.217.36:53893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.diramgroup.24eastyard.com"] [uri "/index.php/robots.txt"] [unique_id "aqxaOwpXMN3p_zkwXf28tgAA-Rw"]
[Thu Sep 17 15:23:10.856799 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/aws/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29qQAAAOM"]
[Thu Sep 17 15:23:10.914531 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/azure/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29rAAAAQA"]
[Thu Sep 17 15:23:10.923610 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29rQAAAI8"]
[Thu Sep 17 15:23:10.925581 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.166.123.190:39660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxaPgpXMN3p_zkwXf29rgAAAL0"]
[Thu Sep 17 15:23:10.971073 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/gcp/.env"] [unique_id "aqxaPgpXMN3p_zkwXf29sgAAAM4"]
[Thu Sep 17 15:23:10.988668 2026] [security2:error] [pid 1012520:tid 1012701] [client 216.73.216.238:60104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "energynowspa.com"] [uri "/index.php"] [unique_id "aqxaPQpXMN3p_zkwXf29YAAAtxg"]
[Thu Sep 17 15:23:11.026289 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/cloud/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29tQAAANM"]
[Thu Sep 17 15:23:11.079788 2026] [security2:error] [pid 1012520:tid 1012717] [client 140.238.42.111:62179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaPwpXMN3p_zkwXf29twAAAMc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:11.081422 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/infrastructure/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29uQAAANo"]
[Thu Sep 17 15:23:11.081439 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29uAAAAL4"]
[Thu Sep 17 15:23:11.136966 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/docker/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29uwAAALI"]
[Thu Sep 17 15:23:11.191441 2026] [security2:error] [pid 1012520:tid 1012752] [client 85.204.70.90:60216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxaPwpXMN3p_zkwXf29vwAAAOo"]
[Thu Sep 17 15:23:11.192171 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/k8s/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29vgAAAMI"]
[Thu Sep 17 15:23:11.243431 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29wAAAAPE"]
[Thu Sep 17 15:23:11.249402 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/kubernetes/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29wQAAANc"]
[Thu Sep 17 15:23:11.308811 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/terraform/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29wwAAAKo"]
[Thu Sep 17 15:23:11.368550 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/ansible/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29xQAAAPo"]
[Thu Sep 17 15:23:11.401985 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29xgAAAP4"]
[Thu Sep 17 15:23:11.424707 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/.git/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29yAAAAMY"]
[Thu Sep 17 15:23:11.453963 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:62491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaPwpXMN3p_zkwXf29ygAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:11.485333 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/ci/.env"] [unique_id "aqxaPwpXMN3p_zkwXf29zQAAAIY"]
[Thu Sep 17 15:23:11.540357 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/cd/.env"] [unique_id "aqxaPwpXMN3p_zkwXf290AAAAME"]
[Thu Sep 17 15:23:11.563688 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxaPwpXMN3p_zkwXf291AAAAO8"]
[Thu Sep 17 15:23:11.598477 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/jenkins/.env"] [unique_id "aqxaPwpXMN3p_zkwXf291QAAAIw"]
[Thu Sep 17 15:23:11.608961 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.166.123.190:33240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxaPwpXMN3p_zkwXf291gAAAKM"]
[Thu Sep 17 15:23:11.617934 2026] [security2:error] [pid 1012520:tid 1012695] [client 216.73.216.238:60104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "energynowspa.com"] [uri "/index.php"] [unique_id "aqxaPwpXMN3p_zkwXf290gAAsVo"]
[Thu Sep 17 15:23:11.659262 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/gitlab/.env"] [unique_id "aqxaPwpXMN3p_zkwXf292AAAANA"]
[Thu Sep 17 15:23:11.715326 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/github/.env"] [unique_id "aqxaPwpXMN3p_zkwXf293AAAAI4"]
[Thu Sep 17 15:23:11.720955 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxaPwpXMN3p_zkwXf293QAAANE"]
[Thu Sep 17 15:23:11.759196 2026] [security2:error] [pid 1012520:tid 1012743] [client 216.73.216.238:34521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.energynowspa.com"] [uri "/index.php"] [unique_id "aqxaPwpXMN3p_zkwXf292QAA4QM"], referer: https://energynowspa.com/sitemap.xml
[Thu Sep 17 15:23:11.765304 2026] [security2:error] [pid 1012520:tid 1012741] [client 85.204.70.90:60220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxaPwpXMN3p_zkwXf293wAAAN8"]
[Thu Sep 17 15:23:11.770553 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/actions/.env"] [unique_id "aqxaPwpXMN3p_zkwXf294QAAAPY"]
[Thu Sep 17 15:23:11.825973 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/circleci/.env"] [unique_id "aqxaPwpXMN3p_zkwXf295AAAALQ"]
[Thu Sep 17 15:23:11.852850 2026] [security2:error] [pid 1012520:tid 1012700] [client 140.238.42.111:62805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaPwpXMN3p_zkwXf295QAAALY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:11.883686 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxaPwpXMN3p_zkwXf295gAAAM8"]
[Thu Sep 17 15:23:11.883687 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/travis/.env"] [unique_id "aqxaPwpXMN3p_zkwXf295wAAAOQ"]
[Thu Sep 17 15:23:11.960086 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/buildkite/.env"] [unique_id "aqxaPwpXMN3p_zkwXf296gAAAMw"]
[Thu Sep 17 15:23:12.018020 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mysql/.env"] [unique_id "aqxaQApXMN3p_zkwXf297wAAAMs"]
[Thu Sep 17 15:23:12.046833 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxaQApXMN3p_zkwXf298AAAAPg"]
[Thu Sep 17 15:23:12.076038 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/postgres/.env"] [unique_id "aqxaQApXMN3p_zkwXf298QAAALU"]
[Thu Sep 17 15:23:12.135801 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/mongodb/.env"] [unique_id "aqxaQApXMN3p_zkwXf299QAAALo"]
[Thu Sep 17 15:23:12.195794 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/redis/.env"] [unique_id "aqxaQApXMN3p_zkwXf29-AAAAQA"]
[Thu Sep 17 15:23:12.212989 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxaQApXMN3p_zkwXf29-QAAAL0"]
[Thu Sep 17 15:23:12.237335 2026] [security2:error] [pid 1012520:tid 1012767] [client 140.238.42.111:63096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaQApXMN3p_zkwXf29-gAAAPk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:12.261297 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/elasticsearch/.env"] [unique_id "aqxaQApXMN3p_zkwXf29_AAAAM0"]
[Thu Sep 17 15:23:12.295977 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.166.123.190:33254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxaQApXMN3p_zkwXf29_wAAANg"]
[Thu Sep 17 15:23:12.321150 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/rabbitmq/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-AAAAAIo"]
[Thu Sep 17 15:23:12.372859 2026] [security2:error] [pid 1012520:tid 1012771] [client 85.204.70.90:60226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQApXMN3p_zkwXf2-AgAAAP0"]
[Thu Sep 17 15:23:12.375322 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-AwAAAPA"]
[Thu Sep 17 15:23:12.378568 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/kafka/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-BQAAAMc"]
[Thu Sep 17 15:23:12.437437 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/queue/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-BgAAAL4"]
[Thu Sep 17 15:23:12.481157 2026] [autoindex:error] [pid 1012520:tid 1012755] [client 107.150.104.176:39290] AH01276: Cannot serve directory /home1/gnqazemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://gnq.aze.mybluehost.me/
[Thu Sep 17 15:23:12.493584 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/worker/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-DAAAAOI"]
[Thu Sep 17 15:23:12.533191 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-DgAAAMI"]
[Thu Sep 17 15:23:12.549557 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/job/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-DwAAAPE"]
[Thu Sep 17 15:23:12.604905 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/test/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-EQAAANc"]
[Thu Sep 17 15:23:12.612357 2026] [security2:error] [pid 1012520:tid 1012735] [client 216.73.216.94:1644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kippremote.com"] [uri "/index.php"] [unique_id "aqxaPQpXMN3p_zkwXf29dAAA2Xo"]
[Thu Sep 17 15:23:12.627275 2026] [security2:error] [pid 1012520:tid 1012671] [client 140.238.42.111:63402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaQApXMN3p_zkwXf2-EgAAAJk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:12.661308 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/qa/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-FAAAAMA"]
[Thu Sep 17 15:23:12.690908 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-FgAAAMY"]
[Thu Sep 17 15:23:12.716655 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/preview/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-FwAAAPM"]
[Thu Sep 17 15:23:12.772980 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/beta/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-GQAAAO8"]
[Thu Sep 17 15:23:12.829657 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/uat/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-GwAAAKM"]
[Thu Sep 17 15:23:12.848455 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-HQAAANA"]
[Thu Sep 17 15:23:12.886131 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/stage/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-HgAAAJY"]
[Thu Sep 17 15:23:12.939206 2026] [security2:error] [pid 1012520:tid 1012672] [client 85.204.70.90:35764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQApXMN3p_zkwXf2-IAAAAJo"]
[Thu Sep 17 15:23:12.941005 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/development/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-IQAAAKs"]
[Thu Sep 17 15:23:12.973382 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.166.123.190:33262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxaQApXMN3p_zkwXf2-IgAAAJs"]
[Thu Sep 17 15:23:12.997113 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/production/.env"] [unique_id "aqxaQApXMN3p_zkwXf2-JQAAAN0"]
[Thu Sep 17 15:23:13.006099 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxaQQpXMN3p_zkwXf2-JgAAAOE"]
[Thu Sep 17 15:23:13.007623 2026] [security2:error] [pid 1012520:tid 1012687] [client 140.238.42.111:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-JwAAAKk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:13.052152 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.23.198.186:38016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aponifenno.com"] [uri "/config/app/.env"] [unique_id "aqxaQQpXMN3p_zkwXf2-KgAAALQ"]
[Thu Sep 17 15:23:13.093960 2026] [autoindex:error] [pid 1012520:tid 1012658] [client 143.244.57.121:35996] AH01276: Cannot serve directory /home1/zcktjlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:23:13.106105 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.23.198.186:38016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/phpinfo.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-LAAAALY"]
[Thu Sep 17 15:23:13.168607 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxaQQpXMN3p_zkwXf2-LgAAAOQ"]
[Thu Sep 17 15:23:13.253580 2026] [security2:error] [pid 1012520:tid 1012675] [client 143.244.57.121:35996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQQpXMN3p_zkwXf2-LwAAAJ0"]
[Thu Sep 17 15:23:13.277946 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.23.198.186:38022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/info.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-MQAAAKc"]
[Thu Sep 17 15:23:13.328255 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxaQQpXMN3p_zkwXf2-MgAAALA"]
[Thu Sep 17 15:23:13.393249 2026] [security2:error] [pid 1012520:tid 1012718] [client 140.238.42.111:63979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-NAAAAMg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:13.448837 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.23.198.186:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/php.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-NwAAANY"]
[Thu Sep 17 15:23:13.499126 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxaQQpXMN3p_zkwXf2-OgAAAL8"]
[Thu Sep 17 15:23:13.529098 2026] [security2:error] [pid 1012520:tid 1012659] [client 85.204.70.90:35778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQQpXMN3p_zkwXf2-OwAAAI0"]
[Thu Sep 17 15:23:13.638640 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.23.198.186:38040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/i.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-PgAAAOg"]
[Thu Sep 17 15:23:13.669512 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.166.123.190:33266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-PwAAAQE"]
[Thu Sep 17 15:23:13.683482 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxaQQpXMN3p_zkwXf2-QAAAAQA"]
[Thu Sep 17 15:23:13.791037 2026] [security2:error] [pid 1012520:tid 1012714] [client 140.238.42.111:64285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-RQAAAMQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:13.806848 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.23.198.186:38042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/pi.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-RgAAAIc"]
[Thu Sep 17 15:23:13.828763 2026] [security2:error] [pid 1012520:tid 1012715] [client 143.244.57.121:35998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zck.tjl.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-RwAAAMU"]
[Thu Sep 17 15:23:13.848235 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxaQQpXMN3p_zkwXf2-SAAAANg"]
[Thu Sep 17 15:23:13.860739 2026] [security2:error] [pid 1012520:tid 1012767] [client 177.196.232.48:61095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-QwAA-UA"]
[Thu Sep 17 15:23:13.971303 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.23.198.186:38048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/pinfo.php"] [unique_id "aqxaQQpXMN3p_zkwXf2-TAAAAPA"]
[Thu Sep 17 15:23:14.011065 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxaQgpXMN3p_zkwXf2-TQAAAIU"]
[Thu Sep 17 15:23:14.093232 2026] [security2:error] [pid 1012520:tid 1012723] [client 85.204.70.90:35782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQgpXMN3p_zkwXf2-UAAAAM0"]
[Thu Sep 17 15:23:14.136451 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.23.198.186:38056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/test.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-UQAAAMI"]
[Thu Sep 17 15:23:14.172742 2026] [security2:error] [pid 1012520:tid 1012682] [client 140.238.42.111:64595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-UgAAAKQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:14.232160 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxaQgpXMN3p_zkwXf2-UwAAAPs"]
[Thu Sep 17 15:23:14.246301 2026] [security2:error] [pid 1012520:tid 1012671] [client 162.241.226.11:43612] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-VQAAAJk"]
[Thu Sep 17 15:23:14.342476 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.166.123.190:33272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-XAAAAJI"]
[Thu Sep 17 15:23:14.348541 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.95.14.119:52982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-WQAAAOw"]
[Thu Sep 17 15:23:14.391563 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxaQgpXMN3p_zkwXf2-XgAAALE"]
[Thu Sep 17 15:23:14.397236 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.23.198.186:38060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/p.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-XwAAANA"]
[Thu Sep 17 15:23:14.398372 2026] [autoindex:error] [pid 1012520:tid 1012752] [client 143.244.57.121:36004] AH01276: Cannot serve directory /home1/zcktjlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:23:14.548250 2026] [security2:error] [pid 1012520:tid 1012698] [client 143.244.57.121:36004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQgpXMN3p_zkwXf2-ZQAAALQ"]
[Thu Sep 17 15:23:14.558980 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxaQgpXMN3p_zkwXf2-ZgAAAJM"]
[Thu Sep 17 15:23:14.560761 2026] [security2:error] [pid 1012520:tid 1012684] [client 140.238.42.111:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-ZwAAAKY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:14.581882 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.23.198.186:38062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/debug.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-aQAAAJs"]
[Thu Sep 17 15:23:14.583866 2026] [security2:error] [pid 1012520:tid 1012760] [client 154.190.208.131:41387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-agAAAPI"]
[Thu Sep 17 15:23:14.590883 2026] [security2:error] [pid 1012520:tid 1012760] [client 154.190.208.131:41387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-agAAAPI"]
[Thu Sep 17 15:23:14.666246 2026] [security2:error] [pid 1012520:tid 1012681] [client 85.204.70.90:35794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQgpXMN3p_zkwXf2-bAAAAKM"]
[Thu Sep 17 15:23:14.718978 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxaQgpXMN3p_zkwXf2-bgAAALA"]
[Thu Sep 17 15:23:14.729357 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.95.14.119:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/info.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-bwAAAN8"]
[Thu Sep 17 15:23:14.754302 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.23.198.186:38076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-cAAAAOk"]
[Thu Sep 17 15:23:14.923771 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.23.198.186:38084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/test/phpinfo.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-dAAAALU"]
[Thu Sep 17 15:23:14.933223 2026] [security2:error] [pid 1012520:tid 1012732] [client 216.73.216.94:1644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kippremote.com"] [uri "/index.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-cgAA1nc"]
[Thu Sep 17 15:23:14.958378 2026] [security2:error] [pid 1012520:tid 1012693] [client 140.238.42.111:65166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaQgpXMN3p_zkwXf2-dQAAAK8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:15.029921 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.166.123.190:33284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-eQAAAK0"]
[Thu Sep 17 15:23:15.090027 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.23.198.186:38092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-ewAAALs"]
[Thu Sep 17 15:23:15.098721 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.95.14.119:60626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/php.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-fAAAAOY"]
[Thu Sep 17 15:23:15.115574 2026] [security2:error] [pid 1012520:tid 1012766] [client 143.244.57.121:36020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQwpXMN3p_zkwXf2-fQAAAPg"]
[Thu Sep 17 15:23:15.214552 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxaQwpXMN3p_zkwXf2-fwAAALk"]
[Thu Sep 17 15:23:15.256870 2026] [security2:error] [pid 1012520:tid 1012659] [client 85.204.70.90:35802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQwpXMN3p_zkwXf2-gAAAAI0"]
[Thu Sep 17 15:23:15.269014 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.23.198.186:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/old/phpinfo.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-gQAAAPU"]
[Thu Sep 17 15:23:15.269284 2026] [security2:error] [pid 1012520:tid 1012646] [remote 216.73.216.94:22267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kippremote.com"] [uri "/index.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-fgAAy3w"], referer: https://www.kippremote.com/sitemap.xml
[Thu Sep 17 15:23:15.289087 2026] [security2:error] [pid 1012520:tid 1012767] [client 169.58.197.253:62257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-ggAAAPk"], referer: binance.com
[Thu Sep 17 15:23:15.355974 2026] [security2:error] [pid 1012520:tid 1012724] [client 140.238.42.111:65491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-gwAAAM4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:15.383137 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxaQwpXMN3p_zkwXf2-hAAAAO0"]
[Thu Sep 17 15:23:15.426784 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.95.14.119:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/i.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-iAAAAP0"]
[Thu Sep 17 15:23:15.441136 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.23.198.186:38118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-iQAAAL4"]
[Thu Sep 17 15:23:15.550781 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxaQwpXMN3p_zkwXf2-jQAAANk"]
[Thu Sep 17 15:23:15.626718 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.23.198.186:38130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/public/phpinfo.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-jwAAANo"]
[Thu Sep 17 15:23:15.631957 2026] [autoindex:error] [pid 1012520:tid 1012704] [client 152.32.158.219:48602] AH01276: Cannot serve directory /home1/zxhxwymy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://zxh.xwy.mybluehost.me/
[Thu Sep 17 15:23:15.716296 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxaQwpXMN3p_zkwXf2-kAAAAJk"]
[Thu Sep 17 15:23:15.739731 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.166.123.190:33300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-kgAAAPE"]
[Thu Sep 17 15:23:15.746161 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:49397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-kwAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:15.750225 2026] [security2:error] [pid 1012520:tid 1012747] [client 143.244.57.121:36036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQwpXMN3p_zkwXf2-lAAAAOU"]
[Thu Sep 17 15:23:15.758296 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.95.14.119:60644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-lQAAAP8"]
[Thu Sep 17 15:23:15.841122 2026] [security2:error] [pid 1012520:tid 1012733] [client 85.204.70.90:35810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "creacity.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxaQwpXMN3p_zkwXf2-mAAAANc"]
[Thu Sep 17 15:23:15.882208 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxaQwpXMN3p_zkwXf2-mgAAANU"]
[Thu Sep 17 15:23:15.966142 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.23.198.186:38136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/php-info.php"] [unique_id "aqxaQwpXMN3p_zkwXf2-nQAAAJI"]
[Thu Sep 17 15:23:16.049209 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxaRApXMN3p_zkwXf2-nwAAALE"]
[Thu Sep 17 15:23:16.094668 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.95.14.119:60656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxaRApXMN3p_zkwXf2-oAAAAME"]
[Thu Sep 17 15:23:16.135791 2026] [security2:error] [pid 1012520:tid 1012655] [client 140.238.42.111:49691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaRApXMN3p_zkwXf2-oQAAAIk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:16.150750 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.23.198.186:38140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/phpversion.php"] [unique_id "aqxaRApXMN3p_zkwXf2-ogAAANA"]
[Thu Sep 17 15:23:16.217830 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.92.151.55:42400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxaRApXMN3p_zkwXf2-owAAAJE"]
[Thu Sep 17 15:23:16.319052 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.23.198.186:38152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/_phpinfo.php"] [unique_id "aqxaRApXMN3p_zkwXf2-pQAAALY"]
[Thu Sep 17 15:23:16.383119 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.14.119:60672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/test.php"] [unique_id "aqxaRApXMN3p_zkwXf2-qAAAAMo"]
[Thu Sep 17 15:23:16.442349 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.166.123.190:33316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxaRApXMN3p_zkwXf2-qwAAALQ"]
[Thu Sep 17 15:23:16.451817 2026] [security2:error] [pid 1012520:tid 1012752] [client 143.244.57.121:36042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxaRApXMN3p_zkwXf2-rAAAAOo"]
[Thu Sep 17 15:23:16.505412 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.23.198.186:38156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/old_phpinfo.php"] [unique_id "aqxaRApXMN3p_zkwXf2-rwAAAJ8"]
[Thu Sep 17 15:23:16.518808 2026] [security2:error] [pid 1012520:tid 1012689] [client 140.238.42.111:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaRApXMN3p_zkwXf2-sQAAAKs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:16.679965 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.23.198.186:38172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/server-info.php"] [unique_id "aqxaRApXMN3p_zkwXf2-swAAALU"]
[Thu Sep 17 15:23:16.710755 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxaRApXMN3p_zkwXf2-tQAAAKc"]
[Thu Sep 17 15:23:16.797775 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.95.14.119:60684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/p.php"] [unique_id "aqxaRApXMN3p_zkwXf2-twAAAOM"]
[Thu Sep 17 15:23:16.858581 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.23.198.186:38314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/server-status.php"] [unique_id "aqxaRApXMN3p_zkwXf2-uQAAALs"]
[Thu Sep 17 15:23:16.888078 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxaRApXMN3p_zkwXf2-ugAAAQM"]
[Thu Sep 17 15:23:16.913437 2026] [security2:error] [pid 1012520:tid 1012691] [client 140.238.42.111:50297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaRApXMN3p_zkwXf2-uwAAAK0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:17.052028 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxaRQpXMN3p_zkwXf2-wwAAAL4"]
[Thu Sep 17 15:23:17.092284 2026] [security2:error] [pid 1012520:tid 1012728] [client 143.244.57.121:36046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxaRQpXMN3p_zkwXf2-xAAAANI"]
[Thu Sep 17 15:23:17.125218 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.166.123.190:33332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-xwAAAJw"]
[Thu Sep 17 15:23:17.193495 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.95.14.119:60692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-yQAAAIs"]
[Thu Sep 17 15:23:17.216649 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.23.198.186:38320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxaRQpXMN3p_zkwXf2-ygAAAJk"]
[Thu Sep 17 15:23:17.217774 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxaRQpXMN3p_zkwXf2-ywAAALc"]
[Thu Sep 17 15:23:17.309651 2026] [security2:error] [pid 1012520:tid 1012769] [client 140.238.42.111:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-zgAAAPs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:17.327136 2026] [security2:error] [pid 1012520:tid 1012763] [client 103.61.184.148:52960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-zwAAAPU"]
[Thu Sep 17 15:23:17.327240 2026] [security2:error] [pid 1012520:tid 1012763] [client 103.61.184.148:52960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-zwAAAPU"]
[Thu Sep 17 15:23:17.384871 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.23.198.186:38334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-0wAAANc"]
[Thu Sep 17 15:23:17.385712 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxaRQpXMN3p_zkwXf2-0gAAANU"]
[Thu Sep 17 15:23:17.550217 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxaRQpXMN3p_zkwXf2-2AAAAO4"]
[Thu Sep 17 15:23:17.562801 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.23.198.186:38346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-2QAAAJM"]
[Thu Sep 17 15:23:17.563140 2026] [security2:error] [pid 1012520:tid 1012719] [client 114.198.138.124:54190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-2gAAAMk"]
[Thu Sep 17 15:23:17.563217 2026] [security2:error] [pid 1012520:tid 1012719] [client 114.198.138.124:54190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-2gAAAMk"]
[Thu Sep 17 15:23:17.651590 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.95.14.119:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-3QAAAJY"]
[Thu Sep 17 15:23:17.702262 2026] [security2:error] [pid 1012520:tid 1012716] [client 143.244.57.121:36054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxaRQpXMN3p_zkwXf2-3gAAAMY"]
[Thu Sep 17 15:23:17.717696 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxaRQpXMN3p_zkwXf2-3wAAAN4"]
[Thu Sep 17 15:23:17.723018 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:50879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-4QAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:17.751215 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.23.198.186:38358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-4gAAALQ"]
[Thu Sep 17 15:23:17.827962 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.166.123.190:33348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-4wAAAPI"]
[Thu Sep 17 15:23:17.844133 2026] [security2:error] [pid 1012520:tid 1012654] [client 185.55.149.49:62904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-5AAAAIg"]
[Thu Sep 17 15:23:17.844366 2026] [security2:error] [pid 1012520:tid 1012654] [client 185.55.149.49:62904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-5AAAAIg"]
[Thu Sep 17 15:23:17.880707 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxaRQpXMN3p_zkwXf2-5QAAAL8"]
[Thu Sep 17 15:23:17.940478 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.23.198.186:38370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxaRQpXMN3p_zkwXf2-6AAAAPQ"]
[Thu Sep 17 15:23:18.052275 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxaRgpXMN3p_zkwXf2-7QAAAKk"]
[Thu Sep 17 15:23:18.067494 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.95.14.119:38832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxaRgpXMN3p_zkwXf2-7gAAAKA"]
[Thu Sep 17 15:23:18.117758 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.23.198.186:38374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxaRgpXMN3p_zkwXf2-7wAAAPg"]
[Thu Sep 17 15:23:18.126551 2026] [security2:error] [pid 1012520:tid 1012694] [client 140.238.42.111:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaRgpXMN3p_zkwXf2-8AAAALA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:18.219426 2026] [security2:error] [pid 1012520:tid 1012777] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxaRgpXMN3p_zkwXf2-8QAAAQM"]
[Thu Sep 17 15:23:18.255429 2026] [security2:error] [pid 1012520:tid 1012738] [client 156.192.234.52:56129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaRgpXMN3p_zkwXf2-8gAAANw"]
[Thu Sep 17 15:23:18.258415 2026] [security2:error] [pid 1012520:tid 1012738] [client 156.192.234.52:56129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaRgpXMN3p_zkwXf2-8gAAANw"]
[Thu Sep 17 15:23:18.311218 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.23.198.186:38382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxaRgpXMN3p_zkwXf2-8wAAAMQ"]
[Thu Sep 17 15:23:18.353873 2026] [security2:error] [pid 1012520:tid 1012686] [client 143.244.57.121:36056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxaRgpXMN3p_zkwXf2-9AAAAKg"]
[Thu Sep 17 15:23:18.388805 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxaRgpXMN3p_zkwXf2-9QAAAPw"]
[Thu Sep 17 15:23:18.470447 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.95.14.119:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxaRgpXMN3p_zkwXf2-9gAAAPA"]
[Thu Sep 17 15:23:18.494273 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.23.198.186:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/phpinfo.php.old"] [unique_id "aqxaRgpXMN3p_zkwXf2--QAAAIo"]
[Thu Sep 17 15:23:18.519168 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.166.123.190:33352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxaRgpXMN3p_zkwXf2--gAAAOA"]
[Thu Sep 17 15:23:18.541869 2026] [security2:error] [pid 1012520:tid 1012721] [client 140.238.42.111:51439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaRgpXMN3p_zkwXf2--wAAAMs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:18.561994 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxaRgpXMN3p_zkwXf2-_AAAAKQ"]
[Thu Sep 17 15:23:18.686021 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.23.198.186:38396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/phpinfo.php~"] [unique_id "aqxaRgpXMN3p_zkwXf2-_gAAALo"]
[Thu Sep 17 15:23:18.734695 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxaRgpXMN3p_zkwXf2-_wAAAKU"]
[Thu Sep 17 15:23:18.833001 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.95.14.119:38848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxaRgpXMN3p_zkwXf2_AQAAANo"]
[Thu Sep 17 15:23:18.854207 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.23.198.186:38410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/info.php.bak"] [unique_id "aqxaRgpXMN3p_zkwXf2_AgAAAJk"]
[Thu Sep 17 15:23:18.896745 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxaRgpXMN3p_zkwXf2_BAAAANQ"]
[Thu Sep 17 15:23:18.947646 2026] [security2:error] [pid 1012520:tid 1012676] [client 140.238.42.111:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaRgpXMN3p_zkwXf2_CAAAAJ4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:18.986102 2026] [security2:error] [pid 1012520:tid 1012670] [client 143.244.57.121:36072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxaRgpXMN3p_zkwXf2_DQAAAJg"]
[Thu Sep 17 15:23:19.031288 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.23.198.186:38426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/phpinfo.php.save"] [unique_id "aqxaRwpXMN3p_zkwXf2_DwAAALg"]
[Thu Sep 17 15:23:19.060179 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxaRwpXMN3p_zkwXf2_EgAAAK4"]
[Thu Sep 17 15:23:19.205234 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.23.198.186:38434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_GAAAAP8"]
[Thu Sep 17 15:23:19.216618 2026] [security2:error] [pid 1012520:tid 1012761] [client 34.166.123.190:33366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_GQAAAPM"]
[Thu Sep 17 15:23:19.222922 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxaRwpXMN3p_zkwXf2_GgAAALM"]
[Thu Sep 17 15:23:19.281206 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.95.14.119:38858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_HQAAAOQ"]
[Thu Sep 17 15:23:19.333612 2026] [security2:error] [pid 1012520:tid 1012743] [client 140.238.42.111:52129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_HwAAAOE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:19.387062 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxaRwpXMN3p_zkwXf2_IAAAAJ0"]
[Thu Sep 17 15:23:19.405100 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.23.198.186:38442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_IQAAAMo"]
[Thu Sep 17 15:23:19.530775 2026] [fcgid:warn] [pid 1012520:tid 1012709] (70014)End of file found: [client 152.32.200.243:52996] mod_fcgid: can't get data from http client
[Thu Sep 17 15:23:19.551692 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxaRwpXMN3p_zkwXf2_JgAAAKs"]
[Thu Sep 17 15:23:19.575308 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.23.198.186:38450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_KAAAAIg"]
[Thu Sep 17 15:23:19.597118 2026] [security2:error] [pid 1012520:tid 1012706] [client 143.244.57.121:36084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxaRwpXMN3p_zkwXf2_KQAAALw"]
[Thu Sep 17 15:23:19.609081 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.95.14.119:38866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_KgAAAOk"]
[Thu Sep 17 15:23:19.722336 2026] [security2:error] [pid 1012520:tid 1012693] [client 140.238.42.111:52462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_KwAAAK8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:19.726241 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxaRwpXMN3p_zkwXf2_LAAAALs"]
[Thu Sep 17 15:23:19.741373 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.23.198.186:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_LQAAAOg"]
[Thu Sep 17 15:23:19.889598 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxaRwpXMN3p_zkwXf2_LwAAAPc"]
[Thu Sep 17 15:23:19.897082 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.166.123.190:33378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_MAAAAKc"]
[Thu Sep 17 15:23:19.917274 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.23.198.186:38466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxaRwpXMN3p_zkwXf2_MgAAAQQ"]
[Thu Sep 17 15:23:20.042454 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.95.14.119:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxaSApXMN3p_zkwXf2_NgAAAO0"]
[Thu Sep 17 15:23:20.060462 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxaSApXMN3p_zkwXf2_OQAAAIo"]
[Thu Sep 17 15:23:20.084291 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.23.198.186:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/www/phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_OwAAAM4"]
[Thu Sep 17 15:23:20.087195 2026] [access_compat:error] [pid 1012520:tid 1012708] [client 78.46.218.89:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/brazilian-adventure
[Thu Sep 17 15:23:20.127069 2026] [security2:error] [pid 1012520:tid 1012770] [client 140.238.42.111:52817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaSApXMN3p_zkwXf2_PQAAAPw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:20.220273 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxaSApXMN3p_zkwXf2_PwAAANI"]
[Thu Sep 17 15:23:20.233391 2026] [security2:error] [pid 1012520:tid 1012739] [client 186.105.232.15:57086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaSApXMN3p_zkwXf2_QAAAAN0"]
[Thu Sep 17 15:23:20.233541 2026] [security2:error] [pid 1012520:tid 1012739] [client 186.105.232.15:57086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaSApXMN3p_zkwXf2_QAAAAN0"]
[Thu Sep 17 15:23:20.243170 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.23.198.186:38486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_QQAAAL0"]
[Thu Sep 17 15:23:20.247026 2026] [security2:error] [pid 1012520:tid 1012752] [client 143.244.57.121:36086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSApXMN3p_zkwXf2_QgAAAOo"]
[Thu Sep 17 15:23:20.378344 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxaSApXMN3p_zkwXf2_QwAAANo"]
[Thu Sep 17 15:23:20.416508 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.23.198.186:38488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_RQAAAIs"]
[Thu Sep 17 15:23:20.456926 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.95.14.119:38890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxaSApXMN3p_zkwXf2_RgAAAKo"]
[Thu Sep 17 15:23:20.512674 2026] [security2:error] [pid 1012520:tid 1012671] [client 140.238.42.111:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaSApXMN3p_zkwXf2_SgAAAJk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:20.539494 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxaSApXMN3p_zkwXf2_SwAAANA"]
[Thu Sep 17 15:23:20.588280 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.23.198.186:38500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/site/phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_TQAAAI4"]
[Thu Sep 17 15:23:20.594544 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.166.123.190:33390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_TgAAALc"]
[Thu Sep 17 15:23:20.702312 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxaSApXMN3p_zkwXf2_UgAAALY"]
[Thu Sep 17 15:23:20.730485 2026] [security2:error] [pid 1012520:tid 1012679] [client 47.128.56.122:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "revelinfear.com"] [uri "/robots.txt"] [unique_id "aqxaSApXMN3p_zkwXf2_VAAAAKE"]
[Thu Sep 17 15:23:20.784172 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.23.198.186:38506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_VQAAAJY"]
[Thu Sep 17 15:23:20.793889 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.95.14.119:38902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_VgAAALE"]
[Thu Sep 17 15:23:20.848327 2026] [security2:error] [pid 1012520:tid 1012710] [client 143.244.57.121:57646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSApXMN3p_zkwXf2_WQAAAMA"]
[Thu Sep 17 15:23:20.861588 2026] [security2:error] [pid 1012520:tid 1012760] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxaSApXMN3p_zkwXf2_WgAAAPI"]
[Thu Sep 17 15:23:20.926051 2026] [security2:error] [pid 1012520:tid 1012747] [client 140.238.42.111:53481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaSApXMN3p_zkwXf2_WwAAAOU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:20.967021 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.23.198.186:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxaSApXMN3p_zkwXf2_XQAAAM0"]
[Thu Sep 17 15:23:21.024259 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxaSQpXMN3p_zkwXf2_YAAAAN8"]
[Thu Sep 17 15:23:21.157027 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.95.14.119:38916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_ZgAAAOY"]
[Thu Sep 17 15:23:21.180591 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.23.198.186:38522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_aAAAAKk"]
[Thu Sep 17 15:23:21.190201 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxaSQpXMN3p_zkwXf2_aQAAAK0"]
[Thu Sep 17 15:23:21.291474 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.166.123.190:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bei.abv.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_bwAAANY"]
[Thu Sep 17 15:23:21.349193 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.23.198.186:38530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/core/phpinfo.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_cAAAANE"]
[Thu Sep 17 15:23:21.353309 2026] [security2:error] [pid 1012520:tid 1012765] [client 140.238.42.111:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_cgAAAPc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:21.355514 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxaSQpXMN3p_zkwXf2_cwAAAIc"]
[Thu Sep 17 15:23:21.446928 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.14.119:38926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_dQAAAIo"]
[Thu Sep 17 15:23:21.447372 2026] [security2:error] [pid 1012520:tid 1012678] [client 143.244.57.121:57660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSQpXMN3p_zkwXf2_dgAAAKA"]
[Thu Sep 17 15:23:21.469777 2026] [security2:error] [pid 1012520:tid 1012617] [remote 94.23.188.202:63120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.copiwestcoast.org"] [uri "/robots.txt"] [unique_id "aqxaSQpXMN3p_zkwXf2_eAAAkF8"]
[Thu Sep 17 15:23:21.469925 2026] [security2:error] [pid 1012520:tid 1012662] [client 94.23.188.202:63120] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.copiwestcoast.org"] [uri "/robots.txt"] [unique_id "aqxaSQpXMN3p_zkwXf2_eAAAkF8"]
[Thu Sep 17 15:23:21.479763 2026] [security2:error] [pid 1012520:tid 1012774] [client 137.131.43.163:58614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "richflaherty.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSQpXMN3p_zkwXf2_eQAAAQA"]
[Thu Sep 17 15:23:21.518008 2026] [security2:error] [pid 1012520:tid 1012739] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxaSQpXMN3p_zkwXf2_egAAAN0"]
[Thu Sep 17 15:23:21.534540 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.23.198.186:38544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aponifenno.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_fQAAAPw"]
[Thu Sep 17 15:23:21.677907 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxaSQpXMN3p_zkwXf2_hAAAAP4"]
[Thu Sep 17 15:23:21.740693 2026] [security2:error] [pid 1012520:tid 1012730] [client 140.238.42.111:54253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_hwAAANQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:21.788808 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.14.119:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxaSQpXMN3p_zkwXf2_igAAAK4"]
[Thu Sep 17 15:23:21.834375 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxaSQpXMN3p_zkwXf2_jQAAANc"]
[Thu Sep 17 15:23:21.991795 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxaSQpXMN3p_zkwXf2_lAAAAKE"]
[Thu Sep 17 15:23:21.997987 2026] [security2:error] [pid 1012520:tid 1012538] [remote 51.81.169.201:46672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.copiwestcoast.org"] [uri "/"] [unique_id "aqxaSQpXMN3p_zkwXf2_lgAAthA"]
[Thu Sep 17 15:23:21.998118 2026] [security2:error] [pid 1012520:tid 1012700] [client 51.81.169.201:46672] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.copiwestcoast.org"] [uri "/"] [unique_id "aqxaSQpXMN3p_zkwXf2_lgAAthA"]
[Thu Sep 17 15:23:22.091336 2026] [security2:error] [pid 1012520:tid 1012652] [client 143.244.57.121:57670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSgpXMN3p_zkwXf2_ogAAAIY"]
[Thu Sep 17 15:23:22.120827 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:54575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_pAAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:22.153075 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxaSgpXMN3p_zkwXf2_pQAAAM0"]
[Thu Sep 17 15:23:22.267204 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.95.14.119:38932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxaSgpXMN3p_zkwXf2_qwAAAPg"]
[Thu Sep 17 15:23:22.319008 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxaSgpXMN3p_zkwXf2_rwAAAQQ"]
[Thu Sep 17 15:23:22.481349 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxaSgpXMN3p_zkwXf2_tgAAAIU"]
[Thu Sep 17 15:23:22.506795 2026] [security2:error] [pid 1012520:tid 1012732] [client 140.238.42.111:54890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_twAAANY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:22.550951 2026] [security2:error] [pid 1012520:tid 1012681] [client 99.65.144.45:38075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_tAAAozI"]
[Thu Sep 17 15:23:22.561166 2026] [security2:error] [pid 1012520:tid 1012675] [client 137.131.43.163:64409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.43.131.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "richflaherty.com"] [uri "/xmlrpc.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_ugAAAJ0"]
[Thu Sep 17 15:23:22.561282 2026] [security2:error] [pid 1012520:tid 1012675] [client 137.131.43.163:64409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "richflaherty.com"] [uri "/xmlrpc.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_ugAAAJ0"]
[Thu Sep 17 15:23:22.644135 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxaSgpXMN3p_zkwXf2_vgAAAIo"]
[Thu Sep 17 15:23:22.645928 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.95.14.119:38934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_vwAAAQE"]
[Thu Sep 17 15:23:22.688817 2026] [security2:error] [pid 1012520:tid 1012727] [client 143.244.57.121:57680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSgpXMN3p_zkwXf2_wQAAANE"]
[Thu Sep 17 15:23:22.804599 2026] [security2:error] [pid 1012520:tid 1012717] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxaSgpXMN3p_zkwXf2_xgAAAMc"]
[Thu Sep 17 15:23:22.892573 2026] [security2:error] [pid 1012520:tid 1012677] [client 140.238.42.111:55215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_yAAAAJ8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:22.963444 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxaSgpXMN3p_zkwXf2_zQAAANo"]
[Thu Sep 17 15:23:22.971436 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.95.14.119:38938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxaSgpXMN3p_zkwXf2_zgAAANI"]
[Thu Sep 17 15:23:23.121087 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxaSwpXMN3p_zkwXf2_2QAAAP8"]
[Thu Sep 17 15:23:23.277925 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxaSwpXMN3p_zkwXf2_3wAAALM"]
[Thu Sep 17 15:23:23.284632 2026] [security2:error] [pid 1012520:tid 1012735] [client 140.238.42.111:55539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaSwpXMN3p_zkwXf2_4QAAANk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:23.287025 2026] [security2:error] [pid 1012520:tid 1012704] [client 143.244.57.121:57690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSwpXMN3p_zkwXf2_4gAAALo"]
[Thu Sep 17 15:23:23.333374 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.95.14.119:38946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxaSwpXMN3p_zkwXf2_4wAAAJU"]
[Thu Sep 17 15:23:23.438543 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxaSwpXMN3p_zkwXf2_5wAAAOM"]
[Thu Sep 17 15:23:23.594823 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxaSwpXMN3p_zkwXf2_8gAAAOE"]
[Thu Sep 17 15:23:23.610250 2026] [security2:error] [pid 1012520:tid 1012700] [client 17.166.21.128:33534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxaSwpXMN3p_zkwXf2_5gAAtg0"]
[Thu Sep 17 15:23:23.655070 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.95.14.119:38954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxaSwpXMN3p_zkwXf2_9QAAAMY"]
[Thu Sep 17 15:23:23.661265 2026] [security2:error] [pid 1012520:tid 1012654] [client 169.58.197.253:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxaSwpXMN3p_zkwXf2_9wAAAIg"], referer: binance.com
[Thu Sep 17 15:23:23.662274 2026] [security2:error] [pid 1012520:tid 1012712] [client 140.238.42.111:55831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaSwpXMN3p_zkwXf2_-AAAAMI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:23.756103 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxaSwpXMN3p_zkwXf2_-wAAALs"]
[Thu Sep 17 15:23:23.890621 2026] [security2:error] [pid 1012520:tid 1012746] [client 143.244.57.121:57698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zck.tjl.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxaSwpXMN3p_zkwXf2__gAAAOQ"]
[Thu Sep 17 15:23:23.912502 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxaSwpXMN3p_zkwXf2__wAAAIc"]
[Thu Sep 17 15:23:23.969984 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.95.14.119:38966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxaSwpXMN3p_zkwXf3AAQAAAM8"]
[Thu Sep 17 15:23:24.045363 2026] [security2:error] [pid 1012520:tid 1012694] [client 140.238.42.111:56141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaTApXMN3p_zkwXf3ABQAAALA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:24.073840 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxaTApXMN3p_zkwXf3ABwAAAKc"]
[Thu Sep 17 15:23:24.235874 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxaTApXMN3p_zkwXf3ADAAAAKs"]
[Thu Sep 17 15:23:24.329941 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.95.14.119:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxaTApXMN3p_zkwXf3ADQAAAIo"]
[Thu Sep 17 15:23:24.414231 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxaTApXMN3p_zkwXf3ADwAAALg"]
[Thu Sep 17 15:23:24.440988 2026] [security2:error] [pid 1012520:tid 1012662] [client 140.238.42.111:56488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaTApXMN3p_zkwXf3AEAAAAJA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:24.582175 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxaTApXMN3p_zkwXf3AFQAAANw"]
[Thu Sep 17 15:23:24.679539 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.95.14.119:38982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxaTApXMN3p_zkwXf3AGAAAAJQ"]
[Thu Sep 17 15:23:24.745899 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxaTApXMN3p_zkwXf3AGwAAAJw"]
[Thu Sep 17 15:23:24.777457 2026] [core:error] [pid 1012520:tid 1012728] [client 107.189.6.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:23:24.777477 2026] [core:error] [pid 1012520:tid 1012728] [client 107.189.6.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:23:24.843055 2026] [security2:error] [pid 1012520:tid 1012752] [client 99.65.144.45:45955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaTApXMN3p_zkwXf3AHQAA6m0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&hideliu=1&hidemyself=1&target=The_Lord_Of_Dwarves&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:23:24.848306 2026] [security2:error] [pid 1012520:tid 1012693] [client 140.238.42.111:56828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaTApXMN3p_zkwXf3AIAAAAK8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:24.905351 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxaTApXMN3p_zkwXf3AIQAAAP8"]
[Thu Sep 17 15:23:24.940070 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.95.14.119:38986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxaTApXMN3p_zkwXf3AIgAAANQ"]
[Thu Sep 17 15:23:25.075003 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxaTQpXMN3p_zkwXf3ARQAAANc"]
[Thu Sep 17 15:23:25.123606 2026] [security2:error] [pid 1012520:tid 1012708] [client 154.190.208.131:41976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaTQpXMN3p_zkwXf3ARgAAAL4"]
[Thu Sep 17 15:23:25.129115 2026] [security2:error] [pid 1012520:tid 1012708] [client 154.190.208.131:41976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaTQpXMN3p_zkwXf3ARgAAAL4"]
[Thu Sep 17 15:23:25.236461 2026] [security2:error] [pid 1012520:tid 1012686] [client 140.238.42.111:57166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaTQpXMN3p_zkwXf3ARwAAAKg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:25.238479 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxaTQpXMN3p_zkwXf3ASAAAAJU"]
[Thu Sep 17 15:23:25.277614 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.95.14.119:38994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxaTQpXMN3p_zkwXf3ASQAAALM"]
[Thu Sep 17 15:23:25.392122 2026] [security2:error] [pid 1012520:tid 1012692] [client 157.85.212.168:12532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxaTQpXMN3p_zkwXf3ASgAArkg"]
[Thu Sep 17 15:23:25.409436 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.92.151.55:56892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uxz.hui.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxaTQpXMN3p_zkwXf3ASwAAAO4"]
[Thu Sep 17 15:23:25.579454 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.92.151.55:56892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxaTQpXMN3p_zkwXf3ATgAAAMY"]
[Thu Sep 17 15:23:25.594988 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.95.14.119:38996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxaTQpXMN3p_zkwXf3AUQAAAMw"]
[Thu Sep 17 15:23:25.639211 2026] [security2:error] [pid 1012520:tid 1012723] [client 140.238.42.111:57538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaTQpXMN3p_zkwXf3AUgAAAM0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:25.934385 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.95.14.119:39000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxaTQpXMN3p_zkwXf3AXgAAAN8"]
[Thu Sep 17 15:23:26.026515 2026] [security2:error] [pid 1012520:tid 1012669] [client 140.238.42.111:57847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AYgAAAJc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:26.053743 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.92.151.55:57010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/info.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AYwAAAOs"]
[Thu Sep 17 15:23:26.265569 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.95.14.119:39008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AZgAAAQE"]
[Thu Sep 17 15:23:26.426128 2026] [security2:error] [pid 1012520:tid 1012778] [client 140.238.42.111:58180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AbAAAAQQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:26.526836 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.92.151.55:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/php.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AbwAAAMQ"]
[Thu Sep 17 15:23:26.688524 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.95.14.119:39014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AfQAAAMs"]
[Thu Sep 17 15:23:26.826274 2026] [security2:error] [pid 1012520:tid 1012728] [client 140.238.42.111:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AgQAAANI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:26.835164 2026] [authz_core:error] [pid 1012520:tid 1012673] [client 5.189.145.112:57554] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:23:26.971830 2026] [security2:error] [pid 1012520:tid 1012693] [client 134.185.85.61:63636] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "stoneofxavier.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxaTgpXMN3p_zkwXf3AhQAAAK8"]
[Thu Sep 17 15:23:27.005741 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.92.151.55:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/i.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AhgAAAJM"]
[Thu Sep 17 15:23:27.051604 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.14.119:39030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AiQAAAMo"]
[Thu Sep 17 15:23:27.068946 2026] [security2:error] [pid 1012520:tid 1012770] [client 146.148.103.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxaTgpXMN3p_zkwXf3AhAAAAPw"]
[Thu Sep 17 15:23:27.220277 2026] [security2:error] [pid 1012520:tid 1012733] [client 140.238.42.111:58951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AjgAAANc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:27.352027 2026] [security2:error] [pid 1012520:tid 1012745] [client 134.185.85.61:57125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "stoneofxavier.com"] [uri "/media/system/js/core.js"] [unique_id "aqxaTwpXMN3p_zkwXf3AkQAAAOM"]
[Thu Sep 17 15:23:27.460079 2026] [security2:error] [pid 1012520:tid 1012711] [client 114.198.138.124:54841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AlAAAAME"]
[Thu Sep 17 15:23:27.460234 2026] [security2:error] [pid 1012520:tid 1012711] [client 114.198.138.124:54841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AlAAAAME"]
[Thu Sep 17 15:23:27.482774 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.92.151.55:57032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AlgAAAIw"]
[Thu Sep 17 15:23:27.586628 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.95.14.119:39036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AmgAAAK4"]
[Thu Sep 17 15:23:27.624932 2026] [security2:error] [pid 1012520:tid 1012757] [client 140.238.42.111:59316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AnAAAAO8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:27.923312 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.95.14.119:34262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AngAAALY"]
[Thu Sep 17 15:23:27.970400 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.92.151.55:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxaTwpXMN3p_zkwXf3AoAAAALs"]
[Thu Sep 17 15:23:28.003822 2026] [security2:error] [pid 1012520:tid 1012776] [client 140.238.42.111:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaUApXMN3p_zkwXf3AowAAAQI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:28.050972 2026] [security2:error] [pid 1012520:tid 1012718] [client 103.61.184.148:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaUApXMN3p_zkwXf3ApQAAAMg"]
[Thu Sep 17 15:23:28.051112 2026] [security2:error] [pid 1012520:tid 1012718] [client 103.61.184.148:53470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaUApXMN3p_zkwXf3ApQAAAMg"]
[Thu Sep 17 15:23:28.246426 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.95.14.119:34278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxaUApXMN3p_zkwXf3ApgAAAJ0"]
[Thu Sep 17 15:23:28.404338 2026] [security2:error] [pid 1012520:tid 1012748] [client 140.238.42.111:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaUApXMN3p_zkwXf3AqAAAAOY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:28.439286 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.92.151.55:57048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/test.php"] [unique_id "aqxaUApXMN3p_zkwXf3AqQAAAQE"]
[Thu Sep 17 15:23:28.519059 2026] [security2:error] [pid 1012520:tid 1012681] [client 185.55.149.49:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaUApXMN3p_zkwXf3ArQAAAKM"]
[Thu Sep 17 15:23:28.519175 2026] [security2:error] [pid 1012520:tid 1012681] [client 185.55.149.49:57076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaUApXMN3p_zkwXf3ArQAAAKM"]
[Thu Sep 17 15:23:28.687440 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.95.14.119:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxaUApXMN3p_zkwXf3AtAAAAPk"]
[Thu Sep 17 15:23:28.783712 2026] [security2:error] [pid 1012520:tid 1012742] [client 140.238.42.111:60379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaUApXMN3p_zkwXf3AtQAAAOA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:28.809989 2026] [security2:error] [pid 1012520:tid 1012758] [client 156.192.234.52:56761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaUApXMN3p_zkwXf3AtgAAAPA"]
[Thu Sep 17 15:23:28.811366 2026] [security2:error] [pid 1012520:tid 1012758] [client 156.192.234.52:56761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaUApXMN3p_zkwXf3AtgAAAPA"]
[Thu Sep 17 15:23:29.074122 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.92.151.55:57050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/p.php"] [unique_id "aqxaUQpXMN3p_zkwXf3AwwAAAI4"]
[Thu Sep 17 15:23:29.082586 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.95.14.119:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxaUQpXMN3p_zkwXf3AxAAAAMo"]
[Thu Sep 17 15:23:29.206614 2026] [security2:error] [pid 1012520:tid 1012688] [client 140.238.42.111:60724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaUQpXMN3p_zkwXf3AywAAAKo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:29.504489 2026] [security2:error] [pid 1012520:tid 1012722] [client 34.95.14.119:34312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxaUQpXMN3p_zkwXf3A0gAAAMw"]
[Thu Sep 17 15:23:29.547066 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.92.151.55:57058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxaUQpXMN3p_zkwXf3A1QAAAIw"]
[Thu Sep 17 15:23:29.595834 2026] [security2:error] [pid 1012520:tid 1012695] [client 140.238.42.111:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaUQpXMN3p_zkwXf3A1gAAALE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:29.698364 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/.env"] [unique_id "aqxaUQpXMN3p_zkwXf3A2AAAALM"]
[Thu Sep 17 15:23:29.822656 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.95.14.119:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxaUQpXMN3p_zkwXf3A3QAAAM0"]
[Thu Sep 17 15:23:29.985450 2026] [security2:error] [pid 1012520:tid 1012764] [client 140.238.42.111:61415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaUQpXMN3p_zkwXf3A4wAAAPY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:30.055634 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.92.151.55:57062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxaUgpXMN3p_zkwXf3A5wAAAKE"]
[Thu Sep 17 15:23:30.183237 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.95.14.119:34330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxaUgpXMN3p_zkwXf3A6wAAAMg"]
[Thu Sep 17 15:23:30.382117 2026] [security2:error] [pid 1012520:tid 1012777] [client 140.238.42.111:61751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaUgpXMN3p_zkwXf3A8AAAAQM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:30.503890 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.95.14.119:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxaUgpXMN3p_zkwXf3A9QAAAOg"]
[Thu Sep 17 15:23:30.550136 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.92.151.55:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxaUgpXMN3p_zkwXf3A9wAAAI8"]
[Thu Sep 17 15:23:30.782524 2026] [security2:error] [pid 1012520:tid 1012765] [client 140.238.42.111:62075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaUgpXMN3p_zkwXf3A_AAAAPc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:30.817102 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.95.14.119:34360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zfk.auz.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxaUgpXMN3p_zkwXf3A_QAAAMs"]
[Thu Sep 17 15:23:31.039575 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.92.151.55:57082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BBQAAAI0"]
[Thu Sep 17 15:23:31.100841 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/.env.bak"] [unique_id "aqxaUwpXMN3p_zkwXf3BBwAAAJ8"]
[Thu Sep 17 15:23:31.187720 2026] [security2:error] [pid 1012520:tid 1012752] [client 140.238.42.111:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BCAAAAOo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:31.229489 2026] [security2:error] [pid 1012520:tid 1012734] [client 57.141.14.61:32798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BBgAA2F4"]
[Thu Sep 17 15:23:31.259956 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/.env.backup"] [unique_id "aqxaUwpXMN3p_zkwXf3BCgAAAPE"]
[Thu Sep 17 15:23:31.289798 2026] [security2:error] [pid 1012520:tid 1012678] [client 216.73.217.36:28924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maska19.24eastyard.com"] [uri "/index.php"] [unique_id "aqxaUgpXMN3p_zkwXf3BAQAAoGE"]
[Thu Sep 17 15:23:31.542813 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.92.151.55:57086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BEwAAAP0"]
[Thu Sep 17 15:23:31.570449 2026] [security2:error] [pid 1012520:tid 1012686] [client 140.238.42.111:62761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BFgAAAKg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:31.630036 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/.env.old"] [unique_id "aqxaUwpXMN3p_zkwXf3BFwAAAJo"]
[Thu Sep 17 15:23:31.695193 2026] [security2:error] [pid 1012520:tid 1012668] [client 169.58.197.253:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BGQAAAJY"], referer: binance.com
[Thu Sep 17 15:23:31.719453 2026] [security2:error] [pid 1012520:tid 1012747] [client 186.105.232.15:57682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BGgAAAOU"]
[Thu Sep 17 15:23:31.719563 2026] [security2:error] [pid 1012520:tid 1012747] [client 186.105.232.15:57682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BGgAAAOU"]
[Thu Sep 17 15:23:31.965281 2026] [security2:error] [pid 1012520:tid 1012695] [client 140.238.42.111:63065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaUwpXMN3p_zkwXf3BIQAAALE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:32.017603 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.92.151.55:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaVApXMN3p_zkwXf3BJgAAALM"]
[Thu Sep 17 15:23:32.371785 2026] [security2:error] [pid 1012520:tid 1012764] [client 140.238.42.111:63363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaVApXMN3p_zkwXf3BNQAAAPY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:32.523438 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.92.151.55:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxaVApXMN3p_zkwXf3BPgAAAKk"]
[Thu Sep 17 15:23:32.789215 2026] [security2:error] [pid 1012520:tid 1012739] [client 140.238.42.111:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaVApXMN3p_zkwXf3BSAAAAN0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:33.170169 2026] [security2:error] [pid 1012520:tid 1012696] [client 140.238.42.111:64017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaVQpXMN3p_zkwXf3BWQAAALI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:33.204564 2026] [security2:error] [pid 1012520:tid 1012690] [client 34.92.151.55:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxaVQpXMN3p_zkwXf3BXQAAAKw"]
[Thu Sep 17 15:23:33.560197 2026] [security2:error] [pid 1012520:tid 1012769] [client 140.238.42.111:64323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaVQpXMN3p_zkwXf3BaQAAAPs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:33.718395 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.92.151.55:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxaVQpXMN3p_zkwXf3BbQAAAP4"]
[Thu Sep 17 15:23:33.955940 2026] [security2:error] [pid 1012520:tid 1012740] [client 140.238.42.111:64637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaVQpXMN3p_zkwXf3BcgAAAN4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:34.064161 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/.env.swp"] [unique_id "aqxaVgpXMN3p_zkwXf3BdQAAAPo"]
[Thu Sep 17 15:23:34.205579 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.92.151.55:54806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxaVgpXMN3p_zkwXf3BdwAAAOw"]
[Thu Sep 17 15:23:34.231303 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/.env~"] [unique_id "aqxaVgpXMN3p_zkwXf3BeQAAAMA"]
[Thu Sep 17 15:23:34.359279 2026] [security2:error] [pid 1012520:tid 1012727] [client 140.238.42.111:64954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaVgpXMN3p_zkwXf3BewAAANE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:34.455886 2026] [security2:error] [pid 1012520:tid 1012746] [client 57.141.14.52:38694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxaVApXMN3p_zkwXf3BLQAA5FA"]
[Thu Sep 17 15:23:34.677495 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.92.151.55:54816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxaVgpXMN3p_zkwXf3BhwAAAJ4"]
[Thu Sep 17 15:23:34.754376 2026] [security2:error] [pid 1012520:tid 1012755] [client 140.238.42.111:65260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaVgpXMN3p_zkwXf3BiAAAAO0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:35.142221 2026] [security2:error] [pid 1012520:tid 1012739] [client 140.238.42.111:49234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BlwAAAN0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:35.174275 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.92.151.55:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BmAAAAKQ"]
[Thu Sep 17 15:23:35.529492 2026] [security2:error] [pid 1012520:tid 1012698] [client 140.238.42.111:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BqAAAALQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:35.618934 2026] [security2:error] [pid 1012520:tid 1012673] [client 57.141.14.14:25606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BogAAmxk"]
[Thu Sep 17 15:23:35.687774 2026] [security2:error] [pid 1012520:tid 1012688] [client 157.48.236.46:60784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BqwAAqgQ"]
[Thu Sep 17 15:23:35.719502 2026] [security2:error] [pid 1012520:tid 1012738] [client 154.190.208.131:42564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BrwAAANw"]
[Thu Sep 17 15:23:35.719630 2026] [security2:error] [pid 1012520:tid 1012738] [client 154.190.208.131:42564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BrwAAANw"]
[Thu Sep 17 15:23:35.730454 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.92.151.55:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BsAAAAIs"]
[Thu Sep 17 15:23:35.842968 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/app/.env"] [unique_id "aqxaVwpXMN3p_zkwXf3BtAAAALU"]
[Thu Sep 17 15:23:35.924148 2026] [security2:error] [pid 1012520:tid 1012664] [client 140.238.42.111:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaVwpXMN3p_zkwXf3BtQAAAJI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:36.013520 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/apps/.env"] [unique_id "aqxaWApXMN3p_zkwXf3BuAAAAP4"]
[Thu Sep 17 15:23:36.171213 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/api/.env"] [unique_id "aqxaWApXMN3p_zkwXf3BuwAAAPo"]
[Thu Sep 17 15:23:36.330767 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/web/.env"] [unique_id "aqxaWApXMN3p_zkwXf3BvgAAAP0"]
[Thu Sep 17 15:23:36.337493 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaWApXMN3p_zkwXf3BvwAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:36.487113 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/site/.env"] [unique_id "aqxaWApXMN3p_zkwXf3BwgAAAKs"]
[Thu Sep 17 15:23:36.500062 2026] [security2:error] [pid 1012520:tid 1012729] [client 168.138.205.35:51735] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "nebulous-llc.com"] [uri "/"] [unique_id "aqxaWApXMN3p_zkwXf3BwQAAANM"]
[Thu Sep 17 15:23:36.578056 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.92.151.55:54850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxaWApXMN3p_zkwXf3BxQAAAOk"]
[Thu Sep 17 15:23:36.645490 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/public/.env"] [unique_id "aqxaWApXMN3p_zkwXf3BxwAAAM8"]
[Thu Sep 17 15:23:36.736393 2026] [security2:error] [pid 1012520:tid 1012764] [client 140.238.42.111:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaWApXMN3p_zkwXf3ByAAAAPY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:37.019167 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/backend/.env"] [unique_id "aqxaWQpXMN3p_zkwXf3B0AAAALA"]
[Thu Sep 17 15:23:37.067491 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.92.151.55:54866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxaWQpXMN3p_zkwXf3B0gAAAOY"]
[Thu Sep 17 15:23:37.142509 2026] [security2:error] [pid 1012520:tid 1012681] [client 140.238.42.111:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaWQpXMN3p_zkwXf3B1QAAAKM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:37.179105 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/server/.env"] [unique_id "aqxaWQpXMN3p_zkwXf3B1wAAANY"]
[Thu Sep 17 15:23:37.339486 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/frontend/.env"] [unique_id "aqxaWQpXMN3p_zkwXf3B2wAAAJQ"]
[Thu Sep 17 15:23:37.504315 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/src/.env"] [unique_id "aqxaWQpXMN3p_zkwXf3B3QAAANI"]
[Thu Sep 17 15:23:37.537245 2026] [security2:error] [pid 1012520:tid 1012683] [client 140.238.42.111:51275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaWQpXMN3p_zkwXf3B4AAAAKU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:37.591051 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.92.151.55:54878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxaWQpXMN3p_zkwXf3B4gAAAOI"]
[Thu Sep 17 15:23:37.665565 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/core/.env"] [unique_id "aqxaWQpXMN3p_zkwXf3B5gAAAJo"]
[Thu Sep 17 15:23:37.827234 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/core/app/.env"] [unique_id "aqxaWQpXMN3p_zkwXf3B5wAAAIs"]
[Thu Sep 17 15:23:37.936615 2026] [security2:error] [pid 1012520:tid 1012745] [client 140.238.42.111:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaWQpXMN3p_zkwXf3B6AAAAOM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:37.980056 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/config/.env"] [unique_id "aqxaWQpXMN3p_zkwXf3B6QAAANk"]
[Thu Sep 17 15:23:38.081137 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.92.151.55:54880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxaWgpXMN3p_zkwXf3B7QAAAJU"]
[Thu Sep 17 15:23:38.137180 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/private/.env"] [unique_id "aqxaWgpXMN3p_zkwXf3B7gAAALI"]
[Thu Sep 17 15:23:38.273464 2026] [security2:error] [pid 1012520:tid 1012769] [client 114.198.138.124:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaWgpXMN3p_zkwXf3B7wAAAPs"]
[Thu Sep 17 15:23:38.273583 2026] [security2:error] [pid 1012520:tid 1012769] [client 114.198.138.124:55499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaWgpXMN3p_zkwXf3B7wAAAPs"]
[Thu Sep 17 15:23:38.294010 2026] [security2:error] [pid 1012520:tid 1012654] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/application/.env"] [unique_id "aqxaWgpXMN3p_zkwXf3B8AAAAIg"]
[Thu Sep 17 15:23:38.318791 2026] [security2:error] [pid 1012520:tid 1012712] [client 140.238.42.111:51928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaWgpXMN3p_zkwXf3B8QAAAMI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:38.448214 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/bootstrap/.env"] [unique_id "aqxaWgpXMN3p_zkwXf3B9AAAAO8"]
[Thu Sep 17 15:23:38.568866 2026] [security2:error] [pid 1012520:tid 1012733] [client 177.104.21.20:7025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaWgpXMN3p_zkwXf3B8wAA1x4"]
[Thu Sep 17 15:23:38.569711 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.92.151.55:54888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxaWgpXMN3p_zkwXf3B_QAAAJI"]
[Thu Sep 17 15:23:38.604736 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/database/.env"] [unique_id "aqxaWgpXMN3p_zkwXf3B_gAAAP0"]
[Thu Sep 17 15:23:38.701008 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaWgpXMN3p_zkwXf3B_wAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:38.761988 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/storage/.env"] [unique_id "aqxaWgpXMN3p_zkwXf3CAQAAAIk"]
[Thu Sep 17 15:23:38.915169 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/var/www/.env"] [unique_id "aqxaWgpXMN3p_zkwXf3CAgAAAOQ"]
[Thu Sep 17 15:23:39.059763 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.92.151.55:54902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CBQAAAOk"]
[Thu Sep 17 15:23:39.072466 2026] [security2:error] [pid 1012520:tid 1012749] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/var/www/html/.env"] [unique_id "aqxaWwpXMN3p_zkwXf3CBgAAAOc"]
[Thu Sep 17 15:23:39.083862 2026] [security2:error] [pid 1012520:tid 1012724] [client 140.238.42.111:52577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CBwAAAM4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:39.225923 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/current/.env"] [unique_id "aqxaWwpXMN3p_zkwXf3CCQAAAJ4"]
[Thu Sep 17 15:23:39.231123 2026] [security2:error] [pid 1012520:tid 1012700] [client 103.61.184.148:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CCgAAALY"]
[Thu Sep 17 15:23:39.231233 2026] [security2:error] [pid 1012520:tid 1012700] [client 103.61.184.148:54024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CCgAAALY"]
[Thu Sep 17 15:23:39.283469 2026] [security2:error] [pid 1012520:tid 1012656] [client 169.58.197.253:63754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CCwAAAIo"], referer: binance.com
[Thu Sep 17 15:23:39.323357 2026] [security2:error] [pid 1012520:tid 1012760] [client 185.55.149.49:57779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CDAAAAPI"]
[Thu Sep 17 15:23:39.323466 2026] [security2:error] [pid 1012520:tid 1012760] [client 185.55.149.49:57779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CDAAAAPI"]
[Thu Sep 17 15:23:39.332624 2026] [security2:error] [pid 1012520:tid 1012764] [client 156.192.234.52:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CDQAAAPY"]
[Thu Sep 17 15:23:39.333329 2026] [security2:error] [pid 1012520:tid 1012764] [client 156.192.234.52:57379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CDQAAAPY"]
[Thu Sep 17 15:23:39.384083 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/release/.env"] [unique_id "aqxaWwpXMN3p_zkwXf3CDgAAAJg"]
[Thu Sep 17 15:23:39.470370 2026] [security2:error] [pid 1012520:tid 1012718] [client 140.238.42.111:52867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CDwAAAMg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:39.536341 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/releases/.env"] [unique_id "aqxaWwpXMN3p_zkwXf3CFAAAAQA"]
[Thu Sep 17 15:23:39.544262 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.92.151.55:54912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxaWwpXMN3p_zkwXf3CFgAAAI8"]
[Thu Sep 17 15:23:39.690591 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/shared/.env"] [unique_id "aqxaWwpXMN3p_zkwXf3CGQAAAMs"]
[Thu Sep 17 15:23:39.850465 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/deploy/.env"] [unique_id "aqxaWwpXMN3p_zkwXf3CGgAAALg"]
[Thu Sep 17 15:23:39.867306 2026] [security2:error] [pid 1012520:tid 1012666] [client 140.238.42.111:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaWwpXMN3p_zkwXf3CGwAAAJQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:40.012530 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/build/.env"] [unique_id "aqxaXApXMN3p_zkwXf3CHAAAAKU"]
[Thu Sep 17 15:23:40.035220 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.92.151.55:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxaXApXMN3p_zkwXf3CHwAAANI"]
[Thu Sep 17 15:23:40.173019 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/dist/.env"] [unique_id "aqxaXApXMN3p_zkwXf3CIQAAALo"]
[Thu Sep 17 15:23:40.267171 2026] [security2:error] [pid 1012520:tid 1012698] [client 140.238.42.111:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaXApXMN3p_zkwXf3CIgAAALQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:40.329835 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/public_html/.env"] [unique_id "aqxaXApXMN3p_zkwXf3CIwAAALk"]
[Thu Sep 17 15:23:40.487912 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/htdocs/.env"] [unique_id "aqxaXApXMN3p_zkwXf3CJAAAAJM"]
[Thu Sep 17 15:23:40.522061 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.92.151.55:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxaXApXMN3p_zkwXf3CKAAAAI4"]
[Thu Sep 17 15:23:40.653100 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/www/.env"] [unique_id "aqxaXApXMN3p_zkwXf3CKgAAAOo"]
[Thu Sep 17 15:23:40.672410 2026] [security2:error] [pid 1012520:tid 1012730] [client 140.238.42.111:53845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaXApXMN3p_zkwXf3CKwAAANQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:40.820545 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/html/.env"] [unique_id "aqxaXApXMN3p_zkwXf3CLwAAAOM"]
[Thu Sep 17 15:23:40.978246 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/live/.env"] [unique_id "aqxaXApXMN3p_zkwXf3CMQAAAPs"]
[Thu Sep 17 15:23:41.013869 2026] [security2:error] [pid 1012520:tid 1012735] [client 34.92.151.55:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxaXQpXMN3p_zkwXf3CNAAAANk"]
[Thu Sep 17 15:23:41.037822 2026] [security2:error] [pid 1012520:tid 1012761] [client 185.191.171.12:52936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jwdnyc.com"] [uri "/robots.txt"] [unique_id "aqxaXQpXMN3p_zkwXf3CNQAAAPM"]
[Thu Sep 17 15:23:41.037971 2026] [security2:error] [pid 1012520:tid 1012761] [client 185.191.171.12:52936] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jwdnyc.com"] [uri "/robots.txt"] [unique_id "aqxaXQpXMN3p_zkwXf3CNQAAAPM"]
[Thu Sep 17 15:23:41.055584 2026] [security2:error] [pid 1012520:tid 1012770] [client 140.238.42.111:54171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaXQpXMN3p_zkwXf3CNgAAAPw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:41.151560 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/prod/.env"] [unique_id "aqxaXQpXMN3p_zkwXf3COAAAALE"]
[Thu Sep 17 15:23:41.305095 2026] [security2:error] [pid 1012520:tid 1012731] [client 185.191.171.9:35412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jwdnyc.com"] [uri "/"] [unique_id "aqxaXQpXMN3p_zkwXf3COgAAANU"]
[Thu Sep 17 15:23:41.305243 2026] [security2:error] [pid 1012520:tid 1012731] [client 185.191.171.9:35412] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jwdnyc.com"] [uri "/"] [unique_id "aqxaXQpXMN3p_zkwXf3COgAAANU"]
[Thu Sep 17 15:23:41.318438 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/dev/.env"] [unique_id "aqxaXQpXMN3p_zkwXf3COwAAAMk"]
[Thu Sep 17 15:23:41.445884 2026] [security2:error] [pid 1012520:tid 1012727] [client 140.238.42.111:54528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaXQpXMN3p_zkwXf3CPQAAANE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:41.472639 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/staging/.env"] [unique_id "aqxaXQpXMN3p_zkwXf3CPgAAAMA"]
[Thu Sep 17 15:23:41.502162 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.92.151.55:54946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxaXQpXMN3p_zkwXf3CPwAAAI0"]
[Thu Sep 17 15:23:41.625550 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/opt/.env"] [unique_id "aqxaXQpXMN3p_zkwXf3CQwAAAN8"]
[Thu Sep 17 15:23:41.779619 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/laravel/.env"] [unique_id "aqxaXQpXMN3p_zkwXf3CRAAAAK0"]
[Thu Sep 17 15:23:41.829877 2026] [security2:error] [pid 1012520:tid 1012746] [client 140.238.42.111:54820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaXQpXMN3p_zkwXf3CRQAAAOQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:41.914236 2026] [authz_core:error] [pid 1012520:tid 1012726] [client 5.189.145.112:49311] AH01630: client denied by server configuration: /home3/chrisvu8/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:23:41.933517 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.154.219.37:57818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/symfony/.env"] [unique_id "aqxaXQpXMN3p_zkwXf3CRwAAAOk"]
[Thu Sep 17 15:23:42.016809 2026] [security2:error] [pid 1012520:tid 1012749] [client 24.45.219.199:50073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.enduringwanderlust.com"] [uri "/index.php"] [unique_id "aqxaXQpXMN3p_zkwXf3CSAAA5yQ"]
[Thu Sep 17 15:23:42.020489 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.92.151.55:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxaXgpXMN3p_zkwXf3CTAAAAN4"]
[Thu Sep 17 15:23:42.219199 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:55115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaXgpXMN3p_zkwXf3CTwAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:42.395458 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/wordpress/.env"] [unique_id "aqxaXgpXMN3p_zkwXf3CUwAAAKM"]
[Thu Sep 17 15:23:42.525577 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.92.151.55:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxaXgpXMN3p_zkwXf3CWAAAAIw"]
[Thu Sep 17 15:23:42.556391 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/wp/.env"] [unique_id "aqxaXgpXMN3p_zkwXf3CWQAAAJw"]
[Thu Sep 17 15:23:42.642271 2026] [security2:error] [pid 1012520:tid 1012652] [client 140.238.42.111:55435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaXgpXMN3p_zkwXf3CWwAAAIY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:42.711583 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/cms/.env"] [unique_id "aqxaXgpXMN3p_zkwXf3CXAAAAKU"]
[Thu Sep 17 15:23:42.847297 2026] [security2:error] [pid 1012520:tid 1012744] [client 17.166.21.250:58218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hole.cyberpunkonline.net"] [uri "/index.php"] [unique_id "aqxaXgpXMN3p_zkwXf3CXgAAAOI"]
[Thu Sep 17 15:23:42.872414 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/drupal/.env"] [unique_id "aqxaXgpXMN3p_zkwXf3CXwAAAPc"]
[Thu Sep 17 15:23:43.022492 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.92.151.55:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxaXwpXMN3p_zkwXf3CZQAAALQ"]
[Thu Sep 17 15:23:43.031905 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/joomla/.env"] [unique_id "aqxaXwpXMN3p_zkwXf3CZgAAAJo"]
[Thu Sep 17 15:23:43.055955 2026] [security2:error] [pid 1012520:tid 1012703] [client 140.238.42.111:55814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaXwpXMN3p_zkwXf3CaQAAALk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:43.183736 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/magento/.env"] [unique_id "aqxaXwpXMN3p_zkwXf3CawAAANg"]
[Thu Sep 17 15:23:43.335406 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/shopify/.env"] [unique_id "aqxaXwpXMN3p_zkwXf3CbQAAALI"]
[Thu Sep 17 15:23:43.449318 2026] [security2:error] [pid 1012520:tid 1012667] [client 140.238.42.111:56178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaXwpXMN3p_zkwXf3CbgAAAJU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:43.490503 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/prestashop/.env"] [unique_id "aqxaXwpXMN3p_zkwXf3CbwAAAJA"]
[Thu Sep 17 15:23:43.560821 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.92.151.55:52350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxaXwpXMN3p_zkwXf3CcwAAAL8"]
[Thu Sep 17 15:23:43.574626 2026] [security2:error] [pid 1012520:tid 1012686] [client 186.105.232.15:58298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaXwpXMN3p_zkwXf3CdAAAAKg"]
[Thu Sep 17 15:23:43.574762 2026] [security2:error] [pid 1012520:tid 1012686] [client 186.105.232.15:58298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaXwpXMN3p_zkwXf3CdAAAAKg"]
[Thu Sep 17 15:23:43.642894 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/codeigniter/.env"] [unique_id "aqxaXwpXMN3p_zkwXf3CdQAAAO8"]
[Thu Sep 17 15:23:43.797939 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/cakephp/.env"] [unique_id "aqxaXwpXMN3p_zkwXf3CdgAAANc"]
[Thu Sep 17 15:23:43.834762 2026] [security2:error] [pid 1012520:tid 1012677] [client 140.238.42.111:56507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaXwpXMN3p_zkwXf3CdwAAAJ8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:43.949063 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/zend/.env"] [unique_id "aqxaXwpXMN3p_zkwXf3CeQAAAJE"]
[Thu Sep 17 15:23:44.075868 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.92.151.55:52354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxaYApXMN3p_zkwXf3CfQAAAMY"]
[Thu Sep 17 15:23:44.101801 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/yii/.env"] [unique_id "aqxaYApXMN3p_zkwXf3CfgAAALM"]
[Thu Sep 17 15:23:44.212875 2026] [security2:error] [pid 1012520:tid 1012719] [client 140.238.42.111:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaYApXMN3p_zkwXf3CfwAAAMk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:44.255021 2026] [security2:error] [pid 1012520:tid 1012710] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/laravel5/.env"] [unique_id "aqxaYApXMN3p_zkwXf3CgQAAAMA"]
[Thu Sep 17 15:23:44.407381 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/v1/.env"] [unique_id "aqxaYApXMN3p_zkwXf3CiAAAAMo"]
[Thu Sep 17 15:23:44.564899 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/v2/.env"] [unique_id "aqxaYApXMN3p_zkwXf3CjAAAAOs"]
[Thu Sep 17 15:23:44.570485 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.92.151.55:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxaYApXMN3p_zkwXf3CjQAAAJ0"]
[Thu Sep 17 15:23:44.605044 2026] [security2:error] [pid 1012520:tid 1012725] [client 140.238.42.111:57139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaYApXMN3p_zkwXf3CjwAAAM8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:44.660280 2026] [security2:error] [pid 1012520:tid 1012746] [client 45.184.194.219:4911] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaYApXMN3p_zkwXf3CiwAA5Fs"]
[Thu Sep 17 15:23:44.727766 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/v3/.env"] [unique_id "aqxaYApXMN3p_zkwXf3CkAAAAOk"]
[Thu Sep 17 15:23:44.886673 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/api/v1/.env"] [unique_id "aqxaYApXMN3p_zkwXf3CkQAAAIo"]
[Thu Sep 17 15:23:45.001498 2026] [security2:error] [pid 1012520:tid 1012707] [client 140.238.42.111:57457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaYQpXMN3p_zkwXf3CkgAAAL0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:45.045876 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/api/v2/.env"] [unique_id "aqxaYQpXMN3p_zkwXf3ClQAAAJg"]
[Thu Sep 17 15:23:45.098742 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.92.151.55:52370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxaYQpXMN3p_zkwXf3ClgAAAPY"]
[Thu Sep 17 15:23:45.202748 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/rest/.env"] [unique_id "aqxaYQpXMN3p_zkwXf3CmgAAAMg"]
[Thu Sep 17 15:23:45.357195 2026] [security2:error] [pid 1012520:tid 1012661] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/graphql/.env"] [unique_id "aqxaYQpXMN3p_zkwXf3CnAAAAI8"]
[Thu Sep 17 15:23:45.373581 2026] [security2:error] [pid 1012520:tid 1012774] [client 169.58.197.253:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxaYQpXMN3p_zkwXf3CngAAAQA"], referer: binance.com
[Thu Sep 17 15:23:45.407591 2026] [security2:error] [pid 1012520:tid 1012682] [client 140.238.42.111:57780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaYQpXMN3p_zkwXf3CnwAAAKQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:45.516362 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/gateway/.env"] [unique_id "aqxaYQpXMN3p_zkwXf3CoQAAAIY"]
[Thu Sep 17 15:23:45.595519 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.92.151.55:52376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxaYQpXMN3p_zkwXf3CpAAAAJw"]
[Thu Sep 17 15:23:45.673844 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/microservice/.env"] [unique_id "aqxaYQpXMN3p_zkwXf3CpgAAAJk"]
[Thu Sep 17 15:23:45.802038 2026] [security2:error] [pid 1012520:tid 1012766] [client 140.238.42.111:58079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaYQpXMN3p_zkwXf3CpwAAAPg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:45.826665 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/service/.env"] [unique_id "aqxaYQpXMN3p_zkwXf3CqAAAALQ"]
[Thu Sep 17 15:23:45.983490 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/api/v3/.env"] [unique_id "aqxaYQpXMN3p_zkwXf3CqQAAANQ"]
[Thu Sep 17 15:23:46.118622 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.92.151.55:52388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxaYgpXMN3p_zkwXf3CsAAAAJo"]
[Thu Sep 17 15:23:46.137366 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/api/dev/.env"] [unique_id "aqxaYgpXMN3p_zkwXf3CsQAAAP8"]
[Thu Sep 17 15:23:46.145072 2026] [security2:error] [pid 1012520:tid 1012653] [client 200.119.32.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxaYApXMN3p_zkwXf3ChwAAAIc"], referer: https://kslandscaping.net/
[Thu Sep 17 15:23:46.170629 2026] [security2:error] [pid 1012520:tid 1012743] [client 154.190.208.131:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaYgpXMN3p_zkwXf3CsgAAAOE"]
[Thu Sep 17 15:23:46.177539 2026] [security2:error] [pid 1012520:tid 1012743] [client 154.190.208.131:41804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaYgpXMN3p_zkwXf3CsgAAAOE"]
[Thu Sep 17 15:23:46.202629 2026] [security2:error] [pid 1012520:tid 1012734] [client 140.238.42.111:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaYgpXMN3p_zkwXf3CswAAANg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:46.292480 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/api/staging/.env"] [unique_id "aqxaYgpXMN3p_zkwXf3CtAAAAJA"]
[Thu Sep 17 15:23:46.447255 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/vendor/.env"] [unique_id "aqxaYgpXMN3p_zkwXf3CtQAAAO8"]
[Thu Sep 17 15:23:46.597012 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:58760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaYgpXMN3p_zkwXf3CuAAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:46.598735 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/lib/.env"] [unique_id "aqxaYgpXMN3p_zkwXf3CuQAAAJY"]
[Thu Sep 17 15:23:46.607425 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.92.151.55:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxaYgpXMN3p_zkwXf3CuwAAAPs"]
[Thu Sep 17 15:23:46.762894 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/resources/.env"] [unique_id "aqxaYgpXMN3p_zkwXf3CvAAAAJ8"]
[Thu Sep 17 15:23:46.914582 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/assets/.env"] [unique_id "aqxaYgpXMN3p_zkwXf3CvgAAAME"]
[Thu Sep 17 15:23:46.991109 2026] [security2:error] [pid 1012520:tid 1012663] [client 140.238.42.111:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaYgpXMN3p_zkwXf3CwAAAAJE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:47.070134 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/uploads/.env"] [unique_id "aqxaYwpXMN3p_zkwXf3CxQAAAMU"]
[Thu Sep 17 15:23:47.114160 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.92.151.55:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxaYwpXMN3p_zkwXf3CyAAAAP4"]
[Thu Sep 17 15:23:47.133514 2026] [fcgid:warn] [pid 1012520:tid 1012735] (70014)End of file found: [client 165.154.134.203:43210] mod_fcgid: can't get data from http client
[Thu Sep 17 15:23:47.219607 2026] [security2:error] [pid 1012520:tid 1012727] [client 169.224.21.142:29360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaYwpXMN3p_zkwXf3CxwAA0Sw"]
[Thu Sep 17 15:23:47.222207 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/internal/.env"] [unique_id "aqxaYwpXMN3p_zkwXf3CzAAAAOs"]
[Thu Sep 17 15:23:47.375179 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/tools/.env"] [unique_id "aqxaYwpXMN3p_zkwXf3CzwAAAO0"]
[Thu Sep 17 15:23:47.386724 2026] [security2:error] [pid 1012520:tid 1012746] [client 140.238.42.111:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaYwpXMN3p_zkwXf3C0AAAAOQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:47.528548 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/scripts/.env"] [unique_id "aqxaYwpXMN3p_zkwXf3C1gAAAIo"]
[Thu Sep 17 15:23:47.607448 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.92.151.55:52404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxaYwpXMN3p_zkwXf3C2AAAALs"]
[Thu Sep 17 15:23:47.680166 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/bin/.env"] [unique_id "aqxaYwpXMN3p_zkwXf3C2wAAAO4"]
[Thu Sep 17 15:23:47.763354 2026] [security2:error] [pid 1012520:tid 1012764] [client 140.238.42.111:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaYwpXMN3p_zkwXf3C3AAAAPY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:47.832539 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/sbin/.env"] [unique_id "aqxaYwpXMN3p_zkwXf3C3QAAAMs"]
[Thu Sep 17 15:23:47.956715 2026] [security2:error] [pid 1012520:tid 1012589] [remote 5.253.204.74:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.204.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zvt.lil.mybluehost.me"] [uri "/website_70311838/wp-login.php"] [unique_id "aqxaYwpXMN3p_zkwXf3C3gAAsEM"], referer: https://zvt.lil.mybluehost.me/website_70311838/
[Thu Sep 17 15:23:47.990596 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/local/.env"] [unique_id "aqxaYwpXMN3p_zkwXf3C4AAAAIw"]
[Thu Sep 17 15:23:48.113424 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.92.151.55:52412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxaZApXMN3p_zkwXf3C5AAAAMQ"]
[Thu Sep 17 15:23:48.143569 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/portal/.env"] [unique_id "aqxaZApXMN3p_zkwXf3C5gAAAQE"]
[Thu Sep 17 15:23:48.145947 2026] [security2:error] [pid 1012520:tid 1012683] [client 140.238.42.111:60062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaZApXMN3p_zkwXf3C5wAAAKU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:48.294692 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/dashboard/.env"] [unique_id "aqxaZApXMN3p_zkwXf3C6gAAAJQ"]
[Thu Sep 17 15:23:48.447870 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/panel/.env"] [unique_id "aqxaZApXMN3p_zkwXf3C8AAAAOo"]
[Thu Sep 17 15:23:48.544421 2026] [security2:error] [pid 1012520:tid 1012713] [client 140.238.42.111:60361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaZApXMN3p_zkwXf3C9gAAAMM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:48.549921 2026] [security2:error] [pid 1012520:tid 1012678] [client 162.241.226.11:58132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bppa-nb.com"] [uri "/wp-content/plugins/event-tickets-plus/src/resources/images/tickets-wallet-plus/example-qr.png"] [unique_id "aqxaZApXMN3p_zkwXf3C9wAAAKA"]
[Thu Sep 17 15:23:48.607142 2026] [security2:error] [pid 1012520:tid 1012696] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/crm/.env"] [unique_id "aqxaZApXMN3p_zkwXf3C-QAAALI"]
[Thu Sep 17 15:23:48.612624 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.92.151.55:52416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.151.92.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uxz.hui.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxaZApXMN3p_zkwXf3C-gAAAIs"]
[Thu Sep 17 15:23:48.758925 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/erp/.env"] [unique_id "aqxaZApXMN3p_zkwXf3C_AAAAJY"]
[Thu Sep 17 15:23:48.907476 2026] [security2:error] [pid 1012520:tid 1012688] [client 114.198.138.124:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaZApXMN3p_zkwXf3C_gAAAKo"]
[Thu Sep 17 15:23:48.907548 2026] [security2:error] [pid 1012520:tid 1012688] [client 114.198.138.124:62497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaZApXMN3p_zkwXf3C_gAAAKo"]
[Thu Sep 17 15:23:48.911327 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/shop/.env"] [unique_id "aqxaZApXMN3p_zkwXf3C_wAAAJ8"]
[Thu Sep 17 15:23:48.925088 2026] [security2:error] [pid 1012520:tid 1012722] [client 140.238.42.111:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaZApXMN3p_zkwXf3DAAAAAMw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:49.062913 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/store/.env"] [unique_id "aqxaZQpXMN3p_zkwXf3DBAAAAOA"]
[Thu Sep 17 15:23:49.218649 2026] [security2:error] [pid 1012520:tid 1012719] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/saas/.env"] [unique_id "aqxaZQpXMN3p_zkwXf3DBwAAAMk"]
[Thu Sep 17 15:23:49.320783 2026] [security2:error] [pid 1012520:tid 1012715] [client 140.238.42.111:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaZQpXMN3p_zkwXf3DCQAAAMU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:49.378477 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/client/.env"] [unique_id "aqxaZQpXMN3p_zkwXf3DCgAAAMI"]
[Thu Sep 17 15:23:49.532917 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/project/.env"] [unique_id "aqxaZQpXMN3p_zkwXf3DEQAAAOU"]
[Thu Sep 17 15:23:49.698691 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/admin-panel/.env"] [unique_id "aqxaZQpXMN3p_zkwXf3DFQAAAKE"]
[Thu Sep 17 15:23:49.715893 2026] [security2:error] [pid 1012520:tid 1012738] [client 140.238.42.111:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaZQpXMN3p_zkwXf3DFgAAANw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:49.728900 2026] [security2:error] [pid 1012520:tid 1012725] [client 141.94.94.46:52370] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1452"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.maggietheturtle.com"] [uri "/"] [unique_id "aqxaZQpXMN3p_zkwXf3DFwAAAM8"]
[Thu Sep 17 15:23:49.859226 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/control-panel/.env"] [unique_id "aqxaZQpXMN3p_zkwXf3DGQAAAOQ"]
[Thu Sep 17 15:23:49.962141 2026] [security2:error] [pid 1012520:tid 1012735] [client 103.61.184.148:54583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaZQpXMN3p_zkwXf3DGgAAANk"]
[Thu Sep 17 15:23:49.962259 2026] [security2:error] [pid 1012520:tid 1012735] [client 103.61.184.148:54583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaZQpXMN3p_zkwXf3DGgAAANk"]
[Thu Sep 17 15:23:50.002339 2026] [security2:error] [pid 1012520:tid 1012727] [client 156.192.234.52:58013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaZQpXMN3p_zkwXf3DGwAAANE"]
[Thu Sep 17 15:23:50.002448 2026] [security2:error] [pid 1012520:tid 1012727] [client 156.192.234.52:58013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaZQpXMN3p_zkwXf3DGwAAANE"]
[Thu Sep 17 15:23:50.020554 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/user-panel/.env"] [unique_id "aqxaZgpXMN3p_zkwXf3DHgAAAM0"]
[Thu Sep 17 15:23:50.101812 2026] [security2:error] [pid 1012520:tid 1012778] [client 140.238.42.111:61608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaZgpXMN3p_zkwXf3DIAAAAQQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:50.165732 2026] [security2:error] [pid 1012520:tid 1012691] [client 185.55.149.49:59366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaZgpXMN3p_zkwXf3DIwAAAK0"]
[Thu Sep 17 15:23:50.166794 2026] [security2:error] [pid 1012520:tid 1012691] [client 185.55.149.49:59366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaZgpXMN3p_zkwXf3DIwAAAK0"]
[Thu Sep 17 15:23:50.185814 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/node/.env"] [unique_id "aqxaZgpXMN3p_zkwXf3DJAAAAJg"]
[Thu Sep 17 15:23:50.339198 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/express/.env"] [unique_id "aqxaZgpXMN3p_zkwXf3DKAAAAIU"]
[Thu Sep 17 15:23:50.500345 2026] [security2:error] [pid 1012520:tid 1012659] [client 140.238.42.111:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaZgpXMN3p_zkwXf3DKgAAAI0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:50.503144 2026] [security2:error] [pid 1012520:tid 1012721] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/next/.env"] [unique_id "aqxaZgpXMN3p_zkwXf3DKwAAAMs"]
[Thu Sep 17 15:23:50.657843 2026] [security2:error] [pid 1012520:tid 1012762] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/nuxt/.env"] [unique_id "aqxaZgpXMN3p_zkwXf3DLwAAAPQ"]
[Thu Sep 17 15:23:50.810820 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/nest/.env"] [unique_id "aqxaZgpXMN3p_zkwXf3DNQAAAIY"]
[Thu Sep 17 15:23:50.881935 2026] [security2:error] [pid 1012520:tid 1012714] [client 140.238.42.111:62274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaZgpXMN3p_zkwXf3DNwAAAMQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:50.963104 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/react/.env"] [unique_id "aqxaZgpXMN3p_zkwXf3DOAAAAPE"]
[Thu Sep 17 15:23:51.016173 2026] [security2:error] [pid 1012520:tid 1012654] [client 162.241.226.11:58154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxaZgpXMN3p_zkwXf3DJgAAAIg"]
[Thu Sep 17 15:23:51.119377 2026] [security2:error] [pid 1012520:tid 1012743] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/vue/.env"] [unique_id "aqxaZwpXMN3p_zkwXf3DPgAAAOE"]
[Thu Sep 17 15:23:51.263068 2026] [security2:error] [pid 1012520:tid 1012766] [client 140.238.42.111:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaZwpXMN3p_zkwXf3DQgAAAPg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:51.277773 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/angular/.env"] [unique_id "aqxaZwpXMN3p_zkwXf3DQwAAAKA"]
[Thu Sep 17 15:23:51.440776 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/svelte/.env"] [unique_id "aqxaZwpXMN3p_zkwXf3DRgAAAIs"]
[Thu Sep 17 15:23:51.592908 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/vite/.env"] [unique_id "aqxaZwpXMN3p_zkwXf3DTAAAAI4"]
[Thu Sep 17 15:23:51.645368 2026] [security2:error] [pid 1012520:tid 1012709] [client 140.238.42.111:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaZwpXMN3p_zkwXf3DTQAAAL8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:51.749991 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/backup/.env"] [unique_id "aqxaZwpXMN3p_zkwXf3DUgAAAJM"]
[Thu Sep 17 15:23:51.784265 2026] [security2:error] [pid 1012520:tid 1012717] [client 169.58.197.253:64566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-filter-sentinel.php"] [unique_id "aqxaZwpXMN3p_zkwXf3DUwAAAMc"], referer: binance.com
[Thu Sep 17 15:23:51.905604 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/backups/.env"] [unique_id "aqxaZwpXMN3p_zkwXf3DVwAAAMY"]
[Thu Sep 17 15:23:51.911650 2026] [autoindex:error] [pid 1012520:tid 1012722] [client 34.92.151.55:52422] AH01276: Cannot serve directory /home1/uxzhuimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:23:52.052770 2026] [security2:error] [pid 1012520:tid 1012699] [client 140.238.42.111:63184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaaApXMN3p_zkwXf3DXQAAALU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:52.057440 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/old/.env"] [unique_id "aqxaaApXMN3p_zkwXf3DXwAAAM8"]
[Thu Sep 17 15:23:52.070070 2026] [security2:error] [pid 1012520:tid 1012675] [client 162.241.226.11:58174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxaZwpXMN3p_zkwXf3DPAAAAIc"]
[Thu Sep 17 15:23:52.211112 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/tmp/.env"] [unique_id "aqxaaApXMN3p_zkwXf3DYwAAANE"]
[Thu Sep 17 15:23:52.363783 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/temp/.env"] [unique_id "aqxaaApXMN3p_zkwXf3DZwAAALs"]
[Thu Sep 17 15:23:52.443042 2026] [security2:error] [pid 1012520:tid 1012751] [client 140.238.42.111:63480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaaApXMN3p_zkwXf3DagAAAOk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:52.518358 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/lab/.env"] [unique_id "aqxaaApXMN3p_zkwXf3DbgAAALA"]
[Thu Sep 17 15:23:52.674171 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/cronlab/.env"] [unique_id "aqxaaApXMN3p_zkwXf3DcAAAAIY"]
[Thu Sep 17 15:23:52.830394 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/cron/.env"] [unique_id "aqxaaApXMN3p_zkwXf3DcgAAALo"]
[Thu Sep 17 15:23:52.845431 2026] [security2:error] [pid 1012520:tid 1012669] [client 140.238.42.111:63767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaaApXMN3p_zkwXf3DcwAAAJc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:52.984108 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/en/.env"] [unique_id "aqxaaApXMN3p_zkwXf3DdwAAANQ"]
[Thu Sep 17 15:23:53.201646 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/administrator/.env"] [unique_id "aqxaaQpXMN3p_zkwXf3DfAAAAMM"]
[Thu Sep 17 15:23:53.243783 2026] [security2:error] [pid 1012520:tid 1012736] [client 140.238.42.111:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaaQpXMN3p_zkwXf3DgwAAANo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:53.363964 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/psnlink/.env"] [unique_id "aqxaaQpXMN3p_zkwXf3DhAAAAP8"]
[Thu Sep 17 15:23:53.458889 2026] [security2:error] [pid 1012520:tid 1012657] [client 5.189.145.112:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxaaQpXMN3p_zkwXf3DhQAAAIs"], referer: binance.com
[Thu Sep 17 15:23:53.516635 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/exapi/.env"] [unique_id "aqxaaQpXMN3p_zkwXf3DhgAAAMo"]
[Thu Sep 17 15:23:53.641004 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaaQpXMN3p_zkwXf3DigAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:53.669179 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/sitemaps/.env"] [unique_id "aqxaaQpXMN3p_zkwXf3DiwAAAJs"]
[Thu Sep 17 15:23:54.036628 2026] [security2:error] [pid 1012520:tid 1012722] [client 140.238.42.111:64642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaagpXMN3p_zkwXf3DlgAAAMw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:54.226907 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.154.219.37:58576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/logs/.env"] [unique_id "aqxaagpXMN3p_zkwXf3DmAAAALU"]
[Thu Sep 17 15:23:54.449712 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:64954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaagpXMN3p_zkwXf3DnAAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:54.603574 2026] [core:crit] [pid 1012520:tid 1012675] (13)Permission denied: [client 176.20.194.246:12628] AH00529: /home1/awesone8/public_html/comicsutra.com/cs/tv2000/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/awesone8/public_html/comicsutra.com/cs/tv2000/' is executable
[Thu Sep 17 15:23:54.614526 2026] [security2:error] [pid 1012520:tid 1012655] [client 52.167.144.67:49936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seekingtheway.net"] [uri "/index.php"] [unique_id "aqxaagpXMN3p_zkwXf3DmwAAiWk"]
[Thu Sep 17 15:23:54.698913 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/cache/.env"] [unique_id "aqxaagpXMN3p_zkwXf3DowAAAQQ"]
[Thu Sep 17 15:23:54.854218 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mailer/.env"] [unique_id "aqxaagpXMN3p_zkwXf3DpgAAAI0"]
[Thu Sep 17 15:23:54.867857 2026] [security2:error] [pid 1012520:tid 1012763] [client 140.238.42.111:65288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaagpXMN3p_zkwXf3DpwAAAPU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:55.011616 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mail/.env"] [unique_id "aqxaawpXMN3p_zkwXf3DrgAAAQA"]
[Thu Sep 17 15:23:55.082486 2026] [security2:error] [pid 1012520:tid 1012746] [client 74.71.102.114:52875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaagpXMN3p_zkwXf3DrQAA5DQ"]
[Thu Sep 17 15:23:55.175523 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/email/.env"] [unique_id "aqxaawpXMN3p_zkwXf3DtQAAANI"]
[Thu Sep 17 15:23:55.258542 2026] [security2:error] [pid 1012520:tid 1012682] [client 140.238.42.111:49226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaawpXMN3p_zkwXf3DtwAAAKQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:55.338419 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/smtp/.env"] [unique_id "aqxaawpXMN3p_zkwXf3DuwAAALg"]
[Thu Sep 17 15:23:55.501466 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mailing/.env"] [unique_id "aqxaawpXMN3p_zkwXf3DvgAAAJA"]
[Thu Sep 17 15:23:55.638895 2026] [security2:error] [pid 1012520:tid 1012720] [client 140.238.42.111:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaawpXMN3p_zkwXf3DwwAAAMo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:55.656347 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/notifications/.env"] [unique_id "aqxaawpXMN3p_zkwXf3DxAAAAJU"]
[Thu Sep 17 15:23:55.810751 2026] [security2:error] [pid 1012520:tid 1012733] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/notify/.env"] [unique_id "aqxaawpXMN3p_zkwXf3DyAAAANc"]
[Thu Sep 17 15:23:55.966819 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/sender/.env"] [unique_id "aqxaawpXMN3p_zkwXf3DyQAAANU"]
[Thu Sep 17 15:23:56.047748 2026] [security2:error] [pid 1012520:tid 1012757] [client 140.238.42.111:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxabApXMN3p_zkwXf3DzQAAAO8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:56.124286 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/campaign/.env"] [unique_id "aqxabApXMN3p_zkwXf3D0AAAAJM"]
[Thu Sep 17 15:23:56.282359 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/newsletter/.env"] [unique_id "aqxabApXMN3p_zkwXf3D0QAAAP0"]
[Thu Sep 17 15:23:56.426096 2026] [security2:error] [pid 1012520:tid 1012663] [client 74.71.102.114:52878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxabApXMN3p_zkwXf3D0gAAkUA"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726085941&hideanons=1&hideminor=1&limit=100&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:23:56.436927 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/ses/.env"] [unique_id "aqxabApXMN3p_zkwXf3D0wAAAIc"]
[Thu Sep 17 15:23:56.445262 2026] [security2:error] [pid 1012520:tid 1012719] [client 140.238.42.111:50173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxabApXMN3p_zkwXf3D1AAAAMk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:56.590635 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/sendgrid/.env"] [unique_id "aqxabApXMN3p_zkwXf3D2AAAAOs"]
[Thu Sep 17 15:23:56.744871 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/sparkpost/.env"] [unique_id "aqxabApXMN3p_zkwXf3D2QAAAIk"]
[Thu Sep 17 15:23:56.757679 2026] [security2:error] [pid 1012520:tid 1012769] [client 154.190.208.131:42399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxabApXMN3p_zkwXf3D2gAAAPs"]
[Thu Sep 17 15:23:56.757789 2026] [security2:error] [pid 1012520:tid 1012769] [client 154.190.208.131:42399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxabApXMN3p_zkwXf3D2gAAAPs"]
[Thu Sep 17 15:23:56.848053 2026] [security2:error] [pid 1012520:tid 1012675] [client 140.238.42.111:50502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxabApXMN3p_zkwXf3D3AAAAJ0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:56.909633 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/postmark/.env"] [unique_id "aqxabApXMN3p_zkwXf3D3QAAAM0"]
[Thu Sep 17 15:23:57.072454 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mailgun/.env"] [unique_id "aqxabQpXMN3p_zkwXf3D4wAAAKU"]
[Thu Sep 17 15:23:57.228453 2026] [security2:error] [pid 1012520:tid 1012748] [client 140.238.42.111:50805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxabQpXMN3p_zkwXf3D5gAAAOY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:57.232525 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mandrill/.env"] [unique_id "aqxabQpXMN3p_zkwXf3D5wAAAJI"]
[Thu Sep 17 15:23:57.392426 2026] [security2:error] [pid 1012520:tid 1012670] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mailjet/.env"] [unique_id "aqxabQpXMN3p_zkwXf3D6wAAAJg"]
[Thu Sep 17 15:23:57.553350 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/brevo/.env"] [unique_id "aqxabQpXMN3p_zkwXf3D7wAAAJc"]
[Thu Sep 17 15:23:57.614896 2026] [security2:error] [pid 1012520:tid 1012691] [client 140.238.42.111:51108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxabQpXMN3p_zkwXf3D8QAAAK0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:57.712429 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/transactional/.env"] [unique_id "aqxabQpXMN3p_zkwXf3D8wAAANg"]
[Thu Sep 17 15:23:57.857280 2026] [security2:error] [pid 1012520:tid 1012671] [client 186.105.232.15:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxabQpXMN3p_zkwXf3D9gAAAJk"]
[Thu Sep 17 15:23:57.857380 2026] [security2:error] [pid 1012520:tid 1012671] [client 186.105.232.15:58903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxabQpXMN3p_zkwXf3D9gAAAJk"]
[Thu Sep 17 15:23:57.874236 2026] [security2:error] [pid 1012520:tid 1012736] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/bulk/.env"] [unique_id "aqxabQpXMN3p_zkwXf3D9wAAANo"]
[Thu Sep 17 15:23:57.979135 2026] [security2:error] [pid 1012520:tid 1012695] [client 66.248.203.10:19650] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxabApXMN3p_zkwXf3DzwAAALE"], referer: http://bluetech.com/?rnd=1789680235718
[Thu Sep 17 15:23:58.006867 2026] [security2:error] [pid 1012520:tid 1012764] [client 140.238.42.111:51407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxabgpXMN3p_zkwXf3D-gAAAPY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:58.034544 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/aws/.env"] [unique_id "aqxabgpXMN3p_zkwXf3D_AAAAIs"]
[Thu Sep 17 15:23:58.193629 2026] [security2:error] [pid 1012520:tid 1012742] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/azure/.env"] [unique_id "aqxabgpXMN3p_zkwXf3EAQAAAOA"]
[Thu Sep 17 15:23:58.354822 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/gcp/.env"] [unique_id "aqxabgpXMN3p_zkwXf3EBAAAAK8"]
[Thu Sep 17 15:23:58.388331 2026] [security2:error] [pid 1012520:tid 1012733] [client 140.238.42.111:51698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxabgpXMN3p_zkwXf3EBgAAANc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:58.513949 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/cloud/.env"] [unique_id "aqxabgpXMN3p_zkwXf3ECwAAAJM"]
[Thu Sep 17 15:23:58.669042 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/infrastructure/.env"] [unique_id "aqxabgpXMN3p_zkwXf3EDwAAAK4"]
[Thu Sep 17 15:23:58.779354 2026] [security2:error] [pid 1012520:tid 1012715] [client 140.238.42.111:51996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxabgpXMN3p_zkwXf3EEAAAAMU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:58.831047 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/docker/.env"] [unique_id "aqxabgpXMN3p_zkwXf3EEQAAALU"]
[Thu Sep 17 15:23:58.991284 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/k8s/.env"] [unique_id "aqxabgpXMN3p_zkwXf3EEwAAALc"]
[Thu Sep 17 15:23:59.145059 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/kubernetes/.env"] [unique_id "aqxabwpXMN3p_zkwXf3EGAAAAO4"]
[Thu Sep 17 15:23:59.168842 2026] [security2:error] [pid 1012520:tid 1012663] [client 140.238.42.111:52324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxabwpXMN3p_zkwXf3EGQAAAJE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:59.302489 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/terraform/.env"] [unique_id "aqxabwpXMN3p_zkwXf3EGgAAAQQ"]
[Thu Sep 17 15:23:59.466617 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/ansible/.env"] [unique_id "aqxabwpXMN3p_zkwXf3EGwAAAM0"]
[Thu Sep 17 15:23:59.480075 2026] [security2:error] [pid 1012520:tid 1012687] [client 104.243.33.53:50773] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alexandernovelist.com"] [uri "/.env"] [unique_id "aqxabwpXMN3p_zkwXf3EHAAAAKk"]
[Thu Sep 17 15:23:59.515813 2026] [security2:error] [pid 1012520:tid 1012707] [client 114.198.138.124:63139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxabwpXMN3p_zkwXf3EHwAAAL0"]
[Thu Sep 17 15:23:59.515901 2026] [security2:error] [pid 1012520:tid 1012707] [client 114.198.138.124:63139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxabwpXMN3p_zkwXf3EHwAAAL0"]
[Thu Sep 17 15:23:59.563247 2026] [security2:error] [pid 1012520:tid 1012729] [client 140.238.42.111:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxabwpXMN3p_zkwXf3EIAAAANM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:59.629179 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/.git/.env"] [unique_id "aqxabwpXMN3p_zkwXf3EIgAAANE"]
[Thu Sep 17 15:23:59.796591 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/ci/.env"] [unique_id "aqxabwpXMN3p_zkwXf3EJgAAAOk"]
[Thu Sep 17 15:23:59.953490 2026] [security2:error] [pid 1012520:tid 1012678] [client 140.238.42.111:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxabwpXMN3p_zkwXf3EKgAAAKA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:23:59.956071 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/cd/.env"] [unique_id "aqxabwpXMN3p_zkwXf3EKwAAAQA"]
[Thu Sep 17 15:23:59.957573 2026] [access_compat:error] [pid 1012520:tid 1012676] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/ancient-jewels-the-mayan-legacy
[Thu Sep 17 15:24:00.115788 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/jenkins/.env"] [unique_id "aqxacApXMN3p_zkwXf3EMAAAAIY"]
[Thu Sep 17 15:24:00.279738 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/gitlab/.env"] [unique_id "aqxacApXMN3p_zkwXf3ENgAAAOw"]
[Thu Sep 17 15:24:00.343156 2026] [security2:error] [pid 1012520:tid 1012739] [client 140.238.42.111:53235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxacApXMN3p_zkwXf3ENwAAAN0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:00.434422 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/github/.env"] [unique_id "aqxacApXMN3p_zkwXf3EOQAAALE"]
[Thu Sep 17 15:24:00.533215 2026] [security2:error] [pid 1012520:tid 1012730] [client 156.192.234.52:58801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxacApXMN3p_zkwXf3EPQAAANQ"]
[Thu Sep 17 15:24:00.534666 2026] [security2:error] [pid 1012520:tid 1012730] [client 156.192.234.52:58801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxacApXMN3p_zkwXf3EPQAAANQ"]
[Thu Sep 17 15:24:00.602070 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/actions/.env"] [unique_id "aqxacApXMN3p_zkwXf3EPwAAAJU"]
[Thu Sep 17 15:24:00.740511 2026] [security2:error] [pid 1012520:tid 1012704] [client 103.61.184.148:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxacApXMN3p_zkwXf3EQwAAALo"]
[Thu Sep 17 15:24:00.740525 2026] [security2:error] [pid 1012520:tid 1012743] [client 140.238.42.111:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxacApXMN3p_zkwXf3EQgAAAOE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:00.740595 2026] [security2:error] [pid 1012520:tid 1012704] [client 103.61.184.148:55085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxacApXMN3p_zkwXf3EQwAAALo"]
[Thu Sep 17 15:24:00.757318 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/circleci/.env"] [unique_id "aqxacApXMN3p_zkwXf3ERAAAAK8"]
[Thu Sep 17 15:24:00.911359 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/travis/.env"] [unique_id "aqxacApXMN3p_zkwXf3ESQAAAKo"]
[Thu Sep 17 15:24:00.917181 2026] [security2:error] [pid 1012520:tid 1012758] [client 185.55.149.49:50522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxacApXMN3p_zkwXf3ESgAAAPA"]
[Thu Sep 17 15:24:00.917264 2026] [security2:error] [pid 1012520:tid 1012758] [client 185.55.149.49:50522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxacApXMN3p_zkwXf3ESgAAAPA"]
[Thu Sep 17 15:24:01.064865 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/buildkite/.env"] [unique_id "aqxacQpXMN3p_zkwXf3ETQAAAP0"]
[Thu Sep 17 15:24:01.083009 2026] [security2:error] [pid 1012520:tid 1012722] [client 169.58.197.253:65103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxacQpXMN3p_zkwXf3ETwAAAMw"], referer: binance.com
[Thu Sep 17 15:24:01.120207 2026] [security2:error] [pid 1012520:tid 1012692] [client 140.238.42.111:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxacQpXMN3p_zkwXf3EUAAAAK4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:01.219260 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mysql/.env"] [unique_id "aqxacQpXMN3p_zkwXf3EVAAAAMU"]
[Thu Sep 17 15:24:01.375339 2026] [security2:error] [pid 1012520:tid 1012756] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/postgres/.env"] [unique_id "aqxacQpXMN3p_zkwXf3EVQAAAO4"]
[Thu Sep 17 15:24:01.500921 2026] [security2:error] [pid 1012520:tid 1012663] [client 140.238.42.111:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxacQpXMN3p_zkwXf3EWQAAAJE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:01.532967 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/mongodb/.env"] [unique_id "aqxacQpXMN3p_zkwXf3EWgAAAQQ"]
[Thu Sep 17 15:24:01.540060 2026] [security2:error] [pid 1012520:tid 1012689] [client 187.183.52.29:4820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxacQpXMN3p_zkwXf3EVgAAAKs"]
[Thu Sep 17 15:24:01.687706 2026] [security2:error] [pid 1012520:tid 1012707] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/redis/.env"] [unique_id "aqxacQpXMN3p_zkwXf3EYAAAAL0"]
[Thu Sep 17 15:24:01.841531 2026] [security2:error] [pid 1012520:tid 1012656] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/elasticsearch/.env"] [unique_id "aqxacQpXMN3p_zkwXf3EYQAAAIo"]
[Thu Sep 17 15:24:01.878206 2026] [security2:error] [pid 1012520:tid 1012729] [client 140.238.42.111:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxacQpXMN3p_zkwXf3EYgAAANM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:01.996060 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/rabbitmq/.env"] [unique_id "aqxacQpXMN3p_zkwXf3EZAAAANw"]
[Thu Sep 17 15:24:02.165755 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/kafka/.env"] [unique_id "aqxacgpXMN3p_zkwXf3EaAAAAOY"]
[Thu Sep 17 15:24:02.257586 2026] [security2:error] [pid 1012520:tid 1012774] [client 140.238.42.111:54635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxacgpXMN3p_zkwXf3EaQAAAQA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:02.319026 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/queue/.env"] [unique_id "aqxacgpXMN3p_zkwXf3EbQAAAOQ"]
[Thu Sep 17 15:24:02.478521 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/worker/.env"] [unique_id "aqxacgpXMN3p_zkwXf3EcgAAAIw"]
[Thu Sep 17 15:24:02.493052 2026] [security2:error] [pid 1012520:tid 1012533] [remote 45.157.54.43:30658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abelardinc.com"] [uri "/xmlrpc.php"] [unique_id "aqxacgpXMN3p_zkwXf3EcQAArAs"]
[Thu Sep 17 15:24:02.493228 2026] [security2:error] [pid 1012520:tid 1012690] [client 45.157.54.43:30658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abelardinc.com"] [uri "/xmlrpc.php"] [unique_id "aqxacgpXMN3p_zkwXf3EcQAArAs"]
[Thu Sep 17 15:24:02.613515 2026] [security2:error] [pid 1012520:tid 1012645] [remote 220.181.108.155:28448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtbclubdecampo.com"] [uri "/estadisticas.php"] [unique_id "aqxacgpXMN3p_zkwXf3EcwAA4ns"]
[Thu Sep 17 15:24:02.632655 2026] [security2:error] [pid 1012520:tid 1012768] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/job/.env"] [unique_id "aqxacgpXMN3p_zkwXf3EdwAAAPo"]
[Thu Sep 17 15:24:02.638867 2026] [security2:error] [pid 1012520:tid 1012664] [client 140.238.42.111:54878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxacgpXMN3p_zkwXf3EeAAAAJI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:02.786757 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/test/.env"] [unique_id "aqxacgpXMN3p_zkwXf3EewAAAJc"]
[Thu Sep 17 15:24:02.941752 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/qa/.env"] [unique_id "aqxacgpXMN3p_zkwXf3EfgAAANQ"]
[Thu Sep 17 15:24:03.027848 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:55175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxacwpXMN3p_zkwXf3EgAAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:03.096787 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/preview/.env"] [unique_id "aqxacwpXMN3p_zkwXf3EhQAAAJY"]
[Thu Sep 17 15:24:03.250831 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/beta/.env"] [unique_id "aqxacwpXMN3p_zkwXf3EiAAAAQE"]
[Thu Sep 17 15:24:03.282730 2026] [security2:error] [pid 1012520:tid 1012765] [client 74.7.230.39:54782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "uxl.ote.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxacwpXMN3p_zkwXf3EiwAA9wE"]
[Thu Sep 17 15:24:03.311936 2026] [security2:error] [pid 1012520:tid 1012539] [remote 45.157.54.43:31741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abelardinc.com"] [uri "/xmlrpc.php"] [unique_id "aqxacwpXMN3p_zkwXf3EjAAAoRE"]
[Thu Sep 17 15:24:03.312083 2026] [security2:error] [pid 1012520:tid 1012679] [client 45.157.54.43:31741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abelardinc.com"] [uri "/xmlrpc.php"] [unique_id "aqxacwpXMN3p_zkwXf3EjAAAoRE"]
[Thu Sep 17 15:24:03.404688 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/uat/.env"] [unique_id "aqxacwpXMN3p_zkwXf3EjgAAAI4"]
[Thu Sep 17 15:24:03.419979 2026] [security2:error] [pid 1012520:tid 1012710] [client 16.216.88.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxacwpXMN3p_zkwXf3EigAAAMA"]
[Thu Sep 17 15:24:03.430281 2026] [security2:error] [pid 1012520:tid 1012722] [client 140.238.42.111:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxacwpXMN3p_zkwXf3EjwAAAMw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:03.566568 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/stage/.env"] [unique_id "aqxacwpXMN3p_zkwXf3ElQAAALs"]
[Thu Sep 17 15:24:03.721186 2026] [security2:error] [pid 1012520:tid 1012727] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/development/.env"] [unique_id "aqxacwpXMN3p_zkwXf3EmQAAANE"]
[Thu Sep 17 15:24:03.799965 2026] [security2:error] [pid 1012520:tid 1012580] [remote 110.249.201.221:57856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acc.edu.ai"] [uri "/academics/division-of-technology/"] [unique_id "aqxacwpXMN3p_zkwXf3EmgAAijo"]
[Thu Sep 17 15:24:03.826210 2026] [security2:error] [pid 1012520:tid 1012726] [client 140.238.42.111:55764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxacwpXMN3p_zkwXf3EmwAAANA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:03.880046 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/production/.env"] [unique_id "aqxacwpXMN3p_zkwXf3EnAAAANM"]
[Thu Sep 17 15:24:04.035984 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.154.219.37:57120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.embracingthehour.com"] [uri "/config/app/.env"] [unique_id "aqxadApXMN3p_zkwXf3EnwAAAJ4"]
[Thu Sep 17 15:24:04.203723 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.154.219.37:57120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/phpinfo.php"] [unique_id "aqxadApXMN3p_zkwXf3EoQAAAPk"]
[Thu Sep 17 15:24:04.211913 2026] [security2:error] [pid 1012520:tid 1012678] [client 140.238.42.111:56085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxadApXMN3p_zkwXf3EowAAAKA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:04.616793 2026] [security2:error] [pid 1012520:tid 1012728] [client 140.238.42.111:56392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxadApXMN3p_zkwXf3EqQAAANI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:04.683856 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.154.219.37:41380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/info.php"] [unique_id "aqxadApXMN3p_zkwXf3EqwAAAME"]
[Thu Sep 17 15:24:05.005851 2026] [security2:error] [pid 1012520:tid 1012734] [client 140.238.42.111:56727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxadQpXMN3p_zkwXf3ErgAAANg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:05.133036 2026] [security2:error] [pid 1012520:tid 1012721] [client 24.45.219.199:50075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.enduringwanderlust.com"] [uri "/wp-login.php"] [unique_id "aqxadApXMN3p_zkwXf3EogAAy18"], referer: https://www.enduringwanderlust.com/wp-login.php?redirect_to=https%3A%2F%2Fwww.enduringwanderlust.com%2Fwp-admin%2F&reauth=1
[Thu Sep 17 15:24:05.164389 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.154.219.37:41396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/php.php"] [unique_id "aqxadQpXMN3p_zkwXf3EtgAAALE"]
[Thu Sep 17 15:24:05.209223 2026] [security2:error] [pid 1012520:tid 1012668] [client 181.118.234.54:56987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxadQpXMN3p_zkwXf3EtAAAlg8"]
[Thu Sep 17 15:24:05.396456 2026] [security2:error] [pid 1012520:tid 1012709] [client 140.238.42.111:57069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxadQpXMN3p_zkwXf3EvAAAAL8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:05.475422 2026] [security2:error] [pid 1012520:tid 1012761] [client 66.93.5.46:55408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mavenme.com"] [uri "/"] [unique_id "aqxadQpXMN3p_zkwXf3EvgAAAPM"]
[Thu Sep 17 15:24:05.637215 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.219.37:41406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/i.php"] [unique_id "aqxadQpXMN3p_zkwXf3EyAAAAJM"]
[Thu Sep 17 15:24:05.679226 2026] [security2:error] [pid 1012520:tid 1012692] [client 43.173.182.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxadQpXMN3p_zkwXf3ExAAAAK4"]
[Thu Sep 17 15:24:05.781356 2026] [security2:error] [pid 1012520:tid 1012715] [client 43.173.175.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxadQpXMN3p_zkwXf3EyQAAAMU"]
[Thu Sep 17 15:24:05.803126 2026] [security2:error] [pid 1012520:tid 1012660] [client 140.238.42.111:57399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxadQpXMN3p_zkwXf3EywAAAI4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:06.118606 2026] [security2:error] [pid 1012520:tid 1012776] [client 34.154.219.37:41410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/pi.php"] [unique_id "aqxadgpXMN3p_zkwXf3E1QAAAQI"]
[Thu Sep 17 15:24:06.180395 2026] [security2:error] [pid 1012520:tid 1012723] [client 140.238.42.111:57723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxadgpXMN3p_zkwXf3E1wAAAM0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:06.573903 2026] [security2:error] [pid 1012520:tid 1012675] [client 140.238.42.111:58007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxadgpXMN3p_zkwXf3E7wAAAJ0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:06.605951 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.154.219.37:41420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/pinfo.php"] [unique_id "aqxadgpXMN3p_zkwXf3E8gAAAMQ"]
[Thu Sep 17 15:24:06.953286 2026] [security2:error] [pid 1012520:tid 1012742] [client 140.238.42.111:58354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxadgpXMN3p_zkwXf3E_QAAAOA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:07.085042 2026] [security2:error] [pid 1012520:tid 1012713] [client 34.154.219.37:41432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/test.php"] [unique_id "aqxadwpXMN3p_zkwXf3FAQAAAMM"]
[Thu Sep 17 15:24:07.348890 2026] [security2:error] [pid 1012520:tid 1012756] [client 140.238.42.111:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxadwpXMN3p_zkwXf3FAwAAAO4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:07.738450 2026] [security2:error] [pid 1012520:tid 1012701] [client 140.238.42.111:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxadwpXMN3p_zkwXf3FCwAAALc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:07.797582 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.154.219.37:41444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/p.php"] [unique_id "aqxadwpXMN3p_zkwXf3FDQAAANM"]
[Thu Sep 17 15:24:08.119589 2026] [security2:error] [pid 1012520:tid 1012684] [client 140.238.42.111:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaeApXMN3p_zkwXf3FFwAAAKY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:08.270312 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.154.219.37:41448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/debug.php"] [unique_id "aqxaeApXMN3p_zkwXf3FGAAAAMQ"]
[Thu Sep 17 15:24:08.315927 2026] [security2:error] [pid 1012520:tid 1012767] [client 154.190.208.131:41664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaeApXMN3p_zkwXf3FGQAAAPk"]
[Thu Sep 17 15:24:08.318860 2026] [security2:error] [pid 1012520:tid 1012767] [client 154.190.208.131:41664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaeApXMN3p_zkwXf3FGQAAAPk"]
[Thu Sep 17 15:24:08.511132 2026] [security2:error] [pid 1012520:tid 1012712] [client 140.238.42.111:59617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaeApXMN3p_zkwXf3FGwAAAMI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:08.747856 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.154.219.37:41454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxaeApXMN3p_zkwXf3FJAAAAOY"]
[Thu Sep 17 15:24:08.811769 2026] [security2:error] [pid 1012520:tid 1012770] [client 5.102.169.29:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/roofing.php"] [unique_id "aqxaeApXMN3p_zkwXf3FLwAAAPw"]
[Thu Sep 17 15:24:08.815966 2026] [security2:error] [pid 1012520:tid 1012764] [client 5.102.169.29:32994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/contact.php"] [unique_id "aqxaeApXMN3p_zkwXf3FJgAAAPY"]
[Thu Sep 17 15:24:08.818723 2026] [security2:error] [pid 1012520:tid 1012736] [client 5.102.169.29:44314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/faqs.php"] [unique_id "aqxaeApXMN3p_zkwXf3FLQAAANo"]
[Thu Sep 17 15:24:08.819134 2026] [security2:error] [pid 1012520:tid 1012726] [client 5.102.169.29:33004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/index.php"] [unique_id "aqxaeApXMN3p_zkwXf3FKQAAANA"]
[Thu Sep 17 15:24:08.819729 2026] [security2:error] [pid 1012520:tid 1012755] [client 5.102.169.29:44290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/sidinggutters.php"] [unique_id "aqxaeApXMN3p_zkwXf3FKgAAAO0"]
[Thu Sep 17 15:24:08.820491 2026] [security2:error] [pid 1012520:tid 1012703] [client 5.102.169.29:44276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/financing.php"] [unique_id "aqxaeApXMN3p_zkwXf3FLAAAALk"]
[Thu Sep 17 15:24:08.821156 2026] [security2:error] [pid 1012520:tid 1012654] [client 5.102.169.29:44304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/windows.php"] [unique_id "aqxaeApXMN3p_zkwXf3FKwAAAIg"]
[Thu Sep 17 15:24:08.821199 2026] [security2:error] [pid 1012520:tid 1012682] [client 5.102.169.29:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/testimonials.php"] [unique_id "aqxaeApXMN3p_zkwXf3FMQAAAKQ"]
[Thu Sep 17 15:24:08.821588 2026] [security2:error] [pid 1012520:tid 1012688] [client 5.102.169.29:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.169.102.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicagolandexteriorsinc.com"] [uri "/claims.php"] [unique_id "aqxaeApXMN3p_zkwXf3FLgAAAKo"]
[Thu Sep 17 15:24:08.861968 2026] [security2:error] [pid 1012520:tid 1012742] [client 169.58.197.253:49223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-icon-collections-registry.php"] [unique_id "aqxaeApXMN3p_zkwXf3FMgAAAOA"], referer: binance.com
[Thu Sep 17 15:24:08.898454 2026] [security2:error] [pid 1012520:tid 1012695] [client 140.238.42.111:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaeApXMN3p_zkwXf3FMwAAALE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:09.215886 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.154.219.37:41470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/test/phpinfo.php"] [unique_id "aqxaeQpXMN3p_zkwXf3FRgAAAO8"]
[Thu Sep 17 15:24:09.289078 2026] [security2:error] [pid 1012520:tid 1012687] [client 140.238.42.111:60272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaeQpXMN3p_zkwXf3FSgAAAKk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:09.673804 2026] [security2:error] [pid 1012520:tid 1012691] [client 140.238.42.111:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaeQpXMN3p_zkwXf3FVwAAAK0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:09.687321 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.154.219.37:41472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxaeQpXMN3p_zkwXf3FWQAAAKg"]
[Thu Sep 17 15:24:09.778168 2026] [autoindex:error] [pid 1012520:tid 1012704] [client 152.32.158.219:40990] AH01276: Cannot serve directory /home1/zxhxwymy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:24:10.063029 2026] [security2:error] [pid 1012520:tid 1012685] [client 140.238.42.111:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaegpXMN3p_zkwXf3FXQAAAKc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:10.095046 2026] [security2:error] [pid 1012520:tid 1012700] [client 114.198.138.124:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaegpXMN3p_zkwXf3FXgAAALY"]
[Thu Sep 17 15:24:10.095150 2026] [security2:error] [pid 1012520:tid 1012700] [client 114.198.138.124:63770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaegpXMN3p_zkwXf3FXgAAALY"]
[Thu Sep 17 15:24:10.161356 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.154.219.37:41478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/old/phpinfo.php"] [unique_id "aqxaegpXMN3p_zkwXf3FYAAAAN4"]
[Thu Sep 17 15:24:10.242775 2026] [security2:error] [pid 1012520:tid 1012721] [client 162.241.226.11:10872] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxaegpXMN3p_zkwXf3FYQAAAMs"]
[Thu Sep 17 15:24:10.401285 2026] [security2:error] [pid 1012520:tid 1012772] [client 186.105.232.15:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaegpXMN3p_zkwXf3FYwAAAP4"]
[Thu Sep 17 15:24:10.402523 2026] [security2:error] [pid 1012520:tid 1012772] [client 186.105.232.15:59514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaegpXMN3p_zkwXf3FYwAAAP4"]
[Thu Sep 17 15:24:10.455648 2026] [security2:error] [pid 1012520:tid 1012747] [client 140.238.42.111:61254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaegpXMN3p_zkwXf3FZAAAAOU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:10.495303 2026] [security2:error] [pid 1012520:tid 1012748] [client 169.224.11.54:55336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaegpXMN3p_zkwXf3FYgAA5k8"]
[Thu Sep 17 15:24:10.636604 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.154.219.37:41482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaegpXMN3p_zkwXf3FawAAAK8"]
[Thu Sep 17 15:24:10.855148 2026] [security2:error] [pid 1012520:tid 1012665] [client 192.178.6.3:42250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxaegpXMN3p_zkwXf3FbwAAAJM"]
[Thu Sep 17 15:24:10.859395 2026] [security2:error] [pid 1012520:tid 1012652] [client 140.238.42.111:61543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaegpXMN3p_zkwXf3FcAAAAIY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:11.103127 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.154.219.37:41490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/public/phpinfo.php"] [unique_id "aqxaewpXMN3p_zkwXf3FdQAAAMo"]
[Thu Sep 17 15:24:11.154036 2026] [security2:error] [pid 1012520:tid 1012759] [client 156.192.234.52:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaewpXMN3p_zkwXf3FdgAAAPE"]
[Thu Sep 17 15:24:11.156165 2026] [security2:error] [pid 1012520:tid 1012759] [client 156.192.234.52:59576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaewpXMN3p_zkwXf3FdgAAAPE"]
[Thu Sep 17 15:24:11.265536 2026] [security2:error] [pid 1012520:tid 1012722] [client 140.238.42.111:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaewpXMN3p_zkwXf3FdwAAAMw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:11.471159 2026] [security2:error] [pid 1012520:tid 1012716] [client 165.154.29.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lumenroast.com"] [uri "/index.php"] [unique_id "aqxaegpXMN3p_zkwXf3FbgAAAMY"], referer: https://mail.avo.jgb.mybluehost.me/favicon.ico
[Thu Sep 17 15:24:11.595538 2026] [security2:error] [pid 1012520:tid 1012664] [client 185.55.149.49:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaewpXMN3p_zkwXf3FgQAAAJI"]
[Thu Sep 17 15:24:11.595674 2026] [security2:error] [pid 1012520:tid 1012664] [client 185.55.149.49:51151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaewpXMN3p_zkwXf3FgQAAAJI"]
[Thu Sep 17 15:24:11.652943 2026] [security2:error] [pid 1012520:tid 1012731] [client 140.238.42.111:62237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaewpXMN3p_zkwXf3FhwAAANU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:11.815710 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.154.219.37:41506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/php-info.php"] [unique_id "aqxaewpXMN3p_zkwXf3FigAAAQA"]
[Thu Sep 17 15:24:12.042640 2026] [security2:error] [pid 1012520:tid 1012717] [client 140.238.42.111:62580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxafApXMN3p_zkwXf3FjQAAAMc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:12.333266 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.154.219.37:41518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/phpversion.php"] [unique_id "aqxafApXMN3p_zkwXf3FlQAAAKc"]
[Thu Sep 17 15:24:12.450579 2026] [security2:error] [pid 1012520:tid 1012718] [client 140.238.42.111:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxafApXMN3p_zkwXf3FmAAAAMg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:12.800322 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.154.219.37:41534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/_phpinfo.php"] [unique_id "aqxafApXMN3p_zkwXf3FngAAAPU"]
[Thu Sep 17 15:24:12.839974 2026] [security2:error] [pid 1012520:tid 1012772] [client 140.238.42.111:63239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxafApXMN3p_zkwXf3FnwAAAP4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:13.254387 2026] [security2:error] [pid 1012520:tid 1012771] [client 140.238.42.111:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxafQpXMN3p_zkwXf3FrAAAAP0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:13.269605 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.154.219.37:41542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/old_phpinfo.php"] [unique_id "aqxafQpXMN3p_zkwXf3FrQAAAPc"]
[Thu Sep 17 15:24:13.656027 2026] [security2:error] [pid 1012520:tid 1012756] [client 140.238.42.111:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxafQpXMN3p_zkwXf3FsgAAAO4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:13.767266 2026] [security2:error] [pid 1012520:tid 1012653] [client 34.154.219.37:41552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/server-info.php"] [unique_id "aqxafQpXMN3p_zkwXf3FtwAAAIc"]
[Thu Sep 17 15:24:13.973645 2026] [security2:error] [pid 1012520:tid 1012733] [client 74.7.175.153:35682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxafQpXMN3p_zkwXf3FuQAA1w4"]
[Thu Sep 17 15:24:14.044314 2026] [security2:error] [pid 1012520:tid 1012724] [client 140.238.42.111:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxafgpXMN3p_zkwXf3FvgAAAM4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:14.259633 2026] [security2:error] [pid 1012520:tid 1012686] [client 34.154.219.37:58240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/server-status.php"] [unique_id "aqxafgpXMN3p_zkwXf3FxAAAAKg"]
[Thu Sep 17 15:24:14.302430 2026] [security2:error] [pid 1012520:tid 1012664] [client 103.61.184.148:55799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxafgpXMN3p_zkwXf3FxgAAAJI"]
[Thu Sep 17 15:24:14.303622 2026] [security2:error] [pid 1012520:tid 1012664] [client 103.61.184.148:55799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxafgpXMN3p_zkwXf3FxgAAAJI"]
[Thu Sep 17 15:24:14.435816 2026] [security2:error] [pid 1012520:tid 1012700] [client 140.238.42.111:64519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxafgpXMN3p_zkwXf3FyAAAALY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:14.816877 2026] [security2:error] [pid 1012520:tid 1012727] [client 140.238.42.111:64815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxafgpXMN3p_zkwXf3FzwAAANE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:15.135813 2026] [security2:error] [pid 1012520:tid 1012688] [client 34.154.219.37:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxafwpXMN3p_zkwXf3F1gAAAKo"]
[Thu Sep 17 15:24:15.203718 2026] [security2:error] [pid 1012520:tid 1012755] [client 140.238.42.111:65114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxafwpXMN3p_zkwXf3F1wAAAO0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:15.592331 2026] [security2:error] [pid 1012520:tid 1012715] [client 140.238.42.111:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxafwpXMN3p_zkwXf3F3QAAAMU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:15.633340 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.154.219.37:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxafwpXMN3p_zkwXf3F3wAAAOg"]
[Thu Sep 17 15:24:15.972530 2026] [security2:error] [pid 1012520:tid 1012696] [client 140.238.42.111:49355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxafwpXMN3p_zkwXf3F4wAAALI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:16.138048 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.154.219.37:58268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxagApXMN3p_zkwXf3F5wAAAPs"]
[Thu Sep 17 15:24:16.354084 2026] [security2:error] [pid 1012520:tid 1012695] [client 140.238.42.111:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxagApXMN3p_zkwXf3F6QAAALE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:16.633267 2026] [security2:error] [pid 1012520:tid 1012778] [client 34.154.219.37:58280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxagApXMN3p_zkwXf3F7QAAAQQ"]
[Thu Sep 17 15:24:16.734539 2026] [security2:error] [pid 1012520:tid 1012729] [client 140.238.42.111:50000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxagApXMN3p_zkwXf3F7gAAANM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:17.130857 2026] [security2:error] [pid 1012520:tid 1012738] [client 140.238.42.111:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxagQpXMN3p_zkwXf3F9AAAANw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:17.159056 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.154.219.37:58284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxagQpXMN3p_zkwXf3F9QAAAOk"]
[Thu Sep 17 15:24:17.517570 2026] [security2:error] [pid 1012520:tid 1012678] [client 140.238.42.111:50654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxagQpXMN3p_zkwXf3F_gAAAKA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:17.623547 2026] [security2:error] [pid 1012520:tid 1012689] [client 73.51.188.161:36187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxagQpXMN3p_zkwXf3F_QAAq2Q"]
[Thu Sep 17 15:24:17.645394 2026] [security2:error] [pid 1012520:tid 1012664] [client 34.154.219.37:58298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxagQpXMN3p_zkwXf3GAgAAAJI"]
[Thu Sep 17 15:24:17.919010 2026] [security2:error] [pid 1012520:tid 1012732] [client 140.238.42.111:50993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxagQpXMN3p_zkwXf3GCQAAANY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:18.141717 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.154.219.37:58314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxaggpXMN3p_zkwXf3GDgAAAIs"]
[Thu Sep 17 15:24:18.304838 2026] [security2:error] [pid 1012520:tid 1012711] [client 140.238.42.111:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaggpXMN3p_zkwXf3GDwAAAME"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:18.674445 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.154.219.37:58330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/phpinfo.php.old"] [unique_id "aqxaggpXMN3p_zkwXf3GFQAAAPY"]
[Thu Sep 17 15:24:18.675706 2026] [security2:error] [pid 1012520:tid 1012662] [client 52.167.144.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxagQpXMN3p_zkwXf3F-AAAAJA"]
[Thu Sep 17 15:24:18.711289 2026] [security2:error] [pid 1012520:tid 1012703] [client 140.238.42.111:51659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaggpXMN3p_zkwXf3GFgAAALk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:18.836077 2026] [security2:error] [pid 1012520:tid 1012741] [client 154.190.208.131:42251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaggpXMN3p_zkwXf3GGAAAAN8"]
[Thu Sep 17 15:24:18.836182 2026] [security2:error] [pid 1012520:tid 1012741] [client 154.190.208.131:42251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaggpXMN3p_zkwXf3GGAAAAN8"]
[Thu Sep 17 15:24:19.028204 2026] [security2:error] [pid 1012520:tid 1012752] [client 24.45.219.199:50085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.enduringwanderlust.com"] [uri "/wp-admin/edit.php"] [unique_id "aqxaggpXMN3p_zkwXf3GGwAA6kk"], referer: https://www.enduringwanderlust.com/wp-admin/edit.php
[Thu Sep 17 15:24:19.094470 2026] [security2:error] [pid 1012520:tid 1012652] [client 140.238.42.111:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxagwpXMN3p_zkwXf3GIAAAAIY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:19.168924 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.154.219.37:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/phpinfo.php~"] [unique_id "aqxagwpXMN3p_zkwXf3GIgAAAMo"]
[Thu Sep 17 15:24:19.482760 2026] [security2:error] [pid 1012520:tid 1012726] [client 140.238.42.111:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxagwpXMN3p_zkwXf3GJwAAANA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:19.532926 2026] [security2:error] [pid 1012520:tid 1012681] [client 43.173.181.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxagwpXMN3p_zkwXf3GJgAAAKM"]
[Thu Sep 17 15:24:19.647384 2026] [security2:error] [pid 1012520:tid 1012716] [client 34.154.219.37:58348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/info.php.bak"] [unique_id "aqxagwpXMN3p_zkwXf3GKwAAAMY"]
[Thu Sep 17 15:24:19.867872 2026] [security2:error] [pid 1012520:tid 1012773] [client 140.238.42.111:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxagwpXMN3p_zkwXf3GLwAAAP8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:19.985384 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.166.217.178:49956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/"] [unique_id "aqxagwpXMN3p_zkwXf3GMAAAAOk"]
[Thu Sep 17 15:24:20.141591 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.154.219.37:58362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/phpinfo.php.save"] [unique_id "aqxahApXMN3p_zkwXf3GNQAAANw"]
[Thu Sep 17 15:24:20.166853 2026] [security2:error] [pid 1012520:tid 1012683] [client 169.58.197.253:49949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxahApXMN3p_zkwXf3GNwAAAKU"], referer: binance.com
[Thu Sep 17 15:24:20.280493 2026] [security2:error] [pid 1012520:tid 1012707] [client 140.238.42.111:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxahApXMN3p_zkwXf3GOAAAAL0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:20.635313 2026] [security2:error] [pid 1012520:tid 1012734] [client 34.154.219.37:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxahApXMN3p_zkwXf3GPwAAANg"]
[Thu Sep 17 15:24:20.684474 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.166.217.178:49962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/"] [unique_id "aqxahApXMN3p_zkwXf3GQgAAAKA"]
[Thu Sep 17 15:24:20.697084 2026] [security2:error] [pid 1012520:tid 1012712] [client 114.198.138.124:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxahApXMN3p_zkwXf3GQwAAAMI"]
[Thu Sep 17 15:24:20.697218 2026] [security2:error] [pid 1012520:tid 1012712] [client 114.198.138.124:64416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxahApXMN3p_zkwXf3GQwAAAMI"]
[Thu Sep 17 15:24:20.699391 2026] [security2:error] [pid 1012520:tid 1012664] [client 140.238.42.111:53423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxahApXMN3p_zkwXf3GRAAAAJI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:21.110434 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.154.219.37:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxahQpXMN3p_zkwXf3GSQAAAL4"]
[Thu Sep 17 15:24:21.111644 2026] [security2:error] [pid 1012520:tid 1012668] [client 140.238.42.111:53857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxahQpXMN3p_zkwXf3GSgAAAJY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:21.268407 2026] [security2:error] [pid 1012520:tid 1012706] [client 73.51.188.161:39061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxahQpXMN3p_zkwXf3GSwAAvHk"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726083039&hideanons=1&hideminor=1&limit=500&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:24:21.381940 2026] [security2:error] [pid 1012520:tid 1012763] [client 34.166.217.178:49964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/"] [unique_id "aqxahQpXMN3p_zkwXf3GTQAAAPU"]
[Thu Sep 17 15:24:21.512042 2026] [security2:error] [pid 1012520:tid 1012709] [client 140.238.42.111:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxahQpXMN3p_zkwXf3GTgAAAL8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:21.612980 2026] [security2:error] [pid 1012520:tid 1012660] [client 34.154.219.37:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxahQpXMN3p_zkwXf3GUQAAAI4"]
[Thu Sep 17 15:24:21.648820 2026] [security2:error] [pid 1012520:tid 1012688] [client 186.105.232.15:60115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxahQpXMN3p_zkwXf3GUwAAAKo"]
[Thu Sep 17 15:24:21.649941 2026] [security2:error] [pid 1012520:tid 1012688] [client 186.105.232.15:60115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxahQpXMN3p_zkwXf3GUwAAAKo"]
[Thu Sep 17 15:24:21.699092 2026] [security2:error] [pid 1012520:tid 1012755] [client 156.192.234.52:60214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxahQpXMN3p_zkwXf3GVwAAAO0"]
[Thu Sep 17 15:24:21.699193 2026] [security2:error] [pid 1012520:tid 1012755] [client 156.192.234.52:60214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxahQpXMN3p_zkwXf3GVwAAAO0"]
[Thu Sep 17 15:24:22.094478 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.154.219.37:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxahgpXMN3p_zkwXf3GXgAAAPk"]
[Thu Sep 17 15:24:22.164720 2026] [autoindex:error] [pid 1012520:tid 1012749] [client 82.223.49.247:33954] AH01276: Cannot serve directory /home1/ruiktkmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:24:22.315657 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.166.217.178:49968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/"] [unique_id "aqxahgpXMN3p_zkwXf3GZQAAAOM"]
[Thu Sep 17 15:24:22.409433 2026] [security2:error] [pid 1012520:tid 1012776] [client 185.55.149.49:50877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxahgpXMN3p_zkwXf3GZwAAAQI"]
[Thu Sep 17 15:24:22.409611 2026] [security2:error] [pid 1012520:tid 1012776] [client 185.55.149.49:50877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxahgpXMN3p_zkwXf3GZwAAAQI"]
[Thu Sep 17 15:24:22.603672 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.154.219.37:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxahgpXMN3p_zkwXf3GbQAAAJk"]
[Thu Sep 17 15:24:22.874266 2026] [security2:error] [pid 1012520:tid 1012670] [client 82.223.49.247:34012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rui.ktk.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxahgpXMN3p_zkwXf3GdQAAAJg"]
[Thu Sep 17 15:24:22.891170 2026] [security2:error] [pid 1012520:tid 1012754] [client 82.223.49.247:34042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.rui.ktk.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxahgpXMN3p_zkwXf3GeAAAAOw"]
[Thu Sep 17 15:24:22.938801 2026] [security2:error] [pid 1012520:tid 1012666] [client 82.223.49.247:33996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rui.ktk.mybluehost.me"] [uri "/.env"] [unique_id "aqxahgpXMN3p_zkwXf3GfAAAAJQ"]
[Thu Sep 17 15:24:22.962938 2026] [security2:error] [pid 1012520:tid 1012764] [client 82.223.49.247:33954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.rui.ktk.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxahgpXMN3p_zkwXf3GfgAAAPY"]
[Thu Sep 17 15:24:22.986339 2026] [security2:error] [pid 1012520:tid 1012705] [client 82.223.49.247:33998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.rui.ktk.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxahgpXMN3p_zkwXf3GfwAAALs"]
[Thu Sep 17 15:24:23.071306 2026] [security2:error] [pid 1012520:tid 1012669] [client 34.154.219.37:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/www/phpinfo.php"] [unique_id "aqxahwpXMN3p_zkwXf3GhAAAAJc"]
[Thu Sep 17 15:24:23.582506 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.154.219.37:58424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxahwpXMN3p_zkwXf3GjQAAAPw"]
[Thu Sep 17 15:24:24.059114 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.154.219.37:48800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxaiApXMN3p_zkwXf3GowAAAPE"]
[Thu Sep 17 15:24:24.526912 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.154.219.37:48830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/site/phpinfo.php"] [unique_id "aqxaiApXMN3p_zkwXf3GuQAAANM"]
[Thu Sep 17 15:24:24.998151 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.154.219.37:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxaiApXMN3p_zkwXf3GywAAAPA"]
[Thu Sep 17 15:24:25.001046 2026] [security2:error] [pid 1012520:tid 1012734] [client 24.45.219.199:50085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.enduringwanderlust.com"] [uri "/index.php"] [unique_id "aqxaiApXMN3p_zkwXf3GyAAA2F8"], referer: https://www.enduringwanderlust.com/wp-content/plugins/nextgen-gallery/static/IGW/Block/editor.css?ver=4.5.0
[Thu Sep 17 15:24:25.042879 2026] [security2:error] [pid 1012520:tid 1012671] [client 103.61.184.148:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaiQpXMN3p_zkwXf3GzAAAAJk"]
[Thu Sep 17 15:24:25.042997 2026] [security2:error] [pid 1012520:tid 1012671] [client 103.61.184.148:56361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaiQpXMN3p_zkwXf3GzAAAAJk"]
[Thu Sep 17 15:24:25.484509 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.154.219.37:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxaiQpXMN3p_zkwXf3G2gAAAMQ"]
[Thu Sep 17 15:24:25.979257 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.154.219.37:48866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxaiQpXMN3p_zkwXf3G5gAAAOg"]
[Thu Sep 17 15:24:26.480811 2026] [security2:error] [pid 1012520:tid 1012759] [client 34.154.219.37:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/core/phpinfo.php"] [unique_id "aqxaigpXMN3p_zkwXf3G9wAAAPE"]
[Thu Sep 17 15:24:26.960076 2026] [security2:error] [pid 1012520:tid 1012672] [client 34.154.219.37:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.embracingthehour.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxaigpXMN3p_zkwXf3HBAAAAJo"]
[Thu Sep 17 15:24:27.279704 2026] [security2:error] [pid 1012520:tid 1012686] [client 104.207.33.33:44795] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxaiwpXMN3p_zkwXf3HFQAAAKg"]
[Thu Sep 17 15:24:27.382506 2026] [security2:error] [pid 1012520:tid 1012748] [client 169.58.197.253:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxaiwpXMN3p_zkwXf3HFwAAAOY"], referer: binance.com
[Thu Sep 17 15:24:27.912521 2026] [security2:error] [pid 1012520:tid 1012730] [client 140.238.42.111:54588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaiwpXMN3p_zkwXf3HKgAAANQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:28.322302 2026] [security2:error] [pid 1012520:tid 1012728] [client 140.238.42.111:59899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxajApXMN3p_zkwXf3HPAAAANI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:28.705050 2026] [security2:error] [pid 1012520:tid 1012661] [client 140.238.42.111:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxajApXMN3p_zkwXf3HSQAAAI8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:28.934101 2026] [security2:error] [pid 1012520:tid 1012692] [client 4.240.114.86:54969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxajApXMN3p_zkwXf3HTQAAAK4"], referer: binance.com
[Thu Sep 17 15:24:29.083453 2026] [security2:error] [pid 1012520:tid 1012762] [client 24.35.114.80:51301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxajApXMN3p_zkwXf3HUQAA9Go"]
[Thu Sep 17 15:24:29.113444 2026] [security2:error] [pid 1012520:tid 1012756] [client 140.238.42.111:60569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HXAAAAO4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:29.362900 2026] [security2:error] [pid 1012520:tid 1012760] [client 154.190.208.131:41499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxajQpXMN3p_zkwXf3HZwAAAPI"]
[Thu Sep 17 15:24:29.363072 2026] [security2:error] [pid 1012520:tid 1012760] [client 154.190.208.131:41499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxajQpXMN3p_zkwXf3HZwAAAPI"]
[Thu Sep 17 15:24:29.515640 2026] [security2:error] [pid 1012520:tid 1012667] [client 140.238.42.111:60923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxajQpXMN3p_zkwXf3HawAAAJU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:29.736493 2026] [security2:error] [pid 1012520:tid 1012679] [client 3.82.141.143:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonnieebsenjackson.com"] [uri "/wp-config.php"] [unique_id "aqxajQpXMN3p_zkwXf3HdgAAAKE"]
[Thu Sep 17 15:24:29.787069 2026] [security2:error] [pid 1012520:tid 1012751] [client 3.82.141.143:30778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.bonnieebsenjackson.com"] [uri "/wp-config.php~"] [unique_id "aqxajQpXMN3p_zkwXf3HhgAAAOk"]
[Thu Sep 17 15:24:29.826034 2026] [security2:error] [pid 1012520:tid 1012753] [client 3.82.141.143:30594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mail.bonnieebsenjackson.com"] [uri "/web.config"] [unique_id "aqxajQpXMN3p_zkwXf3HiwAAAOs"]
[Thu Sep 17 15:24:29.831850 2026] [security2:error] [pid 1012520:tid 1012723] [client 3.82.141.143:30790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.bonnieebsenjackson.com"] [uri "/wp-config.php.bak"] [unique_id "aqxajQpXMN3p_zkwXf3HjgAAAM0"]
[Thu Sep 17 15:24:29.847857 2026] [security2:error] [pid 1012520:tid 1012704] [client 3.82.141.143:30718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.bonnieebsenjackson.com"] [uri "/wp-config.php.old"] [unique_id "aqxajQpXMN3p_zkwXf3HlgAAALo"]
[Thu Sep 17 15:24:29.848441 2026] [security2:error] [pid 1012520:tid 1012698] [client 3.82.141.143:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonnieebsenjackson.com"] [uri "/config.php"] [unique_id "aqxajQpXMN3p_zkwXf3HmQAAALQ"]
[Thu Sep 17 15:24:29.849117 2026] [security2:error] [pid 1012520:tid 1012673] [client 3.82.141.143:30806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.bonnieebsenjackson.com"] [uri "/.env"] [unique_id "aqxajQpXMN3p_zkwXf3HmAAAAJs"]
[Thu Sep 17 15:24:29.849634 2026] [security2:error] [pid 1012520:tid 1012721] [client 3.82.141.143:30834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.bonnieebsenjackson.com"] [uri "/.env.backup"] [unique_id "aqxajQpXMN3p_zkwXf3HlQAAAMs"]
[Thu Sep 17 15:24:29.851263 2026] [security2:error] [pid 1012520:tid 1012765] [client 3.82.141.143:30844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.bonnieebsenjackson.com"] [uri "/.env.bak"] [unique_id "aqxajQpXMN3p_zkwXf3HlwAAAPc"]
[Thu Sep 17 15:24:29.904919 2026] [security2:error] [pid 1012520:tid 1012675] [client 3.82.141.143:30918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.bonnieebsenjackson.com"] [uri "/wp-config.php.save"] [unique_id "aqxajQpXMN3p_zkwXf3HnwAAAJ0"]
[Thu Sep 17 15:24:29.911502 2026] [security2:error] [pid 1012520:tid 1012776] [client 140.238.42.111:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HoAAAAQI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:29.931192 2026] [security2:error] [pid 1012520:tid 1012699] [client 3.82.141.143:30602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.bonnieebsenjackson.com"] [uri "/.env.old"] [unique_id "aqxajQpXMN3p_zkwXf3HowAAALU"]
[Thu Sep 17 15:24:29.952362 2026] [security2:error] [pid 1012520:tid 1012771] [client 3.82.141.143:30658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HfAAAAP0"]
[Thu Sep 17 15:24:29.969035 2026] [security2:error] [pid 1012520:tid 1012687] [client 3.82.141.143:30672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HfQAAAKk"]
[Thu Sep 17 15:24:29.979791 2026] [security2:error] [pid 1012520:tid 1012659] [client 3.82.141.143:30726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HhAAAAI0"]
[Thu Sep 17 15:24:29.985982 2026] [security2:error] [pid 1012520:tid 1012717] [client 3.82.141.143:30860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HhQAAAMc"]
[Thu Sep 17 15:24:29.993389 2026] [security2:error] [pid 1012520:tid 1012757] [client 3.82.141.143:30740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HcwAAAO8"]
[Thu Sep 17 15:24:30.003710 2026] [security2:error] [pid 1012520:tid 1012733] [client 3.82.141.143:30618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HgQAAANc"]
[Thu Sep 17 15:24:30.273355 2026] [security2:error] [pid 1012520:tid 1012661] [client 3.82.141.143:30820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HiAAAAI8"]
[Thu Sep 17 15:24:30.280044 2026] [security2:error] [pid 1012520:tid 1012676] [client 3.82.141.143:30858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HhwAAAJ4"]
[Thu Sep 17 15:24:30.298479 2026] [security2:error] [pid 1012520:tid 1012768] [client 3.82.141.143:30762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HgAAAAPo"]
[Thu Sep 17 15:24:30.311145 2026] [security2:error] [pid 1012520:tid 1012700] [client 140.238.42.111:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxajgpXMN3p_zkwXf3HvQAAALY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:30.336293 2026] [security2:error] [pid 1012520:tid 1012769] [client 3.82.141.143:30750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HjwAAAPs"]
[Thu Sep 17 15:24:30.384547 2026] [security2:error] [pid 1012520:tid 1012705] [client 3.82.141.143:30808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HkgAAALs"]
[Thu Sep 17 15:24:30.384547 2026] [security2:error] [pid 1012520:tid 1012749] [client 3.82.141.143:30730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HjAAAAOc"]
[Thu Sep 17 15:24:30.405877 2026] [security2:error] [pid 1012520:tid 1012728] [client 3.82.141.143:30702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HngAAANI"]
[Thu Sep 17 15:24:30.412704 2026] [security2:error] [pid 1012520:tid 1012657] [client 3.82.141.143:30828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HkwAAAIs"]
[Thu Sep 17 15:24:30.414812 2026] [security2:error] [pid 1012520:tid 1012695] [client 3.82.141.143:30736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HnAAAALE"]
[Thu Sep 17 15:24:30.420486 2026] [security2:error] [pid 1012520:tid 1012745] [client 3.82.141.143:30630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HoQAAAOM"]
[Thu Sep 17 15:24:30.437398 2026] [security2:error] [pid 1012520:tid 1012743] [client 3.82.141.143:30646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HmwAAAOE"]
[Thu Sep 17 15:24:30.446175 2026] [security2:error] [pid 1012520:tid 1012677] [client 3.82.141.143:30764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HlAAAAJ8"]
[Thu Sep 17 15:24:30.448172 2026] [security2:error] [pid 1012520:tid 1012678] [client 3.82.141.143:30908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HkAAAAKA"]
[Thu Sep 17 15:24:30.472798 2026] [security2:error] [pid 1012520:tid 1012764] [client 3.82.141.143:30654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HmgAAAPY"]
[Thu Sep 17 15:24:30.482582 2026] [security2:error] [pid 1012520:tid 1012713] [client 3.82.141.143:30620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HogAAAMM"]
[Thu Sep 17 15:24:30.516834 2026] [security2:error] [pid 1012520:tid 1012702] [client 3.82.141.143:30694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.bonnieebsenjackson.com"] [uri "/index.php"] [unique_id "aqxajQpXMN3p_zkwXf3HnQAAALg"]
[Thu Sep 17 15:24:30.696268 2026] [security2:error] [pid 1012520:tid 1012692] [client 140.238.42.111:61933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxajgpXMN3p_zkwXf3H0gAAAK4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:30.857864 2026] [security2:error] [pid 1012520:tid 1012684] [client 67.207.95.55:33774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxajApXMN3p_zkwXf3HTgAAAKY"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:24:31.087288 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxajwpXMN3p_zkwXf3H4QAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:31.148811 2026] [security2:error] [pid 1012520:tid 1012667] [client 24.35.114.80:49439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxajwpXMN3p_zkwXf3H4AAAlWQ"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726082005&hideanons=1&limit=100&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:24:31.479985 2026] [security2:error] [pid 1012520:tid 1012718] [client 140.238.42.111:62577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxajwpXMN3p_zkwXf3H6wAAAMg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:31.540176 2026] [security2:error] [pid 1012520:tid 1012747] [client 114.198.138.124:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxajwpXMN3p_zkwXf3H8AAAAOU"]
[Thu Sep 17 15:24:31.540274 2026] [security2:error] [pid 1012520:tid 1012747] [client 114.198.138.124:65076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxajwpXMN3p_zkwXf3H8AAAAOU"]
[Thu Sep 17 15:24:31.858616 2026] [security2:error] [pid 1012520:tid 1012695] [client 140.238.42.111:62893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxajwpXMN3p_zkwXf3H8wAAALE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:32.041790 2026] [security2:error] [pid 1012520:tid 1012704] [client 216.24.219.102:45599] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/000.php"] [unique_id "aqxakApXMN3p_zkwXf3H_AAAALo"]
[Thu Sep 17 15:24:32.173027 2026] [security2:error] [pid 1012520:tid 1012723] [client 34.154.237.242:46468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/"] [unique_id "aqxakApXMN3p_zkwXf3H_gAAAM0"]
[Thu Sep 17 15:24:32.232974 2026] [security2:error] [pid 1012520:tid 1012698] [client 140.238.42.111:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxakApXMN3p_zkwXf3IAAAAALQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:32.277116 2026] [security2:error] [pid 1012520:tid 1012751] [client 156.192.234.52:60850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxakApXMN3p_zkwXf3IAQAAAOk"]
[Thu Sep 17 15:24:32.278511 2026] [security2:error] [pid 1012520:tid 1012751] [client 156.192.234.52:60850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxakApXMN3p_zkwXf3IAQAAAOk"]
[Thu Sep 17 15:24:32.305575 2026] [security2:error] [pid 1012520:tid 1012681] [client 67.207.95.55:57726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxakApXMN3p_zkwXf3H_QAAAKM"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:24:32.497457 2026] [security2:error] [pid 1012520:tid 1012699] [client 216.24.219.97:54631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/about.php"] [unique_id "aqxakApXMN3p_zkwXf3IAwAAALU"]
[Thu Sep 17 15:24:32.625749 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:63483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxakApXMN3p_zkwXf3ICAAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:32.676271 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.154.237.242:46482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/"] [unique_id "aqxakApXMN3p_zkwXf3ICQAAANU"]
[Thu Sep 17 15:24:32.753286 2026] [security2:error] [pid 1012520:tid 1012757] [client 193.36.224.148:54001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxakApXMN3p_zkwXf3ICwAAAO8"]
[Thu Sep 17 15:24:32.999499 2026] [security2:error] [pid 1012520:tid 1012674] [client 193.36.224.146:29043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxakApXMN3p_zkwXf3IEwAAAJw"]
[Thu Sep 17 15:24:33.008354 2026] [security2:error] [pid 1012520:tid 1012687] [client 186.105.232.15:60716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxakQpXMN3p_zkwXf3IFAAAAKk"]
[Thu Sep 17 15:24:33.008779 2026] [security2:error] [pid 1012520:tid 1012687] [client 186.105.232.15:60716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxakQpXMN3p_zkwXf3IFAAAAKk"]
[Thu Sep 17 15:24:33.012550 2026] [security2:error] [pid 1012520:tid 1012668] [client 140.238.42.111:63792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxakQpXMN3p_zkwXf3IFQAAAJY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:33.032427 2026] [security2:error] [pid 1012520:tid 1012696] [client 185.55.149.49:51583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxakQpXMN3p_zkwXf3IHAAAALI"]
[Thu Sep 17 15:24:33.032815 2026] [security2:error] [pid 1012520:tid 1012696] [client 185.55.149.49:51583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxakQpXMN3p_zkwXf3IHAAAALI"]
[Thu Sep 17 15:24:33.171059 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.154.237.242:46488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/"] [unique_id "aqxakQpXMN3p_zkwXf3IIQAAAJk"]
[Thu Sep 17 15:24:33.283394 2026] [security2:error] [pid 1012520:tid 1012709] [client 193.36.224.150:44525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxakQpXMN3p_zkwXf3IIgAAAL8"]
[Thu Sep 17 15:24:33.412882 2026] [security2:error] [pid 1012520:tid 1012697] [client 140.238.42.111:64076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxakQpXMN3p_zkwXf3IJAAAALM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:33.674353 2026] [security2:error] [pid 1012520:tid 1012691] [client 193.36.224.151:31599] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxakQpXMN3p_zkwXf3IKwAAAK0"]
[Thu Sep 17 15:24:33.795152 2026] [security2:error] [pid 1012520:tid 1012742] [client 140.238.42.111:64385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxakQpXMN3p_zkwXf3IMAAAAOA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:33.875119 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.154.237.242:46500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/"] [unique_id "aqxakQpXMN3p_zkwXf3IMgAAAKA"]
[Thu Sep 17 15:24:33.970126 2026] [security2:error] [pid 1012520:tid 1012685] [client 216.24.219.105:28425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/bless.php"] [unique_id "aqxakQpXMN3p_zkwXf3INQAAAKc"]
[Thu Sep 17 15:24:34.195527 2026] [security2:error] [pid 1012520:tid 1012723] [client 140.238.42.111:64661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxakgpXMN3p_zkwXf3IOgAAAM0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:34.269057 2026] [security2:error] [pid 1012520:tid 1012776] [client 169.58.197.253:50875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxakgpXMN3p_zkwXf3IPQAAAQI"], referer: binance.com
[Thu Sep 17 15:24:34.353874 2026] [security2:error] [pid 1012520:tid 1012683] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/.env"] [unique_id "aqxakgpXMN3p_zkwXf3IPgAAAKU"]
[Thu Sep 17 15:24:34.433369 2026] [security2:error] [pid 1012520:tid 1012652] [client 104.234.19.151:35043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/goods.php"] [unique_id "aqxakgpXMN3p_zkwXf3IQAAAAIY"]
[Thu Sep 17 15:24:34.581362 2026] [security2:error] [pid 1012520:tid 1012679] [client 45.180.240.133:57860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxakgpXMN3p_zkwXf3IQQAAAKE"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:24:34.610635 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxakgpXMN3p_zkwXf3IRwAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:35.051017 2026] [security2:error] [pid 1012520:tid 1012760] [client 162.241.226.11:19380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jenniferniesslein.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxakwpXMN3p_zkwXf3IVwAAAPI"]
[Thu Sep 17 15:24:35.057510 2026] [security2:error] [pid 1012520:tid 1012761] [client 140.238.42.111:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxakwpXMN3p_zkwXf3IWAAAAPM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:35.360427 2026] [security2:error] [pid 1012520:tid 1012718] [client 24.45.219.199:50091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.enduringwanderlust.com"] [uri "/wp-admin/post.php"] [unique_id "aqxakwpXMN3p_zkwXf3IXQAAyHE"], referer: https://www.enduringwanderlust.com/wp-admin/post.php?post=1965&action=edit
[Thu Sep 17 15:24:35.462635 2026] [security2:error] [pid 1012520:tid 1012744] [client 140.238.42.111:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxakwpXMN3p_zkwXf3IbAAAAOI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:35.687785 2026] [security2:error] [pid 1012520:tid 1012569] [remote 16.216.88.136:30720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxakgpXMN3p_zkwXf3IUQAA9y8"]
[Thu Sep 17 15:24:35.771716 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/.env.bak"] [unique_id "aqxakwpXMN3p_zkwXf3IfgAAAPg"]
[Thu Sep 17 15:24:35.848244 2026] [security2:error] [pid 1012520:tid 1012681] [client 104.207.33.33:46243] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxakwpXMN3p_zkwXf3IgQAAAKM"]
[Thu Sep 17 15:24:35.848912 2026] [security2:error] [pid 1012520:tid 1012658] [client 140.238.42.111:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxakwpXMN3p_zkwXf3IggAAAIw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:35.930187 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/.env.backup"] [unique_id "aqxakwpXMN3p_zkwXf3IhAAAAJQ"]
[Thu Sep 17 15:24:35.967956 2026] [security2:error] [pid 1012520:tid 1012522] [remote 16.216.88.136:30721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.88.216.16.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxakwpXMN3p_zkwXf3IhQABAwA"]
[Thu Sep 17 15:24:36.229142 2026] [security2:error] [pid 1012520:tid 1012754] [client 140.238.42.111:49975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxalApXMN3p_zkwXf3IjQAAAOw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:36.308526 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/.env.old"] [unique_id "aqxalApXMN3p_zkwXf3IjwAAAM4"]
[Thu Sep 17 15:24:36.387908 2026] [security2:error] [pid 1012520:tid 1012697] [client 216.24.219.104:33759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/blurbs.php"] [unique_id "aqxalApXMN3p_zkwXf3IkgAAALM"]
[Thu Sep 17 15:24:36.494763 2026] [security2:error] [pid 1012520:tid 1012696] [client 103.61.184.148:57100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxalApXMN3p_zkwXf3IlgAAALI"]
[Thu Sep 17 15:24:36.495219 2026] [security2:error] [pid 1012520:tid 1012696] [client 103.61.184.148:57100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxalApXMN3p_zkwXf3IlgAAALI"]
[Thu Sep 17 15:24:36.621195 2026] [security2:error] [pid 1012520:tid 1012705] [client 140.238.42.111:50281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxalApXMN3p_zkwXf3ImAAAALs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:36.699268 2026] [security2:error] [pid 1012520:tid 1012688] [client 216.73.216.91:64114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxakgpXMN3p_zkwXf3IUwAAqms"]
[Thu Sep 17 15:24:37.014954 2026] [security2:error] [pid 1012520:tid 1012713] [client 127.0.0.1:35562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxalApXMN3p_zkwXf3IpgAAAMM"]
[Thu Sep 17 15:24:37.015064 2026] [security2:error] [pid 1012520:tid 1012700] [client 74.7.230.16:43084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.petsplace.com.pe"] [uri "/robots.txt"] [unique_id "aqxalApXMN3p_zkwXf3IpQAAtmc"]
[Thu Sep 17 15:24:37.021792 2026] [security2:error] [pid 1012520:tid 1012660] [client 140.238.42.111:50616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxalQpXMN3p_zkwXf3IqAAAAI4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:37.108198 2026] [security2:error] [pid 1012520:tid 1012681] [client 216.24.219.102:63479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxalQpXMN3p_zkwXf3IsQAAAKM"]
[Thu Sep 17 15:24:37.426881 2026] [security2:error] [pid 1012520:tid 1012687] [client 140.238.42.111:50988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxalQpXMN3p_zkwXf3IugAAAKk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:37.833264 2026] [security2:error] [pid 1012520:tid 1012736] [client 140.238.42.111:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxalQpXMN3p_zkwXf3IygAAANo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:37.910163 2026] [security2:error] [pid 1012520:tid 1012685] [client 190.216.61.117:57442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxalQpXMN3p_zkwXf3IyQAAAKc"], referer: https://sharedtablepk.org/
[Thu Sep 17 15:24:38.214146 2026] [security2:error] [pid 1012520:tid 1012671] [client 140.238.42.111:51617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxalgpXMN3p_zkwXf3I2QAAAJk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:38.619999 2026] [security2:error] [pid 1012520:tid 1012718] [client 140.238.42.111:51926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxalgpXMN3p_zkwXf3I5AAAAMg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:38.784543 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/.env.swp"] [unique_id "aqxalgpXMN3p_zkwXf3I5wAAANM"]
[Thu Sep 17 15:24:38.944000 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/.env~"] [unique_id "aqxalgpXMN3p_zkwXf3I7QAAAJM"]
[Thu Sep 17 15:24:39.022246 2026] [security2:error] [pid 1012520:tid 1012702] [client 216.24.219.35:56101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/abcd.php"] [unique_id "aqxalwpXMN3p_zkwXf3I7wAAALg"]
[Thu Sep 17 15:24:39.035247 2026] [security2:error] [pid 1012520:tid 1012747] [client 140.238.42.111:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxalwpXMN3p_zkwXf3I8AAAAOU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:39.452707 2026] [security2:error] [pid 1012520:tid 1012776] [client 140.238.42.111:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxalwpXMN3p_zkwXf3I_wAAAQI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:39.830864 2026] [security2:error] [pid 1012520:tid 1012672] [client 140.238.42.111:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxalwpXMN3p_zkwXf3JCgAAAJo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:39.952992 2026] [security2:error] [pid 1012520:tid 1012679] [client 154.190.208.131:42089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxalwpXMN3p_zkwXf3JCwAAAKE"]
[Thu Sep 17 15:24:39.953164 2026] [security2:error] [pid 1012520:tid 1012679] [client 154.190.208.131:42089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxalwpXMN3p_zkwXf3JCwAAAKE"]
[Thu Sep 17 15:24:40.212878 2026] [security2:error] [pid 1012520:tid 1012651] [client 140.238.42.111:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxamApXMN3p_zkwXf3JFwAAAIU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:40.599001 2026] [security2:error] [pid 1012520:tid 1012712] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/app/.env"] [unique_id "aqxamApXMN3p_zkwXf3JIAAAAMI"]
[Thu Sep 17 15:24:40.627510 2026] [security2:error] [pid 1012520:tid 1012724] [client 140.238.42.111:53600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxamApXMN3p_zkwXf3JIgAAAM4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:40.758839 2026] [security2:error] [pid 1012520:tid 1012693] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/apps/.env"] [unique_id "aqxamApXMN3p_zkwXf3JJAAAAK8"]
[Thu Sep 17 15:24:40.843706 2026] [security2:error] [pid 1012520:tid 1012716] [client 193.36.224.146:37739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxamApXMN3p_zkwXf3JIwAAAMY"]
[Thu Sep 17 15:24:40.924626 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/api/.env"] [unique_id "aqxamApXMN3p_zkwXf3JKQAAAPw"]
[Thu Sep 17 15:24:41.009181 2026] [security2:error] [pid 1012520:tid 1012709] [client 140.238.42.111:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxamQpXMN3p_zkwXf3JKwAAAL8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:41.080379 2026] [security2:error] [pid 1012520:tid 1012741] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/web/.env"] [unique_id "aqxamQpXMN3p_zkwXf3JLwAAAN8"]
[Thu Sep 17 15:24:41.131751 2026] [security2:error] [pid 1012520:tid 1012739] [client 104.234.19.147:29353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/dex.php"] [unique_id "aqxamQpXMN3p_zkwXf3JMgAAAN0"]
[Thu Sep 17 15:24:41.236838 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/site/.env"] [unique_id "aqxamQpXMN3p_zkwXf3JNQAAAPY"]
[Thu Sep 17 15:24:41.395597 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/public/.env"] [unique_id "aqxamQpXMN3p_zkwXf3JOAAAAKA"]
[Thu Sep 17 15:24:41.415768 2026] [security2:error] [pid 1012520:tid 1012729] [client 140.238.42.111:54278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxamQpXMN3p_zkwXf3JOQAAANM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:41.578256 2026] [security2:error] [pid 1012520:tid 1012682] [client 76.180.98.38:60603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxamQpXMN3p_zkwXf3JOgAApBU"], referer: https://www.google.com/
[Thu Sep 17 15:24:41.760954 2026] [security2:error] [pid 1012520:tid 1012673] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/backend/.env"] [unique_id "aqxamQpXMN3p_zkwXf3JQgAAAJs"]
[Thu Sep 17 15:24:41.797717 2026] [security2:error] [pid 1012520:tid 1012664] [client 193.36.224.170:46367] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxamQpXMN3p_zkwXf3JRAAAAJI"]
[Thu Sep 17 15:24:41.817688 2026] [security2:error] [pid 1012520:tid 1012699] [client 140.238.42.111:54655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxamQpXMN3p_zkwXf3JRgAAALU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:41.915607 2026] [security2:error] [pid 1012520:tid 1012731] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/server/.env"] [unique_id "aqxamQpXMN3p_zkwXf3JSQAAANU"]
[Thu Sep 17 15:24:42.041221 2026] [security2:error] [pid 1012520:tid 1012687] [client 216.24.219.97:48107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxamgpXMN3p_zkwXf3JTgAAAKk"]
[Thu Sep 17 15:24:42.072688 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/frontend/.env"] [unique_id "aqxamgpXMN3p_zkwXf3JUQAAAOk"]
[Thu Sep 17 15:24:42.147610 2026] [security2:error] [pid 1012520:tid 1012652] [client 114.198.138.124:53266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxamgpXMN3p_zkwXf3JUwAAAIY"]
[Thu Sep 17 15:24:42.147750 2026] [security2:error] [pid 1012520:tid 1012652] [client 114.198.138.124:53266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxamgpXMN3p_zkwXf3JUwAAAIY"]
[Thu Sep 17 15:24:42.227633 2026] [security2:error] [pid 1012520:tid 1012733] [client 140.238.42.111:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxamgpXMN3p_zkwXf3JVAAAANc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:42.232748 2026] [security2:error] [pid 1012520:tid 1012698] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/src/.env"] [unique_id "aqxamgpXMN3p_zkwXf3JVQAAALQ"]
[Thu Sep 17 15:24:42.389125 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/core/.env"] [unique_id "aqxamgpXMN3p_zkwXf3JWAAAAJ4"]
[Thu Sep 17 15:24:42.552874 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/core/app/.env"] [unique_id "aqxamgpXMN3p_zkwXf3JXwAAAIk"]
[Thu Sep 17 15:24:42.592132 2026] [security2:error] [pid 1012520:tid 1012763] [client 208.109.3.11:43454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluetech.com"] [uri "/index.php"] [unique_id "aqxamgpXMN3p_zkwXf3JVgAAAPU"]
[Thu Sep 17 15:24:42.618868 2026] [security2:error] [pid 1012520:tid 1012760] [client 140.238.42.111:55309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxamgpXMN3p_zkwXf3JZAAAAPI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:42.720843 2026] [security2:error] [pid 1012520:tid 1012773] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/config/.env"] [unique_id "aqxamgpXMN3p_zkwXf3JZQAAAP8"]
[Thu Sep 17 15:24:42.724867 2026] [security2:error] [pid 1012520:tid 1012750] [client 216.24.219.100:48373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/index.php"] [unique_id "aqxamgpXMN3p_zkwXf3JZwAAAOg"]
[Thu Sep 17 15:24:42.881434 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/private/.env"] [unique_id "aqxamgpXMN3p_zkwXf3JawAAAL8"]
[Thu Sep 17 15:24:42.882839 2026] [security2:error] [pid 1012520:tid 1012754] [client 156.192.234.52:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxamgpXMN3p_zkwXf3JbAAAAOw"]
[Thu Sep 17 15:24:42.882935 2026] [security2:error] [pid 1012520:tid 1012754] [client 156.192.234.52:61484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxamgpXMN3p_zkwXf3JbAAAAOw"]
[Thu Sep 17 15:24:42.885655 2026] [security2:error] [pid 1012520:tid 1012686] [client 169.58.197.253:51441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxamgpXMN3p_zkwXf3JbQAAAKg"], referer: binance.com
[Thu Sep 17 15:24:42.908196 2026] [security2:error] [pid 1012520:tid 1012716] [client 76.180.98.38:43503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxamgpXMN3p_zkwXf3JaQAAxhk"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818114618&hideanons=1&hidebots=0&limit=500&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:24:43.021276 2026] [security2:error] [pid 1012520:tid 1012732] [client 140.238.42.111:55652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxamwpXMN3p_zkwXf3JdAAAANY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:43.036936 2026] [security2:error] [pid 1012520:tid 1012688] [client 216.24.219.103:55801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxamwpXMN3p_zkwXf3JdQAAAKo"]
[Thu Sep 17 15:24:43.043585 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/application/.env"] [unique_id "aqxamwpXMN3p_zkwXf3JdwAAAQA"]
[Thu Sep 17 15:24:43.203260 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/bootstrap/.env"] [unique_id "aqxamwpXMN3p_zkwXf3JewAAAOM"]
[Thu Sep 17 15:24:43.358803 2026] [security2:error] [pid 1012520:tid 1012729] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/database/.env"] [unique_id "aqxamwpXMN3p_zkwXf3JfQAAANM"]
[Thu Sep 17 15:24:43.425493 2026] [security2:error] [pid 1012520:tid 1012705] [client 140.238.42.111:55956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxamwpXMN3p_zkwXf3JfgAAALs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:43.517359 2026] [security2:error] [pid 1012520:tid 1012747] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/storage/.env"] [unique_id "aqxamwpXMN3p_zkwXf3JgwAAAOU"]
[Thu Sep 17 15:24:43.610910 2026] [security2:error] [pid 1012520:tid 1012759] [client 193.36.224.152:41031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/index.php"] [unique_id "aqxamwpXMN3p_zkwXf3JjwAAAPE"]
[Thu Sep 17 15:24:43.673510 2026] [security2:error] [pid 1012520:tid 1012674] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/var/www/.env"] [unique_id "aqxamwpXMN3p_zkwXf3JkAAAAJw"]
[Thu Sep 17 15:24:43.757269 2026] [security2:error] [pid 1012520:tid 1012704] [client 185.55.149.49:52221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxamwpXMN3p_zkwXf3JkwAAALo"]
[Thu Sep 17 15:24:43.757383 2026] [security2:error] [pid 1012520:tid 1012704] [client 185.55.149.49:52221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxamwpXMN3p_zkwXf3JkwAAALo"]
[Thu Sep 17 15:24:43.827700 2026] [security2:error] [pid 1012520:tid 1012752] [client 140.238.42.111:56267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxamwpXMN3p_zkwXf3JlAAAAOo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:43.829852 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/var/www/html/.env"] [unique_id "aqxamwpXMN3p_zkwXf3JlQAAAIY"]
[Thu Sep 17 15:24:43.987941 2026] [security2:error] [pid 1012520:tid 1012726] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/current/.env"] [unique_id "aqxamwpXMN3p_zkwXf3JlwAAANA"]
[Thu Sep 17 15:24:43.993921 2026] [security2:error] [pid 1012520:tid 1012660] [client 104.207.33.33:44833] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxamwpXMN3p_zkwXf3JmQAAAI4"]
[Thu Sep 17 15:24:44.143037 2026] [security2:error] [pid 1012520:tid 1012668] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/release/.env"] [unique_id "aqxanApXMN3p_zkwXf3JngAAAJY"]
[Thu Sep 17 15:24:44.219293 2026] [security2:error] [pid 1012520:tid 1012707] [client 140.238.42.111:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxanApXMN3p_zkwXf3JoAAAAL0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:44.306741 2026] [security2:error] [pid 1012520:tid 1012701] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/releases/.env"] [unique_id "aqxanApXMN3p_zkwXf3JoQAAALc"]
[Thu Sep 17 15:24:44.467075 2026] [security2:error] [pid 1012520:tid 1012697] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/shared/.env"] [unique_id "aqxanApXMN3p_zkwXf3JpQAAALM"]
[Thu Sep 17 15:24:44.623830 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/deploy/.env"] [unique_id "aqxanApXMN3p_zkwXf3JqgAAAOw"]
[Thu Sep 17 15:24:44.627081 2026] [security2:error] [pid 1012520:tid 1012735] [client 140.238.42.111:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxanApXMN3p_zkwXf3JqwAAANk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:44.783193 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/build/.env"] [unique_id "aqxanApXMN3p_zkwXf3JrgAAAK0"]
[Thu Sep 17 15:24:44.941258 2026] [security2:error] [pid 1012520:tid 1012778] [client 193.36.224.221:25091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxanApXMN3p_zkwXf3JsgAAAQQ"]
[Thu Sep 17 15:24:44.946086 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/dist/.env"] [unique_id "aqxanApXMN3p_zkwXf3JswAAAJM"]
[Thu Sep 17 15:24:45.016832 2026] [security2:error] [pid 1012520:tid 1012749] [client 140.238.42.111:57278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxanQpXMN3p_zkwXf3JtwAAAOc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:45.117501 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/public_html/.env"] [unique_id "aqxanQpXMN3p_zkwXf3JuAAAAIs"]
[Thu Sep 17 15:24:45.273100 2026] [security2:error] [pid 1012520:tid 1012689] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/htdocs/.env"] [unique_id "aqxanQpXMN3p_zkwXf3JuwAAAKs"]
[Thu Sep 17 15:24:45.358423 2026] [security2:error] [pid 1012520:tid 1012719] [client 193.36.224.212:45581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/file.php"] [unique_id "aqxanQpXMN3p_zkwXf3JvAAAAMk"]
[Thu Sep 17 15:24:45.397622 2026] [security2:error] [pid 1012520:tid 1012729] [client 140.238.42.111:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxanQpXMN3p_zkwXf3JvQAAANM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:45.429396 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/www/.env"] [unique_id "aqxanQpXMN3p_zkwXf3JvwAAALU"]
[Thu Sep 17 15:24:45.553104 2026] [security2:error] [pid 1012520:tid 1012664] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxanQpXMN3p_zkwXf3JwAAAAJI"]
[Thu Sep 17 15:24:45.590552 2026] [security2:error] [pid 1012520:tid 1012769] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/html/.env"] [unique_id "aqxanQpXMN3p_zkwXf3JxQAAAPs"]
[Thu Sep 17 15:24:45.717584 2026] [security2:error] [pid 1012520:tid 1012687] [client 216.24.219.101:46287] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxanQpXMN3p_zkwXf3JywAAAKk"]
[Thu Sep 17 15:24:45.746241 2026] [security2:error] [pid 1012520:tid 1012700] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/live/.env"] [unique_id "aqxanQpXMN3p_zkwXf3JzAAAALY"]
[Thu Sep 17 15:24:45.784633 2026] [security2:error] [pid 1012520:tid 1012765] [client 140.238.42.111:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxanQpXMN3p_zkwXf3JzwAAAPc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:45.901819 2026] [security2:error] [pid 1012520:tid 1012757] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/prod/.env"] [unique_id "aqxanQpXMN3p_zkwXf3J0QAAAO8"]
[Thu Sep 17 15:24:45.935173 2026] [security2:error] [pid 1012520:tid 1012675] [client 186.105.232.15:61300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxanQpXMN3p_zkwXf3J0wAAAJ0"]
[Thu Sep 17 15:24:45.935350 2026] [security2:error] [pid 1012520:tid 1012675] [client 186.105.232.15:61300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxanQpXMN3p_zkwXf3J0wAAAJ0"]
[Thu Sep 17 15:24:46.056374 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/dev/.env"] [unique_id "aqxangpXMN3p_zkwXf3J1gAAAMQ"]
[Thu Sep 17 15:24:46.170783 2026] [security2:error] [pid 1012520:tid 1012733] [client 140.238.42.111:58280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxangpXMN3p_zkwXf3J2gAAANc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:46.208124 2026] [security2:error] [pid 1012520:tid 1012751] [client 66.249.88.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxanQpXMN3p_zkwXf3JzgAAAOk"]
[Thu Sep 17 15:24:46.212560 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/staging/.env"] [unique_id "aqxangpXMN3p_zkwXf3J3AAAAIU"]
[Thu Sep 17 15:24:46.373839 2026] [security2:error] [pid 1012520:tid 1012655] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/opt/.env"] [unique_id "aqxangpXMN3p_zkwXf3J3wAAAIk"]
[Thu Sep 17 15:24:46.531431 2026] [security2:error] [pid 1012520:tid 1012671] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/laravel/.env"] [unique_id "aqxangpXMN3p_zkwXf3J5gAAAJk"]
[Thu Sep 17 15:24:46.562840 2026] [security2:error] [pid 1012520:tid 1012763] [client 140.238.42.111:58631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxangpXMN3p_zkwXf3J6AAAAPU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:46.685117 2026] [security2:error] [pid 1012520:tid 1012703] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/symfony/.env"] [unique_id "aqxangpXMN3p_zkwXf3J7gAAALk"]
[Thu Sep 17 15:24:46.842177 2026] [security2:error] [pid 1012520:tid 1012770] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/wordpress/.env"] [unique_id "aqxangpXMN3p_zkwXf3J8gAAAPw"]
[Thu Sep 17 15:24:46.950228 2026] [security2:error] [pid 1012520:tid 1012690] [client 140.238.42.111:59004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxangpXMN3p_zkwXf3J9QAAAKw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:46.998594 2026] [security2:error] [pid 1012520:tid 1012696] [client 8.231.55.47:58944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/.env"] [unique_id "aqxangpXMN3p_zkwXf3J9gAAALI"]
[Thu Sep 17 15:24:46.999314 2026] [security2:error] [pid 1012520:tid 1012678] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/wp/.env"] [unique_id "aqxangpXMN3p_zkwXf3J9wAAAKA"]
[Thu Sep 17 15:24:47.114014 2026] [security2:error] [pid 1012520:tid 1012725] [client 216.24.219.38:34927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-mail.php"] [unique_id "aqxanwpXMN3p_zkwXf3J_wAAAM8"]
[Thu Sep 17 15:24:47.155666 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cms/.env"] [unique_id "aqxanwpXMN3p_zkwXf3KBQAAAQE"]
[Thu Sep 17 15:24:47.187379 2026] [security2:error] [pid 1012520:tid 1012681] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxanwpXMN3p_zkwXf3J-wAAAKM"]
[Thu Sep 17 15:24:47.210390 2026] [security2:error] [pid 1012520:tid 1012774] [client 103.61.184.148:57832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxanwpXMN3p_zkwXf3KDwAAAQA"]
[Thu Sep 17 15:24:47.210520 2026] [security2:error] [pid 1012520:tid 1012774] [client 103.61.184.148:57832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxanwpXMN3p_zkwXf3KDwAAAQA"]
[Thu Sep 17 15:24:47.336212 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/drupal/.env"] [unique_id "aqxanwpXMN3p_zkwXf3KGQAAAMQ"]
[Thu Sep 17 15:24:47.350473 2026] [security2:error] [pid 1012520:tid 1012663] [client 140.238.42.111:59326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxanwpXMN3p_zkwXf3KGgAAAJE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:47.357973 2026] [security2:error] [pid 1012520:tid 1012660] [client 193.36.224.169:26023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/ioxi-o.php"] [unique_id "aqxanwpXMN3p_zkwXf3KGwAAAI4"]
[Thu Sep 17 15:24:47.492119 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/joomla/.env"] [unique_id "aqxanwpXMN3p_zkwXf3KHwAAAK4"]
[Thu Sep 17 15:24:47.663327 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.154.237.242:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/magento/.env"] [unique_id "aqxanwpXMN3p_zkwXf3KKAAAAJQ"]
[Thu Sep 17 15:24:47.713212 2026] [security2:error] [pid 1012520:tid 1012662] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxanwpXMN3p_zkwXf3KJAAAAJA"]
[Thu Sep 17 15:24:47.746556 2026] [security2:error] [pid 1012520:tid 1012721] [client 140.238.42.111:59640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxanwpXMN3p_zkwXf3KKQAAAMs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:47.797098 2026] [security2:error] [pid 1012520:tid 1012735] [client 165.154.29.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lumenroast.com"] [uri "/index.php"] [unique_id "aqxangpXMN3p_zkwXf3J7QAAANk"], referer: https://mail.avo.jgb.mybluehost.me/sitemap.xml
[Thu Sep 17 15:24:48.124391 2026] [security2:error] [pid 1012520:tid 1012653] [client 140.238.42.111:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaoApXMN3p_zkwXf3KNgAAAIc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:48.139871 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/shopify/.env"] [unique_id "aqxaoApXMN3p_zkwXf3KNwAAAMo"]
[Thu Sep 17 15:24:48.206382 2026] [security2:error] [pid 1012520:tid 1012694] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaoApXMN3p_zkwXf3KNAAAALA"]
[Thu Sep 17 15:24:48.301643 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/prestashop/.env"] [unique_id "aqxaoApXMN3p_zkwXf3KOAAAAK0"]
[Thu Sep 17 15:24:48.321180 2026] [security2:error] [pid 1012520:tid 1012730] [client 216.24.219.31:36463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxaoApXMN3p_zkwXf3KOQAAANQ"]
[Thu Sep 17 15:24:48.458171 2026] [security2:error] [pid 1012520:tid 1012750] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/codeigniter/.env"] [unique_id "aqxaoApXMN3p_zkwXf3KPAAAAOg"]
[Thu Sep 17 15:24:48.525224 2026] [security2:error] [pid 1012520:tid 1012685] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaoApXMN3p_zkwXf3KOwAAAKc"]
[Thu Sep 17 15:24:48.529652 2026] [security2:error] [pid 1012520:tid 1012744] [client 140.238.42.111:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaoApXMN3p_zkwXf3KPwAAAOI"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:48.614541 2026] [security2:error] [pid 1012520:tid 1012706] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cakephp/.env"] [unique_id "aqxaoApXMN3p_zkwXf3KQgAAALw"]
[Thu Sep 17 15:24:48.775119 2026] [security2:error] [pid 1012520:tid 1012681] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaoApXMN3p_zkwXf3KQwAAAKM"]
[Thu Sep 17 15:24:48.784707 2026] [security2:error] [pid 1012520:tid 1012682] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/zend/.env"] [unique_id "aqxaoApXMN3p_zkwXf3KRAAAAKQ"]
[Thu Sep 17 15:24:48.822887 2026] [security2:error] [pid 1012520:tid 1012759] [client 104.234.19.152:47769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/style.php"] [unique_id "aqxaoApXMN3p_zkwXf3KRQAAAPE"]
[Thu Sep 17 15:24:48.914238 2026] [security2:error] [pid 1012520:tid 1012748] [client 140.238.42.111:60611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaoApXMN3p_zkwXf3KSAAAAOY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:48.942090 2026] [security2:error] [pid 1012520:tid 1012658] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/yii/.env"] [unique_id "aqxaoApXMN3p_zkwXf3KSQAAAIw"]
[Thu Sep 17 15:24:49.017501 2026] [security2:error] [pid 1012520:tid 1012769] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaoApXMN3p_zkwXf3KRwAAAPs"]
[Thu Sep 17 15:24:49.096883 2026] [security2:error] [pid 1012520:tid 1012740] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/laravel5/.env"] [unique_id "aqxaoQpXMN3p_zkwXf3KTQAAAN4"]
[Thu Sep 17 15:24:49.250247 2026] [security2:error] [pid 1012520:tid 1012656] [client 8.231.55.47:58944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxaoQpXMN3p_zkwXf3KUAAAAIo"]
[Thu Sep 17 15:24:49.261440 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/v1/.env"] [unique_id "aqxaoQpXMN3p_zkwXf3KUQAAAMQ"]
[Thu Sep 17 15:24:49.296564 2026] [security2:error] [pid 1012520:tid 1012766] [client 140.238.42.111:60951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaoQpXMN3p_zkwXf3KUwAAAPg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:49.319008 2026] [security2:error] [pid 1012520:tid 1012663] [client 8.231.55.47:58944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxaoQpXMN3p_zkwXf3KVAAAAJE"]
[Thu Sep 17 15:24:49.380002 2026] [security2:error] [pid 1012520:tid 1012733] [client 104.234.19.151:44915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/style.php"] [unique_id "aqxaoQpXMN3p_zkwXf3KVgAAANc"]
[Thu Sep 17 15:24:49.416599 2026] [security2:error] [pid 1012520:tid 1012767] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/v2/.env"] [unique_id "aqxaoQpXMN3p_zkwXf3KWAAAAPk"]
[Thu Sep 17 15:24:49.499259 2026] [security2:error] [pid 1012520:tid 1012702] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaoQpXMN3p_zkwXf3KVwAAALg"]
[Thu Sep 17 15:24:49.576779 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/v3/.env"] [unique_id "aqxaoQpXMN3p_zkwXf3KXAAAAM4"]
[Thu Sep 17 15:24:49.670902 2026] [security2:error] [pid 1012520:tid 1012707] [client 5.189.145.112:50114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxaoQpXMN3p_zkwXf3KXwAAAL0"], referer: binance.com
[Thu Sep 17 15:24:49.711376 2026] [security2:error] [pid 1012520:tid 1012735] [client 140.238.42.111:61292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaoQpXMN3p_zkwXf3KYAAAANk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:49.731581 2026] [security2:error] [pid 1012520:tid 1012753] [client 216.24.219.35:28393] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxaoQpXMN3p_zkwXf3KYQAAAOs"]
[Thu Sep 17 15:24:49.733236 2026] [security2:error] [pid 1012520:tid 1012708] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/api/v1/.env"] [unique_id "aqxaoQpXMN3p_zkwXf3KYgAAAL4"]
[Thu Sep 17 15:24:49.754146 2026] [security2:error] [pid 1012520:tid 1012668] [client 8.231.55.47:58944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxaoQpXMN3p_zkwXf3KYwAAAJY"]
[Thu Sep 17 15:24:49.891936 2026] [security2:error] [pid 1012520:tid 1012758] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/api/v2/.env"] [unique_id "aqxaoQpXMN3p_zkwXf3KZgAAAPA"]
[Thu Sep 17 15:24:50.003051 2026] [security2:error] [pid 1012520:tid 1012687] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaoQpXMN3p_zkwXf3KZwAAAKk"]
[Thu Sep 17 15:24:50.045219 2026] [security2:error] [pid 1012520:tid 1012652] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/rest/.env"] [unique_id "aqxaogpXMN3p_zkwXf3KawAAAIY"]
[Thu Sep 17 15:24:50.122343 2026] [security2:error] [pid 1012520:tid 1012710] [client 140.238.42.111:61656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaogpXMN3p_zkwXf3KbgAAAMA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:50.208083 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/graphql/.env"] [unique_id "aqxaogpXMN3p_zkwXf3KcgAAAOw"]
[Thu Sep 17 15:24:50.304990 2026] [security2:error] [pid 1012520:tid 1012694] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaogpXMN3p_zkwXf3KcQAAALA"]
[Thu Sep 17 15:24:50.331568 2026] [security2:error] [pid 1012520:tid 1012722] [client 154.190.208.131:41339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaogpXMN3p_zkwXf3KdQAAAMw"]
[Thu Sep 17 15:24:50.331715 2026] [security2:error] [pid 1012520:tid 1012722] [client 154.190.208.131:41339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxaogpXMN3p_zkwXf3KdQAAAMw"]
[Thu Sep 17 15:24:50.373423 2026] [security2:error] [pid 1012520:tid 1012718] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/gateway/.env"] [unique_id "aqxaogpXMN3p_zkwXf3KdgAAAMg"]
[Thu Sep 17 15:24:50.489084 2026] [security2:error] [pid 1012520:tid 1012739] [client 193.36.224.146:33975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-editor.php"] [unique_id "aqxaogpXMN3p_zkwXf3KeQAAAN0"]
[Thu Sep 17 15:24:50.535116 2026] [security2:error] [pid 1012520:tid 1012711] [client 140.238.42.111:62054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaogpXMN3p_zkwXf3KgAAAAME"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:50.535264 2026] [security2:error] [pid 1012520:tid 1012744] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/microservice/.env"] [unique_id "aqxaogpXMN3p_zkwXf3KfgAAAOI"]
[Thu Sep 17 15:24:50.543115 2026] [autoindex:error] [pid 1012520:tid 1012670] [client 64.69.216.78:45058] AH01276: Cannot serve directory /home1/kolindco/public_html/t2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://thesecondcycle.kolind.co
[Thu Sep 17 15:24:50.691823 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/service/.env"] [unique_id "aqxaogpXMN3p_zkwXf3KhQAAAIs"]
[Thu Sep 17 15:24:50.853361 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/api/v3/.env"] [unique_id "aqxaogpXMN3p_zkwXf3KiAAAANI"]
[Thu Sep 17 15:24:50.962533 2026] [security2:error] [pid 1012520:tid 1012732] [client 140.238.42.111:62488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaogpXMN3p_zkwXf3KiwAAANY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:51.014230 2026] [security2:error] [pid 1012520:tid 1012699] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/api/dev/.env"] [unique_id "aqxaowpXMN3p_zkwXf3KjQAAALU"]
[Thu Sep 17 15:24:51.170275 2026] [autoindex:error] [pid 1012520:tid 1012700] [client 64.69.216.78:45098] AH01276: Cannot serve directory /home1/kolindco/public_html/t2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://thesecondcycle.kolind.co
[Thu Sep 17 15:24:51.170822 2026] [security2:error] [pid 1012520:tid 1012748] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/api/staging/.env"] [unique_id "aqxaowpXMN3p_zkwXf3KlQAAAOY"]
[Thu Sep 17 15:24:51.330263 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/vendor/.env"] [unique_id "aqxaowpXMN3p_zkwXf3KngAAAJE"]
[Thu Sep 17 15:24:51.400654 2026] [security2:error] [pid 1012520:tid 1012769] [client 140.238.42.111:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaowpXMN3p_zkwXf3KoAAAAPs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:51.428287 2026] [security2:error] [pid 1012520:tid 1012723] [client 3.82.141.143:3794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "kwolitee.com"] [uri "/wp-config.php~"] [unique_id "aqxaowpXMN3p_zkwXf3KoQAAAM0"]
[Thu Sep 17 15:24:51.447381 2026] [security2:error] [pid 1012520:tid 1012707] [client 3.82.141.143:3864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "kwolitee.com"] [uri "/wp-config.php.bak"] [unique_id "aqxaowpXMN3p_zkwXf3KowAAAL0"]
[Thu Sep 17 15:24:51.449338 2026] [security2:error] [pid 1012520:tid 1012715] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaowpXMN3p_zkwXf3KnwAAAMU"]
[Thu Sep 17 15:24:51.468948 2026] [security2:error] [pid 1012520:tid 1012686] [client 3.82.141.143:3694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/web.config"] [unique_id "aqxaowpXMN3p_zkwXf3KpwAAAKg"]
[Thu Sep 17 15:24:51.469619 2026] [security2:error] [pid 1012520:tid 1012772] [client 3.82.141.143:3618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.bak"] [unique_id "aqxaowpXMN3p_zkwXf3KqAAAAP4"]
[Thu Sep 17 15:24:51.478515 2026] [security2:error] [pid 1012520:tid 1012693] [client 3.82.141.143:3562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env"] [unique_id "aqxaowpXMN3p_zkwXf3KrQAAAK8"]
[Thu Sep 17 15:24:51.481519 2026] [security2:error] [pid 1012520:tid 1012684] [client 3.82.141.143:3614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.old"] [unique_id "aqxaowpXMN3p_zkwXf3KrgAAAKY"]
[Thu Sep 17 15:24:51.485451 2026] [security2:error] [pid 1012520:tid 1012754] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/lib/.env"] [unique_id "aqxaowpXMN3p_zkwXf3KtQAAAOw"]
[Thu Sep 17 15:24:51.491237 2026] [security2:error] [pid 1012520:tid 1012708] [client 3.82.141.143:3872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "kwolitee.com"] [uri "/wp-config.php.save"] [unique_id "aqxaowpXMN3p_zkwXf3KvAAAAL4"]
[Thu Sep 17 15:24:51.496299 2026] [security2:error] [pid 1012520:tid 1012758] [client 3.82.141.143:3880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kwolitee.com"] [uri "/.env.backup"] [unique_id "aqxaowpXMN3p_zkwXf3KwQAAAPA"]
[Thu Sep 17 15:24:51.499457 2026] [security2:error] [pid 1012520:tid 1012692] [client 3.82.141.143:3684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/config.php"] [unique_id "aqxaowpXMN3p_zkwXf3KxgAAAK4"]
[Thu Sep 17 15:24:51.506503 2026] [security2:error] [pid 1012520:tid 1012718] [client 3.82.141.143:3738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "kwolitee.com"] [uri "/wp-config.php.old"] [unique_id "aqxaowpXMN3p_zkwXf3KygAAAMg"]
[Thu Sep 17 15:24:51.511523 2026] [security2:error] [pid 1012520:tid 1012746] [client 3.82.141.143:3860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kwolitee.com"] [uri "/wp-config.php"] [unique_id "aqxaowpXMN3p_zkwXf3KzAAAAOQ"]
[Thu Sep 17 15:24:51.555069 2026] [security2:error] [pid 1012520:tid 1012709] [client 3.82.141.143:3562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kwolitee.com"] [uri "/index.php"] [unique_id "aqxaowpXMN3p_zkwXf3K0QAAAL8"]
[Thu Sep 17 15:24:51.593646 2026] [security2:error] [pid 1012520:tid 1012765] [client 193.36.224.146:20881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/lufix.php"] [unique_id "aqxaowpXMN3p_zkwXf3K1QAAAPc"]
[Thu Sep 17 15:24:51.644482 2026] [security2:error] [pid 1012520:tid 1012679] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/resources/.env"] [unique_id "aqxaowpXMN3p_zkwXf3K1wAAAKE"]
[Thu Sep 17 15:24:51.646885 2026] [security2:error] [pid 1012520:tid 1012657] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaowpXMN3p_zkwXf3KzwAAAIs"]
[Thu Sep 17 15:24:51.791902 2026] [security2:error] [pid 1012520:tid 1012769] [client 140.238.42.111:63326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaowpXMN3p_zkwXf3K3gAAAPs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:51.800699 2026] [security2:error] [pid 1012520:tid 1012715] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/assets/.env"] [unique_id "aqxaowpXMN3p_zkwXf3K4AAAAMU"]
[Thu Sep 17 15:24:51.834485 2026] [security2:error] [pid 1012520:tid 1012732] [client 104.207.33.33:39657] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxaowpXMN3p_zkwXf3K4wAAANY"]
[Thu Sep 17 15:24:51.841792 2026] [security2:error] [pid 1012520:tid 1012738] [client 216.24.219.38:32641] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/txets.php"] [unique_id "aqxaowpXMN3p_zkwXf3K5AAAANw"]
[Thu Sep 17 15:24:51.919210 2026] [security2:error] [pid 1012520:tid 1012720] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxaowpXMN3p_zkwXf3K4QAAAMo"]
[Thu Sep 17 15:24:51.962169 2026] [security2:error] [pid 1012520:tid 1012662] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/uploads/.env"] [unique_id "aqxaowpXMN3p_zkwXf3K5QAAAJA"]
[Thu Sep 17 15:24:52.142913 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/internal/.env"] [unique_id "aqxapApXMN3p_zkwXf3K7gAAAIU"]
[Thu Sep 17 15:24:52.149432 2026] [security2:error] [pid 1012520:tid 1012668] [client 104.234.19.146:40707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxapApXMN3p_zkwXf3K7wAAAJY"]
[Thu Sep 17 15:24:52.173633 2026] [security2:error] [pid 1012520:tid 1012687] [client 140.238.42.111:63668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxapApXMN3p_zkwXf3K8QAAAKk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:52.223602 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.231.55.47:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxapApXMN3p_zkwXf3K7AAAALQ"]
[Thu Sep 17 15:24:52.297373 2026] [security2:error] [pid 1012520:tid 1012691] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/tools/.env"] [unique_id "aqxapApXMN3p_zkwXf3K8wAAAK0"]
[Thu Sep 17 15:24:52.345312 2026] [security2:error] [pid 1012520:tid 1012730] [client 104.248.203.175:50998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.counselingforchange.net"] [uri "/index.php"] [unique_id "aqxaogpXMN3p_zkwXf3KegAA1FE"], referer: http://mail.counselingforchange.net/wordpress/
[Thu Sep 17 15:24:52.451253 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/scripts/.env"] [unique_id "aqxapApXMN3p_zkwXf3K9wAAAJ8"]
[Thu Sep 17 15:24:52.455634 2026] [security2:error] [pid 1012520:tid 1012665] [client 169.58.197.253:51977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxapApXMN3p_zkwXf3K-AAAAJM"], referer: binance.com
[Thu Sep 17 15:24:52.564284 2026] [security2:error] [pid 1012520:tid 1012734] [client 140.238.42.111:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxapApXMN3p_zkwXf3K_AAAANg"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:52.621507 2026] [security2:error] [pid 1012520:tid 1012728] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/bin/.env"] [unique_id "aqxapApXMN3p_zkwXf3K_QAAANI"]
[Thu Sep 17 15:24:52.729267 2026] [security2:error] [pid 1012520:tid 1012727] [client 114.198.138.124:53935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxapApXMN3p_zkwXf3LBgAAANE"]
[Thu Sep 17 15:24:52.729377 2026] [security2:error] [pid 1012520:tid 1012727] [client 114.198.138.124:53935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxapApXMN3p_zkwXf3LBgAAANE"]
[Thu Sep 17 15:24:52.737041 2026] [security2:error] [pid 1012520:tid 1012749] [client 104.248.203.175:50998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.counselingforchange.net"] [uri "/index.php"] [unique_id "aqxapApXMN3p_zkwXf3LAQAA5y0"], referer: http://mail.counselingforchange.net/old/
[Thu Sep 17 15:24:52.765670 2026] [security2:error] [pid 1012520:tid 1012775] [client 193.36.224.220:54427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxapApXMN3p_zkwXf3LBwAAAQE"]
[Thu Sep 17 15:24:52.781621 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/sbin/.env"] [unique_id "aqxapApXMN3p_zkwXf3LCQAAAP0"]
[Thu Sep 17 15:24:52.938682 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/local/.env"] [unique_id "aqxapApXMN3p_zkwXf3LDQAAALs"]
[Thu Sep 17 15:24:52.959995 2026] [security2:error] [pid 1012520:tid 1012774] [client 140.238.42.111:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxapApXMN3p_zkwXf3LEAAAAQA"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:53.094265 2026] [security2:error] [pid 1012520:tid 1012766] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/portal/.env"] [unique_id "aqxapQpXMN3p_zkwXf3LEgAAAPg"]
[Thu Sep 17 15:24:53.258333 2026] [security2:error] [pid 1012520:tid 1012659] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/dashboard/.env"] [unique_id "aqxapQpXMN3p_zkwXf3LGgAAAI0"]
[Thu Sep 17 15:24:53.289098 2026] [security2:error] [pid 1012520:tid 1012701] [client 216.24.219.100:59191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxapQpXMN3p_zkwXf3LGwAAALc"]
[Thu Sep 17 15:24:53.312066 2026] [security2:error] [pid 1012520:tid 1012679] [client 177.212.79.87:55310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxapQpXMN3p_zkwXf3LFQAAoUM"]
[Thu Sep 17 15:24:53.368810 2026] [security2:error] [pid 1012520:tid 1012723] [client 140.238.42.111:64653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxapQpXMN3p_zkwXf3LHAAAAM0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:53.418292 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/panel/.env"] [unique_id "aqxapQpXMN3p_zkwXf3LHQAAANY"]
[Thu Sep 17 15:24:53.428266 2026] [security2:error] [pid 1012520:tid 1012757] [client 156.192.234.52:62111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxapQpXMN3p_zkwXf3LHgAAAO8"]
[Thu Sep 17 15:24:53.431149 2026] [security2:error] [pid 1012520:tid 1012757] [client 156.192.234.52:62111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxapQpXMN3p_zkwXf3LHgAAAO8"]
[Thu Sep 17 15:24:53.574638 2026] [security2:error] [pid 1012520:tid 1012702] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/crm/.env"] [unique_id "aqxapQpXMN3p_zkwXf3LIQAAALg"]
[Thu Sep 17 15:24:53.733939 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/erp/.env"] [unique_id "aqxapQpXMN3p_zkwXf3LJgAAALo"]
[Thu Sep 17 15:24:53.774919 2026] [security2:error] [pid 1012520:tid 1012673] [client 140.238.42.111:64971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxapQpXMN3p_zkwXf3LKAAAAJs"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:53.799312 2026] [security2:error] [pid 1012520:tid 1012707] [client 104.234.19.143:39825] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/goods.php"] [unique_id "aqxapQpXMN3p_zkwXf3LKQAAAL0"]
[Thu Sep 17 15:24:53.895150 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/shop/.env"] [unique_id "aqxapQpXMN3p_zkwXf3LKwAAAJQ"]
[Thu Sep 17 15:24:54.061341 2026] [security2:error] [pid 1012520:tid 1012687] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/store/.env"] [unique_id "aqxapgpXMN3p_zkwXf3LLwAAAKk"]
[Thu Sep 17 15:24:54.113338 2026] [security2:error] [pid 1012520:tid 1012651] [client 104.248.203.175:50998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.counselingforchange.net"] [uri "/index.php"] [unique_id "aqxapgpXMN3p_zkwXf3LLgAAhUU"], referer: http://mail.counselingforchange.net/blog/
[Thu Sep 17 15:24:54.165481 2026] [security2:error] [pid 1012520:tid 1012668] [client 140.238.42.111:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxapgpXMN3p_zkwXf3LMwAAAJY"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:54.216400 2026] [security2:error] [pid 1012520:tid 1012667] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/saas/.env"] [unique_id "aqxapgpXMN3p_zkwXf3LNAAAAJU"]
[Thu Sep 17 15:24:54.221880 2026] [security2:error] [pid 1012520:tid 1012653] [client 193.36.224.220:48383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kolind.com"] [uri "/php8.php"] [unique_id "aqxapgpXMN3p_zkwXf3LNQAAAIc"]
[Thu Sep 17 15:24:54.379432 2026] [security2:error] [pid 1012520:tid 1012753] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/client/.env"] [unique_id "aqxapgpXMN3p_zkwXf3LOAAAAOs"]
[Thu Sep 17 15:24:54.505258 2026] [security2:error] [pid 1012520:tid 1012665] [client 104.248.203.175:50998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.counselingforchange.net"] [uri "/index.php"] [unique_id "aqxapgpXMN3p_zkwXf3LOgAAkx8"], referer: http://mail.counselingforchange.net/backup/
[Thu Sep 17 15:24:54.540702 2026] [security2:error] [pid 1012520:tid 1012711] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/project/.env"] [unique_id "aqxapgpXMN3p_zkwXf3LOwAAAME"]
[Thu Sep 17 15:24:54.545812 2026] [security2:error] [pid 1012520:tid 1012677] [client 185.55.149.49:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxapgpXMN3p_zkwXf3LPAAAAJ8"]
[Thu Sep 17 15:24:54.545907 2026] [security2:error] [pid 1012520:tid 1012677] [client 185.55.149.49:55347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxapgpXMN3p_zkwXf3LPAAAAJ8"]
[Thu Sep 17 15:24:54.558144 2026] [security2:error] [pid 1012520:tid 1012695] [client 140.238.42.111:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxapgpXMN3p_zkwXf3LPQAAALE"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:54.699575 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/admin-panel/.env"] [unique_id "aqxapgpXMN3p_zkwXf3LRAAAAOk"]
[Thu Sep 17 15:24:54.864825 2026] [security2:error] [pid 1012520:tid 1012775] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/control-panel/.env"] [unique_id "aqxapgpXMN3p_zkwXf3LRwAAAQE"]
[Thu Sep 17 15:24:54.885959 2026] [security2:error] [pid 1012520:tid 1012756] [client 104.248.203.175:50998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.counselingforchange.net"] [uri "/index.php"] [unique_id "aqxapgpXMN3p_zkwXf3LRgAA7ik"], referer: http://mail.counselingforchange.net/wp/
[Thu Sep 17 15:24:54.945623 2026] [security2:error] [pid 1012520:tid 1012749] [client 140.238.42.111:49618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxapgpXMN3p_zkwXf3LSQAAAOc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:55.021438 2026] [security2:error] [pid 1012520:tid 1012725] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/user-panel/.env"] [unique_id "aqxapwpXMN3p_zkwXf3LSgAAAM8"]
[Thu Sep 17 15:24:55.206139 2026] [security2:error] [pid 1012520:tid 1012755] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/node/.env"] [unique_id "aqxapwpXMN3p_zkwXf3LUgAAAO0"]
[Thu Sep 17 15:24:55.248549 2026] [security2:error] [pid 1012520:tid 1012729] [client 8.231.55.47:57362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxapwpXMN3p_zkwXf3LVAAAANM"]
[Thu Sep 17 15:24:55.268168 2026] [security2:error] [pid 1012520:tid 1012709] [client 104.248.203.175:50998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.counselingforchange.net"] [uri "/index.php"] [unique_id "aqxapwpXMN3p_zkwXf3LUAAAv1Y"], referer: http://mail.counselingforchange.net/new/
[Thu Sep 17 15:24:55.336527 2026] [security2:error] [pid 1012520:tid 1012658] [client 140.238.42.111:49985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxapwpXMN3p_zkwXf3LVwAAAIw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:55.390084 2026] [security2:error] [pid 1012520:tid 1012714] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/express/.env"] [unique_id "aqxapwpXMN3p_zkwXf3LWQAAAMQ"]
[Thu Sep 17 15:24:55.450962 2026] [security2:error] [pid 1012520:tid 1012748] [client 103.42.202.228:48138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxapwpXMN3p_zkwXf3LVQAA5nQ"]
[Thu Sep 17 15:24:55.549395 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/next/.env"] [unique_id "aqxapwpXMN3p_zkwXf3LWgAAAOM"]
[Thu Sep 17 15:24:55.567244 2026] [security2:error] [pid 1012520:tid 1012679] [client 8.231.55.47:57362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/.env~"] [unique_id "aqxapwpXMN3p_zkwXf3LXAAAAKE"]
[Thu Sep 17 15:24:55.711564 2026] [security2:error] [pid 1012520:tid 1012767] [client 3.82.141.143:3932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bejackson.com"] [uri "/index.php"] [unique_id "aqxapwpXMN3p_zkwXf3LWwAAAPk"]
[Thu Sep 17 15:24:55.726259 2026] [security2:error] [pid 1012520:tid 1012675] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/nuxt/.env"] [unique_id "aqxapwpXMN3p_zkwXf3LYwAAAJ0"]
[Thu Sep 17 15:24:55.735686 2026] [security2:error] [pid 1012520:tid 1012723] [client 140.238.42.111:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxapwpXMN3p_zkwXf3LZQAAAM0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:55.881646 2026] [security2:error] [pid 1012520:tid 1012704] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/nest/.env"] [unique_id "aqxapwpXMN3p_zkwXf3LcAAAALo"]
[Thu Sep 17 15:24:56.056812 2026] [security2:error] [pid 1012520:tid 1012724] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/react/.env"] [unique_id "aqxaqApXMN3p_zkwXf3LdgAAAM4"]
[Thu Sep 17 15:24:56.152862 2026] [security2:error] [pid 1012520:tid 1012669] [client 140.238.42.111:50721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaqApXMN3p_zkwXf3LgAAAAJc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:56.253738 2026] [security2:error] [pid 1012520:tid 1012692] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/vue/.env"] [unique_id "aqxaqApXMN3p_zkwXf3LhAAAAK4"]
[Thu Sep 17 15:24:56.410588 2026] [security2:error] [pid 1012520:tid 1012730] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/angular/.env"] [unique_id "aqxaqApXMN3p_zkwXf3LhwAAANQ"]
[Thu Sep 17 15:24:56.535040 2026] [security2:error] [pid 1012520:tid 1012665] [client 140.238.42.111:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaqApXMN3p_zkwXf3LigAAAJM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:56.570252 2026] [security2:error] [pid 1012520:tid 1012771] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/svelte/.env"] [unique_id "aqxaqApXMN3p_zkwXf3LiwAAAP0"]
[Thu Sep 17 15:24:56.730567 2026] [security2:error] [pid 1012520:tid 1012709] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/vite/.env"] [unique_id "aqxaqApXMN3p_zkwXf3LlAAAAL8"]
[Thu Sep 17 15:24:56.897128 2026] [security2:error] [pid 1012520:tid 1012752] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/backup/.env"] [unique_id "aqxaqApXMN3p_zkwXf3LmQAAAOo"]
[Thu Sep 17 15:24:56.918405 2026] [security2:error] [pid 1012520:tid 1012658] [client 140.238.42.111:51418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaqApXMN3p_zkwXf3LmgAAAIw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:57.068256 2026] [security2:error] [pid 1012520:tid 1012745] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/backups/.env"] [unique_id "aqxaqQpXMN3p_zkwXf3LngAAAOM"]
[Thu Sep 17 15:24:57.232161 2026] [security2:error] [pid 1012520:tid 1012732] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/old/.env"] [unique_id "aqxaqQpXMN3p_zkwXf3LpgAAANY"]
[Thu Sep 17 15:24:57.311246 2026] [security2:error] [pid 1012520:tid 1012701] [client 140.238.42.111:51719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LqAAAALc"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:57.390915 2026] [security2:error] [pid 1012520:tid 1012738] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/tmp/.env"] [unique_id "aqxaqQpXMN3p_zkwXf3LqgAAANw"]
[Thu Sep 17 15:24:57.572885 2026] [security2:error] [pid 1012520:tid 1012772] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/temp/.env"] [unique_id "aqxaqQpXMN3p_zkwXf3LrgAAAP4"]
[Thu Sep 17 15:24:57.696783 2026] [security2:error] [pid 1012520:tid 1012704] [client 140.238.42.111:52043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LtgAAALo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:57.723049 2026] [security2:error] [pid 1012520:tid 1012759] [client 186.105.232.15:61661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.232.105.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LsAAAAPE"]
[Thu Sep 17 15:24:57.723209 2026] [security2:error] [pid 1012520:tid 1012759] [client 186.105.232.15:61661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LsAAAAPE"]
[Thu Sep 17 15:24:57.737485 2026] [security2:error] [pid 1012520:tid 1012666] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/lab/.env"] [unique_id "aqxaqQpXMN3p_zkwXf3LuwAAAJQ"]
[Thu Sep 17 15:24:57.899312 2026] [security2:error] [pid 1012520:tid 1012684] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cronlab/.env"] [unique_id "aqxaqQpXMN3p_zkwXf3LvwAAAKY"]
[Thu Sep 17 15:24:57.929377 2026] [security2:error] [pid 1012520:tid 1012768] [client 103.61.184.148:58230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LwwAAAPo"]
[Thu Sep 17 15:24:57.929514 2026] [security2:error] [pid 1012520:tid 1012768] [client 103.61.184.148:58230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LwwAAAPo"]
[Thu Sep 17 15:24:57.932118 2026] [security2:error] [pid 1012520:tid 1012702] [client 104.234.53.13:52787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LvQAAALg"]
[Thu Sep 17 15:24:58.060421 2026] [security2:error] [pid 1012520:tid 1012677] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cron/.env"] [unique_id "aqxaqgpXMN3p_zkwXf3LxgAAAJ8"]
[Thu Sep 17 15:24:58.081784 2026] [security2:error] [pid 1012520:tid 1012693] [client 140.238.42.111:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaqgpXMN3p_zkwXf3LxwAAAK8"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:58.136850 2026] [security2:error] [pid 1012520:tid 1012724] [client 210.222.43.21:57477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxaqQpXMN3p_zkwXf3LxQAAAM4"], referer: http://talent-in-borders.com/BACKUP
[Thu Sep 17 15:24:58.230691 2026] [security2:error] [pid 1012520:tid 1012676] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/en/.env"] [unique_id "aqxaqgpXMN3p_zkwXf3LzQAAAJ4"]
[Thu Sep 17 15:24:58.463118 2026] [security2:error] [pid 1012520:tid 1012665] [client 140.238.42.111:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaqgpXMN3p_zkwXf3L1wAAAJM"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:58.563093 2026] [security2:error] [pid 1012520:tid 1012651] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/administrator/.env"] [unique_id "aqxaqgpXMN3p_zkwXf3L1QAAAIU"]
[Thu Sep 17 15:24:58.733938 2026] [security2:error] [pid 1012520:tid 1012681] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/psnlink/.env"] [unique_id "aqxaqgpXMN3p_zkwXf3L3gAAAKM"]
[Thu Sep 17 15:24:58.783385 2026] [security2:error] [pid 1012520:tid 1012746] [client 8.231.55.47:57402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxaqgpXMN3p_zkwXf3L3wAAAOQ"]
[Thu Sep 17 15:24:58.843188 2026] [security2:error] [pid 1012520:tid 1012658] [client 140.238.42.111:52916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaqgpXMN3p_zkwXf3L4AAAAIw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:58.875052 2026] [security2:error] [pid 1012520:tid 1012678] [client 8.231.55.47:57402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxaqgpXMN3p_zkwXf3L4QAAAKA"]
[Thu Sep 17 15:24:58.920561 2026] [security2:error] [pid 1012520:tid 1012663] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/exapi/.env"] [unique_id "aqxaqgpXMN3p_zkwXf3L4wAAAJE"]
[Thu Sep 17 15:24:59.023044 2026] [security2:error] [pid 1012520:tid 1012729] [client 8.231.55.47:57402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxaqwpXMN3p_zkwXf3L5gAAANM"]
[Thu Sep 17 15:24:59.085841 2026] [security2:error] [pid 1012520:tid 1012774] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/sitemaps/.env"] [unique_id "aqxaqwpXMN3p_zkwXf3L5wAAAQA"]
[Thu Sep 17 15:24:59.177782 2026] [security2:error] [pid 1012520:tid 1012716] [client 8.231.55.47:57402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxaqwpXMN3p_zkwXf3L6QAAAMY"]
[Thu Sep 17 15:24:59.233093 2026] [security2:error] [pid 1012520:tid 1012659] [client 140.238.42.111:53224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxaqwpXMN3p_zkwXf3L6gAAAI0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:59.277488 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.231.55.47:57402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxaqwpXMN3p_zkwXf3L7QAAAJ0"]
[Thu Sep 17 15:24:59.356916 2026] [security2:error] [pid 1012520:tid 1012705] [client 8.231.55.47:57402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxaqwpXMN3p_zkwXf3L-QAAALs"]
[Thu Sep 17 15:24:59.362137 2026] [security2:error] [pid 1012520:tid 1012747] [client 172.86.81.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.scigd.com"] [uri "/index.php"] [unique_id "aqxapwpXMN3p_zkwXf3LcwAAAOU"], referer: http://mail.scigd.com/.git/config
[Thu Sep 17 15:24:59.389286 2026] [security2:error] [pid 1012520:tid 1012671] [client 98.62.240.170:53816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaqwpXMN3p_zkwXf3L6wAAmUI"]
[Thu Sep 17 15:24:59.649139 2026] [security2:error] [pid 1012520:tid 1012708] [client 140.238.42.111:53547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxaqwpXMN3p_zkwXf3MBAAAAL4"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:24:59.727738 2026] [security2:error] [pid 1012520:tid 1012765] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/logs/.env"] [unique_id "aqxaqwpXMN3p_zkwXf3MBgAAAPc"]
[Thu Sep 17 15:24:59.888084 2026] [security2:error] [pid 1012520:tid 1012694] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cache/.env"] [unique_id "aqxaqwpXMN3p_zkwXf3MCgAAALA"]
[Thu Sep 17 15:25:00.050163 2026] [security2:error] [pid 1012520:tid 1012707] [client 140.238.42.111:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxarApXMN3p_zkwXf3MDgAAAL0"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:00.090510 2026] [security2:error] [pid 1012520:tid 1012751] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mailer/.env"] [unique_id "aqxarApXMN3p_zkwXf3MEAAAAOk"]
[Thu Sep 17 15:25:00.142823 2026] [security2:error] [pid 1012520:tid 1012693] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxarApXMN3p_zkwXf3MEgAAAK8"]
[Thu Sep 17 15:25:00.237035 2026] [security2:error] [pid 1012520:tid 1012698] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxarApXMN3p_zkwXf3MFQAAALQ"]
[Thu Sep 17 15:25:00.264297 2026] [security2:error] [pid 1012520:tid 1012665] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mail/.env"] [unique_id "aqxarApXMN3p_zkwXf3MFgAAAJM"]
[Thu Sep 17 15:25:00.349493 2026] [security2:error] [pid 1012520:tid 1012762] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxarApXMN3p_zkwXf3MGgAAAPQ"]
[Thu Sep 17 15:25:00.422386 2026] [security2:error] [pid 1012520:tid 1012713] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxarApXMN3p_zkwXf3MGwAAAMM"]
[Thu Sep 17 15:25:00.447603 2026] [security2:error] [pid 1012520:tid 1012764] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/email/.env"] [unique_id "aqxarApXMN3p_zkwXf3MHAAAAPY"]
[Thu Sep 17 15:25:00.459668 2026] [security2:error] [pid 1012520:tid 1012699] [client 140.238.42.111:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxarApXMN3p_zkwXf3MHQAAALU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:00.606109 2026] [security2:error] [pid 1012520:tid 1012746] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/smtp/.env"] [unique_id "aqxarApXMN3p_zkwXf3MHgAAAOQ"]
[Thu Sep 17 15:25:00.631197 2026] [security2:error] [pid 1012520:tid 1012658] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxarApXMN3p_zkwXf3MHwAAAIw"]
[Thu Sep 17 15:25:00.761969 2026] [security2:error] [pid 1012520:tid 1012687] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxarApXMN3p_zkwXf3MIQAAAKk"]
[Thu Sep 17 15:25:00.763915 2026] [security2:error] [pid 1012520:tid 1012709] [client 104.207.33.33:33459] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxarApXMN3p_zkwXf3MIAAAAL8"]
[Thu Sep 17 15:25:00.780355 2026] [security2:error] [pid 1012520:tid 1012657] [client 34.154.237.242:60176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mailing/.env"] [unique_id "aqxarApXMN3p_zkwXf3MIgAAAIs"]
[Thu Sep 17 15:25:00.838033 2026] [security2:error] [pid 1012520:tid 1012770] [client 140.238.42.111:54671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxarApXMN3p_zkwXf3MJgAAAPw"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:00.848056 2026] [security2:error] [pid 1012520:tid 1012728] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxarApXMN3p_zkwXf3MJwAAANI"]
[Thu Sep 17 15:25:00.976159 2026] [security2:error] [pid 1012520:tid 1012732] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxarApXMN3p_zkwXf3MLAAAANY"]
[Thu Sep 17 15:25:01.061714 2026] [security2:error] [pid 1012520:tid 1012766] [client 154.190.208.131:42048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxarQpXMN3p_zkwXf3MLgAAAPg"]
[Thu Sep 17 15:25:01.061856 2026] [security2:error] [pid 1012520:tid 1012766] [client 154.190.208.131:42048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxarQpXMN3p_zkwXf3MLgAAAPg"]
[Thu Sep 17 15:25:01.084323 2026] [security2:error] [pid 1012520:tid 1012659] [client 171.225.185.48:21073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxarApXMN3p_zkwXf3MKwAAjWw"]
[Thu Sep 17 15:25:01.090009 2026] [security2:error] [pid 1012520:tid 1012675] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MLwAAAJ0"]
[Thu Sep 17 15:25:01.170644 2026] [security2:error] [pid 1012520:tid 1012686] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MNAAAAKg"]
[Thu Sep 17 15:25:01.240501 2026] [security2:error] [pid 1012520:tid 1012767] [client 140.238.42.111:54956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxarQpXMN3p_zkwXf3MNQAAAPk"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:01.271509 2026] [security2:error] [pid 1012520:tid 1012740] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MNgAAAN4"]
[Thu Sep 17 15:25:01.273166 2026] [security2:error] [pid 1012520:tid 1012666] [client 169.58.197.253:52487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxarQpXMN3p_zkwXf3MNwAAAJQ"], referer: binance.com
[Thu Sep 17 15:25:01.313583 2026] [security2:error] [pid 1012520:tid 1012705] [client 34.154.237.242:49556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/notifications/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MOgAAALs"]
[Thu Sep 17 15:25:01.410252 2026] [security2:error] [pid 1012520:tid 1012701] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MPgAAALc"]
[Thu Sep 17 15:25:01.486076 2026] [security2:error] [pid 1012520:tid 1012720] [client 34.154.237.242:49556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/notify/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MQQAAAMo"]
[Thu Sep 17 15:25:01.540652 2026] [security2:error] [pid 1012520:tid 1012672] [client 8.231.55.47:57406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MQwAAAJo"]
[Thu Sep 17 15:25:01.632390 2026] [security2:error] [pid 1012520:tid 1012715] [client 140.238.42.111:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxarQpXMN3p_zkwXf3MRgAAAMU"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:01.648985 2026] [security2:error] [pid 1012520:tid 1012685] [client 34.154.237.242:49556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/sender/.env"] [unique_id "aqxarQpXMN3p_zkwXf3MRwAAAKc"]
[Thu Sep 17 15:25:01.776195 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00493: SIGUSR1 received.  Doing graceful restart
[Thu Sep 17 15:25:02.925603 2026] [:notice] [pid 971056:tid 971056] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 971056 stopped
[Thu Sep 17 15:25:03.738476 2026] [security2:error] [pid 1012520:tid 1012695] [client 34.31.203.120:38016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxaqgpXMN3p_zkwXf3LywAAsVM"]
[Thu Sep 17 15:25:05.519521 2026] [lsapi:notice] [pid 907280:tid 907280] mod_lsapi:  version 1.1-92
[Thu Sep 17 15:25:05.524984 2026] [:notice] [pid 1029610:tid 1029610] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 1029610 started
[Thu Sep 17 15:25:05.597930 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tylerblantonmusic.tylerblanton.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.607446 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: deraiz-mx.xavierlopezmiranda.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.644242 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ahmedteleb.tasameem-eg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.647266 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fst-i.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.648047 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fstsprinkler.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.653701 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: southislandpie.southislandpie.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.671591 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardashphotography.reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.688665 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcp-u.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.689759 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.691387 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reedcustomprinting.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.692270 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpphotorestoration.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.692967 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpmobileartscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.694545 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rjglobalhq.com.rebeccamerzius.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.743774 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mermco.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.744448 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ad1homes.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.745356 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-7b36017a.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.750742 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-3f11e808.livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.780085 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: api.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.780876 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: admin.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.809699 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: hamzaabdulhaq.gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.836126 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: site.tengushee.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.881739 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ayfertbarak.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.882657 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: becorenovation.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.883505 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: agent-immobilier.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.889099 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sqlerudition.commutervibe.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.893560 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bothe-net.cyber21.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.916562 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: troopkcampcadet.campcadetmontco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.920868 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vedur-app.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.921860 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: weather-is.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.922807 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tengja-net.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.923645 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bookin-city.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.924810 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-c557c2bf.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.926081 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-1a493541.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.927549 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitlinwhittington.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.928376 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jarrodandcaitlin-us.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:05.968143 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b2133dcc.idautovic.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.006981 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wellfedhealth.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.008647 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wear-out.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.014775 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vogito-inno.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.041497 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: thegoatmentality.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.058912 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.077301 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rpimanufacturing.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.078497 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rosebar.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.085596 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: revelinfear.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.087971 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.103806 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pazcreativehomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.107085 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pagepress.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.120497 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nikistepanianmft.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.123281 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nexgenimplant.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.137330 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mengesphotos.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.139609 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mdlzbenefits.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.143537 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: macmanagement.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.151894 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: lifepointechurchga.org:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.163811 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.168887 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kbmautomation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.175930 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jminner.photo:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.182762 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: janetaylor.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.184477 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.212782 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.235920 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ffwdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.237414 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: evansilver.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.240202 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ericbabin.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.246394 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ellenhirshberg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.269636 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: comfortspecialist.info:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.282681 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: biggselectrical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.285527 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.287409 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.289328 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bvpowersports.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.290479 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buliblog.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.291708 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buildingpro.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.296638 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bodylanguageohio.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.328002 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: afbaco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.329952 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: abelardpsychotherapy.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.443724 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b0f84876.robertsinteractive.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.451319 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tracertgame-com.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.452348 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-f2c0397e.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.454885 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-19b382b5.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.519765 2026] [log_config:warn] [pid 1012520:tid 1012690] (32)Broken pipe: [client 66.249.66.206:54943] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log
[Thu Sep 17 15:25:06.519785 2026] [log_config:warn] [pid 1012520:tid 1012690] (32)Broken pipe: [client 66.249.66.206:54943] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log
[Thu Sep 17 15:25:06.527517 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: marinabelous.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.549027 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: houlaentertainment.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.588925 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:25:06.606115 2026] [qos:notice] [pid 907280:tid 907280] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Sep 17 15:25:06.868140 2026] [http2:info] [pid 907280:tid 907280] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Thu Sep 17 15:25:06.873142 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Sep 17 15:25:06.873158 2026] [core:notice] [pid 907280:tid 907280] AH00094: Command line: '/usr/sbin/httpd'
[Thu Sep 17 15:25:07.927270 2026] [http2:info] [pid 1029697:tid 1029697] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:25:07.946958 2026] [security2:error] [pid 1029697:tid 1029835] [client 134.185.85.61:56960] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "recaonline.org"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxas265wm-f4uX16X5upAAAAAg"]
[Thu Sep 17 15:25:07.991988 2026] [security2:error] [pid 1029697:tid 1029867] [client 192.178.6.4:64212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxas265wm-f4uX16X5uswAAACg"]
[Thu Sep 17 15:25:08.059366 2026] [security2:error] [pid 1029697:tid 1029856] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxatG65wm-f4uX16X5uygAAAB0"]
[Thu Sep 17 15:25:08.079970 2026] [security2:error] [pid 1029697:tid 1029837] [client 140.238.42.111:55613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxatG65wm-f4uX16X5uzAAAAAo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:08.121173 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/sendgrid/.env"] [unique_id "aqxatG65wm-f4uX16X5uzwAAAC4"]
[Thu Sep 17 15:25:08.152337 2026] [security2:error] [pid 1029697:tid 1029847] [client 114.198.138.124:54598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxatG65wm-f4uX16X5u0AAAABQ"]
[Thu Sep 17 15:25:08.152519 2026] [security2:error] [pid 1029697:tid 1029847] [client 114.198.138.124:54598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxatG65wm-f4uX16X5u0AAAABQ"]
[Thu Sep 17 15:25:08.152527 2026] [security2:error] [pid 1029697:tid 1029865] [client 185.55.149.49:56098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxatG65wm-f4uX16X5u0gAAACY"]
[Thu Sep 17 15:25:08.152722 2026] [security2:error] [pid 1029697:tid 1029865] [client 185.55.149.49:56098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxatG65wm-f4uX16X5u0gAAACY"]
[Thu Sep 17 15:25:08.210766 2026] [core:error] [pid 1029697:tid 1029917] [client 172.86.81.177:46184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:08.210790 2026] [core:error] [pid 1029697:tid 1029917] [client 172.86.81.177:46184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:08.231083 2026] [security2:error] [pid 1029697:tid 1029859] [client 57.141.14.36:56308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxas265wm-f4uX16X5uqQAAIH8"]
[Thu Sep 17 15:25:08.237330 2026] [log_config:warn] [pid 1012520:tid 1012724] (32)Broken pipe: [client 66.249.66.74:35116] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log
[Thu Sep 17 15:25:08.237354 2026] [log_config:warn] [pid 1012520:tid 1012724] (32)Broken pipe: [client 66.249.66.74:35116] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log
[Thu Sep 17 15:25:08.249240 2026] [security2:error] [pid 1029697:tid 1029887] [client 104.207.33.33:36197] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxatG65wm-f4uX16X5u3wAAADw"]
[Thu Sep 17 15:25:08.281321 2026] [security2:error] [pid 1029697:tid 1029936] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxatG65wm-f4uX16X5u4gAAAG0"]
[Thu Sep 17 15:25:08.281318 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/sparkpost/.env"] [unique_id "aqxatG65wm-f4uX16X5u4QAAAGw"]
[Thu Sep 17 15:25:08.303311 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.31.203.120:38017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxas265wm-f4uX16X5usQAAOwQ"]
[Thu Sep 17 15:25:08.348243 2026] [security2:error] [pid 1029697:tid 1029951] [client 134.185.85.61:56383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "recaonline.org"] [uri "/media/system/js/core.js"] [unique_id "aqxatG65wm-f4uX16X5u6AAAAHw"]
[Thu Sep 17 15:25:08.405634 2026] [security2:error] [pid 1029697:tid 1029855] [client 156.192.234.52:62743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxatG65wm-f4uX16X5u5wAAABw"]
[Thu Sep 17 15:25:08.405872 2026] [security2:error] [pid 1029697:tid 1029855] [client 156.192.234.52:62743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxatG65wm-f4uX16X5u5wAAABw"]
[Thu Sep 17 15:25:08.442436 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/postmark/.env"] [unique_id "aqxatG65wm-f4uX16X5u8AAAACI"]
[Thu Sep 17 15:25:08.472732 2026] [security2:error] [pid 1029697:tid 1029949] [client 140.238.42.111:60604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxatG65wm-f4uX16X5u8QAAAHo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:08.503931 2026] [security2:error] [pid 1029697:tid 1029941] [client 43.173.180.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxatG65wm-f4uX16X5u4wAAAHI"]
[Thu Sep 17 15:25:08.505320 2026] [security2:error] [pid 1029697:tid 1029940] [client 43.172.196.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxatG65wm-f4uX16X5u5AAAAHE"]
[Thu Sep 17 15:25:08.509063 2026] [security2:error] [pid 1029697:tid 1029945] [client 43.173.181.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxatG65wm-f4uX16X5u5gAAAHY"]
[Thu Sep 17 15:25:08.564257 2026] [security2:error] [pid 1029697:tid 1029906] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxatG65wm-f4uX16X5u-AAAAE8"]
[Thu Sep 17 15:25:08.598066 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mailgun/.env"] [unique_id "aqxatG65wm-f4uX16X5u-wAAABQ"]
[Thu Sep 17 15:25:08.713747 2026] [security2:error] [pid 1029697:tid 1029879] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxatG65wm-f4uX16X5vBAAAADQ"]
[Thu Sep 17 15:25:08.738519 2026] [security2:error] [pid 1029697:tid 1029850] [client 178.226.218.187:44534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxatG65wm-f4uX16X5u9wAAFxE"]
[Thu Sep 17 15:25:08.770420 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mandrill/.env"] [unique_id "aqxatG65wm-f4uX16X5vBwAAACA"]
[Thu Sep 17 15:25:08.850154 2026] [security2:error] [pid 1029697:tid 1029917] [client 140.238.42.111:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-login.php"] [unique_id "aqxatG65wm-f4uX16X5vCwAAAFo"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:08.856387 2026] [security2:error] [pid 1029697:tid 1029870] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxatG65wm-f4uX16X5vDAAAACs"]
[Thu Sep 17 15:25:08.935848 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mailjet/.env"] [unique_id "aqxatG65wm-f4uX16X5vEQAAAFc"]
[Thu Sep 17 15:25:09.088599 2026] [security2:error] [pid 1029697:tid 1029910] [client 152.136.23.159:53920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxatG65wm-f4uX16X5vEAAAAFM"], referer: http://www.streetwisepublicationsltd.com/croesus
[Thu Sep 17 15:25:09.097280 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/brevo/.env"] [unique_id "aqxatW65wm-f4uX16X5vGQAAADs"]
[Thu Sep 17 15:25:09.121297 2026] [security2:error] [pid 1029697:tid 1029831] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxatW65wm-f4uX16X5vGwAAAAQ"]
[Thu Sep 17 15:25:09.252016 2026] [security2:error] [pid 1029697:tid 1029943] [client 140.238.42.111:61245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.42.238.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniquespeechtechniques.com"] [uri "/wp-admin/index.php"] [unique_id "aqxatW65wm-f4uX16X5vIgAAAHQ"], referer: https://uniquespeechtechniques.com/wp-login.php
[Thu Sep 17 15:25:09.252366 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/transactional/.env"] [unique_id "aqxatW65wm-f4uX16X5vIwAAAH8"]
[Thu Sep 17 15:25:09.294579 2026] [security2:error] [pid 1029697:tid 1029951] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxatW65wm-f4uX16X5vKQAAAHw"]
[Thu Sep 17 15:25:09.438452 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/bulk/.env"] [unique_id "aqxatW65wm-f4uX16X5vLwAAAAY"]
[Thu Sep 17 15:25:09.464469 2026] [security2:error] [pid 1029697:tid 1029871] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxatW65wm-f4uX16X5vMAAAACw"]
[Thu Sep 17 15:25:09.572442 2026] [security2:error] [pid 1029697:tid 1029836] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxatW65wm-f4uX16X5vNQAAAAk"]
[Thu Sep 17 15:25:09.615398 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/aws/.env"] [unique_id "aqxatW65wm-f4uX16X5vNwAAAA0"]
[Thu Sep 17 15:25:09.705892 2026] [security2:error] [pid 1029697:tid 1029918] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxatW65wm-f4uX16X5vPAAAAFs"]
[Thu Sep 17 15:25:09.788215 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/azure/.env"] [unique_id "aqxatW65wm-f4uX16X5vPgAAAEo"]
[Thu Sep 17 15:25:09.823246 2026] [security2:error] [pid 1029697:tid 1029827] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxatW65wm-f4uX16X5vQAAAAAA"]
[Thu Sep 17 15:25:09.896568 2026] [security2:error] [pid 1029697:tid 1029864] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxatW65wm-f4uX16X5vQgAAACU"]
[Thu Sep 17 15:25:09.958327 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/gcp/.env"] [unique_id "aqxatW65wm-f4uX16X5vRAAAABQ"]
[Thu Sep 17 15:25:10.086818 2026] [security2:error] [pid 1029697:tid 1029920] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxatm65wm-f4uX16X5vRwAAAF0"]
[Thu Sep 17 15:25:10.118638 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cloud/.env"] [unique_id "aqxatm65wm-f4uX16X5vSwAAACA"]
[Thu Sep 17 15:25:10.184945 2026] [security2:error] [pid 1029697:tid 1029925] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxatm65wm-f4uX16X5vUAAAAGI"]
[Thu Sep 17 15:25:10.280901 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/infrastructure/.env"] [unique_id "aqxatm65wm-f4uX16X5vUgAAACc"]
[Thu Sep 17 15:25:10.302952 2026] [security2:error] [pid 1029697:tid 1029892] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxatm65wm-f4uX16X5vUwAAAEE"]
[Thu Sep 17 15:25:10.389651 2026] [security2:error] [pid 1029697:tid 1029870] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxatm65wm-f4uX16X5vVwAAACs"]
[Thu Sep 17 15:25:10.450547 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/docker/.env"] [unique_id "aqxatm65wm-f4uX16X5vWQAAAAU"]
[Thu Sep 17 15:25:10.467383 2026] [security2:error] [pid 1029697:tid 1029856] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxatm65wm-f4uX16X5vWgAAAB0"]
[Thu Sep 17 15:25:10.549524 2026] [security2:error] [pid 1029697:tid 1029933] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxatm65wm-f4uX16X5vXgAAAGo"]
[Thu Sep 17 15:25:10.616143 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/k8s/.env"] [unique_id "aqxatm65wm-f4uX16X5vYQAAADY"]
[Thu Sep 17 15:25:10.630046 2026] [security2:error] [pid 1029697:tid 1029937] [client 165.245.255.143:49822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "omegacafeportmoody.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxatm65wm-f4uX16X5vYgAAAG4"]
[Thu Sep 17 15:25:10.711561 2026] [security2:error] [pid 1029697:tid 1029886] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxatm65wm-f4uX16X5vYwAAADs"]
[Thu Sep 17 15:25:10.776473 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/kubernetes/.env"] [unique_id "aqxatm65wm-f4uX16X5vZAAAAAQ"]
[Thu Sep 17 15:25:10.835943 2026] [security2:error] [pid 1029697:tid 1029897] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxatm65wm-f4uX16X5vZQAAAEY"]
[Thu Sep 17 15:25:10.885938 2026] [security2:error] [pid 1029697:tid 1029922] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxatm65wm-f4uX16X5vZwAAAF8"]
[Thu Sep 17 15:25:10.943161 2026] [security2:error] [pid 1029697:tid 1029895] [client 165.245.255.143:49828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "omegacafeportmoody.com"] [uri "/"] [unique_id "aqxatm65wm-f4uX16X5vaQAAAEQ"]
[Thu Sep 17 15:25:10.943485 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/terraform/.env"] [unique_id "aqxatm65wm-f4uX16X5vaAAAAHg"]
[Thu Sep 17 15:25:10.965062 2026] [security2:error] [pid 1029697:tid 1029943] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxatm65wm-f4uX16X5vagAAAHQ"]
[Thu Sep 17 15:25:11.057033 2026] [security2:error] [pid 1029697:tid 1029894] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxat265wm-f4uX16X5vawAAAEM"]
[Thu Sep 17 15:25:11.100156 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/ansible/.env"] [unique_id "aqxat265wm-f4uX16X5vbwAAABA"]
[Thu Sep 17 15:25:11.176632 2026] [security2:error] [pid 1029697:tid 1029855] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxat265wm-f4uX16X5vcQAAABw"]
[Thu Sep 17 15:25:11.255538 2026] [security2:error] [pid 1029697:tid 1029841] [client 165.245.255.143:49829] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "omegacafeportmoody.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxat265wm-f4uX16X5vcwAAAA4"]
[Thu Sep 17 15:25:11.258503 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/.git/.env"] [unique_id "aqxat265wm-f4uX16X5vdAAAAB8"]
[Thu Sep 17 15:25:11.278585 2026] [security2:error] [pid 1029697:tid 1029845] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxat265wm-f4uX16X5vdQAAABI"]
[Thu Sep 17 15:25:11.425768 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/ci/.env"] [unique_id "aqxat265wm-f4uX16X5vdwAAAAk"]
[Thu Sep 17 15:25:11.435208 2026] [security2:error] [pid 1029697:tid 1029876] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxat265wm-f4uX16X5veAAAADE"]
[Thu Sep 17 15:25:11.556490 2026] [security2:error] [pid 1029697:tid 1029889] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxat265wm-f4uX16X5veQAAAD4"]
[Thu Sep 17 15:25:11.582369 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cd/.env"] [unique_id "aqxat265wm-f4uX16X5vewAAAHI"]
[Thu Sep 17 15:25:11.597576 2026] [security2:error] [pid 1029697:tid 1029949] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxat265wm-f4uX16X5vfgAAAHo"]
[Thu Sep 17 15:25:11.686188 2026] [security2:error] [pid 1029697:tid 1029919] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxat265wm-f4uX16X5vgAAAAFw"]
[Thu Sep 17 15:25:11.743295 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/jenkins/.env"] [unique_id "aqxat265wm-f4uX16X5vgQAAACk"]
[Thu Sep 17 15:25:11.791522 2026] [security2:error] [pid 1029697:tid 1029899] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxat265wm-f4uX16X5vggAAAEg"]
[Thu Sep 17 15:25:11.834976 2026] [security2:error] [pid 1029697:tid 1029905] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxat265wm-f4uX16X5vhAAAAE4"]
[Thu Sep 17 15:25:11.917525 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/gitlab/.env"] [unique_id "aqxat265wm-f4uX16X5vhQAAAHM"]
[Thu Sep 17 15:25:11.925340 2026] [security2:error] [pid 1029697:tid 1029840] [client 154.190.208.131:41366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxat265wm-f4uX16X5vhwAAAA0"]
[Thu Sep 17 15:25:11.925634 2026] [security2:error] [pid 1029697:tid 1029901] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxat265wm-f4uX16X5vhgAAAEo"]
[Thu Sep 17 15:25:11.930171 2026] [security2:error] [pid 1029697:tid 1029840] [client 154.190.208.131:41366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxat265wm-f4uX16X5vhwAAAA0"]
[Thu Sep 17 15:25:12.004740 2026] [security2:error] [pid 1029697:tid 1029902] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxauG65wm-f4uX16X5viAAAAEs"]
[Thu Sep 17 15:25:12.076995 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/github/.env"] [unique_id "aqxauG65wm-f4uX16X5vjAAAAAw"]
[Thu Sep 17 15:25:12.077499 2026] [security2:error] [pid 1029697:tid 1029884] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxauG65wm-f4uX16X5vjQAAADk"]
[Thu Sep 17 15:25:12.181769 2026] [security2:error] [pid 1029697:tid 1029837] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxauG65wm-f4uX16X5vjwAAAAo"]
[Thu Sep 17 15:25:12.235172 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/actions/.env"] [unique_id "aqxauG65wm-f4uX16X5vkAAAAAg"]
[Thu Sep 17 15:25:12.397310 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/circleci/.env"] [unique_id "aqxauG65wm-f4uX16X5vkgAAAFQ"]
[Thu Sep 17 15:25:12.416183 2026] [security2:error] [pid 1029697:tid 1029851] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxauG65wm-f4uX16X5vkwAAABg"]
[Thu Sep 17 15:25:12.558163 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/travis/.env"] [unique_id "aqxauG65wm-f4uX16X5vlQAAABs"]
[Thu Sep 17 15:25:12.645554 2026] [security2:error] [pid 1029697:tid 1029920] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxauG65wm-f4uX16X5vmAAAAF0"]
[Thu Sep 17 15:25:12.720364 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/buildkite/.env"] [unique_id "aqxauG65wm-f4uX16X5vmgAAAGI"]
[Thu Sep 17 15:25:12.732325 2026] [security2:error] [pid 1029697:tid 1029838] [client 169.58.197.253:53081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxauG65wm-f4uX16X5vmwAAAAs"], referer: binance.com
[Thu Sep 17 15:25:12.764223 2026] [security2:error] [pid 1029697:tid 1029866] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxauG65wm-f4uX16X5vnAAAACc"]
[Thu Sep 17 15:25:12.843362 2026] [security2:error] [pid 1029697:tid 1029853] [client 103.61.184.148:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxauG65wm-f4uX16X5voQAAABo"]
[Thu Sep 17 15:25:12.843561 2026] [security2:error] [pid 1029697:tid 1029853] [client 103.61.184.148:59074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxauG65wm-f4uX16X5voQAAABo"]
[Thu Sep 17 15:25:12.895360 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mysql/.env"] [unique_id "aqxauG65wm-f4uX16X5vogAAADQ"]
[Thu Sep 17 15:25:12.945276 2026] [security2:error] [pid 1029697:tid 1029870] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxauG65wm-f4uX16X5vowAAACs"]
[Thu Sep 17 15:25:13.058631 2026] [security2:error] [pid 1029697:tid 1029929] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxauW65wm-f4uX16X5vpgAAAGY"]
[Thu Sep 17 15:25:13.067878 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/postgres/.env"] [unique_id "aqxauW65wm-f4uX16X5vpwAAAFc"]
[Thu Sep 17 15:25:13.119584 2026] [security2:error] [pid 1029697:tid 1029906] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxauW65wm-f4uX16X5vqAAAAE8"]
[Thu Sep 17 15:25:13.244336 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mongodb/.env"] [unique_id "aqxauW65wm-f4uX16X5vrwAAAGQ"]
[Thu Sep 17 15:25:13.267259 2026] [security2:error] [pid 1029697:tid 1029917] [client 98.116.202.91:56951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxauW65wm-f4uX16X5vqwAAWis"], referer: https://www.google.com/
[Thu Sep 17 15:25:13.283239 2026] [security2:error] [pid 1029697:tid 1029895] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxauW65wm-f4uX16X5vsgAAAEQ"]
[Thu Sep 17 15:25:13.423155 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/redis/.env"] [unique_id "aqxauW65wm-f4uX16X5vswAAABA"]
[Thu Sep 17 15:25:13.589537 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/elasticsearch/.env"] [unique_id "aqxauW65wm-f4uX16X5vuAAAAEk"]
[Thu Sep 17 15:25:13.670296 2026] [security2:error] [pid 1029697:tid 1029949] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxauW65wm-f4uX16X5vvAAAAHo"]
[Thu Sep 17 15:25:13.763552 2026] [security2:error] [pid 1029697:tid 1029918] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxauW65wm-f4uX16X5vvgAAAFs"]
[Thu Sep 17 15:25:13.767415 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/rabbitmq/.env"] [unique_id "aqxauW65wm-f4uX16X5vvwAAACk"]
[Thu Sep 17 15:25:13.849245 2026] [security2:error] [pid 1029697:tid 1029863] [client 114.198.138.124:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxauW65wm-f4uX16X5vwAAAACQ"]
[Thu Sep 17 15:25:13.849351 2026] [security2:error] [pid 1029697:tid 1029863] [client 114.198.138.124:55257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxauW65wm-f4uX16X5vwAAAACQ"]
[Thu Sep 17 15:25:13.896332 2026] [security2:error] [pid 1029697:tid 1029877] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxauW65wm-f4uX16X5vwQAAADI"]
[Thu Sep 17 15:25:13.942762 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/kafka/.env"] [unique_id "aqxauW65wm-f4uX16X5vwgAAAHY"]
[Thu Sep 17 15:25:14.023824 2026] [security2:error] [pid 1029697:tid 1029840] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxaum65wm-f4uX16X5vxAAAAA0"]
[Thu Sep 17 15:25:14.110716 2026] [security2:error] [pid 1029697:tid 1029908] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxaum65wm-f4uX16X5vyQAAAFE"]
[Thu Sep 17 15:25:14.121750 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/queue/.env"] [unique_id "aqxaum65wm-f4uX16X5vygAAAFQ"]
[Thu Sep 17 15:25:14.278881 2026] [security2:error] [pid 1029697:tid 1029827] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxaum65wm-f4uX16X5vzgAAAAA"]
[Thu Sep 17 15:25:14.295527 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/worker/.env"] [unique_id "aqxaum65wm-f4uX16X5vzwAAADA"]
[Thu Sep 17 15:25:14.391847 2026] [security2:error] [pid 1029697:tid 1029861] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxaum65wm-f4uX16X5v0QAAACI"]
[Thu Sep 17 15:25:14.398142 2026] [authz_core:error] [pid 1029697:tid 1029954] [client 4.240.114.86:53539] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:25:14.438036 2026] [security2:error] [pid 1029697:tid 1029942] [client 98.116.202.91:59257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaum65wm-f4uX16X5v0AAAcy8"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818015500&hideanons=1&hidebots=0&limit=250&target=The_Lord_Of_Dwarves&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:25:14.440839 2026] [security2:error] [pid 1029697:tid 1029920] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxaum65wm-f4uX16X5v0gAAAF0"]
[Thu Sep 17 15:25:14.456049 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/job/.env"] [unique_id "aqxaum65wm-f4uX16X5v0wAAAGA"]
[Thu Sep 17 15:25:14.590515 2026] [security2:error] [pid 1029697:tid 1029838] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxaum65wm-f4uX16X5v1gAAAAs"]
[Thu Sep 17 15:25:14.625695 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/test/.env"] [unique_id "aqxaum65wm-f4uX16X5v3AAAAFk"]
[Thu Sep 17 15:25:14.628140 2026] [security2:error] [pid 1029697:tid 1029851] [client 156.192.234.52:63377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaum65wm-f4uX16X5v3QAAABg"]
[Thu Sep 17 15:25:14.633629 2026] [security2:error] [pid 1029697:tid 1029851] [client 156.192.234.52:63377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaum65wm-f4uX16X5v3QAAABg"]
[Thu Sep 17 15:25:14.653473 2026] [security2:error] [pid 1029697:tid 1029870] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxaum65wm-f4uX16X5v3gAAACs"]
[Thu Sep 17 15:25:14.791782 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/qa/.env"] [unique_id "aqxaum65wm-f4uX16X5v4AAAAB0"]
[Thu Sep 17 15:25:14.894754 2026] [log_config:warn] [pid 1012520:tid 1012626] (32)Broken pipe: [remote 24.50.225.139:34503] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log, referer: https://freegamest.com/category/match-3/
[Thu Sep 17 15:25:14.894770 2026] [log_config:warn] [pid 1012520:tid 1012626] (32)Broken pipe: [remote 24.50.225.139:34503] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log, referer: https://freegamest.com/category/match-3/
[Thu Sep 17 15:25:14.981891 2026] [security2:error] [pid 1029697:tid 1029887] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxaum65wm-f4uX16X5v5AAAADw"]
[Thu Sep 17 15:25:14.986471 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/preview/.env"] [unique_id "aqxaum65wm-f4uX16X5v5QAAAG8"]
[Thu Sep 17 15:25:15.148679 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/beta/.env"] [unique_id "aqxau265wm-f4uX16X5v6gAAAGQ"]
[Thu Sep 17 15:25:15.327138 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/uat/.env"] [unique_id "aqxau265wm-f4uX16X5v7QAAAHQ"]
[Thu Sep 17 15:25:15.511150 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/stage/.env"] [unique_id "aqxau265wm-f4uX16X5v8gAAAF4"]
[Thu Sep 17 15:25:15.679489 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/development/.env"] [unique_id "aqxau265wm-f4uX16X5v-QAAAAQ"]
[Thu Sep 17 15:25:15.873274 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/production/.env"] [unique_id "aqxau265wm-f4uX16X5v_wAAAD0"]
[Thu Sep 17 15:25:15.986461 2026] [security2:error] [pid 1029697:tid 1029860] [client 185.55.149.49:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxau265wm-f4uX16X5wAQAAACE"]
[Thu Sep 17 15:25:15.986580 2026] [security2:error] [pid 1029697:tid 1029860] [client 185.55.149.49:56898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxau265wm-f4uX16X5wAQAAACE"]
[Thu Sep 17 15:25:15.993191 2026] [security2:error] [pid 1029697:tid 1029868] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxau265wm-f4uX16X5wAgAAACk"]
[Thu Sep 17 15:25:16.041447 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.237.242:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/config/app/.env"] [unique_id "aqxavG65wm-f4uX16X5wBQAAAD8"]
[Thu Sep 17 15:25:16.099899 2026] [security2:error] [pid 1029697:tid 1029905] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxavG65wm-f4uX16X5wBwAAAE4"]
[Thu Sep 17 15:25:16.192092 2026] [security2:error] [pid 1029697:tid 1029945] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxavG65wm-f4uX16X5wDQAAAHY"]
[Thu Sep 17 15:25:16.237647 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.154.237.242:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/phpinfo.php"] [unique_id "aqxavG65wm-f4uX16X5wDwAAAH0"]
[Thu Sep 17 15:25:16.252359 2026] [security2:error] [pid 1029697:tid 1029839] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxavG65wm-f4uX16X5wEQAAAAw"]
[Thu Sep 17 15:25:16.372901 2026] [security2:error] [pid 1029697:tid 1029909] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxavG65wm-f4uX16X5wEgAAAFI"]
[Thu Sep 17 15:25:16.527656 2026] [security2:error] [pid 1029697:tid 1029847] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxavG65wm-f4uX16X5wFQAAABQ"]
[Thu Sep 17 15:25:16.596106 2026] [security2:error] [pid 1029697:tid 1029907] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxavG65wm-f4uX16X5wGAAAAFA"]
[Thu Sep 17 15:25:16.768092 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.154.237.242:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/info.php"] [unique_id "aqxavG65wm-f4uX16X5wHAAAADA"]
[Thu Sep 17 15:25:16.793250 2026] [security2:error] [pid 1029697:tid 1029913] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxavG65wm-f4uX16X5wHQAAAFY"]
[Thu Sep 17 15:25:16.897491 2026] [security2:error] [pid 1029697:tid 1029920] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxavG65wm-f4uX16X5wHgAAAF0"]
[Thu Sep 17 15:25:17.122437 2026] [security2:error] [pid 1029697:tid 1029870] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxavW65wm-f4uX16X5wIwAAACs"]
[Thu Sep 17 15:25:17.215096 2026] [security2:error] [pid 1029697:tid 1029924] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxavW65wm-f4uX16X5wJgAAAGE"]
[Thu Sep 17 15:25:17.283946 2026] [security2:error] [pid 1029697:tid 1029865] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxavW65wm-f4uX16X5wJwAAACY"]
[Thu Sep 17 15:25:17.296986 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.154.237.242:33742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/php.php"] [unique_id "aqxavW65wm-f4uX16X5wKAAAABg"]
[Thu Sep 17 15:25:17.366519 2026] [core:error] [pid 1029697:tid 1029850] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:17.366540 2026] [core:error] [pid 1029697:tid 1029850] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:17.390928 2026] [security2:error] [pid 1029697:tid 1029866] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxavW65wm-f4uX16X5wLAAAACc"]
[Thu Sep 17 15:25:17.447371 2026] [security2:error] [pid 1029697:tid 1029929] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxavW65wm-f4uX16X5wMAAAAGY"]
[Thu Sep 17 15:25:17.509908 2026] [security2:error] [pid 1029697:tid 1029912] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxavW65wm-f4uX16X5wMQAAAFU"]
[Thu Sep 17 15:25:17.628106 2026] [security2:error] [pid 1029697:tid 1029886] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxavW65wm-f4uX16X5wNgAAADs"]
[Thu Sep 17 15:25:17.631030 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.94.35.161:57708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.lasvegaslife.info"] [uri "/"] [unique_id "aqxavW65wm-f4uX16X5wNwAAADw"]
[Thu Sep 17 15:25:17.711651 2026] [security2:error] [pid 1029697:tid 1029922] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxavW65wm-f4uX16X5wPAAAAF8"]
[Thu Sep 17 15:25:17.788138 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.154.237.242:33744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/i.php"] [unique_id "aqxavW65wm-f4uX16X5wPQAAAEU"]
[Thu Sep 17 15:25:17.891861 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.94.35.161:57710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.lasvegaslife.info"] [uri "/"] [unique_id "aqxavW65wm-f4uX16X5wPwAAACo"]
[Thu Sep 17 15:25:17.906286 2026] [security2:error] [pid 1029697:tid 1029843] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxavW65wm-f4uX16X5wQQAAABA"]
[Thu Sep 17 15:25:18.033270 2026] [security2:error] [pid 1029697:tid 1029831] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxavm65wm-f4uX16X5wQgAAAAQ"]
[Thu Sep 17 15:25:18.092303 2026] [security2:error] [pid 1029697:tid 1029947] [client 43.172.195.116:47806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "talent-in-borders.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxavm65wm-f4uX16X5wRQAAAHg"], referer: https://talent-in-borders.com/platinum-selling-duo-notd-collaborate-with-singer-songwriter-shy-martin-on-new-single-keep-you-mine/
[Thu Sep 17 15:25:18.197649 2026] [security2:error] [pid 1029697:tid 1029919] [client 129.212.238.116:38230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.alanpeckolick.com"] [uri "/index.php"] [unique_id "aqxavG65wm-f4uX16X5wEAAAXDk"], referer: http://www.alanpeckolick.com/backup/
[Thu Sep 17 15:25:18.275793 2026] [security2:error] [pid 1029697:tid 1029842] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxavm65wm-f4uX16X5wTAAAAA8"]
[Thu Sep 17 15:25:18.291175 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.237.242:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/pi.php"] [unique_id "aqxavm65wm-f4uX16X5wTQAAAAM"]
[Thu Sep 17 15:25:18.365000 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.94.35.161:57712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.lasvegaslife.info"] [uri "/"] [unique_id "aqxavm65wm-f4uX16X5wUAAAACM"]
[Thu Sep 17 15:25:18.487816 2026] [security2:error] [pid 1029697:tid 1029876] [client 127.0.0.1:42796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxavm65wm-f4uX16X5wVQAAADE"]
[Thu Sep 17 15:25:18.487825 2026] [security2:error] [pid 1029697:tid 1029948] [client 74.7.230.14:58078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fireflyhotglass.net"] [uri "/robots.txt"] [unique_id "aqxavm65wm-f4uX16X5wVAAAeUM"]
[Thu Sep 17 15:25:18.518693 2026] [security2:error] [pid 1029697:tid 1029899] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxavm65wm-f4uX16X5wWQAAAEg"]
[Thu Sep 17 15:25:18.565673 2026] [core:error] [pid 1029697:tid 1029952] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:18.565695 2026] [core:error] [pid 1029697:tid 1029952] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:18.612285 2026] [security2:error] [pid 1029697:tid 1029911] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxavm65wm-f4uX16X5wYQAAAFQ"]
[Thu Sep 17 15:25:18.687041 2026] [security2:error] [pid 1029697:tid 1029854] [client 129.212.238.116:38230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.alanpeckolick.com"] [uri "/index.php"] [unique_id "aqxavm65wm-f4uX16X5wZgAAG0g"], referer: http://www.alanpeckolick.com/wp/
[Thu Sep 17 15:25:18.736113 2026] [security2:error] [pid 1029697:tid 1029939] [client 8.231.55.47:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxavm65wm-f4uX16X5wbQAAAHA"]
[Thu Sep 17 15:25:18.817274 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.154.237.242:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/pinfo.php"] [unique_id "aqxavm65wm-f4uX16X5wbwAAAFY"]
[Thu Sep 17 15:25:18.872688 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.94.35.161:57728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.lasvegaslife.info"] [uri "/"] [unique_id "aqxavm65wm-f4uX16X5wcwAAAGI"]
[Thu Sep 17 15:25:18.990469 2026] [cgid:error] [pid 1029697:tid 1029774] [remote 74.7.230.57:59508] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/gordonscottcreative/404.shtml
[Thu Sep 17 15:25:18.990589 2026] [security2:error] [pid 1029697:tid 1029930] [client 74.7.230.57:59508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gordonscottcreative.theworldinc.com"] [uri "/404.shtml"] [unique_id "aqxavm65wm-f4uX16X5weQAAZ0w"]
[Thu Sep 17 15:25:19.013928 2026] [security2:error] [pid 1029697:tid 1029884] [client 44.239.144.77:56125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxavG65wm-f4uX16X5wEwAAADk"], referer: http://worthtranslations.com/New
[Thu Sep 17 15:25:19.047232 2026] [security2:error] [pid 1029697:tid 1029867] [client 127.0.0.1:42814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxav265wm-f4uX16X5wfgAAACg"]
[Thu Sep 17 15:25:19.047235 2026] [security2:error] [pid 1029697:tid 1029929] [client 74.7.228.18:36764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.zsk.ops.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxav265wm-f4uX16X5wfAAAAGY"]
[Thu Sep 17 15:25:19.179801 2026] [security2:error] [pid 1029697:tid 1029891] [client 129.212.238.116:38230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alanpeckolick.com"] [uri "/index.php"] [unique_id "aqxav265wm-f4uX16X5whAAAQE8"], referer: http://www.alanpeckolick.com/new/
[Thu Sep 17 15:25:19.256266 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.94.35.161:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxav265wm-f4uX16X5wjAAAACo"]
[Thu Sep 17 15:25:19.326713 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.154.237.242:33776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/test.php"] [unique_id "aqxav265wm-f4uX16X5wkQAAAF4"]
[Thu Sep 17 15:25:19.377618 2026] [core:error] [pid 1029697:tid 1029842] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:19.377637 2026] [core:error] [pid 1029697:tid 1029842] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:19.430864 2026] [security2:error] [pid 1029697:tid 1029830] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxav265wm-f4uX16X5wlgAAAAM"]
[Thu Sep 17 15:25:19.587201 2026] [security2:error] [pid 1029697:tid 1029941] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxav265wm-f4uX16X5wmgAAAHI"]
[Thu Sep 17 15:25:19.624597 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.166.217.178:56548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxav265wm-f4uX16X5wmQAAADo"]
[Thu Sep 17 15:25:19.656228 2026] [security2:error] [pid 1029697:tid 1029837] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxav265wm-f4uX16X5woAAAAAo"]
[Thu Sep 17 15:25:19.777499 2026] [security2:error] [pid 1029697:tid 1029847] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxav265wm-f4uX16X5wowAAABQ"]
[Thu Sep 17 15:25:19.856756 2026] [security2:error] [pid 1029697:tid 1029864] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxav265wm-f4uX16X5wpAAAACU"]
[Thu Sep 17 15:25:19.979296 2026] [security2:error] [pid 1029697:tid 1029931] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxav265wm-f4uX16X5wrAAAAGg"]
[Thu Sep 17 15:25:19.981214 2026] [security2:error] [pid 1029697:tid 1029889] [client 129.212.238.116:38230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.alanpeckolick.com"] [uri "/index.php"] [unique_id "aqxav265wm-f4uX16X5wpwAAPlY"], referer: http://www.alanpeckolick.com/wordpress/
[Thu Sep 17 15:25:20.058155 2026] [core:error] [pid 1029697:tid 1029873] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:20.058179 2026] [core:error] [pid 1029697:tid 1029873] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:20.074880 2026] [security2:error] [pid 1029697:tid 1029924] [client 169.58.197.253:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxawG65wm-f4uX16X5wsgAAAGE"], referer: binance.com
[Thu Sep 17 15:25:20.112518 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.154.237.242:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/p.php"] [unique_id "aqxawG65wm-f4uX16X5wswAAAFA"]
[Thu Sep 17 15:25:20.176396 2026] [security2:error] [pid 1029697:tid 1029916] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxawG65wm-f4uX16X5wtgAAAFk"]
[Thu Sep 17 15:25:20.255581 2026] [security2:error] [pid 1029697:tid 1029846] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxawG65wm-f4uX16X5wuQAAABM"]
[Thu Sep 17 15:25:20.312247 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.166.217.178:45208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/info.php"] [unique_id "aqxawG65wm-f4uX16X5wugAAADA"]
[Thu Sep 17 15:25:20.318038 2026] [security2:error] [pid 1029697:tid 1029903] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxawG65wm-f4uX16X5wuwAAAEw"]
[Thu Sep 17 15:25:20.452036 2026] [security2:error] [pid 1029697:tid 1029884] [client 216.244.66.228:42044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wisdomelders.com"] [uri "/unzi/sgzd6.php"] [unique_id "aqxawG65wm-f4uX16X5wvgAAADk"]
[Thu Sep 17 15:25:20.452155 2026] [security2:error] [pid 1029697:tid 1029884] [client 216.244.66.228:42044] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wisdomelders.com"] [uri "/unzi/sgzd6.php"] [unique_id "aqxawG65wm-f4uX16X5wvgAAADk"]
[Thu Sep 17 15:25:20.467251 2026] [security2:error] [pid 1029697:tid 1029930] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxawG65wm-f4uX16X5wvAAAAGc"]
[Thu Sep 17 15:25:20.490731 2026] [security2:error] [pid 1029697:tid 1029935] [client 129.212.238.116:38230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.alanpeckolick.com"] [uri "/index.php"] [unique_id "aqxawG65wm-f4uX16X5wvQAAbFg"], referer: http://www.alanpeckolick.com/old/
[Thu Sep 17 15:25:20.597998 2026] [core:error] [pid 1029697:tid 1029895] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:20.598346 2026] [core:error] [pid 1029697:tid 1029895] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:20.604438 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.154.237.242:57244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/debug.php"] [unique_id "aqxawG65wm-f4uX16X5wxQAAAG0"]
[Thu Sep 17 15:25:20.701140 2026] [security2:error] [pid 1029697:tid 1029938] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxawG65wm-f4uX16X5wygAAAG8"]
[Thu Sep 17 15:25:20.939625 2026] [security2:error] [pid 1029697:tid 1029868] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxawG65wm-f4uX16X5w2gAAACk"]
[Thu Sep 17 15:25:20.981198 2026] [core:error] [pid 1029697:tid 1029890] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:20.981223 2026] [core:error] [pid 1029697:tid 1029890] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:20.999200 2026] [security2:error] [pid 1029697:tid 1029858] [client 129.212.238.116:38230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.alanpeckolick.com"] [uri "/index.php"] [unique_id "aqxawG65wm-f4uX16X5w2QAAH2M"], referer: http://www.alanpeckolick.com/blog/
[Thu Sep 17 15:25:21.028459 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.166.217.178:45212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/php.php"] [unique_id "aqxawW65wm-f4uX16X5w3gAAAC8"]
[Thu Sep 17 15:25:21.094424 2026] [security2:error] [pid 1029697:tid 1029905] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxawW65wm-f4uX16X5w4AAAAE4"]
[Thu Sep 17 15:25:21.137071 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.154.237.242:57248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxawW65wm-f4uX16X5w5wAAACE"]
[Thu Sep 17 15:25:21.315395 2026] [security2:error] [pid 1029697:tid 1029871] [client 8.231.55.47:49368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxawW65wm-f4uX16X5w6wAAACw"]
[Thu Sep 17 15:25:21.445962 2026] [core:error] [pid 1029697:tid 1029940] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:21.445984 2026] [core:error] [pid 1029697:tid 1029940] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:21.597461 2026] [security2:error] [pid 1029697:tid 1029877] [client 8.231.55.47:49368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxawW65wm-f4uX16X5w9AAAADI"]
[Thu Sep 17 15:25:21.633253 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.154.237.242:57260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/test/phpinfo.php"] [unique_id "aqxawW65wm-f4uX16X5xCAAAAHk"]
[Thu Sep 17 15:25:21.726803 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.166.217.178:45222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/i.php"] [unique_id "aqxawW65wm-f4uX16X5xCgAAAFQ"]
[Thu Sep 17 15:25:21.811680 2026] [security2:error] [pid 1029697:tid 1029836] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxawW65wm-f4uX16X5xCwAAAAk"]
[Thu Sep 17 15:25:21.930710 2026] [core:error] [pid 1029697:tid 1029907] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:21.930727 2026] [core:error] [pid 1029697:tid 1029907] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:21.943291 2026] [security2:error] [pid 1029697:tid 1029925] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxawW65wm-f4uX16X5xEAAAAGI"]
[Thu Sep 17 15:25:22.055423 2026] [security2:error] [pid 1029697:tid 1029879] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxawm65wm-f4uX16X5xEQAAADQ"]
[Thu Sep 17 15:25:22.153809 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.154.237.242:57276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/dev/phpinfo.php"] [unique_id "aqxawm65wm-f4uX16X5xFgAAAAU"]
[Thu Sep 17 15:25:22.185401 2026] [security2:error] [pid 1029697:tid 1029850] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxawm65wm-f4uX16X5xFwAAABc"]
[Thu Sep 17 15:25:22.237697 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.94.35.161:48170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxawm65wm-f4uX16X5xGAAAADY"]
[Thu Sep 17 15:25:22.251005 2026] [security2:error] [pid 1029697:tid 1029912] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxawm65wm-f4uX16X5xGwAAAFU"]
[Thu Sep 17 15:25:22.278201 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.161:48170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxawm65wm-f4uX16X5xHAAAAHc"]
[Thu Sep 17 15:25:22.347136 2026] [security2:error] [pid 1029697:tid 1029932] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxawm65wm-f4uX16X5xIQAAAGk"]
[Thu Sep 17 15:25:22.374126 2026] [core:error] [pid 1029697:tid 1029936] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:22.374145 2026] [core:error] [pid 1029697:tid 1029936] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:22.411591 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.166.217.178:45236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxawm65wm-f4uX16X5xJAAAABo"]
[Thu Sep 17 15:25:22.431290 2026] [security2:error] [pid 1029697:tid 1029937] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxawm65wm-f4uX16X5xJQAAAG4"]
[Thu Sep 17 15:25:22.474556 2026] [security2:error] [pid 1029697:tid 1029875] [client 154.190.208.131:41968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxawm65wm-f4uX16X5xJgAAADA"]
[Thu Sep 17 15:25:22.474718 2026] [security2:error] [pid 1029697:tid 1029875] [client 154.190.208.131:41968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxawm65wm-f4uX16X5xJgAAADA"]
[Thu Sep 17 15:25:22.632521 2026] [security2:error] [pid 1029697:tid 1029848] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxawm65wm-f4uX16X5xKQAAABU"]
[Thu Sep 17 15:25:22.642181 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.154.237.242:57290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/old/phpinfo.php"] [unique_id "aqxawm65wm-f4uX16X5xKgAAAGo"]
[Thu Sep 17 15:25:22.691181 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.94.35.161:48178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxawm65wm-f4uX16X5xKwAAAB0"]
[Thu Sep 17 15:25:22.773961 2026] [security2:error] [pid 1029697:tid 1029951] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxawm65wm-f4uX16X5xLgAAAHw"]
[Thu Sep 17 15:25:22.918228 2026] [security2:error] [pid 1029697:tid 1029894] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxawm65wm-f4uX16X5xMAAAAEM"]
[Thu Sep 17 15:25:22.920068 2026] [core:error] [pid 1029697:tid 1029918] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:22.920090 2026] [core:error] [pid 1029697:tid 1029918] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:23.002408 2026] [security2:error] [pid 1029697:tid 1029849] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxaw265wm-f4uX16X5xMgAAABY"]
[Thu Sep 17 15:25:23.112890 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.166.217.178:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxaw265wm-f4uX16X5xMwAAACk"]
[Thu Sep 17 15:25:23.152868 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.154.237.242:57294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/tmp/phpinfo.php"] [unique_id "aqxaw265wm-f4uX16X5xNwAAAFw"]
[Thu Sep 17 15:25:23.171713 2026] [security2:error] [pid 1029697:tid 1029897] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxaw265wm-f4uX16X5xOAAAAEY"]
[Thu Sep 17 15:25:23.272726 2026] [core:error] [pid 1029697:tid 1029861] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:23.272752 2026] [core:error] [pid 1029697:tid 1029861] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:23.275848 2026] [security2:error] [pid 1029697:tid 1029869] [client 37.236.98.10:57709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaw265wm-f4uX16X5xNAAAKgo"]
[Thu Sep 17 15:25:23.310614 2026] [security2:error] [pid 1029697:tid 1029885] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxaw265wm-f4uX16X5xPwAAADo"]
[Thu Sep 17 15:25:23.490334 2026] [security2:error] [pid 1029697:tid 1029902] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxaw265wm-f4uX16X5xQQAAAEs"]
[Thu Sep 17 15:25:23.505838 2026] [security2:error] [pid 1029697:tid 1029927] [client 103.61.184.148:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaw265wm-f4uX16X5xQwAAAGQ"]
[Thu Sep 17 15:25:23.505990 2026] [security2:error] [pid 1029697:tid 1029927] [client 103.61.184.148:59604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxaw265wm-f4uX16X5xQwAAAGQ"]
[Thu Sep 17 15:25:23.551087 2026] [security2:error] [pid 1029697:tid 1029876] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxaw265wm-f4uX16X5xRQAAADE"]
[Thu Sep 17 15:25:23.606212 2026] [security2:error] [pid 1029697:tid 1029915] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxaw265wm-f4uX16X5xSAAAAFg"]
[Thu Sep 17 15:25:23.678439 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.154.237.242:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/public/phpinfo.php"] [unique_id "aqxaw265wm-f4uX16X5xTAAAABA"]
[Thu Sep 17 15:25:23.802178 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.166.217.178:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/test.php"] [unique_id "aqxaw265wm-f4uX16X5xTgAAAFM"]
[Thu Sep 17 15:25:23.820748 2026] [security2:error] [pid 1029697:tid 1029931] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxaw265wm-f4uX16X5xTwAAAGg"]
[Thu Sep 17 15:25:23.868348 2026] [lsapi:error] [pid 1029697:tid 1029702] [remote 161.35.164.148:55060] [host www.oldschoolrentals.com] Backend fatal error: PHP Fatal error:  Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: http://www.oldschoolrentals.com/
[Thu Sep 17 15:25:23.955465 2026] [core:error] [pid 1029697:tid 1029947] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:23.955489 2026] [core:error] [pid 1029697:tid 1029947] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:23.986258 2026] [security2:error] [pid 1029697:tid 1029893] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxaw265wm-f4uX16X5xUwAAAEI"]
[Thu Sep 17 15:25:24.078642 2026] [security2:error] [pid 1029697:tid 1029873] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxaxG65wm-f4uX16X5xVgAAAC4"]
[Thu Sep 17 15:25:24.209802 2026] [security2:error] [pid 1029697:tid 1029884] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxaxG65wm-f4uX16X5xXQAAADk"]
[Thu Sep 17 15:25:24.310726 2026] [security2:error] [pid 1029697:tid 1029867] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxaxG65wm-f4uX16X5xXwAAACg"]
[Thu Sep 17 15:25:24.383696 2026] [core:error] [pid 1029697:tid 1029872] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:24.383720 2026] [core:error] [pid 1029697:tid 1029872] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:24.399152 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.154.237.242:57306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/php-info.php"] [unique_id "aqxaxG65wm-f4uX16X5xYwAAAGY"]
[Thu Sep 17 15:25:24.403187 2026] [lsapi:error] [pid 1029697:tid 1029699] [remote 161.35.164.148:55060] [host www.oldschoolrentals.com] Backend fatal error: PHP Fatal error:  Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: http://www.oldschoolrentals.com/wordpress/
[Thu Sep 17 15:25:24.509918 2026] [security2:error] [pid 1029697:tid 1029938] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxaxG65wm-f4uX16X5xZgAAAG8"]
[Thu Sep 17 15:25:24.520710 2026] [security2:error] [pid 1029697:tid 1029939] [client 47.79.117.25:53676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxawm65wm-f4uX16X5xEwAAAHA"]
[Thu Sep 17 15:25:24.546630 2026] [security2:error] [pid 1029697:tid 1029892] [client 114.198.138.124:55912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaxG65wm-f4uX16X5xZwAAAEE"]
[Thu Sep 17 15:25:24.546829 2026] [security2:error] [pid 1029697:tid 1029892] [client 114.198.138.124:55912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaxG65wm-f4uX16X5xZwAAAEE"]
[Thu Sep 17 15:25:24.622252 2026] [security2:error] [pid 1029697:tid 1029937] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxaxG65wm-f4uX16X5xaQAAAG4"]
[Thu Sep 17 15:25:24.722747 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.166.217.178:45272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/p.php"] [unique_id "aqxaxG65wm-f4uX16X5xbgAAAAA"]
[Thu Sep 17 15:25:24.761289 2026] [security2:error] [pid 1029697:tid 1029890] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxaxG65wm-f4uX16X5xcAAAAD8"]
[Thu Sep 17 15:25:24.825136 2026] [authz_core:error] [pid 1029697:tid 1029881] [client 4.240.114.86:57273] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:25:24.829230 2026] [security2:error] [pid 1029697:tid 1029943] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxaxG65wm-f4uX16X5xcwAAAHQ"]
[Thu Sep 17 15:25:24.875794 2026] [core:error] [pid 1029697:tid 1029921] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:24.875814 2026] [core:error] [pid 1029697:tid 1029921] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:24.900338 2026] [lsapi:error] [pid 1029697:tid 1029709] [remote 161.35.164.148:55060] [host www.oldschoolrentals.com] Backend fatal error: PHP Fatal error:  Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: http://www.oldschoolrentals.com/backup/
[Thu Sep 17 15:25:24.922286 2026] [security2:error] [pid 1029697:tid 1029862] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxaxG65wm-f4uX16X5xeAAAACM"]
[Thu Sep 17 15:25:24.944489 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.237.242:57318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/phpversion.php"] [unique_id "aqxaxG65wm-f4uX16X5xeQAAAB4"]
[Thu Sep 17 15:25:24.978388 2026] [security2:error] [pid 1029697:tid 1029878] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxaxG65wm-f4uX16X5xegAAADM"]
[Thu Sep 17 15:25:25.122964 2026] [security2:error] [pid 1029697:tid 1029894] [client 156.192.234.52:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaxW65wm-f4uX16X5xgAAAAEM"]
[Thu Sep 17 15:25:25.123904 2026] [security2:error] [pid 1029697:tid 1029894] [client 156.192.234.52:63980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaxW65wm-f4uX16X5xgAAAAEM"]
[Thu Sep 17 15:25:25.188290 2026] [core:error] [pid 1029697:tid 1029847] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:25.188312 2026] [core:error] [pid 1029697:tid 1029847] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:25.223604 2026] [security2:error] [pid 1029697:tid 1029877] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxaxW65wm-f4uX16X5xiwAAADI"]
[Thu Sep 17 15:25:25.266377 2026] [security2:error] [pid 1029697:tid 1029855] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxaxW65wm-f4uX16X5xjAAAABw"]
[Thu Sep 17 15:25:25.374631 2026] [lsapi:error] [pid 1029697:tid 1029718] [remote 161.35.164.148:55060] [host www.oldschoolrentals.com] Backend fatal error: PHP Fatal error:  Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: http://www.oldschoolrentals.com/blog/
[Thu Sep 17 15:25:25.402906 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.166.217.178:49598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxaxW65wm-f4uX16X5xkwAAAAQ"]
[Thu Sep 17 15:25:25.418467 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.154.237.242:57332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/_phpinfo.php"] [unique_id "aqxaxW65wm-f4uX16X5xlgAAAGg"]
[Thu Sep 17 15:25:25.481761 2026] [core:error] [pid 1029697:tid 1029900] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:25.481779 2026] [core:error] [pid 1029697:tid 1029900] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:25.538222 2026] [security2:error] [pid 1029697:tid 1029873] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxaxW65wm-f4uX16X5xmwAAAC4"]
[Thu Sep 17 15:25:25.722502 2026] [security2:error] [pid 1029697:tid 1029952] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxaxW65wm-f4uX16X5xowAAAH0"]
[Thu Sep 17 15:25:25.739770 2026] [core:error] [pid 1029697:tid 1029867] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:25.739797 2026] [core:error] [pid 1029697:tid 1029867] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:25.842653 2026] [lsapi:error] [pid 1029697:tid 1029721] [remote 161.35.164.148:55060] [host www.oldschoolrentals.com] Backend fatal error: PHP Fatal error:  Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: http://www.oldschoolrentals.com/wp/
[Thu Sep 17 15:25:25.888625 2026] [security2:error] [pid 1029697:tid 1029887] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxaxW65wm-f4uX16X5xpwAAADw"]
[Thu Sep 17 15:25:25.929907 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.154.237.242:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/old_phpinfo.php"] [unique_id "aqxaxW65wm-f4uX16X5xqQAAAEQ"]
[Thu Sep 17 15:25:26.013282 2026] [security2:error] [pid 1029697:tid 1029896] [client 177.136.96.136:60372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaxW65wm-f4uX16X5xpQAARRg"]
[Thu Sep 17 15:25:26.029449 2026] [security2:error] [pid 1029697:tid 1029856] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxaxm65wm-f4uX16X5xsAAAAB0"]
[Thu Sep 17 15:25:26.080522 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.166.217.178:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxaxm65wm-f4uX16X5xsQAAACA"]
[Thu Sep 17 15:25:26.145931 2026] [core:error] [pid 1029697:tid 1029917] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:26.145953 2026] [core:error] [pid 1029697:tid 1029917] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:26.311647 2026] [lsapi:error] [pid 1029697:tid 1029726] [remote 161.35.164.148:55060] [host www.oldschoolrentals.com] Backend fatal error: PHP Fatal error:  Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: http://www.oldschoolrentals.com/new/
[Thu Sep 17 15:25:26.334932 2026] [security2:error] [pid 1029697:tid 1029868] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxaxm65wm-f4uX16X5xuQAAACk"]
[Thu Sep 17 15:25:26.372499 2026] [deflate:error] [pid 1029697:tid 1029950] (104)Connection reset by peer: [client 34.97.29.237:41656] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:25:26.415322 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.154.237.242:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/server-info.php"] [unique_id "aqxaxm65wm-f4uX16X5xvwAAAEA"]
[Thu Sep 17 15:25:26.420374 2026] [security2:error] [pid 1029697:tid 1029941] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxaxm65wm-f4uX16X5xwAAAAHI"]
[Thu Sep 17 15:25:26.474386 2026] [core:error] [pid 1029697:tid 1029829] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:26.474409 2026] [core:error] [pid 1029697:tid 1029829] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:26.630066 2026] [security2:error] [pid 1029697:tid 1029863] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxaxm65wm-f4uX16X5xxAAAACQ"]
[Thu Sep 17 15:25:26.708530 2026] [security2:error] [pid 1029697:tid 1029877] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxaxm65wm-f4uX16X5xxwAAADI"]
[Thu Sep 17 15:25:26.736362 2026] [security2:error] [pid 1029697:tid 1029837] [client 185.55.149.49:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaxm65wm-f4uX16X5xyQAAAAo"]
[Thu Sep 17 15:25:26.736468 2026] [security2:error] [pid 1029697:tid 1029837] [client 185.55.149.49:62623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxaxm65wm-f4uX16X5xyQAAAAo"]
[Thu Sep 17 15:25:26.763292 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.166.217.178:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxaxm65wm-f4uX16X5xywAAAAE"]
[Thu Sep 17 15:25:26.778332 2026] [security2:error] [pid 1029697:tid 1029942] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxaxm65wm-f4uX16X5xzAAAAHM"]
[Thu Sep 17 15:25:26.794759 2026] [deflate:error] [pid 1029697:tid 1029864] (104)Connection reset by peer: [client 34.97.29.237:41670] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:25:26.829197 2026] [core:error] [pid 1029697:tid 1029876] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:26.829217 2026] [core:error] [pid 1029697:tid 1029876] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:26.893196 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.154.237.242:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/server-status.php"] [unique_id "aqxaxm65wm-f4uX16X5x0QAAAHo"]
[Thu Sep 17 15:25:26.995585 2026] [security2:error] [pid 1029697:tid 1029835] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxaxm65wm-f4uX16X5x0gAAAAg"]
[Thu Sep 17 15:25:27.063314 2026] [security2:error] [pid 1029697:tid 1029873] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxax265wm-f4uX16X5x1AAAAC4"]
[Thu Sep 17 15:25:27.103911 2026] [security2:error] [pid 1029697:tid 1029850] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxax265wm-f4uX16X5x1QAAABc"]
[Thu Sep 17 15:25:27.223132 2026] [deflate:error] [pid 1029697:tid 1029916] (104)Connection reset by peer: [client 34.97.29.237:41686] AH10298: failed reading from PIPE bucket
[Thu Sep 17 15:25:27.228879 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.35.161:48288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxax265wm-f4uX16X5x3QAAAGk"]
[Thu Sep 17 15:25:27.275267 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.94.35.161:48288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxax265wm-f4uX16X5x3wAAAFE"]
[Thu Sep 17 15:25:27.342231 2026] [core:error] [pid 1029697:tid 1029838] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:27.342252 2026] [core:error] [pid 1029697:tid 1029838] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:27.347178 2026] [security2:error] [pid 1029697:tid 1029912] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxax265wm-f4uX16X5x4wAAAFU"]
[Thu Sep 17 15:25:27.367193 2026] [security2:error] [pid 1029697:tid 1029889] [client 169.58.197.253:54116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxax265wm-f4uX16X5x5AAAAD4"], referer: binance.com
[Thu Sep 17 15:25:27.431168 2026] [security2:error] [pid 1029697:tid 1029930] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxax265wm-f4uX16X5x6AAAAGc"]
[Thu Sep 17 15:25:27.461064 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.166.217.178:49626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxax265wm-f4uX16X5x6QAAAG0"]
[Thu Sep 17 15:25:27.624809 2026] [security2:error] [pid 1029697:tid 1029923] [client 134.185.85.61:57167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "totallyclassicrestoration.com.au"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxax265wm-f4uX16X5x8QAAAGA"]
[Thu Sep 17 15:25:27.666908 2026] [core:error] [pid 1029697:tid 1029866] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:27.666926 2026] [core:error] [pid 1029697:tid 1029866] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:27.704537 2026] [security2:error] [pid 1029697:tid 1029890] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxax265wm-f4uX16X5x9gAAAD8"]
[Thu Sep 17 15:25:27.805316 2026] [security2:error] [pid 1029697:tid 1029858] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxax265wm-f4uX16X5x-QAAAB8"]
[Thu Sep 17 15:25:27.807188 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.154.237.242:57366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/webroot/index.php/_environment"] [unique_id "aqxax265wm-f4uX16X5x-gAAAEo"]
[Thu Sep 17 15:25:27.874468 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/.env"] [unique_id "aqxax265wm-f4uX16X5x-wAAADA"]
[Thu Sep 17 15:25:27.899861 2026] [security2:error] [pid 1029697:tid 1029874] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxax265wm-f4uX16X5x_AAAAC8"]
[Thu Sep 17 15:25:27.958525 2026] [security2:error] [pid 1029697:tid 1029904] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxax265wm-f4uX16X5x_gAAAE0"]
[Thu Sep 17 15:25:28.007722 2026] [security2:error] [pid 1029697:tid 1029862] [client 134.185.85.61:51497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "totallyclassicrestoration.com.au"] [uri "/media/system/js/core.js"] [unique_id "aqxayG65wm-f4uX16X5yAAAAACM"]
[Thu Sep 17 15:25:28.087840 2026] [core:error] [pid 1029697:tid 1029868] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:28.087863 2026] [core:error] [pid 1029697:tid 1029868] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:28.101634 2026] [security2:error] [pid 1029697:tid 1029869] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxayG65wm-f4uX16X5yBQAAACo"]
[Thu Sep 17 15:25:28.155524 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.166.217.178:49630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxayG65wm-f4uX16X5yCAAAABo"]
[Thu Sep 17 15:25:28.201809 2026] [log_config:warn] [pid 1012520:tid 1012737] (32)Broken pipe: [client 188.254.48.226:10090] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log
[Thu Sep 17 15:25:28.201827 2026] [log_config:warn] [pid 1012520:tid 1012737] (32)Broken pipe: [client 188.254.48.226:10090] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log
[Thu Sep 17 15:25:28.246913 2026] [security2:error] [pid 1029697:tid 1029888] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxayG65wm-f4uX16X5yDAAAAD0"]
[Thu Sep 17 15:25:28.303401 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.154.237.242:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/mail/phpinfo.php"] [unique_id "aqxayG65wm-f4uX16X5yDwAAAEc"]
[Thu Sep 17 15:25:28.345236 2026] [security2:error] [pid 1029697:tid 1029906] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxayG65wm-f4uX16X5yEAAAAE8"]
[Thu Sep 17 15:25:28.411862 2026] [security2:error] [pid 1029697:tid 1029922] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxayG65wm-f4uX16X5yFAAAAF8"]
[Thu Sep 17 15:25:28.562949 2026] [security2:error] [pid 1029697:tid 1029831] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxayG65wm-f4uX16X5yGwAAAAQ"]
[Thu Sep 17 15:25:28.595467 2026] [core:error] [pid 1029697:tid 1029902] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:28.595491 2026] [core:error] [pid 1029697:tid 1029902] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:28.686922 2026] [security2:error] [pid 1029697:tid 1029911] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxayG65wm-f4uX16X5yIwAAAFQ"]
[Thu Sep 17 15:25:28.760371 2026] [security2:error] [pid 1029697:tid 1029835] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxayG65wm-f4uX16X5yJQAAAAg"]
[Thu Sep 17 15:25:28.771931 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/.env.bak"] [unique_id "aqxayG65wm-f4uX16X5yJgAAAGI"]
[Thu Sep 17 15:25:28.817769 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.154.237.242:57376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxayG65wm-f4uX16X5yJwAAAFM"]
[Thu Sep 17 15:25:28.843030 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.166.217.178:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxayG65wm-f4uX16X5yKAAAADg"]
[Thu Sep 17 15:25:28.894867 2026] [security2:error] [pid 1029697:tid 1029924] [client 4.240.114.86:58990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxayG65wm-f4uX16X5yKQAAAGE"], referer: binance.com
[Thu Sep 17 15:25:28.906091 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/.env.backup"] [unique_id "aqxayG65wm-f4uX16X5yKgAAAFk"]
[Thu Sep 17 15:25:28.918604 2026] [security2:error] [pid 1029697:tid 1029838] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxayG65wm-f4uX16X5yLAAAAAs"]
[Thu Sep 17 15:25:28.939744 2026] [core:error] [pid 1029697:tid 1029893] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:28.939760 2026] [core:error] [pid 1029697:tid 1029893] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:28.983033 2026] [security2:error] [pid 1029697:tid 1029914] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxayG65wm-f4uX16X5yLwAAAFc"]
[Thu Sep 17 15:25:29.051925 2026] [security2:error] [pid 1029697:tid 1029872] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxayW65wm-f4uX16X5yMQAAAC0"]
[Thu Sep 17 15:25:29.108105 2026] [security2:error] [pid 1029697:tid 1029952] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxayW65wm-f4uX16X5yMgAAAH0"]
[Thu Sep 17 15:25:29.171274 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/.env.old"] [unique_id "aqxayW65wm-f4uX16X5yNQAAADw"]
[Thu Sep 17 15:25:29.270792 2026] [security2:error] [pid 1029697:tid 1029923] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxayW65wm-f4uX16X5yOAAAAGA"]
[Thu Sep 17 15:25:29.308408 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.94.35.161:48336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxayW65wm-f4uX16X5yOwAAAGw"]
[Thu Sep 17 15:25:29.342422 2026] [security2:error] [pid 1029697:tid 1029892] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxayW65wm-f4uX16X5yPAAAAEE"]
[Thu Sep 17 15:25:29.351615 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.154.237.242:57392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/hosting/phpinfo.php"] [unique_id "aqxayW65wm-f4uX16X5yPQAAAF0"]
[Thu Sep 17 15:25:29.454309 2026] [security2:error] [pid 1029697:tid 1029937] [client 8.231.55.47:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "xug.rxg.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxayW65wm-f4uX16X5yPwAAAG4"]
[Thu Sep 17 15:25:29.457171 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.94.35.161:48336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxayW65wm-f4uX16X5yQAAAAEU"]
[Thu Sep 17 15:25:29.527028 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.94.35.161:48336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxayW65wm-f4uX16X5yQQAAAD8"]
[Thu Sep 17 15:25:29.532825 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.166.217.178:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxayW65wm-f4uX16X5yQgAAABs"]
[Thu Sep 17 15:25:29.553316 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.94.35.161:48336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxayW65wm-f4uX16X5yQwAAAA0"]
[Thu Sep 17 15:25:29.734459 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.94.35.161:48336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxayW65wm-f4uX16X5ySQAAAGo"]
[Thu Sep 17 15:25:29.801584 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.94.35.161:48336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxayW65wm-f4uX16X5ySgAAACM"]
[Thu Sep 17 15:25:29.905838 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.154.237.242:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/webmail/phpinfo.php"] [unique_id "aqxayW65wm-f4uX16X5yTwAAAE0"]
[Thu Sep 17 15:25:29.927409 2026] [security2:error] [pid 1029697:tid 1029833] [client 8.231.55.47:47792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxayW65wm-f4uX16X5yTAAAAAY"]
[Thu Sep 17 15:25:30.021301 2026] [core:error] [pid 1029697:tid 1029886] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:30.021330 2026] [core:error] [pid 1029697:tid 1029886] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:30.362705 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxaym65wm-f4uX16X5yXgAAAAc"]
[Thu Sep 17 15:25:30.421237 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.237.242:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/smtp/phpinfo.php"] [unique_id "aqxaym65wm-f4uX16X5yXwAAABI"]
[Thu Sep 17 15:25:30.426897 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxaym65wm-f4uX16X5yYAAAAA8"]
[Thu Sep 17 15:25:30.457920 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.166.217.178:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxaym65wm-f4uX16X5yYgAAAH8"]
[Thu Sep 17 15:25:30.461258 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxaym65wm-f4uX16X5yYwAAAAo"]
[Thu Sep 17 15:25:30.545368 2026] [security2:error] [pid 1029697:tid 1029863] [client 8.231.55.47:47808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/info.php"] [unique_id "aqxaym65wm-f4uX16X5yZAAAACQ"]
[Thu Sep 17 15:25:30.562944 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxaym65wm-f4uX16X5yZQAAABY"]
[Thu Sep 17 15:25:30.704062 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/.env.swp"] [unique_id "aqxaym65wm-f4uX16X5yZwAAAAQ"]
[Thu Sep 17 15:25:30.710609 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxaym65wm-f4uX16X5yagAAAGQ"]
[Thu Sep 17 15:25:30.827354 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/.env~"] [unique_id "aqxaym65wm-f4uX16X5ycwAAADE"]
[Thu Sep 17 15:25:30.835885 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxaym65wm-f4uX16X5ydAAAACU"]
[Thu Sep 17 15:25:30.908692 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxaym65wm-f4uX16X5ydQAAAAs"]
[Thu Sep 17 15:25:30.928637 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.154.237.242:50698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/phpinfo.php.bak"] [unique_id "aqxaym65wm-f4uX16X5ydgAAAAg"]
[Thu Sep 17 15:25:30.933837 2026] [security2:error] [pid 1029697:tid 1029924] [client 8.231.55.47:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/php.php"] [unique_id "aqxaym65wm-f4uX16X5ydwAAAGE"]
[Thu Sep 17 15:25:31.017491 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxay265wm-f4uX16X5yewAAAFc"]
[Thu Sep 17 15:25:31.131632 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxay265wm-f4uX16X5yfwAAAHc"]
[Thu Sep 17 15:25:31.143897 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.166.217.178:49656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxay265wm-f4uX16X5ygAAAAEI"]
[Thu Sep 17 15:25:31.259254 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxay265wm-f4uX16X5yhgAAAF0"]
[Thu Sep 17 15:25:31.366713 2026] [security2:error] [pid 1029697:tid 1029939] [client 8.231.55.47:38770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/i.php"] [unique_id "aqxay265wm-f4uX16X5yiQAAAHA"]
[Thu Sep 17 15:25:31.401216 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxay265wm-f4uX16X5yigAAADA"]
[Thu Sep 17 15:25:31.439694 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.237.242:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/phpinfo.php.old"] [unique_id "aqxay265wm-f4uX16X5yiwAAACc"]
[Thu Sep 17 15:25:31.477451 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxay265wm-f4uX16X5yjgAAAAY"]
[Thu Sep 17 15:25:31.629943 2026] [security2:error] [pid 1029697:tid 1029861] [client 8.231.55.47:38778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxay265wm-f4uX16X5ykwAAACI"]
[Thu Sep 17 15:25:31.663204 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxay265wm-f4uX16X5ylAAAAHI"]
[Thu Sep 17 15:25:31.724486 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxay265wm-f4uX16X5ymAAAAE8"]
[Thu Sep 17 15:25:31.832898 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.166.217.178:49660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxay265wm-f4uX16X5ynAAAAGU"]
[Thu Sep 17 15:25:31.833453 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/app/.env"] [unique_id "aqxay265wm-f4uX16X5ymwAAABQ"]
[Thu Sep 17 15:25:31.878657 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxay265wm-f4uX16X5ynQAAABI"]
[Thu Sep 17 15:25:31.930249 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.154.237.242:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/phpinfo.php~"] [unique_id "aqxay265wm-f4uX16X5yngAAAF8"]
[Thu Sep 17 15:25:31.961551 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/apps/.env"] [unique_id "aqxay265wm-f4uX16X5ynwAAADc"]
[Thu Sep 17 15:25:31.973317 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxay265wm-f4uX16X5yoAAAAH8"]
[Thu Sep 17 15:25:32.058389 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxazG65wm-f4uX16X5yoQAAABE"]
[Thu Sep 17 15:25:32.088606 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/api/.env"] [unique_id "aqxazG65wm-f4uX16X5yogAAAEc"]
[Thu Sep 17 15:25:32.099296 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxazG65wm-f4uX16X5yowAAACQ"]
[Thu Sep 17 15:25:32.121439 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxazG65wm-f4uX16X5ypAAAAAE"]
[Thu Sep 17 15:25:32.209403 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/web/.env"] [unique_id "aqxazG65wm-f4uX16X5yqAAAAAw"]
[Thu Sep 17 15:25:32.217099 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxazG65wm-f4uX16X5yqQAAAFY"]
[Thu Sep 17 15:25:32.274076 2026] [security2:error] [pid 1029697:tid 1029877] [client 8.231.55.47:38784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxazG65wm-f4uX16X5yqwAAADI"]
[Thu Sep 17 15:25:32.277036 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxazG65wm-f4uX16X5yrQAAAFM"]
[Thu Sep 17 15:25:32.330789 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/site/.env"] [unique_id "aqxazG65wm-f4uX16X5yrwAAADE"]
[Thu Sep 17 15:25:32.350596 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxazG65wm-f4uX16X5ysAAAACU"]
[Thu Sep 17 15:25:32.442457 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxazG65wm-f4uX16X5ysgAAAFE"]
[Thu Sep 17 15:25:32.453203 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/public/.env"] [unique_id "aqxazG65wm-f4uX16X5yswAAACs"]
[Thu Sep 17 15:25:32.481982 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.154.237.242:50726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/info.php.bak"] [unique_id "aqxazG65wm-f4uX16X5ytAAAAC4"]
[Thu Sep 17 15:25:32.518448 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.166.217.178:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxazG65wm-f4uX16X5ytwAAAAk"]
[Thu Sep 17 15:25:32.527420 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxazG65wm-f4uX16X5yuAAAAEs"]
[Thu Sep 17 15:25:32.572250 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxazG65wm-f4uX16X5yugAAACY"]
[Thu Sep 17 15:25:32.638839 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxazG65wm-f4uX16X5yvAAAAA4"]
[Thu Sep 17 15:25:32.678698 2026] [security2:error] [pid 1029697:tid 1029947] [client 8.231.55.47:38796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/test.php"] [unique_id "aqxazG65wm-f4uX16X5yvgAAAHg"]
[Thu Sep 17 15:25:32.695511 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxazG65wm-f4uX16X5ywQAAAE4"]
[Thu Sep 17 15:25:32.709406 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/backend/.env"] [unique_id "aqxazG65wm-f4uX16X5ywgAAAGM"]
[Thu Sep 17 15:25:32.736006 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxazG65wm-f4uX16X5yxQAAAEQ"]
[Thu Sep 17 15:25:32.810863 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxazG65wm-f4uX16X5yxwAAAFk"]
[Thu Sep 17 15:25:32.841074 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/server/.env"] [unique_id "aqxazG65wm-f4uX16X5yyQAAAAU"]
[Thu Sep 17 15:25:32.846707 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxazG65wm-f4uX16X5yywAAAD8"]
[Thu Sep 17 15:25:32.891364 2026] [security2:error] [pid 1029697:tid 1029830] [client 137.59.220.183:10378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxazG65wm-f4uX16X5yxAAAAzs"]
[Thu Sep 17 15:25:32.962760 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/frontend/.env"] [unique_id "aqxazG65wm-f4uX16X5yzQAAABs"]
[Thu Sep 17 15:25:32.970838 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxazG65wm-f4uX16X5yzgAAAF4"]
[Thu Sep 17 15:25:32.974928 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.154.237.242:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/phpinfo.php.save"] [unique_id "aqxazG65wm-f4uX16X5yzwAAAD0"]
[Thu Sep 17 15:25:33.002232 2026] [security2:error] [pid 1029697:tid 1029843] [client 154.190.208.131:42610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxazW65wm-f4uX16X5y0AAAABA"]
[Thu Sep 17 15:25:33.002344 2026] [security2:error] [pid 1029697:tid 1029843] [client 154.190.208.131:42610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxazW65wm-f4uX16X5y0AAAABA"]
[Thu Sep 17 15:25:33.076626 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxazW65wm-f4uX16X5y0gAAAFw"]
[Thu Sep 17 15:25:33.084987 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/src/.env"] [unique_id "aqxazW65wm-f4uX16X5y0wAAAGs"]
[Thu Sep 17 15:25:33.163911 2026] [security2:error] [pid 1029697:tid 1029868] [client 8.231.55.47:38812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxazW65wm-f4uX16X5y0QAAACk"]
[Thu Sep 17 15:25:33.170592 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxazW65wm-f4uX16X5y1gAAAEA"]
[Thu Sep 17 15:25:33.231457 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.166.217.178:49670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxazW65wm-f4uX16X5y2QAAABM"]
[Thu Sep 17 15:25:33.232616 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/core/.env"] [unique_id "aqxazW65wm-f4uX16X5y2gAAADM"]
[Thu Sep 17 15:25:33.304884 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxazW65wm-f4uX16X5y2wAAABo"]
[Thu Sep 17 15:25:33.356782 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/core/app/.env"] [unique_id "aqxazW65wm-f4uX16X5y3AAAAHE"]
[Thu Sep 17 15:25:33.391558 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxazW65wm-f4uX16X5y3QAAAEo"]
[Thu Sep 17 15:25:33.448365 2026] [security2:error] [pid 1029697:tid 1029906] [client 8.231.55.47:38812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/p.php"] [unique_id "aqxazW65wm-f4uX16X5y3gAAAE8"]
[Thu Sep 17 15:25:33.467940 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.154.237.242:50736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/staging/phpinfo.php"] [unique_id "aqxazW65wm-f4uX16X5y3wAAAHI"]
[Thu Sep 17 15:25:33.478652 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/config/.env"] [unique_id "aqxazW65wm-f4uX16X5y4AAAAGU"]
[Thu Sep 17 15:25:33.498183 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxazW65wm-f4uX16X5y4QAAABQ"]
[Thu Sep 17 15:25:33.543028 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxazW65wm-f4uX16X5y5AAAADc"]
[Thu Sep 17 15:25:33.600853 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/private/.env"] [unique_id "aqxazW65wm-f4uX16X5y5gAAABE"]
[Thu Sep 17 15:25:33.696600 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxazW65wm-f4uX16X5y6QAAACQ"]
[Thu Sep 17 15:25:33.729619 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/application/.env"] [unique_id "aqxazW65wm-f4uX16X5y6wAAAAQ"]
[Thu Sep 17 15:25:33.802210 2026] [security2:error] [pid 1029697:tid 1029927] [client 8.231.55.47:38822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxazW65wm-f4uX16X5y7AAAAGQ"]
[Thu Sep 17 15:25:33.857137 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/bootstrap/.env"] [unique_id "aqxazW65wm-f4uX16X5y7QAAAFY"]
[Thu Sep 17 15:25:33.910916 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.166.217.178:49680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxazW65wm-f4uX16X5y7gAAABw"]
[Thu Sep 17 15:25:33.914229 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxazW65wm-f4uX16X5y7wAAAGI"]
[Thu Sep 17 15:25:33.979302 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/database/.env"] [unique_id "aqxazW65wm-f4uX16X5y8AAAADI"]
[Thu Sep 17 15:25:33.989644 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.237.242:50746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/beta/phpinfo.php"] [unique_id "aqxazW65wm-f4uX16X5y8QAAAAw"]
[Thu Sep 17 15:25:34.006104 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxazm65wm-f4uX16X5y8gAAAGk"]
[Thu Sep 17 15:25:34.042810 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxazm65wm-f4uX16X5y8wAAAAs"]
[Thu Sep 17 15:25:34.082199 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxazm65wm-f4uX16X5y9QAAAAg"]
[Thu Sep 17 15:25:34.099776 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/storage/.env"] [unique_id "aqxazm65wm-f4uX16X5y9gAAADk"]
[Thu Sep 17 15:25:34.127748 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxazm65wm-f4uX16X5y9wAAAEw"]
[Thu Sep 17 15:25:34.149981 2026] [security2:error] [pid 1029697:tid 1029942] [client 103.61.184.148:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxazm65wm-f4uX16X5y-AAAAHM"]
[Thu Sep 17 15:25:34.150088 2026] [security2:error] [pid 1029697:tid 1029942] [client 103.61.184.148:60168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxazm65wm-f4uX16X5y-AAAAHM"]
[Thu Sep 17 15:25:34.190845 2026] [security2:error] [pid 1029697:tid 1029880] [client 4.240.114.86:60939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxazm65wm-f4uX16X5y-wAAADU"], referer: binance.com
[Thu Sep 17 15:25:34.221562 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/var/www/.env"] [unique_id "aqxazm65wm-f4uX16X5y_gAAAFc"]
[Thu Sep 17 15:25:34.250448 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxazm65wm-f4uX16X5y_wAAABU"]
[Thu Sep 17 15:25:34.343780 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/var/www/html/.env"] [unique_id "aqxazm65wm-f4uX16X5zAAAAAGg"]
[Thu Sep 17 15:25:34.350580 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxazm65wm-f4uX16X5zAQAAADg"]
[Thu Sep 17 15:25:34.391683 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxazm65wm-f4uX16X5zAgAAAFQ"]
[Thu Sep 17 15:25:34.418588 2026] [security2:error] [pid 1029697:tid 1029900] [client 8.231.55.47:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxazm65wm-f4uX16X5zAwAAAEk"]
[Thu Sep 17 15:25:34.464247 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/current/.env"] [unique_id "aqxazm65wm-f4uX16X5zCAAAAH4"]
[Thu Sep 17 15:25:34.470113 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.154.237.242:50758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/uat/phpinfo.php"] [unique_id "aqxazm65wm-f4uX16X5zCQAAAEs"]
[Thu Sep 17 15:25:34.489569 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxazm65wm-f4uX16X5zCgAAAEI"]
[Thu Sep 17 15:25:34.545380 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxazm65wm-f4uX16X5zCwAAAGM"]
[Thu Sep 17 15:25:34.566031 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxazm65wm-f4uX16X5zDAAAAFI"]
[Thu Sep 17 15:25:34.585346 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/release/.env"] [unique_id "aqxazm65wm-f4uX16X5zDQAAABk"]
[Thu Sep 17 15:25:34.632529 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxazm65wm-f4uX16X5zEQAAAEQ"]
[Thu Sep 17 15:25:34.664580 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxazm65wm-f4uX16X5zEgAAAGc"]
[Thu Sep 17 15:25:34.706734 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/releases/.env"] [unique_id "aqxazm65wm-f4uX16X5zFQAAAGw"]
[Thu Sep 17 15:25:34.803736 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxazm65wm-f4uX16X5zGAAAAD0"]
[Thu Sep 17 15:25:34.834104 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/shared/.env"] [unique_id "aqxazm65wm-f4uX16X5zGgAAABA"]
[Thu Sep 17 15:25:34.906924 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxazm65wm-f4uX16X5zGwAAAB0"]
[Thu Sep 17 15:25:34.951085 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.154.237.242:50760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/qa/phpinfo.php"] [unique_id "aqxazm65wm-f4uX16X5zIAAAAF4"]
[Thu Sep 17 15:25:34.951472 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxazm65wm-f4uX16X5zIQAAAGs"]
[Thu Sep 17 15:25:34.958611 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/deploy/.env"] [unique_id "aqxazm65wm-f4uX16X5zIgAAADY"]
[Thu Sep 17 15:25:34.978818 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxazm65wm-f4uX16X5zIwAAAG0"]
[Thu Sep 17 15:25:35.081297 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.166.217.178:49692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxaz265wm-f4uX16X5zJQAAADo"]
[Thu Sep 17 15:25:35.081320 2026] [security2:error] [pid 1029697:tid 1029891] [client 169.58.197.253:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxaz265wm-f4uX16X5zJwAAAEA"], referer: binance.com
[Thu Sep 17 15:25:35.082967 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxaz265wm-f4uX16X5zJgAAACk"]
[Thu Sep 17 15:25:35.134713 2026] [security2:error] [pid 1029697:tid 1029866] [client 114.198.138.124:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaz265wm-f4uX16X5zKAAAACc"]
[Thu Sep 17 15:25:35.134816 2026] [security2:error] [pid 1029697:tid 1029866] [client 114.198.138.124:56547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxaz265wm-f4uX16X5zKAAAACc"]
[Thu Sep 17 15:25:35.135831 2026] [security2:error] [pid 1029697:tid 1029899] [client 8.231.55.47:38836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxaz265wm-f4uX16X5zKQAAAEg"]
[Thu Sep 17 15:25:35.170289 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxaz265wm-f4uX16X5zKgAAAE8"]
[Thu Sep 17 15:25:35.236655 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxaz265wm-f4uX16X5zLQAAABQ"]
[Thu Sep 17 15:25:35.282004 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/build/.env"] [unique_id "aqxaz265wm-f4uX16X5zLwAAAA8"]
[Thu Sep 17 15:25:35.390324 2026] [security2:error] [pid 1029697:tid 1029917] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxaz265wm-f4uX16X5zMgAAAFo"]
[Thu Sep 17 15:25:35.406312 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/dist/.env"] [unique_id "aqxaz265wm-f4uX16X5zMwAAAHQ"]
[Thu Sep 17 15:25:35.472968 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.237.242:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/preview/phpinfo.php"] [unique_id "aqxaz265wm-f4uX16X5zNgAAADc"]
[Thu Sep 17 15:25:35.508588 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxaz265wm-f4uX16X5zNwAAACQ"]
[Thu Sep 17 15:25:35.570063 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxaz265wm-f4uX16X5zOQAAAFY"]
[Thu Sep 17 15:25:35.593543 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxaz265wm-f4uX16X5zOgAAADI"]
[Thu Sep 17 15:25:35.633484 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxaz265wm-f4uX16X5zOwAAABc"]
[Thu Sep 17 15:25:35.641023 2026] [security2:error] [pid 1029697:tid 1029831] [client 45.65.158.68:5544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxaz265wm-f4uX16X5zOAAABEo"]
[Thu Sep 17 15:25:35.649906 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/public_html/.env"] [unique_id "aqxaz265wm-f4uX16X5zPAAAAEc"]
[Thu Sep 17 15:25:35.688143 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxaz265wm-f4uX16X5zPQAAAAw"]
[Thu Sep 17 15:25:35.746834 2026] [security2:error] [pid 1029697:tid 1029886] [client 156.192.234.52:64574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaz265wm-f4uX16X5zQAAAADs"]
[Thu Sep 17 15:25:35.748203 2026] [security2:error] [pid 1029697:tid 1029886] [client 156.192.234.52:64574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxaz265wm-f4uX16X5zQAAAADs"]
[Thu Sep 17 15:25:35.773021 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/htdocs/.env"] [unique_id "aqxaz265wm-f4uX16X5zQgAAAAs"]
[Thu Sep 17 15:25:35.791138 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.166.217.178:47984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxaz265wm-f4uX16X5zRAAAAGQ"]
[Thu Sep 17 15:25:35.880059 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxaz265wm-f4uX16X5zRQAAACg"]
[Thu Sep 17 15:25:35.910866 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/www/.env"] [unique_id "aqxaz265wm-f4uX16X5zRgAAACs"]
[Thu Sep 17 15:25:35.924257 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxaz265wm-f4uX16X5zRwAAADU"]
[Thu Sep 17 15:25:35.976175 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.154.237.242:50784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/www/phpinfo.php"] [unique_id "aqxaz265wm-f4uX16X5zSAAAAEw"]
[Thu Sep 17 15:25:36.036918 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/html/.env"] [unique_id "aqxa0G65wm-f4uX16X5zSgAAAGg"]
[Thu Sep 17 15:25:36.072437 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxa0G65wm-f4uX16X5zSwAAAFQ"]
[Thu Sep 17 15:25:36.161765 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/live/.env"] [unique_id "aqxa0G65wm-f4uX16X5zTAAAAHc"]
[Thu Sep 17 15:25:36.244126 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxa0G65wm-f4uX16X5zTQAAAFE"]
[Thu Sep 17 15:25:36.299139 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/prod/.env"] [unique_id "aqxa0G65wm-f4uX16X5zUAAAAHY"]
[Thu Sep 17 15:25:36.310618 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxa0G65wm-f4uX16X5zUQAAAE4"]
[Thu Sep 17 15:25:36.383852 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxa0G65wm-f4uX16X5zUwAAABk"]
[Thu Sep 17 15:25:36.414946 2026] [security2:error] [pid 1029697:tid 1029937] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxa0G65wm-f4uX16X5zVAAAAG4"]
[Thu Sep 17 15:25:36.425404 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/dev/.env"] [unique_id "aqxa0G65wm-f4uX16X5zVQAAAHU"]
[Thu Sep 17 15:25:36.449371 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.154.237.242:50792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxa0G65wm-f4uX16X5zVwAAADw"]
[Thu Sep 17 15:25:36.475160 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.166.217.178:47994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxa0G65wm-f4uX16X5zWAAAAEs"]
[Thu Sep 17 15:25:36.495000 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxa0G65wm-f4uX16X5zWQAAAEU"]
[Thu Sep 17 15:25:36.525710 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxa0G65wm-f4uX16X5zWwAAAB4"]
[Thu Sep 17 15:25:36.545704 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/staging/.env"] [unique_id "aqxa0G65wm-f4uX16X5zXgAAAAU"]
[Thu Sep 17 15:25:36.583488 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxa0G65wm-f4uX16X5zYgAAAA0"]
[Thu Sep 17 15:25:36.652303 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxa0G65wm-f4uX16X5zZAAAADA"]
[Thu Sep 17 15:25:36.670095 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/opt/.env"] [unique_id "aqxa0G65wm-f4uX16X5zZQAAAF0"]
[Thu Sep 17 15:25:36.678468 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.94.35.161:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxa0G65wm-f4uX16X5zZgAAACo"]
[Thu Sep 17 15:25:36.792865 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/laravel/.env"] [unique_id "aqxa0G65wm-f4uX16X5zagAAAEY"]
[Thu Sep 17 15:25:36.915225 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/symfony/.env"] [unique_id "aqxa0G65wm-f4uX16X5zbAAAAGo"]
[Thu Sep 17 15:25:36.939944 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxa0G65wm-f4uX16X5zbQAAAC8"]
[Thu Sep 17 15:25:36.941621 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.154.237.242:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/public_html/phpinfo.php"] [unique_id "aqxa0G65wm-f4uX16X5zbgAAACk"]
[Thu Sep 17 15:25:36.968028 2026] [security2:error] [pid 1029697:tid 1029899] [client 5.189.145.112:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxa0G65wm-f4uX16X5zbwAAAEg"], referer: binance.com
[Thu Sep 17 15:25:36.981450 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxa0G65wm-f4uX16X5zcAAAAGA"]
[Thu Sep 17 15:25:37.073415 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/wordpress/.env"] [unique_id "aqxa0W65wm-f4uX16X5zcQAAAEo"]
[Thu Sep 17 15:25:37.152942 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.166.217.178:48000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxa0W65wm-f4uX16X5zcgAAACc"]
[Thu Sep 17 15:25:37.198532 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/wp/.env"] [unique_id "aqxa0W65wm-f4uX16X5zcwAAAHw"]
[Thu Sep 17 15:25:37.233881 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxa0W65wm-f4uX16X5zdAAAACA"]
[Thu Sep 17 15:25:37.250227 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxa0W65wm-f4uX16X5zdQAAAFM"]
[Thu Sep 17 15:25:37.324922 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/cms/.env"] [unique_id "aqxa0W65wm-f4uX16X5zegAAAAc"]
[Thu Sep 17 15:25:37.377558 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxa0W65wm-f4uX16X5zewAAACQ"]
[Thu Sep 17 15:25:37.393136 2026] [security2:error] [pid 1029697:tid 1029847] [client 185.55.149.49:63253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa0W65wm-f4uX16X5zfAAAABQ"]
[Thu Sep 17 15:25:37.393253 2026] [security2:error] [pid 1029697:tid 1029847] [client 185.55.149.49:63253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa0W65wm-f4uX16X5zfAAAABQ"]
[Thu Sep 17 15:25:37.431749 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.237.242:50806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/site/phpinfo.php"] [unique_id "aqxa0W65wm-f4uX16X5zfQAAABI"]
[Thu Sep 17 15:25:37.447563 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxa0W65wm-f4uX16X5zfgAAAHI"]
[Thu Sep 17 15:25:37.462586 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.97.29.237:41690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/drupal/.env"] [unique_id "aqxa0W65wm-f4uX16X5zfwAAAGI"]
[Thu Sep 17 15:25:37.572376 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxa0W65wm-f4uX16X5zgAAAABY"]
[Thu Sep 17 15:25:37.625831 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxa0W65wm-f4uX16X5zgQAAAAw"]
[Thu Sep 17 15:25:37.765452 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxa0W65wm-f4uX16X5zhAAAADk"]
[Thu Sep 17 15:25:37.828007 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.166.217.178:48010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxa0W65wm-f4uX16X5zhgAAAEc"]
[Thu Sep 17 15:25:37.836784 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/joomla/.env"] [unique_id "aqxa0W65wm-f4uX16X5ziAAAAAs"]
[Thu Sep 17 15:25:37.877003 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxa0W65wm-f4uX16X5zigAAADU"]
[Thu Sep 17 15:25:37.955258 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.154.237.242:50812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/docs/phpinfo.php"] [unique_id "aqxa0W65wm-f4uX16X5ziwAAAGY"]
[Thu Sep 17 15:25:37.971005 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/magento/.env"] [unique_id "aqxa0W65wm-f4uX16X5zjAAAAGE"]
[Thu Sep 17 15:25:37.994298 2026] [security2:error] [pid 1029697:tid 1029903] [client 4.240.114.86:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxa0W65wm-f4uX16X5zjgAAAEw"], referer: binance.com
[Thu Sep 17 15:25:38.051186 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxa0m65wm-f4uX16X5zjwAAAFc"]
[Thu Sep 17 15:25:38.086915 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxa0m65wm-f4uX16X5zkAAAAFU"]
[Thu Sep 17 15:25:38.098514 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/shopify/.env"] [unique_id "aqxa0m65wm-f4uX16X5zkQAAAFs"]
[Thu Sep 17 15:25:38.118016 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxa0m65wm-f4uX16X5zkgAAACE"]
[Thu Sep 17 15:25:38.221003 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxa0m65wm-f4uX16X5zlAAAAB8"]
[Thu Sep 17 15:25:38.223142 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/prestashop/.env"] [unique_id "aqxa0m65wm-f4uX16X5zlQAAAHk"]
[Thu Sep 17 15:25:38.257105 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxa0m65wm-f4uX16X5zlwAAAFQ"]
[Thu Sep 17 15:25:38.292997 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxa0m65wm-f4uX16X5zmAAAAAE"]
[Thu Sep 17 15:25:38.329793 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxa0m65wm-f4uX16X5zmQAAAHc"]
[Thu Sep 17 15:25:38.350985 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/codeigniter/.env"] [unique_id "aqxa0m65wm-f4uX16X5zmgAAAFE"]
[Thu Sep 17 15:25:38.451808 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxa0m65wm-f4uX16X5znQAAAGM"]
[Thu Sep 17 15:25:38.481882 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.154.237.242:50816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxa0m65wm-f4uX16X5zngAAAC0"]
[Thu Sep 17 15:25:38.504301 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/cakephp/.env"] [unique_id "aqxa0m65wm-f4uX16X5znwAAAFI"]
[Thu Sep 17 15:25:38.532193 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.166.217.178:48018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxa0m65wm-f4uX16X5zoQAAAEk"]
[Thu Sep 17 15:25:38.576280 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxa0m65wm-f4uX16X5zpQAAAEs"]
[Thu Sep 17 15:25:38.627938 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/zend/.env"] [unique_id "aqxa0m65wm-f4uX16X5zpwAAAFk"]
[Thu Sep 17 15:25:38.652847 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxa0m65wm-f4uX16X5zqAAAAA4"]
[Thu Sep 17 15:25:38.679296 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxa0m65wm-f4uX16X5zqQAAAFw"]
[Thu Sep 17 15:25:38.754225 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/yii/.env"] [unique_id "aqxa0m65wm-f4uX16X5zrAAAADA"]
[Thu Sep 17 15:25:38.765487 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxa0m65wm-f4uX16X5zrQAAAB0"]
[Thu Sep 17 15:25:38.857453 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxa0m65wm-f4uX16X5zrgAAAH4"]
[Thu Sep 17 15:25:38.882787 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/laravel5/.env"] [unique_id "aqxa0m65wm-f4uX16X5zrwAAAF4"]
[Thu Sep 17 15:25:38.982289 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxa0m65wm-f4uX16X5ztAAAAEY"]
[Thu Sep 17 15:25:39.016683 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/v1/.env"] [unique_id "aqxa0265wm-f4uX16X5ztgAAADQ"]
[Thu Sep 17 15:25:39.024994 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.154.237.242:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/administrator/phpinfo.php"] [unique_id "aqxa0265wm-f4uX16X5ztwAAACo"]
[Thu Sep 17 15:25:39.079980 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxa0265wm-f4uX16X5zuAAAABo"]
[Thu Sep 17 15:25:39.141085 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/v2/.env"] [unique_id "aqxa0265wm-f4uX16X5zvQAAAEg"]
[Thu Sep 17 15:25:39.207437 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.166.217.178:48020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxa0265wm-f4uX16X5zvwAAACM"]
[Thu Sep 17 15:25:39.262001 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/v3/.env"] [unique_id "aqxa0265wm-f4uX16X5zwAAAADo"]
[Thu Sep 17 15:25:39.285106 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxa0265wm-f4uX16X5zvgAAAGA"]
[Thu Sep 17 15:25:39.388149 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/api/v1/.env"] [unique_id "aqxa0265wm-f4uX16X5zxAAAABE"]
[Thu Sep 17 15:25:39.479428 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxa0265wm-f4uX16X5zyQAAACQ"]
[Thu Sep 17 15:25:39.519260 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/api/v2/.env"] [unique_id "aqxa0265wm-f4uX16X5zygAAAHs"]
[Thu Sep 17 15:25:39.549180 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.237.242:50842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/core/phpinfo.php"] [unique_id "aqxa0265wm-f4uX16X5zywAAAD8"]
[Thu Sep 17 15:25:39.552973 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxa0265wm-f4uX16X5zzAAAAGU"]
[Thu Sep 17 15:25:39.655026 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.94.35.161:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxa0265wm-f4uX16X5zzwAAAGI"]
[Thu Sep 17 15:25:39.667888 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/rest/.env"] [unique_id "aqxa0265wm-f4uX16X5z0AAAABg"]
[Thu Sep 17 15:25:39.792690 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/graphql/.env"] [unique_id "aqxa0265wm-f4uX16X5z1QAAADk"]
[Thu Sep 17 15:25:39.808126 2026] [core:error] [pid 1029697:tid 1029907] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:39.808149 2026] [core:error] [pid 1029697:tid 1029907] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:39.896166 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.166.217.178:48034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxa0265wm-f4uX16X5z2AAAABY"]
[Thu Sep 17 15:25:39.914385 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/gateway/.env"] [unique_id "aqxa0265wm-f4uX16X5z2QAAAFs"]
[Thu Sep 17 15:25:40.044407 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/microservice/.env"] [unique_id "aqxa1G65wm-f4uX16X5z3AAAADg"]
[Thu Sep 17 15:25:40.064448 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.154.237.242:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.237.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.tab-funkenwerk.org"] [uri "/includes/phpinfo.php"] [unique_id "aqxa1G65wm-f4uX16X5z3QAAABU"]
[Thu Sep 17 15:25:40.165916 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/service/.env"] [unique_id "aqxa1G65wm-f4uX16X5z3wAAAAE"]
[Thu Sep 17 15:25:40.245513 2026] [security2:error] [pid 1029697:tid 1029868] [client 43.157.53.115:56266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.freeofgravity.com"] [uri "/index.php"] [unique_id "aqxa0265wm-f4uX16X5zuwAAACk"]
[Thu Sep 17 15:25:40.290081 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/api/v3/.env"] [unique_id "aqxa1G65wm-f4uX16X5z4QAAAC4"]
[Thu Sep 17 15:25:40.422714 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/api/dev/.env"] [unique_id "aqxa1G65wm-f4uX16X5z5wAAAFI"]
[Thu Sep 17 15:25:40.472238 2026] [core:error] [pid 1029697:tid 1029867] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:40.472257 2026] [core:error] [pid 1029697:tid 1029867] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:40.547192 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/api/staging/.env"] [unique_id "aqxa1G65wm-f4uX16X5z7AAAAA0"]
[Thu Sep 17 15:25:40.585407 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.166.217.178:48040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxa1G65wm-f4uX16X5z8AAAAHg"]
[Thu Sep 17 15:25:40.659978 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxa1G65wm-f4uX16X5z8gAAADA"]
[Thu Sep 17 15:25:40.671824 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/vendor/.env"] [unique_id "aqxa1G65wm-f4uX16X5z8wAAAF0"]
[Thu Sep 17 15:25:40.726606 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxa1G65wm-f4uX16X5z9AAAABk"]
[Thu Sep 17 15:25:40.784453 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxa1G65wm-f4uX16X5z9QAAAEI"]
[Thu Sep 17 15:25:40.795464 2026] [security2:error] [pid 1029697:tid 1029892] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/lib/.env"] [unique_id "aqxa1G65wm-f4uX16X5z9wAAAEE"]
[Thu Sep 17 15:25:40.922099 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/resources/.env"] [unique_id "aqxa1G65wm-f4uX16X5z-gAAAAA"]
[Thu Sep 17 15:25:40.930929 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxa1G65wm-f4uX16X5z-wAAADM"]
[Thu Sep 17 15:25:40.947092 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxa1G65wm-f4uX16X5z_AAAABo"]
[Thu Sep 17 15:25:41.026784 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxa1W65wm-f4uX16X50AQAAAEo"]
[Thu Sep 17 15:25:41.043775 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/assets/.env"] [unique_id "aqxa1W65wm-f4uX16X50AwAAADo"]
[Thu Sep 17 15:25:41.095934 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxa1W65wm-f4uX16X50BwAAAHQ"]
[Thu Sep 17 15:25:41.164412 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/uploads/.env"] [unique_id "aqxa1W65wm-f4uX16X50DgAAAAc"]
[Thu Sep 17 15:25:41.234334 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxa1W65wm-f4uX16X50FQAAABw"]
[Thu Sep 17 15:25:41.269871 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.166.217.178:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxa1W65wm-f4uX16X50FgAAAGs"]
[Thu Sep 17 15:25:41.276484 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxa1W65wm-f4uX16X50FwAAADk"]
[Thu Sep 17 15:25:41.285394 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/internal/.env"] [unique_id "aqxa1W65wm-f4uX16X50GAAAACw"]
[Thu Sep 17 15:25:41.308079 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxa1W65wm-f4uX16X50GQAAAFA"]
[Thu Sep 17 15:25:41.389518 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxa1W65wm-f4uX16X50GwAAAEU"]
[Thu Sep 17 15:25:41.407376 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/tools/.env"] [unique_id "aqxa1W65wm-f4uX16X50HAAAAGY"]
[Thu Sep 17 15:25:41.506807 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxa1W65wm-f4uX16X50IgAAACA"]
[Thu Sep 17 15:25:41.526447 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxa1W65wm-f4uX16X50IwAAAAk"]
[Thu Sep 17 15:25:41.528022 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/scripts/.env"] [unique_id "aqxa1W65wm-f4uX16X50JAAAAEA"]
[Thu Sep 17 15:25:41.546137 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxa1W65wm-f4uX16X50JQAAAFU"]
[Thu Sep 17 15:25:41.648982 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/bin/.env"] [unique_id "aqxa1W65wm-f4uX16X50KwAAAGc"]
[Thu Sep 17 15:25:41.683068 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxa1W65wm-f4uX16X50LgAAADg"]
[Thu Sep 17 15:25:41.733916 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxa1W65wm-f4uX16X50LwAAAAE"]
[Thu Sep 17 15:25:41.770325 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/sbin/.env"] [unique_id "aqxa1W65wm-f4uX16X50MAAAAAI"]
[Thu Sep 17 15:25:41.789922 2026] [security2:error] [pid 1029697:tid 1029904] [client 4.240.114.86:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxa1W65wm-f4uX16X50MgAAAE0"], referer: binance.com
[Thu Sep 17 15:25:41.790554 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxa1W65wm-f4uX16X50MQAAAHc"]
[Thu Sep 17 15:25:41.891005 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/local/.env"] [unique_id "aqxa1W65wm-f4uX16X50NwAAAAU"]
[Thu Sep 17 15:25:41.951799 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.166.217.178:48046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxa1W65wm-f4uX16X50OQAAABU"]
[Thu Sep 17 15:25:41.990716 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxa1W65wm-f4uX16X50OwAAADc"]
[Thu Sep 17 15:25:42.012083 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/portal/.env"] [unique_id "aqxa1m65wm-f4uX16X50PgAAAA0"]
[Thu Sep 17 15:25:42.121559 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxa1m65wm-f4uX16X50RAAAABk"]
[Thu Sep 17 15:25:42.138515 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/dashboard/.env"] [unique_id "aqxa1m65wm-f4uX16X50RQAAAEI"]
[Thu Sep 17 15:25:42.249328 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxa1m65wm-f4uX16X50SAAAAD0"]
[Thu Sep 17 15:25:42.259206 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/panel/.env"] [unique_id "aqxa1m65wm-f4uX16X50SgAAAB4"]
[Thu Sep 17 15:25:42.298357 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxa1m65wm-f4uX16X50TgAAADM"]
[Thu Sep 17 15:25:42.367574 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxa1m65wm-f4uX16X50TwAAABs"]
[Thu Sep 17 15:25:42.380610 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/crm/.env"] [unique_id "aqxa1m65wm-f4uX16X50UAAAADo"]
[Thu Sep 17 15:25:42.503485 2026] [security2:error] [pid 1029697:tid 1029917] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/erp/.env"] [unique_id "aqxa1m65wm-f4uX16X50VwAAAFo"]
[Thu Sep 17 15:25:42.533562 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxa1m65wm-f4uX16X50WQAAAD8"]
[Thu Sep 17 15:25:42.635555 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.166.217.178:48050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxa1m65wm-f4uX16X50XAAAAAM"]
[Thu Sep 17 15:25:42.636388 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/shop/.env"] [unique_id "aqxa1m65wm-f4uX16X50WwAAABg"]
[Thu Sep 17 15:25:42.689997 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxa1m65wm-f4uX16X50XwAAAAw"]
[Thu Sep 17 15:25:42.767199 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/store/.env"] [unique_id "aqxa1m65wm-f4uX16X50ZAAAAGs"]
[Thu Sep 17 15:25:42.809402 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxa1m65wm-f4uX16X50ZwAAAH0"]
[Thu Sep 17 15:25:42.874979 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxa1m65wm-f4uX16X50agAAABM"]
[Thu Sep 17 15:25:42.889494 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/saas/.env"] [unique_id "aqxa1m65wm-f4uX16X50bQAAAGE"]
[Thu Sep 17 15:25:42.951716 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxa1m65wm-f4uX16X50cgAAAFU"]
[Thu Sep 17 15:25:42.984499 2026] [security2:error] [pid 1029697:tid 1029883] [client 169.58.197.253:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxa1m65wm-f4uX16X50dQAAADg"], referer: binance.com
[Thu Sep 17 15:25:43.012106 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/client/.env"] [unique_id "aqxa1265wm-f4uX16X50dwAAAGg"]
[Thu Sep 17 15:25:43.099996 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxa1265wm-f4uX16X50eQAAAE0"]
[Thu Sep 17 15:25:43.126530 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxa1265wm-f4uX16X50egAAAHc"]
[Thu Sep 17 15:25:43.133423 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/project/.env"] [unique_id "aqxa1265wm-f4uX16X50fgAAAB8"]
[Thu Sep 17 15:25:43.227181 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxa1265wm-f4uX16X50fwAAAFc"]
[Thu Sep 17 15:25:43.254417 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/admin-panel/.env"] [unique_id "aqxa1265wm-f4uX16X50gAAAACY"]
[Thu Sep 17 15:25:43.275637 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxa1265wm-f4uX16X50gQAAAG8"]
[Thu Sep 17 15:25:43.316999 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.166.217.178:48066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxa1265wm-f4uX16X50ggAAACk"]
[Thu Sep 17 15:25:43.330675 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxa1265wm-f4uX16X50gwAAAFI"]
[Thu Sep 17 15:25:43.366896 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxa1265wm-f4uX16X50hwAAAFk"]
[Thu Sep 17 15:25:43.376082 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/control-panel/.env"] [unique_id "aqxa1265wm-f4uX16X50iQAAAA0"]
[Thu Sep 17 15:25:43.460404 2026] [security2:error] [pid 1029697:tid 1029828] [client 154.190.208.131:41892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa1265wm-f4uX16X50iwAAAAE"]
[Thu Sep 17 15:25:43.469719 2026] [security2:error] [pid 1029697:tid 1029828] [client 154.190.208.131:41892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa1265wm-f4uX16X50iwAAAAE"]
[Thu Sep 17 15:25:43.496553 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/user-panel/.env"] [unique_id "aqxa1265wm-f4uX16X50jgAAABk"]
[Thu Sep 17 15:25:43.510638 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxa1265wm-f4uX16X50jwAAAEI"]
[Thu Sep 17 15:25:43.551904 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxa1265wm-f4uX16X50kAAAAD0"]
[Thu Sep 17 15:25:43.606059 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxa1265wm-f4uX16X50lgAAADM"]
[Thu Sep 17 15:25:43.617316 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/node/.env"] [unique_id "aqxa1265wm-f4uX16X50lwAAAEY"]
[Thu Sep 17 15:25:43.700828 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxa1265wm-f4uX16X50mQAAADo"]
[Thu Sep 17 15:25:43.749352 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/express/.env"] [unique_id "aqxa1265wm-f4uX16X50mgAAADY"]
[Thu Sep 17 15:25:43.771814 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxa1265wm-f4uX16X50mwAAAEo"]
[Thu Sep 17 15:25:43.828481 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxa1265wm-f4uX16X50nAAAAGQ"]
[Thu Sep 17 15:25:43.873504 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/next/.env"] [unique_id "aqxa1265wm-f4uX16X50ngAAAFE"]
[Thu Sep 17 15:25:43.923362 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.18.173.5:47850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hym.qby.mybluehost.me"] [uri "/"] [unique_id "aqxa1265wm-f4uX16X50oQAAAEM"]
[Thu Sep 17 15:25:43.942486 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxa1265wm-f4uX16X50ogAAAAM"]
[Thu Sep 17 15:25:43.994648 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/nuxt/.env"] [unique_id "aqxa1265wm-f4uX16X50pQAAACs"]
[Thu Sep 17 15:25:44.001511 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.166.217.178:48076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxa2G65wm-f4uX16X50pgAAAAY"]
[Thu Sep 17 15:25:44.117769 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/nest/.env"] [unique_id "aqxa2G65wm-f4uX16X50qgAAADE"]
[Thu Sep 17 15:25:44.128563 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxa2G65wm-f4uX16X50rwAAACc"]
[Thu Sep 17 15:25:44.183130 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxa2G65wm-f4uX16X50sgAAAHM"]
[Thu Sep 17 15:25:44.217324 2026] [security2:error] [pid 1029697:tid 1029951] [client 192.178.6.4:58304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxa2G65wm-f4uX16X50swAAAHw"]
[Thu Sep 17 15:25:44.238652 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/react/.env"] [unique_id "aqxa2G65wm-f4uX16X50tAAAADU"]
[Thu Sep 17 15:25:44.265989 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxa2G65wm-f4uX16X50tQAAAGU"]
[Thu Sep 17 15:25:44.322758 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxa2G65wm-f4uX16X50tgAAAAQ"]
[Thu Sep 17 15:25:44.376793 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/vue/.env"] [unique_id "aqxa2G65wm-f4uX16X50twAAACA"]
[Thu Sep 17 15:25:44.422683 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxa2G65wm-f4uX16X50uAAAAEA"]
[Thu Sep 17 15:25:44.472166 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxa2G65wm-f4uX16X50ugAAABY"]
[Thu Sep 17 15:25:44.499125 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/angular/.env"] [unique_id "aqxa2G65wm-f4uX16X50vQAAADg"]
[Thu Sep 17 15:25:44.520779 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxa2G65wm-f4uX16X50vgAAAGg"]
[Thu Sep 17 15:25:44.551538 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxa2G65wm-f4uX16X50vwAAAFg"]
[Thu Sep 17 15:25:44.635582 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/svelte/.env"] [unique_id "aqxa2G65wm-f4uX16X50wQAAAAI"]
[Thu Sep 17 15:25:44.643646 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.18.173.5:38358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hym.qby.mybluehost.me"] [uri "/"] [unique_id "aqxa2G65wm-f4uX16X50wgAAABE"]
[Thu Sep 17 15:25:44.688028 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.166.217.178:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxa2G65wm-f4uX16X50xAAAAFU"]
[Thu Sep 17 15:25:44.688234 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxa2G65wm-f4uX16X50wwAAAE0"]
[Thu Sep 17 15:25:44.754516 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxa2G65wm-f4uX16X50xQAAAHc"]
[Thu Sep 17 15:25:44.761194 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/vite/.env"] [unique_id "aqxa2G65wm-f4uX16X50xgAAAFQ"]
[Thu Sep 17 15:25:44.831080 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxa2G65wm-f4uX16X50xwAAAFc"]
[Thu Sep 17 15:25:44.850311 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxa2G65wm-f4uX16X50yAAAACY"]
[Thu Sep 17 15:25:44.889761 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/backup/.env"] [unique_id "aqxa2G65wm-f4uX16X50ygAAAHo"]
[Thu Sep 17 15:25:44.889764 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxa2G65wm-f4uX16X50yQAAAEw"]
[Thu Sep 17 15:25:45.016130 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/backups/.env"] [unique_id "aqxa2W65wm-f4uX16X50zQAAACk"]
[Thu Sep 17 15:25:45.102568 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxa2W65wm-f4uX16X50zwAAADc"]
[Thu Sep 17 15:25:45.140913 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/old/.env"] [unique_id "aqxa2W65wm-f4uX16X500AAAAF8"]
[Thu Sep 17 15:25:45.153809 2026] [security2:error] [pid 1029697:tid 1029864] [client 103.61.184.148:60730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa2W65wm-f4uX16X500QAAACU"]
[Thu Sep 17 15:25:45.153917 2026] [security2:error] [pid 1029697:tid 1029864] [client 103.61.184.148:60730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa2W65wm-f4uX16X500QAAACU"]
[Thu Sep 17 15:25:45.212218 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxa2W65wm-f4uX16X500gAAAGM"]
[Thu Sep 17 15:25:45.271694 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/tmp/.env"] [unique_id "aqxa2W65wm-f4uX16X501QAAAD0"]
[Thu Sep 17 15:25:45.291818 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxa2W65wm-f4uX16X501gAAADk"]
[Thu Sep 17 15:25:45.325840 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxa2W65wm-f4uX16X501wAAAE4"]
[Thu Sep 17 15:25:45.361470 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.18.173.5:38368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hym.qby.mybluehost.me"] [uri "/"] [unique_id "aqxa2W65wm-f4uX16X502gAAAA0"]
[Thu Sep 17 15:25:45.369269 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.166.217.178:60150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxa2W65wm-f4uX16X502wAAABU"]
[Thu Sep 17 15:25:45.398184 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/temp/.env"] [unique_id "aqxa2W65wm-f4uX16X503QAAAHI"]
[Thu Sep 17 15:25:45.480635 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxa2W65wm-f4uX16X503wAAADM"]
[Thu Sep 17 15:25:45.520997 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/lab/.env"] [unique_id "aqxa2W65wm-f4uX16X504gAAAEY"]
[Thu Sep 17 15:25:45.542342 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxa2W65wm-f4uX16X505AAAAFY"]
[Thu Sep 17 15:25:45.588161 2026] [security2:error] [pid 1029697:tid 1029841] [client 4.240.114.86:49192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxa2W65wm-f4uX16X505wAAAA4"], referer: binance.com
[Thu Sep 17 15:25:45.623163 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxa2W65wm-f4uX16X506gAAAA8"]
[Thu Sep 17 15:25:45.651958 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/cronlab/.env"] [unique_id "aqxa2W65wm-f4uX16X507AAAABA"]
[Thu Sep 17 15:25:45.728250 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.94.35.161:39164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.lasvegaslife.info"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxa2W65wm-f4uX16X508QAAADY"]
[Thu Sep 17 15:25:45.768377 2026] [security2:error] [pid 1029697:tid 1029939] [client 114.198.138.124:59464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa2W65wm-f4uX16X509AAAAHA"]
[Thu Sep 17 15:25:45.768868 2026] [security2:error] [pid 1029697:tid 1029939] [client 114.198.138.124:59464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa2W65wm-f4uX16X509AAAAHA"]
[Thu Sep 17 15:25:45.785907 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/cron/.env"] [unique_id "aqxa2W65wm-f4uX16X509QAAADA"]
[Thu Sep 17 15:25:45.834041 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.94.35.161:39164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/phpinfo.php"] [unique_id "aqxa2W65wm-f4uX16X50-AAAAC0"]
[Thu Sep 17 15:25:45.851678 2026] [security2:error] [pid 1029697:tid 1029950] [client 16.216.88.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brownsdailydose.com"] [uri "/index.php"] [unique_id "aqxa2W65wm-f4uX16X506AAAAHs"]
[Thu Sep 17 15:25:45.917874 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/en/.env"] [unique_id "aqxa2W65wm-f4uX16X50-QAAAHM"]
[Thu Sep 17 15:25:46.063394 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.166.217.178:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxa2m65wm-f4uX16X50_wAAACM"]
[Thu Sep 17 15:25:46.123419 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.94.35.161:38654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/info.php"] [unique_id "aqxa2m65wm-f4uX16X51AgAAAEc"]
[Thu Sep 17 15:25:46.142280 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/administrator/.env"] [unique_id "aqxa2m65wm-f4uX16X50_gAAAFs"]
[Thu Sep 17 15:25:46.268145 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/psnlink/.env"] [unique_id "aqxa2m65wm-f4uX16X51CgAAAE0"]
[Thu Sep 17 15:25:46.279766 2026] [security2:error] [pid 1029697:tid 1029866] [client 156.192.234.52:65181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa2m65wm-f4uX16X51CwAAACc"]
[Thu Sep 17 15:25:46.280165 2026] [security2:error] [pid 1029697:tid 1029866] [client 156.192.234.52:65181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa2m65wm-f4uX16X51CwAAACc"]
[Thu Sep 17 15:25:46.293789 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa2m65wm-f4uX16X51AwAAAEQ"]
[Thu Sep 17 15:25:46.306808 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.94.35.161:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/php.php"] [unique_id "aqxa2m65wm-f4uX16X51DAAAAAI"]
[Thu Sep 17 15:25:46.394079 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/exapi/.env"] [unique_id "aqxa2m65wm-f4uX16X51DgAAACg"]
[Thu Sep 17 15:25:46.444829 2026] [security2:error] [pid 1029697:tid 1029849] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxa2m65wm-f4uX16X51CQAAABY"]
[Thu Sep 17 15:25:46.517164 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/sitemaps/.env"] [unique_id "aqxa2m65wm-f4uX16X51EwAAAAw"]
[Thu Sep 17 15:25:46.550935 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.18.173.5:38378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hym.qby.mybluehost.me"] [uri "/"] [unique_id "aqxa2m65wm-f4uX16X51FAAAAAE"]
[Thu Sep 17 15:25:46.706574 2026] [security2:error] [pid 1029697:tid 1029888] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxa2m65wm-f4uX16X51FwAAAD0"]
[Thu Sep 17 15:25:46.748453 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.166.217.178:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxa2m65wm-f4uX16X51HwAAAGM"]
[Thu Sep 17 15:25:46.786728 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.94.35.161:38664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/i.php"] [unique_id "aqxa2m65wm-f4uX16X51JQAAADk"]
[Thu Sep 17 15:25:46.901735 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/logs/.env"] [unique_id "aqxa2m65wm-f4uX16X51PAAAAFE"]
[Thu Sep 17 15:25:46.961326 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.94.35.161:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/pi.php"] [unique_id "aqxa2m65wm-f4uX16X51PQAAADA"]
[Thu Sep 17 15:25:47.021840 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/cache/.env"] [unique_id "aqxa2265wm-f4uX16X51RgAAAEg"]
[Thu Sep 17 15:25:47.143637 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mailer/.env"] [unique_id "aqxa2265wm-f4uX16X51SgAAAFs"]
[Thu Sep 17 15:25:47.169951 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.94.35.161:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/pinfo.php"] [unique_id "aqxa2265wm-f4uX16X51TAAAAEU"]
[Thu Sep 17 15:25:47.249716 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/.env"] [unique_id "aqxa2265wm-f4uX16X51TwAAAHw"]
[Thu Sep 17 15:25:47.264349 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mail/.env"] [unique_id "aqxa2265wm-f4uX16X51UQAAADg"]
[Thu Sep 17 15:25:47.386143 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.97.29.237:35796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/email/.env"] [unique_id "aqxa2265wm-f4uX16X51VAAAAB0"]
[Thu Sep 17 15:25:47.440524 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.166.217.178:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxa2265wm-f4uX16X51VQAAAHg"]
[Thu Sep 17 15:25:47.451515 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.94.35.161:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/test.php"] [unique_id "aqxa2265wm-f4uX16X51VgAAAFU"]
[Thu Sep 17 15:25:47.567015 2026] [security2:error] [pid 1029697:tid 1029847] [client 223.109.252.193:52836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.iradtech.com"] [uri "/robots.txt"] [unique_id "aqxa2265wm-f4uX16X51WwAAABQ"]
[Thu Sep 17 15:25:47.567154 2026] [security2:error] [pid 1029697:tid 1029847] [client 223.109.252.193:52836] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.iradtech.com"] [uri "/robots.txt"] [unique_id "aqxa2265wm-f4uX16X51WwAAABQ"]
[Thu Sep 17 15:25:47.666145 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa2265wm-f4uX16X51WgAAAAA"]
[Thu Sep 17 15:25:47.745410 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/smtp/.env"] [unique_id "aqxa2265wm-f4uX16X51YgAAABY"]
[Thu Sep 17 15:25:47.847693 2026] [core:error] [pid 1029697:tid 1029919] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:47.847721 2026] [core:error] [pid 1029697:tid 1029919] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:47.865433 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mailing/.env"] [unique_id "aqxa2265wm-f4uX16X51aQAAAE4"]
[Thu Sep 17 15:25:47.985074 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/notifications/.env"] [unique_id "aqxa2265wm-f4uX16X51cQAAABw"]
[Thu Sep 17 15:25:48.070215 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa2265wm-f4uX16X51bQAAAGM"]
[Thu Sep 17 15:25:48.105783 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/notify/.env"] [unique_id "aqxa3G65wm-f4uX16X51eAAAADo"]
[Thu Sep 17 15:25:48.126007 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.166.217.178:60180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxa3G65wm-f4uX16X51eQAAAD0"]
[Thu Sep 17 15:25:48.150827 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.94.35.161:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/p.php"] [unique_id "aqxa3G65wm-f4uX16X51fAAAAGw"]
[Thu Sep 17 15:25:48.156137 2026] [security2:error] [pid 1029697:tid 1029852] [client 185.55.149.49:63885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa3G65wm-f4uX16X51fQAAABk"]
[Thu Sep 17 15:25:48.156712 2026] [security2:error] [pid 1029697:tid 1029852] [client 185.55.149.49:63885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa3G65wm-f4uX16X51fQAAABk"]
[Thu Sep 17 15:25:48.226705 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/sender/.env"] [unique_id "aqxa3G65wm-f4uX16X51gQAAAGo"]
[Thu Sep 17 15:25:48.346428 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/campaign/.env"] [unique_id "aqxa3G65wm-f4uX16X51jgAAAF0"]
[Thu Sep 17 15:25:48.453260 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.94.35.161:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/debug.php"] [unique_id "aqxa3G65wm-f4uX16X51lwAAAGY"]
[Thu Sep 17 15:25:48.460657 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa3G65wm-f4uX16X51jwAAAEU"]
[Thu Sep 17 15:25:48.474818 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/newsletter/.env"] [unique_id "aqxa3G65wm-f4uX16X51mAAAAEo"]
[Thu Sep 17 15:25:48.596370 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/ses/.env"] [unique_id "aqxa3G65wm-f4uX16X51mQAAAFU"]
[Thu Sep 17 15:25:48.716953 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/sendgrid/.env"] [unique_id "aqxa3G65wm-f4uX16X51oQAAACY"]
[Thu Sep 17 15:25:48.807434 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.166.217.178:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxa3G65wm-f4uX16X51pwAAAAI"]
[Thu Sep 17 15:25:48.837721 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/sparkpost/.env"] [unique_id "aqxa3G65wm-f4uX16X51qAAAAAo"]
[Thu Sep 17 15:25:48.910909 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa3G65wm-f4uX16X51pgAAAFw"]
[Thu Sep 17 15:25:48.963610 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/postmark/.env"] [unique_id "aqxa3G65wm-f4uX16X51rAAAADI"]
[Thu Sep 17 15:25:49.084863 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mailgun/.env"] [unique_id "aqxa3W65wm-f4uX16X51sgAAAHA"]
[Thu Sep 17 15:25:49.103973 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.94.35.161:38716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/admin/phpinfo.php"] [unique_id "aqxa3W65wm-f4uX16X51tAAAABg"]
[Thu Sep 17 15:25:49.209895 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mandrill/.env"] [unique_id "aqxa3W65wm-f4uX16X51vwAAACs"]
[Thu Sep 17 15:25:49.326519 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa3W65wm-f4uX16X51vgAAAF0"]
[Thu Sep 17 15:25:49.330259 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mailjet/.env"] [unique_id "aqxa3W65wm-f4uX16X51wgAAAEc"]
[Thu Sep 17 15:25:49.376996 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.94.35.161:38728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/test/phpinfo.php"] [unique_id "aqxa3W65wm-f4uX16X51xgAAAEg"]
[Thu Sep 17 15:25:49.449588 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/brevo/.env"] [unique_id "aqxa3W65wm-f4uX16X511QAAAAU"]
[Thu Sep 17 15:25:49.496625 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.166.217.178:60202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxa3W65wm-f4uX16X511gAAAHY"]
[Thu Sep 17 15:25:49.568647 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/transactional/.env"] [unique_id "aqxa3W65wm-f4uX16X519gAAAEs"]
[Thu Sep 17 15:25:49.694374 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/bulk/.env"] [unique_id "aqxa3W65wm-f4uX16X51_QAAABw"]
[Thu Sep 17 15:25:49.735468 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa3W65wm-f4uX16X519wAAAFQ"]
[Thu Sep 17 15:25:49.740142 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.94.35.161:38732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/dev/phpinfo.php"] [unique_id "aqxa3W65wm-f4uX16X52AQAAACE"]
[Thu Sep 17 15:25:49.771599 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.44.233.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxa3W65wm-f4uX16X514wAAAB8"]
[Thu Sep 17 15:25:49.814543 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/aws/.env"] [unique_id "aqxa3W65wm-f4uX16X52AwAAABY"]
[Thu Sep 17 15:25:49.814950 2026] [security2:error] [pid 1029697:tid 1029873] [client 5.189.145.112:50569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxa3W65wm-f4uX16X52BAAAAC4"], referer: binance.com
[Thu Sep 17 15:25:49.936686 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/azure/.env"] [unique_id "aqxa3W65wm-f4uX16X52CwAAAAM"]
[Thu Sep 17 15:25:49.942597 2026] [security2:error] [pid 1029697:tid 1029834] [client 4.240.114.86:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxa3W65wm-f4uX16X52DAAAAAc"], referer: binance.com
[Thu Sep 17 15:25:49.989411 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxa3W65wm-f4uX16X52DQAAAAs"]
[Thu Sep 17 15:25:50.057023 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/gcp/.env"] [unique_id "aqxa3m65wm-f4uX16X52FwAAABc"]
[Thu Sep 17 15:25:50.081035 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.94.35.161:38746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/old/phpinfo.php"] [unique_id "aqxa3m65wm-f4uX16X52GgAAACs"]
[Thu Sep 17 15:25:50.178782 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/cloud/.env"] [unique_id "aqxa3m65wm-f4uX16X52HQAAACo"]
[Thu Sep 17 15:25:50.185484 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.166.217.178:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxa3m65wm-f4uX16X52HgAAAAY"]
[Thu Sep 17 15:25:50.222775 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxa3m65wm-f4uX16X52IQAAAHs"]
[Thu Sep 17 15:25:50.300727 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/infrastructure/.env"] [unique_id "aqxa3m65wm-f4uX16X52IwAAADM"]
[Thu Sep 17 15:25:50.344035 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.94.35.161:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/tmp/phpinfo.php"] [unique_id "aqxa3m65wm-f4uX16X52JQAAAH8"]
[Thu Sep 17 15:25:50.423188 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/docker/.env"] [unique_id "aqxa3m65wm-f4uX16X52KwAAAEM"]
[Thu Sep 17 15:25:50.544834 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/k8s/.env"] [unique_id "aqxa3m65wm-f4uX16X52PQAAAGE"]
[Thu Sep 17 15:25:50.609253 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa3m65wm-f4uX16X52OQAAAGI"]
[Thu Sep 17 15:25:50.670151 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/kubernetes/.env"] [unique_id "aqxa3m65wm-f4uX16X52TgAAAHA"]
[Thu Sep 17 15:25:50.790986 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/terraform/.env"] [unique_id "aqxa3m65wm-f4uX16X52XAAAAEo"]
[Thu Sep 17 15:25:50.803469 2026] [security2:error] [pid 1029697:tid 1029873] [client 52.167.144.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxa3m65wm-f4uX16X52TQAAAC4"]
[Thu Sep 17 15:25:50.844183 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.94.35.161:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/public/phpinfo.php"] [unique_id "aqxa3m65wm-f4uX16X52XwAAAFw"]
[Thu Sep 17 15:25:50.867269 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxa3m65wm-f4uX16X52YQAAAHM"]
[Thu Sep 17 15:25:50.882778 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.166.217.178:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxa3m65wm-f4uX16X52YwAAAGM"]
[Thu Sep 17 15:25:50.911972 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/ansible/.env"] [unique_id "aqxa3m65wm-f4uX16X52ZgAAAF8"]
[Thu Sep 17 15:25:51.032581 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/.git/.env"] [unique_id "aqxa3265wm-f4uX16X52bgAAAE0"]
[Thu Sep 17 15:25:51.093123 2026] [security2:error] [pid 1029697:tid 1029908] [client 52.167.144.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxa3m65wm-f4uX16X52agAAAFE"]
[Thu Sep 17 15:25:51.153212 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/ci/.env"] [unique_id "aqxa3265wm-f4uX16X52dAAAAGA"]
[Thu Sep 17 15:25:51.220418 2026] [core:error] [pid 1029697:tid 1029884] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:51.220439 2026] [core:error] [pid 1029697:tid 1029884] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:51.253737 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa3265wm-f4uX16X52cwAAABo"]
[Thu Sep 17 15:25:51.272360 2026] [security2:error] [pid 1029697:tid 1029863] [client 112.82.200.91:55544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxa3m65wm-f4uX16X52awAAJHU"], referer: https://iradtech.com/
[Thu Sep 17 15:25:51.273074 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/cd/.env"] [unique_id "aqxa3265wm-f4uX16X52gAAAACc"]
[Thu Sep 17 15:25:51.394411 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/jenkins/.env"] [unique_id "aqxa3265wm-f4uX16X52hgAAAFA"]
[Thu Sep 17 15:25:51.515442 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/gitlab/.env"] [unique_id "aqxa3265wm-f4uX16X52jAAAAHw"]
[Thu Sep 17 15:25:51.539129 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.94.35.161:38782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/php-info.php"] [unique_id "aqxa3265wm-f4uX16X52jQAAAAo"]
[Thu Sep 17 15:25:51.564382 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.166.217.178:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.217.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.uei.mub.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxa3265wm-f4uX16X52jwAAAHA"]
[Thu Sep 17 15:25:51.635500 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/github/.env"] [unique_id "aqxa3265wm-f4uX16X52kQAAAH4"]
[Thu Sep 17 15:25:51.660335 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa3265wm-f4uX16X52jgAAAHk"]
[Thu Sep 17 15:25:51.690380 2026] [security2:error] [pid 1029697:tid 1029818] [remote 40.77.167.55:57326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mtbclubdecampo.com"] [uri "/bici2/ciclista.php"] [unique_id "aqxa3265wm-f4uX16X52kAAAAXg"]
[Thu Sep 17 15:25:51.758868 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/actions/.env"] [unique_id "aqxa3265wm-f4uX16X52nQAAAF8"]
[Thu Sep 17 15:25:51.860574 2026] [security2:error] [pid 1029697:tid 1029896] [client 112.86.225.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iradtech.com"] [uri "/index.php"] [unique_id "aqxa3m65wm-f4uX16X52WgAAAEU"]
[Thu Sep 17 15:25:51.883282 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/circleci/.env"] [unique_id "aqxa3265wm-f4uX16X52owAAAC8"]
[Thu Sep 17 15:25:51.894357 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.94.35.161:33516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/phpversion.php"] [unique_id "aqxa3265wm-f4uX16X52pAAAAH8"]
[Thu Sep 17 15:25:52.008541 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/travis/.env"] [unique_id "aqxa4G65wm-f4uX16X52pwAAAGE"]
[Thu Sep 17 15:25:52.050730 2026] [security2:error] [pid 1029697:tid 1029947] [client 112.82.200.91:55544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxa3265wm-f4uX16X52ogAAeAY"], referer: https://iradtech.com/
[Thu Sep 17 15:25:52.071491 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.94.35.161:33526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/_phpinfo.php"] [unique_id "aqxa4G65wm-f4uX16X52rAAAAD8"]
[Thu Sep 17 15:25:52.132412 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/buildkite/.env"] [unique_id "aqxa4G65wm-f4uX16X52sAAAABU"]
[Thu Sep 17 15:25:52.271088 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mysql/.env"] [unique_id "aqxa4G65wm-f4uX16X52tAAAABM"]
[Thu Sep 17 15:25:52.402911 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/postgres/.env"] [unique_id "aqxa4G65wm-f4uX16X52uQAAABs"]
[Thu Sep 17 15:25:52.456195 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.94.35.161:33530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/old_phpinfo.php"] [unique_id "aqxa4G65wm-f4uX16X52vQAAAE4"]
[Thu Sep 17 15:25:52.483290 2026] [security2:error] [pid 1029697:tid 1029831] [client 169.58.197.253:55741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxa4G65wm-f4uX16X52vgAAAAQ"], referer: binance.com
[Thu Sep 17 15:25:52.519432 2026] [security2:error] [pid 1029697:tid 1029703] [remote 111.225.149.152:42044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acc.edu.ai"] [uri "/"] [unique_id "aqxa4G65wm-f4uX16X52xAAAVQU"]
[Thu Sep 17 15:25:52.522092 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4G65wm-f4uX16X52uwAAABY"]
[Thu Sep 17 15:25:52.527713 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/mongodb/.env"] [unique_id "aqxa4G65wm-f4uX16X52xQAAAD0"]
[Thu Sep 17 15:25:52.601700 2026] [core:error] [pid 1029697:tid 1029877] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:52.601722 2026] [core:error] [pid 1029697:tid 1029877] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:52.652957 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/redis/.env"] [unique_id "aqxa4G65wm-f4uX16X520AAAABw"]
[Thu Sep 17 15:25:52.763735 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.94.35.161:33534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/server-info.php"] [unique_id "aqxa4G65wm-f4uX16X521AAAAFg"]
[Thu Sep 17 15:25:52.773960 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/elasticsearch/.env"] [unique_id "aqxa4G65wm-f4uX16X521gAAAB0"]
[Thu Sep 17 15:25:52.905397 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/rabbitmq/.env"] [unique_id "aqxa4G65wm-f4uX16X522gAAAEQ"]
[Thu Sep 17 15:25:52.920211 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.94.35.161:33544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/server-status.php"] [unique_id "aqxa4G65wm-f4uX16X522wAAAHI"]
[Thu Sep 17 15:25:52.949322 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4G65wm-f4uX16X522AAAADs"]
[Thu Sep 17 15:25:53.026458 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/kafka/.env"] [unique_id "aqxa4W65wm-f4uX16X523gAAADM"]
[Thu Sep 17 15:25:53.104593 2026] [core:error] [pid 1029697:tid 1029929] [client 23.180.120.146:57226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.104619 2026] [core:error] [pid 1029697:tid 1029929] [client 23.180.120.146:57226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.146791 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/queue/.env"] [unique_id "aqxa4W65wm-f4uX16X524wAAAAI"]
[Thu Sep 17 15:25:53.238501 2026] [core:error] [pid 1029697:tid 1029902] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.238520 2026] [core:error] [pid 1029697:tid 1029902] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.270721 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/worker/.env"] [unique_id "aqxa4W65wm-f4uX16X527AAAAGE"]
[Thu Sep 17 15:25:53.354330 2026] [security2:error] [pid 1029697:tid 1029848] [client 162.241.226.11:39898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "owf.sdy.mybluehost.me"] [uri "/website_8d0b1571/wp-admin/upgrade.php"] [unique_id "aqxa4W65wm-f4uX16X528AAAABU"]
[Thu Sep 17 15:25:53.395186 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/job/.env"] [unique_id "aqxa4W65wm-f4uX16X528gAAACM"]
[Thu Sep 17 15:25:53.424808 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4W65wm-f4uX16X527gAAAA4"]
[Thu Sep 17 15:25:53.485005 2026] [core:error] [pid 1029697:tid 1029930] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.485025 2026] [core:error] [pid 1029697:tid 1029930] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.515522 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/test/.env"] [unique_id "aqxa4W65wm-f4uX16X52-QAAACc"]
[Thu Sep 17 15:25:53.640215 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/qa/.env"] [unique_id "aqxa4W65wm-f4uX16X52_wAAAFU"]
[Thu Sep 17 15:25:53.691208 2026] [core:error] [pid 1029697:tid 1029951] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.691226 2026] [core:error] [pid 1029697:tid 1029951] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:25:53.767027 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/preview/.env"] [unique_id "aqxa4W65wm-f4uX16X53BwAAACQ"]
[Thu Sep 17 15:25:53.821278 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.94.35.161:33566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/webroot/index.php/_environment"] [unique_id "aqxa4W65wm-f4uX16X53CgAAAHA"]
[Thu Sep 17 15:25:53.888076 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/beta/.env"] [unique_id "aqxa4W65wm-f4uX16X53DAAAAHM"]
[Thu Sep 17 15:25:53.908896 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4W65wm-f4uX16X53CQAAAFs"]
[Thu Sep 17 15:25:54.012629 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/uat/.env"] [unique_id "aqxa4m65wm-f4uX16X53EQAAABw"]
[Thu Sep 17 15:25:54.058115 2026] [security2:error] [pid 1029697:tid 1029831] [client 154.190.208.131:42502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa4m65wm-f4uX16X53EgAAAAQ"]
[Thu Sep 17 15:25:54.058288 2026] [security2:error] [pid 1029697:tid 1029831] [client 154.190.208.131:42502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa4m65wm-f4uX16X53EgAAAAQ"]
[Thu Sep 17 15:25:54.147408 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/stage/.env"] [unique_id "aqxa4m65wm-f4uX16X53FAAAADA"]
[Thu Sep 17 15:25:54.149572 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.94.35.161:33574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/mail/phpinfo.php"] [unique_id "aqxa4m65wm-f4uX16X53FQAAACs"]
[Thu Sep 17 15:25:54.234855 2026] [security2:error] [pid 1029697:tid 1029941] [client 162.241.226.11:17322] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxa4m65wm-f4uX16X53HQAAAHI"]
[Thu Sep 17 15:25:54.266896 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/development/.env"] [unique_id "aqxa4m65wm-f4uX16X53IQAAABc"]
[Thu Sep 17 15:25:54.347191 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.94.35.161:33586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxa4m65wm-f4uX16X53JQAAACg"]
[Thu Sep 17 15:25:54.388143 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/production/.env"] [unique_id "aqxa4m65wm-f4uX16X53JwAAADU"]
[Thu Sep 17 15:25:54.394529 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4m65wm-f4uX16X53IgAAAEg"]
[Thu Sep 17 15:25:54.508879 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.97.29.237:48646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agent-immobilier.com"] [uri "/config/app/.env"] [unique_id "aqxa4m65wm-f4uX16X53KgAAAGE"]
[Thu Sep 17 15:25:54.571837 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.94.35.161:33590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/hosting/phpinfo.php"] [unique_id "aqxa4m65wm-f4uX16X53KwAAAAU"]
[Thu Sep 17 15:25:54.638835 2026] [security2:error] [pid 1029697:tid 1029848] [client 5.189.145.112:49455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxa4m65wm-f4uX16X53LwAAABU"], referer: binance.com
[Thu Sep 17 15:25:54.716471 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.97.29.237:48646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/phpinfo.php"] [unique_id "aqxa4m65wm-f4uX16X53LgAAAAk"]
[Thu Sep 17 15:25:54.812229 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4m65wm-f4uX16X53MwAAAAE"]
[Thu Sep 17 15:25:54.924292 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.94.35.161:33606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/webmail/phpinfo.php"] [unique_id "aqxa4m65wm-f4uX16X53OQAAAHo"]
[Thu Sep 17 15:25:55.085359 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.97.29.237:48652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/info.php"] [unique_id "aqxa4265wm-f4uX16X53PQAAAEw"]
[Thu Sep 17 15:25:55.127515 2026] [security2:error] [pid 1029697:tid 1029854] [client 4.240.114.86:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxa4265wm-f4uX16X53PgAAABs"], referer: binance.com
[Thu Sep 17 15:25:55.145127 2026] [security2:error] [pid 1029697:tid 1029952] [client 24.7.227.113:63536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxa4m65wm-f4uX16X53OgAAfRc"]
[Thu Sep 17 15:25:55.210590 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.94.35.161:33614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/smtp/phpinfo.php"] [unique_id "aqxa4265wm-f4uX16X53QAAAAEc"]
[Thu Sep 17 15:25:55.227151 2026] [security2:error] [pid 1029697:tid 1029929] [client 112.86.225.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxa4m65wm-f4uX16X53IwAAAGY"]
[Thu Sep 17 15:25:55.358961 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4265wm-f4uX16X53QQAAAHY"]
[Thu Sep 17 15:25:55.447900 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.97.29.237:48666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/php.php"] [unique_id "aqxa4265wm-f4uX16X53SAAAAAs"]
[Thu Sep 17 15:25:55.592513 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.94.35.161:33626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/phpinfo.php.bak"] [unique_id "aqxa4265wm-f4uX16X53SQAAABw"]
[Thu Sep 17 15:25:55.775284 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa4265wm-f4uX16X53TAAAAAY"]
[Thu Sep 17 15:25:55.821114 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.97.29.237:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/i.php"] [unique_id "aqxa4265wm-f4uX16X53VQAAAHI"]
[Thu Sep 17 15:25:55.862044 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.161:33638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/phpinfo.php.old"] [unique_id "aqxa4265wm-f4uX16X53VgAAADM"]
[Thu Sep 17 15:25:56.183101 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.94.35.161:33648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/phpinfo.php~"] [unique_id "aqxa5G65wm-f4uX16X53XgAAAFE"]
[Thu Sep 17 15:25:56.188455 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.97.29.237:48686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/pi.php"] [unique_id "aqxa5G65wm-f4uX16X53XwAAAE0"]
[Thu Sep 17 15:25:56.202568 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa5G65wm-f4uX16X53XAAAAFc"]
[Thu Sep 17 15:25:56.431608 2026] [security2:error] [pid 1029697:tid 1029954] [client 103.61.184.148:61339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa5G65wm-f4uX16X53YgAAAH8"]
[Thu Sep 17 15:25:56.431744 2026] [security2:error] [pid 1029697:tid 1029954] [client 103.61.184.148:61339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa5G65wm-f4uX16X53YgAAAH8"]
[Thu Sep 17 15:25:56.445527 2026] [security2:error] [pid 1029697:tid 1029935] [client 114.198.138.124:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa5G65wm-f4uX16X53YwAAAGw"]
[Thu Sep 17 15:25:56.445641 2026] [security2:error] [pid 1029697:tid 1029935] [client 114.198.138.124:60249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa5G65wm-f4uX16X53YwAAAGw"]
[Thu Sep 17 15:25:56.453918 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxa5G65wm-f4uX16X53ZAAAAA4"]
[Thu Sep 17 15:25:56.482388 2026] [security2:error] [pid 1029697:tid 1029881] [client 162.241.226.11:39906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "owf.sdy.mybluehost.me"] [uri "/website_8d0b1571/wp-cron.php"] [unique_id "aqxa5G65wm-f4uX16X53ZQAAADY"]
[Thu Sep 17 15:25:56.539849 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.94.35.161:33656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/info.php.bak"] [unique_id "aqxa5G65wm-f4uX16X53ZwAAABM"]
[Thu Sep 17 15:25:56.567675 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.97.29.237:48688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/pinfo.php"] [unique_id "aqxa5G65wm-f4uX16X53aAAAADE"]
[Thu Sep 17 15:25:56.686513 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/.env~"] [unique_id "aqxa5G65wm-f4uX16X53aQAAACc"]
[Thu Sep 17 15:25:56.731137 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.94.35.161:33660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/phpinfo.php.save"] [unique_id "aqxa5G65wm-f4uX16X53awAAAEw"]
[Thu Sep 17 15:25:56.836044 2026] [security2:error] [pid 1029697:tid 1029845] [client 156.192.234.52:49415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa5G65wm-f4uX16X53bQAAABI"]
[Thu Sep 17 15:25:56.837064 2026] [security2:error] [pid 1029697:tid 1029845] [client 156.192.234.52:49415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa5G65wm-f4uX16X53bQAAABI"]
[Thu Sep 17 15:25:56.925369 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.97.29.237:60272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/test.php"] [unique_id "aqxa5G65wm-f4uX16X53cgAAADc"]
[Thu Sep 17 15:25:57.017103 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.94.35.161:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/staging/phpinfo.php"] [unique_id "aqxa5W65wm-f4uX16X53dQAAAHE"]
[Thu Sep 17 15:25:57.180757 2026] [security2:error] [pid 1029697:tid 1029901] [client 74.7.241.160:45340] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thenewyearworks.newyearworks.com"] [uri "/robots.txt"] [unique_id "aqxa5W65wm-f4uX16X53fAAAAEo"]
[Thu Sep 17 15:25:57.202375 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa5W65wm-f4uX16X53eAAAAE4"]
[Thu Sep 17 15:25:57.347876 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.94.35.161:33674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/beta/phpinfo.php"] [unique_id "aqxa5W65wm-f4uX16X53gAAAADA"]
[Thu Sep 17 15:25:57.404865 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.97.29.237:60282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/p.php"] [unique_id "aqxa5W65wm-f4uX16X53gQAAABg"]
[Thu Sep 17 15:25:57.743226 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.94.35.161:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/uat/phpinfo.php"] [unique_id "aqxa5W65wm-f4uX16X53iwAAAHI"]
[Thu Sep 17 15:25:57.782760 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.97.29.237:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/debug.php"] [unique_id "aqxa5W65wm-f4uX16X53jAAAAGM"]
[Thu Sep 17 15:25:57.832459 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa5W65wm-f4uX16X53iQAAAHQ"]
[Thu Sep 17 15:25:57.902059 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.94.35.161:33694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/qa/phpinfo.php"] [unique_id "aqxa5W65wm-f4uX16X53kQAAABQ"]
[Thu Sep 17 15:25:58.018249 2026] [security2:error] [pid 1029697:tid 1029917] [client 162.241.226.11:39920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "owf.sdy.mybluehost.me"] [uri "/website_8d0b1571/wp-cron.php"] [unique_id "aqxa5m65wm-f4uX16X53lgAAAFo"]
[Thu Sep 17 15:25:58.172635 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.97.29.237:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxa5m65wm-f4uX16X53mQAAABo"]
[Thu Sep 17 15:25:58.249777 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.35.161:33704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/preview/phpinfo.php"] [unique_id "aqxa5m65wm-f4uX16X53mgAAAGc"]
[Thu Sep 17 15:25:58.547622 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.97.29.237:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/test/phpinfo.php"] [unique_id "aqxa5m65wm-f4uX16X53pQAAAFI"]
[Thu Sep 17 15:25:58.550449 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.94.35.161:33716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/www/phpinfo.php"] [unique_id "aqxa5m65wm-f4uX16X53pgAAAFw"]
[Thu Sep 17 15:25:58.554946 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa5m65wm-f4uX16X53ogAAAD4"]
[Thu Sep 17 15:25:58.824209 2026] [security2:error] [pid 1029697:tid 1029940] [client 185.55.149.49:61351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa5m65wm-f4uX16X53sAAAAHE"]
[Thu Sep 17 15:25:58.824312 2026] [security2:error] [pid 1029697:tid 1029940] [client 185.55.149.49:61351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa5m65wm-f4uX16X53sAAAAHE"]
[Thu Sep 17 15:25:58.843039 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.94.35.161:33730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxa5m65wm-f4uX16X53sgAAAH4"]
[Thu Sep 17 15:25:58.913465 2026] [security2:error] [pid 1029697:tid 1029882] [client 121.229.156.56:35472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acc.edu.ai"] [uri "/6th-form/"] [unique_id "aqxa5m65wm-f4uX16X53swAAADc"]
[Thu Sep 17 15:25:58.913593 2026] [security2:error] [pid 1029697:tid 1029882] [client 121.229.156.56:35472] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "acc.edu.ai"] [uri "/6th-form/"] [unique_id "aqxa5m65wm-f4uX16X53swAAADc"]
[Thu Sep 17 15:25:58.944422 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.97.29.237:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxa5m65wm-f4uX16X53ugAAAA0"]
[Thu Sep 17 15:25:59.300992 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.94.35.161:33742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/public_html/phpinfo.php"] [unique_id "aqxa5265wm-f4uX16X53xgAAAFU"]
[Thu Sep 17 15:25:59.319374 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.97.29.237:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/old/phpinfo.php"] [unique_id "aqxa5265wm-f4uX16X53xwAAAAY"]
[Thu Sep 17 15:25:59.631559 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.94.35.161:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/site/phpinfo.php"] [unique_id "aqxa5265wm-f4uX16X535wAAAFE"]
[Thu Sep 17 15:25:59.644519 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa5265wm-f4uX16X534gAAAG8"]
[Thu Sep 17 15:25:59.682254 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.97.29.237:60328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxa5265wm-f4uX16X536AAAAA8"]
[Thu Sep 17 15:25:59.896260 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.94.35.161:33760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/docs/phpinfo.php"] [unique_id "aqxa5265wm-f4uX16X538gAAAFk"]
[Thu Sep 17 15:26:00.020399 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa5265wm-f4uX16X538wAAAGU"]
[Thu Sep 17 15:26:00.043456 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.97.29.237:60334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/public/phpinfo.php"] [unique_id "aqxa6G65wm-f4uX16X539QAAACA"]
[Thu Sep 17 15:26:00.084697 2026] [security2:error] [pid 1029697:tid 1029846] [client 4.240.114.86:54967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxa6G65wm-f4uX16X539gAAABM"], referer: binance.com
[Thu Sep 17 15:26:00.245643 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.94.35.161:33776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxa6G65wm-f4uX16X539wAAADo"]
[Thu Sep 17 15:26:00.274800 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxa6G65wm-f4uX16X53-AAAAE8"]
[Thu Sep 17 15:26:00.490733 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.94.35.161:33792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/administrator/phpinfo.php"] [unique_id "aqxa6G65wm-f4uX16X53_gAAAD4"]
[Thu Sep 17 15:26:00.519595 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxa6G65wm-f4uX16X53_wAAADQ"]
[Thu Sep 17 15:26:00.560933 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.97.29.237:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/php-info.php"] [unique_id "aqxa6G65wm-f4uX16X54AAAAAEA"]
[Thu Sep 17 15:26:00.751891 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxa6G65wm-f4uX16X54AQAAAFs"]
[Thu Sep 17 15:26:00.925566 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.97.29.237:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/phpversion.php"] [unique_id "aqxa6G65wm-f4uX16X54BwAAAH4"]
[Thu Sep 17 15:26:00.958818 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.35.161:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/core/phpinfo.php"] [unique_id "aqxa6G65wm-f4uX16X54CAAAAGk"]
[Thu Sep 17 15:26:00.983586 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxa6G65wm-f4uX16X54CQAAAFg"]
[Thu Sep 17 15:26:01.216308 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxa6W65wm-f4uX16X54CwAAAEY"]
[Thu Sep 17 15:26:01.292366 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.97.29.237:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/_phpinfo.php"] [unique_id "aqxa6W65wm-f4uX16X54DAAAAGs"]
[Thu Sep 17 15:26:01.341557 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.94.35.161:33802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lasvegaslife.info"] [uri "/includes/phpinfo.php"] [unique_id "aqxa6W65wm-f4uX16X54DgAAAGo"]
[Thu Sep 17 15:26:01.449253 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxa6W65wm-f4uX16X54EQAAAGg"]
[Thu Sep 17 15:26:01.581217 2026] [security2:error] [pid 1029697:tid 1029912] [client 169.58.197.253:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxa6W65wm-f4uX16X54EgAAAFU"], referer: binance.com
[Thu Sep 17 15:26:01.649778 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.97.29.237:60360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/old_phpinfo.php"] [unique_id "aqxa6W65wm-f4uX16X54FQAAAEM"]
[Thu Sep 17 15:26:01.799338 2026] [access_compat:error] [pid 1029697:tid 1029943] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/cozy-finds
[Thu Sep 17 15:26:01.917391 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa6W65wm-f4uX16X54HAAAADU"]
[Thu Sep 17 15:26:02.015417 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.97.29.237:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/server-info.php"] [unique_id "aqxa6m65wm-f4uX16X54JgAAADg"]
[Thu Sep 17 15:26:02.167585 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxa6m65wm-f4uX16X54KgAAACM"]
[Thu Sep 17 15:26:02.236189 2026] [security2:error] [pid 1029697:tid 1029927] [client 105.157.198.74:49105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxa6m65wm-f4uX16X54KQAAZF4"]
[Thu Sep 17 15:26:02.393320 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.97.29.237:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/server-status.php"] [unique_id "aqxa6m65wm-f4uX16X54MAAAAGU"]
[Thu Sep 17 15:26:02.400797 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxa6m65wm-f4uX16X54MQAAABo"]
[Thu Sep 17 15:26:02.546315 2026] [security2:error] [pid 1029697:tid 1029831] [client 5.189.145.112:54038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxa6m65wm-f4uX16X54NAAAAAQ"], referer: binance.com
[Thu Sep 17 15:26:02.637836 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxa6m65wm-f4uX16X54NQAAAGc"]
[Thu Sep 17 15:26:02.803955 2026] [security2:error] [pid 1029697:tid 1029789] [remote 40.77.167.41:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtbclubdecampo.com"] [uri "/bici2/ruta.php"] [unique_id "aqxa6m65wm-f4uX16X54OQAAbVs"]
[Thu Sep 17 15:26:02.874430 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxa6m65wm-f4uX16X54QgAAAD4"]
[Thu Sep 17 15:26:03.005490 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.97.29.237:60386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxa6265wm-f4uX16X54RwAAACQ"]
[Thu Sep 17 15:26:03.107110 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxa6265wm-f4uX16X54SAAAAB4"]
[Thu Sep 17 15:26:03.336801 2026] [core:error] [pid 1029697:tid 1029896] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:03.336819 2026] [core:error] [pid 1029697:tid 1029896] [client 34.94.35.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:03.339759 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxa6265wm-f4uX16X54TQAAAH4"]
[Thu Sep 17 15:26:03.407547 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.97.29.237:60400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxa6265wm-f4uX16X54UAAAAEc"]
[Thu Sep 17 15:26:03.578170 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxa6265wm-f4uX16X54VAAAAGg"]
[Thu Sep 17 15:26:03.781489 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.97.29.237:60410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxa6265wm-f4uX16X54VgAAAD0"]
[Thu Sep 17 15:26:03.811094 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxa6265wm-f4uX16X54VwAAAAc"]
[Thu Sep 17 15:26:04.047281 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxa7G65wm-f4uX16X54ZgAAADU"]
[Thu Sep 17 15:26:04.147633 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.97.29.237:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxa7G65wm-f4uX16X54bAAAAG8"]
[Thu Sep 17 15:26:04.281154 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxa7G65wm-f4uX16X54cgAAAAk"]
[Thu Sep 17 15:26:04.516656 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxa7G65wm-f4uX16X54dgAAAAQ"]
[Thu Sep 17 15:26:04.538317 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.97.29.237:60430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxa7G65wm-f4uX16X54dwAAAAw"]
[Thu Sep 17 15:26:04.748757 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxa7G65wm-f4uX16X54eQAAACY"]
[Thu Sep 17 15:26:04.912177 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.97.29.237:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxa7G65wm-f4uX16X54fgAAAAE"]
[Thu Sep 17 15:26:04.989191 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxa7G65wm-f4uX16X54gAAAAAM"]
[Thu Sep 17 15:26:05.036106 2026] [security2:error] [pid 1029697:tid 1029930] [client 154.190.208.131:41495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa7W65wm-f4uX16X54hAAAAGc"]
[Thu Sep 17 15:26:05.036196 2026] [security2:error] [pid 1029697:tid 1029930] [client 154.190.208.131:41495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa7W65wm-f4uX16X54hAAAAGc"]
[Thu Sep 17 15:26:05.229509 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxa7W65wm-f4uX16X54hwAAAB4"]
[Thu Sep 17 15:26:05.254269 2026] [security2:error] [pid 1029697:tid 1029951] [client 4.240.114.86:57178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxa7W65wm-f4uX16X54iAAAAHw"], referer: binance.com
[Thu Sep 17 15:26:05.286266 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.97.29.237:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxa7W65wm-f4uX16X54iQAAAF0"]
[Thu Sep 17 15:26:05.466140 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxa7W65wm-f4uX16X54kAAAAEc"]
[Thu Sep 17 15:26:05.573197 2026] [fcgid:warn] [pid 1029697:tid 1029834] (70014)End of file found: [client 152.32.205.7:38272] mod_fcgid: can't get data from http client
[Thu Sep 17 15:26:05.647256 2026] [security2:error] [pid 1029697:tid 1029947] [client 46.184.245.238:15322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxa7W65wm-f4uX16X54lAAAeH4"]
[Thu Sep 17 15:26:05.670856 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.97.29.237:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/phpinfo.php.old"] [unique_id "aqxa7W65wm-f4uX16X54lwAAAEM"]
[Thu Sep 17 15:26:05.707400 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxa7W65wm-f4uX16X54mAAAAFc"]
[Thu Sep 17 15:26:05.812121 2026] [security2:error] [pid 1029697:tid 1029888] [client 104.207.33.33:27723] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxa7W65wm-f4uX16X54mgAAAD0"]
[Thu Sep 17 15:26:05.941611 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxa7W65wm-f4uX16X54nQAAABw"]
[Thu Sep 17 15:26:06.035505 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.97.29.237:60456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/phpinfo.php~"] [unique_id "aqxa7m65wm-f4uX16X54oAAAACM"]
[Thu Sep 17 15:26:06.081715 2026] [security2:error] [pid 1029697:tid 1029924] [client 35.146.167.167:25929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxa7W65wm-f4uX16X54ngAAYXw"]
[Thu Sep 17 15:26:06.175869 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxa7m65wm-f4uX16X54pQAAAGQ"]
[Thu Sep 17 15:26:06.411941 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.97.29.237:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/info.php.bak"] [unique_id "aqxa7m65wm-f4uX16X54sQAAAGU"]
[Thu Sep 17 15:26:06.412615 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxa7m65wm-f4uX16X54sAAAABo"]
[Thu Sep 17 15:26:06.655200 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxa7m65wm-f4uX16X54swAAAFw"]
[Thu Sep 17 15:26:06.737771 2026] [fcgid:warn] [pid 1029697:tid 1029845] (70014)End of file found: [client 152.32.205.7:38302] mod_fcgid: can't get data from http client
[Thu Sep 17 15:26:06.781019 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.97.29.237:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/phpinfo.php.save"] [unique_id "aqxa7m65wm-f4uX16X54vAAAAHk"]
[Thu Sep 17 15:26:06.835776 2026] [security2:error] [pid 1029697:tid 1029704] [remote 15.235.27.68:36218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "narwhalbrewery.com"] [uri "/robots.txt"] [unique_id "aqxa7m65wm-f4uX16X54vgAAXQY"]
[Thu Sep 17 15:26:06.835930 2026] [security2:error] [pid 1029697:tid 1029920] [client 15.235.27.68:36218] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "narwhalbrewery.com"] [uri "/robots.txt"] [unique_id "aqxa7m65wm-f4uX16X54vgAAXQY"]
[Thu Sep 17 15:26:06.893214 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxa7m65wm-f4uX16X54vwAAAFs"]
[Thu Sep 17 15:26:06.900413 2026] [security2:error] [pid 1029697:tid 1029868] [client 8.231.55.47:35176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxa7m65wm-f4uX16X54wAAAACk"]
[Thu Sep 17 15:26:06.999558 2026] [security2:error] [pid 1029697:tid 1029952] [client 114.198.138.124:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa7m65wm-f4uX16X54xAAAAH0"]
[Thu Sep 17 15:26:06.999729 2026] [security2:error] [pid 1029697:tid 1029952] [client 114.198.138.124:61032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa7m65wm-f4uX16X54xAAAAH0"]
[Thu Sep 17 15:26:07.100856 2026] [security2:error] [pid 1029697:tid 1029901] [client 8.231.55.47:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxa7265wm-f4uX16X54xgAAAEo"]
[Thu Sep 17 15:26:07.127969 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxa7265wm-f4uX16X54xwAAABE"]
[Thu Sep 17 15:26:07.145805 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.97.29.237:52686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxa7265wm-f4uX16X54yQAAAHY"]
[Thu Sep 17 15:26:07.366093 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxa7265wm-f4uX16X54zwAAADw"]
[Thu Sep 17 15:26:07.444751 2026] [security2:error] [pid 1029697:tid 1029937] [client 156.192.234.52:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa7265wm-f4uX16X540gAAAG4"]
[Thu Sep 17 15:26:07.446097 2026] [security2:error] [pid 1029697:tid 1029937] [client 156.192.234.52:50045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa7265wm-f4uX16X540gAAAG4"]
[Thu Sep 17 15:26:07.519915 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.97.29.237:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxa7265wm-f4uX16X541AAAAB8"]
[Thu Sep 17 15:26:07.523515 2026] [security2:error] [pid 1029697:tid 1029933] [client 8.231.55.47:35194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxa7265wm-f4uX16X541gAAAGo"]
[Thu Sep 17 15:26:07.601429 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxa7265wm-f4uX16X541wAAAFg"]
[Thu Sep 17 15:26:07.755482 2026] [security2:error] [pid 1029697:tid 1029709] [remote 51.81.163.73:55924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "narwhalbrewery.com"] [uri "/"] [unique_id "aqxa7265wm-f4uX16X543QAAdQs"]
[Thu Sep 17 15:26:07.755702 2026] [security2:error] [pid 1029697:tid 1029944] [client 51.81.163.73:55924] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "narwhalbrewery.com"] [uri "/"] [unique_id "aqxa7265wm-f4uX16X543QAAdQs"]
[Thu Sep 17 15:26:07.844956 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxa7265wm-f4uX16X543wAAACA"]
[Thu Sep 17 15:26:07.895741 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.97.29.237:52718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxa7265wm-f4uX16X544QAAAFk"]
[Thu Sep 17 15:26:07.925272 2026] [security2:error] [pid 1029697:tid 1029880] [client 35.146.167.167:25930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxa7265wm-f4uX16X543gAANQ0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818142734&hideanons=1&hideminor=1&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:26:07.997394 2026] [security2:error] [pid 1029697:tid 1029839] [client 8.231.55.47:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxa7265wm-f4uX16X545wAAAAw"]
[Thu Sep 17 15:26:08.081927 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxa8G65wm-f4uX16X546AAAAH8"]
[Thu Sep 17 15:26:08.202094 2026] [security2:error] [pid 1029697:tid 1029876] [client 74.7.175.143:50838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.intervial.com"] [uri "/index.php"] [unique_id "aqxa7265wm-f4uX16X544gAAMQo"]
[Thu Sep 17 15:26:08.267215 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.97.29.237:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxa8G65wm-f4uX16X546gAAAGU"]
[Thu Sep 17 15:26:08.318369 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxa8G65wm-f4uX16X546wAAAEs"]
[Thu Sep 17 15:26:08.559145 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxa8G65wm-f4uX16X548QAAAFM"]
[Thu Sep 17 15:26:08.610021 2026] [security2:error] [pid 1029697:tid 1029930] [client 8.231.55.47:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa8G65wm-f4uX16X548AAAAGc"]
[Thu Sep 17 15:26:08.634075 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.97.29.237:52728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxa8G65wm-f4uX16X549AAAAFQ"]
[Thu Sep 17 15:26:08.723707 2026] [security2:error] [pid 1029697:tid 1029845] [client 103.61.184.148:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa8G65wm-f4uX16X549wAAABI"]
[Thu Sep 17 15:26:08.723852 2026] [security2:error] [pid 1029697:tid 1029845] [client 103.61.184.148:61955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa8G65wm-f4uX16X549wAAABI"]
[Thu Sep 17 15:26:08.796098 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxa8G65wm-f4uX16X54-wAAACs"]
[Thu Sep 17 15:26:08.956936 2026] [security2:error] [pid 1029697:tid 1029887] [client 8.231.55.47:35210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxa8G65wm-f4uX16X55AwAAADw"]
[Thu Sep 17 15:26:08.990365 2026] [access_compat:error] [pid 1029697:tid 1029933] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/mesmalie
[Thu Sep 17 15:26:09.004580 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.97.29.237:52734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/www/phpinfo.php"] [unique_id "aqxa8W65wm-f4uX16X55BgAAABs"]
[Thu Sep 17 15:26:09.033531 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxa8W65wm-f4uX16X55CQAAABw"]
[Thu Sep 17 15:26:09.278185 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxa8W65wm-f4uX16X55DQAAACE"]
[Thu Sep 17 15:26:09.396573 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.97.29.237:52750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxa8W65wm-f4uX16X55EAAAADo"]
[Thu Sep 17 15:26:09.518235 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxa8W65wm-f4uX16X55FwAAADc"]
[Thu Sep 17 15:26:09.538987 2026] [security2:error] [pid 1029697:tid 1029859] [client 8.231.55.47:35222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxa8W65wm-f4uX16X55GAAAACA"]
[Thu Sep 17 15:26:09.756642 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxa8W65wm-f4uX16X55JgAAAAg"]
[Thu Sep 17 15:26:09.783198 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.97.29.237:52764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxa8W65wm-f4uX16X55JwAAADE"]
[Thu Sep 17 15:26:09.899416 2026] [security2:error] [pid 1029697:tid 1029879] [client 8.231.55.47:35226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxa8W65wm-f4uX16X55LAAAADQ"]
[Thu Sep 17 15:26:09.996136 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxa8W65wm-f4uX16X55NAAAAB0"]
[Thu Sep 17 15:26:10.124772 2026] [security2:error] [pid 1029697:tid 1029725] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.env"] [unique_id "aqxa8m65wm-f4uX16X55NwAAERs"]
[Thu Sep 17 15:26:10.126870 2026] [security2:error] [pid 1029697:tid 1029738] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.env.backup"] [unique_id "aqxa8m65wm-f4uX16X55QAAAESg"]
[Thu Sep 17 15:26:10.126944 2026] [security2:error] [pid 1029697:tid 1029731] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.env.bak"] [unique_id "aqxa8m65wm-f4uX16X55QgAAESE"]
[Thu Sep 17 15:26:10.127047 2026] [security2:error] [pid 1029697:tid 1029758] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.env.old"] [unique_id "aqxa8m65wm-f4uX16X55RAAAETw"]
[Thu Sep 17 15:26:10.171893 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.97.29.237:52780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/site/phpinfo.php"] [unique_id "aqxa8m65wm-f4uX16X55SAAAAC4"]
[Thu Sep 17 15:26:10.175829 2026] [security2:error] [pid 1029697:tid 1029947] [client 4.240.114.86:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxa8m65wm-f4uX16X55SQAAAHg"], referer: binance.com
[Thu Sep 17 15:26:10.185303 2026] [security2:error] [pid 1029697:tid 1029933] [client 170.9.239.112:63319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "spayingitforward.com"] [uri "/"] [unique_id "aqxa8m65wm-f4uX16X55SgAAAGo"]
[Thu Sep 17 15:26:10.235241 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxa8m65wm-f4uX16X55SwAAAAs"]
[Thu Sep 17 15:26:10.267585 2026] [security2:error] [pid 1029697:tid 1029875] [client 8.231.55.47:35228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxa8m65wm-f4uX16X55TgAAADA"]
[Thu Sep 17 15:26:10.272887 2026] [security2:error] [pid 1029697:tid 1029883] [client 169.58.197.253:56773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxa8m65wm-f4uX16X55TwAAADg"], referer: binance.com
[Thu Sep 17 15:26:10.291339 2026] [security2:error] [pid 1029697:tid 1029842] [client 170.9.239.112:65127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "spayingitforward.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxa8m65wm-f4uX16X55XAAAAA8"]
[Thu Sep 17 15:26:10.310513 2026] [security2:error] [pid 1029697:tid 1029750] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/.env.php"] [unique_id "aqxa8m65wm-f4uX16X55YgAAcjQ"]
[Thu Sep 17 15:26:10.311655 2026] [security2:error] [pid 1029697:tid 1029762] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.env~"] [unique_id "aqxa8m65wm-f4uX16X55YwAAckA"]
[Thu Sep 17 15:26:10.311675 2026] [security2:error] [pid 1029697:tid 1029770] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.env.swp"] [unique_id "aqxa8m65wm-f4uX16X55XwAAckg"]
[Thu Sep 17 15:26:10.382829 2026] [security2:error] [pid 1029697:tid 1029944] [client 170.9.239.112:51657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "spayingitforward.com"] [uri "/media/system/js/core.js"] [unique_id "aqxa8m65wm-f4uX16X55aAAAAHU"]
[Thu Sep 17 15:26:10.472109 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxa8m65wm-f4uX16X55cAAAAAw"]
[Thu Sep 17 15:26:10.522865 2026] [security2:error] [pid 1029697:tid 1029903] [client 5.189.145.112:55780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxa8m65wm-f4uX16X55dgAAAEw"], referer: binance.com
[Thu Sep 17 15:26:10.524182 2026] [security2:error] [pid 1029697:tid 1029787] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/server/.env"] [unique_id "aqxa8m65wm-f4uX16X55fwAAL1k"]
[Thu Sep 17 15:26:10.524244 2026] [security2:error] [pid 1029697:tid 1029744] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/client/.env"] [unique_id "aqxa8m65wm-f4uX16X55gwAALy4"]
[Thu Sep 17 15:26:10.524249 2026] [security2:error] [pid 1029697:tid 1029778] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/backend/.env"] [unique_id "aqxa8m65wm-f4uX16X55fAAAL1A"]
[Thu Sep 17 15:26:10.524299 2026] [security2:error] [pid 1029697:tid 1029784] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/api/.env"] [unique_id "aqxa8m65wm-f4uX16X55fQAAL1Y"]
[Thu Sep 17 15:26:10.524332 2026] [security2:error] [pid 1029697:tid 1029777] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/src/.env"] [unique_id "aqxa8m65wm-f4uX16X55ggAAL08"]
[Thu Sep 17 15:26:10.524342 2026] [security2:error] [pid 1029697:tid 1029786] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/config/.env"] [unique_id "aqxa8m65wm-f4uX16X55gAAAL1g"]
[Thu Sep 17 15:26:10.524340 2026] [security2:error] [pid 1029697:tid 1029790] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/frontend/.env"] [unique_id "aqxa8m65wm-f4uX16X55hAAAL1w"]
[Thu Sep 17 15:26:10.524448 2026] [security2:error] [pid 1029697:tid 1029795] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/var/www/.env"] [unique_id "aqxa8m65wm-f4uX16X55hgAAL2E"]
[Thu Sep 17 15:26:10.524455 2026] [security2:error] [pid 1029697:tid 1029781] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/app/.env"] [unique_id "aqxa8m65wm-f4uX16X55egAAL1M"]
[Thu Sep 17 15:26:10.524499 2026] [security2:error] [pid 1029697:tid 1029793] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/web/.env"] [unique_id "aqxa8m65wm-f4uX16X55gQAAL18"]
[Thu Sep 17 15:26:10.524504 2026] [security2:error] [pid 1029697:tid 1029742] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/public/.env"] [unique_id "aqxa8m65wm-f4uX16X55hQAALyw"]
[Thu Sep 17 15:26:10.541401 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.97.29.237:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxa8m65wm-f4uX16X55igAAABQ"]
[Thu Sep 17 15:26:10.706635 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxa8m65wm-f4uX16X55jgAAADE"]
[Thu Sep 17 15:26:10.707580 2026] [security2:error] [pid 1029697:tid 1029803] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/old/.env"] [unique_id "aqxa8m65wm-f4uX16X55mwAAAWk"]
[Thu Sep 17 15:26:10.707684 2026] [security2:error] [pid 1029697:tid 1029797] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/backup/.env"] [unique_id "aqxa8m65wm-f4uX16X55lAAAAWM"]
[Thu Sep 17 15:26:10.707724 2026] [security2:error] [pid 1029697:tid 1029804] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/test/.env"] [unique_id "aqxa8m65wm-f4uX16X55mgAAAWo"]
[Thu Sep 17 15:26:10.707746 2026] [security2:error] [pid 1029697:tid 1029805] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/prod/.env"] [unique_id "aqxa8m65wm-f4uX16X55jwAAAWs"]
[Thu Sep 17 15:26:10.707787 2026] [security2:error] [pid 1029697:tid 1029798] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/application/.env"] [unique_id "aqxa8m65wm-f4uX16X55lgAAAWQ"]
[Thu Sep 17 15:26:10.707791 2026] [security2:error] [pid 1029697:tid 1029776] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/laravel/.env"] [unique_id "aqxa8m65wm-f4uX16X55lQAAAU4"]
[Thu Sep 17 15:26:10.707838 2026] [security2:error] [pid 1029697:tid 1029792] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/apps/.env"] [unique_id "aqxa8m65wm-f4uX16X55lwAAAV4"]
[Thu Sep 17 15:26:10.707864 2026] [security2:error] [pid 1029697:tid 1029780] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/back/.env"] [unique_id "aqxa8m65wm-f4uX16X55mAAAAVI"]
[Thu Sep 17 15:26:10.707912 2026] [security2:error] [pid 1029697:tid 1029788] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/production/.env"] [unique_id "aqxa8m65wm-f4uX16X55kwAAAVo"]
[Thu Sep 17 15:26:10.707931 2026] [security2:error] [pid 1029697:tid 1029799] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/staging/.env"] [unique_id "aqxa8m65wm-f4uX16X55mQAAAWU"]
[Thu Sep 17 15:26:10.707967 2026] [security2:error] [pid 1029697:tid 1029791] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/var/www/html/.env"] [unique_id "aqxa8m65wm-f4uX16X55kQAAAV0"]
[Thu Sep 17 15:26:10.707985 2026] [security2:error] [pid 1029697:tid 1029789] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/dev/.env"] [unique_id "aqxa8m65wm-f4uX16X55kAAAAVs"]
[Thu Sep 17 15:26:10.708094 2026] [security2:error] [pid 1029697:tid 1029801] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/new/.env"] [unique_id "aqxa8m65wm-f4uX16X55nQAAAWc"]
[Thu Sep 17 15:26:10.708134 2026] [security2:error] [pid 1029697:tid 1029813] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/node-api/.env"] [unique_id "aqxa8m65wm-f4uX16X55nAAAAXM"]
[Thu Sep 17 15:26:10.708186 2026] [security2:error] [pid 1029697:tid 1029716] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/api-backend/.env"] [unique_id "aqxa8m65wm-f4uX16X55ngAAARI"]
[Thu Sep 17 15:26:10.708202 2026] [security2:error] [pid 1029697:tid 1029796] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/cms/.env"] [unique_id "aqxa8m65wm-f4uX16X55kgAAAWI"]
[Thu Sep 17 15:26:10.754911 2026] [security2:error] [pid 1029697:tid 1029924] [client 8.231.55.47:35230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxa8m65wm-f4uX16X55oAAAAGE"]
[Thu Sep 17 15:26:10.890713 2026] [security2:error] [pid 1029697:tid 1029783] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/server/api/.env"] [unique_id "aqxa8m65wm-f4uX16X55pwAAc1U"]
[Thu Sep 17 15:26:10.890713 2026] [security2:error] [pid 1029697:tid 1029814] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxa8m65wm-f4uX16X55qQAAc3Q"]
[Thu Sep 17 15:26:10.890736 2026] [security2:error] [pid 1029697:tid 1029818] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/stripe/.env"] [unique_id "aqxa8m65wm-f4uX16X55rQAAc3g"]
[Thu Sep 17 15:26:10.890773 2026] [security2:error] [pid 1029697:tid 1029809] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/admin-app/.env"] [unique_id "aqxa8m65wm-f4uX16X55owAAc28"]
[Thu Sep 17 15:26:10.890781 2026] [security2:error] [pid 1029697:tid 1029740] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/current/.env"] [unique_id "aqxa8m65wm-f4uX16X55pQAAcyo"]
[Thu Sep 17 15:26:10.890796 2026] [security2:error] [pid 1029697:tid 1029802] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/server/backend/.env"] [unique_id "aqxa8m65wm-f4uX16X55pAAAc2g"]
[Thu Sep 17 15:26:10.890796 2026] [security2:error] [pid 1029697:tid 1029824] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.aws/.env"] [unique_id "aqxa8m65wm-f4uX16X55rAAAc34"]
[Thu Sep 17 15:26:10.890831 2026] [security2:error] [pid 1029697:tid 1029817] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.docker/.env"] [unique_id "aqxa8m65wm-f4uX16X55qAAAc3c"]
[Thu Sep 17 15:26:10.890831 2026] [security2:error] [pid 1029697:tid 1029766] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/aws/.env"] [unique_id "aqxa8m65wm-f4uX16X55qgAAc0Q"]
[Thu Sep 17 15:26:10.890851 2026] [security2:error] [pid 1029697:tid 1029815] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/public_html/.env"] [unique_id "aqxa8m65wm-f4uX16X55ogAAc3U"]
[Thu Sep 17 15:26:10.890906 2026] [security2:error] [pid 1029697:tid 1029705] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/v1/.env"] [unique_id "aqxa8m65wm-f4uX16X55rwAAcwc"]
[Thu Sep 17 15:26:10.890921 2026] [security2:error] [pid 1029697:tid 1029819] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/v3/.env"] [unique_id "aqxa8m65wm-f4uX16X55sQAAc3k"]
[Thu Sep 17 15:26:10.891029 2026] [security2:error] [pid 1029697:tid 1029822] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/v2/.env"] [unique_id "aqxa8m65wm-f4uX16X55sAAAc3w"]
[Thu Sep 17 15:26:10.901830 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.97.29.237:52796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxa8m65wm-f4uX16X55sgAAAFs"]
[Thu Sep 17 15:26:10.915136 2026] [security2:error] [pid 1029697:tid 1029800] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/administrator/.env"] [unique_id "aqxa8m65wm-f4uX16X55pgAAc2Y"]
[Thu Sep 17 15:26:10.942313 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.18.173.5:38390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxa8m65wm-f4uX16X55twAAAEc"]
[Thu Sep 17 15:26:11.040025 2026] [security2:error] [pid 1029697:tid 1029932] [client 185.55.149.49:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa8265wm-f4uX16X55ugAAAGk"]
[Thu Sep 17 15:26:11.040149 2026] [security2:error] [pid 1029697:tid 1029932] [client 185.55.149.49:61994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa8265wm-f4uX16X55ugAAAGk"]
[Thu Sep 17 15:26:11.083744 2026] [security2:error] [pid 1029697:tid 1029704] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/media/.env"] [unique_id "aqxa8265wm-f4uX16X55vwAAHQY"]
[Thu Sep 17 15:26:11.084086 2026] [security2:error] [pid 1029697:tid 1029717] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.git/config.bak"] [unique_id "aqxa8265wm-f4uX16X55yQAAHRM"]
[Thu Sep 17 15:26:11.115584 2026] [security2:error] [pid 1029697:tid 1029929] [client 8.231.55.47:33716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxa8265wm-f4uX16X55ywAAAGY"]
[Thu Sep 17 15:26:11.272421 2026] [security2:error] [pid 1029697:tid 1029726] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/id_rsa"] [unique_id "aqxa8265wm-f4uX16X552AAADRw"]
[Thu Sep 17 15:26:11.272518 2026] [security2:error] [pid 1029697:tid 1029728] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.aws/credentials.bak"] [unique_id "aqxa8265wm-f4uX16X551AAADR4"]
[Thu Sep 17 15:26:11.272756 2026] [security2:error] [pid 1029697:tid 1029735] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.ssh/id_rsa"] [unique_id "aqxa8265wm-f4uX16X552QAADSU"]
[Thu Sep 17 15:26:11.278200 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.97.29.237:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxa8265wm-f4uX16X553AAAAEI"]
[Thu Sep 17 15:26:11.586071 2026] [security2:error] [pid 1029697:tid 1029844] [client 8.231.55.47:33732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa8265wm-f4uX16X554QAAABE"]
[Thu Sep 17 15:26:11.635681 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxa8265wm-f4uX16X558wAAAHY"]
[Thu Sep 17 15:26:11.638883 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.97.29.237:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/core/phpinfo.php"] [unique_id "aqxa8265wm-f4uX16X559AAAAFg"]
[Thu Sep 17 15:26:11.690474 2026] [security2:error] [pid 1029697:tid 1029770] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/config.php"] [unique_id "aqxa8265wm-f4uX16X559gAAD0g"]
[Thu Sep 17 15:26:11.787201 2026] [security2:error] [pid 1029697:tid 1029902] [client 74.7.228.62:40810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rocketboxcreative.com"] [uri "/index.php"] [unique_id "aqxa8W65wm-f4uX16X55LgAASxo"]
[Thu Sep 17 15:26:11.866904 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxa8265wm-f4uX16X56CQAAAHI"]
[Thu Sep 17 15:26:11.874268 2026] [security2:error] [pid 1029697:tid 1029793] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/config/mail.php"] [unique_id "aqxa8265wm-f4uX16X56EwAARV8"]
[Thu Sep 17 15:26:11.874282 2026] [security2:error] [pid 1029697:tid 1029786] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/config/aws.php"] [unique_id "aqxa8265wm-f4uX16X56DAAARVg"]
[Thu Sep 17 15:26:11.874761 2026] [security2:error] [pid 1029697:tid 1029795] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/config/config.inc.php"] [unique_id "aqxa8265wm-f4uX16X56FAAARWE"]
[Thu Sep 17 15:26:11.874795 2026] [security2:error] [pid 1029697:tid 1029793] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/config/stripe.php"] [unique_id "aqxa8265wm-f4uX16X56FQAARV8"]
[Thu Sep 17 15:26:11.875185 2026] [security2:error] [pid 1029697:tid 1029781] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/config/nexmo.php"] [unique_id "aqxa8265wm-f4uX16X56FwAARVM"]
[Thu Sep 17 15:26:11.963946 2026] [security2:error] [pid 1029697:tid 1029851] [client 8.231.55.47:33732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xug.rxg.mybluehost.me"] [uri "/index.php"] [unique_id "aqxa8265wm-f4uX16X56CAAAABg"]
[Thu Sep 17 15:26:12.005197 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.97.29.237:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.29.97.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agent-immobilier.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxa9G65wm-f4uX16X56HgAAAC0"]
[Thu Sep 17 15:26:12.057718 2026] [security2:error] [pid 1029697:tid 1029803] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cobblehillstudio.net"] [uri "/wp-config.php.new"] [unique_id "aqxa9G65wm-f4uX16X56IAAAB2k"]
[Thu Sep 17 15:26:12.057718 2026] [security2:error] [pid 1029697:tid 1029794] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cobblehillstudio.net"] [uri "/wp-config.php.old"] [unique_id "aqxa9G65wm-f4uX16X56IQAAB2A"]
[Thu Sep 17 15:26:12.057719 2026] [security2:error] [pid 1029697:tid 1029774] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cobblehillstudio.net"] [uri "/wp-config.php.bak"] [unique_id "aqxa9G65wm-f4uX16X56IgAAB0w"]
[Thu Sep 17 15:26:12.058217 2026] [security2:error] [pid 1029697:tid 1029785] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/wp-config.php"] [unique_id "aqxa9G65wm-f4uX16X56HwAAB1c"]
[Thu Sep 17 15:26:12.059220 2026] [security2:error] [pid 1029697:tid 1029797] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/.wp-config.php.swp"] [unique_id "aqxa9G65wm-f4uX16X56IwAAYGM"]
[Thu Sep 17 15:26:12.062419 2026] [security2:error] [pid 1029697:tid 1029789] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/terraform.tfstate.backup"] [unique_id "aqxa9G65wm-f4uX16X56LQAAfFs"]
[Thu Sep 17 15:26:12.062424 2026] [security2:error] [pid 1029697:tid 1029798] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/wp-content/mysql.sql"] [unique_id "aqxa9G65wm-f4uX16X56JgAAfGQ"]
[Thu Sep 17 15:26:12.097170 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxa9G65wm-f4uX16X56MQAAAG0"]
[Thu Sep 17 15:26:12.137163 2026] [security2:error] [pid 1029697:tid 1029831] [client 8.231.55.47:33732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxa9G65wm-f4uX16X56MgAAAAQ"]
[Thu Sep 17 15:26:12.327941 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxa9G65wm-f4uX16X56QwAAAFc"]
[Thu Sep 17 15:26:12.557635 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxa9G65wm-f4uX16X56WQAAABU"]
[Thu Sep 17 15:26:12.683588 2026] [security2:error] [pid 1029697:tid 1029867] [client 8.231.55.47:33742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxa9G65wm-f4uX16X56WwAAACg"]
[Thu Sep 17 15:26:12.780789 2026] [security2:error] [pid 1029697:tid 1029821] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/phpinfo.php"] [unique_id "aqxa9G65wm-f4uX16X56awAABns"]
[Thu Sep 17 15:26:12.788289 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxa9G65wm-f4uX16X56bAAAAAg"]
[Thu Sep 17 15:26:13.017824 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxa9W65wm-f4uX16X56cgAAAGE"]
[Thu Sep 17 15:26:13.249040 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxa9W65wm-f4uX16X56eAAAAA4"]
[Thu Sep 17 15:26:13.252258 2026] [security2:error] [pid 1029697:tid 1029886] [client 45.156.128.177:59570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxa9W65wm-f4uX16X56dAAAADs"]
[Thu Sep 17 15:26:13.307916 2026] [security2:error] [pid 1029697:tid 1029898] [client 8.231.55.47:33754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxa9W65wm-f4uX16X56egAAAEc"]
[Thu Sep 17 15:26:13.310560 2026] [security2:error] [pid 1029697:tid 1029733] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/infophp.php"] [unique_id "aqxa9W65wm-f4uX16X56ggAAfSM"]
[Thu Sep 17 15:26:13.310585 2026] [security2:error] [pid 1029697:tid 1029719] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/infos.php"] [unique_id "aqxa9W65wm-f4uX16X56gQAAfRU"]
[Thu Sep 17 15:26:13.310607 2026] [security2:error] [pid 1029697:tid 1029737] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/info.php"] [unique_id "aqxa9W65wm-f4uX16X56fQAAfSc"]
[Thu Sep 17 15:26:13.310648 2026] [security2:error] [pid 1029697:tid 1029745] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/admin_phpinfo.php"] [unique_id "aqxa9W65wm-f4uX16X56hgAAfS8"]
[Thu Sep 17 15:26:13.310704 2026] [security2:error] [pid 1029697:tid 1029812] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/php-info.php"] [unique_id "aqxa9W65wm-f4uX16X56fgAAfXI"]
[Thu Sep 17 15:26:13.310707 2026] [security2:error] [pid 1029697:tid 1029712] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/php_info.php"] [unique_id "aqxa9W65wm-f4uX16X56fwAAfQ4"]
[Thu Sep 17 15:26:13.310724 2026] [security2:error] [pid 1029697:tid 1029732] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxa9W65wm-f4uX16X56hAAAfSI"]
[Thu Sep 17 15:26:13.310799 2026] [security2:error] [pid 1029697:tid 1029738] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxa9W65wm-f4uX16X56hQAAfSg"]
[Thu Sep 17 15:26:13.310799 2026] [security2:error] [pid 1029697:tid 1029746] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/php.php"] [unique_id "aqxa9W65wm-f4uX16X56gAAAfTA"]
[Thu Sep 17 15:26:13.310854 2026] [security2:error] [pid 1029697:tid 1029749] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/public/phpinfo.php"] [unique_id "aqxa9W65wm-f4uX16X56iAAAfTM"]
[Thu Sep 17 15:26:13.310883 2026] [security2:error] [pid 1029697:tid 1029758] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/api/phpinfo.php"] [unique_id "aqxa9W65wm-f4uX16X56hwAAfTw"]
[Thu Sep 17 15:26:13.478174 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxa9W65wm-f4uX16X56kgAAAHs"]
[Thu Sep 17 15:26:13.499590 2026] [security2:error] [pid 1029697:tid 1029752] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/database.sql"] [unique_id "aqxa9W65wm-f4uX16X56kwAAPzY"]
[Thu Sep 17 15:26:13.705047 2026] [security2:error] [pid 1029697:tid 1029756] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cobblehillstudio.net"] [uri "/wp-config.php.txt"] [unique_id "aqxa9W65wm-f4uX16X56qgAAWDo"]
[Thu Sep 17 15:26:13.706384 2026] [security2:error] [pid 1029697:tid 1029724] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/ses/.env"] [unique_id "aqxa9W65wm-f4uX16X56rAAAWBo"]
[Thu Sep 17 15:26:13.706604 2026] [security2:error] [pid 1029697:tid 1029771] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/lib/.env"] [unique_id "aqxa9W65wm-f4uX16X56qQAAWEk"]
[Thu Sep 17 15:26:13.706754 2026] [security2:error] [pid 1029697:tid 1029781] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/.git/config~"] [unique_id "aqxa9W65wm-f4uX16X56swAAWFM"]
[Thu Sep 17 15:26:13.714172 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxa9W65wm-f4uX16X56tQAAADA"]
[Thu Sep 17 15:26:13.816875 2026] [security2:error] [pid 1029697:tid 1029920] [client 8.231.55.47:33766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxa9W65wm-f4uX16X56twAAAF0"]
[Thu Sep 17 15:26:13.907844 2026] [security2:error] [pid 1029697:tid 1029794] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cobblehillstudio.net"] [uri "/sites/default/settings.php.swp"] [unique_id "aqxa9W65wm-f4uX16X56vgAAD2A"]
[Thu Sep 17 15:26:13.909052 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/yii/.env"] [unique_id "aqxa9W65wm-f4uX16X56vwAADys"]
[Thu Sep 17 15:26:13.909135 2026] [security2:error] [pid 1029697:tid 1029784] [remote 45.138.12.30:54230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cobblehillstudio.net"] [uri "/www.bak"] [unique_id "aqxa9W65wm-f4uX16X56wgAAD1Y"]
[Thu Sep 17 15:26:13.944299 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxa9W65wm-f4uX16X56yAAAAEs"]
[Thu Sep 17 15:26:14.045932 2026] [security2:error] [pid 1029697:tid 1029846] [client 168.231.102.168:52868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "gillilanproductions.com"] [uri "/.git/config"] [unique_id "aqxa9m65wm-f4uX16X560gAAABM"]
[Thu Sep 17 15:26:14.175744 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxa9m65wm-f4uX16X561wAAAHw"]
[Thu Sep 17 15:26:14.259442 2026] [security2:error] [pid 1029697:tid 1029834] [client 31.171.130.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywellnessinparis.com"] [uri "/index.php"] [unique_id "aqxa9m65wm-f4uX16X561gAAAAc"], referer: https://mywellnessinparis.com/
[Thu Sep 17 15:26:14.273677 2026] [security2:error] [pid 1029697:tid 1029944] [client 104.207.33.33:56825] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxa9m65wm-f4uX16X562AAAAHU"]
[Thu Sep 17 15:26:14.416188 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxa9m65wm-f4uX16X562gAAADc"]
[Thu Sep 17 15:26:14.645203 2026] [security2:error] [pid 1029697:tid 1029859] [client 8.231.55.47:33782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxa9m65wm-f4uX16X566gAAACA"]
[Thu Sep 17 15:26:14.649406 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxa9m65wm-f4uX16X566wAAAFE"]
[Thu Sep 17 15:26:14.775972 2026] [security2:error] [pid 1029697:tid 1029860] [client 45.156.128.177:59572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxa9m65wm-f4uX16X567QAAACE"]
[Thu Sep 17 15:26:14.841690 2026] [security2:error] [pid 1029697:tid 1029924] [client 4.240.114.86:61216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxa9m65wm-f4uX16X568AAAAGE"], referer: binance.com
[Thu Sep 17 15:26:14.885508 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxa9m65wm-f4uX16X568QAAABk"]
[Thu Sep 17 15:26:15.115347 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxa9265wm-f4uX16X56-wAAAEA"]
[Thu Sep 17 15:26:15.134306 2026] [security2:error] [pid 1029697:tid 1029918] [client 8.231.55.47:33788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxa9265wm-f4uX16X56_AAAAFs"]
[Thu Sep 17 15:26:15.346640 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxa9265wm-f4uX16X57AAAAAB4"]
[Thu Sep 17 15:26:15.580182 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxa9265wm-f4uX16X57CAAAACk"]
[Thu Sep 17 15:26:15.687618 2026] [security2:error] [pid 1029697:tid 1029928] [client 8.231.55.47:33800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxa9265wm-f4uX16X57DAAAAGU"]
[Thu Sep 17 15:26:15.811534 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxa9265wm-f4uX16X57DgAAADA"]
[Thu Sep 17 15:26:16.043121 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxa-G65wm-f4uX16X57FgAAABM"]
[Thu Sep 17 15:26:16.280566 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxa-G65wm-f4uX16X57HQAAADw"]
[Thu Sep 17 15:26:16.377375 2026] [security2:error] [pid 1029697:tid 1029923] [client 8.231.55.47:33802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxa-G65wm-f4uX16X57IAAAAGA"]
[Thu Sep 17 15:26:16.511024 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxa-G65wm-f4uX16X57JwAAACA"]
[Thu Sep 17 15:26:16.740983 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxa-G65wm-f4uX16X57LgAAACM"]
[Thu Sep 17 15:26:16.978040 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxa-G65wm-f4uX16X57NAAAAGE"]
[Thu Sep 17 15:26:17.167599 2026] [security2:error] [pid 1029697:tid 1029884] [client 139.59.114.163:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.slimmtech.com"] [uri "/index.php"] [unique_id "aqxa-W65wm-f4uX16X57NwAAOWI"], referer: http://mail.slimmtech.com/wp/
[Thu Sep 17 15:26:17.222640 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxa-W65wm-f4uX16X57OAAAAEg"]
[Thu Sep 17 15:26:17.453749 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxa-W65wm-f4uX16X57PAAAAFs"]
[Thu Sep 17 15:26:17.585888 2026] [security2:error] [pid 1029697:tid 1029942] [client 139.59.114.163:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.slimmtech.com"] [uri "/index.php"] [unique_id "aqxa-W65wm-f4uX16X57QgAAc1U"], referer: http://mail.slimmtech.com/old/
[Thu Sep 17 15:26:17.683454 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxa-W65wm-f4uX16X57QwAAADQ"]
[Thu Sep 17 15:26:17.741110 2026] [security2:error] [pid 1029697:tid 1029900] [client 114.198.138.124:61704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-W65wm-f4uX16X57RgAAAEk"]
[Thu Sep 17 15:26:17.741189 2026] [security2:error] [pid 1029697:tid 1029900] [client 114.198.138.124:61704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-W65wm-f4uX16X57RgAAAEk"]
[Thu Sep 17 15:26:17.790790 2026] [security2:error] [pid 1029697:tid 1029891] [client 154.190.208.131:42155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-W65wm-f4uX16X57SQAAAEA"]
[Thu Sep 17 15:26:17.800246 2026] [security2:error] [pid 1029697:tid 1029891] [client 154.190.208.131:42155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-W65wm-f4uX16X57SQAAAEA"]
[Thu Sep 17 15:26:17.802265 2026] [security2:error] [pid 1029697:tid 1029866] [client 45.156.128.178:54470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxa-W65wm-f4uX16X57RAAAACc"]
[Thu Sep 17 15:26:17.848194 2026] [security2:error] [pid 1029697:tid 1029874] [client 8.231.55.47:33804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxa-W65wm-f4uX16X57SgAAAC8"]
[Thu Sep 17 15:26:17.857254 2026] [security2:error] [pid 1029697:tid 1029952] [client 78.173.64.96:25343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxa-W65wm-f4uX16X57RQAAfQc"]
[Thu Sep 17 15:26:17.913273 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxa-W65wm-f4uX16X57TAAAAAI"]
[Thu Sep 17 15:26:18.025911 2026] [security2:error] [pid 1029697:tid 1029853] [client 156.192.234.52:50669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-m65wm-f4uX16X57VQAAABo"]
[Thu Sep 17 15:26:18.026544 2026] [security2:error] [pid 1029697:tid 1029853] [client 156.192.234.52:50669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-m65wm-f4uX16X57VQAAABo"]
[Thu Sep 17 15:26:18.143677 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxa-m65wm-f4uX16X57VwAAAEI"]
[Thu Sep 17 15:26:18.212627 2026] [security2:error] [pid 1029697:tid 1029875] [client 8.231.55.47:33810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxa-m65wm-f4uX16X57WgAAADA"]
[Thu Sep 17 15:26:18.374603 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxa-m65wm-f4uX16X57XwAAAEs"]
[Thu Sep 17 15:26:18.408417 2026] [security2:error] [pid 1029697:tid 1029904] [client 139.59.114.163:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.slimmtech.com"] [uri "/index.php"] [unique_id "aqxa-m65wm-f4uX16X57YAAATXc"], referer: http://mail.slimmtech.com/wordpress/
[Thu Sep 17 15:26:18.606070 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxa-m65wm-f4uX16X57ZgAAAEw"]
[Thu Sep 17 15:26:18.671533 2026] [security2:error] [pid 1029697:tid 1029905] [client 8.231.55.47:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxa-m65wm-f4uX16X57aAAAAE4"]
[Thu Sep 17 15:26:18.834315 2026] [security2:error] [pid 1029697:tid 1029872] [client 139.59.114.163:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.slimmtech.com"] [uri "/index.php"] [unique_id "aqxa-m65wm-f4uX16X57awAALX4"], referer: http://mail.slimmtech.com/blog/
[Thu Sep 17 15:26:18.838896 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxa-m65wm-f4uX16X57bAAAAHE"]
[Thu Sep 17 15:26:19.068899 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxa-265wm-f4uX16X57ewAAAHc"]
[Thu Sep 17 15:26:19.136896 2026] [security2:error] [pid 1029697:tid 1029922] [client 162.241.226.11:59610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "beiselcoaching.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxa-265wm-f4uX16X57fQAAAF8"]
[Thu Sep 17 15:26:19.227940 2026] [security2:error] [pid 1029697:tid 1029835] [client 8.231.55.47:33824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxa-265wm-f4uX16X57gAAAAAg"]
[Thu Sep 17 15:26:19.246755 2026] [security2:error] [pid 1029697:tid 1029935] [client 139.59.114.163:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.slimmtech.com"] [uri "/index.php"] [unique_id "aqxa-265wm-f4uX16X57ggAAbGY"], referer: http://mail.slimmtech.com/new/
[Thu Sep 17 15:26:19.251409 2026] [security2:error] [pid 1029697:tid 1029845] [client 210.222.43.21:58171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxa-265wm-f4uX16X57fAAAABI"], referer: http://talent-in-borders.com/SHOP
[Thu Sep 17 15:26:19.270776 2026] [security2:error] [pid 1029697:tid 1029886] [client 169.58.197.253:57309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxa-265wm-f4uX16X57gwAAADs"], referer: binance.com
[Thu Sep 17 15:26:19.301243 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxa-265wm-f4uX16X57hAAAAAA"]
[Thu Sep 17 15:26:19.488061 2026] [security2:error] [pid 1029697:tid 1029924] [client 103.61.184.148:62520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-265wm-f4uX16X57igAAAGE"]
[Thu Sep 17 15:26:19.488153 2026] [security2:error] [pid 1029697:tid 1029924] [client 103.61.184.148:62520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxa-265wm-f4uX16X57igAAAGE"]
[Thu Sep 17 15:26:19.531256 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxa-265wm-f4uX16X57jQAAACc"]
[Thu Sep 17 15:26:19.588891 2026] [security2:error] [pid 1029697:tid 1029891] [client 8.231.55.47:33832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxa-265wm-f4uX16X57jgAAAEA"]
[Thu Sep 17 15:26:19.666003 2026] [security2:error] [pid 1029697:tid 1029868] [client 139.59.114.163:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.slimmtech.com"] [uri "/index.php"] [unique_id "aqxa-265wm-f4uX16X57kAAAKX0"], referer: http://mail.slimmtech.com/backup/
[Thu Sep 17 15:26:19.767388 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxa-265wm-f4uX16X57kgAAAEI"]
[Thu Sep 17 15:26:19.998618 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxa-265wm-f4uX16X57lwAAABg"]
[Thu Sep 17 15:26:20.080992 2026] [security2:error] [pid 1029697:tid 1029920] [client 3.82.141.143:49938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "torringtonhandyman.com"] [uri "/.env.backup"] [unique_id "aqxa_G65wm-f4uX16X57ngAAAF0"]
[Thu Sep 17 15:26:20.082142 2026] [security2:error] [pid 1029697:tid 1029847] [client 3.82.141.143:50234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "torringtonhandyman.com"] [uri "/wp-config.php~"] [unique_id "aqxa_G65wm-f4uX16X57qAAAABQ"]
[Thu Sep 17 15:26:20.083337 2026] [security2:error] [pid 1029697:tid 1029861] [client 3.82.141.143:50052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "torringtonhandyman.com"] [uri "/config.php"] [unique_id "aqxa_G65wm-f4uX16X57rQAAACI"]
[Thu Sep 17 15:26:20.084179 2026] [security2:error] [pid 1029697:tid 1029925] [client 3.82.141.143:50202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "torringtonhandyman.com"] [uri "/wp-config.php"] [unique_id "aqxa_G65wm-f4uX16X57swAAAGI"]
[Thu Sep 17 15:26:20.085291 2026] [security2:error] [pid 1029697:tid 1029936] [client 3.82.141.143:50216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "torringtonhandyman.com"] [uri "/wp-config.php.bak"] [unique_id "aqxa_G65wm-f4uX16X57tQAAAG0"]
[Thu Sep 17 15:26:20.087089 2026] [security2:error] [pid 1029697:tid 1029944] [client 3.82.141.143:50230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "torringtonhandyman.com"] [uri "/wp-config.php.save"] [unique_id "aqxa_G65wm-f4uX16X57uwAAAHU"]
[Thu Sep 17 15:26:20.098889 2026] [security2:error] [pid 1029697:tid 1029872] [client 3.82.141.143:49894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "torringtonhandyman.com"] [uri "/.env"] [unique_id "aqxa_G65wm-f4uX16X57xgAAAC0"]
[Thu Sep 17 15:26:20.099320 2026] [security2:error] [pid 1029697:tid 1029896] [client 3.82.141.143:49954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "torringtonhandyman.com"] [uri "/.env.old"] [unique_id "aqxa_G65wm-f4uX16X57xQAAAEU"]
[Thu Sep 17 15:26:20.099319 2026] [security2:error] [pid 1029697:tid 1029940] [client 3.82.141.143:49956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "torringtonhandyman.com"] [uri "/.env.bak"] [unique_id "aqxa_G65wm-f4uX16X57xAAAAHE"]
[Thu Sep 17 15:26:20.099711 2026] [security2:error] [pid 1029697:tid 1029895] [client 3.82.141.143:50078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "torringtonhandyman.com"] [uri "/web.config"] [unique_id "aqxa_G65wm-f4uX16X57yAAAAEQ"]
[Thu Sep 17 15:26:20.108035 2026] [security2:error] [pid 1029697:tid 1029931] [client 3.82.141.143:50228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "torringtonhandyman.com"] [uri "/wp-config.php.old"] [unique_id "aqxa_G65wm-f4uX16X572AAAAGg"]
[Thu Sep 17 15:26:20.163148 2026] [security2:error] [pid 1029697:tid 1029883] [client 185.55.149.49:56619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa_G65wm-f4uX16X577wAAADg"]
[Thu Sep 17 15:26:20.163287 2026] [security2:error] [pid 1029697:tid 1029883] [client 185.55.149.49:56619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxa_G65wm-f4uX16X577wAAADg"]
[Thu Sep 17 15:26:20.179404 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.94.254.227:43710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/"] [unique_id "aqxa_G65wm-f4uX16X578QAAAGY"]
[Thu Sep 17 15:26:20.230256 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxa_G65wm-f4uX16X578gAAAB0"]
[Thu Sep 17 15:26:20.362228 2026] [security2:error] [pid 1029697:tid 1029912] [client 8.231.55.47:33842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxa_G65wm-f4uX16X57-QAAAFU"]
[Thu Sep 17 15:26:20.382528 2026] [security2:error] [pid 1029697:tid 1029888] [client 3.82.141.143:50054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X57mgAAAD0"]
[Thu Sep 17 15:26:20.389679 2026] [security2:error] [pid 1029697:tid 1029869] [client 3.82.141.143:50106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X57zQAAACo"]
[Thu Sep 17 15:26:20.390899 2026] [security2:error] [pid 1029697:tid 1029859] [client 3.82.141.143:50112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X57wwAAACA"]
[Thu Sep 17 15:26:20.391763 2026] [security2:error] [pid 1029697:tid 1029831] [client 3.82.141.143:50070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X57ygAAAAQ"]
[Thu Sep 17 15:26:20.400320 2026] [security2:error] [pid 1029697:tid 1029906] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X571QAAAE8"]
[Thu Sep 17 15:26:20.400769 2026] [security2:error] [pid 1029697:tid 1029887] [client 3.82.141.143:50062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X57zwAAADw"]
[Thu Sep 17 15:26:20.407545 2026] [security2:error] [pid 1029697:tid 1029848] [client 3.82.141.143:50074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X572QAAABU"]
[Thu Sep 17 15:26:20.407650 2026] [security2:error] [pid 1029697:tid 1029923] [client 3.82.141.143:50020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X57qQAAAGA"]
[Thu Sep 17 15:26:20.412487 2026] [security2:error] [pid 1029697:tid 1029898] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X575QAAAEc"]
[Thu Sep 17 15:26:20.416465 2026] [security2:error] [pid 1029697:tid 1029870] [client 4.240.114.86:63763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxa_G65wm-f4uX16X57-wAAACs"], referer: binance.com
[Thu Sep 17 15:26:20.432471 2026] [security2:error] [pid 1029697:tid 1029866] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X576wAAACc"]
[Thu Sep 17 15:26:20.447791 2026] [security2:error] [pid 1029697:tid 1029891] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X577AAAAEA"]
[Thu Sep 17 15:26:20.476875 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxa_G65wm-f4uX16X57_AAAADg"]
[Thu Sep 17 15:26:20.517110 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.94.254.227:43716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/"] [unique_id "aqxa_G65wm-f4uX16X57_wAAAF8"]
[Thu Sep 17 15:26:20.707267 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxa_G65wm-f4uX16X58FQAAAAY"]
[Thu Sep 17 15:26:20.747049 2026] [security2:error] [pid 1029697:tid 1029913] [client 8.231.55.47:33846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxa_G65wm-f4uX16X58FwAAAFY"]
[Thu Sep 17 15:26:20.778065 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.94.254.227:43730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/"] [unique_id "aqxa_G65wm-f4uX16X58HQAAAGs"]
[Thu Sep 17 15:26:20.861742 2026] [security2:error] [pid 1029697:tid 1029856] [client 192.178.6.3:46409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxa_G65wm-f4uX16X58IgAAAB0"]
[Thu Sep 17 15:26:20.957240 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxa_G65wm-f4uX16X58JAAAABI"]
[Thu Sep 17 15:26:21.037575 2026] [security2:error] [pid 1029697:tid 1029873] [client 45.156.128.179:17688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58IwAAAC4"]
[Thu Sep 17 15:26:21.107927 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.94.254.227:43738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/"] [unique_id "aqxa_W65wm-f4uX16X58KwAAAHQ"]
[Thu Sep 17 15:26:21.188884 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxa_W65wm-f4uX16X58LAAAAB4"]
[Thu Sep 17 15:26:21.239994 2026] [security2:error] [pid 1029697:tid 1029848] [client 8.231.55.47:39982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxa_W65wm-f4uX16X58LQAAABU"]
[Thu Sep 17 15:26:21.420407 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxa_W65wm-f4uX16X58MwAAAEM"]
[Thu Sep 17 15:26:21.485246 2026] [security2:error] [pid 1029697:tid 1029867] [client 45.156.128.177:12680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxa_W65wm-f4uX16X58MAAAACg"]
[Thu Sep 17 15:26:21.652314 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxa_W65wm-f4uX16X58OwAAACE"]
[Thu Sep 17 15:26:21.736685 2026] [security2:error] [pid 1029697:tid 1029837] [client 8.231.55.47:39988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxa_W65wm-f4uX16X58QAAAAAo"]
[Thu Sep 17 15:26:21.886014 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxa_W65wm-f4uX16X58RgAAAB8"]
[Thu Sep 17 15:26:22.115941 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxa_m65wm-f4uX16X58UwAAACM"]
[Thu Sep 17 15:26:22.179219 2026] [security2:error] [pid 1029697:tid 1029833] [client 104.207.33.33:19769] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxa_m65wm-f4uX16X58VgAAAAY"]
[Thu Sep 17 15:26:22.179921 2026] [security2:error] [pid 1029697:tid 1029946] [client 162.241.226.11:41328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "beiselcoaching.com"] [uri "/wp-cron.php"] [unique_id "aqxa_m65wm-f4uX16X58VwAAAHc"]
[Thu Sep 17 15:26:22.348246 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxa_m65wm-f4uX16X58XAAAAGc"]
[Thu Sep 17 15:26:22.408300 2026] [security2:error] [pid 1029697:tid 1029917] [client 8.231.55.47:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxa_m65wm-f4uX16X58XgAAAFo"]
[Thu Sep 17 15:26:22.413967 2026] [security2:error] [pid 1029697:tid 1029948] [client 3.82.141.143:50302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58BwAAAHk"], referer: https://torringtonhandyman.com/config.js
[Thu Sep 17 15:26:22.425310 2026] [security2:error] [pid 1029697:tid 1029944] [client 3.82.141.143:50284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58BgAAAHU"], referer: https://torringtonhandyman.com/credentials.json
[Thu Sep 17 15:26:22.427710 2026] [security2:error] [pid 1029697:tid 1029885] [client 3.82.141.143:50288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58BAAAADo"], referer: https://torringtonhandyman.com/secrets.json
[Thu Sep 17 15:26:22.429669 2026] [security2:error] [pid 1029697:tid 1029834] [client 3.82.141.143:50256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58BQAAAAc"], referer: https://torringtonhandyman.com/settings.json
[Thu Sep 17 15:26:22.430601 2026] [security2:error] [pid 1029697:tid 1029908] [client 3.82.141.143:50262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58CQAAAFE"], referer: https://torringtonhandyman.com/appsettings.json
[Thu Sep 17 15:26:22.430789 2026] [security2:error] [pid 1029697:tid 1029835] [client 3.82.141.143:50304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58CAAAAAg"], referer: https://torringtonhandyman.com/secret.json
[Thu Sep 17 15:26:22.441439 2026] [security2:error] [pid 1029697:tid 1029953] [client 3.82.141.143:50270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58CgAAAH4"], referer: https://torringtonhandyman.com/appsettings.Development.json
[Thu Sep 17 15:26:22.447149 2026] [security2:error] [pid 1029697:tid 1029868] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58GAAAACk"], referer: https://torringtonhandyman.com/.s3cfg
[Thu Sep 17 15:26:22.465879 2026] [security2:error] [pid 1029697:tid 1029918] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58GwAAAFs"], referer: https://torringtonhandyman.com/.npmrc
[Thu Sep 17 15:26:22.465892 2026] [security2:error] [pid 1029697:tid 1029927] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58FgAAAGQ"], referer: https://torringtonhandyman.com/application.properties
[Thu Sep 17 15:26:22.484379 2026] [security2:error] [pid 1029697:tid 1029886] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxa_G65wm-f4uX16X58HAAAADs"], referer: https://torringtonhandyman.com/.boto
[Thu Sep 17 15:26:22.578088 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxa_m65wm-f4uX16X58aAAAACs"]
[Thu Sep 17 15:26:22.815001 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxa_m65wm-f4uX16X58bQAAAF4"]
[Thu Sep 17 15:26:23.057417 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxa_265wm-f4uX16X58dAAAAEs"]
[Thu Sep 17 15:26:23.105289 2026] [security2:error] [pid 1029697:tid 1029867] [client 8.231.55.47:40002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxa_265wm-f4uX16X58eAAAACg"]
[Thu Sep 17 15:26:23.291686 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxa_265wm-f4uX16X58fgAAAG0"]
[Thu Sep 17 15:26:23.526972 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxa_265wm-f4uX16X58hwAAAGs"]
[Thu Sep 17 15:26:23.574015 2026] [security2:error] [pid 1029697:tid 1029901] [client 8.231.55.47:40014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxa_265wm-f4uX16X58iQAAAEo"]
[Thu Sep 17 15:26:23.756387 2026] [security2:error] [pid 1029697:tid 1029928] [client 162.241.226.11:41344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "beiselcoaching.com"] [uri "/wp-cron.php"] [unique_id "aqxa_265wm-f4uX16X58jwAAAGU"]
[Thu Sep 17 15:26:23.762478 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxa_265wm-f4uX16X58kAAAAB0"]
[Thu Sep 17 15:26:23.899599 2026] [security2:error] [pid 1029697:tid 1029937] [client 45.156.128.179:17692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxa_265wm-f4uX16X58lAAAAG4"]
[Thu Sep 17 15:26:23.998732 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxa_265wm-f4uX16X58mgAAACk"]
[Thu Sep 17 15:26:24.022502 2026] [security2:error] [pid 1029697:tid 1029944] [client 8.231.55.47:40030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxbAG65wm-f4uX16X58ngAAAHU"]
[Thu Sep 17 15:26:24.241142 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxbAG65wm-f4uX16X58owAAABA"]
[Thu Sep 17 15:26:24.477039 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxbAG65wm-f4uX16X58qQAAACc"]
[Thu Sep 17 15:26:24.492070 2026] [security2:error] [pid 1029697:tid 1029954] [client 8.231.55.47:40046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbAG65wm-f4uX16X58qgAAAH8"]
[Thu Sep 17 15:26:24.706574 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxbAG65wm-f4uX16X58swAAAAI"]
[Thu Sep 17 15:26:24.937633 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxbAG65wm-f4uX16X58uAAAAGM"]
[Thu Sep 17 15:26:25.102992 2026] [security2:error] [pid 1029697:tid 1029945] [client 8.231.55.47:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbAW65wm-f4uX16X58vgAAAHY"]
[Thu Sep 17 15:26:25.174937 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxbAW65wm-f4uX16X58wAAAAAk"]
[Thu Sep 17 15:26:25.408789 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxbAW65wm-f4uX16X58yAAAAGk"]
[Thu Sep 17 15:26:25.496529 2026] [security2:error] [pid 1029697:tid 1029950] [client 4.240.114.86:49511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxbAW65wm-f4uX16X58zQAAAHs"], referer: binance.com
[Thu Sep 17 15:26:25.506355 2026] [security2:error] [pid 1029697:tid 1029946] [client 8.231.55.47:40060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxbAW65wm-f4uX16X58zgAAAHc"]
[Thu Sep 17 15:26:25.640717 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxbAW65wm-f4uX16X581AAAAC0"]
[Thu Sep 17 15:26:25.878850 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxbAW65wm-f4uX16X583AAAADs"]
[Thu Sep 17 15:26:26.115152 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxbAm65wm-f4uX16X586AAAAAI"]
[Thu Sep 17 15:26:26.170844 2026] [security2:error] [pid 1029697:tid 1029908] [client 154.190.208.131:41369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbAm65wm-f4uX16X586QAAAFE"]
[Thu Sep 17 15:26:26.175337 2026] [security2:error] [pid 1029697:tid 1029908] [client 154.190.208.131:41369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbAm65wm-f4uX16X586QAAAFE"]
[Thu Sep 17 15:26:26.291510 2026] [security2:error] [pid 1029697:tid 1029859] [client 8.231.55.47:40068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.231.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xug.rxg.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxbAm65wm-f4uX16X587gAAACA"]
[Thu Sep 17 15:26:26.411972 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxbAm65wm-f4uX16X588gAAABU"]
[Thu Sep 17 15:26:26.469781 2026] [security2:error] [pid 1029697:tid 1029831] [client 45.156.128.178:34442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbAm65wm-f4uX16X588wAAAAQ"]
[Thu Sep 17 15:26:26.646442 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxbAm65wm-f4uX16X58_QAAAAo"]
[Thu Sep 17 15:26:26.880820 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxbAm65wm-f4uX16X59BwAAADg"]
[Thu Sep 17 15:26:26.887378 2026] [security2:error] [pid 1029697:tid 1029836] [client 169.58.197.253:57731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wp-view-config-data.php"] [unique_id "aqxbAm65wm-f4uX16X59CAAAAAk"], referer: binance.com
[Thu Sep 17 15:26:27.111799 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxbA265wm-f4uX16X59FQAAAAY"]
[Thu Sep 17 15:26:27.687000 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxbA265wm-f4uX16X59IQAAAB0"]
[Thu Sep 17 15:26:28.182278 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxbBG65wm-f4uX16X59QgAAACw"]
[Thu Sep 17 15:26:28.260378 2026] [security2:error] [pid 1029697:tid 1029841] [client 114.198.138.124:62351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbBG65wm-f4uX16X59SwAAAA4"]
[Thu Sep 17 15:26:28.260458 2026] [security2:error] [pid 1029697:tid 1029841] [client 114.198.138.124:62351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbBG65wm-f4uX16X59SwAAAA4"]
[Thu Sep 17 15:26:28.435394 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxbBG65wm-f4uX16X59UQAAAGM"]
[Thu Sep 17 15:26:28.665676 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxbBG65wm-f4uX16X59XAAAAH0"]
[Thu Sep 17 15:26:28.714012 2026] [security2:error] [pid 1029697:tid 1029837] [client 156.192.234.52:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbBG65wm-f4uX16X59XgAAAAo"]
[Thu Sep 17 15:26:28.714123 2026] [security2:error] [pid 1029697:tid 1029837] [client 156.192.234.52:51286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbBG65wm-f4uX16X59XgAAAAo"]
[Thu Sep 17 15:26:28.895459 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxbBG65wm-f4uX16X59ZAAAAF8"]
[Thu Sep 17 15:26:29.125611 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxbBW65wm-f4uX16X59cgAAABI"]
[Thu Sep 17 15:26:29.355743 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxbBW65wm-f4uX16X59fAAAABQ"]
[Thu Sep 17 15:26:29.397109 2026] [security2:error] [pid 1029697:tid 1029944] [client 45.156.128.177:11366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbBW65wm-f4uX16X59dwAAAHU"]
[Thu Sep 17 15:26:29.585991 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxbBW65wm-f4uX16X59hQAAAHQ"]
[Thu Sep 17 15:26:29.630317 2026] [security2:error] [pid 1029697:tid 1029923] [client 4.240.114.86:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxbBW65wm-f4uX16X59iQAAAGA"], referer: binance.com
[Thu Sep 17 15:26:29.816910 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.18.173.5:60452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxbBW65wm-f4uX16X59jwAAAB4"]
[Thu Sep 17 15:26:30.509105 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxbBm65wm-f4uX16X59rwAAAEw"]
[Thu Sep 17 15:26:30.591301 2026] [security2:error] [pid 1029697:tid 1029926] [client 103.61.184.148:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbBm65wm-f4uX16X59tQAAAGM"]
[Thu Sep 17 15:26:30.591426 2026] [security2:error] [pid 1029697:tid 1029926] [client 103.61.184.148:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbBm65wm-f4uX16X59tQAAAGM"]
[Thu Sep 17 15:26:30.739953 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxbBm65wm-f4uX16X59uAAAACU"]
[Thu Sep 17 15:26:30.825405 2026] [security2:error] [pid 1029697:tid 1029828] [client 185.55.149.49:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbBm65wm-f4uX16X59vQAAAAE"]
[Thu Sep 17 15:26:30.825506 2026] [security2:error] [pid 1029697:tid 1029828] [client 185.55.149.49:57868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbBm65wm-f4uX16X59vQAAAAE"]
[Thu Sep 17 15:26:30.972838 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxbBm65wm-f4uX16X59xAAAAHs"]
[Thu Sep 17 15:26:31.074575 2026] [security2:error] [pid 1029697:tid 1029902] [client 104.207.33.33:60537] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxbB265wm-f4uX16X59zAAAAEs"]
[Thu Sep 17 15:26:31.203046 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxbB265wm-f4uX16X590wAAAGo"]
[Thu Sep 17 15:26:31.432745 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxbB265wm-f4uX16X593AAAAEg"]
[Thu Sep 17 15:26:31.662442 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxbB265wm-f4uX16X595wAAAEY"]
[Thu Sep 17 15:26:31.901193 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxbB265wm-f4uX16X598QAAACY"]
[Thu Sep 17 15:26:32.132435 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxbCG65wm-f4uX16X59-QAAABE"]
[Thu Sep 17 15:26:32.363394 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxbCG65wm-f4uX16X5-AQAAACE"]
[Thu Sep 17 15:26:32.604207 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxbCG65wm-f4uX16X5-EQAAAFI"]
[Thu Sep 17 15:26:32.628305 2026] [security2:error] [pid 1029697:tid 1029940] [client 45.156.128.179:55238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbCG65wm-f4uX16X5-CQAAAHE"]
[Thu Sep 17 15:26:32.841459 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxbCG65wm-f4uX16X5-GgAAAFQ"]
[Thu Sep 17 15:26:33.084465 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxbCW65wm-f4uX16X5-JAAAAAc"]
[Thu Sep 17 15:26:33.322178 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxbCW65wm-f4uX16X5-LAAAADs"]
[Thu Sep 17 15:26:33.557953 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxbCW65wm-f4uX16X5-NgAAACo"]
[Thu Sep 17 15:26:33.792242 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxbCW65wm-f4uX16X5-PgAAAFs"]
[Thu Sep 17 15:26:34.034515 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxbCm65wm-f4uX16X5-SwAAAGE"]
[Thu Sep 17 15:26:34.271398 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxbCm65wm-f4uX16X5-UgAAABE"]
[Thu Sep 17 15:26:34.501668 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxbCm65wm-f4uX16X5-XAAAADY"]
[Thu Sep 17 15:26:34.537206 2026] [security2:error] [pid 1029697:tid 1029856] [client 4.240.114.86:53341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxbCm65wm-f4uX16X5-XwAAAB0"], referer: binance.com
[Thu Sep 17 15:26:34.730724 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxbCm65wm-f4uX16X5-aQAAAH0"]
[Thu Sep 17 15:26:34.737437 2026] [access_compat:error] [pid 1029697:tid 1029870] [client 40.81.232.68:62141] AH01797: client denied by server configuration: /home3/houselif/public_html/wp-content/uploads/ithemes-security/, referer: binance.com
[Thu Sep 17 15:26:34.961075 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxbCm65wm-f4uX16X5-bgAAAHs"]
[Thu Sep 17 15:26:35.192093 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxbC265wm-f4uX16X5-kAAAADc"]
[Thu Sep 17 15:26:35.261435 2026] [security2:error] [pid 1029697:tid 1029884] [client 45.156.128.179:55250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbC265wm-f4uX16X5-jgAAADk"]
[Thu Sep 17 15:26:35.433513 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxbC265wm-f4uX16X5-mwAAACM"]
[Thu Sep 17 15:26:35.664222 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxbC265wm-f4uX16X5-rAAAAHY"]
[Thu Sep 17 15:26:35.677915 2026] [security2:error] [pid 1029697:tid 1029831] [client 45.156.128.178:18880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbC265wm-f4uX16X5-pQAAAAQ"]
[Thu Sep 17 15:26:35.776199 2026] [security2:error] [pid 1029697:tid 1029894] [client 76.232.78.96:51893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbC265wm-f4uX16X5-rQAAQ0s"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:26:35.897189 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxbC265wm-f4uX16X5-twAAAHM"]
[Thu Sep 17 15:26:35.989058 2026] [security2:error] [pid 1029697:tid 1029925] [client 169.58.197.253:58263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxbC265wm-f4uX16X5-vQAAAGI"], referer: binance.com
[Thu Sep 17 15:26:36.062001 2026] [security2:error] [pid 1029697:tid 1029865] [client 162.241.226.11:41314] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxbDG65wm-f4uX16X5-wQAAACY"]
[Thu Sep 17 15:26:36.127088 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxbDG65wm-f4uX16X5-xAAAAFk"]
[Thu Sep 17 15:26:36.363122 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxbDG65wm-f4uX16X5-zgAAABY"]
[Thu Sep 17 15:26:36.584468 2026] [security2:error] [pid 1029697:tid 1029855] [client 154.190.208.131:41962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbDG65wm-f4uX16X5-3gAAABw"]
[Thu Sep 17 15:26:36.592276 2026] [security2:error] [pid 1029697:tid 1029855] [client 154.190.208.131:41962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbDG65wm-f4uX16X5-3gAAABw"]
[Thu Sep 17 15:26:36.597492 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxbDG65wm-f4uX16X5-4AAAADo"]
[Thu Sep 17 15:26:36.829189 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxbDG65wm-f4uX16X5-7AAAAC4"]
[Thu Sep 17 15:26:36.950868 2026] [security2:error] [pid 1029697:tid 1029935] [client 202.46.62.75:36669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxbDG65wm-f4uX16X5-7QAAbCk"]
[Thu Sep 17 15:26:37.059791 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxbDW65wm-f4uX16X5-9wAAAHI"]
[Thu Sep 17 15:26:37.289570 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxbDW65wm-f4uX16X5_AQAAABE"]
[Thu Sep 17 15:26:37.404500 2026] [security2:error] [pid 1029697:tid 1029875] [client 45.55.194.205:54408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seekingtheway.net"] [uri "/index.php"] [unique_id "aqxbC265wm-f4uX16X5-tAAAMEM"], referer: http://seekingtheway.net./wordpress/
[Thu Sep 17 15:26:37.520555 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxbDW65wm-f4uX16X5_DgAAACU"]
[Thu Sep 17 15:26:37.652787 2026] [security2:error] [pid 1029697:tid 1029925] [client 45.55.194.205:54408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seekingtheway.net"] [uri "/index.php"] [unique_id "aqxbDW65wm-f4uX16X5_DwAAYho"], referer: http://seekingtheway.net./old/
[Thu Sep 17 15:26:37.750975 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxbDW65wm-f4uX16X5_FgAAADw"]
[Thu Sep 17 15:26:37.901072 2026] [security2:error] [pid 1029697:tid 1029916] [client 45.55.194.205:54408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seekingtheway.net"] [uri "/index.php"] [unique_id "aqxbDW65wm-f4uX16X5_GQAAWUk"], referer: http://seekingtheway.net./new/
[Thu Sep 17 15:26:37.907773 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.94.254.227:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxbDW65wm-f4uX16X5_HAAAAGM"]
[Thu Sep 17 15:26:37.986095 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxbDW65wm-f4uX16X5_IQAAAAA"]
[Thu Sep 17 15:26:38.139102 2026] [security2:error] [pid 1029697:tid 1029944] [client 45.156.128.179:55256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbDm65wm-f4uX16X5_KAAAAHU"]
[Thu Sep 17 15:26:38.216405 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxbDm65wm-f4uX16X5_LQAAADg"]
[Thu Sep 17 15:26:38.274105 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.94.254.227:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/info.php"] [unique_id "aqxbDm65wm-f4uX16X5_MAAAADo"]
[Thu Sep 17 15:26:38.446409 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxbDm65wm-f4uX16X5_MwAAAFg"]
[Thu Sep 17 15:26:38.495000 2026] [security2:error] [pid 1029697:tid 1029829] [client 104.207.33.33:21489] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxbDm65wm-f4uX16X5_NQAAAAI"]
[Thu Sep 17 15:26:38.571130 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.94.254.227:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/php.php"] [unique_id "aqxbDm65wm-f4uX16X5_OgAAAGU"]
[Thu Sep 17 15:26:38.676423 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxbDm65wm-f4uX16X5_PgAAACI"]
[Thu Sep 17 15:26:38.749900 2026] [security2:error] [pid 1029697:tid 1029924] [client 45.55.194.205:54408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seekingtheway.net"] [uri "/index.php"] [unique_id "aqxbDm65wm-f4uX16X5_PAAAYTQ"], referer: http://seekingtheway.net./backup/
[Thu Sep 17 15:26:38.829857 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.94.254.227:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/i.php"] [unique_id "aqxbDm65wm-f4uX16X5_RAAAAH8"]
[Thu Sep 17 15:26:38.906578 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxbDm65wm-f4uX16X5_SAAAAHI"]
[Thu Sep 17 15:26:38.986549 2026] [security2:error] [pid 1029697:tid 1029896] [client 114.198.138.124:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbDm65wm-f4uX16X5_SwAAAEU"]
[Thu Sep 17 15:26:38.986638 2026] [security2:error] [pid 1029697:tid 1029896] [client 114.198.138.124:50226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbDm65wm-f4uX16X5_SwAAAEU"]
[Thu Sep 17 15:26:39.049979 2026] [security2:error] [pid 1029697:tid 1029880] [client 4.240.114.86:55096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxbD265wm-f4uX16X5_UQAAADU"], referer: binance.com
[Thu Sep 17 15:26:39.068363 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.94.254.227:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxbD265wm-f4uX16X5_UgAAAG8"]
[Thu Sep 17 15:26:39.136258 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxbD265wm-f4uX16X5_VQAAAFM"]
[Thu Sep 17 15:26:39.193406 2026] [security2:error] [pid 1029697:tid 1029867] [client 45.55.194.205:54408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seekingtheway.net"] [uri "/index.php"] [unique_id "aqxbD265wm-f4uX16X5_UwAAKEE"], referer: http://seekingtheway.net./wp/
[Thu Sep 17 15:26:39.258420 2026] [security2:error] [pid 1029697:tid 1029905] [client 156.192.234.52:51893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbD265wm-f4uX16X5_WwAAAE4"]
[Thu Sep 17 15:26:39.259578 2026] [security2:error] [pid 1029697:tid 1029905] [client 156.192.234.52:51893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbD265wm-f4uX16X5_WwAAAE4"]
[Thu Sep 17 15:26:39.312620 2026] [security2:error] [pid 1029697:tid 1029875] [client 76.232.78.96:51899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbD265wm-f4uX16X5_WQAAMD8"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260621112958&hideanons=1&hidebots=0&limit=100&target=Oz&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:26:39.366579 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxbD265wm-f4uX16X5_XwAAAGk"]
[Thu Sep 17 15:26:39.381543 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.94.254.227:53252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxbD265wm-f4uX16X5_YwAAACU"]
[Thu Sep 17 15:26:39.580760 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.94.254.227:53260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/test.php"] [unique_id "aqxbD265wm-f4uX16X5_aQAAAFc"]
[Thu Sep 17 15:26:39.602195 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxbD265wm-f4uX16X5_awAAAH4"]
[Thu Sep 17 15:26:39.832873 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxbD265wm-f4uX16X5_dAAAAHQ"]
[Thu Sep 17 15:26:39.972096 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.94.254.227:53266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/p.php"] [unique_id "aqxbD265wm-f4uX16X5_ewAAAHA"]
[Thu Sep 17 15:26:40.081605 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxbEG65wm-f4uX16X5_gQAAAGw"]
[Thu Sep 17 15:26:40.217791 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.94.254.227:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxbEG65wm-f4uX16X5_hAAAADY"]
[Thu Sep 17 15:26:40.318061 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxbEG65wm-f4uX16X5_hwAAAD0"]
[Thu Sep 17 15:26:40.569439 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxbEG65wm-f4uX16X5_jwAAAFU"]
[Thu Sep 17 15:26:40.693640 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.94.254.227:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxbEG65wm-f4uX16X5_kgAAAE4"]
[Thu Sep 17 15:26:40.808075 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxbEG65wm-f4uX16X5_lgAAACw"]
[Thu Sep 17 15:26:40.878063 2026] [security2:error] [pid 1029697:tid 1029948] [client 2.104.60.34:53181] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "counselingforchange.net"] [uri "/.env"] [unique_id "aqxbEG65wm-f4uX16X5_mAAAAHk"]
[Thu Sep 17 15:26:40.952945 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.94.254.227:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxbEG65wm-f4uX16X5_nQAAAHE"]
[Thu Sep 17 15:26:41.041149 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxbEW65wm-f4uX16X5_oQAAABU"]
[Thu Sep 17 15:26:41.144078 2026] [security2:error] [pid 1029697:tid 1029878] [client 45.156.128.178:58832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbEW65wm-f4uX16X5_ogAAADM"]
[Thu Sep 17 15:26:41.256026 2026] [security2:error] [pid 1029697:tid 1029950] [client 103.61.184.148:63622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbEW65wm-f4uX16X5_qgAAAHs"]
[Thu Sep 17 15:26:41.256123 2026] [security2:error] [pid 1029697:tid 1029950] [client 103.61.184.148:63622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbEW65wm-f4uX16X5_qgAAAHs"]
[Thu Sep 17 15:26:41.278532 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.94.254.227:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxbEW65wm-f4uX16X5_rAAAAC8"]
[Thu Sep 17 15:26:41.281628 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxbEW65wm-f4uX16X5_rQAAAHQ"]
[Thu Sep 17 15:26:41.442567 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.94.254.227:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxbEW65wm-f4uX16X5_rgAAAGA"]
[Thu Sep 17 15:26:41.502617 2026] [security2:error] [pid 1029697:tid 1029883] [client 185.55.149.49:58503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbEW65wm-f4uX16X5_sgAAADg"]
[Thu Sep 17 15:26:41.502723 2026] [security2:error] [pid 1029697:tid 1029883] [client 185.55.149.49:58503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbEW65wm-f4uX16X5_sgAAADg"]
[Thu Sep 17 15:26:41.517834 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxbEW65wm-f4uX16X5_swAAAH0"]
[Thu Sep 17 15:26:41.692852 2026] [security2:error] [pid 1029697:tid 1029917] [client 34.94.254.227:53312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbEW65wm-f4uX16X5_ugAAAFo"]
[Thu Sep 17 15:26:41.755190 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxbEW65wm-f4uX16X5_vQAAAGE"]
[Thu Sep 17 15:26:41.991075 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxbEW65wm-f4uX16X5_wwAAACA"]
[Thu Sep 17 15:26:42.001273 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.94.254.227:53324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxbEm65wm-f4uX16X5_xgAAAAM"]
[Thu Sep 17 15:26:42.253536 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxbEm65wm-f4uX16X5_ywAAADQ"]
[Thu Sep 17 15:26:42.278036 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.94.254.227:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxbEm65wm-f4uX16X5_zQAAAD0"]
[Thu Sep 17 15:26:42.290346 2026] [security2:error] [pid 1029697:tid 1029898] [client 62.60.248.10:63653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.248.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandernovelist.com"] [uri "/wp-login.php"] [unique_id "aqxbEm65wm-f4uX16X5_zAAAAEc"], referer: https://alexandernovelist.com/wp-login.php?action=register
[Thu Sep 17 15:26:42.362423 2026] [security2:error] [pid 1029697:tid 1029757] [remote 47.128.99.233:16894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gazillionmexico.com"] [uri "/"] [unique_id "aqxbEm65wm-f4uX16X5_zwAAXjs"]
[Thu Sep 17 15:26:42.371834 2026] [security2:error] [pid 1029697:tid 1029913] [client 4.240.114.86:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxbEm65wm-f4uX16X5_0AAAAFY"], referer: binance.com
[Thu Sep 17 15:26:42.488678 2026] [security2:error] [pid 1029697:tid 1029900] [client 45.156.128.178:58840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbEm65wm-f4uX16X5_0QAAAEk"]
[Thu Sep 17 15:26:42.490971 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxbEm65wm-f4uX16X5_1AAAAHY"]
[Thu Sep 17 15:26:42.601259 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.94.254.227:53332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxbEm65wm-f4uX16X5_2gAAAEM"]
[Thu Sep 17 15:26:42.728147 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxbEm65wm-f4uX16X5_3gAAAHc"]
[Thu Sep 17 15:26:42.858938 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.94.254.227:53334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxbEm65wm-f4uX16X5_4QAAAAU"]
[Thu Sep 17 15:26:42.881299 2026] [security2:error] [pid 1029697:tid 1029919] [client 169.58.197.253:58740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxbEm65wm-f4uX16X5_4gAAAFw"], referer: binance.com
[Thu Sep 17 15:26:42.964163 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.18.173.5:59320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hym.qby.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxbEm65wm-f4uX16X5_6AAAAHE"]
[Thu Sep 17 15:26:42.965311 2026] [security2:error] [pid 1029697:tid 1029846] [client 62.60.248.10:63774] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "62.60.248.10" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "alexandernovelist.com"] [uri "/wp-login.php"] [unique_id "aqxbEm65wm-f4uX16X5_6QAAABM"], referer: https://alexandernovelist.com/wp-login.php?action=register
[Thu Sep 17 15:26:43.221779 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.94.254.227:53346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxbE265wm-f4uX16X5_-QAAAAs"]
[Thu Sep 17 15:26:43.246143 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.18.173.5:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxbE265wm-f4uX16X5_9wAAAAA"]
[Thu Sep 17 15:26:43.456130 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.94.254.227:53356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxbE265wm-f4uX16X6AAAAAABc"]
[Thu Sep 17 15:26:43.657372 2026] [security2:error] [pid 1029697:tid 1029930] [client 62.60.248.10:63870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.248.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandernovelist.com"] [uri "/wp-login.php"] [unique_id "aqxbE265wm-f4uX16X6AKwAAAGc"], referer: https://alexandernovelist.com/wp-login.php?action=register
[Thu Sep 17 15:26:43.773087 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.94.254.227:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxbE265wm-f4uX16X6ANgAAAB4"]
[Thu Sep 17 15:26:43.960226 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.18.173.5:47446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/info.php"] [unique_id "aqxbE265wm-f4uX16X6APQAAAEA"]
[Thu Sep 17 15:26:44.142518 2026] [core:error] [pid 1029697:tid 1029864] [client 34.180.119.195:37246] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:44.214429 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.94.254.227:50230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbFG65wm-f4uX16X6AUgAAAHE"]
[Thu Sep 17 15:26:44.323559 2026] [security2:error] [pid 1029697:tid 1029882] [client 62.60.248.10:63956] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "62.60.248.10" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "alexandernovelist.com"] [uri "/wp-login.php"] [unique_id "aqxbFG65wm-f4uX16X6AWAAAADc"], referer: https://alexandernovelist.com/wp-login.php?action=register
[Thu Sep 17 15:26:44.419895 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.94.254.227:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxbFG65wm-f4uX16X6AWwAAAHQ"]
[Thu Sep 17 15:26:44.554156 2026] [core:error] [pid 1029697:tid 1029865] [client 34.180.119.195:37252] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:44.651923 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.18.173.5:47450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/php.php"] [unique_id "aqxbFG65wm-f4uX16X6AYwAAABk"]
[Thu Sep 17 15:26:44.871826 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.94.254.227:50246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbFG65wm-f4uX16X6AaAAAAFg"]
[Thu Sep 17 15:26:44.880391 2026] [security2:error] [pid 1029697:tid 1029939] [client 45.156.128.178:58842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbFG65wm-f4uX16X6AZwAAAHA"]
[Thu Sep 17 15:26:44.972187 2026] [core:error] [pid 1029697:tid 1029877] [client 34.180.119.195:37258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:45.108434 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.94.254.227:50250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbFW65wm-f4uX16X6AbQAAAGA"]
[Thu Sep 17 15:26:45.298816 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.94.254.227:50266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbFW65wm-f4uX16X6AdAAAAAI"]
[Thu Sep 17 15:26:45.344724 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.18.173.5:47464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/i.php"] [unique_id "aqxbFW65wm-f4uX16X6AdwAAAB8"]
[Thu Sep 17 15:26:45.371770 2026] [core:error] [pid 1029697:tid 1029889] [client 34.180.119.195:37260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:45.371790 2026] [core:error] [pid 1029697:tid 1029889] [client 34.180.119.195:37260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:45.434677 2026] [security2:error] [pid 1029697:tid 1029830] [client 186.22.18.39:6424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbFW65wm-f4uX16X6AdgAAAxc"]
[Thu Sep 17 15:26:45.530513 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.254.227:50278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbFW65wm-f4uX16X6AfwAAADU"]
[Thu Sep 17 15:26:45.818371 2026] [core:error] [pid 1029697:tid 1029908] [client 34.180.119.195:37266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:45.838169 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.94.254.227:50282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxbFW65wm-f4uX16X6AiwAAAA0"]
[Thu Sep 17 15:26:46.054709 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.18.173.5:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxbFm65wm-f4uX16X6AkwAAAFY"]
[Thu Sep 17 15:26:46.135042 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.94.254.227:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxbFm65wm-f4uX16X6AlwAAACk"]
[Thu Sep 17 15:26:46.189169 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.180.119.195:54828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/.env"] [unique_id "aqxbFm65wm-f4uX16X6AmwAAAE4"]
[Thu Sep 17 15:26:46.243958 2026] [security2:error] [pid 1029697:tid 1029847] [client 4.240.114.86:57735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxbFm65wm-f4uX16X6AnQAAABQ"], referer: binance.com
[Thu Sep 17 15:26:46.314717 2026] [core:error] [pid 1029697:tid 1029882] [client 34.180.119.195:54828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:46.314734 2026] [core:error] [pid 1029697:tid 1029882] [client 34.180.119.195:54828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:46.444847 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.254.227:50306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxbFm65wm-f4uX16X6AogAAADM"]
[Thu Sep 17 15:26:46.664596 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.94.254.227:50318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxbFm65wm-f4uX16X6AqwAAAHU"]
[Thu Sep 17 15:26:46.686434 2026] [core:error] [pid 1029697:tid 1029845] [client 34.180.119.195:54832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:46.686452 2026] [core:error] [pid 1029697:tid 1029845] [client 34.180.119.195:54832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:46.765193 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.18.173.5:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxbFm65wm-f4uX16X6ArQAAAAw"]
[Thu Sep 17 15:26:46.888014 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.94.254.227:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxbFm65wm-f4uX16X6AsAAAADg"]
[Thu Sep 17 15:26:47.057370 2026] [core:error] [pid 1029697:tid 1029850] [client 34.180.119.195:54848] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:47.057390 2026] [core:error] [pid 1029697:tid 1029850] [client 34.180.119.195:54848] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:47.131325 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.254.227:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxbF265wm-f4uX16X6AtgAAAFI"]
[Thu Sep 17 15:26:47.198374 2026] [security2:error] [pid 1029697:tid 1029887] [client 154.190.208.131:42565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbF265wm-f4uX16X6AugAAADw"]
[Thu Sep 17 15:26:47.198479 2026] [security2:error] [pid 1029697:tid 1029887] [client 154.190.208.131:42565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbF265wm-f4uX16X6AugAAADw"]
[Thu Sep 17 15:26:47.445691 2026] [core:error] [pid 1029697:tid 1029954] [client 34.180.119.195:54850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:47.445710 2026] [core:error] [pid 1029697:tid 1029954] [client 34.180.119.195:54850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:47.454462 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.94.254.227:50340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxbF265wm-f4uX16X6AwgAAACA"]
[Thu Sep 17 15:26:47.468864 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.18.173.5:47498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/test.php"] [unique_id "aqxbF265wm-f4uX16X6AwwAAAGc"]
[Thu Sep 17 15:26:47.473467 2026] [security2:error] [pid 1029697:tid 1029863] [client 38.41.50.84:43958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbF265wm-f4uX16X6AvgAAJDA"]
[Thu Sep 17 15:26:47.508231 2026] [security2:error] [pid 1029697:tid 1029858] [client 45.156.128.177:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbF265wm-f4uX16X6AvwAAAB8"]
[Thu Sep 17 15:26:47.655005 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.254.227:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxbF265wm-f4uX16X6AygAAADU"]
[Thu Sep 17 15:26:47.803571 2026] [core:error] [pid 1029697:tid 1029835] [client 34.180.119.195:54860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:47.803587 2026] [core:error] [pid 1029697:tid 1029835] [client 34.180.119.195:54860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:47.820843 2026] [security2:error] [pid 1029697:tid 1029921] [client 127.0.0.1:32312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxbF265wm-f4uX16X6AzgAAAF4"]
[Thu Sep 17 15:26:47.820875 2026] [security2:error] [pid 1029697:tid 1029843] [client 127.0.0.1:32304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.luxelivinglv.com"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxbF265wm-f4uX16X6AzQAAABA"]
[Thu Sep 17 15:26:47.821034 2026] [security2:error] [pid 1029697:tid 1029910] [client 74.7.230.14:57522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.luxelivinglv.com"] [uri "/robots.txt"] [unique_id "aqxbF265wm-f4uX16X6AzAAAUzM"]
[Thu Sep 17 15:26:47.883267 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.254.227:50362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxbF265wm-f4uX16X6A2AAAAGk"]
[Thu Sep 17 15:26:47.936964 2026] [log_config:warn] [pid 1012520:tid 1012680] (32)Broken pipe: [client 209.59.76.58:40062] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log
[Thu Sep 17 15:26:47.936980 2026] [log_config:warn] [pid 1012520:tid 1012680] (32)Broken pipe: [client 209.59.76.58:40062] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log
[Thu Sep 17 15:26:47.989496 2026] [security2:error] [pid 1029697:tid 1029873] [client 104.207.33.33:43171] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxbF265wm-f4uX16X6A3wAAAC4"]
[Thu Sep 17 15:26:48.095116 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.94.254.227:50366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxbGG65wm-f4uX16X6A6QAAAAo"]
[Thu Sep 17 15:26:48.164712 2026] [core:error] [pid 1029697:tid 1029948] [client 34.180.119.195:54870] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:48.164733 2026] [core:error] [pid 1029697:tid 1029948] [client 34.180.119.195:54870] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:48.169351 2026] [security2:error] [pid 1029697:tid 1029903] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxbF265wm-f4uX16X6A1gAAAEw"]
[Thu Sep 17 15:26:48.188549 2026] [security2:error] [pid 1029697:tid 1029913] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxbF265wm-f4uX16X6A1wAAAFY"]
[Thu Sep 17 15:26:48.283646 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.94.254.227:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxbGG65wm-f4uX16X6A-wAAAC0"]
[Thu Sep 17 15:26:48.291934 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.94.39.26:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/phpinfo.php"] [unique_id "aqxbGG65wm-f4uX16X6A-gAAAHo"]
[Thu Sep 17 15:26:48.369032 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxbGG65wm-f4uX16X6A-AAAAGo"]
[Thu Sep 17 15:26:48.521335 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.180.119.195:54880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/.env.bak"] [unique_id "aqxbGG65wm-f4uX16X6BAAAAAH4"]
[Thu Sep 17 15:26:48.539545 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.94.254.227:50390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbGG65wm-f4uX16X6BAQAAAAM"]
[Thu Sep 17 15:26:48.608680 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.18.173.5:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/p.php"] [unique_id "aqxbGG65wm-f4uX16X6BAwAAADU"]
[Thu Sep 17 15:26:48.650250 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.180.119.195:54880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/.env.backup"] [unique_id "aqxbGG65wm-f4uX16X6BBwAAABw"]
[Thu Sep 17 15:26:48.716153 2026] [fcgid:warn] [pid 1029697:tid 1029927] (70014)End of file found: [client 66.132.172.196:60786] mod_fcgid: can't get data from http client
[Thu Sep 17 15:26:48.721007 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.94.39.26:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/info.php"] [unique_id "aqxbGG65wm-f4uX16X6BCQAAACc"]
[Thu Sep 17 15:26:48.774234 2026] [core:error] [pid 1029697:tid 1029853] [client 34.180.119.195:54880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:48.774249 2026] [core:error] [pid 1029697:tid 1029853] [client 34.180.119.195:54880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:48.851261 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.94.254.227:50406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbGG65wm-f4uX16X6BDgAAAF4"]
[Thu Sep 17 15:26:48.888760 2026] [security2:error] [pid 1029697:tid 1029910] [client 104.243.33.53:58452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "threadalittlelight.com"] [uri "/.env"] [unique_id "aqxbGG65wm-f4uX16X6BDwAAAFM"]
[Thu Sep 17 15:26:49.091140 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.94.254.227:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxbGW65wm-f4uX16X6BFQAAAE4"]
[Thu Sep 17 15:26:49.127581 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.180.119.195:54884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/.env.old"] [unique_id "aqxbGW65wm-f4uX16X6BGAAAADA"]
[Thu Sep 17 15:26:49.256793 2026] [core:error] [pid 1029697:tid 1029836] [client 34.180.119.195:54884] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:49.256811 2026] [core:error] [pid 1029697:tid 1029836] [client 34.180.119.195:54884] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:49.306884 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.94.39.26:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/php.php"] [unique_id "aqxbGW65wm-f4uX16X6BIQAAACs"]
[Thu Sep 17 15:26:49.308508 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.18.173.5:47508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxbGW65wm-f4uX16X6BIgAAAEo"]
[Thu Sep 17 15:26:49.407511 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.94.254.227:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxbGW65wm-f4uX16X6BJQAAABs"]
[Thu Sep 17 15:26:49.463342 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.94.39.26:57476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/i.php"] [unique_id "aqxbGW65wm-f4uX16X6BKQAAABY"]
[Thu Sep 17 15:26:49.592316 2026] [security2:error] [pid 1029697:tid 1029865] [client 114.198.138.124:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbGW65wm-f4uX16X6BNQAAACY"]
[Thu Sep 17 15:26:49.592407 2026] [security2:error] [pid 1029697:tid 1029865] [client 114.198.138.124:50869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbGW65wm-f4uX16X6BNQAAACY"]
[Thu Sep 17 15:26:49.604686 2026] [core:error] [pid 1029697:tid 1029943] [client 34.180.119.195:54900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:49.604699 2026] [core:error] [pid 1029697:tid 1029943] [client 34.180.119.195:54900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:49.659763 2026] [security2:error] [pid 1029697:tid 1029928] [client 169.58.197.253:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/connectors.php"] [unique_id "aqxbGW65wm-f4uX16X6BQQAAAGU"], referer: binance.com
[Thu Sep 17 15:26:49.706298 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.254.227:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbGW65wm-f4uX16X6BQgAAAHc"]
[Thu Sep 17 15:26:49.725815 2026] [security2:error] [pid 1029697:tid 1029828] [client 45.156.128.177:23960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbGW65wm-f4uX16X6BPQAAAAE"]
[Thu Sep 17 15:26:49.730556 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.94.39.26:57486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/pi.php"] [unique_id "aqxbGW65wm-f4uX16X6BRAAAAGI"]
[Thu Sep 17 15:26:49.800291 2026] [security2:error] [pid 1029697:tid 1029898] [client 156.192.234.52:52509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbGW65wm-f4uX16X6BRQAAAEc"]
[Thu Sep 17 15:26:49.801090 2026] [security2:error] [pid 1029697:tid 1029898] [client 156.192.234.52:52509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbGW65wm-f4uX16X6BRQAAAEc"]
[Thu Sep 17 15:26:49.864276 2026] [fcgid:warn] [pid 1029697:tid 1029926] (70014)End of file found: [client 152.32.202.250:36566] mod_fcgid: can't get data from http client
[Thu Sep 17 15:26:49.976268 2026] [core:error] [pid 1029697:tid 1029947] [client 34.180.119.195:54910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:49.976287 2026] [core:error] [pid 1029697:tid 1029947] [client 34.180.119.195:54910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:50.009084 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.94.39.26:57502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/pinfo.php"] [unique_id "aqxbGm65wm-f4uX16X6BSQAAADE"]
[Thu Sep 17 15:26:50.012608 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.18.173.5:47520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxbGm65wm-f4uX16X6BSgAAAD4"]
[Thu Sep 17 15:26:50.073920 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.254.227:50432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbGm65wm-f4uX16X6BSwAAAGc"]
[Thu Sep 17 15:26:50.244882 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.94.39.26:57514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/test.php"] [unique_id "aqxbGm65wm-f4uX16X6BUAAAAGQ"]
[Thu Sep 17 15:26:50.314913 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.94.254.227:50438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxbGm65wm-f4uX16X6BUgAAABA"]
[Thu Sep 17 15:26:50.330022 2026] [core:error] [pid 1029697:tid 1029866] [client 34.180.119.195:54922] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:50.330038 2026] [core:error] [pid 1029697:tid 1029866] [client 34.180.119.195:54922] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:50.512608 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.254.227:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.254.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dxu.dyx.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxbGm65wm-f4uX16X6BVgAAAGk"]
[Thu Sep 17 15:26:50.597556 2026] [security2:error] [pid 1029697:tid 1029851] [client 4.240.114.86:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxbGm65wm-f4uX16X6BVwAAABg"], referer: binance.com
[Thu Sep 17 15:26:50.684327 2026] [core:error] [pid 1029697:tid 1029831] [client 34.180.119.195:54924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:50.684343 2026] [core:error] [pid 1029697:tid 1029831] [client 34.180.119.195:54924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:50.717265 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.18.173.5:47534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxbGm65wm-f4uX16X6BXgAAAA0"]
[Thu Sep 17 15:26:50.746688 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.94.39.26:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/p.php"] [unique_id "aqxbGm65wm-f4uX16X6BXwAAABM"]
[Thu Sep 17 15:26:50.923954 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.94.39.26:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/debug.php"] [unique_id "aqxbGm65wm-f4uX16X6BZQAAAFA"]
[Thu Sep 17 15:26:51.047873 2026] [core:error] [pid 1029697:tid 1029874] [client 34.180.119.195:54932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:51.047895 2026] [core:error] [pid 1029697:tid 1029874] [client 34.180.119.195:54932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:51.305630 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.94.39.26:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbG265wm-f4uX16X6BdQAAAGY"]
[Thu Sep 17 15:26:51.408061 2026] [core:error] [pid 1029697:tid 1029883] [client 34.180.119.195:54940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:51.408076 2026] [core:error] [pid 1029697:tid 1029883] [client 34.180.119.195:54940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:51.418100 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.18.173.5:46306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxbG265wm-f4uX16X6BeAAAACY"]
[Thu Sep 17 15:26:51.749604 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.94.39.26:40922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbG265wm-f4uX16X6BggAAACQ"]
[Thu Sep 17 15:26:51.786168 2026] [core:error] [pid 1029697:tid 1029898] [client 34.180.119.195:54942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:51.786188 2026] [core:error] [pid 1029697:tid 1029898] [client 34.180.119.195:54942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:51.909541 2026] [security2:error] [pid 1029697:tid 1029946] [client 103.61.184.148:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbG265wm-f4uX16X6BhgAAAHc"]
[Thu Sep 17 15:26:51.909626 2026] [security2:error] [pid 1029697:tid 1029946] [client 103.61.184.148:64176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbG265wm-f4uX16X6BhgAAAHc"]
[Thu Sep 17 15:26:51.916372 2026] [security2:error] [pid 1029697:tid 1029916] [client 74.7.228.57:54166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.centerforfederaljusticereform.org"] [uri "/robots.txt"] [unique_id "aqxbG265wm-f4uX16X6BiAAAAFk"]
[Thu Sep 17 15:26:52.120457 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.18.173.5:46314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxbHG65wm-f4uX16X6BiwAAADU"]
[Thu Sep 17 15:26:52.141233 2026] [core:error] [pid 1029697:tid 1029866] [client 34.180.119.195:54952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:52.141253 2026] [core:error] [pid 1029697:tid 1029866] [client 34.180.119.195:54952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:52.227359 2026] [security2:error] [pid 1029697:tid 1029912] [client 185.55.149.49:55866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbHG65wm-f4uX16X6BkAAAAFU"]
[Thu Sep 17 15:26:52.227464 2026] [security2:error] [pid 1029697:tid 1029912] [client 185.55.149.49:55866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbHG65wm-f4uX16X6BkAAAAFU"]
[Thu Sep 17 15:26:52.417791 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.94.39.26:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbHG65wm-f4uX16X6BkgAAAFc"]
[Thu Sep 17 15:26:52.500372 2026] [core:error] [pid 1029697:tid 1029940] [client 34.180.119.195:54960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:52.500387 2026] [core:error] [pid 1029697:tid 1029940] [client 34.180.119.195:54960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:52.836766 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.18.173.5:46324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbHG65wm-f4uX16X6BmgAAABM"]
[Thu Sep 17 15:26:52.875655 2026] [core:error] [pid 1029697:tid 1029848] [client 34.180.119.195:54964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:52.875687 2026] [core:error] [pid 1029697:tid 1029848] [client 34.180.119.195:54964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:52.901771 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.94.39.26:40938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbHG65wm-f4uX16X6BnAAAAHs"]
[Thu Sep 17 15:26:52.984382 2026] [security2:error] [pid 1029697:tid 1029856] [client 45.156.128.176:26908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbHG65wm-f4uX16X6BnQAAAB0"]
[Thu Sep 17 15:26:53.146560 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.94.39.26:40950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbHW65wm-f4uX16X6BpgAAAHA"]
[Thu Sep 17 15:26:53.257809 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.180.119.195:54974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/.env.swp"] [unique_id "aqxbHW65wm-f4uX16X6BqwAAACo"]
[Thu Sep 17 15:26:53.270715 2026] [security2:error] [pid 1029697:tid 1029900] [client 18.193.252.127:23914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxbHW65wm-f4uX16X6BrAAAAEk"], referer: https://faewave.com
[Thu Sep 17 15:26:53.377111 2026] [security2:error] [pid 1029697:tid 1029917] [client 34.94.39.26:40960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbHW65wm-f4uX16X6BrgAAAFo"]
[Thu Sep 17 15:26:53.396447 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.180.119.195:54974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/.env~"] [unique_id "aqxbHW65wm-f4uX16X6BrwAAAFI"]
[Thu Sep 17 15:26:53.528896 2026] [core:error] [pid 1029697:tid 1029883] [client 34.180.119.195:54974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:53.528926 2026] [core:error] [pid 1029697:tid 1029883] [client 34.180.119.195:54974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:53.539810 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.18.173.5:46326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxbHW65wm-f4uX16X6BswAAAF8"]
[Thu Sep 17 15:26:53.897231 2026] [core:error] [pid 1029697:tid 1029896] [client 34.180.119.195:54976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:53.897250 2026] [core:error] [pid 1029697:tid 1029896] [client 34.180.119.195:54976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:53.933869 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.94.39.26:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/php-info.php"] [unique_id "aqxbHW65wm-f4uX16X6BwAAAAEc"]
[Thu Sep 17 15:26:54.058535 2026] [security2:error] [pid 1029697:tid 1029930] [client 4.240.114.86:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxbHm65wm-f4uX16X6BwgAAAGc"], referer: binance.com
[Thu Sep 17 15:26:54.258802 2026] [core:error] [pid 1029697:tid 1029916] [client 34.180.119.195:54988] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:54.258827 2026] [core:error] [pid 1029697:tid 1029916] [client 34.180.119.195:54988] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:54.292756 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.94.39.26:40978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/phpversion.php"] [unique_id "aqxbHm65wm-f4uX16X6B0AAAACM"]
[Thu Sep 17 15:26:54.380726 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxbHm65wm-f4uX16X6BzwAAAEY"]
[Thu Sep 17 15:26:54.622314 2026] [core:error] [pid 1029697:tid 1029940] [client 34.180.119.195:54992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:54.622337 2026] [core:error] [pid 1029697:tid 1029940] [client 34.180.119.195:54992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:54.625496 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.18.173.5:46338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxbHm65wm-f4uX16X6B2QAAAHM"]
[Thu Sep 17 15:26:54.883276 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.94.39.26:40990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/_phpinfo.php"] [unique_id "aqxbHm65wm-f4uX16X6B4AAAAFA"]
[Thu Sep 17 15:26:55.003093 2026] [core:error] [pid 1029697:tid 1029838] [client 34.180.119.195:54998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:55.003110 2026] [core:error] [pid 1029697:tid 1029838] [client 34.180.119.195:54998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:55.306197 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.39.26:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbH265wm-f4uX16X6B5wAAAFI"]
[Thu Sep 17 15:26:55.331955 2026] [security2:error] [pid 1029697:tid 1029917] [client 34.18.173.5:46354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxbH265wm-f4uX16X6B6AAAAFo"]
[Thu Sep 17 15:26:55.364491 2026] [core:error] [pid 1029697:tid 1029931] [client 34.180.119.195:55008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:55.364506 2026] [core:error] [pid 1029697:tid 1029931] [client 34.180.119.195:55008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:55.543879 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.94.39.26:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/server-info.php"] [unique_id "aqxbH265wm-f4uX16X6B7AAAACY"]
[Thu Sep 17 15:26:55.741689 2026] [core:error] [pid 1029697:tid 1029874] [client 34.180.119.195:55014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:55.741708 2026] [core:error] [pid 1029697:tid 1029874] [client 34.180.119.195:55014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:55.924968 2026] [security2:error] [pid 1029697:tid 1029829] [client 104.207.33.33:29273] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxbH265wm-f4uX16X6B-AAAAAI"]
[Thu Sep 17 15:26:56.030978 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.18.173.5:46368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxbIG65wm-f4uX16X6CAAAAAAA"]
[Thu Sep 17 15:26:56.089794 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.94.39.26:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/server-status.php"] [unique_id "aqxbIG65wm-f4uX16X6CAwAAADw"]
[Thu Sep 17 15:26:56.097505 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.180.119.195:39228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/app/.env"] [unique_id "aqxbIG65wm-f4uX16X6CBAAAAAM"]
[Thu Sep 17 15:26:56.214021 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.180.119.195:39228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/apps/.env"] [unique_id "aqxbIG65wm-f4uX16X6CCgAAAD0"]
[Thu Sep 17 15:26:56.348817 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.180.119.195:39228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/api/.env"] [unique_id "aqxbIG65wm-f4uX16X6CEAAAADA"]
[Thu Sep 17 15:26:56.463554 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.180.119.195:39228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/web/.env"] [unique_id "aqxbIG65wm-f4uX16X6CFQAAABU"]
[Thu Sep 17 15:26:56.480440 2026] [security2:error] [pid 1029697:tid 1029940] [client 45.156.128.179:26364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbIG65wm-f4uX16X6CEQAAAHE"]
[Thu Sep 17 15:26:56.509769 2026] [security2:error] [pid 1029697:tid 1029943] [client 178.81.193.220:62791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbIG65wm-f4uX16X6CEgAAdD0"]
[Thu Sep 17 15:26:56.582641 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.180.119.195:39228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/site/.env"] [unique_id "aqxbIG65wm-f4uX16X6CGQAAAG0"]
[Thu Sep 17 15:26:56.653510 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.94.39.26:41036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbIG65wm-f4uX16X6CHAAAABA"]
[Thu Sep 17 15:26:56.696288 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.180.119.195:39228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/public/.env"] [unique_id "aqxbIG65wm-f4uX16X6CHgAAABw"]
[Thu Sep 17 15:26:56.729301 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.18.173.5:46374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxbIG65wm-f4uX16X6CIAAAAHs"]
[Thu Sep 17 15:26:56.854435 2026] [core:error] [pid 1029697:tid 1029944] [client 34.180.119.195:39228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:56.854466 2026] [core:error] [pid 1029697:tid 1029944] [client 34.180.119.195:39228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:26:56.865643 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.94.39.26:41040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbIG65wm-f4uX16X6CIwAAAFA"]
[Thu Sep 17 15:26:56.871319 2026] [security2:error] [pid 1029697:tid 1029949] [client 169.58.197.253:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/fonts.php"] [unique_id "aqxbIG65wm-f4uX16X6CJAAAAHo"], referer: binance.com
[Thu Sep 17 15:26:57.224463 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/backend/.env"] [unique_id "aqxbIW65wm-f4uX16X6CLQAAAFI"]
[Thu Sep 17 15:26:57.283999 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.94.39.26:41048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbIW65wm-f4uX16X6CLgAAAE0"]
[Thu Sep 17 15:26:57.344813 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/server/.env"] [unique_id "aqxbIW65wm-f4uX16X6CLwAAAD8"]
[Thu Sep 17 15:26:57.421187 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.18.173.5:46388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxbIW65wm-f4uX16X6CMAAAADs"]
[Thu Sep 17 15:26:57.462742 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/frontend/.env"] [unique_id "aqxbIW65wm-f4uX16X6CMgAAACY"]
[Thu Sep 17 15:26:57.586034 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/src/.env"] [unique_id "aqxbIW65wm-f4uX16X6CMwAAACU"]
[Thu Sep 17 15:26:57.663034 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.94.39.26:41064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbIW65wm-f4uX16X6CNwAAAC4"]
[Thu Sep 17 15:26:57.695457 2026] [security2:error] [pid 1029697:tid 1029931] [client 154.190.208.131:41821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbIW65wm-f4uX16X6COQAAAGg"]
[Thu Sep 17 15:26:57.695577 2026] [security2:error] [pid 1029697:tid 1029931] [client 154.190.208.131:41821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbIW65wm-f4uX16X6COQAAAGg"]
[Thu Sep 17 15:26:57.706209 2026] [security2:error] [pid 1029697:tid 1029937] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/core/.env"] [unique_id "aqxbIW65wm-f4uX16X6COgAAAG4"]
[Thu Sep 17 15:26:57.823229 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/core/app/.env"] [unique_id "aqxbIW65wm-f4uX16X6CPQAAAAU"]
[Thu Sep 17 15:26:57.955716 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/config/.env"] [unique_id "aqxbIW65wm-f4uX16X6CPwAAABE"]
[Thu Sep 17 15:26:58.027554 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.39.26:41066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbIm65wm-f4uX16X6CQQAAAHc"]
[Thu Sep 17 15:26:58.073714 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/private/.env"] [unique_id "aqxbIm65wm-f4uX16X6CQwAAADU"]
[Thu Sep 17 15:26:58.125091 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.18.173.5:46392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxbIm65wm-f4uX16X6CSAAAAAI"]
[Thu Sep 17 15:26:58.194859 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/application/.env"] [unique_id "aqxbIm65wm-f4uX16X6CSgAAAAE"]
[Thu Sep 17 15:26:58.316600 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/bootstrap/.env"] [unique_id "aqxbIm65wm-f4uX16X6CTQAAAGk"]
[Thu Sep 17 15:26:58.445188 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/database/.env"] [unique_id "aqxbIm65wm-f4uX16X6CVAAAAA0"]
[Thu Sep 17 15:26:58.491018 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.94.39.26:41076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbIm65wm-f4uX16X6CVQAAACk"]
[Thu Sep 17 15:26:58.537587 2026] [security2:error] [pid 1029697:tid 1029853] [client 4.240.114.86:62770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxbIm65wm-f4uX16X6CWQAAABo"], referer: binance.com
[Thu Sep 17 15:26:58.564698 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/storage/.env"] [unique_id "aqxbIm65wm-f4uX16X6CWgAAAG8"]
[Thu Sep 17 15:26:58.662427 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.94.39.26:41080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbIm65wm-f4uX16X6CYgAAAG0"]
[Thu Sep 17 15:26:58.686243 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/var/www/.env"] [unique_id "aqxbIm65wm-f4uX16X6CYwAAABA"]
[Thu Sep 17 15:26:58.808779 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/var/www/html/.env"] [unique_id "aqxbIm65wm-f4uX16X6CZAAAAHs"]
[Thu Sep 17 15:26:58.923334 2026] [security2:error] [pid 1029697:tid 1029871] [client 45.156.128.177:47328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxbIm65wm-f4uX16X6CZgAAACw"]
[Thu Sep 17 15:26:58.925271 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/current/.env"] [unique_id "aqxbIm65wm-f4uX16X6CbAAAACo"]
[Thu Sep 17 15:26:59.037943 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxbIm65wm-f4uX16X6CawAAAH0"]
[Thu Sep 17 15:26:59.080937 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/release/.env"] [unique_id "aqxbI265wm-f4uX16X6CbgAAAAc"]
[Thu Sep 17 15:26:59.184341 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.94.39.26:41096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbI265wm-f4uX16X6CegAAAC0"]
[Thu Sep 17 15:26:59.213995 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/releases/.env"] [unique_id "aqxbI265wm-f4uX16X6CewAAABg"]
[Thu Sep 17 15:26:59.232808 2026] [security2:error] [pid 1029697:tid 1029909] [client 187.109.98.158:3591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbI265wm-f4uX16X6CcQAAUjs"]
[Thu Sep 17 15:26:59.327404 2026] [security2:error] [pid 1029697:tid 1029864] [client 45.156.128.177:47336] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "aqxbI265wm-f4uX16X6CgAAAACU"]
[Thu Sep 17 15:26:59.344358 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/shared/.env"] [unique_id "aqxbI265wm-f4uX16X6CggAAAC8"]
[Thu Sep 17 15:26:59.468469 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/deploy/.env"] [unique_id "aqxbI265wm-f4uX16X6ChwAAAGU"]
[Thu Sep 17 15:26:59.510213 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.18.173.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxbI265wm-f4uX16X6CgwAAAGg"]
[Thu Sep 17 15:26:59.596398 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/build/.env"] [unique_id "aqxbI265wm-f4uX16X6CiQAAACA"]
[Thu Sep 17 15:26:59.612352 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.94.39.26:41110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/phpinfo.php~"] [unique_id "aqxbI265wm-f4uX16X6CigAAAGQ"]
[Thu Sep 17 15:26:59.721347 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/dist/.env"] [unique_id "aqxbI265wm-f4uX16X6CjgAAAAA"]
[Thu Sep 17 15:26:59.759276 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.18.173.5:46394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbI265wm-f4uX16X6CjwAAAHc"]
[Thu Sep 17 15:26:59.855375 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/public_html/.env"] [unique_id "aqxbI265wm-f4uX16X6CkgAAAEY"]
[Thu Sep 17 15:26:59.984853 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/htdocs/.env"] [unique_id "aqxbI265wm-f4uX16X6ClQAAADY"]
[Thu Sep 17 15:27:00.063479 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.39.26:41116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/info.php.bak"] [unique_id "aqxbJG65wm-f4uX16X6ClwAAAGc"]
[Thu Sep 17 15:27:00.094422 2026] [security2:error] [pid 1029697:tid 1029899] [client 74.7.230.25:55906] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.charlesgiraudet.com"] [uri "/robots.txt"] [unique_id "aqxbJG65wm-f4uX16X6CmQAASGU"]
[Thu Sep 17 15:27:00.110646 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/www/.env"] [unique_id "aqxbJG65wm-f4uX16X6CmwAAACc"]
[Thu Sep 17 15:27:00.126144 2026] [security2:error] [pid 1029697:tid 1029902] [client 45.156.128.176:18022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "aqxbJG65wm-f4uX16X6CnAAAAEs"]
[Thu Sep 17 15:27:00.233499 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/html/.env"] [unique_id "aqxbJG65wm-f4uX16X6CnwAAABU"]
[Thu Sep 17 15:27:00.307360 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.94.39.26:41120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbJG65wm-f4uX16X6CogAAABo"]
[Thu Sep 17 15:27:00.322232 2026] [security2:error] [pid 1029697:tid 1029941] [client 156.192.234.52:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbJG65wm-f4uX16X6CowAAAHI"]
[Thu Sep 17 15:27:00.322802 2026] [security2:error] [pid 1029697:tid 1029941] [client 156.192.234.52:53131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbJG65wm-f4uX16X6CowAAAHI"]
[Thu Sep 17 15:27:00.339327 2026] [security2:error] [pid 1029697:tid 1029830] [client 114.198.138.124:51519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbJG65wm-f4uX16X6CpAAAAAM"]
[Thu Sep 17 15:27:00.339441 2026] [security2:error] [pid 1029697:tid 1029830] [client 114.198.138.124:51519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbJG65wm-f4uX16X6CpAAAAAM"]
[Thu Sep 17 15:27:00.355307 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/live/.env"] [unique_id "aqxbJG65wm-f4uX16X6CpQAAAGM"]
[Thu Sep 17 15:27:00.486942 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/prod/.env"] [unique_id "aqxbJG65wm-f4uX16X6CrAAAAEM"]
[Thu Sep 17 15:27:00.500149 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.18.173.5:46400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxbJG65wm-f4uX16X6CrQAAAEU"]
[Thu Sep 17 15:27:00.586083 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.94.39.26:41126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbJG65wm-f4uX16X6CrwAAAGI"]
[Thu Sep 17 15:27:00.613918 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/dev/.env"] [unique_id "aqxbJG65wm-f4uX16X6CsQAAAHE"]
[Thu Sep 17 15:27:00.747569 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/staging/.env"] [unique_id "aqxbJG65wm-f4uX16X6CtwAAAFw"]
[Thu Sep 17 15:27:00.788114 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.94.39.26:39580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbJG65wm-f4uX16X6CuQAAABM"]
[Thu Sep 17 15:27:00.865269 2026] [security2:error] [pid 1029697:tid 1029917] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/opt/.env"] [unique_id "aqxbJG65wm-f4uX16X6CvAAAAFo"]
[Thu Sep 17 15:27:00.985113 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/laravel/.env"] [unique_id "aqxbJG65wm-f4uX16X6CvwAAACY"]
[Thu Sep 17 15:27:01.048153 2026] [security2:error] [pid 1029697:tid 1029833] [client 185.73.181.52:45669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "kcooke1.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxbJG65wm-f4uX16X6CvQAAAAY"]
[Thu Sep 17 15:27:01.105531 2026] [security2:error] [pid 1029697:tid 1029888] [client 31.176.231.211:51315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxbJG65wm-f4uX16X6CvgAAPUU"], referer: https://anniechenphotography.com/vancouver-family-photographer-blog/
[Thu Sep 17 15:27:01.126941 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/symfony/.env"] [unique_id "aqxbJW65wm-f4uX16X6CwgAAACI"]
[Thu Sep 17 15:27:01.197222 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.18.173.5:41904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbJW65wm-f4uX16X6CwwAAAFI"]
[Thu Sep 17 15:27:01.255750 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/wordpress/.env"] [unique_id "aqxbJW65wm-f4uX16X6CxAAAAGY"]
[Thu Sep 17 15:27:01.277276 2026] [security2:error] [pid 1029697:tid 1029931] [client 45.156.128.179:27038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "aqxbJW65wm-f4uX16X6CxgAAAGg"]
[Thu Sep 17 15:27:01.284723 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.94.39.26:39586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbJW65wm-f4uX16X6CxwAAACU"]
[Thu Sep 17 15:27:01.374403 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/wp/.env"] [unique_id "aqxbJW65wm-f4uX16X6CzAAAAA4"]
[Thu Sep 17 15:27:01.494041 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/cms/.env"] [unique_id "aqxbJW65wm-f4uX16X6CzgAAADw"]
[Thu Sep 17 15:27:01.613228 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/drupal/.env"] [unique_id "aqxbJW65wm-f4uX16X6C5QAAADY"]
[Thu Sep 17 15:27:01.735567 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/joomla/.env"] [unique_id "aqxbJW65wm-f4uX16X6C7AAAAFM"]
[Thu Sep 17 15:27:01.870999 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/magento/.env"] [unique_id "aqxbJW65wm-f4uX16X6C7gAAAHk"]
[Thu Sep 17 15:27:01.890778 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.94.39.26:39590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbJW65wm-f4uX16X6C7wAAABU"]
[Thu Sep 17 15:27:01.918077 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.18.173.5:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbJW65wm-f4uX16X6C8QAAACc"]
[Thu Sep 17 15:27:02.009158 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/shopify/.env"] [unique_id "aqxbJm65wm-f4uX16X6C8wAAAF4"]
[Thu Sep 17 15:27:02.083180 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.122.173.216:47232] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1452"] [id "9011111"] [msg "SQUID data collection"] [hostname "starstoreonline.com"] [uri "/"] [unique_id "aqxbJm65wm-f4uX16X6C-QAAAFg"]
[Thu Sep 17 15:27:02.117699 2026] [security2:error] [pid 1029697:tid 1029856] [client 4.240.114.86:64261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxbJm65wm-f4uX16X6C-gAAAB0"], referer: binance.com
[Thu Sep 17 15:27:02.137068 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/prestashop/.env"] [unique_id "aqxbJm65wm-f4uX16X6C_AAAAHM"]
[Thu Sep 17 15:27:02.299780 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/codeigniter/.env"] [unique_id "aqxbJm65wm-f4uX16X6DCQAAAGo"]
[Thu Sep 17 15:27:02.416896 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.94.39.26:39594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbJm65wm-f4uX16X6DDwAAAE0"]
[Thu Sep 17 15:27:02.419687 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/cakephp/.env"] [unique_id "aqxbJm65wm-f4uX16X6DEAAAABw"]
[Thu Sep 17 15:27:02.537337 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/zend/.env"] [unique_id "aqxbJm65wm-f4uX16X6DFQAAAH0"]
[Thu Sep 17 15:27:02.623038 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.18.173.5:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbJm65wm-f4uX16X6DFwAAACQ"]
[Thu Sep 17 15:27:02.663190 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/yii/.env"] [unique_id "aqxbJm65wm-f4uX16X6DGQAAACw"]
[Thu Sep 17 15:27:02.707202 2026] [security2:error] [pid 1029697:tid 1029907] [client 103.61.184.148:64751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbJm65wm-f4uX16X6DHQAAAFA"]
[Thu Sep 17 15:27:02.707311 2026] [security2:error] [pid 1029697:tid 1029907] [client 103.61.184.148:64751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbJm65wm-f4uX16X6DHQAAAFA"]
[Thu Sep 17 15:27:02.783521 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/laravel5/.env"] [unique_id "aqxbJm65wm-f4uX16X6DHgAAAGw"]
[Thu Sep 17 15:27:02.899995 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.94.39.26:39598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbJm65wm-f4uX16X6DIAAAAHg"]
[Thu Sep 17 15:27:02.920095 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/v1/.env"] [unique_id "aqxbJm65wm-f4uX16X6DIQAAAAY"]
[Thu Sep 17 15:27:02.936263 2026] [security2:error] [pid 1029697:tid 1029850] [client 185.55.149.49:56745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbJm65wm-f4uX16X6DIwAAABc"]
[Thu Sep 17 15:27:02.936383 2026] [security2:error] [pid 1029697:tid 1029850] [client 185.55.149.49:56745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbJm65wm-f4uX16X6DIwAAABc"]
[Thu Sep 17 15:27:02.954338 2026] [security2:error] [pid 1029697:tid 1029873] [client 45.156.128.177:47348] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "aqxbJm65wm-f4uX16X6DJAAAAC4"]
[Thu Sep 17 15:27:03.045246 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.94.39.26:39612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbJ265wm-f4uX16X6DJQAAAE8"]
[Thu Sep 17 15:27:03.059552 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/v2/.env"] [unique_id "aqxbJ265wm-f4uX16X6DJgAAACI"]
[Thu Sep 17 15:27:03.181604 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/v3/.env"] [unique_id "aqxbJ265wm-f4uX16X6DLAAAAD8"]
[Thu Sep 17 15:27:03.304272 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/api/v1/.env"] [unique_id "aqxbJ265wm-f4uX16X6DLgAAACg"]
[Thu Sep 17 15:27:03.335390 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.18.173.5:41946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbJ265wm-f4uX16X6DLwAAADA"]
[Thu Sep 17 15:27:03.425171 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/api/v2/.env"] [unique_id "aqxbJ265wm-f4uX16X6DMgAAACU"]
[Thu Sep 17 15:27:03.520530 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.94.39.26:39614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbJ265wm-f4uX16X6DNAAAADQ"]
[Thu Sep 17 15:27:03.550735 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/rest/.env"] [unique_id "aqxbJ265wm-f4uX16X6DNQAAACA"]
[Thu Sep 17 15:27:03.678889 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/graphql/.env"] [unique_id "aqxbJ265wm-f4uX16X6DOgAAAAE"]
[Thu Sep 17 15:27:03.812488 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/gateway/.env"] [unique_id "aqxbJ265wm-f4uX16X6DPwAAACo"]
[Thu Sep 17 15:27:03.990483 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/microservice/.env"] [unique_id "aqxbJ265wm-f4uX16X6DRgAAAHI"]
[Thu Sep 17 15:27:04.041835 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.18.173.5:41962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxbKG65wm-f4uX16X6DSAAAAA8"]
[Thu Sep 17 15:27:04.087764 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.94.39.26:39628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbKG65wm-f4uX16X6DSgAAAEw"]
[Thu Sep 17 15:27:04.113219 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/service/.env"] [unique_id "aqxbKG65wm-f4uX16X6DSwAAAFg"]
[Thu Sep 17 15:27:04.254731 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/api/v3/.env"] [unique_id "aqxbKG65wm-f4uX16X6DUwAAAB8"]
[Thu Sep 17 15:27:04.287994 2026] [security2:error] [pid 1029697:tid 1029904] [client 66.249.66.43:56396] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "atzmosocial.com"] [uri "/robots.txt"] [unique_id "aqxbKG65wm-f4uX16X6DVAAAAE0"]
[Thu Sep 17 15:27:04.404743 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.94.39.26:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbKG65wm-f4uX16X6DVgAAABw"]
[Thu Sep 17 15:27:04.435079 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/api/dev/.env"] [unique_id "aqxbKG65wm-f4uX16X6DVwAAADE"]
[Thu Sep 17 15:27:04.485268 2026] [security2:error] [pid 1029697:tid 1029943] [client 169.58.197.253:60170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxbKG65wm-f4uX16X6DWAAAAHQ"], referer: binance.com
[Thu Sep 17 15:27:04.575473 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/api/staging/.env"] [unique_id "aqxbKG65wm-f4uX16X6DWQAAAFA"]
[Thu Sep 17 15:27:04.662285 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.94.39.26:39648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbKG65wm-f4uX16X6DYAAAABM"]
[Thu Sep 17 15:27:04.708789 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/vendor/.env"] [unique_id "aqxbKG65wm-f4uX16X6DYwAAAHg"]
[Thu Sep 17 15:27:04.730535 2026] [security2:error] [pid 1029697:tid 1029952] [client 104.207.33.33:45119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1606"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "www.stevearensberg.com"] [uri "/"] [unique_id "aqxbKG65wm-f4uX16X6DZAAAAH0"]
[Thu Sep 17 15:27:04.775596 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.18.173.5:41974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxbKG65wm-f4uX16X6DZQAAAAw"]
[Thu Sep 17 15:27:04.833997 2026] [security2:error] [pid 1029697:tid 1029906] [client 4.240.114.86:65318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-filter-sentinel.php"] [unique_id "aqxbKG65wm-f4uX16X6DaQAAAE8"], referer: binance.com
[Thu Sep 17 15:27:04.840475 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/lib/.env"] [unique_id "aqxbKG65wm-f4uX16X6DagAAACI"]
[Thu Sep 17 15:27:04.967655 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/resources/.env"] [unique_id "aqxbKG65wm-f4uX16X6DbwAAADA"]
[Thu Sep 17 15:27:05.009025 2026] [security2:error] [pid 1029697:tid 1029917] [client 34.94.39.26:39654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbKW65wm-f4uX16X6DcQAAAFo"]
[Thu Sep 17 15:27:05.089955 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/assets/.env"] [unique_id "aqxbKW65wm-f4uX16X6DcgAAACU"]
[Thu Sep 17 15:27:05.214089 2026] [security2:error] [pid 1029697:tid 1029891] [client 45.156.128.178:20538] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxbKW65wm-f4uX16X6DeAAAAEA"]
[Thu Sep 17 15:27:05.222837 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/uploads/.env"] [unique_id "aqxbKW65wm-f4uX16X6DeQAAAD0"]
[Thu Sep 17 15:27:05.307673 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.94.39.26:39666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbKW65wm-f4uX16X6DegAAAAA"]
[Thu Sep 17 15:27:05.345754 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/internal/.env"] [unique_id "aqxbKW65wm-f4uX16X6DfAAAABY"]
[Thu Sep 17 15:27:05.480780 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/tools/.env"] [unique_id "aqxbKW65wm-f4uX16X6DfwAAAGk"]
[Thu Sep 17 15:27:05.487000 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.18.173.5:41982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxbKW65wm-f4uX16X6DgAAAAAQ"]
[Thu Sep 17 15:27:05.605379 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/scripts/.env"] [unique_id "aqxbKW65wm-f4uX16X6DggAAAF8"]
[Thu Sep 17 15:27:05.615748 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.94.39.26:39670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melissa-gonzales.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbKW65wm-f4uX16X6DgwAAAH4"]
[Thu Sep 17 15:27:05.736251 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/bin/.env"] [unique_id "aqxbKW65wm-f4uX16X6DhwAAAAk"]
[Thu Sep 17 15:27:05.852688 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/sbin/.env"] [unique_id "aqxbKW65wm-f4uX16X6DigAAABo"]
[Thu Sep 17 15:27:05.976207 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/local/.env"] [unique_id "aqxbKW65wm-f4uX16X6DkAAAADU"]
[Thu Sep 17 15:27:06.044980 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.166.123.190:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/phpinfo.php"] [unique_id "aqxbKm65wm-f4uX16X6DkgAAAAM"]
[Thu Sep 17 15:27:06.093406 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/portal/.env"] [unique_id "aqxbKm65wm-f4uX16X6DlAAAAGM"]
[Thu Sep 17 15:27:06.195491 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.18.173.5:41992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxbKm65wm-f4uX16X6DmQAAACc"]
[Thu Sep 17 15:27:06.220029 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/dashboard/.env"] [unique_id "aqxbKm65wm-f4uX16X6DmgAAAHM"]
[Thu Sep 17 15:27:06.367655 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/panel/.env"] [unique_id "aqxbKm65wm-f4uX16X6DnwAAAEU"]
[Thu Sep 17 15:27:06.378035 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.166.123.190:59574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.bejackson.com"] [uri "/"] [unique_id "aqxbKm65wm-f4uX16X6DogAAABw"]
[Thu Sep 17 15:27:06.427588 2026] [security2:error] [pid 1029697:tid 1029934] [client 45.156.128.179:27044] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "aqxbKm65wm-f4uX16X6DpAAAAGs"]
[Thu Sep 17 15:27:06.513842 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/crm/.env"] [unique_id "aqxbKm65wm-f4uX16X6DqgAAAAg"]
[Thu Sep 17 15:27:06.648996 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/erp/.env"] [unique_id "aqxbKm65wm-f4uX16X6DrwAAAAY"]
[Thu Sep 17 15:27:06.729119 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.166.123.190:42162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/info.php"] [unique_id "aqxbKm65wm-f4uX16X6DtgAAADk"]
[Thu Sep 17 15:27:06.773123 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/shop/.env"] [unique_id "aqxbKm65wm-f4uX16X6DuQAAAHs"]
[Thu Sep 17 15:27:06.850755 2026] [security2:error] [pid 1029697:tid 1029899] [client 102.204.153.93:53717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbKm65wm-f4uX16X6DuAAASCc"]
[Thu Sep 17 15:27:06.895002 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.180.119.195:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/store/.env"] [unique_id "aqxbKm65wm-f4uX16X6DvAAAAD8"]
[Thu Sep 17 15:27:06.900968 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.18.173.5:42008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxbKm65wm-f4uX16X6DvQAAACw"]
[Thu Sep 17 15:27:07.065593 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.166.123.190:59584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.bejackson.com"] [uri "/"] [unique_id "aqxbK265wm-f4uX16X6DwQAAAGw"]
[Thu Sep 17 15:27:07.221770 2026] [security2:error] [pid 1029697:tid 1029886] [client 54.39.177.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "npae.net"] [uri "/index.php"] [unique_id "aqxbKG65wm-f4uX16X6DbgAAADs"]
[Thu Sep 17 15:27:07.321189 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/saas/.env"] [unique_id "aqxbK265wm-f4uX16X6DywAAABs"]
[Thu Sep 17 15:27:07.411266 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.166.123.190:42166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/php.php"] [unique_id "aqxbK265wm-f4uX16X6DzQAAACA"]
[Thu Sep 17 15:27:07.455172 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/client/.env"] [unique_id "aqxbK265wm-f4uX16X6DzgAAAAQ"]
[Thu Sep 17 15:27:07.584068 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/project/.env"] [unique_id "aqxbK265wm-f4uX16X6D0QAAAAI"]
[Thu Sep 17 15:27:07.606002 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.18.173.5:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxbK265wm-f4uX16X6D0gAAAB4"]
[Thu Sep 17 15:27:07.710978 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/admin-panel/.env"] [unique_id "aqxbK265wm-f4uX16X6D2AAAABo"]
[Thu Sep 17 15:27:07.757537 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.166.123.190:59592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.bejackson.com"] [uri "/"] [unique_id "aqxbK265wm-f4uX16X6D2gAAABE"]
[Thu Sep 17 15:27:07.848907 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/control-panel/.env"] [unique_id "aqxbK265wm-f4uX16X6D3QAAAHc"]
[Thu Sep 17 15:27:07.868086 2026] [security2:error] [pid 1029697:tid 1029937] [client 4.240.114.86:50230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxbK265wm-f4uX16X6D3gAAAG4"], referer: binance.com
[Thu Sep 17 15:27:08.007402 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/user-panel/.env"] [unique_id "aqxbLG65wm-f4uX16X6D4QAAAHM"]
[Thu Sep 17 15:27:08.105246 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.166.123.190:42174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/i.php"] [unique_id "aqxbLG65wm-f4uX16X6D4gAAAGc"]
[Thu Sep 17 15:27:08.118115 2026] [security2:error] [pid 1029697:tid 1029896] [client 45.156.128.176:18040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "aqxbLG65wm-f4uX16X6D4wAAAEU"]
[Thu Sep 17 15:27:08.137673 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/node/.env"] [unique_id "aqxbLG65wm-f4uX16X6D5AAAABw"]
[Thu Sep 17 15:27:08.234240 2026] [security2:error] [pid 1029697:tid 1029880] [client 154.190.208.131:42425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLG65wm-f4uX16X6D6AAAADU"]
[Thu Sep 17 15:27:08.234364 2026] [security2:error] [pid 1029697:tid 1029880] [client 154.190.208.131:42425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLG65wm-f4uX16X6D6AAAADU"]
[Thu Sep 17 15:27:08.300697 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/express/.env"] [unique_id "aqxbLG65wm-f4uX16X6D6gAAAGs"]
[Thu Sep 17 15:27:08.304914 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.18.173.5:42032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxbLG65wm-f4uX16X6D6wAAAE0"]
[Thu Sep 17 15:27:08.424671 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/next/.env"] [unique_id "aqxbLG65wm-f4uX16X6D8AAAADo"]
[Thu Sep 17 15:27:08.579776 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/nuxt/.env"] [unique_id "aqxbLG65wm-f4uX16X6D9gAAAD8"]
[Thu Sep 17 15:27:08.684760 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.166.123.190:59600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.bejackson.com"] [uri "/"] [unique_id "aqxbLG65wm-f4uX16X6D_AAAAGY"]
[Thu Sep 17 15:27:08.734188 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/nest/.env"] [unique_id "aqxbLG65wm-f4uX16X6D_QAAAEk"]
[Thu Sep 17 15:27:08.792527 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.166.123.190:42186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/pi.php"] [unique_id "aqxbLG65wm-f4uX16X6D_gAAAHs"]
[Thu Sep 17 15:27:08.870260 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/react/.env"] [unique_id "aqxbLG65wm-f4uX16X6EAAAAAD0"]
[Thu Sep 17 15:27:08.989584 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/vue/.env"] [unique_id "aqxbLG65wm-f4uX16X6EBQAAAGQ"]
[Thu Sep 17 15:27:09.009624 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.18.173.5:42044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxbLW65wm-f4uX16X6EBgAAACg"]
[Thu Sep 17 15:27:09.128499 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/angular/.env"] [unique_id "aqxbLW65wm-f4uX16X6EFgAAABk"]
[Thu Sep 17 15:27:09.256509 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/svelte/.env"] [unique_id "aqxbLW65wm-f4uX16X6EHAAAAAE"]
[Thu Sep 17 15:27:09.379949 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/vite/.env"] [unique_id "aqxbLW65wm-f4uX16X6EIgAAACk"]
[Thu Sep 17 15:27:09.471693 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.166.123.190:42200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/pinfo.php"] [unique_id "aqxbLW65wm-f4uX16X6EJwAAADA"]
[Thu Sep 17 15:27:09.518712 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/backup/.env"] [unique_id "aqxbLW65wm-f4uX16X6EKAAAAC0"]
[Thu Sep 17 15:27:09.662730 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/backups/.env"] [unique_id "aqxbLW65wm-f4uX16X6EMwAAAHA"]
[Thu Sep 17 15:27:09.704751 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.18.173.5:42046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxbLW65wm-f4uX16X6EOQAAADU"]
[Thu Sep 17 15:27:09.793345 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/old/.env"] [unique_id "aqxbLW65wm-f4uX16X6ERAAAADM"]
[Thu Sep 17 15:27:09.846298 2026] [security2:error] [pid 1029697:tid 1029918] [client 179.246.193.105:36863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbLW65wm-f4uX16X6EOAAAWxs"]
[Thu Sep 17 15:27:09.916075 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/tmp/.env"] [unique_id "aqxbLW65wm-f4uX16X6ETgAAACU"]
[Thu Sep 17 15:27:09.932753 2026] [security2:error] [pid 1029697:tid 1029900] [client 43.172.194.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbLW65wm-f4uX16X6EQAAAAEk"]
[Thu Sep 17 15:27:09.944136 2026] [security2:error] [pid 1029697:tid 1029938] [client 43.173.182.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbLW65wm-f4uX16X6EPgAAAG8"]
[Thu Sep 17 15:27:10.017318 2026] [security2:error] [pid 1029697:tid 1029839] [client 43.173.181.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbLW65wm-f4uX16X6ERgAAAAw"]
[Thu Sep 17 15:27:10.050559 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/temp/.env"] [unique_id "aqxbLm65wm-f4uX16X6EXQAAABk"]
[Thu Sep 17 15:27:10.071190 2026] [security2:error] [pid 1029697:tid 1029853] [client 45.156.128.179:17558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "aqxbLm65wm-f4uX16X6EXgAAABo"]
[Thu Sep 17 15:27:10.079024 2026] [security2:error] [pid 1029697:tid 1029919] [client 43.173.181.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbLW65wm-f4uX16X6EPAAAAFw"]
[Thu Sep 17 15:27:10.083330 2026] [security2:error] [pid 1029697:tid 1029889] [client 43.172.198.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbLW65wm-f4uX16X6ESwAAAD4"]
[Thu Sep 17 15:27:10.153876 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.166.123.190:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/test.php"] [unique_id "aqxbLm65wm-f4uX16X6EYQAAAGw"]
[Thu Sep 17 15:27:10.171089 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/lab/.env"] [unique_id "aqxbLm65wm-f4uX16X6EZAAAAHM"]
[Thu Sep 17 15:27:10.295688 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/cronlab/.env"] [unique_id "aqxbLm65wm-f4uX16X6EagAAAHg"]
[Thu Sep 17 15:27:10.412138 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.18.173.5:42050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxbLm65wm-f4uX16X6EcAAAAB0"]
[Thu Sep 17 15:27:10.420425 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/cron/.env"] [unique_id "aqxbLm65wm-f4uX16X6EcQAAAD0"]
[Thu Sep 17 15:27:10.553188 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/en/.env"] [unique_id "aqxbLm65wm-f4uX16X6EdwAAAAs"]
[Thu Sep 17 15:27:10.584081 2026] [autoindex:error] [pid 1029697:tid 1029872] [client 34.245.117.201:53084] AH01276: Cannot serve directory /home1/jbnbnlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:27:10.764005 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/administrator/.env"] [unique_id "aqxbLm65wm-f4uX16X6EggAAAAY"]
[Thu Sep 17 15:27:10.891880 2026] [security2:error] [pid 1029697:tid 1029923] [client 156.192.234.52:53752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLm65wm-f4uX16X6EkgAAAGA"]
[Thu Sep 17 15:27:10.893265 2026] [security2:error] [pid 1029697:tid 1029923] [client 156.192.234.52:53752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLm65wm-f4uX16X6EkgAAAGA"]
[Thu Sep 17 15:27:10.904588 2026] [security2:error] [pid 1029697:tid 1029922] [client 114.198.138.124:52167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLm65wm-f4uX16X6EkAAAAF8"]
[Thu Sep 17 15:27:10.904716 2026] [security2:error] [pid 1029697:tid 1029922] [client 114.198.138.124:52167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLm65wm-f4uX16X6EkAAAAF8"]
[Thu Sep 17 15:27:10.924108 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/psnlink/.env"] [unique_id "aqxbLm65wm-f4uX16X6ElAAAAEQ"]
[Thu Sep 17 15:27:10.971986 2026] [security2:error] [pid 1029697:tid 1029884] [client 136.158.61.34:25064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLm65wm-f4uX16X6ElQAAADk"]
[Thu Sep 17 15:27:10.972098 2026] [security2:error] [pid 1029697:tid 1029884] [client 136.158.61.34:25064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbLm65wm-f4uX16X6ElQAAADk"]
[Thu Sep 17 15:27:11.074561 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.166.123.190:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/p.php"] [unique_id "aqxbL265wm-f4uX16X6EmgAAAFw"]
[Thu Sep 17 15:27:11.086271 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/exapi/.env"] [unique_id "aqxbL265wm-f4uX16X6EmwAAAHI"]
[Thu Sep 17 15:27:11.128153 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.18.173.5:42064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxbL265wm-f4uX16X6EnwAAAAw"]
[Thu Sep 17 15:27:11.216484 2026] [security2:error] [pid 1029697:tid 1029937] [client 34.180.119.195:32800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/sitemaps/.env"] [unique_id "aqxbL265wm-f4uX16X6EpwAAAG4"]
[Thu Sep 17 15:27:11.388326 2026] [core:error] [pid 1029697:tid 1029860] [client 34.180.119.195:32800] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:11.388351 2026] [core:error] [pid 1029697:tid 1029860] [client 34.180.119.195:32800] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:11.421088 2026] [security2:error] [pid 1029697:tid 1029840] [client 4.240.114.86:51687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-icon-collections-registry.php"] [unique_id "aqxbL265wm-f4uX16X6ErwAAAA0"], referer: binance.com
[Thu Sep 17 15:27:11.614247 2026] [security2:error] [pid 1029697:tid 1029925] [client 45.156.128.179:17568] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "aqxbL265wm-f4uX16X6EuAAAAGI"]
[Thu Sep 17 15:27:11.763612 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.166.123.190:58122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/debug.php"] [unique_id "aqxbL265wm-f4uX16X6EwAAAADw"]
[Thu Sep 17 15:27:11.835626 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.18.173.5:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbL265wm-f4uX16X6EwgAAADY"]
[Thu Sep 17 15:27:12.003388 2026] [core:error] [pid 1029697:tid 1029846] [client 34.180.119.195:32810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:12.003414 2026] [core:error] [pid 1029697:tid 1029846] [client 34.180.119.195:32810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:12.316097 2026] [security2:error] [pid 1029697:tid 1029951] [client 43.134.100.175:43182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sfvhbt.org"] [uri "/index.php"] [unique_id "aqxbL265wm-f4uX16X6EwwAAAHw"]
[Thu Sep 17 15:27:12.453185 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.166.123.190:58132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbMG65wm-f4uX16X6E0gAAAHQ"]
[Thu Sep 17 15:27:12.517633 2026] [security2:error] [pid 1029697:tid 1029926] [client 104.207.33.33:25069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.stevearensberg.com"] [uri "/wp-content/plugins/wp-ticket/readme.txt"] [unique_id "aqxbMG65wm-f4uX16X6E1AAAAGM"]
[Thu Sep 17 15:27:12.532480 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.18.173.5:37550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbMG65wm-f4uX16X6E1QAAAGY"]
[Thu Sep 17 15:27:12.634546 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/logs/.env"] [unique_id "aqxbMG65wm-f4uX16X6E2QAAADk"]
[Thu Sep 17 15:27:12.789093 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/cache/.env"] [unique_id "aqxbMG65wm-f4uX16X6E3gAAAAk"]
[Thu Sep 17 15:27:12.936905 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mailer/.env"] [unique_id "aqxbMG65wm-f4uX16X6E5QAAAHg"]
[Thu Sep 17 15:27:12.982520 2026] [security2:error] [pid 1029697:tid 1029950] [client 169.58.197.253:60711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxbMG65wm-f4uX16X6E5gAAAHs"], referer: binance.com
[Thu Sep 17 15:27:13.062684 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mail/.env"] [unique_id "aqxbMW65wm-f4uX16X6E5wAAAEI"]
[Thu Sep 17 15:27:13.115357 2026] [security2:error] [pid 1029697:tid 1029903] [client 45.156.128.178:44952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/groma-canary-not-a-real-plugin/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E6QAAAEw"]
[Thu Sep 17 15:27:13.142425 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.166.123.190:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbMW65wm-f4uX16X6E6gAAAEM"]
[Thu Sep 17 15:27:13.193086 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/email/.env"] [unique_id "aqxbMW65wm-f4uX16X6E7AAAAFc"]
[Thu Sep 17 15:27:13.239892 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.18.173.5:37566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxbMW65wm-f4uX16X6E7QAAABQ"]
[Thu Sep 17 15:27:13.320805 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/smtp/.env"] [unique_id "aqxbMW65wm-f4uX16X6E8QAAAB4"]
[Thu Sep 17 15:27:13.419984 2026] [security2:error] [pid 1029697:tid 1029927] [client 45.156.128.178:44966] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E9AAAAGQ"]
[Thu Sep 17 15:27:13.422201 2026] [security2:error] [pid 1029697:tid 1029904] [client 45.156.128.178:44962] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E9QAAAE0"]
[Thu Sep 17 15:27:13.430414 2026] [security2:error] [pid 1029697:tid 1029939] [client 45.156.128.176:14506] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E9gAAAHA"]
[Thu Sep 17 15:27:13.434230 2026] [security2:error] [pid 1029697:tid 1029945] [client 45.156.128.176:14518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E9wAAAHY"]
[Thu Sep 17 15:27:13.437907 2026] [security2:error] [pid 1029697:tid 1029882] [client 45.156.128.177:59694] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E-AAAADc"]
[Thu Sep 17 15:27:13.438481 2026] [security2:error] [pid 1029697:tid 1029838] [client 45.156.128.178:44980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E-QAAAAs"]
[Thu Sep 17 15:27:13.441938 2026] [security2:error] [pid 1029697:tid 1029858] [client 45.156.128.179:17578] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E-gAAAB8"]
[Thu Sep 17 15:27:13.447130 2026] [security2:error] [pid 1029697:tid 1029877] [client 45.156.128.179:17584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E-wAAADI"]
[Thu Sep 17 15:27:13.449980 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mailing/.env"] [unique_id "aqxbMW65wm-f4uX16X6E_AAAADw"]
[Thu Sep 17 15:27:13.454186 2026] [security2:error] [pid 1029697:tid 1029911] [client 103.61.184.148:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbMW65wm-f4uX16X6E_QAAAFQ"]
[Thu Sep 17 15:27:13.454257 2026] [security2:error] [pid 1029697:tid 1029911] [client 103.61.184.148:65312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbMW65wm-f4uX16X6E_QAAAFQ"]
[Thu Sep 17 15:27:13.458333 2026] [security2:error] [pid 1029697:tid 1029872] [client 45.156.128.179:17588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E_gAAAC0"]
[Thu Sep 17 15:27:13.462877 2026] [security2:error] [pid 1029697:tid 1029844] [client 45.156.128.177:59706] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6E_wAAABE"]
[Thu Sep 17 15:27:13.465303 2026] [security2:error] [pid 1029697:tid 1029871] [client 45.156.128.176:14524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FAAAAACw"]
[Thu Sep 17 15:27:13.466922 2026] [security2:error] [pid 1029697:tid 1029881] [client 45.156.128.179:17606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FAQAAADY"]
[Thu Sep 17 15:27:13.471335 2026] [security2:error] [pid 1029697:tid 1029933] [client 45.156.128.178:44986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FAgAAAGo"]
[Thu Sep 17 15:27:13.473617 2026] [security2:error] [pid 1029697:tid 1029892] [client 45.156.128.179:17598] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FAwAAAEE"]
[Thu Sep 17 15:27:13.485266 2026] [security2:error] [pid 1029697:tid 1029878] [client 45.156.128.176:14534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FBAAAADM"]
[Thu Sep 17 15:27:13.489698 2026] [security2:error] [pid 1029697:tid 1029862] [client 45.156.128.176:14540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FBQAAACM"]
[Thu Sep 17 15:27:13.510833 2026] [security2:error] [pid 1029697:tid 1029845] [client 45.156.128.177:59714] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FBgAAABI"]
[Thu Sep 17 15:27:13.516318 2026] [security2:error] [pid 1029697:tid 1029849] [client 45.156.128.179:17622] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FBwAAABY"]
[Thu Sep 17 15:27:13.517901 2026] [security2:error] [pid 1029697:tid 1029928] [client 45.156.128.178:45000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FCAAAAGU"]
[Thu Sep 17 15:27:13.524102 2026] [security2:error] [pid 1029697:tid 1029938] [client 45.156.128.177:59726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FCQAAAG8"]
[Thu Sep 17 15:27:13.530415 2026] [security2:error] [pid 1029697:tid 1029905] [client 45.156.128.179:17628] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FCgAAAE4"]
[Thu Sep 17 15:27:13.535768 2026] [security2:error] [pid 1029697:tid 1029915] [client 45.156.128.178:45016] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FCwAAAFg"]
[Thu Sep 17 15:27:13.539655 2026] [security2:error] [pid 1029697:tid 1029841] [client 45.156.128.177:59738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FDAAAAA4"]
[Thu Sep 17 15:27:13.539741 2026] [security2:error] [pid 1029697:tid 1029855] [client 45.156.128.176:14556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FDQAAABw"]
[Thu Sep 17 15:27:13.539853 2026] [security2:error] [pid 1029697:tid 1029846] [client 45.156.128.177:59752] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FDgAAABM"]
[Thu Sep 17 15:27:13.550740 2026] [security2:error] [pid 1029697:tid 1029896] [client 45.156.128.179:17636] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FDwAAAEU"]
[Thu Sep 17 15:27:13.551050 2026] [security2:error] [pid 1029697:tid 1029886] [client 45.156.128.177:59766] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FEAAAADs"]
[Thu Sep 17 15:27:13.557507 2026] [security2:error] [pid 1029697:tid 1029863] [client 45.156.128.179:17640] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FEQAAACQ"]
[Thu Sep 17 15:27:13.558348 2026] [security2:error] [pid 1029697:tid 1029906] [client 45.156.128.179:17644] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FEgAAAE8"]
[Thu Sep 17 15:27:13.560600 2026] [security2:error] [pid 1029697:tid 1029897] [client 45.156.128.176:14562] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FEwAAAEY"]
[Thu Sep 17 15:27:13.566216 2026] [security2:error] [pid 1029697:tid 1029920] [client 45.156.128.177:59778] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FFQAAAF0"]
[Thu Sep 17 15:27:13.568521 2026] [security2:error] [pid 1029697:tid 1029830] [client 45.156.128.177:59786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FFgAAAAM"]
[Thu Sep 17 15:27:13.570025 2026] [security2:error] [pid 1029697:tid 1029833] [client 45.156.128.179:17648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FFwAAAAY"]
[Thu Sep 17 15:27:13.572565 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/notifications/.env"] [unique_id "aqxbMW65wm-f4uX16X6FGAAAAC4"]
[Thu Sep 17 15:27:13.575386 2026] [security2:error] [pid 1029697:tid 1029913] [client 45.156.128.179:17654] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FGQAAAFY"]
[Thu Sep 17 15:27:13.587779 2026] [security2:error] [pid 1029697:tid 1029951] [client 45.156.128.176:14574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FGgAAAHw"]
[Thu Sep 17 15:27:13.588388 2026] [security2:error] [pid 1029697:tid 1029922] [client 45.156.128.177:59792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FGwAAAF8"]
[Thu Sep 17 15:27:13.599101 2026] [security2:error] [pid 1029697:tid 1029943] [client 45.156.128.178:45024] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FHQAAAHQ"]
[Thu Sep 17 15:27:13.599653 2026] [security2:error] [pid 1029697:tid 1029891] [client 45.156.128.179:17668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FHgAAAEA"]
[Thu Sep 17 15:27:13.601431 2026] [security2:error] [pid 1029697:tid 1029869] [client 45.156.128.178:45038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FHwAAACo"]
[Thu Sep 17 15:27:13.602460 2026] [security2:error] [pid 1029697:tid 1029867] [client 185.55.149.49:57459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbMW65wm-f4uX16X6FIAAAACg"]
[Thu Sep 17 15:27:13.602528 2026] [security2:error] [pid 1029697:tid 1029867] [client 185.55.149.49:57459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbMW65wm-f4uX16X6FIAAAACg"]
[Thu Sep 17 15:27:13.602901 2026] [security2:error] [pid 1029697:tid 1029953] [client 45.156.128.176:14590] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FIQAAAH4"]
[Thu Sep 17 15:27:13.621749 2026] [security2:error] [pid 1029697:tid 1029919] [client 45.156.128.176:14598] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FIgAAAFw"]
[Thu Sep 17 15:27:13.623995 2026] [security2:error] [pid 1029697:tid 1029929] [client 45.156.128.176:14614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FJAAAAGY"]
[Thu Sep 17 15:27:13.632296 2026] [security2:error] [pid 1029697:tid 1029832] [client 45.156.128.176:14618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FJQAAAAU"]
[Thu Sep 17 15:27:13.638233 2026] [security2:error] [pid 1029697:tid 1029828] [client 45.156.128.178:45046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FJgAAAAE"]
[Thu Sep 17 15:27:13.646248 2026] [security2:error] [pid 1029697:tid 1029937] [client 45.156.128.179:17680] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FKAAAAG4"]
[Thu Sep 17 15:27:13.649985 2026] [security2:error] [pid 1029697:tid 1029902] [client 45.156.128.178:45056] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FKQAAAEs"]
[Thu Sep 17 15:27:13.655841 2026] [security2:error] [pid 1029697:tid 1029901] [client 45.156.128.178:45070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FKgAAAEo"]
[Thu Sep 17 15:27:13.655907 2026] [security2:error] [pid 1029697:tid 1029866] [client 45.156.128.179:17686] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FKwAAACc"]
[Thu Sep 17 15:27:13.660855 2026] [security2:error] [pid 1029697:tid 1029834] [client 45.156.128.178:45086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FLAAAAAc"]
[Thu Sep 17 15:27:13.667273 2026] [security2:error] [pid 1029697:tid 1029831] [client 45.156.128.176:14626] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "aqxbMW65wm-f4uX16X6FLgAAAAQ"]
[Thu Sep 17 15:27:13.740243 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/notify/.env"] [unique_id "aqxbMW65wm-f4uX16X6FMQAAADU"]
[Thu Sep 17 15:27:13.824598 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.166.123.190:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbMW65wm-f4uX16X6FNAAAAEQ"]
[Thu Sep 17 15:27:13.900837 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.44.196.215:16032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxbMW65wm-f4uX16X6FIwAACEI"]
[Thu Sep 17 15:27:13.900887 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/sender/.env"] [unique_id "aqxbMW65wm-f4uX16X6FPAAAACw"]
[Thu Sep 17 15:27:13.939309 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.18.173.5:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxbMW65wm-f4uX16X6FPQAAAHU"]
[Thu Sep 17 15:27:14.031134 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/campaign/.env"] [unique_id "aqxbMm65wm-f4uX16X6FPwAAAGU"]
[Thu Sep 17 15:27:14.080585 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.44.196.215:16032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxbMW65wm-f4uX16X6FPgAAEkE"]
[Thu Sep 17 15:27:14.088874 2026] [security2:error] [pid 1029697:tid 1029846] [client 45.156.128.179:17688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "aqxbMm65wm-f4uX16X6FQgAAABM"]
[Thu Sep 17 15:27:14.175691 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/newsletter/.env"] [unique_id "aqxbMm65wm-f4uX16X6FRgAAAB0"]
[Thu Sep 17 15:27:14.299675 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/ses/.env"] [unique_id "aqxbMm65wm-f4uX16X6FUAAAAHQ"]
[Thu Sep 17 15:27:14.409491 2026] [security2:error] [pid 1029697:tid 1029837] [client 192.178.6.4:56754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxbMm65wm-f4uX16X6FVgAAAAo"]
[Thu Sep 17 15:27:14.441344 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/sendgrid/.env"] [unique_id "aqxbMm65wm-f4uX16X6FVwAAAGM"]
[Thu Sep 17 15:27:14.513233 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.166.123.190:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbMm65wm-f4uX16X6FXAAAAGA"]
[Thu Sep 17 15:27:14.523341 2026] [security2:error] [pid 1029697:tid 1029902] [client 4.240.114.86:53083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxbMm65wm-f4uX16X6FXQAAAEs"], referer: binance.com
[Thu Sep 17 15:27:14.537468 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.44.196.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxbMm65wm-f4uX16X6FVQAAAH4"]
[Thu Sep 17 15:27:14.575253 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/sparkpost/.env"] [unique_id "aqxbMm65wm-f4uX16X6FXgAAAAc"]
[Thu Sep 17 15:27:14.643993 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.18.173.5:37586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbMm65wm-f4uX16X6FYAAAAFw"]
[Thu Sep 17 15:27:14.728075 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/postmark/.env"] [unique_id "aqxbMm65wm-f4uX16X6FZAAAAGw"]
[Thu Sep 17 15:27:14.920324 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mailgun/.env"] [unique_id "aqxbMm65wm-f4uX16X6FbgAAAAA"]
[Thu Sep 17 15:27:15.089383 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mandrill/.env"] [unique_id "aqxbM265wm-f4uX16X6FdAAAAD0"]
[Thu Sep 17 15:27:15.206788 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.166.123.190:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbM265wm-f4uX16X6FdgAAAFU"]
[Thu Sep 17 15:27:15.242846 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mailjet/.env"] [unique_id "aqxbM265wm-f4uX16X6FeAAAAC0"]
[Thu Sep 17 15:27:15.344651 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.18.173.5:37596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbM265wm-f4uX16X6FfQAAADc"]
[Thu Sep 17 15:27:15.371554 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/brevo/.env"] [unique_id "aqxbM265wm-f4uX16X6FgAAAAGo"]
[Thu Sep 17 15:27:15.468436 2026] [security2:error] [pid 1029697:tid 1029938] [client 74.7.244.45:56226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxbMm65wm-f4uX16X6FQQAAb2A"]
[Thu Sep 17 15:27:15.505102 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/transactional/.env"] [unique_id "aqxbM265wm-f4uX16X6FhQAAADs"]
[Thu Sep 17 15:27:15.591738 2026] [security2:error] [pid 1029697:tid 1029918] [client 45.156.128.179:17698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxbM265wm-f4uX16X6FiQAAAFs"]
[Thu Sep 17 15:27:15.629740 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/bulk/.env"] [unique_id "aqxbM265wm-f4uX16X6FiwAAAEk"]
[Thu Sep 17 15:27:15.766358 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/aws/.env"] [unique_id "aqxbM265wm-f4uX16X6FkQAAAG0"]
[Thu Sep 17 15:27:15.888630 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.166.123.190:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbM265wm-f4uX16X6FkwAAAE8"]
[Thu Sep 17 15:27:15.904504 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/azure/.env"] [unique_id "aqxbM265wm-f4uX16X6FlAAAADk"]
[Thu Sep 17 15:27:16.033481 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/gcp/.env"] [unique_id "aqxbNG65wm-f4uX16X6FlwAAAAc"]
[Thu Sep 17 15:27:16.055552 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.18.173.5:37608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxbNG65wm-f4uX16X6FmQAAAAw"]
[Thu Sep 17 15:27:16.179586 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/cloud/.env"] [unique_id "aqxbNG65wm-f4uX16X6FmwAAAEA"]
[Thu Sep 17 15:27:16.307876 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/infrastructure/.env"] [unique_id "aqxbNG65wm-f4uX16X6FpAAAAHg"]
[Thu Sep 17 15:27:16.449998 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/docker/.env"] [unique_id "aqxbNG65wm-f4uX16X6FqQAAABs"]
[Thu Sep 17 15:27:16.584210 2026] [security2:error] [pid 1029697:tid 1029836] [client 185.246.175.193:46669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbNG65wm-f4uX16X6FqAAACSs"], referer: https://endless-chronicles.com/
[Thu Sep 17 15:27:16.629151 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/k8s/.env"] [unique_id "aqxbNG65wm-f4uX16X6FrwAAAB4"]
[Thu Sep 17 15:27:16.711199 2026] [autoindex:error] [pid 1029697:tid 1029940] [client 35.198.3.220:46766] AH01276: Cannot serve directory /home1/ditkuemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:27:16.754064 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.18.173.5:37610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.173.18.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hym.qby.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxbNG65wm-f4uX16X6FtQAAAEM"]
[Thu Sep 17 15:27:16.762437 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/kubernetes/.env"] [unique_id "aqxbNG65wm-f4uX16X6FtgAAAHY"]
[Thu Sep 17 15:27:16.810701 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.166.123.190:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/php-info.php"] [unique_id "aqxbNG65wm-f4uX16X6FtwAAAFU"]
[Thu Sep 17 15:27:16.926698 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/terraform/.env"] [unique_id "aqxbNG65wm-f4uX16X6FugAAABU"]
[Thu Sep 17 15:27:17.075741 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/ansible/.env"] [unique_id "aqxbNW65wm-f4uX16X6FvQAAACU"]
[Thu Sep 17 15:27:17.273842 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/.git/.env"] [unique_id "aqxbNW65wm-f4uX16X6FxAAAADs"]
[Thu Sep 17 15:27:17.397307 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/ci/.env"] [unique_id "aqxbNW65wm-f4uX16X6FygAAAHQ"]
[Thu Sep 17 15:27:17.486391 2026] [security2:error] [pid 1029697:tid 1029926] [client 45.156.128.177:59796] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "aqxbNW65wm-f4uX16X6F0QAAAGM"]
[Thu Sep 17 15:27:17.489081 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.166.123.190:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/phpversion.php"] [unique_id "aqxbNW65wm-f4uX16X6F0gAAAG8"]
[Thu Sep 17 15:27:17.567998 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/cd/.env"] [unique_id "aqxbNW65wm-f4uX16X6F1QAAAAU"]
[Thu Sep 17 15:27:17.652464 2026] [authz_core:error] [pid 1029697:tid 1029871] [client 40.81.232.68:57013] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:27:17.697343 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/jenkins/.env"] [unique_id "aqxbNW65wm-f4uX16X6F3QAAAE8"]
[Thu Sep 17 15:27:17.721518 2026] [security2:error] [pid 1029697:tid 1029941] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/.env"] [unique_id "aqxbNW65wm-f4uX16X6F3gAAAHI"]
[Thu Sep 17 15:27:17.834617 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/gitlab/.env"] [unique_id "aqxbNW65wm-f4uX16X6F5AAAAH4"]
[Thu Sep 17 15:27:17.982228 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/github/.env"] [unique_id "aqxbNW65wm-f4uX16X6F6QAAADo"]
[Thu Sep 17 15:27:18.153331 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/actions/.env"] [unique_id "aqxbNm65wm-f4uX16X6F7wAAADE"]
[Thu Sep 17 15:27:18.179336 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.166.123.190:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/_phpinfo.php"] [unique_id "aqxbNm65wm-f4uX16X6F8QAAAEA"]
[Thu Sep 17 15:27:18.282450 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/circleci/.env"] [unique_id "aqxbNm65wm-f4uX16X6F9gAAAAk"]
[Thu Sep 17 15:27:18.305935 2026] [security2:error] [pid 1029697:tid 1029940] [client 4.240.114.86:54689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxbNm65wm-f4uX16X6F-gAAAHE"], referer: binance.com
[Thu Sep 17 15:27:18.425417 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/travis/.env"] [unique_id "aqxbNm65wm-f4uX16X6GAAAAAHA"]
[Thu Sep 17 15:27:18.574534 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/buildkite/.env"] [unique_id "aqxbNm65wm-f4uX16X6GBAAAAFE"]
[Thu Sep 17 15:27:18.691574 2026] [security2:error] [pid 1029697:tid 1029873] [client 154.190.208.131:41551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.208.190.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbNm65wm-f4uX16X6GCAAAAC4"]
[Thu Sep 17 15:27:18.696114 2026] [security2:error] [pid 1029697:tid 1029873] [client 154.190.208.131:41551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "melissa-gonzales.com"] [uri "/xmlrpc.php"] [unique_id "aqxbNm65wm-f4uX16X6GCAAAAC4"]
[Thu Sep 17 15:27:18.700319 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mysql/.env"] [unique_id "aqxbNm65wm-f4uX16X6GCQAAABU"]
[Thu Sep 17 15:27:18.851256 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/postgres/.env"] [unique_id "aqxbNm65wm-f4uX16X6GEAAAACM"]
[Thu Sep 17 15:27:18.862925 2026] [security2:error] [pid 1029697:tid 1029849] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxbNm65wm-f4uX16X6GEgAAABY"]
[Thu Sep 17 15:27:18.876606 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.166.123.190:58222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbNm65wm-f4uX16X6GEwAAABQ"]
[Thu Sep 17 15:27:19.028767 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/mongodb/.env"] [unique_id "aqxbN265wm-f4uX16X6GFwAAAEk"]
[Thu Sep 17 15:27:19.029345 2026] [security2:error] [pid 1029697:tid 1029918] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxbN265wm-f4uX16X6GFgAAAFs"]
[Thu Sep 17 15:27:19.158717 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/redis/.env"] [unique_id "aqxbN265wm-f4uX16X6GHgAAABw"]
[Thu Sep 17 15:27:19.302468 2026] [security2:error] [pid 1029697:tid 1029832] [client 45.156.128.177:50670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxbN265wm-f4uX16X6GJwAAAAU"]
[Thu Sep 17 15:27:19.329025 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/elasticsearch/.env"] [unique_id "aqxbN265wm-f4uX16X6GKgAAAF0"]
[Thu Sep 17 15:27:19.352928 2026] [security2:error] [pid 1029697:tid 1029828] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxbN265wm-f4uX16X6GKwAAAAE"]
[Thu Sep 17 15:27:19.490892 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/rabbitmq/.env"] [unique_id "aqxbN265wm-f4uX16X6GLgAAAFY"]
[Thu Sep 17 15:27:19.572121 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.166.123.190:58224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/server-info.php"] [unique_id "aqxbN265wm-f4uX16X6GMwAAADA"]
[Thu Sep 17 15:27:19.662214 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/kafka/.env"] [unique_id "aqxbN265wm-f4uX16X6GNQAAAB0"]
[Thu Sep 17 15:27:19.846516 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/queue/.env"] [unique_id "aqxbN265wm-f4uX16X6GPQAAAGE"]
[Thu Sep 17 15:27:19.984236 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/worker/.env"] [unique_id "aqxbN265wm-f4uX16X6GRgAAACo"]
[Thu Sep 17 15:27:20.142597 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/job/.env"] [unique_id "aqxbOG65wm-f4uX16X6GTgAAAAk"]
[Thu Sep 17 15:27:20.249206 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.166.123.190:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/server-status.php"] [unique_id "aqxbOG65wm-f4uX16X6GVAAAAGg"]
[Thu Sep 17 15:27:20.269136 2026] [security2:error] [pid 1029697:tid 1029851] [client 169.241.60.108:34280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbOG65wm-f4uX16X6GTAAAGGc"], referer: https://endless-chronicles.com/
[Thu Sep 17 15:27:20.280958 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/test/.env"] [unique_id "aqxbOG65wm-f4uX16X6GWAAAAGI"]
[Thu Sep 17 15:27:20.428503 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/qa/.env"] [unique_id "aqxbOG65wm-f4uX16X6GXAAAAHM"]
[Thu Sep 17 15:27:20.567881 2026] [security2:error] [pid 1029697:tid 1029849] [client 20.255.75.24:1344] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "compassalpha.com"] [uri "/1.php"] [unique_id "aqxbOG65wm-f4uX16X6GYAAAABY"]
[Thu Sep 17 15:27:20.568003 2026] [security2:error] [pid 1029697:tid 1029849] [client 20.255.75.24:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/1.php"] [unique_id "aqxbOG65wm-f4uX16X6GYAAAABY"]
[Thu Sep 17 15:27:20.578152 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/preview/.env"] [unique_id "aqxbOG65wm-f4uX16X6GYgAAAGU"]
[Thu Sep 17 15:27:20.586635 2026] [security2:error] [pid 1029697:tid 1029881] [client 45.156.128.176:40514] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "aqxbOG65wm-f4uX16X6GYwAAADY"]
[Thu Sep 17 15:27:20.732593 2026] [security2:error] [pid 1029697:tid 1029864] [client 20.255.75.24:1369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/new.php"] [unique_id "aqxbOG65wm-f4uX16X6GZwAAACU"]
[Thu Sep 17 15:27:20.743789 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/beta/.env"] [unique_id "aqxbOG65wm-f4uX16X6GawAAAHQ"]
[Thu Sep 17 15:27:20.748609 2026] [security2:error] [pid 1029697:tid 1029867] [client 169.58.197.253:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxbOG65wm-f4uX16X6GbAAAACg"], referer: binance.com
[Thu Sep 17 15:27:20.871921 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/uat/.env"] [unique_id "aqxbOG65wm-f4uX16X6GcwAAAG0"]
[Thu Sep 17 15:27:20.995769 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/stage/.env"] [unique_id "aqxbOG65wm-f4uX16X6GdwAAAHw"]
[Thu Sep 17 15:27:21.137753 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/development/.env"] [unique_id "aqxbOW65wm-f4uX16X6GfAAAADk"]
[Thu Sep 17 15:27:21.205373 2026] [security2:error] [pid 1029697:tid 1029906] [client 20.255.75.24:1358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/num.php"] [unique_id "aqxbOW65wm-f4uX16X6GfwAAAE8"]
[Thu Sep 17 15:27:21.329855 2026] [security2:error] [pid 1029697:tid 1029897] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxbOW65wm-f4uX16X6GiAAAAEY"]
[Thu Sep 17 15:27:21.337188 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/production/.env"] [unique_id "aqxbOW65wm-f4uX16X6GigAAAAQ"]
[Thu Sep 17 15:27:21.358331 2026] [security2:error] [pid 1029697:tid 1029883] [client 104.207.33.33:17647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.stevearensberg.com"] [uri "/wp-content/plugins/wp-automatic/readme.txt"] [unique_id "aqxbOW65wm-f4uX16X6GjAAAADg"]
[Thu Sep 17 15:27:21.404728 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.166.123.190:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbOW65wm-f4uX16X6GjwAAAHg"]
[Thu Sep 17 15:27:21.434122 2026] [security2:error] [pid 1029697:tid 1029840] [client 4.240.114.86:56289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxbOW65wm-f4uX16X6GkQAAAA0"], referer: binance.com
[Thu Sep 17 15:27:21.439976 2026] [security2:error] [pid 1029697:tid 1029871] [client 114.198.138.124:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbOW65wm-f4uX16X6GkgAAACw"]
[Thu Sep 17 15:27:21.440066 2026] [security2:error] [pid 1029697:tid 1029871] [client 114.198.138.124:52822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbOW65wm-f4uX16X6GkgAAACw"]
[Thu Sep 17 15:27:21.474849 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.180.119.195:32822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal-release-website.24eastyard.com"] [uri "/config/app/.env"] [unique_id "aqxbOW65wm-f4uX16X6GlgAAABs"]
[Thu Sep 17 15:27:21.479880 2026] [security2:error] [pid 1029697:tid 1029896] [client 156.192.234.52:54364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbOW65wm-f4uX16X6GlwAAAEU"]
[Thu Sep 17 15:27:21.479987 2026] [security2:error] [pid 1029697:tid 1029896] [client 156.192.234.52:54364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbOW65wm-f4uX16X6GlwAAAEU"]
[Thu Sep 17 15:27:21.496167 2026] [security2:error] [pid 1029697:tid 1029834] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/.env~"] [unique_id "aqxbOW65wm-f4uX16X6GmAAAAAc"]
[Thu Sep 17 15:27:21.649898 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.180.119.195:32822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/phpinfo.php"] [unique_id "aqxbOW65wm-f4uX16X6GmwAAAEI"]
[Thu Sep 17 15:27:21.694512 2026] [fcgid:warn] [pid 1029697:tid 1029866] (70014)End of file found: [client 165.154.151.176:45270] mod_fcgid: can't get data from http client
[Thu Sep 17 15:27:21.876136 2026] [autoindex:error] [pid 1029697:tid 1029858] [client 20.255.75.24:0] AH01276: Cannot serve directory /home3/eglnkumy/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:27:22.051537 2026] [security2:error] [pid 1029697:tid 1029905] [client 20.255.75.24:1363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/admin.php"] [unique_id "aqxbOm65wm-f4uX16X6GuQAAAE4"]
[Thu Sep 17 15:27:22.111386 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.166.123.190:37170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbOm65wm-f4uX16X6GvAAAAFE"]
[Thu Sep 17 15:27:22.190493 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.180.119.195:38894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/info.php"] [unique_id "aqxbOm65wm-f4uX16X6GvwAAAEs"]
[Thu Sep 17 15:27:22.546070 2026] [security2:error] [pid 1029697:tid 1029874] [client 20.255.75.24:1366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/13.php"] [unique_id "aqxbOm65wm-f4uX16X6GywAAAC8"]
[Thu Sep 17 15:27:22.621850 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.180.119.195:38898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/php.php"] [unique_id "aqxbOm65wm-f4uX16X6GzQAAACA"]
[Thu Sep 17 15:27:22.796415 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.166.123.190:37178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbOm65wm-f4uX16X6G1gAAAFI"]
[Thu Sep 17 15:27:22.821076 2026] [security2:error] [pid 1029697:tid 1029850] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxbOm65wm-f4uX16X6G2AAAABc"]
[Thu Sep 17 15:27:22.990611 2026] [security2:error] [pid 1029697:tid 1029865] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxbOm65wm-f4uX16X6G3QAAACY"]
[Thu Sep 17 15:27:23.030226 2026] [security2:error] [pid 1029697:tid 1029932] [client 74.7.241.150:40202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.jazzsimpackages.pk"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxbO265wm-f4uX16X6G3gAAAGk"]
[Thu Sep 17 15:27:23.059728 2026] [security2:error] [pid 1029697:tid 1029938] [client 20.255.75.24:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/222.php"] [unique_id "aqxbO265wm-f4uX16X6G4QAAAG8"]
[Thu Sep 17 15:27:23.152701 2026] [security2:error] [pid 1029697:tid 1029838] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxbO265wm-f4uX16X6G5AAAAAs"]
[Thu Sep 17 15:27:23.159596 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.180.119.195:38906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/i.php"] [unique_id "aqxbO265wm-f4uX16X6G5QAAAHE"]
[Thu Sep 17 15:27:23.313773 2026] [security2:error] [pid 1029697:tid 1029858] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxbO265wm-f4uX16X6G7QAAAB8"]
[Thu Sep 17 15:27:23.473830 2026] [security2:error] [pid 1029697:tid 1029873] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxbO265wm-f4uX16X6G8gAAAC4"]
[Thu Sep 17 15:27:23.488201 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.166.123.190:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbO265wm-f4uX16X6G8wAAAFU"]
[Thu Sep 17 15:27:23.550392 2026] [security2:error] [pid 1029697:tid 1029894] [client 20.255.75.24:1373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/aa.php"] [unique_id "aqxbO265wm-f4uX16X6G9AAAAEM"]
[Thu Sep 17 15:27:23.605699 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.180.119.195:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/pi.php"] [unique_id "aqxbO265wm-f4uX16X6G9wAAABk"]
[Thu Sep 17 15:27:23.636432 2026] [security2:error] [pid 1029697:tid 1029928] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxbO265wm-f4uX16X6G-AAAAGU"]
[Thu Sep 17 15:27:23.837515 2026] [security2:error] [pid 1029697:tid 1029835] [client 136.158.61.34:26210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbO265wm-f4uX16X6HBQAAAAg"]
[Thu Sep 17 15:27:23.837694 2026] [security2:error] [pid 1029697:tid 1029835] [client 136.158.61.34:26210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbO265wm-f4uX16X6HBQAAAAg"]
[Thu Sep 17 15:27:23.962334 2026] [security2:error] [pid 1029697:tid 1029828] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxbO265wm-f4uX16X6HCAAAAAE"]
[Thu Sep 17 15:27:24.028551 2026] [security2:error] [pid 1029697:tid 1029900] [client 20.255.75.24:1356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/abcd.php"] [unique_id "aqxbPG65wm-f4uX16X6HCQAAAEk"]
[Thu Sep 17 15:27:24.115575 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.180.119.195:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/pinfo.php"] [unique_id "aqxbPG65wm-f4uX16X6HDAAAAGQ"]
[Thu Sep 17 15:27:24.124211 2026] [security2:error] [pid 1029697:tid 1029911] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxbPG65wm-f4uX16X6HDQAAAFQ"]
[Thu Sep 17 15:27:24.170488 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.166.123.190:37206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbPG65wm-f4uX16X6HEwAAAD4"]
[Thu Sep 17 15:27:24.171442 2026] [security2:error] [pid 1029697:tid 1029933] [client 216.244.66.228:52106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wisdomelders.com"] [uri "/ulprfx/b4j.php"] [unique_id "aqxbPG65wm-f4uX16X6HFQAAAGo"]
[Thu Sep 17 15:27:24.171529 2026] [security2:error] [pid 1029697:tid 1029933] [client 216.244.66.228:52106] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wisdomelders.com"] [uri "/ulprfx/b4j.php"] [unique_id "aqxbPG65wm-f4uX16X6HFQAAAGo"]
[Thu Sep 17 15:27:24.284174 2026] [security2:error] [pid 1029697:tid 1029916] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxbPG65wm-f4uX16X6HHgAAAFk"]
[Thu Sep 17 15:27:24.331858 2026] [security2:error] [pid 1029697:tid 1029884] [client 185.55.149.49:52753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbPG65wm-f4uX16X6HIAAAADk"]
[Thu Sep 17 15:27:24.331942 2026] [security2:error] [pid 1029697:tid 1029884] [client 185.55.149.49:52753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbPG65wm-f4uX16X6HIAAAADk"]
[Thu Sep 17 15:27:24.387601 2026] [security2:error] [pid 1029697:tid 1029846] [client 73.246.5.171:43395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbPG65wm-f4uX16X6HHAAAE2Y"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:27:24.444357 2026] [security2:error] [pid 1029697:tid 1029854] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxbPG65wm-f4uX16X6HIgAAABs"]
[Thu Sep 17 15:27:24.511230 2026] [security2:error] [pid 1029697:tid 1029871] [client 20.255.75.24:1355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/about.php"] [unique_id "aqxbPG65wm-f4uX16X6HIwAAACw"]
[Thu Sep 17 15:27:24.585255 2026] [security2:error] [pid 1029697:tid 1029865] [client 4.240.114.86:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxbPG65wm-f4uX16X6HJwAAACY"], referer: binance.com
[Thu Sep 17 15:27:24.610730 2026] [security2:error] [pid 1029697:tid 1029940] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxbPG65wm-f4uX16X6HKwAAAHE"]
[Thu Sep 17 15:27:24.630236 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.180.119.195:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/test.php"] [unique_id "aqxbPG65wm-f4uX16X6HLAAAAEo"]
[Thu Sep 17 15:27:24.751776 2026] [security2:error] [pid 1029697:tid 1029893] [client 57.141.14.26:56852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxbPG65wm-f4uX16X6HJQAAQn0"]
[Thu Sep 17 15:27:24.771357 2026] [security2:error] [pid 1029697:tid 1029843] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxbPG65wm-f4uX16X6HMwAAABA"]
[Thu Sep 17 15:27:24.870682 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.166.123.190:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbPG65wm-f4uX16X6HOAAAAAc"]
[Thu Sep 17 15:27:24.933375 2026] [security2:error] [pid 1029697:tid 1029930] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxbPG65wm-f4uX16X6HOgAAAGc"]
[Thu Sep 17 15:27:24.981342 2026] [security2:error] [pid 1029697:tid 1029919] [client 20.255.75.24:1382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/admin.php"] [unique_id "aqxbPG65wm-f4uX16X6HPAAAAFw"]
[Thu Sep 17 15:27:25.096508 2026] [security2:error] [pid 1029697:tid 1029912] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxbPW65wm-f4uX16X6HPwAAAFU"]
[Thu Sep 17 15:27:25.182353 2026] [core:error] [pid 1029697:tid 1029922] [client 34.180.119.195:38944] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:25.182370 2026] [core:error] [pid 1029697:tid 1029922] [client 34.180.119.195:38944] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:25.261548 2026] [security2:error] [pid 1029697:tid 1029907] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxbPW65wm-f4uX16X6HRQAAAFA"]
[Thu Sep 17 15:27:25.423835 2026] [security2:error] [pid 1029697:tid 1029867] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxbPW65wm-f4uX16X6HTAAAACg"]
[Thu Sep 17 15:27:25.496619 2026] [security2:error] [pid 1029697:tid 1029908] [client 20.255.75.24:1345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/adminfuns.php"] [unique_id "aqxbPW65wm-f4uX16X6HTwAAAFE"]
[Thu Sep 17 15:27:25.543630 2026] [security2:error] [pid 1029697:tid 1029894] [client 210.222.43.21:50296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbPW65wm-f4uX16X6HSQAAAEM"], referer: http://talent-in-borders.com/Shop
[Thu Sep 17 15:27:25.573176 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.166.123.190:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbPW65wm-f4uX16X6HVgAAAAg"]
[Thu Sep 17 15:27:25.591359 2026] [security2:error] [pid 1029697:tid 1029898] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxbPW65wm-f4uX16X6HVwAAAEc"]
[Thu Sep 17 15:27:25.604970 2026] [security2:error] [pid 1029697:tid 1029882] [client 73.246.5.171:45535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbPW65wm-f4uX16X6HUgAANwk"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821140930&hideanons=1&hidebots=0&hidemyself=1&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:27:25.620784 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.180.119.195:38956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/p.php"] [unique_id "aqxbPW65wm-f4uX16X6HWAAAADs"]
[Thu Sep 17 15:27:25.758933 2026] [security2:error] [pid 1029697:tid 1029890] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxbPW65wm-f4uX16X6HXgAAAD8"]
[Thu Sep 17 15:27:25.926311 2026] [security2:error] [pid 1029697:tid 1029831] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxbPW65wm-f4uX16X6HZQAAAAQ"]
[Thu Sep 17 15:27:26.016695 2026] [security2:error] [pid 1029697:tid 1029906] [client 20.255.75.24:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxbPm65wm-f4uX16X6HaAAAAE8"]
[Thu Sep 17 15:27:26.068107 2026] [proxy:warn] [pid 1029697:tid 1029874] [client 18.116.101.220:41512] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be trcco.org for uri /400.shtml
[Thu Sep 17 15:27:26.090374 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.180.119.195:46906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/debug.php"] [unique_id "aqxbPm65wm-f4uX16X6HbAAAABU"]
[Thu Sep 17 15:27:26.093870 2026] [security2:error] [pid 1029697:tid 1029854] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxbPm65wm-f4uX16X6HbQAAABs"]
[Thu Sep 17 15:27:26.261687 2026] [security2:error] [pid 1029697:tid 1029830] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxbPm65wm-f4uX16X6HdwAAAAM"]
[Thu Sep 17 15:27:26.274415 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.166.123.190:37238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbPm65wm-f4uX16X6HegAAADU"]
[Thu Sep 17 15:27:26.429980 2026] [security2:error] [pid 1029697:tid 1029833] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxbPm65wm-f4uX16X6HhAAAAAY"]
[Thu Sep 17 15:27:26.522374 2026] [security2:error] [pid 1029697:tid 1029932] [client 20.255.75.24:1372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/ae.php"] [unique_id "aqxbPm65wm-f4uX16X6HigAAAGk"]
[Thu Sep 17 15:27:26.555947 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.180.119.195:46914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbPm65wm-f4uX16X6HiwAAAHA"]
[Thu Sep 17 15:27:26.595980 2026] [security2:error] [pid 1029697:tid 1029912] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxbPm65wm-f4uX16X6HjQAAAFU"]
[Thu Sep 17 15:27:26.760183 2026] [security2:error] [pid 1029697:tid 1029845] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxbPm65wm-f4uX16X6HlgAAABI"]
[Thu Sep 17 15:27:26.946958 2026] [security2:error] [pid 1029697:tid 1029890] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxbPm65wm-f4uX16X6HngAAAD8"]
[Thu Sep 17 15:27:26.968414 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.166.123.190:37248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/phpinfo.php~"] [unique_id "aqxbPm65wm-f4uX16X6HoAAAAC4"]
[Thu Sep 17 15:27:27.023266 2026] [security2:error] [pid 1029697:tid 1029878] [client 20.255.75.24:1365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/akcc.php"] [unique_id "aqxbP265wm-f4uX16X6HogAAADM"]
[Thu Sep 17 15:27:27.065889 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.180.119.195:46926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbP265wm-f4uX16X6HqQAAAEs"]
[Thu Sep 17 15:27:27.107491 2026] [security2:error] [pid 1029697:tid 1029850] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxbP265wm-f4uX16X6HqwAAABc"]
[Thu Sep 17 15:27:27.268707 2026] [security2:error] [pid 1029697:tid 1029929] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxbP265wm-f4uX16X6HtAAAAGY"]
[Thu Sep 17 15:27:27.430733 2026] [security2:error] [pid 1029697:tid 1029906] [client 143.244.57.120:45062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxbP265wm-f4uX16X6HugAAAE8"]
[Thu Sep 17 15:27:27.431332 2026] [security2:error] [pid 1029697:tid 1029836] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxbP265wm-f4uX16X6HuQAAAAk"]
[Thu Sep 17 15:27:27.453888 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/.env"] [unique_id "aqxbP265wm-f4uX16X6HvAAAAF0"]
[Thu Sep 17 15:27:27.480233 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.180.119.195:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbP265wm-f4uX16X6HvgAAAGE"]
[Thu Sep 17 15:27:27.500862 2026] [security2:error] [pid 1029697:tid 1029927] [client 20.255.75.24:1354] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "athikerrev.com"] [uri "/1.php"] [unique_id "aqxbP265wm-f4uX16X6HvwAAAGQ"]
[Thu Sep 17 15:27:27.500987 2026] [security2:error] [pid 1029697:tid 1029927] [client 20.255.75.24:1354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/1.php"] [unique_id "aqxbP265wm-f4uX16X6HvwAAAGQ"]
[Thu Sep 17 15:27:27.517269 2026] [security2:error] [pid 1029697:tid 1029940] [client 20.255.75.24:1381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/bak.php"] [unique_id "aqxbP265wm-f4uX16X6HwQAAAHE"]
[Thu Sep 17 15:27:27.591966 2026] [security2:error] [pid 1029697:tid 1029930] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxbP265wm-f4uX16X6HxQAAAGc"]
[Thu Sep 17 15:27:27.597048 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.122.173.216:6384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxbP265wm-f4uX16X6HuwAAEBE"]
[Thu Sep 17 15:27:27.626125 2026] [security2:error] [pid 1029697:tid 1029856] [client 18.116.101.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxbPm65wm-f4uX16X6HbwAAAB0"]
[Thu Sep 17 15:27:27.626153 2026] [security2:error] [pid 1029697:tid 1029856] [client 18.116.101.220:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxbPm65wm-f4uX16X6HbwAAAB0"]
[Thu Sep 17 15:27:27.655171 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.166.123.190:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/info.php.bak"] [unique_id "aqxbP265wm-f4uX16X6HywAAACc"]
[Thu Sep 17 15:27:27.679174 2026] [security2:error] [pid 1029697:tid 1029912] [client 20.255.75.24:1347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/new.php"] [unique_id "aqxbP265wm-f4uX16X6HzQAAAFU"]
[Thu Sep 17 15:27:27.701027 2026] [security2:error] [pid 1029697:tid 1029874] [client 18.116.101.220:41512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/400.shtml"] [unique_id "aqxbPm65wm-f4uX16X6HagAAAC8"]
[Thu Sep 17 15:27:27.748815 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.122.173.216:6384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxbP265wm-f4uX16X6HygAAXlc"]
[Thu Sep 17 15:27:27.755799 2026] [security2:error] [pid 1029697:tid 1029944] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxbP265wm-f4uX16X6H0AAAAHU"]
[Thu Sep 17 15:27:27.791841 2026] [security2:error] [pid 1029697:tid 1029908] [client 4.240.114.86:61225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxbP265wm-f4uX16X6H0wAAAFE"], referer: binance.com
[Thu Sep 17 15:27:27.894334 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.180.119.195:46946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbP265wm-f4uX16X6H2wAAAGg"]
[Thu Sep 17 15:27:27.924082 2026] [security2:error] [pid 1029697:tid 1029837] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxbP265wm-f4uX16X6H3AAAAAo"]
[Thu Sep 17 15:27:27.967750 2026] [security2:error] [pid 1029697:tid 1029834] [client 103.61.184.148:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbP265wm-f4uX16X6H3wAAAAc"]
[Thu Sep 17 15:27:27.968797 2026] [security2:error] [pid 1029697:tid 1029834] [client 103.61.184.148:49629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbP265wm-f4uX16X6H3wAAAAc"]
[Thu Sep 17 15:27:28.034502 2026] [security2:error] [pid 1029697:tid 1029882] [client 20.255.75.24:1395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/cc.php"] [unique_id "aqxbQG65wm-f4uX16X6H4wAAADc"]
[Thu Sep 17 15:27:28.052991 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.122.173.216:6384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxbP265wm-f4uX16X6H3gAAWxw"]
[Thu Sep 17 15:27:28.089824 2026] [security2:error] [pid 1029697:tid 1029903] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxbQG65wm-f4uX16X6H5wAAAEw"]
[Thu Sep 17 15:27:28.093341 2026] [security2:error] [pid 1029697:tid 1029915] [client 143.244.57.120:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globaldove.org"] [uri "/xmlrpc.php"] [unique_id "aqxbQG65wm-f4uX16X6H5gAAAFg"]
[Thu Sep 17 15:27:28.209523 2026] [security2:error] [pid 1029697:tid 1029928] [client 20.255.75.24:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/num.php"] [unique_id "aqxbQG65wm-f4uX16X6H6wAAAGU"]
[Thu Sep 17 15:27:28.250657 2026] [security2:error] [pid 1029697:tid 1029897] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxbQG65wm-f4uX16X6H8QAAAEY"]
[Thu Sep 17 15:27:28.335736 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.166.123.190:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbQG65wm-f4uX16X6H9AAAAAg"]
[Thu Sep 17 15:27:28.338822 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.180.119.195:46962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbQG65wm-f4uX16X6H9QAAADA"]
[Thu Sep 17 15:27:28.416100 2026] [security2:error] [pid 1029697:tid 1029853] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxbQG65wm-f4uX16X6H9wAAABo"]
[Thu Sep 17 15:27:28.540192 2026] [security2:error] [pid 1029697:tid 1029909] [client 20.255.75.24:1371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/chosen.php"] [unique_id "aqxbQG65wm-f4uX16X6H_wAAAFI"]
[Thu Sep 17 15:27:28.576704 2026] [security2:error] [pid 1029697:tid 1029846] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxbQG65wm-f4uX16X6IAAAAABM"]
[Thu Sep 17 15:27:28.674951 2026] [security2:error] [pid 1029697:tid 1029951] [client 143.244.57.120:1925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxbQG65wm-f4uX16X6IBwAAAHw"]
[Thu Sep 17 15:27:28.733414 2026] [autoindex:error] [pid 1029697:tid 1029877] [client 20.255.75.24:0] AH01276: Cannot serve directory /home1/wxxngamy/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:27:28.734405 2026] [security2:error] [pid 1029697:tid 1029842] [client 185.226.198.4:54610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbQG65wm-f4uX16X6H_AAAAA8"]
[Thu Sep 17 15:27:28.736371 2026] [security2:error] [pid 1029697:tid 1029876] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxbQG65wm-f4uX16X6ICwAAADE"]
[Thu Sep 17 15:27:28.744337 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.180.119.195:46968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbQG65wm-f4uX16X6IDAAAAAM"]
[Thu Sep 17 15:27:28.835948 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/.env.bak"] [unique_id "aqxbQG65wm-f4uX16X6IEgAAAGI"]
[Thu Sep 17 15:27:28.893445 2026] [security2:error] [pid 1029697:tid 1029856] [client 20.255.75.24:1403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/admin.php"] [unique_id "aqxbQG65wm-f4uX16X6IFAAAAB0"]
[Thu Sep 17 15:27:28.896850 2026] [security2:error] [pid 1029697:tid 1029919] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxbQG65wm-f4uX16X6IFgAAAFw"]
[Thu Sep 17 15:27:28.960126 2026] [security2:error] [pid 1029697:tid 1029901] [client 185.226.198.4:54614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbQG65wm-f4uX16X6IEwAAAEo"]
[Thu Sep 17 15:27:28.991320 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/.env.backup"] [unique_id "aqxbQG65wm-f4uX16X6IGQAAACQ"]
[Thu Sep 17 15:27:29.024128 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.166.123.190:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbQW65wm-f4uX16X6IGwAAAHE"]
[Thu Sep 17 15:27:29.034757 2026] [security2:error] [pid 1029697:tid 1029934] [client 20.255.75.24:1390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/classwithtostring.php"] [unique_id "aqxbQW65wm-f4uX16X6IHAAAAGs"]
[Thu Sep 17 15:27:29.057012 2026] [security2:error] [pid 1029697:tid 1029874] [client 35.198.3.220:46766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxbQW65wm-f4uX16X6IHgAAAC8"]
[Thu Sep 17 15:27:29.233922 2026] [core:error] [pid 1029697:tid 1029896] [client 34.180.119.195:46976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:29.233942 2026] [core:error] [pid 1029697:tid 1029896] [client 34.180.119.195:46976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:29.308256 2026] [security2:error] [pid 1029697:tid 1029912] [client 143.244.57.120:45090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxbQW65wm-f4uX16X6IKQAAAFU"]
[Thu Sep 17 15:27:29.348962 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/.env.old"] [unique_id "aqxbQW65wm-f4uX16X6IKgAAADs"]
[Thu Sep 17 15:27:29.387140 2026] [security2:error] [pid 1029697:tid 1029910] [client 20.255.75.24:1396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/13.php"] [unique_id "aqxbQW65wm-f4uX16X6ILQAAAFM"]
[Thu Sep 17 15:27:29.536992 2026] [security2:error] [pid 1029697:tid 1029837] [client 20.255.75.24:1378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/wp-signup.php"] [unique_id "aqxbQW65wm-f4uX16X6INQAAAAo"]
[Thu Sep 17 15:27:29.544145 2026] [security2:error] [pid 1029697:tid 1029870] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxbQW65wm-f4uX16X6INgAAACs"]
[Thu Sep 17 15:27:29.699433 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.180.119.195:46988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/php-info.php"] [unique_id "aqxbQW65wm-f4uX16X6IOQAAAGo"]
[Thu Sep 17 15:27:29.711621 2026] [security2:error] [pid 1029697:tid 1029897] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxbQW65wm-f4uX16X6IOgAAAEY"]
[Thu Sep 17 15:27:29.721179 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.166.123.190:37282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbQW65wm-f4uX16X6IQAAAABY"]
[Thu Sep 17 15:27:29.882840 2026] [security2:error] [pid 1029697:tid 1029871] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxbQW65wm-f4uX16X6IRgAAACw"]
[Thu Sep 17 15:27:29.901338 2026] [security2:error] [pid 1029697:tid 1029881] [client 20.255.75.24:1357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/222.php"] [unique_id "aqxbQW65wm-f4uX16X6IRwAAADY"]
[Thu Sep 17 15:27:29.929239 2026] [security2:error] [pid 1029697:tid 1029928] [client 143.244.57.120:45098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxbQW65wm-f4uX16X6ISwAAAGU"]
[Thu Sep 17 15:27:29.929508 2026] [security2:error] [pid 1029697:tid 1029953] [client 104.207.33.33:32205] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.stevearensberg.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxbQW65wm-f4uX16X6ITAAAAH4"]
[Thu Sep 17 15:27:30.026928 2026] [authz_core:error] [pid 1029697:tid 1029911] [client 40.81.232.68:59915] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:27:30.042138 2026] [security2:error] [pid 1029697:tid 1029877] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxbQm65wm-f4uX16X6IUwAAADI"]
[Thu Sep 17 15:27:30.056104 2026] [security2:error] [pid 1029697:tid 1029855] [client 20.255.75.24:1380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/doc.php"] [unique_id "aqxbQm65wm-f4uX16X6IVAAAABw"]
[Thu Sep 17 15:27:30.185596 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.180.119.195:47004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/phpversion.php"] [unique_id "aqxbQm65wm-f4uX16X6IXwAAAH8"]
[Thu Sep 17 15:27:30.191762 2026] [autoindex:error] [pid 1029697:tid 1029932] [client 165.154.151.176:0] AH01276: Cannot serve directory /home1/sdkfwxmy/public_html/womenscubofpowell.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://sdk.fwx.mybluehost.me/
[Thu Sep 17 15:27:30.202153 2026] [security2:error] [pid 1029697:tid 1029866] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxbQm65wm-f4uX16X6IYAAAACc"]
[Thu Sep 17 15:27:30.362248 2026] [security2:error] [pid 1029697:tid 1029857] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxbQm65wm-f4uX16X6IagAAAB4"]
[Thu Sep 17 15:27:30.375153 2026] [security2:error] [pid 1029697:tid 1029891] [client 20.255.75.24:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/aa.php"] [unique_id "aqxbQm65wm-f4uX16X6IawAAAEA"]
[Thu Sep 17 15:27:30.395899 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.166.123.190:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbQm65wm-f4uX16X6IbAAAAFw"]
[Thu Sep 17 15:27:30.406512 2026] [security2:error] [pid 1029697:tid 1029845] [client 169.58.197.253:61616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/icons.php"] [unique_id "aqxbQm65wm-f4uX16X6IbQAAABI"], referer: binance.com
[Thu Sep 17 15:27:30.523284 2026] [security2:error] [pid 1029697:tid 1029894] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxbQm65wm-f4uX16X6IcwAAAEM"]
[Thu Sep 17 15:27:30.541858 2026] [security2:error] [pid 1029697:tid 1029946] [client 143.244.57.120:60356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxbQm65wm-f4uX16X6IdAAAAHc"]
[Thu Sep 17 15:27:30.552383 2026] [security2:error] [pid 1029697:tid 1029921] [client 20.255.75.24:1368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/edit.php"] [unique_id "aqxbQm65wm-f4uX16X6IdgAAAF4"]
[Thu Sep 17 15:27:30.585932 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.180.119.195:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/_phpinfo.php"] [unique_id "aqxbQm65wm-f4uX16X6IdwAAAA0"]
[Thu Sep 17 15:27:30.597395 2026] [security2:error] [pid 1029697:tid 1029939] [client 4.240.114.86:63347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxbQm65wm-f4uX16X6IeAAAAHA"], referer: binance.com
[Thu Sep 17 15:27:30.684878 2026] [security2:error] [pid 1029697:tid 1029950] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxbQm65wm-f4uX16X6IegAAAHs"]
[Thu Sep 17 15:27:30.845085 2026] [security2:error] [pid 1029697:tid 1029849] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxbQm65wm-f4uX16X6IhQAAABY"]
[Thu Sep 17 15:27:30.889888 2026] [security2:error] [pid 1029697:tid 1029898] [client 20.255.75.24:1359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/abcd.php"] [unique_id "aqxbQm65wm-f4uX16X6IhgAAAEc"]
[Thu Sep 17 15:27:31.009547 2026] [security2:error] [pid 1029697:tid 1029829] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxbQ265wm-f4uX16X6IjAAAAAI"]
[Thu Sep 17 15:27:31.043871 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.180.119.195:47020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbQ265wm-f4uX16X6IjgAAAAQ"]
[Thu Sep 17 15:27:31.048321 2026] [security2:error] [pid 1029697:tid 1029835] [client 20.255.75.24:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/worksec.php"] [unique_id "aqxbQ265wm-f4uX16X6IjwAAAAg"]
[Thu Sep 17 15:27:31.101489 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.166.123.190:37302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbQ265wm-f4uX16X6IkAAAAGA"]
[Thu Sep 17 15:27:31.173224 2026] [security2:error] [pid 1029697:tid 1029916] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxbQ265wm-f4uX16X6ImAAAAFk"]
[Thu Sep 17 15:27:31.182382 2026] [security2:error] [pid 1029697:tid 1029869] [client 143.244.57.120:60370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxbQ265wm-f4uX16X6ImQAAACo"]
[Thu Sep 17 15:27:31.336469 2026] [security2:error] [pid 1029697:tid 1029842] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxbQ265wm-f4uX16X6InwAAAA8"]
[Thu Sep 17 15:27:31.399503 2026] [security2:error] [pid 1029697:tid 1029953] [client 20.255.75.24:1384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/about.php"] [unique_id "aqxbQ265wm-f4uX16X6IowAAAH4"]
[Thu Sep 17 15:27:31.499043 2026] [security2:error] [pid 1029697:tid 1029828] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxbQ265wm-f4uX16X6IpgAAAAE"]
[Thu Sep 17 15:27:31.504579 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.180.119.195:47024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/server-info.php"] [unique_id "aqxbQ265wm-f4uX16X6IqQAAAEI"]
[Thu Sep 17 15:27:31.531774 2026] [security2:error] [pid 1029697:tid 1029920] [client 20.255.75.24:1367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/ultra.php"] [unique_id "aqxbQ265wm-f4uX16X6IqgAAAF0"]
[Thu Sep 17 15:27:31.659096 2026] [security2:error] [pid 1029697:tid 1029866] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxbQ265wm-f4uX16X6IsQAAACc"]
[Thu Sep 17 15:27:31.666697 2026] [security2:error] [pid 1029697:tid 1029904] [client 5.189.145.112:65476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiansoncampusnlc.com"] [uri "/index.php"] [unique_id "aqxbQ265wm-f4uX16X6IkQAAAE0"], referer: binance.com
[Thu Sep 17 15:27:31.752129 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/.env.swp"] [unique_id "aqxbQ265wm-f4uX16X6ItQAAAC8"]
[Thu Sep 17 15:27:31.786901 2026] [security2:error] [pid 1029697:tid 1029843] [client 143.244.57.120:60372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxbQ265wm-f4uX16X6IuAAAABA"]
[Thu Sep 17 15:27:31.787349 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.166.123.190:41464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbQ265wm-f4uX16X6IuQAAAH8"]
[Thu Sep 17 15:27:31.818940 2026] [security2:error] [pid 1029697:tid 1029891] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxbQ265wm-f4uX16X6IugAAAEA"]
[Thu Sep 17 15:27:31.901784 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.180.119.195:47038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/server-status.php"] [unique_id "aqxbQ265wm-f4uX16X6IvQAAAGs"]
[Thu Sep 17 15:27:31.911161 2026] [security2:error] [pid 1029697:tid 1029852] [client 20.255.75.24:1394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/admin.php"] [unique_id "aqxbQ265wm-f4uX16X6IvgAAABk"]
[Thu Sep 17 15:27:31.917669 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/.env~"] [unique_id "aqxbQ265wm-f4uX16X6IvwAAAAA"]
[Thu Sep 17 15:27:31.981792 2026] [security2:error] [pid 1029697:tid 1029931] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxbQ265wm-f4uX16X6IwQAAAGg"]
[Thu Sep 17 15:27:32.033472 2026] [security2:error] [pid 1029697:tid 1029924] [client 20.255.75.24:1370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/gecko.php"] [unique_id "aqxbRG65wm-f4uX16X6IwgAAAGE"]
[Thu Sep 17 15:27:32.035385 2026] [security2:error] [pid 1029697:tid 1029847] [client 156.192.234.52:54980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbRG65wm-f4uX16X6IwwAAABQ"]
[Thu Sep 17 15:27:32.038411 2026] [security2:error] [pid 1029697:tid 1029847] [client 156.192.234.52:54980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbRG65wm-f4uX16X6IwwAAABQ"]
[Thu Sep 17 15:27:32.141503 2026] [security2:error] [pid 1029697:tid 1029900] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxbRG65wm-f4uX16X6IygAAAEk"]
[Thu Sep 17 15:27:32.226636 2026] [security2:error] [pid 1029697:tid 1029910] [client 114.198.138.124:53469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbRG65wm-f4uX16X6IzgAAAFM"]
[Thu Sep 17 15:27:32.227084 2026] [security2:error] [pid 1029697:tid 1029910] [client 114.198.138.124:53469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbRG65wm-f4uX16X6IzgAAAFM"]
[Thu Sep 17 15:27:32.306084 2026] [security2:error] [pid 1029697:tid 1029849] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxbRG65wm-f4uX16X6I1AAAABY"]
[Thu Sep 17 15:27:32.319751 2026] [security2:error] [pid 1029697:tid 1029905] [client 125.234.209.241:38854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbRG65wm-f4uX16X6IzAAATig"]
[Thu Sep 17 15:27:32.368901 2026] [security2:error] [pid 1029697:tid 1029935] [client 143.244.57.120:60384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxbRG65wm-f4uX16X6I1gAAAGw"]
[Thu Sep 17 15:27:32.402792 2026] [security2:error] [pid 1029697:tid 1029943] [client 20.255.75.24:1374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/adminfuns.php"] [unique_id "aqxbRG65wm-f4uX16X6I2QAAAHQ"]
[Thu Sep 17 15:27:32.431879 2026] [core:error] [pid 1029697:tid 1029897] [client 34.180.119.195:47052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:32.431897 2026] [core:error] [pid 1029697:tid 1029897] [client 34.180.119.195:47052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:32.467940 2026] [security2:error] [pid 1029697:tid 1029889] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxbRG65wm-f4uX16X6I3AAAAD4"]
[Thu Sep 17 15:27:32.477441 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.166.123.190:41478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbRG65wm-f4uX16X6I3QAAAH0"]
[Thu Sep 17 15:27:32.530241 2026] [security2:error] [pid 1029697:tid 1029918] [client 20.255.75.24:1349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/goods.php"] [unique_id "aqxbRG65wm-f4uX16X6I4gAAAFs"]
[Thu Sep 17 15:27:32.628123 2026] [security2:error] [pid 1029697:tid 1029909] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxbRG65wm-f4uX16X6I5QAAAFI"]
[Thu Sep 17 15:27:32.790054 2026] [security2:error] [pid 1029697:tid 1029879] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxbRG65wm-f4uX16X6I8AAAADQ"]
[Thu Sep 17 15:27:32.895471 2026] [security2:error] [pid 1029697:tid 1029913] [client 20.255.75.24:1379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "aqxbRG65wm-f4uX16X6I9QAAAFY"]
[Thu Sep 17 15:27:32.956226 2026] [security2:error] [pid 1029697:tid 1029914] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxbRG65wm-f4uX16X6I-wAAAFc"]
[Thu Sep 17 15:27:32.969931 2026] [security2:error] [pid 1029697:tid 1029877] [client 143.244.57.120:60398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxbRG65wm-f4uX16X6I_AAAADI"]
[Thu Sep 17 15:27:32.990300 2026] [core:error] [pid 1029697:tid 1029911] [client 34.180.119.195:47056] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:32.990320 2026] [core:error] [pid 1029697:tid 1029911] [client 34.180.119.195:47056] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:32.995063 2026] [core:error] [pid 1029697:tid 1029940] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:32.995078 2026] [core:error] [pid 1029697:tid 1029940] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:33.048072 2026] [security2:error] [pid 1029697:tid 1029833] [client 20.255.75.24:1386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/man.php"] [unique_id "aqxbRW65wm-f4uX16X6JAQAAAAY"]
[Thu Sep 17 15:27:33.117286 2026] [security2:error] [pid 1029697:tid 1029852] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxbRW65wm-f4uX16X6JBgAAABk"]
[Thu Sep 17 15:27:33.171619 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.166.123.190:41480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbRW65wm-f4uX16X6JCAAAAE0"]
[Thu Sep 17 15:27:33.254396 2026] [security2:error] [pid 1029697:tid 1029841] [client 104.238.222.26:63264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stoneofxavier.com"] [uri "/wp-login.php"] [unique_id "aqxbRW65wm-f4uX16X6JCQAAAA4"]
[Thu Sep 17 15:27:33.282696 2026] [security2:error] [pid 1029697:tid 1029847] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxbRW65wm-f4uX16X6JDQAAABQ"]
[Thu Sep 17 15:27:33.370765 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.180.119.195:47060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbRW65wm-f4uX16X6JFQAAABE"]
[Thu Sep 17 15:27:33.400799 2026] [security2:error] [pid 1029697:tid 1029872] [client 20.255.75.24:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/ae.php"] [unique_id "aqxbRW65wm-f4uX16X6JGQAAAC0"]
[Thu Sep 17 15:27:33.447107 2026] [security2:error] [pid 1029697:tid 1029899] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxbRW65wm-f4uX16X6JGgAAAEg"]
[Thu Sep 17 15:27:33.508528 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/app/.env"] [unique_id "aqxbRW65wm-f4uX16X6JHAAAAFM"]
[Thu Sep 17 15:27:33.532654 2026] [security2:error] [pid 1029697:tid 1029851] [client 20.255.75.24:1398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/wp-settings.php"] [unique_id "aqxbRW65wm-f4uX16X6JHQAAABg"]
[Thu Sep 17 15:27:33.612130 2026] [security2:error] [pid 1029697:tid 1029949] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxbRW65wm-f4uX16X6JIAAAAHo"]
[Thu Sep 17 15:27:33.649682 2026] [security2:error] [pid 1029697:tid 1029944] [client 143.244.57.120:60404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxbRW65wm-f4uX16X6JIwAAAHU"]
[Thu Sep 17 15:27:33.679614 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/apps/.env"] [unique_id "aqxbRW65wm-f4uX16X6JJAAAAEs"]
[Thu Sep 17 15:27:33.776738 2026] [security2:error] [pid 1029697:tid 1029941] [client 185.226.198.5:32648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbRW65wm-f4uX16X6JHwAAAHI"]
[Thu Sep 17 15:27:33.777609 2026] [security2:error] [pid 1029697:tid 1029837] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxbRW65wm-f4uX16X6JKQAAAAo"]
[Thu Sep 17 15:27:33.840514 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/api/.env"] [unique_id "aqxbRW65wm-f4uX16X6JKwAAAD8"]
[Thu Sep 17 15:27:33.848958 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.180.119.195:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbRW65wm-f4uX16X6JLQAAADU"]
[Thu Sep 17 15:27:33.880937 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.166.123.190:41494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbRW65wm-f4uX16X6JLwAAAFg"]
[Thu Sep 17 15:27:33.902786 2026] [security2:error] [pid 1029697:tid 1029850] [client 20.255.75.24:1376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/akcc.php"] [unique_id "aqxbRW65wm-f4uX16X6JMAAAABc"]
[Thu Sep 17 15:27:33.942958 2026] [security2:error] [pid 1029697:tid 1029923] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxbRW65wm-f4uX16X6JMgAAAGA"]
[Thu Sep 17 15:27:33.997873 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/web/.env"] [unique_id "aqxbRW65wm-f4uX16X6JNAAAAFk"]
[Thu Sep 17 15:27:34.027974 2026] [security2:error] [pid 1029697:tid 1029889] [client 20.255.75.24:1392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/k.php"] [unique_id "aqxbRm65wm-f4uX16X6JNQAAAD4"]
[Thu Sep 17 15:27:34.080270 2026] [security2:error] [pid 1029697:tid 1029875] [client 185.226.198.7:22954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbRW65wm-f4uX16X6JMQAAADA"]
[Thu Sep 17 15:27:34.105882 2026] [security2:error] [pid 1029697:tid 1029863] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxbRm65wm-f4uX16X6JNwAAACQ"]
[Thu Sep 17 15:27:34.156832 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/site/.env"] [unique_id "aqxbRm65wm-f4uX16X6JOQAAAAk"]
[Thu Sep 17 15:27:34.279800 2026] [security2:error] [pid 1029697:tid 1029893] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxbRm65wm-f4uX16X6JPgAAAEI"]
[Thu Sep 17 15:27:34.315355 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/public/.env"] [unique_id "aqxbRm65wm-f4uX16X6JPwAAAF0"]
[Thu Sep 17 15:27:34.315364 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.180.119.195:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbRm65wm-f4uX16X6JQAAAAHk"]
[Thu Sep 17 15:27:34.376245 2026] [security2:error] [pid 1029697:tid 1029928] [client 143.244.57.120:60410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxbRm65wm-f4uX16X6JQwAAAGU"]
[Thu Sep 17 15:27:34.405577 2026] [security2:error] [pid 1029697:tid 1029887] [client 185.226.198.6:11374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbRm65wm-f4uX16X6JPQAAADw"]
[Thu Sep 17 15:27:34.411583 2026] [security2:error] [pid 1029697:tid 1029914] [client 4.240.114.86:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxbRm65wm-f4uX16X6JRQAAAFc"], referer: binance.com
[Thu Sep 17 15:27:34.415360 2026] [security2:error] [pid 1029697:tid 1029828] [client 20.255.75.24:1399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/bak.php"] [unique_id "aqxbRm65wm-f4uX16X6JRgAAAAE"]
[Thu Sep 17 15:27:34.440603 2026] [security2:error] [pid 1029697:tid 1029877] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxbRm65wm-f4uX16X6JRwAAADI"]
[Thu Sep 17 15:27:34.555499 2026] [security2:error] [pid 1029697:tid 1029906] [client 20.255.75.24:1352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/autoload_classmap.php"] [unique_id "aqxbRm65wm-f4uX16X6JUAAAAE8"]
[Thu Sep 17 15:27:34.563189 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.166.123.190:41502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbRm65wm-f4uX16X6JUgAAAGk"]
[Thu Sep 17 15:27:34.573027 2026] [security2:error] [pid 1029697:tid 1029911] [client 190.84.116.212:22624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbRm65wm-f4uX16X6JSQAAVCA"]
[Thu Sep 17 15:27:34.605114 2026] [security2:error] [pid 1029697:tid 1029934] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxbRm65wm-f4uX16X6JVAAAAGs"]
[Thu Sep 17 15:27:34.672592 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/backend/.env"] [unique_id "aqxbRm65wm-f4uX16X6JVgAAAHY"]
[Thu Sep 17 15:27:34.766587 2026] [security2:error] [pid 1029697:tid 1029924] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxbRm65wm-f4uX16X6JWwAAAGE"]
[Thu Sep 17 15:27:34.828034 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.180.119.195:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbRm65wm-f4uX16X6JXwAAACM"]
[Thu Sep 17 15:27:34.842707 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/server/.env"] [unique_id "aqxbRm65wm-f4uX16X6JYgAAAC0"]
[Thu Sep 17 15:27:34.921048 2026] [security2:error] [pid 1029697:tid 1029834] [client 20.255.75.24:1348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/cc.php"] [unique_id "aqxbRm65wm-f4uX16X6JZgAAAAc"]
[Thu Sep 17 15:27:34.927641 2026] [security2:error] [pid 1029697:tid 1029849] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxbRm65wm-f4uX16X6JZwAAABY"]
[Thu Sep 17 15:27:35.006255 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/frontend/.env"] [unique_id "aqxbR265wm-f4uX16X6JawAAAGw"]
[Thu Sep 17 15:27:35.040667 2026] [security2:error] [pid 1029697:tid 1029907] [client 143.244.57.120:60418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxbR265wm-f4uX16X6JbAAAAFA"]
[Thu Sep 17 15:27:35.064906 2026] [security2:error] [pid 1029697:tid 1029910] [client 20.255.75.24:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/profile.php"] [unique_id "aqxbR265wm-f4uX16X6JbgAAAFM"]
[Thu Sep 17 15:27:35.093023 2026] [security2:error] [pid 1029697:tid 1029859] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxbR265wm-f4uX16X6JcQAAACA"]
[Thu Sep 17 15:27:35.130655 2026] [security2:error] [pid 1029697:tid 1029858] [client 185.55.149.49:53391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbR265wm-f4uX16X6JcgAAAB8"]
[Thu Sep 17 15:27:35.130812 2026] [security2:error] [pid 1029697:tid 1029858] [client 185.55.149.49:53391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbR265wm-f4uX16X6JcgAAAB8"]
[Thu Sep 17 15:27:35.162476 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/src/.env"] [unique_id "aqxbR265wm-f4uX16X6JdAAAACw"]
[Thu Sep 17 15:27:35.257627 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.180.119.195:47084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbR265wm-f4uX16X6JdQAAADM"]
[Thu Sep 17 15:27:35.259103 2026] [security2:error] [pid 1029697:tid 1029952] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxbR265wm-f4uX16X6JdgAAAH0"]
[Thu Sep 17 15:27:35.266011 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.166.123.190:41506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbR265wm-f4uX16X6JeQAAABs"]
[Thu Sep 17 15:27:35.323376 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/core/.env"] [unique_id "aqxbR265wm-f4uX16X6JfQAAAEY"]
[Thu Sep 17 15:27:35.421451 2026] [security2:error] [pid 1029697:tid 1029926] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxbR265wm-f4uX16X6JfwAAAGM"]
[Thu Sep 17 15:27:35.423071 2026] [security2:error] [pid 1029697:tid 1029922] [client 20.255.75.24:1383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/chosen.php"] [unique_id "aqxbR265wm-f4uX16X6JgAAAAF8"]
[Thu Sep 17 15:27:35.495141 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/core/app/.env"] [unique_id "aqxbR265wm-f4uX16X6JgQAAAHw"]
[Thu Sep 17 15:27:35.580072 2026] [security2:error] [pid 1029697:tid 1029916] [client 20.255.75.24:1389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/server.php"] [unique_id "aqxbR265wm-f4uX16X6JhgAAAFk"]
[Thu Sep 17 15:27:35.582620 2026] [security2:error] [pid 1029697:tid 1029948] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxbR265wm-f4uX16X6JhwAAAHk"]
[Thu Sep 17 15:27:35.654301 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/config/.env"] [unique_id "aqxbR265wm-f4uX16X6JigAAAGU"]
[Thu Sep 17 15:27:35.671588 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.180.119.195:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbR265wm-f4uX16X6JjAAAAA8"]
[Thu Sep 17 15:27:35.738269 2026] [security2:error] [pid 1029697:tid 1029839] [client 143.244.57.120:60432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxbR265wm-f4uX16X6JjwAAAAw"]
[Thu Sep 17 15:27:35.747259 2026] [security2:error] [pid 1029697:tid 1029877] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxbR265wm-f4uX16X6JkAAAADI"]
[Thu Sep 17 15:27:35.814206 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/private/.env"] [unique_id "aqxbR265wm-f4uX16X6JkwAAAAM"]
[Thu Sep 17 15:27:35.909178 2026] [security2:error] [pid 1029697:tid 1029908] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxbR265wm-f4uX16X6JmQAAAFE"]
[Thu Sep 17 15:27:35.957635 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.166.123.190:41518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbR265wm-f4uX16X6JmwAAAFc"]
[Thu Sep 17 15:27:35.957684 2026] [security2:error] [pid 1029697:tid 1029874] [client 20.255.75.24:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/classwithtostring.php"] [unique_id "aqxbR265wm-f4uX16X6JnAAAAC8"]
[Thu Sep 17 15:27:35.969108 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/application/.env"] [unique_id "aqxbR265wm-f4uX16X6JnQAAAGE"]
[Thu Sep 17 15:27:36.071187 2026] [security2:error] [pid 1029697:tid 1029872] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxbSG65wm-f4uX16X6JoAAAAC0"]
[Thu Sep 17 15:27:36.100211 2026] [security2:error] [pid 1029697:tid 1029827] [client 20.255.75.24:1346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/shell.php"] [unique_id "aqxbSG65wm-f4uX16X6JowAAAAA"]
[Thu Sep 17 15:27:36.126852 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/bootstrap/.env"] [unique_id "aqxbSG65wm-f4uX16X6JpQAAABg"]
[Thu Sep 17 15:27:36.141359 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.180.119.195:45030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbSG65wm-f4uX16X6JpgAAACM"]
[Thu Sep 17 15:27:36.245264 2026] [security2:error] [pid 1029697:tid 1029907] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxbSG65wm-f4uX16X6JrQAAAFA"]
[Thu Sep 17 15:27:36.292400 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/database/.env"] [unique_id "aqxbSG65wm-f4uX16X6JrwAAACw"]
[Thu Sep 17 15:27:36.394745 2026] [security2:error] [pid 1029697:tid 1029844] [client 143.244.57.120:60440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxbSG65wm-f4uX16X6JtAAAABE"]
[Thu Sep 17 15:27:36.406114 2026] [security2:error] [pid 1029697:tid 1029869] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxbSG65wm-f4uX16X6JtwAAACo"]
[Thu Sep 17 15:27:36.446869 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/storage/.env"] [unique_id "aqxbSG65wm-f4uX16X6JuQAAAGM"]
[Thu Sep 17 15:27:36.447857 2026] [security2:error] [pid 1029697:tid 1029829] [client 20.255.75.24:1397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/wp-signup.php"] [unique_id "aqxbSG65wm-f4uX16X6JugAAAAI"]
[Thu Sep 17 15:27:36.512493 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.180.119.195:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbSG65wm-f4uX16X6JvgAAAEQ"]
[Thu Sep 17 15:27:36.567767 2026] [security2:error] [pid 1029697:tid 1029928] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxbSG65wm-f4uX16X6JxAAAAGU"]
[Thu Sep 17 15:27:36.601109 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/var/www/.env"] [unique_id "aqxbSG65wm-f4uX16X6JxwAAACc"]
[Thu Sep 17 15:27:36.604707 2026] [security2:error] [pid 1029697:tid 1029889] [client 20.255.75.24:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/t.php"] [unique_id "aqxbSG65wm-f4uX16X6JyQAAAD4"]
[Thu Sep 17 15:27:36.655971 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.166.123.190:41526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbSG65wm-f4uX16X6JywAAAGQ"]
[Thu Sep 17 15:27:36.672378 2026] [security2:error] [pid 1029697:tid 1029858] [client 136.158.61.34:27426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbSG65wm-f4uX16X6JzAAAAB8"]
[Thu Sep 17 15:27:36.676082 2026] [security2:error] [pid 1029697:tid 1029858] [client 136.158.61.34:27426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbSG65wm-f4uX16X6JzAAAAB8"]
[Thu Sep 17 15:27:36.728346 2026] [security2:error] [pid 1029697:tid 1029903] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxbSG65wm-f4uX16X6J0gAAAEw"]
[Thu Sep 17 15:27:36.758400 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/var/www/html/.env"] [unique_id "aqxbSG65wm-f4uX16X6J1gAAAAY"]
[Thu Sep 17 15:27:36.890837 2026] [security2:error] [pid 1029697:tid 1029847] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxbSG65wm-f4uX16X6J2QAAABQ"]
[Thu Sep 17 15:27:36.921941 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.180.119.195:45048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/phpinfo.php~"] [unique_id "aqxbSG65wm-f4uX16X6J2gAAABk"]
[Thu Sep 17 15:27:36.923059 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/current/.env"] [unique_id "aqxbSG65wm-f4uX16X6J2wAAAA0"]
[Thu Sep 17 15:27:36.942155 2026] [security2:error] [pid 1029697:tid 1029876] [client 20.255.75.24:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/doc.php"] [unique_id "aqxbSG65wm-f4uX16X6J3AAAADE"]
[Thu Sep 17 15:27:36.969329 2026] [security2:error] [pid 1029697:tid 1029936] [client 143.244.57.120:60442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxbSG65wm-f4uX16X6J3gAAAG0"]
[Thu Sep 17 15:27:37.054780 2026] [security2:error] [pid 1029697:tid 1029872] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxbSW65wm-f4uX16X6J4gAAAC0"]
[Thu Sep 17 15:27:37.076961 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/release/.env"] [unique_id "aqxbSW65wm-f4uX16X6J4wAAACg"]
[Thu Sep 17 15:27:37.091192 2026] [security2:error] [pid 1029697:tid 1029900] [client 185.226.198.4:42482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbSW65wm-f4uX16X6J4AAAAEk"]
[Thu Sep 17 15:27:37.120590 2026] [security2:error] [pid 1029697:tid 1029856] [client 20.255.75.24:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/hello.php"] [unique_id "aqxbSW65wm-f4uX16X6J5AAAAB0"]
[Thu Sep 17 15:27:37.215364 2026] [security2:error] [pid 1029697:tid 1029907] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxbSW65wm-f4uX16X6J6AAAAFA"]
[Thu Sep 17 15:27:37.237939 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/releases/.env"] [unique_id "aqxbSW65wm-f4uX16X6J6QAAAHU"]
[Thu Sep 17 15:27:37.313151 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.180.119.195:45050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/info.php.bak"] [unique_id "aqxbSW65wm-f4uX16X6J8QAAAAc"]
[Thu Sep 17 15:27:37.315195 2026] [security2:error] [pid 1029697:tid 1029892] [client 4.240.114.86:51957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxbSW65wm-f4uX16X6J8gAAAEE"], referer: binance.com
[Thu Sep 17 15:27:37.334348 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.166.123.190:41534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbSW65wm-f4uX16X6J9AAAAEM"]
[Thu Sep 17 15:27:37.376031 2026] [security2:error] [pid 1029697:tid 1029873] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxbSW65wm-f4uX16X6J9QAAAC4"]
[Thu Sep 17 15:27:37.418347 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/shared/.env"] [unique_id "aqxbSW65wm-f4uX16X6J9wAAAHQ"]
[Thu Sep 17 15:27:37.422157 2026] [security2:error] [pid 1029697:tid 1029880] [client 20.255.75.24:1391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/edit.php"] [unique_id "aqxbSW65wm-f4uX16X6J-AAAADU"]
[Thu Sep 17 15:27:37.502506 2026] [security2:error] [pid 1029697:tid 1029849] [client 185.226.198.5:32654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbSW65wm-f4uX16X6J8wAAABY"]
[Thu Sep 17 15:27:37.540876 2026] [security2:error] [pid 1029697:tid 1029921] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxbSW65wm-f4uX16X6J_AAAAF4"]
[Thu Sep 17 15:27:37.573286 2026] [security2:error] [pid 1029697:tid 1029848] [client 143.244.57.120:60454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "globaldove.org"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxbSW65wm-f4uX16X6J_QAAABU"]
[Thu Sep 17 15:27:37.575253 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/deploy/.env"] [unique_id "aqxbSW65wm-f4uX16X6J_gAAABc"]
[Thu Sep 17 15:27:37.700631 2026] [security2:error] [pid 1029697:tid 1029923] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxbSW65wm-f4uX16X6KAwAAAGA"]
[Thu Sep 17 15:27:37.728896 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/build/.env"] [unique_id "aqxbSW65wm-f4uX16X6KBgAAAGU"]
[Thu Sep 17 15:27:37.736933 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.180.119.195:45060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbSW65wm-f4uX16X6KCAAAAFs"]
[Thu Sep 17 15:27:37.777049 2026] [security2:error] [pid 1029697:tid 1029916] [client 216.73.217.79:18218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tipsysex.com"] [uri "/index.php"] [unique_id "aqxbSW65wm-f4uX16X6KAgAAWTk"]
[Thu Sep 17 15:27:37.861084 2026] [security2:error] [pid 1029697:tid 1029903] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxbSW65wm-f4uX16X6KDgAAAEw"]
[Thu Sep 17 15:27:37.898358 2026] [security2:error] [pid 1029697:tid 1029889] [client 20.255.75.24:1375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/worksec.php"] [unique_id "aqxbSW65wm-f4uX16X6KEAAAAD4"]
[Thu Sep 17 15:27:37.898577 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/dist/.env"] [unique_id "aqxbSW65wm-f4uX16X6KDwAAABA"]
[Thu Sep 17 15:27:37.968575 2026] [security2:error] [pid 1029697:tid 1029948] [client 104.207.33.33:54009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.stevearensberg.com"] [uri "/wp-content/plugins/gamipress/readme.txt"] [unique_id "aqxbSW65wm-f4uX16X6KFAAAAHk"]
[Thu Sep 17 15:27:38.018153 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.166.123.190:41538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbSm65wm-f4uX16X6KFgAAAGQ"]
[Thu Sep 17 15:27:38.026553 2026] [security2:error] [pid 1029697:tid 1029908] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxbSm65wm-f4uX16X6KFwAAAFE"]
[Thu Sep 17 15:27:38.053890 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/public_html/.env"] [unique_id "aqxbSm65wm-f4uX16X6KGQAAAGs"]
[Thu Sep 17 15:27:38.106117 2026] [security2:error] [pid 1029697:tid 1029863] [client 44.239.144.77:62697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxbSG65wm-f4uX16X6JpAAAACQ"], referer: http://worthtranslations.com/NEW
[Thu Sep 17 15:27:38.121149 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.180.119.195:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbSm65wm-f4uX16X6KGwAAACY"]
[Thu Sep 17 15:27:38.192738 2026] [security2:error] [pid 1029697:tid 1029874] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxbSm65wm-f4uX16X6KHwAAAC8"]
[Thu Sep 17 15:27:38.214756 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/htdocs/.env"] [unique_id "aqxbSm65wm-f4uX16X6KIAAAAG8"]
[Thu Sep 17 15:27:38.277252 2026] [security2:error] [pid 1029697:tid 1029847] [client 169.58.197.253:62142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/json-schema.php"] [unique_id "aqxbSm65wm-f4uX16X6KIwAAABQ"], referer: binance.com
[Thu Sep 17 15:27:38.371220 2026] [security2:error] [pid 1029697:tid 1029876] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxbSm65wm-f4uX16X6KJQAAADE"]
[Thu Sep 17 15:27:38.376328 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/www/.env"] [unique_id "aqxbSm65wm-f4uX16X6KJgAAAG0"]
[Thu Sep 17 15:27:38.380784 2026] [security2:error] [pid 1029697:tid 1029914] [client 20.255.75.24:1405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/ultra.php"] [unique_id "aqxbSm65wm-f4uX16X6KJwAAAFc"]
[Thu Sep 17 15:27:38.491742 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.180.119.195:45084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbSm65wm-f4uX16X6KKwAAAHs"]
[Thu Sep 17 15:27:38.531057 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/html/.env"] [unique_id "aqxbSm65wm-f4uX16X6KLAAAADc"]
[Thu Sep 17 15:27:38.531583 2026] [security2:error] [pid 1029697:tid 1029887] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxbSm65wm-f4uX16X6KLQAAADw"]
[Thu Sep 17 15:27:38.686135 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/live/.env"] [unique_id "aqxbSm65wm-f4uX16X6KMgAAAD8"]
[Thu Sep 17 15:27:38.693506 2026] [security2:error] [pid 1029697:tid 1029909] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxbSm65wm-f4uX16X6KMwAAAFI"]
[Thu Sep 17 15:27:38.844748 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/prod/.env"] [unique_id "aqxbSm65wm-f4uX16X6KOQAAAGw"]
[Thu Sep 17 15:27:38.855609 2026] [security2:error] [pid 1029697:tid 1029834] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxbSm65wm-f4uX16X6KOgAAAAc"]
[Thu Sep 17 15:27:38.860946 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.180.119.195:45096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbSm65wm-f4uX16X6KOwAAAH0"]
[Thu Sep 17 15:27:38.878491 2026] [security2:error] [pid 1029697:tid 1029910] [client 20.255.75.24:1035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/gecko.php"] [unique_id "aqxbSm65wm-f4uX16X6KPwAAAFM"]
[Thu Sep 17 15:27:39.006254 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/dev/.env"] [unique_id "aqxbS265wm-f4uX16X6KQwAAADU"]
[Thu Sep 17 15:27:39.020299 2026] [security2:error] [pid 1029697:tid 1029829] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxbS265wm-f4uX16X6KRQAAAAI"]
[Thu Sep 17 15:27:39.022251 2026] [security2:error] [pid 1029697:tid 1029944] [client 103.61.184.148:50178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbS265wm-f4uX16X6KRAAAAHU"]
[Thu Sep 17 15:27:39.022418 2026] [security2:error] [pid 1029697:tid 1029944] [client 103.61.184.148:50178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbS265wm-f4uX16X6KRAAAAHU"]
[Thu Sep 17 15:27:39.160754 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/staging/.env"] [unique_id "aqxbS265wm-f4uX16X6KSgAAAFg"]
[Thu Sep 17 15:27:39.181115 2026] [security2:error] [pid 1029697:tid 1029933] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxbS265wm-f4uX16X6KSwAAAGo"]
[Thu Sep 17 15:27:39.227839 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.180.119.195:45100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbS265wm-f4uX16X6KUQAAAGY"]
[Thu Sep 17 15:27:39.332144 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/opt/.env"] [unique_id "aqxbS265wm-f4uX16X6KVAAAACc"]
[Thu Sep 17 15:27:39.340904 2026] [security2:error] [pid 1029697:tid 1029839] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxbS265wm-f4uX16X6KVgAAAAw"]
[Thu Sep 17 15:27:39.360836 2026] [security2:error] [pid 1029697:tid 1029836] [client 20.255.75.24:1174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/goods.php"] [unique_id "aqxbS265wm-f4uX16X6KWAAAAAk"]
[Thu Sep 17 15:27:39.425618 2026] [security2:error] [pid 1029697:tid 1029898] [client 17.166.233.31:55400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxbS265wm-f4uX16X6KUgAAR1Q"]
[Thu Sep 17 15:27:39.487176 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/laravel/.env"] [unique_id "aqxbS265wm-f4uX16X6KXAAAABI"]
[Thu Sep 17 15:27:39.502199 2026] [security2:error] [pid 1029697:tid 1029879] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxbS265wm-f4uX16X6KXQAAADQ"]
[Thu Sep 17 15:27:39.507515 2026] [security2:error] [pid 1029697:tid 1029901] [client 184.154.36.174:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "recessionnews.org"] [uri "/cgi-sys/404.html"] [unique_id "aqxbS265wm-f4uX16X6KXgAAAEo"]
[Thu Sep 17 15:27:39.603424 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.180.119.195:45112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbS265wm-f4uX16X6KYQAAAD4"]
[Thu Sep 17 15:27:39.611639 2026] [security2:error] [pid 1029697:tid 1029951] [client 184.154.36.174:51536] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "recessionnews.org"] [uri "/th1s_1s_a_4o4.html"] [unique_id "aqxbS265wm-f4uX16X6KTAAAAHw"]
[Thu Sep 17 15:27:39.642193 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.154.239.243:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/symfony/.env"] [unique_id "aqxbS265wm-f4uX16X6KZAAAAHE"]
[Thu Sep 17 15:27:39.664250 2026] [security2:error] [pid 1029697:tid 1029930] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxbS265wm-f4uX16X6KZQAAAGc"]
[Thu Sep 17 15:27:39.824971 2026] [security2:error] [pid 1029697:tid 1029938] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxbS265wm-f4uX16X6KbgAAAG8"]
[Thu Sep 17 15:27:39.842220 2026] [security2:error] [pid 1029697:tid 1029828] [client 20.255.75.24:1180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/man.php"] [unique_id "aqxbS265wm-f4uX16X6KcAAAAAE"]
[Thu Sep 17 15:27:39.943855 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.180.119.195:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbS265wm-f4uX16X6KdQAAAE8"]
[Thu Sep 17 15:27:39.946851 2026] [security2:error] [pid 1029697:tid 1029873] [client 5.189.145.112:60815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.christiansoncampusnlc.com"] [uri "/index.php"] [unique_id "aqxbS265wm-f4uX16X6KawAAAC4"], referer: binance.com
[Thu Sep 17 15:27:39.985752 2026] [security2:error] [pid 1029697:tid 1029851] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxbS265wm-f4uX16X6KeAAAABg"]
[Thu Sep 17 15:27:40.124619 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/wordpress/.env"] [unique_id "aqxbTG65wm-f4uX16X6KfQAAAHs"]
[Thu Sep 17 15:27:40.145995 2026] [security2:error] [pid 1029697:tid 1029939] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxbTG65wm-f4uX16X6KfgAAAHA"]
[Thu Sep 17 15:27:40.279138 2026] [security2:error] [pid 1029697:tid 1029892] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/wp/.env"] [unique_id "aqxbTG65wm-f4uX16X6KhQAAAEE"]
[Thu Sep 17 15:27:40.285856 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.180.119.195:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbTG65wm-f4uX16X6KhgAAAFI"]
[Thu Sep 17 15:27:40.306228 2026] [security2:error] [pid 1029697:tid 1029846] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxbTG65wm-f4uX16X6KiAAAABM"]
[Thu Sep 17 15:27:40.323658 2026] [security2:error] [pid 1029697:tid 1029890] [client 20.255.75.24:1176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/wp-settings.php"] [unique_id "aqxbTG65wm-f4uX16X6KigAAAD8"]
[Thu Sep 17 15:27:40.435809 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/cms/.env"] [unique_id "aqxbTG65wm-f4uX16X6KjgAAAAI"]
[Thu Sep 17 15:27:40.441384 2026] [security2:error] [pid 1029697:tid 1029896] [client 185.226.198.4:34070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbTG65wm-f4uX16X6KgQAAAEU"]
[Thu Sep 17 15:27:40.466796 2026] [security2:error] [pid 1029697:tid 1029922] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxbTG65wm-f4uX16X6KkgAAAF8"]
[Thu Sep 17 15:27:40.477303 2026] [security2:error] [pid 1029697:tid 1029849] [client 4.240.114.86:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxbTG65wm-f4uX16X6KkwAAABY"], referer: binance.com
[Thu Sep 17 15:27:40.600546 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/drupal/.env"] [unique_id "aqxbTG65wm-f4uX16X6KlwAAADg"]
[Thu Sep 17 15:27:40.627103 2026] [security2:error] [pid 1029697:tid 1029915] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxbTG65wm-f4uX16X6KmQAAAFg"]
[Thu Sep 17 15:27:40.687181 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.180.119.195:45136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbTG65wm-f4uX16X6KmwAAACg"]
[Thu Sep 17 15:27:40.758937 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/joomla/.env"] [unique_id "aqxbTG65wm-f4uX16X6KnwAAAAw"]
[Thu Sep 17 15:27:40.826713 2026] [security2:error] [pid 1029697:tid 1029933] [client 20.255.75.24:1169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/k.php"] [unique_id "aqxbTG65wm-f4uX16X6KpQAAAGo"]
[Thu Sep 17 15:27:40.826729 2026] [security2:error] [pid 1029697:tid 1029898] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxbTG65wm-f4uX16X6KowAAAEc"]
[Thu Sep 17 15:27:40.918870 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/magento/.env"] [unique_id "aqxbTG65wm-f4uX16X6KrAAAAB4"]
[Thu Sep 17 15:27:40.962180 2026] [security2:error] [pid 1029697:tid 1029861] [client 183.88.2.227:50712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbTG65wm-f4uX16X6KpgAAIlg"]
[Thu Sep 17 15:27:40.987630 2026] [security2:error] [pid 1029697:tid 1029911] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxbTG65wm-f4uX16X6KrwAAAFQ"]
[Thu Sep 17 15:27:41.056805 2026] [security2:error] [pid 1029697:tid 1029835] [client 52.167.144.216:7983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brownsdailydose.com"] [uri "/index.php"] [unique_id "aqxbTG65wm-f4uX16X6KoQAACD8"]
[Thu Sep 17 15:27:41.072871 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.180.119.195:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbTW65wm-f4uX16X6KtAAAAD4"]
[Thu Sep 17 15:27:41.077012 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/shopify/.env"] [unique_id "aqxbTW65wm-f4uX16X6KtQAAAGc"]
[Thu Sep 17 15:27:41.152242 2026] [security2:error] [pid 1029697:tid 1029828] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxbTW65wm-f4uX16X6KuAAAAAE"]
[Thu Sep 17 15:27:41.237331 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/prestashop/.env"] [unique_id "aqxbTW65wm-f4uX16X6KvQAAACY"]
[Thu Sep 17 15:27:41.312380 2026] [security2:error] [pid 1029697:tid 1029870] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxbTW65wm-f4uX16X6KwQAAACs"]
[Thu Sep 17 15:27:41.346880 2026] [security2:error] [pid 1029697:tid 1029932] [client 20.255.75.24:1183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/autoload_classmap.php"] [unique_id "aqxbTW65wm-f4uX16X6KwgAAAGk"]
[Thu Sep 17 15:27:41.403614 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/codeigniter/.env"] [unique_id "aqxbTW65wm-f4uX16X6KxAAAAE4"]
[Thu Sep 17 15:27:41.481165 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.180.119.195:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbTW65wm-f4uX16X6KyQAAADw"]
[Thu Sep 17 15:27:41.570476 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/cakephp/.env"] [unique_id "aqxbTW65wm-f4uX16X6KywAAAFI"]
[Thu Sep 17 15:27:41.729690 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/zend/.env"] [unique_id "aqxbTW65wm-f4uX16X6K1gAAAEU"]
[Thu Sep 17 15:27:41.797397 2026] [security2:error] [pid 1029697:tid 1029842] [client 35.198.3.220:53284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxbTW65wm-f4uX16X6K2QAAAA8"]
[Thu Sep 17 15:27:41.830161 2026] [security2:error] [pid 1029697:tid 1029854] [client 20.255.75.24:1184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/profile.php"] [unique_id "aqxbTW65wm-f4uX16X6K3AAAABs"]
[Thu Sep 17 15:27:41.837692 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.180.119.195:45174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbTW65wm-f4uX16X6K3QAAACw"]
[Thu Sep 17 15:27:41.877652 2026] [security2:error] [pid 1029697:tid 1029851] [client 143.105.152.240:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbTW65wm-f4uX16X6K2wAAABg"]
[Thu Sep 17 15:27:41.877785 2026] [security2:error] [pid 1029697:tid 1029851] [client 143.105.152.240:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbTW65wm-f4uX16X6K2wAAABg"]
[Thu Sep 17 15:27:41.889853 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/yii/.env"] [unique_id "aqxbTW65wm-f4uX16X6K4AAAAHg"]
[Thu Sep 17 15:27:42.044137 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/laravel5/.env"] [unique_id "aqxbTm65wm-f4uX16X6K5gAAAB4"]
[Thu Sep 17 15:27:42.199620 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/v1/.env"] [unique_id "aqxbTm65wm-f4uX16X6K6wAAAAg"]
[Thu Sep 17 15:27:42.213238 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.180.119.195:45186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbTm65wm-f4uX16X6K7QAAACI"]
[Thu Sep 17 15:27:42.288874 2026] [security2:error] [pid 1029697:tid 1029948] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxbTm65wm-f4uX16X6K8QAAAHk"]
[Thu Sep 17 15:27:42.319964 2026] [security2:error] [pid 1029697:tid 1029886] [client 20.255.75.24:1162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/server.php"] [unique_id "aqxbTm65wm-f4uX16X6K8gAAADs"]
[Thu Sep 17 15:27:42.352533 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/v2/.env"] [unique_id "aqxbTm65wm-f4uX16X6K9wAAAG8"]
[Thu Sep 17 15:27:42.454610 2026] [security2:error] [pid 1029697:tid 1029943] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxbTm65wm-f4uX16X6K_AAAAHQ"]
[Thu Sep 17 15:27:42.510762 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/v3/.env"] [unique_id "aqxbTm65wm-f4uX16X6K_gAAAB0"]
[Thu Sep 17 15:27:42.575638 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.180.119.195:45202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbTm65wm-f4uX16X6LAgAAAAE"]
[Thu Sep 17 15:27:42.606942 2026] [security2:error] [pid 1029697:tid 1029944] [client 156.192.234.52:55604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbTm65wm-f4uX16X6LBAAAAHU"]
[Thu Sep 17 15:27:42.607103 2026] [security2:error] [pid 1029697:tid 1029944] [client 156.192.234.52:55604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbTm65wm-f4uX16X6LBAAAAHU"]
[Thu Sep 17 15:27:42.616752 2026] [security2:error] [pid 1029697:tid 1029932] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxbTm65wm-f4uX16X6LBQAAAGk"]
[Thu Sep 17 15:27:42.665914 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/api/v1/.env"] [unique_id "aqxbTm65wm-f4uX16X6LCQAAACU"]
[Thu Sep 17 15:27:42.777982 2026] [security2:error] [pid 1029697:tid 1029830] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxbTm65wm-f4uX16X6LDQAAAAM"]
[Thu Sep 17 15:27:42.802043 2026] [security2:error] [pid 1029697:tid 1029860] [client 20.255.75.24:1157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/shell.php"] [unique_id "aqxbTm65wm-f4uX16X6LDwAAACE"]
[Thu Sep 17 15:27:42.820145 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/api/v2/.env"] [unique_id "aqxbTm65wm-f4uX16X6LEQAAAFU"]
[Thu Sep 17 15:27:42.822564 2026] [security2:error] [pid 1029697:tid 1029862] [client 114.198.138.124:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbTm65wm-f4uX16X6LEgAAACM"]
[Thu Sep 17 15:27:42.823029 2026] [security2:error] [pid 1029697:tid 1029862] [client 114.198.138.124:62503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbTm65wm-f4uX16X6LEgAAACM"]
[Thu Sep 17 15:27:42.930565 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.180.119.195:45210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.119.180.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal-release-website.24eastyard.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbTm65wm-f4uX16X6LGwAAAAU"]
[Thu Sep 17 15:27:42.936707 2026] [security2:error] [pid 1029697:tid 1029887] [client 167.235.143.113:57658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxbTm65wm-f4uX16X6LGgAAADw"], referer: https://eris.media
[Thu Sep 17 15:27:42.946249 2026] [security2:error] [pid 1029697:tid 1029869] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxbTm65wm-f4uX16X6LHAAAACo"]
[Thu Sep 17 15:27:42.995826 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/rest/.env"] [unique_id "aqxbTm65wm-f4uX16X6LHwAAAHI"]
[Thu Sep 17 15:27:43.014429 2026] [security2:error] [pid 1029697:tid 1029881] [client 81.196.132.182:50187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbTm65wm-f4uX16X6LGQAANkw"]
[Thu Sep 17 15:27:43.106917 2026] [security2:error] [pid 1029697:tid 1029867] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxbT265wm-f4uX16X6LIgAAACg"]
[Thu Sep 17 15:27:43.156776 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/graphql/.env"] [unique_id "aqxbT265wm-f4uX16X6LJAAAAAw"]
[Thu Sep 17 15:27:43.269511 2026] [security2:error] [pid 1029697:tid 1029836] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxbT265wm-f4uX16X6LKgAAAAk"]
[Thu Sep 17 15:27:43.313792 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/gateway/.env"] [unique_id "aqxbT265wm-f4uX16X6LLwAAAGM"]
[Thu Sep 17 15:27:43.317342 2026] [core:error] [pid 1029697:tid 1029851] [client 34.180.119.195:45226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:43.317358 2026] [core:error] [pid 1029697:tid 1029851] [client 34.180.119.195:45226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:43.329408 2026] [security2:error] [pid 1029697:tid 1029871] [client 20.255.75.24:1179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/t.php"] [unique_id "aqxbT265wm-f4uX16X6LMAAAACw"]
[Thu Sep 17 15:27:43.417241 2026] [security2:error] [pid 1029697:tid 1029951] [client 4.240.114.86:55979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxbT265wm-f4uX16X6LMwAAAHw"], referer: binance.com
[Thu Sep 17 15:27:43.431637 2026] [security2:error] [pid 1029697:tid 1029835] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxbT265wm-f4uX16X6LNAAAAAg"]
[Thu Sep 17 15:27:43.472684 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/microservice/.env"] [unique_id "aqxbT265wm-f4uX16X6LNgAAAHk"]
[Thu Sep 17 15:27:43.596500 2026] [security2:error] [pid 1029697:tid 1029855] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxbT265wm-f4uX16X6LPgAAABw"]
[Thu Sep 17 15:27:43.641739 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/service/.env"] [unique_id "aqxbT265wm-f4uX16X6LQAAAAGU"]
[Thu Sep 17 15:27:43.737352 2026] [core:error] [pid 1029697:tid 1029838] [client 34.180.119.195:45230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:43.737372 2026] [core:error] [pid 1029697:tid 1029838] [client 34.180.119.195:45230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:43.757990 2026] [security2:error] [pid 1029697:tid 1029870] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxbT265wm-f4uX16X6LSAAAACs"]
[Thu Sep 17 15:27:43.759134 2026] [security2:error] [pid 1029697:tid 1029921] [client 106.219.165.75:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.165.219.106.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.streetwisepublicationsltd.com"] [uri "/xmlrpc.php"] [unique_id "aqxbT265wm-f4uX16X6LQQAAAF4"], referer: https://www.streetwisepublicationsltd.com/croesus/
[Thu Sep 17 15:27:43.823209 2026] [security2:error] [pid 1029697:tid 1029884] [client 20.255.75.24:1156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.75.255.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athikerrev.com"] [uri "/hello.php"] [unique_id "aqxbT265wm-f4uX16X6LTwAAADk"]
[Thu Sep 17 15:27:43.836803 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/api/v3/.env"] [unique_id "aqxbT265wm-f4uX16X6LUQAAACU"]
[Thu Sep 17 15:27:43.920430 2026] [security2:error] [pid 1029697:tid 1029912] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxbT265wm-f4uX16X6LVgAAAFU"]
[Thu Sep 17 15:27:44.002044 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/api/dev/.env"] [unique_id "aqxbT265wm-f4uX16X6LWAAAABQ"]
[Thu Sep 17 15:27:44.060257 2026] [security2:error] [pid 1029697:tid 1029900] [client 185.226.198.5:39328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbT265wm-f4uX16X6LUgAAAEk"]
[Thu Sep 17 15:27:44.089891 2026] [security2:error] [pid 1029697:tid 1029907] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxbUG65wm-f4uX16X6LXwAAAFA"]
[Thu Sep 17 15:27:44.130353 2026] [core:error] [pid 1029697:tid 1029949] [client 34.180.119.195:45242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:44.130370 2026] [core:error] [pid 1029697:tid 1029949] [client 34.180.119.195:45242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:44.168408 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/api/staging/.env"] [unique_id "aqxbUG65wm-f4uX16X6LZgAAACo"]
[Thu Sep 17 15:27:44.250972 2026] [security2:error] [pid 1029697:tid 1029829] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxbUG65wm-f4uX16X6LbQAAAAI"]
[Thu Sep 17 15:27:44.343927 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/vendor/.env"] [unique_id "aqxbUG65wm-f4uX16X6LdAAAAA8"]
[Thu Sep 17 15:27:44.355812 2026] [security2:error] [pid 1029697:tid 1029924] [client 51.83.237.175:36392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "brownsdailydose.com"] [uri "/robots.txt"] [unique_id "aqxbUG65wm-f4uX16X6LdgAAAGE"]
[Thu Sep 17 15:27:44.355961 2026] [security2:error] [pid 1029697:tid 1029924] [client 51.83.237.175:36392] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brownsdailydose.com"] [uri "/robots.txt"] [unique_id "aqxbUG65wm-f4uX16X6LdgAAAGE"]
[Thu Sep 17 15:27:44.417594 2026] [security2:error] [pid 1029697:tid 1029839] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxbUG65wm-f4uX16X6LeQAAAAw"]
[Thu Sep 17 15:27:44.491670 2026] [security2:error] [pid 1029697:tid 1029922] [client 162.241.226.11:42500] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxbUG65wm-f4uX16X6LegAAAF8"]
[Thu Sep 17 15:27:44.504915 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/lib/.env"] [unique_id "aqxbUG65wm-f4uX16X6LfgAAAHg"]
[Thu Sep 17 15:27:44.530942 2026] [core:error] [pid 1029697:tid 1029915] [client 34.180.119.195:45254] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:44.530963 2026] [core:error] [pid 1029697:tid 1029915] [client 34.180.119.195:45254] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:44.582398 2026] [security2:error] [pid 1029697:tid 1029923] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxbUG65wm-f4uX16X6LggAAAGA"]
[Thu Sep 17 15:27:44.676355 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/resources/.env"] [unique_id "aqxbUG65wm-f4uX16X6LhAAAACI"]
[Thu Sep 17 15:27:44.744111 2026] [security2:error] [pid 1029697:tid 1029886] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxbUG65wm-f4uX16X6LhgAAADs"]
[Thu Sep 17 15:27:44.777692 2026] [security2:error] [pid 1029697:tid 1029930] [client 184.154.36.174:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "recessionnews.org"] [uri "/xmlrpc.php"] [unique_id "aqxbUG65wm-f4uX16X6LcwAAAGc"]
[Thu Sep 17 15:27:44.807902 2026] [security2:error] [pid 1029697:tid 1029858] [client 184.154.36.174:54110] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "recessionnews.org"] [uri "/xmlrpc.php"] [unique_id "aqxbUG65wm-f4uX16X6LYwAAAB8"]
[Thu Sep 17 15:27:44.847655 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/assets/.env"] [unique_id "aqxbUG65wm-f4uX16X6LjwAAAD4"]
[Thu Sep 17 15:27:44.904996 2026] [security2:error] [pid 1029697:tid 1029873] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxbUG65wm-f4uX16X6LkwAAAC4"]
[Thu Sep 17 15:27:44.934548 2026] [core:error] [pid 1029697:tid 1029928] [client 34.180.119.195:45262] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:44.934568 2026] [core:error] [pid 1029697:tid 1029928] [client 34.180.119.195:45262] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:45.006372 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/uploads/.env"] [unique_id "aqxbUW65wm-f4uX16X6LnAAAAFk"]
[Thu Sep 17 15:27:45.067876 2026] [security2:error] [pid 1029697:tid 1029912] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxbUW65wm-f4uX16X6LoAAAAFU"]
[Thu Sep 17 15:27:45.168324 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/internal/.env"] [unique_id "aqxbUW65wm-f4uX16X6LpAAAABQ"]
[Thu Sep 17 15:27:45.229920 2026] [security2:error] [pid 1029697:tid 1029846] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxbUW65wm-f4uX16X6LpwAAABM"]
[Thu Sep 17 15:27:45.323958 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/tools/.env"] [unique_id "aqxbUW65wm-f4uX16X6LrwAAAFA"]
[Thu Sep 17 15:27:45.347884 2026] [core:error] [pid 1029697:tid 1029910] [client 34.180.119.195:45278] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:45.347911 2026] [core:error] [pid 1029697:tid 1029910] [client 34.180.119.195:45278] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:45.394180 2026] [security2:error] [pid 1029697:tid 1029941] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxbUW65wm-f4uX16X6LsQAAAHI"]
[Thu Sep 17 15:27:45.484522 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/scripts/.env"] [unique_id "aqxbUW65wm-f4uX16X6LuAAAAH0"]
[Thu Sep 17 15:27:45.555777 2026] [security2:error] [pid 1029697:tid 1029903] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxbUW65wm-f4uX16X6LvQAAAEw"]
[Thu Sep 17 15:27:45.643705 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/bin/.env"] [unique_id "aqxbUW65wm-f4uX16X6LwQAAACY"]
[Thu Sep 17 15:27:45.718517 2026] [security2:error] [pid 1029697:tid 1029915] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxbUW65wm-f4uX16X6LwwAAAFg"]
[Thu Sep 17 15:27:45.765610 2026] [core:error] [pid 1029697:tid 1029936] [client 34.180.119.195:45282] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:45.765627 2026] [core:error] [pid 1029697:tid 1029936] [client 34.180.119.195:45282] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:45.807442 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/sbin/.env"] [unique_id "aqxbUW65wm-f4uX16X6LyQAAABE"]
[Thu Sep 17 15:27:45.863544 2026] [security2:error] [pid 1029697:tid 1029920] [client 185.55.149.49:54026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbUW65wm-f4uX16X6LzQAAAF0"]
[Thu Sep 17 15:27:45.863677 2026] [security2:error] [pid 1029697:tid 1029920] [client 185.55.149.49:54026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbUW65wm-f4uX16X6LzQAAAF0"]
[Thu Sep 17 15:27:45.881048 2026] [security2:error] [pid 1029697:tid 1029951] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxbUW65wm-f4uX16X6LzgAAAHw"]
[Thu Sep 17 15:27:45.965638 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/local/.env"] [unique_id "aqxbUW65wm-f4uX16X6L1QAAAEo"]
[Thu Sep 17 15:27:46.041762 2026] [security2:error] [pid 1029697:tid 1029930] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxbUm65wm-f4uX16X6L2QAAAGc"]
[Thu Sep 17 15:27:46.066320 2026] [core:error] [pid 1029697:tid 1029902] [client 185.247.137.121:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:46.066339 2026] [core:error] [pid 1029697:tid 1029902] [client 185.247.137.121:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:46.080215 2026] [security2:error] [pid 1029697:tid 1029889] [client 169.58.197.253:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxbUm65wm-f4uX16X6L3AAAAD4"], referer: binance.com
[Thu Sep 17 15:27:46.127407 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/portal/.env"] [unique_id "aqxbUm65wm-f4uX16X6L3gAAAAE"]
[Thu Sep 17 15:27:46.176231 2026] [core:error] [pid 1029697:tid 1029876] [client 34.180.119.195:38620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:46.176254 2026] [core:error] [pid 1029697:tid 1029876] [client 34.180.119.195:38620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:46.201887 2026] [security2:error] [pid 1029697:tid 1029852] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxbUm65wm-f4uX16X6L4gAAABk"]
[Thu Sep 17 15:27:46.287682 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/dashboard/.env"] [unique_id "aqxbUm65wm-f4uX16X6L5wAAACE"]
[Thu Sep 17 15:27:46.364069 2026] [security2:error] [pid 1029697:tid 1029893] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxbUm65wm-f4uX16X6L7QAAAEI"]
[Thu Sep 17 15:27:46.394991 2026] [security2:error] [pid 1029697:tid 1029905] [client 104.207.33.33:61437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.stevearensberg.com"] [uri "/wp-content/plugins/userswp/readme.txt"] [unique_id "aqxbUm65wm-f4uX16X6L7wAAAE4"]
[Thu Sep 17 15:27:46.464769 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/panel/.env"] [unique_id "aqxbUm65wm-f4uX16X6L9AAAADw"]
[Thu Sep 17 15:27:46.525926 2026] [security2:error] [pid 1029697:tid 1029904] [client 185.226.198.7:48676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbUm65wm-f4uX16X6L7AAAAE0"]
[Thu Sep 17 15:27:46.528162 2026] [security2:error] [pid 1029697:tid 1029949] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxbUm65wm-f4uX16X6L9QAAAHo"]
[Thu Sep 17 15:27:46.584018 2026] [core:error] [pid 1029697:tid 1029897] [client 34.180.119.195:38636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:46.584037 2026] [core:error] [pid 1029697:tid 1029897] [client 34.180.119.195:38636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:46.619218 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/crm/.env"] [unique_id "aqxbUm65wm-f4uX16X6L_QAAADg"]
[Thu Sep 17 15:27:46.691993 2026] [security2:error] [pid 1029697:tid 1029848] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxbUm65wm-f4uX16X6MAwAAABU"]
[Thu Sep 17 15:27:46.692739 2026] [proxy:warn] [pid 1029697:tid 1029875] [client 18.116.101.220:59962] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be trcco.org for uri /400.shtml
[Thu Sep 17 15:27:46.781710 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/erp/.env"] [unique_id "aqxbUm65wm-f4uX16X6MDQAAABs"]
[Thu Sep 17 15:27:46.797286 2026] [security2:error] [pid 1029697:tid 1029922] [client 18.116.101.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxbUm65wm-f4uX16X6MCQAAAF8"]
[Thu Sep 17 15:27:46.797308 2026] [security2:error] [pid 1029697:tid 1029922] [client 18.116.101.220:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxbUm65wm-f4uX16X6MCQAAAF8"]
[Thu Sep 17 15:27:46.820830 2026] [security2:error] [pid 1029697:tid 1029875] [client 18.116.101.220:59962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/400.shtml"] [unique_id "aqxbUm65wm-f4uX16X6MBAAAADA"]
[Thu Sep 17 15:27:46.825713 2026] [security2:error] [pid 1029697:tid 1029827] [client 4.240.114.86:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxbUm65wm-f4uX16X6MDgAAAAA"], referer: binance.com
[Thu Sep 17 15:27:46.856354 2026] [security2:error] [pid 1029697:tid 1029927] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxbUm65wm-f4uX16X6MEwAAAGQ"]
[Thu Sep 17 15:27:46.862320 2026] [security2:error] [pid 1029697:tid 1029896] [client 168.119.123.75:27862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxbUm65wm-f4uX16X6MFAAAAEU"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:27:46.944136 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/shop/.env"] [unique_id "aqxbUm65wm-f4uX16X6MFwAAAGM"]
[Thu Sep 17 15:27:47.002171 2026] [core:error] [pid 1029697:tid 1029865] [client 34.180.119.195:38638] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:47.002197 2026] [core:error] [pid 1029697:tid 1029865] [client 34.180.119.195:38638] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:47.022995 2026] [security2:error] [pid 1029697:tid 1029945] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxbU265wm-f4uX16X6MHAAAAHY"]
[Thu Sep 17 15:27:47.099015 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/store/.env"] [unique_id "aqxbU265wm-f4uX16X6MIgAAAHM"]
[Thu Sep 17 15:27:47.186797 2026] [security2:error] [pid 1029697:tid 1029857] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxbU265wm-f4uX16X6MJgAAAB4"]
[Thu Sep 17 15:27:47.254320 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/saas/.env"] [unique_id "aqxbU265wm-f4uX16X6MKQAAADM"]
[Thu Sep 17 15:27:47.335638 2026] [security2:error] [pid 1029697:tid 1029909] [client 168.119.123.75:27866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxbU265wm-f4uX16X6MMAAAAFI"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:27:47.347278 2026] [security2:error] [pid 1029697:tid 1029856] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxbU265wm-f4uX16X6MMQAAAB0"]
[Thu Sep 17 15:27:47.404096 2026] [core:error] [pid 1029697:tid 1029858] [client 34.180.119.195:38652] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:47.404122 2026] [core:error] [pid 1029697:tid 1029858] [client 34.180.119.195:38652] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:47.407255 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/client/.env"] [unique_id "aqxbU265wm-f4uX16X6MNgAAAC4"]
[Thu Sep 17 15:27:47.522810 2026] [security2:error] [pid 1029697:tid 1029845] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxbU265wm-f4uX16X6MOgAAABI"]
[Thu Sep 17 15:27:47.563506 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/project/.env"] [unique_id "aqxbU265wm-f4uX16X6MPAAAACE"]
[Thu Sep 17 15:27:47.684767 2026] [security2:error] [pid 1029697:tid 1029833] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxbU265wm-f4uX16X6MQwAAAAY"]
[Thu Sep 17 15:27:47.731798 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/admin-panel/.env"] [unique_id "aqxbU265wm-f4uX16X6MRQAAADw"]
[Thu Sep 17 15:27:47.851249 2026] [security2:error] [pid 1029697:tid 1029897] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxbU265wm-f4uX16X6MUQAAAEY"]
[Thu Sep 17 15:27:47.884305 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/control-panel/.env"] [unique_id "aqxbU265wm-f4uX16X6MUwAAADg"]
[Thu Sep 17 15:27:47.905609 2026] [core:error] [pid 1029697:tid 1029832] [client 34.180.119.195:38656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:47.905631 2026] [core:error] [pid 1029697:tid 1029832] [client 34.180.119.195:38656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:48.012167 2026] [security2:error] [pid 1029697:tid 1029880] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxbVG65wm-f4uX16X6MWgAAADU"]
[Thu Sep 17 15:27:48.037425 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/user-panel/.env"] [unique_id "aqxbVG65wm-f4uX16X6MWwAAAD8"]
[Thu Sep 17 15:27:48.172625 2026] [security2:error] [pid 1029697:tid 1029916] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxbVG65wm-f4uX16X6MYQAAAFk"]
[Thu Sep 17 15:27:48.192476 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/node/.env"] [unique_id "aqxbVG65wm-f4uX16X6MYgAAADc"]
[Thu Sep 17 15:27:48.333340 2026] [security2:error] [pid 1029697:tid 1029936] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxbVG65wm-f4uX16X6MawAAAG0"]
[Thu Sep 17 15:27:48.352061 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/express/.env"] [unique_id "aqxbVG65wm-f4uX16X6MbAAAAAo"]
[Thu Sep 17 15:27:48.371398 2026] [core:error] [pid 1029697:tid 1029843] [client 34.180.119.195:38666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:48.371428 2026] [core:error] [pid 1029697:tid 1029843] [client 34.180.119.195:38666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:48.499095 2026] [security2:error] [pid 1029697:tid 1029944] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxbVG65wm-f4uX16X6McgAAAHU"]
[Thu Sep 17 15:27:48.506468 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/next/.env"] [unique_id "aqxbVG65wm-f4uX16X6McwAAAGA"]
[Thu Sep 17 15:27:48.663973 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/nuxt/.env"] [unique_id "aqxbVG65wm-f4uX16X6MegAAAGw"]
[Thu Sep 17 15:27:48.664791 2026] [security2:error] [pid 1029697:tid 1029834] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxbVG65wm-f4uX16X6MewAAAAc"]
[Thu Sep 17 15:27:48.808406 2026] [core:error] [pid 1029697:tid 1029886] [client 34.180.119.195:38680] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:48.808428 2026] [core:error] [pid 1029697:tid 1029886] [client 34.180.119.195:38680] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:27:48.816510 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/nest/.env"] [unique_id "aqxbVG65wm-f4uX16X6MhQAAAFI"]
[Thu Sep 17 15:27:48.826533 2026] [security2:error] [pid 1029697:tid 1029856] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxbVG65wm-f4uX16X6MhgAAAB0"]
[Thu Sep 17 15:27:48.852881 2026] [security2:error] [pid 1029697:tid 1029921] [client 134.185.85.61:61337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "paltals.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxbVG65wm-f4uX16X6MhwAAAF4"]
[Thu Sep 17 15:27:48.969570 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/react/.env"] [unique_id "aqxbVG65wm-f4uX16X6MjQAAAFs"]
[Thu Sep 17 15:27:48.986893 2026] [security2:error] [pid 1029697:tid 1029855] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxbVG65wm-f4uX16X6MkQAAABw"]
[Thu Sep 17 15:27:49.122347 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/vue/.env"] [unique_id "aqxbVW65wm-f4uX16X6MnQAAABM"]
[Thu Sep 17 15:27:49.148228 2026] [security2:error] [pid 1029697:tid 1029859] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxbVW65wm-f4uX16X6MoQAAACA"]
[Thu Sep 17 15:27:49.233515 2026] [security2:error] [pid 1029697:tid 1029847] [client 134.185.85.61:55531] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "paltals.com"] [uri "/media/system/js/core.js"] [unique_id "aqxbVW65wm-f4uX16X6MqgAAABQ"]
[Thu Sep 17 15:27:49.282009 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/angular/.env"] [unique_id "aqxbVW65wm-f4uX16X6MsgAAAHg"]
[Thu Sep 17 15:27:49.287404 2026] [security2:error] [pid 1029697:tid 1029887] [client 185.226.198.6:45712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbVW65wm-f4uX16X6MngAAADw"]
[Thu Sep 17 15:27:49.315045 2026] [security2:error] [pid 1029697:tid 1029827] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxbVW65wm-f4uX16X6MtwAAAAA"]
[Thu Sep 17 15:27:49.443446 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/svelte/.env"] [unique_id "aqxbVW65wm-f4uX16X6MwwAAAGY"]
[Thu Sep 17 15:27:49.484033 2026] [security2:error] [pid 1029697:tid 1029920] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxbVW65wm-f4uX16X6MxgAAAF0"]
[Thu Sep 17 15:27:49.501268 2026] [security2:error] [pid 1029697:tid 1029862] [client 103.61.184.148:50737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbVW65wm-f4uX16X6MygAAACM"]
[Thu Sep 17 15:27:49.501381 2026] [security2:error] [pid 1029697:tid 1029862] [client 103.61.184.148:50737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbVW65wm-f4uX16X6MygAAACM"]
[Thu Sep 17 15:27:49.607134 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/vite/.env"] [unique_id "aqxbVW65wm-f4uX16X6MzgAAAHM"]
[Thu Sep 17 15:27:49.652629 2026] [security2:error] [pid 1029697:tid 1029930] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxbVW65wm-f4uX16X6M0QAAAGc"]
[Thu Sep 17 15:27:49.669036 2026] [security2:error] [pid 1029697:tid 1029927] [client 185.226.198.5:28940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbVW65wm-f4uX16X6MxQAAAGQ"]
[Thu Sep 17 15:27:49.752936 2026] [security2:error] [pid 1029697:tid 1029842] [client 43.157.153.236:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.153.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireflyhotglass.net"] [uri "/glass/wp-content/plugins/events-manager/multilingual/em-ml.php"] [unique_id "aqxbVW65wm-f4uX16X6M1QAAAA8"]
[Thu Sep 17 15:27:49.765111 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/backup/.env"] [unique_id "aqxbVW65wm-f4uX16X6M2QAAAGs"]
[Thu Sep 17 15:27:49.823972 2026] [security2:error] [pid 1029697:tid 1029892] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxbVW65wm-f4uX16X6M3AAAAEE"]
[Thu Sep 17 15:27:49.886091 2026] [security2:error] [pid 1029697:tid 1029946] [client 136.158.61.34:28475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbVW65wm-f4uX16X6M4QAAAHc"]
[Thu Sep 17 15:27:49.886219 2026] [security2:error] [pid 1029697:tid 1029946] [client 136.158.61.34:28475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbVW65wm-f4uX16X6M4QAAAHc"]
[Thu Sep 17 15:27:49.925017 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/backups/.env"] [unique_id "aqxbVW65wm-f4uX16X6M5AAAACE"]
[Thu Sep 17 15:27:49.939781 2026] [security2:error] [pid 1029697:tid 1029921] [client 185.226.198.4:30950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbVW65wm-f4uX16X6M2gAAAF4"]
[Thu Sep 17 15:27:49.994396 2026] [security2:error] [pid 1029697:tid 1029888] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxbVW65wm-f4uX16X6M6gAAAD0"]
[Thu Sep 17 15:27:50.085114 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/old/.env"] [unique_id "aqxbVm65wm-f4uX16X6M7wAAAHo"]
[Thu Sep 17 15:27:50.161482 2026] [security2:error] [pid 1029697:tid 1029924] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxbVm65wm-f4uX16X6M8gAAAGE"]
[Thu Sep 17 15:27:50.250398 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/tmp/.env"] [unique_id "aqxbVm65wm-f4uX16X6M9QAAABQ"]
[Thu Sep 17 15:27:50.322274 2026] [security2:error] [pid 1029697:tid 1029887] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxbVm65wm-f4uX16X6M-gAAADw"]
[Thu Sep 17 15:27:50.366036 2026] [security2:error] [pid 1029697:tid 1029827] [client 4.240.114.86:59955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxbVm65wm-f4uX16X6M_QAAAAA"], referer: binance.com
[Thu Sep 17 15:27:50.408368 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/temp/.env"] [unique_id "aqxbVm65wm-f4uX16X6M_wAAADc"]
[Thu Sep 17 15:27:50.483810 2026] [security2:error] [pid 1029697:tid 1029926] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxbVm65wm-f4uX16X6NAQAAAGM"]
[Thu Sep 17 15:27:50.566699 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/lab/.env"] [unique_id "aqxbVm65wm-f4uX16X6NBgAAACY"]
[Thu Sep 17 15:27:50.645318 2026] [security2:error] [pid 1029697:tid 1029903] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxbVm65wm-f4uX16X6NCwAAAEw"]
[Thu Sep 17 15:27:50.736045 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/cronlab/.env"] [unique_id "aqxbVm65wm-f4uX16X6NEgAAAFQ"]
[Thu Sep 17 15:27:50.806013 2026] [security2:error] [pid 1029697:tid 1029857] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxbVm65wm-f4uX16X6NHAAAAB4"]
[Thu Sep 17 15:27:50.891843 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/cron/.env"] [unique_id "aqxbVm65wm-f4uX16X6NIQAAAEs"]
[Thu Sep 17 15:27:50.968193 2026] [security2:error] [pid 1029697:tid 1029941] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxbVm65wm-f4uX16X6NJAAAAHI"]
[Thu Sep 17 15:27:51.055476 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/en/.env"] [unique_id "aqxbV265wm-f4uX16X6NKAAAADM"]
[Thu Sep 17 15:27:51.132310 2026] [security2:error] [pid 1029697:tid 1029928] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxbV265wm-f4uX16X6NLgAAAGU"]
[Thu Sep 17 15:27:51.288270 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/administrator/.env"] [unique_id "aqxbV265wm-f4uX16X6NMwAAAFI"]
[Thu Sep 17 15:27:51.293696 2026] [security2:error] [pid 1029697:tid 1029859] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxbV265wm-f4uX16X6NOgAAACA"]
[Thu Sep 17 15:27:51.298850 2026] [security2:error] [pid 1029697:tid 1029889] [client 185.226.198.7:38010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbV265wm-f4uX16X6NLQAAAD4"]
[Thu Sep 17 15:27:51.453485 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/psnlink/.env"] [unique_id "aqxbV265wm-f4uX16X6NRQAAACU"]
[Thu Sep 17 15:27:51.455812 2026] [security2:error] [pid 1029697:tid 1029832] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxbV265wm-f4uX16X6NRgAAAAU"]
[Thu Sep 17 15:27:51.615555 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/exapi/.env"] [unique_id "aqxbV265wm-f4uX16X6NTwAAADU"]
[Thu Sep 17 15:27:51.620785 2026] [security2:error] [pid 1029697:tid 1029833] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxbV265wm-f4uX16X6NUAAAAAY"]
[Thu Sep 17 15:27:51.769324 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/sitemaps/.env"] [unique_id "aqxbV265wm-f4uX16X6NWwAAAHQ"]
[Thu Sep 17 15:27:51.782557 2026] [security2:error] [pid 1029697:tid 1029936] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxbV265wm-f4uX16X6NXAAAAG0"]
[Thu Sep 17 15:27:51.944872 2026] [security2:error] [pid 1029697:tid 1029862] [client 35.198.3.220:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dit.kue.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxbV265wm-f4uX16X6NaQAAACM"]
[Thu Sep 17 15:27:52.151389 2026] [security2:error] [pid 1029697:tid 1029844] [client 35.198.3.220:46246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxbWG65wm-f4uX16X6NcAAAABE"]
[Thu Sep 17 15:27:52.340448 2026] [security2:error] [pid 1029697:tid 1029892] [client 34.154.239.243:52538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/logs/.env"] [unique_id "aqxbWG65wm-f4uX16X6NfgAAAEE"]
[Thu Sep 17 15:27:52.446410 2026] [security2:error] [pid 1029697:tid 1029903] [client 143.105.152.240:39947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbWG65wm-f4uX16X6NhAAAAEw"]
[Thu Sep 17 15:27:52.446506 2026] [security2:error] [pid 1029697:tid 1029903] [client 143.105.152.240:39947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbWG65wm-f4uX16X6NhAAAAEw"]
[Thu Sep 17 15:27:52.745655 2026] [security2:error] [pid 1029697:tid 1029949] [client 153.66.253.125:45394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbWG65wm-f4uX16X6NiQAAelg"]
[Thu Sep 17 15:27:52.768432 2026] [security2:error] [pid 1029697:tid 1029914] [client 82.223.49.247:46694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.shahzaibparacha.gocbeglobal.com"] [uri "/.env.old"] [unique_id "aqxbWG65wm-f4uX16X6NlwAAAFc"]
[Thu Sep 17 15:27:52.768612 2026] [security2:error] [pid 1029697:tid 1029858] [client 82.223.49.247:46722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.shahzaibparacha.gocbeglobal.com"] [uri "/.env.swp"] [unique_id "aqxbWG65wm-f4uX16X6NmAAAAB8"]
[Thu Sep 17 15:27:52.785100 2026] [security2:error] [pid 1029697:tid 1029856] [client 35.198.3.220:57352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/info.php"] [unique_id "aqxbWG65wm-f4uX16X6NmgAAAB0"]
[Thu Sep 17 15:27:52.802845 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/cache/.env"] [unique_id "aqxbWG65wm-f4uX16X6NnAAAAFI"]
[Thu Sep 17 15:27:52.864908 2026] [security2:error] [pid 1029697:tid 1029881] [client 169.58.197.253:63032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxbWG65wm-f4uX16X6NnwAAADY"], referer: binance.com
[Thu Sep 17 15:27:52.894114 2026] [security2:error] [pid 1029697:tid 1029891] [client 82.223.49.247:46672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.shahzaibparacha.gocbeglobal.com"] [uri "/.env"] [unique_id "aqxbWG65wm-f4uX16X6NpwAAAEA"]
[Thu Sep 17 15:27:52.926620 2026] [security2:error] [pid 1029697:tid 1029895] [client 82.223.49.247:46722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.shahzaibparacha.gocbeglobal.com"] [uri "/.env.backup"] [unique_id "aqxbWG65wm-f4uX16X6NqgAAAEQ"]
[Thu Sep 17 15:27:52.930318 2026] [security2:error] [pid 1029697:tid 1029931] [client 82.223.49.247:46694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.shahzaibparacha.gocbeglobal.com"] [uri "/.env.bak"] [unique_id "aqxbWG65wm-f4uX16X6NqwAAAGg"]
[Thu Sep 17 15:27:52.960225 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mailer/.env"] [unique_id "aqxbWG65wm-f4uX16X6NrgAAABw"]
[Thu Sep 17 15:27:52.966822 2026] [security2:error] [pid 1029697:tid 1029827] [client 4.240.114.86:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxbWG65wm-f4uX16X6NrwAAAAA"], referer: binance.com
[Thu Sep 17 15:27:53.115871 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mail/.env"] [unique_id "aqxbWW65wm-f4uX16X6NtQAAAEU"]
[Thu Sep 17 15:27:53.215912 2026] [security2:error] [pid 1029697:tid 1029847] [client 156.192.234.52:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbWW65wm-f4uX16X6NuwAAABQ"]
[Thu Sep 17 15:27:53.216028 2026] [security2:error] [pid 1029697:tid 1029847] [client 156.192.234.52:56222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbWW65wm-f4uX16X6NuwAAABQ"]
[Thu Sep 17 15:27:53.271408 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/email/.env"] [unique_id "aqxbWW65wm-f4uX16X6NwAAAAGw"]
[Thu Sep 17 15:27:53.275379 2026] [security2:error] [pid 1029697:tid 1029837] [client 35.198.3.220:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/php.php"] [unique_id "aqxbWW65wm-f4uX16X6NwQAAAAo"]
[Thu Sep 17 15:27:53.371658 2026] [security2:error] [pid 1029697:tid 1029850] [client 184.154.36.174:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "recessionnews.org"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxbWW65wm-f4uX16X6NygAAABc"]
[Thu Sep 17 15:27:53.402100 2026] [security2:error] [pid 1029697:tid 1029836] [client 184.154.36.174:57840] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "recessionnews.org"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxbWW65wm-f4uX16X6NxAAAAAk"]
[Thu Sep 17 15:27:53.427849 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/smtp/.env"] [unique_id "aqxbWW65wm-f4uX16X6NywAAAGs"]
[Thu Sep 17 15:27:53.514560 2026] [security2:error] [pid 1029697:tid 1029952] [client 185.117.225.196:34796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "mail.christchurchplymouth.org"] [uri "/robots.txt"] [unique_id "aqxbWW65wm-f4uX16X6NzgAAAH0"]
[Thu Sep 17 15:27:53.524313 2026] [security2:error] [pid 1029697:tid 1029871] [client 114.198.138.124:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbWW65wm-f4uX16X6NzwAAACw"]
[Thu Sep 17 15:27:53.524393 2026] [security2:error] [pid 1029697:tid 1029871] [client 114.198.138.124:59630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbWW65wm-f4uX16X6NzwAAACw"]
[Thu Sep 17 15:27:53.581790 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mailing/.env"] [unique_id "aqxbWW65wm-f4uX16X6N0QAAADM"]
[Thu Sep 17 15:27:53.718082 2026] [fcgid:warn] [pid 1029697:tid 1029860] (70014)End of file found: [client 107.150.101.57:36244] mod_fcgid: can't get data from http client
[Thu Sep 17 15:27:53.722904 2026] [security2:error] [pid 1029697:tid 1029880] [client 13.42.40.97:56292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.auxotech.com"] [uri "/cpc/theme/load_page.php"] [unique_id "aqxbWW65wm-f4uX16X6NtgAANWE"], referer: https://www.auxotech.com/cpc/
[Thu Sep 17 15:27:53.740275 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/notifications/.env"] [unique_id "aqxbWW65wm-f4uX16X6N2AAAAC8"]
[Thu Sep 17 15:27:53.782745 2026] [security2:error] [pid 1029697:tid 1029939] [client 35.198.3.220:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/i.php"] [unique_id "aqxbWW65wm-f4uX16X6N3QAAAHA"]
[Thu Sep 17 15:27:53.898957 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/notify/.env"] [unique_id "aqxbWW65wm-f4uX16X6N5AAAABY"]
[Thu Sep 17 15:27:54.052893 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/sender/.env"] [unique_id "aqxbWm65wm-f4uX16X6N6wAAADY"]
[Thu Sep 17 15:27:54.122655 2026] [security2:error] [pid 1029697:tid 1029946] [client 153.66.253.125:42615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbWm65wm-f4uX16X6N6gAAdys"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&hideanons=1&hidebots=0&hideminor=1&limit=500&target=The_Unseelie_Court&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:27:54.219558 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/campaign/.env"] [unique_id "aqxbWm65wm-f4uX16X6N9QAAAGg"]
[Thu Sep 17 15:27:54.295399 2026] [security2:error] [pid 1029697:tid 1029910] [client 35.198.3.220:57386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxbWm65wm-f4uX16X6N_AAAAFM"]
[Thu Sep 17 15:27:54.303998 2026] [security2:error] [pid 1029697:tid 1029940] [client 185.226.198.6:45726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbWm65wm-f4uX16X6N8gAAAHE"]
[Thu Sep 17 15:27:54.379678 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/newsletter/.env"] [unique_id "aqxbWm65wm-f4uX16X6OAAAAAEc"]
[Thu Sep 17 15:27:54.543249 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/ses/.env"] [unique_id "aqxbWm65wm-f4uX16X6OBgAAAFQ"]
[Thu Sep 17 15:27:54.697886 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/sendgrid/.env"] [unique_id "aqxbWm65wm-f4uX16X6ODwAAADs"]
[Thu Sep 17 15:27:54.791675 2026] [security2:error] [pid 1029697:tid 1029851] [client 35.198.3.220:57388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxbWm65wm-f4uX16X6OFwAAABg"]
[Thu Sep 17 15:27:54.836820 2026] [security2:error] [pid 1029697:tid 1029900] [client 193.189.100.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbWm65wm-f4uX16X6OEAAAAEk"]
[Thu Sep 17 15:27:54.852610 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/sparkpost/.env"] [unique_id "aqxbWm65wm-f4uX16X6OGwAAAA0"]
[Thu Sep 17 15:27:54.900322 2026] [security2:error] [pid 1029697:tid 1029838] [client 104.207.33.33:59985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.stevearensberg.com"] [uri "/wp-content/plugins/bookingpress-appointment-booking/readme.txt"] [unique_id "aqxbWm65wm-f4uX16X6OJwAAAAs"]
[Thu Sep 17 15:27:55.013609 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/postmark/.env"] [unique_id "aqxbW265wm-f4uX16X6OLAAAAD8"]
[Thu Sep 17 15:27:55.092827 2026] [security2:error] [pid 1029697:tid 1029938] [client 185.117.225.196:45634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "mail.christchurchplymouth.org"] [uri "/robots.txt"] [unique_id "aqxbW265wm-f4uX16X6OMAAAAG8"]
[Thu Sep 17 15:27:55.169245 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mailgun/.env"] [unique_id "aqxbW265wm-f4uX16X6ONwAAADY"]
[Thu Sep 17 15:27:55.283977 2026] [security2:error] [pid 1029697:tid 1029856] [client 35.198.3.220:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/test.php"] [unique_id "aqxbW265wm-f4uX16X6OQAAAAB0"]
[Thu Sep 17 15:27:55.323144 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mandrill/.env"] [unique_id "aqxbW265wm-f4uX16X6ORAAAAGE"]
[Thu Sep 17 15:27:55.476653 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mailjet/.env"] [unique_id "aqxbW265wm-f4uX16X6OTAAAAAY"]
[Thu Sep 17 15:27:55.640251 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/brevo/.env"] [unique_id "aqxbW265wm-f4uX16X6OVAAAAEc"]
[Thu Sep 17 15:27:55.770812 2026] [security2:error] [pid 1029697:tid 1029927] [client 5.189.145.112:57903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiansoncampusnlc.com"] [uri "/index.php"] [unique_id "aqxbW265wm-f4uX16X6OWAAAAGQ"], referer: binance.com
[Thu Sep 17 15:27:55.799764 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/transactional/.env"] [unique_id "aqxbW265wm-f4uX16X6OYAAAADI"]
[Thu Sep 17 15:27:55.911060 2026] [security2:error] [pid 1029697:tid 1029902] [client 4.240.114.86:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxbW265wm-f4uX16X6OZgAAAEs"], referer: binance.com
[Thu Sep 17 15:27:55.954691 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/bulk/.env"] [unique_id "aqxbW265wm-f4uX16X6OaAAAADs"]
[Thu Sep 17 15:27:55.970428 2026] [security2:error] [pid 1029697:tid 1029827] [client 35.198.3.220:57408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/p.php"] [unique_id "aqxbW265wm-f4uX16X6OagAAAAA"]
[Thu Sep 17 15:27:56.097246 2026] [security2:error] [pid 1029697:tid 1029900] [client 209.141.32.143:38500] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gruposink.sinkgp.com"] [uri "/wp-content/plugins/jetformbuilder/readme.txt"] [unique_id "aqxbXG65wm-f4uX16X6OcwAAAEk"]
[Thu Sep 17 15:27:56.108196 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/aws/.env"] [unique_id "aqxbXG65wm-f4uX16X6OdAAAAGw"]
[Thu Sep 17 15:27:56.275517 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/azure/.env"] [unique_id "aqxbXG65wm-f4uX16X6OgQAAAG8"]
[Thu Sep 17 15:27:56.429457 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/gcp/.env"] [unique_id "aqxbXG65wm-f4uX16X6OjwAAAGE"]
[Thu Sep 17 15:27:56.459928 2026] [security2:error] [pid 1029697:tid 1029859] [client 35.198.3.220:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxbXG65wm-f4uX16X6OkAAAACA"]
[Thu Sep 17 15:27:56.538133 2026] [core:error] [pid 1029697:tid 1029864] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://sdk.fwx.mybluehost.me/robots.txt
[Thu Sep 17 15:27:56.538154 2026] [core:error] [pid 1029697:tid 1029864] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://sdk.fwx.mybluehost.me/robots.txt
[Thu Sep 17 15:27:56.552473 2026] [security2:error] [pid 1029697:tid 1029856] [client 185.55.149.49:64268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbXG65wm-f4uX16X6OmgAAAB0"]
[Thu Sep 17 15:27:56.552562 2026] [security2:error] [pid 1029697:tid 1029856] [client 185.55.149.49:64268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbXG65wm-f4uX16X6OmgAAAB0"]
[Thu Sep 17 15:27:56.583824 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/cloud/.env"] [unique_id "aqxbXG65wm-f4uX16X6OmwAAAEU"]
[Thu Sep 17 15:27:56.739375 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/infrastructure/.env"] [unique_id "aqxbXG65wm-f4uX16X6OogAAAGM"]
[Thu Sep 17 15:27:56.893681 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/docker/.env"] [unique_id "aqxbXG65wm-f4uX16X6OqwAAABI"]
[Thu Sep 17 15:27:56.953719 2026] [security2:error] [pid 1029697:tid 1029831] [client 35.198.3.220:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxbXG65wm-f4uX16X6OrgAAAAQ"]
[Thu Sep 17 15:27:57.048023 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/k8s/.env"] [unique_id "aqxbXW65wm-f4uX16X6OtQAAAHY"]
[Thu Sep 17 15:27:57.204188 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/kubernetes/.env"] [unique_id "aqxbXW65wm-f4uX16X6OuwAAAAs"]
[Thu Sep 17 15:27:57.218888 2026] [security2:error] [pid 1029697:tid 1029915] [client 185.226.198.4:30958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbXW65wm-f4uX16X6OtAAAAFg"]
[Thu Sep 17 15:27:57.359988 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/terraform/.env"] [unique_id "aqxbXW65wm-f4uX16X6OxAAAAGs"]
[Thu Sep 17 15:27:57.455637 2026] [security2:error] [pid 1029697:tid 1029872] [client 35.198.3.220:57422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxbXW65wm-f4uX16X6OxwAAAC0"]
[Thu Sep 17 15:27:57.513696 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/ansible/.env"] [unique_id "aqxbXW65wm-f4uX16X6OzQAAAH4"]
[Thu Sep 17 15:27:57.561717 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.166.123.190:58882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/phpinfo.php"] [unique_id "aqxbXW65wm-f4uX16X6OzgAAABE"]
[Thu Sep 17 15:27:57.667589 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/.git/.env"] [unique_id "aqxbXW65wm-f4uX16X6O0QAAAE8"]
[Thu Sep 17 15:27:57.695927 2026] [security2:error] [pid 1029697:tid 1029905] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxbXG65wm-f4uX16X6OigAAAE4"]
[Thu Sep 17 15:27:57.801271 2026] [security2:error] [pid 1029697:tid 1029723] [remote 47.128.51.55:28046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gazillionmexico.com"] [uri "/robots.txt"] [unique_id "aqxbXW65wm-f4uX16X6O2AAAOBk"]
[Thu Sep 17 15:27:57.833066 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/ci/.env"] [unique_id "aqxbXW65wm-f4uX16X6O2QAAAFM"]
[Thu Sep 17 15:27:57.958698 2026] [security2:error] [pid 1029697:tid 1029909] [client 35.198.3.220:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxbXW65wm-f4uX16X6O5AAAAFI"]
[Thu Sep 17 15:27:57.991765 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/cd/.env"] [unique_id "aqxbXW65wm-f4uX16X6O6AAAAC8"]
[Thu Sep 17 15:27:58.024421 2026] [security2:error] [pid 1029697:tid 1029887] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxbXW65wm-f4uX16X6O4gAAADw"]
[Thu Sep 17 15:27:58.146475 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/jenkins/.env"] [unique_id "aqxbXm65wm-f4uX16X6O8AAAAAQ"]
[Thu Sep 17 15:27:58.234949 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.166.123.190:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/info.php"] [unique_id "aqxbXm65wm-f4uX16X6O9QAAAFs"]
[Thu Sep 17 15:27:58.270694 2026] [security2:error] [pid 1029697:tid 1029854] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxbXm65wm-f4uX16X6O8QAAABs"]
[Thu Sep 17 15:27:58.302423 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/gitlab/.env"] [unique_id "aqxbXm65wm-f4uX16X6O-QAAAH0"]
[Thu Sep 17 15:27:58.449697 2026] [security2:error] [pid 1029697:tid 1029855] [client 35.198.3.220:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxbXm65wm-f4uX16X6PAAAAABw"]
[Thu Sep 17 15:27:58.460880 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/github/.env"] [unique_id "aqxbXm65wm-f4uX16X6PAwAAADU"]
[Thu Sep 17 15:27:58.615176 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/actions/.env"] [unique_id "aqxbXm65wm-f4uX16X6PDAAAAC0"]
[Thu Sep 17 15:27:58.774159 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/circleci/.env"] [unique_id "aqxbXm65wm-f4uX16X6PFQAAAFk"]
[Thu Sep 17 15:27:58.785333 2026] [security2:error] [pid 1029697:tid 1029835] [client 4.240.114.86:64803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxbXm65wm-f4uX16X6PFwAAAAg"], referer: binance.com
[Thu Sep 17 15:27:58.923513 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.166.123.190:37808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/php.php"] [unique_id "aqxbXm65wm-f4uX16X6PIQAAACc"]
[Thu Sep 17 15:27:58.936824 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/travis/.env"] [unique_id "aqxbXm65wm-f4uX16X6PIwAAADg"]
[Thu Sep 17 15:27:58.938711 2026] [security2:error] [pid 1029697:tid 1029848] [client 35.198.3.220:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbXm65wm-f4uX16X6PJQAAABU"]
[Thu Sep 17 15:27:59.071591 2026] [security2:error] [pid 1029697:tid 1029856] [client 169.58.197.253:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxbX265wm-f4uX16X6PKQAAAB0"], referer: binance.com
[Thu Sep 17 15:27:59.091298 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/buildkite/.env"] [unique_id "aqxbX265wm-f4uX16X6PKgAAADk"]
[Thu Sep 17 15:27:59.262269 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mysql/.env"] [unique_id "aqxbX265wm-f4uX16X6PLwAAAGY"]
[Thu Sep 17 15:27:59.399793 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.166.123.190:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/phpinfo.php"] [unique_id "aqxbX265wm-f4uX16X6POgAAACw"]
[Thu Sep 17 15:27:59.420034 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/postgres/.env"] [unique_id "aqxbX265wm-f4uX16X6POwAAAAw"]
[Thu Sep 17 15:27:59.428503 2026] [security2:error] [pid 1029697:tid 1029845] [client 35.198.3.220:57548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxbX265wm-f4uX16X6PPAAAABI"]
[Thu Sep 17 15:27:59.578354 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/mongodb/.env"] [unique_id "aqxbX265wm-f4uX16X6PRgAAAFg"]
[Thu Sep 17 15:27:59.628249 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.166.123.190:37818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/i.php"] [unique_id "aqxbX265wm-f4uX16X6PSAAAAFY"]
[Thu Sep 17 15:27:59.702588 2026] [security2:error] [pid 1029697:tid 1029878] [client 185.226.198.7:24934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbX265wm-f4uX16X6PQgAAADM"]
[Thu Sep 17 15:27:59.731402 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/redis/.env"] [unique_id "aqxbX265wm-f4uX16X6PTQAAAEg"]
[Thu Sep 17 15:27:59.886184 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/elasticsearch/.env"] [unique_id "aqxbX265wm-f4uX16X6PWgAAAFM"]
[Thu Sep 17 15:28:00.041025 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/rabbitmq/.env"] [unique_id "aqxbYG65wm-f4uX16X6PYwAAACM"]
[Thu Sep 17 15:28:00.086817 2026] [security2:error] [pid 1029697:tid 1029887] [client 35.198.3.220:57554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxbYG65wm-f4uX16X6PZwAAADw"]
[Thu Sep 17 15:28:00.092493 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.166.123.190:37824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/info.php"] [unique_id "aqxbYG65wm-f4uX16X6PaAAAADY"]
[Thu Sep 17 15:28:00.197745 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/kafka/.env"] [unique_id "aqxbYG65wm-f4uX16X6PbgAAABs"]
[Thu Sep 17 15:28:00.280566 2026] [security2:error] [pid 1029697:tid 1029942] [client 103.61.184.148:51315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbYG65wm-f4uX16X6PcwAAAHM"]
[Thu Sep 17 15:28:00.282572 2026] [security2:error] [pid 1029697:tid 1029942] [client 103.61.184.148:51315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbYG65wm-f4uX16X6PcwAAAHM"]
[Thu Sep 17 15:28:00.336446 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.166.123.190:37830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/pi.php"] [unique_id "aqxbYG65wm-f4uX16X6PdgAAADc"]
[Thu Sep 17 15:28:00.354634 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/queue/.env"] [unique_id "aqxbYG65wm-f4uX16X6PeAAAABQ"]
[Thu Sep 17 15:28:00.515360 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/worker/.env"] [unique_id "aqxbYG65wm-f4uX16X6PfwAAADQ"]
[Thu Sep 17 15:28:00.579656 2026] [security2:error] [pid 1029697:tid 1029903] [client 35.198.3.220:57560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxbYG65wm-f4uX16X6PgAAAAEw"]
[Thu Sep 17 15:28:00.684397 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/job/.env"] [unique_id "aqxbYG65wm-f4uX16X6PgwAAAE4"]
[Thu Sep 17 15:28:00.782860 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.166.123.190:37834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/php.php"] [unique_id "aqxbYG65wm-f4uX16X6PigAAAFY"]
[Thu Sep 17 15:28:00.839175 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/test/.env"] [unique_id "aqxbYG65wm-f4uX16X6PjwAAAF8"]
[Thu Sep 17 15:28:00.989921 2026] [security2:error] [pid 1029697:tid 1029949] [client 51.83.237.175:56004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "brownsdailydose.com"] [uri "/robots.txt"] [unique_id "aqxbYG65wm-f4uX16X6PlQAAAHo"]
[Thu Sep 17 15:28:00.990062 2026] [security2:error] [pid 1029697:tid 1029949] [client 51.83.237.175:56004] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brownsdailydose.com"] [uri "/robots.txt"] [unique_id "aqxbYG65wm-f4uX16X6PlQAAAHo"]
[Thu Sep 17 15:28:00.994171 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/qa/.env"] [unique_id "aqxbYG65wm-f4uX16X6PlgAAABk"]
[Thu Sep 17 15:28:01.020159 2026] [security2:error] [pid 1029697:tid 1029953] [client 43.135.115.233:55494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxbX265wm-f4uX16X6PPwAAAH4"]
[Thu Sep 17 15:28:01.023776 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.166.123.190:37850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/pinfo.php"] [unique_id "aqxbYW65wm-f4uX16X6PmAAAAHE"]
[Thu Sep 17 15:28:01.081720 2026] [security2:error] [pid 1029697:tid 1029868] [client 35.198.3.220:57564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxbYW65wm-f4uX16X6PmgAAACk"]
[Thu Sep 17 15:28:01.161094 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/preview/.env"] [unique_id "aqxbYW65wm-f4uX16X6PngAAAGM"]
[Thu Sep 17 15:28:01.243056 2026] [security2:error] [pid 1029697:tid 1029911] [client 13.42.40.97:56293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.auxotech.com"] [uri "/cpc/theme/load_page.php"] [unique_id "aqxbYW65wm-f4uX16X6PnwAAVEA"], referer: https://www.auxotech.com/cpc/
[Thu Sep 17 15:28:01.317107 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/beta/.env"] [unique_id "aqxbYW65wm-f4uX16X6PpAAAAHw"]
[Thu Sep 17 15:28:01.405460 2026] [security2:error] [pid 1029697:tid 1029924] [client 4.240.114.86:49821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wp-view-config-data.php"] [unique_id "aqxbYW65wm-f4uX16X6PqAAAAGE"], referer: binance.com
[Thu Sep 17 15:28:01.410455 2026] [security2:error] [pid 1029697:tid 1029834] [client 112.86.225.121:57606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dfwservicesllc.com"] [uri "/"] [unique_id "aqxbYW65wm-f4uX16X6PqQAAAAc"]
[Thu Sep 17 15:28:01.410555 2026] [security2:error] [pid 1029697:tid 1029834] [client 112.86.225.121:57606] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dfwservicesllc.com"] [uri "/"] [unique_id "aqxbYW65wm-f4uX16X6PqQAAAAc"]
[Thu Sep 17 15:28:01.471949 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/uat/.env"] [unique_id "aqxbYW65wm-f4uX16X6PrQAAAGo"]
[Thu Sep 17 15:28:01.472176 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.166.123.190:41108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/i.php"] [unique_id "aqxbYW65wm-f4uX16X6PrgAAABs"]
[Thu Sep 17 15:28:01.573847 2026] [security2:error] [pid 1029697:tid 1029914] [client 35.198.3.220:57576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxbYW65wm-f4uX16X6PtQAAAFc"]
[Thu Sep 17 15:28:01.642088 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/stage/.env"] [unique_id "aqxbYW65wm-f4uX16X6PuAAAAHs"]
[Thu Sep 17 15:28:01.711638 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.166.123.190:41114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/test.php"] [unique_id "aqxbYW65wm-f4uX16X6PugAAACw"]
[Thu Sep 17 15:28:01.797102 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/development/.env"] [unique_id "aqxbYW65wm-f4uX16X6PwgAAAA8"]
[Thu Sep 17 15:28:01.950822 2026] [security2:error] [pid 1029697:tid 1029937] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/production/.env"] [unique_id "aqxbYW65wm-f4uX16X6PxgAAAG4"]
[Thu Sep 17 15:28:02.060341 2026] [security2:error] [pid 1029697:tid 1029844] [client 35.198.3.220:57586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxbYm65wm-f4uX16X6PywAAABE"]
[Thu Sep 17 15:28:02.105116 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.154.239.243:47162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.wamu.uk"] [uri "/config/app/.env"] [unique_id "aqxbYm65wm-f4uX16X6PzAAAABg"]
[Thu Sep 17 15:28:02.153677 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.166.123.190:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/pi.php"] [unique_id "aqxbYm65wm-f4uX16X6P0AAAAAo"]
[Thu Sep 17 15:28:02.259047 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.239.243:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/phpinfo.php"] [unique_id "aqxbYm65wm-f4uX16X6P0wAAAB4"]
[Thu Sep 17 15:28:02.400294 2026] [security2:error] [pid 1029697:tid 1029846] [client 136.158.61.34:29433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbYm65wm-f4uX16X6P3AAAABM"]
[Thu Sep 17 15:28:02.400411 2026] [security2:error] [pid 1029697:tid 1029846] [client 136.158.61.34:29433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbYm65wm-f4uX16X6P3AAAABM"]
[Thu Sep 17 15:28:02.554596 2026] [security2:error] [pid 1029697:tid 1029947] [client 35.198.3.220:57594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxbYm65wm-f4uX16X6P4gAAAHg"]
[Thu Sep 17 15:28:02.635721 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.166.123.190:41140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/p.php"] [unique_id "aqxbYm65wm-f4uX16X6P5gAAAAw"]
[Thu Sep 17 15:28:02.773139 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.239.243:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/info.php"] [unique_id "aqxbYm65wm-f4uX16X6P5wAAAAM"]
[Thu Sep 17 15:28:02.811974 2026] [security2:error] [pid 1029697:tid 1029881] [client 143.105.152.240:42470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbYm65wm-f4uX16X6P7AAAADY"]
[Thu Sep 17 15:28:02.812118 2026] [security2:error] [pid 1029697:tid 1029881] [client 143.105.152.240:42470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbYm65wm-f4uX16X6P7AAAADY"]
[Thu Sep 17 15:28:02.838892 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.166.123.190:41146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/pinfo.php"] [unique_id "aqxbYm65wm-f4uX16X6P7wAAABs"]
[Thu Sep 17 15:28:02.928095 2026] [core:error] [pid 1029697:tid 1029876] [client 107.189.3.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:02.928119 2026] [core:error] [pid 1029697:tid 1029876] [client 107.189.3.148:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:03.284905 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.239.243:45204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/php.php"] [unique_id "aqxbY265wm-f4uX16X6QBAAAACc"]
[Thu Sep 17 15:28:03.313462 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.166.123.190:41158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/debug.php"] [unique_id "aqxbY265wm-f4uX16X6QCAAAAHQ"]
[Thu Sep 17 15:28:03.373224 2026] [security2:error] [pid 1029697:tid 1029837] [client 35.198.3.220:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbY265wm-f4uX16X6QEAAAAAo"]
[Thu Sep 17 15:28:03.460393 2026] [security2:error] [pid 1029697:tid 1029858] [client 185.226.198.4:32542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbY265wm-f4uX16X6QAgAAAB8"]
[Thu Sep 17 15:28:03.462174 2026] [security2:error] [pid 1029697:tid 1029884] [client 192.227.237.44:50822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.heromakers.org"] [uri "/index.php"] [unique_id "aqxbY265wm-f4uX16X6QAwAAOUI"]
[Thu Sep 17 15:28:03.464178 2026] [security2:error] [pid 1029697:tid 1029851] [client 213.22.153.202:39894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbY265wm-f4uX16X6QDQAAGC4"]
[Thu Sep 17 15:28:03.515157 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.166.123.190:41174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/test.php"] [unique_id "aqxbY265wm-f4uX16X6QIAAAAH0"]
[Thu Sep 17 15:28:03.515766 2026] [security2:error] [pid 1029697:tid 1029877] [client 3.82.141.143:21540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bluecollarbiblicalscholar.com"] [uri "/wp-config.php"] [unique_id "aqxbY265wm-f4uX16X6QIgAAADI"]
[Thu Sep 17 15:28:03.516109 2026] [security2:error] [pid 1029697:tid 1029868] [client 3.82.141.143:21568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.bluecollarbiblicalscholar.com"] [uri "/wp-config.php.old"] [unique_id "aqxbY265wm-f4uX16X6QJAAAACk"]
[Thu Sep 17 15:28:03.516184 2026] [security2:error] [pid 1029697:tid 1029927] [client 3.82.141.143:21584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.bluecollarbiblicalscholar.com"] [uri "/wp-config.php.save"] [unique_id "aqxbY265wm-f4uX16X6QJgAAAGQ"]
[Thu Sep 17 15:28:03.519339 2026] [security2:error] [pid 1029697:tid 1029885] [client 3.82.141.143:21552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.bluecollarbiblicalscholar.com"] [uri "/wp-config.php.bak"] [unique_id "aqxbY265wm-f4uX16X6QKQAAADo"]
[Thu Sep 17 15:28:03.536518 2026] [security2:error] [pid 1029697:tid 1029839] [client 3.82.141.143:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bluecollarbiblicalscholar.com"] [uri "/config.php"] [unique_id "aqxbY265wm-f4uX16X6QOwAAAAw"]
[Thu Sep 17 15:28:03.537103 2026] [security2:error] [pid 1029697:tid 1029926] [client 3.82.141.143:21606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.bluecollarbiblicalscholar.com"] [uri "/wp-config.php~"] [unique_id "aqxbY265wm-f4uX16X6QPAAAAGM"]
[Thu Sep 17 15:28:03.760316 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.154.239.243:45220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/i.php"] [unique_id "aqxbY265wm-f4uX16X6QSgAAAFg"]
[Thu Sep 17 15:28:03.799432 2026] [security2:error] [pid 1029697:tid 1029945] [client 156.192.234.52:56827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbY265wm-f4uX16X6QSwAAAHY"]
[Thu Sep 17 15:28:03.799996 2026] [security2:error] [pid 1029697:tid 1029945] [client 156.192.234.52:56827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbY265wm-f4uX16X6QSwAAAHY"]
[Thu Sep 17 15:28:03.891327 2026] [security2:error] [pid 1029697:tid 1029943] [client 35.198.3.220:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxbY265wm-f4uX16X6QUwAAAHQ"]
[Thu Sep 17 15:28:03.997242 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.166.123.190:41186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbY265wm-f4uX16X6QWwAAAHo"]
[Thu Sep 17 15:28:04.127883 2026] [security2:error] [pid 1029697:tid 1029927] [client 114.198.138.124:60465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbZG65wm-f4uX16X6QXgAAAGQ"]
[Thu Sep 17 15:28:04.128028 2026] [security2:error] [pid 1029697:tid 1029927] [client 114.198.138.124:60465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbZG65wm-f4uX16X6QXgAAAGQ"]
[Thu Sep 17 15:28:04.229496 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.154.239.243:45230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/pi.php"] [unique_id "aqxbZG65wm-f4uX16X6QYQAAAHE"]
[Thu Sep 17 15:28:04.303715 2026] [core:error] [pid 1029697:tid 1029854] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://sdk.fwx.mybluehost.me/sitemap.xml
[Thu Sep 17 15:28:04.303737 2026] [core:error] [pid 1029697:tid 1029854] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://sdk.fwx.mybluehost.me/sitemap.xml
[Thu Sep 17 15:28:04.366410 2026] [security2:error] [pid 1029697:tid 1029939] [client 4.240.114.86:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxbZG65wm-f4uX16X6QbwAAAHA"], referer: binance.com
[Thu Sep 17 15:28:04.406653 2026] [security2:error] [pid 1029697:tid 1029920] [client 35.198.3.220:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbZG65wm-f4uX16X6QcQAAAF0"]
[Thu Sep 17 15:28:04.439912 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.166.123.190:41200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/p.php"] [unique_id "aqxbZG65wm-f4uX16X6QcgAAAC8"]
[Thu Sep 17 15:28:04.683435 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.166.123.190:41214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbZG65wm-f4uX16X6QewAAAFY"]
[Thu Sep 17 15:28:04.706493 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.154.239.243:45234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/pinfo.php"] [unique_id "aqxbZG65wm-f4uX16X6QfAAAAFg"]
[Thu Sep 17 15:28:04.920562 2026] [security2:error] [pid 1029697:tid 1029910] [client 35.198.3.220:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbZG65wm-f4uX16X6QkwAAAFM"]
[Thu Sep 17 15:28:05.140820 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.166.123.190:41228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/debug.php"] [unique_id "aqxbZW65wm-f4uX16X6QpQAAAAM"]
[Thu Sep 17 15:28:05.173720 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.239.243:45248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/test.php"] [unique_id "aqxbZW65wm-f4uX16X6QtQAAAD8"]
[Thu Sep 17 15:28:05.325718 2026] [security2:error] [pid 1029697:tid 1029878] [client 183.82.103.31:58756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbZW65wm-f4uX16X6QswAAM2w"]
[Thu Sep 17 15:28:05.373457 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.166.123.190:41230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbZW65wm-f4uX16X6QywAAAC0"]
[Thu Sep 17 15:28:05.426167 2026] [security2:error] [pid 1029697:tid 1029897] [client 35.198.3.220:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbZW65wm-f4uX16X6QzwAAAEY"]
[Thu Sep 17 15:28:05.848609 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.166.123.190:41246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbZW65wm-f4uX16X6Q4wAAAF0"]
[Thu Sep 17 15:28:05.864419 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.154.239.243:45258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/p.php"] [unique_id "aqxbZW65wm-f4uX16X6Q5AAAACg"]
[Thu Sep 17 15:28:05.915146 2026] [security2:error] [pid 1029697:tid 1029833] [client 35.198.3.220:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbZW65wm-f4uX16X6Q5wAAAAY"]
[Thu Sep 17 15:28:06.110785 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.166.123.190:41250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbZm65wm-f4uX16X6Q7wAAACM"]
[Thu Sep 17 15:28:06.342392 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.154.239.243:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/debug.php"] [unique_id "aqxbZm65wm-f4uX16X6RAAAAACo"]
[Thu Sep 17 15:28:06.432878 2026] [security2:error] [pid 1029697:tid 1029952] [client 35.198.3.220:57674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxbZm65wm-f4uX16X6RAgAAAH0"]
[Thu Sep 17 15:28:06.550047 2026] [security2:error] [pid 1029697:tid 1029938] [client 185.226.198.7:24952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbZm65wm-f4uX16X6RAQAAAG8"]
[Thu Sep 17 15:28:06.564535 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.166.123.190:41258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbZm65wm-f4uX16X6RBwAAAEI"]
[Thu Sep 17 15:28:06.799651 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.166.123.190:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbZm65wm-f4uX16X6RFQAAACw"]
[Thu Sep 17 15:28:06.816327 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.154.239.243:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/admin/phpinfo.php"] [unique_id "aqxbZm65wm-f4uX16X6RFgAAAEw"]
[Thu Sep 17 15:28:06.837301 2026] [access_compat:error] [pid 1029697:tid 1029940] [client 159.69.14.98:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/feed
[Thu Sep 17 15:28:06.898111 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.95.14.119:42906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxbZm65wm-f4uX16X6RGwAAAB4"]
[Thu Sep 17 15:28:06.918655 2026] [security2:error] [pid 1029697:tid 1029900] [client 35.198.3.220:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxbZm65wm-f4uX16X6RHAAAAEk"]
[Thu Sep 17 15:28:07.257780 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.166.123.190:41282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbZ265wm-f4uX16X6RJgAAAC4"]
[Thu Sep 17 15:28:07.262371 2026] [security2:error] [pid 1029697:tid 1029906] [client 185.55.149.49:64920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbZ265wm-f4uX16X6RJAAAAE8"]
[Thu Sep 17 15:28:07.262477 2026] [security2:error] [pid 1029697:tid 1029906] [client 185.55.149.49:64920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbZ265wm-f4uX16X6RJAAAAE8"]
[Thu Sep 17 15:28:07.279093 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.154.239.243:45304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/test/phpinfo.php"] [unique_id "aqxbZ265wm-f4uX16X6RKgAAAAU"]
[Thu Sep 17 15:28:07.281263 2026] [core:error] [pid 1029697:tid 1029833] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:07.281279 2026] [core:error] [pid 1029697:tid 1029833] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:07.306345 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.95.14.119:42918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/info.php"] [unique_id "aqxbZ265wm-f4uX16X6RKwAAAF0"]
[Thu Sep 17 15:28:07.402745 2026] [security2:error] [pid 1029697:tid 1029882] [client 35.198.3.220:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxbZ265wm-f4uX16X6RMQAAADc"]
[Thu Sep 17 15:28:07.416259 2026] [security2:error] [pid 1029697:tid 1029894] [client 119.28.89.249:60564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxbZ265wm-f4uX16X6RLwAAAEM"]
[Thu Sep 17 15:28:07.483065 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.166.123.190:41284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbZ265wm-f4uX16X6RMwAAADw"]
[Thu Sep 17 15:28:07.591600 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.95.14.119:42930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/php.php"] [unique_id "aqxbZ265wm-f4uX16X6RNgAAAHQ"]
[Thu Sep 17 15:28:07.758509 2026] [core:error] [pid 1029697:tid 1029935] [client 23.180.120.146:40426] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:07.758531 2026] [core:error] [pid 1029697:tid 1029935] [client 23.180.120.146:40426] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:07.761702 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.154.239.243:45306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/dev/phpinfo.php"] [unique_id "aqxbZ265wm-f4uX16X6ROwAAAH4"]
[Thu Sep 17 15:28:07.888085 2026] [security2:error] [pid 1029697:tid 1029870] [client 35.198.3.220:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxbZ265wm-f4uX16X6RPwAAACs"]
[Thu Sep 17 15:28:07.938919 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.166.123.190:41286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbZ265wm-f4uX16X6RQAAAAFg"]
[Thu Sep 17 15:28:07.939493 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.95.14.119:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/i.php"] [unique_id "aqxbZ265wm-f4uX16X6RQQAAADI"]
[Thu Sep 17 15:28:08.063260 2026] [security2:error] [pid 1029697:tid 1029908] [client 4.240.114.86:53482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxbaG65wm-f4uX16X6RRQAAAFE"], referer: binance.com
[Thu Sep 17 15:28:08.201249 2026] [security2:error] [pid 1029697:tid 1029736] [remote 17.166.20.216:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.20.166.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ccrmediator.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxbaG65wm-f4uX16X6RSAAALCY"], referer: https://ccrmediator.com/lincoln-on-litigation-and-lawyers-as-peacemakers/
[Thu Sep 17 15:28:08.226999 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.95.14.119:35258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxbaG65wm-f4uX16X6RTAAAAE4"]
[Thu Sep 17 15:28:08.232271 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.154.239.243:33740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/old/phpinfo.php"] [unique_id "aqxbaG65wm-f4uX16X6RTQAAAEg"]
[Thu Sep 17 15:28:08.375231 2026] [security2:error] [pid 1029697:tid 1029883] [client 35.198.3.220:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxbaG65wm-f4uX16X6RVAAAADg"]
[Thu Sep 17 15:28:08.402634 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.166.123.190:41298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/php-info.php"] [unique_id "aqxbaG65wm-f4uX16X6RVQAAAHw"]
[Thu Sep 17 15:28:08.473884 2026] [core:error] [pid 1029697:tid 1029904] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:08.473902 2026] [core:error] [pid 1029697:tid 1029904] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:08.482361 2026] [security2:error] [pid 1029697:tid 1029939] [client 169.58.197.253:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxbaG65wm-f4uX16X6RWAAAAHA"], referer: binance.com
[Thu Sep 17 15:28:08.624450 2026] [security2:error] [pid 1029697:tid 1029768] [remote 157.55.39.200:52699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mtbclubdecampo.com"] [uri "/calendario.php"] [unique_id "aqxbaG65wm-f4uX16X6RWQAABkY"]
[Thu Sep 17 15:28:08.639030 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.166.123.190:41314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbaG65wm-f4uX16X6RWgAAABI"]
[Thu Sep 17 15:28:08.640210 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.95.14.119:35264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxbaG65wm-f4uX16X6RWwAAABc"]
[Thu Sep 17 15:28:08.748730 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.154.239.243:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbaG65wm-f4uX16X6RXQAAAFI"]
[Thu Sep 17 15:28:08.879553 2026] [security2:error] [pid 1029697:tid 1029835] [client 35.198.3.220:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxbaG65wm-f4uX16X6RYQAAAAg"]
[Thu Sep 17 15:28:09.100509 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.166.123.190:41322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/phpversion.php"] [unique_id "aqxbaW65wm-f4uX16X6RaQAAABg"]
[Thu Sep 17 15:28:09.125864 2026] [security2:error] [pid 1029697:tid 1029912] [client 185.226.198.4:46740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbaG65wm-f4uX16X6RYwAAAFU"]
[Thu Sep 17 15:28:09.147991 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.95.14.119:35280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/test.php"] [unique_id "aqxbaW65wm-f4uX16X6RagAAAFw"]
[Thu Sep 17 15:28:09.224398 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.154.239.243:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/public/phpinfo.php"] [unique_id "aqxbaW65wm-f4uX16X6RbAAAAGA"]
[Thu Sep 17 15:28:09.338208 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.166.123.190:41324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbaW65wm-f4uX16X6RbwAAAFc"]
[Thu Sep 17 15:28:09.373212 2026] [security2:error] [pid 1029697:tid 1029885] [client 35.198.3.220:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxbaW65wm-f4uX16X6RcQAAADo"]
[Thu Sep 17 15:28:09.687824 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.95.14.119:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/p.php"] [unique_id "aqxbaW65wm-f4uX16X6RewAAACw"]
[Thu Sep 17 15:28:09.794020 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.166.123.190:41338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/_phpinfo.php"] [unique_id "aqxbaW65wm-f4uX16X6RhAAAAA0"]
[Thu Sep 17 15:28:09.879684 2026] [security2:error] [pid 1029697:tid 1029940] [client 35.198.3.220:56856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxbaW65wm-f4uX16X6RhgAAAHE"]
[Thu Sep 17 15:28:09.928749 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.166.228.3:54562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/phpinfo.php"] [unique_id "aqxbaW65wm-f4uX16X6RiAAAAD8"]
[Thu Sep 17 15:28:09.957104 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.154.239.243:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/php-info.php"] [unique_id "aqxbaW65wm-f4uX16X6RiwAAAEY"]
[Thu Sep 17 15:28:10.028352 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.95.14.119:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxbam65wm-f4uX16X6RjQAAAHI"]
[Thu Sep 17 15:28:10.250681 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.166.123.190:41342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/php-info.php"] [unique_id "aqxbam65wm-f4uX16X6RkwAAADU"]
[Thu Sep 17 15:28:10.366161 2026] [security2:error] [pid 1029697:tid 1029850] [client 35.198.3.220:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxbam65wm-f4uX16X6RlwAAABc"]
[Thu Sep 17 15:28:10.418416 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.95.14.119:35308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxbam65wm-f4uX16X6RmAAAAHY"]
[Thu Sep 17 15:28:10.435910 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.154.239.243:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/phpversion.php"] [unique_id "aqxbam65wm-f4uX16X6RmgAAAFI"]
[Thu Sep 17 15:28:10.489749 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.166.123.190:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbam65wm-f4uX16X6RnAAAAGY"]
[Thu Sep 17 15:28:10.608432 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.166.228.3:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/info.php"] [unique_id "aqxbam65wm-f4uX16X6RngAAACQ"]
[Thu Sep 17 15:28:10.710492 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.95.14.119:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxbam65wm-f4uX16X6RnwAAAGA"]
[Thu Sep 17 15:28:10.864308 2026] [security2:error] [pid 1029697:tid 1029852] [client 35.198.3.220:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxbam65wm-f4uX16X6RpgAAABk"]
[Thu Sep 17 15:28:10.929557 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.154.239.243:33772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/_phpinfo.php"] [unique_id "aqxbam65wm-f4uX16X6RqQAAAGk"]
[Thu Sep 17 15:28:10.957432 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.166.123.190:41356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/phpversion.php"] [unique_id "aqxbam65wm-f4uX16X6RqgAAADI"]
[Thu Sep 17 15:28:11.021045 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.95.14.119:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6RrQAAAC8"]
[Thu Sep 17 15:28:11.140012 2026] [security2:error] [pid 1029697:tid 1029914] [client 103.61.184.148:51891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxba265wm-f4uX16X6RswAAAFc"]
[Thu Sep 17 15:28:11.140101 2026] [security2:error] [pid 1029697:tid 1029914] [client 103.61.184.148:51891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxba265wm-f4uX16X6RswAAAFc"]
[Thu Sep 17 15:28:11.189885 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.166.123.190:41368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/server-info.php"] [unique_id "aqxba265wm-f4uX16X6RtgAAACk"]
[Thu Sep 17 15:28:11.292789 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.166.228.3:34602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/php.php"] [unique_id "aqxba265wm-f4uX16X6RugAAAFg"]
[Thu Sep 17 15:28:11.361063 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.95.14.119:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6RvAAAAD8"]
[Thu Sep 17 15:28:11.374690 2026] [security2:error] [pid 1029697:tid 1029940] [client 35.198.3.220:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6RvgAAAHE"]
[Thu Sep 17 15:28:11.404641 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.154.239.243:33776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/old_phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6RvwAAADA"]
[Thu Sep 17 15:28:11.640110 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.166.123.190:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/_phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6RxQAAAFQ"]
[Thu Sep 17 15:28:11.664727 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.95.14.119:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6RxgAAAE8"]
[Thu Sep 17 15:28:11.869235 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.166.123.190:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/server-status.php"] [unique_id "aqxba265wm-f4uX16X6R0AAAACc"]
[Thu Sep 17 15:28:11.873070 2026] [security2:error] [pid 1029697:tid 1029937] [client 35.198.3.220:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6R0QAAAG4"]
[Thu Sep 17 15:28:11.957057 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.154.239.243:33782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/server-info.php"] [unique_id "aqxba265wm-f4uX16X6R0wAAAAg"]
[Thu Sep 17 15:28:11.976150 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.95.14.119:35370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxba265wm-f4uX16X6R1AAAAGY"]
[Thu Sep 17 15:28:12.021367 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.166.228.3:34606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/i.php"] [unique_id "aqxbbG65wm-f4uX16X6R1QAAAAc"]
[Thu Sep 17 15:28:12.320179 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.166.123.190:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbbG65wm-f4uX16X6R3gAAAH4"]
[Thu Sep 17 15:28:12.373160 2026] [security2:error] [pid 1029697:tid 1029954] [client 35.198.3.220:56896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbbG65wm-f4uX16X6R4wAAAH8"]
[Thu Sep 17 15:28:12.468827 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.95.14.119:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxbbG65wm-f4uX16X6R5gAAADI"]
[Thu Sep 17 15:28:12.471961 2026] [access_compat:error] [pid 1029697:tid 1029872] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/tidy-mart
[Thu Sep 17 15:28:12.485813 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.154.239.243:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/server-status.php"] [unique_id "aqxbbG65wm-f4uX16X6R6AAAAHM"]
[Thu Sep 17 15:28:12.700064 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.166.228.3:51986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/pi.php"] [unique_id "aqxbbG65wm-f4uX16X6R6wAAAB8"]
[Thu Sep 17 15:28:12.829353 2026] [security2:error] [pid 1029697:tid 1029899] [client 185.226.198.6:58920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbbG65wm-f4uX16X6R6gAAAEg"]
[Thu Sep 17 15:28:12.867352 2026] [security2:error] [pid 1029697:tid 1029938] [client 35.198.3.220:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxbbG65wm-f4uX16X6R8wAAAG8"]
[Thu Sep 17 15:28:12.891599 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.95.14.119:35394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxbbG65wm-f4uX16X6R9AAAAGo"]
[Thu Sep 17 15:28:12.947831 2026] [security2:error] [pid 1029697:tid 1029856] [client 4.240.114.86:56091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxbbG65wm-f4uX16X6R9QAAAB0"], referer: binance.com
[Thu Sep 17 15:28:13.018029 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.166.123.190:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbbW65wm-f4uX16X6SFgAAAD4"]
[Thu Sep 17 15:28:13.029964 2026] [security2:error] [pid 1029697:tid 1029868] [client 34.166.123.190:52856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/server-info.php"] [unique_id "aqxbbW65wm-f4uX16X6SGgAAACk"]
[Thu Sep 17 15:28:13.247236 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.95.14.119:35406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxbbW65wm-f4uX16X6SIQAAAF8"]
[Thu Sep 17 15:28:13.378885 2026] [security2:error] [pid 1029697:tid 1029837] [client 35.198.3.220:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxbbW65wm-f4uX16X6SJAAAAAo"]
[Thu Sep 17 15:28:13.402291 2026] [security2:error] [pid 1029697:tid 1029940] [client 143.105.152.240:44047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbbW65wm-f4uX16X6SJQAAAHE"]
[Thu Sep 17 15:28:13.403599 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.166.228.3:52000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/pinfo.php"] [unique_id "aqxbbW65wm-f4uX16X6SJgAAAHA"]
[Thu Sep 17 15:28:13.404442 2026] [security2:error] [pid 1029697:tid 1029940] [client 143.105.152.240:44047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbbW65wm-f4uX16X6SJQAAAHE"]
[Thu Sep 17 15:28:13.414793 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.154.239.243:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbbW65wm-f4uX16X6SJwAAAEs"]
[Thu Sep 17 15:28:13.561835 2026] [security2:error] [pid 1029697:tid 1029950] [client 170.106.163.48:40800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.163.106.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acc.edu.ai"] [uri "/xmlrpc.php"] [unique_id "aqxbbW65wm-f4uX16X6SKQAAAHs"]
[Thu Sep 17 15:28:13.614296 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.95.14.119:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxbbW65wm-f4uX16X6SLgAAACo"]
[Thu Sep 17 15:28:13.701173 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.166.123.190:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbbW65wm-f4uX16X6SLwAAAGU"]
[Thu Sep 17 15:28:13.717353 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.166.123.190:52874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/server-status.php"] [unique_id "aqxbbW65wm-f4uX16X6SMAAAAAI"]
[Thu Sep 17 15:28:13.884687 2026] [security2:error] [pid 1029697:tid 1029936] [client 35.198.3.220:56918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbbW65wm-f4uX16X6SNwAAAG0"]
[Thu Sep 17 15:28:13.910943 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.239.243:33802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/mail/phpinfo.php"] [unique_id "aqxbbW65wm-f4uX16X6SOAAAABI"]
[Thu Sep 17 15:28:14.056848 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.95.14.119:35428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxbbm65wm-f4uX16X6SOwAAAH4"]
[Thu Sep 17 15:28:14.110533 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.166.228.3:52004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/test.php"] [unique_id "aqxbbm65wm-f4uX16X6SPQAAAGA"]
[Thu Sep 17 15:28:14.354040 2026] [security2:error] [pid 1029697:tid 1029852] [client 156.192.234.52:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbbm65wm-f4uX16X6SRwAAABk"]
[Thu Sep 17 15:28:14.360309 2026] [security2:error] [pid 1029697:tid 1029852] [client 156.192.234.52:57436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbbm65wm-f4uX16X6SRwAAABk"]
[Thu Sep 17 15:28:14.397060 2026] [security2:error] [pid 1029697:tid 1029879] [client 35.198.3.220:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbbm65wm-f4uX16X6SSQAAADQ"]
[Thu Sep 17 15:28:14.405170 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.166.123.190:52886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbbm65wm-f4uX16X6SSwAAAHQ"]
[Thu Sep 17 15:28:14.407491 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.154.239.243:33810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbbm65wm-f4uX16X6STAAAACA"]
[Thu Sep 17 15:28:14.477911 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.95.14.119:35444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxbbm65wm-f4uX16X6SUQAAACI"]
[Thu Sep 17 15:28:14.722225 2026] [security2:error] [pid 1029697:tid 1029864] [client 136.158.61.34:30381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbbm65wm-f4uX16X6SWAAAACU"]
[Thu Sep 17 15:28:14.722357 2026] [security2:error] [pid 1029697:tid 1029864] [client 136.158.61.34:30381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbbm65wm-f4uX16X6SWAAAACU"]
[Thu Sep 17 15:28:14.772785 2026] [security2:error] [pid 1029697:tid 1029849] [client 114.198.138.124:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbbm65wm-f4uX16X6SWQAAABY"]
[Thu Sep 17 15:28:14.772923 2026] [security2:error] [pid 1029697:tid 1029849] [client 114.198.138.124:61227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbbm65wm-f4uX16X6SWQAAABY"]
[Thu Sep 17 15:28:14.877784 2026] [security2:error] [pid 1029697:tid 1029946] [client 35.198.3.220:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxbbm65wm-f4uX16X6SYgAAAHc"]
[Thu Sep 17 15:28:14.913313 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.166.123.190:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbbm65wm-f4uX16X6SZQAAAHI"]
[Thu Sep 17 15:28:14.918978 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.154.239.243:33816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbbm65wm-f4uX16X6SZwAAAAU"]
[Thu Sep 17 15:28:15.042299 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.95.14.119:35450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbb265wm-f4uX16X6SbAAAAEc"]
[Thu Sep 17 15:28:15.048323 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.166.228.3:52018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/p.php"] [unique_id "aqxbb265wm-f4uX16X6SbQAAACM"]
[Thu Sep 17 15:28:15.092670 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.166.123.190:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6SbgAAAA8"]
[Thu Sep 17 15:28:15.363989 2026] [security2:error] [pid 1029697:tid 1029866] [client 121.229.156.122:38018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "talent-in-borders.com"] [uri "/"] [unique_id "aqxbb265wm-f4uX16X6ScgAAACc"]
[Thu Sep 17 15:28:15.364107 2026] [security2:error] [pid 1029697:tid 1029866] [client 121.229.156.122:38018] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "talent-in-borders.com"] [uri "/"] [unique_id "aqxbb265wm-f4uX16X6ScgAAACc"]
[Thu Sep 17 15:28:15.366715 2026] [security2:error] [pid 1029697:tid 1029834] [client 35.198.3.220:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.3.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dit.kue.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6ScwAAAAc"]
[Thu Sep 17 15:28:15.392424 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.95.14.119:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6SdQAAACQ"]
[Thu Sep 17 15:28:15.402895 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.239.243:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6SdgAAAGU"]
[Thu Sep 17 15:28:15.592100 2026] [security2:error] [pid 1029697:tid 1029932] [client 193.189.100.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbb265wm-f4uX16X6SeQAAAGk"]
[Thu Sep 17 15:28:15.709029 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.166.123.190:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6SfAAAAHg"]
[Thu Sep 17 15:28:15.727328 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.166.228.3:52034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/debug.php"] [unique_id "aqxbb265wm-f4uX16X6SfQAAADI"]
[Thu Sep 17 15:28:15.755360 2026] [security2:error] [pid 1029697:tid 1029926] [client 185.226.198.7:18612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "aqxbb265wm-f4uX16X6SfgAAAGM"]
[Thu Sep 17 15:28:15.759133 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.95.14.119:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6SfwAAADo"]
[Thu Sep 17 15:28:15.815810 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.166.123.190:52922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6SggAAAH4"]
[Thu Sep 17 15:28:15.895768 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.239.243:33832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbb265wm-f4uX16X6ShgAAAAM"]
[Thu Sep 17 15:28:16.213108 2026] [security2:error] [pid 1029697:tid 1029897] [client 105.113.70.172:28601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbcG65wm-f4uX16X6SjAAARlc"]
[Thu Sep 17 15:28:16.220796 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.95.14.119:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbcG65wm-f4uX16X6SkwAAAB0"]
[Thu Sep 17 15:28:16.396718 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.154.239.243:33840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/phpinfo.php.bak"] [unique_id "aqxbcG65wm-f4uX16X6SmwAAAF8"]
[Thu Sep 17 15:28:16.406850 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.166.123.190:52930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbcG65wm-f4uX16X6SnAAAAEI"]
[Thu Sep 17 15:28:16.410254 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.166.228.3:52048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbcG65wm-f4uX16X6SnQAAACU"]
[Thu Sep 17 15:28:16.518499 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.166.123.190:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbcG65wm-f4uX16X6SnwAAAD0"]
[Thu Sep 17 15:28:16.521808 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.95.14.119:35486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbcG65wm-f4uX16X6SoAAAABM"]
[Thu Sep 17 15:28:16.733165 2026] [security2:error] [pid 1029697:tid 1029841] [client 162.241.226.11:55168] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxbcG65wm-f4uX16X6SrwAAAA4"]
[Thu Sep 17 15:28:16.899091 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.154.239.243:33852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/phpinfo.php.old"] [unique_id "aqxbcG65wm-f4uX16X6SwgAAAEk"]
[Thu Sep 17 15:28:16.909321 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.95.14.119:35494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbcG65wm-f4uX16X6SxAAAAH0"]
[Thu Sep 17 15:28:17.091131 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.166.228.3:52050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbcW65wm-f4uX16X6SzQAAAH8"]
[Thu Sep 17 15:28:17.096606 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.166.123.190:52956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbcW65wm-f4uX16X6SzgAAAGQ"]
[Thu Sep 17 15:28:17.203898 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.166.123.190:52958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbcW65wm-f4uX16X6S0QAAADE"]
[Thu Sep 17 15:28:17.251913 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.95.14.119:35500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxbcW65wm-f4uX16X6S1AAAAFk"]
[Thu Sep 17 15:28:17.387579 2026] [security2:error] [pid 1029697:tid 1029856] [client 193.189.100.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbcW65wm-f4uX16X6S2QAAAB0"]
[Thu Sep 17 15:28:17.392741 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.154.239.243:33868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/phpinfo.php~"] [unique_id "aqxbcW65wm-f4uX16X6S4QAAAEY"]
[Thu Sep 17 15:28:17.659220 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.95.14.119:35506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxbcW65wm-f4uX16X6S5wAAAAQ"]
[Thu Sep 17 15:28:17.779801 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.166.228.3:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbcW65wm-f4uX16X6S6gAAAD8"]
[Thu Sep 17 15:28:17.783589 2026] [security2:error] [pid 1029697:tid 1029836] [client 185.226.198.7:18614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "aqxbcW65wm-f4uX16X6S6wAAAAk"]
[Thu Sep 17 15:28:17.785828 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.166.123.190:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbcW65wm-f4uX16X6S7AAAACo"]
[Thu Sep 17 15:28:17.904737 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.239.243:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/info.php.bak"] [unique_id "aqxbcW65wm-f4uX16X6S9QAAAA0"]
[Thu Sep 17 15:28:17.905396 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.166.123.190:52990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbcW65wm-f4uX16X6S9gAAADM"]
[Thu Sep 17 15:28:18.057841 2026] [security2:error] [pid 1029697:tid 1029943] [client 185.55.149.49:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbcm65wm-f4uX16X6S-wAAAHQ"]
[Thu Sep 17 15:28:18.058761 2026] [security2:error] [pid 1029697:tid 1029943] [client 185.55.149.49:49172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbcm65wm-f4uX16X6S-wAAAHQ"]
[Thu Sep 17 15:28:18.089261 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.95.14.119:48528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxbcm65wm-f4uX16X6S_QAAAGk"]
[Thu Sep 17 15:28:18.096705 2026] [security2:error] [pid 1029697:tid 1029900] [client 4.240.114.86:58665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxbcm65wm-f4uX16X6S_gAAAEk"], referer: binance.com
[Thu Sep 17 15:28:18.159522 2026] [security2:error] [pid 1029697:tid 1029882] [client 170.9.239.112:51589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "www.streetwisepublicationsltd.com"] [uri "/new-legacy"] [unique_id "aqxbcm65wm-f4uX16X6TAQAAADc"], referer: http://partnerme.uk/
[Thu Sep 17 15:28:18.272968 2026] [security2:error] [pid 1029697:tid 1029857] [client 169.58.197.253:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxbcm65wm-f4uX16X6TBQAAAB4"], referer: binance.com
[Thu Sep 17 15:28:18.335226 2026] [security2:error] [pid 1029697:tid 1029893] [client 85.138.174.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "courses.ritamayblog.com"] [uri "/index.php"] [unique_id "aqxbcW65wm-f4uX16X6S4AAAAEI"]
[Thu Sep 17 15:28:18.411209 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.154.239.243:43382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/phpinfo.php.save"] [unique_id "aqxbcm65wm-f4uX16X6TCwAAAEg"]
[Thu Sep 17 15:28:18.446571 2026] [security2:error] [pid 1029697:tid 1029916] [client 107.150.101.57:51764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "slj.skj.mybluehost.me"] [uri "/wp-content/plugins/mojo-marketplace-wp-plugin/readme.txt"] [unique_id "aqxbcm65wm-f4uX16X6TDAAAAFk"]
[Thu Sep 17 15:28:18.465591 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.95.14.119:48536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxbcm65wm-f4uX16X6TDQAAABU"]
[Thu Sep 17 15:28:18.471772 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.166.228.3:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbcm65wm-f4uX16X6TDgAAACE"]
[Thu Sep 17 15:28:18.472743 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.166.123.190:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbcm65wm-f4uX16X6TDwAAACc"]
[Thu Sep 17 15:28:18.521796 2026] [autoindex:error] [pid 1029697:tid 1029876] [client 35.198.3.220:56964] AH01276: Cannot serve directory /home1/ditkuemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:28:18.595720 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.166.123.190:53000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/phpinfo.php~"] [unique_id "aqxbcm65wm-f4uX16X6TEQAAABY"]
[Thu Sep 17 15:28:18.852466 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.95.14.119:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxbcm65wm-f4uX16X6TGwAAAEc"]
[Thu Sep 17 15:28:18.907505 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.154.239.243:43384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/staging/phpinfo.php"] [unique_id "aqxbcm65wm-f4uX16X6THgAAACM"]
[Thu Sep 17 15:28:19.022063 2026] [security2:error] [pid 1029697:tid 1029861] [client 193.189.100.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbcm65wm-f4uX16X6THQAAACI"]
[Thu Sep 17 15:28:19.111166 2026] [security2:error] [pid 1029697:tid 1029851] [client 137.131.43.163:63999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arhitecturabuzau.ro"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxbc265wm-f4uX16X6TIgAAABg"]
[Thu Sep 17 15:28:19.167681 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.166.228.3:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbc265wm-f4uX16X6TJQAAAHs"]
[Thu Sep 17 15:28:19.169042 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.166.123.190:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbc265wm-f4uX16X6TJgAAAG8"]
[Thu Sep 17 15:28:19.198387 2026] [security2:error] [pid 1029697:tid 1029920] [client 186.22.238.206:12065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbc265wm-f4uX16X6TIAAAXTg"]
[Thu Sep 17 15:28:19.205860 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.95.14.119:48548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxbc265wm-f4uX16X6TJwAAACo"]
[Thu Sep 17 15:28:19.285906 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.166.123.190:53024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/info.php.bak"] [unique_id "aqxbc265wm-f4uX16X6TLgAAAEA"]
[Thu Sep 17 15:28:19.310779 2026] [security2:error] [pid 1029697:tid 1029878] [client 40.81.232.68:51875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-login.php"] [unique_id "aqxbc265wm-f4uX16X6TKAAAADM"], referer: binance.com
[Thu Sep 17 15:28:19.405197 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.239.243:43388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/beta/phpinfo.php"] [unique_id "aqxbc265wm-f4uX16X6TMQAAAA0"]
[Thu Sep 17 15:28:19.593541 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.95.14.119:48550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxbc265wm-f4uX16X6TNgAAAFg"]
[Thu Sep 17 15:28:19.673452 2026] [security2:error] [pid 1029697:tid 1029859] [client 185.226.198.5:43406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxbc265wm-f4uX16X6TOQAAACA"]
[Thu Sep 17 15:28:19.867393 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.166.123.190:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbc265wm-f4uX16X6TPwAAABI"]
[Thu Sep 17 15:28:19.877768 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.166.228.3:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbc265wm-f4uX16X6TQAAAADQ"]
[Thu Sep 17 15:28:19.908283 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.154.239.243:43394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/uat/phpinfo.php"] [unique_id "aqxbc265wm-f4uX16X6TQQAAAGQ"]
[Thu Sep 17 15:28:19.985105 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.166.123.190:53052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbc265wm-f4uX16X6TQgAAAD4"]
[Thu Sep 17 15:28:20.057821 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.95.14.119:48566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxbdG65wm-f4uX16X6TRwAAAAY"]
[Thu Sep 17 15:28:20.380889 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.154.239.243:43408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/qa/phpinfo.php"] [unique_id "aqxbdG65wm-f4uX16X6TTAAAAEs"]
[Thu Sep 17 15:28:20.444486 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.95.14.119:48578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxbdG65wm-f4uX16X6TUQAAAEc"]
[Thu Sep 17 15:28:20.533064 2026] [security2:error] [pid 1029697:tid 1029954] [client 193.189.100.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbdG65wm-f4uX16X6TUAAAAH8"]
[Thu Sep 17 15:28:20.571143 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.166.123.190:53056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/phpinfo.php~"] [unique_id "aqxbdG65wm-f4uX16X6TVQAAABM"]
[Thu Sep 17 15:28:20.669055 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.166.123.190:53068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbdG65wm-f4uX16X6TWAAAADU"]
[Thu Sep 17 15:28:20.734692 2026] [security2:error] [pid 1029697:tid 1029832] [client 137.131.43.163:52322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.43.131.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbdG65wm-f4uX16X6TWQAAAAU"]
[Thu Sep 17 15:28:20.734837 2026] [security2:error] [pid 1029697:tid 1029832] [client 137.131.43.163:52322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbdG65wm-f4uX16X6TWQAAAAU"]
[Thu Sep 17 15:28:20.801107 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.166.228.3:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/php-info.php"] [unique_id "aqxbdG65wm-f4uX16X6TXAAAAD8"]
[Thu Sep 17 15:28:20.805757 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.95.14.119:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxbdG65wm-f4uX16X6TXQAAAAI"]
[Thu Sep 17 15:28:20.858257 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.154.239.243:43420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/preview/phpinfo.php"] [unique_id "aqxbdG65wm-f4uX16X6TXgAAAAA"]
[Thu Sep 17 15:28:21.126978 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.95.14.119:48594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxbdW65wm-f4uX16X6TZgAAADM"]
[Thu Sep 17 15:28:21.256222 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.166.123.190:53080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/info.php.bak"] [unique_id "aqxbdW65wm-f4uX16X6TawAAAA0"]
[Thu Sep 17 15:28:21.348519 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.166.123.190:41468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbdW65wm-f4uX16X6TbwAAAG0"]
[Thu Sep 17 15:28:21.367704 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.154.239.243:43434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/www/phpinfo.php"] [unique_id "aqxbdW65wm-f4uX16X6TcAAAAFI"]
[Thu Sep 17 15:28:21.446976 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.95.14.119:48606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbdW65wm-f4uX16X6TcQAAAGU"]
[Thu Sep 17 15:28:21.483967 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.166.228.3:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/phpversion.php"] [unique_id "aqxbdW65wm-f4uX16X6TcwAAACA"]
[Thu Sep 17 15:28:21.655458 2026] [security2:error] [pid 1029697:tid 1029858] [client 185.226.198.6:42404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxbdW65wm-f4uX16X6TdwAAAB8"]
[Thu Sep 17 15:28:21.789055 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.95.14.119:48608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbdW65wm-f4uX16X6TfgAAAGo"]
[Thu Sep 17 15:28:21.885409 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.154.239.243:43448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbdW65wm-f4uX16X6TgAAAABU"]
[Thu Sep 17 15:28:21.918858 2026] [security2:error] [pid 1029697:tid 1029927] [client 103.61.184.148:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbdW65wm-f4uX16X6TgQAAAGQ"]
[Thu Sep 17 15:28:21.918960 2026] [security2:error] [pid 1029697:tid 1029927] [client 103.61.184.148:52446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbdW65wm-f4uX16X6TgQAAAGQ"]
[Thu Sep 17 15:28:21.948007 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.166.123.190:41470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbdW65wm-f4uX16X6ThQAAAHM"]
[Thu Sep 17 15:28:22.055455 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.166.123.190:41482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6ThwAAAHA"]
[Thu Sep 17 15:28:22.085445 2026] [security2:error] [pid 1029697:tid 1029892] [client 193.189.100.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbdW65wm-f4uX16X6ThgAAAEE"]
[Thu Sep 17 15:28:22.185119 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.166.228.3:56894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/_phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TiAAAAHU"]
[Thu Sep 17 15:28:22.326052 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.95.14.119:48624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TjgAAAAQ"]
[Thu Sep 17 15:28:22.353327 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.239.243:43456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TjwAAACY"]
[Thu Sep 17 15:28:22.630868 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.166.123.190:41488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TlgAAADA"]
[Thu Sep 17 15:28:22.669477 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.95.14.119:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TmQAAAAA"]
[Thu Sep 17 15:28:22.746284 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.166.123.190:41494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TmgAAAAk"]
[Thu Sep 17 15:28:22.848228 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.154.239.243:43464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/site/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TngAAAFc"]
[Thu Sep 17 15:28:22.887037 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.166.228.3:56904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6ToAAAADs"]
[Thu Sep 17 15:28:22.982600 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.95.14.119:48640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbdm65wm-f4uX16X6TogAAAC0"]
[Thu Sep 17 15:28:23.327195 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.166.123.190:41500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbd265wm-f4uX16X6TqwAAAH0"]
[Thu Sep 17 15:28:23.347712 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.154.239.243:43474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/docs/phpinfo.php"] [unique_id "aqxbd265wm-f4uX16X6TrAAAADY"]
[Thu Sep 17 15:28:23.385620 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.95.14.119:48656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbd265wm-f4uX16X6TrQAAAFI"]
[Thu Sep 17 15:28:23.388680 2026] [security2:error] [pid 1029697:tid 1029885] [client 42.115.196.123:5017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbd265wm-f4uX16X6TqQAAOmk"]
[Thu Sep 17 15:28:23.424720 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.166.123.190:41510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbd265wm-f4uX16X6TrwAAAFY"]
[Thu Sep 17 15:28:23.585043 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.166.228.3:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/server-info.php"] [unique_id "aqxbd265wm-f4uX16X6TswAAAA4"]
[Thu Sep 17 15:28:23.721655 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.95.14.119:48666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxbd265wm-f4uX16X6TugAAAAo"]
[Thu Sep 17 15:28:23.808331 2026] [security2:error] [pid 1029697:tid 1029945] [client 193.189.100.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbd265wm-f4uX16X6TuAAAAHY"]
[Thu Sep 17 15:28:23.839848 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.239.243:43484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbd265wm-f4uX16X6TwQAAACc"]
[Thu Sep 17 15:28:23.849784 2026] [security2:error] [pid 1029697:tid 1029864] [client 4.240.114.86:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxbd265wm-f4uX16X6TwgAAACU"], referer: binance.com
[Thu Sep 17 15:28:23.895072 2026] [security2:error] [pid 1029697:tid 1029954] [client 185.226.198.6:42408] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "aqxbd265wm-f4uX16X6TxAAAAH8"]
[Thu Sep 17 15:28:23.941176 2026] [security2:error] [pid 1029697:tid 1029879] [client 143.105.152.240:21900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbd265wm-f4uX16X6TxQAAADQ"]
[Thu Sep 17 15:28:23.944907 2026] [security2:error] [pid 1029697:tid 1029879] [client 143.105.152.240:21900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbd265wm-f4uX16X6TxQAAADQ"]
[Thu Sep 17 15:28:24.008957 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.166.123.190:41520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbeG65wm-f4uX16X6TxgAAAAY"]
[Thu Sep 17 15:28:24.110837 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.95.14.119:48680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zga.qdn.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxbeG65wm-f4uX16X6TxwAAAD0"]
[Thu Sep 17 15:28:24.129594 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.166.123.190:41530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbeG65wm-f4uX16X6TyAAAAB0"]
[Thu Sep 17 15:28:24.261143 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.166.228.3:56918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/server-status.php"] [unique_id "aqxbeG65wm-f4uX16X6T0gAAADU"]
[Thu Sep 17 15:28:24.343414 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.154.239.243:43490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbeG65wm-f4uX16X6T2AAAAAE"]
[Thu Sep 17 15:28:24.688807 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.166.123.190:41536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbeG65wm-f4uX16X6T4AAAAHg"]
[Thu Sep 17 15:28:24.822113 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.166.123.190:41548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbeG65wm-f4uX16X6T6AAAAGk"]
[Thu Sep 17 15:28:24.826281 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.239.243:43496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/core/phpinfo.php"] [unique_id "aqxbeG65wm-f4uX16X6T6QAAABQ"]
[Thu Sep 17 15:28:24.847251 2026] [security2:error] [pid 1029697:tid 1029877] [client 156.192.234.52:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbeG65wm-f4uX16X6T6gAAADI"]
[Thu Sep 17 15:28:24.847828 2026] [security2:error] [pid 1029697:tid 1029877] [client 156.192.234.52:58056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbeG65wm-f4uX16X6T6gAAADI"]
[Thu Sep 17 15:28:25.273026 2026] [security2:error] [pid 1029697:tid 1029897] [client 178.51.123.80:7931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbeW65wm-f4uX16X6T9QAARm8"]
[Thu Sep 17 15:28:25.302895 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.239.243:43512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.239.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.wamu.uk"] [uri "/includes/phpinfo.php"] [unique_id "aqxbeW65wm-f4uX16X6T-QAAACc"]
[Thu Sep 17 15:28:25.359731 2026] [security2:error] [pid 1029697:tid 1029942] [client 114.198.138.124:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbeW65wm-f4uX16X6T_QAAAHM"]
[Thu Sep 17 15:28:25.359846 2026] [security2:error] [pid 1029697:tid 1029942] [client 114.198.138.124:61875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbeW65wm-f4uX16X6T_QAAAHM"]
[Thu Sep 17 15:28:25.371373 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.166.123.190:41564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbeW65wm-f4uX16X6T_wAAACE"]
[Thu Sep 17 15:28:25.417401 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.166.228.3:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbeW65wm-f4uX16X6UAAAAABU"]
[Thu Sep 17 15:28:25.505958 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.166.123.190:41580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbeW65wm-f4uX16X6UAwAAACw"]
[Thu Sep 17 15:28:25.507859 2026] [security2:error] [pid 1029697:tid 1029865] [client 185.226.198.4:23576] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "aqxbeW65wm-f4uX16X6UBAAAACY"]
[Thu Sep 17 15:28:26.066301 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.166.123.190:41586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbem65wm-f4uX16X6UGgAAAHw"]
[Thu Sep 17 15:28:26.099773 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.166.228.3:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbem65wm-f4uX16X6UHwAAACo"]
[Thu Sep 17 15:28:26.211500 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.166.123.190:41590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbem65wm-f4uX16X6UKAAAAGc"]
[Thu Sep 17 15:28:26.745066 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.166.123.190:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbem65wm-f4uX16X6UOwAAAHo"]
[Thu Sep 17 15:28:26.757920 2026] [security2:error] [pid 1029697:tid 1029889] [client 169.58.197.253:65001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxbem65wm-f4uX16X6UPAAAAD4"], referer: binance.com
[Thu Sep 17 15:28:26.785982 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.166.228.3:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbem65wm-f4uX16X6UQAAAAGo"]
[Thu Sep 17 15:28:26.926063 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.166.123.190:41604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbem65wm-f4uX16X6URQAAACc"]
[Thu Sep 17 15:28:27.334921 2026] [security2:error] [pid 1029697:tid 1029843] [client 185.226.198.7:29364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "aqxbe265wm-f4uX16X6UVAAAABA"]
[Thu Sep 17 15:28:27.452425 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.166.123.190:41620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbe265wm-f4uX16X6UWgAAABM"]
[Thu Sep 17 15:28:27.500285 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.166.228.3:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbe265wm-f4uX16X6UXgAAABc"]
[Thu Sep 17 15:28:27.610029 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.166.123.190:41626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbe265wm-f4uX16X6UYAAAAAk"]
[Thu Sep 17 15:28:28.080982 2026] [security2:error] [pid 1029697:tid 1029900] [client 136.158.61.34:31556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbfG65wm-f4uX16X6UbgAAAEk"]
[Thu Sep 17 15:28:28.081149 2026] [security2:error] [pid 1029697:tid 1029900] [client 136.158.61.34:31556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbfG65wm-f4uX16X6UbgAAAEk"]
[Thu Sep 17 15:28:28.142694 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.166.123.190:41642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbfG65wm-f4uX16X6UdgAAABs"]
[Thu Sep 17 15:28:28.177425 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.166.228.3:56990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbfG65wm-f4uX16X6UdwAAAGk"]
[Thu Sep 17 15:28:28.351261 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.166.123.190:41644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbfG65wm-f4uX16X6UgQAAAGA"]
[Thu Sep 17 15:28:28.825550 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.166.123.190:41650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbfG65wm-f4uX16X6UkwAAADQ"]
[Thu Sep 17 15:28:28.875127 2026] [security2:error] [pid 1029697:tid 1029848] [client 185.55.149.49:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbfG65wm-f4uX16X6UlQAAABU"]
[Thu Sep 17 15:28:28.875230 2026] [security2:error] [pid 1029697:tid 1029848] [client 185.55.149.49:58928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbfG65wm-f4uX16X6UlQAAABU"]
[Thu Sep 17 15:28:28.875699 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.166.228.3:56992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbfG65wm-f4uX16X6UlAAAACc"]
[Thu Sep 17 15:28:29.031325 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.166.123.190:41656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbfW65wm-f4uX16X6UmQAAACY"]
[Thu Sep 17 15:28:29.430327 2026] [security2:error] [pid 1029697:tid 1029918] [client 4.240.114.86:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxbfW65wm-f4uX16X6UpAAAAFs"], referer: binance.com
[Thu Sep 17 15:28:29.505481 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.166.123.190:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbfW65wm-f4uX16X6UpwAAAEM"]
[Thu Sep 17 15:28:29.567059 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.166.228.3:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbfW65wm-f4uX16X6UqQAAAEQ"]
[Thu Sep 17 15:28:29.720851 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.166.123.190:41674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejacksonauthor.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbfW65wm-f4uX16X6UqgAAAGE"]
[Thu Sep 17 15:28:30.032821 2026] [security2:error] [pid 1029697:tid 1029906] [client 74.7.230.57:40796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.seh.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxbfm65wm-f4uX16X6UxAAAAE8"]
[Thu Sep 17 15:28:30.183051 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.166.123.190:41690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbfm65wm-f4uX16X6U2wAAAFk"]
[Thu Sep 17 15:28:30.251927 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.166.228.3:57014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbfm65wm-f4uX16X6U3wAAAEs"]
[Thu Sep 17 15:28:30.752358 2026] [security2:error] [pid 1029697:tid 1029832] [client 185.226.198.7:41846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "aqxbfm65wm-f4uX16X6U9wAAAAU"]
[Thu Sep 17 15:28:30.871213 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.166.123.190:41702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbfm65wm-f4uX16X6U_AAAAH0"]
[Thu Sep 17 15:28:30.935094 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.166.228.3:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/phpinfo.php~"] [unique_id "aqxbfm65wm-f4uX16X6U_gAAADU"]
[Thu Sep 17 15:28:31.559359 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.166.123.190:48740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.123.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bejackson.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbf265wm-f4uX16X6VEAAAAEQ"]
[Thu Sep 17 15:28:31.619263 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.166.228.3:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/info.php.bak"] [unique_id "aqxbf265wm-f4uX16X6VFAAAADw"]
[Thu Sep 17 15:28:32.125416 2026] [security2:error] [pid 1029697:tid 1029901] [client 200.141.229.182:37271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbgG65wm-f4uX16X6VIQAASh8"]
[Thu Sep 17 15:28:32.320934 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.166.228.3:42118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbgG65wm-f4uX16X6VMgAAAHo"]
[Thu Sep 17 15:28:32.530794 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.154.219.249:42252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/"] [unique_id "aqxbgG65wm-f4uX16X6VOgAAAGY"]
[Thu Sep 17 15:28:32.718330 2026] [security2:error] [pid 1029697:tid 1029880] [client 4.240.114.86:49397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxbgG65wm-f4uX16X6VQQAAADU"], referer: binance.com
[Thu Sep 17 15:28:32.795962 2026] [security2:error] [pid 1029697:tid 1029884] [client 103.61.184.148:53089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbgG65wm-f4uX16X6VRAAAADk"]
[Thu Sep 17 15:28:32.796287 2026] [security2:error] [pid 1029697:tid 1029884] [client 103.61.184.148:53089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbgG65wm-f4uX16X6VRAAAADk"]
[Thu Sep 17 15:28:33.010493 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.166.228.3:42126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbgW65wm-f4uX16X6VUQAAADs"]
[Thu Sep 17 15:28:33.017476 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.154.219.249:42268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/"] [unique_id "aqxbgW65wm-f4uX16X6VUgAAAG8"]
[Thu Sep 17 15:28:33.093683 2026] [security2:error] [pid 1029697:tid 1029754] [remote 45.157.54.43:42463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.acc.edu.ai"] [uri "/xmlrpc.php"] [unique_id "aqxbgW65wm-f4uX16X6VVAAAcTg"]
[Thu Sep 17 15:28:33.093917 2026] [security2:error] [pid 1029697:tid 1029940] [client 45.157.54.43:42463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cpcalendars.acc.edu.ai"] [uri "/xmlrpc.php"] [unique_id "aqxbgW65wm-f4uX16X6VVAAAcTg"]
[Thu Sep 17 15:28:33.506173 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.154.219.249:42270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/"] [unique_id "aqxbgW65wm-f4uX16X6VYgAAADA"]
[Thu Sep 17 15:28:33.695398 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.166.228.3:42140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbgW65wm-f4uX16X6VaAAAAEs"]
[Thu Sep 17 15:28:33.705967 2026] [security2:error] [pid 1029697:tid 1029871] [client 185.226.198.5:31308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "aqxbgW65wm-f4uX16X6VaQAAACw"]
[Thu Sep 17 15:28:34.228328 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.154.219.249:42282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/"] [unique_id "aqxbgm65wm-f4uX16X6VeQAAAC8"]
[Thu Sep 17 15:28:34.243106 2026] [security2:error] [pid 1029697:tid 1029850] [client 101.181.104.50:45419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbgm65wm-f4uX16X6VdgAAFzc"]
[Thu Sep 17 15:28:34.396937 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.166.228.3:42144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbgm65wm-f4uX16X6VfAAAAGI"]
[Thu Sep 17 15:28:34.528602 2026] [security2:error] [pid 1029697:tid 1029922] [client 143.105.152.240:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbgm65wm-f4uX16X6VggAAAF8"]
[Thu Sep 17 15:28:34.528734 2026] [security2:error] [pid 1029697:tid 1029922] [client 143.105.152.240:17297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbgm65wm-f4uX16X6VggAAAF8"]
[Thu Sep 17 15:28:34.742761 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/.env"] [unique_id "aqxbgm65wm-f4uX16X6ViAAAAGM"]
[Thu Sep 17 15:28:35.085818 2026] [security2:error] [pid 1029697:tid 1029860] [client 34.166.228.3:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbg265wm-f4uX16X6VlwAAACE"]
[Thu Sep 17 15:28:35.177272 2026] [security2:error] [pid 1029697:tid 1029881] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vancouverpreschoolphotographer.com"] [uri "/wp-admin/install.php"] [unique_id "aqxbg265wm-f4uX16X6VmgAAADY"]
[Thu Sep 17 15:28:35.367117 2026] [security2:error] [pid 1029697:tid 1029901] [client 4.240.114.86:50825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/icons.php"] [unique_id "aqxbg265wm-f4uX16X6VogAAAEo"], referer: binance.com
[Thu Sep 17 15:28:35.394287 2026] [security2:error] [pid 1029697:tid 1029951] [client 156.192.234.52:58820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.234.192.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbg265wm-f4uX16X6VowAAAHw"]
[Thu Sep 17 15:28:35.395818 2026] [security2:error] [pid 1029697:tid 1029951] [client 156.192.234.52:58820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arrowake.com"] [uri "/xmlrpc.php"] [unique_id "aqxbg265wm-f4uX16X6VowAAAHw"]
[Thu Sep 17 15:28:35.770246 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.166.228.3:42162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbg265wm-f4uX16X6VtQAAAB4"]
[Thu Sep 17 15:28:35.827839 2026] [security2:error] [pid 1029697:tid 1029882] [client 114.198.138.124:62522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbg265wm-f4uX16X6VtgAAADc"]
[Thu Sep 17 15:28:35.827965 2026] [security2:error] [pid 1029697:tid 1029882] [client 114.198.138.124:62522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbg265wm-f4uX16X6VtgAAADc"]
[Thu Sep 17 15:28:36.036409 2026] [security2:error] [pid 1029697:tid 1029934] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxbg265wm-f4uX16X6VsQAAa2s"]
[Thu Sep 17 15:28:36.133730 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxbhG65wm-f4uX16X6VxQAAACY"]
[Thu Sep 17 15:28:36.289144 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxbhG65wm-f4uX16X6VygAAAFA"]
[Thu Sep 17 15:28:36.300614 2026] [security2:error] [pid 1029697:tid 1029886] [client 185.226.198.4:45180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "aqxbhG65wm-f4uX16X6VywAAADs"]
[Thu Sep 17 15:28:36.451235 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.166.228.3:42178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbhG65wm-f4uX16X6V0AAAAAU"]
[Thu Sep 17 15:28:36.560989 2026] [security2:error] [pid 1029697:tid 1029923] [client 169.58.197.253:65532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxbhG65wm-f4uX16X6V1QAAAGA"], referer: binance.com
[Thu Sep 17 15:28:36.652300 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxbhG65wm-f4uX16X6V1gAAAAA"]
[Thu Sep 17 15:28:36.739659 2026] [security2:error] [pid 1029697:tid 1029864] [client 147.224.161.222:55227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "globaldove.org"] [uri "/"] [unique_id "aqxbhG65wm-f4uX16X6V3AAAACU"]
[Thu Sep 17 15:28:36.831770 2026] [security2:error] [pid 1029697:tid 1029927] [client 147.224.161.222:58835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "globaldove.org"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxbhG65wm-f4uX16X6V4AAAAGQ"]
[Thu Sep 17 15:28:36.932320 2026] [security2:error] [pid 1029697:tid 1029954] [client 147.224.161.222:65396] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "globaldove.org"] [uri "/media/system/js/core.js"] [unique_id "aqxbhG65wm-f4uX16X6V5gAAAH8"]
[Thu Sep 17 15:28:37.132853 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.166.228.3:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbhW65wm-f4uX16X6V8QAAACw"]
[Thu Sep 17 15:28:37.268512 2026] [security2:error] [pid 1029697:tid 1029905] [client 107.150.101.57:49130] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "slj.skj.mybluehost.me"] [uri "/wp-content/plugins/mojo-marketplace-wp-plugin/readme.txt"] [unique_id "aqxbhW65wm-f4uX16X6V9wAAAE4"]
[Thu Sep 17 15:28:37.349873 2026] [security2:error] [pid 1029697:tid 1029882] [client 74.7.228.6:55090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-f89fe5aa.deh.kei.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxbhW65wm-f4uX16X6V-AAAADc"]
[Thu Sep 17 15:28:37.524798 2026] [security2:error] [pid 1029697:tid 1029883] [client 162.222.195.198:43171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbhW65wm-f4uX16X6V-QAAOEI"]
[Thu Sep 17 15:28:37.560399 2026] [security2:error] [pid 1029697:tid 1029916] [client 4.240.114.86:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/json-schema.php"] [unique_id "aqxbhW65wm-f4uX16X6WAwAAAFk"], referer: binance.com
[Thu Sep 17 15:28:37.835212 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.166.228.3:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbhW65wm-f4uX16X6WBwAAAFU"]
[Thu Sep 17 15:28:37.855528 2026] [security2:error] [pid 1029697:tid 1029834] [client 174.138.37.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "danijelascatshop.me"] [uri "/index.php"] [unique_id "aqxbhW65wm-f4uX16X6V7gAAAAc"], referer: https://danijelascatshop.me/
[Thu Sep 17 15:28:38.518630 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.166.228.3:42214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbhm65wm-f4uX16X6WIAAAAA4"]
[Thu Sep 17 15:28:38.688225 2026] [security2:error] [pid 1029697:tid 1029789] [remote 45.157.54.43:49398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.acc.edu.ai"] [uri "/xmlrpc.php"] [unique_id "aqxbhm65wm-f4uX16X6WLAAASVs"]
[Thu Sep 17 15:28:38.688329 2026] [security2:error] [pid 1029697:tid 1029900] [client 45.157.54.43:49398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cpcalendars.acc.edu.ai"] [uri "/xmlrpc.php"] [unique_id "aqxbhm65wm-f4uX16X6WLAAASVs"]
[Thu Sep 17 15:28:39.060333 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxbh265wm-f4uX16X6WOwAAAH0"]
[Thu Sep 17 15:28:39.105680 2026] [security2:error] [pid 1029697:tid 1029896] [client 185.226.198.7:52064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "aqxbh265wm-f4uX16X6WPQAAAEU"]
[Thu Sep 17 15:28:39.203920 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.166.228.3:42218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbh265wm-f4uX16X6WPwAAAGY"]
[Thu Sep 17 15:28:39.221987 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/.env~"] [unique_id "aqxbh265wm-f4uX16X6WQAAAAGI"]
[Thu Sep 17 15:28:39.593864 2026] [security2:error] [pid 1029697:tid 1029879] [client 185.55.149.49:59573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbh265wm-f4uX16X6WSwAAADQ"]
[Thu Sep 17 15:28:39.594305 2026] [security2:error] [pid 1029697:tid 1029879] [client 185.55.149.49:59573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbh265wm-f4uX16X6WSwAAADQ"]
[Thu Sep 17 15:28:39.880385 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.166.228.3:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbh265wm-f4uX16X6WUwAAAHs"]
[Thu Sep 17 15:28:40.558238 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.166.228.3:42238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbiG65wm-f4uX16X6WbQAAAAo"]
[Thu Sep 17 15:28:40.713086 2026] [security2:error] [pid 1029697:tid 1029829] [client 136.158.61.34:32519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbiG65wm-f4uX16X6WcQAAAAI"]
[Thu Sep 17 15:28:40.713214 2026] [security2:error] [pid 1029697:tid 1029829] [client 136.158.61.34:32519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbiG65wm-f4uX16X6WcQAAAAI"]
[Thu Sep 17 15:28:40.775638 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxbiG65wm-f4uX16X6WcwAAABQ"]
[Thu Sep 17 15:28:40.891620 2026] [security2:error] [pid 1029697:tid 1029921] [client 177.37.138.4:34544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbiG65wm-f4uX16X6WcgAAXmA"]
[Thu Sep 17 15:28:40.918353 2026] [security2:error] [pid 1029697:tid 1029877] [client 185.226.198.5:42612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxbiG65wm-f4uX16X6WdgAAADI"]
[Thu Sep 17 15:28:40.935246 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxbiG65wm-f4uX16X6WdwAAAFQ"]
[Thu Sep 17 15:28:41.103027 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxbiW65wm-f4uX16X6WfQAAADE"]
[Thu Sep 17 15:28:41.160830 2026] [security2:error] [pid 1029697:tid 1029896] [client 4.240.114.86:53599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxbiW65wm-f4uX16X6WfwAAAEU"], referer: binance.com
[Thu Sep 17 15:28:41.239276 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.166.228.3:42252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbiW65wm-f4uX16X6WgQAAACg"]
[Thu Sep 17 15:28:41.263506 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxbiW65wm-f4uX16X6WggAAACQ"]
[Thu Sep 17 15:28:41.422573 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxbiW65wm-f4uX16X6WhQAAAB4"]
[Thu Sep 17 15:28:41.585881 2026] [security2:error] [pid 1029697:tid 1029809] [remote 111.225.149.160:55952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "chabelo.com"] [uri "/"] [unique_id "aqxbiW65wm-f4uX16X6WjwAAdW8"]
[Thu Sep 17 15:28:41.586128 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxbiW65wm-f4uX16X6WjgAAADQ"]
[Thu Sep 17 15:28:41.847621 2026] [security2:error] [pid 1029697:tid 1029885] [client 80.190.83.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moorekuehn.com"] [uri "/index.php"] [unique_id "aqxbiW65wm-f4uX16X6WlwAAADo"]
[Thu Sep 17 15:28:41.891120 2026] [security2:error] [pid 1029697:tid 1029934] [client 178.128.143.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "realdubrovnikexperience.com"] [uri "/index.php"] [unique_id "aqxbiW65wm-f4uX16X6WlAAAAGs"]
[Thu Sep 17 15:28:41.922183 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.166.228.3:42268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.228.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.godcapitalpartners.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbiW65wm-f4uX16X6WngAAAEA"]
[Thu Sep 17 15:28:41.947617 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxbiW65wm-f4uX16X6WnwAAAFM"]
[Thu Sep 17 15:28:42.107462 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxbim65wm-f4uX16X6WpQAAAGA"]
[Thu Sep 17 15:28:42.237359 2026] [security2:error] [pid 1029697:tid 1029937] [client 40.81.232.68:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-login.php"] [unique_id "aqxbim65wm-f4uX16X6WqAAAAG4"], referer: binance.com
[Thu Sep 17 15:28:42.261348 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxbim65wm-f4uX16X6WqgAAAFc"]
[Thu Sep 17 15:28:42.425999 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxbim65wm-f4uX16X6WsQAAABo"]
[Thu Sep 17 15:28:42.582026 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxbim65wm-f4uX16X6WtwAAAHc"]
[Thu Sep 17 15:28:42.613899 2026] [security2:error] [pid 1029697:tid 1029948] [client 185.226.198.6:41930] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/groma-canary-not-a-real-plugin/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WuAAAAHk"]
[Thu Sep 17 15:28:42.685387 2026] [security2:error] [pid 1029697:tid 1029859] [client 185.226.198.5:42628] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WugAAACA"]
[Thu Sep 17 15:28:42.690653 2026] [security2:error] [pid 1029697:tid 1029901] [client 185.226.198.6:41944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WuwAAAEo"]
[Thu Sep 17 15:28:42.694487 2026] [security2:error] [pid 1029697:tid 1029932] [client 185.226.198.6:41950] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WvAAAAGk"]
[Thu Sep 17 15:28:42.694507 2026] [security2:error] [pid 1029697:tid 1029831] [client 185.226.198.5:42640] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WvQAAAAQ"]
[Thu Sep 17 15:28:42.694763 2026] [security2:error] [pid 1029697:tid 1029862] [client 185.226.198.7:52070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WvgAAACM"]
[Thu Sep 17 15:28:42.695029 2026] [security2:error] [pid 1029697:tid 1029953] [client 185.226.198.5:42644] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WvwAAAH4"]
[Thu Sep 17 15:28:42.695858 2026] [security2:error] [pid 1029697:tid 1029909] [client 185.226.198.5:42634] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WwAAAAFI"]
[Thu Sep 17 15:28:42.696699 2026] [security2:error] [pid 1029697:tid 1029921] [client 185.226.198.5:42650] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WwQAAAF4"]
[Thu Sep 17 15:28:42.697396 2026] [security2:error] [pid 1029697:tid 1029877] [client 185.226.198.7:52068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WwgAAADI"]
[Thu Sep 17 15:28:42.699877 2026] [security2:error] [pid 1029697:tid 1029911] [client 185.226.198.6:41954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WwwAAAFQ"]
[Thu Sep 17 15:28:42.703036 2026] [security2:error] [pid 1029697:tid 1029902] [client 185.226.198.5:42666] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WxAAAAEs"]
[Thu Sep 17 15:28:42.707130 2026] [security2:error] [pid 1029697:tid 1029952] [client 185.226.198.4:18502] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WxQAAAH0"]
[Thu Sep 17 15:28:42.707211 2026] [security2:error] [pid 1029697:tid 1029882] [client 185.226.198.4:18510] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WxgAAADc"]
[Thu Sep 17 15:28:42.708618 2026] [security2:error] [pid 1029697:tid 1029905] [client 185.226.198.7:52084] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WxwAAAE4"]
[Thu Sep 17 15:28:42.715908 2026] [security2:error] [pid 1029697:tid 1029875] [client 185.226.198.5:42678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WyAAAADA"]
[Thu Sep 17 15:28:42.717501 2026] [security2:error] [pid 1029697:tid 1029896] [client 185.226.198.5:42696] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WyQAAAEU"]
[Thu Sep 17 15:28:42.719120 2026] [security2:error] [pid 1029697:tid 1029830] [client 185.226.198.6:41968] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WygAAAAM"]
[Thu Sep 17 15:28:42.719866 2026] [security2:error] [pid 1029697:tid 1029867] [client 185.226.198.5:42692] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WywAAACg"]
[Thu Sep 17 15:28:42.724750 2026] [security2:error] [pid 1029697:tid 1029883] [client 185.226.198.4:18526] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WzAAAADg"]
[Thu Sep 17 15:28:42.727114 2026] [security2:error] [pid 1029697:tid 1029857] [client 185.226.198.6:41992] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WzQAAAB4"]
[Thu Sep 17 15:28:42.727944 2026] [security2:error] [pid 1029697:tid 1029942] [client 185.226.198.6:41980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6WzgAAAHM"]
[Thu Sep 17 15:28:42.731894 2026] [security2:error] [pid 1029697:tid 1029848] [client 185.226.198.5:42698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W0AAAABU"]
[Thu Sep 17 15:28:42.737595 2026] [security2:error] [pid 1029697:tid 1029880] [client 185.226.198.4:18552] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W0gAAADU"]
[Thu Sep 17 15:28:42.738378 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxbim65wm-f4uX16X6W0QAAAHU"]
[Thu Sep 17 15:28:42.739971 2026] [security2:error] [pid 1029697:tid 1029835] [client 185.226.198.4:18554] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W0wAAAAg"]
[Thu Sep 17 15:28:42.740193 2026] [security2:error] [pid 1029697:tid 1029943] [client 185.226.198.5:42708] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W1AAAAHQ"]
[Thu Sep 17 15:28:42.741555 2026] [security2:error] [pid 1029697:tid 1029886] [client 185.226.198.4:18528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W1QAAADs"]
[Thu Sep 17 15:28:42.743097 2026] [security2:error] [pid 1029697:tid 1029927] [client 185.226.198.5:42718] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W1gAAAGQ"]
[Thu Sep 17 15:28:42.744754 2026] [security2:error] [pid 1029697:tid 1029870] [client 185.226.198.4:18538] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W1wAAACs"]
[Thu Sep 17 15:28:42.748755 2026] [security2:error] [pid 1029697:tid 1029904] [client 185.226.198.4:18556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W2AAAAE0"]
[Thu Sep 17 15:28:42.752421 2026] [security2:error] [pid 1029697:tid 1029950] [client 185.226.198.5:42712] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W2QAAAHs"]
[Thu Sep 17 15:28:42.754104 2026] [security2:error] [pid 1029697:tid 1029903] [client 185.226.198.5:42742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W2gAAAEw"]
[Thu Sep 17 15:28:42.759164 2026] [security2:error] [pid 1029697:tid 1029839] [client 185.226.198.5:42740] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W2wAAAAw"]
[Thu Sep 17 15:28:42.762403 2026] [security2:error] [pid 1029697:tid 1029861] [client 185.226.198.7:52096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W3AAAACI"]
[Thu Sep 17 15:28:42.772019 2026] [security2:error] [pid 1029697:tid 1029934] [client 185.226.198.5:42726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W3QAAAGs"]
[Thu Sep 17 15:28:42.776161 2026] [security2:error] [pid 1029697:tid 1029851] [client 185.226.198.4:18564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W3gAAABg"]
[Thu Sep 17 15:28:42.777695 2026] [security2:error] [pid 1029697:tid 1029891] [client 185.226.198.7:52116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W3wAAAEA"]
[Thu Sep 17 15:28:42.779253 2026] [security2:error] [pid 1029697:tid 1029866] [client 185.226.198.6:42002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W4AAAACc"]
[Thu Sep 17 15:28:42.782514 2026] [security2:error] [pid 1029697:tid 1029865] [client 185.226.198.7:52104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W4QAAACY"]
[Thu Sep 17 15:28:42.788002 2026] [security2:error] [pid 1029697:tid 1029894] [client 185.226.198.4:18566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W4gAAAEM"]
[Thu Sep 17 15:28:42.788848 2026] [security2:error] [pid 1029697:tid 1029899] [client 185.226.198.4:18624] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W4wAAAEg"]
[Thu Sep 17 15:28:42.789073 2026] [security2:error] [pid 1029697:tid 1029834] [client 185.226.198.6:42008] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W5AAAAAc"]
[Thu Sep 17 15:28:42.789099 2026] [security2:error] [pid 1029697:tid 1029836] [client 185.226.198.4:18598] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W5QAAAAk"]
[Thu Sep 17 15:28:42.789799 2026] [security2:error] [pid 1029697:tid 1029923] [client 185.226.198.4:18608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W5gAAAGA"]
[Thu Sep 17 15:28:42.796918 2026] [security2:error] [pid 1029697:tid 1029933] [client 185.226.198.4:18582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W5wAAAGo"]
[Thu Sep 17 15:28:42.800129 2026] [security2:error] [pid 1029697:tid 1029928] [client 185.226.198.5:42756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W6AAAAGU"]
[Thu Sep 17 15:28:42.800902 2026] [security2:error] [pid 1029697:tid 1029887] [client 185.226.198.6:42014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W6QAAADw"]
[Thu Sep 17 15:28:42.807310 2026] [security2:error] [pid 1029697:tid 1029842] [client 185.226.198.5:42760] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W6gAAAA8"]
[Thu Sep 17 15:28:42.810720 2026] [security2:error] [pid 1029697:tid 1029852] [client 185.226.198.7:52118] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W6wAAABk"]
[Thu Sep 17 15:28:42.811428 2026] [security2:error] [pid 1029697:tid 1029908] [client 185.226.198.5:42762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W7AAAAFE"]
[Thu Sep 17 15:28:42.813027 2026] [security2:error] [pid 1029697:tid 1029898] [client 185.226.198.4:18630] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W7QAAAEc"]
[Thu Sep 17 15:28:42.901242 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxbim65wm-f4uX16X6W8AAAAAo"]
[Thu Sep 17 15:28:42.949911 2026] [security2:error] [pid 1029697:tid 1029864] [client 185.226.198.4:18632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "aqxbim65wm-f4uX16X6W9AAAACU"]
[Thu Sep 17 15:28:42.951227 2026] [security2:error] [pid 1029697:tid 1029801] [remote 110.249.201.167:59680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zapatos.chabelo.com"] [uri "/en/"] [unique_id "aqxbim65wm-f4uX16X6W9QAAAmc"]
[Thu Sep 17 15:28:43.056522 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxbi265wm-f4uX16X6W-AAAABA"]
[Thu Sep 17 15:28:43.209810 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxbi265wm-f4uX16X6W_AAAAAQ"]
[Thu Sep 17 15:28:43.368290 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxbi265wm-f4uX16X6XAQAAAHo"]
[Thu Sep 17 15:28:43.522189 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxbi265wm-f4uX16X6XCAAAAEU"]
[Thu Sep 17 15:28:43.553670 2026] [security2:error] [pid 1029697:tid 1029873] [client 103.61.184.148:53656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbi265wm-f4uX16X6XCQAAAC4"]
[Thu Sep 17 15:28:43.553803 2026] [security2:error] [pid 1029697:tid 1029873] [client 103.61.184.148:53656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbi265wm-f4uX16X6XCQAAAC4"]
[Thu Sep 17 15:28:43.676886 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxbi265wm-f4uX16X6XEAAAAHY"]
[Thu Sep 17 15:28:43.836975 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxbi265wm-f4uX16X6XFQAAAHQ"]
[Thu Sep 17 15:28:43.990896 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxbi265wm-f4uX16X6XGwAAADo"]
[Thu Sep 17 15:28:44.149042 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxbjG65wm-f4uX16X6XIQAAACo"]
[Thu Sep 17 15:28:44.304766 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxbjG65wm-f4uX16X6XJgAAAGA"]
[Thu Sep 17 15:28:44.312722 2026] [security2:error] [pid 1029697:tid 1029851] [client 162.241.226.11:44048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxbjG65wm-f4uX16X6XIgAAABg"]
[Thu Sep 17 15:28:44.459843 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxbjG65wm-f4uX16X6XLwAAAB0"]
[Thu Sep 17 15:28:44.462595 2026] [security2:error] [pid 1029697:tid 1029928] [client 162.241.226.11:44050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxbjG65wm-f4uX16X6XKQAAAGU"]
[Thu Sep 17 15:28:44.612821 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxbjG65wm-f4uX16X6XMwAAACU"]
[Thu Sep 17 15:28:44.774095 2026] [security2:error] [pid 1029697:tid 1029892] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxbjG65wm-f4uX16X6XNwAAAEE"]
[Thu Sep 17 15:28:44.870055 2026] [security2:error] [pid 1029697:tid 1029847] [client 185.226.198.4:18642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thechurchinirving.org"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "aqxbjG65wm-f4uX16X6XOwAAABQ"]
[Thu Sep 17 15:28:44.932118 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxbjG65wm-f4uX16X6XPAAAAAQ"]
[Thu Sep 17 15:28:45.092218 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxbjW65wm-f4uX16X6XSQAAAH0"]
[Thu Sep 17 15:28:45.122796 2026] [proxy:warn] [pid 1029697:tid 1029896] [client 18.116.101.220:57864] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be trcco.org for uri /400.shtml
[Thu Sep 17 15:28:45.130947 2026] [security2:error] [pid 1029697:tid 1029853] [client 143.105.152.240:3644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbjW65wm-f4uX16X6XTQAAABo"]
[Thu Sep 17 15:28:45.131042 2026] [security2:error] [pid 1029697:tid 1029853] [client 143.105.152.240:3644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbjW65wm-f4uX16X6XTQAAABo"]
[Thu Sep 17 15:28:45.198110 2026] [security2:error] [pid 1029697:tid 1029884] [client 4.240.114.86:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxbjW65wm-f4uX16X6XUAAAADk"], referer: binance.com
[Thu Sep 17 15:28:45.231575 2026] [security2:error] [pid 1029697:tid 1029830] [client 18.116.101.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxbjW65wm-f4uX16X6XTwAAAAM"]
[Thu Sep 17 15:28:45.231601 2026] [security2:error] [pid 1029697:tid 1029830] [client 18.116.101.220:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxbjW65wm-f4uX16X6XTwAAAAM"]
[Thu Sep 17 15:28:45.262481 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxbjW65wm-f4uX16X6XUQAAAC8"]
[Thu Sep 17 15:28:45.356506 2026] [security2:error] [pid 1029697:tid 1029896] [client 18.116.101.220:57864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/400.shtml"] [unique_id "aqxbjW65wm-f4uX16X6XSwAAAEU"]
[Thu Sep 17 15:28:45.422804 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxbjW65wm-f4uX16X6XWAAAAFY"]
[Thu Sep 17 15:28:45.579634 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxbjW65wm-f4uX16X6XYQAAAHA"]
[Thu Sep 17 15:28:45.739973 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxbjW65wm-f4uX16X6XZgAAACY"]
[Thu Sep 17 15:28:45.899161 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxbjW65wm-f4uX16X6XbQAAADM"]
[Thu Sep 17 15:28:45.951688 2026] [security2:error] [pid 1029697:tid 1029925] [client 16.216.88.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxbjW65wm-f4uX16X6XaAAAAGI"]
[Thu Sep 17 15:28:46.059013 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxbjm65wm-f4uX16X6XdQAAAB0"]
[Thu Sep 17 15:28:46.220639 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxbjm65wm-f4uX16X6XewAAAFc"]
[Thu Sep 17 15:28:46.364939 2026] [security2:error] [pid 1029697:tid 1029900] [client 114.198.138.124:63342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbjm65wm-f4uX16X6XgAAAAEk"]
[Thu Sep 17 15:28:46.365261 2026] [security2:error] [pid 1029697:tid 1029900] [client 114.198.138.124:63342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbjm65wm-f4uX16X6XgAAAAEk"]
[Thu Sep 17 15:28:46.377374 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxbjm65wm-f4uX16X6XggAAAD0"]
[Thu Sep 17 15:28:46.535401 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxbjm65wm-f4uX16X6XigAAAHo"]
[Thu Sep 17 15:28:46.694066 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxbjm65wm-f4uX16X6XjgAAAGk"]
[Thu Sep 17 15:28:46.851971 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxbjm65wm-f4uX16X6XkgAAABE"]
[Thu Sep 17 15:28:47.013844 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxbj265wm-f4uX16X6XmAAAAEI"]
[Thu Sep 17 15:28:47.176546 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxbj265wm-f4uX16X6XmwAAAAw"]
[Thu Sep 17 15:28:47.181285 2026] [security2:error] [pid 1029697:tid 1029927] [client 185.226.198.6:42020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxbj265wm-f4uX16X6XmgAAAGQ"]
[Thu Sep 17 15:28:47.336791 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxbj265wm-f4uX16X6XnwAAAGs"]
[Thu Sep 17 15:28:47.456129 2026] [security2:error] [pid 1029697:tid 1029875] [client 36.36.91.126:20586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.91.36.36.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mtbclubdecampo.com"] [uri "/ruta.php"] [unique_id "aqxbj265wm-f4uX16X6XoAAAADA"], referer: http://www.mtbclubdecampo.com/descripciones.php?orden=distancia
[Thu Sep 17 15:28:47.502030 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxbj265wm-f4uX16X6XpAAAACQ"]
[Thu Sep 17 15:28:47.660049 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxbj265wm-f4uX16X6XpgAAAHU"]
[Thu Sep 17 15:28:47.822266 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.219.249:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxbj265wm-f4uX16X6XqQAAADc"]
[Thu Sep 17 15:28:48.054544 2026] [security2:error] [pid 1029697:tid 1029840] [client 57.141.14.67:40458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxbj265wm-f4uX16X6XqwAADQs"]
[Thu Sep 17 15:28:48.228272 2026] [security2:error] [pid 1029697:tid 1029909] [client 41.23.99.196:23764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbkG65wm-f4uX16X6XsgAAUgM"]
[Thu Sep 17 15:28:48.296650 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxbkG65wm-f4uX16X6XtgAAAAA"]
[Thu Sep 17 15:28:48.449425 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxbkG65wm-f4uX16X6XugAAADE"]
[Thu Sep 17 15:28:48.601534 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxbkG65wm-f4uX16X6XvgAAAAY"]
[Thu Sep 17 15:28:48.783273 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxbkG65wm-f4uX16X6XwwAAACU"]
[Thu Sep 17 15:28:48.786017 2026] [security2:error] [pid 1029697:tid 1029846] [client 169.58.197.253:49906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/utf8.php"] [unique_id "aqxbkG65wm-f4uX16X6XxAAAABM"], referer: binance.com
[Thu Sep 17 15:28:48.935937 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxbkG65wm-f4uX16X6XyAAAAEc"]
[Thu Sep 17 15:28:49.004598 2026] [core:error] [pid 1029697:tid 1029828] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:49.004615 2026] [core:error] [pid 1029697:tid 1029828] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:49.094815 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxbkW65wm-f4uX16X6XzwAAACA"]
[Thu Sep 17 15:28:49.247641 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxbkW65wm-f4uX16X6X0gAAABc"]
[Thu Sep 17 15:28:49.334434 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.94.35.111:43220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.ivorygarlock.com"] [uri "/"] [unique_id "aqxbkW65wm-f4uX16X6X1wAAAH8"]
[Thu Sep 17 15:28:49.403794 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxbkW65wm-f4uX16X6X2QAAAGk"]
[Thu Sep 17 15:28:49.555348 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxbkW65wm-f4uX16X6X3wAAAB4"]
[Thu Sep 17 15:28:49.654829 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.35.111:43232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.ivorygarlock.com"] [uri "/"] [unique_id "aqxbkW65wm-f4uX16X6X4wAAADU"]
[Thu Sep 17 15:28:49.709204 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxbkW65wm-f4uX16X6X5AAAADo"]
[Thu Sep 17 15:28:49.865316 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxbkW65wm-f4uX16X6X5wAAAEQ"]
[Thu Sep 17 15:28:50.014419 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.94.35.111:43242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.ivorygarlock.com"] [uri "/"] [unique_id "aqxbkm65wm-f4uX16X6X6wAAAGQ"]
[Thu Sep 17 15:28:50.017154 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxbkm65wm-f4uX16X6X7AAAADA"]
[Thu Sep 17 15:28:50.147324 2026] [security2:error] [pid 1029697:tid 1029951] [client 4.240.114.86:57858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxbkm65wm-f4uX16X6X8wAAAHw"], referer: binance.com
[Thu Sep 17 15:28:50.174315 2026] [security2:error] [pid 1029697:tid 1029891] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxbkm65wm-f4uX16X6X9AAAAEA"]
[Thu Sep 17 15:28:50.305355 2026] [security2:error] [pid 1029697:tid 1029849] [client 185.55.149.49:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbkm65wm-f4uX16X6X-QAAABY"]
[Thu Sep 17 15:28:50.305463 2026] [security2:error] [pid 1029697:tid 1029849] [client 185.55.149.49:60662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbkm65wm-f4uX16X6X-QAAABY"]
[Thu Sep 17 15:28:50.327352 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxbkm65wm-f4uX16X6X-gAAAD8"]
[Thu Sep 17 15:28:50.331019 2026] [core:error] [pid 1029697:tid 1029866] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:50.331034 2026] [core:error] [pid 1029697:tid 1029866] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:50.479926 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxbkm65wm-f4uX16X6YAAAAAGc"]
[Thu Sep 17 15:28:50.595715 2026] [security2:error] [pid 1029697:tid 1029703] [remote 216.73.216.238:19467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.energynowspa.com"] [uri "/index.php"] [unique_id "aqxbkm65wm-f4uX16X6YAgAAHQU"]
[Thu Sep 17 15:28:50.607426 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.94.35.111:43266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.ivorygarlock.com"] [uri "/"] [unique_id "aqxbkm65wm-f4uX16X6YBAAAAAY"]
[Thu Sep 17 15:28:50.632332 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxbkm65wm-f4uX16X6YBQAAAB8"]
[Thu Sep 17 15:28:50.784135 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxbkm65wm-f4uX16X6YCQAAABk"]
[Thu Sep 17 15:28:50.807199 2026] [security2:error] [pid 1029697:tid 1029898] [client 93.152.209.7:17910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "brianpagano.com"] [uri "/.env"] [unique_id "aqxbkm65wm-f4uX16X6YCwAAAEc"]
[Thu Sep 17 15:28:50.935801 2026] [security2:error] [pid 1029697:tid 1029892] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxbkm65wm-f4uX16X6YDgAAAEE"]
[Thu Sep 17 15:28:50.955056 2026] [security2:error] [pid 1029697:tid 1029746] [remote 93.152.209.7:10432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "brianpagano.com"] [uri "/.env"] [unique_id "aqxbkm65wm-f4uX16X6YDwAAPjA"]
[Thu Sep 17 15:28:51.026801 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.94.35.111:43278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxbk265wm-f4uX16X6YFgAAABQ"]
[Thu Sep 17 15:28:51.087499 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxbk265wm-f4uX16X6YGQAAADY"]
[Thu Sep 17 15:28:51.119611 2026] [core:error] [pid 1029697:tid 1029871] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:51.119627 2026] [core:error] [pid 1029697:tid 1029871] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:51.244216 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxbk265wm-f4uX16X6YHgAAADI"]
[Thu Sep 17 15:28:51.373878 2026] [security2:error] [pid 1029697:tid 1029848] [client 69.178.71.175:57945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbk265wm-f4uX16X6YHwAAFRk"]
[Thu Sep 17 15:28:51.396444 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxbk265wm-f4uX16X6YIwAAAEI"]
[Thu Sep 17 15:28:51.501510 2026] [core:error] [pid 1029697:tid 1029953] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:51.501531 2026] [core:error] [pid 1029697:tid 1029953] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:51.549025 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxbk265wm-f4uX16X6YKwAAAAI"]
[Thu Sep 17 15:28:51.700584 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxbk265wm-f4uX16X6YLgAAAGs"]
[Thu Sep 17 15:28:51.853165 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxbk265wm-f4uX16X6YMgAAAHI"]
[Thu Sep 17 15:28:51.917015 2026] [core:error] [pid 1029697:tid 1029894] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:51.917032 2026] [core:error] [pid 1029697:tid 1029894] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:52.007551 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxblG65wm-f4uX16X6YOwAAACo"]
[Thu Sep 17 15:28:52.159938 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxblG65wm-f4uX16X6YPQAAAAA"]
[Thu Sep 17 15:28:52.237216 2026] [core:error] [pid 1029697:tid 1029923] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:52.237236 2026] [core:error] [pid 1029697:tid 1029923] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:52.311806 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxblG65wm-f4uX16X6YSAAAAB8"]
[Thu Sep 17 15:28:52.464203 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxblG65wm-f4uX16X6YTAAAAEc"]
[Thu Sep 17 15:28:52.574700 2026] [core:error] [pid 1029697:tid 1029859] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:52.574718 2026] [core:error] [pid 1029697:tid 1029859] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:52.615899 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxblG65wm-f4uX16X6YVQAAABQ"]
[Thu Sep 17 15:28:52.698838 2026] [security2:error] [pid 1029697:tid 1029842] [client 69.178.71.175:60661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxblG65wm-f4uX16X6YVgAADyc"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&from=20260818012338&hideliu=1&limit=100&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:28:52.773991 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxblG65wm-f4uX16X6YXAAAAAQ"]
[Thu Sep 17 15:28:52.930455 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxblG65wm-f4uX16X6YXwAAAB4"]
[Thu Sep 17 15:28:53.086033 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxblW65wm-f4uX16X6YZQAAAEI"]
[Thu Sep 17 15:28:53.117198 2026] [security2:error] [pid 1029697:tid 1029839] [client 4.240.114.86:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxblW65wm-f4uX16X6YaAAAAAw"], referer: binance.com
[Thu Sep 17 15:28:53.119066 2026] [core:error] [pid 1029697:tid 1029921] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:53.119080 2026] [core:error] [pid 1029697:tid 1029921] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:53.241219 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxblW65wm-f4uX16X6YagAAAEw"]
[Thu Sep 17 15:28:53.332003 2026] [security2:error] [pid 1029697:tid 1029896] [client 136.158.61.34:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxblW65wm-f4uX16X6YbQAAAEU"]
[Thu Sep 17 15:28:53.332092 2026] [security2:error] [pid 1029697:tid 1029896] [client 136.158.61.34:33560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxblW65wm-f4uX16X6YbQAAAEU"]
[Thu Sep 17 15:28:53.396247 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxblW65wm-f4uX16X6YbgAAAHI"]
[Thu Sep 17 15:28:53.516604 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.94.35.111:43338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxblW65wm-f4uX16X6YcgAAAEM"]
[Thu Sep 17 15:28:53.549063 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.94.35.111:43338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxblW65wm-f4uX16X6YdAAAAGM"]
[Thu Sep 17 15:28:53.550424 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxblW65wm-f4uX16X6YdgAAACo"]
[Thu Sep 17 15:28:53.658066 2026] [core:error] [pid 1029697:tid 1029862] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:53.658082 2026] [core:error] [pid 1029697:tid 1029862] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:53.716834 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxblW65wm-f4uX16X6YgQAAAD8"]
[Thu Sep 17 15:28:53.874956 2026] [security2:error] [pid 1029697:tid 1029876] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxblW65wm-f4uX16X6YhwAAADE"]
[Thu Sep 17 15:28:53.899753 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.35.111:43348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxblW65wm-f4uX16X6YiAAAAFI"]
[Thu Sep 17 15:28:54.036991 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxblm65wm-f4uX16X6YkwAAABk"]
[Thu Sep 17 15:28:54.065789 2026] [core:error] [pid 1029697:tid 1029898] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:54.065807 2026] [core:error] [pid 1029697:tid 1029898] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:54.217820 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxblm65wm-f4uX16X6YmQAAAFc"]
[Thu Sep 17 15:28:54.371535 2026] [core:error] [pid 1029697:tid 1029868] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:54.371557 2026] [core:error] [pid 1029697:tid 1029868] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:54.388175 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxblm65wm-f4uX16X6YoQAAAAM"]
[Thu Sep 17 15:28:54.549214 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxblm65wm-f4uX16X6YpgAAABo"]
[Thu Sep 17 15:28:54.703343 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxblm65wm-f4uX16X6YrAAAAF0"]
[Thu Sep 17 15:28:54.730720 2026] [core:error] [pid 1029697:tid 1029880] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:54.730740 2026] [core:error] [pid 1029697:tid 1029880] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:54.855753 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxblm65wm-f4uX16X6YsQAAAEw"]
[Thu Sep 17 15:28:55.006788 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxbl265wm-f4uX16X6YtwAAADc"]
[Thu Sep 17 15:28:55.044919 2026] [core:error] [pid 1029697:tid 1029863] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:55.044936 2026] [core:error] [pid 1029697:tid 1029863] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:55.158577 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxbl265wm-f4uX16X6YvgAAACM"]
[Thu Sep 17 15:28:55.242838 2026] [security2:error] [pid 1029697:tid 1029944] [client 103.61.184.148:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbl265wm-f4uX16X6YwgAAAHU"]
[Thu Sep 17 15:28:55.242981 2026] [security2:error] [pid 1029697:tid 1029944] [client 103.61.184.148:54218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbl265wm-f4uX16X6YwgAAAHU"]
[Thu Sep 17 15:28:55.315231 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxbl265wm-f4uX16X6YxAAAAEk"]
[Thu Sep 17 15:28:55.475826 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxbl265wm-f4uX16X6YzAAAAEg"]
[Thu Sep 17 15:28:55.630326 2026] [core:error] [pid 1029697:tid 1029871] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:55.630347 2026] [core:error] [pid 1029697:tid 1029871] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:55.649421 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxbl265wm-f4uX16X6Y2gAAAGc"]
[Thu Sep 17 15:28:55.693616 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.31.203.120:15360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxbl265wm-f4uX16X6YxgAAYBQ"]
[Thu Sep 17 15:28:55.780717 2026] [security2:error] [pid 1029697:tid 1029854] [client 143.105.152.240:15210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbl265wm-f4uX16X6Y6AAAABs"]
[Thu Sep 17 15:28:55.780910 2026] [security2:error] [pid 1029697:tid 1029854] [client 143.105.152.240:15210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbl265wm-f4uX16X6Y6AAAABs"]
[Thu Sep 17 15:28:55.808280 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxbl265wm-f4uX16X6Y6QAAABU"]
[Thu Sep 17 15:28:55.968787 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxbl265wm-f4uX16X6Y8wAAAGQ"]
[Thu Sep 17 15:28:56.027635 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxbl265wm-f4uX16X6Y7gAAAF0"]
[Thu Sep 17 15:28:56.085521 2026] [core:error] [pid 1029697:tid 1029950] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:56.085544 2026] [core:error] [pid 1029697:tid 1029950] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:56.125790 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxbmG65wm-f4uX16X6ZAAAAAHU"]
[Thu Sep 17 15:28:56.195828 2026] [security2:error] [pid 1029697:tid 1029836] [client 4.240.114.86:60757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxbmG65wm-f4uX16X6ZBAAAAAk"], referer: binance.com
[Thu Sep 17 15:28:56.279006 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxbmG65wm-f4uX16X6ZBgAAAG0"]
[Thu Sep 17 15:28:56.434764 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxbmG65wm-f4uX16X6ZCwAAAGg"]
[Thu Sep 17 15:28:56.533027 2026] [core:error] [pid 1029697:tid 1029935] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:56.533049 2026] [core:error] [pid 1029697:tid 1029935] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:56.610339 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxbmG65wm-f4uX16X6ZEgAAAD0"]
[Thu Sep 17 15:28:56.619819 2026] [security2:error] [pid 1029697:tid 1029938] [client 216.73.216.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxbmG65wm-f4uX16X6ZBQAAAG8"], referer: http://sableandox.co.uk/sitemap.xml
[Thu Sep 17 15:28:56.761889 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxbmG65wm-f4uX16X6ZFwAAAB4"]
[Thu Sep 17 15:28:56.918782 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxbmG65wm-f4uX16X6ZHQAAAE8"]
[Thu Sep 17 15:28:56.998412 2026] [security2:error] [pid 1029697:tid 1029828] [client 114.198.138.124:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbmG65wm-f4uX16X6ZIAAAAAE"]
[Thu Sep 17 15:28:56.998509 2026] [security2:error] [pid 1029697:tid 1029828] [client 114.198.138.124:63978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbmG65wm-f4uX16X6ZIAAAAAE"]
[Thu Sep 17 15:28:57.070870 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxbmW65wm-f4uX16X6ZIgAAAF4"]
[Thu Sep 17 15:28:57.209511 2026] [core:error] [pid 1029697:tid 1029902] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:57.209528 2026] [core:error] [pid 1029697:tid 1029902] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:57.222120 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxbmW65wm-f4uX16X6ZJwAAAF8"]
[Thu Sep 17 15:28:57.377528 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxbmW65wm-f4uX16X6ZKQAAAGQ"]
[Thu Sep 17 15:28:57.544529 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxbmW65wm-f4uX16X6ZMQAAAEY"]
[Thu Sep 17 15:28:57.639701 2026] [core:error] [pid 1029697:tid 1029901] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:57.639721 2026] [core:error] [pid 1029697:tid 1029901] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:57.700565 2026] [security2:error] [pid 1029697:tid 1029885] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxbmW65wm-f4uX16X6ZOQAAADo"]
[Thu Sep 17 15:28:57.787863 2026] [security2:error] [pid 1029697:tid 1029851] [client 169.58.197.253:50520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/view-config.php"] [unique_id "aqxbmW65wm-f4uX16X6ZOwAAABg"], referer: binance.com
[Thu Sep 17 15:28:57.859145 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxbmW65wm-f4uX16X6ZPwAAAA0"]
[Thu Sep 17 15:28:58.020116 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxbmm65wm-f4uX16X6ZRwAAAAc"]
[Thu Sep 17 15:28:58.118397 2026] [security2:error] [pid 1029697:tid 1029946] [client 96.244.144.135:64932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbmW65wm-f4uX16X6ZRQAAd1A"]
[Thu Sep 17 15:28:58.213882 2026] [core:error] [pid 1029697:tid 1029915] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:58.213902 2026] [core:error] [pid 1029697:tid 1029915] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:58.223761 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxbmm65wm-f4uX16X6ZTgAAAD8"]
[Thu Sep 17 15:28:58.392577 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxbmm65wm-f4uX16X6ZVwAAACw"]
[Thu Sep 17 15:28:58.514933 2026] [core:error] [pid 1029697:tid 1029938] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:58.514953 2026] [core:error] [pid 1029697:tid 1029938] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:58.570106 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxbmm65wm-f4uX16X6ZYgAAAB4"]
[Thu Sep 17 15:28:58.723638 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxbmm65wm-f4uX16X6ZaAAAAAE"]
[Thu Sep 17 15:28:58.811746 2026] [security2:error] [pid 1029697:tid 1029887] [client 4.240.114.86:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxbmm65wm-f4uX16X6ZagAAADw"], referer: binance.com
[Thu Sep 17 15:28:58.842624 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.94.35.111:55116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxbmm65wm-f4uX16X6ZawAAAD4"]
[Thu Sep 17 15:28:58.882140 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.94.35.111:55116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxbmm65wm-f4uX16X6ZbgAAAC8"]
[Thu Sep 17 15:28:58.934088 2026] [security2:error] [pid 1029697:tid 1029836] [client 66.249.93.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overrock.uk"] [uri "/index.php"] [unique_id "aqxbmm65wm-f4uX16X6ZTAAACTI"]
[Thu Sep 17 15:28:58.941694 2026] [core:error] [pid 1029697:tid 1029910] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:58.941711 2026] [core:error] [pid 1029697:tid 1029910] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:59.279051 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxbm265wm-f4uX16X6ZewAAABc"]
[Thu Sep 17 15:28:59.418740 2026] [core:error] [pid 1029697:tid 1029941] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:59.418758 2026] [core:error] [pid 1029697:tid 1029941] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:59.435829 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxbm265wm-f4uX16X6ZgQAAAGs"]
[Thu Sep 17 15:28:59.592463 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxbm265wm-f4uX16X6ZjAAAAGo"]
[Thu Sep 17 15:28:59.747701 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxbm265wm-f4uX16X6ZkQAAAEM"]
[Thu Sep 17 15:28:59.766265 2026] [core:error] [pid 1029697:tid 1029896] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:59.766282 2026] [core:error] [pid 1029697:tid 1029896] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:28:59.903201 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxbm265wm-f4uX16X6ZlAAAABQ"]
[Thu Sep 17 15:29:00.069844 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxbnG65wm-f4uX16X6ZmQAAAAY"]
[Thu Sep 17 15:29:00.226537 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.154.219.249:59376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxbnG65wm-f4uX16X6ZnwAAAHM"]
[Thu Sep 17 15:29:00.358906 2026] [security2:error] [pid 1029697:tid 1029924] [client 96.244.144.135:64968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbnG65wm-f4uX16X6ZoAAAYSw"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260725133453&hideanons=1&limit=500&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:29:00.392065 2026] [core:error] [pid 1029697:tid 1029835] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:00.392084 2026] [core:error] [pid 1029697:tid 1029835] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:00.695171 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxbnG65wm-f4uX16X6ZrQAAAE8"]
[Thu Sep 17 15:29:00.853309 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxbnG65wm-f4uX16X6ZsQAAAAQ"]
[Thu Sep 17 15:29:00.883592 2026] [core:error] [pid 1029697:tid 1029945] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:00.883608 2026] [core:error] [pid 1029697:tid 1029945] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:00.953750 2026] [core:error] [pid 1029697:tid 1029852] [client 157.245.146.242:41264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:00.953767 2026] [core:error] [pid 1029697:tid 1029852] [client 157.245.146.242:41264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:01.012703 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxbnW65wm-f4uX16X6ZuwAAAEo"]
[Thu Sep 17 15:29:01.130525 2026] [security2:error] [pid 1029697:tid 1029865] [client 4.240.114.86:63414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxbnW65wm-f4uX16X6ZvAAAACY"], referer: binance.com
[Thu Sep 17 15:29:01.168235 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxbnW65wm-f4uX16X6ZwAAAABg"]
[Thu Sep 17 15:29:01.319109 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.94.35.111:55154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxbnW65wm-f4uX16X6ZxAAAAHg"]
[Thu Sep 17 15:29:01.324793 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxbnW65wm-f4uX16X6ZxgAAAAc"]
[Thu Sep 17 15:29:01.385795 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.111:55154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxbnW65wm-f4uX16X6ZyQAAAHc"]
[Thu Sep 17 15:29:01.417834 2026] [core:error] [pid 1029697:tid 1029853] [client 157.245.146.242:41274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:01.417871 2026] [core:error] [pid 1029697:tid 1029853] [client 157.245.146.242:41274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:01.447539 2026] [security2:error] [pid 1029697:tid 1029844] [client 185.55.149.49:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbnW65wm-f4uX16X6ZzAAAABE"]
[Thu Sep 17 15:29:01.447708 2026] [security2:error] [pid 1029697:tid 1029844] [client 185.55.149.49:63608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbnW65wm-f4uX16X6ZzAAAABE"]
[Thu Sep 17 15:29:01.482717 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxbnW65wm-f4uX16X6ZzgAAAG0"]
[Thu Sep 17 15:29:01.636755 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.94.35.111:55154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxbnW65wm-f4uX16X6Z0wAAAAg"]
[Thu Sep 17 15:29:01.640931 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxbnW65wm-f4uX16X6Z1AAAAEg"]
[Thu Sep 17 15:29:01.667465 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.94.35.111:55154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxbnW65wm-f4uX16X6Z1QAAAHo"]
[Thu Sep 17 15:29:01.734671 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.35.111:55154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxbnW65wm-f4uX16X6Z1gAAAGc"]
[Thu Sep 17 15:29:01.764394 2026] [security2:error] [pid 1029697:tid 1029889] [client 34.94.35.111:55154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxbnW65wm-f4uX16X6Z1wAAAD4"]
[Thu Sep 17 15:29:01.796166 2026] [security2:error] [pid 1029697:tid 1029937] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxbnW65wm-f4uX16X6Z2QAAAG4"]
[Thu Sep 17 15:29:01.861183 2026] [core:error] [pid 1029697:tid 1029831] [client 157.245.146.242:41284] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:01.861205 2026] [core:error] [pid 1029697:tid 1029831] [client 157.245.146.242:41284] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:01.900264 2026] [core:error] [pid 1029697:tid 1029940] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:01.900285 2026] [core:error] [pid 1029697:tid 1029940] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:01.954210 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxbnW65wm-f4uX16X6aAAAAAGQ"]
[Thu Sep 17 15:29:02.128005 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxbnm65wm-f4uX16X6aCgAAADc"]
[Thu Sep 17 15:29:02.211287 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxbnm65wm-f4uX16X6aDAAAAHs"]
[Thu Sep 17 15:29:02.241775 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxbnm65wm-f4uX16X6aDQAAAGs"]
[Thu Sep 17 15:29:02.288874 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxbnm65wm-f4uX16X6aDwAAADg"]
[Thu Sep 17 15:29:02.303835 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxbnm65wm-f4uX16X6aEAAAAFQ"]
[Thu Sep 17 15:29:02.319262 2026] [core:error] [pid 1029697:tid 1029851] [client 157.245.146.242:41294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:02.319279 2026] [core:error] [pid 1029697:tid 1029851] [client 157.245.146.242:41294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:02.342314 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxbnm65wm-f4uX16X6aEgAAAGo"]
[Thu Sep 17 15:29:02.456888 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxbnm65wm-f4uX16X6aFwAAAEI"]
[Thu Sep 17 15:29:02.468687 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxbnm65wm-f4uX16X6aGQAAAEk"]
[Thu Sep 17 15:29:02.617635 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxbnm65wm-f4uX16X6aHgAAAB4"]
[Thu Sep 17 15:29:02.629940 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxbnm65wm-f4uX16X6aIQAAAEg"]
[Thu Sep 17 15:29:02.646064 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxbnm65wm-f4uX16X6aIgAAACU"]
[Thu Sep 17 15:29:02.666852 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxbnm65wm-f4uX16X6aIwAAADM"]
[Thu Sep 17 15:29:02.776910 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxbnm65wm-f4uX16X6aJwAAAB0"]
[Thu Sep 17 15:29:02.778061 2026] [core:error] [pid 1029697:tid 1029831] [client 157.245.146.242:41300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:02.778081 2026] [core:error] [pid 1029697:tid 1029831] [client 157.245.146.242:41300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:02.803472 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxbnm65wm-f4uX16X6aKAAAAF8"]
[Thu Sep 17 15:29:02.884594 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxbnm65wm-f4uX16X6aKgAAAEs"]
[Thu Sep 17 15:29:02.914906 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxbnm65wm-f4uX16X6aKwAAAFY"]
[Thu Sep 17 15:29:02.939785 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxbnm65wm-f4uX16X6aLAAAABI"]
[Thu Sep 17 15:29:03.023077 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxbn265wm-f4uX16X6aMAAAAE8"]
[Thu Sep 17 15:29:03.102963 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxbn265wm-f4uX16X6aNQAAADc"]
[Thu Sep 17 15:29:03.128521 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxbn265wm-f4uX16X6aNgAAAGs"]
[Thu Sep 17 15:29:03.187830 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxbn265wm-f4uX16X6aNwAAACQ"]
[Thu Sep 17 15:29:03.262042 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxbn265wm-f4uX16X6aOAAAAGU"]
[Thu Sep 17 15:29:03.276220 2026] [core:error] [pid 1029697:tid 1029885] [client 157.245.146.242:41304] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:03.276234 2026] [core:error] [pid 1029697:tid 1029885] [client 157.245.146.242:41304] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:03.400732 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxbn265wm-f4uX16X6aPQAAAA0"]
[Thu Sep 17 15:29:03.421086 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxbn265wm-f4uX16X6aPgAAACM"]
[Thu Sep 17 15:29:03.472296 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxbn265wm-f4uX16X6aQQAAAEk"]
[Thu Sep 17 15:29:03.492719 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxbn265wm-f4uX16X6aQgAAABE"]
[Thu Sep 17 15:29:03.582718 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxbn265wm-f4uX16X6aRgAAAB8"]
[Thu Sep 17 15:29:03.636556 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxbn265wm-f4uX16X6aSAAAAB4"]
[Thu Sep 17 15:29:03.644402 2026] [security2:error] [pid 1029697:tid 1029899] [client 4.240.114.86:64642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxbn265wm-f4uX16X6aSgAAAEg"], referer: binance.com
[Thu Sep 17 15:29:03.715729 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxbn265wm-f4uX16X6aTwAAACg"]
[Thu Sep 17 15:29:03.744244 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxbn265wm-f4uX16X6aUQAAAAk"]
[Thu Sep 17 15:29:03.792628 2026] [security2:error] [pid 1029697:tid 1029880] [client 172.235.55.41:46908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.235.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nexgenimplant.com"] [uri "/index.php"] [unique_id "aqxbn265wm-f4uX16X6aUwAAADU"]
[Thu Sep 17 15:29:03.795000 2026] [security2:error] [pid 1029697:tid 1029848] [client 172.235.55.41:46910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.235.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nexgenimplant.com"] [uri "/index.php/wp-json/batch/v1"] [unique_id "aqxbn265wm-f4uX16X6aUgAAABU"]
[Thu Sep 17 15:29:03.796097 2026] [security2:error] [pid 1029697:tid 1029953] [client 172.235.55.41:46902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexgenimplant.com"] [uri "/"] [unique_id "aqxbn265wm-f4uX16X6aVQAAAH4"]
[Thu Sep 17 15:29:03.796695 2026] [security2:error] [pid 1029697:tid 1029940] [client 172.235.55.41:46894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.nexgenimplant.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxbn265wm-f4uX16X6aVAAAAHE"]
[Thu Sep 17 15:29:03.841139 2026] [security2:error] [pid 1029697:tid 1029875] [client 172.235.55.41:46938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexgenimplant.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxbn265wm-f4uX16X6aVwAAADA"]
[Thu Sep 17 15:29:03.853197 2026] [security2:error] [pid 1029697:tid 1029909] [client 172.235.55.41:46960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexgenimplant.com"] [uri "/index.php"] [unique_id "aqxbn265wm-f4uX16X6aWAAAAFI"]
[Thu Sep 17 15:29:03.854416 2026] [security2:error] [pid 1029697:tid 1029891] [client 172.235.55.41:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.235.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nexgenimplant.com"] [uri "/index.php/wp-json/batch/v1"] [unique_id "aqxbn265wm-f4uX16X6aWQAAAEA"]
[Thu Sep 17 15:29:03.856618 2026] [security2:error] [pid 1029697:tid 1029945] [client 172.235.55.41:46932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.nexgenimplant.com"] [uri "/"] [unique_id "aqxbn265wm-f4uX16X6aWgAAAHY"]
[Thu Sep 17 15:29:03.906453 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxbn265wm-f4uX16X6aWwAAACc"]
[Thu Sep 17 15:29:03.966539 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxbn265wm-f4uX16X6aXQAAAF4"]
[Thu Sep 17 15:29:04.066922 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxboG65wm-f4uX16X6aYgAAAHI"]
[Thu Sep 17 15:29:04.082074 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxboG65wm-f4uX16X6aZgAAAGs"]
[Thu Sep 17 15:29:04.100404 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxboG65wm-f4uX16X6aZwAAACI"]
[Thu Sep 17 15:29:04.227951 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxboG65wm-f4uX16X6aaAAAAF0"]
[Thu Sep 17 15:29:04.267982 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxboG65wm-f4uX16X6aagAAAFM"]
[Thu Sep 17 15:29:04.388056 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxboG65wm-f4uX16X6abAAAABw"]
[Thu Sep 17 15:29:04.446497 2026] [autoindex:error] [pid 1029697:tid 1029914] [client 165.154.151.176:0] AH01276: Cannot serve directory /home1/sdkfwxmy/public_html/womenscubofpowell.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:29:04.465360 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxboG65wm-f4uX16X6acgAAAA0"]
[Thu Sep 17 15:29:04.492112 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxboG65wm-f4uX16X6acwAAACM"]
[Thu Sep 17 15:29:04.508058 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxboG65wm-f4uX16X6adAAAAHw"]
[Thu Sep 17 15:29:04.547344 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxboG65wm-f4uX16X6adgAAAAM"]
[Thu Sep 17 15:29:04.708829 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxboG65wm-f4uX16X6aeQAAAFU"]
[Thu Sep 17 15:29:04.735608 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxboG65wm-f4uX16X6aegAAAA4"]
[Thu Sep 17 15:29:04.796946 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxboG65wm-f4uX16X6afwAAAHc"]
[Thu Sep 17 15:29:04.858967 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxboG65wm-f4uX16X6agAAAAHg"]
[Thu Sep 17 15:29:04.878174 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxboG65wm-f4uX16X6agQAAAAU"]
[Thu Sep 17 15:29:04.959988 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxboG65wm-f4uX16X6ahQAAABU"]
[Thu Sep 17 15:29:05.035267 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxboW65wm-f4uX16X6ajQAAAEQ"]
[Thu Sep 17 15:29:05.070147 2026] [security2:error] [pid 1029697:tid 1029810] [remote 47.128.20.66:34530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/a-5-part-series-on-michael-heisers-the-unseen-realm-part-4-jesus-casts-out-demons-and-leads-an-assault-on-mount-hermon/"] [unique_id "aqxboW65wm-f4uX16X6ajgAAUnA"]
[Thu Sep 17 15:29:05.191771 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxboW65wm-f4uX16X6akAAAADI"]
[Thu Sep 17 15:29:05.208879 2026] [security2:error] [pid 1029697:tid 1029908] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxboW65wm-f4uX16X6akQAAAFE"]
[Thu Sep 17 15:29:05.251799 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxboW65wm-f4uX16X6akwAAABA"]
[Thu Sep 17 15:29:05.326586 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxboW65wm-f4uX16X6anwAAAD8"]
[Thu Sep 17 15:29:05.352203 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxboW65wm-f4uX16X6aoQAAAAE"]
[Thu Sep 17 15:29:05.439669 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxboW65wm-f4uX16X6apwAAACA"]
[Thu Sep 17 15:29:05.461277 2026] [security2:error] [pid 1029697:tid 1029819] [remote 111.225.148.199:42138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zapatos.chabelo.com"] [uri "/"] [unique_id "aqxboW65wm-f4uX16X6aqQAAM3k"]
[Thu Sep 17 15:29:05.470789 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxboW65wm-f4uX16X6arAAAABs"]
[Thu Sep 17 15:29:05.514732 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxboW65wm-f4uX16X6asQAAACI"]
[Thu Sep 17 15:29:05.675459 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxboW65wm-f4uX16X6a1QAAAEI"]
[Thu Sep 17 15:29:05.767774 2026] [security2:error] [pid 1029697:tid 1029875] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxboW65wm-f4uX16X6a3wAAADA"]
[Thu Sep 17 15:29:05.839405 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxboW65wm-f4uX16X6a4wAAAD8"]
[Thu Sep 17 15:29:05.902284 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxboW65wm-f4uX16X6a6QAAAAE"]
[Thu Sep 17 15:29:05.955949 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxboW65wm-f4uX16X6a7wAAABs"]
[Thu Sep 17 15:29:06.000331 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxboW65wm-f4uX16X6a9gAAADg"]
[Thu Sep 17 15:29:06.017491 2026] [security2:error] [pid 1029697:tid 1029916] [client 136.158.61.34:34629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbom65wm-f4uX16X6a-AAAAFk"]
[Thu Sep 17 15:29:06.019412 2026] [security2:error] [pid 1029697:tid 1029916] [client 136.158.61.34:34629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbom65wm-f4uX16X6a-AAAAFk"]
[Thu Sep 17 15:29:06.030062 2026] [security2:error] [pid 1029697:tid 1029871] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxbom65wm-f4uX16X6a-QAAACw"]
[Thu Sep 17 15:29:06.112751 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxbom65wm-f4uX16X6a-wAAAF0"]
[Thu Sep 17 15:29:06.161460 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxbom65wm-f4uX16X6a_AAAAHs"]
[Thu Sep 17 15:29:06.173640 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxbom65wm-f4uX16X6a_wAAAHU"]
[Thu Sep 17 15:29:06.199531 2026] [security2:error] [pid 1029697:tid 1029834] [client 103.61.184.148:65395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbom65wm-f4uX16X6bAgAAAAc"]
[Thu Sep 17 15:29:06.199617 2026] [security2:error] [pid 1029697:tid 1029834] [client 103.61.184.148:65395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbom65wm-f4uX16X6bAgAAAAc"]
[Thu Sep 17 15:29:06.242832 2026] [security2:error] [pid 1029697:tid 1029884] [client 143.105.152.240:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbom65wm-f4uX16X6bBAAAADk"]
[Thu Sep 17 15:29:06.242934 2026] [security2:error] [pid 1029697:tid 1029884] [client 143.105.152.240:56762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbom65wm-f4uX16X6bBAAAADk"]
[Thu Sep 17 15:29:06.285950 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxbom65wm-f4uX16X6bBgAAAB4"]
[Thu Sep 17 15:29:06.325045 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxbom65wm-f4uX16X6bCAAAACM"]
[Thu Sep 17 15:29:06.492314 2026] [security2:error] [pid 1029697:tid 1029841] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxbom65wm-f4uX16X6bJgAAAA4"]
[Thu Sep 17 15:29:06.538945 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxbom65wm-f4uX16X6bJwAAABU"]
[Thu Sep 17 15:29:06.565004 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxbom65wm-f4uX16X6bKAAAACg"]
[Thu Sep 17 15:29:06.625860 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxbom65wm-f4uX16X6bKgAAAAQ"]
[Thu Sep 17 15:29:06.654421 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxbom65wm-f4uX16X6bLAAAAEQ"]
[Thu Sep 17 15:29:06.676994 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxbom65wm-f4uX16X6bLQAAAAw"]
[Thu Sep 17 15:29:06.721822 2026] [security2:error] [pid 1029697:tid 1029952] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxbom65wm-f4uX16X6bMAAAAH0"]
[Thu Sep 17 15:29:06.765607 2026] [security2:error] [pid 1029697:tid 1029913] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxbom65wm-f4uX16X6bMwAAAFY"]
[Thu Sep 17 15:29:06.785254 2026] [security2:error] [pid 1029697:tid 1029934] [client 169.58.197.253:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxbom65wm-f4uX16X6bNAAAAGs"], referer: binance.com
[Thu Sep 17 15:29:06.807039 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxbom65wm-f4uX16X6bNQAAAGw"]
[Thu Sep 17 15:29:06.818100 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxbom65wm-f4uX16X6bNgAAAD8"]
[Thu Sep 17 15:29:06.834539 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxbom65wm-f4uX16X6bOAAAAE8"]
[Thu Sep 17 15:29:06.866417 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxbom65wm-f4uX16X6bOQAAAAo"]
[Thu Sep 17 15:29:06.898677 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxbom65wm-f4uX16X6bOwAAAEs"]
[Thu Sep 17 15:29:06.936217 2026] [security2:error] [pid 1029697:tid 1029859] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxbom65wm-f4uX16X6bPAAAACA"]
[Thu Sep 17 15:29:06.972978 2026] [security2:error] [pid 1029697:tid 1029881] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxbom65wm-f4uX16X6bPwAAADY"]
[Thu Sep 17 15:29:06.981011 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxbom65wm-f4uX16X6bQAAAAG8"]
[Thu Sep 17 15:29:07.081329 2026] [security2:error] [pid 1029697:tid 1029882] [client 5.189.145.112:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.145.189.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christiansoncampusnlc.com"] [uri "/.well-known/config.php"] [unique_id "aqxbo265wm-f4uX16X6bVgAAADc"], referer: binance.com
[Thu Sep 17 15:29:07.082845 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxbo265wm-f4uX16X6bWQAAAGA"]
[Thu Sep 17 15:29:07.109601 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxbo265wm-f4uX16X6bYAAAAFw"]
[Thu Sep 17 15:29:07.136738 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxbo265wm-f4uX16X6bYQAAADQ"]
[Thu Sep 17 15:29:07.140073 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxbo265wm-f4uX16X6bYgAAAGo"]
[Thu Sep 17 15:29:07.161158 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxbo265wm-f4uX16X6bYwAAADw"]
[Thu Sep 17 15:29:07.220489 2026] [security2:error] [pid 1029697:tid 1029925] [client 4.240.114.86:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxbo265wm-f4uX16X6beAAAAGI"], referer: binance.com
[Thu Sep 17 15:29:07.249245 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxbo265wm-f4uX16X6bgQAAAHU"]
[Thu Sep 17 15:29:07.275892 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxbo265wm-f4uX16X6bgwAAAAc"]
[Thu Sep 17 15:29:07.303841 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxbo265wm-f4uX16X6bhgAAAGU"]
[Thu Sep 17 15:29:07.312214 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxbo265wm-f4uX16X6bhwAAADs"]
[Thu Sep 17 15:29:07.356808 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxbo265wm-f4uX16X6bjAAAADk"]
[Thu Sep 17 15:29:07.422830 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxbo265wm-f4uX16X6bjQAAACM"]
[Thu Sep 17 15:29:07.470454 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxbo265wm-f4uX16X6bkgAAAA0"]
[Thu Sep 17 15:29:07.622977 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxbo265wm-f4uX16X6bsAAAAHM"]
[Thu Sep 17 15:29:07.630758 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxbo265wm-f4uX16X6bsQAAABM"]
[Thu Sep 17 15:29:07.692780 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxbo265wm-f4uX16X6bswAAABc"]
[Thu Sep 17 15:29:07.709494 2026] [security2:error] [pid 1029697:tid 1029885] [client 114.198.138.124:64622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbo265wm-f4uX16X6btAAAADo"]
[Thu Sep 17 15:29:07.709580 2026] [security2:error] [pid 1029697:tid 1029885] [client 114.198.138.124:64622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbo265wm-f4uX16X6btAAAADo"]
[Thu Sep 17 15:29:07.753526 2026] [security2:error] [pid 1029697:tid 1029929] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxbo265wm-f4uX16X6btQAAAGY"]
[Thu Sep 17 15:29:07.791054 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxbo265wm-f4uX16X6bvAAAAB8"]
[Thu Sep 17 15:29:07.950270 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxbo265wm-f4uX16X6bvwAAACg"]
[Thu Sep 17 15:29:07.957735 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxbo265wm-f4uX16X6bwQAAABY"]
[Thu Sep 17 15:29:08.058562 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxbpG65wm-f4uX16X6bxwAAAHY"]
[Thu Sep 17 15:29:08.116473 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxbpG65wm-f4uX16X6bygAAACY"]
[Thu Sep 17 15:29:08.138152 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxbpG65wm-f4uX16X6bzAAAADU"]
[Thu Sep 17 15:29:08.226560 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxbpG65wm-f4uX16X6bzQAAAD8"]
[Thu Sep 17 15:29:08.273385 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxbpG65wm-f4uX16X6bzgAAAA8"]
[Thu Sep 17 15:29:08.288984 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxbpG65wm-f4uX16X6b0AAAAGk"]
[Thu Sep 17 15:29:08.387289 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxbpG65wm-f4uX16X6b0wAAAHA"]
[Thu Sep 17 15:29:08.419192 2026] [security2:error] [pid 1029697:tid 1029837] [client 168.228.216.137:32934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbpG65wm-f4uX16X6b0QAACmM"]
[Thu Sep 17 15:29:08.425264 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxbpG65wm-f4uX16X6b1AAAAAE"]
[Thu Sep 17 15:29:08.433192 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxbpG65wm-f4uX16X6b1QAAAEs"]
[Thu Sep 17 15:29:08.468146 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxbpG65wm-f4uX16X6b2AAAAF8"]
[Thu Sep 17 15:29:08.566289 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxbpG65wm-f4uX16X6b2wAAACo"]
[Thu Sep 17 15:29:08.591859 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxbpG65wm-f4uX16X6b3AAAAFk"]
[Thu Sep 17 15:29:08.627610 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.94.35.111:55160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxbpG65wm-f4uX16X6b3QAAAAg"]
[Thu Sep 17 15:29:08.747466 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxbpG65wm-f4uX16X6b4QAAAFw"]
[Thu Sep 17 15:29:08.867985 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxbpG65wm-f4uX16X6b5AAAAGo"]
[Thu Sep 17 15:29:08.908890 2026] [security2:error] [pid 1029697:tid 1029925] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxbpG65wm-f4uX16X6b5QAAAGI"]
[Thu Sep 17 15:29:08.987916 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxbpG65wm-f4uX16X6b6gAAADM"]
[Thu Sep 17 15:29:09.019280 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.env.bak"] [unique_id "aqxbpW65wm-f4uX16X6b7QAAdSs"]
[Thu Sep 17 15:29:09.019286 2026] [security2:error] [pid 1029697:tid 1029813] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.env.backup"] [unique_id "aqxbpW65wm-f4uX16X6b7wAAdXM"]
[Thu Sep 17 15:29:09.020385 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.env.old"] [unique_id "aqxbpW65wm-f4uX16X6b8gAAdSs"]
[Thu Sep 17 15:29:09.025701 2026] [security2:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.env.bak"] [unique_id "aqxbpW65wm-f4uX16X6cCwAAOTc"]
[Thu Sep 17 15:29:09.025731 2026] [security2:error] [pid 1029697:tid 1029814] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.env.backup"] [unique_id "aqxbpW65wm-f4uX16X6cDAAAOXQ"]
[Thu Sep 17 15:29:09.026765 2026] [security2:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.env.old"] [unique_id "aqxbpW65wm-f4uX16X6cDQAAOTc"]
[Thu Sep 17 15:29:09.049747 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxbpW65wm-f4uX16X6cIwAAABc"]
[Thu Sep 17 15:29:09.068062 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxbpW65wm-f4uX16X6cMAAAABU"]
[Thu Sep 17 15:29:09.111057 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxbpW65wm-f4uX16X6cPQAAAAw"]
[Thu Sep 17 15:29:09.191814 2026] [http2:info] [pid 16723:tid 16723] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:29:09.249461 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.154.219.249:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxbpW65wm-f4uX16X6cQAAAAH4"]
[Thu Sep 17 15:29:09.258172 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxbpW65wm-f4uX16X6cPwAAAFI"]
[Thu Sep 17 15:29:09.343101 2026] [security2:error] [pid 1029697:tid 1029946] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cKgAAAHc"]
[Thu Sep 17 15:29:09.361060 2026] [security2:error] [pid 1029697:tid 1029948] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cKwAAAHk"]
[Thu Sep 17 15:29:09.366297 2026] [security2:error] [pid 1029697:tid 1029784] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.env"] [unique_id "aqxbpW65wm-f4uX16X6cQwAAdVY"]
[Thu Sep 17 15:29:09.366800 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxbpW65wm-f4uX16X6cQgAAADU"]
[Thu Sep 17 15:29:09.373963 2026] [security2:error] [pid 1029697:tid 1029858] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cMQAAAB8"]
[Thu Sep 17 15:29:09.374491 2026] [security2:error] [pid 1029697:tid 1029851] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cNAAAABg"]
[Thu Sep 17 15:29:09.374513 2026] [security2:error] [pid 1029697:tid 1029892] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cJgAAAEE"]
[Thu Sep 17 15:29:09.384537 2026] [security2:error] [pid 1029697:tid 1029707] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.env"] [unique_id "aqxbpW65wm-f4uX16X6cRAAAOQk"]
[Thu Sep 17 15:29:09.411770 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.154.219.249:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxbpW65wm-f4uX16X6cRgAAAHA"]
[Thu Sep 17 15:29:09.415156 2026] [security2:error] [pid 1029697:tid 1029841] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cNwAAAA4"]
[Thu Sep 17 15:29:09.429685 2026] [security2:error] [pid 1029697:tid 1029885] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cKQAAADo"]
[Thu Sep 17 15:29:09.447223 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxbpW65wm-f4uX16X6cRwAAAF8"]
[Thu Sep 17 15:29:09.465731 2026] [security2:error] [pid 1029697:tid 1029701] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/.env.bak"] [unique_id "aqxbpW65wm-f4uX16X6cSQAAGwM"]
[Thu Sep 17 15:29:09.465738 2026] [security2:error] [pid 1029697:tid 1029820] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/.env.backup"] [unique_id "aqxbpW65wm-f4uX16X6cTAAAG3o"]
[Thu Sep 17 15:29:09.466776 2026] [security2:error] [pid 1029697:tid 1029701] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/.env.old"] [unique_id "aqxbpW65wm-f4uX16X6cTwAAGwM"]
[Thu Sep 17 15:29:09.471487 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxbpW65wm-f4uX16X6cWQAAAFk"]
[Thu Sep 17 15:29:09.587425 2026] [security2:error] [pid 1029697:tid 1029700] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/.env.php"] [unique_id "aqxbpW65wm-f4uX16X6cXgAAdQI"]
[Thu Sep 17 15:29:09.665561 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxbpW65wm-f4uX16X6cbAAAAHs"]
[Thu Sep 17 15:29:09.706653 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxbpW65wm-f4uX16X6cbQAAABc"]
[Thu Sep 17 15:29:09.715565 2026] [security2:error] [pid 1029697:tid 1029706] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/.env.php"] [unique_id "aqxbpW65wm-f4uX16X6ccAAAOQg"]
[Thu Sep 17 15:29:09.873058 2026] [security2:error] [pid 1029697:tid 1029752] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.env~"] [unique_id "aqxbpW65wm-f4uX16X6ceAAAdTY"]
[Thu Sep 17 15:29:09.873062 2026] [security2:error] [pid 1029697:tid 1029770] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.env.swp"] [unique_id "aqxbpW65wm-f4uX16X6ceQAAdUg"]
[Thu Sep 17 15:29:09.890148 2026] [security2:error] [pid 16723:tid 16904] [client 34.154.219.249:40970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/info.php"] [unique_id "aqxbpS9E0uOV11S2qN6aYwAAALc"]
[Thu Sep 17 15:29:09.890263 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxbpW65wm-f4uX16X6cewAAAEw"]
[Thu Sep 17 15:29:09.945312 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxbpW65wm-f4uX16X6cfgAAAGg"]
[Thu Sep 17 15:29:09.946295 2026] [security2:error] [pid 1029697:tid 1029734] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.env~"] [unique_id "aqxbpW65wm-f4uX16X6cfwAAOSQ"]
[Thu Sep 17 15:29:09.982325 2026] [security2:error] [pid 1029697:tid 1029946] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxbpW65wm-f4uX16X6chwAAAHc"]
[Thu Sep 17 15:29:10.057646 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxbpm65wm-f4uX16X6cigAAAEI"]
[Thu Sep 17 15:29:10.136079 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxbpm65wm-f4uX16X6ciwAAABg"]
[Thu Sep 17 15:29:10.186971 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxbpm65wm-f4uX16X6cjAAAAEc"]
[Thu Sep 17 15:29:10.201998 2026] [security2:error] [pid 1029697:tid 1029721] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.env.bak"] [unique_id "aqxbpm65wm-f4uX16X6ckQAAAxc"]
[Thu Sep 17 15:29:10.202005 2026] [security2:error] [pid 1029697:tid 1029723] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.env.backup"] [unique_id "aqxbpm65wm-f4uX16X6ckgAAAxk"]
[Thu Sep 17 15:29:10.203119 2026] [security2:error] [pid 1029697:tid 1029721] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.env.old"] [unique_id "aqxbpm65wm-f4uX16X6ckwAAAxc"]
[Thu Sep 17 15:29:10.213413 2026] [security2:error] [pid 1029697:tid 1029939] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxbpm65wm-f4uX16X6cowAAAHA"]
[Thu Sep 17 15:29:10.230230 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxbpm65wm-f4uX16X6cpgAAAGc"]
[Thu Sep 17 15:29:10.230546 2026] [security2:error] [pid 16723:tid 16783] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.env.bak"] [unique_id "aqxbpi9E0uOV11S2qN6acgAAqTo"]
[Thu Sep 17 15:29:10.230575 2026] [security2:error] [pid 16723:tid 16784] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.env.backup"] [unique_id "aqxbpi9E0uOV11S2qN6acwAAqTs"]
[Thu Sep 17 15:29:10.231720 2026] [qos:error] [pid 16723:tid 16814] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6aewAAqVk
[Thu Sep 17 15:29:10.232013 2026] [qos:error] [pid 16723:tid 16875] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpi9E0uOV11S2qN6afAAAAJo
[Thu Sep 17 15:29:10.232127 2026] [security2:error] [pid 16723:tid 16783] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.env.old"] [unique_id "aqxbpi9E0uOV11S2qN6adAAAqTo"]
[Thu Sep 17 15:29:10.232634 2026] [qos:error] [pid 16723:tid 16783] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6afgAAqTo
[Thu Sep 17 15:29:10.237571 2026] [security2:error] [pid 1029697:tid 1029721] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.env"] [unique_id "aqxbpm65wm-f4uX16X6crAAAAxc"]
[Thu Sep 17 15:29:10.240994 2026] [qos:error] [pid 16723:tid 16870] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpi9E0uOV11S2qN6ahQAAAJU
[Thu Sep 17 15:29:10.250602 2026] [qos:error] [pid 16723:tid 16910] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpi9E0uOV11S2qN6ahwAAAL0
[Thu Sep 17 15:29:10.251220 2026] [qos:error] [pid 16723:tid 16906] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpi9E0uOV11S2qN6aiAAAALk
[Thu Sep 17 15:29:10.251386 2026] [qos:error] [pid 1029697:tid 1029916] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxbpm65wm-f4uX16X6crgAAAFk
[Thu Sep 17 15:29:10.253568 2026] [qos:error] [pid 1029697:tid 1029922] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpm65wm-f4uX16X6crwAAAF8
[Thu Sep 17 15:29:10.258352 2026] [security2:error] [pid 1029697:tid 1029947] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cMgAAAHg"]
[Thu Sep 17 15:29:10.279716 2026] [qos:error] [pid 1029697:tid 1029933] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpm65wm-f4uX16X6ctAAAAGo
[Thu Sep 17 15:29:10.280230 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxbpm65wm-f4uX16X6csgAAADM"]
[Thu Sep 17 15:29:10.281802 2026] [qos:error] [pid 1029697:tid 1029866] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpm65wm-f4uX16X6cswAAACc
[Thu Sep 17 15:29:10.282169 2026] [qos:error] [pid 16723:tid 16916] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpi9E0uOV11S2qN6ajQAAAMM
[Thu Sep 17 15:29:10.285396 2026] [security2:error] [pid 1029697:tid 1029849] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cOgAAABY"]
[Thu Sep 17 15:29:10.287563 2026] [security2:error] [pid 1029697:tid 1029895] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cPAAAAEQ"]
[Thu Sep 17 15:29:10.291369 2026] [security2:error] [pid 1029697:tid 1029754] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.env.swp"] [unique_id "aqxbpm65wm-f4uX16X6ctQAAOTg"]
[Thu Sep 17 15:29:10.294121 2026] [security2:error] [pid 1029697:tid 1029897] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cLgAAAEY"]
[Thu Sep 17 15:29:10.294369 2026] [security2:error] [pid 1029697:tid 1029829] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cJwAAAAI"]
[Thu Sep 17 15:29:10.298722 2026] [security2:error] [pid 1029697:tid 1029870] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cLwAAACs"]
[Thu Sep 17 15:29:10.299593 2026] [security2:error] [pid 1029697:tid 1029912] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cLAAAAFU"]
[Thu Sep 17 15:29:10.301347 2026] [security2:error] [pid 1029697:tid 1029949] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cJQAAAHo"]
[Thu Sep 17 15:29:10.302345 2026] [security2:error] [pid 1029697:tid 1029927] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cOQAAAGQ"]
[Thu Sep 17 15:29:10.304417 2026] [security2:error] [pid 1029697:tid 1029853] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cNgAAABo"]
[Thu Sep 17 15:29:10.332383 2026] [security2:error] [pid 1029697:tid 1029929] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cLQAAAGY"]
[Thu Sep 17 15:29:10.358317 2026] [security2:error] [pid 1029697:tid 1029856] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cJAAAAB0"]
[Thu Sep 17 15:29:10.362720 2026] [security2:error] [pid 1029697:tid 1029864] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cKAAAACU"]
[Thu Sep 17 15:29:10.372307 2026] [security2:error] [pid 16723:tid 16913] [client 34.154.219.249:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/php.php"] [unique_id "aqxbpi9E0uOV11S2qN6akQAAAMA"]
[Thu Sep 17 15:29:10.379366 2026] [security2:error] [pid 1029697:tid 1029874] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cNQAAAC8"]
[Thu Sep 17 15:29:10.394587 2026] [security2:error] [pid 1029697:tid 1029900] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cMwAAAEk"]
[Thu Sep 17 15:29:10.415530 2026] [security2:error] [pid 16723:tid 16825] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/.env.php"] [unique_id "aqxbpi9E0uOV11S2qN6algAAqWQ"]
[Thu Sep 17 15:29:10.421726 2026] [security2:error] [pid 1029697:tid 1029750] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/.env.php"] [unique_id "aqxbpm65wm-f4uX16X6cvgAAAzQ"]
[Thu Sep 17 15:29:10.422425 2026] [security2:error] [pid 16723:tid 16844] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.env~"] [unique_id "aqxbpi9E0uOV11S2qN6amAAAqXc"]
[Thu Sep 17 15:29:10.435794 2026] [security2:error] [pid 1029697:tid 1029793] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.env~"] [unique_id "aqxbpm65wm-f4uX16X6cwgAAA18"]
[Thu Sep 17 15:29:10.437324 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxbpm65wm-f4uX16X6cwwAAAA8"]
[Thu Sep 17 15:29:10.437517 2026] [security2:error] [pid 16723:tid 16845] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.env.swp"] [unique_id "aqxbpi9E0uOV11S2qN6anAAAqXg"]
[Thu Sep 17 15:29:10.447988 2026] [security2:error] [pid 1029697:tid 1029771] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.env.swp"] [unique_id "aqxbpm65wm-f4uX16X6cygAAA0k"]
[Thu Sep 17 15:29:10.486202 2026] [security2:error] [pid 1029697:tid 1029731] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/api/.env"] [unique_id "aqxbpm65wm-f4uX16X6c1gAAdSE"]
[Thu Sep 17 15:29:10.487047 2026] [security2:error] [pid 1029697:tid 1029777] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/api/.env"] [unique_id "aqxbpm65wm-f4uX16X6c1wAAOU8"]
[Thu Sep 17 15:29:10.487210 2026] [security2:error] [pid 1029697:tid 1029762] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/app/.env"] [unique_id "aqxbpm65wm-f4uX16X6c2AAAOUA"]
[Thu Sep 17 15:29:10.493344 2026] [qos:error] [pid 1029697:tid 1029725] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c2gAAORs
[Thu Sep 17 15:29:10.496903 2026] [qos:error] [pid 16723:tid 16942] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpi9E0uOV11S2qN6aqgAAAN0
[Thu Sep 17 15:29:10.503260 2026] [qos:error] [pid 1029697:tid 1029901] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpm65wm-f4uX16X6c2wAAAEo
[Thu Sep 17 15:29:10.504794 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxbpm65wm-f4uX16X6c3AAAACc"]
[Thu Sep 17 15:29:10.505543 2026] [qos:error] [pid 16723:tid 16946] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpi9E0uOV11S2qN6arAAAAOE
[Thu Sep 17 15:29:10.512831 2026] [qos:error] [pid 1029697:tid 1029921] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpm65wm-f4uX16X6c3gAAAF4
[Thu Sep 17 15:29:10.578828 2026] [qos:error] [pid 1029697:tid 1029744] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c4QAAAy4
[Thu Sep 17 15:29:10.578833 2026] [qos:error] [pid 1029697:tid 1029738] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c4gAAAyg
[Thu Sep 17 15:29:10.578844 2026] [qos:error] [pid 1029697:tid 1029768] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c4wAAA0Y
[Thu Sep 17 15:29:10.578849 2026] [qos:error] [pid 1029697:tid 1029764] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c4AAAdUI
[Thu Sep 17 15:29:10.579179 2026] [security2:error] [pid 1029697:tid 1029775] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/app/.env"] [unique_id "aqxbpm65wm-f4uX16X6c3wAAdU0"]
[Thu Sep 17 15:29:10.595941 2026] [security2:error] [pid 1029697:tid 1029895] [client 4.240.114.86:54500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxbpm65wm-f4uX16X6c5AAAAEQ"], referer: binance.com
[Thu Sep 17 15:29:10.602446 2026] [qos:error] [pid 1029697:tid 1029730] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c5QAAAyA
[Thu Sep 17 15:29:10.607305 2026] [qos:error] [pid 16723:tid 16836] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6asAAAqW8
[Thu Sep 17 15:29:10.612889 2026] [qos:error] [pid 1029697:tid 1029757] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c5gAAdTs
[Thu Sep 17 15:29:10.616885 2026] [qos:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c5wAAA04
[Thu Sep 17 15:29:10.630857 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxbpm65wm-f4uX16X6c6AAAACs"]
[Thu Sep 17 15:29:10.642256 2026] [qos:error] [pid 1029697:tid 1029912] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbpm65wm-f4uX16X6c6QAAAFU
[Thu Sep 17 15:29:10.644554 2026] [security2:error] [pid 1029697:tid 1029803] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/api/.env"] [unique_id "aqxbpm65wm-f4uX16X6c6gAAA2k"]
[Thu Sep 17 15:29:10.647357 2026] [security2:error] [pid 1029697:tid 1029789] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/backend/.env"] [unique_id "aqxbpm65wm-f4uX16X6c6wAAdVs"]
[Thu Sep 17 15:29:10.662466 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxbpm65wm-f4uX16X6c7AAAABc"]
[Thu Sep 17 15:29:10.700851 2026] [security2:error] [pid 16723:tid 16849] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/api/.env"] [unique_id "aqxbpi9E0uOV11S2qN6asQAAqXw"]
[Thu Sep 17 15:29:10.705102 2026] [security2:error] [pid 1029697:tid 1029792] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/server/.env"] [unique_id "aqxbpm65wm-f4uX16X6c8AAAdV4"]
[Thu Sep 17 15:29:10.744932 2026] [security2:error] [pid 1029697:tid 1029831] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxbpm65wm-f4uX16X6c8gAAAAQ"]
[Thu Sep 17 15:29:10.753627 2026] [qos:error] [pid 1029697:tid 1029759] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c8wAAdT0
[Thu Sep 17 15:29:10.754303 2026] [qos:error] [pid 1029697:tid 1029786] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c9AAAdVg
[Thu Sep 17 15:29:10.756504 2026] [qos:error] [pid 1029697:tid 1029790] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c9QAAdVw
[Thu Sep 17 15:29:10.758226 2026] [qos:error] [pid 1029697:tid 1029797] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c9gAAA2M
[Thu Sep 17 15:29:10.758243 2026] [qos:error] [pid 1029697:tid 1029705] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c9wAAAwc
[Thu Sep 17 15:29:10.758265 2026] [qos:error] [pid 1029697:tid 1029782] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c-AAAA1Q
[Thu Sep 17 15:29:10.761395 2026] [qos:error] [pid 1029697:tid 1029772] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c-QAAdUo
[Thu Sep 17 15:29:10.761491 2026] [qos:error] [pid 1029697:tid 1029809] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c-gAAdW8
[Thu Sep 17 15:29:10.791078 2026] [qos:error] [pid 1029697:tid 1029801] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c-wAAA2c
[Thu Sep 17 15:29:10.793824 2026] [qos:error] [pid 16723:tid 16837] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6asgAAqXA
[Thu Sep 17 15:29:10.800310 2026] [qos:error] [pid 1029697:tid 1029783] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c_AAAA1U
[Thu Sep 17 15:29:10.817156 2026] [qos:error] [pid 1029697:tid 1029779] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c_gAAOVE
[Thu Sep 17 15:29:10.817176 2026] [qos:error] [pid 1029697:tid 1029787] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dAgAAOVk
[Thu Sep 17 15:29:10.817181 2026] [qos:error] [pid 1029697:tid 1029708] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c_QAAdQo
[Thu Sep 17 15:29:10.817297 2026] [qos:error] [pid 1029697:tid 1029785] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dAwAAOVc
[Thu Sep 17 15:29:10.817310 2026] [qos:error] [pid 1029697:tid 1029822] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6c_wAAOXw
[Thu Sep 17 15:29:10.817362 2026] [qos:error] [pid 1029697:tid 1029825] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dAQAAOX8
[Thu Sep 17 15:29:10.817423 2026] [qos:error] [pid 1029697:tid 1029784] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dBAAAOVY
[Thu Sep 17 15:29:10.817477 2026] [qos:error] [pid 1029697:tid 1029804] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dBQAAOWo
[Thu Sep 17 15:29:10.817842 2026] [qos:error] [pid 1029697:tid 1029812] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dAAAAOXI
[Thu Sep 17 15:29:10.823138 2026] [qos:error] [pid 1029697:tid 1029716] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dBgAAdRI
[Thu Sep 17 15:29:10.823930 2026] [qos:error] [pid 1029697:tid 1029707] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dBwAAAwk
[Thu Sep 17 15:29:10.824164 2026] [qos:error] [pid 16723:tid 16850] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6aswAAqX0
[Thu Sep 17 15:29:10.850030 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.154.219.249:50662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/i.php"] [unique_id "aqxbpm65wm-f4uX16X6dCAAAAC4"]
[Thu Sep 17 15:29:10.885066 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxbpm65wm-f4uX16X6dCQAAACc"]
[Thu Sep 17 15:29:10.890409 2026] [qos:error] [pid 1029697:tid 1029740] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dCgAAdSo
[Thu Sep 17 15:29:10.917375 2026] [qos:error] [pid 16723:tid 16761] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6atgAAqSQ
[Thu Sep 17 15:29:10.917379 2026] [qos:error] [pid 16723:tid 16838] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6atQAAqXE
[Thu Sep 17 15:29:10.931706 2026] [qos:error] [pid 1029697:tid 1029726] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dDwAAdRw
[Thu Sep 17 15:29:10.931749 2026] [qos:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dDgAAdSs
[Thu Sep 17 15:29:10.933149 2026] [qos:error] [pid 1029697:tid 1029798] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dEAAAdWQ
[Thu Sep 17 15:29:10.936285 2026] [qos:error] [pid 1029697:tid 1029717] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dEQAAdRM
[Thu Sep 17 15:29:10.936293 2026] [qos:error] [pid 1029697:tid 1029810] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dEgAAdXA
[Thu Sep 17 15:29:10.938632 2026] [security2:error] [pid 1029697:tid 1029843] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxbpm65wm-f4uX16X6dDQAAABA"]
[Thu Sep 17 15:29:10.939373 2026] [qos:error] [pid 1029697:tid 1029720] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dFAAAAxY
[Thu Sep 17 15:29:10.939377 2026] [qos:error] [pid 1029697:tid 1029748] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dFQAAAzI
[Thu Sep 17 15:29:10.939504 2026] [qos:error] [pid 1029697:tid 1029746] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbpm65wm-f4uX16X6dEwAAAzA
[Thu Sep 17 15:29:10.980520 2026] [qos:error] [pid 16723:tid 16839] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpi9E0uOV11S2qN6atwAAqXI
[Thu Sep 17 15:29:11.155392 2026] [qos:error] [pid 1029697:tid 1029735] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dGgAAdSU
[Thu Sep 17 15:29:11.155420 2026] [qos:error] [pid 1029697:tid 1029819] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dIwAAOXk
[Thu Sep 17 15:29:11.155437 2026] [qos:error] [pid 1029697:tid 1029770] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dHgAAOUg
[Thu Sep 17 15:29:11.155442 2026] [qos:error] [pid 1029697:tid 1029743] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dHAAAOS0
[Thu Sep 17 15:29:11.155465 2026] [qos:error] [pid 1029697:tid 1029752] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dHQAAOTY
[Thu Sep 17 15:29:11.155469 2026] [qos:error] [pid 1029697:tid 1029807] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dIQAAOW0
[Thu Sep 17 15:29:11.155485 2026] [qos:error] [pid 1029697:tid 1029732] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dHwAAOSI
[Thu Sep 17 15:29:11.155488 2026] [qos:error] [pid 1029697:tid 1029734] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dIAAAOSQ
[Thu Sep 17 15:29:11.155498 2026] [qos:error] [pid 1029697:tid 1029824] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=109, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dIgAAOX4
[Thu Sep 17 15:29:11.155794 2026] [qos:error] [pid 1029697:tid 1029706] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dGwAAdQg
[Thu Sep 17 15:29:11.158761 2026] [qos:error] [pid 1029697:tid 1029815] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dJAAAA3U
[Thu Sep 17 15:29:11.158768 2026] [qos:error] [pid 1029697:tid 1029729] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dJQAAAx8
[Thu Sep 17 15:29:11.158785 2026] [qos:error] [pid 1029697:tid 1029749] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dJgAAAzM
[Thu Sep 17 15:29:11.172103 2026] [security2:error] [pid 1029697:tid 1029927] [client 200.4.118.214:36829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbp265wm-f4uX16X6dGAAAZBo"]
[Thu Sep 17 15:29:11.183276 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxbp265wm-f4uX16X6dJwAAABE"]
[Thu Sep 17 15:29:11.214541 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxbp265wm-f4uX16X6dKAAAAAw"]
[Thu Sep 17 15:29:11.266273 2026] [qos:error] [pid 16723:tid 16760] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpy9E0uOV11S2qN6auQAAqSM
[Thu Sep 17 15:29:11.281618 2026] [security2:error] [pid 1029697:tid 1029867] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cOwAAACg"]
[Thu Sep 17 15:29:11.308005 2026] [security2:error] [pid 1029697:tid 1029951] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cOAAAAHw"]
[Thu Sep 17 15:29:11.313545 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.154.219.249:50666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxbp265wm-f4uX16X6dKgAAAEM"]
[Thu Sep 17 15:29:11.359803 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.94.35.111:40476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxbp265wm-f4uX16X6dKwAAAE0"]
[Thu Sep 17 15:29:11.454680 2026] [qos:error] [pid 1029697:tid 1029742] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dOAAAdSw
[Thu Sep 17 15:29:11.454713 2026] [qos:error] [pid 1029697:tid 1029773] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dMQAAdUs
[Thu Sep 17 15:29:11.454715 2026] [qos:error] [pid 1029697:tid 1029745] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dNQAAdS8
[Thu Sep 17 15:29:11.454722 2026] [qos:error] [pid 1029697:tid 1029721] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dMwAAdRc
[Thu Sep 17 15:29:11.454909 2026] [security2:error] [pid 1029697:tid 1029715] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/node-api/.env"] [unique_id "aqxbp265wm-f4uX16X6dNwAAdRE"]
[Thu Sep 17 15:29:11.454918 2026] [security2:error] [pid 1029697:tid 1029699] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/test/.env"] [unique_id "aqxbp265wm-f4uX16X6dNAAAdQE"]
[Thu Sep 17 15:29:11.454989 2026] [security2:error] [pid 1029697:tid 1029718] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/staging/.env"] [unique_id "aqxbp265wm-f4uX16X6dMgAAdRQ"]
[Thu Sep 17 15:29:11.455041 2026] [security2:error] [pid 1029697:tid 1029767] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/new/.env"] [unique_id "aqxbp265wm-f4uX16X6dNgAAdUU"]
[Thu Sep 17 15:29:11.456963 2026] [security2:error] [pid 1029697:tid 1029754] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/backup/.env"] [unique_id "aqxbp265wm-f4uX16X6dOQAAOTg"]
[Thu Sep 17 15:29:11.457191 2026] [security2:error] [pid 1029697:tid 1029774] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/cms/.env"] [unique_id "aqxbp265wm-f4uX16X6dOgAAOUw"]
[Thu Sep 17 15:29:11.481035 2026] [security2:error] [pid 16723:tid 16840] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/config/.env"] [unique_id "aqxbpy9E0uOV11S2qN6augAAqXM"]
[Thu Sep 17 15:29:11.481051 2026] [security2:error] [pid 16723:tid 16773] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/client/.env"] [unique_id "aqxbpy9E0uOV11S2qN6avQAAqTA"]
[Thu Sep 17 15:29:11.481061 2026] [security2:error] [pid 16723:tid 16759] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/src/.env"] [unique_id "aqxbpy9E0uOV11S2qN6auwAAqSI"]
[Thu Sep 17 15:29:11.481075 2026] [security2:error] [pid 16723:tid 16841] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/web/.env"] [unique_id "aqxbpy9E0uOV11S2qN6avAAAqXQ"]
[Thu Sep 17 15:29:11.516087 2026] [core:error] [pid 16723:tid 16960] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:11.516102 2026] [core:error] [pid 16723:tid 16960] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:11.633839 2026] [qos:error] [pid 1029697:tid 1029763] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dRQAAA0E
[Thu Sep 17 15:29:11.633846 2026] [qos:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dQwAAAzc
[Thu Sep 17 15:29:11.634127 2026] [security2:error] [pid 1029697:tid 1029795] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/var/www/html/.env"] [unique_id "aqxbp265wm-f4uX16X6dQQAAA2E"]
[Thu Sep 17 15:29:11.634147 2026] [security2:error] [pid 1029697:tid 1029794] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/var/www/.env"] [unique_id "aqxbp265wm-f4uX16X6dQAAAA2A"]
[Thu Sep 17 15:29:11.634173 2026] [security2:error] [pid 1029697:tid 1029722] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/laravel/.env"] [unique_id "aqxbp265wm-f4uX16X6dQgAAAxg"]
[Thu Sep 17 15:29:11.634194 2026] [security2:error] [pid 1029697:tid 1029698] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/apps/.env"] [unique_id "aqxbp265wm-f4uX16X6dRAAAAwA"]
[Thu Sep 17 15:29:11.678632 2026] [security2:error] [pid 1029697:tid 1029802] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/prod/.env"] [unique_id "aqxbp265wm-f4uX16X6dSAAAOWg"]
[Thu Sep 17 15:29:11.678734 2026] [security2:error] [pid 1029697:tid 1029813] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/dev/.env"] [unique_id "aqxbp265wm-f4uX16X6dRwAAOXM"]
[Thu Sep 17 15:29:11.737992 2026] [qos:error] [pid 1029697:tid 1029793] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dTAAAdV8
[Thu Sep 17 15:29:11.737999 2026] [qos:error] [pid 1029697:tid 1029777] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dTwAAdU8
[Thu Sep 17 15:29:11.738003 2026] [qos:error] [pid 1029697:tid 1029762] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dUAAAdUA
[Thu Sep 17 15:29:11.738216 2026] [security2:error] [pid 1029697:tid 1029750] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/public_html/.env"] [unique_id "aqxbp265wm-f4uX16X6dSwAAdTQ"]
[Thu Sep 17 15:29:11.738308 2026] [security2:error] [pid 1029697:tid 1029771] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/server/api/.env"] [unique_id "aqxbp265wm-f4uX16X6dTQAAdUk"]
[Thu Sep 17 15:29:11.738314 2026] [security2:error] [pid 1029697:tid 1029814] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/admin-app/.env"] [unique_id "aqxbp265wm-f4uX16X6dSgAAdXQ"]
[Thu Sep 17 15:29:11.738338 2026] [security2:error] [pid 1029697:tid 1029731] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/server/backend/.env"] [unique_id "aqxbp265wm-f4uX16X6dTgAAdSE"]
[Thu Sep 17 15:29:11.747767 2026] [security2:error] [pid 16723:tid 16771] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/var/www/.env"] [unique_id "aqxbpy9E0uOV11S2qN6awQAAqS4"]
[Thu Sep 17 15:29:11.747816 2026] [security2:error] [pid 16723:tid 16779] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/public/.env"] [unique_id "aqxbpy9E0uOV11S2qN6awwAAqTY"]
[Thu Sep 17 15:29:11.747854 2026] [security2:error] [pid 16723:tid 16795] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/var/www/html/.env"] [unique_id "aqxbpy9E0uOV11S2qN6axAAAqUY"]
[Thu Sep 17 15:29:11.747898 2026] [security2:error] [pid 16723:tid 16778] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/frontend/.env"] [unique_id "aqxbpy9E0uOV11S2qN6awgAAqTU"]
[Thu Sep 17 15:29:11.780874 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.154.219.249:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxbp265wm-f4uX16X6dUgAAAF8"]
[Thu Sep 17 15:29:11.799115 2026] [security2:error] [pid 1029697:tid 1029739] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/administrator/.env"] [unique_id "aqxbp265wm-f4uX16X6dSQAAdSk"]
[Thu Sep 17 15:29:11.812885 2026] [core:error] [pid 16723:tid 16970] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:11.812897 2026] [core:error] [pid 16723:tid 16970] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:11.887085 2026] [security2:error] [pid 16723:tid 16804] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/laravel/.env"] [unique_id "aqxbpy9E0uOV11S2qN6ayQAAqU8"]
[Thu Sep 17 15:29:11.898262 2026] [qos:error] [pid 16723:tid 16729] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpy9E0uOV11S2qN6azwAAqQQ
[Thu Sep 17 15:29:11.898480 2026] [security2:error] [pid 16723:tid 16805] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/application/.env"] [unique_id "aqxbpy9E0uOV11S2qN6aygAAqVA"]
[Thu Sep 17 15:29:11.898502 2026] [security2:error] [pid 16723:tid 16809] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/backup/.env"] [unique_id "aqxbpy9E0uOV11S2qN6azQAAqVQ"]
[Thu Sep 17 15:29:11.898524 2026] [security2:error] [pid 16723:tid 16807] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/back/.env"] [unique_id "aqxbpy9E0uOV11S2qN6azAAAqVI"]
[Thu Sep 17 15:29:11.898543 2026] [qos:error] [pid 16723:tid 16811] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbpy9E0uOV11S2qN6azgAAqVY
[Thu Sep 17 15:29:11.898561 2026] [security2:error] [pid 16723:tid 16806] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/apps/.env"] [unique_id "aqxbpy9E0uOV11S2qN6aywAAqVE"]
[Thu Sep 17 15:29:11.950412 2026] [qos:error] [pid 1029697:tid 1029738] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dWQAAdSg
[Thu Sep 17 15:29:11.950508 2026] [qos:error] [pid 1029697:tid 1029744] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dWgAAdS4
[Thu Sep 17 15:29:11.950518 2026] [qos:error] [pid 1029697:tid 1029764] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbp265wm-f4uX16X6dWAAAdUI
[Thu Sep 17 15:29:11.950635 2026] [security2:error] [pid 1029697:tid 1029747] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.aws/.env"] [unique_id "aqxbp265wm-f4uX16X6dVQAAdTE"]
[Thu Sep 17 15:29:11.950722 2026] [security2:error] [pid 1029697:tid 1029765] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/stripe/.env"] [unique_id "aqxbp265wm-f4uX16X6dVgAAdUM"]
[Thu Sep 17 15:29:11.950735 2026] [security2:error] [pid 1029697:tid 1029725] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/aws/.env"] [unique_id "aqxbp265wm-f4uX16X6dVAAAdRs"]
[Thu Sep 17 15:29:11.977256 2026] [security2:error] [pid 1029697:tid 1029775] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/v3/.env"] [unique_id "aqxbp265wm-f4uX16X6dXgAAdU0"]
[Thu Sep 17 15:29:12.001888 2026] [qos:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dYgAAA04
[Thu Sep 17 15:29:12.001895 2026] [qos:error] [pid 1029697:tid 1029805] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dYwAAA2s
[Thu Sep 17 15:29:12.001901 2026] [qos:error] [pid 1029697:tid 1029789] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dZQAAA1s
[Thu Sep 17 15:29:12.002093 2026] [security2:error] [pid 1029697:tid 1029730] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/backup/.env"] [unique_id "aqxbqG65wm-f4uX16X6dYAAAAyA"]
[Thu Sep 17 15:29:12.002104 2026] [qos:error] [pid 1029697:tid 1029757] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dYQAAAzs
[Thu Sep 17 15:29:12.002104 2026] [security2:error] [pid 1029697:tid 1029803] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/production/.env"] [unique_id "aqxbqG65wm-f4uX16X6dZAAAA2k"]
[Thu Sep 17 15:29:12.088684 2026] [security2:error] [pid 1029697:tid 1029792] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/production/.env"] [unique_id "aqxbqG65wm-f4uX16X6daAAAOV4"]
[Thu Sep 17 15:29:12.088765 2026] [security2:error] [pid 1029697:tid 1029759] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/staging/.env"] [unique_id "aqxbqG65wm-f4uX16X6daQAAOT0"]
[Thu Sep 17 15:29:12.119735 2026] [qos:error] [pid 16723:tid 16738] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqC9E0uOV11S2qN6a1AAAqQ0
[Thu Sep 17 15:29:12.119739 2026] [qos:error] [pid 16723:tid 16728] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqC9E0uOV11S2qN6a0gAAqQM
[Thu Sep 17 15:29:12.120043 2026] [security2:error] [pid 16723:tid 16727] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/production/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a0QAAqQI"]
[Thu Sep 17 15:29:12.120038 2026] [security2:error] [pid 16723:tid 16725] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/prod/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a0wAAqQA"]
[Thu Sep 17 15:29:12.129258 2026] [security2:error] [pid 1029697:tid 1029912] [client 185.55.149.49:64280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbqG65wm-f4uX16X6dawAAAFU"]
[Thu Sep 17 15:29:12.129675 2026] [security2:error] [pid 1029697:tid 1029912] [client 185.55.149.49:64280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbqG65wm-f4uX16X6dawAAAFU"]
[Thu Sep 17 15:29:12.153653 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxbqG65wm-f4uX16X6dbAAAAEw"]
[Thu Sep 17 15:29:12.187280 2026] [qos:error] [pid 1029697:tid 1029772] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dcAAAdUo
[Thu Sep 17 15:29:12.187289 2026] [qos:error] [pid 1029697:tid 1029705] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dcQAAdQc
[Thu Sep 17 15:29:12.187297 2026] [qos:error] [pid 1029697:tid 1029786] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dbQAAdVg
[Thu Sep 17 15:29:12.187308 2026] [qos:error] [pid 1029697:tid 1029782] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dbwAAdVQ
[Thu Sep 17 15:29:12.187320 2026] [qos:error] [pid 1029697:tid 1029809] [remote 45.138.12.25:37842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqG65wm-f4uX16X6dcwAAdW8
[Thu Sep 17 15:29:12.247363 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.154.219.249:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/test.php"] [unique_id "aqxbqG65wm-f4uX16X6ddQAAAFs"]
[Thu Sep 17 15:29:12.261936 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxbqG65wm-f4uX16X6ddgAAAHw"]
[Thu Sep 17 15:29:12.284513 2026] [security2:error] [pid 1029697:tid 1029859] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cYAAAACA"]
[Thu Sep 17 15:29:12.287486 2026] [security2:error] [pid 1029697:tid 1029925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cawAAAGI"]
[Thu Sep 17 15:29:12.300969 2026] [security2:error] [pid 16723:tid 16911] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6abAAAAL4"]
[Thu Sep 17 15:29:12.306990 2026] [security2:error] [pid 16723:tid 16861] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpS9E0uOV11S2qN6aXQAAAIw"]
[Thu Sep 17 15:29:12.316179 2026] [security2:error] [pid 1029697:tid 1029948] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6ciQAAAHk"]
[Thu Sep 17 15:29:12.318675 2026] [security2:error] [pid 1029697:tid 1029852] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cZwAAABk"]
[Thu Sep 17 15:29:12.325332 2026] [security2:error] [pid 1029697:tid 1029919] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cYQAAAFw"]
[Thu Sep 17 15:29:12.337009 2026] [security2:error] [pid 1029697:tid 1029808] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/old/.env"] [unique_id "aqxbqG65wm-f4uX16X6dewAAOW4"]
[Thu Sep 17 15:29:12.337039 2026] [security2:error] [pid 1029697:tid 1029801] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/test/.env"] [unique_id "aqxbqG65wm-f4uX16X6degAAOWc"]
[Thu Sep 17 15:29:12.338337 2026] [security2:error] [pid 16723:tid 16862] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpS9E0uOV11S2qN6aXgAAAI0"]
[Thu Sep 17 15:29:12.352055 2026] [security2:error] [pid 1029697:tid 1029861] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cagAAACI"]
[Thu Sep 17 15:29:12.352055 2026] [security2:error] [pid 16723:tid 16864] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpS9E0uOV11S2qN6aYgAAAI8"]
[Thu Sep 17 15:29:12.353761 2026] [security2:error] [pid 1029697:tid 1029847] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cdgAAABQ"]
[Thu Sep 17 15:29:12.356678 2026] [security2:error] [pid 1029697:tid 1029887] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cZQAAADw"]
[Thu Sep 17 15:29:12.367718 2026] [security2:error] [pid 1029697:tid 1029883] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6caQAAADg"]
[Thu Sep 17 15:29:12.369776 2026] [security2:error] [pid 1029697:tid 1029936] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6caAAAAG0"]
[Thu Sep 17 15:29:12.384150 2026] [security2:error] [pid 16723:tid 16730] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/new/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a1wAAqQU"]
[Thu Sep 17 15:29:12.384631 2026] [security2:error] [pid 1029697:tid 1029920] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cZgAAAF0"]
[Thu Sep 17 15:29:12.385777 2026] [security2:error] [pid 16723:tid 16860] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpS9E0uOV11S2qN6aWgAAAIs"]
[Thu Sep 17 15:29:12.385945 2026] [security2:error] [pid 16723:tid 16741] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/old/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a1gAAqRA"]
[Thu Sep 17 15:29:12.387015 2026] [security2:error] [pid 16723:tid 16730] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/admin-app/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a2gAAqQU"]
[Thu Sep 17 15:29:12.387083 2026] [security2:error] [pid 16723:tid 16766] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/public_html/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a2wAAqSk"]
[Thu Sep 17 15:29:12.387273 2026] [security2:error] [pid 16723:tid 16765] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/api-backend/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a2QAAqSg"]
[Thu Sep 17 15:29:12.387857 2026] [security2:error] [pid 16723:tid 16749] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/node-api/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a2AAAqRg"]
[Thu Sep 17 15:29:12.388248 2026] [security2:error] [pid 16723:tid 16741] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/administrator/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a3AAAqRA"]
[Thu Sep 17 15:29:12.410284 2026] [security2:error] [pid 16723:tid 16912] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpS9E0uOV11S2qN6aXwAAAL8"]
[Thu Sep 17 15:29:12.411588 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxbqG65wm-f4uX16X6dfgAAAEc"]
[Thu Sep 17 15:29:12.418234 2026] [security2:error] [pid 16723:tid 16917] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpS9E0uOV11S2qN6aYQAAAMQ"]
[Thu Sep 17 15:29:12.418282 2026] [security2:error] [pid 1029697:tid 1029837] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6cpQAAAAo"]
[Thu Sep 17 15:29:12.419069 2026] [security2:error] [pid 16723:tid 16780] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.docker/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a4QAAqTc"]
[Thu Sep 17 15:29:12.419074 2026] [security2:error] [pid 16723:tid 16772] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/server/api/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a3wAAqS8"]
[Thu Sep 17 15:29:12.419245 2026] [security2:error] [pid 16723:tid 16777] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/server/backend/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a4AAAqTQ"]
[Thu Sep 17 15:29:12.419271 2026] [security2:error] [pid 16723:tid 16769] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/current/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a3gAAqSw"]
[Thu Sep 17 15:29:12.467789 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxbqG65wm-f4uX16X6dggAAAGs"]
[Thu Sep 17 15:29:12.470800 2026] [security2:error] [pid 1029697:tid 1029708] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/test/.env"] [unique_id "aqxbqG65wm-f4uX16X6dhAAAAwo"]
[Thu Sep 17 15:29:12.470818 2026] [security2:error] [pid 1029697:tid 1029785] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/new/.env"] [unique_id "aqxbqG65wm-f4uX16X6dhQAAA1c"]
[Thu Sep 17 15:29:12.470861 2026] [security2:error] [pid 1029697:tid 1029804] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/admin-app/.env"] [unique_id "aqxbqG65wm-f4uX16X6diAAAA2o"]
[Thu Sep 17 15:29:12.470879 2026] [security2:error] [pid 1029697:tid 1029825] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/old/.env"] [unique_id "aqxbqG65wm-f4uX16X6dgwAAA38"]
[Thu Sep 17 15:29:12.470969 2026] [security2:error] [pid 1029697:tid 1029822] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/node-api/.env"] [unique_id "aqxbqG65wm-f4uX16X6dhwAAA3w"]
[Thu Sep 17 15:29:12.470969 2026] [security2:error] [pid 1029697:tid 1029784] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/api-backend/.env"] [unique_id "aqxbqG65wm-f4uX16X6dhgAAA1Y"]
[Thu Sep 17 15:29:12.479423 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxbqG65wm-f4uX16X6diQAAAC4"]
[Thu Sep 17 15:29:12.538814 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/new/.env"] [unique_id "aqxbqG65wm-f4uX16X6dkgAAOSs"]
[Thu Sep 17 15:29:12.538825 2026] [security2:error] [pid 1029697:tid 1029798] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/node-api/.env"] [unique_id "aqxbqG65wm-f4uX16X6dkwAAOWQ"]
[Thu Sep 17 15:29:12.540213 2026] [security2:error] [pid 1029697:tid 1029810] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/public_html/.env"] [unique_id "aqxbqG65wm-f4uX16X6dlQAAA3A"]
[Thu Sep 17 15:29:12.540273 2026] [security2:error] [pid 1029697:tid 1029720] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/current/.env"] [unique_id "aqxbqG65wm-f4uX16X6dlgAAAxY"]
[Thu Sep 17 15:29:12.540593 2026] [security2:error] [pid 1029697:tid 1029717] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/administrator/.env"] [unique_id "aqxbqG65wm-f4uX16X6dlAAAAxM"]
[Thu Sep 17 15:29:12.543400 2026] [security2:error] [pid 1029697:tid 1029748] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/server/api/.env"] [unique_id "aqxbqG65wm-f4uX16X6dlwAAAzI"]
[Thu Sep 17 15:29:12.543430 2026] [security2:error] [pid 1029697:tid 1029700] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.docker/.env"] [unique_id "aqxbqG65wm-f4uX16X6dmQAAAwI"]
[Thu Sep 17 15:29:12.543542 2026] [security2:error] [pid 1029697:tid 1029746] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/server/backend/.env"] [unique_id "aqxbqG65wm-f4uX16X6dmAAAAzA"]
[Thu Sep 17 15:29:12.543542 2026] [security2:error] [pid 1029697:tid 1029735] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxbqG65wm-f4uX16X6dmgAAAyU"]
[Thu Sep 17 15:29:12.566108 2026] [security2:error] [pid 1029697:tid 1029770] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/.git/config.bak"] [unique_id "aqxbqG65wm-f4uX16X6dmwAAdUg"]
[Thu Sep 17 15:29:12.569348 2026] [security2:error] [pid 1029697:tid 1029743] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/api-backend/.env"] [unique_id "aqxbqG65wm-f4uX16X6dnwAAOS0"]
[Thu Sep 17 15:29:12.569794 2026] [security2:error] [pid 1029697:tid 1029807] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/admin-app/.env"] [unique_id "aqxbqG65wm-f4uX16X6doAAAOW0"]
[Thu Sep 17 15:29:12.654858 2026] [security2:error] [pid 1029697:tid 1029878] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxbqG65wm-f4uX16X6dowAAADM"]
[Thu Sep 17 15:29:12.718046 2026] [security2:error] [pid 1029697:tid 1029752] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/administrator/.env"] [unique_id "aqxbqG65wm-f4uX16X6dpAAAOTY"]
[Thu Sep 17 15:29:12.723247 2026] [security2:error] [pid 1029697:tid 1029732] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/public_html/.env"] [unique_id "aqxbqG65wm-f4uX16X6dpgAAOSI"]
[Thu Sep 17 15:29:12.723247 2026] [security2:error] [pid 1029697:tid 1029734] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/current/.env"] [unique_id "aqxbqG65wm-f4uX16X6dpQAAOSQ"]
[Thu Sep 17 15:29:12.771201 2026] [security2:error] [pid 1029697:tid 1029824] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/server/api/.env"] [unique_id "aqxbqG65wm-f4uX16X6dqgAAOX4"]
[Thu Sep 17 15:29:12.771200 2026] [security2:error] [pid 1029697:tid 1029706] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/server/backend/.env"] [unique_id "aqxbqG65wm-f4uX16X6dqQAAOQg"]
[Thu Sep 17 15:29:12.827423 2026] [security2:error] [pid 16723:tid 16742] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.aws/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a7AAAqRE"]
[Thu Sep 17 15:29:12.827503 2026] [security2:error] [pid 16723:tid 16743] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/stripe/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a6gAAqRI"]
[Thu Sep 17 15:29:12.827503 2026] [security2:error] [pid 16723:tid 16726] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/aws/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a6wAAqQE"]
[Thu Sep 17 15:29:12.827507 2026] [security2:error] [pid 16723:tid 16753] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/v1/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a7wAAqRw"]
[Thu Sep 17 15:29:12.827539 2026] [security2:error] [pid 16723:tid 16754] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/v3/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a8QAAqR0"]
[Thu Sep 17 15:29:12.827553 2026] [security2:error] [pid 16723:tid 16750] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/media/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a8gAAqRk"]
[Thu Sep 17 15:29:12.827627 2026] [security2:error] [pid 16723:tid 16745] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/v2/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a8AAAqRQ"]
[Thu Sep 17 15:29:12.827633 2026] [security2:error] [pid 16723:tid 16731] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxbqC9E0uOV11S2qN6a6QAAqQY"]
[Thu Sep 17 15:29:12.838793 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxbqG65wm-f4uX16X6drQAAAD0"]
[Thu Sep 17 15:29:12.859050 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxbqG65wm-f4uX16X6drgAAAHE"]
[Thu Sep 17 15:29:12.943057 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.154.219.249:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/p.php"] [unique_id "aqxbqG65wm-f4uX16X6dsAAAAFU"]
[Thu Sep 17 15:29:12.954002 2026] [security2:error] [pid 1029697:tid 1029724] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/aws/.env"] [unique_id "aqxbqG65wm-f4uX16X6dsgAAORo"]
[Thu Sep 17 15:29:12.954006 2026] [security2:error] [pid 1029697:tid 1029729] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxbqG65wm-f4uX16X6dsQAAOR8"]
[Thu Sep 17 15:29:12.954065 2026] [security2:error] [pid 1029697:tid 1029749] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.docker/.env"] [unique_id "aqxbqG65wm-f4uX16X6dswAAOTM"]
[Thu Sep 17 15:29:12.987109 2026] [security2:error] [pid 1029697:tid 1029742] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/aws/.env"] [unique_id "aqxbqG65wm-f4uX16X6dtwAAAyw"]
[Thu Sep 17 15:29:12.987118 2026] [security2:error] [pid 1029697:tid 1029699] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/v1/.env"] [unique_id "aqxbqG65wm-f4uX16X6dvAAAAwE"]
[Thu Sep 17 15:29:12.987180 2026] [security2:error] [pid 1029697:tid 1029718] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/v2/.env"] [unique_id "aqxbqG65wm-f4uX16X6dvQAAAxQ"]
[Thu Sep 17 15:29:12.987223 2026] [security2:error] [pid 1029697:tid 1029745] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.aws/.env"] [unique_id "aqxbqG65wm-f4uX16X6duQAAAy8"]
[Thu Sep 17 15:29:12.987313 2026] [security2:error] [pid 1029697:tid 1029767] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/v3/.env"] [unique_id "aqxbqG65wm-f4uX16X6dvgAAA0U"]
[Thu Sep 17 15:29:12.987331 2026] [security2:error] [pid 1029697:tid 1029773] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/stripe/.env"] [unique_id "aqxbqG65wm-f4uX16X6duAAAA0s"]
[Thu Sep 17 15:29:12.987506 2026] [security2:error] [pid 1029697:tid 1029754] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/media/.env"] [unique_id "aqxbqG65wm-f4uX16X6dwAAAAzg"]
[Thu Sep 17 15:29:12.996379 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxbqG65wm-f4uX16X6dyAAAAAc"]
[Thu Sep 17 15:29:13.140404 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxbqW65wm-f4uX16X6dzgAAAD8"]
[Thu Sep 17 15:29:13.168237 2026] [core:error] [pid 1029697:tid 1029929] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:13.168259 2026] [core:error] [pid 1029697:tid 1029929] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:13.197639 2026] [qos:error] [pid 1029697:tid 1029722] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d0gAAORg
[Thu Sep 17 15:29:13.197957 2026] [security2:error] [pid 1029697:tid 1029794] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/stripe/.env"] [unique_id "aqxbqW65wm-f4uX16X6d0AAAOWA"]
[Thu Sep 17 15:29:13.197960 2026] [security2:error] [pid 1029697:tid 1029795] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/.aws/.env"] [unique_id "aqxbqW65wm-f4uX16X6d0QAAOWE"]
[Thu Sep 17 15:29:13.224992 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxbqW65wm-f4uX16X6d0wAAAEg"]
[Thu Sep 17 15:29:13.253447 2026] [security2:error] [pid 1029697:tid 1029802] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/v1/.env"] [unique_id "aqxbqW65wm-f4uX16X6d1QAAOWg"]
[Thu Sep 17 15:29:13.269116 2026] [security2:error] [pid 16723:tid 16905] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6abQAAALg"]
[Thu Sep 17 15:29:13.279421 2026] [fcgid:warn] [pid 1029697:tid 1029889] (70014)End of file found: [client 152.32.205.184:48236] mod_fcgid: can't get data from http client
[Thu Sep 17 15:29:13.327394 2026] [security2:error] [pid 16723:tid 16876] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6aigAAAJs"]
[Thu Sep 17 15:29:13.332134 2026] [security2:error] [pid 16723:tid 16863] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbpS9E0uOV11S2qN6aXAAAAI4"]
[Thu Sep 17 15:29:13.365298 2026] [security2:error] [pid 1029697:tid 1029865] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6ciAAAACY"]
[Thu Sep 17 15:29:13.372762 2026] [security2:error] [pid 16723:tid 16879] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6ajgAAAJ4"]
[Thu Sep 17 15:29:13.377708 2026] [security2:error] [pid 1029697:tid 1029703] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/media/.env"] [unique_id "aqxbqW65wm-f4uX16X6d3AAAOQU"]
[Thu Sep 17 15:29:13.378956 2026] [security2:error] [pid 1029697:tid 1029793] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/v3/.env"] [unique_id "aqxbqW65wm-f4uX16X6d2wAAOV8"]
[Thu Sep 17 15:29:13.379368 2026] [security2:error] [pid 1029697:tid 1029766] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/v2/.env"] [unique_id "aqxbqW65wm-f4uX16X6d2gAAOUQ"]
[Thu Sep 17 15:29:13.405544 2026] [security2:error] [pid 1029697:tid 1029909] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cfAAAAFI"]
[Thu Sep 17 15:29:13.407941 2026] [security2:error] [pid 1029697:tid 1029846] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6ctgAAABM"]
[Thu Sep 17 15:29:13.408098 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.154.219.249:50708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxbqW65wm-f4uX16X6d3wAAACI"]
[Thu Sep 17 15:29:13.410428 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxbqW65wm-f4uX16X6d4AAAAE4"]
[Thu Sep 17 15:29:13.430701 2026] [security2:error] [pid 16723:tid 16882] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6akAAAAKE"]
[Thu Sep 17 15:29:13.453360 2026] [qos:error] [pid 16723:tid 16959] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbqS9E0uOV11S2qN6bFwAAAO4
[Thu Sep 17 15:29:13.454245 2026] [qos:error] [pid 16723:tid 16969] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbqS9E0uOV11S2qN6bGAAAAPg
[Thu Sep 17 15:29:13.454373 2026] [qos:error] [pid 1029697:tid 1029840] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbqW65wm-f4uX16X6d6AAAAA0
[Thu Sep 17 15:29:13.455357 2026] [qos:error] [pid 1029697:tid 1029814] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d6QAAA3Q
[Thu Sep 17 15:29:13.455366 2026] [qos:error] [pid 16723:tid 16971] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxbqS9E0uOV11S2qN6bGQAAAPo
[Thu Sep 17 15:29:13.455368 2026] [qos:error] [pid 1029697:tid 1029744] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d6gAAAy4
[Thu Sep 17 15:29:13.455523 2026] [qos:error] [pid 1029697:tid 1029937] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.230, id=aqxbqW65wm-f4uX16X6d6wAAAG4
[Thu Sep 17 15:29:13.455736 2026] [qos:error] [pid 1029697:tid 1029814] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d7AAAA3Q
[Thu Sep 17 15:29:13.458342 2026] [security2:error] [pid 1029697:tid 1029725] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/.git/config.bak"] [unique_id "aqxbqW65wm-f4uX16X6d8AAAAxs"]
[Thu Sep 17 15:29:13.483033 2026] [qos:error] [pid 1029697:tid 1029898] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbqW65wm-f4uX16X6d8wAAAEc
[Thu Sep 17 15:29:13.487358 2026] [qos:error] [pid 16723:tid 16747] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqS9E0uOV11S2qN6bIQAAqRY
[Thu Sep 17 15:29:13.499334 2026] [qos:error] [pid 16723:tid 16861] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbqS9E0uOV11S2qN6bJAAAAIw
[Thu Sep 17 15:29:13.499518 2026] [security2:error] [pid 1029697:tid 1029952] [client 216.73.216.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.melodypicture.us"] [uri "/index.php"] [unique_id "aqxbpW65wm-f4uX16X6cPgAAfQY"]
[Thu Sep 17 15:29:13.565498 2026] [qos:error] [pid 1029697:tid 1029805] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d9QAAOWs
[Thu Sep 17 15:29:13.565504 2026] [qos:error] [pid 1029697:tid 1029789] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d9gAAOVs
[Thu Sep 17 15:29:13.565535 2026] [qos:error] [pid 1029697:tid 1029730] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d9wAAOSA
[Thu Sep 17 15:29:13.572240 2026] [qos:error] [pid 1029697:tid 1029757] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d-AAAOTs
[Thu Sep 17 15:29:13.572304 2026] [qos:error] [pid 1029697:tid 1029759] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d-wAAOT0
[Thu Sep 17 15:29:13.572333 2026] [qos:error] [pid 1029697:tid 1029772] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d_wAAOUo
[Thu Sep 17 15:29:13.572337 2026] [qos:error] [pid 1029697:tid 1029792] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d-gAAOV4
[Thu Sep 17 15:29:13.572340 2026] [qos:error] [pid 1029697:tid 1029786] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d_AAAOVg
[Thu Sep 17 15:29:13.572367 2026] [qos:error] [pid 1029697:tid 1029803] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d-QAAOWk
[Thu Sep 17 15:29:13.572400 2026] [qos:error] [pid 1029697:tid 1029782] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d_gAAOVQ
[Thu Sep 17 15:29:13.572405 2026] [qos:error] [pid 1029697:tid 1029705] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6d_QAAOQc
[Thu Sep 17 15:29:13.613291 2026] [security2:error] [pid 1029697:tid 1029873] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxbqW65wm-f4uX16X6eAAAAAC4"]
[Thu Sep 17 15:29:13.636004 2026] [qos:error] [pid 1029697:tid 1029808] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eAgAAA24
[Thu Sep 17 15:29:13.636013 2026] [qos:error] [pid 1029697:tid 1029801] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eBQAAA2c
[Thu Sep 17 15:29:13.636020 2026] [qos:error] [pid 1029697:tid 1029733] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eBgAAAyM
[Thu Sep 17 15:29:13.636058 2026] [qos:error] [pid 1029697:tid 1029768] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eAwAAA0Y
[Thu Sep 17 15:29:13.636080 2026] [qos:error] [pid 1029697:tid 1029783] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eBAAAA1U
[Thu Sep 17 15:29:13.639471 2026] [qos:error] [pid 16723:tid 16758] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqS9E0uOV11S2qN6bJwAAqSE
[Thu Sep 17 15:29:13.682474 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxbqW65wm-f4uX16X6eCAAAACs"]
[Thu Sep 17 15:29:13.698513 2026] [qos:error] [pid 1029697:tid 1029728] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eCQAAOR4
[Thu Sep 17 15:29:13.729498 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxbqW65wm-f4uX16X6eCwAAAFg"]
[Thu Sep 17 15:29:13.753059 2026] [qos:error] [pid 1029697:tid 1029818] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eDwAAA3g
[Thu Sep 17 15:29:13.821717 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxbqW65wm-f4uX16X6eEgAAAHY"]
[Thu Sep 17 15:29:13.837361 2026] [security2:error] [pid 1029697:tid 1029872] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxbqW65wm-f4uX16X6eEwAAAC0"]
[Thu Sep 17 15:29:13.849922 2026] [qos:error] [pid 16723:tid 16789] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqS9E0uOV11S2qN6bKAAAqUA
[Thu Sep 17 15:29:13.874264 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.154.219.249:50718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxbqW65wm-f4uX16X6eFAAAAG8"]
[Thu Sep 17 15:29:13.883364 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxbqW65wm-f4uX16X6eFQAAAGQ"]
[Thu Sep 17 15:29:13.906796 2026] [qos:error] [pid 1029697:tid 1029791] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eFgAAA10
[Thu Sep 17 15:29:13.906802 2026] [qos:error] [pid 1029697:tid 1029709] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eGQAAAws
[Thu Sep 17 15:29:13.906808 2026] [qos:error] [pid 1029697:tid 1029737] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eGAAAAyc
[Thu Sep 17 15:29:13.906814 2026] [qos:error] [pid 1029697:tid 1029821] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eGgAAA3s
[Thu Sep 17 15:29:13.906819 2026] [qos:error] [pid 1029697:tid 1029755] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eFwAAAzk
[Thu Sep 17 15:29:13.909299 2026] [qos:error] [pid 1029697:tid 1029713] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eGwAAOQ8
[Thu Sep 17 15:29:13.909386 2026] [qos:error] [pid 1029697:tid 1029799] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eHQAAOWU
[Thu Sep 17 15:29:13.909436 2026] [qos:error] [pid 1029697:tid 1029719] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eHAAAORU
[Thu Sep 17 15:29:13.909571 2026] [qos:error] [pid 1029697:tid 1029751] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eHwAAOTU
[Thu Sep 17 15:29:13.909685 2026] [qos:error] [pid 1029697:tid 1029779] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eHgAAOVE
[Thu Sep 17 15:29:13.909692 2026] [qos:error] [pid 1029697:tid 1029780] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eIgAAOVI
[Thu Sep 17 15:29:13.909717 2026] [qos:error] [pid 1029697:tid 1029708] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eIwAAOQo
[Thu Sep 17 15:29:13.909725 2026] [qos:error] [pid 1029697:tid 1029806] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eIAAAOWw
[Thu Sep 17 15:29:13.909751 2026] [qos:error] [pid 1029697:tid 1029761] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eIQAAOT8
[Thu Sep 17 15:29:13.909803 2026] [qos:error] [pid 1029697:tid 1029785] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eJAAAOVc
[Thu Sep 17 15:29:13.909850 2026] [qos:error] [pid 1029697:tid 1029804] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eJQAAOWo
[Thu Sep 17 15:29:13.909889 2026] [qos:error] [pid 1029697:tid 1029825] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqW65wm-f4uX16X6eJgAAOX8
[Thu Sep 17 15:29:14.013471 2026] [security2:error] [pid 1029697:tid 1029941] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxbqm65wm-f4uX16X6eKgAAAHI"]
[Thu Sep 17 15:29:14.033692 2026] [qos:error] [pid 1029697:tid 1029784] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6eKwAAA1Y
[Thu Sep 17 15:29:14.059384 2026] [qos:error] [pid 16723:tid 16790] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqi9E0uOV11S2qN6bKgAAqUE
[Thu Sep 17 15:29:14.093699 2026] [qos:error] [pid 1029697:tid 1029798] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6eLQAAOWQ
[Thu Sep 17 15:29:14.095329 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxbqm65wm-f4uX16X6eLgAAABc"]
[Thu Sep 17 15:29:14.230062 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxbqm65wm-f4uX16X6eMAAAAHQ"]
[Thu Sep 17 15:29:14.254785 2026] [qos:error] [pid 16723:tid 16842] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqi9E0uOV11S2qN6bLwAAqXU
[Thu Sep 17 15:29:14.262156 2026] [security2:error] [pid 1029697:tid 1029885] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6cyQAAADo"]
[Thu Sep 17 15:29:14.264735 2026] [security2:error] [pid 1029697:tid 1029933] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6ctwAAAGo"]
[Thu Sep 17 15:29:14.279652 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/id_rsa"] [unique_id "aqxbqm65wm-f4uX16X6eMQAAAys"]
[Thu Sep 17 15:29:14.294246 2026] [security2:error] [pid 1029697:tid 1029911] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6cxwAAAFQ"]
[Thu Sep 17 15:29:14.310888 2026] [security2:error] [pid 1029697:tid 1029868] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6csQAAACk"]
[Thu Sep 17 15:29:14.316168 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxbqm65wm-f4uX16X6eNwAAAFw"]
[Thu Sep 17 15:29:14.326676 2026] [security2:error] [pid 16723:tid 16883] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6anwAAAKI"]
[Thu Sep 17 15:29:14.330402 2026] [security2:error] [pid 16723:tid 16935] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6aoAAAANY"]
[Thu Sep 17 15:29:14.340305 2026] [security2:error] [pid 1029697:tid 1029841] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6cvwAAAA4"]
[Thu Sep 17 15:29:14.344811 2026] [security2:error] [pid 16723:tid 16871] [client 34.154.219.249:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxbqi9E0uOV11S2qN6bOwAAAJY"]
[Thu Sep 17 15:29:14.371508 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxbqm65wm-f4uX16X6eOgAAABQ"]
[Thu Sep 17 15:29:14.393050 2026] [security2:error] [pid 16723:tid 16932] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6angAAANM"]
[Thu Sep 17 15:29:14.400379 2026] [security2:error] [pid 16723:tid 16924] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6aiwAAAMs"]
[Thu Sep 17 15:29:14.400745 2026] [security2:error] [pid 16723:tid 16898] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6ajAAAALE"]
[Thu Sep 17 15:29:14.401999 2026] [security2:error] [pid 16723:tid 16936] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6aoQAAANc"]
[Thu Sep 17 15:29:14.404180 2026] [security2:error] [pid 1029697:tid 1029827] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6cxgAAAAA"]
[Thu Sep 17 15:29:14.429038 2026] [security2:error] [pid 16723:tid 16951] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6arQAAAOY"]
[Thu Sep 17 15:29:14.433253 2026] [security2:error] [pid 16723:tid 16944] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6aqwAAAN8"]
[Thu Sep 17 15:29:14.445318 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxbqm65wm-f4uX16X6eTwAAAFI"]
[Thu Sep 17 15:29:14.460736 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxbqm65wm-f4uX16X6eUQAAAB0"]
[Thu Sep 17 15:29:14.485636 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxbqm65wm-f4uX16X6eUwAAACM"]
[Thu Sep 17 15:29:14.609193 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxbqm65wm-f4uX16X6eWgAAAAE"]
[Thu Sep 17 15:29:14.642559 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxbqm65wm-f4uX16X6eXAAAAF0"]
[Thu Sep 17 15:29:14.674241 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxbqm65wm-f4uX16X6eXgAAABg"]
[Thu Sep 17 15:29:14.706196 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxbqm65wm-f4uX16X6eYAAAAAo"]
[Thu Sep 17 15:29:14.727264 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxbqm65wm-f4uX16X6eZwAAABU"]
[Thu Sep 17 15:29:14.800415 2026] [qos:error] [pid 1029697:tid 1029744] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6edgAAOS4
[Thu Sep 17 15:29:14.800490 2026] [qos:error] [pid 1029697:tid 1029758] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6ebwAAOTw
[Thu Sep 17 15:29:14.800733 2026] [qos:error] [pid 1029697:tid 1029703] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6edAAAOQU
[Thu Sep 17 15:29:14.800738 2026] [qos:error] [pid 1029697:tid 1029764] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6edwAAOUI
[Thu Sep 17 15:29:14.812632 2026] [security2:error] [pid 16723:tid 16959] [client 34.154.219.249:50734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxbqi9E0uOV11S2qN6bVgAAAO4"]
[Thu Sep 17 15:29:14.814439 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxbqm65wm-f4uX16X6eewAAABw"]
[Thu Sep 17 15:29:14.823552 2026] [qos:error] [pid 1029697:tid 1029814] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6efAAAA3Q
[Thu Sep 17 15:29:14.839190 2026] [qos:error] [pid 1029697:tid 1029915] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbqm65wm-f4uX16X6efgAAAFg
[Thu Sep 17 15:29:14.839195 2026] [qos:error] [pid 16723:tid 16960] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxbqi9E0uOV11S2qN6bVwAAAO8
[Thu Sep 17 15:29:14.839246 2026] [qos:error] [pid 1029697:tid 1029858] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.230, id=aqxbqm65wm-f4uX16X6efQAAAB8
[Thu Sep 17 15:29:14.839971 2026] [qos:error] [pid 16723:tid 16956] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbqi9E0uOV11S2qN6bWAAAAOs
[Thu Sep 17 15:29:14.886463 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxbqm65wm-f4uX16X6egwAAAGQ"]
[Thu Sep 17 15:29:14.941678 2026] [security2:error] [pid 16723:tid 16954] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mywellnessinparis.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bUgAAAOk"]
[Thu Sep 17 15:29:14.952205 2026] [security2:error] [pid 1029697:tid 1029898] [client 74.7.244.51:47054] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mywellnessinparis.com"] [uri "/robots.txt"] [unique_id "aqxbqm65wm-f4uX16X6eaAAAR2g"]
[Thu Sep 17 15:29:14.975835 2026] [qos:error] [pid 1029697:tid 1029725] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6ejAAAORs
[Thu Sep 17 15:29:14.975839 2026] [qos:error] [pid 1029697:tid 1029739] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6eiwAAOSk
[Thu Sep 17 15:29:14.976107 2026] [qos:error] [pid 1029697:tid 1029738] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6eigAAOSg
[Thu Sep 17 15:29:14.976162 2026] [qos:error] [pid 1029697:tid 1029765] [remote 45.138.12.25:37856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqm65wm-f4uX16X6ejQAAOUM
[Thu Sep 17 15:29:14.982270 2026] [security2:error] [pid 1029697:tid 1029912] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxbqm65wm-f4uX16X6ejgAAAFU"]
[Thu Sep 17 15:29:15.007933 2026] [security2:error] [pid 1029697:tid 1029834] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxbq265wm-f4uX16X6ekgAAAAc"]
[Thu Sep 17 15:29:15.040201 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxbq265wm-f4uX16X6elAAAAGo"]
[Thu Sep 17 15:29:15.082123 2026] [security2:error] [pid 1029697:tid 1029853] [client 43.173.182.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbqm65wm-f4uX16X6eggAAABo"]
[Thu Sep 17 15:29:15.088763 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxbq265wm-f4uX16X6elQAAAGk"]
[Thu Sep 17 15:29:15.091906 2026] [qos:error] [pid 1029697:tid 1029805] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbq265wm-f4uX16X6elwAAA2s
[Thu Sep 17 15:29:15.091910 2026] [qos:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbq265wm-f4uX16X6elgAAA04
[Thu Sep 17 15:29:15.129228 2026] [security2:error] [pid 16723:tid 16856] [client 43.173.181.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bXAAAAIc"]
[Thu Sep 17 15:29:15.186610 2026] [security2:error] [pid 16723:tid 16855] [client 43.172.197.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbqy9E0uOV11S2qN6bXwAAAIY"]
[Thu Sep 17 15:29:15.222440 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxbq265wm-f4uX16X6enQAAAGc"]
[Thu Sep 17 15:29:15.267923 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.154.219.249:50748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxbq265wm-f4uX16X6enwAAAFw"]
[Thu Sep 17 15:29:15.273809 2026] [security2:error] [pid 16723:tid 16885] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6anQAAAKQ"]
[Thu Sep 17 15:29:15.283321 2026] [security2:error] [pid 1029697:tid 1029891] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6c8QAAAEA"]
[Thu Sep 17 15:29:15.283581 2026] [security2:error] [pid 1029697:tid 1029849] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6c3QAAABY"]
[Thu Sep 17 15:29:15.295104 2026] [security2:error] [pid 1029697:tid 1029923] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6csAAAAGA"]
[Thu Sep 17 15:29:15.296022 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxbq265wm-f4uX16X6eoQAAAAg"]
[Thu Sep 17 15:29:15.298640 2026] [security2:error] [pid 1029697:tid 1029730] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/config.php"] [unique_id "aqxbq265wm-f4uX16X6eogAAOSA"]
[Thu Sep 17 15:29:15.321224 2026] [security2:error] [pid 1029697:tid 1029862] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxbq265wm-f4uX16X6epgAAACM"]
[Thu Sep 17 15:29:15.328177 2026] [security2:error] [pid 1029697:tid 1029902] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6crQAAAEs"]
[Thu Sep 17 15:29:15.339417 2026] [security2:error] [pid 16723:tid 16880] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbpi9E0uOV11S2qN6ajwAAAJ8"]
[Thu Sep 17 15:29:15.362361 2026] [security2:error] [pid 1029697:tid 1029954] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbpm65wm-f4uX16X6czwAAAH8"]
[Thu Sep 17 15:29:15.401399 2026] [security2:error] [pid 16723:tid 16797] [remote 172.59.116.88:58704] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1441"] [id "9009999"] [msg "8 char spam"] [hostname "woodstockchristmaseve.com"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aqxbqy9E0uOV11S2qN6baAAAxEg"], referer: https://woodstockchristmaseve.com/
[Thu Sep 17 15:29:15.406345 2026] [security2:error] [pid 1029697:tid 1029866] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqG65wm-f4uX16X6dkAAAACc"]
[Thu Sep 17 15:29:15.424056 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxbq265wm-f4uX16X6eqgAAABw"]
[Thu Sep 17 15:29:15.534703 2026] [security2:error] [pid 16723:tid 16980] [client 43.172.196.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbqy9E0uOV11S2qN6bYgAAAQM"]
[Thu Sep 17 15:29:15.562003 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxbq265wm-f4uX16X6erAAAADg"]
[Thu Sep 17 15:29:15.618587 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxbq265wm-f4uX16X6esgAAAAU"]
[Thu Sep 17 15:29:15.732473 2026] [security2:error] [pid 16723:tid 16951] [client 34.154.219.249:50758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbqy9E0uOV11S2qN6bdgAAAOY"]
[Thu Sep 17 15:29:15.745169 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxbq265wm-f4uX16X6ewAAAAHQ"]
[Thu Sep 17 15:29:15.817903 2026] [qos:error] [pid 16723:tid 16799] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6begAAqUo
[Thu Sep 17 15:29:15.817911 2026] [qos:error] [pid 16723:tid 16820] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6beQAAqV8
[Thu Sep 17 15:29:15.817916 2026] [qos:error] [pid 16723:tid 16796] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6beAAAqUc
[Thu Sep 17 15:29:15.821655 2026] [security2:error] [pid 1029697:tid 1029934] [client 43.173.173.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbq265wm-f4uX16X6etwAAAGs"]
[Thu Sep 17 15:29:15.835749 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxbq265wm-f4uX16X6ewwAAAE0"]
[Thu Sep 17 15:29:15.854892 2026] [qos:error] [pid 16723:tid 16803] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bgQAAqU4
[Thu Sep 17 15:29:15.854896 2026] [qos:error] [pid 16723:tid 16800] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bfAAAqUs
[Thu Sep 17 15:29:15.854905 2026] [qos:error] [pid 16723:tid 16802] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bfQAAqU0
[Thu Sep 17 15:29:15.854911 2026] [qos:error] [pid 16723:tid 16824] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bggAAqWM
[Thu Sep 17 15:29:15.854919 2026] [qos:error] [pid 16723:tid 16823] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bgAAAqWI
[Thu Sep 17 15:29:15.854924 2026] [qos:error] [pid 16723:tid 16801] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bfwAAqUw
[Thu Sep 17 15:29:15.854932 2026] [qos:error] [pid 16723:tid 16822] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bewAAqWE
[Thu Sep 17 15:29:15.854943 2026] [qos:error] [pid 16723:tid 16821] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=45.138.12.25, id=aqxbqy9E0uOV11S2qN6bfgAAqWA
[Thu Sep 17 15:29:15.866071 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxbq265wm-f4uX16X6exAAAAGk"]
[Thu Sep 17 15:29:16.017883 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxbrG65wm-f4uX16X6eywAAAA0"]
[Thu Sep 17 15:29:16.034185 2026] [qos:error] [pid 16723:tid 16826] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bhQAAqWU
[Thu Sep 17 15:29:16.034196 2026] [qos:error] [pid 16723:tid 16808] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bhAAAqVM
[Thu Sep 17 15:29:16.034190 2026] [qos:error] [pid 16723:tid 16810] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bhgAAqVU
[Thu Sep 17 15:29:16.059762 2026] [qos:error] [pid 16723:tid 16828] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6biAAAqWc
[Thu Sep 17 15:29:16.060155 2026] [qos:error] [pid 16723:tid 16830] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6biwAAqWk
[Thu Sep 17 15:29:16.060505 2026] [qos:error] [pid 16723:tid 16827] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6biQAAqWY
[Thu Sep 17 15:29:16.060516 2026] [qos:error] [pid 16723:tid 16828] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bjQAAqWc
[Thu Sep 17 15:29:16.060627 2026] [qos:error] [pid 16723:tid 16829] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bigAAqWg
[Thu Sep 17 15:29:16.060694 2026] [qos:error] [pid 16723:tid 16831] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bjAAAqWo
[Thu Sep 17 15:29:16.060713 2026] [qos:error] [pid 16723:tid 16830] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bjgAAqWk
[Thu Sep 17 15:29:16.061360 2026] [qos:error] [pid 16723:tid 16832] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6bjwAAqWs
[Thu Sep 17 15:29:16.119782 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxbrG65wm-f4uX16X6ezgAAABE"]
[Thu Sep 17 15:29:16.178732 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxbrG65wm-f4uX16X6e0AAAAFQ"]
[Thu Sep 17 15:29:16.191697 2026] [security2:error] [pid 16723:tid 16971] [client 34.154.219.249:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxbrC9E0uOV11S2qN6bkwAAAPo"]
[Thu Sep 17 15:29:16.220144 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxbrG65wm-f4uX16X6e0QAAAEw"]
[Thu Sep 17 15:29:16.269538 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxbrG65wm-f4uX16X6e0gAAAHk"]
[Thu Sep 17 15:29:16.272116 2026] [security2:error] [pid 16723:tid 16870] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqC9E0uOV11S2qN6a9wAAAJU"]
[Thu Sep 17 15:29:16.280885 2026] [security2:error] [pid 1029697:tid 1029901] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbqG65wm-f4uX16X6dgQAAAEo"]
[Thu Sep 17 15:29:16.284956 2026] [security2:error] [pid 16723:tid 16925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqC9E0uOV11S2qN6a6AAAAMw"]
[Thu Sep 17 15:29:16.297333 2026] [security2:error] [pid 1029697:tid 1029882] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqG65wm-f4uX16X6doQAAADc"]
[Thu Sep 17 15:29:16.307279 2026] [security2:error] [pid 1029697:tid 1029820] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/src/.env"] [unique_id "aqxbqm65wm-f4uX16X6e0wAAG3o"]
[Thu Sep 17 15:29:16.311882 2026] [security2:error] [pid 1029697:tid 1029921] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqG65wm-f4uX16X6dkQAAAF4"]
[Thu Sep 17 15:29:16.312703 2026] [security2:error] [pid 1029697:tid 1029728] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/client/.env"] [unique_id "aqxbqm65wm-f4uX16X6e1gAAGx4"]
[Thu Sep 17 15:29:16.312978 2026] [security2:error] [pid 1029697:tid 1029818] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/frontend/.env"] [unique_id "aqxbqm65wm-f4uX16X6e1wAAG3g"]
[Thu Sep 17 15:29:16.316523 2026] [security2:error] [pid 16723:tid 16908] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqC9E0uOV11S2qN6a5wAAALs"]
[Thu Sep 17 15:29:16.317094 2026] [security2:error] [pid 1029697:tid 1029818] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/public/.env"] [unique_id "aqxbqm65wm-f4uX16X6e2AAAG3g"]
[Thu Sep 17 15:29:16.318777 2026] [security2:error] [pid 1029697:tid 1029728] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/var/www/.env"] [unique_id "aqxbqm65wm-f4uX16X6e2QAAGx4"]
[Thu Sep 17 15:29:16.320580 2026] [security2:error] [pid 1029697:tid 1029820] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/web/.env"] [unique_id "aqxbqm65wm-f4uX16X6e1QAAG3o"]
[Thu Sep 17 15:29:16.321992 2026] [security2:error] [pid 1029697:tid 1029821] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/apps/.env"] [unique_id "aqxbqm65wm-f4uX16X6e3QAAG3s"]
[Thu Sep 17 15:29:16.323157 2026] [security2:error] [pid 1029697:tid 1029799] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/backup/.env"] [unique_id "aqxbqm65wm-f4uX16X6e3wAAG2U"]
[Thu Sep 17 15:29:16.323319 2026] [security2:error] [pid 1029697:tid 1029719] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/dev/.env"] [unique_id "aqxbrG65wm-f4uX16X6e4gAAGxU"]
[Thu Sep 17 15:29:16.323402 2026] [security2:error] [pid 1029697:tid 1029713] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/back/.env"] [unique_id "aqxbqm65wm-f4uX16X6e3gAAGw8"]
[Thu Sep 17 15:29:16.324142 2026] [security2:error] [pid 1029697:tid 1029818] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/var/www/html/.env"] [unique_id "aqxbqm65wm-f4uX16X6e2gAAG3g"]
[Thu Sep 17 15:29:16.324285 2026] [security2:error] [pid 1029697:tid 1029728] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/laravel/.env"] [unique_id "aqxbqm65wm-f4uX16X6e2wAAGx4"]
[Thu Sep 17 15:29:16.324362 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxbrG65wm-f4uX16X6e4QAAAF8"]
[Thu Sep 17 15:29:16.324456 2026] [security2:error] [pid 1029697:tid 1029719] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/prod/.env"] [unique_id "aqxbrG65wm-f4uX16X6e4wAAGxU"]
[Thu Sep 17 15:29:16.324491 2026] [security2:error] [pid 1029697:tid 1029713] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/production/.env"] [unique_id "aqxbrG65wm-f4uX16X6e5AAAGw8"]
[Thu Sep 17 15:29:16.324571 2026] [security2:error] [pid 1029697:tid 1029821] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/cms/.env"] [unique_id "aqxbqm65wm-f4uX16X6e4AAAG3s"]
[Thu Sep 17 15:29:16.324766 2026] [security2:error] [pid 1029697:tid 1029820] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/application/.env"] [unique_id "aqxbqm65wm-f4uX16X6e3AAAG3o"]
[Thu Sep 17 15:29:16.376688 2026] [security2:error] [pid 1029697:tid 1029947] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbp265wm-f4uX16X6dXQAAAHg"]
[Thu Sep 17 15:29:16.377315 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxbrG65wm-f4uX16X6e5wAAAFI"]
[Thu Sep 17 15:29:16.378991 2026] [security2:error] [pid 1029697:tid 1029925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqW65wm-f4uX16X6dzQAAAGI"]
[Thu Sep 17 15:29:16.391188 2026] [security2:error] [pid 1029697:tid 1029908] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqW65wm-f4uX16X6dzAAAAFE"]
[Thu Sep 17 15:29:16.409138 2026] [security2:error] [pid 16723:tid 16929] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6a_QAAANA"]
[Thu Sep 17 15:29:16.430682 2026] [security2:error] [pid 1029697:tid 1029829] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqG65wm-f4uX16X6dogAAAAI"]
[Thu Sep 17 15:29:16.443594 2026] [security2:error] [pid 16723:tid 16933] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6bAwAAANQ"]
[Thu Sep 17 15:29:16.452040 2026] [security2:error] [pid 16723:tid 16910] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqC9E0uOV11S2qN6a-gAAAL0"]
[Thu Sep 17 15:29:16.452200 2026] [security2:error] [pid 16723:tid 16922] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqC9E0uOV11S2qN6a-QAAAMk"]
[Thu Sep 17 15:29:16.461638 2026] [security2:error] [pid 1029697:tid 1029928] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqG65wm-f4uX16X6dfAAAAGU"]
[Thu Sep 17 15:29:16.479001 2026] [security2:error] [pid 1029697:tid 1029849] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxbrG65wm-f4uX16X6e8gAAABY"]
[Thu Sep 17 15:29:16.480534 2026] [security2:error] [pid 1029697:tid 1029859] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqW65wm-f4uX16X6dyQAAACA"]
[Thu Sep 17 15:29:16.489502 2026] [security2:error] [pid 1029697:tid 1029817] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/config.php"] [unique_id "aqxbrG65wm-f4uX16X6e9AAAA3c"]
[Thu Sep 17 15:29:16.498484 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxbrG65wm-f4uX16X6e9QAAABI"]
[Thu Sep 17 15:29:16.503485 2026] [security2:error] [pid 1029697:tid 1029896] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbqG65wm-f4uX16X6ddwAAAEU"]
[Thu Sep 17 15:29:16.504059 2026] [security2:error] [pid 16723:tid 16937] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6bBwAAANg"]
[Thu Sep 17 15:29:16.504163 2026] [security2:error] [pid 1029697:tid 1029720] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/test/.env"] [unique_id "aqxbrG65wm-f4uX16X6e9wAAVxY"]
[Thu Sep 17 15:29:16.504602 2026] [security2:error] [pid 16723:tid 16949] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6bDwAAAOQ"]
[Thu Sep 17 15:29:16.504818 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/new/.env"] [unique_id "aqxbrG65wm-f4uX16X6e-QAAVys"]
[Thu Sep 17 15:29:16.504818 2026] [security2:error] [pid 1029697:tid 1029790] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/api-backend/.env"] [unique_id "aqxbrG65wm-f4uX16X6e-wAAV1w"]
[Thu Sep 17 15:29:16.505847 2026] [security2:error] [pid 1029697:tid 1029781] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/current/.env"] [unique_id "aqxbrG65wm-f4uX16X6fAAAAV1M"]
[Thu Sep 17 15:29:16.505951 2026] [security2:error] [pid 1029697:tid 1029790] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/server/api/.env"] [unique_id "aqxbrG65wm-f4uX16X6fAQAAV1w"]
[Thu Sep 17 15:29:16.505999 2026] [security2:error] [pid 1029697:tid 1029720] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/admin-app/.env"] [unique_id "aqxbrG65wm-f4uX16X6e_QAAVxY"]
[Thu Sep 17 15:29:16.506120 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/public_html/.env"] [unique_id "aqxbrG65wm-f4uX16X6e_wAAVys"]
[Thu Sep 17 15:29:16.506127 2026] [security2:error] [pid 1029697:tid 1029714] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/administrator/.env"] [unique_id "aqxbrG65wm-f4uX16X6e_gAAVxA"]
[Thu Sep 17 15:29:16.506339 2026] [security2:error] [pid 1029697:tid 1029732] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/server/backend/.env"] [unique_id "aqxbrG65wm-f4uX16X6fAgAAVyI"]
[Thu Sep 17 15:29:16.507727 2026] [security2:error] [pid 1029697:tid 1029717] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/old/.env"] [unique_id "aqxbrG65wm-f4uX16X6e-AAAVxM"]
[Thu Sep 17 15:29:16.508134 2026] [security2:error] [pid 1029697:tid 1029748] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/staging/.env"] [unique_id "aqxbrG65wm-f4uX16X6e9gAAVzI"]
[Thu Sep 17 15:29:16.509408 2026] [security2:error] [pid 1029697:tid 1029700] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/node-api/.env"] [unique_id "aqxbrG65wm-f4uX16X6e-gAAVwI"]
[Thu Sep 17 15:29:16.526637 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxbrG65wm-f4uX16X6fBAAAAAg"]
[Thu Sep 17 15:29:16.558307 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxbrG65wm-f4uX16X6fBgAAAAY"]
[Thu Sep 17 15:29:16.615591 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxbrG65wm-f4uX16X6fDQAAADs"]
[Thu Sep 17 15:29:16.659277 2026] [security2:error] [pid 1029697:tid 1029749] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/.docker/.env"] [unique_id "aqxbrG65wm-f4uX16X6fEAAAWTM"]
[Thu Sep 17 15:29:16.659277 2026] [security2:error] [pid 1029697:tid 1029788] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/.aws/.env"] [unique_id "aqxbrG65wm-f4uX16X6fEwAAWVo"]
[Thu Sep 17 15:29:16.659282 2026] [security2:error] [pid 1029697:tid 1029823] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/aws/.env"] [unique_id "aqxbrG65wm-f4uX16X6fEQAAWX0"]
[Thu Sep 17 15:29:16.659295 2026] [security2:error] [pid 1029697:tid 1029769] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxbrG65wm-f4uX16X6fEgAAWUc"]
[Thu Sep 17 15:29:16.689501 2026] [security2:error] [pid 1029697:tid 1029760] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/stripe/.env"] [unique_id "aqxbrG65wm-f4uX16X6fFwAAFT4"]
[Thu Sep 17 15:29:16.691313 2026] [security2:error] [pid 1029697:tid 1029760] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/v1/.env"] [unique_id "aqxbrG65wm-f4uX16X6fGwAAFT4"]
[Thu Sep 17 15:29:16.691375 2026] [qos:error] [pid 1029697:tid 1029764] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fIwAAFUI
[Thu Sep 17 15:29:16.691388 2026] [qos:error] [pid 1029697:tid 1029754] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fHQAAFTg
[Thu Sep 17 15:29:16.691389 2026] [qos:error] [pid 16723:tid 16872] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxbrC9E0uOV11S2qN6b0AAAAJc
[Thu Sep 17 15:29:16.691826 2026] [qos:error] [pid 1029697:tid 1029745] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fHgAAFS8
[Thu Sep 17 15:29:16.691981 2026] [qos:error] [pid 1029697:tid 1029758] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fIQAAFTw
[Thu Sep 17 15:29:16.691995 2026] [qos:error] [pid 1029697:tid 1029742] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fHwAAFSw
[Thu Sep 17 15:29:16.692005 2026] [qos:error] [pid 1029697:tid 1029744] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fIAAAFS4
[Thu Sep 17 15:29:16.692011 2026] [qos:error] [pid 1029697:tid 1029767] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fHAAAFUU
[Thu Sep 17 15:29:16.692027 2026] [qos:error] [pid 1029697:tid 1029703] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fIgAAFQU
[Thu Sep 17 15:29:16.696440 2026] [qos:error] [pid 16723:tid 16884] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbrC9E0uOV11S2qN6b1gAAAKM
[Thu Sep 17 15:29:16.696459 2026] [qos:error] [pid 16723:tid 16885] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxbrC9E0uOV11S2qN6b1wAAAKQ
[Thu Sep 17 15:29:16.696572 2026] [qos:error] [pid 16723:tid 16923] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbrC9E0uOV11S2qN6b1QAAAMo
[Thu Sep 17 15:29:16.719705 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxbrG65wm-f4uX16X6fJAAAADU"]
[Thu Sep 17 15:29:16.745324 2026] [security2:error] [pid 16723:tid 16977] [client 143.105.152.240:3817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbrC9E0uOV11S2qN6b2gAAAQA"]
[Thu Sep 17 15:29:16.749223 2026] [security2:error] [pid 16723:tid 16977] [client 143.105.152.240:3817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbrC9E0uOV11S2qN6b2gAAAQA"]
[Thu Sep 17 15:29:16.771460 2026] [qos:error] [pid 1029697:tid 1029814] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fJgAAA3Q
[Thu Sep 17 15:29:16.797362 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxbrG65wm-f4uX16X6fJwAAADw"]
[Thu Sep 17 15:29:16.801492 2026] [qos:error] [pid 16723:tid 16839] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6b3QAAqXI
[Thu Sep 17 15:29:16.801569 2026] [qos:error] [pid 16723:tid 16759] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6b3gAAqSI
[Thu Sep 17 15:29:16.801577 2026] [qos:error] [pid 16723:tid 16760] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6b3wAAqSM
[Thu Sep 17 15:29:16.829225 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.94.35.111:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ivorygarlock.com"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxbrG65wm-f4uX16X6fKAAAADI"]
[Thu Sep 17 15:29:16.834128 2026] [security2:error] [pid 16723:tid 16888] [client 103.61.184.148:53677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbrC9E0uOV11S2qN6b4AAAAKc"]
[Thu Sep 17 15:29:16.834230 2026] [security2:error] [pid 16723:tid 16888] [client 103.61.184.148:53677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbrC9E0uOV11S2qN6b4AAAAKc"]
[Thu Sep 17 15:29:16.835396 2026] [qos:error] [pid 1029697:tid 1029777] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fKgAAFU8
[Thu Sep 17 15:29:16.836115 2026] [qos:error] [pid 1029697:tid 1029777] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fLAAAFU8
[Thu Sep 17 15:29:16.836117 2026] [qos:error] [pid 1029697:tid 1029712] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fLQAAFQ4
[Thu Sep 17 15:29:16.836120 2026] [qos:error] [pid 1029697:tid 1029813] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fKwAAFXM
[Thu Sep 17 15:29:16.851068 2026] [security2:error] [pid 16723:tid 16946] [client 34.154.219.249:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxbrC9E0uOV11S2qN6b4QAAAOE"]
[Thu Sep 17 15:29:16.892229 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.94.35.111:40498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/phpinfo.php"] [unique_id "aqxbrG65wm-f4uX16X6fLgAAABQ"]
[Thu Sep 17 15:29:16.900523 2026] [security2:error] [pid 16723:tid 16940] [client 172.59.116.88:58704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "woodstockchristmaseve.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6b2QAA23E"], referer: https://woodstockchristmaseve.com/
[Thu Sep 17 15:29:16.949427 2026] [core:error] [pid 1029697:tid 1029945] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:16.949447 2026] [core:error] [pid 1029697:tid 1029945] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:16.960703 2026] [qos:error] [pid 1029697:tid 1029711] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fMgAAFQ0
[Thu Sep 17 15:29:16.960701 2026] [qos:error] [pid 1029697:tid 1029802] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fMwAAFWg
[Thu Sep 17 15:29:16.960705 2026] [qos:error] [pid 1029697:tid 1029765] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fNQAAFUM
[Thu Sep 17 15:29:16.960710 2026] [qos:error] [pid 1029697:tid 1029739] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fMQAAFSk
[Thu Sep 17 15:29:16.960718 2026] [qos:error] [pid 1029697:tid 1029805] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fNgAAFWs
[Thu Sep 17 15:29:16.960724 2026] [qos:error] [pid 1029697:tid 1029704] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fOAAAFQY
[Thu Sep 17 15:29:16.960767 2026] [qos:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fNwAAFU4
[Thu Sep 17 15:29:16.960777 2026] [qos:error] [pid 1029697:tid 1029725] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fMAAAFRs
[Thu Sep 17 15:29:16.960784 2026] [qos:error] [pid 1029697:tid 1029738] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=109, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fNAAAFSg
[Thu Sep 17 15:29:16.960787 2026] [qos:error] [pid 1029697:tid 1029778] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=110, c=45.138.12.25, id=aqxbrG65wm-f4uX16X6fOQAAFVA
[Thu Sep 17 15:29:16.967804 2026] [qos:error] [pid 16723:tid 16773] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6b5QAAqTA
[Thu Sep 17 15:29:16.967876 2026] [qos:error] [pid 16723:tid 16840] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrC9E0uOV11S2qN6b5gAAqXM
[Thu Sep 17 15:29:17.080728 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.166.113.162:34378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/phpinfo.php"] [unique_id "aqxbrW65wm-f4uX16X6fOwAAAE4"]
[Thu Sep 17 15:29:17.127205 2026] [security2:error] [pid 16723:tid 16771] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/config.php"] [unique_id "aqxbrS9E0uOV11S2qN6b6wAAqS4"]
[Thu Sep 17 15:29:17.127865 2026] [qos:error] [pid 16723:tid 16795] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrS9E0uOV11S2qN6b7QAAqUY
[Thu Sep 17 15:29:17.128137 2026] [qos:error] [pid 16723:tid 16779] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrS9E0uOV11S2qN6b7AAAqTY
[Thu Sep 17 15:29:17.189419 2026] [qos:error] [pid 1029697:tid 1029710] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fQQAAFQw
[Thu Sep 17 15:29:17.189421 2026] [qos:error] [pid 1029697:tid 1029783] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fRwAAFVU
[Thu Sep 17 15:29:17.189432 2026] [qos:error] [pid 1029697:tid 1029756] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fQAAAFTo
[Thu Sep 17 15:29:17.189441 2026] [qos:error] [pid 1029697:tid 1029819] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fRgAAFXk
[Thu Sep 17 15:29:17.189448 2026] [qos:error] [pid 1029697:tid 1029733] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fQwAAFSM
[Thu Sep 17 15:29:17.189454 2026] [qos:error] [pid 1029697:tid 1029812] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fQgAAFXI
[Thu Sep 17 15:29:17.189464 2026] [qos:error] [pid 1029697:tid 1029772] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fRAAAFUo
[Thu Sep 17 15:29:17.189474 2026] [qos:error] [pid 1029697:tid 1029786] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fPwAAFVg
[Thu Sep 17 15:29:17.189498 2026] [qos:error] [pid 1029697:tid 1029768] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=109, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fRQAAFUY
[Thu Sep 17 15:29:17.189501 2026] [qos:error] [pid 1029697:tid 1029709] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=110, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fTAAAFQs
[Thu Sep 17 15:29:17.189730 2026] [qos:error] [pid 1029697:tid 1029791] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fSgAAFV0
[Thu Sep 17 15:29:17.189774 2026] [qos:error] [pid 1029697:tid 1029701] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fSQAAFQM
[Thu Sep 17 15:29:17.189778 2026] [qos:error] [pid 1029697:tid 1029707] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fSAAAFQk
[Thu Sep 17 15:29:17.189782 2026] [qos:error] [pid 1029697:tid 1029716] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=109, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fSwAAFRI
[Thu Sep 17 15:29:17.204145 2026] [qos:error] [pid 1029697:tid 1029737] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fTQAAAyc
[Thu Sep 17 15:29:17.232254 2026] [security2:error] [pid 1029697:tid 1029870] [client 177.102.253.96:51460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbrW65wm-f4uX16X6fPgAAK1s"]
[Thu Sep 17 15:29:17.270486 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.94.35.111:36192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/info.php"] [unique_id "aqxbrW65wm-f4uX16X6fTgAAAHQ"]
[Thu Sep 17 15:29:17.272136 2026] [security2:error] [pid 16723:tid 16902] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqC9E0uOV11S2qN6a-AAAALU"]
[Thu Sep 17 15:29:17.279435 2026] [security2:error] [pid 1029697:tid 1029895] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqW65wm-f4uX16X6dywAAAEQ"]
[Thu Sep 17 15:29:17.283704 2026] [security2:error] [pid 1029697:tid 1029892] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqW65wm-f4uX16X6d5wAAAEE"]
[Thu Sep 17 15:29:17.288629 2026] [security2:error] [pid 16723:tid 16950] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6bEQAAAOU"]
[Thu Sep 17 15:29:17.292914 2026] [security2:error] [pid 16723:tid 16921] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6a_wAAAMg"]
[Thu Sep 17 15:29:17.335110 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.154.219.249:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxbrW65wm-f4uX16X6fUAAAAE0"]
[Thu Sep 17 15:29:17.451186 2026] [qos:error] [pid 1029697:tid 1029755] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fVQAAFTk
[Thu Sep 17 15:29:17.451283 2026] [qos:error] [pid 1029697:tid 1029713] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fWwAAFQ8
[Thu Sep 17 15:29:17.451433 2026] [qos:error] [pid 1029697:tid 1029818] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fXAAAFXg
[Thu Sep 17 15:29:17.452300 2026] [qos:error] [pid 1029697:tid 1029755] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fXQAAFTk
[Thu Sep 17 15:29:17.452439 2026] [qos:error] [pid 1029697:tid 1029713] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fXgAAFQ8
[Thu Sep 17 15:29:17.452478 2026] [qos:error] [pid 1029697:tid 1029818] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fXwAAFXg
[Thu Sep 17 15:29:17.453029 2026] [qos:error] [pid 1029697:tid 1029821] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fYAAAFXs
[Thu Sep 17 15:29:17.574084 2026] [qos:error] [pid 1029697:tid 1029911] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbrW65wm-f4uX16X6fYwAAAFQ
[Thu Sep 17 15:29:17.581669 2026] [qos:error] [pid 1029697:tid 1029864] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbrW65wm-f4uX16X6fZAAAACU
[Thu Sep 17 15:29:17.614251 2026] [security2:error] [pid 16723:tid 16888] [client 34.94.35.111:36200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/php.php"] [unique_id "aqxbrS9E0uOV11S2qN6b_QAAAKc"]
[Thu Sep 17 15:29:17.634532 2026] [qos:error] [pid 16723:tid 16898] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbrS9E0uOV11S2qN6cAQAAALE
[Thu Sep 17 15:29:17.657706 2026] [qos:error] [pid 16723:tid 16871] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbrS9E0uOV11S2qN6cBAAAAJY
[Thu Sep 17 15:29:17.768223 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.166.113.162:34962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/info.php"] [unique_id "aqxbrW65wm-f4uX16X6faQAAAG8"]
[Thu Sep 17 15:29:17.806609 2026] [security2:error] [pid 16723:tid 16940] [client 34.154.219.249:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxbrS9E0uOV11S2qN6cBQAAANs"]
[Thu Sep 17 15:29:17.981093 2026] [qos:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fbAAAFTc
[Thu Sep 17 15:29:17.981741 2026] [qos:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fcQAAFTc
[Thu Sep 17 15:29:17.982350 2026] [qos:error] [pid 1029697:tid 1029740] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fbgAAFSo
[Thu Sep 17 15:29:17.983087 2026] [qos:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fcwAAFTc
[Thu Sep 17 15:29:17.983101 2026] [qos:error] [pid 1029697:tid 1029815] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fcAAAFXU
[Thu Sep 17 15:29:17.983107 2026] [qos:error] [pid 1029697:tid 1029784] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fbwAAFVY
[Thu Sep 17 15:29:17.983155 2026] [qos:error] [pid 1029697:tid 1029809] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fcgAAFW8
[Thu Sep 17 15:29:17.983597 2026] [security2:error] [pid 1029697:tid 1029784] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/config.php"] [unique_id "aqxbrW65wm-f4uX16X6fdAAAFVY"]
[Thu Sep 17 15:29:17.984041 2026] [qos:error] [pid 1029697:tid 1029817] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fdQAAFXc
[Thu Sep 17 15:29:17.984046 2026] [qos:error] [pid 1029697:tid 1029746] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbrW65wm-f4uX16X6fdgAAFTA
[Thu Sep 17 15:29:18.028936 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.94.35.111:36214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/i.php"] [unique_id "aqxbrm65wm-f4uX16X6feAAAABs"]
[Thu Sep 17 15:29:18.061436 2026] [qos:error] [pid 16723:tid 16933] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbri9E0uOV11S2qN6cDgAAANQ
[Thu Sep 17 15:29:18.068107 2026] [qos:error] [pid 1029697:tid 1029787] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrm65wm-f4uX16X6fewAAFVk
[Thu Sep 17 15:29:18.068821 2026] [qos:error] [pid 1029697:tid 1029720] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbrm65wm-f4uX16X6fegAAFRY
[Thu Sep 17 15:29:18.073872 2026] [qos:error] [pid 16723:tid 16727] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbri9E0uOV11S2qN6cDwAAqQI
[Thu Sep 17 15:29:18.073881 2026] [qos:error] [pid 16723:tid 16728] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbri9E0uOV11S2qN6cEAAAqQM
[Thu Sep 17 15:29:18.267566 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.219.249:50796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxbrm65wm-f4uX16X6ffgAAAGU"]
[Thu Sep 17 15:29:18.268438 2026] [security2:error] [pid 1029697:tid 1029881] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqm65wm-f4uX16X6eawAAADY"]
[Thu Sep 17 15:29:18.282457 2026] [security2:error] [pid 16723:tid 16887] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bRQAAAKY"]
[Thu Sep 17 15:29:18.285341 2026] [security2:error] [pid 16723:tid 16955] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6bFgAAAOo"]
[Thu Sep 17 15:29:18.300963 2026] [security2:error] [pid 1029697:tid 1029889] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqm65wm-f4uX16X6eSwAAAD4"]
[Thu Sep 17 15:29:18.308326 2026] [security2:error] [pid 16723:tid 16865] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bXQAAAJA"]
[Thu Sep 17 15:29:18.313491 2026] [security2:error] [pid 16723:tid 16974] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6bHwAAAP0"]
[Thu Sep 17 15:29:18.344323 2026] [security2:error] [pid 16723:tid 16909] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bQQAAALw"]
[Thu Sep 17 15:29:18.364167 2026] [security2:error] [pid 16723:tid 16886] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqy9E0uOV11S2qN6bcwAAAKU"]
[Thu Sep 17 15:29:18.364484 2026] [security2:error] [pid 16723:tid 16965] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bWQAAAPQ"]
[Thu Sep 17 15:29:18.374316 2026] [security2:error] [pid 16723:tid 16876] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bQAAAAJs"]
[Thu Sep 17 15:29:18.390861 2026] [security2:error] [pid 16723:tid 16854] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqy9E0uOV11S2qN6bcAAAAIU"]
[Thu Sep 17 15:29:18.402572 2026] [security2:error] [pid 16723:tid 16935] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqy9E0uOV11S2qN6bZgAAANY"]
[Thu Sep 17 15:29:18.410053 2026] [security2:error] [pid 16723:tid 16921] [client 114.198.138.124:65252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbri9E0uOV11S2qN6cFgAAAMg"]
[Thu Sep 17 15:29:18.410200 2026] [security2:error] [pid 16723:tid 16921] [client 114.198.138.124:65252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbri9E0uOV11S2qN6cFgAAAMg"]
[Thu Sep 17 15:29:18.434657 2026] [security2:error] [pid 16723:tid 16879] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bRAAAAJ4"]
[Thu Sep 17 15:29:18.449658 2026] [security2:error] [pid 16723:tid 16857] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqS9E0uOV11S2qN6bJQAAAIg"]
[Thu Sep 17 15:29:18.449797 2026] [security2:error] [pid 16723:tid 16894] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bSAAAAK0"]
[Thu Sep 17 15:29:18.451694 2026] [security2:error] [pid 1029697:tid 1029834] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbq265wm-f4uX16X6ewgAAAAc"]
[Thu Sep 17 15:29:18.462417 2026] [security2:error] [pid 16723:tid 16945] [client 34.166.113.162:34964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/php.php"] [unique_id "aqxbri9E0uOV11S2qN6cFwAAAOA"]
[Thu Sep 17 15:29:18.467126 2026] [security2:error] [pid 16723:tid 16863] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bRgAAAI4"]
[Thu Sep 17 15:29:18.471417 2026] [security2:error] [pid 16723:tid 16966] [client 34.94.35.111:36228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/pi.php"] [unique_id "aqxbri9E0uOV11S2qN6cGAAAAPU"]
[Thu Sep 17 15:29:18.485175 2026] [security2:error] [pid 1029697:tid 1029879] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqW65wm-f4uX16X6d7wAAADQ"]
[Thu Sep 17 15:29:18.555107 2026] [security2:error] [pid 1029697:tid 1029849] [client 165.245.228.249:51812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbrm65wm-f4uX16X6ffQAAFgQ"], referer: http://talent-in-borders.com/new/
[Thu Sep 17 15:29:18.719080 2026] [security2:error] [pid 1029697:tid 1029754] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/config/stripe.php"] [unique_id "aqxbrm65wm-f4uX16X6fkAAAFTg"]
[Thu Sep 17 15:29:18.719098 2026] [security2:error] [pid 1029697:tid 1029798] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/config/aws.php"] [unique_id "aqxbrm65wm-f4uX16X6fjgAAFWQ"]
[Thu Sep 17 15:29:18.741452 2026] [security2:error] [pid 16723:tid 16929] [client 34.154.219.249:50804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxbri9E0uOV11S2qN6cHwAAANA"]
[Thu Sep 17 15:29:18.763154 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.94.35.111:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/pinfo.php"] [unique_id "aqxbrm65wm-f4uX16X6flwAAADI"]
[Thu Sep 17 15:29:18.961086 2026] [security2:error] [pid 1029697:tid 1029814] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/config/config.inc.php"] [unique_id "aqxbrm65wm-f4uX16X6foQAAFXQ"]
[Thu Sep 17 15:29:18.961100 2026] [security2:error] [pid 1029697:tid 1029703] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/config/mail.php"] [unique_id "aqxbrm65wm-f4uX16X6fogAAFQU"]
[Thu Sep 17 15:29:18.961129 2026] [security2:error] [pid 1029697:tid 1029712] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/config/nexmo.php"] [unique_id "aqxbrm65wm-f4uX16X6fpQAAFQ4"]
[Thu Sep 17 15:29:19.037614 2026] [security2:error] [pid 1029697:tid 1029832] [client 165.245.228.249:51812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbrm65wm-f4uX16X6fnwAABUU"], referer: http://talent-in-borders.com/backup/
[Thu Sep 17 15:29:19.058432 2026] [security2:error] [pid 16723:tid 16963] [client 18.188.3.41:50354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/xmlrpc.php"] [unique_id "aqxbry9E0uOV11S2qN6cLwAAAPI"]
[Thu Sep 17 15:29:19.084868 2026] [security2:error] [pid 16723:tid 16923] [client 136.158.61.34:35734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbry9E0uOV11S2qN6cMQAAAMo"]
[Thu Sep 17 15:29:19.085008 2026] [security2:error] [pid 16723:tid 16923] [client 136.158.61.34:35734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbry9E0uOV11S2qN6cMQAAAMo"]
[Thu Sep 17 15:29:19.125065 2026] [security2:error] [pid 16723:tid 16909] [client 34.94.35.111:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/test.php"] [unique_id "aqxbry9E0uOV11S2qN6cMwAAALw"]
[Thu Sep 17 15:29:19.171216 2026] [security2:error] [pid 16723:tid 16887] [client 34.166.113.162:34976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/i.php"] [unique_id "aqxbry9E0uOV11S2qN6cNAAAAKY"]
[Thu Sep 17 15:29:19.199656 2026] [security2:error] [pid 16723:tid 16905] [client 34.154.219.249:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxbry9E0uOV11S2qN6cNQAAALg"]
[Thu Sep 17 15:29:19.266459 2026] [security2:error] [pid 16723:tid 16930] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bQwAAANE"]
[Thu Sep 17 15:29:19.287811 2026] [security2:error] [pid 16723:tid 16972] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bUQAAAPs"]
[Thu Sep 17 15:29:19.290400 2026] [security2:error] [pid 16723:tid 16969] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbqi9E0uOV11S2qN6bTAAAAPg"]
[Thu Sep 17 15:29:19.292705 2026] [security2:error] [pid 1029697:tid 1029913] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqm65wm-f4uX16X6efwAAAFY"]
[Thu Sep 17 15:29:19.295433 2026] [security2:error] [pid 1029697:tid 1029863] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbq265wm-f4uX16X6euAAAACQ"]
[Thu Sep 17 15:29:19.300159 2026] [security2:error] [pid 16723:tid 16915] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbqy9E0uOV11S2qN6bcgAAAMI"]
[Thu Sep 17 15:29:19.318199 2026] [security2:error] [pid 1029697:tid 1029805] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "relvnv.com"] [uri "/wp-config.php.bak"] [unique_id "aqxbr265wm-f4uX16X6frQAAFWs"]
[Thu Sep 17 15:29:19.318787 2026] [security2:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/wp-config.php"] [unique_id "aqxbr265wm-f4uX16X6fqwAAFU4"]
[Thu Sep 17 15:29:19.348188 2026] [security2:error] [pid 1029697:tid 1029872] [client 165.245.228.249:51812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fqgAALQ0"], referer: http://talent-in-borders.com/old/
[Thu Sep 17 15:29:19.362820 2026] [security2:error] [pid 16723:tid 16934] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bqAAAANU"]
[Thu Sep 17 15:29:19.380140 2026] [security2:error] [pid 16723:tid 16856] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bnQAAAIc"]
[Thu Sep 17 15:29:19.395683 2026] [security2:error] [pid 1029697:tid 1029836] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrG65wm-f4uX16X6fDwAAAAk"]
[Thu Sep 17 15:29:19.407399 2026] [security2:error] [pid 16723:tid 16859] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bowAAAIo"]
[Thu Sep 17 15:29:19.418052 2026] [security2:error] [pid 1029697:tid 1029950] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbrG65wm-f4uX16X6fBQAAAHs"]
[Thu Sep 17 15:29:19.430629 2026] [security2:error] [pid 16723:tid 16891] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbqy9E0uOV11S2qN6bdwAAAKo"]
[Thu Sep 17 15:29:19.497079 2026] [security2:error] [pid 1029697:tid 1029733] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "relvnv.com"] [uri "/wp-config.php.old"] [unique_id "aqxbr265wm-f4uX16X6ftwAAFSM"]
[Thu Sep 17 15:29:19.497108 2026] [security2:error] [pid 1029697:tid 1029819] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "relvnv.com"] [uri "/wp-config.php.new"] [unique_id "aqxbr265wm-f4uX16X6fuAAAFXk"]
[Thu Sep 17 15:29:19.592354 2026] [security2:error] [pid 16723:tid 16730] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/config/aws.php"] [unique_id "aqxbry9E0uOV11S2qN6cPwAAqQU"]
[Thu Sep 17 15:29:19.607936 2026] [core:error] [pid 1029697:tid 1029882] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:19.607954 2026] [core:error] [pid 1029697:tid 1029882] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:19.624731 2026] [security2:error] [pid 16723:tid 16765] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/config/stripe.php"] [unique_id "aqxbry9E0uOV11S2qN6cQQAAqSg"]
[Thu Sep 17 15:29:19.624829 2026] [security2:error] [pid 16723:tid 16741] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/config/mail.php"] [unique_id "aqxbry9E0uOV11S2qN6cQwAAqRA"]
[Thu Sep 17 15:29:19.625009 2026] [security2:error] [pid 16723:tid 16765] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/config/config.inc.php"] [unique_id "aqxbry9E0uOV11S2qN6cRAAAqSg"]
[Thu Sep 17 15:29:19.649032 2026] [security2:error] [pid 16723:tid 16959] [client 145.82.241.167:57002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbry9E0uOV11S2qN6cPgAA7is"]
[Thu Sep 17 15:29:19.684422 2026] [security2:error] [pid 1029697:tid 1029783] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxbr265wm-f4uX16X6fwQAAFVU"]
[Thu Sep 17 15:29:19.835766 2026] [security2:error] [pid 1029697:tid 1029907] [client 165.245.228.249:51812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fxAAAUDo"], referer: http://talent-in-borders.com/wordpress/
[Thu Sep 17 15:29:19.867841 2026] [security2:error] [pid 16723:tid 16953] [client 34.166.113.162:34990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/pi.php"] [unique_id "aqxbry9E0uOV11S2qN6cUAAAAOg"]
[Thu Sep 17 15:29:19.925649 2026] [security2:error] [pid 16723:tid 16961] [client 34.94.35.111:36254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/p.php"] [unique_id "aqxbry9E0uOV11S2qN6cVgAAAPA"]
[Thu Sep 17 15:29:19.941496 2026] [security2:error] [pid 16723:tid 16753] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "nevadastaterealty.com"] [uri "/wp-config.php.bak"] [unique_id "aqxbry9E0uOV11S2qN6cWwAAqRw"]
[Thu Sep 17 15:29:19.941781 2026] [security2:error] [pid 16723:tid 16780] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/config/nexmo.php"] [unique_id "aqxbry9E0uOV11S2qN6cVwAAqTc"]
[Thu Sep 17 15:29:19.941802 2026] [security2:error] [pid 16723:tid 16726] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/wp-config.php"] [unique_id "aqxbry9E0uOV11S2qN6cWgAAqQE"]
[Thu Sep 17 15:29:20.080875 2026] [security2:error] [pid 16723:tid 16921] [client 34.154.219.249:50820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbsC9E0uOV11S2qN6cYgAAAMg"]
[Thu Sep 17 15:29:20.107928 2026] [security2:error] [pid 1029697:tid 1029909] [client 45.115.26.203:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/info.php"] [unique_id "aqxbsG65wm-f4uX16X6f1AAAAFI"]
[Thu Sep 17 15:29:20.113151 2026] [security2:error] [pid 1029697:tid 1029854] [client 45.115.26.203:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/php_info.php"] [unique_id "aqxbsG65wm-f4uX16X6f2gAAABs"]
[Thu Sep 17 15:29:20.113507 2026] [security2:error] [pid 16723:tid 16915] [client 45.115.26.203:59852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/i.php"] [unique_id "aqxbsC9E0uOV11S2qN6cbgAAAMI"]
[Thu Sep 17 15:29:20.113682 2026] [security2:error] [pid 16723:tid 16937] [client 45.115.26.203:59888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/pi.php"] [unique_id "aqxbsC9E0uOV11S2qN6cbwAAANg"]
[Thu Sep 17 15:29:20.113862 2026] [security2:error] [pid 1029697:tid 1029894] [client 45.115.26.203:59854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/test.php"] [unique_id "aqxbsG65wm-f4uX16X6f3AAAAEM"]
[Thu Sep 17 15:29:20.114081 2026] [proxy_http:error] [pid 1029697:tid 1029874] (20014)Internal error (specific information not available): [client 45.115.26.203:59658] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.114090 2026] [proxy:error] [pid 1029697:tid 1029874] [client 45.115.26.203:59658] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.backup
[Thu Sep 17 15:29:20.121212 2026] [security2:error] [pid 1029697:tid 1029953] [client 45.115.26.203:59886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/php-info.php"] [unique_id "aqxbsG65wm-f4uX16X6f3gAAAH4"]
[Thu Sep 17 15:29:20.122092 2026] [proxy_http:error] [pid 16723:tid 16909] (20014)Internal error (specific information not available): [client 45.115.26.203:59780] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.122108 2026] [security2:error] [pid 16723:tid 16754] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "nevadastaterealty.com"] [uri "/wp-config.php.old"] [unique_id "aqxbsC9E0uOV11S2qN6ccAAAqR0"]
[Thu Sep 17 15:29:20.122110 2026] [proxy:error] [pid 16723:tid 16909] [client 45.115.26.203:59780] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.kube/config
[Thu Sep 17 15:29:20.122831 2026] [security2:error] [pid 16723:tid 16750] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "nevadastaterealty.com"] [uri "/wp-config.php.new"] [unique_id "aqxbsC9E0uOV11S2qN6ccQAAqRk"]
[Thu Sep 17 15:29:20.123056 2026] [security2:error] [pid 16723:tid 16745] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxbsC9E0uOV11S2qN6ccgAAqRQ"]
[Thu Sep 17 15:29:20.124636 2026] [security2:error] [pid 1029697:tid 1029859] [client 45.115.26.203:59838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/phpinfo.php"] [unique_id "aqxbsG65wm-f4uX16X6f4AAAACA"]
[Thu Sep 17 15:29:20.128262 2026] [proxy_http:error] [pid 16723:tid 16956] (20014)Internal error (specific information not available): [client 45.115.26.203:59590] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.128279 2026] [proxy:error] [pid 16723:tid 16956] [client 45.115.26.203:59590] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/404.html
[Thu Sep 17 15:29:20.129493 2026] [proxy_http:error] [pid 1029697:tid 1029926] (20014)Internal error (specific information not available): [client 45.115.26.203:59748] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.129509 2026] [proxy:error] [pid 1029697:tid 1029926] [client 45.115.26.203:59748] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/src/.env
[Thu Sep 17 15:29:20.131302 2026] [security2:error] [pid 16723:tid 16952] [client 45.115.26.203:59878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rcpphotorestoration.com"] [uri "/_phpinfo.php"] [unique_id "aqxbsC9E0uOV11S2qN6cdwAAAOc"]
[Thu Sep 17 15:29:20.135823 2026] [proxy_http:error] [pid 1029697:tid 1029906] (20014)Internal error (specific information not available): [client 45.115.26.203:59898] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.135834 2026] [proxy:error] [pid 1029697:tid 1029906] [client 45.115.26.203:59898] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/actuator/env
[Thu Sep 17 15:29:20.136527 2026] [proxy_http:error] [pid 16723:tid 16972] (20014)Internal error (specific information not available): [client 45.115.26.203:59706] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.136537 2026] [proxy:error] [pid 16723:tid 16972] [client 45.115.26.203:59706] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.swp
[Thu Sep 17 15:29:20.142435 2026] [proxy_http:error] [pid 16723:tid 16905] (20014)Internal error (specific information not available): [client 45.115.26.203:59926] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.142448 2026] [proxy:error] [pid 16723:tid 16905] [client 45.115.26.203:59926] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/server-status
[Thu Sep 17 15:29:20.143195 2026] [proxy_http:error] [pid 1029697:tid 1029829] (20014)Internal error (specific information not available): [client 45.115.26.203:59772] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.143217 2026] [proxy:error] [pid 1029697:tid 1029829] [client 45.115.26.203:59772] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.docker/config.json
[Thu Sep 17 15:29:20.148779 2026] [proxy_http:error] [pid 1029697:tid 1029922] (20014)Internal error (specific information not available): [client 45.115.26.203:59642] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.148796 2026] [proxy:error] [pid 1029697:tid 1029922] [client 45.115.26.203:59642] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.stage
[Thu Sep 17 15:29:20.153694 2026] [proxy_http:error] [pid 1029697:tid 1029939] (20014)Internal error (specific information not available): [client 45.115.26.203:59722] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.153708 2026] [proxy:error] [pid 1029697:tid 1029939] [client 45.115.26.203:59722] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/api/.env
[Thu Sep 17 15:29:20.154392 2026] [proxy_http:error] [pid 16723:tid 16909] (20014)Internal error (specific information not available): [client 45.115.26.203:59780] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.154403 2026] [proxy:error] [pid 16723:tid 16909] [client 45.115.26.203:59780] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Thu Sep 17 15:29:20.158228 2026] [proxy_http:error] [pid 1029697:tid 1029926] (20014)Internal error (specific information not available): [client 45.115.26.203:59748] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.158242 2026] [proxy:error] [pid 1029697:tid 1029926] [client 45.115.26.203:59748] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml
[Thu Sep 17 15:29:20.159472 2026] [proxy_http:error] [pid 16723:tid 16854] (20014)Internal error (specific information not available): [client 45.115.26.203:59678] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.159484 2026] [proxy:error] [pid 16723:tid 16854] [client 45.115.26.203:59678] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.old
[Thu Sep 17 15:29:20.164124 2026] [proxy_http:error] [pid 16723:tid 16882] (20014)Internal error (specific information not available): [client 45.115.26.203:59690] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.164137 2026] [proxy:error] [pid 16723:tid 16882] [client 45.115.26.203:59690] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.save
[Thu Sep 17 15:29:20.168551 2026] [proxy_http:error] [pid 16723:tid 16978] (20014)Internal error (specific information not available): [client 45.115.26.203:59558] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:29:20.168561 2026] [proxy:error] [pid 16723:tid 16978] [client 45.115.26.203:59558] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env
[Thu Sep 17 15:29:20.184836 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.94.35.111:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/debug.php"] [unique_id "aqxbsG65wm-f4uX16X6f4wAAAAE"]
[Thu Sep 17 15:29:20.270971 2026] [security2:error] [pid 16723:tid 16874] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6brgAAAJk"]
[Thu Sep 17 15:29:20.277289 2026] [security2:error] [pid 16723:tid 16878] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bsAAAAJ0"]
[Thu Sep 17 15:29:20.277988 2026] [security2:error] [pid 16723:tid 16925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bzQAAAMw"]
[Thu Sep 17 15:29:20.285382 2026] [security2:error] [pid 1029697:tid 1029750] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/config/aws.php"] [unique_id "aqxbrW65wm-f4uX16X6f5AAAOTQ"]
[Thu Sep 17 15:29:20.285906 2026] [security2:error] [pid 16723:tid 16867] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6boQAAAJI"]
[Thu Sep 17 15:29:20.286283 2026] [security2:error] [pid 1029697:tid 1029759] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/config/stripe.php"] [unique_id "aqxbrW65wm-f4uX16X6f5QAAOT0"]
[Thu Sep 17 15:29:20.286660 2026] [security2:error] [pid 1029697:tid 1029759] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/config/mail.php"] [unique_id "aqxbrW65wm-f4uX16X6f6AAAOT0"]
[Thu Sep 17 15:29:20.287004 2026] [security2:error] [pid 1029697:tid 1029759] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/config/config.inc.php"] [unique_id "aqxbrW65wm-f4uX16X6f6QAAOT0"]
[Thu Sep 17 15:29:20.293072 2026] [security2:error] [pid 1029697:tid 1029750] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/config/nexmo.php"] [unique_id "aqxbrm65wm-f4uX16X6f6wAAOTQ"]
[Thu Sep 17 15:29:20.299335 2026] [security2:error] [pid 1029697:tid 1029715] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "silverstaterealty.com"] [uri "/wp-config.php.bak"] [unique_id "aqxbrm65wm-f4uX16X6f8QAAORE"]
[Thu Sep 17 15:29:20.299512 2026] [security2:error] [pid 1029697:tid 1029796] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "silverstaterealty.com"] [uri "/wp-config.php.old"] [unique_id "aqxbrm65wm-f4uX16X6f8gAAOWI"]
[Thu Sep 17 15:29:20.299639 2026] [security2:error] [pid 1029697:tid 1029796] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "silverstaterealty.com"] [uri "/wp-config.php.new"] [unique_id "aqxbr265wm-f4uX16X6f8wAAOWI"]
[Thu Sep 17 15:29:20.299779 2026] [security2:error] [pid 1029697:tid 1029821] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/wp-config.php"] [unique_id "aqxbrm65wm-f4uX16X6f8AAAOXs"]
[Thu Sep 17 15:29:20.300147 2026] [security2:error] [pid 1029697:tid 1029796] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxbr265wm-f4uX16X6f9AAAOWI"]
[Thu Sep 17 15:29:20.314906 2026] [security2:error] [pid 16723:tid 16787] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxbsC9E0uOV11S2qN6cfwAAqT4"]
[Thu Sep 17 15:29:20.330808 2026] [security2:error] [pid 16723:tid 16976] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6b3AAAAP8"]
[Thu Sep 17 15:29:20.342652 2026] [security2:error] [pid 16723:tid 16948] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bpAAAAOM"]
[Thu Sep 17 15:29:20.344539 2026] [security2:error] [pid 1029697:tid 1029699] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxbr265wm-f4uX16X6f_AAAFQE"]
[Thu Sep 17 15:29:20.348502 2026] [security2:error] [pid 1029697:tid 1029912] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbq265wm-f4uX16X6ewQAAAFU"]
[Thu Sep 17 15:29:20.356996 2026] [security2:error] [pid 16723:tid 16980] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bqgAAAQM"]
[Thu Sep 17 15:29:20.357752 2026] [security2:error] [pid 16723:tid 16908] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bzwAAALs"]
[Thu Sep 17 15:29:20.359955 2026] [security2:error] [pid 16723:tid 16954] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6bzgAAAOk"]
[Thu Sep 17 15:29:20.397462 2026] [security2:error] [pid 1029697:tid 1029866] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrG65wm-f4uX16X6fGAAAACc"]
[Thu Sep 17 15:29:20.421263 2026] [security2:error] [pid 16723:tid 16949] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrS9E0uOV11S2qN6b_AAAAOQ"]
[Thu Sep 17 15:29:20.502812 2026] [security2:error] [pid 1029697:tid 1029833] [client 165.245.228.249:51812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6f-QAABgo"], referer: http://talent-in-borders.com/wp/
[Thu Sep 17 15:29:20.516023 2026] [security2:error] [pid 16723:tid 16733] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxbsC9E0uOV11S2qN6chgAAqQg"]
[Thu Sep 17 15:29:20.554610 2026] [security2:error] [pid 1029697:tid 1029851] [client 34.166.113.162:35000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/pinfo.php"] [unique_id "aqxbsG65wm-f4uX16X6gGAAAABg"]
[Thu Sep 17 15:29:20.563784 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.154.219.249:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxbsG65wm-f4uX16X6gGgAAADw"]
[Thu Sep 17 15:29:20.568401 2026] [security2:error] [pid 1029697:tid 1029924] [client 168.138.205.35:54838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "pascalweldinganddesign.com"] [uri "/"] [unique_id "aqxbsG65wm-f4uX16X6gGQAAAGE"]
[Thu Sep 17 15:29:20.701343 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.94.35.111:36274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbsG65wm-f4uX16X6gHQAAAGc"]
[Thu Sep 17 15:29:20.801727 2026] [security2:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxbsG65wm-f4uX16X6gHgAAFTc"]
[Thu Sep 17 15:29:20.974442 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.94.35.111:36276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbsG65wm-f4uX16X6gIwAAAEI"]
[Thu Sep 17 15:29:21.039215 2026] [security2:error] [pid 1029697:tid 1029923] [client 34.154.219.249:47046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbsW65wm-f4uX16X6gJgAAAGA"]
[Thu Sep 17 15:29:21.237304 2026] [security2:error] [pid 16723:tid 16926] [client 34.94.35.111:36282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbsS9E0uOV11S2qN6cpQAAAM0"]
[Thu Sep 17 15:29:21.248200 2026] [security2:error] [pid 1029697:tid 1029909] [client 34.166.113.162:35012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/test.php"] [unique_id "aqxbsW65wm-f4uX16X6gKgAAAFI"]
[Thu Sep 17 15:29:21.267117 2026] [security2:error] [pid 16723:tid 16946] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrS9E0uOV11S2qN6cAgAAAOE"]
[Thu Sep 17 15:29:21.279620 2026] [security2:error] [pid 16723:tid 16906] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6b2wAAALk"]
[Thu Sep 17 15:29:21.289940 2026] [security2:error] [pid 16723:tid 16971] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrS9E0uOV11S2qN6b-gAAAPo"]
[Thu Sep 17 15:29:21.304168 2026] [security2:error] [pid 16723:tid 16955] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbri9E0uOV11S2qN6cKQAAAOo"]
[Thu Sep 17 15:29:21.312095 2026] [security2:error] [pid 16723:tid 16875] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbri9E0uOV11S2qN6cJQAAAJo"]
[Thu Sep 17 15:29:21.312765 2026] [security2:error] [pid 16723:tid 16862] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrS9E0uOV11S2qN6cAAAAAI0"]
[Thu Sep 17 15:29:21.325281 2026] [security2:error] [pid 16723:tid 16975] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6b0gAAAP4"]
[Thu Sep 17 15:29:21.327150 2026] [security2:error] [pid 1029697:tid 1029915] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbrG65wm-f4uX16X6fJQAAAFg"]
[Thu Sep 17 15:29:21.333135 2026] [security2:error] [pid 1029697:tid 1029927] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrm65wm-f4uX16X6fmAAAAGQ"]
[Thu Sep 17 15:29:21.363953 2026] [security2:error] [pid 16723:tid 16902] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbri9E0uOV11S2qN6cIwAAALU"]
[Thu Sep 17 15:29:21.373954 2026] [security2:error] [pid 16723:tid 16918] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbri9E0uOV11S2qN6cIAAAAMU"]
[Thu Sep 17 15:29:21.400229 2026] [security2:error] [pid 1029697:tid 1029736] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/config/mail.php"] [unique_id "aqxbrm65wm-f4uX16X6gLQAAAyY"]
[Thu Sep 17 15:29:21.400746 2026] [security2:error] [pid 1029697:tid 1029850] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrm65wm-f4uX16X6fnQAAABc"]
[Thu Sep 17 15:29:21.401055 2026] [security2:error] [pid 1029697:tid 1029736] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/config/config.inc.php"] [unique_id "aqxbrm65wm-f4uX16X6gLgAAAyY"]
[Thu Sep 17 15:29:21.403379 2026] [security2:error] [pid 1029697:tid 1029771] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/config/nexmo.php"] [unique_id "aqxbrm65wm-f4uX16X6gMAAAA0k"]
[Thu Sep 17 15:29:21.428421 2026] [security2:error] [pid 16723:tid 16970] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbrC9E0uOV11S2qN6b2AAAAPk"]
[Thu Sep 17 15:29:21.497392 2026] [security2:error] [pid 1029697:tid 1029906] [client 162.241.226.11:24194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "alanpeckolick.com"] [uri "/wp-content/uploads/2015/07/AP-web-logo1.png"] [unique_id "aqxbsW65wm-f4uX16X6gOwAAAE8"]
[Thu Sep 17 15:29:21.502905 2026] [security2:error] [pid 16723:tid 16867] [client 34.154.219.249:47060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbsS9E0uOV11S2qN6cswAAAJI"]
[Thu Sep 17 15:29:21.503261 2026] [security2:error] [pid 1029697:tid 1029734] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/wp-config.php"] [unique_id "aqxbr265wm-f4uX16X6gPAAAAyQ"]
[Thu Sep 17 15:29:21.503438 2026] [security2:error] [pid 1029697:tid 1029734] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "edmagiktv.com"] [uri "/wp-config.php.bak"] [unique_id "aqxbsG65wm-f4uX16X6gPQAAAyQ"]
[Thu Sep 17 15:29:21.503493 2026] [security2:error] [pid 1029697:tid 1029803] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "edmagiktv.com"] [uri "/wp-config.php.old"] [unique_id "aqxbsG65wm-f4uX16X6gPgAAA2k"]
[Thu Sep 17 15:29:21.503544 2026] [security2:error] [pid 1029697:tid 1029734] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "edmagiktv.com"] [uri "/wp-config.php.new"] [unique_id "aqxbsG65wm-f4uX16X6gPwAAAyQ"]
[Thu Sep 17 15:29:21.503925 2026] [security2:error] [pid 1029697:tid 1029803] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxbsG65wm-f4uX16X6gQAAAA2k"]
[Thu Sep 17 15:29:21.504630 2026] [security2:error] [pid 1029697:tid 1029773] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxbsG65wm-f4uX16X6gQwAAA0s"]
[Thu Sep 17 15:29:21.620183 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.94.35.111:36288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbsW65wm-f4uX16X6gUAAAAAI"]
[Thu Sep 17 15:29:21.687742 2026] [security2:error] [pid 1029697:tid 1029742] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxbsW65wm-f4uX16X6gVAAAAyw"]
[Thu Sep 17 15:29:21.734224 2026] [qos:error] [pid 16723:tid 16954] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsS9E0uOV11S2qN6cxAAAAOk
[Thu Sep 17 15:29:21.740003 2026] [qos:error] [pid 16723:tid 16916] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsS9E0uOV11S2qN6cxgAAAMM
[Thu Sep 17 15:29:21.761048 2026] [qos:error] [pid 16723:tid 16904] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsS9E0uOV11S2qN6cyQAAALc
[Thu Sep 17 15:29:21.814624 2026] [qos:error] [pid 16723:tid 16937] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsS9E0uOV11S2qN6cywAAANg
[Thu Sep 17 15:29:21.920993 2026] [security2:error] [pid 16723:tid 16868] [client 34.94.35.111:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbsS9E0uOV11S2qN6czgAAAJM"]
[Thu Sep 17 15:29:21.994187 2026] [security2:error] [pid 16723:tid 16951] [client 34.154.219.249:47064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbsS9E0uOV11S2qN6c0AAAAOY"]
[Thu Sep 17 15:29:22.001511 2026] [qos:error] [pid 1029697:tid 1029805] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gaQAAA2s
[Thu Sep 17 15:29:22.001883 2026] [qos:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gagAAA04
[Thu Sep 17 15:29:22.001888 2026] [qos:error] [pid 1029697:tid 1029711] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gawAAAw0
[Thu Sep 17 15:29:22.036160 2026] [qos:error] [pid 1029697:tid 1029836] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsm65wm-f4uX16X6gbQAAAAk
[Thu Sep 17 15:29:22.068182 2026] [qos:error] [pid 1029697:tid 1029806] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gbgAAFWw
[Thu Sep 17 15:29:22.150063 2026] [qos:error] [pid 16723:tid 16971] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsi9E0uOV11S2qN6c2QAAAPo
[Thu Sep 17 15:29:22.178953 2026] [security2:error] [pid 1029697:tid 1029937] [client 34.94.35.111:36308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbsm65wm-f4uX16X6gcgAAAG4"]
[Thu Sep 17 15:29:22.186433 2026] [security2:error] [pid 1029697:tid 1029938] [client 34.166.113.162:35026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/p.php"] [unique_id "aqxbsm65wm-f4uX16X6gcwAAAG8"]
[Thu Sep 17 15:29:22.261432 2026] [security2:error] [pid 16723:tid 16950] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbri9E0uOV11S2qN6cJAAAAOU"]
[Thu Sep 17 15:29:22.314459 2026] [security2:error] [pid 1029697:tid 1029901] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fvQAAAEo"]
[Thu Sep 17 15:29:22.321561 2026] [qos:error] [pid 1029697:tid 1029733] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6geQAAAyM
[Thu Sep 17 15:29:22.327843 2026] [qos:error] [pid 1029697:tid 1029819] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gegAAA3k
[Thu Sep 17 15:29:22.328248 2026] [qos:error] [pid 1029697:tid 1029812] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gewAAA3I
[Thu Sep 17 15:29:22.328542 2026] [security2:error] [pid 16723:tid 16940] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbry9E0uOV11S2qN6cTQAAANs"]
[Thu Sep 17 15:29:22.329285 2026] [qos:error] [pid 1029697:tid 1029819] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gfAAAA3k
[Thu Sep 17 15:29:22.363563 2026] [security2:error] [pid 16723:tid 16958] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbry9E0uOV11S2qN6cYAAAAO0"]
[Thu Sep 17 15:29:22.370825 2026] [security2:error] [pid 1029697:tid 1029848] [client 45.138.12.25:37862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fwwAAFQw"]
[Thu Sep 17 15:29:22.386759 2026] [qos:error] [pid 16723:tid 16941] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsi9E0uOV11S2qN6c4QAAANw
[Thu Sep 17 15:29:22.390817 2026] [security2:error] [pid 1029697:tid 1029868] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fsQAAACk"]
[Thu Sep 17 15:29:22.409525 2026] [security2:error] [pid 1029697:tid 1029844] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gBQAAABE"]
[Thu Sep 17 15:29:22.436210 2026] [security2:error] [pid 1029697:tid 1029910] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gCQAAAFM"]
[Thu Sep 17 15:29:22.473934 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.154.219.249:47070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbsm65wm-f4uX16X6gigAAAA0"]
[Thu Sep 17 15:29:22.517964 2026] [qos:error] [pid 1029697:tid 1029707] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gjgAAFQk
[Thu Sep 17 15:29:22.518009 2026] [qos:error] [pid 16723:tid 16932] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxbsi9E0uOV11S2qN6c5gAAANM
[Thu Sep 17 15:29:22.518399 2026] [qos:error] [pid 1029697:tid 1029716] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gjwAAFRI
[Thu Sep 17 15:29:22.540529 2026] [security2:error] [pid 16723:tid 16890] [client 45.138.12.25:37868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6cfgAAqT0"]
[Thu Sep 17 15:29:22.601532 2026] [core:error] [pid 1029697:tid 1029915] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:22.601549 2026] [core:error] [pid 1029697:tid 1029915] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:22.646222 2026] [qos:error] [pid 1029697:tid 1029850] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsm65wm-f4uX16X6gngAAABc
[Thu Sep 17 15:29:22.653881 2026] [qos:error] [pid 1029697:tid 1029929] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsm65wm-f4uX16X6gnwAAAGY
[Thu Sep 17 15:29:22.694762 2026] [qos:error] [pid 1029697:tid 1029780] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gpAAAFVI
[Thu Sep 17 15:29:22.695152 2026] [qos:error] [pid 1029697:tid 1029791] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gpQAAFV0
[Thu Sep 17 15:29:22.699078 2026] [qos:error] [pid 1029697:tid 1029829] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsm65wm-f4uX16X6gpgAAAAI
[Thu Sep 17 15:29:22.722100 2026] [qos:error] [pid 16723:tid 16817] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsi9E0uOV11S2qN6c8AAAqVw
[Thu Sep 17 15:29:22.731163 2026] [qos:error] [pid 1029697:tid 1029699] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gqQAAAwE
[Thu Sep 17 15:29:22.731329 2026] [qos:error] [pid 1029697:tid 1029804] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gqgAAA2o
[Thu Sep 17 15:29:22.731358 2026] [qos:error] [pid 1029697:tid 1029818] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gqAAAA3g
[Thu Sep 17 15:29:22.731516 2026] [qos:error] [pid 1029697:tid 1029801] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gqwAAA2c
[Thu Sep 17 15:29:22.757622 2026] [qos:error] [pid 1029697:tid 1029751] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6grAAAAzU
[Thu Sep 17 15:29:22.765710 2026] [qos:error] [pid 16723:tid 16757] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsi9E0uOV11S2qN6c8gAAqSA
[Thu Sep 17 15:29:22.778345 2026] [qos:error] [pid 1029697:tid 1029781] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6grQAAA1M
[Thu Sep 17 15:29:22.786693 2026] [security2:error] [pid 16723:tid 16976] [client 185.55.149.49:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbsi9E0uOV11S2qN6c8wAAAP8"]
[Thu Sep 17 15:29:22.786781 2026] [security2:error] [pid 16723:tid 16976] [client 185.55.149.49:65335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbsi9E0uOV11S2qN6c8wAAAP8"]
[Thu Sep 17 15:29:22.820127 2026] [qos:error] [pid 16723:tid 16960] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsi9E0uOV11S2qN6c9AAAAO8
[Thu Sep 17 15:29:22.874581 2026] [qos:error] [pid 16723:tid 16937] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsi9E0uOV11S2qN6c9gAAANg
[Thu Sep 17 15:29:22.880042 2026] [security2:error] [pid 16723:tid 16883] [client 34.94.35.111:36332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/php-info.php"] [unique_id "aqxbsi9E0uOV11S2qN6c-AAAAKI"]
[Thu Sep 17 15:29:22.881295 2026] [security2:error] [pid 1029697:tid 1029837] [client 34.166.113.162:51400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/debug.php"] [unique_id "aqxbsm65wm-f4uX16X6gsAAAAAo"]
[Thu Sep 17 15:29:22.911257 2026] [qos:error] [pid 1029697:tid 1029784] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gswAAA1Y
[Thu Sep 17 15:29:22.911331 2026] [qos:error] [pid 1029697:tid 1029708] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gtAAAAwo
[Thu Sep 17 15:29:22.911333 2026] [qos:error] [pid 1029697:tid 1029815] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gsgAAA3U
[Thu Sep 17 15:29:22.935360 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.154.219.249:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxbsm65wm-f4uX16X6gtQAAAEc"]
[Thu Sep 17 15:29:22.937221 2026] [qos:error] [pid 1029697:tid 1029817] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gtgAAA3c
[Thu Sep 17 15:29:22.939135 2026] [qos:error] [pid 16723:tid 16814] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsi9E0uOV11S2qN6c-wAAqVk
[Thu Sep 17 15:29:22.947031 2026] [qos:error] [pid 16723:tid 16776] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsi9E0uOV11S2qN6c_AAAqTM
[Thu Sep 17 15:29:22.956082 2026] [qos:error] [pid 16723:tid 16951] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsi9E0uOV11S2qN6c_wAAAOY
[Thu Sep 17 15:29:22.959113 2026] [qos:error] [pid 1029697:tid 1029763] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6guwAAFUE
[Thu Sep 17 15:29:22.959116 2026] [qos:error] [pid 1029697:tid 1029752] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6guQAAAzY
[Thu Sep 17 15:29:22.959436 2026] [qos:error] [pid 1029697:tid 1029740] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6guAAAFSo
[Thu Sep 17 15:29:22.959458 2026] [qos:error] [pid 1029697:tid 1029825] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gvAAAFX8
[Thu Sep 17 15:29:22.959485 2026] [qos:error] [pid 1029697:tid 1029753] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gugAAFTc
[Thu Sep 17 15:29:22.959615 2026] [qos:error] [pid 1029697:tid 1029752] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gvwAAFTY
[Thu Sep 17 15:29:22.959620 2026] [qos:error] [pid 1029697:tid 1029763] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gvQAAFUE
[Thu Sep 17 15:29:22.959688 2026] [qos:error] [pid 1029697:tid 1029788] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gwAAAFVo
[Thu Sep 17 15:29:22.959735 2026] [qos:error] [pid 1029697:tid 1029794] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbsm65wm-f4uX16X6gvgAAFWA
[Thu Sep 17 15:29:23.008368 2026] [qos:error] [pid 16723:tid 16797] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsy9E0uOV11S2qN6dAAAAqUg
[Thu Sep 17 15:29:23.085913 2026] [security2:error] [pid 16723:tid 16926] [client 34.94.35.111:36338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/phpversion.php"] [unique_id "aqxbsy9E0uOV11S2qN6dAQAAAM0"]
[Thu Sep 17 15:29:23.087245 2026] [qos:error] [pid 16723:tid 16798] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsy9E0uOV11S2qN6dAgAAqUk
[Thu Sep 17 15:29:23.089946 2026] [qos:error] [pid 1029697:tid 1029731] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gxgAAAyE
[Thu Sep 17 15:29:23.089953 2026] [qos:error] [pid 1029697:tid 1029724] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gxQAAAxo
[Thu Sep 17 15:29:23.090238 2026] [qos:error] [pid 1029697:tid 1029705] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gxAAAAwc
[Thu Sep 17 15:29:23.108812 2026] [qos:error] [pid 16723:tid 16978] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsy9E0uOV11S2qN6dAwAAAQE
[Thu Sep 17 15:29:23.119550 2026] [qos:error] [pid 16723:tid 16799] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsy9E0uOV11S2qN6dBAAAqUo
[Thu Sep 17 15:29:23.128113 2026] [qos:error] [pid 16723:tid 16820] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsy9E0uOV11S2qN6dBgAAqV8
[Thu Sep 17 15:29:23.137505 2026] [qos:error] [pid 1029697:tid 1029769] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gyAAAFUc
[Thu Sep 17 15:29:23.137552 2026] [qos:error] [pid 1029697:tid 1029702] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gzQAAFQQ
[Thu Sep 17 15:29:23.137758 2026] [qos:error] [pid 1029697:tid 1029823] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gygAAFX0
[Thu Sep 17 15:29:23.137762 2026] [qos:error] [pid 1029697:tid 1029706] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gzgAAFQg
[Thu Sep 17 15:29:23.137768 2026] [qos:error] [pid 1029697:tid 1029800] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gzAAAFWY
[Thu Sep 17 15:29:23.137785 2026] [qos:error] [pid 1029697:tid 1029790] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gywAAFVw
[Thu Sep 17 15:29:23.137790 2026] [qos:error] [pid 1029697:tid 1029803] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gzwAAFWk
[Thu Sep 17 15:29:23.137835 2026] [qos:error] [pid 1029697:tid 1029727] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.138.12.25, id=aqxbs265wm-f4uX16X6gyQAAFR0
[Thu Sep 17 15:29:23.141077 2026] [qos:error] [pid 1029697:tid 1029773] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbs265wm-f4uX16X6g0AAAA0s
[Thu Sep 17 15:29:23.189936 2026] [qos:error] [pid 16723:tid 16796] [remote 45.138.12.25:37868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbsy9E0uOV11S2qN6dBwAAqUc
[Thu Sep 17 15:29:23.205296 2026] [qos:error] [pid 16723:tid 16880] [client 45.138.12.25:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxbsy9E0uOV11S2qN6dCAAAAJ8
[Thu Sep 17 15:29:23.210516 2026] [qos:error] [pid 1029697:tid 1029798] [remote 45.138.12.25:37884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbs265wm-f4uX16X6g0QAAA2Q
[Thu Sep 17 15:29:23.258815 2026] [security2:error] [pid 1029697:tid 1029888] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fzAAAAD0"]
[Thu Sep 17 15:29:23.263970 2026] [security2:error] [pid 16723:tid 16877] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbry9E0uOV11S2qN6cTgAAAJw"]
[Thu Sep 17 15:29:23.270851 2026] [security2:error] [pid 1029697:tid 1029885] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrm65wm-f4uX16X6fnAAAADo"]
[Thu Sep 17 15:29:23.274454 2026] [security2:error] [pid 1029697:tid 1029895] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrm65wm-f4uX16X6fpwAAAEQ"]
[Thu Sep 17 15:29:23.275289 2026] [security2:error] [pid 1029697:tid 1029872] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6f_gAAAC0"]
[Thu Sep 17 15:29:23.282789 2026] [security2:error] [pid 1029697:tid 1029905] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbrm65wm-f4uX16X6fngAAAE4"]
[Thu Sep 17 15:29:23.288499 2026] [security2:error] [pid 1029697:tid 1029950] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gBAAAAHs"]
[Thu Sep 17 15:29:23.290391 2026] [security2:error] [pid 1029697:tid 1029714] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/phpinfo.php"] [unique_id "aqxbs265wm-f4uX16X6g2AAAAxA"]
[Thu Sep 17 15:29:23.293215 2026] [security2:error] [pid 16723:tid 16919] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6ciQAAAMY"]
[Thu Sep 17 15:29:23.315297 2026] [security2:error] [pid 1029697:tid 1029722] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/phpinfo.php"] [unique_id "aqxbs265wm-f4uX16X6g3QAAFRg"]
[Thu Sep 17 15:29:23.315756 2026] [security2:error] [pid 1029697:tid 1029722] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/info.php"] [unique_id "aqxbs265wm-f4uX16X6g3gAAFRg"]
[Thu Sep 17 15:29:23.316155 2026] [security2:error] [pid 1029697:tid 1029722] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/infos.php"] [unique_id "aqxbs265wm-f4uX16X6g3wAAFRg"]
[Thu Sep 17 15:29:23.323554 2026] [security2:error] [pid 1029697:tid 1029940] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fuwAAAHE"]
[Thu Sep 17 15:29:23.324295 2026] [security2:error] [pid 1029697:tid 1029949] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6f_wAAAHo"]
[Thu Sep 17 15:29:23.338004 2026] [security2:error] [pid 1029697:tid 1029899] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbr265wm-f4uX16X6fvgAAAEg"]
[Thu Sep 17 15:29:23.349265 2026] [security2:error] [pid 1029697:tid 1029882] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gEAAAADc"]
[Thu Sep 17 15:29:23.350556 2026] [security2:error] [pid 16723:tid 16975] [client 34.94.35.111:36348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/_phpinfo.php"] [unique_id "aqxbsy9E0uOV11S2qN6dHQAAAP4"]
[Thu Sep 17 15:29:23.382007 2026] [security2:error] [pid 16723:tid 16865] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbry9E0uOV11S2qN6cLAAAAJA"]
[Thu Sep 17 15:29:23.390556 2026] [security2:error] [pid 1029697:tid 1029712] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/info.php"] [unique_id "aqxbs265wm-f4uX16X6g4wAAAw4"]
[Thu Sep 17 15:29:23.399685 2026] [security2:error] [pid 16723:tid 16862] [client 34.154.219.249:47090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxbsy9E0uOV11S2qN6dKAAAAI0"]
[Thu Sep 17 15:29:23.408714 2026] [security2:error] [pid 16723:tid 16885] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbry9E0uOV11S2qN6cTwAAAKQ"]
[Thu Sep 17 15:29:23.414490 2026] [security2:error] [pid 16723:tid 16923] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6cjQAAAMo"]
[Thu Sep 17 15:29:23.416994 2026] [security2:error] [pid 1029697:tid 1029782] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/infos.php"] [unique_id "aqxbs265wm-f4uX16X6g5QAAA1Q"]
[Thu Sep 17 15:29:23.430569 2026] [security2:error] [pid 16723:tid 16867] [client 104.238.222.26:64661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.arhitecturabuzau.ro"] [uri "/wp-login.php"] [unique_id "aqxbsy9E0uOV11S2qN6dKQAAAJI"]
[Thu Sep 17 15:29:23.471232 2026] [security2:error] [pid 1029697:tid 1029711] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/php_info.php"] [unique_id "aqxbs265wm-f4uX16X6g5wAAAw0"]
[Thu Sep 17 15:29:23.491108 2026] [security2:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/php_info.php"] [unique_id "aqxbs265wm-f4uX16X6g6AAAFU4"]
[Thu Sep 17 15:29:23.491165 2026] [security2:error] [pid 1029697:tid 1029766] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/php-info.php"] [unique_id "aqxbs265wm-f4uX16X6g6gAAFUQ"]
[Thu Sep 17 15:29:23.491178 2026] [security2:error] [pid 1029697:tid 1029806] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/php.php"] [unique_id "aqxbs265wm-f4uX16X6g6QAAFWw"]
[Thu Sep 17 15:29:23.571912 2026] [security2:error] [pid 16723:tid 16855] [client 34.166.113.162:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbsy9E0uOV11S2qN6dMgAAAIY"]
[Thu Sep 17 15:29:23.711818 2026] [security2:error] [pid 16723:tid 16915] [client 34.94.35.111:36354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbsy9E0uOV11S2qN6dNgAAAMI"]
[Thu Sep 17 15:29:23.818310 2026] [core:error] [pid 16723:tid 16879] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:23.818328 2026] [core:error] [pid 16723:tid 16879] [client 165.154.151.176:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:23.822556 2026] [security2:error] [pid 1029697:tid 1029744] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/infophp.php"] [unique_id "aqxbs265wm-f4uX16X6g7QAAFS4"]
[Thu Sep 17 15:29:23.836768 2026] [security2:error] [pid 1029697:tid 1029764] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbs265wm-f4uX16X6g8AAAFUI"]
[Thu Sep 17 15:29:23.836794 2026] [security2:error] [pid 1029697:tid 1029733] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxbs265wm-f4uX16X6g8QAAFSM"]
[Thu Sep 17 15:29:23.836823 2026] [security2:error] [pid 1029697:tid 1029704] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxbs265wm-f4uX16X6g7wAAFQY"]
[Thu Sep 17 15:29:23.860090 2026] [security2:error] [pid 16723:tid 16956] [client 34.154.219.249:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxbsy9E0uOV11S2qN6dPAAAAOs"]
[Thu Sep 17 15:29:23.985327 2026] [security2:error] [pid 16723:tid 16859] [client 34.94.35.111:36366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/server-info.php"] [unique_id "aqxbsy9E0uOV11S2qN6dPwAAAIo"]
[Thu Sep 17 15:29:24.015157 2026] [security2:error] [pid 1029697:tid 1029741] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/api/phpinfo.php"] [unique_id "aqxbtG65wm-f4uX16X6g9AAAFSs"]
[Thu Sep 17 15:29:24.015218 2026] [security2:error] [pid 1029697:tid 1029822] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbtG65wm-f4uX16X6g9QAAFXw"]
[Thu Sep 17 15:29:24.031303 2026] [qos:error] [pid 1029697:tid 1029802] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbtG65wm-f4uX16X6g9wAAFWg
[Thu Sep 17 15:29:24.183081 2026] [qos:error] [pid 1029697:tid 1029768] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbtG65wm-f4uX16X6g-AAAFUY
[Thu Sep 17 15:29:24.197392 2026] [qos:error] [pid 1029697:tid 1029785] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbtG65wm-f4uX16X6g-QAAFVc
[Thu Sep 17 15:29:24.197400 2026] [qos:error] [pid 1029697:tid 1029755] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.138.12.25, id=aqxbtG65wm-f4uX16X6g-gAAFTk
[Thu Sep 17 15:29:24.239408 2026] [qos:error] [pid 1029697:tid 1029707] [remote 45.138.12.25:37862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.138.12.25, id=aqxbtG65wm-f4uX16X6g-wAAFQk
[Thu Sep 17 15:29:24.268132 2026] [security2:error] [pid 1029697:tid 1029931] [client 34.166.113.162:51414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/test/phpinfo.php"] [unique_id "aqxbtG65wm-f4uX16X6g_AAAAGg"]
[Thu Sep 17 15:29:24.278495 2026] [security2:error] [pid 1029697:tid 1029897] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gGwAAAEY"]
[Thu Sep 17 15:29:24.283007 2026] [security2:error] [pid 16723:tid 16860] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6chQAAAIs"]
[Thu Sep 17 15:29:24.287420 2026] [security2:error] [pid 1029697:tid 1029914] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gIQAAAFc"]
[Thu Sep 17 15:29:24.303274 2026] [security2:error] [pid 1029697:tid 1029921] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gFQAAAF4"]
[Thu Sep 17 15:29:24.318577 2026] [security2:error] [pid 1029697:tid 1029893] [client 34.154.219.249:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxbtG65wm-f4uX16X6g_QAAAEI"]
[Thu Sep 17 15:29:24.318603 2026] [security2:error] [pid 16723:tid 16870] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6clQAAAJU"]
[Thu Sep 17 15:29:24.322457 2026] [security2:error] [pid 16723:tid 16854] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cpgAAAIU"]
[Thu Sep 17 15:29:24.334114 2026] [security2:error] [pid 16723:tid 16963] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6cmgAAAPI"]
[Thu Sep 17 15:29:24.341426 2026] [security2:error] [pid 16723:tid 16887] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6cnAAAAKY"]
[Thu Sep 17 15:29:24.349201 2026] [security2:error] [pid 16723:tid 16940] [client 34.94.35.111:36368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/server-status.php"] [unique_id "aqxbtC9E0uOV11S2qN6dQgAAANs"]
[Thu Sep 17 15:29:24.352160 2026] [security2:error] [pid 1029697:tid 1029855] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsW65wm-f4uX16X6gSgAAABw"]
[Thu Sep 17 15:29:24.360948 2026] [security2:error] [pid 1029697:tid 1029846] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsW65wm-f4uX16X6gNQAAABM"]
[Thu Sep 17 15:29:24.371540 2026] [security2:error] [pid 16723:tid 16921] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6clgAAAMg"]
[Thu Sep 17 15:29:24.377490 2026] [security2:error] [pid 1029697:tid 1029820] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/database.sql"] [unique_id "aqxbtG65wm-f4uX16X6hBQAAFXo"]
[Thu Sep 17 15:29:24.395785 2026] [security2:error] [pid 16723:tid 16901] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cuwAAALQ"]
[Thu Sep 17 15:29:24.397537 2026] [security2:error] [pid 16723:tid 16911] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6ctwAAAL4"]
[Thu Sep 17 15:29:24.403795 2026] [security2:error] [pid 1029697:tid 1029947] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsW65wm-f4uX16X6gLAAAAHg"]
[Thu Sep 17 15:29:24.424276 2026] [security2:error] [pid 16723:tid 16930] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6coQAAANE"]
[Thu Sep 17 15:29:24.429532 2026] [security2:error] [pid 16723:tid 16968] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cwwAAAPc"]
[Thu Sep 17 15:29:24.429791 2026] [security2:error] [pid 16723:tid 16966] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cuAAAAPU"]
[Thu Sep 17 15:29:24.593581 2026] [security2:error] [pid 1029697:tid 1029715] [remote 47.128.20.36:55590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/a-5-part-series-on-michael-heisers-the-unseen-realm-part-4-jesus-casts-out-demons-and-leads-an-assault-on-mount-hermon/"] [unique_id "aqxbtG65wm-f4uX16X6hEAAAYxE"]
[Thu Sep 17 15:29:24.656403 2026] [core:error] [pid 16723:tid 16972] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:24.656421 2026] [core:error] [pid 16723:tid 16972] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:24.780592 2026] [security2:error] [pid 16723:tid 16882] [client 34.154.219.249:47132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxbtC9E0uOV11S2qN6dUAAAAKE"]
[Thu Sep 17 15:29:24.867600 2026] [core:error] [pid 16723:tid 16978] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:24.867617 2026] [core:error] [pid 16723:tid 16978] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:24.954400 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.166.113.162:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxbtG65wm-f4uX16X6hFAAAAAE"]
[Thu Sep 17 15:29:25.084430 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.94.35.111:36402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbtW65wm-f4uX16X6hGgAAAHw"]
[Thu Sep 17 15:29:25.123303 2026] [security2:error] [pid 1029697:tid 1029713] [remote 45.157.54.43:24868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-75fc8138.newyearworks.com"] [uri "/xmlrpc.php"] [unique_id "aqxbtW65wm-f4uX16X6hGwAAcw8"]
[Thu Sep 17 15:29:25.123437 2026] [security2:error] [pid 1029697:tid 1029942] [client 45.157.54.43:24868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-75fc8138.newyearworks.com"] [uri "/xmlrpc.php"] [unique_id "aqxbtW65wm-f4uX16X6hGwAAcw8"]
[Thu Sep 17 15:29:25.249477 2026] [security2:error] [pid 1029697:tid 1029936] [client 34.154.219.249:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxbtW65wm-f4uX16X6hHQAAAG0"]
[Thu Sep 17 15:29:25.276314 2026] [security2:error] [pid 16723:tid 16965] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsC9E0uOV11S2qN6cnQAAAPQ"]
[Thu Sep 17 15:29:25.307517 2026] [security2:error] [pid 16723:tid 16945] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6ctgAAAOA"]
[Thu Sep 17 15:29:25.329627 2026] [security2:error] [pid 1029697:tid 1029873] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsW65wm-f4uX16X6gSQAAAC4"]
[Thu Sep 17 15:29:25.338443 2026] [security2:error] [pid 16723:tid 16888] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cwAAAAKc"]
[Thu Sep 17 15:29:25.345551 2026] [security2:error] [pid 16723:tid 16911] [client 34.94.35.111:36410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbtS9E0uOV11S2qN6dWwAAAL4"]
[Thu Sep 17 15:29:25.364697 2026] [security2:error] [pid 1029697:tid 1029865] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsW65wm-f4uX16X6gSwAAACY"]
[Thu Sep 17 15:29:25.411352 2026] [security2:error] [pid 16723:tid 16884] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsi9E0uOV11S2qN6c5QAAAKM"]
[Thu Sep 17 15:29:25.531302 2026] [security2:error] [pid 16723:tid 16949] [client 185.104.184.228:33230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/js/dist/"] [unique_id "aqxbtS9E0uOV11S2qN6dXgAAAOQ"]
[Thu Sep 17 15:29:25.609622 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.94.35.111:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbtW65wm-f4uX16X6hIgAAAB4"]
[Thu Sep 17 15:29:25.640758 2026] [security2:error] [pid 1029697:tid 1029883] [client 34.166.113.162:51428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/old/phpinfo.php"] [unique_id "aqxbtW65wm-f4uX16X6hIwAAADg"]
[Thu Sep 17 15:29:25.721034 2026] [security2:error] [pid 16723:tid 16909] [client 34.154.219.249:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxbtS9E0uOV11S2qN6dZgAAALw"]
[Thu Sep 17 15:29:25.892420 2026] [security2:error] [pid 1029697:tid 1029851] [client 18.188.3.41:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbtW65wm-f4uX16X6hJQAAABg"]
[Thu Sep 17 15:29:25.957012 2026] [security2:error] [pid 16723:tid 16920] [client 34.94.35.111:36434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbtS9E0uOV11S2qN6dagAAAMc"]
[Thu Sep 17 15:29:26.186678 2026] [security2:error] [pid 16723:tid 16978] [client 34.154.219.249:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxbti9E0uOV11S2qN6dbwAAAQE"]
[Thu Sep 17 15:29:26.242145 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.94.35.111:36446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbtm65wm-f4uX16X6hKwAAADw"]
[Thu Sep 17 15:29:26.264462 2026] [security2:error] [pid 16723:tid 16927] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dEwAAAM4"]
[Thu Sep 17 15:29:26.268716 2026] [security2:error] [pid 1029697:tid 1029906] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsm65wm-f4uX16X6gogAAAE8"]
[Thu Sep 17 15:29:26.278124 2026] [security2:error] [pid 16723:tid 16973] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cxwAAAPw"]
[Thu Sep 17 15:29:26.278348 2026] [security2:error] [pid 16723:tid 16857] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dDwAAAIg"]
[Thu Sep 17 15:29:26.287800 2026] [security2:error] [pid 16723:tid 16943] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cyAAAAN4"]
[Thu Sep 17 15:29:26.296034 2026] [security2:error] [pid 16723:tid 16910] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsi9E0uOV11S2qN6c4wAAAL0"]
[Thu Sep 17 15:29:26.304355 2026] [security2:error] [pid 16723:tid 16977] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsi9E0uOV11S2qN6c5wAAAQA"]
[Thu Sep 17 15:29:26.309725 2026] [security2:error] [pid 1029697:tid 1029879] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsm65wm-f4uX16X6gowAAADQ"]
[Thu Sep 17 15:29:26.325930 2026] [security2:error] [pid 16723:tid 16914] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dDgAAAME"]
[Thu Sep 17 15:29:26.334874 2026] [security2:error] [pid 1029697:tid 1029730] [remote 45.138.12.25:37884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6gQgAAAyA"]
[Thu Sep 17 15:29:26.341616 2026] [security2:error] [pid 16723:tid 16938] [client 34.166.113.162:51436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxbti9E0uOV11S2qN6dcQAAANk"]
[Thu Sep 17 15:29:26.367837 2026] [security2:error] [pid 16723:tid 16896] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsi9E0uOV11S2qN6c7QAAAK8"]
[Thu Sep 17 15:29:26.374355 2026] [security2:error] [pid 16723:tid 16925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dHwAAAMw"]
[Thu Sep 17 15:29:26.376719 2026] [security2:error] [pid 16723:tid 16908] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cwQAAALs"]
[Thu Sep 17 15:29:26.381581 2026] [security2:error] [pid 16723:tid 16889] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dIgAAAKg"]
[Thu Sep 17 15:29:26.382133 2026] [security2:error] [pid 16723:tid 16932] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dHgAAANM"]
[Thu Sep 17 15:29:26.385117 2026] [security2:error] [pid 16723:tid 16891] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsS9E0uOV11S2qN6cygAAAKo"]
[Thu Sep 17 15:29:26.385132 2026] [security2:error] [pid 1029697:tid 1029737] [remote 45.138.12.25:37856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbsG65wm-f4uX16X6g4gAAOSc"]
[Thu Sep 17 15:29:26.408809 2026] [security2:error] [pid 16723:tid 16960] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/.env"] [unique_id "aqxbti9E0uOV11S2qN6dcwAAAO8"]
[Thu Sep 17 15:29:26.426728 2026] [security2:error] [pid 1029697:tid 1029842] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsm65wm-f4uX16X6ggwAAAA8"]
[Thu Sep 17 15:29:26.560167 2026] [security2:error] [pid 16723:tid 16901] [client 34.94.35.111:36462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbti9E0uOV11S2qN6ddQAAALQ"]
[Thu Sep 17 15:29:26.653546 2026] [security2:error] [pid 16723:tid 16874] [client 34.154.219.249:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxbti9E0uOV11S2qN6deQAAAJk"]
[Thu Sep 17 15:29:26.836852 2026] [security2:error] [pid 16723:tid 16966] [client 34.94.35.111:34580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbti9E0uOV11S2qN6dfAAAAPU"]
[Thu Sep 17 15:29:27.031875 2026] [security2:error] [pid 16723:tid 16954] [client 34.166.113.162:51452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbty9E0uOV11S2qN6dgAAAAOk"]
[Thu Sep 17 15:29:27.076343 2026] [security2:error] [pid 1029697:tid 1029751] [remote 198.244.226.199:32056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.languageandsociety.co.il"] [uri "/robots.txt"] [unique_id "aqxbt265wm-f4uX16X6hNQAAVDU"]
[Thu Sep 17 15:29:27.076541 2026] [security2:error] [pid 1029697:tid 1029911] [client 198.244.226.199:32056] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.languageandsociety.co.il"] [uri "/robots.txt"] [unique_id "aqxbt265wm-f4uX16X6hNQAAVDU"]
[Thu Sep 17 15:29:27.094204 2026] [security2:error] [pid 16723:tid 16974] [client 139.170.159.113:54708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "couscousdaily.com"] [uri "/.env"] [unique_id "aqxbty9E0uOV11S2qN6dgwAAAP0"]
[Thu Sep 17 15:29:27.120500 2026] [security2:error] [pid 1029697:tid 1029890] [client 34.154.219.249:47198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxbt265wm-f4uX16X6hNwAAAD8"]
[Thu Sep 17 15:29:27.143438 2026] [security2:error] [pid 16723:tid 16892] [client 34.94.35.111:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbty9E0uOV11S2qN6dhQAAAKs"]
[Thu Sep 17 15:29:27.266812 2026] [security2:error] [pid 16723:tid 16864] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dIAAAAI8"]
[Thu Sep 17 15:29:27.267155 2026] [security2:error] [pid 1029697:tid 1029896] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsm65wm-f4uX16X6ghQAAAEU"]
[Thu Sep 17 15:29:27.275001 2026] [security2:error] [pid 1029697:tid 1029765] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbtG65wm-f4uX16X6hOAAAA0M"]
[Thu Sep 17 15:29:27.275881 2026] [security2:error] [pid 1029697:tid 1029709] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/api/phpinfo.php"] [unique_id "aqxbtG65wm-f4uX16X6hOgAAAws"]
[Thu Sep 17 15:29:27.276191 2026] [security2:error] [pid 1029697:tid 1029809] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbtW65wm-f4uX16X6hOwAAA28"]
[Thu Sep 17 15:29:27.277221 2026] [security2:error] [pid 1029697:tid 1029765] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxbtG65wm-f4uX16X6hOQAAA0M"]
[Thu Sep 17 15:29:27.306879 2026] [security2:error] [pid 16723:tid 16902] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dJwAAALU"]
[Thu Sep 17 15:29:27.323066 2026] [security2:error] [pid 16723:tid 16872] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dJAAAAJc"]
[Thu Sep 17 15:29:27.343450 2026] [security2:error] [pid 16723:tid 16873] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dPQAAAJg"]
[Thu Sep 17 15:29:27.347972 2026] [security2:error] [pid 16723:tid 16893] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dNQAAAKw"]
[Thu Sep 17 15:29:27.351131 2026] [security2:error] [pid 1029697:tid 1029894] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbtG65wm-f4uX16X6hAQAAAEM"]
[Thu Sep 17 15:29:27.353264 2026] [security2:error] [pid 1029697:tid 1029925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbtG65wm-f4uX16X6hDwAAAGI"]
[Thu Sep 17 15:29:27.358597 2026] [security2:error] [pid 1029697:tid 1029847] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbtG65wm-f4uX16X6hDQAAABQ"]
[Thu Sep 17 15:29:27.363584 2026] [security2:error] [pid 16723:tid 16926] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbtC9E0uOV11S2qN6dSgAAAM0"]
[Thu Sep 17 15:29:27.368723 2026] [security2:error] [pid 16723:tid 16916] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dKwAAAMM"]
[Thu Sep 17 15:29:27.377935 2026] [security2:error] [pid 16723:tid 16971] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbtC9E0uOV11S2qN6dTAAAAPo"]
[Thu Sep 17 15:29:27.380592 2026] [security2:error] [pid 1029697:tid 1029838] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbs265wm-f4uX16X6g5AAAAAs"]
[Thu Sep 17 15:29:27.384041 2026] [security2:error] [pid 16723:tid 16937] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbsy9E0uOV11S2qN6dMQAAANg"]
[Thu Sep 17 15:29:27.384232 2026] [security2:error] [pid 16723:tid 16875] [client 34.94.35.111:34598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/phpinfo.php~"] [unique_id "aqxbty9E0uOV11S2qN6dkAAAAJo"]
[Thu Sep 17 15:29:27.390558 2026] [security2:error] [pid 1029697:tid 1029799] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/config/mail.php"] [unique_id "aqxbtG65wm-f4uX16X6hQwAAdWU"]
[Thu Sep 17 15:29:27.391595 2026] [security2:error] [pid 1029697:tid 1029799] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/config/config.inc.php"] [unique_id "aqxbtG65wm-f4uX16X6hRAAAdWU"]
[Thu Sep 17 15:29:27.392220 2026] [security2:error] [pid 1029697:tid 1029799] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/config/nexmo.php"] [unique_id "aqxbtG65wm-f4uX16X6hRwAAdWU"]
[Thu Sep 17 15:29:27.406996 2026] [security2:error] [pid 1029697:tid 1029829] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbtG65wm-f4uX16X6hEwAAAAI"]
[Thu Sep 17 15:29:27.412580 2026] [security2:error] [pid 16723:tid 16879] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbtC9E0uOV11S2qN6dTQAAAJ4"]
[Thu Sep 17 15:29:27.415410 2026] [security2:error] [pid 16723:tid 16936] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbtC9E0uOV11S2qN6dSwAAANc"]
[Thu Sep 17 15:29:27.416751 2026] [security2:error] [pid 1029697:tid 1029950] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbtW65wm-f4uX16X6hHwAAAHs"]
[Thu Sep 17 15:29:27.422912 2026] [security2:error] [pid 1029697:tid 1029761] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/wp-config.php"] [unique_id "aqxbtW65wm-f4uX16X6hTAAAdT8"]
[Thu Sep 17 15:29:27.423173 2026] [security2:error] [pid 1029697:tid 1029761] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "allin1.com"] [uri "/wp-config.php.bak"] [unique_id "aqxbtW65wm-f4uX16X6hTQAAdT8"]
[Thu Sep 17 15:29:27.423313 2026] [security2:error] [pid 1029697:tid 1029761] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "allin1.com"] [uri "/wp-config.php.old"] [unique_id "aqxbtW65wm-f4uX16X6hTgAAdT8"]
[Thu Sep 17 15:29:27.423566 2026] [security2:error] [pid 1029697:tid 1029705] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "allin1.com"] [uri "/wp-config.php.new"] [unique_id "aqxbtW65wm-f4uX16X6hUQAAdQc"]
[Thu Sep 17 15:29:27.424003 2026] [security2:error] [pid 1029697:tid 1029705] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxbtW65wm-f4uX16X6hUwAAdQc"]
[Thu Sep 17 15:29:27.427299 2026] [security2:error] [pid 1029697:tid 1029706] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxbtm65wm-f4uX16X6hVQAAdQg"]
[Thu Sep 17 15:29:27.431825 2026] [security2:error] [pid 16723:tid 16880] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbtC9E0uOV11S2qN6dTgAAAJ8"]
[Thu Sep 17 15:29:27.434085 2026] [security2:error] [pid 16723:tid 16883] [client 143.105.152.240:6402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbty9E0uOV11S2qN6dnQAAAKI"]
[Thu Sep 17 15:29:27.434292 2026] [security2:error] [pid 16723:tid 16883] [client 143.105.152.240:6402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbty9E0uOV11S2qN6dnQAAAKI"]
[Thu Sep 17 15:29:27.440785 2026] [security2:error] [pid 16723:tid 16947] [client 223.123.91.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dhgAAAOI"], referer: https://homeworthlv.com/
[Thu Sep 17 15:29:27.479192 2026] [security2:error] [pid 16723:tid 16833] [remote 142.44.220.27:31882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.languageandsociety.co.il"] [uri "/encyclopedia/%D7%A4%D7%95%D7%A0%D7%A7%D7%A6%D7%99%D7%94/"] [unique_id "aqxbty9E0uOV11S2qN6drAABAGw"]
[Thu Sep 17 15:29:27.479312 2026] [security2:error] [pid 16723:tid 16977] [client 142.44.220.27:31882] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.languageandsociety.co.il"] [uri "/encyclopedia/%D7%A4%D7%95%D7%A0%D7%A7%D7%A6%D7%99%D7%94/"] [unique_id "aqxbty9E0uOV11S2qN6drAABAGw"]
[Thu Sep 17 15:29:27.582534 2026] [security2:error] [pid 1029697:tid 1029793] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxbt265wm-f4uX16X6hcAAAdV8"]
[Thu Sep 17 15:29:27.591763 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.154.219.249:47202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxbt265wm-f4uX16X6hcQAAAAE"]
[Thu Sep 17 15:29:27.691737 2026] [security2:error] [pid 1029697:tid 1029902] [client 103.61.184.148:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbt265wm-f4uX16X6hfgAAAEs"]
[Thu Sep 17 15:29:27.692304 2026] [security2:error] [pid 1029697:tid 1029902] [client 103.61.184.148:52122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbt265wm-f4uX16X6hfgAAAEs"]
[Thu Sep 17 15:29:27.788681 2026] [security2:error] [pid 16723:tid 16864] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/.env.bak"] [unique_id "aqxbty9E0uOV11S2qN6dwAAAAI8"]
[Thu Sep 17 15:29:27.855117 2026] [security2:error] [pid 16723:tid 16899] [client 34.94.35.111:34610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/info.php.bak"] [unique_id "aqxbty9E0uOV11S2qN6dxQAAALI"]
[Thu Sep 17 15:29:27.940266 2026] [security2:error] [pid 16723:tid 16966] [client 3.79.134.69:5232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dwgAAAPU"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:29:27.945500 2026] [security2:error] [pid 16723:tid 16934] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/.env.backup"] [unique_id "aqxbty9E0uOV11S2qN6dyAAAANU"]
[Thu Sep 17 15:29:27.992253 2026] [security2:error] [pid 16723:tid 16906] [client 34.166.113.162:51462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/php-info.php"] [unique_id "aqxbty9E0uOV11S2qN6dyQAAALk"]
[Thu Sep 17 15:29:28.022220 2026] [security2:error] [pid 16723:tid 16903] [client 66.248.203.10:20146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dvwAAALY"]
[Thu Sep 17 15:29:28.075897 2026] [security2:error] [pid 16723:tid 16902] [client 34.154.219.249:47208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbuC9E0uOV11S2qN6dzAAAALU"]
[Thu Sep 17 15:29:28.088871 2026] [security2:error] [pid 1029697:tid 1029927] [client 189.113.67.159:56261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbt265wm-f4uX16X6hiAAAZAY"]
[Thu Sep 17 15:29:28.110153 2026] [security2:error] [pid 16723:tid 16873] [client 34.94.35.111:34626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbuC9E0uOV11S2qN6dzwAAAJg"]
[Thu Sep 17 15:29:28.240868 2026] [fcgid:warn] [pid 16723:tid 16885] (70014)End of file found: [client 152.32.205.7:53400] mod_fcgid: can't get data from http client
[Thu Sep 17 15:29:28.297272 2026] [security2:error] [pid 16723:tid 16969] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbti9E0uOV11S2qN6ddAAAAPg"]
[Thu Sep 17 15:29:28.300693 2026] [security2:error] [pid 16723:tid 16971] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/.env.old"] [unique_id "aqxbuC9E0uOV11S2qN6d0QAAAPo"]
[Thu Sep 17 15:29:28.339915 2026] [security2:error] [pid 16723:tid 16882] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6djAAAAKE"]
[Thu Sep 17 15:29:28.418046 2026] [security2:error] [pid 16723:tid 16920] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6diwAAAMc"]
[Thu Sep 17 15:29:28.466618 2026] [security2:error] [pid 16723:tid 16854] [client 34.94.35.111:34636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbuC9E0uOV11S2qN6d1QAAAIU"]
[Thu Sep 17 15:29:28.526180 2026] [security2:error] [pid 16723:tid 16870] [client 3.79.134.69:5240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxbuC9E0uOV11S2qN6d0gAAAJU"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:29:28.573586 2026] [security2:error] [pid 1029697:tid 1029852] [client 34.154.219.249:47212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbuG65wm-f4uX16X6hkgAAABk"]
[Thu Sep 17 15:29:28.697656 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.166.113.162:51476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/phpversion.php"] [unique_id "aqxbuG65wm-f4uX16X6hkwAAAAY"]
[Thu Sep 17 15:29:28.715527 2026] [security2:error] [pid 16723:tid 16856] [client 34.94.35.111:34652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbuC9E0uOV11S2qN6d3QAAAIc"]
[Thu Sep 17 15:29:28.855077 2026] [security2:error] [pid 16723:tid 16911] [client 185.104.184.228:33230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.freeofgravity.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6duAAAAL4"]
[Thu Sep 17 15:29:28.855098 2026] [security2:error] [pid 16723:tid 16911] [client 185.104.184.228:33230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.freeofgravity.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6duAAAAL4"]
[Thu Sep 17 15:29:29.042898 2026] [security2:error] [pid 16723:tid 16947] [client 34.154.219.249:47228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxbuS9E0uOV11S2qN6d4gAAAOI"]
[Thu Sep 17 15:29:29.087706 2026] [security2:error] [pid 16723:tid 16871] [client 34.94.35.111:34666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbuS9E0uOV11S2qN6d5gAAAJY"]
[Thu Sep 17 15:29:29.116680 2026] [security2:error] [pid 16723:tid 16887] [client 114.198.138.124:49513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6AAAAKY"]
[Thu Sep 17 15:29:29.116771 2026] [security2:error] [pid 16723:tid 16887] [client 114.198.138.124:49513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6AAAAKY"]
[Thu Sep 17 15:29:29.151819 2026] [security2:error] [pid 16723:tid 16905] [client 18.188.3.41:62445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6QAAALg"]
[Thu Sep 17 15:29:29.151895 2026] [security2:error] [pid 16723:tid 16905] [client 18.188.3.41:62445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6QAAALg"]
[Thu Sep 17 15:29:29.153381 2026] [security2:error] [pid 16723:tid 16863] [client 18.188.3.41:62449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6gAAAI4"]
[Thu Sep 17 15:29:29.153466 2026] [security2:error] [pid 16723:tid 16863] [client 18.188.3.41:62449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6gAAAI4"]
[Thu Sep 17 15:29:29.157622 2026] [security2:error] [pid 16723:tid 16897] [client 18.188.3.41:62523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6wAAALA"]
[Thu Sep 17 15:29:29.157703 2026] [security2:error] [pid 16723:tid 16897] [client 18.188.3.41:62523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbuS9E0uOV11S2qN6d6wAAALA"]
[Thu Sep 17 15:29:29.271604 2026] [security2:error] [pid 1029697:tid 1029835] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6hagAAAAg"]
[Thu Sep 17 15:29:29.303216 2026] [security2:error] [pid 16723:tid 16940] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dmwAAANs"]
[Thu Sep 17 15:29:29.305841 2026] [security2:error] [pid 16723:tid 16923] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dqgAAAMo"]
[Thu Sep 17 15:29:29.306107 2026] [security2:error] [pid 16723:tid 16892] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dvAAAAKs"]
[Thu Sep 17 15:29:29.309207 2026] [security2:error] [pid 1029697:tid 1029869] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6hYwAAACo"]
[Thu Sep 17 15:29:29.310337 2026] [security2:error] [pid 16723:tid 16925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dogAAAMw"]
[Thu Sep 17 15:29:29.334421 2026] [security2:error] [pid 1029697:tid 1029705] [remote 45.138.12.25:37842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbtW65wm-f4uX16X6hVAAAdQc"]
[Thu Sep 17 15:29:29.383174 2026] [security2:error] [pid 16723:tid 16974] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dvQAAAP0"]
[Thu Sep 17 15:29:29.406915 2026] [security2:error] [pid 1029697:tid 1029916] [client 34.166.113.162:51490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/_phpinfo.php"] [unique_id "aqxbuW65wm-f4uX16X6hqAAAAFk"]
[Thu Sep 17 15:29:29.407330 2026] [security2:error] [pid 16723:tid 16891] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dpgAAAKo"]
[Thu Sep 17 15:29:29.413491 2026] [security2:error] [pid 1029697:tid 1029935] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6hSQAAAGw"]
[Thu Sep 17 15:29:29.428087 2026] [security2:error] [pid 16723:tid 16959] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dmQAAAO4"]
[Thu Sep 17 15:29:29.428580 2026] [security2:error] [pid 16723:tid 16932] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dpwAAANM"]
[Thu Sep 17 15:29:29.434211 2026] [security2:error] [pid 16723:tid 16965] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dqwAAAPQ"]
[Thu Sep 17 15:29:29.441289 2026] [security2:error] [pid 16723:tid 16900] [client 34.94.35.111:34682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbuS9E0uOV11S2qN6d-wAAALM"]
[Thu Sep 17 15:29:29.524713 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.154.219.249:47240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxbuW65wm-f4uX16X6hqwAAADw"]
[Thu Sep 17 15:29:29.852952 2026] [security2:error] [pid 1029697:tid 1029855] [client 34.94.35.111:34690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbuW65wm-f4uX16X6hsgAAABw"]
[Thu Sep 17 15:29:29.989442 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.154.219.249:33410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbuW65wm-f4uX16X6htQAAAFg"]
[Thu Sep 17 15:29:30.081215 2026] [security2:error] [pid 16723:tid 16831] [remote 110.249.202.229:14196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zapatos.chabelo.com"] [uri "/2022/12/02/zapatos-chabelo/"] [unique_id "aqxbui9E0uOV11S2qN6eBQAAh2o"]
[Thu Sep 17 15:29:30.134973 2026] [security2:error] [pid 16723:tid 16865] [client 34.166.113.162:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/old_phpinfo.php"] [unique_id "aqxbui9E0uOV11S2qN6eCAAAAJA"]
[Thu Sep 17 15:29:30.158147 2026] [security2:error] [pid 1029697:tid 1029896] [client 69.165.75.187:50745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.taxcentr.com"] [uri "/index.php"] [unique_id "aqxbum65wm-f4uX16X6hugAAAEU"], referer: https://mail.taxcentr.com
[Thu Sep 17 15:29:30.212858 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.94.35.111:34694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbum65wm-f4uX16X6hvgAAAEM"]
[Thu Sep 17 15:29:30.248562 2026] [security2:error] [pid 1029697:tid 1029914] [client 87.115.188.2:51009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbum65wm-f4uX16X6huQAAVxE"]
[Thu Sep 17 15:29:30.263333 2026] [security2:error] [pid 16723:tid 16952] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dugAAAOc"]
[Thu Sep 17 15:29:30.289571 2026] [security2:error] [pid 16723:tid 16919] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dqQAAAMY"]
[Thu Sep 17 15:29:30.303943 2026] [security2:error] [pid 1029697:tid 1029888] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6hfAAAAD0"]
[Thu Sep 17 15:29:30.306804 2026] [security2:error] [pid 1029697:tid 1029942] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6haQAAAHM"]
[Thu Sep 17 15:29:30.322772 2026] [security2:error] [pid 1029697:tid 1029885] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6hfQAAADo"]
[Thu Sep 17 15:29:30.327081 2026] [security2:error] [pid 16723:tid 16894] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dqAAAAK0"]
[Thu Sep 17 15:29:30.342537 2026] [security2:error] [pid 16723:tid 16908] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dowAAALs"]
[Thu Sep 17 15:29:30.342794 2026] [security2:error] [pid 16723:tid 16967] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6duwAAAPY"]
[Thu Sep 17 15:29:30.348373 2026] [security2:error] [pid 16723:tid 16953] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6duQAAAOg"]
[Thu Sep 17 15:29:30.357846 2026] [security2:error] [pid 1029697:tid 1029913] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6hawAAAFY"]
[Thu Sep 17 15:29:30.360583 2026] [security2:error] [pid 16723:tid 16878] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dxgAAAJ0"]
[Thu Sep 17 15:29:30.361265 2026] [security2:error] [pid 16723:tid 16858] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dwwAAAIk"]
[Thu Sep 17 15:29:30.371434 2026] [security2:error] [pid 1029697:tid 1029808] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "relvnv.com"] [uri "/job/.env"] [unique_id "aqxbt265wm-f4uX16X6hygAAFW4"]
[Thu Sep 17 15:29:30.378576 2026] [security2:error] [pid 16723:tid 16889] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dpQAAAKg"]
[Thu Sep 17 15:29:30.416118 2026] [security2:error] [pid 16723:tid 16922] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbuC9E0uOV11S2qN6d1wAAAMk"]
[Thu Sep 17 15:29:30.432876 2026] [security2:error] [pid 1029697:tid 1029889] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuW65wm-f4uX16X6hpAAAAD4"]
[Thu Sep 17 15:29:30.443866 2026] [security2:error] [pid 1029697:tid 1029920] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuW65wm-f4uX16X6howAAAF0"]
[Thu Sep 17 15:29:30.444172 2026] [security2:error] [pid 16723:tid 16972] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbty9E0uOV11S2qN6dxwAAAPs"]
[Thu Sep 17 15:29:30.463033 2026] [security2:error] [pid 1029697:tid 1029888] [client 34.154.219.249:33412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbum65wm-f4uX16X6h0wAAAD0"]
[Thu Sep 17 15:29:30.588958 2026] [security2:error] [pid 16723:tid 16928] [client 34.94.35.111:34706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbui9E0uOV11S2qN6eHQAAAM8"]
[Thu Sep 17 15:29:30.788368 2026] [security2:error] [pid 16723:tid 16910] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/.env.swp"] [unique_id "aqxbui9E0uOV11S2qN6eJwAAAL0"]
[Thu Sep 17 15:29:30.825636 2026] [security2:error] [pid 16723:tid 16945] [client 34.166.113.162:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/server-info.php"] [unique_id "aqxbui9E0uOV11S2qN6eKAAAAOA"]
[Thu Sep 17 15:29:30.845852 2026] [security2:error] [pid 1029697:tid 1029943] [client 34.94.35.111:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbum65wm-f4uX16X6h5gAAAHQ"]
[Thu Sep 17 15:29:30.925172 2026] [security2:error] [pid 1029697:tid 1029862] [client 18.188.3.41:64232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbum65wm-f4uX16X6h5wAAACM"]
[Thu Sep 17 15:29:30.925274 2026] [security2:error] [pid 1029697:tid 1029862] [client 18.188.3.41:64232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbum65wm-f4uX16X6h5wAAACM"]
[Thu Sep 17 15:29:30.937535 2026] [security2:error] [pid 16723:tid 16869] [client 18.188.3.41:64248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbui9E0uOV11S2qN6eKgAAAJQ"]
[Thu Sep 17 15:29:30.937623 2026] [security2:error] [pid 16723:tid 16869] [client 18.188.3.41:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tazbodywork.com"] [uri "/wp/xmlrpc.php"] [unique_id "aqxbui9E0uOV11S2qN6eKgAAAJQ"]
[Thu Sep 17 15:29:30.937933 2026] [security2:error] [pid 16723:tid 16965] [client 34.154.219.249:33428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxbui9E0uOV11S2qN6eKQAAAPQ"]
[Thu Sep 17 15:29:30.945414 2026] [security2:error] [pid 16723:tid 16981] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/.env~"] [unique_id "aqxbui9E0uOV11S2qN6eKwAAAQQ"]
[Thu Sep 17 15:29:31.305434 2026] [security2:error] [pid 16723:tid 16902] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuS9E0uOV11S2qN6d9QAAALU"]
[Thu Sep 17 15:29:31.308756 2026] [security2:error] [pid 16723:tid 16893] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuS9E0uOV11S2qN6d9gAAAKw"]
[Thu Sep 17 15:29:31.311862 2026] [security2:error] [pid 16723:tid 16873] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuS9E0uOV11S2qN6d9wAAAJg"]
[Thu Sep 17 15:29:31.322240 2026] [security2:error] [pid 1029697:tid 1029875] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbt265wm-f4uX16X6hhwAAADA"]
[Thu Sep 17 15:29:31.322819 2026] [security2:error] [pid 16723:tid 16850] [remote 45.157.54.43:35451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-75fc8138.newyearworks.com"] [uri "/xmlrpc.php"] [unique_id "aqxbuy9E0uOV11S2qN6eRQAAl30"]
[Thu Sep 17 15:29:31.323199 2026] [security2:error] [pid 16723:tid 16872] [client 45.157.54.43:35451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-75fc8138.newyearworks.com"] [uri "/xmlrpc.php"] [unique_id "aqxbuy9E0uOV11S2qN6eRQAAl30"]
[Thu Sep 17 15:29:31.339782 2026] [security2:error] [pid 1029697:tid 1029934] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuW65wm-f4uX16X6hpQAAAGs"]
[Thu Sep 17 15:29:31.339933 2026] [security2:error] [pid 1029697:tid 1029844] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuW65wm-f4uX16X6hpgAAABE"]
[Thu Sep 17 15:29:31.339932 2026] [security2:error] [pid 16723:tid 16875] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbuS9E0uOV11S2qN6d_AAAAJo"]
[Thu Sep 17 15:29:31.349674 2026] [security2:error] [pid 16723:tid 16962] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuC9E0uOV11S2qN6d0wAAAPE"]
[Thu Sep 17 15:29:31.350238 2026] [security2:error] [pid 16723:tid 16968] [client 34.94.35.111:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbuy9E0uOV11S2qN6eRwAAAPc"]
[Thu Sep 17 15:29:31.362799 2026] [security2:error] [pid 16723:tid 16935] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbuS9E0uOV11S2qN6d_QAAANY"]
[Thu Sep 17 15:29:31.367524 2026] [security2:error] [pid 16723:tid 16802] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxbuC9E0uOV11S2qN6eSAAAqU0"]
[Thu Sep 17 15:29:31.368006 2026] [security2:error] [pid 16723:tid 16802] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/api/phpinfo.php"] [unique_id "aqxbuC9E0uOV11S2qN6eSQAAqU0"]
[Thu Sep 17 15:29:31.368036 2026] [security2:error] [pid 16723:tid 16845] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbuS9E0uOV11S2qN6eSgAAqXg"]
[Thu Sep 17 15:29:31.402574 2026] [security2:error] [pid 1029697:tid 1029937] [client 34.154.219.249:33434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ceh.cxi.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxbu265wm-f4uX16X6iAQAAAG4"]
[Thu Sep 17 15:29:31.506660 2026] [security2:error] [pid 1029697:tid 1029918] [client 34.166.113.162:51518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/server-status.php"] [unique_id "aqxbu265wm-f4uX16X6iBQAAAFs"]
[Thu Sep 17 15:29:31.591133 2026] [security2:error] [pid 16723:tid 16924] [client 193.36.224.151:48177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/000.php"] [unique_id "aqxbuy9E0uOV11S2qN6eXQAAAMs"]
[Thu Sep 17 15:29:31.825092 2026] [security2:error] [pid 1029697:tid 1029932] [client 193.36.224.220:55621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/about.php"] [unique_id "aqxbu265wm-f4uX16X6iDAAAAGk"]
[Thu Sep 17 15:29:31.862241 2026] [security2:error] [pid 16723:tid 16945] [client 34.94.35.111:34736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbuy9E0uOV11S2qN6edgAAAOA"]
[Thu Sep 17 15:29:32.027189 2026] [security2:error] [pid 16723:tid 16955] [client 136.158.61.34:36760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbvC9E0uOV11S2qN6egwAAAOo"]
[Thu Sep 17 15:29:32.027268 2026] [security2:error] [pid 16723:tid 16955] [client 136.158.61.34:36760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbvC9E0uOV11S2qN6egwAAAOo"]
[Thu Sep 17 15:29:32.052081 2026] [security2:error] [pid 16723:tid 16909] [client 193.36.224.219:44017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxbvC9E0uOV11S2qN6eiAAAALw"]
[Thu Sep 17 15:29:32.277964 2026] [security2:error] [pid 16723:tid 16915] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6ePAAAAMI"]
[Thu Sep 17 15:29:32.284812 2026] [security2:error] [pid 16723:tid 16975] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eLgAAAP4"]
[Thu Sep 17 15:29:32.292551 2026] [security2:error] [pid 16723:tid 16902] [client 34.94.35.111:34750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbvC9E0uOV11S2qN6enAAAALU"]
[Thu Sep 17 15:29:32.297441 2026] [security2:error] [pid 16723:tid 16894] [client 104.234.19.144:36769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxbvC9E0uOV11S2qN6enQAAAK0"]
[Thu Sep 17 15:29:32.307614 2026] [security2:error] [pid 16723:tid 16938] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eFgAAANk"]
[Thu Sep 17 15:29:32.309577 2026] [security2:error] [pid 16723:tid 16856] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eMwAAAIc"]
[Thu Sep 17 15:29:32.330745 2026] [security2:error] [pid 1029697:tid 1029726] [remote 45.138.12.25:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "relvnv.com"] [uri "/index_dev.php"] [unique_id "aqxbuW65wm-f4uX16X6iGAAAFRw"]
[Thu Sep 17 15:29:32.344861 2026] [security2:error] [pid 1029697:tid 1029927] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbum65wm-f4uX16X6h3QAAAGQ"]
[Thu Sep 17 15:29:32.349176 2026] [security2:error] [pid 1029697:tid 1029828] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbum65wm-f4uX16X6h0gAAAAE"]
[Thu Sep 17 15:29:32.363155 2026] [security2:error] [pid 16723:tid 16978] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eIwAAAQE"]
[Thu Sep 17 15:29:32.364700 2026] [security2:error] [pid 1029697:tid 1029870] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbu265wm-f4uX16X6h9AAAACs"]
[Thu Sep 17 15:29:32.365963 2026] [security2:error] [pid 16723:tid 16867] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eQgAAAJI"]
[Thu Sep 17 15:29:32.366038 2026] [security2:error] [pid 16723:tid 16980] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eIQAAAQM"]
[Thu Sep 17 15:29:32.368372 2026] [security2:error] [pid 16723:tid 16930] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eEwAAANE"]
[Thu Sep 17 15:29:32.380820 2026] [security2:error] [pid 16723:tid 16957] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eGgAAAOw"]
[Thu Sep 17 15:29:32.405049 2026] [security2:error] [pid 16723:tid 16885] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eIgAAAKQ"]
[Thu Sep 17 15:29:32.408718 2026] [security2:error] [pid 16723:tid 16891] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eJAAAAKo"]
[Thu Sep 17 15:29:32.418360 2026] [security2:error] [pid 1029697:tid 1029901] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbu265wm-f4uX16X6h9QAAAEo"]
[Thu Sep 17 15:29:32.419454 2026] [security2:error] [pid 16723:tid 16954] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eFAAAAOk"]
[Thu Sep 17 15:29:32.450996 2026] [security2:error] [pid 16723:tid 16940] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbui9E0uOV11S2qN6eFwAAANs"]
[Thu Sep 17 15:29:32.529086 2026] [security2:error] [pid 1029697:tid 1029854] [client 193.36.224.219:63633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxbvG65wm-f4uX16X6iLgAAABs"]
[Thu Sep 17 15:29:32.587495 2026] [security2:error] [pid 16723:tid 16880] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/app/.env"] [unique_id "aqxbvC9E0uOV11S2qN6eyQAAAJ8"]
[Thu Sep 17 15:29:32.674321 2026] [security2:error] [pid 16723:tid 16917] [client 34.166.113.162:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxbvC9E0uOV11S2qN6eygAAAMQ"]
[Thu Sep 17 15:29:32.687514 2026] [security2:error] [pid 16723:tid 16963] [client 34.94.35.111:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbvC9E0uOV11S2qN6ezAAAAPI"]
[Thu Sep 17 15:29:32.742803 2026] [security2:error] [pid 16723:tid 16909] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/apps/.env"] [unique_id "aqxbvC9E0uOV11S2qN6e0gAAALw"]
[Thu Sep 17 15:29:32.759900 2026] [security2:error] [pid 16723:tid 16872] [client 216.24.219.21:57431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxbvC9E0uOV11S2qN6e1QAAAJc"]
[Thu Sep 17 15:29:32.773234 2026] [security2:error] [pid 16723:tid 16879] [client 18.188.3.41:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxbvC9E0uOV11S2qN6e1wAAAJ4"]
[Thu Sep 17 15:29:32.777739 2026] [core:error] [pid 16723:tid 16899] [client 152.32.201.247:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:32.777756 2026] [core:error] [pid 16723:tid 16899] [client 152.32.201.247:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:32.898875 2026] [security2:error] [pid 16723:tid 16949] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/api/.env"] [unique_id "aqxbvC9E0uOV11S2qN6e2wAAAOQ"]
[Thu Sep 17 15:29:32.918090 2026] [security2:error] [pid 16723:tid 16874] [client 34.94.35.111:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbvC9E0uOV11S2qN6e3QAAAJk"]
[Thu Sep 17 15:29:32.986632 2026] [security2:error] [pid 16723:tid 16975] [client 104.234.19.144:60315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/bless.php"] [unique_id "aqxbvC9E0uOV11S2qN6e4QAAAP4"]
[Thu Sep 17 15:29:33.062307 2026] [security2:error] [pid 16723:tid 16902] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/web/.env"] [unique_id "aqxbvS9E0uOV11S2qN6e5AAAALU"]
[Thu Sep 17 15:29:33.135323 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.94.35.111:34786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ivorygarlock.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbvW65wm-f4uX16X6iRgAAAEc"]
[Thu Sep 17 15:29:33.210624 2026] [security2:error] [pid 16723:tid 16920] [client 216.24.219.103:31841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/goods.php"] [unique_id "aqxbvS9E0uOV11S2qN6e6QAAAMc"]
[Thu Sep 17 15:29:33.219561 2026] [security2:error] [pid 16723:tid 16953] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/site/.env"] [unique_id "aqxbvS9E0uOV11S2qN6e6gAAAOg"]
[Thu Sep 17 15:29:33.264759 2026] [security2:error] [pid 1029697:tid 1029837] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbum65wm-f4uX16X6h0QAAAAo"]
[Thu Sep 17 15:29:33.277291 2026] [security2:error] [pid 16723:tid 16907] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eVgAAALo"]
[Thu Sep 17 15:29:33.298502 2026] [security2:error] [pid 16723:tid 16862] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eWAAAAI0"]
[Thu Sep 17 15:29:33.321174 2026] [security2:error] [pid 1029697:tid 1029748] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/wp/.env"] [unique_id "aqxbum65wm-f4uX16X6iSQAAAzI"]
[Thu Sep 17 15:29:33.326096 2026] [security2:error] [pid 16723:tid 16958] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eVQAAAO0"]
[Thu Sep 17 15:29:33.343683 2026] [security2:error] [pid 16723:tid 16961] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eVwAAAPA"]
[Thu Sep 17 15:29:33.345792 2026] [security2:error] [pid 16723:tid 16922] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eWQAAAMk"]
[Thu Sep 17 15:29:33.346858 2026] [security2:error] [pid 16723:tid 16860] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbuy9E0uOV11S2qN6eUwAAAIs"]
[Thu Sep 17 15:29:33.352271 2026] [security2:error] [pid 1029697:tid 1029708] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/php.php"] [unique_id "aqxbum65wm-f4uX16X6iSwAAOQo"]
[Thu Sep 17 15:29:33.352365 2026] [security2:error] [pid 1029697:tid 1029938] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbu265wm-f4uX16X6iAwAAAG8"]
[Thu Sep 17 15:29:33.353192 2026] [security2:error] [pid 1029697:tid 1029708] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/php-info.php"] [unique_id "aqxbum65wm-f4uX16X6iTQAAOQo"]
[Thu Sep 17 15:29:33.354099 2026] [security2:error] [pid 1029697:tid 1029806] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxbum65wm-f4uX16X6iTwAAOWw"]
[Thu Sep 17 15:29:33.354585 2026] [security2:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/infophp.php"] [unique_id "aqxbum65wm-f4uX16X6iUAAAOU4"]
[Thu Sep 17 15:29:33.355196 2026] [security2:error] [pid 1029697:tid 1029729] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbum65wm-f4uX16X6iUQAAOR8"]
[Thu Sep 17 15:29:33.355630 2026] [security2:error] [pid 1029697:tid 1029714] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/api/phpinfo.php"] [unique_id "aqxbvG65wm-f4uX16X6iUwAAORA"]
[Thu Sep 17 15:29:33.355722 2026] [security2:error] [pid 1029697:tid 1029806] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbvG65wm-f4uX16X6iVAAAOWw"]
[Thu Sep 17 15:29:33.356095 2026] [security2:error] [pid 1029697:tid 1029764] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxbu265wm-f4uX16X6iUgAAOUI"]
[Thu Sep 17 15:29:33.359204 2026] [security2:error] [pid 16723:tid 16923] [client 34.166.113.162:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxbvS9E0uOV11S2qN6e8QAAAMo"]
[Thu Sep 17 15:29:33.382609 2026] [security2:error] [pid 16723:tid 16919] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/public/.env"] [unique_id "aqxbvS9E0uOV11S2qN6e9QAAAMY"]
[Thu Sep 17 15:29:33.437316 2026] [security2:error] [pid 16723:tid 16926] [client 193.36.224.113:51121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/blurbs.php"] [unique_id "aqxbvS9E0uOV11S2qN6e_AAAAM0"]
[Thu Sep 17 15:29:33.469128 2026] [security2:error] [pid 1029697:tid 1029952] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iKwAAAH0"]
[Thu Sep 17 15:29:33.474363 2026] [security2:error] [pid 16723:tid 16924] [client 185.55.149.49:49956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbvS9E0uOV11S2qN6e_QAAAMs"]
[Thu Sep 17 15:29:33.474541 2026] [security2:error] [pid 16723:tid 16924] [client 185.55.149.49:49956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbvS9E0uOV11S2qN6e_QAAAMs"]
[Thu Sep 17 15:29:33.478163 2026] [security2:error] [pid 1029697:tid 1029782] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/phpinfo.php"] [unique_id "aqxbvG65wm-f4uX16X6iaAAAdVQ"]
[Thu Sep 17 15:29:33.495790 2026] [security2:error] [pid 1029697:tid 1029939] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iIwAAAHA"]
[Thu Sep 17 15:29:33.680197 2026] [security2:error] [pid 16723:tid 16861] [client 104.234.19.150:63095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxbvS9E0uOV11S2qN6fCQAAAIw"]
[Thu Sep 17 15:29:33.746997 2026] [security2:error] [pid 16723:tid 16895] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/backend/.env"] [unique_id "aqxbvS9E0uOV11S2qN6fCwAAAK4"]
[Thu Sep 17 15:29:33.907077 2026] [security2:error] [pid 16723:tid 16948] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/server/.env"] [unique_id "aqxbvS9E0uOV11S2qN6fDwAAAOM"]
[Thu Sep 17 15:29:33.911242 2026] [security2:error] [pid 16723:tid 16859] [client 193.36.224.156:29293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/abcd.php"] [unique_id "aqxbvS9E0uOV11S2qN6fEAAAAIo"]
[Thu Sep 17 15:29:34.070759 2026] [security2:error] [pid 16723:tid 16893] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/frontend/.env"] [unique_id "aqxbvi9E0uOV11S2qN6fGQAAAKw"]
[Thu Sep 17 15:29:34.151495 2026] [security2:error] [pid 16723:tid 16880] [client 34.166.113.162:50526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxbvi9E0uOV11S2qN6fHgAAAJ8"]
[Thu Sep 17 15:29:34.192868 2026] [security2:error] [pid 16723:tid 16863] [client 216.24.219.103:63985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxbvi9E0uOV11S2qN6fHAAAAI4"]
[Thu Sep 17 15:29:34.226343 2026] [security2:error] [pid 16723:tid 16975] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/src/.env"] [unique_id "aqxbvi9E0uOV11S2qN6fIwAAAP4"]
[Thu Sep 17 15:29:34.280767 2026] [security2:error] [pid 16723:tid 16965] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbvC9E0uOV11S2qN6eugAAAPQ"]
[Thu Sep 17 15:29:34.292429 2026] [security2:error] [pid 1029697:tid 1029925] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iLAAAAGI"]
[Thu Sep 17 15:29:34.294023 2026] [security2:error] [pid 1029697:tid 1029863] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iLQAAACQ"]
[Thu Sep 17 15:29:34.299854 2026] [security2:error] [pid 1029697:tid 1029739] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/info.php"] [unique_id "aqxbvG65wm-f4uX16X6idQAAdSk"]
[Thu Sep 17 15:29:34.300638 2026] [security2:error] [pid 1029697:tid 1029739] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/infos.php"] [unique_id "aqxbvG65wm-f4uX16X6idgAAdSk"]
[Thu Sep 17 15:29:34.301451 2026] [security2:error] [pid 1029697:tid 1029739] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/php_info.php"] [unique_id "aqxbvG65wm-f4uX16X6idwAAdSk"]
[Thu Sep 17 15:29:34.302526 2026] [security2:error] [pid 1029697:tid 1029750] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/php-info.php"] [unique_id "aqxbvG65wm-f4uX16X6ieAAAdTQ"]
[Thu Sep 17 15:29:34.302606 2026] [security2:error] [pid 1029697:tid 1029813] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/infophp.php"] [unique_id "aqxbvG65wm-f4uX16X6iewAAdXM"]
[Thu Sep 17 15:29:34.302656 2026] [security2:error] [pid 1029697:tid 1029787] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxbvW65wm-f4uX16X6ieQAAdVk"]
[Thu Sep 17 15:29:34.303239 2026] [security2:error] [pid 1029697:tid 1029739] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/php.php"] [unique_id "aqxbvG65wm-f4uX16X6ifAAAdSk"]
[Thu Sep 17 15:29:34.310760 2026] [security2:error] [pid 1029697:tid 1029765] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "edmagiktv.com"] [uri "/index_dev.php"] [unique_id "aqxbu265wm-f4uX16X6igAAAA0M"]
[Thu Sep 17 15:29:34.326197 2026] [security2:error] [pid 1029697:tid 1029933] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iNwAAAGo"]
[Thu Sep 17 15:29:34.338623 2026] [security2:error] [pid 1029697:tid 1029851] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iOQAAABg"]
[Thu Sep 17 15:29:34.340957 2026] [security2:error] [pid 1029697:tid 1029948] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iOAAAAHk"]
[Thu Sep 17 15:29:34.357023 2026] [security2:error] [pid 1029697:tid 1029942] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iIQAAAHM"]
[Thu Sep 17 15:29:34.386406 2026] [security2:error] [pid 16723:tid 16907] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/core/.env"] [unique_id "aqxbvi9E0uOV11S2qN6fKgAAALo"]
[Thu Sep 17 15:29:34.400107 2026] [security2:error] [pid 16723:tid 16944] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvC9E0uOV11S2qN6evwAAAN8"]
[Thu Sep 17 15:29:34.414514 2026] [security2:error] [pid 16723:tid 16957] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvS9E0uOV11S2qN6e9wAAAOw"]
[Thu Sep 17 15:29:34.458239 2026] [security2:error] [pid 16723:tid 16886] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvC9E0uOV11S2qN6e0QAAAKU"]
[Thu Sep 17 15:29:34.559223 2026] [security2:error] [pid 16723:tid 16876] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/core/app/.env"] [unique_id "aqxbvi9E0uOV11S2qN6fMAAAAJs"]
[Thu Sep 17 15:29:34.718882 2026] [security2:error] [pid 16723:tid 16884] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/config/.env"] [unique_id "aqxbvi9E0uOV11S2qN6fOAAAAKM"]
[Thu Sep 17 15:29:34.747050 2026] [security2:error] [pid 1029697:tid 1029736] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/public/phpinfo.php"] [unique_id "aqxbvm65wm-f4uX16X6ikAAAdSY"]
[Thu Sep 17 15:29:34.747129 2026] [security2:error] [pid 1029697:tid 1029746] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxbvm65wm-f4uX16X6ikQAAdTA"]
[Thu Sep 17 15:29:34.747162 2026] [security2:error] [pid 1029697:tid 1029703] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxbvm65wm-f4uX16X6ikgAAdQU"]
[Thu Sep 17 15:29:34.747212 2026] [security2:error] [pid 1029697:tid 1029772] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/api/phpinfo.php"] [unique_id "aqxbvm65wm-f4uX16X6ijwAAdUo"]
[Thu Sep 17 15:29:34.748437 2026] [security2:error] [pid 1029697:tid 1029824] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/database.sql"] [unique_id "aqxbvm65wm-f4uX16X6imwAAdX4"]
[Thu Sep 17 15:29:34.790562 2026] [authz_core:error] [pid 16723:tid 16915] [client 4.240.114.86:54721] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:29:34.821183 2026] [security2:error] [pid 16723:tid 16854] [client 193.36.224.116:63701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/dex.php"] [unique_id "aqxbvi9E0uOV11S2qN6fSAAAAIU"]
[Thu Sep 17 15:29:34.843271 2026] [security2:error] [pid 1029697:tid 1029874] [client 34.166.113.162:50538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxbvm65wm-f4uX16X6ipAAAAC8"]
[Thu Sep 17 15:29:34.881928 2026] [security2:error] [pid 16723:tid 16877] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/private/.env"] [unique_id "aqxbvi9E0uOV11S2qN6fSwAAAJw"]
[Thu Sep 17 15:29:35.038647 2026] [core:error] [pid 1029697:tid 1029859] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:35.038676 2026] [core:error] [pid 1029697:tid 1029859] [client 34.94.35.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:35.039855 2026] [security2:error] [pid 1029697:tid 1029924] [client 139.59.114.163:39316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxbvG65wm-f4uX16X6iOwAAYWM"], referer: http://mail.jwdnyc.com/wp/
[Thu Sep 17 15:29:35.040309 2026] [security2:error] [pid 16723:tid 16908] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/application/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fUwAAALs"]
[Thu Sep 17 15:29:35.176367 2026] [security2:error] [pid 16723:tid 16878] [client 104.234.19.146:62523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxbvy9E0uOV11S2qN6fXgAAAJ0"]
[Thu Sep 17 15:29:35.197989 2026] [security2:error] [pid 16723:tid 16968] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/bootstrap/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fXwAAAPc"]
[Thu Sep 17 15:29:35.274513 2026] [security2:error] [pid 1029697:tid 1029935] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvW65wm-f4uX16X6iYwAAAGw"]
[Thu Sep 17 15:29:35.280022 2026] [security2:error] [pid 1029697:tid 1029748] [remote 45.138.12.25:37884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbum65wm-f4uX16X6iSgAAAzI"]
[Thu Sep 17 15:29:35.281582 2026] [security2:error] [pid 1029697:tid 1029879] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvW65wm-f4uX16X6iZQAAADQ"]
[Thu Sep 17 15:29:35.286891 2026] [security2:error] [pid 1029697:tid 1029748] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "edmagiktv.com"] [uri "/wp-config.php~"] [unique_id "aqxbvG65wm-f4uX16X6itQAAAzI"]
[Thu Sep 17 15:29:35.288564 2026] [security2:error] [pid 1029697:tid 1029751] [remote 45.138.12.25:37884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edmagiktv.com"] [uri "/2021/.env"] [unique_id "aqxbvG65wm-f4uX16X6itgAAAzU"]
[Thu Sep 17 15:29:35.289470 2026] [security2:error] [pid 1029697:tid 1029931] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbvW65wm-f4uX16X6iYgAAAGg"]
[Thu Sep 17 15:29:35.301567 2026] [security2:error] [pid 16723:tid 16858] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvS9E0uOV11S2qN6e-QAAAIk"]
[Thu Sep 17 15:29:35.304292 2026] [security2:error] [pid 16723:tid 16930] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbvS9E0uOV11S2qN6e7gAAANE"]
[Thu Sep 17 15:29:35.313187 2026] [security2:error] [pid 1029697:tid 1029936] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvW65wm-f4uX16X6iZAAAAG0"]
[Thu Sep 17 15:29:35.339055 2026] [security2:error] [pid 1029697:tid 1029709] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/database.sql"] [unique_id "aqxbvW65wm-f4uX16X6iwwAAOQs"]
[Thu Sep 17 15:29:35.358000 2026] [security2:error] [pid 16723:tid 16907] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/database/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fZwAAALo"]
[Thu Sep 17 15:29:35.363805 2026] [security2:error] [pid 16723:tid 16888] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvS9E0uOV11S2qN6e-gAAAKc"]
[Thu Sep 17 15:29:35.372436 2026] [security2:error] [pid 16723:tid 16868] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvS9E0uOV11S2qN6e-AAAAJM"]
[Thu Sep 17 15:29:35.401973 2026] [security2:error] [pid 16723:tid 16951] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbvi9E0uOV11S2qN6fJwAAAOY"]
[Thu Sep 17 15:29:35.465945 2026] [security2:error] [pid 1029697:tid 1029894] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbvm65wm-f4uX16X6ihQAAAEM"]
[Thu Sep 17 15:29:35.523597 2026] [security2:error] [pid 16723:tid 16871] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/storage/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fcQAAAJY"]
[Thu Sep 17 15:29:35.542288 2026] [security2:error] [pid 16723:tid 16902] [client 34.166.113.162:50542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxbvy9E0uOV11S2qN6fdAAAALU"]
[Thu Sep 17 15:29:35.579855 2026] [security2:error] [pid 1029697:tid 1029845] [client 139.59.114.163:39316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i4AAAEkw"], referer: http://mail.jwdnyc.com/old/
[Thu Sep 17 15:29:35.680565 2026] [security2:error] [pid 16723:tid 16963] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/var/www/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fewAAAPI"]
[Thu Sep 17 15:29:35.843356 2026] [security2:error] [pid 16723:tid 16950] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/var/www/html/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fggAAAOU"]
[Thu Sep 17 15:29:35.905533 2026] [security2:error] [pid 16723:tid 16887] [client 193.36.224.152:29469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6fgwAAAKY"]
[Thu Sep 17 15:29:35.997824 2026] [security2:error] [pid 16723:tid 16859] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/current/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fhAAAAIo"]
[Thu Sep 17 15:29:36.152390 2026] [security2:error] [pid 16723:tid 16893] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/release/.env"] [unique_id "aqxbwC9E0uOV11S2qN6fhQAAAKw"]
[Thu Sep 17 15:29:36.235116 2026] [security2:error] [pid 16723:tid 16909] [client 34.166.113.162:50552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxbwC9E0uOV11S2qN6fiAAAALw"]
[Thu Sep 17 15:29:36.269930 2026] [security2:error] [pid 16723:tid 16964] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvS9E0uOV11S2qN6fCAAAAPM"]
[Thu Sep 17 15:29:36.269930 2026] [security2:error] [pid 16723:tid 16861] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvi9E0uOV11S2qN6fQwAAAIw"]
[Thu Sep 17 15:29:36.271462 2026] [security2:error] [pid 1029697:tid 1029928] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvm65wm-f4uX16X6ihgAAAGU"]
[Thu Sep 17 15:29:36.289349 2026] [security2:error] [pid 16723:tid 16954] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbvS9E0uOV11S2qN6fBAAAAOk"]
[Thu Sep 17 15:29:36.306971 2026] [security2:error] [pid 16723:tid 16969] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/releases/.env"] [unique_id "aqxbwC9E0uOV11S2qN6figAAAPg"]
[Thu Sep 17 15:29:36.377990 2026] [security2:error] [pid 1029697:tid 1029866] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6isgAAACc"]
[Thu Sep 17 15:29:36.403947 2026] [security2:error] [pid 16723:tid 16862] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "relvnv.com"] [uri "/index.php"] [unique_id "aqxbvi9E0uOV11S2qN6fKwAAAI0"]
[Thu Sep 17 15:29:36.404573 2026] [security2:error] [pid 1029697:tid 1029899] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i0wAAAEg"]
[Thu Sep 17 15:29:36.412563 2026] [security2:error] [pid 16723:tid 16920] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbvi9E0uOV11S2qN6fKAAAAMc"]
[Thu Sep 17 15:29:36.413695 2026] [security2:error] [pid 1029697:tid 1029913] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvm65wm-f4uX16X6ingAAAFY"]
[Thu Sep 17 15:29:36.417680 2026] [security2:error] [pid 16723:tid 16945] [client 193.36.224.116:38821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/index.php"] [unique_id "aqxbwC9E0uOV11S2qN6fiwAAAOA"]
[Thu Sep 17 15:29:36.443407 2026] [security2:error] [pid 1029697:tid 1029946] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvm65wm-f4uX16X6inwAAAHc"]
[Thu Sep 17 15:29:36.447010 2026] [security2:error] [pid 16723:tid 16929] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6fWgAAANA"]
[Thu Sep 17 15:29:36.448497 2026] [security2:error] [pid 1029697:tid 1029952] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i0QAAAH0"]
[Thu Sep 17 15:29:36.463152 2026] [security2:error] [pid 16723:tid 16913] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/shared/.env"] [unique_id "aqxbwC9E0uOV11S2qN6fjAAAAMA"]
[Thu Sep 17 15:29:36.617845 2026] [security2:error] [pid 16723:tid 16978] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/deploy/.env"] [unique_id "aqxbwC9E0uOV11S2qN6fkAAAAQE"]
[Thu Sep 17 15:29:36.714099 2026] [security2:error] [pid 1029697:tid 1029895] [client 216.24.219.19:26199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxbwG65wm-f4uX16X6i9QAAAEQ"]
[Thu Sep 17 15:29:36.762457 2026] [security2:error] [pid 1029697:tid 1029745] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/job/.env"] [unique_id "aqxbwG65wm-f4uX16X6i9gAAdS8"]
[Thu Sep 17 15:29:36.776301 2026] [security2:error] [pid 16723:tid 16980] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/build/.env"] [unique_id "aqxbwC9E0uOV11S2qN6flAAAAQM"]
[Thu Sep 17 15:29:36.923051 2026] [security2:error] [pid 16723:tid 16925] [client 34.166.113.162:50554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxbwC9E0uOV11S2qN6fnAAAAMw"]
[Thu Sep 17 15:29:36.934437 2026] [security2:error] [pid 16723:tid 16860] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/dist/.env"] [unique_id "aqxbwC9E0uOV11S2qN6fnQAAAIs"]
[Thu Sep 17 15:29:37.107065 2026] [security2:error] [pid 16723:tid 16931] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/public_html/.env"] [unique_id "aqxbwS9E0uOV11S2qN6fpgAAANI"]
[Thu Sep 17 15:29:37.246906 2026] [security2:error] [pid 16723:tid 16881] [client 104.234.19.143:23525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/index.php"] [unique_id "aqxbwS9E0uOV11S2qN6fqwAAAKA"]
[Thu Sep 17 15:29:37.256953 2026] [security2:error] [pid 16723:tid 16952] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6fZgAAAOc"]
[Thu Sep 17 15:29:37.257674 2026] [security2:error] [pid 16723:tid 16981] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvi9E0uOV11S2qN6fRAAAAQQ"]
[Thu Sep 17 15:29:37.265675 2026] [security2:error] [pid 16723:tid 16872] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/htdocs/.env"] [unique_id "aqxbwS9E0uOV11S2qN6frwAAAJc"]
[Thu Sep 17 15:29:37.293727 2026] [security2:error] [pid 16723:tid 16895] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvi9E0uOV11S2qN6fRQAAAK4"]
[Thu Sep 17 15:29:37.298338 2026] [security2:error] [pid 16723:tid 16864] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6fVwAAAI8"]
[Thu Sep 17 15:29:37.311360 2026] [security2:error] [pid 16723:tid 16979] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6fWQAAAQI"]
[Thu Sep 17 15:29:37.313088 2026] [security2:error] [pid 1029697:tid 1029937] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6iygAAAG4"]
[Thu Sep 17 15:29:37.316497 2026] [security2:error] [pid 1029697:tid 1029886] [client 223.109.255.146:51286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "breathingboxing.com"] [uri "/about/"] [unique_id "aqxbwW65wm-f4uX16X6jDwAAADs"]
[Thu Sep 17 15:29:37.316678 2026] [security2:error] [pid 1029697:tid 1029886] [client 223.109.255.146:51286] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "breathingboxing.com"] [uri "/about/"] [unique_id "aqxbwW65wm-f4uX16X6jDwAAADs"]
[Thu Sep 17 15:29:37.321955 2026] [security2:error] [pid 16723:tid 16761] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/wp/.env"] [unique_id "aqxbvi9E0uOV11S2qN6fsQAAqSQ"]
[Thu Sep 17 15:29:37.324540 2026] [security2:error] [pid 16723:tid 16801] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "nevadastaterealty.com"] [uri "/wp-config.php.swp"] [unique_id "aqxbvi9E0uOV11S2qN6fswAAqUw"]
[Thu Sep 17 15:29:37.325326 2026] [security2:error] [pid 16723:tid 16803] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nevadastaterealty.com"] [uri "/index_dev.php"] [unique_id "aqxbvy9E0uOV11S2qN6ftQAAqU4"]
[Thu Sep 17 15:29:37.336319 2026] [security2:error] [pid 16723:tid 16793] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "nevadastaterealty.com"] [uri "/wp-config.php~"] [unique_id "aqxbvy9E0uOV11S2qN6fuwAAqUQ"]
[Thu Sep 17 15:29:37.337731 2026] [security2:error] [pid 16723:tid 16793] [remote 45.138.12.25:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nevadastaterealty.com"] [uri "/2021/.env"] [unique_id "aqxbvy9E0uOV11S2qN6fvAAAqUQ"]
[Thu Sep 17 15:29:37.341068 2026] [security2:error] [pid 1029697:tid 1029878] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvm65wm-f4uX16X6iogAAADM"]
[Thu Sep 17 15:29:37.342124 2026] [security2:error] [pid 1029697:tid 1029868] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i1wAAACk"]
[Thu Sep 17 15:29:37.354221 2026] [security2:error] [pid 1029697:tid 1029929] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvm65wm-f4uX16X6ioAAAAGY"]
[Thu Sep 17 15:29:37.380746 2026] [security2:error] [pid 16723:tid 16976] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6faAAAAP8"]
[Thu Sep 17 15:29:37.387295 2026] [security2:error] [pid 1029697:tid 1029911] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i2wAAAFQ"]
[Thu Sep 17 15:29:37.420894 2026] [security2:error] [pid 16723:tid 16862] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/www/.env"] [unique_id "aqxbwS9E0uOV11S2qN6fxgAAAI0"]
[Thu Sep 17 15:29:37.460924 2026] [security2:error] [pid 1029697:tid 1029932] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i3gAAAGk"]
[Thu Sep 17 15:29:37.465185 2026] [security2:error] [pid 1029697:tid 1029887] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "edmagiktv.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6ixAAAADw"]
[Thu Sep 17 15:29:37.470051 2026] [security2:error] [pid 16723:tid 16889] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6fcwAAAKg"]
[Thu Sep 17 15:29:37.473265 2026] [security2:error] [pid 1029697:tid 1029941] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i0gAAAHI"]
[Thu Sep 17 15:29:37.533807 2026] [security2:error] [pid 1029697:tid 1029779] [remote 139.59.114.163:39316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxbwW65wm-f4uX16X6jEgAAb1E"], referer: http://mail.jwdnyc.com/wordpress/
[Thu Sep 17 15:29:37.581289 2026] [security2:error] [pid 16723:tid 16930] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/html/.env"] [unique_id "aqxbwS9E0uOV11S2qN6fyAAAANE"]
[Thu Sep 17 15:29:37.619159 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.166.113.162:50570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/phpinfo.php.old"] [unique_id "aqxbwW65wm-f4uX16X6jGQAAAHg"]
[Thu Sep 17 15:29:37.658368 2026] [security2:error] [pid 1029697:tid 1029816] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "allin1.com"] [uri "/wp-config.php.swp"] [unique_id "aqxbwW65wm-f4uX16X6jHQAAdXY"]
[Thu Sep 17 15:29:37.658855 2026] [security2:error] [pid 1029697:tid 1029817] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allin1.com"] [uri "/index_dev.php"] [unique_id "aqxbwW65wm-f4uX16X6jGwAAdXc"]
[Thu Sep 17 15:29:37.659937 2026] [security2:error] [pid 1029697:tid 1029807] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/wp/.env"] [unique_id "aqxbwW65wm-f4uX16X6jIAAAdW0"]
[Thu Sep 17 15:29:37.740708 2026] [security2:error] [pid 16723:tid 16938] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/live/.env"] [unique_id "aqxbwS9E0uOV11S2qN6fygAAANk"]
[Thu Sep 17 15:29:37.888033 2026] [security2:error] [pid 1029697:tid 1029850] [client 193.36.224.108:31495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxbwW65wm-f4uX16X6jJgAAABc"]
[Thu Sep 17 15:29:37.901134 2026] [security2:error] [pid 16723:tid 16928] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/prod/.env"] [unique_id "aqxbwS9E0uOV11S2qN6f0QAAAM8"]
[Thu Sep 17 15:29:37.911835 2026] [security2:error] [pid 16723:tid 16948] [client 143.105.152.240:25790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbwS9E0uOV11S2qN6f0gAAAOM"]
[Thu Sep 17 15:29:37.912631 2026] [security2:error] [pid 1029697:tid 1029729] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "allin1.com"] [uri "/wp-config.php~"] [unique_id "aqxbwW65wm-f4uX16X6jKAAAdR8"]
[Thu Sep 17 15:29:37.913857 2026] [security2:error] [pid 1029697:tid 1029776] [remote 45.138.12.25:37842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "allin1.com"] [uri "/2021/.env"] [unique_id "aqxbwW65wm-f4uX16X6jKQAAdU4"]
[Thu Sep 17 15:29:37.926007 2026] [security2:error] [pid 16723:tid 16948] [client 143.105.152.240:25790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbwS9E0uOV11S2qN6f0gAAAOM"]
[Thu Sep 17 15:29:37.951051 2026] [security2:error] [pid 1029697:tid 1029829] [client 191.36.234.149:56788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbwW65wm-f4uX16X6jJQAAAis"]
[Thu Sep 17 15:29:38.060361 2026] [security2:error] [pid 16723:tid 16957] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/dev/.env"] [unique_id "aqxbwi9E0uOV11S2qN6f1QAAAOw"]
[Thu Sep 17 15:29:38.069822 2026] [security2:error] [pid 1029697:tid 1029904] [client 139.59.114.163:39316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxbwW65wm-f4uX16X6jLgAATQM"], referer: http://mail.jwdnyc.com/blog/
[Thu Sep 17 15:29:38.217037 2026] [security2:error] [pid 16723:tid 16884] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/staging/.env"] [unique_id "aqxbwi9E0uOV11S2qN6f2gAAAKM"]
[Thu Sep 17 15:29:38.284513 2026] [security2:error] [pid 16723:tid 16958] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbvy9E0uOV11S2qN6fbAAAAO0"]
[Thu Sep 17 15:29:38.314692 2026] [security2:error] [pid 1029697:tid 1029849] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i3AAAABY"]
[Thu Sep 17 15:29:38.320796 2026] [security2:error] [pid 16723:tid 16888] [client 103.61.184.148:53375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbwi9E0uOV11S2qN6f4QAAAKc"]
[Thu Sep 17 15:29:38.320966 2026] [security2:error] [pid 16723:tid 16888] [client 103.61.184.148:53375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbwi9E0uOV11S2qN6f4QAAAKc"]
[Thu Sep 17 15:29:38.332963 2026] [security2:error] [pid 16723:tid 16856] [client 34.166.113.162:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/phpinfo.php~"] [unique_id "aqxbwi9E0uOV11S2qN6f4gAAAIc"]
[Thu Sep 17 15:29:38.356901 2026] [security2:error] [pid 1029697:tid 1029854] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbvm65wm-f4uX16X6ioQAAABs"]
[Thu Sep 17 15:29:38.364989 2026] [security2:error] [pid 1029697:tid 1029908] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwG65wm-f4uX16X6jAwAAAFE"]
[Thu Sep 17 15:29:38.375322 2026] [security2:error] [pid 16723:tid 16931] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/opt/.env"] [unique_id "aqxbwi9E0uOV11S2qN6f5AAAANI"]
[Thu Sep 17 15:29:38.393528 2026] [security2:error] [pid 16723:tid 16906] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwC9E0uOV11S2qN6flwAAALk"]
[Thu Sep 17 15:29:38.405788 2026] [security2:error] [pid 16723:tid 16977] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwC9E0uOV11S2qN6fmgAAAQA"]
[Thu Sep 17 15:29:38.409953 2026] [security2:error] [pid 1029697:tid 1029844] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbwW65wm-f4uX16X6jEwAAABE"]
[Thu Sep 17 15:29:38.414402 2026] [security2:error] [pid 16723:tid 16905] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbwS9E0uOV11S2qN6fwwAAALg"]
[Thu Sep 17 15:29:38.421822 2026] [security2:error] [pid 1029697:tid 1029920] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwG65wm-f4uX16X6jAAAAAF0"]
[Thu Sep 17 15:29:38.435974 2026] [security2:error] [pid 1029697:tid 1029924] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwG65wm-f4uX16X6i_gAAAGE"]
[Thu Sep 17 15:29:38.446085 2026] [security2:error] [pid 16723:tid 16968] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbwS9E0uOV11S2qN6fxAAAAPc"]
[Thu Sep 17 15:29:38.455506 2026] [security2:error] [pid 1029697:tid 1029898] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwW65wm-f4uX16X6jCwAAAEc"]
[Thu Sep 17 15:29:38.531484 2026] [security2:error] [pid 16723:tid 16949] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/laravel/.env"] [unique_id "aqxbwi9E0uOV11S2qN6f6QAAAOQ"]
[Thu Sep 17 15:29:38.559967 2026] [security2:error] [pid 1029697:tid 1029843] [client 216.24.219.35:45801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/file.php"] [unique_id "aqxbwm65wm-f4uX16X6jPgAAABA"]
[Thu Sep 17 15:29:38.614210 2026] [security2:error] [pid 1029697:tid 1029946] [client 139.59.114.163:39316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxbwm65wm-f4uX16X6jPQAAd08"], referer: http://mail.jwdnyc.com/new/
[Thu Sep 17 15:29:38.675277 2026] [security2:error] [pid 16723:tid 16979] [client 18.188.3.41:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/old/xmlrpc.php"] [unique_id "aqxbwi9E0uOV11S2qN6f7gAAAQI"]
[Thu Sep 17 15:29:38.696843 2026] [security2:error] [pid 16723:tid 16910] [client 34.154.232.68:47448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/symfony/.env"] [unique_id "aqxbwi9E0uOV11S2qN6f7wAAAL0"]
[Thu Sep 17 15:29:38.979185 2026] [security2:error] [pid 16723:tid 16976] [client 193.36.224.169:54129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxbwi9E0uOV11S2qN6f9QAAAP8"]
[Thu Sep 17 15:29:39.026332 2026] [security2:error] [pid 16723:tid 16964] [client 34.166.113.162:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/info.php.bak"] [unique_id "aqxbwy9E0uOV11S2qN6f9gAAAPM"]
[Thu Sep 17 15:29:39.164905 2026] [security2:error] [pid 1029697:tid 1029863] [client 139.59.114.163:39316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxbw265wm-f4uX16X6jRQAAJCk"], referer: http://mail.jwdnyc.com/backup/
[Thu Sep 17 15:29:39.177781 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/wordpress/.env"] [unique_id "aqxbw265wm-f4uX16X6jRgAAAAM"]
[Thu Sep 17 15:29:39.260695 2026] [security2:error] [pid 1029697:tid 1029839] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwG65wm-f4uX16X6i7gAAAAw"]
[Thu Sep 17 15:29:39.270437 2026] [security2:error] [pid 1029697:tid 1029855] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i3wAAABw"]
[Thu Sep 17 15:29:39.271182 2026] [security2:error] [pid 1029697:tid 1029915] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbv265wm-f4uX16X6i5gAAAFg"]
[Thu Sep 17 15:29:39.274025 2026] [security2:error] [pid 1029697:tid 1029944] [client 45.138.12.25:37842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwW65wm-f4uX16X6jHgAAdV8"]
[Thu Sep 17 15:29:39.290701 2026] [security2:error] [pid 16723:tid 16761] [remote 45.138.12.25:37868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbvi9E0uOV11S2qN6fsgAAqSQ"]
[Thu Sep 17 15:29:39.310833 2026] [security2:error] [pid 16723:tid 16866] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f1gAAAJE"]
[Thu Sep 17 15:29:39.317055 2026] [security2:error] [pid 16723:tid 16860] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f2wAAAIs"]
[Thu Sep 17 15:29:39.318267 2026] [security2:error] [pid 16723:tid 16969] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbwS9E0uOV11S2qN6fxQAAAPg"]
[Thu Sep 17 15:29:39.325788 2026] [security2:error] [pid 16723:tid 16978] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f1AAAAQE"]
[Thu Sep 17 15:29:39.338999 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/wp/.env"] [unique_id "aqxbw265wm-f4uX16X6jTAAAAHs"]
[Thu Sep 17 15:29:39.356452 2026] [security2:error] [pid 1029697:tid 1029866] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwm65wm-f4uX16X6jNwAAACc"]
[Thu Sep 17 15:29:39.356554 2026] [security2:error] [pid 16723:tid 16914] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f3AAAAME"]
[Thu Sep 17 15:29:39.380013 2026] [security2:error] [pid 16723:tid 16927] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f4AAAAM4"]
[Thu Sep 17 15:29:39.420393 2026] [security2:error] [pid 16723:tid 16903] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f5wAAALY"]
[Thu Sep 17 15:29:39.425654 2026] [security2:error] [pid 16723:tid 16944] [client 193.36.224.170:30641] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-mail.php"] [unique_id "aqxbwy9E0uOV11S2qN6gAgAAAN8"]
[Thu Sep 17 15:29:39.428532 2026] [security2:error] [pid 1029697:tid 1029914] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwm65wm-f4uX16X6jOwAAAFc"]
[Thu Sep 17 15:29:39.442540 2026] [security2:error] [pid 16723:tid 16864] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f7QAAAI8"]
[Thu Sep 17 15:29:39.448649 2026] [security2:error] [pid 16723:tid 16882] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allin1.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f5gAAAKE"]
[Thu Sep 17 15:29:39.450124 2026] [security2:error] [pid 16723:tid 16899] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbwi9E0uOV11S2qN6f6wAAALI"]
[Thu Sep 17 15:29:39.492373 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/cms/.env"] [unique_id "aqxbw265wm-f4uX16X6jTwAAAAg"]
[Thu Sep 17 15:29:39.494131 2026] [security2:error] [pid 1029697:tid 1029773] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "silverstaterealty.com"] [uri "/wp-config.php.swp"] [unique_id "aqxbwG65wm-f4uX16X6jUQAAOUs"]
[Thu Sep 17 15:29:39.494954 2026] [security2:error] [pid 1029697:tid 1029707] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/wp/.env"] [unique_id "aqxbwG65wm-f4uX16X6jUAAAOQk"]
[Thu Sep 17 15:29:39.495321 2026] [security2:error] [pid 1029697:tid 1029707] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "silverstaterealty.com"] [uri "/index_dev.php"] [unique_id "aqxbwW65wm-f4uX16X6jVAAAOQk"]
[Thu Sep 17 15:29:39.497600 2026] [security2:error] [pid 1029697:tid 1029806] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "silverstaterealty.com"] [uri "/wp-config.php~"] [unique_id "aqxbwm65wm-f4uX16X6jWwAAOWw"]
[Thu Sep 17 15:29:39.498348 2026] [security2:error] [pid 1029697:tid 1029806] [remote 45.138.12.25:37856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "silverstaterealty.com"] [uri "/2021/.env"] [unique_id "aqxbwm65wm-f4uX16X6jXAAAOWw"]
[Thu Sep 17 15:29:39.535015 2026] [security2:error] [pid 16723:tid 16928] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbwy9E0uOV11S2qN6gAAAAAM8"]
[Thu Sep 17 15:29:39.649349 2026] [security2:error] [pid 1029697:tid 1029911] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/drupal/.env"] [unique_id "aqxbw265wm-f4uX16X6jYgAAAFQ"]
[Thu Sep 17 15:29:39.651375 2026] [security2:error] [pid 1029697:tid 1029796] [remote 45.138.12.25:37856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbwG65wm-f4uX16X6jUgAAOWI"]
[Thu Sep 17 15:29:39.689068 2026] [security2:error] [pid 1029697:tid 1029936] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbw265wm-f4uX16X6jXwAAAG0"]
[Thu Sep 17 15:29:39.692018 2026] [security2:error] [pid 16723:tid 16904] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbwy9E0uOV11S2qN6gCgAAALc"]
[Thu Sep 17 15:29:39.693943 2026] [security2:error] [pid 16723:tid 16977] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbwy9E0uOV11S2qN6gCQAAAQA"]
[Thu Sep 17 15:29:39.713518 2026] [security2:error] [pid 16723:tid 16877] [client 83.115.223.79:50580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxbwy9E0uOV11S2qN6gCwAAnGw"]
[Thu Sep 17 15:29:39.728595 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.166.113.162:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/phpinfo.php.save"] [unique_id "aqxbw265wm-f4uX16X6jaQAAADs"]
[Thu Sep 17 15:29:39.768377 2026] [security2:error] [pid 16723:tid 16961] [client 114.198.138.124:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbwy9E0uOV11S2qN6gDgAAAPA"]
[Thu Sep 17 15:29:39.768559 2026] [security2:error] [pid 16723:tid 16961] [client 114.198.138.124:50254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbwy9E0uOV11S2qN6gDgAAAPA"]
[Thu Sep 17 15:29:39.809082 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/joomla/.env"] [unique_id "aqxbw265wm-f4uX16X6jbgAAAF4"]
[Thu Sep 17 15:29:39.846704 2026] [security2:error] [pid 1029697:tid 1029930] [client 193.36.224.206:62721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/ioxi-o.php"] [unique_id "aqxbw265wm-f4uX16X6jcQAAAGc"]
[Thu Sep 17 15:29:39.970080 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/magento/.env"] [unique_id "aqxbw265wm-f4uX16X6jcgAAABI"]
[Thu Sep 17 15:29:40.126178 2026] [security2:error] [pid 1029697:tid 1029945] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/shopify/.env"] [unique_id "aqxbxG65wm-f4uX16X6jdAAAAHY"]
[Thu Sep 17 15:29:40.227301 2026] [security2:error] [pid 1029697:tid 1029934] [client 193.36.224.169:51269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxbxG65wm-f4uX16X6jdQAAAGs"]
[Thu Sep 17 15:29:40.279720 2026] [security2:error] [pid 1029697:tid 1029864] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/prestashop/.env"] [unique_id "aqxbxG65wm-f4uX16X6jdwAAACU"]
[Thu Sep 17 15:29:40.292074 2026] [security2:error] [pid 1029697:tid 1029929] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbw265wm-f4uX16X6jYwAAAGY"]
[Thu Sep 17 15:29:40.360270 2026] [security2:error] [pid 16723:tid 16886] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbwy9E0uOV11S2qN6gDwAAAKU"]
[Thu Sep 17 15:29:40.360283 2026] [security2:error] [pid 1029697:tid 1029887] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbw265wm-f4uX16X6jbAAAADw"]
[Thu Sep 17 15:29:40.360714 2026] [security2:error] [pid 1029697:tid 1029894] [client 45.138.12.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "silverstaterealty.com"] [uri "/index.php"] [unique_id "aqxbw265wm-f4uX16X6jbQAAAEM"]
[Thu Sep 17 15:29:40.433264 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.166.113.162:50604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxbxG65wm-f4uX16X6jeQAAAFw"]
[Thu Sep 17 15:29:40.442142 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/codeigniter/.env"] [unique_id "aqxbxG65wm-f4uX16X6jewAAAAI"]
[Thu Sep 17 15:29:40.598753 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/cakephp/.env"] [unique_id "aqxbxG65wm-f4uX16X6jfAAAAAE"]
[Thu Sep 17 15:29:40.702478 2026] [security2:error] [pid 16723:tid 16956] [client 193.36.224.146:40155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/style.php"] [unique_id "aqxbxC9E0uOV11S2qN6gFgAAAOs"]
[Thu Sep 17 15:29:40.755023 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/zend/.env"] [unique_id "aqxbxG65wm-f4uX16X6jfQAAACY"]
[Thu Sep 17 15:29:40.909147 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/yii/.env"] [unique_id "aqxbxG65wm-f4uX16X6jfgAAABs"]
[Thu Sep 17 15:29:41.061714 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/laravel5/.env"] [unique_id "aqxbxW65wm-f4uX16X6jgQAAAEo"]
[Thu Sep 17 15:29:41.127711 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.166.113.162:50610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxbxW65wm-f4uX16X6jgwAAADI"]
[Thu Sep 17 15:29:41.220139 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/v1/.env"] [unique_id "aqxbxW65wm-f4uX16X6jhQAAAF0"]
[Thu Sep 17 15:29:41.377843 2026] [security2:error] [pid 1029697:tid 1029940] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/v2/.env"] [unique_id "aqxbxW65wm-f4uX16X6jiwAAAHE"]
[Thu Sep 17 15:29:41.541799 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/v3/.env"] [unique_id "aqxbxW65wm-f4uX16X6jkQAAACI"]
[Thu Sep 17 15:29:41.700924 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/api/v1/.env"] [unique_id "aqxbxW65wm-f4uX16X6jkwAAACQ"]
[Thu Sep 17 15:29:41.819559 2026] [security2:error] [pid 16723:tid 16946] [client 34.166.113.162:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxbxS9E0uOV11S2qN6gIAAAAOE"]
[Thu Sep 17 15:29:41.842009 2026] [security2:error] [pid 1029697:tid 1029846] [client 3.19.142.206:49518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbxW65wm-f4uX16X6jlwAAABM"]
[Thu Sep 17 15:29:41.862091 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/api/v2/.env"] [unique_id "aqxbxW65wm-f4uX16X6jmAAAAAw"]
[Thu Sep 17 15:29:41.913140 2026] [core:error] [pid 1029697:tid 1029858] [client 152.32.201.247:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:41.913158 2026] [core:error] [pid 1029697:tid 1029858] [client 152.32.201.247:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:41.970785 2026] [security2:error] [pid 16723:tid 16978] [client 216.24.219.38:38955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/style.php"] [unique_id "aqxbxS9E0uOV11S2qN6gIQAAAQE"]
[Thu Sep 17 15:29:42.018541 2026] [security2:error] [pid 1029697:tid 1029879] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/rest/.env"] [unique_id "aqxbxm65wm-f4uX16X6jnQAAADQ"]
[Thu Sep 17 15:29:42.139694 2026] [security2:error] [pid 1029697:tid 1029882] [client 43.163.206.70:54270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxbxW65wm-f4uX16X6jlAAAADc"]
[Thu Sep 17 15:29:42.190022 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/graphql/.env"] [unique_id "aqxbxm65wm-f4uX16X6jnwAAAF8"]
[Thu Sep 17 15:29:42.238164 2026] [security2:error] [pid 1029697:tid 1029914] [client 216.24.219.38:64983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxbxm65wm-f4uX16X6joAAAAFc"]
[Thu Sep 17 15:29:42.347146 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/gateway/.env"] [unique_id "aqxbxm65wm-f4uX16X6joQAAAEk"]
[Thu Sep 17 15:29:42.417934 2026] [security2:error] [pid 16723:tid 16903] [client 66.249.66.34:42996] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "abbacsrealms.com"] [uri "/robots.txt"] [unique_id "aqxbxi9E0uOV11S2qN6gJgAAALY"]
[Thu Sep 17 15:29:42.503633 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/microservice/.env"] [unique_id "aqxbxm65wm-f4uX16X6jpAAAABQ"]
[Thu Sep 17 15:29:42.516766 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.166.113.162:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxbxm65wm-f4uX16X6jpgAAAHU"]
[Thu Sep 17 15:29:42.664528 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/service/.env"] [unique_id "aqxbxm65wm-f4uX16X6jqAAAAGk"]
[Thu Sep 17 15:29:42.759589 2026] [security2:error] [pid 1029697:tid 1029902] [client 193.36.224.226:49817] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-editor.php"] [unique_id "aqxbxm65wm-f4uX16X6jqgAAAEs"]
[Thu Sep 17 15:29:42.818874 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/api/v3/.env"] [unique_id "aqxbxm65wm-f4uX16X6jqwAAAEQ"]
[Thu Sep 17 15:29:42.973335 2026] [security2:error] [pid 1029697:tid 1029897] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/api/dev/.env"] [unique_id "aqxbxm65wm-f4uX16X6jsQAAAEY"]
[Thu Sep 17 15:29:43.062119 2026] [security2:error] [pid 16723:tid 16925] [client 104.234.19.149:58305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/lufix.php"] [unique_id "aqxbxy9E0uOV11S2qN6gLgAAAMw"]
[Thu Sep 17 15:29:43.133484 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/api/staging/.env"] [unique_id "aqxbx265wm-f4uX16X6jtQAAAHw"]
[Thu Sep 17 15:29:43.200513 2026] [security2:error] [pid 16723:tid 16902] [client 34.166.113.162:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxbxy9E0uOV11S2qN6gNgAAALU"]
[Thu Sep 17 15:29:43.289559 2026] [security2:error] [pid 1029697:tid 1029856] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/vendor/.env"] [unique_id "aqxbx265wm-f4uX16X6juQAAAB0"]
[Thu Sep 17 15:29:43.292249 2026] [security2:error] [pid 16723:tid 16940] [client 104.234.19.144:51313] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/txets.php"] [unique_id "aqxbxy9E0uOV11S2qN6gNwAAANs"]
[Thu Sep 17 15:29:43.445764 2026] [security2:error] [pid 1029697:tid 1029887] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/lib/.env"] [unique_id "aqxbx265wm-f4uX16X6juwAAADw"]
[Thu Sep 17 15:29:43.552962 2026] [security2:error] [pid 1029697:tid 1029948] [client 193.36.224.156:36713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxbx265wm-f4uX16X6jvgAAAHk"]
[Thu Sep 17 15:29:43.604415 2026] [security2:error] [pid 1029697:tid 1029935] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/resources/.env"] [unique_id "aqxbx265wm-f4uX16X6jvwAAAGw"]
[Thu Sep 17 15:29:43.771418 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/assets/.env"] [unique_id "aqxbx265wm-f4uX16X6jwQAAAE0"]
[Thu Sep 17 15:29:43.860670 2026] [security2:error] [pid 1029697:tid 1029953] [client 193.36.224.156:51737] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxbx265wm-f4uX16X6jwwAAAH4"]
[Thu Sep 17 15:29:43.888945 2026] [security2:error] [pid 16723:tid 16904] [client 34.166.113.162:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/www/phpinfo.php"] [unique_id "aqxbxy9E0uOV11S2qN6gQQAAALc"]
[Thu Sep 17 15:29:43.928598 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/uploads/.env"] [unique_id "aqxbx265wm-f4uX16X6jxgAAAH8"]
[Thu Sep 17 15:29:43.997603 2026] [security2:error] [pid 16723:tid 16900] [client 162.241.226.11:44924] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxbxy9E0uOV11S2qN6gQgAAALM"]
[Thu Sep 17 15:29:44.087439 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/internal/.env"] [unique_id "aqxbyG65wm-f4uX16X6j0QAAAGE"]
[Thu Sep 17 15:29:44.176174 2026] [security2:error] [pid 16723:tid 16892] [client 216.24.219.103:21199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxbyC9E0uOV11S2qN6gSgAAAKs"]
[Thu Sep 17 15:29:44.183540 2026] [security2:error] [pid 16723:tid 16917] [client 185.55.149.49:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.149.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbyC9E0uOV11S2qN6gSwAAAMQ"]
[Thu Sep 17 15:29:44.183779 2026] [security2:error] [pid 16723:tid 16917] [client 185.55.149.49:50588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arhitecturabuzau.ro"] [uri "/xmlrpc.php"] [unique_id "aqxbyC9E0uOV11S2qN6gSwAAAMQ"]
[Thu Sep 17 15:29:44.250044 2026] [security2:error] [pid 1029697:tid 1029933] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/tools/.env"] [unique_id "aqxbyG65wm-f4uX16X6j2AAAAGo"]
[Thu Sep 17 15:29:44.295171 2026] [security2:error] [pid 1029697:tid 1029901] [client 136.158.61.34:37704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbyG65wm-f4uX16X6j7wAAAEo"]
[Thu Sep 17 15:29:44.295322 2026] [security2:error] [pid 1029697:tid 1029901] [client 136.158.61.34:37704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxbyG65wm-f4uX16X6j7wAAAEo"]
[Thu Sep 17 15:29:44.405886 2026] [security2:error] [pid 1029697:tid 1029928] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/scripts/.env"] [unique_id "aqxbyG65wm-f4uX16X6j8QAAAGU"]
[Thu Sep 17 15:29:44.432512 2026] [security2:error] [pid 16723:tid 16887] [client 193.36.224.151:64645] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/goods.php"] [unique_id "aqxbyC9E0uOV11S2qN6gTwAAAKY"]
[Thu Sep 17 15:29:44.560532 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/bin/.env"] [unique_id "aqxbyG65wm-f4uX16X6j8wAAAE8"]
[Thu Sep 17 15:29:44.590875 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.166.113.162:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxbyG65wm-f4uX16X6j9QAAABU"]
[Thu Sep 17 15:29:44.700976 2026] [authz_core:error] [pid 16723:tid 16979] [client 4.240.114.86:61635] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:29:44.714273 2026] [security2:error] [pid 1029697:tid 1029905] [client 216.24.219.22:24329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "adventuresofapril.com"] [uri "/php8.php"] [unique_id "aqxbyG65wm-f4uX16X6j-gAAAE4"]
[Thu Sep 17 15:29:44.715181 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/sbin/.env"] [unique_id "aqxbyG65wm-f4uX16X6j-wAAAFA"]
[Thu Sep 17 15:29:44.875360 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/local/.env"] [unique_id "aqxbyG65wm-f4uX16X6kFQAAACc"]
[Thu Sep 17 15:29:45.038886 2026] [security2:error] [pid 1029697:tid 1029914] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/portal/.env"] [unique_id "aqxbyW65wm-f4uX16X6kGAAAAFc"]
[Thu Sep 17 15:29:45.193846 2026] [security2:error] [pid 1029697:tid 1029833] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/dashboard/.env"] [unique_id "aqxbyW65wm-f4uX16X6kGgAAAAY"]
[Thu Sep 17 15:29:45.277572 2026] [security2:error] [pid 16723:tid 16923] [client 34.166.113.162:52254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxbyS9E0uOV11S2qN6gWgAAAMo"]
[Thu Sep 17 15:29:45.356168 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/panel/.env"] [unique_id "aqxbyW65wm-f4uX16X6kGwAAAAg"]
[Thu Sep 17 15:29:45.524950 2026] [security2:error] [pid 1029697:tid 1029853] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/crm/.env"] [unique_id "aqxbyW65wm-f4uX16X6kIAAAABo"]
[Thu Sep 17 15:29:45.683738 2026] [security2:error] [pid 1029697:tid 1029886] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/erp/.env"] [unique_id "aqxbyW65wm-f4uX16X6kIgAAADs"]
[Thu Sep 17 15:29:45.842567 2026] [security2:error] [pid 1029697:tid 1029932] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/shop/.env"] [unique_id "aqxbyW65wm-f4uX16X6kJQAAAGk"]
[Thu Sep 17 15:29:45.960198 2026] [security2:error] [pid 16723:tid 16890] [client 34.166.113.162:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/site/phpinfo.php"] [unique_id "aqxbyS9E0uOV11S2qN6gbAAAAKk"]
[Thu Sep 17 15:29:46.003351 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/store/.env"] [unique_id "aqxbym65wm-f4uX16X6kLAAAAEQ"]
[Thu Sep 17 15:29:46.157323 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/saas/.env"] [unique_id "aqxbym65wm-f4uX16X6kMAAAAGc"]
[Thu Sep 17 15:29:46.175793 2026] [security2:error] [pid 16723:tid 16867] [client 18.188.3.41:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/new/xmlrpc.php"] [unique_id "aqxbyi9E0uOV11S2qN6gfQAAAJI"]
[Thu Sep 17 15:29:46.319523 2026] [security2:error] [pid 1029697:tid 1029845] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/client/.env"] [unique_id "aqxbym65wm-f4uX16X6kMQAAABI"]
[Thu Sep 17 15:29:46.475854 2026] [security2:error] [pid 1029697:tid 1029842] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/project/.env"] [unique_id "aqxbym65wm-f4uX16X6kNQAAAA8"]
[Thu Sep 17 15:29:46.629015 2026] [security2:error] [pid 1029697:tid 1029850] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/admin-panel/.env"] [unique_id "aqxbym65wm-f4uX16X6kNgAAABc"]
[Thu Sep 17 15:29:46.652509 2026] [security2:error] [pid 16723:tid 16858] [client 34.166.113.162:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxbyi9E0uOV11S2qN6gmAAAAIk"]
[Thu Sep 17 15:29:46.782224 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/control-panel/.env"] [unique_id "aqxbym65wm-f4uX16X6kOAAAAFw"]
[Thu Sep 17 15:29:46.856667 2026] [security2:error] [pid 16723:tid 16875] [client 128.1.131.203:36516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5305.bluehost.com"] [uri "/index.cgi"] [unique_id "aqxbyi9E0uOV11S2qN6gmgAAAJo"]
[Thu Sep 17 15:29:46.953845 2026] [security2:error] [pid 1029697:tid 1029870] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/user-panel/.env"] [unique_id "aqxbym65wm-f4uX16X6kOwAAACs"]
[Thu Sep 17 15:29:47.079544 2026] [authz_core:error] [pid 16723:tid 16965] [client 169.58.197.253:53588] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:29:47.118061 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/node/.env"] [unique_id "aqxby265wm-f4uX16X6kPAAAAE0"]
[Thu Sep 17 15:29:47.184193 2026] [core:error] [pid 16723:tid 16891] [client 152.32.201.247:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:47.184219 2026] [core:error] [pid 16723:tid 16891] [client 152.32.201.247:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:29:47.212012 2026] [security2:error] [pid 1029697:tid 1029828] [client 216.244.66.228:50340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wisdomelders.com"] [uri "/00m4dm/eimo37.php"] [unique_id "aqxby265wm-f4uX16X6kPgAAAAE"]
[Thu Sep 17 15:29:47.212100 2026] [security2:error] [pid 1029697:tid 1029828] [client 216.244.66.228:50340] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wisdomelders.com"] [uri "/00m4dm/eimo37.php"] [unique_id "aqxby265wm-f4uX16X6kPgAAAAE"]
[Thu Sep 17 15:29:47.273402 2026] [security2:error] [pid 1029697:tid 1029953] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/express/.env"] [unique_id "aqxby265wm-f4uX16X6kPwAAAH4"]
[Thu Sep 17 15:29:47.349292 2026] [security2:error] [pid 16723:tid 16960] [client 34.166.113.162:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxbyy9E0uOV11S2qN6gtQAAAO8"]
[Thu Sep 17 15:29:47.442253 2026] [security2:error] [pid 1029697:tid 1029854] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/next/.env"] [unique_id "aqxby265wm-f4uX16X6kQQAAABs"]
[Thu Sep 17 15:29:47.599248 2026] [security2:error] [pid 1029697:tid 1029896] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/nuxt/.env"] [unique_id "aqxby265wm-f4uX16X6kRAAAAEU"]
[Thu Sep 17 15:29:47.759730 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/nest/.env"] [unique_id "aqxby265wm-f4uX16X6kRQAAAEg"]
[Thu Sep 17 15:29:47.849901 2026] [security2:error] [pid 16723:tid 16865] [client 162.241.226.11:44970] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxbyy9E0uOV11S2qN6gxQAAAJA"]
[Thu Sep 17 15:29:47.914737 2026] [security2:error] [pid 1029697:tid 1029829] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/react/.env"] [unique_id "aqxby265wm-f4uX16X6kRgAAAAI"]
[Thu Sep 17 15:29:48.031823 2026] [security2:error] [pid 16723:tid 16902] [client 34.166.113.162:52302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxbzC9E0uOV11S2qN6gygAAALU"]
[Thu Sep 17 15:29:48.067461 2026] [security2:error] [pid 1029697:tid 1029901] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/vue/.env"] [unique_id "aqxbzG65wm-f4uX16X6kSwAAAEo"]
[Thu Sep 17 15:29:48.222764 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/angular/.env"] [unique_id "aqxbzG65wm-f4uX16X6kTwAAADU"]
[Thu Sep 17 15:29:48.380312 2026] [security2:error] [pid 1029697:tid 1029863] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/svelte/.env"] [unique_id "aqxbzG65wm-f4uX16X6kUwAAACQ"]
[Thu Sep 17 15:29:48.518317 2026] [security2:error] [pid 1029697:tid 1029943] [client 143.105.152.240:18012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbzG65wm-f4uX16X6kVwAAAHQ"]
[Thu Sep 17 15:29:48.518456 2026] [security2:error] [pid 1029697:tid 1029943] [client 143.105.152.240:18012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxbzG65wm-f4uX16X6kVwAAAHQ"]
[Thu Sep 17 15:29:48.543443 2026] [security2:error] [pid 1029697:tid 1029844] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/vite/.env"] [unique_id "aqxbzG65wm-f4uX16X6kWAAAABE"]
[Thu Sep 17 15:29:48.676392 2026] [fcgid:warn] [pid 1029697:tid 1029839] (70014)End of file found: [client 128.1.131.203:54322] mod_fcgid: can't get data from http client
[Thu Sep 17 15:29:48.691570 2026] [security2:error] [pid 16723:tid 16882] [client 5.37.185.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxbyy9E0uOV11S2qN6gwQAAAKE"]
[Thu Sep 17 15:29:48.700305 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/backup/.env"] [unique_id "aqxbzG65wm-f4uX16X6kWgAAAFg"]
[Thu Sep 17 15:29:48.753580 2026] [security2:error] [pid 16723:tid 16959] [client 34.166.113.162:52306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/core/phpinfo.php"] [unique_id "aqxbzC9E0uOV11S2qN6g0QAAAO4"]
[Thu Sep 17 15:29:48.853947 2026] [security2:error] [pid 1029697:tid 1029905] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/backups/.env"] [unique_id "aqxbzG65wm-f4uX16X6kWwAAAE4"]
[Thu Sep 17 15:29:48.875513 2026] [security2:error] [pid 16723:tid 16945] [client 66.249.73.235:45894] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sut.mjj.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxbzC9E0uOV11S2qN6g0gAAAOA"]
[Thu Sep 17 15:29:49.013638 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/old/.env"] [unique_id "aqxbzW65wm-f4uX16X6kXwAAAAk"]
[Thu Sep 17 15:29:49.086278 2026] [fcgid:warn] [pid 16723:tid 16924] (70014)End of file found: [client 128.1.131.203:54348] mod_fcgid: can't get data from http client
[Thu Sep 17 15:29:49.163083 2026] [security2:error] [pid 16723:tid 16868] [client 103.61.184.148:54127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbzS9E0uOV11S2qN6g3AAAAJM"]
[Thu Sep 17 15:29:49.163230 2026] [security2:error] [pid 16723:tid 16868] [client 103.61.184.148:54127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxbzS9E0uOV11S2qN6g3AAAAJM"]
[Thu Sep 17 15:29:49.168321 2026] [security2:error] [pid 1029697:tid 1029882] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/tmp/.env"] [unique_id "aqxbzW65wm-f4uX16X6kYQAAADc"]
[Thu Sep 17 15:29:49.335601 2026] [security2:error] [pid 1029697:tid 1029950] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/temp/.env"] [unique_id "aqxbzW65wm-f4uX16X6kYwAAAHs"]
[Thu Sep 17 15:29:49.476578 2026] [security2:error] [pid 16723:tid 16856] [client 34.166.113.162:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alexandernovelist.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxbzS9E0uOV11S2qN6g4AAAAIc"]
[Thu Sep 17 15:29:49.499128 2026] [security2:error] [pid 1029697:tid 1029835] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/lab/.env"] [unique_id "aqxbzW65wm-f4uX16X6kaQAAAAg"]
[Thu Sep 17 15:29:49.509363 2026] [fcgid:warn] [pid 16723:tid 16949] (70014)End of file found: [client 128.1.131.203:54388] mod_fcgid: can't get data from http client
[Thu Sep 17 15:29:49.541449 2026] [security2:error] [pid 1029697:tid 1029888] [client 127.0.0.1:16072] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxbzW65wm-f4uX16X6kagAAAD0"]
[Thu Sep 17 15:29:49.541449 2026] [security2:error] [pid 16723:tid 16956] [client 127.0.0.1:16060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.awesome8s.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxbzS9E0uOV11S2qN6g4QAAAOs"]
[Thu Sep 17 15:29:49.541562 2026] [security2:error] [pid 1029697:tid 1029916] [client 74.7.228.9:33866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.awesome8s.com"] [uri "/robots.txt"] [unique_id "aqxbzW65wm-f4uX16X6kZwAAWVk"]
[Thu Sep 17 15:29:49.666216 2026] [security2:error] [pid 1029697:tid 1029944] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/cronlab/.env"] [unique_id "aqxbzW65wm-f4uX16X6kawAAAHU"]
[Thu Sep 17 15:29:49.833314 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/cron/.env"] [unique_id "aqxbzW65wm-f4uX16X6kbQAAAHo"]
[Thu Sep 17 15:29:49.987829 2026] [security2:error] [pid 1029697:tid 1029837] [client 45.12.3.114:56060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.3.12.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wheresmymap.com"] [uri "/images/images/cache.php"] [unique_id "aqxbzW65wm-f4uX16X6kbwAAAAo"]
[Thu Sep 17 15:29:49.992221 2026] [security2:error] [pid 1029697:tid 1029830] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/en/.env"] [unique_id "aqxbzW65wm-f4uX16X6kcAAAAAM"]
[Thu Sep 17 15:29:50.244405 2026] [security2:error] [pid 1029697:tid 1029903] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/administrator/.env"] [unique_id "aqxbzm65wm-f4uX16X6kcgAAAEw"]
[Thu Sep 17 15:29:50.400041 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/psnlink/.env"] [unique_id "aqxbzm65wm-f4uX16X6kdAAAAEQ"]
[Thu Sep 17 15:29:50.553839 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/exapi/.env"] [unique_id "aqxbzm65wm-f4uX16X6keAAAAGc"]
[Thu Sep 17 15:29:50.644143 2026] [security2:error] [pid 16723:tid 16925] [client 114.198.138.124:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbzi9E0uOV11S2qN6g_gAAAMw"]
[Thu Sep 17 15:29:50.644499 2026] [security2:error] [pid 16723:tid 16925] [client 114.198.138.124:50898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxbzi9E0uOV11S2qN6g_gAAAMw"]
[Thu Sep 17 15:29:50.706159 2026] [security2:error] [pid 1029697:tid 1029921] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/sitemaps/.env"] [unique_id "aqxbzm65wm-f4uX16X6kfgAAAF4"]
[Thu Sep 17 15:29:50.884927 2026] [security2:error] [pid 1029697:tid 1029856] [client 3.19.142.206:52785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzm65wm-f4uX16X6kgQAAAB0"]
[Thu Sep 17 15:29:50.884988 2026] [security2:error] [pid 1029697:tid 1029856] [client 3.19.142.206:52785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzm65wm-f4uX16X6kgQAAAB0"]
[Thu Sep 17 15:29:50.907056 2026] [security2:error] [pid 16723:tid 16963] [client 3.19.142.206:52828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzi9E0uOV11S2qN6hBAAAAPI"]
[Thu Sep 17 15:29:50.907109 2026] [security2:error] [pid 16723:tid 16963] [client 3.19.142.206:52828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzi9E0uOV11S2qN6hBAAAAPI"]
[Thu Sep 17 15:29:50.913322 2026] [security2:error] [pid 16723:tid 16977] [client 3.19.142.206:52818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzi9E0uOV11S2qN6hBwAAAQA"]
[Thu Sep 17 15:29:50.913355 2026] [security2:error] [pid 16723:tid 16977] [client 3.19.142.206:52818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzi9E0uOV11S2qN6hBwAAAQA"]
[Thu Sep 17 15:29:51.047025 2026] [security2:error] [pid 16723:tid 16881] [client 3.19.142.206:52818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzy9E0uOV11S2qN6hCgAAAKA"]
[Thu Sep 17 15:29:51.047088 2026] [security2:error] [pid 16723:tid 16881] [client 3.19.142.206:52818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzy9E0uOV11S2qN6hCgAAAKA"]
[Thu Sep 17 15:29:51.065127 2026] [security2:error] [pid 1029697:tid 1029919] [client 3.19.142.206:52785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbz265wm-f4uX16X6khgAAAFw"]
[Thu Sep 17 15:29:51.065190 2026] [security2:error] [pid 1029697:tid 1029919] [client 3.19.142.206:52785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbz265wm-f4uX16X6khgAAAFw"]
[Thu Sep 17 15:29:51.072444 2026] [security2:error] [pid 16723:tid 16935] [client 3.19.142.206:52828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzy9E0uOV11S2qN6hCwAAANY"]
[Thu Sep 17 15:29:51.072503 2026] [security2:error] [pid 16723:tid 16935] [client 3.19.142.206:52828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/xmlrpc.php"] [unique_id "aqxbzy9E0uOV11S2qN6hCwAAANY"]
[Thu Sep 17 15:29:51.280568 2026] [security2:error] [pid 1029697:tid 1029828] [client 34.154.232.68:50438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/logs/.env"] [unique_id "aqxbz265wm-f4uX16X6kigAAAAE"]
[Thu Sep 17 15:29:51.538820 2026] [security2:error] [pid 16723:tid 16885] [client 204.16.112.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxbzS9E0uOV11S2qN6g6AAAAKQ"], referer: https://facebook.com/
[Thu Sep 17 15:29:51.770269 2026] [security2:error] [pid 16723:tid 16956] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/cache/.env"] [unique_id "aqxbzy9E0uOV11S2qN6hGAAAAOs"]
[Thu Sep 17 15:29:51.932723 2026] [security2:error] [pid 16723:tid 16883] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mailer/.env"] [unique_id "aqxbzy9E0uOV11S2qN6hHQAAAKI"]
[Thu Sep 17 15:29:52.006072 2026] [security2:error] [pid 16723:tid 16896] [client 34.31.203.120:13313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxbzy9E0uOV11S2qN6hDgAArxg"]
[Thu Sep 17 15:29:52.098346 2026] [security2:error] [pid 16723:tid 16966] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mail/.env"] [unique_id "aqxb0C9E0uOV11S2qN6hJgAAAPU"]
[Thu Sep 17 15:29:52.257920 2026] [security2:error] [pid 16723:tid 16919] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/email/.env"] [unique_id "aqxb0C9E0uOV11S2qN6hKwAAAMY"]
[Thu Sep 17 15:29:52.271346 2026] [security2:error] [pid 16723:tid 16903] [client 34.31.203.120:13313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxb0C9E0uOV11S2qN6hIwAAtiY"]
[Thu Sep 17 15:29:52.418920 2026] [security2:error] [pid 16723:tid 16906] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/smtp/.env"] [unique_id "aqxb0C9E0uOV11S2qN6hMwAAALk"]
[Thu Sep 17 15:29:52.432155 2026] [security2:error] [pid 16723:tid 16879] [client 82.102.18.118:59696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "breathingboxing.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxb0C9E0uOV11S2qN6hNAAAAJ4"]
[Thu Sep 17 15:29:52.587940 2026] [security2:error] [pid 16723:tid 16934] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mailing/.env"] [unique_id "aqxb0C9E0uOV11S2qN6hOAAAANU"]
[Thu Sep 17 15:29:52.749300 2026] [security2:error] [pid 16723:tid 16932] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/notifications/.env"] [unique_id "aqxb0C9E0uOV11S2qN6hOgAAANM"]
[Thu Sep 17 15:29:52.920469 2026] [security2:error] [pid 16723:tid 16858] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/notify/.env"] [unique_id "aqxb0C9E0uOV11S2qN6hPQAAAIk"]
[Thu Sep 17 15:29:53.090937 2026] [security2:error] [pid 16723:tid 16874] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/sender/.env"] [unique_id "aqxb0S9E0uOV11S2qN6hQwAAAJk"]
[Thu Sep 17 15:29:53.132037 2026] [security2:error] [pid 16723:tid 16959] [client 82.102.18.118:59710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "breathingboxing.org"] [uri "/xmlrpc.php"] [unique_id "aqxb0S9E0uOV11S2qN6hRQAAAO4"]
[Thu Sep 17 15:29:53.250284 2026] [security2:error] [pid 16723:tid 16866] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/campaign/.env"] [unique_id "aqxb0S9E0uOV11S2qN6hSAAAAJE"]
[Thu Sep 17 15:29:53.324042 2026] [security2:error] [pid 16723:tid 16898] [client 3.19.142.206:53779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb0S9E0uOV11S2qN6hSgAAALE"]
[Thu Sep 17 15:29:53.409144 2026] [security2:error] [pid 16723:tid 16916] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/newsletter/.env"] [unique_id "aqxb0S9E0uOV11S2qN6hTAAAAMM"]
[Thu Sep 17 15:29:53.567576 2026] [security2:error] [pid 16723:tid 16868] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/ses/.env"] [unique_id "aqxb0S9E0uOV11S2qN6hUQAAAJM"]
[Thu Sep 17 15:29:53.680304 2026] [security2:error] [pid 1029697:tid 1029824] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.env"] [unique_id "aqxb0W65wm-f4uX16X6kuQAARH4"]
[Thu Sep 17 15:29:53.728552 2026] [security2:error] [pid 16723:tid 16904] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/sendgrid/.env"] [unique_id "aqxb0S9E0uOV11S2qN6hVQAAALc"]
[Thu Sep 17 15:29:53.899647 2026] [security2:error] [pid 16723:tid 16953] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/sparkpost/.env"] [unique_id "aqxb0S9E0uOV11S2qN6hXQAAAOg"]
[Thu Sep 17 15:29:53.982863 2026] [security2:error] [pid 16723:tid 16960] [client 181.124.145.243:20880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb0S9E0uOV11S2qN6hWQAA7yA"]
[Thu Sep 17 15:29:53.984509 2026] [security2:error] [pid 16723:tid 16923] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0S9E0uOV11S2qN6hVwAAAMo"]
[Thu Sep 17 15:29:53.999553 2026] [security2:error] [pid 1029697:tid 1029744] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.env.bak"] [unique_id "aqxb0W65wm-f4uX16X6kyAAARC4"]
[Thu Sep 17 15:29:53.999556 2026] [security2:error] [pid 1029697:tid 1029756] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.env.old"] [unique_id "aqxb0W65wm-f4uX16X6kxQAARDo"]
[Thu Sep 17 15:29:53.999568 2026] [security2:error] [pid 1029697:tid 1029735] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.env.backup"] [unique_id "aqxb0W65wm-f4uX16X6kyQAARCU"]
[Thu Sep 17 15:29:54.059558 2026] [security2:error] [pid 16723:tid 16966] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/postmark/.env"] [unique_id "aqxb0i9E0uOV11S2qN6hZwAAAPU"]
[Thu Sep 17 15:29:54.084169 2026] [security2:error] [pid 16723:tid 16861] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0S9E0uOV11S2qN6hXAAAAIw"]
[Thu Sep 17 15:29:54.087169 2026] [security2:error] [pid 16723:tid 16946] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0S9E0uOV11S2qN6hXgAAAOE"]
[Thu Sep 17 15:29:54.104772 2026] [security2:error] [pid 1029697:tid 1029951] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0W65wm-f4uX16X6kxAAAAHw"]
[Thu Sep 17 15:29:54.105040 2026] [security2:error] [pid 1029697:tid 1029906] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0W65wm-f4uX16X6kwwAAAE8"]
[Thu Sep 17 15:29:54.123793 2026] [security2:error] [pid 16723:tid 16955] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0S9E0uOV11S2qN6hXwAAAOo"]
[Thu Sep 17 15:29:54.140029 2026] [security2:error] [pid 1029697:tid 1029710] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/.env.php"] [unique_id "aqxb0m65wm-f4uX16X6k4AAARAw"]
[Thu Sep 17 15:29:54.142109 2026] [security2:error] [pid 1029697:tid 1029710] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.env~"] [unique_id "aqxb0m65wm-f4uX16X6k4QAARAw"]
[Thu Sep 17 15:29:54.206975 2026] [security2:error] [pid 16723:tid 16974] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hZQAAAP0"]
[Thu Sep 17 15:29:54.228006 2026] [security2:error] [pid 16723:tid 16927] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mailgun/.env"] [unique_id "aqxb0i9E0uOV11S2qN6hawAAAM4"]
[Thu Sep 17 15:29:54.234040 2026] [security2:error] [pid 1029697:tid 1029768] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.env.swp"] [unique_id "aqxb0m65wm-f4uX16X6k5QAAREY"]
[Thu Sep 17 15:29:54.249069 2026] [security2:error] [pid 1029697:tid 1029904] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k3AAAAE0"]
[Thu Sep 17 15:29:54.249069 2026] [security2:error] [pid 1029697:tid 1029919] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k2gAAAFw"]
[Thu Sep 17 15:29:54.261121 2026] [security2:error] [pid 16723:tid 16876] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hZgAAAJs"]
[Thu Sep 17 15:29:54.261334 2026] [security2:error] [pid 1029697:tid 1029894] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k2QAAAEM"]
[Thu Sep 17 15:29:54.261721 2026] [security2:error] [pid 16723:tid 16942] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6haAAAAN0"]
[Thu Sep 17 15:29:54.261882 2026] [security2:error] [pid 1029697:tid 1029857] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k2wAAAB4"]
[Thu Sep 17 15:29:54.287627 2026] [security2:error] [pid 1029697:tid 1029719] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/api/.env"] [unique_id "aqxb0m65wm-f4uX16X6k7QAARBU"]
[Thu Sep 17 15:29:54.374732 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k5AAAAGs"]
[Thu Sep 17 15:29:54.390724 2026] [security2:error] [pid 16723:tid 16871] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mandrill/.env"] [unique_id "aqxb0i9E0uOV11S2qN6hdQAAAJY"]
[Thu Sep 17 15:29:54.394892 2026] [security2:error] [pid 16723:tid 16951] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hagAAAOY"]
[Thu Sep 17 15:29:54.398586 2026] [security2:error] [pid 1029697:tid 1029732] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/backend/.env"] [unique_id "aqxb0m65wm-f4uX16X6k8wAARCI"]
[Thu Sep 17 15:29:54.398595 2026] [security2:error] [pid 1029697:tid 1029814] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/app/.env"] [unique_id "aqxb0m65wm-f4uX16X6k8AAARHQ"]
[Thu Sep 17 15:29:54.404553 2026] [security2:error] [pid 1029697:tid 1029733] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/server/.env"] [unique_id "aqxb0m65wm-f4uX16X6k9gAARCM"]
[Thu Sep 17 15:29:54.418616 2026] [security2:error] [pid 1029697:tid 1029791] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/config/.env"] [unique_id "aqxb0m65wm-f4uX16X6k-AAARF0"]
[Thu Sep 17 15:29:54.418638 2026] [security2:error] [pid 1029697:tid 1029742] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/src/.env"] [unique_id "aqxb0m65wm-f4uX16X6k-QAARCw"]
[Thu Sep 17 15:29:54.432099 2026] [security2:error] [pid 1029697:tid 1029794] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/web/.env"] [unique_id "aqxb0m65wm-f4uX16X6k-gAARGA"]
[Thu Sep 17 15:29:54.484895 2026] [security2:error] [pid 16723:tid 16869] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hcQAAAJQ"]
[Thu Sep 17 15:29:54.489765 2026] [security2:error] [pid 16723:tid 16867] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hcAAAAJI"]
[Thu Sep 17 15:29:54.507191 2026] [security2:error] [pid 16723:tid 16905] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hcwAAALg"]
[Thu Sep 17 15:29:54.512983 2026] [security2:error] [pid 1029697:tid 1029877] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k7gAAADI"]
[Thu Sep 17 15:29:54.538906 2026] [security2:error] [pid 1029697:tid 1029760] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/client/.env"] [unique_id "aqxb0m65wm-f4uX16X6lAgAARD4"]
[Thu Sep 17 15:29:54.538910 2026] [security2:error] [pid 1029697:tid 1029715] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/frontend/.env"] [unique_id "aqxb0m65wm-f4uX16X6lAwAARBE"]
[Thu Sep 17 15:29:54.543747 2026] [security2:error] [pid 1029697:tid 1029725] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/public/.env"] [unique_id "aqxb0m65wm-f4uX16X6lBAAARBs"]
[Thu Sep 17 15:29:54.545181 2026] [security2:error] [pid 16723:tid 16877] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hcgAAAJw"]
[Thu Sep 17 15:29:54.556292 2026] [security2:error] [pid 16723:tid 16932] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mailjet/.env"] [unique_id "aqxb0i9E0uOV11S2qN6heQAAANM"]
[Thu Sep 17 15:29:54.560147 2026] [security2:error] [pid 1029697:tid 1029700] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/laravel/.env"] [unique_id "aqxb0m65wm-f4uX16X6lBQAARAI"]
[Thu Sep 17 15:29:54.560183 2026] [security2:error] [pid 1029697:tid 1029805] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/application/.env"] [unique_id "aqxb0m65wm-f4uX16X6lCAAARGs"]
[Thu Sep 17 15:29:54.560227 2026] [security2:error] [pid 1029697:tid 1029721] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/var/www/.env"] [unique_id "aqxb0m65wm-f4uX16X6lBwAARBc"]
[Thu Sep 17 15:29:54.560258 2026] [security2:error] [pid 1029697:tid 1029808] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/var/www/html/.env"] [unique_id "aqxb0m65wm-f4uX16X6lBgAARG4"]
[Thu Sep 17 15:29:54.574200 2026] [security2:error] [pid 1029697:tid 1029748] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/apps/.env"] [unique_id "aqxb0m65wm-f4uX16X6lCQAARDI"]
[Thu Sep 17 15:29:54.576334 2026] [security2:error] [pid 1029697:tid 1029884] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k_AAAADk"]
[Thu Sep 17 15:29:54.581997 2026] [security2:error] [pid 1029697:tid 1029861] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0m65wm-f4uX16X6k_QAAACI"]
[Thu Sep 17 15:29:54.618283 2026] [security2:error] [pid 16723:tid 16952] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hdwAAAOc"]
[Thu Sep 17 15:29:54.637783 2026] [security2:error] [pid 1029697:tid 1029702] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/backup/.env"] [unique_id "aqxb0m65wm-f4uX16X6lCwAARAQ"]
[Thu Sep 17 15:29:54.637832 2026] [security2:error] [pid 1029697:tid 1029792] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/back/.env"] [unique_id "aqxb0m65wm-f4uX16X6lDAAARF4"]
[Thu Sep 17 15:29:54.679459 2026] [security2:error] [pid 1029697:tid 1029823] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/prod/.env"] [unique_id "aqxb0m65wm-f4uX16X6lDwAAKn0"]
[Thu Sep 17 15:29:54.679474 2026] [security2:error] [pid 1029697:tid 1029766] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/production/.env"] [unique_id "aqxb0m65wm-f4uX16X6lEAAAKkQ"]
[Thu Sep 17 15:29:54.679498 2026] [security2:error] [pid 1029697:tid 1029790] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/dev/.env"] [unique_id "aqxb0m65wm-f4uX16X6lDgAAKlw"]
[Thu Sep 17 15:29:54.679571 2026] [security2:error] [pid 1029697:tid 1029757] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/cms/.env"] [unique_id "aqxb0m65wm-f4uX16X6lDQAAKjs"]
[Thu Sep 17 15:29:54.697843 2026] [security2:error] [pid 1029697:tid 1029767] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/staging/.env"] [unique_id "aqxb0m65wm-f4uX16X6lEQAAUEU"]
[Thu Sep 17 15:29:54.718044 2026] [security2:error] [pid 1029697:tid 1029779] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/new/.env"] [unique_id "aqxb0m65wm-f4uX16X6lEwAAI1E"]
[Thu Sep 17 15:29:54.718045 2026] [security2:error] [pid 1029697:tid 1029770] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/node-api/.env"] [unique_id "aqxb0m65wm-f4uX16X6lFgAAI0g"]
[Thu Sep 17 15:29:54.718046 2026] [security2:error] [pid 1029697:tid 1029804] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/api-backend/.env"] [unique_id "aqxb0m65wm-f4uX16X6lFQAAI2o"]
[Thu Sep 17 15:29:54.718046 2026] [security2:error] [pid 1029697:tid 1029738] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/test/.env"] [unique_id "aqxb0m65wm-f4uX16X6lEgAAIyg"]
[Thu Sep 17 15:29:54.718095 2026] [security2:error] [pid 1029697:tid 1029817] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/admin-app/.env"] [unique_id "aqxb0m65wm-f4uX16X6lFwAAI3c"]
[Thu Sep 17 15:29:54.718102 2026] [security2:error] [pid 1029697:tid 1029718] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/old/.env"] [unique_id "aqxb0m65wm-f4uX16X6lFAAAIxQ"]
[Thu Sep 17 15:29:54.718483 2026] [security2:error] [pid 16723:tid 16950] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/brevo/.env"] [unique_id "aqxb0i9E0uOV11S2qN6hewAAAOU"]
[Thu Sep 17 15:29:54.740185 2026] [security2:error] [pid 1029697:tid 1029764] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/public_html/.env"] [unique_id "aqxb0m65wm-f4uX16X6lGAAAB0I"]
[Thu Sep 17 15:29:54.778986 2026] [security2:error] [pid 1029697:tid 1029815] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/server/api/.env"] [unique_id "aqxb0m65wm-f4uX16X6lGgAAB3U"]
[Thu Sep 17 15:29:54.778988 2026] [security2:error] [pid 1029697:tid 1029712] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/current/.env"] [unique_id "aqxb0m65wm-f4uX16X6lGwAABw4"]
[Thu Sep 17 15:29:54.796289 2026] [security2:error] [pid 1029697:tid 1029786] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/server/backend/.env"] [unique_id "aqxb0m65wm-f4uX16X6lHAAAB1g"]
[Thu Sep 17 15:29:54.824270 2026] [security2:error] [pid 1029697:tid 1029751] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.docker/.env"] [unique_id "aqxb0m65wm-f4uX16X6lHgAABzU"]
[Thu Sep 17 15:29:54.824317 2026] [security2:error] [pid 1029697:tid 1029816] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxb0m65wm-f4uX16X6lHwAAB3Y"]
[Thu Sep 17 15:29:54.824326 2026] [security2:error] [pid 1029697:tid 1029717] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/aws/.env"] [unique_id "aqxb0m65wm-f4uX16X6lHQAABxM"]
[Thu Sep 17 15:29:54.824364 2026] [security2:error] [pid 1029697:tid 1029747] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.aws/.env"] [unique_id "aqxb0m65wm-f4uX16X6lIAAABzE"]
[Thu Sep 17 15:29:54.838322 2026] [authz_core:error] [pid 16723:tid 16921] [client 4.240.114.86:51875] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:29:54.846924 2026] [security2:error] [pid 1029697:tid 1029801] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/stripe/.env"] [unique_id "aqxb0m65wm-f4uX16X6lIQAAB2c"]
[Thu Sep 17 15:29:54.851759 2026] [security2:error] [pid 1029697:tid 1029807] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/administrator/.env"] [unique_id "aqxb0m65wm-f4uX16X6lGQAAB20"]
[Thu Sep 17 15:29:54.861074 2026] [security2:error] [pid 1029697:tid 1029729] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/v2/.env"] [unique_id "aqxb0m65wm-f4uX16X6lJQAARx8"]
[Thu Sep 17 15:29:54.861075 2026] [security2:error] [pid 1029697:tid 1029802] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/v3/.env"] [unique_id "aqxb0m65wm-f4uX16X6lJgAAR2g"]
[Thu Sep 17 15:29:54.861109 2026] [security2:error] [pid 1029697:tid 1029706] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/v1/.env"] [unique_id "aqxb0m65wm-f4uX16X6lIwAARwg"]
[Thu Sep 17 15:29:54.861200 2026] [security2:error] [pid 1029697:tid 1029716] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/media/.env"] [unique_id "aqxb0m65wm-f4uX16X6lJwAARxI"]
[Thu Sep 17 15:29:54.879869 2026] [security2:error] [pid 16723:tid 16975] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/transactional/.env"] [unique_id "aqxb0i9E0uOV11S2qN6hgQAAAP4"]
[Thu Sep 17 15:29:54.920573 2026] [security2:error] [pid 16723:tid 16979] [client 74.7.244.49:60166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "sd-yaranaturals.24eastyard.com"] [uri "/index.php/robots.txt"] [unique_id "aqxbzy9E0uOV11S2qN6hHAABAiw"]
[Thu Sep 17 15:29:54.920602 2026] [security2:error] [pid 16723:tid 16979] [client 74.7.244.49:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sd-yaranaturals.24eastyard.com"] [uri "/index.php/robots.txt"] [unique_id "aqxbzy9E0uOV11S2qN6hHAABAiw"]
[Thu Sep 17 15:29:55.003155 2026] [security2:error] [pid 1029697:tid 1029810] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.git/config.bak"] [unique_id "aqxb0265wm-f4uX16X6lOwAAR3A"]
[Thu Sep 17 15:29:55.042468 2026] [security2:error] [pid 16723:tid 16916] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/bulk/.env"] [unique_id "aqxb0y9E0uOV11S2qN6hjwAAAMM"]
[Thu Sep 17 15:29:55.125257 2026] [security2:error] [pid 16723:tid 16913] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hhQAAAMA"]
[Thu Sep 17 15:29:55.147868 2026] [security2:error] [pid 16723:tid 16964] [client 74.7.244.49:60166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sd-yaranaturals.24eastyard.com"] [uri "/index.php/robots.txt/"] [unique_id "aqxb0i9E0uOV11S2qN6hiAAA8wk"], referer: https://sd-yaranaturals.24eastyard.com/robots.txt
[Thu Sep 17 15:29:55.163961 2026] [security2:error] [pid 16723:tid 16922] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0i9E0uOV11S2qN6hhwAAAMk"]
[Thu Sep 17 15:29:55.204987 2026] [security2:error] [pid 1029697:tid 1029847] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0265wm-f4uX16X6lQAAAABQ"]
[Thu Sep 17 15:29:55.205140 2026] [security2:error] [pid 16723:tid 16860] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/aws/.env"] [unique_id "aqxb0y9E0uOV11S2qN6hmQAAAIs"]
[Thu Sep 17 15:29:55.211021 2026] [security2:error] [pid 16723:tid 16856] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hjgAAAIc"]
[Thu Sep 17 15:29:55.257538 2026] [security2:error] [pid 16723:tid 16880] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hjQAAAJ8"]
[Thu Sep 17 15:29:55.267627 2026] [security2:error] [pid 1029697:tid 1029920] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0265wm-f4uX16X6lPwAAAF0"]
[Thu Sep 17 15:29:55.286968 2026] [security2:error] [pid 16723:tid 16920] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hjAAAAMc"]
[Thu Sep 17 15:29:55.295193 2026] [security2:error] [pid 16723:tid 16892] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hkQAAAKs"]
[Thu Sep 17 15:29:55.296619 2026] [security2:error] [pid 16723:tid 16872] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hlQAAAJc"]
[Thu Sep 17 15:29:55.297609 2026] [security2:error] [pid 16723:tid 16956] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hkgAAAOs"]
[Thu Sep 17 15:29:55.309331 2026] [security2:error] [pid 16723:tid 16863] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hkAAAAI4"]
[Thu Sep 17 15:29:55.310025 2026] [security2:error] [pid 16723:tid 16957] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hkwAAAOw"]
[Thu Sep 17 15:29:55.333823 2026] [security2:error] [pid 1029697:tid 1029900] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0265wm-f4uX16X6lQgAAAEk"]
[Thu Sep 17 15:29:55.333905 2026] [security2:error] [pid 16723:tid 16868] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hlgAAAJM"]
[Thu Sep 17 15:29:55.373679 2026] [security2:error] [pid 16723:tid 16895] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/azure/.env"] [unique_id "aqxb0y9E0uOV11S2qN6hnwAAAK4"]
[Thu Sep 17 15:29:55.385420 2026] [security2:error] [pid 1029697:tid 1029949] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0265wm-f4uX16X6lRAAAAHo"]
[Thu Sep 17 15:29:55.428728 2026] [security2:error] [pid 16723:tid 16969] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hmgAAAPg"]
[Thu Sep 17 15:29:55.436498 2026] [security2:error] [pid 1029697:tid 1029728] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxb0265wm-f4uX16X6lTgAARx4"]
[Thu Sep 17 15:29:55.468417 2026] [security2:error] [pid 1029697:tid 1029785] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxb0265wm-f4uX16X6lUwAAR1c"]
[Thu Sep 17 15:29:55.470611 2026] [security2:error] [pid 1029697:tid 1029743] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/id_rsa"] [unique_id "aqxb0265wm-f4uX16X6lVQAARy0"]
[Thu Sep 17 15:29:55.510384 2026] [security2:error] [pid 16723:tid 16927] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hnAAAAM4"]
[Thu Sep 17 15:29:55.538335 2026] [security2:error] [pid 16723:tid 16879] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/gcp/.env"] [unique_id "aqxb0y9E0uOV11S2qN6hqAAAAJ4"]
[Thu Sep 17 15:29:55.560722 2026] [security2:error] [pid 16723:tid 16857] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hoAAAAIg"]
[Thu Sep 17 15:29:55.582466 2026] [security2:error] [pid 16723:tid 16876] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hoQAAAJs"]
[Thu Sep 17 15:29:55.595146 2026] [security2:error] [pid 1029697:tid 1029902] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0265wm-f4uX16X6lSwAAAEs"]
[Thu Sep 17 15:29:55.641581 2026] [security2:error] [pid 16723:tid 16938] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hpQAAANk"]
[Thu Sep 17 15:29:55.694791 2026] [security2:error] [pid 16723:tid 16900] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hpgAAALM"]
[Thu Sep 17 15:29:55.699443 2026] [security2:error] [pid 16723:tid 16881] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/cloud/.env"] [unique_id "aqxb0y9E0uOV11S2qN6hsgAAAKA"]
[Thu Sep 17 15:29:55.705406 2026] [security2:error] [pid 16723:tid 16906] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hqQAAALk"]
[Thu Sep 17 15:29:55.706654 2026] [security2:error] [pid 16723:tid 16931] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hpwAAANI"]
[Thu Sep 17 15:29:55.744509 2026] [security2:error] [pid 16723:tid 16891] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hqgAAAKo"]
[Thu Sep 17 15:29:55.744509 2026] [security2:error] [pid 16723:tid 16871] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hrAAAAJY"]
[Thu Sep 17 15:29:55.863822 2026] [security2:error] [pid 16723:tid 16893] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/infrastructure/.env"] [unique_id "aqxb0y9E0uOV11S2qN6hvwAAAKw"]
[Thu Sep 17 15:29:55.873723 2026] [security2:error] [pid 16723:tid 16948] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hsQAAAOM"]
[Thu Sep 17 15:29:56.023743 2026] [security2:error] [pid 16723:tid 16923] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/docker/.env"] [unique_id "aqxb1C9E0uOV11S2qN6hygAAAMo"]
[Thu Sep 17 15:29:56.024405 2026] [security2:error] [pid 1029697:tid 1029699] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/config.php"] [unique_id "aqxb1G65wm-f4uX16X6lggAARwE"]
[Thu Sep 17 15:29:56.187478 2026] [security2:error] [pid 16723:tid 16856] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/k8s/.env"] [unique_id "aqxb1C9E0uOV11S2qN6hzQAAAIc"]
[Thu Sep 17 15:29:56.264674 2026] [security2:error] [pid 16723:tid 16971] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6htwAAAPo"]
[Thu Sep 17 15:29:56.264687 2026] [security2:error] [pid 16723:tid 16979] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6huAAAAQI"]
[Thu Sep 17 15:29:56.309389 2026] [security2:error] [pid 16723:tid 16945] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hugAAAOA"]
[Thu Sep 17 15:29:56.327853 2026] [security2:error] [pid 16723:tid 16907] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hxgAAALo"]
[Thu Sep 17 15:29:56.327858 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0265wm-f4uX16X6lcAAAAH8"]
[Thu Sep 17 15:29:56.328623 2026] [security2:error] [pid 16723:tid 16862] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hwQAAAI0"]
[Thu Sep 17 15:29:56.329884 2026] [security2:error] [pid 16723:tid 16916] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hwAAAAMM"]
[Thu Sep 17 15:29:56.346095 2026] [security2:error] [pid 16723:tid 16863] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/kubernetes/.env"] [unique_id "aqxb1C9E0uOV11S2qN6h0wAAAI4"]
[Thu Sep 17 15:29:56.355402 2026] [security2:error] [pid 16723:tid 16886] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hxAAAAKU"]
[Thu Sep 17 15:29:56.357501 2026] [security2:error] [pid 1029697:tid 1029910] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0265wm-f4uX16X6ldwAAAFM"]
[Thu Sep 17 15:29:56.379977 2026] [security2:error] [pid 16723:tid 16874] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hxwAAAJk"]
[Thu Sep 17 15:29:56.431496 2026] [security2:error] [pid 1029697:tid 1029924] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6ljgAAAGE"]
[Thu Sep 17 15:29:56.434294 2026] [security2:error] [pid 1029697:tid 1029947] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6lgAAAAHg"]
[Thu Sep 17 15:29:56.434333 2026] [security2:error] [pid 16723:tid 16922] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb0y9E0uOV11S2qN6hyQAAAMk"]
[Thu Sep 17 15:29:56.434485 2026] [security2:error] [pid 16723:tid 16860] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6hzAAAAIs"]
[Thu Sep 17 15:29:56.463455 2026] [security2:error] [pid 16723:tid 16943] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h0QAAAN4"]
[Thu Sep 17 15:29:56.477982 2026] [security2:error] [pid 1029697:tid 1029732] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/config/aws.php"] [unique_id "aqxb1G65wm-f4uX16X6lmgAARyI"]
[Thu Sep 17 15:29:56.510682 2026] [security2:error] [pid 16723:tid 16969] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/terraform/.env"] [unique_id "aqxb1C9E0uOV11S2qN6h2wAAAPg"]
[Thu Sep 17 15:29:56.514003 2026] [security2:error] [pid 1029697:tid 1029740] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/config/stripe.php"] [unique_id "aqxb1G65wm-f4uX16X6lnwAARyo"]
[Thu Sep 17 15:29:56.574262 2026] [security2:error] [pid 16723:tid 16955] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h1AAAAOo"]
[Thu Sep 17 15:29:56.575466 2026] [security2:error] [pid 1029697:tid 1029742] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/config/mail.php"] [unique_id "aqxb1G65wm-f4uX16X6lowAARyw"]
[Thu Sep 17 15:29:56.581802 2026] [security2:error] [pid 1029697:tid 1029794] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/config/config.inc.php"] [unique_id "aqxb1G65wm-f4uX16X6lpAAAR2A"]
[Thu Sep 17 15:29:56.582270 2026] [security2:error] [pid 1029697:tid 1029774] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/config/nexmo.php"] [unique_id "aqxb1G65wm-f4uX16X6lpQAAR0w"]
[Thu Sep 17 15:29:56.620194 2026] [security2:error] [pid 1029697:tid 1029760] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/wp-config.php"] [unique_id "aqxb1G65wm-f4uX16X6lqgAARz4"]
[Thu Sep 17 15:29:56.643128 2026] [security2:error] [pid 16723:tid 16895] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h2gAAAK4"]
[Thu Sep 17 15:29:56.652691 2026] [security2:error] [pid 1029697:tid 1029725] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "moroccohometravel.com"] [uri "/wp-config.php.bak"] [unique_id "aqxb1G65wm-f4uX16X6lrAAARxs"]
[Thu Sep 17 15:29:56.653210 2026] [security2:error] [pid 1029697:tid 1029838] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6lnAAAAAs"]
[Thu Sep 17 15:29:56.654902 2026] [security2:error] [pid 1029697:tid 1029789] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "moroccohometravel.com"] [uri "/wp-config.php.old"] [unique_id "aqxb1G65wm-f4uX16X6lrQAAR1s"]
[Thu Sep 17 15:29:56.655970 2026] [security2:error] [pid 1029697:tid 1029912] [client 200.195.114.32:14906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb1G65wm-f4uX16X6lngAAVSM"]
[Thu Sep 17 15:29:56.667419 2026] [security2:error] [pid 16723:tid 16857] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/ansible/.env"] [unique_id "aqxb1C9E0uOV11S2qN6h4wAAAIg"]
[Thu Sep 17 15:29:56.678554 2026] [security2:error] [pid 1029697:tid 1029846] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6loQAAABM"]
[Thu Sep 17 15:29:56.690369 2026] [security2:error] [pid 16723:tid 16912] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h3QAAAL8"]
[Thu Sep 17 15:29:56.709084 2026] [security2:error] [pid 1029697:tid 1029788] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "moroccohometravel.com"] [uri "/wp-config.php.new"] [unique_id "aqxb1G65wm-f4uX16X6lsAAAR1o"]
[Thu Sep 17 15:29:56.711959 2026] [security2:error] [pid 16723:tid 16875] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h3wAAAJo"]
[Thu Sep 17 15:29:56.716418 2026] [security2:error] [pid 1029697:tid 1029700] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxb1G65wm-f4uX16X6lsQAARwI"]
[Thu Sep 17 15:29:56.760631 2026] [security2:error] [pid 1029697:tid 1029748] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxb1G65wm-f4uX16X6luAAARzI"]
[Thu Sep 17 15:29:56.787414 2026] [security2:error] [pid 1029697:tid 1029745] [remote 47.128.16.62:21934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eco-tech.vn"] [uri "/robots.txt"] [unique_id "aqxb1G65wm-f4uX16X6lugAAPS8"]
[Thu Sep 17 15:29:56.830381 2026] [security2:error] [pid 16723:tid 16865] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/.git/.env"] [unique_id "aqxb1C9E0uOV11S2qN6h5gAAAJA"]
[Thu Sep 17 15:29:56.847817 2026] [security2:error] [pid 1029697:tid 1029823] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxb1G65wm-f4uX16X6lwQAAR30"]
[Thu Sep 17 15:29:56.851232 2026] [security2:error] [pid 1029697:tid 1029861] [client 136.158.61.34:38853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb1G65wm-f4uX16X6lwgAAACI"]
[Thu Sep 17 15:29:56.851334 2026] [security2:error] [pid 1029697:tid 1029861] [client 136.158.61.34:38853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb1G65wm-f4uX16X6lwgAAACI"]
[Thu Sep 17 15:29:56.998928 2026] [security2:error] [pid 16723:tid 16939] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/ci/.env"] [unique_id "aqxb1C9E0uOV11S2qN6h8QAAANo"]
[Thu Sep 17 15:29:57.160773 2026] [security2:error] [pid 16723:tid 16910] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/cd/.env"] [unique_id "aqxb1S9E0uOV11S2qN6h9gAAAL0"]
[Thu Sep 17 15:29:57.238397 2026] [fcgid:warn] [pid 1029697:tid 1029867] (70014)End of file found: [client 128.1.131.203:38120] mod_fcgid: can't get data from http client
[Thu Sep 17 15:29:57.289820 2026] [security2:error] [pid 1029697:tid 1029907] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6ltQAAAFA"]
[Thu Sep 17 15:29:57.295385 2026] [security2:error] [pid 16723:tid 16890] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h5AAAAKk"]
[Thu Sep 17 15:29:57.302319 2026] [security2:error] [pid 1029697:tid 1029898] [client 34.140.132.132:34528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6ltAAARxc"]
[Thu Sep 17 15:29:57.305703 2026] [security2:error] [pid 1029697:tid 1029869] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6ltgAAACo"]
[Thu Sep 17 15:29:57.321698 2026] [security2:error] [pid 16723:tid 16858] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/jenkins/.env"] [unique_id "aqxb1S9E0uOV11S2qN6h-AAAAIk"]
[Thu Sep 17 15:29:57.323538 2026] [security2:error] [pid 16723:tid 16869] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h5QAAAJQ"]
[Thu Sep 17 15:29:57.342507 2026] [security2:error] [pid 1029697:tid 1029880] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6luQAAADU"]
[Thu Sep 17 15:29:57.423171 2026] [security2:error] [pid 1029697:tid 1029927] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6l3wAAAGQ"]
[Thu Sep 17 15:29:57.426147 2026] [security2:error] [pid 16723:tid 16873] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h6AAAAJg"]
[Thu Sep 17 15:29:57.432923 2026] [security2:error] [pid 1029697:tid 1029827] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6lyQAAAAA"]
[Thu Sep 17 15:29:57.432923 2026] [security2:error] [pid 1029697:tid 1029926] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1G65wm-f4uX16X6lyAAAAGM"]
[Thu Sep 17 15:29:57.432949 2026] [security2:error] [pid 16723:tid 16961] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6h8wAAAPA"]
[Thu Sep 17 15:29:57.432950 2026] [security2:error] [pid 16723:tid 16855] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1C9E0uOV11S2qN6h7wAAAIY"]
[Thu Sep 17 15:29:57.440338 2026] [security2:error] [pid 16723:tid 16952] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6h9AAAAOc"]
[Thu Sep 17 15:29:57.449881 2026] [security2:error] [pid 16723:tid 16917] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6h9QAAAMQ"]
[Thu Sep 17 15:29:57.475888 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6l4QAAAHM"]
[Thu Sep 17 15:29:57.483367 2026] [security2:error] [pid 16723:tid 16916] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/gitlab/.env"] [unique_id "aqxb1S9E0uOV11S2qN6h_AAAAMM"]
[Thu Sep 17 15:29:57.504647 2026] [security2:error] [pid 1029697:tid 1029836] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6l4wAAAAk"]
[Thu Sep 17 15:29:57.639759 2026] [security2:error] [pid 16723:tid 16866] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/github/.env"] [unique_id "aqxb1S9E0uOV11S2qN6iAwAAAJE"]
[Thu Sep 17 15:29:57.722760 2026] [security2:error] [pid 1029697:tid 1029930] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6l7gAAAGc"]
[Thu Sep 17 15:29:57.749523 2026] [security2:error] [pid 16723:tid 16975] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6h_gAAAP4"]
[Thu Sep 17 15:29:57.753823 2026] [security2:error] [pid 1029697:tid 1029948] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6l8wAAAHk"]
[Thu Sep 17 15:29:57.781557 2026] [security2:error] [pid 16723:tid 16957] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iBAAAAOw"]
[Thu Sep 17 15:29:57.781656 2026] [security2:error] [pid 1029697:tid 1029892] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6l-QAAAEE"]
[Thu Sep 17 15:29:57.782971 2026] [security2:error] [pid 16723:tid 16863] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iAQAAAI4"]
[Thu Sep 17 15:29:57.798324 2026] [security2:error] [pid 16723:tid 16926] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/actions/.env"] [unique_id "aqxb1S9E0uOV11S2qN6iCgAAAM0"]
[Thu Sep 17 15:29:57.957180 2026] [security2:error] [pid 16723:tid 16857] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/circleci/.env"] [unique_id "aqxb1S9E0uOV11S2qN6iEQAAAIg"]
[Thu Sep 17 15:29:58.116760 2026] [security2:error] [pid 16723:tid 16973] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/travis/.env"] [unique_id "aqxb1i9E0uOV11S2qN6iFQAAAPw"]
[Thu Sep 17 15:29:58.284469 2026] [security2:error] [pid 16723:tid 16967] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/buildkite/.env"] [unique_id "aqxb1i9E0uOV11S2qN6iGgAAAPY"]
[Thu Sep 17 15:29:58.319806 2026] [security2:error] [pid 1029697:tid 1029858] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6mCwAAAB8"]
[Thu Sep 17 15:29:58.319806 2026] [security2:error] [pid 1029697:tid 1029866] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6mCgAAACc"]
[Thu Sep 17 15:29:58.320200 2026] [fcgid:warn] [pid 1029697:tid 1029901] (70014)End of file found: [client 128.1.34.69:50762] mod_fcgid: can't get data from http client
[Thu Sep 17 15:29:58.357252 2026] [security2:error] [pid 16723:tid 16943] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iCwAAAN4"]
[Thu Sep 17 15:29:58.388031 2026] [security2:error] [pid 1029697:tid 1029934] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6mDAAAAGs"]
[Thu Sep 17 15:29:58.389012 2026] [security2:error] [pid 16723:tid 16911] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iDQAAAL4"]
[Thu Sep 17 15:29:58.393409 2026] [security2:error] [pid 1029697:tid 1029954] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1W65wm-f4uX16X6mDQAAAH8"]
[Thu Sep 17 15:29:58.398017 2026] [security2:error] [pid 16723:tid 16933] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iDwAAANQ"]
[Thu Sep 17 15:29:58.407620 2026] [security2:error] [pid 16723:tid 16899] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iEAAAALI"]
[Thu Sep 17 15:29:58.408722 2026] [security2:error] [pid 16723:tid 16969] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iDAAAAPg"]
[Thu Sep 17 15:29:58.427001 2026] [security2:error] [pid 16723:tid 16955] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1S9E0uOV11S2qN6iDgAAAOo"]
[Thu Sep 17 15:29:58.427022 2026] [security2:error] [pid 16723:tid 16940] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iFAAAANs"]
[Thu Sep 17 15:29:58.444788 2026] [security2:error] [pid 16723:tid 16913] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mysql/.env"] [unique_id "aqxb1i9E0uOV11S2qN6iHwAAAMA"]
[Thu Sep 17 15:29:58.495809 2026] [security2:error] [pid 1029697:tid 1029782] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/phpinfo.php"] [unique_id "aqxb1m65wm-f4uX16X6mIAAAR1Q"]
[Thu Sep 17 15:29:58.573079 2026] [security2:error] [pid 16723:tid 16938] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iHQAAANk"]
[Thu Sep 17 15:29:58.593513 2026] [security2:error] [pid 1029697:tid 1029793] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/info.php"] [unique_id "aqxb1m65wm-f4uX16X6mJQAAR18"]
[Thu Sep 17 15:29:58.593541 2026] [security2:error] [pid 1029697:tid 1029752] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/infos.php"] [unique_id "aqxb1m65wm-f4uX16X6mJgAARzY"]
[Thu Sep 17 15:29:58.594120 2026] [security2:error] [pid 1029697:tid 1029704] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/php_info.php"] [unique_id "aqxb1m65wm-f4uX16X6mJwAARwY"]
[Thu Sep 17 15:29:58.594935 2026] [security2:error] [pid 1029697:tid 1029705] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/php.php"] [unique_id "aqxb1m65wm-f4uX16X6mKAAARwc"]
[Thu Sep 17 15:29:58.598073 2026] [security2:error] [pid 1029697:tid 1029813] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/infophp.php"] [unique_id "aqxb1m65wm-f4uX16X6mKgAAR3M"]
[Thu Sep 17 15:29:58.598092 2026] [security2:error] [pid 1029697:tid 1029811] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/php-info.php"] [unique_id "aqxb1m65wm-f4uX16X6mKQAAR3E"]
[Thu Sep 17 15:29:58.598357 2026] [security2:error] [pid 16723:tid 16959] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iIAAAAO4"]
[Thu Sep 17 15:29:58.603221 2026] [security2:error] [pid 16723:tid 16900] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/postgres/.env"] [unique_id "aqxb1i9E0uOV11S2qN6iJgAAALM"]
[Thu Sep 17 15:29:58.633385 2026] [security2:error] [pid 16723:tid 16875] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iIQAAAJo"]
[Thu Sep 17 15:29:58.634719 2026] [security2:error] [pid 1029697:tid 1029809] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxb1m65wm-f4uX16X6mLAAAR28"]
[Thu Sep 17 15:29:58.691852 2026] [security2:error] [pid 1029697:tid 1029798] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxb1m65wm-f4uX16X6mLQAAR2Q"]
[Thu Sep 17 15:29:58.714555 2026] [security2:error] [pid 1029697:tid 1029895] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1m65wm-f4uX16X6mIQAAAEQ"]
[Thu Sep 17 15:29:58.732637 2026] [security2:error] [pid 1029697:tid 1029797] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/api/phpinfo.php"] [unique_id "aqxb1m65wm-f4uX16X6mLgAAR2M"]
[Thu Sep 17 15:29:58.732685 2026] [security2:error] [pid 1029697:tid 1029784] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/public/phpinfo.php"] [unique_id "aqxb1m65wm-f4uX16X6mMAAAR1Y"]
[Thu Sep 17 15:29:58.732752 2026] [security2:error] [pid 1029697:tid 1029822] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxb1m65wm-f4uX16X6mLwAAR3w"]
[Thu Sep 17 15:29:58.765171 2026] [security2:error] [pid 16723:tid 16917] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/mongodb/.env"] [unique_id "aqxb1i9E0uOV11S2qN6iMwAAAMQ"]
[Thu Sep 17 15:29:58.780301 2026] [security2:error] [pid 16723:tid 16858] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iKwAAAIk"]
[Thu Sep 17 15:29:58.806443 2026] [security2:error] [pid 16723:tid 16893] [client 3.19.142.206:55462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iMAAAAKw"]
[Thu Sep 17 15:29:58.817631 2026] [security2:error] [pid 16723:tid 16924] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iLAAAAMs"]
[Thu Sep 17 15:29:58.879349 2026] [security2:error] [pid 1029697:tid 1029759] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/database.sql"] [unique_id "aqxb1m65wm-f4uX16X6mPwAARz0"]
[Thu Sep 17 15:29:58.911506 2026] [security2:error] [pid 16723:tid 16952] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iMgAAAOc"]
[Thu Sep 17 15:29:58.933657 2026] [security2:error] [pid 16723:tid 16957] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/redis/.env"] [unique_id "aqxb1i9E0uOV11S2qN6iQwAAAOw"]
[Thu Sep 17 15:29:58.939679 2026] [security2:error] [pid 16723:tid 16979] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iNAAAAQI"]
[Thu Sep 17 15:29:58.943358 2026] [security2:error] [pid 16723:tid 16907] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iOQAAALo"]
[Thu Sep 17 15:29:59.093636 2026] [security2:error] [pid 16723:tid 16963] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/elasticsearch/.env"] [unique_id "aqxb1y9E0uOV11S2qN6iTwAAAPI"]
[Thu Sep 17 15:29:59.157591 2026] [security2:error] [pid 16723:tid 16921] [client 143.105.152.240:15330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb1y9E0uOV11S2qN6iUgAAAMg"]
[Thu Sep 17 15:29:59.157721 2026] [security2:error] [pid 16723:tid 16921] [client 143.105.152.240:15330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb1y9E0uOV11S2qN6iUgAAAMg"]
[Thu Sep 17 15:29:59.259926 2026] [security2:error] [pid 16723:tid 16909] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iOwAAALw"]
[Thu Sep 17 15:29:59.264038 2026] [security2:error] [pid 16723:tid 16940] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/rabbitmq/.env"] [unique_id "aqxb1y9E0uOV11S2qN6iVwAAANs"]
[Thu Sep 17 15:29:59.284330 2026] [security2:error] [pid 16723:tid 16916] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iPAAAAMM"]
[Thu Sep 17 15:29:59.289260 2026] [security2:error] [pid 16723:tid 16892] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iPQAAAKs"]
[Thu Sep 17 15:29:59.410773 2026] [security2:error] [pid 16723:tid 16888] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iSgAAAKc"]
[Thu Sep 17 15:29:59.410773 2026] [security2:error] [pid 16723:tid 16895] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1y9E0uOV11S2qN6iTAAAAK4"]
[Thu Sep 17 15:29:59.410841 2026] [security2:error] [pid 16723:tid 16878] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1y9E0uOV11S2qN6iVAAAAJ0"]
[Thu Sep 17 15:29:59.412978 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1265wm-f4uX16X6mVQAAAF8"]
[Thu Sep 17 15:29:59.416886 2026] [security2:error] [pid 1029697:tid 1029848] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1m65wm-f4uX16X6mRAAAABU"]
[Thu Sep 17 15:29:59.431333 2026] [security2:error] [pid 16723:tid 16854] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/kafka/.env"] [unique_id "aqxb1y9E0uOV11S2qN6iWQAAAIU"]
[Thu Sep 17 15:29:59.441518 2026] [security2:error] [pid 16723:tid 16879] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1y9E0uOV11S2qN6iSwAAAJ4"]
[Thu Sep 17 15:29:59.441518 2026] [security2:error] [pid 16723:tid 16968] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1i9E0uOV11S2qN6iRwAAAPc"]
[Thu Sep 17 15:29:59.451209 2026] [security2:error] [pid 1029697:tid 1029915] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1m65wm-f4uX16X6mSQAAAFg"]
[Thu Sep 17 15:29:59.453363 2026] [security2:error] [pid 1029697:tid 1029840] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1m65wm-f4uX16X6mRgAAAA0"]
[Thu Sep 17 15:29:59.455230 2026] [security2:error] [pid 16723:tid 16857] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1y9E0uOV11S2qN6iTQAAAIg"]
[Thu Sep 17 15:29:59.489063 2026] [security2:error] [pid 1029697:tid 1029867] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1265wm-f4uX16X6mWQAAACg"]
[Thu Sep 17 15:29:59.526958 2026] [security2:error] [pid 16723:tid 16949] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1y9E0uOV11S2qN6iWAAAAOQ"]
[Thu Sep 17 15:29:59.535271 2026] [security2:error] [pid 1029697:tid 1029832] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1265wm-f4uX16X6mXQAAAAU"]
[Thu Sep 17 15:29:59.558067 2026] [security2:error] [pid 1029697:tid 1029951] [client 74.7.175.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.pkum.org"] [uri "/index.php"] [unique_id "aqxb1265wm-f4uX16X6mYgAAAHw"]
[Thu Sep 17 15:29:59.592212 2026] [security2:error] [pid 16723:tid 16960] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/queue/.env"] [unique_id "aqxb1y9E0uOV11S2qN6iXQAAAO8"]
[Thu Sep 17 15:29:59.613729 2026] [security2:error] [pid 1029697:tid 1029909] [client 74.7.175.189:51200] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.pkum.org"] [uri "/robots.txt"] [unique_id "aqxb1265wm-f4uX16X6mXgAAUhU"]
[Thu Sep 17 15:29:59.749667 2026] [security2:error] [pid 1029697:tid 1029760] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/test.config.php"] [unique_id "aqxb1265wm-f4uX16X6maAAAcz4"]
[Thu Sep 17 15:29:59.749726 2026] [security2:error] [pid 1029697:tid 1029744] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/aws_settings.php"] [unique_id "aqxb1265wm-f4uX16X6mbgAAcy4"]
[Thu Sep 17 15:29:59.750395 2026] [security2:error] [pid 1029697:tid 1029789] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/config.json.php"] [unique_id "aqxb1265wm-f4uX16X6magAAc1s"]
[Thu Sep 17 15:29:59.750416 2026] [security2:error] [pid 1029697:tid 1029795] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/.env.production.php"] [unique_id "aqxb1265wm-f4uX16X6mYwAAc2E"]
[Thu Sep 17 15:29:59.750817 2026] [security2:error] [pid 1029697:tid 1029708] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/fe/.env"] [unique_id "aqxb1265wm-f4uX16X6mZwAAcwo"]
[Thu Sep 17 15:29:59.750832 2026] [security2:error] [pid 1029697:tid 1029820] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moroccohometravel.com"] [uri "/react-app/.env"] [unique_id "aqxb1265wm-f4uX16X6mbQAAc3o"]
[Thu Sep 17 15:29:59.753949 2026] [security2:error] [pid 16723:tid 16873] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/worker/.env"] [unique_id "aqxb1y9E0uOV11S2qN6iXgAAAJg"]
[Thu Sep 17 15:29:59.884881 2026] [security2:error] [pid 1029697:tid 1029754] [remote 34.140.132.132:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.132.140.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moroccohometravel.com"] [uri "/api/info.php"] [unique_id "aqxb1265wm-f4uX16X6mewAAczg"]
[Thu Sep 17 15:29:59.913241 2026] [security2:error] [pid 16723:tid 16966] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/job/.env"] [unique_id "aqxb1y9E0uOV11S2qN6iaQAAAPU"]
[Thu Sep 17 15:29:59.920903 2026] [security2:error] [pid 1029697:tid 1029942] [client 34.140.132.132:34528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1265wm-f4uX16X6mawAAcyM"]
[Thu Sep 17 15:29:59.941405 2026] [security2:error] [pid 1029697:tid 1029873] [client 103.61.184.148:56450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb1265wm-f4uX16X6mggAAAC4"]
[Thu Sep 17 15:29:59.941548 2026] [security2:error] [pid 1029697:tid 1029873] [client 103.61.184.148:56450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb1265wm-f4uX16X6mggAAAC4"]
[Thu Sep 17 15:30:00.080776 2026] [security2:error] [pid 16723:tid 16863] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/test/.env"] [unique_id "aqxb2C9E0uOV11S2qN6idQAAAI4"]
[Thu Sep 17 15:30:00.085057 2026] [security2:error] [pid 16723:tid 16941] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1y9E0uOV11S2qN6iaAAAANw"]
[Thu Sep 17 15:30:00.097742 2026] [security2:error] [pid 1029697:tid 1029865] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb1265wm-f4uX16X6mgQAAACY"]
[Thu Sep 17 15:30:00.245427 2026] [security2:error] [pid 16723:tid 16929] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/qa/.env"] [unique_id "aqxb2C9E0uOV11S2qN6iegAAANA"]
[Thu Sep 17 15:30:00.299879 2026] [security2:error] [pid 1029697:tid 1029899] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2G65wm-f4uX16X6mhwAAAEg"]
[Thu Sep 17 15:30:00.300311 2026] [security2:error] [pid 16723:tid 16950] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6ibAAAAOU"]
[Thu Sep 17 15:30:00.300320 2026] [security2:error] [pid 16723:tid 16883] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6ibQAAAKI"]
[Thu Sep 17 15:30:00.302183 2026] [security2:error] [pid 16723:tid 16924] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6ibwAAAMs"]
[Thu Sep 17 15:30:00.318945 2026] [security2:error] [pid 16723:tid 16907] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6idgAAALo"]
[Thu Sep 17 15:30:00.318945 2026] [security2:error] [pid 16723:tid 16897] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6icgAAALA"]
[Thu Sep 17 15:30:00.318945 2026] [security2:error] [pid 16723:tid 16872] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6icAAAAJc"]
[Thu Sep 17 15:30:00.318947 2026] [security2:error] [pid 16723:tid 16979] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6idAAAAQI"]
[Thu Sep 17 15:30:00.320302 2026] [security2:error] [pid 16723:tid 16957] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6icwAAAOw"]
[Thu Sep 17 15:30:00.321354 2026] [security2:error] [pid 16723:tid 16866] [client 34.140.132.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxb2C9E0uOV11S2qN6icQAAAJE"]
[Thu Sep 17 15:30:00.404371 2026] [security2:error] [pid 16723:tid 16969] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/preview/.env"] [unique_id "aqxb2C9E0uOV11S2qN6iewAAAPg"]
[Thu Sep 17 15:30:00.572443 2026] [security2:error] [pid 16723:tid 16939] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/beta/.env"] [unique_id "aqxb2C9E0uOV11S2qN6ifAAAANo"]
[Thu Sep 17 15:30:00.668239 2026] [security2:error] [pid 16723:tid 16916] [client 82.102.18.118:59726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "breathingboxing.org"] [uri "/xmlrpc.php"] [unique_id "aqxb2C9E0uOV11S2qN6ifQAAAMM"]
[Thu Sep 17 15:30:00.668371 2026] [security2:error] [pid 16723:tid 16916] [client 82.102.18.118:59726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "breathingboxing.org"] [uri "/xmlrpc.php"] [unique_id "aqxb2C9E0uOV11S2qN6ifQAAAMM"]
[Thu Sep 17 15:30:00.730936 2026] [security2:error] [pid 16723:tid 16874] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/uat/.env"] [unique_id "aqxb2C9E0uOV11S2qN6ifgAAAJk"]
[Thu Sep 17 15:30:00.894754 2026] [security2:error] [pid 16723:tid 16901] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/stage/.env"] [unique_id "aqxb2C9E0uOV11S2qN6iggAAALQ"]
[Thu Sep 17 15:30:01.058186 2026] [security2:error] [pid 16723:tid 16958] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/development/.env"] [unique_id "aqxb2S9E0uOV11S2qN6ihAAAAO0"]
[Thu Sep 17 15:30:01.216380 2026] [security2:error] [pid 16723:tid 16888] [client 3.19.142.206:56416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxb2S9E0uOV11S2qN6ihQAAAKc"]
[Thu Sep 17 15:30:01.228601 2026] [security2:error] [pid 1029697:tid 1029849] [client 114.198.138.124:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb2W65wm-f4uX16X6mlgAAABY"]
[Thu Sep 17 15:30:01.228737 2026] [security2:error] [pid 1029697:tid 1029849] [client 114.198.138.124:51536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb2W65wm-f4uX16X6mlgAAABY"]
[Thu Sep 17 15:30:01.231545 2026] [security2:error] [pid 16723:tid 16919] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/production/.env"] [unique_id "aqxb2S9E0uOV11S2qN6iiAAAAMY"]
[Thu Sep 17 15:30:01.370825 2026] [security2:error] [pid 1029697:tid 1029856] [client 82.102.18.118:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "breathingboxing.org"] [uri "/xmlrpc.php"] [unique_id "aqxb2W65wm-f4uX16X6mlwAAAB0"]
[Thu Sep 17 15:30:01.370993 2026] [security2:error] [pid 1029697:tid 1029856] [client 82.102.18.118:57660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "breathingboxing.org"] [uri "/xmlrpc.php"] [unique_id "aqxb2W65wm-f4uX16X6mlwAAAB0"]
[Thu Sep 17 15:30:01.391002 2026] [security2:error] [pid 16723:tid 16902] [client 34.154.232.68:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.ravenindustries.net"] [uri "/config/app/.env"] [unique_id "aqxb2S9E0uOV11S2qN6ikQAAALU"]
[Thu Sep 17 15:30:01.553732 2026] [security2:error] [pid 16723:tid 16900] [client 34.154.232.68:43378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/phpinfo.php"] [unique_id "aqxb2S9E0uOV11S2qN6ilwAAALM"]
[Thu Sep 17 15:30:01.566790 2026] [authz_core:error] [pid 16723:tid 16894] [client 4.240.114.86:56303] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:30:02.009718 2026] [core:error] [pid 16723:tid 16914] [client 138.246.253.24:34932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:02.009751 2026] [core:error] [pid 16723:tid 16914] [client 138.246.253.24:34932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:02.053062 2026] [security2:error] [pid 1029697:tid 1029839] [client 34.154.232.68:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/info.php"] [unique_id "aqxb2m65wm-f4uX16X6mnAAAAAw"]
[Thu Sep 17 15:30:02.498858 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00493: SIGUSR1 received.  Doing graceful restart
[Thu Sep 17 15:30:02.550668 2026] [security2:error] [pid 1029697:tid 1029922] [client 34.154.232.68:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/php.php"] [unique_id "aqxb2m65wm-f4uX16X6mpAAAAF8"]
[Thu Sep 17 15:30:03.653670 2026] [:notice] [pid 1029610:tid 1029610] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 1029610 stopped
[Thu Sep 17 15:30:06.174846 2026] [lsapi:notice] [pid 907280:tid 907280] mod_lsapi:  version 1.1-92
[Thu Sep 17 15:30:06.185341 2026] [:notice] [pid 18931:tid 18931] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 18931 started
[Thu Sep 17 15:30:06.254044 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tylerblantonmusic.tylerblanton.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.261169 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: deraiz-mx.xavierlopezmiranda.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.282110 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ahmedteleb.tasameem-eg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.284021 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fst-i.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.284450 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fstsprinkler.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.288356 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: southislandpie.southislandpie.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.299007 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardashphotography.reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.310495 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcp-u.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.311052 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.312021 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reedcustomprinting.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.312583 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpphotorestoration.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.313015 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpmobileartscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.313797 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rjglobalhq.com.rebeccamerzius.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.341495 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mermco.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.341894 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ad1homes.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.342400 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-7b36017a.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.345093 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-3f11e808.livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.359493 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: api.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.359875 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: admin.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.375040 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: hamzaabdulhaq.gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.391093 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: site.tengushee.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.412634 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ayfertbarak.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.413165 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: becorenovation.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.413516 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: agent-immobilier.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.415794 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sqlerudition.commutervibe.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.417905 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bothe-net.cyber21.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.430887 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: troopkcampcadet.campcadetmontco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.432702 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vedur-app.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.433213 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: weather-is.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.433741 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tengja-net.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.434218 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bookin-city.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.434690 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-c557c2bf.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.435176 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-1a493541.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.435704 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitlinwhittington.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.436071 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jarrodandcaitlin-us.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.455982 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b2133dcc.idautovic.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.475752 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wellfedhealth.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.476582 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wear-out.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.479276 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vogito-inno.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.492704 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: thegoatmentality.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.501230 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.509964 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rpimanufacturing.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.510474 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rosebar.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.514030 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: revelinfear.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.515399 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.523405 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pazcreativehomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.525180 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pagepress.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.532838 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nikistepanianmft.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.534368 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nexgenimplant.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.542125 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mengesphotos.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.543260 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mdlzbenefits.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.545146 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: macmanagement.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.549548 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: lifepointechurchga.org:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.555481 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.557590 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kbmautomation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.560813 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jminner.photo:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.564327 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: janetaylor.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.565202 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.579911 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.590738 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ffwdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.591488 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: evansilver.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.594935 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ericbabin.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.597833 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ellenhirshberg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.608865 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: comfortspecialist.info:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.614842 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: biggselectrical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.615936 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.616787 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.617478 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bvpowersports.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.617822 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buliblog.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.618310 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buildingpro.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.620556 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bodylanguageohio.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.634805 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: afbaco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.635671 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: abelardpsychotherapy.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.688930 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b0f84876.robertsinteractive.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.692959 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tracertgame-com.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.693485 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-f2c0397e.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.694755 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-19b382b5.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.737812 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: marinabelous.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.751232 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: houlaentertainment.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.770621 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:30:06.786540 2026] [qos:notice] [pid 907280:tid 907280] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Sep 17 15:30:07.037522 2026] [http2:info] [pid 907280:tid 907280] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Thu Sep 17 15:30:07.042567 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Sep 17 15:30:07.042581 2026] [core:notice] [pid 907280:tid 907280] AH00094: Command line: '/usr/sbin/httpd'
[Thu Sep 17 15:30:08.092870 2026] [http2:info] [pid 18946:tid 18946] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:30:08.117083 2026] [security2:error] [pid 18946:tid 19088] [client 4.240.114.86:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8OAAAARY"], referer: binance.com
[Thu Sep 17 15:30:08.118185 2026] [security2:error] [pid 18946:tid 19082] [client 18.188.3.41:59107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/blog/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8NQAAARA"]
[Thu Sep 17 15:30:08.118197 2026] [security2:error] [pid 18946:tid 19080] [client 3.19.142.206:57354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8MgAAAQ4"]
[Thu Sep 17 15:30:08.118197 2026] [security2:error] [pid 18946:tid 19086] [client 3.19.142.206:57333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8NAAAARQ"]
[Thu Sep 17 15:30:08.118235 2026] [security2:error] [pid 18946:tid 19080] [client 3.19.142.206:57354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8MgAAAQ4"]
[Thu Sep 17 15:30:08.118238 2026] [security2:error] [pid 18946:tid 19086] [client 3.19.142.206:57333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8NAAAARQ"]
[Thu Sep 17 15:30:08.118975 2026] [security2:error] [pid 18946:tid 19076] [client 3.19.142.206:57329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8MQAAAQo"]
[Thu Sep 17 15:30:08.119006 2026] [security2:error] [pid 18946:tid 19076] [client 3.19.142.206:57329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8MQAAAQo"]
[Thu Sep 17 15:30:08.133034 2026] [authz_core:error] [pid 18946:tid 19077] [client 169.58.197.253:54552] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:30:08.283778 2026] [security2:error] [pid 18946:tid 19110] [client 34.154.232.68:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/pinfo.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8VwAAASw"]
[Thu Sep 17 15:30:08.433274 2026] [security2:error] [pid 18946:tid 19138] [client 3.19.142.206:57354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8XwAAAUg"]
[Thu Sep 17 15:30:08.433341 2026] [security2:error] [pid 18946:tid 19138] [client 3.19.142.206:57354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/wp/xmlrpc.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8XwAAAUg"]
[Thu Sep 17 15:30:08.466970 2026] [security2:error] [pid 18946:tid 18961] [remote 52.167.144.25:35658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ritamayblog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8YgABTA4"], referer: https://ritamayblog.com/its-not-your-fault-you-struggle-with-food/
[Thu Sep 17 15:30:08.800842 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.232.68:54338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/test.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8bgAAAV0"]
[Thu Sep 17 15:30:09.054556 2026] [security2:error] [pid 18946:tid 19171] [client 45.4.106.26:13486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb4DqiPMah0Tz_U1N8cQABaRQ"]
[Thu Sep 17 15:30:09.497352 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.232.68:45316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/p.php"] [unique_id "aqxb4TqiPMah0Tz_U1N8ggAAAQ0"]
[Thu Sep 17 15:30:09.555070 2026] [security2:error] [pid 18946:tid 19198] [client 43.173.180.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxb4TqiPMah0Tz_U1N8gAAAAYQ"]
[Thu Sep 17 15:30:09.773006 2026] [security2:error] [pid 18946:tid 19118] [client 184.154.36.186:42132] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "houselifeinc.com"] [uri "/cgi-sys/404.html"] [unique_id "aqxb4TqiPMah0Tz_U1N8hwAAATQ"]
[Thu Sep 17 15:30:09.977863 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.232.68:45322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/debug.php"] [unique_id "aqxb4TqiPMah0Tz_U1N8iQAAAT0"]
[Thu Sep 17 15:30:10.119295 2026] [security2:error] [pid 18946:tid 19141] [client 3.19.142.206:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8jAAAAUs"]
[Thu Sep 17 15:30:10.231986 2026] [security2:error] [pid 18946:tid 19133] [client 136.158.61.34:40189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8kwAAAUM"]
[Thu Sep 17 15:30:10.232140 2026] [security2:error] [pid 18946:tid 19133] [client 136.158.61.34:40189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8kwAAAUM"]
[Thu Sep 17 15:30:10.473401 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.232.68:45328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8mgAAAVc"]
[Thu Sep 17 15:30:10.555902 2026] [security2:error] [pid 18946:tid 19138] [client 143.105.152.240:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8mwAAAUg"]
[Thu Sep 17 15:30:10.556191 2026] [security2:error] [pid 18946:tid 19138] [client 143.105.152.240:33422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8mwAAAUg"]
[Thu Sep 17 15:30:10.733990 2026] [security2:error] [pid 18946:tid 19152] [client 103.61.184.148:55583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8nwAAAVY"]
[Thu Sep 17 15:30:10.734187 2026] [security2:error] [pid 18946:tid 19152] [client 103.61.184.148:55583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8nwAAAVY"]
[Thu Sep 17 15:30:10.971635 2026] [security2:error] [pid 18946:tid 19099] [client 34.154.232.68:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/test/phpinfo.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8oQAAASE"]
[Thu Sep 17 15:30:11.447678 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.232.68:45348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxb4zqiPMah0Tz_U1N8rwAAAXc"]
[Thu Sep 17 15:30:11.819376 2026] [security2:error] [pid 18946:tid 19164] [client 114.198.138.124:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb4zqiPMah0Tz_U1N8vAAAAWI"]
[Thu Sep 17 15:30:11.819462 2026] [security2:error] [pid 18946:tid 19164] [client 114.198.138.124:52189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb4zqiPMah0Tz_U1N8vAAAAWI"]
[Thu Sep 17 15:30:11.823218 2026] [security2:error] [pid 18946:tid 19144] [client 213.230.87.37:59836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb4zqiPMah0Tz_U1N8tQABTiA"]
[Thu Sep 17 15:30:11.920489 2026] [security2:error] [pid 18946:tid 19094] [client 4.240.114.86:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxb4zqiPMah0Tz_U1N8vwAAARw"], referer: binance.com
[Thu Sep 17 15:30:11.939061 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.232.68:45356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/old/phpinfo.php"] [unique_id "aqxb4zqiPMah0Tz_U1N8wAAAAYg"]
[Thu Sep 17 15:30:12.423671 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.232.68:45368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxb5DqiPMah0Tz_U1N8zQAAASQ"]
[Thu Sep 17 15:30:12.915450 2026] [security2:error] [pid 18946:tid 19155] [client 34.154.232.68:45372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/public/phpinfo.php"] [unique_id "aqxb5DqiPMah0Tz_U1N89wAAAVk"]
[Thu Sep 17 15:30:12.965873 2026] [security2:error] [pid 18946:tid 19151] [client 172.86.81.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.gazillionmexico.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxb4jqiPMah0Tz_U1N8lQAAAVU"], referer: http://www.gazillionmexico.xavierlopezmiranda.com/.git/config
[Thu Sep 17 15:30:12.968979 2026] [access_compat:error] [pid 18946:tid 19119] [client 169.58.197.251:59437] AH01797: client denied by server configuration: /home2/sfvhbtor/public_html/wp-content/uploads/wp-statistics/, referer: binance.com
[Thu Sep 17 15:30:13.263855 2026] [security2:error] [pid 18946:tid 19099] [client 69.140.155.103:55203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb5TqiPMah0Tz_U1N8_QABIUc"]
[Thu Sep 17 15:30:13.626463 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.232.68:45378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/php-info.php"] [unique_id "aqxb5TqiPMah0Tz_U1N9CgAAAW0"]
[Thu Sep 17 15:30:13.774951 2026] [security2:error] [pid 18946:tid 19159] [client 198.44.116.203:58496] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "intolovinghomes.com.au"] [uri "/wp-content/plugins/broken-link-checker/readme.txt"] [unique_id "aqxb5TqiPMah0Tz_U1N9EAAAAV0"]
[Thu Sep 17 15:30:14.059206 2026] [security2:error] [pid 18946:tid 19085] [client 198.44.116.203:58498] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "intolovinghomes.com.au"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aqxb5jqiPMah0Tz_U1N9FwAAARM"]
[Thu Sep 17 15:30:14.068456 2026] [security2:error] [pid 18946:tid 19101] [client 4.240.114.86:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxb5jqiPMah0Tz_U1N9GAAAASM"], referer: binance.com
[Thu Sep 17 15:30:14.123203 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.232.68:45382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/phpversion.php"] [unique_id "aqxb5jqiPMah0Tz_U1N9GwAAARQ"]
[Thu Sep 17 15:30:14.199058 2026] [security2:error] [pid 18946:tid 19089] [client 169.58.197.253:55259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-content/uploads/500.php"] [unique_id "aqxb5jqiPMah0Tz_U1N9IAAAARc"], referer: binance.com
[Thu Sep 17 15:30:14.209069 2026] [security2:error] [pid 18946:tid 19078] [client 184.154.36.186:42150] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houselifeinc.com"] [uri "/wp-content/themes/Divi/includes/builder/scripts/waypoints.min.js"] [unique_id "aqxb5jqiPMah0Tz_U1N9IQAAAQw"]
[Thu Sep 17 15:30:14.442477 2026] [security2:error] [pid 18946:tid 19098] [client 3.19.142.206:61020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxb5jqiPMah0Tz_U1N9JQAAASA"]
[Thu Sep 17 15:30:14.632962 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.232.68:45390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/_phpinfo.php"] [unique_id "aqxb5jqiPMah0Tz_U1N9MQAAAVI"]
[Thu Sep 17 15:30:14.695701 2026] [security2:error] [pid 18946:tid 19123] [client 104.28.245.127:55485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "palveluklubi.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxb5jqiPMah0Tz_U1N9NgAAATk"]
[Thu Sep 17 15:30:14.729061 2026] [security2:error] [pid 18946:tid 19112] [client 3.19.142.206:61121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxb5jqiPMah0Tz_U1N9MwAAAS4"]
[Thu Sep 17 15:30:15.115365 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.232.68:45394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/old_phpinfo.php"] [unique_id "aqxb5zqiPMah0Tz_U1N9QQAAATY"]
[Thu Sep 17 15:30:15.375824 2026] [security2:error] [pid 18946:tid 19184] [client 18.188.3.41:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/backup/xmlrpc.php"] [unique_id "aqxb5zqiPMah0Tz_U1N9SgAAAXY"]
[Thu Sep 17 15:30:15.477570 2026] [security2:error] [pid 18946:tid 19143] [client 69.140.155.103:55208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb5zqiPMah0Tz_U1N9SwABTV0"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260726012618&hideanons=1&hidebots=0&target=The_God-Emperor&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:30:15.603236 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.232.68:45406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/server-info.php"] [unique_id "aqxb5zqiPMah0Tz_U1N9UQAAAQ0"]
[Thu Sep 17 15:30:15.871776 2026] [security2:error] [pid 18946:tid 19101] [client 74.7.228.9:40106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.ele.ixy.mybluehost.me"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxb5zqiPMah0Tz_U1N9WAAAASM"]
[Thu Sep 17 15:30:16.046229 2026] [security2:error] [pid 18946:tid 19085] [client 23.251.146.115:16000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxb5zqiPMah0Tz_U1N9VgABE18"]
[Thu Sep 17 15:30:16.105052 2026] [security2:error] [pid 18946:tid 19135] [client 34.154.232.68:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/server-status.php"] [unique_id "aqxb6DqiPMah0Tz_U1N9XAAAAUU"]
[Thu Sep 17 15:30:16.235141 2026] [security2:error] [pid 18946:tid 19098] [client 23.251.146.115:16000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drhusseinalbeedh.com"] [uri "/index.php"] [unique_id "aqxb6DqiPMah0Tz_U1N9WwABIGI"]
[Thu Sep 17 15:30:16.494129 2026] [security2:error] [pid 18946:tid 19162] [client 216.73.217.1:45090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "votersrevenge.info"] [uri "/index.php"] [unique_id "aqxb5zqiPMah0Tz_U1N9RQABYFs"]
[Thu Sep 17 15:30:17.003133 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.232.68:45418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxb6TqiPMah0Tz_U1N9cgAAAYc"]
[Thu Sep 17 15:30:17.003506 2026] [security2:error] [pid 18946:tid 19203] [client 4.240.114.86:49199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9cwAAAYk"], referer: binance.com
[Thu Sep 17 15:30:17.335505 2026] [security2:error] [pid 18946:tid 19157] [client 216.73.217.1:45090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "votersrevenge.info"] [uri "/index.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9ewABW2s"]
[Thu Sep 17 15:30:17.472700 2026] [security2:error] [pid 18946:tid 19100] [client 34.154.232.68:45422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9hAAAASI"]
[Thu Sep 17 15:30:17.493756 2026] [security2:error] [pid 18946:tid 19161] [client 45.55.91.79:54778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenbrickbuilders.com"] [uri "/index.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9fgABX2w"], referer: http://greenbrickbuilders.com/backup/
[Thu Sep 17 15:30:17.786599 2026] [security2:error] [pid 18946:tid 19092] [client 3.19.142.206:62212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9jAAAARo"]
[Thu Sep 17 15:30:17.788235 2026] [security2:error] [pid 18946:tid 19092] [client 3.19.142.206:62212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9jAAAARo"]
[Thu Sep 17 15:30:17.796835 2026] [security2:error] [pid 18946:tid 19187] [client 3.19.142.206:62220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9jQAAAXk"]
[Thu Sep 17 15:30:17.799501 2026] [security2:error] [pid 18946:tid 19187] [client 3.19.142.206:62220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9jQAAAXk"]
[Thu Sep 17 15:30:17.866297 2026] [security2:error] [pid 18946:tid 19182] [client 3.19.142.206:62261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9kQAAAXQ"]
[Thu Sep 17 15:30:17.870443 2026] [security2:error] [pid 18946:tid 19182] [client 3.19.142.206:62261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9kQAAAXQ"]
[Thu Sep 17 15:30:17.951372 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.232.68:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9lAAAAYE"]
[Thu Sep 17 15:30:18.079637 2026] [security2:error] [pid 18946:tid 19139] [client 45.55.91.79:54778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenbrickbuilders.com"] [uri "/index.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9kwABSXI"], referer: http://greenbrickbuilders.com/wordpress/
[Thu Sep 17 15:30:18.424568 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.232.68:45440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxb6jqiPMah0Tz_U1N9nQAAAW0"]
[Thu Sep 17 15:30:18.653119 2026] [security2:error] [pid 18946:tid 19181] [client 45.55.91.79:54778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenbrickbuilders.com"] [uri "/index.php"] [unique_id "aqxb6jqiPMah0Tz_U1N9oAABc3Y"], referer: http://greenbrickbuilders.com/wp/
[Thu Sep 17 15:30:18.882769 2026] [security2:error] [pid 18946:tid 19156] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxb6TqiPMah0Tz_U1N9gwAAAVo"]
[Thu Sep 17 15:30:18.901211 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.232.68:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxb6jqiPMah0Tz_U1N9qAAAAS8"]
[Thu Sep 17 15:30:18.944128 2026] [security2:error] [pid 18946:tid 19148] [client 45.55.91.79:54778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenbrickbuilders.com"] [uri "/index.php"] [unique_id "aqxb6jqiPMah0Tz_U1N9pgABUng"], referer: http://greenbrickbuilders.com/new/
[Thu Sep 17 15:30:19.239362 2026] [security2:error] [pid 18946:tid 19111] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxb6zqiPMah0Tz_U1N9rQAAAS0"]
[Thu Sep 17 15:30:19.270383 2026] [security2:error] [pid 18946:tid 19114] [client 45.55.91.79:54778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenbrickbuilders.com"] [uri "/index.php"] [unique_id "aqxb6zqiPMah0Tz_U1N9rAABMHo"], referer: http://greenbrickbuilders.com/old/
[Thu Sep 17 15:30:19.374937 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.232.68:51578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxb6zqiPMah0Tz_U1N9tAAAAUg"]
[Thu Sep 17 15:30:19.862443 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.232.68:51586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxb6zqiPMah0Tz_U1N9vgAAASk"]
[Thu Sep 17 15:30:20.055545 2026] [security2:error] [pid 18946:tid 19193] [client 3.19.142.206:63019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb7DqiPMah0Tz_U1N9wwAAAX8"]
[Thu Sep 17 15:30:20.055688 2026] [security2:error] [pid 18946:tid 19193] [client 3.19.142.206:63019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxb7DqiPMah0Tz_U1N9wwAAAX8"]
[Thu Sep 17 15:30:20.325988 2026] [security2:error] [pid 18946:tid 19172] [client 143.105.152.240:19490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb7DqiPMah0Tz_U1N9zwAAAWo"]
[Thu Sep 17 15:30:20.326088 2026] [security2:error] [pid 18946:tid 19172] [client 143.105.152.240:19490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb7DqiPMah0Tz_U1N9zwAAAWo"]
[Thu Sep 17 15:30:20.333825 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.232.68:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/phpinfo.php.old"] [unique_id "aqxb7DqiPMah0Tz_U1N90AAAAXw"]
[Thu Sep 17 15:30:20.518712 2026] [security2:error] [pid 18946:tid 19085] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxb7DqiPMah0Tz_U1N90wAAARM"]
[Thu Sep 17 15:30:20.807759 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.232.68:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/phpinfo.php~"] [unique_id "aqxb7DqiPMah0Tz_U1N93gAAAWA"]
[Thu Sep 17 15:30:21.293310 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.232.68:51604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/info.php.bak"] [unique_id "aqxb7TqiPMah0Tz_U1N96gAAAYk"]
[Thu Sep 17 15:30:21.361575 2026] [security2:error] [pid 18946:tid 19179] [client 103.61.184.148:56630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7TqiPMah0Tz_U1N96wAAAXE"]
[Thu Sep 17 15:30:21.361744 2026] [security2:error] [pid 18946:tid 19179] [client 103.61.184.148:56630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7TqiPMah0Tz_U1N96wAAAXE"]
[Thu Sep 17 15:30:21.698654 2026] [security2:error] [pid 18946:tid 19136] [client 184.154.36.186:51618] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "405"] [hostname "houselifeinc.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7TqiPMah0Tz_U1N98AAAAUY"]
[Thu Sep 17 15:30:21.767719 2026] [security2:error] [pid 18946:tid 19183] [client 34.154.232.68:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/phpinfo.php.save"] [unique_id "aqxb7TqiPMah0Tz_U1N99AAAAXU"]
[Thu Sep 17 15:30:21.982428 2026] [security2:error] [pid 18946:tid 19169] [client 3.19.142.206:63721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb7TqiPMah0Tz_U1N9-wAAAWc"]
[Thu Sep 17 15:30:22.026983 2026] [security2:error] [pid 18946:tid 19143] [client 184.154.36.186:51620] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houselifeinc.com"] [uri "/index.php"] [unique_id "aqxb7TqiPMah0Tz_U1N99wAAAU0"]
[Thu Sep 17 15:30:22.188115 2026] [security2:error] [pid 18946:tid 19192] [client 18.188.3.41:53001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/web/xmlrpc.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-AQAAAX4"]
[Thu Sep 17 15:30:22.246127 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.232.68:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-AgAAAUA"]
[Thu Sep 17 15:30:22.436593 2026] [security2:error] [pid 18946:tid 19121] [client 184.154.36.186:51624] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houselifeinc.com"] [uri "/index.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-BAAAATc"]
[Thu Sep 17 15:30:22.578785 2026] [security2:error] [pid 18946:tid 19082] [client 114.198.138.124:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-BQAAARA"]
[Thu Sep 17 15:30:22.578915 2026] [security2:error] [pid 18946:tid 19082] [client 114.198.138.124:52843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-BQAAARA"]
[Thu Sep 17 15:30:22.737308 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.232.68:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-CgAAARk"]
[Thu Sep 17 15:30:22.900882 2026] [security2:error] [pid 18946:tid 19176] [client 136.158.61.34:41502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-DAAAAW4"]
[Thu Sep 17 15:30:22.900995 2026] [security2:error] [pid 18946:tid 19176] [client 136.158.61.34:41502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7jqiPMah0Tz_U1N-DAAAAW4"]
[Thu Sep 17 15:30:23.223155 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.232.68:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxb7zqiPMah0Tz_U1N-FQAAASQ"]
[Thu Sep 17 15:30:23.271350 2026] [security2:error] [pid 18946:tid 19122] [client 89.92.213.162:64063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb7zqiPMah0Tz_U1N-EAABOAo"]
[Thu Sep 17 15:30:23.409706 2026] [security2:error] [pid 18946:tid 19163] [client 184.154.36.186:51634] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houselifeinc.com"] [uri "/wp-content/themes/Divi/includes/builder/scripts/jquery.mobile.custom.min.js"] [unique_id "aqxb7zqiPMah0Tz_U1N-GAAAAWE"]
[Thu Sep 17 15:30:23.713069 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.232.68:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxb7zqiPMah0Tz_U1N-HQAAAT4"]
[Thu Sep 17 15:30:23.779067 2026] [authz_core:error] [pid 18946:tid 19106] [client 169.58.197.253:55896] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:30:23.967140 2026] [security2:error] [pid 18946:tid 18953] [remote 45.157.54.43:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "darfieldearthship.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7zqiPMah0Tz_U1N-JAABWAY"]
[Thu Sep 17 15:30:23.967349 2026] [security2:error] [pid 18946:tid 19154] [client 45.157.54.43:52569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "darfieldearthship.com"] [uri "/xmlrpc.php"] [unique_id "aqxb7zqiPMah0Tz_U1N-JAABWAY"]
[Thu Sep 17 15:30:23.998040 2026] [security2:error] [pid 18946:tid 19165] [client 57.141.14.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whataboutsarah.ca"] [uri "/index.php"] [unique_id "aqxb7TqiPMah0Tz_U1N94gAAAWM"]
[Thu Sep 17 15:30:24.178244 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.232.68:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxb8DqiPMah0Tz_U1N-LQAAAVA"]
[Thu Sep 17 15:30:24.508025 2026] [security2:error] [pid 18946:tid 19083] [client 184.154.36.186:35702] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "houselifeinc.com"] [uri "/\\\\\\"https:\\\\/\\\\/houselifeinc.com\\\\/\\\\\\""] [unique_id "aqxb8DqiPMah0Tz_U1N-OAAAARE"]
[Thu Sep 17 15:30:24.655893 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.232.68:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/www/phpinfo.php"] [unique_id "aqxb8DqiPMah0Tz_U1N-PQAAAQw"]
[Thu Sep 17 15:30:24.732389 2026] [security2:error] [pid 18946:tid 19178] [client 152.32.225.35:34608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5305.bluehost.com"] [uri "/index.cgi"] [unique_id "aqxb8DqiPMah0Tz_U1N-QAAAAXA"]
[Thu Sep 17 15:30:24.737307 2026] [security2:error] [pid 18946:tid 19164] [client 184.154.36.186:51672] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "houselifeinc.com"] [uri "/cgi-sys/404.html"] [unique_id "aqxb8DqiPMah0Tz_U1N-QgAAAWI"]
[Thu Sep 17 15:30:25.114883 2026] [security2:error] [pid 18946:tid 19082] [client 184.154.36.186:51678] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houselifeinc.com"] [uri "/index.php"] [unique_id "aqxb8DqiPMah0Tz_U1N-RwAAARA"]
[Thu Sep 17 15:30:25.145586 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.232.68:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxb8TqiPMah0Tz_U1N-SwAAARM"]
[Thu Sep 17 15:30:25.190811 2026] [fcgid:warn] [pid 18946:tid 19093] (70014)End of file found: [client 152.32.225.35:52780] mod_fcgid: can't get data from http client
[Thu Sep 17 15:30:25.205581 2026] [security2:error] [pid 18946:tid 18968] [remote 45.157.54.43:54179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "darfieldearthship.numeraconsulting.ca"] [uri "/xmlrpc.php"] [unique_id "aqxb8TqiPMah0Tz_U1N-TgABSRU"]
[Thu Sep 17 15:30:25.205748 2026] [security2:error] [pid 18946:tid 19139] [client 45.157.54.43:54179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "darfieldearthship.numeraconsulting.ca"] [uri "/xmlrpc.php"] [unique_id "aqxb8TqiPMah0Tz_U1N-TgABSRU"]
[Thu Sep 17 15:30:25.534105 2026] [fcgid:warn] [pid 18946:tid 19108] (70014)End of file found: [client 152.32.225.35:52842] mod_fcgid: can't get data from http client
[Thu Sep 17 15:30:25.620041 2026] [security2:error] [pid 18946:tid 19098] [client 34.154.232.68:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxb8TqiPMah0Tz_U1N-VwAAASA"]
[Thu Sep 17 15:30:25.789755 2026] [security2:error] [pid 18946:tid 19127] [client 210.222.43.21:52176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxb8TqiPMah0Tz_U1N-VgAAAT0"], referer: http://talent-in-borders.com/shop
[Thu Sep 17 15:30:25.929988 2026] [fcgid:warn] [pid 18946:tid 19154] (70014)End of file found: [client 152.32.225.35:52880] mod_fcgid: can't get data from http client
[Thu Sep 17 15:30:26.084012 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.232.68:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/site/phpinfo.php"] [unique_id "aqxb8jqiPMah0Tz_U1N-aQAAAR0"]
[Thu Sep 17 15:30:26.560086 2026] [security2:error] [pid 18946:tid 19100] [client 34.154.232.68:51702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxb8jqiPMah0Tz_U1N-bgAAASI"]
[Thu Sep 17 15:30:26.682754 2026] [security2:error] [pid 18946:tid 19197] [client 184.154.36.186:51722] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houselifeinc.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxb8jqiPMah0Tz_U1N-dwAAAYM"]
[Thu Sep 17 15:30:26.744915 2026] [security2:error] [pid 18946:tid 19143] [client 41.193.163.136:16946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb8jqiPMah0Tz_U1N-dAABTR4"]
[Thu Sep 17 15:30:26.791943 2026] [security2:error] [pid 18946:tid 19112] [client 3.19.142.206:65174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxb8jqiPMah0Tz_U1N-eAAAAS4"]
[Thu Sep 17 15:30:27.042892 2026] [security2:error] [pid 18946:tid 19161] [client 34.154.232.68:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxb8zqiPMah0Tz_U1N-gwAAAV8"]
[Thu Sep 17 15:30:27.069140 2026] [security2:error] [pid 18946:tid 19164] [client 184.154.36.186:51724] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houselifeinc.com"] [uri "/wp-content/themes/Divi/style.css"] [unique_id "aqxb8jqiPMah0Tz_U1N-ggAAAWI"]
[Thu Sep 17 15:30:27.533748 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.232.68:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxb8zqiPMah0Tz_U1N-jwAAATk"]
[Thu Sep 17 15:30:27.557778 2026] [core:error] [pid 18946:tid 19167] [client 107.189.6.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:27.557801 2026] [core:error] [pid 18946:tid 19167] [client 107.189.6.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:27.611228 2026] [security2:error] [pid 18946:tid 19115] [client 74.7.228.20:45482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "npcplano.com"] [uri "/robots.txt"] [unique_id "aqxb8zqiPMah0Tz_U1N-kQAAATE"]
[Thu Sep 17 15:30:27.845961 2026] [core:error] [pid 18946:tid 19128] [client 138.246.253.24:38244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:27.845982 2026] [core:error] [pid 18946:tid 19128] [client 138.246.253.24:38244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:28.027619 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.232.68:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/core/phpinfo.php"] [unique_id "aqxb9DqiPMah0Tz_U1N_CQAAAVM"]
[Thu Sep 17 15:30:28.133801 2026] [http2:info] [pid 20162:tid 20162] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:30:28.520719 2026] [security2:error] [pid 20162:tid 20294] [client 3.19.142.206:49715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxb9K-O_Kk7aqBvaiFvDQAAAZA"]
[Thu Sep 17 15:30:28.521677 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.232.68:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.ravenindustries.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxb9DqiPMah0Tz_U1N_EgAAAT4"]
[Thu Sep 17 15:30:28.928271 2026] [security2:error] [pid 20162:tid 20302] [client 74.7.175.141:60476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "jaremsawatsky.cqf.sfu.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxb9K-O_Kk7aqBvaiFvEQAAAZg"]
[Thu Sep 17 15:30:29.007163 2026] [security2:error] [pid 20162:tid 20305] [client 74.7.175.141:60476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jaremsawatsky.cqf.sfu.mybluehost.me"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxb9K-O_Kk7aqBvaiFvEwAAAZs"], referer: https://jaremsawatsky.cqf.sfu.mybluehost.me/robots.txt
[Thu Sep 17 15:30:29.545632 2026] [security2:error] [pid 20162:tid 20318] [client 18.188.3.41:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.3.188.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tazbodywork.com"] [uri "/site/xmlrpc.php"] [unique_id "aqxb9a-O_Kk7aqBvaiFvHgAAAag"]
[Thu Sep 17 15:30:30.271917 2026] [security2:error] [pid 18946:tid 19194] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxb9DqiPMah0Tz_U1N_DQAAAYA"]
[Thu Sep 17 15:30:30.878817 2026] [security2:error] [pid 20162:tid 20348] [client 143.105.152.240:47288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb9q-O_Kk7aqBvaiFvMwAAAcY"]
[Thu Sep 17 15:30:30.878968 2026] [security2:error] [pid 20162:tid 20348] [client 143.105.152.240:47288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxb9q-O_Kk7aqBvaiFvMwAAAcY"]
[Thu Sep 17 15:30:31.378609 2026] [security2:error] [pid 18946:tid 19111] [client 3.19.142.206:50624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_RwAAAS0"]
[Thu Sep 17 15:30:31.378666 2026] [security2:error] [pid 18946:tid 19111] [client 3.19.142.206:50624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_RwAAAS0"]
[Thu Sep 17 15:30:31.451564 2026] [security2:error] [pid 18946:tid 19127] [client 3.19.142.206:50673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_SgAAAT0"]
[Thu Sep 17 15:30:31.451610 2026] [security2:error] [pid 18946:tid 19127] [client 3.19.142.206:50673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_SgAAAT0"]
[Thu Sep 17 15:30:31.489983 2026] [security2:error] [pid 18946:tid 19107] [client 3.19.142.206:50704] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_TwAAASk"]
[Thu Sep 17 15:30:31.490014 2026] [security2:error] [pid 18946:tid 19107] [client 3.19.142.206:50704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_TwAAASk"]
[Thu Sep 17 15:30:31.490059 2026] [security2:error] [pid 18946:tid 19107] [client 3.19.142.206:50704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_TwAAASk"]
[Thu Sep 17 15:30:31.503047 2026] [security2:error] [pid 18946:tid 19180] [client 3.19.142.206:50624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_UQAAAXI"]
[Thu Sep 17 15:30:31.503102 2026] [security2:error] [pid 18946:tid 19180] [client 3.19.142.206:50624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/old/xmlrpc.php"] [unique_id "aqxb9zqiPMah0Tz_U1N_UQAAAXI"]
[Thu Sep 17 15:30:32.169671 2026] [security2:error] [pid 18946:tid 19189] [client 103.61.184.148:57666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-DqiPMah0Tz_U1N_dAAAAXs"]
[Thu Sep 17 15:30:32.169812 2026] [security2:error] [pid 18946:tid 19189] [client 103.61.184.148:57666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-DqiPMah0Tz_U1N_dAAAAXs"]
[Thu Sep 17 15:30:32.173111 2026] [security2:error] [pid 18946:tid 19113] [client 52.167.144.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxb-DqiPMah0Tz_U1N_bwAAAS8"]
[Thu Sep 17 15:30:32.655799 2026] [security2:error] [pid 18946:tid 19131] [client 38.210.0.166:56939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb-DqiPMah0Tz_U1N_dgABQSk"]
[Thu Sep 17 15:30:32.766532 2026] [security2:error] [pid 20162:tid 20295] [client 130.210.56.65:60964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "anumbersjourney.com"] [uri "/"] [unique_id "aqxb-K-O_Kk7aqBvaiFvWgAAAZE"]
[Thu Sep 17 15:30:33.309871 2026] [security2:error] [pid 20162:tid 20309] [client 114.198.138.124:53488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-a-O_Kk7aqBvaiFvYgAAAZ8"]
[Thu Sep 17 15:30:33.309995 2026] [security2:error] [pid 20162:tid 20309] [client 114.198.138.124:53488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-a-O_Kk7aqBvaiFvYgAAAZ8"]
[Thu Sep 17 15:30:33.481006 2026] [security2:error] [pid 18946:tid 19161] [client 93.152.209.11:1954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.fmo.xwi.mybluehost.me"] [uri "/.env"] [unique_id "aqxb-TqiPMah0Tz_U1N_gAAAAV8"]
[Thu Sep 17 15:30:33.642135 2026] [security2:error] [pid 20162:tid 20169] [remote 93.152.209.11:23270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.fmo.xwi.mybluehost.me"] [uri "/.env"] [unique_id "aqxb-a-O_Kk7aqBvaiFvZAABpwU"]
[Thu Sep 17 15:30:34.035753 2026] [security2:error] [pid 20162:tid 20339] [client 3.19.142.206:51473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxb-q-O_Kk7aqBvaiFvbwAAAb0"]
[Thu Sep 17 15:30:34.055742 2026] [security2:error] [pid 20162:tid 20335] [client 52.167.144.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxb-a-O_Kk7aqBvaiFvbgAAAbk"]
[Thu Sep 17 15:30:34.321127 2026] [security2:error] [pid 18946:tid 19013] [remote 45.157.54.43:65532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "darfieldearthship.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-jqiPMah0Tz_U1N_jgABLkI"]
[Thu Sep 17 15:30:34.321276 2026] [security2:error] [pid 18946:tid 19112] [client 45.157.54.43:65532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "darfieldearthship.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-jqiPMah0Tz_U1N_jgABLkI"]
[Thu Sep 17 15:30:34.900093 2026] [fcgid:warn] [pid 20162:tid 20381] (70014)End of file found: [client 152.32.225.35:35542] mod_fcgid: can't get data from http client
[Thu Sep 17 15:30:35.166891 2026] [security2:error] [pid 20162:tid 20370] [client 136.158.61.34:42695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-6-O_Kk7aqBvaiFvgQAAAdw"]
[Thu Sep 17 15:30:35.167038 2026] [security2:error] [pid 20162:tid 20370] [client 136.158.61.34:42695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxb-6-O_Kk7aqBvaiFvgQAAAdw"]
[Thu Sep 17 15:30:35.317607 2026] [security2:error] [pid 20162:tid 20387] [client 186.55.147.56:53777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxb-6-O_Kk7aqBvaiFvggAB7Qk"]
[Thu Sep 17 15:30:36.230970 2026] [security2:error] [pid 20162:tid 20174] [remote 45.157.54.43:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "darfieldearthship.numeraconsulting.ca"] [uri "/xmlrpc.php"] [unique_id "aqxb_K-O_Kk7aqBvaiFvjAAB8go"]
[Thu Sep 17 15:30:36.231200 2026] [security2:error] [pid 20162:tid 20392] [client 45.157.54.43:11200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "darfieldearthship.numeraconsulting.ca"] [uri "/xmlrpc.php"] [unique_id "aqxb_K-O_Kk7aqBvaiFvjAAB8go"]
[Thu Sep 17 15:30:36.615914 2026] [log_config:warn] [pid 1029697:tid 1029882] (32)Broken pipe: [client 102.253.135.10:45943] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log, referer: https://freegamest.com/?s=farm
[Thu Sep 17 15:30:36.615932 2026] [log_config:warn] [pid 1029697:tid 1029882] (32)Broken pipe: [client 102.253.135.10:45943] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log, referer: https://freegamest.com/?s=farm
[Thu Sep 17 15:30:36.702423 2026] [security2:error] [pid 20162:tid 20175] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env"] [unique_id "aqxb_K-O_Kk7aqBvaiFvkgACDgs"]
[Thu Sep 17 15:30:36.704293 2026] [security2:error] [pid 20162:tid 20180] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxb_K-O_Kk7aqBvaiFvmQACDhA"]
[Thu Sep 17 15:30:36.704603 2026] [security2:error] [pid 20162:tid 20188] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxb_K-O_Kk7aqBvaiFvnwACDhg"]
[Thu Sep 17 15:30:36.704607 2026] [security2:error] [pid 20162:tid 20175] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxb_K-O_Kk7aqBvaiFvngACDgs"]
[Thu Sep 17 15:30:36.884861 2026] [security2:error] [pid 20162:tid 20193] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env~"] [unique_id "aqxb_K-O_Kk7aqBvaiFvpAABkB0"]
[Thu Sep 17 15:30:36.884870 2026] [security2:error] [pid 20162:tid 20196] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxb_K-O_Kk7aqBvaiFvpwABkCA"]
[Thu Sep 17 15:30:36.895443 2026] [fcgid:warn] [pid 20162:tid 20297] (70014)End of file found: [client 152.32.205.184:40798] mod_fcgid: can't get data from http client
[Thu Sep 17 15:30:36.897649 2026] [security2:error] [pid 20162:tid 20194] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env.php"] [unique_id "aqxb_K-O_Kk7aqBvaiFvpQABkB4"]
[Thu Sep 17 15:30:37.063177 2026] [security2:error] [pid 20162:tid 20203] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvsQABkic"]
[Thu Sep 17 15:30:37.063230 2026] [security2:error] [pid 20162:tid 20204] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvsgABkig"]
[Thu Sep 17 15:30:37.063334 2026] [security2:error] [pid 20162:tid 20206] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvtAABkio"]
[Thu Sep 17 15:30:37.065653 2026] [security2:error] [pid 20162:tid 20209] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvtwABmy0"]
[Thu Sep 17 15:30:37.065801 2026] [security2:error] [pid 20162:tid 20212] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvugABmzA"]
[Thu Sep 17 15:30:37.065849 2026] [security2:error] [pid 20162:tid 20213] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvuwABmzE"]
[Thu Sep 17 15:30:37.065852 2026] [security2:error] [pid 20162:tid 20211] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvuQABmy8"]
[Thu Sep 17 15:30:37.065865 2026] [security2:error] [pid 20162:tid 20214] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvvAABmzI"]
[Thu Sep 17 15:30:37.065888 2026] [security2:error] [pid 20162:tid 20215] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvvQABmzM"]
[Thu Sep 17 15:30:37.065888 2026] [security2:error] [pid 20162:tid 20210] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvuAABmy4"]
[Thu Sep 17 15:30:37.065953 2026] [security2:error] [pid 20162:tid 20216] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvvgABmzQ"]
[Thu Sep 17 15:30:37.078224 2026] [security2:error] [pid 20162:tid 20217] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvvwABnTU"]
[Thu Sep 17 15:30:37.244267 2026] [security2:error] [pid 20162:tid 20219] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvxQABojc"]
[Thu Sep 17 15:30:37.244279 2026] [security2:error] [pid 20162:tid 20220] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvxAABojg"]
[Thu Sep 17 15:30:37.244332 2026] [security2:error] [pid 20162:tid 20218] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvwwABojY"]
[Thu Sep 17 15:30:37.245876 2026] [security2:error] [pid 20162:tid 20221] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/back/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvxgABmTk"]
[Thu Sep 17 15:30:37.249106 2026] [security2:error] [pid 20162:tid 20222] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvyAABpjo"]
[Thu Sep 17 15:30:37.249181 2026] [security2:error] [pid 20162:tid 20224] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvygABpjw"]
[Thu Sep 17 15:30:37.249411 2026] [security2:error] [pid 20162:tid 20226] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvzAABpj4"]
[Thu Sep 17 15:30:37.249435 2026] [security2:error] [pid 20162:tid 20225] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvywABpj0"]
[Thu Sep 17 15:30:37.249477 2026] [security2:error] [pid 20162:tid 20228] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvzgABpkA"]
[Thu Sep 17 15:30:37.249480 2026] [security2:error] [pid 20162:tid 20231] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/node-api/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv0QABpkM"]
[Thu Sep 17 15:30:37.249509 2026] [security2:error] [pid 20162:tid 20230] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/new/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv0AABpkI"]
[Thu Sep 17 15:30:37.249531 2026] [security2:error] [pid 20162:tid 20229] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvzwABpkE"]
[Thu Sep 17 15:30:37.249564 2026] [security2:error] [pid 20162:tid 20227] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvzQABpj8"]
[Thu Sep 17 15:30:37.249787 2026] [security2:error] [pid 20162:tid 20223] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFvyQABpjs"]
[Thu Sep 17 15:30:37.252056 2026] [security2:error] [pid 20162:tid 20232] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/api-backend/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv0gABqUQ"]
[Thu Sep 17 15:30:37.258813 2026] [security2:error] [pid 20162:tid 20233] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/admin-app/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv0wABp0U"]
[Thu Sep 17 15:30:37.425542 2026] [security2:error] [pid 20162:tid 20236] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv1gABqkg"]
[Thu Sep 17 15:30:37.425556 2026] [security2:error] [pid 20162:tid 20235] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv1QABqkc"]
[Thu Sep 17 15:30:37.425694 2026] [security2:error] [pid 20162:tid 20237] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/server/api/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv1wABqkk"]
[Thu Sep 17 15:30:37.429429 2026] [security2:error] [pid 20162:tid 20238] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/server/backend/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv2AABqko"]
[Thu Sep 17 15:30:37.429474 2026] [security2:error] [pid 20162:tid 20242] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.aws/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv3AABqk4"]
[Thu Sep 17 15:30:37.429491 2026] [security2:error] [pid 20162:tid 20239] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.docker/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv2QABqks"]
[Thu Sep 17 15:30:37.429521 2026] [security2:error] [pid 20162:tid 20240] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv2gABqkw"]
[Thu Sep 17 15:30:37.429560 2026] [security2:error] [pid 20162:tid 20241] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv2wABqk0"]
[Thu Sep 17 15:30:37.429571 2026] [security2:error] [pid 20162:tid 20243] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/stripe/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv3QABqk8"]
[Thu Sep 17 15:30:37.429801 2026] [security2:error] [pid 20162:tid 20246] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv4AABqlI"]
[Thu Sep 17 15:30:37.431550 2026] [security2:error] [pid 20162:tid 20247] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv4gABqlM"]
[Thu Sep 17 15:30:37.431990 2026] [security2:error] [pid 20162:tid 20248] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv4wABqlQ"]
[Thu Sep 17 15:30:37.438605 2026] [security2:error] [pid 20162:tid 20249] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/media/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv5AABqlU"]
[Thu Sep 17 15:30:37.440425 2026] [security2:error] [pid 20162:tid 20234] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxb_a-O_Kk7aqBvaiFv1AABqkY"]
[Thu Sep 17 15:30:37.616522 2026] [security2:error] [pid 20162:tid 20262] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.git/config.bak"] [unique_id "aqxb_a-O_Kk7aqBvaiFv8gABo2I"]
[Thu Sep 17 15:30:37.798047 2026] [security2:error] [pid 20162:tid 20275] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.ssh/id_rsa"] [unique_id "aqxb_a-O_Kk7aqBvaiFwAAABr28"]
[Thu Sep 17 15:30:37.798071 2026] [security2:error] [pid 20162:tid 20276] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/id_rsa"] [unique_id "aqxb_a-O_Kk7aqBvaiFwAQABr3A"]
[Thu Sep 17 15:30:37.798151 2026] [security2:error] [pid 20162:tid 20271] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/.aws/credentials.bak"] [unique_id "aqxb_a-O_Kk7aqBvaiFv_AABr2s"]
[Thu Sep 17 15:30:38.162073 2026] [security2:error] [pid 20162:tid 20183] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/config.php"] [unique_id "aqxb_q-O_Kk7aqBvaiFwIwABwBM"]
[Thu Sep 17 15:30:38.346430 2026] [security2:error] [pid 20162:tid 20191] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/config/aws.php"] [unique_id "aqxb_q-O_Kk7aqBvaiFwNQABzhs"]
[Thu Sep 17 15:30:38.346441 2026] [security2:error] [pid 20162:tid 20200] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/config/stripe.php"] [unique_id "aqxb_q-O_Kk7aqBvaiFwNwABziQ"]
[Thu Sep 17 15:30:38.346857 2026] [security2:error] [pid 20162:tid 20191] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/config/mail.php"] [unique_id "aqxb_q-O_Kk7aqBvaiFwOQABzhs"]
[Thu Sep 17 15:30:38.346974 2026] [security2:error] [pid 20162:tid 20192] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/config/config.inc.php"] [unique_id "aqxb_q-O_Kk7aqBvaiFwOwABzhw"]
[Thu Sep 17 15:30:38.347049 2026] [security2:error] [pid 20162:tid 20194] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/config/nexmo.php"] [unique_id "aqxb_q-O_Kk7aqBvaiFwPAABzh4"]
[Thu Sep 17 15:30:38.351023 2026] [security2:error] [pid 20162:tid 20207] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/wp-config.php"] [unique_id "aqxb_q-O_Kk7aqBvaiFwPwAB0Ss"]
[Thu Sep 17 15:30:38.588785 2026] [security2:error] [pid 18946:tid 19171] [client 3.19.142.206:53006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxb_jqiPMah0Tz_U1N_uQAAAWk"]
[Thu Sep 17 15:30:38.707321 2026] [security2:error] [pid 20162:tid 20212] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eej.kbo.mybluehost.me"] [uri "/wp-config.php.new"] [unique_id "aqxb_q-O_Kk7aqBvaiFwRAABzTA"]
[Thu Sep 17 15:30:38.707332 2026] [security2:error] [pid 20162:tid 20209] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eej.kbo.mybluehost.me"] [uri "/wp-config.php.old"] [unique_id "aqxb_q-O_Kk7aqBvaiFwQgABzS0"]
[Thu Sep 17 15:30:38.707330 2026] [security2:error] [pid 20162:tid 20205] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "eej.kbo.mybluehost.me"] [uri "/wp-config.php.bak"] [unique_id "aqxb_q-O_Kk7aqBvaiFwQwABzSk"]
[Thu Sep 17 15:30:38.707900 2026] [security2:error] [pid 20162:tid 20214] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/.wp-config.php.swp"] [unique_id "aqxb_q-O_Kk7aqBvaiFwRQABzTI"]
[Thu Sep 17 15:30:38.709108 2026] [security2:error] [pid 20162:tid 20211] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/wp-content/mysql.sql"] [unique_id "aqxb_q-O_Kk7aqBvaiFwRwABzS8"]
[Thu Sep 17 15:30:38.711805 2026] [security2:error] [pid 20162:tid 20220] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/terraform.tfstate.backup"] [unique_id "aqxb_q-O_Kk7aqBvaiFwTwABwTg"]
[Thu Sep 17 15:30:39.276580 2026] [security2:error] [pid 20162:tid 20256] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwfwAB6Fw"]
[Thu Sep 17 15:30:39.462829 2026] [security2:error] [pid 20162:tid 20266] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwiwAB5WY"]
[Thu Sep 17 15:30:39.462855 2026] [security2:error] [pid 20162:tid 20274] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/infophp.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwjAAB5W4"]
[Thu Sep 17 15:30:39.462879 2026] [security2:error] [pid 20162:tid 20272] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/php_info.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwiQAB5Ww"]
[Thu Sep 17 15:30:39.462891 2026] [security2:error] [pid 20162:tid 20277] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/php.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwigAB5XE"]
[Thu Sep 17 15:30:39.462932 2026] [security2:error] [pid 20162:tid 20273] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/infos.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwiAAB5W0"]
[Thu Sep 17 15:30:39.462961 2026] [security2:error] [pid 20162:tid 20276] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/info.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwhwAB5XA"]
[Thu Sep 17 15:30:39.464026 2026] [security2:error] [pid 20162:tid 20278] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwjwAB8HI"]
[Thu Sep 17 15:30:39.464048 2026] [security2:error] [pid 20162:tid 20280] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/admin_phpinfo.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwkAAB8HQ"]
[Thu Sep 17 15:30:39.464072 2026] [security2:error] [pid 20162:tid 20166] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwkgAB8AI"]
[Thu Sep 17 15:30:39.464110 2026] [security2:error] [pid 20162:tid 20281] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/api/phpinfo.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwkQAB8HU"]
[Thu Sep 17 15:30:39.464148 2026] [security2:error] [pid 20162:tid 20279] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwjgAB8HM"]
[Thu Sep 17 15:30:39.654532 2026] [security2:error] [pid 20162:tid 20288] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/database.sql"] [unique_id "aqxb_6-O_Kk7aqBvaiFwnQAB7Xw"]
[Thu Sep 17 15:30:39.844067 2026] [security2:error] [pid 20162:tid 20181] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/aws_secret_config.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwrgAB6RE"]
[Thu Sep 17 15:30:39.844161 2026] [security2:error] [pid 20162:tid 20177] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/textpattern/config.php"] [unique_id "aqxb_6-O_Kk7aqBvaiFwswAB6Q0"]
[Thu Sep 17 15:30:39.849789 2026] [security2:error] [pid 20162:tid 20204] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/market/.env"] [unique_id "aqxb_6-O_Kk7aqBvaiFwuAAB7Cg"]
[Thu Sep 17 15:30:40.029987 2026] [security2:error] [pid 20162:tid 20199] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eej.kbo.mybluehost.me"] [uri "/.env.local.php"] [unique_id "aqxcAK-O_Kk7aqBvaiFwwgAB-yM"]
[Thu Sep 17 15:30:40.030486 2026] [security2:error] [pid 20162:tid 20195] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxcAK-O_Kk7aqBvaiFwwQAB-x8"]
[Thu Sep 17 15:30:40.030500 2026] [security2:error] [pid 20162:tid 20202] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/back-end/.env"] [unique_id "aqxcAK-O_Kk7aqBvaiFwxAAB-yY"]
[Thu Sep 17 15:30:40.030559 2026] [security2:error] [pid 20162:tid 20191] [remote 45.138.12.24:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eej.kbo.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxcAK-O_Kk7aqBvaiFwwwAB-xs"]
[Thu Sep 17 15:30:40.781918 2026] [core:error] [pid 18946:tid 19026] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/wordpress/
[Thu Sep 17 15:30:40.781944 2026] [core:error] [pid 18946:tid 19026] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/wordpress/
[Thu Sep 17 15:30:41.105656 2026] [core:error] [pid 18946:tid 19028] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/old/
[Thu Sep 17 15:30:41.105691 2026] [core:error] [pid 18946:tid 19028] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/old/
[Thu Sep 17 15:30:41.191978 2026] [security2:error] [pid 20162:tid 20406] [client 3.19.142.206:53771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxcAa-O_Kk7aqBvaiFw1gAAAgA"]
[Thu Sep 17 15:30:41.420621 2026] [security2:error] [pid 18946:tid 19169] [client 143.105.152.240:10699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcATqiPMah0Tz_U1N_2QAAAWc"]
[Thu Sep 17 15:30:41.420779 2026] [security2:error] [pid 18946:tid 19169] [client 143.105.152.240:10699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcATqiPMah0Tz_U1N_2QAAAWc"]
[Thu Sep 17 15:30:41.739930 2026] [core:error] [pid 18946:tid 19034] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/blog/
[Thu Sep 17 15:30:41.739959 2026] [core:error] [pid 18946:tid 19034] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/blog/
[Thu Sep 17 15:30:42.051403 2026] [core:error] [pid 18946:tid 19035] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/backup/
[Thu Sep 17 15:30:42.051428 2026] [core:error] [pid 18946:tid 19035] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/backup/
[Thu Sep 17 15:30:42.368911 2026] [core:error] [pid 18946:tid 19036] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/wp/
[Thu Sep 17 15:30:42.368935 2026] [core:error] [pid 18946:tid 19036] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/wp/
[Thu Sep 17 15:30:42.678632 2026] [core:error] [pid 18946:tid 19039] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/new/
[Thu Sep 17 15:30:42.678665 2026] [core:error] [pid 18946:tid 19039] [remote 104.248.203.175:56828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://mail.carmody5.net/new/
[Thu Sep 17 15:30:42.768298 2026] [security2:error] [pid 20162:tid 20215] [remote 47.128.99.215:47988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gazillionmexico.com"] [uri "/"] [unique_id "aqxcAq-O_Kk7aqBvaiFw5gABtjM"]
[Thu Sep 17 15:30:42.837648 2026] [security2:error] [pid 18946:tid 19164] [client 103.61.184.148:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcAjqiPMah0Tz_U1N_8AAAAWI"]
[Thu Sep 17 15:30:42.837824 2026] [security2:error] [pid 18946:tid 19164] [client 103.61.184.148:58181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcAjqiPMah0Tz_U1N_8AAAAWI"]
[Thu Sep 17 15:30:43.394994 2026] [authz_core:error] [pid 20162:tid 20346] [client 169.58.197.253:57067] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:30:43.471773 2026] [security2:error] [pid 20162:tid 20340] [client 3.19.142.206:54766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcA6-O_Kk7aqBvaiFw6wAAAb4"]
[Thu Sep 17 15:30:43.472784 2026] [security2:error] [pid 20162:tid 20340] [client 3.19.142.206:54766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcA6-O_Kk7aqBvaiFw6wAAAb4"]
[Thu Sep 17 15:30:43.523606 2026] [security2:error] [pid 20162:tid 20342] [client 3.19.142.206:54785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcA6-O_Kk7aqBvaiFw7gAAAcA"]
[Thu Sep 17 15:30:43.524113 2026] [security2:error] [pid 20162:tid 20342] [client 3.19.142.206:54785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcA6-O_Kk7aqBvaiFw7gAAAcA"]
[Thu Sep 17 15:30:43.536389 2026] [security2:error] [pid 20162:tid 20353] [client 3.19.142.206:54789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcA6-O_Kk7aqBvaiFw7wAAAcs"]
[Thu Sep 17 15:30:43.536487 2026] [security2:error] [pid 20162:tid 20353] [client 3.19.142.206:54789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcA6-O_Kk7aqBvaiFw7wAAAcs"]
[Thu Sep 17 15:30:43.664599 2026] [security2:error] [pid 18946:tid 19161] [client 54.211.108.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lemuspools.com"] [uri "/index.php"] [unique_id "aqxcAzqiPMah0Tz_U1N_-QAAAV8"]
[Thu Sep 17 15:30:43.848769 2026] [security2:error] [pid 18946:tid 19127] [client 114.198.138.124:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcAzqiPMah0Tz_U1N__AAAAT0"]
[Thu Sep 17 15:30:43.849172 2026] [security2:error] [pid 18946:tid 19127] [client 114.198.138.124:65281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcAzqiPMah0Tz_U1N__AAAAT0"]
[Thu Sep 17 15:30:46.845566 2026] [security2:error] [pid 18946:tid 19146] [client 57.141.14.28:22758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxcBjqiPMah0Tz_U1OAFAABUGc"]
[Thu Sep 17 15:30:47.013511 2026] [security2:error] [pid 18946:tid 19170] [client 75.110.227.38:59187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcBjqiPMah0Tz_U1OAFwABaGs"], referer: https://www.google.com/
[Thu Sep 17 15:30:48.237658 2026] [access_compat:error] [pid 20162:tid 20364] [client 159.69.14.108:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/mishap-2-an-intentional-haunting-collectors-edition
[Thu Sep 17 15:30:48.338598 2026] [security2:error] [pid 20162:tid 20355] [client 3.19.142.206:56233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcCK-O_Kk7aqBvaiFxSgAAAc0"]
[Thu Sep 17 15:30:48.338725 2026] [security2:error] [pid 20162:tid 20355] [client 3.19.142.206:56233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "newspace.us"] [uri "/new/xmlrpc.php"] [unique_id "aqxcCK-O_Kk7aqBvaiFxSgAAAc0"]
[Thu Sep 17 15:30:48.741975 2026] [security2:error] [pid 18946:tid 19163] [client 136.158.61.34:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcCDqiPMah0Tz_U1OAJAAAAWE"]
[Thu Sep 17 15:30:48.742198 2026] [security2:error] [pid 18946:tid 19163] [client 136.158.61.34:43936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcCDqiPMah0Tz_U1OAJAAAAWE"]
[Thu Sep 17 15:30:49.004438 2026] [security2:error] [pid 20162:tid 20358] [client 81.208.175.87:51605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "rickanddonnaproctor.com"] [uri "/"] [unique_id "aqxcCa-O_Kk7aqBvaiFxTAAAAdA"]
[Thu Sep 17 15:30:49.341034 2026] [qos:error] [pid 18946:tid 19081] [client 45.115.26.203:60718] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCTqiPMah0Tz_U1OAgQAAAQ8
[Thu Sep 17 15:30:49.343959 2026] [qos:error] [pid 18946:tid 19107] [client 45.115.26.203:60516] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCTqiPMah0Tz_U1OAhAAAASk
[Thu Sep 17 15:30:49.344813 2026] [qos:error] [pid 18946:tid 19172] [client 45.115.26.203:60728] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCTqiPMah0Tz_U1OAhQAAAWo
[Thu Sep 17 15:30:49.345352 2026] [qos:error] [pid 18946:tid 19105] [client 45.115.26.203:60474] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCTqiPMah0Tz_U1OAhwAAASc
[Thu Sep 17 15:30:49.345747 2026] [qos:error] [pid 18946:tid 19196] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAiAAAAYI
[Thu Sep 17 15:30:49.345898 2026] [qos:error] [pid 18946:tid 19127] [client 45.115.26.203:60670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCTqiPMah0Tz_U1OAiQAAAT0
[Thu Sep 17 15:30:49.346003 2026] [qos:error] [pid 18946:tid 19120] [client 45.115.26.203:60764] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCTqiPMah0Tz_U1OAigAAATY
[Thu Sep 17 15:30:49.348164 2026] [qos:error] [pid 20162:tid 20412] [client 45.115.26.203:60364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCa-O_Kk7aqBvaiFxiQAAAgY
[Thu Sep 17 15:30:49.348578 2026] [qos:error] [pid 20162:tid 20419] [client 45.115.26.203:60762] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCa-O_Kk7aqBvaiFxigAAAg0
[Thu Sep 17 15:30:49.380472 2026] [qos:error] [pid 18946:tid 19133] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAlgAAAUM
[Thu Sep 17 15:30:49.383417 2026] [qos:error] [pid 18946:tid 19192] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAngAAAX4
[Thu Sep 17 15:30:49.387079 2026] [qos:error] [pid 18946:tid 19105] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAogAAASc
[Thu Sep 17 15:30:49.388984 2026] [qos:error] [pid 18946:tid 19149] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAmQAAAVM
[Thu Sep 17 15:30:49.389083 2026] [qos:error] [pid 18946:tid 19107] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAowAAASk
[Thu Sep 17 15:30:49.389197 2026] [qos:error] [pid 18946:tid 19175] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAnAAAAW0
[Thu Sep 17 15:30:49.391756 2026] [qos:error] [pid 18946:tid 19160] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAmAAAAV4
[Thu Sep 17 15:30:49.393600 2026] [qos:error] [pid 18946:tid 19189] [client 45.115.26.203:60512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCTqiPMah0Tz_U1OApgAAAXs
[Thu Sep 17 15:30:49.397401 2026] [qos:error] [pid 20162:tid 20418] [client 45.115.26.203:60502] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.115.26.203, id=aqxcCa-O_Kk7aqBvaiFxhgAAAgw
[Thu Sep 17 15:30:49.397653 2026] [qos:error] [pid 20162:tid 20403] [client 45.115.26.203:60626] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.115.26.203, id=aqxcCa-O_Kk7aqBvaiFxhwAAAf0
[Thu Sep 17 15:30:49.397774 2026] [qos:error] [pid 20162:tid 20324] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCa-O_Kk7aqBvaiFxhQAAAa4
[Thu Sep 17 15:30:49.399809 2026] [security2:error] [pid 18946:tid 19192] [client 81.208.175.87:51711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "rickanddonnaproctor.com"] [uri "/"] [unique_id "aqxcCTqiPMah0Tz_U1OAqgAAAX4"]
[Thu Sep 17 15:30:49.459290 2026] [qos:error] [pid 18946:tid 19169] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OArQAAAWc
[Thu Sep 17 15:30:49.459394 2026] [qos:error] [pid 18946:tid 19149] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAqwAAAVM
[Thu Sep 17 15:30:49.462590 2026] [qos:error] [pid 20162:tid 20331] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.230, id=aqxcCa-O_Kk7aqBvaiFxlAAAAbU
[Thu Sep 17 15:30:49.463888 2026] [qos:error] [pid 18946:tid 19090] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OArgAAARg
[Thu Sep 17 15:30:49.473778 2026] [qos:error] [pid 18946:tid 19193] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OArwAAAX8
[Thu Sep 17 15:30:49.485614 2026] [qos:error] [pid 20162:tid 20339] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCa-O_Kk7aqBvaiFxmwAAAb0
[Thu Sep 17 15:30:49.487286 2026] [qos:error] [pid 18946:tid 19187] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAsAAAAXk
[Thu Sep 17 15:30:49.494684 2026] [qos:error] [pid 20162:tid 20344] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCa-O_Kk7aqBvaiFxmAAAAcI
[Thu Sep 17 15:30:49.494948 2026] [qos:error] [pid 20162:tid 20382] [client 45.115.26.203:60782] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCa-O_Kk7aqBvaiFxfQAAAeg
[Thu Sep 17 15:30:49.495315 2026] [qos:error] [pid 20162:tid 20298] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCa-O_Kk7aqBvaiFxnAAAAZQ
[Thu Sep 17 15:30:49.495772 2026] [qos:error] [pid 18946:tid 19164] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAsQAAAWI
[Thu Sep 17 15:30:49.531620 2026] [qos:error] [pid 18946:tid 19090] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCTqiPMah0Tz_U1OAswAAARg
[Thu Sep 17 15:30:49.667647 2026] [security2:error] [pid 18946:tid 19084] [client 75.110.227.38:54759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcCTqiPMah0Tz_U1OAtAABEnQ"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260628153626&hideanons=1&limit=500&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:30:50.223160 2026] [qos:error] [pid 20162:tid 20298] [client 45.115.26.203:60818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxuAAAAZQ, referer: http://navishiur.org/product/choose-happiness-shoftim-21-sh-8/
[Thu Sep 17 15:30:50.223177 2026] [qos:error] [pid 20162:tid 20382] [client 45.115.26.203:60792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxvAAAAeg, referer: http://navishiur.org/product-category/seforim/?add-to-cart=2045
[Thu Sep 17 15:30:50.223189 2026] [qos:error] [pid 20162:tid 20341] [client 45.115.26.203:60858] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxuwAAAb8, referer: http://navishiur.org/product-category/seforim/?add-to-cart=4690
[Thu Sep 17 15:30:50.230180 2026] [qos:error] [pid 20162:tid 20351] [client 45.115.26.203:60866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxvgAAAck, referer: http://navishiur.org/product-category/seforim/
[Thu Sep 17 15:30:50.236094 2026] [qos:error] [pid 20162:tid 20300] [client 45.115.26.203:60800] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxvwAAAZY, referer: http://navishiur.org/product/two-esthers-shoftim-216-sh-12/
[Thu Sep 17 15:30:50.238853 2026] [qos:error] [pid 20162:tid 20356] [client 45.115.26.203:60934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxwgAAAc4, referer: http://navishiur.org/product-category/topic-sets/?add-to-cart=124
[Thu Sep 17 15:30:50.238860 2026] [qos:error] [pid 20162:tid 20352] [client 45.115.26.203:60838] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxwAAAAco, referer: http://navishiur.org/product/sefirah-special-complete-sefer-ezra-mp3-only/
[Thu Sep 17 15:30:50.238863 2026] [qos:error] [pid 20162:tid 20304] [client 45.115.26.203:60922] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxwQAAAZo, referer: http://navishiur.org/product-category/shoftim/?add-to-cart=2063
[Thu Sep 17 15:30:50.249368 2026] [qos:error] [pid 20162:tid 20417] [client 45.115.26.203:60848] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxwwAAAgs, referer: http://navishiur.org/product/worship-your-wife-shoftim-112-sh-5/
[Thu Sep 17 15:30:50.305806 2026] [qos:error] [pid 20162:tid 20369] [client 45.115.26.203:60994] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxxAAAAds, referer: http://navishiur.org/product-category/uncategorized/
[Thu Sep 17 15:30:50.308922 2026] [qos:error] [pid 20162:tid 20308] [client 45.115.26.203:60980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxxQAAAZ4, referer: http://navishiur.org/product/our-yerushalaym-18-sh-4/
[Thu Sep 17 15:30:50.310444 2026] [qos:error] [pid 18946:tid 19193] [client 45.115.26.203:60996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCjqiPMah0Tz_U1OA0AAAAX8, referer: http://navishiur.org/product-category/shoftim/?add-to-cart=2079
[Thu Sep 17 15:30:50.317717 2026] [qos:error] [pid 20162:tid 20342] [client 45.115.26.203:60964] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxxgAAAcA, referer: http://navishiur.org/product-category/shoftim/?add-to-cart=2133
[Thu Sep 17 15:30:50.318933 2026] [qos:error] [pid 20162:tid 20365] [client 45.115.26.203:60882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxywAAAdc, referer: http://navishiur.org/product-category/shoftim/?add-to-cart=2009
[Thu Sep 17 15:30:50.318937 2026] [qos:error] [pid 20162:tid 20345] [client 45.115.26.203:60898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxygAAAcM, referer: http://navishiur.org/product/imponderables/
[Thu Sep 17 15:30:50.318987 2026] [qos:error] [pid 20162:tid 20353] [client 45.115.26.203:60850] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxzAAAAcs, referer: http://navishiur.org/product/the-gaon-of-vilna-shoftim-26-sh-9/
[Thu Sep 17 15:30:50.320342 2026] [qos:error] [pid 18946:tid 19201] [client 45.115.26.203:60910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.115.26.203, id=aqxcCjqiPMah0Tz_U1OA0QAAAYc, referer: http://navishiur.org/product/chasanah/
[Thu Sep 17 15:30:50.320344 2026] [qos:error] [pid 20162:tid 20359] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.230, id=aqxcCq-O_Kk7aqBvaiFxzQAAAdE, referer: http://navishiur.org/product-category/topic-sets/?add-to-cart=120
[Thu Sep 17 15:30:50.320432 2026] [qos:error] [pid 20162:tid 20330] [client 45.115.26.203:60916] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxxwAAAbQ, referer: http://navishiur.org/product/tzugevoint-shoftim-213-sh-11/
[Thu Sep 17 15:30:50.321192 2026] [qos:error] [pid 18946:tid 19108] [client 45.115.26.203:60828] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.115.26.203, id=aqxcCjqiPMah0Tz_U1OA0gAAASo, referer: http://navishiur.org/product-category/seforim/
[Thu Sep 17 15:30:50.321339 2026] [qos:error] [pid 20162:tid 20343] [client 45.115.26.203:60974] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxyAAAAcE, referer: http://navishiur.org/product-category/shoftim/?add-to-cart=2122
[Thu Sep 17 15:30:50.321429 2026] [qos:error] [pid 20162:tid 20404] [client 45.115.26.203:60950] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFxyQAAAf4, referer: http://navishiur.org/product-category/uncategorized/
[Thu Sep 17 15:30:50.332006 2026] [qos:error] [pid 18946:tid 19149] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCjqiPMah0Tz_U1OA1AAAAVM, referer: http://navishiur.org/sale/
[Thu Sep 17 15:30:50.420495 2026] [qos:error] [pid 20162:tid 20403] [client 45.115.26.203:60866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.26.203, id=aqxcCq-O_Kk7aqBvaiFx2QAAAf0, referer: http://navishiur.org/product-category/seforim/?add-to-cart=2097
[Thu Sep 17 15:30:50.490628 2026] [qos:error] [pid 20162:tid 20392] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCq-O_Kk7aqBvaiFx3wAAAfI, referer: http://navishiur.org/product/moods/
[Thu Sep 17 15:30:50.491830 2026] [qos:error] [pid 18946:tid 19187] [client 45.115.26.203:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.230, id=aqxcCjqiPMah0Tz_U1OA3gAAAXk, referer: http://navishiur.org/privacy-policy/
[Thu Sep 17 15:30:50.701691 2026] [security2:error] [pid 18946:tid 19149] [client 3.19.142.206:56983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcCjqiPMah0Tz_U1OA3wAAAVM"]
[Thu Sep 17 15:30:52.124016 2026] [security2:error] [pid 18946:tid 19134] [client 143.105.152.240:38405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcDDqiPMah0Tz_U1OA6wAAAUQ"]
[Thu Sep 17 15:30:52.124150 2026] [security2:error] [pid 18946:tid 19134] [client 143.105.152.240:38405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcDDqiPMah0Tz_U1OA6wAAAUQ"]
[Thu Sep 17 15:30:52.155556 2026] [security2:error] [pid 20162:tid 20392] [client 98.82.66.172:1126] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.freegamest.com"] [uri "/"] [unique_id "aqxcDK-O_Kk7aqBvaiFx6wAAAfI"]
[Thu Sep 17 15:30:52.559765 2026] [proxy_http:error] [pid 20162:tid 20352] (20014)Internal error (specific information not available): [client 45.115.26.203:36144] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:30:52.559784 2026] [proxy:error] [pid 20162:tid 20352] [client 45.115.26.203:36144] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.local
[Thu Sep 17 15:30:52.584336 2026] [proxy_http:error] [pid 20162:tid 20376] (20014)Internal error (specific information not available): [client 45.115.26.203:36096] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:30:52.584352 2026] [proxy:error] [pid 20162:tid 20376] [client 45.115.26.203:36096] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env
[Thu Sep 17 15:30:52.736480 2026] [proxy_http:error] [pid 18946:tid 19202] (20014)Internal error (specific information not available): [client 45.115.26.203:36148] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:30:52.769517 2026] [proxy_http:error] [pid 20162:tid 20419] (20014)Internal error (specific information not available): [client 45.115.26.203:36110] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:30:52.882263 2026] [security2:error] [pid 20162:tid 20264] [remote 47.128.113.252:52532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "chabelo.com"] [uri "/robots.txt"] [unique_id "aqxcDK-O_Kk7aqBvaiFx-wABsmQ"]
[Thu Sep 17 15:30:52.923452 2026] [proxy_http:error] [pid 20162:tid 20316] (20014)Internal error (specific information not available): [client 45.115.26.203:36096] AH01102: error reading status line from remote server 127.0.0.1:2095
[Thu Sep 17 15:30:53.069274 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.243.218:35640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/.env"] [unique_id "aqxcDTqiPMah0Tz_U1OA9AAAAW0"]
[Thu Sep 17 15:30:53.427970 2026] [security2:error] [pid 20162:tid 20339] [client 45.115.26.203:36108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jenniferniesslein.com"] [uri "/phpinfo.php"] [unique_id "aqxcDa-O_Kk7aqBvaiFyCAAAAb0"]
[Thu Sep 17 15:30:53.452889 2026] [security2:error] [pid 20162:tid 20350] [client 45.115.26.203:36156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jenniferniesslein.com"] [uri "/info.php"] [unique_id "aqxcDa-O_Kk7aqBvaiFyCQAAAcg"]
[Thu Sep 17 15:30:53.566701 2026] [security2:error] [pid 20162:tid 20398] [client 45.115.26.203:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jenniferniesslein.com"] [uri "/i.php"] [unique_id "aqxcDa-O_Kk7aqBvaiFyCwAAAfg"]
[Thu Sep 17 15:30:53.595829 2026] [security2:error] [pid 18946:tid 19090] [client 45.115.26.203:36172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jenniferniesslein.com"] [uri "/test.php"] [unique_id "aqxcDTqiPMah0Tz_U1OA_gAAARg"]
[Thu Sep 17 15:30:53.653141 2026] [security2:error] [pid 20162:tid 20403] [client 103.61.184.148:58759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcDa-O_Kk7aqBvaiFyDAAAAf0"]
[Thu Sep 17 15:30:53.653278 2026] [security2:error] [pid 20162:tid 20403] [client 103.61.184.148:58759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcDa-O_Kk7aqBvaiFyDAAAAf0"]
[Thu Sep 17 15:30:54.207787 2026] [security2:error] [pid 20162:tid 20415] [client 102.69.36.65:53298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "caitlinwhittington.com"] [uri "/index.php"] [unique_id "aqxcC6-O_Kk7aqBvaiFx5wACCWU"], referer: https://caitlinwhittington.com
[Thu Sep 17 15:30:54.251961 2026] [security2:error] [pid 20162:tid 20295] [client 182.232.46.46:46286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcDq-O_Kk7aqBvaiFyFAABkV8"]
[Thu Sep 17 15:30:54.471975 2026] [security2:error] [pid 20162:tid 20419] [client 114.198.138.124:49551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcDq-O_Kk7aqBvaiFyGAAAAg0"]
[Thu Sep 17 15:30:54.472107 2026] [security2:error] [pid 20162:tid 20419] [client 114.198.138.124:49551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcDq-O_Kk7aqBvaiFyGAAAAg0"]
[Thu Sep 17 15:30:55.453835 2026] [core:crit] [pid 18946:tid 19156] (13)Permission denied: [client 43.162.114.69:54468] AH00529: /home1/awesone8/public_html/comicsutra.com/cs/tv1999/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/awesone8/public_html/comicsutra.com/cs/tv1999/' is executable
[Thu Sep 17 15:30:55.937470 2026] [security2:error] [pid 18946:tid 19115] [client 51.8.102.73:55199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxcDzqiPMah0Tz_U1OBJAABMXE"]
[Thu Sep 17 15:30:56.167496 2026] [security2:error] [pid 18946:tid 19124] [client 3.19.142.206:58659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxcEDqiPMah0Tz_U1OBKQAAATo"]
[Thu Sep 17 15:30:56.407443 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.243.218:56088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/.env.bak"] [unique_id "aqxcEDqiPMah0Tz_U1OBKgAAAW4"]
[Thu Sep 17 15:30:56.566959 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.243.218:56088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/.env.backup"] [unique_id "aqxcEDqiPMah0Tz_U1OBLgAAAWA"]
[Thu Sep 17 15:30:56.918471 2026] [security2:error] [pid 18946:tid 19078] [client 181.105.111.60:62296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcEDqiPMah0Tz_U1OBMgABDAw"]
[Thu Sep 17 15:30:57.233757 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.243.218:56100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/.env.old"] [unique_id "aqxcETqiPMah0Tz_U1OBNQAAAX0"]
[Thu Sep 17 15:30:57.858201 2026] [security2:error] [pid 18946:tid 19183] [client 169.58.197.251:62786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxcDzqiPMah0Tz_U1OBGAAAAXU"], referer: binance.com
[Thu Sep 17 15:30:58.361316 2026] [security2:error] [pid 18946:tid 19164] [client 3.19.142.206:59484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxcEjqiPMah0Tz_U1OBTQAAAWI"]
[Thu Sep 17 15:30:59.229921 2026] [core:error] [pid 18946:tid 19156] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:59.229941 2026] [core:error] [pid 18946:tid 19156] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:59.456634 2026] [core:error] [pid 20162:tid 20395] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:59.456672 2026] [core:error] [pid 20162:tid 20395] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:59.483879 2026] [security2:error] [pid 18946:tid 19189] [client 2.104.60.34:45395] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cowboywithacamera.com"] [uri "/.env"] [unique_id "aqxcEzqiPMah0Tz_U1OBZwAAAXs"]
[Thu Sep 17 15:30:59.741009 2026] [core:error] [pid 18946:tid 19107] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:30:59.741027 2026] [core:error] [pid 18946:tid 19107] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.026573 2026] [core:error] [pid 18946:tid 19150] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.026590 2026] [core:error] [pid 18946:tid 19150] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.282805 2026] [core:error] [pid 18946:tid 19181] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.282824 2026] [core:error] [pid 18946:tid 19181] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.492302 2026] [security2:error] [pid 18946:tid 19149] [client 3.19.142.206:60511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFDqiPMah0Tz_U1OBfQAAAVM"]
[Thu Sep 17 15:31:00.492344 2026] [security2:error] [pid 18946:tid 19149] [client 3.19.142.206:60511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFDqiPMah0Tz_U1OBfQAAAVM"]
[Thu Sep 17 15:31:00.509746 2026] [core:error] [pid 20162:tid 20392] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.509770 2026] [core:error] [pid 20162:tid 20392] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.521697 2026] [security2:error] [pid 18946:tid 19127] [client 3.19.142.206:60527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFDqiPMah0Tz_U1OBfgAAAT0"]
[Thu Sep 17 15:31:00.521744 2026] [security2:error] [pid 18946:tid 19127] [client 3.19.142.206:60527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFDqiPMah0Tz_U1OBfgAAAT0"]
[Thu Sep 17 15:31:00.524214 2026] [security2:error] [pid 20162:tid 20350] [client 3.19.142.206:60528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFK-O_Kk7aqBvaiFyJwAAAcg"]
[Thu Sep 17 15:31:00.524248 2026] [security2:error] [pid 20162:tid 20350] [client 3.19.142.206:60528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFK-O_Kk7aqBvaiFyJwAAAcg"]
[Thu Sep 17 15:31:00.573871 2026] [security2:error] [pid 18946:tid 19172] [client 3.19.142.206:60511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFDqiPMah0Tz_U1OBgAAAAWo"]
[Thu Sep 17 15:31:00.573912 2026] [security2:error] [pid 18946:tid 19172] [client 3.19.142.206:60511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/blog/xmlrpc.php"] [unique_id "aqxcFDqiPMah0Tz_U1OBgAAAAWo"]
[Thu Sep 17 15:31:00.794803 2026] [core:error] [pid 20162:tid 20368] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:00.794824 2026] [core:error] [pid 20162:tid 20368] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:01.008542 2026] [security2:error] [pid 20162:tid 20388] [client 127.0.0.1:25204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxcFK-O_Kk7aqBvaiFyLQAAAe4"]
[Thu Sep 17 15:31:01.008725 2026] [security2:error] [pid 18946:tid 19200] [client 74.7.230.27:41070] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.uxe.gqk.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxcFDqiPMah0Tz_U1OBhQABhhQ"]
[Thu Sep 17 15:31:01.067530 2026] [security2:error] [pid 18946:tid 19183] [client 195.2.84.198:49453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.84.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "melissa-gonzales.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxcFTqiPMah0Tz_U1OBiwAAAXU"], referer: https://melissa-gonzales.com/
[Thu Sep 17 15:31:01.100909 2026] [core:error] [pid 18946:tid 19139] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:01.100934 2026] [core:error] [pid 18946:tid 19139] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:01.224523 2026] [security2:error] [pid 18946:tid 19122] [client 216.73.216.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wherearetheymeow.com"] [uri "/index.php"] [unique_id "aqxcFTqiPMah0Tz_U1OBiQAAATg"]
[Thu Sep 17 15:31:01.382458 2026] [security2:error] [pid 18946:tid 19086] [client 169.58.197.253:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxcFTqiPMah0Tz_U1OBkAAAARQ"], referer: binance.com
[Thu Sep 17 15:31:01.648175 2026] [security2:error] [pid 18946:tid 19143] [client 210.222.43.21:63597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcFTqiPMah0Tz_U1OBlAAAAU0"], referer: http://talent-in-borders.com/bak
[Thu Sep 17 15:31:01.740739 2026] [core:error] [pid 18946:tid 19175] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:01.740758 2026] [core:error] [pid 18946:tid 19175] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:02.081088 2026] [core:error] [pid 20162:tid 20356] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:02.081109 2026] [core:error] [pid 20162:tid 20356] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:02.163820 2026] [security2:error] [pid 20162:tid 20393] [client 136.158.61.34:45195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcFq-O_Kk7aqBvaiFyPAAAAfM"]
[Thu Sep 17 15:31:02.163981 2026] [security2:error] [pid 20162:tid 20393] [client 136.158.61.34:45195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcFq-O_Kk7aqBvaiFyPAAAAfM"]
[Thu Sep 17 15:31:02.259887 2026] [security2:error] [pid 18946:tid 19201] [client 34.55.12.4:13626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.afw.noo.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxcFjqiPMah0Tz_U1OBoQAAAYc"]
[Thu Sep 17 15:31:02.444380 2026] [core:error] [pid 18946:tid 19134] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:02.444401 2026] [core:error] [pid 18946:tid 19134] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:02.652721 2026] [security2:error] [pid 20162:tid 20417] [client 143.105.152.240:47442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcFq-O_Kk7aqBvaiFyQgAAAgs"]
[Thu Sep 17 15:31:02.660503 2026] [security2:error] [pid 20162:tid 20417] [client 143.105.152.240:47442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcFq-O_Kk7aqBvaiFyQgAAAgs"]
[Thu Sep 17 15:31:02.841577 2026] [core:error] [pid 20162:tid 20310] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:02.841597 2026] [core:error] [pid 20162:tid 20310] [client 34.55.12.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:03.064284 2026] [security2:error] [pid 20162:tid 20394] [client 3.19.142.206:61277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcF6-O_Kk7aqBvaiFySAAAAfQ"]
[Thu Sep 17 15:31:03.114153 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.243.218:56188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/.env.swp"] [unique_id "aqxcFzqiPMah0Tz_U1OBuAAAAS0"]
[Thu Sep 17 15:31:03.271011 2026] [security2:error] [pid 18946:tid 19172] [client 34.154.243.218:56188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/.env~"] [unique_id "aqxcFzqiPMah0Tz_U1OBugAAAWo"]
[Thu Sep 17 15:31:04.543800 2026] [security2:error] [pid 20162:tid 20344] [client 103.61.184.148:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcGK-O_Kk7aqBvaiFyVAAAAcI"]
[Thu Sep 17 15:31:04.543931 2026] [security2:error] [pid 20162:tid 20344] [client 103.61.184.148:59348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcGK-O_Kk7aqBvaiFyVAAAAcI"]
[Thu Sep 17 15:31:04.763988 2026] [security2:error] [pid 18946:tid 19165] [client 93.152.209.11:5432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.fow.qtd.mybluehost.me"] [uri "/.env"] [unique_id "aqxcGDqiPMah0Tz_U1OBzAAAAWM"]
[Thu Sep 17 15:31:04.962497 2026] [security2:error] [pid 20162:tid 20280] [remote 93.152.209.11:27864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.fow.qtd.mybluehost.me"] [uri "/.env"] [unique_id "aqxcGK-O_Kk7aqBvaiFyVgABsHQ"]
[Thu Sep 17 15:31:05.042734 2026] [security2:error] [pid 18946:tid 19185] [client 114.198.138.124:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcGTqiPMah0Tz_U1OB0wAAAXc"]
[Thu Sep 17 15:31:05.042845 2026] [security2:error] [pid 18946:tid 19185] [client 114.198.138.124:50204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcGTqiPMah0Tz_U1OB0wAAAXc"]
[Thu Sep 17 15:31:06.894959 2026] [security2:error] [pid 18946:tid 19106] [client 191.37.175.128:37780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcGjqiPMah0Tz_U1OB5AABKCc"]
[Thu Sep 17 15:31:07.031626 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.243.218:36208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/app/.env"] [unique_id "aqxcGzqiPMah0Tz_U1OB7AAAAV0"]
[Thu Sep 17 15:31:07.186361 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.243.218:36208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/apps/.env"] [unique_id "aqxcGzqiPMah0Tz_U1OB7QAAAXM"]
[Thu Sep 17 15:31:07.341191 2026] [security2:error] [pid 18946:tid 19144] [client 34.154.243.218:36208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/api/.env"] [unique_id "aqxcGzqiPMah0Tz_U1OB7wAAAU4"]
[Thu Sep 17 15:31:07.495444 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.243.218:36208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/web/.env"] [unique_id "aqxcGzqiPMah0Tz_U1OB8wAAAQ0"]
[Thu Sep 17 15:31:07.649242 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.243.218:36208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/site/.env"] [unique_id "aqxcGzqiPMah0Tz_U1OB9QAAAS0"]
[Thu Sep 17 15:31:07.759854 2026] [security2:error] [pid 18946:tid 19182] [client 3.19.142.206:62667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxcGzqiPMah0Tz_U1OB9gAAAXQ"]
[Thu Sep 17 15:31:07.803422 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.243.218:36208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/public/.env"] [unique_id "aqxcGzqiPMah0Tz_U1OB-AAAAXg"]
[Thu Sep 17 15:31:08.276819 2026] [security2:error] [pid 18946:tid 19155] [client 162.241.226.11:36592] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "reedcustomprinting.com"] [uri "/wp-cron.php"] [unique_id "aqxcHDqiPMah0Tz_U1OCBAAAAVk"]
[Thu Sep 17 15:31:08.461307 2026] [security2:error] [pid 20162:tid 20306] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/backend/.env"] [unique_id "aqxcHK-O_Kk7aqBvaiFybQAAAZw"]
[Thu Sep 17 15:31:08.619974 2026] [security2:error] [pid 20162:tid 20372] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/server/.env"] [unique_id "aqxcHK-O_Kk7aqBvaiFybwAAAd4"]
[Thu Sep 17 15:31:08.772309 2026] [security2:error] [pid 20162:tid 20384] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/frontend/.env"] [unique_id "aqxcHK-O_Kk7aqBvaiFycQAAAeo"]
[Thu Sep 17 15:31:08.924621 2026] [security2:error] [pid 20162:tid 20398] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/src/.env"] [unique_id "aqxcHK-O_Kk7aqBvaiFycgAAAfg"]
[Thu Sep 17 15:31:09.077793 2026] [security2:error] [pid 20162:tid 20418] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/core/.env"] [unique_id "aqxcHa-O_Kk7aqBvaiFycwAAAgw"]
[Thu Sep 17 15:31:09.134009 2026] [security2:error] [pid 18946:tid 19124] [client 169.58.197.251:64045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sfvhbt.org"] [uri "/index.php"] [unique_id "aqxcHDqiPMah0Tz_U1OCCwAAATo"], referer: binance.com
[Thu Sep 17 15:31:09.149329 2026] [security2:error] [pid 18946:tid 19173] [client 212.237.119.3:13315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcHTqiPMah0Tz_U1OCDAABayo"]
[Thu Sep 17 15:31:09.230579 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/core/app/.env"] [unique_id "aqxcHa-O_Kk7aqBvaiFydAAAAZs"]
[Thu Sep 17 15:31:09.382994 2026] [security2:error] [pid 20162:tid 20319] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/config/.env"] [unique_id "aqxcHa-O_Kk7aqBvaiFydQAAAak"]
[Thu Sep 17 15:31:09.537024 2026] [security2:error] [pid 20162:tid 20412] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/private/.env"] [unique_id "aqxcHa-O_Kk7aqBvaiFydwAAAgY"]
[Thu Sep 17 15:31:09.689840 2026] [security2:error] [pid 20162:tid 20304] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/application/.env"] [unique_id "aqxcHa-O_Kk7aqBvaiFyegAAAZo"]
[Thu Sep 17 15:31:09.841267 2026] [security2:error] [pid 20162:tid 20369] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/bootstrap/.env"] [unique_id "aqxcHa-O_Kk7aqBvaiFyfAAAAds"]
[Thu Sep 17 15:31:09.878933 2026] [security2:error] [pid 20162:tid 20298] [client 169.58.197.253:58697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxcHa-O_Kk7aqBvaiFyfQAAAZQ"], referer: binance.com
[Thu Sep 17 15:31:09.993394 2026] [security2:error] [pid 20162:tid 20308] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/database/.env"] [unique_id "aqxcHa-O_Kk7aqBvaiFygAAAAZ4"]
[Thu Sep 17 15:31:10.012051 2026] [authz_core:error] [pid 18946:tid 19143] [client 40.81.232.68:59868] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:31:10.072970 2026] [security2:error] [pid 20162:tid 20297] [client 75.182.214.141:38306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jamescarmody.com"] [uri "/cigar/add_review.php"] [unique_id "aqxcHa-O_Kk7aqBvaiFydgABkwE"], referer: https://jamescarmody.com/cigar/add_review.php?cigar_id=25
[Thu Sep 17 15:31:10.160930 2026] [security2:error] [pid 20162:tid 20408] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/storage/.env"] [unique_id "aqxcHq-O_Kk7aqBvaiFygQAAAgI"]
[Thu Sep 17 15:31:10.315550 2026] [security2:error] [pid 20162:tid 20310] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/var/www/.env"] [unique_id "aqxcHq-O_Kk7aqBvaiFyhAAAAaA"]
[Thu Sep 17 15:31:10.468036 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/var/www/html/.env"] [unique_id "aqxcHq-O_Kk7aqBvaiFyhQAAAZE"]
[Thu Sep 17 15:31:10.573417 2026] [security2:error] [pid 18946:tid 19099] [client 3.19.142.206:63595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxcHjqiPMah0Tz_U1OCFgAAASE"]
[Thu Sep 17 15:31:10.621074 2026] [security2:error] [pid 20162:tid 20340] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/current/.env"] [unique_id "aqxcHq-O_Kk7aqBvaiFyhgAAAb4"]
[Thu Sep 17 15:31:10.779430 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/release/.env"] [unique_id "aqxcHq-O_Kk7aqBvaiFyhwAAAfQ"]
[Thu Sep 17 15:31:10.940311 2026] [security2:error] [pid 20162:tid 20353] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/releases/.env"] [unique_id "aqxcHq-O_Kk7aqBvaiFyiAAAAcs"]
[Thu Sep 17 15:31:11.050036 2026] [authz_core:error] [pid 18946:tid 19175] [client 169.58.197.253:58655] AH01630: client denied by server configuration: /home2/brianpag/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:31:11.094219 2026] [security2:error] [pid 20162:tid 20328] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/shared/.env"] [unique_id "aqxcH6-O_Kk7aqBvaiFyiQAAAbI"]
[Thu Sep 17 15:31:11.195004 2026] [security2:error] [pid 18946:tid 19176] [client 99.11.233.49:51272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.churchinirving.org"] [uri "/index.php"] [unique_id "aqxcHzqiPMah0Tz_U1OCHgAAAW4"]
[Thu Sep 17 15:31:11.252925 2026] [security2:error] [pid 20162:tid 20404] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/deploy/.env"] [unique_id "aqxcH6-O_Kk7aqBvaiFyigAAAf4"]
[Thu Sep 17 15:31:11.408013 2026] [security2:error] [pid 20162:tid 20345] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/build/.env"] [unique_id "aqxcH6-O_Kk7aqBvaiFyjAAAAcM"]
[Thu Sep 17 15:31:11.561391 2026] [security2:error] [pid 20162:tid 20367] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/dist/.env"] [unique_id "aqxcH6-O_Kk7aqBvaiFyjQAAAdk"]
[Thu Sep 17 15:31:11.716982 2026] [security2:error] [pid 20162:tid 20357] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/public_html/.env"] [unique_id "aqxcH6-O_Kk7aqBvaiFyjwAAAc8"]
[Thu Sep 17 15:31:11.870331 2026] [security2:error] [pid 20162:tid 20379] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/htdocs/.env"] [unique_id "aqxcH6-O_Kk7aqBvaiFykAAAAeU"]
[Thu Sep 17 15:31:12.029556 2026] [security2:error] [pid 20162:tid 20334] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/www/.env"] [unique_id "aqxcIK-O_Kk7aqBvaiFykwAAAbg"]
[Thu Sep 17 15:31:12.187957 2026] [security2:error] [pid 20162:tid 20330] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/html/.env"] [unique_id "aqxcIK-O_Kk7aqBvaiFylgAAAbQ"]
[Thu Sep 17 15:31:12.227999 2026] [security2:error] [pid 20162:tid 20346] [client 52.167.144.168:28698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "stephaniearnold.net"] [uri "/index.php"] [unique_id "aqxcIK-O_Kk7aqBvaiFykgABxAA"]
[Thu Sep 17 15:31:12.351980 2026] [security2:error] [pid 20162:tid 20410] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/live/.env"] [unique_id "aqxcIK-O_Kk7aqBvaiFymgAAAgQ"]
[Thu Sep 17 15:31:12.504732 2026] [security2:error] [pid 20162:tid 20385] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/prod/.env"] [unique_id "aqxcIK-O_Kk7aqBvaiFynAAAAes"]
[Thu Sep 17 15:31:12.664238 2026] [security2:error] [pid 20162:tid 20413] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/dev/.env"] [unique_id "aqxcIK-O_Kk7aqBvaiFynQAAAgc"]
[Thu Sep 17 15:31:12.821615 2026] [security2:error] [pid 20162:tid 20405] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/staging/.env"] [unique_id "aqxcIK-O_Kk7aqBvaiFyngAAAf8"]
[Thu Sep 17 15:31:12.974600 2026] [security2:error] [pid 20162:tid 20409] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/opt/.env"] [unique_id "aqxcIK-O_Kk7aqBvaiFyoAAAAgM"]
[Thu Sep 17 15:31:13.128672 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/laravel/.env"] [unique_id "aqxcIa-O_Kk7aqBvaiFyoQAAAgg"]
[Thu Sep 17 15:31:13.143613 2026] [security2:error] [pid 20162:tid 20389] [client 3.19.142.206:64527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcIa-O_Kk7aqBvaiFyogAAAe8"]
[Thu Sep 17 15:31:13.143685 2026] [security2:error] [pid 20162:tid 20389] [client 3.19.142.206:64527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcIa-O_Kk7aqBvaiFyogAAAe8"]
[Thu Sep 17 15:31:13.157291 2026] [security2:error] [pid 18946:tid 19091] [client 3.19.142.206:64531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcITqiPMah0Tz_U1OCOgAAARk"]
[Thu Sep 17 15:31:13.157347 2026] [security2:error] [pid 18946:tid 19091] [client 3.19.142.206:64531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcITqiPMah0Tz_U1OCOgAAARk"]
[Thu Sep 17 15:31:13.161277 2026] [security2:error] [pid 18946:tid 19135] [client 3.19.142.206:64522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcITqiPMah0Tz_U1OCOwAAAUU"]
[Thu Sep 17 15:31:13.161324 2026] [security2:error] [pid 18946:tid 19135] [client 3.19.142.206:64522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcITqiPMah0Tz_U1OCOwAAAUU"]
[Thu Sep 17 15:31:13.216965 2026] [security2:error] [pid 18946:tid 19160] [client 143.105.152.240:9334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcITqiPMah0Tz_U1OCQAAAAV4"]
[Thu Sep 17 15:31:13.218268 2026] [security2:error] [pid 18946:tid 19160] [client 143.105.152.240:9334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcITqiPMah0Tz_U1OCQAAAAV4"]
[Thu Sep 17 15:31:13.219254 2026] [security2:error] [pid 20162:tid 20411] [client 3.19.142.206:64527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcIa-O_Kk7aqBvaiFypQAAAgU"]
[Thu Sep 17 15:31:13.219294 2026] [security2:error] [pid 20162:tid 20411] [client 3.19.142.206:64527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/backup/xmlrpc.php"] [unique_id "aqxcIa-O_Kk7aqBvaiFypQAAAgU"]
[Thu Sep 17 15:31:13.249949 2026] [security2:error] [pid 18946:tid 19190] [client 57.141.14.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxcITqiPMah0Tz_U1OCPAAAAXw"]
[Thu Sep 17 15:31:13.286982 2026] [security2:error] [pid 20162:tid 20336] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/symfony/.env"] [unique_id "aqxcIa-O_Kk7aqBvaiFypgAAAbo"]
[Thu Sep 17 15:31:13.440999 2026] [security2:error] [pid 20162:tid 20392] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/wordpress/.env"] [unique_id "aqxcIa-O_Kk7aqBvaiFyqgAAAfI"]
[Thu Sep 17 15:31:13.596252 2026] [security2:error] [pid 20162:tid 20335] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/wp/.env"] [unique_id "aqxcIa-O_Kk7aqBvaiFyqwAAAbk"]
[Thu Sep 17 15:31:13.747065 2026] [core:error] [pid 18946:tid 19123] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:13.747084 2026] [core:error] [pid 18946:tid 19123] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:13.758514 2026] [security2:error] [pid 20162:tid 20420] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cms/.env"] [unique_id "aqxcIa-O_Kk7aqBvaiFyrQAAAg4"]
[Thu Sep 17 15:31:13.911990 2026] [security2:error] [pid 20162:tid 20388] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/drupal/.env"] [unique_id "aqxcIa-O_Kk7aqBvaiFysgAAAe4"]
[Thu Sep 17 15:31:14.067337 2026] [security2:error] [pid 20162:tid 20309] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/joomla/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFyswAAAZ8"]
[Thu Sep 17 15:31:14.095799 2026] [core:error] [pid 20162:tid 20338] [client 34.94.72.59:33470] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:14.095822 2026] [core:error] [pid 20162:tid 20338] [client 34.94.72.59:33470] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:14.220261 2026] [security2:error] [pid 20162:tid 20306] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/magento/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFytQAAAZw"]
[Thu Sep 17 15:31:14.227054 2026] [security2:error] [pid 20162:tid 20296] [client 93.152.209.7:15572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "bridge2lifeteenhomes.org"] [uri "/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFytgAAAZI"]
[Thu Sep 17 15:31:14.372426 2026] [security2:error] [pid 20162:tid 20364] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/shopify/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFytwAAAdY"]
[Thu Sep 17 15:31:14.403615 2026] [security2:error] [pid 18946:tid 19016] [remote 93.152.209.7:33562] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "bridge2lifeteenhomes.org"] [uri "/.env"] [unique_id "aqxcIjqiPMah0Tz_U1OCSwABZkU"]
[Thu Sep 17 15:31:14.529842 2026] [security2:error] [pid 20162:tid 20382] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/prestashop/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFyuQAAAeg"]
[Thu Sep 17 15:31:14.550902 2026] [core:error] [pid 18946:tid 19129] [client 34.94.72.59:33474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:14.550923 2026] [core:error] [pid 18946:tid 19129] [client 34.94.72.59:33474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:14.684474 2026] [security2:error] [pid 20162:tid 20354] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/codeigniter/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFyuwAAAcw"]
[Thu Sep 17 15:31:14.742615 2026] [security2:error] [pid 20162:tid 20333] [client 136.158.61.34:46353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcIq-O_Kk7aqBvaiFyvAAAAbc"]
[Thu Sep 17 15:31:14.742789 2026] [security2:error] [pid 20162:tid 20333] [client 136.158.61.34:46353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcIq-O_Kk7aqBvaiFyvAAAAbc"]
[Thu Sep 17 15:31:14.839927 2026] [security2:error] [pid 20162:tid 20351] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cakephp/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFyvQAAAck"]
[Thu Sep 17 15:31:14.920971 2026] [core:error] [pid 20162:tid 20398] [client 34.94.72.59:33488] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:14.920990 2026] [core:error] [pid 20162:tid 20398] [client 34.94.72.59:33488] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:14.999054 2026] [security2:error] [pid 20162:tid 20403] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/zend/.env"] [unique_id "aqxcIq-O_Kk7aqBvaiFyvwAAAf0"]
[Thu Sep 17 15:31:15.124869 2026] [security2:error] [pid 20162:tid 20352] [client 3.19.142.206:65319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcI6-O_Kk7aqBvaiFywQAAAco"]
[Thu Sep 17 15:31:15.153170 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/yii/.env"] [unique_id "aqxcI6-O_Kk7aqBvaiFywgAAAbs"]
[Thu Sep 17 15:31:15.300218 2026] [security2:error] [pid 20162:tid 20418] [client 103.61.184.148:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcI6-O_Kk7aqBvaiFyxQAAAgw"]
[Thu Sep 17 15:31:15.302954 2026] [security2:error] [pid 20162:tid 20418] [client 103.61.184.148:59925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcI6-O_Kk7aqBvaiFyxQAAAgw"]
[Thu Sep 17 15:31:15.307069 2026] [security2:error] [pid 20162:tid 20297] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/laravel5/.env"] [unique_id "aqxcI6-O_Kk7aqBvaiFyxgAAAZM"]
[Thu Sep 17 15:31:15.317442 2026] [core:error] [pid 18946:tid 19143] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:15.317463 2026] [core:error] [pid 18946:tid 19143] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:15.461696 2026] [security2:error] [pid 20162:tid 20366] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/v1/.env"] [unique_id "aqxcI6-O_Kk7aqBvaiFyyAAAAdg"]
[Thu Sep 17 15:31:15.616727 2026] [security2:error] [pid 20162:tid 20340] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/v2/.env"] [unique_id "aqxcI6-O_Kk7aqBvaiFyygAAAb4"]
[Thu Sep 17 15:31:15.697565 2026] [core:error] [pid 18946:tid 19145] [client 34.94.72.59:33502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:15.697585 2026] [core:error] [pid 18946:tid 19145] [client 34.94.72.59:33502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:15.774340 2026] [security2:error] [pid 20162:tid 20325] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/v3/.env"] [unique_id "aqxcI6-O_Kk7aqBvaiFyzAAAAa8"]
[Thu Sep 17 15:31:15.865869 2026] [security2:error] [pid 20162:tid 20343] [client 114.198.138.124:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcI6-O_Kk7aqBvaiFyzgAAAcE"]
[Thu Sep 17 15:31:15.865993 2026] [security2:error] [pid 20162:tid 20343] [client 114.198.138.124:50864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcI6-O_Kk7aqBvaiFyzgAAAcE"]
[Thu Sep 17 15:31:15.927457 2026] [security2:error] [pid 20162:tid 20328] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/api/v1/.env"] [unique_id "aqxcI6-O_Kk7aqBvaiFy0AAAAbI"]
[Thu Sep 17 15:31:16.072502 2026] [security2:error] [pid 18946:tid 19110] [client 34.94.72.59:33504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxcJDqiPMah0Tz_U1OCXAAAASw"]
[Thu Sep 17 15:31:16.087148 2026] [security2:error] [pid 20162:tid 20376] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/api/v2/.env"] [unique_id "aqxcJK-O_Kk7aqBvaiFy0gAAAeI"]
[Thu Sep 17 15:31:16.213965 2026] [core:error] [pid 18946:tid 19101] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:16.213982 2026] [core:error] [pid 18946:tid 19101] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:16.242221 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/rest/.env"] [unique_id "aqxcJK-O_Kk7aqBvaiFy0wAAAcI"]
[Thu Sep 17 15:31:16.395178 2026] [security2:error] [pid 20162:tid 20400] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/graphql/.env"] [unique_id "aqxcJK-O_Kk7aqBvaiFy1AAAAfo"]
[Thu Sep 17 15:31:16.550652 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/gateway/.env"] [unique_id "aqxcJK-O_Kk7aqBvaiFy2AAAAZk"]
[Thu Sep 17 15:31:16.683511 2026] [security2:error] [pid 20162:tid 20334] [client 43.173.181.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcJK-O_Kk7aqBvaiFy1wAAAbg"]
[Thu Sep 17 15:31:16.705154 2026] [security2:error] [pid 20162:tid 20387] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/microservice/.env"] [unique_id "aqxcJK-O_Kk7aqBvaiFy2gAAAe0"]
[Thu Sep 17 15:31:16.806599 2026] [core:error] [pid 18946:tid 19097] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:16.806617 2026] [core:error] [pid 18946:tid 19097] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:16.854367 2026] [security2:error] [pid 18946:tid 19140] [client 162.241.226.11:31938] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxcJDqiPMah0Tz_U1OCawAAAUo"]
[Thu Sep 17 15:31:16.858901 2026] [security2:error] [pid 20162:tid 20406] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/service/.env"] [unique_id "aqxcJK-O_Kk7aqBvaiFy3AAAAgA"]
[Thu Sep 17 15:31:17.011787 2026] [security2:error] [pid 20162:tid 20326] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/api/v3/.env"] [unique_id "aqxcJa-O_Kk7aqBvaiFy3gAAAbA"]
[Thu Sep 17 15:31:17.138868 2026] [core:error] [pid 20162:tid 20416] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:17.138885 2026] [core:error] [pid 20162:tid 20416] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:17.164520 2026] [security2:error] [pid 20162:tid 20385] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/api/dev/.env"] [unique_id "aqxcJa-O_Kk7aqBvaiFy4wAAAes"]
[Thu Sep 17 15:31:17.317533 2026] [security2:error] [pid 20162:tid 20323] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/api/staging/.env"] [unique_id "aqxcJa-O_Kk7aqBvaiFy5AAAAa0"]
[Thu Sep 17 15:31:17.470514 2026] [security2:error] [pid 20162:tid 20402] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/vendor/.env"] [unique_id "aqxcJa-O_Kk7aqBvaiFy5wAAAfw"]
[Thu Sep 17 15:31:17.548072 2026] [security2:error] [pid 20162:tid 20377] [client 178.75.242.240:52226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcJa-O_Kk7aqBvaiFy5QAB4wM"]
[Thu Sep 17 15:31:17.628234 2026] [security2:error] [pid 20162:tid 20409] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/lib/.env"] [unique_id "aqxcJa-O_Kk7aqBvaiFy7AAAAgM"]
[Thu Sep 17 15:31:17.698914 2026] [core:error] [pid 20162:tid 20389] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:17.698940 2026] [core:error] [pid 20162:tid 20389] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:17.781896 2026] [security2:error] [pid 20162:tid 20336] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/resources/.env"] [unique_id "aqxcJa-O_Kk7aqBvaiFy7gAAAbo"]
[Thu Sep 17 15:31:17.882750 2026] [security2:error] [pid 20162:tid 20311] [client 169.58.197.253:59208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxcJa-O_Kk7aqBvaiFy7wAAAaE"], referer: binance.com
[Thu Sep 17 15:31:17.937019 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/assets/.env"] [unique_id "aqxcJa-O_Kk7aqBvaiFy8AAAAaM"]
[Thu Sep 17 15:31:18.091186 2026] [security2:error] [pid 20162:tid 20401] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/uploads/.env"] [unique_id "aqxcJq-O_Kk7aqBvaiFy8gAAAfs"]
[Thu Sep 17 15:31:18.190418 2026] [core:error] [pid 20162:tid 20320] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:18.190442 2026] [core:error] [pid 20162:tid 20320] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:18.245588 2026] [security2:error] [pid 20162:tid 20420] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/internal/.env"] [unique_id "aqxcJq-O_Kk7aqBvaiFy9gAAAg4"]
[Thu Sep 17 15:31:18.402100 2026] [security2:error] [pid 20162:tid 20388] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/tools/.env"] [unique_id "aqxcJq-O_Kk7aqBvaiFy-QAAAe4"]
[Thu Sep 17 15:31:18.416433 2026] [core:error] [pid 20162:tid 20293] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:18.416452 2026] [core:error] [pid 20162:tid 20293] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:18.457977 2026] [security2:error] [pid 20162:tid 20373] [client 170.78.119.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gazillionmexico.com"] [uri "/index.php"] [unique_id "aqxcJq-O_Kk7aqBvaiFy8wAAAd8"]
[Thu Sep 17 15:31:18.559040 2026] [security2:error] [pid 20162:tid 20307] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/scripts/.env"] [unique_id "aqxcJq-O_Kk7aqBvaiFy_QAAAZ0"]
[Thu Sep 17 15:31:18.714408 2026] [security2:error] [pid 20162:tid 20350] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/bin/.env"] [unique_id "aqxcJq-O_Kk7aqBvaiFy_gAAAcg"]
[Thu Sep 17 15:31:18.736190 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.72.59:57698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxcJjqiPMah0Tz_U1OCzgAAAXk"]
[Thu Sep 17 15:31:18.847143 2026] [security2:error] [pid 18946:tid 19165] [client 34.94.72.59:57698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxcJjqiPMah0Tz_U1OC3AAAAWM"]
[Thu Sep 17 15:31:18.867508 2026] [security2:error] [pid 20162:tid 20296] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/sbin/.env"] [unique_id "aqxcJq-O_Kk7aqBvaiFzAAAAAZI"]
[Thu Sep 17 15:31:18.899399 2026] [core:error] [pid 18946:tid 19167] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:18.899427 2026] [core:error] [pid 18946:tid 19167] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:19.020624 2026] [security2:error] [pid 20162:tid 20354] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/local/.env"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzAQAAAcw"]
[Thu Sep 17 15:31:19.172815 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/portal/.env"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzBAAAAZs"]
[Thu Sep 17 15:31:19.305362 2026] [security2:error] [pid 18946:tid 19133] [client 34.94.72.59:57712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxcJzqiPMah0Tz_U1OC6wAAAUM"]
[Thu Sep 17 15:31:19.326350 2026] [security2:error] [pid 20162:tid 20384] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/dashboard/.env"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzBQAAAeo"]
[Thu Sep 17 15:31:19.375688 2026] [security2:error] [pid 18946:tid 19107] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxcJzqiPMah0Tz_U1OC6AAAASk"]
[Thu Sep 17 15:31:19.449085 2026] [core:error] [pid 18946:tid 19178] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:19.449109 2026] [core:error] [pid 18946:tid 19178] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:19.482440 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/panel/.env"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzBwAAAbs"]
[Thu Sep 17 15:31:19.635453 2026] [security2:error] [pid 20162:tid 20297] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/crm/.env"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzDgAAAZM"]
[Thu Sep 17 15:31:19.682492 2026] [security2:error] [pid 18946:tid 19097] [client 3.19.142.206:50393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxcJzqiPMah0Tz_U1OC8wAAAR8"]
[Thu Sep 17 15:31:19.690223 2026] [security2:error] [pid 20162:tid 20319] [client 34.90.238.223:48324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.taxcentr.com"] [uri "/.git/config"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzDwAAAak"]
[Thu Sep 17 15:31:19.737305 2026] [core:error] [pid 20162:tid 20359] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:19.737325 2026] [core:error] [pid 20162:tid 20359] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:19.791801 2026] [security2:error] [pid 20162:tid 20417] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/erp/.env"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzFAAAAgs"]
[Thu Sep 17 15:31:19.945450 2026] [security2:error] [pid 20162:tid 20343] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/shop/.env"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzFwAAAcE"]
[Thu Sep 17 15:31:20.019215 2026] [security2:error] [pid 20162:tid 20394] [client 179.113.100.235:43774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcJ6-O_Kk7aqBvaiFzFgAB9AQ"]
[Thu Sep 17 15:31:20.065813 2026] [security2:error] [pid 18946:tid 18997] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.env.bak"] [unique_id "aqxcKDqiPMah0Tz_U1ODAAABLTI"]
[Thu Sep 17 15:31:20.065826 2026] [security2:error] [pid 18946:tid 19001] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.env.backup"] [unique_id "aqxcKDqiPMah0Tz_U1ODAQABLTY"]
[Thu Sep 17 15:31:20.068490 2026] [security2:error] [pid 18946:tid 18997] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.env.old"] [unique_id "aqxcKDqiPMah0Tz_U1ODAgABLTI"]
[Thu Sep 17 15:31:20.077635 2026] [core:error] [pid 20162:tid 20376] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:20.077670 2026] [core:error] [pid 20162:tid 20376] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:20.098116 2026] [security2:error] [pid 20162:tid 20379] [client 34.154.243.218:36220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/store/.env"] [unique_id "aqxcKK-O_Kk7aqBvaiFzHgAAAeU"]
[Thu Sep 17 15:31:20.334269 2026] [security2:error] [pid 18946:tid 19006] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.env"] [unique_id "aqxcKDqiPMah0Tz_U1ODGgABLTs"]
[Thu Sep 17 15:31:20.385668 2026] [core:error] [pid 20162:tid 20396] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:20.385700 2026] [core:error] [pid 20162:tid 20396] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:20.567229 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/saas/.env"] [unique_id "aqxcKK-O_Kk7aqBvaiFzKgAAAZA"]
[Thu Sep 17 15:31:20.653767 2026] [core:error] [pid 18946:tid 19185] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:20.653791 2026] [core:error] [pid 18946:tid 19185] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:20.727292 2026] [security2:error] [pid 20162:tid 20302] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/client/.env"] [unique_id "aqxcKK-O_Kk7aqBvaiFzLAAAAZg"]
[Thu Sep 17 15:31:20.744522 2026] [security2:error] [pid 18946:tid 19004] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.env~"] [unique_id "aqxcKDqiPMah0Tz_U1ODMgABLTk"]
[Thu Sep 17 15:31:20.885548 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/project/.env"] [unique_id "aqxcKK-O_Kk7aqBvaiFzLQAAAgg"]
[Thu Sep 17 15:31:21.040783 2026] [security2:error] [pid 20162:tid 20332] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/admin-panel/.env"] [unique_id "aqxcKa-O_Kk7aqBvaiFzLwAAAbY"]
[Thu Sep 17 15:31:21.086042 2026] [core:error] [pid 18946:tid 19179] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:21.086062 2026] [core:error] [pid 18946:tid 19179] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:21.196135 2026] [security2:error] [pid 20162:tid 20407] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/control-panel/.env"] [unique_id "aqxcKa-O_Kk7aqBvaiFzMAAAAgE"]
[Thu Sep 17 15:31:21.336789 2026] [core:error] [pid 18946:tid 19162] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:21.336808 2026] [core:error] [pid 18946:tid 19162] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:21.353027 2026] [security2:error] [pid 20162:tid 20324] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/user-panel/.env"] [unique_id "aqxcKa-O_Kk7aqBvaiFzMQAAAa4"]
[Thu Sep 17 15:31:21.476915 2026] [security2:error] [pid 18946:tid 19021] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.env.swp"] [unique_id "aqxcKTqiPMah0Tz_U1ODRAABLUo"]
[Thu Sep 17 15:31:21.510372 2026] [security2:error] [pid 20162:tid 20301] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/node/.env"] [unique_id "aqxcKa-O_Kk7aqBvaiFzMgAAAZc"]
[Thu Sep 17 15:31:21.666377 2026] [security2:error] [pid 20162:tid 20320] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/express/.env"] [unique_id "aqxcKa-O_Kk7aqBvaiFzNAAAAao"]
[Thu Sep 17 15:31:21.822050 2026] [security2:error] [pid 20162:tid 20399] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/next/.env"] [unique_id "aqxcKa-O_Kk7aqBvaiFzNgAAAfk"]
[Thu Sep 17 15:31:21.894817 2026] [core:error] [pid 18946:tid 19079] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:21.894840 2026] [core:error] [pid 18946:tid 19079] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:21.982915 2026] [security2:error] [pid 20162:tid 20309] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/nuxt/.env"] [unique_id "aqxcKa-O_Kk7aqBvaiFzOQAAAZ8"]
[Thu Sep 17 15:31:22.140867 2026] [security2:error] [pid 20162:tid 20338] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/nest/.env"] [unique_id "aqxcKq-O_Kk7aqBvaiFzOgAAAbw"]
[Thu Sep 17 15:31:22.161133 2026] [security2:error] [pid 18946:tid 19039] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/api/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODUwABE1w"]
[Thu Sep 17 15:31:22.161254 2026] [security2:error] [pid 18946:tid 19057] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/app/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODVAABE24"]
[Thu Sep 17 15:31:22.161535 2026] [security2:error] [pid 18946:tid 19045] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/config/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODWgABE2I"]
[Thu Sep 17 15:31:22.161690 2026] [security2:error] [pid 18946:tid 19063] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/web/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODXAABE3Q"]
[Thu Sep 17 15:31:22.161717 2026] [security2:error] [pid 18946:tid 19030] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/src/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODWwABE1M"]
[Thu Sep 17 15:31:22.161741 2026] [security2:error] [pid 18946:tid 19061] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/server/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODWQABE3I"]
[Thu Sep 17 15:31:22.161796 2026] [security2:error] [pid 18946:tid 19033] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/client/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODXQABE1Y"]
[Thu Sep 17 15:31:22.162590 2026] [security2:error] [pid 18946:tid 19054] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/backend/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODVwABE2s"]
[Thu Sep 17 15:31:22.322986 2026] [security2:error] [pid 20162:tid 20375] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/react/.env"] [unique_id "aqxcKq-O_Kk7aqBvaiFzPgAAAeE"]
[Thu Sep 17 15:31:22.392438 2026] [core:error] [pid 18946:tid 19202] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:22.392463 2026] [core:error] [pid 18946:tid 19202] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:22.450597 2026] [security2:error] [pid 18946:tid 19041] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/frontend/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODcAABbF4"]
[Thu Sep 17 15:31:22.455529 2026] [security2:error] [pid 20162:tid 20362] [client 3.19.142.206:51273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxcKq-O_Kk7aqBvaiFzPQAAAdQ"]
[Thu Sep 17 15:31:22.482257 2026] [security2:error] [pid 20162:tid 20312] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/vue/.env"] [unique_id "aqxcKq-O_Kk7aqBvaiFzQgAAAaI"]
[Thu Sep 17 15:31:22.488881 2026] [security2:error] [pid 18946:tid 19028] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/back/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODdwABY1E"]
[Thu Sep 17 15:31:22.488904 2026] [security2:error] [pid 18946:tid 19049] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/var/www/html/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODcwABY2Y"]
[Thu Sep 17 15:31:22.488939 2026] [security2:error] [pid 18946:tid 19029] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/public/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODcQABY1I"]
[Thu Sep 17 15:31:22.488950 2026] [security2:error] [pid 18946:tid 19053] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/backup/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODeAABY2o"]
[Thu Sep 17 15:31:22.488995 2026] [security2:error] [pid 18946:tid 19051] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/apps/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODdgABY2g"]
[Thu Sep 17 15:31:22.489024 2026] [security2:error] [pid 18946:tid 19043] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/var/www/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODcgABY2A"]
[Thu Sep 17 15:31:22.489033 2026] [security2:error] [pid 18946:tid 19046] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/laravel/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODdAABY2M"]
[Thu Sep 17 15:31:22.489079 2026] [security2:error] [pid 18946:tid 19050] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/application/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODdQABY2c"]
[Thu Sep 17 15:31:22.642382 2026] [security2:error] [pid 20162:tid 20398] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/angular/.env"] [unique_id "aqxcKq-O_Kk7aqBvaiFzQwAAAfg"]
[Thu Sep 17 15:31:22.737893 2026] [security2:error] [pid 18946:tid 19048] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/dev/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODewABMmU"]
[Thu Sep 17 15:31:22.737941 2026] [security2:error] [pid 18946:tid 19055] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/prod/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODegABMmw"]
[Thu Sep 17 15:31:22.737979 2026] [security2:error] [pid 18946:tid 19032] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/old/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODgAABMlU"]
[Thu Sep 17 15:31:22.738054 2026] [security2:error] [pid 18946:tid 19027] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/staging/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODfgABMlA"]
[Thu Sep 17 15:31:22.738054 2026] [security2:error] [pid 18946:tid 19042] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/production/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODfQABMl8"]
[Thu Sep 17 15:31:22.738116 2026] [security2:error] [pid 18946:tid 19025] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/cms/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODfAABMk4"]
[Thu Sep 17 15:31:22.738116 2026] [security2:error] [pid 18946:tid 19036] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/test/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODfwABMlk"]
[Thu Sep 17 15:31:22.799714 2026] [core:error] [pid 18946:tid 19161] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:22.799734 2026] [core:error] [pid 18946:tid 19161] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:22.805236 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/svelte/.env"] [unique_id "aqxcKq-O_Kk7aqBvaiFzRQAAAc4"]
[Thu Sep 17 15:31:22.870784 2026] [security2:error] [pid 18946:tid 19073] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/server/backend/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODjgABIX4"]
[Thu Sep 17 15:31:22.870781 2026] [security2:error] [pid 18946:tid 18952] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/server/api/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODjQABIQU"]
[Thu Sep 17 15:31:22.870854 2026] [security2:error] [pid 18946:tid 19067] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/new/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODhgABIXg"]
[Thu Sep 17 15:31:22.870863 2026] [security2:error] [pid 18946:tid 19065] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/admin-app/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODiQABIXY"]
[Thu Sep 17 15:31:22.870872 2026] [security2:error] [pid 18946:tid 19062] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/api-backend/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODiAABIXM"]
[Thu Sep 17 15:31:22.870883 2026] [security2:error] [pid 18946:tid 19064] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/node-api/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODhwABIXU"]
[Thu Sep 17 15:31:22.870897 2026] [security2:error] [pid 18946:tid 19047] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/current/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODjAABIWQ"]
[Thu Sep 17 15:31:22.870939 2026] [security2:error] [pid 18946:tid 19066] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/public_html/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODiwABIXc"]
[Thu Sep 17 15:31:22.888834 2026] [security2:error] [pid 18946:tid 19056] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/administrator/.env"] [unique_id "aqxcKjqiPMah0Tz_U1ODigABIW0"]
[Thu Sep 17 15:31:22.973503 2026] [security2:error] [pid 20162:tid 20384] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/vite/.env"] [unique_id "aqxcKq-O_Kk7aqBvaiFzRgAAAeo"]
[Thu Sep 17 15:31:23.007818 2026] [security2:error] [pid 18946:tid 19069] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODkAABHno"]
[Thu Sep 17 15:31:23.007834 2026] [security2:error] [pid 18946:tid 19070] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.aws/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODkwABHns"]
[Thu Sep 17 15:31:23.007914 2026] [security2:error] [pid 18946:tid 19071] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/aws/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODkQABHnw"]
[Thu Sep 17 15:31:23.007926 2026] [security2:error] [pid 18946:tid 19060] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/stripe/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODkgABHnE"]
[Thu Sep 17 15:31:23.007926 2026] [security2:error] [pid 18946:tid 19072] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.docker/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODjwABHn0"]
[Thu Sep 17 15:31:23.099975 2026] [core:error] [pid 18946:tid 19087] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:23.099996 2026] [core:error] [pid 18946:tid 19087] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:23.129430 2026] [security2:error] [pid 20162:tid 20352] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/backup/.env"] [unique_id "aqxcK6-O_Kk7aqBvaiFzSgAAAco"]
[Thu Sep 17 15:31:23.283073 2026] [security2:error] [pid 20162:tid 20364] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/backups/.env"] [unique_id "aqxcK6-O_Kk7aqBvaiFzSwAAAdY"]
[Thu Sep 17 15:31:23.299941 2026] [security2:error] [pid 18946:tid 18950] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/media/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODoAABIAM"]
[Thu Sep 17 15:31:23.300011 2026] [security2:error] [pid 18946:tid 18957] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/v3/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODnwABIAo"]
[Thu Sep 17 15:31:23.300043 2026] [security2:error] [pid 18946:tid 19044] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/v2/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODnQABIGE"]
[Thu Sep 17 15:31:23.300129 2026] [security2:error] [pid 18946:tid 18947] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/v1/.env"] [unique_id "aqxcKzqiPMah0Tz_U1ODngABIAA"]
[Thu Sep 17 15:31:23.431149 2026] [security2:error] [pid 20162:tid 20369] [client 34.94.72.59:57810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxcK6-O_Kk7aqBvaiFzUwAAAds"]
[Thu Sep 17 15:31:23.438099 2026] [security2:error] [pid 20162:tid 20340] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/old/.env"] [unique_id "aqxcK6-O_Kk7aqBvaiFzVAAAAb4"]
[Thu Sep 17 15:31:23.508139 2026] [security2:error] [pid 20162:tid 20295] [client 34.94.72.59:57810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxcK6-O_Kk7aqBvaiFzVgAAAZE"]
[Thu Sep 17 15:31:23.530570 2026] [security2:error] [pid 18946:tid 18967] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.git/config.bak"] [unique_id "aqxcKzqiPMah0Tz_U1ODvgABIBQ"]
[Thu Sep 17 15:31:23.599085 2026] [security2:error] [pid 20162:tid 20365] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/tmp/.env"] [unique_id "aqxcK6-O_Kk7aqBvaiFzWQAAAdc"]
[Thu Sep 17 15:31:23.632959 2026] [security2:error] [pid 18946:tid 19178] [client 161.35.164.148:49768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcKTqiPMah0Tz_U1ODRwABcE0"], referer: http://www.ohanaclinic.com/old/
[Thu Sep 17 15:31:23.635510 2026] [core:error] [pid 18946:tid 19135] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:23.635531 2026] [core:error] [pid 18946:tid 19135] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:23.773128 2026] [security2:error] [pid 20162:tid 20410] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/temp/.env"] [unique_id "aqxcK6-O_Kk7aqBvaiFzWwAAAgQ"]
[Thu Sep 17 15:31:23.799091 2026] [security2:error] [pid 18946:tid 18978] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxcKzqiPMah0Tz_U1OD1gABIB8"]
[Thu Sep 17 15:31:23.799131 2026] [security2:error] [pid 20162:tid 20319] [client 143.105.152.240:62468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcK6-O_Kk7aqBvaiFzXAAAAak"]
[Thu Sep 17 15:31:23.799266 2026] [security2:error] [pid 20162:tid 20319] [client 143.105.152.240:62468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcK6-O_Kk7aqBvaiFzXAAAAak"]
[Thu Sep 17 15:31:23.912159 2026] [security2:error] [pid 18946:tid 18982] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/id_rsa"] [unique_id "aqxcKzqiPMah0Tz_U1OD6gABICM"]
[Thu Sep 17 15:31:23.912229 2026] [security2:error] [pid 18946:tid 18974] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxcKzqiPMah0Tz_U1OD6wABIBs"]
[Thu Sep 17 15:31:23.931899 2026] [security2:error] [pid 20162:tid 20299] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/lab/.env"] [unique_id "aqxcK6-O_Kk7aqBvaiFzYAAAAZU"]
[Thu Sep 17 15:31:24.091291 2026] [security2:error] [pid 20162:tid 20371] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cronlab/.env"] [unique_id "aqxcLK-O_Kk7aqBvaiFzYQAAAd0"]
[Thu Sep 17 15:31:24.098570 2026] [core:error] [pid 18946:tid 19193] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:24.098589 2026] [core:error] [pid 18946:tid 19193] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:24.123957 2026] [security2:error] [pid 20162:tid 20380] [client 74.7.228.31:45016] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.roq.hcd.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxcLK-O_Kk7aqBvaiFzYgAB5hA"]
[Thu Sep 17 15:31:24.247848 2026] [security2:error] [pid 20162:tid 20315] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cron/.env"] [unique_id "aqxcLK-O_Kk7aqBvaiFzYwAAAaU"]
[Thu Sep 17 15:31:24.288382 2026] [autoindex:error] [pid 18946:tid 18977] [remote 74.7.227.4:60332] AH01276: Cannot serve directory /home1/roqhcdmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:31:24.320882 2026] [security2:error] [pid 18946:tid 19179] [client 161.35.164.148:58488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcLDqiPMah0Tz_U1OD8AABcSA"], referer: https://www.ohanaclinic.com/old/
[Thu Sep 17 15:31:24.404146 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/en/.env"] [unique_id "aqxcLK-O_Kk7aqBvaiFzaQAAAZA"]
[Thu Sep 17 15:31:24.430578 2026] [security2:error] [pid 18946:tid 19203] [client 139.59.114.163:39866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxcLDqiPMah0Tz_U1OD7wAAAYk"]
[Thu Sep 17 15:31:24.588597 2026] [core:error] [pid 20162:tid 20332] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:24.588617 2026] [core:error] [pid 20162:tid 20332] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:24.601544 2026] [security2:error] [pid 20162:tid 20389] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/administrator/.env"] [unique_id "aqxcLK-O_Kk7aqBvaiFzbwAAAe8"]
[Thu Sep 17 15:31:24.706568 2026] [authz_core:error] [pid 20162:tid 20419] [client 40.81.232.68:53936] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:31:24.756857 2026] [security2:error] [pid 20162:tid 20334] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/psnlink/.env"] [unique_id "aqxcLK-O_Kk7aqBvaiFzdQAAAbg"]
[Thu Sep 17 15:31:24.765906 2026] [security2:error] [pid 18946:tid 19196] [client 3.19.142.206:52187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OEBQAAAYI"]
[Thu Sep 17 15:31:24.765961 2026] [security2:error] [pid 18946:tid 19196] [client 3.19.142.206:52187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OEBQAAAYI"]
[Thu Sep 17 15:31:24.774350 2026] [security2:error] [pid 18946:tid 19117] [client 3.19.142.206:52213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OEBgAAATM"]
[Thu Sep 17 15:31:24.774392 2026] [security2:error] [pid 18946:tid 19117] [client 3.19.142.206:52213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OEBgAAATM"]
[Thu Sep 17 15:31:24.910576 2026] [security2:error] [pid 20162:tid 20339] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/exapi/.env"] [unique_id "aqxcLK-O_Kk7aqBvaiFzeAAAAb0"]
[Thu Sep 17 15:31:24.914175 2026] [security2:error] [pid 18946:tid 19136] [client 3.19.142.206:52234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OECgAAAUY"]
[Thu Sep 17 15:31:24.914226 2026] [security2:error] [pid 18946:tid 19136] [client 3.19.142.206:52234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OECgAAAUY"]
[Thu Sep 17 15:31:24.927902 2026] [security2:error] [pid 18946:tid 19197] [client 3.19.142.206:52213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OECwAAAYM"]
[Thu Sep 17 15:31:24.927950 2026] [security2:error] [pid 18946:tid 19197] [client 3.19.142.206:52213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/web/xmlrpc.php"] [unique_id "aqxcLDqiPMah0Tz_U1OECwAAAYM"]
[Thu Sep 17 15:31:24.983179 2026] [core:error] [pid 18946:tid 19109] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:24.983201 2026] [core:error] [pid 18946:tid 19109] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:25.067700 2026] [security2:error] [pid 20162:tid 20324] [client 34.154.243.218:53114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/sitemaps/.env"] [unique_id "aqxcLa-O_Kk7aqBvaiFzeQAAAa4"]
[Thu Sep 17 15:31:25.361753 2026] [security2:error] [pid 18946:tid 19078] [client 169.58.197.253:59720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxcLTqiPMah0Tz_U1OEEQAAAQw"], referer: binance.com
[Thu Sep 17 15:31:25.379013 2026] [core:error] [pid 18946:tid 19198] [client 34.94.72.59:57842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:25.379035 2026] [core:error] [pid 18946:tid 19198] [client 34.94.72.59:57842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:25.720100 2026] [security2:error] [pid 18946:tid 19174] [client 161.35.164.148:49768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcLTqiPMah0Tz_U1OEFgABbEw"], referer: http://www.ohanaclinic.com/wordpress/
[Thu Sep 17 15:31:25.720993 2026] [core:error] [pid 18946:tid 19090] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:25.721014 2026] [core:error] [pid 18946:tid 19090] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:25.866006 2026] [security2:error] [pid 20162:tid 20375] [client 79.116.89.151:57908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLa-O_Kk7aqBvaiFziwAAAeE"]
[Thu Sep 17 15:31:25.866150 2026] [security2:error] [pid 20162:tid 20375] [client 79.116.89.151:57908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLa-O_Kk7aqBvaiFziwAAAeE"]
[Thu Sep 17 15:31:25.960798 2026] [security2:error] [pid 18946:tid 19084] [client 103.61.184.148:60499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLTqiPMah0Tz_U1OEKwAAARI"]
[Thu Sep 17 15:31:25.960951 2026] [security2:error] [pid 18946:tid 19084] [client 103.61.184.148:60499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLTqiPMah0Tz_U1OEKwAAARI"]
[Thu Sep 17 15:31:26.057383 2026] [security2:error] [pid 18946:tid 19106] [client 161.35.164.148:58488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcLTqiPMah0Tz_U1OEKQABKCs"], referer: https://www.ohanaclinic.com/wordpress/
[Thu Sep 17 15:31:26.267219 2026] [security2:error] [pid 20162:tid 20304] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/logs/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzkQAAAZo"]
[Thu Sep 17 15:31:26.321427 2026] [core:error] [pid 20162:tid 20337] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:26.321455 2026] [core:error] [pid 20162:tid 20337] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:26.423402 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cache/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzlwAAAZE"]
[Thu Sep 17 15:31:26.424181 2026] [security2:error] [pid 20162:tid 20171] [remote 62.201.244.85:24927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcLq-O_Kk7aqBvaiFzkgABlAc"]
[Thu Sep 17 15:31:26.559100 2026] [security2:error] [pid 18946:tid 19140] [client 161.35.164.148:49768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcLjqiPMah0Tz_U1OEMgABSkE"], referer: http://www.ohanaclinic.com/backup/
[Thu Sep 17 15:31:26.576419 2026] [security2:error] [pid 20162:tid 20358] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mailer/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzmAAAAdA"]
[Thu Sep 17 15:31:26.598441 2026] [security2:error] [pid 20162:tid 20379] [client 34.94.72.59:57874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzmQAAAeU"]
[Thu Sep 17 15:31:26.629130 2026] [security2:error] [pid 20162:tid 20372] [client 114.198.138.124:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLq-O_Kk7aqBvaiFzmwAAAd4"]
[Thu Sep 17 15:31:26.629263 2026] [security2:error] [pid 20162:tid 20372] [client 114.198.138.124:51516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLq-O_Kk7aqBvaiFzmwAAAd4"]
[Thu Sep 17 15:31:26.704070 2026] [security2:error] [pid 20162:tid 20412] [client 34.94.72.59:57874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFznQAAAgY"]
[Thu Sep 17 15:31:26.729994 2026] [security2:error] [pid 20162:tid 20380] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mail/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzoAAAAeY"]
[Thu Sep 17 15:31:26.755962 2026] [security2:error] [pid 18946:tid 19188] [client 139.59.114.163:39872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxcLjqiPMah0Tz_U1OEPQAAAXo"]
[Thu Sep 17 15:31:26.836362 2026] [security2:error] [pid 20162:tid 20357] [client 34.94.72.59:57874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzoQAAAc8"]
[Thu Sep 17 15:31:26.881170 2026] [security2:error] [pid 20162:tid 20385] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/email/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzowAAAes"]
[Thu Sep 17 15:31:26.890817 2026] [security2:error] [pid 18946:tid 19096] [client 161.35.164.148:58488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcLjqiPMah0Tz_U1OEPgABHj0"], referer: https://www.ohanaclinic.com/backup/
[Thu Sep 17 15:31:26.893468 2026] [security2:error] [pid 20162:tid 20349] [client 34.94.72.59:57874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzpQAAAcc"]
[Thu Sep 17 15:31:26.941790 2026] [security2:error] [pid 20162:tid 20355] [client 34.94.72.59:57874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzqQAAAc0"]
[Thu Sep 17 15:31:26.980976 2026] [security2:error] [pid 20162:tid 20381] [client 34.94.72.59:57874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxcLq-O_Kk7aqBvaiFzrwAAAec"]
[Thu Sep 17 15:31:27.008125 2026] [security2:error] [pid 18946:tid 19156] [client 136.158.61.34:47558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEYAAAAVo"]
[Thu Sep 17 15:31:27.008252 2026] [security2:error] [pid 18946:tid 19156] [client 136.158.61.34:47558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEYAAAAVo"]
[Thu Sep 17 15:31:27.037069 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/smtp/.env"] [unique_id "aqxcL6-O_Kk7aqBvaiFzsgAAAaM"]
[Thu Sep 17 15:31:27.042073 2026] [security2:error] [pid 18946:tid 19195] [client 139.59.114.163:39872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxcLjqiPMah0Tz_U1OEXQAAAYE"]
[Thu Sep 17 15:31:27.105984 2026] [core:error] [pid 18946:tid 19133] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:27.106003 2026] [core:error] [pid 18946:tid 19133] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:27.195688 2026] [security2:error] [pid 20162:tid 20324] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mailing/.env"] [unique_id "aqxcL6-O_Kk7aqBvaiFzuAAAAa4"]
[Thu Sep 17 15:31:27.216320 2026] [security2:error] [pid 18946:tid 19079] [client 3.19.142.206:52997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEcgAAAQ0"]
[Thu Sep 17 15:31:27.302147 2026] [security2:error] [pid 18946:tid 19043] [remote 45.138.12.25:55296] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900923"] [msg "contact form logging"] [hostname "freegamest.com"] [uri "/config/mail.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEdAABKWA"]
[Thu Sep 17 15:31:27.302177 2026] [security2:error] [pid 18946:tid 19043] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1554"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "freegamest.com"] [uri "/config/mail.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEdAABKWA"]
[Thu Sep 17 15:31:27.334159 2026] [security2:error] [pid 18946:tid 19198] [client 139.59.114.163:39872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.org"] [uri "/index.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEcwAAAYQ"]
[Thu Sep 17 15:31:27.354103 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/notifications/.env"] [unique_id "aqxcL6-O_Kk7aqBvaiFzuQAAAcI"]
[Thu Sep 17 15:31:27.375646 2026] [security2:error] [pid 18946:tid 19169] [client 161.35.164.148:49768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEcAABZ2g"], referer: http://www.ohanaclinic.com/blog/
[Thu Sep 17 15:31:27.483175 2026] [security2:error] [pid 18946:tid 19150] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OEdwAAAVQ"]
[Thu Sep 17 15:31:27.514139 2026] [security2:error] [pid 20162:tid 20341] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/notify/.env"] [unique_id "aqxcL6-O_Kk7aqBvaiFzuwAAAb8"]
[Thu Sep 17 15:31:27.549570 2026] [security2:error] [pid 18946:tid 19165] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OEeQAAAWM"]
[Thu Sep 17 15:31:27.588090 2026] [security2:error] [pid 18946:tid 19200] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OEegAAAYY"]
[Thu Sep 17 15:31:27.670054 2026] [security2:error] [pid 20162:tid 20307] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/sender/.env"] [unique_id "aqxcL6-O_Kk7aqBvaiFzvQAAAZ0"]
[Thu Sep 17 15:31:27.680340 2026] [security2:error] [pid 18946:tid 19122] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OEewAAATg"]
[Thu Sep 17 15:31:27.714358 2026] [security2:error] [pid 18946:tid 19174] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OEfQAAAWw"]
[Thu Sep 17 15:31:27.719598 2026] [security2:error] [pid 18946:tid 19036] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "freegamest.com"] [uri "/wp-config.php.old"] [unique_id "aqxcLzqiPMah0Tz_U1OEhQABGFk"]
[Thu Sep 17 15:31:27.719598 2026] [security2:error] [pid 18946:tid 19025] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "freegamest.com"] [uri "/wp-config.php.bak"] [unique_id "aqxcLzqiPMah0Tz_U1OEhAABGE4"]
[Thu Sep 17 15:31:27.719607 2026] [security2:error] [pid 18946:tid 19073] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "freegamest.com"] [uri "/wp-config.php.new"] [unique_id "aqxcLzqiPMah0Tz_U1OEhgABGH4"]
[Thu Sep 17 15:31:27.778657 2026] [security2:error] [pid 18946:tid 18952] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxcLzqiPMah0Tz_U1OEjwABGAU"]
[Thu Sep 17 15:31:27.778691 2026] [security2:error] [pid 18946:tid 19062] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxcLzqiPMah0Tz_U1OEkgABGHM"]
[Thu Sep 17 15:31:27.799057 2026] [security2:error] [pid 18946:tid 19143] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OElwAAAU0"]
[Thu Sep 17 15:31:27.822058 2026] [security2:error] [pid 20162:tid 20350] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/campaign/.env"] [unique_id "aqxcL6-O_Kk7aqBvaiFzxgAAAcg"]
[Thu Sep 17 15:31:27.859904 2026] [security2:error] [pid 18946:tid 19121] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OEmwAAATc"]
[Thu Sep 17 15:31:27.978043 2026] [security2:error] [pid 20162:tid 20368] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/newsletter/.env"] [unique_id "aqxcL6-O_Kk7aqBvaiFzyQAAAdo"]
[Thu Sep 17 15:31:27.988387 2026] [security2:error] [pid 18946:tid 19098] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxcLzqiPMah0Tz_U1OEngAAASA"]
[Thu Sep 17 15:31:28.011245 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxcMDqiPMah0Tz_U1OEnwAAASY"]
[Thu Sep 17 15:31:28.090653 2026] [security2:error] [pid 18946:tid 19040] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxcMDqiPMah0Tz_U1OEpQABbV0"]
[Thu Sep 17 15:31:28.129806 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/ses/.env"] [unique_id "aqxcMK-O_Kk7aqBvaiFzygAAAZs"]
[Thu Sep 17 15:31:28.161774 2026] [security2:error] [pid 18946:tid 19115] [client 161.35.164.148:49768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcLzqiPMah0Tz_U1OEnQABMW0"], referer: http://www.ohanaclinic.com/wp/
[Thu Sep 17 15:31:28.180510 2026] [security2:error] [pid 18946:tid 19138] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxcMDqiPMah0Tz_U1OEqgAAAUg"]
[Thu Sep 17 15:31:28.290721 2026] [security2:error] [pid 20162:tid 20304] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/sendgrid/.env"] [unique_id "aqxcMK-O_Kk7aqBvaiFzywAAAZo"]
[Thu Sep 17 15:31:28.316416 2026] [security2:error] [pid 18946:tid 19077] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxcMDqiPMah0Tz_U1OErwAAAQs"]
[Thu Sep 17 15:31:28.443208 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/sparkpost/.env"] [unique_id "aqxcMK-O_Kk7aqBvaiFzzAAAAbs"]
[Thu Sep 17 15:31:28.486733 2026] [security2:error] [pid 18946:tid 19194] [client 161.35.164.148:58488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcMDqiPMah0Tz_U1OErQABgAs"], referer: https://www.ohanaclinic.com/wp/
[Thu Sep 17 15:31:28.539379 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxcMDqiPMah0Tz_U1OEsgAAAUY"]
[Thu Sep 17 15:31:28.594945 2026] [security2:error] [pid 20162:tid 20398] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/postmark/.env"] [unique_id "aqxcMK-O_Kk7aqBvaiFz1wAAAfg"]
[Thu Sep 17 15:31:28.675258 2026] [security2:error] [pid 20162:tid 20333] [client 217.196.163.96:47168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcMK-O_Kk7aqBvaiFzzwABtxc"]
[Thu Sep 17 15:31:28.718235 2026] [security2:error] [pid 18946:tid 19185] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxcMDqiPMah0Tz_U1OEzAAAAXc"]
[Thu Sep 17 15:31:28.748457 2026] [security2:error] [pid 20162:tid 20415] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mailgun/.env"] [unique_id "aqxcMK-O_Kk7aqBvaiFz3AAAAgk"]
[Thu Sep 17 15:31:28.902165 2026] [security2:error] [pid 20162:tid 20319] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mandrill/.env"] [unique_id "aqxcMK-O_Kk7aqBvaiFz4AAAAak"]
[Thu Sep 17 15:31:28.933539 2026] [security2:error] [pid 18946:tid 19107] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxcMDqiPMah0Tz_U1OE5gAAASk"]
[Thu Sep 17 15:31:28.965147 2026] [security2:error] [pid 18946:tid 19119] [client 161.35.164.148:49768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcMDqiPMah0Tz_U1OEzQABNXk"], referer: http://www.ohanaclinic.com/new/
[Thu Sep 17 15:31:29.055816 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mailjet/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiFz5wAAAeQ"]
[Thu Sep 17 15:31:29.189739 2026] [security2:error] [pid 18946:tid 19084] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OE8gAAARI"]
[Thu Sep 17 15:31:29.208863 2026] [security2:error] [pid 20162:tid 20381] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/brevo/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiFz7gAAAec"]
[Thu Sep 17 15:31:29.248108 2026] [security2:error] [pid 18946:tid 19177] [client 23.251.146.115:42784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxcMDqiPMah0Tz_U1OEpwABb1o"]
[Thu Sep 17 15:31:29.249988 2026] [security2:error] [pid 18946:tid 19094] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFAQAAARw"]
[Thu Sep 17 15:31:29.300821 2026] [security2:error] [pid 18946:tid 19140] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFCgAAAUo"]
[Thu Sep 17 15:31:29.344551 2026] [security2:error] [pid 18946:tid 19200] [client 161.35.164.148:58488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ohanaclinic.com"] [uri "/index.php"] [unique_id "aqxcMTqiPMah0Tz_U1OE7wABhhw"], referer: https://www.ohanaclinic.com/new/
[Thu Sep 17 15:31:29.361521 2026] [security2:error] [pid 20162:tid 20397] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/transactional/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiFz9gAAAfc"]
[Thu Sep 17 15:31:29.378080 2026] [security2:error] [pid 18946:tid 19144] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFEwAAAU4"]
[Thu Sep 17 15:31:29.454169 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFGAAAASs"]
[Thu Sep 17 15:31:29.492357 2026] [security2:error] [pid 18946:tid 19096] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFHwAAAR4"]
[Thu Sep 17 15:31:29.515444 2026] [security2:error] [pid 20162:tid 20296] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/bulk/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiF0AwAAAZI"]
[Thu Sep 17 15:31:29.516855 2026] [security2:error] [pid 18946:tid 19121] [client 23.251.146.115:42784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxcMTqiPMah0Tz_U1OFCAABN0g"]
[Thu Sep 17 15:31:29.530018 2026] [security2:error] [pid 18946:tid 19176] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFIwAAAW4"]
[Thu Sep 17 15:31:29.634897 2026] [security2:error] [pid 20162:tid 20305] [client 40.81.232.68:57519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxcMa-O_Kk7aqBvaiF0CAAAAZs"], referer: binance.com
[Thu Sep 17 15:31:29.646796 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFQAAAAR8"]
[Thu Sep 17 15:31:29.667626 2026] [security2:error] [pid 20162:tid 20392] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/aws/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiF0CgAAAfI"]
[Thu Sep 17 15:31:29.684135 2026] [security2:error] [pid 20162:tid 20406] [client 34.55.12.4:44002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.emp.zyt.mybluehost.me"] [uri "/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiF0DAAAAgA"]
[Thu Sep 17 15:31:29.722315 2026] [security2:error] [pid 18946:tid 19169] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFQwAAAWc"]
[Thu Sep 17 15:31:29.749100 2026] [security2:error] [pid 18946:tid 19122] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFRQAAATg"]
[Thu Sep 17 15:31:29.804869 2026] [security2:error] [pid 18946:tid 19079] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFUQAAAQ0"]
[Thu Sep 17 15:31:29.819986 2026] [security2:error] [pid 20162:tid 20360] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/azure/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiF0DgAAAdI"]
[Thu Sep 17 15:31:29.835373 2026] [security2:error] [pid 18946:tid 19054] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/database.sql"] [unique_id "aqxcMTqiPMah0Tz_U1OFXAABGWs"]
[Thu Sep 17 15:31:29.858167 2026] [security2:error] [pid 18946:tid 19181] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxcMTqiPMah0Tz_U1OFQQAAAXM"]
[Thu Sep 17 15:31:29.972151 2026] [security2:error] [pid 20162:tid 20342] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/gcp/.env"] [unique_id "aqxcMa-O_Kk7aqBvaiF0GQAAAcA"]
[Thu Sep 17 15:31:29.982522 2026] [security2:error] [pid 18946:tid 19145] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxcMTqiPMah0Tz_U1OFZwAAAU8"]
[Thu Sep 17 15:31:30.007904 2026] [security2:error] [pid 18946:tid 19110] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFaQAAASw"]
[Thu Sep 17 15:31:30.030831 2026] [security2:error] [pid 18946:tid 19089] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFagAAARc"]
[Thu Sep 17 15:31:30.051290 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFbgAAASs"]
[Thu Sep 17 15:31:30.122124 2026] [security2:error] [pid 18946:tid 19158] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFhQAAAVw"]
[Thu Sep 17 15:31:30.123946 2026] [security2:error] [pid 20162:tid 20400] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cloud/.env"] [unique_id "aqxcMq-O_Kk7aqBvaiF0GwAAAfo"]
[Thu Sep 17 15:31:30.136210 2026] [security2:error] [pid 18946:tid 19043] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/job/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFiQABQWA"]
[Thu Sep 17 15:31:30.245477 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFkQAAAUc"]
[Thu Sep 17 15:31:30.274968 2026] [security2:error] [pid 20162:tid 20349] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/infrastructure/.env"] [unique_id "aqxcMq-O_Kk7aqBvaiF0IgAAAcc"]
[Thu Sep 17 15:31:30.355465 2026] [authz_core:error] [pid 18946:tid 19192] [client 169.58.197.251:49544] AH01630: client denied by server configuration: /home2/sfvhbtor/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:31:30.434295 2026] [security2:error] [pid 18946:tid 19124] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFmAAAATo"]
[Thu Sep 17 15:31:30.437105 2026] [security2:error] [pid 20162:tid 20389] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/docker/.env"] [unique_id "aqxcMq-O_Kk7aqBvaiF0KgAAAe8"]
[Thu Sep 17 15:31:30.530726 2026] [security2:error] [pid 18946:tid 19148] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFmQAAAVI"]
[Thu Sep 17 15:31:30.589201 2026] [security2:error] [pid 20162:tid 20409] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/k8s/.env"] [unique_id "aqxcMq-O_Kk7aqBvaiF0KwAAAgM"]
[Thu Sep 17 15:31:30.632490 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFnAAAAYg"]
[Thu Sep 17 15:31:30.718651 2026] [security2:error] [pid 18946:tid 19062] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "freegamest.com"] [uri "/wp-config.php.swp"] [unique_id "aqxcMjqiPMah0Tz_U1OFowABb3M"]
[Thu Sep 17 15:31:30.719572 2026] [security2:error] [pid 18946:tid 19035] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/wp/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFnwABb1g"]
[Thu Sep 17 15:31:30.723092 2026] [security2:error] [pid 18946:tid 19094] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFrAAAARw"]
[Thu Sep 17 15:31:30.742592 2026] [security2:error] [pid 20162:tid 20390] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/kubernetes/.env"] [unique_id "aqxcMq-O_Kk7aqBvaiF0LgAAAfA"]
[Thu Sep 17 15:31:30.800028 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFsgAAAVA"]
[Thu Sep 17 15:31:30.903333 2026] [security2:error] [pid 20162:tid 20341] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/terraform/.env"] [unique_id "aqxcMq-O_Kk7aqBvaiF0MgAAAb8"]
[Thu Sep 17 15:31:30.904093 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxcMjqiPMah0Tz_U1OFtwAAAQ8"]
[Thu Sep 17 15:31:31.037300 2026] [security2:error] [pid 18946:tid 19113] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFuQAAAS8"]
[Thu Sep 17 15:31:31.073826 2026] [security2:error] [pid 20162:tid 20363] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/ansible/.env"] [unique_id "aqxcM6-O_Kk7aqBvaiF0NAAAAdU"]
[Thu Sep 17 15:31:31.131593 2026] [security2:error] [pid 18946:tid 19066] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "freegamest.com"] [uri "/wp-config.php~"] [unique_id "aqxcMzqiPMah0Tz_U1OFugABf3c"]
[Thu Sep 17 15:31:31.133230 2026] [security2:error] [pid 18946:tid 19040] [remote 45.138.12.25:55296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freegamest.com"] [uri "/2021/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFvQABf10"]
[Thu Sep 17 15:31:31.210396 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFxgAAAUk"]
[Thu Sep 17 15:31:31.237228 2026] [security2:error] [pid 20162:tid 20316] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/.git/.env"] [unique_id "aqxcM6-O_Kk7aqBvaiF0OgAAAaY"]
[Thu Sep 17 15:31:31.242818 2026] [security2:error] [pid 18946:tid 19157] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFxwAAAVs"]
[Thu Sep 17 15:31:31.300778 2026] [security2:error] [pid 18946:tid 19091] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFyQAAARk"]
[Thu Sep 17 15:31:31.362387 2026] [security2:error] [pid 18946:tid 19115] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFzAAAATE"]
[Thu Sep 17 15:31:31.390441 2026] [security2:error] [pid 20162:tid 20350] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/ci/.env"] [unique_id "aqxcM6-O_Kk7aqBvaiF0PAAAAcg"]
[Thu Sep 17 15:31:31.421111 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFzgAAAWQ"]
[Thu Sep 17 15:31:31.446132 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OFzwAAASE"]
[Thu Sep 17 15:31:31.549659 2026] [security2:error] [pid 20162:tid 20314] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cd/.env"] [unique_id "aqxcM6-O_Kk7aqBvaiF0PQAAAaQ"]
[Thu Sep 17 15:31:31.556387 2026] [security2:error] [pid 18946:tid 19167] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OF0gAAAWU"]
[Thu Sep 17 15:31:31.668182 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OF1QAAASQ"]
[Thu Sep 17 15:31:31.702881 2026] [authz_core:error] [pid 18946:tid 19162] [client 4.240.114.86:61667] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:31:31.707182 2026] [security2:error] [pid 20162:tid 20362] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/jenkins/.env"] [unique_id "aqxcM6-O_Kk7aqBvaiF0PwAAAdQ"]
[Thu Sep 17 15:31:31.743403 2026] [security2:error] [pid 18946:tid 19080] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OF1wAAAQ4"]
[Thu Sep 17 15:31:31.792111 2026] [security2:error] [pid 18946:tid 19179] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OF2AAAAXE"]
[Thu Sep 17 15:31:31.859276 2026] [security2:error] [pid 20162:tid 20351] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/gitlab/.env"] [unique_id "aqxcM6-O_Kk7aqBvaiF0QQAAAck"]
[Thu Sep 17 15:31:31.871635 2026] [security2:error] [pid 18946:tid 19077] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OF2wAAAQs"]
[Thu Sep 17 15:31:31.918348 2026] [security2:error] [pid 18946:tid 19194] [client 3.19.142.206:54437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/index.php"] [unique_id "aqxcMzqiPMah0Tz_U1OF2gAAAYA"]
[Thu Sep 17 15:31:31.966944 2026] [security2:error] [pid 18946:tid 19180] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxcMzqiPMah0Tz_U1OF3QAAAXI"]
[Thu Sep 17 15:31:32.010213 2026] [security2:error] [pid 18946:tid 19151] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF3gAAAVU"]
[Thu Sep 17 15:31:32.012097 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/github/.env"] [unique_id "aqxcNK-O_Kk7aqBvaiF0QgAAAZs"]
[Thu Sep 17 15:31:32.066947 2026] [security2:error] [pid 18946:tid 19118] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF3wAAATQ"]
[Thu Sep 17 15:31:32.148838 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF4AAAAYc"]
[Thu Sep 17 15:31:32.163633 2026] [security2:error] [pid 20162:tid 20406] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/actions/.env"] [unique_id "aqxcNK-O_Kk7aqBvaiF0RAAAAgA"]
[Thu Sep 17 15:31:32.188611 2026] [security2:error] [pid 18946:tid 19108] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF4QAAASo"]
[Thu Sep 17 15:31:32.226153 2026] [security2:error] [pid 18946:tid 19133] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF4gAAAUM"]
[Thu Sep 17 15:31:32.323234 2026] [security2:error] [pid 20162:tid 20382] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/circleci/.env"] [unique_id "aqxcNK-O_Kk7aqBvaiF0RQAAAeg"]
[Thu Sep 17 15:31:32.345490 2026] [security2:error] [pid 18946:tid 19176] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF5QAAAW4"]
[Thu Sep 17 15:31:32.413567 2026] [security2:error] [pid 18946:tid 19095] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF6AAAAR0"]
[Thu Sep 17 15:31:32.476196 2026] [security2:error] [pid 20162:tid 20407] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/travis/.env"] [unique_id "aqxcNK-O_Kk7aqBvaiF0RgAAAgE"]
[Thu Sep 17 15:31:32.568355 2026] [security2:error] [pid 18946:tid 19186] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF6QAAAXg"]
[Thu Sep 17 15:31:32.636834 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/buildkite/.env"] [unique_id "aqxcNK-O_Kk7aqBvaiF0SQAAAZE"]
[Thu Sep 17 15:31:32.672262 2026] [security2:error] [pid 18946:tid 19172] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF7AAAAWo"]
[Thu Sep 17 15:31:32.774692 2026] [security2:error] [pid 18946:tid 19117] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF7QAAATM"]
[Thu Sep 17 15:31:32.789100 2026] [security2:error] [pid 20162:tid 20417] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mysql/.env"] [unique_id "aqxcNK-O_Kk7aqBvaiF0SgAAAgs"]
[Thu Sep 17 15:31:32.802145 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF7gAAAVc"]
[Thu Sep 17 15:31:32.850885 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF8QAAAR8"]
[Thu Sep 17 15:31:32.908166 2026] [security2:error] [pid 18946:tid 19192] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF9QAAAX4"]
[Thu Sep 17 15:31:32.946625 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/postgres/.env"] [unique_id "aqxcNK-O_Kk7aqBvaiF0SwAAAfQ"]
[Thu Sep 17 15:31:32.987150 2026] [security2:error] [pid 18946:tid 19150] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxcNDqiPMah0Tz_U1OF9gAAAVQ"]
[Thu Sep 17 15:31:33.050479 2026] [security2:error] [pid 18946:tid 19148] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OF9wAAAVI"]
[Thu Sep 17 15:31:33.100580 2026] [security2:error] [pid 20162:tid 20325] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mongodb/.env"] [unique_id "aqxcNa-O_Kk7aqBvaiF0TQAAAa8"]
[Thu Sep 17 15:31:33.130682 2026] [security2:error] [pid 18946:tid 19094] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OF-AAAARw"]
[Thu Sep 17 15:31:33.188995 2026] [security2:error] [pid 18946:tid 19195] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OF_QAAAYE"]
[Thu Sep 17 15:31:33.256017 2026] [security2:error] [pid 20162:tid 20348] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/redis/.env"] [unique_id "aqxcNa-O_Kk7aqBvaiF0VgAAAcY"]
[Thu Sep 17 15:31:33.269124 2026] [security2:error] [pid 18946:tid 19197] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGDQAAAYM"]
[Thu Sep 17 15:31:33.332994 2026] [security2:error] [pid 18946:tid 19198] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGFwAAAYQ"]
[Thu Sep 17 15:31:33.388221 2026] [security2:error] [pid 18946:tid 19103] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGIgAAASU"]
[Thu Sep 17 15:31:33.413625 2026] [security2:error] [pid 20162:tid 20357] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/elasticsearch/.env"] [unique_id "aqxcNa-O_Kk7aqBvaiF0cQAAAc8"]
[Thu Sep 17 15:31:33.457175 2026] [security2:error] [pid 18946:tid 19145] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGJgAAAU8"]
[Thu Sep 17 15:31:33.521932 2026] [security2:error] [pid 18946:tid 19175] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGKAAAAW0"]
[Thu Sep 17 15:31:33.566224 2026] [security2:error] [pid 20162:tid 20334] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/rabbitmq/.env"] [unique_id "aqxcNa-O_Kk7aqBvaiF0cgAAAbg"]
[Thu Sep 17 15:31:33.568885 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGKgAAASQ"]
[Thu Sep 17 15:31:33.624603 2026] [security2:error] [pid 18946:tid 19162] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGKwAAAWA"]
[Thu Sep 17 15:31:33.638950 2026] [security2:error] [pid 18946:tid 19080] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGLgAAAQ4"]
[Thu Sep 17 15:31:33.674767 2026] [security2:error] [pid 18946:tid 19077] [client 34.94.72.59:57878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGMQAAAQs"]
[Thu Sep 17 15:31:33.726812 2026] [security2:error] [pid 20162:tid 20327] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/kafka/.env"] [unique_id "aqxcNa-O_Kk7aqBvaiF0dgAAAbE"]
[Thu Sep 17 15:31:33.883260 2026] [security2:error] [pid 20162:tid 20419] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/queue/.env"] [unique_id "aqxcNa-O_Kk7aqBvaiF0egAAAg0"]
[Thu Sep 17 15:31:33.948264 2026] [security2:error] [pid 18946:tid 19149] [client 3.82.141.143:37992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "beiselcoaching.com"] [uri "/web.config"] [unique_id "aqxcNTqiPMah0Tz_U1OGOwAAAVM"]
[Thu Sep 17 15:31:33.948816 2026] [security2:error] [pid 20162:tid 20390] [client 3.82.141.143:37888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "beiselcoaching.com"] [uri "/.env.old"] [unique_id "aqxcNa-O_Kk7aqBvaiF0fQAAAfA"]
[Thu Sep 17 15:31:33.950114 2026] [security2:error] [pid 20162:tid 20336] [client 3.82.141.143:38140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "beiselcoaching.com"] [uri "/wp-config.php.save"] [unique_id "aqxcNa-O_Kk7aqBvaiF0iQAAAbo"]
[Thu Sep 17 15:31:33.951429 2026] [security2:error] [pid 18946:tid 19084] [client 3.82.141.143:37890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "beiselcoaching.com"] [uri "/.env.bak"] [unique_id "aqxcNTqiPMah0Tz_U1OGPgAAARI"]
[Thu Sep 17 15:31:33.951430 2026] [security2:error] [pid 20162:tid 20346] [client 3.82.141.143:38166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "beiselcoaching.com"] [uri "/.env.backup"] [unique_id "aqxcNa-O_Kk7aqBvaiF0iAAAAcQ"]
[Thu Sep 17 15:31:33.951903 2026] [security2:error] [pid 18946:tid 19201] [client 3.82.141.143:38146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "beiselcoaching.com"] [uri "/wp-config.php~"] [unique_id "aqxcNTqiPMah0Tz_U1OGQQAAAYc"]
[Thu Sep 17 15:31:33.952845 2026] [security2:error] [pid 20162:tid 20345] [client 3.82.141.143:38118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beiselcoaching.com"] [uri "/wp-config.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0jAAAAcM"]
[Thu Sep 17 15:31:33.953309 2026] [security2:error] [pid 18946:tid 19199] [client 3.82.141.143:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "beiselcoaching.com"] [uri "/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGRAAAAYU"]
[Thu Sep 17 15:31:33.957507 2026] [security2:error] [pid 18946:tid 19135] [client 3.82.141.143:38200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beiselcoaching.com"] [uri "/config.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGSAAAAUU"]
[Thu Sep 17 15:31:33.959067 2026] [security2:error] [pid 18946:tid 19163] [client 3.82.141.143:38110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "beiselcoaching.com"] [uri "/wp-config.php.bak"] [unique_id "aqxcNTqiPMah0Tz_U1OGSgAAAWE"]
[Thu Sep 17 15:31:33.961213 2026] [security2:error] [pid 18946:tid 19185] [client 3.82.141.143:38132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "beiselcoaching.com"] [uri "/wp-config.php.old"] [unique_id "aqxcNTqiPMah0Tz_U1OGTQAAAXc"]
[Thu Sep 17 15:31:33.969890 2026] [security2:error] [pid 18946:tid 19078] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxcNTqiPMah0Tz_U1OGTgAAAQw"]
[Thu Sep 17 15:31:34.027629 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGUgAAAR8"]
[Thu Sep 17 15:31:34.035335 2026] [security2:error] [pid 20162:tid 20322] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/worker/.env"] [unique_id "aqxcNq-O_Kk7aqBvaiF0lQAAAaw"]
[Thu Sep 17 15:31:34.155187 2026] [security2:error] [pid 18946:tid 19150] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGVAAAAVQ"]
[Thu Sep 17 15:31:34.192118 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/job/.env"] [unique_id "aqxcNq-O_Kk7aqBvaiF0lwAAAc4"]
[Thu Sep 17 15:31:34.233501 2026] [security2:error] [pid 18946:tid 19131] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGVgAAAUE"]
[Thu Sep 17 15:31:34.262615 2026] [security2:error] [pid 18946:tid 19200] [client 3.82.141.143:38100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGPwAAAYY"]
[Thu Sep 17 15:31:34.264571 2026] [security2:error] [pid 18946:tid 19122] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGVwAAATg"]
[Thu Sep 17 15:31:34.265735 2026] [security2:error] [pid 18946:tid 19134] [client 3.82.141.143:37932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGQgAAAUQ"]
[Thu Sep 17 15:31:34.267363 2026] [security2:error] [pid 18946:tid 19111] [client 3.82.141.143:38170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGSwAAAS0"]
[Thu Sep 17 15:31:34.275722 2026] [security2:error] [pid 20162:tid 20374] [client 3.82.141.143:38022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0hQAAAeA"]
[Thu Sep 17 15:31:34.281003 2026] [security2:error] [pid 18946:tid 19176] [client 3.82.141.143:37874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGRgAAAW4"]
[Thu Sep 17 15:31:34.285981 2026] [security2:error] [pid 20162:tid 20301] [client 3.82.141.143:38084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0hAAAAZc"]
[Thu Sep 17 15:31:34.288608 2026] [security2:error] [pid 20162:tid 20294] [client 3.82.141.143:37924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0jQAAAZA"]
[Thu Sep 17 15:31:34.291182 2026] [security2:error] [pid 20162:tid 20335] [client 3.82.141.143:38186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0igAAAbk"]
[Thu Sep 17 15:31:34.294103 2026] [security2:error] [pid 20162:tid 20326] [client 3.82.141.143:38074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0gwAAAbA"]
[Thu Sep 17 15:31:34.294856 2026] [security2:error] [pid 18946:tid 19156] [client 3.82.141.143:37854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGRwAAAVo"]
[Thu Sep 17 15:31:34.308013 2026] [security2:error] [pid 20162:tid 20341] [client 3.82.141.143:38048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0jwAAAb8"]
[Thu Sep 17 15:31:34.326406 2026] [security2:error] [pid 20162:tid 20381] [client 3.82.141.143:37958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0gAAAAec"]
[Thu Sep 17 15:31:34.328812 2026] [security2:error] [pid 20162:tid 20323] [client 3.82.141.143:38086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0fgAAAa0"]
[Thu Sep 17 15:31:34.329082 2026] [security2:error] [pid 18946:tid 19101] [client 3.82.141.143:38072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGPAAAASM"]
[Thu Sep 17 15:31:34.331989 2026] [security2:error] [pid 18946:tid 19106] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGWgAAASg"]
[Thu Sep 17 15:31:34.336628 2026] [security2:error] [pid 20162:tid 20329] [client 3.82.141.143:38148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0iwAAAbM"]
[Thu Sep 17 15:31:34.348123 2026] [security2:error] [pid 18946:tid 19095] [client 3.82.141.143:37912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGTAAAAR0"]
[Thu Sep 17 15:31:34.348871 2026] [security2:error] [pid 20162:tid 20362] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/test/.env"] [unique_id "aqxcNq-O_Kk7aqBvaiF0mwAAAdQ"]
[Thu Sep 17 15:31:34.351602 2026] [security2:error] [pid 18946:tid 19136] [client 3.82.141.143:37896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGQwAAAUY"]
[Thu Sep 17 15:31:34.382299 2026] [security2:error] [pid 18946:tid 19171] [client 3.82.141.143:38030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGOgAAAWk"]
[Thu Sep 17 15:31:34.406226 2026] [security2:error] [pid 20162:tid 20409] [client 143.105.152.240:30138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcNq-O_Kk7aqBvaiF0ngAAAgM"]
[Thu Sep 17 15:31:34.406877 2026] [security2:error] [pid 18946:tid 19138] [client 3.82.141.143:37976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGSQAAAUg"]
[Thu Sep 17 15:31:34.409258 2026] [security2:error] [pid 18946:tid 19114] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGWwAAATA"]
[Thu Sep 17 15:31:34.410552 2026] [security2:error] [pid 20162:tid 20409] [client 143.105.152.240:30138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcNq-O_Kk7aqBvaiF0ngAAAgM"]
[Thu Sep 17 15:31:34.426491 2026] [security2:error] [pid 20162:tid 20311] [client 3.82.141.143:38164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0ggAAAaE"]
[Thu Sep 17 15:31:34.461292 2026] [security2:error] [pid 20162:tid 20324] [client 3.82.141.143:38058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNa-O_Kk7aqBvaiF0fwAAAa4"]
[Thu Sep 17 15:31:34.504288 2026] [security2:error] [pid 20162:tid 20407] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/qa/.env"] [unique_id "aqxcNq-O_Kk7aqBvaiF0oAAAAgE"]
[Thu Sep 17 15:31:34.522674 2026] [security2:error] [pid 18946:tid 19190] [client 3.82.141.143:37982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcNTqiPMah0Tz_U1OGTwAAAXw"]
[Thu Sep 17 15:31:34.550812 2026] [security2:error] [pid 18946:tid 19144] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGXQAAAU4"]
[Thu Sep 17 15:31:34.594682 2026] [security2:error] [pid 20162:tid 20360] [client 3.19.142.206:55210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newspace.us"] [uri "/index.php"] [unique_id "aqxcNq-O_Kk7aqBvaiF0oQAAAdI"]
[Thu Sep 17 15:31:34.641742 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGYAAAATI"]
[Thu Sep 17 15:31:34.656957 2026] [security2:error] [pid 20162:tid 20408] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/preview/.env"] [unique_id "aqxcNq-O_Kk7aqBvaiF0pQAAAgI"]
[Thu Sep 17 15:31:34.811605 2026] [security2:error] [pid 20162:tid 20342] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/beta/.env"] [unique_id "aqxcNq-O_Kk7aqBvaiF0qAAAAcA"]
[Thu Sep 17 15:31:34.831930 2026] [security2:error] [pid 18946:tid 19162] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxcNjqiPMah0Tz_U1OGZwAAAWA"]
[Thu Sep 17 15:31:34.931417 2026] [security2:error] [pid 18946:tid 19152] [client 74.7.230.60:36694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "test.interlinck.com"] [uri "/index.php"] [unique_id "aqxcNDqiPMah0Tz_U1OF8wABVgg"]
[Thu Sep 17 15:31:34.973131 2026] [security2:error] [pid 20162:tid 20327] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/uat/.env"] [unique_id "aqxcNq-O_Kk7aqBvaiF0swAAAbE"]
[Thu Sep 17 15:31:35.037620 2026] [security2:error] [pid 18946:tid 19123] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGbgAAATk"]
[Thu Sep 17 15:31:35.089213 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGbwAAAUc"]
[Thu Sep 17 15:31:35.126962 2026] [security2:error] [pid 20162:tid 20419] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/stage/.env"] [unique_id "aqxcN6-O_Kk7aqBvaiF0tQAAAg0"]
[Thu Sep 17 15:31:35.142557 2026] [security2:error] [pid 18946:tid 19188] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGcQAAAXo"]
[Thu Sep 17 15:31:35.220911 2026] [security2:error] [pid 18946:tid 19200] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGdAAAAYY"]
[Thu Sep 17 15:31:35.286515 2026] [security2:error] [pid 20162:tid 20397] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/development/.env"] [unique_id "aqxcN6-O_Kk7aqBvaiF0uwAAAfc"]
[Thu Sep 17 15:31:35.353537 2026] [security2:error] [pid 18946:tid 19176] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGdwAAAW4"]
[Thu Sep 17 15:31:35.388772 2026] [security2:error] [pid 18946:tid 19156] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGeAAAAVo"]
[Thu Sep 17 15:31:35.422943 2026] [security2:error] [pid 18946:tid 19120] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGeQAAATY"]
[Thu Sep 17 15:31:35.446020 2026] [security2:error] [pid 20162:tid 20335] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/production/.env"] [unique_id "aqxcN6-O_Kk7aqBvaiF0vQAAAbk"]
[Thu Sep 17 15:31:35.474303 2026] [security2:error] [pid 18946:tid 19095] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGegAAAR0"]
[Thu Sep 17 15:31:35.528147 2026] [security2:error] [pid 18946:tid 19193] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGfQAAAX8"]
[Thu Sep 17 15:31:35.539837 2026] [security2:error] [pid 20162:tid 20323] [client 40.81.232.68:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxcN6-O_Kk7aqBvaiF0vgAAAa0"], referer: binance.com
[Thu Sep 17 15:31:35.549807 2026] [security2:error] [pid 18946:tid 19091] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGfgAAARk"]
[Thu Sep 17 15:31:35.590897 2026] [security2:error] [pid 18946:tid 19199] [client 79.106.203.86:46537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcNzqiPMah0Tz_U1OGewABhSI"]
[Thu Sep 17 15:31:35.600631 2026] [security2:error] [pid 20162:tid 20376] [client 34.154.243.218:54960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bigsisterteams.com"] [uri "/config/app/.env"] [unique_id "aqxcN6-O_Kk7aqBvaiF0vwAAAeI"]
[Thu Sep 17 15:31:35.674199 2026] [security2:error] [pid 18946:tid 19142] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGfwAAAUw"]
[Thu Sep 17 15:31:35.744676 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGgAAAAQ8"]
[Thu Sep 17 15:31:35.769545 2026] [security2:error] [pid 20162:tid 20383] [client 34.154.243.218:54960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/phpinfo.php"] [unique_id "aqxcN6-O_Kk7aqBvaiF0wAAAAek"]
[Thu Sep 17 15:31:35.811351 2026] [security2:error] [pid 18946:tid 19191] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGiAAAAX0"]
[Thu Sep 17 15:31:35.895895 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGjgAAATI"]
[Thu Sep 17 15:31:35.927882 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGjwAAAVA"]
[Thu Sep 17 15:31:36.016845 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxcNzqiPMah0Tz_U1OGkAAAAWQ"]
[Thu Sep 17 15:31:36.138449 2026] [security2:error] [pid 18946:tid 19135] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxcODqiPMah0Tz_U1OGlAAAAUU"]
[Thu Sep 17 15:31:36.179268 2026] [security2:error] [pid 18946:tid 19123] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxcODqiPMah0Tz_U1OGlQAAATk"]
[Thu Sep 17 15:31:36.287078 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.243.218:43630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/info.php"] [unique_id "aqxcODqiPMah0Tz_U1OGlwAAASQ"]
[Thu Sep 17 15:31:36.306347 2026] [security2:error] [pid 18946:tid 19188] [client 34.94.72.59:35572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxcODqiPMah0Tz_U1OGmgAAAXo"]
[Thu Sep 17 15:31:36.517821 2026] [core:error] [pid 20162:tid 20380] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:36.517841 2026] [core:error] [pid 20162:tid 20380] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:36.735695 2026] [security2:error] [pid 18946:tid 19091] [client 3.19.142.206:56127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGtgAAARk"]
[Thu Sep 17 15:31:36.735735 2026] [security2:error] [pid 18946:tid 19091] [client 3.19.142.206:56127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGtgAAARk"]
[Thu Sep 17 15:31:36.738289 2026] [security2:error] [pid 18946:tid 19199] [client 3.19.142.206:56141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGuAAAAYU"]
[Thu Sep 17 15:31:36.738289 2026] [security2:error] [pid 18946:tid 19112] [client 3.19.142.206:56143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGtwAAAS4"]
[Thu Sep 17 15:31:36.738327 2026] [security2:error] [pid 18946:tid 19199] [client 3.19.142.206:56141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGuAAAAYU"]
[Thu Sep 17 15:31:36.738328 2026] [security2:error] [pid 18946:tid 19112] [client 3.19.142.206:56143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGtwAAAS4"]
[Thu Sep 17 15:31:36.745992 2026] [security2:error] [pid 18946:tid 19104] [client 34.154.243.218:43644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/php.php"] [unique_id "aqxcODqiPMah0Tz_U1OGuQAAASY"]
[Thu Sep 17 15:31:36.790244 2026] [authz_core:error] [pid 20162:tid 20346] [client 169.58.197.253:60382] AH01630: client denied by server configuration: /home2/brianpag/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:31:36.796671 2026] [security2:error] [pid 20162:tid 20295] [client 103.61.184.148:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcOK-O_Kk7aqBvaiF0yAAAAZE"]
[Thu Sep 17 15:31:36.796785 2026] [security2:error] [pid 20162:tid 20295] [client 103.61.184.148:61082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcOK-O_Kk7aqBvaiF0yAAAAZE"]
[Thu Sep 17 15:31:36.891384 2026] [core:error] [pid 18946:tid 19187] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:36.891401 2026] [core:error] [pid 18946:tid 19187] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:36.901002 2026] [security2:error] [pid 18946:tid 19144] [client 3.19.142.206:56143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGvgAAAU4"]
[Thu Sep 17 15:31:36.901033 2026] [security2:error] [pid 18946:tid 19144] [client 3.19.142.206:56143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newspace.us"] [uri "/site/xmlrpc.php"] [unique_id "aqxcODqiPMah0Tz_U1OGvgAAAU4"]
[Thu Sep 17 15:31:37.127094 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OGwAAAAYc"]
[Thu Sep 17 15:31:37.183595 2026] [security2:error] [pid 18946:tid 19132] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OGwwAAAUI"]
[Thu Sep 17 15:31:37.217421 2026] [security2:error] [pid 18946:tid 19167] [client 34.154.243.218:43648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/i.php"] [unique_id "aqxcOTqiPMah0Tz_U1OGxQAAAWU"]
[Thu Sep 17 15:31:37.230366 2026] [security2:error] [pid 18946:tid 19190] [client 114.198.138.124:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcOTqiPMah0Tz_U1OGygAAAXw"]
[Thu Sep 17 15:31:37.230471 2026] [security2:error] [pid 18946:tid 19190] [client 114.198.138.124:62798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcOTqiPMah0Tz_U1OGygAAAXw"]
[Thu Sep 17 15:31:37.264011 2026] [security2:error] [pid 18946:tid 19165] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OGzAAAAWM"]
[Thu Sep 17 15:31:37.317159 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG0AAAAR8"]
[Thu Sep 17 15:31:37.365955 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG0gAAASQ"]
[Thu Sep 17 15:31:37.443081 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG0wAAATs"]
[Thu Sep 17 15:31:37.477889 2026] [security2:error] [pid 18946:tid 19203] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG1QAAAYk"]
[Thu Sep 17 15:31:37.579389 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG1gAAAVE"]
[Thu Sep 17 15:31:37.602821 2026] [security2:error] [pid 18946:tid 19117] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG1wAAATM"]
[Thu Sep 17 15:31:37.655880 2026] [security2:error] [pid 20162:tid 20372] [client 203.164.38.0:45737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcOa-O_Kk7aqBvaiF0zgAB3iM"]
[Thu Sep 17 15:31:37.682500 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.243.218:43650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/pi.php"] [unique_id "aqxcOTqiPMah0Tz_U1OG2wAAARw"]
[Thu Sep 17 15:31:37.702427 2026] [security2:error] [pid 18946:tid 19126] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG3AAAATw"]
[Thu Sep 17 15:31:37.797892 2026] [security2:error] [pid 18946:tid 19076] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG4gAAAQo"]
[Thu Sep 17 15:31:37.833110 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG5AAAASE"]
[Thu Sep 17 15:31:37.907550 2026] [security2:error] [pid 18946:tid 19177] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG5gAAAW8"]
[Thu Sep 17 15:31:37.928532 2026] [security2:error] [pid 18946:tid 19078] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxcOTqiPMah0Tz_U1OG5wAAAQw"]
[Thu Sep 17 15:31:38.134945 2026] [security2:error] [pid 18946:tid 19145] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG6gAAAU8"]
[Thu Sep 17 15:31:38.153427 2026] [security2:error] [pid 18946:tid 19080] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG6wAAAQ4"]
[Thu Sep 17 15:31:38.156677 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.243.218:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/pinfo.php"] [unique_id "aqxcOjqiPMah0Tz_U1OG7AAAAW4"]
[Thu Sep 17 15:31:38.197436 2026] [security2:error] [pid 18946:tid 19178] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG7QAAAXA"]
[Thu Sep 17 15:31:38.222343 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG7gAAAUk"]
[Thu Sep 17 15:31:38.285713 2026] [security2:error] [pid 18946:tid 19101] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG8QAAASM"]
[Thu Sep 17 15:31:38.316975 2026] [security2:error] [pid 18946:tid 19082] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG9AAAARA"]
[Thu Sep 17 15:31:38.385248 2026] [security2:error] [pid 18946:tid 19133] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG-AAAAUM"]
[Thu Sep 17 15:31:38.467149 2026] [security2:error] [pid 18946:tid 19093] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG-QAAARs"]
[Thu Sep 17 15:31:38.501300 2026] [security2:error] [pid 18946:tid 19180] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG-gAAAXI"]
[Thu Sep 17 15:31:38.632681 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.243.218:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/test.php"] [unique_id "aqxcOjqiPMah0Tz_U1OG_QAAAYQ"]
[Thu Sep 17 15:31:38.637733 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG_gAAARQ"]
[Thu Sep 17 15:31:38.686935 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OG_wAAAUY"]
[Thu Sep 17 15:31:38.796782 2026] [security2:error] [pid 18946:tid 19157] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OHAwAAAVs"]
[Thu Sep 17 15:31:38.906852 2026] [security2:error] [pid 18946:tid 19138] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxcOjqiPMah0Tz_U1OHCAAAAUg"]
[Thu Sep 17 15:31:38.912069 2026] [authz_core:error] [pid 18946:tid 19106] [client 4.240.114.86:50272] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:31:39.021881 2026] [security2:error] [pid 18946:tid 19189] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHCQAAAXs"]
[Thu Sep 17 15:31:39.106006 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHCgAAATI"]
[Thu Sep 17 15:31:39.145772 2026] [security2:error] [pid 18946:tid 19085] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHDwAAARM"]
[Thu Sep 17 15:31:39.189521 2026] [security2:error] [pid 18946:tid 19083] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHEQAAARE"]
[Thu Sep 17 15:31:39.210327 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHEgAAAWQ"]
[Thu Sep 17 15:31:39.256202 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHEwAAAQ8"]
[Thu Sep 17 15:31:39.301024 2026] [security2:error] [pid 18946:tid 19159] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHFQAAAV0"]
[Thu Sep 17 15:31:39.341915 2026] [security2:error] [pid 18946:tid 19140] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHGAAAAUo"]
[Thu Sep 17 15:31:39.456423 2026] [security2:error] [pid 18946:tid 19167] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHGwAAAWU"]
[Thu Sep 17 15:31:39.603913 2026] [security2:error] [pid 18946:tid 19188] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHHgAAAXo"]
[Thu Sep 17 15:31:39.622004 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.243.218:43682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/p.php"] [unique_id "aqxcOzqiPMah0Tz_U1OHHwAAAXw"]
[Thu Sep 17 15:31:39.638547 2026] [security2:error] [pid 18946:tid 19088] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHIAAAARY"]
[Thu Sep 17 15:31:39.698828 2026] [security2:error] [pid 18946:tid 19164] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHIQAAAWI"]
[Thu Sep 17 15:31:39.806965 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHJAAAATs"]
[Thu Sep 17 15:31:39.832018 2026] [security2:error] [pid 18946:tid 19186] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHJgAAAXg"]
[Thu Sep 17 15:31:39.911397 2026] [security2:error] [pid 18946:tid 19203] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHKAAAAYk"]
[Thu Sep 17 15:31:39.953453 2026] [security2:error] [pid 18946:tid 19155] [client 40.81.232.68:63058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxcOzqiPMah0Tz_U1OHKQAAAVk"], referer: binance.com
[Thu Sep 17 15:31:39.963830 2026] [security2:error] [pid 18946:tid 19131] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxcOzqiPMah0Tz_U1OHKgAAAUE"]
[Thu Sep 17 15:31:40.084459 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.243.218:43684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/debug.php"] [unique_id "aqxcPDqiPMah0Tz_U1OHLQAAAVE"]
[Thu Sep 17 15:31:40.096158 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHLwAAASE"]
[Thu Sep 17 15:31:40.127539 2026] [security2:error] [pid 18946:tid 19169] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHMAAAAWc"]
[Thu Sep 17 15:31:40.154016 2026] [security2:error] [pid 18946:tid 19177] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHMQAAAW8"]
[Thu Sep 17 15:31:40.192747 2026] [security2:error] [pid 18946:tid 19110] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHMgAAASw"]
[Thu Sep 17 15:31:40.300146 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHNAAAASc"]
[Thu Sep 17 15:31:40.346110 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHNgAAARo"]
[Thu Sep 17 15:31:40.402559 2026] [security2:error] [pid 18946:tid 19145] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHOAAAAU8"]
[Thu Sep 17 15:31:40.456182 2026] [security2:error] [pid 18946:tid 19200] [client 136.158.61.34:48878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcPDqiPMah0Tz_U1OHOQAAAYY"]
[Thu Sep 17 15:31:40.456292 2026] [security2:error] [pid 18946:tid 19200] [client 136.158.61.34:48878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcPDqiPMah0Tz_U1OHOQAAAYY"]
[Thu Sep 17 15:31:40.476814 2026] [security2:error] [pid 18946:tid 19178] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHOgAAAXA"]
[Thu Sep 17 15:31:40.544776 2026] [security2:error] [pid 20162:tid 20299] [client 34.154.243.218:43694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxcPK-O_Kk7aqBvaiF01AAAAZU"]
[Thu Sep 17 15:31:40.564488 2026] [security2:error] [pid 18946:tid 19121] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHOwAAATc"]
[Thu Sep 17 15:31:40.614306 2026] [security2:error] [pid 18946:tid 19194] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHPAAAAYA"]
[Thu Sep 17 15:31:40.738792 2026] [security2:error] [pid 18946:tid 19113] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHQAAAAS8"]
[Thu Sep 17 15:31:40.820847 2026] [security2:error] [pid 18946:tid 19093] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHQwAAARs"]
[Thu Sep 17 15:31:40.895805 2026] [security2:error] [pid 18946:tid 19198] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHSAAAAYQ"]
[Thu Sep 17 15:31:40.956875 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxcPDqiPMah0Tz_U1OHSgAAAUY"]
[Thu Sep 17 15:31:41.004048 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.243.218:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/test/phpinfo.php"] [unique_id "aqxcPTqiPMah0Tz_U1OHSwAAAT4"]
[Thu Sep 17 15:31:41.154422 2026] [security2:error] [pid 18946:tid 19179] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxcPTqiPMah0Tz_U1OHTAAAAXE"]
[Thu Sep 17 15:31:41.342444 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxcPTqiPMah0Tz_U1OHUQAAASY"]
[Thu Sep 17 15:31:41.424236 2026] [security2:error] [pid 18946:tid 19115] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxcPTqiPMah0Tz_U1OHUwAAATE"]
[Thu Sep 17 15:31:41.470367 2026] [security2:error] [pid 20162:tid 20329] [client 34.154.243.218:43718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxcPa-O_Kk7aqBvaiF01gAAAbM"]
[Thu Sep 17 15:31:41.480571 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.72.59:35604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.threadalittlelight.com"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxcPTqiPMah0Tz_U1OHVAAAAXk"]
[Thu Sep 17 15:31:41.577123 2026] [security2:error] [pid 18946:tid 19162] [client 34.94.72.59:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/phpinfo.php"] [unique_id "aqxcPTqiPMah0Tz_U1OHVgAAAWA"]
[Thu Sep 17 15:31:41.934371 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.243.218:43728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/old/phpinfo.php"] [unique_id "aqxcPTqiPMah0Tz_U1OHWAAAARM"]
[Thu Sep 17 15:31:41.965421 2026] [security2:error] [pid 20162:tid 20392] [client 34.94.72.59:55414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/info.php"] [unique_id "aqxcPa-O_Kk7aqBvaiF02QAAAfI"]
[Thu Sep 17 15:31:42.389201 2026] [security2:error] [pid 20162:tid 20377] [client 34.154.243.218:43742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcPq-O_Kk7aqBvaiF03QAAAeM"]
[Thu Sep 17 15:31:42.406832 2026] [security2:error] [pid 20162:tid 20314] [client 34.94.72.59:55418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/php.php"] [unique_id "aqxcPq-O_Kk7aqBvaiF03gAAAaQ"]
[Thu Sep 17 15:31:42.730311 2026] [security2:error] [pid 20162:tid 20331] [client 160.250.44.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxcPq-O_Kk7aqBvaiF03wAAAbU"], referer: https://ccrmediator.com
[Thu Sep 17 15:31:42.746490 2026] [security2:error] [pid 18946:tid 19149] [client 57.141.14.112:29764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxcPjqiPMah0Tz_U1OHZwABU1Y"]
[Thu Sep 17 15:31:42.863051 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.243.218:43748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/public/phpinfo.php"] [unique_id "aqxcPjqiPMah0Tz_U1OHbQAAASo"]
[Thu Sep 17 15:31:42.899615 2026] [security2:error] [pid 18946:tid 19131] [client 34.94.72.59:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/i.php"] [unique_id "aqxcPjqiPMah0Tz_U1OHcAAAAUE"]
[Thu Sep 17 15:31:43.364042 2026] [security2:error] [pid 18946:tid 19133] [client 35.224.250.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recessionnews.org"] [uri "/index.php"] [unique_id "aqxcPDqiPMah0Tz_U1OHPwAAAUM"]
[Thu Sep 17 15:31:43.364182 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.72.59:55434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/pi.php"] [unique_id "aqxcPzqiPMah0Tz_U1OHewAAARo"]
[Thu Sep 17 15:31:43.672576 2026] [security2:error] [pid 20162:tid 20418] [client 34.94.72.59:55446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/pinfo.php"] [unique_id "aqxcP6-O_Kk7aqBvaiF06AAAAgw"]
[Thu Sep 17 15:31:43.854712 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.243.218:43776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/php-info.php"] [unique_id "aqxcPzqiPMah0Tz_U1OHhQAAAQ0"]
[Thu Sep 17 15:31:43.961283 2026] [security2:error] [pid 18946:tid 19170] [client 34.94.72.59:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/test.php"] [unique_id "aqxcPzqiPMah0Tz_U1OHiwAAAWg"]
[Thu Sep 17 15:31:44.137219 2026] [core:error] [pid 18946:tid 19166] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:44.137239 2026] [core:error] [pid 18946:tid 19166] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:44.324053 2026] [security2:error] [pid 20162:tid 20306] [client 34.154.243.218:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/phpversion.php"] [unique_id "aqxcQK-O_Kk7aqBvaiF06wAAAZw"]
[Thu Sep 17 15:31:44.403964 2026] [security2:error] [pid 18946:tid 19132] [client 79.116.89.151:58524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcQDqiPMah0Tz_U1OHnQAAAUI"]
[Thu Sep 17 15:31:44.404486 2026] [security2:error] [pid 18946:tid 19132] [client 79.116.89.151:58524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcQDqiPMah0Tz_U1OHnQAAAUI"]
[Thu Sep 17 15:31:44.516948 2026] [security2:error] [pid 18946:tid 19155] [client 34.94.72.59:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/p.php"] [unique_id "aqxcQDqiPMah0Tz_U1OHowAAAVk"]
[Thu Sep 17 15:31:44.602091 2026] [security2:error] [pid 18946:tid 19202] [client 85.204.70.90:51120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxcQDqiPMah0Tz_U1OHpwAAAYg"]
[Thu Sep 17 15:31:44.725974 2026] [security2:error] [pid 20162:tid 20297] [client 34.94.72.59:55486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/debug.php"] [unique_id "aqxcQK-O_Kk7aqBvaiF07gAAAZM"]
[Thu Sep 17 15:31:44.788175 2026] [security2:error] [pid 18946:tid 19177] [client 34.154.243.218:43794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/_phpinfo.php"] [unique_id "aqxcQDqiPMah0Tz_U1OHqAAAAW8"]
[Thu Sep 17 15:31:44.965142 2026] [security2:error] [pid 18946:tid 19150] [client 143.105.152.240:63996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcQDqiPMah0Tz_U1OHrgAAAVQ"]
[Thu Sep 17 15:31:44.981626 2026] [security2:error] [pid 18946:tid 19150] [client 143.105.152.240:63996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcQDqiPMah0Tz_U1OHrgAAAVQ"]
[Thu Sep 17 15:31:45.003544 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.72.59:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxcQTqiPMah0Tz_U1OHsAAAAUk"]
[Thu Sep 17 15:31:45.221819 2026] [security2:error] [pid 18946:tid 19121] [client 85.204.70.90:51132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesecondcycle.com"] [uri "/xmlrpc.php"] [unique_id "aqxcQTqiPMah0Tz_U1OHsgAAATc"]
[Thu Sep 17 15:31:45.262725 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.243.218:43804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/old_phpinfo.php"] [unique_id "aqxcQTqiPMah0Tz_U1OHswAAAS0"]
[Thu Sep 17 15:31:45.548315 2026] [security2:error] [pid 20162:tid 20342] [client 34.94.72.59:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/test/phpinfo.php"] [unique_id "aqxcQa-O_Kk7aqBvaiF07wAAAcA"]
[Thu Sep 17 15:31:45.749837 2026] [security2:error] [pid 20162:tid 20384] [client 34.154.243.218:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/server-info.php"] [unique_id "aqxcQa-O_Kk7aqBvaiF08AAAAeo"]
[Thu Sep 17 15:31:45.763443 2026] [authz_core:error] [pid 18946:tid 19093] [client 4.240.114.86:54837] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:31:45.772071 2026] [security2:error] [pid 20162:tid 20357] [client 34.94.72.59:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxcQa-O_Kk7aqBvaiF08gAAAc8"]
[Thu Sep 17 15:31:45.942295 2026] [security2:error] [pid 18946:tid 19119] [client 85.204.70.90:51148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxcQTqiPMah0Tz_U1OHvwAAATU"]
[Thu Sep 17 15:31:45.989585 2026] [security2:error] [pid 18946:tid 19134] [client 34.94.72.59:55546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/old/phpinfo.php"] [unique_id "aqxcQTqiPMah0Tz_U1OHwAAAAUQ"]
[Thu Sep 17 15:31:46.107953 2026] [security2:error] [pid 18946:tid 19199] [client 162.241.226.11:17614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "caninecompanionsltd.org"] [uri "/index.php"] [unique_id "aqxcQTqiPMah0Tz_U1OHuwAAAYU"]
[Thu Sep 17 15:31:46.223441 2026] [security2:error] [pid 20162:tid 20404] [client 34.154.243.218:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/server-status.php"] [unique_id "aqxcQq-O_Kk7aqBvaiF09gAAAf4"]
[Thu Sep 17 15:31:46.312831 2026] [security2:error] [pid 18946:tid 19187] [client 162.241.226.11:17630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "caninecompanionsltd.org"] [uri "/index.php"] [unique_id "aqxcQjqiPMah0Tz_U1OHwQAAAXk"]
[Thu Sep 17 15:31:46.324595 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.72.59:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcQjqiPMah0Tz_U1OHxQAAAWQ"]
[Thu Sep 17 15:31:46.493778 2026] [security2:error] [pid 20162:tid 20327] [client 85.204.70.90:51164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxcQq-O_Kk7aqBvaiF0-AAAAbE"]
[Thu Sep 17 15:31:46.581132 2026] [security2:error] [pid 18946:tid 19188] [client 92.72.180.217:64603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxcQjqiPMah0Tz_U1OHxgABel8"]
[Thu Sep 17 15:31:46.585378 2026] [security2:error] [pid 20162:tid 20371] [client 34.94.72.59:55564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/public/phpinfo.php"] [unique_id "aqxcQq-O_Kk7aqBvaiF0-QAAAd0"]
[Thu Sep 17 15:31:46.817014 2026] [cgid:error] [pid 20162:tid 20200] [remote 216.73.217.169:4648] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:31:46.924685 2026] [security2:error] [pid 18946:tid 19149] [client 74.7.175.167:51038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.nkb.wyz.mybluehost.me"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxcQjqiPMah0Tz_U1OHzwAAAVM"]
[Thu Sep 17 15:31:46.952501 2026] [core:error] [pid 20162:tid 20387] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:46.952524 2026] [core:error] [pid 20162:tid 20387] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:46.982121 2026] [security2:error] [pid 18946:tid 19151] [client 92.72.180.217:64603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxcQjqiPMah0Tz_U1OHzgABVVA"]
[Thu Sep 17 15:31:47.082771 2026] [security2:error] [pid 18946:tid 19192] [client 85.204.70.90:51176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxcQzqiPMah0Tz_U1OH0gAAAX4"]
[Thu Sep 17 15:31:47.304689 2026] [security2:error] [pid 20162:tid 20395] [client 34.94.72.59:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/php-info.php"] [unique_id "aqxcQ6-O_Kk7aqBvaiF1AwAAAfU"]
[Thu Sep 17 15:31:47.542279 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.72.59:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/phpversion.php"] [unique_id "aqxcQzqiPMah0Tz_U1OH1wAAAYc"]
[Thu Sep 17 15:31:47.544992 2026] [security2:error] [pid 18946:tid 19096] [client 103.61.184.148:61654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcQzqiPMah0Tz_U1OH2AAAAR4"]
[Thu Sep 17 15:31:47.545100 2026] [security2:error] [pid 18946:tid 19096] [client 103.61.184.148:61654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcQzqiPMah0Tz_U1OH2AAAAR4"]
[Thu Sep 17 15:31:47.653556 2026] [security2:error] [pid 20162:tid 20320] [client 85.204.70.90:51186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxcQ6-O_Kk7aqBvaiF1BgAAAao"]
[Thu Sep 17 15:31:47.714980 2026] [security2:error] [pid 18946:tid 19117] [client 34.94.72.59:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/_phpinfo.php"] [unique_id "aqxcQzqiPMah0Tz_U1OH2QAAATM"]
[Thu Sep 17 15:31:47.742722 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.243.218:32994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcQzqiPMah0Tz_U1OH2gAAAW0"]
[Thu Sep 17 15:31:47.967444 2026] [security2:error] [pid 20162:tid 20374] [client 34.94.72.59:34050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/old_phpinfo.php"] [unique_id "aqxcQ6-O_Kk7aqBvaiF1CQAAAeA"]
[Thu Sep 17 15:31:47.978413 2026] [security2:error] [pid 18946:tid 19137] [client 114.198.138.124:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcQzqiPMah0Tz_U1OH3wAAAUc"]
[Thu Sep 17 15:31:47.978490 2026] [security2:error] [pid 18946:tid 19137] [client 114.198.138.124:52348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcQzqiPMah0Tz_U1OH3wAAAUc"]
[Thu Sep 17 15:31:48.139900 2026] [security2:error] [pid 18946:tid 19176] [client 34.94.72.59:34066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/server-info.php"] [unique_id "aqxcRDqiPMah0Tz_U1OH4gAAAW4"]
[Thu Sep 17 15:31:48.217099 2026] [security2:error] [pid 20162:tid 20391] [client 34.154.243.218:32998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxcRK-O_Kk7aqBvaiF1CwAAAfE"]
[Thu Sep 17 15:31:48.234163 2026] [security2:error] [pid 20162:tid 20375] [client 85.204.70.90:51188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxcRK-O_Kk7aqBvaiF1DQAAAeE"]
[Thu Sep 17 15:31:48.519235 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.72.59:34068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/server-status.php"] [unique_id "aqxcRDqiPMah0Tz_U1OH5wAAAV4"]
[Thu Sep 17 15:31:48.685728 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.243.218:33002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxcRDqiPMah0Tz_U1OH6QAAATw"]
[Thu Sep 17 15:31:48.816454 2026] [security2:error] [pid 18946:tid 19182] [client 85.204.70.90:51192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxcRDqiPMah0Tz_U1OH7gAAAXQ"]
[Thu Sep 17 15:31:48.912758 2026] [core:error] [pid 18946:tid 19122] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:48.912777 2026] [core:error] [pid 18946:tid 19122] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:48.927160 2026] [security2:error] [pid 18946:tid 19118] [client 40.77.167.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overrock.uk"] [uri "/index.php"] [unique_id "aqxcRDqiPMah0Tz_U1OH4wAAATQ"]
[Thu Sep 17 15:31:48.954844 2026] [authz_core:error] [pid 18946:tid 19150] [client 169.58.197.251:51349] AH01630: client denied by server configuration: /home2/sfvhbtor/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:31:49.177304 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.243.218:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcRTqiPMah0Tz_U1OH9wAAAYQ"]
[Thu Sep 17 15:31:49.235159 2026] [core:error] [pid 18946:tid 19173] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:49.235182 2026] [core:error] [pid 18946:tid 19173] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:49.296484 2026] [security2:error] [pid 18946:tid 19180] [client 168.181.181.113:8897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcRTqiPMah0Tz_U1OH-QABcng"]
[Thu Sep 17 15:31:49.357409 2026] [security2:error] [pid 18946:tid 19146] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxcRTqiPMah0Tz_U1OH-gAAAVA"]
[Thu Sep 17 15:31:49.402609 2026] [security2:error] [pid 18946:tid 19164] [client 85.204.70.90:51200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxcRTqiPMah0Tz_U1OH_wAAAWI"]
[Thu Sep 17 15:31:49.471067 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.72.59:34110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcRTqiPMah0Tz_U1OIAgAAAR8"]
[Thu Sep 17 15:31:49.645544 2026] [security2:error] [pid 20162:tid 20377] [client 34.154.243.218:33028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcRa-O_Kk7aqBvaiF1HgAAAeM"]
[Thu Sep 17 15:31:49.755241 2026] [security2:error] [pid 18946:tid 19190] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxcRTqiPMah0Tz_U1OIBQAAAXw"]
[Thu Sep 17 15:31:49.778223 2026] [security2:error] [pid 18946:tid 19183] [client 34.94.72.59:34116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxcRTqiPMah0Tz_U1OIBwAAAXU"]
[Thu Sep 17 15:31:49.973126 2026] [security2:error] [pid 20162:tid 20378] [client 85.204.70.90:51212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxcRa-O_Kk7aqBvaiF1HwAAAeQ"]
[Thu Sep 17 15:31:50.124927 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.243.218:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcRjqiPMah0Tz_U1OIDAAAAYk"]
[Thu Sep 17 15:31:50.179923 2026] [security2:error] [pid 20162:tid 20310] [client 34.94.72.59:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxcRq-O_Kk7aqBvaiF1IAAAAaA"]
[Thu Sep 17 15:31:50.394999 2026] [security2:error] [pid 18946:tid 19172] [client 34.94.72.59:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcRjqiPMah0Tz_U1OIDwAAAWo"]
[Thu Sep 17 15:31:50.523177 2026] [security2:error] [pid 18946:tid 19096] [client 85.204.70.90:51222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxcRjqiPMah0Tz_U1OIEAAAAR4"]
[Thu Sep 17 15:31:50.587975 2026] [security2:error] [pid 18946:tid 19117] [client 34.154.243.218:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxcRjqiPMah0Tz_U1OIEQAAATM"]
[Thu Sep 17 15:31:50.734934 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.72.59:34152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcRjqiPMah0Tz_U1OIEgAAAVc"]
[Thu Sep 17 15:31:50.814245 2026] [security2:error] [pid 18946:tid 19127] [client 40.81.232.68:53808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxcRjqiPMah0Tz_U1OIFAAAAT0"], referer: binance.com
[Thu Sep 17 15:31:50.906587 2026] [security2:error] [pid 18946:tid 19137] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxcRjqiPMah0Tz_U1OIEwAAAUc"]
[Thu Sep 17 15:31:51.003724 2026] [security2:error] [pid 18946:tid 19113] [client 34.94.72.59:34164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcRzqiPMah0Tz_U1OIGwAAAS8"]
[Thu Sep 17 15:31:51.045868 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.243.218:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/phpinfo.php.old"] [unique_id "aqxcRzqiPMah0Tz_U1OIHAAAAUM"]
[Thu Sep 17 15:31:51.087216 2026] [security2:error] [pid 18946:tid 19105] [client 85.204.70.90:51224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxcRzqiPMah0Tz_U1OIHQAAASc"]
[Thu Sep 17 15:31:51.332416 2026] [security2:error] [pid 18946:tid 19177] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxcRzqiPMah0Tz_U1OIHgAAAW8"]
[Thu Sep 17 15:31:51.337586 2026] [security2:error] [pid 18946:tid 19163] [client 34.94.72.59:34166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxcRzqiPMah0Tz_U1OIIAAAAWE"]
[Thu Sep 17 15:31:51.518010 2026] [security2:error] [pid 20162:tid 20417] [client 34.154.243.218:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/phpinfo.php~"] [unique_id "aqxcR6-O_Kk7aqBvaiF1KQAAAgs"]
[Thu Sep 17 15:31:51.601723 2026] [security2:error] [pid 18946:tid 19111] [client 52.167.144.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxcRzqiPMah0Tz_U1OIJAAAAS0"]
[Thu Sep 17 15:31:51.652583 2026] [security2:error] [pid 18946:tid 19131] [client 34.94.72.59:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/phpinfo.php.old"] [unique_id "aqxcRzqiPMah0Tz_U1OIJQAAAUE"]
[Thu Sep 17 15:31:51.653179 2026] [security2:error] [pid 18946:tid 19196] [client 85.204.70.90:51238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxcRzqiPMah0Tz_U1OIJgAAAYI"]
[Thu Sep 17 15:31:51.846617 2026] [security2:error] [pid 18946:tid 19089] [client 177.220.180.81:7349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcRzqiPMah0Tz_U1OIJwABF3c"]
[Thu Sep 17 15:31:51.994670 2026] [security2:error] [pid 18946:tid 19156] [client 34.154.243.218:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/info.php.bak"] [unique_id "aqxcRzqiPMah0Tz_U1OILAAAAVo"]
[Thu Sep 17 15:31:52.031540 2026] [security2:error] [pid 20162:tid 20313] [client 34.94.72.59:34180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/phpinfo.php~"] [unique_id "aqxcSK-O_Kk7aqBvaiF1KgAAAaM"]
[Thu Sep 17 15:31:52.227441 2026] [security2:error] [pid 18946:tid 19124] [client 85.204.70.90:51240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thesecondcycle.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxcSDqiPMah0Tz_U1OIMQAAATo"]
[Thu Sep 17 15:31:52.341227 2026] [security2:error] [pid 18946:tid 19180] [client 34.94.72.59:34190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/info.php.bak"] [unique_id "aqxcSDqiPMah0Tz_U1OIMgAAAXI"]
[Thu Sep 17 15:31:52.479833 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.243.218:33070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/phpinfo.php.save"] [unique_id "aqxcSDqiPMah0Tz_U1OINgAAAUQ"]
[Thu Sep 17 15:31:52.687089 2026] [security2:error] [pid 18946:tid 19161] [client 34.94.72.59:34204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/phpinfo.php.save"] [unique_id "aqxcSDqiPMah0Tz_U1OINwAAAV8"]
[Thu Sep 17 15:31:52.830554 2026] [security2:error] [pid 18946:tid 19181] [client 34.94.72.59:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxcSDqiPMah0Tz_U1OIOwAAAXM"]
[Thu Sep 17 15:31:52.917099 2026] [authz_core:error] [pid 18946:tid 19191] [client 4.240.114.86:60426] AH01630: client denied by server configuration: /home2/alanacki/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:31:52.939239 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.243.218:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxcSK-O_Kk7aqBvaiF1MwAAAfQ"]
[Thu Sep 17 15:31:53.049621 2026] [security2:error] [pid 20162:tid 20397] [client 34.94.72.59:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxcSa-O_Kk7aqBvaiF1NQAAAfc"]
[Thu Sep 17 15:31:53.332944 2026] [security2:error] [pid 20162:tid 20295] [client 34.94.72.59:34230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxcSa-O_Kk7aqBvaiF1NwAAAZE"]
[Thu Sep 17 15:31:53.410600 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.243.218:33082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxcSTqiPMah0Tz_U1OIRQAAAVw"]
[Thu Sep 17 15:31:53.572613 2026] [security2:error] [pid 20162:tid 20410] [client 34.94.72.59:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxcSa-O_Kk7aqBvaiF1OgAAAgQ"]
[Thu Sep 17 15:31:53.667535 2026] [security2:error] [pid 20162:tid 20412] [client 136.158.61.34:50076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcSa-O_Kk7aqBvaiF1OwAAAgY"]
[Thu Sep 17 15:31:53.667679 2026] [security2:error] [pid 20162:tid 20412] [client 136.158.61.34:50076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcSa-O_Kk7aqBvaiF1OwAAAgY"]
[Thu Sep 17 15:31:53.888353 2026] [security2:error] [pid 20162:tid 20401] [client 34.154.243.218:33090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxcSa-O_Kk7aqBvaiF1PQAAAfs"]
[Thu Sep 17 15:31:53.954945 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.72.59:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxcSTqiPMah0Tz_U1OISQAAASE"]
[Thu Sep 17 15:31:54.267042 2026] [security2:error] [pid 18946:tid 19154] [client 45.115.26.203:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/i.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIUgAAAVg"]
[Thu Sep 17 15:31:54.267064 2026] [security2:error] [pid 20162:tid 20341] [client 45.115.26.203:60018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/php_info.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1RQAAAb8"]
[Thu Sep 17 15:31:54.267110 2026] [security2:error] [pid 20162:tid 20335] [client 45.115.26.203:60026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/_phpinfo.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1RgAAAbk"]
[Thu Sep 17 15:31:54.267122 2026] [security2:error] [pid 18946:tid 19127] [client 45.115.26.203:59720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env"] [unique_id "aqxcSjqiPMah0Tz_U1OITQAAAT0"]
[Thu Sep 17 15:31:54.267370 2026] [security2:error] [pid 20162:tid 20294] [client 45.115.26.203:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/info.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1SQAAAZA"]
[Thu Sep 17 15:31:54.267582 2026] [security2:error] [pid 20162:tid 20302] [client 45.115.26.203:59844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/backend/.env"] [unique_id "aqxcSq-O_Kk7aqBvaiF1SAAAAZg"]
[Thu Sep 17 15:31:54.267589 2026] [security2:error] [pid 18946:tid 19169] [client 45.115.26.203:59874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/app/.env"] [unique_id "aqxcSjqiPMah0Tz_U1OIVAAAAWc"]
[Thu Sep 17 15:31:54.267714 2026] [security2:error] [pid 20162:tid 20413] [client 45.115.26.203:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/test.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1SwAAAgc"]
[Thu Sep 17 15:31:54.267952 2026] [security2:error] [pid 20162:tid 20420] [client 45.115.26.203:59800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.old"] [unique_id "aqxcSq-O_Kk7aqBvaiF1RwAAAg4"]
[Thu Sep 17 15:31:54.268318 2026] [security2:error] [pid 18946:tid 19133] [client 45.115.26.203:59888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/src/.env"] [unique_id "aqxcSjqiPMah0Tz_U1OIWAAAAUM"]
[Thu Sep 17 15:31:54.269606 2026] [security2:error] [pid 18946:tid 19082] [client 45.115.26.203:60038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/php-info.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIXQAAARA"]
[Thu Sep 17 15:31:54.272056 2026] [security2:error] [pid 18946:tid 19108] [client 45.115.26.203:59832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.swp"] [unique_id "aqxcSjqiPMah0Tz_U1OIXgAAASo"]
[Thu Sep 17 15:31:54.272190 2026] [security2:error] [pid 18946:tid 19116] [client 45.115.26.203:59816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env~"] [unique_id "aqxcSjqiPMah0Tz_U1OIXwAAATI"]
[Thu Sep 17 15:31:54.274767 2026] [security2:error] [pid 18946:tid 19177] [client 45.115.26.203:59774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.backup"] [unique_id "aqxcSjqiPMah0Tz_U1OIaAAAAW8"]
[Thu Sep 17 15:31:54.275349 2026] [security2:error] [pid 18946:tid 19200] [client 45.115.26.203:59980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/phpinfo.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIagAAAYY"]
[Thu Sep 17 15:31:54.281078 2026] [security2:error] [pid 18946:tid 19160] [client 45.115.26.203:59698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env"] [unique_id "aqxcSjqiPMah0Tz_U1OIbAAAAV4"]
[Thu Sep 17 15:31:54.281114 2026] [security2:error] [pid 20162:tid 20299] [client 45.115.26.203:60044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/pi.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1WAAAAZU"]
[Thu Sep 17 15:31:54.281481 2026] [security2:error] [pid 20162:tid 20349] [client 45.115.26.203:59858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/api/.env"] [unique_id "aqxcSq-O_Kk7aqBvaiF1WQAAAcc"]
[Thu Sep 17 15:31:54.281739 2026] [security2:error] [pid 20162:tid 20323] [client 45.115.26.203:59788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.bak"] [unique_id "aqxcSq-O_Kk7aqBvaiF1WgAAAa0"]
[Thu Sep 17 15:31:54.344003 2026] [security2:error] [pid 18946:tid 19085] [client 34.94.72.59:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/www/phpinfo.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIhAAAARM"]
[Thu Sep 17 15:31:54.347135 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.243.218:33096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIhQAAATc"]
[Thu Sep 17 15:31:54.502931 2026] [security2:error] [pid 18946:tid 19156] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIeAAAAVo"]
[Thu Sep 17 15:31:54.545838 2026] [security2:error] [pid 18946:tid 19103] [client 34.94.72.59:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIiAAAASU"]
[Thu Sep 17 15:31:54.694937 2026] [access_compat:error] [pid 18946:tid 19141] [client 45.115.26.203:60060] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Thu Sep 17 15:31:54.718134 2026] [security2:error] [pid 18946:tid 19181] [client 34.94.72.59:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIiwAAAXM"]
[Thu Sep 17 15:31:54.736057 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.154.225:32782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.wholeworkplace.com"] [uri "/"] [unique_id "aqxcSjqiPMah0Tz_U1OIjAAAAXw"]
[Thu Sep 17 15:31:54.813014 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.243.218:33106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIjQAAATk"]
[Thu Sep 17 15:31:55.002171 2026] [security2:error] [pid 20162:tid 20418] [client 34.94.72.59:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/site/phpinfo.php"] [unique_id "aqxcS6-O_Kk7aqBvaiF1aAAAAgw"]
[Thu Sep 17 15:31:55.258985 2026] [security2:error] [pid 18946:tid 19198] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIdQAAAYQ"]
[Thu Sep 17 15:31:55.260029 2026] [security2:error] [pid 18946:tid 19179] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIeQAAAXE"]
[Thu Sep 17 15:31:55.284545 2026] [security2:error] [pid 18946:tid 19162] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIdwAAAWA"]
[Thu Sep 17 15:31:55.287502 2026] [security2:error] [pid 20162:tid 20383] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1XAAAAek"]
[Thu Sep 17 15:31:55.296772 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.243.218:33112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/www/phpinfo.php"] [unique_id "aqxcSzqiPMah0Tz_U1OIlgAAAU0"]
[Thu Sep 17 15:31:55.297263 2026] [security2:error] [pid 20162:tid 20406] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1XgAAAgA"]
[Thu Sep 17 15:31:55.299079 2026] [security2:error] [pid 20162:tid 20382] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1YAAAAeg"]
[Thu Sep 17 15:31:55.312335 2026] [security2:error] [pid 18946:tid 19150] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIfAAAAVQ"]
[Thu Sep 17 15:31:55.312335 2026] [security2:error] [pid 18946:tid 19101] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIegAAASM"]
[Thu Sep 17 15:31:55.329686 2026] [security2:error] [pid 18946:tid 19091] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIfgAAARk"]
[Thu Sep 17 15:31:55.335213 2026] [security2:error] [pid 20162:tid 20354] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1XwAAAcw"]
[Thu Sep 17 15:31:55.335424 2026] [security2:error] [pid 18946:tid 19115] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIfwAAATE"]
[Thu Sep 17 15:31:55.337910 2026] [security2:error] [pid 18946:tid 19096] [client 34.94.72.59:34292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxcSzqiPMah0Tz_U1OImQAAAR4"]
[Thu Sep 17 15:31:55.357449 2026] [security2:error] [pid 18946:tid 19128] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIfQAAAT4"]
[Thu Sep 17 15:31:55.357496 2026] [security2:error] [pid 18946:tid 19093] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIgQAAARs"]
[Thu Sep 17 15:31:55.358961 2026] [security2:error] [pid 18946:tid 19112] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIdgAAAS4"]
[Thu Sep 17 15:31:55.359916 2026] [security2:error] [pid 18946:tid 19119] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSjqiPMah0Tz_U1OIewAAATU"]
[Thu Sep 17 15:31:55.360840 2026] [security2:error] [pid 20162:tid 20324] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxcSq-O_Kk7aqBvaiF1YQAAAa4"]
[Thu Sep 17 15:31:55.434499 2026] [security2:error] [pid 20162:tid 20398] [client 34.166.154.225:32794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.wholeworkplace.com"] [uri "/"] [unique_id "aqxcS6-O_Kk7aqBvaiF1awAAAfg"]
[Thu Sep 17 15:31:55.574720 2026] [security2:error] [pid 18946:tid 19094] [client 143.105.152.240:53155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcSzqiPMah0Tz_U1OInQAAARw"]
[Thu Sep 17 15:31:55.574833 2026] [security2:error] [pid 18946:tid 19094] [client 143.105.152.240:53155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcSzqiPMah0Tz_U1OInQAAARw"]
[Thu Sep 17 15:31:55.680496 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.72.59:34308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcSzqiPMah0Tz_U1OIngAAASY"]
[Thu Sep 17 15:31:55.759088 2026] [security2:error] [pid 18946:tid 19165] [client 34.154.243.218:33126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcSzqiPMah0Tz_U1OInwAAAWM"]
[Thu Sep 17 15:31:56.125105 2026] [security2:error] [pid 18946:tid 19161] [client 34.166.154.225:32802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.wholeworkplace.com"] [uri "/"] [unique_id "aqxcTDqiPMah0Tz_U1OIqQAAAV8"]
[Thu Sep 17 15:31:56.161980 2026] [security2:error] [pid 20162:tid 20345] [client 34.94.72.59:34320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcTK-O_Kk7aqBvaiF1cQAAAcM"]
[Thu Sep 17 15:31:56.224183 2026] [security2:error] [pid 20162:tid 20371] [client 34.154.243.218:50020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcTK-O_Kk7aqBvaiF1cgAAAd0"]
[Thu Sep 17 15:31:56.303367 2026] [security2:error] [pid 18946:tid 19125] [client 2.51.243.96:53919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcTDqiPMah0Tz_U1OIqgABOwI"]
[Thu Sep 17 15:31:56.346212 2026] [security2:error] [pid 20162:tid 20416] [client 40.81.232.68:51698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxcTK-O_Kk7aqBvaiF1dAAAAgo"], referer: binance.com
[Thu Sep 17 15:31:56.515718 2026] [security2:error] [pid 18946:tid 19158] [client 34.94.72.59:34334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/core/phpinfo.php"] [unique_id "aqxcTDqiPMah0Tz_U1OItAAAAVw"]
[Thu Sep 17 15:31:56.561057 2026] [security2:error] [pid 18946:tid 19191] [client 3.82.141.143:25872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxcTDqiPMah0Tz_U1OIsAAAAX0"]
[Thu Sep 17 15:31:56.682048 2026] [security2:error] [pid 18946:tid 19098] [client 34.154.243.218:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/site/phpinfo.php"] [unique_id "aqxcTDqiPMah0Tz_U1OItgAAASA"]
[Thu Sep 17 15:31:56.841422 2026] [security2:error] [pid 20162:tid 20309] [client 34.94.72.59:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.72.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.threadalittlelight.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxcTK-O_Kk7aqBvaiF1egAAAZ8"]
[Thu Sep 17 15:31:57.059351 2026] [security2:error] [pid 18946:tid 19101] [client 34.166.154.225:32808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.wholeworkplace.com"] [uri "/"] [unique_id "aqxcTTqiPMah0Tz_U1OIvgAAASM"]
[Thu Sep 17 15:31:57.106321 2026] [core:error] [pid 18946:tid 19113] [client 34.94.72.59:34350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.106341 2026] [core:error] [pid 18946:tid 19113] [client 34.94.72.59:34350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.170850 2026] [security2:error] [pid 18946:tid 19110] [client 34.154.243.218:50034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxcTTqiPMah0Tz_U1OIwAAAASw"]
[Thu Sep 17 15:31:57.271754 2026] [core:error] [pid 18946:tid 19182] [client 34.94.72.59:34364] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.271774 2026] [core:error] [pid 18946:tid 19182] [client 34.94.72.59:34364] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.421526 2026] [security2:error] [pid 20162:tid 20358] [client 4.240.114.86:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxcTa-O_Kk7aqBvaiF1fgAAAdA"], referer: binance.com
[Thu Sep 17 15:31:57.458029 2026] [core:error] [pid 18946:tid 19111] [client 34.94.72.59:34374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.458049 2026] [core:error] [pid 18946:tid 19111] [client 34.94.72.59:34374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.631887 2026] [security2:error] [pid 20162:tid 20343] [client 34.154.243.218:50036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcTa-O_Kk7aqBvaiF1gQAAAcE"]
[Thu Sep 17 15:31:57.662781 2026] [core:error] [pid 20162:tid 20364] [client 34.94.72.59:34376] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.662798 2026] [core:error] [pid 20162:tid 20364] [client 34.94.72.59:34376] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:57.720686 2026] [security2:error] [pid 20162:tid 20300] [client 79.116.89.151:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcTa-O_Kk7aqBvaiF1iAAAAZY"]
[Thu Sep 17 15:31:57.720806 2026] [security2:error] [pid 20162:tid 20300] [client 79.116.89.151:59127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcTa-O_Kk7aqBvaiF1iAAAAZY"]
[Thu Sep 17 15:31:57.782157 2026] [access_compat:error] [pid 18946:tid 19112] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/lets-travel-10-welcome-to-switzerland
[Thu Sep 17 15:31:58.111106 2026] [security2:error] [pid 20162:tid 20326] [client 34.154.243.218:50046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcTq-O_Kk7aqBvaiF1jQAAAbA"]
[Thu Sep 17 15:31:58.133963 2026] [core:error] [pid 20162:tid 20366] [client 34.94.72.59:44650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:58.133988 2026] [core:error] [pid 20162:tid 20366] [client 34.94.72.59:44650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:58.193530 2026] [security2:error] [pid 20162:tid 20402] [client 52.28.162.93:24760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxcTq-O_Kk7aqBvaiF1jwAAAfw"], referer: https://faewave.com
[Thu Sep 17 15:31:58.328703 2026] [core:error] [pid 20162:tid 20303] [client 34.94.72.59:44658] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:58.328724 2026] [core:error] [pid 20162:tid 20303] [client 34.94.72.59:44658] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:58.396566 2026] [security2:error] [pid 20162:tid 20331] [client 103.61.184.148:62196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcTq-O_Kk7aqBvaiF1kgAAAbU"]
[Thu Sep 17 15:31:58.396686 2026] [security2:error] [pid 20162:tid 20331] [client 103.61.184.148:62196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcTq-O_Kk7aqBvaiF1kgAAAbU"]
[Thu Sep 17 15:31:58.474851 2026] [security2:error] [pid 20162:tid 20359] [client 114.198.138.124:53005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcTq-O_Kk7aqBvaiF1lAAAAdE"]
[Thu Sep 17 15:31:58.474967 2026] [security2:error] [pid 20162:tid 20359] [client 114.198.138.124:53005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcTq-O_Kk7aqBvaiF1lAAAAdE"]
[Thu Sep 17 15:31:58.587485 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.243.218:50060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/core/phpinfo.php"] [unique_id "aqxcTjqiPMah0Tz_U1OI2QAAAYg"]
[Thu Sep 17 15:31:58.614935 2026] [core:error] [pid 18946:tid 19133] [client 34.94.72.59:44664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:58.614957 2026] [core:error] [pid 18946:tid 19133] [client 34.94.72.59:44664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:58.730185 2026] [security2:error] [pid 20162:tid 20310] [client 187.103.1.49:34532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcTq-O_Kk7aqBvaiF1lgABoCU"]
[Thu Sep 17 15:31:58.906794 2026] [core:error] [pid 18946:tid 19140] [client 34.94.72.59:44668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:58.906814 2026] [core:error] [pid 18946:tid 19140] [client 34.94.72.59:44668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.073707 2026] [security2:error] [pid 20162:tid 20407] [client 34.154.243.218:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.243.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bigsisterteams.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxcT6-O_Kk7aqBvaiF1mgAAAgE"]
[Thu Sep 17 15:31:59.135936 2026] [security2:error] [pid 18946:tid 19156] [client 40.81.232.68:54982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxcTzqiPMah0Tz_U1OI6gAAAVo"], referer: binance.com
[Thu Sep 17 15:31:59.180213 2026] [core:error] [pid 18946:tid 19189] [client 34.94.72.59:44670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.180237 2026] [core:error] [pid 18946:tid 19189] [client 34.94.72.59:44670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.513927 2026] [core:error] [pid 20162:tid 20406] [client 34.94.72.59:44682] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.513954 2026] [core:error] [pid 20162:tid 20406] [client 34.94.72.59:44682] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.729159 2026] [core:error] [pid 18946:tid 19155] [client 34.94.72.59:44686] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.729180 2026] [core:error] [pid 18946:tid 19155] [client 34.94.72.59:44686] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.893087 2026] [core:error] [pid 18946:tid 19143] [client 34.94.72.59:44700] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:31:59.893104 2026] [core:error] [pid 18946:tid 19143] [client 34.94.72.59:44700] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:00.113305 2026] [core:error] [pid 18946:tid 19092] [client 34.94.72.59:44706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:00.113328 2026] [core:error] [pid 18946:tid 19092] [client 34.94.72.59:44706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:00.507786 2026] [core:error] [pid 20162:tid 20417] [client 34.94.72.59:44722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:00.507808 2026] [core:error] [pid 20162:tid 20417] [client 34.94.72.59:44722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:00.972969 2026] [core:error] [pid 18946:tid 19160] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:00.972988 2026] [core:error] [pid 18946:tid 19160] [client 34.94.72.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:02.095812 2026] [core:error] [pid 18946:tid 19180] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:02.095836 2026] [core:error] [pid 18946:tid 19180] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:02.237780 2026] [core:error] [pid 18946:tid 19190] [client 34.94.39.26:58668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:02.237814 2026] [core:error] [pid 18946:tid 19190] [client 34.94.39.26:58668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:02.423207 2026] [core:error] [pid 18946:tid 19123] [client 34.94.39.26:58682] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:02.423234 2026] [core:error] [pid 18946:tid 19123] [client 34.94.39.26:58682] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:03.123693 2026] [core:error] [pid 20162:tid 20299] [client 34.94.39.26:58698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:03.123714 2026] [core:error] [pid 20162:tid 20299] [client 34.94.39.26:58698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:03.188770 2026] [security2:error] [pid 20162:tid 20402] [client 40.81.232.68:51219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxcU6-O_Kk7aqBvaiF12QAAAfw"], referer: binance.com
[Thu Sep 17 15:32:03.240084 2026] [security2:error] [pid 18946:tid 19198] [client 129.212.238.116:33110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcUjqiPMah0Tz_U1OJOAABhBc"], referer: http://www.beaglerescueleague.org/backup/
[Thu Sep 17 15:32:03.378679 2026] [core:error] [pid 18946:tid 19104] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:03.378815 2026] [core:error] [pid 18946:tid 19104] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:03.605954 2026] [core:error] [pid 18946:tid 19147] [client 34.94.39.26:58720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:03.605977 2026] [core:error] [pid 18946:tid 19147] [client 34.94.39.26:58720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:03.951267 2026] [security2:error] [pid 20162:tid 20311] [client 129.212.238.116:33124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcU6-O_Kk7aqBvaiF14QABoQY"], referer: https://www.beaglerescueleague.org/backup/
[Thu Sep 17 15:32:04.037905 2026] [security2:error] [pid 20162:tid 20336] [client 34.94.39.26:58732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxcVK-O_Kk7aqBvaiF15QAAAbo"]
[Thu Sep 17 15:32:04.130288 2026] [core:error] [pid 18946:tid 19154] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:04.130308 2026] [core:error] [pid 18946:tid 19154] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:04.421145 2026] [core:error] [pid 18946:tid 19088] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:04.421162 2026] [core:error] [pid 18946:tid 19088] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:04.461137 2026] [security2:error] [pid 18946:tid 19157] [client 129.212.238.116:33110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVDqiPMah0Tz_U1OJYAABWxs"], referer: http://www.beaglerescueleague.org/wp/
[Thu Sep 17 15:32:04.724289 2026] [security2:error] [pid 20162:tid 20324] [client 129.212.238.116:33124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVK-O_Kk7aqBvaiF18gABrjs"], referer: https://www.beaglerescueleague.org/wp/
[Thu Sep 17 15:32:04.779629 2026] [core:error] [pid 18946:tid 19197] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:04.779658 2026] [core:error] [pid 18946:tid 19197] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.075744 2026] [core:error] [pid 18946:tid 19156] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.075765 2026] [core:error] [pid 18946:tid 19156] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.249154 2026] [security2:error] [pid 18946:tid 19138] [client 129.212.238.116:33110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVTqiPMah0Tz_U1OJeQABSBE"], referer: http://www.beaglerescueleague.org/new/
[Thu Sep 17 15:32:05.271951 2026] [security2:error] [pid 18946:tid 19094] [client 79.116.89.151:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcVTqiPMah0Tz_U1OJfQAAARw"]
[Thu Sep 17 15:32:05.272046 2026] [security2:error] [pid 18946:tid 19094] [client 79.116.89.151:59559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcVTqiPMah0Tz_U1OJfQAAARw"]
[Thu Sep 17 15:32:05.519601 2026] [core:error] [pid 20162:tid 20373] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.519621 2026] [core:error] [pid 20162:tid 20373] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.522298 2026] [security2:error] [pid 20162:tid 20315] [client 129.212.238.116:33124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVa-O_Kk7aqBvaiF2AQABpTY"], referer: https://www.beaglerescueleague.org/new/
[Thu Sep 17 15:32:05.744439 2026] [core:error] [pid 20162:tid 20412] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.744459 2026] [core:error] [pid 20162:tid 20412] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.993878 2026] [core:error] [pid 18946:tid 19182] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:05.993901 2026] [core:error] [pid 18946:tid 19182] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:06.004092 2026] [security2:error] [pid 20162:tid 20400] [client 136.158.61.34:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcVa-O_Kk7aqBvaiF2EQAAAfo"]
[Thu Sep 17 15:32:06.004248 2026] [security2:error] [pid 20162:tid 20400] [client 136.158.61.34:51087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcVa-O_Kk7aqBvaiF2EQAAAfo"]
[Thu Sep 17 15:32:06.035131 2026] [security2:error] [pid 18946:tid 19137] [client 129.212.238.116:33110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVTqiPMah0Tz_U1OJkQABRx8"], referer: http://www.beaglerescueleague.org/wordpress/
[Thu Sep 17 15:32:06.138451 2026] [core:error] [pid 18946:tid 19196] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:06.138470 2026] [core:error] [pid 18946:tid 19196] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:06.141008 2026] [security2:error] [pid 18946:tid 19192] [client 143.105.152.240:30443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcVjqiPMah0Tz_U1OJmgAAAX4"]
[Thu Sep 17 15:32:06.151308 2026] [security2:error] [pid 18946:tid 19192] [client 143.105.152.240:30443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcVjqiPMah0Tz_U1OJmgAAAX4"]
[Thu Sep 17 15:32:06.308032 2026] [security2:error] [pid 20162:tid 20392] [client 129.212.238.116:33124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVq-O_Kk7aqBvaiF2FAAB8kE"], referer: https://www.beaglerescueleague.org/wordpress/
[Thu Sep 17 15:32:06.332592 2026] [security2:error] [pid 18946:tid 19111] [client 34.94.39.26:58794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxcVjqiPMah0Tz_U1OJnAAAAS0"]
[Thu Sep 17 15:32:06.335333 2026] [cgid:error] [pid 18946:tid 19080] [client 221.149.119.65:23583] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/wordpress
[Thu Sep 17 15:32:06.409084 2026] [security2:error] [pid 18946:tid 19082] [client 34.94.39.26:58794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxcVjqiPMah0Tz_U1OJoAAAARA"]
[Thu Sep 17 15:32:06.570108 2026] [core:error] [pid 20162:tid 20321] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:06.570131 2026] [core:error] [pid 20162:tid 20321] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:06.671966 2026] [autoindex:error] [pid 18946:tid 19092] [client 4.240.114.86:53514] AH01276: Cannot serve directory /home1/awesone8/public_html/bethrimmels/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:32:06.807288 2026] [security2:error] [pid 18946:tid 19153] [client 40.81.232.68:64507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxcVjqiPMah0Tz_U1OJqgAAAVc"], referer: binance.com
[Thu Sep 17 15:32:06.817418 2026] [security2:error] [pid 18946:tid 19093] [client 129.212.238.116:33110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVjqiPMah0Tz_U1OJqQABG3k"], referer: http://www.beaglerescueleague.org/old/
[Thu Sep 17 15:32:06.853513 2026] [core:error] [pid 20162:tid 20298] [client 34.166.157.71:58848] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:06.853533 2026] [core:error] [pid 20162:tid 20298] [client 34.166.157.71:58848] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:06.901634 2026] [security2:error] [pid 18946:tid 19090] [client 34.94.39.26:58808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxcVjqiPMah0Tz_U1OJrQAAARg"]
[Thu Sep 17 15:32:07.081306 2026] [security2:error] [pid 20162:tid 20338] [client 129.212.238.116:33124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcV6-O_Kk7aqBvaiF2JAABvEI"], referer: https://www.beaglerescueleague.org/old/
[Thu Sep 17 15:32:07.115219 2026] [core:error] [pid 20162:tid 20411] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.115237 2026] [core:error] [pid 20162:tid 20411] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.367672 2026] [security2:error] [pid 18946:tid 19189] [client 35.252.83.108:52482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/.env"] [unique_id "aqxcVzqiPMah0Tz_U1OJvgAAAXs"]
[Thu Sep 17 15:32:07.378808 2026] [core:error] [pid 18946:tid 19193] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.378827 2026] [core:error] [pid 18946:tid 19193] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.504131 2026] [core:error] [pid 18946:tid 19194] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.504153 2026] [core:error] [pid 18946:tid 19194] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.541482 2026] [core:error] [pid 18946:tid 19086] [client 34.166.157.71:33892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.541509 2026] [core:error] [pid 18946:tid 19086] [client 34.166.157.71:33892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.586852 2026] [security2:error] [pid 18946:tid 19149] [client 129.212.238.116:33110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcVzqiPMah0Tz_U1OJxgABUxo"], referer: http://www.beaglerescueleague.org/blog/
[Thu Sep 17 15:32:07.626104 2026] [core:error] [pid 18946:tid 19100] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.626120 2026] [core:error] [pid 18946:tid 19100] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.694871 2026] [core:error] [pid 18946:tid 19139] [client 34.94.39.26:58868] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.694891 2026] [core:error] [pid 18946:tid 19139] [client 34.94.39.26:58868] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.851665 2026] [security2:error] [pid 20162:tid 20361] [client 129.212.238.116:33124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "beaglerescueleague.org"] [uri "/index.php"] [unique_id "aqxcV6-O_Kk7aqBvaiF2LQAB00M"], referer: https://www.beaglerescueleague.org/blog/
[Thu Sep 17 15:32:07.857216 2026] [core:error] [pid 20162:tid 20339] [client 34.94.39.26:58882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:07.857238 2026] [core:error] [pid 20162:tid 20339] [client 34.94.39.26:58882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.005197 2026] [core:error] [pid 18946:tid 19201] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.005225 2026] [core:error] [pid 18946:tid 19201] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.055579 2026] [core:error] [pid 18946:tid 19101] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.055599 2026] [core:error] [pid 18946:tid 19101] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.226192 2026] [core:error] [pid 18946:tid 19191] [client 34.166.157.71:33908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.226215 2026] [core:error] [pid 18946:tid 19191] [client 34.166.157.71:33908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.252005 2026] [core:error] [pid 20162:tid 20342] [client 34.94.39.26:58890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.252023 2026] [core:error] [pid 20162:tid 20342] [client 34.94.39.26:58890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.400920 2026] [core:error] [pid 18946:tid 19131] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.400938 2026] [core:error] [pid 18946:tid 19131] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.504743 2026] [core:error] [pid 18946:tid 19192] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.505368 2026] [core:error] [pid 18946:tid 19192] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.612681 2026] [core:error] [pid 20162:tid 20355] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.612699 2026] [core:error] [pid 20162:tid 20355] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.824789 2026] [core:error] [pid 18946:tid 19115] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.824809 2026] [core:error] [pid 18946:tid 19115] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.972071 2026] [core:error] [pid 18946:tid 19185] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.972090 2026] [core:error] [pid 18946:tid 19185] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.983327 2026] [core:error] [pid 18946:tid 19103] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:08.983348 2026] [core:error] [pid 18946:tid 19103] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.090452 2026] [core:error] [pid 20162:tid 20386] [client 34.94.39.26:58914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.090471 2026] [core:error] [pid 20162:tid 20386] [client 34.94.39.26:58914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.091173 2026] [security2:error] [pid 18946:tid 19157] [client 114.198.138.124:53647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcWTqiPMah0Tz_U1OJ_gAAAVs"]
[Thu Sep 17 15:32:09.091257 2026] [security2:error] [pid 18946:tid 19157] [client 114.198.138.124:53647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcWTqiPMah0Tz_U1OJ_gAAAVs"]
[Thu Sep 17 15:32:09.255389 2026] [core:error] [pid 18946:tid 19136] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.255413 2026] [core:error] [pid 18946:tid 19136] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.289167 2026] [security2:error] [pid 20162:tid 20398] [client 103.61.184.148:62779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcWa-O_Kk7aqBvaiF2UAAAAfg"]
[Thu Sep 17 15:32:09.289625 2026] [security2:error] [pid 20162:tid 20398] [client 103.61.184.148:62779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcWa-O_Kk7aqBvaiF2UAAAAfg"]
[Thu Sep 17 15:32:09.315887 2026] [security2:error] [pid 20162:tid 20401] [client 34.94.39.26:58932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxcWa-O_Kk7aqBvaiF2UQAAAfs"]
[Thu Sep 17 15:32:09.375864 2026] [core:error] [pid 20162:tid 20390] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.375884 2026] [core:error] [pid 20162:tid 20390] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.411608 2026] [core:error] [pid 20162:tid 20320] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.411632 2026] [core:error] [pid 20162:tid 20320] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.540083 2026] [security2:error] [pid 20162:tid 20416] [client 66.249.66.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcWa-O_Kk7aqBvaiF2UwAAAgo"]
[Thu Sep 17 15:32:09.638175 2026] [core:error] [pid 18946:tid 19123] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.638204 2026] [core:error] [pid 18946:tid 19123] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.666621 2026] [core:error] [pid 20162:tid 20377] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.666649 2026] [core:error] [pid 20162:tid 20377] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.669671 2026] [core:error] [pid 20162:tid 20328] [client 34.166.157.71:33934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.669690 2026] [core:error] [pid 20162:tid 20328] [client 34.166.157.71:33934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.896560 2026] [core:error] [pid 18946:tid 19143] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.896580 2026] [core:error] [pid 18946:tid 19143] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.924498 2026] [core:error] [pid 18946:tid 19159] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:09.924521 2026] [core:error] [pid 18946:tid 19159] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.007843 2026] [security2:error] [pid 18946:tid 19142] [client 35.252.83.108:52556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxcWjqiPMah0Tz_U1OKIgAAAUw"]
[Thu Sep 17 15:32:10.053495 2026] [security2:error] [pid 18946:tid 19117] [client 35.252.83.108:52556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxcWjqiPMah0Tz_U1OKIwAAATM"]
[Thu Sep 17 15:32:10.163253 2026] [core:error] [pid 18946:tid 19076] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.163279 2026] [core:error] [pid 18946:tid 19076] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.181742 2026] [core:error] [pid 18946:tid 19127] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.181766 2026] [core:error] [pid 18946:tid 19127] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.293796 2026] [core:error] [pid 18946:tid 19186] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.293818 2026] [core:error] [pid 18946:tid 19186] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.348161 2026] [security2:error] [pid 20162:tid 20298] [client 34.166.157.71:33936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "aqxcWq-O_Kk7aqBvaiF2bQAAAZQ"]
[Thu Sep 17 15:32:10.486982 2026] [security2:error] [pid 20162:tid 20338] [client 35.252.83.108:52572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxcWq-O_Kk7aqBvaiF2bgAAAbw"]
[Thu Sep 17 15:32:10.507365 2026] [core:error] [pid 18946:tid 19133] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.507393 2026] [core:error] [pid 18946:tid 19133] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.555209 2026] [core:error] [pid 20162:tid 20346] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.555228 2026] [core:error] [pid 20162:tid 20346] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.595711 2026] [core:error] [pid 20162:tid 20378] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.595735 2026] [core:error] [pid 20162:tid 20378] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.602967 2026] [core:error] [pid 18946:tid 19185] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.602985 2026] [core:error] [pid 18946:tid 19185] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.984889 2026] [core:error] [pid 18946:tid 19177] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:10.984912 2026] [core:error] [pid 18946:tid 19177] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.070129 2026] [core:error] [pid 18946:tid 19095] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.070150 2026] [core:error] [pid 18946:tid 19095] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.120554 2026] [core:error] [pid 20162:tid 20324] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.120573 2026] [core:error] [pid 20162:tid 20324] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.238228 2026] [security2:error] [pid 20162:tid 20293] [client 34.94.39.26:52288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxcW6-O_Kk7aqBvaiF2hQAAAY8"]
[Thu Sep 17 15:32:11.291856 2026] [security2:error] [pid 20162:tid 20317] [client 34.94.39.26:52288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxcW6-O_Kk7aqBvaiF2hwAAAac"]
[Thu Sep 17 15:32:11.329503 2026] [security2:error] [pid 20162:tid 20355] [client 41.56.249.87:49848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcW6-O_Kk7aqBvaiF2hAABzUQ"]
[Thu Sep 17 15:32:11.405785 2026] [core:error] [pid 18946:tid 19167] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.405804 2026] [core:error] [pid 18946:tid 19167] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.437056 2026] [security2:error] [pid 18946:tid 19151] [client 40.81.232.68:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxcWzqiPMah0Tz_U1OKUwAAAVU"], referer: binance.com
[Thu Sep 17 15:32:11.457065 2026] [core:error] [pid 18946:tid 19179] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.457086 2026] [core:error] [pid 18946:tid 19179] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.485035 2026] [core:error] [pid 18946:tid 19181] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.485057 2026] [core:error] [pid 18946:tid 19181] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.495778 2026] [security2:error] [pid 18946:tid 19141] [client 162.241.226.11:34898] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxcWzqiPMah0Tz_U1OKVQAAAUs"]
[Thu Sep 17 15:32:11.523238 2026] [core:error] [pid 18946:tid 19143] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.523256 2026] [core:error] [pid 18946:tid 19143] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.794595 2026] [core:error] [pid 18946:tid 19110] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.794621 2026] [core:error] [pid 18946:tid 19110] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.876108 2026] [core:error] [pid 20162:tid 20295] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.876128 2026] [core:error] [pid 20162:tid 20295] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:11.899024 2026] [security2:error] [pid 18946:tid 19118] [client 34.94.39.26:52312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxcWzqiPMah0Tz_U1OKagAAATQ"]
[Thu Sep 17 15:32:12.007972 2026] [security2:error] [pid 18946:tid 19184] [client 34.94.39.26:52312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxcXDqiPMah0Tz_U1OKbQAAAXY"]
[Thu Sep 17 15:32:12.105697 2026] [core:error] [pid 20162:tid 20348] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.105714 2026] [core:error] [pid 20162:tid 20348] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.135668 2026] [core:error] [pid 18946:tid 19168] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.135692 2026] [core:error] [pid 18946:tid 19168] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.320489 2026] [core:error] [pid 18946:tid 19153] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.320509 2026] [core:error] [pid 18946:tid 19153] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.492096 2026] [security2:error] [pid 18946:tid 19203] [client 74.7.244.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.thecareerscholar.com"] [uri "/index.php"] [unique_id "aqxcWTqiPMah0Tz_U1OKEQAAAYk"]
[Thu Sep 17 15:32:12.492128 2026] [security2:error] [pid 18946:tid 19203] [client 74.7.244.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thecareerscholar.com"] [uri "/index.php"] [unique_id "aqxcWTqiPMah0Tz_U1OKEQAAAYk"]
[Thu Sep 17 15:32:12.517529 2026] [security2:error] [pid 18946:tid 19188] [client 74.7.244.23:60754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.thecareerscholar.com"] [uri "/robots.txt"] [unique_id "aqxcWTqiPMah0Tz_U1OKDgABeio"]
[Thu Sep 17 15:32:12.528443 2026] [core:error] [pid 20162:tid 20327] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.528462 2026] [core:error] [pid 20162:tid 20327] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.749448 2026] [core:error] [pid 20162:tid 20335] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.749469 2026] [core:error] [pid 20162:tid 20335] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.788328 2026] [core:error] [pid 18946:tid 19140] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.788350 2026] [core:error] [pid 18946:tid 19140] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.883852 2026] [core:error] [pid 20162:tid 20420] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.883879 2026] [core:error] [pid 20162:tid 20420] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:12.901010 2026] [security2:error] [pid 20162:tid 20400] [client 34.94.39.26:52344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxcXK-O_Kk7aqBvaiF2qwAAAfo"]
[Thu Sep 17 15:32:12.934068 2026] [security2:error] [pid 20162:tid 20349] [client 74.7.244.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thecareerscholar.com"] [uri "/index.php"] [unique_id "aqxcXK-O_Kk7aqBvaiF2pAAAAcc"], referer: https://www.thecareerscholar.com/robots.txt
[Thu Sep 17 15:32:12.943827 2026] [security2:error] [pid 18946:tid 19106] [client 74.7.244.23:37442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thecareerscholar.com"] [uri "/robots.txt"] [unique_id "aqxcXDqiPMah0Tz_U1OKgwABKEU"], referer: https://www.thecareerscholar.com/robots.txt
[Thu Sep 17 15:32:13.033611 2026] [core:error] [pid 20162:tid 20316] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.033633 2026] [core:error] [pid 20162:tid 20316] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.264131 2026] [core:error] [pid 20162:tid 20411] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.264151 2026] [core:error] [pid 20162:tid 20411] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.352828 2026] [core:error] [pid 20162:tid 20378] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.352851 2026] [core:error] [pid 20162:tid 20378] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.414304 2026] [core:error] [pid 20162:tid 20359] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.414324 2026] [core:error] [pid 20162:tid 20359] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.648308 2026] [core:error] [pid 18946:tid 19125] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.648332 2026] [core:error] [pid 18946:tid 19125] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.723525 2026] [core:error] [pid 18946:tid 19077] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.723556 2026] [core:error] [pid 18946:tid 19077] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.788263 2026] [security2:error] [pid 18946:tid 19132] [client 34.94.39.26:52380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxcXTqiPMah0Tz_U1OKoAAAAUI"]
[Thu Sep 17 15:32:13.853962 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.39.26:52380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxcXTqiPMah0Tz_U1OKpAAAATI"]
[Thu Sep 17 15:32:13.855096 2026] [core:error] [pid 20162:tid 20393] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.855112 2026] [core:error] [pid 20162:tid 20393] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:13.978024 2026] [security2:error] [pid 18946:tid 19192] [client 34.94.39.26:52380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxcXTqiPMah0Tz_U1OKrAAAAX4"]
[Thu Sep 17 15:32:14.039187 2026] [security2:error] [pid 18946:tid 19101] [client 34.94.39.26:52380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OKrwAAASM"]
[Thu Sep 17 15:32:14.065094 2026] [core:error] [pid 18946:tid 19126] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.065106 2026] [security2:error] [pid 18946:tid 19098] [client 43.173.181.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcXTqiPMah0Tz_U1OKqwAAASA"]
[Thu Sep 17 15:32:14.065127 2026] [core:error] [pid 18946:tid 19126] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.074512 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.39.26:52380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OKsgAAARo"]
[Thu Sep 17 15:32:14.131046 2026] [security2:error] [pid 18946:tid 19093] [client 34.94.39.26:52380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OKswAAARs"]
[Thu Sep 17 15:32:14.232818 2026] [core:error] [pid 20162:tid 20375] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.232841 2026] [core:error] [pid 20162:tid 20375] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.389093 2026] [security2:error] [pid 18946:tid 19184] [client 46.101.77.15:46340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxcXjqiPMah0Tz_U1OKtgABdiw"], referer: http://nevadastaterealty.com/blog/
[Thu Sep 17 15:32:14.390053 2026] [core:error] [pid 18946:tid 19183] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.390067 2026] [core:error] [pid 18946:tid 19183] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.523510 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OKyQAAASc"]
[Thu Sep 17 15:32:14.548314 2026] [core:error] [pid 18946:tid 19107] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.548334 2026] [core:error] [pid 18946:tid 19107] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.563423 2026] [core:error] [pid 18946:tid 19162] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.563443 2026] [core:error] [pid 18946:tid 19162] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.585973 2026] [security2:error] [pid 18946:tid 19152] [client 181.127.84.82:60009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcXjqiPMah0Tz_U1OKwwABVkI"]
[Thu Sep 17 15:32:14.678167 2026] [security2:error] [pid 18946:tid 19170] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OK0gAAAWg"]
[Thu Sep 17 15:32:14.766441 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OK1AAAAWQ"]
[Thu Sep 17 15:32:14.782586 2026] [security2:error] [pid 18946:tid 19198] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OK1QAAAYQ"]
[Thu Sep 17 15:32:14.798807 2026] [security2:error] [pid 18946:tid 19097] [client 46.101.77.15:46340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxcXjqiPMah0Tz_U1OK0QABH0E"], referer: http://nevadastaterealty.com/backup/
[Thu Sep 17 15:32:14.817416 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OK1wAAAUY"]
[Thu Sep 17 15:32:14.853455 2026] [security2:error] [pid 18946:tid 19144] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OK2wAAAU4"]
[Thu Sep 17 15:32:14.884628 2026] [security2:error] [pid 18946:tid 19150] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxcXjqiPMah0Tz_U1OK4QAAAVQ"]
[Thu Sep 17 15:32:14.923942 2026] [core:error] [pid 20162:tid 20345] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:14.923964 2026] [core:error] [pid 20162:tid 20345] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.034236 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OK6wAAAUk"]
[Thu Sep 17 15:32:15.080973 2026] [core:error] [pid 18946:tid 19108] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.080999 2026] [core:error] [pid 18946:tid 19108] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.089285 2026] [security2:error] [pid 18946:tid 19123] [client 34.166.157.71:34010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "aqxcXzqiPMah0Tz_U1OK7gAAATk"]
[Thu Sep 17 15:32:15.117804 2026] [security2:error] [pid 18946:tid 19116] [client 43.172.195.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcXjqiPMah0Tz_U1OK6AAAATI"]
[Thu Sep 17 15:32:15.176453 2026] [security2:error] [pid 18946:tid 19155] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OK7wAAAVk"]
[Thu Sep 17 15:32:15.197742 2026] [security2:error] [pid 18946:tid 19142] [client 46.101.77.15:46340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxcXzqiPMah0Tz_U1OK7QABTDs"], referer: http://nevadastaterealty.com/wordpress/
[Thu Sep 17 15:32:15.255384 2026] [security2:error] [pid 18946:tid 19126] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OK8QAAATw"]
[Thu Sep 17 15:32:15.312969 2026] [security2:error] [pid 20162:tid 20350] [client 35.252.83.108:35720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxcX6-O_Kk7aqBvaiF22AAAAcg"]
[Thu Sep 17 15:32:15.318192 2026] [security2:error] [pid 18946:tid 19102] [client 34.166.157.71:34010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "aqxcXzqiPMah0Tz_U1OK8gAAASQ"]
[Thu Sep 17 15:32:15.388522 2026] [security2:error] [pid 18946:tid 19169] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OK9QAAAWc"]
[Thu Sep 17 15:32:15.430034 2026] [security2:error] [pid 20162:tid 20397] [client 35.252.83.108:35720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/.env~"] [unique_id "aqxcX6-O_Kk7aqBvaiF22wAAAfc"]
[Thu Sep 17 15:32:15.467605 2026] [core:error] [pid 18946:tid 19093] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.467623 2026] [core:error] [pid 18946:tid 19093] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.502057 2026] [security2:error] [pid 18946:tid 19133] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OK_gAAAUM"]
[Thu Sep 17 15:32:15.534761 2026] [security2:error] [pid 18946:tid 19080] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OK_wAAAQ4"]
[Thu Sep 17 15:32:15.582052 2026] [core:error] [pid 18946:tid 19135] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.582073 2026] [core:error] [pid 18946:tid 19135] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.585243 2026] [security2:error] [pid 18946:tid 19179] [client 46.101.77.15:46340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxcXzqiPMah0Tz_U1OK_QABcW4"], referer: http://nevadastaterealty.com/new/
[Thu Sep 17 15:32:15.600032 2026] [core:error] [pid 18946:tid 19160] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.600049 2026] [core:error] [pid 18946:tid 19160] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.669122 2026] [core:error] [pid 20162:tid 20340] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.669143 2026] [core:error] [pid 20162:tid 20340] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.691206 2026] [security2:error] [pid 18946:tid 19156] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OLBgAAAVo"]
[Thu Sep 17 15:32:15.795026 2026] [security2:error] [pid 18946:tid 19162] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OLCAAAAWA"]
[Thu Sep 17 15:32:15.884236 2026] [security2:error] [pid 20162:tid 20348] [client 79.116.89.151:60121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcX6-O_Kk7aqBvaiF24wAAAcY"]
[Thu Sep 17 15:32:15.884350 2026] [security2:error] [pid 20162:tid 20348] [client 79.116.89.151:60121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcX6-O_Kk7aqBvaiF24wAAAcY"]
[Thu Sep 17 15:32:15.921253 2026] [security2:error] [pid 18946:tid 19152] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxcXzqiPMah0Tz_U1OLDgAAAVY"]
[Thu Sep 17 15:32:15.945103 2026] [core:error] [pid 18946:tid 19189] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:15.945123 2026] [core:error] [pid 18946:tid 19189] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.031954 2026] [security2:error] [pid 18946:tid 19149] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLEwAAAVM"]
[Thu Sep 17 15:32:16.131059 2026] [core:error] [pid 20162:tid 20335] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.131079 2026] [core:error] [pid 20162:tid 20335] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.181571 2026] [security2:error] [pid 20162:tid 20310] [client 43.173.175.173:54990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.175.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcYK-O_Kk7aqBvaiF26wAAAaA"]
[Thu Sep 17 15:32:16.188336 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLFQAAAWQ"]
[Thu Sep 17 15:32:16.269486 2026] [security2:error] [pid 18946:tid 19198] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLFgAAAYQ"]
[Thu Sep 17 15:32:16.291296 2026] [security2:error] [pid 18946:tid 19114] [client 34.166.157.71:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "aqxcYDqiPMah0Tz_U1OLFwAAATA"]
[Thu Sep 17 15:32:16.369579 2026] [security2:error] [pid 18946:tid 19163] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLGwAAAWE"]
[Thu Sep 17 15:32:16.391809 2026] [core:error] [pid 18946:tid 19177] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.391832 2026] [core:error] [pid 18946:tid 19177] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.464945 2026] [security2:error] [pid 18946:tid 19108] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLHwAAASo"]
[Thu Sep 17 15:32:16.556482 2026] [security2:error] [pid 18946:tid 19159] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLJAAAAV0"]
[Thu Sep 17 15:32:16.598369 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLJQAAATs"]
[Thu Sep 17 15:32:16.601716 2026] [core:error] [pid 20162:tid 20339] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.601735 2026] [core:error] [pid 20162:tid 20339] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.612808 2026] [core:error] [pid 18946:tid 19117] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.612829 2026] [core:error] [pid 18946:tid 19117] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:16.626575 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLJwAAAQ8"]
[Thu Sep 17 15:32:16.767819 2026] [security2:error] [pid 18946:tid 19082] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLKwAAARA"]
[Thu Sep 17 15:32:16.782065 2026] [security2:error] [pid 20162:tid 20418] [client 143.105.152.240:21927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcYK-O_Kk7aqBvaiF2-gAAAgw"]
[Thu Sep 17 15:32:16.784136 2026] [security2:error] [pid 20162:tid 20418] [client 143.105.152.240:21927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcYK-O_Kk7aqBvaiF2-gAAAgw"]
[Thu Sep 17 15:32:16.889884 2026] [security2:error] [pid 18946:tid 19135] [client 40.81.232.68:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxcYDqiPMah0Tz_U1OLMwAAAUU"], referer: binance.com
[Thu Sep 17 15:32:16.898351 2026] [security2:error] [pid 18946:tid 19183] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxcYDqiPMah0Tz_U1OLNgAAAXU"]
[Thu Sep 17 15:32:16.993256 2026] [security2:error] [pid 18946:tid 19080] [client 46.101.77.15:46340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxcYDqiPMah0Tz_U1OLMgABDnI"], referer: http://nevadastaterealty.com/old/
[Thu Sep 17 15:32:17.017625 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLNwAAAYc"]
[Thu Sep 17 15:32:17.057046 2026] [core:error] [pid 18946:tid 19185] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.057069 2026] [core:error] [pid 18946:tid 19185] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.059679 2026] [core:error] [pid 20162:tid 20301] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.059700 2026] [core:error] [pid 20162:tid 20301] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.115481 2026] [security2:error] [pid 18946:tid 19088] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLOgAAARY"]
[Thu Sep 17 15:32:17.349648 2026] [core:error] [pid 18946:tid 19148] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.349684 2026] [core:error] [pid 18946:tid 19148] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.351738 2026] [core:error] [pid 18946:tid 19152] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.351757 2026] [core:error] [pid 18946:tid 19152] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.385110 2026] [security2:error] [pid 18946:tid 19161] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLSgAAAV8"]
[Thu Sep 17 15:32:17.391091 2026] [security2:error] [pid 18946:tid 19194] [client 46.101.77.15:46340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevadastaterealty.com"] [uri "/index.php"] [unique_id "aqxcYTqiPMah0Tz_U1OLQQABgHQ"], referer: http://nevadastaterealty.com/wp/
[Thu Sep 17 15:32:17.421221 2026] [core:error] [pid 18946:tid 19109] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.421244 2026] [core:error] [pid 18946:tid 19109] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:17.554394 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLTAAAAR8"]
[Thu Sep 17 15:32:17.580968 2026] [security2:error] [pid 18946:tid 19199] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLTgAAAYU"]
[Thu Sep 17 15:32:17.637482 2026] [security2:error] [pid 18946:tid 19144] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLTwAAAU4"]
[Thu Sep 17 15:32:17.641708 2026] [security2:error] [pid 18946:tid 19122] [client 35.252.83.108:35764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLUAAAATg"]
[Thu Sep 17 15:32:17.674575 2026] [security2:error] [pid 18946:tid 19100] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLUQAAASI"]
[Thu Sep 17 15:32:17.725245 2026] [security2:error] [pid 18946:tid 19181] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLUgAAAXM"]
[Thu Sep 17 15:32:17.768228 2026] [security2:error] [pid 18946:tid 19150] [client 35.252.83.108:35764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLUwAAAVQ"]
[Thu Sep 17 15:32:17.787560 2026] [security2:error] [pid 18946:tid 19158] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLVAAAAVw"]
[Thu Sep 17 15:32:17.838037 2026] [security2:error] [pid 18946:tid 19108] [client 35.252.83.108:35764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLVgAAASo"]
[Thu Sep 17 15:32:17.891517 2026] [security2:error] [pid 18946:tid 19172] [client 66.249.66.44:62455] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "centerforfederaljusticereform.org"] [uri "/robots.txt"] [unique_id "aqxcYTqiPMah0Tz_U1OLWQAAAWo"]
[Thu Sep 17 15:32:17.909563 2026] [security2:error] [pid 18946:tid 19138] [client 34.94.39.26:52488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxcYTqiPMah0Tz_U1OLWgAAAUg"]
[Thu Sep 17 15:32:17.952543 2026] [security2:error] [pid 20162:tid 20315] [client 58.84.150.1:47779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxcYa-O_Kk7aqBvaiF3SAABpQU"], referer: https://intolovinghomes.com.au/
[Thu Sep 17 15:32:17.956232 2026] [security2:error] [pid 18946:tid 19085] [client 34.94.39.26:52488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxcYTqiPMah0Tz_U1OLWwAAARM"]
[Thu Sep 17 15:32:17.961773 2026] [security2:error] [pid 18946:tid 19123] [client 35.252.83.108:35764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxcYTqiPMah0Tz_U1OLXAAAATk"]
[Thu Sep 17 15:32:18.011168 2026] [security2:error] [pid 18946:tid 19151] [client 35.252.83.108:35764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLXgAAAVU"]
[Thu Sep 17 15:32:18.019370 2026] [security2:error] [pid 18946:tid 19171] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLYAAAAWk"]
[Thu Sep 17 15:32:18.041105 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLYwAAATs"]
[Thu Sep 17 15:32:18.062365 2026] [security2:error] [pid 18946:tid 19110] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLZQAAASw"]
[Thu Sep 17 15:32:18.063478 2026] [security2:error] [pid 18946:tid 19119] [client 35.252.83.108:35764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLZgAAATU"]
[Thu Sep 17 15:32:18.078944 2026] [core:error] [pid 18946:tid 19142] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.078967 2026] [core:error] [pid 18946:tid 19142] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.082335 2026] [core:error] [pid 18946:tid 19087] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.082352 2026] [core:error] [pid 18946:tid 19087] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.104834 2026] [security2:error] [pid 18946:tid 19113] [client 76.139.184.220:58629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcYjqiPMah0Tz_U1OLXQABL2A"]
[Thu Sep 17 15:32:18.140813 2026] [security2:error] [pid 18946:tid 19143] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLawAAAU0"]
[Thu Sep 17 15:32:18.161209 2026] [security2:error] [pid 18946:tid 19079] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLbAAAAQ0"]
[Thu Sep 17 15:32:18.165167 2026] [security2:error] [pid 20162:tid 20352] [client 4.240.114.86:61700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxcYq-O_Kk7aqBvaiF3WQAAAco"], referer: binance.com
[Thu Sep 17 15:32:18.272596 2026] [security2:error] [pid 18946:tid 19076] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLbgAAAQo"]
[Thu Sep 17 15:32:18.284785 2026] [core:error] [pid 18946:tid 19178] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.284804 2026] [core:error] [pid 18946:tid 19178] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.368560 2026] [security2:error] [pid 18946:tid 19182] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLcQAAAXQ"]
[Thu Sep 17 15:32:18.500979 2026] [security2:error] [pid 18946:tid 19096] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLdQAAAR4"]
[Thu Sep 17 15:32:18.556234 2026] [security2:error] [pid 20162:tid 20320] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxcYq-O_Kk7aqBvaiF3XwAAAao"]
[Thu Sep 17 15:32:18.586020 2026] [security2:error] [pid 18946:tid 19135] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLegAAAUU"]
[Thu Sep 17 15:32:18.630368 2026] [core:error] [pid 20162:tid 20358] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.630391 2026] [core:error] [pid 20162:tid 20358] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.638296 2026] [security2:error] [pid 20162:tid 20374] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxcYq-O_Kk7aqBvaiF3YgAAAeA"]
[Thu Sep 17 15:32:18.681206 2026] [security2:error] [pid 18946:tid 19174] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLewAAAWw"]
[Thu Sep 17 15:32:18.723254 2026] [security2:error] [pid 18946:tid 19121] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLfAAAATc"]
[Thu Sep 17 15:32:18.736192 2026] [security2:error] [pid 20162:tid 20415] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxcYq-O_Kk7aqBvaiF3ZAAAAgk"]
[Thu Sep 17 15:32:18.796463 2026] [security2:error] [pid 20162:tid 20356] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxcYq-O_Kk7aqBvaiF3ZgAAAc4"]
[Thu Sep 17 15:32:18.852897 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLfgAAASc"]
[Thu Sep 17 15:32:18.893754 2026] [security2:error] [pid 20162:tid 20328] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxcYq-O_Kk7aqBvaiF3aQAAAbI"]
[Thu Sep 17 15:32:18.942087 2026] [security2:error] [pid 20162:tid 20327] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxcYq-O_Kk7aqBvaiF3agAAAbE"]
[Thu Sep 17 15:32:18.949807 2026] [core:error] [pid 20162:tid 20329] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.949830 2026] [core:error] [pid 20162:tid 20329] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:18.999901 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxcYjqiPMah0Tz_U1OLgwAAAV4"]
[Thu Sep 17 15:32:19.038554 2026] [security2:error] [pid 20162:tid 20302] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3cAAAAZg"]
[Thu Sep 17 15:32:19.039729 2026] [security2:error] [pid 18946:tid 19130] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLhQAAAUA"]
[Thu Sep 17 15:32:19.086843 2026] [security2:error] [pid 20162:tid 20326] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3cgAAAbA"]
[Thu Sep 17 15:32:19.095934 2026] [security2:error] [pid 18946:tid 19197] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLhgAAAYM"]
[Thu Sep 17 15:32:19.125489 2026] [security2:error] [pid 18946:tid 19148] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLhwAAAVI"]
[Thu Sep 17 15:32:19.175945 2026] [security2:error] [pid 18946:tid 19152] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLiAAAAVY"]
[Thu Sep 17 15:32:19.261271 2026] [security2:error] [pid 18946:tid 19106] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLjQAAASg"]
[Thu Sep 17 15:32:19.263074 2026] [security2:error] [pid 20162:tid 20366] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3dQAAAdg"]
[Thu Sep 17 15:32:19.317189 2026] [security2:error] [pid 20162:tid 20403] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3eAAAAf0"]
[Thu Sep 17 15:32:19.330498 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLjgAAASE"]
[Thu Sep 17 15:32:19.355481 2026] [core:error] [pid 18946:tid 19173] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:19.355506 2026] [core:error] [pid 18946:tid 19173] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:19.391165 2026] [security2:error] [pid 18946:tid 19161] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLlAAAAV8"]
[Thu Sep 17 15:32:19.402320 2026] [security2:error] [pid 20162:tid 20334] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3eQAAAbg"]
[Thu Sep 17 15:32:19.423527 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLlQAAASs"]
[Thu Sep 17 15:32:19.458556 2026] [security2:error] [pid 20162:tid 20321] [client 58.84.150.1:47779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxcY6-O_Kk7aqBvaiF3dgABqw0"], referer: https://intolovinghomes.com.au/
[Thu Sep 17 15:32:19.481473 2026] [security2:error] [pid 20162:tid 20306] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3ewAAAZw"]
[Thu Sep 17 15:32:19.520167 2026] [security2:error] [pid 18946:tid 19198] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLmgAAAYQ"]
[Thu Sep 17 15:32:19.531530 2026] [security2:error] [pid 20162:tid 20346] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3fAAAAcQ"]
[Thu Sep 17 15:32:19.553490 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLmwAAAR8"]
[Thu Sep 17 15:32:19.593751 2026] [security2:error] [pid 20162:tid 20378] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3fgAAAeQ"]
[Thu Sep 17 15:32:19.624296 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLnQAAAVA"]
[Thu Sep 17 15:32:19.684166 2026] [security2:error] [pid 20162:tid 20339] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3gQAAAb0"]
[Thu Sep 17 15:32:19.703223 2026] [security2:error] [pid 18946:tid 19202] [client 136.158.61.34:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcYzqiPMah0Tz_U1OLoQAAAYg"]
[Thu Sep 17 15:32:19.703366 2026] [security2:error] [pid 18946:tid 19202] [client 136.158.61.34:52252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcYzqiPMah0Tz_U1OLoQAAAYg"]
[Thu Sep 17 15:32:19.704237 2026] [security2:error] [pid 18946:tid 19179] [client 114.198.138.124:54290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcYzqiPMah0Tz_U1OLogAAAXE"]
[Thu Sep 17 15:32:19.704324 2026] [security2:error] [pid 18946:tid 19179] [client 114.198.138.124:54290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcYzqiPMah0Tz_U1OLogAAAXE"]
[Thu Sep 17 15:32:19.760472 2026] [core:error] [pid 20162:tid 20299] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:19.760490 2026] [core:error] [pid 20162:tid 20299] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:19.767045 2026] [security2:error] [pid 18946:tid 19100] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLowAAASI"]
[Thu Sep 17 15:32:19.870691 2026] [security2:error] [pid 18946:tid 19181] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLpAAAAXM"]
[Thu Sep 17 15:32:19.881137 2026] [security2:error] [pid 20162:tid 20418] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3igAAAgw"]
[Thu Sep 17 15:32:19.885222 2026] [core:error] [pid 18946:tid 19150] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:19.885239 2026] [core:error] [pid 18946:tid 19150] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:19.938174 2026] [security2:error] [pid 18946:tid 19111] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLqgAAAS0"]
[Thu Sep 17 15:32:19.943809 2026] [security2:error] [pid 20162:tid 20382] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxcY6-O_Kk7aqBvaiF3jAAAAeg"]
[Thu Sep 17 15:32:19.984789 2026] [security2:error] [pid 18946:tid 19085] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxcYzqiPMah0Tz_U1OLrwAAARM"]
[Thu Sep 17 15:32:20.007254 2026] [security2:error] [pid 18946:tid 19123] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLsAAAATk"]
[Thu Sep 17 15:32:20.049832 2026] [security2:error] [pid 18946:tid 19151] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLsQAAAVU"]
[Thu Sep 17 15:32:20.050350 2026] [security2:error] [pid 18946:tid 19139] [client 76.139.184.220:58077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcYzqiPMah0Tz_U1OLrQABSVc"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260602155541&hideliu=1&hideminor=1&limit=500&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:32:20.062073 2026] [security2:error] [pid 20162:tid 20333] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3jgAAAbc"]
[Thu Sep 17 15:32:20.088120 2026] [security2:error] [pid 18946:tid 19171] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLsgAAAWk"]
[Thu Sep 17 15:32:20.146820 2026] [security2:error] [pid 18946:tid 19118] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLtAAAATQ"]
[Thu Sep 17 15:32:20.168789 2026] [security2:error] [pid 20162:tid 20408] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3jwAAAgI"]
[Thu Sep 17 15:32:20.238764 2026] [security2:error] [pid 20162:tid 20393] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3kQAAAfM"]
[Thu Sep 17 15:32:20.311190 2026] [security2:error] [pid 18946:tid 19143] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLtwAAAU0"]
[Thu Sep 17 15:32:20.327012 2026] [security2:error] [pid 20162:tid 20342] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3kwAAAcA"]
[Thu Sep 17 15:32:20.386496 2026] [security2:error] [pid 18946:tid 19117] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLvQAAATM"]
[Thu Sep 17 15:32:20.419928 2026] [core:error] [pid 18946:tid 19081] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:20.419953 2026] [core:error] [pid 18946:tid 19081] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:20.467797 2026] [security2:error] [pid 20162:tid 20367] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3lQAAAdk"]
[Thu Sep 17 15:32:20.471754 2026] [security2:error] [pid 18946:tid 19129] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLwgAAAT8"]
[Thu Sep 17 15:32:20.519943 2026] [core:error] [pid 18946:tid 19116] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:20.519966 2026] [core:error] [pid 18946:tid 19116] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:20.608279 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLxAAAAUc"]
[Thu Sep 17 15:32:20.650453 2026] [security2:error] [pid 20162:tid 20384] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3lwAAAeo"]
[Thu Sep 17 15:32:20.674789 2026] [security2:error] [pid 18946:tid 19183] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLxgAAAXU"]
[Thu Sep 17 15:32:20.743610 2026] [security2:error] [pid 18946:tid 19174] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLxwAAAWw"]
[Thu Sep 17 15:32:20.747991 2026] [security2:error] [pid 20162:tid 20381] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3mQAAAec"]
[Thu Sep 17 15:32:20.819421 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.39.26:52540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLyQAAAXk"]
[Thu Sep 17 15:32:20.844879 2026] [security2:error] [pid 20162:tid 20316] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3mgAAAaY"]
[Thu Sep 17 15:32:20.886590 2026] [security2:error] [pid 18946:tid 19185] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLzgAAAXc"]
[Thu Sep 17 15:32:20.933842 2026] [security2:error] [pid 18946:tid 19130] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OLzwAAAUA"]
[Thu Sep 17 15:32:20.937824 2026] [security2:error] [pid 18946:tid 19088] [client 34.94.39.26:52540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OL0AAAARY"]
[Thu Sep 17 15:32:20.954015 2026] [security2:error] [pid 18946:tid 19120] [client 34.94.39.26:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxcZDqiPMah0Tz_U1OL0QAAATY"]
[Thu Sep 17 15:32:20.987928 2026] [security2:error] [pid 20162:tid 20314] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxcZK-O_Kk7aqBvaiF3nQAAAaQ"]
[Thu Sep 17 15:32:21.060198 2026] [security2:error] [pid 20162:tid 20368] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3ngAAAdo"]
[Thu Sep 17 15:32:21.063983 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.39.26:52540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxcZTqiPMah0Tz_U1OL0wAAARo"]
[Thu Sep 17 15:32:21.124218 2026] [security2:error] [pid 20162:tid 20355] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3oAAAAc0"]
[Thu Sep 17 15:32:21.152384 2026] [security2:error] [pid 18946:tid 19152] [client 34.94.39.26:52540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxcZTqiPMah0Tz_U1OL1QAAAVY"]
[Thu Sep 17 15:32:21.189906 2026] [security2:error] [pid 18946:tid 19180] [client 34.94.39.26:52540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxcZTqiPMah0Tz_U1OL1gAAAXI"]
[Thu Sep 17 15:32:21.232252 2026] [security2:error] [pid 20162:tid 20394] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3owAAAfQ"]
[Thu Sep 17 15:32:21.262632 2026] [security2:error] [pid 18946:tid 19200] [client 34.94.39.26:52540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxcZTqiPMah0Tz_U1OL2QAAAYY"]
[Thu Sep 17 15:32:21.264840 2026] [core:error] [pid 18946:tid 19165] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:21.264855 2026] [core:error] [pid 18946:tid 19165] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:21.374120 2026] [security2:error] [pid 20162:tid 20375] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3pAAAAeE"]
[Thu Sep 17 15:32:21.406071 2026] [security2:error] [pid 20162:tid 20324] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3pgAAAa4"]
[Thu Sep 17 15:32:21.422030 2026] [security2:error] [pid 20162:tid 20332] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3qAAAAbY"]
[Thu Sep 17 15:32:21.481752 2026] [security2:error] [pid 20162:tid 20330] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3qQAAAbQ"]
[Thu Sep 17 15:32:21.510359 2026] [security2:error] [pid 20162:tid 20373] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3qgAAAd8"]
[Thu Sep 17 15:32:21.516237 2026] [security2:error] [pid 20162:tid 20313] [client 40.81.232.68:59813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxcZa-O_Kk7aqBvaiF3rQAAAaM"], referer: binance.com
[Thu Sep 17 15:32:21.539806 2026] [security2:error] [pid 20162:tid 20380] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3rwAAAeY"]
[Thu Sep 17 15:32:21.545481 2026] [core:error] [pid 20162:tid 20404] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:21.545498 2026] [core:error] [pid 20162:tid 20404] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:21.607696 2026] [security2:error] [pid 20162:tid 20309] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3swAAAZ8"]
[Thu Sep 17 15:32:21.628868 2026] [security2:error] [pid 20162:tid 20388] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3tQAAAe4"]
[Thu Sep 17 15:32:21.714334 2026] [security2:error] [pid 20162:tid 20320] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3ugAAAao"]
[Thu Sep 17 15:32:21.741972 2026] [security2:error] [pid 20162:tid 20307] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3uwAAAZ0"]
[Thu Sep 17 15:32:21.765546 2026] [security2:error] [pid 20162:tid 20374] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3vAAAAeA"]
[Thu Sep 17 15:32:21.829203 2026] [security2:error] [pid 20162:tid 20341] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3vQAAAb8"]
[Thu Sep 17 15:32:21.880057 2026] [security2:error] [pid 20162:tid 20356] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3vwAAAc4"]
[Thu Sep 17 15:32:21.916768 2026] [security2:error] [pid 18946:tid 19199] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxcZTqiPMah0Tz_U1OL6QAAAYU"]
[Thu Sep 17 15:32:21.917968 2026] [security2:error] [pid 20162:tid 20328] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3wAAAAbI"]
[Thu Sep 17 15:32:21.962097 2026] [security2:error] [pid 20162:tid 20327] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3wgAAAbE"]
[Thu Sep 17 15:32:21.981300 2026] [security2:error] [pid 20162:tid 20329] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxcZa-O_Kk7aqBvaiF3wwAAAbM"]
[Thu Sep 17 15:32:22.006909 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OL6gAAAYg"]
[Thu Sep 17 15:32:22.034599 2026] [security2:error] [pid 20162:tid 20387] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF3xAAAAe0"]
[Thu Sep 17 15:32:22.037744 2026] [security2:error] [pid 18946:tid 19184] [client 52.167.144.170:52272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxcZDqiPMah0Tz_U1OLyAABdk8"]
[Thu Sep 17 15:32:22.073925 2026] [security2:error] [pid 20162:tid 20302] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF3xgAAAZg"]
[Thu Sep 17 15:32:22.092673 2026] [core:error] [pid 20162:tid 20310] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:22.092693 2026] [core:error] [pid 20162:tid 20310] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:22.113801 2026] [security2:error] [pid 18946:tid 19181] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OL7gAAAXM"]
[Thu Sep 17 15:32:22.149170 2026] [security2:error] [pid 20162:tid 20377] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF3ygAAAeM"]
[Thu Sep 17 15:32:22.270912 2026] [security2:error] [pid 20162:tid 20369] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF3ywAAAds"]
[Thu Sep 17 15:32:22.313629 2026] [security2:error] [pid 20162:tid 20360] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF3zAAAAdI"]
[Thu Sep 17 15:32:22.353712 2026] [security2:error] [pid 20162:tid 20308] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF3zgAAAZ4"]
[Thu Sep 17 15:32:22.383878 2026] [security2:error] [pid 18946:tid 19172] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OL8QAAAWo"]
[Thu Sep 17 15:32:22.429169 2026] [security2:error] [pid 18946:tid 19114] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OL9QAAATA"]
[Thu Sep 17 15:32:22.496702 2026] [security2:error] [pid 20162:tid 20351] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF3zwAAAck"]
[Thu Sep 17 15:32:22.514025 2026] [security2:error] [pid 18946:tid 19107] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OL9wAAASk"]
[Thu Sep 17 15:32:22.559167 2026] [security2:error] [pid 20162:tid 20402] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF30AAAAfw"]
[Thu Sep 17 15:32:22.561198 2026] [security2:error] [pid 20162:tid 20334] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF30QAAAbg"]
[Thu Sep 17 15:32:22.623480 2026] [security2:error] [pid 18946:tid 19171] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OL-gAAAWk"]
[Thu Sep 17 15:32:22.662401 2026] [security2:error] [pid 20162:tid 20321] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF30wAAAas"]
[Thu Sep 17 15:32:22.672192 2026] [security2:error] [pid 20162:tid 20298] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF31AAAAZQ"]
[Thu Sep 17 15:32:22.732873 2026] [security2:error] [pid 20162:tid 20306] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF31QAAAZw"]
[Thu Sep 17 15:32:22.747082 2026] [security2:error] [pid 20162:tid 20346] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF31gAAAcQ"]
[Thu Sep 17 15:32:22.785103 2026] [security2:error] [pid 20162:tid 20411] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF32AAAAgU"]
[Thu Sep 17 15:32:22.824986 2026] [security2:error] [pid 18946:tid 19089] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OL_gAAARc"]
[Thu Sep 17 15:32:22.833238 2026] [security2:error] [pid 20162:tid 20303] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF32gAAAZk"]
[Thu Sep 17 15:32:22.862734 2026] [security2:error] [pid 20162:tid 20323] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF33AAAAa0"]
[Thu Sep 17 15:32:22.875998 2026] [core:error] [pid 20162:tid 20385] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:22.876017 2026] [core:error] [pid 20162:tid 20385] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:22.880244 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxcZjqiPMah0Tz_U1OMBAAAAQ8"]
[Thu Sep 17 15:32:22.924861 2026] [security2:error] [pid 20162:tid 20392] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF33gAAAfI"]
[Thu Sep 17 15:32:22.928712 2026] [core:error] [pid 18946:tid 19094] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:22.928727 2026] [core:error] [pid 18946:tid 19094] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:22.981099 2026] [security2:error] [pid 20162:tid 20331] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxcZq-O_Kk7aqBvaiF33wAAAbU"]
[Thu Sep 17 15:32:23.011227 2026] [security2:error] [pid 20162:tid 20420] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF34AAAAg4"]
[Thu Sep 17 15:32:23.033950 2026] [security2:error] [pid 18946:tid 19164] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMCQAAAWI"]
[Thu Sep 17 15:32:23.050483 2026] [security2:error] [pid 20162:tid 20337] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF34QAAAbs"]
[Thu Sep 17 15:32:23.088622 2026] [security2:error] [pid 20162:tid 20418] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF35AAAAgw"]
[Thu Sep 17 15:32:23.108447 2026] [security2:error] [pid 20162:tid 20325] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF35QAAAa8"]
[Thu Sep 17 15:32:23.121575 2026] [security2:error] [pid 18946:tid 19103] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMDQAAASU"]
[Thu Sep 17 15:32:23.171856 2026] [security2:error] [pid 20162:tid 20389] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF35gAAAe8"]
[Thu Sep 17 15:32:23.202903 2026] [security2:error] [pid 20162:tid 20338] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF36AAAAbw"]
[Thu Sep 17 15:32:23.209505 2026] [security2:error] [pid 18946:tid 19096] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMDwAAAR4"]
[Thu Sep 17 15:32:23.236685 2026] [security2:error] [pid 20162:tid 20312] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF36QAAAaI"]
[Thu Sep 17 15:32:23.260656 2026] [security2:error] [pid 20162:tid 20344] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF36gAAAcI"]
[Thu Sep 17 15:32:23.266941 2026] [security2:error] [pid 20162:tid 20336] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF36wAAAbo"]
[Thu Sep 17 15:32:23.320591 2026] [security2:error] [pid 20162:tid 20408] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF37gAAAgI"]
[Thu Sep 17 15:32:23.327306 2026] [security2:error] [pid 18946:tid 19196] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMEQAAAYI"]
[Thu Sep 17 15:32:23.371486 2026] [security2:error] [pid 20162:tid 20393] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF38AAAAfM"]
[Thu Sep 17 15:32:23.399345 2026] [security2:error] [pid 20162:tid 20414] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF38QAAAgg"]
[Thu Sep 17 15:32:23.505496 2026] [security2:error] [pid 18946:tid 19132] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMFwAAAUI"]
[Thu Sep 17 15:32:23.506855 2026] [security2:error] [pid 20162:tid 20297] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF38wAAAZM"]
[Thu Sep 17 15:32:23.550555 2026] [security2:error] [pid 20162:tid 20357] [client 167.172.76.13:58220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxcZa-O_Kk7aqBvaiF3nwABzw4"], referer: http://www.sweetlifelowermills.com/wp/
[Thu Sep 17 15:32:23.560502 2026] [security2:error] [pid 18946:tid 19174] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMGAAAAWw"]
[Thu Sep 17 15:32:23.579645 2026] [security2:error] [pid 20162:tid 20381] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF39gAAAec"]
[Thu Sep 17 15:32:23.594099 2026] [core:error] [pid 18946:tid 19090] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:23.594120 2026] [core:error] [pid 18946:tid 19090] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:23.596757 2026] [security2:error] [pid 20162:tid 20316] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF39wAAAaY"]
[Thu Sep 17 15:32:23.631559 2026] [security2:error] [pid 20162:tid 20395] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF3-AAAAfU"]
[Thu Sep 17 15:32:23.672117 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMHQAAAV4"]
[Thu Sep 17 15:32:23.697981 2026] [security2:error] [pid 20162:tid 20317] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF3-QAAAac"]
[Thu Sep 17 15:32:23.705616 2026] [security2:error] [pid 20162:tid 20412] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF3-gAAAgY"]
[Thu Sep 17 15:32:23.760300 2026] [security2:error] [pid 20162:tid 20314] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF3_AAAAaQ"]
[Thu Sep 17 15:32:23.760300 2026] [security2:error] [pid 18946:tid 19088] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMHwAAARY"]
[Thu Sep 17 15:32:23.783618 2026] [security2:error] [pid 20162:tid 20359] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF3_gAAAdE"]
[Thu Sep 17 15:32:23.863423 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMIQAAARo"]
[Thu Sep 17 15:32:23.870407 2026] [security2:error] [pid 20162:tid 20354] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF3_wAAAcw"]
[Thu Sep 17 15:32:23.883491 2026] [security2:error] [pid 20162:tid 20361] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF4AQAAAdM"]
[Thu Sep 17 15:32:23.886355 2026] [security2:error] [pid 20162:tid 20319] [client 167.172.76.13:58226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxcZ6-O_Kk7aqBvaiF34wABqRM"], referer: http://www.thephoenixprojects.org/new/
[Thu Sep 17 15:32:23.921575 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMJQAAASc"]
[Thu Sep 17 15:32:23.926148 2026] [security2:error] [pid 20162:tid 20394] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxcZ6-O_Kk7aqBvaiF4AgAAAfQ"]
[Thu Sep 17 15:32:23.956779 2026] [security2:error] [pid 18946:tid 19106] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxcZzqiPMah0Tz_U1OMKAAAASg"]
[Thu Sep 17 15:32:24.027702 2026] [security2:error] [pid 18946:tid 19200] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMKQAAAYY"]
[Thu Sep 17 15:32:24.031332 2026] [security2:error] [pid 20162:tid 20318] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4BQAAAag"]
[Thu Sep 17 15:32:24.037721 2026] [security2:error] [pid 20162:tid 20399] [client 167.172.76.13:58220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxcZ6-O_Kk7aqBvaiF4AwAB-Rc"], referer: http://www.sweetlifelowermills.com/new/
[Thu Sep 17 15:32:24.090110 2026] [security2:error] [pid 20162:tid 20330] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4CAAAAbQ"]
[Thu Sep 17 15:32:24.104062 2026] [security2:error] [pid 20162:tid 20407] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4BgAAAgE"]
[Thu Sep 17 15:32:24.112105 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMLQAAARQ"]
[Thu Sep 17 15:32:24.153539 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMLgAAAYc"]
[Thu Sep 17 15:32:24.169590 2026] [security2:error] [pid 20162:tid 20313] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4CgAAAaM"]
[Thu Sep 17 15:32:24.193349 2026] [security2:error] [pid 20162:tid 20370] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4CwAAAdw"]
[Thu Sep 17 15:32:24.198335 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMMAAAASs"]
[Thu Sep 17 15:32:24.259115 2026] [security2:error] [pid 20162:tid 20296] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4DgAAAZI"]
[Thu Sep 17 15:32:24.280825 2026] [security2:error] [pid 20162:tid 20383] [client 34.94.39.26:59508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4EAAAAek"]
[Thu Sep 17 15:32:24.292936 2026] [security2:error] [pid 18946:tid 19198] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMMQAAAYQ"]
[Thu Sep 17 15:32:24.301801 2026] [core:error] [pid 20162:tid 20295] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:24.301817 2026] [core:error] [pid 20162:tid 20295] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:24.322564 2026] [security2:error] [pid 20162:tid 20388] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4FAAAAe4"]
[Thu Sep 17 15:32:24.334363 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMMwAAAVE"]
[Thu Sep 17 15:32:24.375474 2026] [security2:error] [pid 18946:tid 19157] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMNAAAAVs"]
[Thu Sep 17 15:32:24.448252 2026] [security2:error] [pid 20162:tid 20340] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4FwAAAb4"]
[Thu Sep 17 15:32:24.461890 2026] [core:error] [pid 18946:tid 19202] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:24.461907 2026] [core:error] [pid 18946:tid 19202] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:24.530256 2026] [security2:error] [pid 20162:tid 20348] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4GwAAAcY"]
[Thu Sep 17 15:32:24.569896 2026] [security2:error] [pid 20162:tid 20379] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4HAAAAeU"]
[Thu Sep 17 15:32:24.590946 2026] [security2:error] [pid 18946:tid 19100] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMPwAAASI"]
[Thu Sep 17 15:32:24.620964 2026] [security2:error] [pid 18946:tid 19144] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMQQAAAU4"]
[Thu Sep 17 15:32:24.707382 2026] [security2:error] [pid 18946:tid 19158] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMRQAAAVw"]
[Thu Sep 17 15:32:24.752229 2026] [security2:error] [pid 20162:tid 20376] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4IgAAAeI"]
[Thu Sep 17 15:32:24.791949 2026] [security2:error] [pid 20162:tid 20320] [client 103.61.184.148:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcaK-O_Kk7aqBvaiF4IwAAAao"]
[Thu Sep 17 15:32:24.792078 2026] [security2:error] [pid 20162:tid 20320] [client 103.61.184.148:63584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcaK-O_Kk7aqBvaiF4IwAAAao"]
[Thu Sep 17 15:32:24.827258 2026] [security2:error] [pid 20162:tid 20364] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4JQAAAdY"]
[Thu Sep 17 15:32:24.831892 2026] [security2:error] [pid 20162:tid 20398] [client 167.172.76.13:58220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxcaK-O_Kk7aqBvaiF4IAAB-Cg"], referer: http://www.sweetlifelowermills.com/wordpress/
[Thu Sep 17 15:32:24.844718 2026] [security2:error] [pid 18946:tid 19107] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMSgAAASk"]
[Thu Sep 17 15:32:24.877043 2026] [security2:error] [pid 18946:tid 19151] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMTgAAAVU"]
[Thu Sep 17 15:32:24.892343 2026] [security2:error] [pid 20162:tid 20310] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4KAAAAaA"]
[Thu Sep 17 15:32:24.914841 2026] [security2:error] [pid 18946:tid 19191] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMTwAAAX0"]
[Thu Sep 17 15:32:24.964381 2026] [security2:error] [pid 20162:tid 20391] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxcaK-O_Kk7aqBvaiF4KgAAAfE"]
[Thu Sep 17 15:32:24.967214 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMUwAAASY"]
[Thu Sep 17 15:32:24.989437 2026] [security2:error] [pid 18946:tid 19110] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxcaDqiPMah0Tz_U1OMVQAAASw"]
[Thu Sep 17 15:32:25.011260 2026] [security2:error] [pid 18946:tid 19089] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMVgAAARc"]
[Thu Sep 17 15:32:25.019967 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.157.71:43120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "aqxcaTqiPMah0Tz_U1OMWAAAAYk"]
[Thu Sep 17 15:32:25.030962 2026] [security2:error] [pid 20162:tid 20349] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4LQAAAcc"]
[Thu Sep 17 15:32:25.046068 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMWgAAAQ8"]
[Thu Sep 17 15:32:25.046076 2026] [core:error] [pid 20162:tid 20308] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:25.046090 2026] [core:error] [pid 20162:tid 20308] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:25.111607 2026] [security2:error] [pid 20162:tid 20351] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4MQAAAck"]
[Thu Sep 17 15:32:25.154726 2026] [security2:error] [pid 18946:tid 19095] [client 40.81.232.68:62751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxcaTqiPMah0Tz_U1OMXAAAAR0"], referer: binance.com
[Thu Sep 17 15:32:25.167775 2026] [security2:error] [pid 20162:tid 20402] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4MgAAAfw"]
[Thu Sep 17 15:32:25.224263 2026] [security2:error] [pid 18946:tid 19119] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMXQAAATU"]
[Thu Sep 17 15:32:25.248552 2026] [security2:error] [pid 18946:tid 19178] [client 34.166.157.71:43120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "aqxcaTqiPMah0Tz_U1OMXgAAAXA"]
[Thu Sep 17 15:32:25.259558 2026] [security2:error] [pid 18946:tid 19164] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMYAAAAWI"]
[Thu Sep 17 15:32:25.263502 2026] [security2:error] [pid 20162:tid 20321] [client 35.252.83.108:35778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4NQAAAas"]
[Thu Sep 17 15:32:25.315015 2026] [security2:error] [pid 18946:tid 19098] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMYQAAASA"]
[Thu Sep 17 15:32:25.329076 2026] [security2:error] [pid 20162:tid 20335] [client 167.172.76.13:58226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxcaa-O_Kk7aqBvaiF4NgABuSc"], referer: http://www.thephoenixprojects.org/blog/
[Thu Sep 17 15:32:25.351285 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMZAAAATI"]
[Thu Sep 17 15:32:25.368903 2026] [security2:error] [pid 18946:tid 19186] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMZgAAAXg"]
[Thu Sep 17 15:32:25.428654 2026] [security2:error] [pid 18946:tid 19117] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMaAAAATM"]
[Thu Sep 17 15:32:25.439237 2026] [security2:error] [pid 20162:tid 20298] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4NwAAAZQ"]
[Thu Sep 17 15:32:25.490820 2026] [security2:error] [pid 18946:tid 19124] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMbAAAATo"]
[Thu Sep 17 15:32:25.511593 2026] [security2:error] [pid 20162:tid 20303] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4OwAAAZk"]
[Thu Sep 17 15:32:25.544338 2026] [core:error] [pid 20162:tid 20339] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:25.544355 2026] [core:error] [pid 20162:tid 20339] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:25.566818 2026] [security2:error] [pid 18946:tid 19169] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMbgAAAWc"]
[Thu Sep 17 15:32:25.566857 2026] [security2:error] [pid 20162:tid 20323] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4PQAAAa0"]
[Thu Sep 17 15:32:25.581529 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMcAAAAUc"]
[Thu Sep 17 15:32:25.617731 2026] [security2:error] [pid 20162:tid 20403] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4PgAAAf0"]
[Thu Sep 17 15:32:25.629949 2026] [security2:error] [pid 18946:tid 19079] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMcQAAAQ0"]
[Thu Sep 17 15:32:25.631087 2026] [security2:error] [pid 18946:tid 19132] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMcgAAAUI"]
[Thu Sep 17 15:32:25.645754 2026] [security2:error] [pid 18946:tid 19126] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMcwAAATw"]
[Thu Sep 17 15:32:25.704893 2026] [security2:error] [pid 18946:tid 19145] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMdAAAAU8"]
[Thu Sep 17 15:32:25.712841 2026] [security2:error] [pid 20162:tid 20337] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4QgAAAbs"]
[Thu Sep 17 15:32:25.731826 2026] [security2:error] [pid 20162:tid 20420] [client 167.172.76.13:58226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxcaa-O_Kk7aqBvaiF4QQACDiM"], referer: http://www.thephoenixprojects.org/old/
[Thu Sep 17 15:32:25.748053 2026] [security2:error] [pid 18946:tid 19142] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMdgAAAUw"]
[Thu Sep 17 15:32:25.758509 2026] [security2:error] [pid 18946:tid 19174] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMdwAAAWw"]
[Thu Sep 17 15:32:25.799005 2026] [security2:error] [pid 20162:tid 20362] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4QwAAAdQ"]
[Thu Sep 17 15:32:25.803561 2026] [security2:error] [pid 20162:tid 20331] [client 167.172.76.13:58220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxcaa-O_Kk7aqBvaiF4QAABtRw"], referer: http://www.sweetlifelowermills.com/blog/
[Thu Sep 17 15:32:25.807784 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMeAAAAVc"]
[Thu Sep 17 15:32:25.809847 2026] [security2:error] [pid 18946:tid 19168] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMegAAAWY"]
[Thu Sep 17 15:32:25.870800 2026] [security2:error] [pid 18946:tid 19154] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMfAAAAVg"]
[Thu Sep 17 15:32:25.898217 2026] [security2:error] [pid 18946:tid 19130] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMfwAAAUA"]
[Thu Sep 17 15:32:25.900025 2026] [security2:error] [pid 20162:tid 20418] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4RAAAAgw"]
[Thu Sep 17 15:32:25.912166 2026] [security2:error] [pid 18946:tid 19088] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMgAAAARY"]
[Thu Sep 17 15:32:25.968870 2026] [security2:error] [pid 18946:tid 19165] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxcaTqiPMah0Tz_U1OMhgAAAWM"]
[Thu Sep 17 15:32:25.979646 2026] [security2:error] [pid 20162:tid 20417] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4SAAAAgs"]
[Thu Sep 17 15:32:25.999653 2026] [security2:error] [pid 20162:tid 20382] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxcaa-O_Kk7aqBvaiF4SgAAAeg"]
[Thu Sep 17 15:32:26.014236 2026] [security2:error] [pid 18946:tid 19148] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMiAAAAVI"]
[Thu Sep 17 15:32:26.060530 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMiwAAARQ"]
[Thu Sep 17 15:32:26.073255 2026] [security2:error] [pid 18946:tid 19201] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMjAAAAYc"]
[Thu Sep 17 15:32:26.085034 2026] [security2:error] [pid 20162:tid 20312] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4TAAAAaI"]
[Thu Sep 17 15:32:26.121666 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMjQAAASs"]
[Thu Sep 17 15:32:26.136014 2026] [security2:error] [pid 20162:tid 20336] [client 167.172.76.13:58226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxcaq-O_Kk7aqBvaiF4TQABuh8"], referer: http://www.thephoenixprojects.org/backup/
[Thu Sep 17 15:32:26.162643 2026] [security2:error] [pid 18946:tid 19147] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMjgAAAVE"]
[Thu Sep 17 15:32:26.192216 2026] [security2:error] [pid 20162:tid 20414] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4UAAAAgg"]
[Thu Sep 17 15:32:26.220026 2026] [security2:error] [pid 18946:tid 19173] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMkAAAAWs"]
[Thu Sep 17 15:32:26.235264 2026] [security2:error] [pid 20162:tid 20342] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4UQAAAcA"]
[Thu Sep 17 15:32:26.261121 2026] [security2:error] [pid 20162:tid 20297] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4UgAAAZM"]
[Thu Sep 17 15:32:26.289002 2026] [security2:error] [pid 20162:tid 20408] [client 167.172.76.13:58220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxcaq-O_Kk7aqBvaiF4TwACAiY"], referer: http://www.sweetlifelowermills.com/old/
[Thu Sep 17 15:32:26.317257 2026] [security2:error] [pid 20162:tid 20367] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4VAAAAdk"]
[Thu Sep 17 15:32:26.341074 2026] [security2:error] [pid 18946:tid 19149] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMoAAAAVM"]
[Thu Sep 17 15:32:26.350953 2026] [security2:error] [pid 18946:tid 19144] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMoQAAAU4"]
[Thu Sep 17 15:32:26.362927 2026] [security2:error] [pid 20162:tid 20371] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4VQAAAd0"]
[Thu Sep 17 15:32:26.420095 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMpwAAAUY"]
[Thu Sep 17 15:32:26.427210 2026] [security2:error] [pid 20162:tid 20344] [client 79.116.89.151:60727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcaq-O_Kk7aqBvaiF4VwAAAcI"]
[Thu Sep 17 15:32:26.427314 2026] [security2:error] [pid 20162:tid 20344] [client 79.116.89.151:60727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcaq-O_Kk7aqBvaiF4VwAAAcI"]
[Thu Sep 17 15:32:26.463294 2026] [security2:error] [pid 18946:tid 19138] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMqQAAAUg"]
[Thu Sep 17 15:32:26.467073 2026] [core:error] [pid 18946:tid 19158] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:26.467089 2026] [core:error] [pid 18946:tid 19158] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:26.467959 2026] [security2:error] [pid 18946:tid 19172] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMqwAAAWo"]
[Thu Sep 17 15:32:26.500565 2026] [security2:error] [pid 18946:tid 19114] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMrQAAATA"]
[Thu Sep 17 15:32:26.528905 2026] [security2:error] [pid 18946:tid 19125] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMrwAAATs"]
[Thu Sep 17 15:32:26.539499 2026] [security2:error] [pid 20162:tid 20315] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4WQAAAaU"]
[Thu Sep 17 15:32:26.546570 2026] [security2:error] [pid 18946:tid 19159] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMsAAAAV0"]
[Thu Sep 17 15:32:26.627737 2026] [security2:error] [pid 18946:tid 19108] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMsgAAASo"]
[Thu Sep 17 15:32:26.670403 2026] [security2:error] [pid 18946:tid 19089] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMswAAARc"]
[Thu Sep 17 15:32:26.674197 2026] [security2:error] [pid 18946:tid 19087] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMtQAAARU"]
[Thu Sep 17 15:32:26.716112 2026] [security2:error] [pid 18946:tid 19176] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMtgAAAW4"]
[Thu Sep 17 15:32:26.722581 2026] [security2:error] [pid 20162:tid 20314] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4XQAAAaQ"]
[Thu Sep 17 15:32:26.779385 2026] [security2:error] [pid 20162:tid 20386] [client 167.172.76.13:58220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxcaq-O_Kk7aqBvaiF4XAAB7Bs"], referer: http://www.sweetlifelowermills.com/backup/
[Thu Sep 17 15:32:26.783714 2026] [security2:error] [pid 20162:tid 20319] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4XgAAAak"]
[Thu Sep 17 15:32:26.843290 2026] [security2:error] [pid 20162:tid 20355] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4XwAAAc0"]
[Thu Sep 17 15:32:26.857600 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMugAAAUk"]
[Thu Sep 17 15:32:26.857869 2026] [security2:error] [pid 18946:tid 19113] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMuwAAAS8"]
[Thu Sep 17 15:32:26.889936 2026] [security2:error] [pid 20162:tid 20375] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4YgAAAeE"]
[Thu Sep 17 15:32:26.908911 2026] [security2:error] [pid 18946:tid 19094] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMvQAAARw"]
[Thu Sep 17 15:32:26.920170 2026] [security2:error] [pid 18946:tid 19095] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMvwAAAR0"]
[Thu Sep 17 15:32:26.956386 2026] [security2:error] [pid 18946:tid 19119] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMwAAAATU"]
[Thu Sep 17 15:32:26.971082 2026] [security2:error] [pid 20162:tid 20330] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxcaq-O_Kk7aqBvaiF4YwAAAbQ"]
[Thu Sep 17 15:32:26.986557 2026] [security2:error] [pid 18946:tid 19102] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxcajqiPMah0Tz_U1OMxAAAASQ"]
[Thu Sep 17 15:32:27.004819 2026] [security2:error] [pid 18946:tid 19129] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxcazqiPMah0Tz_U1OMxQAAAT8"]
[Thu Sep 17 15:32:27.062770 2026] [security2:error] [pid 18946:tid 19096] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxcazqiPMah0Tz_U1OMxgAAAR4"]
[Thu Sep 17 15:32:27.092361 2026] [security2:error] [pid 18946:tid 19193] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxcazqiPMah0Tz_U1OMxwAAAX8"]
[Thu Sep 17 15:32:27.094694 2026] [security2:error] [pid 18946:tid 19196] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxcazqiPMah0Tz_U1OMyAAAAYI"]
[Thu Sep 17 15:32:27.122282 2026] [security2:error] [pid 20162:tid 20332] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4ZgAAAbY"]
[Thu Sep 17 15:32:27.138807 2026] [security2:error] [pid 18946:tid 19093] [client 144.172.93.238:17482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "missglitterteaches.com"] [uri "/.env"] [unique_id "aqxcazqiPMah0Tz_U1OMywAAARs"]
[Thu Sep 17 15:32:27.146454 2026] [security2:error] [pid 18946:tid 19133] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxcazqiPMah0Tz_U1OMzAAAAUM"]
[Thu Sep 17 15:32:27.183466 2026] [security2:error] [pid 20162:tid 20313] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4ZwAAAaM"]
[Thu Sep 17 15:32:27.214986 2026] [core:error] [pid 18946:tid 19143] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:27.215006 2026] [core:error] [pid 18946:tid 19143] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:27.230151 2026] [security2:error] [pid 18946:tid 19182] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM1gAAAXQ"]
[Thu Sep 17 15:32:27.235426 2026] [security2:error] [pid 20162:tid 20345] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4aAAAAcM"]
[Thu Sep 17 15:32:27.306964 2026] [security2:error] [pid 18946:tid 19145] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM1wAAAU8"]
[Thu Sep 17 15:32:27.334301 2026] [security2:error] [pid 20162:tid 20296] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4aQAAAZI"]
[Thu Sep 17 15:32:27.357600 2026] [security2:error] [pid 18946:tid 19156] [client 143.105.152.240:28959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcazqiPMah0Tz_U1OM2QAAAVo"]
[Thu Sep 17 15:32:27.366749 2026] [security2:error] [pid 18946:tid 19156] [client 143.105.152.240:28959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcazqiPMah0Tz_U1OM2QAAAVo"]
[Thu Sep 17 15:32:27.383772 2026] [security2:error] [pid 18946:tid 19090] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM2wAAARg"]
[Thu Sep 17 15:32:27.385953 2026] [security2:error] [pid 20162:tid 20406] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4bAAAAgA"]
[Thu Sep 17 15:32:27.424284 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM3AAAAVc"]
[Thu Sep 17 15:32:27.462560 2026] [security2:error] [pid 20162:tid 20295] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4bgAAAZE"]
[Thu Sep 17 15:32:27.485997 2026] [security2:error] [pid 18946:tid 19154] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM3gAAAVg"]
[Thu Sep 17 15:32:27.498307 2026] [security2:error] [pid 20162:tid 20352] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4bwAAAco"]
[Thu Sep 17 15:32:27.519772 2026] [security2:error] [pid 18946:tid 19079] [client 144.172.93.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxcazqiPMah0Tz_U1OM0wAAAQ0"]
[Thu Sep 17 15:32:27.528960 2026] [security2:error] [pid 18946:tid 19092] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM4AAAARo"]
[Thu Sep 17 15:32:27.573629 2026] [security2:error] [pid 18946:tid 19197] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM4QAAAYM"]
[Thu Sep 17 15:32:27.627819 2026] [security2:error] [pid 20162:tid 20372] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4cgAAAd4"]
[Thu Sep 17 15:32:27.635467 2026] [security2:error] [pid 18946:tid 19128] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM5gAAAT4"]
[Thu Sep 17 15:32:27.643872 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM5wAAAV4"]
[Thu Sep 17 15:32:27.669869 2026] [security2:error] [pid 20162:tid 20322] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4cwAAAaw"]
[Thu Sep 17 15:32:27.688267 2026] [security2:error] [pid 18946:tid 19194] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM7wAAAYA"]
[Thu Sep 17 15:32:27.736616 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM8QAAAYg"]
[Thu Sep 17 15:32:27.754248 2026] [security2:error] [pid 20162:tid 20396] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4dAAAAfY"]
[Thu Sep 17 15:32:27.826557 2026] [security2:error] [pid 18946:tid 19199] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM8wAAAYU"]
[Thu Sep 17 15:32:27.843330 2026] [security2:error] [pid 18946:tid 19163] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM8gAAAWE"]
[Thu Sep 17 15:32:27.862328 2026] [security2:error] [pid 18946:tid 19190] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM9AAAAXw"]
[Thu Sep 17 15:32:27.877650 2026] [security2:error] [pid 20162:tid 20401] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4dgAAAfs"]
[Thu Sep 17 15:32:27.889365 2026] [security2:error] [pid 18946:tid 19078] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM9gAAAQw"]
[Thu Sep 17 15:32:27.897001 2026] [security2:error] [pid 20162:tid 20340] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4dwAAAb4"]
[Thu Sep 17 15:32:27.926393 2026] [security2:error] [pid 18946:tid 19172] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxcazqiPMah0Tz_U1OM_QAAAWo"]
[Thu Sep 17 15:32:27.943553 2026] [security2:error] [pid 18946:tid 19151] [client 34.94.39.26:59524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxcazqiPMah0Tz_U1ONAQAAAVU"]
[Thu Sep 17 15:32:27.958595 2026] [security2:error] [pid 18946:tid 19157] [client 144.172.93.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxcazqiPMah0Tz_U1OM8AAAAVs"]
[Thu Sep 17 15:32:27.969228 2026] [security2:error] [pid 18946:tid 19100] [client 35.252.83.108:40720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxcazqiPMah0Tz_U1ONAgAAASI"]
[Thu Sep 17 15:32:27.998074 2026] [security2:error] [pid 20162:tid 20374] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxca6-O_Kk7aqBvaiF4eQAAAeA"]
[Thu Sep 17 15:32:28.071406 2026] [security2:error] [pid 18946:tid 19191] [client 74.7.241.186:49038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.wzhconsulting.com"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "aqxcbDqiPMah0Tz_U1ONBgAAAX0"]
[Thu Sep 17 15:32:28.085385 2026] [core:error] [pid 18946:tid 19104] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:28.085403 2026] [core:error] [pid 18946:tid 19104] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:28.086784 2026] [autoindex:error] [pid 20162:tid 20307] [client 35.228.71.49:38368] AH01276: Cannot serve directory /home1/mimsjomy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:32:28.120343 2026] [security2:error] [pid 20162:tid 20348] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4fQAAAcY"]
[Thu Sep 17 15:32:28.152672 2026] [security2:error] [pid 20162:tid 20380] [client 74.7.228.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "herbslee.com"] [uri "/index.php"] [unique_id "aqxca6-O_Kk7aqBvaiF4eAAAAeY"]
[Thu Sep 17 15:32:28.161364 2026] [security2:error] [pid 18946:tid 19086] [client 74.7.228.20:33584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "herbslee.com"] [uri "/robots.txt"] [unique_id "aqxcazqiPMah0Tz_U1OM7AABFA4"]
[Thu Sep 17 15:32:28.225838 2026] [security2:error] [pid 20162:tid 20327] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4fwAAAbE"]
[Thu Sep 17 15:32:28.290753 2026] [security2:error] [pid 18946:tid 19111] [client 40.81.232.68:65145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxcbDqiPMah0Tz_U1ONEAAAAS0"], referer: binance.com
[Thu Sep 17 15:32:28.291688 2026] [security2:error] [pid 20162:tid 20390] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4gQAAAfA"]
[Thu Sep 17 15:32:28.291760 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONDwAAAUk"]
[Thu Sep 17 15:32:28.342425 2026] [security2:error] [pid 18946:tid 19186] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONEgAAAXg"]
[Thu Sep 17 15:32:28.342479 2026] [security2:error] [pid 20162:tid 20320] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4gwAAAao"]
[Thu Sep 17 15:32:28.364984 2026] [core:error] [pid 20162:tid 20387] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:28.365001 2026] [core:error] [pid 20162:tid 20387] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:28.373680 2026] [security2:error] [pid 20162:tid 20364] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4hQAAAdY"]
[Thu Sep 17 15:32:28.400730 2026] [security2:error] [pid 18946:tid 19117] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONFgAAATM"]
[Thu Sep 17 15:32:28.417188 2026] [security2:error] [pid 20162:tid 20310] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4hgAAAaA"]
[Thu Sep 17 15:32:28.418932 2026] [security2:error] [pid 18946:tid 19181] [client 144.172.93.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxcbDqiPMah0Tz_U1ONCgAAAXM"]
[Thu Sep 17 15:32:28.419651 2026] [security2:error] [pid 18946:tid 19193] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONGwAAAX8"]
[Thu Sep 17 15:32:28.479412 2026] [security2:error] [pid 20162:tid 20326] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4hwAAAbA"]
[Thu Sep 17 15:32:28.484377 2026] [security2:error] [pid 18946:tid 19143] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONHQAAAU0"]
[Thu Sep 17 15:32:28.515621 2026] [security2:error] [pid 18946:tid 19115] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONHwAAATE"]
[Thu Sep 17 15:32:28.640272 2026] [security2:error] [pid 20162:tid 20360] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4iwAAAdI"]
[Thu Sep 17 15:32:28.649427 2026] [security2:error] [pid 18946:tid 19118] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONJQAAATQ"]
[Thu Sep 17 15:32:28.673743 2026] [core:error] [pid 18946:tid 19088] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:28.673765 2026] [core:error] [pid 18946:tid 19088] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:28.691514 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONKwAAARo"]
[Thu Sep 17 15:32:28.732759 2026] [security2:error] [pid 18946:tid 19130] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONLgAAAUA"]
[Thu Sep 17 15:32:28.785029 2026] [security2:error] [pid 18946:tid 19155] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONMAAAAVk"]
[Thu Sep 17 15:32:28.808424 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONMgAAASc"]
[Thu Sep 17 15:32:28.865690 2026] [security2:error] [pid 18946:tid 19168] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONNgAAAWY"]
[Thu Sep 17 15:32:28.870187 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONNwAAAYc"]
[Thu Sep 17 15:32:28.870228 2026] [security2:error] [pid 20162:tid 20308] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4jgAAAZ4"]
[Thu Sep 17 15:32:28.900159 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONOQAAAV4"]
[Thu Sep 17 15:32:28.922009 2026] [security2:error] [pid 20162:tid 20366] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxcbK-O_Kk7aqBvaiF4kAAAAdg"]
[Thu Sep 17 15:32:28.981102 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONOwAAAYg"]
[Thu Sep 17 15:32:28.987084 2026] [security2:error] [pid 18946:tid 19175] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxcbDqiPMah0Tz_U1ONPAAAAW0"]
[Thu Sep 17 15:32:29.012503 2026] [security2:error] [pid 18946:tid 19197] [client 144.172.93.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxcbDqiPMah0Tz_U1ONLwAAAYM"]
[Thu Sep 17 15:32:29.033862 2026] [security2:error] [pid 20162:tid 20347] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4kQAAAcU"]
[Thu Sep 17 15:32:29.063233 2026] [security2:error] [pid 18946:tid 19146] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONPwAAAVA"]
[Thu Sep 17 15:32:29.086403 2026] [security2:error] [pid 20162:tid 20402] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4lAAAAfw"]
[Thu Sep 17 15:32:29.177395 2026] [security2:error] [pid 18946:tid 19198] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONRgAAAYQ"]
[Thu Sep 17 15:32:29.177418 2026] [security2:error] [pid 18946:tid 19158] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONRwAAAVw"]
[Thu Sep 17 15:32:29.178517 2026] [security2:error] [pid 20162:tid 20334] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4lQAAAbg"]
[Thu Sep 17 15:32:29.246944 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONSwAAAUY"]
[Thu Sep 17 15:32:29.254049 2026] [security2:error] [pid 18946:tid 19149] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONTQAAAVM"]
[Thu Sep 17 15:32:29.263919 2026] [security2:error] [pid 20162:tid 20321] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4lgAAAas"]
[Thu Sep 17 15:32:29.283211 2026] [security2:error] [pid 18946:tid 19188] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONTgAAAXo"]
[Thu Sep 17 15:32:29.295689 2026] [security2:error] [pid 20162:tid 20335] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4lwAAAbk"]
[Thu Sep 17 15:32:29.321889 2026] [security2:error] [pid 20162:tid 20346] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4mgAAAcQ"]
[Thu Sep 17 15:32:29.336013 2026] [security2:error] [pid 18946:tid 19087] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONUQAAARU"]
[Thu Sep 17 15:32:29.340295 2026] [security2:error] [pid 20162:tid 20411] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4mwAAAgU"]
[Thu Sep 17 15:32:29.404019 2026] [security2:error] [pid 20162:tid 20378] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4nAAAAeQ"]
[Thu Sep 17 15:32:29.412827 2026] [security2:error] [pid 18946:tid 19144] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONVAAAAU4"]
[Thu Sep 17 15:32:29.440884 2026] [security2:error] [pid 18946:tid 19122] [client 144.172.93.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxcbTqiPMah0Tz_U1ONSAAAATg"]
[Thu Sep 17 15:32:29.468979 2026] [security2:error] [pid 18946:tid 19141] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONWAAAAUs"]
[Thu Sep 17 15:32:29.477886 2026] [core:error] [pid 20162:tid 20323] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:29.477905 2026] [core:error] [pid 20162:tid 20323] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:29.510290 2026] [security2:error] [pid 18946:tid 19085] [client 144.172.93.238:17482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "missglitterteaches.com"] [uri "/.env.backup"] [unique_id "aqxcbTqiPMah0Tz_U1ONWgAAARM"]
[Thu Sep 17 15:32:29.521798 2026] [security2:error] [pid 20162:tid 20403] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4nwAAAf0"]
[Thu Sep 17 15:32:29.540386 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONXQAAARQ"]
[Thu Sep 17 15:32:29.544805 2026] [security2:error] [pid 18946:tid 19169] [client 144.172.93.238:17482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "missglitterteaches.com"] [uri "/.env.bak"] [unique_id "aqxcbTqiPMah0Tz_U1ONXgAAAWc"]
[Thu Sep 17 15:32:29.554517 2026] [security2:error] [pid 18946:tid 19131] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONXwAAAUE"]
[Thu Sep 17 15:32:29.565737 2026] [security2:error] [pid 18946:tid 19178] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONYAAAAXA"]
[Thu Sep 17 15:32:29.580434 2026] [security2:error] [pid 18946:tid 19129] [client 144.172.93.238:17482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "missglitterteaches.com"] [uri "/.env.old"] [unique_id "aqxcbTqiPMah0Tz_U1ONYgAAAT8"]
[Thu Sep 17 15:32:29.596065 2026] [security2:error] [pid 20162:tid 20337] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4oQAAAbs"]
[Thu Sep 17 15:32:29.612014 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONYwAAAUk"]
[Thu Sep 17 15:32:29.622539 2026] [security2:error] [pid 18946:tid 19106] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONZgAAASg"]
[Thu Sep 17 15:32:29.725028 2026] [security2:error] [pid 18946:tid 19143] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONaAAAAU0"]
[Thu Sep 17 15:32:29.760597 2026] [security2:error] [pid 18946:tid 19115] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONagAAATE"]
[Thu Sep 17 15:32:29.780123 2026] [security2:error] [pid 18946:tid 19076] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONbAAAAQo"]
[Thu Sep 17 15:32:29.782308 2026] [security2:error] [pid 20162:tid 20294] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4pwAAAZA"]
[Thu Sep 17 15:32:29.817864 2026] [security2:error] [pid 18946:tid 19145] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONbgAAAU8"]
[Thu Sep 17 15:32:29.849746 2026] [security2:error] [pid 18946:tid 19108] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONbwAAASo"]
[Thu Sep 17 15:32:29.875744 2026] [security2:error] [pid 20162:tid 20331] [client 144.172.93.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxcba-O_Kk7aqBvaiF4pAAAAbU"]
[Thu Sep 17 15:32:29.876105 2026] [security2:error] [pid 20162:tid 20389] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4qQAAAe8"]
[Thu Sep 17 15:32:29.876110 2026] [security2:error] [pid 18946:tid 19183] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONcAAAAXU"]
[Thu Sep 17 15:32:29.901211 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONcQAAAWQ"]
[Thu Sep 17 15:32:29.920221 2026] [security2:error] [pid 18946:tid 19156] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONcwAAAVo"]
[Thu Sep 17 15:32:29.949261 2026] [security2:error] [pid 18946:tid 19174] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONdgAAAWw"]
[Thu Sep 17 15:32:29.960950 2026] [security2:error] [pid 18946:tid 19118] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxcbTqiPMah0Tz_U1ONeAAAATQ"]
[Thu Sep 17 15:32:29.961248 2026] [security2:error] [pid 18946:tid 19187] [client 144.172.93.238:17482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.93.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "missglitterteaches.com"] [uri "/.env.php"] [unique_id "aqxcbTqiPMah0Tz_U1ONdwAAAXk"]
[Thu Sep 17 15:32:29.967384 2026] [security2:error] [pid 20162:tid 20333] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxcba-O_Kk7aqBvaiF4rAAAAbc"]
[Thu Sep 17 15:32:30.029890 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONfAAAAUc"]
[Thu Sep 17 15:32:30.057207 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONfwAAASc"]
[Thu Sep 17 15:32:30.066038 2026] [security2:error] [pid 18946:tid 19154] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONgQAAAVg"]
[Thu Sep 17 15:32:30.109574 2026] [security2:error] [pid 20162:tid 20365] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4sAAAAdc"]
[Thu Sep 17 15:32:30.160116 2026] [security2:error] [pid 18946:tid 19201] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONhgAAAYc"]
[Thu Sep 17 15:32:30.221014 2026] [security2:error] [pid 20162:tid 20393] [client 34.166.157.71:42288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4swAAAfM"]
[Thu Sep 17 15:32:30.236345 2026] [security2:error] [pid 20162:tid 20381] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4tAAAAec"]
[Thu Sep 17 15:32:30.248766 2026] [security2:error] [pid 18946:tid 19175] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONjAAAAW0"]
[Thu Sep 17 15:32:30.250699 2026] [security2:error] [pid 18946:tid 19197] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONjQAAAYM"]
[Thu Sep 17 15:32:30.345284 2026] [security2:error] [pid 20162:tid 20293] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4twAAAY8"]
[Thu Sep 17 15:32:30.373278 2026] [security2:error] [pid 18946:tid 19161] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONlQAAAV8"]
[Thu Sep 17 15:32:30.373750 2026] [security2:error] [pid 18946:tid 19189] [client 144.172.93.238:34218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.93.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "missglitterteaches.com"] [uri "/.env.php"] [unique_id "aqxcbjqiPMah0Tz_U1ONlgAAAXs"]
[Thu Sep 17 15:32:30.410599 2026] [security2:error] [pid 18946:tid 19170] [client 34.94.39.26:59540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONmQAAAWg"]
[Thu Sep 17 15:32:30.416846 2026] [security2:error] [pid 18946:tid 19158] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONmgAAAVw"]
[Thu Sep 17 15:32:30.436391 2026] [security2:error] [pid 20162:tid 20314] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4uQAAAaQ"]
[Thu Sep 17 15:32:30.451768 2026] [security2:error] [pid 20162:tid 20354] [client 34.166.157.71:42288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/apps/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4ugAAAcw"]
[Thu Sep 17 15:32:30.468338 2026] [security2:error] [pid 20162:tid 20319] [client 34.94.39.26:59534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodymalek.com"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4vQAAAak"]
[Thu Sep 17 15:32:30.488197 2026] [security2:error] [pid 18946:tid 19188] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONnwAAAXo"]
[Thu Sep 17 15:32:30.521804 2026] [security2:error] [pid 20162:tid 20316] [client 114.198.138.124:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcbq-O_Kk7aqBvaiF4vwAAAaY"]
[Thu Sep 17 15:32:30.521933 2026] [security2:error] [pid 20162:tid 20316] [client 114.198.138.124:54942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcbq-O_Kk7aqBvaiF4vwAAAaY"]
[Thu Sep 17 15:32:30.523298 2026] [security2:error] [pid 20162:tid 20355] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxcbq-O_Kk7aqBvaiF4vgAAAc0"]
[Thu Sep 17 15:32:30.534334 2026] [security2:error] [pid 20162:tid 20375] [client 34.94.39.26:59534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/phpinfo.php"] [unique_id "aqxcbq-O_Kk7aqBvaiF4wAAAAeE"]
[Thu Sep 17 15:32:30.564749 2026] [security2:error] [pid 18946:tid 19203] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONpwAAAYk"]
[Thu Sep 17 15:32:30.569092 2026] [core:error] [pid 18946:tid 19083] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:30.569108 2026] [core:error] [pid 18946:tid 19083] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:30.671027 2026] [security2:error] [pid 18946:tid 19102] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONrQAAASQ"]
[Thu Sep 17 15:32:30.684352 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.39.26:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/info.php"] [unique_id "aqxcbjqiPMah0Tz_U1ONrgAAARQ"]
[Thu Sep 17 15:32:30.684963 2026] [security2:error] [pid 20162:tid 20313] [client 34.166.157.71:42288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4wwAAAaM"]
[Thu Sep 17 15:32:30.701413 2026] [security2:error] [pid 20162:tid 20345] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxcbq-O_Kk7aqBvaiF4xAAAAcM"]
[Thu Sep 17 15:32:30.728025 2026] [security2:error] [pid 18946:tid 19098] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONsAAAASA"]
[Thu Sep 17 15:32:30.811163 2026] [security2:error] [pid 18946:tid 19125] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONtQAAATs"]
[Thu Sep 17 15:32:30.858410 2026] [security2:error] [pid 18946:tid 19181] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONuQAAAXM"]
[Thu Sep 17 15:32:30.883937 2026] [core:error] [pid 18946:tid 19164] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:30.883958 2026] [core:error] [pid 18946:tid 19164] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:30.896147 2026] [security2:error] [pid 18946:tid 19143] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONvAAAAU0"]
[Thu Sep 17 15:32:30.916746 2026] [security2:error] [pid 20162:tid 20383] [client 34.166.157.71:42288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/web/.env"] [unique_id "aqxcbq-O_Kk7aqBvaiF4ygAAAek"]
[Thu Sep 17 15:32:30.941494 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.39.26:38274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/php.php"] [unique_id "aqxcbjqiPMah0Tz_U1ONvwAAATI"]
[Thu Sep 17 15:32:30.951861 2026] [security2:error] [pid 18946:tid 19104] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxcbjqiPMah0Tz_U1ONwAAAASY"]
[Thu Sep 17 15:32:31.063652 2026] [security2:error] [pid 20162:tid 20372] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxcb6-O_Kk7aqBvaiF4zAAAAd4"]
[Thu Sep 17 15:32:31.113633 2026] [security2:error] [pid 18946:tid 19187] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ONxwAAAXk"]
[Thu Sep 17 15:32:31.145207 2026] [security2:error] [pid 20162:tid 20322] [client 34.166.157.71:42288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/site/.env"] [unique_id "aqxcb6-O_Kk7aqBvaiF4zQAAAaw"]
[Thu Sep 17 15:32:31.189458 2026] [security2:error] [pid 18946:tid 19137] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ONygAAAUc"]
[Thu Sep 17 15:32:31.234124 2026] [security2:error] [pid 18946:tid 19154] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ONzAAAAVg"]
[Thu Sep 17 15:32:31.298064 2026] [security2:error] [pid 18946:tid 19171] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ONzgAAAWk"]
[Thu Sep 17 15:32:31.305508 2026] [security2:error] [pid 18946:tid 19090] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON0AAAARg"]
[Thu Sep 17 15:32:31.354984 2026] [security2:error] [pid 18946:tid 19121] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON0gAAATc"]
[Thu Sep 17 15:32:31.382714 2026] [security2:error] [pid 20162:tid 20401] [client 34.166.157.71:42288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/public/.env"] [unique_id "aqxcb6-O_Kk7aqBvaiF40AAAAfs"]
[Thu Sep 17 15:32:31.392508 2026] [security2:error] [pid 18946:tid 19165] [client 34.94.39.26:38288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/i.php"] [unique_id "aqxcbzqiPMah0Tz_U1ON0wAAAWM"]
[Thu Sep 17 15:32:31.401822 2026] [security2:error] [pid 18946:tid 19124] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON1AAAATo"]
[Thu Sep 17 15:32:31.425943 2026] [security2:error] [pid 18946:tid 19126] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON2QAAATw"]
[Thu Sep 17 15:32:31.480189 2026] [security2:error] [pid 18946:tid 19175] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON3AAAAW0"]
[Thu Sep 17 15:32:31.486123 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON3gAAAYg"]
[Thu Sep 17 15:32:31.521250 2026] [security2:error] [pid 18946:tid 19146] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON4AAAAVA"]
[Thu Sep 17 15:32:31.523321 2026] [security2:error] [pid 18946:tid 19078] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON4QAAAQw"]
[Thu Sep 17 15:32:31.559496 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON4wAAAVc"]
[Thu Sep 17 15:32:31.622734 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.39.26:38296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/pi.php"] [unique_id "aqxcbzqiPMah0Tz_U1ON5QAAAR8"]
[Thu Sep 17 15:32:31.661071 2026] [security2:error] [pid 18946:tid 19100] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON5gAAASI"]
[Thu Sep 17 15:32:31.667495 2026] [security2:error] [pid 18946:tid 19189] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON5wAAAXs"]
[Thu Sep 17 15:32:31.677289 2026] [security2:error] [pid 18946:tid 19109] [client 4.240.114.86:54125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxcbzqiPMah0Tz_U1ON6AAAASs"], referer: binance.com
[Thu Sep 17 15:32:31.710012 2026] [core:error] [pid 20162:tid 20348] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:31.710028 2026] [core:error] [pid 20162:tid 20348] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:31.718351 2026] [security2:error] [pid 18946:tid 19170] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON6wAAAWg"]
[Thu Sep 17 15:32:31.808867 2026] [security2:error] [pid 18946:tid 19188] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON7QAAAXo"]
[Thu Sep 17 15:32:31.812989 2026] [security2:error] [pid 18946:tid 19159] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON7gAAAV0"]
[Thu Sep 17 15:32:31.870200 2026] [security2:error] [pid 18946:tid 19136] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON7wAAAUY"]
[Thu Sep 17 15:32:31.874367 2026] [security2:error] [pid 18946:tid 19148] [client 34.94.39.26:38312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/pinfo.php"] [unique_id "aqxcbzqiPMah0Tz_U1ON8AAAAVI"]
[Thu Sep 17 15:32:31.908155 2026] [security2:error] [pid 18946:tid 19144] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON8QAAAU4"]
[Thu Sep 17 15:32:31.955154 2026] [security2:error] [pid 18946:tid 19203] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON9gAAAYk"]
[Thu Sep 17 15:32:31.975711 2026] [security2:error] [pid 18946:tid 19150] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxcbzqiPMah0Tz_U1ON-AAAAVQ"]
[Thu Sep 17 15:32:32.024941 2026] [security2:error] [pid 18946:tid 19085] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxccDqiPMah0Tz_U1ON-QAAARM"]
[Thu Sep 17 15:32:32.026958 2026] [security2:error] [pid 18946:tid 19087] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxccDqiPMah0Tz_U1ON-gAAARU"]
[Thu Sep 17 15:32:32.056962 2026] [security2:error] [pid 18946:tid 19119] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxccDqiPMah0Tz_U1ON_AAAATU"]
[Thu Sep 17 15:32:32.113961 2026] [security2:error] [pid 18946:tid 19094] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxccDqiPMah0Tz_U1ON_wAAARw"]
[Thu Sep 17 15:32:32.148851 2026] [security2:error] [pid 18946:tid 19084] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOAAAAARI"]
[Thu Sep 17 15:32:32.177163 2026] [security2:error] [pid 18946:tid 19185] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOAgAAAXc"]
[Thu Sep 17 15:32:32.222196 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOCAAAARQ"]
[Thu Sep 17 15:32:32.232853 2026] [security2:error] [pid 18946:tid 19131] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOCQAAAUE"]
[Thu Sep 17 15:32:32.270237 2026] [security2:error] [pid 18946:tid 19091] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOCgAAARk"]
[Thu Sep 17 15:32:32.274439 2026] [security2:error] [pid 18946:tid 19178] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOCwAAAXA"]
[Thu Sep 17 15:32:32.286450 2026] [security2:error] [pid 18946:tid 19182] [client 34.94.39.26:38320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/test.php"] [unique_id "aqxccDqiPMah0Tz_U1OODgAAAXQ"]
[Thu Sep 17 15:32:32.300594 2026] [security2:error] [pid 18946:tid 19110] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxccDqiPMah0Tz_U1OODwAAASw"]
[Thu Sep 17 15:32:32.347802 2026] [security2:error] [pid 18946:tid 19129] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOEAAAAT8"]
[Thu Sep 17 15:32:32.347969 2026] [security2:error] [pid 18946:tid 19173] [client 40.81.232.68:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxccDqiPMah0Tz_U1OOEQAAAWs"], referer: binance.com
[Thu Sep 17 15:32:32.359349 2026] [security2:error] [pid 18946:tid 19099] [client 162.241.226.11:59430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxcbzqiPMah0Tz_U1ON3wAAAXw"]
[Thu Sep 17 15:32:32.405420 2026] [security2:error] [pid 18946:tid 19162] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOEgAAAWA"]
[Thu Sep 17 15:32:32.405458 2026] [security2:error] [pid 20162:tid 20387] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "aqxccK-O_Kk7aqBvaiF42wAAAe0"]
[Thu Sep 17 15:32:32.462576 2026] [security2:error] [pid 18946:tid 19134] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOFgAAAUQ"]
[Thu Sep 17 15:32:32.517116 2026] [security2:error] [pid 18946:tid 19116] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOGQAAATI"]
[Thu Sep 17 15:32:32.599801 2026] [core:error] [pid 20162:tid 20358] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:32.599828 2026] [core:error] [pid 20162:tid 20358] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:32.626878 2026] [security2:error] [pid 18946:tid 19183] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOHAAAAXU"]
[Thu Sep 17 15:32:32.633941 2026] [security2:error] [pid 18946:tid 19156] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOHQAAAVo"]
[Thu Sep 17 15:32:32.633941 2026] [security2:error] [pid 20162:tid 20308] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/server/.env"] [unique_id "aqxccK-O_Kk7aqBvaiF45AAAAZ4"]
[Thu Sep 17 15:32:32.736345 2026] [security2:error] [pid 18946:tid 19132] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOIgAAAUI"]
[Thu Sep 17 15:32:32.749501 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOIwAAAUc"]
[Thu Sep 17 15:32:32.842134 2026] [security2:error] [pid 18946:tid 19163] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOJwAAAWE"]
[Thu Sep 17 15:32:32.862990 2026] [security2:error] [pid 20162:tid 20392] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/frontend/.env"] [unique_id "aqxccK-O_Kk7aqBvaiF45wAAAfI"]
[Thu Sep 17 15:32:32.868296 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOKAAAAVc"]
[Thu Sep 17 15:32:32.884819 2026] [security2:error] [pid 18946:tid 19180] [client 3.82.141.143:36340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.ivorygarlock.com"] [uri "/wp-config.php.old"] [unique_id "aqxccDqiPMah0Tz_U1OOLQAAAXI"]
[Thu Sep 17 15:32:32.885824 2026] [security2:error] [pid 18946:tid 19176] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOKwAAAW4"]
[Thu Sep 17 15:32:32.886523 2026] [security2:error] [pid 20162:tid 20419] [client 84.139.25.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxccK-O_Kk7aqBvaiF45QAAAg0"]
[Thu Sep 17 15:32:32.886770 2026] [security2:error] [pid 18946:tid 19201] [client 3.82.141.143:36348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.ivorygarlock.com"] [uri "/wp-config.php.save"] [unique_id "aqxccDqiPMah0Tz_U1OOMQAAAYc"]
[Thu Sep 17 15:32:32.887078 2026] [security2:error] [pid 20162:tid 20334] [client 3.82.141.143:36316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.ivorygarlock.com"] [uri "/wp-config.php.bak"] [unique_id "aqxccK-O_Kk7aqBvaiF47QAAAbg"]
[Thu Sep 17 15:32:32.887357 2026] [security2:error] [pid 18946:tid 19101] [client 3.82.141.143:36050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.ivorygarlock.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "aqxccDqiPMah0Tz_U1OOLgAAASM"]
[Thu Sep 17 15:32:32.889087 2026] [security2:error] [pid 20162:tid 20346] [client 3.82.141.143:36350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.ivorygarlock.com"] [uri "/wp-config.php~"] [unique_id "aqxccK-O_Kk7aqBvaiF48QAAAcQ"]
[Thu Sep 17 15:32:32.889146 2026] [security2:error] [pid 18946:tid 19128] [client 3.82.141.143:36310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ivorygarlock.com"] [uri "/wp-config.php"] [unique_id "aqxccDqiPMah0Tz_U1OONgAAAT4"]
[Thu Sep 17 15:32:32.889967 2026] [security2:error] [pid 18946:tid 19194] [client 3.82.141.143:36008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.ivorygarlock.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxccDqiPMah0Tz_U1OONQAAAYA"]
[Thu Sep 17 15:32:32.890341 2026] [security2:error] [pid 20162:tid 20321] [client 3.82.141.143:36156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "cpanel.ivorygarlock.com"] [uri "/___proxy_subdomain_cpanel/web.config"] [unique_id "aqxccK-O_Kk7aqBvaiF47wAAAas"]
[Thu Sep 17 15:32:32.891042 2026] [security2:error] [pid 20162:tid 20306] [client 3.82.141.143:36036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.ivorygarlock.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "aqxccK-O_Kk7aqBvaiF48wAAAZw"]
[Thu Sep 17 15:32:32.894580 2026] [security2:error] [pid 18946:tid 19198] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxccDqiPMah0Tz_U1OOPAAAAYQ"]
[Thu Sep 17 15:32:32.896101 2026] [security2:error] [pid 18946:tid 19175] [client 3.82.141.143:36030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.ivorygarlock.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "aqxccDqiPMah0Tz_U1OOQgAAAW0"]
[Thu Sep 17 15:32:32.901455 2026] [security2:error] [pid 18946:tid 19146] [client 3.82.141.143:36120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ivorygarlock.com"] [uri "/config.php"] [unique_id "aqxccDqiPMah0Tz_U1OOSAAAAVA"]
[Thu Sep 17 15:32:32.954226 2026] [security2:error] [pid 20162:tid 20337] [client 34.94.39.26:38342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/p.php"] [unique_id "aqxccK-O_Kk7aqBvaiF5CAAAAbs"]
[Thu Sep 17 15:32:32.988938 2026] [core:error] [pid 18946:tid 19148] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:32.988961 2026] [core:error] [pid 18946:tid 19148] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:32.996354 2026] [core:error] [pid 18946:tid 19095] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:32.996382 2026] [core:error] [pid 18946:tid 19095] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.001181 2026] [core:error] [pid 18946:tid 19192] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.001206 2026] [core:error] [pid 18946:tid 19192] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.001247 2026] [core:error] [pid 18946:tid 19196] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.001258 2026] [core:error] [pid 18946:tid 19196] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.001757 2026] [core:error] [pid 20162:tid 20418] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.001775 2026] [core:error] [pid 20162:tid 20418] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.002735 2026] [core:error] [pid 20162:tid 20344] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.002751 2026] [core:error] [pid 20162:tid 20344] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.002847 2026] [core:error] [pid 18946:tid 19199] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.002858 2026] [core:error] [pid 18946:tid 19199] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.003343 2026] [core:error] [pid 20162:tid 20357] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.003354 2026] [core:error] [pid 20162:tid 20357] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.003393 2026] [core:error] [pid 20162:tid 20412] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.003411 2026] [core:error] [pid 20162:tid 20412] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.005624 2026] [core:error] [pid 20162:tid 20298] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.005654 2026] [core:error] [pid 20162:tid 20298] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.005821 2026] [core:error] [pid 20162:tid 20384] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.005833 2026] [core:error] [pid 20162:tid 20384] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.007167 2026] [core:error] [pid 20162:tid 20393] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.007182 2026] [core:error] [pid 20162:tid 20393] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.008376 2026] [core:error] [pid 18946:tid 19131] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.008390 2026] [core:error] [pid 18946:tid 19131] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.009212 2026] [core:error] [pid 20162:tid 20381] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.009227 2026] [core:error] [pid 20162:tid 20381] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.010115 2026] [core:error] [pid 20162:tid 20317] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.010126 2026] [core:error] [pid 20162:tid 20317] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.011355 2026] [core:error] [pid 18946:tid 19169] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.011376 2026] [core:error] [pid 18946:tid 19169] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.014954 2026] [core:error] [pid 18946:tid 19091] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.014968 2026] [core:error] [pid 18946:tid 19091] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.016994 2026] [core:error] [pid 20162:tid 20301] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.017009 2026] [core:error] [pid 20162:tid 20301] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.018849 2026] [security2:error] [pid 18946:tid 19077] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOWwAAAQs"]
[Thu Sep 17 15:32:33.031761 2026] [core:error] [pid 18946:tid 19103] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.031781 2026] [core:error] [pid 18946:tid 19103] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.036085 2026] [core:error] [pid 18946:tid 19139] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.036104 2026] [core:error] [pid 18946:tid 19139] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.036376 2026] [core:error] [pid 20162:tid 20332] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.036389 2026] [core:error] [pid 20162:tid 20332] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.044087 2026] [security2:error] [pid 18946:tid 19134] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOXgAAAUQ"]
[Thu Sep 17 15:32:33.095584 2026] [security2:error] [pid 20162:tid 20376] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/src/.env"] [unique_id "aqxcca-O_Kk7aqBvaiF5FQAAAeI"]
[Thu Sep 17 15:32:33.103081 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOYgAAARo"]
[Thu Sep 17 15:32:33.137067 2026] [security2:error] [pid 18946:tid 19193] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOYwAAAX8"]
[Thu Sep 17 15:32:33.172108 2026] [security2:error] [pid 18946:tid 19191] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOZgAAAX0"]
[Thu Sep 17 15:32:33.224682 2026] [security2:error] [pid 18946:tid 19180] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOZwAAAXI"]
[Thu Sep 17 15:32:33.273075 2026] [security2:error] [pid 18946:tid 19090] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOagAAARg"]
[Thu Sep 17 15:32:33.287293 2026] [core:error] [pid 18946:tid 19184] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.287311 2026] [core:error] [pid 18946:tid 19184] [client 3.82.141.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:33.288482 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxccTqiPMah0Tz_U1OObQAAAXk"]
[Thu Sep 17 15:32:33.289828 2026] [security2:error] [pid 20162:tid 20391] [client 162.241.226.11:12424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxccK-O_Kk7aqBvaiF43AAAAaA"]
[Thu Sep 17 15:32:33.318511 2026] [security2:error] [pid 20162:tid 20408] [client 136.158.61.34:53517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcca-O_Kk7aqBvaiF5FwAAAgI"]
[Thu Sep 17 15:32:33.320991 2026] [security2:error] [pid 20162:tid 20408] [client 136.158.61.34:53517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcca-O_Kk7aqBvaiF5FwAAAgI"]
[Thu Sep 17 15:32:33.324798 2026] [security2:error] [pid 20162:tid 20307] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/core/.env"] [unique_id "aqxcca-O_Kk7aqBvaiF5GAAAAZ0"]
[Thu Sep 17 15:32:33.358325 2026] [security2:error] [pid 18946:tid 19194] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxccTqiPMah0Tz_U1OObgAAAYA"]
[Thu Sep 17 15:32:33.368774 2026] [security2:error] [pid 18946:tid 19198] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxccTqiPMah0Tz_U1OObwAAAYQ"]
[Thu Sep 17 15:32:33.442389 2026] [security2:error] [pid 18946:tid 19078] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOcgAAAQw"]
[Thu Sep 17 15:32:33.448384 2026] [security2:error] [pid 20162:tid 20349] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxcca-O_Kk7aqBvaiF5GgAAAcc"]
[Thu Sep 17 15:32:33.462233 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.39.26:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/debug.php"] [unique_id "aqxccTqiPMah0Tz_U1OOdQAAAVA"]
[Thu Sep 17 15:32:33.470798 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOdgAAAYg"]
[Thu Sep 17 15:32:33.539037 2026] [security2:error] [pid 18946:tid 19080] [client 35.252.83.108:40748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOeQAAAQ4"]
[Thu Sep 17 15:32:33.558708 2026] [security2:error] [pid 20162:tid 20413] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/core/app/.env"] [unique_id "aqxcca-O_Kk7aqBvaiF5GwAAAgc"]
[Thu Sep 17 15:32:33.626327 2026] [security2:error] [pid 20162:tid 20362] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/.env~"] [unique_id "aqxcca-O_Kk7aqBvaiF5HgAAAdQ"]
[Thu Sep 17 15:32:33.661319 2026] [security2:error] [pid 18946:tid 19119] [client 35.252.83.108:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxccTqiPMah0Tz_U1OOfgAAATU"]
[Thu Sep 17 15:32:33.793376 2026] [security2:error] [pid 20162:tid 20321] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "aqxcca-O_Kk7aqBvaiF5IQAAAas"]
[Thu Sep 17 15:32:33.834258 2026] [security2:error] [pid 20162:tid 20392] [client 31.56.58.59:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxcca-O_Kk7aqBvaiF5IAAAAfI"]
[Thu Sep 17 15:32:33.840018 2026] [security2:error] [pid 18946:tid 19196] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOgAAAAYI"]
[Thu Sep 17 15:32:33.861557 2026] [security2:error] [pid 18946:tid 19182] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOgwAAAXQ"]
[Thu Sep 17 15:32:33.868930 2026] [security2:error] [pid 18946:tid 19192] [client 34.94.39.26:38360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxccTqiPMah0Tz_U1OOhAAAAX4"]
[Thu Sep 17 15:32:33.883501 2026] [security2:error] [pid 18946:tid 19170] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxccTqiPMah0Tz_U1OOhQAAAWg"]
[Thu Sep 17 15:32:33.886408 2026] [security2:error] [pid 20162:tid 20306] [client 35.252.83.108:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/info.php"] [unique_id "aqxcca-O_Kk7aqBvaiF5JAAAAZw"]
[Thu Sep 17 15:32:34.005435 2026] [security2:error] [pid 18946:tid 19173] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOigAAAWs"]
[Thu Sep 17 15:32:34.021083 2026] [security2:error] [pid 20162:tid 20360] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/private/.env"] [unique_id "aqxccq-O_Kk7aqBvaiF5JwAAAdI"]
[Thu Sep 17 15:32:34.034244 2026] [security2:error] [pid 20162:tid 20353] [client 4.240.114.86:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxccq-O_Kk7aqBvaiF5KAAAAcs"], referer: binance.com
[Thu Sep 17 15:32:34.079212 2026] [security2:error] [pid 18946:tid 19197] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOjAAAAYM"]
[Thu Sep 17 15:32:34.111551 2026] [security2:error] [pid 18946:tid 19171] [client 35.252.83.108:57322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/php.php"] [unique_id "aqxccjqiPMah0Tz_U1OOjgAAAWk"]
[Thu Sep 17 15:32:34.172623 2026] [security2:error] [pid 18946:tid 19190] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOjwAAAXw"]
[Thu Sep 17 15:32:34.243509 2026] [security2:error] [pid 18946:tid 19077] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOkQAAAQs"]
[Thu Sep 17 15:32:34.249428 2026] [security2:error] [pid 20162:tid 20371] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/application/.env"] [unique_id "aqxccq-O_Kk7aqBvaiF5KwAAAd0"]
[Thu Sep 17 15:32:34.288030 2026] [security2:error] [pid 18946:tid 19200] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOkwAAAYY"]
[Thu Sep 17 15:32:34.390202 2026] [security2:error] [pid 20162:tid 20417] [client 34.94.39.26:38374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/test/phpinfo.php"] [unique_id "aqxccq-O_Kk7aqBvaiF5LQAAAgs"]
[Thu Sep 17 15:32:34.454956 2026] [security2:error] [pid 18946:tid 19103] [client 35.252.83.108:57326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/i.php"] [unique_id "aqxccjqiPMah0Tz_U1OOlgAAASU"]
[Thu Sep 17 15:32:34.465006 2026] [security2:error] [pid 18946:tid 19164] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOlwAAAWI"]
[Thu Sep 17 15:32:34.478321 2026] [security2:error] [pid 20162:tid 20400] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bootstrap/.env"] [unique_id "aqxccq-O_Kk7aqBvaiF5LgAAAfo"]
[Thu Sep 17 15:32:34.712971 2026] [security2:error] [pid 20162:tid 20368] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/database/.env"] [unique_id "aqxccq-O_Kk7aqBvaiF5MQAAAdo"]
[Thu Sep 17 15:32:34.713203 2026] [security2:error] [pid 20162:tid 20357] [client 35.252.83.108:57338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxccq-O_Kk7aqBvaiF5MgAAAc8"]
[Thu Sep 17 15:32:34.729015 2026] [security2:error] [pid 18946:tid 19088] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOpAAAARY"]
[Thu Sep 17 15:32:34.732443 2026] [security2:error] [pid 20162:tid 20419] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxcca-O_Kk7aqBvaiF5HwAAAg0"]
[Thu Sep 17 15:32:34.732978 2026] [security2:error] [pid 20162:tid 20339] [client 31.56.58.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxccq-O_Kk7aqBvaiF5JQAAAb0"], referer: http://mail.flyingbookshouse.com/api/session/properties
[Thu Sep 17 15:32:34.769206 2026] [security2:error] [pid 18946:tid 19179] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOpQAAAXE"]
[Thu Sep 17 15:32:34.841982 2026] [security2:error] [pid 18946:tid 19092] [client 34.94.39.26:38386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxccjqiPMah0Tz_U1OOqAAAARo"]
[Thu Sep 17 15:32:34.913154 2026] [security2:error] [pid 20162:tid 20414] [client 35.252.83.108:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxccq-O_Kk7aqBvaiF5NQAAAgg"]
[Thu Sep 17 15:32:34.914404 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOqQAAAUc"]
[Thu Sep 17 15:32:34.944981 2026] [security2:error] [pid 20162:tid 20381] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/storage/.env"] [unique_id "aqxccq-O_Kk7aqBvaiF5NgAAAec"]
[Thu Sep 17 15:32:34.955512 2026] [security2:error] [pid 18946:tid 19113] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxccjqiPMah0Tz_U1OOrAAAAS8"]
[Thu Sep 17 15:32:35.007364 2026] [security2:error] [pid 18946:tid 19168] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOsAAAAWY"]
[Thu Sep 17 15:32:35.045478 2026] [security2:error] [pid 18946:tid 19176] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOsgAAAW4"]
[Thu Sep 17 15:32:35.090139 2026] [security2:error] [pid 18946:tid 19141] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOtQAAAUs"]
[Thu Sep 17 15:32:35.121498 2026] [security2:error] [pid 18946:tid 19193] [client 31.56.58.59:45662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxcczqiPMah0Tz_U1OOswAAAX8"], referer: http://mail.jenniferniesslein.com/api/session/properties
[Thu Sep 17 15:32:35.173787 2026] [security2:error] [pid 20162:tid 20303] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5OgAAAZk"]
[Thu Sep 17 15:32:35.174001 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.39.26:38398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/old/phpinfo.php"] [unique_id "aqxcczqiPMah0Tz_U1OOtgAAAYc"]
[Thu Sep 17 15:32:35.179670 2026] [security2:error] [pid 20162:tid 20325] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/var/www/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5OwAAAa8"]
[Thu Sep 17 15:32:35.204758 2026] [security2:error] [pid 18946:tid 19128] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOtwAAAT4"]
[Thu Sep 17 15:32:35.360692 2026] [security2:error] [pid 18946:tid 19078] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOvQAAAQw"]
[Thu Sep 17 15:32:35.367050 2026] [security2:error] [pid 20162:tid 20313] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5PQAAAaM"]
[Thu Sep 17 15:32:35.408201 2026] [security2:error] [pid 20162:tid 20407] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/var/www/html/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5PgAAAgE"]
[Thu Sep 17 15:32:35.408380 2026] [security2:error] [pid 18946:tid 19100] [client 37.228.202.196:9062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcczqiPMah0Tz_U1OOuwABIjQ"]
[Thu Sep 17 15:32:35.454893 2026] [security2:error] [pid 20162:tid 20402] [client 35.252.83.108:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/test.php"] [unique_id "aqxcc6-O_Kk7aqBvaiF5PwAAAfw"]
[Thu Sep 17 15:32:35.481298 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOvwAAAYg"]
[Thu Sep 17 15:32:35.526888 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOwwAAAV4"]
[Thu Sep 17 15:32:35.553330 2026] [security2:error] [pid 20162:tid 20351] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5QQAAAck"]
[Thu Sep 17 15:32:35.556844 2026] [security2:error] [pid 18946:tid 19150] [client 34.94.39.26:38402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcczqiPMah0Tz_U1OOxQAAAVQ"]
[Thu Sep 17 15:32:35.566247 2026] [security2:error] [pid 18946:tid 19087] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOxgAAARU"]
[Thu Sep 17 15:32:35.638035 2026] [security2:error] [pid 20162:tid 20333] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/current/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5QgAAAbc"]
[Thu Sep 17 15:32:35.699199 2026] [security2:error] [pid 18946:tid 19159] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOywAAAV0"]
[Thu Sep 17 15:32:35.732197 2026] [security2:error] [pid 20162:tid 20296] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5QwAAAZI"]
[Thu Sep 17 15:32:35.735242 2026] [security2:error] [pid 18946:tid 19114] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxcczqiPMah0Tz_U1OOzgAAATA"]
[Thu Sep 17 15:32:35.738462 2026] [security2:error] [pid 18946:tid 19140] [client 103.61.184.148:64163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcczqiPMah0Tz_U1OOzQAAAUo"]
[Thu Sep 17 15:32:35.738577 2026] [security2:error] [pid 18946:tid 19140] [client 103.61.184.148:64163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcczqiPMah0Tz_U1OOzQAAAUo"]
[Thu Sep 17 15:32:35.867174 2026] [security2:error] [pid 20162:tid 20295] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/release/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5RAAAAZE"]
[Thu Sep 17 15:32:35.881992 2026] [security2:error] [pid 20162:tid 20406] [client 34.94.39.26:38418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/public/phpinfo.php"] [unique_id "aqxcc6-O_Kk7aqBvaiF5RQAAAgA"]
[Thu Sep 17 15:32:35.903849 2026] [core:error] [pid 20162:tid 20309] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:35.903873 2026] [core:error] [pid 20162:tid 20309] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:35.913682 2026] [security2:error] [pid 20162:tid 20411] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxcc6-O_Kk7aqBvaiF5RwAAAgU"]
[Thu Sep 17 15:32:35.978496 2026] [security2:error] [pid 18946:tid 19171] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxcczqiPMah0Tz_U1OO2gAAAWk"]
[Thu Sep 17 15:32:36.001150 2026] [security2:error] [pid 18946:tid 19124] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxcczqiPMah0Tz_U1OO2wAAATo"]
[Thu Sep 17 15:32:36.100247 2026] [security2:error] [pid 20162:tid 20347] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5SAAAAcU"]
[Thu Sep 17 15:32:36.100248 2026] [security2:error] [pid 20162:tid 20382] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/releases/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5SQAAAeg"]
[Thu Sep 17 15:32:36.154388 2026] [security2:error] [pid 18946:tid 19079] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO3QAAAQ0"]
[Thu Sep 17 15:32:36.170893 2026] [security2:error] [pid 18946:tid 19149] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO3gAAAVM"]
[Thu Sep 17 15:32:36.288520 2026] [core:error] [pid 20162:tid 20332] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:36.288538 2026] [core:error] [pid 20162:tid 20332] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:36.300118 2026] [security2:error] [pid 18946:tid 19203] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO4wAAAYk"]
[Thu Sep 17 15:32:36.325047 2026] [security2:error] [pid 18946:tid 19111] [client 35.252.83.108:57378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/p.php"] [unique_id "aqxcdDqiPMah0Tz_U1OO5AAAAS0"]
[Thu Sep 17 15:32:36.334771 2026] [security2:error] [pid 18946:tid 19165] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO5QAAAWM"]
[Thu Sep 17 15:32:36.334816 2026] [security2:error] [pid 20162:tid 20378] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shared/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5TwAAAeQ"]
[Thu Sep 17 15:32:36.394525 2026] [security2:error] [pid 18946:tid 19169] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO5gAAAWc"]
[Thu Sep 17 15:32:36.472400 2026] [security2:error] [pid 20162:tid 20331] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5UQAAAbU"]
[Thu Sep 17 15:32:36.547832 2026] [security2:error] [pid 18946:tid 19152] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO7gAAAVY"]
[Thu Sep 17 15:32:36.565216 2026] [security2:error] [pid 20162:tid 20348] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/deploy/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5VQAAAcY"]
[Thu Sep 17 15:32:36.586776 2026] [security2:error] [pid 18946:tid 19126] [client 35.252.83.108:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxcdDqiPMah0Tz_U1OO8AAAATw"]
[Thu Sep 17 15:32:36.610494 2026] [security2:error] [pid 18946:tid 19103] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO8QAAASU"]
[Thu Sep 17 15:32:36.656772 2026] [security2:error] [pid 20162:tid 20379] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5VwAAAeU"]
[Thu Sep 17 15:32:36.662606 2026] [security2:error] [pid 18946:tid 19123] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO8wAAATk"]
[Thu Sep 17 15:32:36.710008 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO9QAAASY"]
[Thu Sep 17 15:32:36.712868 2026] [security2:error] [pid 18946:tid 19082] [client 40.81.232.68:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxcdDqiPMah0Tz_U1OO9gAAARA"], referer: binance.com
[Thu Sep 17 15:32:36.721262 2026] [core:error] [pid 20162:tid 20390] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:36.721279 2026] [core:error] [pid 20162:tid 20390] [client 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:36.731359 2026] [security2:error] [pid 18946:tid 19183] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO9wAAAXU"]
[Thu Sep 17 15:32:36.788144 2026] [security2:error] [pid 18946:tid 19158] [client 34.94.39.26:38448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/php-info.php"] [unique_id "aqxcdDqiPMah0Tz_U1OO-QAAAVw"]
[Thu Sep 17 15:32:36.795000 2026] [security2:error] [pid 20162:tid 20387] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/build/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5WwAAAe0"]
[Thu Sep 17 15:32:36.829519 2026] [security2:error] [pid 20162:tid 20398] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxcdK-O_Kk7aqBvaiF5XAAAAfg"]
[Thu Sep 17 15:32:36.878841 2026] [security2:error] [pid 18946:tid 19134] [client 34.94.39.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.melodypicture.us"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxcdDqiPMah0Tz_U1OO-wAAAUQ"]
[Thu Sep 17 15:32:36.899898 2026] [security2:error] [pid 20162:tid 20300] [client 35.252.83.108:57396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxcdK-O_Kk7aqBvaiF5XQAAAZY"]
[Thu Sep 17 15:32:36.923937 2026] [security2:error] [pid 18946:tid 19088] [client 34.94.39.26:38278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/phpinfo.php"] [unique_id "aqxcdDqiPMah0Tz_U1OO_gAAARY"]
[Thu Sep 17 15:32:37.013970 2026] [security2:error] [pid 20162:tid 20416] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5XgAAAgo"]
[Thu Sep 17 15:32:37.029307 2026] [security2:error] [pid 20162:tid 20327] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dist/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5XwAAAbE"]
[Thu Sep 17 15:32:37.117363 2026] [security2:error] [pid 20162:tid 20364] [client 79.116.89.151:61338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcda-O_Kk7aqBvaiF5YQAAAdY"]
[Thu Sep 17 15:32:37.117519 2026] [security2:error] [pid 20162:tid 20364] [client 79.116.89.151:61338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcda-O_Kk7aqBvaiF5YQAAAdY"]
[Thu Sep 17 15:32:37.192594 2026] [security2:error] [pid 20162:tid 20369] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5YgAAAds"]
[Thu Sep 17 15:32:37.229520 2026] [security2:error] [pid 20162:tid 20335] [client 34.94.39.26:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/phpversion.php"] [unique_id "aqxcda-O_Kk7aqBvaiF5YwAAAbk"]
[Thu Sep 17 15:32:37.259037 2026] [security2:error] [pid 20162:tid 20358] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/public_html/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5ZAAAAdA"]
[Thu Sep 17 15:32:37.269441 2026] [security2:error] [pid 20162:tid 20377] [client 34.94.39.26:38452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/info.php"] [unique_id "aqxcda-O_Kk7aqBvaiF5ZQAAAeM"]
[Thu Sep 17 15:32:37.299236 2026] [security2:error] [pid 18946:tid 19093] [client 35.252.83.108:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxcdTqiPMah0Tz_U1OPBgAAARs"]
[Thu Sep 17 15:32:37.372490 2026] [security2:error] [pid 20162:tid 20413] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5ZgAAAgc"]
[Thu Sep 17 15:32:37.487329 2026] [security2:error] [pid 20162:tid 20346] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/htdocs/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5aQAAAcQ"]
[Thu Sep 17 15:32:37.490196 2026] [security2:error] [pid 18946:tid 19132] [client 34.94.39.26:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/_phpinfo.php"] [unique_id "aqxcdTqiPMah0Tz_U1OPCwAAAUI"]
[Thu Sep 17 15:32:37.547694 2026] [security2:error] [pid 20162:tid 20306] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5bAAAAZw"]
[Thu Sep 17 15:32:37.548629 2026] [security2:error] [pid 18946:tid 19191] [client 114.119.153.246:34523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hoffman412.org"] [uri "/images/gallery/installation%20pics%2012/4.JPG"] [unique_id "aqxcdTqiPMah0Tz_U1OPDAAAAX0"], referer: https://hoffman412.org/images/gallery/installation%20pics%2012/4.JPG
[Thu Sep 17 15:32:37.589485 2026] [security2:error] [pid 18946:tid 19106] [client 35.252.83.108:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxcdTqiPMah0Tz_U1OPDgAAASg"]
[Thu Sep 17 15:32:37.633815 2026] [security2:error] [pid 20162:tid 20392] [client 31.215.223.135:52587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcda-O_Kk7aqBvaiF5awAB8jM"]
[Thu Sep 17 15:32:37.715723 2026] [security2:error] [pid 20162:tid 20403] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/www/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5bQAAAf0"]
[Thu Sep 17 15:32:37.755599 2026] [security2:error] [pid 20162:tid 20360] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5bgAAAdI"]
[Thu Sep 17 15:32:37.912467 2026] [security2:error] [pid 18946:tid 19194] [client 34.94.39.26:38480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/old_phpinfo.php"] [unique_id "aqxcdTqiPMah0Tz_U1OPEwAAAYA"]
[Thu Sep 17 15:32:37.946401 2026] [security2:error] [pid 20162:tid 20371] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/html/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5bwAAAd0"]
[Thu Sep 17 15:32:37.947543 2026] [security2:error] [pid 20162:tid 20409] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxcda-O_Kk7aqBvaiF5cAAAAgM"]
[Thu Sep 17 15:32:37.972890 2026] [security2:error] [pid 18946:tid 19141] [client 143.105.152.240:17549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcdTqiPMah0Tz_U1OPFgAAAUs"]
[Thu Sep 17 15:32:37.972996 2026] [security2:error] [pid 18946:tid 19141] [client 143.105.152.240:17549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcdTqiPMah0Tz_U1OPFgAAAUs"]
[Thu Sep 17 15:32:38.011470 2026] [security2:error] [pid 18946:tid 19144] [client 35.252.83.108:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxcdjqiPMah0Tz_U1OPGAAAAU4"]
[Thu Sep 17 15:32:38.121716 2026] [security2:error] [pid 20162:tid 20323] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5cQAAAa0"]
[Thu Sep 17 15:32:38.174890 2026] [security2:error] [pid 20162:tid 20400] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/live/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5cgAAAfo"]
[Thu Sep 17 15:32:38.183043 2026] [security2:error] [pid 20162:tid 20417] [client 35.252.83.108:57422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcdq-O_Kk7aqBvaiF5cwAAAgs"]
[Thu Sep 17 15:32:38.190037 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.39.26:38506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/server-info.php"] [unique_id "aqxcdjqiPMah0Tz_U1OPHAAAAVc"]
[Thu Sep 17 15:32:38.195633 2026] [security2:error] [pid 20162:tid 20337] [client 34.94.39.26:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/php.php"] [unique_id "aqxcdq-O_Kk7aqBvaiF5dAAAAbs"]
[Thu Sep 17 15:32:38.294296 2026] [security2:error] [pid 20162:tid 20334] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5dwAAAbg"]
[Thu Sep 17 15:32:38.404298 2026] [security2:error] [pid 20162:tid 20385] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/prod/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5eAAAAes"]
[Thu Sep 17 15:32:38.427916 2026] [security2:error] [pid 20162:tid 20302] [client 35.252.83.108:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxcdq-O_Kk7aqBvaiF5eQAAAZg"]
[Thu Sep 17 15:32:38.466904 2026] [security2:error] [pid 20162:tid 20314] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5egAAAaQ"]
[Thu Sep 17 15:32:38.631812 2026] [security2:error] [pid 20162:tid 20414] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dev/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5fAAAAgg"]
[Thu Sep 17 15:32:38.672500 2026] [security2:error] [pid 20162:tid 20381] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5fQAAAec"]
[Thu Sep 17 15:32:38.737620 2026] [security2:error] [pid 18946:tid 19079] [client 34.94.39.26:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/server-status.php"] [unique_id "aqxcdjqiPMah0Tz_U1OPKwAAAQ0"]
[Thu Sep 17 15:32:38.786524 2026] [security2:error] [pid 20162:tid 20297] [client 34.94.39.26:38508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/i.php"] [unique_id "aqxcdq-O_Kk7aqBvaiF5fwAAAZM"]
[Thu Sep 17 15:32:38.819678 2026] [core:error] [pid 18946:tid 19111] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:38.819700 2026] [core:error] [pid 18946:tid 19111] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:38.852703 2026] [security2:error] [pid 20162:tid 20318] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5gAAAAag"]
[Thu Sep 17 15:32:38.859380 2026] [security2:error] [pid 20162:tid 20375] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/staging/.env"] [unique_id "aqxcdq-O_Kk7aqBvaiF5ggAAAeE"]
[Thu Sep 17 15:32:39.034762 2026] [security2:error] [pid 18946:tid 19126] [client 34.94.39.26:38528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/pi.php"] [unique_id "aqxcdzqiPMah0Tz_U1OPNQAAATw"]
[Thu Sep 17 15:32:39.040471 2026] [security2:error] [pid 20162:tid 20386] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5hAAAAew"]
[Thu Sep 17 15:32:39.090881 2026] [security2:error] [pid 20162:tid 20313] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/opt/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5hgAAAaM"]
[Thu Sep 17 15:32:39.214899 2026] [security2:error] [pid 20162:tid 20402] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5hwAAAfw"]
[Thu Sep 17 15:32:39.306052 2026] [core:error] [pid 20162:tid 20351] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:39.306071 2026] [core:error] [pid 20162:tid 20351] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:39.319157 2026] [security2:error] [pid 20162:tid 20394] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/laravel/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5igAAAfQ"]
[Thu Sep 17 15:32:39.391267 2026] [security2:error] [pid 20162:tid 20407] [client 34.94.39.26:38540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/pinfo.php"] [unique_id "aqxcd6-O_Kk7aqBvaiF5iwAAAgE"]
[Thu Sep 17 15:32:39.398591 2026] [security2:error] [pid 20162:tid 20304] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5jAAAAZo"]
[Thu Sep 17 15:32:39.422742 2026] [security2:error] [pid 18946:tid 19151] [client 35.252.83.108:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxcdzqiPMah0Tz_U1OPQQAAAVU"]
[Thu Sep 17 15:32:39.548376 2026] [security2:error] [pid 20162:tid 20406] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/symfony/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5jwAAAgA"]
[Thu Sep 17 15:32:39.570092 2026] [security2:error] [pid 20162:tid 20411] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5kAAAAgU"]
[Thu Sep 17 15:32:39.659167 2026] [security2:error] [pid 20162:tid 20309] [client 34.94.39.26:38558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/test.php"] [unique_id "aqxcd6-O_Kk7aqBvaiF5kQAAAZ8"]
[Thu Sep 17 15:32:39.741527 2026] [security2:error] [pid 20162:tid 20382] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5lQAAAeg"]
[Thu Sep 17 15:32:39.752797 2026] [core:error] [pid 20162:tid 20347] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:39.752812 2026] [core:error] [pid 20162:tid 20347] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:39.776105 2026] [security2:error] [pid 20162:tid 20332] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/wordpress/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5lwAAAbY"]
[Thu Sep 17 15:32:39.787095 2026] [security2:error] [pid 20162:tid 20383] [client 35.252.83.108:57446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxcd6-O_Kk7aqBvaiF5mAAAAek"]
[Thu Sep 17 15:32:39.918251 2026] [security2:error] [pid 20162:tid 20348] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxcd6-O_Kk7aqBvaiF5mQAAAcY"]
[Thu Sep 17 15:32:40.004331 2026] [security2:error] [pid 20162:tid 20379] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/wp/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5nAAAAeU"]
[Thu Sep 17 15:32:40.034505 2026] [security2:error] [pid 18946:tid 19132] [client 35.252.83.108:57456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxceDqiPMah0Tz_U1OPVAAAAUI"]
[Thu Sep 17 15:32:40.054693 2026] [security2:error] [pid 20162:tid 20340] [client 34.94.39.26:38576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxceK-O_Kk7aqBvaiF5nQAAAb4"]
[Thu Sep 17 15:32:40.112337 2026] [security2:error] [pid 20162:tid 20356] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5oAAAAc4"]
[Thu Sep 17 15:32:40.209917 2026] [core:error] [pid 20162:tid 20415] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:40.209944 2026] [core:error] [pid 20162:tid 20415] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:40.235157 2026] [security2:error] [pid 20162:tid 20343] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cms/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5owAAAcE"]
[Thu Sep 17 15:32:40.296727 2026] [security2:error] [pid 20162:tid 20387] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5pAAAAe0"]
[Thu Sep 17 15:32:40.357800 2026] [security2:error] [pid 20162:tid 20341] [client 35.252.83.108:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxceK-O_Kk7aqBvaiF5pQAAAb8"]
[Thu Sep 17 15:32:40.463444 2026] [security2:error] [pid 20162:tid 20300] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/drupal/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5pwAAAZY"]
[Thu Sep 17 15:32:40.467263 2026] [security2:error] [pid 18946:tid 19078] [client 34.94.39.26:38594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/p.php"] [unique_id "aqxceDqiPMah0Tz_U1OPXgAAAQw"]
[Thu Sep 17 15:32:40.468500 2026] [security2:error] [pid 20162:tid 20416] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5qAAAAgo"]
[Thu Sep 17 15:32:40.565397 2026] [security2:error] [pid 20162:tid 20310] [client 34.94.39.26:38590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxceK-O_Kk7aqBvaiF5qQAAAaA"]
[Thu Sep 17 15:32:40.641742 2026] [security2:error] [pid 20162:tid 20369] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5qgAAAds"]
[Thu Sep 17 15:32:40.653448 2026] [security2:error] [pid 20162:tid 20307] [client 35.252.83.108:57480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxceK-O_Kk7aqBvaiF5qwAAAZ0"]
[Thu Sep 17 15:32:40.687425 2026] [security2:error] [pid 20162:tid 20364] [client 34.94.39.26:38600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/debug.php"] [unique_id "aqxceK-O_Kk7aqBvaiF5rAAAAdY"]
[Thu Sep 17 15:32:40.691605 2026] [security2:error] [pid 20162:tid 20335] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/joomla/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5rQAAAbk"]
[Thu Sep 17 15:32:40.828922 2026] [security2:error] [pid 20162:tid 20326] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5rgAAAbA"]
[Thu Sep 17 15:32:40.907930 2026] [security2:error] [pid 18946:tid 19108] [client 34.94.39.26:51806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxceDqiPMah0Tz_U1OPawAAASo"]
[Thu Sep 17 15:32:40.921304 2026] [security2:error] [pid 20162:tid 20346] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/magento/.env"] [unique_id "aqxceK-O_Kk7aqBvaiF5sAAAAcQ"]
[Thu Sep 17 15:32:40.935133 2026] [security2:error] [pid 18946:tid 19114] [client 35.252.83.108:57492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxceDqiPMah0Tz_U1OPbQAAATA"]
[Thu Sep 17 15:32:41.005394 2026] [security2:error] [pid 20162:tid 20306] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5sQAAAZw"]
[Thu Sep 17 15:32:41.094166 2026] [security2:error] [pid 18946:tid 19199] [client 114.198.138.124:52652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxceTqiPMah0Tz_U1OPcwAAAYU"]
[Thu Sep 17 15:32:41.094296 2026] [security2:error] [pid 18946:tid 19199] [client 114.198.138.124:52652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxceTqiPMah0Tz_U1OPcwAAAYU"]
[Thu Sep 17 15:32:41.157948 2026] [security2:error] [pid 20162:tid 20366] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shopify/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5tAAAAdg"]
[Thu Sep 17 15:32:41.168577 2026] [security2:error] [pid 18946:tid 19099] [client 74.7.241.168:58728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ravenindustries-net.geekngamer.com"] [uri "/404.html"] [unique_id "aqxceTqiPMah0Tz_U1OPeAABITo"]
[Thu Sep 17 15:32:41.180313 2026] [security2:error] [pid 20162:tid 20338] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5tgAAAbw"]
[Thu Sep 17 15:32:41.187910 2026] [security2:error] [pid 18946:tid 19079] [client 74.7.244.16:45880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "troop707.net"] [uri "/robots.txt"] [unique_id "aqxceTqiPMah0Tz_U1OPeQAAAQ0"]
[Thu Sep 17 15:32:41.196878 2026] [security2:error] [pid 18946:tid 18987] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxceTqiPMah0Tz_U1OPegABXyg"]
[Thu Sep 17 15:32:41.215286 2026] [security2:error] [pid 18946:tid 19188] [client 34.94.39.26:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/admin/phpinfo.php"] [unique_id "aqxceTqiPMah0Tz_U1OPfQAAAXo"]
[Thu Sep 17 15:32:41.353351 2026] [security2:error] [pid 20162:tid 20336] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5uQAAAbo"]
[Thu Sep 17 15:32:41.387796 2026] [core:error] [pid 20162:tid 20365] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:41.387819 2026] [core:error] [pid 20162:tid 20365] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:41.395557 2026] [security2:error] [pid 20162:tid 20409] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/prestashop/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5uwAAAgM"]
[Thu Sep 17 15:32:41.404876 2026] [security2:error] [pid 18946:tid 19200] [client 34.94.39.26:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxceTqiPMah0Tz_U1OPigAAAYY"]
[Thu Sep 17 15:32:41.431227 2026] [security2:error] [pid 20162:tid 20400] [client 40.81.232.68:65453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxcea-O_Kk7aqBvaiF5vgAAAfo"], referer: binance.com
[Thu Sep 17 15:32:41.480584 2026] [security2:error] [pid 18946:tid 19057] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxceTqiPMah0Tz_U1OPjwABdW4"]
[Thu Sep 17 15:32:41.513412 2026] [security2:error] [pid 18946:tid 19009] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxceTqiPMah0Tz_U1OPkgABVT4"]
[Thu Sep 17 15:32:41.528699 2026] [security2:error] [pid 20162:tid 20337] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5vwAAAbs"]
[Thu Sep 17 15:32:41.551698 2026] [security2:error] [pid 18946:tid 19152] [client 34.94.39.26:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/test/phpinfo.php"] [unique_id "aqxceTqiPMah0Tz_U1OPlQAAAVY"]
[Thu Sep 17 15:32:41.590624 2026] [security2:error] [pid 18946:tid 19045] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxceTqiPMah0Tz_U1OPmAABaWI"]
[Thu Sep 17 15:32:41.620188 2026] [security2:error] [pid 18946:tid 19083] [client 66.96.214.58:14891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxceTqiPMah0Tz_U1OPjAAAARE"]
[Thu Sep 17 15:32:41.623310 2026] [security2:error] [pid 20162:tid 20399] [client 16.216.88.106:20480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "westshorebrewing.com"] [uri "/index.php"] [unique_id "aqxcd6-O_Kk7aqBvaiF5jQAB-TQ"]
[Thu Sep 17 15:32:41.623893 2026] [security2:error] [pid 20162:tid 20339] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/codeigniter/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5wQAAAb0"]
[Thu Sep 17 15:32:41.727000 2026] [security2:error] [pid 20162:tid 20298] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5wgAAAZQ"]
[Thu Sep 17 15:32:41.739422 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.39.26:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxceTqiPMah0Tz_U1OPngAAAUY"]
[Thu Sep 17 15:32:41.755970 2026] [security2:error] [pid 18946:tid 19133] [client 4.240.114.86:60055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxceTqiPMah0Tz_U1OPoQAAAUM"], referer: binance.com
[Thu Sep 17 15:32:41.757676 2026] [security2:error] [pid 18946:tid 19138] [client 58.84.150.1:47800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxceTqiPMah0Tz_U1OPkwABSFw"], referer: https://intolovinghomes.com.au/
[Thu Sep 17 15:32:41.841216 2026] [core:error] [pid 18946:tid 19192] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:41.841237 2026] [core:error] [pid 18946:tid 19192] [client 35.252.83.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:41.852633 2026] [security2:error] [pid 20162:tid 20384] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cakephp/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5wwAAAeo"]
[Thu Sep 17 15:32:41.918607 2026] [security2:error] [pid 20162:tid 20334] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxcea-O_Kk7aqBvaiF5xAAAAbg"]
[Thu Sep 17 15:32:42.083777 2026] [security2:error] [pid 20162:tid 20344] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/zend/.env"] [unique_id "aqxceq-O_Kk7aqBvaiF5xgAAAcI"]
[Thu Sep 17 15:32:42.085533 2026] [security2:error] [pid 20162:tid 20302] [client 16.216.88.106:20480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "westshorebrewing.com"] [uri "/index.php"] [unique_id "aqxceq-O_Kk7aqBvaiF5xQABmC4"]
[Thu Sep 17 15:32:42.091078 2026] [security2:error] [pid 20162:tid 20395] [client 35.228.71.49:38368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxceq-O_Kk7aqBvaiF5xwAAAfU"]
[Thu Sep 17 15:32:42.108446 2026] [security2:error] [pid 18946:tid 19058] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxcejqiPMah0Tz_U1OPuAABFW8"]
[Thu Sep 17 15:32:42.112336 2026] [security2:error] [pid 18946:tid 19112] [client 35.252.83.108:57518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcejqiPMah0Tz_U1OPuQAAAS4"]
[Thu Sep 17 15:32:42.131797 2026] [security2:error] [pid 18946:tid 19084] [client 34.94.39.26:51848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/dev/phpinfo.php"] [unique_id "aqxcejqiPMah0Tz_U1OPugAAARI"]
[Thu Sep 17 15:32:42.142150 2026] [security2:error] [pid 18946:tid 19053] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxcejqiPMah0Tz_U1OPvAABQGo"]
[Thu Sep 17 15:32:42.144591 2026] [security2:error] [pid 18946:tid 19163] [client 34.94.39.26:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcejqiPMah0Tz_U1OPvQAAAWE"]
[Thu Sep 17 15:32:42.233341 2026] [security2:error] [pid 18946:tid 19150] [client 74.7.228.38:47150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.gmeolaw.com"] [uri "/robots.txt"] [unique_id "aqxcejqiPMah0Tz_U1OPwQABVGY"]
[Thu Sep 17 15:32:42.311267 2026] [security2:error] [pid 20162:tid 20319] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/yii/.env"] [unique_id "aqxceq-O_Kk7aqBvaiF5ywAAAak"]
[Thu Sep 17 15:32:42.326560 2026] [security2:error] [pid 18946:tid 19153] [client 35.252.83.108:57524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxcejqiPMah0Tz_U1OPyAAAAVc"]
[Thu Sep 17 15:32:42.441934 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.39.26:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/old/phpinfo.php"] [unique_id "aqxcejqiPMah0Tz_U1OPzAAAASQ"]
[Thu Sep 17 15:32:42.531337 2026] [security2:error] [pid 18946:tid 19042] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP0AABe18"]
[Thu Sep 17 15:32:42.539988 2026] [security2:error] [pid 20162:tid 20355] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/laravel5/.env"] [unique_id "aqxceq-O_Kk7aqBvaiF5zgAAAc0"]
[Thu Sep 17 15:32:42.560784 2026] [security2:error] [pid 18946:tid 19032] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP1gABY1U"]
[Thu Sep 17 15:32:42.602180 2026] [security2:error] [pid 18946:tid 19048] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP1wABDWU"]
[Thu Sep 17 15:32:42.622986 2026] [security2:error] [pid 18946:tid 19199] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP2AAAAYU"]
[Thu Sep 17 15:32:42.688028 2026] [security2:error] [pid 18946:tid 19035] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP2QABX1g"]
[Thu Sep 17 15:32:42.718467 2026] [security2:error] [pid 18946:tid 18952] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP2gABCwU"]
[Thu Sep 17 15:32:42.773643 2026] [security2:error] [pid 20162:tid 20303] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v1/.env"] [unique_id "aqxceq-O_Kk7aqBvaiF50AAAAZk"]
[Thu Sep 17 15:32:42.775629 2026] [security2:error] [pid 20162:tid 20375] [client 34.94.39.26:51872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxceq-O_Kk7aqBvaiF50QAAAeE"]
[Thu Sep 17 15:32:42.775681 2026] [security2:error] [pid 20162:tid 20386] [client 35.252.83.108:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxceq-O_Kk7aqBvaiF50gAAAew"]
[Thu Sep 17 15:32:42.776871 2026] [security2:error] [pid 18946:tid 19036] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP3AABPFk"]
[Thu Sep 17 15:32:42.803734 2026] [security2:error] [pid 18946:tid 19181] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP3gAAAXM"]
[Thu Sep 17 15:32:42.860411 2026] [security2:error] [pid 18946:tid 19047] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP4gABD2Q"]
[Thu Sep 17 15:32:42.913325 2026] [security2:error] [pid 18946:tid 19067] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP4wABH3g"]
[Thu Sep 17 15:32:42.965675 2026] [security2:error] [pid 18946:tid 19055] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP5AABEGw"]
[Thu Sep 17 15:32:42.977343 2026] [security2:error] [pid 18946:tid 19091] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxcejqiPMah0Tz_U1OP5gAAARk"]
[Thu Sep 17 15:32:42.993616 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.39.26:51886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcejqiPMah0Tz_U1OP6gAAASY"]
[Thu Sep 17 15:32:43.005342 2026] [security2:error] [pid 20162:tid 20407] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v2/.env"] [unique_id "aqxce6-O_Kk7aqBvaiF51QAAAgE"]
[Thu Sep 17 15:32:43.011877 2026] [security2:error] [pid 18946:tid 19062] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP7AABRHM"]
[Thu Sep 17 15:32:43.033078 2026] [security2:error] [pid 18946:tid 19162] [client 35.252.83.108:33826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcezqiPMah0Tz_U1OP8AAAAWA"]
[Thu Sep 17 15:32:43.045269 2026] [security2:error] [pid 18946:tid 19066] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP8QABfHc"]
[Thu Sep 17 15:32:43.084820 2026] [security2:error] [pid 18946:tid 19183] [client 34.94.39.26:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/phpinfo.php.old"] [unique_id "aqxcezqiPMah0Tz_U1OP8wAAAXU"]
[Thu Sep 17 15:32:43.108104 2026] [security2:error] [pid 18946:tid 19025] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP9AABaU4"]
[Thu Sep 17 15:32:43.137578 2026] [security2:error] [pid 18946:tid 19065] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP9QABWnY"]
[Thu Sep 17 15:32:43.168758 2026] [security2:error] [pid 18946:tid 19195] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP9wAAAYE"]
[Thu Sep 17 15:32:43.174248 2026] [security2:error] [pid 18946:tid 19070] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP-AABRXs"]
[Thu Sep 17 15:32:43.234468 2026] [security2:error] [pid 18946:tid 19069] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP-wABKXo"]
[Thu Sep 17 15:32:43.238821 2026] [security2:error] [pid 20162:tid 20333] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/v3/.env"] [unique_id "aqxce6-O_Kk7aqBvaiF51gAAAbc"]
[Thu Sep 17 15:32:43.270140 2026] [security2:error] [pid 18946:tid 19072] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP_QABL30"]
[Thu Sep 17 15:32:43.323900 2026] [security2:error] [pid 20162:tid 20325] [client 35.252.83.108:33840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxce6-O_Kk7aqBvaiF51wAAAa8"]
[Thu Sep 17 15:32:43.334954 2026] [security2:error] [pid 18946:tid 19060] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxcezqiPMah0Tz_U1OP_wABI3E"]
[Thu Sep 17 15:32:43.338517 2026] [security2:error] [pid 18946:tid 19176] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQAAAAAW4"]
[Thu Sep 17 15:32:43.363431 2026] [security2:error] [pid 18946:tid 19071] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQAQABh3w"]
[Thu Sep 17 15:32:43.421689 2026] [security2:error] [pid 18946:tid 19056] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQAgABZm0"]
[Thu Sep 17 15:32:43.455886 2026] [security2:error] [pid 18946:tid 18957] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQAwABPgo"]
[Thu Sep 17 15:32:43.472246 2026] [security2:error] [pid 20162:tid 20382] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v1/.env"] [unique_id "aqxce6-O_Kk7aqBvaiF52QAAAeg"]
[Thu Sep 17 15:32:43.477742 2026] [security2:error] [pid 20162:tid 20411] [client 34.94.39.26:51900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/public/phpinfo.php"] [unique_id "aqxce6-O_Kk7aqBvaiF52gAAAgU"]
[Thu Sep 17 15:32:43.493908 2026] [security2:error] [pid 18946:tid 18965] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQBgABbRI"]
[Thu Sep 17 15:32:43.510076 2026] [security2:error] [pid 18946:tid 19100] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQBwAAASI"]
[Thu Sep 17 15:32:43.535230 2026] [security2:error] [pid 18946:tid 18961] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQCQABNQ4"]
[Thu Sep 17 15:32:43.540633 2026] [security2:error] [pid 18946:tid 19098] [client 34.94.39.26:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/phpinfo.php~"] [unique_id "aqxcezqiPMah0Tz_U1OQCwAAASA"]
[Thu Sep 17 15:32:43.590904 2026] [security2:error] [pid 18946:tid 18958] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQDwABYQs"]
[Thu Sep 17 15:32:43.669181 2026] [security2:error] [pid 18946:tid 18963] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQEgABNxA"]
[Thu Sep 17 15:32:43.673440 2026] [security2:error] [pid 18946:tid 19080] [client 35.252.83.108:33854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcezqiPMah0Tz_U1OQEwAAAQ4"]
[Thu Sep 17 15:32:43.679882 2026] [security2:error] [pid 18946:tid 19155] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQFAAAAVk"]
[Thu Sep 17 15:32:43.706919 2026] [security2:error] [pid 18946:tid 18950] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQGQABhAM"]
[Thu Sep 17 15:32:43.706919 2026] [security2:error] [pid 20162:tid 20305] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v2/.env"] [unique_id "aqxce6-O_Kk7aqBvaiF53QAAAZs"]
[Thu Sep 17 15:32:43.739500 2026] [security2:error] [pid 18946:tid 18966] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQGwABKhM"]
[Thu Sep 17 15:32:43.819647 2026] [security2:error] [pid 18946:tid 18956] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQHgABTwk"]
[Thu Sep 17 15:32:43.852474 2026] [security2:error] [pid 18946:tid 19149] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQHwAAAVM"]
[Thu Sep 17 15:32:43.862285 2026] [security2:error] [pid 18946:tid 18948] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQIAABewE"]
[Thu Sep 17 15:32:43.888754 2026] [security2:error] [pid 18946:tid 19074] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQIQABUH8"]
[Thu Sep 17 15:32:43.934458 2026] [security2:error] [pid 20162:tid 20332] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/rest/.env"] [unique_id "aqxce6-O_Kk7aqBvaiF53wAAAbY"]
[Thu Sep 17 15:32:43.951888 2026] [security2:error] [pid 18946:tid 18955] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQJAABiQg"]
[Thu Sep 17 15:32:43.980991 2026] [security2:error] [pid 20162:tid 20383] [client 34.94.39.26:51928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/info.php.bak"] [unique_id "aqxce6-O_Kk7aqBvaiF54QAAAek"]
[Thu Sep 17 15:32:43.981929 2026] [core:error] [pid 20162:tid 20350] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:43.981945 2026] [core:error] [pid 20162:tid 20350] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:43.999585 2026] [security2:error] [pid 18946:tid 18981] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxcezqiPMah0Tz_U1OQJgABDSI"]
[Thu Sep 17 15:32:44.007963 2026] [security2:error] [pid 20162:tid 20294] [client 35.252.83.108:33870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxcfK-O_Kk7aqBvaiF54gAAAZA"]
[Thu Sep 17 15:32:44.030079 2026] [security2:error] [pid 18946:tid 19111] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQKAAAAS0"]
[Thu Sep 17 15:32:44.046620 2026] [security2:error] [pid 18946:tid 18968] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQKgABZxU"]
[Thu Sep 17 15:32:44.084262 2026] [security2:error] [pid 18946:tid 19044] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQKwABPGE"]
[Thu Sep 17 15:32:44.133120 2026] [security2:error] [pid 18946:tid 18962] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQLQABOQ8"]
[Thu Sep 17 15:32:44.162133 2026] [security2:error] [pid 20162:tid 20340] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/graphql/.env"] [unique_id "aqxcfK-O_Kk7aqBvaiF55AAAAb4"]
[Thu Sep 17 15:32:44.180469 2026] [security2:error] [pid 18946:tid 18954] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQLgABXgc"]
[Thu Sep 17 15:32:44.200951 2026] [security2:error] [pid 18946:tid 19197] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQMQAAAYM"]
[Thu Sep 17 15:32:44.238653 2026] [security2:error] [pid 18946:tid 19037] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQMgABD1o"]
[Thu Sep 17 15:32:44.252506 2026] [security2:error] [pid 20162:tid 20356] [client 34.94.39.26:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/phpinfo.php.save"] [unique_id "aqxcfK-O_Kk7aqBvaiF55gAAAc4"]
[Thu Sep 17 15:32:44.254697 2026] [security2:error] [pid 18946:tid 19180] [client 35.252.83.108:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxcfDqiPMah0Tz_U1OQMwAAAXI"]
[Thu Sep 17 15:32:44.280289 2026] [security2:error] [pid 18946:tid 18967] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQNgABRxQ"]
[Thu Sep 17 15:32:44.296808 2026] [security2:error] [pid 18946:tid 19125] [client 43.153.54.14:47816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.54.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.votersrevenge.info"] [uri "/index.php"] [unique_id "aqxcfDqiPMah0Tz_U1OQNAAAATs"]
[Thu Sep 17 15:32:44.335049 2026] [security2:error] [pid 18946:tid 18970] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQNwABSxc"]
[Thu Sep 17 15:32:44.371228 2026] [security2:error] [pid 18946:tid 19082] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQOAAAARA"]
[Thu Sep 17 15:32:44.390111 2026] [security2:error] [pid 20162:tid 20329] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gateway/.env"] [unique_id "aqxcfK-O_Kk7aqBvaiF55wAAAbM"]
[Thu Sep 17 15:32:44.390365 2026] [security2:error] [pid 18946:tid 18984] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQOQABGSU"]
[Thu Sep 17 15:32:44.437460 2026] [security2:error] [pid 18946:tid 18988] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQPAABXCk"]
[Thu Sep 17 15:32:44.458088 2026] [security2:error] [pid 20162:tid 20415] [client 34.94.39.26:51960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/php-info.php"] [unique_id "aqxcfK-O_Kk7aqBvaiF56AAAAgk"]
[Thu Sep 17 15:32:44.471652 2026] [security2:error] [pid 18946:tid 18982] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQPQABdiM"]
[Thu Sep 17 15:32:44.501239 2026] [security2:error] [pid 18946:tid 19187] [client 35.252.83.108:33884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxcfDqiPMah0Tz_U1OQPgAAAXk"]
[Thu Sep 17 15:32:44.506567 2026] [security2:error] [pid 18946:tid 18974] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQQAABXRs"]
[Thu Sep 17 15:32:44.546779 2026] [security2:error] [pid 18946:tid 19134] [client 34.94.39.26:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxcfDqiPMah0Tz_U1OQRgAAAUQ"]
[Thu Sep 17 15:32:44.564589 2026] [security2:error] [pid 18946:tid 19156] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQSQAAAVo"]
[Thu Sep 17 15:32:44.582740 2026] [security2:error] [pid 18946:tid 18964] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQSgABYhE"]
[Thu Sep 17 15:32:44.618155 2026] [security2:error] [pid 20162:tid 20315] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/microservice/.env"] [unique_id "aqxcfK-O_Kk7aqBvaiF56wAAAaU"]
[Thu Sep 17 15:32:44.632461 2026] [security2:error] [pid 18946:tid 18992] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQSwABMi0"]
[Thu Sep 17 15:32:44.681545 2026] [security2:error] [pid 18946:tid 19024] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQTgABbE0"]
[Thu Sep 17 15:32:44.718918 2026] [security2:error] [pid 18946:tid 18971] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQTwABNhg"]
[Thu Sep 17 15:32:44.735397 2026] [security2:error] [pid 18946:tid 19136] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQUAAAAUY"]
[Thu Sep 17 15:32:44.756684 2026] [security2:error] [pid 18946:tid 18978] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQUgABWx8"]
[Thu Sep 17 15:32:44.812040 2026] [security2:error] [pid 18946:tid 19138] [client 35.252.83.108:33890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxcfDqiPMah0Tz_U1OQUwAAAUg"]
[Thu Sep 17 15:32:44.821904 2026] [security2:error] [pid 18946:tid 18996] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQVAABSTE"]
[Thu Sep 17 15:32:44.846507 2026] [security2:error] [pid 20162:tid 20387] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/service/.env"] [unique_id "aqxcfK-O_Kk7aqBvaiF57QAAAe0"]
[Thu Sep 17 15:32:44.854852 2026] [security2:error] [pid 18946:tid 18959] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQVgABTQw"]
[Thu Sep 17 15:32:44.879724 2026] [core:error] [pid 18946:tid 19113] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:44.879746 2026] [core:error] [pid 18946:tid 19113] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:44.897041 2026] [security2:error] [pid 18946:tid 19192] [client 34.94.39.26:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/phpversion.php"] [unique_id "aqxcfDqiPMah0Tz_U1OQWgAAAX4"]
[Thu Sep 17 15:32:44.904919 2026] [security2:error] [pid 18946:tid 19168] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQWwAAAWY"]
[Thu Sep 17 15:32:44.932582 2026] [security2:error] [pid 18946:tid 18953] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQXQABbQY"]
[Thu Sep 17 15:32:44.982655 2026] [security2:error] [pid 18946:tid 18980] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxcfDqiPMah0Tz_U1OQYgABFSE"]
[Thu Sep 17 15:32:44.988746 2026] [security2:error] [pid 18946:tid 19193] [client 34.94.39.26:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxcfDqiPMah0Tz_U1OQZQAAAX8"]
[Thu Sep 17 15:32:45.071296 2026] [security2:error] [pid 18946:tid 19121] [client 35.252.83.108:33906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxcfTqiPMah0Tz_U1OQaAAAATc"]
[Thu Sep 17 15:32:45.073189 2026] [security2:error] [pid 18946:tid 18983] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQaQABWSQ"]
[Thu Sep 17 15:32:45.074183 2026] [security2:error] [pid 20162:tid 20390] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/v3/.env"] [unique_id "aqxcfa-O_Kk7aqBvaiF57wAAAfA"]
[Thu Sep 17 15:32:45.075736 2026] [security2:error] [pid 18946:tid 19172] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQagAAAWo"]
[Thu Sep 17 15:32:45.106974 2026] [security2:error] [pid 18946:tid 18973] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQawABHRo"]
[Thu Sep 17 15:32:45.152689 2026] [security2:error] [pid 18946:tid 18986] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQbgABPyc"]
[Thu Sep 17 15:32:45.200145 2026] [security2:error] [pid 18946:tid 19023] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQbwABMEw"]
[Thu Sep 17 15:32:45.242242 2026] [security2:error] [pid 18946:tid 19144] [client 34.166.206.210:49492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQcAAAAU4"]
[Thu Sep 17 15:32:45.251118 2026] [security2:error] [pid 18946:tid 19084] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQcQAAARI"]
[Thu Sep 17 15:32:45.262040 2026] [security2:error] [pid 18946:tid 19153] [client 35.252.83.108:33912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQcgAAAVc"]
[Thu Sep 17 15:32:45.277275 2026] [security2:error] [pid 18946:tid 18995] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQcwABLjA"]
[Thu Sep 17 15:32:45.302088 2026] [security2:error] [pid 20162:tid 20300] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/dev/.env"] [unique_id "aqxcfa-O_Kk7aqBvaiF58AAAAZY"]
[Thu Sep 17 15:32:45.317226 2026] [security2:error] [pid 18946:tid 18975] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQdAABQRw"]
[Thu Sep 17 15:32:45.387561 2026] [security2:error] [pid 18946:tid 18994] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQdgABLC8"]
[Thu Sep 17 15:32:45.422519 2026] [security2:error] [pid 18946:tid 19203] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQeAAAAYk"]
[Thu Sep 17 15:32:45.437700 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.39.26:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/_phpinfo.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQeQAAARQ"]
[Thu Sep 17 15:32:45.455268 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.39.26:52008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQegAAASQ"]
[Thu Sep 17 15:32:45.466330 2026] [security2:error] [pid 18946:tid 18951] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQewABIQQ"]
[Thu Sep 17 15:32:45.530156 2026] [security2:error] [pid 20162:tid 20369] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/api/staging/.env"] [unique_id "aqxcfa-O_Kk7aqBvaiF58wAAAds"]
[Thu Sep 17 15:32:45.545110 2026] [security2:error] [pid 18946:tid 18977] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQfgABLR4"]
[Thu Sep 17 15:32:45.596371 2026] [security2:error] [pid 18946:tid 19169] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQgAAAAWc"]
[Thu Sep 17 15:32:45.600092 2026] [security2:error] [pid 18946:tid 19014] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQgQABJUM"]
[Thu Sep 17 15:32:45.608645 2026] [security2:error] [pid 18946:tid 19124] [client 35.252.83.108:33918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQggAAATo"]
[Thu Sep 17 15:32:45.645222 2026] [security2:error] [pid 18946:tid 19002] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQhAABczc"]
[Thu Sep 17 15:32:45.653529 2026] [security2:error] [pid 18946:tid 19147] [client 4.240.114.86:62374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQhQAAAVE"], referer: binance.com
[Thu Sep 17 15:32:45.682477 2026] [security2:error] [pid 18946:tid 19126] [client 34.94.39.26:52036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/old_phpinfo.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQhgAAATw"]
[Thu Sep 17 15:32:45.691389 2026] [security2:error] [pid 20162:tid 20408] [client 34.94.39.26:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxcfa-O_Kk7aqBvaiF59QAAAgI"]
[Thu Sep 17 15:32:45.716722 2026] [security2:error] [pid 18946:tid 19019] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQhwABg0g"]
[Thu Sep 17 15:32:45.740886 2026] [security2:error] [pid 18946:tid 19003] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQiAABCzg"]
[Thu Sep 17 15:32:45.758476 2026] [security2:error] [pid 20162:tid 20374] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vendor/.env"] [unique_id "aqxcfa-O_Kk7aqBvaiF59gAAAeA"]
[Thu Sep 17 15:32:45.768533 2026] [security2:error] [pid 20162:tid 20327] [client 136.158.61.34:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcfa-O_Kk7aqBvaiF59wAAAbE"]
[Thu Sep 17 15:32:45.768625 2026] [security2:error] [pid 20162:tid 20327] [client 136.158.61.34:54714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcfa-O_Kk7aqBvaiF59wAAAbE"]
[Thu Sep 17 15:32:45.780701 2026] [security2:error] [pid 18946:tid 19161] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQiQAAAV8"]
[Thu Sep 17 15:32:45.815804 2026] [security2:error] [pid 18946:tid 18985] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQigABDyY"]
[Thu Sep 17 15:32:45.882415 2026] [security2:error] [pid 18946:tid 18989] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQjQABJyo"]
[Thu Sep 17 15:32:45.930098 2026] [security2:error] [pid 20162:tid 20358] [client 34.166.206.210:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/info.php"] [unique_id "aqxcfa-O_Kk7aqBvaiF5-QAAAdA"]
[Thu Sep 17 15:32:45.943676 2026] [security2:error] [pid 18946:tid 19137] [client 35.252.83.108:33926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQjgAAAUc"]
[Thu Sep 17 15:32:45.949953 2026] [security2:error] [pid 18946:tid 18972] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQjwABHBk"]
[Thu Sep 17 15:32:45.953060 2026] [security2:error] [pid 18946:tid 19091] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxcfTqiPMah0Tz_U1OQkAAAARk"]
[Thu Sep 17 15:32:45.959882 2026] [security2:error] [pid 18946:tid 19141] [client 34.94.39.26:52048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/server-info.php"] [unique_id "aqxcfTqiPMah0Tz_U1OQkQAAAUs"]
[Thu Sep 17 15:32:45.986520 2026] [security2:error] [pid 20162:tid 20346] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/lib/.env"] [unique_id "aqxcfa-O_Kk7aqBvaiF5-wAAAcQ"]
[Thu Sep 17 15:32:46.011344 2026] [security2:error] [pid 18946:tid 19000] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQkgABdjU"]
[Thu Sep 17 15:32:46.046929 2026] [security2:error] [pid 18946:tid 18997] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQlwABVTI"]
[Thu Sep 17 15:32:46.097237 2026] [security2:error] [pid 18946:tid 18991] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQmAABRCw"]
[Thu Sep 17 15:32:46.137934 2026] [security2:error] [pid 18946:tid 19016] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQmgABcUU"]
[Thu Sep 17 15:32:46.139040 2026] [security2:error] [pid 18946:tid 19164] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQmwAAAWI"]
[Thu Sep 17 15:32:46.164114 2026] [security2:error] [pid 18946:tid 19015] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQnQABNEQ"]
[Thu Sep 17 15:32:46.215278 2026] [security2:error] [pid 20162:tid 20338] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/resources/.env"] [unique_id "aqxcfq-O_Kk7aqBvaiF5_QAAAbw"]
[Thu Sep 17 15:32:46.238132 2026] [security2:error] [pid 18946:tid 19005] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQngABYDo"]
[Thu Sep 17 15:32:46.268094 2026] [security2:error] [pid 20162:tid 20363] [client 34.94.39.26:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxcfq-O_Kk7aqBvaiF5_gAAAdU"]
[Thu Sep 17 15:32:46.280419 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.39.26:52066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/server-status.php"] [unique_id "aqxcfjqiPMah0Tz_U1OQnwAAATI"]
[Thu Sep 17 15:32:46.311149 2026] [security2:error] [pid 18946:tid 19092] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQoQAAARo"]
[Thu Sep 17 15:32:46.352486 2026] [security2:error] [pid 18946:tid 19120] [client 35.252.83.108:33942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxcfjqiPMah0Tz_U1OQowAAATY"]
[Thu Sep 17 15:32:46.390054 2026] [security2:error] [pid 18946:tid 18987] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQpAABKSg"]
[Thu Sep 17 15:32:46.430321 2026] [security2:error] [pid 18946:tid 19013] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQpQABSUI"]
[Thu Sep 17 15:32:46.442666 2026] [security2:error] [pid 20162:tid 20362] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/assets/.env"] [unique_id "aqxcfq-O_Kk7aqBvaiF6AAAAAdQ"]
[Thu Sep 17 15:32:46.488178 2026] [security2:error] [pid 18946:tid 19012] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQpgABQkE"]
[Thu Sep 17 15:32:46.492374 2026] [security2:error] [pid 18946:tid 19093] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQpwAAARs"]
[Thu Sep 17 15:32:46.538265 2026] [security2:error] [pid 18946:tid 18998] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQrAABGDM"]
[Thu Sep 17 15:32:46.613581 2026] [security2:error] [pid 18946:tid 19020] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQrgABPkk"]
[Thu Sep 17 15:32:46.617947 2026] [security2:error] [pid 20162:tid 20353] [client 34.166.206.210:47840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/php.php"] [unique_id "aqxcfq-O_Kk7aqBvaiF6AgAAAcs"]
[Thu Sep 17 15:32:46.627354 2026] [security2:error] [pid 18946:tid 19200] [client 103.61.184.148:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcfjqiPMah0Tz_U1OQrwAAAYY"]
[Thu Sep 17 15:32:46.627440 2026] [security2:error] [pid 18946:tid 19200] [client 103.61.184.148:64741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcfjqiPMah0Tz_U1OQrwAAAYY"]
[Thu Sep 17 15:32:46.652333 2026] [security2:error] [pid 18946:tid 18976] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQsAABNR0"]
[Thu Sep 17 15:32:46.664963 2026] [security2:error] [pid 18946:tid 19087] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQsQAAARU"]
[Thu Sep 17 15:32:46.675426 2026] [security2:error] [pid 20162:tid 20365] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/uploads/.env"] [unique_id "aqxcfq-O_Kk7aqBvaiF6BAAAAdc"]
[Thu Sep 17 15:32:46.687769 2026] [security2:error] [pid 18946:tid 19017] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQsgABKEY"]
[Thu Sep 17 15:32:46.704523 2026] [security2:error] [pid 18946:tid 19175] [client 35.252.83.108:33948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxcfjqiPMah0Tz_U1OQswAAAW0"]
[Thu Sep 17 15:32:46.726171 2026] [security2:error] [pid 18946:tid 19006] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQtAABNzs"]
[Thu Sep 17 15:32:46.766908 2026] [security2:error] [pid 18946:tid 19054] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQtgABhGs"]
[Thu Sep 17 15:32:46.798998 2026] [security2:error] [pid 20162:tid 20400] [client 40.81.232.68:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxcfq-O_Kk7aqBvaiF6BgAAAfo"], referer: binance.com
[Thu Sep 17 15:32:46.826349 2026] [security2:error] [pid 18946:tid 19057] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQtwABgG4"]
[Thu Sep 17 15:32:46.827294 2026] [security2:error] [pid 20162:tid 20371] [client 34.94.39.26:52070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/www/phpinfo.php"] [unique_id "aqxcfq-O_Kk7aqBvaiF6BwAAAd0"]
[Thu Sep 17 15:32:46.838956 2026] [security2:error] [pid 18946:tid 19129] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQuwAAAT8"]
[Thu Sep 17 15:32:46.871327 2026] [security2:error] [pid 18946:tid 19009] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQvAABKj4"]
[Thu Sep 17 15:32:46.903343 2026] [security2:error] [pid 20162:tid 20417] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/internal/.env"] [unique_id "aqxcfq-O_Kk7aqBvaiF6CAAAAgs"]
[Thu Sep 17 15:32:46.922547 2026] [core:error] [pid 20162:tid 20337] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:46.922565 2026] [core:error] [pid 20162:tid 20337] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:46.941097 2026] [security2:error] [pid 18946:tid 19033] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQwAABQFY"]
[Thu Sep 17 15:32:46.973394 2026] [security2:error] [pid 18946:tid 19045] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxcfjqiPMah0Tz_U1OQwQABdWI"]
[Thu Sep 17 15:32:47.009836 2026] [security2:error] [pid 18946:tid 19112] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQxQAAAS4"]
[Thu Sep 17 15:32:47.027731 2026] [security2:error] [pid 18946:tid 19114] [client 35.252.83.108:33964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQxgAAATA"]
[Thu Sep 17 15:32:47.034803 2026] [security2:error] [pid 18946:tid 19061] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQxwABTHI"]
[Thu Sep 17 15:32:47.090657 2026] [security2:error] [pid 18946:tid 19022] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQygABUEs"]
[Thu Sep 17 15:32:47.134913 2026] [security2:error] [pid 20162:tid 20368] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/tools/.env"] [unique_id "aqxcf6-O_Kk7aqBvaiF6DAAAAdo"]
[Thu Sep 17 15:32:47.140429 2026] [security2:error] [pid 18946:tid 19011] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQzAABFEA"]
[Thu Sep 17 15:32:47.191086 2026] [security2:error] [pid 18946:tid 19098] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQzQAAASA"]
[Thu Sep 17 15:32:47.216473 2026] [security2:error] [pid 18946:tid 19100] [client 34.166.154.225:40894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/phpinfo.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQzgAAASI"]
[Thu Sep 17 15:32:47.222685 2026] [security2:error] [pid 18946:tid 19039] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQzwABY1w"]
[Thu Sep 17 15:32:47.289597 2026] [security2:error] [pid 18946:tid 19018] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ0QABIUc"]
[Thu Sep 17 15:32:47.298053 2026] [security2:error] [pid 18946:tid 19145] [client 34.166.206.210:47854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/i.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQ0gAAAU8"]
[Thu Sep 17 15:32:47.307825 2026] [core:error] [pid 18946:tid 19085] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:47.307842 2026] [core:error] [pid 18946:tid 19085] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:47.344090 2026] [security2:error] [pid 18946:tid 19063] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ1QABJXQ"]
[Thu Sep 17 15:32:47.363319 2026] [security2:error] [pid 20162:tid 20334] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/scripts/.env"] [unique_id "aqxcf6-O_Kk7aqBvaiF6EAAAAbg"]
[Thu Sep 17 15:32:47.364348 2026] [security2:error] [pid 18946:tid 19170] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ1gAAAWg"]
[Thu Sep 17 15:32:47.384594 2026] [security2:error] [pid 18946:tid 19169] [client 35.252.83.108:33968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQ1wAAAWc"]
[Thu Sep 17 15:32:47.407597 2026] [security2:error] [pid 18946:tid 19059] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ2AABUXA"]
[Thu Sep 17 15:32:47.425812 2026] [security2:error] [pid 18946:tid 19189] [client 34.94.39.26:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQ2QAAAXs"]
[Thu Sep 17 15:32:47.441705 2026] [security2:error] [pid 18946:tid 19043] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ2gABOGA"]
[Thu Sep 17 15:32:47.492441 2026] [security2:error] [pid 18946:tid 19010] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ2wABCz8"]
[Thu Sep 17 15:32:47.529180 2026] [security2:error] [pid 18946:tid 19031] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ3AABclQ"]
[Thu Sep 17 15:32:47.543308 2026] [security2:error] [pid 18946:tid 19125] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ3QAAATs"]
[Thu Sep 17 15:32:47.590713 2026] [security2:error] [pid 20162:tid 20316] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bin/.env"] [unique_id "aqxcf6-O_Kk7aqBvaiF6EwAAAaY"]
[Thu Sep 17 15:32:47.592401 2026] [security2:error] [pid 18946:tid 19030] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ4QABHFM"]
[Thu Sep 17 15:32:47.646057 2026] [security2:error] [pid 18946:tid 19082] [client 35.252.83.108:33978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQ4gAAARA"]
[Thu Sep 17 15:32:47.659467 2026] [security2:error] [pid 18946:tid 19034] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ4wABZVc"]
[Thu Sep 17 15:32:47.684834 2026] [security2:error] [pid 18946:tid 19058] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ5AABS28"]
[Thu Sep 17 15:32:47.712389 2026] [security2:error] [pid 18946:tid 19173] [client 79.116.89.151:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQ5QAAAWs"]
[Thu Sep 17 15:32:47.712517 2026] [security2:error] [pid 18946:tid 19173] [client 79.116.89.151:61940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQ5QAAAWs"]
[Thu Sep 17 15:32:47.714577 2026] [security2:error] [pid 18946:tid 19158] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ5gAAAVw"]
[Thu Sep 17 15:32:47.738994 2026] [security2:error] [pid 18946:tid 19053] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ5wABfWo"]
[Thu Sep 17 15:32:47.764309 2026] [security2:error] [pid 18946:tid 19041] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ6AABVV4"]
[Thu Sep 17 15:32:47.793424 2026] [security2:error] [pid 18946:tid 19021] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ6QABWko"]
[Thu Sep 17 15:32:47.819421 2026] [security2:error] [pid 20162:tid 20303] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sbin/.env"] [unique_id "aqxcf6-O_Kk7aqBvaiF6FgAAAZk"]
[Thu Sep 17 15:32:47.829773 2026] [security2:error] [pid 18946:tid 19091] [client 34.94.39.26:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcfzqiPMah0Tz_U1OQ6wAAARk"]
[Thu Sep 17 15:32:47.833207 2026] [security2:error] [pid 18946:tid 19049] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ7AABYmY"]
[Thu Sep 17 15:32:47.869761 2026] [security2:error] [pid 18946:tid 18993] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ7QABRS4"]
[Thu Sep 17 15:32:47.894875 2026] [security2:error] [pid 18946:tid 19159] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ7gAAAV0"]
[Thu Sep 17 15:32:47.897162 2026] [security2:error] [pid 20162:tid 20319] [client 34.166.154.225:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/info.php"] [unique_id "aqxcf6-O_Kk7aqBvaiF6FwAAAak"]
[Thu Sep 17 15:32:47.933650 2026] [security2:error] [pid 18946:tid 19038] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ8AABeVs"]
[Thu Sep 17 15:32:47.965411 2026] [security2:error] [pid 18946:tid 19029] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxcfzqiPMah0Tz_U1OQ8gABMlI"]
[Thu Sep 17 15:32:47.979088 2026] [security2:error] [pid 20162:tid 20355] [client 34.166.206.210:47864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxcf6-O_Kk7aqBvaiF6GQAAAc0"]
[Thu Sep 17 15:32:47.981305 2026] [security2:error] [pid 20162:tid 20297] [client 34.94.39.26:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcf6-O_Kk7aqBvaiF6GgAAAZM"]
[Thu Sep 17 15:32:47.999759 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.39.26:52142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/mail/phpinfo.php"] [unique_id "aqxcfzqiPMah0Tz_U1OQ9gAAAWQ"]
[Thu Sep 17 15:32:48.004544 2026] [security2:error] [pid 18946:tid 19052] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxcgDqiPMah0Tz_U1OQ-AABKWk"]
[Thu Sep 17 15:32:48.047492 2026] [security2:error] [pid 20162:tid 20313] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/local/.env"] [unique_id "aqxcgK-O_Kk7aqBvaiF6HQAAAaM"]
[Thu Sep 17 15:32:48.061317 2026] [security2:error] [pid 18946:tid 19050] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxcgDqiPMah0Tz_U1OQ-gABSWc"]
[Thu Sep 17 15:32:48.070763 2026] [security2:error] [pid 18946:tid 19132] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxcgDqiPMah0Tz_U1OQ_AAAAUI"]
[Thu Sep 17 15:32:48.079382 2026] [security2:error] [pid 18946:tid 19162] [client 35.252.83.108:33984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxcgDqiPMah0Tz_U1OQ_QAAAWA"]
[Thu Sep 17 15:32:48.092546 2026] [security2:error] [pid 18946:tid 19046] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxcgDqiPMah0Tz_U1OQ_gABL2M"]
[Thu Sep 17 15:32:48.154119 2026] [security2:error] [pid 18946:tid 19042] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxcgDqiPMah0Tz_U1OQ_wABGF8"]
[Thu Sep 17 15:32:48.202453 2026] [security2:error] [pid 18946:tid 19032] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORAAABPlU"]
[Thu Sep 17 15:32:48.234403 2026] [security2:error] [pid 20162:tid 20407] [client 34.94.39.26:52150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxcgK-O_Kk7aqBvaiF6IAAAAgE"]
[Thu Sep 17 15:32:48.253241 2026] [security2:error] [pid 18946:tid 19195] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORAQAAAYE"]
[Thu Sep 17 15:32:48.278878 2026] [security2:error] [pid 20162:tid 20325] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/portal/.env"] [unique_id "aqxcgK-O_Kk7aqBvaiF6IQAAAa8"]
[Thu Sep 17 15:32:48.374079 2026] [security2:error] [pid 18946:tid 18952] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORBQABbQU"]
[Thu Sep 17 15:32:48.416599 2026] [security2:error] [pid 18946:tid 19036] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORBwABWVk"]
[Thu Sep 17 15:32:48.417274 2026] [security2:error] [pid 18946:tid 19087] [client 35.252.83.108:33998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxcgDqiPMah0Tz_U1ORCAAAARU"]
[Thu Sep 17 15:32:48.429872 2026] [security2:error] [pid 18946:tid 19172] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORCgAAAWo"]
[Thu Sep 17 15:32:48.453414 2026] [security2:error] [pid 20162:tid 20406] [client 34.94.39.26:52158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/site/phpinfo.php"] [unique_id "aqxcgK-O_Kk7aqBvaiF6JAAAAgA"]
[Thu Sep 17 15:32:48.470382 2026] [security2:error] [pid 18946:tid 19073] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORCwABgH4"]
[Thu Sep 17 15:32:48.517397 2026] [security2:error] [pid 20162:tid 20296] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/dashboard/.env"] [unique_id "aqxcgK-O_Kk7aqBvaiF6JgAAAZI"]
[Thu Sep 17 15:32:48.526424 2026] [security2:error] [pid 18946:tid 19129] [client 34.94.39.26:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcgDqiPMah0Tz_U1OREAAAAT8"]
[Thu Sep 17 15:32:48.528602 2026] [security2:error] [pid 18946:tid 19055] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxcgDqiPMah0Tz_U1OREgABYWw"]
[Thu Sep 17 15:32:48.578812 2026] [security2:error] [pid 18946:tid 19062] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORFAABdXM"]
[Thu Sep 17 15:32:48.591650 2026] [security2:error] [pid 20162:tid 20411] [client 34.166.154.225:50848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/php.php"] [unique_id "aqxcgK-O_Kk7aqBvaiF6KAAAAgU"]
[Thu Sep 17 15:32:48.607904 2026] [security2:error] [pid 18946:tid 19115] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORFQAAATE"]
[Thu Sep 17 15:32:48.617968 2026] [security2:error] [pid 18946:tid 19066] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORFgABLnc"]
[Thu Sep 17 15:32:48.663834 2026] [security2:error] [pid 18946:tid 19025] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORGAABLE4"]
[Thu Sep 17 15:32:48.674841 2026] [security2:error] [pid 18946:tid 19198] [client 34.166.206.210:47878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxcgDqiPMah0Tz_U1ORGQAAAYQ"]
[Thu Sep 17 15:32:48.691912 2026] [security2:error] [pid 18946:tid 19185] [client 35.252.83.108:34004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcgDqiPMah0Tz_U1ORGgAAAXc"]
[Thu Sep 17 15:32:48.709714 2026] [security2:error] [pid 18946:tid 19065] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORGwABiXY"]
[Thu Sep 17 15:32:48.732110 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.39.26:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxcgDqiPMah0Tz_U1ORHgAAAVA"]
[Thu Sep 17 15:32:48.744735 2026] [security2:error] [pid 18946:tid 19070] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORHwABIns"]
[Thu Sep 17 15:32:48.748217 2026] [security2:error] [pid 20162:tid 20350] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/panel/.env"] [unique_id "aqxcgK-O_Kk7aqBvaiF6LAAAAcg"]
[Thu Sep 17 15:32:48.761729 2026] [security2:error] [pid 20162:tid 20388] [client 4.240.114.86:64344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanacking.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxcgK-O_Kk7aqBvaiF6LQAAAe4"], referer: binance.com
[Thu Sep 17 15:32:48.787490 2026] [security2:error] [pid 18946:tid 19084] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORIQAAARI"]
[Thu Sep 17 15:32:48.789063 2026] [security2:error] [pid 18946:tid 19040] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORIgABiF0"]
[Thu Sep 17 15:32:48.834099 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.39.26:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcgDqiPMah0Tz_U1ORJQAAASE"]
[Thu Sep 17 15:32:48.873886 2026] [security2:error] [pid 20162:tid 20312] [client 143.105.152.240:47137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcgK-O_Kk7aqBvaiF6LwAAAaI"]
[Thu Sep 17 15:32:48.888870 2026] [security2:error] [pid 20162:tid 20312] [client 143.105.152.240:47137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcgK-O_Kk7aqBvaiF6LwAAAaI"]
[Thu Sep 17 15:32:48.906977 2026] [security2:error] [pid 18946:tid 19072] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORJwABhX0"]
[Thu Sep 17 15:32:48.923418 2026] [security2:error] [pid 20162:tid 20294] [client 35.252.83.108:34006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcgK-O_Kk7aqBvaiF6MAAAAZA"]
[Thu Sep 17 15:32:48.934205 2026] [security2:error] [pid 18946:tid 19060] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORKAABOnE"]
[Thu Sep 17 15:32:48.966174 2026] [security2:error] [pid 18946:tid 19150] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORKQAAAVQ"]
[Thu Sep 17 15:32:48.979318 2026] [security2:error] [pid 18946:tid 19071] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxcgDqiPMah0Tz_U1ORKgABOXw"]
[Thu Sep 17 15:32:48.982762 2026] [security2:error] [pid 20162:tid 20379] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/crm/.env"] [unique_id "aqxcgK-O_Kk7aqBvaiF6MgAAAeU"]
[Thu Sep 17 15:32:49.039203 2026] [security2:error] [pid 18946:tid 18965] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORMQABexI"]
[Thu Sep 17 15:32:49.089336 2026] [security2:error] [pid 18946:tid 19181] [client 34.94.39.26:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcgTqiPMah0Tz_U1ORMwAAAXM"]
[Thu Sep 17 15:32:49.096104 2026] [security2:error] [pid 18946:tid 18958] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORNAABOAs"]
[Thu Sep 17 15:32:49.146079 2026] [security2:error] [pid 18946:tid 19180] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORNwAAAXI"]
[Thu Sep 17 15:32:49.152497 2026] [security2:error] [pid 18946:tid 18963] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxcgTqiPMah0Tz_U1OROAABJxA"]
[Thu Sep 17 15:32:49.162751 2026] [security2:error] [pid 20162:tid 20315] [client 34.94.39.26:52200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcga-O_Kk7aqBvaiF6OwAAAaU"]
[Thu Sep 17 15:32:49.202520 2026] [security2:error] [pid 18946:tid 19007] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxcgTqiPMah0Tz_U1OROQABZTw"]
[Thu Sep 17 15:32:49.210484 2026] [security2:error] [pid 20162:tid 20369] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/erp/.env"] [unique_id "aqxcga-O_Kk7aqBvaiF6PQAAAds"]
[Thu Sep 17 15:32:49.234076 2026] [security2:error] [pid 20162:tid 20415] [client 78.46.215.1:56564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxcga-O_Kk7aqBvaiF6PgAAAgk"], referer: https://eris.media
[Thu Sep 17 15:32:49.242396 2026] [security2:error] [pid 18946:tid 18950] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxcgTqiPMah0Tz_U1OROwABRwM"]
[Thu Sep 17 15:32:49.303524 2026] [security2:error] [pid 18946:tid 18966] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORPQABfRM"]
[Thu Sep 17 15:32:49.308609 2026] [security2:error] [pid 20162:tid 20343] [client 34.166.154.225:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/i.php"] [unique_id "aqxcga-O_Kk7aqBvaiF6QAAAAcE"]
[Thu Sep 17 15:32:49.326290 2026] [security2:error] [pid 18946:tid 19151] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORPgAAAVU"]
[Thu Sep 17 15:32:49.356552 2026] [security2:error] [pid 18946:tid 18949] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORPwABWgI"]
[Thu Sep 17 15:32:49.375121 2026] [security2:error] [pid 20162:tid 20341] [client 35.252.83.108:34018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxcga-O_Kk7aqBvaiF6QgAAAb8"]
[Thu Sep 17 15:32:49.379150 2026] [security2:error] [pid 18946:tid 19081] [client 34.166.206.210:49784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/test.php"] [unique_id "aqxcgTqiPMah0Tz_U1ORQAAAAQ8"]
[Thu Sep 17 15:32:49.423827 2026] [security2:error] [pid 18946:tid 18956] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORQQABYgk"]
[Thu Sep 17 15:32:49.439588 2026] [security2:error] [pid 20162:tid 20408] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/shop/.env"] [unique_id "aqxcga-O_Kk7aqBvaiF6QwAAAgI"]
[Thu Sep 17 15:32:49.477396 2026] [security2:error] [pid 18946:tid 19074] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORQwABNH8"]
[Thu Sep 17 15:32:49.483454 2026] [security2:error] [pid 18946:tid 19179] [client 34.94.39.26:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/phpinfo.php.bak"] [unique_id "aqxcgTqiPMah0Tz_U1ORRAAAAXE"]
[Thu Sep 17 15:32:49.501546 2026] [security2:error] [pid 18946:tid 19152] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORRQAAAVY"]
[Thu Sep 17 15:32:49.543684 2026] [security2:error] [pid 18946:tid 18947] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORSQABXQA"]
[Thu Sep 17 15:32:49.580550 2026] [security2:error] [pid 18946:tid 19091] [client 34.94.39.26:52222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcgTqiPMah0Tz_U1ORSgAAARk"]
[Thu Sep 17 15:32:49.609307 2026] [security2:error] [pid 18946:tid 18981] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORTAABRiI"]
[Thu Sep 17 15:32:49.664046 2026] [security2:error] [pid 18946:tid 18968] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORTQABJhU"]
[Thu Sep 17 15:32:49.667858 2026] [security2:error] [pid 20162:tid 20377] [client 34.166.157.71:42292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/store/.env"] [unique_id "aqxcga-O_Kk7aqBvaiF6RgAAAeM"]
[Thu Sep 17 15:32:49.675552 2026] [security2:error] [pid 18946:tid 19139] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORTwAAAUk"]
[Thu Sep 17 15:32:49.736093 2026] [security2:error] [pid 18946:tid 19044] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORUAABYGE"]
[Thu Sep 17 15:32:49.747391 2026] [security2:error] [pid 18946:tid 19174] [client 35.252.83.108:34028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.83.252.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-1be5e4e4.akl.bjl.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxcgTqiPMah0Tz_U1ORUQAAAWw"]
[Thu Sep 17 15:32:49.780999 2026] [security2:error] [pid 18946:tid 18962] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORUwABhw8"]
[Thu Sep 17 15:32:49.848241 2026] [security2:error] [pid 18946:tid 18969] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORVQABNhY"]
[Thu Sep 17 15:32:49.851336 2026] [security2:error] [pid 18946:tid 19128] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORVgAAAT4"]
[Thu Sep 17 15:32:49.910249 2026] [security2:error] [pid 18946:tid 19037] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORVwABNVo"]
[Thu Sep 17 15:32:49.963578 2026] [security2:error] [pid 18946:tid 18970] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxcgTqiPMah0Tz_U1ORWgABbhc"]
[Thu Sep 17 15:32:50.002879 2026] [security2:error] [pid 20162:tid 20308] [client 34.166.154.225:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/pi.php"] [unique_id "aqxcgq-O_Kk7aqBvaiF6SgAAAZ4"]
[Thu Sep 17 15:32:50.008525 2026] [security2:error] [pid 18946:tid 18984] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORWwABWSU"]
[Thu Sep 17 15:32:50.024395 2026] [security2:error] [pid 18946:tid 19080] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORXwAAAQ4"]
[Thu Sep 17 15:32:50.050708 2026] [security2:error] [pid 18946:tid 19106] [client 34.94.39.26:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/core/phpinfo.php"] [unique_id "aqxcgjqiPMah0Tz_U1ORYQAAASg"]
[Thu Sep 17 15:32:50.061793 2026] [security2:error] [pid 20162:tid 20346] [client 34.94.39.26:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/phpinfo.php.old"] [unique_id "aqxcgq-O_Kk7aqBvaiF6TAAAAcQ"]
[Thu Sep 17 15:32:50.067855 2026] [security2:error] [pid 18946:tid 18982] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORYgABFiM"]
[Thu Sep 17 15:32:50.144506 2026] [security2:error] [pid 18946:tid 18992] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORaQABMS0"]
[Thu Sep 17 15:32:50.195701 2026] [security2:error] [pid 18946:tid 19112] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORagAAAS4"]
[Thu Sep 17 15:32:50.195716 2026] [security2:error] [pid 18946:tid 19024] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORawABTk0"]
[Thu Sep 17 15:32:50.242586 2026] [security2:error] [pid 18946:tid 18979] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORbgABQSA"]
[Thu Sep 17 15:32:50.288715 2026] [security2:error] [pid 18946:tid 18971] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORcAABhBg"]
[Thu Sep 17 15:32:50.302893 2026] [security2:error] [pid 20162:tid 20363] [client 34.94.39.26:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodymalek.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxcgq-O_Kk7aqBvaiF6TwAAAdU"]
[Thu Sep 17 15:32:50.330368 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.206.210:49790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/p.php"] [unique_id "aqxcgjqiPMah0Tz_U1ORcQAAAYk"]
[Thu Sep 17 15:32:50.353865 2026] [security2:error] [pid 20162:tid 20366] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/saas/.env"] [unique_id "aqxcgq-O_Kk7aqBvaiF6UAAAAdg"]
[Thu Sep 17 15:32:50.365883 2026] [security2:error] [pid 18946:tid 19108] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORcgAAASo"]
[Thu Sep 17 15:32:50.378708 2026] [security2:error] [pid 18946:tid 18978] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORdAABUx8"]
[Thu Sep 17 15:32:50.451272 2026] [security2:error] [pid 18946:tid 18959] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORdgABVww"]
[Thu Sep 17 15:32:50.502500 2026] [security2:error] [pid 18946:tid 18953] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxcgjqiPMah0Tz_U1OReAABEwY"]
[Thu Sep 17 15:32:50.510556 2026] [security2:error] [pid 18946:tid 19084] [client 34.94.39.26:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/phpinfo.php~"] [unique_id "aqxcgjqiPMah0Tz_U1ORegAAARI"]
[Thu Sep 17 15:32:50.535167 2026] [security2:error] [pid 18946:tid 19111] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORfgAAAS0"]
[Thu Sep 17 15:32:50.561276 2026] [security2:error] [pid 18946:tid 18983] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORfwABDCQ"]
[Thu Sep 17 15:32:50.581056 2026] [security2:error] [pid 20162:tid 20417] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/client/.env"] [unique_id "aqxcgq-O_Kk7aqBvaiF6VgAAAgs"]
[Thu Sep 17 15:32:50.594179 2026] [security2:error] [pid 18946:tid 18973] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORgQABexo"]
[Thu Sep 17 15:32:50.635152 2026] [security2:error] [pid 18946:tid 18986] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORhQABMyc"]
[Thu Sep 17 15:32:50.671821 2026] [security2:error] [pid 18946:tid 19023] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORhwABC0w"]
[Thu Sep 17 15:32:50.690241 2026] [security2:error] [pid 18946:tid 19145] [client 34.166.154.225:50888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/pinfo.php"] [unique_id "aqxcgjqiPMah0Tz_U1ORiAAAAU8"]
[Thu Sep 17 15:32:50.719447 2026] [security2:error] [pid 18946:tid 19161] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORiwAAAV8"]
[Thu Sep 17 15:32:50.756569 2026] [security2:error] [pid 18946:tid 18999] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORjQABcjQ"]
[Thu Sep 17 15:32:50.807963 2026] [security2:error] [pid 20162:tid 20368] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/project/.env"] [unique_id "aqxcgq-O_Kk7aqBvaiF6WgAAAdo"]
[Thu Sep 17 15:32:50.841735 2026] [security2:error] [pid 18946:tid 18975] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORkwABXBw"]
[Thu Sep 17 15:32:50.889254 2026] [security2:error] [pid 18946:tid 19147] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORlwAAAVE"]
[Thu Sep 17 15:32:50.899064 2026] [security2:error] [pid 18946:tid 19068] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORmAABVXk"]
[Thu Sep 17 15:32:50.923007 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.39.26:44182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/info.php.bak"] [unique_id "aqxcgjqiPMah0Tz_U1ORmQAAARQ"]
[Thu Sep 17 15:32:50.978203 2026] [security2:error] [pid 18946:tid 18951] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxcgjqiPMah0Tz_U1ORngABNAQ"]
[Thu Sep 17 15:32:51.037058 2026] [security2:error] [pid 18946:tid 19167] [client 34.166.206.210:49792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxcgzqiPMah0Tz_U1ORpAAAAWU"]
[Thu Sep 17 15:32:51.038307 2026] [security2:error] [pid 20162:tid 20384] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/admin-panel/.env"] [unique_id "aqxcg6-O_Kk7aqBvaiF6XwAAAeo"]
[Thu Sep 17 15:32:51.048549 2026] [security2:error] [pid 18946:tid 19014] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORpQABeEM"]
[Thu Sep 17 15:32:51.068293 2026] [security2:error] [pid 18946:tid 19136] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORpgAAAUY"]
[Thu Sep 17 15:32:51.110246 2026] [security2:error] [pid 20162:tid 20419] [client 179.15.176.117:59908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcgq-O_Kk7aqBvaiF6XgACDTo"]
[Thu Sep 17 15:32:51.128931 2026] [security2:error] [pid 18946:tid 18990] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORqAABGis"]
[Thu Sep 17 15:32:51.184072 2026] [security2:error] [pid 18946:tid 19019] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORqwABh0g"]
[Thu Sep 17 15:32:51.205164 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.39.26:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/phpinfo.php.save"] [unique_id "aqxcgzqiPMah0Tz_U1ORrgAAASY"]
[Thu Sep 17 15:32:51.240209 2026] [security2:error] [pid 18946:tid 19120] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORrwAAATY"]
[Thu Sep 17 15:32:51.265783 2026] [security2:error] [pid 20162:tid 20302] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/control-panel/.env"] [unique_id "aqxcg6-O_Kk7aqBvaiF6YwAAAZg"]
[Thu Sep 17 15:32:51.269438 2026] [security2:error] [pid 18946:tid 19003] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORsQABWzg"]
[Thu Sep 17 15:32:51.320153 2026] [security2:error] [pid 18946:tid 18985] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORtAABHiY"]
[Thu Sep 17 15:32:51.379653 2026] [security2:error] [pid 18946:tid 19162] [client 34.166.154.225:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/test.php"] [unique_id "aqxcgzqiPMah0Tz_U1ORtQAAAWA"]
[Thu Sep 17 15:32:51.394514 2026] [security2:error] [pid 18946:tid 18989] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORtgABbio"]
[Thu Sep 17 15:32:51.419067 2026] [security2:error] [pid 18946:tid 19175] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORtwAAAW0"]
[Thu Sep 17 15:32:51.431591 2026] [security2:error] [pid 18946:tid 18972] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORuAABNxk"]
[Thu Sep 17 15:32:51.472412 2026] [security2:error] [pid 18946:tid 19000] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORugABKDU"]
[Thu Sep 17 15:32:51.497775 2026] [security2:error] [pid 20162:tid 20318] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/user-panel/.env"] [unique_id "aqxcg6-O_Kk7aqBvaiF6ZgAAAag"]
[Thu Sep 17 15:32:51.592523 2026] [security2:error] [pid 18946:tid 18991] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORwQABYSw"]
[Thu Sep 17 15:32:51.593612 2026] [security2:error] [pid 18946:tid 19190] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORwgAAAXw"]
[Thu Sep 17 15:32:51.639407 2026] [security2:error] [pid 18946:tid 19112] [client 34.94.39.26:44198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/staging/phpinfo.php"] [unique_id "aqxcgzqiPMah0Tz_U1ORxAAAAS4"]
[Thu Sep 17 15:32:51.641976 2026] [security2:error] [pid 18946:tid 19016] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORxQABQUU"]
[Thu Sep 17 15:32:51.720386 2026] [security2:error] [pid 18946:tid 19015] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORyAABf0Q"]
[Thu Sep 17 15:32:51.724140 2026] [security2:error] [pid 20162:tid 20386] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/node/.env"] [unique_id "aqxcg6-O_Kk7aqBvaiF6awAAAew"]
[Thu Sep 17 15:32:51.727744 2026] [security2:error] [pid 18946:tid 19194] [client 34.166.206.210:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxcgzqiPMah0Tz_U1ORyQAAAYA"]
[Thu Sep 17 15:32:51.737034 2026] [security2:error] [pid 18946:tid 19168] [client 114.198.138.124:53310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcgzqiPMah0Tz_U1ORywAAAWY"]
[Thu Sep 17 15:32:51.737122 2026] [security2:error] [pid 18946:tid 19168] [client 114.198.138.124:53310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcgzqiPMah0Tz_U1ORywAAAWY"]
[Thu Sep 17 15:32:51.753273 2026] [security2:error] [pid 18946:tid 19108] [client 40.81.232.68:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxcgzqiPMah0Tz_U1ORzAAAASo"], referer: binance.com
[Thu Sep 17 15:32:51.767568 2026] [security2:error] [pid 18946:tid 19089] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORzQAAARc"]
[Thu Sep 17 15:32:51.796575 2026] [security2:error] [pid 18946:tid 19001] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxcgzqiPMah0Tz_U1ORzgABYzY"]
[Thu Sep 17 15:32:51.842270 2026] [security2:error] [pid 18946:tid 19005] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxcgzqiPMah0Tz_U1OR0AABFTo"]
[Thu Sep 17 15:32:51.890784 2026] [security2:error] [pid 18946:tid 18987] [remote 34.94.35.161:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.latranslator.com"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxcgzqiPMah0Tz_U1OR0QABVyg"]
[Thu Sep 17 15:32:51.948115 2026] [security2:error] [pid 18946:tid 19085] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxcgzqiPMah0Tz_U1OR0wAAARM"]
[Thu Sep 17 15:32:51.952323 2026] [security2:error] [pid 18946:tid 19013] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/phpinfo.php"] [unique_id "aqxcgzqiPMah0Tz_U1OR1AABEkI"]
[Thu Sep 17 15:32:51.953147 2026] [security2:error] [pid 20162:tid 20301] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/express/.env"] [unique_id "aqxcg6-O_Kk7aqBvaiF6cAAAAZc"]
[Thu Sep 17 15:32:51.998321 2026] [security2:error] [pid 18946:tid 19012] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/info.php"] [unique_id "aqxcgzqiPMah0Tz_U1OR2AABVEE"]
[Thu Sep 17 15:32:52.062589 2026] [security2:error] [pid 18946:tid 19020] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/php.php"] [unique_id "aqxchDqiPMah0Tz_U1OR2wABOEk"]
[Thu Sep 17 15:32:52.105958 2026] [security2:error] [pid 18946:tid 18976] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/i.php"] [unique_id "aqxchDqiPMah0Tz_U1OR3gABCx0"]
[Thu Sep 17 15:32:52.122958 2026] [security2:error] [pid 18946:tid 19145] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxchDqiPMah0Tz_U1OR3wAAAU8"]
[Thu Sep 17 15:32:52.154075 2026] [security2:error] [pid 18946:tid 19017] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/pi.php"] [unique_id "aqxchDqiPMah0Tz_U1OR4AABd0Y"]
[Thu Sep 17 15:32:52.172356 2026] [security2:error] [pid 20162:tid 20304] [client 34.94.39.26:44206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/beta/phpinfo.php"] [unique_id "aqxchK-O_Kk7aqBvaiF6dQAAAZo"]
[Thu Sep 17 15:32:52.183911 2026] [security2:error] [pid 20162:tid 20325] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/next/.env"] [unique_id "aqxchK-O_Kk7aqBvaiF6dgAAAa8"]
[Thu Sep 17 15:32:52.214542 2026] [security2:error] [pid 18946:tid 19004] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/pinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OR4QABhTk"]
[Thu Sep 17 15:32:52.255151 2026] [security2:error] [pid 18946:tid 19006] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/test.php"] [unique_id "aqxchDqiPMah0Tz_U1OR5AABbzs"]
[Thu Sep 17 15:32:52.293254 2026] [security2:error] [pid 18946:tid 19079] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxchDqiPMah0Tz_U1OR5wAAAQ0"]
[Thu Sep 17 15:32:52.319317 2026] [security2:error] [pid 18946:tid 19196] [client 34.166.154.225:50912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/p.php"] [unique_id "aqxchDqiPMah0Tz_U1OR6AAAAYI"]
[Thu Sep 17 15:32:52.353120 2026] [security2:error] [pid 18946:tid 19057] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/p.php"] [unique_id "aqxchDqiPMah0Tz_U1OR6QABem4"]
[Thu Sep 17 15:32:52.394052 2026] [security2:error] [pid 18946:tid 19009] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/debug.php"] [unique_id "aqxchDqiPMah0Tz_U1OR6gABID4"]
[Thu Sep 17 15:32:52.411155 2026] [security2:error] [pid 20162:tid 20305] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/nuxt/.env"] [unique_id "aqxchK-O_Kk7aqBvaiF6egAAAZs"]
[Thu Sep 17 15:32:52.424915 2026] [security2:error] [pid 20162:tid 20360] [client 34.166.206.210:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxchK-O_Kk7aqBvaiF6fAAAAdI"]
[Thu Sep 17 15:32:52.426687 2026] [security2:error] [pid 18946:tid 19045] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OR7AABa2I"]
[Thu Sep 17 15:32:52.462970 2026] [security2:error] [pid 18946:tid 19182] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxchDqiPMah0Tz_U1OR7QAAAXQ"]
[Thu Sep 17 15:32:52.463138 2026] [core:error] [pid 20162:tid 20295] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:52.463148 2026] [core:error] [pid 20162:tid 20295] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:52.560069 2026] [security2:error] [pid 18946:tid 19022] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/test/phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OR8wABREs"]
[Thu Sep 17 15:32:52.616354 2026] [security2:error] [pid 18946:tid 19011] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OR9QABXkA"]
[Thu Sep 17 15:32:52.632947 2026] [security2:error] [pid 18946:tid 19169] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxchDqiPMah0Tz_U1OR9wAAAWc"]
[Thu Sep 17 15:32:52.637670 2026] [security2:error] [pid 20162:tid 20331] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/nest/.env"] [unique_id "aqxchK-O_Kk7aqBvaiF6fwAAAbU"]
[Thu Sep 17 15:32:52.646597 2026] [security2:error] [pid 18946:tid 19039] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/old/phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OR-AABYlw"]
[Thu Sep 17 15:32:52.684430 2026] [security2:error] [pid 18946:tid 19008] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OR-QABND0"]
[Thu Sep 17 15:32:52.725400 2026] [security2:error] [pid 18946:tid 19018] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/public/phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OR-gABK0c"]
[Thu Sep 17 15:32:52.745006 2026] [security2:error] [pid 20162:tid 20388] [client 52.28.162.93:39206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxchK-O_Kk7aqBvaiF6gAAAAe4"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:32:52.805081 2026] [security2:error] [pid 18946:tid 19083] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxchDqiPMah0Tz_U1OR_QAAARE"]
[Thu Sep 17 15:32:52.834500 2026] [security2:error] [pid 18946:tid 19059] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/php-info.php"] [unique_id "aqxchDqiPMah0Tz_U1OR_gABGnA"]
[Thu Sep 17 15:32:52.865012 2026] [security2:error] [pid 20162:tid 20348] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/react/.env"] [unique_id "aqxchK-O_Kk7aqBvaiF6ggAAAcY"]
[Thu Sep 17 15:32:52.867220 2026] [security2:error] [pid 20162:tid 20294] [client 34.94.39.26:44212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/uat/phpinfo.php"] [unique_id "aqxchK-O_Kk7aqBvaiF6gwAAAZA"]
[Thu Sep 17 15:32:52.908870 2026] [security2:error] [pid 18946:tid 19043] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/phpversion.php"] [unique_id "aqxchDqiPMah0Tz_U1OR_wABZGA"]
[Thu Sep 17 15:32:52.947476 2026] [security2:error] [pid 18946:tid 19010] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/_phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OSAAABQj8"]
[Thu Sep 17 15:32:52.982167 2026] [security2:error] [pid 18946:tid 19143] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxchDqiPMah0Tz_U1OSAwAAAU0"]
[Thu Sep 17 15:32:52.982923 2026] [security2:error] [pid 18946:tid 19030] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/old_phpinfo.php"] [unique_id "aqxchDqiPMah0Tz_U1OSBAABJlM"]
[Thu Sep 17 15:32:53.008033 2026] [security2:error] [pid 18946:tid 19186] [client 34.166.154.225:50916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/debug.php"] [unique_id "aqxchTqiPMah0Tz_U1OSBgAAAXg"]
[Thu Sep 17 15:32:53.076330 2026] [security2:error] [pid 18946:tid 19058] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/server-info.php"] [unique_id "aqxchTqiPMah0Tz_U1OSCQABW28"]
[Thu Sep 17 15:32:53.091868 2026] [security2:error] [pid 20162:tid 20315] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vue/.env"] [unique_id "aqxcha-O_Kk7aqBvaiF6iQAAAaU"]
[Thu Sep 17 15:32:53.139362 2026] [security2:error] [pid 20162:tid 20356] [client 34.166.206.210:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxcha-O_Kk7aqBvaiF6igAAAc4"]
[Thu Sep 17 15:32:53.161594 2026] [security2:error] [pid 18946:tid 19119] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxchTqiPMah0Tz_U1OSCgAAATU"]
[Thu Sep 17 15:32:53.197425 2026] [security2:error] [pid 18946:tid 19028] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/server-status.php"] [unique_id "aqxchTqiPMah0Tz_U1OSDAABYFE"]
[Thu Sep 17 15:32:53.225113 2026] [security2:error] [pid 18946:tid 19091] [client 34.94.39.26:44220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/qa/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSDgAAARk"]
[Thu Sep 17 15:32:53.233145 2026] [security2:error] [pid 18946:tid 19200] [client 52.28.162.93:39220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxchTqiPMah0Tz_U1OSDQAAAYY"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:32:53.324057 2026] [security2:error] [pid 20162:tid 20387] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/angular/.env"] [unique_id "aqxcha-O_Kk7aqBvaiF6jgAAAe0"]
[Thu Sep 17 15:32:53.336963 2026] [security2:error] [pid 18946:tid 19121] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxchTqiPMah0Tz_U1OSEgAAATc"]
[Thu Sep 17 15:32:53.371818 2026] [security2:error] [pid 18946:tid 19021] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxchTqiPMah0Tz_U1OSEwABQ0o"]
[Thu Sep 17 15:32:53.435578 2026] [security2:error] [pid 18946:tid 19049] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSFQABbGY"]
[Thu Sep 17 15:32:53.514385 2026] [security2:error] [pid 18946:tid 19026] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSGgABLE8"]
[Thu Sep 17 15:32:53.515325 2026] [security2:error] [pid 18946:tid 19142] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxchTqiPMah0Tz_U1OSGQAAAUw"]
[Thu Sep 17 15:32:53.555023 2026] [security2:error] [pid 20162:tid 20415] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/svelte/.env"] [unique_id "aqxcha-O_Kk7aqBvaiF6kAAAAgk"]
[Thu Sep 17 15:32:53.574673 2026] [security2:error] [pid 18946:tid 19038] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSGwABhFs"]
[Thu Sep 17 15:32:53.601027 2026] [security2:error] [pid 18946:tid 19183] [client 34.94.39.26:44236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/preview/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSHAAAAXU"]
[Thu Sep 17 15:32:53.668536 2026] [security2:error] [pid 18946:tid 19029] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSHQABf1I"]
[Thu Sep 17 15:32:53.686471 2026] [security2:error] [pid 18946:tid 19194] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxchTqiPMah0Tz_U1OSHgAAAYA"]
[Thu Sep 17 15:32:53.696055 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.154.225:52798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSHwAAAXw"]
[Thu Sep 17 15:32:53.711026 2026] [security2:error] [pid 18946:tid 19052] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSIAABZmk"]
[Thu Sep 17 15:32:53.768024 2026] [security2:error] [pid 18946:tid 19050] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxchTqiPMah0Tz_U1OSIgABU2c"]
[Thu Sep 17 15:32:53.788113 2026] [security2:error] [pid 20162:tid 20335] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/vite/.env"] [unique_id "aqxcha-O_Kk7aqBvaiF6lAAAAbk"]
[Thu Sep 17 15:32:53.820671 2026] [security2:error] [pid 18946:tid 19046] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/phpinfo.php.old"] [unique_id "aqxchTqiPMah0Tz_U1OSIwABI2M"]
[Thu Sep 17 15:32:53.838482 2026] [security2:error] [pid 18946:tid 19129] [client 34.94.39.26:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/www/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSJAAAAT8"]
[Thu Sep 17 15:32:53.849366 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.206.210:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSJQAAAYk"]
[Thu Sep 17 15:32:53.866078 2026] [security2:error] [pid 18946:tid 19154] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxchTqiPMah0Tz_U1OSJgAAAVg"]
[Thu Sep 17 15:32:53.885248 2026] [security2:error] [pid 18946:tid 19042] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/phpinfo.php~"] [unique_id "aqxchTqiPMah0Tz_U1OSKAABV18"]
[Thu Sep 17 15:32:53.951025 2026] [security2:error] [pid 18946:tid 19032] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/info.php.bak"] [unique_id "aqxchTqiPMah0Tz_U1OSKQABLVU"]
[Thu Sep 17 15:32:53.951535 2026] [security2:error] [pid 18946:tid 19113] [client 34.94.39.26:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxchTqiPMah0Tz_U1OSKgAAAS8"]
[Thu Sep 17 15:32:54.014010 2026] [security2:error] [pid 20162:tid 20311] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backup/.env"] [unique_id "aqxchq-O_Kk7aqBvaiF6mQAAAaE"]
[Thu Sep 17 15:32:54.015785 2026] [security2:error] [pid 18946:tid 19048] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/phpinfo.php.save"] [unique_id "aqxchjqiPMah0Tz_U1OSLgABe2U"]
[Thu Sep 17 15:32:54.041538 2026] [security2:error] [pid 18946:tid 19077] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxchjqiPMah0Tz_U1OSMAAAAQs"]
[Thu Sep 17 15:32:54.063468 2026] [security2:error] [pid 18946:tid 19035] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSMQABT1g"]
[Thu Sep 17 15:32:54.101229 2026] [security2:error] [pid 18946:tid 18952] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSMgABiAU"]
[Thu Sep 17 15:32:54.154981 2026] [security2:error] [pid 18946:tid 19036] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSNAABb1k"]
[Thu Sep 17 15:32:54.212203 2026] [security2:error] [pid 18946:tid 19117] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxchjqiPMah0Tz_U1OSNQAAATM"]
[Thu Sep 17 15:32:54.214233 2026] [security2:error] [pid 18946:tid 19073] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSNgABcn4"]
[Thu Sep 17 15:32:54.243138 2026] [security2:error] [pid 20162:tid 20346] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/backups/.env"] [unique_id "aqxchq-O_Kk7aqBvaiF6nQAAAcQ"]
[Thu Sep 17 15:32:54.273751 2026] [security2:error] [pid 18946:tid 19027] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSOAABPFA"]
[Thu Sep 17 15:32:54.286392 2026] [security2:error] [pid 18946:tid 19161] [client 34.94.39.26:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/public_html/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSOQAAAV8"]
[Thu Sep 17 15:32:54.326761 2026] [security2:error] [pid 18946:tid 19055] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/www/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSOgABJ2w"]
[Thu Sep 17 15:32:54.368474 2026] [security2:error] [pid 18946:tid 19062] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSOwABgnM"]
[Thu Sep 17 15:32:54.389542 2026] [security2:error] [pid 18946:tid 19188] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxchjqiPMah0Tz_U1OSPAAAAXo"]
[Thu Sep 17 15:32:54.395930 2026] [security2:error] [pid 20162:tid 20328] [client 34.166.154.225:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/test/phpinfo.php"] [unique_id "aqxchq-O_Kk7aqBvaiF6nwAAAbI"]
[Thu Sep 17 15:32:54.467435 2026] [security2:error] [pid 18946:tid 19066] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSPgABO3c"]
[Thu Sep 17 15:32:54.500969 2026] [security2:error] [pid 18946:tid 19098] [client 34.166.218.131:39448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSPwAAASA"]
[Thu Sep 17 15:32:54.506734 2026] [security2:error] [pid 20162:tid 20353] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/old/.env"] [unique_id "aqxchq-O_Kk7aqBvaiF6oQAAAcs"]
[Thu Sep 17 15:32:54.527360 2026] [security2:error] [pid 18946:tid 19065] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/site/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSQQABdHY"]
[Thu Sep 17 15:32:54.552914 2026] [security2:error] [pid 20162:tid 20396] [client 34.166.206.210:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxchq-O_Kk7aqBvaiF6pAAAAfY"]
[Thu Sep 17 15:32:54.571055 2026] [security2:error] [pid 18946:tid 19137] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxchjqiPMah0Tz_U1OSQgAAAUc"]
[Thu Sep 17 15:32:54.577187 2026] [security2:error] [pid 18946:tid 19047] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSQwABHGQ"]
[Thu Sep 17 15:32:54.618019 2026] [security2:error] [pid 18946:tid 19040] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSRgABRF0"]
[Thu Sep 17 15:32:54.662395 2026] [security2:error] [pid 18946:tid 19069] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSRwABS3o"]
[Thu Sep 17 15:32:54.665211 2026] [security2:error] [pid 20162:tid 20362] [client 34.94.39.26:44252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/site/phpinfo.php"] [unique_id "aqxchq-O_Kk7aqBvaiF6pgAAAdQ"]
[Thu Sep 17 15:32:54.717211 2026] [security2:error] [pid 18946:tid 19067] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/core/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSSAABXng"]
[Thu Sep 17 15:32:54.736625 2026] [security2:error] [pid 20162:tid 20417] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/tmp/.env"] [unique_id "aqxchq-O_Kk7aqBvaiF6pwAAAgs"]
[Thu Sep 17 15:32:54.758036 2026] [security2:error] [pid 18946:tid 19072] [remote 34.94.35.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.35.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.latranslator.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxchjqiPMah0Tz_U1OSSQABZ30"]
[Thu Sep 17 15:32:54.833933 2026] [security2:error] [pid 18946:tid 19164] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxchjqiPMah0Tz_U1OSSgAAAWI"]
[Thu Sep 17 15:32:54.898617 2026] [security2:error] [pid 20162:tid 20365] [client 23.251.146.115:33472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxchq-O_Kk7aqBvaiF6owAB10I"]
[Thu Sep 17 15:32:54.964492 2026] [security2:error] [pid 20162:tid 20378] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/temp/.env"] [unique_id "aqxchq-O_Kk7aqBvaiF6qgAAAeQ"]
[Thu Sep 17 15:32:54.978129 2026] [security2:error] [pid 18946:tid 19096] [client 45.224.190.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxchTqiPMah0Tz_U1OSCwAAAR4"], referer: https://hikingforwildness.com/arizona-trail
[Thu Sep 17 15:32:55.006412 2026] [security2:error] [pid 18946:tid 19139] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxchzqiPMah0Tz_U1OSUQAAAUk"]
[Thu Sep 17 15:32:55.087092 2026] [security2:error] [pid 18946:tid 19118] [client 34.166.154.225:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxchzqiPMah0Tz_U1OSVgAAATQ"]
[Thu Sep 17 15:32:55.139179 2026] [security2:error] [pid 18946:tid 19158] [client 34.94.39.26:44268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/docs/phpinfo.php"] [unique_id "aqxchzqiPMah0Tz_U1OSWQAAAVw"]
[Thu Sep 17 15:32:55.178245 2026] [security2:error] [pid 18946:tid 19200] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxchzqiPMah0Tz_U1OSWwAAAYY"]
[Thu Sep 17 15:32:55.180119 2026] [security2:error] [pid 20162:tid 20321] [client 23.251.146.115:33472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxchq-O_Kk7aqBvaiF6qQABq0M"]
[Thu Sep 17 15:32:55.192212 2026] [security2:error] [pid 20162:tid 20329] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/lab/.env"] [unique_id "aqxch6-O_Kk7aqBvaiF6rwAAAbM"]
[Thu Sep 17 15:32:55.199444 2026] [security2:error] [pid 18946:tid 19116] [client 34.166.218.131:49692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/info.php"] [unique_id "aqxchzqiPMah0Tz_U1OSXAAAATI"]
[Thu Sep 17 15:32:55.241066 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.206.210:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxchzqiPMah0Tz_U1OSXgAAAUI"]
[Thu Sep 17 15:32:55.367973 2026] [security2:error] [pid 18946:tid 19088] [client 34.94.39.26:44274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxchzqiPMah0Tz_U1OSYgAAARY"]
[Thu Sep 17 15:32:55.369189 2026] [security2:error] [pid 18946:tid 19144] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxchzqiPMah0Tz_U1OSYwAAAU4"]
[Thu Sep 17 15:32:55.419031 2026] [security2:error] [pid 20162:tid 20419] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cronlab/.env"] [unique_id "aqxch6-O_Kk7aqBvaiF6sgAAAg0"]
[Thu Sep 17 15:32:55.645920 2026] [security2:error] [pid 20162:tid 20414] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cron/.env"] [unique_id "aqxch6-O_Kk7aqBvaiF6tgAAAgg"]
[Thu Sep 17 15:32:55.695061 2026] [security2:error] [pid 18946:tid 19172] [client 34.94.39.26:44286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/administrator/phpinfo.php"] [unique_id "aqxchzqiPMah0Tz_U1OScwAAAWo"]
[Thu Sep 17 15:32:55.781424 2026] [security2:error] [pid 20162:tid 20393] [client 34.166.154.225:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/old/phpinfo.php"] [unique_id "aqxch6-O_Kk7aqBvaiF6uQAAAfM"]
[Thu Sep 17 15:32:55.787602 2026] [security2:error] [pid 18946:tid 19168] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "missglitterteaches.com"] [uri "/index.php"] [unique_id "aqxchzqiPMah0Tz_U1OSbwAAAWY"]
[Thu Sep 17 15:32:55.875238 2026] [security2:error] [pid 20162:tid 20301] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/en/.env"] [unique_id "aqxch6-O_Kk7aqBvaiF6vQAAAZc"]
[Thu Sep 17 15:32:55.887137 2026] [security2:error] [pid 20162:tid 20386] [client 34.166.218.131:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/php.php"] [unique_id "aqxch6-O_Kk7aqBvaiF6vgAAAew"]
[Thu Sep 17 15:32:55.943014 2026] [security2:error] [pid 18946:tid 19184] [client 35.228.71.49:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxchzqiPMah0Tz_U1OSeQAAAXY"]
[Thu Sep 17 15:32:55.943550 2026] [security2:error] [pid 18946:tid 19135] [client 34.94.39.26:44292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/core/phpinfo.php"] [unique_id "aqxchzqiPMah0Tz_U1OSewAAAUU"]
[Thu Sep 17 15:32:56.164304 2026] [security2:error] [pid 20162:tid 20407] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/administrator/.env"] [unique_id "aqxciK-O_Kk7aqBvaiF6wgAAAgE"]
[Thu Sep 17 15:32:56.184669 2026] [security2:error] [pid 18946:tid 19161] [client 34.166.206.210:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxciDqiPMah0Tz_U1OShgAAAV8"]
[Thu Sep 17 15:32:56.393820 2026] [security2:error] [pid 18946:tid 19079] [client 78.130.132.151:33636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxciDqiPMah0Tz_U1OSiAABDVo"]
[Thu Sep 17 15:32:56.393944 2026] [security2:error] [pid 20162:tid 20373] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/psnlink/.env"] [unique_id "aqxciK-O_Kk7aqBvaiF6xwAAAd8"]
[Thu Sep 17 15:32:56.472476 2026] [security2:error] [pid 20162:tid 20382] [client 34.166.154.225:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxciK-O_Kk7aqBvaiF6yAAAAeg"]
[Thu Sep 17 15:32:56.480514 2026] [security2:error] [pid 18946:tid 19094] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxciDqiPMah0Tz_U1OSjgAAARw"]
[Thu Sep 17 15:32:56.506251 2026] [security2:error] [pid 20162:tid 20406] [client 34.94.39.26:44304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.39.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.melodypicture.us"] [uri "/includes/phpinfo.php"] [unique_id "aqxciK-O_Kk7aqBvaiF6yQAAAgA"]
[Thu Sep 17 15:32:56.579792 2026] [security2:error] [pid 18946:tid 19134] [client 34.166.218.131:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/i.php"] [unique_id "aqxciDqiPMah0Tz_U1OSkwAAAUQ"]
[Thu Sep 17 15:32:56.622718 2026] [security2:error] [pid 20162:tid 20411] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/exapi/.env"] [unique_id "aqxciK-O_Kk7aqBvaiF6zAAAAgU"]
[Thu Sep 17 15:32:56.656123 2026] [security2:error] [pid 18946:tid 19076] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxciDqiPMah0Tz_U1OSlQAAAQo"]
[Thu Sep 17 15:32:56.828258 2026] [security2:error] [pid 18946:tid 19139] [client 40.81.232.68:49362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxciDqiPMah0Tz_U1OSmwAAAUk"], referer: binance.com
[Thu Sep 17 15:32:56.837313 2026] [security2:error] [pid 18946:tid 19201] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxciDqiPMah0Tz_U1OSnAAAAYc"]
[Thu Sep 17 15:32:56.852325 2026] [security2:error] [pid 20162:tid 20298] [client 34.166.157.71:57488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sitemaps/.env"] [unique_id "aqxciK-O_Kk7aqBvaiF6zgAAAZQ"]
[Thu Sep 17 15:32:56.888933 2026] [security2:error] [pid 20162:tid 20295] [client 34.166.206.210:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxciK-O_Kk7aqBvaiF60AAAAZE"]
[Thu Sep 17 15:32:57.008280 2026] [security2:error] [pid 18946:tid 19175] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxciTqiPMah0Tz_U1OSpgAAAW0"]
[Thu Sep 17 15:32:57.121150 2026] [core:error] [pid 20162:tid 20294] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:57.121169 2026] [core:error] [pid 20162:tid 20294] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:57.161803 2026] [security2:error] [pid 18946:tid 19118] [client 34.166.154.225:52870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/public/phpinfo.php"] [unique_id "aqxciTqiPMah0Tz_U1OSrgAAATQ"]
[Thu Sep 17 15:32:57.185826 2026] [security2:error] [pid 18946:tid 19133] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxciTqiPMah0Tz_U1OSrwAAAUM"]
[Thu Sep 17 15:32:57.279860 2026] [security2:error] [pid 20162:tid 20379] [client 34.166.218.131:49712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxcia-O_Kk7aqBvaiF61gAAAeU"]
[Thu Sep 17 15:32:57.366879 2026] [security2:error] [pid 18946:tid 19091] [client 103.61.184.148:65313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxciTqiPMah0Tz_U1OStQAAARk"]
[Thu Sep 17 15:32:57.367243 2026] [security2:error] [pid 18946:tid 19091] [client 103.61.184.148:65313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxciTqiPMah0Tz_U1OStQAAARk"]
[Thu Sep 17 15:32:57.369372 2026] [security2:error] [pid 18946:tid 19127] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxciTqiPMah0Tz_U1OStgAAAT0"]
[Thu Sep 17 15:32:57.540688 2026] [security2:error] [pid 18946:tid 19114] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxciTqiPMah0Tz_U1OSvgAAATA"]
[Thu Sep 17 15:32:57.583001 2026] [security2:error] [pid 18946:tid 19193] [client 34.166.206.210:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxciTqiPMah0Tz_U1OSwQAAAX8"]
[Thu Sep 17 15:32:57.721599 2026] [security2:error] [pid 18946:tid 19155] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxciTqiPMah0Tz_U1OSxgAAAVk"]
[Thu Sep 17 15:32:57.905823 2026] [core:error] [pid 20162:tid 20398] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:57.905848 2026] [core:error] [pid 20162:tid 20398] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:57.914769 2026] [security2:error] [pid 18946:tid 19180] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxciTqiPMah0Tz_U1OSzgAAAXI"]
[Thu Sep 17 15:32:57.975578 2026] [security2:error] [pid 18946:tid 19189] [client 34.166.218.131:49728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxciTqiPMah0Tz_U1OSzwAAAXs"]
[Thu Sep 17 15:32:58.090245 2026] [security2:error] [pid 18946:tid 19126] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxcijqiPMah0Tz_U1OS1QAAATw"]
[Thu Sep 17 15:32:58.109558 2026] [security2:error] [pid 18946:tid 19161] [client 34.166.154.225:52886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/php-info.php"] [unique_id "aqxcijqiPMah0Tz_U1OS1gAAAV8"]
[Thu Sep 17 15:32:58.263227 2026] [security2:error] [pid 18946:tid 19177] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxcijqiPMah0Tz_U1OS2QAAAW8"]
[Thu Sep 17 15:32:58.271002 2026] [security2:error] [pid 20162:tid 20335] [client 79.116.89.151:62543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxciq-O_Kk7aqBvaiF63wAAAbk"]
[Thu Sep 17 15:32:58.271098 2026] [security2:error] [pid 20162:tid 20335] [client 79.116.89.151:62543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxciq-O_Kk7aqBvaiF63wAAAbk"]
[Thu Sep 17 15:32:58.278767 2026] [security2:error] [pid 18946:tid 19150] [client 34.166.206.210:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxcijqiPMah0Tz_U1OS2wAAAVQ"]
[Thu Sep 17 15:32:58.316938 2026] [core:error] [pid 18946:tid 19137] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:58.316973 2026] [core:error] [pid 18946:tid 19137] [client 34.94.39.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:32:58.454956 2026] [security2:error] [pid 18946:tid 19165] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxcijqiPMah0Tz_U1OS4AAAAWM"]
[Thu Sep 17 15:32:58.585967 2026] [security2:error] [pid 18946:tid 19188] [client 136.158.61.34:55862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcijqiPMah0Tz_U1OS4wAAAXo"]
[Thu Sep 17 15:32:58.586083 2026] [security2:error] [pid 18946:tid 19188] [client 136.158.61.34:55862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcijqiPMah0Tz_U1OS4wAAAXo"]
[Thu Sep 17 15:32:58.602551 2026] [security2:error] [pid 18946:tid 19082] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/logs/.env"] [unique_id "aqxcijqiPMah0Tz_U1OS5gAAARA"]
[Thu Sep 17 15:32:58.639956 2026] [security2:error] [pid 18946:tid 19096] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxcijqiPMah0Tz_U1OS6QAAAR4"]
[Thu Sep 17 15:32:58.660404 2026] [security2:error] [pid 18946:tid 19192] [client 34.166.218.131:49730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/test.php"] [unique_id "aqxcijqiPMah0Tz_U1OS6gAAAX4"]
[Thu Sep 17 15:32:58.788653 2026] [security2:error] [pid 18946:tid 19086] [client 34.166.154.225:52894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/phpversion.php"] [unique_id "aqxcijqiPMah0Tz_U1OS7QAAARQ"]
[Thu Sep 17 15:32:58.834687 2026] [security2:error] [pid 18946:tid 19116] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cache/.env"] [unique_id "aqxcijqiPMah0Tz_U1OS7gAAATI"]
[Thu Sep 17 15:32:58.843842 2026] [security2:error] [pid 18946:tid 19173] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxcijqiPMah0Tz_U1OS7wAAAWs"]
[Thu Sep 17 15:32:58.981673 2026] [security2:error] [pid 18946:tid 19201] [client 34.166.206.210:49898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxcijqiPMah0Tz_U1OS9AAAAYc"]
[Thu Sep 17 15:32:59.014975 2026] [security2:error] [pid 18946:tid 19115] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTAwAAATE"]
[Thu Sep 17 15:32:59.064286 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailer/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTHgAAAXw"]
[Thu Sep 17 15:32:59.091454 2026] [security2:error] [pid 18946:tid 19076] [client 143.105.152.240:12846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcizqiPMah0Tz_U1OTIAAAAQo"]
[Thu Sep 17 15:32:59.091559 2026] [security2:error] [pid 18946:tid 19076] [client 143.105.152.240:12846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcizqiPMah0Tz_U1OTIAAAAQo"]
[Thu Sep 17 15:32:59.198158 2026] [security2:error] [pid 18946:tid 19195] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTIQAAAYE"]
[Thu Sep 17 15:32:59.304336 2026] [security2:error] [pid 18946:tid 19191] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mail/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTJgAAAX0"]
[Thu Sep 17 15:32:59.369947 2026] [security2:error] [pid 18946:tid 19081] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTNgAAAQ8"]
[Thu Sep 17 15:32:59.473514 2026] [security2:error] [pid 20162:tid 20413] [client 34.166.154.225:52908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/_phpinfo.php"] [unique_id "aqxci6-O_Kk7aqBvaiF64QAAAgc"]
[Thu Sep 17 15:32:59.541418 2026] [security2:error] [pid 18946:tid 19161] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/email/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTRQAAAV8"]
[Thu Sep 17 15:32:59.551448 2026] [security2:error] [pid 18946:tid 19151] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTRgAAAVU"]
[Thu Sep 17 15:32:59.601475 2026] [security2:error] [pid 18946:tid 19178] [client 34.166.218.131:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/p.php"] [unique_id "aqxcizqiPMah0Tz_U1OTSgAAAXA"]
[Thu Sep 17 15:32:59.681289 2026] [security2:error] [pid 20162:tid 20391] [client 34.166.206.210:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxci6-O_Kk7aqBvaiF64wAAAfE"]
[Thu Sep 17 15:32:59.733615 2026] [security2:error] [pid 18946:tid 19098] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTTAAAASA"]
[Thu Sep 17 15:32:59.770990 2026] [security2:error] [pid 18946:tid 19079] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/smtp/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTTwAAAQ0"]
[Thu Sep 17 15:32:59.912758 2026] [security2:error] [pid 18946:tid 19164] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTVQAAAWI"]
[Thu Sep 17 15:32:59.999039 2026] [security2:error] [pid 18946:tid 19188] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailing/.env"] [unique_id "aqxcizqiPMah0Tz_U1OTXAAAAXo"]
[Thu Sep 17 15:33:00.086866 2026] [security2:error] [pid 18946:tid 19139] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTYgAAAUk"]
[Thu Sep 17 15:33:00.175433 2026] [security2:error] [pid 18946:tid 19165] [client 34.166.154.225:52916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/old_phpinfo.php"] [unique_id "aqxcjDqiPMah0Tz_U1OTZAAAAWM"]
[Thu Sep 17 15:33:00.231507 2026] [security2:error] [pid 18946:tid 19185] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/notifications/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTZQAAAXc"]
[Thu Sep 17 15:33:00.272002 2026] [security2:error] [pid 18946:tid 19145] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTZgAAAU8"]
[Thu Sep 17 15:33:00.293596 2026] [security2:error] [pid 18946:tid 19202] [client 34.166.218.131:45312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxcjDqiPMah0Tz_U1OTaAAAAYg"]
[Thu Sep 17 15:33:00.453729 2026] [security2:error] [pid 18946:tid 19173] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTagAAAWs"]
[Thu Sep 17 15:33:00.458417 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/notify/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTbAAAAUI"]
[Thu Sep 17 15:33:00.626944 2026] [security2:error] [pid 18946:tid 19174] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTcgAAAWw"]
[Thu Sep 17 15:33:00.687534 2026] [security2:error] [pid 18946:tid 19176] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sender/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTdAAAAW4"]
[Thu Sep 17 15:33:00.796536 2026] [security2:error] [pid 18946:tid 19091] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTdgAAARk"]
[Thu Sep 17 15:33:00.848253 2026] [security2:error] [pid 18946:tid 19108] [client 34.166.206.210:44824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcjDqiPMah0Tz_U1OTeAAAASo"]
[Thu Sep 17 15:33:00.873297 2026] [security2:error] [pid 18946:tid 19115] [client 34.166.154.225:52920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/server-info.php"] [unique_id "aqxcjDqiPMah0Tz_U1OTegAAATE"]
[Thu Sep 17 15:33:00.922678 2026] [security2:error] [pid 18946:tid 19195] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/campaign/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTfgAAAYE"]
[Thu Sep 17 15:33:00.969278 2026] [security2:error] [pid 18946:tid 19183] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxcjDqiPMah0Tz_U1OTfwAAAXU"]
[Thu Sep 17 15:33:00.973395 2026] [security2:error] [pid 18946:tid 19194] [client 34.166.218.131:45316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxcjDqiPMah0Tz_U1OTgAAAAYA"]
[Thu Sep 17 15:33:01.143272 2026] [security2:error] [pid 18946:tid 19080] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTgwAAAQ4"]
[Thu Sep 17 15:33:01.152540 2026] [security2:error] [pid 18946:tid 19102] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/newsletter/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTiQAAASQ"]
[Thu Sep 17 15:33:01.316819 2026] [security2:error] [pid 18946:tid 19181] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTjgAAAXM"]
[Thu Sep 17 15:33:01.341885 2026] [security2:error] [pid 18946:tid 19129] [client 217.138.162.13:48823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kristinagibson.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aqxcjTqiPMah0Tz_U1OTkAAAAT8"]
[Thu Sep 17 15:33:01.383417 2026] [security2:error] [pid 18946:tid 19084] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ses/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTkQAAARI"]
[Thu Sep 17 15:33:01.509648 2026] [security2:error] [pid 18946:tid 19093] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTkwAAARs"]
[Thu Sep 17 15:33:01.543988 2026] [security2:error] [pid 18946:tid 19085] [client 34.166.206.210:44834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxcjTqiPMah0Tz_U1OTlAAAARM"]
[Thu Sep 17 15:33:01.564630 2026] [security2:error] [pid 20162:tid 20363] [client 34.166.154.225:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/server-status.php"] [unique_id "aqxcja-O_Kk7aqBvaiF65QAAAdU"]
[Thu Sep 17 15:33:01.621929 2026] [security2:error] [pid 18946:tid 19123] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sendgrid/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTlQAAATk"]
[Thu Sep 17 15:33:01.659406 2026] [security2:error] [pid 20162:tid 20353] [client 34.166.218.131:45326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxcja-O_Kk7aqBvaiF65gAAAcs"]
[Thu Sep 17 15:33:01.686712 2026] [security2:error] [pid 18946:tid 19137] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTmQAAAUc"]
[Thu Sep 17 15:33:01.813769 2026] [security2:error] [pid 20162:tid 20396] [client 40.81.232.68:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxcja-O_Kk7aqBvaiF65wAAAfY"], referer: binance.com
[Thu Sep 17 15:33:01.849240 2026] [security2:error] [pid 18946:tid 19182] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/sparkpost/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTnQAAAXQ"]
[Thu Sep 17 15:33:01.872297 2026] [security2:error] [pid 18946:tid 19130] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxcjTqiPMah0Tz_U1OTngAAAUA"]
[Thu Sep 17 15:33:02.065467 2026] [security2:error] [pid 18946:tid 19152] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OToQAAAVY"]
[Thu Sep 17 15:33:02.075956 2026] [security2:error] [pid 18946:tid 19146] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/postmark/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTowAAAVA"]
[Thu Sep 17 15:33:02.222713 2026] [security2:error] [pid 18946:tid 19186] [client 45.229.89.18:48054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcjjqiPMah0Tz_U1OTpAABeAk"]
[Thu Sep 17 15:33:02.223984 2026] [security2:error] [pid 18946:tid 19156] [client 34.166.206.210:44844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxcjjqiPMah0Tz_U1OTqgAAAVo"]
[Thu Sep 17 15:33:02.234943 2026] [security2:error] [pid 18946:tid 19202] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTqwAAAYg"]
[Thu Sep 17 15:33:02.289575 2026] [security2:error] [pid 18946:tid 19136] [client 114.198.138.124:53979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcjjqiPMah0Tz_U1OTrQAAAUY"]
[Thu Sep 17 15:33:02.289720 2026] [security2:error] [pid 18946:tid 19136] [client 114.198.138.124:53979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcjjqiPMah0Tz_U1OTrQAAAUY"]
[Thu Sep 17 15:33:02.302849 2026] [security2:error] [pid 18946:tid 19170] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailgun/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTrgAAAWg"]
[Thu Sep 17 15:33:02.343503 2026] [security2:error] [pid 18946:tid 19187] [client 34.166.218.131:45332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxcjjqiPMah0Tz_U1OTsAAAAXk"]
[Thu Sep 17 15:33:02.409155 2026] [security2:error] [pid 18946:tid 19162] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTswAAAWA"]
[Thu Sep 17 15:33:02.426322 2026] [security2:error] [pid 20162:tid 20400] [client 217.138.162.13:31467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.162.138.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kristinagibson.com"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aqxcjq-O_Kk7aqBvaiF66AAAAfo"]
[Thu Sep 17 15:33:02.530104 2026] [security2:error] [pid 18946:tid 19201] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mandrill/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTtwAAAYc"]
[Thu Sep 17 15:33:02.531631 2026] [security2:error] [pid 18946:tid 19155] [client 173.252.107.8:64048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mybeloved.camera"] [uri "/index.php"] [unique_id "aqxcizqiPMah0Tz_U1OTNAABWQU"]
[Thu Sep 17 15:33:02.588403 2026] [security2:error] [pid 18946:tid 19095] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTuAAAAR0"]
[Thu Sep 17 15:33:02.714464 2026] [security2:error] [pid 18946:tid 19108] [client 34.166.154.225:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcjjqiPMah0Tz_U1OTwAAAASo"]
[Thu Sep 17 15:33:02.757237 2026] [security2:error] [pid 18946:tid 19149] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mailjet/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTwQAAAVM"]
[Thu Sep 17 15:33:02.760911 2026] [security2:error] [pid 18946:tid 19115] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTwgAAATE"]
[Thu Sep 17 15:33:02.812677 2026] [security2:error] [pid 18946:tid 18947] [remote 47.128.35.119:30710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mavenme.com"] [uri "/robots.txt"] [unique_id "aqxcjjqiPMah0Tz_U1OTwwABVwA"]
[Thu Sep 17 15:33:02.898892 2026] [security2:error] [pid 20162:tid 20362] [client 34.166.206.210:44854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcjq-O_Kk7aqBvaiF66QAAAdQ"]
[Thu Sep 17 15:33:02.983342 2026] [security2:error] [pid 18946:tid 19104] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTywAAASY"]
[Thu Sep 17 15:33:02.983344 2026] [security2:error] [pid 18946:tid 19200] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/brevo/.env"] [unique_id "aqxcjjqiPMah0Tz_U1OTzAAAAYY"]
[Thu Sep 17 15:33:02.995021 2026] [security2:error] [pid 18946:tid 19150] [client 169.58.197.251:58417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sfvhbt.org"] [uri "/wp-login.php"] [unique_id "aqxcjjqiPMah0Tz_U1OTyQAAAVQ"], referer: binance.com
[Thu Sep 17 15:33:03.028137 2026] [security2:error] [pid 18946:tid 19195] [client 34.166.218.131:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxcjzqiPMah0Tz_U1OT0AAAAYE"]
[Thu Sep 17 15:33:03.102594 2026] [security2:error] [pid 18946:tid 19122] [client 217.138.162.13:45513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "kristinagibson.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aqxcjzqiPMah0Tz_U1OT0wAAATg"]
[Thu Sep 17 15:33:03.175542 2026] [security2:error] [pid 18946:tid 19118] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT1wAAATQ"]
[Thu Sep 17 15:33:03.210410 2026] [security2:error] [pid 18946:tid 19199] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/transactional/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT2QAAAYU"]
[Thu Sep 17 15:33:03.358329 2026] [security2:error] [pid 18946:tid 19085] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT3AAAARM"]
[Thu Sep 17 15:33:03.392214 2026] [security2:error] [pid 18946:tid 19181] [client 34.166.154.225:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxcjzqiPMah0Tz_U1OT3QAAAXM"]
[Thu Sep 17 15:33:03.437619 2026] [security2:error] [pid 18946:tid 19123] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/bulk/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT3gAAATk"]
[Thu Sep 17 15:33:03.529560 2026] [security2:error] [pid 18946:tid 19137] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT4AAAAUc"]
[Thu Sep 17 15:33:03.578611 2026] [security2:error] [pid 18946:tid 19093] [client 34.166.206.210:44860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcjzqiPMah0Tz_U1OT4QAAARs"]
[Thu Sep 17 15:33:03.663830 2026] [security2:error] [pid 18946:tid 19130] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/aws/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT5gAAAUA"]
[Thu Sep 17 15:33:03.707767 2026] [security2:error] [pid 18946:tid 19094] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT6AAAARw"]
[Thu Sep 17 15:33:03.716752 2026] [security2:error] [pid 18946:tid 19177] [client 34.166.218.131:45358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcjzqiPMah0Tz_U1OT6QAAAW8"]
[Thu Sep 17 15:33:03.745627 2026] [security2:error] [pid 18946:tid 19098] [client 74.7.241.137:43118] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ramadabaymeadows.roreinvestment.com"] [uri "/robots.txt"] [unique_id "aqxcjzqiPMah0Tz_U1OT6gABIGE"]
[Thu Sep 17 15:33:03.814378 2026] [security2:error] [pid 18946:tid 19164] [client 217.138.162.13:22991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.162.138.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kristinagibson.com"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aqxcjzqiPMah0Tz_U1OT6wAAAWI"]
[Thu Sep 17 15:33:03.880562 2026] [security2:error] [pid 18946:tid 19146] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT7QAAAVA"]
[Thu Sep 17 15:33:03.890072 2026] [security2:error] [pid 18946:tid 19185] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/azure/.env"] [unique_id "aqxcjzqiPMah0Tz_U1OT7gAAAXc"]
[Thu Sep 17 15:33:04.049458 2026] [security2:error] [pid 18946:tid 19119] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxckDqiPMah0Tz_U1OT8QAAATU"]
[Thu Sep 17 15:33:04.073517 2026] [security2:error] [pid 18946:tid 19188] [client 34.166.154.225:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxckDqiPMah0Tz_U1OT8gAAAXo"]
[Thu Sep 17 15:33:04.117311 2026] [security2:error] [pid 18946:tid 19139] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gcp/.env"] [unique_id "aqxckDqiPMah0Tz_U1OT8wAAAUk"]
[Thu Sep 17 15:33:04.232788 2026] [security2:error] [pid 18946:tid 19134] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxckDqiPMah0Tz_U1OT9wAAAUQ"]
[Thu Sep 17 15:33:04.281118 2026] [security2:error] [pid 18946:tid 19202] [client 34.166.206.210:44874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxckDqiPMah0Tz_U1OT-QAAAYg"]
[Thu Sep 17 15:33:04.344616 2026] [security2:error] [pid 18946:tid 19192] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cloud/.env"] [unique_id "aqxckDqiPMah0Tz_U1OT_AAAAX4"]
[Thu Sep 17 15:33:04.404136 2026] [security2:error] [pid 18946:tid 19162] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxckDqiPMah0Tz_U1OT_gAAAWA"]
[Thu Sep 17 15:33:04.404512 2026] [security2:error] [pid 20162:tid 20378] [client 34.166.218.131:45374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxckK-O_Kk7aqBvaiF67AAAAeQ"]
[Thu Sep 17 15:33:04.573303 2026] [security2:error] [pid 18946:tid 19155] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/infrastructure/.env"] [unique_id "aqxckDqiPMah0Tz_U1OUAgAAAVk"]
[Thu Sep 17 15:33:04.594703 2026] [security2:error] [pid 18946:tid 19088] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxckDqiPMah0Tz_U1OUAwAAARY"]
[Thu Sep 17 15:33:04.772210 2026] [security2:error] [pid 18946:tid 19107] [client 34.166.154.225:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxckDqiPMah0Tz_U1OUCQAAASk"]
[Thu Sep 17 15:33:04.772518 2026] [security2:error] [pid 18946:tid 19127] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxckDqiPMah0Tz_U1OUCAAAAT0"]
[Thu Sep 17 15:33:04.807899 2026] [security2:error] [pid 18946:tid 19149] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/docker/.env"] [unique_id "aqxckDqiPMah0Tz_U1OUCgAAAVM"]
[Thu Sep 17 15:33:04.969744 2026] [security2:error] [pid 18946:tid 19133] [client 34.166.206.210:44882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxckDqiPMah0Tz_U1OUEAAAAUM"]
[Thu Sep 17 15:33:04.978754 2026] [security2:error] [pid 18946:tid 19200] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxckDqiPMah0Tz_U1OUEgAAAYY"]
[Thu Sep 17 15:33:05.035429 2026] [security2:error] [pid 18946:tid 19159] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/k8s/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUEwAAAV0"]
[Thu Sep 17 15:33:05.151254 2026] [security2:error] [pid 18946:tid 19122] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUFwAAATg"]
[Thu Sep 17 15:33:05.262221 2026] [security2:error] [pid 18946:tid 19099] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/kubernetes/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUHAAAASE"]
[Thu Sep 17 15:33:05.326331 2026] [security2:error] [pid 18946:tid 19160] [client 34.166.218.131:45384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxckTqiPMah0Tz_U1OUHgAAAV4"]
[Thu Sep 17 15:33:05.334989 2026] [security2:error] [pid 18946:tid 19157] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUHwAAAVs"]
[Thu Sep 17 15:33:05.450232 2026] [security2:error] [pid 18946:tid 19154] [client 34.166.154.225:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxckTqiPMah0Tz_U1OUIgAAAVg"]
[Thu Sep 17 15:33:05.494504 2026] [security2:error] [pid 18946:tid 19085] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/terraform/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUIwAAARM"]
[Thu Sep 17 15:33:05.505983 2026] [security2:error] [pid 18946:tid 19161] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUJAAAAV8"]
[Thu Sep 17 15:33:05.626460 2026] [security2:error] [pid 18946:tid 19138] [client 40.81.232.68:55361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxckTqiPMah0Tz_U1OUKAAAAUg"], referer: binance.com
[Thu Sep 17 15:33:05.647430 2026] [security2:error] [pid 18946:tid 19111] [client 34.166.206.210:44896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxckTqiPMah0Tz_U1OUKQAAAS0"]
[Thu Sep 17 15:33:05.683136 2026] [security2:error] [pid 18946:tid 19178] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxckTqiPMah0Tz_U1OULQAAAXA"]
[Thu Sep 17 15:33:05.725689 2026] [security2:error] [pid 18946:tid 19125] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ansible/.env"] [unique_id "aqxckTqiPMah0Tz_U1OULwAAATs"]
[Thu Sep 17 15:33:05.859991 2026] [security2:error] [pid 18946:tid 19105] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUMgAAASc"]
[Thu Sep 17 15:33:05.884465 2026] [security2:error] [pid 18946:tid 19147] [client 131.196.160.185:51460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxckTqiPMah0Tz_U1OUMQABUSA"]
[Thu Sep 17 15:33:05.952854 2026] [security2:error] [pid 18946:tid 19152] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.git/.env"] [unique_id "aqxckTqiPMah0Tz_U1OUNQAAAVY"]
[Thu Sep 17 15:33:06.006527 2026] [security2:error] [pid 18946:tid 19141] [client 34.166.218.131:45386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxckjqiPMah0Tz_U1OUNgAAAUs"]
[Thu Sep 17 15:33:06.033743 2026] [security2:error] [pid 18946:tid 19185] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUNwAAAXc"]
[Thu Sep 17 15:33:06.133764 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.154.225:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxckjqiPMah0Tz_U1OUOwAAAWI"]
[Thu Sep 17 15:33:06.184128 2026] [security2:error] [pid 18946:tid 19156] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/ci/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUPQAAAVo"]
[Thu Sep 17 15:33:06.219501 2026] [security2:error] [pid 18946:tid 19119] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUPgAAATU"]
[Thu Sep 17 15:33:06.333109 2026] [security2:error] [pid 18946:tid 19079] [client 34.166.206.210:44912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxckjqiPMah0Tz_U1OUQgAAAQ0"]
[Thu Sep 17 15:33:06.396085 2026] [security2:error] [pid 18946:tid 19202] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUQwAAAYg"]
[Thu Sep 17 15:33:06.410968 2026] [security2:error] [pid 18946:tid 19169] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cd/.env"] [unique_id "aqxckjqiPMah0Tz_U1OURAAAAWc"]
[Thu Sep 17 15:33:06.568709 2026] [security2:error] [pid 18946:tid 19162] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxckjqiPMah0Tz_U1OURwAAAWA"]
[Thu Sep 17 15:33:06.638223 2026] [security2:error] [pid 18946:tid 19120] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/jenkins/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUSgAAATY"]
[Thu Sep 17 15:33:06.702139 2026] [security2:error] [pid 18946:tid 19145] [client 34.166.218.131:45392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxckjqiPMah0Tz_U1OUTQAAAU8"]
[Thu Sep 17 15:33:06.741120 2026] [security2:error] [pid 18946:tid 19088] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUTgAAARY"]
[Thu Sep 17 15:33:06.818322 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.154.225:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxckjqiPMah0Tz_U1OUUQAAAUI"]
[Thu Sep 17 15:33:06.870415 2026] [security2:error] [pid 18946:tid 19091] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/gitlab/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUUgAAARk"]
[Thu Sep 17 15:33:06.917122 2026] [security2:error] [pid 18946:tid 19127] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxckjqiPMah0Tz_U1OUVgAAAT0"]
[Thu Sep 17 15:33:07.030746 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.206.210:44924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxckzqiPMah0Tz_U1OUWAAAAXw"]
[Thu Sep 17 15:33:07.103873 2026] [security2:error] [pid 18946:tid 19158] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/github/.env"] [unique_id "aqxckzqiPMah0Tz_U1OUWQAAAVw"]
[Thu Sep 17 15:33:07.110830 2026] [security2:error] [pid 18946:tid 19142] [client 35.228.71.49:60218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxckzqiPMah0Tz_U1OUWgAAAUw"]
[Thu Sep 17 15:33:07.306622 2026] [security2:error] [pid 18946:tid 19200] [client 35.228.71.49:60218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxckzqiPMah0Tz_U1OUYAAAAYY"]
[Thu Sep 17 15:33:07.338272 2026] [security2:error] [pid 18946:tid 19102] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/actions/.env"] [unique_id "aqxckzqiPMah0Tz_U1OUYwAAASQ"]
[Thu Sep 17 15:33:07.398862 2026] [security2:error] [pid 18946:tid 19109] [client 34.166.218.131:45398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxckzqiPMah0Tz_U1OUZwAAASs"]
[Thu Sep 17 15:33:07.536093 2026] [security2:error] [pid 18946:tid 19150] [client 34.166.154.225:52106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/phpinfo.php.old"] [unique_id "aqxckzqiPMah0Tz_U1OUaQAAAVQ"]
[Thu Sep 17 15:33:07.581394 2026] [security2:error] [pid 18946:tid 19114] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/circleci/.env"] [unique_id "aqxckzqiPMah0Tz_U1OUagAAATA"]
[Thu Sep 17 15:33:07.721137 2026] [security2:error] [pid 18946:tid 19189] [client 34.166.206.210:44928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxckzqiPMah0Tz_U1OUbwAAAXs"]
[Thu Sep 17 15:33:07.807924 2026] [security2:error] [pid 18946:tid 19104] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/travis/.env"] [unique_id "aqxckzqiPMah0Tz_U1OUcgAAASY"]
[Thu Sep 17 15:33:07.914488 2026] [security2:error] [pid 18946:tid 19118] [client 35.228.71.49:50382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/info.php"] [unique_id "aqxckzqiPMah0Tz_U1OUcwAAATQ"]
[Thu Sep 17 15:33:08.037540 2026] [security2:error] [pid 18946:tid 19123] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/buildkite/.env"] [unique_id "aqxclDqiPMah0Tz_U1OUdgAAATk"]
[Thu Sep 17 15:33:08.087458 2026] [security2:error] [pid 18946:tid 19151] [client 34.166.218.131:45402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxclDqiPMah0Tz_U1OUdwAAAVU"]
[Thu Sep 17 15:33:08.225123 2026] [security2:error] [pid 18946:tid 19181] [client 34.166.154.225:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/phpinfo.php~"] [unique_id "aqxclDqiPMah0Tz_U1OUfAAAAXM"]
[Thu Sep 17 15:33:08.266829 2026] [security2:error] [pid 18946:tid 19147] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mysql/.env"] [unique_id "aqxclDqiPMah0Tz_U1OUfQAAAVE"]
[Thu Sep 17 15:33:08.403031 2026] [security2:error] [pid 18946:tid 19140] [client 34.166.206.210:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxclDqiPMah0Tz_U1OUfwAAAUo"]
[Thu Sep 17 15:33:08.439771 2026] [security2:error] [pid 20162:tid 20357] [client 35.228.71.49:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/php.php"] [unique_id "aqxclK-O_Kk7aqBvaiF68QAAAc8"]
[Thu Sep 17 15:33:08.493954 2026] [security2:error] [pid 18946:tid 19119] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/postgres/.env"] [unique_id "aqxclDqiPMah0Tz_U1OUgQAAATU"]
[Thu Sep 17 15:33:08.720538 2026] [security2:error] [pid 18946:tid 19165] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/mongodb/.env"] [unique_id "aqxclDqiPMah0Tz_U1OUhwAAAWM"]
[Thu Sep 17 15:33:08.774409 2026] [security2:error] [pid 20162:tid 20354] [client 34.166.218.131:45416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxclK-O_Kk7aqBvaiF68wAAAcw"]
[Thu Sep 17 15:33:08.821990 2026] [security2:error] [pid 18946:tid 19139] [client 79.116.89.151:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxclDqiPMah0Tz_U1OUiAAAAUk"]
[Thu Sep 17 15:33:08.822085 2026] [security2:error] [pid 18946:tid 19139] [client 79.116.89.151:63143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxclDqiPMah0Tz_U1OUiAAAAUk"]
[Thu Sep 17 15:33:08.903359 2026] [security2:error] [pid 18946:tid 19188] [client 34.166.154.225:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/info.php.bak"] [unique_id "aqxclDqiPMah0Tz_U1OUigAAAXo"]
[Thu Sep 17 15:33:08.947970 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/redis/.env"] [unique_id "aqxclDqiPMah0Tz_U1OUiwAAAUY"]
[Thu Sep 17 15:33:08.984684 2026] [security2:error] [pid 18946:tid 19166] [client 103.61.184.148:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxclDqiPMah0Tz_U1OUjAAAAWQ"]
[Thu Sep 17 15:33:08.984819 2026] [security2:error] [pid 18946:tid 19166] [client 103.61.184.148:49553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxclDqiPMah0Tz_U1OUjAAAAWQ"]
[Thu Sep 17 15:33:08.989289 2026] [security2:error] [pid 18946:tid 19124] [client 35.228.71.49:50396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/i.php"] [unique_id "aqxclDqiPMah0Tz_U1OUjQAAATo"]
[Thu Sep 17 15:33:09.085310 2026] [security2:error] [pid 18946:tid 19086] [client 34.166.206.210:44958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxclTqiPMah0Tz_U1OUkwAAARQ"]
[Thu Sep 17 15:33:09.177407 2026] [security2:error] [pid 18946:tid 19091] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/elasticsearch/.env"] [unique_id "aqxclTqiPMah0Tz_U1OUmQAAARk"]
[Thu Sep 17 15:33:09.406005 2026] [security2:error] [pid 18946:tid 19087] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/rabbitmq/.env"] [unique_id "aqxclTqiPMah0Tz_U1OUnwAAARU"]
[Thu Sep 17 15:33:09.526097 2026] [security2:error] [pid 20162:tid 20355] [client 35.228.71.49:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxcla-O_Kk7aqBvaiF69gAAAc0"]
[Thu Sep 17 15:33:09.582426 2026] [security2:error] [pid 20162:tid 20303] [client 34.166.154.225:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/phpinfo.php.save"] [unique_id "aqxcla-O_Kk7aqBvaiF69wAAAZk"]
[Thu Sep 17 15:33:09.632911 2026] [security2:error] [pid 18946:tid 19115] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/kafka/.env"] [unique_id "aqxclTqiPMah0Tz_U1OUpAAAATE"]
[Thu Sep 17 15:33:09.763380 2026] [security2:error] [pid 18946:tid 19187] [client 143.105.152.240:21736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxclTqiPMah0Tz_U1OUqwAAAXk"]
[Thu Sep 17 15:33:09.766287 2026] [security2:error] [pid 20162:tid 20393] [client 34.166.206.210:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxcla-O_Kk7aqBvaiF6-AAAAfM"]
[Thu Sep 17 15:33:09.768619 2026] [security2:error] [pid 18946:tid 19187] [client 143.105.152.240:21736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxclTqiPMah0Tz_U1OUqwAAAXk"]
[Thu Sep 17 15:33:09.865468 2026] [security2:error] [pid 18946:tid 19083] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/queue/.env"] [unique_id "aqxclTqiPMah0Tz_U1OUrQAAARE"]
[Thu Sep 17 15:33:09.949235 2026] [security2:error] [pid 18946:tid 19184] [client 34.166.218.131:45430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxclTqiPMah0Tz_U1OUrgAAAXY"]
[Thu Sep 17 15:33:10.058433 2026] [security2:error] [pid 18946:tid 19108] [client 35.228.71.49:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxcljqiPMah0Tz_U1OUsQAAASo"]
[Thu Sep 17 15:33:10.091761 2026] [security2:error] [pid 18946:tid 19150] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/worker/.env"] [unique_id "aqxcljqiPMah0Tz_U1OUswAAAVQ"]
[Thu Sep 17 15:33:10.268877 2026] [security2:error] [pid 18946:tid 19198] [client 34.166.154.225:52136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxcljqiPMah0Tz_U1OUugAAAYQ"]
[Thu Sep 17 15:33:10.320545 2026] [security2:error] [pid 18946:tid 19157] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/job/.env"] [unique_id "aqxcljqiPMah0Tz_U1OUuwAAAVs"]
[Thu Sep 17 15:33:10.451882 2026] [security2:error] [pid 18946:tid 19085] [client 34.166.206.210:51800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxcljqiPMah0Tz_U1OUwAAAARM"]
[Thu Sep 17 15:33:10.547738 2026] [security2:error] [pid 18946:tid 19137] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/test/.env"] [unique_id "aqxcljqiPMah0Tz_U1OUwgAAAUc"]
[Thu Sep 17 15:33:10.617262 2026] [security2:error] [pid 18946:tid 19118] [client 35.228.71.49:50418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/test.php"] [unique_id "aqxcljqiPMah0Tz_U1OUxgAAATQ"]
[Thu Sep 17 15:33:10.750582 2026] [security2:error] [pid 18946:tid 19178] [client 34.166.218.131:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxcljqiPMah0Tz_U1OUyAAAAXA"]
[Thu Sep 17 15:33:10.774424 2026] [security2:error] [pid 18946:tid 19181] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/qa/.env"] [unique_id "aqxcljqiPMah0Tz_U1OUygAAAXM"]
[Thu Sep 17 15:33:10.955071 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.154.225:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxcljqiPMah0Tz_U1OUzQAAAYk"]
[Thu Sep 17 15:33:11.002071 2026] [security2:error] [pid 18946:tid 19177] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/preview/.env"] [unique_id "aqxclzqiPMah0Tz_U1OUzgAAAW8"]
[Thu Sep 17 15:33:11.141850 2026] [security2:error] [pid 18946:tid 19141] [client 34.166.206.210:51816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxclzqiPMah0Tz_U1OU0gAAAUs"]
[Thu Sep 17 15:33:11.235074 2026] [security2:error] [pid 18946:tid 19139] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/beta/.env"] [unique_id "aqxclzqiPMah0Tz_U1OU2AAAAUk"]
[Thu Sep 17 15:33:11.290014 2026] [security2:error] [pid 18946:tid 19156] [client 45.236.222.55:60797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxclzqiPMah0Tz_U1OU0wABWkg"]
[Thu Sep 17 15:33:11.330805 2026] [security2:error] [pid 20162:tid 20381] [client 35.228.71.49:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/p.php"] [unique_id "aqxcl6-O_Kk7aqBvaiF6_AAAAec"]
[Thu Sep 17 15:33:11.457933 2026] [security2:error] [pid 18946:tid 19134] [client 34.166.218.131:38716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxclzqiPMah0Tz_U1OU2wAAAUQ"]
[Thu Sep 17 15:33:11.464414 2026] [security2:error] [pid 18946:tid 19090] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/uat/.env"] [unique_id "aqxclzqiPMah0Tz_U1OU3AAAARg"]
[Thu Sep 17 15:33:11.561058 2026] [security2:error] [pid 18946:tid 19079] [client 136.158.61.34:57175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxclzqiPMah0Tz_U1OU3gAAAQ0"]
[Thu Sep 17 15:33:11.561161 2026] [security2:error] [pid 18946:tid 19079] [client 136.158.61.34:57175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxclzqiPMah0Tz_U1OU3gAAAQ0"]
[Thu Sep 17 15:33:11.652751 2026] [security2:error] [pid 18946:tid 19162] [client 34.166.154.225:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxclzqiPMah0Tz_U1OU4gAAAWA"]
[Thu Sep 17 15:33:11.693900 2026] [security2:error] [pid 18946:tid 19088] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/stage/.env"] [unique_id "aqxclzqiPMah0Tz_U1OU5QAAARY"]
[Thu Sep 17 15:33:11.851291 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.206.210:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxclzqiPMah0Tz_U1OU6wAAAUI"]
[Thu Sep 17 15:33:11.883501 2026] [security2:error] [pid 18946:tid 19142] [client 35.228.71.49:50442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxclzqiPMah0Tz_U1OU7AAAAUw"]
[Thu Sep 17 15:33:11.929955 2026] [security2:error] [pid 18946:tid 19100] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/development/.env"] [unique_id "aqxclzqiPMah0Tz_U1OU7QAAASI"]
[Thu Sep 17 15:33:12.139106 2026] [security2:error] [pid 18946:tid 19127] [client 34.166.218.131:38732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcmDqiPMah0Tz_U1OU8gAAAT0"]
[Thu Sep 17 15:33:12.163822 2026] [security2:error] [pid 18946:tid 19168] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/production/.env"] [unique_id "aqxcmDqiPMah0Tz_U1OU9AAAAWY"]
[Thu Sep 17 15:33:12.336692 2026] [security2:error] [pid 18946:tid 19195] [client 34.166.154.225:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxcmDqiPMah0Tz_U1OU9wAAAYE"]
[Thu Sep 17 15:33:12.395494 2026] [security2:error] [pid 18946:tid 19135] [client 34.166.157.71:38366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/config/app/.env"] [unique_id "aqxcmDqiPMah0Tz_U1OU-QAAAUU"]
[Thu Sep 17 15:33:12.421818 2026] [security2:error] [pid 20162:tid 20309] [client 35.228.71.49:50446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxcmK-O_Kk7aqBvaiF6_QAAAZ8"]
[Thu Sep 17 15:33:12.541689 2026] [security2:error] [pid 18946:tid 19172] [client 34.166.206.210:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcmDqiPMah0Tz_U1OVAAAAAWo"]
[Thu Sep 17 15:33:12.646139 2026] [security2:error] [pid 18946:tid 19199] [client 34.166.157.71:38366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxcmDqiPMah0Tz_U1OVBgAAAYU"]
[Thu Sep 17 15:33:12.846577 2026] [security2:error] [pid 20162:tid 20297] [client 34.166.218.131:38740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcmK-O_Kk7aqBvaiF7AQAAAZM"]
[Thu Sep 17 15:33:12.950811 2026] [security2:error] [pid 18946:tid 19122] [client 35.228.71.49:50448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxcmDqiPMah0Tz_U1OVDAAAATg"]
[Thu Sep 17 15:33:13.043549 2026] [security2:error] [pid 18946:tid 19084] [client 34.166.154.225:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVEAAAARI"]
[Thu Sep 17 15:33:13.252424 2026] [security2:error] [pid 18946:tid 19094] [client 34.166.206.210:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVGAAAARw"]
[Thu Sep 17 15:33:13.344361 2026] [security2:error] [pid 20162:tid 20382] [client 34.166.157.71:56814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/info.php"] [unique_id "aqxcma-O_Kk7aqBvaiF7BgAAAeg"]
[Thu Sep 17 15:33:13.490922 2026] [security2:error] [pid 18946:tid 19170] [client 35.228.71.49:50452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVHgAAAWg"]
[Thu Sep 17 15:33:13.540153 2026] [security2:error] [pid 20162:tid 20332] [client 34.166.218.131:38754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcma-O_Kk7aqBvaiF7BwAAAbY"]
[Thu Sep 17 15:33:13.736410 2026] [security2:error] [pid 18946:tid 19134] [client 34.166.154.225:41834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/www/phpinfo.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVKAAAAUQ"]
[Thu Sep 17 15:33:13.754582 2026] [security2:error] [pid 18946:tid 19157] [client 114.198.138.124:54637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVKgAAAVs"]
[Thu Sep 17 15:33:13.754681 2026] [security2:error] [pid 18946:tid 19157] [client 114.198.138.124:54637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVKgAAAVs"]
[Thu Sep 17 15:33:13.837585 2026] [security2:error] [pid 18946:tid 19085] [client 169.58.197.253:49981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.brianpagano.com"] [uri "/wp-login.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVLQAAARM"], referer: binance.com
[Thu Sep 17 15:33:13.945200 2026] [security2:error] [pid 18946:tid 19088] [client 34.166.206.210:51848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxcmTqiPMah0Tz_U1OVMAAAARY"]
[Thu Sep 17 15:33:14.033646 2026] [security2:error] [pid 20162:tid 20412] [client 35.228.71.49:50468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxcmq-O_Kk7aqBvaiF7CgAAAgY"]
[Thu Sep 17 15:33:14.047730 2026] [security2:error] [pid 18946:tid 19173] [client 34.166.157.71:56828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/php.php"] [unique_id "aqxcmjqiPMah0Tz_U1OVMgAAAWs"]
[Thu Sep 17 15:33:14.256532 2026] [security2:error] [pid 18946:tid 19115] [client 34.166.218.131:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxcmjqiPMah0Tz_U1OVOAAAATE"]
[Thu Sep 17 15:33:14.423547 2026] [security2:error] [pid 18946:tid 19099] [client 34.166.154.225:41842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcmjqiPMah0Tz_U1OVPgAAASE"]
[Thu Sep 17 15:33:14.558273 2026] [security2:error] [pid 18946:tid 19135] [client 35.228.71.49:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcmjqiPMah0Tz_U1OVQwAAAUU"]
[Thu Sep 17 15:33:14.581894 2026] [security2:error] [pid 18946:tid 19112] [client 181.166.92.145:49567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcmjqiPMah0Tz_U1OVPwABLkk"]
[Thu Sep 17 15:33:14.629052 2026] [security2:error] [pid 20162:tid 20348] [client 34.166.206.210:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxcmq-O_Kk7aqBvaiF7EQAAAcY"]
[Thu Sep 17 15:33:14.742057 2026] [security2:error] [pid 20162:tid 20388] [client 34.166.157.71:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/i.php"] [unique_id "aqxcmq-O_Kk7aqBvaiF7FAAAAe4"]
[Thu Sep 17 15:33:14.970959 2026] [security2:error] [pid 18946:tid 19137] [client 34.166.218.131:38776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxcmjqiPMah0Tz_U1OVSwAAAUc"]
[Thu Sep 17 15:33:15.091466 2026] [security2:error] [pid 20162:tid 20307] [client 35.228.71.49:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxcm6-O_Kk7aqBvaiF7FgAAAZ0"]
[Thu Sep 17 15:33:15.128315 2026] [security2:error] [pid 20162:tid 20415] [client 34.166.154.225:41852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcm6-O_Kk7aqBvaiF7GAAAAgk"]
[Thu Sep 17 15:33:15.325491 2026] [security2:error] [pid 18946:tid 19130] [client 34.166.206.210:51876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcmzqiPMah0Tz_U1OVWAAAAUA"]
[Thu Sep 17 15:33:15.437835 2026] [security2:error] [pid 18946:tid 19147] [client 34.166.157.71:56840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxcmzqiPMah0Tz_U1OVWgAAAVE"]
[Thu Sep 17 15:33:15.657729 2026] [security2:error] [pid 18946:tid 19141] [client 34.166.218.131:38778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxcmzqiPMah0Tz_U1OVYgAAAUs"]
[Thu Sep 17 15:33:15.798142 2026] [security2:error] [pid 18946:tid 19086] [client 35.228.71.49:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxcmzqiPMah0Tz_U1OVaQAAARQ"]
[Thu Sep 17 15:33:15.812645 2026] [security2:error] [pid 18946:tid 19136] [client 45.61.184.170:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.184.61.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.intolovinghomes.com.au"] [uri "/wp-login.php"] [unique_id "aqxcmzqiPMah0Tz_U1OVZwAAAUY"]
[Thu Sep 17 15:33:15.831123 2026] [security2:error] [pid 18946:tid 19184] [client 34.166.154.225:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/site/phpinfo.php"] [unique_id "aqxcmzqiPMah0Tz_U1OVagAAAXY"]
[Thu Sep 17 15:33:16.015036 2026] [security2:error] [pid 18946:tid 19124] [client 34.166.206.210:51884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcnDqiPMah0Tz_U1OVbQAAATo"]
[Thu Sep 17 15:33:16.134420 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.157.71:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxcnDqiPMah0Tz_U1OVbwAAAWI"]
[Thu Sep 17 15:33:16.309302 2026] [security2:error] [pid 18946:tid 19140] [client 35.228.71.49:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxcnDqiPMah0Tz_U1OVkQAAAUo"]
[Thu Sep 17 15:33:16.352697 2026] [security2:error] [pid 18946:tid 19139] [client 34.166.218.131:38788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxcnDqiPMah0Tz_U1OVkwAAAUk"]
[Thu Sep 17 15:33:16.509199 2026] [security2:error] [pid 18946:tid 19200] [client 34.166.154.225:41872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxcnDqiPMah0Tz_U1OVlgAAAYY"]
[Thu Sep 17 15:33:16.707842 2026] [security2:error] [pid 18946:tid 19078] [client 34.166.206.210:51892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxcnDqiPMah0Tz_U1OVmwAAAQw"]
[Thu Sep 17 15:33:16.822908 2026] [security2:error] [pid 20162:tid 20326] [client 34.166.157.71:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/test.php"] [unique_id "aqxcnK-O_Kk7aqBvaiF7HwAAAbA"]
[Thu Sep 17 15:33:16.853105 2026] [security2:error] [pid 18946:tid 19115] [client 35.228.71.49:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxcnDqiPMah0Tz_U1OVoQAAATE"]
[Thu Sep 17 15:33:16.890861 2026] [access_compat:error] [pid 18946:tid 19097] [client 49.12.9.78:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/haunted-legends-11-the-cursed-gift-collectors-edition
[Thu Sep 17 15:33:17.045891 2026] [security2:error] [pid 18946:tid 19150] [client 34.166.218.131:38790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxcnTqiPMah0Tz_U1OVqQAAAVQ"]
[Thu Sep 17 15:33:17.190133 2026] [security2:error] [pid 18946:tid 19199] [client 34.166.154.225:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcnTqiPMah0Tz_U1OVswAAAYU"]
[Thu Sep 17 15:33:17.375756 2026] [security2:error] [pid 18946:tid 19121] [client 35.228.71.49:58424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxcnTqiPMah0Tz_U1OVuAAAATc"]
[Thu Sep 17 15:33:17.395004 2026] [security2:error] [pid 18946:tid 19179] [client 34.166.206.210:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.206.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.suj.pyn.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxcnTqiPMah0Tz_U1OVuQAAAXE"]
[Thu Sep 17 15:33:17.552157 2026] [core:error] [pid 20162:tid 20403] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:17.552181 2026] [core:error] [pid 20162:tid 20403] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:17.723771 2026] [security2:error] [pid 18946:tid 19181] [client 34.166.218.131:38798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxcnTqiPMah0Tz_U1OVxQAAAXM"]
[Thu Sep 17 15:33:17.870443 2026] [security2:error] [pid 18946:tid 19147] [client 34.166.154.225:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcnTqiPMah0Tz_U1OVxwAAAVE"]
[Thu Sep 17 15:33:17.915855 2026] [security2:error] [pid 18946:tid 19197] [client 35.228.71.49:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxcnTqiPMah0Tz_U1OVyAAAAYM"]
[Thu Sep 17 15:33:18.239678 2026] [security2:error] [pid 20162:tid 20338] [client 34.166.157.71:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/p.php"] [unique_id "aqxcnq-O_Kk7aqBvaiF7KAAAAbw"]
[Thu Sep 17 15:33:18.244048 2026] [security2:error] [pid 20162:tid 20397] [client 142.93.128.196:53276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxcm6-O_Kk7aqBvaiF7FQAB90g"], referer: http://sableandox.co.uk/new/
[Thu Sep 17 15:33:18.417542 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.218.131:38812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxcnjqiPMah0Tz_U1OV1gAAAU0"]
[Thu Sep 17 15:33:18.450844 2026] [security2:error] [pid 20162:tid 20400] [client 35.228.71.49:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxcnq-O_Kk7aqBvaiF7KgAAAfo"]
[Thu Sep 17 15:33:18.557381 2026] [security2:error] [pid 18946:tid 19088] [client 34.166.154.225:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/core/phpinfo.php"] [unique_id "aqxcnjqiPMah0Tz_U1OV2gAAARY"]
[Thu Sep 17 15:33:18.936064 2026] [security2:error] [pid 20162:tid 20378] [client 34.166.157.71:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxcnq-O_Kk7aqBvaiF7PQAAAeQ"]
[Thu Sep 17 15:33:19.009820 2026] [security2:error] [pid 20162:tid 20357] [client 40.81.232.68:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxcn6-O_Kk7aqBvaiF7QwAAAc8"], referer: binance.com
[Thu Sep 17 15:33:19.099072 2026] [security2:error] [pid 18946:tid 19077] [client 34.166.218.131:38820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxcnzqiPMah0Tz_U1OV7AAAAQs"]
[Thu Sep 17 15:33:19.242362 2026] [security2:error] [pid 18946:tid 19189] [client 34.166.154.225:41898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.154.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholeworkplace.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxcnzqiPMah0Tz_U1OV8QAAAXs"]
[Thu Sep 17 15:33:19.250725 2026] [security2:error] [pid 20162:tid 20419] [client 142.93.128.196:53276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxcnq-O_Kk7aqBvaiF7QgACDVs"], referer: http://sableandox.co.uk/blog/
[Thu Sep 17 15:33:19.342797 2026] [security2:error] [pid 18946:tid 19154] [client 35.228.71.49:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcnzqiPMah0Tz_U1OV9AAAAVg"]
[Thu Sep 17 15:33:19.359046 2026] [security2:error] [pid 20162:tid 20346] [client 209.38.96.235:60342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcna-O_Kk7aqBvaiF7IQABxFY"], referer: http://mechapteriaao.org/new/
[Thu Sep 17 15:33:19.478750 2026] [security2:error] [pid 18946:tid 19106] [client 79.116.89.151:63748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcnzqiPMah0Tz_U1OV-AAAASg"]
[Thu Sep 17 15:33:19.478852 2026] [security2:error] [pid 18946:tid 19106] [client 79.116.89.151:63748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcnzqiPMah0Tz_U1OV-AAAASg"]
[Thu Sep 17 15:33:19.642837 2026] [security2:error] [pid 18946:tid 19102] [client 34.166.157.71:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxcnzqiPMah0Tz_U1OV_AAAASQ"]
[Thu Sep 17 15:33:19.797575 2026] [security2:error] [pid 18946:tid 19201] [client 34.166.218.131:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxcnzqiPMah0Tz_U1OWBQAAAYc"]
[Thu Sep 17 15:33:19.811291 2026] [security2:error] [pid 20162:tid 20319] [client 142.93.128.196:53276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxcn6-O_Kk7aqBvaiF7RgABqV4"], referer: http://sableandox.co.uk/backup/
[Thu Sep 17 15:33:19.884313 2026] [security2:error] [pid 18946:tid 19136] [client 35.228.71.49:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxcnzqiPMah0Tz_U1OWCAAAAUY"]
[Thu Sep 17 15:33:20.108129 2026] [security2:error] [pid 18946:tid 19123] [client 143.105.152.240:18661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcoDqiPMah0Tz_U1OWEgAAATk"]
[Thu Sep 17 15:33:20.115053 2026] [security2:error] [pid 18946:tid 19123] [client 143.105.152.240:18661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcoDqiPMah0Tz_U1OWEgAAATk"]
[Thu Sep 17 15:33:20.286263 2026] [security2:error] [pid 20162:tid 20304] [client 209.38.96.235:60342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcoK-O_Kk7aqBvaiF7VgABmnA"], referer: http://mechapteriaao.org/backup/
[Thu Sep 17 15:33:20.328154 2026] [security2:error] [pid 18946:tid 19196] [client 34.166.157.71:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxcoDqiPMah0Tz_U1OWHAAAAYI"]
[Thu Sep 17 15:33:20.394350 2026] [security2:error] [pid 20162:tid 20301] [client 142.93.128.196:53276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxcoK-O_Kk7aqBvaiF7UgABl3s"], referer: http://sableandox.co.uk/wordpress/
[Thu Sep 17 15:33:20.408649 2026] [security2:error] [pid 20162:tid 20325] [client 35.228.71.49:58470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxcoK-O_Kk7aqBvaiF7VwAAAa8"]
[Thu Sep 17 15:33:20.462294 2026] [security2:error] [pid 18946:tid 19092] [client 68.48.70.156:46677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcoDqiPMah0Tz_U1OWHQABGhM"]
[Thu Sep 17 15:33:20.485428 2026] [security2:error] [pid 20162:tid 20395] [client 34.166.218.131:57186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxcoK-O_Kk7aqBvaiF7WAAAAfU"]
[Thu Sep 17 15:33:20.507446 2026] [security2:error] [pid 18946:tid 19145] [client 209.38.96.235:54348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcoDqiPMah0Tz_U1OWIQABTwM"], referer: https://mechapteriaao.org/backup/
[Thu Sep 17 15:33:20.920553 2026] [security2:error] [pid 18946:tid 19188] [client 35.228.71.49:58474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcoDqiPMah0Tz_U1OWNwAAAXo"]
[Thu Sep 17 15:33:20.930249 2026] [autoindex:error] [pid 18946:tid 19172] [client 34.215.228.126:57206] AH01276: Cannot serve directory /home3/kippremo/public_html/brookfieldchiro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://brookfieldchiro-net.kippremote.com
[Thu Sep 17 15:33:21.028468 2026] [security2:error] [pid 20162:tid 20359] [client 34.166.157.71:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxcoa-O_Kk7aqBvaiF7YgAAAdE"]
[Thu Sep 17 15:33:21.170438 2026] [security2:error] [pid 18946:tid 19160] [client 34.166.218.131:57200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxcoTqiPMah0Tz_U1OWQgAAAV4"]
[Thu Sep 17 15:33:21.209556 2026] [security2:error] [pid 18946:tid 19090] [client 4.240.114.86:50557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxcoTqiPMah0Tz_U1OWPgAAARg"], referer: binance.com
[Thu Sep 17 15:33:21.443875 2026] [security2:error] [pid 20162:tid 20406] [client 35.228.71.49:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcoa-O_Kk7aqBvaiF7aAAAAgA"]
[Thu Sep 17 15:33:21.498210 2026] [security2:error] [pid 20162:tid 20294] [client 209.38.96.235:60342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcoa-O_Kk7aqBvaiF7ZwABkH8"], referer: http://mechapteriaao.org/blog/
[Thu Sep 17 15:33:21.621337 2026] [security2:error] [pid 20162:tid 20412] [client 142.93.128.196:53276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxcoa-O_Kk7aqBvaiF7ZQACBnw"], referer: http://sableandox.co.uk/wp/
[Thu Sep 17 15:33:21.712868 2026] [security2:error] [pid 20162:tid 20340] [client 34.166.157.71:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxcoa-O_Kk7aqBvaiF7awAAAb4"]
[Thu Sep 17 15:33:21.716125 2026] [security2:error] [pid 18946:tid 19136] [client 209.38.96.235:54348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcoTqiPMah0Tz_U1OWUQABRg8"], referer: https://mechapteriaao.org/blog/
[Thu Sep 17 15:33:21.763978 2026] [security2:error] [pid 18946:tid 19129] [client 34.95.224.210:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxcoTqiPMah0Tz_U1OWVQAAAT8"]
[Thu Sep 17 15:33:21.877334 2026] [security2:error] [pid 20162:tid 20350] [client 68.48.70.156:55017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcoa-O_Kk7aqBvaiF7bAAByGQ"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818062947&hideanons=1&hidebots=0&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:33:21.886647 2026] [security2:error] [pid 18946:tid 19098] [client 34.166.218.131:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcoTqiPMah0Tz_U1OWWAAAASA"]
[Thu Sep 17 15:33:21.988407 2026] [security2:error] [pid 18946:tid 19157] [client 35.228.71.49:58500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcoTqiPMah0Tz_U1OWWQAAAVs"]
[Thu Sep 17 15:33:22.091748 2026] [security2:error] [pid 20162:tid 20415] [client 209.38.96.235:60342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcoq-O_Kk7aqBvaiF7cAACCVo"], referer: http://mechapteriaao.org/wordpress/
[Thu Sep 17 15:33:22.173349 2026] [security2:error] [pid 20162:tid 20416] [client 142.93.128.196:53276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sableandox.co.uk"] [uri "/index.php"] [unique_id "aqxcoa-O_Kk7aqBvaiF7bwACChg"], referer: http://sableandox.co.uk/old/
[Thu Sep 17 15:33:22.305751 2026] [security2:error] [pid 18946:tid 19105] [client 209.38.96.235:54348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcojqiPMah0Tz_U1OWXwABJ2E"], referer: https://mechapteriaao.org/wordpress/
[Thu Sep 17 15:33:22.360967 2026] [security2:error] [pid 20162:tid 20307] [client 103.61.184.148:50195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcoq-O_Kk7aqBvaiF7dQAAAZ0"]
[Thu Sep 17 15:33:22.361395 2026] [security2:error] [pid 20162:tid 20307] [client 103.61.184.148:50195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcoq-O_Kk7aqBvaiF7dQAAAZ0"]
[Thu Sep 17 15:33:22.392470 2026] [security2:error] [pid 18946:tid 19202] [client 34.95.224.210:56106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/info.php"] [unique_id "aqxcojqiPMah0Tz_U1OWYQAAAYg"]
[Thu Sep 17 15:33:22.426926 2026] [security2:error] [pid 18946:tid 19196] [client 34.166.157.71:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcojqiPMah0Tz_U1OWYgAAAYI"]
[Thu Sep 17 15:33:22.525740 2026] [security2:error] [pid 20162:tid 20352] [client 35.228.71.49:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxcoq-O_Kk7aqBvaiF7dwAAAco"]
[Thu Sep 17 15:33:22.592234 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.218.131:57216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcojqiPMah0Tz_U1OWZQAAAU0"]
[Thu Sep 17 15:33:22.679746 2026] [security2:error] [pid 20162:tid 20327] [client 209.38.96.235:60342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcoq-O_Kk7aqBvaiF7eAABsXg"], referer: http://mechapteriaao.org/wp/
[Thu Sep 17 15:33:22.879691 2026] [security2:error] [pid 18946:tid 19095] [client 34.95.224.210:56120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/php.php"] [unique_id "aqxcojqiPMah0Tz_U1OWbQAAAR0"]
[Thu Sep 17 15:33:22.892366 2026] [security2:error] [pid 18946:tid 19109] [client 209.38.96.235:54348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcojqiPMah0Tz_U1OWbAABK1o"], referer: https://mechapteriaao.org/wp/
[Thu Sep 17 15:33:23.073880 2026] [security2:error] [pid 20162:tid 20363] [client 35.228.71.49:58522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxco6-O_Kk7aqBvaiF7fQAAAdU"]
[Thu Sep 17 15:33:23.107485 2026] [security2:error] [pid 18946:tid 19185] [client 34.166.157.71:60712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxcozqiPMah0Tz_U1OWcgAAAXc"]
[Thu Sep 17 15:33:23.273434 2026] [security2:error] [pid 20162:tid 20366] [client 209.38.96.235:60342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxco6-O_Kk7aqBvaiF7fgAB2AE"], referer: http://mechapteriaao.org/old/
[Thu Sep 17 15:33:23.283396 2026] [security2:error] [pid 20162:tid 20353] [client 34.166.218.131:57224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxco6-O_Kk7aqBvaiF7fwAAAcs"]
[Thu Sep 17 15:33:23.376936 2026] [security2:error] [pid 18946:tid 19199] [client 34.95.224.210:56134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/i.php"] [unique_id "aqxcozqiPMah0Tz_U1OWeQAAAYU"]
[Thu Sep 17 15:33:23.439325 2026] [security2:error] [pid 20162:tid 20343] [client 190.121.236.41:51722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxco6-O_Kk7aqBvaiF7gAAAAcE"]
[Thu Sep 17 15:33:23.445739 2026] [security2:error] [pid 20162:tid 20396] [client 114.198.138.124:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxco6-O_Kk7aqBvaiF7gQAAAfY"]
[Thu Sep 17 15:33:23.445852 2026] [security2:error] [pid 20162:tid 20396] [client 114.198.138.124:55284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxco6-O_Kk7aqBvaiF7gQAAAfY"]
[Thu Sep 17 15:33:23.473113 2026] [security2:error] [pid 20162:tid 20371] [client 103.137.189.70:57732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "manymemoirs.com"] [uri "/"] [unique_id "aqxco6-O_Kk7aqBvaiF7ggAAAd0"]
[Thu Sep 17 15:33:23.485516 2026] [security2:error] [pid 18946:tid 19078] [client 209.38.96.235:54348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxcozqiPMah0Tz_U1OWegABDBI"], referer: https://mechapteriaao.org/old/
[Thu Sep 17 15:33:23.666602 2026] [security2:error] [pid 20162:tid 20338] [client 35.228.71.49:58536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxco6-O_Kk7aqBvaiF7gwAAAbw"]
[Thu Sep 17 15:33:23.868559 2026] [security2:error] [pid 20162:tid 20368] [client 34.95.224.210:56146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxco6-O_Kk7aqBvaiF7hgAAAdo"]
[Thu Sep 17 15:33:23.868828 2026] [core:error] [pid 18946:tid 19180] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:23.868843 2026] [core:error] [pid 18946:tid 19180] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:23.959847 2026] [security2:error] [pid 20162:tid 20418] [client 34.166.218.131:57234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxco6-O_Kk7aqBvaiF7iAAAAgw"]
[Thu Sep 17 15:33:24.196125 2026] [security2:error] [pid 20162:tid 20337] [client 35.228.71.49:58552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxcpK-O_Kk7aqBvaiF7iwAAAbs"]
[Thu Sep 17 15:33:24.374236 2026] [security2:error] [pid 18946:tid 19169] [client 34.95.224.210:56154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxcpDqiPMah0Tz_U1OWiwAAAWc"]
[Thu Sep 17 15:33:24.574493 2026] [security2:error] [pid 18946:tid 19128] [client 34.166.157.71:60728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxcpDqiPMah0Tz_U1OWjQAAAT4"]
[Thu Sep 17 15:33:24.645804 2026] [security2:error] [pid 18946:tid 19094] [client 34.166.218.131:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcpDqiPMah0Tz_U1OWjwAAARw"]
[Thu Sep 17 15:33:24.720378 2026] [security2:error] [pid 18946:tid 19141] [client 35.228.71.49:58558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxcpDqiPMah0Tz_U1OWkQAAAUs"]
[Thu Sep 17 15:33:24.730582 2026] [security2:error] [pid 18946:tid 19134] [client 130.210.56.65:40712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "auxotech.com"] [uri "/"] [unique_id "aqxcpDqiPMah0Tz_U1OWkgAAAUQ"]
[Thu Sep 17 15:33:24.860034 2026] [security2:error] [pid 18946:tid 19098] [client 34.95.224.210:56156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/test.php"] [unique_id "aqxcpDqiPMah0Tz_U1OWlAAAASA"]
[Thu Sep 17 15:33:24.867728 2026] [security2:error] [pid 18946:tid 19181] [client 136.158.61.34:58554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcpDqiPMah0Tz_U1OWkwAAAXM"]
[Thu Sep 17 15:33:24.867814 2026] [security2:error] [pid 18946:tid 19181] [client 136.158.61.34:58554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcpDqiPMah0Tz_U1OWkwAAAXM"]
[Thu Sep 17 15:33:24.935699 2026] [security2:error] [pid 18946:tid 19198] [client 40.81.232.68:59047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxcpDqiPMah0Tz_U1OWlgAAAYQ"], referer: binance.com
[Thu Sep 17 15:33:25.258066 2026] [security2:error] [pid 20162:tid 20342] [client 35.228.71.49:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxcpa-O_Kk7aqBvaiF7kAAAAcA"]
[Thu Sep 17 15:33:25.259654 2026] [security2:error] [pid 20162:tid 20329] [client 34.166.157.71:60732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxcpa-O_Kk7aqBvaiF7kQAAAbM"]
[Thu Sep 17 15:33:25.347879 2026] [security2:error] [pid 18946:tid 19105] [client 34.166.218.131:57246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcpTqiPMah0Tz_U1OWnQAAASc"]
[Thu Sep 17 15:33:25.537763 2026] [security2:error] [pid 20162:tid 20325] [client 34.95.224.210:56170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/p.php"] [unique_id "aqxcpa-O_Kk7aqBvaiF7lAAAAa8"]
[Thu Sep 17 15:33:25.639886 2026] [core:error] [pid 18946:tid 19092] [client 152.232.47.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:25.639904 2026] [core:error] [pid 18946:tid 19092] [client 152.232.47.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:25.675914 2026] [security2:error] [pid 20162:tid 20393] [client 177.44.133.72:58261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcpa-O_Kk7aqBvaiF7lwAAAfM"]
[Thu Sep 17 15:33:25.676044 2026] [security2:error] [pid 20162:tid 20393] [client 177.44.133.72:58261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcpa-O_Kk7aqBvaiF7lwAAAfM"]
[Thu Sep 17 15:33:25.766351 2026] [security2:error] [pid 18946:tid 19196] [client 35.228.71.49:51916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxcpTqiPMah0Tz_U1OWpwAAAYI"]
[Thu Sep 17 15:33:25.943802 2026] [security2:error] [pid 20162:tid 20297] [client 34.166.157.71:60734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxcpa-O_Kk7aqBvaiF7nAAAAZM"]
[Thu Sep 17 15:33:26.023209 2026] [security2:error] [pid 20162:tid 20411] [client 34.95.224.210:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxcpq-O_Kk7aqBvaiF7nwAAAgU"]
[Thu Sep 17 15:33:26.054899 2026] [security2:error] [pid 18946:tid 19115] [client 34.166.218.131:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxcpjqiPMah0Tz_U1OWqwAAATE"]
[Thu Sep 17 15:33:26.293201 2026] [security2:error] [pid 18946:tid 19109] [client 35.228.71.49:51928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxcpjqiPMah0Tz_U1OWsAAAASs"]
[Thu Sep 17 15:33:26.546108 2026] [security2:error] [pid 18946:tid 19150] [client 210.222.43.21:59007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcpjqiPMah0Tz_U1OWsgAAAVQ"], referer: http://talent-in-borders.com/sitio
[Thu Sep 17 15:33:26.551595 2026] [security2:error] [pid 20162:tid 20379] [client 34.95.224.210:56188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxcpq-O_Kk7aqBvaiF7pAAAAeU"]
[Thu Sep 17 15:33:26.665750 2026] [security2:error] [pid 18946:tid 19168] [client 34.166.157.71:60746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxcpjqiPMah0Tz_U1OWtAAAAWY"]
[Thu Sep 17 15:33:26.743656 2026] [security2:error] [pid 18946:tid 19188] [client 34.166.218.131:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.218.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xhm.cia.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxcpjqiPMah0Tz_U1OWtgAAAXo"]
[Thu Sep 17 15:33:26.820819 2026] [security2:error] [pid 18946:tid 19144] [client 35.228.71.49:51940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxcpjqiPMah0Tz_U1OWtwAAAU4"]
[Thu Sep 17 15:33:27.046701 2026] [security2:error] [pid 20162:tid 20364] [client 34.95.224.210:56190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxcp6-O_Kk7aqBvaiF7pgAAAdY"]
[Thu Sep 17 15:33:27.054851 2026] [security2:error] [pid 18946:tid 19164] [client 162.241.226.11:44472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "alanpeckolick.com"] [uri "/wp-content/uploads/2015/07/AP-web-logo1.png"] [unique_id "aqxcpzqiPMah0Tz_U1OWuQAAAWI"]
[Thu Sep 17 15:33:27.229060 2026] [security2:error] [pid 20162:tid 20331] [client 169.58.197.251:60939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sfvhbt.org"] [uri "/wp-login.php"] [unique_id "aqxcp6-O_Kk7aqBvaiF7qAAAAbU"], referer: binance.com
[Thu Sep 17 15:33:27.362957 2026] [security2:error] [pid 18946:tid 19194] [client 35.228.71.49:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxcpzqiPMah0Tz_U1OWvwAAAYA"]
[Thu Sep 17 15:33:27.365805 2026] [security2:error] [pid 18946:tid 19138] [client 34.166.157.71:40600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxcpzqiPMah0Tz_U1OWwAAAAUg"]
[Thu Sep 17 15:33:27.561808 2026] [security2:error] [pid 18946:tid 19096] [client 34.95.224.210:56206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxcpzqiPMah0Tz_U1OWwgAAAR4"]
[Thu Sep 17 15:33:27.902049 2026] [security2:error] [pid 20162:tid 20335] [client 35.228.71.49:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxcp6-O_Kk7aqBvaiF7rQAAAbk"]
[Thu Sep 17 15:33:28.054365 2026] [security2:error] [pid 20162:tid 20374] [client 34.95.224.210:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxcqK-O_Kk7aqBvaiF7sQAAAeA"]
[Thu Sep 17 15:33:28.071789 2026] [core:error] [pid 18946:tid 19169] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:28.071812 2026] [core:error] [pid 18946:tid 19169] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:28.219577 2026] [security2:error] [pid 18946:tid 19156] [client 165.227.40.102:58946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxcqDqiPMah0Tz_U1OWzwAAAVo"]
[Thu Sep 17 15:33:28.423347 2026] [security2:error] [pid 20162:tid 20391] [client 35.228.71.49:51956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxcqK-O_Kk7aqBvaiF7sgAAAfE"]
[Thu Sep 17 15:33:28.539840 2026] [security2:error] [pid 20162:tid 20328] [client 165.227.40.102:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.40.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.southislandpie.ca"] [uri "/xmlrpc.php"] [unique_id "aqxcqK-O_Kk7aqBvaiF7swAAAbI"]
[Thu Sep 17 15:33:28.540279 2026] [security2:error] [pid 20162:tid 20403] [client 34.95.224.210:56232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxcqK-O_Kk7aqBvaiF7tQAAAf0"]
[Thu Sep 17 15:33:28.816412 2026] [core:error] [pid 20162:tid 20400] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:28.816431 2026] [core:error] [pid 20162:tid 20400] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:28.939463 2026] [security2:error] [pid 20162:tid 20362] [client 35.228.71.49:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcqK-O_Kk7aqBvaiF7uQAAAdQ"]
[Thu Sep 17 15:33:29.023491 2026] [security2:error] [pid 20162:tid 20417] [client 34.95.224.210:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxcqa-O_Kk7aqBvaiF7ugAAAgs"]
[Thu Sep 17 15:33:29.486736 2026] [security2:error] [pid 18946:tid 19123] [client 35.228.71.49:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxcqTqiPMah0Tz_U1OW3wAAATk"]
[Thu Sep 17 15:33:29.487296 2026] [security2:error] [pid 20162:tid 20337] [client 145.239.10.137:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veryhungrybrooklyn.com"] [uri "/access.php"] [unique_id "aqxcqa-O_Kk7aqBvaiF7vAAAAbs"], referer: http://veryhungrybrooklyn.com/access.php
[Thu Sep 17 15:33:29.585366 2026] [security2:error] [pid 18946:tid 19087] [client 34.166.157.71:40626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcqTqiPMah0Tz_U1OW4QAAARU"]
[Thu Sep 17 15:33:29.697171 2026] [security2:error] [pid 18946:tid 19081] [client 34.95.224.210:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxcqTqiPMah0Tz_U1OW5QAAAQ8"]
[Thu Sep 17 15:33:29.833797 2026] [security2:error] [pid 20162:tid 20378] [client 192.141.188.172:1160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcqa-O_Kk7aqBvaiF7vQAB5AQ"]
[Thu Sep 17 15:33:30.051712 2026] [security2:error] [pid 20162:tid 20334] [client 35.228.71.49:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF7xwAAAbg"]
[Thu Sep 17 15:33:30.137116 2026] [security2:error] [pid 20162:tid 20336] [client 79.116.89.151:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF7yQAAAbo"]
[Thu Sep 17 15:33:30.137241 2026] [security2:error] [pid 20162:tid 20336] [client 79.116.89.151:64355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF7yQAAAbo"]
[Thu Sep 17 15:33:30.203597 2026] [security2:error] [pid 20162:tid 20302] [client 34.95.224.210:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF7ywAAAZg"]
[Thu Sep 17 15:33:30.286961 2026] [security2:error] [pid 20162:tid 20342] [client 34.166.157.71:40640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF7zQAAAcA"]
[Thu Sep 17 15:33:30.607062 2026] [security2:error] [pid 20162:tid 20389] [client 35.228.71.49:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF7zgAAAe8"]
[Thu Sep 17 15:33:30.691194 2026] [security2:error] [pid 20162:tid 20409] [client 34.95.224.210:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF7zwAAAgM"]
[Thu Sep 17 15:33:30.700431 2026] [security2:error] [pid 20162:tid 20394] [client 143.105.152.240:35223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF70AAAAfQ"]
[Thu Sep 17 15:33:30.704224 2026] [security2:error] [pid 20162:tid 20394] [client 143.105.152.240:35223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcqq-O_Kk7aqBvaiF70AAAAfQ"]
[Thu Sep 17 15:33:30.966883 2026] [security2:error] [pid 18946:tid 19108] [client 34.166.157.71:40654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxcqjqiPMah0Tz_U1OW9QAAASo"]
[Thu Sep 17 15:33:31.152102 2026] [security2:error] [pid 20162:tid 20414] [client 35.228.71.49:51996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcq6-O_Kk7aqBvaiF70wAAAgg"]
[Thu Sep 17 15:33:31.195177 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.224.210:56278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxcq6-O_Kk7aqBvaiF71QAAAZs"]
[Thu Sep 17 15:33:31.538195 2026] [security2:error] [pid 18946:tid 19137] [client 165.227.40.102:59142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxcqzqiPMah0Tz_U1OW-gAAAUc"]
[Thu Sep 17 15:33:31.662055 2026] [security2:error] [pid 18946:tid 19154] [client 34.166.157.71:40664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcqzqiPMah0Tz_U1OW_QAAAVg"]
[Thu Sep 17 15:33:31.683191 2026] [security2:error] [pid 18946:tid 19144] [client 34.95.224.210:56284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxcqzqiPMah0Tz_U1OW_wAAAU4"]
[Thu Sep 17 15:33:31.683212 2026] [security2:error] [pid 18946:tid 19188] [client 35.228.71.49:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxcqzqiPMah0Tz_U1OW_gAAAXo"]
[Thu Sep 17 15:33:31.837430 2026] [security2:error] [pid 20162:tid 20322] [client 165.227.40.102:60268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxcq6-O_Kk7aqBvaiF72gAAAaw"]
[Thu Sep 17 15:33:32.147240 2026] [security2:error] [pid 18946:tid 19106] [client 165.227.40.102:60356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrDqiPMah0Tz_U1OXAgAAASg"]
[Thu Sep 17 15:33:32.194625 2026] [security2:error] [pid 18946:tid 19180] [client 34.95.224.210:43542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxcrDqiPMah0Tz_U1OXBQAAAXI"]
[Thu Sep 17 15:33:32.204771 2026] [security2:error] [pid 18946:tid 19083] [client 35.228.71.49:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.71.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mim.sjo.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxcrDqiPMah0Tz_U1OXBgAAARE"]
[Thu Sep 17 15:33:32.216847 2026] [security2:error] [pid 18946:tid 19121] [client 152.58.128.100:56191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcrDqiPMah0Tz_U1OXAQABNyI"]
[Thu Sep 17 15:33:32.346242 2026] [security2:error] [pid 18946:tid 19162] [client 34.166.157.71:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcrDqiPMah0Tz_U1OXCAAAAWA"]
[Thu Sep 17 15:33:32.484510 2026] [security2:error] [pid 18946:tid 19160] [client 165.227.40.102:60470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrDqiPMah0Tz_U1OXDAAAAV4"]
[Thu Sep 17 15:33:32.802739 2026] [security2:error] [pid 18946:tid 19084] [client 165.227.40.102:60571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrDqiPMah0Tz_U1OXEgAAARI"]
[Thu Sep 17 15:33:32.826337 2026] [security2:error] [pid 20162:tid 20398] [client 40.81.232.68:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxcrK-O_Kk7aqBvaiF73AAAAfg"], referer: binance.com
[Thu Sep 17 15:33:33.048556 2026] [security2:error] [pid 20162:tid 20350] [client 34.166.157.71:40686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcra-O_Kk7aqBvaiF73wAAAcg"]
[Thu Sep 17 15:33:33.048580 2026] [security2:error] [pid 20162:tid 20369] [client 34.95.224.210:43558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxcra-O_Kk7aqBvaiF73gAAAds"]
[Thu Sep 17 15:33:33.150557 2026] [security2:error] [pid 18946:tid 19141] [client 165.227.40.102:60687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrTqiPMah0Tz_U1OXHAAAAUs"]
[Thu Sep 17 15:33:33.275519 2026] [security2:error] [pid 18946:tid 19169] [client 103.61.184.148:50757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcrTqiPMah0Tz_U1OXHwAAAWc"]
[Thu Sep 17 15:33:33.275597 2026] [security2:error] [pid 18946:tid 19169] [client 103.61.184.148:50757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcrTqiPMah0Tz_U1OXHwAAAWc"]
[Thu Sep 17 15:33:33.449042 2026] [security2:error] [pid 18946:tid 19076] [client 165.227.40.102:60766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrTqiPMah0Tz_U1OXIQAAAQo"]
[Thu Sep 17 15:33:33.543488 2026] [security2:error] [pid 18946:tid 19086] [client 34.95.224.210:43566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxcrTqiPMah0Tz_U1OXIgAAARQ"]
[Thu Sep 17 15:33:33.726962 2026] [security2:error] [pid 18946:tid 19013] [remote 47.128.36.212:26768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kslandscaping.net"] [uri "/category/news/"] [unique_id "aqxcrTqiPMah0Tz_U1OXKAABgkI"]
[Thu Sep 17 15:33:33.732023 2026] [security2:error] [pid 18946:tid 19202] [client 34.166.157.71:40692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxcrTqiPMah0Tz_U1OXKQAAAYg"]
[Thu Sep 17 15:33:33.771266 2026] [security2:error] [pid 18946:tid 19135] [client 165.227.40.102:60872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrTqiPMah0Tz_U1OXKwAAAUU"]
[Thu Sep 17 15:33:33.840314 2026] [core:error] [pid 18946:tid 19186] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:33.840330 2026] [core:error] [pid 18946:tid 19186] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:34.042162 2026] [security2:error] [pid 18946:tid 19097] [client 34.95.224.210:43578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxcrjqiPMah0Tz_U1OXMQAAAR8"]
[Thu Sep 17 15:33:34.080547 2026] [security2:error] [pid 18946:tid 19095] [client 114.198.138.124:55940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcrjqiPMah0Tz_U1OXMgAAAR0"]
[Thu Sep 17 15:33:34.080657 2026] [security2:error] [pid 18946:tid 19095] [client 114.198.138.124:55940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcrjqiPMah0Tz_U1OXMgAAAR0"]
[Thu Sep 17 15:33:34.080907 2026] [security2:error] [pid 18946:tid 19171] [client 165.227.40.102:60963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrjqiPMah0Tz_U1OXMwAAAWk"]
[Thu Sep 17 15:33:34.376690 2026] [security2:error] [pid 20162:tid 20299] [client 165.227.40.102:61066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrq-O_Kk7aqBvaiF74QAAAZU"]
[Thu Sep 17 15:33:34.422914 2026] [security2:error] [pid 20162:tid 20298] [client 34.166.157.71:40706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxcrq-O_Kk7aqBvaiF74gAAAZQ"]
[Thu Sep 17 15:33:34.463541 2026] [security2:error] [pid 18946:tid 19080] [client 4.240.114.86:54813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alanacking.com"] [uri "/index.php"] [unique_id "aqxcrjqiPMah0Tz_U1OXOwAAAQ4"], referer: binance.com
[Thu Sep 17 15:33:34.553266 2026] [security2:error] [pid 18946:tid 19111] [client 34.95.224.210:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxcrjqiPMah0Tz_U1OXQAAAAS0"]
[Thu Sep 17 15:33:34.595212 2026] [core:error] [pid 18946:tid 19078] [client 34.166.234.125:55344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:34.595230 2026] [core:error] [pid 18946:tid 19078] [client 34.166.234.125:55344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:34.698071 2026] [security2:error] [pid 18946:tid 19106] [client 165.227.40.102:61183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrjqiPMah0Tz_U1OXRgAAASg"]
[Thu Sep 17 15:33:35.002428 2026] [security2:error] [pid 18946:tid 19110] [client 165.227.40.102:61297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrzqiPMah0Tz_U1OXSwAAASw"]
[Thu Sep 17 15:33:35.057731 2026] [security2:error] [pid 18946:tid 19167] [client 34.95.224.210:43596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxcrzqiPMah0Tz_U1OXTQAAAWU"]
[Thu Sep 17 15:33:35.124285 2026] [security2:error] [pid 18946:tid 19201] [client 34.166.157.71:40718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxcrzqiPMah0Tz_U1OXTgAAAYc"]
[Thu Sep 17 15:33:35.288009 2026] [core:error] [pid 18946:tid 19193] [client 34.166.234.125:55360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:35.288028 2026] [core:error] [pid 18946:tid 19193] [client 34.166.234.125:55360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:35.309935 2026] [security2:error] [pid 18946:tid 19197] [client 165.227.40.102:61408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrzqiPMah0Tz_U1OXVQAAAYM"]
[Thu Sep 17 15:33:35.566645 2026] [security2:error] [pid 18946:tid 19181] [client 34.95.224.210:43612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxcrzqiPMah0Tz_U1OXWQAAAXM"]
[Thu Sep 17 15:33:35.592030 2026] [autoindex:error] [pid 18946:tid 19156] [client 35.228.71.49:54706] AH01276: Cannot serve directory /home1/mimsjomy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:33:35.627369 2026] [security2:error] [pid 18946:tid 19085] [client 165.227.40.102:61510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrzqiPMah0Tz_U1OXWwAAARM"]
[Thu Sep 17 15:33:35.807702 2026] [security2:error] [pid 18946:tid 19198] [client 34.166.157.71:40724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxcrzqiPMah0Tz_U1OXXgAAAYQ"]
[Thu Sep 17 15:33:35.924736 2026] [security2:error] [pid 18946:tid 19118] [client 165.227.40.102:61613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxcrzqiPMah0Tz_U1OXYgAAATQ"]
[Thu Sep 17 15:33:35.956370 2026] [security2:error] [pid 18946:tid 19132] [client 177.44.133.72:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcrzqiPMah0Tz_U1OXYwAAAUI"]
[Thu Sep 17 15:33:35.956467 2026] [security2:error] [pid 18946:tid 19132] [client 177.44.133.72:58936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcrzqiPMah0Tz_U1OXYwAAAUI"]
[Thu Sep 17 15:33:35.975528 2026] [core:error] [pid 20162:tid 20327] [client 34.166.234.125:55374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:35.975554 2026] [core:error] [pid 20162:tid 20327] [client 34.166.234.125:55374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:36.050509 2026] [security2:error] [pid 18946:tid 19082] [client 34.95.224.210:43614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxcsDqiPMah0Tz_U1OXZAAAARA"]
[Thu Sep 17 15:33:36.223280 2026] [security2:error] [pid 18946:tid 19196] [client 165.227.40.102:61703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.southislandpie.ca"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxcsDqiPMah0Tz_U1OXaAAAAYI"]
[Thu Sep 17 15:33:36.492206 2026] [security2:error] [pid 18946:tid 19200] [client 34.166.157.71:40738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxcsDqiPMah0Tz_U1OXawAAAYY"]
[Thu Sep 17 15:33:36.534155 2026] [security2:error] [pid 20162:tid 20397] [client 34.95.224.210:43624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxcsK-O_Kk7aqBvaiF77QAAAfc"]
[Thu Sep 17 15:33:36.766894 2026] [core:error] [pid 20162:tid 20362] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:36.766918 2026] [core:error] [pid 20162:tid 20362] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:37.031186 2026] [security2:error] [pid 18946:tid 19150] [client 34.95.224.210:43638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxcsTqiPMah0Tz_U1OXcgAAAVQ"]
[Thu Sep 17 15:33:37.101244 2026] [security2:error] [pid 20162:tid 20417] [client 136.158.61.34:59851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcsa-O_Kk7aqBvaiF78QAAAgs"]
[Thu Sep 17 15:33:37.101371 2026] [security2:error] [pid 20162:tid 20417] [client 136.158.61.34:59851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcsa-O_Kk7aqBvaiF78QAAAgs"]
[Thu Sep 17 15:33:37.170323 2026] [security2:error] [pid 20162:tid 20399] [client 34.166.157.71:43864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxcsa-O_Kk7aqBvaiF78gAAAfk"]
[Thu Sep 17 15:33:37.484632 2026] [core:error] [pid 18946:tid 19192] [client 34.166.234.125:55388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:37.484650 2026] [core:error] [pid 18946:tid 19192] [client 34.166.234.125:55388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:37.531482 2026] [security2:error] [pid 18946:tid 19120] [client 34.95.224.210:43646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxcsTqiPMah0Tz_U1OXegAAATY"]
[Thu Sep 17 15:33:37.866960 2026] [security2:error] [pid 20162:tid 20323] [client 34.166.157.71:43872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxcsa-O_Kk7aqBvaiF79AAAAa0"]
[Thu Sep 17 15:33:38.045737 2026] [security2:error] [pid 20162:tid 20337] [client 34.95.224.210:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxcsq-O_Kk7aqBvaiF7-AAAAbs"]
[Thu Sep 17 15:33:38.152696 2026] [security2:error] [pid 20162:tid 20354] [client 40.81.232.68:55876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxcsq-O_Kk7aqBvaiF7-gAAAcw"], referer: binance.com
[Thu Sep 17 15:33:38.184436 2026] [security2:error] [pid 20162:tid 20378] [client 34.166.234.125:55394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "aqxcsq-O_Kk7aqBvaiF7_AAAAeQ"]
[Thu Sep 17 15:33:38.451338 2026] [core:error] [pid 20162:tid 20330] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:38.451361 2026] [core:error] [pid 20162:tid 20330] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:38.539700 2026] [security2:error] [pid 18946:tid 19125] [client 34.95.224.210:43672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxcsjqiPMah0Tz_U1OXfwAAATs"]
[Thu Sep 17 15:33:38.550371 2026] [security2:error] [pid 18946:tid 19116] [client 34.166.157.71:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxcsjqiPMah0Tz_U1OXgAAAATI"]
[Thu Sep 17 15:33:38.566413 2026] [core:error] [pid 18946:tid 19077] [client 185.207.250.239:52148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:38.566428 2026] [core:error] [pid 18946:tid 19077] [client 185.207.250.239:52148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:38.812305 2026] [cgid:error] [pid 18946:tid 19138] [client 221.149.119.65:14449] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/Wordpress
[Thu Sep 17 15:33:39.035675 2026] [security2:error] [pid 20162:tid 20373] [client 34.95.224.210:43680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxcs6-O_Kk7aqBvaiF8AwAAAd8"]
[Thu Sep 17 15:33:39.232086 2026] [core:error] [pid 18946:tid 19091] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:39.232109 2026] [core:error] [pid 18946:tid 19091] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:39.232993 2026] [security2:error] [pid 20162:tid 20329] [client 34.166.157.71:43896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxcs6-O_Kk7aqBvaiF8BAAAAbM"]
[Thu Sep 17 15:33:39.236204 2026] [security2:error] [pid 18946:tid 19193] [client 68.100.13.228:57729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcszqiPMah0Tz_U1OXhgABf1Y"]
[Thu Sep 17 15:33:39.531240 2026] [security2:error] [pid 18946:tid 19163] [client 34.95.224.210:43690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxcszqiPMah0Tz_U1OXjgAAAWE"]
[Thu Sep 17 15:33:39.919546 2026] [security2:error] [pid 20162:tid 20420] [client 34.166.157.71:43898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxcs6-O_Kk7aqBvaiF8BgAAAg4"]
[Thu Sep 17 15:33:40.025539 2026] [security2:error] [pid 18946:tid 19114] [client 34.95.224.210:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxctDqiPMah0Tz_U1OXnwAAATA"]
[Thu Sep 17 15:33:40.030488 2026] [core:error] [pid 18946:tid 19132] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:40.030503 2026] [core:error] [pid 18946:tid 19132] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:40.261989 2026] [security2:error] [pid 18946:tid 19102] [client 169.58.197.253:51700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.brianpagano.com"] [uri "/wp-login.php"] [unique_id "aqxctDqiPMah0Tz_U1OXpQAAASQ"], referer: binance.com
[Thu Sep 17 15:33:40.529157 2026] [security2:error] [pid 18946:tid 19166] [client 34.95.224.210:43712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxctDqiPMah0Tz_U1OXqQAAAWQ"]
[Thu Sep 17 15:33:40.555285 2026] [autoindex:error] [pid 18946:tid 19149] [client 4.240.114.86:56601] AH01276: Cannot serve directory /home3/rravkcmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:33:40.615711 2026] [security2:error] [pid 20162:tid 20411] [client 137.131.43.163:61164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxctK-O_Kk7aqBvaiF8DQAAAgU"]
[Thu Sep 17 15:33:40.619039 2026] [security2:error] [pid 18946:tid 19153] [client 34.166.157.71:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxctDqiPMah0Tz_U1OXrQAAAVc"]
[Thu Sep 17 15:33:40.696376 2026] [security2:error] [pid 20162:tid 20414] [client 137.131.43.163:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.43.131.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danielstepniak.com"] [uri "/xmlrpc.php"] [unique_id "aqxctK-O_Kk7aqBvaiF8DwAAAgg"]
[Thu Sep 17 15:33:40.733739 2026] [security2:error] [pid 20162:tid 20295] [client 137.131.43.163:53230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxctK-O_Kk7aqBvaiF8EAAAAZE"]
[Thu Sep 17 15:33:40.734960 2026] [security2:error] [pid 18946:tid 19092] [client 79.116.89.151:64957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxctDqiPMah0Tz_U1OXsQAAARo"]
[Thu Sep 17 15:33:40.735607 2026] [security2:error] [pid 18946:tid 19092] [client 79.116.89.151:64957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxctDqiPMah0Tz_U1OXsQAAARo"]
[Thu Sep 17 15:33:40.786195 2026] [security2:error] [pid 20162:tid 20348] [client 137.131.43.163:53547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxctK-O_Kk7aqBvaiF8EwAAAcY"]
[Thu Sep 17 15:33:40.846069 2026] [security2:error] [pid 18946:tid 19186] [client 68.100.13.228:57741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxctDqiPMah0Tz_U1OXtAABeFw"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260722130430&hideanons=1&hidebots=0&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:33:40.863810 2026] [security2:error] [pid 18946:tid 19199] [client 137.131.43.163:53907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxctDqiPMah0Tz_U1OXtQAAAYU"]
[Thu Sep 17 15:33:40.917819 2026] [security2:error] [pid 18946:tid 19137] [client 137.131.43.163:61902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxctDqiPMah0Tz_U1OXtgAAAUc"]
[Thu Sep 17 15:33:40.954446 2026] [core:error] [pid 18946:tid 19148] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:40.954475 2026] [core:error] [pid 18946:tid 19148] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:40.959127 2026] [security2:error] [pid 18946:tid 19154] [client 137.131.43.163:52693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxctDqiPMah0Tz_U1OXugAAAVg"]
[Thu Sep 17 15:33:41.004237 2026] [security2:error] [pid 18946:tid 19192] [client 137.131.43.163:62014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxctTqiPMah0Tz_U1OXuwAAAX4"]
[Thu Sep 17 15:33:41.022671 2026] [security2:error] [pid 18946:tid 19162] [client 137.131.43.163:62061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxctTqiPMah0Tz_U1OXvAAAAWA"]
[Thu Sep 17 15:33:41.052465 2026] [security2:error] [pid 18946:tid 19113] [client 137.131.43.163:62322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxctTqiPMah0Tz_U1OXvQAAAS8"]
[Thu Sep 17 15:33:41.056284 2026] [security2:error] [pid 18946:tid 19172] [client 34.95.224.210:43714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxctTqiPMah0Tz_U1OXvwAAAWo"]
[Thu Sep 17 15:33:41.108547 2026] [security2:error] [pid 18946:tid 19116] [client 137.131.43.163:61303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielstepniak.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxctTqiPMah0Tz_U1OXwgAAATI"]
[Thu Sep 17 15:33:41.312841 2026] [security2:error] [pid 18946:tid 19125] [client 34.166.157.71:43920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxctTqiPMah0Tz_U1OXxgAAATs"]
[Thu Sep 17 15:33:41.316963 2026] [security2:error] [pid 18946:tid 19097] [client 143.105.152.240:6246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxctTqiPMah0Tz_U1OXxwAAAR8"]
[Thu Sep 17 15:33:41.324750 2026] [security2:error] [pid 18946:tid 19097] [client 143.105.152.240:6246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxctTqiPMah0Tz_U1OXxwAAAR8"]
[Thu Sep 17 15:33:41.551419 2026] [security2:error] [pid 18946:tid 19193] [client 34.95.224.210:43728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxctTqiPMah0Tz_U1OXyQAAAX8"]
[Thu Sep 17 15:33:41.721444 2026] [core:error] [pid 18946:tid 19112] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:41.721461 2026] [core:error] [pid 18946:tid 19112] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:41.996429 2026] [security2:error] [pid 20162:tid 20404] [client 34.166.157.71:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxcta-O_Kk7aqBvaiF8GAAAAf4"]
[Thu Sep 17 15:33:42.039850 2026] [security2:error] [pid 20162:tid 20413] [client 34.95.224.210:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxctq-O_Kk7aqBvaiF8HAAAAgc"]
[Thu Sep 17 15:33:42.273464 2026] [security2:error] [pid 20162:tid 20383] [client 145.239.10.137:40173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veryplastic.com"] [uri "/access.php"] [unique_id "aqxctq-O_Kk7aqBvaiF8HQAAAek"], referer: http://veryplastic.com/access.php
[Thu Sep 17 15:33:42.433194 2026] [core:error] [pid 18946:tid 19123] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:42.433214 2026] [core:error] [pid 18946:tid 19123] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:42.549560 2026] [security2:error] [pid 18946:tid 19079] [client 34.95.224.210:42812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxctjqiPMah0Tz_U1OX2AAAAQ0"]
[Thu Sep 17 15:33:42.681567 2026] [security2:error] [pid 18946:tid 19139] [client 34.166.157.71:43930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxctjqiPMah0Tz_U1OX3wAAAUk"]
[Thu Sep 17 15:33:43.047871 2026] [security2:error] [pid 18946:tid 19098] [client 34.95.224.210:42820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxctzqiPMah0Tz_U1OX5QAAASA"]
[Thu Sep 17 15:33:43.141500 2026] [security2:error] [pid 20162:tid 20352] [client 74.7.228.44:34474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-70311838.newyearworks.com"] [uri "/robots.txt"] [unique_id "aqxct6-O_Kk7aqBvaiF8IAAAAco"]
[Thu Sep 17 15:33:43.144118 2026] [security2:error] [pid 18946:tid 19151] [client 34.166.234.125:55456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "aqxctzqiPMah0Tz_U1OX5gAAAVU"]
[Thu Sep 17 15:33:43.367946 2026] [security2:error] [pid 20162:tid 20327] [client 34.166.157.71:43944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxct6-O_Kk7aqBvaiF8IQAAAbE"]
[Thu Sep 17 15:33:43.373249 2026] [security2:error] [pid 18946:tid 19189] [client 34.166.234.125:55456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "aqxctzqiPMah0Tz_U1OX6wAAAXs"]
[Thu Sep 17 15:33:43.533603 2026] [security2:error] [pid 20162:tid 20403] [client 34.95.224.210:42826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxct6-O_Kk7aqBvaiF8IgAAAf0"]
[Thu Sep 17 15:33:43.831762 2026] [core:error] [pid 18946:tid 19148] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:43.831787 2026] [core:error] [pid 18946:tid 19148] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:43.878123 2026] [security2:error] [pid 18946:tid 19099] [client 40.81.232.68:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxctzqiPMah0Tz_U1OX8wAAASE"], referer: binance.com
[Thu Sep 17 15:33:44.024771 2026] [security2:error] [pid 20162:tid 20396] [client 34.95.224.210:42842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcuK-O_Kk7aqBvaiF8JgAAAfY"]
[Thu Sep 17 15:33:44.053382 2026] [security2:error] [pid 18946:tid 19154] [client 34.166.157.71:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxcuDqiPMah0Tz_U1OX9QAAAVg"]
[Thu Sep 17 15:33:44.114029 2026] [security2:error] [pid 18946:tid 19188] [client 103.61.184.148:51335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcuDqiPMah0Tz_U1OX9gAAAXo"]
[Thu Sep 17 15:33:44.114569 2026] [security2:error] [pid 18946:tid 19188] [client 103.61.184.148:51335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcuDqiPMah0Tz_U1OX9gAAAXo"]
[Thu Sep 17 15:33:44.512957 2026] [security2:error] [pid 18946:tid 19183] [client 34.95.224.210:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxcuDqiPMah0Tz_U1OX_gAAAXU"]
[Thu Sep 17 15:33:44.599994 2026] [security2:error] [pid 18946:tid 19167] [client 34.166.234.125:41602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "aqxcuDqiPMah0Tz_U1OYEQAAAWU"]
[Thu Sep 17 15:33:44.737524 2026] [security2:error] [pid 18946:tid 19125] [client 34.166.157.71:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxcuDqiPMah0Tz_U1OYFgAAATs"]
[Thu Sep 17 15:33:44.818910 2026] [security2:error] [pid 18946:tid 19090] [client 114.198.138.124:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcuDqiPMah0Tz_U1OYIgAAARg"]
[Thu Sep 17 15:33:44.819067 2026] [security2:error] [pid 18946:tid 19090] [client 114.198.138.124:55310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcuDqiPMah0Tz_U1OYIgAAARg"]
[Thu Sep 17 15:33:44.896975 2026] [core:error] [pid 20162:tid 20323] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:44.896999 2026] [core:error] [pid 20162:tid 20323] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:44.936224 2026] [security2:error] [pid 18946:tid 19190] [client 74.7.228.11:54960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.espiral-com-mx.xavierlopezmiranda.com"] [uri "/index.php"] [unique_id "aqxctzqiPMah0Tz_U1OX7wABfFA"]
[Thu Sep 17 15:33:45.005902 2026] [security2:error] [pid 18946:tid 19134] [client 34.95.224.210:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.224.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oem.izd.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxcuTqiPMah0Tz_U1OYKAAAAUQ"]
[Thu Sep 17 15:33:45.055823 2026] [security2:error] [pid 20162:tid 20371] [client 54.168.30.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcuK-O_Kk7aqBvaiF8MQAAAd0"]
[Thu Sep 17 15:33:45.417187 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.157.71:43974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxcuTqiPMah0Tz_U1OYNgAAAUI"]
[Thu Sep 17 15:33:45.603086 2026] [core:error] [pid 18946:tid 19166] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:45.603105 2026] [core:error] [pid 18946:tid 19166] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:45.716186 2026] [security2:error] [pid 18946:tid 19153] [client 35.76.107.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcuTqiPMah0Tz_U1OYQgAAAVc"]
[Thu Sep 17 15:33:46.104416 2026] [security2:error] [pid 20162:tid 20314] [client 34.166.157.71:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.157.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.aau.oxd.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxcuq-O_Kk7aqBvaiF8NQAAAaQ"]
[Thu Sep 17 15:33:46.353999 2026] [core:error] [pid 18946:tid 19077] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:46.354020 2026] [core:error] [pid 18946:tid 19077] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:46.521602 2026] [security2:error] [pid 20162:tid 20407] [client 177.44.133.72:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcuq-O_Kk7aqBvaiF8OgAAAgE"]
[Thu Sep 17 15:33:46.521784 2026] [security2:error] [pid 20162:tid 20407] [client 177.44.133.72:59570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcuq-O_Kk7aqBvaiF8OgAAAgE"]
[Thu Sep 17 15:33:47.106598 2026] [core:error] [pid 20162:tid 20420] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:47.106621 2026] [core:error] [pid 20162:tid 20420] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:47.913170 2026] [core:error] [pid 20162:tid 20333] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:47.913185 2026] [core:error] [pid 20162:tid 20333] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:48.296502 2026] [core:error] [pid 18946:tid 18951] [remote 103.117.213.214:42769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Sep 17 15:33:48.296517 2026] [core:error] [pid 18946:tid 18951] [remote 103.117.213.214:42769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Sep 17 15:33:48.645110 2026] [core:error] [pid 20162:tid 20368] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:48.645130 2026] [core:error] [pid 20162:tid 20368] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:49.223058 2026] [security2:error] [pid 18946:tid 19087] [client 177.20.183.174:31747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcvTqiPMah0Tz_U1OYlwABFUM"]
[Thu Sep 17 15:33:49.380786 2026] [core:error] [pid 20162:tid 20406] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:49.380806 2026] [core:error] [pid 20162:tid 20406] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:49.588496 2026] [core:error] [pid 20162:tid 20172] [remote 178.171.103.71:53163] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:49.588519 2026] [core:error] [pid 20162:tid 20172] [remote 178.171.103.71:53163] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:49.654904 2026] [security2:error] [pid 18946:tid 19167] [client 40.81.232.68:56954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxcvTqiPMah0Tz_U1OYoQAAAWU"], referer: binance.com
[Thu Sep 17 15:33:49.730226 2026] [security2:error] [pid 20162:tid 20401] [client 136.158.61.34:61034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcva-O_Kk7aqBvaiF8UgAAAfs"]
[Thu Sep 17 15:33:49.730410 2026] [security2:error] [pid 20162:tid 20401] [client 136.158.61.34:61034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcva-O_Kk7aqBvaiF8UgAAAfs"]
[Thu Sep 17 15:33:50.115346 2026] [core:error] [pid 20162:tid 20307] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:50.115368 2026] [core:error] [pid 20162:tid 20307] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:50.575430 2026] [core:error] [pid 20162:tid 20352] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:50.575455 2026] [core:error] [pid 20162:tid 20352] [client 34.166.157.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:50.893495 2026] [core:error] [pid 20162:tid 20308] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:50.893513 2026] [core:error] [pid 20162:tid 20308] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:51.038528 2026] [security2:error] [pid 18946:tid 19185] [client 18.181.46.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcvjqiPMah0Tz_U1OYxgAAAXc"]
[Thu Sep 17 15:33:51.192864 2026] [security2:error] [pid 18946:tid 19137] [client 103.121.176.59:55268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcvzqiPMah0Tz_U1OYygABRzU"]
[Thu Sep 17 15:33:51.359735 2026] [security2:error] [pid 18946:tid 19109] [client 79.116.89.151:49182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcvzqiPMah0Tz_U1OY1AAAASs"]
[Thu Sep 17 15:33:51.359892 2026] [security2:error] [pid 18946:tid 19109] [client 79.116.89.151:49182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcvzqiPMah0Tz_U1OY1AAAASs"]
[Thu Sep 17 15:33:51.653316 2026] [core:error] [pid 20162:tid 20321] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:51.653337 2026] [core:error] [pid 20162:tid 20321] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:51.875796 2026] [security2:error] [pid 18946:tid 19188] [client 143.105.152.240:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcvzqiPMah0Tz_U1OY3AAAAXo"]
[Thu Sep 17 15:33:51.879674 2026] [security2:error] [pid 18946:tid 19188] [client 143.105.152.240:65149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcvzqiPMah0Tz_U1OY3AAAAXo"]
[Thu Sep 17 15:33:52.827315 2026] [core:error] [pid 18946:tid 19184] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:52.827338 2026] [core:error] [pid 18946:tid 19184] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:53.575863 2026] [security2:error] [pid 18946:tid 19146] [client 34.166.234.125:41698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "aqxcwTqiPMah0Tz_U1OY9QAAAVA"]
[Thu Sep 17 15:33:53.814141 2026] [security2:error] [pid 18946:tid 19129] [client 34.166.234.125:41698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "aqxcwTqiPMah0Tz_U1OY-QAAAT8"]
[Thu Sep 17 15:33:53.978702 2026] [security2:error] [pid 20162:tid 20302] [client 192.178.15.132:58609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "southislandpie.ca"] [uri "/index.php"] [unique_id "aqxcwa-O_Kk7aqBvaiF8bgAAAZg"]
[Thu Sep 17 15:33:54.189042 2026] [core:error] [pid 20162:tid 20339] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:54.189061 2026] [core:error] [pid 20162:tid 20339] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:54.408276 2026] [security2:error] [pid 20162:tid 20330] [client 43.157.149.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.tab-funkenwerk.org"] [uri "/index.php"] [unique_id "aqxcwq-O_Kk7aqBvaiF8cAAAAbQ"]
[Thu Sep 17 15:33:55.006575 2026] [core:error] [pid 18946:tid 19126] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:55.006595 2026] [core:error] [pid 18946:tid 19126] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:55.013632 2026] [security2:error] [pid 20162:tid 20407] [client 103.61.184.148:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcwq-O_Kk7aqBvaiF8cgAAAgE"]
[Thu Sep 17 15:33:55.013753 2026] [security2:error] [pid 20162:tid 20407] [client 103.61.184.148:51912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcwq-O_Kk7aqBvaiF8cgAAAgE"]
[Thu Sep 17 15:33:55.606139 2026] [security2:error] [pid 20162:tid 20351] [client 114.198.138.124:55981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcw6-O_Kk7aqBvaiF8dwAAAck"]
[Thu Sep 17 15:33:55.606237 2026] [security2:error] [pid 20162:tid 20351] [client 114.198.138.124:55981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxcw6-O_Kk7aqBvaiF8dwAAAck"]
[Thu Sep 17 15:33:55.918053 2026] [security2:error] [pid 18946:tid 19112] [client 192.178.6.3:52594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxcwzqiPMah0Tz_U1OZLAAAAS4"]
[Thu Sep 17 15:33:55.975844 2026] [core:error] [pid 20162:tid 20333] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:55.975864 2026] [core:error] [pid 20162:tid 20333] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:57.355856 2026] [core:error] [pid 20162:tid 20369] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:57.355875 2026] [core:error] [pid 20162:tid 20369] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:57.365423 2026] [security2:error] [pid 18946:tid 19140] [client 177.44.133.72:60219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcxTqiPMah0Tz_U1OZSwAAAUo"]
[Thu Sep 17 15:33:57.365554 2026] [security2:error] [pid 18946:tid 19140] [client 177.44.133.72:60219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxcxTqiPMah0Tz_U1OZSwAAAUo"]
[Thu Sep 17 15:33:57.871708 2026] [security2:error] [pid 18946:tid 19089] [client 216.73.217.94:31610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newdaychurchbrandon.org"] [uri "/index.php"] [unique_id "aqxcxTqiPMah0Tz_U1OZWgABF1E"]
[Thu Sep 17 15:33:58.095079 2026] [core:error] [pid 20162:tid 20410] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:58.095104 2026] [core:error] [pid 20162:tid 20410] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:33:58.499491 2026] [security2:error] [pid 18946:tid 19116] [client 216.73.217.94:31610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "newdaychurchbrandon.org"] [uri "/index.php"] [unique_id "aqxcxTqiPMah0Tz_U1OZXgABMig"], referer: https://newdaychurchbrandon.org/sitemap.xml
[Thu Sep 17 15:33:58.793227 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.234.125:43278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "aqxcxjqiPMah0Tz_U1OZcgAAAU0"]
[Thu Sep 17 15:33:59.026856 2026] [security2:error] [pid 18946:tid 19112] [client 34.166.234.125:43278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "aqxcxzqiPMah0Tz_U1OZegAAAS4"]
[Thu Sep 17 15:33:59.260742 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.234.125:43278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "aqxcxzqiPMah0Tz_U1OZfgAAAYk"]
[Thu Sep 17 15:33:59.494163 2026] [security2:error] [pid 18946:tid 19182] [client 34.166.234.125:43278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "aqxcxzqiPMah0Tz_U1OZggAAAXQ"]
[Thu Sep 17 15:33:59.726557 2026] [security2:error] [pid 18946:tid 19134] [client 34.166.234.125:43278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/site/.env"] [unique_id "aqxcxzqiPMah0Tz_U1OZhgAAAUQ"]
[Thu Sep 17 15:33:59.985368 2026] [security2:error] [pid 18946:tid 19128] [client 34.166.234.125:43278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "aqxcxzqiPMah0Tz_U1OZiQAAAT4"]
[Thu Sep 17 15:34:00.274685 2026] [core:error] [pid 20162:tid 20336] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:00.274710 2026] [core:error] [pid 20162:tid 20336] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:00.636187 2026] [security2:error] [pid 18946:tid 19175] [client 40.81.232.68:57596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxcyDqiPMah0Tz_U1OZnAAAAW0"], referer: binance.com
[Thu Sep 17 15:34:00.965269 2026] [security2:error] [pid 18946:tid 19124] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "aqxcyDqiPMah0Tz_U1OZqgAAATo"]
[Thu Sep 17 15:34:01.190721 2026] [security2:error] [pid 18946:tid 19183] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "aqxcyTqiPMah0Tz_U1OZsAAAAXU"]
[Thu Sep 17 15:34:01.419301 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "aqxcyTqiPMah0Tz_U1OZtgAAAU0"]
[Thu Sep 17 15:34:01.624619 2026] [security2:error] [pid 20162:tid 20303] [client 114.119.136.66:40429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stephaniearnold.net"] [uri "/speaker"] [unique_id "aqxcya-O_Kk7aqBvaiF8qAAAAZk"], referer: http://stephaniearnold.net/speaker
[Thu Sep 17 15:34:01.645840 2026] [security2:error] [pid 18946:tid 19096] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "aqxcyTqiPMah0Tz_U1OZuAAAAR4"]
[Thu Sep 17 15:34:01.872049 2026] [security2:error] [pid 18946:tid 19201] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/core/.env"] [unique_id "aqxcyTqiPMah0Tz_U1OZvQAAAYc"]
[Thu Sep 17 15:34:01.910742 2026] [security2:error] [pid 20162:tid 20419] [client 79.116.89.151:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcya-O_Kk7aqBvaiF8qQAAAg0"]
[Thu Sep 17 15:34:01.910856 2026] [security2:error] [pid 20162:tid 20419] [client 79.116.89.151:49793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxcya-O_Kk7aqBvaiF8qQAAAg0"]
[Thu Sep 17 15:34:02.099780 2026] [security2:error] [pid 18946:tid 19189] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/core/app/.env"] [unique_id "aqxcyjqiPMah0Tz_U1OZwAAAAXs"]
[Thu Sep 17 15:34:02.330178 2026] [security2:error] [pid 18946:tid 19147] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "aqxcyjqiPMah0Tz_U1OZxgAAAVE"]
[Thu Sep 17 15:34:02.428578 2026] [security2:error] [pid 20162:tid 20375] [client 143.105.152.240:40444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcyq-O_Kk7aqBvaiF8rAAAAeE"]
[Thu Sep 17 15:34:02.435444 2026] [security2:error] [pid 20162:tid 20375] [client 143.105.152.240:40444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxcyq-O_Kk7aqBvaiF8rAAAAeE"]
[Thu Sep 17 15:34:02.559871 2026] [security2:error] [pid 18946:tid 19082] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/private/.env"] [unique_id "aqxcyjqiPMah0Tz_U1OZzQAAARA"]
[Thu Sep 17 15:34:02.787193 2026] [security2:error] [pid 18946:tid 19076] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "aqxcyjqiPMah0Tz_U1OZ1AAAAQo"]
[Thu Sep 17 15:34:03.014383 2026] [security2:error] [pid 18946:tid 19100] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/bootstrap/.env"] [unique_id "aqxcyzqiPMah0Tz_U1OZ1wAAASI"]
[Thu Sep 17 15:34:03.113375 2026] [security2:error] [pid 18946:tid 19194] [client 136.158.61.34:62187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcyzqiPMah0Tz_U1OZ2AAAAYA"]
[Thu Sep 17 15:34:03.113475 2026] [security2:error] [pid 18946:tid 19194] [client 136.158.61.34:62187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxcyzqiPMah0Tz_U1OZ2AAAAYA"]
[Thu Sep 17 15:34:03.240697 2026] [security2:error] [pid 18946:tid 19127] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/database/.env"] [unique_id "aqxcyzqiPMah0Tz_U1OZ4AAAAT0"]
[Thu Sep 17 15:34:03.365507 2026] [security2:error] [pid 18946:tid 19081] [client 164.163.69.103:33985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxcyzqiPMah0Tz_U1OZ4QABDw0"]
[Thu Sep 17 15:34:03.467722 2026] [security2:error] [pid 18946:tid 19166] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/storage/.env"] [unique_id "aqxcyzqiPMah0Tz_U1OZ5AAAAWQ"]
[Thu Sep 17 15:34:03.693326 2026] [security2:error] [pid 18946:tid 19198] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "aqxcyzqiPMah0Tz_U1OZ5wAAAYQ"]
[Thu Sep 17 15:34:03.919462 2026] [security2:error] [pid 18946:tid 19193] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "aqxcyzqiPMah0Tz_U1OZ7AAAAX8"]
[Thu Sep 17 15:34:04.147887 2026] [security2:error] [pid 18946:tid 19111] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "aqxczDqiPMah0Tz_U1OZ8AAAAS0"]
[Thu Sep 17 15:34:04.378198 2026] [security2:error] [pid 18946:tid 19196] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/release/.env"] [unique_id "aqxczDqiPMah0Tz_U1OZ9gAAAYI"]
[Thu Sep 17 15:34:04.610956 2026] [security2:error] [pid 18946:tid 19146] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/releases/.env"] [unique_id "aqxczDqiPMah0Tz_U1OZ-AAAAVA"]
[Thu Sep 17 15:34:04.633193 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.45.51:53284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.rafaelceara.com"] [uri "/"] [unique_id "aqxczK-O_Kk7aqBvaiF8tQAAAgg"]
[Thu Sep 17 15:34:04.837156 2026] [security2:error] [pid 18946:tid 19115] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "aqxczDqiPMah0Tz_U1OZ_gAAATE"]
[Thu Sep 17 15:34:05.064548 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/deploy/.env"] [unique_id "aqxczTqiPMah0Tz_U1OaAAAAAWI"]
[Thu Sep 17 15:34:05.066229 2026] [security2:error] [pid 18946:tid 19188] [client 40.81.232.68:58288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxczTqiPMah0Tz_U1OaAQAAAXo"], referer: binance.com
[Thu Sep 17 15:34:05.165374 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.45.51:53300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.rafaelceara.com"] [uri "/"] [unique_id "aqxcza-O_Kk7aqBvaiF8tgAAAZE"]
[Thu Sep 17 15:34:05.290165 2026] [security2:error] [pid 18946:tid 19174] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/build/.env"] [unique_id "aqxczTqiPMah0Tz_U1OaCgAAAWw"]
[Thu Sep 17 15:34:05.516199 2026] [security2:error] [pid 18946:tid 19189] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/dist/.env"] [unique_id "aqxczTqiPMah0Tz_U1OaDgAAAXs"]
[Thu Sep 17 15:34:05.670331 2026] [security2:error] [pid 18946:tid 19091] [client 170.150.253.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxczTqiPMah0Tz_U1OaDQAAARk"], referer: https://hikingforwildness.com/
[Thu Sep 17 15:34:05.742958 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "aqxczTqiPMah0Tz_U1OaEwAAAXw"]
[Thu Sep 17 15:34:05.744941 2026] [security2:error] [pid 20162:tid 20415] [client 103.61.184.148:52481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcza-O_Kk7aqBvaiF8uAAAAgk"]
[Thu Sep 17 15:34:05.745028 2026] [security2:error] [pid 20162:tid 20415] [client 103.61.184.148:52481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxcza-O_Kk7aqBvaiF8uAAAAgk"]
[Thu Sep 17 15:34:05.765816 2026] [security2:error] [pid 20162:tid 20379] [client 34.154.45.51:53306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.rafaelceara.com"] [uri "/"] [unique_id "aqxcza-O_Kk7aqBvaiF8ugAAAeU"]
[Thu Sep 17 15:34:05.970898 2026] [security2:error] [pid 18946:tid 19079] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/htdocs/.env"] [unique_id "aqxczTqiPMah0Tz_U1OaFwAAAQ0"]
[Thu Sep 17 15:34:06.174820 2026] [security2:error] [pid 18946:tid 19160] [client 191.242.51.83:33822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxczjqiPMah0Tz_U1OaGAABXgM"]
[Thu Sep 17 15:34:06.200276 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/www/.env"] [unique_id "aqxczjqiPMah0Tz_U1OaGgAAAUY"]
[Thu Sep 17 15:34:06.300776 2026] [security2:error] [pid 18946:tid 19144] [client 114.198.138.124:56624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxczjqiPMah0Tz_U1OaHgAAAU4"]
[Thu Sep 17 15:34:06.300901 2026] [security2:error] [pid 18946:tid 19144] [client 114.198.138.124:56624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxczjqiPMah0Tz_U1OaHgAAAU4"]
[Thu Sep 17 15:34:06.427683 2026] [security2:error] [pid 18946:tid 19139] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/html/.env"] [unique_id "aqxczjqiPMah0Tz_U1OaIgAAAUk"]
[Thu Sep 17 15:34:06.486520 2026] [security2:error] [pid 18946:tid 19140] [client 162.241.226.11:59170] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxczjqiPMah0Tz_U1OaIwAAAUo"]
[Thu Sep 17 15:34:06.655339 2026] [security2:error] [pid 18946:tid 19159] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/live/.env"] [unique_id "aqxczjqiPMah0Tz_U1OaJQAAAV0"]
[Thu Sep 17 15:34:06.877467 2026] [security2:error] [pid 20162:tid 20356] [client 127.0.0.1:33146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxczq-O_Kk7aqBvaiF8wwAAAc4"]
[Thu Sep 17 15:34:06.877520 2026] [security2:error] [pid 20162:tid 20335] [client 74.7.175.177:49754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ceh.cxi.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxczq-O_Kk7aqBvaiF8wgABuSc"]
[Thu Sep 17 15:34:06.881297 2026] [security2:error] [pid 18946:tid 19185] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "aqxczjqiPMah0Tz_U1OaKgAAAXc"]
[Thu Sep 17 15:34:06.881570 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.45.51:53328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.rafaelceara.com"] [uri "/"] [unique_id "aqxczjqiPMah0Tz_U1OaKwAAATA"]
[Thu Sep 17 15:34:07.107592 2026] [security2:error] [pid 18946:tid 19168] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "aqxczzqiPMah0Tz_U1OaLwAAAWY"]
[Thu Sep 17 15:34:07.333314 2026] [security2:error] [pid 18946:tid 19084] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "aqxczzqiPMah0Tz_U1OaNAAAARI"]
[Thu Sep 17 15:34:07.380115 2026] [security2:error] [pid 18946:tid 19186] [client 74.7.244.15:56340] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "www.auditbyibrahim.gocbeglobal.com"] [uri "/robots.txt"] [unique_id "aqxczzqiPMah0Tz_U1OaNgABeAU"]
[Thu Sep 17 15:34:07.500384 2026] [security2:error] [pid 18946:tid 19193] [client 34.154.45.51:53340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/.env"] [unique_id "aqxczzqiPMah0Tz_U1OaNwAAAX8"]
[Thu Sep 17 15:34:07.522650 2026] [security2:error] [pid 20162:tid 20410] [client 17.166.20.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxcz6-O_Kk7aqBvaiF8xQAAAgQ"]
[Thu Sep 17 15:34:07.560858 2026] [security2:error] [pid 18946:tid 19200] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "aqxczzqiPMah0Tz_U1OaOAAAAYY"]
[Thu Sep 17 15:34:07.789244 2026] [security2:error] [pid 18946:tid 19179] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "aqxczzqiPMah0Tz_U1OaPwAAAXE"]
[Thu Sep 17 15:34:08.016545 2026] [security2:error] [pid 18946:tid 19121] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/symfony/.env"] [unique_id "aqxc0DqiPMah0Tz_U1OaRAAAATc"]
[Thu Sep 17 15:34:08.139491 2026] [security2:error] [pid 20162:tid 20363] [client 177.44.133.72:60856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc0K-O_Kk7aqBvaiF80AAAAdU"]
[Thu Sep 17 15:34:08.139612 2026] [security2:error] [pid 20162:tid 20363] [client 177.44.133.72:60856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc0K-O_Kk7aqBvaiF80AAAAdU"]
[Thu Sep 17 15:34:08.247428 2026] [security2:error] [pid 18946:tid 19122] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/wordpress/.env"] [unique_id "aqxc0DqiPMah0Tz_U1OaSQAAATg"]
[Thu Sep 17 15:34:08.404322 2026] [security2:error] [pid 18946:tid 19083] [client 216.73.216.193:27320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "beiselcoaching.com"] [uri "/index.php"] [unique_id "aqxc0DqiPMah0Tz_U1OaUAABEX8"]
[Thu Sep 17 15:34:08.474211 2026] [security2:error] [pid 18946:tid 19118] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/wp/.env"] [unique_id "aqxc0DqiPMah0Tz_U1OaUQAAATQ"]
[Thu Sep 17 15:34:08.700818 2026] [security2:error] [pid 18946:tid 19180] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "aqxc0DqiPMah0Tz_U1OaVwAAAXI"]
[Thu Sep 17 15:34:08.928425 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/drupal/.env"] [unique_id "aqxc0DqiPMah0Tz_U1OaXAAAAYk"]
[Thu Sep 17 15:34:09.157065 2026] [security2:error] [pid 18946:tid 19163] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/joomla/.env"] [unique_id "aqxc0TqiPMah0Tz_U1OaXwAAAWE"]
[Thu Sep 17 15:34:09.388462 2026] [security2:error] [pid 18946:tid 19101] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/magento/.env"] [unique_id "aqxc0TqiPMah0Tz_U1OaZQAAASM"]
[Thu Sep 17 15:34:09.615581 2026] [security2:error] [pid 18946:tid 19105] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/shopify/.env"] [unique_id "aqxc0TqiPMah0Tz_U1OaawAAASc"]
[Thu Sep 17 15:34:09.842632 2026] [security2:error] [pid 18946:tid 19140] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/prestashop/.env"] [unique_id "aqxc0TqiPMah0Tz_U1OacAAAAUo"]
[Thu Sep 17 15:34:10.069069 2026] [security2:error] [pid 18946:tid 19099] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/codeigniter/.env"] [unique_id "aqxc0jqiPMah0Tz_U1OacgAAASE"]
[Thu Sep 17 15:34:10.291402 2026] [security2:error] [pid 20162:tid 20409] [client 127.0.0.1:33270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxc0q-O_Kk7aqBvaiF85wAAAgM"]
[Thu Sep 17 15:34:10.291414 2026] [security2:error] [pid 20162:tid 20351] [client 127.0.0.1:33254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kidsandlifeot.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxc0q-O_Kk7aqBvaiF85gAAAck"]
[Thu Sep 17 15:34:10.291491 2026] [security2:error] [pid 18946:tid 19178] [client 74.7.175.164:51606] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kidsandlifeot.com"] [uri "/robots.txt"] [unique_id "aqxc0jqiPMah0Tz_U1OaegABcCM"]
[Thu Sep 17 15:34:10.294853 2026] [security2:error] [pid 18946:tid 19185] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cakephp/.env"] [unique_id "aqxc0jqiPMah0Tz_U1OaewAAAXc"]
[Thu Sep 17 15:34:10.332523 2026] [security2:error] [pid 18946:tid 19090] [client 145.239.10.137:58449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fetchandfierce.com"] [uri "/wp-content/themes/pwnd-themes/403.php"] [unique_id "aqxc0jqiPMah0Tz_U1OafgAAARg"], referer: http://fetchandfierce.com/wp-content/themes/pwnd-themes/403.php
[Thu Sep 17 15:34:10.341725 2026] [core:error] [pid 20162:tid 20191] [remote 17.166.153.160:39262] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:10.341739 2026] [core:error] [pid 20162:tid 20191] [remote 17.166.153.160:39262] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:10.355337 2026] [security2:error] [pid 20162:tid 20420] [client 40.81.232.68:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxc0q-O_Kk7aqBvaiF86gAAAg4"], referer: binance.com
[Thu Sep 17 15:34:10.531074 2026] [security2:error] [pid 18946:tid 19113] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/zend/.env"] [unique_id "aqxc0jqiPMah0Tz_U1OagwAAAS8"]
[Thu Sep 17 15:34:10.760791 2026] [security2:error] [pid 18946:tid 19094] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/yii/.env"] [unique_id "aqxc0jqiPMah0Tz_U1OaiAAAARw"]
[Thu Sep 17 15:34:10.994154 2026] [security2:error] [pid 18946:tid 19080] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/laravel5/.env"] [unique_id "aqxc0jqiPMah0Tz_U1OajgAAAQ4"]
[Thu Sep 17 15:34:11.221542 2026] [security2:error] [pid 18946:tid 19115] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "aqxc0zqiPMah0Tz_U1OajwAAATE"]
[Thu Sep 17 15:34:11.339775 2026] [security2:error] [pid 18946:tid 19106] [client 34.154.45.51:53368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/.env.bak"] [unique_id "aqxc0zqiPMah0Tz_U1OakwAAASg"]
[Thu Sep 17 15:34:11.456477 2026] [security2:error] [pid 18946:tid 19121] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "aqxc0zqiPMah0Tz_U1OalwAAATc"]
[Thu Sep 17 15:34:11.545777 2026] [security2:error] [pid 18946:tid 19174] [client 34.154.45.51:53368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/.env.backup"] [unique_id "aqxc0zqiPMah0Tz_U1OamgAAAWw"]
[Thu Sep 17 15:34:11.683858 2026] [security2:error] [pid 18946:tid 19122] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "aqxc0zqiPMah0Tz_U1OanAAAATg"]
[Thu Sep 17 15:34:11.911835 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/v1/.env"] [unique_id "aqxc0zqiPMah0Tz_U1OapQAAAU0"]
[Thu Sep 17 15:34:12.139194 2026] [security2:error] [pid 18946:tid 19171] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/v2/.env"] [unique_id "aqxc1DqiPMah0Tz_U1OaqAAAAWk"]
[Thu Sep 17 15:34:12.363689 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.45.51:53378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/.env.old"] [unique_id "aqxc1DqiPMah0Tz_U1OasAAAATY"]
[Thu Sep 17 15:34:12.365799 2026] [security2:error] [pid 18946:tid 19202] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/rest/.env"] [unique_id "aqxc1DqiPMah0Tz_U1OasQAAAYg"]
[Thu Sep 17 15:34:12.538602 2026] [security2:error] [pid 18946:tid 19089] [client 79.116.89.151:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc1DqiPMah0Tz_U1OatgAAARc"]
[Thu Sep 17 15:34:12.538709 2026] [security2:error] [pid 18946:tid 19089] [client 79.116.89.151:50400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc1DqiPMah0Tz_U1OatgAAARc"]
[Thu Sep 17 15:34:12.592408 2026] [security2:error] [pid 18946:tid 19191] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/graphql/.env"] [unique_id "aqxc1DqiPMah0Tz_U1OatwAAAX0"]
[Thu Sep 17 15:34:12.818889 2026] [security2:error] [pid 18946:tid 19079] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/gateway/.env"] [unique_id "aqxc1DqiPMah0Tz_U1OavAAAAQ0"]
[Thu Sep 17 15:34:13.055088 2026] [security2:error] [pid 18946:tid 19085] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/microservice/.env"] [unique_id "aqxc1TqiPMah0Tz_U1OaxQAAARM"]
[Thu Sep 17 15:34:13.121459 2026] [security2:error] [pid 18946:tid 19144] [client 143.105.152.240:43947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc1TqiPMah0Tz_U1OaxwAAAU4"]
[Thu Sep 17 15:34:13.130811 2026] [security2:error] [pid 18946:tid 19144] [client 143.105.152.240:43947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc1TqiPMah0Tz_U1OaxwAAAU4"]
[Thu Sep 17 15:34:13.203348 2026] [security2:error] [pid 18946:tid 19119] [client 104.182.190.110:54853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc1TqiPMah0Tz_U1OaxgABNSk"]
[Thu Sep 17 15:34:13.282732 2026] [security2:error] [pid 18946:tid 19084] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "aqxc1TqiPMah0Tz_U1OazgAAARI"]
[Thu Sep 17 15:34:13.513166 2026] [security2:error] [pid 18946:tid 19192] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/v3/.env"] [unique_id "aqxc1TqiPMah0Tz_U1Oa1gAAAX4"]
[Thu Sep 17 15:34:13.714539 2026] [security2:error] [pid 20162:tid 20332] [client 35.77.26.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxc1a-O_Kk7aqBvaiF9AgAAAbY"]
[Thu Sep 17 15:34:13.740394 2026] [security2:error] [pid 18946:tid 19146] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/dev/.env"] [unique_id "aqxc1TqiPMah0Tz_U1Oa3AAAAVA"]
[Thu Sep 17 15:34:13.975079 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/api/staging/.env"] [unique_id "aqxc1TqiPMah0Tz_U1Oa5gAAAWI"]
[Thu Sep 17 15:34:14.204587 2026] [security2:error] [pid 18946:tid 19201] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/vendor/.env"] [unique_id "aqxc1jqiPMah0Tz_U1Oa7gAAAYc"]
[Thu Sep 17 15:34:14.431749 2026] [security2:error] [pid 18946:tid 19112] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/lib/.env"] [unique_id "aqxc1jqiPMah0Tz_U1Oa8wAAAS4"]
[Thu Sep 17 15:34:14.495761 2026] [security2:error] [pid 20162:tid 20352] [client 104.182.190.110:36015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc1q-O_Kk7aqBvaiF9CAAByiE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&hideanons=1&limit=250&target=VOC_Company&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:34:14.527609 2026] [security2:error] [pid 18946:tid 19147] [client 74.7.175.151:46702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.prz.wvs.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxc1jqiPMah0Tz_U1Oa9wAAAVE"]
[Thu Sep 17 15:34:14.572116 2026] [security2:error] [pid 18946:tid 19130] [client 127.0.0.1:26048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxc1jqiPMah0Tz_U1Oa-QAAAUA"]
[Thu Sep 17 15:34:14.572158 2026] [security2:error] [pid 18946:tid 19107] [client 74.7.175.151:52114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.rcpphotorestoration.com"] [uri "/robots.txt"] [unique_id "aqxc1jqiPMah0Tz_U1Oa-AABKQY"]
[Thu Sep 17 15:34:14.659530 2026] [security2:error] [pid 18946:tid 19120] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/resources/.env"] [unique_id "aqxc1jqiPMah0Tz_U1Oa-wAAATY"]
[Thu Sep 17 15:34:14.886298 2026] [security2:error] [pid 18946:tid 19110] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/assets/.env"] [unique_id "aqxc1jqiPMah0Tz_U1ObAAAAASw"]
[Thu Sep 17 15:34:15.112991 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/uploads/.env"] [unique_id "aqxc1zqiPMah0Tz_U1ObBAAAAUY"]
[Thu Sep 17 15:34:15.339770 2026] [security2:error] [pid 18946:tid 19157] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/internal/.env"] [unique_id "aqxc1zqiPMah0Tz_U1ObCAAAAVs"]
[Thu Sep 17 15:34:15.566414 2026] [security2:error] [pid 18946:tid 19151] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/tools/.env"] [unique_id "aqxc1zqiPMah0Tz_U1ObCwAAAVU"]
[Thu Sep 17 15:34:15.719016 2026] [security2:error] [pid 18946:tid 19127] [client 136.158.61.34:63498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc1zqiPMah0Tz_U1ObEAAAAT0"]
[Thu Sep 17 15:34:15.719144 2026] [security2:error] [pid 18946:tid 19127] [client 136.158.61.34:63498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc1zqiPMah0Tz_U1ObEAAAAT0"]
[Thu Sep 17 15:34:15.798104 2026] [security2:error] [pid 18946:tid 19099] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/scripts/.env"] [unique_id "aqxc1zqiPMah0Tz_U1ObFQAAASE"]
[Thu Sep 17 15:34:15.889174 2026] [security2:error] [pid 18946:tid 19148] [client 74.7.228.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bte.taq.mybluehost.me"] [uri "/index.php"] [unique_id "aqxc1jqiPMah0Tz_U1Oa7AAAAVI"]
[Thu Sep 17 15:34:15.915940 2026] [security2:error] [pid 20162:tid 20326] [client 43.173.175.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxc16-O_Kk7aqBvaiF9EQAAAbA"]
[Thu Sep 17 15:34:15.937929 2026] [security2:error] [pid 18946:tid 19077] [client 74.7.228.28:44052] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bte.taq.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxc1jqiPMah0Tz_U1Oa6AABCww"]
[Thu Sep 17 15:34:16.030455 2026] [security2:error] [pid 18946:tid 19088] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/bin/.env"] [unique_id "aqxc2DqiPMah0Tz_U1ObHQAAARY"]
[Thu Sep 17 15:34:16.118762 2026] [security2:error] [pid 18946:tid 19123] [client 43.173.173.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxc1zqiPMah0Tz_U1ObGwAAATk"]
[Thu Sep 17 15:34:16.265678 2026] [security2:error] [pid 18946:tid 19098] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sbin/.env"] [unique_id "aqxc2DqiPMah0Tz_U1ObIwAAASA"]
[Thu Sep 17 15:34:16.495830 2026] [security2:error] [pid 18946:tid 19179] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "aqxc2DqiPMah0Tz_U1ObLQAAAXE"]
[Thu Sep 17 15:34:16.613110 2026] [security2:error] [pid 18946:tid 19103] [client 103.61.184.148:53055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc2DqiPMah0Tz_U1ObLwAAASU"]
[Thu Sep 17 15:34:16.613214 2026] [security2:error] [pid 18946:tid 19103] [client 103.61.184.148:53055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc2DqiPMah0Tz_U1ObLwAAASU"]
[Thu Sep 17 15:34:16.724972 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "aqxc2DqiPMah0Tz_U1ObMAAAAWI"]
[Thu Sep 17 15:34:16.858991 2026] [security2:error] [pid 18946:tid 19196] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2DqiPMah0Tz_U1ObMwAAAYI"]
[Thu Sep 17 15:34:16.902026 2026] [security2:error] [pid 18946:tid 19121] [client 114.198.138.124:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc2DqiPMah0Tz_U1ObOgAAATc"]
[Thu Sep 17 15:34:16.902133 2026] [security2:error] [pid 18946:tid 19121] [client 114.198.138.124:57258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc2DqiPMah0Tz_U1ObOgAAATc"]
[Thu Sep 17 15:34:16.952156 2026] [security2:error] [pid 18946:tid 19112] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/dashboard/.env"] [unique_id "aqxc2DqiPMah0Tz_U1ObPAAAAS4"]
[Thu Sep 17 15:34:17.178794 2026] [security2:error] [pid 18946:tid 19107] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/panel/.env"] [unique_id "aqxc2TqiPMah0Tz_U1ObRQAAASk"]
[Thu Sep 17 15:34:17.299721 2026] [security2:error] [pid 18946:tid 19145] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/.env"] [unique_id "aqxc2TqiPMah0Tz_U1ObSQAAAU8"]
[Thu Sep 17 15:34:17.407334 2026] [security2:error] [pid 18946:tid 19142] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "aqxc2TqiPMah0Tz_U1ObSwAAAUw"]
[Thu Sep 17 15:34:17.446427 2026] [security2:error] [pid 20162:tid 20339] [client 14.96.156.146:57126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc2a-O_Kk7aqBvaiF9GQAAAb0"]
[Thu Sep 17 15:34:17.446523 2026] [security2:error] [pid 20162:tid 20339] [client 14.96.156.146:57126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc2a-O_Kk7aqBvaiF9GQAAAb0"]
[Thu Sep 17 15:34:17.571968 2026] [security2:error] [pid 18946:tid 19134] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2TqiPMah0Tz_U1ObTgAAAUQ"]
[Thu Sep 17 15:34:17.604822 2026] [core:error] [pid 20162:tid 20393] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:17.604841 2026] [core:error] [pid 20162:tid 20393] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:17.633842 2026] [security2:error] [pid 18946:tid 19157] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "aqxc2TqiPMah0Tz_U1ObVAAAAVs"]
[Thu Sep 17 15:34:17.787308 2026] [core:error] [pid 18946:tid 19139] [client 34.94.67.131:41164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:17.787326 2026] [core:error] [pid 18946:tid 19139] [client 34.94.67.131:41164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:17.850018 2026] [security2:error] [pid 18946:tid 19151] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2TqiPMah0Tz_U1ObVgAAAVU"]
[Thu Sep 17 15:34:17.867364 2026] [security2:error] [pid 18946:tid 19169] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "aqxc2TqiPMah0Tz_U1ObXQAAAWc"]
[Thu Sep 17 15:34:17.963708 2026] [security2:error] [pid 18946:tid 19173] [client 40.81.232.68:57541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxc2TqiPMah0Tz_U1ObZQAAAWs"], referer: binance.com
[Thu Sep 17 15:34:18.005305 2026] [core:error] [pid 18946:tid 19162] [client 34.94.67.131:41166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.005328 2026] [core:error] [pid 18946:tid 19162] [client 34.94.67.131:41166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.094798 2026] [security2:error] [pid 18946:tid 19085] [client 34.166.234.125:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/store/.env"] [unique_id "aqxc2jqiPMah0Tz_U1ObaQAAARM"]
[Thu Sep 17 15:34:18.118085 2026] [security2:error] [pid 18946:tid 19113] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObaAAAAS8"]
[Thu Sep 17 15:34:18.186539 2026] [security2:error] [pid 18946:tid 19178] [client 5.188.86.234:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "networkorbitz.com"] [uri "/blog/wp-login.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObbAAAAXA"]
[Thu Sep 17 15:34:18.188724 2026] [core:error] [pid 18946:tid 19153] [client 34.94.67.131:41168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.188740 2026] [core:error] [pid 18946:tid 19153] [client 34.94.67.131:41168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.391849 2026] [security2:error] [pid 18946:tid 19190] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObdAAAAXw"]
[Thu Sep 17 15:34:18.505056 2026] [core:error] [pid 20162:tid 20312] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.505076 2026] [core:error] [pid 20162:tid 20312] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.643822 2026] [security2:error] [pid 18946:tid 18989] [remote 5.188.86.234:60724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "networkorbitz.com"] [uri "/blog/wp-login.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObgwABGSo"]
[Thu Sep 17 15:34:18.671696 2026] [security2:error] [pid 18946:tid 19122] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObgQAAATg"]
[Thu Sep 17 15:34:18.707796 2026] [security2:error] [pid 18946:tid 19152] [client 177.44.133.72:61506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObhQAAAVY"]
[Thu Sep 17 15:34:18.707889 2026] [security2:error] [pid 18946:tid 19152] [client 177.44.133.72:61506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObhQAAAVY"]
[Thu Sep 17 15:34:18.714187 2026] [core:error] [pid 20162:tid 20359] [client 34.94.67.131:41190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.714202 2026] [core:error] [pid 20162:tid 20359] [client 34.94.67.131:41190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:18.902362 2026] [security2:error] [pid 18946:tid 19165] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/saas/.env"] [unique_id "aqxc2jqiPMah0Tz_U1ObjgAAAWM"]
[Thu Sep 17 15:34:18.956971 2026] [security2:error] [pid 18946:tid 19202] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2jqiPMah0Tz_U1ObjAAAAYg"]
[Thu Sep 17 15:34:18.960111 2026] [security2:error] [pid 20162:tid 20309] [client 34.94.67.131:41196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxc2q-O_Kk7aqBvaiF9LAAAAZ8"]
[Thu Sep 17 15:34:19.116580 2026] [security2:error] [pid 18946:tid 19189] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/.env.bak"] [unique_id "aqxc2zqiPMah0Tz_U1ObmwAAAXs"]
[Thu Sep 17 15:34:19.135881 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "aqxc2zqiPMah0Tz_U1ObnAAAAU0"]
[Thu Sep 17 15:34:19.204608 2026] [core:error] [pid 20162:tid 20415] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:19.204639 2026] [core:error] [pid 20162:tid 20415] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:19.272141 2026] [security2:error] [pid 18946:tid 19135] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/.env.backup"] [unique_id "aqxc2zqiPMah0Tz_U1ObpwAAAUU"]
[Thu Sep 17 15:34:19.274155 2026] [security2:error] [pid 20162:tid 20340] [client 3.82.141.143:57084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cfevlc.com"] [uri "/config.php"] [unique_id "aqxc26-O_Kk7aqBvaiF9OQAAAb4"]
[Thu Sep 17 15:34:19.274528 2026] [security2:error] [pid 20162:tid 20294] [client 3.82.141.143:57296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.cfevlc.com"] [uri "/wp-config.php~"] [unique_id "aqxc26-O_Kk7aqBvaiF9OgAAAZA"]
[Thu Sep 17 15:34:19.276078 2026] [security2:error] [pid 20162:tid 20322] [client 3.82.141.143:57260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cfevlc.com"] [uri "/wp-config.php"] [unique_id "aqxc26-O_Kk7aqBvaiF9PQAAAaw"]
[Thu Sep 17 15:34:19.283310 2026] [security2:error] [pid 18946:tid 19109] [client 3.82.141.143:57294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.cfevlc.com"] [uri "/wp-config.php.save"] [unique_id "aqxc2zqiPMah0Tz_U1ObsAAAASs"]
[Thu Sep 17 15:34:19.286306 2026] [security2:error] [pid 18946:tid 19077] [client 3.82.141.143:57302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.cfevlc.com"] [uri "/wp-config.php.bak"] [unique_id "aqxc2zqiPMah0Tz_U1ObswAAAQs"]
[Thu Sep 17 15:34:19.298843 2026] [security2:error] [pid 20162:tid 20331] [client 3.82.141.143:57248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.cfevlc.com"] [uri "/wp-config.php.old"] [unique_id "aqxc26-O_Kk7aqBvaiF9QwAAAbU"]
[Thu Sep 17 15:34:19.363060 2026] [security2:error] [pid 18946:tid 19175] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "aqxc2zqiPMah0Tz_U1ObugAAAW0"]
[Thu Sep 17 15:34:19.547999 2026] [security2:error] [pid 18946:tid 19198] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2zqiPMah0Tz_U1ObvQAAAYQ"]
[Thu Sep 17 15:34:19.551413 2026] [core:error] [pid 20162:tid 20366] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:19.551430 2026] [core:error] [pid 20162:tid 20366] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:19.589796 2026] [security2:error] [pid 18946:tid 19131] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/admin-panel/.env"] [unique_id "aqxc2zqiPMah0Tz_U1ObwQAAAUE"]
[Thu Sep 17 15:34:19.590675 2026] [security2:error] [pid 18946:tid 19148] [client 43.173.173.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "starrjoyblog.com"] [uri "/index.php"] [unique_id "aqxc2TqiPMah0Tz_U1ObYQAAAVI"]
[Thu Sep 17 15:34:19.704742 2026] [security2:error] [pid 20162:tid 20397] [client 34.154.45.51:54052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/.env.swp"] [unique_id "aqxc26-O_Kk7aqBvaiF9RgAAAfc"]
[Thu Sep 17 15:34:19.706972 2026] [security2:error] [pid 18946:tid 19149] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/.env.old"] [unique_id "aqxc2zqiPMah0Tz_U1ObwwAAAVM"]
[Thu Sep 17 15:34:19.818985 2026] [security2:error] [pid 18946:tid 19092] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/control-panel/.env"] [unique_id "aqxc2zqiPMah0Tz_U1ObyQAAARo"]
[Thu Sep 17 15:34:19.857335 2026] [core:error] [pid 20162:tid 20337] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:19.857354 2026] [core:error] [pid 20162:tid 20337] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:19.878466 2026] [security2:error] [pid 20162:tid 20380] [client 34.154.45.51:54052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/.env~"] [unique_id "aqxc26-O_Kk7aqBvaiF9SAAAAeY"]
[Thu Sep 17 15:34:19.998157 2026] [security2:error] [pid 18946:tid 19091] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc2zqiPMah0Tz_U1ObygAAARk"]
[Thu Sep 17 15:34:20.044932 2026] [security2:error] [pid 18946:tid 19078] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/user-panel/.env"] [unique_id "aqxc3DqiPMah0Tz_U1ObzQAAAQw"]
[Thu Sep 17 15:34:20.210943 2026] [core:error] [pid 18946:tid 19101] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:20.210966 2026] [core:error] [pid 18946:tid 19101] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:20.273104 2026] [security2:error] [pid 18946:tid 19100] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "aqxc3DqiPMah0Tz_U1Ob1gAAASI"]
[Thu Sep 17 15:34:20.284461 2026] [security2:error] [pid 18946:tid 19176] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3DqiPMah0Tz_U1Ob0QAAAW4"]
[Thu Sep 17 15:34:20.500265 2026] [security2:error] [pid 18946:tid 19163] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/express/.env"] [unique_id "aqxc3DqiPMah0Tz_U1Ob4AAAAWE"]
[Thu Sep 17 15:34:20.539224 2026] [core:error] [pid 18946:tid 19125] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:20.539244 2026] [core:error] [pid 18946:tid 19125] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:20.564421 2026] [security2:error] [pid 18946:tid 19080] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3DqiPMah0Tz_U1Ob3QAAAQ4"]
[Thu Sep 17 15:34:20.725336 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/next/.env"] [unique_id "aqxc3DqiPMah0Tz_U1Ob5QAAAYk"]
[Thu Sep 17 15:34:20.840815 2026] [core:error] [pid 18946:tid 19111] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:20.840836 2026] [core:error] [pid 18946:tid 19111] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:20.850687 2026] [security2:error] [pid 18946:tid 19088] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3DqiPMah0Tz_U1Ob5AAAARY"]
[Thu Sep 17 15:34:20.951741 2026] [security2:error] [pid 18946:tid 19153] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/nuxt/.env"] [unique_id "aqxc3DqiPMah0Tz_U1Ob7AAAAVc"]
[Thu Sep 17 15:34:20.993503 2026] [security2:error] [pid 18946:tid 19169] [client 34.94.67.131:35282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxc3DqiPMah0Tz_U1Ob7QAAAWc"]
[Thu Sep 17 15:34:21.032886 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.67.131:35282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxc3TqiPMah0Tz_U1Ob7wAAASQ"]
[Thu Sep 17 15:34:21.139635 2026] [security2:error] [pid 18946:tid 19170] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3TqiPMah0Tz_U1Ob7gAAAWg"]
[Thu Sep 17 15:34:21.168448 2026] [core:error] [pid 18946:tid 19084] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:21.168467 2026] [core:error] [pid 18946:tid 19084] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:21.177230 2026] [security2:error] [pid 18946:tid 19168] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/nest/.env"] [unique_id "aqxc3TqiPMah0Tz_U1Ob9AAAAWY"]
[Thu Sep 17 15:34:21.404804 2026] [security2:error] [pid 18946:tid 19137] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/react/.env"] [unique_id "aqxc3TqiPMah0Tz_U1Ob_gAAAUc"]
[Thu Sep 17 15:34:21.414111 2026] [security2:error] [pid 18946:tid 19201] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3TqiPMah0Tz_U1Ob-AAAAYc"]
[Thu Sep 17 15:34:21.472032 2026] [security2:error] [pid 18946:tid 19191] [client 34.94.67.131:35292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxc3TqiPMah0Tz_U1Ob_wAAAX0"]
[Thu Sep 17 15:34:21.627161 2026] [core:error] [pid 20162:tid 20344] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:21.627179 2026] [core:error] [pid 20162:tid 20344] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:21.630266 2026] [security2:error] [pid 18946:tid 19196] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/vue/.env"] [unique_id "aqxc3TqiPMah0Tz_U1OcBAAAAYI"]
[Thu Sep 17 15:34:21.676413 2026] [security2:error] [pid 18946:tid 19149] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3TqiPMah0Tz_U1OcAgAAAVM"]
[Thu Sep 17 15:34:21.855640 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/angular/.env"] [unique_id "aqxc3TqiPMah0Tz_U1OcDAAAAUI"]
[Thu Sep 17 15:34:21.970535 2026] [security2:error] [pid 18946:tid 19145] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3TqiPMah0Tz_U1OcDQAAAU8"]
[Thu Sep 17 15:34:22.032528 2026] [core:error] [pid 18946:tid 19108] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.032555 2026] [core:error] [pid 18946:tid 19108] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.081882 2026] [security2:error] [pid 18946:tid 19165] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/svelte/.env"] [unique_id "aqxc3jqiPMah0Tz_U1OcEgAAAWM"]
[Thu Sep 17 15:34:22.238210 2026] [security2:error] [pid 18946:tid 19136] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3jqiPMah0Tz_U1OcFQAAAUY"]
[Thu Sep 17 15:34:22.306357 2026] [core:error] [pid 18946:tid 19110] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.306378 2026] [core:error] [pid 18946:tid 19110] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.311501 2026] [security2:error] [pid 18946:tid 19181] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/vite/.env"] [unique_id "aqxc3jqiPMah0Tz_U1OcIAAAAXM"]
[Thu Sep 17 15:34:22.430523 2026] [security2:error] [pid 18946:tid 19194] [client 43.207.121.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxc3jqiPMah0Tz_U1OcHQAAAYA"]
[Thu Sep 17 15:34:22.484395 2026] [core:error] [pid 18946:tid 19155] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.484412 2026] [core:error] [pid 18946:tid 19155] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.506534 2026] [security2:error] [pid 18946:tid 19157] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3jqiPMah0Tz_U1OcJAAAAVs"]
[Thu Sep 17 15:34:22.540898 2026] [security2:error] [pid 18946:tid 19172] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "aqxc3jqiPMah0Tz_U1OcLAAAAWo"]
[Thu Sep 17 15:34:22.787095 2026] [security2:error] [pid 18946:tid 19133] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/backups/.env"] [unique_id "aqxc3jqiPMah0Tz_U1OcLwAAAUM"]
[Thu Sep 17 15:34:22.794338 2026] [security2:error] [pid 18946:tid 19088] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3jqiPMah0Tz_U1OcLgAAARY"]
[Thu Sep 17 15:34:22.889789 2026] [core:error] [pid 18946:tid 19179] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.889805 2026] [core:error] [pid 18946:tid 19179] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:22.960445 2026] [security2:error] [pid 18946:tid 19170] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/.env.swp"] [unique_id "aqxc3jqiPMah0Tz_U1OcOgAAAWg"]
[Thu Sep 17 15:34:23.025145 2026] [security2:error] [pid 18946:tid 19159] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "aqxc3zqiPMah0Tz_U1OcOwAAAV0"]
[Thu Sep 17 15:34:23.099655 2026] [security2:error] [pid 20162:tid 20418] [client 185.104.184.228:50328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.184.104.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control.php"] [unique_id "aqxc36-O_Kk7aqBvaiF9VgAAAgw"]
[Thu Sep 17 15:34:23.099779 2026] [security2:error] [pid 20162:tid 20418] [client 185.104.184.228:50328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control.php"] [unique_id "aqxc36-O_Kk7aqBvaiF9VgAAAgw"]
[Thu Sep 17 15:34:23.119034 2026] [security2:error] [pid 18946:tid 19164] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/.env~"] [unique_id "aqxc3zqiPMah0Tz_U1OcQQAAAWI"]
[Thu Sep 17 15:34:23.149722 2026] [security2:error] [pid 18946:tid 19153] [client 79.116.89.151:51012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcQwAAAVc"]
[Thu Sep 17 15:34:23.149803 2026] [security2:error] [pid 18946:tid 19153] [client 79.116.89.151:51012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcQwAAAVc"]
[Thu Sep 17 15:34:23.252763 2026] [security2:error] [pid 18946:tid 19098] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/tmp/.env"] [unique_id "aqxc3zqiPMah0Tz_U1OcRAAAASA"]
[Thu Sep 17 15:34:23.351561 2026] [core:error] [pid 18946:tid 19086] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:23.351580 2026] [core:error] [pid 18946:tid 19086] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:23.386007 2026] [security2:error] [pid 18946:tid 19079] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcRQAAAQ0"]
[Thu Sep 17 15:34:23.479442 2026] [security2:error] [pid 18946:tid 19096] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/temp/.env"] [unique_id "aqxc3zqiPMah0Tz_U1OcTQAAAR4"]
[Thu Sep 17 15:34:23.596871 2026] [security2:error] [pid 18946:tid 19168] [client 143.105.152.240:14976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcUgAAAWY"]
[Thu Sep 17 15:34:23.601127 2026] [core:error] [pid 18946:tid 19149] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:23.601141 2026] [core:error] [pid 18946:tid 19149] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:23.603866 2026] [security2:error] [pid 18946:tid 19087] [client 40.81.232.68:60319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcVAAAARU"], referer: binance.com
[Thu Sep 17 15:34:23.607823 2026] [security2:error] [pid 18946:tid 19168] [client 143.105.152.240:14976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcUgAAAWY"]
[Thu Sep 17 15:34:23.650742 2026] [security2:error] [pid 18946:tid 19092] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcTwAAARo"]
[Thu Sep 17 15:34:23.705889 2026] [security2:error] [pid 18946:tid 19122] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/lab/.env"] [unique_id "aqxc3zqiPMah0Tz_U1OcWAAAATg"]
[Thu Sep 17 15:34:23.852792 2026] [core:error] [pid 18946:tid 19115] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:23.852810 2026] [core:error] [pid 18946:tid 19115] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:23.931646 2026] [security2:error] [pid 18946:tid 19110] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cronlab/.env"] [unique_id "aqxc3zqiPMah0Tz_U1OcZAAAASw"]
[Thu Sep 17 15:34:23.937527 2026] [security2:error] [pid 18946:tid 19197] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc3zqiPMah0Tz_U1OcYQAAAYM"]
[Thu Sep 17 15:34:24.140680 2026] [security2:error] [pid 18946:tid 19181] [client 188.6.85.90:33766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc4DqiPMah0Tz_U1OcZQABcz4"]
[Thu Sep 17 15:34:24.157484 2026] [security2:error] [pid 18946:tid 19101] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OcaQAAASM"]
[Thu Sep 17 15:34:24.335078 2026] [core:error] [pid 18946:tid 19157] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:24.335097 2026] [core:error] [pid 18946:tid 19157] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:24.360788 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.45.51:58678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/app/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OccAAAAT8"]
[Thu Sep 17 15:34:24.385486 2026] [security2:error] [pid 18946:tid 19171] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/en/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OccQAAAWk"]
[Thu Sep 17 15:34:24.538834 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.45.51:58678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/apps/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OcdgAAAV0"]
[Thu Sep 17 15:34:24.543936 2026] [security2:error] [pid 18946:tid 19179] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc4DqiPMah0Tz_U1OccwAAAXE"]
[Thu Sep 17 15:34:24.590984 2026] [core:error] [pid 18946:tid 19102] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:24.591002 2026] [core:error] [pid 18946:tid 19102] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:24.636909 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OcewAAAWI"]
[Thu Sep 17 15:34:24.740749 2026] [security2:error] [pid 18946:tid 19150] [client 34.154.45.51:58678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/api/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OcfwAAAVQ"]
[Thu Sep 17 15:34:24.789489 2026] [core:error] [pid 18946:tid 19198] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:24.789509 2026] [core:error] [pid 18946:tid 19198] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:24.847435 2026] [security2:error] [pid 18946:tid 19127] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc4DqiPMah0Tz_U1OcfAAAAT0"]
[Thu Sep 17 15:34:24.868594 2026] [security2:error] [pid 18946:tid 19131] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/psnlink/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OchwAAAUE"]
[Thu Sep 17 15:34:24.944417 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.45.51:58678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/web/.env"] [unique_id "aqxc4DqiPMah0Tz_U1OcjAAAAX0"]
[Thu Sep 17 15:34:25.003226 2026] [security2:error] [pid 18946:tid 19178] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/app/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OcjgAAAXA"]
[Thu Sep 17 15:34:25.106404 2026] [security2:error] [pid 18946:tid 19114] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/exapi/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OcjwAAATA"]
[Thu Sep 17 15:34:25.141107 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.45.51:58678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/site/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OckwAAAVM"]
[Thu Sep 17 15:34:25.161596 2026] [security2:error] [pid 18946:tid 19087] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/apps/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OclAAAARU"]
[Thu Sep 17 15:34:25.259723 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.67.131:35384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxc4TqiPMah0Tz_U1OcmgAAATI"]
[Thu Sep 17 15:34:25.321472 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.45.51:58678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/public/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OcoAAAAYY"]
[Thu Sep 17 15:34:25.322406 2026] [security2:error] [pid 18946:tid 19142] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/api/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OcoQAAAUw"]
[Thu Sep 17 15:34:25.331252 2026] [security2:error] [pid 18946:tid 19115] [client 34.166.234.125:34020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sitemaps/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OcogAAATE"]
[Thu Sep 17 15:34:25.344350 2026] [security2:error] [pid 18946:tid 19176] [client 34.94.67.131:35384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxc4TqiPMah0Tz_U1OcpQAAAW4"]
[Thu Sep 17 15:34:25.404581 2026] [core:error] [pid 18946:tid 19110] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:25.404596 2026] [core:error] [pid 18946:tid 19110] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:25.479291 2026] [security2:error] [pid 18946:tid 19103] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/web/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OcrAAAASU"]
[Thu Sep 17 15:34:25.598996 2026] [core:error] [pid 20162:tid 20406] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:25.599013 2026] [core:error] [pid 20162:tid 20406] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:25.639730 2026] [security2:error] [pid 18946:tid 19155] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/site/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OctQAAAVk"]
[Thu Sep 17 15:34:25.797899 2026] [security2:error] [pid 18946:tid 19130] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/public/.env"] [unique_id "aqxc4TqiPMah0Tz_U1OcvAAAAUA"]
[Thu Sep 17 15:34:25.836557 2026] [core:error] [pid 18946:tid 19203] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:25.836571 2026] [core:error] [pid 18946:tid 19203] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:26.075276 2026] [security2:error] [pid 18946:tid 19174] [client 34.32.10.189:60900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc4TqiPMah0Tz_U1OcxwAAAWw"]
[Thu Sep 17 15:34:26.123181 2026] [security2:error] [pid 18946:tid 19088] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/backend/.env"] [unique_id "aqxc4jqiPMah0Tz_U1OcyQAAARY"]
[Thu Sep 17 15:34:26.138126 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/.env"] [unique_id "aqxc4jqiPMah0Tz_U1OcygAAASQ"]
[Thu Sep 17 15:34:26.169652 2026] [security2:error] [pid 18946:tid 19179] [client 103.126.35.168:65314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc4jqiPMah0Tz_U1OcyAABcWY"]
[Thu Sep 17 15:34:26.259506 2026] [security2:error] [pid 18946:tid 19162] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/backend/.env"] [unique_id "aqxc4jqiPMah0Tz_U1OczAAAAWA"]
[Thu Sep 17 15:34:26.282066 2026] [security2:error] [pid 18946:tid 19193] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/server/.env"] [unique_id "aqxc4jqiPMah0Tz_U1OczQAAAX8"]
[Thu Sep 17 15:34:26.334181 2026] [core:error] [pid 20162:tid 20381] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:26.334201 2026] [core:error] [pid 20162:tid 20381] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:26.417915 2026] [security2:error] [pid 18946:tid 19156] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/server/.env"] [unique_id "aqxc4jqiPMah0Tz_U1Oc2AAAAVo"]
[Thu Sep 17 15:34:26.449356 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/frontend/.env"] [unique_id "aqxc4jqiPMah0Tz_U1Oc2gAAAT0"]
[Thu Sep 17 15:34:26.493269 2026] [core:error] [pid 18946:tid 19131] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:26.493290 2026] [core:error] [pid 18946:tid 19131] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:26.577359 2026] [security2:error] [pid 18946:tid 19186] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/frontend/.env"] [unique_id "aqxc4jqiPMah0Tz_U1Oc4AAAAXg"]
[Thu Sep 17 15:34:26.648751 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/src/.env"] [unique_id "aqxc4jqiPMah0Tz_U1Oc4QAAAR4"]
[Thu Sep 17 15:34:26.735986 2026] [security2:error] [pid 18946:tid 19112] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/src/.env"] [unique_id "aqxc4jqiPMah0Tz_U1Oc5gAAAS4"]
[Thu Sep 17 15:34:26.860314 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/core/.env"] [unique_id "aqxc4jqiPMah0Tz_U1Oc7AAAAXc"]
[Thu Sep 17 15:34:26.894988 2026] [security2:error] [pid 18946:tid 19200] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/core/.env"] [unique_id "aqxc4jqiPMah0Tz_U1Oc7QAAAYY"]
[Thu Sep 17 15:34:27.025040 2026] [security2:error] [pid 18946:tid 19087] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/logs/.env"] [unique_id "aqxc4zqiPMah0Tz_U1Oc9QAAARU"]
[Thu Sep 17 15:34:27.033139 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/core/app/.env"] [unique_id "aqxc4zqiPMah0Tz_U1Oc9gAAAYM"]
[Thu Sep 17 15:34:27.040795 2026] [core:error] [pid 18946:tid 19110] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:27.040809 2026] [core:error] [pid 18946:tid 19110] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:27.049967 2026] [security2:error] [pid 18946:tid 19138] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/core/app/.env"] [unique_id "aqxc4zqiPMah0Tz_U1Oc-AAAAUg"]
[Thu Sep 17 15:34:27.205762 2026] [security2:error] [pid 18946:tid 19100] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/config/.env"] [unique_id "aqxc4zqiPMah0Tz_U1Oc_QAAASI"]
[Thu Sep 17 15:34:27.241686 2026] [security2:error] [pid 18946:tid 19194] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/config/.env"] [unique_id "aqxc4zqiPMah0Tz_U1Oc_wAAAYA"]
[Thu Sep 17 15:34:27.254000 2026] [security2:error] [pid 18946:tid 19091] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cache/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdAAAAARk"]
[Thu Sep 17 15:34:27.362707 2026] [core:error] [pid 20162:tid 20383] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:27.362728 2026] [core:error] [pid 20162:tid 20383] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:27.363796 2026] [security2:error] [pid 18946:tid 19135] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/private/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdCAAAAUU"]
[Thu Sep 17 15:34:27.381562 2026] [security2:error] [pid 20162:tid 20390] [client 114.198.138.124:57889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc46-O_Kk7aqBvaiF9awAAAfA"]
[Thu Sep 17 15:34:27.381645 2026] [security2:error] [pid 20162:tid 20390] [client 114.198.138.124:57889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc46-O_Kk7aqBvaiF9awAAAfA"]
[Thu Sep 17 15:34:27.398739 2026] [security2:error] [pid 18946:tid 19140] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/private/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdCgAAAUo"]
[Thu Sep 17 15:34:27.411354 2026] [security2:error] [pid 18946:tid 19095] [client 103.61.184.148:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc4zqiPMah0Tz_U1OdCwAAAR0"]
[Thu Sep 17 15:34:27.411445 2026] [security2:error] [pid 18946:tid 19095] [client 103.61.184.148:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc4zqiPMah0Tz_U1OdCwAAAR0"]
[Thu Sep 17 15:34:27.482769 2026] [security2:error] [pid 18946:tid 19130] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailer/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdDAAAAUA"]
[Thu Sep 17 15:34:27.501709 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/.env.bak"] [unique_id "aqxc4zqiPMah0Tz_U1OdDQAAAWE"]
[Thu Sep 17 15:34:27.519060 2026] [security2:error] [pid 18946:tid 19077] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/application/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdDgAAAQs"]
[Thu Sep 17 15:34:27.542296 2026] [security2:error] [pid 20162:tid 20356] [client 34.94.67.131:35430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxc46-O_Kk7aqBvaiF9bQAAAc4"]
[Thu Sep 17 15:34:27.560827 2026] [security2:error] [pid 20162:tid 20372] [client 14.96.156.146:57860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc46-O_Kk7aqBvaiF9bgAAAd4"]
[Thu Sep 17 15:34:27.560943 2026] [security2:error] [pid 20162:tid 20372] [client 14.96.156.146:57860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc46-O_Kk7aqBvaiF9bgAAAd4"]
[Thu Sep 17 15:34:27.567775 2026] [security2:error] [pid 20162:tid 20300] [client 34.94.67.131:35430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxc46-O_Kk7aqBvaiF9cAAAAZY"]
[Thu Sep 17 15:34:27.594259 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/application/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdDwAAAS0"]
[Thu Sep 17 15:34:27.609767 2026] [security2:error] [pid 20162:tid 20376] [client 34.94.67.131:35430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxc46-O_Kk7aqBvaiF9cQAAAeI"]
[Thu Sep 17 15:34:27.657626 2026] [security2:error] [pid 18946:tid 19171] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/.env.backup"] [unique_id "aqxc4zqiPMah0Tz_U1OdEAAAAWk"]
[Thu Sep 17 15:34:27.680939 2026] [security2:error] [pid 20162:tid 20299] [client 34.94.67.131:35430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxc46-O_Kk7aqBvaiF9cgAAAZU"]
[Thu Sep 17 15:34:27.681556 2026] [security2:error] [pid 18946:tid 19169] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/bootstrap/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdEgAAAWc"]
[Thu Sep 17 15:34:27.701542 2026] [security2:error] [pid 20162:tid 20412] [client 34.94.67.131:35430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxc46-O_Kk7aqBvaiF9cwAAAgY"]
[Thu Sep 17 15:34:27.711091 2026] [security2:error] [pid 18946:tid 19183] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mail/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdEwAAAXU"]
[Thu Sep 17 15:34:27.775089 2026] [security2:error] [pid 20162:tid 20311] [client 34.94.67.131:35430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxc46-O_Kk7aqBvaiF9dAAAAaE"]
[Thu Sep 17 15:34:27.783418 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/bootstrap/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdFAAAAVA"]
[Thu Sep 17 15:34:27.837978 2026] [security2:error] [pid 18946:tid 19159] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/database/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdGAAAAV0"]
[Thu Sep 17 15:34:27.901172 2026] [core:error] [pid 18946:tid 19179] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:27.901191 2026] [core:error] [pid 18946:tid 19179] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:27.944503 2026] [security2:error] [pid 18946:tid 19133] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/email/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdIQAAAUM"]
[Thu Sep 17 15:34:27.979199 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/database/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdIgAAAXI"]
[Thu Sep 17 15:34:27.995713 2026] [security2:error] [pid 18946:tid 19128] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/storage/.env"] [unique_id "aqxc4zqiPMah0Tz_U1OdIwAAAT4"]
[Thu Sep 17 15:34:28.014161 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/.env.old"] [unique_id "aqxc5DqiPMah0Tz_U1OdJQAAASk"]
[Thu Sep 17 15:34:28.147296 2026] [security2:error] [pid 18946:tid 19199] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/storage/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdJwAAAYU"]
[Thu Sep 17 15:34:28.150108 2026] [security2:error] [pid 18946:tid 19156] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/var/www/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdKAAAAVo"]
[Thu Sep 17 15:34:28.175179 2026] [security2:error] [pid 18946:tid 19148] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/smtp/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdLQAAAVI"]
[Thu Sep 17 15:34:28.310479 2026] [security2:error] [pid 18946:tid 19144] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/var/www/html/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdLgAAAU4"]
[Thu Sep 17 15:34:28.320046 2026] [security2:error] [pid 18946:tid 19086] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdMQAAARQ"]
[Thu Sep 17 15:34:28.322833 2026] [security2:error] [pid 18946:tid 19187] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/var/www/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdMgAAAXk"]
[Thu Sep 17 15:34:28.402799 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailing/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdNgAAAXw"]
[Thu Sep 17 15:34:28.418851 2026] [security2:error] [pid 18946:tid 19192] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdOAAAAX4"]
[Thu Sep 17 15:34:28.468959 2026] [security2:error] [pid 18946:tid 19149] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/current/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdOwAAAVM"]
[Thu Sep 17 15:34:28.484757 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/var/www/html/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdPQAAAVw"]
[Thu Sep 17 15:34:28.489478 2026] [security2:error] [pid 18946:tid 19112] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdPgAAAS4"]
[Thu Sep 17 15:34:28.530763 2026] [security2:error] [pid 18946:tid 19137] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdPwAAAUc"]
[Thu Sep 17 15:34:28.625852 2026] [security2:error] [pid 18946:tid 19099] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/release/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdRAAAASE"]
[Thu Sep 17 15:34:28.631076 2026] [security2:error] [pid 18946:tid 19108] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/notifications/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdRQAAASo"]
[Thu Sep 17 15:34:28.648792 2026] [security2:error] [pid 18946:tid 19122] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdRgAAATg"]
[Thu Sep 17 15:34:28.674155 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/current/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdSAAAAVE"]
[Thu Sep 17 15:34:28.781753 2026] [security2:error] [pid 18946:tid 19115] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/releases/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdSgAAATE"]
[Thu Sep 17 15:34:28.797944 2026] [security2:error] [pid 18946:tid 19161] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdTQAAAV8"]
[Thu Sep 17 15:34:28.821856 2026] [security2:error] [pid 18946:tid 19141] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdUAAAAUs"]
[Thu Sep 17 15:34:28.838872 2026] [security2:error] [pid 20162:tid 20341] [client 136.158.61.34:64707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc5K-O_Kk7aqBvaiF9eAAAAb8"]
[Thu Sep 17 15:34:28.838960 2026] [security2:error] [pid 20162:tid 20341] [client 136.158.61.34:64707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc5K-O_Kk7aqBvaiF9eAAAAb8"]
[Thu Sep 17 15:34:28.860104 2026] [security2:error] [pid 18946:tid 19197] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/notify/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdUQAAAYM"]
[Thu Sep 17 15:34:28.887313 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/release/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdUgAAAUQ"]
[Thu Sep 17 15:34:28.903445 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdVAAAATs"]
[Thu Sep 17 15:34:28.938205 2026] [security2:error] [pid 18946:tid 19093] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/shared/.env"] [unique_id "aqxc5DqiPMah0Tz_U1OdVQAAARs"]
[Thu Sep 17 15:34:29.025633 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdWAAAASc"]
[Thu Sep 17 15:34:29.088185 2026] [security2:error] [pid 18946:tid 19120] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sender/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdWgAAATY"]
[Thu Sep 17 15:34:29.092467 2026] [security2:error] [pid 18946:tid 19145] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdWwAAAU8"]
[Thu Sep 17 15:34:29.094535 2026] [security2:error] [pid 18946:tid 19092] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/deploy/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdXAAAARo"]
[Thu Sep 17 15:34:29.143059 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/releases/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdXQAAATI"]
[Thu Sep 17 15:34:29.182951 2026] [security2:error] [pid 18946:tid 19100] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdYQAAASI"]
[Thu Sep 17 15:34:29.252952 2026] [security2:error] [pid 18946:tid 19194] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/build/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdYgAAAYA"]
[Thu Sep 17 15:34:29.318135 2026] [security2:error] [pid 18946:tid 19181] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/campaign/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdZAAAAXM"]
[Thu Sep 17 15:34:29.342538 2026] [security2:error] [pid 18946:tid 19135] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/shared/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdZgAAAUU"]
[Thu Sep 17 15:34:29.370213 2026] [security2:error] [pid 20162:tid 20310] [client 177.44.133.72:62146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc5a-O_Kk7aqBvaiF9ewAAAaA"]
[Thu Sep 17 15:34:29.370339 2026] [security2:error] [pid 20162:tid 20310] [client 177.44.133.72:62146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc5a-O_Kk7aqBvaiF9ewAAAaA"]
[Thu Sep 17 15:34:29.407440 2026] [security2:error] [pid 18946:tid 19140] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/dist/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdawAAAUo"]
[Thu Sep 17 15:34:29.409585 2026] [security2:error] [pid 18946:tid 19095] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdbAAAAR0"]
[Thu Sep 17 15:34:29.516476 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/deploy/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdbwAAARA"]
[Thu Sep 17 15:34:29.547020 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/newsletter/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdcQAAAU0"]
[Thu Sep 17 15:34:29.554077 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdcgAAASY"]
[Thu Sep 17 15:34:29.564278 2026] [security2:error] [pid 18946:tid 19081] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/public_html/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdcwAAAQ8"]
[Thu Sep 17 15:34:29.619792 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OddwAAAV4"]
[Thu Sep 17 15:34:29.683985 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/build/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdeQAAAWc"]
[Thu Sep 17 15:34:29.704768 2026] [security2:error] [pid 18946:tid 19175] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdegAAAW0"]
[Thu Sep 17 15:34:29.720540 2026] [security2:error] [pid 18946:tid 19183] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/htdocs/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdewAAAXU"]
[Thu Sep 17 15:34:29.764845 2026] [security2:error] [pid 18946:tid 19159] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdfAAAAV0"]
[Thu Sep 17 15:34:29.775137 2026] [security2:error] [pid 18946:tid 19179] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/ses/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdgAAAAXE"]
[Thu Sep 17 15:34:29.794334 2026] [security2:error] [pid 18946:tid 19084] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdgQAAARI"]
[Thu Sep 17 15:34:29.849304 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/dist/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdhAAAAUI"]
[Thu Sep 17 15:34:29.875897 2026] [security2:error] [pid 18946:tid 19164] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/www/.env"] [unique_id "aqxc5TqiPMah0Tz_U1OdhQAAAWI"]
[Thu Sep 17 15:34:30.010499 2026] [security2:error] [pid 18946:tid 19126] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sendgrid/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdiwAAATw"]
[Thu Sep 17 15:34:30.026636 2026] [security2:error] [pid 18946:tid 19156] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/html/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdjQAAAVo"]
[Thu Sep 17 15:34:30.034513 2026] [security2:error] [pid 18946:tid 19080] [client 23.251.146.115:1792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxc4zqiPMah0Tz_U1OdAQABDmU"]
[Thu Sep 17 15:34:30.040050 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/public_html/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdjgAAAYc"]
[Thu Sep 17 15:34:30.073715 2026] [security2:error] [pid 18946:tid 19131] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdjwAAAUE"]
[Thu Sep 17 15:34:30.129336 2026] [security2:error] [pid 18946:tid 19123] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdkwAAATk"]
[Thu Sep 17 15:34:30.152715 2026] [security2:error] [pid 20162:tid 20403] [client 40.81.232.68:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxc5q-O_Kk7aqBvaiF9gAAAAf0"], referer: binance.com
[Thu Sep 17 15:34:30.166119 2026] [security2:error] [pid 18946:tid 19154] [client 23.251.146.115:1792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxc5jqiPMah0Tz_U1OdkAABWDM"]
[Thu Sep 17 15:34:30.201097 2026] [security2:error] [pid 18946:tid 19187] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/live/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdlgAAAXk"]
[Thu Sep 17 15:34:30.234215 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/htdocs/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdmAAAARw"]
[Thu Sep 17 15:34:30.239234 2026] [security2:error] [pid 18946:tid 19193] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/sparkpost/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdmQAAAX8"]
[Thu Sep 17 15:34:30.262961 2026] [security2:error] [pid 18946:tid 19190] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdmgAAAXw"]
[Thu Sep 17 15:34:30.348242 2026] [security2:error] [pid 18946:tid 19106] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdnAAAASg"]
[Thu Sep 17 15:34:30.355963 2026] [security2:error] [pid 18946:tid 19192] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/prod/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdnQAAAX4"]
[Thu Sep 17 15:34:30.387035 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/.env.swp"] [unique_id "aqxc5jqiPMah0Tz_U1OdngAAATU"]
[Thu Sep 17 15:34:30.397971 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/www/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdnwAAAXg"]
[Thu Sep 17 15:34:30.407490 2026] [security2:error] [pid 18946:tid 19096] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdoAAAAR4"]
[Thu Sep 17 15:34:30.468416 2026] [security2:error] [pid 18946:tid 19158] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/postmark/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdogAAAVw"]
[Thu Sep 17 15:34:30.503315 2026] [security2:error] [pid 18946:tid 19079] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdowAAAQ0"]
[Thu Sep 17 15:34:30.515227 2026] [security2:error] [pid 18946:tid 19112] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/dev/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdpAAAAS4"]
[Thu Sep 17 15:34:30.548094 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/.env~"] [unique_id "aqxc5jqiPMah0Tz_U1OdpQAAAUc"]
[Thu Sep 17 15:34:30.555530 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/html/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdpgAAAYQ"]
[Thu Sep 17 15:34:30.563022 2026] [security2:error] [pid 18946:tid 19196] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdpwAAAYI"]
[Thu Sep 17 15:34:30.600785 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdqAAAAWQ"]
[Thu Sep 17 15:34:30.677198 2026] [security2:error] [pid 18946:tid 19200] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/staging/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdqQAAAYY"]
[Thu Sep 17 15:34:30.701737 2026] [security2:error] [pid 18946:tid 19195] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailgun/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdqgAAAYE"]
[Thu Sep 17 15:34:30.707467 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdqwAAASE"]
[Thu Sep 17 15:34:30.751344 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/live/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdrQAAATg"]
[Thu Sep 17 15:34:30.760119 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdrgAAAVE"]
[Thu Sep 17 15:34:30.836259 2026] [security2:error] [pid 18946:tid 19161] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/opt/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdsQAAAV8"]
[Thu Sep 17 15:34:30.864785 2026] [security2:error] [pid 18946:tid 19142] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdsgAAAUw"]
[Thu Sep 17 15:34:30.869029 2026] [security2:error] [pid 20162:tid 20362] [client 74.7.241.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agingwellcounseling.com"] [uri "/index.php"] [unique_id "aqxc5a-O_Kk7aqBvaiF9fAAAAdQ"]
[Thu Sep 17 15:34:30.921811 2026] [security2:error] [pid 18946:tid 19152] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxc5jqiPMah0Tz_U1OdsAAAAVY"]
[Thu Sep 17 15:34:30.931881 2026] [security2:error] [pid 18946:tid 19134] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mandrill/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdtgAAAUQ"]
[Thu Sep 17 15:34:30.952391 2026] [security2:error] [pid 18946:tid 19110] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/prod/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OdtwAAASw"]
[Thu Sep 17 15:34:30.962570 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OduAAAATs"]
[Thu Sep 17 15:34:30.996346 2026] [security2:error] [pid 18946:tid 19093] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/laravel/.env"] [unique_id "aqxc5jqiPMah0Tz_U1OduQAAARs"]
[Thu Sep 17 15:34:31.032703 2026] [security2:error] [pid 18946:tid 19157] [client 74.7.241.184:40584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agingwellcounseling.com"] [uri "/robots.txt"] [unique_id "aqxc5TqiPMah0Tz_U1OdbQABW1M"]
[Thu Sep 17 15:34:31.098009 2026] [security2:error] [pid 18946:tid 19087] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdvQAAARU"]
[Thu Sep 17 15:34:31.113841 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/dev/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdvgAAARc"]
[Thu Sep 17 15:34:31.153649 2026] [security2:error] [pid 18946:tid 19165] [client 34.32.10.189:60900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/symfony/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdwgAAAWM"]
[Thu Sep 17 15:34:31.156365 2026] [security2:error] [pid 18946:tid 19182] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdwwAAAXQ"]
[Thu Sep 17 15:34:31.159592 2026] [security2:error] [pid 18946:tid 19194] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mailjet/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdxAAAAYA"]
[Thu Sep 17 15:34:31.171016 2026] [security2:error] [pid 20162:tid 20399] [client 74.125.215.161:58271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.airmacinc.com"] [uri "/index.php"] [unique_id "aqxc5q-O_Kk7aqBvaiF9jAAAAfk"]
[Thu Sep 17 15:34:31.277004 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/staging/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdxQAAAXM"]
[Thu Sep 17 15:34:31.281144 2026] [security2:error] [pid 18946:tid 19135] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdxgAAAUU"]
[Thu Sep 17 15:34:31.308038 2026] [security2:error] [pid 18946:tid 19095] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdxwAAAR0"]
[Thu Sep 17 15:34:31.393426 2026] [security2:error] [pid 18946:tid 19130] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/brevo/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdzAAAAUA"]
[Thu Sep 17 15:34:31.403218 2026] [security2:error] [pid 18946:tid 19121] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdzQAAATc"]
[Thu Sep 17 15:34:31.456557 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/opt/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdzgAAAWE"]
[Thu Sep 17 15:34:31.494817 2026] [security2:error] [pid 18946:tid 19167] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxc5zqiPMah0Tz_U1OdzwAAAWU"]
[Thu Sep 17 15:34:31.544816 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od0gAAASY"]
[Thu Sep 17 15:34:31.606132 2026] [security2:error] [pid 18946:tid 19178] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/wordpress/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od0wAAAXA"]
[Thu Sep 17 15:34:31.609692 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/laravel/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od1AAAAS0"]
[Thu Sep 17 15:34:31.614320 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od1QAAASs"]
[Thu Sep 17 15:34:31.620589 2026] [security2:error] [pid 18946:tid 19077] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/transactional/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od1gAAAQs"]
[Thu Sep 17 15:34:31.654964 2026] [security2:error] [pid 18946:tid 19169] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od2AAAAWc"]
[Thu Sep 17 15:34:31.701143 2026] [security2:error] [pid 18946:tid 19183] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od2QAAAXU"]
[Thu Sep 17 15:34:31.726769 2026] [security2:error] [pid 18946:tid 19084] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od3QAAARI"]
[Thu Sep 17 15:34:31.754738 2026] [security2:error] [pid 18946:tid 19113] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/wp/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od3wAAAS8"]
[Thu Sep 17 15:34:31.773815 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/symfony/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od4AAAAT8"]
[Thu Sep 17 15:34:31.849415 2026] [security2:error] [pid 18946:tid 19114] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/bulk/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od4gAAATA"]
[Thu Sep 17 15:34:31.875090 2026] [security2:error] [pid 18946:tid 19124] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od5QAAATo"]
[Thu Sep 17 15:34:31.907763 2026] [security2:error] [pid 18946:tid 19180] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/cms/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od5gAAAXI"]
[Thu Sep 17 15:34:31.952184 2026] [security2:error] [pid 18946:tid 19107] [client 185.79.138.71:35898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.138.79.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "breathingboxing.org"] [uri "/wp-content/uploads/0xss.php"] [unique_id "aqxc5zqiPMah0Tz_U1Od5wAAASk"]
[Thu Sep 17 15:34:31.978609 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/wordpress/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od6wAAAVI"]
[Thu Sep 17 15:34:31.989159 2026] [security2:error] [pid 18946:tid 19080] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxc5zqiPMah0Tz_U1Od7AAAAQ4"]
[Thu Sep 17 15:34:32.030469 2026] [security2:error] [pid 18946:tid 19154] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od8AAAAVg"]
[Thu Sep 17 15:34:32.062485 2026] [security2:error] [pid 18946:tid 19172] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/drupal/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od8QAAAWo"]
[Thu Sep 17 15:34:32.065959 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od8gAAAXk"]
[Thu Sep 17 15:34:32.077710 2026] [security2:error] [pid 18946:tid 19086] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/aws/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od8wAAARQ"]
[Thu Sep 17 15:34:32.124159 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/app/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od9gAAARw"]
[Thu Sep 17 15:34:32.141705 2026] [security2:error] [pid 18946:tid 19193] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/wp/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od9wAAAX8"]
[Thu Sep 17 15:34:32.160935 2026] [security2:error] [pid 18946:tid 19190] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od-QAAAXw"]
[Thu Sep 17 15:34:32.215343 2026] [security2:error] [pid 18946:tid 19106] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/joomla/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od-wAAASg"]
[Thu Sep 17 15:34:32.274360 2026] [security2:error] [pid 18946:tid 19119] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od_AAAATU"]
[Thu Sep 17 15:34:32.279768 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/apps/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od_QAAAXg"]
[Thu Sep 17 15:34:32.307752 2026] [security2:error] [pid 18946:tid 19096] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/azure/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od_gAAAR4"]
[Thu Sep 17 15:34:32.322446 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/cms/.env"] [unique_id "aqxc6DqiPMah0Tz_U1Od_wAAAVw"]
[Thu Sep 17 15:34:32.364705 2026] [security2:error] [pid 18946:tid 19112] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/magento/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeAAAAAS4"]
[Thu Sep 17 15:34:32.428966 2026] [security2:error] [pid 18946:tid 19196] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeAwAAAYI"]
[Thu Sep 17 15:34:32.435046 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/api/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeBAAAAWQ"]
[Thu Sep 17 15:34:32.457576 2026] [security2:error] [pid 18946:tid 19185] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeBQAAAXc"]
[Thu Sep 17 15:34:32.501858 2026] [security2:error] [pid 18946:tid 19099] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/drupal/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeBgAAASE"]
[Thu Sep 17 15:34:32.511424 2026] [security2:error] [pid 18946:tid 19108] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/shopify/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeCAAAASo"]
[Thu Sep 17 15:34:32.526722 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeCQAAAVE"]
[Thu Sep 17 15:34:32.540637 2026] [security2:error] [pid 18946:tid 19128] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/gcp/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeCgAAAT4"]
[Thu Sep 17 15:34:32.576430 2026] [security2:error] [pid 18946:tid 19168] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeDQAAAWY"]
[Thu Sep 17 15:34:32.592947 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/web/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeDwAAAUQ"]
[Thu Sep 17 15:34:32.659293 2026] [security2:error] [pid 18946:tid 19197] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/prestashop/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeEAAAAYM"]
[Thu Sep 17 15:34:32.660694 2026] [security2:error] [pid 18946:tid 19141] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeEQAAAUs"]
[Thu Sep 17 15:34:32.733078 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeEgAAATs"]
[Thu Sep 17 15:34:32.736451 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/joomla/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeEwAAARs"]
[Thu Sep 17 15:34:32.756685 2026] [security2:error] [pid 18946:tid 19117] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/site/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeFAAAATM"]
[Thu Sep 17 15:34:32.769399 2026] [security2:error] [pid 18946:tid 19127] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cloud/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeFQAAAT0"]
[Thu Sep 17 15:34:32.808738 2026] [security2:error] [pid 18946:tid 19103] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/codeigniter/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeFgAAASU"]
[Thu Sep 17 15:34:32.881981 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeGAAAAUk"]
[Thu Sep 17 15:34:32.910395 2026] [security2:error] [pid 18946:tid 19087] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/public/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeGgAAARU"]
[Thu Sep 17 15:34:32.923435 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/magento/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeGwAAARc"]
[Thu Sep 17 15:34:32.959789 2026] [security2:error] [pid 18946:tid 19165] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/cakephp/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeHAAAAWM"]
[Thu Sep 17 15:34:32.963068 2026] [security2:error] [pid 18946:tid 19182] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxc6DqiPMah0Tz_U1OeHQAAAXQ"]
[Thu Sep 17 15:34:33.003735 2026] [security2:error] [pid 18946:tid 19194] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/infrastructure/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeHgAAAYA"]
[Thu Sep 17 15:34:33.004387 2026] [security2:error] [pid 18946:tid 19189] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeHwAAAXs"]
[Thu Sep 17 15:34:33.047409 2026] [security2:error] [pid 18946:tid 19149] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeIgAAAVM"]
[Thu Sep 17 15:34:33.107795 2026] [security2:error] [pid 18946:tid 19095] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/zend/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeJgAAAR0"]
[Thu Sep 17 15:34:33.134598 2026] [security2:error] [pid 18946:tid 19076] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/shopify/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeJwAAAQo"]
[Thu Sep 17 15:34:33.140156 2026] [security2:error] [pid 18946:tid 19130] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeKAAAAUA"]
[Thu Sep 17 15:34:33.234569 2026] [security2:error] [pid 18946:tid 19163] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/docker/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeKgAAAWE"]
[Thu Sep 17 15:34:33.255057 2026] [security2:error] [pid 18946:tid 19167] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/yii/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeKwAAAWU"]
[Thu Sep 17 15:34:33.266020 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/backend/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeLAAAAYk"]
[Thu Sep 17 15:34:33.292127 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeLQAAASY"]
[Thu Sep 17 15:34:33.302932 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/prestashop/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeLgAAAQ8"]
[Thu Sep 17 15:34:33.403362 2026] [security2:error] [pid 18946:tid 19111] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/laravel5/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeLwAAAS0"]
[Thu Sep 17 15:34:33.429819 2026] [security2:error] [pid 18946:tid 19077] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/server/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeMAAAAQs"]
[Thu Sep 17 15:34:33.455155 2026] [security2:error] [pid 18946:tid 19171] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeMQAAAWk"]
[Thu Sep 17 15:34:33.462646 2026] [security2:error] [pid 18946:tid 19169] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/k8s/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeMgAAAWc"]
[Thu Sep 17 15:34:33.481022 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeMwAAAVA"]
[Thu Sep 17 15:34:33.496020 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/codeigniter/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeNgAAAS8"]
[Thu Sep 17 15:34:33.540990 2026] [security2:error] [pid 18946:tid 19129] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeOwAAAT8"]
[Thu Sep 17 15:34:33.550673 2026] [security2:error] [pid 18946:tid 19116] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/v1/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OePAAAATI"]
[Thu Sep 17 15:34:33.584244 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/frontend/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OePQAAARg"]
[Thu Sep 17 15:34:33.607831 2026] [security2:error] [pid 18946:tid 19138] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OePgAAAUg"]
[Thu Sep 17 15:34:33.664642 2026] [security2:error] [pid 18946:tid 19124] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/cakephp/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeQAAAATo"]
[Thu Sep 17 15:34:33.696532 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/kubernetes/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeQgAAAWI"]
[Thu Sep 17 15:34:33.702351 2026] [security2:error] [pid 18946:tid 19175] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/v2/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeRAAAAW0"]
[Thu Sep 17 15:34:33.737206 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/src/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeRQAAAXI"]
[Thu Sep 17 15:34:33.741144 2026] [security2:error] [pid 18946:tid 19109] [client 79.116.89.151:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc6TqiPMah0Tz_U1OeRgAAASs"]
[Thu Sep 17 15:34:33.741236 2026] [security2:error] [pid 18946:tid 19109] [client 79.116.89.151:51621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc6TqiPMah0Tz_U1OeRgAAASs"]
[Thu Sep 17 15:34:33.746108 2026] [security2:error] [pid 18946:tid 19155] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeRwAAAVk"]
[Thu Sep 17 15:34:33.811203 2026] [security2:error] [pid 18946:tid 19082] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeSQAAARA"]
[Thu Sep 17 15:34:33.847244 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/zend/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeSgAAAXo"]
[Thu Sep 17 15:34:33.851285 2026] [security2:error] [pid 18946:tid 19107] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/v3/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeSwAAASk"]
[Thu Sep 17 15:34:33.866967 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeTAAAASQ"]
[Thu Sep 17 15:34:33.894403 2026] [security2:error] [pid 18946:tid 19174] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/core/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeTQAAAWw"]
[Thu Sep 17 15:34:33.924380 2026] [security2:error] [pid 18946:tid 19080] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/terraform/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeTgAAAQ4"]
[Thu Sep 17 15:34:33.953404 2026] [security2:error] [pid 18946:tid 19098] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxc6TqiPMah0Tz_U1OeTwAAASA"]
[Thu Sep 17 15:34:34.005891 2026] [security2:error] [pid 18946:tid 19187] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/api/v1/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeUAAAAXk"]
[Thu Sep 17 15:34:34.018533 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/yii/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeUQAAARQ"]
[Thu Sep 17 15:34:34.042259 2026] [security2:error] [pid 18946:tid 19162] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeVAAAAWA"]
[Thu Sep 17 15:34:34.048248 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/core/app/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeVQAAAVc"]
[Thu Sep 17 15:34:34.152577 2026] [security2:error] [pid 18946:tid 19106] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/ansible/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeWAAAASg"]
[Thu Sep 17 15:34:34.154496 2026] [security2:error] [pid 18946:tid 19192] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/api/v2/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeWQAAAX4"]
[Thu Sep 17 15:34:34.156609 2026] [security2:error] [pid 18946:tid 19088] [client 180.94.24.250:40486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc6jqiPMah0Tz_U1OeVgABFg0"]
[Thu Sep 17 15:34:34.181938 2026] [security2:error] [pid 18946:tid 19119] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeWgAAATU"]
[Thu Sep 17 15:34:34.202351 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/config/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeWwAAAXg"]
[Thu Sep 17 15:34:34.205575 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/laravel5/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeXAAAAVw"]
[Thu Sep 17 15:34:34.205824 2026] [security2:error] [pid 18946:tid 19160] [client 143.105.152.240:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc6jqiPMah0Tz_U1OeXQAAAV4"]
[Thu Sep 17 15:34:34.216099 2026] [security2:error] [pid 18946:tid 19160] [client 143.105.152.240:4243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc6jqiPMah0Tz_U1OeXQAAAV4"]
[Thu Sep 17 15:34:34.219185 2026] [security2:error] [pid 18946:tid 19144] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeXgAAAU4"]
[Thu Sep 17 15:34:34.257705 2026] [security2:error] [pid 18946:tid 19112] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeXwAAAS4"]
[Thu Sep 17 15:34:34.301220 2026] [security2:error] [pid 18946:tid 19137] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/rest/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeYAAAAUc"]
[Thu Sep 17 15:34:34.311499 2026] [security2:error] [pid 18946:tid 19131] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeYQAAAUE"]
[Thu Sep 17 15:34:34.340567 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeYgAAAWQ"]
[Thu Sep 17 15:34:34.354700 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/private/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeYwAAAXc"]
[Thu Sep 17 15:34:34.380494 2026] [security2:error] [pid 18946:tid 19108] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.git/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeZAAAASo"]
[Thu Sep 17 15:34:34.403675 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeZQAAAVE"]
[Thu Sep 17 15:34:34.419668 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/v1/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeZgAAAT4"]
[Thu Sep 17 15:34:34.450400 2026] [security2:error] [pid 18946:tid 19152] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/graphql/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeaAAAAVY"]
[Thu Sep 17 15:34:34.470886 2026] [security2:error] [pid 18946:tid 19134] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeaQAAAUQ"]
[Thu Sep 17 15:34:34.507554 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/application/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeagAAAUs"]
[Thu Sep 17 15:34:34.603880 2026] [security2:error] [pid 18946:tid 19093] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/gateway/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OebQAAARs"]
[Thu Sep 17 15:34:34.606823 2026] [security2:error] [pid 18946:tid 19173] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OebgAAAWs"]
[Thu Sep 17 15:34:34.609174 2026] [security2:error] [pid 18946:tid 19117] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/ci/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OecAAAATM"]
[Thu Sep 17 15:34:34.616629 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/v2/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OecQAAAT0"]
[Thu Sep 17 15:34:34.663109 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/bootstrap/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OedAAAAU8"]
[Thu Sep 17 15:34:34.663157 2026] [security2:error] [pid 18946:tid 19103] [client 34.94.67.131:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OecwAAASU"]
[Thu Sep 17 15:34:34.758936 2026] [security2:error] [pid 18946:tid 19142] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/microservice/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OedQAAAUw"]
[Thu Sep 17 15:34:34.812944 2026] [security2:error] [pid 18946:tid 19115] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/v3/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OedgAAATE"]
[Thu Sep 17 15:34:34.819805 2026] [security2:error] [pid 18946:tid 19157] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/database/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OedwAAAVs"]
[Thu Sep 17 15:34:34.843833 2026] [security2:error] [pid 18946:tid 19087] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/cd/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeeAAAARU"]
[Thu Sep 17 15:34:34.913820 2026] [security2:error] [pid 18946:tid 19165] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/service/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeeQAAAWM"]
[Thu Sep 17 15:34:34.976312 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/api/v1/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeegAAAXQ"]
[Thu Sep 17 15:34:34.979766 2026] [security2:error] [pid 18946:tid 19194] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/storage/.env"] [unique_id "aqxc6jqiPMah0Tz_U1OeewAAAYA"]
[Thu Sep 17 15:34:35.033856 2026] [security2:error] [pid 18946:tid 19089] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OefAAAARc"]
[Thu Sep 17 15:34:35.073298 2026] [security2:error] [pid 18946:tid 19149] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/api/v3/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OefwAAAVM"]
[Thu Sep 17 15:34:35.083868 2026] [security2:error] [pid 18946:tid 19177] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/jenkins/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OegAAAAW8"]
[Thu Sep 17 15:34:35.112036 2026] [security2:error] [pid 18946:tid 19101] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OegQAAASM"]
[Thu Sep 17 15:34:35.129989 2026] [security2:error] [pid 18946:tid 19076] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/api/v2/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OehAAAAQo"]
[Thu Sep 17 15:34:35.132222 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/var/www/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OehgAAAUA"]
[Thu Sep 17 15:34:35.192429 2026] [security2:error] [pid 18946:tid 19163] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeiAAAAWE"]
[Thu Sep 17 15:34:35.229059 2026] [security2:error] [pid 18946:tid 19167] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/api/dev/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeiQAAAWU"]
[Thu Sep 17 15:34:35.292126 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/var/www/html/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeiwAAARk"]
[Thu Sep 17 15:34:35.297956 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/rest/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OejAAAAXM"]
[Thu Sep 17 15:34:35.315854 2026] [security2:error] [pid 18946:tid 19136] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OejQAAAUY"]
[Thu Sep 17 15:34:35.322720 2026] [security2:error] [pid 18946:tid 19111] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/gitlab/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OejgAAAS0"]
[Thu Sep 17 15:34:35.342180 2026] [security2:error] [pid 18946:tid 19077] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OejwAAAQs"]
[Thu Sep 17 15:34:35.382556 2026] [security2:error] [pid 18946:tid 19169] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/api/staging/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OekAAAAWc"]
[Thu Sep 17 15:34:35.445052 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OekwAAAVA"]
[Thu Sep 17 15:34:35.454417 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/current/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OelAAAAS8"]
[Thu Sep 17 15:34:35.488151 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/graphql/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OelgAAATI"]
[Thu Sep 17 15:34:35.496221 2026] [security2:error] [pid 18946:tid 19090] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OelwAAARg"]
[Thu Sep 17 15:34:35.534887 2026] [security2:error] [pid 18946:tid 19138] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/vendor/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OemAAAAUg"]
[Thu Sep 17 15:34:35.546989 2026] [security2:error] [pid 18946:tid 19132] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OemwAAAUI"]
[Thu Sep 17 15:34:35.550427 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/github/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OenAAAAWI"]
[Thu Sep 17 15:34:35.585365 2026] [security2:error] [pid 18946:tid 19180] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OengAAAXI"]
[Thu Sep 17 15:34:35.607366 2026] [security2:error] [pid 18946:tid 19109] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/release/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OenwAAASs"]
[Thu Sep 17 15:34:35.611324 2026] [security2:error] [pid 18946:tid 19155] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeoAAAAVk"]
[Thu Sep 17 15:34:35.651249 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/gateway/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeoQAAAYY"]
[Thu Sep 17 15:34:35.690946 2026] [security2:error] [pid 18946:tid 19082] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/lib/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeogAAARA"]
[Thu Sep 17 15:34:35.709720 2026] [security2:error] [pid 18946:tid 19107] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OepAAAASk"]
[Thu Sep 17 15:34:35.728606 2026] [security2:error] [pid 18946:tid 19174] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OepQAAAWw"]
[Thu Sep 17 15:34:35.760732 2026] [security2:error] [pid 18946:tid 19150] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/releases/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OepgAAAVQ"]
[Thu Sep 17 15:34:35.780157 2026] [security2:error] [pid 18946:tid 19148] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/actions/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OepwAAAVI"]
[Thu Sep 17 15:34:35.791188 2026] [security2:error] [pid 18946:tid 19170] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeqAAAAWg"]
[Thu Sep 17 15:34:35.839730 2026] [security2:error] [pid 18946:tid 19114] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/resources/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeqQAAATA"]
[Thu Sep 17 15:34:35.848043 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/microservice/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeqgAAAVg"]
[Thu Sep 17 15:34:35.865120 2026] [security2:error] [pid 18946:tid 19172] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeqwAAAWo"]
[Thu Sep 17 15:34:35.892951 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OerAAAAXk"]
[Thu Sep 17 15:34:35.913721 2026] [security2:error] [pid 18946:tid 19159] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OerQAAAV0"]
[Thu Sep 17 15:34:35.914946 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/shared/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OergAAATw"]
[Thu Sep 17 15:34:35.934392 2026] [security2:error] [pid 18946:tid 19179] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OerwAAAXE"]
[Thu Sep 17 15:34:35.987734 2026] [security2:error] [pid 18946:tid 19084] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/assets/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OesgAAARI"]
[Thu Sep 17 15:34:35.990883 2026] [security2:error] [pid 18946:tid 19156] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxc6zqiPMah0Tz_U1OeswAAAVo"]
[Thu Sep 17 15:34:36.008981 2026] [security2:error] [pid 18946:tid 19183] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/circleci/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OetAAAAXU"]
[Thu Sep 17 15:34:36.010554 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/service/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OetQAAAVc"]
[Thu Sep 17 15:34:36.078959 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/deploy/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OeuQAAAR4"]
[Thu Sep 17 15:34:36.140635 2026] [security2:error] [pid 18946:tid 19158] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/uploads/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OeugAAAVw"]
[Thu Sep 17 15:34:36.164770 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OeuwAAAV4"]
[Thu Sep 17 15:34:36.186062 2026] [security2:error] [pid 18946:tid 19144] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/api/v3/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OevAAAAU4"]
[Thu Sep 17 15:34:36.230462 2026] [security2:error] [pid 18946:tid 19112] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OevQAAAS4"]
[Thu Sep 17 15:34:36.237402 2026] [security2:error] [pid 18946:tid 19137] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/travis/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OevgAAAUc"]
[Thu Sep 17 15:34:36.238707 2026] [security2:error] [pid 18946:tid 19131] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/build/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OevwAAAUE"]
[Thu Sep 17 15:34:36.244951 2026] [security2:error] [pid 18946:tid 19166] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OewQAAAWQ"]
[Thu Sep 17 15:34:36.288671 2026] [security2:error] [pid 18946:tid 19193] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/internal/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OewgAAAX8"]
[Thu Sep 17 15:34:36.288671 2026] [security2:error] [pid 18946:tid 19185] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OewwAAAXc"]
[Thu Sep 17 15:34:36.359040 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OexAAAASE"]
[Thu Sep 17 15:34:36.362352 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/api/dev/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OexQAAASo"]
[Thu Sep 17 15:34:36.363726 2026] [security2:error] [pid 20162:tid 20370] [client 181.138.7.236:55126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc7K-O_Kk7aqBvaiF9rQAB3DQ"]
[Thu Sep 17 15:34:36.392524 2026] [security2:error] [pid 18946:tid 19152] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/dist/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OexwAAAVY"]
[Thu Sep 17 15:34:36.434361 2026] [security2:error] [pid 18946:tid 19141] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OeyAAAAUs"]
[Thu Sep 17 15:34:36.436251 2026] [security2:error] [pid 18946:tid 19085] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/tools/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OeyQAAARM"]
[Thu Sep 17 15:34:36.453760 2026] [security2:error] [pid 18946:tid 19093] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OeygAAARs"]
[Thu Sep 17 15:34:36.465685 2026] [security2:error] [pid 18946:tid 19079] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/buildkite/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OeywAAAQ0"]
[Thu Sep 17 15:34:36.522151 2026] [security2:error] [pid 18946:tid 19117] [client 40.81.232.68:54553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxc7DqiPMah0Tz_U1OezQAAATM"], referer: binance.com
[Thu Sep 17 15:34:36.548227 2026] [security2:error] [pid 18946:tid 19103] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/public_html/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe0AAAASU"]
[Thu Sep 17 15:34:36.561600 2026] [security2:error] [pid 18946:tid 19173] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxc7DqiPMah0Tz_U1OezAAAAWs"]
[Thu Sep 17 15:34:36.575985 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/api/staging/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe0QAAATY"]
[Thu Sep 17 15:34:36.586496 2026] [security2:error] [pid 18946:tid 19118] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/scripts/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe0gAAATQ"]
[Thu Sep 17 15:34:36.635352 2026] [security2:error] [pid 18946:tid 19142] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe0wAAAUw"]
[Thu Sep 17 15:34:36.699485 2026] [security2:error] [pid 18946:tid 19198] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mysql/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe1QAAAYQ"]
[Thu Sep 17 15:34:36.700842 2026] [security2:error] [pid 20162:tid 20316] [client 192.178.7.194:37212] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.gruposomacol.com"] [uri "/robots.txt"] [unique_id "aqxc7K-O_Kk7aqBvaiF9wAAAAaY"]
[Thu Sep 17 15:34:36.710446 2026] [security2:error] [pid 18946:tid 19161] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe1gAAAV8"]
[Thu Sep 17 15:34:36.715164 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/htdocs/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe1wAAARo"]
[Thu Sep 17 15:34:36.743328 2026] [security2:error] [pid 18946:tid 19125] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/bin/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe2AAAATs"]
[Thu Sep 17 15:34:36.812575 2026] [security2:error] [pid 18946:tid 19115] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/vendor/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe2QAAATE"]
[Thu Sep 17 15:34:36.817272 2026] [security2:error] [pid 18946:tid 19157] [client 34.94.67.131:36806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe2gAAAVs"]
[Thu Sep 17 15:34:36.870234 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/www/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe3AAAASc"]
[Thu Sep 17 15:34:36.904885 2026] [security2:error] [pid 18946:tid 19182] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/sbin/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe3QAAAXQ"]
[Thu Sep 17 15:34:36.928769 2026] [security2:error] [pid 18946:tid 19177] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/postgres/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe4QAAAW8"]
[Thu Sep 17 15:34:36.955900 2026] [core:error] [pid 18946:tid 19101] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:36.955917 2026] [core:error] [pid 18946:tid 19101] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:36.979300 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/lib/.env"] [unique_id "aqxc7DqiPMah0Tz_U1Oe4wAAAWE"]
[Thu Sep 17 15:34:37.024281 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/html/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe5AAAAYk"]
[Thu Sep 17 15:34:37.075090 2026] [security2:error] [pid 18946:tid 19181] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/local/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe5wAAAXM"]
[Thu Sep 17 15:34:37.136443 2026] [security2:error] [pid 18946:tid 19189] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/resources/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe6wAAAXs"]
[Thu Sep 17 15:34:37.160902 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/mongodb/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe7AAAAUY"]
[Thu Sep 17 15:34:37.179970 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/live/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe7gAAAWc"]
[Thu Sep 17 15:34:37.236923 2026] [security2:error] [pid 18946:tid 19116] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/portal/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe8AAAATI"]
[Thu Sep 17 15:34:37.277569 2026] [core:error] [pid 18946:tid 19132] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:37.277588 2026] [core:error] [pid 18946:tid 19132] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:37.298272 2026] [security2:error] [pid 18946:tid 19138] [client 192.178.6.4:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxc7TqiPMah0Tz_U1Oe8gAAAUg"]
[Thu Sep 17 15:34:37.339450 2026] [security2:error] [pid 18946:tid 19155] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/prod/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe9QAAAVk"]
[Thu Sep 17 15:34:37.346715 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/assets/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe9gAAASk"]
[Thu Sep 17 15:34:37.386503 2026] [security2:error] [pid 18946:tid 19150] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/dashboard/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe9wAAAVQ"]
[Thu Sep 17 15:34:37.393919 2026] [security2:error] [pid 18946:tid 19129] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/redis/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe-AAAAT8"]
[Thu Sep 17 15:34:37.480357 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe-QAAAYg"]
[Thu Sep 17 15:34:37.498298 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/dev/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe-wAAAQ4"]
[Thu Sep 17 15:34:37.520927 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe_QAAAQ8"]
[Thu Sep 17 15:34:37.520927 2026] [security2:error] [pid 18946:tid 19098] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/uploads/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe_AAAASA"]
[Thu Sep 17 15:34:37.534890 2026] [security2:error] [pid 18946:tid 19114] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/panel/.env"] [unique_id "aqxc7TqiPMah0Tz_U1Oe_gAAATA"]
[Thu Sep 17 15:34:37.597609 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfAQAAAXk"]
[Thu Sep 17 15:34:37.629329 2026] [security2:error] [pid 18946:tid 19159] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/elasticsearch/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfAwAAAV0"]
[Thu Sep 17 15:34:37.665177 2026] [security2:error] [pid 18946:tid 19179] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/staging/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfBAAAAXE"]
[Thu Sep 17 15:34:37.678941 2026] [security2:error] [pid 18946:tid 19156] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfBQAAAVo"]
[Thu Sep 17 15:34:37.684968 2026] [security2:error] [pid 18946:tid 19183] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/internal/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfBwAAAXU"]
[Thu Sep 17 15:34:37.685067 2026] [security2:error] [pid 18946:tid 19153] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/crm/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfBgAAAVc"]
[Thu Sep 17 15:34:37.728113 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfCAAAAR8"]
[Thu Sep 17 15:34:37.770452 2026] [security2:error] [pid 18946:tid 18984] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfGAABfSU"]
[Thu Sep 17 15:34:37.773301 2026] [security2:error] [pid 18946:tid 18973] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env.bak"] [unique_id "aqxc7TqiPMah0Tz_U1OfJAABfRo"]
[Thu Sep 17 15:34:37.773474 2026] [security2:error] [pid 18946:tid 18988] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env.backup"] [unique_id "aqxc7TqiPMah0Tz_U1OfIgABfSk"]
[Thu Sep 17 15:34:37.773646 2026] [security2:error] [pid 18946:tid 18979] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env.old"] [unique_id "aqxc7TqiPMah0Tz_U1OfIQABfSA"]
[Thu Sep 17 15:34:37.790785 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfKgAAAV4"]
[Thu Sep 17 15:34:37.828271 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/opt/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfKwAAAS4"]
[Thu Sep 17 15:34:37.840339 2026] [security2:error] [pid 18946:tid 19137] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/erp/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfLAAAAUc"]
[Thu Sep 17 15:34:37.843767 2026] [security2:error] [pid 18946:tid 19196] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfLQAAAYI"]
[Thu Sep 17 15:34:37.868812 2026] [security2:error] [pid 18946:tid 19131] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/rabbitmq/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfLwAAAUE"]
[Thu Sep 17 15:34:37.869401 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfGQABfU0"]
[Thu Sep 17 15:34:37.869591 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfHAABfRQ"]
[Thu Sep 17 15:34:37.871822 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfHQABfWE"]
[Thu Sep 17 15:34:37.871928 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfIAABfSU"]
[Thu Sep 17 15:34:37.872652 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/tools/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfMAAAAWQ"]
[Thu Sep 17 15:34:37.873825 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfJwABfQY"]
[Thu Sep 17 15:34:37.877122 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfHwABfVo"]
[Thu Sep 17 15:34:37.879347 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfGwABfS0"]
[Thu Sep 17 15:34:37.885880 2026] [security2:error] [pid 18946:tid 19140] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfMQAAAUo"]
[Thu Sep 17 15:34:37.982486 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/laravel/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfNQAAAYE"]
[Thu Sep 17 15:34:37.988561 2026] [security2:error] [pid 18946:tid 19188] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/shop/.env"] [unique_id "aqxc7TqiPMah0Tz_U1OfNgAAAXo"]
[Thu Sep 17 15:34:38.002731 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfIwABfRs"]
[Thu Sep 17 15:34:38.002981 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfGgABfRI"]
[Thu Sep 17 15:34:38.003138 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfHgABfR8"]
[Thu Sep 17 15:34:38.003198 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfJgABfRE"]
[Thu Sep 17 15:34:38.003255 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7TqiPMah0Tz_U1OfKAABfTE"]
[Thu Sep 17 15:34:38.005348 2026] [security2:error] [pid 18946:tid 18995] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env~"] [unique_id "aqxc7jqiPMah0Tz_U1OfPAABfTA"]
[Thu Sep 17 15:34:38.005359 2026] [security2:error] [pid 18946:tid 18985] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env.swp"] [unique_id "aqxc7jqiPMah0Tz_U1OfOQABfSY"]
[Thu Sep 17 15:34:38.021193 2026] [security2:error] [pid 18946:tid 19014] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfNwABfUM"]
[Thu Sep 17 15:34:38.026443 2026] [security2:error] [pid 18946:tid 19185] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfPwAAAXc"]
[Thu Sep 17 15:34:38.050953 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/scripts/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfQgAAASo"]
[Thu Sep 17 15:34:38.070362 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfPgABfSo"]
[Thu Sep 17 15:34:38.070545 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfOwABfQQ"]
[Thu Sep 17 15:34:38.070632 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfOAABfXk"]
[Thu Sep 17 15:34:38.076181 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfOgABfTc"]
[Thu Sep 17 15:34:38.079006 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfPQABfUg"]
[Thu Sep 17 15:34:38.094676 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfRAAAAVE"]
[Thu Sep 17 15:34:38.095673 2026] [security2:error] [pid 20162:tid 20416] [client 114.198.138.124:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc7q-O_Kk7aqBvaiF9zAAAAgo"]
[Thu Sep 17 15:34:38.095793 2026] [security2:error] [pid 20162:tid 20416] [client 114.198.138.124:58535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc7q-O_Kk7aqBvaiF9zAAAAgo"]
[Thu Sep 17 15:34:38.099137 2026] [security2:error] [pid 18946:tid 19134] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/kafka/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfRQAAAUQ"]
[Thu Sep 17 15:34:38.112252 2026] [security2:error] [pid 20162:tid 20398] [client 14.96.156.146:58498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc7q-O_Kk7aqBvaiF9zQAAAfg"]
[Thu Sep 17 15:34:38.112317 2026] [security2:error] [pid 20162:tid 20398] [client 14.96.156.146:58498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc7q-O_Kk7aqBvaiF9zQAAAfg"]
[Thu Sep 17 15:34:38.136877 2026] [security2:error] [pid 18946:tid 19110] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/store/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfRgAAASw"]
[Thu Sep 17 15:34:38.137182 2026] [security2:error] [pid 18946:tid 19088] [client 34.154.219.37:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/symfony/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfRwAAARY"]
[Thu Sep 17 15:34:38.139452 2026] [security2:error] [pid 18946:tid 19016] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/api/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfSQABg0U"]
[Thu Sep 17 15:34:38.140594 2026] [security2:error] [pid 18946:tid 18991] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/app/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfTAABgyw"]
[Thu Sep 17 15:34:38.140904 2026] [security2:error] [pid 18946:tid 19005] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/backend/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfTQABgzo"]
[Thu Sep 17 15:34:38.142386 2026] [security2:error] [pid 18946:tid 19121] [client 103.61.184.148:54119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfUAAAATc"]
[Thu Sep 17 15:34:38.142469 2026] [security2:error] [pid 18946:tid 19121] [client 103.61.184.148:54119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfUAAAATc"]
[Thu Sep 17 15:34:38.171362 2026] [security2:error] [pid 18946:tid 19141] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfUQAAAUs"]
[Thu Sep 17 15:34:38.175765 2026] [security2:error] [pid 18946:tid 19001] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/server/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfUwABgzY"]
[Thu Sep 17 15:34:38.175837 2026] [security2:error] [pid 18946:tid 19013] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfVAABg0I"]
[Thu Sep 17 15:34:38.208898 2026] [security2:error] [pid 18946:tid 19197] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfSgABgyI"]
[Thu Sep 17 15:34:38.209112 2026] [security2:error] [pid 18946:tid 19197] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfTwABg0w"]
[Thu Sep 17 15:34:38.211013 2026] [security2:error] [pid 18946:tid 19197] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfTgABgzI"]
[Thu Sep 17 15:34:38.212287 2026] [security2:error] [pid 18946:tid 19197] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfSAABgzg"]
[Thu Sep 17 15:34:38.212398 2026] [security2:error] [pid 18946:tid 19197] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfSwABgx4"]
[Thu Sep 17 15:34:38.245219 2026] [security2:error] [pid 18946:tid 19197] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfUgABgzU"]
[Thu Sep 17 15:34:38.245930 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/bin/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfVQAAAQ0"]
[Thu Sep 17 15:34:38.273098 2026] [security2:error] [pid 18946:tid 19004] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/web/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfWAABazk"]
[Thu Sep 17 15:34:38.273101 2026] [security2:error] [pid 18946:tid 19012] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/src/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfXAABa0E"]
[Thu Sep 17 15:34:38.273104 2026] [security2:error] [pid 18946:tid 19008] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/frontend/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfWwABaz0"]
[Thu Sep 17 15:34:38.273133 2026] [security2:error] [pid 18946:tid 19054] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/public/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfWQABa2s"]
[Thu Sep 17 15:34:38.273135 2026] [security2:error] [pid 18946:tid 19020] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/client/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfWgABa0k"]
[Thu Sep 17 15:34:38.273640 2026] [security2:error] [pid 18946:tid 19009] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/var/www/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfXQABaz4"]
[Thu Sep 17 15:34:38.274747 2026] [security2:error] [pid 18946:tid 19022] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/var/www/html/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfXgABNks"]
[Thu Sep 17 15:34:38.274990 2026] [security2:error] [pid 18946:tid 19053] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/laravel/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfXwABNmo"]
[Thu Sep 17 15:34:38.281446 2026] [security2:error] [pid 18946:tid 19118] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfYAAAATQ"]
[Thu Sep 17 15:34:38.283574 2026] [security2:error] [pid 18946:tid 19198] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/saas/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfYQAAAYQ"]
[Thu Sep 17 15:34:38.309941 2026] [security2:error] [pid 18946:tid 19061] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/application/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfYgABGnI"]
[Thu Sep 17 15:34:38.310097 2026] [security2:error] [pid 18946:tid 19043] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/apps/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfYwABGmA"]
[Thu Sep 17 15:34:38.329513 2026] [security2:error] [pid 18946:tid 19125] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/queue/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfZAAAATs"]
[Thu Sep 17 15:34:38.342857 2026] [security2:error] [pid 18946:tid 19122] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfaAAAATg"]
[Thu Sep 17 15:34:38.343134 2026] [security2:error] [pid 18946:tid 19033] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/back/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfaQABJ1Y"]
[Thu Sep 17 15:34:38.343202 2026] [security2:error] [pid 18946:tid 19010] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/backup/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfagABJz8"]
[Thu Sep 17 15:34:38.345629 2026] [security2:error] [pid 18946:tid 19017] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/cms/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfbAABY0Y"]
[Thu Sep 17 15:34:38.348436 2026] [security2:error] [pid 18946:tid 18994] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/prod/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfbQABdC8"]
[Thu Sep 17 15:34:38.348463 2026] [security2:error] [pid 18946:tid 19031] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/dev/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfbgABdFQ"]
[Thu Sep 17 15:34:38.379757 2026] [security2:error] [pid 18946:tid 19050] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/production/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfbwABT2c"]
[Thu Sep 17 15:34:38.404230 2026] [security2:error] [pid 18946:tid 19168] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfcAAAAWY"]
[Thu Sep 17 15:34:38.407537 2026] [security2:error] [pid 18946:tid 19034] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/new/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfcwABPVc"]
[Thu Sep 17 15:34:38.407584 2026] [security2:error] [pid 18946:tid 18993] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/test/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfcQABPS4"]
[Thu Sep 17 15:34:38.407592 2026] [security2:error] [pid 18946:tid 19057] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/staging/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfcgABPW4"]
[Thu Sep 17 15:34:38.407651 2026] [security2:error] [pid 18946:tid 19006] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/node-api/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfdAABPTs"]
[Thu Sep 17 15:34:38.407673 2026] [security2:error] [pid 18946:tid 19046] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/old/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfdQABPWM"]
[Thu Sep 17 15:34:38.407805 2026] [security2:error] [pid 18946:tid 19039] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/api-backend/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfdgABPVw"]
[Thu Sep 17 15:34:38.408868 2026] [security2:error] [pid 18946:tid 19041] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/admin-app/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfdwABU14"]
[Thu Sep 17 15:34:38.428218 2026] [security2:error] [pid 18946:tid 19018] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/administrator/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfeAABU0c"]
[Thu Sep 17 15:34:38.431008 2026] [security2:error] [pid 18946:tid 19101] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/client/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfeQAAASM"]
[Thu Sep 17 15:34:38.465248 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/sbin/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfegAAARc"]
[Thu Sep 17 15:34:38.472705 2026] [security2:error] [pid 18946:tid 19038] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/current/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfewABQFs"]
[Thu Sep 17 15:34:38.472728 2026] [security2:error] [pid 18946:tid 19029] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/public_html/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OffAABQFI"]
[Thu Sep 17 15:34:38.477571 2026] [security2:error] [pid 18946:tid 19042] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/server/backend/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OffgABgF8"]
[Thu Sep 17 15:34:38.477599 2026] [security2:error] [pid 18946:tid 19028] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/server/api/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OffQABgFE"]
[Thu Sep 17 15:34:38.480256 2026] [security2:error] [pid 18946:tid 19011] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.docker/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OffwABYUA"]
[Thu Sep 17 15:34:38.482467 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfgAAAASY"]
[Thu Sep 17 15:34:38.482731 2026] [security2:error] [pid 18946:tid 18998] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/aws/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfggABiTM"]
[Thu Sep 17 15:34:38.482777 2026] [security2:error] [pid 18946:tid 19048] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfgQABiWU"]
[Thu Sep 17 15:34:38.514107 2026] [security2:error] [pid 18946:tid 19026] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.aws/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfgwABZU8"]
[Thu Sep 17 15:34:38.544757 2026] [security2:error] [pid 18946:tid 18987] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/stripe/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfhAABGSg"]
[Thu Sep 17 15:34:38.544811 2026] [security2:error] [pid 18946:tid 19059] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/v2/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfhwABGXA"]
[Thu Sep 17 15:34:38.544864 2026] [security2:error] [pid 18946:tid 19052] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/v3/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfiQABGWk"]
[Thu Sep 17 15:34:38.544933 2026] [security2:error] [pid 18946:tid 19030] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/v1/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfiAABGVM"]
[Thu Sep 17 15:34:38.544935 2026] [security2:error] [pid 18946:tid 19073] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/media/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfigABGX4"]
[Thu Sep 17 15:34:38.557091 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/worker/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfjgAAAUY"]
[Thu Sep 17 15:34:38.578446 2026] [security2:error] [pid 18946:tid 19135] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/project/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfkAAAAUU"]
[Thu Sep 17 15:34:38.584776 2026] [security2:error] [pid 18946:tid 19113] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfkgAAAS8"]
[Thu Sep 17 15:34:38.613214 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfhQABGVU"]
[Thu Sep 17 15:34:38.616435 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfhgABGVk"]
[Thu Sep 17 15:34:38.619734 2026] [security2:error] [pid 18946:tid 19076] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/wordpress/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfmAAAAQo"]
[Thu Sep 17 15:34:38.634702 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfjwABGVg"]
[Thu Sep 17 15:34:38.643981 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/local/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfmwAAARg"]
[Thu Sep 17 15:34:38.659685 2026] [security2:error] [pid 18946:tid 19116] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfnAAAATI"]
[Thu Sep 17 15:34:38.684925 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OflAABGWg"]
[Thu Sep 17 15:34:38.685437 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfkwABGWw"]
[Thu Sep 17 15:34:38.685787 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OflQABGXc"]
[Thu Sep 17 15:34:38.690703 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfmgABGXE"]
[Thu Sep 17 15:34:38.691720 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OflgABGXg"]
[Thu Sep 17 15:34:38.692312 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfmQABGXo"]
[Thu Sep 17 15:34:38.692631 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OflwABGQ4"]
[Thu Sep 17 15:34:38.711876 2026] [security2:error] [pid 18946:tid 19062] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.git/config.bak"] [unique_id "aqxc7jqiPMah0Tz_U1OfnwABGXM"]
[Thu Sep 17 15:34:38.712543 2026] [security2:error] [pid 18946:tid 19077] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfowAAAQs"]
[Thu Sep 17 15:34:38.726044 2026] [security2:error] [pid 18946:tid 19138] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/admin-panel/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfpAAAAUg"]
[Thu Sep 17 15:34:38.737680 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfnQABGQ0"]
[Thu Sep 17 15:34:38.774933 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfngABGU4"]
[Thu Sep 17 15:34:38.775069 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfoQABGXs"]
[Thu Sep 17 15:34:38.778372 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfqAAAASs"]
[Thu Sep 17 15:34:38.780612 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfoAABGWQ"]
[Thu Sep 17 15:34:38.780959 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfogABGX0"]
[Thu Sep 17 15:34:38.791321 2026] [security2:error] [pid 18946:tid 19107] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/job/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfqQAAASk"]
[Thu Sep 17 15:34:38.817680 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/wp/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfqgAAAW0"]
[Thu Sep 17 15:34:38.829940 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/portal/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfqwAAAXI"]
[Thu Sep 17 15:34:38.832071 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfpgABGRA"]
[Thu Sep 17 15:34:38.833357 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfpQABGW0"]
[Thu Sep 17 15:34:38.833687 2026] [security2:error] [pid 18946:tid 19111] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfrQAAAS0"]
[Thu Sep 17 15:34:38.860086 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfrgAAASQ"]
[Thu Sep 17 15:34:38.875326 2026] [security2:error] [pid 18946:tid 19124] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/control-panel/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OftAAAATo"]
[Thu Sep 17 15:34:38.897121 2026] [security2:error] [pid 18946:tid 19091] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7jqiPMah0Tz_U1OfrAABGQo"]
[Thu Sep 17 15:34:38.923059 2026] [security2:error] [pid 18946:tid 19178] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OftQAAAXA"]
[Thu Sep 17 15:34:38.976603 2026] [security2:error] [pid 18946:tid 19199] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/cms/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OftgAAAYU"]
[Thu Sep 17 15:34:38.977775 2026] [security2:error] [pid 18946:tid 19100] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OftwAAASI"]
[Thu Sep 17 15:34:38.992999 2026] [security2:error] [pid 18946:tid 19171] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/dashboard/.env"] [unique_id "aqxc7jqiPMah0Tz_U1OfuAAAAWk"]
[Thu Sep 17 15:34:39.012439 2026] [security2:error] [pid 18946:tid 19083] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OfuQAAARE"]
[Thu Sep 17 15:34:39.018513 2026] [security2:error] [pid 18946:tid 19129] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OfuwAAAT8"]
[Thu Sep 17 15:34:39.023491 2026] [security2:error] [pid 18946:tid 19148] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/user-panel/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OfvQAAAVI"]
[Thu Sep 17 15:34:39.026295 2026] [security2:error] [pid 18946:tid 18954] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxc7zqiPMah0Tz_U1OfwwABaAc"]
[Thu Sep 17 15:34:39.026299 2026] [security2:error] [pid 18946:tid 18970] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/id_rsa"] [unique_id "aqxc7zqiPMah0Tz_U1OfvwABaBc"]
[Thu Sep 17 15:34:39.026642 2026] [security2:error] [pid 18946:tid 18955] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxc7zqiPMah0Tz_U1OfwAABaAg"]
[Thu Sep 17 15:34:39.079598 2026] [security2:error] [pid 18946:tid 19143] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OfzgAAAU0"]
[Thu Sep 17 15:34:39.095943 2026] [security2:error] [pid 18946:tid 19081] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OfzwAAAQ8"]
[Thu Sep 17 15:34:39.111263 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfyAABaA8"]
[Thu Sep 17 15:34:39.111672 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfxAABaBY"]
[Thu Sep 17 15:34:39.114927 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfywABaEo"]
[Thu Sep 17 15:34:39.115056 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfwQABaH8"]
[Thu Sep 17 15:34:39.154691 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/drupal/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of0AAAATA"]
[Thu Sep 17 15:34:39.159828 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of0QAAAXk"]
[Thu Sep 17 15:34:39.170146 2026] [security2:error] [pid 18946:tid 19159] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/node/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of1QAAAV0"]
[Thu Sep 17 15:34:39.178237 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/panel/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of1gAAATU"]
[Thu Sep 17 15:34:39.233330 2026] [security2:error] [pid 18946:tid 19126] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of1wAAATw"]
[Thu Sep 17 15:34:39.246886 2026] [security2:error] [pid 18946:tid 19179] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of2AAAAXE"]
[Thu Sep 17 15:34:39.256575 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfyQABaAw"]
[Thu Sep 17 15:34:39.262756 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfvgABaBU"]
[Thu Sep 17 15:34:39.263001 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfxwABaAI"]
[Thu Sep 17 15:34:39.263170 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfygABaDQ"]
[Thu Sep 17 15:34:39.264131 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfwgABaBg"]
[Thu Sep 17 15:34:39.265245 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfzAABaFA"]
[Thu Sep 17 15:34:39.265901 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfxQABaAE"]
[Thu Sep 17 15:34:39.271853 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfxgABaDw"]
[Thu Sep 17 15:34:39.285968 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OfzQABaBo"]
[Thu Sep 17 15:34:39.295025 2026] [security2:error] [pid 18946:tid 19084] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of2QAAARI"]
[Thu Sep 17 15:34:39.313292 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/joomla/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of2gAAARw"]
[Thu Sep 17 15:34:39.320561 2026] [security2:error] [pid 18946:tid 19183] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/express/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of2wAAAXU"]
[Thu Sep 17 15:34:39.329091 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of0wABaCA"]
[Thu Sep 17 15:34:39.329207 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of1AABaCM"]
[Thu Sep 17 15:34:39.333494 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of0gABaCk"]
[Thu Sep 17 15:34:39.358602 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of4AAAAVc"]
[Thu Sep 17 15:34:39.373567 2026] [security2:error] [pid 18946:tid 19097] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of4QAAAR8"]
[Thu Sep 17 15:34:39.375317 2026] [security2:error] [pid 18946:tid 19192] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/crm/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of4gAAAX4"]
[Thu Sep 17 15:34:39.386225 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of3AABaE0"]
[Thu Sep 17 15:34:39.387176 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of3QABaAU"]
[Thu Sep 17 15:34:39.388093 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of3gABaCU"]
[Thu Sep 17 15:34:39.392915 2026] [security2:error] [pid 18946:tid 19170] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of3wABaBQ"]
[Thu Sep 17 15:34:39.461121 2026] [security2:error] [pid 18946:tid 19096] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of7AAAAR4"]
[Thu Sep 17 15:34:39.470750 2026] [security2:error] [pid 18946:tid 19146] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/next/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of8QAAAVA"]
[Thu Sep 17 15:34:39.473084 2026] [security2:error] [pid 18946:tid 19160] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/magento/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of8gAAAV4"]
[Thu Sep 17 15:34:39.474814 2026] [security2:error] [pid 18946:tid 19158] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/preview/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of8wAAAVw"]
[Thu Sep 17 15:34:39.491427 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of5AABeGE"]
[Thu Sep 17 15:34:39.510545 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of5QABeAY"]
[Thu Sep 17 15:34:39.511189 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of5gABeCQ"]
[Thu Sep 17 15:34:39.513376 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of5wABeFo"]
[Thu Sep 17 15:34:39.531237 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of6AABeDE"]
[Thu Sep 17 15:34:39.531363 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of6wABeBI"]
[Thu Sep 17 15:34:39.531476 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of6QABeC0"]
[Thu Sep 17 15:34:39.531527 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of6gABeBs"]
[Thu Sep 17 15:34:39.550344 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of7QABeBE"]
[Thu Sep 17 15:34:39.550480 2026] [security2:error] [pid 18946:tid 19196] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of-gAAAYI"]
[Thu Sep 17 15:34:39.553011 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/erp/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of-wAAAWQ"]
[Thu Sep 17 15:34:39.553707 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of7wABeCc"]
[Thu Sep 17 15:34:39.554169 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of7gABeCE"]
[Thu Sep 17 15:34:39.555781 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of8AABeBw"]
[Thu Sep 17 15:34:39.573780 2026] [security2:error] [pid 18946:tid 19123] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of_QAAATk"]
[Thu Sep 17 15:34:39.621282 2026] [security2:error] [pid 18946:tid 19186] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1Of-QABeDA"]
[Thu Sep 17 15:34:39.624954 2026] [security2:error] [pid 18946:tid 19140] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/nuxt/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of_gAAAUo"]
[Thu Sep 17 15:34:39.632266 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/shopify/.env"] [unique_id "aqxc7zqiPMah0Tz_U1Of_wAAAXw"]
[Thu Sep 17 15:34:39.635405 2026] [security2:error] [pid 18946:tid 19095] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgAAAAAR0"]
[Thu Sep 17 15:34:39.665284 2026] [security2:error] [pid 18946:tid 19195] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgAQAAAYE"]
[Thu Sep 17 15:34:39.703755 2026] [security2:error] [pid 18946:tid 19108] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgAgAAASo"]
[Thu Sep 17 15:34:39.711342 2026] [security2:error] [pid 18946:tid 19152] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/shop/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgBgAAAVY"]
[Thu Sep 17 15:34:39.730173 2026] [security2:error] [pid 18946:tid 19002] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgEQABfTc"]
[Thu Sep 17 15:34:39.747478 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgEwAAAVE"]
[Thu Sep 17 15:34:39.770420 2026] [security2:error] [pid 18946:tid 19134] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgFAAAAUQ"]
[Thu Sep 17 15:34:39.788232 2026] [security2:error] [pid 18946:tid 19110] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/prestashop/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgFQAAASw"]
[Thu Sep 17 15:34:39.795217 2026] [security2:error] [pid 18946:tid 19088] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/nest/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgFgAAARY"]
[Thu Sep 17 15:34:39.883979 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.45.51:58694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/store/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgGAAAAUM"]
[Thu Sep 17 15:34:39.921939 2026] [security2:error] [pid 18946:tid 19085] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgGQAAARM"]
[Thu Sep 17 15:34:39.934382 2026] [security2:error] [pid 18946:tid 19197] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/uat/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgGgAAAYM"]
[Thu Sep 17 15:34:39.944462 2026] [security2:error] [pid 18946:tid 19099] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/codeigniter/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgHAAAASE"]
[Thu Sep 17 15:34:39.944515 2026] [security2:error] [pid 18946:tid 19117] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/react/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgGwAAATM"]
[Thu Sep 17 15:34:39.990477 2026] [security2:error] [pid 18946:tid 19103] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxc7zqiPMah0Tz_U1OgHQAAASU"]
[Thu Sep 17 15:34:40.052410 2026] [security2:error] [pid 18946:tid 19142] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgIAAAAUw"]
[Thu Sep 17 15:34:40.074311 2026] [security2:error] [pid 18946:tid 19185] [client 177.44.133.72:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgIQAAAXc"]
[Thu Sep 17 15:34:40.074419 2026] [security2:error] [pid 18946:tid 19185] [client 177.44.133.72:62795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgIQAAAXc"]
[Thu Sep 17 15:34:40.093830 2026] [security2:error] [pid 18946:tid 19161] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/vue/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgIwAAAV8"]
[Thu Sep 17 15:34:40.100592 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/cakephp/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgJAAAARo"]
[Thu Sep 17 15:34:40.150383 2026] [security2:error] [pid 18946:tid 19125] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgJwAAATs"]
[Thu Sep 17 15:34:40.163686 2026] [security2:error] [pid 18946:tid 19157] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgKAAAAVs"]
[Thu Sep 17 15:34:40.197849 2026] [security2:error] [pid 18946:tid 19165] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgLAAAAWM"]
[Thu Sep 17 15:34:40.208814 2026] [security2:error] [pid 18946:tid 19004] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config/aws.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgLQABfTk"]
[Thu Sep 17 15:34:40.228199 2026] [security2:error] [pid 18946:tid 19168] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgLwAAAWY"]
[Thu Sep 17 15:34:40.241015 2026] [security2:error] [pid 18946:tid 19127] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/angular/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgMAAAAT0"]
[Thu Sep 17 15:34:40.256106 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/zend/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgMQAAAVM"]
[Thu Sep 17 15:34:40.273253 2026] [security2:error] [pid 18946:tid 19089] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgMgAAARc"]
[Thu Sep 17 15:34:40.294505 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgBAABfXk"]
[Thu Sep 17 15:34:40.302400 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgBQABfQQ"]
[Thu Sep 17 15:34:40.302538 2026] [security2:error] [pid 18946:tid 18989] [remote 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgAwABfSo"]
[Thu Sep 17 15:34:40.309516 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgDAABfTg"]
[Thu Sep 17 15:34:40.314446 2026] [security2:error] [pid 18946:tid 19130] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgNAAAAUA"]
[Thu Sep 17 15:34:40.314555 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgEgABfR4"]
[Thu Sep 17 15:34:40.317287 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgCQABfUI"]
[Thu Sep 17 15:34:40.324149 2026] [security2:error] [pid 18946:tid 19194] [client 40.77.167.55:57328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fetchandfierce.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgNQAAAYA"]
[Thu Sep 17 15:34:40.324893 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgDwABfUU"]
[Thu Sep 17 15:34:40.325015 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgDQABfSw"]
[Thu Sep 17 15:34:40.330461 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgCgABfUg"]
[Thu Sep 17 15:34:40.332796 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgDgABfTo"]
[Thu Sep 17 15:34:40.337976 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgEAABfUw"]
[Thu Sep 17 15:34:40.338199 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgCwABfTY"]
[Thu Sep 17 15:34:40.338241 2026] [security2:error] [pid 18946:tid 19104] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgNgAAASY"]
[Thu Sep 17 15:34:40.338270 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgBwABfSI"]
[Thu Sep 17 15:34:40.339556 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc7zqiPMah0Tz_U1OgCAABfTI"]
[Thu Sep 17 15:34:40.369313 2026] [security2:error] [pid 18946:tid 19191] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgKQABfUQ"]
[Thu Sep 17 15:34:40.389080 2026] [security2:error] [pid 18946:tid 19189] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/svelte/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgNwAAAXs"]
[Thu Sep 17 15:34:40.392218 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgOAAAAUY"]
[Thu Sep 17 15:34:40.402055 2026] [security2:error] [pid 18946:tid 19076] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgOgAAAQo"]
[Thu Sep 17 15:34:40.411203 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/yii/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgOwAAAWc"]
[Thu Sep 17 15:34:40.429706 2026] [security2:error] [pid 18946:tid 19012] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config/stripe.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgPQABh0E"]
[Thu Sep 17 15:34:40.437109 2026] [security2:error] [pid 18946:tid 19090] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgPgAAARg"]
[Thu Sep 17 15:34:40.443858 2026] [security2:error] [pid 18946:tid 19020] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config/mail.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgQAABh0k"]
[Thu Sep 17 15:34:40.464989 2026] [security2:error] [pid 18946:tid 19009] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config/config.inc.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgQQABhz4"]
[Thu Sep 17 15:34:40.470365 2026] [security2:error] [pid 18946:tid 19053] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config/nexmo.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgQwABh2o"]
[Thu Sep 17 15:34:40.488471 2026] [security2:error] [pid 18946:tid 19063] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/wp-config.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgRgABh3Q"]
[Thu Sep 17 15:34:40.501084 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/saas/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgSgAAAWE"]
[Thu Sep 17 15:34:40.504053 2026] [security2:error] [pid 18946:tid 19033] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/wp-config.php.bak"] [unique_id "aqxc8DqiPMah0Tz_U1OgTAABh1Y"]
[Thu Sep 17 15:34:40.504391 2026] [security2:error] [pid 18946:tid 19201] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgPAABhz0"]
[Thu Sep 17 15:34:40.508949 2026] [security2:error] [pid 18946:tid 19201] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgPwABh2s"]
[Thu Sep 17 15:34:40.520173 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgTQAAAUk"]
[Thu Sep 17 15:34:40.541155 2026] [security2:error] [pid 18946:tid 19082] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/vite/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgUAAAARA"]
[Thu Sep 17 15:34:40.541303 2026] [security2:error] [pid 18946:tid 19201] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgQgABh0s"]
[Thu Sep 17 15:34:40.541510 2026] [security2:error] [pid 18946:tid 19201] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgRAABh3I"]
[Thu Sep 17 15:34:40.549276 2026] [security2:error] [pid 18946:tid 19017] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/wp-config.php.new"] [unique_id "aqxc8DqiPMah0Tz_U1OgUQABh0Y"]
[Thu Sep 17 15:34:40.549276 2026] [security2:error] [pid 18946:tid 19010] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/wp-config.php.old"] [unique_id "aqxc8DqiPMah0Tz_U1OgUgABhz8"]
[Thu Sep 17 15:34:40.549776 2026] [security2:error] [pid 18946:tid 19049] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxc8DqiPMah0Tz_U1OgUwABh2Y"]
[Thu Sep 17 15:34:40.557279 2026] [security2:error] [pid 18946:tid 19109] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgVAAAASs"]
[Thu Sep 17 15:34:40.558262 2026] [security2:error] [pid 18946:tid 19201] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgRQABh2A"]
[Thu Sep 17 15:34:40.570093 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/laravel5/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgVQAAASk"]
[Thu Sep 17 15:34:40.604384 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgWQAAASQ"]
[Thu Sep 17 15:34:40.620747 2026] [security2:error] [pid 18946:tid 19124] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgWgAAATo"]
[Thu Sep 17 15:34:40.641447 2026] [security2:error] [pid 18946:tid 19034] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxc8DqiPMah0Tz_U1OgXQABLVc"]
[Thu Sep 17 15:34:40.674769 2026] [security2:error] [pid 18946:tid 19111] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgWAABLVQ"]
[Thu Sep 17 15:34:40.683607 2026] [security2:error] [pid 18946:tid 19178] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/client/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgXwAAAXA"]
[Thu Sep 17 15:34:40.689165 2026] [security2:error] [pid 18946:tid 19199] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/backup/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgYAAAAYU"]
[Thu Sep 17 15:34:40.692445 2026] [security2:error] [pid 18946:tid 19100] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgYQAAASI"]
[Thu Sep 17 15:34:40.717053 2026] [security2:error] [pid 18946:tid 19129] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgYwAAAT8"]
[Thu Sep 17 15:34:40.724830 2026] [security2:error] [pid 18946:tid 19111] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgWwABLWc"]
[Thu Sep 17 15:34:40.725796 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/v1/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgZAAAAVI"]
[Thu Sep 17 15:34:40.728084 2026] [security2:error] [pid 18946:tid 19111] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgXAABLS4"]
[Thu Sep 17 15:34:40.729693 2026] [security2:error] [pid 18946:tid 19111] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgXgABLW4"]
[Thu Sep 17 15:34:40.757353 2026] [security2:error] [pid 18946:tid 19098] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgZQAAASA"]
[Thu Sep 17 15:34:40.775320 2026] [security2:error] [pid 20162:tid 20337] [client 69.112.165.154:49673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc8K-O_Kk7aqBvaiF94wABu0Q"], referer: https://www.google.com/
[Thu Sep 17 15:34:40.786886 2026] [security2:error] [pid 18946:tid 19114] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgZwAAATA"]
[Thu Sep 17 15:34:40.821722 2026] [security2:error] [pid 18946:tid 19187] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgaQAAAXk"]
[Thu Sep 17 15:34:40.837393 2026] [security2:error] [pid 18946:tid 19159] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/backups/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgagAAAV0"]
[Thu Sep 17 15:34:40.849369 2026] [security2:error] [pid 18946:tid 19119] [client 34.166.234.125:44484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/config/app/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgawAAATU"]
[Thu Sep 17 15:34:40.851981 2026] [security2:error] [pid 18946:tid 19126] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgbAAAATw"]
[Thu Sep 17 15:34:40.858151 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgZgABDzs"]
[Thu Sep 17 15:34:40.858494 2026] [security2:error] [pid 18946:tid 19179] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/project/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgbQAAAXE"]
[Thu Sep 17 15:34:40.865146 2026] [security2:error] [pid 18946:tid 19018] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxc8DqiPMah0Tz_U1OgcAABD0c"]
[Thu Sep 17 15:34:40.885910 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgaAABD2M"]
[Thu Sep 17 15:34:40.886147 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/v2/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgdAAAAYg"]
[Thu Sep 17 15:34:40.892597 2026] [security2:error] [pid 18946:tid 19162] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgdQAAAWA"]
[Thu Sep 17 15:34:40.947151 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgbwABD14"]
[Thu Sep 17 15:34:40.947388 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgbgABD1w"]
[Thu Sep 17 15:34:40.950459 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgcwABD1s"]
[Thu Sep 17 15:34:40.984894 2026] [security2:error] [pid 18946:tid 19183] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/old/.env"] [unique_id "aqxc8DqiPMah0Tz_U1OgfQAAAXU"]
[Thu Sep 17 15:34:41.015024 2026] [security2:error] [pid 18946:tid 19153] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgfgAAAVc"]
[Thu Sep 17 15:34:41.021394 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/admin-panel/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgfwAAAQw"]
[Thu Sep 17 15:34:41.047170 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/v3/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OggwAAAR4"]
[Thu Sep 17 15:34:41.059825 2026] [security2:error] [pid 18946:tid 19146] [client 34.94.67.131:36822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OghAAAAVA"]
[Thu Sep 17 15:34:41.078828 2026] [security2:error] [pid 18946:tid 19086] [client 34.166.234.125:44484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgiAAAARQ"]
[Thu Sep 17 15:34:41.134269 2026] [security2:error] [pid 18946:tid 19166] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/tmp/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgjAAAAWQ"]
[Thu Sep 17 15:34:41.184091 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/control-panel/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgjgAAAYE"]
[Thu Sep 17 15:34:41.185164 2026] [security2:error] [pid 18946:tid 19105] [client 34.94.67.131:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgjQAAASc"]
[Thu Sep 17 15:34:41.203548 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/api/v1/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgjwAAAXo"]
[Thu Sep 17 15:34:41.262192 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgcQABD1I"]
[Thu Sep 17 15:34:41.265625 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgcgABD18"]
[Thu Sep 17 15:34:41.283492 2026] [security2:error] [pid 18946:tid 19134] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/temp/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgkgAAAUQ"]
[Thu Sep 17 15:34:41.343043 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgewABD3A"]
[Thu Sep 17 15:34:41.343214 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgfAABDzM"]
[Thu Sep 17 15:34:41.345038 2026] [security2:error] [pid 18946:tid 18987] [remote 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgeAABDyg"]
[Thu Sep 17 15:34:41.346168 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgeQABD2U"]
[Thu Sep 17 15:34:41.346432 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgggABD34"]
[Thu Sep 17 15:34:41.346812 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgegABD08"]
[Thu Sep 17 15:34:41.347037 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgdwABD0A"]
[Thu Sep 17 15:34:41.349835 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8DqiPMah0Tz_U1OgdgABD1E"]
[Thu Sep 17 15:34:41.351493 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OghQABD10"]
[Thu Sep 17 15:34:41.351719 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OggQABD1M"]
[Thu Sep 17 15:34:41.352822 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgigABD1g"]
[Thu Sep 17 15:34:41.353020 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/user-panel/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgkwAAAVg"]
[Thu Sep 17 15:34:41.353477 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgiQABD1k"]
[Thu Sep 17 15:34:41.353868 2026] [security2:error] [pid 18946:tid 19081] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgiwABD2g"]
[Thu Sep 17 15:34:41.360641 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/api/v2/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OglAAAAUM"]
[Thu Sep 17 15:34:41.431318 2026] [security2:error] [pid 18946:tid 19197] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/lab/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OglgAAAYM"]
[Thu Sep 17 15:34:41.458787 2026] [security2:error] [pid 18946:tid 19093] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OglQABG2w"]
[Thu Sep 17 15:34:41.520114 2026] [security2:error] [pid 18946:tid 19131] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/rest/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgpgAAAUE"]
[Thu Sep 17 15:34:41.528744 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.67.131:42622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/info.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgqAAAASE"]
[Thu Sep 17 15:34:41.569583 2026] [security2:error] [pid 18946:tid 19103] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/node/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgqwAAASU"]
[Thu Sep 17 15:34:41.580821 2026] [security2:error] [pid 18946:tid 19142] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/cronlab/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgrAAAAUw"]
[Thu Sep 17 15:34:41.588383 2026] [security2:error] [pid 18946:tid 19060] [remote 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgnwABM3E"]
[Thu Sep 17 15:34:41.591350 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgnAABM3o"]
[Thu Sep 17 15:34:41.655800 2026] [security2:error] [pid 18946:tid 19088] [client 136.158.61.34:289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgrgAAARY"]
[Thu Sep 17 15:34:41.655983 2026] [security2:error] [pid 18946:tid 19088] [client 136.158.61.34:289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgrgAAARY"]
[Thu Sep 17 15:34:41.677082 2026] [security2:error] [pid 18946:tid 19161] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/graphql/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgrwAAAV8"]
[Thu Sep 17 15:34:41.729433 2026] [security2:error] [pid 18946:tid 19092] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/cron/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgsAAAARo"]
[Thu Sep 17 15:34:41.732570 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/express/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgsQAAATs"]
[Thu Sep 17 15:34:41.759438 2026] [security2:error] [pid 18946:tid 19157] [client 34.94.67.131:42636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/php.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgsgAAAVs"]
[Thu Sep 17 15:34:41.762827 2026] [security2:error] [pid 20162:tid 20326] [client 34.166.234.125:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/info.php"] [unique_id "aqxc8a-O_Kk7aqBvaiF97AAAAbA"]
[Thu Sep 17 15:34:41.832922 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/gateway/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgtQAAAU8"]
[Thu Sep 17 15:34:41.863552 2026] [security2:error] [pid 18946:tid 19182] [client 34.94.67.131:42648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/i.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgtwAAAXQ"]
[Thu Sep 17 15:34:41.877421 2026] [security2:error] [pid 18946:tid 19127] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/en/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OguAAAAT0"]
[Thu Sep 17 15:34:41.903917 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/next/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OguQAAAVM"]
[Thu Sep 17 15:34:41.932165 2026] [security2:error] [pid 18946:tid 19089] [client 40.81.232.68:53204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgugAAARc"], referer: binance.com
[Thu Sep 17 15:34:41.998431 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/microservice/.env"] [unique_id "aqxc8TqiPMah0Tz_U1OgvAAAAUA"]
[Thu Sep 17 15:34:42.015133 2026] [security2:error] [pid 20162:tid 20319] [client 69.112.165.154:36526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxc8a-O_Kk7aqBvaiF97gABqU4"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&from=20260818153627&hideliu=1&hideminor=1&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:34:42.045158 2026] [security2:error] [pid 18946:tid 19164] [client 34.94.67.131:42662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxc8jqiPMah0Tz_U1OgvgAAAWI"]
[Thu Sep 17 15:34:42.077240 2026] [security2:error] [pid 18946:tid 19194] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/administrator/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgvQAAAYA"]
[Thu Sep 17 15:34:42.100854 2026] [security2:error] [pid 18946:tid 19189] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/nuxt/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgwgAAAXs"]
[Thu Sep 17 15:34:42.161084 2026] [security2:error] [pid 18946:tid 19135] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/service/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgwwAAAUU"]
[Thu Sep 17 15:34:42.228740 2026] [security2:error] [pid 18946:tid 19132] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/psnlink/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgxAAAAUI"]
[Thu Sep 17 15:34:42.258089 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgmwABM3g"]
[Thu Sep 17 15:34:42.258844 2026] [security2:error] [pid 18946:tid 18961] [remote 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgmQABMw4"]
[Thu Sep 17 15:34:42.261198 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/nest/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgxQAAARA"]
[Thu Sep 17 15:34:42.261953 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OglwABM3M"]
[Thu Sep 17 15:34:42.263957 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgngABM3c"]
[Thu Sep 17 15:34:42.270318 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgmgABMw0"]
[Thu Sep 17 15:34:42.273394 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgowABM30"]
[Thu Sep 17 15:34:42.280747 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgoQABM3s"]
[Thu Sep 17 15:34:42.283106 2026] [security2:error] [pid 18946:tid 19169] [client 34.94.67.131:42666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxc8jqiPMah0Tz_U1OgxgAAAWc"]
[Thu Sep 17 15:34:42.283106 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgpQABM04"]
[Thu Sep 17 15:34:42.285173 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgmAABMxM"]
[Thu Sep 17 15:34:42.289626 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgpAABM2Q"]
[Thu Sep 17 15:34:42.291678 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgnQABM3Y"]
[Thu Sep 17 15:34:42.294371 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgogABMxA"]
[Thu Sep 17 15:34:42.296982 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgoAABM20"]
[Thu Sep 17 15:34:42.324363 2026] [security2:error] [pid 18946:tid 19109] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/api/v3/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgxwAAASs"]
[Thu Sep 17 15:34:42.332647 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgtAABM3U"]
[Thu Sep 17 15:34:42.332944 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgswABMxk"]
[Thu Sep 17 15:34:42.334585 2026] [security2:error] [pid 18946:tid 19117] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8TqiPMah0Tz_U1OgrQABM3w"]
[Thu Sep 17 15:34:42.377071 2026] [security2:error] [pid 18946:tid 19115] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/exapi/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgyAAAATE"]
[Thu Sep 17 15:34:42.424632 2026] [security2:error] [pid 18946:tid 19102] [client 74.7.241.160:60012] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcalendars.seh.yiu.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxc8jqiPMah0Tz_U1OgyQAAASQ"]
[Thu Sep 17 15:34:42.434137 2026] [security2:error] [pid 18946:tid 19178] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/react/.env"] [unique_id "aqxc8jqiPMah0Tz_U1OgywAAAXA"]
[Thu Sep 17 15:34:42.440817 2026] [security2:error] [pid 18946:tid 19077] [client 34.166.234.125:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/php.php"] [unique_id "aqxc8jqiPMah0Tz_U1OgzAAAAQs"]
[Thu Sep 17 15:34:42.464488 2026] [security2:error] [pid 18946:tid 19199] [client 34.94.67.131:42676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/test.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og0wAAAYU"]
[Thu Sep 17 15:34:42.486974 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/api/dev/.env"] [unique_id "aqxc8jqiPMah0Tz_U1Og2AAAAT8"]
[Thu Sep 17 15:34:42.525565 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1OgzQABIgg"]
[Thu Sep 17 15:34:42.526146 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1OgzwABIhc"]
[Thu Sep 17 15:34:42.526233 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1OgzgABIg8"]
[Thu Sep 17 15:34:42.527146 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og0AABIgc"]
[Thu Sep 17 15:34:42.527720 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og0QABIgM"]
[Thu Sep 17 15:34:42.528578 2026] [security2:error] [pid 18946:tid 19148] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/sitemaps/.env"] [unique_id "aqxc8jqiPMah0Tz_U1Og3AAAAVI"]
[Thu Sep 17 15:34:42.537244 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og0gABIhY"]
[Thu Sep 17 15:34:42.553679 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og1AABIgw"]
[Thu Sep 17 15:34:42.553916 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og1gABIn8"]
[Thu Sep 17 15:34:42.555600 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og1QABIko"]
[Thu Sep 17 15:34:42.556593 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og1wABIhU"]
[Thu Sep 17 15:34:42.565801 2026] [security2:error] [pid 18946:tid 18948] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/phpinfo.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og3wABIgE"]
[Thu Sep 17 15:34:42.576887 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og2QABIjQ"]
[Thu Sep 17 15:34:42.579022 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og2gABIhg"]
[Thu Sep 17 15:34:42.579620 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og2wABIgI"]
[Thu Sep 17 15:34:42.632190 2026] [security2:error] [pid 18946:tid 19100] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og4AABIgA"]
[Thu Sep 17 15:34:42.648194 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/api/staging/.env"] [unique_id "aqxc8jqiPMah0Tz_U1Og4QAAAU0"]
[Thu Sep 17 15:34:42.654687 2026] [security2:error] [pid 18946:tid 19007] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/info.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og4gABSDw"]
[Thu Sep 17 15:34:42.659711 2026] [security2:error] [pid 18946:tid 18973] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/infos.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og4wABcho"]
[Thu Sep 17 15:34:42.660282 2026] [security2:error] [pid 18946:tid 18979] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/php_info.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og5AABciA"]
[Thu Sep 17 15:34:42.660477 2026] [security2:error] [pid 18946:tid 18982] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/php.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og5QABciM"]
[Thu Sep 17 15:34:42.660948 2026] [security2:error] [pid 18946:tid 18988] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/php-info.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og5gABbCk"]
[Thu Sep 17 15:34:42.662338 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/vue/.env"] [unique_id "aqxc8jqiPMah0Tz_U1Og5wAAAW0"]
[Thu Sep 17 15:34:42.677984 2026] [security2:error] [pid 18946:tid 19024] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/infophp.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og6gABXU0"]
[Thu Sep 17 15:34:42.705677 2026] [security2:error] [pid 18946:tid 18984] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og7AABXSU"]
[Thu Sep 17 15:34:42.711019 2026] [security2:error] [pid 18946:tid 18967] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og7QABXRQ"]
[Thu Sep 17 15:34:42.731751 2026] [security2:error] [pid 18946:tid 19044] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og7gABXWE"]
[Thu Sep 17 15:34:42.752455 2026] [security2:error] [pid 18946:tid 19159] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og6QABXQU"]
[Thu Sep 17 15:34:42.768074 2026] [security2:error] [pid 18946:tid 18985] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/api/phpinfo.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og8QABcSY"]
[Thu Sep 17 15:34:42.768086 2026] [security2:error] [pid 18946:tid 18983] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/public/phpinfo.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og8AABcSQ"]
[Thu Sep 17 15:34:42.804057 2026] [security2:error] [pid 18946:tid 19184] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/vendor/.env"] [unique_id "aqxc8jqiPMah0Tz_U1Og-QAAAXY"]
[Thu Sep 17 15:34:42.806147 2026] [core:error] [pid 18946:tid 19084] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:42.806169 2026] [core:error] [pid 18946:tid 19084] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:42.813526 2026] [security2:error] [pid 18946:tid 19114] [client 34.32.10.189:56822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og6AAAATA"]
[Thu Sep 17 15:34:42.869521 2026] [security2:error] [pid 18946:tid 19162] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og8gABYFo"]
[Thu Sep 17 15:34:42.872703 2026] [security2:error] [pid 18946:tid 19162] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og9QABYBI"]
[Thu Sep 17 15:34:42.873477 2026] [security2:error] [pid 18946:tid 19162] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og9gABYC0"]
[Thu Sep 17 15:34:42.874702 2026] [security2:error] [pid 18946:tid 19162] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8jqiPMah0Tz_U1Og9wABYBE"]
[Thu Sep 17 15:34:42.886427 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/angular/.env"] [unique_id "aqxc8jqiPMah0Tz_U1Og-wAAAR8"]
[Thu Sep 17 15:34:42.959775 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/lib/.env"] [unique_id "aqxc8jqiPMah0Tz_U1Og_wAAAVA"]
[Thu Sep 17 15:34:42.977072 2026] [security2:error] [pid 20162:tid 20325] [client 34.94.67.131:42692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/p.php"] [unique_id "aqxc8q-O_Kk7aqBvaiF9-AAAAa8"]
[Thu Sep 17 15:34:43.033177 2026] [security2:error] [pid 18946:tid 19002] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/database.sql"] [unique_id "aqxc8zqiPMah0Tz_U1OhAgABTjc"]
[Thu Sep 17 15:34:43.063994 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/svelte/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhCwAAAWQ"]
[Thu Sep 17 15:34:43.122641 2026] [security2:error] [pid 18946:tid 19140] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/resources/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhDQAAAUo"]
[Thu Sep 17 15:34:43.126514 2026] [security2:error] [pid 18946:tid 19200] [client 34.166.234.125:53628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/i.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhDgAAAYY"]
[Thu Sep 17 15:34:43.167837 2026] [security2:error] [pid 18946:tid 19123] [client 34.94.67.131:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhDwAAATk"]
[Thu Sep 17 15:34:43.236737 2026] [security2:error] [pid 18946:tid 19186] [client 34.32.10.189:56822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhDAAAAXg"]
[Thu Sep 17 15:34:43.248643 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/vite/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhEAAAAYE"]
[Thu Sep 17 15:34:43.283215 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/assets/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhEQAAAXo"]
[Thu Sep 17 15:34:43.322027 2026] [security2:error] [pid 18946:tid 19144] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhBwABTiE"]
[Thu Sep 17 15:34:43.322228 2026] [security2:error] [pid 18946:tid 19144] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhBgABTh8"]
[Thu Sep 17 15:34:43.324145 2026] [security2:error] [pid 18946:tid 19144] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhAwABTkM"]
[Thu Sep 17 15:34:43.324823 2026] [security2:error] [pid 18946:tid 19144] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhBAABThw"]
[Thu Sep 17 15:34:43.328523 2026] [security2:error] [pid 18946:tid 19144] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhBQABTjA"]
[Thu Sep 17 15:34:43.383418 2026] [security2:error] [pid 18946:tid 19147] [client 34.94.67.131:42700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhEwAAAVE"]
[Thu Sep 17 15:34:43.384549 2026] [security2:error] [pid 18946:tid 19110] [client 34.32.10.189:56822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/logs/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhEgAAASw"]
[Thu Sep 17 15:34:43.440518 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/uploads/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhFAAAAUQ"]
[Thu Sep 17 15:34:43.473987 2026] [security2:error] [pid 18946:tid 19106] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/backup/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhFQAAASg"]
[Thu Sep 17 15:34:43.598373 2026] [security2:error] [pid 18946:tid 19131] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/internal/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhHQAAAUE"]
[Thu Sep 17 15:34:43.600750 2026] [security2:error] [pid 18946:tid 19133] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhFwABQ3k"]
[Thu Sep 17 15:34:43.604659 2026] [security2:error] [pid 18946:tid 19133] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhFgABQzk"]
[Thu Sep 17 15:34:43.636964 2026] [security2:error] [pid 18946:tid 19103] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/backups/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhHwAAASU"]
[Thu Sep 17 15:34:43.702814 2026] [security2:error] [pid 18946:tid 19099] [client 34.94.67.131:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhIAAAASE"]
[Thu Sep 17 15:34:43.773076 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/tools/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhIQAAAYQ"]
[Thu Sep 17 15:34:43.804830 2026] [security2:error] [pid 18946:tid 19093] [client 34.166.234.125:53638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhIgAAARs"]
[Thu Sep 17 15:34:43.819228 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/old/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhIwAAARo"]
[Thu Sep 17 15:34:43.839152 2026] [security2:error] [pid 20162:tid 20368] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/cache/.env"] [unique_id "aqxc86-O_Kk7aqBvaiF9_wAAAdo"]
[Thu Sep 17 15:34:43.927678 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhJwABO0U"]
[Thu Sep 17 15:34:43.927873 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhJgABOzg"]
[Thu Sep 17 15:34:43.927930 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhKQABOyw"]
[Thu Sep 17 15:34:43.928884 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhLAABO0w"]
[Thu Sep 17 15:34:43.930423 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhKwABO0g"]
[Thu Sep 17 15:34:43.930593 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhJAABOyo"]
[Thu Sep 17 15:34:43.930697 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhKgABOzo"]
[Thu Sep 17 15:34:43.934270 2026] [security2:error] [pid 18946:tid 19165] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/scripts/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhLQAAAWM"]
[Thu Sep 17 15:34:43.936315 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhJQABO0I"]
[Thu Sep 17 15:34:43.936540 2026] [security2:error] [pid 18946:tid 19125] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhKAABOx4"]
[Thu Sep 17 15:34:43.976113 2026] [security2:error] [pid 18946:tid 19157] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/tmp/.env"] [unique_id "aqxc8zqiPMah0Tz_U1OhLgAAAVs"]
[Thu Sep 17 15:34:43.987529 2026] [security2:error] [pid 18946:tid 19177] [client 34.94.67.131:42720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxc8zqiPMah0Tz_U1OhLwAAAW8"]
[Thu Sep 17 15:34:43.990471 2026] [security2:error] [pid 20162:tid 20309] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mailer/.env"] [unique_id "aqxc86-O_Kk7aqBvaiF-AAAAAZ8"]
[Thu Sep 17 15:34:44.064089 2026] [security2:error] [pid 18946:tid 19015] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/site.sql"] [unique_id "aqxc9DqiPMah0Tz_U1OhNAABI0Q"]
[Thu Sep 17 15:34:44.065017 2026] [security2:error] [pid 18946:tid 19020] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/2022/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhNwABI0k"]
[Thu Sep 17 15:34:44.065776 2026] [security2:error] [pid 18946:tid 19033] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/config.properties.bak"] [unique_id "aqxc9DqiPMah0Tz_U1OhOwABI1Y"]
[Thu Sep 17 15:34:44.065929 2026] [security2:error] [pid 18946:tid 19054] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/wp-config.php.backup"] [unique_id "aqxc9DqiPMah0Tz_U1OhPAABI2s"]
[Thu Sep 17 15:34:44.071161 2026] [security2:error] [pid 18946:tid 19022] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/shop/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhPgABI0s"]
[Thu Sep 17 15:34:44.091655 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/bin/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhQAAAAUA"]
[Thu Sep 17 15:34:44.123921 2026] [security2:error] [pid 18946:tid 19149] [client 34.94.67.131:42726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhQgAAAVM"]
[Thu Sep 17 15:34:44.139500 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/temp/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhQwAAAYk"]
[Thu Sep 17 15:34:44.140553 2026] [security2:error] [pid 20162:tid 20333] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mail/.env"] [unique_id "aqxc9K-O_Kk7aqBvaiF-AgAAAbc"]
[Thu Sep 17 15:34:44.141858 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhOQABIz4"]
[Thu Sep 17 15:34:44.141979 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhOgABI3Q"]
[Thu Sep 17 15:34:44.142172 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhOAABI2o"]
[Thu Sep 17 15:34:44.142385 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhPwABI3I"]
[Thu Sep 17 15:34:44.142888 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhNQABI0E"]
[Thu Sep 17 15:34:44.143007 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhMwABIzI"]
[Thu Sep 17 15:34:44.143281 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhMgABIzY"]
[Thu Sep 17 15:34:44.143724 2026] [security2:error] [pid 18946:tid 19101] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhPQABIz0"]
[Thu Sep 17 15:34:44.186489 2026] [core:error] [pid 20162:tid 20415] [client 74.7.175.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:44.186508 2026] [core:error] [pid 20162:tid 20415] [client 74.7.175.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:44.186652 2026] [security2:error] [pid 20162:tid 20415] [client 74.7.175.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "aqxc9K-O_Kk7aqBvaiF-BQAAAgk"]
[Thu Sep 17 15:34:44.188987 2026] [security2:error] [pid 20162:tid 20370] [client 74.7.175.152:33858] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.srm.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxc9K-O_Kk7aqBvaiF-AwAB3Fg"]
[Thu Sep 17 15:34:44.248200 2026] [security2:error] [pid 18946:tid 19135] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/sbin/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhTAAAAUU"]
[Thu Sep 17 15:34:44.257158 2026] [security2:error] [pid 20162:tid 20350] [client 34.166.190.195:48020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxc9K-O_Kk7aqBvaiF-BgAAAcg"]
[Thu Sep 17 15:34:44.283034 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhRgABWmA"]
[Thu Sep 17 15:34:44.283230 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhRwABWlc"]
[Thu Sep 17 15:34:44.283694 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhRAABWmY"]
[Thu Sep 17 15:34:44.283820 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhSAABWis"]
[Thu Sep 17 15:34:44.283966 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhSgABWmc"]
[Thu Sep 17 15:34:44.284562 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhRQABWj8"]
[Thu Sep 17 15:34:44.284796 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhSQABWlQ"]
[Thu Sep 17 15:34:44.292126 2026] [security2:error] [pid 20162:tid 20295] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/email/.env"] [unique_id "aqxc9K-O_Kk7aqBvaiF-BwAAAZE"]
[Thu Sep 17 15:34:44.294603 2026] [security2:error] [pid 18946:tid 19156] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhSwABWi4"]
[Thu Sep 17 15:34:44.315526 2026] [security2:error] [pid 18946:tid 19113] [client 34.94.67.131:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhTwAAAS8"]
[Thu Sep 17 15:34:44.317357 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/lab/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhUAAAAX0"]
[Thu Sep 17 15:34:44.350432 2026] [security2:error] [pid 18946:tid 19006] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/app_dev.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhVAABJjs"]
[Thu Sep 17 15:34:44.351501 2026] [security2:error] [pid 18946:tid 19018] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/2020/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhVgABJkc"]
[Thu Sep 17 15:34:44.351861 2026] [security2:error] [pid 18946:tid 19058] [remote 34.38.113.44:35424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/.env.local.orig"] [unique_id "aqxc9DqiPMah0Tz_U1OhUgABJm8"]
[Thu Sep 17 15:34:44.376844 2026] [security2:error] [pid 18946:tid 19089] [client 79.116.89.151:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhVwAAARc"]
[Thu Sep 17 15:34:44.377069 2026] [security2:error] [pid 18946:tid 19089] [client 79.116.89.151:52231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhVwAAARc"]
[Thu Sep 17 15:34:44.407144 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/local/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhWAAAARA"]
[Thu Sep 17 15:34:44.422195 2026] [security2:error] [pid 18946:tid 19104] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhUwABJmM"]
[Thu Sep 17 15:34:44.422354 2026] [security2:error] [pid 18946:tid 19104] [client 34.38.113.44:35424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swlfv1.sweetlifelowermills.com"] [uri "/index.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhVQABJi8"]
[Thu Sep 17 15:34:44.443277 2026] [security2:error] [pid 20162:tid 20296] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/smtp/.env"] [unique_id "aqxc9K-O_Kk7aqBvaiF-CQAAAZI"]
[Thu Sep 17 15:34:44.483581 2026] [security2:error] [pid 18946:tid 19090] [client 34.166.234.125:43200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhWQAAARg"]
[Thu Sep 17 15:34:44.499638 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/cronlab/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhWgAAASk"]
[Thu Sep 17 15:34:44.563643 2026] [security2:error] [pid 18946:tid 19178] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/portal/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhWwAAAXA"]
[Thu Sep 17 15:34:44.595867 2026] [security2:error] [pid 20162:tid 20331] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mailing/.env"] [unique_id "aqxc9K-O_Kk7aqBvaiF-CgAAAbU"]
[Thu Sep 17 15:34:44.623765 2026] [security2:error] [pid 18946:tid 19080] [client 34.94.67.131:42746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhagAAAQ4"]
[Thu Sep 17 15:34:44.676069 2026] [security2:error] [pid 18946:tid 19174] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/cron/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhdAAAAWw"]
[Thu Sep 17 15:34:44.719265 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/dashboard/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhdQAAAV0"]
[Thu Sep 17 15:34:44.746228 2026] [security2:error] [pid 20162:tid 20382] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/notifications/.env"] [unique_id "aqxc9K-O_Kk7aqBvaiF-CwAAAeg"]
[Thu Sep 17 15:34:44.850179 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/en/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OheQAAARw"]
[Thu Sep 17 15:34:44.876953 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/panel/.env"] [unique_id "aqxc9DqiPMah0Tz_U1OhewAAATA"]
[Thu Sep 17 15:34:44.897076 2026] [security2:error] [pid 20162:tid 20315] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/notify/.env"] [unique_id "aqxc9K-O_Kk7aqBvaiF-DAAAAaU"]
[Thu Sep 17 15:34:44.934760 2026] [security2:error] [pid 18946:tid 19169] [client 143.105.152.240:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhfAAAAWc"]
[Thu Sep 17 15:34:44.938146 2026] [security2:error] [pid 18946:tid 19169] [client 143.105.152.240:50904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhfAAAAWc"]
[Thu Sep 17 15:34:44.945705 2026] [core:error] [pid 18946:tid 19119] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:44.945721 2026] [core:error] [pid 18946:tid 19119] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:44.950710 2026] [security2:error] [pid 18946:tid 19126] [client 34.166.190.195:51080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/info.php"] [unique_id "aqxc9DqiPMah0Tz_U1OhfgAAATw"]
[Thu Sep 17 15:34:45.032632 2026] [security2:error] [pid 18946:tid 19155] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/crm/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhfwAAAVk"]
[Thu Sep 17 15:34:45.047764 2026] [security2:error] [pid 20162:tid 20383] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/sender/.env"] [unique_id "aqxc9a-O_Kk7aqBvaiF-DQAAAek"]
[Thu Sep 17 15:34:45.137917 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/administrator/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhgAAAARQ"]
[Thu Sep 17 15:34:45.160917 2026] [security2:error] [pid 18946:tid 19140] [client 34.94.67.131:42776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxc9TqiPMah0Tz_U1OhhQAAAUo"]
[Thu Sep 17 15:34:45.169716 2026] [security2:error] [pid 18946:tid 19153] [client 34.166.234.125:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/test.php"] [unique_id "aqxc9TqiPMah0Tz_U1OhhgAAAVc"]
[Thu Sep 17 15:34:45.192454 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/erp/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhiQAAATg"]
[Thu Sep 17 15:34:45.199398 2026] [security2:error] [pid 20162:tid 20416] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/campaign/.env"] [unique_id "aqxc9a-O_Kk7aqBvaiF-DwAAAgo"]
[Thu Sep 17 15:34:45.332860 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/psnlink/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhkgAAAUQ"]
[Thu Sep 17 15:34:45.347587 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/shop/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhlAAAATc"]
[Thu Sep 17 15:34:45.350305 2026] [security2:error] [pid 20162:tid 20361] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/newsletter/.env"] [unique_id "aqxc9a-O_Kk7aqBvaiF-EgAAAdM"]
[Thu Sep 17 15:34:45.443053 2026] [security2:error] [pid 18946:tid 19103] [client 34.94.67.131:42788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxc9TqiPMah0Tz_U1OhmwAAASU"]
[Thu Sep 17 15:34:45.502393 2026] [security2:error] [pid 20162:tid 20356] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/ses/.env"] [unique_id "aqxc9a-O_Kk7aqBvaiF-EwAAAc4"]
[Thu Sep 17 15:34:45.503763 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/store/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhngAAARs"]
[Thu Sep 17 15:34:45.524788 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/exapi/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhnwAAARo"]
[Thu Sep 17 15:34:45.604924 2026] [autoindex:error] [pid 18946:tid 19087] [client 216.245.140.84:0] AH01276: Cannot serve directory /home2/relvnvco/public_html/realtybyjohnson/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:34:45.644170 2026] [security2:error] [pid 18946:tid 19099] [client 34.166.190.195:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/php.php"] [unique_id "aqxc9TqiPMah0Tz_U1OhqAAAASE"]
[Thu Sep 17 15:34:45.653226 2026] [security2:error] [pid 20162:tid 20413] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/sendgrid/.env"] [unique_id "aqxc9a-O_Kk7aqBvaiF-FQAAAgc"]
[Thu Sep 17 15:34:45.659330 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/saas/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhqQAAAQ0"]
[Thu Sep 17 15:34:45.681863 2026] [security2:error] [pid 20162:tid 20376] [client 34.94.67.131:42792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxc9a-O_Kk7aqBvaiF-FwAAAeI"]
[Thu Sep 17 15:34:45.716908 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.45.51:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/sitemaps/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhqgAAAYk"]
[Thu Sep 17 15:34:45.809524 2026] [security2:error] [pid 20162:tid 20311] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/sparkpost/.env"] [unique_id "aqxc9a-O_Kk7aqBvaiF-GAAAAaE"]
[Thu Sep 17 15:34:45.819969 2026] [security2:error] [pid 18946:tid 19164] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/client/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhqwAAAWI"]
[Thu Sep 17 15:34:45.828679 2026] [security2:error] [pid 18946:tid 19135] [client 34.94.67.131:42794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxc9TqiPMah0Tz_U1OhrAAAAUU"]
[Thu Sep 17 15:34:45.965262 2026] [security2:error] [pid 20162:tid 20401] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/postmark/.env"] [unique_id "aqxc9a-O_Kk7aqBvaiF-GwAAAfs"]
[Thu Sep 17 15:34:45.984508 2026] [security2:error] [pid 18946:tid 19115] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/project/.env"] [unique_id "aqxc9TqiPMah0Tz_U1OhtwAAATE"]
[Thu Sep 17 15:34:45.988755 2026] [core:error] [pid 18946:tid 19109] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:45.988769 2026] [core:error] [pid 18946:tid 19109] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:46.034136 2026] [security2:error] [pid 18946:tid 19201] [client 34.94.67.131:42796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxc9jqiPMah0Tz_U1OhvgAAAYc"]
[Thu Sep 17 15:34:46.118825 2026] [security2:error] [pid 20162:tid 20341] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mailgun/.env"] [unique_id "aqxc9q-O_Kk7aqBvaiF-HQAAAb8"]
[Thu Sep 17 15:34:46.143609 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/admin-panel/.env"] [unique_id "aqxc9jqiPMah0Tz_U1OhwQAAAUg"]
[Thu Sep 17 15:34:46.194125 2026] [security2:error] [pid 18946:tid 19180] [client 34.94.67.131:42802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxc9jqiPMah0Tz_U1OhwwAAAXI"]
[Thu Sep 17 15:34:46.269989 2026] [security2:error] [pid 20162:tid 20352] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mandrill/.env"] [unique_id "aqxc9q-O_Kk7aqBvaiF-HgAAAco"]
[Thu Sep 17 15:34:46.300760 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/control-panel/.env"] [unique_id "aqxc9jqiPMah0Tz_U1OhxAAAAS4"]
[Thu Sep 17 15:34:46.341847 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.190.195:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/i.php"] [unique_id "aqxc9jqiPMah0Tz_U1OhxQAAAU0"]
[Thu Sep 17 15:34:46.420982 2026] [security2:error] [pid 20162:tid 20320] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mailjet/.env"] [unique_id "aqxc9q-O_Kk7aqBvaiF-IAAAAao"]
[Thu Sep 17 15:34:46.439852 2026] [security2:error] [pid 18946:tid 19178] [client 40.77.167.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "breathingboxing.com"] [uri "/index.php"] [unique_id "aqxc9jqiPMah0Tz_U1OhvwAAAXA"]
[Thu Sep 17 15:34:46.462781 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/user-panel/.env"] [unique_id "aqxc9jqiPMah0Tz_U1OhywAAATU"]
[Thu Sep 17 15:34:46.475979 2026] [core:error] [pid 18946:tid 19083] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:46.475998 2026] [core:error] [pid 18946:tid 19083] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:46.575862 2026] [security2:error] [pid 20162:tid 20343] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/brevo/.env"] [unique_id "aqxc9q-O_Kk7aqBvaiF-IgAAAcE"]
[Thu Sep 17 15:34:46.619734 2026] [security2:error] [pid 20162:tid 20310] [client 74.7.228.42:34190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.rickanddonnaproctor.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxc9q-O_Kk7aqBvaiF-IwAAAaA"]
[Thu Sep 17 15:34:46.624766 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/node/.env"] [unique_id "aqxc9jqiPMah0Tz_U1Oh0AAAAVc"]
[Thu Sep 17 15:34:46.705259 2026] [security2:error] [pid 18946:tid 19126] [client 34.166.234.125:43224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/p.php"] [unique_id "aqxc9jqiPMah0Tz_U1Oh0gAAATw"]
[Thu Sep 17 15:34:46.727553 2026] [security2:error] [pid 20162:tid 20337] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/transactional/.env"] [unique_id "aqxc9q-O_Kk7aqBvaiF-KQAAAbs"]
[Thu Sep 17 15:34:46.764496 2026] [core:error] [pid 18946:tid 19186] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:46.764511 2026] [core:error] [pid 18946:tid 19186] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:46.788472 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/express/.env"] [unique_id "aqxc9jqiPMah0Tz_U1Oh1AAAAXo"]
[Thu Sep 17 15:34:46.887878 2026] [security2:error] [pid 20162:tid 20323] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/bulk/.env"] [unique_id "aqxc9q-O_Kk7aqBvaiF-KgAAAa0"]
[Thu Sep 17 15:34:46.947021 2026] [security2:error] [pid 18946:tid 19110] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/next/.env"] [unique_id "aqxc9jqiPMah0Tz_U1Oh1QAAASw"]
[Thu Sep 17 15:34:47.039351 2026] [security2:error] [pid 18946:tid 19137] [client 138.246.253.24:46946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.interactive.tengushee.com"] [uri "/index.php"] [unique_id "aqxc9zqiPMah0Tz_U1Oh2gAAAUc"]
[Thu Sep 17 15:34:47.046358 2026] [security2:error] [pid 20162:tid 20363] [client 34.166.190.195:51118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxc96-O_Kk7aqBvaiF-KwAAAdU"]
[Thu Sep 17 15:34:47.048092 2026] [security2:error] [pid 20162:tid 20362] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/aws/.env"] [unique_id "aqxc96-O_Kk7aqBvaiF-LAAAAdQ"]
[Thu Sep 17 15:34:47.107362 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/nuxt/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh2wAAAVg"]
[Thu Sep 17 15:34:47.116960 2026] [security2:error] [pid 18946:tid 19134] [client 34.94.67.131:42826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxc9zqiPMah0Tz_U1Oh3AAAAUQ"]
[Thu Sep 17 15:34:47.205925 2026] [security2:error] [pid 20162:tid 20321] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/azure/.env"] [unique_id "aqxc96-O_Kk7aqBvaiF-LgAAAas"]
[Thu Sep 17 15:34:47.273816 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/nest/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh3QAAAUM"]
[Thu Sep 17 15:34:47.279101 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/logs/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh3gAAATc"]
[Thu Sep 17 15:34:47.308569 2026] [security2:error] [pid 20162:tid 20318] [client 34.94.67.131:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxc96-O_Kk7aqBvaiF-LwAAAag"]
[Thu Sep 17 15:34:47.363083 2026] [security2:error] [pid 20162:tid 20357] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/gcp/.env"] [unique_id "aqxc96-O_Kk7aqBvaiF-MAAAAc8"]
[Thu Sep 17 15:34:47.403894 2026] [security2:error] [pid 20162:tid 20334] [client 34.166.234.125:43226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxc96-O_Kk7aqBvaiF-MQAAAbg"]
[Thu Sep 17 15:34:47.429411 2026] [security2:error] [pid 20162:tid 20400] [client 34.94.67.131:42842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxc96-O_Kk7aqBvaiF-MgAAAfo"]
[Thu Sep 17 15:34:47.435025 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/react/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh3wAAAYQ"]
[Thu Sep 17 15:34:47.448428 2026] [security2:error] [pid 18946:tid 19142] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/cache/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh4AAAAUw"]
[Thu Sep 17 15:34:47.515566 2026] [security2:error] [pid 20162:tid 20402] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/cloud/.env"] [unique_id "aqxc96-O_Kk7aqBvaiF-MwAAAfw"]
[Thu Sep 17 15:34:47.595588 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/vue/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh5AAAARs"]
[Thu Sep 17 15:34:47.654571 2026] [security2:error] [pid 18946:tid 19161] [client 34.94.67.131:42854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxc9zqiPMah0Tz_U1Oh5wAAAV8"]
[Thu Sep 17 15:34:47.654624 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mailer/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh5gAAARo"]
[Thu Sep 17 15:34:47.671538 2026] [security2:error] [pid 20162:tid 20397] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/infrastructure/.env"] [unique_id "aqxc96-O_Kk7aqBvaiF-NAAAAfc"]
[Thu Sep 17 15:34:47.743106 2026] [security2:error] [pid 20162:tid 20365] [client 34.166.190.195:51122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxc96-O_Kk7aqBvaiF-NQAAAdc"]
[Thu Sep 17 15:34:47.756201 2026] [security2:error] [pid 18946:tid 19157] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/angular/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh6AAAAVs"]
[Thu Sep 17 15:34:47.793605 2026] [security2:error] [pid 18946:tid 19177] [client 34.94.67.131:42860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxc9zqiPMah0Tz_U1Oh6QAAAW8"]
[Thu Sep 17 15:34:47.828255 2026] [security2:error] [pid 20162:tid 20378] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/docker/.env"] [unique_id "aqxc96-O_Kk7aqBvaiF-NgAAAeQ"]
[Thu Sep 17 15:34:47.845969 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mail/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh6gAAATY"]
[Thu Sep 17 15:34:47.918020 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/svelte/.env"] [unique_id "aqxc9zqiPMah0Tz_U1Oh6wAAAUs"]
[Thu Sep 17 15:34:47.957208 2026] [security2:error] [pid 18946:tid 19197] [client 34.94.67.131:42866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxc9zqiPMah0Tz_U1Oh7AAAAYM"]
[Thu Sep 17 15:34:47.983787 2026] [security2:error] [pid 20162:tid 20344] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/k8s/.env"] [unique_id "aqxc96-O_Kk7aqBvaiF-NwAAAcI"]
[Thu Sep 17 15:34:48.033136 2026] [security2:error] [pid 18946:tid 19099] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/email/.env"] [unique_id "aqxc-DqiPMah0Tz_U1Oh7gAAASE"]
[Thu Sep 17 15:34:48.073606 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/vite/.env"] [unique_id "aqxc-DqiPMah0Tz_U1Oh8QAAAYk"]
[Thu Sep 17 15:34:48.081689 2026] [security2:error] [pid 18946:tid 19151] [client 34.166.234.125:43238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxc-DqiPMah0Tz_U1Oh8gAAAVU"]
[Thu Sep 17 15:34:48.132908 2026] [security2:error] [pid 18946:tid 19101] [client 34.94.67.131:42880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxc-DqiPMah0Tz_U1Oh9QAAASM"]
[Thu Sep 17 15:34:48.137123 2026] [security2:error] [pid 20162:tid 20384] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/kubernetes/.env"] [unique_id "aqxc-K-O_Kk7aqBvaiF-OgAAAeo"]
[Thu Sep 17 15:34:48.210558 2026] [security2:error] [pid 18946:tid 19135] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/smtp/.env"] [unique_id "aqxc-DqiPMah0Tz_U1Oh9gAAAUU"]
[Thu Sep 17 15:34:48.232188 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/backup/.env"] [unique_id "aqxc-DqiPMah0Tz_U1Oh9wAAAUI"]
[Thu Sep 17 15:34:48.288628 2026] [security2:error] [pid 20162:tid 20306] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/terraform/.env"] [unique_id "aqxc-K-O_Kk7aqBvaiF-OwAAAZw"]
[Thu Sep 17 15:34:48.317103 2026] [security2:error] [pid 18946:tid 19191] [client 34.94.67.131:42892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxc-DqiPMah0Tz_U1Oh-AAAAX0"]
[Thu Sep 17 15:34:48.364695 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mailing/.env"] [unique_id "aqxc-DqiPMah0Tz_U1Oh-QAAARc"]
[Thu Sep 17 15:34:48.396011 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/backups/.env"] [unique_id "aqxc-DqiPMah0Tz_U1Oh-gAAASk"]
[Thu Sep 17 15:34:48.423644 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.190.195:51138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/test.php"] [unique_id "aqxc-DqiPMah0Tz_U1Oh_AAAAWI"]
[Thu Sep 17 15:34:48.438701 2026] [security2:error] [pid 20162:tid 20330] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/ansible/.env"] [unique_id "aqxc-K-O_Kk7aqBvaiF-PwAAAbQ"]
[Thu Sep 17 15:34:48.490579 2026] [security2:error] [pid 20162:tid 20303] [client 20.24.86.237:57504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxc-K-O_Kk7aqBvaiF-QAAAAZk"]
[Thu Sep 17 15:34:48.490677 2026] [security2:error] [pid 20162:tid 20303] [client 20.24.86.237:57504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxc-K-O_Kk7aqBvaiF-QAAAAZk"]
[Thu Sep 17 15:34:48.527426 2026] [security2:error] [pid 18946:tid 19167] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/notifications/.env"] [unique_id "aqxc-DqiPMah0Tz_U1Oh_gAAAWU"]
[Thu Sep 17 15:34:48.530952 2026] [security2:error] [pid 18946:tid 19139] [client 34.94.67.131:42900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxc-DqiPMah0Tz_U1Oh_wAAAUk"]
[Thu Sep 17 15:34:48.551283 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/old/.env"] [unique_id "aqxc-DqiPMah0Tz_U1OiAgAAAYc"]
[Thu Sep 17 15:34:48.573569 2026] [security2:error] [pid 18946:tid 19185] [client 114.198.138.124:65136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiBAAAAXc"]
[Thu Sep 17 15:34:48.573686 2026] [security2:error] [pid 18946:tid 19185] [client 114.198.138.124:65136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiBAAAAXc"]
[Thu Sep 17 15:34:48.589375 2026] [security2:error] [pid 20162:tid 20345] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/.git/.env"] [unique_id "aqxc-K-O_Kk7aqBvaiF-QQAAAcM"]
[Thu Sep 17 15:34:48.710781 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/tmp/.env"] [unique_id "aqxc-DqiPMah0Tz_U1OiBgAAAW0"]
[Thu Sep 17 15:34:48.714337 2026] [security2:error] [pid 20162:tid 20301] [client 34.94.67.131:42902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxc-K-O_Kk7aqBvaiF-QgAAAZc"]
[Thu Sep 17 15:34:48.716919 2026] [security2:error] [pid 18946:tid 19098] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/notify/.env"] [unique_id "aqxc-DqiPMah0Tz_U1OiBwAAASA"]
[Thu Sep 17 15:34:48.739996 2026] [security2:error] [pid 20162:tid 20339] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/ci/.env"] [unique_id "aqxc-K-O_Kk7aqBvaiF-QwAAAb0"]
[Thu Sep 17 15:34:48.801008 2026] [security2:error] [pid 18946:tid 19102] [client 14.96.156.146:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiCAAAASQ"]
[Thu Sep 17 15:34:48.801113 2026] [security2:error] [pid 18946:tid 19102] [client 14.96.156.146:59120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiCAAAASQ"]
[Thu Sep 17 15:34:48.823428 2026] [security2:error] [pid 20162:tid 20391] [client 20.24.86.237:57496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxc-K-O_Kk7aqBvaiF-RAAAAfE"]
[Thu Sep 17 15:34:48.823524 2026] [security2:error] [pid 20162:tid 20391] [client 20.24.86.237:57496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxc-K-O_Kk7aqBvaiF-RAAAAfE"]
[Thu Sep 17 15:34:48.847839 2026] [security2:error] [pid 18946:tid 19138] [client 34.166.234.125:43250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiCQAAAUg"]
[Thu Sep 17 15:34:48.861977 2026] [security2:error] [pid 20162:tid 20394] [client 34.94.67.131:42904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxc-K-O_Kk7aqBvaiF-RQAAAfQ"]
[Thu Sep 17 15:34:48.869695 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/temp/.env"] [unique_id "aqxc-DqiPMah0Tz_U1OiCwAAAT8"]
[Thu Sep 17 15:34:48.873672 2026] [security2:error] [pid 18946:tid 19163] [client 103.61.184.148:54685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiDAAAAWE"]
[Thu Sep 17 15:34:48.873755 2026] [security2:error] [pid 18946:tid 19163] [client 103.61.184.148:54685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiDAAAAWE"]
[Thu Sep 17 15:34:48.885487 2026] [security2:error] [pid 18946:tid 19179] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/sender/.env"] [unique_id "aqxc-DqiPMah0Tz_U1OiDQAAAXE"]
[Thu Sep 17 15:34:48.893872 2026] [security2:error] [pid 20162:tid 20419] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/cd/.env"] [unique_id "aqxc-K-O_Kk7aqBvaiF-RgAAAg0"]
[Thu Sep 17 15:34:48.964757 2026] [security2:error] [pid 18946:tid 19202] [client 34.94.67.131:42906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxc-DqiPMah0Tz_U1OiDgAAAYg"]
[Thu Sep 17 15:34:49.028419 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/lab/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiEAAAAWc"]
[Thu Sep 17 15:34:49.048627 2026] [security2:error] [pid 20162:tid 20355] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/jenkins/.env"] [unique_id "aqxc-a-O_Kk7aqBvaiF-RwAAAc0"]
[Thu Sep 17 15:34:49.066047 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/campaign/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiEQAAATA"]
[Thu Sep 17 15:34:49.120303 2026] [security2:error] [pid 18946:tid 19083] [client 34.94.67.131:42910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiFAAAARE"]
[Thu Sep 17 15:34:49.141091 2026] [security2:error] [pid 18946:tid 19097] [client 20.24.86.237:57437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger0.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiFwAAAR8"]
[Thu Sep 17 15:34:49.141174 2026] [security2:error] [pid 18946:tid 19097] [client 20.24.86.237:57437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger0.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiFwAAAR8"]
[Thu Sep 17 15:34:49.192860 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/cronlab/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiGAAAAVA"]
[Thu Sep 17 15:34:49.207744 2026] [security2:error] [pid 20162:tid 20389] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/gitlab/.env"] [unique_id "aqxc-a-O_Kk7aqBvaiF-SAAAAe8"]
[Thu Sep 17 15:34:49.232997 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/newsletter/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiGQAAARQ"]
[Thu Sep 17 15:34:49.242222 2026] [security2:error] [pid 18946:tid 19155] [client 34.94.67.131:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiGgAAAVk"]
[Thu Sep 17 15:34:49.347635 2026] [security2:error] [pid 18946:tid 19153] [client 34.166.190.195:42782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/p.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiHAAAAVc"]
[Thu Sep 17 15:34:49.351115 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/cron/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiHQAAATw"]
[Thu Sep 17 15:34:49.360647 2026] [security2:error] [pid 20162:tid 20312] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/github/.env"] [unique_id "aqxc-a-O_Kk7aqBvaiF-SQAAAaI"]
[Thu Sep 17 15:34:49.366876 2026] [security2:error] [pid 18946:tid 19150] [client 34.94.67.131:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiHgAAAVQ"]
[Thu Sep 17 15:34:49.396609 2026] [security2:error] [pid 18946:tid 19140] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/ses/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiHwAAAUo"]
[Thu Sep 17 15:34:49.474235 2026] [security2:error] [pid 18946:tid 19195] [client 20.24.86.237:57483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/01.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiIAAAAYE"]
[Thu Sep 17 15:34:49.474305 2026] [security2:error] [pid 18946:tid 19195] [client 20.24.86.237:57483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/01.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiIAAAAYE"]
[Thu Sep 17 15:34:49.503204 2026] [security2:error] [pid 18946:tid 19186] [client 34.94.67.131:42944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiIQAAAXg"]
[Thu Sep 17 15:34:49.508882 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/en/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiIgAAASc"]
[Thu Sep 17 15:34:49.513247 2026] [security2:error] [pid 20162:tid 20411] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/actions/.env"] [unique_id "aqxc-a-O_Kk7aqBvaiF-SgAAAgU"]
[Thu Sep 17 15:34:49.535197 2026] [security2:error] [pid 20162:tid 20347] [client 34.166.234.125:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxc-a-O_Kk7aqBvaiF-SwAAAcU"]
[Thu Sep 17 15:34:49.568952 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/sendgrid/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiIwAAAR4"]
[Thu Sep 17 15:34:49.639898 2026] [security2:error] [pid 18946:tid 19110] [client 34.94.67.131:42958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiJgAAASw"]
[Thu Sep 17 15:34:49.666069 2026] [security2:error] [pid 20162:tid 20297] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/circleci/.env"] [unique_id "aqxc-a-O_Kk7aqBvaiF-TAAAAZM"]
[Thu Sep 17 15:34:49.716857 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/administrator/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiKAAAAUM"]
[Thu Sep 17 15:34:49.789250 2026] [security2:error] [pid 20162:tid 20359] [client 34.94.67.131:44280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxc-a-O_Kk7aqBvaiF-TQAAAdE"]
[Thu Sep 17 15:34:49.802254 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/sparkpost/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiKgAAAWQ"]
[Thu Sep 17 15:34:49.812464 2026] [security2:error] [pid 20162:tid 20368] [client 20.24.86.237:57487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-xmlgal.php"] [unique_id "aqxc-a-O_Kk7aqBvaiF-TgAAAdo"]
[Thu Sep 17 15:34:49.812552 2026] [security2:error] [pid 20162:tid 20368] [client 20.24.86.237:57487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-xmlgal.php"] [unique_id "aqxc-a-O_Kk7aqBvaiF-TgAAAdo"]
[Thu Sep 17 15:34:49.829207 2026] [security2:error] [pid 20162:tid 20309] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/travis/.env"] [unique_id "aqxc-a-O_Kk7aqBvaiF-TwAAAZ8"]
[Thu Sep 17 15:34:49.874508 2026] [security2:error] [pid 18946:tid 19103] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/psnlink/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiKwAAASU"]
[Thu Sep 17 15:34:49.959605 2026] [security2:error] [pid 18946:tid 19142] [client 34.94.67.131:44296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxc-TqiPMah0Tz_U1OiLQAAAUw"]
[Thu Sep 17 15:34:49.979869 2026] [security2:error] [pid 20162:tid 20333] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/buildkite/.env"] [unique_id "aqxc-a-O_Kk7aqBvaiF-UAAAAbc"]
[Thu Sep 17 15:34:49.993052 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/postmark/.env"] [unique_id "aqxc-TqiPMah0Tz_U1OiLgAAARo"]
[Thu Sep 17 15:34:50.032089 2026] [security2:error] [pid 18946:tid 19077] [client 34.166.190.195:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiLwAAAQs"]
[Thu Sep 17 15:34:50.041320 2026] [security2:error] [pid 18946:tid 19165] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/exapi/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiMAAAAWM"]
[Thu Sep 17 15:34:50.067211 2026] [security2:error] [pid 18946:tid 19125] [client 40.81.232.68:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiMQAAATs"], referer: binance.com
[Thu Sep 17 15:34:50.130373 2026] [security2:error] [pid 20162:tid 20381] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mysql/.env"] [unique_id "aqxc-q-O_Kk7aqBvaiF-UQAAAec"]
[Thu Sep 17 15:34:50.133234 2026] [security2:error] [pid 20162:tid 20415] [client 34.94.67.131:44310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxc-q-O_Kk7aqBvaiF-UgAAAgk"]
[Thu Sep 17 15:34:50.155653 2026] [security2:error] [pid 18946:tid 19087] [client 20.24.86.237:57474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/yich.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiNgAAARU"]
[Thu Sep 17 15:34:50.155743 2026] [security2:error] [pid 18946:tid 19087] [client 20.24.86.237:57474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/yich.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiNgAAARU"]
[Thu Sep 17 15:34:50.199481 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mailgun/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiOAAAATY"]
[Thu Sep 17 15:34:50.205805 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/sitemaps/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiOQAAAU8"]
[Thu Sep 17 15:34:50.220265 2026] [security2:error] [pid 18946:tid 19093] [client 34.166.234.125:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiOgAAARs"]
[Thu Sep 17 15:34:50.282497 2026] [security2:error] [pid 20162:tid 20370] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/postgres/.env"] [unique_id "aqxc-q-O_Kk7aqBvaiF-VAAAAdw"]
[Thu Sep 17 15:34:50.323388 2026] [security2:error] [pid 18946:tid 19160] [client 34.94.67.131:44314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiPAAAAV4"]
[Thu Sep 17 15:34:50.393866 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mandrill/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiQAAAAUI"]
[Thu Sep 17 15:34:50.434342 2026] [security2:error] [pid 20162:tid 20350] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/mongodb/.env"] [unique_id "aqxc-q-O_Kk7aqBvaiF-VQAAAcg"]
[Thu Sep 17 15:34:50.471935 2026] [security2:error] [pid 18946:tid 19194] [client 34.94.67.131:44326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiQQAAAYA"]
[Thu Sep 17 15:34:50.500530 2026] [security2:error] [pid 18946:tid 19149] [client 20.24.86.237:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-blink.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiQgAAAVM"]
[Thu Sep 17 15:34:50.500602 2026] [security2:error] [pid 18946:tid 19149] [client 20.24.86.237:57430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-blink.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiQgAAAVM"]
[Thu Sep 17 15:34:50.561673 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mailjet/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiQwAAAX0"]
[Thu Sep 17 15:34:50.584243 2026] [security2:error] [pid 20162:tid 20295] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/redis/.env"] [unique_id "aqxc-q-O_Kk7aqBvaiF-VgAAAZE"]
[Thu Sep 17 15:34:50.617422 2026] [security2:error] [pid 18946:tid 19164] [client 34.94.67.131:44340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiRwAAAWI"]
[Thu Sep 17 15:34:50.655608 2026] [security2:error] [pid 18946:tid 19197] [client 177.44.133.72:63430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiTQAAAYM"]
[Thu Sep 17 15:34:50.655715 2026] [security2:error] [pid 18946:tid 19197] [client 177.44.133.72:63430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiTQAAAYM"]
[Thu Sep 17 15:34:50.707774 2026] [security2:error] [pid 18946:tid 19027] [remote 45.157.54.43:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop-me.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiTwABPVA"]
[Thu Sep 17 15:34:50.707985 2026] [security2:error] [pid 18946:tid 19127] [client 45.157.54.43:61426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop-me.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiTwABPVA"]
[Thu Sep 17 15:34:50.723472 2026] [security2:error] [pid 18946:tid 19102] [client 34.94.67.131:44350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiUAAAASQ"]
[Thu Sep 17 15:34:50.734073 2026] [security2:error] [pid 18946:tid 19182] [client 34.166.190.195:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiUQAAAXQ"]
[Thu Sep 17 15:34:50.734447 2026] [security2:error] [pid 20162:tid 20340] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/elasticsearch/.env"] [unique_id "aqxc-q-O_Kk7aqBvaiF-VwAAAb4"]
[Thu Sep 17 15:34:50.759943 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/brevo/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiUgAAAYg"]
[Thu Sep 17 15:34:50.763464 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.219.37:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/logs/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiUwAAAS4"]
[Thu Sep 17 15:34:50.830451 2026] [security2:error] [pid 20162:tid 20294] [client 20.24.86.237:57514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-logis.php"] [unique_id "aqxc-q-O_Kk7aqBvaiF-WAAAAZA"]
[Thu Sep 17 15:34:50.830551 2026] [security2:error] [pid 20162:tid 20294] [client 20.24.86.237:57514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-logis.php"] [unique_id "aqxc-q-O_Kk7aqBvaiF-WAAAAZA"]
[Thu Sep 17 15:34:50.864820 2026] [security2:error] [pid 18946:tid 18996] [remote 45.157.54.43:61626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop-me.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiVAABLTE"]
[Thu Sep 17 15:34:50.864939 2026] [security2:error] [pid 18946:tid 19111] [client 45.157.54.43:61626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop-me.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiVAABLTE"]
[Thu Sep 17 15:34:50.885200 2026] [security2:error] [pid 20162:tid 20322] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/rabbitmq/.env"] [unique_id "aqxc-q-O_Kk7aqBvaiF-WQAAAaw"]
[Thu Sep 17 15:34:50.902355 2026] [security2:error] [pid 20162:tid 20296] [client 34.94.67.131:44364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.67.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.srm.drf.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxc-q-O_Kk7aqBvaiF-WgAAAZI"]
[Thu Sep 17 15:34:50.919223 2026] [security2:error] [pid 18946:tid 19180] [client 34.166.234.125:43278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxc-jqiPMah0Tz_U1OiVQAAAXI"]
[Thu Sep 17 15:34:50.920256 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/transactional/.env"] [unique_id "aqxc-jqiPMah0Tz_U1OiVgAAAV0"]
[Thu Sep 17 15:34:51.040740 2026] [security2:error] [pid 20162:tid 20315] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/kafka/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-WwAAAaU"]
[Thu Sep 17 15:34:51.136962 2026] [security2:error] [pid 18946:tid 19155] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/bulk/.env"] [unique_id "aqxc-zqiPMah0Tz_U1OiXwAAAVk"]
[Thu Sep 17 15:34:51.168750 2026] [security2:error] [pid 18946:tid 19150] [client 20.24.86.237:57527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wsxedc.php"] [unique_id "aqxc-zqiPMah0Tz_U1OiYQAAAVQ"]
[Thu Sep 17 15:34:51.168831 2026] [security2:error] [pid 18946:tid 19150] [client 20.24.86.237:57527] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wsxedc.php"] [unique_id "aqxc-zqiPMah0Tz_U1OiYQAAAVQ"]
[Thu Sep 17 15:34:51.194201 2026] [security2:error] [pid 20162:tid 20364] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/queue/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-XwAAAdY"]
[Thu Sep 17 15:34:51.260305 2026] [security2:error] [pid 20162:tid 20383] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/cache/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-YAAAAek"]
[Thu Sep 17 15:34:51.308248 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/aws/.env"] [unique_id "aqxc-zqiPMah0Tz_U1OiZQAAAXM"]
[Thu Sep 17 15:34:51.343508 2026] [security2:error] [pid 20162:tid 20361] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/worker/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-YQAAAdM"]
[Thu Sep 17 15:34:51.422692 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mailer/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-YwAAAc4"]
[Thu Sep 17 15:34:51.431312 2026] [security2:error] [pid 20162:tid 20404] [client 34.166.190.195:42804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxc-6-O_Kk7aqBvaiF-ZAAAAf4"]
[Thu Sep 17 15:34:51.482925 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/azure/.env"] [unique_id "aqxc-zqiPMah0Tz_U1OiagAAAR4"]
[Thu Sep 17 15:34:51.495911 2026] [security2:error] [pid 20162:tid 20372] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/job/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-ZQAAAd4"]
[Thu Sep 17 15:34:51.497383 2026] [security2:error] [pid 18946:tid 19137] [client 20.24.86.237:57512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/idolet.php"] [unique_id "aqxc-zqiPMah0Tz_U1OibgAAAUc"]
[Thu Sep 17 15:34:51.497450 2026] [security2:error] [pid 18946:tid 19137] [client 20.24.86.237:57512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/idolet.php"] [unique_id "aqxc-zqiPMah0Tz_U1OibgAAAUc"]
[Thu Sep 17 15:34:51.594859 2026] [security2:error] [pid 20162:tid 20413] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mail/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-ZgAAAgc"]
[Thu Sep 17 15:34:51.601434 2026] [security2:error] [pid 18946:tid 19084] [client 34.166.234.125:43290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxc-zqiPMah0Tz_U1OicQAAARI"]
[Thu Sep 17 15:34:51.647114 2026] [security2:error] [pid 18946:tid 19131] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/gcp/.env"] [unique_id "aqxc-zqiPMah0Tz_U1OicwAAAUE"]
[Thu Sep 17 15:34:51.648274 2026] [security2:error] [pid 20162:tid 20311] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/test/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-ZwAAAaE"]
[Thu Sep 17 15:34:51.754298 2026] [security2:error] [pid 20162:tid 20377] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/email/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-bAAAAeM"]
[Thu Sep 17 15:34:51.767247 2026] [core:error] [pid 18946:tid 19085] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:51.768445 2026] [core:error] [pid 18946:tid 19085] [client 34.94.67.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:51.799430 2026] [security2:error] [pid 20162:tid 20374] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/qa/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-bgAAAeA"]
[Thu Sep 17 15:34:51.853217 2026] [security2:error] [pid 18946:tid 19161] [client 20.24.86.237:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/weem.php"] [unique_id "aqxc-zqiPMah0Tz_U1OieQAAAV8"]
[Thu Sep 17 15:34:51.853350 2026] [security2:error] [pid 18946:tid 19161] [client 20.24.86.237:57510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/weem.php"] [unique_id "aqxc-zqiPMah0Tz_U1OieQAAAV8"]
[Thu Sep 17 15:34:51.854705 2026] [security2:error] [pid 18946:tid 19077] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/cloud/.env"] [unique_id "aqxc-zqiPMah0Tz_U1OiegAAAQs"]
[Thu Sep 17 15:34:51.912540 2026] [security2:error] [pid 20162:tid 20408] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/smtp/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-bwAAAgI"]
[Thu Sep 17 15:34:51.927934 2026] [security2:error] [pid 18946:tid 19002] [remote 45.157.54.43:62966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-zqiPMah0Tz_U1OifAABNzc"]
[Thu Sep 17 15:34:51.928066 2026] [security2:error] [pid 18946:tid 19121] [client 45.157.54.43:62966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop.com"] [uri "/xmlrpc.php"] [unique_id "aqxc-zqiPMah0Tz_U1OifAABNzc"]
[Thu Sep 17 15:34:51.951261 2026] [security2:error] [pid 20162:tid 20308] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/preview/.env"] [unique_id "aqxc-6-O_Kk7aqBvaiF-cAAAAZ4"]
[Thu Sep 17 15:34:52.021861 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/infrastructure/.env"] [unique_id "aqxc_DqiPMah0Tz_U1OifQAAAUY"]
[Thu Sep 17 15:34:52.060111 2026] [core:error] [pid 20162:tid 20300] [client 138.68.136.141:34442] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.060136 2026] [core:error] [pid 20162:tid 20300] [client 138.68.136.141:34442] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.073406 2026] [security2:error] [pid 20162:tid 20310] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mailing/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-cgAAAaA"]
[Thu Sep 17 15:34:52.102103 2026] [security2:error] [pid 20162:tid 20317] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/beta/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-cwAAAac"]
[Thu Sep 17 15:34:52.128949 2026] [security2:error] [pid 18946:tid 19145] [client 34.166.190.195:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxc_DqiPMah0Tz_U1OifwAAAU8"]
[Thu Sep 17 15:34:52.191158 2026] [security2:error] [pid 18946:tid 19152] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/docker/.env"] [unique_id "aqxc_DqiPMah0Tz_U1OihAAAAVY"]
[Thu Sep 17 15:34:52.199942 2026] [security2:error] [pid 20162:tid 20386] [client 20.24.86.237:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/vitellose.php"] [unique_id "aqxc_K-O_Kk7aqBvaiF-dAAAAew"]
[Thu Sep 17 15:34:52.200053 2026] [security2:error] [pid 20162:tid 20386] [client 20.24.86.237:57412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/vitellose.php"] [unique_id "aqxc_K-O_Kk7aqBvaiF-dAAAAew"]
[Thu Sep 17 15:34:52.219463 2026] [security2:error] [pid 18946:tid 19000] [remote 45.157.54.43:63009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_DqiPMah0Tz_U1OihQABZDU"]
[Thu Sep 17 15:34:52.219635 2026] [security2:error] [pid 18946:tid 19166] [client 45.157.54.43:63009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_DqiPMah0Tz_U1OihQABZDU"]
[Thu Sep 17 15:34:52.239172 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/notifications/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-dQAAAbs"]
[Thu Sep 17 15:34:52.262229 2026] [security2:error] [pid 20162:tid 20298] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/uat/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-dgAAAZQ"]
[Thu Sep 17 15:34:52.361003 2026] [core:error] [pid 18946:tid 19194] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.361022 2026] [core:error] [pid 18946:tid 19194] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.399640 2026] [security2:error] [pid 20162:tid 20358] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/notify/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-eAAAAdA"]
[Thu Sep 17 15:34:52.421531 2026] [security2:error] [pid 20162:tid 20403] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/stage/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-eQAAAf0"]
[Thu Sep 17 15:34:52.432179 2026] [security2:error] [pid 18946:tid 19117] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/k8s/.env"] [unique_id "aqxc_DqiPMah0Tz_U1OiigAAATM"]
[Thu Sep 17 15:34:52.502649 2026] [security2:error] [pid 18946:tid 19126] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxc-zqiPMah0Tz_U1OiYgAAATw"]
[Thu Sep 17 15:34:52.556313 2026] [security2:error] [pid 20162:tid 20362] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/sender/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-fAAAAdQ"]
[Thu Sep 17 15:34:52.572098 2026] [core:error] [pid 20162:tid 20321] [client 138.68.136.141:34448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.572120 2026] [core:error] [pid 20162:tid 20321] [client 138.68.136.141:34448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.575839 2026] [security2:error] [pid 20162:tid 20367] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/development/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-fgAAAdk"]
[Thu Sep 17 15:34:52.580010 2026] [security2:error] [pid 20162:tid 20293] [client 20.24.86.237:57518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/carcassed.php"] [unique_id "aqxc_K-O_Kk7aqBvaiF-fwAAAY8"]
[Thu Sep 17 15:34:52.580086 2026] [security2:error] [pid 20162:tid 20293] [client 20.24.86.237:57518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/carcassed.php"] [unique_id "aqxc_K-O_Kk7aqBvaiF-fwAAAY8"]
[Thu Sep 17 15:34:52.600235 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/kubernetes/.env"] [unique_id "aqxc_DqiPMah0Tz_U1OiiwAAAWE"]
[Thu Sep 17 15:34:52.711812 2026] [security2:error] [pid 20162:tid 20334] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/campaign/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-ggAAAbg"]
[Thu Sep 17 15:34:52.731571 2026] [security2:error] [pid 20162:tid 20380] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/production/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-gwAAAeY"]
[Thu Sep 17 15:34:52.772525 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/terraform/.env"] [unique_id "aqxc_DqiPMah0Tz_U1OikwAAAU0"]
[Thu Sep 17 15:34:52.807437 2026] [security2:error] [pid 18946:tid 19112] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxc_DqiPMah0Tz_U1OikAAAAS4"]
[Thu Sep 17 15:34:52.814293 2026] [security2:error] [pid 20162:tid 20336] [client 34.166.190.195:42820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxc_K-O_Kk7aqBvaiF-hQAAAbo"]
[Thu Sep 17 15:34:52.869978 2026] [security2:error] [pid 20162:tid 20365] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/newsletter/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-hgAAAdc"]
[Thu Sep 17 15:34:52.883477 2026] [security2:error] [pid 20162:tid 20378] [client 34.32.10.189:52336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.snowhillstokes.org"] [uri "/config/app/.env"] [unique_id "aqxc_K-O_Kk7aqBvaiF-hwAAAeQ"]
[Thu Sep 17 15:34:52.908035 2026] [core:error] [pid 20162:tid 20319] [client 138.68.136.141:34452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.908049 2026] [core:error] [pid 20162:tid 20319] [client 138.68.136.141:34452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:52.911972 2026] [security2:error] [pid 18946:tid 19178] [client 20.24.86.237:57519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/esc.php"] [unique_id "aqxc_DqiPMah0Tz_U1OilwAAAXA"]
[Thu Sep 17 15:34:52.912040 2026] [security2:error] [pid 18946:tid 19178] [client 20.24.86.237:57519] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/esc.php"] [unique_id "aqxc_DqiPMah0Tz_U1OilwAAAXA"]
[Thu Sep 17 15:34:52.944014 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/ansible/.env"] [unique_id "aqxc_DqiPMah0Tz_U1OimAAAAQw"]
[Thu Sep 17 15:34:53.032221 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/ses/.env"] [unique_id "aqxc_a-O_Kk7aqBvaiF-iQAAAaM"]
[Thu Sep 17 15:34:53.055308 2026] [security2:error] [pid 20162:tid 20306] [client 34.32.10.189:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/phpinfo.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-igAAAZw"]
[Thu Sep 17 15:34:53.064697 2026] [security2:error] [pid 18946:tid 19094] [client 34.166.234.125:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxc_TqiPMah0Tz_U1OimQAAARw"]
[Thu Sep 17 15:34:53.113604 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/.git/.env"] [unique_id "aqxc_TqiPMah0Tz_U1OimgAAAW4"]
[Thu Sep 17 15:34:53.195856 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/sendgrid/.env"] [unique_id "aqxc_a-O_Kk7aqBvaiF-iwAAAZk"]
[Thu Sep 17 15:34:53.215209 2026] [core:error] [pid 20162:tid 20407] [client 138.68.136.141:34468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:53.215223 2026] [core:error] [pid 20162:tid 20407] [client 138.68.136.141:34468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:53.252406 2026] [security2:error] [pid 18946:tid 19083] [client 20.24.86.237:57503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger2.php"] [unique_id "aqxc_TqiPMah0Tz_U1OinQAAARE"]
[Thu Sep 17 15:34:53.252497 2026] [security2:error] [pid 18946:tid 19083] [client 20.24.86.237:57503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger2.php"] [unique_id "aqxc_TqiPMah0Tz_U1OinQAAARE"]
[Thu Sep 17 15:34:53.271781 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/ci/.env"] [unique_id "aqxc_TqiPMah0Tz_U1OingAAAR8"]
[Thu Sep 17 15:34:53.360515 2026] [security2:error] [pid 20162:tid 20301] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/sparkpost/.env"] [unique_id "aqxc_a-O_Kk7aqBvaiF-jQAAAZc"]
[Thu Sep 17 15:34:53.439997 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/cd/.env"] [unique_id "aqxc_TqiPMah0Tz_U1OioAAAAXw"]
[Thu Sep 17 15:34:53.512400 2026] [security2:error] [pid 20162:tid 20385] [client 34.166.190.195:42822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-jgAAAes"]
[Thu Sep 17 15:34:53.526474 2026] [security2:error] [pid 18946:tid 19113] [client 34.32.10.189:45292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/info.php"] [unique_id "aqxc_TqiPMah0Tz_U1OiowAAAS8"]
[Thu Sep 17 15:34:53.530443 2026] [security2:error] [pid 20162:tid 20391] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/postmark/.env"] [unique_id "aqxc_a-O_Kk7aqBvaiF-jwAAAfE"]
[Thu Sep 17 15:34:53.535132 2026] [core:error] [pid 20162:tid 20419] [client 138.68.136.141:34478] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:53.535146 2026] [core:error] [pid 20162:tid 20419] [client 138.68.136.141:34478] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:53.605560 2026] [security2:error] [pid 20162:tid 20375] [client 20.24.86.237:57485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger3.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-kgAAAeE"]
[Thu Sep 17 15:34:53.605674 2026] [security2:error] [pid 20162:tid 20375] [client 20.24.86.237:57485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger3.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-kgAAAeE"]
[Thu Sep 17 15:34:53.661438 2026] [security2:error] [pid 18946:tid 19187] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/jenkins/.env"] [unique_id "aqxc_TqiPMah0Tz_U1OipAAAAXk"]
[Thu Sep 17 15:34:53.676831 2026] [security2:error] [pid 20162:tid 20351] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-kQAAAck"]
[Thu Sep 17 15:34:53.692351 2026] [security2:error] [pid 20162:tid 20325] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mailgun/.env"] [unique_id "aqxc_a-O_Kk7aqBvaiF-kwAAAa8"]
[Thu Sep 17 15:34:53.765379 2026] [security2:error] [pid 20162:tid 20394] [client 34.166.234.125:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-lAAAAfQ"]
[Thu Sep 17 15:34:53.828753 2026] [core:error] [pid 20162:tid 20355] [client 138.68.136.141:34486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:53.828769 2026] [core:error] [pid 20162:tid 20355] [client 138.68.136.141:34486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:53.852072 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/gitlab/.env"] [unique_id "aqxc_TqiPMah0Tz_U1OipwAAASc"]
[Thu Sep 17 15:34:53.856368 2026] [security2:error] [pid 20162:tid 20389] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mandrill/.env"] [unique_id "aqxc_a-O_Kk7aqBvaiF-lgAAAe8"]
[Thu Sep 17 15:34:53.953700 2026] [security2:error] [pid 20162:tid 20420] [client 20.24.86.237:57501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger4.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-lwAAAg4"]
[Thu Sep 17 15:34:53.953802 2026] [security2:error] [pid 20162:tid 20420] [client 20.24.86.237:57501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger4.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-lwAAAg4"]
[Thu Sep 17 15:34:53.990253 2026] [security2:error] [pid 20162:tid 20342] [client 34.32.10.189:45300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/php.php"] [unique_id "aqxc_a-O_Kk7aqBvaiF-mAAAAcA"]
[Thu Sep 17 15:34:54.016148 2026] [security2:error] [pid 18946:tid 19084] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/github/.env"] [unique_id "aqxc_jqiPMah0Tz_U1OiqAAAARI"]
[Thu Sep 17 15:34:54.017114 2026] [security2:error] [pid 20162:tid 20312] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mailjet/.env"] [unique_id "aqxc_q-O_Kk7aqBvaiF-mQAAAaI"]
[Thu Sep 17 15:34:54.180159 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/brevo/.env"] [unique_id "aqxc_q-O_Kk7aqBvaiF-nAAAAZs"]
[Thu Sep 17 15:34:54.206782 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/actions/.env"] [unique_id "aqxc_jqiPMah0Tz_U1OiqwAAARM"]
[Thu Sep 17 15:34:54.212119 2026] [security2:error] [pid 20162:tid 20395] [client 34.166.190.195:42834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxc_q-O_Kk7aqBvaiF-nQAAAfU"]
[Thu Sep 17 15:34:54.354528 2026] [security2:error] [pid 20162:tid 20415] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/transactional/.env"] [unique_id "aqxc_q-O_Kk7aqBvaiF-ngAAAgk"]
[Thu Sep 17 15:34:54.382387 2026] [security2:error] [pid 20162:tid 20360] [client 20.24.86.237:57488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger5.php"] [unique_id "aqxc_q-O_Kk7aqBvaiF-nwAAAdI"]
[Thu Sep 17 15:34:54.382452 2026] [security2:error] [pid 20162:tid 20360] [client 20.24.86.237:57488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger5.php"] [unique_id "aqxc_q-O_Kk7aqBvaiF-nwAAAdI"]
[Thu Sep 17 15:34:54.404840 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/circleci/.env"] [unique_id "aqxc_jqiPMah0Tz_U1OirAAAAQ8"]
[Thu Sep 17 15:34:54.414515 2026] [security2:error] [pid 18946:tid 19016] [remote 45.157.54.43:64869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop.me"] [uri "/xmlrpc.php"] [unique_id "aqxc_jqiPMah0Tz_U1OirgABY0U"]
[Thu Sep 17 15:34:54.414633 2026] [security2:error] [pid 18946:tid 19165] [client 45.157.54.43:64869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop.me"] [uri "/xmlrpc.php"] [unique_id "aqxc_jqiPMah0Tz_U1OirgABY0U"]
[Thu Sep 17 15:34:54.441996 2026] [security2:error] [pid 18946:tid 19162] [client 34.32.10.189:45308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/i.php"] [unique_id "aqxc_jqiPMah0Tz_U1OisQAAAWA"]
[Thu Sep 17 15:34:54.455415 2026] [security2:error] [pid 18946:tid 19134] [client 34.166.234.125:54730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxc_jqiPMah0Tz_U1OisgAAAUQ"]
[Thu Sep 17 15:34:54.513625 2026] [security2:error] [pid 20162:tid 20316] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/bulk/.env"] [unique_id "aqxc_q-O_Kk7aqBvaiF-oQAAAaY"]
[Thu Sep 17 15:34:54.521325 2026] [security2:error] [pid 18946:tid 19077] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxc_jqiPMah0Tz_U1OirQAAAQs"]
[Thu Sep 17 15:34:54.610203 2026] [security2:error] [pid 18946:tid 19196] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/travis/.env"] [unique_id "aqxc_jqiPMah0Tz_U1OitAAAAYI"]
[Thu Sep 17 15:34:54.670768 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/aws/.env"] [unique_id "aqxc_q-O_Kk7aqBvaiF-owAAAZA"]
[Thu Sep 17 15:34:54.676589 2026] [security2:error] [pid 18946:tid 19023] [remote 45.157.54.43:65078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop.me"] [uri "/xmlrpc.php"] [unique_id "aqxc_jqiPMah0Tz_U1OitQABGUw"]
[Thu Sep 17 15:34:54.676725 2026] [security2:error] [pid 18946:tid 19091] [client 45.157.54.43:65078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop.me"] [uri "/xmlrpc.php"] [unique_id "aqxc_jqiPMah0Tz_U1OitQABGUw"]
[Thu Sep 17 15:34:54.705207 2026] [security2:error] [pid 20162:tid 20379] [client 20.24.86.237:57420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger6.php"] [unique_id "aqxc_q-O_Kk7aqBvaiF-pAAAAeU"]
[Thu Sep 17 15:34:54.705275 2026] [security2:error] [pid 20162:tid 20379] [client 20.24.86.237:57420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger6.php"] [unique_id "aqxc_q-O_Kk7aqBvaiF-pAAAAeU"]
[Thu Sep 17 15:34:54.768098 2026] [security2:error] [pid 18946:tid 19192] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/buildkite/.env"] [unique_id "aqxc_jqiPMah0Tz_U1OitwAAAX4"]
[Thu Sep 17 15:34:54.828301 2026] [security2:error] [pid 20162:tid 20322] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/azure/.env"] [unique_id "aqxc_q-O_Kk7aqBvaiF-pQAAAaw"]
[Thu Sep 17 15:34:54.854450 2026] [security2:error] [pid 20162:tid 20350] [client 136.158.61.34:1662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_q-O_Kk7aqBvaiF-pgAAAcg"]
[Thu Sep 17 15:34:54.854766 2026] [security2:error] [pid 20162:tid 20350] [client 136.158.61.34:1662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_q-O_Kk7aqBvaiF-pgAAAcg"]
[Thu Sep 17 15:34:54.893800 2026] [security2:error] [pid 18946:tid 19166] [client 34.32.10.189:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/pi.php"] [unique_id "aqxc_jqiPMah0Tz_U1OiugAAAWQ"]
[Thu Sep 17 15:34:54.943997 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mysql/.env"] [unique_id "aqxc_jqiPMah0Tz_U1OivQAAAYk"]
[Thu Sep 17 15:34:54.984426 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/gcp/.env"] [unique_id "aqxc_q-O_Kk7aqBvaiF-qAAAAgg"]
[Thu Sep 17 15:34:55.023240 2026] [security2:error] [pid 20162:tid 20315] [client 20.24.86.237:57486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger7.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-qQAAAaU"]
[Thu Sep 17 15:34:55.023339 2026] [security2:error] [pid 20162:tid 20315] [client 20.24.86.237:57486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger7.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-qQAAAaU"]
[Thu Sep 17 15:34:55.118231 2026] [security2:error] [pid 20162:tid 20369] [client 79.116.89.151:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-qgAAAds"]
[Thu Sep 17 15:34:55.118345 2026] [security2:error] [pid 20162:tid 20369] [client 79.116.89.151:52850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-qgAAAds"]
[Thu Sep 17 15:34:55.124680 2026] [security2:error] [pid 18946:tid 19164] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/postgres/.env"] [unique_id "aqxc_zqiPMah0Tz_U1OiwwAAAWI"]
[Thu Sep 17 15:34:55.136364 2026] [security2:error] [pid 18946:tid 19151] [client 34.166.234.125:54732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxc_zqiPMah0Tz_U1OixAAAAVU"]
[Thu Sep 17 15:34:55.137693 2026] [security2:error] [pid 18946:tid 19156] [client 34.166.190.195:42850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxc_zqiPMah0Tz_U1OixgAAAVo"]
[Thu Sep 17 15:34:55.146631 2026] [security2:error] [pid 20162:tid 20364] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/cloud/.env"] [unique_id "aqxc_6-O_Kk7aqBvaiF-rAAAAdY"]
[Thu Sep 17 15:34:55.183403 2026] [security2:error] [pid 18946:tid 19128] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxc_zqiPMah0Tz_U1OivwAAAT4"]
[Thu Sep 17 15:34:55.210435 2026] [security2:error] [pid 20162:tid 20387] [client 43.157.180.116:46662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.180.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "daprayer.com"] [uri "/wp-login.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-qwAAAe0"]
[Thu Sep 17 15:34:55.304582 2026] [security2:error] [pid 18946:tid 19157] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/mongodb/.env"] [unique_id "aqxc_zqiPMah0Tz_U1OizAAAAVs"]
[Thu Sep 17 15:34:55.307278 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/infrastructure/.env"] [unique_id "aqxc_6-O_Kk7aqBvaiF-rgAAAc4"]
[Thu Sep 17 15:34:55.341456 2026] [security2:error] [pid 18946:tid 19171] [client 143.105.152.240:22718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc_zqiPMah0Tz_U1OizQAAAWk"]
[Thu Sep 17 15:34:55.344894 2026] [security2:error] [pid 20162:tid 20390] [client 34.32.10.189:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/pinfo.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-rwAAAfA"]
[Thu Sep 17 15:34:55.345209 2026] [security2:error] [pid 18946:tid 19171] [client 143.105.152.240:22718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxc_zqiPMah0Tz_U1OizQAAAWk"]
[Thu Sep 17 15:34:55.355997 2026] [security2:error] [pid 20162:tid 20349] [client 20.24.86.237:57426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger8.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-sAAAAcc"]
[Thu Sep 17 15:34:55.356070 2026] [security2:error] [pid 20162:tid 20349] [client 20.24.86.237:57426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger8.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-sAAAAcc"]
[Thu Sep 17 15:34:55.362811 2026] [security2:error] [pid 18946:tid 19163] [client 185.139.153.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kcooke1.com"] [uri "/index.php"] [unique_id "aqxc_zqiPMah0Tz_U1OiywAAAWE"], referer: http://kcooke1.com/llms.txt
[Thu Sep 17 15:34:55.468929 2026] [security2:error] [pid 20162:tid 20413] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/docker/.env"] [unique_id "aqxc_6-O_Kk7aqBvaiF-sQAAAgc"]
[Thu Sep 17 15:34:55.481438 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/redis/.env"] [unique_id "aqxc_zqiPMah0Tz_U1OizgAAAS4"]
[Thu Sep 17 15:34:55.627883 2026] [security2:error] [pid 20162:tid 20259] [remote 45.157.54.43:12215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-sgAB_l8"]
[Thu Sep 17 15:34:55.628008 2026] [security2:error] [pid 20162:tid 20404] [client 45.157.54.43:12215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-sgAB_l8"]
[Thu Sep 17 15:34:55.639721 2026] [security2:error] [pid 20162:tid 20401] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/k8s/.env"] [unique_id "aqxc_6-O_Kk7aqBvaiF-swAAAfs"]
[Thu Sep 17 15:34:55.641113 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/elasticsearch/.env"] [unique_id "aqxc_zqiPMah0Tz_U1Oi0QAAAXQ"]
[Thu Sep 17 15:34:55.709870 2026] [security2:error] [pid 20162:tid 20377] [client 20.24.86.237:57534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger9.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-tAAAAeM"]
[Thu Sep 17 15:34:55.709937 2026] [security2:error] [pid 20162:tid 20377] [client 20.24.86.237:57534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger9.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-tAAAAeM"]
[Thu Sep 17 15:34:55.771500 2026] [security2:error] [pid 18946:tid 19094] [client 40.81.232.68:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxc_zqiPMah0Tz_U1Oi1wAAARw"], referer: binance.com
[Thu Sep 17 15:34:55.800867 2026] [security2:error] [pid 18946:tid 19102] [client 34.32.10.189:45334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/test.php"] [unique_id "aqxc_zqiPMah0Tz_U1Oi2AAAASQ"]
[Thu Sep 17 15:34:55.801734 2026] [security2:error] [pid 20162:tid 20299] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/kubernetes/.env"] [unique_id "aqxc_6-O_Kk7aqBvaiF-tQAAAZU"]
[Thu Sep 17 15:34:55.829383 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/rabbitmq/.env"] [unique_id "aqxc_zqiPMah0Tz_U1Oi2QAAATU"]
[Thu Sep 17 15:34:55.832112 2026] [security2:error] [pid 18946:tid 19199] [client 34.166.234.125:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxc_zqiPMah0Tz_U1Oi2gAAAYU"]
[Thu Sep 17 15:34:55.839280 2026] [security2:error] [pid 20162:tid 20327] [client 34.166.190.195:42858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxc_6-O_Kk7aqBvaiF-twAAAbE"]
[Thu Sep 17 15:34:55.964796 2026] [security2:error] [pid 20162:tid 20308] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/terraform/.env"] [unique_id "aqxc_6-O_Kk7aqBvaiF-uQAAAZ4"]
[Thu Sep 17 15:34:56.046431 2026] [security2:error] [pid 18946:tid 19090] [client 20.24.86.237:57417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger10.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi3QAAARg"]
[Thu Sep 17 15:34:56.046522 2026] [security2:error] [pid 18946:tid 19090] [client 20.24.86.237:57417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger10.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi3QAAARg"]
[Thu Sep 17 15:34:56.054213 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/kafka/.env"] [unique_id "aqxdADqiPMah0Tz_U1Oi3wAAAS8"]
[Thu Sep 17 15:34:56.120291 2026] [security2:error] [pid 20162:tid 20300] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/ansible/.env"] [unique_id "aqxdAK-O_Kk7aqBvaiF-ugAAAZY"]
[Thu Sep 17 15:34:56.277102 2026] [security2:error] [pid 18946:tid 19150] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/queue/.env"] [unique_id "aqxdADqiPMah0Tz_U1Oi5QAAAVQ"]
[Thu Sep 17 15:34:56.283638 2026] [security2:error] [pid 20162:tid 20317] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/.git/.env"] [unique_id "aqxdAK-O_Kk7aqBvaiF-uwAAAac"]
[Thu Sep 17 15:34:56.390518 2026] [security2:error] [pid 18946:tid 19098] [client 20.24.86.237:57495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger11.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi5wAAASA"]
[Thu Sep 17 15:34:56.390624 2026] [security2:error] [pid 18946:tid 19098] [client 20.24.86.237:57495] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger11.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi5wAAASA"]
[Thu Sep 17 15:34:56.391299 2026] [security2:error] [pid 18946:tid 19122] [client 34.32.10.189:45346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi5AAAATg"]
[Thu Sep 17 15:34:56.442729 2026] [security2:error] [pid 20162:tid 20392] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/ci/.env"] [unique_id "aqxdAK-O_Kk7aqBvaiF-vAAAAfI"]
[Thu Sep 17 15:34:56.444866 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/worker/.env"] [unique_id "aqxdADqiPMah0Tz_U1Oi6QAAAVw"]
[Thu Sep 17 15:34:56.527436 2026] [security2:error] [pid 20162:tid 20366] [client 34.166.234.125:54760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxdAK-O_Kk7aqBvaiF-vQAAAdg"]
[Thu Sep 17 15:34:56.532118 2026] [security2:error] [pid 20162:tid 20386] [client 34.166.190.195:42864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxdAK-O_Kk7aqBvaiF-vgAAAew"]
[Thu Sep 17 15:34:56.608753 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/cd/.env"] [unique_id "aqxdAK-O_Kk7aqBvaiF-vwAAAbs"]
[Thu Sep 17 15:34:56.624881 2026] [security2:error] [pid 18946:tid 19088] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/job/.env"] [unique_id "aqxdADqiPMah0Tz_U1Oi6wAAARY"]
[Thu Sep 17 15:34:56.694117 2026] [security2:error] [pid 18946:tid 19172] [client 34.32.10.189:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/p.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi7wAAAWo"]
[Thu Sep 17 15:34:56.727332 2026] [security2:error] [pid 18946:tid 19165] [client 20.24.86.237:57477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger12.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi8gAAAWM"]
[Thu Sep 17 15:34:56.727409 2026] [security2:error] [pid 18946:tid 19165] [client 20.24.86.237:57477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-filemannger12.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi8gAAAWM"]
[Thu Sep 17 15:34:56.783430 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/jenkins/.env"] [unique_id "aqxdAK-O_Kk7aqBvaiF-wQAAAfY"]
[Thu Sep 17 15:34:56.818968 2026] [security2:error] [pid 18946:tid 19077] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/test/.env"] [unique_id "aqxdADqiPMah0Tz_U1Oi9AAAAQs"]
[Thu Sep 17 15:34:56.933370 2026] [security2:error] [pid 18946:tid 19087] [client 45.162.138.172:39548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdADqiPMah0Tz_U1Oi8wABFWs"]
[Thu Sep 17 15:34:56.938014 2026] [security2:error] [pid 20162:tid 20321] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/gitlab/.env"] [unique_id "aqxdAK-O_Kk7aqBvaiF-wwAAAas"]
[Thu Sep 17 15:34:56.978181 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/qa/.env"] [unique_id "aqxdADqiPMah0Tz_U1Oi9gAAAUs"]
[Thu Sep 17 15:34:57.040619 2026] [security2:error] [pid 20162:tid 20334] [client 20.24.86.237:11530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/2.php"] [unique_id "aqxdAa-O_Kk7aqBvaiF-xAAAAbg"]
[Thu Sep 17 15:34:57.040717 2026] [security2:error] [pid 20162:tid 20334] [client 20.24.86.237:11530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/2.php"] [unique_id "aqxdAa-O_Kk7aqBvaiF-xAAAAbg"]
[Thu Sep 17 15:34:57.103419 2026] [security2:error] [pid 20162:tid 20326] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/github/.env"] [unique_id "aqxdAa-O_Kk7aqBvaiF-xQAAAbA"]
[Thu Sep 17 15:34:57.141205 2026] [security2:error] [pid 20162:tid 20400] [client 34.32.10.189:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/debug.php"] [unique_id "aqxdAa-O_Kk7aqBvaiF-xgAAAfo"]
[Thu Sep 17 15:34:57.145984 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/preview/.env"] [unique_id "aqxdATqiPMah0Tz_U1Oi9wAAAUY"]
[Thu Sep 17 15:34:57.209063 2026] [security2:error] [pid 20162:tid 20354] [client 34.166.190.195:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxdAa-O_Kk7aqBvaiF-xwAAAcw"]
[Thu Sep 17 15:34:57.258329 2026] [security2:error] [pid 20162:tid 20357] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/actions/.env"] [unique_id "aqxdAa-O_Kk7aqBvaiF-ygAAAc8"]
[Thu Sep 17 15:34:57.332978 2026] [security2:error] [pid 18946:tid 19118] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/beta/.env"] [unique_id "aqxdATqiPMah0Tz_U1Oi_QAAATQ"]
[Thu Sep 17 15:34:57.361212 2026] [security2:error] [pid 18946:tid 19152] [client 20.24.86.237:57481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/ba.php"] [unique_id "aqxdATqiPMah0Tz_U1Oi_gAAAVY"]
[Thu Sep 17 15:34:57.361293 2026] [security2:error] [pid 18946:tid 19152] [client 20.24.86.237:57481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/ba.php"] [unique_id "aqxdATqiPMah0Tz_U1Oi_gAAAVY"]
[Thu Sep 17 15:34:57.367556 2026] [security2:error] [pid 18946:tid 19022] [remote 45.157.54.43:12205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danijelascatshop.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxdATqiPMah0Tz_U1Oi_wABLEs"]
[Thu Sep 17 15:34:57.367711 2026] [security2:error] [pid 18946:tid 19110] [client 45.157.54.43:12205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "danijelascatshop.wheresmymap.com"] [uri "/xmlrpc.php"] [unique_id "aqxdATqiPMah0Tz_U1Oi_wABLEs"]
[Thu Sep 17 15:34:57.370590 2026] [core:error] [pid 18946:tid 19121] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:57.370609 2026] [core:error] [pid 18946:tid 19121] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:57.414948 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/circleci/.env"] [unique_id "aqxdAa-O_Kk7aqBvaiF-zAAAAeQ"]
[Thu Sep 17 15:34:57.522188 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/uat/.env"] [unique_id "aqxdATqiPMah0Tz_U1OjAwAAATs"]
[Thu Sep 17 15:34:57.574623 2026] [security2:error] [pid 20162:tid 20371] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/travis/.env"] [unique_id "aqxdAa-O_Kk7aqBvaiF-zgAAAd0"]
[Thu Sep 17 15:34:57.589303 2026] [security2:error] [pid 20162:tid 20344] [client 34.32.10.189:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxdAa-O_Kk7aqBvaiF-0AAAAcI"]
[Thu Sep 17 15:34:57.681089 2026] [security2:error] [pid 18946:tid 19168] [client 20.24.86.237:57517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/great.php"] [unique_id "aqxdATqiPMah0Tz_U1OjCAAAAWY"]
[Thu Sep 17 15:34:57.681199 2026] [security2:error] [pid 18946:tid 19168] [client 20.24.86.237:57517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/great.php"] [unique_id "aqxdATqiPMah0Tz_U1OjCAAAAWY"]
[Thu Sep 17 15:34:57.711321 2026] [security2:error] [pid 18946:tid 19157] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/stage/.env"] [unique_id "aqxdATqiPMah0Tz_U1OjCQAAAVs"]
[Thu Sep 17 15:34:57.729388 2026] [security2:error] [pid 20162:tid 20407] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/buildkite/.env"] [unique_id "aqxdAa-O_Kk7aqBvaiF-0QAAAgE"]
[Thu Sep 17 15:34:57.887811 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/development/.env"] [unique_id "aqxdATqiPMah0Tz_U1OjCgAAAVI"]
[Thu Sep 17 15:34:57.891043 2026] [security2:error] [pid 20162:tid 20385] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mysql/.env"] [unique_id "aqxdAa-O_Kk7aqBvaiF-0gAAAes"]
[Thu Sep 17 15:34:57.895838 2026] [security2:error] [pid 18946:tid 19128] [client 34.166.190.195:42878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxdATqiPMah0Tz_U1OjCwAAAT4"]
[Thu Sep 17 15:34:57.999701 2026] [security2:error] [pid 20162:tid 20419] [client 20.24.86.237:57507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aqxdAa-O_Kk7aqBvaiF-1AAAAg0"]
[Thu Sep 17 15:34:57.999818 2026] [security2:error] [pid 20162:tid 20419] [client 20.24.86.237:57507] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aqxdAa-O_Kk7aqBvaiF-1AAAAg0"]
[Thu Sep 17 15:34:58.036747 2026] [security2:error] [pid 18946:tid 19163] [client 34.32.10.189:45368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/test/phpinfo.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjDAAAAWE"]
[Thu Sep 17 15:34:58.045373 2026] [security2:error] [pid 20162:tid 20375] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/postgres/.env"] [unique_id "aqxdAq-O_Kk7aqBvaiF-1QAAAeE"]
[Thu Sep 17 15:34:58.050161 2026] [security2:error] [pid 18946:tid 19104] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/production/.env"] [unique_id "aqxdAjqiPMah0Tz_U1OjDQAAASY"]
[Thu Sep 17 15:34:58.180441 2026] [core:error] [pid 20162:tid 20324] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:58.180460 2026] [core:error] [pid 20162:tid 20324] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:34:58.199383 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/mongodb/.env"] [unique_id "aqxdAq-O_Kk7aqBvaiF-3AAAAfQ"]
[Thu Sep 17 15:34:58.247377 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.45.51:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rafaelceara.com"] [uri "/config/app/.env"] [unique_id "aqxdAjqiPMah0Tz_U1OjEgAAAYY"]
[Thu Sep 17 15:34:58.330196 2026] [security2:error] [pid 20162:tid 20418] [client 20.24.86.237:57498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/robots.php"] [unique_id "aqxdAq-O_Kk7aqBvaiF-3QAAAgw"]
[Thu Sep 17 15:34:58.330282 2026] [security2:error] [pid 20162:tid 20418] [client 20.24.86.237:57498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/robots.php"] [unique_id "aqxdAq-O_Kk7aqBvaiF-3QAAAgw"]
[Thu Sep 17 15:34:58.353388 2026] [security2:error] [pid 20162:tid 20355] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/redis/.env"] [unique_id "aqxdAq-O_Kk7aqBvaiF-3gAAAc0"]
[Thu Sep 17 15:34:58.442680 2026] [security2:error] [pid 18946:tid 19199] [client 34.154.45.51:51996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/phpinfo.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjFgAAAYU"]
[Thu Sep 17 15:34:58.494167 2026] [security2:error] [pid 18946:tid 19078] [client 34.32.10.189:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/dev/phpinfo.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjGAAAAQw"]
[Thu Sep 17 15:34:58.507893 2026] [security2:error] [pid 20162:tid 20342] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/elasticsearch/.env"] [unique_id "aqxdAq-O_Kk7aqBvaiF-4QAAAcA"]
[Thu Sep 17 15:34:58.575173 2026] [security2:error] [pid 18946:tid 19117] [client 34.166.190.195:42888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjGgAAATM"]
[Thu Sep 17 15:34:58.652792 2026] [security2:error] [pid 18946:tid 19097] [client 20.24.86.237:57411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/k.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjHQAAAR8"]
[Thu Sep 17 15:34:58.652886 2026] [security2:error] [pid 18946:tid 19097] [client 20.24.86.237:57411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/k.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjHQAAAR8"]
[Thu Sep 17 15:34:58.662628 2026] [security2:error] [pid 20162:tid 20348] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/rabbitmq/.env"] [unique_id "aqxdAq-O_Kk7aqBvaiF-4wAAAcY"]
[Thu Sep 17 15:34:58.832022 2026] [security2:error] [pid 20162:tid 20309] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/kafka/.env"] [unique_id "aqxdAq-O_Kk7aqBvaiF-6QAAAZ8"]
[Thu Sep 17 15:34:58.943825 2026] [security2:error] [pid 18946:tid 19155] [client 34.32.10.189:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/old/phpinfo.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjKQAAAVk"]
[Thu Sep 17 15:34:58.966879 2026] [security2:error] [pid 18946:tid 19146] [client 34.166.234.125:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdAjqiPMah0Tz_U1OjKwAAAVA"]
[Thu Sep 17 15:34:58.982152 2026] [security2:error] [pid 20162:tid 20406] [client 20.24.86.237:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/w.php"] [unique_id "aqxdAq-O_Kk7aqBvaiF-6gAAAgA"]
[Thu Sep 17 15:34:58.982248 2026] [security2:error] [pid 20162:tid 20406] [client 20.24.86.237:57433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/w.php"] [unique_id "aqxdAq-O_Kk7aqBvaiF-6gAAAgA"]
[Thu Sep 17 15:34:58.993332 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/queue/.env"] [unique_id "aqxdAq-O_Kk7aqBvaiF-6wAAAZs"]
[Thu Sep 17 15:34:59.045719 2026] [security2:error] [pid 18946:tid 19105] [client 169.58.22.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxdAjqiPMah0Tz_U1OjJgAAASc"]
[Thu Sep 17 15:34:59.100371 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.45.51:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/info.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjLAAAARQ"]
[Thu Sep 17 15:34:59.160084 2026] [security2:error] [pid 20162:tid 20333] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/worker/.env"] [unique_id "aqxdA6-O_Kk7aqBvaiF-7AAAAbc"]
[Thu Sep 17 15:34:59.213554 2026] [security2:error] [pid 20162:tid 20395] [client 114.198.138.124:49396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdA6-O_Kk7aqBvaiF-7QAAAfU"]
[Thu Sep 17 15:34:59.213643 2026] [security2:error] [pid 20162:tid 20395] [client 114.198.138.124:49396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdA6-O_Kk7aqBvaiF-7QAAAfU"]
[Thu Sep 17 15:34:59.316937 2026] [security2:error] [pid 18946:tid 19161] [client 20.24.86.237:57473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/ccc.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjMQAAAV8"]
[Thu Sep 17 15:34:59.317014 2026] [security2:error] [pid 18946:tid 19161] [client 20.24.86.237:57473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/ccc.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjMQAAAV8"]
[Thu Sep 17 15:34:59.319330 2026] [security2:error] [pid 20162:tid 20415] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/job/.env"] [unique_id "aqxdA6-O_Kk7aqBvaiF-7gAAAgk"]
[Thu Sep 17 15:34:59.408030 2026] [security2:error] [pid 18946:tid 19133] [client 34.32.10.189:47054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjMgAAAUM"]
[Thu Sep 17 15:34:59.480684 2026] [security2:error] [pid 20162:tid 20370] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/test/.env"] [unique_id "aqxdA6-O_Kk7aqBvaiF-7wAAAdw"]
[Thu Sep 17 15:34:59.505060 2026] [security2:error] [pid 18946:tid 19142] [client 14.96.156.146:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjNAAAAUw"]
[Thu Sep 17 15:34:59.505457 2026] [security2:error] [pid 18946:tid 19142] [client 14.96.156.146:59745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjNAAAAUw"]
[Thu Sep 17 15:34:59.640020 2026] [security2:error] [pid 20162:tid 20340] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/qa/.env"] [unique_id "aqxdA6-O_Kk7aqBvaiF-8AAAAb4"]
[Thu Sep 17 15:34:59.652224 2026] [security2:error] [pid 20162:tid 20316] [client 34.154.45.51:49562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/php.php"] [unique_id "aqxdA6-O_Kk7aqBvaiF-8QAAAaY"]
[Thu Sep 17 15:34:59.658988 2026] [security2:error] [pid 18946:tid 19091] [client 20.24.86.237:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/images.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjNwAAARk"]
[Thu Sep 17 15:34:59.659057 2026] [security2:error] [pid 18946:tid 19091] [client 20.24.86.237:57410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/images.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjNwAAARk"]
[Thu Sep 17 15:34:59.672759 2026] [security2:error] [pid 18946:tid 19081] [client 34.166.234.125:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjOAAAAQ8"]
[Thu Sep 17 15:34:59.731346 2026] [security2:error] [pid 18946:tid 19160] [client 34.166.190.195:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdAzqiPMah0Tz_U1OjOQAAAV4"]
[Thu Sep 17 15:34:59.804183 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/preview/.env"] [unique_id "aqxdA6-O_Kk7aqBvaiF-8gAAAZA"]
[Thu Sep 17 15:34:59.860986 2026] [security2:error] [pid 18946:tid 19188] [client 34.32.10.189:47058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/public/phpinfo.php"] [unique_id "aqxdAzqiPMah0Tz_U1OjOwAAAXo"]
[Thu Sep 17 15:34:59.981251 2026] [security2:error] [pid 20162:tid 20322] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/beta/.env"] [unique_id "aqxdA6-O_Kk7aqBvaiF-8wAAAaw"]
[Thu Sep 17 15:35:00.021145 2026] [security2:error] [pid 18946:tid 19103] [client 20.24.86.237:57499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/alls.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjPQAAASU"]
[Thu Sep 17 15:35:00.021276 2026] [security2:error] [pid 18946:tid 19103] [client 20.24.86.237:57499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/alls.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjPQAAASU"]
[Thu Sep 17 15:35:00.141857 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/uat/.env"] [unique_id "aqxdBK-O_Kk7aqBvaiF-9AAAAgg"]
[Thu Sep 17 15:35:00.200188 2026] [security2:error] [pid 20162:tid 20350] [client 34.154.45.51:49574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/i.php"] [unique_id "aqxdBK-O_Kk7aqBvaiF-9QAAAcg"]
[Thu Sep 17 15:35:00.316709 2026] [security2:error] [pid 20162:tid 20382] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/stage/.env"] [unique_id "aqxdBK-O_Kk7aqBvaiF-9gAAAeg"]
[Thu Sep 17 15:35:00.366490 2026] [security2:error] [pid 20162:tid 20331] [client 34.166.234.125:54808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdBK-O_Kk7aqBvaiF--gAAAbU"]
[Thu Sep 17 15:35:00.392511 2026] [security2:error] [pid 20162:tid 20297] [client 20.24.86.237:57422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/admin.php"] [unique_id "aqxdBK-O_Kk7aqBvaiF-_AAAAZM"]
[Thu Sep 17 15:35:00.392589 2026] [security2:error] [pid 20162:tid 20297] [client 20.24.86.237:57422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/admin.php"] [unique_id "aqxdBK-O_Kk7aqBvaiF-_AAAAZM"]
[Thu Sep 17 15:35:00.456184 2026] [security2:error] [pid 18946:tid 19101] [client 34.32.10.189:47066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjRQAAASM"]
[Thu Sep 17 15:35:00.477744 2026] [security2:error] [pid 20162:tid 20307] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/development/.env"] [unique_id "aqxdBK-O_Kk7aqBvaiF-_QAAAZ0"]
[Thu Sep 17 15:35:00.534554 2026] [security2:error] [pid 18946:tid 19168] [client 34.166.190.195:37562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjSgAAAWY"]
[Thu Sep 17 15:35:00.646196 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/production/.env"] [unique_id "aqxdBK-O_Kk7aqBvaiF-_gAAAc4"]
[Thu Sep 17 15:35:00.726429 2026] [security2:error] [pid 18946:tid 19200] [client 20.24.86.237:57443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-ana.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjUQAAAYY"]
[Thu Sep 17 15:35:00.726523 2026] [security2:error] [pid 18946:tid 19200] [client 20.24.86.237:57443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/wp-ana.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjUQAAAYY"]
[Thu Sep 17 15:35:00.767887 2026] [security2:error] [pid 18946:tid 19175] [client 34.32.10.189:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/php-info.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjUgAAAW0"]
[Thu Sep 17 15:35:00.806429 2026] [security2:error] [pid 20162:tid 20390] [client 34.154.219.37:44124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emilylutringer.com"] [uri "/config/app/.env"] [unique_id "aqxdBK-O_Kk7aqBvaiF_AQAAAfA"]
[Thu Sep 17 15:35:00.814830 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.45.51:49588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/pi.php"] [unique_id "aqxdBDqiPMah0Tz_U1OjVAAAAT4"]
[Thu Sep 17 15:35:00.859337 2026] [security2:error] [pid 20162:tid 20361] [client 103.61.184.148:55520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdBK-O_Kk7aqBvaiF_AgAAAdM"]
[Thu Sep 17 15:35:00.859470 2026] [security2:error] [pid 20162:tid 20361] [client 103.61.184.148:55520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdBK-O_Kk7aqBvaiF_AgAAAdM"]
[Thu Sep 17 15:35:00.979190 2026] [security2:error] [pid 20162:tid 20349] [client 34.154.219.37:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/phpinfo.php"] [unique_id "aqxdBK-O_Kk7aqBvaiF_BAAAAcc"]
[Thu Sep 17 15:35:01.041317 2026] [security2:error] [pid 20162:tid 20401] [client 20.24.86.237:57447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/geck.php"] [unique_id "aqxdBa-O_Kk7aqBvaiF_BQAAAfs"]
[Thu Sep 17 15:35:01.041423 2026] [security2:error] [pid 20162:tid 20401] [client 20.24.86.237:57447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/geck.php"] [unique_id "aqxdBa-O_Kk7aqBvaiF_BQAAAfs"]
[Thu Sep 17 15:35:01.048353 2026] [security2:error] [pid 18946:tid 19162] [client 34.166.234.125:54816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjVgAAAWA"]
[Thu Sep 17 15:35:01.107445 2026] [security2:error] [pid 20162:tid 20282] [remote 142.44.225.111:15600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bajansoaps.com"] [uri "/robots.txt"] [unique_id "aqxdBa-O_Kk7aqBvaiF_BgAB_nY"]
[Thu Sep 17 15:35:01.107605 2026] [security2:error] [pid 20162:tid 20404] [client 142.44.225.111:15600] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bajansoaps.com"] [uri "/robots.txt"] [unique_id "aqxdBa-O_Kk7aqBvaiF_BgAB_nY"]
[Thu Sep 17 15:35:01.228907 2026] [security2:error] [pid 20162:tid 20413] [client 34.166.190.195:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdBa-O_Kk7aqBvaiF_CAAAAgc"]
[Thu Sep 17 15:35:01.239124 2026] [security2:error] [pid 18946:tid 19102] [client 34.32.10.189:47068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/phpversion.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjWgAAASQ"]
[Thu Sep 17 15:35:01.363512 2026] [security2:error] [pid 18946:tid 19199] [client 34.154.45.51:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/pinfo.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjXQAAAYU"]
[Thu Sep 17 15:35:01.366702 2026] [security2:error] [pid 18946:tid 19113] [client 162.241.226.11:25400] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjXAAAAS8"]
[Thu Sep 17 15:35:01.382026 2026] [security2:error] [pid 18946:tid 19176] [client 20.24.86.237:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/biufile.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjXgAAAW4"]
[Thu Sep 17 15:35:01.382108 2026] [security2:error] [pid 18946:tid 19176] [client 20.24.86.237:57453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/biufile.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjXgAAAW4"]
[Thu Sep 17 15:35:01.396142 2026] [security2:error] [pid 18946:tid 19182] [client 177.44.133.72:64082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjXwAAAXQ"]
[Thu Sep 17 15:35:01.396221 2026] [security2:error] [pid 18946:tid 19182] [client 177.44.133.72:64082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjXwAAAXQ"]
[Thu Sep 17 15:35:01.501897 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.219.37:53876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/info.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjYAAAAYE"]
[Thu Sep 17 15:35:01.562096 2026] [core:error] [pid 20162:tid 20308] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:35:01.562115 2026] [core:error] [pid 20162:tid 20308] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:35:01.703206 2026] [security2:error] [pid 18946:tid 19090] [client 34.32.10.189:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/_phpinfo.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjZAAAARg"]
[Thu Sep 17 15:35:01.737949 2026] [security2:error] [pid 20162:tid 20409] [client 34.166.234.125:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdBa-O_Kk7aqBvaiF_DQAAAgM"]
[Thu Sep 17 15:35:01.744126 2026] [security2:error] [pid 18946:tid 19105] [client 20.24.86.237:57522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.86.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.foxshee.com"] [uri "/dejavu.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjZQAAASc"]
[Thu Sep 17 15:35:01.744223 2026] [security2:error] [pid 18946:tid 19105] [client 20.24.86.237:57522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.foxshee.com"] [uri "/dejavu.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjZQAAASc"]
[Thu Sep 17 15:35:01.928799 2026] [security2:error] [pid 18946:tid 19187] [client 34.166.190.195:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjZwAAAXk"]
[Thu Sep 17 15:35:01.935061 2026] [security2:error] [pid 20162:tid 20317] [client 34.154.45.51:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/test.php"] [unique_id "aqxdBa-O_Kk7aqBvaiF_EQAAAac"]
[Thu Sep 17 15:35:01.987349 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.219.37:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/php.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjaAAAAVw"]
[Thu Sep 17 15:35:02.007969 2026] [security2:error] [pid 18946:tid 19140] [client 169.58.22.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxdBTqiPMah0Tz_U1OjZgAAAUo"]
[Thu Sep 17 15:35:02.013588 2026] [security2:error] [pid 20162:tid 20266] [remote 51.81.163.31:18438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bajansoaps.com"] [uri "/"] [unique_id "aqxdBq-O_Kk7aqBvaiF_EgABwWY"]
[Thu Sep 17 15:35:02.013764 2026] [security2:error] [pid 20162:tid 20343] [client 51.81.163.31:18438] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bajansoaps.com"] [uri "/"] [unique_id "aqxdBq-O_Kk7aqBvaiF_EgABwWY"]
[Thu Sep 17 15:35:02.176836 2026] [security2:error] [pid 18946:tid 19184] [client 34.32.10.189:47088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/old_phpinfo.php"] [unique_id "aqxdBjqiPMah0Tz_U1OjbgAAAXY"]
[Thu Sep 17 15:35:02.286755 2026] [security2:error] [pid 20162:tid 20323] [client 104.243.33.53:62792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zapatoschabelo.xavierlopezmiranda.com"] [uri "/.env"] [unique_id "aqxdBq-O_Kk7aqBvaiF_EwAAAa0"]
[Thu Sep 17 15:35:02.428638 2026] [security2:error] [pid 18946:tid 19172] [client 34.166.234.125:54828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdBjqiPMah0Tz_U1OjcgAAAWo"]
[Thu Sep 17 15:35:02.475206 2026] [security2:error] [pid 20162:tid 20363] [client 34.154.219.37:53898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/i.php"] [unique_id "aqxdBq-O_Kk7aqBvaiF_FAAAAdU"]
[Thu Sep 17 15:35:02.625478 2026] [security2:error] [pid 18946:tid 19152] [client 34.32.10.189:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/server-info.php"] [unique_id "aqxdBjqiPMah0Tz_U1OjegAAAVY"]
[Thu Sep 17 15:35:02.638335 2026] [security2:error] [pid 18946:tid 19186] [client 34.166.190.195:37602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdBjqiPMah0Tz_U1OjewAAAXg"]
[Thu Sep 17 15:35:02.964396 2026] [security2:error] [pid 20162:tid 20354] [client 34.154.219.37:53904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/pi.php"] [unique_id "aqxdBq-O_Kk7aqBvaiF_GQAAAcw"]
[Thu Sep 17 15:35:03.076357 2026] [security2:error] [pid 18946:tid 19156] [client 34.32.10.189:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/server-status.php"] [unique_id "aqxdBzqiPMah0Tz_U1OjgQAAAVo"]
[Thu Sep 17 15:35:03.099021 2026] [security2:error] [pid 20162:tid 20417] [client 34.154.45.51:46352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/p.php"] [unique_id "aqxdB6-O_Kk7aqBvaiF_GwAAAgs"]
[Thu Sep 17 15:35:03.124219 2026] [security2:error] [pid 18946:tid 19126] [client 34.166.234.125:54834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxdBzqiPMah0Tz_U1OjggAAATw"]
[Thu Sep 17 15:35:03.346210 2026] [security2:error] [pid 20162:tid 20378] [client 34.166.190.195:37614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdB6-O_Kk7aqBvaiF_IQAAAeQ"]
[Thu Sep 17 15:35:03.450539 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.219.37:53918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/pinfo.php"] [unique_id "aqxdBzqiPMah0Tz_U1OjhgAAAYg"]
[Thu Sep 17 15:35:03.622380 2026] [security2:error] [pid 20162:tid 20399] [client 34.154.45.51:46354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/debug.php"] [unique_id "aqxdB6-O_Kk7aqBvaiF_JQAAAfk"]
[Thu Sep 17 15:35:03.666515 2026] [security2:error] [pid 20162:tid 20345] [client 34.32.10.189:47126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxdB6-O_Kk7aqBvaiF_JAAAAcM"]
[Thu Sep 17 15:35:03.810730 2026] [security2:error] [pid 18946:tid 19170] [client 34.166.234.125:54838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxdBzqiPMah0Tz_U1OjigAAAWg"]
[Thu Sep 17 15:35:03.890318 2026] [autoindex:error] [pid 18946:tid 19191] [client 216.245.140.84:0] AH01276: Cannot serve directory /home2/relvnvco/public_html/realtybyjohnson/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:35:03.895073 2026] [authz_core:error] [pid 18946:tid 19189] [client 169.58.197.253:57053] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:35:03.909428 2026] [security2:error] [pid 18946:tid 19097] [client 40.81.232.68:59618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxdBzqiPMah0Tz_U1OjjgAAAR8"], referer: binance.com
[Thu Sep 17 15:35:03.970227 2026] [security2:error] [pid 20162:tid 20373] [client 34.154.219.37:53934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/test.php"] [unique_id "aqxdB6-O_Kk7aqBvaiF_JwAAAd8"]
[Thu Sep 17 15:35:04.038889 2026] [security2:error] [pid 18946:tid 19119] [client 34.166.190.195:37618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxdCDqiPMah0Tz_U1OjjwAAATU"]
[Thu Sep 17 15:35:04.085669 2026] [security2:error] [pid 20162:tid 20325] [client 34.32.10.189:47126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.snowhillstokes.org"] [uri "/index.php"] [unique_id "aqxdB6-O_Kk7aqBvaiF_KAAAAa8"]
[Thu Sep 17 15:35:04.210602 2026] [security2:error] [pid 18946:tid 19083] [client 34.154.45.51:46370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxdCDqiPMah0Tz_U1OjkgAAARE"]
[Thu Sep 17 15:35:04.238639 2026] [security2:error] [pid 20162:tid 20355] [client 34.32.10.189:47126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdCK-O_Kk7aqBvaiF_LAAAAc0"]
[Thu Sep 17 15:35:04.503925 2026] [security2:error] [pid 20162:tid 20389] [client 34.166.234.125:34604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxdCK-O_Kk7aqBvaiF_LwAAAe8"]
[Thu Sep 17 15:35:04.644804 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.219.37:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/p.php"] [unique_id "aqxdCDqiPMah0Tz_U1OjmQAAAVA"]
[Thu Sep 17 15:35:04.689037 2026] [security2:error] [pid 18946:tid 19137] [client 34.32.10.189:47142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/mail/phpinfo.php"] [unique_id "aqxdCDqiPMah0Tz_U1OjmgAAAUc"]
[Thu Sep 17 15:35:04.734645 2026] [security2:error] [pid 18946:tid 19144] [client 34.166.190.195:37634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxdCDqiPMah0Tz_U1OjnAAAAU4"]
[Thu Sep 17 15:35:04.745858 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.45.51:46386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/test/phpinfo.php"] [unique_id "aqxdCDqiPMah0Tz_U1OjnQAAAVc"]
[Thu Sep 17 15:35:05.124172 2026] [security2:error] [pid 20162:tid 20348] [client 34.154.219.37:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/debug.php"] [unique_id "aqxdCa-O_Kk7aqBvaiF_NQAAAcY"]
[Thu Sep 17 15:35:05.158066 2026] [security2:error] [pid 20162:tid 20359] [client 34.32.10.189:47144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdCa-O_Kk7aqBvaiF_NwAAAdE"]
[Thu Sep 17 15:35:05.190082 2026] [security2:error] [pid 18946:tid 19147] [client 34.166.234.125:34616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxdCTqiPMah0Tz_U1OjpgAAAVE"]
[Thu Sep 17 15:35:05.273547 2026] [security2:error] [pid 20162:tid 20368] [client 34.154.45.51:46400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxdCa-O_Kk7aqBvaiF_OAAAAdo"]
[Thu Sep 17 15:35:05.330969 2026] [security2:error] [pid 18946:tid 19077] [client 52.167.144.195:26283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dfwservicesllc.com"] [uri "/index.php"] [unique_id "aqxdCTqiPMah0Tz_U1OjqAABC2k"]
[Thu Sep 17 15:35:05.446791 2026] [security2:error] [pid 18946:tid 19161] [client 34.166.190.195:37636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxdCTqiPMah0Tz_U1OjqQAAAV8"]
[Thu Sep 17 15:35:05.598658 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.219.37:46970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxdCTqiPMah0Tz_U1OjrAAAAUQ"]
[Thu Sep 17 15:35:05.621051 2026] [security2:error] [pid 20162:tid 20370] [client 34.32.10.189:47150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdCa-O_Kk7aqBvaiF_OQAAAdw"]
[Thu Sep 17 15:35:05.775439 2026] [security2:error] [pid 18946:tid 19177] [client 79.116.89.151:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdCTqiPMah0Tz_U1OjrwAAAW8"]
[Thu Sep 17 15:35:05.775557 2026] [security2:error] [pid 18946:tid 19177] [client 79.116.89.151:53457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdCTqiPMah0Tz_U1OjrwAAAW8"]
[Thu Sep 17 15:35:05.868371 2026] [security2:error] [pid 18946:tid 19196] [client 34.154.45.51:46412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/old/phpinfo.php"] [unique_id "aqxdCTqiPMah0Tz_U1OjsAAAAYI"]
[Thu Sep 17 15:35:05.872262 2026] [security2:error] [pid 18946:tid 19192] [client 34.166.234.125:34632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxdCTqiPMah0Tz_U1OjsQAAAX4"]
[Thu Sep 17 15:35:05.904624 2026] [security2:error] [pid 18946:tid 19093] [client 143.105.152.240:16464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdCTqiPMah0Tz_U1OjsgAAARs"]
[Thu Sep 17 15:35:05.904734 2026] [security2:error] [pid 18946:tid 19093] [client 143.105.152.240:16464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdCTqiPMah0Tz_U1OjsgAAARs"]
[Thu Sep 17 15:35:06.063704 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.219.37:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/test/phpinfo.php"] [unique_id "aqxdCq-O_Kk7aqBvaiF_OwAAAgg"]
[Thu Sep 17 15:35:06.080415 2026] [security2:error] [pid 20162:tid 20382] [client 34.32.10.189:47156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdCq-O_Kk7aqBvaiF_PAAAAeg"]
[Thu Sep 17 15:35:06.143786 2026] [security2:error] [pid 20162:tid 20350] [client 34.166.190.195:37638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxdCq-O_Kk7aqBvaiF_PQAAAcg"]
[Thu Sep 17 15:35:06.284945 2026] [security2:error] [pid 20162:tid 20329] [client 40.77.167.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.arhitecturabuzau.ro"] [uri "/index.php"] [unique_id "aqxdCK-O_Kk7aqBvaiF_LgAAAbM"]
[Thu Sep 17 15:35:06.427828 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.45.51:46422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdCjqiPMah0Tz_U1OjvQAAATI"]
[Thu Sep 17 15:35:06.540350 2026] [security2:error] [pid 20162:tid 20315] [client 34.154.219.37:46988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxdCq-O_Kk7aqBvaiF_QAAAAaU"]
[Thu Sep 17 15:35:06.549035 2026] [security2:error] [pid 20162:tid 20296] [client 34.32.10.189:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdCq-O_Kk7aqBvaiF_QQAAAZI"]
[Thu Sep 17 15:35:06.558971 2026] [security2:error] [pid 20162:tid 20369] [client 34.166.234.125:34642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxdCq-O_Kk7aqBvaiF_QgAAAds"]
[Thu Sep 17 15:35:06.834274 2026] [security2:error] [pid 18946:tid 19175] [client 34.166.190.195:37654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxdCjqiPMah0Tz_U1OjwgAAAW0"]
[Thu Sep 17 15:35:07.010842 2026] [security2:error] [pid 20162:tid 20361] [client 34.154.219.37:47000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/old/phpinfo.php"] [unique_id "aqxdC6-O_Kk7aqBvaiF_RAAAAdM"]
[Thu Sep 17 15:35:07.012834 2026] [security2:error] [pid 18946:tid 19202] [client 34.32.10.189:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/phpinfo.php.bak"] [unique_id "aqxdCzqiPMah0Tz_U1OjwwAAAYg"]
[Thu Sep 17 15:35:07.065369 2026] [security2:error] [pid 18946:tid 19178] [client 34.154.45.51:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/public/phpinfo.php"] [unique_id "aqxdCzqiPMah0Tz_U1OjxAAAAXA"]
[Thu Sep 17 15:35:07.245926 2026] [security2:error] [pid 18946:tid 19094] [client 34.166.234.125:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxdCzqiPMah0Tz_U1OjxwAAARw"]
[Thu Sep 17 15:35:07.459174 2026] [security2:error] [pid 18946:tid 19191] [client 136.158.61.34:2906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdCzqiPMah0Tz_U1OjyAAAAX0"]
[Thu Sep 17 15:35:07.459291 2026] [security2:error] [pid 18946:tid 19191] [client 136.158.61.34:2906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdCzqiPMah0Tz_U1OjyAAAAX0"]
[Thu Sep 17 15:35:07.482780 2026] [security2:error] [pid 20162:tid 20335] [client 34.32.10.189:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/phpinfo.php.old"] [unique_id "aqxdC6-O_Kk7aqBvaiF_RwAAAbk"]
[Thu Sep 17 15:35:07.499745 2026] [security2:error] [pid 20162:tid 20320] [client 34.154.219.37:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdC6-O_Kk7aqBvaiF_SAAAAao"]
[Thu Sep 17 15:35:07.528598 2026] [security2:error] [pid 20162:tid 20327] [client 34.166.190.195:37660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxdC6-O_Kk7aqBvaiF_SQAAAbE"]
[Thu Sep 17 15:35:07.928018 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.234.125:34666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxdCzqiPMah0Tz_U1OjzgAAAXw"]
[Thu Sep 17 15:35:07.947522 2026] [security2:error] [pid 20162:tid 20374] [client 34.32.10.189:47176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/phpinfo.php~"] [unique_id "aqxdC6-O_Kk7aqBvaiF_SwAAAeA"]
[Thu Sep 17 15:35:07.958331 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.219.37:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/public/phpinfo.php"] [unique_id "aqxdCzqiPMah0Tz_U1OjzwAAARc"]
[Thu Sep 17 15:35:08.186634 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.45.51:46442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/php-info.php"] [unique_id "aqxdDDqiPMah0Tz_U1Oj1wAAAXI"]
[Thu Sep 17 15:35:08.226856 2026] [security2:error] [pid 18946:tid 19182] [client 34.166.190.195:37668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxdDDqiPMah0Tz_U1Oj2AAAAXQ"]
[Thu Sep 17 15:35:08.411583 2026] [security2:error] [pid 18946:tid 19169] [client 34.32.10.189:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/info.php.bak"] [unique_id "aqxdDDqiPMah0Tz_U1Oj2QAAAWc"]
[Thu Sep 17 15:35:08.611915 2026] [security2:error] [pid 18946:tid 19122] [client 34.166.234.125:34668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxdDDqiPMah0Tz_U1Oj3QAAATg"]
[Thu Sep 17 15:35:08.642353 2026] [security2:error] [pid 18946:tid 19087] [client 34.154.219.37:47022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/php-info.php"] [unique_id "aqxdDDqiPMah0Tz_U1Oj3gAAARU"]
[Thu Sep 17 15:35:08.724378 2026] [security2:error] [pid 18946:tid 19077] [client 34.154.45.51:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/phpversion.php"] [unique_id "aqxdDDqiPMah0Tz_U1Oj4QAAAQs"]
[Thu Sep 17 15:35:08.879626 2026] [security2:error] [pid 18946:tid 19161] [client 34.32.10.189:47184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/phpinfo.php.save"] [unique_id "aqxdDDqiPMah0Tz_U1Oj4gAAAV8"]
[Thu Sep 17 15:35:08.935425 2026] [security2:error] [pid 18946:tid 19084] [client 34.166.190.195:37682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxdDDqiPMah0Tz_U1Oj4wAAARI"]
[Thu Sep 17 15:35:09.124034 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.219.37:47034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/phpversion.php"] [unique_id "aqxdDTqiPMah0Tz_U1Oj5gAAAWQ"]
[Thu Sep 17 15:35:09.266215 2026] [security2:error] [pid 20162:tid 20358] [client 34.154.45.51:46458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/_phpinfo.php"] [unique_id "aqxdDa-O_Kk7aqBvaiF_TwAAAdA"]
[Thu Sep 17 15:35:09.327559 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.234.125:34682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxdDTqiPMah0Tz_U1Oj6QAAAUY"]
[Thu Sep 17 15:35:09.331172 2026] [security2:error] [pid 20162:tid 20403] [client 34.32.10.189:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/staging/phpinfo.php"] [unique_id "aqxdDa-O_Kk7aqBvaiF_UAAAAf0"]
[Thu Sep 17 15:35:09.604232 2026] [security2:error] [pid 20162:tid 20376] [client 34.154.219.37:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/_phpinfo.php"] [unique_id "aqxdDa-O_Kk7aqBvaiF_UQAAAeI"]
[Thu Sep 17 15:35:09.641578 2026] [security2:error] [pid 20162:tid 20363] [client 34.166.190.195:56238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxdDa-O_Kk7aqBvaiF_UgAAAdU"]
[Thu Sep 17 15:35:09.703290 2026] [security2:error] [pid 20162:tid 20362] [client 40.81.232.68:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxdDa-O_Kk7aqBvaiF_UwAAAdQ"], referer: binance.com
[Thu Sep 17 15:35:09.741807 2026] [security2:error] [pid 18946:tid 19192] [client 114.198.138.124:50047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdDTqiPMah0Tz_U1Oj7QAAAX4"]
[Thu Sep 17 15:35:09.741886 2026] [security2:error] [pid 18946:tid 19192] [client 114.198.138.124:50047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdDTqiPMah0Tz_U1Oj7QAAAX4"]
[Thu Sep 17 15:35:09.796705 2026] [security2:error] [pid 20162:tid 20293] [client 34.32.10.189:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/beta/phpinfo.php"] [unique_id "aqxdDa-O_Kk7aqBvaiF_VAAAAY8"]
[Thu Sep 17 15:35:09.826090 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.45.51:46472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/old_phpinfo.php"] [unique_id "aqxdDTqiPMah0Tz_U1Oj8QAAASo"]
[Thu Sep 17 15:35:10.024148 2026] [security2:error] [pid 18946:tid 19171] [client 34.166.234.125:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxdDjqiPMah0Tz_U1Oj9AAAAWk"]
[Thu Sep 17 15:35:10.118728 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.219.37:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/old_phpinfo.php"] [unique_id "aqxdDjqiPMah0Tz_U1Oj9QAAAYM"]
[Thu Sep 17 15:35:10.152248 2026] [security2:error] [pid 18946:tid 19107] [client 14.96.156.146:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdDjqiPMah0Tz_U1Oj-QAAASk"]
[Thu Sep 17 15:35:10.152669 2026] [security2:error] [pid 18946:tid 19107] [client 14.96.156.146:60378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdDjqiPMah0Tz_U1Oj-QAAASk"]
[Thu Sep 17 15:35:10.254345 2026] [security2:error] [pid 18946:tid 19132] [client 34.32.10.189:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/uat/phpinfo.php"] [unique_id "aqxdDjqiPMah0Tz_U1Oj-wAAAUI"]
[Thu Sep 17 15:35:10.345929 2026] [security2:error] [pid 20162:tid 20357] [client 34.166.190.195:56242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxdDq-O_Kk7aqBvaiF_VgAAAc8"]
[Thu Sep 17 15:35:10.376983 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.45.51:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/server-info.php"] [unique_id "aqxdDjqiPMah0Tz_U1Oj_QAAAYY"]
[Thu Sep 17 15:35:10.614878 2026] [security2:error] [pid 20162:tid 20397] [client 34.154.219.37:47060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/server-info.php"] [unique_id "aqxdDq-O_Kk7aqBvaiF_VwAAAfc"]
[Thu Sep 17 15:35:10.704670 2026] [security2:error] [pid 20162:tid 20354] [client 34.166.234.125:34700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdDq-O_Kk7aqBvaiF_WAAAAcw"]
[Thu Sep 17 15:35:10.705454 2026] [security2:error] [pid 18946:tid 19178] [client 34.32.10.189:36382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/qa/phpinfo.php"] [unique_id "aqxdDjqiPMah0Tz_U1OkAQAAAXA"]
[Thu Sep 17 15:35:10.848701 2026] [security2:error] [pid 18946:tid 19067] [remote 62.60.130.252:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "entrustcounseling.com"] [uri "/wp-login.php"] [unique_id "aqxdDjqiPMah0Tz_U1OkAwABHHg"]
[Thu Sep 17 15:35:10.957653 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.45.51:46496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/server-status.php"] [unique_id "aqxdDjqiPMah0Tz_U1OkBQAAAS4"]
[Thu Sep 17 15:35:11.050290 2026] [security2:error] [pid 18946:tid 19102] [client 34.166.190.195:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkCAAAASQ"]
[Thu Sep 17 15:35:11.110079 2026] [security2:error] [pid 20162:tid 20330] [client 34.154.219.37:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/server-status.php"] [unique_id "aqxdD6-O_Kk7aqBvaiF_WwAAAbQ"]
[Thu Sep 17 15:35:11.152966 2026] [security2:error] [pid 18946:tid 19113] [client 34.32.10.189:36386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/preview/phpinfo.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkCQAAAS8"]
[Thu Sep 17 15:35:11.387757 2026] [security2:error] [pid 18946:tid 19190] [client 34.166.234.125:34708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkDQAAAXw"]
[Thu Sep 17 15:35:11.520751 2026] [security2:error] [pid 18946:tid 18961] [remote 62.60.130.252:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "entrustcounseling.com"] [uri "/wp-login.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkEQABGg4"]
[Thu Sep 17 15:35:11.623022 2026] [security2:error] [pid 18946:tid 19105] [client 34.32.10.189:36398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/www/phpinfo.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkEwAAASc"]
[Thu Sep 17 15:35:11.739270 2026] [security2:error] [pid 18946:tid 19146] [client 34.166.190.195:56252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkFwAAAVA"]
[Thu Sep 17 15:35:11.756571 2026] [security2:error] [pid 18946:tid 19155] [client 103.61.184.148:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkGAAAAVk"]
[Thu Sep 17 15:35:11.756677 2026] [security2:error] [pid 18946:tid 19155] [client 103.61.184.148:56128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdDzqiPMah0Tz_U1OkGAAAAVk"]
[Thu Sep 17 15:35:11.994884 2026] [security2:error] [pid 20162:tid 20314] [client 34.154.219.37:47090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdD6-O_Kk7aqBvaiF_YgAAAaQ"]
[Thu Sep 17 15:35:12.077684 2026] [security2:error] [pid 20162:tid 20419] [client 34.166.234.125:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_YwAAAg0"]
[Thu Sep 17 15:35:12.078710 2026] [security2:error] [pid 20162:tid 20304] [client 34.32.10.189:36412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_ZAAAAZo"]
[Thu Sep 17 15:35:12.126556 2026] [security2:error] [pid 18946:tid 19193] [client 177.44.133.72:64729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdEDqiPMah0Tz_U1OkGgAAAX8"]
[Thu Sep 17 15:35:12.126688 2026] [security2:error] [pid 18946:tid 19193] [client 177.44.133.72:64729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdEDqiPMah0Tz_U1OkGgAAAX8"]
[Thu Sep 17 15:35:12.413521 2026] [security2:error] [pid 20162:tid 20309] [client 34.166.190.195:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_bgAAAZ8"]
[Thu Sep 17 15:35:12.460804 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.219.37:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxdEDqiPMah0Tz_U1OkGwAAAUM"]
[Thu Sep 17 15:35:12.527691 2026] [security2:error] [pid 18946:tid 19134] [client 34.32.10.189:36418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdEDqiPMah0Tz_U1OkHAAAAUQ"]
[Thu Sep 17 15:35:12.684798 2026] [security2:error] [pid 20162:tid 20360] [client 34.154.45.51:46510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdEK-O_Kk7aqBvaiF_cQAAAdI"]
[Thu Sep 17 15:35:12.761408 2026] [security2:error] [pid 20162:tid 20370] [client 34.166.234.125:34718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_cwAAAdw"]
[Thu Sep 17 15:35:12.854179 2026] [security2:error] [pid 20162:tid 20359] [client 95.108.213.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "starstoreonline.com"] [uri "/index.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_bQAAAdE"]
[Thu Sep 17 15:35:12.861240 2026] [security2:error] [pid 20162:tid 20294] [client 192.178.6.4:54122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_dQAAAZA"]
[Thu Sep 17 15:35:12.899547 2026] [security2:error] [pid 20162:tid 20340] [client 68.67.113.17:54591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dfdub.com"] [uri "/index.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_dAAAAb4"]
[Thu Sep 17 15:35:12.933352 2026] [security2:error] [pid 18946:tid 19098] [client 34.154.219.37:47106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdEDqiPMah0Tz_U1OkIgAAASA"]
[Thu Sep 17 15:35:12.974900 2026] [security2:error] [pid 20162:tid 20379] [client 34.32.10.189:36430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/site/phpinfo.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_dwAAAeU"]
[Thu Sep 17 15:35:12.991426 2026] [security2:error] [pid 20162:tid 20331] [client 24.188.210.41:57161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdEK-O_Kk7aqBvaiF_dgABtW8"], referer: https://www.google.com/
[Thu Sep 17 15:35:13.093699 2026] [security2:error] [pid 18946:tid 19153] [client 34.166.190.195:56276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkJwAAAVc"]
[Thu Sep 17 15:35:13.245069 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.45.51:44016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkLQAAARs"]
[Thu Sep 17 15:35:13.415430 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.219.37:47114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkMAAAATI"]
[Thu Sep 17 15:35:13.423701 2026] [security2:error] [pid 20162:tid 20364] [client 34.32.10.189:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/docs/phpinfo.php"] [unique_id "aqxdEa-O_Kk7aqBvaiF_eAAAAdY"]
[Thu Sep 17 15:35:13.450583 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.234.125:34734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkMgAAAWI"]
[Thu Sep 17 15:35:13.611919 2026] [security2:error] [pid 18946:tid 19132] [client 17.166.151.18:55716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxdETqiPMah0Tz_U1OkMQABQnU"]
[Thu Sep 17 15:35:13.757984 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.45.51:44028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkOAAAAW0"]
[Thu Sep 17 15:35:13.788130 2026] [security2:error] [pid 18946:tid 19135] [client 34.166.190.195:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkOQAAAUU"]
[Thu Sep 17 15:35:13.882596 2026] [security2:error] [pid 18946:tid 19080] [client 34.32.10.189:36448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkOgAAAQ4"]
[Thu Sep 17 15:35:13.898177 2026] [security2:error] [pid 18946:tid 19174] [client 34.154.219.37:47130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdETqiPMah0Tz_U1OkOwAAAWw"]
[Thu Sep 17 15:35:14.129334 2026] [security2:error] [pid 18946:tid 19170] [client 34.166.234.125:34740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdEjqiPMah0Tz_U1OkPAAAAWg"]
[Thu Sep 17 15:35:14.308309 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.45.51:44038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdEjqiPMah0Tz_U1OkQQAAAS4"]
[Thu Sep 17 15:35:14.334692 2026] [security2:error] [pid 18946:tid 19106] [client 34.32.10.189:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdEjqiPMah0Tz_U1OkQgAAASg"]
[Thu Sep 17 15:35:14.390593 2026] [security2:error] [pid 20162:tid 20387] [client 34.154.219.37:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdEq-O_Kk7aqBvaiF_fAAAAe0"]
[Thu Sep 17 15:35:14.481529 2026] [security2:error] [pid 18946:tid 19176] [client 34.166.190.195:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdEjqiPMah0Tz_U1OkQwAAAW4"]
[Thu Sep 17 15:35:14.787931 2026] [security2:error] [pid 20162:tid 20377] [client 34.32.10.189:36462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/core/phpinfo.php"] [unique_id "aqxdEq-O_Kk7aqBvaiF_fgAAAeM"]
[Thu Sep 17 15:35:14.814650 2026] [security2:error] [pid 18946:tid 19183] [client 34.166.234.125:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxdEjqiPMah0Tz_U1OkRwAAAXU"]
[Thu Sep 17 15:35:14.821283 2026] [security2:error] [pid 20162:tid 20404] [client 34.154.45.51:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdEq-O_Kk7aqBvaiF_fwAAAf4"]
[Thu Sep 17 15:35:14.865306 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.219.37:53026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxdEq-O_Kk7aqBvaiF_gAAAAaM"]
[Thu Sep 17 15:35:15.161008 2026] [security2:error] [pid 20162:tid 20413] [client 34.166.190.195:56298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdE6-O_Kk7aqBvaiF_gQAAAgc"]
[Thu Sep 17 15:35:15.241552 2026] [security2:error] [pid 18946:tid 19151] [client 34.32.10.189:36468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.10.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.snowhillstokes.org"] [uri "/includes/phpinfo.php"] [unique_id "aqxdEzqiPMah0Tz_U1OkSwAAAVU"]
[Thu Sep 17 15:35:15.295850 2026] [security2:error] [pid 18946:tid 19190] [client 40.81.232.68:60721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxdEzqiPMah0Tz_U1OkTAAAAXw"], referer: binance.com
[Thu Sep 17 15:35:15.343650 2026] [security2:error] [pid 18946:tid 19096] [client 43.173.78.245:49388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdEzqiPMah0Tz_U1OkSAABHgg"]
[Thu Sep 17 15:35:15.361927 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.45.51:44070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdEzqiPMah0Tz_U1OkTQAAAT0"]
[Thu Sep 17 15:35:15.363841 2026] [security2:error] [pid 20162:tid 20327] [client 34.154.219.37:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/phpinfo.php.old"] [unique_id "aqxdE6-O_Kk7aqBvaiF_gwAAAbE"]
[Thu Sep 17 15:35:15.507075 2026] [security2:error] [pid 18946:tid 19148] [client 34.166.234.125:34604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldc.coo.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxdEzqiPMah0Tz_U1OkTgAAAVI"]
[Thu Sep 17 15:35:15.841766 2026] [security2:error] [pid 20162:tid 20328] [client 34.154.219.37:53042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/phpinfo.php~"] [unique_id "aqxdE6-O_Kk7aqBvaiF_hAAAAbI"]
[Thu Sep 17 15:35:15.850253 2026] [security2:error] [pid 18946:tid 19095] [client 34.166.190.195:56314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxdEzqiPMah0Tz_U1OkVwAAAR0"]
[Thu Sep 17 15:35:15.898372 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.45.51:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxdEzqiPMah0Tz_U1OkWwAAAWE"]
[Thu Sep 17 15:35:15.918148 2026] [security2:error] [pid 18946:tid 19114] [client 45.115.26.203:34336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/.env"] [unique_id "aqxdEzqiPMah0Tz_U1OkXAAAATA"]
[Thu Sep 17 15:35:15.921886 2026] [security2:error] [pid 20162:tid 20300] [client 45.115.26.203:34342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/info.php"] [unique_id "aqxdE6-O_Kk7aqBvaiF_hgAAAZY"]
[Thu Sep 17 15:35:16.034415 2026] [security2:error] [pid 20162:tid 20409] [client 45.115.26.203:34438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/test.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_hwAAAgM"]
[Thu Sep 17 15:35:16.035733 2026] [security2:error] [pid 18946:tid 19117] [client 45.115.26.203:34420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/i.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkXgAAATM"]
[Thu Sep 17 15:35:16.036273 2026] [security2:error] [pid 18946:tid 19146] [client 45.115.26.203:34380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/api/.env"] [unique_id "aqxdFDqiPMah0Tz_U1OkXwAAAVA"]
[Thu Sep 17 15:35:16.039730 2026] [security2:error] [pid 20162:tid 20410] [client 45.115.26.203:34494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/phpinfo.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_iQAAAgQ"]
[Thu Sep 17 15:35:16.039748 2026] [security2:error] [pid 18946:tid 19090] [client 45.115.26.203:34376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/php_info.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkaAAAARg"]
[Thu Sep 17 15:35:16.039773 2026] [security2:error] [pid 18946:tid 19122] [client 45.115.26.203:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/_phpinfo.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkaQAAATg"]
[Thu Sep 17 15:35:16.039792 2026] [security2:error] [pid 18946:tid 19077] [client 45.115.26.203:34580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/php-info.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkZgAAAQs"]
[Thu Sep 17 15:35:16.040517 2026] [security2:error] [pid 18946:tid 19193] [client 45.115.26.203:34432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/.env~"] [unique_id "aqxdFDqiPMah0Tz_U1OkZQAAAX8"]
[Thu Sep 17 15:35:16.045864 2026] [security2:error] [pid 18946:tid 19195] [client 45.115.26.203:34452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/app/.env"] [unique_id "aqxdFDqiPMah0Tz_U1OkawAAAYE"]
[Thu Sep 17 15:35:16.046125 2026] [security2:error] [pid 20162:tid 20343] [client 45.115.26.203:34356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/.env.old"] [unique_id "aqxdFK-O_Kk7aqBvaiF_jAAAAcE"]
[Thu Sep 17 15:35:16.049706 2026] [security2:error] [pid 18946:tid 19086] [client 45.115.26.203:34576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/.env.bak"] [unique_id "aqxdFDqiPMah0Tz_U1OkbAAAARQ"]
[Thu Sep 17 15:35:16.050221 2026] [security2:error] [pid 18946:tid 19161] [client 45.115.26.203:34398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/backend/.env"] [unique_id "aqxdFDqiPMah0Tz_U1OkbQAAAV8"]
[Thu Sep 17 15:35:16.050754 2026] [security2:error] [pid 20162:tid 20366] [client 45.115.26.203:34476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/src/.env"] [unique_id "aqxdFK-O_Kk7aqBvaiF_jwAAAdg"]
[Thu Sep 17 15:35:16.050974 2026] [security2:error] [pid 18946:tid 19100] [client 45.115.26.203:34552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/.env.swp"] [unique_id "aqxdFDqiPMah0Tz_U1OkbgAAASI"]
[Thu Sep 17 15:35:16.052135 2026] [security2:error] [pid 20162:tid 20337] [client 45.115.26.203:34512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/.env"] [unique_id "aqxdFK-O_Kk7aqBvaiF_kQAAAbs"]
[Thu Sep 17 15:35:16.086709 2026] [security2:error] [pid 20162:tid 20374] [client 45.115.26.203:34340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdE6-O_Kk7aqBvaiF_hQAAAeA"]
[Thu Sep 17 15:35:16.184401 2026] [security2:error] [pid 18946:tid 19157] [client 45.115.26.203:34380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.mindmappower.com"] [uri "/.env.backup"] [unique_id "aqxdFDqiPMah0Tz_U1OkdgAAAVs"]
[Thu Sep 17 15:35:16.225069 2026] [security2:error] [pid 18946:tid 19185] [client 45.115.26.203:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mindmappower.com"] [uri "/pi.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkegAAAXc"]
[Thu Sep 17 15:35:16.304856 2026] [security2:error] [pid 18946:tid 19120] [client 45.115.26.203:34484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkYQAAATY"]
[Thu Sep 17 15:35:16.305958 2026] [security2:error] [pid 18946:tid 19087] [client 45.115.26.203:34406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkagAAARU"]
[Thu Sep 17 15:35:16.307198 2026] [security2:error] [pid 18946:tid 19147] [client 45.115.26.203:34322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkYwAAAVE"]
[Thu Sep 17 15:35:16.308503 2026] [security2:error] [pid 20162:tid 20310] [client 45.115.26.203:34488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_iAAAAaA"]
[Thu Sep 17 15:35:16.319947 2026] [security2:error] [pid 20162:tid 20353] [client 45.115.26.203:34534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_iwAAAcs"]
[Thu Sep 17 15:35:16.326886 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.219.37:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/info.php.bak"] [unique_id "aqxdFK-O_Kk7aqBvaiF_lQAAAfY"]
[Thu Sep 17 15:35:16.327384 2026] [security2:error] [pid 20162:tid 20323] [client 45.115.26.203:34502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_jgAAAa0"]
[Thu Sep 17 15:35:16.327387 2026] [security2:error] [pid 18946:tid 19140] [client 45.115.26.203:34566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkZwAAAUo"]
[Thu Sep 17 15:35:16.327779 2026] [security2:error] [pid 20162:tid 20386] [client 45.115.26.203:34468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_kwAAAew"]
[Thu Sep 17 15:35:16.330922 2026] [security2:error] [pid 18946:tid 19198] [client 45.115.26.203:34426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkYgAAAYQ"]
[Thu Sep 17 15:35:16.334045 2026] [security2:error] [pid 20162:tid 20358] [client 45.115.26.203:34518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_kAAAAdA"]
[Thu Sep 17 15:35:16.340775 2026] [security2:error] [pid 18946:tid 19076] [client 45.115.26.203:34548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkbwAAAQo"]
[Thu Sep 17 15:35:16.342953 2026] [security2:error] [pid 20162:tid 20332] [client 45.115.26.203:34604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_jQAAAbY"]
[Thu Sep 17 15:35:16.431441 2026] [security2:error] [pid 18946:tid 19153] [client 79.116.89.151:54067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkgAAAAVc"]
[Thu Sep 17 15:35:16.431744 2026] [security2:error] [pid 18946:tid 19153] [client 79.116.89.151:54067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkgAAAAVc"]
[Thu Sep 17 15:35:16.436453 2026] [security2:error] [pid 20162:tid 20326] [client 34.154.45.51:44074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/phpinfo.php.old"] [unique_id "aqxdFK-O_Kk7aqBvaiF_lwAAAbA"]
[Thu Sep 17 15:35:16.467333 2026] [access_compat:error] [pid 18946:tid 19184] [client 45.115.26.203:34370] AH01797: client denied by server configuration: /home4/mindmap9/public_html/server-status
[Thu Sep 17 15:35:16.488128 2026] [security2:error] [pid 18946:tid 19136] [client 143.105.152.240:19687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkgwAAAUY"]
[Thu Sep 17 15:35:16.490101 2026] [security2:error] [pid 18946:tid 19136] [client 143.105.152.240:19687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkgwAAAUY"]
[Thu Sep 17 15:35:16.547246 2026] [security2:error] [pid 18946:tid 19175] [client 34.166.190.195:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.190.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hom.xcs.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkhQAAAW0"]
[Thu Sep 17 15:35:16.582451 2026] [security2:error] [pid 18946:tid 19080] [client 43.172.198.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkgQAAAQ4"]
[Thu Sep 17 15:35:16.815393 2026] [security2:error] [pid 18946:tid 19096] [client 74.7.241.184:49706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jerkalert.org"] [uri "/robots.txt"] [unique_id "aqxdFDqiPMah0Tz_U1OkjAABHjQ"]
[Thu Sep 17 15:35:16.849517 2026] [security2:error] [pid 18946:tid 19151] [client 34.154.219.37:53062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/phpinfo.php.save"] [unique_id "aqxdFDqiPMah0Tz_U1OkjQAAAVU"]
[Thu Sep 17 15:35:16.983795 2026] [security2:error] [pid 20162:tid 20365] [client 111.221.44.115:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.44.221.111.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compassalpha.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_nQAAAdc"]
[Thu Sep 17 15:35:16.988248 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.45.51:44084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/phpinfo.php~"] [unique_id "aqxdFDqiPMah0Tz_U1OkmQAAAUc"]
[Thu Sep 17 15:35:17.260765 2026] [security2:error] [pid 18946:tid 19098] [client 45.115.26.203:34336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkcgAAASA"]
[Thu Sep 17 15:35:17.279526 2026] [security2:error] [pid 18946:tid 19142] [client 45.115.26.203:34608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkcAAAAUw"]
[Thu Sep 17 15:35:17.317379 2026] [security2:error] [pid 20162:tid 20399] [client 34.154.219.37:53068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxdFa-O_Kk7aqBvaiF_nwAAAfk"]
[Thu Sep 17 15:35:17.337945 2026] [security2:error] [pid 18946:tid 19203] [client 45.115.26.203:34388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkdwAAAYk"]
[Thu Sep 17 15:35:17.509122 2026] [security2:error] [pid 18946:tid 19193] [client 34.154.45.51:44094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/info.php.bak"] [unique_id "aqxdFTqiPMah0Tz_U1OkrAAAAX8"]
[Thu Sep 17 15:35:17.563979 2026] [security2:error] [pid 18946:tid 19155] [client 111.221.44.115:63971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "compassalpha.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxdFTqiPMah0Tz_U1OkrgAAAVk"]
[Thu Sep 17 15:35:17.683351 2026] [security2:error] [pid 18946:tid 19109] [client 169.58.22.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxdFTqiPMah0Tz_U1OkqQAAASs"]
[Thu Sep 17 15:35:17.789407 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.219.37:53076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxdFTqiPMah0Tz_U1OktwAAAQ0"]
[Thu Sep 17 15:35:18.065299 2026] [security2:error] [pid 20162:tid 20342] [client 34.154.45.51:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/phpinfo.php.save"] [unique_id "aqxdFq-O_Kk7aqBvaiF_twAAAcA"]
[Thu Sep 17 15:35:18.239689 2026] [security2:error] [pid 18946:tid 19090] [client 57.129.81.224:42282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxdFTqiPMah0Tz_U1OkqgAAARg"]
[Thu Sep 17 15:35:18.253981 2026] [security2:error] [pid 18946:tid 19140] [client 57.129.139.88:37102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxdFjqiPMah0Tz_U1OkuwAAAUo"]
[Thu Sep 17 15:35:18.264047 2026] [security2:error] [pid 18946:tid 19200] [client 45.115.26.203:34398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkeQAAAYY"]
[Thu Sep 17 15:35:18.265396 2026] [security2:error] [pid 20162:tid 20293] [client 45.115.26.203:34306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_lAAAAY8"]
[Thu Sep 17 15:35:18.269418 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.219.37:53086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxdFjqiPMah0Tz_U1OkxAAAAVM"]
[Thu Sep 17 15:35:18.319673 2026] [security2:error] [pid 18946:tid 19168] [client 13.193.182.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdFjqiPMah0Tz_U1OkvgAAAWY"]
[Thu Sep 17 15:35:18.334333 2026] [security2:error] [pid 18946:tid 19106] [client 45.115.26.203:34704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkjwAAASg"], referer: https://www.mindmappower.com/.git-credentials
[Thu Sep 17 15:35:18.335600 2026] [security2:error] [pid 18946:tid 19102] [client 45.115.26.203:34760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkkwAAASQ"], referer: https://www.mindmappower.com/.env.local
[Thu Sep 17 15:35:18.356978 2026] [security2:error] [pid 20162:tid 20344] [client 45.115.26.203:34738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_mwAAAcI"], referer: https://www.mindmappower.com/.aws/config
[Thu Sep 17 15:35:18.367024 2026] [security2:error] [pid 18946:tid 19162] [client 45.115.26.203:34712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkkAAAAWA"], referer: https://www.mindmappower.com/.kube/config
[Thu Sep 17 15:35:18.590864 2026] [authz_core:error] [pid 18946:tid 19103] [client 169.58.197.253:58064] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:35:18.630804 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.45.51:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxdFjqiPMah0Tz_U1OkywAAAQ4"]
[Thu Sep 17 15:35:18.778112 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.219.37:53102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxdFjqiPMah0Tz_U1Ok2QAAARc"]
[Thu Sep 17 15:35:19.049618 2026] [security2:error] [pid 18946:tid 19139] [client 213.32.68.85:53416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxdFjqiPMah0Tz_U1Ok2gAAAUk"]
[Thu Sep 17 15:35:19.155533 2026] [security2:error] [pid 20162:tid 20420] [client 34.154.45.51:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxdF6-O_Kk7aqBvaiF_zwAAAg4"]
[Thu Sep 17 15:35:19.256813 2026] [security2:error] [pid 18946:tid 19083] [client 45.115.26.203:34728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkkQAAARE"], referer: https://www.mindmappower.com/.env.production
[Thu Sep 17 15:35:19.262134 2026] [security2:error] [pid 18946:tid 19119] [client 45.115.26.203:34766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OklAAAATU"], referer: https://www.mindmappower.com/.pypirc
[Thu Sep 17 15:35:19.268138 2026] [security2:error] [pid 20162:tid 20402] [client 45.115.26.203:34664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_mAAAAfw"], referer: https://www.mindmappower.com/.env.stage
[Thu Sep 17 15:35:19.272051 2026] [security2:error] [pid 18946:tid 19189] [client 45.115.26.203:34680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkigAAAXs"], referer: https://www.mindmappower.com/actuator/configprops
[Thu Sep 17 15:35:19.275072 2026] [security2:error] [pid 18946:tid 19176] [client 45.115.26.203:34744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OkkgAAAW4"], referer: https://www.mindmappower.com/.env.dev
[Thu Sep 17 15:35:19.277373 2026] [security2:error] [pid 20162:tid 20306] [client 45.115.26.203:34696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFK-O_Kk7aqBvaiF_nAAAAZw"], referer: https://www.mindmappower.com/debug/vars
[Thu Sep 17 15:35:19.279769 2026] [security2:error] [pid 18946:tid 19182] [client 45.115.26.203:34790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OklQAAAXQ"], referer: https://www.mindmappower.com/.env.prod
[Thu Sep 17 15:35:19.282196 2026] [security2:error] [pid 18946:tid 19115] [client 34.154.219.37:53106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxdFzqiPMah0Tz_U1Ok7AAAATE"]
[Thu Sep 17 15:35:19.283634 2026] [security2:error] [pid 18946:tid 19144] [client 45.115.26.203:34782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OklgAAAU4"], referer: https://www.mindmappower.com/.netrc
[Thu Sep 17 15:35:19.305314 2026] [security2:error] [pid 18946:tid 19093] [client 45.115.26.203:34852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFTqiPMah0Tz_U1OktgAAARs"], referer: https://www.mindmappower.com/.env.staging
[Thu Sep 17 15:35:19.326696 2026] [security2:error] [pid 18946:tid 19104] [client 45.115.26.203:34780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFDqiPMah0Tz_U1OklwAAASY"], referer: https://www.mindmappower.com/.env.development
[Thu Sep 17 15:35:19.347078 2026] [autoindex:error] [pid 18946:tid 19161] [client 195.96.139.199:56321] AH01276: Cannot serve directory /home1/oiyojzmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://oiy.ojz.mybluehost.me
[Thu Sep 17 15:35:19.356242 2026] [security2:error] [pid 20162:tid 20389] [client 45.115.26.203:34902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFa-O_Kk7aqBvaiF_pgAAAe8"], referer: https://www.mindmappower.com/.env.save
[Thu Sep 17 15:35:19.363757 2026] [security2:error] [pid 18946:tid 19118] [client 45.115.26.203:34898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFTqiPMah0Tz_U1OkuAAAATQ"], referer: https://www.mindmappower.com/.docker/config.json
[Thu Sep 17 15:35:19.382036 2026] [security2:error] [pid 18946:tid 19150] [client 45.115.26.203:34904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFjqiPMah0Tz_U1Ok0gAAAVQ"], referer: https://www.mindmappower.com/.npmrc
[Thu Sep 17 15:35:19.382585 2026] [security2:error] [pid 18946:tid 19127] [client 45.115.26.203:34914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mindmappower.com"] [uri "/index.php"] [unique_id "aqxdFjqiPMah0Tz_U1Ok1wAAAT0"], referer: https://www.mindmappower.com/actuator/env
[Thu Sep 17 15:35:19.448745 2026] [security2:error] [pid 18946:tid 19099] [client 40.81.232.68:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxdFzqiPMah0Tz_U1Ok7gAAASE"], referer: binance.com
[Thu Sep 17 15:35:19.623126 2026] [security2:error] [pid 18946:tid 19192] [client 136.158.61.34:4054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdFzqiPMah0Tz_U1Ok8QAAAX4"]
[Thu Sep 17 15:35:19.623240 2026] [security2:error] [pid 18946:tid 19192] [client 136.158.61.34:4054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdFzqiPMah0Tz_U1Ok8QAAAX4"]
[Thu Sep 17 15:35:19.679206 2026] [security2:error] [pid 20162:tid 20416] [client 34.154.45.51:44128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxdF6-O_Kk7aqBvaiF_3QAAAgo"]
[Thu Sep 17 15:35:19.757376 2026] [security2:error] [pid 20162:tid 20302] [client 34.154.219.37:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/www/phpinfo.php"] [unique_id "aqxdF6-O_Kk7aqBvaiF_3gAAAZg"]
[Thu Sep 17 15:35:19.947276 2026] [core:error] [pid 18946:tid 19112] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:35:19.947299 2026] [core:error] [pid 18946:tid 19112] [client 34.166.234.125:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:35:20.221272 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.45.51:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlBAAAAR0"]
[Thu Sep 17 15:35:20.231641 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.219.37:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlBQAAAUc"]
[Thu Sep 17 15:35:20.381739 2026] [security2:error] [pid 18946:tid 19077] [client 114.198.138.124:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlCAAAAQs"]
[Thu Sep 17 15:35:20.381829 2026] [security2:error] [pid 18946:tid 19077] [client 114.198.138.124:50692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlCAAAAQs"]
[Thu Sep 17 15:35:20.523563 2026] [security2:error] [pid 18946:tid 19186] [client 57.129.81.227:52884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlBwAAAXg"]
[Thu Sep 17 15:35:20.719344 2026] [security2:error] [pid 20162:tid 20337] [client 14.96.156.146:60997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdGK-O_Kk7aqBvaiF_7AAAAbs"]
[Thu Sep 17 15:35:20.719500 2026] [security2:error] [pid 20162:tid 20337] [client 14.96.156.146:60997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdGK-O_Kk7aqBvaiF_7AAAAbs"]
[Thu Sep 17 15:35:20.722031 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.219.37:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlDwAAATU"]
[Thu Sep 17 15:35:20.738857 2026] [security2:error] [pid 18946:tid 19189] [client 34.154.45.51:44150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlEQAAAXs"]
[Thu Sep 17 15:35:20.897211 2026] [security2:error] [pid 18946:tid 19127] [client 3.79.134.69:38078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.geekngamer.com"] [uri "/index.html"] [unique_id "aqxdGDqiPMah0Tz_U1OlEwAAAT0"], referer: http://www.geekngamer.com
[Thu Sep 17 15:35:21.077203 2026] [security2:error] [pid 18946:tid 19113] [client 74.7.228.60:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.danijelascatshop.me"] [uri "/index.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlFAAAAS8"]
[Thu Sep 17 15:35:21.087293 2026] [security2:error] [pid 20162:tid 20376] [client 74.7.228.60:43296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.danijelascatshop.me"] [uri "/robots.txt"] [unique_id "aqxdGK-O_Kk7aqBvaiF_7gAB4ic"]
[Thu Sep 17 15:35:21.110437 2026] [security2:error] [pid 18946:tid 19144] [client 24.237.80.184:54347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdGDqiPMah0Tz_U1OlFQABTgU"]
[Thu Sep 17 15:35:21.196711 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.219.37:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/site/phpinfo.php"] [unique_id "aqxdGTqiPMah0Tz_U1OlHgAAAXc"]
[Thu Sep 17 15:35:21.271699 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.45.51:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/www/phpinfo.php"] [unique_id "aqxdGTqiPMah0Tz_U1OlHwAAAWE"]
[Thu Sep 17 15:35:21.332059 2026] [security2:error] [pid 18946:tid 19193] [client 57.129.81.224:37624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxdGTqiPMah0Tz_U1OlGAAAAX8"]
[Thu Sep 17 15:35:21.343570 2026] [security2:error] [pid 20162:tid 20357] [client 169.58.22.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxdGa-O_Kk7aqBvaiF_9AAAAc8"]
[Thu Sep 17 15:35:21.659806 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.219.37:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxdGa-O_Kk7aqBvaiF__QAAAZk"]
[Thu Sep 17 15:35:21.846005 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.45.51:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdGTqiPMah0Tz_U1OlKgAAARg"]
[Thu Sep 17 15:35:22.135467 2026] [security2:error] [pid 20162:tid 20316] [client 34.154.219.37:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdGq-O_Kk7aqBvaiGABAAAAaY"]
[Thu Sep 17 15:35:22.259966 2026] [security2:error] [pid 20162:tid 20394] [client 162.241.226.11:40280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxdGq-O_Kk7aqBvaiGAAwAAAfQ"]
[Thu Sep 17 15:35:22.388315 2026] [security2:error] [pid 18946:tid 19172] [client 34.154.45.51:44168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdGjqiPMah0Tz_U1OlLwAAAWo"]
[Thu Sep 17 15:35:22.420044 2026] [security2:error] [pid 20162:tid 20370] [client 162.241.226.11:40290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxdGq-O_Kk7aqBvaiGABgAAAdw"]
[Thu Sep 17 15:35:22.481432 2026] [security2:error] [pid 20162:tid 20415] [client 103.61.184.148:56711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdGq-O_Kk7aqBvaiGACAAAAgk"]
[Thu Sep 17 15:35:22.481572 2026] [security2:error] [pid 20162:tid 20415] [client 103.61.184.148:56711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdGq-O_Kk7aqBvaiGACAAAAgk"]
[Thu Sep 17 15:35:22.572332 2026] [security2:error] [pid 18946:tid 19169] [client 74.7.244.43:33248] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "zlt.mai.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxdGjqiPMah0Tz_U1OlMAABZxI"]
[Thu Sep 17 15:35:22.618452 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.219.37:53174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdGjqiPMah0Tz_U1OlMQAAAS4"]
[Thu Sep 17 15:35:22.760119 2026] [security2:error] [pid 18946:tid 19125] [client 177.44.133.72:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdGjqiPMah0Tz_U1OlNAAAATs"]
[Thu Sep 17 15:35:22.760217 2026] [security2:error] [pid 18946:tid 19125] [client 177.44.133.72:65386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdGjqiPMah0Tz_U1OlNAAAATs"]
[Thu Sep 17 15:35:22.851151 2026] [security2:error] [pid 20162:tid 20329] [client 24.237.80.184:54364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdGq-O_Kk7aqBvaiGADgABsyI"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818064218&hideanons=1&hidebots=0&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:35:22.922310 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.45.51:44180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/site/phpinfo.php"] [unique_id "aqxdGjqiPMah0Tz_U1OlNgAAAVg"]
[Thu Sep 17 15:35:23.002733 2026] [security2:error] [pid 18946:tid 19165] [client 79.117.143.123:37008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdGjqiPMah0Tz_U1OlNQAAAWM"]
[Thu Sep 17 15:35:23.087085 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.219.37:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/core/phpinfo.php"] [unique_id "aqxdGzqiPMah0Tz_U1OlNwAAARc"]
[Thu Sep 17 15:35:23.455243 2026] [security2:error] [pid 20162:tid 20387] [client 34.154.45.51:47752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxdG6-O_Kk7aqBvaiGAFAAAAe0"]
[Thu Sep 17 15:35:23.578897 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.219.37:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emilylutringer.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxdG6-O_Kk7aqBvaiGAFQAAAZE"]
[Thu Sep 17 15:35:23.711944 2026] [security2:error] [pid 20162:tid 20404] [client 40.81.232.68:60157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxdG6-O_Kk7aqBvaiGAFwAAAf4"], referer: binance.com
[Thu Sep 17 15:35:23.778722 2026] [security2:error] [pid 20162:tid 20339] [client 74.7.230.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.nicholasdunnephotography.com"] [uri "/index.php"] [unique_id "aqxdGa-O_Kk7aqBvaiF_-QAAAb0"]
[Thu Sep 17 15:35:23.784257 2026] [security2:error] [pid 20162:tid 20336] [client 74.7.230.32:44824] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.nicholasdunnephotography.com"] [uri "/robots.txt"] [unique_id "aqxdGa-O_Kk7aqBvaiF_-AABuhw"]
[Thu Sep 17 15:35:23.859028 2026] [security2:error] [pid 20162:tid 20350] [client 82.102.18.118:36546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "troopkcampcadet.com"] [uri "/xmlrpc.php"] [unique_id "aqxdG6-O_Kk7aqBvaiGAGQAAAcg"]
[Thu Sep 17 15:35:23.859112 2026] [security2:error] [pid 20162:tid 20350] [client 82.102.18.118:36546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "troopkcampcadet.com"] [uri "/xmlrpc.php"] [unique_id "aqxdG6-O_Kk7aqBvaiGAGQAAAcg"]
[Thu Sep 17 15:35:23.927820 2026] [security2:error] [pid 18946:tid 19152] [client 34.154.45.51:47764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdGzqiPMah0Tz_U1OlPgAAAVY"]
[Thu Sep 17 15:35:24.229395 2026] [security2:error] [pid 18946:tid 19100] [client 82.102.18.118:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "troopkcampcadet.com"] [uri "/xmlrpc.php"] [unique_id "aqxdHDqiPMah0Tz_U1OlRwAAASI"]
[Thu Sep 17 15:35:24.229513 2026] [security2:error] [pid 18946:tid 19100] [client 82.102.18.118:36550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "troopkcampcadet.com"] [uri "/xmlrpc.php"] [unique_id "aqxdHDqiPMah0Tz_U1OlRwAAASI"]
[Thu Sep 17 15:35:24.396513 2026] [security2:error] [pid 20162:tid 20300] [client 34.154.45.51:47772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdHK-O_Kk7aqBvaiGAIQAAAZY"]
[Thu Sep 17 15:35:24.855090 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.45.51:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/core/phpinfo.php"] [unique_id "aqxdHDqiPMah0Tz_U1OlVAAAAT4"]
[Thu Sep 17 15:35:25.321264 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.45.51:47788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.45.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rafaelceara.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxdHTqiPMah0Tz_U1OlXwAAAUg"]
[Thu Sep 17 15:35:26.532656 2026] [security2:error] [pid 18946:tid 19102] [client 45.8.19.245:30251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.19.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anniechenphotography.com"] [uri "/wp-login.php"] [unique_id "aqxdHjqiPMah0Tz_U1OldQAAASQ"]
[Thu Sep 17 15:35:27.065400 2026] [security2:error] [pid 18946:tid 19133] [client 79.116.89.151:54673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdHzqiPMah0Tz_U1OlgQAAAUM"]
[Thu Sep 17 15:35:27.065938 2026] [security2:error] [pid 18946:tid 19133] [client 79.116.89.151:54673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdHzqiPMah0Tz_U1OlgQAAAUM"]
[Thu Sep 17 15:35:27.206961 2026] [security2:error] [pid 20162:tid 20375] [client 2.139.26.243:53522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mtbclubdecampo.com"] [uri "/ruta.php"] [unique_id "aqxdH6-O_Kk7aqBvaiGAQAAAAeE"]
[Thu Sep 17 15:35:27.233107 2026] [security2:error] [pid 18946:tid 19094] [client 143.105.152.240:16993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdHzqiPMah0Tz_U1OlhQAAARw"]
[Thu Sep 17 15:35:27.233212 2026] [security2:error] [pid 18946:tid 19094] [client 143.105.152.240:16993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdHzqiPMah0Tz_U1OlhQAAARw"]
[Thu Sep 17 15:35:27.563633 2026] [security2:error] [pid 18946:tid 19086] [client 40.81.232.68:49906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxdHzqiPMah0Tz_U1OljAAAARQ"], referer: binance.com
[Thu Sep 17 15:35:30.959623 2026] [security2:error] [pid 18946:tid 19095] [client 114.198.138.124:51406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdIjqiPMah0Tz_U1OlyQAAAR0"]
[Thu Sep 17 15:35:30.959700 2026] [security2:error] [pid 18946:tid 19095] [client 114.198.138.124:51406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdIjqiPMah0Tz_U1OlyQAAAR0"]
[Thu Sep 17 15:35:31.427128 2026] [security2:error] [pid 18946:tid 19082] [client 14.96.156.146:61627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdIzqiPMah0Tz_U1Ol1wAAARA"]
[Thu Sep 17 15:35:31.427253 2026] [security2:error] [pid 18946:tid 19082] [client 14.96.156.146:61627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdIzqiPMah0Tz_U1Ol1wAAARA"]
[Thu Sep 17 15:35:31.486769 2026] [security2:error] [pid 20162:tid 20349] [client 114.119.152.164:29781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.counsellingincambridge.ca"] [uri "/"] [unique_id "aqxdI6-O_Kk7aqBvaiGAUAAAAcc"], referer: https://www.counsellingincambridge.ca/
[Thu Sep 17 15:35:31.664845 2026] [security2:error] [pid 18946:tid 19161] [client 40.81.232.68:56456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxdIzqiPMah0Tz_U1Ol3QAAAV8"], referer: binance.com
[Thu Sep 17 15:35:31.791894 2026] [security2:error] [pid 18946:tid 19185] [client 49.13.164.148:27666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "i.am.tengushee.com"] [uri "/index.html"] [unique_id "aqxdIzqiPMah0Tz_U1Ol3wAAAXc"], referer: http://i.am.tengushee.com
[Thu Sep 17 15:35:31.924563 2026] [security2:error] [pid 18946:tid 19091] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdIzqiPMah0Tz_U1Ol4gAAARk"]
[Thu Sep 17 15:35:32.284358 2026] [security2:error] [pid 18946:tid 19104] [client 52.28.162.93:9940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.endless-chronicles.com"] [uri "/index.php"] [unique_id "aqxdJDqiPMah0Tz_U1Ol6QAAASY"], referer: http://www.endless-chronicles.com
[Thu Sep 17 15:35:33.083888 2026] [security2:error] [pid 20162:tid 20383] [client 136.158.61.34:5124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdJa-O_Kk7aqBvaiGAVAAAAek"]
[Thu Sep 17 15:35:33.084023 2026] [security2:error] [pid 20162:tid 20383] [client 136.158.61.34:5124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdJa-O_Kk7aqBvaiGAVAAAAek"]
[Thu Sep 17 15:35:33.271550 2026] [security2:error] [pid 20162:tid 20341] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdJa-O_Kk7aqBvaiGAVQAAAb8"]
[Thu Sep 17 15:35:33.297411 2026] [authz_core:error] [pid 20162:tid 20336] [client 169.58.197.253:59003] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:35:33.392695 2026] [security2:error] [pid 18946:tid 19202] [client 177.44.133.72:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdJTqiPMah0Tz_U1OmAgAAAYg"]
[Thu Sep 17 15:35:33.392787 2026] [security2:error] [pid 18946:tid 19202] [client 177.44.133.72:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdJTqiPMah0Tz_U1OmAgAAAYg"]
[Thu Sep 17 15:35:33.623852 2026] [security2:error] [pid 18946:tid 19088] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdJTqiPMah0Tz_U1OmBAAAARY"]
[Thu Sep 17 15:35:33.940316 2026] [security2:error] [pid 20162:tid 20410] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdJa-O_Kk7aqBvaiGAWwAAAgQ"]
[Thu Sep 17 15:35:34.734031 2026] [security2:error] [pid 18946:tid 19175] [client 186.208.87.134:52354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdJjqiPMah0Tz_U1OmEwABbX4"]
[Thu Sep 17 15:35:35.544411 2026] [security2:error] [pid 18946:tid 19140] [client 127.0.0.1:12424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxdJzqiPMah0Tz_U1OmMgAAAUo"]
[Thu Sep 17 15:35:35.544476 2026] [security2:error] [pid 18946:tid 19130] [client 127.0.0.1:12410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.alanpeckolick.com"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxdJzqiPMah0Tz_U1OmMQAAAUA"]
[Thu Sep 17 15:35:35.544718 2026] [security2:error] [pid 20162:tid 20323] [client 74.7.228.44:45456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.alanpeckolick.com"] [uri "/robots.txt"] [unique_id "aqxdJ6-O_Kk7aqBvaiGAYwABrTU"]
[Thu Sep 17 15:35:35.577026 2026] [security2:error] [pid 18946:tid 19091] [client 103.61.184.148:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdJzqiPMah0Tz_U1OmNwAAARk"]
[Thu Sep 17 15:35:35.577356 2026] [security2:error] [pid 18946:tid 19091] [client 103.61.184.148:57458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdJzqiPMah0Tz_U1OmNwAAARk"]
[Thu Sep 17 15:35:35.772205 2026] [security2:error] [pid 18946:tid 19170] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/.env"] [unique_id "aqxdJzqiPMah0Tz_U1OmPwAAAWg"]
[Thu Sep 17 15:35:35.812409 2026] [security2:error] [pid 18946:tid 19090] [client 40.81.232.68:51709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxdJzqiPMah0Tz_U1OmQAAAARg"], referer: binance.com
[Thu Sep 17 15:35:36.133926 2026] [security2:error] [pid 20162:tid 20405] [client 114.119.155.121:53635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tutorialsphere.com"] [uri "/tutorial/flash/3d/5797/how-to-make-3d-wall-flash-photo-gallery"] [unique_id "aqxdKK-O_Kk7aqBvaiGAZwAAAf8"], referer: https://www.flashslideshow-maker.com/flash-xml-image-wall-with-text.html
[Thu Sep 17 15:35:36.659216 2026] [security2:error] [pid 18946:tid 19135] [client 156.199.21.151:40998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdKDqiPMah0Tz_U1OmUgABRWg"]
[Thu Sep 17 15:35:36.770479 2026] [security2:error] [pid 18946:tid 19077] [client 34.95.14.119:57624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/"] [unique_id "aqxdKDqiPMah0Tz_U1OmWgAAAQs"]
[Thu Sep 17 15:35:37.023253 2026] [security2:error] [pid 18946:tid 19076] [client 34.95.14.119:57628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/"] [unique_id "aqxdKTqiPMah0Tz_U1OmXgAAAQo"]
[Thu Sep 17 15:35:37.156544 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/.env.bak"] [unique_id "aqxdKTqiPMah0Tz_U1OmXwAAASk"]
[Thu Sep 17 15:35:37.311942 2026] [security2:error] [pid 18946:tid 19164] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/.env.backup"] [unique_id "aqxdKTqiPMah0Tz_U1OmZgAAAWI"]
[Thu Sep 17 15:35:37.409398 2026] [security2:error] [pid 18946:tid 19177] [client 34.95.14.119:57644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/"] [unique_id "aqxdKTqiPMah0Tz_U1OmZwAAAW8"]
[Thu Sep 17 15:35:37.662084 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/.env.old"] [unique_id "aqxdKTqiPMah0Tz_U1OmbAAAAT0"]
[Thu Sep 17 15:35:37.701568 2026] [security2:error] [pid 18946:tid 19189] [client 79.116.89.151:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdKTqiPMah0Tz_U1OmbQAAAXs"]
[Thu Sep 17 15:35:37.701676 2026] [security2:error] [pid 18946:tid 19189] [client 79.116.89.151:55280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdKTqiPMah0Tz_U1OmbQAAAXs"]
[Thu Sep 17 15:35:37.744868 2026] [security2:error] [pid 18946:tid 19176] [client 143.105.152.240:60336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdKTqiPMah0Tz_U1OmcAAAAW4"]
[Thu Sep 17 15:35:37.754311 2026] [security2:error] [pid 18946:tid 19176] [client 143.105.152.240:60336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdKTqiPMah0Tz_U1OmcAAAAW4"]
[Thu Sep 17 15:35:37.837998 2026] [security2:error] [pid 18946:tid 19122] [client 34.95.14.119:57658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/"] [unique_id "aqxdKTqiPMah0Tz_U1OmdgAAATg"]
[Thu Sep 17 15:35:39.220653 2026] [security2:error] [pid 18946:tid 19125] [client 114.119.128.14:29279] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.endless-chronicles.com"] [uri "/"] [unique_id "aqxdKzqiPMah0Tz_U1OmpwAAATs"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:35:39.330416 2026] [security2:error] [pid 18946:tid 19106] [client 114.119.134.110:39701] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "devilsarmynetwork.com"] [uri "/vanecek-and-hughes-carry-devils-to-victory/"] [unique_id "aqxdKzqiPMah0Tz_U1OmrQAAASg"], referer: https://www.puckalytics.com/players/vitek-vanecek-8477970
[Thu Sep 17 15:35:40.043510 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/.env.swp"] [unique_id "aqxdLDqiPMah0Tz_U1OmyAAAAXc"]
[Thu Sep 17 15:35:40.085379 2026] [security2:error] [pid 18946:tid 19109] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdKzqiPMah0Tz_U1OmxgAAASs"]
[Thu Sep 17 15:35:40.203906 2026] [security2:error] [pid 18946:tid 19156] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/.env~"] [unique_id "aqxdLDqiPMah0Tz_U1OmzQAAAVo"]
[Thu Sep 17 15:35:40.576098 2026] [security2:error] [pid 18946:tid 19099] [client 40.81.232.68:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxdLDqiPMah0Tz_U1Om1gAAASE"], referer: binance.com
[Thu Sep 17 15:35:41.196455 2026] [security2:error] [pid 20162:tid 20420] [client 51.38.187.130:41480] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1452"] [id "9011111"] [msg "SQUID data collection"] [hostname "starrjoyblog.com"] [uri "/"] [unique_id "aqxdLa-O_Kk7aqBvaiGAhwAAAg4"]
[Thu Sep 17 15:35:41.624866 2026] [security2:error] [pid 18946:tid 19112] [client 114.198.138.124:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdLTqiPMah0Tz_U1Om_QAAAS4"]
[Thu Sep 17 15:35:41.628241 2026] [security2:error] [pid 18946:tid 19112] [client 114.198.138.124:64868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdLTqiPMah0Tz_U1Om_QAAAS4"]
[Thu Sep 17 15:35:41.761369 2026] [security2:error] [pid 18946:tid 19140] [client 114.119.155.118:35387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "enchantedpapers.com"] [uri "/k8rg4/tcole-3186-online.html"] [unique_id "aqxdLTqiPMah0Tz_U1OnAgAAAUo"], referer: http://enchantedpapers.com/k8rg4/tcole-3186-online.html
[Thu Sep 17 15:35:41.771914 2026] [security2:error] [pid 18946:tid 19160] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/app/.env"] [unique_id "aqxdLTqiPMah0Tz_U1OnAwAAAV4"]
[Thu Sep 17 15:35:41.834867 2026] [security2:error] [pid 18946:tid 19086] [client 114.119.128.35:25873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lemuspools.com"] [uri "/R-Industrial-Strength-Mini-Stretch-Wrap-Film-With-392288/"] [unique_id "aqxdLTqiPMah0Tz_U1OnBQAAARQ"], referer: https://lemuspools.com/R-Industrial-Strength-Mini-Stretch-Wrap-Film-With-392288/
[Thu Sep 17 15:35:41.928503 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/apps/.env"] [unique_id "aqxdLTqiPMah0Tz_U1OnBwAAAQ0"]
[Thu Sep 17 15:35:42.023216 2026] [security2:error] [pid 18946:tid 19129] [client 114.119.136.134:36465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "frenchtutoringfun.com"] [uri "/talk-about-what-you-like-doing-in-french/"] [unique_id "aqxdLjqiPMah0Tz_U1OnCAAAAT8"], referer: https://frenchtutoringfun.com/ecriture-inclusive/
[Thu Sep 17 15:35:42.088705 2026] [security2:error] [pid 18946:tid 19164] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/api/.env"] [unique_id "aqxdLjqiPMah0Tz_U1OnCQAAAWI"]
[Thu Sep 17 15:35:42.162917 2026] [security2:error] [pid 18946:tid 19111] [client 14.96.156.146:62260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdLjqiPMah0Tz_U1OnDQAAAS0"]
[Thu Sep 17 15:35:42.163033 2026] [security2:error] [pid 18946:tid 19111] [client 14.96.156.146:62260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdLjqiPMah0Tz_U1OnDQAAAS0"]
[Thu Sep 17 15:35:42.265471 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/web/.env"] [unique_id "aqxdLjqiPMah0Tz_U1OnDwAAAYE"]
[Thu Sep 17 15:35:42.423175 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/site/.env"] [unique_id "aqxdLjqiPMah0Tz_U1OnEwAAAS8"]
[Thu Sep 17 15:35:42.583585 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/public/.env"] [unique_id "aqxdLjqiPMah0Tz_U1OnFQAAAWQ"]
[Thu Sep 17 15:35:42.935166 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/backend/.env"] [unique_id "aqxdLjqiPMah0Tz_U1OnIAAAAXI"]
[Thu Sep 17 15:35:43.010170 2026] [security2:error] [pid 18946:tid 19115] [client 114.119.158.94:40907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freemarkjordan.com"] [uri "/wp-trades/bi-quyet-thang-lon-khi-danh-bai-tu-co-ban-den-chien-thuat-cao-cap-2025-07-03-14"] [unique_id "aqxdLzqiPMah0Tz_U1OnIQAAATE"], referer: https://www.thaibinhweb.net/wp-posts/sex-ko-che-vn-bi-chien-thang-cau-chuyen-thu-vi-26-07-2025
[Thu Sep 17 15:35:43.091204 2026] [security2:error] [pid 18946:tid 19099] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/server/.env"] [unique_id "aqxdLzqiPMah0Tz_U1OnIwAAASE"]
[Thu Sep 17 15:35:43.234076 2026] [security2:error] [pid 18946:tid 19198] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdLzqiPMah0Tz_U1OnJwAAAYQ"]
[Thu Sep 17 15:35:43.250302 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/frontend/.env"] [unique_id "aqxdLzqiPMah0Tz_U1OnLAAAAR4"]
[Thu Sep 17 15:35:43.406728 2026] [security2:error] [pid 18946:tid 19168] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/src/.env"] [unique_id "aqxdLzqiPMah0Tz_U1OnLgAAAWY"]
[Thu Sep 17 15:35:43.534998 2026] [security2:error] [pid 20162:tid 20387] [client 177.74.208.0:47128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdL6-O_Kk7aqBvaiGAkAAB7QY"]
[Thu Sep 17 15:35:43.541349 2026] [security2:error] [pid 20162:tid 20419] [client 206.62.142.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "scadalogik.com"] [uri "/index.php"] [unique_id "aqxdK6-O_Kk7aqBvaiGAcAAAAg0"], referer: https://scadalogik.company/
[Thu Sep 17 15:35:43.561231 2026] [security2:error] [pid 18946:tid 19192] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/core/.env"] [unique_id "aqxdLzqiPMah0Tz_U1OnMQAAAX4"]
[Thu Sep 17 15:35:43.714063 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/core/app/.env"] [unique_id "aqxdLzqiPMah0Tz_U1OnOAAAASQ"]
[Thu Sep 17 15:35:43.716781 2026] [security2:error] [pid 20162:tid 20313] [client 114.119.136.99:49039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "missglitterteaches.com"] [uri "/my-classroom-tour-revealed/"] [unique_id "aqxdL6-O_Kk7aqBvaiGAkgAAAaM"], referer: https://missglitterteaches.com/my-classroom-tour-revealed/
[Thu Sep 17 15:35:43.868112 2026] [security2:error] [pid 18946:tid 19084] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/config/.env"] [unique_id "aqxdLzqiPMah0Tz_U1OnOwAAARI"]
[Thu Sep 17 15:35:44.020713 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/private/.env"] [unique_id "aqxdMDqiPMah0Tz_U1OnQAAAAR0"]
[Thu Sep 17 15:35:44.059289 2026] [security2:error] [pid 20162:tid 20339] [client 177.44.133.72:50313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdMK-O_Kk7aqBvaiGAlAAAAb0"]
[Thu Sep 17 15:35:44.059438 2026] [security2:error] [pid 20162:tid 20339] [client 177.44.133.72:50313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdMK-O_Kk7aqBvaiGAlAAAAb0"]
[Thu Sep 17 15:35:44.088086 2026] [security2:error] [pid 20162:tid 20302] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdL6-O_Kk7aqBvaiGAkwAAAZg"]
[Thu Sep 17 15:35:44.172878 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/application/.env"] [unique_id "aqxdMDqiPMah0Tz_U1OnRwAAAWA"]
[Thu Sep 17 15:35:44.329758 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/bootstrap/.env"] [unique_id "aqxdMDqiPMah0Tz_U1OnSwAAAUc"]
[Thu Sep 17 15:35:44.484889 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/database/.env"] [unique_id "aqxdMDqiPMah0Tz_U1OnTQAAAXQ"]
[Thu Sep 17 15:35:44.640196 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/storage/.env"] [unique_id "aqxdMDqiPMah0Tz_U1OnUwAAAT8"]
[Thu Sep 17 15:35:44.806427 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/var/www/.env"] [unique_id "aqxdMDqiPMah0Tz_U1OnWQAAAYE"]
[Thu Sep 17 15:35:44.968071 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/var/www/html/.env"] [unique_id "aqxdMDqiPMah0Tz_U1OnYAAAAS8"]
[Thu Sep 17 15:35:45.041472 2026] [security2:error] [pid 18946:tid 19177] [client 114.119.139.42:25275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kevinsundberg.com"] [uri "/postalcode/n3c0g4/"] [unique_id "aqxdMTqiPMah0Tz_U1OnYQAAAW8"], referer: https://kevinsundberg.com/postalcode/n3c0g4/
[Thu Sep 17 15:35:45.127571 2026] [security2:error] [pid 18946:tid 19150] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/current/.env"] [unique_id "aqxdMTqiPMah0Tz_U1OnZAAAAVQ"]
[Thu Sep 17 15:35:45.282400 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/release/.env"] [unique_id "aqxdMTqiPMah0Tz_U1OnbgAAAYk"]
[Thu Sep 17 15:35:45.410389 2026] [security2:error] [pid 18946:tid 19108] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdMTqiPMah0Tz_U1OncAAAASo"]
[Thu Sep 17 15:35:45.442463 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/releases/.env"] [unique_id "aqxdMTqiPMah0Tz_U1OndgAAAYc"]
[Thu Sep 17 15:35:45.607088 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/shared/.env"] [unique_id "aqxdMTqiPMah0Tz_U1OnfAAAAX0"]
[Thu Sep 17 15:35:45.643468 2026] [security2:error] [pid 18946:tid 19104] [client 136.158.61.34:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdMTqiPMah0Tz_U1OnfgAAASY"]
[Thu Sep 17 15:35:45.643593 2026] [security2:error] [pid 18946:tid 19104] [client 136.158.61.34:6134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdMTqiPMah0Tz_U1OnfgAAASY"]
[Thu Sep 17 15:35:45.668925 2026] [security2:error] [pid 18946:tid 19145] [client 18.183.1.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdMTqiPMah0Tz_U1OneAAAAU8"]
[Thu Sep 17 15:35:45.766598 2026] [security2:error] [pid 18946:tid 19168] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/deploy/.env"] [unique_id "aqxdMTqiPMah0Tz_U1OnhAAAAWY"]
[Thu Sep 17 15:35:45.795861 2026] [security2:error] [pid 20162:tid 20392] [client 114.119.154.13:39039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "daprayer.com"] [uri "/workshop-review-book-binding-workshop-by-the-thistle-bindery/"] [unique_id "aqxdMa-O_Kk7aqBvaiGAmgAAAfI"], referer: http://daprayer.com/workshop-review-book-binding-workshop-by-the-thistle-bindery
[Thu Sep 17 15:35:45.930806 2026] [security2:error] [pid 18946:tid 19173] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/build/.env"] [unique_id "aqxdMTqiPMah0Tz_U1OnjQAAAWs"]
[Thu Sep 17 15:35:45.981996 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/.env"] [unique_id "aqxdMTqiPMah0Tz_U1OnjgAAATc"]
[Thu Sep 17 15:35:46.086825 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/dist/.env"] [unique_id "aqxdMjqiPMah0Tz_U1OnlAAAAR0"]
[Thu Sep 17 15:35:46.099460 2026] [security2:error] [pid 18946:tid 19135] [client 40.81.232.68:57317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxdMjqiPMah0Tz_U1OnlQAAAUU"], referer: binance.com
[Thu Sep 17 15:35:46.214095 2026] [security2:error] [pid 18946:tid 19102] [client 103.61.184.148:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdMjqiPMah0Tz_U1OnnQAAASQ"]
[Thu Sep 17 15:35:46.214187 2026] [security2:error] [pid 18946:tid 19102] [client 103.61.184.148:58034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdMjqiPMah0Tz_U1OnnQAAASQ"]
[Thu Sep 17 15:35:46.239816 2026] [security2:error] [pid 18946:tid 19142] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/public_html/.env"] [unique_id "aqxdMjqiPMah0Tz_U1OnngAAAUw"]
[Thu Sep 17 15:35:46.321176 2026] [security2:error] [pid 20162:tid 20310] [client 34.154.243.210:34100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.ahmedteleb.com"] [uri "/"] [unique_id "aqxdMq-O_Kk7aqBvaiGApAAAAaA"]
[Thu Sep 17 15:35:46.356680 2026] [security2:error] [pid 20162:tid 20308] [client 13.196.165.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdMq-O_Kk7aqBvaiGAogAAAZ4"]
[Thu Sep 17 15:35:46.396719 2026] [security2:error] [pid 18946:tid 19076] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/htdocs/.env"] [unique_id "aqxdMjqiPMah0Tz_U1OnpAAAAQo"]
[Thu Sep 17 15:35:46.552636 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/www/.env"] [unique_id "aqxdMjqiPMah0Tz_U1OnqgAAARQ"]
[Thu Sep 17 15:35:46.640641 2026] [security2:error] [pid 20162:tid 20354] [client 166.199.242.33:17577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxdMq-O_Kk7aqBvaiGApgABzD8"]
[Thu Sep 17 15:35:46.687388 2026] [security2:error] [pid 18946:tid 19160] [client 74.7.230.32:52538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/index.php"] [unique_id "aqxdMjqiPMah0Tz_U1OnqwABXho"]
[Thu Sep 17 15:35:46.705749 2026] [security2:error] [pid 18946:tid 19118] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/html/.env"] [unique_id "aqxdMjqiPMah0Tz_U1OnswAAATQ"]
[Thu Sep 17 15:35:46.793010 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.243.210:34106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.ahmedteleb.com"] [uri "/"] [unique_id "aqxdMjqiPMah0Tz_U1OnugAAAUQ"]
[Thu Sep 17 15:35:46.861108 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/live/.env"] [unique_id "aqxdMjqiPMah0Tz_U1OnvAAAAS8"]
[Thu Sep 17 15:35:46.951541 2026] [security2:error] [pid 18946:tid 19150] [client 114.119.148.108:60085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kopecdental.com"] [uri "/patient-information/technology"] [unique_id "aqxdMjqiPMah0Tz_U1OnwQAAAVQ"], referer: https://kopecdental.com/tag/dental-emergencies/page/2
[Thu Sep 17 15:35:47.022067 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/prod/.env"] [unique_id "aqxdMzqiPMah0Tz_U1OnxAAAAYk"]
[Thu Sep 17 15:35:47.034809 2026] [security2:error] [pid 18946:tid 19185] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdMjqiPMah0Tz_U1OnwAAAAXc"]
[Thu Sep 17 15:35:47.180319 2026] [security2:error] [pid 18946:tid 19124] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/dev/.env"] [unique_id "aqxdMzqiPMah0Tz_U1OnzQAAATo"]
[Thu Sep 17 15:35:47.297162 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.243.210:34112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.ahmedteleb.com"] [uri "/"] [unique_id "aqxdMzqiPMah0Tz_U1On0gAAAUI"]
[Thu Sep 17 15:35:47.334311 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/staging/.env"] [unique_id "aqxdMzqiPMah0Tz_U1On0wAAAWc"]
[Thu Sep 17 15:35:47.358553 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/.env.bak"] [unique_id "aqxdMzqiPMah0Tz_U1On1AAAAXM"]
[Thu Sep 17 15:35:47.379212 2026] [security2:error] [pid 18946:tid 19115] [client 202.46.62.20:62853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdMzqiPMah0Tz_U1On0QABMU0"]
[Thu Sep 17 15:35:47.490843 2026] [security2:error] [pid 18946:tid 19173] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/opt/.env"] [unique_id "aqxdMzqiPMah0Tz_U1On3AAAAWs"]
[Thu Sep 17 15:35:47.511475 2026] [security2:error] [pid 18946:tid 19131] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/.env.backup"] [unique_id "aqxdMzqiPMah0Tz_U1On3QAAAUE"]
[Thu Sep 17 15:35:47.566140 2026] [security2:error] [pid 18946:tid 19192] [client 74.7.244.5:60418] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.impactreliability.com"] [uri "/index.php"] [unique_id "aqxdMzqiPMah0Tz_U1On2AABfhQ"]
[Thu Sep 17 15:35:47.566164 2026] [security2:error] [pid 18946:tid 19192] [client 74.7.244.5:60418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.impactreliability.com"] [uri "/index.php"] [unique_id "aqxdMzqiPMah0Tz_U1On2AABfhQ"]
[Thu Sep 17 15:35:47.650368 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/laravel/.env"] [unique_id "aqxdMzqiPMah0Tz_U1On4QAAAR0"]
[Thu Sep 17 15:35:47.814381 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.219.249:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/symfony/.env"] [unique_id "aqxdMzqiPMah0Tz_U1On7wAAAQw"]
[Thu Sep 17 15:35:47.836063 2026] [security2:error] [pid 18946:tid 19087] [client 95.247.68.20:61793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdMzqiPMah0Tz_U1On6AABFWE"]
[Thu Sep 17 15:35:47.860203 2026] [security2:error] [pid 18946:tid 19139] [client 74.7.244.5:60422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "impactreliability.com"] [uri "/index.php"] [unique_id "aqxdMzqiPMah0Tz_U1On5wABSSY"], referer: https://www.impactreliability.com/robots.txt
[Thu Sep 17 15:35:47.877805 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/.env.old"] [unique_id "aqxdMzqiPMah0Tz_U1On8AAAAXo"]
[Thu Sep 17 15:35:48.185737 2026] [security2:error] [pid 18946:tid 19091] [client 114.119.134.3:20291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "relvnv.com"] [uri "/2019/01/08/selling-a-home"] [unique_id "aqxdNDqiPMah0Tz_U1On_AAAARk"], referer: https://relvnv.com/2019/01/08/selling-a-home
[Thu Sep 17 15:35:48.289131 2026] [security2:error] [pid 18946:tid 19081] [client 210.222.43.21:60551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdNDqiPMah0Tz_U1On-gAAAQ8"], referer: http://talent-in-borders.com/bac
[Thu Sep 17 15:35:48.289439 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/wordpress/.env"] [unique_id "aqxdNDqiPMah0Tz_U1OoAgAAAVg"]
[Thu Sep 17 15:35:48.309320 2026] [security2:error] [pid 18946:tid 19093] [client 143.105.152.240:63295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdNDqiPMah0Tz_U1OoAwAAARs"]
[Thu Sep 17 15:35:48.315819 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.243.210:34132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autodiscover.ahmedteleb.com"] [uri "/"] [unique_id "aqxdNDqiPMah0Tz_U1OoBAAAAWA"]
[Thu Sep 17 15:35:48.317023 2026] [security2:error] [pid 18946:tid 19093] [client 143.105.152.240:63295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdNDqiPMah0Tz_U1OoAwAAARs"]
[Thu Sep 17 15:35:48.343015 2026] [security2:error] [pid 18946:tid 19182] [client 79.116.89.151:55895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdNDqiPMah0Tz_U1OoBQAAAXQ"]
[Thu Sep 17 15:35:48.343538 2026] [security2:error] [pid 18946:tid 19182] [client 79.116.89.151:55895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdNDqiPMah0Tz_U1OoBQAAAXQ"]
[Thu Sep 17 15:35:48.451055 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/wp/.env"] [unique_id "aqxdNDqiPMah0Tz_U1OoCgAAAWE"]
[Thu Sep 17 15:35:48.608237 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cms/.env"] [unique_id "aqxdNDqiPMah0Tz_U1OoDQAAAXc"]
[Thu Sep 17 15:35:48.762219 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/drupal/.env"] [unique_id "aqxdNDqiPMah0Tz_U1OoFQAAAXI"]
[Thu Sep 17 15:35:48.825643 2026] [security2:error] [pid 18946:tid 19152] [client 34.154.243.210:34140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/.env"] [unique_id "aqxdNDqiPMah0Tz_U1OoGQAAAVY"]
[Thu Sep 17 15:35:48.916811 2026] [security2:error] [pid 18946:tid 19104] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/joomla/.env"] [unique_id "aqxdNDqiPMah0Tz_U1OoHQAAASY"]
[Thu Sep 17 15:35:49.071791 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/magento/.env"] [unique_id "aqxdNTqiPMah0Tz_U1OoIwAAAUI"]
[Thu Sep 17 15:35:49.231144 2026] [security2:error] [pid 18946:tid 19115] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/shopify/.env"] [unique_id "aqxdNTqiPMah0Tz_U1OoKwAAATE"]
[Thu Sep 17 15:35:49.385862 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/prestashop/.env"] [unique_id "aqxdNTqiPMah0Tz_U1OoMQAAAUY"]
[Thu Sep 17 15:35:49.538840 2026] [security2:error] [pid 18946:tid 19192] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/codeigniter/.env"] [unique_id "aqxdNTqiPMah0Tz_U1OoOAAAAX4"]
[Thu Sep 17 15:35:49.600777 2026] [security2:error] [pid 18946:tid 19125] [client 114.119.137.160:52281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "troopkcampcadet.com"] [uri "/wp-content/uploads/photo-gallery/phila_19/16620175-645B-4614-99B2-8493462882A7.jpeg"] [unique_id "aqxdNTqiPMah0Tz_U1OoOwAAATs"], referer: https://troopkcampcadet.com/bwg_gallery/day-3-2019/?page_number_0=2
[Thu Sep 17 15:35:49.693390 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cakephp/.env"] [unique_id "aqxdNTqiPMah0Tz_U1OoQgAAAQw"]
[Thu Sep 17 15:35:49.848093 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/zend/.env"] [unique_id "aqxdNTqiPMah0Tz_U1OoRgAAARg"]
[Thu Sep 17 15:35:50.006345 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/yii/.env"] [unique_id "aqxdNjqiPMah0Tz_U1OoSwAAAV0"]
[Thu Sep 17 15:35:50.039215 2026] [security2:error] [pid 18946:tid 19076] [client 93.138.73.102:58612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdNTqiPMah0Tz_U1OoSgABClo"]
[Thu Sep 17 15:35:50.159555 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/laravel5/.env"] [unique_id "aqxdNjqiPMah0Tz_U1OoVQAAAQ4"]
[Thu Sep 17 15:35:50.275013 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/.env.swp"] [unique_id "aqxdNjqiPMah0Tz_U1OoVwAAAVM"]
[Thu Sep 17 15:35:50.317742 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/v1/.env"] [unique_id "aqxdNjqiPMah0Tz_U1OoWQAAAQ8"]
[Thu Sep 17 15:35:50.430457 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/.env~"] [unique_id "aqxdNjqiPMah0Tz_U1OoXAAAAYE"]
[Thu Sep 17 15:35:50.471419 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/v2/.env"] [unique_id "aqxdNjqiPMah0Tz_U1OoXQAAAW4"]
[Thu Sep 17 15:35:50.632376 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/v3/.env"] [unique_id "aqxdNjqiPMah0Tz_U1OoZQAAAVw"]
[Thu Sep 17 15:35:50.788064 2026] [security2:error] [pid 18946:tid 19177] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/api/v1/.env"] [unique_id "aqxdNjqiPMah0Tz_U1OobAAAAW8"]
[Thu Sep 17 15:35:50.805489 2026] [security2:error] [pid 20162:tid 20384] [client 40.81.232.68:52715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxdNq-O_Kk7aqBvaiGAugAAAeo"], referer: binance.com
[Thu Sep 17 15:35:50.868918 2026] [security2:error] [pid 18946:tid 19088] [client 114.119.143.213:24601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sqlerudition.com"] [uri "/sql-server-2008-microsoft-certified-master-mcm-readiness-videos"] [unique_id "aqxdNjqiPMah0Tz_U1OocAAAARY"], referer: http://www.sqlerudition.com/sql-server-2008-microsoft-certified-master-mcm-readiness-videos?share=skyp
[Thu Sep 17 15:35:50.949251 2026] [security2:error] [pid 18946:tid 19196] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/api/v2/.env"] [unique_id "aqxdNjqiPMah0Tz_U1OocgAAAYI"]
[Thu Sep 17 15:35:50.990584 2026] [authz_core:error] [pid 18946:tid 19180] [client 169.58.197.253:60063] AH01630: client denied by server configuration: /home1/geekngam/public_html/ppfc/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:35:51.105735 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/rest/.env"] [unique_id "aqxdNzqiPMah0Tz_U1OoewAAAUg"]
[Thu Sep 17 15:35:51.267072 2026] [security2:error] [pid 18946:tid 19103] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/graphql/.env"] [unique_id "aqxdNzqiPMah0Tz_U1OogwAAASU"]
[Thu Sep 17 15:35:51.421635 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/gateway/.env"] [unique_id "aqxdNzqiPMah0Tz_U1OoiAAAAYQ"]
[Thu Sep 17 15:35:51.576107 2026] [security2:error] [pid 18946:tid 19110] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/microservice/.env"] [unique_id "aqxdNzqiPMah0Tz_U1OokAAAASw"]
[Thu Sep 17 15:35:51.616337 2026] [security2:error] [pid 18946:tid 19151] [client 216.73.216.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iradtech.com"] [uri "/index.php"] [unique_id "aqxdNTqiPMah0Tz_U1OoLwAAAVU"], referer: http://www.iradtech.com/robots.txt
[Thu Sep 17 15:35:51.731113 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/service/.env"] [unique_id "aqxdNzqiPMah0Tz_U1OomQAAAYg"]
[Thu Sep 17 15:35:51.757546 2026] [security2:error] [pid 18946:tid 19125] [client 93.138.73.102:58612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdNzqiPMah0Tz_U1OolgABO0U"]
[Thu Sep 17 15:35:51.889025 2026] [security2:error] [pid 18946:tid 19083] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/api/v3/.env"] [unique_id "aqxdNzqiPMah0Tz_U1OonwAAARE"]
[Thu Sep 17 15:35:51.941451 2026] [cgid:error] [pid 18946:tid 18991] [remote 216.73.217.169:57342] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml, referer: http://www.tutorialsphere.com/sitemap.xml
[Thu Sep 17 15:35:51.980859 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/app/.env"] [unique_id "aqxdNzqiPMah0Tz_U1OopwAAASk"]
[Thu Sep 17 15:35:52.042742 2026] [security2:error] [pid 18946:tid 19160] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/api/dev/.env"] [unique_id "aqxdODqiPMah0Tz_U1OoqAAAAV4"]
[Thu Sep 17 15:35:52.144852 2026] [security2:error] [pid 18946:tid 19157] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/apps/.env"] [unique_id "aqxdODqiPMah0Tz_U1OoqQAAAVs"]
[Thu Sep 17 15:35:52.167461 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.243.210:34190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/.env.bak"] [unique_id "aqxdODqiPMah0Tz_U1OoqwAAARk"]
[Thu Sep 17 15:35:52.196956 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/api/staging/.env"] [unique_id "aqxdODqiPMah0Tz_U1OorgAAAQ0"]
[Thu Sep 17 15:35:52.303765 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/api/.env"] [unique_id "aqxdODqiPMah0Tz_U1OosQAAAS4"]
[Thu Sep 17 15:35:52.313217 2026] [security2:error] [pid 18946:tid 19080] [client 114.198.138.124:60995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdODqiPMah0Tz_U1OosgAAAQ4"]
[Thu Sep 17 15:35:52.313310 2026] [security2:error] [pid 18946:tid 19080] [client 114.198.138.124:60995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdODqiPMah0Tz_U1OosgAAAQ4"]
[Thu Sep 17 15:35:52.341369 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.243.210:34190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/.env.backup"] [unique_id "aqxdODqiPMah0Tz_U1OoswAAAWA"]
[Thu Sep 17 15:35:52.352931 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/vendor/.env"] [unique_id "aqxdODqiPMah0Tz_U1OotAAAAXQ"]
[Thu Sep 17 15:35:52.474755 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/web/.env"] [unique_id "aqxdODqiPMah0Tz_U1OotwAAAYE"]
[Thu Sep 17 15:35:52.480136 2026] [security2:error] [pid 18946:tid 19128] [client 52.167.144.150:57943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dfwservicesllc.com"] [uri "/index.php"] [unique_id "aqxdODqiPMah0Tz_U1OorAABPjg"]
[Thu Sep 17 15:35:52.505630 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/lib/.env"] [unique_id "aqxdODqiPMah0Tz_U1OouwAAARs"]
[Thu Sep 17 15:35:52.633642 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/site/.env"] [unique_id "aqxdODqiPMah0Tz_U1OowAAAAU0"]
[Thu Sep 17 15:35:52.665736 2026] [security2:error] [pid 18946:tid 19189] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/resources/.env"] [unique_id "aqxdODqiPMah0Tz_U1OowwAAAXs"]
[Thu Sep 17 15:35:52.793497 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/public/.env"] [unique_id "aqxdODqiPMah0Tz_U1OoxAAAAVA"]
[Thu Sep 17 15:35:52.819180 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/assets/.env"] [unique_id "aqxdODqiPMah0Tz_U1OoxgAAAXI"]
[Thu Sep 17 15:35:52.844055 2026] [security2:error] [pid 18946:tid 19193] [client 14.96.156.146:62888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdODqiPMah0Tz_U1OoyAAAAX8"]
[Thu Sep 17 15:35:52.844346 2026] [security2:error] [pid 18946:tid 19193] [client 14.96.156.146:62888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdODqiPMah0Tz_U1OoyAAAAX8"]
[Thu Sep 17 15:35:52.973022 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/uploads/.env"] [unique_id "aqxdODqiPMah0Tz_U1OozwAAATg"]
[Thu Sep 17 15:35:53.033143 2026] [security2:error] [pid 20162:tid 20415] [client 34.154.243.210:34192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/.env.old"] [unique_id "aqxdOa-O_Kk7aqBvaiGAvgAAAgk"]
[Thu Sep 17 15:35:53.134365 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/internal/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo1wAAAWc"]
[Thu Sep 17 15:35:53.152592 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/backend/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo2AAAAUs"]
[Thu Sep 17 15:35:53.289459 2026] [security2:error] [pid 18946:tid 19117] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/tools/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo3AAAATM"]
[Thu Sep 17 15:35:53.305202 2026] [security2:error] [pid 18946:tid 19110] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/server/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo3QAAASw"]
[Thu Sep 17 15:35:53.442125 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/scripts/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo4wAAATA"]
[Thu Sep 17 15:35:53.461726 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/frontend/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo5AAAAVE"]
[Thu Sep 17 15:35:53.598123 2026] [security2:error] [pid 18946:tid 19087] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/bin/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo7AAAARU"]
[Thu Sep 17 15:35:53.622317 2026] [security2:error] [pid 18946:tid 19170] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/src/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo7QAAAWg"]
[Thu Sep 17 15:35:53.687448 2026] [security2:error] [pid 18946:tid 19168] [client 114.119.145.188:32659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tradingmemories.net"] [uri "/client/photo/Z0F-JVF4/000-0000/4/344a22fb49b9750dd1dd1143b2162922"] [unique_id "aqxdOTqiPMah0Tz_U1Oo7wAAAWY"], referer: https://www.tradingmemories.net/client/photo/Z0F-JVF4/000-0000/4/db9c927efeaaef4b8b4ba025dbcd9f5f
[Thu Sep 17 15:35:53.752019 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/sbin/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo8AAAARg"]
[Thu Sep 17 15:35:53.784177 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/core/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo9QAAAVI"]
[Thu Sep 17 15:35:53.905506 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/local/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo_AAAASk"]
[Thu Sep 17 15:35:53.942130 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/core/app/.env"] [unique_id "aqxdOTqiPMah0Tz_U1Oo_gAAAT8"]
[Thu Sep 17 15:35:54.063507 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/portal/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpBQAAAQ8"]
[Thu Sep 17 15:35:54.066464 2026] [security2:error] [pid 18946:tid 19118] [client 162.241.226.11:40392] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxdOjqiPMah0Tz_U1OpAwAAATQ"]
[Thu Sep 17 15:35:54.099432 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/config/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpBgAAAQ4"]
[Thu Sep 17 15:35:54.230357 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/dashboard/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpCAAAAT4"]
[Thu Sep 17 15:35:54.257024 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/private/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpCgAAAR8"]
[Thu Sep 17 15:35:54.384078 2026] [security2:error] [pid 18946:tid 19194] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/panel/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpDwAAAYA"]
[Thu Sep 17 15:35:54.416670 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/application/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpEAAAAVw"]
[Thu Sep 17 15:35:54.551124 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/crm/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpFgAAAXc"]
[Thu Sep 17 15:35:54.585052 2026] [security2:error] [pid 18946:tid 19101] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/bootstrap/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpFwAAASM"]
[Thu Sep 17 15:35:54.633149 2026] [security2:error] [pid 18946:tid 19093] [client 177.44.133.72:50964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdOjqiPMah0Tz_U1OpGQAAARs"]
[Thu Sep 17 15:35:54.633279 2026] [security2:error] [pid 18946:tid 19093] [client 177.44.133.72:50964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdOjqiPMah0Tz_U1OpGQAAARs"]
[Thu Sep 17 15:35:54.713453 2026] [security2:error] [pid 18946:tid 19196] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/erp/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpGwAAAYI"]
[Thu Sep 17 15:35:54.754075 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/database/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpHAAAAW4"]
[Thu Sep 17 15:35:54.869628 2026] [security2:error] [pid 18946:tid 19179] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/shop/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpHwAAAXE"]
[Thu Sep 17 15:35:54.912701 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/storage/.env"] [unique_id "aqxdOjqiPMah0Tz_U1OpIwAAATg"]
[Thu Sep 17 15:35:55.032456 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/store/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpKAAAATI"]
[Thu Sep 17 15:35:55.072694 2026] [security2:error] [pid 18946:tid 19199] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/var/www/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpKQAAAYU"]
[Thu Sep 17 15:35:55.194845 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/saas/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpLAAAASo"]
[Thu Sep 17 15:35:55.229888 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/var/www/html/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpLgAAAYY"]
[Thu Sep 17 15:35:55.361122 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/client/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpMQAAAU8"]
[Thu Sep 17 15:35:55.396521 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/current/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpMgAAARA"]
[Thu Sep 17 15:35:55.523472 2026] [security2:error] [pid 18946:tid 19173] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/project/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpOgAAAWs"]
[Thu Sep 17 15:35:55.555390 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/release/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpOwAAATc"]
[Thu Sep 17 15:35:55.630325 2026] [security2:error] [pid 20162:tid 20372] [client 40.81.232.68:50073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxdO6-O_Kk7aqBvaiGAxwAAAd4"], referer: binance.com
[Thu Sep 17 15:35:55.685942 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/admin-panel/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpQwAAAUY"]
[Thu Sep 17 15:35:55.720462 2026] [security2:error] [pid 18946:tid 19170] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/releases/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpRQAAAWg"]
[Thu Sep 17 15:35:55.850364 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/control-panel/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpSwAAAUc"]
[Thu Sep 17 15:35:55.883550 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/shared/.env"] [unique_id "aqxdOzqiPMah0Tz_U1OpTAAAAVI"]
[Thu Sep 17 15:35:55.930311 2026] [security2:error] [pid 18946:tid 19078] [client 114.119.153.53:61079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.norifon.com"] [uri "/fujifilm"] [unique_id "aqxdOzqiPMah0Tz_U1OpTQAAAQw"], referer: https://www.norifon.com/fujifilm
[Thu Sep 17 15:35:56.008550 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/user-panel/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpUgAAAXo"]
[Thu Sep 17 15:35:56.039690 2026] [security2:error] [pid 18946:tid 19183] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/deploy/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpVgAAAXU"]
[Thu Sep 17 15:35:56.157847 2026] [security2:error] [pid 18946:tid 19157] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdPDqiPMah0Tz_U1OpWgAAAVs"]
[Thu Sep 17 15:35:56.168422 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/node/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpWwAAAVM"]
[Thu Sep 17 15:35:56.197109 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/build/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpXQAAAQ8"]
[Thu Sep 17 15:35:56.336468 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/express/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpYAAAAVg"]
[Thu Sep 17 15:35:56.354026 2026] [security2:error] [pid 18946:tid 19155] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/dist/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpYQAAAVk"]
[Thu Sep 17 15:35:56.496483 2026] [security2:error] [pid 18946:tid 19165] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/next/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpZAAAAWM"]
[Thu Sep 17 15:35:56.511045 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/public_html/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpaAAAAT4"]
[Thu Sep 17 15:35:56.524156 2026] [security2:error] [pid 18946:tid 19151] [client 216.73.216.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxdOzqiPMah0Tz_U1OpQgAAAVU"], referer: https://www.iradtech.com/robots.txt
[Thu Sep 17 15:35:56.659895 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/nuxt/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpcAAAAU0"]
[Thu Sep 17 15:35:56.669387 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/htdocs/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpcgAAAUQ"]
[Thu Sep 17 15:35:56.828198 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/www/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpdwAAAS0"]
[Thu Sep 17 15:35:56.829569 2026] [security2:error] [pid 18946:tid 19164] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/nest/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpeAAAAWI"]
[Thu Sep 17 15:35:56.979356 2026] [security2:error] [pid 20162:tid 20369] [client 103.61.184.148:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdPK-O_Kk7aqBvaiGAyQAAAds"]
[Thu Sep 17 15:35:56.979447 2026] [security2:error] [pid 20162:tid 20369] [client 103.61.184.148:58606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdPK-O_Kk7aqBvaiGAyQAAAds"]
[Thu Sep 17 15:35:56.987283 2026] [security2:error] [pid 18946:tid 19179] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/react/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpfAAAAXE"]
[Thu Sep 17 15:35:56.988534 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/html/.env"] [unique_id "aqxdPDqiPMah0Tz_U1OpfQAAATg"]
[Thu Sep 17 15:35:57.142998 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/live/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpgwAAARM"]
[Thu Sep 17 15:35:57.145885 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/vue/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OphAAAASc"]
[Thu Sep 17 15:35:57.300688 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/prod/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpiwAAAUI"]
[Thu Sep 17 15:35:57.311421 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/angular/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpjAAAAUs"]
[Thu Sep 17 15:35:57.456971 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/dev/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpjgAAARA"]
[Thu Sep 17 15:35:57.469788 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/svelte/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpkAAAAXM"]
[Thu Sep 17 15:35:57.614809 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/staging/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OplQAAAVc"]
[Thu Sep 17 15:35:57.633876 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/vite/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OplgAAASQ"]
[Thu Sep 17 15:35:57.772272 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/opt/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpnAAAAUc"]
[Thu Sep 17 15:35:57.787493 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/backup/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpnQAAATU"]
[Thu Sep 17 15:35:57.860053 2026] [security2:error] [pid 18946:tid 19168] [client 69.165.72.149:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.72.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/index.php"] [unique_id "aqxdPTqiPMah0Tz_U1OpnwAAAWY"], referer: https://p3collaborative.com
[Thu Sep 17 15:35:57.881875 2026] [security2:error] [pid 18946:tid 19096] [client 114.119.133.76:51987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anniechenphotography.com"] [uri "/galleries/family-photography/"] [unique_id "aqxdPTqiPMah0Tz_U1OpoAAAAR4"], referer: https://anniechenphotography.com/galleries/family-photography/
[Thu Sep 17 15:35:57.926803 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/laravel/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpoQAAARw"]
[Thu Sep 17 15:35:57.944837 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/backups/.env"] [unique_id "aqxdPTqiPMah0Tz_U1OpogAAATs"]
[Thu Sep 17 15:35:57.963762 2026] [security2:error] [pid 20162:tid 20401] [client 136.158.61.34:7104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdPa-O_Kk7aqBvaiGA0AAAAfs"]
[Thu Sep 17 15:35:57.963878 2026] [security2:error] [pid 20162:tid 20401] [client 136.158.61.34:7104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdPa-O_Kk7aqBvaiGA0AAAAfs"]
[Thu Sep 17 15:35:58.088017 2026] [security2:error] [pid 18946:tid 19157] [client 34.154.21.169:37710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/symfony/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OppwAAAVs"]
[Thu Sep 17 15:35:58.102234 2026] [security2:error] [pid 18946:tid 19167] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/old/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OpqAAAAWU"]
[Thu Sep 17 15:35:58.263426 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/tmp/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OpqQAAAQ8"]
[Thu Sep 17 15:35:58.387366 2026] [security2:error] [pid 18946:tid 19083] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdPjqiPMah0Tz_U1OprAAAARE"]
[Thu Sep 17 15:35:58.417031 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/temp/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OpsAAAAYg"]
[Thu Sep 17 15:35:58.575243 2026] [security2:error] [pid 18946:tid 19151] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/lab/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OptAAAAVU"]
[Thu Sep 17 15:35:58.593280 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/wordpress/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OptQAAAQ4"]
[Thu Sep 17 15:35:58.742967 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cronlab/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OpuQAAAWA"]
[Thu Sep 17 15:35:58.750993 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/wp/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OpugAAAVw"]
[Thu Sep 17 15:35:58.898672 2026] [security2:error] [pid 18946:tid 19144] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cron/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OpvQAAAU4"]
[Thu Sep 17 15:35:58.914870 2026] [security2:error] [pid 18946:tid 19101] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cms/.env"] [unique_id "aqxdPjqiPMah0Tz_U1OpvgAAASM"]
[Thu Sep 17 15:35:58.960720 2026] [security2:error] [pid 18946:tid 19079] [client 143.105.152.240:39187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdPjqiPMah0Tz_U1OpwgAAAQ0"]
[Thu Sep 17 15:35:58.976539 2026] [security2:error] [pid 18946:tid 19079] [client 143.105.152.240:39187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdPjqiPMah0Tz_U1OpwgAAAQ0"]
[Thu Sep 17 15:35:59.053026 2026] [security2:error] [pid 18946:tid 19164] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/en/.env"] [unique_id "aqxdPzqiPMah0Tz_U1OpxwAAAWI"]
[Thu Sep 17 15:35:59.054405 2026] [security2:error] [pid 18946:tid 19182] [client 79.116.89.151:56501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdPzqiPMah0Tz_U1OpyQAAAXQ"]
[Thu Sep 17 15:35:59.054487 2026] [security2:error] [pid 18946:tid 19182] [client 79.116.89.151:56501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdPzqiPMah0Tz_U1OpyQAAAXQ"]
[Thu Sep 17 15:35:59.073414 2026] [security2:error] [pid 18946:tid 19194] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/drupal/.env"] [unique_id "aqxdPzqiPMah0Tz_U1OpywAAAYA"]
[Thu Sep 17 15:35:59.215058 2026] [security2:error] [pid 18946:tid 19180] [client 93.138.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jumpplot.com"] [uri "/index.php"] [unique_id "aqxdPzqiPMah0Tz_U1OpzAAAAXI"]
[Thu Sep 17 15:35:59.231537 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/joomla/.env"] [unique_id "aqxdPzqiPMah0Tz_U1OpzwAAARM"]
[Thu Sep 17 15:35:59.232588 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/administrator/.env"] [unique_id "aqxdPzqiPMah0Tz_U1OpzgAAAW4"]
[Thu Sep 17 15:35:59.387631 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/psnlink/.env"] [unique_id "aqxdPzqiPMah0Tz_U1Op0gAAAUg"]
[Thu Sep 17 15:35:59.394937 2026] [security2:error] [pid 18946:tid 19199] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/magento/.env"] [unique_id "aqxdPzqiPMah0Tz_U1Op0wAAAYU"]
[Thu Sep 17 15:35:59.524496 2026] [security2:error] [pid 20162:tid 20327] [client 34.154.243.210:55884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/.env.swp"] [unique_id "aqxdP6-O_Kk7aqBvaiGA4QAAAbE"]
[Thu Sep 17 15:35:59.557328 2026] [security2:error] [pid 18946:tid 19174] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/exapi/.env"] [unique_id "aqxdPzqiPMah0Tz_U1Op2QAAAWw"]
[Thu Sep 17 15:35:59.557330 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/shopify/.env"] [unique_id "aqxdPzqiPMah0Tz_U1Op2AAAAUI"]
[Thu Sep 17 15:35:59.701350 2026] [security2:error] [pid 20162:tid 20300] [client 34.154.243.210:55884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/.env~"] [unique_id "aqxdP6-O_Kk7aqBvaiGA4wAAAZY"]
[Thu Sep 17 15:35:59.717366 2026] [security2:error] [pid 18946:tid 19184] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/prestashop/.env"] [unique_id "aqxdPzqiPMah0Tz_U1Op3QAAAXY"]
[Thu Sep 17 15:35:59.718539 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/sitemaps/.env"] [unique_id "aqxdPzqiPMah0Tz_U1Op3wAAAW0"]
[Thu Sep 17 15:35:59.876671 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/codeigniter/.env"] [unique_id "aqxdPzqiPMah0Tz_U1Op4gAAATc"]
[Thu Sep 17 15:36:00.035003 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cakephp/.env"] [unique_id "aqxdQDqiPMah0Tz_U1Op7AAAAYM"]
[Thu Sep 17 15:36:00.191642 2026] [security2:error] [pid 18946:tid 19168] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/zend/.env"] [unique_id "aqxdQDqiPMah0Tz_U1Op8gAAAWY"]
[Thu Sep 17 15:36:00.261787 2026] [security2:error] [pid 18946:tid 19160] [client 34.154.219.249:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/logs/.env"] [unique_id "aqxdQDqiPMah0Tz_U1Op9AAAAV4"]
[Thu Sep 17 15:36:00.268553 2026] [security2:error] [pid 18946:tid 19086] [client 78.142.18.40:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.maggietheturtle.com"] [uri "/wp-login.php"] [unique_id "aqxdQDqiPMah0Tz_U1Op8wAAARQ"]
[Thu Sep 17 15:36:00.360053 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/yii/.env"] [unique_id "aqxdQDqiPMah0Tz_U1Op9QAAARc"]
[Thu Sep 17 15:36:00.522684 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/laravel5/.env"] [unique_id "aqxdQDqiPMah0Tz_U1Op_QAAAQ8"]
[Thu Sep 17 15:36:00.682358 2026] [security2:error] [pid 18946:tid 19083] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/v1/.env"] [unique_id "aqxdQDqiPMah0Tz_U1OqAQAAARE"]
[Thu Sep 17 15:36:00.730313 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cache/.env"] [unique_id "aqxdQDqiPMah0Tz_U1OqAgAAAXw"]
[Thu Sep 17 15:36:00.839650 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/v2/.env"] [unique_id "aqxdQDqiPMah0Tz_U1OqBAAAAYg"]
[Thu Sep 17 15:36:00.896741 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mailer/.env"] [unique_id "aqxdQDqiPMah0Tz_U1OqBwAAAQ4"]
[Thu Sep 17 15:36:00.997346 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/v3/.env"] [unique_id "aqxdQDqiPMah0Tz_U1OqCAAAAWA"]
[Thu Sep 17 15:36:01.057433 2026] [security2:error] [pid 18946:tid 19165] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mail/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqDwAAAWM"]
[Thu Sep 17 15:36:01.057506 2026] [security2:error] [pid 18946:tid 19203] [client 40.81.232.68:49267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxdQTqiPMah0Tz_U1OqEAAAAYk"], referer: binance.com
[Thu Sep 17 15:36:01.163976 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/api/v1/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqFQAAAXQ"]
[Thu Sep 17 15:36:01.211814 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/email/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqFgAAAR0"]
[Thu Sep 17 15:36:01.322017 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/api/v2/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqFwAAAVA"]
[Thu Sep 17 15:36:01.366237 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/smtp/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqGQAAAT0"]
[Thu Sep 17 15:36:01.490290 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/rest/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqGwAAATg"]
[Thu Sep 17 15:36:01.522170 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mailing/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqHwAAASo"]
[Thu Sep 17 15:36:01.538830 2026] [security2:error] [pid 18946:tid 19152] [client 86.137.69.19:52291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxdQTqiPMah0Tz_U1OqGAABVh0"]
[Thu Sep 17 15:36:01.652237 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/graphql/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqIQAAAXI"]
[Thu Sep 17 15:36:01.684038 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/notifications/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqIgAAATY"]
[Thu Sep 17 15:36:01.814568 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/gateway/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqKQAAARA"]
[Thu Sep 17 15:36:01.847618 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/notify/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqKgAAAXM"]
[Thu Sep 17 15:36:01.916314 2026] [security2:error] [pid 20162:tid 20385] [client 35.193.89.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdQa-O_Kk7aqBvaiGBAQAAAes"]
[Thu Sep 17 15:36:01.971650 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/microservice/.env"] [unique_id "aqxdQTqiPMah0Tz_U1OqLQAAATc"]
[Thu Sep 17 15:36:02.020372 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/sender/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqMQAAASQ"]
[Thu Sep 17 15:36:02.130805 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/service/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqMwAAAYM"]
[Thu Sep 17 15:36:02.179181 2026] [security2:error] [pid 18946:tid 19087] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/campaign/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqNAAAARU"]
[Thu Sep 17 15:36:02.295120 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/api/v3/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqNwAAAR4"]
[Thu Sep 17 15:36:02.346430 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/newsletter/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqOgAAATU"]
[Thu Sep 17 15:36:02.460632 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/api/dev/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqPAAAARQ"]
[Thu Sep 17 15:36:02.511246 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/ses/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqQAAAAV0"]
[Thu Sep 17 15:36:02.618679 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/api/staging/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqQwAAAVM"]
[Thu Sep 17 15:36:02.670043 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/sendgrid/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqRQAAAQ8"]
[Thu Sep 17 15:36:02.780542 2026] [security2:error] [pid 18946:tid 19084] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/vendor/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqRwAAARI"]
[Thu Sep 17 15:36:02.824530 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/sparkpost/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqSAAAAT8"]
[Thu Sep 17 15:36:02.871523 2026] [security2:error] [pid 18946:tid 19112] [client 86.120.179.139:50151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdQjqiPMah0Tz_U1OqRgABLl0"]
[Thu Sep 17 15:36:02.941907 2026] [security2:error] [pid 18946:tid 19151] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/lib/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqTgAAAVU"]
[Thu Sep 17 15:36:02.980950 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/postmark/.env"] [unique_id "aqxdQjqiPMah0Tz_U1OqUAAAATA"]
[Thu Sep 17 15:36:03.024279 2026] [security2:error] [pid 20162:tid 20314] [client 114.198.138.124:61655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdQ6-O_Kk7aqBvaiGBGAAAAaQ"]
[Thu Sep 17 15:36:03.024402 2026] [security2:error] [pid 20162:tid 20314] [client 114.198.138.124:61655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdQ6-O_Kk7aqBvaiGBGAAAAaQ"]
[Thu Sep 17 15:36:03.111171 2026] [security2:error] [pid 18946:tid 19144] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/resources/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqVQAAAU4"]
[Thu Sep 17 15:36:03.137017 2026] [security2:error] [pid 18946:tid 19187] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mailgun/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqVgAAAXk"]
[Thu Sep 17 15:36:03.285705 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/assets/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqWAAAAR8"]
[Thu Sep 17 15:36:03.294634 2026] [security2:error] [pid 18946:tid 19189] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mandrill/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqWQAAAXs"]
[Thu Sep 17 15:36:03.447759 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/uploads/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqWgAAAU0"]
[Thu Sep 17 15:36:03.451244 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mailjet/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqXQAAAVw"]
[Thu Sep 17 15:36:03.473707 2026] [security2:error] [pid 18946:tid 19140] [client 14.96.156.146:63519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdQzqiPMah0Tz_U1OqXgAAAUo"]
[Thu Sep 17 15:36:03.474016 2026] [security2:error] [pid 18946:tid 19140] [client 14.96.156.146:63519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdQzqiPMah0Tz_U1OqXgAAAUo"]
[Thu Sep 17 15:36:03.606298 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/brevo/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqaQAAATg"]
[Thu Sep 17 15:36:03.610589 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/internal/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqagAAASo"]
[Thu Sep 17 15:36:03.716608 2026] [autoindex:error] [pid 18946:tid 19177] [client 43.140.247.223:40438] AH01276: Cannot serve directory /home1/awesone8/public_html/risingstarspress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://risingstarspress.com
[Thu Sep 17 15:36:03.765695 2026] [security2:error] [pid 18946:tid 19103] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/transactional/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqbgAAASU"]
[Thu Sep 17 15:36:03.778103 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/tools/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqbwAAAYY"]
[Thu Sep 17 15:36:03.928975 2026] [security2:error] [pid 18946:tid 19099] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/bulk/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqcAAAASE"]
[Thu Sep 17 15:36:03.942813 2026] [security2:error] [pid 18946:tid 19124] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/scripts/.env"] [unique_id "aqxdQzqiPMah0Tz_U1OqcQAAATo"]
[Thu Sep 17 15:36:04.091831 2026] [security2:error] [pid 18946:tid 19088] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/aws/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqdQAAARY"]
[Thu Sep 17 15:36:04.093503 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.243.210:41884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/app/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqdgAAAX0"]
[Thu Sep 17 15:36:04.101893 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/bin/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqdwAAATw"]
[Thu Sep 17 15:36:04.246962 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/azure/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqegAAATI"]
[Thu Sep 17 15:36:04.255408 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.243.210:41884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/apps/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqfAAAAXM"]
[Thu Sep 17 15:36:04.259853 2026] [security2:error] [pid 18946:tid 19115] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/sbin/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqfQAAATE"]
[Thu Sep 17 15:36:04.409993 2026] [security2:error] [pid 18946:tid 19171] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/gcp/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqgAAAAWk"]
[Thu Sep 17 15:36:04.421394 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/local/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqgQAAATc"]
[Thu Sep 17 15:36:04.434395 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.243.210:41884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/api/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqggAAAVc"]
[Thu Sep 17 15:36:04.468916 2026] [security2:error] [pid 20162:tid 20382] [client 34.95.14.119:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxdRK-O_Kk7aqBvaiGBKwAAAeg"]
[Thu Sep 17 15:36:04.577090 2026] [security2:error] [pid 18946:tid 19106] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cloud/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqhwAAASg"]
[Thu Sep 17 15:36:04.587188 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/portal/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqiAAAAVI"]
[Thu Sep 17 15:36:04.600302 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.243.210:41884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/web/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqiQAAAWQ"]
[Thu Sep 17 15:36:04.734723 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/infrastructure/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqjAAAAWc"]
[Thu Sep 17 15:36:04.750853 2026] [security2:error] [pid 18946:tid 19094] [client 185.117.225.18:37466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "ad1homes.com"] [uri "/robots.txt"] [unique_id "aqxdRDqiPMah0Tz_U1OqjwAAARw"]
[Thu Sep 17 15:36:04.762397 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/dashboard/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqkAAAAVE"]
[Thu Sep 17 15:36:04.805802 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.243.210:41884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/site/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqkwAAATs"]
[Thu Sep 17 15:36:04.812551 2026] [security2:error] [pid 18946:tid 19136] [client 34.95.14.119:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/info.php"] [unique_id "aqxdRDqiPMah0Tz_U1OqlAAAAUY"]
[Thu Sep 17 15:36:04.889495 2026] [security2:error] [pid 18946:tid 19139] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/docker/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqlQAAAUk"]
[Thu Sep 17 15:36:04.921434 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/panel/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqlgAAATk"]
[Thu Sep 17 15:36:04.973403 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.243.210:41884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/public/.env"] [unique_id "aqxdRDqiPMah0Tz_U1OqlwAAARc"]
[Thu Sep 17 15:36:05.044891 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/k8s/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqmwAAAQ8"]
[Thu Sep 17 15:36:05.081926 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/crm/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqnQAAAUA"]
[Thu Sep 17 15:36:05.140553 2026] [security2:error] [pid 18946:tid 19160] [client 114.119.158.216:46093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.joeledmundanderson.com"] [uri "/why-is-the-bible-so-badly-written-part-2-the-destructive-effects-of-fundamentalism"] [unique_id "aqxdRTqiPMah0Tz_U1OqnwAAAV4"], referer: http://www.joeledmundanderson.com/page/16?cpage=1
[Thu Sep 17 15:36:05.146306 2026] [security2:error] [pid 18946:tid 19155] [client 34.95.14.119:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/php.php"] [unique_id "aqxdRTqiPMah0Tz_U1OqoAAAAVk"]
[Thu Sep 17 15:36:05.201132 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/kubernetes/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqoQAAARk"]
[Thu Sep 17 15:36:05.251736 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/erp/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqowAAASk"]
[Thu Sep 17 15:36:05.358032 2026] [security2:error] [pid 18946:tid 19086] [client 177.44.133.72:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdRTqiPMah0Tz_U1OqpgAAARQ"]
[Thu Sep 17 15:36:05.358140 2026] [security2:error] [pid 18946:tid 19086] [client 177.44.133.72:51620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdRTqiPMah0Tz_U1OqpgAAARQ"]
[Thu Sep 17 15:36:05.359509 2026] [security2:error] [pid 18946:tid 19161] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/terraform/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqpQAAAV8"]
[Thu Sep 17 15:36:05.424584 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/shop/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqpwAAARs"]
[Thu Sep 17 15:36:05.449913 2026] [security2:error] [pid 18946:tid 19118] [client 34.95.14.119:55034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/i.php"] [unique_id "aqxdRTqiPMah0Tz_U1OqqAAAATQ"]
[Thu Sep 17 15:36:05.520866 2026] [security2:error] [pid 18946:tid 19170] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/ansible/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqqgAAAWg"]
[Thu Sep 17 15:36:05.595434 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/store/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqrQAAAU0"]
[Thu Sep 17 15:36:05.630053 2026] [security2:error] [pid 20162:tid 20339] [client 170.245.10.42:2529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdRa-O_Kk7aqBvaiGBMwABvVE"]
[Thu Sep 17 15:36:05.674673 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/.git/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqsAAAAT0"]
[Thu Sep 17 15:36:05.695287 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/backend/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqsgAAAXg"]
[Thu Sep 17 15:36:05.768772 2026] [security2:error] [pid 18946:tid 19142] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/saas/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqtAAAAUw"]
[Thu Sep 17 15:36:05.834917 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/ci/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqtgAAAVA"]
[Thu Sep 17 15:36:05.857283 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/server/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OquQAAARM"]
[Thu Sep 17 15:36:05.933086 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/client/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqvAAAAYE"]
[Thu Sep 17 15:36:05.956030 2026] [security2:error] [pid 20162:tid 20352] [client 192.178.6.3:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxdRa-O_Kk7aqBvaiGBOgAAAco"]
[Thu Sep 17 15:36:05.957033 2026] [security2:error] [pid 20162:tid 20410] [client 34.95.14.119:55044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxdRa-O_Kk7aqBvaiGBOwAAAgQ"]
[Thu Sep 17 15:36:05.992166 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cd/.env"] [unique_id "aqxdRTqiPMah0Tz_U1OqvQAAAS8"]
[Thu Sep 17 15:36:06.019424 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/frontend/.env"] [unique_id "aqxdRjqiPMah0Tz_U1OqvgAAASc"]
[Thu Sep 17 15:36:06.102068 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/project/.env"] [unique_id "aqxdRjqiPMah0Tz_U1OqwwAAATw"]
[Thu Sep 17 15:36:06.150947 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/jenkins/.env"] [unique_id "aqxdRjqiPMah0Tz_U1OqxAAAAWE"]
[Thu Sep 17 15:36:06.187782 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/src/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq0AAAAXM"]
[Thu Sep 17 15:36:06.273177 2026] [security2:error] [pid 18946:tid 19184] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/admin-panel/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq0QAAAXY"]
[Thu Sep 17 15:36:06.310715 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/gitlab/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq0gAAAVc"]
[Thu Sep 17 15:36:06.370996 2026] [security2:error] [pid 20162:tid 20308] [client 34.95.14.119:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxdRq-O_Kk7aqBvaiGBPwAAAZ4"]
[Thu Sep 17 15:36:06.376029 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/core/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq1AAAAYM"]
[Thu Sep 17 15:36:06.443228 2026] [security2:error] [pid 18946:tid 19076] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/control-panel/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq1QAAAQo"]
[Thu Sep 17 15:36:06.472058 2026] [security2:error] [pid 18946:tid 19106] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/github/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq1gAAASg"]
[Thu Sep 17 15:36:06.545495 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/core/app/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq2wAAAWc"]
[Thu Sep 17 15:36:06.614694 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/user-panel/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq3QAAAW0"]
[Thu Sep 17 15:36:06.637592 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/actions/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq3gAAAVE"]
[Thu Sep 17 15:36:06.660728 2026] [security2:error] [pid 20162:tid 20354] [client 34.95.14.119:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/test.php"] [unique_id "aqxdRq-O_Kk7aqBvaiGBQgAAAcw"]
[Thu Sep 17 15:36:06.703234 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/config/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq3wAAAU8"]
[Thu Sep 17 15:36:06.781438 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/node/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq4QAAAUY"]
[Thu Sep 17 15:36:06.804099 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/circleci/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq4wAAARg"]
[Thu Sep 17 15:36:06.872998 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/private/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq5QAAATk"]
[Thu Sep 17 15:36:06.897703 2026] [security2:error] [pid 18946:tid 19149] [client 114.119.129.74:37413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireflyhotglass.net"] [uri "/glass/wp-content/plugins/ckeditor-for-wordpress/ckeditor/plugins/wsc/lang/af.js"] [unique_id "aqxdRjqiPMah0Tz_U1Oq5gAAAVM"], referer: http://fireflyhotglass.net/glass/wp-content/plugins/ckeditor-for-wordpress/ckeditor/plugins/wsc/lang/?C=D%3BO%3DA
[Thu Sep 17 15:36:06.944729 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/express/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq5wAAAXo"]
[Thu Sep 17 15:36:06.958518 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/travis/.env"] [unique_id "aqxdRjqiPMah0Tz_U1Oq6AAAAQ8"]
[Thu Sep 17 15:36:06.990410 2026] [security2:error] [pid 18946:tid 19155] [client 114.119.133.42:41565] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fleigfinancialsllc.com"] [uri "/"] [unique_id "aqxdRjqiPMah0Tz_U1Oq6gAAAVk"], referer: http://www.fleigfinancialsllc.com/?paged=5&author=2
[Thu Sep 17 15:36:07.058640 2026] [security2:error] [pid 18946:tid 19167] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/application/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq7AAAAWU"]
[Thu Sep 17 15:36:07.112242 2026] [security2:error] [pid 18946:tid 19172] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/buildkite/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq7wAAAWo"]
[Thu Sep 17 15:36:07.112322 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/next/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq8AAAAQw"]
[Thu Sep 17 15:36:07.172026 2026] [security2:error] [pid 18946:tid 19084] [client 34.95.14.119:55066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/p.php"] [unique_id "aqxdRzqiPMah0Tz_U1Oq8QAAARI"]
[Thu Sep 17 15:36:07.228135 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/bootstrap/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq8wAAAS4"]
[Thu Sep 17 15:36:07.265833 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mysql/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq9AAAAW4"]
[Thu Sep 17 15:36:07.272975 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/nuxt/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq9QAAAXw"]
[Thu Sep 17 15:36:07.419269 2026] [security2:error] [pid 18946:tid 19083] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/postgres/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq9wAAARE"]
[Thu Sep 17 15:36:07.438109 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/nest/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq-QAAARs"]
[Thu Sep 17 15:36:07.439316 2026] [security2:error] [pid 18946:tid 19118] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/database/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq-gAAATQ"]
[Thu Sep 17 15:36:07.574383 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mongodb/.env"] [unique_id "aqxdRzqiPMah0Tz_U1Oq_wAAAVw"]
[Thu Sep 17 15:36:07.592325 2026] [security2:error] [pid 18946:tid 19203] [client 34.95.14.119:55072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxdRzqiPMah0Tz_U1OrAAAAAYk"]
[Thu Sep 17 15:36:07.597517 2026] [security2:error] [pid 18946:tid 19187] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/storage/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrAQAAAXk"]
[Thu Sep 17 15:36:07.603358 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/react/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrAwAAAT0"]
[Thu Sep 17 15:36:07.729851 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/redis/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrBQAAASo"]
[Thu Sep 17 15:36:07.738580 2026] [security2:error] [pid 18946:tid 19179] [client 103.61.184.148:59189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdRzqiPMah0Tz_U1OrBgAAAXE"]
[Thu Sep 17 15:36:07.738699 2026] [security2:error] [pid 18946:tid 19179] [client 103.61.184.148:59189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdRzqiPMah0Tz_U1OrBgAAAXE"]
[Thu Sep 17 15:36:07.766980 2026] [security2:error] [pid 18946:tid 19140] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/vue/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrCAAAAUo"]
[Thu Sep 17 15:36:07.766980 2026] [security2:error] [pid 18946:tid 19142] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/var/www/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrBwAAAUw"]
[Thu Sep 17 15:36:07.885114 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/elasticsearch/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrCgAAAQ0"]
[Thu Sep 17 15:36:07.926751 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/angular/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrCwAAAVA"]
[Thu Sep 17 15:36:07.959734 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/var/www/html/.env"] [unique_id "aqxdRzqiPMah0Tz_U1OrDAAAATY"]
[Thu Sep 17 15:36:07.976296 2026] [security2:error] [pid 20162:tid 20409] [client 34.95.14.119:34476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxdR6-O_Kk7aqBvaiGBRgAAAgM"]
[Thu Sep 17 15:36:08.039403 2026] [security2:error] [pid 18946:tid 19131] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/rabbitmq/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrDwAAAUE"]
[Thu Sep 17 15:36:08.086424 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/svelte/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrEQAAASc"]
[Thu Sep 17 15:36:08.136589 2026] [security2:error] [pid 20162:tid 20380] [client 185.117.225.18:41162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "ad1homes.com"] [uri "/robots.txt"] [unique_id "aqxdSK-O_Kk7aqBvaiGBRwAAAeY"]
[Thu Sep 17 15:36:08.161509 2026] [security2:error] [pid 18946:tid 19124] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/current/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrEgAAATo"]
[Thu Sep 17 15:36:08.192717 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/kafka/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrFAAAAX0"]
[Thu Sep 17 15:36:08.247343 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/vite/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrFgAAAXM"]
[Thu Sep 17 15:36:08.280582 2026] [core:error] [pid 18946:tid 19174] [client 185.185.217.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:08.280613 2026] [core:error] [pid 18946:tid 19174] [client 185.185.217.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:08.282986 2026] [security2:error] [pid 18946:tid 19180] [client 34.95.14.119:34480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxdSDqiPMah0Tz_U1OrGgAAAXI"]
[Thu Sep 17 15:36:08.334041 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/release/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrGwAAAYc"]
[Thu Sep 17 15:36:08.346733 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/queue/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrHAAAAYY"]
[Thu Sep 17 15:36:08.410255 2026] [security2:error] [pid 18946:tid 19104] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/backup/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrHgAAASY"]
[Thu Sep 17 15:36:08.500968 2026] [security2:error] [pid 18946:tid 19076] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/worker/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrIgAAAQo"]
[Thu Sep 17 15:36:08.548536 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/releases/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrJQAAARw"]
[Thu Sep 17 15:36:08.569336 2026] [security2:error] [pid 18946:tid 19087] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/backups/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrJgAAARU"]
[Thu Sep 17 15:36:08.656709 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/job/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrKQAAATU"]
[Thu Sep 17 15:36:08.664320 2026] [security2:error] [pid 20162:tid 20337] [client 34.95.14.119:34488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxdSK-O_Kk7aqBvaiGBTgAAAbs"]
[Thu Sep 17 15:36:08.732591 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/shared/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrLwAAAYQ"]
[Thu Sep 17 15:36:08.734767 2026] [security2:error] [pid 18946:tid 19098] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/old/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrMAAAASA"]
[Thu Sep 17 15:36:08.770133 2026] [security2:error] [pid 18946:tid 19168] [client 114.119.132.58:22175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.enduringwanderlust.com"] [uri "/"] [unique_id "aqxdSDqiPMah0Tz_U1OrMQAAAWY"], referer: https://travestistube.top/xexkr/san%20diego%20%E5%91%A8%E9%82%8A%20%E9%81%8A-7658435716/
[Thu Sep 17 15:36:08.782828 2026] [security2:error] [pid 20162:tid 20406] [client 114.119.131.35:65023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wisdomelders.com"] [uri "/ulprfx/b4j.php"] [unique_id "aqxdSK-O_Kk7aqBvaiGBUAAAAgA"], referer: http://wisdomelders.com/ulprfx/b4j.php?tom=mplab-ide-for-pic-microcontroller-download
[Thu Sep 17 15:36:08.813009 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/test/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrMgAAARk"]
[Thu Sep 17 15:36:08.905709 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/tmp/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrNAAAAUA"]
[Thu Sep 17 15:36:08.915341 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/deploy/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrNQAAAQw"]
[Thu Sep 17 15:36:08.969384 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/qa/.env"] [unique_id "aqxdSDqiPMah0Tz_U1OrNgAAAV0"]
[Thu Sep 17 15:36:09.000569 2026] [security2:error] [pid 18946:tid 19133] [client 34.95.14.119:34496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxdSDqiPMah0Tz_U1OrOAAAAUM"]
[Thu Sep 17 15:36:09.066962 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/temp/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrOwAAAXw"]
[Thu Sep 17 15:36:09.077165 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/build/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrPQAAAT4"]
[Thu Sep 17 15:36:09.112444 2026] [security2:error] [pid 18946:tid 19117] [client 20.235.136.168:47490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "mail.dfwservicesllc.com"] [uri "/"] [unique_id "aqxdSTqiPMah0Tz_U1OrPwAAATM"]
[Thu Sep 17 15:36:09.122947 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/preview/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrQAAAAUQ"]
[Thu Sep 17 15:36:09.224928 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/lab/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrQgAAAYg"]
[Thu Sep 17 15:36:09.254550 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/dist/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrQwAAARQ"]
[Thu Sep 17 15:36:09.277638 2026] [security2:error] [pid 18946:tid 19161] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/beta/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrRAAAAV8"]
[Thu Sep 17 15:36:09.330866 2026] [security2:error] [pid 18946:tid 19114] [client 34.95.14.119:34504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdSTqiPMah0Tz_U1OrRwAAATA"]
[Thu Sep 17 15:36:09.384579 2026] [security2:error] [pid 18946:tid 19144] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cronlab/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrSgAAAU4"]
[Thu Sep 17 15:36:09.412635 2026] [security2:error] [pid 18946:tid 19118] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/public_html/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrSwAAATQ"]
[Thu Sep 17 15:36:09.430882 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/uat/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrTwAAARo"]
[Thu Sep 17 15:36:09.469574 2026] [security2:error] [pid 18946:tid 19143] [client 169.58.197.253:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxdSTqiPMah0Tz_U1OrUQAAAU0"], referer: binance.com
[Thu Sep 17 15:36:09.505875 2026] [security2:error] [pid 18946:tid 19157] [client 143.105.152.240:60439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdSTqiPMah0Tz_U1OrVAAAAVs"]
[Thu Sep 17 15:36:09.516049 2026] [security2:error] [pid 18946:tid 19157] [client 143.105.152.240:60439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdSTqiPMah0Tz_U1OrVAAAAVs"]
[Thu Sep 17 15:36:09.543391 2026] [security2:error] [pid 18946:tid 19192] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cron/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrVgAAAX4"]
[Thu Sep 17 15:36:09.586369 2026] [security2:error] [pid 18946:tid 19178] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/stage/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrWQAAAXA"]
[Thu Sep 17 15:36:09.606840 2026] [security2:error] [pid 18946:tid 19156] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/htdocs/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrXAAAAVo"]
[Thu Sep 17 15:36:09.616631 2026] [security2:error] [pid 20162:tid 20359] [client 79.116.89.151:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdSa-O_Kk7aqBvaiGBWQAAAdE"]
[Thu Sep 17 15:36:09.617998 2026] [security2:error] [pid 20162:tid 20359] [client 79.116.89.151:57114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdSa-O_Kk7aqBvaiGBWQAAAdE"]
[Thu Sep 17 15:36:09.709443 2026] [security2:error] [pid 18946:tid 19185] [client 162.241.226.11:49800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxdSTqiPMah0Tz_U1OrWgAAAXc"]
[Thu Sep 17 15:36:09.710158 2026] [security2:error] [pid 18946:tid 19142] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/en/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrXQAAAUw"]
[Thu Sep 17 15:36:09.746203 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/development/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrYAAAARM"]
[Thu Sep 17 15:36:09.765196 2026] [security2:error] [pid 18946:tid 19177] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/www/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrYQAAAW8"]
[Thu Sep 17 15:36:09.818747 2026] [security2:error] [pid 18946:tid 19079] [client 162.241.226.11:49812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qja.nnk.mybluehost.me"] [uri "/index.php"] [unique_id "aqxdSTqiPMah0Tz_U1OrXwAAAQ0"]
[Thu Sep 17 15:36:09.889202 2026] [security2:error] [pid 20162:tid 20417] [client 34.95.14.119:34518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxdSa-O_Kk7aqBvaiGBWgAAAgs"]
[Thu Sep 17 15:36:09.899784 2026] [security2:error] [pid 18946:tid 19195] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/production/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrZAAAAYE"]
[Thu Sep 17 15:36:09.912080 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/administrator/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrYwAAASc"]
[Thu Sep 17 15:36:09.931355 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/html/.env"] [unique_id "aqxdSTqiPMah0Tz_U1OrZQAAAS0"]
[Thu Sep 17 15:36:10.015738 2026] [security2:error] [pid 18946:tid 19140] [client 136.158.61.34:8322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdSjqiPMah0Tz_U1OraAAAAUo"]
[Thu Sep 17 15:36:10.015859 2026] [security2:error] [pid 18946:tid 19140] [client 136.158.61.34:8322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdSjqiPMah0Tz_U1OraAAAAUo"]
[Thu Sep 17 15:36:10.057942 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.219.249:45132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.cellovsviolin.com"] [uri "/config/app/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OraQAAAX0"]
[Thu Sep 17 15:36:10.089885 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/psnlink/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OragAAATw"]
[Thu Sep 17 15:36:10.090875 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/live/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrawAAAUs"]
[Thu Sep 17 15:36:10.228773 2026] [security2:error] [pid 18946:tid 19174] [client 34.154.219.249:45132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/phpinfo.php"] [unique_id "aqxdSjqiPMah0Tz_U1OrbQAAAWw"]
[Thu Sep 17 15:36:10.250455 2026] [security2:error] [pid 18946:tid 19194] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/exapi/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrbwAAAYA"]
[Thu Sep 17 15:36:10.283502 2026] [security2:error] [pid 18946:tid 19077] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/prod/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrcAAAAQs"]
[Thu Sep 17 15:36:10.354445 2026] [security2:error] [pid 18946:tid 19082] [client 114.119.151.156:30455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "navishiur.org"] [uri "/product/shmuel-i-51-2-si-13/"] [unique_id "aqxdSjqiPMah0Tz_U1OrcgAAARA"], referer: https://navishiur.org/product/shmuel-i-11-10-si-1/
[Thu Sep 17 15:36:10.410929 2026] [security2:error] [pid 18946:tid 19184] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/sitemaps/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrcwAAAXY"]
[Thu Sep 17 15:36:10.440854 2026] [security2:error] [pid 18946:tid 19100] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/dev/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrdAAAASI"]
[Thu Sep 17 15:36:10.572135 2026] [security2:error] [pid 20162:tid 20395] [client 34.95.14.119:34520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxdSq-O_Kk7aqBvaiGBXgAAAfU"]
[Thu Sep 17 15:36:10.612889 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/staging/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrfgAAAVE"]
[Thu Sep 17 15:36:10.639047 2026] [security2:error] [pid 20162:tid 20344] [client 199.163.228.108:56085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdSq-O_Kk7aqBvaiGBXQABwms"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:36:10.688461 2026] [security2:error] [pid 20162:tid 20364] [client 34.154.219.249:48824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/info.php"] [unique_id "aqxdSq-O_Kk7aqBvaiGBXwAAAdY"]
[Thu Sep 17 15:36:10.794874 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/opt/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrggAAAUY"]
[Thu Sep 17 15:36:10.925996 2026] [security2:error] [pid 18946:tid 19155] [client 34.95.14.119:34526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxdSjqiPMah0Tz_U1OrigAAAVk"]
[Thu Sep 17 15:36:10.993294 2026] [security2:error] [pid 18946:tid 19084] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/laravel/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrjAAAARI"]
[Thu Sep 17 15:36:10.998052 2026] [security2:error] [pid 18946:tid 19096] [client 34.154.21.169:34144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/logs/.env"] [unique_id "aqxdSjqiPMah0Tz_U1OrjQAAAR4"]
[Thu Sep 17 15:36:11.039131 2026] [security2:error] [pid 18946:tid 19167] [client 199.163.228.108:45389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdSjqiPMah0Tz_U1OriwABZQI"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:36:11.146978 2026] [security2:error] [pid 18946:tid 19135] [client 34.154.219.249:48836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/php.php"] [unique_id "aqxdSzqiPMah0Tz_U1OrkgAAAUU"]
[Thu Sep 17 15:36:11.178017 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/symfony/.env"] [unique_id "aqxdSzqiPMah0Tz_U1OrkwAAAS4"]
[Thu Sep 17 15:36:11.216967 2026] [security2:error] [pid 18946:tid 19086] [client 40.81.232.68:60428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxdSzqiPMah0Tz_U1OrlgAAARQ"], referer: binance.com
[Thu Sep 17 15:36:11.327850 2026] [security2:error] [pid 18946:tid 19110] [client 34.95.14.119:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxdSzqiPMah0Tz_U1OrmAAAASw"]
[Thu Sep 17 15:36:11.348832 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/wordpress/.env"] [unique_id "aqxdSzqiPMah0Tz_U1OrmgAAATA"]
[Thu Sep 17 15:36:11.496327 2026] [security2:error] [pid 20162:tid 20328] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cache/.env"] [unique_id "aqxdS6-O_Kk7aqBvaiGBYgAAAbI"]
[Thu Sep 17 15:36:11.534316 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/wp/.env"] [unique_id "aqxdSzqiPMah0Tz_U1OrpAAAAUg"]
[Thu Sep 17 15:36:11.557217 2026] [security2:error] [pid 18946:tid 19118] [client 57.141.14.97:52480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxdSzqiPMah0Tz_U1OrnwABNCU"]
[Thu Sep 17 15:36:11.626776 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.219.249:48842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/i.php"] [unique_id "aqxdS6-O_Kk7aqBvaiGBYwAAAZA"]
[Thu Sep 17 15:36:11.656166 2026] [security2:error] [pid 20162:tid 20372] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mailer/.env"] [unique_id "aqxdS6-O_Kk7aqBvaiGBZAAAAd4"]
[Thu Sep 17 15:36:11.681555 2026] [security2:error] [pid 18946:tid 19203] [client 34.95.14.119:34542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxdSzqiPMah0Tz_U1OrqAAAAYk"]
[Thu Sep 17 15:36:11.696856 2026] [security2:error] [pid 18946:tid 19187] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/cms/.env"] [unique_id "aqxdSzqiPMah0Tz_U1OrqQAAAXk"]
[Thu Sep 17 15:36:11.811893 2026] [security2:error] [pid 20162:tid 20315] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mail/.env"] [unique_id "aqxdS6-O_Kk7aqBvaiGBZQAAAaU"]
[Thu Sep 17 15:36:11.859585 2026] [security2:error] [pid 18946:tid 19170] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/drupal/.env"] [unique_id "aqxdSzqiPMah0Tz_U1OrqwAAAWg"]
[Thu Sep 17 15:36:11.971077 2026] [security2:error] [pid 20162:tid 20307] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/email/.env"] [unique_id "aqxdS6-O_Kk7aqBvaiGBZgAAAZ0"]
[Thu Sep 17 15:36:12.042987 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/joomla/.env"] [unique_id "aqxdTDqiPMah0Tz_U1OrrgAAAXc"]
[Thu Sep 17 15:36:12.081396 2026] [security2:error] [pid 20162:tid 20311] [client 34.95.14.119:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxdTK-O_Kk7aqBvaiGBZwAAAaE"]
[Thu Sep 17 15:36:12.097558 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.219.249:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/pi.php"] [unique_id "aqxdTDqiPMah0Tz_U1OrsAAAAQ4"]
[Thu Sep 17 15:36:12.126458 2026] [security2:error] [pid 20162:tid 20319] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/smtp/.env"] [unique_id "aqxdTK-O_Kk7aqBvaiGBaAAAAak"]
[Thu Sep 17 15:36:12.237261 2026] [security2:error] [pid 18946:tid 19085] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/magento/.env"] [unique_id "aqxdTDqiPMah0Tz_U1OrsgAAARM"]
[Thu Sep 17 15:36:12.284574 2026] [security2:error] [pid 20162:tid 20418] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mailing/.env"] [unique_id "aqxdTK-O_Kk7aqBvaiGBaQAAAgw"]
[Thu Sep 17 15:36:12.391953 2026] [security2:error] [pid 20162:tid 20382] [client 34.95.14.119:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxdTK-O_Kk7aqBvaiGBagAAAeg"]
[Thu Sep 17 15:36:12.420173 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/shopify/.env"] [unique_id "aqxdTDqiPMah0Tz_U1OrtQAAAQ0"]
[Thu Sep 17 15:36:12.440052 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/notifications/.env"] [unique_id "aqxdTK-O_Kk7aqBvaiGBawAAAc4"]
[Thu Sep 17 15:36:12.514373 2026] [security2:error] [pid 18946:tid 19192] [client 169.224.105.43:58224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "counsellingincambridge.ca"] [uri "/index.php"] [unique_id "aqxdTDqiPMah0Tz_U1OrswAAAX4"], referer: https://counsellingincambridge.com/
[Thu Sep 17 15:36:12.557761 2026] [security2:error] [pid 20162:tid 20329] [client 34.154.219.249:48870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/pinfo.php"] [unique_id "aqxdTK-O_Kk7aqBvaiGBbgAAAbM"]
[Thu Sep 17 15:36:12.595144 2026] [security2:error] [pid 20162:tid 20355] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/notify/.env"] [unique_id "aqxdTK-O_Kk7aqBvaiGBbwAAAc0"]
[Thu Sep 17 15:36:12.605591 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/prestashop/.env"] [unique_id "aqxdTDqiPMah0Tz_U1OrugAAAT0"]
[Thu Sep 17 15:36:12.750024 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/sender/.env"] [unique_id "aqxdTK-O_Kk7aqBvaiGBcwAAAZE"]
[Thu Sep 17 15:36:12.771046 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/codeigniter/.env"] [unique_id "aqxdTDqiPMah0Tz_U1OruwAAAS0"]
[Thu Sep 17 15:36:12.906166 2026] [security2:error] [pid 20162:tid 20320] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/campaign/.env"] [unique_id "aqxdTK-O_Kk7aqBvaiGBdQAAAao"]
[Thu Sep 17 15:36:12.950560 2026] [security2:error] [pid 20162:tid 20302] [client 34.95.14.119:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdTK-O_Kk7aqBvaiGBdgAAAZg"]
[Thu Sep 17 15:36:12.976837 2026] [security2:error] [pid 18946:tid 19088] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/cakephp/.env"] [unique_id "aqxdTDqiPMah0Tz_U1OrvwAAARY"]
[Thu Sep 17 15:36:13.021635 2026] [security2:error] [pid 20162:tid 20416] [client 34.154.219.249:48876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/test.php"] [unique_id "aqxdTa-O_Kk7aqBvaiGBeQAAAgo"]
[Thu Sep 17 15:36:13.061956 2026] [security2:error] [pid 20162:tid 20350] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/newsletter/.env"] [unique_id "aqxdTa-O_Kk7aqBvaiGBewAAAcg"]
[Thu Sep 17 15:36:13.134180 2026] [security2:error] [pid 18946:tid 19194] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/zend/.env"] [unique_id "aqxdTTqiPMah0Tz_U1OrwQAAAYA"]
[Thu Sep 17 15:36:13.220044 2026] [security2:error] [pid 20162:tid 20300] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/ses/.env"] [unique_id "aqxdTa-O_Kk7aqBvaiGBfAAAAZY"]
[Thu Sep 17 15:36:13.319026 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/yii/.env"] [unique_id "aqxdTTqiPMah0Tz_U1OrxAAAAWE"]
[Thu Sep 17 15:36:13.376786 2026] [security2:error] [pid 20162:tid 20334] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/sendgrid/.env"] [unique_id "aqxdTa-O_Kk7aqBvaiGBfQAAAbg"]
[Thu Sep 17 15:36:13.458317 2026] [security2:error] [pid 18946:tid 19082] [client 34.95.14.119:34584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxdTTqiPMah0Tz_U1OrxQAAARA"]
[Thu Sep 17 15:36:13.500625 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/laravel5/.env"] [unique_id "aqxdTTqiPMah0Tz_U1OryAAAAYc"]
[Thu Sep 17 15:36:13.526547 2026] [security2:error] [pid 20162:tid 20317] [client 167.58.91.112:48504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdTa-O_Kk7aqBvaiGBfgABp1k"]
[Thu Sep 17 15:36:13.541055 2026] [security2:error] [pid 20162:tid 20323] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/sparkpost/.env"] [unique_id "aqxdTa-O_Kk7aqBvaiGBfwAAAa0"]
[Thu Sep 17 15:36:13.692460 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.219.249:48890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/p.php"] [unique_id "aqxdTTqiPMah0Tz_U1OrzQAAAVE"]
[Thu Sep 17 15:36:13.699810 2026] [security2:error] [pid 20162:tid 20392] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/postmark/.env"] [unique_id "aqxdTa-O_Kk7aqBvaiGBgQAAAfI"]
[Thu Sep 17 15:36:13.716329 2026] [security2:error] [pid 18946:tid 19169] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/v1/.env"] [unique_id "aqxdTTqiPMah0Tz_U1OrzgAAAWc"]
[Thu Sep 17 15:36:13.789984 2026] [security2:error] [pid 18946:tid 19106] [client 114.198.138.124:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdTTqiPMah0Tz_U1Or0AAAASg"]
[Thu Sep 17 15:36:13.790099 2026] [security2:error] [pid 18946:tid 19106] [client 114.198.138.124:62299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdTTqiPMah0Tz_U1Or0AAAASg"]
[Thu Sep 17 15:36:13.863192 2026] [security2:error] [pid 20162:tid 20397] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mailgun/.env"] [unique_id "aqxdTa-O_Kk7aqBvaiGBggAAAfc"]
[Thu Sep 17 15:36:13.914155 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/v2/.env"] [unique_id "aqxdTTqiPMah0Tz_U1Or0QAAAU8"]
[Thu Sep 17 15:36:13.921451 2026] [security2:error] [pid 20162:tid 20310] [client 34.95.14.119:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdTa-O_Kk7aqBvaiGBgwAAAaA"]
[Thu Sep 17 15:36:14.024582 2026] [security2:error] [pid 20162:tid 20308] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mandrill/.env"] [unique_id "aqxdTq-O_Kk7aqBvaiGBhQAAAZ4"]
[Thu Sep 17 15:36:14.080736 2026] [security2:error] [pid 20162:tid 20358] [client 14.96.156.146:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdTq-O_Kk7aqBvaiGBhgAAAdA"]
[Thu Sep 17 15:36:14.080875 2026] [security2:error] [pid 20162:tid 20358] [client 14.96.156.146:64152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdTq-O_Kk7aqBvaiGBhgAAAdA"]
[Thu Sep 17 15:36:14.090060 2026] [security2:error] [pid 18946:tid 19139] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/v3/.env"] [unique_id "aqxdTjqiPMah0Tz_U1Or1QAAAUk"]
[Thu Sep 17 15:36:14.173683 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.219.249:48898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/debug.php"] [unique_id "aqxdTjqiPMah0Tz_U1Or1wAAARg"]
[Thu Sep 17 15:36:14.179866 2026] [security2:error] [pid 20162:tid 20354] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mailjet/.env"] [unique_id "aqxdTq-O_Kk7aqBvaiGBhwAAAcw"]
[Thu Sep 17 15:36:14.232110 2026] [security2:error] [pid 20162:tid 20405] [client 34.95.14.119:34598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdTq-O_Kk7aqBvaiGBiQAAAf8"]
[Thu Sep 17 15:36:14.267645 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/api/v1/.env"] [unique_id "aqxdTjqiPMah0Tz_U1Or2AAAATk"]
[Thu Sep 17 15:36:14.314410 2026] [security2:error] [pid 18946:tid 19076] [client 35.185.138.72:52766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.sale.darisocial.com"] [uri "/index.cgi"] [unique_id "aqxdTjqiPMah0Tz_U1Or2QAAAQo"]
[Thu Sep 17 15:36:14.335478 2026] [security2:error] [pid 20162:tid 20380] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/brevo/.env"] [unique_id "aqxdTq-O_Kk7aqBvaiGBigAAAeY"]
[Thu Sep 17 15:36:14.395300 2026] [security2:error] [pid 18946:tid 19150] [client 114.119.132.28:46435] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "coronadoiscalling.com"] [uri "/category/music-arts/page/3/"] [unique_id "aqxdTjqiPMah0Tz_U1Or2wAAAVQ"], referer: https://coronadoiscalling.com/category/music-arts/page/5/
[Thu Sep 17 15:36:14.415503 2026] [security2:error] [pid 20162:tid 20374] [client 114.119.137.238:52177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "askmrhenderson.com"] [uri "/category/real-estate-basics/page/6/"] [unique_id "aqxdTq-O_Kk7aqBvaiGBiwAAAeA"], referer: https://askmrhenderson.com/category/real-estate-basics/page/7/
[Thu Sep 17 15:36:14.466408 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/api/v2/.env"] [unique_id "aqxdTjqiPMah0Tz_U1Or3AAAAQ8"]
[Thu Sep 17 15:36:14.497440 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/transactional/.env"] [unique_id "aqxdTq-O_Kk7aqBvaiGBjAAAAfY"]
[Thu Sep 17 15:36:14.591175 2026] [security2:error] [pid 18946:tid 19148] [client 34.95.14.119:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdTjqiPMah0Tz_U1Or4gAAAVI"]
[Thu Sep 17 15:36:14.638384 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/rest/.env"] [unique_id "aqxdTjqiPMah0Tz_U1Or4wAAAV0"]
[Thu Sep 17 15:36:14.646439 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.219.249:48904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxdTjqiPMah0Tz_U1Or5AAAAVc"]
[Thu Sep 17 15:36:14.654119 2026] [security2:error] [pid 20162:tid 20321] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/bulk/.env"] [unique_id "aqxdTq-O_Kk7aqBvaiGBjQAAAas"]
[Thu Sep 17 15:36:14.819781 2026] [security2:error] [pid 20162:tid 20399] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/aws/.env"] [unique_id "aqxdTq-O_Kk7aqBvaiGBjgAAAfk"]
[Thu Sep 17 15:36:14.828315 2026] [security2:error] [pid 18946:tid 19167] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/graphql/.env"] [unique_id "aqxdTjqiPMah0Tz_U1Or6QAAAWU"]
[Thu Sep 17 15:36:14.916824 2026] [security2:error] [pid 18946:tid 19176] [client 114.119.144.178:56025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.impact100sydneynorth.org"] [uri "/0-2"] [unique_id "aqxdTjqiPMah0Tz_U1Or6gAAAW4"], referer: http://www.impact100sydneynorth.org/0-2/
[Thu Sep 17 15:36:14.977608 2026] [security2:error] [pid 20162:tid 20324] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/azure/.env"] [unique_id "aqxdTq-O_Kk7aqBvaiGBjwAAAa4"]
[Thu Sep 17 15:36:14.990421 2026] [security2:error] [pid 18946:tid 19128] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/gateway/.env"] [unique_id "aqxdTjqiPMah0Tz_U1Or6wAAAT4"]
[Thu Sep 17 15:36:15.059669 2026] [security2:error] [pid 18946:tid 19117] [client 34.95.14.119:34616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdTzqiPMah0Tz_U1Or7gAAATM"]
[Thu Sep 17 15:36:15.117170 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.219.249:48914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/test/phpinfo.php"] [unique_id "aqxdTzqiPMah0Tz_U1Or8QAAAS4"]
[Thu Sep 17 15:36:15.139513 2026] [security2:error] [pid 20162:tid 20304] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/gcp/.env"] [unique_id "aqxdT6-O_Kk7aqBvaiGBkQAAAZo"]
[Thu Sep 17 15:36:15.164772 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/microservice/.env"] [unique_id "aqxdTzqiPMah0Tz_U1Or8gAAATA"]
[Thu Sep 17 15:36:15.299539 2026] [security2:error] [pid 20162:tid 20298] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cloud/.env"] [unique_id "aqxdT6-O_Kk7aqBvaiGBkgAAAZQ"]
[Thu Sep 17 15:36:15.320883 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/service/.env"] [unique_id "aqxdTzqiPMah0Tz_U1Or8wAAAUg"]
[Thu Sep 17 15:36:15.456706 2026] [security2:error] [pid 20162:tid 20385] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/infrastructure/.env"] [unique_id "aqxdT6-O_Kk7aqBvaiGBkwAAAes"]
[Thu Sep 17 15:36:15.460456 2026] [security2:error] [pid 18946:tid 19118] [client 34.95.14.119:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxdTzqiPMah0Tz_U1Or9QAAATQ"]
[Thu Sep 17 15:36:15.546964 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/api/v3/.env"] [unique_id "aqxdTzqiPMah0Tz_U1Or-AAAAXg"]
[Thu Sep 17 15:36:15.616821 2026] [security2:error] [pid 20162:tid 20330] [client 34.154.219.249:48922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxdT6-O_Kk7aqBvaiGBlwAAAbQ"]
[Thu Sep 17 15:36:15.623215 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/docker/.env"] [unique_id "aqxdT6-O_Kk7aqBvaiGBmAAAAZs"]
[Thu Sep 17 15:36:15.737496 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/api/dev/.env"] [unique_id "aqxdTzqiPMah0Tz_U1Or-wAAASo"]
[Thu Sep 17 15:36:15.788316 2026] [security2:error] [pid 20162:tid 20342] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/k8s/.env"] [unique_id "aqxdT6-O_Kk7aqBvaiGBmQAAAcA"]
[Thu Sep 17 15:36:15.836212 2026] [security2:error] [pid 18946:tid 19185] [client 34.95.14.119:34636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxdTzqiPMah0Tz_U1Or_gAAAXc"]
[Thu Sep 17 15:36:15.903580 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/api/staging/.env"] [unique_id "aqxdTzqiPMah0Tz_U1OsAQAAAVA"]
[Thu Sep 17 15:36:15.944976 2026] [security2:error] [pid 20162:tid 20333] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/kubernetes/.env"] [unique_id "aqxdT6-O_Kk7aqBvaiGBnQAAAbc"]
[Thu Sep 17 15:36:16.075847 2026] [security2:error] [pid 18946:tid 19109] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/vendor/.env"] [unique_id "aqxdUDqiPMah0Tz_U1OsBQAAASs"]
[Thu Sep 17 15:36:16.100736 2026] [security2:error] [pid 18946:tid 19189] [client 177.44.133.72:52281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdUDqiPMah0Tz_U1OsBwAAAXs"]
[Thu Sep 17 15:36:16.100875 2026] [security2:error] [pid 18946:tid 19189] [client 177.44.133.72:52281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdUDqiPMah0Tz_U1OsBwAAAXs"]
[Thu Sep 17 15:36:16.125370 2026] [security2:error] [pid 20162:tid 20391] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/terraform/.env"] [unique_id "aqxdUK-O_Kk7aqBvaiGBnwAAAfE"]
[Thu Sep 17 15:36:16.175073 2026] [security2:error] [pid 20162:tid 20384] [client 34.154.219.249:48928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/old/phpinfo.php"] [unique_id "aqxdUK-O_Kk7aqBvaiGBoAAAAeo"]
[Thu Sep 17 15:36:16.257213 2026] [security2:error] [pid 18946:tid 19196] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/lib/.env"] [unique_id "aqxdUDqiPMah0Tz_U1OsCQAAAYI"]
[Thu Sep 17 15:36:16.275448 2026] [security2:error] [pid 20162:tid 20371] [client 34.95.14.119:34648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxdUK-O_Kk7aqBvaiGBogAAAd0"]
[Thu Sep 17 15:36:16.291623 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/ansible/.env"] [unique_id "aqxdUK-O_Kk7aqBvaiGBowAAAgg"]
[Thu Sep 17 15:36:16.455241 2026] [security2:error] [pid 20162:tid 20314] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/.git/.env"] [unique_id "aqxdUK-O_Kk7aqBvaiGBpQAAAaQ"]
[Thu Sep 17 15:36:16.467936 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/resources/.env"] [unique_id "aqxdUDqiPMah0Tz_U1OsDAAAAX0"]
[Thu Sep 17 15:36:16.544959 2026] [security2:error] [pid 20162:tid 20322] [client 37.231.35.204:17112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdUK-O_Kk7aqBvaiGBpAABrFA"]
[Thu Sep 17 15:36:16.615366 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/ci/.env"] [unique_id "aqxdUK-O_Kk7aqBvaiGBqQAAAcI"]
[Thu Sep 17 15:36:16.623849 2026] [security2:error] [pid 20162:tid 20394] [client 34.95.14.119:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxdUK-O_Kk7aqBvaiGBqgAAAfQ"]
[Thu Sep 17 15:36:16.660497 2026] [security2:error] [pid 18946:tid 19088] [client 34.154.219.249:48934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdUDqiPMah0Tz_U1OsEAAAARY"]
[Thu Sep 17 15:36:16.665308 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/assets/.env"] [unique_id "aqxdUDqiPMah0Tz_U1OsEQAAAXI"]
[Thu Sep 17 15:36:16.787801 2026] [security2:error] [pid 20162:tid 20296] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cd/.env"] [unique_id "aqxdUK-O_Kk7aqBvaiGBqwAAAZI"]
[Thu Sep 17 15:36:16.832447 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/uploads/.env"] [unique_id "aqxdUDqiPMah0Tz_U1OsEwAAATw"]
[Thu Sep 17 15:36:16.932869 2026] [security2:error] [pid 20162:tid 20364] [client 114.119.154.113:42299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bppa-nb.com"] [uri "/staying-safe/security-reports/37/"] [unique_id "aqxdUK-O_Kk7aqBvaiGBrQAAAdY"], referer: https://bppa-nb.com/staying-safe/security-reports/56/
[Thu Sep 17 15:36:16.950399 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/jenkins/.env"] [unique_id "aqxdUK-O_Kk7aqBvaiGBrgAAAZA"]
[Thu Sep 17 15:36:17.015618 2026] [security2:error] [pid 20162:tid 20402] [client 34.95.14.119:34672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxdUa-O_Kk7aqBvaiGBrwAAAfw"]
[Thu Sep 17 15:36:17.019421 2026] [security2:error] [pid 18946:tid 19199] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/internal/.env"] [unique_id "aqxdUTqiPMah0Tz_U1OsGAAAAYU"]
[Thu Sep 17 15:36:17.112693 2026] [security2:error] [pid 20162:tid 20372] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/gitlab/.env"] [unique_id "aqxdUa-O_Kk7aqBvaiGBsAAAAd4"]
[Thu Sep 17 15:36:17.181034 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.219.249:48942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/public/phpinfo.php"] [unique_id "aqxdUTqiPMah0Tz_U1OsGwAAAYc"]
[Thu Sep 17 15:36:17.181849 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/tools/.env"] [unique_id "aqxdUTqiPMah0Tz_U1OsHAAAAW0"]
[Thu Sep 17 15:36:17.278064 2026] [security2:error] [pid 20162:tid 20311] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/github/.env"] [unique_id "aqxdUa-O_Kk7aqBvaiGBsQAAAaE"]
[Thu Sep 17 15:36:17.325202 2026] [security2:error] [pid 18946:tid 19147] [client 34.95.14.119:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxdUTqiPMah0Tz_U1OsHQAAAVE"]
[Thu Sep 17 15:36:17.399574 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/scripts/.env"] [unique_id "aqxdUTqiPMah0Tz_U1OsHwAAATI"]
[Thu Sep 17 15:36:17.438578 2026] [security2:error] [pid 20162:tid 20319] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/actions/.env"] [unique_id "aqxdUa-O_Kk7aqBvaiGBsgAAAak"]
[Thu Sep 17 15:36:17.556833 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/bin/.env"] [unique_id "aqxdUTqiPMah0Tz_U1OsIwAAAXQ"]
[Thu Sep 17 15:36:17.602850 2026] [security2:error] [pid 20162:tid 20382] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/circleci/.env"] [unique_id "aqxdUa-O_Kk7aqBvaiGBswAAAeg"]
[Thu Sep 17 15:36:17.603196 2026] [access_compat:error] [pid 18946:tid 19090] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/fofumia
[Thu Sep 17 15:36:17.718698 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/sbin/.env"] [unique_id "aqxdUTqiPMah0Tz_U1OsKQAAAUY"]
[Thu Sep 17 15:36:17.765210 2026] [security2:error] [pid 20162:tid 20329] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/travis/.env"] [unique_id "aqxdUa-O_Kk7aqBvaiGBtwAAAbM"]
[Thu Sep 17 15:36:17.776298 2026] [security2:error] [pid 20162:tid 20369] [client 34.95.14.119:34694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxdUa-O_Kk7aqBvaiGBuAAAAds"]
[Thu Sep 17 15:36:17.837031 2026] [security2:error] [pid 20162:tid 20418] [client 57.141.14.27:64468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxdUa-O_Kk7aqBvaiGBtAACDFs"]
[Thu Sep 17 15:36:17.854861 2026] [security2:error] [pid 20162:tid 20387] [client 34.154.219.249:48944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/php-info.php"] [unique_id "aqxdUa-O_Kk7aqBvaiGBugAAAe0"]
[Thu Sep 17 15:36:17.881652 2026] [security2:error] [pid 20162:tid 20383] [client 114.119.141.51:45911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "comicsutra.com"] [uri "/cs/tv/tv_art/witchblade/sara_boxing_s.jpg"] [unique_id "aqxdUa-O_Kk7aqBvaiGBuwAAAek"], referer: http://comicsutra.com/cs/tv/tv_art/witchblade/sara_boxing_s.jpg
[Thu Sep 17 15:36:17.916864 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/local/.env"] [unique_id "aqxdUTqiPMah0Tz_U1OsLQAAAQ8"]
[Thu Sep 17 15:36:17.927537 2026] [security2:error] [pid 20162:tid 20335] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/buildkite/.env"] [unique_id "aqxdUa-O_Kk7aqBvaiGBvAAAAbk"]
[Thu Sep 17 15:36:18.085063 2026] [security2:error] [pid 20162:tid 20302] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mysql/.env"] [unique_id "aqxdUq-O_Kk7aqBvaiGBvwAAAZg"]
[Thu Sep 17 15:36:18.085920 2026] [security2:error] [pid 18946:tid 19172] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/portal/.env"] [unique_id "aqxdUjqiPMah0Tz_U1OsLwAAAWo"]
[Thu Sep 17 15:36:18.174136 2026] [security2:error] [pid 20162:tid 20306] [client 44.195.188.79:12300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "votersrevenge.info"] [uri "/index.php"] [unique_id "aqxdUK-O_Kk7aqBvaiGBrAAAAZw"]
[Thu Sep 17 15:36:18.196363 2026] [security2:error] [pid 18946:tid 19168] [client 34.95.14.119:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxdUjqiPMah0Tz_U1OsMQAAAWY"]
[Thu Sep 17 15:36:18.247880 2026] [security2:error] [pid 20162:tid 20410] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/postgres/.env"] [unique_id "aqxdUq-O_Kk7aqBvaiGBwQAAAgQ"]
[Thu Sep 17 15:36:18.310675 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/dashboard/.env"] [unique_id "aqxdUjqiPMah0Tz_U1OsMgAAAVc"]
[Thu Sep 17 15:36:18.339050 2026] [security2:error] [pid 20162:tid 20327] [client 34.154.219.249:48958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/phpversion.php"] [unique_id "aqxdUq-O_Kk7aqBvaiGBwgAAAbE"]
[Thu Sep 17 15:36:18.411488 2026] [security2:error] [pid 20162:tid 20331] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mongodb/.env"] [unique_id "aqxdUq-O_Kk7aqBvaiGBwwAAAbU"]
[Thu Sep 17 15:36:18.491717 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/panel/.env"] [unique_id "aqxdUjqiPMah0Tz_U1OsNQAAAXw"]
[Thu Sep 17 15:36:18.547936 2026] [security2:error] [pid 18946:tid 19155] [client 103.61.184.148:59754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdUjqiPMah0Tz_U1OsOAAAAVk"]
[Thu Sep 17 15:36:18.548066 2026] [security2:error] [pid 18946:tid 19155] [client 103.61.184.148:59754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdUjqiPMah0Tz_U1OsOAAAAVk"]
[Thu Sep 17 15:36:18.569698 2026] [security2:error] [pid 20162:tid 20411] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/redis/.env"] [unique_id "aqxdUq-O_Kk7aqBvaiGBxAAAAgU"]
[Thu Sep 17 15:36:18.677518 2026] [security2:error] [pid 18946:tid 19167] [client 34.95.14.119:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxdUjqiPMah0Tz_U1OsOwAAAWU"]
[Thu Sep 17 15:36:18.682439 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/crm/.env"] [unique_id "aqxdUjqiPMah0Tz_U1OsPAAAARk"]
[Thu Sep 17 15:36:18.729896 2026] [security2:error] [pid 20162:tid 20408] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/elasticsearch/.env"] [unique_id "aqxdUq-O_Kk7aqBvaiGBxQAAAgI"]
[Thu Sep 17 15:36:18.817750 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.219.249:48966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/_phpinfo.php"] [unique_id "aqxdUjqiPMah0Tz_U1OsQAAAAVM"]
[Thu Sep 17 15:36:18.844014 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/erp/.env"] [unique_id "aqxdUjqiPMah0Tz_U1OsQQAAAYg"]
[Thu Sep 17 15:36:18.890253 2026] [security2:error] [pid 20162:tid 20363] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/rabbitmq/.env"] [unique_id "aqxdUq-O_Kk7aqBvaiGBxgAAAdU"]
[Thu Sep 17 15:36:19.021337 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/shop/.env"] [unique_id "aqxdUzqiPMah0Tz_U1OsRQAAAVg"]
[Thu Sep 17 15:36:19.052840 2026] [security2:error] [pid 20162:tid 20300] [client 40.81.232.68:58621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxdU6-O_Kk7aqBvaiGBxwAAAZY"], referer: binance.com
[Thu Sep 17 15:36:19.055081 2026] [security2:error] [pid 20162:tid 20361] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/kafka/.env"] [unique_id "aqxdU6-O_Kk7aqBvaiGByAAAAdM"]
[Thu Sep 17 15:36:19.138979 2026] [security2:error] [pid 18946:tid 19097] [client 34.95.14.119:49050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxdUzqiPMah0Tz_U1OsSAAAAR8"]
[Thu Sep 17 15:36:19.206712 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.243.210:41900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/store/.env"] [unique_id "aqxdUzqiPMah0Tz_U1OsSwAAAXg"]
[Thu Sep 17 15:36:19.221882 2026] [security2:error] [pid 20162:tid 20317] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/queue/.env"] [unique_id "aqxdU6-O_Kk7aqBvaiGByQAAAac"]
[Thu Sep 17 15:36:19.290679 2026] [security2:error] [pid 20162:tid 20366] [client 34.154.219.249:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/old_phpinfo.php"] [unique_id "aqxdU6-O_Kk7aqBvaiGBygAAAdg"]
[Thu Sep 17 15:36:19.382358 2026] [security2:error] [pid 20162:tid 20413] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/worker/.env"] [unique_id "aqxdU6-O_Kk7aqBvaiGBywAAAgc"]
[Thu Sep 17 15:36:19.539863 2026] [security2:error] [pid 20162:tid 20397] [client 34.95.14.119:49052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxdU6-O_Kk7aqBvaiGBzgAAAfc"]
[Thu Sep 17 15:36:19.543258 2026] [security2:error] [pid 20162:tid 20386] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/job/.env"] [unique_id "aqxdU6-O_Kk7aqBvaiGBzwAAAew"]
[Thu Sep 17 15:36:19.709187 2026] [security2:error] [pid 20162:tid 20407] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/test/.env"] [unique_id "aqxdU6-O_Kk7aqBvaiGB0QAAAgE"]
[Thu Sep 17 15:36:19.759111 2026] [security2:error] [pid 18946:tid 19177] [client 34.154.219.249:48974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/server-info.php"] [unique_id "aqxdUzqiPMah0Tz_U1OsUwAAAW8"]
[Thu Sep 17 15:36:19.856250 2026] [security2:error] [pid 20162:tid 20358] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/saas/.env"] [unique_id "aqxdU6-O_Kk7aqBvaiGB0wAAAdA"]
[Thu Sep 17 15:36:19.867578 2026] [security2:error] [pid 20162:tid 20405] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/qa/.env"] [unique_id "aqxdU6-O_Kk7aqBvaiGB1AAAAf8"]
[Thu Sep 17 15:36:19.921454 2026] [security2:error] [pid 18946:tid 19150] [client 52.167.144.142:25144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.findproductivity.com"] [uri "/index.php"] [unique_id "aqxdUTqiPMah0Tz_U1OsKgAAAVQ"]
[Thu Sep 17 15:36:19.945525 2026] [security2:error] [pid 18946:tid 19131] [client 34.95.14.119:49062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdUzqiPMah0Tz_U1OsVgAAAUE"]
[Thu Sep 17 15:36:20.028790 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/preview/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB2AAAAfY"]
[Thu Sep 17 15:36:20.032961 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/client/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB2QAAAeQ"]
[Thu Sep 17 15:36:20.213634 2026] [security2:error] [pid 20162:tid 20298] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/beta/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB3AAAAZQ"]
[Thu Sep 17 15:36:20.229068 2026] [security2:error] [pid 18946:tid 19178] [client 143.105.152.240:31036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdVDqiPMah0Tz_U1OsWgAAAXA"]
[Thu Sep 17 15:36:20.229174 2026] [security2:error] [pid 18946:tid 19178] [client 143.105.152.240:31036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdVDqiPMah0Tz_U1OsWgAAAXA"]
[Thu Sep 17 15:36:20.247227 2026] [security2:error] [pid 20162:tid 20304] [client 34.154.219.249:43074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/server-status.php"] [unique_id "aqxdVK-O_Kk7aqBvaiGB3QAAAZo"]
[Thu Sep 17 15:36:20.251335 2026] [security2:error] [pid 20162:tid 20412] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/project/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB3gAAAgY"]
[Thu Sep 17 15:36:20.278004 2026] [security2:error] [pid 18946:tid 18989] [remote 45.157.54.43:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "realdubrovnikexperience.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVDqiPMah0Tz_U1OsXQABVio"]
[Thu Sep 17 15:36:20.278009 2026] [security2:error] [pid 18946:tid 18977] [remote 45.157.54.43:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "realdubrovnikexperience.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVDqiPMah0Tz_U1OsXgABFh4"]
[Thu Sep 17 15:36:20.278184 2026] [security2:error] [pid 18946:tid 19152] [client 45.157.54.43:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "realdubrovnikexperience.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVDqiPMah0Tz_U1OsXQABVio"]
[Thu Sep 17 15:36:20.278184 2026] [security2:error] [pid 18946:tid 19088] [client 45.157.54.43:65471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "realdubrovnikexperience.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVDqiPMah0Tz_U1OsXgABFh4"]
[Thu Sep 17 15:36:20.313364 2026] [security2:error] [pid 20162:tid 20374] [client 79.116.89.151:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVK-O_Kk7aqBvaiGB3wAAAeA"]
[Thu Sep 17 15:36:20.313500 2026] [security2:error] [pid 20162:tid 20374] [client 79.116.89.151:57794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVK-O_Kk7aqBvaiGB3wAAAeA"]
[Thu Sep 17 15:36:20.378222 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/uat/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB4AAAAZs"]
[Thu Sep 17 15:36:20.378348 2026] [security2:error] [pid 18946:tid 19111] [client 34.95.14.119:49078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdVDqiPMah0Tz_U1OsYAAAAS0"]
[Thu Sep 17 15:36:20.473654 2026] [security2:error] [pid 20162:tid 20342] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/admin-panel/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB4QAAAcA"]
[Thu Sep 17 15:36:20.533576 2026] [security2:error] [pid 20162:tid 20293] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/stage/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB4gAAAY8"]
[Thu Sep 17 15:36:20.689465 2026] [security2:error] [pid 20162:tid 20351] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/development/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB4wAAAck"]
[Thu Sep 17 15:36:20.711294 2026] [security2:error] [pid 20162:tid 20301] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/control-panel/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB5AAAAZc"]
[Thu Sep 17 15:36:20.844761 2026] [security2:error] [pid 20162:tid 20346] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/production/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB5QAAAcQ"]
[Thu Sep 17 15:36:20.923376 2026] [security2:error] [pid 20162:tid 20368] [client 34.95.14.119:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxdVK-O_Kk7aqBvaiGB5wAAAdo"]
[Thu Sep 17 15:36:20.966794 2026] [security2:error] [pid 20162:tid 20353] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/user-panel/.env"] [unique_id "aqxdVK-O_Kk7aqBvaiGB6QAAAcs"]
[Thu Sep 17 15:36:21.006586 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.21.169:52478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.adventuresofapril.com"] [uri "/config/app/.env"] [unique_id "aqxdVa-O_Kk7aqBvaiGB6gAAAbs"]
[Thu Sep 17 15:36:21.158292 2026] [security2:error] [pid 20162:tid 20371] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/node/.env"] [unique_id "aqxdVa-O_Kk7aqBvaiGB7AAAAd0"]
[Thu Sep 17 15:36:21.162425 2026] [security2:error] [pid 18946:tid 19171] [client 34.154.219.249:43078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdVTqiPMah0Tz_U1OsdQAAAWk"]
[Thu Sep 17 15:36:21.163228 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.21.169:52478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/phpinfo.php"] [unique_id "aqxdVa-O_Kk7aqBvaiGB7QAAAgg"]
[Thu Sep 17 15:36:21.240567 2026] [security2:error] [pid 20162:tid 20309] [client 114.119.145.239:42779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whataboutsarah.ca"] [uri "/category/coronavirus/"] [unique_id "aqxdVa-O_Kk7aqBvaiGB7gAAAZ8"], referer: http://whataboutsarah.ca/
[Thu Sep 17 15:36:21.305053 2026] [security2:error] [pid 18946:tid 19197] [client 34.95.14.119:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxdVTqiPMah0Tz_U1OseQAAAYM"]
[Thu Sep 17 15:36:21.344611 2026] [security2:error] [pid 20162:tid 20314] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/express/.env"] [unique_id "aqxdVa-O_Kk7aqBvaiGB8AAAAaQ"]
[Thu Sep 17 15:36:21.348092 2026] [security2:error] [pid 18946:tid 19139] [client 45.65.131.184:7640] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.joeledmundanderson.com"] [uri "/robots.txt"] [unique_id "aqxdVTqiPMah0Tz_U1OsegAAAUk"]
[Thu Sep 17 15:36:21.542328 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/next/.env"] [unique_id "aqxdVa-O_Kk7aqBvaiGB8wAAAcI"]
[Thu Sep 17 15:36:21.636885 2026] [security2:error] [pid 18946:tid 19167] [client 34.154.21.169:50176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/info.php"] [unique_id "aqxdVTqiPMah0Tz_U1OsggAAAWU"]
[Thu Sep 17 15:36:21.643985 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.219.249:43092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxdVTqiPMah0Tz_U1OsgwAAARk"]
[Thu Sep 17 15:36:21.707245 2026] [security2:error] [pid 20162:tid 20373] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/nuxt/.env"] [unique_id "aqxdVa-O_Kk7aqBvaiGB9QAAAd8"]
[Thu Sep 17 15:36:21.888484 2026] [security2:error] [pid 20162:tid 20328] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/nest/.env"] [unique_id "aqxdVa-O_Kk7aqBvaiGB9gAAAbI"]
[Thu Sep 17 15:36:22.072873 2026] [cgid:error] [pid 18946:tid 19114] [client 221.149.119.65:57867] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/WORDPRESS
[Thu Sep 17 15:36:22.093401 2026] [security2:error] [pid 20162:tid 20307] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/react/.env"] [unique_id "aqxdVq-O_Kk7aqBvaiGB-AAAAZ0"]
[Thu Sep 17 15:36:22.123913 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.21.169:50180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/php.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGB-QAAAZA"]
[Thu Sep 17 15:36:22.125381 2026] [security2:error] [pid 20162:tid 20402] [client 34.154.219.249:43098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGB-gAAAfw"]
[Thu Sep 17 15:36:22.224800 2026] [security2:error] [pid 18946:tid 19097] [client 114.119.140.64:20733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mybeloved.camera"] [uri "/photos/"] [unique_id "aqxdVjqiPMah0Tz_U1OsiQAAAR8"], referer: https://www.mybeloved.camera/photos/
[Thu Sep 17 15:36:22.317281 2026] [security2:error] [pid 20162:tid 20369] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/vue/.env"] [unique_id "aqxdVq-O_Kk7aqBvaiGB_AAAAds"]
[Thu Sep 17 15:36:22.333687 2026] [security2:error] [pid 18946:tid 19164] [client 105.155.189.228:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdVjqiPMah0Tz_U1OsiAABYhw"]
[Thu Sep 17 15:36:22.450842 2026] [security2:error] [pid 20162:tid 20356] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGB_QAAAc4"]
[Thu Sep 17 15:36:22.471111 2026] [security2:error] [pid 18946:tid 19160] [client 34.95.14.119:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdVjqiPMah0Tz_U1OsiwAAAV4"]
[Thu Sep 17 15:36:22.487004 2026] [security2:error] [pid 20162:tid 20335] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/angular/.env"] [unique_id "aqxdVq-O_Kk7aqBvaiGB_gAAAbk"]
[Thu Sep 17 15:36:22.588505 2026] [security2:error] [pid 20162:tid 20338] [client 34.154.219.249:43102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGCAwAAAbw"]
[Thu Sep 17 15:36:22.606565 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.21.169:50186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/i.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGCBAAAAaM"]
[Thu Sep 17 15:36:22.685138 2026] [security2:error] [pid 20162:tid 20410] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/svelte/.env"] [unique_id "aqxdVq-O_Kk7aqBvaiGCBwAAAgQ"]
[Thu Sep 17 15:36:22.693949 2026] [security2:error] [pid 20162:tid 20327] [client 208.109.2.10:2612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGCAAAAAdI"]
[Thu Sep 17 15:36:22.756221 2026] [security2:error] [pid 20162:tid 20355] [client 136.158.61.34:9554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGCCgAAAc0"]
[Thu Sep 17 15:36:22.756336 2026] [security2:error] [pid 20162:tid 20355] [client 136.158.61.34:9554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGCCgAAAc0"]
[Thu Sep 17 15:36:22.758776 2026] [security2:error] [pid 18946:tid 19165] [client 95.158.48.126:16918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdVjqiPMah0Tz_U1OskAAAAWM"]
[Thu Sep 17 15:36:22.790505 2026] [security2:error] [pid 18946:tid 19187] [client 210.222.43.21:61359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdVjqiPMah0Tz_U1OsjwAAAXk"], referer: http://talent-in-borders.com/sito
[Thu Sep 17 15:36:22.815535 2026] [security2:error] [pid 20162:tid 20343] [client 34.95.14.119:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGCDwAAAcE"]
[Thu Sep 17 15:36:22.885491 2026] [security2:error] [pid 20162:tid 20310] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/vite/.env"] [unique_id "aqxdVq-O_Kk7aqBvaiGCEgAAAaA"]
[Thu Sep 17 15:36:22.905946 2026] [security2:error] [pid 20162:tid 20418] [client 200.216.167.250:49238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdVq-O_Kk7aqBvaiGCDgAAAgw"]
[Thu Sep 17 15:36:23.047511 2026] [security2:error] [pid 20162:tid 20318] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/backup/.env"] [unique_id "aqxdV6-O_Kk7aqBvaiGCFQAAAag"]
[Thu Sep 17 15:36:23.062834 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.219.249:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdVzqiPMah0Tz_U1OsmAAAAR0"]
[Thu Sep 17 15:36:23.086900 2026] [security2:error] [pid 18946:tid 19079] [client 34.154.21.169:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/pi.php"] [unique_id "aqxdVzqiPMah0Tz_U1OsmQAAAQ0"]
[Thu Sep 17 15:36:23.164762 2026] [security2:error] [pid 18946:tid 19178] [client 34.95.14.119:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxdVzqiPMah0Tz_U1OsmgAAAXA"]
[Thu Sep 17 15:36:23.252101 2026] [security2:error] [pid 20162:tid 20357] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/backups/.env"] [unique_id "aqxdV6-O_Kk7aqBvaiGCGQAAAc8"]
[Thu Sep 17 15:36:23.427053 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/old/.env"] [unique_id "aqxdV6-O_Kk7aqBvaiGCGwAAAeQ"]
[Thu Sep 17 15:36:23.428319 2026] [security2:error] [pid 18946:tid 19088] [client 114.119.132.9:58213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nlfephrata.org"] [uri "/event/ohana-youth-ministry/2022-02-20"] [unique_id "aqxdVzqiPMah0Tz_U1OsnQAAARY"], referer: https://www.nlfephrata.org/event/ohana-youth-ministry/2022-02-27
[Thu Sep 17 15:36:23.531057 2026] [security2:error] [pid 20162:tid 20326] [client 34.154.219.249:43120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdV6-O_Kk7aqBvaiGCHQAAAbA"]
[Thu Sep 17 15:36:23.576046 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.21.169:50210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/pinfo.php"] [unique_id "aqxdV6-O_Kk7aqBvaiGCIAAAAfY"]
[Thu Sep 17 15:36:23.619125 2026] [security2:error] [pid 20162:tid 20393] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/tmp/.env"] [unique_id "aqxdV6-O_Kk7aqBvaiGCIgAAAfM"]
[Thu Sep 17 15:36:23.624359 2026] [security2:error] [pid 18946:tid 19181] [client 34.95.14.119:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhb.onr.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxdVzqiPMah0Tz_U1OsngAAAXM"]
[Thu Sep 17 15:36:23.793293 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/temp/.env"] [unique_id "aqxdV6-O_Kk7aqBvaiGCJQAAAZs"]
[Thu Sep 17 15:36:23.915039 2026] [authz_core:error] [pid 18946:tid 19012] [remote 162.120.185.205:32985] AH01630: client denied by server configuration: /home2/healiou1/public_html/sites/all/modules/advanced_forum/styles/naked/error_log, referer: https://www.google.com/
[Thu Sep 17 15:36:23.980556 2026] [security2:error] [pid 20162:tid 20333] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/lab/.env"] [unique_id "aqxdV6-O_Kk7aqBvaiGCJwAAAbc"]
[Thu Sep 17 15:36:24.018211 2026] [security2:error] [pid 20162:tid 20285] [remote 160.238.109.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.109.238.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littledove.space"] [uri "/xmlrpc.php"] [unique_id "aqxdV6-O_Kk7aqBvaiGCKAABwHk"]
[Thu Sep 17 15:36:24.018485 2026] [security2:error] [pid 20162:tid 20342] [client 160.238.109.246:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littledove.space"] [uri "/xmlrpc.php"] [unique_id "aqxdV6-O_Kk7aqBvaiGCKAABwHk"]
[Thu Sep 17 15:36:24.025196 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.219.249:43134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxdWDqiPMah0Tz_U1OspQAAAVE"]
[Thu Sep 17 15:36:24.050936 2026] [security2:error] [pid 20162:tid 20375] [client 34.154.21.169:50222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/test.php"] [unique_id "aqxdWK-O_Kk7aqBvaiGCKQAAAeE"]
[Thu Sep 17 15:36:24.169096 2026] [security2:error] [pid 20162:tid 20351] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/cronlab/.env"] [unique_id "aqxdWK-O_Kk7aqBvaiGCKwAAAck"]
[Thu Sep 17 15:36:24.339678 2026] [security2:error] [pid 20162:tid 20345] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/cron/.env"] [unique_id "aqxdWK-O_Kk7aqBvaiGCLwAAAcM"]
[Thu Sep 17 15:36:24.376646 2026] [security2:error] [pid 18946:tid 19126] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdWDqiPMah0Tz_U1OsqgAAATw"]
[Thu Sep 17 15:36:24.511590 2026] [security2:error] [pid 20162:tid 20359] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/en/.env"] [unique_id "aqxdWK-O_Kk7aqBvaiGCMQAAAdE"]
[Thu Sep 17 15:36:24.526851 2026] [security2:error] [pid 18946:tid 19087] [client 34.154.219.249:43138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/phpinfo.php.old"] [unique_id "aqxdWDqiPMah0Tz_U1OstgAAARU"]
[Thu Sep 17 15:36:24.703407 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/administrator/.env"] [unique_id "aqxdWK-O_Kk7aqBvaiGCNAAAAgg"]
[Thu Sep 17 15:36:24.711297 2026] [security2:error] [pid 18946:tid 19104] [client 14.96.156.146:64788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdWDqiPMah0Tz_U1OsuwAAASY"]
[Thu Sep 17 15:36:24.711573 2026] [security2:error] [pid 18946:tid 19104] [client 14.96.156.146:64788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdWDqiPMah0Tz_U1OsuwAAASY"]
[Thu Sep 17 15:36:24.756186 2026] [security2:error] [pid 18946:tid 19121] [client 114.198.138.124:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdWDqiPMah0Tz_U1OswQAAATc"]
[Thu Sep 17 15:36:24.756296 2026] [security2:error] [pid 18946:tid 19121] [client 114.198.138.124:62950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdWDqiPMah0Tz_U1OswQAAATc"]
[Thu Sep 17 15:36:24.765522 2026] [security2:error] [pid 20162:tid 20395] [client 34.154.21.169:50230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/p.php"] [unique_id "aqxdWK-O_Kk7aqBvaiGCNwAAAfU"]
[Thu Sep 17 15:36:24.902559 2026] [security2:error] [pid 20162:tid 20364] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/psnlink/.env"] [unique_id "aqxdWK-O_Kk7aqBvaiGCPgAAAdY"]
[Thu Sep 17 15:36:24.927360 2026] [security2:error] [pid 20162:tid 20296] [client 45.164.105.1:16236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdWK-O_Kk7aqBvaiGCOgABkno"]
[Thu Sep 17 15:36:24.993363 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.219.249:43142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/phpinfo.php~"] [unique_id "aqxdWDqiPMah0Tz_U1OsxwAAATs"]
[Thu Sep 17 15:36:25.065761 2026] [security2:error] [pid 20162:tid 20402] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/exapi/.env"] [unique_id "aqxdWa-O_Kk7aqBvaiGCQgAAAfw"]
[Thu Sep 17 15:36:25.118853 2026] [security2:error] [pid 18946:tid 19202] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdWDqiPMah0Tz_U1OsxgAAAYg"]
[Thu Sep 17 15:36:25.152483 2026] [security2:error] [pid 18946:tid 19098] [client 216.73.216.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mycarydentist.com"] [uri "/index.php"] [unique_id "aqxdWTqiPMah0Tz_U1OsyAAAASA"]
[Thu Sep 17 15:36:25.233034 2026] [security2:error] [pid 20162:tid 20398] [client 34.154.243.210:55660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/sitemaps/.env"] [unique_id "aqxdWa-O_Kk7aqBvaiGCRAAAAfg"]
[Thu Sep 17 15:36:25.249977 2026] [security2:error] [pid 20162:tid 20349] [client 34.154.21.169:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/debug.php"] [unique_id "aqxdWa-O_Kk7aqBvaiGCRgAAAcc"]
[Thu Sep 17 15:36:25.469915 2026] [security2:error] [pid 20162:tid 20401] [client 34.154.219.249:43148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/info.php.bak"] [unique_id "aqxdWa-O_Kk7aqBvaiGCTQAAAfs"]
[Thu Sep 17 15:36:25.739085 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.21.169:50252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxdWTqiPMah0Tz_U1Os2QAAAUI"]
[Thu Sep 17 15:36:25.957532 2026] [security2:error] [pid 18946:tid 19156] [client 202.46.62.55:64023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdWTqiPMah0Tz_U1Os3AABWkc"]
[Thu Sep 17 15:36:25.963841 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.219.249:43158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/phpinfo.php.save"] [unique_id "aqxdWTqiPMah0Tz_U1Os4AAAAR0"]
[Thu Sep 17 15:36:26.217513 2026] [security2:error] [pid 20162:tid 20310] [client 34.154.21.169:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/test/phpinfo.php"] [unique_id "aqxdWq-O_Kk7aqBvaiGCWAAAAaA"]
[Thu Sep 17 15:36:26.439916 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.219.249:43168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxdWjqiPMah0Tz_U1Os8QAAAYc"]
[Thu Sep 17 15:36:26.685024 2026] [security2:error] [pid 18946:tid 19175] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/logs/.env"] [unique_id "aqxdWjqiPMah0Tz_U1Os8wAAAW0"]
[Thu Sep 17 15:36:26.698543 2026] [security2:error] [pid 18946:tid 19134] [client 34.154.21.169:51978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxdWjqiPMah0Tz_U1Os9AAAAUQ"]
[Thu Sep 17 15:36:26.754819 2026] [security2:error] [pid 20162:tid 20303] [client 66.102.6.44:44217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healingmindsnola.org"] [uri "/index.php"] [unique_id "aqxdV6-O_Kk7aqBvaiGCIwAAAZk"]
[Thu Sep 17 15:36:26.790249 2026] [security2:error] [pid 18946:tid 19185] [client 177.44.133.72:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdWjqiPMah0Tz_U1Os9wAAAXc"]
[Thu Sep 17 15:36:26.790371 2026] [security2:error] [pid 18946:tid 19185] [client 177.44.133.72:52934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdWjqiPMah0Tz_U1Os9wAAAXc"]
[Thu Sep 17 15:36:26.821777 2026] [security2:error] [pid 20162:tid 20380] [client 40.81.232.68:54783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxdWq-O_Kk7aqBvaiGCXgAAAeY"], referer: binance.com
[Thu Sep 17 15:36:26.889647 2026] [security2:error] [pid 18946:tid 19100] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/cache/.env"] [unique_id "aqxdWjqiPMah0Tz_U1Os-QAAASI"]
[Thu Sep 17 15:36:26.927905 2026] [security2:error] [pid 20162:tid 20358] [client 34.154.219.249:43172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxdWq-O_Kk7aqBvaiGCXwAAAdA"]
[Thu Sep 17 15:36:27.060374 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mailer/.env"] [unique_id "aqxdWzqiPMah0Tz_U1Os-wAAARA"]
[Thu Sep 17 15:36:27.173442 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.21.169:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/old/phpinfo.php"] [unique_id "aqxdWzqiPMah0Tz_U1Os_AAAAUY"]
[Thu Sep 17 15:36:27.222269 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mail/.env"] [unique_id "aqxdWzqiPMah0Tz_U1Os_QAAAQ8"]
[Thu Sep 17 15:36:27.381788 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/email/.env"] [unique_id "aqxdWzqiPMah0Tz_U1OtAwAAAYM"]
[Thu Sep 17 15:36:27.394973 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.219.249:43188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxdWzqiPMah0Tz_U1OtBAAAAYQ"]
[Thu Sep 17 15:36:27.542710 2026] [security2:error] [pid 18946:tid 19078] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/smtp/.env"] [unique_id "aqxdWzqiPMah0Tz_U1OtBgAAAQw"]
[Thu Sep 17 15:36:27.658248 2026] [security2:error] [pid 18946:tid 19148] [client 34.154.21.169:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdWzqiPMah0Tz_U1OtCAAAAVI"]
[Thu Sep 17 15:36:27.699840 2026] [security2:error] [pid 20162:tid 20332] [client 114.119.154.87:48107] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "emilylutringer.com"] [uri "/DoctoralDelve/category/papers-docs-and-essays/"] [unique_id "aqxdW6-O_Kk7aqBvaiGCagAAAbY"], referer: https://emilylutringer.com/DoctoralDelve/2022/03/
[Thu Sep 17 15:36:27.712292 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mailing/.env"] [unique_id "aqxdWzqiPMah0Tz_U1OtCQAAATc"]
[Thu Sep 17 15:36:27.856471 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.219.249:43200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxdWzqiPMah0Tz_U1OtDAAAAXw"]
[Thu Sep 17 15:36:27.878442 2026] [security2:error] [pid 18946:tid 19172] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/notifications/.env"] [unique_id "aqxdWzqiPMah0Tz_U1OtDQAAAWo"]
[Thu Sep 17 15:36:27.935543 2026] [security2:error] [pid 18946:tid 19158] [client 114.119.130.183:48319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sfvhbt.org"] [uri "/marriage/"] [unique_id "aqxdWzqiPMah0Tz_U1OtDgAAAVw"], referer: https://www.sfvhbt.org/marriage/
[Thu Sep 17 15:36:28.061555 2026] [security2:error] [pid 18946:tid 19084] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/notify/.env"] [unique_id "aqxdXDqiPMah0Tz_U1OtDwAAARI"]
[Thu Sep 17 15:36:28.143125 2026] [security2:error] [pid 20162:tid 20333] [client 34.154.21.169:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/public/phpinfo.php"] [unique_id "aqxdXK-O_Kk7aqBvaiGCbwAAAbc"]
[Thu Sep 17 15:36:28.218013 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/sender/.env"] [unique_id "aqxdXDqiPMah0Tz_U1OtEAAAATs"]
[Thu Sep 17 15:36:28.325420 2026] [security2:error] [pid 18946:tid 19161] [client 34.154.219.249:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxdXDqiPMah0Tz_U1OtEwAAAV8"]
[Thu Sep 17 15:36:28.383318 2026] [security2:error] [pid 18946:tid 19143] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/campaign/.env"] [unique_id "aqxdXDqiPMah0Tz_U1OtFAAAAU0"]
[Thu Sep 17 15:36:28.552059 2026] [security2:error] [pid 18946:tid 19086] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/newsletter/.env"] [unique_id "aqxdXDqiPMah0Tz_U1OtFgAAARQ"]
[Thu Sep 17 15:36:28.680446 2026] [security2:error] [pid 20162:tid 20384] [client 202.46.62.49:13115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdXK-O_Kk7aqBvaiGCdAAAAeo"]
[Thu Sep 17 15:36:28.727869 2026] [security2:error] [pid 18946:tid 19164] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/ses/.env"] [unique_id "aqxdXDqiPMah0Tz_U1OtGQAAAWI"]
[Thu Sep 17 15:36:28.799719 2026] [security2:error] [pid 18946:tid 19108] [client 34.154.219.249:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/www/phpinfo.php"] [unique_id "aqxdXDqiPMah0Tz_U1OtHAAAASo"]
[Thu Sep 17 15:36:28.827613 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.21.169:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/php-info.php"] [unique_id "aqxdXK-O_Kk7aqBvaiGCeQAAAfQ"]
[Thu Sep 17 15:36:28.895414 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/sendgrid/.env"] [unique_id "aqxdXDqiPMah0Tz_U1OtHQAAAVA"]
[Thu Sep 17 15:36:29.052948 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/sparkpost/.env"] [unique_id "aqxdXTqiPMah0Tz_U1OtHwAAARs"]
[Thu Sep 17 15:36:29.219627 2026] [security2:error] [pid 18946:tid 19193] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/postmark/.env"] [unique_id "aqxdXTqiPMah0Tz_U1OtIAAAAX8"]
[Thu Sep 17 15:36:29.221634 2026] [security2:error] [pid 20162:tid 20294] [client 114.119.136.176:65035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thevagabondhiker.com"] [uri "/dscn8266_waterfall-along-rio-arazas-ordesa-2"] [unique_id "aqxdXa-O_Kk7aqBvaiGChAAAAZA"], referer: https://www.thevagabondhiker.com/dscn8266_waterfall-along-rio-arazas-ordesa-2/
[Thu Sep 17 15:36:29.247414 2026] [security2:error] [pid 20162:tid 20322] [client 103.61.184.148:60327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdXa-O_Kk7aqBvaiGChQAAAaw"]
[Thu Sep 17 15:36:29.247559 2026] [security2:error] [pid 20162:tid 20322] [client 103.61.184.148:60327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdXa-O_Kk7aqBvaiGChQAAAaw"]
[Thu Sep 17 15:36:29.272872 2026] [security2:error] [pid 18946:tid 19095] [client 34.154.219.249:43224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdXTqiPMah0Tz_U1OtJAAAAR0"]
[Thu Sep 17 15:36:29.321342 2026] [security2:error] [pid 20162:tid 20369] [client 34.154.21.169:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/phpversion.php"] [unique_id "aqxdXa-O_Kk7aqBvaiGCiQAAAds"]
[Thu Sep 17 15:36:29.382804 2026] [security2:error] [pid 18946:tid 19150] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mailgun/.env"] [unique_id "aqxdXTqiPMah0Tz_U1OtJwAAAVQ"]
[Thu Sep 17 15:36:29.541379 2026] [security2:error] [pid 18946:tid 19178] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mandrill/.env"] [unique_id "aqxdXTqiPMah0Tz_U1OtKgAAAXA"]
[Thu Sep 17 15:36:29.715334 2026] [security2:error] [pid 18946:tid 19115] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mailjet/.env"] [unique_id "aqxdXTqiPMah0Tz_U1OtLQAAATE"]
[Thu Sep 17 15:36:29.739262 2026] [security2:error] [pid 18946:tid 19077] [client 34.154.219.249:43232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdXTqiPMah0Tz_U1OtMAAAAQs"]
[Thu Sep 17 15:36:29.818688 2026] [security2:error] [pid 18946:tid 19163] [client 34.154.21.169:52042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/_phpinfo.php"] [unique_id "aqxdXTqiPMah0Tz_U1OtMwAAAWE"]
[Thu Sep 17 15:36:29.887111 2026] [security2:error] [pid 18946:tid 19105] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/brevo/.env"] [unique_id "aqxdXTqiPMah0Tz_U1OtNAAAASc"]
[Thu Sep 17 15:36:30.120200 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/transactional/.env"] [unique_id "aqxdXjqiPMah0Tz_U1OtNQAAAXQ"]
[Thu Sep 17 15:36:30.222738 2026] [security2:error] [pid 18946:tid 19100] [client 34.154.219.249:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/site/phpinfo.php"] [unique_id "aqxdXjqiPMah0Tz_U1OtNgAAASI"]
[Thu Sep 17 15:36:30.301419 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/bulk/.env"] [unique_id "aqxdXjqiPMah0Tz_U1OtOQAAAU8"]
[Thu Sep 17 15:36:30.320677 2026] [security2:error] [pid 20162:tid 20386] [client 34.154.21.169:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/old_phpinfo.php"] [unique_id "aqxdXq-O_Kk7aqBvaiGCkgAAAew"]
[Thu Sep 17 15:36:30.488892 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/aws/.env"] [unique_id "aqxdXjqiPMah0Tz_U1OtOgAAAUY"]
[Thu Sep 17 15:36:30.565195 2026] [security2:error] [pid 20162:tid 20362] [client 114.119.152.12:49723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "threadalittlelight.com"] [uri "/rocketship"] [unique_id "aqxdXq-O_Kk7aqBvaiGClQAAAdQ"], referer: https://threadalittlelight.com/rocketship/
[Thu Sep 17 15:36:30.646634 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/azure/.env"] [unique_id "aqxdXjqiPMah0Tz_U1OtPQAAAYQ"]
[Thu Sep 17 15:36:30.694932 2026] [security2:error] [pid 20162:tid 20319] [client 34.154.219.249:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxdXq-O_Kk7aqBvaiGClwAAAak"]
[Thu Sep 17 15:36:30.720880 2026] [security2:error] [pid 20162:tid 20367] [client 143.105.152.240:34291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdXq-O_Kk7aqBvaiGCmAAAAdk"]
[Thu Sep 17 15:36:30.721000 2026] [security2:error] [pid 20162:tid 20367] [client 143.105.152.240:34291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdXq-O_Kk7aqBvaiGCmAAAAdk"]
[Thu Sep 17 15:36:30.770450 2026] [security2:error] [pid 20162:tid 20321] [client 79.116.89.151:58568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdXq-O_Kk7aqBvaiGCmQAAAas"]
[Thu Sep 17 15:36:30.770572 2026] [security2:error] [pid 20162:tid 20321] [client 79.116.89.151:58568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdXq-O_Kk7aqBvaiGCmQAAAas"]
[Thu Sep 17 15:36:30.825059 2026] [security2:error] [pid 18946:tid 19173] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/gcp/.env"] [unique_id "aqxdXjqiPMah0Tz_U1OtQQAAAWs"]
[Thu Sep 17 15:36:30.833389 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.21.169:52058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/server-info.php"] [unique_id "aqxdXjqiPMah0Tz_U1OtQgAAASQ"]
[Thu Sep 17 15:36:30.992351 2026] [security2:error] [pid 18946:tid 19113] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/cloud/.env"] [unique_id "aqxdXjqiPMah0Tz_U1OtQwAAAS8"]
[Thu Sep 17 15:36:31.031800 2026] [security2:error] [pid 20162:tid 20374] [client 114.119.132.76:52385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mycarydentist.com"] [uri "/maximilian-kolbe/factors-affecting-motivation-in-psychology-slideshare"] [unique_id "aqxdX6-O_Kk7aqBvaiGCmwAAAeA"], referer: http://mycarydentist.com/maximilian-kolbe/factors-affecting-motivation-in-psychology-slideshare
[Thu Sep 17 15:36:31.148924 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/infrastructure/.env"] [unique_id "aqxdXzqiPMah0Tz_U1OtRAAAAVw"]
[Thu Sep 17 15:36:31.159810 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.219.249:56792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdXzqiPMah0Tz_U1OtRQAAAXw"]
[Thu Sep 17 15:36:31.312941 2026] [security2:error] [pid 18946:tid 19084] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/docker/.env"] [unique_id "aqxdXzqiPMah0Tz_U1OtSgAAARI"]
[Thu Sep 17 15:36:31.372532 2026] [security2:error] [pid 20162:tid 20399] [client 34.154.21.169:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/server-status.php"] [unique_id "aqxdX6-O_Kk7aqBvaiGCnwAAAfk"]
[Thu Sep 17 15:36:31.496455 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/k8s/.env"] [unique_id "aqxdXzqiPMah0Tz_U1OtTgAAATs"]
[Thu Sep 17 15:36:31.630719 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.219.249:56794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdXzqiPMah0Tz_U1OtTwAAAV0"]
[Thu Sep 17 15:36:31.681488 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/kubernetes/.env"] [unique_id "aqxdXzqiPMah0Tz_U1OtUQAAAUA"]
[Thu Sep 17 15:36:31.843066 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/terraform/.env"] [unique_id "aqxdXzqiPMah0Tz_U1OtVAAAATk"]
[Thu Sep 17 15:36:32.009139 2026] [security2:error] [pid 18946:tid 19161] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/ansible/.env"] [unique_id "aqxdYDqiPMah0Tz_U1OtVwAAAV8"]
[Thu Sep 17 15:36:32.115907 2026] [security2:error] [pid 20162:tid 20371] [client 34.154.219.249:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/core/phpinfo.php"] [unique_id "aqxdYK-O_Kk7aqBvaiGCqQAAAd0"]
[Thu Sep 17 15:36:32.164247 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/.git/.env"] [unique_id "aqxdYDqiPMah0Tz_U1OtWAAAARk"]
[Thu Sep 17 15:36:32.274786 2026] [security2:error] [pid 20162:tid 20337] [client 40.81.232.68:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxdYK-O_Kk7aqBvaiGCqwAAAbs"], referer: binance.com
[Thu Sep 17 15:36:32.313671 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.21.169:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdYK-O_Kk7aqBvaiGCrAAAAcI"]
[Thu Sep 17 15:36:32.336272 2026] [security2:error] [pid 18946:tid 19144] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/ci/.env"] [unique_id "aqxdYDqiPMah0Tz_U1OtXgAAAU4"]
[Thu Sep 17 15:36:32.505256 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/cd/.env"] [unique_id "aqxdYDqiPMah0Tz_U1OtYQAAAUI"]
[Thu Sep 17 15:36:32.615091 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.219.249:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.cellovsviolin.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxdYDqiPMah0Tz_U1OtYgAAAXg"]
[Thu Sep 17 15:36:32.660948 2026] [security2:error] [pid 18946:tid 19109] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/jenkins/.env"] [unique_id "aqxdYDqiPMah0Tz_U1OtYwAAASs"]
[Thu Sep 17 15:36:32.842421 2026] [security2:error] [pid 18946:tid 19093] [client 34.154.21.169:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxdYDqiPMah0Tz_U1OtaAAAARs"]
[Thu Sep 17 15:36:32.868585 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/gitlab/.env"] [unique_id "aqxdYDqiPMah0Tz_U1OtaQAAAT0"]
[Thu Sep 17 15:36:33.038018 2026] [security2:error] [pid 18946:tid 19184] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/github/.env"] [unique_id "aqxdYTqiPMah0Tz_U1OtbAAAAXY"]
[Thu Sep 17 15:36:33.211349 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/actions/.env"] [unique_id "aqxdYTqiPMah0Tz_U1OtcAAAAX0"]
[Thu Sep 17 15:36:33.320348 2026] [security2:error] [pid 18946:tid 19201] [client 34.154.21.169:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdYTqiPMah0Tz_U1OteAAAAYc"]
[Thu Sep 17 15:36:33.376232 2026] [security2:error] [pid 18946:tid 19094] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/circleci/.env"] [unique_id "aqxdYTqiPMah0Tz_U1OtfAAAARw"]
[Thu Sep 17 15:36:33.532044 2026] [security2:error] [pid 18946:tid 19103] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/travis/.env"] [unique_id "aqxdYTqiPMah0Tz_U1OtgwAAASU"]
[Thu Sep 17 15:36:33.606747 2026] [cgid:error] [pid 18946:tid 19145] [client 206.42.109.58:55276] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:36:33.692838 2026] [security2:error] [pid 18946:tid 19082] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/buildkite/.env"] [unique_id "aqxdYTqiPMah0Tz_U1OtiAAAARA"]
[Thu Sep 17 15:36:33.815815 2026] [security2:error] [pid 18946:tid 19196] [client 34.154.21.169:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdYTqiPMah0Tz_U1OtjgAAAYI"]
[Thu Sep 17 15:36:33.859814 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mysql/.env"] [unique_id "aqxdYTqiPMah0Tz_U1OtjwAAAYM"]
[Thu Sep 17 15:36:34.028657 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/postgres/.env"] [unique_id "aqxdYjqiPMah0Tz_U1OtlQAAAYY"]
[Thu Sep 17 15:36:34.185987 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/mongodb/.env"] [unique_id "aqxdYjqiPMah0Tz_U1OtmAAAAVw"]
[Thu Sep 17 15:36:34.295984 2026] [cgid:error] [pid 18946:tid 19125] [client 206.42.109.58:55276] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:36:34.323184 2026] [security2:error] [pid 18946:tid 19172] [client 34.154.21.169:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdYjqiPMah0Tz_U1OtoQAAAWo"]
[Thu Sep 17 15:36:34.341050 2026] [security2:error] [pid 18946:tid 19153] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/redis/.env"] [unique_id "aqxdYjqiPMah0Tz_U1OtogAAAVc"]
[Thu Sep 17 15:36:34.507816 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/elasticsearch/.env"] [unique_id "aqxdYjqiPMah0Tz_U1OtpgAAAVg"]
[Thu Sep 17 15:36:34.666418 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/rabbitmq/.env"] [unique_id "aqxdYjqiPMah0Tz_U1OtqQAAAUc"]
[Thu Sep 17 15:36:34.788969 2026] [security2:error] [pid 18946:tid 19110] [client 128.140.41.193:2528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxdYjqiPMah0Tz_U1OtpwAAASw"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:36:34.823793 2026] [security2:error] [pid 18946:tid 19118] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/kafka/.env"] [unique_id "aqxdYjqiPMah0Tz_U1OtrgAAATQ"]
[Thu Sep 17 15:36:34.832734 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.21.169:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdYjqiPMah0Tz_U1OtrwAAAR8"]
[Thu Sep 17 15:36:34.982770 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/queue/.env"] [unique_id "aqxdYjqiPMah0Tz_U1OttAAAAVA"]
[Thu Sep 17 15:36:35.142267 2026] [security2:error] [pid 18946:tid 19168] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/worker/.env"] [unique_id "aqxdYzqiPMah0Tz_U1OtuAAAAWY"]
[Thu Sep 17 15:36:35.299758 2026] [security2:error] [pid 18946:tid 19112] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/job/.env"] [unique_id "aqxdYzqiPMah0Tz_U1OtvQAAAS4"]
[Thu Sep 17 15:36:35.333259 2026] [cgid:error] [pid 18946:tid 19177] [client 206.42.109.58:55276] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:36:35.339875 2026] [security2:error] [pid 18946:tid 19186] [client 34.154.21.169:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxdYzqiPMah0Tz_U1OtwgAAAXg"]
[Thu Sep 17 15:36:35.479520 2026] [security2:error] [pid 18946:tid 19140] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/test/.env"] [unique_id "aqxdYzqiPMah0Tz_U1OtwwAAAUo"]
[Thu Sep 17 15:36:35.481262 2026] [security2:error] [pid 18946:tid 19195] [client 14.96.156.146:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdYzqiPMah0Tz_U1OtxAAAAYE"]
[Thu Sep 17 15:36:35.481370 2026] [security2:error] [pid 18946:tid 19195] [client 14.96.156.146:65420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdYzqiPMah0Tz_U1OtxAAAAYE"]
[Thu Sep 17 15:36:35.513155 2026] [security2:error] [pid 20162:tid 20354] [client 114.198.138.124:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdY6-O_Kk7aqBvaiGC3QAAAcw"]
[Thu Sep 17 15:36:35.513272 2026] [security2:error] [pid 20162:tid 20354] [client 114.198.138.124:63589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdY6-O_Kk7aqBvaiGC3QAAAcw"]
[Thu Sep 17 15:36:35.527077 2026] [security2:error] [pid 18946:tid 19179] [client 128.140.41.193:2534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxdYzqiPMah0Tz_U1OtwAAAAXE"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:36:35.644447 2026] [security2:error] [pid 18946:tid 19191] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/qa/.env"] [unique_id "aqxdYzqiPMah0Tz_U1OtygAAAX0"]
[Thu Sep 17 15:36:35.759761 2026] [security2:error] [pid 20162:tid 20400] [client 208.109.2.10:31442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bluetech.com"] [uri "/wp-login.php"] [unique_id "aqxdY6-O_Kk7aqBvaiGC3AAAAfo"], referer: https://bluetech.com/wp-login.php
[Thu Sep 17 15:36:35.799629 2026] [security2:error] [pid 18946:tid 19131] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/preview/.env"] [unique_id "aqxdYzqiPMah0Tz_U1Ot0QAAAUE"]
[Thu Sep 17 15:36:35.845136 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.21.169:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/phpinfo.php.old"] [unique_id "aqxdY6-O_Kk7aqBvaiGC4wAAAZk"]
[Thu Sep 17 15:36:35.956165 2026] [security2:error] [pid 18946:tid 19185] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/beta/.env"] [unique_id "aqxdYzqiPMah0Tz_U1Ot0wAAAXc"]
[Thu Sep 17 15:36:36.112541 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/uat/.env"] [unique_id "aqxdZDqiPMah0Tz_U1Ot1gAAAXQ"]
[Thu Sep 17 15:36:36.268465 2026] [security2:error] [pid 18946:tid 19100] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/stage/.env"] [unique_id "aqxdZDqiPMah0Tz_U1Ot2wAAASI"]
[Thu Sep 17 15:36:36.320817 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.21.169:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/phpinfo.php~"] [unique_id "aqxdZK-O_Kk7aqBvaiGC5wAAAeQ"]
[Thu Sep 17 15:36:36.360835 2026] [security2:error] [pid 18946:tid 19115] [client 136.158.61.34:10739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdZDqiPMah0Tz_U1Ot3gAAATE"]
[Thu Sep 17 15:36:36.360970 2026] [security2:error] [pid 18946:tid 19115] [client 136.158.61.34:10739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdZDqiPMah0Tz_U1Ot3gAAATE"]
[Thu Sep 17 15:36:36.392218 2026] [security2:error] [pid 20162:tid 20420] [client 114.119.128.23:56769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.freeofgravity.com"] [uri "/transformation-part-2-unwanted-attention/"] [unique_id "aqxdZK-O_Kk7aqBvaiGC6QAAAg4"], referer: https://www.freeofgravity.com/transformation-part-2-unwanted-attention
[Thu Sep 17 15:36:36.427015 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/development/.env"] [unique_id "aqxdZDqiPMah0Tz_U1Ot3wAAATg"]
[Thu Sep 17 15:36:36.585461 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/production/.env"] [unique_id "aqxdZDqiPMah0Tz_U1Ot4AAAAQ8"]
[Thu Sep 17 15:36:36.741804 2026] [security2:error] [pid 18946:tid 19076] [client 34.154.243.210:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/config/app/.env"] [unique_id "aqxdZDqiPMah0Tz_U1Ot4wAAAQo"]
[Thu Sep 17 15:36:36.835841 2026] [security2:error] [pid 18946:tid 19197] [client 114.119.152.139:60351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "showtimeeventsvb.com"] [uri "/partners_breakout_bash/"] [unique_id "aqxdZDqiPMah0Tz_U1Ot5gAAAYM"], referer: https://showtimeeventsvb.com/breakout-bash
[Thu Sep 17 15:36:36.843973 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.21.169:59928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/info.php.bak"] [unique_id "aqxdZDqiPMah0Tz_U1Ot5wAAAYQ"]
[Thu Sep 17 15:36:37.343841 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.21.169:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/phpinfo.php.save"] [unique_id "aqxdZTqiPMah0Tz_U1Ot7gAAAXw"]
[Thu Sep 17 15:36:37.540103 2026] [security2:error] [pid 18946:tid 19084] [client 177.44.133.72:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdZTqiPMah0Tz_U1Ot9AAAARI"]
[Thu Sep 17 15:36:37.541968 2026] [security2:error] [pid 18946:tid 19084] [client 177.44.133.72:53595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdZTqiPMah0Tz_U1Ot9AAAARI"]
[Thu Sep 17 15:36:37.837841 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.21.169:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxdZTqiPMah0Tz_U1Ot_gAAAUI"]
[Thu Sep 17 15:36:37.897959 2026] [security2:error] [pid 20162:tid 20417] [client 34.166.139.118:40180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/phpinfo.php"] [unique_id "aqxdZa-O_Kk7aqBvaiGC-wAAAgs"]
[Thu Sep 17 15:36:38.333998 2026] [security2:error] [pid 18946:tid 19101] [client 34.154.21.169:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxdZjqiPMah0Tz_U1OuCgAAASM"]
[Thu Sep 17 15:36:38.336529 2026] [security2:error] [pid 20162:tid 20403] [client 114.119.151.81:23765] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.streetwisepublicationsltd.com"] [uri "/the-worlds-worst-business/"] [unique_id "aqxdZq-O_Kk7aqBvaiGDAAAAAf0"], referer: https://www.streetwisepublicationsltd.com/2020/06/20
[Thu Sep 17 15:36:38.581197 2026] [security2:error] [pid 18946:tid 19079] [client 34.166.139.118:49018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/info.php"] [unique_id "aqxdZjqiPMah0Tz_U1OuEAAAAQ0"]
[Thu Sep 17 15:36:38.850488 2026] [security2:error] [pid 18946:tid 19126] [client 34.154.21.169:59974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxdZjqiPMah0Tz_U1OuFAAAATw"]
[Thu Sep 17 15:36:39.360369 2026] [security2:error] [pid 18946:tid 19196] [client 34.166.139.118:49022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/php.php"] [unique_id "aqxdZzqiPMah0Tz_U1OuHgAAAYI"]
[Thu Sep 17 15:36:39.371410 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.21.169:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxdZzqiPMah0Tz_U1OuHwAAAUs"]
[Thu Sep 17 15:36:39.592562 2026] [core:error] [pid 18946:tid 19188] [client 45.156.128.170:38258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:39.592583 2026] [core:error] [pid 18946:tid 19188] [client 45.156.128.170:38258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:39.875110 2026] [security2:error] [pid 20162:tid 20387] [client 34.154.21.169:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxdZ6-O_Kk7aqBvaiGDCgAAAe0"]
[Thu Sep 17 15:36:40.027011 2026] [security2:error] [pid 20162:tid 20329] [client 103.61.184.148:60849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdaK-O_Kk7aqBvaiGDCwAAAbM"]
[Thu Sep 17 15:36:40.027151 2026] [security2:error] [pid 20162:tid 20329] [client 103.61.184.148:60849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdaK-O_Kk7aqBvaiGDCwAAAbM"]
[Thu Sep 17 15:36:40.039523 2026] [security2:error] [pid 20162:tid 20398] [client 34.166.139.118:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/i.php"] [unique_id "aqxdaK-O_Kk7aqBvaiGDDgAAAfg"]
[Thu Sep 17 15:36:40.238460 2026] [core:error] [pid 20162:tid 20338] [client 45.156.128.169:35672] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:40.238479 2026] [core:error] [pid 20162:tid 20338] [client 45.156.128.169:35672] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:40.450296 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.21.169:60018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/www/phpinfo.php"] [unique_id "aqxdaDqiPMah0Tz_U1OuMAAAATs"]
[Thu Sep 17 15:36:40.818402 2026] [security2:error] [pid 18946:tid 19117] [client 34.166.139.118:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/pi.php"] [unique_id "aqxdaDqiPMah0Tz_U1OuNQAAATM"]
[Thu Sep 17 15:36:41.128431 2026] [security2:error] [pid 20162:tid 20419] [client 34.154.21.169:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdaa-O_Kk7aqBvaiGDGQAAAg0"]
[Thu Sep 17 15:36:41.357610 2026] [security2:error] [pid 20162:tid 20356] [client 143.105.152.240:16165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdaa-O_Kk7aqBvaiGDGwAAAc4"]
[Thu Sep 17 15:36:41.362086 2026] [security2:error] [pid 20162:tid 20356] [client 143.105.152.240:16165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdaa-O_Kk7aqBvaiGDGwAAAc4"]
[Thu Sep 17 15:36:41.453754 2026] [security2:error] [pid 20162:tid 20316] [client 79.116.89.151:59252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdaa-O_Kk7aqBvaiGDHAAAAaY"]
[Thu Sep 17 15:36:41.454263 2026] [security2:error] [pid 20162:tid 20316] [client 79.116.89.151:59252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdaa-O_Kk7aqBvaiGDHAAAAaY"]
[Thu Sep 17 15:36:41.525637 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.139.118:49052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/pinfo.php"] [unique_id "aqxdaTqiPMah0Tz_U1OuPgAAAYk"]
[Thu Sep 17 15:36:41.683855 2026] [security2:error] [pid 20162:tid 20310] [client 34.154.21.169:60036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdaa-O_Kk7aqBvaiGDHQAAAaA"]
[Thu Sep 17 15:36:42.150233 2026] [security2:error] [pid 20162:tid 20320] [client 38.77.137.20:56829] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "openpathdental.com"] [uri "/index.php"] [unique_id "aqxdZ6-O_Kk7aqBvaiGDCQAAAao"]
[Thu Sep 17 15:36:42.168869 2026] [security2:error] [pid 20162:tid 20358] [client 34.166.234.125:50966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/"] [unique_id "aqxdaq-O_Kk7aqBvaiGDIQAAAdA"]
[Thu Sep 17 15:36:42.210630 2026] [security2:error] [pid 18946:tid 19152] [client 34.154.21.169:60038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/site/phpinfo.php"] [unique_id "aqxdajqiPMah0Tz_U1OuSAAAAVY"]
[Thu Sep 17 15:36:42.304943 2026] [security2:error] [pid 18946:tid 19184] [client 34.166.139.118:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/test.php"] [unique_id "aqxdajqiPMah0Tz_U1OuSwAAAXY"]
[Thu Sep 17 15:36:42.419337 2026] [security2:error] [pid 18946:tid 19201] [client 114.119.155.42:20547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "clarkcougarsports.com"] [uri "/category/spring-sports/baseball/"] [unique_id "aqxdajqiPMah0Tz_U1OuTwAAAYc"], referer: https://clarkcougarsports.com/recruiting-videos/
[Thu Sep 17 15:36:42.754799 2026] [security2:error] [pid 20162:tid 20400] [client 34.154.21.169:60044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxdaq-O_Kk7aqBvaiGDIwAAAfo"]
[Thu Sep 17 15:36:42.853507 2026] [security2:error] [pid 18946:tid 19144] [client 34.166.234.125:50978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/"] [unique_id "aqxdajqiPMah0Tz_U1OuWAAAAU4"]
[Thu Sep 17 15:36:42.885520 2026] [core:error] [pid 20162:tid 20323] [client 45.156.128.168:33242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:42.885543 2026] [core:error] [pid 20162:tid 20323] [client 45.156.128.168:33242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:43.273859 2026] [security2:error] [pid 18946:tid 19173] [client 34.166.139.118:49078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/p.php"] [unique_id "aqxdazqiPMah0Tz_U1OuXwAAAWs"]
[Thu Sep 17 15:36:43.283359 2026] [security2:error] [pid 20162:tid 20381] [client 34.154.21.169:60046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxda6-O_Kk7aqBvaiGDKgAAAec"]
[Thu Sep 17 15:36:43.539724 2026] [security2:error] [pid 20162:tid 20332] [client 34.166.234.125:50986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/"] [unique_id "aqxda6-O_Kk7aqBvaiGDLQAAAbY"]
[Thu Sep 17 15:36:43.750067 2026] [security2:error] [pid 18946:tid 19135] [client 31.223.145.199:10254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdazqiPMah0Tz_U1OuaAABRTQ"]
[Thu Sep 17 15:36:43.840666 2026] [security2:error] [pid 18946:tid 19176] [client 34.154.21.169:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdazqiPMah0Tz_U1OubQAAAW4"]
[Thu Sep 17 15:36:43.992981 2026] [security2:error] [pid 18946:tid 19130] [client 34.166.139.118:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/debug.php"] [unique_id "aqxdazqiPMah0Tz_U1OubgAAAUA"]
[Thu Sep 17 15:36:44.101324 2026] [security2:error] [pid 18946:tid 19149] [client 38.77.137.20:56832] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.openpathdental.com"] [uri "/index.php"] [unique_id "aqxdajqiPMah0Tz_U1OuUAAAARQ"]
[Thu Sep 17 15:36:44.379025 2026] [security2:error] [pid 18946:tid 19202] [client 34.154.21.169:60060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/core/phpinfo.php"] [unique_id "aqxdbDqiPMah0Tz_U1OucgAAAYg"]
[Thu Sep 17 15:36:44.464993 2026] [security2:error] [pid 20162:tid 20372] [client 34.166.234.125:42256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/"] [unique_id "aqxdbK-O_Kk7aqBvaiGDOQAAAd4"]
[Thu Sep 17 15:36:44.677058 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.139.118:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxdbDqiPMah0Tz_U1OucwAAAWI"]
[Thu Sep 17 15:36:44.916847 2026] [security2:error] [pid 20162:tid 20402] [client 34.154.21.169:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.adventuresofapril.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxdbK-O_Kk7aqBvaiGDPAAAAfw"]
[Thu Sep 17 15:36:45.448064 2026] [security2:error] [pid 20162:tid 20390] [client 34.166.139.118:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/test/phpinfo.php"] [unique_id "aqxdba-O_Kk7aqBvaiGDPwAAAfA"]
[Thu Sep 17 15:36:45.697863 2026] [security2:error] [pid 20162:tid 20341] [client 14.227.156.221:55056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdba-O_Kk7aqBvaiGDQAABvxI"]
[Thu Sep 17 15:36:45.895406 2026] [core:error] [pid 20162:tid 20335] [client 45.156.128.168:33244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:45.895426 2026] [core:error] [pid 20162:tid 20335] [client 45.156.128.168:33244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:46.063205 2026] [security2:error] [pid 18946:tid 19095] [client 14.96.156.146:49941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdbjqiPMah0Tz_U1OujAAAAR0"]
[Thu Sep 17 15:36:46.063320 2026] [security2:error] [pid 18946:tid 19095] [client 14.96.156.146:49941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdbjqiPMah0Tz_U1OujAAAAR0"]
[Thu Sep 17 15:36:46.147947 2026] [security2:error] [pid 18946:tid 19085] [client 34.166.139.118:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxdbjqiPMah0Tz_U1OujgAAARM"]
[Thu Sep 17 15:36:46.266333 2026] [security2:error] [pid 20162:tid 20306] [client 114.198.138.124:49419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdbq-O_Kk7aqBvaiGDRQAAAZw"]
[Thu Sep 17 15:36:46.266441 2026] [security2:error] [pid 20162:tid 20306] [client 114.198.138.124:49419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdbq-O_Kk7aqBvaiGDRQAAAZw"]
[Thu Sep 17 15:36:46.574565 2026] [core:error] [pid 18946:tid 19126] [client 45.156.128.170:38274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:46.574591 2026] [core:error] [pid 18946:tid 19126] [client 45.156.128.170:38274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:46.829738 2026] [security2:error] [pid 18946:tid 19169] [client 114.119.158.157:31191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "timalba.com"] [uri "/parenting"] [unique_id "aqxdbjqiPMah0Tz_U1OuzgAAAWc"], referer: https://timalba.com/parenting
[Thu Sep 17 15:36:46.887536 2026] [security2:error] [pid 18946:tid 19175] [client 34.166.139.118:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/old/phpinfo.php"] [unique_id "aqxdbjqiPMah0Tz_U1Ou0gAAAW0"]
[Thu Sep 17 15:36:47.042064 2026] [security2:error] [pid 20162:tid 20344] [client 114.119.142.8:42453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hikingforwildness.com"] [uri "/the-geese-we-never-hear/"] [unique_id "aqxdb6-O_Kk7aqBvaiGDSQAAAcI"], referer: https://hikingforwildness.com/day-5-kentucky-camp
[Thu Sep 17 15:36:47.616527 2026] [security2:error] [pid 20162:tid 20313] [client 34.166.139.118:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdb6-O_Kk7aqBvaiGDTQAAAaM"]
[Thu Sep 17 15:36:48.141419 2026] [security2:error] [pid 18946:tid 19143] [client 177.44.133.72:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdcDqiPMah0Tz_U1Ou8gAAAU0"]
[Thu Sep 17 15:36:48.141560 2026] [security2:error] [pid 18946:tid 19143] [client 177.44.133.72:54247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdcDqiPMah0Tz_U1Ou8gAAAU0"]
[Thu Sep 17 15:36:48.306292 2026] [security2:error] [pid 18946:tid 19109] [client 34.166.139.118:49158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/public/phpinfo.php"] [unique_id "aqxdcDqiPMah0Tz_U1Ou_AAAASs"]
[Thu Sep 17 15:36:48.800036 2026] [security2:error] [pid 20162:tid 20418] [client 136.158.61.34:11862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdcK-O_Kk7aqBvaiGDVAAAAgw"]
[Thu Sep 17 15:36:48.800175 2026] [security2:error] [pid 20162:tid 20418] [client 136.158.61.34:11862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdcK-O_Kk7aqBvaiGDVAAAAgw"]
[Thu Sep 17 15:36:49.346717 2026] [security2:error] [pid 20162:tid 20404] [client 34.166.139.118:49162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/php-info.php"] [unique_id "aqxdca-O_Kk7aqBvaiGDWQAAAf4"]
[Thu Sep 17 15:36:50.115075 2026] [security2:error] [pid 20162:tid 20358] [client 34.166.139.118:49174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/phpversion.php"] [unique_id "aqxdcq-O_Kk7aqBvaiGDXQAAAdA"]
[Thu Sep 17 15:36:50.461010 2026] [core:error] [pid 20162:tid 20396] [client 45.156.128.169:41058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:50.461030 2026] [core:error] [pid 20162:tid 20396] [client 45.156.128.169:41058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:50.739232 2026] [security2:error] [pid 20162:tid 20343] [client 103.61.184.148:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdcq-O_Kk7aqBvaiGDYAAAAcE"]
[Thu Sep 17 15:36:50.739343 2026] [security2:error] [pid 20162:tid 20343] [client 103.61.184.148:61420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdcq-O_Kk7aqBvaiGDYAAAAcE"]
[Thu Sep 17 15:36:50.739390 2026] [security2:error] [pid 18946:tid 19148] [client 114.119.156.44:50011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.polishedclosets.com"] [uri "/the-look-athleisure/"] [unique_id "aqxdcjqiPMah0Tz_U1OvNQAAAVI"], referer: https://www.polishedclosets.com/clear-bags
[Thu Sep 17 15:36:50.797147 2026] [security2:error] [pid 18946:tid 19185] [client 34.166.139.118:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/_phpinfo.php"] [unique_id "aqxdcjqiPMah0Tz_U1OvNwAAAXc"]
[Thu Sep 17 15:36:50.946913 2026] [security2:error] [pid 20162:tid 20378] [client 127.0.0.1:18930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxdcq-O_Kk7aqBvaiGDYwAAAeQ"]
[Thu Sep 17 15:36:50.946977 2026] [security2:error] [pid 18946:tid 19172] [client 127.0.0.1:18916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.pascalweldinganddesign.com"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxdcjqiPMah0Tz_U1OvOQAAAWo"]
[Thu Sep 17 15:36:50.947149 2026] [security2:error] [pid 20162:tid 20392] [client 74.7.228.47:58586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.pascalweldinganddesign.com"] [uri "/robots.txt"] [unique_id "aqxdcq-O_Kk7aqBvaiGDYgAB8go"]
[Thu Sep 17 15:36:51.575854 2026] [security2:error] [pid 18946:tid 19153] [client 34.166.139.118:49196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/old_phpinfo.php"] [unique_id "aqxdczqiPMah0Tz_U1OvTAAAAVc"]
[Thu Sep 17 15:36:51.907348 2026] [security2:error] [pid 18946:tid 19146] [client 143.105.152.240:21480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdczqiPMah0Tz_U1OvVQAAAVA"]
[Thu Sep 17 15:36:51.912446 2026] [security2:error] [pid 18946:tid 19146] [client 143.105.152.240:21480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdczqiPMah0Tz_U1OvVQAAAVA"]
[Thu Sep 17 15:36:52.059679 2026] [security2:error] [pid 20162:tid 20324] [client 79.116.89.151:59901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxddK-O_Kk7aqBvaiGDZwAAAa4"]
[Thu Sep 17 15:36:52.059799 2026] [security2:error] [pid 20162:tid 20324] [client 79.116.89.151:59901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxddK-O_Kk7aqBvaiGDZwAAAa4"]
[Thu Sep 17 15:36:52.275478 2026] [security2:error] [pid 20162:tid 20399] [client 34.166.139.118:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/server-info.php"] [unique_id "aqxddK-O_Kk7aqBvaiGDaAAAAfk"]
[Thu Sep 17 15:36:52.397716 2026] [security2:error] [pid 18946:tid 19197] [client 60.228.199.209:60651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxdcTqiPMah0Tz_U1OvGgABgz0"]
[Thu Sep 17 15:36:52.397875 2026] [security2:error] [pid 18946:tid 19197] [client 60.228.199.209:60651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxdcTqiPMah0Tz_U1OvGwABgzI"]
[Thu Sep 17 15:36:52.603726 2026] [core:error] [pid 20162:tid 20379] [client 45.156.128.171:54912] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:52.603744 2026] [core:error] [pid 20162:tid 20379] [client 45.156.128.171:54912] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
suexec policy violation: see suexec log for more details
[Thu Sep 17 15:36:52.662810 2026] [cgid:error] [pid 18946:tid 19057] [remote 216.73.217.24:51312] End of script output before headers: dispatch.cgi
[Thu Sep 17 15:36:53.119564 2026] [security2:error] [pid 18946:tid 19106] [client 34.154.243.210:53418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxddTqiPMah0Tz_U1OvcQAAASg"]
[Thu Sep 17 15:36:53.219470 2026] [security2:error] [pid 20162:tid 20351] [client 34.166.139.118:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/server-status.php"] [unique_id "aqxdda-O_Kk7aqBvaiGDbwAAAck"]
[Thu Sep 17 15:36:53.274916 2026] [security2:error] [pid 18946:tid 19190] [client 34.154.243.210:53418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/phpinfo.php.old"] [unique_id "aqxddTqiPMah0Tz_U1OveAAAAXw"]
[Thu Sep 17 15:36:53.447286 2026] [security2:error] [pid 18946:tid 19125] [client 34.154.243.210:53418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/phpinfo.php~"] [unique_id "aqxddTqiPMah0Tz_U1OvfAAAATs"]
[Thu Sep 17 15:36:53.612258 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.243.210:53418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.ahmedteleb.com"] [uri "/info.php.bak"] [unique_id "aqxddTqiPMah0Tz_U1OvgwAAAUM"]
[Thu Sep 17 15:36:53.824016 2026] [security2:error] [pid 20162:tid 20402] [client 114.119.159.177:23009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.darfieldearthship.com"] [uri "/u-walls-are-done"] [unique_id "aqxdda-O_Kk7aqBvaiGDdwAAAfw"], referer: https://www.darfieldearthship.com/u-walls-are-done
[Thu Sep 17 15:36:54.383419 2026] [security2:error] [pid 20162:tid 20401] [client 34.166.139.118:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxddq-O_Kk7aqBvaiGDggAAAfs"]
[Thu Sep 17 15:36:55.084714 2026] [core:error] [pid 18946:tid 19187] [client 45.156.128.170:30120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:55.084743 2026] [core:error] [pid 18946:tid 19187] [client 45.156.128.170:30120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:55.174104 2026] [security2:error] [pid 18946:tid 19095] [client 34.166.139.118:49228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxddzqiPMah0Tz_U1OvmgAAAR0"]
[Thu Sep 17 15:36:55.779254 2026] [security2:error] [pid 18946:tid 19120] [client 134.185.85.61:49342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kaizenal.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxddzqiPMah0Tz_U1OvqQAAATY"]
[Thu Sep 17 15:36:55.913452 2026] [security2:error] [pid 18946:tid 19161] [client 34.166.139.118:49244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxddzqiPMah0Tz_U1OvqgAAAV8"]
[Thu Sep 17 15:36:56.171795 2026] [security2:error] [pid 20162:tid 20350] [client 134.185.85.61:50056] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "kaizenal.com"] [uri "/media/system/js/core.js"] [unique_id "aqxdeK-O_Kk7aqBvaiGDjgAAAcg"]
[Thu Sep 17 15:36:56.456061 2026] [security2:error] [pid 18946:tid 19080] [client 95.112.66.80:41351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdeDqiPMah0Tz_U1OvtQABDlk"]
[Thu Sep 17 15:36:56.618973 2026] [security2:error] [pid 18946:tid 19198] [client 34.166.139.118:49250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdeDqiPMah0Tz_U1OvvAAAAYQ"]
[Thu Sep 17 15:36:56.620920 2026] [security2:error] [pid 18946:tid 19196] [client 14.96.156.146:50571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdeDqiPMah0Tz_U1OvvQAAAYI"]
[Thu Sep 17 15:36:56.621047 2026] [security2:error] [pid 18946:tid 19196] [client 14.96.156.146:50571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdeDqiPMah0Tz_U1OvvQAAAYI"]
[Thu Sep 17 15:36:56.904316 2026] [security2:error] [pid 18946:tid 19174] [client 114.198.138.124:50090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdeDqiPMah0Tz_U1OvxAAAAWw"]
[Thu Sep 17 15:36:56.904420 2026] [security2:error] [pid 18946:tid 19174] [client 114.198.138.124:50090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdeDqiPMah0Tz_U1OvxAAAAWw"]
[Thu Sep 17 15:36:57.306806 2026] [security2:error] [pid 18946:tid 19123] [client 34.166.139.118:36782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdeTqiPMah0Tz_U1Ov0QAAATk"]
[Thu Sep 17 15:36:57.709816 2026] [security2:error] [pid 18946:tid 19095] [client 114.119.156.209:39925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gillilanproductions.com"] [uri "/xoxls0w/7j3i2i.php"] [unique_id "aqxdeTqiPMah0Tz_U1Ov3QAAAR0"], referer: http://gillilanproductions.com/xoxls0w/7j3i2i.php?vb=stanley-computer-game
[Thu Sep 17 15:36:57.988209 2026] [security2:error] [pid 18946:tid 19101] [client 34.166.139.118:36796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdeTqiPMah0Tz_U1Ov4gAAASM"]
[Thu Sep 17 15:36:58.190877 2026] [core:error] [pid 18946:tid 19156] [client 45.156.128.169:11236] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:58.190903 2026] [core:error] [pid 18946:tid 19156] [client 45.156.128.169:11236] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:58.631986 2026] [security2:error] [pid 18946:tid 19072] [remote 177.66.136.161:8978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdejqiPMah0Tz_U1Ov7gABC30"]
[Thu Sep 17 15:36:58.673746 2026] [security2:error] [pid 20162:tid 20397] [client 34.166.139.118:36808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxdeq-O_Kk7aqBvaiGDmQAAAfc"]
[Thu Sep 17 15:36:58.724197 2026] [core:error] [pid 20162:tid 20328] [client 45.156.128.168:43156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:58.724218 2026] [core:error] [pid 20162:tid 20328] [client 45.156.128.168:43156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:58.815616 2026] [security2:error] [pid 18946:tid 19081] [client 177.44.133.72:54901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdejqiPMah0Tz_U1Ov8wAAAQ8"]
[Thu Sep 17 15:36:58.815767 2026] [security2:error] [pid 18946:tid 19081] [client 177.44.133.72:54901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdejqiPMah0Tz_U1Ov8wAAAQ8"]
[Thu Sep 17 15:36:59.063240 2026] [security2:error] [pid 20162:tid 20316] [client 44.239.144.77:61640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxdea-O_Kk7aqBvaiGDlAAAAaY"], referer: http://worthtranslations.com/wp-old
[Thu Sep 17 15:36:59.336684 2026] [security2:error] [pid 18946:tid 19173] [client 161.58.212.81:47243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdezqiPMah0Tz_U1Ov-gABaxM"]
[Thu Sep 17 15:36:59.349096 2026] [core:error] [pid 20162:tid 20412] [client 45.156.128.170:38544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:59.349127 2026] [core:error] [pid 20162:tid 20412] [client 45.156.128.170:38544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:36:59.355619 2026] [security2:error] [pid 20162:tid 20362] [client 34.166.139.118:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/phpinfo.php.old"] [unique_id "aqxde6-O_Kk7aqBvaiGDpQAAAdQ"]
[Thu Sep 17 15:36:59.705815 2026] [security2:error] [pid 18946:tid 19141] [client 161.58.212.81:47069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdezqiPMah0Tz_U1Ov_wABSws"]
[Thu Sep 17 15:37:00.033852 2026] [security2:error] [pid 18946:tid 19125] [client 34.166.139.118:36838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/phpinfo.php~"] [unique_id "aqxdfDqiPMah0Tz_U1OwCwAAATs"]
[Thu Sep 17 15:37:00.234753 2026] [security2:error] [pid 18946:tid 19175] [client 162.241.226.11:28870] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxdfDqiPMah0Tz_U1OwDgAAAW0"]
[Thu Sep 17 15:37:00.712855 2026] [security2:error] [pid 20162:tid 20309] [client 34.166.139.118:36840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/info.php.bak"] [unique_id "aqxdfK-O_Kk7aqBvaiGDtQAAAZ8"]
[Thu Sep 17 15:37:01.046314 2026] [security2:error] [pid 20162:tid 20395] [client 136.158.61.34:13004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdfa-O_Kk7aqBvaiGDvgAAAfU"]
[Thu Sep 17 15:37:01.046447 2026] [security2:error] [pid 20162:tid 20395] [client 136.158.61.34:13004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdfa-O_Kk7aqBvaiGDvgAAAfU"]
[Thu Sep 17 15:37:01.407750 2026] [security2:error] [pid 20162:tid 20299] [client 34.166.139.118:36846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/phpinfo.php.save"] [unique_id "aqxdfa-O_Kk7aqBvaiGDwQAAAZU"]
[Thu Sep 17 15:37:01.521331 2026] [core:error] [pid 20162:tid 20410] [client 45.156.128.168:43160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:01.521360 2026] [core:error] [pid 20162:tid 20410] [client 45.156.128.168:43160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:01.554386 2026] [security2:error] [pid 20162:tid 20411] [client 103.61.184.148:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdfa-O_Kk7aqBvaiGDxAAAAgU"]
[Thu Sep 17 15:37:01.554535 2026] [security2:error] [pid 20162:tid 20411] [client 103.61.184.148:61974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdfa-O_Kk7aqBvaiGDxAAAAgU"]
[Thu Sep 17 15:37:02.094658 2026] [security2:error] [pid 18946:tid 19078] [client 34.166.139.118:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxdfjqiPMah0Tz_U1OwOwAAAQw"]
[Thu Sep 17 15:37:02.485273 2026] [security2:error] [pid 18946:tid 19197] [client 143.105.152.240:10983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdfjqiPMah0Tz_U1OwQQAAAYM"]
[Thu Sep 17 15:37:02.491380 2026] [security2:error] [pid 18946:tid 19197] [client 143.105.152.240:10983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdfjqiPMah0Tz_U1OwQQAAAYM"]
[Thu Sep 17 15:37:02.518456 2026] [security2:error] [pid 18946:tid 19099] [client 168.119.53.160:12250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxdfjqiPMah0Tz_U1OwQwAAASE"], referer: https://faewave.com
[Thu Sep 17 15:37:02.686044 2026] [security2:error] [pid 20162:tid 20355] [client 79.116.89.151:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdfq-O_Kk7aqBvaiGDygAAAc0"]
[Thu Sep 17 15:37:02.686183 2026] [security2:error] [pid 20162:tid 20355] [client 79.116.89.151:60532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdfq-O_Kk7aqBvaiGDygAAAc0"]
[Thu Sep 17 15:37:02.774018 2026] [security2:error] [pid 20162:tid 20366] [client 34.166.139.118:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxdfq-O_Kk7aqBvaiGDywAAAdg"]
[Thu Sep 17 15:37:03.449410 2026] [security2:error] [pid 18946:tid 19148] [client 34.166.139.118:36876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxdfzqiPMah0Tz_U1OwXAAAAVI"]
[Thu Sep 17 15:37:03.659086 2026] [security2:error] [pid 18946:tid 19138] [client 74.7.228.46:48098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "everybodylovesportugal.dov.wxt.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxdfzqiPMah0Tz_U1OwYAAAAUg"]
[Thu Sep 17 15:37:03.816887 2026] [core:error] [pid 18946:tid 19183] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:03.816910 2026] [core:error] [pid 18946:tid 19183] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.027983 2026] [security2:error] [pid 18946:tid 19098] [client 45.238.1.114:9164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdfzqiPMah0Tz_U1OwagABIBs"], referer: https://www.joeledmundanderson.com
[Thu Sep 17 15:37:04.041950 2026] [security2:error] [pid 18946:tid 19024] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.ssh/id_rsa"] [unique_id "aqxdgDqiPMah0Tz_U1OwcwABgE0"]
[Thu Sep 17 15:37:04.072993 2026] [core:error] [pid 18946:tid 19162] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.073014 2026] [core:error] [pid 18946:tid 19162] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.074171 2026] [core:error] [pid 20162:tid 20420] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.074189 2026] [core:error] [pid 20162:tid 20420] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.074436 2026] [core:error] [pid 18946:tid 19100] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.074458 2026] [core:error] [pid 18946:tid 19100] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.128803 2026] [security2:error] [pid 18946:tid 19152] [client 34.166.139.118:36890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxdgDqiPMah0Tz_U1OwegAAAVY"]
[Thu Sep 17 15:37:04.255785 2026] [core:error] [pid 18946:tid 19044] [remote 35.234.44.14:51108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.amecoegypt.com
[Thu Sep 17 15:37:04.255806 2026] [core:error] [pid 18946:tid 19044] [remote 35.234.44.14:51108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.amecoegypt.com
[Thu Sep 17 15:37:04.419777 2026] [core:error] [pid 18946:tid 19167] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.419796 2026] [core:error] [pid 18946:tid 19167] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.459508 2026] [security2:error] [pid 18946:tid 19197] [client 169.58.197.253:64622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxdgDqiPMah0Tz_U1OwhgAAAYM"], referer: binance.com
[Thu Sep 17 15:37:04.498900 2026] [core:error] [pid 20162:tid 20381] [client 45.156.128.170:38552] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.498917 2026] [core:error] [pid 20162:tid 20381] [client 45.156.128.170:38552] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.688016 2026] [core:error] [pid 20162:tid 20326] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.688035 2026] [core:error] [pid 20162:tid 20326] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.812993 2026] [security2:error] [pid 20162:tid 20374] [client 34.166.139.118:36906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxdgK-O_Kk7aqBvaiGD3QAAAeA"]
[Thu Sep 17 15:37:04.847800 2026] [core:error] [pid 18946:tid 19125] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.847820 2026] [core:error] [pid 18946:tid 19125] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.851732 2026] [core:error] [pid 18946:tid 19121] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.851748 2026] [core:error] [pid 18946:tid 19121] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:04.851786 2026] [security2:error] [pid 18946:tid 18964] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.ssh/id_dsa"] [unique_id "aqxdgDqiPMah0Tz_U1OwlgABJhE"]
[Thu Sep 17 15:37:04.854733 2026] [security2:error] [pid 18946:tid 19037] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/id_dsa"] [unique_id "aqxdgDqiPMah0Tz_U1OwlwABJlo"]
[Thu Sep 17 15:37:04.854844 2026] [security2:error] [pid 18946:tid 19104] [client 35.234.44.14:51108] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/id_dsa"] [unique_id "aqxdgDqiPMah0Tz_U1OwlwABJlo"]
[Thu Sep 17 15:37:04.857372 2026] [security2:error] [pid 18946:tid 19102] [client 49.36.9.27:34340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdgDqiPMah0Tz_U1OwjwABJAY"]
[Thu Sep 17 15:37:04.897367 2026] [security2:error] [pid 18946:tid 18986] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/.ssh/known_hosts"] [unique_id "aqxdgDqiPMah0Tz_U1OwmgABHic"]
[Thu Sep 17 15:37:04.946133 2026] [core:error] [pid 18946:tid 18980] [remote 35.234.44.14:51108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.amecoegypt.com
[Thu Sep 17 15:37:04.946159 2026] [core:error] [pid 18946:tid 18980] [remote 35.234.44.14:51108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.amecoegypt.com
[Thu Sep 17 15:37:04.972838 2026] [security2:error] [pid 18946:tid 18995] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/id_rsa"] [unique_id "aqxdgDqiPMah0Tz_U1OwnAABfjA"]
[Thu Sep 17 15:37:05.083713 2026] [security2:error] [pid 18946:tid 19014] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/key.pem"] [unique_id "aqxdgTqiPMah0Tz_U1OwoAABQEM"]
[Thu Sep 17 15:37:05.094697 2026] [security2:error] [pid 18946:tid 19004] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/id_ed25519"] [unique_id "aqxdgTqiPMah0Tz_U1OwpAABQDk"]
[Thu Sep 17 15:37:05.094699 2026] [security2:error] [pid 18946:tid 19000] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/id_ecdsa"] [unique_id "aqxdgTqiPMah0Tz_U1OwowABQDU"]
[Thu Sep 17 15:37:05.094900 2026] [security2:error] [pid 18946:tid 19130] [client 35.234.44.14:51108] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/id_ed25519"] [unique_id "aqxdgTqiPMah0Tz_U1OwpAABQDk"]
[Thu Sep 17 15:37:05.095848 2026] [security2:error] [pid 18946:tid 19068] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/privatekey.key"] [unique_id "aqxdgTqiPMah0Tz_U1OwogABQHk"]
[Thu Sep 17 15:37:05.113429 2026] [core:error] [pid 18946:tid 19089] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.113444 2026] [core:error] [pid 18946:tid 19089] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.184581 2026] [core:error] [pid 18946:tid 19023] [remote 35.234.44.14:51108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.amecoegypt.com
[Thu Sep 17 15:37:05.184613 2026] [core:error] [pid 18946:tid 19023] [remote 35.234.44.14:51108] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.amecoegypt.com
[Thu Sep 17 15:37:05.307094 2026] [core:error] [pid 18946:tid 19193] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.307116 2026] [core:error] [pid 18946:tid 19193] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.308034 2026] [core:error] [pid 18946:tid 19178] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.308048 2026] [core:error] [pid 18946:tid 19178] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.328007 2026] [core:error] [pid 18946:tid 19147] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.328024 2026] [core:error] [pid 18946:tid 19147] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.347151 2026] [core:error] [pid 18946:tid 19170] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.347166 2026] [core:error] [pid 18946:tid 19170] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.361358 2026] [core:error] [pid 18946:tid 19088] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.361382 2026] [core:error] [pid 18946:tid 19088] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.443361 2026] [security2:error] [pid 18946:tid 18977] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/.bashrc"] [unique_id "aqxdgTqiPMah0Tz_U1OwwgABIh4"]
[Thu Sep 17 15:37:05.443584 2026] [security2:error] [pid 18946:tid 19100] [client 35.234.44.14:51108] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/.bashrc"] [unique_id "aqxdgTqiPMah0Tz_U1OwwgABIh4"]
[Thu Sep 17 15:37:05.503102 2026] [security2:error] [pid 18946:tid 19087] [client 34.166.139.118:36908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/www/phpinfo.php"] [unique_id "aqxdgTqiPMah0Tz_U1OwxQAAARU"]
[Thu Sep 17 15:37:05.531941 2026] [core:error] [pid 20162:tid 20372] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.531959 2026] [core:error] [pid 20162:tid 20372] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.585455 2026] [security2:error] [pid 18946:tid 19005] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/@fs/src/.env"] [unique_id "aqxdgTqiPMah0Tz_U1OwxgABZDo"]
[Thu Sep 17 15:37:05.650989 2026] [security2:error] [pid 18946:tid 19022] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdgTqiPMah0Tz_U1OwyAABWks"]
[Thu Sep 17 15:37:05.673386 2026] [security2:error] [pid 18946:tid 19013] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/@fs/app/.env"] [unique_id "aqxdgTqiPMah0Tz_U1OwygABPkI"]
[Thu Sep 17 15:37:05.676692 2026] [security2:error] [pid 18946:tid 19002] [remote 35.234.44.14:51108] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/.zshrc"] [unique_id "aqxdgTqiPMah0Tz_U1OwzAABPjc"]
[Thu Sep 17 15:37:05.702173 2026] [core:error] [pid 18946:tid 19194] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.702200 2026] [core:error] [pid 18946:tid 19194] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:05.787116 2026] [security2:error] [pid 18946:tid 19033] [remote 35.234.44.14:51108] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "aqxdgTqiPMah0Tz_U1Ow0gABXlY"]
[Thu Sep 17 15:37:06.183994 2026] [security2:error] [pid 20162:tid 20398] [client 34.166.139.118:36910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdgq-O_Kk7aqBvaiGD7AAAAfg"]
[Thu Sep 17 15:37:06.685883 2026] [security2:error] [pid 18946:tid 18981] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/static//app/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow7QABFCI"]
[Thu Sep 17 15:37:06.685882 2026] [security2:error] [pid 18946:tid 19063] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/api/.env/public/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow6gABFHQ"]
[Thu Sep 17 15:37:06.685887 2026] [security2:error] [pid 18946:tid 19054] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow7AABFGs"]
[Thu Sep 17 15:37:06.686225 2026] [security2:error] [pid 18946:tid 19086] [client 35.234.44.14:51110] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/static//app/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow7QABFCI"]
[Thu Sep 17 15:37:06.687084 2026] [security2:error] [pid 18946:tid 19061] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow6wABFHI"]
[Thu Sep 17 15:37:06.687092 2026] [security2:error] [pid 18946:tid 19009] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/static/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow6QABFD4"]
[Thu Sep 17 15:37:06.687126 2026] [security2:error] [pid 18946:tid 19053] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/static/home/user/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow6AABFGo"]
[Thu Sep 17 15:37:06.869449 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.139.118:36922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdgjqiPMah0Tz_U1Ow-AAAAU0"]
[Thu Sep 17 15:37:06.883745 2026] [security2:error] [pid 18946:tid 19010] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow-QABVD8"]
[Thu Sep 17 15:37:06.883770 2026] [security2:error] [pid 18946:tid 18990] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/images../.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow-gABVCs"]
[Thu Sep 17 15:37:06.884456 2026] [security2:error] [pid 18946:tid 19031] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/assets../.env"] [unique_id "aqxdgjqiPMah0Tz_U1Ow-wABVFQ"]
[Thu Sep 17 15:37:06.889668 2026] [core:error] [pid 18946:tid 19034] [remote 35.234.44.14:51110] AH10244: invalid URI path (/%2e%2e/.env)
[Thu Sep 17 15:37:06.918309 2026] [core:error] [pid 20162:tid 20409] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:06.918332 2026] [core:error] [pid 20162:tid 20409] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:06.965432 2026] [security2:error] [pid 18946:tid 19091] [client 206.248.98.230:49203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdgjqiPMah0Tz_U1Ow9AABGWc"]
[Thu Sep 17 15:37:07.082494 2026] [core:error] [pid 18946:tid 19114] [client 45.156.128.170:38560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.082521 2026] [core:error] [pid 18946:tid 19114] [client 45.156.128.170:38560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.212393 2026] [security2:error] [pid 18946:tid 18993] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/img../.env"] [unique_id "aqxdgzqiPMah0Tz_U1OxCwABhS4"]
[Thu Sep 17 15:37:07.212400 2026] [security2:error] [pid 18946:tid 19018] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/uploads../.env"] [unique_id "aqxdgzqiPMah0Tz_U1OxCgABhUc"]
[Thu Sep 17 15:37:07.213182 2026] [security2:error] [pid 18946:tid 19184] [client 14.96.156.146:51200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdgzqiPMah0Tz_U1OxDAAAAXY"]
[Thu Sep 17 15:37:07.213264 2026] [security2:error] [pid 18946:tid 19184] [client 14.96.156.146:51200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdgzqiPMah0Tz_U1OxDAAAAXY"]
[Thu Sep 17 15:37:07.217892 2026] [security2:error] [pid 18946:tid 18956] [remote 35.234.44.14:51110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/@fs/var/task/.env"] [unique_id "aqxdgzqiPMah0Tz_U1OxDQABXQk"]
[Thu Sep 17 15:37:07.218025 2026] [security2:error] [pid 18946:tid 19159] [client 35.234.44.14:51110] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/@fs/var/task/.env"] [unique_id "aqxdgzqiPMah0Tz_U1OxDQABXQk"]
[Thu Sep 17 15:37:07.246119 2026] [core:error] [pid 18946:tid 19083] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.246140 2026] [core:error] [pid 18946:tid 19083] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.274737 2026] [core:error] [pid 18946:tid 19100] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.274757 2026] [core:error] [pid 18946:tid 19100] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.325057 2026] [core:error] [pid 18946:tid 19122] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.325079 2026] [core:error] [pid 18946:tid 19122] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:07.567536 2026] [security2:error] [pid 18946:tid 19087] [client 34.166.139.118:55384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/site/phpinfo.php"] [unique_id "aqxdgzqiPMah0Tz_U1OxIgAAARU"]
[Thu Sep 17 15:37:07.570139 2026] [security2:error] [pid 18946:tid 19124] [client 114.198.138.124:50739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdgzqiPMah0Tz_U1OxIQAAATo"]
[Thu Sep 17 15:37:07.570207 2026] [security2:error] [pid 18946:tid 19124] [client 114.198.138.124:50739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdgzqiPMah0Tz_U1OxIQAAATo"]
[Thu Sep 17 15:37:07.842064 2026] [security2:error] [pid 18946:tid 19052] [remote 35.234.44.14:51110] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aqxdgzqiPMah0Tz_U1OxKAABg2k"]
[Thu Sep 17 15:37:07.939210 2026] [security2:error] [pid 18946:tid 19144] [client 212.28.183.205:49158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "box5305.bluehost.com"] [uri "/.cache/.env"] [unique_id "aqxdgzqiPMah0Tz_U1OxLQAAAU4"]
[Thu Sep 17 15:37:08.083610 2026] [security2:error] [pid 20162:tid 20327] [client 212.28.183.205:49166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "box5305.bluehost.com"] [uri "/cache/.env"] [unique_id "aqxdhK-O_Kk7aqBvaiGD_gAAAbE"]
[Thu Sep 17 15:37:08.214789 2026] [security2:error] [pid 20162:tid 20363] [client 212.28.183.205:49174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "box5305.bluehost.com"] [uri "/cakephp/.env"] [unique_id "aqxdhK-O_Kk7aqBvaiGD_wAAAdU"]
[Thu Sep 17 15:37:08.264394 2026] [security2:error] [pid 18946:tid 19164] [client 34.166.139.118:55388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxdhDqiPMah0Tz_U1OxMwAAAWI"]
[Thu Sep 17 15:37:08.443649 2026] [security2:error] [pid 20162:tid 20216] [remote 35.234.44.14:51116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/@fs/.env"] [unique_id "aqxdhK-O_Kk7aqBvaiGECgABujQ"]
[Thu Sep 17 15:37:08.443711 2026] [security2:error] [pid 20162:tid 20217] [remote 35.234.44.14:51116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/@fs/.env"] [unique_id "aqxdhK-O_Kk7aqBvaiGECwABujU"]
[Thu Sep 17 15:37:08.732510 2026] [security2:error] [pid 20162:tid 20214] [remote 35.234.44.14:51116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filename. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/__vite_rsc_findSourceMapURL"] [unique_id "aqxdhK-O_Kk7aqBvaiGEDAAB2zI"]
[Thu Sep 17 15:37:08.759605 2026] [security2:error] [pid 20162:tid 20205] [remote 35.234.44.14:51116] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxdhK-O_Kk7aqBvaiGEDQAB_ik"]
[Thu Sep 17 15:37:08.760417 2026] [security2:error] [pid 20162:tid 20221] [remote 35.234.44.14:51116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/@fs/.env"] [unique_id "aqxdhK-O_Kk7aqBvaiGEEAAB_jk"]
[Thu Sep 17 15:37:08.760926 2026] [security2:error] [pid 20162:tid 20229] [remote 35.234.44.14:51116] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/__vite_rsc_findSourceMapURL"] [unique_id "aqxdhK-O_Kk7aqBvaiGEDgAB_kE"]
[Thu Sep 17 15:37:08.760928 2026] [security2:error] [pid 20162:tid 20231] [remote 35.234.44.14:51116] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/__vite_rsc_findSourceMapURL"] [unique_id "aqxdhK-O_Kk7aqBvaiGEDwAB_kM"]
[Thu Sep 17 15:37:08.947394 2026] [security2:error] [pid 18946:tid 19146] [client 34.166.139.118:55402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdhDqiPMah0Tz_U1OxSAAAAVA"]
[Thu Sep 17 15:37:09.310338 2026] [security2:error] [pid 18946:tid 19073] [remote 35.234.44.14:51122] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/public/plugins/text/../../../../../../../../proc/self/environ"] [unique_id "aqxdhTqiPMah0Tz_U1OxTQABOX4"]
[Thu Sep 17 15:37:09.564098 2026] [security2:error] [pid 18946:tid 19100] [client 177.44.133.72:55584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdhTqiPMah0Tz_U1OxUgAAASI"]
[Thu Sep 17 15:37:09.564209 2026] [security2:error] [pid 18946:tid 19100] [client 177.44.133.72:55584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdhTqiPMah0Tz_U1OxUgAAASI"]
[Thu Sep 17 15:37:09.626215 2026] [security2:error] [pid 20162:tid 20303] [client 34.166.139.118:55404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdha-O_Kk7aqBvaiGEGwAAAZk"]
[Thu Sep 17 15:37:10.095654 2026] [core:error] [pid 20162:tid 20381] [client 45.156.128.169:32908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:10.095684 2026] [core:error] [pid 20162:tid 20381] [client 45.156.128.169:32908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:10.230272 2026] [authz_core:error] [pid 18946:tid 19163] [client 40.81.232.68:54954] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:37:10.309554 2026] [security2:error] [pid 18946:tid 19153] [client 34.166.139.118:55418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/core/phpinfo.php"] [unique_id "aqxdhjqiPMah0Tz_U1OxWgAAAVc"]
[Thu Sep 17 15:37:10.452641 2026] [security2:error] [pid 20162:tid 20226] [remote 35.234.44.14:51136] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ"] [unique_id "aqxdhq-O_Kk7aqBvaiGEJwAB2T4"]
[Thu Sep 17 15:37:10.452726 2026] [security2:error] [pid 20162:tid 20218] [remote 35.234.44.14:51136] ModSecurity: Access denied with code 500 (phase 1) (Error: Connection drop requested but failed to close the  socket). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ"] [unique_id "aqxdhq-O_Kk7aqBvaiGEIwAB2TY"]
[Thu Sep 17 15:37:10.452728 2026] [security2:error] [pid 20162:tid 20213] [remote 35.234.44.14:51136] ModSecurity: Access denied with code 500 (phase 1) (Error: Connection drop requested but failed to close the  socket). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "aqxdhq-O_Kk7aqBvaiGEJQAB2TE"]
[Thu Sep 17 15:37:10.452788 2026] [security2:error] [pid 20162:tid 20224] [remote 35.234.44.14:51136] ModSecurity: Warning. Pattern match "%2e.%2e%2e" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1524"] [id "900917"] [msg "temporary CVE-2021-41773 logging rule"] [hostname "cpanel.amecoegypt.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqxdhq-O_Kk7aqBvaiGEJAAB2Tw"]
[Thu Sep 17 15:37:10.452825 2026] [core:error] [pid 20162:tid 20224] [remote 35.234.44.14:51136] AH10244: invalid URI path (/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env)
[Thu Sep 17 15:37:10.478350 2026] [core:error] [pid 20162:tid 20353] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:10.478372 2026] [core:error] [pid 20162:tid 20353] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:10.492830 2026] [security2:error] [pid 20162:tid 20380] [client 167.172.76.13:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.trcco.org"] [uri "/index.php"] [unique_id "aqxdha-O_Kk7aqBvaiGEFQAB5jc"], referer: http://www.trcco.org/wp/
[Thu Sep 17 15:37:10.589901 2026] [security2:error] [pid 20162:tid 20351] [client 192.178.6.4:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxdhq-O_Kk7aqBvaiGELQAAAck"]
[Thu Sep 17 15:37:10.801495 2026] [core:error] [pid 20162:tid 20312] [client 45.156.128.169:32912] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:10.801521 2026] [core:error] [pid 20162:tid 20312] [client 45.156.128.169:32912] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:10.965815 2026] [core:error] [pid 20162:tid 20230] [remote 35.234.44.14:51138] AH10244: invalid URI path (/appearance/../../.env)
[Thu Sep 17 15:37:10.991459 2026] [core:error] [pid 18946:tid 19173] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:10.991481 2026] [core:error] [pid 18946:tid 19173] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:11.005867 2026] [security2:error] [pid 20162:tid 20333] [client 34.166.139.118:55428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.139.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kbmautomation.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxdh6-O_Kk7aqBvaiGEMgAAAbc"]
[Thu Sep 17 15:37:11.095548 2026] [security2:error] [pid 20162:tid 20376] [client 167.172.76.13:41324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdh6-O_Kk7aqBvaiGEMwAB4j8"], referer: https://www.trcco.org/wp/
[Thu Sep 17 15:37:11.516519 2026] [security2:error] [pid 20162:tid 20329] [client 167.172.76.13:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.trcco.org"] [uri "/index.php"] [unique_id "aqxdh6-O_Kk7aqBvaiGEOgABs0A"], referer: http://www.trcco.org/new/
[Thu Sep 17 15:37:11.570540 2026] [security2:error] [pid 20162:tid 20235] [remote 35.234.44.14:51138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/appearance/../../proc/self/environ"] [unique_id "aqxdh6-O_Kk7aqBvaiGEPQABuUc"]
[Thu Sep 17 15:37:11.570819 2026] [security2:error] [pid 20162:tid 20232] [remote 35.234.44.14:51138] ModSecurity: Warning. Pattern match "%2e.%2e%2e" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1524"] [id "900917"] [msg "temporary CVE-2021-41773 logging rule"] [hostname "cpanel.amecoegypt.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aqxdh6-O_Kk7aqBvaiGEPAABuUQ"]
[Thu Sep 17 15:37:11.570871 2026] [core:error] [pid 20162:tid 20232] [remote 35.234.44.14:51138] AH10244: invalid URI path (/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env)
[Thu Sep 17 15:37:11.570885 2026] [security2:error] [pid 20162:tid 20225] [remote 35.234.44.14:51138] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ"] [unique_id "aqxdh6-O_Kk7aqBvaiGEOwABuT0"]
[Thu Sep 17 15:37:11.571065 2026] [security2:error] [pid 20162:tid 20242] [remote 35.234.44.14:51138] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env"] [unique_id "aqxdh6-O_Kk7aqBvaiGEPgABuU4"]
[Thu Sep 17 15:37:11.616448 2026] [core:error] [pid 20162:tid 20403] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:11.616470 2026] [core:error] [pid 20162:tid 20403] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:11.723565 2026] [security2:error] [pid 18946:tid 19078] [client 43.245.158.111:33435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxdhzqiPMah0Tz_U1OxdAABDFk"], referer: https://ourstraytribe.com
[Thu Sep 17 15:37:11.744174 2026] [security2:error] [pid 20162:tid 20299] [client 167.172.76.13:41324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdh6-O_Kk7aqBvaiGEQgABlUU"], referer: https://www.trcco.org/new/
[Thu Sep 17 15:37:11.797128 2026] [security2:error] [pid 18946:tid 19084] [client 129.159.56.14:34782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-3b205263.gas.frg.mybluehost.me"] [uri "/.env"] [unique_id "aqxdhzqiPMah0Tz_U1OxgAAAARI"]
[Thu Sep 17 15:37:12.112739 2026] [core:error] [pid 18946:tid 19051] [remote 35.234.44.14:51150] AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../proc/self/cmdline)
[Thu Sep 17 15:37:12.158610 2026] [security2:error] [pid 18946:tid 19067] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/var/run/secrets/kubernetes.io/serviceaccount/token"] [unique_id "aqxdiDqiPMah0Tz_U1OxigABdHg"]
[Thu Sep 17 15:37:12.158768 2026] [security2:error] [pid 18946:tid 19182] [client 35.234.44.14:51150] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/var/run/secrets/kubernetes.io/serviceaccount/token"] [unique_id "aqxdiDqiPMah0Tz_U1OxigABdHg"]
[Thu Sep 17 15:37:12.164095 2026] [security2:error] [pid 18946:tid 19030] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/proc/self/cmdline"] [unique_id "aqxdiDqiPMah0Tz_U1OxjQABdFM"]
[Thu Sep 17 15:37:12.164248 2026] [security2:error] [pid 18946:tid 19182] [client 35.234.44.14:51150] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/proc/self/cmdline"] [unique_id "aqxdiDqiPMah0Tz_U1OxjQABdFM"]
[Thu Sep 17 15:37:12.164847 2026] [security2:error] [pid 18946:tid 19032] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdiDqiPMah0Tz_U1OxjAABdFU"]
[Thu Sep 17 15:37:12.167476 2026] [security2:error] [pid 20162:tid 20327] [client 167.172.76.13:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.trcco.org"] [uri "/index.php"] [unique_id "aqxdiK-O_Kk7aqBvaiGERgABsUo"], referer: http://www.trcco.org/wordpress/
[Thu Sep 17 15:37:12.180088 2026] [core:error] [pid 18946:tid 19130] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.180103 2026] [core:error] [pid 18946:tid 19130] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.198076 2026] [core:error] [pid 20162:tid 20295] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.198093 2026] [core:error] [pid 20162:tid 20295] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.203900 2026] [core:error] [pid 18946:tid 19159] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.203918 2026] [core:error] [pid 18946:tid 19159] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.237412 2026] [security2:error] [pid 18946:tid 19091] [client 103.61.184.148:62543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdiDqiPMah0Tz_U1OxkgAAARk"]
[Thu Sep 17 15:37:12.237496 2026] [security2:error] [pid 18946:tid 19091] [client 103.61.184.148:62543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdiDqiPMah0Tz_U1OxkgAAARk"]
[Thu Sep 17 15:37:12.338587 2026] [security2:error] [pid 18946:tid 19011] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdiDqiPMah0Tz_U1OxlgABG0A"]
[Thu Sep 17 15:37:12.338617 2026] [security2:error] [pid 18946:tid 18957] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdiDqiPMah0Tz_U1OxlQABGwo"]
[Thu Sep 17 15:37:12.393188 2026] [security2:error] [pid 20162:tid 20308] [client 167.172.76.13:41324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdiK-O_Kk7aqBvaiGETgABnk8"], referer: https://www.trcco.org/wordpress/
[Thu Sep 17 15:37:12.407352 2026] [core:error] [pid 18946:tid 19122] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.407371 2026] [core:error] [pid 18946:tid 19122] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.407422 2026] [core:error] [pid 18946:tid 19138] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.407434 2026] [core:error] [pid 18946:tid 19138] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.466647 2026] [core:error] [pid 18946:tid 19152] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.466673 2026] [core:error] [pid 18946:tid 19152] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.506310 2026] [core:error] [pid 18946:tid 19181] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.506331 2026] [core:error] [pid 18946:tid 19181] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.646474 2026] [core:error] [pid 20162:tid 20336] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.646493 2026] [core:error] [pid 20162:tid 20336] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.693112 2026] [core:error] [pid 18946:tid 19087] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.693141 2026] [core:error] [pid 18946:tid 19087] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.747889 2026] [core:error] [pid 18946:tid 19116] [client 45.156.128.168:16406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.747905 2026] [core:error] [pid 18946:tid 19116] [client 45.156.128.168:16406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.770255 2026] [security2:error] [pid 18946:tid 19035] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/@fs/src/.env"] [unique_id "aqxdiDqiPMah0Tz_U1OxsAABRlg"]
[Thu Sep 17 15:37:12.814036 2026] [security2:error] [pid 18946:tid 19065] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/@fs/app/.env"] [unique_id "aqxdiDqiPMah0Tz_U1OxswABRnY"]
[Thu Sep 17 15:37:12.901695 2026] [core:error] [pid 20162:tid 20404] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.901716 2026] [core:error] [pid 20162:tid 20404] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.921215 2026] [core:error] [pid 18946:tid 19113] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:12.921235 2026] [core:error] [pid 18946:tid 19113] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.131348 2026] [security2:error] [pid 18946:tid 19168] [client 143.105.152.240:18762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdiTqiPMah0Tz_U1OxvAAAAWY"]
[Thu Sep 17 15:37:13.135893 2026] [security2:error] [pid 18946:tid 19041] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/dist../.env"] [unique_id "aqxdiTqiPMah0Tz_U1OxvQABS14"]
[Thu Sep 17 15:37:13.148749 2026] [security2:error] [pid 18946:tid 19168] [client 143.105.152.240:18762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdiTqiPMah0Tz_U1OxvAAAAWY"]
[Thu Sep 17 15:37:13.158745 2026] [security2:error] [pid 18946:tid 19071] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/build../.env"] [unique_id "aqxdiTqiPMah0Tz_U1OxvwABiHw"]
[Thu Sep 17 15:37:13.330222 2026] [security2:error] [pid 20162:tid 20365] [client 79.116.89.151:61156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdia-O_Kk7aqBvaiGEVgAAAdc"]
[Thu Sep 17 15:37:13.330855 2026] [security2:error] [pid 20162:tid 20365] [client 79.116.89.151:61156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdia-O_Kk7aqBvaiGEVgAAAdc"]
[Thu Sep 17 15:37:13.340160 2026] [security2:error] [pid 18946:tid 19025] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/css../.env"] [unique_id "aqxdiTqiPMah0Tz_U1OxxAABZU4"]
[Thu Sep 17 15:37:13.459563 2026] [core:error] [pid 18946:tid 18955] [remote 35.234.44.14:51150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.459590 2026] [core:error] [pid 18946:tid 18955] [remote 35.234.44.14:51150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.464843 2026] [security2:error] [pid 20162:tid 20294] [client 167.172.76.13:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.trcco.org"] [uri "/index.php"] [unique_id "aqxdia-O_Kk7aqBvaiGEWgABkEg"], referer: http://www.trcco.org/blog/
[Thu Sep 17 15:37:13.474001 2026] [security2:error] [pid 18946:tid 18963] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdiTqiPMah0Tz_U1OxyQABgRA"]
[Thu Sep 17 15:37:13.480062 2026] [security2:error] [pid 18946:tid 18970] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdiTqiPMah0Tz_U1OxygABcRc"]
[Thu Sep 17 15:37:13.483901 2026] [security2:error] [pid 18946:tid 18954] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/public../.env"] [unique_id "aqxdiTqiPMah0Tz_U1OxywABcAc"]
[Thu Sep 17 15:37:13.495782 2026] [security2:error] [pid 18946:tid 18959] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/js../.env"] [unique_id "aqxdiTqiPMah0Tz_U1OxzAABHQw"]
[Thu Sep 17 15:37:13.625696 2026] [security2:error] [pid 18946:tid 18962] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/userfiles"] [unique_id "aqxdiTqiPMah0Tz_U1OxzgABQg8"]
[Thu Sep 17 15:37:13.634436 2026] [security2:error] [pid 18946:tid 18948] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/userfiles"] [unique_id "aqxdiTqiPMah0Tz_U1Ox0gABQgE"]
[Thu Sep 17 15:37:13.653201 2026] [security2:error] [pid 18946:tid 19074] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/userfiles"] [unique_id "aqxdiTqiPMah0Tz_U1Ox1wABQn8"]
[Thu Sep 17 15:37:13.674752 2026] [core:error] [pid 18946:tid 19187] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.674773 2026] [core:error] [pid 18946:tid 19187] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.678731 2026] [core:error] [pid 18946:tid 19121] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.678748 2026] [core:error] [pid 18946:tid 19121] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.689314 2026] [security2:error] [pid 20162:tid 20386] [client 167.172.76.13:41324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdia-O_Kk7aqBvaiGEWwAB7FQ"], referer: https://www.trcco.org/blog/
[Thu Sep 17 15:37:13.698346 2026] [security2:error] [pid 18946:tid 19142] [client 204.14.250.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxdiTqiPMah0Tz_U1OxxgAAAUw"], referer: https://facebook.com/
[Thu Sep 17 15:37:13.706350 2026] [core:error] [pid 18946:tid 19117] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:13.706369 2026] [core:error] [pid 18946:tid 19117] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:14.005163 2026] [security2:error] [pid 18946:tid 18974] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.amecoegypt.com"] [uri "/wp-config.php.bak"] [unique_id "aqxdijqiPMah0Tz_U1Ox5gABUBs"]
[Thu Sep 17 15:37:14.005206 2026] [security2:error] [pid 18946:tid 18969] [remote 35.234.44.14:51150] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/userfiles"] [unique_id "aqxdijqiPMah0Tz_U1Ox4gABUBY"]
[Thu Sep 17 15:37:14.005284 2026] [security2:error] [pid 18946:tid 18971] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 500 (phase 1) (Error: Connection drop requested but failed to close the  socket). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.amecoegypt.com"] [uri "/userfiles/x"] [unique_id "aqxdijqiPMah0Tz_U1Ox5QABUBg"]
[Thu Sep 17 15:37:14.006416 2026] [security2:error] [pid 18946:tid 18973] [remote 35.234.44.14:51150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/userfiles/x"] [unique_id "aqxdijqiPMah0Tz_U1Ox5AABUBo"]
[Thu Sep 17 15:37:14.009192 2026] [core:error] [pid 18946:tid 18967] [remote 35.234.44.14:51150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:14.009207 2026] [core:error] [pid 18946:tid 18967] [remote 35.234.44.14:51150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:14.124974 2026] [security2:error] [pid 20162:tid 20378] [client 167.172.76.13:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.trcco.org"] [uri "/index.php"] [unique_id "aqxdiq-O_Kk7aqBvaiGEXgAB5FE"], referer: http://www.trcco.org/old/
[Thu Sep 17 15:37:14.261076 2026] [security2:error] [pid 18946:tid 19130] [client 136.158.61.34:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdijqiPMah0Tz_U1Ox6wAAAUA"]
[Thu Sep 17 15:37:14.261201 2026] [security2:error] [pid 18946:tid 19130] [client 136.158.61.34:14295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdijqiPMah0Tz_U1Ox6wAAAUA"]
[Thu Sep 17 15:37:14.358302 2026] [security2:error] [pid 20162:tid 20330] [client 167.172.76.13:41324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdiq-O_Kk7aqBvaiGEZQABtFU"], referer: https://www.trcco.org/old/
[Thu Sep 17 15:37:14.783199 2026] [security2:error] [pid 20162:tid 20346] [client 167.172.76.13:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.trcco.org"] [uri "/index.php"] [unique_id "aqxdiq-O_Kk7aqBvaiGEZwABxF8"], referer: http://www.trcco.org/backup/
[Thu Sep 17 15:37:14.997212 2026] [security2:error] [pid 18946:tid 18985] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.amecoegypt.com"] [uri "/wp-config.php.old"] [unique_id "aqxdijqiPMah0Tz_U1Ox-wABPiY"]
[Thu Sep 17 15:37:14.997350 2026] [security2:error] [pid 18946:tid 19128] [client 35.234.44.14:34792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.amecoegypt.com"] [uri "/wp-config.php.old"] [unique_id "aqxdijqiPMah0Tz_U1Ox-wABPiY"]
[Thu Sep 17 15:37:15.008258 2026] [security2:error] [pid 18946:tid 18983] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.44.234.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.amecoegypt.com"] [uri "/configuration.php.bak"] [unique_id "aqxdijqiPMah0Tz_U1Ox_AABPiQ"]
[Thu Sep 17 15:37:15.010942 2026] [security2:error] [pid 20162:tid 20371] [client 167.172.76.13:41324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdiq-O_Kk7aqBvaiGEaAAB3VM"], referer: https://www.trcco.org/backup/
[Thu Sep 17 15:37:15.034619 2026] [security2:error] [pid 18946:tid 18984] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.44.234.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.amecoegypt.com"] [uri "/config.php.bak"] [unique_id "aqxdizqiPMah0Tz_U1OyAAABYSU"]
[Thu Sep 17 15:37:15.034637 2026] [security2:error] [pid 18946:tid 18952] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.44.234.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.amecoegypt.com"] [uri "/.env.php.bak"] [unique_id "aqxdizqiPMah0Tz_U1Ox_wABYQU"]
[Thu Sep 17 15:37:15.034657 2026] [security2:error] [pid 18946:tid 18996] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.44.234.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.amecoegypt.com"] [uri "/config/.env.php"] [unique_id "aqxdizqiPMah0Tz_U1Ox_QABYTE"]
[Thu Sep 17 15:37:15.145002 2026] [core:error] [pid 20162:tid 20370] [client 45.156.128.169:32918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.145023 2026] [core:error] [pid 20162:tid 20370] [client 45.156.128.169:32918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.197368 2026] [security2:error] [pid 18946:tid 18982] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "aqxdizqiPMah0Tz_U1OyBAABPCM"]
[Thu Sep 17 15:37:15.220034 2026] [security2:error] [pid 18946:tid 18964] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "aqxdizqiPMah0Tz_U1OyBQABPBE"]
[Thu Sep 17 15:37:15.225102 2026] [security2:error] [pid 18946:tid 18953] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/.aws/credentials"] [unique_id "aqxdizqiPMah0Tz_U1OyBwABPAY"]
[Thu Sep 17 15:37:15.225815 2026] [security2:error] [pid 18946:tid 19037] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "aqxdizqiPMah0Tz_U1OyBgABPFo"]
[Thu Sep 17 15:37:15.233005 2026] [security2:error] [pid 18946:tid 18968] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.amecoegypt.com"] [uri "/wp-config.php~"] [unique_id "aqxdizqiPMah0Tz_U1OyCQABPBU"]
[Thu Sep 17 15:37:15.264831 2026] [core:error] [pid 18946:tid 19148] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.264847 2026] [core:error] [pid 18946:tid 19148] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.516932 2026] [security2:error] [pid 18946:tid 19173] [client 74.7.228.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxdizqiPMah0Tz_U1OyEgAAAWs"]
[Thu Sep 17 15:37:15.520650 2026] [security2:error] [pid 18946:tid 19082] [client 74.7.228.7:41378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "aqxdizqiPMah0Tz_U1OyEAAAARA"]
[Thu Sep 17 15:37:15.591358 2026] [security2:error] [pid 20162:tid 20380] [client 74.7.228.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdi6-O_Kk7aqBvaiGEawAAAeY"], referer: https://cpanel.ycs.drf.mybluehost.me/robots.txt
[Thu Sep 17 15:37:15.593679 2026] [security2:error] [pid 18946:tid 19099] [client 74.7.228.7:41378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdizqiPMah0Tz_U1OyEwAAASE"], referer: https://cpanel.ycs.drf.mybluehost.me/robots.txt
[Thu Sep 17 15:37:15.667611 2026] [security2:error] [pid 20162:tid 20374] [client 74.7.228.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdi6-O_Kk7aqBvaiGEbAAAAeA"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:15.671531 2026] [security2:error] [pid 18946:tid 19191] [client 74.7.228.7:41378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdizqiPMah0Tz_U1OyFgAAAX0"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:15.766719 2026] [security2:error] [pid 20162:tid 20351] [client 74.7.228.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdi6-O_Kk7aqBvaiGEbQAAAck"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:15.773025 2026] [security2:error] [pid 18946:tid 19141] [client 74.7.228.7:41378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdizqiPMah0Tz_U1OyGAAAAUs"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:15.820218 2026] [security2:error] [pid 18946:tid 19014] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "aqxdizqiPMah0Tz_U1OyIQABSUM"]
[Thu Sep 17 15:37:15.839570 2026] [security2:error] [pid 18946:tid 19151] [client 74.7.228.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdizqiPMah0Tz_U1OyKgAAAVU"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:15.840411 2026] [core:error] [pid 18946:tid 19176] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.840426 2026] [core:error] [pid 18946:tid 19176] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.841154 2026] [core:error] [pid 18946:tid 19129] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.841168 2026] [core:error] [pid 18946:tid 19129] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.841801 2026] [security2:error] [pid 18946:tid 19106] [client 74.7.228.7:41378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdizqiPMah0Tz_U1OyHQAAASg"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:15.844087 2026] [core:error] [pid 18946:tid 19195] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.844100 2026] [core:error] [pid 18946:tid 19195] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.845630 2026] [core:error] [pid 20162:tid 20312] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.845644 2026] [core:error] [pid 20162:tid 20312] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.849874 2026] [core:error] [pid 18946:tid 19164] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.849887 2026] [core:error] [pid 18946:tid 19164] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:15.907788 2026] [security2:error] [pid 18946:tid 19127] [client 74.7.228.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdizqiPMah0Tz_U1OyMQAAAT0"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:15.909318 2026] [security2:error] [pid 18946:tid 19193] [client 74.7.228.7:41378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpanel.ycs.drf.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdizqiPMah0Tz_U1OyLwAAAX8"], referer: https://cpanel.ycs.drf.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:37:16.023732 2026] [security2:error] [pid 18946:tid 18951] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.amecoegypt.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxdjDqiPMah0Tz_U1OyNwABagQ"]
[Thu Sep 17 15:37:16.038544 2026] [core:error] [pid 18946:tid 19135] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.038565 2026] [core:error] [pid 18946:tid 19135] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.045518 2026] [core:error] [pid 18946:tid 19143] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.045534 2026] [core:error] [pid 18946:tid 19143] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.045814 2026] [core:error] [pid 18946:tid 19110] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.045829 2026] [core:error] [pid 18946:tid 19110] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.046764 2026] [core:error] [pid 18946:tid 19150] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.046775 2026] [core:error] [pid 18946:tid 19150] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.050720 2026] [core:error] [pid 18946:tid 19003] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.050734 2026] [core:error] [pid 18946:tid 19003] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.052003 2026] [core:error] [pid 18946:tid 19097] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.052015 2026] [core:error] [pid 18946:tid 19097] [client 35.234.44.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.137449 2026] [security2:error] [pid 18946:tid 18977] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/__/firebase/init.json"] [unique_id "aqxdjDqiPMah0Tz_U1OyRQABMR4"]
[Thu Sep 17 15:37:16.181272 2026] [core:error] [pid 18946:tid 18965] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.181295 2026] [core:error] [pid 18946:tid 18965] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.356422 2026] [core:error] [pid 18946:tid 19022] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.356441 2026] [core:error] [pid 18946:tid 19022] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.512713 2026] [core:error] [pid 18946:tid 19013] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.512733 2026] [core:error] [pid 18946:tid 19013] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.598548 2026] [security2:error] [pid 18946:tid 19138] [client 169.58.197.251:62692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxdjDqiPMah0Tz_U1OyTQAAAUg"], referer: binance.com
[Thu Sep 17 15:37:16.740046 2026] [core:error] [pid 18946:tid 19180] [client 45.156.128.169:32920] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:16.740074 2026] [core:error] [pid 18946:tid 19180] [client 45.156.128.169:32920] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.161759 2026] [core:error] [pid 18946:tid 18992] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.161778 2026] [core:error] [pid 18946:tid 18992] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.336456 2026] [core:error] [pid 18946:tid 18975] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.336477 2026] [core:error] [pid 18946:tid 18975] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.535807 2026] [core:error] [pid 18946:tid 19063] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.535831 2026] [core:error] [pid 18946:tid 19063] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.705363 2026] [core:error] [pid 18946:tid 19054] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.705389 2026] [core:error] [pid 18946:tid 19054] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.856490 2026] [security2:error] [pid 18946:tid 19176] [client 14.96.156.146:51825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdjTqiPMah0Tz_U1OyagAAAW4"]
[Thu Sep 17 15:37:17.856648 2026] [security2:error] [pid 18946:tid 19176] [client 14.96.156.146:51825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdjTqiPMah0Tz_U1OyagAAAW4"]
[Thu Sep 17 15:37:17.865567 2026] [core:error] [pid 18946:tid 19061] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:17.865582 2026] [core:error] [pid 18946:tid 19061] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:18.136485 2026] [security2:error] [pid 18946:tid 19134] [client 114.198.138.124:51394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdjjqiPMah0Tz_U1OycAAAAUQ"]
[Thu Sep 17 15:37:18.136636 2026] [security2:error] [pid 18946:tid 19134] [client 114.198.138.124:51394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdjjqiPMah0Tz_U1OycAAAAUQ"]
[Thu Sep 17 15:37:18.398787 2026] [core:error] [pid 18946:tid 19053] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:18.398809 2026] [core:error] [pid 18946:tid 19053] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:18.560250 2026] [core:error] [pid 18946:tid 19001] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:18.560273 2026] [core:error] [pid 18946:tid 19001] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.368221 2026] [security2:error] [pid 18946:tid 19031] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.amecoegypt.com"] [uri "/lib/terminal-xhr.php"] [unique_id "aqxdjzqiPMah0Tz_U1OyhQABUFQ"]
[Thu Sep 17 15:37:19.474954 2026] [core:error] [pid 18946:tid 19083] [client 45.156.128.170:54266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.474984 2026] [core:error] [pid 18946:tid 19083] [client 45.156.128.170:54266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.511402 2026] [security2:error] [pid 18946:tid 19058] [remote 35.234.44.14:34792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.44.234.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.amecoegypt.com"] [uri "/icecoder/lib/terminal-xhr.php"] [unique_id "aqxdjzqiPMah0Tz_U1OyiAABH28"]
[Thu Sep 17 15:37:19.685772 2026] [core:error] [pid 18946:tid 19050] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.685793 2026] [core:error] [pid 18946:tid 19050] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.750172 2026] [core:error] [pid 18946:tid 19194] [client 31.56.58.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.750202 2026] [core:error] [pid 18946:tid 19194] [client 31.56.58.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.905564 2026] [core:error] [pid 18946:tid 19034] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:19.905587 2026] [core:error] [pid 18946:tid 19034] [remote 35.234.44.14:34792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:20.186145 2026] [security2:error] [pid 18946:tid 19160] [client 177.44.133.72:56233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdkDqiPMah0Tz_U1OymwAAAV4"]
[Thu Sep 17 15:37:20.186269 2026] [security2:error] [pid 18946:tid 19160] [client 177.44.133.72:56233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdkDqiPMah0Tz_U1OymwAAAV4"]
[Thu Sep 17 15:37:20.264960 2026] [security2:error] [pid 18946:tid 19043] [remote 45.157.54.43:30642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-cc9d9bdc.kiyetec1.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkDqiPMah0Tz_U1OyoAABR2A"]
[Thu Sep 17 15:37:20.265104 2026] [security2:error] [pid 18946:tid 19137] [client 45.157.54.43:30642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-cc9d9bdc.kiyetec1.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkDqiPMah0Tz_U1OyoAABR2A"]
[Thu Sep 17 15:37:20.865036 2026] [security2:error] [pid 18946:tid 19141] [client 57.141.14.80:51200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxdkDqiPMah0Tz_U1OyrgABSwk"]
[Thu Sep 17 15:37:21.335923 2026] [security2:error] [pid 20162:tid 20341] [client 37.139.53.11:58043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pger.net"] [uri "/football/index.php"] [unique_id "aqxdkK-O_Kk7aqBvaiGEewAAAb8"], referer: http://pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:37:21.361550 2026] [core:error] [pid 18946:tid 19134] [client 45.156.128.170:54270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:21.361571 2026] [core:error] [pid 18946:tid 19134] [client 45.156.128.170:54270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:21.527118 2026] [security2:error] [pid 18946:tid 19012] [remote 45.157.54.43:30601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-cc9d9bdc.kiyetec1.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkTqiPMah0Tz_U1OyxAABZkE"]
[Thu Sep 17 15:37:21.527266 2026] [security2:error] [pid 18946:tid 19168] [client 45.157.54.43:30601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-cc9d9bdc.kiyetec1.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkTqiPMah0Tz_U1OyxAABZkE"]
[Thu Sep 17 15:37:21.842444 2026] [authz_core:error] [pid 18946:tid 19175] [client 40.81.232.68:58232] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:37:23.021141 2026] [security2:error] [pid 18946:tid 19166] [client 103.61.184.148:63118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkzqiPMah0Tz_U1Oy4AAAAWQ"]
[Thu Sep 17 15:37:23.023826 2026] [security2:error] [pid 18946:tid 19166] [client 103.61.184.148:63118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkzqiPMah0Tz_U1Oy4AAAAWQ"]
[Thu Sep 17 15:37:23.643802 2026] [security2:error] [pid 20162:tid 20336] [client 143.105.152.240:10275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdk6-O_Kk7aqBvaiGEjAAAAbo"]
[Thu Sep 17 15:37:23.645878 2026] [security2:error] [pid 20162:tid 20336] [client 143.105.152.240:10275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdk6-O_Kk7aqBvaiGEjAAAAbo"]
[Thu Sep 17 15:37:23.783794 2026] [core:error] [pid 20162:tid 20365] [client 45.156.128.170:54274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:23.783814 2026] [core:error] [pid 20162:tid 20365] [client 45.156.128.170:54274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:23.930222 2026] [security2:error] [pid 18946:tid 19195] [client 79.116.89.151:61775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkzqiPMah0Tz_U1Oy7QAAAYE"]
[Thu Sep 17 15:37:23.930343 2026] [security2:error] [pid 18946:tid 19195] [client 79.116.89.151:61775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdkzqiPMah0Tz_U1Oy7QAAAYE"]
[Thu Sep 17 15:37:24.342257 2026] [security2:error] [pid 18946:tid 19101] [client 138.117.47.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdlDqiPMah0Tz_U1Oy8wAAASM"], referer: https://trcco.org
[Thu Sep 17 15:37:24.841431 2026] [security2:error] [pid 18946:tid 19159] [client 37.139.53.11:52431] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.11" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.pger.net"] [uri "/football/wp-comments-post.php"] [unique_id "aqxdlDqiPMah0Tz_U1Oy-wAAAV0"], referer: http://www.pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:37:24.841523 2026] [security2:error] [pid 18946:tid 19159] [client 37.139.53.11:52431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.pger.net"] [uri "/football/wp-comments-post.php"] [unique_id "aqxdlDqiPMah0Tz_U1Oy-wAAAV0"], referer: http://www.pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:37:25.351734 2026] [security2:error] [pid 18946:tid 19193] [client 170.199.230.56:33763] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900923"] [msg "contact form logging"] [hostname "www.pger.net"] [uri "/football/wp-comments-post.php"] [unique_id "aqxdlTqiPMah0Tz_U1Oy_gAAAX8"], referer: http://www.pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:37:25.488972 2026] [security2:error] [pid 18946:tid 19193] [client 170.199.230.56:33763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.pger.net"] [uri "/football/wp-comments-post.php"] [unique_id "aqxdlTqiPMah0Tz_U1Oy_gAAAX8"], referer: http://www.pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:37:25.489032 2026] [security2:error] [pid 18946:tid 19193] [client 170.199.230.56:33763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.pger.net"] [uri "/football/wp-comments-post.php"] [unique_id "aqxdlTqiPMah0Tz_U1Oy_gAAAX8"], referer: http://www.pger.net/football/2018/07/10/the-angst-of-the-coaching/
[Thu Sep 17 15:37:26.254945 2026] [security2:error] [pid 20162:tid 20353] [client 177.92.48.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxdlK-O_Kk7aqBvaiGEmQAAAcs"], referer: https://coronadoiscalling.com
[Thu Sep 17 15:37:26.749049 2026] [core:error] [pid 20162:tid 20333] [client 45.156.128.169:45004] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:26.749071 2026] [core:error] [pid 20162:tid 20333] [client 45.156.128.169:45004] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:26.869161 2026] [security2:error] [pid 20162:tid 20324] [client 136.158.61.34:15404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdlq-O_Kk7aqBvaiGEowAAAa4"]
[Thu Sep 17 15:37:26.869288 2026] [security2:error] [pid 20162:tid 20324] [client 136.158.61.34:15404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdlq-O_Kk7aqBvaiGEowAAAa4"]
[Thu Sep 17 15:37:27.380588 2026] [core:error] [pid 20162:tid 20384] [client 45.156.128.171:60008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:27.380621 2026] [core:error] [pid 20162:tid 20384] [client 45.156.128.171:60008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:27.534309 2026] [security2:error] [pid 20162:tid 20391] [client 190.14.138.151:23201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdl6-O_Kk7aqBvaiGEqAAB8Wo"]
[Thu Sep 17 15:37:28.435446 2026] [security2:error] [pid 18946:tid 19137] [client 14.96.156.146:52455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdmDqiPMah0Tz_U1OzOQAAAUc"]
[Thu Sep 17 15:37:28.435555 2026] [security2:error] [pid 18946:tid 19137] [client 14.96.156.146:52455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdmDqiPMah0Tz_U1OzOQAAAUc"]
[Thu Sep 17 15:37:28.444599 2026] [security2:error] [pid 20162:tid 20406] [client 116.179.37.56:43277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.norifon.com"] [uri "/index.php"] [unique_id "aqxdmK-O_Kk7aqBvaiGErQAAAgA"], referer: https://www.norifon.com/lcd-usb-charger-for-olympus-blm-1-camera-battery?tag=LCD%20USB%20Charger&page=6
[Thu Sep 17 15:37:28.929156 2026] [security2:error] [pid 18946:tid 19201] [client 40.77.167.25:36350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "findproductivity.com"] [uri "/index.php"] [unique_id "aqxdmDqiPMah0Tz_U1OzPwAAAYc"]
[Thu Sep 17 15:37:28.943806 2026] [security2:error] [pid 20162:tid 20337] [client 114.198.138.124:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdmK-O_Kk7aqBvaiGEsAAAAbs"]
[Thu Sep 17 15:37:28.943911 2026] [security2:error] [pid 20162:tid 20337] [client 114.198.138.124:52054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdmK-O_Kk7aqBvaiGEsAAAAbs"]
[Thu Sep 17 15:37:29.101027 2026] [core:error] [pid 18946:tid 19175] [client 45.156.128.168:13744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:29.101046 2026] [core:error] [pid 18946:tid 19175] [client 45.156.128.168:13744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:29.300420 2026] [security2:error] [pid 18946:tid 19165] [client 49.36.239.152:33265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdmTqiPMah0Tz_U1OzSAABY3o"]
[Thu Sep 17 15:37:29.789730 2026] [security2:error] [pid 18946:tid 19088] [client 185.93.228.10:13878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bluetech.com"] [uri "/wp-content/uploads/2019/03/SEWP_V_Ordering_Guide_-_Blue_Tech.pdf"] [unique_id "aqxdmTqiPMah0Tz_U1OzUgAAARY"]
[Thu Sep 17 15:37:30.158274 2026] [security2:error] [pid 20162:tid 20354] [client 187.191.7.84:7781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdmq-O_Kk7aqBvaiGEtQABzFs"]
[Thu Sep 17 15:37:30.819721 2026] [security2:error] [pid 18946:tid 19155] [client 177.44.133.72:56889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdmjqiPMah0Tz_U1OzZQAAAVk"]
[Thu Sep 17 15:37:30.819838 2026] [security2:error] [pid 18946:tid 19155] [client 177.44.133.72:56889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdmjqiPMah0Tz_U1OzZQAAAVk"]
[Thu Sep 17 15:37:31.164156 2026] [security2:error] [pid 18946:tid 19081] [client 186.29.17.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdmzqiPMah0Tz_U1OzbAAAAQ8"], referer: https://trcco.org
[Thu Sep 17 15:37:31.645688 2026] [security2:error] [pid 18946:tid 19199] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxdmzqiPMah0Tz_U1OzdwAAAYU"]
[Thu Sep 17 15:37:31.645819 2026] [security2:error] [pid 18946:tid 19199] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aqxdmzqiPMah0Tz_U1OzdwAAAYU"]
[Thu Sep 17 15:37:31.701837 2026] [core:error] [pid 20162:tid 20369] [client 45.156.128.169:12710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:31.701859 2026] [core:error] [pid 20162:tid 20369] [client 45.156.128.169:12710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:37:31.787612 2026] [security2:error] [pid 18946:tid 19106] [client 177.227.112.122:9898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdmzqiPMah0Tz_U1OzeAABKAw"]
[Thu Sep 17 15:37:32.207290 2026] [security2:error] [pid 18946:tid 19080] [client 162.241.226.11:48260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxdmjqiPMah0Tz_U1OzYwAAAQ4"]
[Thu Sep 17 15:37:32.226862 2026] [security2:error] [pid 18946:tid 19177] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxdnDqiPMah0Tz_U1OzgQAAAW8"]
[Thu Sep 17 15:37:32.226945 2026] [security2:error] [pid 18946:tid 19177] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aqxdnDqiPMah0Tz_U1OzgQAAAW8"]
[Thu Sep 17 15:37:32.779722 2026] [authz_core:error] [pid 18946:tid 19117] [client 40.81.232.68:59454] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:37:32.828264 2026] [security2:error] [pid 18946:tid 19203] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger0.php"] [unique_id "aqxdnDqiPMah0Tz_U1OzkAAAAYk"]
[Thu Sep 17 15:37:32.828366 2026] [security2:error] [pid 18946:tid 19203] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger0.php"] [unique_id "aqxdnDqiPMah0Tz_U1OzkAAAAYk"]
[Thu Sep 17 15:37:33.236693 2026] [security2:error] [pid 18946:tid 19112] [client 80.9.27.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxdnTqiPMah0Tz_U1OzmgAAAS4"], referer: https://coronadoiscalling.com
[Thu Sep 17 15:37:33.379332 2026] [security2:error] [pid 18946:tid 19097] [client 162.241.226.11:41032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxdnDqiPMah0Tz_U1OzggAAAR8"]
[Thu Sep 17 15:37:33.432684 2026] [security2:error] [pid 18946:tid 19144] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/01.php"] [unique_id "aqxdnTqiPMah0Tz_U1OzowAAAU4"]
[Thu Sep 17 15:37:33.432796 2026] [security2:error] [pid 18946:tid 19144] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/01.php"] [unique_id "aqxdnTqiPMah0Tz_U1OzowAAAU4"]
[Thu Sep 17 15:37:34.024191 2026] [security2:error] [pid 18946:tid 18949] [remote 47.128.36.242:43032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kslandscaping.net"] [uri "/category/news/"] [unique_id "aqxdnjqiPMah0Tz_U1OzrQABeQI"]
[Thu Sep 17 15:37:34.024950 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-xmlgal.php"] [unique_id "aqxdnjqiPMah0Tz_U1OzrgAAAUU"]
[Thu Sep 17 15:37:34.025019 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-xmlgal.php"] [unique_id "aqxdnjqiPMah0Tz_U1OzrgAAAUU"]
[Thu Sep 17 15:37:34.270405 2026] [security2:error] [pid 18946:tid 19126] [client 143.105.152.240:43549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdnjqiPMah0Tz_U1OztgAAATw"]
[Thu Sep 17 15:37:34.270512 2026] [security2:error] [pid 18946:tid 19126] [client 143.105.152.240:43549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdnjqiPMah0Tz_U1OztgAAATw"]
[Thu Sep 17 15:37:34.302878 2026] [security2:error] [pid 18946:tid 19196] [client 66.249.66.204:63412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ourstraytribe.com"] [uri "/index.php"] [unique_id "aqxdnjqiPMah0Tz_U1OzswAAAYI"]
[Thu Sep 17 15:37:34.344810 2026] [security2:error] [pid 20162:tid 20326] [client 103.61.184.148:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdnq-O_Kk7aqBvaiGExAAAAbA"]
[Thu Sep 17 15:37:34.344922 2026] [security2:error] [pid 20162:tid 20326] [client 103.61.184.148:63691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdnq-O_Kk7aqBvaiGExAAAAbA"]
[Thu Sep 17 15:37:34.585349 2026] [security2:error] [pid 20162:tid 20301] [client 79.116.89.151:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdnq-O_Kk7aqBvaiGExgAAAZc"]
[Thu Sep 17 15:37:34.585521 2026] [security2:error] [pid 20162:tid 20301] [client 79.116.89.151:62406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdnq-O_Kk7aqBvaiGExgAAAZc"]
[Thu Sep 17 15:37:34.612234 2026] [security2:error] [pid 20162:tid 20367] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/yich.php"] [unique_id "aqxdnq-O_Kk7aqBvaiGExwAAAdk"]
[Thu Sep 17 15:37:34.612311 2026] [security2:error] [pid 20162:tid 20367] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/yich.php"] [unique_id "aqxdnq-O_Kk7aqBvaiGExwAAAdk"]
[Thu Sep 17 15:37:35.145407 2026] [security2:error] [pid 18946:tid 19156] [client 143.244.57.120:54212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxdnzqiPMah0Tz_U1Oz0QAAAVo"]
[Thu Sep 17 15:37:35.224624 2026] [security2:error] [pid 18946:tid 19171] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-blink.php"] [unique_id "aqxdnzqiPMah0Tz_U1Oz0wAAAWk"]
[Thu Sep 17 15:37:35.224727 2026] [security2:error] [pid 18946:tid 19171] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-blink.php"] [unique_id "aqxdnzqiPMah0Tz_U1Oz0wAAAWk"]
[Thu Sep 17 15:37:35.532380 2026] [security2:error] [pid 18946:tid 19092] [client 143.244.57.120:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.kbmautomation.com"] [uri "/xmlrpc.php"] [unique_id "aqxdnzqiPMah0Tz_U1Oz2wAAARo"]
[Thu Sep 17 15:37:35.811629 2026] [security2:error] [pid 18946:tid 19179] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-logis.php"] [unique_id "aqxdnzqiPMah0Tz_U1Oz4gAAAXE"]
[Thu Sep 17 15:37:35.811747 2026] [security2:error] [pid 18946:tid 19179] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-logis.php"] [unique_id "aqxdnzqiPMah0Tz_U1Oz4gAAAXE"]
[Thu Sep 17 15:37:36.000082 2026] [security2:error] [pid 18946:tid 19151] [client 34.166.234.125:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxdnzqiPMah0Tz_U1Oz6AAAAVU"]
[Thu Sep 17 15:37:36.267528 2026] [security2:error] [pid 18946:tid 19078] [client 143.244.57.120:54234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxdoDqiPMah0Tz_U1Oz7gAAAQw"]
[Thu Sep 17 15:37:36.405328 2026] [security2:error] [pid 20162:tid 20322] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wsxedc.php"] [unique_id "aqxdoK-O_Kk7aqBvaiGE0QAAAaw"]
[Thu Sep 17 15:37:36.405421 2026] [security2:error] [pid 20162:tid 20322] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wsxedc.php"] [unique_id "aqxdoK-O_Kk7aqBvaiGE0QAAAaw"]
[Thu Sep 17 15:37:36.593599 2026] [security2:error] [pid 20162:tid 20390] [client 143.244.57.120:54236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxdoK-O_Kk7aqBvaiGE0wAAAfA"]
[Thu Sep 17 15:37:36.683756 2026] [security2:error] [pid 18946:tid 19137] [client 34.166.234.125:55900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/info.php"] [unique_id "aqxdoDqiPMah0Tz_U1Oz9gAAAUc"]
[Thu Sep 17 15:37:36.906722 2026] [security2:error] [pid 20162:tid 20403] [client 143.244.57.120:54242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxdoK-O_Kk7aqBvaiGE1QAAAf0"]
[Thu Sep 17 15:37:36.991105 2026] [security2:error] [pid 18946:tid 19172] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/idolet.php"] [unique_id "aqxdoDqiPMah0Tz_U1Oz_gAAAWo"]
[Thu Sep 17 15:37:36.991189 2026] [security2:error] [pid 18946:tid 19172] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/idolet.php"] [unique_id "aqxdoDqiPMah0Tz_U1Oz_gAAAWo"]
[Thu Sep 17 15:37:37.223237 2026] [security2:error] [pid 18946:tid 19201] [client 143.244.57.120:54252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxdoTqiPMah0Tz_U1O0BQAAAYc"]
[Thu Sep 17 15:37:37.381137 2026] [security2:error] [pid 18946:tid 19090] [client 34.166.234.125:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/php.php"] [unique_id "aqxdoTqiPMah0Tz_U1O0CgAAARg"]
[Thu Sep 17 15:37:37.526092 2026] [security2:error] [pid 18946:tid 19115] [client 143.244.57.120:54266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxdoTqiPMah0Tz_U1O0DgAAATE"]
[Thu Sep 17 15:37:37.563803 2026] [security2:error] [pid 18946:tid 19093] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/weem.php"] [unique_id "aqxdoTqiPMah0Tz_U1O0DwAAARs"]
[Thu Sep 17 15:37:37.563885 2026] [security2:error] [pid 18946:tid 19093] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/weem.php"] [unique_id "aqxdoTqiPMah0Tz_U1O0DwAAARs"]
[Thu Sep 17 15:37:37.580428 2026] [security2:error] [pid 18946:tid 19161] [client 103.178.7.243:57011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdoTqiPMah0Tz_U1O0DQABXxU"]
[Thu Sep 17 15:37:37.914159 2026] [security2:error] [pid 20162:tid 20299] [client 143.244.57.120:54274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxdoa-O_Kk7aqBvaiGE2gAAAZU"]
[Thu Sep 17 15:37:37.955474 2026] [security2:error] [pid 18946:tid 18986] [remote 45.157.54.43:53233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "churchinirving.org"] [uri "/xmlrpc.php"] [unique_id "aqxdoTqiPMah0Tz_U1O0GAABNic"]
[Thu Sep 17 15:37:37.955638 2026] [security2:error] [pid 18946:tid 19120] [client 45.157.54.43:53233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "churchinirving.org"] [uri "/xmlrpc.php"] [unique_id "aqxdoTqiPMah0Tz_U1O0GAABNic"]
[Thu Sep 17 15:37:38.081413 2026] [security2:error] [pid 18946:tid 19203] [client 34.166.234.125:55916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/i.php"] [unique_id "aqxdojqiPMah0Tz_U1O0HAAAAYk"]
[Thu Sep 17 15:37:38.134503 2026] [security2:error] [pid 18946:tid 19162] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/vitellose.php"] [unique_id "aqxdojqiPMah0Tz_U1O0HgAAAWA"]
[Thu Sep 17 15:37:38.134588 2026] [security2:error] [pid 18946:tid 19162] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/vitellose.php"] [unique_id "aqxdojqiPMah0Tz_U1O0HgAAAWA"]
[Thu Sep 17 15:37:38.217253 2026] [security2:error] [pid 20162:tid 20355] [client 143.244.57.120:54284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxdoq-O_Kk7aqBvaiGE4QAAAc0"]
[Thu Sep 17 15:37:38.523301 2026] [security2:error] [pid 18946:tid 19157] [client 143.244.57.120:54298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxdojqiPMah0Tz_U1O0RgAAAVs"]
[Thu Sep 17 15:37:38.718176 2026] [security2:error] [pid 18946:tid 19168] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/carcassed.php"] [unique_id "aqxdojqiPMah0Tz_U1O0SgAAAWY"]
[Thu Sep 17 15:37:38.718307 2026] [security2:error] [pid 18946:tid 19168] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/carcassed.php"] [unique_id "aqxdojqiPMah0Tz_U1O0SgAAAWY"]
[Thu Sep 17 15:37:38.786635 2026] [security2:error] [pid 18946:tid 19099] [client 34.166.234.125:55918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxdojqiPMah0Tz_U1O0SwAAASE"]
[Thu Sep 17 15:37:38.811984 2026] [security2:error] [pid 18946:tid 19172] [client 143.244.57.120:54306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxdojqiPMah0Tz_U1O0TgAAAWo"]
[Thu Sep 17 15:37:38.857188 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.220.126:58484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/"] [unique_id "aqxdoq-O_Kk7aqBvaiGFDAAAAZk"]
[Thu Sep 17 15:37:39.111358 2026] [security2:error] [pid 18946:tid 19094] [client 143.244.57.120:54308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxdozqiPMah0Tz_U1O0VQAAARw"]
[Thu Sep 17 15:37:39.200443 2026] [security2:error] [pid 18946:tid 19089] [client 14.96.156.146:53082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdozqiPMah0Tz_U1O0VwAAARc"]
[Thu Sep 17 15:37:39.201066 2026] [security2:error] [pid 18946:tid 19089] [client 14.96.156.146:53082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdozqiPMah0Tz_U1O0VwAAARc"]
[Thu Sep 17 15:37:39.304642 2026] [security2:error] [pid 20162:tid 20266] [remote 45.157.54.43:54971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "churchinirving.org"] [uri "/xmlrpc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFDwABw2Y"]
[Thu Sep 17 15:37:39.304913 2026] [security2:error] [pid 20162:tid 20345] [client 45.157.54.43:54971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "churchinirving.org"] [uri "/xmlrpc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFDwABw2Y"]
[Thu Sep 17 15:37:39.314089 2026] [security2:error] [pid 20162:tid 20417] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/esc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFEQAAAgs"]
[Thu Sep 17 15:37:39.314241 2026] [security2:error] [pid 20162:tid 20417] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/esc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFEQAAAgs"]
[Thu Sep 17 15:37:39.404142 2026] [security2:error] [pid 18946:tid 19170] [client 143.244.57.120:54318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxdozqiPMah0Tz_U1O0YAAAAWg"]
[Thu Sep 17 15:37:39.419939 2026] [security2:error] [pid 20162:tid 20326] [client 34.154.220.126:58500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/"] [unique_id "aqxdo6-O_Kk7aqBvaiGFFQAAAbA"]
[Thu Sep 17 15:37:39.465007 2026] [security2:error] [pid 20162:tid 20318] [client 114.198.138.124:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFFgAAAag"]
[Thu Sep 17 15:37:39.465514 2026] [security2:error] [pid 20162:tid 20318] [client 114.198.138.124:57316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFFgAAAag"]
[Thu Sep 17 15:37:39.486798 2026] [security2:error] [pid 20162:tid 20298] [client 34.166.234.125:55920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFFwAAAZQ"]
[Thu Sep 17 15:37:39.488409 2026] [security2:error] [pid 20162:tid 20332] [client 136.158.61.34:16639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFGAAAAbY"]
[Thu Sep 17 15:37:39.488732 2026] [security2:error] [pid 20162:tid 20332] [client 136.158.61.34:16639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdo6-O_Kk7aqBvaiGFGAAAAbY"]
[Thu Sep 17 15:37:39.515869 2026] [security2:error] [pid 18946:tid 19104] [client 196.117.219.135:49832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdozqiPMah0Tz_U1O0XgABJnk"]
[Thu Sep 17 15:37:39.726249 2026] [security2:error] [pid 20162:tid 20314] [client 143.244.57.120:54330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxdo6-O_Kk7aqBvaiGFGgAAAaQ"]
[Thu Sep 17 15:37:39.912841 2026] [security2:error] [pid 18946:tid 19203] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger2.php"] [unique_id "aqxdozqiPMah0Tz_U1O0aQAAAYk"]
[Thu Sep 17 15:37:39.912934 2026] [security2:error] [pid 18946:tid 19203] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger2.php"] [unique_id "aqxdozqiPMah0Tz_U1O0aQAAAYk"]
[Thu Sep 17 15:37:39.964881 2026] [security2:error] [pid 18946:tid 19139] [client 34.154.220.126:58516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/"] [unique_id "aqxdozqiPMah0Tz_U1O0awAAAUk"]
[Thu Sep 17 15:37:40.008031 2026] [security2:error] [pid 18946:tid 19162] [client 143.244.57.120:58872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxdpDqiPMah0Tz_U1O0bAAAAWA"]
[Thu Sep 17 15:37:40.171888 2026] [security2:error] [pid 20162:tid 20324] [client 34.166.234.125:55932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/test.php"] [unique_id "aqxdpK-O_Kk7aqBvaiGFHAAAAa4"]
[Thu Sep 17 15:37:40.400389 2026] [security2:error] [pid 20162:tid 20362] [client 143.244.57.120:58888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxdpK-O_Kk7aqBvaiGFHwAAAdQ"]
[Thu Sep 17 15:37:40.494270 2026] [security2:error] [pid 18946:tid 19169] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger3.php"] [unique_id "aqxdpDqiPMah0Tz_U1O0dwAAAWc"]
[Thu Sep 17 15:37:40.494367 2026] [security2:error] [pid 18946:tid 19169] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger3.php"] [unique_id "aqxdpDqiPMah0Tz_U1O0dwAAAWc"]
[Thu Sep 17 15:37:40.665780 2026] [security2:error] [pid 20162:tid 20376] [client 34.154.220.126:58530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/"] [unique_id "aqxdpK-O_Kk7aqBvaiGFIwAAAeI"]
[Thu Sep 17 15:37:40.698329 2026] [security2:error] [pid 20162:tid 20377] [client 143.244.57.120:58892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.kbmautomation.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxdpK-O_Kk7aqBvaiGFJAAAAeM"]
[Thu Sep 17 15:37:41.115033 2026] [security2:error] [pid 20162:tid 20335] [client 34.166.234.125:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/p.php"] [unique_id "aqxdpa-O_Kk7aqBvaiGFJgAAAbk"]
[Thu Sep 17 15:37:41.137714 2026] [security2:error] [pid 20162:tid 20403] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/.env"] [unique_id "aqxdpa-O_Kk7aqBvaiGFJwAAAf0"]
[Thu Sep 17 15:37:41.178679 2026] [security2:error] [pid 18946:tid 19090] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger4.php"] [unique_id "aqxdpTqiPMah0Tz_U1O0kAAAARg"]
[Thu Sep 17 15:37:41.178777 2026] [security2:error] [pid 18946:tid 19090] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger4.php"] [unique_id "aqxdpTqiPMah0Tz_U1O0kAAAARg"]
[Thu Sep 17 15:37:41.482419 2026] [security2:error] [pid 18946:tid 19096] [client 177.44.133.72:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdpTqiPMah0Tz_U1O0mgAAAR4"]
[Thu Sep 17 15:37:41.482548 2026] [security2:error] [pid 18946:tid 19096] [client 177.44.133.72:57700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdpTqiPMah0Tz_U1O0mgAAAR4"]
[Thu Sep 17 15:37:41.790906 2026] [security2:error] [pid 20162:tid 20337] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger5.php"] [unique_id "aqxdpa-O_Kk7aqBvaiGFLgAAAbs"]
[Thu Sep 17 15:37:41.790985 2026] [security2:error] [pid 20162:tid 20337] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger5.php"] [unique_id "aqxdpa-O_Kk7aqBvaiGFLgAAAbs"]
[Thu Sep 17 15:37:41.815649 2026] [security2:error] [pid 18946:tid 19149] [client 34.166.234.125:55954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxdpTqiPMah0Tz_U1O0oQAAAVM"]
[Thu Sep 17 15:37:42.214653 2026] [security2:error] [pid 18946:tid 19184] [client 41.99.143.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxdpjqiPMah0Tz_U1O0qAAAAXY"], referer: http://coronadoiscalling.com/promotion-request
[Thu Sep 17 15:37:42.528042 2026] [security2:error] [pid 18946:tid 19162] [client 34.166.234.125:55964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxdpjqiPMah0Tz_U1O0sAAAAWA"]
[Thu Sep 17 15:37:42.571909 2026] [security2:error] [pid 20162:tid 20302] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxdpq-O_Kk7aqBvaiGFNQAAAZg"]
[Thu Sep 17 15:37:42.650397 2026] [security2:error] [pid 18946:tid 19155] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger6.php"] [unique_id "aqxdpjqiPMah0Tz_U1O0sgAAAVk"]
[Thu Sep 17 15:37:42.650485 2026] [security2:error] [pid 18946:tid 19155] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger6.php"] [unique_id "aqxdpjqiPMah0Tz_U1O0sgAAAVk"]
[Thu Sep 17 15:37:42.734182 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxdpq-O_Kk7aqBvaiGFNwAAAZk"]
[Thu Sep 17 15:37:43.101891 2026] [security2:error] [pid 20162:tid 20301] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxdp6-O_Kk7aqBvaiGFUAAAAZc"]
[Thu Sep 17 15:37:43.219804 2026] [security2:error] [pid 20162:tid 20305] [client 34.166.234.125:55980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxdp6-O_Kk7aqBvaiGFVgAAAZs"]
[Thu Sep 17 15:37:43.224138 2026] [security2:error] [pid 20162:tid 20389] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger7.php"] [unique_id "aqxdp6-O_Kk7aqBvaiGFVwAAAe8"]
[Thu Sep 17 15:37:43.224228 2026] [security2:error] [pid 20162:tid 20389] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger7.php"] [unique_id "aqxdp6-O_Kk7aqBvaiGFVwAAAe8"]
[Thu Sep 17 15:37:43.782324 2026] [security2:error] [pid 20162:tid 20335] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger8.php"] [unique_id "aqxdp6-O_Kk7aqBvaiGFYgAAAbk"]
[Thu Sep 17 15:37:43.782419 2026] [security2:error] [pid 20162:tid 20335] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger8.php"] [unique_id "aqxdp6-O_Kk7aqBvaiGFYgAAAbk"]
[Thu Sep 17 15:37:43.904410 2026] [security2:error] [pid 20162:tid 20398] [client 34.166.234.125:55996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxdp6-O_Kk7aqBvaiGFZQAAAfg"]
[Thu Sep 17 15:37:44.016041 2026] [security2:error] [pid 18946:tid 19171] [client 114.119.129.233:49003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.seedboxpress.com"] [uri "/sitemap.rss"] [unique_id "aqxdqDqiPMah0Tz_U1O08wAAAWk"]
[Thu Sep 17 15:37:44.361416 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger9.php"] [unique_id "aqxdqDqiPMah0Tz_U1O0_QAAAUU"]
[Thu Sep 17 15:37:44.361560 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger9.php"] [unique_id "aqxdqDqiPMah0Tz_U1O0_QAAAUU"]
[Thu Sep 17 15:37:44.362628 2026] [security2:error] [pid 18946:tid 19151] [client 200.86.228.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxdqDqiPMah0Tz_U1O0-QAAAVU"], referer: https://coronadoiscalling.com
[Thu Sep 17 15:37:44.599415 2026] [security2:error] [pid 18946:tid 19080] [client 34.166.234.125:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxdqDqiPMah0Tz_U1O0_wAAAQ4"]
[Thu Sep 17 15:37:44.725808 2026] [security2:error] [pid 18946:tid 19199] [client 103.61.184.148:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdqDqiPMah0Tz_U1O1AAAAAYU"]
[Thu Sep 17 15:37:44.725904 2026] [security2:error] [pid 18946:tid 19199] [client 103.61.184.148:64270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdqDqiPMah0Tz_U1O1AAAAAYU"]
[Thu Sep 17 15:37:44.900035 2026] [security2:error] [pid 18946:tid 19185] [client 143.105.152.240:60844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdqDqiPMah0Tz_U1O1AgAAAXc"]
[Thu Sep 17 15:37:44.900208 2026] [security2:error] [pid 18946:tid 19185] [client 143.105.152.240:60844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdqDqiPMah0Tz_U1O1AgAAAXc"]
[Thu Sep 17 15:37:44.965365 2026] [security2:error] [pid 20162:tid 20362] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger10.php"] [unique_id "aqxdqK-O_Kk7aqBvaiGFgQAAAdQ"]
[Thu Sep 17 15:37:44.965468 2026] [security2:error] [pid 20162:tid 20362] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger10.php"] [unique_id "aqxdqK-O_Kk7aqBvaiGFgQAAAdQ"]
[Thu Sep 17 15:37:45.181152 2026] [security2:error] [pid 20162:tid 20324] [client 79.116.89.151:63030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdqa-O_Kk7aqBvaiGFiAAAAa4"]
[Thu Sep 17 15:37:45.181279 2026] [security2:error] [pid 20162:tid 20324] [client 79.116.89.151:63030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdqa-O_Kk7aqBvaiGFiAAAAa4"]
[Thu Sep 17 15:37:45.285151 2026] [security2:error] [pid 20162:tid 20329] [client 34.166.234.125:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdqa-O_Kk7aqBvaiGFigAAAbM"]
[Thu Sep 17 15:37:45.569528 2026] [security2:error] [pid 20162:tid 20395] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger11.php"] [unique_id "aqxdqa-O_Kk7aqBvaiGFkAAAAfU"]
[Thu Sep 17 15:37:45.569684 2026] [security2:error] [pid 20162:tid 20395] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger11.php"] [unique_id "aqxdqa-O_Kk7aqBvaiGFkAAAAfU"]
[Thu Sep 17 15:37:45.585034 2026] [security2:error] [pid 20162:tid 20306] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxdqa-O_Kk7aqBvaiGFkQAAAZw"]
[Thu Sep 17 15:37:45.740013 2026] [security2:error] [pid 20162:tid 20416] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/.env~"] [unique_id "aqxdqa-O_Kk7aqBvaiGFkwAAAgo"]
[Thu Sep 17 15:37:45.963559 2026] [security2:error] [pid 20162:tid 20316] [client 34.166.234.125:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxdqa-O_Kk7aqBvaiGFmAAAAaY"]
[Thu Sep 17 15:37:45.983024 2026] [authz_core:error] [pid 20162:tid 20370] [client 40.81.232.68:59964] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Thu Sep 17 15:37:46.148009 2026] [security2:error] [pid 18946:tid 19186] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger12.php"] [unique_id "aqxdqjqiPMah0Tz_U1O1DwAAAXg"]
[Thu Sep 17 15:37:46.148088 2026] [security2:error] [pid 18946:tid 19186] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemannger12.php"] [unique_id "aqxdqjqiPMah0Tz_U1O1DwAAAXg"]
[Thu Sep 17 15:37:46.378464 2026] [security2:error] [pid 18946:tid 19197] [client 169.58.197.253:50887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxdqjqiPMah0Tz_U1O1FgAAAYM"], referer: binance.com
[Thu Sep 17 15:37:46.748804 2026] [security2:error] [pid 18946:tid 19187] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/2.php"] [unique_id "aqxdqjqiPMah0Tz_U1O1HAAAAXk"]
[Thu Sep 17 15:37:46.748892 2026] [security2:error] [pid 18946:tid 19187] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/2.php"] [unique_id "aqxdqjqiPMah0Tz_U1O1HAAAAXk"]
[Thu Sep 17 15:37:46.897741 2026] [security2:error] [pid 18946:tid 19199] [client 34.166.234.125:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxdqjqiPMah0Tz_U1O1HQAAAYU"]
[Thu Sep 17 15:37:47.326198 2026] [security2:error] [pid 20162:tid 20394] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/ba.php"] [unique_id "aqxdq6-O_Kk7aqBvaiGFtgAAAfQ"]
[Thu Sep 17 15:37:47.326443 2026] [security2:error] [pid 20162:tid 20394] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/ba.php"] [unique_id "aqxdq6-O_Kk7aqBvaiGFtgAAAfQ"]
[Thu Sep 17 15:37:47.380879 2026] [security2:error] [pid 18946:tid 19102] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdojqiPMah0Tz_U1O0IAAAASQ"]
[Thu Sep 17 15:37:47.402195 2026] [security2:error] [pid 20162:tid 20364] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxdq6-O_Kk7aqBvaiGFuAAAAdY"]
[Thu Sep 17 15:37:47.534530 2026] [core:error] [pid 20162:tid 20267] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/new/
[Thu Sep 17 15:37:47.534547 2026] [core:error] [pid 20162:tid 20267] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/new/
[Thu Sep 17 15:37:47.578630 2026] [security2:error] [pid 20162:tid 20325] [client 34.166.234.125:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxdq6-O_Kk7aqBvaiGFvAAAAa8"]
[Thu Sep 17 15:37:47.594095 2026] [security2:error] [pid 20162:tid 20416] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxdq6-O_Kk7aqBvaiGFvQAAAgo"]
[Thu Sep 17 15:37:47.767956 2026] [security2:error] [pid 20162:tid 20420] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxdq6-O_Kk7aqBvaiGFxAAAAg4"]
[Thu Sep 17 15:37:47.784201 2026] [security2:error] [pid 20162:tid 20316] [client 79.117.187.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdq6-O_Kk7aqBvaiGFwgAAAaY"], referer: https://trcco.org
[Thu Sep 17 15:37:47.951570 2026] [security2:error] [pid 20162:tid 20301] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxdq6-O_Kk7aqBvaiGFxwAAAZc"]
[Thu Sep 17 15:37:47.954510 2026] [security2:error] [pid 18946:tid 19122] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/great.php"] [unique_id "aqxdqzqiPMah0Tz_U1O1LwAAATg"]
[Thu Sep 17 15:37:47.954597 2026] [security2:error] [pid 18946:tid 19122] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/great.php"] [unique_id "aqxdqzqiPMah0Tz_U1O1LwAAATg"]
[Thu Sep 17 15:37:47.984709 2026] [core:error] [pid 20162:tid 20273] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/backup/
[Thu Sep 17 15:37:47.984726 2026] [core:error] [pid 20162:tid 20273] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/backup/
[Thu Sep 17 15:37:48.116895 2026] [security2:error] [pid 20162:tid 20376] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxdrK-O_Kk7aqBvaiGFzQAAAeI"]
[Thu Sep 17 15:37:48.257871 2026] [security2:error] [pid 20162:tid 20340] [client 34.166.234.125:47198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxdrK-O_Kk7aqBvaiGFzwAAAb4"]
[Thu Sep 17 15:37:48.305883 2026] [security2:error] [pid 20162:tid 20398] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxdrK-O_Kk7aqBvaiGF0AAAAfg"]
[Thu Sep 17 15:37:48.441219 2026] [core:error] [pid 20162:tid 20166] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/blog/
[Thu Sep 17 15:37:48.441238 2026] [core:error] [pid 20162:tid 20166] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/blog/
[Thu Sep 17 15:37:48.533475 2026] [security2:error] [pid 18946:tid 19165] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aqxdrDqiPMah0Tz_U1O1OQAAAWM"]
[Thu Sep 17 15:37:48.533548 2026] [security2:error] [pid 18946:tid 19165] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aqxdrDqiPMah0Tz_U1O1OQAAAWM"]
[Thu Sep 17 15:37:48.672055 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxdrK-O_Kk7aqBvaiGF2AAAAbs"]
[Thu Sep 17 15:37:48.834999 2026] [security2:error] [pid 20162:tid 20405] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxdrK-O_Kk7aqBvaiGF2wAAAf8"]
[Thu Sep 17 15:37:48.886717 2026] [core:error] [pid 20162:tid 20287] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/wordpress/
[Thu Sep 17 15:37:48.886736 2026] [core:error] [pid 20162:tid 20287] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/wordpress/
[Thu Sep 17 15:37:48.950787 2026] [security2:error] [pid 18946:tid 19147] [client 34.166.234.125:47218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxdrDqiPMah0Tz_U1O1QAAAAVE"]
[Thu Sep 17 15:37:49.007281 2026] [security2:error] [pid 20162:tid 20294] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxdra-O_Kk7aqBvaiGF3gAAAZA"]
[Thu Sep 17 15:37:49.122715 2026] [security2:error] [pid 18946:tid 19181] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/robots.php"] [unique_id "aqxdrTqiPMah0Tz_U1O1QwAAAXM"]
[Thu Sep 17 15:37:49.122800 2026] [security2:error] [pid 18946:tid 19181] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/robots.php"] [unique_id "aqxdrTqiPMah0Tz_U1O1QwAAAXM"]
[Thu Sep 17 15:37:49.162416 2026] [security2:error] [pid 20162:tid 20316] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxdra-O_Kk7aqBvaiGF4AAAAaY"]
[Thu Sep 17 15:37:49.338101 2026] [core:error] [pid 20162:tid 20268] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/old/
[Thu Sep 17 15:37:49.338132 2026] [core:error] [pid 20162:tid 20268] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/old/
[Thu Sep 17 15:37:49.342459 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxdra-O_Kk7aqBvaiGF4wAAAeQ"]
[Thu Sep 17 15:37:49.535498 2026] [security2:error] [pid 20162:tid 20309] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxdra-O_Kk7aqBvaiGF5gAAAZ8"]
[Thu Sep 17 15:37:49.635249 2026] [security2:error] [pid 20162:tid 20303] [client 34.166.234.125:47226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxdra-O_Kk7aqBvaiGF5wAAAZk"]
[Thu Sep 17 15:37:49.706342 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxdra-O_Kk7aqBvaiGF6QAAAfY"]
[Thu Sep 17 15:37:49.713447 2026] [security2:error] [pid 20162:tid 20354] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/k.php"] [unique_id "aqxdra-O_Kk7aqBvaiGF6gAAAcw"]
[Thu Sep 17 15:37:49.713522 2026] [security2:error] [pid 20162:tid 20354] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/k.php"] [unique_id "aqxdra-O_Kk7aqBvaiGF6gAAAcw"]
[Thu Sep 17 15:37:49.788224 2026] [core:error] [pid 20162:tid 20261] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/wp/
[Thu Sep 17 15:37:49.788242 2026] [core:error] [pid 20162:tid 20261] [remote 157.245.146.242:58756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://risingstarspress.com/wp/
[Thu Sep 17 15:37:49.815560 2026] [security2:error] [pid 18946:tid 19136] [client 14.96.156.146:53719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdrTqiPMah0Tz_U1O1SwAAAUY"]
[Thu Sep 17 15:37:49.815650 2026] [security2:error] [pid 18946:tid 19136] [client 14.96.156.146:53719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdrTqiPMah0Tz_U1O1SwAAAUY"]
[Thu Sep 17 15:37:49.888714 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxdra-O_Kk7aqBvaiGF7QAAAc4"]
[Thu Sep 17 15:37:49.951245 2026] [security2:error] [pid 18946:tid 19137] [client 40.81.232.68:51805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "aqxdrTqiPMah0Tz_U1O1TAAAAUc"], referer: binance.com
[Thu Sep 17 15:37:50.053889 2026] [security2:error] [pid 20162:tid 20384] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxdrq-O_Kk7aqBvaiGF8QAAAeo"]
[Thu Sep 17 15:37:50.084020 2026] [security2:error] [pid 18946:tid 19079] [client 114.198.138.124:57961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdrjqiPMah0Tz_U1O1UAAAAQ0"]
[Thu Sep 17 15:37:50.084122 2026] [security2:error] [pid 18946:tid 19079] [client 114.198.138.124:57961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdrjqiPMah0Tz_U1O1UAAAAQ0"]
[Thu Sep 17 15:37:50.236352 2026] [security2:error] [pid 20162:tid 20300] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxdrq-O_Kk7aqBvaiGF9QAAAZY"]
[Thu Sep 17 15:37:50.238425 2026] [autoindex:error] [pid 20162:tid 20274] [remote 157.245.146.242:58756] AH01276: Cannot serve directory /home1/awesone8/public_html/risingstarspress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://risingstarspress.com/
[Thu Sep 17 15:37:50.275915 2026] [security2:error] [pid 18946:tid 19132] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/w.php"] [unique_id "aqxdrjqiPMah0Tz_U1O1UgAAAUI"]
[Thu Sep 17 15:37:50.276108 2026] [security2:error] [pid 18946:tid 19132] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/w.php"] [unique_id "aqxdrjqiPMah0Tz_U1O1UgAAAUI"]
[Thu Sep 17 15:37:50.317707 2026] [security2:error] [pid 18946:tid 19199] [client 34.166.234.125:47244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxdrjqiPMah0Tz_U1O1UwAAAYU"]
[Thu Sep 17 15:37:50.410881 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxdrq-O_Kk7aqBvaiGF9wAAAaM"]
[Thu Sep 17 15:37:50.569846 2026] [security2:error] [pid 20162:tid 20391] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxdrq-O_Kk7aqBvaiGF-wAAAfE"]
[Thu Sep 17 15:37:50.748836 2026] [security2:error] [pid 20162:tid 20339] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxdrq-O_Kk7aqBvaiGF_QAAAb0"]
[Thu Sep 17 15:37:50.841303 2026] [security2:error] [pid 18946:tid 19088] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/ccc.php"] [unique_id "aqxdrjqiPMah0Tz_U1O1WQAAARY"]
[Thu Sep 17 15:37:50.841392 2026] [security2:error] [pid 18946:tid 19088] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/ccc.php"] [unique_id "aqxdrjqiPMah0Tz_U1O1WQAAARY"]
[Thu Sep 17 15:37:50.954314 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxdrq-O_Kk7aqBvaiGGAgAAAcI"]
[Thu Sep 17 15:37:51.135227 2026] [security2:error] [pid 20162:tid 20411] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxdr6-O_Kk7aqBvaiGGBAAAAgU"]
[Thu Sep 17 15:37:51.303425 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxdr6-O_Kk7aqBvaiGGCAAAAfQ"]
[Thu Sep 17 15:37:51.438616 2026] [security2:error] [pid 20162:tid 20404] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/images.php"] [unique_id "aqxdr6-O_Kk7aqBvaiGGDAAAAf4"]
[Thu Sep 17 15:37:51.438721 2026] [security2:error] [pid 20162:tid 20404] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/images.php"] [unique_id "aqxdr6-O_Kk7aqBvaiGGDAAAAf4"]
[Thu Sep 17 15:37:51.475819 2026] [security2:error] [pid 20162:tid 20410] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxdr6-O_Kk7aqBvaiGGDQAAAgQ"]
[Thu Sep 17 15:37:51.496295 2026] [security2:error] [pid 18946:tid 19167] [client 34.166.234.125:47254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdrzqiPMah0Tz_U1O1ZwAAAWU"]
[Thu Sep 17 15:37:51.643642 2026] [security2:error] [pid 20162:tid 20293] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxdr6-O_Kk7aqBvaiGGEQAAAY8"]
[Thu Sep 17 15:37:51.818644 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxdr6-O_Kk7aqBvaiGGFgAAAZE"]
[Thu Sep 17 15:37:51.989176 2026] [security2:error] [pid 20162:tid 20370] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxdr6-O_Kk7aqBvaiGGGQAAAdw"]
[Thu Sep 17 15:37:52.033210 2026] [security2:error] [pid 20162:tid 20294] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/alls.php"] [unique_id "aqxdsK-O_Kk7aqBvaiGGGgAAAZA"]
[Thu Sep 17 15:37:52.033330 2026] [security2:error] [pid 20162:tid 20294] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/alls.php"] [unique_id "aqxdsK-O_Kk7aqBvaiGGGgAAAZA"]
[Thu Sep 17 15:37:52.083886 2026] [security2:error] [pid 18946:tid 19085] [client 136.158.61.34:17743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdsDqiPMah0Tz_U1O1awAAARM"]
[Thu Sep 17 15:37:52.084023 2026] [security2:error] [pid 18946:tid 19085] [client 136.158.61.34:17743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdsDqiPMah0Tz_U1O1awAAARM"]
[Thu Sep 17 15:37:52.129870 2026] [security2:error] [pid 20162:tid 20327] [client 177.44.133.72:58490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdsK-O_Kk7aqBvaiGGGwAAAbE"]
[Thu Sep 17 15:37:52.129991 2026] [security2:error] [pid 20162:tid 20327] [client 177.44.133.72:58490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdsK-O_Kk7aqBvaiGGGwAAAbE"]
[Thu Sep 17 15:37:52.156006 2026] [security2:error] [pid 20162:tid 20316] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxdsK-O_Kk7aqBvaiGGHQAAAaY"]
[Thu Sep 17 15:37:52.179384 2026] [security2:error] [pid 20162:tid 20416] [client 34.166.234.125:47280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxdsK-O_Kk7aqBvaiGGHgAAAgo"]
[Thu Sep 17 15:37:52.311613 2026] [security2:error] [pid 20162:tid 20323] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxdsK-O_Kk7aqBvaiGGIQAAAa0"]
[Thu Sep 17 15:37:52.472259 2026] [security2:error] [pid 20162:tid 20345] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxdsK-O_Kk7aqBvaiGGJQAAAcM"]
[Thu Sep 17 15:37:52.604174 2026] [security2:error] [pid 20162:tid 20389] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxdsK-O_Kk7aqBvaiGGKQAAAe8"]
[Thu Sep 17 15:37:52.604293 2026] [security2:error] [pid 20162:tid 20389] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxdsK-O_Kk7aqBvaiGGKQAAAe8"]
[Thu Sep 17 15:37:52.658413 2026] [security2:error] [pid 20162:tid 20309] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxdsK-O_Kk7aqBvaiGGKgAAAZ8"]
[Thu Sep 17 15:37:52.824522 2026] [security2:error] [pid 20162:tid 20340] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxdsK-O_Kk7aqBvaiGGKwAAAb4"]
[Thu Sep 17 15:37:52.863386 2026] [security2:error] [pid 18946:tid 19108] [client 34.166.234.125:47312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdsDqiPMah0Tz_U1O1dAAAASo"]
[Thu Sep 17 15:37:52.984671 2026] [security2:error] [pid 20162:tid 20315] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxdsK-O_Kk7aqBvaiGGLwAAAaU"]
[Thu Sep 17 15:37:53.155975 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxdsa-O_Kk7aqBvaiGGMwAAAaM"]
[Thu Sep 17 15:37:53.180008 2026] [security2:error] [pid 20162:tid 20330] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-ana.php"] [unique_id "aqxdsa-O_Kk7aqBvaiGGNQAAAbQ"]
[Thu Sep 17 15:37:53.180120 2026] [security2:error] [pid 20162:tid 20330] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-ana.php"] [unique_id "aqxdsa-O_Kk7aqBvaiGGNQAAAbQ"]
[Thu Sep 17 15:37:53.326084 2026] [security2:error] [pid 20162:tid 20348] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxdsa-O_Kk7aqBvaiGGNwAAAcY"]
[Thu Sep 17 15:37:53.493340 2026] [security2:error] [pid 20162:tid 20336] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxdsa-O_Kk7aqBvaiGGPQAAAbo"]
[Thu Sep 17 15:37:53.525769 2026] [security2:error] [pid 18946:tid 19156] [client 79.117.194.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxdsTqiPMah0Tz_U1O1eQAAAVo"], referer: https://trcco.org
[Thu Sep 17 15:37:53.548322 2026] [security2:error] [pid 20162:tid 20328] [client 34.166.234.125:47338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdsa-O_Kk7aqBvaiGGQgAAAbI"]
[Thu Sep 17 15:37:53.661415 2026] [security2:error] [pid 20162:tid 20369] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxdsa-O_Kk7aqBvaiGGRAAAAds"]
[Thu Sep 17 15:37:53.758483 2026] [security2:error] [pid 20162:tid 20297] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/geck.php"] [unique_id "aqxdsa-O_Kk7aqBvaiGGSQAAAZM"]
[Thu Sep 17 15:37:53.758603 2026] [security2:error] [pid 20162:tid 20297] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/geck.php"] [unique_id "aqxdsa-O_Kk7aqBvaiGGSQAAAZM"]
[Thu Sep 17 15:37:53.803968 2026] [security2:error] [pid 20162:tid 20364] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdsa-O_Kk7aqBvaiGGSAAAAdY"]
[Thu Sep 17 15:37:53.825288 2026] [security2:error] [pid 20162:tid 20395] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxdsa-O_Kk7aqBvaiGGSwAAAfU"]
[Thu Sep 17 15:37:53.982692 2026] [security2:error] [pid 20162:tid 20296] [client 34.95.173.223:45842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.chriswestlake.com"] [uri "/"] [unique_id "aqxdsa-O_Kk7aqBvaiGGTwAAAZI"]
[Thu Sep 17 15:37:53.984125 2026] [security2:error] [pid 20162:tid 20413] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxdsa-O_Kk7aqBvaiGGTgAAAgc"]
[Thu Sep 17 15:37:54.142288 2026] [security2:error] [pid 20162:tid 20306] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxdsq-O_Kk7aqBvaiGGUwAAAZw"]
[Thu Sep 17 15:37:54.229700 2026] [security2:error] [pid 20162:tid 20337] [client 34.166.234.125:39512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdsq-O_Kk7aqBvaiGGVQAAAbs"]
[Thu Sep 17 15:37:54.302984 2026] [security2:error] [pid 20162:tid 20327] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxdsq-O_Kk7aqBvaiGGVgAAAbE"]
[Thu Sep 17 15:37:54.327936 2026] [security2:error] [pid 20162:tid 20416] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/biufile.php"] [unique_id "aqxdsq-O_Kk7aqBvaiGGWAAAAgo"]
[Thu Sep 17 15:37:54.328124 2026] [security2:error] [pid 20162:tid 20416] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/biufile.php"] [unique_id "aqxdsq-O_Kk7aqBvaiGGWAAAAgo"]
[Thu Sep 17 15:37:54.338237 2026] [security2:error] [pid 18946:tid 19017] [remote 114.119.135.136:26949] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "chicagolandexteriorsinc.com"] [uri "/financing"] [unique_id "aqxdsjqiPMah0Tz_U1O1gAABHUY"]
[Thu Sep 17 15:37:54.470588 2026] [security2:error] [pid 20162:tid 20316] [client 34.95.173.223:48004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.chriswestlake.com"] [uri "/"] [unique_id "aqxdsq-O_Kk7aqBvaiGGXAAAAaY"]
[Thu Sep 17 15:37:54.486229 2026] [security2:error] [pid 20162:tid 20419] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxdsq-O_Kk7aqBvaiGGXQAAAg0"]
[Thu Sep 17 15:37:54.661892 2026] [security2:error] [pid 20162:tid 20345] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxdsq-O_Kk7aqBvaiGGYAAAAcM"]
[Thu Sep 17 15:37:54.699384 2026] [security2:error] [pid 18946:tid 19160] [client 3.77.67.4:58138] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxdsjqiPMah0Tz_U1O1hQAAAV4"], referer: https://eris.media
[Thu Sep 17 15:37:54.822948 2026] [security2:error] [pid 20162:tid 20376] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxdsq-O_Kk7aqBvaiGGYwAAAeI"]
[Thu Sep 17 15:37:54.829001 2026] [security2:error] [pid 18946:tid 19130] [client 40.81.232.68:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "aqxdsjqiPMah0Tz_U1O1hgAAAUA"], referer: binance.com
[Thu Sep 17 15:37:54.885074 2026] [security2:error] [pid 20162:tid 20334] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/dejavu.php"] [unique_id "aqxdsq-O_Kk7aqBvaiGGZgAAAbg"]
[Thu Sep 17 15:37:54.885160 2026] [security2:error] [pid 20162:tid 20334] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/dejavu.php"] [unique_id "aqxdsq-O_Kk7aqBvaiGGZgAAAbg"]
[Thu Sep 17 15:37:54.907270 2026] [security2:error] [pid 18946:tid 19169] [client 34.166.234.125:39514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdsjqiPMah0Tz_U1O1hwAAAWc"]
[Thu Sep 17 15:37:54.960565 2026] [security2:error] [pid 18946:tid 19147] [client 34.95.173.223:48008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.chriswestlake.com"] [uri "/"] [unique_id "aqxdsjqiPMah0Tz_U1O1iAAAAVE"]
[Thu Sep 17 15:37:54.999277 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.220.126:58538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxdsq-O_Kk7aqBvaiGGZwAAAeQ"]
[Thu Sep 17 15:37:55.385430 2026] [security2:error] [pid 20162:tid 20301] [client 143.105.152.240:44533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxds6-O_Kk7aqBvaiGGbgAAAZc"]
[Thu Sep 17 15:37:55.385584 2026] [security2:error] [pid 20162:tid 20301] [client 143.105.152.240:44533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxds6-O_Kk7aqBvaiGGbgAAAZc"]
[Thu Sep 17 15:37:55.442190 2026] [security2:error] [pid 18946:tid 19148] [client 34.166.134.22:35654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.globaldove.org"] [uri "/"] [unique_id "aqxdszqiPMah0Tz_U1O1jgAAAVI"]
[Thu Sep 17 15:37:55.448452 2026] [security2:error] [pid 18946:tid 19179] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/faa.php"] [unique_id "aqxdszqiPMah0Tz_U1O1jwAAAXE"]
[Thu Sep 17 15:37:55.448550 2026] [security2:error] [pid 18946:tid 19179] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/faa.php"] [unique_id "aqxdszqiPMah0Tz_U1O1jwAAAXE"]
[Thu Sep 17 15:37:55.523629 2026] [security2:error] [pid 20162:tid 20381] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxds6-O_Kk7aqBvaiGGcgAAAec"]
[Thu Sep 17 15:37:55.556553 2026] [security2:error] [pid 20162:tid 20356] [client 103.61.184.148:64818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxds6-O_Kk7aqBvaiGGdAAAAc4"]
[Thu Sep 17 15:37:55.556678 2026] [security2:error] [pid 20162:tid 20356] [client 103.61.184.148:64818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxds6-O_Kk7aqBvaiGGdAAAAc4"]
[Thu Sep 17 15:37:55.573468 2026] [security2:error] [pid 18946:tid 19154] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxdszqiPMah0Tz_U1O1kQAAAVg"]
[Thu Sep 17 15:37:55.583954 2026] [security2:error] [pid 18946:tid 19114] [client 34.166.234.125:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxdszqiPMah0Tz_U1O1lQAAATA"]
[Thu Sep 17 15:37:55.620233 2026] [security2:error] [pid 18946:tid 19080] [client 34.95.173.223:48014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail.chriswestlake.com"] [uri "/"] [unique_id "aqxdszqiPMah0Tz_U1O1mQAAAQ4"]
[Thu Sep 17 15:37:55.682710 2026] [security2:error] [pid 20162:tid 20358] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxds6-O_Kk7aqBvaiGGegAAAdA"]
[Thu Sep 17 15:37:55.838263 2026] [security2:error] [pid 20162:tid 20357] [client 79.116.89.151:63654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxds6-O_Kk7aqBvaiGGfQAAAc8"]
[Thu Sep 17 15:37:55.838355 2026] [security2:error] [pid 20162:tid 20357] [client 79.116.89.151:63654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxds6-O_Kk7aqBvaiGGfQAAAc8"]
[Thu Sep 17 15:37:55.848476 2026] [security2:error] [pid 20162:tid 20398] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxds6-O_Kk7aqBvaiGGfgAAAfg"]
[Thu Sep 17 15:37:56.010744 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxdtK-O_Kk7aqBvaiGGggAAAcI"]
[Thu Sep 17 15:37:56.037265 2026] [security2:error] [pid 18946:tid 19149] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/h02ugyh.php"] [unique_id "aqxdtDqiPMah0Tz_U1O1ngAAAVM"]
[Thu Sep 17 15:37:56.037375 2026] [security2:error] [pid 18946:tid 19149] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/h02ugyh.php"] [unique_id "aqxdtDqiPMah0Tz_U1O1ngAAAVM"]
[Thu Sep 17 15:37:56.128096 2026] [security2:error] [pid 20162:tid 20339] [client 34.166.134.22:35664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.globaldove.org"] [uri "/"] [unique_id "aqxdtK-O_Kk7aqBvaiGGhgAAAb0"]
[Thu Sep 17 15:37:56.179013 2026] [security2:error] [pid 20162:tid 20383] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxdtK-O_Kk7aqBvaiGGhwAAAek"]
[Thu Sep 17 15:37:56.264568 2026] [security2:error] [pid 20162:tid 20410] [client 34.166.234.125:39526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxdtK-O_Kk7aqBvaiGGiQAAAgQ"]
[Thu Sep 17 15:37:56.266320 2026] [security2:error] [pid 18946:tid 19029] [remote 216.73.217.142:30745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxdtDqiPMah0Tz_U1O1ogABM1I"]
[Thu Sep 17 15:37:56.268474 2026] [security2:error] [pid 20162:tid 20418] [client 169.58.197.253:51482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxdtK-O_Kk7aqBvaiGGigAAAgw"], referer: binance.com
[Thu Sep 17 15:37:56.357583 2026] [security2:error] [pid 20162:tid 20409] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxdtK-O_Kk7aqBvaiGGjAAAAgM"]
[Thu Sep 17 15:37:56.481715 2026] [security2:error] [pid 18946:tid 19110] [client 45.185.97.70:45867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdtDqiPMah0Tz_U1O1pAABLF0"]
[Thu Sep 17 15:37:56.516622 2026] [security2:error] [pid 20162:tid 20370] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxdtK-O_Kk7aqBvaiGGkQAAAdw"]
[Thu Sep 17 15:37:56.608352 2026] [security2:error] [pid 18946:tid 19203] [client 103.102.207.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxdsDqiPMah0Tz_U1O1bgAAAYk"], referer: https://kslandscaping.net/blog
[Thu Sep 17 15:37:56.630670 2026] [security2:error] [pid 18946:tid 19201] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/155.php"] [unique_id "aqxdtDqiPMah0Tz_U1O1qwAAAYc"]
[Thu Sep 17 15:37:56.630795 2026] [security2:error] [pid 18946:tid 19201] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/155.php"] [unique_id "aqxdtDqiPMah0Tz_U1O1qwAAAYc"]
[Thu Sep 17 15:37:56.691440 2026] [security2:error] [pid 20162:tid 20372] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxdtK-O_Kk7aqBvaiGGlQAAAd4"]
[Thu Sep 17 15:37:56.751388 2026] [security2:error] [pid 18946:tid 19101] [client 40.77.167.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lemuspools.com"] [uri "/index.php"] [unique_id "aqxdtDqiPMah0Tz_U1O1rgAAASM"]
[Thu Sep 17 15:37:56.827039 2026] [security2:error] [pid 20162:tid 20327] [client 34.166.134.22:35670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.globaldove.org"] [uri "/"] [unique_id "aqxdtK-O_Kk7aqBvaiGGmQAAAbE"]
[Thu Sep 17 15:37:56.860585 2026] [security2:error] [pid 20162:tid 20415] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxdtK-O_Kk7aqBvaiGGmgAAAgk"]
[Thu Sep 17 15:37:56.959777 2026] [security2:error] [pid 20162:tid 20419] [client 34.166.234.125:39538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxdtK-O_Kk7aqBvaiGGnAAAAg0"]
[Thu Sep 17 15:37:57.055522 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxdta-O_Kk7aqBvaiGGngAAAZk"]
[Thu Sep 17 15:37:57.214407 2026] [security2:error] [pid 20162:tid 20393] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxdta-O_Kk7aqBvaiGGogAAAfM"]
[Thu Sep 17 15:37:57.219182 2026] [security2:error] [pid 20162:tid 20333] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/ops.php"] [unique_id "aqxdta-O_Kk7aqBvaiGGowAAAbc"]
[Thu Sep 17 15:37:57.219263 2026] [security2:error] [pid 20162:tid 20333] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/ops.php"] [unique_id "aqxdta-O_Kk7aqBvaiGGowAAAbc"]
[Thu Sep 17 15:37:57.389987 2026] [security2:error] [pid 20162:tid 20330] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxdta-O_Kk7aqBvaiGGqQAAAbQ"]
[Thu Sep 17 15:37:57.551994 2026] [security2:error] [pid 20162:tid 20381] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxdta-O_Kk7aqBvaiGGswAAAec"]
[Thu Sep 17 15:37:57.657940 2026] [security2:error] [pid 18946:tid 19175] [client 34.166.234.125:39554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxdtTqiPMah0Tz_U1O1xwAAAW0"]
[Thu Sep 17 15:37:57.725943 2026] [security2:error] [pid 20162:tid 20403] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxdta-O_Kk7aqBvaiGGtwAAAf0"]
[Thu Sep 17 15:37:57.742385 2026] [security2:error] [pid 20162:tid 20358] [client 34.166.134.22:35674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.globaldove.org"] [uri "/"] [unique_id "aqxdta-O_Kk7aqBvaiGGuQAAAdA"]
[Thu Sep 17 15:37:57.801366 2026] [security2:error] [pid 20162:tid 20299] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/mac.php"] [unique_id "aqxdta-O_Kk7aqBvaiGGugAAAZU"]
[Thu Sep 17 15:37:57.801441 2026] [security2:error] [pid 20162:tid 20299] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/mac.php"] [unique_id "aqxdta-O_Kk7aqBvaiGGugAAAZU"]
[Thu Sep 17 15:37:57.898302 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxdta-O_Kk7aqBvaiGGvAAAAfQ"]
[Thu Sep 17 15:37:58.085082 2026] [security2:error] [pid 20162:tid 20297] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxdtq-O_Kk7aqBvaiGGwQAAAZM"]
[Thu Sep 17 15:37:58.246294 2026] [security2:error] [pid 20162:tid 20383] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxdtq-O_Kk7aqBvaiGGxAAAAek"]
[Thu Sep 17 15:37:58.357759 2026] [security2:error] [pid 20162:tid 20344] [client 34.166.234.125:39558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxdtq-O_Kk7aqBvaiGGygAAAcI"]
[Thu Sep 17 15:37:58.391423 2026] [security2:error] [pid 20162:tid 20391] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/makeasmtp.php"] [unique_id "aqxdtq-O_Kk7aqBvaiGGywAAAfE"]
[Thu Sep 17 15:37:58.391528 2026] [security2:error] [pid 20162:tid 20391] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/makeasmtp.php"] [unique_id "aqxdtq-O_Kk7aqBvaiGGywAAAfE"]
[Thu Sep 17 15:37:58.414194 2026] [security2:error] [pid 20162:tid 20296] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxdtq-O_Kk7aqBvaiGGzAAAAZI"]
[Thu Sep 17 15:37:58.587871 2026] [security2:error] [pid 20162:tid 20325] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxdtq-O_Kk7aqBvaiGG0QAAAa8"]
[Thu Sep 17 15:37:58.752249 2026] [security2:error] [pid 20162:tid 20319] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxdtq-O_Kk7aqBvaiGG1QAAAak"]
[Thu Sep 17 15:37:58.932078 2026] [security2:error] [pid 20162:tid 20365] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxdtq-O_Kk7aqBvaiGG3AAAAdc"]
[Thu Sep 17 15:37:58.942967 2026] [security2:error] [pid 20162:tid 20420] [client 168.195.163.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxdtq-O_Kk7aqBvaiGG2gAAAg4"], referer: https://coronadoiscalling.com
[Thu Sep 17 15:37:58.975095 2026] [security2:error] [pid 20162:tid 20415] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/pucci.php"] [unique_id "aqxdtq-O_Kk7aqBvaiGG3gAAAgk"]
[Thu Sep 17 15:37:58.975198 2026] [security2:error] [pid 20162:tid 20415] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/pucci.php"] [unique_id "aqxdtq-O_Kk7aqBvaiGG3gAAAgk"]
[Thu Sep 17 15:37:59.056149 2026] [security2:error] [pid 20162:tid 20306] [client 34.166.234.125:39564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxdt6-O_Kk7aqBvaiGG4AAAAZw"]
[Thu Sep 17 15:37:59.097065 2026] [security2:error] [pid 20162:tid 20321] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxdt6-O_Kk7aqBvaiGG4gAAAas"]
[Thu Sep 17 15:37:59.263507 2026] [security2:error] [pid 20162:tid 20309] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxdt6-O_Kk7aqBvaiGG5QAAAZ8"]
[Thu Sep 17 15:37:59.430455 2026] [security2:error] [pid 20162:tid 20340] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxdt6-O_Kk7aqBvaiGG6AAAAb4"]
[Thu Sep 17 15:37:59.557466 2026] [security2:error] [pid 20162:tid 20378] [client 78.47.98.55:50012] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxdt6-O_Kk7aqBvaiGG6QAAAeQ"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:37:59.565003 2026] [security2:error] [pid 18946:tid 19130] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/puc.php"] [unique_id "aqxdtzqiPMah0Tz_U1O15gAAAUA"]
[Thu Sep 17 15:37:59.565073 2026] [security2:error] [pid 18946:tid 19130] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/puc.php"] [unique_id "aqxdtzqiPMah0Tz_U1O15gAAAUA"]
[Thu Sep 17 15:37:59.590112 2026] [security2:error] [pid 20162:tid 20341] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxdt6-O_Kk7aqBvaiGG6wAAAb8"]
[Thu Sep 17 15:37:59.734842 2026] [security2:error] [pid 20162:tid 20396] [client 34.166.234.125:39570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxdt6-O_Kk7aqBvaiGG7QAAAfY"]
[Thu Sep 17 15:37:59.745738 2026] [security2:error] [pid 20162:tid 20333] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxdt6-O_Kk7aqBvaiGG7gAAAbc"]
[Thu Sep 17 15:37:59.915741 2026] [security2:error] [pid 20162:tid 20362] [client 186.193.194.56:53624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdt6-O_Kk7aqBvaiGG7wAB1BE"]
[Thu Sep 17 15:37:59.918077 2026] [security2:error] [pid 20162:tid 20300] [client 40.81.232.68:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "aqxdt6-O_Kk7aqBvaiGG8QAAAZY"], referer: binance.com
[Thu Sep 17 15:37:59.942116 2026] [security2:error] [pid 20162:tid 20380] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxdt6-O_Kk7aqBvaiGG8gAAAeY"]
[Thu Sep 17 15:38:00.032315 2026] [security2:error] [pid 18946:tid 19109] [client 78.47.98.55:50022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxduDqiPMah0Tz_U1O18AAAASs"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:38:00.100789 2026] [security2:error] [pid 20162:tid 20315] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxduK-O_Kk7aqBvaiGG9QAAAaU"]
[Thu Sep 17 15:38:00.157084 2026] [security2:error] [pid 20162:tid 20313] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/8.php"] [unique_id "aqxduK-O_Kk7aqBvaiGG9wAAAaM"]
[Thu Sep 17 15:38:00.157163 2026] [security2:error] [pid 20162:tid 20313] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/8.php"] [unique_id "aqxduK-O_Kk7aqBvaiGG9wAAAaM"]
[Thu Sep 17 15:38:00.294505 2026] [security2:error] [pid 20162:tid 20330] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxduK-O_Kk7aqBvaiGG-wAAAbQ"]
[Thu Sep 17 15:38:00.406844 2026] [security2:error] [pid 20162:tid 20379] [client 34.95.14.119:58098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxduK-O_Kk7aqBvaiGG_QAAAeU"]
[Thu Sep 17 15:38:00.415178 2026] [security2:error] [pid 20162:tid 20307] [client 34.166.234.125:39574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxduK-O_Kk7aqBvaiGG_gAAAZ0"]
[Thu Sep 17 15:38:00.471052 2026] [security2:error] [pid 18946:tid 19101] [client 14.96.156.146:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxduDqiPMah0Tz_U1O1-QAAASM"]
[Thu Sep 17 15:38:00.473813 2026] [security2:error] [pid 18946:tid 19101] [client 14.96.156.146:54354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxduDqiPMah0Tz_U1O1-QAAASM"]
[Thu Sep 17 15:38:00.538868 2026] [security2:error] [pid 20162:tid 20385] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxduK-O_Kk7aqBvaiGHAAAAAes"]
[Thu Sep 17 15:38:00.717537 2026] [security2:error] [pid 20162:tid 20317] [client 114.198.138.124:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxduK-O_Kk7aqBvaiGHAwAAAac"]
[Thu Sep 17 15:38:00.717689 2026] [security2:error] [pid 20162:tid 20317] [client 114.198.138.124:58608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxduK-O_Kk7aqBvaiGHAwAAAac"]
[Thu Sep 17 15:38:00.717849 2026] [security2:error] [pid 20162:tid 20329] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxduK-O_Kk7aqBvaiGHAgAAAbM"]
[Thu Sep 17 15:38:00.767388 2026] [security2:error] [pid 18946:tid 19148] [client 4.224.45.129:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dev.marinacontroller.com"] [uri "/1.php"] [unique_id "aqxduDqiPMah0Tz_U1O1_QAAAVI"]
[Thu Sep 17 15:38:00.767844 2026] [security2:error] [pid 18946:tid 19148] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/1.php"] [unique_id "aqxduDqiPMah0Tz_U1O1_QAAAVI"]
[Thu Sep 17 15:38:00.767970 2026] [security2:error] [pid 18946:tid 19148] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/1.php"] [unique_id "aqxduDqiPMah0Tz_U1O1_QAAAVI"]
[Thu Sep 17 15:38:00.833845 2026] [security2:error] [pid 18946:tid 19138] [client 34.95.14.119:34618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/info.php"] [unique_id "aqxduDqiPMah0Tz_U1O2AQAAAUg"]
[Thu Sep 17 15:38:00.896182 2026] [security2:error] [pid 20162:tid 20299] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxduK-O_Kk7aqBvaiGHBgAAAZU"]
[Thu Sep 17 15:38:01.072467 2026] [security2:error] [pid 20162:tid 20414] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxdua-O_Kk7aqBvaiGHCAAAAgg"]
[Thu Sep 17 15:38:01.125346 2026] [security2:error] [pid 18946:tid 19188] [client 34.166.234.125:39580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxduTqiPMah0Tz_U1O2CQAAAXo"]
[Thu Sep 17 15:38:01.250881 2026] [security2:error] [pid 20162:tid 20364] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxdua-O_Kk7aqBvaiGHCwAAAdY"]
[Thu Sep 17 15:38:01.261238 2026] [security2:error] [pid 18946:tid 19159] [client 34.95.14.119:34622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/php.php"] [unique_id "aqxduTqiPMah0Tz_U1O2DQAAAV0"]
[Thu Sep 17 15:38:01.368316 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxduTqiPMah0Tz_U1O2EgAAAUU"]
[Thu Sep 17 15:38:01.368446 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxduTqiPMah0Tz_U1O2EgAAAUU"]
[Thu Sep 17 15:38:01.424366 2026] [security2:error] [pid 20162:tid 20293] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxdua-O_Kk7aqBvaiGHDAAAAY8"]
[Thu Sep 17 15:38:01.591767 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxdua-O_Kk7aqBvaiGHDgAAAcI"]
[Thu Sep 17 15:38:01.767076 2026] [security2:error] [pid 18946:tid 19165] [client 34.95.14.119:34632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/i.php"] [unique_id "aqxduTqiPMah0Tz_U1O2HAAAAWM"]
[Thu Sep 17 15:38:01.796340 2026] [security2:error] [pid 20162:tid 20390] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxdua-O_Kk7aqBvaiGHDwAAAfA"]
[Thu Sep 17 15:38:01.813804 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.234.125:39592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxduTqiPMah0Tz_U1O2HQAAAUI"]
[Thu Sep 17 15:38:01.977390 2026] [security2:error] [pid 18946:tid 19182] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/edit.php"] [unique_id "aqxduTqiPMah0Tz_U1O2IAAAAXQ"]
[Thu Sep 17 15:38:01.977482 2026] [security2:error] [pid 18946:tid 19182] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/edit.php"] [unique_id "aqxduTqiPMah0Tz_U1O2IAAAAXQ"]
[Thu Sep 17 15:38:01.978051 2026] [security2:error] [pid 20162:tid 20395] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxdua-O_Kk7aqBvaiGHEQAAAfU"]
[Thu Sep 17 15:38:02.139995 2026] [security2:error] [pid 20162:tid 20418] [client 34.95.14.119:34638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxduq-O_Kk7aqBvaiGHEwAAAgw"]
[Thu Sep 17 15:38:02.164550 2026] [security2:error] [pid 20162:tid 20409] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxduq-O_Kk7aqBvaiGHFAAAAgM"]
[Thu Sep 17 15:38:02.338066 2026] [security2:error] [pid 20162:tid 20377] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxduq-O_Kk7aqBvaiGHFgAAAeM"]
[Thu Sep 17 15:38:02.470996 2026] [security2:error] [pid 20162:tid 20387] [client 34.95.14.119:34644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxduq-O_Kk7aqBvaiGHFwAAAe0"]
[Thu Sep 17 15:38:02.497566 2026] [security2:error] [pid 20162:tid 20325] [client 34.166.234.125:39598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxduq-O_Kk7aqBvaiGHGAAAAa8"]
[Thu Sep 17 15:38:02.506831 2026] [security2:error] [pid 20162:tid 20382] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxduq-O_Kk7aqBvaiGHGQAAAeg"]
[Thu Sep 17 15:38:02.597527 2026] [security2:error] [pid 18946:tid 19097] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/inputs.php"] [unique_id "aqxdujqiPMah0Tz_U1O2LAAAAR8"]
[Thu Sep 17 15:38:02.597621 2026] [security2:error] [pid 18946:tid 19097] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/inputs.php"] [unique_id "aqxdujqiPMah0Tz_U1O2LAAAAR8"]
[Thu Sep 17 15:38:02.617853 2026] [fcgid:warn] [pid 18946:tid 19155] (70014)End of file found: [client 195.96.139.79:52035] mod_fcgid: can't get data from http client
[Thu Sep 17 15:38:02.682511 2026] [security2:error] [pid 20162:tid 20322] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxduq-O_Kk7aqBvaiGHHAAAAaw"]
[Thu Sep 17 15:38:02.712114 2026] [security2:error] [pid 20162:tid 20295] [client 177.44.133.72:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxduq-O_Kk7aqBvaiGHHQAAAZE"]
[Thu Sep 17 15:38:02.712206 2026] [security2:error] [pid 20162:tid 20295] [client 177.44.133.72:59142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxduq-O_Kk7aqBvaiGHHQAAAZE"]
[Thu Sep 17 15:38:02.810395 2026] [security2:error] [pid 20162:tid 20372] [client 34.95.14.119:34650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/test.php"] [unique_id "aqxduq-O_Kk7aqBvaiGHHgAAAd4"]
[Thu Sep 17 15:38:02.879556 2026] [security2:error] [pid 20162:tid 20337] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxduq-O_Kk7aqBvaiGHHwAAAbs"]
[Thu Sep 17 15:38:03.052831 2026] [security2:error] [pid 20162:tid 20415] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxdu6-O_Kk7aqBvaiGHIAAAAgk"]
[Thu Sep 17 15:38:03.188909 2026] [security2:error] [pid 18946:tid 19201] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/classwithtostring.php"] [unique_id "aqxduzqiPMah0Tz_U1O2OAAAAYc"]
[Thu Sep 17 15:38:03.188989 2026] [security2:error] [pid 18946:tid 19201] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/classwithtostring.php"] [unique_id "aqxduzqiPMah0Tz_U1O2OAAAAYc"]
[Thu Sep 17 15:38:03.195867 2026] [security2:error] [pid 20162:tid 20416] [client 34.166.234.125:39600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdu6-O_Kk7aqBvaiGHIgAAAgo"]
[Thu Sep 17 15:38:03.208344 2026] [security2:error] [pid 20162:tid 20318] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxdu6-O_Kk7aqBvaiGHIwAAAag"]
[Thu Sep 17 15:38:03.269133 2026] [security2:error] [pid 20162:tid 20367] [client 34.95.14.119:34664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/p.php"] [unique_id "aqxdu6-O_Kk7aqBvaiGHJAAAAdk"]
[Thu Sep 17 15:38:03.278619 2026] [security2:error] [pid 18946:tid 19086] [client 129.212.238.116:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxduDqiPMah0Tz_U1O2AgABFFM"], referer: http://www.anniechenphotography.com/backup/
[Thu Sep 17 15:38:03.343767 2026] [security2:error] [pid 18946:tid 19106] [client 127.0.0.1:18492] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aqxduzqiPMah0Tz_U1O2OwAAASg"]
[Thu Sep 17 15:38:03.343866 2026] [security2:error] [pid 20162:tid 20375] [client 74.7.244.34:46272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pgo.pfj.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxdu6-O_Kk7aqBvaiGHJQAB4Qk"]
[Thu Sep 17 15:38:03.398379 2026] [security2:error] [pid 20162:tid 20345] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxdu6-O_Kk7aqBvaiGHJgAAAcM"]
[Thu Sep 17 15:38:03.563237 2026] [security2:error] [pid 20162:tid 20366] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxdu6-O_Kk7aqBvaiGHJwAAAdg"]
[Thu Sep 17 15:38:03.601681 2026] [security2:error] [pid 20162:tid 20376] [client 34.95.14.119:34674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxdu6-O_Kk7aqBvaiGHKQAAAeI"]
[Thu Sep 17 15:38:03.735098 2026] [security2:error] [pid 20162:tid 20305] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxdu6-O_Kk7aqBvaiGHKwAAAZs"]
[Thu Sep 17 15:38:03.768219 2026] [security2:error] [pid 18946:tid 19148] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/adminfuns.php"] [unique_id "aqxduzqiPMah0Tz_U1O2RgAAAVI"]
[Thu Sep 17 15:38:03.768304 2026] [security2:error] [pid 18946:tid 19148] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/adminfuns.php"] [unique_id "aqxduzqiPMah0Tz_U1O2RgAAAVI"]
[Thu Sep 17 15:38:03.877730 2026] [security2:error] [pid 18946:tid 19141] [client 34.166.234.125:39604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxduzqiPMah0Tz_U1O2SgAAAUs"]
[Thu Sep 17 15:38:03.934692 2026] [security2:error] [pid 20162:tid 20378] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxdu6-O_Kk7aqBvaiGHLQAAAeQ"]
[Thu Sep 17 15:38:03.999069 2026] [security2:error] [pid 18946:tid 19190] [client 129.212.238.116:32916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxduzqiPMah0Tz_U1O2SwABfHo"], referer: https://www.anniechenphotography.com/backup/
[Thu Sep 17 15:38:04.020772 2026] [security2:error] [pid 18946:tid 19198] [client 34.95.14.119:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxdvDqiPMah0Tz_U1O2UAAAAYQ"]
[Thu Sep 17 15:38:04.075425 2026] [security2:error] [pid 20162:tid 20323] [client 169.58.197.253:51985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxdvK-O_Kk7aqBvaiGHLgAAAa0"], referer: binance.com
[Thu Sep 17 15:38:04.096365 2026] [security2:error] [pid 20162:tid 20393] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxdvK-O_Kk7aqBvaiGHLwAAAfM"]
[Thu Sep 17 15:38:04.158310 2026] [security2:error] [pid 18946:tid 19158] [client 74.7.228.6:33852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "charlesgiraudet.com"] [uri "/robots.txt"] [unique_id "aqxdvDqiPMah0Tz_U1O2VQABXHU"]
[Thu Sep 17 15:38:04.283478 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxdvK-O_Kk7aqBvaiGHMgAAAfY"]
[Thu Sep 17 15:38:04.329706 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/222.php"] [unique_id "aqxdvDqiPMah0Tz_U1O2WQAAAUU"]
[Thu Sep 17 15:38:04.329799 2026] [security2:error] [pid 18946:tid 19135] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/222.php"] [unique_id "aqxdvDqiPMah0Tz_U1O2WQAAAUU"]
[Thu Sep 17 15:38:04.361928 2026] [security2:error] [pid 20162:tid 20333] [client 34.95.14.119:34694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxdvK-O_Kk7aqBvaiGHMwAAAbc"]
[Thu Sep 17 15:38:04.454058 2026] [security2:error] [pid 20162:tid 20300] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxdvK-O_Kk7aqBvaiGHNAAAAZY"]
[Thu Sep 17 15:38:04.497078 2026] [security2:error] [pid 18946:tid 19183] [client 129.212.238.116:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvDqiPMah0Tz_U1O2WgABdWQ"], referer: http://www.anniechenphotography.com/wp/
[Thu Sep 17 15:38:04.565161 2026] [security2:error] [pid 20162:tid 20298] [client 34.166.234.125:43916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxdvK-O_Kk7aqBvaiGHNQAAAZQ"]
[Thu Sep 17 15:38:04.613105 2026] [security2:error] [pid 20162:tid 20315] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxdvK-O_Kk7aqBvaiGHNgAAAaU"]
[Thu Sep 17 15:38:04.634463 2026] [security2:error] [pid 18946:tid 19103] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxdvDqiPMah0Tz_U1O2ZQAAASU"]
[Thu Sep 17 15:38:04.645072 2026] [security2:error] [pid 20162:tid 20353] [client 34.95.14.119:34704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxdvK-O_Kk7aqBvaiGHOAAAAcs"]
[Thu Sep 17 15:38:04.656244 2026] [security2:error] [pid 18946:tid 19193] [client 74.7.241.164:42354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxdvDqiPMah0Tz_U1O2YgABf3w"]
[Thu Sep 17 15:38:04.731198 2026] [security2:error] [pid 18946:tid 19092] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvDqiPMah0Tz_U1O2agAAARo"], referer: https://cpcalendars.znr.kei.mybluehost.me/robots.txt
[Thu Sep 17 15:38:04.734098 2026] [security2:error] [pid 18946:tid 19162] [client 74.7.241.164:42354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvDqiPMah0Tz_U1O2aAABYAg"], referer: https://cpcalendars.znr.kei.mybluehost.me/robots.txt
[Thu Sep 17 15:38:04.794994 2026] [security2:error] [pid 20162:tid 20351] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxdvK-O_Kk7aqBvaiGHOwAAAck"]
[Thu Sep 17 15:38:04.804999 2026] [security2:error] [pid 20162:tid 20374] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvK-O_Kk7aqBvaiGHPAAAAeA"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:04.807188 2026] [security2:error] [pid 18946:tid 19126] [client 74.7.241.164:42354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvDqiPMah0Tz_U1O2cAABPBA"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:04.810407 2026] [security2:error] [pid 18946:tid 19172] [client 129.212.238.116:32916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvDqiPMah0Tz_U1O2ZwABags"], referer: https://www.anniechenphotography.com/wp/
[Thu Sep 17 15:38:04.886257 2026] [security2:error] [pid 20162:tid 20332] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvK-O_Kk7aqBvaiGHQQAAAbY"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:04.887777 2026] [security2:error] [pid 18946:tid 19192] [client 74.7.241.164:42354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvDqiPMah0Tz_U1O2cwABfgc"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:04.905399 2026] [security2:error] [pid 20162:tid 20352] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/BDKR28WP.php"] [unique_id "aqxdvK-O_Kk7aqBvaiGHQgAAAco"]
[Thu Sep 17 15:38:04.905507 2026] [security2:error] [pid 20162:tid 20352] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/BDKR28WP.php"] [unique_id "aqxdvK-O_Kk7aqBvaiGHQgAAAco"]
[Thu Sep 17 15:38:04.949735 2026] [security2:error] [pid 18946:tid 19197] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvDqiPMah0Tz_U1O2fAAAAYM"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:04.951323 2026] [security2:error] [pid 18946:tid 19168] [client 74.7.241.164:42354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvDqiPMah0Tz_U1O2eQABZgw"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:04.963428 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxdvK-O_Kk7aqBvaiGHQwAAAc4"]
[Thu Sep 17 15:38:04.976087 2026] [security2:error] [pid 20162:tid 20384] [client 34.95.14.119:34718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxdvK-O_Kk7aqBvaiGHRQAAAeo"]
[Thu Sep 17 15:38:05.071043 2026] [security2:error] [pid 18946:tid 19128] [client 74.7.241.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvTqiPMah0Tz_U1O2hAAAAT4"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:05.084988 2026] [security2:error] [pid 18946:tid 19115] [client 74.7.241.164:42354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.znr.kei.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxdvDqiPMah0Tz_U1O2gQABMQ8"], referer: https://cpcalendars.znr.kei.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:38:05.149735 2026] [security2:error] [pid 20162:tid 20394] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxdva-O_Kk7aqBvaiGHTAAAAfQ"]
[Thu Sep 17 15:38:05.243115 2026] [security2:error] [pid 20162:tid 20317] [client 34.166.234.125:43930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxdva-O_Kk7aqBvaiGHUAAAAac"]
[Thu Sep 17 15:38:05.301247 2026] [security2:error] [pid 18946:tid 19096] [client 129.212.238.116:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2iQABHgE"], referer: http://www.anniechenphotography.com/new/
[Thu Sep 17 15:38:05.333906 2026] [security2:error] [pid 20162:tid 20414] [client 34.95.14.119:34722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxdva-O_Kk7aqBvaiGHVQAAAgg"]
[Thu Sep 17 15:38:05.384696 2026] [security2:error] [pid 20162:tid 20383] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxdva-O_Kk7aqBvaiGHWAAAAek"]
[Thu Sep 17 15:38:05.429380 2026] [security2:error] [pid 18946:tid 19125] [client 162.241.226.11:37824] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2kAAAATs"]
[Thu Sep 17 15:38:05.492978 2026] [security2:error] [pid 18946:tid 19195] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2lwAAAYE"]
[Thu Sep 17 15:38:05.493063 2026] [security2:error] [pid 18946:tid 19195] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2lwAAAYE"]
[Thu Sep 17 15:38:05.508247 2026] [security2:error] [pid 20162:tid 20397] [client 136.158.61.34:18988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdva-O_Kk7aqBvaiGHXAAAAfc"]
[Thu Sep 17 15:38:05.508336 2026] [security2:error] [pid 20162:tid 20397] [client 136.158.61.34:18988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdva-O_Kk7aqBvaiGHXAAAAfc"]
[Thu Sep 17 15:38:05.543242 2026] [security2:error] [pid 20162:tid 20377] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxdva-O_Kk7aqBvaiGHXQAAAeM"]
[Thu Sep 17 15:38:05.703898 2026] [security2:error] [pid 20162:tid 20386] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxdva-O_Kk7aqBvaiGHXwAAAew"]
[Thu Sep 17 15:38:05.770409 2026] [security2:error] [pid 20162:tid 20361] [client 34.95.14.119:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxdva-O_Kk7aqBvaiGHYAAAAdM"]
[Thu Sep 17 15:38:05.870924 2026] [security2:error] [pid 20162:tid 20295] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxdva-O_Kk7aqBvaiGHYQAAAZE"]
[Thu Sep 17 15:38:05.922603 2026] [security2:error] [pid 18946:tid 19099] [client 143.105.152.240:54035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2ogAAASE"]
[Thu Sep 17 15:38:05.926395 2026] [security2:error] [pid 18946:tid 19099] [client 143.105.152.240:54035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2ogAAASE"]
[Thu Sep 17 15:38:05.927758 2026] [security2:error] [pid 18946:tid 19157] [client 34.166.234.125:43938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2owAAAVs"]
[Thu Sep 17 15:38:05.999808 2026] [security2:error] [pid 18946:tid 19103] [client 129.212.238.116:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2oQABJTQ"], referer: http://www.anniechenphotography.com/wordpress/
[Thu Sep 17 15:38:06.027440 2026] [security2:error] [pid 20162:tid 20365] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxdvq-O_Kk7aqBvaiGHZAAAAdc"]
[Thu Sep 17 15:38:06.050455 2026] [security2:error] [pid 18946:tid 19180] [client 138.204.96.219:56539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdvTqiPMah0Tz_U1O2pQABcho"]
[Thu Sep 17 15:38:06.079674 2026] [security2:error] [pid 18946:tid 19129] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/simple.php"] [unique_id "aqxdvjqiPMah0Tz_U1O2qQAAAT8"]
[Thu Sep 17 15:38:06.079751 2026] [security2:error] [pid 18946:tid 19129] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/simple.php"] [unique_id "aqxdvjqiPMah0Tz_U1O2qQAAAT8"]
[Thu Sep 17 15:38:06.184473 2026] [security2:error] [pid 20162:tid 20350] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxdvq-O_Kk7aqBvaiGHaAAAAcg"]
[Thu Sep 17 15:38:06.267196 2026] [security2:error] [pid 20162:tid 20416] [client 34.95.14.119:34740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxdvq-O_Kk7aqBvaiGHagAAAgo"]
[Thu Sep 17 15:38:06.284123 2026] [security2:error] [pid 20162:tid 20413] [client 103.61.184.148:65387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdvq-O_Kk7aqBvaiGHawAAAgc"]
[Thu Sep 17 15:38:06.284210 2026] [security2:error] [pid 20162:tid 20413] [client 103.61.184.148:65387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdvq-O_Kk7aqBvaiGHawAAAgc"]
[Thu Sep 17 15:38:06.307736 2026] [security2:error] [pid 18946:tid 19162] [client 129.212.238.116:32916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvjqiPMah0Tz_U1O2rQABYBQ"], referer: https://www.anniechenphotography.com/wordpress/
[Thu Sep 17 15:38:06.358302 2026] [security2:error] [pid 20162:tid 20318] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxdvq-O_Kk7aqBvaiGHbAAAAag"]
[Thu Sep 17 15:38:06.467718 2026] [security2:error] [pid 18946:tid 19134] [client 79.116.89.151:64285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdvjqiPMah0Tz_U1O2uQAAAUQ"]
[Thu Sep 17 15:38:06.467813 2026] [security2:error] [pid 18946:tid 19134] [client 79.116.89.151:64285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdvjqiPMah0Tz_U1O2uQAAAUQ"]
[Thu Sep 17 15:38:06.573934 2026] [security2:error] [pid 20162:tid 20303] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxdvq-O_Kk7aqBvaiGHcQAAAZk"]
[Thu Sep 17 15:38:06.609451 2026] [security2:error] [pid 18946:tid 19143] [client 34.166.234.125:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdvjqiPMah0Tz_U1O2vQAAAU0"]
[Thu Sep 17 15:38:06.639028 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.14.119:34746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxdvq-O_Kk7aqBvaiGHcwAAAZs"]
[Thu Sep 17 15:38:06.663425 2026] [security2:error] [pid 20162:tid 20340] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/chosen.php"] [unique_id "aqxdvq-O_Kk7aqBvaiGHdAAAAb4"]
[Thu Sep 17 15:38:06.663520 2026] [security2:error] [pid 20162:tid 20340] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/chosen.php"] [unique_id "aqxdvq-O_Kk7aqBvaiGHdAAAAb4"]
[Thu Sep 17 15:38:06.784988 2026] [security2:error] [pid 20162:tid 20373] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxdvq-O_Kk7aqBvaiGHdgAAAd8"]
[Thu Sep 17 15:38:06.806319 2026] [security2:error] [pid 18946:tid 19120] [client 129.212.238.116:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvjqiPMah0Tz_U1O2wQABNhY"], referer: http://www.anniechenphotography.com/old/
[Thu Sep 17 15:38:06.942872 2026] [security2:error] [pid 20162:tid 20396] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxdvq-O_Kk7aqBvaiGHeAAAAfY"]
[Thu Sep 17 15:38:07.011790 2026] [security2:error] [pid 18946:tid 19083] [client 34.95.14.119:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxdvzqiPMah0Tz_U1O2yQAAARE"]
[Thu Sep 17 15:38:07.099344 2026] [security2:error] [pid 20162:tid 20300] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxdv6-O_Kk7aqBvaiGHeQAAAZY"]
[Thu Sep 17 15:38:07.126154 2026] [security2:error] [pid 18946:tid 19082] [client 129.212.238.116:32916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvzqiPMah0Tz_U1O2yAABECY"], referer: https://www.anniechenphotography.com/old/
[Thu Sep 17 15:38:07.230841 2026] [security2:error] [pid 20162:tid 20298] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/als.php"] [unique_id "aqxdv6-O_Kk7aqBvaiGHewAAAZQ"]
[Thu Sep 17 15:38:07.230929 2026] [security2:error] [pid 20162:tid 20298] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/als.php"] [unique_id "aqxdv6-O_Kk7aqBvaiGHewAAAZQ"]
[Thu Sep 17 15:38:07.293888 2026] [security2:error] [pid 18946:tid 19100] [client 34.166.234.125:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxdvzqiPMah0Tz_U1O21QAAASI"]
[Thu Sep 17 15:38:07.311243 2026] [security2:error] [pid 18946:tid 19096] [client 34.95.14.119:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxdvzqiPMah0Tz_U1O21wAAAR4"]
[Thu Sep 17 15:38:07.425608 2026] [security2:error] [pid 18946:tid 19101] [client 210.222.43.21:61035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxdvzqiPMah0Tz_U1O20wAAASM"], referer: http://talent-in-borders.com/site
[Thu Sep 17 15:38:07.631278 2026] [security2:error] [pid 18946:tid 19189] [client 129.212.238.116:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvzqiPMah0Tz_U1O23gABewU"], referer: http://www.anniechenphotography.com/blog/
[Thu Sep 17 15:38:07.641955 2026] [security2:error] [pid 20162:tid 20326] [client 34.95.14.119:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxdv6-O_Kk7aqBvaiGHhgAAAbA"]
[Thu Sep 17 15:38:07.690060 2026] [security2:error] [pid 20162:tid 20356] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxdv6-O_Kk7aqBvaiGHhwAAAc4"]
[Thu Sep 17 15:38:07.807009 2026] [security2:error] [pid 18946:tid 19156] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxdvzqiPMah0Tz_U1O25gAAAVo"]
[Thu Sep 17 15:38:07.807127 2026] [security2:error] [pid 18946:tid 19156] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxdvzqiPMah0Tz_U1O25gAAAVo"]
[Thu Sep 17 15:38:07.894148 2026] [security2:error] [pid 18946:tid 19158] [client 34.95.14.119:46652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxdvzqiPMah0Tz_U1O27AAAAVw"]
[Thu Sep 17 15:38:07.931071 2026] [security2:error] [pid 20162:tid 20310] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxdv6-O_Kk7aqBvaiGHjAAAAaA"]
[Thu Sep 17 15:38:07.949842 2026] [security2:error] [pid 18946:tid 19157] [client 129.212.238.116:32916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anniechenphotography.com"] [uri "/index.php"] [unique_id "aqxdvzqiPMah0Tz_U1O26gABWzE"], referer: https://www.anniechenphotography.com/blog/
[Thu Sep 17 15:38:07.971928 2026] [security2:error] [pid 18946:tid 19183] [client 34.166.234.125:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.234.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldi.any.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxdvzqiPMah0Tz_U1O27gAAAXU"]
[Thu Sep 17 15:38:08.113585 2026] [security2:error] [pid 20162:tid 20401] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxdwK-O_Kk7aqBvaiGHjwAAAfs"]
[Thu Sep 17 15:38:08.282825 2026] [security2:error] [pid 20162:tid 20336] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxdwK-O_Kk7aqBvaiGHkQAAAbo"]
[Thu Sep 17 15:38:08.362426 2026] [security2:error] [pid 18946:tid 19162] [client 34.95.14.119:46656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxdwDqiPMah0Tz_U1O2-QAAAWA"]
[Thu Sep 17 15:38:08.412505 2026] [security2:error] [pid 20162:tid 20357] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/f35.php"] [unique_id "aqxdwK-O_Kk7aqBvaiGHkgAAAc8"]
[Thu Sep 17 15:38:08.412614 2026] [security2:error] [pid 20162:tid 20357] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/f35.php"] [unique_id "aqxdwK-O_Kk7aqBvaiGHkgAAAc8"]
[Thu Sep 17 15:38:08.451926 2026] [security2:error] [pid 20162:tid 20400] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxdwK-O_Kk7aqBvaiGHkwAAAfo"]
[Thu Sep 17 15:38:08.627376 2026] [security2:error] [pid 20162:tid 20408] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxdwK-O_Kk7aqBvaiGHlAAAAgI"]
[Thu Sep 17 15:38:08.633706 2026] [security2:error] [pid 18946:tid 19127] [client 34.95.14.119:46662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxdwDqiPMah0Tz_U1O3AAAAAT0"]
[Thu Sep 17 15:38:08.805561 2026] [security2:error] [pid 20162:tid 20398] [client 34.154.220.126:34246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxdwK-O_Kk7aqBvaiGHlgAAAfg"]
[Thu Sep 17 15:38:08.990500 2026] [security2:error] [pid 18946:tid 19081] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/aaa.php"] [unique_id "aqxdwDqiPMah0Tz_U1O3CgAAAQ8"]
[Thu Sep 17 15:38:08.990607 2026] [security2:error] [pid 18946:tid 19081] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/aaa.php"] [unique_id "aqxdwDqiPMah0Tz_U1O3CgAAAQ8"]
[Thu Sep 17 15:38:09.063610 2026] [security2:error] [pid 18946:tid 19168] [client 34.95.14.119:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxdwTqiPMah0Tz_U1O3DwAAAWY"]
[Thu Sep 17 15:38:09.238422 2026] [security2:error] [pid 18946:tid 19128] [client 34.122.173.216:12160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdwTqiPMah0Tz_U1O3EAABPic"]
[Thu Sep 17 15:38:09.353601 2026] [security2:error] [pid 18946:tid 19083] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxdwTqiPMah0Tz_U1O3EwAAARE"]
[Thu Sep 17 15:38:09.357090 2026] [security2:error] [pid 18946:tid 19161] [client 34.122.173.216:12160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdwTqiPMah0Tz_U1O3EgABXzw"]
[Thu Sep 17 15:38:09.392068 2026] [security2:error] [pid 18946:tid 19196] [client 34.95.14.119:46682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxdwTqiPMah0Tz_U1O3FAAAAYI"]
[Thu Sep 17 15:38:09.541814 2026] [security2:error] [pid 20162:tid 20410] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/gecko.php"] [unique_id "aqxdwa-O_Kk7aqBvaiGHnQAAAgQ"]
[Thu Sep 17 15:38:09.541908 2026] [security2:error] [pid 20162:tid 20410] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/gecko.php"] [unique_id "aqxdwa-O_Kk7aqBvaiGHnQAAAgQ"]
[Thu Sep 17 15:38:09.561700 2026] [security2:error] [pid 20162:tid 20404] [client 40.81.232.68:64725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "aqxdwa-O_Kk7aqBvaiGHnwAAAf4"], referer: binance.com
[Thu Sep 17 15:38:09.591068 2026] [security2:error] [pid 18946:tid 19100] [client 34.122.173.216:12160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxdwTqiPMah0Tz_U1O3GAABIjA"]
[Thu Sep 17 15:38:09.618626 2026] [security2:error] [pid 18946:tid 19141] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxdwTqiPMah0Tz_U1O3GQAAAUs"]
[Thu Sep 17 15:38:09.785021 2026] [security2:error] [pid 20162:tid 20409] [client 34.95.14.119:46696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxdwa-O_Kk7aqBvaiGHowAAAgM"]
[Thu Sep 17 15:38:09.817605 2026] [security2:error] [pid 18946:tid 19080] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxdwTqiPMah0Tz_U1O3HQAAAQ4"]
[Thu Sep 17 15:38:09.847059 2026] [security2:error] [pid 18946:tid 19181] [client 164.163.15.222:58754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdwTqiPMah0Tz_U1O3HAABc3k"]
[Thu Sep 17 15:38:09.985612 2026] [security2:error] [pid 18946:tid 19084] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxdwTqiPMah0Tz_U1O3IAAAARI"]
[Thu Sep 17 15:38:10.094453 2026] [security2:error] [pid 18946:tid 19076] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/xiugai.php"] [unique_id "aqxdwjqiPMah0Tz_U1O3IgAAAQo"]
[Thu Sep 17 15:38:10.094561 2026] [security2:error] [pid 18946:tid 19076] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/xiugai.php"] [unique_id "aqxdwjqiPMah0Tz_U1O3IgAAAQo"]
[Thu Sep 17 15:38:10.145694 2026] [security2:error] [pid 18946:tid 19152] [client 34.95.14.119:46708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxdwjqiPMah0Tz_U1O3JAAAAVY"]
[Thu Sep 17 15:38:10.146551 2026] [security2:error] [pid 18946:tid 19189] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxdwjqiPMah0Tz_U1O3IwAAAXs"]
[Thu Sep 17 15:38:10.314569 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxdwjqiPMah0Tz_U1O3JgAAAVg"]
[Thu Sep 17 15:38:10.466524 2026] [security2:error] [pid 18946:tid 19102] [client 34.95.14.119:46722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxdwjqiPMah0Tz_U1O3KgAAASQ"]
[Thu Sep 17 15:38:10.488074 2026] [security2:error] [pid 18946:tid 19149] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxdwjqiPMah0Tz_U1O3KwAAAVM"]
[Thu Sep 17 15:38:10.660608 2026] [security2:error] [pid 18946:tid 19129] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxdwjqiPMah0Tz_U1O3MQAAAT8"]
[Thu Sep 17 15:38:10.667750 2026] [security2:error] [pid 18946:tid 19180] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/inx.php"] [unique_id "aqxdwjqiPMah0Tz_U1O3MgAAAXI"]
[Thu Sep 17 15:38:10.667827 2026] [security2:error] [pid 18946:tid 19180] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/inx.php"] [unique_id "aqxdwjqiPMah0Tz_U1O3MgAAAXI"]
[Thu Sep 17 15:38:10.773412 2026] [security2:error] [pid 18946:tid 19178] [client 34.95.14.119:46724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxdwjqiPMah0Tz_U1O3MwAAAXA"]
[Thu Sep 17 15:38:10.831311 2026] [security2:error] [pid 18946:tid 19117] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxdwjqiPMah0Tz_U1O3NAAAATM"]
[Thu Sep 17 15:38:11.010425 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxdwzqiPMah0Tz_U1O3OAAAAWA"]
[Thu Sep 17 15:38:11.081449 2026] [security2:error] [pid 18946:tid 19185] [client 34.95.14.119:46728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxdwzqiPMah0Tz_U1O3PAAAAXc"]
[Thu Sep 17 15:38:11.153653 2026] [security2:error] [pid 18946:tid 19176] [client 2.104.60.34:45333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cranberryadventures.com"] [uri "/.env"] [unique_id "aqxdwzqiPMah0Tz_U1O3PgAAAW4"]
[Thu Sep 17 15:38:11.166569 2026] [security2:error] [pid 18946:tid 19107] [client 14.96.156.146:55004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3PwAAASk"]
[Thu Sep 17 15:38:11.166688 2026] [security2:error] [pid 18946:tid 19107] [client 14.96.156.146:55004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3PwAAASk"]
[Thu Sep 17 15:38:11.192254 2026] [security2:error] [pid 18946:tid 19118] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxdwzqiPMah0Tz_U1O3QAAAATQ"]
[Thu Sep 17 15:38:11.248732 2026] [security2:error] [pid 18946:tid 19155] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/11.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3QQAAAVk"]
[Thu Sep 17 15:38:11.248813 2026] [security2:error] [pid 18946:tid 19155] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/11.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3QQAAAVk"]
[Thu Sep 17 15:38:11.350650 2026] [security2:error] [pid 18946:tid 19146] [client 34.95.14.119:46734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxdwzqiPMah0Tz_U1O3RgAAAVA"]
[Thu Sep 17 15:38:11.351194 2026] [security2:error] [pid 18946:tid 19140] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxdwzqiPMah0Tz_U1O3RQAAAUo"]
[Thu Sep 17 15:38:11.374586 2026] [security2:error] [pid 18946:tid 19193] [client 114.198.138.124:59247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3RwAAAX8"]
[Thu Sep 17 15:38:11.374686 2026] [security2:error] [pid 18946:tid 19193] [client 114.198.138.124:59247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3RwAAAX8"]
[Thu Sep 17 15:38:11.528805 2026] [security2:error] [pid 18946:tid 19203] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxdwzqiPMah0Tz_U1O3SwAAAYk"]
[Thu Sep 17 15:38:11.645410 2026] [security2:error] [pid 18946:tid 19171] [client 34.95.14.119:46738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxdwzqiPMah0Tz_U1O3UAAAAWk"]
[Thu Sep 17 15:38:11.688449 2026] [security2:error] [pid 18946:tid 19170] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxdwzqiPMah0Tz_U1O3UQAAAWg"]
[Thu Sep 17 15:38:11.843081 2026] [security2:error] [pid 18946:tid 19106] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/File.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3VQAAASg"]
[Thu Sep 17 15:38:11.843165 2026] [security2:error] [pid 18946:tid 19106] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/File.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3VQAAASg"]
[Thu Sep 17 15:38:11.868801 2026] [security2:error] [pid 18946:tid 19174] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxdwzqiPMah0Tz_U1O3VgAAAWw"]
[Thu Sep 17 15:38:11.993677 2026] [security2:error] [pid 18946:tid 19080] [client 206.189.130.172:46036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ravenindustries.net"] [uri "/index.php"] [unique_id "aqxdwzqiPMah0Tz_U1O3WQAAAQ4"]
[Thu Sep 17 15:38:12.025702 2026] [security2:error] [pid 18946:tid 19181] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxdxDqiPMah0Tz_U1O3WgAAAXM"]
[Thu Sep 17 15:38:12.027937 2026] [security2:error] [pid 18946:tid 19119] [client 34.95.14.119:46754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxdxDqiPMah0Tz_U1O3WwAAATU"]
[Thu Sep 17 15:38:12.170872 2026] [security2:error] [pid 20162:tid 20341] [client 169.58.197.253:52504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxdxK-O_Kk7aqBvaiGHvwAAAb8"], referer: binance.com
[Thu Sep 17 15:38:12.211230 2026] [security2:error] [pid 18946:tid 19189] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxdxDqiPMah0Tz_U1O3XgAAAXs"]
[Thu Sep 17 15:38:12.321527 2026] [security2:error] [pid 18946:tid 19096] [client 114.119.147.32:61807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toristocco.com"] [uri "/category/happiness/"] [unique_id "aqxdxDqiPMah0Tz_U1O3YQAAAR4"], referer: https://toristocco.com/category/chicago
[Thu Sep 17 15:38:12.363790 2026] [security2:error] [pid 18946:tid 19186] [client 34.95.14.119:46766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxdxDqiPMah0Tz_U1O3YgAAAXg"]
[Thu Sep 17 15:38:12.384961 2026] [security2:error] [pid 18946:tid 19087] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxdxDqiPMah0Tz_U1O3YwAAARU"]
[Thu Sep 17 15:38:12.427783 2026] [security2:error] [pid 20162:tid 20396] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aqxdxK-O_Kk7aqBvaiGHxAAAAfY"]
[Thu Sep 17 15:38:12.427875 2026] [security2:error] [pid 20162:tid 20396] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aqxdxK-O_Kk7aqBvaiGHxAAAAfY"]
[Thu Sep 17 15:38:12.554239 2026] [security2:error] [pid 18946:tid 19158] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxdxDqiPMah0Tz_U1O3agAAAVw"]
[Thu Sep 17 15:38:12.703576 2026] [security2:error] [pid 18946:tid 19094] [client 34.95.14.119:46776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxdxDqiPMah0Tz_U1O3bAAAARw"]
[Thu Sep 17 15:38:12.763287 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxdxDqiPMah0Tz_U1O3bgAAAUY"]
[Thu Sep 17 15:38:12.900384 2026] [security2:error] [pid 18946:tid 19112] [client 165.16.171.246:35092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdxDqiPMah0Tz_U1O3bwABLkg"]
[Thu Sep 17 15:38:12.927368 2026] [security2:error] [pid 18946:tid 19122] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxdxDqiPMah0Tz_U1O3cgAAATg"]
[Thu Sep 17 15:38:12.977865 2026] [security2:error] [pid 18946:tid 19132] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aqxdxDqiPMah0Tz_U1O3dwAAAUI"]
[Thu Sep 17 15:38:12.977884 2026] [security2:error] [pid 18946:tid 19133] [client 34.95.14.119:46788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxdxDqiPMah0Tz_U1O3eAAAAUM"]
[Thu Sep 17 15:38:12.977968 2026] [security2:error] [pid 18946:tid 19132] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aqxdxDqiPMah0Tz_U1O3dwAAAUI"]
[Thu Sep 17 15:38:13.093647 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxdxTqiPMah0Tz_U1O3egAAAR8"]
[Thu Sep 17 15:38:13.271205 2026] [security2:error] [pid 18946:tid 19090] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxdxTqiPMah0Tz_U1O3fgAAARg"]
[Thu Sep 17 15:38:13.275989 2026] [security2:error] [pid 20162:tid 20304] [client 34.95.14.119:46802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxdxa-O_Kk7aqBvaiGHzgAAAZo"]
[Thu Sep 17 15:38:13.331996 2026] [security2:error] [pid 18946:tid 19178] [client 177.44.133.72:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdxTqiPMah0Tz_U1O3gQAAAXA"]
[Thu Sep 17 15:38:13.332094 2026] [security2:error] [pid 18946:tid 19178] [client 177.44.133.72:59802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxdxTqiPMah0Tz_U1O3gQAAAXA"]
[Thu Sep 17 15:38:13.438939 2026] [security2:error] [pid 18946:tid 19121] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxdxTqiPMah0Tz_U1O3hQAAATc"]
[Thu Sep 17 15:38:13.545979 2026] [security2:error] [pid 20162:tid 20332] [client 34.95.14.119:46806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxdxa-O_Kk7aqBvaiGH0QAAAbY"]
[Thu Sep 17 15:38:13.550746 2026] [security2:error] [pid 18946:tid 19197] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aqxdxTqiPMah0Tz_U1O3iwAAAYM"]
[Thu Sep 17 15:38:13.550826 2026] [security2:error] [pid 18946:tid 19197] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aqxdxTqiPMah0Tz_U1O3iwAAAYM"]
[Thu Sep 17 15:38:13.598834 2026] [security2:error] [pid 18946:tid 19120] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxdxTqiPMah0Tz_U1O3jAAAATY"]
[Thu Sep 17 15:38:13.640517 2026] [security2:error] [pid 18946:tid 19146] [client 103.142.69.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxdxTqiPMah0Tz_U1O3hwAAAVA"], referer: https://kslandscaping.net/blog
[Thu Sep 17 15:38:13.761651 2026] [security2:error] [pid 18946:tid 19111] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxdxTqiPMah0Tz_U1O3kQAAAS0"]
[Thu Sep 17 15:38:13.904121 2026] [security2:error] [pid 18946:tid 19115] [client 34.95.14.119:46820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxdxTqiPMah0Tz_U1O3kgAAATE"]
[Thu Sep 17 15:38:13.923903 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxdxTqiPMah0Tz_U1O3lAAAAQ8"]
[Thu Sep 17 15:38:14.089918 2026] [security2:error] [pid 18946:tid 19106] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxdxjqiPMah0Tz_U1O3lwAAASg"]
[Thu Sep 17 15:38:14.124088 2026] [security2:error] [pid 18946:tid 19100] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aqxdxjqiPMah0Tz_U1O3mAAAASI"]
[Thu Sep 17 15:38:14.124177 2026] [security2:error] [pid 18946:tid 19100] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aqxdxjqiPMah0Tz_U1O3mAAAASI"]
[Thu Sep 17 15:38:14.215068 2026] [security2:error] [pid 18946:tid 19174] [client 34.95.14.119:46836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxdxjqiPMah0Tz_U1O3mgAAAWw"]
[Thu Sep 17 15:38:14.273854 2026] [security2:error] [pid 18946:tid 19198] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxdxjqiPMah0Tz_U1O3mwAAAYQ"]
[Thu Sep 17 15:38:14.432646 2026] [security2:error] [pid 18946:tid 19119] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxdxjqiPMah0Tz_U1O3nQAAATU"]
[Thu Sep 17 15:38:14.578293 2026] [security2:error] [pid 18946:tid 19084] [client 34.95.14.119:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxdxjqiPMah0Tz_U1O3oQAAARI"]
[Thu Sep 17 15:38:14.583027 2026] [security2:error] [pid 18946:tid 19130] [client 66.249.74.33:46980] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "xrx.sgh.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxdxjqiPMah0Tz_U1O3ogAAAUA"]
[Thu Sep 17 15:38:14.591205 2026] [security2:error] [pid 18946:tid 19152] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxdxjqiPMah0Tz_U1O3owAAAVY"]
[Thu Sep 17 15:38:14.708429 2026] [security2:error] [pid 18946:tid 19188] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aqxdxjqiPMah0Tz_U1O3pQAAAXo"]
[Thu Sep 17 15:38:14.708514 2026] [security2:error] [pid 18946:tid 19188] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aqxdxjqiPMah0Tz_U1O3pQAAAXo"]
[Thu Sep 17 15:38:14.790528 2026] [security2:error] [pid 18946:tid 19114] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxdxjqiPMah0Tz_U1O3qQAAATA"]
[Thu Sep 17 15:38:14.903494 2026] [security2:error] [pid 20162:tid 20399] [client 34.95.14.119:46856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxdxq-O_Kk7aqBvaiGH3wAAAfk"]
[Thu Sep 17 15:38:14.951407 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxdxjqiPMah0Tz_U1O3qwAAAVg"]
[Thu Sep 17 15:38:15.111045 2026] [security2:error] [pid 18946:tid 19102] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxdxzqiPMah0Tz_U1O3sAAAASQ"]
[Thu Sep 17 15:38:15.280092 2026] [security2:error] [pid 18946:tid 19137] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxdxzqiPMah0Tz_U1O3sQAAAUc"]
[Thu Sep 17 15:38:15.288555 2026] [security2:error] [pid 18946:tid 19149] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aqxdxzqiPMah0Tz_U1O3sgAAAVM"]
[Thu Sep 17 15:38:15.288649 2026] [security2:error] [pid 18946:tid 19149] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aqxdxzqiPMah0Tz_U1O3sgAAAVM"]
[Thu Sep 17 15:38:15.308756 2026] [security2:error] [pid 20162:tid 20317] [client 34.95.14.119:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxdx6-O_Kk7aqBvaiGH6AAAAac"]
[Thu Sep 17 15:38:15.436678 2026] [security2:error] [pid 18946:tid 19142] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxdxzqiPMah0Tz_U1O3tAAAAUw"]
[Thu Sep 17 15:38:15.600112 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxdxzqiPMah0Tz_U1O3uAAAAYY"]
[Thu Sep 17 15:38:15.692116 2026] [security2:error] [pid 18946:tid 19183] [client 34.95.14.119:46874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxdxzqiPMah0Tz_U1O3uQAAAXU"]
[Thu Sep 17 15:38:15.760348 2026] [security2:error] [pid 18946:tid 19166] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxdxzqiPMah0Tz_U1O3ugAAAWQ"]
[Thu Sep 17 15:38:15.880076 2026] [security2:error] [pid 18946:tid 19162] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/media.php"] [unique_id "aqxdxzqiPMah0Tz_U1O3vAAAAWA"]
[Thu Sep 17 15:38:15.880166 2026] [security2:error] [pid 18946:tid 19162] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/media.php"] [unique_id "aqxdxzqiPMah0Tz_U1O3vAAAAWA"]
[Thu Sep 17 15:38:15.919112 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxdxzqiPMah0Tz_U1O3vQAAAV0"]
[Thu Sep 17 15:38:16.079295 2026] [security2:error] [pid 18946:tid 19098] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxdyDqiPMah0Tz_U1O3xwAAASA"]
[Thu Sep 17 15:38:16.102693 2026] [security2:error] [pid 20162:tid 20418] [client 34.95.14.119:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxdyK-O_Kk7aqBvaiGH-QAAAgw"]
[Thu Sep 17 15:38:16.261705 2026] [security2:error] [pid 18946:tid 19092] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxdyDqiPMah0Tz_U1O31QAAARo"]
[Thu Sep 17 15:38:16.435683 2026] [security2:error] [pid 18946:tid 19140] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxdyDqiPMah0Tz_U1O33AAAAUo"]
[Thu Sep 17 15:38:16.457617 2026] [security2:error] [pid 18946:tid 19178] [client 34.95.14.119:46882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zhh.eek.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxdyDqiPMah0Tz_U1O33QAAAXA"]
[Thu Sep 17 15:38:16.464442 2026] [security2:error] [pid 18946:tid 19169] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/inso.php"] [unique_id "aqxdyDqiPMah0Tz_U1O33gAAAWc"]
[Thu Sep 17 15:38:16.464561 2026] [security2:error] [pid 18946:tid 19169] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/inso.php"] [unique_id "aqxdyDqiPMah0Tz_U1O33gAAAWc"]
[Thu Sep 17 15:38:16.583491 2026] [security2:error] [pid 20162:tid 20368] [client 143.105.152.240:44876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdyK-O_Kk7aqBvaiGIBQAAAdo"]
[Thu Sep 17 15:38:16.591244 2026] [security2:error] [pid 20162:tid 20368] [client 143.105.152.240:44876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxdyK-O_Kk7aqBvaiGIBQAAAdo"]
[Thu Sep 17 15:38:16.601008 2026] [security2:error] [pid 18946:tid 19146] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxdyDqiPMah0Tz_U1O34wAAAVA"]
[Thu Sep 17 15:38:16.764350 2026] [security2:error] [pid 18946:tid 19171] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxdyDqiPMah0Tz_U1O35gAAAWk"]
[Thu Sep 17 15:38:16.797410 2026] [security2:error] [pid 18946:tid 19147] [client 189.7.227.116:25698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "meatlessmusings.com"] [uri "/index.php"] [unique_id "aqxdxzqiPMah0Tz_U1O3rwAAAVE"], referer: https://meatlessmusings.com/
[Thu Sep 17 15:38:16.940558 2026] [security2:error] [pid 18946:tid 19196] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxdyDqiPMah0Tz_U1O37AAAAYI"]
[Thu Sep 17 15:38:17.037351 2026] [security2:error] [pid 18946:tid 19194] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/shiny.php"] [unique_id "aqxdyTqiPMah0Tz_U1O39AAAAYA"]
[Thu Sep 17 15:38:17.037453 2026] [security2:error] [pid 18946:tid 19194] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/shiny.php"] [unique_id "aqxdyTqiPMah0Tz_U1O39AAAAYA"]
[Thu Sep 17 15:38:17.111873 2026] [security2:error] [pid 18946:tid 19101] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxdyTqiPMah0Tz_U1O39wAAASM"]
[Thu Sep 17 15:38:17.132033 2026] [security2:error] [pid 18946:tid 19081] [client 79.116.89.151:64913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdyTqiPMah0Tz_U1O3-AAAAQ8"]
[Thu Sep 17 15:38:17.132310 2026] [security2:error] [pid 18946:tid 19081] [client 79.116.89.151:64913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxdyTqiPMah0Tz_U1O3-AAAAQ8"]
[Thu Sep 17 15:38:17.280323 2026] [security2:error] [pid 18946:tid 19116] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxdyTqiPMah0Tz_U1O3_QAAATI"]
[Thu Sep 17 15:38:17.433903 2026] [security2:error] [pid 18946:tid 19155] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxdyTqiPMah0Tz_U1O4AQAAAVk"]
[Thu Sep 17 15:38:17.592173 2026] [security2:error] [pid 18946:tid 19138] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxdyTqiPMah0Tz_U1O4BgAAAUg"]
[Thu Sep 17 15:38:17.599028 2026] [security2:error] [pid 20162:tid 20393] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/403dd.php"] [unique_id "aqxdya-O_Kk7aqBvaiGIFgAAAfM"]
[Thu Sep 17 15:38:17.599117 2026] [security2:error] [pid 20162:tid 20393] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/403dd.php"] [unique_id "aqxdya-O_Kk7aqBvaiGIFgAAAfM"]
[Thu Sep 17 15:38:17.759139 2026] [security2:error] [pid 18946:tid 19144] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxdyTqiPMah0Tz_U1O4CQAAAU4"]
[Thu Sep 17 15:38:17.899947 2026] [security2:error] [pid 20162:tid 20347] [client 24.140.202.61:29137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brownsdailydose.com"] [uri "/xmlrpc.php"] [unique_id "aqxdx6-O_Kk7aqBvaiGH8gABxUE"]
[Thu Sep 17 15:38:17.917185 2026] [security2:error] [pid 18946:tid 19200] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxdyTqiPMah0Tz_U1O4EAAAAYY"]
[Thu Sep 17 15:38:17.992851 2026] [security2:error] [pid 20162:tid 20347] [client 24.140.202.61:29137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brownsdailydose.com"] [uri "/xmlrpc.php"] [unique_id "aqxdx6-O_Kk7aqBvaiGH9AABxSk"]
[Thu Sep 17 15:38:18.074325 2026] [security2:error] [pid 18946:tid 19145] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxdyjqiPMah0Tz_U1O4FQAAAU8"]
[Thu Sep 17 15:38:18.095447 2026] [security2:error] [pid 18946:tid 19117] [client 40.77.167.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rcpscanning.com"] [uri "/index.php"] [unique_id "aqxdyDqiPMah0Tz_U1O3yAAAATM"]
[Thu Sep 17 15:38:18.117953 2026] [security2:error] [pid 18946:tid 19186] [client 136.158.61.34:20151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4GAAAAXg"]
[Thu Sep 17 15:38:18.118081 2026] [security2:error] [pid 18946:tid 19186] [client 136.158.61.34:20151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4GAAAAXg"]
[Thu Sep 17 15:38:18.162105 2026] [security2:error] [pid 18946:tid 19169] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/baba.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4GgAAAWc"]
[Thu Sep 17 15:38:18.162220 2026] [security2:error] [pid 18946:tid 19169] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/baba.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4GgAAAWc"]
[Thu Sep 17 15:38:18.230031 2026] [security2:error] [pid 20162:tid 20347] [client 24.140.202.61:29137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brownsdailydose.com"] [uri "/xmlrpc.php"] [unique_id "aqxdx6-O_Kk7aqBvaiGH8wABxUM"]
[Thu Sep 17 15:38:18.236696 2026] [security2:error] [pid 18946:tid 19088] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxdyjqiPMah0Tz_U1O4IwAAARY"]
[Thu Sep 17 15:38:18.265517 2026] [security2:error] [pid 20162:tid 20347] [client 24.140.202.61:29137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brownsdailydose.com"] [uri "/xmlrpc.php"] [unique_id "aqxdx6-O_Kk7aqBvaiGH9QABxQY"]
[Thu Sep 17 15:38:18.368912 2026] [security2:error] [pid 18946:tid 19125] [client 197.48.194.6:51440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4JwABO0c"]
[Thu Sep 17 15:38:18.392781 2026] [security2:error] [pid 18946:tid 19147] [client 34.154.220.126:49164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxdyjqiPMah0Tz_U1O4MQAAAVE"]
[Thu Sep 17 15:38:18.558630 2026] [security2:error] [pid 18946:tid 19081] [client 34.154.220.126:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4NgAAAQ8"]
[Thu Sep 17 15:38:18.687720 2026] [security2:error] [pid 18946:tid 19184] [client 34.122.173.216:9984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxdyDqiPMah0Tz_U1O35AABdjs"]
[Thu Sep 17 15:38:18.737519 2026] [security2:error] [pid 18946:tid 19093] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/cabs.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4PAAAARs"]
[Thu Sep 17 15:38:18.737684 2026] [security2:error] [pid 18946:tid 19093] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/cabs.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4PAAAARs"]
[Thu Sep 17 15:38:18.909429 2026] [security2:error] [pid 18946:tid 19104] [client 34.122.173.216:9984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4OwABJmk"]
[Thu Sep 17 15:38:19.036438 2026] [security2:error] [pid 18946:tid 19154] [client 34.154.220.126:46792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/info.php"] [unique_id "aqxdyzqiPMah0Tz_U1O4SQAAAVg"]
[Thu Sep 17 15:38:19.076385 2026] [security2:error] [pid 18946:tid 19149] [client 45.234.208.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxdyjqiPMah0Tz_U1O4RAAAAVM"], referer: https://coronadoiscalling.com
[Thu Sep 17 15:38:19.076479 2026] [security2:error] [pid 20162:tid 20403] [client 24.140.202.61:29352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "brownsdailydose.com"] [uri "/index.php"] [unique_id "aqxdyq-O_Kk7aqBvaiGILwAB_TY"]
[Thu Sep 17 15:38:19.327836 2026] [security2:error] [pid 18946:tid 19120] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/insc.php"] [unique_id "aqxdyzqiPMah0Tz_U1O4UAAAATY"]
[Thu Sep 17 15:38:19.327940 2026] [security2:error] [pid 18946:tid 19120] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/insc.php"] [unique_id "aqxdyzqiPMah0Tz_U1O4UAAAATY"]
[Thu Sep 17 15:38:19.384346 2026] [security2:error] [pid 20162:tid 20358] [client 34.122.173.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccrmediator.com"] [uri "/index.php"] [unique_id "aqxdy6-O_Kk7aqBvaiGINAAAAdA"]
[Thu Sep 17 15:38:19.543567 2026] [security2:error] [pid 20162:tid 20408] [client 34.154.220.126:46806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/php.php"] [unique_id "aqxdy6-O_Kk7aqBvaiGIOgAAAgI"]
[Thu Sep 17 15:38:19.630835 2026] [security2:error] [pid 18946:tid 19117] [client 103.61.184.148:49721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdyzqiPMah0Tz_U1O4WAAAATM"]
[Thu Sep 17 15:38:19.630964 2026] [security2:error] [pid 18946:tid 19117] [client 103.61.184.148:49721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxdyzqiPMah0Tz_U1O4WAAAATM"]
[Thu Sep 17 15:38:19.768941 2026] [security2:error] [pid 20162:tid 20410] [client 169.58.197.253:53013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppfc.net"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxdy6-O_Kk7aqBvaiGIQAAAAgQ"], referer: binance.com
[Thu Sep 17 15:38:19.934086 2026] [security2:error] [pid 18946:tid 19082] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/file.php"] [unique_id "aqxdyzqiPMah0Tz_U1O4XwAAARA"]
[Thu Sep 17 15:38:19.934186 2026] [security2:error] [pid 18946:tid 19082] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/file.php"] [unique_id "aqxdyzqiPMah0Tz_U1O4XwAAARA"]
[Thu Sep 17 15:38:19.952283 2026] [security2:error] [pid 18946:tid 19055] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env.bak"] [unique_id "aqxdyzqiPMah0Tz_U1O4ZAABVGw"]
[Thu Sep 17 15:38:19.952291 2026] [security2:error] [pid 18946:tid 19067] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env.backup"] [unique_id "aqxdyzqiPMah0Tz_U1O4YQABVHg"]
[Thu Sep 17 15:38:19.953380 2026] [security2:error] [pid 18946:tid 19067] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env.old"] [unique_id "aqxdyzqiPMah0Tz_U1O4aAABVHg"]
[Thu Sep 17 15:38:19.954794 2026] [security2:error] [pid 18946:tid 19011] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env"] [unique_id "aqxdyzqiPMah0Tz_U1O4bwABVEA"]
[Thu Sep 17 15:38:20.036539 2026] [security2:error] [pid 18946:tid 19124] [client 34.154.220.126:46810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/i.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4dQAAATo"]
[Thu Sep 17 15:38:20.113978 2026] [cgid:error] [pid 18946:tid 19125] [client 221.149.119.65:4370] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/WordPress
[Thu Sep 17 15:38:20.288140 2026] [security2:error] [pid 18946:tid 19069] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env~"] [unique_id "aqxdzDqiPMah0Tz_U1O4fgABG3o"]
[Thu Sep 17 15:38:20.288148 2026] [security2:error] [pid 18946:tid 19064] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env.swp"] [unique_id "aqxdzDqiPMah0Tz_U1O4gAABG3U"]
[Thu Sep 17 15:38:20.289195 2026] [security2:error] [pid 18946:tid 19030] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4egABG1M"]
[Thu Sep 17 15:38:20.351290 2026] [security2:error] [pid 20162:tid 20412] [client 78.166.61.95:48423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIRQACBjw"]
[Thu Sep 17 15:38:20.390206 2026] [security2:error] [pid 20162:tid 20377] [client 45.115.26.203:33308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/.env"] [unique_id "aqxdzK-O_Kk7aqBvaiGIRwAAAeM"]
[Thu Sep 17 15:38:20.391384 2026] [security2:error] [pid 20162:tid 20364] [client 45.115.26.203:33486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/app/.env"] [unique_id "aqxdzK-O_Kk7aqBvaiGISAAAAdY"]
[Thu Sep 17 15:38:20.391455 2026] [security2:error] [pid 18946:tid 19110] [client 45.115.26.203:33478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/backend/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4hAAAASw"]
[Thu Sep 17 15:38:20.391854 2026] [security2:error] [pid 18946:tid 19101] [client 45.115.26.203:33456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/.env~"] [unique_id "aqxdzDqiPMah0Tz_U1O4hQAAASM"]
[Thu Sep 17 15:38:20.394639 2026] [security2:error] [pid 20162:tid 20404] [client 45.115.26.203:33326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/.env"] [unique_id "aqxdzK-O_Kk7aqBvaiGITAAAAf4"]
[Thu Sep 17 15:38:20.394971 2026] [security2:error] [pid 18946:tid 19170] [client 45.115.26.203:33462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/.env.swp"] [unique_id "aqxdzDqiPMah0Tz_U1O4hwAAAWg"]
[Thu Sep 17 15:38:20.441492 2026] [security2:error] [pid 18946:tid 19130] [client 45.115.26.203:33594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/php_info.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4kgAAAUA"]
[Thu Sep 17 15:38:20.441557 2026] [security2:error] [pid 18946:tid 19189] [client 45.115.26.203:33596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/_phpinfo.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4kwAAAXs"]
[Thu Sep 17 15:38:20.446786 2026] [security2:error] [pid 18946:tid 19152] [client 45.115.26.203:33616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/pi.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4mAAAAVY"]
[Thu Sep 17 15:38:20.446804 2026] [security2:error] [pid 18946:tid 19116] [client 45.115.26.203:33590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/test.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4lgAAATI"]
[Thu Sep 17 15:38:20.453250 2026] [security2:error] [pid 18946:tid 19089] [client 45.115.26.203:33574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/info.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4ngAAARc"]
[Thu Sep 17 15:38:20.455178 2026] [security2:error] [pid 18946:tid 19187] [client 45.115.26.203:33606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/php-info.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4pAAAAXk"]
[Thu Sep 17 15:38:20.455898 2026] [security2:error] [pid 18946:tid 19077] [client 45.115.26.203:33480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/api/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4owAAAQs"]
[Thu Sep 17 15:38:20.456126 2026] [security2:error] [pid 18946:tid 19191] [client 45.115.26.203:33582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/i.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4pgAAAX0"]
[Thu Sep 17 15:38:20.456387 2026] [security2:error] [pid 18946:tid 19080] [client 45.115.26.203:33412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/.env.backup"] [unique_id "aqxdzDqiPMah0Tz_U1O4ogAAAQ4"]
[Thu Sep 17 15:38:20.456793 2026] [security2:error] [pid 18946:tid 19131] [client 45.115.26.203:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casualchessclub.com"] [uri "/phpinfo.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4pwAAAUE"]
[Thu Sep 17 15:38:20.457572 2026] [security2:error] [pid 20162:tid 20397] [client 45.115.26.203:33488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/src/.env"] [unique_id "aqxdzK-O_Kk7aqBvaiGIVwAAAfc"]
[Thu Sep 17 15:38:20.457964 2026] [security2:error] [pid 18946:tid 19179] [client 45.115.26.203:33438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/.env.old"] [unique_id "aqxdzDqiPMah0Tz_U1O4qAAAAXE"]
[Thu Sep 17 15:38:20.457977 2026] [security2:error] [pid 18946:tid 19196] [client 45.115.26.203:33426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "casualchessclub.com"] [uri "/.env.bak"] [unique_id "aqxdzDqiPMah0Tz_U1O4qQAAAYI"]
[Thu Sep 17 15:38:20.489149 2026] [security2:error] [pid 18946:tid 18958] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/app/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4rgABbQs"]
[Thu Sep 17 15:38:20.489184 2026] [security2:error] [pid 18946:tid 18963] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/api/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4rwABbRA"]
[Thu Sep 17 15:38:20.490241 2026] [security2:error] [pid 18946:tid 18959] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/backend/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4tAABbQw"]
[Thu Sep 17 15:38:20.503110 2026] [security2:error] [pid 18946:tid 19178] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/dex.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4tQAAAXA"]
[Thu Sep 17 15:38:20.503233 2026] [security2:error] [pid 18946:tid 19178] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/dex.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4tQAAAXA"]
[Thu Sep 17 15:38:20.542469 2026] [security2:error] [pid 18946:tid 19188] [client 34.154.220.126:46820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4vQAAAXo"]
[Thu Sep 17 15:38:20.728465 2026] [security2:error] [pid 18946:tid 19074] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/src/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4xQABUH8"]
[Thu Sep 17 15:38:20.728509 2026] [security2:error] [pid 18946:tid 18950] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/config/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4wgABUAM"]
[Thu Sep 17 15:38:20.728515 2026] [security2:error] [pid 18946:tid 18973] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/frontend/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4xwABUBo"]
[Thu Sep 17 15:38:20.728567 2026] [security2:error] [pid 18946:tid 19021] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/web/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4xAABUEo"]
[Thu Sep 17 15:38:20.728567 2026] [security2:error] [pid 18946:tid 18999] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/client/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4xgABUDQ"]
[Thu Sep 17 15:38:20.728578 2026] [security2:error] [pid 18946:tid 18948] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/server/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4yAABUAE"]
[Thu Sep 17 15:38:20.728601 2026] [security2:error] [pid 18946:tid 18974] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/public/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4wQABUBs"]
[Thu Sep 17 15:38:20.864999 2026] [security2:error] [pid 18946:tid 18967] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/var/www/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4zAABQhQ"]
[Thu Sep 17 15:38:20.865002 2026] [security2:error] [pid 18946:tid 18969] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/laravel/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4ywABQhY"]
[Thu Sep 17 15:38:20.865040 2026] [security2:error] [pid 18946:tid 18985] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/apps/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4ygABQiY"]
[Thu Sep 17 15:38:20.865069 2026] [security2:error] [pid 18946:tid 18988] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/back/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4zwABQik"]
[Thu Sep 17 15:38:20.865117 2026] [security2:error] [pid 18946:tid 18949] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/application/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4zQABQgI"]
[Thu Sep 17 15:38:20.865130 2026] [security2:error] [pid 18946:tid 18952] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/backup/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O4zgABQgU"]
[Thu Sep 17 15:38:20.865170 2026] [security2:error] [pid 18946:tid 18971] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/var/www/html/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O40AABQhg"]
[Thu Sep 17 15:38:20.867953 2026] [access_compat:error] [pid 20162:tid 20388] [client 45.115.26.203:33646] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Thu Sep 17 15:38:20.868764 2026] [security2:error] [pid 18946:tid 18979] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/cms/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O40QABbyA"]
[Thu Sep 17 15:38:20.934264 2026] [security2:error] [pid 18946:tid 19044] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/dev/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O41wABiWE"]
[Thu Sep 17 15:38:20.934279 2026] [security2:error] [pid 18946:tid 18953] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/staging/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O42gABiQY"]
[Thu Sep 17 15:38:20.934281 2026] [security2:error] [pid 18946:tid 18986] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/new/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O43AABiSc"]
[Thu Sep 17 15:38:20.934313 2026] [security2:error] [pid 18946:tid 18968] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/production/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O42AABiRU"]
[Thu Sep 17 15:38:20.934342 2026] [security2:error] [pid 18946:tid 18984] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/test/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O41gABiSU"]
[Thu Sep 17 15:38:20.934351 2026] [security2:error] [pid 18946:tid 18982] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/prod/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O42QABiSM"]
[Thu Sep 17 15:38:20.934392 2026] [security2:error] [pid 18946:tid 19007] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/node-api/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O43QABiTw"]
[Thu Sep 17 15:38:20.934398 2026] [security2:error] [pid 18946:tid 19037] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/old/.env"] [unique_id "aqxdzDqiPMah0Tz_U1O42wABiVo"]
[Thu Sep 17 15:38:21.025754 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.220.126:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxdzTqiPMah0Tz_U1O44QAAAR8"]
[Thu Sep 17 15:38:21.085820 2026] [security2:error] [pid 18946:tid 19150] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/key.php"] [unique_id "aqxdzTqiPMah0Tz_U1O44wAAAVQ"]
[Thu Sep 17 15:38:21.085953 2026] [security2:error] [pid 18946:tid 19150] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/key.php"] [unique_id "aqxdzTqiPMah0Tz_U1O44wAAAVQ"]
[Thu Sep 17 15:38:21.099115 2026] [security2:error] [pid 18946:tid 19068] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/public_html/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O46AABUnk"]
[Thu Sep 17 15:38:21.099140 2026] [security2:error] [pid 18946:tid 18995] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/api-backend/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O46gABUjA"]
[Thu Sep 17 15:38:21.099141 2026] [security2:error] [pid 18946:tid 18964] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/server/api/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O46wABUhE"]
[Thu Sep 17 15:38:21.099181 2026] [security2:error] [pid 18946:tid 18947] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/server/backend/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O45wABUgA"]
[Thu Sep 17 15:38:21.099181 2026] [security2:error] [pid 18946:tid 18983] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/admin-app/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O45AABUiQ"]
[Thu Sep 17 15:38:21.099187 2026] [security2:error] [pid 18946:tid 19000] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.docker/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O45gABUjU"]
[Thu Sep 17 15:38:21.099199 2026] [security2:error] [pid 18946:tid 19004] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/current/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O45QABUjk"]
[Thu Sep 17 15:38:21.155097 2026] [security2:error] [pid 18946:tid 19014] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/administrator/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O46QABUkM"]
[Thu Sep 17 15:38:21.271221 2026] [security2:error] [pid 18946:tid 18980] [remote 114.119.146.45:65171] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thehivetribe.com"] [uri "/yard_mk-2"] [unique_id "aqxdzTqiPMah0Tz_U1O47QABXSE"]
[Thu Sep 17 15:38:21.314024 2026] [security2:error] [pid 18946:tid 18991] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/v1/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O49AABIiw"]
[Thu Sep 17 15:38:21.314567 2026] [security2:error] [pid 18946:tid 18965] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/v2/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O49QABIhI"]
[Thu Sep 17 15:38:21.314569 2026] [security2:error] [pid 18946:tid 18978] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O48AABIh8"]
[Thu Sep 17 15:38:21.315532 2026] [security2:error] [pid 18946:tid 19023] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.aws/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O49gABIkw"]
[Thu Sep 17 15:38:21.315696 2026] [security2:error] [pid 18946:tid 19019] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/aws/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O48QABIkg"]
[Thu Sep 17 15:38:21.318841 2026] [security2:error] [pid 18946:tid 19003] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/stripe/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O47wABIjg"]
[Thu Sep 17 15:38:21.507369 2026] [security2:error] [pid 20162:tid 20347] [client 34.154.220.126:46830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/test.php"] [unique_id "aqxdza-O_Kk7aqBvaiGIfAAAAcU"]
[Thu Sep 17 15:38:21.662301 2026] [security2:error] [pid 18946:tid 19110] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/kir.php"] [unique_id "aqxdzTqiPMah0Tz_U1O4-wAAASw"]
[Thu Sep 17 15:38:21.662408 2026] [security2:error] [pid 18946:tid 19110] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/kir.php"] [unique_id "aqxdzTqiPMah0Tz_U1O4-wAAASw"]
[Thu Sep 17 15:38:21.671069 2026] [security2:error] [pid 18946:tid 19016] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/v3/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O4_AABaEU"]
[Thu Sep 17 15:38:21.671197 2026] [security2:error] [pid 18946:tid 19013] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/media/.env"] [unique_id "aqxdzTqiPMah0Tz_U1O4_QABaEI"]
[Thu Sep 17 15:38:21.767553 2026] [security2:error] [pid 18946:tid 19093] [client 14.96.156.146:55633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdzTqiPMah0Tz_U1O5CAAAARs"]
[Thu Sep 17 15:38:21.768631 2026] [security2:error] [pid 18946:tid 19093] [client 14.96.156.146:55633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxdzTqiPMah0Tz_U1O5CAAAARs"]
[Thu Sep 17 15:38:22.073252 2026] [security2:error] [pid 18946:tid 19179] [client 114.198.138.124:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdzjqiPMah0Tz_U1O5FAAAAXE"]
[Thu Sep 17 15:38:22.073384 2026] [security2:error] [pid 18946:tid 19179] [client 114.198.138.124:59959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxdzjqiPMah0Tz_U1O5FAAAAXE"]
[Thu Sep 17 15:38:22.201827 2026] [security2:error] [pid 18946:tid 19172] [client 34.154.220.126:43178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/p.php"] [unique_id "aqxdzjqiPMah0Tz_U1O5GgAAAWo"]
[Thu Sep 17 15:38:22.250885 2026] [security2:error] [pid 20162:tid 20308] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/fling.php"] [unique_id "aqxdzq-O_Kk7aqBvaiGIigAAAZ4"]
[Thu Sep 17 15:38:22.251019 2026] [security2:error] [pid 20162:tid 20308] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/fling.php"] [unique_id "aqxdzq-O_Kk7aqBvaiGIigAAAZ4"]
[Thu Sep 17 15:38:22.407198 2026] [security2:error] [pid 18946:tid 19063] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.git/config.bak"] [unique_id "aqxdzjqiPMah0Tz_U1O5IwABIHQ"]
[Thu Sep 17 15:38:22.548100 2026] [security2:error] [pid 18946:tid 18997] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.aws/credentials.bak"] [unique_id "aqxdzjqiPMah0Tz_U1O5LQABDTI"]
[Thu Sep 17 15:38:22.603029 2026] [security2:error] [pid 18946:tid 19045] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.ssh/id_rsa"] [unique_id "aqxdzjqiPMah0Tz_U1O5NAABOmI"]
[Thu Sep 17 15:38:22.647569 2026] [security2:error] [pid 18946:tid 19017] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/id_rsa"] [unique_id "aqxdzjqiPMah0Tz_U1O5NwABZkY"]
[Thu Sep 17 15:38:22.706669 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.220.126:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxdzjqiPMah0Tz_U1O5QAAAAR8"]
[Thu Sep 17 15:38:22.866116 2026] [security2:error] [pid 18946:tid 19147] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/btyuio.php"] [unique_id "aqxdzjqiPMah0Tz_U1O5VAAAAVE"]
[Thu Sep 17 15:38:22.866204 2026] [security2:error] [pid 18946:tid 19147] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/btyuio.php"] [unique_id "aqxdzjqiPMah0Tz_U1O5VAAAAVE"]
[Thu Sep 17 15:38:22.870732 2026] [security2:error] [pid 20162:tid 20339] [client 185.192.20.41:52566] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.192.20.41" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.freeofgravity.com"] [uri "/wp-comments-post.php"] [unique_id "aqxdzq-O_Kk7aqBvaiGIkAAAAb0"], referer: http://www.freeofgravity.com/launch-day-wonder-over-fear/
[Thu Sep 17 15:38:22.870829 2026] [security2:error] [pid 20162:tid 20339] [client 185.192.20.41:52566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.freeofgravity.com"] [uri "/wp-comments-post.php"] [unique_id "aqxdzq-O_Kk7aqBvaiGIkAAAAb0"], referer: http://www.freeofgravity.com/launch-day-wonder-over-fear/
[Thu Sep 17 15:38:22.954436 2026] [security2:error] [pid 18946:tid 19065] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/config.php"] [unique_id "aqxdzjqiPMah0Tz_U1O5XAABRXY"]
[Thu Sep 17 15:38:23.105448 2026] [security2:error] [pid 18946:tid 18950] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/config/aws.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5cgABGwM"]
[Thu Sep 17 15:38:23.105481 2026] [security2:error] [pid 18946:tid 18999] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/config/stripe.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5cAABGzQ"]
[Thu Sep 17 15:38:23.116834 2026] [security2:error] [pid 18946:tid 18974] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/config/mail.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5cwABCxs"]
[Thu Sep 17 15:38:23.126062 2026] [security2:error] [pid 18946:tid 18972] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/config/config.inc.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5dAABfRk"]
[Thu Sep 17 15:38:23.207931 2026] [security2:error] [pid 20162:tid 20417] [client 34.154.220.126:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxdz6-O_Kk7aqBvaiGIlQAAAgs"]
[Thu Sep 17 15:38:23.312967 2026] [security2:error] [pid 18946:tid 19071] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/config/nexmo.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5dgABKnw"]
[Thu Sep 17 15:38:23.314327 2026] [security2:error] [pid 18946:tid 18967] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/wp-config.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5dwABKhQ"]
[Thu Sep 17 15:38:23.314551 2026] [security2:error] [pid 18946:tid 18967] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/wp-config.php.bak"] [unique_id "aqxdzzqiPMah0Tz_U1O5eQABKhQ"]
[Thu Sep 17 15:38:23.314780 2026] [security2:error] [pid 18946:tid 18967] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/wp-config.php.old"] [unique_id "aqxdzzqiPMah0Tz_U1O5egABKhQ"]
[Thu Sep 17 15:38:23.314975 2026] [security2:error] [pid 18946:tid 18967] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/wp-config.php.new"] [unique_id "aqxdzzqiPMah0Tz_U1O5ewABKhQ"]
[Thu Sep 17 15:38:23.315414 2026] [security2:error] [pid 18946:tid 18967] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.wp-config.php.swp"] [unique_id "aqxdzzqiPMah0Tz_U1O5fAABKhQ"]
[Thu Sep 17 15:38:23.320163 2026] [security2:error] [pid 18946:tid 18988] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/wp-content/mysql.sql"] [unique_id "aqxdzzqiPMah0Tz_U1O5fwABKik"]
[Thu Sep 17 15:38:23.435322 2026] [security2:error] [pid 18946:tid 19104] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/or.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5hAAAASY"]
[Thu Sep 17 15:38:23.435418 2026] [security2:error] [pid 18946:tid 19104] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/or.php"] [unique_id "aqxdzzqiPMah0Tz_U1O5hAAAASY"]
[Thu Sep 17 15:38:23.454873 2026] [security2:error] [pid 18946:tid 18995] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/terraform.tfstate.backup"] [unique_id "aqxdzzqiPMah0Tz_U1O5iwABPDA"]
[Thu Sep 17 15:38:23.736986 2026] [security2:error] [pid 20162:tid 20370] [client 34.154.220.126:43224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxdz6-O_Kk7aqBvaiGIoQAAAdw"]
[Thu Sep 17 15:38:24.012388 2026] [security2:error] [pid 18946:tid 19157] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/sm.php"] [unique_id "aqxd0DqiPMah0Tz_U1O5qQAAAVs"]
[Thu Sep 17 15:38:24.012491 2026] [security2:error] [pid 18946:tid 19157] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/sm.php"] [unique_id "aqxd0DqiPMah0Tz_U1O5qQAAAVs"]
[Thu Sep 17 15:38:24.063599 2026] [security2:error] [pid 18946:tid 19152] [client 177.44.133.72:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd0DqiPMah0Tz_U1O5qwAAAVY"]
[Thu Sep 17 15:38:24.063726 2026] [security2:error] [pid 18946:tid 19152] [client 177.44.133.72:60450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd0DqiPMah0Tz_U1O5qwAAAVY"]
[Thu Sep 17 15:38:24.241939 2026] [security2:error] [pid 18946:tid 19133] [client 34.154.220.126:43234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxd0DqiPMah0Tz_U1O5uAAAAUM"]
[Thu Sep 17 15:38:24.416142 2026] [security2:error] [pid 18946:tid 19059] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/phpinfo.php"] [unique_id "aqxd0DqiPMah0Tz_U1O5zgABOXA"]
[Thu Sep 17 15:38:24.454842 2026] [security2:error] [pid 18946:tid 18976] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/info.php"] [unique_id "aqxd0DqiPMah0Tz_U1O50AABHx0"]
[Thu Sep 17 15:38:24.594675 2026] [security2:error] [pid 18946:tid 19078] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/a.php"] [unique_id "aqxd0DqiPMah0Tz_U1O51gAAAQw"]
[Thu Sep 17 15:38:24.594770 2026] [security2:error] [pid 18946:tid 19078] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/a.php"] [unique_id "aqxd0DqiPMah0Tz_U1O51gAAAQw"]
[Thu Sep 17 15:38:24.818567 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.220.126:43244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxd0DqiPMah0Tz_U1O52QAAAV0"]
[Thu Sep 17 15:38:24.867995 2026] [security2:error] [pid 18946:tid 19018] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/infos.php"] [unique_id "aqxd0DqiPMah0Tz_U1O53AABaEc"]
[Thu Sep 17 15:38:24.868025 2026] [security2:error] [pid 18946:tid 19073] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxd0DqiPMah0Tz_U1O53wABaH4"]
[Thu Sep 17 15:38:24.868097 2026] [security2:error] [pid 18946:tid 19051] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxd0DqiPMah0Tz_U1O54AABaGg"]
[Thu Sep 17 15:38:24.868182 2026] [security2:error] [pid 18946:tid 19011] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/admin_phpinfo.php"] [unique_id "aqxd0DqiPMah0Tz_U1O54QABaEA"]
[Thu Sep 17 15:38:24.868210 2026] [security2:error] [pid 18946:tid 19032] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/infophp.php"] [unique_id "aqxd0DqiPMah0Tz_U1O52gABaFU"]
[Thu Sep 17 15:38:24.868224 2026] [security2:error] [pid 18946:tid 19026] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/php.php"] [unique_id "aqxd0DqiPMah0Tz_U1O52wABaE8"]
[Thu Sep 17 15:38:24.868312 2026] [security2:error] [pid 18946:tid 19036] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/api/phpinfo.php"] [unique_id "aqxd0DqiPMah0Tz_U1O54gABaFk"]
[Thu Sep 17 15:38:24.868324 2026] [security2:error] [pid 18946:tid 19070] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/php-info.php"] [unique_id "aqxd0DqiPMah0Tz_U1O53QABaHs"]
[Thu Sep 17 15:38:24.868513 2026] [security2:error] [pid 18946:tid 18987] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/php_info.php"] [unique_id "aqxd0DqiPMah0Tz_U1O54wABaCg"]
[Thu Sep 17 15:38:24.926838 2026] [security2:error] [pid 20162:tid 20382] [client 114.119.155.149:51365] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtbclubdecampo.com"] [uri "/Fotos/Las_Navas-Valle_Enmedio_08-06-2008/IMG_3992.JPG"] [unique_id "aqxd0K-O_Kk7aqBvaiGIswAAAeg"], referer: https://mtbclubdecampo.com/Fotos/Las_Navas-Valle_Enmedio_08-06-2008/IMG_3992.JPG
[Thu Sep 17 15:38:25.020156 2026] [security2:error] [pid 18946:tid 19067] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/public/phpinfo.php"] [unique_id "aqxd0TqiPMah0Tz_U1O57QABI3g"]
[Thu Sep 17 15:38:25.021168 2026] [security2:error] [pid 18946:tid 19040] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/database.sql"] [unique_id "aqxd0TqiPMah0Tz_U1O58gABI10"]
[Thu Sep 17 15:38:25.162829 2026] [security2:error] [pid 18946:tid 19125] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/sb.php"] [unique_id "aqxd0TqiPMah0Tz_U1O59wAAATs"]
[Thu Sep 17 15:38:25.162916 2026] [security2:error] [pid 18946:tid 19125] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/sb.php"] [unique_id "aqxd0TqiPMah0Tz_U1O59wAAATs"]
[Thu Sep 17 15:38:25.335955 2026] [security2:error] [pid 18946:tid 19197] [client 34.154.220.126:43246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxd0TqiPMah0Tz_U1O6AAAAAYM"]
[Thu Sep 17 15:38:25.418621 2026] [security2:error] [pid 18946:tid 19164] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4rAAAAWI"]
[Thu Sep 17 15:38:25.503474 2026] [security2:error] [pid 18946:tid 18972] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/web.config.bak"] [unique_id "aqxd0TqiPMah0Tz_U1O6DgABFhk"]
[Thu Sep 17 15:38:25.712033 2026] [security2:error] [pid 18946:tid 18967] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env.orig"] [unique_id "aqxd0TqiPMah0Tz_U1O6HAABRxQ"]
[Thu Sep 17 15:38:25.712080 2026] [security2:error] [pid 18946:tid 18988] [remote 34.14.99.143:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hole.cult.cyberpunkonline.net"] [uri "/.env.php.bak"] [unique_id "aqxd0TqiPMah0Tz_U1O6IAABRyk"]
[Thu Sep 17 15:38:25.737073 2026] [security2:error] [pid 18946:tid 19145] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/av.php"] [unique_id "aqxd0TqiPMah0Tz_U1O6JQAAAU8"]
[Thu Sep 17 15:38:25.737159 2026] [security2:error] [pid 18946:tid 19145] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/av.php"] [unique_id "aqxd0TqiPMah0Tz_U1O6JQAAAU8"]
[Thu Sep 17 15:38:25.828128 2026] [security2:error] [pid 20162:tid 20299] [client 34.154.220.126:43248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxd0a-O_Kk7aqBvaiGIyQAAAZU"]
[Thu Sep 17 15:38:26.295979 2026] [security2:error] [pid 18946:tid 19192] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/cae2.2.php"] [unique_id "aqxd0jqiPMah0Tz_U1O6OgAAAX4"]
[Thu Sep 17 15:38:26.296132 2026] [security2:error] [pid 18946:tid 19192] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/cae2.2.php"] [unique_id "aqxd0jqiPMah0Tz_U1O6OgAAAX4"]
[Thu Sep 17 15:38:26.307576 2026] [security2:error] [pid 18946:tid 19198] [client 45.115.26.203:33502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4lAAAAYQ"]
[Thu Sep 17 15:38:26.331742 2026] [security2:error] [pid 18946:tid 19195] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4uQAAAYE"]
[Thu Sep 17 15:38:26.339438 2026] [security2:error] [pid 20162:tid 20366] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIaAAAAdg"]
[Thu Sep 17 15:38:26.344720 2026] [security2:error] [pid 20162:tid 20420] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIYgAAAg4"]
[Thu Sep 17 15:38:26.347070 2026] [security2:error] [pid 20162:tid 20334] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIaQAAAbg"]
[Thu Sep 17 15:38:26.388486 2026] [security2:error] [pid 18946:tid 19086] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4qwAAARQ"]
[Thu Sep 17 15:38:26.390162 2026] [security2:error] [pid 20162:tid 20350] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIXwAAAcg"]
[Thu Sep 17 15:38:26.416169 2026] [security2:error] [pid 20162:tid 20405] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIagAAAf8"]
[Thu Sep 17 15:38:26.438612 2026] [security2:error] [pid 18946:tid 19158] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4ugAAAVw"]
[Thu Sep 17 15:38:26.476438 2026] [security2:error] [pid 18946:tid 19152] [client 79.117.245.35:44018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tab-funkenwerk.org"] [uri "/index.php"] [unique_id "aqxd0TqiPMah0Tz_U1O6JgABVgc"], referer: https://tab-funkenwerk.org/
[Thu Sep 17 15:38:26.587386 2026] [security2:error] [pid 18946:tid 19180] [client 34.154.220.126:43252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxd0jqiPMah0Tz_U1O6QgAAAXI"]
[Thu Sep 17 15:38:26.862543 2026] [security2:error] [pid 20162:tid 20375] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/b8.php"] [unique_id "aqxd0q-O_Kk7aqBvaiGI2wAAAeE"]
[Thu Sep 17 15:38:26.862647 2026] [security2:error] [pid 20162:tid 20375] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/b8.php"] [unique_id "aqxd0q-O_Kk7aqBvaiGI2wAAAeE"]
[Thu Sep 17 15:38:27.142709 2026] [security2:error] [pid 20162:tid 20338] [client 34.154.220.126:43254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxd06-O_Kk7aqBvaiGI4gAAAbw"]
[Thu Sep 17 15:38:27.261517 2026] [security2:error] [pid 18946:tid 19149] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4qgAAAVM"]
[Thu Sep 17 15:38:27.327429 2026] [security2:error] [pid 20162:tid 20316] [client 143.105.152.240:40101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd06-O_Kk7aqBvaiGI5QAAAaY"]
[Thu Sep 17 15:38:27.330725 2026] [security2:error] [pid 20162:tid 20345] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIZgAAAcM"]
[Thu Sep 17 15:38:27.334161 2026] [security2:error] [pid 20162:tid 20316] [client 143.105.152.240:40101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd06-O_Kk7aqBvaiGI5QAAAaY"]
[Thu Sep 17 15:38:27.352169 2026] [security2:error] [pid 18946:tid 19092] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4wAAAARo"]
[Thu Sep 17 15:38:27.356705 2026] [security2:error] [pid 18946:tid 19176] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4vwAAAW4"]
[Thu Sep 17 15:38:27.439424 2026] [security2:error] [pid 20162:tid 20376] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzK-O_Kk7aqBvaiGIZwAAAeI"]
[Thu Sep 17 15:38:27.441708 2026] [security2:error] [pid 20162:tid 20382] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp_blog_footer.php"] [unique_id "aqxd06-O_Kk7aqBvaiGI6QAAAeg"]
[Thu Sep 17 15:38:27.441823 2026] [security2:error] [pid 20162:tid 20382] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp_blog_footer.php"] [unique_id "aqxd06-O_Kk7aqBvaiGI6QAAAeg"]
[Thu Sep 17 15:38:27.474485 2026] [security2:error] [pid 18946:tid 19134] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4uAAAAUQ"]
[Thu Sep 17 15:38:27.476512 2026] [security2:error] [pid 18946:tid 19102] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4uwAAASQ"]
[Thu Sep 17 15:38:27.489327 2026] [security2:error] [pid 18946:tid 19185] [client 45.115.26.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxdzDqiPMah0Tz_U1O4vAAAAXc"]
[Thu Sep 17 15:38:27.673520 2026] [security2:error] [pid 20162:tid 20360] [client 34.154.220.126:43256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxd06-O_Kk7aqBvaiGI7wAAAdI"]
[Thu Sep 17 15:38:27.800891 2026] [security2:error] [pid 18946:tid 19175] [client 79.116.89.151:49153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd0zqiPMah0Tz_U1O6VwAAAW0"]
[Thu Sep 17 15:38:27.801035 2026] [security2:error] [pid 18946:tid 19175] [client 79.116.89.151:49153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd0zqiPMah0Tz_U1O6VwAAAW0"]
[Thu Sep 17 15:38:28.019038 2026] [security2:error] [pid 20162:tid 20385] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/CAE-2.5.php"] [unique_id "aqxd1K-O_Kk7aqBvaiGI9QAAAes"]
[Thu Sep 17 15:38:28.019157 2026] [security2:error] [pid 20162:tid 20385] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/CAE-2.5.php"] [unique_id "aqxd1K-O_Kk7aqBvaiGI9QAAAes"]
[Thu Sep 17 15:38:28.172274 2026] [security2:error] [pid 20162:tid 20313] [client 34.154.220.126:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxd1K-O_Kk7aqBvaiGI9wAAAaM"]
[Thu Sep 17 15:38:28.612197 2026] [security2:error] [pid 20162:tid 20320] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/0.php"] [unique_id "aqxd1K-O_Kk7aqBvaiGI_wAAAao"]
[Thu Sep 17 15:38:28.612330 2026] [security2:error] [pid 20162:tid 20320] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/0.php"] [unique_id "aqxd1K-O_Kk7aqBvaiGI_wAAAao"]
[Thu Sep 17 15:38:28.713186 2026] [security2:error] [pid 20162:tid 20369] [client 34.154.220.126:43280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxd1K-O_Kk7aqBvaiGJAAAAAds"]
[Thu Sep 17 15:38:28.906341 2026] [security2:error] [pid 20162:tid 20362] [client 179.190.99.170:58773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd1K-O_Kk7aqBvaiGJAwAB1D0"]
[Thu Sep 17 15:38:28.969166 2026] [security2:error] [pid 18946:tid 19114] [client 74.7.241.156:51346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tab-funkenwerk.org"] [uri "/robots.txt"] [unique_id "aqxd1DqiPMah0Tz_U1O6agABMEU"]
[Thu Sep 17 15:38:29.184422 2026] [security2:error] [pid 18946:tid 19093] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/fms.php"] [unique_id "aqxd1TqiPMah0Tz_U1O6dgAAARs"]
[Thu Sep 17 15:38:29.184525 2026] [security2:error] [pid 18946:tid 19093] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/fms.php"] [unique_id "aqxd1TqiPMah0Tz_U1O6dgAAARs"]
[Thu Sep 17 15:38:29.231295 2026] [security2:error] [pid 18946:tid 19107] [client 34.154.220.126:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxd1TqiPMah0Tz_U1O6eAAAASk"]
[Thu Sep 17 15:38:29.775185 2026] [security2:error] [pid 20162:tid 20370] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/cycfruf.php"] [unique_id "aqxd1a-O_Kk7aqBvaiGJGAAAAdw"]
[Thu Sep 17 15:38:29.775274 2026] [security2:error] [pid 20162:tid 20370] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/cycfruf.php"] [unique_id "aqxd1a-O_Kk7aqBvaiGJGAAAAdw"]
[Thu Sep 17 15:38:29.865813 2026] [security2:error] [pid 20162:tid 20412] [client 74.7.244.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.jenayatalkscaps.com"] [uri "/index.php"] [unique_id "aqxd1a-O_Kk7aqBvaiGJEwAAAgY"]
[Thu Sep 17 15:38:29.888131 2026] [security2:error] [pid 20162:tid 20406] [client 74.7.244.62:48774] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.jenayatalkscaps.com"] [uri "/robots.txt"] [unique_id "aqxd1a-O_Kk7aqBvaiGJDAACAEQ"]
[Thu Sep 17 15:38:30.277807 2026] [security2:error] [pid 20162:tid 20409] [client 34.154.220.126:43290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxd1q-O_Kk7aqBvaiGJIAAAAgM"]
[Thu Sep 17 15:38:30.318750 2026] [security2:error] [pid 20162:tid 20294] [client 136.158.61.34:21085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd1q-O_Kk7aqBvaiGJIgAAAZA"]
[Thu Sep 17 15:38:30.318874 2026] [security2:error] [pid 20162:tid 20294] [client 136.158.61.34:21085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd1q-O_Kk7aqBvaiGJIgAAAZA"]
[Thu Sep 17 15:38:30.322733 2026] [security2:error] [pid 20162:tid 20338] [client 103.61.184.148:50295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd1q-O_Kk7aqBvaiGJIwAAAbw"]
[Thu Sep 17 15:38:30.322821 2026] [security2:error] [pid 20162:tid 20338] [client 103.61.184.148:50295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd1q-O_Kk7aqBvaiGJIwAAAbw"]
[Thu Sep 17 15:38:30.376188 2026] [security2:error] [pid 18946:tid 19157] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/cdc.php"] [unique_id "aqxd1jqiPMah0Tz_U1O6kQAAAVs"]
[Thu Sep 17 15:38:30.376272 2026] [security2:error] [pid 18946:tid 19157] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/cdc.php"] [unique_id "aqxd1jqiPMah0Tz_U1O6kQAAAVs"]
[Thu Sep 17 15:38:30.716215 2026] [security2:error] [pid 18946:tid 19182] [client 180.244.132.193:27152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd1jqiPMah0Tz_U1O6mgABdEQ"]
[Thu Sep 17 15:38:30.851697 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.220.126:43292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxd1jqiPMah0Tz_U1O6nQAAATk"]
[Thu Sep 17 15:38:30.969274 2026] [security2:error] [pid 18946:tid 19096] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/aj.php"] [unique_id "aqxd1jqiPMah0Tz_U1O6owAAAR4"]
[Thu Sep 17 15:38:30.969403 2026] [security2:error] [pid 18946:tid 19096] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/aj.php"] [unique_id "aqxd1jqiPMah0Tz_U1O6owAAAR4"]
[Thu Sep 17 15:38:31.389537 2026] [security2:error] [pid 18946:tid 19159] [client 34.154.220.126:43294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxd1zqiPMah0Tz_U1O6qgAAAV0"]
[Thu Sep 17 15:38:31.534111 2026] [security2:error] [pid 20162:tid 20381] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/min.php"] [unique_id "aqxd16-O_Kk7aqBvaiGJNgAAAec"]
[Thu Sep 17 15:38:31.534205 2026] [security2:error] [pid 20162:tid 20381] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/min.php"] [unique_id "aqxd16-O_Kk7aqBvaiGJNgAAAec"]
[Thu Sep 17 15:38:31.946539 2026] [security2:error] [pid 18946:tid 19155] [client 34.154.220.126:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxd1zqiPMah0Tz_U1O6swAAAVk"]
[Thu Sep 17 15:38:32.112643 2026] [security2:error] [pid 18946:tid 19189] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-whe.php"] [unique_id "aqxd2DqiPMah0Tz_U1O6uAAAAXs"]
[Thu Sep 17 15:38:32.112747 2026] [security2:error] [pid 18946:tid 19189] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-whe.php"] [unique_id "aqxd2DqiPMah0Tz_U1O6uAAAAXs"]
[Thu Sep 17 15:38:32.150046 2026] [security2:error] [pid 20162:tid 20308] [client 34.95.173.223:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/phpinfo.php"] [unique_id "aqxd2K-O_Kk7aqBvaiGJPgAAAZ4"]
[Thu Sep 17 15:38:32.377461 2026] [security2:error] [pid 20162:tid 20394] [client 14.96.156.146:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd2K-O_Kk7aqBvaiGJQwAAAfQ"]
[Thu Sep 17 15:38:32.377571 2026] [security2:error] [pid 20162:tid 20394] [client 14.96.156.146:56272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd2K-O_Kk7aqBvaiGJQwAAAfQ"]
[Thu Sep 17 15:38:32.532526 2026] [security2:error] [pid 20162:tid 20320] [client 34.154.220.126:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxd2K-O_Kk7aqBvaiGJRwAAAao"]
[Thu Sep 17 15:38:32.640617 2026] [security2:error] [pid 20162:tid 20312] [client 34.95.173.223:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/info.php"] [unique_id "aqxd2K-O_Kk7aqBvaiGJSgAAAaI"]
[Thu Sep 17 15:38:32.666345 2026] [security2:error] [pid 18946:tid 19197] [client 114.198.138.124:60763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxd2DqiPMah0Tz_U1O6vwAAAYM"]
[Thu Sep 17 15:38:32.666453 2026] [security2:error] [pid 18946:tid 19197] [client 114.198.138.124:60763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skippyblairuniversalunitsystem.com"] [uri "/xmlrpc.php"] [unique_id "aqxd2DqiPMah0Tz_U1O6vwAAAYM"]
[Thu Sep 17 15:38:32.691202 2026] [security2:error] [pid 18946:tid 19112] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemanager1.php"] [unique_id "aqxd2DqiPMah0Tz_U1O6wQAAAS4"]
[Thu Sep 17 15:38:32.691331 2026] [security2:error] [pid 18946:tid 19112] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-filemanager1.php"] [unique_id "aqxd2DqiPMah0Tz_U1O6wQAAAS4"]
[Thu Sep 17 15:38:33.127789 2026] [security2:error] [pid 18946:tid 19076] [client 34.95.173.223:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/php.php"] [unique_id "aqxd2TqiPMah0Tz_U1O6ygAAAQo"]
[Thu Sep 17 15:38:33.163643 2026] [security2:error] [pid 20162:tid 20410] [client 34.154.220.126:38614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxd2a-O_Kk7aqBvaiGJTQAAAgQ"]
[Thu Sep 17 15:38:33.274075 2026] [security2:error] [pid 18946:tid 19126] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-freya.php"] [unique_id "aqxd2TqiPMah0Tz_U1O6zgAAATw"]
[Thu Sep 17 15:38:33.274200 2026] [security2:error] [pid 18946:tid 19126] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-freya.php"] [unique_id "aqxd2TqiPMah0Tz_U1O6zgAAATw"]
[Thu Sep 17 15:38:33.620577 2026] [security2:error] [pid 18946:tid 19137] [client 34.95.173.223:46600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/i.php"] [unique_id "aqxd2TqiPMah0Tz_U1O62wAAAUc"]
[Thu Sep 17 15:38:33.800752 2026] [security2:error] [pid 18946:tid 19136] [client 34.154.220.126:38624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxd2TqiPMah0Tz_U1O63wAAAUY"]
[Thu Sep 17 15:38:33.856735 2026] [security2:error] [pid 20162:tid 20372] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/admin.php/admin.php"] [unique_id "aqxd2a-O_Kk7aqBvaiGJUwAAAd4"]
[Thu Sep 17 15:38:33.856850 2026] [security2:error] [pid 20162:tid 20372] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/admin.php/admin.php"] [unique_id "aqxd2a-O_Kk7aqBvaiGJUwAAAd4"]
[Thu Sep 17 15:38:34.123157 2026] [security2:error] [pid 20162:tid 20386] [client 34.95.173.223:54734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/pi.php"] [unique_id "aqxd2q-O_Kk7aqBvaiGJVwAAAew"]
[Thu Sep 17 15:38:34.445804 2026] [security2:error] [pid 18946:tid 19168] [client 34.154.220.126:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxd2jqiPMah0Tz_U1O67AAAAWY"]
[Thu Sep 17 15:38:34.446168 2026] [security2:error] [pid 18946:tid 19195] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxd2jqiPMah0Tz_U1O67QAAAYE"]
[Thu Sep 17 15:38:34.446242 2026] [security2:error] [pid 18946:tid 19195] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/admin.php"] [unique_id "aqxd2jqiPMah0Tz_U1O67QAAAYE"]
[Thu Sep 17 15:38:34.566719 2026] [security2:error] [pid 20162:tid 20412] [client 177.44.133.72:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd2q-O_Kk7aqBvaiGJXAAAAgY"]
[Thu Sep 17 15:38:34.566845 2026] [security2:error] [pid 20162:tid 20412] [client 177.44.133.72:61092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd2q-O_Kk7aqBvaiGJXAAAAgY"]
[Thu Sep 17 15:38:34.615337 2026] [security2:error] [pid 18946:tid 19100] [client 34.95.173.223:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/pinfo.php"] [unique_id "aqxd2jqiPMah0Tz_U1O68wAAASI"]
[Thu Sep 17 15:38:34.725566 2026] [security2:error] [pid 18946:tid 19185] [client 74.7.228.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "reedcustomprinting.com"] [uri "/index.php"] [unique_id "aqxd2TqiPMah0Tz_U1O62AAAAXc"]
[Thu Sep 17 15:38:34.731826 2026] [security2:error] [pid 18946:tid 19161] [client 74.7.228.58:51918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "reedcustomprinting.com"] [uri "/robots.txt"] [unique_id "aqxd2TqiPMah0Tz_U1O61gAAAV8"]
[Thu Sep 17 15:38:34.992464 2026] [security2:error] [pid 18946:tid 19147] [client 156.245.246.154:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.torringtonhandyman.com"] [uri "/index.php"] [unique_id "aqxd2jqiPMah0Tz_U1O6-AAAAVE"], referer: https://mail.torringtonhandyman.com
[Thu Sep 17 15:38:35.040026 2026] [security2:error] [pid 18946:tid 19189] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/gold.php"] [unique_id "aqxd2zqiPMah0Tz_U1O6-wAAAXs"]
[Thu Sep 17 15:38:35.040112 2026] [security2:error] [pid 18946:tid 19189] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/gold.php"] [unique_id "aqxd2zqiPMah0Tz_U1O6-wAAAXs"]
[Thu Sep 17 15:38:35.077504 2026] [security2:error] [pid 18946:tid 19091] [client 34.154.220.126:38646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxd2zqiPMah0Tz_U1O6_AAAARk"]
[Thu Sep 17 15:38:35.110236 2026] [security2:error] [pid 20162:tid 20345] [client 34.95.173.223:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/test.php"] [unique_id "aqxd26-O_Kk7aqBvaiGJYAAAAcM"]
[Thu Sep 17 15:38:35.609257 2026] [security2:error] [pid 20162:tid 20338] [client 34.154.220.126:38650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxd26-O_Kk7aqBvaiGJZAAAAbw"]
[Thu Sep 17 15:38:35.638262 2026] [security2:error] [pid 18946:tid 19109] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/faiy.php"] [unique_id "aqxd2zqiPMah0Tz_U1O7BQAAASs"]
[Thu Sep 17 15:38:35.638375 2026] [security2:error] [pid 18946:tid 19109] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/faiy.php"] [unique_id "aqxd2zqiPMah0Tz_U1O7BQAAASs"]
[Thu Sep 17 15:38:35.787682 2026] [security2:error] [pid 18946:tid 19130] [client 34.95.173.223:54770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/p.php"] [unique_id "aqxd2zqiPMah0Tz_U1O7BwAAAUA"]
[Thu Sep 17 15:38:36.222740 2026] [security2:error] [pid 18946:tid 19200] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/file-mancvgertdxz.php"] [unique_id "aqxd3DqiPMah0Tz_U1O7DwAAAYY"]
[Thu Sep 17 15:38:36.222827 2026] [security2:error] [pid 18946:tid 19200] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/file-mancvgertdxz.php"] [unique_id "aqxd3DqiPMah0Tz_U1O7DwAAAYY"]
[Thu Sep 17 15:38:36.244062 2026] [security2:error] [pid 18946:tid 19184] [client 34.154.220.126:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxd3DqiPMah0Tz_U1O7EAAAAXY"]
[Thu Sep 17 15:38:36.279080 2026] [security2:error] [pid 18946:tid 19149] [client 34.95.173.223:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/debug.php"] [unique_id "aqxd3DqiPMah0Tz_U1O7EQAAAVM"]
[Thu Sep 17 15:38:36.659309 2026] [security2:error] [pid 18946:tid 19136] [client 134.185.85.61:49632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "toristocco.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxd3DqiPMah0Tz_U1O7HAAAAUY"]
[Thu Sep 17 15:38:36.768341 2026] [security2:error] [pid 18946:tid 19082] [client 34.95.173.223:54794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxd3DqiPMah0Tz_U1O7HgAAARA"]
[Thu Sep 17 15:38:36.801508 2026] [security2:error] [pid 20162:tid 20347] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/myglu.php"] [unique_id "aqxd3K-O_Kk7aqBvaiGJbgAAAcU"]
[Thu Sep 17 15:38:36.801654 2026] [security2:error] [pid 20162:tid 20347] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/myglu.php"] [unique_id "aqxd3K-O_Kk7aqBvaiGJbgAAAcU"]
[Thu Sep 17 15:38:36.872633 2026] [security2:error] [pid 18946:tid 19097] [client 34.154.220.126:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxd3DqiPMah0Tz_U1O7IAAAAR8"]
[Thu Sep 17 15:38:37.037869 2026] [security2:error] [pid 18946:tid 19078] [client 134.185.85.61:63467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "toristocco.com"] [uri "/media/system/js/core.js"] [unique_id "aqxd3TqiPMah0Tz_U1O7JAAAAQw"]
[Thu Sep 17 15:38:37.265303 2026] [security2:error] [pid 20162:tid 20360] [client 34.95.173.223:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/test/phpinfo.php"] [unique_id "aqxd3a-O_Kk7aqBvaiGJcgAAAdI"]
[Thu Sep 17 15:38:37.380200 2026] [security2:error] [pid 20162:tid 20392] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/bnmtp.php"] [unique_id "aqxd3a-O_Kk7aqBvaiGJdAAAAfI"]
[Thu Sep 17 15:38:37.380316 2026] [security2:error] [pid 20162:tid 20392] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/bnmtp.php"] [unique_id "aqxd3a-O_Kk7aqBvaiGJdAAAAfI"]
[Thu Sep 17 15:38:37.481978 2026] [security2:error] [pid 18946:tid 19117] [client 34.154.220.126:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxd3TqiPMah0Tz_U1O7KgAAATM"]
[Thu Sep 17 15:38:37.664705 2026] [security2:error] [pid 20162:tid 20363] [client 143.105.152.240:13840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd3a-O_Kk7aqBvaiGJdwAAAdU"]
[Thu Sep 17 15:38:37.664853 2026] [security2:error] [pid 20162:tid 20363] [client 143.105.152.240:13840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd3a-O_Kk7aqBvaiGJdwAAAdU"]
[Thu Sep 17 15:38:37.766292 2026] [security2:error] [pid 20162:tid 20301] [client 34.95.173.223:54818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxd3a-O_Kk7aqBvaiGJeAAAAZc"]
[Thu Sep 17 15:38:37.958960 2026] [security2:error] [pid 18946:tid 19175] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/zeta.php"] [unique_id "aqxd3TqiPMah0Tz_U1O7MwAAAW0"]
[Thu Sep 17 15:38:37.959046 2026] [security2:error] [pid 18946:tid 19175] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/zeta.php"] [unique_id "aqxd3TqiPMah0Tz_U1O7MwAAAW0"]
[Thu Sep 17 15:38:38.132948 2026] [security2:error] [pid 20162:tid 20348] [client 34.154.220.126:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxd3q-O_Kk7aqBvaiGJfAAAAcY"]
[Thu Sep 17 15:38:38.263043 2026] [security2:error] [pid 18946:tid 19159] [client 34.95.173.223:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/old/phpinfo.php"] [unique_id "aqxd3jqiPMah0Tz_U1O7OAAAAV0"]
[Thu Sep 17 15:38:38.423797 2026] [security2:error] [pid 18946:tid 19161] [client 79.116.89.151:49779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd3jqiPMah0Tz_U1O7OgAAAV8"]
[Thu Sep 17 15:38:38.423918 2026] [security2:error] [pid 18946:tid 19161] [client 79.116.89.151:49779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd3jqiPMah0Tz_U1O7OgAAAV8"]
[Thu Sep 17 15:38:38.586492 2026] [security2:error] [pid 18946:tid 19178] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-content/upgrade/wp-firewall.php"] [unique_id "aqxd3jqiPMah0Tz_U1O7PwAAAXA"]
[Thu Sep 17 15:38:38.586602 2026] [security2:error] [pid 18946:tid 19178] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-content/upgrade/wp-firewall.php"] [unique_id "aqxd3jqiPMah0Tz_U1O7PwAAAXA"]
[Thu Sep 17 15:38:38.752089 2026] [security2:error] [pid 18946:tid 19127] [client 34.95.173.223:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxd3jqiPMah0Tz_U1O7QQAAAT0"]
[Thu Sep 17 15:38:38.804451 2026] [security2:error] [pid 18946:tid 19089] [client 34.154.220.126:38678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxd3jqiPMah0Tz_U1O7QgAAARc"]
[Thu Sep 17 15:38:39.179345 2026] [security2:error] [pid 18946:tid 19080] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-admin/includes/class-wp-site-list.php"] [unique_id "aqxd3zqiPMah0Tz_U1O7RwAAAQ4"]
[Thu Sep 17 15:38:39.179447 2026] [security2:error] [pid 18946:tid 19080] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-admin/includes/class-wp-site-list.php"] [unique_id "aqxd3zqiPMah0Tz_U1O7RwAAAQ4"]
[Thu Sep 17 15:38:39.244784 2026] [security2:error] [pid 18946:tid 19112] [client 34.95.173.223:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/public/phpinfo.php"] [unique_id "aqxd3zqiPMah0Tz_U1O7SAAAAS4"]
[Thu Sep 17 15:38:39.455444 2026] [security2:error] [pid 18946:tid 19176] [client 45.161.200.148:50199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd3zqiPMah0Tz_U1O7SgABbl0"]
[Thu Sep 17 15:38:39.461824 2026] [security2:error] [pid 18946:tid 19130] [client 34.154.220.126:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxd3zqiPMah0Tz_U1O7TQAAAUA"]
[Thu Sep 17 15:38:39.753082 2026] [security2:error] [pid 18946:tid 19146] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/text.php"] [unique_id "aqxd3zqiPMah0Tz_U1O7UwAAAVA"]
[Thu Sep 17 15:38:39.753163 2026] [security2:error] [pid 18946:tid 19146] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/text.php"] [unique_id "aqxd3zqiPMah0Tz_U1O7UwAAAVA"]
[Thu Sep 17 15:38:39.940332 2026] [security2:error] [pid 20162:tid 20390] [client 34.95.173.223:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/php-info.php"] [unique_id "aqxd36-O_Kk7aqBvaiGJiQAAAfA"]
[Thu Sep 17 15:38:40.112570 2026] [security2:error] [pid 20162:tid 20344] [client 34.154.220.126:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxd4K-O_Kk7aqBvaiGJiwAAAcI"]
[Thu Sep 17 15:38:40.315610 2026] [security2:error] [pid 18946:tid 19129] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/gif.php"] [unique_id "aqxd4DqiPMah0Tz_U1O7WwAAAT8"]
[Thu Sep 17 15:38:40.315697 2026] [security2:error] [pid 18946:tid 19129] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/gif.php"] [unique_id "aqxd4DqiPMah0Tz_U1O7WwAAAT8"]
[Thu Sep 17 15:38:40.453103 2026] [security2:error] [pid 18946:tid 19123] [client 34.95.173.223:54872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/phpversion.php"] [unique_id "aqxd4DqiPMah0Tz_U1O7XAAAATk"]
[Thu Sep 17 15:38:40.574699 2026] [security2:error] [pid 20162:tid 20312] [client 43.157.98.187:51230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.98.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intolovinghomes.com.au"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxd4K-O_Kk7aqBvaiGJjwAAAaI"]
[Thu Sep 17 15:38:40.670814 2026] [security2:error] [pid 20162:tid 20362] [client 34.154.220.126:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxd4K-O_Kk7aqBvaiGJkQAAAdQ"]
[Thu Sep 17 15:38:40.883093 2026] [security2:error] [pid 18946:tid 19202] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/ezfhylnt.php"] [unique_id "aqxd4DqiPMah0Tz_U1O7aAAAAYg"]
[Thu Sep 17 15:38:40.883177 2026] [security2:error] [pid 18946:tid 19202] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/ezfhylnt.php"] [unique_id "aqxd4DqiPMah0Tz_U1O7aAAAAYg"]
[Thu Sep 17 15:38:40.931062 2026] [security2:error] [pid 18946:tid 19096] [client 216.24.219.31:53357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/000.php"] [unique_id "aqxd4DqiPMah0Tz_U1O7aQAAAR4"]
[Thu Sep 17 15:38:40.941117 2026] [security2:error] [pid 18946:tid 19201] [client 34.95.173.223:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/_phpinfo.php"] [unique_id "aqxd4DqiPMah0Tz_U1O7agAAAYc"]
[Thu Sep 17 15:38:41.231600 2026] [security2:error] [pid 18946:tid 19132] [client 34.154.220.126:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxd4TqiPMah0Tz_U1O7cgAAAUI"]
[Thu Sep 17 15:38:41.274081 2026] [security2:error] [pid 20162:tid 20321] [client 193.36.224.113:20499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/about.php"] [unique_id "aqxd4a-O_Kk7aqBvaiGJlgAAAas"]
[Thu Sep 17 15:38:41.424573 2026] [security2:error] [pid 18946:tid 19161] [client 34.95.173.223:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/old_phpinfo.php"] [unique_id "aqxd4TqiPMah0Tz_U1O7eAAAAV8"]
[Thu Sep 17 15:38:41.439729 2026] [security2:error] [pid 20162:tid 20339] [client 103.61.184.148:50843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd4a-O_Kk7aqBvaiGJmQAAAb0"]
[Thu Sep 17 15:38:41.439924 2026] [security2:error] [pid 20162:tid 20339] [client 103.61.184.148:50843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd4a-O_Kk7aqBvaiGJmQAAAb0"]
[Thu Sep 17 15:38:41.446124 2026] [security2:error] [pid 20162:tid 20389] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/wp-X1s2e6h3p7.php"] [unique_id "aqxd4a-O_Kk7aqBvaiGJmgAAAe8"]
[Thu Sep 17 15:38:41.446221 2026] [security2:error] [pid 20162:tid 20389] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/wp-X1s2e6h3p7.php"] [unique_id "aqxd4a-O_Kk7aqBvaiGJmgAAAe8"]
[Thu Sep 17 15:38:41.636744 2026] [security2:error] [pid 18946:tid 19163] [client 216.24.219.100:41935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxd4TqiPMah0Tz_U1O7gAAAAWE"]
[Thu Sep 17 15:38:41.855389 2026] [security2:error] [pid 18946:tid 19162] [client 34.154.220.126:38730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxd4TqiPMah0Tz_U1O7gwAAAWA"]
[Thu Sep 17 15:38:41.857448 2026] [security2:error] [pid 18946:tid 19144] [client 193.36.224.152:22101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxd4TqiPMah0Tz_U1O7hQAAAU4"]
[Thu Sep 17 15:38:41.889154 2026] [security2:error] [pid 20162:tid 20323] [client 170.84.56.29:39144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd4a-O_Kk7aqBvaiGJnwABrVQ"]
[Thu Sep 17 15:38:41.926853 2026] [security2:error] [pid 18946:tid 19166] [client 34.95.173.223:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/server-info.php"] [unique_id "aqxd4TqiPMah0Tz_U1O7hwAAAWQ"]
[Thu Sep 17 15:38:42.041273 2026] [security2:error] [pid 18946:tid 19200] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/kuningshell.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7iQAAAYY"]
[Thu Sep 17 15:38:42.041365 2026] [security2:error] [pid 18946:tid 19200] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/kuningshell.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7iQAAAYY"]
[Thu Sep 17 15:38:42.097038 2026] [security2:error] [pid 18946:tid 19179] [client 193.36.224.221:60209] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7jAAAAXE"]
[Thu Sep 17 15:38:42.332667 2026] [security2:error] [pid 18946:tid 19125] [client 104.234.19.151:20133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7kQAAATs"]
[Thu Sep 17 15:38:42.400841 2026] [security2:error] [pid 18946:tid 19142] [client 34.154.220.126:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7kwAAAUw"]
[Thu Sep 17 15:38:42.428078 2026] [security2:error] [pid 18946:tid 19199] [client 74.7.241.133:56810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ivn.nmc.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxd4jqiPMah0Tz_U1O7lAAAAYU"]
[Thu Sep 17 15:38:42.428273 2026] [security2:error] [pid 18946:tid 19203] [client 34.95.173.223:54912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/server-status.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7lQAAAYk"]
[Thu Sep 17 15:38:42.570756 2026] [security2:error] [pid 18946:tid 19150] [client 193.36.224.108:32911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/bless.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7mAAAAVQ"]
[Thu Sep 17 15:38:42.624727 2026] [security2:error] [pid 20162:tid 20300] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/dream.php"] [unique_id "aqxd4q-O_Kk7aqBvaiGJpAAAAZY"]
[Thu Sep 17 15:38:42.624809 2026] [security2:error] [pid 20162:tid 20300] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/dream.php"] [unique_id "aqxd4q-O_Kk7aqBvaiGJpAAAAZY"]
[Thu Sep 17 15:38:42.760313 2026] [security2:error] [pid 18946:tid 19088] [client 136.158.61.34:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7mwAAARY"]
[Thu Sep 17 15:38:42.760410 2026] [security2:error] [pid 18946:tid 19088] [client 136.158.61.34:22221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7mwAAARY"]
[Thu Sep 17 15:38:42.805655 2026] [security2:error] [pid 18946:tid 19097] [client 104.234.19.150:45019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/goods.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7nQAAAR8"]
[Thu Sep 17 15:38:42.976213 2026] [security2:error] [pid 18946:tid 19193] [client 14.96.156.146:57136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7oQAAAX8"]
[Thu Sep 17 15:38:42.976364 2026] [security2:error] [pid 18946:tid 19193] [client 14.96.156.146:57136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd4jqiPMah0Tz_U1O7oQAAAX8"]
[Thu Sep 17 15:38:43.042206 2026] [security2:error] [pid 18946:tid 19123] [client 34.154.220.126:54872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7owAAATk"]
[Thu Sep 17 15:38:43.078256 2026] [security2:error] [pid 18946:tid 19145] [client 216.24.219.88:26577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/blurbs.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7pAAAAU8"]
[Thu Sep 17 15:38:43.204351 2026] [security2:error] [pid 18946:tid 19106] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/xkg.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7qAAAASg"]
[Thu Sep 17 15:38:43.204460 2026] [security2:error] [pid 18946:tid 19106] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/xkg.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7qAAAASg"]
[Thu Sep 17 15:38:43.254170 2026] [security2:error] [pid 18946:tid 19195] [client 34.95.173.223:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxd4zqiPMah0Tz_U1O7qQAAAYE"]
[Thu Sep 17 15:38:43.327350 2026] [security2:error] [pid 18946:tid 19185] [client 216.24.219.38:38467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7qgAAAXc"]
[Thu Sep 17 15:38:43.613273 2026] [security2:error] [pid 18946:tid 19114] [client 216.24.219.37:33201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/abcd.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7sQAAATA"]
[Thu Sep 17 15:38:43.670753 2026] [security2:error] [pid 18946:tid 19168] [client 161.35.164.148:52252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.openpathdental.com"] [uri "/index.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7pwABZgM"], referer: http://www.openpathdental.com/old/
[Thu Sep 17 15:38:43.682022 2026] [security2:error] [pid 18946:tid 19182] [client 34.154.220.126:54874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7sgAAAXQ"]
[Thu Sep 17 15:38:43.754385 2026] [security2:error] [pid 18946:tid 19170] [client 34.95.173.223:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7swAAAWg"]
[Thu Sep 17 15:38:43.780912 2026] [security2:error] [pid 20162:tid 20331] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/laki.php"] [unique_id "aqxd46-O_Kk7aqBvaiGJsAAAAbU"]
[Thu Sep 17 15:38:43.781017 2026] [security2:error] [pid 20162:tid 20331] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/laki.php"] [unique_id "aqxd46-O_Kk7aqBvaiGJsAAAAbU"]
[Thu Sep 17 15:38:43.914675 2026] [security2:error] [pid 18946:tid 19077] [client 216.24.219.104:24425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxd4zqiPMah0Tz_U1O7tgAAAQs"]
[Thu Sep 17 15:38:44.256008 2026] [security2:error] [pid 18946:tid 19190] [client 34.95.173.223:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxd5DqiPMah0Tz_U1O7wQAAAXw"]
[Thu Sep 17 15:38:44.331323 2026] [security2:error] [pid 18946:tid 19127] [client 34.154.220.126:54876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxd5DqiPMah0Tz_U1O7wwAAAT0"]
[Thu Sep 17 15:38:44.359566 2026] [security2:error] [pid 18946:tid 19151] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/flamini.php"] [unique_id "aqxd5DqiPMah0Tz_U1O7xAAAAVU"]
[Thu Sep 17 15:38:44.359727 2026] [security2:error] [pid 18946:tid 19151] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/flamini.php"] [unique_id "aqxd5DqiPMah0Tz_U1O7xAAAAVU"]
[Thu Sep 17 15:38:44.479537 2026] [security2:error] [pid 18946:tid 19144] [client 193.36.224.168:25453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/dex.php"] [unique_id "aqxd5DqiPMah0Tz_U1O7xwAAAU4"]
[Thu Sep 17 15:38:44.715914 2026] [security2:error] [pid 18946:tid 19146] [client 216.24.219.20:45319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxd5DqiPMah0Tz_U1O70gAAAVA"]
[Thu Sep 17 15:38:44.743935 2026] [security2:error] [pid 20162:tid 20352] [client 34.95.173.223:47352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxd5K-O_Kk7aqBvaiGJuQAAAco"]
[Thu Sep 17 15:38:44.902247 2026] [security2:error] [pid 20162:tid 20360] [client 34.154.220.126:54880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.220.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.hom.xcs.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxd5K-O_Kk7aqBvaiGJvAAAAdI"]
[Thu Sep 17 15:38:44.945099 2026] [security2:error] [pid 18946:tid 19172] [client 4.224.45.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.45.224.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.marinacontroller.com"] [uri "/xstelth.php"] [unique_id "aqxd5DqiPMah0Tz_U1O71gAAAWo"]
[Thu Sep 17 15:38:44.945198 2026] [security2:error] [pid 18946:tid 19172] [client 4.224.45.129:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dev.marinacontroller.com"] [uri "/xstelth.php"] [unique_id "aqxd5DqiPMah0Tz_U1O71gAAAWo"]
[Thu Sep 17 15:38:44.961248 2026] [security2:error] [pid 20162:tid 20326] [client 193.36.224.148:61371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxd5K-O_Kk7aqBvaiGJvQAAAbA"]
[Thu Sep 17 15:38:45.133739 2026] [security2:error] [pid 18946:tid 19121] [client 161.35.164.148:52252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.openpathdental.com"] [uri "/index.php"] [unique_id "aqxd5DqiPMah0Tz_U1O70wABNxo"], referer: http://www.openpathdental.com/wordpress/
[Thu Sep 17 15:38:45.241000 2026] [security2:error] [pid 18946:tid 19199] [client 34.95.173.223:47364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxd5TqiPMah0Tz_U1O73AAAAYU"]
[Thu Sep 17 15:38:45.289979 2026] [security2:error] [pid 18946:tid 19134] [client 177.44.133.72:61744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd5TqiPMah0Tz_U1O73gAAAUQ"]
[Thu Sep 17 15:38:45.290107 2026] [security2:error] [pid 18946:tid 19134] [client 177.44.133.72:61744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd5TqiPMah0Tz_U1O73gAAAUQ"]
[Thu Sep 17 15:38:45.371131 2026] [security2:error] [pid 18946:tid 19088] [client 193.36.224.169:40659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/index.php"] [unique_id "aqxd5TqiPMah0Tz_U1O73wAAARY"]
[Thu Sep 17 15:38:45.647322 2026] [security2:error] [pid 18946:tid 19160] [client 193.36.224.221:34441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxd5TqiPMah0Tz_U1O75gAAAV4"]
[Thu Sep 17 15:38:45.730644 2026] [security2:error] [pid 18946:tid 19133] [client 34.95.173.223:47368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxd5TqiPMah0Tz_U1O76AAAAUM"]
[Thu Sep 17 15:38:45.812737 2026] [security2:error] [pid 18946:tid 19084] [client 161.35.164.148:52252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.openpathdental.com"] [uri "/index.php"] [unique_id "aqxd5TqiPMah0Tz_U1O74AABEhs"], referer: http://www.openpathdental.com/backup/
[Thu Sep 17 15:38:45.883626 2026] [security2:error] [pid 18946:tid 19100] [client 104.234.19.144:60193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/index.php"] [unique_id "aqxd5TqiPMah0Tz_U1O76wAAASI"]
[Thu Sep 17 15:38:46.220682 2026] [security2:error] [pid 18946:tid 19124] [client 34.95.173.223:47382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxd5jqiPMah0Tz_U1O79gAAATo"]
[Thu Sep 17 15:38:46.253812 2026] [security2:error] [pid 18946:tid 19093] [client 193.36.224.213:35895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxd5jqiPMah0Tz_U1O79wAAARs"]
[Thu Sep 17 15:38:46.504761 2026] [security2:error] [pid 18946:tid 19202] [client 161.35.164.148:52252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.openpathdental.com"] [uri "/index.php"] [unique_id "aqxd5jqiPMah0Tz_U1O78gABiA8"], referer: http://www.openpathdental.com/blog/
[Thu Sep 17 15:38:46.636501 2026] [security2:error] [pid 18946:tid 19077] [client 193.36.224.149:57697] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/file.php"] [unique_id "aqxd5jqiPMah0Tz_U1O7_wAAAQs"]
[Thu Sep 17 15:38:46.710942 2026] [security2:error] [pid 20162:tid 20379] [client 34.95.173.223:47394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/phpinfo.php.old"] [unique_id "aqxd5q-O_Kk7aqBvaiGJ0QAAAeU"]
[Thu Sep 17 15:38:46.879201 2026] [security2:error] [pid 18946:tid 19154] [client 193.36.224.226:49095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxd5jqiPMah0Tz_U1O8BwAAAVg"]
[Thu Sep 17 15:38:47.187655 2026] [security2:error] [pid 18946:tid 19105] [client 193.36.224.152:64779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-mail.php"] [unique_id "aqxd5zqiPMah0Tz_U1O8DwAAASc"]
[Thu Sep 17 15:38:47.187818 2026] [security2:error] [pid 18946:tid 19153] [client 161.35.164.148:52252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.openpathdental.com"] [uri "/index.php"] [unique_id "aqxd5jqiPMah0Tz_U1O8BgABVws"], referer: http://www.openpathdental.com/wp/
[Thu Sep 17 15:38:47.194297 2026] [security2:error] [pid 18946:tid 19112] [client 34.95.173.223:47406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/phpinfo.php~"] [unique_id "aqxd5zqiPMah0Tz_U1O8EAAAAS4"]
[Thu Sep 17 15:38:47.528260 2026] [security2:error] [pid 18946:tid 19083] [client 193.36.224.149:24869] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/ioxi-o.php"] [unique_id "aqxd5zqiPMah0Tz_U1O8GgAAARE"]
[Thu Sep 17 15:38:47.691342 2026] [security2:error] [pid 18946:tid 19197] [client 34.95.173.223:47420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/info.php.bak"] [unique_id "aqxd5zqiPMah0Tz_U1O8HgAAAYM"]
[Thu Sep 17 15:38:47.772695 2026] [security2:error] [pid 20162:tid 20417] [client 216.24.219.38:29469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxd56-O_Kk7aqBvaiGJ2QAAAgs"]
[Thu Sep 17 15:38:47.880955 2026] [security2:error] [pid 18946:tid 19143] [client 161.35.164.148:52252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.openpathdental.com"] [uri "/index.php"] [unique_id "aqxd5zqiPMah0Tz_U1O8FwABTRQ"], referer: http://www.openpathdental.com/new/
[Thu Sep 17 15:38:48.001277 2026] [security2:error] [pid 18946:tid 19090] [client 216.24.219.89:40719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/style.php"] [unique_id "aqxd6DqiPMah0Tz_U1O8IwAAARg"]
[Thu Sep 17 15:38:48.175271 2026] [security2:error] [pid 18946:tid 19134] [client 34.95.173.223:47436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/phpinfo.php.save"] [unique_id "aqxd6DqiPMah0Tz_U1O8KwAAAUQ"]
[Thu Sep 17 15:38:48.181161 2026] [security2:error] [pid 18946:tid 19101] [client 143.105.152.240:11514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd6DqiPMah0Tz_U1O8LAAAASM"]
[Thu Sep 17 15:38:48.188803 2026] [security2:error] [pid 18946:tid 19101] [client 143.105.152.240:11514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd6DqiPMah0Tz_U1O8LAAAASM"]
[Thu Sep 17 15:38:48.232844 2026] [security2:error] [pid 18946:tid 19167] [client 193.36.224.156:52279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/style.php"] [unique_id "aqxd6DqiPMah0Tz_U1O8LgAAAWU"]
[Thu Sep 17 15:38:48.285039 2026] [security2:error] [pid 18946:tid 19110] [client 34.166.134.22:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/phpinfo.php"] [unique_id "aqxd6DqiPMah0Tz_U1O8LwAAASw"]
[Thu Sep 17 15:38:48.539082 2026] [security2:error] [pid 18946:tid 19128] [client 193.36.224.150:23339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxd6DqiPMah0Tz_U1O8MQAAAT4"]
[Thu Sep 17 15:38:48.664713 2026] [security2:error] [pid 18946:tid 19104] [client 34.95.173.223:47440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxd6DqiPMah0Tz_U1O8NQAAASY"]
[Thu Sep 17 15:38:48.965564 2026] [security2:error] [pid 20162:tid 20377] [client 34.166.134.22:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/info.php"] [unique_id "aqxd6K-O_Kk7aqBvaiGJ5QAAAeM"]
[Thu Sep 17 15:38:49.020950 2026] [security2:error] [pid 18946:tid 19159] [client 79.116.89.151:50402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd6TqiPMah0Tz_U1O8NwAAAV0"]
[Thu Sep 17 15:38:49.021509 2026] [security2:error] [pid 18946:tid 19159] [client 79.116.89.151:50402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd6TqiPMah0Tz_U1O8NwAAAV0"]
[Thu Sep 17 15:38:49.155806 2026] [security2:error] [pid 18946:tid 19119] [client 34.95.173.223:47448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxd6TqiPMah0Tz_U1O8OAAAATU"]
[Thu Sep 17 15:38:49.388631 2026] [security2:error] [pid 18946:tid 19195] [client 213.230.78.87:64821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd6TqiPMah0Tz_U1O8OwABgQU"]
[Thu Sep 17 15:38:49.646875 2026] [security2:error] [pid 18946:tid 19168] [client 34.166.134.22:55710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/php.php"] [unique_id "aqxd6TqiPMah0Tz_U1O8QwAAAWY"]
[Thu Sep 17 15:38:49.647226 2026] [security2:error] [pid 18946:tid 19077] [client 34.95.173.223:47464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxd6TqiPMah0Tz_U1O8RAAAAQs"]
[Thu Sep 17 15:38:49.824005 2026] [security2:error] [pid 18946:tid 19154] [client 193.36.224.148:60903] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-editor.php"] [unique_id "aqxd6TqiPMah0Tz_U1O8SAAAAVg"]
[Thu Sep 17 15:38:50.084168 2026] [security2:error] [pid 18946:tid 19163] [client 193.36.224.220:58285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/lufix.php"] [unique_id "aqxd6jqiPMah0Tz_U1O8SgAAAWE"]
[Thu Sep 17 15:38:50.130716 2026] [security2:error] [pid 20162:tid 20375] [client 34.95.173.223:47470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxd6q-O_Kk7aqBvaiGJ9QAAAeE"]
[Thu Sep 17 15:38:50.339891 2026] [security2:error] [pid 20162:tid 20393] [client 34.166.134.22:53452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/i.php"] [unique_id "aqxd6q-O_Kk7aqBvaiGJ-AAAAfM"]
[Thu Sep 17 15:38:50.435835 2026] [security2:error] [pid 18946:tid 19130] [client 193.36.224.156:47077] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/txets.php"] [unique_id "aqxd6jqiPMah0Tz_U1O8UAAAAUA"]
[Thu Sep 17 15:38:50.614932 2026] [security2:error] [pid 20162:tid 20416] [client 34.95.173.223:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxd6q-O_Kk7aqBvaiGJ-wAAAgo"]
[Thu Sep 17 15:38:50.706091 2026] [security2:error] [pid 18946:tid 19087] [client 104.234.19.150:55177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxd6jqiPMah0Tz_U1O8VAAAARU"]
[Thu Sep 17 15:38:50.884695 2026] [security2:error] [pid 18946:tid 19083] [client 134.185.85.61:62406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxd6jqiPMah0Tz_U1O8VgAAARE"]
[Thu Sep 17 15:38:50.966684 2026] [security2:error] [pid 18946:tid 19197] [client 193.36.224.221:55395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxd6jqiPMah0Tz_U1O8VwAAAYM"]
[Thu Sep 17 15:38:51.024075 2026] [security2:error] [pid 18946:tid 19118] [client 34.166.134.22:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/pi.php"] [unique_id "aqxd6zqiPMah0Tz_U1O8WAAAATQ"]
[Thu Sep 17 15:38:51.099516 2026] [security2:error] [pid 18946:tid 19138] [client 34.95.173.223:47482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/www/phpinfo.php"] [unique_id "aqxd6zqiPMah0Tz_U1O8WgAAAUg"]
[Thu Sep 17 15:38:51.266508 2026] [security2:error] [pid 18946:tid 19079] [client 134.185.85.61:63244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sableandox.co.uk"] [uri "/media/system/js/core.js"] [unique_id "aqxd6zqiPMah0Tz_U1O8YAAAAQ0"]
[Thu Sep 17 15:38:51.291366 2026] [security2:error] [pid 18946:tid 19097] [client 193.36.224.213:22241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxd6zqiPMah0Tz_U1O8YgAAAR8"]
[Thu Sep 17 15:38:51.326027 2026] [security2:error] [pid 18946:tid 19200] [client 84.33.142.45:22540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd6zqiPMah0Tz_U1O8XgABhiU"]
[Thu Sep 17 15:38:51.585982 2026] [security2:error] [pid 20162:tid 20388] [client 34.95.173.223:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxd66-O_Kk7aqBvaiGKAQAAAe4"]
[Thu Sep 17 15:38:51.689760 2026] [security2:error] [pid 18946:tid 19157] [client 216.24.219.35:22219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/goods.php"] [unique_id "aqxd6zqiPMah0Tz_U1O8ZgAAAVs"]
[Thu Sep 17 15:38:51.713760 2026] [security2:error] [pid 18946:tid 19094] [client 34.166.134.22:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/pinfo.php"] [unique_id "aqxd6zqiPMah0Tz_U1O8aQAAARw"]
[Thu Sep 17 15:38:51.906147 2026] [security2:error] [pid 18946:tid 19152] [client 216.24.219.32:38529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "sqlerudition.com"] [uri "/php8.php"] [unique_id "aqxd6zqiPMah0Tz_U1O8bQAAAVY"]
[Thu Sep 17 15:38:52.074898 2026] [security2:error] [pid 18946:tid 19113] [client 34.95.173.223:47494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8bgAAAS8"]
[Thu Sep 17 15:38:52.294079 2026] [security2:error] [pid 18946:tid 19119] [client 103.61.184.148:51423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8dQAAATU"]
[Thu Sep 17 15:38:52.294199 2026] [security2:error] [pid 18946:tid 19119] [client 103.61.184.148:51423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8dQAAATU"]
[Thu Sep 17 15:38:52.294356 2026] [security2:error] [pid 18946:tid 19000] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/.env"] [unique_id "aqxd7DqiPMah0Tz_U1O8dgABfDU"]
[Thu Sep 17 15:38:52.405234 2026] [security2:error] [pid 20162:tid 20307] [client 34.166.134.22:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/test.php"] [unique_id "aqxd7K-O_Kk7aqBvaiGKBgAAAZ0"]
[Thu Sep 17 15:38:52.568354 2026] [security2:error] [pid 20162:tid 20363] [client 34.95.173.223:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/site/phpinfo.php"] [unique_id "aqxd7K-O_Kk7aqBvaiGKCAAAAdU"]
[Thu Sep 17 15:38:52.847040 2026] [security2:error] [pid 18946:tid 19027] [remote 74.220.219.26:11300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafiqco-net.gocbeglobal.com"] [uri "/wp-login.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8hAABUlA"]
[Thu Sep 17 15:38:52.887976 2026] [security2:error] [pid 18946:tid 19019] [remote 74.220.219.26:11316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rafiqco-net.gocbeglobal.com"] [uri "/wp-login.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8hgABTkg"]
[Thu Sep 17 15:38:52.892529 2026] [security2:error] [pid 18946:tid 18995] [remote 74.220.219.26:11324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafiqco-net.gocbeglobal.com"] [uri "/xmlrpc.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8hwABMTA"]
[Thu Sep 17 15:38:52.904782 2026] [security2:error] [pid 18946:tid 19081] [client 69.57.248.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8ggAAAQ8"]
[Thu Sep 17 15:38:52.909983 2026] [security2:error] [pid 18946:tid 19003] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/.env.bak"] [unique_id "aqxd7DqiPMah0Tz_U1O8iAABVzg"]
[Thu Sep 17 15:38:52.918435 2026] [security2:error] [pid 20162:tid 20374] [client 69.57.248.16:50034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxd7K-O_Kk7aqBvaiGKCgAB4FA"]
[Thu Sep 17 15:38:52.918900 2026] [security2:error] [pid 20162:tid 20374] [client 69.57.248.16:50034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxd7K-O_Kk7aqBvaiGKCwAB4EY"]
[Thu Sep 17 15:38:52.953821 2026] [security2:error] [pid 18946:tid 19022] [remote 74.220.219.26:11332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rafiqco-net.gocbeglobal.com"] [uri "/xmlrpc.php"] [unique_id "aqxd7DqiPMah0Tz_U1O8iQABOEs"]
[Thu Sep 17 15:38:52.997265 2026] [security2:error] [pid 18946:tid 19016] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/.env.backup"] [unique_id "aqxd7DqiPMah0Tz_U1O8igABgEU"]
[Thu Sep 17 15:38:53.061492 2026] [security2:error] [pid 20162:tid 20332] [client 34.95.173.223:47518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxd7a-O_Kk7aqBvaiGKDwAAAbY"]
[Thu Sep 17 15:38:53.178712 2026] [security2:error] [pid 18946:tid 19004] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/.env.old"] [unique_id "aqxd7TqiPMah0Tz_U1O8jQABWjk"]
[Thu Sep 17 15:38:53.343025 2026] [security2:error] [pid 18946:tid 19176] [client 34.166.134.22:53486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/p.php"] [unique_id "aqxd7TqiPMah0Tz_U1O8lAAAAW4"]
[Thu Sep 17 15:38:53.564583 2026] [security2:error] [pid 18946:tid 19150] [client 34.95.173.223:47526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxd7TqiPMah0Tz_U1O8mwAAAVQ"]
[Thu Sep 17 15:38:53.575693 2026] [security2:error] [pid 20162:tid 20317] [client 14.96.156.146:57893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd7a-O_Kk7aqBvaiGKFwAAAac"]
[Thu Sep 17 15:38:53.575834 2026] [security2:error] [pid 20162:tid 20317] [client 14.96.156.146:57893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd7a-O_Kk7aqBvaiGKFwAAAac"]
[Thu Sep 17 15:38:53.722567 2026] [security2:error] [pid 18946:tid 19079] [client 69.57.248.16:64537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxd7TqiPMah0Tz_U1O8nQABDUk"]
[Thu Sep 17 15:38:53.723208 2026] [security2:error] [pid 18946:tid 19079] [client 69.57.248.16:64537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxd7TqiPMah0Tz_U1O8nAABDS0"]
[Thu Sep 17 15:38:54.039825 2026] [security2:error] [pid 20162:tid 20297] [client 34.166.134.22:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/debug.php"] [unique_id "aqxd7q-O_Kk7aqBvaiGKGwAAAZM"]
[Thu Sep 17 15:38:54.053165 2026] [security2:error] [pid 20162:tid 20320] [client 34.95.173.223:35598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxd7q-O_Kk7aqBvaiGKHAAAAao"]
[Thu Sep 17 15:38:54.057386 2026] [core:error] [pid 18946:tid 19094] [client 172.86.81.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://test.jcktax.com/.git/config
[Thu Sep 17 15:38:54.057401 2026] [core:error] [pid 18946:tid 19094] [client 172.86.81.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://test.jcktax.com/.git/config
[Thu Sep 17 15:38:54.214340 2026] [security2:error] [pid 18946:tid 19001] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/.env.swp"] [unique_id "aqxd7jqiPMah0Tz_U1O8tgABKDY"]
[Thu Sep 17 15:38:54.299267 2026] [security2:error] [pid 18946:tid 19063] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/.env~"] [unique_id "aqxd7jqiPMah0Tz_U1O8twABXHQ"]
[Thu Sep 17 15:38:54.541854 2026] [security2:error] [pid 18946:tid 19202] [client 34.95.173.223:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/core/phpinfo.php"] [unique_id "aqxd7jqiPMah0Tz_U1O8vAAAAYg"]
[Thu Sep 17 15:38:54.720473 2026] [security2:error] [pid 18946:tid 19109] [client 34.166.134.22:53512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxd7jqiPMah0Tz_U1O8wgAAASs"]
[Thu Sep 17 15:38:54.888729 2026] [security2:error] [pid 18946:tid 19189] [client 193.36.224.182:53317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/000.php"] [unique_id "aqxd7jqiPMah0Tz_U1O8yQAAAXs"]
[Thu Sep 17 15:38:54.980854 2026] [security2:error] [pid 18946:tid 19017] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/app/.env"] [unique_id "aqxd7jqiPMah0Tz_U1O8zQABYUY"]
[Thu Sep 17 15:38:55.036343 2026] [security2:error] [pid 18946:tid 19174] [client 34.95.173.223:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.173.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.chriswestlake.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxd7zqiPMah0Tz_U1O8zgAAAWw"]
[Thu Sep 17 15:38:55.067247 2026] [security2:error] [pid 18946:tid 19052] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/apps/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O8zwABYmk"]
[Thu Sep 17 15:38:55.160580 2026] [security2:error] [pid 18946:tid 18976] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/api/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O80AABVR0"]
[Thu Sep 17 15:38:55.183761 2026] [security2:error] [pid 18946:tid 19112] [client 216.24.219.101:30143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/about.php"] [unique_id "aqxd7zqiPMah0Tz_U1O80gAAAS4"]
[Thu Sep 17 15:38:55.240379 2026] [security2:error] [pid 18946:tid 19060] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/web/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O81wABcHE"]
[Thu Sep 17 15:38:55.326801 2026] [security2:error] [pid 18946:tid 19029] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/site/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O82gABdVI"]
[Thu Sep 17 15:38:55.403602 2026] [security2:error] [pid 18946:tid 19126] [client 34.166.134.22:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/test/phpinfo.php"] [unique_id "aqxd7zqiPMah0Tz_U1O83gAAATw"]
[Thu Sep 17 15:38:55.413124 2026] [security2:error] [pid 18946:tid 19018] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/public/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O83wABbkc"]
[Thu Sep 17 15:38:55.466863 2026] [security2:error] [pid 20162:tid 20328] [client 104.234.19.144:23057] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxd76-O_Kk7aqBvaiGKKAAAAbI"]
[Thu Sep 17 15:38:55.597252 2026] [security2:error] [pid 18946:tid 19011] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/backend/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O84gABb0A"]
[Thu Sep 17 15:38:55.683193 2026] [security2:error] [pid 18946:tid 19073] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/server/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O85gABF34"]
[Thu Sep 17 15:38:55.729150 2026] [security2:error] [pid 20162:tid 20339] [client 193.36.224.156:60579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxd76-O_Kk7aqBvaiGKLgAAAb0"]
[Thu Sep 17 15:38:55.767558 2026] [security2:error] [pid 18946:tid 19032] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/frontend/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O86QABhlU"]
[Thu Sep 17 15:38:55.859470 2026] [security2:error] [pid 18946:tid 19070] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/src/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O86wABRHs"]
[Thu Sep 17 15:38:55.942444 2026] [security2:error] [pid 20162:tid 20350] [client 177.44.133.72:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd76-O_Kk7aqBvaiGKMgAAAcg"]
[Thu Sep 17 15:38:55.942889 2026] [security2:error] [pid 20162:tid 20350] [client 177.44.133.72:62402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd76-O_Kk7aqBvaiGKMgAAAcg"]
[Thu Sep 17 15:38:55.943121 2026] [security2:error] [pid 18946:tid 19026] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/core/.env"] [unique_id "aqxd7zqiPMah0Tz_U1O87gABFk8"]
[Thu Sep 17 15:38:56.030819 2026] [security2:error] [pid 18946:tid 18987] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/core/app/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O87wABWSg"]
[Thu Sep 17 15:38:56.087392 2026] [security2:error] [pid 18946:tid 19086] [client 193.36.224.116:58069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxd8DqiPMah0Tz_U1O88QAAARQ"]
[Thu Sep 17 15:38:56.092083 2026] [security2:error] [pid 18946:tid 19101] [client 34.166.134.22:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/dev/phpinfo.php"] [unique_id "aqxd8DqiPMah0Tz_U1O88gAAASM"]
[Thu Sep 17 15:38:56.112643 2026] [security2:error] [pid 18946:tid 19028] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/config/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O88wABg1E"]
[Thu Sep 17 15:38:56.176623 2026] [security2:error] [pid 20162:tid 20387] [client 136.158.61.34:23407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd8K-O_Kk7aqBvaiGKNQAAAe0"]
[Thu Sep 17 15:38:56.176798 2026] [security2:error] [pid 20162:tid 20387] [client 136.158.61.34:23407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd8K-O_Kk7aqBvaiGKNQAAAe0"]
[Thu Sep 17 15:38:56.197460 2026] [security2:error] [pid 18946:tid 19066] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/private/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O89AABaXc"]
[Thu Sep 17 15:38:56.285675 2026] [security2:error] [pid 18946:tid 18957] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/application/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O8-gABJgo"]
[Thu Sep 17 15:38:56.322411 2026] [security2:error] [pid 18946:tid 19093] [client 193.36.224.226:61769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxd8DqiPMah0Tz_U1O8-wAAARs"]
[Thu Sep 17 15:38:56.368755 2026] [security2:error] [pid 18946:tid 18961] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/bootstrap/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O8_AABPg4"]
[Thu Sep 17 15:38:56.467225 2026] [security2:error] [pid 18946:tid 19048] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/database/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O8_gABemU"]
[Thu Sep 17 15:38:56.568493 2026] [security2:error] [pid 18946:tid 19038] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/storage/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O9AQABHls"]
[Thu Sep 17 15:38:56.611450 2026] [security2:error] [pid 18946:tid 19131] [client 193.36.224.206:57387] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/bless.php"] [unique_id "aqxd8DqiPMah0Tz_U1O9AwAAAUE"]
[Thu Sep 17 15:38:56.657417 2026] [security2:error] [pid 18946:tid 19039] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/var/www/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O9BAABgVw"]
[Thu Sep 17 15:38:56.739499 2026] [security2:error] [pid 20162:tid 20323] [client 44.239.144.77:50457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxd8K-O_Kk7aqBvaiGKOwAAAa0"], referer: http://worthtranslations.com/2022
[Thu Sep 17 15:38:56.741439 2026] [security2:error] [pid 18946:tid 19042] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/var/www/html/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O9CAABiF8"]
[Thu Sep 17 15:38:56.790172 2026] [security2:error] [pid 20162:tid 20345] [client 34.166.134.22:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/old/phpinfo.php"] [unique_id "aqxd8K-O_Kk7aqBvaiGKQAAAAcM"]
[Thu Sep 17 15:38:56.829293 2026] [security2:error] [pid 18946:tid 19055] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/current/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O9CgABK2w"]
[Thu Sep 17 15:38:56.864791 2026] [security2:error] [pid 18946:tid 19108] [client 104.234.19.143:31239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/goods.php"] [unique_id "aqxd8DqiPMah0Tz_U1O9CwAAASo"]
[Thu Sep 17 15:38:56.914872 2026] [security2:error] [pid 18946:tid 19041] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/release/.env"] [unique_id "aqxd8DqiPMah0Tz_U1O9DgABC14"]
[Thu Sep 17 15:38:57.006647 2026] [security2:error] [pid 18946:tid 18960] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/releases/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9DwABew0"]
[Thu Sep 17 15:38:57.092680 2026] [security2:error] [pid 20162:tid 20354] [client 216.24.219.31:44275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/blurbs.php"] [unique_id "aqxd8a-O_Kk7aqBvaiGKRAAAAcw"]
[Thu Sep 17 15:38:57.102703 2026] [security2:error] [pid 18946:tid 19069] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/shared/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9EQABXno"]
[Thu Sep 17 15:38:57.188514 2026] [security2:error] [pid 18946:tid 19064] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/deploy/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9EgABM3U"]
[Thu Sep 17 15:38:57.288425 2026] [security2:error] [pid 18946:tid 19030] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/build/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9GAABVVM"]
[Thu Sep 17 15:38:57.351281 2026] [security2:error] [pid 18946:tid 19112] [client 104.234.19.146:35895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxd8TqiPMah0Tz_U1O9GQAAAS4"]
[Thu Sep 17 15:38:57.386427 2026] [security2:error] [pid 18946:tid 19065] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/dist/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9GgABV3Y"]
[Thu Sep 17 15:38:57.473240 2026] [security2:error] [pid 18946:tid 18998] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/public_html/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9HAABJzM"]
[Thu Sep 17 15:38:57.480322 2026] [security2:error] [pid 18946:tid 19124] [client 34.166.134.22:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/tmp/phpinfo.php"] [unique_id "aqxd8TqiPMah0Tz_U1O9HQAAATo"]
[Thu Sep 17 15:38:57.554989 2026] [security2:error] [pid 18946:tid 18950] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/htdocs/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9HgABQAM"]
[Thu Sep 17 15:38:57.575941 2026] [security2:error] [pid 18946:tid 19102] [client 104.234.19.143:24451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/abcd.php"] [unique_id "aqxd8TqiPMah0Tz_U1O9HwAAASQ"]
[Thu Sep 17 15:38:57.637224 2026] [security2:error] [pid 18946:tid 18963] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/www/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9IQABcBA"]
[Thu Sep 17 15:38:57.727003 2026] [security2:error] [pid 18946:tid 18955] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/html/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9JgABYAg"]
[Thu Sep 17 15:38:57.812749 2026] [security2:error] [pid 18946:tid 18999] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/live/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9KgABNDQ"]
[Thu Sep 17 15:38:57.894836 2026] [security2:error] [pid 18946:tid 19056] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/prod/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9KwABb20"]
[Thu Sep 17 15:38:57.975357 2026] [security2:error] [pid 18946:tid 19127] [client 193.36.224.149:27095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxd8TqiPMah0Tz_U1O9LAAAAT0"]
[Thu Sep 17 15:38:57.980313 2026] [security2:error] [pid 18946:tid 18972] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/dev/.env"] [unique_id "aqxd8TqiPMah0Tz_U1O9LQABUxk"]
[Thu Sep 17 15:38:58.064848 2026] [security2:error] [pid 18946:tid 18985] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/staging/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9LgABRiY"]
[Thu Sep 17 15:38:58.150521 2026] [security2:error] [pid 18946:tid 18973] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/opt/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9MQABFxo"]
[Thu Sep 17 15:38:58.164520 2026] [security2:error] [pid 20162:tid 20363] [client 34.166.134.22:53548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/public/phpinfo.php"] [unique_id "aqxd8q-O_Kk7aqBvaiGKTQAAAdU"]
[Thu Sep 17 15:38:58.235773 2026] [security2:error] [pid 18946:tid 19074] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/laravel/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9MwABTX8"]
[Thu Sep 17 15:38:58.341811 2026] [security2:error] [pid 18946:tid 18974] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/symfony/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9NQABhhs"]
[Thu Sep 17 15:38:58.424485 2026] [security2:error] [pid 18946:tid 18948] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/wordpress/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9OAABTAE"]
[Thu Sep 17 15:38:58.521622 2026] [security2:error] [pid 18946:tid 18962] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/wp/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9PAABFg8"]
[Thu Sep 17 15:38:58.592350 2026] [security2:error] [pid 18946:tid 19194] [client 181.78.100.181:43311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxd8jqiPMah0Tz_U1O9NwAAAYA"], referer: https://thebulkdachecker.store/dir/powerful-seo-backlinks-47403
[Thu Sep 17 15:38:58.604825 2026] [security2:error] [pid 18946:tid 19062] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/cms/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9QAABWXM"]
[Thu Sep 17 15:38:58.663090 2026] [security2:error] [pid 20162:tid 20330] [client 74.0.96.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxd8q-O_Kk7aqBvaiGKUwAAAbQ"]
[Thu Sep 17 15:38:58.694543 2026] [security2:error] [pid 18946:tid 18966] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/drupal/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9QQABFBM"]
[Thu Sep 17 15:38:58.786183 2026] [security2:error] [pid 18946:tid 18959] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/joomla/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9RwABIgw"]
[Thu Sep 17 15:38:58.833870 2026] [security2:error] [pid 20162:tid 20348] [client 143.105.152.240:12683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd8q-O_Kk7aqBvaiGKWQAAAcY"]
[Thu Sep 17 15:38:58.834087 2026] [security2:error] [pid 20162:tid 20348] [client 143.105.152.240:12683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd8q-O_Kk7aqBvaiGKWQAAAcY"]
[Thu Sep 17 15:38:58.874581 2026] [security2:error] [pid 18946:tid 19071] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/magento/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9SQABPnw"]
[Thu Sep 17 15:38:58.880853 2026] [security2:error] [pid 18946:tid 19094] [client 216.24.219.105:53221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/dex.php"] [unique_id "aqxd8jqiPMah0Tz_U1O9SgAAARw"]
[Thu Sep 17 15:38:58.960323 2026] [security2:error] [pid 18946:tid 18967] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/shopify/.env"] [unique_id "aqxd8jqiPMah0Tz_U1O9SwABEBQ"]
[Thu Sep 17 15:38:59.048619 2026] [security2:error] [pid 18946:tid 19044] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/prestashop/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9TwABemE"]
[Thu Sep 17 15:38:59.086154 2026] [security2:error] [pid 18946:tid 19114] [client 34.166.134.22:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/php-info.php"] [unique_id "aqxd8zqiPMah0Tz_U1O9UAAAATA"]
[Thu Sep 17 15:38:59.108176 2026] [security2:error] [pid 18946:tid 19140] [client 193.36.224.156:30505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxd8zqiPMah0Tz_U1O9UQAAAUo"]
[Thu Sep 17 15:38:59.149877 2026] [security2:error] [pid 18946:tid 18949] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/codeigniter/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9UgABgQI"]
[Thu Sep 17 15:38:59.266853 2026] [security2:error] [pid 18946:tid 18994] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/cakephp/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9VgABEi8"]
[Thu Sep 17 15:38:59.310217 2026] [security2:error] [pid 20162:tid 20344] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "dbtrc.com"] [uri "/"] [unique_id "aqxd86-O_Kk7aqBvaiGKXwAAAcI"]
[Thu Sep 17 15:38:59.315757 2026] [security2:error] [pid 18946:tid 19108] [client 34.0.12.64:36238] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "dbtrc.com"] [uri "/"] [unique_id "aqxd8zqiPMah0Tz_U1O9VwAAASo"]
[Thu Sep 17 15:38:59.351670 2026] [security2:error] [pid 20162:tid 20326] [client 160.119.76.210:33226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "162.241.225.249"] [uri "/html/admin/config.php"] [unique_id "aqxd86-O_Kk7aqBvaiGKYQAAAbA"]
[Thu Sep 17 15:38:59.358527 2026] [security2:error] [pid 18946:tid 18988] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/zend/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9WgABCyk"]
[Thu Sep 17 15:38:59.446609 2026] [security2:error] [pid 18946:tid 18970] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/yii/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9WwABSxc"]
[Thu Sep 17 15:38:59.464736 2026] [fcgid:warn] [pid 18946:tid 19196] (70014)End of file found: [client 165.154.187.159:40176] mod_fcgid: can't get data from http client
[Thu Sep 17 15:38:59.529826 2026] [security2:error] [pid 18946:tid 18979] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/laravel5/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9XQABLyA"]
[Thu Sep 17 15:38:59.614679 2026] [security2:error] [pid 18946:tid 19037] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/v1/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9XgABclo"]
[Thu Sep 17 15:38:59.650286 2026] [security2:error] [pid 20162:tid 20302] [client 79.116.89.151:51021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd86-O_Kk7aqBvaiGKYwAAAZg"]
[Thu Sep 17 15:38:59.650458 2026] [security2:error] [pid 20162:tid 20302] [client 79.116.89.151:51021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd86-O_Kk7aqBvaiGKYwAAAZg"]
[Thu Sep 17 15:38:59.698649 2026] [security2:error] [pid 18946:tid 18982] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/v2/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9YgABYiM"]
[Thu Sep 17 15:38:59.729125 2026] [security2:error] [pid 18946:tid 19115] [client 193.36.224.206:46051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxd8zqiPMah0Tz_U1O9ZQAAATE"]
[Thu Sep 17 15:38:59.774801 2026] [security2:error] [pid 18946:tid 19120] [client 34.166.134.22:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/phpversion.php"] [unique_id "aqxd8zqiPMah0Tz_U1O9ZgAAATY"]
[Thu Sep 17 15:38:59.803844 2026] [security2:error] [pid 18946:tid 18968] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/v3/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9ZwABLhU"]
[Thu Sep 17 15:38:59.841985 2026] [security2:error] [pid 18946:tid 19159] [client 177.73.111.3:22995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd8zqiPMah0Tz_U1O9ZAABXRY"]
[Thu Sep 17 15:38:59.907505 2026] [security2:error] [pid 18946:tid 18984] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/api/v1/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9aAABVyU"]
[Thu Sep 17 15:38:59.996163 2026] [security2:error] [pid 18946:tid 18953] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/api/v2/.env"] [unique_id "aqxd8zqiPMah0Tz_U1O9aQABcQY"]
[Thu Sep 17 15:39:00.088933 2026] [security2:error] [pid 18946:tid 19007] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/rest/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9bAABQDw"]
[Thu Sep 17 15:39:00.108471 2026] [security2:error] [pid 20162:tid 20377] [client 134.185.85.61:58066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "niemd.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxd9K-O_Kk7aqBvaiGKawAAAeM"]
[Thu Sep 17 15:39:00.178846 2026] [security2:error] [pid 18946:tid 18964] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/graphql/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9bQABChE"]
[Thu Sep 17 15:39:00.269373 2026] [security2:error] [pid 18946:tid 19000] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/gateway/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9cwABWjU"]
[Thu Sep 17 15:39:00.292919 2026] [security2:error] [pid 18946:tid 19166] [client 216.24.219.103:21313] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/index.php"] [unique_id "aqxd9DqiPMah0Tz_U1O9dAAAAWQ"]
[Thu Sep 17 15:39:00.328688 2026] [security2:error] [pid 18946:tid 19103] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "dbtrc.com"] [uri "/index.php"] [unique_id "aqxd9DqiPMah0Tz_U1O9cQAAASU"]
[Thu Sep 17 15:39:00.330747 2026] [security2:error] [pid 20162:tid 20361] [client 34.0.12.64:49946] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "dbtrc.com"] [uri "/"] [unique_id "aqxd86-O_Kk7aqBvaiGKaAAB03Q"]
[Thu Sep 17 15:39:00.358654 2026] [security2:error] [pid 18946:tid 18996] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/microservice/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9dQABbzE"]
[Thu Sep 17 15:39:00.381622 2026] [security2:error] [pid 20162:tid 20305] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "dbtrc.com"] [uri "/index.php"] [unique_id "aqxd9K-O_Kk7aqBvaiGKbQAAAZs"]
[Thu Sep 17 15:39:00.389211 2026] [security2:error] [pid 18946:tid 19144] [client 34.0.12.64:49950] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "dbtrc.com"] [uri "/"] [unique_id "aqxd9DqiPMah0Tz_U1O9agABThg"]
[Thu Sep 17 15:39:00.444258 2026] [security2:error] [pid 18946:tid 18978] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/service/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9dgABWB8"]
[Thu Sep 17 15:39:00.467083 2026] [security2:error] [pid 18946:tid 19126] [client 34.166.134.22:54142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/_phpinfo.php"] [unique_id "aqxd9DqiPMah0Tz_U1O9dwAAATw"]
[Thu Sep 17 15:39:00.489880 2026] [security2:error] [pid 18946:tid 19127] [client 134.185.85.61:62588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "niemd.com"] [uri "/media/system/js/core.js"] [unique_id "aqxd9DqiPMah0Tz_U1O9eQAAAT0"]
[Thu Sep 17 15:39:00.533641 2026] [security2:error] [pid 18946:tid 18954] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/api/v3/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9ewABFwc"]
[Thu Sep 17 15:39:00.573445 2026] [authz_core:error] [pid 20162:tid 20310] [client 169.58.197.253:55446] AH01630: client denied by server configuration: /home2/brianpag/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:39:00.622517 2026] [security2:error] [pid 18946:tid 19023] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/api/dev/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9fgABdkw"]
[Thu Sep 17 15:39:00.714138 2026] [security2:error] [pid 18946:tid 19012] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/api/staging/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9ggABTEE"]
[Thu Sep 17 15:39:00.802118 2026] [security2:error] [pid 18946:tid 19146] [client 104.234.19.152:36895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxd9DqiPMah0Tz_U1O9hAAAAVA"]
[Thu Sep 17 15:39:00.804782 2026] [security2:error] [pid 18946:tid 19019] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/vendor/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9hQABFkg"]
[Thu Sep 17 15:39:00.903981 2026] [security2:error] [pid 18946:tid 18995] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/lib/.env"] [unique_id "aqxd9DqiPMah0Tz_U1O9hwABGDA"]
[Thu Sep 17 15:39:01.014150 2026] [security2:error] [pid 18946:tid 19003] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/resources/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9iAABDDg"]
[Thu Sep 17 15:39:01.102942 2026] [security2:error] [pid 18946:tid 19016] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/assets/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9jAABFEU"]
[Thu Sep 17 15:39:01.183361 2026] [security2:error] [pid 18946:tid 19133] [client 34.166.134.22:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/old_phpinfo.php"] [unique_id "aqxd9TqiPMah0Tz_U1O9kAAAAUM"]
[Thu Sep 17 15:39:01.190802 2026] [security2:error] [pid 18946:tid 19004] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/uploads/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9kwABfjk"]
[Thu Sep 17 15:39:01.264773 2026] [security2:error] [pid 20162:tid 20323] [client 216.24.219.36:35535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/index.php"] [unique_id "aqxd9a-O_Kk7aqBvaiGKfwAAAa0"]
[Thu Sep 17 15:39:01.285986 2026] [security2:error] [pid 18946:tid 19054] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/internal/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9lwABW2s"]
[Thu Sep 17 15:39:01.371703 2026] [security2:error] [pid 18946:tid 19013] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/tools/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9mgABMEI"]
[Thu Sep 17 15:39:01.403517 2026] [security2:error] [pid 20162:tid 20300] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd9a-O_Kk7aqBvaiGKewAAAZY"]
[Thu Sep 17 15:39:01.408974 2026] [security2:error] [pid 20162:tid 20370] [client 34.0.12.64:49956] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/"] [unique_id "aqxd9a-O_Kk7aqBvaiGKeAAB3HA"]
[Thu Sep 17 15:39:01.463896 2026] [security2:error] [pid 18946:tid 19053] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/scripts/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9mwABSmo"]
[Thu Sep 17 15:39:01.553790 2026] [security2:error] [pid 18946:tid 18947] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/bin/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9pgABLAA"]
[Thu Sep 17 15:39:01.623832 2026] [authz_core:error] [pid 18946:tid 19147] [client 169.58.197.251:54118] AH01630: client denied by server configuration: /home2/sfvhbtor/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:39:01.639684 2026] [security2:error] [pid 18946:tid 19031] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/sbin/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9qgABDlQ"]
[Thu Sep 17 15:39:01.732649 2026] [security2:error] [pid 18946:tid 19001] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/local/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9rgABfDY"]
[Thu Sep 17 15:39:01.820483 2026] [security2:error] [pid 18946:tid 19063] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/portal/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9rwABQnQ"]
[Thu Sep 17 15:39:01.881227 2026] [security2:error] [pid 20162:tid 20419] [client 34.166.134.22:54160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/server-info.php"] [unique_id "aqxd9a-O_Kk7aqBvaiGKjAAAAg0"]
[Thu Sep 17 15:39:01.907083 2026] [security2:error] [pid 18946:tid 18981] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/dashboard/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9sgABNSI"]
[Thu Sep 17 15:39:01.999745 2026] [security2:error] [pid 18946:tid 19005] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/panel/.env"] [unique_id "aqxd9TqiPMah0Tz_U1O9tAABLzo"]
[Thu Sep 17 15:39:02.036799 2026] [security2:error] [pid 18946:tid 19109] [client 160.119.76.210:35120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "162.241.226.11"] [uri "/html/admin/config.php"] [unique_id "aqxd9jqiPMah0Tz_U1O9tgAAASs"]
[Thu Sep 17 15:39:02.049499 2026] [security2:error] [pid 18946:tid 19180] [client 162.241.226.11:44992] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxd9jqiPMah0Tz_U1O9tQAAAXI"]
[Thu Sep 17 15:39:02.085344 2026] [security2:error] [pid 18946:tid 19024] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/crm/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9uQABM00"]
[Thu Sep 17 15:39:02.173475 2026] [security2:error] [pid 18946:tid 18956] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/erp/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9ugABXgk"]
[Thu Sep 17 15:39:02.173653 2026] [security2:error] [pid 20162:tid 20338] [client 77.110.166.62:52235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxd9q-O_Kk7aqBvaiGKjQABvG4"]
[Thu Sep 17 15:39:02.265514 2026] [security2:error] [pid 18946:tid 18997] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/shop/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9vgABZjI"]
[Thu Sep 17 15:39:02.353258 2026] [security2:error] [pid 18946:tid 19006] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/store/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9wAABcDs"]
[Thu Sep 17 15:39:02.353383 2026] [security2:error] [pid 18946:tid 19076] [client 104.234.19.144:42679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxd9jqiPMah0Tz_U1O9wQAAAQo"]
[Thu Sep 17 15:39:02.432851 2026] [security2:error] [pid 18946:tid 19179] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd9jqiPMah0Tz_U1O9vQAAAXE"]
[Thu Sep 17 15:39:02.440969 2026] [security2:error] [pid 18946:tid 18993] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/saas/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9wgABJS4"]
[Thu Sep 17 15:39:02.444084 2026] [security2:error] [pid 20162:tid 20378] [client 34.0.12.64:49972] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/"] [unique_id "aqxd9a-O_Kk7aqBvaiGKfAAB5Gc"]
[Thu Sep 17 15:39:02.532266 2026] [security2:error] [pid 18946:tid 19059] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/client/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9wwABOnA"]
[Thu Sep 17 15:39:02.579519 2026] [security2:error] [pid 18946:tid 19130] [client 34.166.134.22:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/server-status.php"] [unique_id "aqxd9jqiPMah0Tz_U1O9xQAAAUA"]
[Thu Sep 17 15:39:02.626289 2026] [security2:error] [pid 18946:tid 19017] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/project/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9xgABTkY"]
[Thu Sep 17 15:39:02.724494 2026] [security2:error] [pid 18946:tid 18976] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/admin-panel/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O9zAABFR0"]
[Thu Sep 17 15:39:02.814904 2026] [security2:error] [pid 20162:tid 20358] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd9q-O_Kk7aqBvaiGKlgAAAdA"]
[Thu Sep 17 15:39:02.820517 2026] [security2:error] [pid 18946:tid 19057] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/control-panel/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O90AABZ24"]
[Thu Sep 17 15:39:02.825528 2026] [security2:error] [pid 20162:tid 20341] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/robots.txt"] [unique_id "aqxd9q-O_Kk7aqBvaiGKlQABv2M"]
[Thu Sep 17 15:39:02.908580 2026] [security2:error] [pid 18946:tid 19018] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/user-panel/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O90QABTEc"]
[Thu Sep 17 15:39:02.998767 2026] [security2:error] [pid 18946:tid 19034] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/node/.env"] [unique_id "aqxd9jqiPMah0Tz_U1O91AABU1c"]
[Thu Sep 17 15:39:03.081146 2026] [security2:error] [pid 18946:tid 19073] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/express/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O91QABJH4"]
[Thu Sep 17 15:39:03.165242 2026] [security2:error] [pid 18946:tid 19043] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/next/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O92QABGGA"]
[Thu Sep 17 15:39:03.193249 2026] [security2:error] [pid 18946:tid 19089] [client 103.61.184.148:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd9zqiPMah0Tz_U1O92wAAARc"]
[Thu Sep 17 15:39:03.193418 2026] [security2:error] [pid 18946:tid 19089] [client 103.61.184.148:52006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxd9zqiPMah0Tz_U1O92wAAARc"]
[Thu Sep 17 15:39:03.256951 2026] [security2:error] [pid 18946:tid 19070] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/nuxt/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O93gABDHs"]
[Thu Sep 17 15:39:03.340288 2026] [security2:error] [pid 18946:tid 19036] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/nest/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O94wABIlk"]
[Thu Sep 17 15:39:03.341347 2026] [security2:error] [pid 20162:tid 20420] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd96-O_Kk7aqBvaiGKoAAAAg4"]
[Thu Sep 17 15:39:03.341455 2026] [security2:error] [pid 18946:tid 19088] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd9zqiPMah0Tz_U1O92AAAARY"]
[Thu Sep 17 15:39:03.425841 2026] [security2:error] [pid 18946:tid 19026] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/react/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O95AABJk8"]
[Thu Sep 17 15:39:03.477440 2026] [security2:error] [pid 18946:tid 19086] [client 54.147.178.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxd9zqiPMah0Tz_U1O94gAAARQ"]
[Thu Sep 17 15:39:03.517288 2026] [security2:error] [pid 18946:tid 18987] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/vue/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O95QABfig"]
[Thu Sep 17 15:39:03.543245 2026] [security2:error] [pid 20162:tid 20328] [client 104.234.19.150:63353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/file.php"] [unique_id "aqxd96-O_Kk7aqBvaiGKpgAAAbI"]
[Thu Sep 17 15:39:03.587702 2026] [security2:error] [pid 20162:tid 20408] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/parent-skills-training/"] [unique_id "aqxd96-O_Kk7aqBvaiGKnQACAhg"]
[Thu Sep 17 15:39:03.587830 2026] [security2:error] [pid 20162:tid 20408] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/dbt-for-adults/"] [unique_id "aqxd96-O_Kk7aqBvaiGKngACAmQ"]
[Thu Sep 17 15:39:03.603542 2026] [security2:error] [pid 18946:tid 19028] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/angular/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O95wABHFE"]
[Thu Sep 17 15:39:03.685098 2026] [security2:error] [pid 18946:tid 18957] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/svelte/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O96QABPgo"]
[Thu Sep 17 15:39:03.762023 2026] [security2:error] [pid 18946:tid 19199] [client 34.166.134.22:54188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/webroot/index.php/_environment"] [unique_id "aqxd9zqiPMah0Tz_U1O97AAAAYU"]
[Thu Sep 17 15:39:03.766678 2026] [security2:error] [pid 18946:tid 19040] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/vite/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O97QABHl0"]
[Thu Sep 17 15:39:03.827276 2026] [security2:error] [pid 18946:tid 19129] [client 160.119.76.210:12688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "162.241.226.12"] [uri "/html/admin/config.php"] [unique_id "aqxd9zqiPMah0Tz_U1O97wAAAT8"]
[Thu Sep 17 15:39:03.850344 2026] [security2:error] [pid 18946:tid 19048] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/backup/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O98AABgWU"]
[Thu Sep 17 15:39:03.940372 2026] [security2:error] [pid 18946:tid 19038] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/backups/.env"] [unique_id "aqxd9zqiPMah0Tz_U1O98QABXFs"]
[Thu Sep 17 15:39:04.021952 2026] [security2:error] [pid 18946:tid 19042] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/old/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O98wABVl8"]
[Thu Sep 17 15:39:04.105324 2026] [security2:error] [pid 18946:tid 19055] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/tmp/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O99QABUWw"]
[Thu Sep 17 15:39:04.113725 2026] [security2:error] [pid 20162:tid 20305] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKsQABm34"]
[Thu Sep 17 15:39:04.113881 2026] [security2:error] [pid 20162:tid 20305] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKswABm3w"]
[Thu Sep 17 15:39:04.115713 2026] [security2:error] [pid 20162:tid 20305] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKrwABm2k"]
[Thu Sep 17 15:39:04.115863 2026] [security2:error] [pid 20162:tid 20305] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-content/plugins/elementor/assets/js/frontend-modules.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKsAABm30"]
[Thu Sep 17 15:39:04.116523 2026] [security2:error] [pid 20162:tid 20305] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-includes/js/jquery/jquery.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKsgABm38"]
[Thu Sep 17 15:39:04.118111 2026] [security2:error] [pid 20162:tid 20305] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/link-prefetch.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKrgABmwM"]
[Thu Sep 17 15:39:04.188246 2026] [security2:error] [pid 18946:tid 19119] [client 64.181.216.111:55258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "azclassicbronco.org"] [uri "/"] [unique_id "aqxd-DqiPMah0Tz_U1O9-QAAATU"]
[Thu Sep 17 15:39:04.188729 2026] [security2:error] [pid 18946:tid 19041] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/temp/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O9-AABbV4"]
[Thu Sep 17 15:39:04.271817 2026] [security2:error] [pid 18946:tid 18960] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/lab/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O9-gABSw0"]
[Thu Sep 17 15:39:04.288521 2026] [security2:error] [pid 20162:tid 20398] [client 64.181.216.111:57902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "azclassicbronco.org"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxd-K-O_Kk7aqBvaiGKtQAAAfg"]
[Thu Sep 17 15:39:04.328138 2026] [security2:error] [pid 18946:tid 19067] [remote 74.220.219.26:23662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/wp-login.php"] [unique_id "aqxd-DqiPMah0Tz_U1O9_AABKng"]
[Thu Sep 17 15:39:04.358060 2026] [security2:error] [pid 18946:tid 19069] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/cronlab/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O9_QABYno"]
[Thu Sep 17 15:39:04.363389 2026] [security2:error] [pid 18946:tid 19190] [client 14.96.156.146:58543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd-DqiPMah0Tz_U1O9_gAAAXw"]
[Thu Sep 17 15:39:04.363489 2026] [security2:error] [pid 18946:tid 19190] [client 14.96.156.146:58543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxd-DqiPMah0Tz_U1O9_gAAAXw"]
[Thu Sep 17 15:39:04.371649 2026] [security2:error] [pid 20162:tid 20335] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-includes/js/jquery/ui/core.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKtgABuQA"]
[Thu Sep 17 15:39:04.371959 2026] [security2:error] [pid 20162:tid 20335] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/wp-content/plugins/elementor/assets/js/frontend.min.js"] [unique_id "aqxd-K-O_Kk7aqBvaiGKtwABuXE"]
[Thu Sep 17 15:39:04.378853 2026] [security2:error] [pid 18946:tid 19120] [client 64.181.216.111:58938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "azclassicbronco.org"] [uri "/media/system/js/core.js"] [unique_id "aqxd-DqiPMah0Tz_U1O-AQAAATY"]
[Thu Sep 17 15:39:04.390619 2026] [security2:error] [pid 18946:tid 19064] [remote 74.220.219.26:23678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/xmlrpc.php"] [unique_id "aqxd-DqiPMah0Tz_U1O-AwABXXU"]
[Thu Sep 17 15:39:04.415986 2026] [security2:error] [pid 20162:tid 20169] [remote 74.220.219.26:23694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website.learn360lms.com"] [uri "/xmlrpc.php"] [unique_id "aqxd-K-O_Kk7aqBvaiGKvQAB7QU"]
[Thu Sep 17 15:39:04.447992 2026] [security2:error] [pid 20162:tid 20350] [client 34.166.134.22:54194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/mail/phpinfo.php"] [unique_id "aqxd-K-O_Kk7aqBvaiGKvgAAAcg"]
[Thu Sep 17 15:39:04.463814 2026] [security2:error] [pid 18946:tid 19030] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/cron/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O-BQABM1M"]
[Thu Sep 17 15:39:04.466138 2026] [security2:error] [pid 20162:tid 20306] [client 104.234.19.145:43341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxd-K-O_Kk7aqBvaiGKvwAAAZw"]
[Thu Sep 17 15:39:04.468815 2026] [security2:error] [pid 20162:tid 20283] [remote 74.220.219.26:23700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website.learn360lms.com"] [uri "/wp-login.php"] [unique_id "aqxd-K-O_Kk7aqBvaiGKwAABwXc"]
[Thu Sep 17 15:39:04.553941 2026] [security2:error] [pid 18946:tid 19047] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/en/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O-BwABcGQ"]
[Thu Sep 17 15:39:04.574183 2026] [security2:error] [pid 18946:tid 19112] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd-DqiPMah0Tz_U1O-AgAAAS4"]
[Thu Sep 17 15:39:04.574211 2026] [security2:error] [pid 18946:tid 19112] [client 34.0.12.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd-DqiPMah0Tz_U1O-AgAAAS4"]
[Thu Sep 17 15:39:04.582789 2026] [security2:error] [pid 20162:tid 20415] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd-K-O_Kk7aqBvaiGKvAAAAgk"]
[Thu Sep 17 15:39:04.630454 2026] [security2:error] [pid 20162:tid 20335] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dbtrc.com"] [uri "/ads.txt"] [unique_id "aqxd-K-O_Kk7aqBvaiGKugABuQQ"]
[Thu Sep 17 15:39:04.636823 2026] [security2:error] [pid 20162:tid 20335] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/contact/"] [unique_id "aqxd-K-O_Kk7aqBvaiGKuAABuRU"]
[Thu Sep 17 15:39:04.664043 2026] [security2:error] [pid 18946:tid 19065] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/administrator/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O-CAABcXY"]
[Thu Sep 17 15:39:04.758451 2026] [security2:error] [pid 18946:tid 18950] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/psnlink/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O-CwABHQM"]
[Thu Sep 17 15:39:04.765595 2026] [security2:error] [pid 18946:tid 19168] [client 34.0.12.64:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/index.php"] [unique_id "aqxd-DqiPMah0Tz_U1O-BgAAAWY"]
[Thu Sep 17 15:39:04.828079 2026] [security2:error] [pid 20162:tid 20335] [client 34.0.12.64:60370] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dbtrc.com"] [uri "/meet-the-team/"] [unique_id "aqxd-K-O_Kk7aqBvaiGKuQABuQE"]
[Thu Sep 17 15:39:04.845838 2026] [security2:error] [pid 18946:tid 18963] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/exapi/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O-DQABQBA"]
[Thu Sep 17 15:39:04.929850 2026] [security2:error] [pid 18946:tid 18955] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/sitemaps/.env"] [unique_id "aqxd-DqiPMah0Tz_U1O-DgABbgg"]
[Thu Sep 17 15:39:04.990375 2026] [security2:error] [pid 20162:tid 20370] [client 104.234.19.145:36577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-mail.php"] [unique_id "aqxd-K-O_Kk7aqBvaiGKyQAAAdw"]
[Thu Sep 17 15:39:05.133101 2026] [security2:error] [pid 20162:tid 20333] [client 34.166.134.22:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxd-a-O_Kk7aqBvaiGKygAAAbc"]
[Thu Sep 17 15:39:05.201560 2026] [security2:error] [pid 18946:tid 18972] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/logs/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-EwABRhk"]
[Thu Sep 17 15:39:05.283515 2026] [security2:error] [pid 18946:tid 18985] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/cache/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-FAABNyY"]
[Thu Sep 17 15:39:05.371042 2026] [security2:error] [pid 18946:tid 18973] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mailer/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-FQABaho"]
[Thu Sep 17 15:39:05.459272 2026] [security2:error] [pid 18946:tid 19074] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mail/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-FwABNH8"]
[Thu Sep 17 15:39:05.546010 2026] [security2:error] [pid 18946:tid 18974] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/email/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-GAABYBs"]
[Thu Sep 17 15:39:05.633885 2026] [security2:error] [pid 18946:tid 18948] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/smtp/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-GQABTQE"]
[Thu Sep 17 15:39:05.717549 2026] [security2:error] [pid 18946:tid 18962] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mailing/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-HgABWQ8"]
[Thu Sep 17 15:39:05.801933 2026] [security2:error] [pid 18946:tid 19062] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/notifications/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-HwABf3M"]
[Thu Sep 17 15:39:05.825134 2026] [security2:error] [pid 18946:tid 19142] [client 34.166.134.22:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/hosting/phpinfo.php"] [unique_id "aqxd-TqiPMah0Tz_U1O-IAAAAUw"]
[Thu Sep 17 15:39:05.849138 2026] [security2:error] [pid 18946:tid 19083] [client 104.234.19.152:41629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/ioxi-o.php"] [unique_id "aqxd-TqiPMah0Tz_U1O-IQAAARE"]
[Thu Sep 17 15:39:05.889522 2026] [security2:error] [pid 18946:tid 18966] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/notify/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-IwABDBM"]
[Thu Sep 17 15:39:05.976468 2026] [security2:error] [pid 18946:tid 18959] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/sender/.env"] [unique_id "aqxd-TqiPMah0Tz_U1O-JQABFgw"]
[Thu Sep 17 15:39:06.031020 2026] [security2:error] [pid 20162:tid 20321] [client 163.47.157.54:57850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxd-K-O_Kk7aqBvaiGKxwABq3g"], referer: https://www.enolastable.com/2016/11/08/it-cost-me-93-95-to-vote/
[Thu Sep 17 15:39:06.071730 2026] [security2:error] [pid 18946:tid 19071] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/campaign/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-JgABGnw"]
[Thu Sep 17 15:39:06.158965 2026] [security2:error] [pid 18946:tid 18958] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/newsletter/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-KAABFAs"]
[Thu Sep 17 15:39:06.240608 2026] [security2:error] [pid 18946:tid 19044] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/ses/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-LAABHGE"]
[Thu Sep 17 15:39:06.326523 2026] [security2:error] [pid 18946:tid 19021] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/sendgrid/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-MAABEEo"]
[Thu Sep 17 15:39:06.411714 2026] [security2:error] [pid 18946:tid 18949] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/sparkpost/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-MwABHgI"]
[Thu Sep 17 15:39:06.462185 2026] [security2:error] [pid 20162:tid 20356] [client 192.178.6.3:35012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxd-q-O_Kk7aqBvaiGK4AAAAc4"]
[Thu Sep 17 15:39:06.496435 2026] [security2:error] [pid 18946:tid 18994] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/postmark/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-NAABSC8"]
[Thu Sep 17 15:39:06.509601 2026] [security2:error] [pid 20162:tid 20378] [client 34.166.134.22:54222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/webmail/phpinfo.php"] [unique_id "aqxd-q-O_Kk7aqBvaiGK4wAAAeQ"]
[Thu Sep 17 15:39:06.569626 2026] [security2:error] [pid 20162:tid 20299] [client 193.36.224.149:33801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxd-q-O_Kk7aqBvaiGK5AAAAZU"]
[Thu Sep 17 15:39:06.578942 2026] [security2:error] [pid 18946:tid 18986] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mailgun/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-OAABgSc"]
[Thu Sep 17 15:39:06.635728 2026] [security2:error] [pid 20162:tid 20367] [client 177.44.133.72:63057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd-q-O_Kk7aqBvaiGK5QAAAdk"]
[Thu Sep 17 15:39:06.636656 2026] [security2:error] [pid 20162:tid 20367] [client 177.44.133.72:63057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxd-q-O_Kk7aqBvaiGK5QAAAdk"]
[Thu Sep 17 15:39:06.663931 2026] [security2:error] [pid 18946:tid 18988] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mandrill/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-OQABXCk"]
[Thu Sep 17 15:39:06.747840 2026] [security2:error] [pid 18946:tid 18970] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mailjet/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-PQABYxc"]
[Thu Sep 17 15:39:06.781422 2026] [security2:error] [pid 20162:tid 20365] [client 162.241.226.11:58844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxd-a-O_Kk7aqBvaiGK0wAAAdc"]
[Thu Sep 17 15:39:06.829403 2026] [security2:error] [pid 18946:tid 18979] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/brevo/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-PwABLyA"]
[Thu Sep 17 15:39:06.917510 2026] [security2:error] [pid 18946:tid 19037] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/transactional/.env"] [unique_id "aqxd-jqiPMah0Tz_U1O-QgABMVo"]
[Thu Sep 17 15:39:06.938858 2026] [security2:error] [pid 20162:tid 20400] [client 34.166.221.252:40496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/phpinfo.php"] [unique_id "aqxd-q-O_Kk7aqBvaiGK6QAAAfo"]
[Thu Sep 17 15:39:07.003843 2026] [security2:error] [pid 18946:tid 18982] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/bulk/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-RgABXiM"]
[Thu Sep 17 15:39:07.087955 2026] [security2:error] [pid 18946:tid 18968] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/aws/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-RwABVRU"]
[Thu Sep 17 15:39:07.171247 2026] [security2:error] [pid 18946:tid 18969] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/azure/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-SAABbBY"]
[Thu Sep 17 15:39:07.217631 2026] [security2:error] [pid 18946:tid 19163] [client 34.166.134.22:54238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/smtp/phpinfo.php"] [unique_id "aqxd-zqiPMah0Tz_U1O-SwAAAWE"]
[Thu Sep 17 15:39:07.267949 2026] [security2:error] [pid 18946:tid 18984] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/gcp/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-TAABcCU"]
[Thu Sep 17 15:39:07.356222 2026] [security2:error] [pid 18946:tid 19007] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/cloud/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-TwABXzw"]
[Thu Sep 17 15:39:07.442207 2026] [security2:error] [pid 18946:tid 18964] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/infrastructure/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-UQABchE"]
[Thu Sep 17 15:39:07.541686 2026] [security2:error] [pid 18946:tid 19000] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/docker/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-UgABRzU"]
[Thu Sep 17 15:39:07.628621 2026] [security2:error] [pid 18946:tid 19132] [client 34.166.221.252:40486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/info.php"] [unique_id "aqxd-zqiPMah0Tz_U1O-UwAAAUI"]
[Thu Sep 17 15:39:07.632245 2026] [security2:error] [pid 18946:tid 18996] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/k8s/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-VAABZjE"]
[Thu Sep 17 15:39:07.724337 2026] [security2:error] [pid 18946:tid 18983] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/kubernetes/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-VwABOiQ"]
[Thu Sep 17 15:39:07.813056 2026] [security2:error] [pid 18946:tid 18978] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/terraform/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-WgABZB8"]
[Thu Sep 17 15:39:07.914327 2026] [security2:error] [pid 18946:tid 19023] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/ansible/.env"] [unique_id "aqxd-zqiPMah0Tz_U1O-XQABgkw"]
[Thu Sep 17 15:39:07.931957 2026] [security2:error] [pid 20162:tid 20361] [client 34.166.134.22:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/phpinfo.php.bak"] [unique_id "aqxd-6-O_Kk7aqBvaiGK8gAAAdM"]
[Thu Sep 17 15:39:08.022184 2026] [security2:error] [pid 18946:tid 19153] [client 186.168.138.60:58248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxd-zqiPMah0Tz_U1O-XgABV0E"], referer: https://www.enolastable.com/2016/11/08/it-cost-me-93-95-to-vote/
[Thu Sep 17 15:39:08.035574 2026] [security2:error] [pid 18946:tid 18965] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/.git/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-XwABNBI"]
[Thu Sep 17 15:39:08.108746 2026] [security2:error] [pid 18946:tid 19127] [client 74.7.228.36:60728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.eej.kbo.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxd_DqiPMah0Tz_U1O-YQABPUg"]
[Thu Sep 17 15:39:08.123553 2026] [fcgid:warn] [pid 18946:tid 19187] (70014)End of file found: [client 152.32.205.184:55360] mod_fcgid: can't get data from http client
[Thu Sep 17 15:39:08.134108 2026] [security2:error] [pid 18946:tid 18995] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/ci/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-YwABETA"]
[Thu Sep 17 15:39:08.180681 2026] [security2:error] [pid 18946:tid 19102] [client 162.241.226.11:58852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxd-jqiPMah0Tz_U1O-PgAAAVE"]
[Thu Sep 17 15:39:08.209227 2026] [security2:error] [pid 18946:tid 19122] [client 193.36.224.156:53687] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/000.php"] [unique_id "aqxd_DqiPMah0Tz_U1O-ZQAAATg"]
[Thu Sep 17 15:39:08.222717 2026] [security2:error] [pid 18946:tid 18980] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/cd/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-ZgABhiE"]
[Thu Sep 17 15:39:08.309420 2026] [security2:error] [pid 18946:tid 19016] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/jenkins/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-aQABhUU"]
[Thu Sep 17 15:39:08.333223 2026] [security2:error] [pid 20162:tid 20364] [client 34.166.221.252:40498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/php.php"] [unique_id "aqxd_K-O_Kk7aqBvaiGK8wAAAdY"]
[Thu Sep 17 15:39:08.374123 2026] [security2:error] [pid 18946:tid 19101] [client 216.24.219.37:46283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/style.php"] [unique_id "aqxd_DqiPMah0Tz_U1O-eQAAASM"]
[Thu Sep 17 15:39:08.399948 2026] [security2:error] [pid 18946:tid 19004] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/gitlab/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-gAABWzk"]
[Thu Sep 17 15:39:08.449833 2026] [security2:error] [pid 18946:tid 19201] [client 193.36.224.219:31985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/about.php"] [unique_id "aqxd_DqiPMah0Tz_U1O-ggAAAYc"]
[Thu Sep 17 15:39:08.490981 2026] [security2:error] [pid 18946:tid 19054] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/github/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-hAABMGs"]
[Thu Sep 17 15:39:08.513713 2026] [security2:error] [pid 20162:tid 20323] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxd_K-O_Kk7aqBvaiGK_wAAAa0"]
[Thu Sep 17 15:39:08.581171 2026] [security2:error] [pid 18946:tid 19027] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/actions/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-hQABXFA"]
[Thu Sep 17 15:39:08.623818 2026] [security2:error] [pid 18946:tid 19129] [client 34.166.134.22:54248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/phpinfo.php.old"] [unique_id "aqxd_DqiPMah0Tz_U1O-hgAAAT8"]
[Thu Sep 17 15:39:08.675518 2026] [security2:error] [pid 18946:tid 19013] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/circleci/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-hwABaEI"]
[Thu Sep 17 15:39:08.677918 2026] [security2:error] [pid 18946:tid 19107] [client 193.36.224.156:49783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/style.php"] [unique_id "aqxd_DqiPMah0Tz_U1O-iAAAASk"]
[Thu Sep 17 15:39:08.774404 2026] [security2:error] [pid 18946:tid 19014] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/travis/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-jAABEkM"]
[Thu Sep 17 15:39:08.812776 2026] [security2:error] [pid 18946:tid 19152] [client 193.36.224.156:28447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxd_DqiPMah0Tz_U1O-jQAAAVY"]
[Thu Sep 17 15:39:08.819199 2026] [security2:error] [pid 18946:tid 19138] [client 136.158.61.34:24400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd_DqiPMah0Tz_U1O-jwAAAUg"]
[Thu Sep 17 15:39:08.823629 2026] [security2:error] [pid 18946:tid 19138] [client 136.158.61.34:24400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxd_DqiPMah0Tz_U1O-jwAAAUg"]
[Thu Sep 17 15:39:08.865108 2026] [security2:error] [pid 18946:tid 18977] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/buildkite/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-kQABfB4"]
[Thu Sep 17 15:39:08.956444 2026] [security2:error] [pid 18946:tid 19053] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mysql/.env"] [unique_id "aqxd_DqiPMah0Tz_U1O-lAABRWo"]
[Thu Sep 17 15:39:09.026075 2026] [security2:error] [pid 20162:tid 20375] [client 34.166.221.252:40504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/i.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLBwAAAeE"]
[Thu Sep 17 15:39:09.050622 2026] [security2:error] [pid 18946:tid 19112] [client 216.24.219.22:46713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxd_TqiPMah0Tz_U1O-lQAAAS4"]
[Thu Sep 17 15:39:09.056630 2026] [security2:error] [pid 18946:tid 18992] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/postgres/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-lgABci0"]
[Thu Sep 17 15:39:09.146717 2026] [security2:error] [pid 18946:tid 18990] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/mongodb/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-lwABeCs"]
[Thu Sep 17 15:39:09.187184 2026] [security2:error] [pid 18946:tid 19080] [client 216.24.219.21:37053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxd_TqiPMah0Tz_U1O-mAAAAQ4"]
[Thu Sep 17 15:39:09.245715 2026] [security2:error] [pid 18946:tid 18975] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/redis/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-mQABhBw"]
[Thu Sep 17 15:39:09.315309 2026] [security2:error] [pid 20162:tid 20331] [client 34.166.134.22:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/phpinfo.php~"] [unique_id "aqxd_a-O_Kk7aqBvaiGLCQAAAbU"]
[Thu Sep 17 15:39:09.331098 2026] [security2:error] [pid 18946:tid 19020] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/elasticsearch/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-mwABQkk"]
[Thu Sep 17 15:39:09.375879 2026] [security2:error] [pid 20162:tid 20371] [client 216.24.219.37:49081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-editor.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLCwAAAd0"]
[Thu Sep 17 15:39:09.406913 2026] [security2:error] [pid 20162:tid 20388] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/.env"] [unique_id "aqxd_a-O_Kk7aqBvaiGLDAAAAe4"]
[Thu Sep 17 15:39:09.414654 2026] [security2:error] [pid 18946:tid 19010] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/rabbitmq/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-nAABOj8"]
[Thu Sep 17 15:39:09.453294 2026] [security2:error] [pid 20162:tid 20309] [client 143.105.152.240:50302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLDQAAAZ8"]
[Thu Sep 17 15:39:09.457890 2026] [security2:error] [pid 20162:tid 20309] [client 143.105.152.240:50302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLDQAAAZ8"]
[Thu Sep 17 15:39:09.485016 2026] [security2:error] [pid 18946:tid 19087] [client 216.24.219.100:46163] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxd_TqiPMah0Tz_U1O-ngAAARU"]
[Thu Sep 17 15:39:09.502898 2026] [security2:error] [pid 18946:tid 18989] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/kafka/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-nwABPCo"]
[Thu Sep 17 15:39:09.585906 2026] [security2:error] [pid 18946:tid 19015] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/queue/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-oAABRkQ"]
[Thu Sep 17 15:39:09.630131 2026] [security2:error] [pid 20162:tid 20315] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLDwAAAaU"]
[Thu Sep 17 15:39:09.676932 2026] [security2:error] [pid 18946:tid 19002] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/worker/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-ogABfTc"]
[Thu Sep 17 15:39:09.712975 2026] [security2:error] [pid 20162:tid 20298] [client 34.166.221.252:40512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/pi.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLEwAAAZQ"]
[Thu Sep 17 15:39:09.759381 2026] [security2:error] [pid 18946:tid 19172] [client 193.36.224.169:56783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/lufix.php"] [unique_id "aqxd_TqiPMah0Tz_U1O-owAAAWo"]
[Thu Sep 17 15:39:09.764215 2026] [security2:error] [pid 18946:tid 19058] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/job/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-pAABK28"]
[Thu Sep 17 15:39:09.787884 2026] [security2:error] [pid 20162:tid 20338] [client 193.36.224.146:40337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLFQAAAbw"]
[Thu Sep 17 15:39:09.854500 2026] [security2:error] [pid 18946:tid 19001] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/test/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-pwABNDY"]
[Thu Sep 17 15:39:09.945493 2026] [security2:error] [pid 18946:tid 19063] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/qa/.env"] [unique_id "aqxd_TqiPMah0Tz_U1O-qAABPXQ"]
[Thu Sep 17 15:39:09.999377 2026] [security2:error] [pid 20162:tid 20363] [client 34.166.134.22:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/info.php.bak"] [unique_id "aqxd_a-O_Kk7aqBvaiGLGAAAAdU"]
[Thu Sep 17 15:39:10.040034 2026] [security2:error] [pid 20162:tid 20374] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxd_a-O_Kk7aqBvaiGLFgAAAeA"]
[Thu Sep 17 15:39:10.040236 2026] [security2:error] [pid 18946:tid 19033] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/preview/.env"] [unique_id "aqxd_jqiPMah0Tz_U1O-qgABdlY"]
[Thu Sep 17 15:39:10.130376 2026] [security2:error] [pid 18946:tid 19009] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/beta/.env"] [unique_id "aqxd_jqiPMah0Tz_U1O-rAABUT4"]
[Thu Sep 17 15:39:10.143331 2026] [security2:error] [pid 18946:tid 19102] [client 104.234.19.148:29591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/txets.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-rQAAASQ"]
[Thu Sep 17 15:39:10.228798 2026] [security2:error] [pid 18946:tid 19050] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/uat/.env"] [unique_id "aqxd_jqiPMah0Tz_U1O-rwABHGc"]
[Thu Sep 17 15:39:10.287908 2026] [security2:error] [pid 20162:tid 20336] [client 193.36.224.146:48767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/bless.php"] [unique_id "aqxd_q-O_Kk7aqBvaiGLIAAAAbo"]
[Thu Sep 17 15:39:10.322124 2026] [security2:error] [pid 18946:tid 19005] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/stage/.env"] [unique_id "aqxd_jqiPMah0Tz_U1O-sQABPjo"]
[Thu Sep 17 15:39:10.335506 2026] [security2:error] [pid 20162:tid 20373] [client 79.116.89.151:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd_q-O_Kk7aqBvaiGLIQAAAd8"]
[Thu Sep 17 15:39:10.335619 2026] [security2:error] [pid 20162:tid 20373] [client 79.116.89.151:51647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxd_q-O_Kk7aqBvaiGLIQAAAd8"]
[Thu Sep 17 15:39:10.409781 2026] [security2:error] [pid 18946:tid 19192] [client 34.166.221.252:40528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/pinfo.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-swAAAX4"]
[Thu Sep 17 15:39:10.429610 2026] [security2:error] [pid 18946:tid 19024] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/development/.env"] [unique_id "aqxd_jqiPMah0Tz_U1O-tAABh00"]
[Thu Sep 17 15:39:10.520435 2026] [security2:error] [pid 18946:tid 18956] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/production/.env"] [unique_id "aqxd_jqiPMah0Tz_U1O-tQABSgk"]
[Thu Sep 17 15:39:10.560790 2026] [security2:error] [pid 18946:tid 19197] [client 216.24.219.35:48061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-tgAAAYM"]
[Thu Sep 17 15:39:10.561828 2026] [security2:error] [pid 18946:tid 19195] [client 216.24.219.102:27671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/goods.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-twAAAYE"]
[Thu Sep 17 15:39:10.606012 2026] [security2:error] [pid 20162:tid 20297] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxd_q-O_Kk7aqBvaiGLIwAAAZM"]
[Thu Sep 17 15:39:10.610068 2026] [security2:error] [pid 18946:tid 19006] [remote 34.24.7.149:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lugrel.com"] [uri "/config/app/.env"] [unique_id "aqxd_jqiPMah0Tz_U1O-ugABXDs"]
[Thu Sep 17 15:39:10.714186 2026] [security2:error] [pid 18946:tid 19008] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/phpinfo.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-vAABKD0"]
[Thu Sep 17 15:39:10.724276 2026] [security2:error] [pid 20162:tid 20344] [client 34.166.134.22:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/phpinfo.php.save"] [unique_id "aqxd_q-O_Kk7aqBvaiGLJQAAAcI"]
[Thu Sep 17 15:39:10.812772 2026] [security2:error] [pid 18946:tid 18993] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/info.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-vQABJy4"]
[Thu Sep 17 15:39:10.813114 2026] [security2:error] [pid 18946:tid 19170] [client 104.234.19.146:32205] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-vgAAAWg"]
[Thu Sep 17 15:39:10.813337 2026] [security2:error] [pid 18946:tid 19107] [client 216.24.219.36:43521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/blurbs.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-vwAAASk"]
[Thu Sep 17 15:39:10.903141 2026] [security2:error] [pid 18946:tid 19046] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/php.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-wAABH2M"]
[Thu Sep 17 15:39:10.993525 2026] [security2:error] [pid 18946:tid 19059] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/i.php"] [unique_id "aqxd_jqiPMah0Tz_U1O-wwABTXA"]
[Thu Sep 17 15:39:11.062579 2026] [security2:error] [pid 18946:tid 19160] [client 216.24.219.37:25097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-xAAAAV4"]
[Thu Sep 17 15:39:11.086825 2026] [security2:error] [pid 18946:tid 18976] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/pi.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-xwABYR0"]
[Thu Sep 17 15:39:11.101190 2026] [security2:error] [pid 18946:tid 19178] [client 216.24.219.88:25141] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-yAAAAXA"]
[Thu Sep 17 15:39:11.103465 2026] [security2:error] [pid 18946:tid 19084] [client 34.166.221.252:40536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/test.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-yQAAARI"]
[Thu Sep 17 15:39:11.144967 2026] [security2:error] [pid 20162:tid 20353] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxd_6-O_Kk7aqBvaiGLKAAAAcs"]
[Thu Sep 17 15:39:11.175897 2026] [security2:error] [pid 18946:tid 19045] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/pinfo.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-ywABcmI"]
[Thu Sep 17 15:39:11.262015 2026] [security2:error] [pid 18946:tid 19060] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/test.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-zAABWnE"]
[Thu Sep 17 15:39:11.309443 2026] [security2:error] [pid 18946:tid 19179] [client 216.24.219.20:47391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/goods.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-zQAAAXE"]
[Thu Sep 17 15:39:11.410101 2026] [security2:error] [pid 18946:tid 19098] [client 193.36.224.146:44683] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/abcd.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-zwAAASA"]
[Thu Sep 17 15:39:11.422903 2026] [security2:error] [pid 20162:tid 20334] [client 34.166.134.22:55570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/staging/phpinfo.php"] [unique_id "aqxd_6-O_Kk7aqBvaiGLKQAAAbg"]
[Thu Sep 17 15:39:11.468796 2026] [security2:error] [pid 18946:tid 19057] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/p.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-0AABYG4"]
[Thu Sep 17 15:39:11.572988 2026] [security2:error] [pid 18946:tid 19052] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/debug.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-1AABQmk"]
[Thu Sep 17 15:39:11.573775 2026] [security2:error] [pid 20162:tid 20302] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxd_6-O_Kk7aqBvaiGLKgAAAZg"]
[Thu Sep 17 15:39:11.660561 2026] [security2:error] [pid 18946:tid 19051] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-2AABZGg"]
[Thu Sep 17 15:39:11.697068 2026] [security2:error] [pid 18946:tid 19193] [client 104.234.19.146:28585] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-1wAAAX8"]
[Thu Sep 17 15:39:11.801081 2026] [security2:error] [pid 18946:tid 19034] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/test/phpinfo.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-2QABFVc"]
[Thu Sep 17 15:39:11.889384 2026] [security2:error] [pid 18946:tid 19073] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-2wABc34"]
[Thu Sep 17 15:39:11.972168 2026] [security2:error] [pid 20162:tid 20369] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxd_6-O_Kk7aqBvaiGLMAAAAds"]
[Thu Sep 17 15:39:11.978469 2026] [security2:error] [pid 18946:tid 19043] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/old/phpinfo.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-3QABbmA"]
[Thu Sep 17 15:39:11.993085 2026] [security2:error] [pid 18946:tid 19136] [client 216.24.219.35:64223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/dex.php"] [unique_id "aqxd_zqiPMah0Tz_U1O-3gAAAUY"]
[Thu Sep 17 15:39:12.063380 2026] [security2:error] [pid 20162:tid 20414] [client 34.166.221.252:40548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/p.php"] [unique_id "aqxeAK-O_Kk7aqBvaiGLMQAAAgg"]
[Thu Sep 17 15:39:12.073147 2026] [security2:error] [pid 18946:tid 19011] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxeADqiPMah0Tz_U1O-3wABZ0A"]
[Thu Sep 17 15:39:12.113767 2026] [security2:error] [pid 20162:tid 20362] [client 34.166.134.22:55586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/beta/phpinfo.php"] [unique_id "aqxeAK-O_Kk7aqBvaiGLMgAAAdQ"]
[Thu Sep 17 15:39:12.167677 2026] [security2:error] [pid 18946:tid 19036] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/public/phpinfo.php"] [unique_id "aqxeADqiPMah0Tz_U1O-5AABS1k"]
[Thu Sep 17 15:39:12.254323 2026] [security2:error] [pid 18946:tid 19177] [client 104.234.19.150:29839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxeADqiPMah0Tz_U1O-5QAAAW8"]
[Thu Sep 17 15:39:12.362825 2026] [security2:error] [pid 18946:tid 18987] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/php-info.php"] [unique_id "aqxeADqiPMah0Tz_U1O-6QABdyg"]
[Thu Sep 17 15:39:12.449980 2026] [security2:error] [pid 18946:tid 19028] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/phpversion.php"] [unique_id "aqxeADqiPMah0Tz_U1O-7QABdlE"]
[Thu Sep 17 15:39:12.542430 2026] [security2:error] [pid 18946:tid 19040] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/_phpinfo.php"] [unique_id "aqxeADqiPMah0Tz_U1O-7wABQ10"]
[Thu Sep 17 15:39:12.559518 2026] [security2:error] [pid 18946:tid 19171] [client 95.142.47.113:57715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sqlerudition.com"] [uri "/index.php"] [unique_id "aqxeADqiPMah0Tz_U1O-6wAAAWk"], referer: http://sqlerudition.com/tag/tips-and-tricks/
[Thu Sep 17 15:39:12.605996 2026] [security2:error] [pid 18946:tid 19144] [client 216.24.219.104:44877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxeADqiPMah0Tz_U1O-8gAAAU4"]
[Thu Sep 17 15:39:12.617034 2026] [security2:error] [pid 20162:tid 20406] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxeAK-O_Kk7aqBvaiGLNgAAAgA"]
[Thu Sep 17 15:39:12.629120 2026] [security2:error] [pid 18946:tid 19038] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/old_phpinfo.php"] [unique_id "aqxeADqiPMah0Tz_U1O-9AABIls"]
[Thu Sep 17 15:39:12.717202 2026] [security2:error] [pid 20162:tid 20361] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxeAK-O_Kk7aqBvaiGLOAAAAdM"]
[Thu Sep 17 15:39:12.723840 2026] [security2:error] [pid 18946:tid 19066] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/server-info.php"] [unique_id "aqxeADqiPMah0Tz_U1O-9gABMnc"]
[Thu Sep 17 15:39:12.762764 2026] [security2:error] [pid 18946:tid 19200] [client 104.234.19.143:24033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "radtechresourcesgroup.com"] [uri "/php8.php"] [unique_id "aqxeADqiPMah0Tz_U1O--AAAAYY"]
[Thu Sep 17 15:39:12.765536 2026] [security2:error] [pid 20162:tid 20401] [client 34.166.221.252:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/debug.php"] [unique_id "aqxeAK-O_Kk7aqBvaiGLOQAAAfs"]
[Thu Sep 17 15:39:12.811458 2026] [security2:error] [pid 18946:tid 19042] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/server-status.php"] [unique_id "aqxeADqiPMah0Tz_U1O--QABfl8"]
[Thu Sep 17 15:39:12.811980 2026] [security2:error] [pid 20162:tid 20310] [client 34.166.134.22:55602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/uat/phpinfo.php"] [unique_id "aqxeAK-O_Kk7aqBvaiGLOwAAAaA"]
[Thu Sep 17 15:39:12.919643 2026] [security2:error] [pid 20162:tid 20387] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeAK-O_Kk7aqBvaiGLOgAAAe0"]
[Thu Sep 17 15:39:12.948405 2026] [security2:error] [pid 18946:tid 19114] [client 104.234.19.150:28309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/index.php"] [unique_id "aqxeADqiPMah0Tz_U1O--wAAATA"]
[Thu Sep 17 15:39:13.099208 2026] [security2:error] [pid 18946:tid 19069] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxeATqiPMah0Tz_U1O_AQABEHo"]
[Thu Sep 17 15:39:13.190639 2026] [security2:error] [pid 18946:tid 19030] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxeATqiPMah0Tz_U1O_BAABbVM"]
[Thu Sep 17 15:39:13.222313 2026] [security2:error] [pid 20162:tid 20386] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxeAa-O_Kk7aqBvaiGLPQAAAew"]
[Thu Sep 17 15:39:13.290782 2026] [security2:error] [pid 18946:tid 19047] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxeATqiPMah0Tz_U1O_CAABP2Q"]
[Thu Sep 17 15:39:13.309676 2026] [security2:error] [pid 18946:tid 19145] [client 104.234.19.152:65403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxeATqiPMah0Tz_U1O_CgAAAU8"]
[Thu Sep 17 15:39:13.374645 2026] [security2:error] [pid 18946:tid 19072] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxeATqiPMah0Tz_U1O_DAABVn0"]
[Thu Sep 17 15:39:13.468054 2026] [security2:error] [pid 18946:tid 19039] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxeATqiPMah0Tz_U1O_DgABTVw"]
[Thu Sep 17 15:39:13.506732 2026] [security2:error] [pid 20162:tid 20343] [client 34.166.134.22:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/qa/phpinfo.php"] [unique_id "aqxeAa-O_Kk7aqBvaiGLQAAAAcE"]
[Thu Sep 17 15:39:13.524351 2026] [security2:error] [pid 20162:tid 20311] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeAa-O_Kk7aqBvaiGLPwAAAaE"]
[Thu Sep 17 15:39:13.568852 2026] [security2:error] [pid 18946:tid 19190] [client 66.211.28.35:59339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeATqiPMah0Tz_U1O_DQABfHY"], referer: https://www.google.com/
[Thu Sep 17 15:39:13.569189 2026] [security2:error] [pid 18946:tid 18950] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxeATqiPMah0Tz_U1O_DwABbAM"]
[Thu Sep 17 15:39:13.575311 2026] [security2:error] [pid 20162:tid 20296] [client 104.234.19.151:63957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/index.php"] [unique_id "aqxeAa-O_Kk7aqBvaiGLQQAAAZI"]
[Thu Sep 17 15:39:13.609125 2026] [security2:error] [pid 18946:tid 19149] [client 34.166.221.252:40566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxeATqiPMah0Tz_U1O_EgAAAVM"]
[Thu Sep 17 15:39:13.660626 2026] [security2:error] [pid 18946:tid 18955] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxeATqiPMah0Tz_U1O_EwABMwg"]
[Thu Sep 17 15:39:13.745364 2026] [security2:error] [pid 18946:tid 18998] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/phpinfo.php.old"] [unique_id "aqxeATqiPMah0Tz_U1O_FQABWjM"]
[Thu Sep 17 15:39:13.817777 2026] [security2:error] [pid 18946:tid 19125] [client 193.36.224.169:59651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxeATqiPMah0Tz_U1O_FgAAATs"]
[Thu Sep 17 15:39:13.833034 2026] [security2:error] [pid 18946:tid 19025] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/phpinfo.php~"] [unique_id "aqxeATqiPMah0Tz_U1O_GAABYk4"]
[Thu Sep 17 15:39:13.879377 2026] [security2:error] [pid 20162:tid 20350] [client 103.61.184.148:52588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeAa-O_Kk7aqBvaiGLRQAAAcg"]
[Thu Sep 17 15:39:13.879512 2026] [security2:error] [pid 20162:tid 20350] [client 103.61.184.148:52588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeAa-O_Kk7aqBvaiGLRQAAAcg"]
[Thu Sep 17 15:39:13.903923 2026] [security2:error] [pid 20162:tid 20413] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeAa-O_Kk7aqBvaiGLQwAAAgc"]
[Thu Sep 17 15:39:13.927866 2026] [security2:error] [pid 18946:tid 18972] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/info.php.bak"] [unique_id "aqxeATqiPMah0Tz_U1O_GQABORk"]
[Thu Sep 17 15:39:14.026330 2026] [security2:error] [pid 18946:tid 18985] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/phpinfo.php.save"] [unique_id "aqxeAjqiPMah0Tz_U1O_GgABYCY"]
[Thu Sep 17 15:39:14.067157 2026] [security2:error] [pid 18946:tid 19166] [client 104.234.19.148:43001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/file.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_HQAAAWQ"]
[Thu Sep 17 15:39:14.121898 2026] [security2:error] [pid 18946:tid 19056] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_IgABOm0"]
[Thu Sep 17 15:39:14.200136 2026] [security2:error] [pid 18946:tid 19120] [client 34.166.134.22:55628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/preview/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_IwAAATY"]
[Thu Sep 17 15:39:14.213264 2026] [security2:error] [pid 18946:tid 18974] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_JAABghs"]
[Thu Sep 17 15:39:14.298714 2026] [security2:error] [pid 18946:tid 19193] [client 34.166.221.252:60186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/test/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_JQAAAX8"]
[Thu Sep 17 15:39:14.310530 2026] [security2:error] [pid 18946:tid 18948] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_JgABbgE"]
[Thu Sep 17 15:39:14.344581 2026] [security2:error] [pid 20162:tid 20392] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeAq-O_Kk7aqBvaiGLRwAAAfI"]
[Thu Sep 17 15:39:14.398098 2026] [security2:error] [pid 18946:tid 18962] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_KgABfQ8"]
[Thu Sep 17 15:39:14.405083 2026] [autoindex:error] [pid 20162:tid 20381] [client 175.27.163.171:0] AH01276: Cannot serve directory /home4/wisdomel/public_html/elementalessences/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.elementalessences.com
[Thu Sep 17 15:39:14.479044 2026] [security2:error] [pid 20162:tid 20391] [client 193.36.224.156:48163] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxeAq-O_Kk7aqBvaiGLTAAAAfE"]
[Thu Sep 17 15:39:14.486475 2026] [security2:error] [pid 18946:tid 19062] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_KwABV3M"]
[Thu Sep 17 15:39:14.568018 2026] [security2:error] [pid 18946:tid 18966] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/www/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_LgABdhM"]
[Thu Sep 17 15:39:14.655064 2026] [security2:error] [pid 18946:tid 19071] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_MwABTnw"]
[Thu Sep 17 15:39:14.709232 2026] [security2:error] [pid 20162:tid 20340] [client 104.234.19.148:64999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-mail.php"] [unique_id "aqxeAq-O_Kk7aqBvaiGLTgAAAb4"]
[Thu Sep 17 15:39:14.745949 2026] [security2:error] [pid 18946:tid 19035] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_NAABHFg"]
[Thu Sep 17 15:39:14.786641 2026] [security2:error] [pid 20162:tid 20382] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeAq-O_Kk7aqBvaiGLTQAAAeg"]
[Thu Sep 17 15:39:14.834163 2026] [security2:error] [pid 18946:tid 18958] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/site/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_OAABhws"]
[Thu Sep 17 15:39:14.894417 2026] [security2:error] [pid 20162:tid 20307] [client 34.166.134.22:55638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/www/phpinfo.php"] [unique_id "aqxeAq-O_Kk7aqBvaiGLTwAAAZ0"]
[Thu Sep 17 15:39:14.930614 2026] [security2:error] [pid 18946:tid 19044] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_OgABUmE"]
[Thu Sep 17 15:39:14.988508 2026] [security2:error] [pid 20162:tid 20337] [client 34.166.221.252:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxeAq-O_Kk7aqBvaiGLUAAAAbs"]
[Thu Sep 17 15:39:14.996302 2026] [security2:error] [pid 18946:tid 19100] [client 14.96.156.146:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_OwAAASI"]
[Thu Sep 17 15:39:14.996459 2026] [security2:error] [pid 18946:tid 19100] [client 14.96.156.146:59306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeAjqiPMah0Tz_U1O_OwAAASI"]
[Thu Sep 17 15:39:15.016506 2026] [security2:error] [pid 18946:tid 19021] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_PgABgEo"]
[Thu Sep 17 15:39:15.091030 2026] [security2:error] [pid 20162:tid 20338] [client 193.36.224.220:53723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/ioxi-o.php"] [unique_id "aqxeA6-O_Kk7aqBvaiGLUwAAAbw"]
[Thu Sep 17 15:39:15.109032 2026] [security2:error] [pid 18946:tid 18967] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_QQABgRQ"]
[Thu Sep 17 15:39:15.165303 2026] [security2:error] [pid 18946:tid 19114] [client 51.161.128.55:52132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "creacity.com"] [uri "/webmail"] [unique_id "aqxeAzqiPMah0Tz_U1O_QwAAATA"]
[Thu Sep 17 15:39:15.172758 2026] [security2:error] [pid 18946:tid 19076] [client 51.161.128.55:52142] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "creacity.com"] [uri "/mail"] [unique_id "aqxeAzqiPMah0Tz_U1O_RAAAAQo"]
[Thu Sep 17 15:39:15.202483 2026] [security2:error] [pid 18946:tid 18994] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/core/phpinfo.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_RgABDy8"]
[Thu Sep 17 15:39:15.301490 2026] [security2:error] [pid 20162:tid 20349] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeA6-O_Kk7aqBvaiGLVAAAAcc"]
[Thu Sep 17 15:39:15.306004 2026] [security2:error] [pid 18946:tid 18986] [remote 34.24.7.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.7.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lugrel.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_SAABPyc"]
[Thu Sep 17 15:39:15.346136 2026] [security2:error] [pid 18946:tid 19137] [client 51.161.128.55:52146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.creacity.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "aqxeAzqiPMah0Tz_U1O_SQAAAUc"]
[Thu Sep 17 15:39:15.364706 2026] [security2:error] [pid 18946:tid 19134] [client 193.36.224.213:32013] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_SwAAAUQ"]
[Thu Sep 17 15:39:15.457275 2026] [security2:error] [pid 18946:tid 19170] [client 51.161.128.55:52156] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.creacity.com"] [uri "/"] [unique_id "aqxeAzqiPMah0Tz_U1O_TgAAAWg"]
[Thu Sep 17 15:39:15.578955 2026] [security2:error] [pid 18946:tid 19131] [client 34.166.134.22:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_UwAAAUE"]
[Thu Sep 17 15:39:15.631812 2026] [security2:error] [pid 18946:tid 19151] [client 216.24.219.37:46829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/style.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_WAAAAVU"]
[Thu Sep 17 15:39:15.639220 2026] [security2:error] [pid 18946:tid 19186] [client 69.171.230.42:56140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thehivetribe.com"] [uri "/index.php"] [unique_id "aqxeATqiPMah0Tz_U1O_FwABeDQ"]
[Thu Sep 17 15:39:15.643623 2026] [security2:error] [pid 18946:tid 19085] [client 66.211.28.35:34983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_UgABEwU"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821085902&hideanons=1&hidebots=0&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:39:15.680241 2026] [security2:error] [pid 20162:tid 20322] [client 34.166.221.252:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/old/phpinfo.php"] [unique_id "aqxeA6-O_Kk7aqBvaiGLVwAAAaw"]
[Thu Sep 17 15:39:15.781512 2026] [security2:error] [pid 20162:tid 20385] [client 95.142.47.113:60385] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "95.142.47.113" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.sqlerudition.com"] [uri "/wp-comments-post.php"] [unique_id "aqxeA6-O_Kk7aqBvaiGLWQAAAes"], referer: https://www.sqlerudition.com/suppress-the-error-number-severity-level-and-state-number-in-the-error-output/
[Thu Sep 17 15:39:15.781679 2026] [security2:error] [pid 20162:tid 20385] [client 95.142.47.113:60385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sqlerudition.com"] [uri "/wp-comments-post.php"] [unique_id "aqxeA6-O_Kk7aqBvaiGLWQAAAes"], referer: https://www.sqlerudition.com/suppress-the-error-number-severity-level-and-state-number-in-the-error-output/
[Thu Sep 17 15:39:15.827048 2026] [security2:error] [pid 20162:tid 20411] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeA6-O_Kk7aqBvaiGLWAAAAgU"]
[Thu Sep 17 15:39:15.877459 2026] [security2:error] [pid 18946:tid 19115] [client 216.24.219.35:47331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/style.php"] [unique_id "aqxeAzqiPMah0Tz_U1O_YQAAATE"]
[Thu Sep 17 15:39:16.160444 2026] [security2:error] [pid 18946:tid 19184] [client 216.24.219.20:62615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxeBDqiPMah0Tz_U1O_bgAAAXY"]
[Thu Sep 17 15:39:16.261484 2026] [security2:error] [pid 18946:tid 19086] [client 34.166.134.22:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/public_html/phpinfo.php"] [unique_id "aqxeBDqiPMah0Tz_U1O_dAAAARQ"]
[Thu Sep 17 15:39:16.295243 2026] [security2:error] [pid 18946:tid 19095] [client 43.173.173.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxeBDqiPMah0Tz_U1O_bAAAAR0"]
[Thu Sep 17 15:39:16.308478 2026] [security2:error] [pid 20162:tid 20378] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeBK-O_Kk7aqBvaiGLXQAAAeQ"]
[Thu Sep 17 15:39:16.344274 2026] [security2:error] [pid 18946:tid 19133] [client 43.172.196.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxeBDqiPMah0Tz_U1O_cgAAAUM"]
[Thu Sep 17 15:39:16.374395 2026] [security2:error] [pid 20162:tid 20373] [client 43.173.182.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxeBK-O_Kk7aqBvaiGLXwAAAd8"]
[Thu Sep 17 15:39:16.377685 2026] [security2:error] [pid 18946:tid 19159] [client 34.166.221.252:60222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxeBDqiPMah0Tz_U1O_dgAAAV0"]
[Thu Sep 17 15:39:16.504002 2026] [security2:error] [pid 20162:tid 20313] [client 216.24.219.36:45255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-editor.php"] [unique_id "aqxeBK-O_Kk7aqBvaiGLYgAAAaM"]
[Thu Sep 17 15:39:16.758765 2026] [security2:error] [pid 20162:tid 20293] [client 216.24.219.20:60049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/lufix.php"] [unique_id "aqxeBK-O_Kk7aqBvaiGLZQAAAY8"]
[Thu Sep 17 15:39:16.779055 2026] [security2:error] [pid 20162:tid 20365] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeBK-O_Kk7aqBvaiGLZAAAAdc"]
[Thu Sep 17 15:39:16.810284 2026] [security2:error] [pid 18946:tid 19167] [client 16.216.88.0:57344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxeBDqiPMah0Tz_U1O_fwABZSE"]
[Thu Sep 17 15:39:16.958888 2026] [security2:error] [pid 18946:tid 19106] [client 34.166.134.22:55660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/site/phpinfo.php"] [unique_id "aqxeBDqiPMah0Tz_U1O_hQAAASg"]
[Thu Sep 17 15:39:17.017613 2026] [security2:error] [pid 18946:tid 19160] [client 216.24.219.32:23757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/txets.php"] [unique_id "aqxeBTqiPMah0Tz_U1O_hwAAAV4"]
[Thu Sep 17 15:39:17.066960 2026] [security2:error] [pid 20162:tid 20299] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeBK-O_Kk7aqBvaiGLZgAAAZU"]
[Thu Sep 17 15:39:17.068894 2026] [security2:error] [pid 18946:tid 19145] [client 34.166.221.252:60226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/public/phpinfo.php"] [unique_id "aqxeBTqiPMah0Tz_U1O_iAAAAU8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:39:17.240302 2026] [security2:error] [pid 18946:tid 19122] [client 177.44.133.72:63718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeBTqiPMah0Tz_U1O_lQAAATg"]
[Thu Sep 17 15:39:17.240489 2026] [security2:error] [pid 18946:tid 19122] [client 177.44.133.72:63718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeBTqiPMah0Tz_U1O_lQAAATg"]
[Thu Sep 17 15:39:17.277013 2026] [security2:error] [pid 18946:tid 19090] [client 216.24.219.35:25155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxeBTqiPMah0Tz_U1O_lgAAARg"]
[Thu Sep 17 15:39:17.522920 2026] [security2:error] [pid 18946:tid 19138] [client 104.234.19.152:59923] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxeBTqiPMah0Tz_U1O_mAAAAUg"]
[Thu Sep 17 15:39:17.547033 2026] [security2:error] [pid 20162:tid 20312] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeBa-O_Kk7aqBvaiGLawAAAaI"]
[Thu Sep 17 15:39:17.644318 2026] [security2:error] [pid 20162:tid 20302] [client 34.166.134.22:55674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/docs/phpinfo.php"] [unique_id "aqxeBa-O_Kk7aqBvaiGLbQAAAZg"]
[Thu Sep 17 15:39:17.753700 2026] [security2:error] [pid 20162:tid 20377] [client 193.36.224.156:58999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxeBa-O_Kk7aqBvaiGLbwAAAeM"]
[Thu Sep 17 15:39:17.947124 2026] [security2:error] [pid 20162:tid 20342] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeBa-O_Kk7aqBvaiGLcAAAAcA"]
[Thu Sep 17 15:39:18.010918 2026] [security2:error] [pid 18946:tid 19091] [client 34.166.221.252:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/php-info.php"] [unique_id "aqxeBjqiPMah0Tz_U1O_oQAAARk"]
[Thu Sep 17 15:39:18.190131 2026] [security2:error] [pid 18946:tid 19127] [client 104.234.19.145:47829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/goods.php"] [unique_id "aqxeBjqiPMah0Tz_U1O_pwAAAT0"]
[Thu Sep 17 15:39:18.208168 2026] [security2:error] [pid 20162:tid 20346] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxeBq-O_Kk7aqBvaiGLdQAAAcQ"]
[Thu Sep 17 15:39:18.293308 2026] [authz_core:error] [pid 20162:tid 20334] [client 169.58.197.251:55949] AH01630: client denied by server configuration: /home2/sfvhbtor/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:39:18.330879 2026] [security2:error] [pid 18946:tid 19191] [client 34.166.134.22:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxeBjqiPMah0Tz_U1O_qQAAAX0"]
[Thu Sep 17 15:39:18.383318 2026] [security2:error] [pid 20162:tid 20329] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/.env~"] [unique_id "aqxeBq-O_Kk7aqBvaiGLdgAAAbM"]
[Thu Sep 17 15:39:18.545570 2026] [security2:error] [pid 20162:tid 20402] [client 216.24.219.36:32607] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "test.interlinck.com"] [uri "/php8.php"] [unique_id "aqxeBq-O_Kk7aqBvaiGLeAAAAfw"]
[Thu Sep 17 15:39:18.569393 2026] [security2:error] [pid 20162:tid 20404] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeBq-O_Kk7aqBvaiGLdwAAAf4"]
[Thu Sep 17 15:39:18.700730 2026] [security2:error] [pid 18946:tid 19095] [client 34.166.221.252:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/phpversion.php"] [unique_id "aqxeBjqiPMah0Tz_U1O_rAAAAR0"]
[Thu Sep 17 15:39:18.930637 2026] [security2:error] [pid 20162:tid 20401] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeBq-O_Kk7aqBvaiGLegAAAfs"]
[Thu Sep 17 15:39:19.017550 2026] [security2:error] [pid 18946:tid 19102] [client 34.166.134.22:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/administrator/phpinfo.php"] [unique_id "aqxeBzqiPMah0Tz_U1O_sAAAASQ"]
[Thu Sep 17 15:39:19.394557 2026] [security2:error] [pid 20162:tid 20364] [client 34.166.221.252:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/_phpinfo.php"] [unique_id "aqxeB6-O_Kk7aqBvaiGLfwAAAdY"]
[Thu Sep 17 15:39:19.405218 2026] [security2:error] [pid 20162:tid 20398] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeB6-O_Kk7aqBvaiGLfQAAAfg"]
[Thu Sep 17 15:39:19.704744 2026] [security2:error] [pid 20162:tid 20295] [client 34.166.134.22:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/core/phpinfo.php"] [unique_id "aqxeB6-O_Kk7aqBvaiGLggAAAZE"]
[Thu Sep 17 15:39:19.817060 2026] [security2:error] [pid 20162:tid 20335] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeB6-O_Kk7aqBvaiGLgQAAAbk"]
[Thu Sep 17 15:39:20.040653 2026] [security2:error] [pid 18946:tid 19175] [client 143.105.152.240:22071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeCDqiPMah0Tz_U1O_uQAAAW0"]
[Thu Sep 17 15:39:20.048573 2026] [security2:error] [pid 18946:tid 19175] [client 143.105.152.240:22071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeCDqiPMah0Tz_U1O_uQAAAW0"]
[Thu Sep 17 15:39:20.076753 2026] [security2:error] [pid 18946:tid 19165] [client 34.166.221.252:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/old_phpinfo.php"] [unique_id "aqxeCDqiPMah0Tz_U1O_uwAAAWM"]
[Thu Sep 17 15:39:20.280743 2026] [security2:error] [pid 20162:tid 20306] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeCK-O_Kk7aqBvaiGLhQAAAZw"]
[Thu Sep 17 15:39:20.389553 2026] [security2:error] [pid 18946:tid 19197] [client 34.166.134.22:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.134.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globaldove.org"] [uri "/includes/phpinfo.php"] [unique_id "aqxeCDqiPMah0Tz_U1O_wAAAAYM"]
[Thu Sep 17 15:39:20.596167 2026] [security2:error] [pid 20162:tid 20333] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeCK-O_Kk7aqBvaiGLhwAAAbc"]
[Thu Sep 17 15:39:20.754831 2026] [security2:error] [pid 18946:tid 19090] [client 34.166.221.252:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/server-info.php"] [unique_id "aqxeCDqiPMah0Tz_U1O_yAAAARg"]
[Thu Sep 17 15:39:20.865636 2026] [security2:error] [pid 20162:tid 20417] [client 79.116.89.151:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeCK-O_Kk7aqBvaiGLigAAAgs"]
[Thu Sep 17 15:39:20.865761 2026] [security2:error] [pid 20162:tid 20417] [client 79.116.89.151:52278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeCK-O_Kk7aqBvaiGLigAAAgs"]
[Thu Sep 17 15:39:20.887794 2026] [security2:error] [pid 20162:tid 20350] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeCK-O_Kk7aqBvaiGLiAAAAcg"]
[Thu Sep 17 15:39:21.015759 2026] [security2:error] [pid 18946:tid 19085] [client 136.158.61.34:25701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeCTqiPMah0Tz_U1O_ygAAARM"]
[Thu Sep 17 15:39:21.015905 2026] [security2:error] [pid 18946:tid 19085] [client 136.158.61.34:25701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeCTqiPMah0Tz_U1O_ygAAARM"]
[Thu Sep 17 15:39:21.164002 2026] [security2:error] [pid 20162:tid 20354] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxeCa-O_Kk7aqBvaiGLkwAAAcw"]
[Thu Sep 17 15:39:21.251748 2026] [security2:error] [pid 20162:tid 20325] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxeCa-O_Kk7aqBvaiGLlQAAAa8"]
[Thu Sep 17 15:39:21.320146 2026] [security2:error] [pid 20162:tid 20382] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxeCa-O_Kk7aqBvaiGLmAAAAeg"]
[Thu Sep 17 15:39:21.409800 2026] [security2:error] [pid 20162:tid 20399] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxeCa-O_Kk7aqBvaiGLmwAAAfk"]
[Thu Sep 17 15:39:21.444069 2026] [security2:error] [pid 20162:tid 20415] [client 34.166.221.252:60284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/server-status.php"] [unique_id "aqxeCa-O_Kk7aqBvaiGLnQAAAgk"]
[Thu Sep 17 15:39:21.482007 2026] [security2:error] [pid 20162:tid 20304] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxeCa-O_Kk7aqBvaiGLngAAAZo"]
[Thu Sep 17 15:39:21.549301 2026] [security2:error] [pid 20162:tid 20351] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxeCa-O_Kk7aqBvaiGLowAAAck"]
[Thu Sep 17 15:39:21.778763 2026] [security2:error] [pid 20162:tid 20411] [client 34.26.62.32:58318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeCa-O_Kk7aqBvaiGLpAAAAgU"]
[Thu Sep 17 15:39:22.097510 2026] [security2:error] [pid 20162:tid 20379] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLqQAAAeU"]
[Thu Sep 17 15:39:22.178828 2026] [security2:error] [pid 20162:tid 20344] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLqwAAAcI"]
[Thu Sep 17 15:39:22.251219 2026] [security2:error] [pid 20162:tid 20320] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLrQAAAao"]
[Thu Sep 17 15:39:22.318373 2026] [security2:error] [pid 20162:tid 20419] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLsAAAAg0"]
[Thu Sep 17 15:39:22.381620 2026] [security2:error] [pid 20162:tid 20332] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLsQAAAbY"]
[Thu Sep 17 15:39:22.441428 2026] [security2:error] [pid 20162:tid 20408] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLsgAAAgI"]
[Thu Sep 17 15:39:22.520095 2026] [security2:error] [pid 20162:tid 20319] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLtAAAAak"]
[Thu Sep 17 15:39:22.588269 2026] [security2:error] [pid 20162:tid 20339] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLtQAAAb0"]
[Thu Sep 17 15:39:22.705120 2026] [security2:error] [pid 18946:tid 19086] [client 34.166.221.252:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxeCjqiPMah0Tz_U1O_5AAAARQ"]
[Thu Sep 17 15:39:22.747487 2026] [security2:error] [pid 20162:tid 20334] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLvwAAAbg"]
[Thu Sep 17 15:39:22.865146 2026] [security2:error] [pid 20162:tid 20404] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLwAAAAf4"]
[Thu Sep 17 15:39:22.943205 2026] [security2:error] [pid 20162:tid 20361] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxeCq-O_Kk7aqBvaiGLwQAAAdM"]
[Thu Sep 17 15:39:23.011504 2026] [security2:error] [pid 20162:tid 20401] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGLxAAAAfs"]
[Thu Sep 17 15:39:23.098502 2026] [security2:error] [pid 20162:tid 20410] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGLxgAAAgQ"]
[Thu Sep 17 15:39:23.196937 2026] [security2:error] [pid 20162:tid 20364] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGLyQAAAdY"]
[Thu Sep 17 15:39:23.243728 2026] [authz_core:error] [pid 20162:tid 20358] [client 169.58.197.253:56980] AH01630: client denied by server configuration: /home2/brianpag/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:39:23.282380 2026] [security2:error] [pid 20162:tid 20366] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGLywAAAdg"]
[Thu Sep 17 15:39:23.356360 2026] [security2:error] [pid 20162:tid 20389] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGLzQAAAe8"]
[Thu Sep 17 15:39:23.387637 2026] [security2:error] [pid 20162:tid 20387] [client 34.166.221.252:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxeC6-O_Kk7aqBvaiGLzgAAAe0"]
[Thu Sep 17 15:39:23.391720 2026] [security2:error] [pid 20162:tid 20405] [client 200.192.101.164:39691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeC6-O_Kk7aqBvaiGLzAAB_y8"]
[Thu Sep 17 15:39:23.433812 2026] [security2:error] [pid 20162:tid 20345] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGLzwAAAcM"]
[Thu Sep 17 15:39:23.537845 2026] [security2:error] [pid 20162:tid 20335] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGL0QAAAbk"]
[Thu Sep 17 15:39:23.618833 2026] [security2:error] [pid 20162:tid 20370] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGL0gAAAdw"]
[Thu Sep 17 15:39:23.719521 2026] [security2:error] [pid 20162:tid 20343] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGL1AAAAcE"]
[Thu Sep 17 15:39:23.777675 2026] [security2:error] [pid 20162:tid 20416] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGL1gAAAgo"]
[Thu Sep 17 15:39:23.854657 2026] [security2:error] [pid 20162:tid 20375] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGL1wAAAeE"]
[Thu Sep 17 15:39:23.989796 2026] [security2:error] [pid 20162:tid 20324] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxeC6-O_Kk7aqBvaiGL2QAAAa4"]
[Thu Sep 17 15:39:24.001058 2026] [security2:error] [pid 20162:tid 20217] [remote 47.128.111.242:33460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lemuspools.com"] [uri "/reviews/product/468065"] [unique_id "aqxeDK-O_Kk7aqBvaiGL2gAB8DU"]
[Thu Sep 17 15:39:24.068991 2026] [security2:error] [pid 20162:tid 20306] [client 34.166.221.252:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxeDK-O_Kk7aqBvaiGL2wAAAZw"]
[Thu Sep 17 15:39:24.081148 2026] [security2:error] [pid 20162:tid 20350] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL3AAAAcg"]
[Thu Sep 17 15:39:24.151092 2026] [security2:error] [pid 20162:tid 20354] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL4AAAAcw"]
[Thu Sep 17 15:39:24.242414 2026] [security2:error] [pid 20162:tid 20325] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL4gAAAa8"]
[Thu Sep 17 15:39:24.315007 2026] [security2:error] [pid 20162:tid 20340] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL4wAAAb4"]
[Thu Sep 17 15:39:24.403881 2026] [security2:error] [pid 20162:tid 20309] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL5AAAAZ8"]
[Thu Sep 17 15:39:24.486436 2026] [security2:error] [pid 20162:tid 20413] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL5QAAAgc"]
[Thu Sep 17 15:39:24.551123 2026] [security2:error] [pid 20162:tid 20388] [client 103.61.184.148:53066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeDK-O_Kk7aqBvaiGL5wAAAe4"]
[Thu Sep 17 15:39:24.551265 2026] [security2:error] [pid 20162:tid 20388] [client 103.61.184.148:53066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeDK-O_Kk7aqBvaiGL5wAAAe4"]
[Thu Sep 17 15:39:24.581002 2026] [security2:error] [pid 20162:tid 20337] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL6AAAAbs"]
[Thu Sep 17 15:39:24.638647 2026] [security2:error] [pid 20162:tid 20307] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL6QAAAZ0"]
[Thu Sep 17 15:39:24.707328 2026] [security2:error] [pid 20162:tid 20338] [client 34.26.62.32:58318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxeDK-O_Kk7aqBvaiGL6gAAAbw"]
[Thu Sep 17 15:39:24.755819 2026] [security2:error] [pid 18946:tid 19135] [client 34.166.221.252:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxeDDqiPMah0Tz_U1PAAAAAAUU"]
[Thu Sep 17 15:39:24.933950 2026] [security2:error] [pid 18946:tid 19138] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxeDDqiPMah0Tz_U1PAAgAAAUg"]
[Thu Sep 17 15:39:25.038416 2026] [security2:error] [pid 18946:tid 19105] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PAAwAAASc"]
[Thu Sep 17 15:39:25.118686 2026] [security2:error] [pid 18946:tid 19196] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PABgAAAYI"]
[Thu Sep 17 15:39:25.233027 2026] [security2:error] [pid 18946:tid 19164] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PACAAAAWI"]
[Thu Sep 17 15:39:25.292679 2026] [security2:error] [pid 18946:tid 19123] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PACgAAATk"]
[Thu Sep 17 15:39:25.366406 2026] [security2:error] [pid 18946:tid 19101] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PACwAAASM"]
[Thu Sep 17 15:39:25.444968 2026] [security2:error] [pid 18946:tid 19082] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PADAAAARA"]
[Thu Sep 17 15:39:25.450021 2026] [security2:error] [pid 20162:tid 20314] [client 34.166.221.252:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxeDa-O_Kk7aqBvaiGL6wAAAaQ"]
[Thu Sep 17 15:39:25.512440 2026] [security2:error] [pid 18946:tid 19166] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PADwAAAWQ"]
[Thu Sep 17 15:39:25.590499 2026] [security2:error] [pid 18946:tid 19132] [client 151.77.154.8:56768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeDTqiPMah0Tz_U1PADQABQj4"]
[Thu Sep 17 15:39:25.594965 2026] [security2:error] [pid 18946:tid 19127] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PAEgAAAT0"]
[Thu Sep 17 15:39:25.668734 2026] [security2:error] [pid 18946:tid 19107] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PAFAAAASk"]
[Thu Sep 17 15:39:25.722216 2026] [security2:error] [pid 18946:tid 19080] [client 14.96.156.146:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeDTqiPMah0Tz_U1PAFQAAAQ4"]
[Thu Sep 17 15:39:25.722331 2026] [security2:error] [pid 18946:tid 19080] [client 14.96.156.146:59944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeDTqiPMah0Tz_U1PAFQAAAQ4"]
[Thu Sep 17 15:39:25.748768 2026] [security2:error] [pid 18946:tid 19125] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PAFgAAATs"]
[Thu Sep 17 15:39:25.827822 2026] [security2:error] [pid 18946:tid 19098] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PAGQAAASA"]
[Thu Sep 17 15:39:25.895980 2026] [security2:error] [pid 18946:tid 19176] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PAGgAAAW4"]
[Thu Sep 17 15:39:25.994436 2026] [security2:error] [pid 18946:tid 19142] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxeDTqiPMah0Tz_U1PAGwAAAUw"]
[Thu Sep 17 15:39:26.086919 2026] [security2:error] [pid 18946:tid 19169] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PAHQAAAWc"]
[Thu Sep 17 15:39:26.140412 2026] [security2:error] [pid 18946:tid 19087] [client 34.166.221.252:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxeDjqiPMah0Tz_U1PAIAAAARU"]
[Thu Sep 17 15:39:26.160244 2026] [security2:error] [pid 18946:tid 19092] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PAIQAAARo"]
[Thu Sep 17 15:39:26.291732 2026] [security2:error] [pid 18946:tid 19096] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PAJAAAAR4"]
[Thu Sep 17 15:39:26.443483 2026] [security2:error] [pid 18946:tid 19083] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PAJQAAARE"]
[Thu Sep 17 15:39:26.575374 2026] [security2:error] [pid 18946:tid 19111] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PAKQAAAS0"]
[Thu Sep 17 15:39:26.629635 2026] [security2:error] [pid 18946:tid 19159] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PALgAAAV0"]
[Thu Sep 17 15:39:26.727555 2026] [security2:error] [pid 18946:tid 19148] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PALwAAAVI"]
[Thu Sep 17 15:39:26.802265 2026] [security2:error] [pid 18946:tid 19199] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PAMAAAAYU"]
[Thu Sep 17 15:39:26.830309 2026] [security2:error] [pid 18946:tid 19192] [client 34.166.221.252:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxeDjqiPMah0Tz_U1PAMQAAAX4"]
[Thu Sep 17 15:39:26.882153 2026] [security2:error] [pid 18946:tid 19114] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PAMgAAATA"]
[Thu Sep 17 15:39:26.980869 2026] [security2:error] [pid 18946:tid 19150] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxeDjqiPMah0Tz_U1PANQAAAVQ"]
[Thu Sep 17 15:39:27.065350 2026] [security2:error] [pid 18946:tid 19121] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PANwAAATc"]
[Thu Sep 17 15:39:27.128787 2026] [security2:error] [pid 18946:tid 19103] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PAOwAAASU"]
[Thu Sep 17 15:39:27.212525 2026] [security2:error] [pid 18946:tid 19100] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PAPAAAASI"]
[Thu Sep 17 15:39:27.281253 2026] [security2:error] [pid 18946:tid 19167] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PAPgAAAWU"]
[Thu Sep 17 15:39:27.403703 2026] [security2:error] [pid 18946:tid 19076] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PAQgAAAQo"]
[Thu Sep 17 15:39:27.517657 2026] [security2:error] [pid 18946:tid 19155] [client 34.166.221.252:52638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/phpinfo.php.old"] [unique_id "aqxeDzqiPMah0Tz_U1PAQwAAAVk"]
[Thu Sep 17 15:39:27.542722 2026] [security2:error] [pid 18946:tid 19160] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PARQAAAV4"]
[Thu Sep 17 15:39:27.600342 2026] [security2:error] [pid 18946:tid 19122] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PASQAAATg"]
[Thu Sep 17 15:39:27.673640 2026] [security2:error] [pid 18946:tid 19189] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PASgAAAXs"]
[Thu Sep 17 15:39:27.733509 2026] [security2:error] [pid 18946:tid 19145] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PASwAAAU8"]
[Thu Sep 17 15:39:27.808162 2026] [security2:error] [pid 18946:tid 19099] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PATAAAASE"]
[Thu Sep 17 15:39:27.844427 2026] [security2:error] [pid 20162:tid 20378] [client 177.44.133.72:64378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeD6-O_Kk7aqBvaiGL8wAAAeQ"]
[Thu Sep 17 15:39:27.844580 2026] [security2:error] [pid 20162:tid 20378] [client 177.44.133.72:64378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeD6-O_Kk7aqBvaiGL8wAAAeQ"]
[Thu Sep 17 15:39:27.895476 2026] [security2:error] [pid 18946:tid 19202] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PATgAAAYg"]
[Thu Sep 17 15:39:27.982174 2026] [security2:error] [pid 18946:tid 19140] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxeDzqiPMah0Tz_U1PATwAAAUo"]
[Thu Sep 17 15:39:28.074739 2026] [security2:error] [pid 18946:tid 19129] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAUQAAAT8"]
[Thu Sep 17 15:39:28.171280 2026] [security2:error] [pid 18946:tid 19174] [client 210.222.43.21:65178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAUAAAAWw"], referer: http://talent-in-borders.com/Site
[Thu Sep 17 15:39:28.180970 2026] [security2:error] [pid 18946:tid 19179] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAVAAAAXE"]
[Thu Sep 17 15:39:28.201340 2026] [security2:error] [pid 18946:tid 19151] [client 34.166.221.252:52652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/phpinfo.php~"] [unique_id "aqxeEDqiPMah0Tz_U1PAVgAAAVU"]
[Thu Sep 17 15:39:28.266574 2026] [security2:error] [pid 18946:tid 19105] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAVwAAASc"]
[Thu Sep 17 15:39:28.343292 2026] [security2:error] [pid 18946:tid 19106] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAWAAAASg"]
[Thu Sep 17 15:39:28.420963 2026] [security2:error] [pid 18946:tid 19180] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAWQAAAXI"]
[Thu Sep 17 15:39:28.489599 2026] [security2:error] [pid 18946:tid 19123] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAWgAAATk"]
[Thu Sep 17 15:39:28.592255 2026] [security2:error] [pid 18946:tid 19118] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAXQAAATQ"]
[Thu Sep 17 15:39:28.658219 2026] [security2:error] [pid 18946:tid 19166] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAYQAAAWQ"]
[Thu Sep 17 15:39:28.725298 2026] [security2:error] [pid 18946:tid 19083] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAYgAAARE"]
[Thu Sep 17 15:39:28.852576 2026] [security2:error] [pid 18946:tid 19125] [client 45.115.26.203:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/test.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAawAAATs"]
[Thu Sep 17 15:39:28.852601 2026] [security2:error] [pid 18946:tid 19177] [client 45.115.26.203:37896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/phpinfo.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAbQAAAW8"]
[Thu Sep 17 15:39:28.857330 2026] [security2:error] [pid 18946:tid 19176] [client 45.115.26.203:37926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/i.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAcwAAAW4"]
[Thu Sep 17 15:39:28.859365 2026] [proxy_http:error] [pid 20162:tid 20332] (20014)Internal error (specific information not available): [client 45.115.26.203:37794] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:28.859380 2026] [proxy:error] [pid 20162:tid 20332] [client 45.115.26.203:37794] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/backend/.env
[Thu Sep 17 15:39:28.859388 2026] [proxy_http:error] [pid 18946:tid 19184] (20014)Internal error (specific information not available): [client 45.115.26.203:37804] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:28.859398 2026] [proxy:error] [pid 18946:tid 19184] [client 45.115.26.203:37804] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/.env
[Thu Sep 17 15:39:28.859420 2026] [security2:error] [pid 18946:tid 19119] [client 45.115.26.203:37910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/info.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAdAAAATU"]
[Thu Sep 17 15:39:28.859832 2026] [security2:error] [pid 18946:tid 19126] [client 45.115.26.203:37956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/php_info.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAdgAAATw"]
[Thu Sep 17 15:39:28.863085 2026] [security2:error] [pid 18946:tid 19077] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAdwAAAQs"]
[Thu Sep 17 15:39:28.865404 2026] [proxy_http:error] [pid 18946:tid 19142] (20014)Internal error (specific information not available): [client 45.115.26.203:38016] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:28.865426 2026] [proxy:error] [pid 18946:tid 19142] [client 45.115.26.203:38016] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/debug/vars
[Thu Sep 17 15:39:28.866343 2026] [proxy_http:error] [pid 20162:tid 20302] (20014)Internal error (specific information not available): [client 45.115.26.203:37782] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:28.866358 2026] [proxy:error] [pid 20162:tid 20302] [client 45.115.26.203:37782] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env~
[Thu Sep 17 15:39:28.870652 2026] [proxy_http:error] [pid 18946:tid 19080] (20014)Internal error (specific information not available): [client 45.115.26.203:37854] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:28.870680 2026] [proxy:error] [pid 18946:tid 19080] [client 45.115.26.203:37854] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.netrc
[Thu Sep 17 15:39:28.872176 2026] [proxy_http:error] [pid 20162:tid 20319] (20014)Internal error (specific information not available): [client 45.115.26.203:37848] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:28.872189 2026] [proxy:error] [pid 20162:tid 20319] [client 45.115.26.203:37848] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.docker/config.json
[Thu Sep 17 15:39:28.875881 2026] [proxy_http:error] [pid 18946:tid 19091] (20014)Internal error (specific information not available): [client 45.115.26.203:37832] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:28.875897 2026] [proxy:error] [pid 18946:tid 19091] [client 45.115.26.203:37832] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/src/.env
[Thu Sep 17 15:39:28.882726 2026] [security2:error] [pid 18946:tid 19190] [client 66.249.73.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thezoeyline.com"] [uri "/index.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAXgAAAXw"]
[Thu Sep 17 15:39:28.883425 2026] [security2:error] [pid 18946:tid 19144] [client 45.115.26.203:37968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/_phpinfo.php"] [unique_id "aqxeEDqiPMah0Tz_U1PAfQAAAU4"]
[Thu Sep 17 15:39:28.904678 2026] [security2:error] [pid 18946:tid 19136] [client 34.166.221.252:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/info.php.bak"] [unique_id "aqxeEDqiPMah0Tz_U1PAfgAAAUY"]
[Thu Sep 17 15:39:28.949814 2026] [security2:error] [pid 18946:tid 19079] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxeEDqiPMah0Tz_U1PAgAAAAQ0"]
[Thu Sep 17 15:39:29.001555 2026] [proxy_http:error] [pid 18946:tid 19153] (20014)Internal error (specific information not available): [client 45.115.26.203:38022] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:29.031346 2026] [security2:error] [pid 18946:tid 19103] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAhQAAASU"]
[Thu Sep 17 15:39:29.040531 2026] [security2:error] [pid 20162:tid 20377] [client 45.115.26.203:37794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.115.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.beiselcoaching.com"] [uri "/pi.php"] [unique_id "aqxeEa-O_Kk7aqBvaiGMBwAAAeM"]
[Thu Sep 17 15:39:29.042949 2026] [proxy_http:error] [pid 18946:tid 19152] (20014)Internal error (specific information not available): [client 45.115.26.203:37766] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:29.043449 2026] [proxy_http:error] [pid 20162:tid 20384] (20014)Internal error (specific information not available): [client 45.115.26.203:37698] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:29.048831 2026] [proxy_http:error] [pid 18946:tid 19094] (20014)Internal error (specific information not available): [client 45.115.26.203:38016] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:29.054623 2026] [proxy_http:error] [pid 18946:tid 19087] (20014)Internal error (specific information not available): [client 45.115.26.203:37646] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Sep 17 15:39:29.054637 2026] [proxy:error] [pid 18946:tid 19087] [client 45.115.26.203:37646] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.staging
[Thu Sep 17 15:39:29.059731 2026] [proxy_http:error] [pid 18946:tid 19128] (20014)Internal error (specific information not available): [client 45.115.26.203:37686] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.beiselcoaching.com/.env.backup
[Thu Sep 17 15:39:29.111564 2026] [security2:error] [pid 18946:tid 19137] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAkwAAAUc"]
[Thu Sep 17 15:39:29.190042 2026] [security2:error] [pid 18946:tid 19165] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAlQAAAWM"]
[Thu Sep 17 15:39:29.244103 2026] [security2:error] [pid 18946:tid 19135] [client 169.58.197.253:57346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ppfc.net"] [uri "/index.php"] [unique_id "aqxeDzqiPMah0Tz_U1PATQAAAUU"], referer: binance.com
[Thu Sep 17 15:39:29.269576 2026] [security2:error] [pid 18946:tid 19138] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAlwAAAUg"]
[Thu Sep 17 15:39:29.357328 2026] [security2:error] [pid 18946:tid 19164] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAmwAAAWI"]
[Thu Sep 17 15:39:29.455442 2026] [security2:error] [pid 18946:tid 19082] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAnQAAARA"]
[Thu Sep 17 15:39:29.585744 2026] [security2:error] [pid 18946:tid 19149] [client 34.166.221.252:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/phpinfo.php.save"] [unique_id "aqxeETqiPMah0Tz_U1PAnwAAAVM"]
[Thu Sep 17 15:39:29.599455 2026] [security2:error] [pid 18946:tid 19166] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAoQAAAWQ"]
[Thu Sep 17 15:39:29.705608 2026] [security2:error] [pid 18946:tid 19132] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxeETqiPMah0Tz_U1PApgAAAUI"]
[Thu Sep 17 15:39:29.780141 2026] [security2:error] [pid 18946:tid 19177] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAqAAAAW8"]
[Thu Sep 17 15:39:29.858968 2026] [security2:error] [pid 18946:tid 19126] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAqgAAATw"]
[Thu Sep 17 15:39:29.869056 2026] [security2:error] [pid 20162:tid 20370] [client 43.173.181.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxeEa-O_Kk7aqBvaiGMEAAAAdw"]
[Thu Sep 17 15:39:29.927940 2026] [security2:error] [pid 18946:tid 19193] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxeETqiPMah0Tz_U1PAqwAAAX8"]
[Thu Sep 17 15:39:30.018948 2026] [security2:error] [pid 18946:tid 19148] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PArAAAAVI"]
[Thu Sep 17 15:39:30.096515 2026] [security2:error] [pid 18946:tid 19162] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PArwAAAWA"]
[Thu Sep 17 15:39:30.172142 2026] [security2:error] [pid 18946:tid 19147] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAsAAAAVE"]
[Thu Sep 17 15:39:30.272001 2026] [security2:error] [pid 18946:tid 19184] [client 34.166.221.252:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxeEjqiPMah0Tz_U1PAsgAAAXY"]
[Thu Sep 17 15:39:30.273096 2026] [security2:error] [pid 18946:tid 19101] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAsQAAASM"]
[Thu Sep 17 15:39:30.355199 2026] [security2:error] [pid 18946:tid 19096] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAswAAAR4"]
[Thu Sep 17 15:39:30.458088 2026] [security2:error] [pid 18946:tid 19191] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAtAAAAX0"]
[Thu Sep 17 15:39:30.496526 2026] [security2:error] [pid 18946:tid 19127] [client 143.105.152.240:35257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeEjqiPMah0Tz_U1PAtQAAAT0"]
[Thu Sep 17 15:39:30.496668 2026] [security2:error] [pid 18946:tid 19127] [client 143.105.152.240:35257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeEjqiPMah0Tz_U1PAtQAAAT0"]
[Thu Sep 17 15:39:30.519876 2026] [security2:error] [pid 18946:tid 19192] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAtgAAAX4"]
[Thu Sep 17 15:39:30.594579 2026] [security2:error] [pid 18946:tid 19172] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAuQAAAWo"]
[Thu Sep 17 15:39:30.697379 2026] [security2:error] [pid 18946:tid 19200] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAvAAAAYY"]
[Thu Sep 17 15:39:30.729199 2026] [security2:error] [pid 20162:tid 20375] [client 34.122.173.216:1232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeEq-O_Kk7aqBvaiGMEgAB4S4"]
[Thu Sep 17 15:39:30.774924 2026] [security2:error] [pid 18946:tid 19076] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAwAAAAQo"]
[Thu Sep 17 15:39:30.892182 2026] [security2:error] [pid 20162:tid 20390] [client 34.122.173.216:1232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeEq-O_Kk7aqBvaiGMEwAB8Dg"]
[Thu Sep 17 15:39:30.898964 2026] [security2:error] [pid 18946:tid 19137] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PAzgAAAUc"]
[Thu Sep 17 15:39:30.960825 2026] [security2:error] [pid 18946:tid 19188] [client 34.166.221.252:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxeEjqiPMah0Tz_U1PA0AAAAXo"]
[Thu Sep 17 15:39:31.005835 2026] [security2:error] [pid 18946:tid 19133] [client 187.188.79.162:53690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeEjqiPMah0Tz_U1PAzwABQ1k"]
[Thu Sep 17 15:39:31.012549 2026] [security2:error] [pid 18946:tid 19170] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxeEjqiPMah0Tz_U1PA0QAAAWg"]
[Thu Sep 17 15:39:31.089384 2026] [security2:error] [pid 18946:tid 19154] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxeEzqiPMah0Tz_U1PA1QAAAVg"]
[Thu Sep 17 15:39:31.166636 2026] [security2:error] [pid 18946:tid 19122] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxeEzqiPMah0Tz_U1PA2QAAATg"]
[Thu Sep 17 15:39:31.183958 2026] [security2:error] [pid 20162:tid 20417] [client 34.122.173.216:1232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeE6-O_Kk7aqBvaiGMFQACCzs"]
[Thu Sep 17 15:39:31.234292 2026] [security2:error] [pid 18946:tid 19186] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxeEzqiPMah0Tz_U1PA2gAAAXg"]
[Thu Sep 17 15:39:31.374060 2026] [security2:error] [pid 18946:tid 19145] [client 45.173.97.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cellovsviolin.com"] [uri "/index.php"] [unique_id "aqxeETqiPMah0Tz_U1PAlAAAAU8"], referer: https://cellovsviolin.com/
[Thu Sep 17 15:39:31.440623 2026] [security2:error] [pid 18946:tid 19078] [client 34.26.62.32:49394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeEzqiPMah0Tz_U1PA2wAAAQw"]
[Thu Sep 17 15:39:31.499185 2026] [security2:error] [pid 20162:tid 20350] [client 79.116.89.151:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeE6-O_Kk7aqBvaiGMGwAAAcg"]
[Thu Sep 17 15:39:31.499293 2026] [security2:error] [pid 20162:tid 20350] [client 79.116.89.151:52902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeE6-O_Kk7aqBvaiGMGwAAAcg"]
[Thu Sep 17 15:39:31.642679 2026] [security2:error] [pid 18946:tid 19129] [client 34.166.221.252:52690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxeEzqiPMah0Tz_U1PA4AAAAT8"]
[Thu Sep 17 15:39:31.893100 2026] [security2:error] [pid 18946:tid 19093] [client 34.26.62.32:49394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeEzqiPMah0Tz_U1PA4gAAARs"]
[Thu Sep 17 15:39:32.163168 2026] [security2:error] [pid 18946:tid 19132] [client 34.26.62.32:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxeFDqiPMah0Tz_U1PA6QAAAUI"]
[Thu Sep 17 15:39:32.335240 2026] [security2:error] [pid 20162:tid 20307] [client 34.166.221.252:52706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxeFK-O_Kk7aqBvaiGMHQAAAZ0"]
[Thu Sep 17 15:39:32.449592 2026] [security2:error] [pid 20162:tid 20338] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxeFK-O_Kk7aqBvaiGMHwAAAbw"]
[Thu Sep 17 15:39:32.572943 2026] [security2:error] [pid 20162:tid 20300] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxeFK-O_Kk7aqBvaiGMIAAAAZY"]
[Thu Sep 17 15:39:32.651416 2026] [security2:error] [pid 20162:tid 20314] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxeFK-O_Kk7aqBvaiGMIgAAAaQ"]
[Thu Sep 17 15:39:32.756394 2026] [security2:error] [pid 20162:tid 20399] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxeFK-O_Kk7aqBvaiGMIwAAAfk"]
[Thu Sep 17 15:39:32.825882 2026] [security2:error] [pid 20162:tid 20415] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxeFK-O_Kk7aqBvaiGMJAAAAgk"]
[Thu Sep 17 15:39:32.918056 2026] [security2:error] [pid 20162:tid 20403] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxeFK-O_Kk7aqBvaiGMJQAAAf0"]
[Thu Sep 17 15:39:32.974500 2026] [access_compat:error] [pid 20162:tid 20374] [client 162.241.226.11:33866] AH01797: client denied by server configuration: /home3/whereso8/public_html/wherearetheymeow/wp-admin/upgrade.php
[Thu Sep 17 15:39:32.991419 2026] [security2:error] [pid 20162:tid 20411] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxeFK-O_Kk7aqBvaiGMKAAAAgU"]
[Thu Sep 17 15:39:33.045391 2026] [security2:error] [pid 18946:tid 19107] [client 34.166.221.252:52714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxeFTqiPMah0Tz_U1PA7wAAASk"]
[Thu Sep 17 15:39:33.102812 2026] [security2:error] [pid 20162:tid 20322] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMKQAAAaw"]
[Thu Sep 17 15:39:33.138444 2026] [security2:error] [pid 18946:tid 19123] [client 45.180.198.109:4271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxeFDqiPMah0Tz_U1PA7gABOXc"], referer: https://www.enolastable.com/2016/11/08/it-cost-me-93-95-to-vote/
[Thu Sep 17 15:39:33.205741 2026] [security2:error] [pid 20162:tid 20368] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMLQAAAdo"]
[Thu Sep 17 15:39:33.289210 2026] [security2:error] [pid 20162:tid 20348] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMLwAAAcY"]
[Thu Sep 17 15:39:33.362248 2026] [security2:error] [pid 18946:tid 19080] [client 212.237.125.217:56760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeFTqiPMah0Tz_U1PA9AABDl8"]
[Thu Sep 17 15:39:33.428719 2026] [security2:error] [pid 20162:tid 20357] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMMwAAAc8"]
[Thu Sep 17 15:39:33.506936 2026] [security2:error] [pid 20162:tid 20353] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMNAAAAcs"]
[Thu Sep 17 15:39:33.603077 2026] [security2:error] [pid 20162:tid 20293] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMNQAAAY8"]
[Thu Sep 17 15:39:33.661626 2026] [security2:error] [pid 20162:tid 20326] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMNgAAAbA"]
[Thu Sep 17 15:39:33.724226 2026] [security2:error] [pid 18946:tid 19086] [client 34.166.221.252:52722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/www/phpinfo.php"] [unique_id "aqxeFTqiPMah0Tz_U1PA_QAAARQ"]
[Thu Sep 17 15:39:33.734483 2026] [security2:error] [pid 20162:tid 20313] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMOAAAAaM"]
[Thu Sep 17 15:39:33.847141 2026] [security2:error] [pid 20162:tid 20419] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMOQAAAg0"]
[Thu Sep 17 15:39:33.931193 2026] [security2:error] [pid 20162:tid 20356] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxeFa-O_Kk7aqBvaiGMOgAAAc4"]
[Thu Sep 17 15:39:34.010097 2026] [security2:error] [pid 20162:tid 20336] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMPAAAAbo"]
[Thu Sep 17 15:39:34.082405 2026] [security2:error] [pid 20162:tid 20346] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMPgAAAcQ"]
[Thu Sep 17 15:39:34.170503 2026] [security2:error] [pid 20162:tid 20332] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMPwAAAbY"]
[Thu Sep 17 15:39:34.259849 2026] [security2:error] [pid 20162:tid 20319] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMQAAAAak"]
[Thu Sep 17 15:39:34.336751 2026] [security2:error] [pid 20162:tid 20397] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMQQAAAfc"]
[Thu Sep 17 15:39:34.417610 2026] [security2:error] [pid 18946:tid 19097] [client 34.166.221.252:48280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxeFjqiPMah0Tz_U1PBAgAAAR8"]
[Thu Sep 17 15:39:34.433936 2026] [security2:error] [pid 20162:tid 20334] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMQgAAAbg"]
[Thu Sep 17 15:39:34.546215 2026] [security2:error] [pid 20162:tid 20302] [client 136.158.61.34:27012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeFq-O_Kk7aqBvaiGMQwAAAZg"]
[Thu Sep 17 15:39:34.546330 2026] [security2:error] [pid 20162:tid 20302] [client 136.158.61.34:27012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeFq-O_Kk7aqBvaiGMQwAAAZg"]
[Thu Sep 17 15:39:34.556345 2026] [security2:error] [pid 20162:tid 20297] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMRAAAAZM"]
[Thu Sep 17 15:39:34.679459 2026] [security2:error] [pid 20162:tid 20414] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMRwAAAgg"]
[Thu Sep 17 15:39:34.792040 2026] [security2:error] [pid 20162:tid 20384] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMSgAAAeo"]
[Thu Sep 17 15:39:34.914818 2026] [security2:error] [pid 20162:tid 20327] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxeFq-O_Kk7aqBvaiGMSwAAAbE"]
[Thu Sep 17 15:39:35.023440 2026] [security2:error] [pid 20162:tid 20361] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMTAAAAdM"]
[Thu Sep 17 15:39:35.097671 2026] [security2:error] [pid 20162:tid 20404] [client 34.166.221.252:48294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMTgAAAf4"]
[Thu Sep 17 15:39:35.124620 2026] [security2:error] [pid 20162:tid 20410] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMTwAAAgQ"]
[Thu Sep 17 15:39:35.147327 2026] [security2:error] [pid 20162:tid 20383] [client 103.61.184.148:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMUAAAAek"]
[Thu Sep 17 15:39:35.147458 2026] [security2:error] [pid 20162:tid 20383] [client 103.61.184.148:53595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMUAAAAek"]
[Thu Sep 17 15:39:35.228011 2026] [security2:error] [pid 20162:tid 20400] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMUQAAAfo"]
[Thu Sep 17 15:39:35.365228 2026] [security2:error] [pid 20162:tid 20329] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMVAAAAbM"]
[Thu Sep 17 15:39:35.436083 2026] [security2:error] [pid 18946:tid 19128] [client 3.82.141.143:11872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.backup"] [unique_id "aqxeFzqiPMah0Tz_U1PBEwAAAT4"]
[Thu Sep 17 15:39:35.437103 2026] [security2:error] [pid 20162:tid 20386] [client 3.82.141.143:12194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp-config.php~"] [unique_id "aqxeF6-O_Kk7aqBvaiGMXAAAAew"]
[Thu Sep 17 15:39:35.437339 2026] [security2:error] [pid 18946:tid 19087] [client 3.82.141.143:12060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/web.config"] [unique_id "aqxeFzqiPMah0Tz_U1PBFgAAARU"]
[Thu Sep 17 15:39:35.437430 2026] [security2:error] [pid 20162:tid 20393] [client 3.82.141.143:12164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp-config.php.bak"] [unique_id "aqxeF6-O_Kk7aqBvaiGMXQAAAfM"]
[Thu Sep 17 15:39:35.437532 2026] [security2:error] [pid 20162:tid 20362] [client 3.82.141.143:11846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMWwAAAdQ"]
[Thu Sep 17 15:39:35.440674 2026] [security2:error] [pid 18946:tid 19105] [client 3.82.141.143:12152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp-config.php.old"] [unique_id "aqxeFzqiPMah0Tz_U1PBIAAAASc"]
[Thu Sep 17 15:39:35.440676 2026] [security2:error] [pid 18946:tid 19129] [client 3.82.141.143:12170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp-config.php.save"] [unique_id "aqxeFzqiPMah0Tz_U1PBHwAAAT8"]
[Thu Sep 17 15:39:35.441803 2026] [security2:error] [pid 20162:tid 20321] [client 3.82.141.143:11910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.bak"] [unique_id "aqxeF6-O_Kk7aqBvaiGMYQAAAas"]
[Thu Sep 17 15:39:35.446673 2026] [security2:error] [pid 18946:tid 19163] [client 3.82.141.143:11898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/.env.old"] [unique_id "aqxeFzqiPMah0Tz_U1PBKwAAAWE"]
[Thu Sep 17 15:39:35.452595 2026] [security2:error] [pid 18946:tid 19106] [client 3.82.141.143:12216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/wp-config.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBGQAAASg"]
[Thu Sep 17 15:39:35.458079 2026] [security2:error] [pid 18946:tid 19110] [client 3.82.141.143:11990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/config.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBLQAAASw"]
[Thu Sep 17 15:39:35.477548 2026] [security2:error] [pid 20162:tid 20363] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMbwAAAdU"]
[Thu Sep 17 15:39:35.585356 2026] [security2:error] [pid 20162:tid 20318] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMegAAAag"]
[Thu Sep 17 15:39:35.665196 2026] [security2:error] [pid 20162:tid 20359] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMfAAAAdE"]
[Thu Sep 17 15:39:35.735177 2026] [security2:error] [pid 20162:tid 20399] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMfgAAAfk"]
[Thu Sep 17 15:39:35.783509 2026] [security2:error] [pid 18946:tid 19120] [client 34.166.221.252:48302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/site/phpinfo.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBRQAAATY"]
[Thu Sep 17 15:39:35.826254 2026] [security2:error] [pid 20162:tid 20349] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxeF6-O_Kk7aqBvaiGMfwAAAcc"]
[Thu Sep 17 15:39:36.016910 2026] [security2:error] [pid 20162:tid 20374] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMgwAAAeA"]
[Thu Sep 17 15:39:36.133783 2026] [security2:error] [pid 20162:tid 20301] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMhgAAAZc"]
[Thu Sep 17 15:39:36.242922 2026] [security2:error] [pid 20162:tid 20368] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMhwAAAdo"]
[Thu Sep 17 15:39:36.312604 2026] [security2:error] [pid 20162:tid 20352] [client 14.96.156.146:60593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeGK-O_Kk7aqBvaiGMiAAAAco"]
[Thu Sep 17 15:39:36.313067 2026] [security2:error] [pid 20162:tid 20352] [client 14.96.156.146:60593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeGK-O_Kk7aqBvaiGMiAAAAco"]
[Thu Sep 17 15:39:36.340126 2026] [security2:error] [pid 20162:tid 20348] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMiQAAAcY"]
[Thu Sep 17 15:39:36.410259 2026] [security2:error] [pid 20162:tid 20379] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMigAAAeU"]
[Thu Sep 17 15:39:36.465079 2026] [security2:error] [pid 18946:tid 19191] [client 34.166.221.252:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxeGDqiPMah0Tz_U1PBSwAAAX0"]
[Thu Sep 17 15:39:36.504214 2026] [security2:error] [pid 20162:tid 20326] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMjQAAAbA"]
[Thu Sep 17 15:39:36.591146 2026] [security2:error] [pid 20162:tid 20367] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMjgAAAdk"]
[Thu Sep 17 15:39:36.631433 2026] [security2:error] [pid 20162:tid 20419] [client 74.7.230.24:60526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "seh.yiu.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxeGK-O_Kk7aqBvaiGMkQAAAg0"]
[Thu Sep 17 15:39:36.650283 2026] [security2:error] [pid 20162:tid 20328] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMkgAAAbI"]
[Thu Sep 17 15:39:36.720521 2026] [security2:error] [pid 20162:tid 20420] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMkwAAAg4"]
[Thu Sep 17 15:39:36.795741 2026] [security2:error] [pid 20162:tid 20312] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMlAAAAaI"]
[Thu Sep 17 15:39:36.881485 2026] [security2:error] [pid 20162:tid 20342] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMlQAAAcA"]
[Thu Sep 17 15:39:36.969536 2026] [security2:error] [pid 20162:tid 20334] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxeGK-O_Kk7aqBvaiGMlgAAAbg"]
[Thu Sep 17 15:39:37.090306 2026] [security2:error] [pid 20162:tid 20377] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMlwAAAeM"]
[Thu Sep 17 15:39:37.162207 2026] [security2:error] [pid 20162:tid 20397] [client 34.166.221.252:48316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxeGa-O_Kk7aqBvaiGMmwAAAfc"]
[Thu Sep 17 15:39:37.163431 2026] [security2:error] [pid 20162:tid 20305] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMmgAAAZs"]
[Thu Sep 17 15:39:37.197019 2026] [security2:error] [pid 18946:tid 19143] [client 169.58.197.253:57872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ppfc.net"] [uri "/index.php"] [unique_id "aqxeGTqiPMah0Tz_U1PBUQAAAU0"], referer: binance.com
[Thu Sep 17 15:39:37.275449 2026] [security2:error] [pid 20162:tid 20310] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMnwAAAaA"]
[Thu Sep 17 15:39:37.416196 2026] [security2:error] [pid 20162:tid 20383] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMoAAAAek"]
[Thu Sep 17 15:39:37.493930 2026] [security2:error] [pid 20162:tid 20299] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMoQAAAZU"]
[Thu Sep 17 15:39:37.558740 2026] [security2:error] [pid 20162:tid 20372] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMogAAAd4"]
[Thu Sep 17 15:39:37.640322 2026] [security2:error] [pid 20162:tid 20303] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMowAAAZk"]
[Thu Sep 17 15:39:37.733168 2026] [security2:error] [pid 20162:tid 20366] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMpgAAAdg"]
[Thu Sep 17 15:39:37.831130 2026] [security2:error] [pid 20162:tid 20360] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMpwAAAdI"]
[Thu Sep 17 15:39:37.846301 2026] [security2:error] [pid 20162:tid 20400] [client 34.166.221.252:48330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxeGa-O_Kk7aqBvaiGMqAAAAfo"]
[Thu Sep 17 15:39:37.908265 2026] [security2:error] [pid 20162:tid 20409] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMqQAAAgM"]
[Thu Sep 17 15:39:37.978071 2026] [security2:error] [pid 20162:tid 20386] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxeGa-O_Kk7aqBvaiGMqgAAAew"]
[Thu Sep 17 15:39:38.123904 2026] [security2:error] [pid 20162:tid 20395] [client 34.26.62.32:49402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxeGq-O_Kk7aqBvaiGMqwAAAfU"]
[Thu Sep 17 15:39:38.239494 2026] [security2:error] [pid 20162:tid 20335] [client 34.26.62.32:49402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxeGq-O_Kk7aqBvaiGMrQAAAbk"]
[Thu Sep 17 15:39:38.311624 2026] [security2:error] [pid 20162:tid 20389] [client 40.77.167.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxeGq-O_Kk7aqBvaiGMrAAAAe8"]
[Thu Sep 17 15:39:38.503615 2026] [security2:error] [pid 18946:tid 19165] [client 177.44.133.72:65047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeGjqiPMah0Tz_U1PBXwAAAWM"]
[Thu Sep 17 15:39:38.503745 2026] [security2:error] [pid 18946:tid 19165] [client 177.44.133.72:65047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeGjqiPMah0Tz_U1PBXwAAAWM"]
[Thu Sep 17 15:39:38.543976 2026] [security2:error] [pid 20162:tid 20363] [client 34.166.221.252:48340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/core/phpinfo.php"] [unique_id "aqxeGq-O_Kk7aqBvaiGMsAAAAdU"]
[Thu Sep 17 15:39:38.606222 2026] [security2:error] [pid 18946:tid 19154] [client 34.26.62.32:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/info.php"] [unique_id "aqxeGjqiPMah0Tz_U1PBYQAAAVg"]
[Thu Sep 17 15:39:38.939508 2026] [security2:error] [pid 20162:tid 20349] [client 34.26.62.32:53898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/php.php"] [unique_id "aqxeGq-O_Kk7aqBvaiGMswAAAcc"]
[Thu Sep 17 15:39:39.139422 2026] [security2:error] [pid 20162:tid 20314] [client 207.46.13.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxeGq-O_Kk7aqBvaiGMtAAAAaQ"]
[Thu Sep 17 15:39:39.237556 2026] [security2:error] [pid 20162:tid 20415] [client 34.166.221.252:48348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.221.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.enolastable.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxeG6-O_Kk7aqBvaiGMtQAAAgk"]
[Thu Sep 17 15:39:39.273793 2026] [security2:error] [pid 18946:tid 19085] [client 34.26.62.32:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/i.php"] [unique_id "aqxeGzqiPMah0Tz_U1PBawAAARM"]
[Thu Sep 17 15:39:39.448259 2026] [security2:error] [pid 18946:tid 19118] [client 193.250.106.118:48832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeGzqiPMah0Tz_U1PBbAABNBk"]
[Thu Sep 17 15:39:39.571323 2026] [security2:error] [pid 18946:tid 19172] [client 34.26.62.32:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxeGzqiPMah0Tz_U1PBbgAAAWo"]
[Thu Sep 17 15:39:39.953209 2026] [security2:error] [pid 18946:tid 19191] [client 34.26.62.32:53930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxeGzqiPMah0Tz_U1PBdwAAAX0"]
[Thu Sep 17 15:39:40.226369 2026] [security2:error] [pid 18946:tid 19152] [client 34.26.62.32:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/test.php"] [unique_id "aqxeHDqiPMah0Tz_U1PBfQAAAVY"]
[Thu Sep 17 15:39:40.683826 2026] [security2:error] [pid 18946:tid 19097] [client 34.26.62.32:53952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeHDqiPMah0Tz_U1PBgQAAAR8"]
[Thu Sep 17 15:39:40.943375 2026] [security2:error] [pid 18946:tid 19154] [client 34.26.62.32:53952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/p.php"] [unique_id "aqxeHDqiPMah0Tz_U1PBhwAAAVg"]
[Thu Sep 17 15:39:41.123261 2026] [security2:error] [pid 20162:tid 20320] [client 139.135.192.109:35095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeHK-O_Kk7aqBvaiGMvgABqj8"]
[Thu Sep 17 15:39:41.211283 2026] [security2:error] [pid 18946:tid 19163] [client 34.26.62.32:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxeHTqiPMah0Tz_U1PBiwAAAWE"]
[Thu Sep 17 15:39:41.452741 2026] [security2:error] [pid 18946:tid 19116] [client 143.105.152.240:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeHTqiPMah0Tz_U1PBkAAAATI"]
[Thu Sep 17 15:39:41.452912 2026] [security2:error] [pid 18946:tid 19116] [client 143.105.152.240:64246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeHTqiPMah0Tz_U1PBkAAAATI"]
[Thu Sep 17 15:39:41.507311 2026] [security2:error] [pid 20162:tid 20334] [client 34.26.62.32:53970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxeHa-O_Kk7aqBvaiGMwwAAAbg"]
[Thu Sep 17 15:39:41.781120 2026] [security2:error] [pid 18946:tid 19178] [client 34.26.62.32:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxeHTqiPMah0Tz_U1PBlQAAAXA"]
[Thu Sep 17 15:39:42.060483 2026] [security2:error] [pid 20162:tid 20383] [client 34.26.62.32:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxeHq-O_Kk7aqBvaiGMygAAAek"]
[Thu Sep 17 15:39:42.086518 2026] [security2:error] [pid 18946:tid 19120] [client 79.116.89.151:53523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeHjqiPMah0Tz_U1PBlwAAATY"]
[Thu Sep 17 15:39:42.086695 2026] [security2:error] [pid 18946:tid 19120] [client 79.116.89.151:53523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeHjqiPMah0Tz_U1PBlwAAATY"]
[Thu Sep 17 15:39:42.345237 2026] [security2:error] [pid 20162:tid 20303] [client 34.26.62.32:54004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxeHq-O_Kk7aqBvaiGMzAAAAZk"]
[Thu Sep 17 15:39:42.600451 2026] [security2:error] [pid 20162:tid 20400] [client 64.16.133.24:16099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thephoenixprojects.org"] [uri "/index.php"] [unique_id "aqxeHq-O_Kk7aqBvaiGMzgAAAfo"]
[Thu Sep 17 15:39:42.607228 2026] [security2:error] [pid 18946:tid 19153] [client 34.26.62.32:54018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxeHjqiPMah0Tz_U1PBpgAAAVc"]
[Thu Sep 17 15:39:42.875632 2026] [security2:error] [pid 20162:tid 20393] [client 34.26.62.32:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxeHq-O_Kk7aqBvaiGM0wAAAfM"]
[Thu Sep 17 15:39:42.953478 2026] [security2:error] [pid 18946:tid 19156] [client 52.231.79.181:1101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/autoload_classmap.php"] [unique_id "aqxeHjqiPMah0Tz_U1PBrgAAAVo"]
[Thu Sep 17 15:39:43.084590 2026] [security2:error] [pid 18946:tid 19160] [client 52.231.79.181:1121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/post.php"] [unique_id "aqxeHzqiPMah0Tz_U1PBsAAAAV4"]
[Thu Sep 17 15:39:43.486287 2026] [security2:error] [pid 20162:tid 20398] [client 34.26.62.32:50660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeH6-O_Kk7aqBvaiGM2QAAAfg"]
[Thu Sep 17 15:39:43.497231 2026] [security2:error] [pid 20162:tid 20403] [client 52.231.79.181:1439] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "p3collaborative.com"] [uri "/1.php"] [unique_id "aqxeH6-O_Kk7aqBvaiGM4AAAAf0"]
[Thu Sep 17 15:39:43.497373 2026] [security2:error] [pid 20162:tid 20403] [client 52.231.79.181:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/1.php"] [unique_id "aqxeH6-O_Kk7aqBvaiGM4AAAAf0"]
[Thu Sep 17 15:39:43.654409 2026] [security2:error] [pid 20162:tid 20399] [client 40.77.167.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.theholyarkproject.com"] [uri "/index.php"] [unique_id "aqxeH6-O_Kk7aqBvaiGM3gAAAfk"]
[Thu Sep 17 15:39:43.764072 2026] [security2:error] [pid 20162:tid 20341] [client 34.26.62.32:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxeH6-O_Kk7aqBvaiGM5AAAAb8"]
[Thu Sep 17 15:39:43.911232 2026] [security2:error] [pid 18946:tid 19129] [client 52.231.79.181:1113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/flower.php"] [unique_id "aqxeHzqiPMah0Tz_U1PBtAAAAT8"]
[Thu Sep 17 15:39:43.982941 2026] [security2:error] [pid 18946:tid 19175] [client 34.26.62.32:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxeHzqiPMah0Tz_U1PBtQAAAW0"]
[Thu Sep 17 15:39:44.297280 2026] [security2:error] [pid 18946:tid 19133] [client 34.26.62.32:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxeIDqiPMah0Tz_U1PBvAAAAUM"]
[Thu Sep 17 15:39:44.308727 2026] [security2:error] [pid 18946:tid 19111] [client 52.231.79.181:1126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/meta.php"] [unique_id "aqxeIDqiPMah0Tz_U1PBvQAAAS0"]
[Thu Sep 17 15:39:44.550103 2026] [security2:error] [pid 20162:tid 20336] [client 34.26.62.32:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxeIK-O_Kk7aqBvaiGM6QAAAbo"]
[Thu Sep 17 15:39:44.710997 2026] [security2:error] [pid 20162:tid 20391] [client 52.231.79.181:1108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/about.php"] [unique_id "aqxeIK-O_Kk7aqBvaiGM7AAAAfE"]
[Thu Sep 17 15:39:44.800053 2026] [security2:error] [pid 18946:tid 19100] [client 34.26.62.32:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxeIDqiPMah0Tz_U1PBwwAAASI"]
[Thu Sep 17 15:39:45.036319 2026] [security2:error] [pid 20162:tid 20312] [client 34.26.62.32:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGM8gAAAaI"]
[Thu Sep 17 15:39:45.111110 2026] [security2:error] [pid 18946:tid 19201] [client 52.231.79.181:1228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/randkeyword.php"] [unique_id "aqxeITqiPMah0Tz_U1PBxwAAAYc"]
[Thu Sep 17 15:39:45.449373 2026] [security2:error] [pid 18946:tid 19164] [client 34.26.62.32:50704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PByAAAAWI"]
[Thu Sep 17 15:39:45.507696 2026] [security2:error] [pid 20162:tid 20381] [client 52.231.79.181:1432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/goods.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGM9AAAAec"]
[Thu Sep 17 15:39:45.786792 2026] [security2:error] [pid 18946:tid 19133] [client 34.26.62.32:50704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB8gAAAUM"]
[Thu Sep 17 15:39:45.937069 2026] [security2:error] [pid 20162:tid 20389] [client 52.231.79.181:1441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/hehe.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGNFgAAAe8"]
[Thu Sep 17 15:39:45.969444 2026] [security2:error] [pid 18946:tid 19092] [client 34.26.62.32:50704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxeITqiPMah0Tz_U1PB9AAAARo"]
[Thu Sep 17 15:39:46.205252 2026] [security2:error] [pid 20162:tid 20298] [client 34.26.62.32:50714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxeIq-O_Kk7aqBvaiGNGQAAAZQ"]
[Thu Sep 17 15:39:46.314747 2026] [security2:error] [pid 18946:tid 19185] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBOQAAAXc"]
[Thu Sep 17 15:39:46.315606 2026] [security2:error] [pid 18946:tid 19125] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBPAAAATs"]
[Thu Sep 17 15:39:46.315944 2026] [security2:error] [pid 20162:tid 20309] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMcwAAAZ8"]
[Thu Sep 17 15:39:46.316459 2026] [security2:error] [pid 20162:tid 20392] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMdgAAAfI"]
[Thu Sep 17 15:39:46.316767 2026] [security2:error] [pid 20162:tid 20315] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMcQAAAaU"]
[Thu Sep 17 15:39:46.318487 2026] [security2:error] [pid 20162:tid 20306] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMeAAAAZw"]
[Thu Sep 17 15:39:46.318499 2026] [security2:error] [pid 18946:tid 19109] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBOAAAASs"]
[Thu Sep 17 15:39:46.320942 2026] [security2:error] [pid 20162:tid 20325] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMdAAAAa8"]
[Thu Sep 17 15:39:46.321109 2026] [security2:error] [pid 18946:tid 19107] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBPQAAASk"]
[Thu Sep 17 15:39:46.325798 2026] [security2:error] [pid 20162:tid 20412] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMbQAAAgY"]
[Thu Sep 17 15:39:46.327800 2026] [security2:error] [pid 20162:tid 20402] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMcAAAAfw"]
[Thu Sep 17 15:39:46.327897 2026] [security2:error] [pid 20162:tid 20350] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMcgAAAcg"]
[Thu Sep 17 15:39:46.327992 2026] [security2:error] [pid 18946:tid 19123] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBQQAAATk"]
[Thu Sep 17 15:39:46.328220 2026] [security2:error] [pid 20162:tid 20331] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMdQAAAbU"]
[Thu Sep 17 15:39:46.329602 2026] [security2:error] [pid 20162:tid 20413] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMdwAAAgc"]
[Thu Sep 17 15:39:46.333465 2026] [security2:error] [pid 18946:tid 19101] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBPwAAASM"]
[Thu Sep 17 15:39:46.336966 2026] [security2:error] [pid 18946:tid 19162] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBOwAAAWA"]
[Thu Sep 17 15:39:46.338308 2026] [security2:error] [pid 20162:tid 20385] [client 52.231.79.181:1132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/user.php"] [unique_id "aqxeIq-O_Kk7aqBvaiGNGwAAAes"]
[Thu Sep 17 15:39:46.338516 2026] [security2:error] [pid 20162:tid 20382] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMeQAAAeg"]
[Thu Sep 17 15:39:46.339640 2026] [security2:error] [pid 18946:tid 19169] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBOgAAAWc"]
[Thu Sep 17 15:39:46.497344 2026] [security2:error] [pid 18946:tid 19121] [client 34.26.62.32:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxeIjqiPMah0Tz_U1PB-wAAATc"]
[Thu Sep 17 15:39:46.730923 2026] [security2:error] [pid 20162:tid 20294] [client 34.26.62.32:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxeIq-O_Kk7aqBvaiGNIgAAAZA"]
[Thu Sep 17 15:39:46.732714 2026] [security2:error] [pid 20162:tid 20301] [client 52.231.79.181:1102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/wp-2019.php"] [unique_id "aqxeIq-O_Kk7aqBvaiGNIwAAAZc"]
[Thu Sep 17 15:39:46.736620 2026] [security2:error] [pid 18946:tid 19147] [client 189.6.16.225:37227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.16.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizzylovesdisney.com"] [uri "/xmlrpc.php"] [unique_id "aqxeIjqiPMah0Tz_U1PB_wAAAVE"]
[Thu Sep 17 15:39:46.736744 2026] [security2:error] [pid 18946:tid 19147] [client 189.6.16.225:37227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizzylovesdisney.com"] [uri "/xmlrpc.php"] [unique_id "aqxeIjqiPMah0Tz_U1PB_wAAAVE"]
[Thu Sep 17 15:39:46.972834 2026] [security2:error] [pid 20162:tid 20326] [client 14.96.156.146:61229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeIq-O_Kk7aqBvaiGNJQAAAbA"]
[Thu Sep 17 15:39:46.972928 2026] [security2:error] [pid 20162:tid 20326] [client 14.96.156.146:61229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeIq-O_Kk7aqBvaiGNJQAAAbA"]
[Thu Sep 17 15:39:47.001169 2026] [security2:error] [pid 18946:tid 19141] [client 34.26.62.32:50736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxeIzqiPMah0Tz_U1PCBAAAAUs"]
[Thu Sep 17 15:39:47.084496 2026] [security2:error] [pid 18946:tid 19108] [client 103.61.184.148:60098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeIzqiPMah0Tz_U1PCBwAAASo"]
[Thu Sep 17 15:39:47.084609 2026] [security2:error] [pid 18946:tid 19108] [client 103.61.184.148:60098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeIzqiPMah0Tz_U1PCBwAAASo"]
[Thu Sep 17 15:39:47.161164 2026] [security2:error] [pid 20162:tid 20371] [client 52.231.79.181:1095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/chosen.php"] [unique_id "aqxeI6-O_Kk7aqBvaiGNKAAAAd0"]
[Thu Sep 17 15:39:47.330434 2026] [security2:error] [pid 18946:tid 19144] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBQAAAAU4"]
[Thu Sep 17 15:39:47.332615 2026] [security2:error] [pid 20162:tid 20354] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeF6-O_Kk7aqBvaiGMbAAAAcw"]
[Thu Sep 17 15:39:47.350031 2026] [security2:error] [pid 18946:tid 19184] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeFzqiPMah0Tz_U1PBPgAAAXY"]
[Thu Sep 17 15:39:47.374194 2026] [security2:error] [pid 18946:tid 19107] [client 34.26.62.32:50752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxeIzqiPMah0Tz_U1PCCgAAASk"]
[Thu Sep 17 15:39:47.585598 2026] [security2:error] [pid 18946:tid 19100] [client 52.231.79.181:1433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/functions.php"] [unique_id "aqxeIzqiPMah0Tz_U1PCDQAAASI"]
[Thu Sep 17 15:39:47.697746 2026] [security2:error] [pid 20162:tid 20297] [client 34.26.62.32:50758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxeI6-O_Kk7aqBvaiGNLgAAAZM"]
[Thu Sep 17 15:39:47.883940 2026] [security2:error] [pid 20162:tid 20334] [client 136.158.61.34:28099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeI6-O_Kk7aqBvaiGNMAAAAbg"]
[Thu Sep 17 15:39:47.884161 2026] [security2:error] [pid 20162:tid 20334] [client 136.158.61.34:28099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeI6-O_Kk7aqBvaiGNMAAAAbg"]
[Thu Sep 17 15:39:47.973265 2026] [security2:error] [pid 20162:tid 20388] [client 34.26.62.32:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxeI6-O_Kk7aqBvaiGNMQAAAe4"]
[Thu Sep 17 15:39:47.981324 2026] [security2:error] [pid 20162:tid 20381] [client 52.231.79.181:1125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/cron.php"] [unique_id "aqxeI6-O_Kk7aqBvaiGNMgAAAec"]
[Thu Sep 17 15:39:48.172230 2026] [security2:error] [pid 20162:tid 20318] [client 34.26.62.32:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxeJK-O_Kk7aqBvaiGNNgAAAag"]
[Thu Sep 17 15:39:48.321341 2026] [security2:error] [pid 18946:tid 19088] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB3wAAARY"]
[Thu Sep 17 15:39:48.360518 2026] [security2:error] [pid 20162:tid 20302] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGNEQAAAZg"]
[Thu Sep 17 15:39:48.369059 2026] [security2:error] [pid 18946:tid 19119] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB4QAAATU"]
[Thu Sep 17 15:39:48.419006 2026] [security2:error] [pid 20162:tid 20325] [client 52.231.79.181:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/gecko-new.php"] [unique_id "aqxeJK-O_Kk7aqBvaiGNOgAAAa8"]
[Thu Sep 17 15:39:48.451713 2026] [security2:error] [pid 20162:tid 20402] [client 34.26.62.32:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxeJK-O_Kk7aqBvaiGNOwAAAfw"]
[Thu Sep 17 15:39:48.490821 2026] [cgid:error] [pid 20162:tid 20368] [client 221.149.119.65:61173] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/wp
[Thu Sep 17 15:39:48.693334 2026] [security2:error] [pid 20162:tid 20378] [client 34.26.62.32:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxeJK-O_Kk7aqBvaiGNQgAAAeQ"]
[Thu Sep 17 15:39:48.855607 2026] [security2:error] [pid 20162:tid 20335] [client 52.231.79.181:1127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/cookie.php"] [unique_id "aqxeJK-O_Kk7aqBvaiGNRwAAAbk"]
[Thu Sep 17 15:39:49.003166 2026] [security2:error] [pid 20162:tid 20347] [client 34.26.62.32:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNSQAAAcU"]
[Thu Sep 17 15:39:49.054880 2026] [security2:error] [pid 20162:tid 20420] [client 45.181.57.32:50528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeJK-O_Kk7aqBvaiGNSAACDkg"]
[Thu Sep 17 15:39:49.151521 2026] [security2:error] [pid 20162:tid 20301] [client 177.44.133.72:49329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNTQAAAZc"]
[Thu Sep 17 15:39:49.151686 2026] [security2:error] [pid 20162:tid 20301] [client 177.44.133.72:49329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNTQAAAZc"]
[Thu Sep 17 15:39:49.256560 2026] [security2:error] [pid 20162:tid 20371] [client 52.231.79.181:1416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/xleet.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNTwAAAd0"]
[Thu Sep 17 15:39:49.263273 2026] [security2:error] [pid 18946:tid 19129] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB6AAAAT8"]
[Thu Sep 17 15:39:49.279912 2026] [security2:error] [pid 20162:tid 20346] [client 34.26.62.32:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNUAAAAcQ"]
[Thu Sep 17 15:39:49.311125 2026] [security2:error] [pid 18946:tid 19140] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB7AAAAUo"]
[Thu Sep 17 15:39:49.322608 2026] [security2:error] [pid 18946:tid 19110] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB6gAAASw"]
[Thu Sep 17 15:39:49.329700 2026] [security2:error] [pid 18946:tid 19197] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB5gAAAYM"]
[Thu Sep 17 15:39:49.333109 2026] [security2:error] [pid 18946:tid 19078] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB5AAAAQw"]
[Thu Sep 17 15:39:49.348831 2026] [security2:error] [pid 18946:tid 19175] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB6QAAAW0"]
[Thu Sep 17 15:39:49.350487 2026] [security2:error] [pid 18946:tid 19151] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB4gAAAVU"]
[Thu Sep 17 15:39:49.351337 2026] [security2:error] [pid 20162:tid 20293] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGNEAAAAY8"]
[Thu Sep 17 15:39:49.362892 2026] [security2:error] [pid 20162:tid 20362] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGNEgAAAdQ"]
[Thu Sep 17 15:39:49.362932 2026] [security2:error] [pid 18946:tid 19145] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB4wAAAU8"]
[Thu Sep 17 15:39:49.388538 2026] [security2:error] [pid 18946:tid 19106] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB7QAAASg"]
[Thu Sep 17 15:39:49.401655 2026] [security2:error] [pid 18946:tid 19128] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB5QAAAT4"]
[Thu Sep 17 15:39:49.404027 2026] [security2:error] [pid 20162:tid 20393] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGNFAAAAfM"]
[Thu Sep 17 15:39:49.410230 2026] [security2:error] [pid 18946:tid 19122] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB5wAAATg"]
[Thu Sep 17 15:39:49.433887 2026] [security2:error] [pid 20162:tid 20405] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGNDwAAAf8"]
[Thu Sep 17 15:39:49.445724 2026] [security2:error] [pid 20162:tid 20361] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeIa-O_Kk7aqBvaiGNEwAAAdM"]
[Thu Sep 17 15:39:49.564401 2026] [security2:error] [pid 20162:tid 20414] [client 34.26.62.32:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNVQAAAgg"]
[Thu Sep 17 15:39:49.656041 2026] [security2:error] [pid 20162:tid 20388] [client 52.231.79.181:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/spip.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNWAAAAe4"]
[Thu Sep 17 15:39:49.906431 2026] [security2:error] [pid 20162:tid 20330] [client 34.26.62.32:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxeJa-O_Kk7aqBvaiGNWgAAAbQ"]
[Thu Sep 17 15:39:50.077558 2026] [security2:error] [pid 20162:tid 20298] [client 52.231.79.181:1100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/22.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNWwAAAZQ"]
[Thu Sep 17 15:39:50.150387 2026] [security2:error] [pid 20162:tid 20310] [client 34.26.62.32:50850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNXgAAAaA"]
[Thu Sep 17 15:39:50.258317 2026] [security2:error] [pid 18946:tid 19138] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB7wAAAUg"]
[Thu Sep 17 15:39:50.258487 2026] [security2:error] [pid 18946:tid 19163] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB6wAAAWE"]
[Thu Sep 17 15:39:50.284272 2026] [security2:error] [pid 18946:tid 19116] [client 3.82.141.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-bfd830a9.uniquespeechtechniques.com"] [uri "/index.php"] [unique_id "aqxeITqiPMah0Tz_U1PB8AAAATI"]
[Thu Sep 17 15:39:50.472770 2026] [security2:error] [pid 20162:tid 20399] [client 34.26.62.32:50852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNZAAAAfk"]
[Thu Sep 17 15:39:50.514714 2026] [security2:error] [pid 20162:tid 20323] [client 52.231.79.181:1235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/room.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNZQAAAa0"]
[Thu Sep 17 15:39:50.791963 2026] [security2:error] [pid 20162:tid 20367] [client 34.26.62.32:50860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNbgAAAdk"]
[Thu Sep 17 15:39:50.942301 2026] [security2:error] [pid 20162:tid 20394] [client 52.231.79.181:1098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/disagreed.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNbwAAAfQ"]
[Thu Sep 17 15:39:50.999979 2026] [security2:error] [pid 20162:tid 20326] [client 34.26.62.32:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNcAAAAbA"]
[Thu Sep 17 15:39:51.028401 2026] [security2:error] [pid 20162:tid 20398] [client 52.167.144.232:9619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxeJq-O_Kk7aqBvaiGNaQAB-Gs"]
[Thu Sep 17 15:39:51.263260 2026] [security2:error] [pid 20162:tid 20409] [client 34.26.62.32:50868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNdQAAAgM"]
[Thu Sep 17 15:39:51.372486 2026] [security2:error] [pid 20162:tid 20293] [client 52.231.79.181:1444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/text.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNdgAAAY8"]
[Thu Sep 17 15:39:51.476233 2026] [security2:error] [pid 20162:tid 20341] [client 34.26.62.32:50874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNeAAAAb8"]
[Thu Sep 17 15:39:51.556952 2026] [security2:error] [pid 20162:tid 20351] [client 186.189.92.120:8096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNdwAByUs"]
[Thu Sep 17 15:39:51.594230 2026] [security2:error] [pid 20162:tid 20346] [client 143.105.152.240:48799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNfwAAAcQ"]
[Thu Sep 17 15:39:51.605846 2026] [security2:error] [pid 20162:tid 20346] [client 143.105.152.240:48799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNfwAAAcQ"]
[Thu Sep 17 15:39:51.716172 2026] [security2:error] [pid 20162:tid 20393] [client 34.26.62.32:50882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNgQAAAfM"]
[Thu Sep 17 15:39:51.782234 2026] [security2:error] [pid 20162:tid 20356] [client 52.231.79.181:1241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/alfa-rex.php"] [unique_id "aqxeJ6-O_Kk7aqBvaiGNggAAAc4"]
[Thu Sep 17 15:39:52.061726 2026] [security2:error] [pid 20162:tid 20317] [client 34.26.62.32:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxeKK-O_Kk7aqBvaiGNiQAAAac"]
[Thu Sep 17 15:39:52.191951 2026] [security2:error] [pid 20162:tid 20381] [client 52.231.79.181:1267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/alfa-rex.php7"] [unique_id "aqxeKK-O_Kk7aqBvaiGNjwAAAec"]
[Thu Sep 17 15:39:52.367578 2026] [security2:error] [pid 20162:tid 20309] [client 34.26.62.32:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxeKK-O_Kk7aqBvaiGNlAAAAZ8"]
[Thu Sep 17 15:39:52.604603 2026] [security2:error] [pid 20162:tid 20419] [client 52.231.79.181:1225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/radio.php"] [unique_id "aqxeKK-O_Kk7aqBvaiGNlgAAAg0"]
[Thu Sep 17 15:39:52.635030 2026] [security2:error] [pid 20162:tid 20303] [client 34.26.62.32:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxeKK-O_Kk7aqBvaiGNmAAAAZk"]
[Thu Sep 17 15:39:52.703504 2026] [security2:error] [pid 20162:tid 20316] [client 79.116.89.151:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeKK-O_Kk7aqBvaiGNmwAAAaY"]
[Thu Sep 17 15:39:52.703639 2026] [security2:error] [pid 20162:tid 20316] [client 79.116.89.151:54140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeKK-O_Kk7aqBvaiGNmwAAAaY"]
[Thu Sep 17 15:39:52.993919 2026] [security2:error] [pid 20162:tid 20399] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeKK-O_Kk7aqBvaiGNnQAAAfk"]
[Thu Sep 17 15:39:53.002067 2026] [security2:error] [pid 20162:tid 20323] [client 52.231.79.181:1440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/dropdown.php"] [unique_id "aqxeKa-O_Kk7aqBvaiGNoAAAAa0"]
[Thu Sep 17 15:39:53.360508 2026] [security2:error] [pid 20162:tid 20364] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeKa-O_Kk7aqBvaiGNpQAAAdY"]
[Thu Sep 17 15:39:53.408742 2026] [security2:error] [pid 20162:tid 20335] [client 52.231.79.181:1411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/defaults.php"] [unique_id "aqxeKa-O_Kk7aqBvaiGNqQAAAbk"]
[Thu Sep 17 15:39:53.643098 2026] [security2:error] [pid 20162:tid 20398] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeKa-O_Kk7aqBvaiGNqgAAAfg"]
[Thu Sep 17 15:39:53.835174 2026] [security2:error] [pid 20162:tid 20327] [client 52.231.79.181:1221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/system.php"] [unique_id "aqxeKa-O_Kk7aqBvaiGNrwAAAbE"]
[Thu Sep 17 15:39:53.999062 2026] [security2:error] [pid 20162:tid 20362] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeKa-O_Kk7aqBvaiGNsQAAAdQ"]
[Thu Sep 17 15:39:54.056329 2026] [security2:error] [pid 20162:tid 20293] [client 87.199.193.246:41824] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.193.246" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNsgAAAY8"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:39:54.056440 2026] [security2:error] [pid 20162:tid 20293] [client 87.199.193.246:41824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNsgAAAY8"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:39:54.273808 2026] [security2:error] [pid 20162:tid 20416] [client 52.231.79.181:1091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/xmlrpc.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNuAAAAgo"]
[Thu Sep 17 15:39:54.301428 2026] [security2:error] [pid 20162:tid 20346] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNtQAAAcQ"]
[Thu Sep 17 15:39:54.385946 2026] [security2:error] [pid 20162:tid 20312] [client 87.199.193.246:41858] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.193.246" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNugAAAaI"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:39:54.386027 2026] [security2:error] [pid 20162:tid 20312] [client 87.199.193.246:41858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "ojorojomusic.com"] [uri "/wp-comments-post.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNugAAAaI"], referer: http://ojorojomusic.com/why-did-rock-music-get-popular/
[Thu Sep 17 15:39:54.519997 2026] [security2:error] [pid 20162:tid 20344] [client 213.165.44.48:47498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/svg+xml"] [severity "WARNING"] [hostname "wtff.net"] [uri "/"] [unique_id "aqxeKq-O_Kk7aqBvaiGNvAAAAcI"]
[Thu Sep 17 15:39:54.520111 2026] [security2:error] [pid 20162:tid 20344] [client 213.165.44.48:47498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "wtff.net"] [uri "/"] [unique_id "aqxeKq-O_Kk7aqBvaiGNvAAAAcI"]
[Thu Sep 17 15:39:54.595333 2026] [security2:error] [pid 20162:tid 20359] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNuwAAAdE"]
[Thu Sep 17 15:39:54.688791 2026] [security2:error] [pid 20162:tid 20381] [client 52.231.79.181:1137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/xmlrpc.php0"] [unique_id "aqxeKq-O_Kk7aqBvaiGNwQAAAec"]
[Thu Sep 17 15:39:54.926706 2026] [security2:error] [pid 20162:tid 20315] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeKq-O_Kk7aqBvaiGNwgAAAaU"]
[Thu Sep 17 15:39:55.100417 2026] [security2:error] [pid 20162:tid 20348] [client 52.231.79.181:1107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/colors.php"] [unique_id "aqxeK6-O_Kk7aqBvaiGNygAAAcY"]
[Thu Sep 17 15:39:55.197774 2026] [security2:error] [pid 20162:tid 20396] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeK6-O_Kk7aqBvaiGNxwAAAfY"]
[Thu Sep 17 15:39:55.523822 2026] [security2:error] [pid 20162:tid 20419] [client 52.231.79.181:1417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/updates.php"] [unique_id "aqxeK6-O_Kk7aqBvaiGN0QAAAg0"]
[Thu Sep 17 15:39:55.560416 2026] [security2:error] [pid 20162:tid 20303] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeK6-O_Kk7aqBvaiGNzgAAAZk"]
[Thu Sep 17 15:39:55.924348 2026] [security2:error] [pid 20162:tid 20306] [client 52.231.79.181:1442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/alfa-rex1.php"] [unique_id "aqxeK6-O_Kk7aqBvaiGN2AAAAZw"]
[Thu Sep 17 15:39:55.924365 2026] [security2:error] [pid 20162:tid 20374] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeK6-O_Kk7aqBvaiGN1wAAAeA"]
[Thu Sep 17 15:39:55.955012 2026] [security2:error] [pid 20162:tid 20402] [client 13.223.3.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxeK6-O_Kk7aqBvaiGNywAAAfw"]
[Thu Sep 17 15:39:56.237103 2026] [security2:error] [pid 20162:tid 20345] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeLK-O_Kk7aqBvaiGN3AAAAcM"]
[Thu Sep 17 15:39:56.342379 2026] [security2:error] [pid 20162:tid 20313] [client 52.231.79.181:1096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/wp-admin.php"] [unique_id "aqxeLK-O_Kk7aqBvaiGN4wAAAaM"]
[Thu Sep 17 15:39:56.551281 2026] [security2:error] [pid 20162:tid 20369] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeLK-O_Kk7aqBvaiGN5wAAAds"]
[Thu Sep 17 15:39:56.769870 2026] [security2:error] [pid 20162:tid 20332] [client 52.231.79.181:1117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/alfa.php"] [unique_id "aqxeLK-O_Kk7aqBvaiGN7wAAAbY"]
[Thu Sep 17 15:39:56.795865 2026] [security2:error] [pid 20162:tid 20417] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeLK-O_Kk7aqBvaiGN7gAAAgs"]
[Thu Sep 17 15:39:57.125066 2026] [security2:error] [pid 20162:tid 20293] [client 34.26.62.32:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msp.whe.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeLa-O_Kk7aqBvaiGN8AAAAY8"]
[Thu Sep 17 15:39:57.170967 2026] [security2:error] [pid 20162:tid 20380] [client 52.231.79.181:1120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/alfanew.php7"] [unique_id "aqxeLa-O_Kk7aqBvaiGN9QAAAeY"]
[Thu Sep 17 15:39:57.586305 2026] [security2:error] [pid 20162:tid 20317] [client 52.231.79.181:1222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/locale.php"] [unique_id "aqxeLa-O_Kk7aqBvaiGN_gAAAac"]
[Thu Sep 17 15:39:57.634368 2026] [security2:error] [pid 20162:tid 20339] [client 14.96.156.146:61876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeLa-O_Kk7aqBvaiGOAAAAAb0"]
[Thu Sep 17 15:39:57.634466 2026] [security2:error] [pid 20162:tid 20339] [client 14.96.156.146:61876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeLa-O_Kk7aqBvaiGOAAAAAb0"]
[Thu Sep 17 15:39:57.697227 2026] [security2:error] [pid 20162:tid 20353] [client 103.61.184.148:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeLa-O_Kk7aqBvaiGOAgAAAcs"]
[Thu Sep 17 15:39:57.697395 2026] [security2:error] [pid 20162:tid 20353] [client 103.61.184.148:61082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeLa-O_Kk7aqBvaiGOAgAAAcs"]
[Thu Sep 17 15:39:57.982548 2026] [security2:error] [pid 20162:tid 20349] [client 52.231.79.181:1148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/wxo.php"] [unique_id "aqxeLa-O_Kk7aqBvaiGOAwAAAcc"]
[Thu Sep 17 15:39:58.393116 2026] [security2:error] [pid 20162:tid 20368] [client 52.231.79.181:1454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/colour.php"] [unique_id "aqxeLq-O_Kk7aqBvaiGODAAAAdo"]
[Thu Sep 17 15:39:58.788958 2026] [security2:error] [pid 20162:tid 20378] [client 52.231.79.181:1226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/install.php"] [unique_id "aqxeLq-O_Kk7aqBvaiGOEwAAAeQ"]
[Thu Sep 17 15:39:59.190936 2026] [security2:error] [pid 20162:tid 20345] [client 52.231.79.181:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/wp-contentt.php"] [unique_id "aqxeL6-O_Kk7aqBvaiGOGgAAAcM"]
[Thu Sep 17 15:39:59.633492 2026] [security2:error] [pid 20162:tid 20398] [client 52.231.79.181:1409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/config.php7"] [unique_id "aqxeL6-O_Kk7aqBvaiGOHQAAAfg"]
[Thu Sep 17 15:39:59.846689 2026] [security2:error] [pid 20162:tid 20299] [client 177.44.133.72:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeL6-O_Kk7aqBvaiGOIQAAAZU"]
[Thu Sep 17 15:39:59.846830 2026] [security2:error] [pid 20162:tid 20299] [client 177.44.133.72:50014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeL6-O_Kk7aqBvaiGOIQAAAZU"]
[Thu Sep 17 15:40:00.042739 2026] [security2:error] [pid 20162:tid 20412] [client 52.231.79.181:1144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/config.php"] [unique_id "aqxeMK-O_Kk7aqBvaiGOIwAAAgY"]
[Thu Sep 17 15:40:00.419152 2026] [security2:error] [pid 20162:tid 20341] [client 136.158.61.34:29167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeMK-O_Kk7aqBvaiGOKgAAAb8"]
[Thu Sep 17 15:40:00.419309 2026] [security2:error] [pid 20162:tid 20341] [client 136.158.61.34:29167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeMK-O_Kk7aqBvaiGOKgAAAb8"]
[Thu Sep 17 15:40:00.442304 2026] [security2:error] [pid 20162:tid 20384] [client 52.231.79.181:1141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/theme.php"] [unique_id "aqxeMK-O_Kk7aqBvaiGOKwAAAeo"]
[Thu Sep 17 15:40:00.843512 2026] [security2:error] [pid 20162:tid 20318] [client 52.231.79.181:1414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/block-bindings.php"] [unique_id "aqxeMK-O_Kk7aqBvaiGOOAAAAag"]
[Thu Sep 17 15:40:01.270556 2026] [security2:error] [pid 20162:tid 20303] [client 52.231.79.181:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/class_api.php"] [unique_id "aqxeMa-O_Kk7aqBvaiGOPgAAAZk"]
[Thu Sep 17 15:40:01.671367 2026] [security2:error] [pid 20162:tid 20378] [client 52.231.79.181:1438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/inputs.php"] [unique_id "aqxeMa-O_Kk7aqBvaiGOSAAAAeQ"]
[Thu Sep 17 15:40:01.677185 2026] [security2:error] [pid 20162:tid 20361] [client 24.5.181.213:50281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeMa-O_Kk7aqBvaiGOQwAB01o"], referer: https://www.google.com/
[Thu Sep 17 15:40:02.071989 2026] [security2:error] [pid 20162:tid 20335] [client 52.231.79.181:1437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/root.php"] [unique_id "aqxeMq-O_Kk7aqBvaiGOTAAAAbk"]
[Thu Sep 17 15:40:02.159079 2026] [security2:error] [pid 20162:tid 20337] [client 143.105.152.240:23096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeMq-O_Kk7aqBvaiGOUQAAAbs"]
[Thu Sep 17 15:40:02.169909 2026] [security2:error] [pid 20162:tid 20337] [client 143.105.152.240:23096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeMq-O_Kk7aqBvaiGOUQAAAbs"]
[Thu Sep 17 15:40:02.469152 2026] [security2:error] [pid 20162:tid 20375] [client 52.231.79.181:1412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/menu.php"] [unique_id "aqxeMq-O_Kk7aqBvaiGOVgAAAeE"]
[Thu Sep 17 15:40:02.862405 2026] [security2:error] [pid 20162:tid 20397] [client 169.58.197.251:60259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxeMq-O_Kk7aqBvaiGOWgAAAfc"], referer: binance.com
[Thu Sep 17 15:40:02.866577 2026] [security2:error] [pid 20162:tid 20296] [client 52.231.79.181:1420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/cloud.php"] [unique_id "aqxeMq-O_Kk7aqBvaiGOWwAAAZI"]
[Thu Sep 17 15:40:03.233920 2026] [security2:error] [pid 20162:tid 20380] [client 79.116.89.151:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeM6-O_Kk7aqBvaiGOZAAAAeY"]
[Thu Sep 17 15:40:03.234141 2026] [security2:error] [pid 20162:tid 20380] [client 79.116.89.151:54764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeM6-O_Kk7aqBvaiGOZAAAAeY"]
[Thu Sep 17 15:40:03.269782 2026] [security2:error] [pid 20162:tid 20351] [client 52.231.79.181:1248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/configs.php"] [unique_id "aqxeM6-O_Kk7aqBvaiGOZQAAAck"]
[Thu Sep 17 15:40:03.504871 2026] [security2:error] [pid 20162:tid 20384] [client 24.5.181.213:42230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeM6-O_Kk7aqBvaiGOZgAB6nc"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260606033741&hideliu=1&hideminor=1&limit=250&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:40:03.671387 2026] [security2:error] [pid 20162:tid 20344] [client 52.231.79.181:1450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/wp-configs.php"] [unique_id "aqxeM6-O_Kk7aqBvaiGObAAAAcI"]
[Thu Sep 17 15:40:04.068479 2026] [security2:error] [pid 20162:tid 20363] [client 52.231.79.181:1467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/update.php"] [unique_id "aqxeNK-O_Kk7aqBvaiGOeQAAAdU"]
[Thu Sep 17 15:40:04.471540 2026] [security2:error] [pid 20162:tid 20419] [client 52.231.79.181:1216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/2.php"] [unique_id "aqxeNK-O_Kk7aqBvaiGOgAAAAg0"]
[Thu Sep 17 15:40:04.875012 2026] [security2:error] [pid 20162:tid 20308] [client 52.231.79.181:1458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/aaa.php"] [unique_id "aqxeNK-O_Kk7aqBvaiGOigAAAZ4"]
[Thu Sep 17 15:40:04.988987 2026] [security2:error] [pid 20162:tid 20361] [client 49.37.39.61:49188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.39.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxeNK-O_Kk7aqBvaiGOjAAAAdM"]
[Thu Sep 17 15:40:04.989132 2026] [security2:error] [pid 20162:tid 20361] [client 49.37.39.61:49188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lemuspools.com"] [uri "/xmlrpc.php"] [unique_id "aqxeNK-O_Kk7aqBvaiGOjAAAAdM"]
[Thu Sep 17 15:40:05.517877 2026] [security2:error] [pid 20162:tid 20294] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNa-O_Kk7aqBvaiGOlAAAAZA"]
[Thu Sep 17 15:40:05.720178 2026] [security2:error] [pid 20162:tid 20366] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/.env"] [unique_id "aqxeNa-O_Kk7aqBvaiGOmQAAAdg"]
[Thu Sep 17 15:40:05.834204 2026] [security2:error] [pid 20162:tid 20420] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNa-O_Kk7aqBvaiGOmgAAAg4"]
[Thu Sep 17 15:40:05.963606 2026] [security2:error] [pid 20162:tid 20408] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNa-O_Kk7aqBvaiGOnAAAAgI"]
[Thu Sep 17 15:40:06.072354 2026] [security2:error] [pid 20162:tid 20417] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNq-O_Kk7aqBvaiGOnQAAAgs"]
[Thu Sep 17 15:40:06.198502 2026] [security2:error] [pid 20162:tid 20320] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNq-O_Kk7aqBvaiGOoQAAAao"]
[Thu Sep 17 15:40:06.317370 2026] [security2:error] [pid 20162:tid 20314] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNq-O_Kk7aqBvaiGOpgAAAaQ"]
[Thu Sep 17 15:40:06.449387 2026] [security2:error] [pid 20162:tid 20410] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNq-O_Kk7aqBvaiGOqAAAAgQ"]
[Thu Sep 17 15:40:06.504519 2026] [security2:error] [pid 20162:tid 20400] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/.env.bak"] [unique_id "aqxeNq-O_Kk7aqBvaiGOqQAAAfo"]
[Thu Sep 17 15:40:06.560993 2026] [security2:error] [pid 20162:tid 20364] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/.env.backup"] [unique_id "aqxeNq-O_Kk7aqBvaiGOrAAAAdY"]
[Thu Sep 17 15:40:06.672065 2026] [security2:error] [pid 20162:tid 20329] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNq-O_Kk7aqBvaiGOtAAAAbM"]
[Thu Sep 17 15:40:06.735738 2026] [security2:error] [pid 20162:tid 20346] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/.env.old"] [unique_id "aqxeNq-O_Kk7aqBvaiGOtwAAAcQ"]
[Thu Sep 17 15:40:06.851816 2026] [security2:error] [pid 20162:tid 20370] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNq-O_Kk7aqBvaiGOuQAAAdw"]
[Thu Sep 17 15:40:06.959731 2026] [security2:error] [pid 20162:tid 20389] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeNq-O_Kk7aqBvaiGOugAAAe8"]
[Thu Sep 17 15:40:07.105417 2026] [security2:error] [pid 20162:tid 20388] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGOvAAAAe4"]
[Thu Sep 17 15:40:07.221009 2026] [security2:error] [pid 20162:tid 20309] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGOwAAAAZ8"]
[Thu Sep 17 15:40:07.284590 2026] [security2:error] [pid 20162:tid 20393] [client 57.141.14.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGOwwAAAfM"]
[Thu Sep 17 15:40:07.340001 2026] [security2:error] [pid 20162:tid 20310] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGOxQAAAaA"]
[Thu Sep 17 15:40:07.452875 2026] [security2:error] [pid 20162:tid 20419] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGOzQAAAg0"]
[Thu Sep 17 15:40:07.566612 2026] [security2:error] [pid 20162:tid 20316] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGO3AAAAaY"]
[Thu Sep 17 15:40:07.690441 2026] [security2:error] [pid 20162:tid 20308] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGO4AAAAZ4"]
[Thu Sep 17 15:40:07.811163 2026] [security2:error] [pid 20162:tid 20331] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGO4QAAAbU"]
[Thu Sep 17 15:40:07.941163 2026] [security2:error] [pid 20162:tid 20361] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeN6-O_Kk7aqBvaiGO4gAAAdM"]
[Thu Sep 17 15:40:08.066947 2026] [security2:error] [pid 20162:tid 20335] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO4wAAAbk"]
[Thu Sep 17 15:40:08.143870 2026] [security2:error] [pid 20162:tid 20305] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/.env.swp"] [unique_id "aqxeOK-O_Kk7aqBvaiGO8wAAAZs"]
[Thu Sep 17 15:40:08.207034 2026] [security2:error] [pid 20162:tid 20301] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/.env~"] [unique_id "aqxeOK-O_Kk7aqBvaiGO9wAAAZc"]
[Thu Sep 17 15:40:08.220537 2026] [security2:error] [pid 20162:tid 20345] [client 14.96.156.146:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO-AAAAcM"]
[Thu Sep 17 15:40:08.220666 2026] [security2:error] [pid 20162:tid 20345] [client 14.96.156.146:62525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO-AAAAcM"]
[Thu Sep 17 15:40:08.328939 2026] [security2:error] [pid 20162:tid 20313] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO-QAAAaM"]
[Thu Sep 17 15:40:08.469783 2026] [security2:error] [pid 20162:tid 20360] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO-gAAAdI"]
[Thu Sep 17 15:40:08.500915 2026] [security2:error] [pid 20162:tid 20300] [client 103.61.184.148:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO_QAAAZY"]
[Thu Sep 17 15:40:08.501172 2026] [security2:error] [pid 20162:tid 20300] [client 103.61.184.148:57920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO_QAAAZY"]
[Thu Sep 17 15:40:08.525368 2026] [security2:error] [pid 20162:tid 20323] [client 88.248.118.121:1555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO-wABrT0"]
[Thu Sep 17 15:40:08.598715 2026] [security2:error] [pid 20162:tid 20385] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGO_gAAAes"]
[Thu Sep 17 15:40:08.722393 2026] [security2:error] [pid 20162:tid 20320] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGPBgAAAao"]
[Thu Sep 17 15:40:08.839280 2026] [security2:error] [pid 20162:tid 20314] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGPBwAAAaQ"]
[Thu Sep 17 15:40:08.990289 2026] [security2:error] [pid 20162:tid 20343] [client 162.241.226.11:17194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGPCgAAAcE"]
[Thu Sep 17 15:40:08.995246 2026] [security2:error] [pid 20162:tid 20365] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOK-O_Kk7aqBvaiGPCwAAAdc"]
[Thu Sep 17 15:40:09.108094 2026] [security2:error] [pid 20162:tid 20341] [client 88.248.118.121:1555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeOa-O_Kk7aqBvaiGPDAABv0U"]
[Thu Sep 17 15:40:09.125753 2026] [security2:error] [pid 20162:tid 20311] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOa-O_Kk7aqBvaiGPDwAAAaE"]
[Thu Sep 17 15:40:09.174657 2026] [security2:error] [pid 20162:tid 20329] [client 162.241.226.11:17200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxeOa-O_Kk7aqBvaiGPDQAAAbM"]
[Thu Sep 17 15:40:09.214451 2026] [security2:error] [pid 20162:tid 20383] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/app/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPEwAAAek"]
[Thu Sep 17 15:40:09.272425 2026] [security2:error] [pid 20162:tid 20344] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/apps/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPFAAAAcI"]
[Thu Sep 17 15:40:09.330197 2026] [security2:error] [pid 20162:tid 20340] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/api/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPFQAAAb4"]
[Thu Sep 17 15:40:09.394070 2026] [security2:error] [pid 20162:tid 20339] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/web/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPFgAAAb0"]
[Thu Sep 17 15:40:09.451466 2026] [security2:error] [pid 20162:tid 20330] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/site/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPFwAAAbQ"]
[Thu Sep 17 15:40:09.508185 2026] [security2:error] [pid 20162:tid 20325] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/public/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPGAAAAa8"]
[Thu Sep 17 15:40:09.626404 2026] [security2:error] [pid 20162:tid 20319] [client 34.23.198.186:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeOa-O_Kk7aqBvaiGPGQAAAak"]
[Thu Sep 17 15:40:09.697198 2026] [security2:error] [pid 20162:tid 20363] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/backend/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPIQAAAdU"]
[Thu Sep 17 15:40:09.751636 2026] [security2:error] [pid 20162:tid 20293] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/server/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPJAAAAY8"]
[Thu Sep 17 15:40:09.806976 2026] [security2:error] [pid 20162:tid 20396] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/frontend/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPJQAAAfY"]
[Thu Sep 17 15:40:09.861033 2026] [security2:error] [pid 20162:tid 20359] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/src/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPJgAAAdE"]
[Thu Sep 17 15:40:09.917546 2026] [security2:error] [pid 20162:tid 20371] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/core/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPJwAAAd0"]
[Thu Sep 17 15:40:09.973349 2026] [security2:error] [pid 20162:tid 20418] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/core/app/.env"] [unique_id "aqxeOa-O_Kk7aqBvaiGPKAAAAgw"]
[Thu Sep 17 15:40:10.032637 2026] [security2:error] [pid 20162:tid 20405] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/config/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPKQAAAf8"]
[Thu Sep 17 15:40:10.089491 2026] [security2:error] [pid 20162:tid 20303] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/private/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPKgAAAZk"]
[Thu Sep 17 15:40:10.149852 2026] [security2:error] [pid 20162:tid 20419] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/application/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPLwAAAg0"]
[Thu Sep 17 15:40:10.213700 2026] [security2:error] [pid 20162:tid 20338] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/bootstrap/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPMQAAAbw"]
[Thu Sep 17 15:40:10.279041 2026] [security2:error] [pid 20162:tid 20392] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/database/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPMwAAAfI"]
[Thu Sep 17 15:40:10.342983 2026] [security2:error] [pid 20162:tid 20413] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/storage/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPNAAAAgc"]
[Thu Sep 17 15:40:10.407523 2026] [security2:error] [pid 20162:tid 20381] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/var/www/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPNQAAAec"]
[Thu Sep 17 15:40:10.465276 2026] [security2:error] [pid 20162:tid 20358] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/var/www/html/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPNwAAAdA"]
[Thu Sep 17 15:40:10.535948 2026] [security2:error] [pid 20162:tid 20335] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/current/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPOAAAAbk"]
[Thu Sep 17 15:40:10.563381 2026] [security2:error] [pid 20162:tid 20357] [client 177.44.133.72:50679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeOq-O_Kk7aqBvaiGPOQAAAc8"]
[Thu Sep 17 15:40:10.563865 2026] [security2:error] [pid 20162:tid 20357] [client 177.44.133.72:50679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeOq-O_Kk7aqBvaiGPOQAAAc8"]
[Thu Sep 17 15:40:10.604040 2026] [security2:error] [pid 20162:tid 20298] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/release/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPOgAAAZQ"]
[Thu Sep 17 15:40:10.668545 2026] [security2:error] [pid 20162:tid 20305] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/releases/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPPQAAAZs"]
[Thu Sep 17 15:40:10.730224 2026] [security2:error] [pid 20162:tid 20352] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/shared/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPPwAAAco"]
[Thu Sep 17 15:40:10.809266 2026] [security2:error] [pid 20162:tid 20345] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/deploy/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPQQAAAcM"]
[Thu Sep 17 15:40:10.877108 2026] [security2:error] [pid 20162:tid 20313] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/build/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPQgAAAaM"]
[Thu Sep 17 15:40:10.950021 2026] [security2:error] [pid 20162:tid 20394] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/dist/.env"] [unique_id "aqxeOq-O_Kk7aqBvaiGPQwAAAfQ"]
[Thu Sep 17 15:40:11.013400 2026] [security2:error] [pid 20162:tid 20294] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/public_html/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPRgAAAZA"]
[Thu Sep 17 15:40:11.078717 2026] [security2:error] [pid 20162:tid 20306] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/htdocs/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPRwAAAZw"]
[Thu Sep 17 15:40:11.138524 2026] [security2:error] [pid 20162:tid 20366] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/www/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPSgAAAdg"]
[Thu Sep 17 15:40:11.198929 2026] [security2:error] [pid 20162:tid 20323] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/html/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPTQAAAa0"]
[Thu Sep 17 15:40:11.260179 2026] [security2:error] [pid 20162:tid 20374] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/live/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPTgAAAeA"]
[Thu Sep 17 15:40:11.274483 2026] [security2:error] [pid 20162:tid 20300] [client 169.58.197.253:59978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ppfc.net"] [uri "/index.php"] [unique_id "aqxeO6-O_Kk7aqBvaiGPTAAAAZY"], referer: binance.com
[Thu Sep 17 15:40:11.321024 2026] [security2:error] [pid 20162:tid 20385] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/prod/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPTwAAAes"]
[Thu Sep 17 15:40:11.381764 2026] [security2:error] [pid 20162:tid 20384] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/dev/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPUAAAAeo"]
[Thu Sep 17 15:40:11.442050 2026] [security2:error] [pid 20162:tid 20397] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/staging/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPUQAAAfc"]
[Thu Sep 17 15:40:11.507279 2026] [security2:error] [pid 20162:tid 20299] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/opt/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPUgAAAZU"]
[Thu Sep 17 15:40:11.574449 2026] [security2:error] [pid 20162:tid 20401] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/laravel/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPVQAAAfs"]
[Thu Sep 17 15:40:11.633289 2026] [security2:error] [pid 20162:tid 20375] [client 34.23.198.186:53324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/symfony/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPWQAAAeE"]
[Thu Sep 17 15:40:11.803273 2026] [security2:error] [pid 20162:tid 20365] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/wordpress/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPXwAAAdc"]
[Thu Sep 17 15:40:11.859674 2026] [security2:error] [pid 20162:tid 20346] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/wp/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPYQAAAcQ"]
[Thu Sep 17 15:40:11.923033 2026] [security2:error] [pid 20162:tid 20370] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/cms/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPYgAAAdw"]
[Thu Sep 17 15:40:11.979158 2026] [security2:error] [pid 20162:tid 20341] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/drupal/.env"] [unique_id "aqxeO6-O_Kk7aqBvaiGPYwAAAb8"]
[Thu Sep 17 15:40:12.042780 2026] [security2:error] [pid 20162:tid 20311] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/joomla/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPZAAAAaE"]
[Thu Sep 17 15:40:12.101510 2026] [security2:error] [pid 20162:tid 20404] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/magento/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPZwAAAf4"]
[Thu Sep 17 15:40:12.162844 2026] [security2:error] [pid 20162:tid 20317] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/shopify/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPagAAAac"]
[Thu Sep 17 15:40:12.219014 2026] [security2:error] [pid 20162:tid 20325] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/prestashop/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPawAAAa8"]
[Thu Sep 17 15:40:12.283290 2026] [security2:error] [pid 20162:tid 20388] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/codeigniter/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPbAAAAe4"]
[Thu Sep 17 15:40:12.338155 2026] [security2:error] [pid 20162:tid 20389] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/cakephp/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPcAAAAe8"]
[Thu Sep 17 15:40:12.376427 2026] [security2:error] [pid 20162:tid 20250] [remote 45.94.31.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.marinacontroller.com"] [uri "/wp-login.php"] [unique_id "aqxePK-O_Kk7aqBvaiGPbgABzlY"], referer: https://www.facebook.com/
[Thu Sep 17 15:40:12.394063 2026] [security2:error] [pid 20162:tid 20395] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/zend/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPcQAAAfU"]
[Thu Sep 17 15:40:12.455494 2026] [security2:error] [pid 20162:tid 20319] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/yii/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPcgAAAak"]
[Thu Sep 17 15:40:12.510614 2026] [security2:error] [pid 20162:tid 20342] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/laravel5/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPdAAAAcA"]
[Thu Sep 17 15:40:12.569029 2026] [security2:error] [pid 20162:tid 20414] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/v1/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPdQAAAgg"]
[Thu Sep 17 15:40:12.620757 2026] [security2:error] [pid 20162:tid 20409] [client 136.158.61.34:30270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxePK-O_Kk7aqBvaiGPeAAAAgM"]
[Thu Sep 17 15:40:12.621866 2026] [security2:error] [pid 20162:tid 20409] [client 136.158.61.34:30270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxePK-O_Kk7aqBvaiGPeAAAAgM"]
[Thu Sep 17 15:40:12.623042 2026] [security2:error] [pid 20162:tid 20415] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/v2/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPeQAAAgk"]
[Thu Sep 17 15:40:12.677423 2026] [security2:error] [pid 20162:tid 20359] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/v3/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPewAAAdE"]
[Thu Sep 17 15:40:12.731632 2026] [security2:error] [pid 20162:tid 20318] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/api/v1/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPfAAAAag"]
[Thu Sep 17 15:40:12.788599 2026] [security2:error] [pid 20162:tid 20402] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/api/v2/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPfgAAAfw"]
[Thu Sep 17 15:40:12.843479 2026] [security2:error] [pid 20162:tid 20419] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/rest/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPgQAAAg0"]
[Thu Sep 17 15:40:12.848360 2026] [security2:error] [pid 20162:tid 20386] [client 143.105.152.240:46819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxePK-O_Kk7aqBvaiGPgAAAAew"]
[Thu Sep 17 15:40:12.851932 2026] [security2:error] [pid 20162:tid 20386] [client 143.105.152.240:46819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxePK-O_Kk7aqBvaiGPgAAAAew"]
[Thu Sep 17 15:40:12.900085 2026] [security2:error] [pid 20162:tid 20338] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/graphql/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPggAAAbw"]
[Thu Sep 17 15:40:12.920018 2026] [security2:error] [pid 20162:tid 20316] [client 45.94.31.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.marinacontroller.com"] [uri "/wp-login.php"] [unique_id "aqxePK-O_Kk7aqBvaiGPgwAAAaY"], referer: https://www.bing.com/
[Thu Sep 17 15:40:12.959400 2026] [security2:error] [pid 20162:tid 20392] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/gateway/.env"] [unique_id "aqxePK-O_Kk7aqBvaiGPhAAAAfI"]
[Thu Sep 17 15:40:13.022362 2026] [security2:error] [pid 20162:tid 20308] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/microservice/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPhQAAAZ4"]
[Thu Sep 17 15:40:13.083062 2026] [security2:error] [pid 20162:tid 20413] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/service/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPhgAAAgc"]
[Thu Sep 17 15:40:13.140115 2026] [security2:error] [pid 20162:tid 20333] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/api/v3/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPigAAAbc"]
[Thu Sep 17 15:40:13.195011 2026] [security2:error] [pid 20162:tid 20357] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/api/dev/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPjAAAAc8"]
[Thu Sep 17 15:40:13.251540 2026] [security2:error] [pid 20162:tid 20298] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/api/staging/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPjQAAAZQ"]
[Thu Sep 17 15:40:13.309958 2026] [security2:error] [pid 20162:tid 20361] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/vendor/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPjgAAAdM"]
[Thu Sep 17 15:40:13.370379 2026] [security2:error] [pid 20162:tid 20345] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/lib/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPjwAAAcM"]
[Thu Sep 17 15:40:13.429961 2026] [security2:error] [pid 20162:tid 20378] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/resources/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPkAAAAeQ"]
[Thu Sep 17 15:40:13.501684 2026] [security2:error] [pid 20162:tid 20399] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/assets/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPkwAAAfk"]
[Thu Sep 17 15:40:13.559432 2026] [security2:error] [pid 20162:tid 20355] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/uploads/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPlAAAAc0"]
[Thu Sep 17 15:40:13.613628 2026] [security2:error] [pid 20162:tid 20302] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/internal/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPlgAAAZg"]
[Thu Sep 17 15:40:13.667550 2026] [security2:error] [pid 20162:tid 20366] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/tools/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPmgAAAdg"]
[Thu Sep 17 15:40:13.723993 2026] [security2:error] [pid 20162:tid 20374] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/scripts/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPmwAAAeA"]
[Thu Sep 17 15:40:13.779100 2026] [security2:error] [pid 20162:tid 20300] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/bin/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPngAAAZY"]
[Thu Sep 17 15:40:13.788670 2026] [security2:error] [pid 20162:tid 20326] [client 79.116.89.151:55392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxePa-O_Kk7aqBvaiGPnQAAAbA"]
[Thu Sep 17 15:40:13.788787 2026] [security2:error] [pid 20162:tid 20326] [client 79.116.89.151:55392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxePa-O_Kk7aqBvaiGPnQAAAbA"]
[Thu Sep 17 15:40:13.833255 2026] [security2:error] [pid 20162:tid 20324] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/sbin/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPnwAAAa4"]
[Thu Sep 17 15:40:13.887214 2026] [security2:error] [pid 20162:tid 20417] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/local/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPoAAAAgs"]
[Thu Sep 17 15:40:13.944484 2026] [security2:error] [pid 20162:tid 20397] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/portal/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPogAAAfc"]
[Thu Sep 17 15:40:13.998771 2026] [security2:error] [pid 20162:tid 20377] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/dashboard/.env"] [unique_id "aqxePa-O_Kk7aqBvaiGPpQAAAeM"]
[Thu Sep 17 15:40:14.053055 2026] [security2:error] [pid 20162:tid 20401] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/panel/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPpgAAAfs"]
[Thu Sep 17 15:40:14.107335 2026] [security2:error] [pid 20162:tid 20347] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/crm/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPqAAAAcU"]
[Thu Sep 17 15:40:14.163253 2026] [security2:error] [pid 20162:tid 20400] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/erp/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPrAAAAfo"]
[Thu Sep 17 15:40:14.218976 2026] [security2:error] [pid 20162:tid 20410] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/shop/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPrgAAAgQ"]
[Thu Sep 17 15:40:14.274182 2026] [security2:error] [pid 20162:tid 20341] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/store/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPswAAAb8"]
[Thu Sep 17 15:40:14.293805 2026] [autoindex:error] [pid 20162:tid 20311] [client 20.244.34.24:0] AH01276: Cannot serve directory /home4/buildai5/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:40:14.328540 2026] [security2:error] [pid 20162:tid 20340] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/saas/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPtwAAAb4"]
[Thu Sep 17 15:40:14.385001 2026] [security2:error] [pid 20162:tid 20404] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/client/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPuAAAAf4"]
[Thu Sep 17 15:40:14.440829 2026] [security2:error] [pid 20162:tid 20317] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/project/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPuQAAAac"]
[Thu Sep 17 15:40:14.502865 2026] [security2:error] [pid 20162:tid 20416] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/admin-panel/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPugAAAgo"]
[Thu Sep 17 15:40:14.557785 2026] [security2:error] [pid 20162:tid 20403] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/control-panel/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPuwAAAf0"]
[Thu Sep 17 15:40:14.614961 2026] [security2:error] [pid 20162:tid 20350] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/user-panel/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPvwAAAcg"]
[Thu Sep 17 15:40:14.626715 2026] [security2:error] [pid 20162:tid 20325] [client 74.7.241.135:36504] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mtbclubdecampo.com"] [uri "/robots.txt"] [unique_id "aqxePq-O_Kk7aqBvaiGPwQABr3o"]
[Thu Sep 17 15:40:14.675786 2026] [security2:error] [pid 20162:tid 20356] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/node/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPxAAAAc4"]
[Thu Sep 17 15:40:14.746366 2026] [security2:error] [pid 20162:tid 20307] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/express/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPyAAAAZ0"]
[Thu Sep 17 15:40:14.803787 2026] [security2:error] [pid 20162:tid 20363] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/next/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPyQAAAdU"]
[Thu Sep 17 15:40:14.858783 2026] [security2:error] [pid 20162:tid 20402] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/nuxt/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPywAAAfw"]
[Thu Sep 17 15:40:14.917739 2026] [security2:error] [pid 20162:tid 20315] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/nest/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPzQAAAaU"]
[Thu Sep 17 15:40:14.934478 2026] [security2:error] [pid 20162:tid 20295] [client 109.105.210.87:52462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeOq-O_Kk7aqBvaiGPNgAAAZE"]
[Thu Sep 17 15:40:14.973131 2026] [security2:error] [pid 20162:tid 20386] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/react/.env"] [unique_id "aqxePq-O_Kk7aqBvaiGPzwAAAew"]
[Thu Sep 17 15:40:15.031552 2026] [security2:error] [pid 20162:tid 20338] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/vue/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP0AAAAbw"]
[Thu Sep 17 15:40:15.085561 2026] [security2:error] [pid 20162:tid 20392] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/angular/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP0QAAAfI"]
[Thu Sep 17 15:40:15.143326 2026] [security2:error] [pid 20162:tid 20413] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/svelte/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP1QAAAgc"]
[Thu Sep 17 15:40:15.199396 2026] [security2:error] [pid 20162:tid 20304] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/vite/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP1wAAAZo"]
[Thu Sep 17 15:40:15.272620 2026] [security2:error] [pid 20162:tid 20333] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/backup/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP2AAAAbc"]
[Thu Sep 17 15:40:15.333287 2026] [security2:error] [pid 20162:tid 20358] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/backups/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP2QAAAdA"]
[Thu Sep 17 15:40:15.393193 2026] [security2:error] [pid 20162:tid 20335] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/old/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP3AAAAbk"]
[Thu Sep 17 15:40:15.453147 2026] [security2:error] [pid 20162:tid 20373] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/tmp/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP3gAAAd8"]
[Thu Sep 17 15:40:15.510834 2026] [security2:error] [pid 20162:tid 20322] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/temp/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP4AAAAaw"]
[Thu Sep 17 15:40:15.568790 2026] [security2:error] [pid 20162:tid 20378] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/lab/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP4QAAAeQ"]
[Thu Sep 17 15:40:15.636465 2026] [security2:error] [pid 20162:tid 20302] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/cronlab/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP5AAAAZg"]
[Thu Sep 17 15:40:15.701380 2026] [security2:error] [pid 20162:tid 20300] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/cron/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP5wAAAZY"]
[Thu Sep 17 15:40:15.759670 2026] [security2:error] [pid 20162:tid 20326] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/en/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP6AAAAbA"]
[Thu Sep 17 15:40:15.877532 2026] [security2:error] [pid 20162:tid 20360] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/administrator/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP6QAAAdI"]
[Thu Sep 17 15:40:15.941597 2026] [security2:error] [pid 20162:tid 20385] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/psnlink/.env"] [unique_id "aqxeP6-O_Kk7aqBvaiGP6wAAAes"]
[Thu Sep 17 15:40:16.004967 2026] [security2:error] [pid 20162:tid 20384] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/exapi/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGP7QAAAeo"]
[Thu Sep 17 15:40:16.065734 2026] [security2:error] [pid 20162:tid 20299] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/sitemaps/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGP7wAAAZU"]
[Thu Sep 17 15:40:16.159067 2026] [security2:error] [pid 20162:tid 20341] [client 169.58.197.251:61097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/abilities.php"] [unique_id "aqxeQK-O_Kk7aqBvaiGP9wAAAb8"], referer: binance.com
[Thu Sep 17 15:40:16.204685 2026] [security2:error] [pid 20162:tid 20391] [client 34.23.198.186:35418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeQK-O_Kk7aqBvaiGP9AAAAfE"]
[Thu Sep 17 15:40:16.339296 2026] [security2:error] [pid 20162:tid 20288] [remote 66.116.251.167:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happybirthdaybestmum.geekngamer.com"] [uri "/xmlrpc.php"] [unique_id "aqxeQK-O_Kk7aqBvaiGP_QAB9Hw"]
[Thu Sep 17 15:40:16.340869 2026] [security2:error] [pid 20162:tid 20290] [remote 66.116.251.167:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.happybirthdaybestmum.geekngamer.com"] [uri "/wp-login.php"] [unique_id "aqxeQK-O_Kk7aqBvaiGP-gAB434"]
[Thu Sep 17 15:40:16.343096 2026] [security2:error] [pid 20162:tid 20264] [remote 66.116.251.167:51560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.happybirthdaybestmum.geekngamer.com"] [uri "/xmlrpc.php"] [unique_id "aqxeQK-O_Kk7aqBvaiGP_gAB22Q"]
[Thu Sep 17 15:40:16.347322 2026] [security2:error] [pid 20162:tid 20166] [remote 66.116.251.167:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happybirthdaybestmum.geekngamer.com"] [uri "/wp-login.php"] [unique_id "aqxeQK-O_Kk7aqBvaiGP_AAB6AI"]
[Thu Sep 17 15:40:16.377811 2026] [security2:error] [pid 20162:tid 20353] [client 34.23.198.186:35418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeQK-O_Kk7aqBvaiGP-wAAAcs"]
[Thu Sep 17 15:40:16.441601 2026] [security2:error] [pid 20162:tid 20336] [client 34.23.198.186:35418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/logs/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGQAAAAAbo"]
[Thu Sep 17 15:40:16.639645 2026] [security2:error] [pid 20162:tid 20339] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/cache/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGQCAAAAb0"]
[Thu Sep 17 15:40:16.703984 2026] [security2:error] [pid 20162:tid 20307] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mailer/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGQCgAAAZ0"]
[Thu Sep 17 15:40:16.766303 2026] [security2:error] [pid 20162:tid 20415] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mail/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGQDQAAAgk"]
[Thu Sep 17 15:40:16.827535 2026] [security2:error] [pid 20162:tid 20388] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/email/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGQDgAAAe4"]
[Thu Sep 17 15:40:16.889777 2026] [security2:error] [pid 20162:tid 20318] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/smtp/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGQDwAAAag"]
[Thu Sep 17 15:40:16.948630 2026] [security2:error] [pid 20162:tid 20395] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mailing/.env"] [unique_id "aqxeQK-O_Kk7aqBvaiGQEAAAAfU"]
[Thu Sep 17 15:40:17.005030 2026] [security2:error] [pid 20162:tid 20349] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/notifications/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQEQAAAcc"]
[Thu Sep 17 15:40:17.069512 2026] [security2:error] [pid 20162:tid 20368] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/notify/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQEwAAAdo"]
[Thu Sep 17 15:40:17.126772 2026] [security2:error] [pid 20162:tid 20405] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/sender/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQGQAAAf8"]
[Thu Sep 17 15:40:17.189904 2026] [security2:error] [pid 20162:tid 20386] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/campaign/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQIgAAAew"]
[Thu Sep 17 15:40:17.245216 2026] [security2:error] [pid 20162:tid 20331] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/newsletter/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQIwAAAbU"]
[Thu Sep 17 15:40:17.302005 2026] [security2:error] [pid 20162:tid 20387] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/ses/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQJQAAAe0"]
[Thu Sep 17 15:40:17.362524 2026] [security2:error] [pid 20162:tid 20335] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/sendgrid/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQJwAAAbk"]
[Thu Sep 17 15:40:17.421958 2026] [security2:error] [pid 20162:tid 20322] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/sparkpost/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQKAAAAaw"]
[Thu Sep 17 15:40:17.481009 2026] [security2:error] [pid 20162:tid 20378] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/postmark/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQKgAAAeQ"]
[Thu Sep 17 15:40:17.542949 2026] [security2:error] [pid 20162:tid 20352] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mailgun/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQKwAAAco"]
[Thu Sep 17 15:40:17.604912 2026] [security2:error] [pid 20162:tid 20298] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mandrill/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQLgAAAZQ"]
[Thu Sep 17 15:40:17.673935 2026] [security2:error] [pid 20162:tid 20374] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mailjet/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQMAAAAeA"]
[Thu Sep 17 15:40:17.737012 2026] [security2:error] [pid 20162:tid 20354] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/brevo/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQMgAAAcw"]
[Thu Sep 17 15:40:17.754323 2026] [security2:error] [pid 20162:tid 20312] [client 192.185.81.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thecurveonwestwood.com"] [uri "/index.php"] [unique_id "aqxeQa-O_Kk7aqBvaiGQIQABohE"]
[Thu Sep 17 15:40:17.754432 2026] [security2:error] [pid 20162:tid 20312] [client 192.185.81.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thecurveonwestwood.com"] [uri "/index.php"] [unique_id "aqxeQa-O_Kk7aqBvaiGQHgABohA"]
[Thu Sep 17 15:40:17.796350 2026] [security2:error] [pid 20162:tid 20420] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/transactional/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQNAAAAg4"]
[Thu Sep 17 15:40:17.855109 2026] [security2:error] [pid 20162:tid 20294] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/bulk/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQNgAAAZA"]
[Thu Sep 17 15:40:17.912471 2026] [security2:error] [pid 20162:tid 20360] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/aws/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQOAAAAdI"]
[Thu Sep 17 15:40:17.985235 2026] [security2:error] [pid 20162:tid 20417] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/azure/.env"] [unique_id "aqxeQa-O_Kk7aqBvaiGQOwAAAgs"]
[Thu Sep 17 15:40:18.050674 2026] [security2:error] [pid 20162:tid 20397] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/gcp/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQPAAAAfc"]
[Thu Sep 17 15:40:18.115689 2026] [security2:error] [pid 20162:tid 20391] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/cloud/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQQwAAAfE"]
[Thu Sep 17 15:40:18.139316 2026] [security2:error] [pid 20162:tid 20398] [client 192.185.81.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thecurveonwestwood.com"] [uri "/index.php"] [unique_id "aqxeQa-O_Kk7aqBvaiGQNwAB-As"]
[Thu Sep 17 15:40:18.176257 2026] [security2:error] [pid 20162:tid 20311] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/infrastructure/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQRgAAAaE"]
[Thu Sep 17 15:40:18.237940 2026] [security2:error] [pid 20162:tid 20347] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/docker/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQRwAAAcU"]
[Thu Sep 17 15:40:18.297459 2026] [security2:error] [pid 20162:tid 20377] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/k8s/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQSQAAAeM"]
[Thu Sep 17 15:40:18.354998 2026] [security2:error] [pid 20162:tid 20173] [remote 192.185.81.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thecurveonwestwood.com"] [uri "/index.php"] [unique_id "aqxeQq-O_Kk7aqBvaiGQSAAB5Qk"], referer: https://www.thecurveonwestwood.com/
[Thu Sep 17 15:40:18.359947 2026] [security2:error] [pid 20162:tid 20369] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/kubernetes/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQSgAAAds"]
[Thu Sep 17 15:40:18.421086 2026] [security2:error] [pid 20162:tid 20353] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/terraform/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQSwAAAcs"]
[Thu Sep 17 15:40:18.478958 2026] [security2:error] [pid 20162:tid 20411] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/ansible/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQTQAAAgU"]
[Thu Sep 17 15:40:18.528366 2026] [security2:error] [pid 20162:tid 20380] [client 192.185.81.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thecurveonwestwood.com"] [uri "/index.php"] [unique_id "aqxeQq-O_Kk7aqBvaiGQTAAB5iM"]
[Thu Sep 17 15:40:18.543631 2026] [security2:error] [pid 20162:tid 20296] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/.git/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQTgAAAZI"]
[Thu Sep 17 15:40:18.600389 2026] [security2:error] [pid 20162:tid 20370] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/ci/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQUwAAAdw"]
[Thu Sep 17 15:40:18.663896 2026] [security2:error] [pid 20162:tid 20346] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/cd/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQVAAAAcQ"]
[Thu Sep 17 15:40:18.736688 2026] [security2:error] [pid 20162:tid 20406] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/jenkins/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQWQAAAgA"]
[Thu Sep 17 15:40:18.750334 2026] [core:error] [pid 20162:tid 20415] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:18.750352 2026] [core:error] [pid 20162:tid 20415] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:18.795950 2026] [security2:error] [pid 20162:tid 20328] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/gitlab/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQWwAAAbI"]
[Thu Sep 17 15:40:18.825543 2026] [security2:error] [pid 20162:tid 20321] [client 34.94.56.93:35494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.premium-cuts.com"] [uri "/"] [unique_id "aqxeQq-O_Kk7aqBvaiGQXAAAAas"]
[Thu Sep 17 15:40:18.852627 2026] [security2:error] [pid 20162:tid 20395] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/github/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQXQAAAfU"]
[Thu Sep 17 15:40:18.877279 2026] [security2:error] [pid 20162:tid 20356] [client 14.96.156.146:63171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeQq-O_Kk7aqBvaiGQYAAAAc4"]
[Thu Sep 17 15:40:18.877405 2026] [security2:error] [pid 20162:tid 20356] [client 14.96.156.146:63171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeQq-O_Kk7aqBvaiGQYAAAAc4"]
[Thu Sep 17 15:40:18.909019 2026] [security2:error] [pid 20162:tid 20402] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/actions/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQYgAAAfw"]
[Thu Sep 17 15:40:18.919342 2026] [security2:error] [pid 20162:tid 20368] [client 34.94.56.93:35502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.premium-cuts.com"] [uri "/"] [unique_id "aqxeQq-O_Kk7aqBvaiGQYwAAAdo"]
[Thu Sep 17 15:40:18.964548 2026] [security2:error] [pid 20162:tid 20340] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/circleci/.env"] [unique_id "aqxeQq-O_Kk7aqBvaiGQZAAAAb4"]
[Thu Sep 17 15:40:18.974962 2026] [security2:error] [pid 20162:tid 20393] [client 169.58.197.253:60409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxeQq-O_Kk7aqBvaiGQZQAAAfM"], referer: binance.com
[Thu Sep 17 15:40:19.000046 2026] [security2:error] [pid 20162:tid 20293] [client 62.201.248.20:33588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeQq-O_Kk7aqBvaiGQYQABjx8"]
[Thu Sep 17 15:40:19.009585 2026] [security2:error] [pid 20162:tid 20386] [client 34.94.56.93:35504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.premium-cuts.com"] [uri "/"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQZwAAAew"]
[Thu Sep 17 15:40:19.026656 2026] [security2:error] [pid 20162:tid 20323] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/travis/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQaAAAAa0"]
[Thu Sep 17 15:40:19.083722 2026] [security2:error] [pid 20162:tid 20371] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/buildkite/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQawAAAd0"]
[Thu Sep 17 15:40:19.121036 2026] [core:error] [pid 20162:tid 20358] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.121059 2026] [core:error] [pid 20162:tid 20358] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.144269 2026] [security2:error] [pid 20162:tid 20357] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mysql/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQcQAAAc8"]
[Thu Sep 17 15:40:19.195519 2026] [security2:error] [pid 20162:tid 20304] [client 34.94.56.93:35520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webdisk.premium-cuts.com"] [uri "/"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQcgAAAZo"]
[Thu Sep 17 15:40:19.200906 2026] [security2:error] [pid 20162:tid 20310] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/postgres/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQcwAAAaA"]
[Thu Sep 17 15:40:19.257406 2026] [security2:error] [pid 20162:tid 20345] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/mongodb/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQdQAAAcM"]
[Thu Sep 17 15:40:19.292776 2026] [security2:error] [pid 20162:tid 20352] [client 34.94.56.93:35524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQdgAAAco"]
[Thu Sep 17 15:40:19.322174 2026] [security2:error] [pid 20162:tid 20374] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/redis/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQeQAAAeA"]
[Thu Sep 17 15:40:19.341938 2026] [core:error] [pid 20162:tid 20300] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.341953 2026] [core:error] [pid 20162:tid 20300] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.383713 2026] [security2:error] [pid 20162:tid 20408] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/elasticsearch/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQfAAAAgI"]
[Thu Sep 17 15:40:19.440969 2026] [security2:error] [pid 20162:tid 20294] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/rabbitmq/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQfwAAAZA"]
[Thu Sep 17 15:40:19.443638 2026] [core:error] [pid 20162:tid 20361] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.443656 2026] [core:error] [pid 20162:tid 20361] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.498324 2026] [security2:error] [pid 20162:tid 20399] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/kafka/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQgQAAAfk"]
[Thu Sep 17 15:40:19.553805 2026] [security2:error] [pid 20162:tid 20398] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/queue/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQhAAAAfg"]
[Thu Sep 17 15:40:19.578408 2026] [core:error] [pid 20162:tid 20320] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.578426 2026] [core:error] [pid 20162:tid 20320] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.610603 2026] [security2:error] [pid 20162:tid 20347] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/worker/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQiAAAAcU"]
[Thu Sep 17 15:40:19.675268 2026] [security2:error] [pid 20162:tid 20394] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/job/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQjQAAAfQ"]
[Thu Sep 17 15:40:19.677947 2026] [core:error] [pid 20162:tid 20337] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.677963 2026] [core:error] [pid 20162:tid 20337] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.730854 2026] [security2:error] [pid 20162:tid 20344] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/test/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQjwAAAcI"]
[Thu Sep 17 15:40:19.786691 2026] [security2:error] [pid 20162:tid 20350] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/qa/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQkwAAAcg"]
[Thu Sep 17 15:40:19.821559 2026] [security2:error] [pid 20162:tid 20206] [remote 62.201.248.20:33588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQkQABtio"]
[Thu Sep 17 15:40:19.836827 2026] [core:error] [pid 20162:tid 20339] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.836846 2026] [core:error] [pid 20162:tid 20339] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.841238 2026] [security2:error] [pid 20162:tid 20307] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/preview/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQlgAAAZ0"]
[Thu Sep 17 15:40:19.897895 2026] [security2:error] [pid 20162:tid 20412] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/beta/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQmQAAAgY"]
[Thu Sep 17 15:40:19.955628 2026] [security2:error] [pid 20162:tid 20362] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/uat/.env"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQnwAAAdQ"]
[Thu Sep 17 15:40:19.977218 2026] [core:error] [pid 20162:tid 20342] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:19.977242 2026] [core:error] [pid 20162:tid 20342] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.011318 2026] [security2:error] [pid 20162:tid 20395] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/stage/.env"] [unique_id "aqxeRK-O_Kk7aqBvaiGQoQAAAfU"]
[Thu Sep 17 15:40:20.048210 2026] [security2:error] [pid 20162:tid 20349] [client 34.94.56.93:35574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxeRK-O_Kk7aqBvaiGQogAAAcc"]
[Thu Sep 17 15:40:20.069282 2026] [security2:error] [pid 20162:tid 20396] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/development/.env"] [unique_id "aqxeRK-O_Kk7aqBvaiGQpAAAAfY"]
[Thu Sep 17 15:40:20.075530 2026] [security2:error] [pid 20162:tid 20403] [client 34.94.56.93:35574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxeRK-O_Kk7aqBvaiGQpQAAAf0"]
[Thu Sep 17 15:40:20.127168 2026] [security2:error] [pid 20162:tid 20368] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/production/.env"] [unique_id "aqxeRK-O_Kk7aqBvaiGQpwAAAdo"]
[Thu Sep 17 15:40:20.185276 2026] [security2:error] [pid 20162:tid 20414] [client 34.23.198.186:35432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.appalachian-landscapes.com"] [uri "/config/app/.env"] [unique_id "aqxeRK-O_Kk7aqBvaiGQrQAAAgg"]
[Thu Sep 17 15:40:20.217920 2026] [core:error] [pid 20162:tid 20338] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.217939 2026] [core:error] [pid 20162:tid 20338] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.243202 2026] [security2:error] [pid 20162:tid 20381] [client 34.23.198.186:35432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/phpinfo.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQsQAAAec"]
[Thu Sep 17 15:40:20.296165 2026] [security2:error] [pid 20162:tid 20358] [client 34.94.56.93:35582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxeRK-O_Kk7aqBvaiGQswAAAdA"]
[Thu Sep 17 15:40:20.373980 2026] [core:error] [pid 20162:tid 20331] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.374001 2026] [core:error] [pid 20162:tid 20331] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.421021 2026] [security2:error] [pid 20162:tid 20363] [client 34.23.198.186:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/info.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQtwAAAdU"]
[Thu Sep 17 15:40:20.516175 2026] [security2:error] [pid 20162:tid 20393] [client 103.61.184.148:56779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQugAAAfM"]
[Thu Sep 17 15:40:20.516322 2026] [security2:error] [pid 20162:tid 20393] [client 103.61.184.148:56779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQugAAAfM"]
[Thu Sep 17 15:40:20.529942 2026] [core:error] [pid 20162:tid 20383] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.529960 2026] [core:error] [pid 20162:tid 20383] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.581884 2026] [security2:error] [pid 20162:tid 20322] [client 34.23.198.186:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/php.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQvAAAAaw"]
[Thu Sep 17 15:40:20.661795 2026] [core:error] [pid 20162:tid 20326] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.661825 2026] [core:error] [pid 20162:tid 20326] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.736271 2026] [security2:error] [pid 20162:tid 20301] [client 109.105.210.89:36434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQvQAAAZc"]
[Thu Sep 17 15:40:20.770932 2026] [security2:error] [pid 20162:tid 20408] [client 34.23.198.186:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/i.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQxQAAAgI"]
[Thu Sep 17 15:40:20.857052 2026] [core:error] [pid 20162:tid 20410] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.857075 2026] [core:error] [pid 20162:tid 20410] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.868213 2026] [security2:error] [pid 20162:tid 20382] [client 4.240.114.86:57311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jwdnyc.com"] [uri "/index.php"] [unique_id "aqxeQq-O_Kk7aqBvaiGQXgAAAeg"], referer: binance.com
[Thu Sep 17 15:40:20.941512 2026] [security2:error] [pid 20162:tid 20341] [client 34.23.198.186:34278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/pi.php"] [unique_id "aqxeRK-O_Kk7aqBvaiGQzAAAAb8"]
[Thu Sep 17 15:40:20.955168 2026] [core:error] [pid 20162:tid 20375] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:20.955190 2026] [core:error] [pid 20162:tid 20375] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.078259 2026] [core:error] [pid 20162:tid 20317] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.078286 2026] [core:error] [pid 20162:tid 20317] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.125816 2026] [security2:error] [pid 20162:tid 20343] [client 34.23.198.186:34282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/pinfo.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ1QAAAcE"]
[Thu Sep 17 15:40:21.141205 2026] [security2:error] [pid 20162:tid 20406] [client 162.241.226.11:27738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxeQ6-O_Kk7aqBvaiGQlwAAAgA"]
[Thu Sep 17 15:40:21.216250 2026] [security2:error] [pid 20162:tid 20398] [client 177.44.133.72:51349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ2gAAAfg"]
[Thu Sep 17 15:40:21.216370 2026] [security2:error] [pid 20162:tid 20398] [client 177.44.133.72:51349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ2gAAAfg"]
[Thu Sep 17 15:40:21.234334 2026] [core:error] [pid 20162:tid 20319] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.234348 2026] [core:error] [pid 20162:tid 20319] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.291357 2026] [security2:error] [pid 20162:tid 20362] [client 34.23.198.186:34292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/test.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ3QAAAdQ"]
[Thu Sep 17 15:40:21.346188 2026] [core:error] [pid 20162:tid 20328] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.346205 2026] [core:error] [pid 20162:tid 20328] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.513742 2026] [core:error] [pid 20162:tid 20386] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.513761 2026] [core:error] [pid 20162:tid 20386] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.603555 2026] [core:error] [pid 20162:tid 20308] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.603574 2026] [core:error] [pid 20162:tid 20308] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.613106 2026] [security2:error] [pid 20162:tid 20397] [client 34.23.198.186:34304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ4QAAAfc"]
[Thu Sep 17 15:40:21.667042 2026] [security2:error] [pid 20162:tid 20373] [client 34.23.198.186:34304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/p.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ8AAAAd8"]
[Thu Sep 17 15:40:21.729497 2026] [core:error] [pid 20162:tid 20335] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.729518 2026] [core:error] [pid 20162:tid 20335] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.827435 2026] [security2:error] [pid 20162:tid 20366] [client 34.94.56.93:57660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ9AAAAdg"]
[Thu Sep 17 15:40:21.837842 2026] [security2:error] [pid 20162:tid 20374] [client 34.23.198.186:34308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/debug.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ9QAAAeA"]
[Thu Sep 17 15:40:21.860784 2026] [security2:error] [pid 20162:tid 20326] [client 34.94.56.93:57660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ9gAAAbA"]
[Thu Sep 17 15:40:21.951696 2026] [core:error] [pid 20162:tid 20420] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:21.951715 2026] [core:error] [pid 20162:tid 20420] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.052601 2026] [security2:error] [pid 20162:tid 20360] [client 34.23.198.186:34316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxeRq-O_Kk7aqBvaiGQ-wAAAdI"]
[Thu Sep 17 15:40:22.141026 2026] [core:error] [pid 20162:tid 20320] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.141044 2026] [core:error] [pid 20162:tid 20320] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.227270 2026] [security2:error] [pid 20162:tid 20408] [client 109.105.210.88:39892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeRq-O_Kk7aqBvaiGQ_gAAAgI"]
[Thu Sep 17 15:40:22.232686 2026] [security2:error] [pid 20162:tid 20400] [client 34.23.198.186:34330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/test/phpinfo.php"] [unique_id "aqxeRq-O_Kk7aqBvaiGRBgAAAfo"]
[Thu Sep 17 15:40:22.294131 2026] [core:error] [pid 20162:tid 20376] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.294150 2026] [core:error] [pid 20162:tid 20376] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.411990 2026] [security2:error] [pid 20162:tid 20343] [client 34.23.198.186:34332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxeRq-O_Kk7aqBvaiGRCwAAAcE"]
[Thu Sep 17 15:40:22.421883 2026] [security2:error] [pid 20162:tid 20411] [client 162.241.226.11:27750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxeRa-O_Kk7aqBvaiGQ2AAAAgU"]
[Thu Sep 17 15:40:22.578936 2026] [security2:error] [pid 20162:tid 20307] [client 34.23.198.186:34334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/old/phpinfo.php"] [unique_id "aqxeRq-O_Kk7aqBvaiGRDQAAAZ0"]
[Thu Sep 17 15:40:22.747161 2026] [security2:error] [pid 20162:tid 20359] [client 34.23.198.186:34342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxeRq-O_Kk7aqBvaiGRFAAAAdE"]
[Thu Sep 17 15:40:22.779553 2026] [core:error] [pid 20162:tid 20395] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.779570 2026] [core:error] [pid 20162:tid 20395] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.909832 2026] [core:error] [pid 20162:tid 20402] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.909851 2026] [core:error] [pid 20162:tid 20402] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:22.913484 2026] [security2:error] [pid 20162:tid 20414] [client 34.23.198.186:34356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/public/phpinfo.php"] [unique_id "aqxeRq-O_Kk7aqBvaiGRHwAAAgg"]
[Thu Sep 17 15:40:23.034163 2026] [security2:error] [pid 20162:tid 20340] [client 34.94.56.93:57728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRIwAAAb4"]
[Thu Sep 17 15:40:23.064971 2026] [security2:error] [pid 20162:tid 20363] [client 34.94.56.93:57728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRJAAAAdU"]
[Thu Sep 17 15:40:23.087910 2026] [security2:error] [pid 20162:tid 20373] [client 34.94.56.93:57728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRJQAAAd8"]
[Thu Sep 17 15:40:23.115112 2026] [security2:error] [pid 20162:tid 20378] [client 34.94.56.93:57728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRJwAAAeQ"]
[Thu Sep 17 15:40:23.138740 2026] [security2:error] [pid 20162:tid 20310] [client 34.94.56.93:57728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRKwAAAaA"]
[Thu Sep 17 15:40:23.163411 2026] [security2:error] [pid 20162:tid 20302] [client 34.94.56.93:57728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRLQAAAZg"]
[Thu Sep 17 15:40:23.164863 2026] [security2:error] [pid 20162:tid 20357] [client 34.23.198.186:34364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRJgAAAc8"]
[Thu Sep 17 15:40:23.248934 2026] [security2:error] [pid 20162:tid 20420] [client 169.58.197.251:61898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRMQAAAg4"], referer: binance.com
[Thu Sep 17 15:40:23.286288 2026] [core:error] [pid 20162:tid 20354] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:23.286307 2026] [core:error] [pid 20162:tid 20354] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:23.324380 2026] [security2:error] [pid 20162:tid 20410] [client 34.23.198.186:34364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/php-info.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRMwAAAgQ"]
[Thu Sep 17 15:40:23.398388 2026] [security2:error] [pid 20162:tid 20305] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGROgAAAZs"]
[Thu Sep 17 15:40:23.416810 2026] [security2:error] [pid 20162:tid 20375] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRQAAAAeE"]
[Thu Sep 17 15:40:23.420411 2026] [security2:error] [pid 20162:tid 20392] [client 143.105.152.240:22300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRQQAAAfI"]
[Thu Sep 17 15:40:23.429070 2026] [security2:error] [pid 20162:tid 20392] [client 143.105.152.240:22300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRQQAAAfI"]
[Thu Sep 17 15:40:23.444882 2026] [security2:error] [pid 20162:tid 20306] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRQgAAAZw"]
[Thu Sep 17 15:40:23.464986 2026] [security2:error] [pid 20162:tid 20347] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRQwAAAcU"]
[Thu Sep 17 15:40:23.481011 2026] [security2:error] [pid 20162:tid 20408] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRRAAAAgI"]
[Thu Sep 17 15:40:23.492762 2026] [security2:error] [pid 20162:tid 20401] [client 34.23.198.186:34368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/phpversion.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRRQAAAfs"]
[Thu Sep 17 15:40:23.498738 2026] [security2:error] [pid 20162:tid 20400] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRRgAAAfo"]
[Thu Sep 17 15:40:23.513872 2026] [security2:error] [pid 20162:tid 20409] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRRwAAAgM"]
[Thu Sep 17 15:40:23.537234 2026] [security2:error] [pid 20162:tid 20369] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRSAAAAds"]
[Thu Sep 17 15:40:23.554888 2026] [security2:error] [pid 20162:tid 20353] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRSwAAAcs"]
[Thu Sep 17 15:40:23.570908 2026] [security2:error] [pid 20162:tid 20298] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRTAAAAZQ"]
[Thu Sep 17 15:40:23.588620 2026] [security2:error] [pid 20162:tid 20394] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRTwAAAfQ"]
[Thu Sep 17 15:40:23.606286 2026] [security2:error] [pid 20162:tid 20390] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRUAAAAfA"]
[Thu Sep 17 15:40:23.619939 2026] [security2:error] [pid 20162:tid 20344] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRUQAAAcI"]
[Thu Sep 17 15:40:23.634316 2026] [security2:error] [pid 20162:tid 20406] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRUgAAAgA"]
[Thu Sep 17 15:40:23.666104 2026] [security2:error] [pid 20162:tid 20351] [client 34.23.198.186:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/_phpinfo.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRVwAAAck"]
[Thu Sep 17 15:40:23.666266 2026] [security2:error] [pid 20162:tid 20411] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRVQAAAgU"]
[Thu Sep 17 15:40:23.694725 2026] [security2:error] [pid 20162:tid 20352] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRWQAAAco"]
[Thu Sep 17 15:40:23.706722 2026] [security2:error] [pid 20162:tid 20404] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRWgAAAf4"]
[Thu Sep 17 15:40:23.734690 2026] [security2:error] [pid 20162:tid 20336] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRXQAAAbo"]
[Thu Sep 17 15:40:23.760380 2026] [security2:error] [pid 20162:tid 20332] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRXgAAAbY"]
[Thu Sep 17 15:40:23.779502 2026] [security2:error] [pid 20162:tid 20339] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRXwAAAb0"]
[Thu Sep 17 15:40:23.797696 2026] [security2:error] [pid 20162:tid 20359] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRYAAAAdE"]
[Thu Sep 17 15:40:23.821969 2026] [security2:error] [pid 20162:tid 20395] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRYQAAAfU"]
[Thu Sep 17 15:40:23.848345 2026] [security2:error] [pid 20162:tid 20396] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRZAAAAfY"]
[Thu Sep 17 15:40:23.868326 2026] [security2:error] [pid 20162:tid 20389] [client 34.23.198.186:34380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/old_phpinfo.php"] [unique_id "aqxeR6-O_Kk7aqBvaiGRZQAAAe8"]
[Thu Sep 17 15:40:23.872720 2026] [security2:error] [pid 20162:tid 20362] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRZgAAAdQ"]
[Thu Sep 17 15:40:23.890350 2026] [security2:error] [pid 20162:tid 20368] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRZwAAAdo"]
[Thu Sep 17 15:40:23.918717 2026] [security2:error] [pid 20162:tid 20377] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRaAAAAeM"]
[Thu Sep 17 15:40:23.939367 2026] [security2:error] [pid 20162:tid 20318] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRaQAAAag"]
[Thu Sep 17 15:40:23.953842 2026] [security2:error] [pid 20162:tid 20338] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRbAAAAbw"]
[Thu Sep 17 15:40:23.970199 2026] [security2:error] [pid 20162:tid 20414] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRbQAAAgg"]
[Thu Sep 17 15:40:23.994651 2026] [security2:error] [pid 20162:tid 20416] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxeR6-O_Kk7aqBvaiGRbgAAAgo"]
[Thu Sep 17 15:40:24.012235 2026] [security2:error] [pid 20162:tid 20419] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRbwAAAg0"]
[Thu Sep 17 15:40:24.014968 2026] [core:error] [pid 20162:tid 20213] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.014988 2026] [core:error] [pid 20162:tid 20213] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.047668 2026] [security2:error] [pid 20162:tid 20308] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRcQAAAZ4"]
[Thu Sep 17 15:40:24.057187 2026] [security2:error] [pid 20162:tid 20386] [client 34.23.198.186:34388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/server-info.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGRdAAAAew"]
[Thu Sep 17 15:40:24.071123 2026] [security2:error] [pid 20162:tid 20304] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRdgAAAZo"]
[Thu Sep 17 15:40:24.097990 2026] [security2:error] [pid 20162:tid 20331] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGReQAAAbU"]
[Thu Sep 17 15:40:24.098260 2026] [security2:error] [pid 20162:tid 20340] [client 127.0.0.1:44256] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxeSK-O_Kk7aqBvaiGRdQAAAb4"]
[Thu Sep 17 15:40:24.098329 2026] [security2:error] [pid 20162:tid 20397] [client 127.0.0.1:44254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.stevenreedcollins.com"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxeSK-O_Kk7aqBvaiGRcwAAAfc"]
[Thu Sep 17 15:40:24.098465 2026] [security2:error] [pid 20162:tid 20371] [client 74.7.175.135:60288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.stevenreedcollins.com"] [uri "/robots.txt"] [unique_id "aqxeSK-O_Kk7aqBvaiGRcgAB3Uc"]
[Thu Sep 17 15:40:24.118192 2026] [security2:error] [pid 20162:tid 20310] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRewAAAaA"]
[Thu Sep 17 15:40:24.134801 2026] [security2:error] [pid 20162:tid 20356] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRfAAAAc4"]
[Thu Sep 17 15:40:24.151292 2026] [security2:error] [pid 20162:tid 20349] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRfgAAAcc"]
[Thu Sep 17 15:40:24.157271 2026] [security2:error] [pid 20162:tid 20225] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRgQABmD0"]
[Thu Sep 17 15:40:24.158643 2026] [security2:error] [pid 20162:tid 20248] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.env.old"] [unique_id "aqxeSK-O_Kk7aqBvaiGRiAABmFQ"]
[Thu Sep 17 15:40:24.158696 2026] [security2:error] [pid 20162:tid 20243] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.env.backup"] [unique_id "aqxeSK-O_Kk7aqBvaiGRhwABmE8"]
[Thu Sep 17 15:40:24.158695 2026] [security2:error] [pid 20162:tid 20245] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.env.bak"] [unique_id "aqxeSK-O_Kk7aqBvaiGRiQABmFE"]
[Thu Sep 17 15:40:24.158855 2026] [core:error] [pid 20162:tid 20232] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.158868 2026] [core:error] [pid 20162:tid 20232] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159067 2026] [core:error] [pid 20162:tid 20242] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159074 2026] [core:error] [pid 20162:tid 20242] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159079 2026] [core:error] [pid 20162:tid 20228] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159090 2026] [core:error] [pid 20162:tid 20228] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159091 2026] [core:error] [pid 20162:tid 20179] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159097 2026] [core:error] [pid 20162:tid 20179] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159108 2026] [core:error] [pid 20162:tid 20241] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159118 2026] [core:error] [pid 20162:tid 20241] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159826 2026] [core:error] [pid 20162:tid 20225] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159838 2026] [core:error] [pid 20162:tid 20225] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159852 2026] [core:error] [pid 20162:tid 20238] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159863 2026] [core:error] [pid 20162:tid 20238] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159874 2026] [core:error] [pid 20162:tid 20249] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159874 2026] [core:error] [pid 20162:tid 20251] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159879 2026] [core:error] [pid 20162:tid 20249] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.159884 2026] [core:error] [pid 20162:tid 20251] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.160523 2026] [core:error] [pid 20162:tid 20248] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.160528 2026] [core:error] [pid 20162:tid 20248] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.160866 2026] [core:error] [pid 20162:tid 20243] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.160865 2026] [core:error] [pid 20162:tid 20259] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.160878 2026] [core:error] [pid 20162:tid 20243] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.160879 2026] [core:error] [pid 20162:tid 20259] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.171330 2026] [security2:error] [pid 20162:tid 20366] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRjwAAAdg"]
[Thu Sep 17 15:40:24.186904 2026] [security2:error] [pid 20162:tid 20309] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRkAAAAZ8"]
[Thu Sep 17 15:40:24.203461 2026] [security2:error] [pid 20162:tid 20420] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRkQAAAg4"]
[Thu Sep 17 15:40:24.218729 2026] [security2:error] [pid 20162:tid 20294] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRkgAAAZA"]
[Thu Sep 17 15:40:24.219993 2026] [security2:error] [pid 20162:tid 20357] [client 34.23.198.186:34396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/server-status.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGRkwAAAc8"]
[Thu Sep 17 15:40:24.244519 2026] [security2:error] [pid 20162:tid 20372] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRlAAAAd4"]
[Thu Sep 17 15:40:24.269225 2026] [security2:error] [pid 20162:tid 20354] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRlQAAAcw"]
[Thu Sep 17 15:40:24.291865 2026] [security2:error] [pid 20162:tid 20301] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRlgAAAZc"]
[Thu Sep 17 15:40:24.294773 2026] [core:error] [pid 20162:tid 20271] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.294787 2026] [core:error] [pid 20162:tid 20271] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.295314 2026] [security2:error] [pid 20162:tid 20279] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.env~"] [unique_id "aqxeSK-O_Kk7aqBvaiGRmwABsXM"]
[Thu Sep 17 15:40:24.295446 2026] [security2:error] [pid 20162:tid 20237] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.env.swp"] [unique_id "aqxeSK-O_Kk7aqBvaiGRnAABsUk"]
[Thu Sep 17 15:40:24.296165 2026] [core:error] [pid 20162:tid 20244] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296176 2026] [core:error] [pid 20162:tid 20244] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296293 2026] [core:error] [pid 20162:tid 20253] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296299 2026] [core:error] [pid 20162:tid 20253] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296370 2026] [core:error] [pid 20162:tid 20234] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296380 2026] [core:error] [pid 20162:tid 20234] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296476 2026] [core:error] [pid 20162:tid 20247] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296477 2026] [core:error] [pid 20162:tid 20246] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296485 2026] [core:error] [pid 20162:tid 20247] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.296487 2026] [core:error] [pid 20162:tid 20246] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.298196 2026] [security2:error] [pid 20162:tid 20270] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/api/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRoQABsWo"]
[Thu Sep 17 15:40:24.298269 2026] [security2:error] [pid 20162:tid 20250] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/app/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRowABsVY"]
[Thu Sep 17 15:40:24.298985 2026] [core:error] [pid 20162:tid 20191] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.298995 2026] [core:error] [pid 20162:tid 20191] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.299152 2026] [core:error] [pid 20162:tid 20255] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.299160 2026] [core:error] [pid 20162:tid 20255] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.311096 2026] [security2:error] [pid 20162:tid 20326] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRpAAAAbA"]
[Thu Sep 17 15:40:24.312134 2026] [security2:error] [pid 20162:tid 20239] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/.env.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGRmQABsUs"]
[Thu Sep 17 15:40:24.327178 2026] [security2:error] [pid 20162:tid 20360] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRpQAAAdI"]
[Thu Sep 17 15:40:24.349323 2026] [security2:error] [pid 20162:tid 20316] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRpgAAAaY"]
[Thu Sep 17 15:40:24.369441 2026] [security2:error] [pid 20162:tid 20385] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRpwAAAes"]
[Thu Sep 17 15:40:24.397433 2026] [security2:error] [pid 20162:tid 20320] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRqQAAAao"]
[Thu Sep 17 15:40:24.415477 2026] [security2:error] [pid 20162:tid 20410] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRqgAAAgQ"]
[Thu Sep 17 15:40:24.420667 2026] [security2:error] [pid 20162:tid 20315] [client 79.116.89.151:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGRqwAAAaU"]
[Thu Sep 17 15:40:24.420746 2026] [security2:error] [pid 20162:tid 20315] [client 79.116.89.151:56026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGRqwAAAaU"]
[Thu Sep 17 15:40:24.427492 2026] [security2:error] [pid 20162:tid 20260] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/backend/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRrgAB6WA"]
[Thu Sep 17 15:40:24.428643 2026] [core:error] [pid 20162:tid 20282] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.428656 2026] [core:error] [pid 20162:tid 20282] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.428694 2026] [core:error] [pid 20162:tid 20256] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.428701 2026] [core:error] [pid 20162:tid 20256] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.432338 2026] [security2:error] [pid 20162:tid 20311] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRrwAAAaE"]
[Thu Sep 17 15:40:24.441414 2026] [core:error] [pid 20162:tid 20281] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.441431 2026] [core:error] [pid 20162:tid 20281] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.443882 2026] [security2:error] [pid 20162:tid 20265] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/client/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRtQAB-WU"]
[Thu Sep 17 15:40:24.443899 2026] [security2:error] [pid 20162:tid 20285] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/config/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRsgAB-Xk"]
[Thu Sep 17 15:40:24.443914 2026] [security2:error] [pid 20162:tid 20266] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/src/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRswAB-WY"]
[Thu Sep 17 15:40:24.443950 2026] [security2:error] [pid 20162:tid 20278] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/server/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRsQAB-XI"]
[Thu Sep 17 15:40:24.443977 2026] [security2:error] [pid 20162:tid 20257] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/web/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRtAAB-V0"]
[Thu Sep 17 15:40:24.444007 2026] [security2:error] [pid 20162:tid 20280] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/laravel/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRugAB-XQ"]
[Thu Sep 17 15:40:24.444035 2026] [security2:error] [pid 20162:tid 20286] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/public/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRtwAB-Xo"]
[Thu Sep 17 15:40:24.444065 2026] [security2:error] [pid 20162:tid 20276] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/var/www/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRuAAB-XA"]
[Thu Sep 17 15:40:24.444067 2026] [security2:error] [pid 20162:tid 20258] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/var/www/html/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRuQAB-V4"]
[Thu Sep 17 15:40:24.444081 2026] [security2:error] [pid 20162:tid 20275] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/frontend/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRtgAB-W8"]
[Thu Sep 17 15:40:24.444148 2026] [security2:error] [pid 20162:tid 20273] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/application/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRuwAB-W0"]
[Thu Sep 17 15:40:24.446978 2026] [security2:error] [pid 20162:tid 20374] [client 34.23.198.186:34404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGRqAAAAeA"]
[Thu Sep 17 15:40:24.457249 2026] [security2:error] [pid 20162:tid 20287] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/apps/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRvAABlXs"]
[Thu Sep 17 15:40:24.458024 2026] [security2:error] [pid 20162:tid 20312] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRvQAAAaI"]
[Thu Sep 17 15:40:24.479203 2026] [security2:error] [pid 20162:tid 20391] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRvgAAAfE"]
[Thu Sep 17 15:40:24.495028 2026] [security2:error] [pid 20162:tid 20382] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRvwAAAeg"]
[Thu Sep 17 15:40:24.533050 2026] [security2:error] [pid 20162:tid 20381] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRwQAAAec"]
[Thu Sep 17 15:40:24.559033 2026] [security2:error] [pid 20162:tid 20305] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRwwAAAZs"]
[Thu Sep 17 15:40:24.561694 2026] [security2:error] [pid 20162:tid 20274] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/back/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRxAAB4W4"]
[Thu Sep 17 15:40:24.563107 2026] [security2:error] [pid 20162:tid 20268] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/backup/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRxgAB8mg"]
[Thu Sep 17 15:40:24.563731 2026] [security2:error] [pid 20162:tid 20272] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/cms/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRxQAB8mw"]
[Thu Sep 17 15:40:24.575381 2026] [security2:error] [pid 20162:tid 20306] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRxwAAAZw"]
[Thu Sep 17 15:40:24.576046 2026] [security2:error] [pid 20162:tid 20267] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/dev/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRyAAB-2c"]
[Thu Sep 17 15:40:24.578461 2026] [security2:error] [pid 20162:tid 20269] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/staging/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRzgAB-mk"]
[Thu Sep 17 15:40:24.578482 2026] [security2:error] [pid 20162:tid 20263] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/prod/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRyQAB-mM"]
[Thu Sep 17 15:40:24.578505 2026] [security2:error] [pid 20162:tid 20290] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/test/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRywAB-n4"]
[Thu Sep 17 15:40:24.578529 2026] [security2:error] [pid 20162:tid 20262] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/new/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRzwAB-mI"]
[Thu Sep 17 15:40:24.578564 2026] [security2:error] [pid 20162:tid 20166] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/node-api/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRzQAB-gI"]
[Thu Sep 17 15:40:24.578569 2026] [security2:error] [pid 20162:tid 20264] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/old/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRzAAB-mQ"]
[Thu Sep 17 15:40:24.578615 2026] [security2:error] [pid 20162:tid 20254] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/api-backend/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR0AAB-lo"]
[Thu Sep 17 15:40:24.578621 2026] [security2:error] [pid 20162:tid 20288] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/production/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGRygAB-nw"]
[Thu Sep 17 15:40:24.579088 2026] [security2:error] [pid 20162:tid 20188] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/admin-app/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR0QAB-hg"]
[Thu Sep 17 15:40:24.579155 2026] [security2:error] [pid 20162:tid 20291] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/public_html/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR0wAB-n8"]
[Thu Sep 17 15:40:24.591526 2026] [security2:error] [pid 20162:tid 20169] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/current/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR1AAB-gU"]
[Thu Sep 17 15:40:24.603042 2026] [security2:error] [pid 20162:tid 20409] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR1QAAAgM"]
[Thu Sep 17 15:40:24.608985 2026] [security2:error] [pid 20162:tid 20277] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/administrator/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR0gAB-nE"]
[Thu Sep 17 15:40:24.615748 2026] [security2:error] [pid 20162:tid 20341] [client 34.23.198.186:34404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGRwgAAAb8"]
[Thu Sep 17 15:40:24.631531 2026] [security2:error] [pid 20162:tid 20376] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR2AAAAeI"]
[Thu Sep 17 15:40:24.670934 2026] [security2:error] [pid 20162:tid 20353] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR2gAAAcs"]
[Thu Sep 17 15:40:24.674143 2026] [security2:error] [pid 20162:tid 20298] [client 34.23.198.186:34404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxeSK-O_Kk7aqBvaiGR2wAAAZQ"]
[Thu Sep 17 15:40:24.692126 2026] [security2:error] [pid 20162:tid 20394] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR3AAAAfQ"]
[Thu Sep 17 15:40:24.698591 2026] [security2:error] [pid 20162:tid 20289] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/server/api/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR3QABp30"]
[Thu Sep 17 15:40:24.700560 2026] [security2:error] [pid 20162:tid 20167] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.docker/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR3wAB8AM"]
[Thu Sep 17 15:40:24.700560 2026] [security2:error] [pid 20162:tid 20283] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/server/backend/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR3gAB8Hc"]
[Thu Sep 17 15:40:24.706903 2026] [security2:error] [pid 20162:tid 20344] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR4AAAAcI"]
[Thu Sep 17 15:40:24.713359 2026] [security2:error] [pid 20162:tid 20178] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR4QACAA4"]
[Thu Sep 17 15:40:24.715060 2026] [security2:error] [pid 20162:tid 20168] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/aws/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR4gAB3AQ"]
[Thu Sep 17 15:40:24.715136 2026] [security2:error] [pid 20162:tid 20171] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/v1/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR6QAB3Ac"]
[Thu Sep 17 15:40:24.715162 2026] [security2:error] [pid 20162:tid 20177] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.aws/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR4wAB3A0"]
[Thu Sep 17 15:40:24.715216 2026] [security2:error] [pid 20162:tid 20172] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/stripe/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR5AAB3Ag"]
[Thu Sep 17 15:40:24.715266 2026] [security2:error] [pid 20162:tid 20165] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/v2/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR5wAB3AE"]
[Thu Sep 17 15:40:24.715288 2026] [security2:error] [pid 20162:tid 20174] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/media/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR6gAB3Ao"]
[Thu Sep 17 15:40:24.715312 2026] [security2:error] [pid 20162:tid 20284] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/v3/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR6AAB3Hg"]
[Thu Sep 17 15:40:24.716255 2026] [core:error] [pid 20162:tid 20181] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.716265 2026] [core:error] [pid 20162:tid 20181] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.716303 2026] [core:error] [pid 20162:tid 20175] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.716315 2026] [core:error] [pid 20162:tid 20175] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.716852 2026] [core:error] [pid 20162:tid 20180] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.716867 2026] [core:error] [pid 20162:tid 20180] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.726961 2026] [core:error] [pid 20162:tid 20185] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.726973 2026] [core:error] [pid 20162:tid 20185] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.732694 2026] [security2:error] [pid 20162:tid 20411] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR7QAAAgU"]
[Thu Sep 17 15:40:24.743929 2026] [core:error] [pid 20162:tid 20183] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.743940 2026] [core:error] [pid 20162:tid 20183] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.758649 2026] [security2:error] [pid 20162:tid 20398] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR7wAAAfg"]
[Thu Sep 17 15:40:24.775852 2026] [security2:error] [pid 20162:tid 20404] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR8AAAAf4"]
[Thu Sep 17 15:40:24.800743 2026] [security2:error] [pid 20162:tid 20297] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR8gAAAZM"]
[Thu Sep 17 15:40:24.819398 2026] [security2:error] [pid 20162:tid 20321] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR8wAAAas"]
[Thu Sep 17 15:40:24.835169 2026] [core:error] [pid 20162:tid 20173] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.835188 2026] [core:error] [pid 20162:tid 20173] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.835787 2026] [security2:error] [pid 20162:tid 20339] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGR9wAAAb0"]
[Thu Sep 17 15:40:24.835829 2026] [core:error] [pid 20162:tid 20199] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.835837 2026] [core:error] [pid 20162:tid 20199] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.835959 2026] [core:error] [pid 20162:tid 20187] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.835967 2026] [core:error] [pid 20162:tid 20187] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.842922 2026] [security2:error] [pid 20162:tid 20342] [client 34.23.198.186:34408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxeSK-O_Kk7aqBvaiGR-AAAAcA"]
[Thu Sep 17 15:40:24.848465 2026] [core:error] [pid 20162:tid 20203] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.848479 2026] [core:error] [pid 20162:tid 20203] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.849750 2026] [security2:error] [pid 20162:tid 20186] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.git/config.bak"] [unique_id "aqxeSK-O_Kk7aqBvaiGR_wABwRY"]
[Thu Sep 17 15:40:24.850520 2026] [core:error] [pid 20162:tid 20194] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.850530 2026] [core:error] [pid 20162:tid 20194] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.850668 2026] [core:error] [pid 20162:tid 20190] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.850680 2026] [core:error] [pid 20162:tid 20190] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.850781 2026] [core:error] [pid 20162:tid 20202] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.850782 2026] [core:error] [pid 20162:tid 20195] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.850791 2026] [core:error] [pid 20162:tid 20202] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.850796 2026] [core:error] [pid 20162:tid 20195] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851081 2026] [core:error] [pid 20162:tid 20204] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851087 2026] [core:error] [pid 20162:tid 20204] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851232 2026] [core:error] [pid 20162:tid 20182] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851242 2026] [core:error] [pid 20162:tid 20182] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851346 2026] [core:error] [pid 20162:tid 20206] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851352 2026] [core:error] [pid 20162:tid 20206] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851746 2026] [core:error] [pid 20162:tid 20198] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851757 2026] [core:error] [pid 20162:tid 20198] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851901 2026] [core:error] [pid 20162:tid 20176] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.851910 2026] [core:error] [pid 20162:tid 20176] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.862578 2026] [core:error] [pid 20162:tid 20197] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.862596 2026] [core:error] [pid 20162:tid 20197] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.875970 2026] [security2:error] [pid 20162:tid 20388] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGSBQAAAe4"]
[Thu Sep 17 15:40:24.879294 2026] [core:error] [pid 20162:tid 20192] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.879310 2026] [core:error] [pid 20162:tid 20192] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.890151 2026] [security2:error] [pid 20162:tid 20296] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGSBwAAAZI"]
[Thu Sep 17 15:40:24.916419 2026] [security2:error] [pid 20162:tid 20384] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGSCAAAAeo"]
[Thu Sep 17 15:40:24.938548 2026] [security2:error] [pid 20162:tid 20389] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGSCQAAAe8"]
[Thu Sep 17 15:40:24.965417 2026] [security2:error] [pid 20162:tid 20377] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGSCgAAAeM"]
[Thu Sep 17 15:40:24.970312 2026] [security2:error] [pid 20162:tid 20200] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.aws/credentials.bak"] [unique_id "aqxeSK-O_Kk7aqBvaiGSDQABoyQ"]
[Thu Sep 17 15:40:24.971158 2026] [core:error] [pid 20162:tid 20207] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.971172 2026] [core:error] [pid 20162:tid 20207] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.971180 2026] [core:error] [pid 20162:tid 20189] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.971188 2026] [core:error] [pid 20162:tid 20189] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.983254 2026] [security2:error] [pid 20162:tid 20318] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxeSK-O_Kk7aqBvaiGSDgAAAag"]
[Thu Sep 17 15:40:24.984006 2026] [core:error] [pid 20162:tid 20196] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.984017 2026] [core:error] [pid 20162:tid 20196] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.984568 2026] [core:error] [pid 20162:tid 20211] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.984576 2026] [core:error] [pid 20162:tid 20211] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.985532 2026] [security2:error] [pid 20162:tid 20209] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/id_rsa"] [unique_id "aqxeSK-O_Kk7aqBvaiGSEwACCC0"]
[Thu Sep 17 15:40:24.985616 2026] [security2:error] [pid 20162:tid 20212] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/.ssh/id_rsa"] [unique_id "aqxeSK-O_Kk7aqBvaiGSEgACCDA"]
[Thu Sep 17 15:40:24.986112 2026] [core:error] [pid 20162:tid 20193] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.986121 2026] [core:error] [pid 20162:tid 20193] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.986442 2026] [core:error] [pid 20162:tid 20214] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.986450 2026] [core:error] [pid 20162:tid 20214] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.986631 2026] [core:error] [pid 20162:tid 20215] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.986638 2026] [core:error] [pid 20162:tid 20215] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.986747 2026] [core:error] [pid 20162:tid 20201] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.986756 2026] [core:error] [pid 20162:tid 20201] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.987117 2026] [core:error] [pid 20162:tid 20216] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.987127 2026] [core:error] [pid 20162:tid 20216] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.987348 2026] [core:error] [pid 20162:tid 20217] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.987357 2026] [core:error] [pid 20162:tid 20217] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.987927 2026] [core:error] [pid 20162:tid 20208] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.987942 2026] [core:error] [pid 20162:tid 20208] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.998171 2026] [core:error] [pid 20162:tid 20205] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:24.998183 2026] [core:error] [pid 20162:tid 20205] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.010531 2026] [security2:error] [pid 20162:tid 20368] [client 34.23.198.186:34414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSGwAAAdo"]
[Thu Sep 17 15:40:25.013272 2026] [security2:error] [pid 20162:tid 20358] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSHAAAAdA"]
[Thu Sep 17 15:40:25.014404 2026] [core:error] [pid 20162:tid 20170] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.014416 2026] [core:error] [pid 20162:tid 20170] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.027886 2026] [security2:error] [pid 20162:tid 20308] [client 34.94.56.93:57738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSIQAAAZ4"]
[Thu Sep 17 15:40:25.100602 2026] [security2:error] [pid 20162:tid 20334] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSJQAAAbg"]
[Thu Sep 17 15:40:25.105999 2026] [core:error] [pid 20162:tid 20210] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.106017 2026] [core:error] [pid 20162:tid 20210] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.106708 2026] [core:error] [pid 20162:tid 20184] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.106720 2026] [core:error] [pid 20162:tid 20184] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.106852 2026] [core:error] [pid 20162:tid 20223] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.106860 2026] [core:error] [pid 20162:tid 20223] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.118910 2026] [core:error] [pid 20162:tid 20218] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.118920 2026] [core:error] [pid 20162:tid 20218] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.119503 2026] [core:error] [pid 20162:tid 20231] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.119513 2026] [core:error] [pid 20162:tid 20231] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.120430 2026] [core:error] [pid 20162:tid 20220] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.120443 2026] [core:error] [pid 20162:tid 20220] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.120640 2026] [core:error] [pid 20162:tid 20229] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.120650 2026] [core:error] [pid 20162:tid 20229] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.121136 2026] [core:error] [pid 20162:tid 20230] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.121151 2026] [core:error] [pid 20162:tid 20230] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.121330 2026] [core:error] [pid 20162:tid 20219] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.121337 2026] [core:error] [pid 20162:tid 20219] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.121705 2026] [core:error] [pid 20162:tid 20222] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.121716 2026] [core:error] [pid 20162:tid 20222] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122116 2026] [core:error] [pid 20162:tid 20226] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122126 2026] [core:error] [pid 20162:tid 20226] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122205 2026] [core:error] [pid 20162:tid 20224] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122213 2026] [core:error] [pid 20162:tid 20224] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122739 2026] [core:error] [pid 20162:tid 20213] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122753 2026] [core:error] [pid 20162:tid 20213] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122844 2026] [core:error] [pid 20162:tid 20235] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.122850 2026] [core:error] [pid 20162:tid 20235] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.123774 2026] [security2:error] [pid 20162:tid 20397] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSNAAAAfc"]
[Thu Sep 17 15:40:25.135072 2026] [core:error] [pid 20162:tid 20240] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.135084 2026] [core:error] [pid 20162:tid 20240] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.152005 2026] [core:error] [pid 20162:tid 20236] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.152019 2026] [core:error] [pid 20162:tid 20236] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.161383 2026] [security2:error] [pid 20162:tid 20349] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSOgAAAcc"]
[Thu Sep 17 15:40:25.181489 2026] [security2:error] [pid 20162:tid 20415] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSOwAAAgk"]
[Thu Sep 17 15:40:25.184272 2026] [security2:error] [pid 20162:tid 20371] [client 34.23.198.186:34418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSPAAAAd0"]
[Thu Sep 17 15:40:25.213205 2026] [security2:error] [pid 20162:tid 20309] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSPgAAAZ8"]
[Thu Sep 17 15:40:25.243995 2026] [security2:error] [pid 20162:tid 20328] [client 136.158.61.34:31293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSPwAAAbI"]
[Thu Sep 17 15:40:25.244105 2026] [security2:error] [pid 20162:tid 20328] [client 136.158.61.34:31293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSPwAAAbI"]
[Thu Sep 17 15:40:25.247236 2026] [security2:error] [pid 20162:tid 20372] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSQwAAAd4"]
[Thu Sep 17 15:40:25.247259 2026] [core:error] [pid 20162:tid 20245] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.247262 2026] [core:error] [pid 20162:tid 20232] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.247272 2026] [core:error] [pid 20162:tid 20245] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.247278 2026] [core:error] [pid 20162:tid 20232] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.247838 2026] [core:error] [pid 20162:tid 20252] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.247858 2026] [core:error] [pid 20162:tid 20252] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.258130 2026] [security2:error] [pid 20162:tid 20241] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/config.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSRwAB800"]
[Thu Sep 17 15:40:25.258253 2026] [core:error] [pid 20162:tid 20242] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.258262 2026] [core:error] [pid 20162:tid 20179] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.258263 2026] [core:error] [pid 20162:tid 20242] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.258267 2026] [core:error] [pid 20162:tid 20179] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.259292 2026] [core:error] [pid 20162:tid 20238] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.259303 2026] [core:error] [pid 20162:tid 20238] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.259344 2026] [core:error] [pid 20162:tid 20225] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.259351 2026] [core:error] [pid 20162:tid 20225] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.259961 2026] [core:error] [pid 20162:tid 20249] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.259972 2026] [core:error] [pid 20162:tid 20249] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.260623 2026] [core:error] [pid 20162:tid 20251] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.260641 2026] [core:error] [pid 20162:tid 20251] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.261628 2026] [core:error] [pid 20162:tid 20248] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.261642 2026] [core:error] [pid 20162:tid 20248] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.261741 2026] [core:error] [pid 20162:tid 20243] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.261752 2026] [core:error] [pid 20162:tid 20243] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.261982 2026] [core:error] [pid 20162:tid 20259] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.261987 2026] [core:error] [pid 20162:tid 20259] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.263987 2026] [security2:error] [pid 20162:tid 20361] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSUAAAAdM"]
[Thu Sep 17 15:40:25.264333 2026] [core:error] [pid 20162:tid 20271] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.264339 2026] [core:error] [pid 20162:tid 20271] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.271923 2026] [core:error] [pid 20162:tid 20279] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.271931 2026] [core:error] [pid 20162:tid 20279] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.277991 2026] [core:error] [pid 20162:tid 20301] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.278002 2026] [core:error] [pid 20162:tid 20301] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.281697 2026] [security2:error] [pid 20162:tid 20360] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSUwAAAdI"]
[Thu Sep 17 15:40:25.288462 2026] [core:error] [pid 20162:tid 20237] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.288473 2026] [core:error] [pid 20162:tid 20237] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.312487 2026] [security2:error] [pid 20162:tid 20316] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSVgAAAaY"]
[Thu Sep 17 15:40:25.343736 2026] [security2:error] [pid 20162:tid 20410] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSWAAAAgQ"]
[Thu Sep 17 15:40:25.350599 2026] [security2:error] [pid 20162:tid 20367] [client 34.23.198.186:34428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSWQAAAdk"]
[Thu Sep 17 15:40:25.369933 2026] [security2:error] [pid 20162:tid 20311] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSWgAAAaE"]
[Thu Sep 17 15:40:25.372795 2026] [security2:error] [pid 20162:tid 20302] [client 109.105.210.89:37352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSRAAAAZg"]
[Thu Sep 17 15:40:25.381903 2026] [security2:error] [pid 20162:tid 20234] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/config/aws.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSXQACC0Y"]
[Thu Sep 17 15:40:25.383455 2026] [core:error] [pid 20162:tid 20244] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.383458 2026] [core:error] [pid 20162:tid 20253] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.383468 2026] [core:error] [pid 20162:tid 20244] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.383472 2026] [core:error] [pid 20162:tid 20253] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.387647 2026] [security2:error] [pid 20162:tid 20399] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSXgAAAfk"]
[Thu Sep 17 15:40:25.392268 2026] [security2:error] [pid 20162:tid 20247] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/config/stripe.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSYAAB4FM"]
[Thu Sep 17 15:40:25.393393 2026] [core:error] [pid 20162:tid 20246] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.393402 2026] [core:error] [pid 20162:tid 20246] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.393676 2026] [security2:error] [pid 20162:tid 20250] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/config/mail.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSYgAB4FY"]
[Thu Sep 17 15:40:25.393742 2026] [security2:error] [pid 20162:tid 20191] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/config/config.inc.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSYwAB4Bs"]
[Thu Sep 17 15:40:25.394011 2026] [core:error] [pid 20162:tid 20270] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.394019 2026] [core:error] [pid 20162:tid 20270] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.394458 2026] [security2:error] [pid 20162:tid 20239] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/config/nexmo.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSZQAB4Es"]
[Thu Sep 17 15:40:25.394925 2026] [core:error] [pid 20162:tid 20246] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.394934 2026] [core:error] [pid 20162:tid 20246] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.396081 2026] [security2:error] [pid 20162:tid 20282] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/wp-config.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSaAABlXY"]
[Thu Sep 17 15:40:25.396493 2026] [core:error] [pid 20162:tid 20227] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.396500 2026] [core:error] [pid 20162:tid 20227] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.396577 2026] [core:error] [pid 20162:tid 20260] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.396596 2026] [core:error] [pid 20162:tid 20260] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.398376 2026] [security2:error] [pid 20162:tid 20256] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "journals.languageandsociety.co.il"] [uri "/wp-config.php.bak"] [unique_id "aqxeSa-O_Kk7aqBvaiGSaQABolw"]
[Thu Sep 17 15:40:25.405603 2026] [security2:error] [pid 20162:tid 20281] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "journals.languageandsociety.co.il"] [uri "/wp-config.php.old"] [unique_id "aqxeSa-O_Kk7aqBvaiGSagAB8XU"]
[Thu Sep 17 15:40:25.422455 2026] [security2:error] [pid 20162:tid 20265] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "journals.languageandsociety.co.il"] [uri "/wp-config.php.new"] [unique_id "aqxeSa-O_Kk7aqBvaiGSawAB4WU"]
[Thu Sep 17 15:40:25.424603 2026] [security2:error] [pid 20162:tid 20392] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSbAAAAfI"]
[Thu Sep 17 15:40:25.439102 2026] [security2:error] [pid 20162:tid 20347] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSbQAAAcU"]
[Thu Sep 17 15:40:25.455286 2026] [security2:error] [pid 20162:tid 20408] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSbgAAAgI"]
[Thu Sep 17 15:40:25.488859 2026] [security2:error] [pid 20162:tid 20400] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSbwAAAfo"]
[Thu Sep 17 15:40:25.512142 2026] [security2:error] [pid 20162:tid 20329] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGScQAAAbM"]
[Thu Sep 17 15:40:25.517429 2026] [security2:error] [pid 20162:tid 20266] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/.wp-config.php.swp"] [unique_id "aqxeSa-O_Kk7aqBvaiGScgABy2Y"]
[Thu Sep 17 15:40:25.518264 2026] [security2:error] [pid 20162:tid 20306] [client 34.23.198.186:34440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGScwAAAZw"]
[Thu Sep 17 15:40:25.520407 2026] [core:error] [pid 20162:tid 20276] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.520416 2026] [core:error] [pid 20162:tid 20276] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.520797 2026] [core:error] [pid 20162:tid 20278] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.520811 2026] [core:error] [pid 20162:tid 20278] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.534590 2026] [security2:error] [pid 20162:tid 20394] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSdgAAAfQ"]
[Thu Sep 17 15:40:25.537025 2026] [security2:error] [pid 20162:tid 20257] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/wp-content/mysql.sql"] [unique_id "aqxeSa-O_Kk7aqBvaiGSeAABp10"]
[Thu Sep 17 15:40:25.537395 2026] [security2:error] [pid 20162:tid 20274] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/terraform.tfstate.backup"] [unique_id "aqxeSa-O_Kk7aqBvaiGSfgABp24"]
[Thu Sep 17 15:40:25.537801 2026] [core:error] [pid 20162:tid 20280] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.537812 2026] [core:error] [pid 20162:tid 20280] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.537988 2026] [core:error] [pid 20162:tid 20275] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.537997 2026] [core:error] [pid 20162:tid 20275] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538141 2026] [core:error] [pid 20162:tid 20258] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538148 2026] [core:error] [pid 20162:tid 20258] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538224 2026] [core:error] [pid 20162:tid 20273] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538232 2026] [core:error] [pid 20162:tid 20273] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538400 2026] [core:error] [pid 20162:tid 20286] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538410 2026] [core:error] [pid 20162:tid 20286] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538499 2026] [core:error] [pid 20162:tid 20287] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.538504 2026] [core:error] [pid 20162:tid 20287] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.541913 2026] [core:error] [pid 20162:tid 20268] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.541924 2026] [core:error] [pid 20162:tid 20268] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.544711 2026] [core:error] [pid 20162:tid 20272] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.544723 2026] [core:error] [pid 20162:tid 20272] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.545063 2026] [core:error] [pid 20162:tid 20267] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.545071 2026] [core:error] [pid 20162:tid 20267] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.546618 2026] [core:error] [pid 20162:tid 20269] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.546628 2026] [core:error] [pid 20162:tid 20269] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.553029 2026] [security2:error] [pid 20162:tid 20351] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSgwAAAck"]
[Thu Sep 17 15:40:25.558053 2026] [core:error] [pid 20162:tid 20263] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.558072 2026] [core:error] [pid 20162:tid 20263] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.586372 2026] [security2:error] [pid 20162:tid 20398] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGShQAAAfg"]
[Thu Sep 17 15:40:25.602135 2026] [security2:error] [pid 20162:tid 20404] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGShwAAAf4"]
[Thu Sep 17 15:40:25.631402 2026] [security2:error] [pid 20162:tid 20339] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSigAAAb0"]
[Thu Sep 17 15:40:25.659078 2026] [core:error] [pid 20162:tid 20262] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.659099 2026] [core:error] [pid 20162:tid 20262] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.664384 2026] [core:error] [pid 20162:tid 20166] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.664400 2026] [core:error] [pid 20162:tid 20166] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.664593 2026] [core:error] [pid 20162:tid 20264] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.664603 2026] [core:error] [pid 20162:tid 20264] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.673671 2026] [security2:error] [pid 20162:tid 20395] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSjgAAAfU"]
[Thu Sep 17 15:40:25.679533 2026] [core:error] [pid 20162:tid 20254] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.679552 2026] [core:error] [pid 20162:tid 20254] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.679645 2026] [core:error] [pid 20162:tid 20188] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.679654 2026] [core:error] [pid 20162:tid 20188] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.679975 2026] [core:error] [pid 20162:tid 20288] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.679988 2026] [core:error] [pid 20162:tid 20288] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680058 2026] [core:error] [pid 20162:tid 20261] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680068 2026] [core:error] [pid 20162:tid 20261] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680127 2026] [core:error] [pid 20162:tid 20167] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680133 2026] [core:error] [pid 20162:tid 20167] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680316 2026] [core:error] [pid 20162:tid 20277] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680332 2026] [core:error] [pid 20162:tid 20277] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680440 2026] [core:error] [pid 20162:tid 20291] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680451 2026] [core:error] [pid 20162:tid 20291] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680534 2026] [core:error] [pid 20162:tid 20289] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680541 2026] [core:error] [pid 20162:tid 20289] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680635 2026] [core:error] [pid 20162:tid 20169] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.680645 2026] [core:error] [pid 20162:tid 20169] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.681153 2026] [core:error] [pid 20162:tid 20178] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.681163 2026] [core:error] [pid 20162:tid 20178] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.681501 2026] [core:error] [pid 20162:tid 20283] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.681511 2026] [core:error] [pid 20162:tid 20283] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.682831 2026] [core:error] [pid 20162:tid 20168] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.682843 2026] [core:error] [pid 20162:tid 20168] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.693277 2026] [security2:error] [pid 20162:tid 20332] [client 34.23.198.186:34454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxeSa-O_Kk7aqBvaiGSnAAAAbY"]
[Thu Sep 17 15:40:25.701875 2026] [security2:error] [pid 20162:tid 20303] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSnQAAAZk"]
[Thu Sep 17 15:40:25.708157 2026] [core:error] [pid 20162:tid 20171] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.708171 2026] [core:error] [pid 20162:tid 20171] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.728239 2026] [security2:error] [pid 20162:tid 20379] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSoQAAAeU"]
[Thu Sep 17 15:40:25.792147 2026] [security2:error] [pid 20162:tid 20323] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSogAAAa0"]
[Thu Sep 17 15:40:25.801765 2026] [core:error] [pid 20162:tid 20165] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.801781 2026] [core:error] [pid 20162:tid 20165] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.804816 2026] [core:error] [pid 20162:tid 20174] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.804829 2026] [core:error] [pid 20162:tid 20174] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.805080 2026] [core:error] [pid 20162:tid 20172] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.805090 2026] [core:error] [pid 20162:tid 20172] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.822962 2026] [core:error] [pid 20162:tid 20284] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.822967 2026] [core:error] [pid 20162:tid 20181] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.822971 2026] [core:error] [pid 20162:tid 20175] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.822980 2026] [core:error] [pid 20162:tid 20284] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.822981 2026] [core:error] [pid 20162:tid 20181] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.822987 2026] [core:error] [pid 20162:tid 20175] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823071 2026] [core:error] [pid 20162:tid 20186] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823078 2026] [core:error] [pid 20162:tid 20186] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823234 2026] [core:error] [pid 20162:tid 20183] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823238 2026] [core:error] [pid 20162:tid 20173] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823245 2026] [core:error] [pid 20162:tid 20183] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823246 2026] [core:error] [pid 20162:tid 20173] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823247 2026] [core:error] [pid 20162:tid 20180] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823264 2026] [core:error] [pid 20162:tid 20180] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823335 2026] [core:error] [pid 20162:tid 20185] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823336 2026] [core:error] [pid 20162:tid 20203] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823345 2026] [core:error] [pid 20162:tid 20185] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823346 2026] [core:error] [pid 20162:tid 20203] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823482 2026] [core:error] [pid 20162:tid 20199] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823493 2026] [core:error] [pid 20162:tid 20199] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823571 2026] [core:error] [pid 20162:tid 20187] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.823590 2026] [core:error] [pid 20162:tid 20187] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.826009 2026] [core:error] [pid 20162:tid 20194] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.826020 2026] [core:error] [pid 20162:tid 20194] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.840229 2026] [security2:error] [pid 20162:tid 20419] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGStQAAAg0"]
[Thu Sep 17 15:40:25.849072 2026] [core:error] [pid 20162:tid 20190] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.849086 2026] [core:error] [pid 20162:tid 20190] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.864395 2026] [security2:error] [pid 20162:tid 20325] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGStwAAAa8"]
[Thu Sep 17 15:40:25.864534 2026] [security2:error] [pid 20162:tid 20416] [client 34.23.198.186:34466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/phpinfo.php.old"] [unique_id "aqxeSa-O_Kk7aqBvaiGSuAAAAgo"]
[Thu Sep 17 15:40:25.877872 2026] [security2:error] [pid 20162:tid 20388] [client 109.105.210.87:59036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSowAAAe4"]
[Thu Sep 17 15:40:25.902566 2026] [security2:error] [pid 20162:tid 20386] [client 34.94.56.93:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxeSa-O_Kk7aqBvaiGSuQAAAew"]
[Thu Sep 17 15:40:25.944029 2026] [core:error] [pid 20162:tid 20202] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.944045 2026] [core:error] [pid 20162:tid 20202] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.945951 2026] [core:error] [pid 20162:tid 20195] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.945950 2026] [core:error] [pid 20162:tid 20204] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.945968 2026] [core:error] [pid 20162:tid 20195] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.945968 2026] [core:error] [pid 20162:tid 20204] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.962404 2026] [security2:error] [pid 20162:tid 20189] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/phpinfo.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSygABkRk"]
[Thu Sep 17 15:40:25.962958 2026] [security2:error] [pid 20162:tid 20211] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/info.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSzAABkS8"]
[Thu Sep 17 15:40:25.963818 2026] [security2:error] [pid 20162:tid 20209] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/infos.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSzQABkS0"]
[Thu Sep 17 15:40:25.964000 2026] [core:error] [pid 20162:tid 20196] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964008 2026] [core:error] [pid 20162:tid 20196] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964243 2026] [core:error] [pid 20162:tid 20200] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964250 2026] [core:error] [pid 20162:tid 20200] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964292 2026] [core:error] [pid 20162:tid 20206] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964296 2026] [core:error] [pid 20162:tid 20198] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964301 2026] [core:error] [pid 20162:tid 20207] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964306 2026] [core:error] [pid 20162:tid 20164] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964309 2026] [core:error] [pid 20162:tid 20206] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964311 2026] [core:error] [pid 20162:tid 20198] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964317 2026] [core:error] [pid 20162:tid 20207] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964318 2026] [core:error] [pid 20162:tid 20164] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964376 2026] [core:error] [pid 20162:tid 20176] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964379 2026] [core:error] [pid 20162:tid 20197] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964387 2026] [core:error] [pid 20162:tid 20176] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964390 2026] [core:error] [pid 20162:tid 20192] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964392 2026] [core:error] [pid 20162:tid 20197] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.964398 2026] [core:error] [pid 20162:tid 20192] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:25.986438 2026] [security2:error] [pid 20162:tid 20212] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/php_info.php"] [unique_id "aqxeSa-O_Kk7aqBvaiGSzgABrDA"]
[Thu Sep 17 15:40:26.036904 2026] [security2:error] [pid 20162:tid 20310] [client 34.23.198.186:34478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/phpinfo.php~"] [unique_id "aqxeSq-O_Kk7aqBvaiGSzwAAAaA"]
[Thu Sep 17 15:40:26.042328 2026] [core:error] [pid 20162:tid 20349] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.042345 2026] [core:error] [pid 20162:tid 20349] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.082206 2026] [security2:error] [pid 20162:tid 20193] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/php.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS0gACDh0"]
[Thu Sep 17 15:40:26.085296 2026] [security2:error] [pid 20162:tid 20215] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/infophp.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS1AABkDM"]
[Thu Sep 17 15:40:26.085314 2026] [security2:error] [pid 20162:tid 20214] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/php-info.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS0wABkDI"]
[Thu Sep 17 15:40:26.099634 2026] [security2:error] [pid 20162:tid 20217] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS1wAB8zU"]
[Thu Sep 17 15:40:26.100442 2026] [security2:error] [pid 20162:tid 20205] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/admin_phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS2QAB8yk"]
[Thu Sep 17 15:40:26.100454 2026] [security2:error] [pid 20162:tid 20208] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/admin/phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS2AAB8yw"]
[Thu Sep 17 15:40:26.100500 2026] [security2:error] [pid 20162:tid 20170] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/api/phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS2gAB8wY"]
[Thu Sep 17 15:40:26.100528 2026] [security2:error] [pid 20162:tid 20210] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/public/phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS2wAB8y4"]
[Thu Sep 17 15:40:26.102046 2026] [core:error] [pid 20162:tid 20216] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102060 2026] [core:error] [pid 20162:tid 20216] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102465 2026] [core:error] [pid 20162:tid 20231] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102472 2026] [core:error] [pid 20162:tid 20231] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102600 2026] [core:error] [pid 20162:tid 20184] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102606 2026] [core:error] [pid 20162:tid 20184] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102789 2026] [core:error] [pid 20162:tid 20229] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102791 2026] [core:error] [pid 20162:tid 20223] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102803 2026] [core:error] [pid 20162:tid 20229] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102808 2026] [core:error] [pid 20162:tid 20223] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102828 2026] [core:error] [pid 20162:tid 20220] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.102838 2026] [core:error] [pid 20162:tid 20220] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.138743 2026] [core:error] [pid 20162:tid 20219] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.138759 2026] [core:error] [pid 20162:tid 20219] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.224894 2026] [core:error] [pid 20162:tid 20226] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.224914 2026] [core:error] [pid 20162:tid 20226] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.225001 2026] [security2:error] [pid 20162:tid 20224] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/database.sql"] [unique_id "aqxeSq-O_Kk7aqBvaiGS6gAB1Tw"]
[Thu Sep 17 15:40:26.225761 2026] [core:error] [pid 20162:tid 20213] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.225774 2026] [core:error] [pid 20162:tid 20213] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.228642 2026] [security2:error] [pid 20162:tid 20327] [client 34.23.198.186:34484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/info.php.bak"] [unique_id "aqxeSq-O_Kk7aqBvaiGS7AAAAbE"]
[Thu Sep 17 15:40:26.239376 2026] [core:error] [pid 20162:tid 20235] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.239390 2026] [core:error] [pid 20162:tid 20235] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244149 2026] [core:error] [pid 20162:tid 20241] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244161 2026] [core:error] [pid 20162:tid 20228] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244167 2026] [core:error] [pid 20162:tid 20241] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244170 2026] [core:error] [pid 20162:tid 20228] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244173 2026] [core:error] [pid 20162:tid 20232] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244181 2026] [core:error] [pid 20162:tid 20232] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244526 2026] [core:error] [pid 20162:tid 20236] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244534 2026] [core:error] [pid 20162:tid 20236] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244535 2026] [core:error] [pid 20162:tid 20240] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244545 2026] [core:error] [pid 20162:tid 20240] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244695 2026] [core:error] [pid 20162:tid 20233] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244698 2026] [core:error] [pid 20162:tid 20179] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244706 2026] [core:error] [pid 20162:tid 20233] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244712 2026] [core:error] [pid 20162:tid 20179] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244825 2026] [core:error] [pid 20162:tid 20252] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244832 2026] [core:error] [pid 20162:tid 20252] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244920 2026] [core:error] [pid 20162:tid 20245] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.244931 2026] [core:error] [pid 20162:tid 20245] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.245388 2026] [core:error] [pid 20162:tid 20242] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.245394 2026] [core:error] [pid 20162:tid 20242] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.245930 2026] [core:error] [pid 20162:tid 20238] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.245940 2026] [core:error] [pid 20162:tid 20238] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.291378 2026] [core:error] [pid 20162:tid 20225] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.291391 2026] [core:error] [pid 20162:tid 20225] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.365876 2026] [security2:error] [pid 20162:tid 20248] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "journals.languageandsociety.co.il"] [uri "/wp-config.php.orig"] [unique_id "aqxeSq-O_Kk7aqBvaiGS_QAB4FQ"]
[Thu Sep 17 15:40:26.367359 2026] [core:error] [pid 20162:tid 20259] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.367363 2026] [core:error] [pid 20162:tid 20243] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.367371 2026] [core:error] [pid 20162:tid 20259] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.367380 2026] [core:error] [pid 20162:tid 20243] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.379111 2026] [core:error] [pid 20162:tid 20271] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.379120 2026] [core:error] [pid 20162:tid 20271] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.388668 2026] [security2:error] [pid 20162:tid 20221] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/configuration.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGTAwAB6Dk"]
[Thu Sep 17 15:40:26.388799 2026] [security2:error] [pid 20162:tid 20255] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/aws-credentials.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGTCAAB6Fs"]
[Thu Sep 17 15:40:26.390032 2026] [core:error] [pid 20162:tid 20237] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390043 2026] [core:error] [pid 20162:tid 20237] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390325 2026] [core:error] [pid 20162:tid 20191] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390326 2026] [core:error] [pid 20162:tid 20253] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390333 2026] [core:error] [pid 20162:tid 20191] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390336 2026] [core:error] [pid 20162:tid 20253] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390369 2026] [core:error] [pid 20162:tid 20234] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390377 2026] [core:error] [pid 20162:tid 20234] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390590 2026] [core:error] [pid 20162:tid 20244] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390601 2026] [core:error] [pid 20162:tid 20244] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390626 2026] [core:error] [pid 20162:tid 20279] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390635 2026] [core:error] [pid 20162:tid 20279] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390704 2026] [core:error] [pid 20162:tid 20247] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390713 2026] [core:error] [pid 20162:tid 20247] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390883 2026] [core:error] [pid 20162:tid 20270] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390889 2026] [core:error] [pid 20162:tid 20270] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390962 2026] [core:error] [pid 20162:tid 20250] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.390972 2026] [core:error] [pid 20162:tid 20250] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.402310 2026] [security2:error] [pid 20162:tid 20367] [client 34.23.198.186:34486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/phpinfo.php.save"] [unique_id "aqxeSq-O_Kk7aqBvaiGTDAAAAdk"]
[Thu Sep 17 15:40:26.415105 2026] [core:error] [pid 20162:tid 20385] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.415115 2026] [core:error] [pid 20162:tid 20385] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.431257 2026] [core:error] [pid 20162:tid 20239] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.431269 2026] [core:error] [pid 20162:tid 20239] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.462169 2026] [security2:error] [pid 20162:tid 20302] [client 37.76.195.21:50664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGS-wABmFc"]
[Thu Sep 17 15:40:26.521111 2026] [core:error] [pid 20162:tid 20282] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.521126 2026] [core:error] [pid 20162:tid 20282] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.523218 2026] [core:error] [pid 20162:tid 20227] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.523231 2026] [core:error] [pid 20162:tid 20227] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.523289 2026] [core:error] [pid 20162:tid 20260] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.523297 2026] [core:error] [pid 20162:tid 20260] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.525200 2026] [security2:error] [pid 20162:tid 20256] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "journals.languageandsociety.co.il"] [uri "/env/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTFAABy1w"]
[Thu Sep 17 15:40:26.529852 2026] [security2:error] [pid 20162:tid 20281] [remote 34.62.116.145:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.116.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journals.languageandsociety.co.il"] [uri "/shadow-bot.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGTFQABnHU"]
[Thu Sep 17 15:40:26.530946 2026] [core:error] [pid 20162:tid 20265] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.530956 2026] [core:error] [pid 20162:tid 20265] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.534020 2026] [core:error] [pid 20162:tid 20266] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.534030 2026] [core:error] [pid 20162:tid 20266] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.534262 2026] [core:error] [pid 20162:tid 20276] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.534271 2026] [core:error] [pid 20162:tid 20276] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.534282 2026] [core:error] [pid 20162:tid 20278] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.534290 2026] [core:error] [pid 20162:tid 20278] [remote 34.62.116.145:55084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:26.591568 2026] [security2:error] [pid 20162:tid 20390] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTHAAAAfA"]
[Thu Sep 17 15:40:26.595556 2026] [security2:error] [pid 20162:tid 20317] [client 34.23.198.186:34502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGTHgAAAac"]
[Thu Sep 17 15:40:26.621984 2026] [security2:error] [pid 20162:tid 20324] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTHwAAAa4"]
[Thu Sep 17 15:40:26.664282 2026] [security2:error] [pid 20162:tid 20350] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTIAAAAcg"]
[Thu Sep 17 15:40:26.685070 2026] [security2:error] [pid 20162:tid 20297] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTIwAAAZM"]
[Thu Sep 17 15:40:26.707377 2026] [security2:error] [pid 20162:tid 20339] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTJAAAAb0"]
[Thu Sep 17 15:40:26.732415 2026] [security2:error] [pid 20162:tid 20395] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTJwAAAfU"]
[Thu Sep 17 15:40:26.754223 2026] [security2:error] [pid 20162:tid 20296] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTKQAAAZI"]
[Thu Sep 17 15:40:26.774835 2026] [security2:error] [pid 20162:tid 20359] [client 34.23.198.186:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGTKwAAAdE"]
[Thu Sep 17 15:40:26.788740 2026] [security2:error] [pid 20162:tid 20303] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTLAAAAZk"]
[Thu Sep 17 15:40:26.826004 2026] [security2:error] [pid 20162:tid 20376] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTLQAAAeI"]
[Thu Sep 17 15:40:26.856677 2026] [security2:error] [pid 20162:tid 20335] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTLgAAAbk"]
[Thu Sep 17 15:40:26.903635 2026] [security2:error] [pid 20162:tid 20352] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTMAAAAco"]
[Thu Sep 17 15:40:26.942210 2026] [security2:error] [pid 20162:tid 20364] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTMQAAAdY"]
[Thu Sep 17 15:40:26.995320 2026] [security2:error] [pid 20162:tid 20377] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxeSq-O_Kk7aqBvaiGTMwAAAeM"]
[Thu Sep 17 15:40:26.995649 2026] [security2:error] [pid 20162:tid 20403] [client 34.23.198.186:53452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGTNAAAAf0"]
[Thu Sep 17 15:40:27.042704 2026] [security2:error] [pid 20162:tid 20405] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTNQAAAf8"]
[Thu Sep 17 15:40:27.080341 2026] [security2:error] [pid 20162:tid 20368] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTNgAAAdo"]
[Thu Sep 17 15:40:27.122921 2026] [security2:error] [pid 20162:tid 20416] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTOgAAAgo"]
[Thu Sep 17 15:40:27.170176 2026] [security2:error] [pid 20162:tid 20388] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTPAAAAe4"]
[Thu Sep 17 15:40:27.172691 2026] [security2:error] [pid 20162:tid 20325] [client 34.23.198.186:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxeS6-O_Kk7aqBvaiGTPgAAAa8"]
[Thu Sep 17 15:40:27.197982 2026] [security2:error] [pid 20162:tid 20337] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTPwAAAbs"]
[Thu Sep 17 15:40:27.238009 2026] [security2:error] [pid 20162:tid 20355] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTQgAAAc0"]
[Thu Sep 17 15:40:27.260110 2026] [security2:error] [pid 20162:tid 20348] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTRAAAAcY"]
[Thu Sep 17 15:40:27.301639 2026] [security2:error] [pid 20162:tid 20340] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTRgAAAb4"]
[Thu Sep 17 15:40:27.342387 2026] [security2:error] [pid 20162:tid 20322] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTRwAAAaw"]
[Thu Sep 17 15:40:27.353677 2026] [security2:error] [pid 20162:tid 20314] [client 34.23.198.186:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxeS6-O_Kk7aqBvaiGTSAAAAaQ"]
[Thu Sep 17 15:40:27.369992 2026] [security2:error] [pid 20162:tid 20349] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTSQAAAcc"]
[Thu Sep 17 15:40:27.397567 2026] [security2:error] [pid 20162:tid 20309] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTSgAAAZ8"]
[Thu Sep 17 15:40:27.420510 2026] [security2:error] [pid 20162:tid 20294] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTSwAAAZA"]
[Thu Sep 17 15:40:27.476569 2026] [security2:error] [pid 20162:tid 20304] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTTAAAAZo"]
[Thu Sep 17 15:40:27.496777 2026] [security2:error] [pid 20162:tid 20333] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTTQAAAbc"]
[Thu Sep 17 15:40:27.527763 2026] [security2:error] [pid 20162:tid 20316] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTTgAAAaY"]
[Thu Sep 17 15:40:27.547823 2026] [security2:error] [pid 20162:tid 20418] [client 34.23.198.186:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/www/phpinfo.php"] [unique_id "aqxeS6-O_Kk7aqBvaiGTUAAAAgw"]
[Thu Sep 17 15:40:27.552516 2026] [security2:error] [pid 20162:tid 20307] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTUQAAAZ0"]
[Thu Sep 17 15:40:27.586614 2026] [security2:error] [pid 20162:tid 20312] [client 4.240.114.86:60761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxeSq-O_Kk7aqBvaiGTLwAAAaI"], referer: binance.com
[Thu Sep 17 15:40:27.636214 2026] [security2:error] [pid 20162:tid 20399] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTVgAAAfk"]
[Thu Sep 17 15:40:27.666123 2026] [security2:error] [pid 20162:tid 20299] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTVwAAAZU"]
[Thu Sep 17 15:40:27.685375 2026] [security2:error] [pid 20162:tid 20393] [client 109.105.210.90:17310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeS6-O_Kk7aqBvaiGTTwAAAfM"]
[Thu Sep 17 15:40:27.696539 2026] [security2:error] [pid 20162:tid 20385] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTWgAAAes"]
[Thu Sep 17 15:40:27.727135 2026] [security2:error] [pid 20162:tid 20381] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTXQAAAec"]
[Thu Sep 17 15:40:27.727455 2026] [security2:error] [pid 20162:tid 20382] [client 34.23.198.186:53482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxeS6-O_Kk7aqBvaiGTXgAAAeg"]
[Thu Sep 17 15:40:27.755952 2026] [security2:error] [pid 20162:tid 20305] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTXwAAAZs"]
[Thu Sep 17 15:40:27.780869 2026] [security2:error] [pid 20162:tid 20330] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTYAAAAbQ"]
[Thu Sep 17 15:40:27.822559 2026] [security2:error] [pid 20162:tid 20409] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTYQAAAgM"]
[Thu Sep 17 15:40:27.847396 2026] [security2:error] [pid 20162:tid 20329] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTYwAAAbM"]
[Thu Sep 17 15:40:27.880339 2026] [security2:error] [pid 20162:tid 20298] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTZAAAAZQ"]
[Thu Sep 17 15:40:27.912139 2026] [security2:error] [pid 20162:tid 20324] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTZQAAAa4"]
[Thu Sep 17 15:40:27.945399 2026] [security2:error] [pid 20162:tid 20351] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTZgAAAck"]
[Thu Sep 17 15:40:27.946768 2026] [security2:error] [pid 20162:tid 20353] [client 34.23.198.186:53498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxeS6-O_Kk7aqBvaiGTZwAAAcs"]
[Thu Sep 17 15:40:27.976706 2026] [security2:error] [pid 20162:tid 20350] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxeS6-O_Kk7aqBvaiGTaAAAAcg"]
[Thu Sep 17 15:40:28.003157 2026] [security2:error] [pid 20162:tid 20404] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTaQAAAf4"]
[Thu Sep 17 15:40:28.030887 2026] [security2:error] [pid 20162:tid 20395] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTagAAAfU"]
[Thu Sep 17 15:40:28.062668 2026] [security2:error] [pid 20162:tid 20296] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTawAAAZI"]
[Thu Sep 17 15:40:28.100084 2026] [security2:error] [pid 20162:tid 20303] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTbQAAAZk"]
[Thu Sep 17 15:40:28.129233 2026] [security2:error] [pid 20162:tid 20338] [client 34.23.198.186:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/site/phpinfo.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTcAAAAbw"]
[Thu Sep 17 15:40:28.150829 2026] [security2:error] [pid 20162:tid 20335] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTcQAAAbk"]
[Thu Sep 17 15:40:28.184526 2026] [security2:error] [pid 20162:tid 20318] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTcwAAAag"]
[Thu Sep 17 15:40:28.227514 2026] [security2:error] [pid 20162:tid 20403] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTdAAAAf0"]
[Thu Sep 17 15:40:28.250651 2026] [security2:error] [pid 20162:tid 20344] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTdQAAAcI"]
[Thu Sep 17 15:40:28.273050 2026] [security2:error] [pid 20162:tid 20389] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTdgAAAe8"]
[Thu Sep 17 15:40:28.280835 2026] [security2:error] [pid 20162:tid 20419] [client 169.58.197.253:60965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTdwAAAg0"], referer: binance.com
[Thu Sep 17 15:40:28.295369 2026] [security2:error] [pid 20162:tid 20396] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTeQAAAfY"]
[Thu Sep 17 15:40:28.313434 2026] [security2:error] [pid 20162:tid 20405] [client 34.23.198.186:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTegAAAf8"]
[Thu Sep 17 15:40:28.317028 2026] [security2:error] [pid 20162:tid 20346] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTewAAAcQ"]
[Thu Sep 17 15:40:28.336277 2026] [security2:error] [pid 20162:tid 20416] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTfAAAAgo"]
[Thu Sep 17 15:40:28.358783 2026] [security2:error] [pid 20162:tid 20412] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTfQAAAgY"]
[Thu Sep 17 15:40:28.382824 2026] [security2:error] [pid 20162:tid 20325] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTfgAAAa8"]
[Thu Sep 17 15:40:28.424628 2026] [security2:error] [pid 20162:tid 20345] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTfwAAAcM"]
[Thu Sep 17 15:40:28.465495 2026] [security2:error] [pid 20162:tid 20348] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTgQAAAcY"]
[Thu Sep 17 15:40:28.503287 2026] [security2:error] [pid 20162:tid 20295] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGThwAAAZE"]
[Thu Sep 17 15:40:28.506936 2026] [security2:error] [pid 20162:tid 20386] [client 34.23.198.186:53538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTiAAAAew"]
[Thu Sep 17 15:40:28.527293 2026] [security2:error] [pid 20162:tid 20313] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTiQAAAaM"]
[Thu Sep 17 15:40:28.560275 2026] [security2:error] [pid 20162:tid 20322] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTigAAAaw"]
[Thu Sep 17 15:40:28.591681 2026] [security2:error] [pid 20162:tid 20349] [client 34.94.56.93:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.premium-cuts.com"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxeTK-O_Kk7aqBvaiGTjAAAAcc"]
[Thu Sep 17 15:40:28.644781 2026] [security2:error] [pid 20162:tid 20420] [client 34.94.56.93:57772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/phpinfo.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTjwAAAg4"]
[Thu Sep 17 15:40:28.690837 2026] [security2:error] [pid 20162:tid 20373] [client 34.23.198.186:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTkQAAAd8"]
[Thu Sep 17 15:40:28.729248 2026] [security2:error] [pid 20162:tid 20360] [client 34.94.56.93:57782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/info.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTkwAAAdI"]
[Thu Sep 17 15:40:28.847354 2026] [security2:error] [pid 20162:tid 20358] [client 34.94.56.93:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/php.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTlgAAAdA"]
[Thu Sep 17 15:40:28.910737 2026] [security2:error] [pid 20162:tid 20413] [client 34.23.198.186:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/core/phpinfo.php"] [unique_id "aqxeTK-O_Kk7aqBvaiGTmAAAAgc"]
[Thu Sep 17 15:40:29.001832 2026] [security2:error] [pid 20162:tid 20362] [client 34.94.56.93:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/i.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTmgAAAdQ"]
[Thu Sep 17 15:40:29.078127 2026] [security2:error] [pid 20162:tid 20307] [client 34.23.198.186:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appalachian-landscapes.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTmwAAAZ0"]
[Thu Sep 17 15:40:29.083528 2026] [security2:error] [pid 20162:tid 20328] [client 34.94.56.93:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/pi.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTnQAAAbI"]
[Thu Sep 17 15:40:29.174127 2026] [security2:error] [pid 20162:tid 20393] [client 34.94.56.93:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/pinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTogAAAfM"]
[Thu Sep 17 15:40:29.249994 2026] [security2:error] [pid 20162:tid 20382] [client 34.94.56.93:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/test.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTpQAAAeg"]
[Thu Sep 17 15:40:29.327126 2026] [security2:error] [pid 20162:tid 20381] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTpgAAAec"]
[Thu Sep 17 15:40:29.351288 2026] [core:error] [pid 20162:tid 20301] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:29.351305 2026] [core:error] [pid 20162:tid 20301] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:29.428875 2026] [security2:error] [pid 20162:tid 20298] [client 34.94.56.93:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/p.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTqgAAAZQ"]
[Thu Sep 17 15:40:29.499591 2026] [security2:error] [pid 20162:tid 20334] [client 34.94.56.93:57864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/debug.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTrAAAAbg"]
[Thu Sep 17 15:40:29.500506 2026] [security2:error] [pid 20162:tid 20406] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTqwAAAgA"]
[Thu Sep 17 15:40:29.580696 2026] [security2:error] [pid 20162:tid 20383] [client 34.94.56.93:57872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTrgAAAek"]
[Thu Sep 17 15:40:29.628390 2026] [security2:error] [pid 20162:tid 20397] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTrQAAAfc"]
[Thu Sep 17 15:40:29.651315 2026] [security2:error] [pid 20162:tid 20351] [client 34.94.56.93:57876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/test/phpinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTsQAAAck"]
[Thu Sep 17 15:40:29.663928 2026] [security2:error] [pid 20162:tid 20394] [client 14.96.156.146:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTsgAAAfQ"]
[Thu Sep 17 15:40:29.664011 2026] [security2:error] [pid 20162:tid 20394] [client 14.96.156.146:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTsgAAAfQ"]
[Thu Sep 17 15:40:29.708027 2026] [security2:error] [pid 20162:tid 20359] [client 34.94.56.93:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTtgAAAdE"]
[Thu Sep 17 15:40:29.741491 2026] [security2:error] [pid 20162:tid 20395] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTtAAAAfU"]
[Thu Sep 17 15:40:29.778833 2026] [security2:error] [pid 20162:tid 20303] [client 34.94.56.93:57892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/old/phpinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTtwAAAZk"]
[Thu Sep 17 15:40:29.867758 2026] [security2:error] [pid 20162:tid 20343] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTuAAAAcE"]
[Thu Sep 17 15:40:29.873768 2026] [security2:error] [pid 20162:tid 20318] [client 34.94.56.93:57902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTugAAAag"]
[Thu Sep 17 15:40:29.973075 2026] [security2:error] [pid 20162:tid 20338] [client 109.105.210.89:37356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTuQAAAbw"]
[Thu Sep 17 15:40:29.979542 2026] [security2:error] [pid 20162:tid 20405] [client 34.94.56.93:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/public/phpinfo.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTvAAAAf8"]
[Thu Sep 17 15:40:29.988689 2026] [security2:error] [pid 20162:tid 20368] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTa-O_Kk7aqBvaiGTuwAAAdo"]
[Thu Sep 17 15:40:30.102429 2026] [security2:error] [pid 20162:tid 20388] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGTvQAAAe4"]
[Thu Sep 17 15:40:30.150522 2026] [core:error] [pid 20162:tid 20384] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:30.150548 2026] [core:error] [pid 20162:tid 20384] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:30.223214 2026] [security2:error] [pid 20162:tid 20386] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGTxQAAAew"]
[Thu Sep 17 15:40:30.228448 2026] [security2:error] [pid 20162:tid 20322] [client 34.94.56.93:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/php-info.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGTxgAAAaw"]
[Thu Sep 17 15:40:30.342368 2026] [security2:error] [pid 20162:tid 20294] [client 34.94.56.93:57940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/phpversion.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGTzQAAAZA"]
[Thu Sep 17 15:40:30.367979 2026] [security2:error] [pid 20162:tid 20349] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGTyAAAAcc"]
[Thu Sep 17 15:40:30.438711 2026] [security2:error] [pid 20162:tid 20360] [client 34.94.56.93:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/_phpinfo.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGTzwAAAdI"]
[Thu Sep 17 15:40:30.493068 2026] [security2:error] [pid 20162:tid 20319] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGTzgAAAak"]
[Thu Sep 17 15:40:30.512720 2026] [security2:error] [pid 20162:tid 20327] [client 34.94.56.93:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/old_phpinfo.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT0AAAAbE"]
[Thu Sep 17 15:40:30.610813 2026] [security2:error] [pid 20162:tid 20341] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT0QAAAb8"]
[Thu Sep 17 15:40:30.622953 2026] [security2:error] [pid 20162:tid 20333] [client 34.94.56.93:57956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/server-info.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT1AAAAbc"]
[Thu Sep 17 15:40:30.723445 2026] [security2:error] [pid 20162:tid 20418] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT2AAAAgw"]
[Thu Sep 17 15:40:30.740685 2026] [security2:error] [pid 20162:tid 20320] [client 34.94.56.93:40964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/server-status.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT2wAAAao"]
[Thu Sep 17 15:40:30.836624 2026] [security2:error] [pid 20162:tid 20364] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT3AAAAdY"]
[Thu Sep 17 15:40:30.862323 2026] [core:error] [pid 20162:tid 20305] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:30.862340 2026] [core:error] [pid 20162:tid 20305] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:30.951164 2026] [security2:error] [pid 20162:tid 20381] [client 34.23.198.186:53558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.appalachian-landscapes.com"] [uri "/index.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT4wAAAec"]
[Thu Sep 17 15:40:30.979231 2026] [security2:error] [pid 20162:tid 20392] [client 169.58.197.251:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxeTq-O_Kk7aqBvaiGT5AAAAfI"], referer: binance.com
[Thu Sep 17 15:40:31.027595 2026] [core:error] [pid 20162:tid 20406] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:31.027611 2026] [core:error] [pid 20162:tid 20406] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:31.126062 2026] [security2:error] [pid 20162:tid 20394] [client 34.94.56.93:41000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxeT6-O_Kk7aqBvaiGT6QAAAfQ"]
[Thu Sep 17 15:40:31.194055 2026] [security2:error] [pid 20162:tid 20404] [client 34.94.56.93:41004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGT8QAAAf4"]
[Thu Sep 17 15:40:31.263987 2026] [security2:error] [pid 20162:tid 20396] [client 34.94.56.93:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGT8wAAAfY"]
[Thu Sep 17 15:40:31.333377 2026] [security2:error] [pid 20162:tid 20293] [client 34.94.56.93:41014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGT9wAAAY8"]
[Thu Sep 17 15:40:31.383489 2026] [security2:error] [pid 20162:tid 20325] [client 34.94.56.93:41022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGT-QAAAa8"]
[Thu Sep 17 15:40:31.458185 2026] [security2:error] [pid 20162:tid 20322] [client 34.94.56.93:41036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGT-gAAAaw"]
[Thu Sep 17 15:40:31.557622 2026] [security2:error] [pid 20162:tid 20335] [client 103.61.184.148:57566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGT_QAAAbk"]
[Thu Sep 17 15:40:31.557731 2026] [security2:error] [pid 20162:tid 20335] [client 103.61.184.148:57566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGT_QAAAbk"]
[Thu Sep 17 15:40:31.567080 2026] [security2:error] [pid 20162:tid 20294] [client 34.94.56.93:41044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxeT6-O_Kk7aqBvaiGT_gAAAZA"]
[Thu Sep 17 15:40:31.634059 2026] [security2:error] [pid 20162:tid 20349] [client 34.94.56.93:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/phpinfo.php.old"] [unique_id "aqxeT6-O_Kk7aqBvaiGUAgAAAcc"]
[Thu Sep 17 15:40:31.699727 2026] [security2:error] [pid 20162:tid 20360] [client 34.94.56.93:41076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/phpinfo.php~"] [unique_id "aqxeT6-O_Kk7aqBvaiGUBwAAAdI"]
[Thu Sep 17 15:40:31.741609 2026] [security2:error] [pid 20162:tid 20415] [client 34.94.56.93:41078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/info.php.bak"] [unique_id "aqxeT6-O_Kk7aqBvaiGUCQAAAgk"]
[Thu Sep 17 15:40:31.825305 2026] [security2:error] [pid 20162:tid 20320] [client 34.94.56.93:41080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/phpinfo.php.save"] [unique_id "aqxeT6-O_Kk7aqBvaiGUCwAAAao"]
[Thu Sep 17 15:40:31.906261 2026] [security2:error] [pid 20162:tid 20321] [client 177.44.133.72:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGUDAAAAas"]
[Thu Sep 17 15:40:31.906421 2026] [security2:error] [pid 20162:tid 20321] [client 177.44.133.72:52016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGUDAAAAas"]
[Thu Sep 17 15:40:31.935095 2026] [security2:error] [pid 20162:tid 20410] [client 34.94.56.93:41084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxeT6-O_Kk7aqBvaiGUDQAAAgQ"]
[Thu Sep 17 15:40:32.015514 2026] [security2:error] [pid 20162:tid 20382] [client 34.94.56.93:41092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUEAAAAeg"]
[Thu Sep 17 15:40:32.128385 2026] [security2:error] [pid 20162:tid 20365] [client 34.94.56.93:41096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUFAAAAdc"]
[Thu Sep 17 15:40:32.177416 2026] [security2:error] [pid 20162:tid 20367] [client 34.94.56.93:41110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUGwAAAdk"]
[Thu Sep 17 15:40:32.240034 2026] [security2:error] [pid 20162:tid 20374] [client 34.94.56.93:41122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUHQAAAeA"]
[Thu Sep 17 15:40:32.260764 2026] [security2:error] [pid 20162:tid 20302] [client 109.105.210.88:57474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUFwAAAZg"]
[Thu Sep 17 15:40:32.345299 2026] [security2:error] [pid 20162:tid 20399] [client 34.94.56.93:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/www/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUIAAAAfk"]
[Thu Sep 17 15:40:32.420690 2026] [security2:error] [pid 20162:tid 20324] [client 34.94.56.93:41140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUIgAAAa4"]
[Thu Sep 17 15:40:32.528320 2026] [security2:error] [pid 20162:tid 20339] [client 34.94.56.93:41146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUJQAAAb0"]
[Thu Sep 17 15:40:32.583100 2026] [security2:error] [pid 20162:tid 20404] [client 34.94.56.93:41162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/site/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUJwAAAf4"]
[Thu Sep 17 15:40:32.691956 2026] [security2:error] [pid 20162:tid 20377] [client 34.94.56.93:41166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGULAAAAeM"]
[Thu Sep 17 15:40:32.755338 2026] [security2:error] [pid 20162:tid 20405] [client 34.94.56.93:41182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGULwAAAf8"]
[Thu Sep 17 15:40:32.870087 2026] [security2:error] [pid 20162:tid 20359] [client 34.94.56.93:41196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUMwAAAdE"]
[Thu Sep 17 15:40:32.940133 2026] [security2:error] [pid 20162:tid 20409] [client 34.94.56.93:41204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/core/phpinfo.php"] [unique_id "aqxeUK-O_Kk7aqBvaiGUNQAAAgM"]
[Thu Sep 17 15:40:33.026776 2026] [security2:error] [pid 20162:tid 20342] [client 34.94.56.93:41210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.56.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.premium-cuts.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxeUa-O_Kk7aqBvaiGUNgAAAcA"]
[Thu Sep 17 15:40:33.598908 2026] [core:error] [pid 20162:tid 20379] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:33.598975 2026] [core:error] [pid 20162:tid 20379] [client 34.94.56.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:33.853491 2026] [security2:error] [pid 20162:tid 20367] [client 109.105.210.89:28156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeUa-O_Kk7aqBvaiGUXAAAAdk"]
[Thu Sep 17 15:40:33.974351 2026] [security2:error] [pid 20162:tid 20320] [client 143.105.152.240:51490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeUa-O_Kk7aqBvaiGUYgAAAao"]
[Thu Sep 17 15:40:33.977329 2026] [security2:error] [pid 20162:tid 20320] [client 143.105.152.240:51490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeUa-O_Kk7aqBvaiGUYgAAAao"]
[Thu Sep 17 15:40:34.880192 2026] [security2:error] [pid 20162:tid 20405] [client 169.58.197.253:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxeUq-O_Kk7aqBvaiGUcQAAAf8"], referer: binance.com
[Thu Sep 17 15:40:34.948196 2026] [security2:error] [pid 20162:tid 20372] [client 74.7.230.50:34424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.alkaral.com"] [uri "/robots.txt"] [unique_id "aqxeUq-O_Kk7aqBvaiGUcgAB3is"]
[Thu Sep 17 15:40:35.109471 2026] [security2:error] [pid 20162:tid 20389] [client 79.116.89.151:56654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeU6-O_Kk7aqBvaiGUdgAAAe8"]
[Thu Sep 17 15:40:35.109612 2026] [security2:error] [pid 20162:tid 20389] [client 79.116.89.151:56654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeU6-O_Kk7aqBvaiGUdgAAAe8"]
[Thu Sep 17 15:40:35.798375 2026] [security2:error] [pid 20162:tid 20420] [client 109.105.210.89:28168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeU6-O_Kk7aqBvaiGUiQAAAg4"]
[Thu Sep 17 15:40:35.982674 2026] [core:error] [pid 20162:tid 20217] [remote 74.7.228.50:47200] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:35.982690 2026] [core:error] [pid 20162:tid 20217] [remote 74.7.228.50:47200] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:40:35.982830 2026] [security2:error] [pid 20162:tid 20415] [client 74.7.228.50:47200] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "jood.24eastyard.com"] [uri "/index.php/index.php/index.php/index.php/index.php/index.php/index.php/index.php/index.php/index.php/robots.txt"] [unique_id "aqxeU6-O_Kk7aqBvaiGUjQACCTU"]
[Thu Sep 17 15:40:36.992526 2026] [security2:error] [pid 20162:tid 20302] [client 109.105.210.89:28188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeVK-O_Kk7aqBvaiGUogAAAZg"]
[Thu Sep 17 15:40:37.117602 2026] [security2:error] [pid 20162:tid 20397] [client 192.178.6.3:47940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxeVa-O_Kk7aqBvaiGUrAAAAfc"]
[Thu Sep 17 15:40:38.016367 2026] [security2:error] [pid 20162:tid 20386] [client 169.58.197.251:63662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxeVq-O_Kk7aqBvaiGUvAAAAew"], referer: binance.com
[Thu Sep 17 15:40:38.649656 2026] [security2:error] [pid 20162:tid 20369] [client 136.158.61.34:32314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeVq-O_Kk7aqBvaiGUzgAAAds"]
[Thu Sep 17 15:40:38.649756 2026] [security2:error] [pid 20162:tid 20369] [client 136.158.61.34:32314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeVq-O_Kk7aqBvaiGUzgAAAds"]
[Thu Sep 17 15:40:39.595410 2026] [security2:error] [pid 20162:tid 20302] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxeV6-O_Kk7aqBvaiGU4QAAAZg"]
[Thu Sep 17 15:40:39.648333 2026] [security2:error] [pid 20162:tid 20329] [client 109.105.210.90:28612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeV6-O_Kk7aqBvaiGU4wAAAbM"]
[Thu Sep 17 15:40:39.661894 2026] [security2:error] [pid 20162:tid 20406] [client 45.201.135.53:54936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeV6-O_Kk7aqBvaiGU5AACAFE"]
[Thu Sep 17 15:40:39.967109 2026] [authz_core:error] [pid 20162:tid 20380] [client 4.240.114.86:50147] AH01630: client denied by server configuration: /home1/jwdnycco/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:40:40.202247 2026] [security2:error] [pid 20162:tid 20351] [client 109.105.210.88:49912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeWK-O_Kk7aqBvaiGU9QAAAck"]
[Thu Sep 17 15:40:40.237358 2026] [security2:error] [pid 20162:tid 20372] [client 14.96.156.146:64806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeWK-O_Kk7aqBvaiGU9wAAAd4"]
[Thu Sep 17 15:40:40.237469 2026] [security2:error] [pid 20162:tid 20372] [client 14.96.156.146:64806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeWK-O_Kk7aqBvaiGU9wAAAd4"]
[Thu Sep 17 15:40:42.319795 2026] [security2:error] [pid 20162:tid 20345] [client 103.61.184.148:53672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeWq-O_Kk7aqBvaiGVJAAAAcM"]
[Thu Sep 17 15:40:42.319913 2026] [security2:error] [pid 20162:tid 20345] [client 103.61.184.148:53672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeWq-O_Kk7aqBvaiGVJAAAAcM"]
[Thu Sep 17 15:40:42.513923 2026] [security2:error] [pid 20162:tid 20411] [client 177.44.133.72:52679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeWq-O_Kk7aqBvaiGVKAAAAgU"]
[Thu Sep 17 15:40:42.514000 2026] [security2:error] [pid 20162:tid 20411] [client 177.44.133.72:52679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeWq-O_Kk7aqBvaiGVKAAAAgU"]
[Thu Sep 17 15:40:42.675696 2026] [security2:error] [pid 20162:tid 20296] [client 169.58.197.253:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxeWq-O_Kk7aqBvaiGVLAAAAZI"], referer: binance.com
[Thu Sep 17 15:40:43.390054 2026] [security2:error] [pid 20162:tid 20386] [client 109.105.210.89:23592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeW6-O_Kk7aqBvaiGVOgAAAew"]
[Thu Sep 17 15:40:44.589894 2026] [security2:error] [pid 20162:tid 20400] [client 143.105.152.240:28459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeXK-O_Kk7aqBvaiGVUQAAAfo"]
[Thu Sep 17 15:40:44.600854 2026] [security2:error] [pid 20162:tid 20400] [client 143.105.152.240:28459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeXK-O_Kk7aqBvaiGVUQAAAfo"]
[Thu Sep 17 15:40:45.178447 2026] [security2:error] [pid 20162:tid 20305] [client 109.105.210.89:23608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeXa-O_Kk7aqBvaiGVXAAAAZs"]
[Thu Sep 17 15:40:45.671206 2026] [security2:error] [pid 20162:tid 20367] [client 109.105.210.90:28222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeXa-O_Kk7aqBvaiGVYAAAAdk"]
[Thu Sep 17 15:40:45.704034 2026] [security2:error] [pid 20162:tid 20311] [client 79.116.89.151:57276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeXa-O_Kk7aqBvaiGVZgAAAaE"]
[Thu Sep 17 15:40:45.704129 2026] [security2:error] [pid 20162:tid 20311] [client 79.116.89.151:57276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeXa-O_Kk7aqBvaiGVZgAAAaE"]
[Thu Sep 17 15:40:46.097657 2026] [security2:error] [pid 20162:tid 20348] [client 109.105.210.90:28234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeXa-O_Kk7aqBvaiGVZwAAAcY"]
[Thu Sep 17 15:40:47.266755 2026] [security2:error] [pid 20162:tid 20341] [client 169.58.197.251:64422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxeX6-O_Kk7aqBvaiGVggAAAb8"], referer: binance.com
[Thu Sep 17 15:40:47.822346 2026] [security2:error] [pid 20162:tid 20333] [client 109.105.210.87:30856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeX6-O_Kk7aqBvaiGViAAAAbc"]
[Thu Sep 17 15:40:48.360634 2026] [access_compat:error] [pid 20162:tid 20365] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/tukoni-forest-keepers
[Thu Sep 17 15:40:48.499273 2026] [security2:error] [pid 20162:tid 20366] [client 3.82.141.143:18576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.patricelthomas.com"] [uri "/.env"] [unique_id "aqxeYK-O_Kk7aqBvaiGVlAAAAdg"]
[Thu Sep 17 15:40:48.511985 2026] [security2:error] [pid 20162:tid 20346] [client 3.82.141.143:18642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.patricelthomas.com"] [uri "/.env.backup"] [unique_id "aqxeYK-O_Kk7aqBvaiGVoQAAAcQ"]
[Thu Sep 17 15:40:48.512806 2026] [security2:error] [pid 20162:tid 20296] [client 3.82.141.143:18874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.patricelthomas.com"] [uri "/wp-config.php.bak"] [unique_id "aqxeYK-O_Kk7aqBvaiGVpAAAAZI"]
[Thu Sep 17 15:40:48.520694 2026] [security2:error] [pid 20162:tid 20305] [client 3.82.141.143:18602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.patricelthomas.com"] [uri "/.env.bak"] [unique_id "aqxeYK-O_Kk7aqBvaiGVqwAAAZs"]
[Thu Sep 17 15:40:48.524060 2026] [security2:error] [pid 20162:tid 20314] [client 3.82.141.143:18848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.patricelthomas.com"] [uri "/wp-config.php.old"] [unique_id "aqxeYK-O_Kk7aqBvaiGVtAAAAaQ"]
[Thu Sep 17 15:40:48.535336 2026] [security2:error] [pid 20162:tid 20322] [client 3.82.141.143:18906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.patricelthomas.com"] [uri "/wp-config.php.save"] [unique_id "aqxeYK-O_Kk7aqBvaiGVxQAAAaw"]
[Thu Sep 17 15:40:48.538869 2026] [security2:error] [pid 20162:tid 20358] [client 3.82.141.143:18832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricelthomas.com"] [uri "/wp-config.php"] [unique_id "aqxeYK-O_Kk7aqBvaiGVzAAAAdA"]
[Thu Sep 17 15:40:48.544897 2026] [security2:error] [pid 20162:tid 20406] [client 3.82.141.143:18922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.patricelthomas.com"] [uri "/wp-config.php~"] [unique_id "aqxeYK-O_Kk7aqBvaiGV4AAAAgA"]
[Thu Sep 17 15:40:48.563944 2026] [security2:error] [pid 20162:tid 20377] [client 3.82.141.143:18862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricelthomas.com"] [uri "/config.php"] [unique_id "aqxeYK-O_Kk7aqBvaiGV3QAAAeM"]
[Thu Sep 17 15:40:48.565785 2026] [security2:error] [pid 20162:tid 20298] [client 3.82.141.143:18570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.patricelthomas.com"] [uri "/.env.old"] [unique_id "aqxeYK-O_Kk7aqBvaiGV3wAAAZQ"]
[Thu Sep 17 15:40:48.566748 2026] [security2:error] [pid 20162:tid 20378] [client 3.82.141.143:18666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "autodiscover.patricelthomas.com"] [uri "/web.config"] [unique_id "aqxeYK-O_Kk7aqBvaiGV3gAAAeQ"]
[Thu Sep 17 15:40:48.733399 2026] [security2:error] [pid 20162:tid 20386] [client 216.73.216.134:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.caitlinannemack.com"] [uri "/images/brand.php/sitemap635.xml"] [unique_id "aqxeYK-O_Kk7aqBvaiGWAgAAAew"]
[Thu Sep 17 15:40:49.948769 2026] [security2:error] [pid 20162:tid 20398] [client 185.24.60.235:50518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeYa-O_Kk7aqBvaiGWEAAB-BM"]
[Thu Sep 17 15:40:50.760336 2026] [authz_core:error] [pid 20162:tid 20353] [client 4.240.114.86:55484] AH01630: client denied by server configuration: /home1/jwdnycco/public_html/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:40:50.880080 2026] [security2:error] [pid 20162:tid 20332] [client 14.96.156.146:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeYq-O_Kk7aqBvaiGWJwAAAbY"]
[Thu Sep 17 15:40:50.880198 2026] [security2:error] [pid 20162:tid 20332] [client 14.96.156.146:65455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeYq-O_Kk7aqBvaiGWJwAAAbY"]
[Thu Sep 17 15:40:51.391851 2026] [security2:error] [pid 20162:tid 20311] [client 136.158.61.34:33315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeY6-O_Kk7aqBvaiGWLgAAAaE"]
[Thu Sep 17 15:40:51.392050 2026] [security2:error] [pid 20162:tid 20311] [client 136.158.61.34:33315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeY6-O_Kk7aqBvaiGWLgAAAaE"]
[Thu Sep 17 15:40:51.776887 2026] [security2:error] [pid 20162:tid 20417] [client 109.105.210.87:30868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeY6-O_Kk7aqBvaiGWNgAAAgs"]
[Thu Sep 17 15:40:52.808980 2026] [security2:error] [pid 20162:tid 20304] [client 162.241.226.11:53012] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxeZK-O_Kk7aqBvaiGWTgAAAZo"]
[Thu Sep 17 15:40:52.813294 2026] [security2:error] [pid 20162:tid 20303] [client 223.123.38.98:44188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeZK-O_Kk7aqBvaiGWTAABmSI"]
[Thu Sep 17 15:40:52.872395 2026] [security2:error] [pid 20162:tid 20310] [client 169.58.197.253:62538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxeZK-O_Kk7aqBvaiGWUAAAAaA"], referer: binance.com
[Thu Sep 17 15:40:53.107904 2026] [security2:error] [pid 20162:tid 20357] [client 103.61.184.148:61836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeZa-O_Kk7aqBvaiGWUQAAAc8"]
[Thu Sep 17 15:40:53.108053 2026] [security2:error] [pid 20162:tid 20357] [client 103.61.184.148:61836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeZa-O_Kk7aqBvaiGWUQAAAc8"]
[Thu Sep 17 15:40:53.199031 2026] [security2:error] [pid 20162:tid 20296] [client 177.44.133.72:53349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeZa-O_Kk7aqBvaiGWVgAAAZI"]
[Thu Sep 17 15:40:53.199162 2026] [security2:error] [pid 20162:tid 20296] [client 177.44.133.72:53349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeZa-O_Kk7aqBvaiGWVgAAAZI"]
[Thu Sep 17 15:40:53.876834 2026] [security2:error] [pid 20162:tid 20316] [client 109.105.210.88:55564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeZa-O_Kk7aqBvaiGWXAAAAaY"]
[Thu Sep 17 15:40:54.168368 2026] [security2:error] [pid 20162:tid 20405] [client 216.73.216.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kuriouskitty.net"] [uri "/index.php"] [unique_id "aqxeZq-O_Kk7aqBvaiGWYQAAAf8"]
[Thu Sep 17 15:40:54.259676 2026] [security2:error] [pid 20162:tid 20324] [client 109.105.210.87:56072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeZq-O_Kk7aqBvaiGWZgAAAa4"]
[Thu Sep 17 15:40:55.162031 2026] [security2:error] [pid 20162:tid 20412] [client 143.105.152.240:48532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeZ6-O_Kk7aqBvaiGWeAAAAgY"]
[Thu Sep 17 15:40:55.162131 2026] [security2:error] [pid 20162:tid 20412] [client 143.105.152.240:48532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeZ6-O_Kk7aqBvaiGWeAAAAgY"]
[Thu Sep 17 15:40:55.210756 2026] [security2:error] [pid 20162:tid 20350] [client 57.141.14.56:38330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxeZ6-O_Kk7aqBvaiGWcgAByC4"]
[Thu Sep 17 15:40:56.104930 2026] [security2:error] [pid 20162:tid 20312] [client 131.0.198.227:23444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxeZ6-O_Kk7aqBvaiGWhQABojY"], referer: https://www.sqlerudition.com
[Thu Sep 17 15:40:56.335561 2026] [security2:error] [pid 20162:tid 20400] [client 79.116.89.151:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeaK-O_Kk7aqBvaiGWjQAAAfo"]
[Thu Sep 17 15:40:56.335680 2026] [security2:error] [pid 20162:tid 20400] [client 79.116.89.151:58016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeaK-O_Kk7aqBvaiGWjQAAAfo"]
[Thu Sep 17 15:40:56.919492 2026] [security2:error] [pid 20162:tid 20346] [client 142.93.220.18:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxeaK-O_Kk7aqBvaiGWlwABxEc"], referer: http://www.cowboywithacamera.com/wp/
[Thu Sep 17 15:40:56.944941 2026] [security2:error] [pid 20162:tid 20405] [client 109.105.210.87:56088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeaK-O_Kk7aqBvaiGWlgAAAf8"]
[Thu Sep 17 15:40:57.411401 2026] [security2:error] [pid 20162:tid 20373] [client 109.105.210.89:33348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxeaa-O_Kk7aqBvaiGWpQAAAd8"]
[Thu Sep 17 15:40:57.468365 2026] [security2:error] [pid 20162:tid 20308] [client 2.104.60.34:56481] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "creapoint.com"] [uri "/.env"] [unique_id "aqxeaa-O_Kk7aqBvaiGWqAAAAZ4"]
[Thu Sep 17 15:40:57.869519 2026] [security2:error] [pid 20162:tid 20305] [client 109.105.210.89:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.210.105.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plasticvisual.com"] [uri "/wp-login.php"] [unique_id "aqxeaa-O_Kk7aqBvaiGWsAAAAZs"], referer: https://plasticvisual.tutorialsphere.com/login
[Thu Sep 17 15:40:57.951738 2026] [security2:error] [pid 20162:tid 20369] [client 142.93.220.18:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxeaa-O_Kk7aqBvaiGWsQAB20w"], referer: http://www.cowboywithacamera.com/backup/
[Thu Sep 17 15:40:58.370061 2026] [security2:error] [pid 20162:tid 20294] [client 51.4.104.8:61850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.104.4.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beauty-technic.com"] [uri "/wp-login.php"] [unique_id "aqxeaq-O_Kk7aqBvaiGWuwAAAZA"]
[Thu Sep 17 15:40:58.468023 2026] [security2:error] [pid 20162:tid 20342] [client 142.93.220.18:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxeaq-O_Kk7aqBvaiGWvgABwFE"], referer: http://www.cowboywithacamera.com/new/
[Thu Sep 17 15:40:58.692129 2026] [security2:error] [pid 20162:tid 20404] [client 50.6.53.48:54650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.6.50.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intolovinghomes.com.au"] [uri "/wp-cron.php"] [unique_id "aqxeaq-O_Kk7aqBvaiGWxAAAAf4"]
[Thu Sep 17 15:40:59.257273 2026] [security2:error] [pid 20162:tid 20333] [client 142.93.220.18:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxea6-O_Kk7aqBvaiGW1gABt08"], referer: http://www.cowboywithacamera.com/blog/
[Thu Sep 17 15:40:59.768511 2026] [security2:error] [pid 20162:tid 20383] [client 142.93.220.18:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxea6-O_Kk7aqBvaiGW5gAB6XM"], referer: http://www.cowboywithacamera.com/wordpress/
[Thu Sep 17 15:41:00.014902 2026] [security2:error] [pid 20162:tid 20363] [client 192.241.185.121:35692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxeaq-O_Kk7aqBvaiGWvwAB1Uo"], referer: http://idautovic.com/wordpress/
[Thu Sep 17 15:41:00.231144 2026] [security2:error] [pid 20162:tid 20336] [client 51.4.104.8:64848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.104.4.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beauty-technic.com"] [uri "/xmlrpc.php"] [unique_id "aqxebK-O_Kk7aqBvaiGW-AAAAbo"]
[Thu Sep 17 15:41:00.279281 2026] [security2:error] [pid 20162:tid 20401] [client 142.93.220.18:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxebK-O_Kk7aqBvaiGW9wAB-24"], referer: http://www.cowboywithacamera.com/old/
[Thu Sep 17 15:41:00.455609 2026] [security2:error] [pid 20162:tid 20385] [client 192.241.185.121:35692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxebK-O_Kk7aqBvaiGW9QAB63I"], referer: http://idautovic.com/backup/
[Thu Sep 17 15:41:00.568136 2026] [security2:error] [pid 20162:tid 20305] [client 169.58.197.253:63051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxebK-O_Kk7aqBvaiGXAAAAAZs"], referer: binance.com
[Thu Sep 17 15:41:01.130834 2026] [security2:error] [pid 20162:tid 20297] [client 68.67.113.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amecoegypt.com"] [uri "/index.php"] [unique_id "aqxebK-O_Kk7aqBvaiGW_gAAAZM"]
[Thu Sep 17 15:41:01.147139 2026] [security2:error] [pid 20162:tid 20360] [client 68.67.113.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amecoegypt.com"] [uri "/index.php"] [unique_id "aqxeaq-O_Kk7aqBvaiGWzAAAAdI"]
[Thu Sep 17 15:41:01.395290 2026] [security2:error] [pid 20162:tid 20350] [client 192.241.185.121:35692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxeba-O_Kk7aqBvaiGXDAAByHs"], referer: http://idautovic.com/wp/
[Thu Sep 17 15:41:01.658099 2026] [security2:error] [pid 20162:tid 20326] [client 14.96.156.146:49991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeba-O_Kk7aqBvaiGXGgAAAbA"]
[Thu Sep 17 15:41:01.658186 2026] [security2:error] [pid 20162:tid 20326] [client 14.96.156.146:49991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeba-O_Kk7aqBvaiGXGgAAAbA"]
[Thu Sep 17 15:41:01.741152 2026] [security2:error] [pid 20162:tid 20400] [client 85.204.70.90:38822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bejackson.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxeba-O_Kk7aqBvaiGXHQAAAfo"]
[Thu Sep 17 15:41:01.815817 2026] [security2:error] [pid 20162:tid 20410] [client 192.241.185.121:35692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxeba-O_Kk7aqBvaiGXFwACBHo"], referer: http://idautovic.com/new/
[Thu Sep 17 15:41:02.327274 2026] [security2:error] [pid 20162:tid 20334] [client 85.204.70.90:38832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bejackson.com"] [uri "/xmlrpc.php"] [unique_id "aqxebq-O_Kk7aqBvaiGXLgAAAbg"]
[Thu Sep 17 15:41:02.678133 2026] [security2:error] [pid 20162:tid 20363] [client 192.241.185.121:35692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxebq-O_Kk7aqBvaiGXLwAB1QM"], referer: http://idautovic.com/old/
[Thu Sep 17 15:41:03.842655 2026] [security2:error] [pid 20162:tid 20325] [client 177.44.133.72:54017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeb6-O_Kk7aqBvaiGXQwAAAa8"]
[Thu Sep 17 15:41:03.842787 2026] [security2:error] [pid 20162:tid 20325] [client 177.44.133.72:54017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeb6-O_Kk7aqBvaiGXQwAAAa8"]
[Thu Sep 17 15:41:03.884679 2026] [security2:error] [pid 20162:tid 20415] [client 136.158.61.34:34411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeb6-O_Kk7aqBvaiGXRQAAAgk"]
[Thu Sep 17 15:41:03.884797 2026] [security2:error] [pid 20162:tid 20415] [client 136.158.61.34:34411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeb6-O_Kk7aqBvaiGXRQAAAgk"]
[Thu Sep 17 15:41:03.958259 2026] [security2:error] [pid 20162:tid 20330] [client 103.61.184.148:62581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeb6-O_Kk7aqBvaiGXRgAAAbQ"]
[Thu Sep 17 15:41:03.958406 2026] [security2:error] [pid 20162:tid 20330] [client 103.61.184.148:62581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeb6-O_Kk7aqBvaiGXRgAAAbQ"]
[Thu Sep 17 15:41:04.190320 2026] [fcgid:warn] [pid 20162:tid 20418] (70014)End of file found: [client 167.94.146.60:31300] mod_fcgid: can't get data from http client
[Thu Sep 17 15:41:04.506482 2026] [security2:error] [pid 20162:tid 20368] [client 169.58.197.251:65380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/block-template.php"] [unique_id "aqxecK-O_Kk7aqBvaiGXWAAAAdo"], referer: binance.com
[Thu Sep 17 15:41:04.621865 2026] [security2:error] [pid 20162:tid 20321] [client 34.44.142.114:16288] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1452"] [id "9011111"] [msg "SQUID data collection"] [hostname "jaymadera.com"] [uri "/"] [unique_id "aqxecK-O_Kk7aqBvaiGXXQAAAas"]
[Thu Sep 17 15:41:05.429037 2026] [security2:error] [pid 20162:tid 20339] [client 85.204.70.90:53196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bejackson.com"] [uri "/xmlrpc.php"] [unique_id "aqxeca-O_Kk7aqBvaiGXcQAAAb0"]
[Thu Sep 17 15:41:05.429147 2026] [security2:error] [pid 20162:tid 20339] [client 85.204.70.90:53196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bejackson.com"] [uri "/xmlrpc.php"] [unique_id "aqxeca-O_Kk7aqBvaiGXcQAAAb0"]
[Thu Sep 17 15:41:05.766216 2026] [security2:error] [pid 20162:tid 20397] [client 143.105.152.240:18380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeca-O_Kk7aqBvaiGXfQAAAfc"]
[Thu Sep 17 15:41:05.766384 2026] [security2:error] [pid 20162:tid 20397] [client 143.105.152.240:18380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeca-O_Kk7aqBvaiGXfQAAAfc"]
[Thu Sep 17 15:41:05.780703 2026] [security2:error] [pid 20162:tid 20358] [client 24.89.24.240:54471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeca-O_Kk7aqBvaiGXdQAB0BY"], referer: https://www.google.com/
[Thu Sep 17 15:41:06.155221 2026] [access_compat:error] [pid 20162:tid 20372] [client 208.92.218.66:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/avalon-legends-solitaire-3
[Thu Sep 17 15:41:06.897279 2026] [security2:error] [pid 20162:tid 20410] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxecq-O_Kk7aqBvaiGXlgAAAgQ"]
[Thu Sep 17 15:41:06.936427 2026] [security2:error] [pid 20162:tid 20416] [client 79.116.89.151:58762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxecq-O_Kk7aqBvaiGXnwAAAgo"]
[Thu Sep 17 15:41:06.936525 2026] [security2:error] [pid 20162:tid 20416] [client 79.116.89.151:58762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxecq-O_Kk7aqBvaiGXnwAAAgo"]
[Thu Sep 17 15:41:07.372894 2026] [security2:error] [pid 20162:tid 20371] [client 162.241.226.11:48426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxec6-O_Kk7aqBvaiGXpQAAAd0"]
[Thu Sep 17 15:41:07.543226 2026] [security2:error] [pid 20162:tid 20354] [client 162.241.226.11:48432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "troopkcampcadet.com"] [uri "/index.php"] [unique_id "aqxec6-O_Kk7aqBvaiGXsAAAAcw"]
[Thu Sep 17 15:41:07.677756 2026] [security2:error] [pid 20162:tid 20300] [client 109.105.210.87:21900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/index.php"] [unique_id "aqxec6-O_Kk7aqBvaiGXswAAAZY"]
[Thu Sep 17 15:41:07.838639 2026] [security2:error] [pid 20162:tid 20389] [client 165.232.187.211:62157] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxec6-O_Kk7aqBvaiGXugAAAe8"]
[Thu Sep 17 15:41:07.929677 2026] [security2:error] [pid 20162:tid 20345] [client 109.105.210.88:54534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "aqxec6-O_Kk7aqBvaiGXvAAAAcM"]
[Thu Sep 17 15:41:07.940958 2026] [security2:error] [pid 20162:tid 20330] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/.env"] [unique_id "aqxec6-O_Kk7aqBvaiGXvQAAAbQ"]
[Thu Sep 17 15:41:08.251876 2026] [security2:error] [pid 20162:tid 20317] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxedK-O_Kk7aqBvaiGXwQAAAac"]
[Thu Sep 17 15:41:08.578047 2026] [security2:error] [pid 20162:tid 20412] [client 24.89.24.240:52439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxedK-O_Kk7aqBvaiGXygACBgw"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260607173719&hideanons=1&hidebots=0&limit=100&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:41:08.776330 2026] [security2:error] [pid 20162:tid 20379] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxedK-O_Kk7aqBvaiGXzgAAAeU"]
[Thu Sep 17 15:41:08.795046 2026] [security2:error] [pid 20162:tid 20332] [client 165.232.187.211:62651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.187.232.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kolind.co"] [uri "/xmlrpc.php"] [unique_id "aqxedK-O_Kk7aqBvaiGX2QAAAbY"]
[Thu Sep 17 15:41:09.270001 2026] [security2:error] [pid 20162:tid 20381] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeda-O_Kk7aqBvaiGX8wAAAec"]
[Thu Sep 17 15:41:09.325307 2026] [security2:error] [pid 20162:tid 20385] [client 217.144.190.194:45144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "azclassicbronco.org"] [uri "/"] [unique_id "aqxeda-O_Kk7aqBvaiGYAgAAAes"]
[Thu Sep 17 15:41:09.938341 2026] [security2:error] [pid 20162:tid 20306] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeda-O_Kk7aqBvaiGYCQAAAZw"]
[Thu Sep 17 15:41:09.980140 2026] [security2:error] [pid 20162:tid 20355] [client 165.232.187.211:63027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxeda-O_Kk7aqBvaiGYDgAAAc0"]
[Thu Sep 17 15:41:10.022367 2026] [security2:error] [pid 20162:tid 20344] [client 109.105.210.89:34038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "aqxedq-O_Kk7aqBvaiGYEQAAAcI"]
[Thu Sep 17 15:41:10.103129 2026] [security2:error] [pid 20162:tid 20372] [client 169.58.197.253:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYEwAAAd4"], referer: binance.com
[Thu Sep 17 15:41:10.492088 2026] [security2:error] [pid 20162:tid 20412] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYGgAAAgY"]
[Thu Sep 17 15:41:10.664285 2026] [security2:error] [pid 20162:tid 20271] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.env.backup"] [unique_id "aqxedq-O_Kk7aqBvaiGYJgABvms"]
[Thu Sep 17 15:41:10.664318 2026] [security2:error] [pid 20162:tid 20255] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.env.bak"] [unique_id "aqxedq-O_Kk7aqBvaiGYJAABvls"]
[Thu Sep 17 15:41:10.665598 2026] [security2:error] [pid 20162:tid 20271] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.env.old"] [unique_id "aqxedq-O_Kk7aqBvaiGYJwABvms"]
[Thu Sep 17 15:41:10.840719 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYLQABvmo"]
[Thu Sep 17 15:41:10.840803 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYIwABvjk"]
[Thu Sep 17 15:41:10.840845 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYIQABvl8"]
[Thu Sep 17 15:41:10.841439 2026] [security2:error] [pid 20162:tid 20270] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.env"] [unique_id "aqxedq-O_Kk7aqBvaiGYNwABvmo"]
[Thu Sep 17 15:41:10.842611 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYJQABvkk"]
[Thu Sep 17 15:41:10.843144 2026] [security2:error] [pid 20162:tid 20319] [client 185.104.184.228:33832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.184.104.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-includes/customize/class-wp-widget-form-customize-control.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYOAAAAak"]
[Thu Sep 17 15:41:10.843147 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYKwABvhs"]
[Thu Sep 17 15:41:10.843240 2026] [security2:error] [pid 20162:tid 20319] [client 185.104.184.228:33832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "freeofgravity-com.stevearensberg.com"] [uri "/wp-includes/customize/class-wp-widget-form-customize-control.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYOAAAAak"]
[Thu Sep 17 15:41:10.844408 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYLgABvnY"]
[Thu Sep 17 15:41:10.846245 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYKAABvls"]
[Thu Sep 17 15:41:10.847385 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYKgABvnM"]
[Thu Sep 17 15:41:10.847778 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYIgABvk8"]
[Thu Sep 17 15:41:10.849009 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYLwABvmU"]
[Thu Sep 17 15:41:10.865530 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYLAABvlk"]
[Thu Sep 17 15:41:10.870271 2026] [security2:error] [pid 20162:tid 20340] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYKQABvlM"]
[Thu Sep 17 15:41:10.934851 2026] [security2:error] [pid 20162:tid 20333] [client 165.232.187.211:63594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxedq-O_Kk7aqBvaiGYOgAAAbc"]
[Thu Sep 17 15:41:10.975876 2026] [security2:error] [pid 20162:tid 20238] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/.env.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYOwABxUo"]
[Thu Sep 17 15:41:11.048354 2026] [security2:error] [pid 20162:tid 20379] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYNgAAAeU"]
[Thu Sep 17 15:41:11.127298 2026] [security2:error] [pid 20162:tid 20246] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.env~"] [unique_id "aqxed6-O_Kk7aqBvaiGYPwABxVI"]
[Thu Sep 17 15:41:11.137372 2026] [security2:error] [pid 20162:tid 20301] [client 169.58.197.251:49875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYQQAAAZc"], referer: binance.com
[Thu Sep 17 15:41:11.151329 2026] [security2:error] [pid 20162:tid 20399] [client 152.32.218.30:55176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYOQAAAfk"], referer: https://mdp.iax.mybluehost.me/favicon.ico
[Thu Sep 17 15:41:11.268335 2026] [security2:error] [pid 20162:tid 20347] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYPQABxT8"]
[Thu Sep 17 15:41:11.268418 2026] [security2:error] [pid 20162:tid 20275] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.env.swp"] [unique_id "aqxed6-O_Kk7aqBvaiGYSAABxW8"]
[Thu Sep 17 15:41:11.269636 2026] [security2:error] [pid 20162:tid 20347] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxedq-O_Kk7aqBvaiGYPAABxVA"]
[Thu Sep 17 15:41:11.316667 2026] [security2:error] [pid 20162:tid 20313] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxed6-O_Kk7aqBvaiGYSQAAAaM"]
[Thu Sep 17 15:41:11.354085 2026] [security2:error] [pid 20162:tid 20347] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYQAABxW4"]
[Thu Sep 17 15:41:11.400303 2026] [security2:error] [pid 20162:tid 20304] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxed6-O_Kk7aqBvaiGYTAAAAZo"]
[Thu Sep 17 15:41:11.523278 2026] [security2:error] [pid 20162:tid 20385] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYTgAB61c"]
[Thu Sep 17 15:41:11.533386 2026] [security2:error] [pid 20162:tid 20385] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYTQAB63I"]
[Thu Sep 17 15:41:11.763206 2026] [security2:error] [pid 20162:tid 20329] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYVAAAAbM"]
[Thu Sep 17 15:41:11.892762 2026] [security2:error] [pid 20162:tid 20380] [client 165.232.187.211:64033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxed6-O_Kk7aqBvaiGYWwAAAeY"]
[Thu Sep 17 15:41:11.906908 2026] [security2:error] [pid 20162:tid 20269] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/server/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYZQAB7Wk"]
[Thu Sep 17 15:41:11.906930 2026] [security2:error] [pid 20162:tid 20166] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/config/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYZgAB7QI"]
[Thu Sep 17 15:41:11.906978 2026] [security2:error] [pid 20162:tid 20264] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/src/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYZwAB7WQ"]
[Thu Sep 17 15:41:11.907008 2026] [security2:error] [pid 20162:tid 20287] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/api/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYYgAB7Xs"]
[Thu Sep 17 15:41:11.907099 2026] [security2:error] [pid 20162:tid 20262] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/web/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYaAAB7WI"]
[Thu Sep 17 15:41:11.907123 2026] [security2:error] [pid 20162:tid 20272] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/app/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYYQAB7Ww"]
[Thu Sep 17 15:41:11.907127 2026] [security2:error] [pid 20162:tid 20263] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/backend/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYYwAB7WM"]
[Thu Sep 17 15:41:11.907231 2026] [security2:error] [pid 20162:tid 20254] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/client/.env"] [unique_id "aqxed6-O_Kk7aqBvaiGYaQAB7Vo"]
[Thu Sep 17 15:41:12.012542 2026] [security2:error] [pid 20162:tid 20387] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYXQAB7V4"]
[Thu Sep 17 15:41:12.012712 2026] [security2:error] [pid 20162:tid 20387] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYXgAB7Xo"]
[Thu Sep 17 15:41:12.021514 2026] [security2:error] [pid 20162:tid 20387] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYZAAB7Wg"]
[Thu Sep 17 15:41:12.025480 2026] [security2:error] [pid 20162:tid 20387] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYXwAB7Wc"]
[Thu Sep 17 15:41:12.028317 2026] [security2:error] [pid 20162:tid 20387] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYYAAB7V0"]
[Thu Sep 17 15:41:12.030051 2026] [security2:error] [pid 20162:tid 20387] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxed6-O_Kk7aqBvaiGYXAAB7Us"]
[Thu Sep 17 15:41:12.035987 2026] [security2:error] [pid 20162:tid 20389] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxeeK-O_Kk7aqBvaiGYbQAAAe8"]
[Thu Sep 17 15:41:12.084643 2026] [security2:error] [pid 20162:tid 20288] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/frontend/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYcQAB33w"]
[Thu Sep 17 15:41:12.084657 2026] [security2:error] [pid 20162:tid 20188] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/public/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYcgAB3xg"]
[Thu Sep 17 15:41:12.133981 2026] [security2:error] [pid 20162:tid 20306] [client 109.105.210.90:45454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "aqxeeK-O_Kk7aqBvaiGYdgAAAZw"]
[Thu Sep 17 15:41:12.166651 2026] [security2:error] [pid 20162:tid 20178] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/var/www/html/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYewAB_A4"]
[Thu Sep 17 15:41:12.166668 2026] [security2:error] [pid 20162:tid 20277] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/var/www/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYegAB_HE"]
[Thu Sep 17 15:41:12.166723 2026] [security2:error] [pid 20162:tid 20291] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/laravel/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYeQAB_H8"]
[Thu Sep 17 15:41:12.166729 2026] [security2:error] [pid 20162:tid 20283] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/application/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYeAAB_Hc"]
[Thu Sep 17 15:41:12.195908 2026] [security2:error] [pid 20162:tid 20169] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/apps/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYfQABwQU"]
[Thu Sep 17 15:41:12.195908 2026] [security2:error] [pid 20162:tid 20289] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/back/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYfgABwX0"]
[Thu Sep 17 15:41:12.231757 2026] [security2:error] [pid 20162:tid 20168] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/backup/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYgwAB9gQ"]
[Thu Sep 17 15:41:12.232107 2026] [security2:error] [pid 20162:tid 20284] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/cms/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYhAAB9ng"]
[Thu Sep 17 15:41:12.251116 2026] [core:error] [pid 20162:tid 20299] [client 74.7.244.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:12.251133 2026] [core:error] [pid 20162:tid 20299] [client 74.7.244.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:12.251261 2026] [security2:error] [pid 20162:tid 20299] [client 74.7.244.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.arrowake.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYhgAAAZU"]
[Thu Sep 17 15:41:12.253985 2026] [security2:error] [pid 20162:tid 20350] [client 74.7.244.62:45422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.arrowake.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "aqxeeK-O_Kk7aqBvaiGYgQAByAc"]
[Thu Sep 17 15:41:12.363337 2026] [security2:error] [pid 20162:tid 20165] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/dev/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYiwAB4gE"]
[Thu Sep 17 15:41:12.363354 2026] [security2:error] [pid 20162:tid 20181] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/prod/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYjAAB4hE"]
[Thu Sep 17 15:41:12.363398 2026] [security2:error] [pid 20162:tid 20183] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/staging/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYjQAB4hM"]
[Thu Sep 17 15:41:12.363423 2026] [security2:error] [pid 20162:tid 20175] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/production/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYjgAB4gs"]
[Thu Sep 17 15:41:12.367213 2026] [security2:error] [pid 20162:tid 20294] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYdwAAAZA"]
[Thu Sep 17 15:41:12.409028 2026] [security2:error] [pid 20162:tid 20390] [client 14.96.156.146:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYjwAAAfA"]
[Thu Sep 17 15:41:12.409112 2026] [security2:error] [pid 20162:tid 20390] [client 14.96.156.146:50643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYjwAAAfA"]
[Thu Sep 17 15:41:12.613642 2026] [security2:error] [pid 20162:tid 20187] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/public_html/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYmgAB_xc"]
[Thu Sep 17 15:41:12.613669 2026] [security2:error] [pid 20162:tid 20172] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/new/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYlgAB_wg"]
[Thu Sep 17 15:41:12.613671 2026] [security2:error] [pid 20162:tid 20202] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/server/api/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYnAAB_yY"]
[Thu Sep 17 15:41:12.613730 2026] [security2:error] [pid 20162:tid 20199] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/node-api/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYmQAB_yM"]
[Thu Sep 17 15:41:12.613743 2026] [security2:error] [pid 20162:tid 20185] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/api-backend/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYlwAB_xU"]
[Thu Sep 17 15:41:12.613743 2026] [security2:error] [pid 20162:tid 20190] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/admin-app/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYlQAB_xo"]
[Thu Sep 17 15:41:12.613747 2026] [security2:error] [pid 20162:tid 20203] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/old/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYmAAB_yc"]
[Thu Sep 17 15:41:12.613827 2026] [security2:error] [pid 20162:tid 20194] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/current/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYmwAB_x4"]
[Thu Sep 17 15:41:12.613917 2026] [security2:error] [pid 20162:tid 20180] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/test/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYkwAB_xA"]
[Thu Sep 17 15:41:12.667017 2026] [security2:error] [pid 20162:tid 20173] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/administrator/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYlAAB_wk"]
[Thu Sep 17 15:41:12.749144 2026] [security2:error] [pid 20162:tid 20209] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/aws/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYpQABoy0"]
[Thu Sep 17 15:41:12.749205 2026] [security2:error] [pid 20162:tid 20200] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.aws/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYpAABoyQ"]
[Thu Sep 17 15:41:12.749236 2026] [security2:error] [pid 20162:tid 20211] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.docker/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYpgABoy8"]
[Thu Sep 17 15:41:12.749244 2026] [security2:error] [pid 20162:tid 20206] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/stripe/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYqQABoyo"]
[Thu Sep 17 15:41:12.749260 2026] [security2:error] [pid 20162:tid 20290] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/server/backend/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYqAABo34"]
[Thu Sep 17 15:41:12.749344 2026] [security2:error] [pid 20162:tid 20204] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYpwABoyg"]
[Thu Sep 17 15:41:12.801104 2026] [security2:error] [pid 20162:tid 20197] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/v1/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYrgABoyE"]
[Thu Sep 17 15:41:12.805785 2026] [security2:error] [pid 20162:tid 20176] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/v2/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYrwABoww"]
[Thu Sep 17 15:41:12.819304 2026] [security2:error] [pid 20162:tid 20392] [client 165.232.187.211:64444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxeeK-O_Kk7aqBvaiGYsAAAAfI"]
[Thu Sep 17 15:41:12.858357 2026] [security2:error] [pid 20162:tid 20313] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYqgABoyI"]
[Thu Sep 17 15:41:12.859356 2026] [security2:error] [pid 20162:tid 20313] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYqwABoys"]
[Thu Sep 17 15:41:12.887051 2026] [security2:error] [pid 20162:tid 20174] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/v3/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYsQABmgo"]
[Thu Sep 17 15:41:12.887133 2026] [security2:error] [pid 20162:tid 20192] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/media/.env"] [unique_id "aqxeeK-O_Kk7aqBvaiGYtQABmhw"]
[Thu Sep 17 15:41:12.998639 2026] [security2:error] [pid 20162:tid 20338] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYowAAAbw"]
[Thu Sep 17 15:41:13.004638 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYtAABmjU"]
[Thu Sep 17 15:41:13.006143 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYswABmjY"]
[Thu Sep 17 15:41:13.007729 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYsgABmjM"]
[Thu Sep 17 15:41:13.020694 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYtgABmjQ"]
[Thu Sep 17 15:41:13.078854 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYuAABmiw"]
[Thu Sep 17 15:41:13.084847 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYtwABmhQ"]
[Thu Sep 17 15:41:13.120210 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYvQABmiA"]
[Thu Sep 17 15:41:13.135079 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeK-O_Kk7aqBvaiGYvAABmjg"]
[Thu Sep 17 15:41:13.204975 2026] [security2:error] [pid 20162:tid 20320] [client 179.42.72.172:5313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYvgABqkM"]
[Thu Sep 17 15:41:13.212687 2026] [security2:error] [pid 20162:tid 20229] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.git/config.bak"] [unique_id "aqxeea-O_Kk7aqBvaiGYxwABmkE"]
[Thu Sep 17 15:41:13.218944 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYwQABmi4"]
[Thu Sep 17 15:41:13.223956 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYwAABmjI"]
[Thu Sep 17 15:41:13.270215 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYxAABmh0"]
[Thu Sep 17 15:41:13.281253 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYwwABmgY"]
[Thu Sep 17 15:41:13.334527 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYyAABmjs"]
[Thu Sep 17 15:41:13.344507 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYxgABmjc"]
[Thu Sep 17 15:41:13.347790 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYyQABmj4"]
[Thu Sep 17 15:41:13.373289 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYywABmjo"]
[Thu Sep 17 15:41:13.404239 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGYzQABmkc"]
[Thu Sep 17 15:41:13.419568 2026] [security2:error] [pid 20162:tid 20232] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.aws/credentials.bak"] [unique_id "aqxeea-O_Kk7aqBvaiGY2AABmkQ"]
[Thu Sep 17 15:41:13.428641 2026] [security2:error] [pid 20162:tid 20179] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.ssh/id_rsa"] [unique_id "aqxeea-O_Kk7aqBvaiGY3AABmg8"]
[Thu Sep 17 15:41:13.428641 2026] [security2:error] [pid 20162:tid 20241] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/id_rsa"] [unique_id "aqxeea-O_Kk7aqBvaiGY3QABmk0"]
[Thu Sep 17 15:41:13.469378 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY1AABmkA"]
[Thu Sep 17 15:41:13.485642 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY1gABmjE"]
[Thu Sep 17 15:41:13.485981 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY1wABmjA"]
[Thu Sep 17 15:41:13.542147 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY2wABmkU"]
[Thu Sep 17 15:41:13.545136 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY2gABmkw"]
[Thu Sep 17 15:41:13.545623 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY2QABmjw"]
[Thu Sep 17 15:41:13.581794 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY4AABmlE"]
[Thu Sep 17 15:41:13.584816 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY3wABmk4"]
[Thu Sep 17 15:41:13.588097 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY3gABmlg"]
[Thu Sep 17 15:41:13.626244 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY4QABmlU"]
[Thu Sep 17 15:41:13.640344 2026] [security2:error] [pid 20162:tid 20314] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY1QAAAaQ"]
[Thu Sep 17 15:41:13.656400 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY4gABmj0"]
[Thu Sep 17 15:41:13.667121 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY5QABmkY"]
[Thu Sep 17 15:41:13.672778 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY4wABmhI"]
[Thu Sep 17 15:41:13.685717 2026] [security2:error] [pid 20162:tid 20304] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY5AABmnU"]
[Thu Sep 17 15:41:13.747256 2026] [security2:error] [pid 20162:tid 20329] [client 165.232.187.211:64884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxeea-O_Kk7aqBvaiGY6wAAAbM"]
[Thu Sep 17 15:41:14.288595 2026] [security2:error] [pid 20162:tid 20396] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGY_gAAAfY"]
[Thu Sep 17 15:41:14.376422 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY8QAB318"]
[Thu Sep 17 15:41:14.377063 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY7wAB3yU"]
[Thu Sep 17 15:41:14.377211 2026] [security2:error] [pid 20162:tid 20282] [remote 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY9AAB33Y"]
[Thu Sep 17 15:41:14.378157 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY8wAB3xs"]
[Thu Sep 17 15:41:14.378651 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY8gAB30k"]
[Thu Sep 17 15:41:14.382404 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY8AAB32o"]
[Thu Sep 17 15:41:14.388115 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY7QAB31w"]
[Thu Sep 17 15:41:14.392275 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY9QAB31s"]
[Thu Sep 17 15:41:14.395505 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY-QAB32U"]
[Thu Sep 17 15:41:14.422229 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY7gAB3zk"]
[Thu Sep 17 15:41:14.433837 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY-gAB33M"]
[Thu Sep 17 15:41:14.434111 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY9wAB31M"]
[Thu Sep 17 15:41:14.436995 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY-AAB308"]
[Thu Sep 17 15:41:14.438937 2026] [security2:error] [pid 20162:tid 20373] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY9gAB31k"]
[Thu Sep 17 15:41:14.560754 2026] [security2:error] [pid 20162:tid 20348] [client 177.44.133.72:54691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZBQAAAcY"]
[Thu Sep 17 15:41:14.560915 2026] [security2:error] [pid 20162:tid 20348] [client 177.44.133.72:54691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZBQAAAcY"]
[Thu Sep 17 15:41:14.685488 2026] [security2:error] [pid 20162:tid 20411] [client 165.232.187.211:65252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxeeq-O_Kk7aqBvaiGZCwAAAgU"]
[Thu Sep 17 15:41:14.706775 2026] [security2:error] [pid 20162:tid 20376] [client 103.61.184.148:63158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZDAAAAeI"]
[Thu Sep 17 15:41:14.707796 2026] [security2:error] [pid 20162:tid 20376] [client 103.61.184.148:63158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZDAAAAeI"]
[Thu Sep 17 15:41:14.745088 2026] [security2:error] [pid 20162:tid 20351] [client 109.105.210.87:51042] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "aqxeeq-O_Kk7aqBvaiGZEAAAAck"]
[Thu Sep 17 15:41:14.801839 2026] [security2:error] [pid 20162:tid 20269] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/config.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZHAAB-Wk"]
[Thu Sep 17 15:41:14.961093 2026] [security2:error] [pid 20162:tid 20298] [client 52.167.144.181:40465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "meatlessmusings.com"] [uri "/index.php"] [unique_id "aqxeea-O_Kk7aqBvaiGY-wABlFQ"]
[Thu Sep 17 15:41:15.022967 2026] [security2:error] [pid 20162:tid 20405] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZEwAAAf8"]
[Thu Sep 17 15:41:15.344345 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZFgAB-W4"]
[Thu Sep 17 15:41:15.344535 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZGwAB-W0"]
[Thu Sep 17 15:41:15.344886 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZFwAB-WY"]
[Thu Sep 17 15:41:15.345111 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZGQAB-XI"]
[Thu Sep 17 15:41:15.348165 2026] [security2:error] [pid 20162:tid 20251] [remote 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZGAAB-Vc"]
[Thu Sep 17 15:41:15.349200 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZGgAB-XQ"]
[Thu Sep 17 15:41:15.376566 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZFQAB-VA"]
[Thu Sep 17 15:41:15.393627 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZJwAB-Xs"]
[Thu Sep 17 15:41:15.399251 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZJAAB-WI"]
[Thu Sep 17 15:41:15.403098 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZKAAB-Vo"]
[Thu Sep 17 15:41:15.415201 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZIwAB-WQ"]
[Thu Sep 17 15:41:15.429216 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZKgAB-Xo"]
[Thu Sep 17 15:41:15.430589 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZJgAB-Ww"]
[Thu Sep 17 15:41:15.448965 2026] [security2:error] [pid 20162:tid 20399] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxeeq-O_Kk7aqBvaiGZJQAB-WM"]
[Thu Sep 17 15:41:15.502264 2026] [security2:error] [pid 20162:tid 20358] [client 186.84.88.173:6084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZMwAB0Hw"]
[Thu Sep 17 15:41:15.591441 2026] [security2:error] [pid 20162:tid 20283] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/config/aws.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZPwABonc"]
[Thu Sep 17 15:41:15.611058 2026] [security2:error] [pid 20162:tid 20385] [client 165.232.187.211:49265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxee6-O_Kk7aqBvaiGZQQAAAes"]
[Thu Sep 17 15:41:15.784685 2026] [security2:error] [pid 20162:tid 20303] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZOAAAAZk"]
[Thu Sep 17 15:41:15.944519 2026] [security2:error] [pid 20162:tid 20306] [client 109.105.210.89:27088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxee6-O_Kk7aqBvaiGZVgAAAZw"]
[Thu Sep 17 15:41:16.272614 2026] [security2:error] [pid 20162:tid 20312] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZOgABonE"]
[Thu Sep 17 15:41:16.282859 2026] [security2:error] [pid 20162:tid 20312] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZOQABohg"]
[Thu Sep 17 15:41:16.291935 2026] [security2:error] [pid 20162:tid 20312] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZOwABogM"]
[Thu Sep 17 15:41:16.311930 2026] [security2:error] [pid 20162:tid 20396] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZXQAAAfY"]
[Thu Sep 17 15:41:16.313846 2026] [security2:error] [pid 20162:tid 20312] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZPgABog4"]
[Thu Sep 17 15:41:16.316195 2026] [security2:error] [pid 20162:tid 20312] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZPQABon8"]
[Thu Sep 17 15:41:16.321840 2026] [security2:error] [pid 20162:tid 20312] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxee6-O_Kk7aqBvaiGZPAABogU"]
[Thu Sep 17 15:41:16.358575 2026] [security2:error] [pid 20162:tid 20325] [client 143.105.152.240:42954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZZAAAAa8"]
[Thu Sep 17 15:41:16.358698 2026] [security2:error] [pid 20162:tid 20325] [client 143.105.152.240:42954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZZAAAAa8"]
[Thu Sep 17 15:41:16.409475 2026] [security2:error] [pid 20162:tid 20176] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/config/stripe.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZZwACBAw"]
[Thu Sep 17 15:41:16.428951 2026] [security2:error] [pid 20162:tid 20207] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/config/mail.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZagABwis"]
[Thu Sep 17 15:41:16.459311 2026] [security2:error] [pid 20162:tid 20174] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/config/config.inc.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZawABwgo"]
[Thu Sep 17 15:41:16.484929 2026] [security2:error] [pid 20162:tid 20217] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/config/nexmo.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZbQABwjU"]
[Thu Sep 17 15:41:16.525604 2026] [security2:error] [pid 20162:tid 20344] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZaAABwhk"]
[Thu Sep 17 15:41:16.549561 2026] [security2:error] [pid 20162:tid 20375] [client 165.232.187.211:49607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxefK-O_Kk7aqBvaiGZcgAAAeE"]
[Thu Sep 17 15:41:16.566832 2026] [security2:error] [pid 20162:tid 20344] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZbAABwhw"]
[Thu Sep 17 15:41:16.568147 2026] [security2:error] [pid 20162:tid 20352] [client 102.179.132.197:39592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZaQAByiI"], referer: https://www.sqlerudition.com
[Thu Sep 17 15:41:16.614958 2026] [security2:error] [pid 20162:tid 20164] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-config.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZeAABrAA"]
[Thu Sep 17 15:41:16.636117 2026] [security2:error] [pid 20162:tid 20210] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sfvhbt.org"] [uri "/wp-config.php.old"] [unique_id "aqxefK-O_Kk7aqBvaiGZgAABrC4"]
[Thu Sep 17 15:41:16.636116 2026] [security2:error] [pid 20162:tid 20214] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sfvhbt.org"] [uri "/wp-config.php.new"] [unique_id "aqxefK-O_Kk7aqBvaiGZfAABrDI"]
[Thu Sep 17 15:41:16.636117 2026] [security2:error] [pid 20162:tid 20229] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sfvhbt.org"] [uri "/wp-config.php.bak"] [unique_id "aqxefK-O_Kk7aqBvaiGZgQABrEE"]
[Thu Sep 17 15:41:16.636494 2026] [security2:error] [pid 20162:tid 20193] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/.wp-config.php.swp"] [unique_id "aqxefK-O_Kk7aqBvaiGZfQABrB0"]
[Thu Sep 17 15:41:16.637715 2026] [security2:error] [pid 20162:tid 20219] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/wp-content/mysql.sql"] [unique_id "aqxefK-O_Kk7aqBvaiGZfwABrDc"]
[Thu Sep 17 15:41:16.725885 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZegABrDg"]
[Thu Sep 17 15:41:16.726815 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZeQABrCk"]
[Thu Sep 17 15:41:16.742077 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZggABrDs"]
[Thu Sep 17 15:41:16.742222 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZfgABrAY"]
[Thu Sep 17 15:41:16.743162 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZgwABrD4"]
[Thu Sep 17 15:41:16.952261 2026] [security2:error] [pid 20162:tid 20310] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxefK-O_Kk7aqBvaiGZjQAAAaA"]
[Thu Sep 17 15:41:17.098563 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZkwABzkQ"]
[Thu Sep 17 15:41:17.167025 2026] [security2:error] [pid 20162:tid 20397] [client 109.105.210.89:27102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "aqxefa-O_Kk7aqBvaiGZmwAAAfc"]
[Thu Sep 17 15:41:17.208029 2026] [security2:error] [pid 20162:tid 20252] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/terraform.tfstate.backup"] [unique_id "aqxefa-O_Kk7aqBvaiGZnwAB5Fg"]
[Thu Sep 17 15:41:17.307043 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZogAB5FE"]
[Thu Sep 17 15:41:17.309687 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZpAAB5FU"]
[Thu Sep 17 15:41:17.309778 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZngAB5E4"]
[Thu Sep 17 15:41:17.316492 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZowAB5Dw"]
[Thu Sep 17 15:41:17.323872 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZoQAB5Gs"]
[Thu Sep 17 15:41:17.324934 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZpQAB5FY"]
[Thu Sep 17 15:41:17.330039 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZoAAB5Ew"]
[Thu Sep 17 15:41:17.368378 2026] [security2:error] [pid 20162:tid 20309] [client 136.158.61.34:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZrwAAAZ8"]
[Thu Sep 17 15:41:17.368526 2026] [security2:error] [pid 20162:tid 20309] [client 136.158.61.34:35572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZrwAAAZ8"]
[Thu Sep 17 15:41:17.419139 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZrQAB5BI"]
[Thu Sep 17 15:41:17.440200 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZqwAB5GA"]
[Thu Sep 17 15:41:17.440320 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZrgAB5HU"]
[Thu Sep 17 15:41:17.440369 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZqgAB5EY"]
[Thu Sep 17 15:41:17.443567 2026] [security2:error] [pid 20162:tid 20378] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZrAAB5Eo"]
[Thu Sep 17 15:41:17.481304 2026] [security2:error] [pid 20162:tid 20398] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZpgAAAfg"]
[Thu Sep 17 15:41:17.493177 2026] [security2:error] [pid 20162:tid 20320] [client 165.232.187.211:50003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxefa-O_Kk7aqBvaiGZtAAAAao"]
[Thu Sep 17 15:41:17.569644 2026] [security2:error] [pid 20162:tid 20389] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZsgAB73A"]
[Thu Sep 17 15:41:17.598712 2026] [security2:error] [pid 20162:tid 20389] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZswAB718"]
[Thu Sep 17 15:41:17.657317 2026] [security2:error] [pid 20162:tid 20389] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZtQAB7yU"]
[Thu Sep 17 15:41:17.663096 2026] [security2:error] [pid 20162:tid 20389] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZtgAB73Y"]
[Thu Sep 17 15:41:17.711873 2026] [security2:error] [pid 20162:tid 20389] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZtwAB7xs"]
[Thu Sep 17 15:41:17.713199 2026] [security2:error] [pid 20162:tid 20389] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZuAAB70k"]
[Thu Sep 17 15:41:17.861673 2026] [security2:error] [pid 20162:tid 20388] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZwQAB7mU"]
[Thu Sep 17 15:41:17.862234 2026] [security2:error] [pid 20162:tid 20388] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZvgAB7ls"]
[Thu Sep 17 15:41:17.877458 2026] [security2:error] [pid 20162:tid 20388] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZvwAB7jk"]
[Thu Sep 17 15:41:17.877555 2026] [security2:error] [pid 20162:tid 20388] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZwAAB7nM"]
[Thu Sep 17 15:41:17.879560 2026] [security2:error] [pid 20162:tid 20388] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZwgAB7lM"]
[Thu Sep 17 15:41:18.045252 2026] [security2:error] [pid 20162:tid 20314] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZwwAAAaQ"]
[Thu Sep 17 15:41:18.169410 2026] [security2:error] [pid 20162:tid 20419] [client 169.58.197.253:64183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ0AAAAg0"], referer: binance.com
[Thu Sep 17 15:41:18.287934 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZxQABqFk"]
[Thu Sep 17 15:41:18.296530 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZxgABqE8"]
[Thu Sep 17 15:41:18.344631 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZyQABqG8"]
[Thu Sep 17 15:41:18.345561 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZywABqFQ"]
[Thu Sep 17 15:41:18.347319 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZzQABqGc"]
[Thu Sep 17 15:41:18.347386 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZygABqGg"]
[Thu Sep 17 15:41:18.355334 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZzgABqF0"]
[Thu Sep 17 15:41:18.356180 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefa-O_Kk7aqBvaiGZxwABqD8"]
[Thu Sep 17 15:41:18.358740 2026] [security2:error] [pid 20162:tid 20318] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZzwABqF4"]
[Thu Sep 17 15:41:18.457538 2026] [security2:error] [pid 20162:tid 20316] [client 165.232.187.211:50493] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxefq-O_Kk7aqBvaiGZ2gAAAaY"]
[Thu Sep 17 15:41:18.512834 2026] [security2:error] [pid 20162:tid 20373] [client 79.116.89.151:58967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ3QAAAd8"]
[Thu Sep 17 15:41:18.512937 2026] [security2:error] [pid 20162:tid 20373] [client 79.116.89.151:58967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ3QAAAd8"]
[Thu Sep 17 15:41:18.515202 2026] [security2:error] [pid 20162:tid 20325] [client 109.105.210.88:45272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxefq-O_Kk7aqBvaiGZ4AAAAa8"]
[Thu Sep 17 15:41:18.585927 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ3AACBGY"]
[Thu Sep 17 15:41:18.586970 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ2wACBG0"]
[Thu Sep 17 15:41:18.678484 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ5AACBHI"]
[Thu Sep 17 15:41:18.678602 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ5QACBFo"]
[Thu Sep 17 15:41:18.679686 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ6QACBGQ"]
[Thu Sep 17 15:41:18.680766 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ5gACBEs"]
[Thu Sep 17 15:41:18.685163 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ4gACBHQ"]
[Thu Sep 17 15:41:18.685354 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ6AACBHs"]
[Thu Sep 17 15:41:18.691226 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ4QACBGI"]
[Thu Sep 17 15:41:18.696175 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ5wACBFc"]
[Thu Sep 17 15:41:18.739408 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ4wACBFA"]
[Thu Sep 17 15:41:18.750204 2026] [security2:error] [pid 20162:tid 20355] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ3wAAAc0"]
[Thu Sep 17 15:41:18.828852 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ8QACBGM"]
[Thu Sep 17 15:41:18.830309 2026] [security2:error] [pid 20162:tid 20410] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ8AACBGw"]
[Thu Sep 17 15:41:18.846274 2026] [security2:error] [pid 20162:tid 20284] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/phpinfo.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ-gABvHg"]
[Thu Sep 17 15:41:19.013727 2026] [security2:error] [pid 20162:tid 20405] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxef6-O_Kk7aqBvaiGZ_gAAAf8"]
[Thu Sep 17 15:41:19.055163 2026] [security2:error] [pid 20162:tid 20181] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/info.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaAAABvBE"]
[Thu Sep 17 15:41:19.055189 2026] [security2:error] [pid 20162:tid 20285] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/infos.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaAgABvHk"]
[Thu Sep 17 15:41:19.055196 2026] [security2:error] [pid 20162:tid 20187] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/php_info.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaAQABvBc"]
[Thu Sep 17 15:41:19.083613 2026] [security2:error] [pid 20162:tid 20323] [client 135.136.20.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "charmacounselling.com"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGZ_wAAAa0"], referer: https://charmacounselling.com/contact-me/
[Thu Sep 17 15:41:19.087376 2026] [security2:error] [pid 20162:tid 20202] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/php.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaBAABvCY"]
[Thu Sep 17 15:41:19.157216 2026] [security2:error] [pid 20162:tid 20395] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/.env~"] [unique_id "aqxef6-O_Kk7aqBvaiGaBQAAAfU"]
[Thu Sep 17 15:41:19.337035 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ9AABvAQ"]
[Thu Sep 17 15:41:19.338673 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ9gABvHc"]
[Thu Sep 17 15:41:19.339270 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ-QABvAc"]
[Thu Sep 17 15:41:19.339650 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ8wABvHw"]
[Thu Sep 17 15:41:19.344035 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ9QABvH0"]
[Thu Sep 17 15:41:19.357915 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ9wABvA0"]
[Thu Sep 17 15:41:19.360231 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ-AABvBM"]
[Thu Sep 17 15:41:19.378739 2026] [security2:error] [pid 20162:tid 20338] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxefq-O_Kk7aqBvaiGZ-wABvAE"]
[Thu Sep 17 15:41:19.417477 2026] [security2:error] [pid 20162:tid 20347] [client 165.232.187.211:50937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aqxef6-O_Kk7aqBvaiGaDAAAAcU"]
[Thu Sep 17 15:41:19.501030 2026] [security2:error] [pid 20162:tid 20199] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/php-info.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaEgABtyM"]
[Thu Sep 17 15:41:19.501050 2026] [security2:error] [pid 20162:tid 20195] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaFQABtx8"]
[Thu Sep 17 15:41:19.501086 2026] [security2:error] [pid 20162:tid 20194] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/infophp.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaFAABtx4"]
[Thu Sep 17 15:41:19.509133 2026] [security2:error] [pid 20162:tid 20310] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaCwAAAaA"]
[Thu Sep 17 15:41:19.534477 2026] [security2:error] [pid 20162:tid 20420] [client 169.58.197.251:50604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaFgAAAg4"], referer: binance.com
[Thu Sep 17 15:41:19.559626 2026] [security2:error] [pid 20162:tid 20383] [client 45.179.148.38:49344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sqlerudition.com"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaDgAB6Sc"], referer: https://www.sqlerudition.com
[Thu Sep 17 15:41:19.565283 2026] [core:error] [pid 20162:tid 20356] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:19.565299 2026] [core:error] [pid 20162:tid 20356] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:19.611193 2026] [security2:error] [pid 20162:tid 20333] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaEwABtxo"]
[Thu Sep 17 15:41:19.691027 2026] [security2:error] [pid 20162:tid 20175] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaGQAB-Qs"]
[Thu Sep 17 15:41:19.698784 2026] [security2:error] [pid 20162:tid 20186] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/public/phpinfo.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaGgABtBY"]
[Thu Sep 17 15:41:19.698815 2026] [security2:error] [pid 20162:tid 20209] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/admin_phpinfo.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaGwABtC0"]
[Thu Sep 17 15:41:19.698846 2026] [security2:error] [pid 20162:tid 20173] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/api/phpinfo.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaHAABtAk"]
[Thu Sep 17 15:41:19.804104 2026] [security2:error] [pid 20162:tid 20407] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaHQACASQ"]
[Thu Sep 17 15:41:19.930984 2026] [security2:error] [pid 20162:tid 20407] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaJQACAXE"]
[Thu Sep 17 15:41:19.948002 2026] [security2:error] [pid 20162:tid 20407] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaKAACAQ4"]
[Thu Sep 17 15:41:19.958617 2026] [security2:error] [pid 20162:tid 20407] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaKQACARg"]
[Thu Sep 17 15:41:19.958741 2026] [security2:error] [pid 20162:tid 20407] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaKgACAQM"]
[Thu Sep 17 15:41:20.004877 2026] [security2:error] [pid 20162:tid 20407] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaLAACAX8"]
[Thu Sep 17 15:41:20.083164 2026] [security2:error] [pid 20162:tid 20407] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaMAACAQU"]
[Thu Sep 17 15:41:20.142907 2026] [security2:error] [pid 20162:tid 20261] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/database.sql"] [unique_id "aqxegK-O_Kk7aqBvaiGaMgABz2E"]
[Thu Sep 17 15:41:20.168956 2026] [security2:error] [pid 20162:tid 20342] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxef6-O_Kk7aqBvaiGaLwAAAcA"]
[Thu Sep 17 15:41:20.283050 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaMwABnH4"]
[Thu Sep 17 15:41:20.336602 2026] [security2:error] [pid 20162:tid 20331] [client 165.232.187.211:51292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxegK-O_Kk7aqBvaiGaOwAAAbU"]
[Thu Sep 17 15:41:20.347593 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaNgABnCs"]
[Thu Sep 17 15:41:20.371929 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaOQABnDY"]
[Thu Sep 17 15:41:20.383100 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaOAABnAo"]
[Thu Sep 17 15:41:20.387202 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaNwABnDM"]
[Thu Sep 17 15:41:20.499263 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaPAABnDU"]
[Thu Sep 17 15:41:20.530258 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaPQABnDQ"]
[Thu Sep 17 15:41:20.626071 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaQAABnBk"]
[Thu Sep 17 15:41:20.643944 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaRwABnCA"]
[Thu Sep 17 15:41:20.647381 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaRAABnCI"]
[Thu Sep 17 15:41:20.647748 2026] [security2:error] [pid 20162:tid 20306] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaRQABnBw"]
[Thu Sep 17 15:41:20.810061 2026] [security2:error] [pid 20162:tid 20368] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaSAAAAdo"]
[Thu Sep 17 15:41:20.851133 2026] [security2:error] [pid 20162:tid 20197] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/web.config.bak"] [unique_id "aqxegK-O_Kk7aqBvaiGaVgAB5SE"]
[Thu Sep 17 15:41:20.905014 2026] [security2:error] [pid 20162:tid 20379] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaUAAB5S4"]
[Thu Sep 17 15:41:20.906280 2026] [security2:error] [pid 20162:tid 20379] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaUQAB5UE"]
[Thu Sep 17 15:41:20.906444 2026] [security2:error] [pid 20162:tid 20379] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaUwAB5R0"]
[Thu Sep 17 15:41:20.913176 2026] [security2:error] [pid 20162:tid 20379] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaTwAB5TI"]
[Thu Sep 17 15:41:20.914258 2026] [security2:error] [pid 20162:tid 20379] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaUgAB5Tc"]
[Thu Sep 17 15:41:20.980036 2026] [security2:error] [pid 20162:tid 20379] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxegK-O_Kk7aqBvaiGaVQAB5To"]
[Thu Sep 17 15:41:21.264243 2026] [security2:error] [pid 20162:tid 20334] [client 165.232.187.211:51646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxega-O_Kk7aqBvaiGaZwAAAbg"]
[Thu Sep 17 15:41:21.276681 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaWQABrCk"]
[Thu Sep 17 15:41:21.326792 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaYAABrDA"]
[Thu Sep 17 15:41:21.330446 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaXwABrAY"]
[Thu Sep 17 15:41:21.333880 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaXQABrEc"]
[Thu Sep 17 15:41:21.338857 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaYgABrEI"]
[Thu Sep 17 15:41:21.346524 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaYQABrD4"]
[Thu Sep 17 15:41:21.349863 2026] [security2:error] [pid 20162:tid 20322] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaXgABrEA"]
[Thu Sep 17 15:41:21.472415 2026] [security2:error] [pid 20162:tid 20232] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "sfvhbt.org"] [uri "/.env.orig"] [unique_id "aqxega-O_Kk7aqBvaiGabQABxUQ"]
[Thu Sep 17 15:41:21.475163 2026] [security2:error] [pid 20162:tid 20252] [remote 34.14.99.143:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.99.14.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/.env.php.bak"] [unique_id "aqxega-O_Kk7aqBvaiGacAABxVg"]
[Thu Sep 17 15:41:21.578240 2026] [security2:error] [pid 20162:tid 20347] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGabgABxQ8"]
[Thu Sep 17 15:41:21.578323 2026] [security2:error] [pid 20162:tid 20347] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGabwABxUU"]
[Thu Sep 17 15:41:21.693497 2026] [security2:error] [pid 20162:tid 20299] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaawAAAZU"]
[Thu Sep 17 15:41:21.700504 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGacQABzlE"]
[Thu Sep 17 15:41:21.715424 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGacgABzk4"]
[Thu Sep 17 15:41:21.795070 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGadgABzjw"]
[Thu Sep 17 15:41:21.799786 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGadwABzms"]
[Thu Sep 17 15:41:21.811772 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaeAABzj0"]
[Thu Sep 17 15:41:21.834358 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaeQABzlY"]
[Thu Sep 17 15:41:21.836013 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaegABzkw"]
[Thu Sep 17 15:41:21.886894 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGafQABzk0"]
[Thu Sep 17 15:41:21.935887 2026] [security2:error] [pid 20162:tid 20378] [client 40.86.204.64:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.204.86.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yjy.vmo.mybluehost.me"] [uri "/wp-login.php"] [unique_id "aqxega-O_Kk7aqBvaiGahAAAAeQ"]
[Thu Sep 17 15:41:21.955327 2026] [security2:error] [pid 20162:tid 20349] [client 109.105.210.89:27118] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "aqxega-O_Kk7aqBvaiGaiwAAAcc"]
[Thu Sep 17 15:41:21.965855 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGagAABznU"]
[Thu Sep 17 15:41:21.968305 2026] [security2:error] [pid 20162:tid 20356] [client 34.14.99.143:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sfvhbt.org"] [uri "/index.php"] [unique_id "aqxega-O_Kk7aqBvaiGaggABzkY"]
[Thu Sep 17 15:41:22.199093 2026] [security2:error] [pid 20162:tid 20382] [client 165.232.187.211:52091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxegq-O_Kk7aqBvaiGalwAAAeg"]
[Thu Sep 17 15:41:22.212726 2026] [security2:error] [pid 20162:tid 20314] [client 43.173.182.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxegq-O_Kk7aqBvaiGakQAAAaQ"]
[Thu Sep 17 15:41:22.237833 2026] [security2:error] [pid 20162:tid 20416] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxegq-O_Kk7aqBvaiGakAAAAgo"]
[Thu Sep 17 15:41:22.555329 2026] [security2:error] [pid 20162:tid 20339] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxegq-O_Kk7aqBvaiGaowAAAb0"]
[Thu Sep 17 15:41:22.662174 2026] [security2:error] [pid 20162:tid 20394] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxegq-O_Kk7aqBvaiGapQAAAfQ"]
[Thu Sep 17 15:41:22.743922 2026] [security2:error] [pid 20162:tid 20323] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxegq-O_Kk7aqBvaiGapgAAAa0"]
[Thu Sep 17 15:41:22.761170 2026] [security2:error] [pid 20162:tid 20352] [client 40.86.204.64:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.204.86.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yjy.vmo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "aqxegq-O_Kk7aqBvaiGaqQAAAco"]
[Thu Sep 17 15:41:22.830653 2026] [security2:error] [pid 20162:tid 20395] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxegq-O_Kk7aqBvaiGarAAAAfU"]
[Thu Sep 17 15:41:22.926168 2026] [security2:error] [pid 20162:tid 20337] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxegq-O_Kk7aqBvaiGarQAAAbs"]
[Thu Sep 17 15:41:22.981589 2026] [security2:error] [pid 20162:tid 20345] [client 14.96.156.146:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxegq-O_Kk7aqBvaiGargAAAcM"]
[Thu Sep 17 15:41:22.981699 2026] [security2:error] [pid 20162:tid 20345] [client 14.96.156.146:51286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxegq-O_Kk7aqBvaiGargAAAcM"]
[Thu Sep 17 15:41:23.056893 2026] [security2:error] [pid 20162:tid 20406] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxeg6-O_Kk7aqBvaiGasQAAAgA"]
[Thu Sep 17 15:41:23.153967 2026] [security2:error] [pid 20162:tid 20414] [client 165.232.187.211:52526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxeg6-O_Kk7aqBvaiGatAAAAgg"]
[Thu Sep 17 15:41:23.487259 2026] [security2:error] [pid 20162:tid 20397] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeg6-O_Kk7aqBvaiGauQAAAfc"]
[Thu Sep 17 15:41:23.764260 2026] [security2:error] [pid 20162:tid 20398] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxeg6-O_Kk7aqBvaiGawgAAAfg"]
[Thu Sep 17 15:41:23.844717 2026] [security2:error] [pid 20162:tid 20358] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxeg6-O_Kk7aqBvaiGaxgAAAdA"]
[Thu Sep 17 15:41:23.930863 2026] [security2:error] [pid 20162:tid 20415] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxeg6-O_Kk7aqBvaiGayQAAAgk"]
[Thu Sep 17 15:41:24.041549 2026] [security2:error] [pid 20162:tid 20407] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGaygAAAgE"]
[Thu Sep 17 15:41:24.099694 2026] [security2:error] [pid 20162:tid 20300] [client 165.232.187.211:52903] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kolind.co"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxehK-O_Kk7aqBvaiGazQAAAZY"]
[Thu Sep 17 15:41:24.111820 2026] [security2:error] [pid 20162:tid 20362] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGazgAAAdQ"]
[Thu Sep 17 15:41:24.145548 2026] [security2:error] [pid 20162:tid 20381] [client 69.165.75.187:54871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanpeckolick.jwdnyc.com"] [uri "/index.php"] [unique_id "aqxehK-O_Kk7aqBvaiGazwAAAec"], referer: https://alanpeckolick.jwdnyc.com
[Thu Sep 17 15:41:24.192355 2026] [security2:error] [pid 20162:tid 20403] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa0QAAAf0"]
[Thu Sep 17 15:41:24.286420 2026] [security2:error] [pid 20162:tid 20400] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa1wAAAfo"]
[Thu Sep 17 15:41:24.344099 2026] [security2:error] [pid 20162:tid 20314] [client 134.185.85.61:60892] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "developingskill.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxehK-O_Kk7aqBvaiGa2QAAAaQ"]
[Thu Sep 17 15:41:24.372526 2026] [security2:error] [pid 20162:tid 20325] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa2gAAAa8"]
[Thu Sep 17 15:41:24.412384 2026] [security2:error] [pid 20162:tid 20382] [client 109.105.210.87:12070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxehK-O_Kk7aqBvaiGa2wAAAeg"]
[Thu Sep 17 15:41:24.448759 2026] [security2:error] [pid 20162:tid 20418] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa3QAAAgw"]
[Thu Sep 17 15:41:24.590536 2026] [security2:error] [pid 20162:tid 20312] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa3gAAAaI"]
[Thu Sep 17 15:41:24.660448 2026] [security2:error] [pid 20162:tid 20367] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa4QAAAdk"]
[Thu Sep 17 15:41:24.741648 2026] [security2:error] [pid 20162:tid 20315] [client 134.185.85.61:55255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "developingskill.com"] [uri "/media/system/js/core.js"] [unique_id "aqxehK-O_Kk7aqBvaiGa4wAAAaU"]
[Thu Sep 17 15:41:24.741752 2026] [security2:error] [pid 20162:tid 20360] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa4gAAAdI"]
[Thu Sep 17 15:41:24.850375 2026] [security2:error] [pid 20162:tid 20340] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa5wAAAb4"]
[Thu Sep 17 15:41:24.959506 2026] [security2:error] [pid 20162:tid 20355] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxehK-O_Kk7aqBvaiGa6AAAAc0"]
[Thu Sep 17 15:41:25.044722 2026] [security2:error] [pid 20162:tid 20296] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa6QAAAZI"]
[Thu Sep 17 15:41:25.118941 2026] [security2:error] [pid 20162:tid 20343] [client 177.44.133.72:55386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeha-O_Kk7aqBvaiGa6gAAAcE"]
[Thu Sep 17 15:41:25.119066 2026] [security2:error] [pid 20162:tid 20343] [client 177.44.133.72:55386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeha-O_Kk7aqBvaiGa6gAAAcE"]
[Thu Sep 17 15:41:25.121562 2026] [security2:error] [pid 20162:tid 20394] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa6wAAAfQ"]
[Thu Sep 17 15:41:25.279980 2026] [security2:error] [pid 20162:tid 20322] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa8AAAAaw"]
[Thu Sep 17 15:41:25.356921 2026] [security2:error] [pid 20162:tid 20336] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa8wAAAbo"]
[Thu Sep 17 15:41:25.361642 2026] [security2:error] [pid 20162:tid 20384] [client 103.61.184.148:63731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeha-O_Kk7aqBvaiGa8gAAAeo"]
[Thu Sep 17 15:41:25.361741 2026] [security2:error] [pid 20162:tid 20384] [client 103.61.184.148:63731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeha-O_Kk7aqBvaiGa8gAAAeo"]
[Thu Sep 17 15:41:25.432037 2026] [security2:error] [pid 20162:tid 20406] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa9QAAAgA"]
[Thu Sep 17 15:41:25.505111 2026] [security2:error] [pid 20162:tid 20354] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa-QAAAcw"]
[Thu Sep 17 15:41:25.599206 2026] [security2:error] [pid 20162:tid 20408] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa-wAAAgI"]
[Thu Sep 17 15:41:25.661031 2026] [security2:error] [pid 20162:tid 20332] [client 169.58.197.253:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxeha-O_Kk7aqBvaiGa_QAAAbY"], referer: binance.com
[Thu Sep 17 15:41:25.694297 2026] [security2:error] [pid 20162:tid 20301] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGa_gAAAZc"]
[Thu Sep 17 15:41:25.808882 2026] [security2:error] [pid 20162:tid 20302] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGbAgAAAZg"]
[Thu Sep 17 15:41:25.913555 2026] [security2:error] [pid 20162:tid 20370] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxeha-O_Kk7aqBvaiGbBQAAAdw"]
[Thu Sep 17 15:41:26.045144 2026] [security2:error] [pid 20162:tid 20399] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbBwAAAfk"]
[Thu Sep 17 15:41:26.116075 2026] [security2:error] [pid 20162:tid 20397] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbCgAAAfc"]
[Thu Sep 17 15:41:26.193328 2026] [security2:error] [pid 20162:tid 20366] [client 210.222.43.21:49338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxehq-O_Kk7aqBvaiGbCAAAAdg"], referer: http://talent-in-borders.com/SITE
[Thu Sep 17 15:41:26.206485 2026] [security2:error] [pid 20162:tid 20294] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbCwAAAZA"]
[Thu Sep 17 15:41:26.207643 2026] [security2:error] [pid 20162:tid 20311] [client 109.105.210.90:19170] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "aqxehq-O_Kk7aqBvaiGbDAAAAaE"]
[Thu Sep 17 15:41:26.307394 2026] [security2:error] [pid 20162:tid 20293] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbEAAAAY8"]
[Thu Sep 17 15:41:26.393266 2026] [security2:error] [pid 20162:tid 20358] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbEQAAAdA"]
[Thu Sep 17 15:41:26.502373 2026] [security2:error] [pid 20162:tid 20298] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbEgAAAZQ"]
[Thu Sep 17 15:41:26.631019 2026] [security2:error] [pid 20162:tid 20356] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbEwAAAc4"]
[Thu Sep 17 15:41:26.763356 2026] [security2:error] [pid 20162:tid 20393] [client 34.95.61.66:36084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxehq-O_Kk7aqBvaiGbGAAAAfM"]
[Thu Sep 17 15:41:26.924136 2026] [security2:error] [pid 20162:tid 20341] [client 143.105.152.240:33971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxehq-O_Kk7aqBvaiGbGwAAAb8"]
[Thu Sep 17 15:41:26.924231 2026] [security2:error] [pid 20162:tid 20341] [client 143.105.152.240:33971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxehq-O_Kk7aqBvaiGbGwAAAb8"]
[Thu Sep 17 15:41:27.114680 2026] [security2:error] [pid 20162:tid 20326] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbHwAAAbA"]
[Thu Sep 17 15:41:27.193043 2026] [security2:error] [pid 20162:tid 20325] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbIQAAAa8"]
[Thu Sep 17 15:41:27.286347 2026] [security2:error] [pid 20162:tid 20388] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbJQAAAe4"]
[Thu Sep 17 15:41:27.399194 2026] [security2:error] [pid 20162:tid 20372] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbJwAAAd4"]
[Thu Sep 17 15:41:27.504693 2026] [security2:error] [pid 20162:tid 20312] [client 169.58.197.251:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxeh6-O_Kk7aqBvaiGbLAAAAaI"], referer: binance.com
[Thu Sep 17 15:41:27.512972 2026] [security2:error] [pid 20162:tid 20353] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbLQAAAcs"]
[Thu Sep 17 15:41:27.583243 2026] [security2:error] [pid 20162:tid 20318] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbLgAAAag"]
[Thu Sep 17 15:41:27.662967 2026] [security2:error] [pid 20162:tid 20327] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbMQAAAbE"]
[Thu Sep 17 15:41:27.767207 2026] [security2:error] [pid 20162:tid 20339] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbNgAAAb0"]
[Thu Sep 17 15:41:27.866348 2026] [security2:error] [pid 20162:tid 20404] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbOwAAAf4"]
[Thu Sep 17 15:41:27.967817 2026] [security2:error] [pid 20162:tid 20390] [client 109.105.210.88:48246] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "aqxeh6-O_Kk7aqBvaiGbVAAAAfA"]
[Thu Sep 17 15:41:27.979321 2026] [security2:error] [pid 20162:tid 20414] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxeh6-O_Kk7aqBvaiGbVgAAAgg"]
[Thu Sep 17 15:41:28.053375 2026] [security2:error] [pid 20162:tid 20309] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbWgAAAZ8"]
[Thu Sep 17 15:41:28.163344 2026] [security2:error] [pid 20162:tid 20365] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbZgAAAdc"]
[Thu Sep 17 15:41:28.252336 2026] [security2:error] [pid 20162:tid 20347] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbaQAAAcU"]
[Thu Sep 17 15:41:28.370304 2026] [security2:error] [pid 20162:tid 20293] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbbgAAAY8"]
[Thu Sep 17 15:41:28.443370 2026] [security2:error] [pid 20162:tid 20298] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbcAAAAZQ"]
[Thu Sep 17 15:41:28.543217 2026] [security2:error] [pid 20162:tid 20401] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbdAAAAfs"]
[Thu Sep 17 15:41:28.635972 2026] [security2:error] [pid 20162:tid 20328] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbdgAAAbI"]
[Thu Sep 17 15:41:28.714295 2026] [security2:error] [pid 20162:tid 20420] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbegAAAg4"]
[Thu Sep 17 15:41:28.825870 2026] [security2:error] [pid 20162:tid 20326] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbfwAAAbA"]
[Thu Sep 17 15:41:28.913438 2026] [security2:error] [pid 20162:tid 20325] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbhgAAAa8"]
[Thu Sep 17 15:41:28.991984 2026] [security2:error] [pid 20162:tid 20386] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxeiK-O_Kk7aqBvaiGbiAAAAew"]
[Thu Sep 17 15:41:29.099850 2026] [security2:error] [pid 20162:tid 20418] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbiQAAAgw"]
[Thu Sep 17 15:41:29.149826 2026] [security2:error] [pid 20162:tid 20319] [client 79.116.89.151:59370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeia-O_Kk7aqBvaiGbiwAAAak"]
[Thu Sep 17 15:41:29.149912 2026] [security2:error] [pid 20162:tid 20319] [client 79.116.89.151:59370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxeia-O_Kk7aqBvaiGbiwAAAak"]
[Thu Sep 17 15:41:29.173826 2026] [security2:error] [pid 20162:tid 20382] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbjAAAAeg"]
[Thu Sep 17 15:41:29.246913 2026] [security2:error] [pid 20162:tid 20353] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbjwAAAcs"]
[Thu Sep 17 15:41:29.378604 2026] [security2:error] [pid 20162:tid 20315] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbkQAAAaU"]
[Thu Sep 17 15:41:29.481834 2026] [authz_core:error] [pid 20162:tid 20388] [client 40.81.232.68:52875] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:41:29.503669 2026] [security2:error] [pid 20162:tid 20340] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGblQAAAb4"]
[Thu Sep 17 15:41:29.529719 2026] [security2:error] [pid 20162:tid 20360] [client 109.105.210.90:19172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "aqxeia-O_Kk7aqBvaiGbmAAAAdI"]
[Thu Sep 17 15:41:29.612789 2026] [security2:error] [pid 20162:tid 20343] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbmQAAAcE"]
[Thu Sep 17 15:41:29.698256 2026] [security2:error] [pid 20162:tid 20295] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbnAAAAZE"]
[Thu Sep 17 15:41:29.772495 2026] [security2:error] [pid 20162:tid 20322] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbnwAAAaw"]
[Thu Sep 17 15:41:29.892642 2026] [security2:error] [pid 20162:tid 20405] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGboQAAAf8"]
[Thu Sep 17 15:41:29.958494 2026] [security2:error] [pid 20162:tid 20394] [client 136.158.61.34:36607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeia-O_Kk7aqBvaiGbowAAAfQ"]
[Thu Sep 17 15:41:29.958605 2026] [security2:error] [pid 20162:tid 20394] [client 136.158.61.34:36607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeia-O_Kk7aqBvaiGbowAAAfQ"]
[Thu Sep 17 15:41:29.978193 2026] [security2:error] [pid 20162:tid 20390] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxeia-O_Kk7aqBvaiGbpAAAAfA"]
[Thu Sep 17 15:41:30.071156 2026] [security2:error] [pid 20162:tid 20332] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbpQAAAbY"]
[Thu Sep 17 15:41:30.162268 2026] [security2:error] [pid 20162:tid 20409] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbpwAAAgM"]
[Thu Sep 17 15:41:30.266438 2026] [security2:error] [pid 20162:tid 20399] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbqwAAAfk"]
[Thu Sep 17 15:41:30.354695 2026] [security2:error] [pid 20162:tid 20313] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbrgAAAaM"]
[Thu Sep 17 15:41:30.429597 2026] [security2:error] [pid 20162:tid 20413] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbswAAAgc"]
[Thu Sep 17 15:41:30.562524 2026] [security2:error] [pid 20162:tid 20311] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbtQAAAaE"]
[Thu Sep 17 15:41:30.653013 2026] [security2:error] [pid 20162:tid 20345] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbuQAAAcM"]
[Thu Sep 17 15:41:30.867907 2026] [security2:error] [pid 20162:tid 20356] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbvwAAAc4"]
[Thu Sep 17 15:41:30.961751 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxeiq-O_Kk7aqBvaiGbwQAAAZs"]
[Thu Sep 17 15:41:31.065791 2026] [security2:error] [pid 20162:tid 20357] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGbwwAAAc8"]
[Thu Sep 17 15:41:31.181487 2026] [security2:error] [pid 20162:tid 20328] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGbxgAAAbI"]
[Thu Sep 17 15:41:31.302059 2026] [security2:error] [pid 20162:tid 20420] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGbygAAAg4"]
[Thu Sep 17 15:41:31.337856 2026] [security2:error] [pid 20162:tid 20317] [client 109.105.210.87:12074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "aqxei6-O_Kk7aqBvaiGbywAAAac"]
[Thu Sep 17 15:41:31.418379 2026] [security2:error] [pid 20162:tid 20331] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGbzAAAAbU"]
[Thu Sep 17 15:41:31.487545 2026] [security2:error] [pid 20162:tid 20400] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGbzwAAAfo"]
[Thu Sep 17 15:41:31.558241 2026] [security2:error] [pid 20162:tid 20396] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGb0AAAAfY"]
[Thu Sep 17 15:41:31.632446 2026] [security2:error] [pid 20162:tid 20373] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGb1QAAAd8"]
[Thu Sep 17 15:41:31.750676 2026] [security2:error] [pid 20162:tid 20385] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGb2AAAAes"]
[Thu Sep 17 15:41:31.846293 2026] [security2:error] [pid 20162:tid 20353] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxei6-O_Kk7aqBvaiGb2wAAAcs"]
[Thu Sep 17 15:41:31.944669 2026] [security2:error] [pid 20162:tid 20214] [remote 223.109.255.152:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moneysmartlatina.com"] [uri "/latinas-guide-long-distance-love/"] [unique_id "aqxei6-O_Kk7aqBvaiGb3gABojI"]
[Thu Sep 17 15:41:31.944805 2026] [security2:error] [pid 20162:tid 20312] [client 223.109.255.152:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moneysmartlatina.com"] [uri "/latinas-guide-long-distance-love/"] [unique_id "aqxei6-O_Kk7aqBvaiGb3gABojI"]
[Thu Sep 17 15:41:32.010941 2026] [cgid:error] [pid 20162:tid 20367] [client 221.149.119.65:3423] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/Wp
[Thu Sep 17 15:41:32.051477 2026] [security2:error] [pid 20162:tid 20343] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb4gAAAcE"]
[Thu Sep 17 15:41:32.143914 2026] [security2:error] [pid 20162:tid 20395] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb5QAAAfU"]
[Thu Sep 17 15:41:32.215120 2026] [security2:error] [pid 20162:tid 20372] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb5gAAAd4"]
[Thu Sep 17 15:41:32.303713 2026] [security2:error] [pid 20162:tid 20405] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb6gAAAf8"]
[Thu Sep 17 15:41:32.459997 2026] [security2:error] [pid 20162:tid 20414] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb7AAAAgg"]
[Thu Sep 17 15:41:32.545226 2026] [security2:error] [pid 20162:tid 20316] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb7QAAAaY"]
[Thu Sep 17 15:41:32.625195 2026] [security2:error] [pid 20162:tid 20364] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb7gAAAdY"]
[Thu Sep 17 15:41:32.716055 2026] [security2:error] [pid 20162:tid 20370] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb8wAAAdw"]
[Thu Sep 17 15:41:32.717130 2026] [core:error] [pid 20162:tid 20399] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:32.717145 2026] [core:error] [pid 20162:tid 20399] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:32.801783 2026] [core:error] [pid 20162:tid 20212] [remote 74.7.175.190:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:32.801800 2026] [core:error] [pid 20162:tid 20212] [remote 74.7.175.190:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:32.801938 2026] [security2:error] [pid 20162:tid 20308] [client 74.7.175.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.moneysmartlatina.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "aqxejK-O_Kk7aqBvaiGb9wABnjA"]
[Thu Sep 17 15:41:32.820472 2026] [security2:error] [pid 20162:tid 20413] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb-AAAAgc"]
[Thu Sep 17 15:41:32.911842 2026] [security2:error] [pid 20162:tid 20366] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxejK-O_Kk7aqBvaiGb-QAAAdg"]
[Thu Sep 17 15:41:33.029156 2026] [security2:error] [pid 20162:tid 20383] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGb-gAAAek"]
[Thu Sep 17 15:41:33.128726 2026] [security2:error] [pid 20162:tid 20345] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGb_QAAAcM"]
[Thu Sep 17 15:41:33.187350 2026] [security2:error] [pid 20162:tid 20329] [client 169.58.197.253:65216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxeja-O_Kk7aqBvaiGb_gAAAbM"], referer: binance.com
[Thu Sep 17 15:41:33.266092 2026] [security2:error] [pid 20162:tid 20293] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcAgAAAY8"]
[Thu Sep 17 15:41:33.359799 2026] [security2:error] [pid 20162:tid 20387] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcBAAAAe0"]
[Thu Sep 17 15:41:33.430060 2026] [security2:error] [pid 20162:tid 20378] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcCAAAAeQ"]
[Thu Sep 17 15:41:33.500152 2026] [security2:error] [pid 20162:tid 20356] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcCQAAAc4"]
[Thu Sep 17 15:41:33.593013 2026] [security2:error] [pid 20162:tid 20297] [client 14.96.156.146:51933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeja-O_Kk7aqBvaiGcCwAAAZM"]
[Thu Sep 17 15:41:33.593114 2026] [security2:error] [pid 20162:tid 20297] [client 14.96.156.146:51933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeja-O_Kk7aqBvaiGcCwAAAZM"]
[Thu Sep 17 15:41:33.594265 2026] [security2:error] [pid 20162:tid 20344] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcCgAAAcI"]
[Thu Sep 17 15:41:33.686354 2026] [security2:error] [pid 20162:tid 20357] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcDQAAAc8"]
[Thu Sep 17 15:41:33.796787 2026] [security2:error] [pid 20162:tid 20341] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcEAAAAb8"]
[Thu Sep 17 15:41:33.871447 2026] [security2:error] [pid 20162:tid 20321] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcEwAAAas"]
[Thu Sep 17 15:41:33.999320 2026] [security2:error] [pid 20162:tid 20396] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxeja-O_Kk7aqBvaiGcFQAAAfY"]
[Thu Sep 17 15:41:34.097706 2026] [security2:error] [pid 20162:tid 20375] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxejq-O_Kk7aqBvaiGcFwAAAeE"]
[Thu Sep 17 15:41:34.192985 2026] [security2:error] [pid 20162:tid 20339] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxejq-O_Kk7aqBvaiGcGQAAAb0"]
[Thu Sep 17 15:41:34.260539 2026] [security2:error] [pid 20162:tid 20391] [client 109.105.210.88:49204] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "aqxejq-O_Kk7aqBvaiGcHQAAAfE"]
[Thu Sep 17 15:41:34.266173 2026] [security2:error] [pid 20162:tid 20348] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxejq-O_Kk7aqBvaiGcHgAAAcY"]
[Thu Sep 17 15:41:34.602695 2026] [security2:error] [pid 20162:tid 20310] [client 49.0.250.123:39920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxejq-O_Kk7aqBvaiGcJwAAAaA"]
[Thu Sep 17 15:41:34.701372 2026] [security2:error] [pid 20162:tid 20327] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxejq-O_Kk7aqBvaiGcJQAAAbE"]
[Thu Sep 17 15:41:34.875843 2026] [security2:error] [pid 20162:tid 20386] [client 56.10.97.151:47862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxejq-O_Kk7aqBvaiGcLgAAAew"]
[Thu Sep 17 15:41:34.876444 2026] [security2:error] [pid 20162:tid 20385] [client 159.138.122.244:41226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxejq-O_Kk7aqBvaiGcLQAAAes"]
[Thu Sep 17 15:41:35.074385 2026] [security2:error] [pid 20162:tid 20318] [client 149.232.138.84:48424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mechapteriaao.org"] [uri "/index.php"] [unique_id "aqxej6-O_Kk7aqBvaiGcMAAAAag"]
[Thu Sep 17 15:41:35.266279 2026] [security2:error] [pid 20162:tid 20352] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxej6-O_Kk7aqBvaiGcMwAAAco"]
[Thu Sep 17 15:41:35.581291 2026] [security2:error] [pid 20162:tid 20399] [client 34.95.61.66:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxej6-O_Kk7aqBvaiGcPAAAAfk"]
[Thu Sep 17 15:41:35.704402 2026] [security2:error] [pid 20162:tid 20414] [client 177.44.133.72:56051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxej6-O_Kk7aqBvaiGcQAAAAgg"]
[Thu Sep 17 15:41:35.704494 2026] [security2:error] [pid 20162:tid 20414] [client 177.44.133.72:56051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxej6-O_Kk7aqBvaiGcQAAAAgg"]
[Thu Sep 17 15:41:35.774468 2026] [fcgid:warn] [pid 20162:tid 20366] (70014)End of file found: [client 128.1.34.69:59354] mod_fcgid: can't get data from http client
[Thu Sep 17 15:41:35.777971 2026] [core:error] [pid 20162:tid 20313] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:35.777992 2026] [core:error] [pid 20162:tid 20313] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:35.997032 2026] [security2:error] [pid 20162:tid 20309] [client 103.61.184.148:64305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxej6-O_Kk7aqBvaiGcSQAAAZ8"]
[Thu Sep 17 15:41:35.997143 2026] [security2:error] [pid 20162:tid 20309] [client 103.61.184.148:64305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxej6-O_Kk7aqBvaiGcSQAAAZ8"]
[Thu Sep 17 15:41:36.039207 2026] [security2:error] [pid 20162:tid 20330] [client 109.105.210.89:40410] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/groma-canary-not-a-real-plugin/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcSgAAAbQ"]
[Thu Sep 17 15:41:36.079198 2026] [security2:error] [pid 20162:tid 20369] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcTAAAAds"]
[Thu Sep 17 15:41:36.166405 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcTgAAAZs"]
[Thu Sep 17 15:41:36.272251 2026] [security2:error] [pid 20162:tid 20362] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcUQAAAdQ"]
[Thu Sep 17 15:41:36.346627 2026] [security2:error] [pid 20162:tid 20320] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcVAAAAao"]
[Thu Sep 17 15:41:36.426821 2026] [security2:error] [pid 20162:tid 20374] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcVwAAAeA"]
[Thu Sep 17 15:41:36.513757 2026] [security2:error] [pid 20162:tid 20339] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcXAAAAb0"]
[Thu Sep 17 15:41:36.548139 2026] [security2:error] [pid 20162:tid 20326] [client 109.105.210.87:25016] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcXQAAAbA"]
[Thu Sep 17 15:41:36.564919 2026] [security2:error] [pid 20162:tid 20373] [client 109.105.210.87:25022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcXgAAAd8"]
[Thu Sep 17 15:41:36.590398 2026] [security2:error] [pid 20162:tid 20418] [client 109.105.210.90:33504] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcYQAAAgw"]
[Thu Sep 17 15:41:36.594493 2026] [security2:error] [pid 20162:tid 20348] [client 109.105.210.88:49220] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcYgAAAcY"]
[Thu Sep 17 15:41:36.596032 2026] [security2:error] [pid 20162:tid 20382] [client 109.105.210.90:33520] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcYwAAAeg"]
[Thu Sep 17 15:41:36.601107 2026] [security2:error] [pid 20162:tid 20412] [client 109.105.210.87:25034] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcZAAAAgY"]
[Thu Sep 17 15:41:36.619197 2026] [security2:error] [pid 20162:tid 20353] [client 109.105.210.89:40422] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcZQAAAcs"]
[Thu Sep 17 15:41:36.623329 2026] [security2:error] [pid 20162:tid 20306] [client 109.105.210.88:49234] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcZgAAAZw"]
[Thu Sep 17 15:41:36.633348 2026] [security2:error] [pid 20162:tid 20377] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcZwAAAeM"]
[Thu Sep 17 15:41:36.642397 2026] [security2:error] [pid 20162:tid 20312] [client 109.105.210.90:33536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcaAAAAaI"]
[Thu Sep 17 15:41:36.648710 2026] [security2:error] [pid 20162:tid 20298] [client 109.105.210.87:25040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcaQAAAZQ"]
[Thu Sep 17 15:41:36.651486 2026] [security2:error] [pid 20162:tid 20381] [client 109.105.210.88:49250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcawAAAec"]
[Thu Sep 17 15:41:36.700399 2026] [security2:error] [pid 20162:tid 20360] [client 109.105.210.88:49262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcbAAAAdI"]
[Thu Sep 17 15:41:36.711980 2026] [security2:error] [pid 20162:tid 20408] [client 109.105.210.89:40432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcbgAAAgI"]
[Thu Sep 17 15:41:36.724401 2026] [security2:error] [pid 20162:tid 20325] [client 109.105.210.88:49274] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGccAAAAa8"]
[Thu Sep 17 15:41:36.735829 2026] [security2:error] [pid 20162:tid 20395] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGccQAAAfU"]
[Thu Sep 17 15:41:36.746585 2026] [security2:error] [pid 20162:tid 20404] [client 109.105.210.87:25048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGccgAAAf4"]
[Thu Sep 17 15:41:36.747636 2026] [security2:error] [pid 20162:tid 20392] [client 109.105.210.90:33540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGccwAAAfI"]
[Thu Sep 17 15:41:36.751315 2026] [security2:error] [pid 20162:tid 20416] [client 109.105.210.88:49288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcdAAAAgo"]
[Thu Sep 17 15:41:36.760794 2026] [security2:error] [pid 20162:tid 20318] [client 109.105.210.88:49300] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcdgAAAag"]
[Thu Sep 17 15:41:36.780308 2026] [security2:error] [pid 20162:tid 20406] [client 109.105.210.88:49306] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcdwAAAgA"]
[Thu Sep 17 15:41:36.782551 2026] [security2:error] [pid 20162:tid 20335] [client 109.105.210.89:40436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGceAAAAbk"]
[Thu Sep 17 15:41:36.792815 2026] [security2:error] [pid 20162:tid 20352] [client 109.105.210.87:25054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcegAAAco"]
[Thu Sep 17 15:41:36.812477 2026] [security2:error] [pid 20162:tid 20322] [client 109.105.210.87:25062] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcewAAAaw"]
[Thu Sep 17 15:41:36.822010 2026] [security2:error] [pid 20162:tid 20394] [client 109.105.210.88:49322] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcfAAAAfQ"]
[Thu Sep 17 15:41:36.832317 2026] [security2:error] [pid 20162:tid 20334] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGcfQAAAbg"]
[Thu Sep 17 15:41:36.832588 2026] [security2:error] [pid 20162:tid 20364] [client 109.105.210.89:40446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcfgAAAdY"]
[Thu Sep 17 15:41:36.838185 2026] [security2:error] [pid 20162:tid 20324] [client 109.105.210.89:40460] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcfwAAAa4"]
[Thu Sep 17 15:41:36.838999 2026] [security2:error] [pid 20162:tid 20370] [client 109.105.210.90:33544] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcgAAAAdw"]
[Thu Sep 17 15:41:36.862975 2026] [security2:error] [pid 20162:tid 20337] [client 109.105.210.87:25070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcgQAAAbs"]
[Thu Sep 17 15:41:36.875950 2026] [security2:error] [pid 20162:tid 20366] [client 109.105.210.89:40462] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcggAAAdg"]
[Thu Sep 17 15:41:36.888580 2026] [security2:error] [pid 20162:tid 20302] [client 109.105.210.88:49338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGchAAAAZg"]
[Thu Sep 17 15:41:36.888579 2026] [security2:error] [pid 20162:tid 20409] [client 109.105.210.90:33550] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcgwAAAgM"]
[Thu Sep 17 15:41:36.920277 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxekK-O_Kk7aqBvaiGchQAAAZs"]
[Thu Sep 17 15:41:36.923445 2026] [security2:error] [pid 20162:tid 20293] [client 109.105.210.88:49352] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGchgAAAY8"]
[Thu Sep 17 15:41:36.931672 2026] [security2:error] [pid 20162:tid 20294] [client 109.105.210.90:33552] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGciAAAAZA"]
[Thu Sep 17 15:41:36.931708 2026] [security2:error] [pid 20162:tid 20358] [client 109.105.210.88:49364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGciQAAAdA"]
[Thu Sep 17 15:41:36.945312 2026] [security2:error] [pid 20162:tid 20356] [client 109.105.210.87:25084] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGciwAAAc4"]
[Thu Sep 17 15:41:36.968900 2026] [security2:error] [pid 20162:tid 20369] [client 109.105.210.90:33562] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcjQAAAds"]
[Thu Sep 17 15:41:36.980146 2026] [security2:error] [pid 20162:tid 20384] [client 109.105.210.89:40466] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "aqxekK-O_Kk7aqBvaiGcjgAAAeo"]
[Thu Sep 17 15:41:37.003491 2026] [security2:error] [pid 20162:tid 20311] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcjwAAAaE"]
[Thu Sep 17 15:41:37.039477 2026] [security2:error] [pid 20162:tid 20317] [client 109.105.210.88:49378] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGckAAAAac"]
[Thu Sep 17 15:41:37.047095 2026] [security2:error] [pid 20162:tid 20389] [client 109.105.210.89:40468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGckQAAAe8"]
[Thu Sep 17 15:41:37.082440 2026] [security2:error] [pid 20162:tid 20375] [client 109.105.210.88:49382] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGckgAAAeE"]
[Thu Sep 17 15:41:37.104060 2026] [security2:error] [pid 20162:tid 20306] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGclAAAAZw"]
[Thu Sep 17 15:41:37.151107 2026] [security2:error] [pid 20162:tid 20348] [client 109.105.210.89:40470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGclQAAAcY"]
[Thu Sep 17 15:41:37.187183 2026] [security2:error] [pid 20162:tid 20354] [client 109.105.210.87:25098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGclgAAAcw"]
[Thu Sep 17 15:41:37.207614 2026] [security2:error] [pid 20162:tid 20298] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGclwAAAZQ"]
[Thu Sep 17 15:41:37.244118 2026] [security2:error] [pid 20162:tid 20367] [client 109.105.210.89:40480] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcmAAAAdk"]
[Thu Sep 17 15:41:37.253193 2026] [security2:error] [pid 20162:tid 20388] [client 139.170.159.113:59992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "creacity.com"] [uri "/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcmgAAAe4"]
[Thu Sep 17 15:41:37.264185 2026] [security2:error] [pid 20162:tid 20310] [client 109.105.210.88:49384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcnAAAAaA"]
[Thu Sep 17 15:41:37.266804 2026] [security2:error] [pid 20162:tid 20296] [client 109.105.210.90:33568] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcnQAAAZI"]
[Thu Sep 17 15:41:37.267357 2026] [security2:error] [pid 20162:tid 20312] [client 109.105.210.88:49398] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcngAAAaI"]
[Thu Sep 17 15:41:37.272726 2026] [security2:error] [pid 20162:tid 20368] [client 109.105.210.90:33584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcoAAAAdo"]
[Thu Sep 17 15:41:37.284640 2026] [security2:error] [pid 20162:tid 20381] [client 109.105.210.87:25110] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcoQAAAec"]
[Thu Sep 17 15:41:37.296496 2026] [security2:error] [pid 20162:tid 20327] [client 109.105.210.89:40484] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcogAAAbE"]
[Thu Sep 17 15:41:37.299369 2026] [security2:error] [pid 20162:tid 20365] [client 109.105.210.88:49408] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "plasticvisual.tutorialsphere.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "aqxeka-O_Kk7aqBvaiGcowAAAdc"]
[Thu Sep 17 15:41:37.321714 2026] [security2:error] [pid 20162:tid 20410] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcpAAAAgQ"]
[Thu Sep 17 15:41:37.419820 2026] [security2:error] [pid 20162:tid 20403] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcqAAAAf0"]
[Thu Sep 17 15:41:37.494211 2026] [security2:error] [pid 20162:tid 20378] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcqwAAAeQ"]
[Thu Sep 17 15:41:37.516161 2026] [security2:error] [pid 20162:tid 20339] [client 143.105.152.240:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeka-O_Kk7aqBvaiGcrQAAAb0"]
[Thu Sep 17 15:41:37.523955 2026] [security2:error] [pid 20162:tid 20339] [client 143.105.152.240:4184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeka-O_Kk7aqBvaiGcrQAAAb0"]
[Thu Sep 17 15:41:37.572522 2026] [security2:error] [pid 20162:tid 20299] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcrgAAAZU"]
[Thu Sep 17 15:41:37.667978 2026] [security2:error] [pid 20162:tid 20376] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcsQAAAeI"]
[Thu Sep 17 15:41:37.774031 2026] [security2:error] [pid 20162:tid 20313] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGcswAAAaM"]
[Thu Sep 17 15:41:37.888374 2026] [security2:error] [pid 20162:tid 20405] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGctgAAAf8"]
[Thu Sep 17 15:41:37.975865 2026] [security2:error] [pid 20162:tid 20345] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxeka-O_Kk7aqBvaiGctwAAAcM"]
[Thu Sep 17 15:41:38.049287 2026] [security2:error] [pid 20162:tid 20364] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGcuQAAAdY"]
[Thu Sep 17 15:41:38.122016 2026] [security2:error] [pid 20162:tid 20370] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGcuwAAAdw"]
[Thu Sep 17 15:41:38.241552 2026] [security2:error] [pid 20162:tid 20366] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGcwgAAAdg"]
[Thu Sep 17 15:41:38.356771 2026] [security2:error] [pid 20162:tid 20297] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGcxQAAAZM"]
[Thu Sep 17 15:41:38.442186 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGcxgAAAZs"]
[Thu Sep 17 15:41:38.522500 2026] [security2:error] [pid 20162:tid 20357] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGcxwAAAc8"]
[Thu Sep 17 15:41:38.612326 2026] [security2:error] [pid 20162:tid 20356] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGcywAAAc4"]
[Thu Sep 17 15:41:38.693319 2026] [security2:error] [pid 20162:tid 20415] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGczQAAAgk"]
[Thu Sep 17 15:41:38.781154 2026] [security2:error] [pid 20162:tid 20331] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGc0gAAAbU"]
[Thu Sep 17 15:41:38.869558 2026] [security2:error] [pid 20162:tid 20314] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGc1AAAAaQ"]
[Thu Sep 17 15:41:38.945175 2026] [security2:error] [pid 20162:tid 20375] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxekq-O_Kk7aqBvaiGc2gAAAeE"]
[Thu Sep 17 15:41:39.056187 2026] [security2:error] [pid 20162:tid 20306] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc3QAAAZw"]
[Thu Sep 17 15:41:39.235898 2026] [security2:error] [pid 20162:tid 20372] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc4wAAAd4"]
[Thu Sep 17 15:41:39.323830 2026] [security2:error] [pid 20162:tid 20336] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc6AAAAbo"]
[Thu Sep 17 15:41:39.406618 2026] [security2:error] [pid 20162:tid 20419] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc7AAAAg0"]
[Thu Sep 17 15:41:39.512207 2026] [security2:error] [pid 20162:tid 20399] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc7gAAAfk"]
[Thu Sep 17 15:41:39.619013 2026] [security2:error] [pid 20162:tid 20414] [client 169.58.197.251:52367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxek6-O_Kk7aqBvaiGc8AAAAgg"], referer: binance.com
[Thu Sep 17 15:41:39.663456 2026] [security2:error] [pid 20162:tid 20394] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc8gAAAfQ"]
[Thu Sep 17 15:41:39.762002 2026] [security2:error] [pid 20162:tid 20334] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc9AAAAbg"]
[Thu Sep 17 15:41:39.846425 2026] [security2:error] [pid 20162:tid 20393] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc-AAAAfM"]
[Thu Sep 17 15:41:39.917504 2026] [security2:error] [pid 20162:tid 20346] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc-wAAAcQ"]
[Thu Sep 17 15:41:39.997437 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxek6-O_Kk7aqBvaiGc_QAAAZs"]
[Thu Sep 17 15:41:40.106507 2026] [security2:error] [pid 20162:tid 20350] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGc_gAAAcg"]
[Thu Sep 17 15:41:40.245351 2026] [security2:error] [pid 20162:tid 20293] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdAAAAAY8"]
[Thu Sep 17 15:41:40.370882 2026] [security2:error] [pid 20162:tid 20415] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdBAAAAgk"]
[Thu Sep 17 15:41:40.467261 2026] [security2:error] [pid 20162:tid 20344] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdBQAAAcI"]
[Thu Sep 17 15:41:40.562506 2026] [security2:error] [pid 20162:tid 20374] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdBgAAAeA"]
[Thu Sep 17 15:41:40.666598 2026] [security2:error] [pid 20162:tid 20328] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdCQAAAbI"]
[Thu Sep 17 15:41:40.787294 2026] [security2:error] [pid 20162:tid 20314] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdDAAAAaQ"]
[Thu Sep 17 15:41:40.872304 2026] [security2:error] [pid 20162:tid 20300] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdDgAAAZY"]
[Thu Sep 17 15:41:40.982892 2026] [security2:error] [pid 20162:tid 20382] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxelK-O_Kk7aqBvaiGdEQAAAeg"]
[Thu Sep 17 15:41:41.053346 2026] [security2:error] [pid 20162:tid 20407] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdEgAAAgE"]
[Thu Sep 17 15:41:41.136108 2026] [security2:error] [pid 20162:tid 20348] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdFAAAAcY"]
[Thu Sep 17 15:41:41.239931 2026] [security2:error] [pid 20162:tid 20360] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdFgAAAdI"]
[Thu Sep 17 15:41:41.328028 2026] [security2:error] [pid 20162:tid 20303] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdGgAAAZk"]
[Thu Sep 17 15:41:41.411303 2026] [security2:error] [pid 20162:tid 20365] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdHgAAAdc"]
[Thu Sep 17 15:41:41.530808 2026] [security2:error] [pid 20162:tid 20359] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdIAAAAdE"]
[Thu Sep 17 15:41:41.607864 2026] [security2:error] [pid 20162:tid 20316] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdIQAAAaY"]
[Thu Sep 17 15:41:41.741077 2026] [security2:error] [pid 20162:tid 20412] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdIwAAAgY"]
[Thu Sep 17 15:41:41.816447 2026] [security2:error] [pid 20162:tid 20391] [client 34.95.61.66:50856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxela-O_Kk7aqBvaiGdJwAAAfE"]
[Thu Sep 17 15:41:41.904581 2026] [security2:error] [pid 20162:tid 20397] [client 34.95.61.66:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxela-O_Kk7aqBvaiGdKAAAAfc"]
[Thu Sep 17 15:41:42.240684 2026] [security2:error] [pid 20162:tid 20414] [client 34.95.61.66:54984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/info.php"] [unique_id "aqxelq-O_Kk7aqBvaiGdMAAAAgg"]
[Thu Sep 17 15:41:42.523712 2026] [security2:error] [pid 20162:tid 20322] [client 34.95.61.66:54998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/php.php"] [unique_id "aqxelq-O_Kk7aqBvaiGdNQAAAaw"]
[Thu Sep 17 15:41:42.625814 2026] [security2:error] [pid 20162:tid 20355] [client 136.158.61.34:37745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxelq-O_Kk7aqBvaiGdNgAAAc0"]
[Thu Sep 17 15:41:42.626468 2026] [security2:error] [pid 20162:tid 20355] [client 136.158.61.34:37745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxelq-O_Kk7aqBvaiGdNgAAAc0"]
[Thu Sep 17 15:41:42.796600 2026] [security2:error] [pid 20162:tid 20364] [client 34.95.61.66:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/i.php"] [unique_id "aqxelq-O_Kk7aqBvaiGdPQAAAdY"]
[Thu Sep 17 15:41:43.087802 2026] [security2:error] [pid 20162:tid 20398] [client 34.95.61.66:55012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxel6-O_Kk7aqBvaiGdQgAAAfg"]
[Thu Sep 17 15:41:43.396033 2026] [security2:error] [pid 20162:tid 20328] [client 34.95.61.66:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxel6-O_Kk7aqBvaiGdRwAAAbI"]
[Thu Sep 17 15:41:43.476815 2026] [security2:error] [pid 20162:tid 20320] [client 169.58.197.253:49425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxel6-O_Kk7aqBvaiGdSAAAAao"], referer: binance.com
[Thu Sep 17 15:41:43.619303 2026] [security2:error] [pid 20162:tid 20363] [client 4.240.114.86:63432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jwdnyc.com"] [uri "/wp-login.php"] [unique_id "aqxel6-O_Kk7aqBvaiGdSwAAAdU"], referer: binance.com
[Thu Sep 17 15:41:43.694441 2026] [security2:error] [pid 20162:tid 20304] [client 34.95.61.66:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/test.php"] [unique_id "aqxel6-O_Kk7aqBvaiGdTQAAAZo"]
[Thu Sep 17 15:41:44.403430 2026] [security2:error] [pid 20162:tid 20340] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxemK-O_Kk7aqBvaiGdXAAAAb4"]
[Thu Sep 17 15:41:44.450773 2026] [security2:error] [pid 20162:tid 20365] [client 14.96.156.146:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxemK-O_Kk7aqBvaiGdZAAAAdc"]
[Thu Sep 17 15:41:44.450889 2026] [security2:error] [pid 20162:tid 20365] [client 14.96.156.146:52587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxemK-O_Kk7aqBvaiGdZAAAAdc"]
[Thu Sep 17 15:41:44.469076 2026] [authz_core:error] [pid 20162:tid 20418] [client 40.81.232.68:65148] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Thu Sep 17 15:41:44.727534 2026] [security2:error] [pid 20162:tid 20312] [client 34.95.61.66:55034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/p.php"] [unique_id "aqxemK-O_Kk7aqBvaiGdaQAAAaI"]
[Thu Sep 17 15:41:45.074692 2026] [security2:error] [pid 20162:tid 20395] [client 34.95.61.66:55040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxema-O_Kk7aqBvaiGdbgAAAfU"]
[Thu Sep 17 15:41:45.398325 2026] [security2:error] [pid 20162:tid 20349] [client 34.95.61.66:55052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxema-O_Kk7aqBvaiGddwAAAcc"]
[Thu Sep 17 15:41:45.740218 2026] [security2:error] [pid 20162:tid 20350] [client 34.95.61.66:55054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxema-O_Kk7aqBvaiGdfwAAAcg"]
[Thu Sep 17 15:41:45.915319 2026] [core:error] [pid 20162:tid 20319] [client 66.132.172.142:44306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:45.915342 2026] [core:error] [pid 20162:tid 20319] [client 66.132.172.142:44306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:46.043792 2026] [security2:error] [pid 20162:tid 20387] [client 34.95.61.66:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxemq-O_Kk7aqBvaiGdggAAAe0"]
[Thu Sep 17 15:41:46.241859 2026] [security2:error] [pid 20162:tid 20167] [remote 110.249.201.217:59654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cult.cyberpunkonline.net"] [uri "/geffine/GEFFINE-004.txt"] [unique_id "aqxemq-O_Kk7aqBvaiGdiAABpAM"]
[Thu Sep 17 15:41:46.264151 2026] [security2:error] [pid 20162:tid 20320] [client 74.7.244.8:52090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.tesselessetbooks.com"] [uri "/robots.txt"] [unique_id "aqxemq-O_Kk7aqBvaiGdigABqn8"]
[Thu Sep 17 15:41:46.338343 2026] [security2:error] [pid 20162:tid 20321] [client 177.44.133.72:56723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxemq-O_Kk7aqBvaiGdjAAAAas"]
[Thu Sep 17 15:41:46.338468 2026] [security2:error] [pid 20162:tid 20321] [client 177.44.133.72:56723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxemq-O_Kk7aqBvaiGdjAAAAas"]
[Thu Sep 17 15:41:46.340116 2026] [security2:error] [pid 20162:tid 20206] [remote 47.128.23.33:16550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "casualchessclub.com"] [uri "/robots.txt"] [unique_id "aqxemq-O_Kk7aqBvaiGdjQAB6Co"]
[Thu Sep 17 15:41:46.429783 2026] [security2:error] [pid 20162:tid 20304] [client 34.95.61.66:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxemq-O_Kk7aqBvaiGdjgAAAZo"]
[Thu Sep 17 15:41:46.742558 2026] [security2:error] [pid 20162:tid 20316] [client 34.95.61.66:55096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxemq-O_Kk7aqBvaiGdlgAAAaY"]
[Thu Sep 17 15:41:46.796675 2026] [security2:error] [pid 20162:tid 20375] [client 103.61.184.148:64882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxemq-O_Kk7aqBvaiGdlwAAAeE"]
[Thu Sep 17 15:41:46.796791 2026] [security2:error] [pid 20162:tid 20375] [client 103.61.184.148:64882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxemq-O_Kk7aqBvaiGdlwAAAeE"]
[Thu Sep 17 15:41:47.082617 2026] [security2:error] [pid 20162:tid 20389] [client 34.95.61.66:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxem6-O_Kk7aqBvaiGdmwAAAe8"]
[Thu Sep 17 15:41:47.492087 2026] [security2:error] [pid 20162:tid 20413] [client 169.58.197.251:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxem6-O_Kk7aqBvaiGdpQAAAgc"], referer: binance.com
[Thu Sep 17 15:41:47.647583 2026] [security2:error] [pid 20162:tid 20383] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxem6-O_Kk7aqBvaiGdpAAAAek"]
[Thu Sep 17 15:41:47.836644 2026] [authz_core:error] [pid 20162:tid 20347] [client 169.58.197.253:0] AH01630: client denied by server configuration: /home4/ccrmedia/public_html/p3collaborative/wp-content/uploads/wpcf7_uploads/, referer: binance.com
[Thu Sep 17 15:41:48.000297 2026] [security2:error] [pid 20162:tid 20415] [client 34.95.61.66:55118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxem6-O_Kk7aqBvaiGduQAAAgk"]
[Thu Sep 17 15:41:48.069606 2026] [security2:error] [pid 20162:tid 20392] [client 143.105.152.240:32384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxenK-O_Kk7aqBvaiGduwAAAfI"]
[Thu Sep 17 15:41:48.077393 2026] [security2:error] [pid 20162:tid 20392] [client 143.105.152.240:32384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxenK-O_Kk7aqBvaiGduwAAAfI"]
[Thu Sep 17 15:41:48.298841 2026] [security2:error] [pid 20162:tid 20344] [client 34.95.61.66:55132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxenK-O_Kk7aqBvaiGd0AAAAcI"]
[Thu Sep 17 15:41:48.384954 2026] [security2:error] [pid 20162:tid 20363] [client 162.241.226.11:27952] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxenK-O_Kk7aqBvaiGd3AAAAdU"]
[Thu Sep 17 15:41:48.486965 2026] [security2:error] [pid 20162:tid 20333] [client 34.26.62.32:38018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/"] [unique_id "aqxenK-O_Kk7aqBvaiGd8QAAAbc"]
[Thu Sep 17 15:41:48.670279 2026] [security2:error] [pid 20162:tid 20388] [client 34.95.61.66:55134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxenK-O_Kk7aqBvaiGd8wAAAe4"]
[Thu Sep 17 15:41:48.700456 2026] [security2:error] [pid 20162:tid 20331] [client 34.26.62.32:38020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/"] [unique_id "aqxenK-O_Kk7aqBvaiGd9AAAAbU"]
[Thu Sep 17 15:41:48.928021 2026] [security2:error] [pid 20162:tid 20419] [client 34.26.62.32:38024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/"] [unique_id "aqxenK-O_Kk7aqBvaiGeCQAAAg0"]
[Thu Sep 17 15:41:48.997553 2026] [security2:error] [pid 20162:tid 20303] [client 34.95.61.66:55146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxenK-O_Kk7aqBvaiGeCwAAAZk"]
[Thu Sep 17 15:41:49.269760 2026] [security2:error] [pid 20162:tid 20399] [client 34.95.61.66:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxena-O_Kk7aqBvaiGeIAAAAfk"]
[Thu Sep 17 15:41:49.300382 2026] [security2:error] [pid 20162:tid 20335] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxena-O_Kk7aqBvaiGeFQAAAbk"]
[Thu Sep 17 15:41:49.303524 2026] [security2:error] [pid 20162:tid 20412] [client 79.116.89.151:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxena-O_Kk7aqBvaiGeIQAAAgY"]
[Thu Sep 17 15:41:49.303787 2026] [security2:error] [pid 20162:tid 20412] [client 79.116.89.151:60298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxena-O_Kk7aqBvaiGeIQAAAgY"]
[Thu Sep 17 15:41:49.376182 2026] [security2:error] [pid 20162:tid 20305] [client 34.26.62.32:38026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/"] [unique_id "aqxena-O_Kk7aqBvaiGeJgAAAZs"]
[Thu Sep 17 15:41:49.554529 2026] [security2:error] [pid 20162:tid 20393] [client 34.95.61.66:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxena-O_Kk7aqBvaiGeKQAAAfM"]
[Thu Sep 17 15:41:49.564043 2026] [security2:error] [pid 20162:tid 20330] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/.env"] [unique_id "aqxena-O_Kk7aqBvaiGeKwAAAbQ"]
[Thu Sep 17 15:41:49.754272 2026] [security2:error] [pid 20162:tid 20369] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxena-O_Kk7aqBvaiGeLwAAAds"]
[Thu Sep 17 15:41:49.939497 2026] [security2:error] [pid 20162:tid 20363] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxena-O_Kk7aqBvaiGeNQAAAdU"]
[Thu Sep 17 15:41:50.137030 2026] [security2:error] [pid 20162:tid 20311] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGeOwAAAaE"]
[Thu Sep 17 15:41:50.138051 2026] [security2:error] [pid 20162:tid 20342] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxena-O_Kk7aqBvaiGeOAAAAcA"]
[Thu Sep 17 15:41:50.365534 2026] [security2:error] [pid 20162:tid 20359] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGeRwAAAdE"]
[Thu Sep 17 15:41:50.627896 2026] [security2:error] [pid 20162:tid 20298] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGeTQAAAZQ"]
[Thu Sep 17 15:41:50.786537 2026] [security2:error] [pid 20162:tid 20310] [client 34.95.61.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGeUQAAAaA"]
[Thu Sep 17 15:41:50.886671 2026] [security2:error] [pid 20162:tid 20380] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGeWAAAAeY"]
[Thu Sep 17 15:41:50.957517 2026] [security2:error] [pid 20162:tid 20383] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxenq-O_Kk7aqBvaiGeWgAAAek"]
[Thu Sep 17 15:41:51.034534 2026] [security2:error] [pid 20162:tid 20413] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxen6-O_Kk7aqBvaiGeXAAAAgc"]
[Thu Sep 17 15:41:51.075580 2026] [security2:error] [pid 20162:tid 20395] [client 34.95.61.66:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxen6-O_Kk7aqBvaiGeXwAAAfU"]
[Thu Sep 17 15:41:51.208230 2026] [security2:error] [pid 20162:tid 20305] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxen6-O_Kk7aqBvaiGeYwAAAZs"]
[Thu Sep 17 15:41:51.290879 2026] [security2:error] [pid 20162:tid 20315] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxen6-O_Kk7aqBvaiGeaAAAAaU"]
[Thu Sep 17 15:41:51.468004 2026] [security2:error] [pid 20162:tid 20398] [client 34.95.61.66:46572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxen6-O_Kk7aqBvaiGecQAAAfg"]
[Thu Sep 17 15:41:51.487440 2026] [security2:error] [pid 20162:tid 20349] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxen6-O_Kk7aqBvaiGeawAAAcc"]
[Thu Sep 17 15:41:51.524280 2026] [security2:error] [pid 20162:tid 20377] [client 204.14.250.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGePgAAAeM"], referer: https://facebook.com/
[Thu Sep 17 15:41:51.524298 2026] [security2:error] [pid 20162:tid 20406] [client 204.14.250.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGeTgAAAgA"], referer: http://m.facebook.com
[Thu Sep 17 15:41:51.686778 2026] [security2:error] [pid 20162:tid 20384] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxen6-O_Kk7aqBvaiGedgAAAeo"]
[Thu Sep 17 15:41:51.801815 2026] [security2:error] [pid 20162:tid 20363] [client 34.95.61.66:46578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxen6-O_Kk7aqBvaiGeewAAAdU"]
[Thu Sep 17 15:41:51.911418 2026] [core:error] [pid 20162:tid 20376] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:51.911437 2026] [core:error] [pid 20162:tid 20376] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:52.160793 2026] [security2:error] [pid 20162:tid 20348] [client 34.95.61.66:46584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxeoK-O_Kk7aqBvaiGeggAAAcY"]
[Thu Sep 17 15:41:52.424928 2026] [core:error] [pid 20162:tid 20400] [client 34.95.193.102:45624] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:52.424946 2026] [core:error] [pid 20162:tid 20400] [client 34.95.193.102:45624] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:52.506268 2026] [security2:error] [pid 20162:tid 20340] [client 34.95.61.66:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxeoK-O_Kk7aqBvaiGeiQAAAb4"]
[Thu Sep 17 15:41:52.704951 2026] [security2:error] [pid 20162:tid 20318] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoK-O_Kk7aqBvaiGejQAAAag"]
[Thu Sep 17 15:41:52.761789 2026] [security2:error] [pid 20162:tid 20373] [client 34.95.61.66:46600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxeoK-O_Kk7aqBvaiGejwAAAd8"]
[Thu Sep 17 15:41:52.835267 2026] [security2:error] [pid 20162:tid 20333] [client 116.179.32.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxenq-O_Kk7aqBvaiGeQQABtxE"]
[Thu Sep 17 15:41:52.915033 2026] [core:error] [pid 20162:tid 20365] [client 34.95.193.102:45640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:52.915055 2026] [core:error] [pid 20162:tid 20365] [client 34.95.193.102:45640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:52.935119 2026] [security2:error] [pid 20162:tid 20378] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoK-O_Kk7aqBvaiGelwAAAeQ"]
[Thu Sep 17 15:41:53.068888 2026] [security2:error] [pid 20162:tid 20380] [client 34.95.61.66:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxeoa-O_Kk7aqBvaiGemwAAAeY"]
[Thu Sep 17 15:41:53.168885 2026] [security2:error] [pid 20162:tid 20395] [client 169.58.197.253:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxeoa-O_Kk7aqBvaiGengAAAfU"], referer: binance.com
[Thu Sep 17 15:41:53.178789 2026] [security2:error] [pid 20162:tid 20410] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoa-O_Kk7aqBvaiGenAAAAgQ"]
[Thu Sep 17 15:41:53.367602 2026] [security2:error] [pid 20162:tid 20416] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoa-O_Kk7aqBvaiGeowAAAgo"]
[Thu Sep 17 15:41:53.408898 2026] [core:error] [pid 20162:tid 20302] [client 34.95.193.102:45656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:53.408919 2026] [core:error] [pid 20162:tid 20302] [client 34.95.193.102:45656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:53.453724 2026] [security2:error] [pid 20162:tid 20393] [client 34.95.61.66:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxeoa-O_Kk7aqBvaiGerAAAAfM"]
[Thu Sep 17 15:41:53.608684 2026] [security2:error] [pid 20162:tid 20349] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoa-O_Kk7aqBvaiGergAAAcc"]
[Thu Sep 17 15:41:53.727268 2026] [security2:error] [pid 20162:tid 20392] [client 34.95.61.66:46624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxeoa-O_Kk7aqBvaiGeswAAAfI"]
[Thu Sep 17 15:41:53.825906 2026] [security2:error] [pid 20162:tid 20402] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoa-O_Kk7aqBvaiGetQAAAfw"]
[Thu Sep 17 15:41:53.944728 2026] [security2:error] [pid 20162:tid 20387] [client 216.73.216.134:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.caitlinannemack.com"] [uri "/pages.php/sitemap316.xml"] [unique_id "aqxeoa-O_Kk7aqBvaiGeugAAAe0"]
[Thu Sep 17 15:41:53.952710 2026] [security2:error] [pid 20162:tid 20386] [client 169.58.197.251:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxeoa-O_Kk7aqBvaiGeuwAAAew"], referer: binance.com
[Thu Sep 17 15:41:53.966226 2026] [core:error] [pid 20162:tid 20357] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:53.966249 2026] [core:error] [pid 20162:tid 20357] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:54.116418 2026] [security2:error] [pid 20162:tid 20334] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoq-O_Kk7aqBvaiGevwAAAbg"]
[Thu Sep 17 15:41:54.184187 2026] [security2:error] [pid 20162:tid 20300] [client 34.95.61.66:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxeoq-O_Kk7aqBvaiGewQAAAZY"]
[Thu Sep 17 15:41:54.332805 2026] [security2:error] [pid 20162:tid 20311] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoq-O_Kk7aqBvaiGexAAAAaE"]
[Thu Sep 17 15:41:54.497807 2026] [core:error] [pid 20162:tid 20417] [client 34.95.193.102:58554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:54.497825 2026] [core:error] [pid 20162:tid 20417] [client 34.95.193.102:58554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:54.532178 2026] [security2:error] [pid 20162:tid 20381] [client 34.95.61.66:46636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxeoq-O_Kk7aqBvaiGezAAAAec"]
[Thu Sep 17 15:41:54.579219 2026] [security2:error] [pid 20162:tid 20356] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoq-O_Kk7aqBvaiGeygAAAc4"]
[Thu Sep 17 15:41:54.700391 2026] [security2:error] [pid 20162:tid 20303] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxeoq-O_Kk7aqBvaiGezwAAAZk"]
[Thu Sep 17 15:41:54.763541 2026] [security2:error] [pid 20162:tid 20365] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/.env~"] [unique_id "aqxeoq-O_Kk7aqBvaiGe0gAAAdc"]
[Thu Sep 17 15:41:54.849926 2026] [security2:error] [pid 20162:tid 20418] [client 34.95.61.66:46646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxeoq-O_Kk7aqBvaiGe1gAAAgw"]
[Thu Sep 17 15:41:54.954759 2026] [security2:error] [pid 20162:tid 20403] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeoq-O_Kk7aqBvaiGe2AAAAf0"]
[Thu Sep 17 15:41:54.998996 2026] [security2:error] [pid 20162:tid 20394] [client 34.95.193.102:58568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "aqxeoq-O_Kk7aqBvaiGe2wAAAfQ"]
[Thu Sep 17 15:41:55.118516 2026] [security2:error] [pid 20162:tid 20391] [client 14.96.156.146:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGe5gAAAfE"]
[Thu Sep 17 15:41:55.118613 2026] [security2:error] [pid 20162:tid 20391] [client 14.96.156.146:53246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGe5gAAAfE"]
[Thu Sep 17 15:41:55.125806 2026] [security2:error] [pid 20162:tid 20364] [client 34.95.61.66:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGe5wAAAdY"]
[Thu Sep 17 15:41:55.182255 2026] [security2:error] [pid 20162:tid 20329] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGe4AAAAbM"]
[Thu Sep 17 15:41:55.199055 2026] [core:error] [pid 20162:tid 20325] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:55.199070 2026] [core:error] [pid 20162:tid 20325] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:55.411755 2026] [security2:error] [pid 20162:tid 20392] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGe8wAAAfI"]
[Thu Sep 17 15:41:55.418649 2026] [security2:error] [pid 20162:tid 20398] [client 34.95.61.66:46662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGe_wAAAfg"]
[Thu Sep 17 15:41:55.591546 2026] [security2:error] [pid 20162:tid 20313] [client 136.158.61.34:39064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGfAwAAAaM"]
[Thu Sep 17 15:41:55.591644 2026] [security2:error] [pid 20162:tid 20313] [client 136.158.61.34:39064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGfAwAAAaM"]
[Thu Sep 17 15:41:55.780548 2026] [core:error] [pid 20162:tid 20405] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:55.780563 2026] [core:error] [pid 20162:tid 20405] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:55.786414 2026] [security2:error] [pid 20162:tid 20363] [client 34.95.61.66:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGfCwAAAdU"]
[Thu Sep 17 15:41:56.060179 2026] [security2:error] [pid 20162:tid 20419] [client 34.95.61.66:46678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxepK-O_Kk7aqBvaiGfFQAAAg0"]
[Thu Sep 17 15:41:56.074210 2026] [security2:error] [pid 20162:tid 20331] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeo6-O_Kk7aqBvaiGfEwAAAbU"]
[Thu Sep 17 15:41:56.322726 2026] [security2:error] [pid 20162:tid 20396] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxepK-O_Kk7aqBvaiGfGQAAAfY"]
[Thu Sep 17 15:41:56.326277 2026] [security2:error] [pid 20162:tid 20404] [client 34.95.61.66:46690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxepK-O_Kk7aqBvaiGfIAAAAf4"]
[Thu Sep 17 15:41:56.459886 2026] [security2:error] [pid 20162:tid 20383] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxepK-O_Kk7aqBvaiGfIwAAAek"]
[Thu Sep 17 15:41:56.466026 2026] [core:error] [pid 20162:tid 20394] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:56.466043 2026] [core:error] [pid 20162:tid 20394] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:56.520216 2026] [security2:error] [pid 20162:tid 20416] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxepK-O_Kk7aqBvaiGfJgAAAgo"]
[Thu Sep 17 15:41:56.574801 2026] [security2:error] [pid 20162:tid 20329] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxepK-O_Kk7aqBvaiGfKAAAAbM"]
[Thu Sep 17 15:41:56.629525 2026] [security2:error] [pid 20162:tid 20352] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxepK-O_Kk7aqBvaiGfKgAAAco"]
[Thu Sep 17 15:41:56.651293 2026] [security2:error] [pid 20162:tid 20347] [client 34.95.61.66:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxepK-O_Kk7aqBvaiGfLAAAAcU"]
[Thu Sep 17 15:41:56.692275 2026] [security2:error] [pid 20162:tid 20358] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxepK-O_Kk7aqBvaiGfLQAAAdA"]
[Thu Sep 17 15:41:56.765765 2026] [security2:error] [pid 20162:tid 20308] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxepK-O_Kk7aqBvaiGfMAAAAZ4"]
[Thu Sep 17 15:41:56.912119 2026] [security2:error] [pid 20162:tid 20332] [client 34.95.61.66:46720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxepK-O_Kk7aqBvaiGfNgAAAbY"]
[Thu Sep 17 15:41:56.982340 2026] [security2:error] [pid 20162:tid 20302] [client 177.44.133.72:57497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxepK-O_Kk7aqBvaiGfOwAAAZg"]
[Thu Sep 17 15:41:56.982434 2026] [security2:error] [pid 20162:tid 20302] [client 177.44.133.72:57497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxepK-O_Kk7aqBvaiGfOwAAAZg"]
[Thu Sep 17 15:41:57.181546 2026] [core:error] [pid 20162:tid 20357] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:57.181572 2026] [core:error] [pid 20162:tid 20357] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:57.244068 2026] [security2:error] [pid 20162:tid 20294] [client 34.95.61.66:46734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxepa-O_Kk7aqBvaiGfRgAAAZA"]
[Thu Sep 17 15:41:57.279624 2026] [security2:error] [pid 20162:tid 20386] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxepa-O_Kk7aqBvaiGfQgAAAew"]
[Thu Sep 17 15:41:57.401481 2026] [security2:error] [pid 20162:tid 20387] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfTQAAAe0"]
[Thu Sep 17 15:41:57.456038 2026] [security2:error] [pid 20162:tid 20324] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfTgAAAa4"]
[Thu Sep 17 15:41:57.511274 2026] [security2:error] [pid 20162:tid 20376] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfTwAAAeI"]
[Thu Sep 17 15:41:57.573398 2026] [security2:error] [pid 20162:tid 20348] [client 34.95.61.66:46742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxepa-O_Kk7aqBvaiGfUgAAAcY"]
[Thu Sep 17 15:41:57.581991 2026] [security2:error] [pid 20162:tid 20417] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfUwAAAgs"]
[Thu Sep 17 15:41:57.635172 2026] [security2:error] [pid 20162:tid 20316] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfVQAAAaY"]
[Thu Sep 17 15:41:57.688960 2026] [security2:error] [pid 20162:tid 20331] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfVgAAAbU"]
[Thu Sep 17 15:41:57.743385 2026] [core:error] [pid 20162:tid 20312] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:57.743402 2026] [core:error] [pid 20162:tid 20312] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:57.748504 2026] [security2:error] [pid 20162:tid 20395] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfXAAAAfU"]
[Thu Sep 17 15:41:57.803729 2026] [security2:error] [pid 20162:tid 20305] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfYgAAAZs"]
[Thu Sep 17 15:41:57.821503 2026] [security2:error] [pid 20162:tid 20378] [client 34.95.61.66:46758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxepa-O_Kk7aqBvaiGfYwAAAeQ"]
[Thu Sep 17 15:41:57.865694 2026] [security2:error] [pid 20162:tid 20416] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfZAAAAgo"]
[Thu Sep 17 15:41:57.926738 2026] [security2:error] [pid 20162:tid 20293] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfZwAAAY8"]
[Thu Sep 17 15:41:57.984274 2026] [security2:error] [pid 20162:tid 20397] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxepa-O_Kk7aqBvaiGfaAAAAfc"]
[Thu Sep 17 15:41:58.050144 2026] [security2:error] [pid 20162:tid 20352] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfagAAAco"]
[Thu Sep 17 15:41:58.107206 2026] [security2:error] [pid 20162:tid 20358] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfbAAAAdA"]
[Thu Sep 17 15:41:58.160894 2026] [security2:error] [pid 20162:tid 20368] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfbwAAAdo"]
[Thu Sep 17 15:41:58.168425 2026] [security2:error] [pid 20162:tid 20346] [client 34.95.61.66:46772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxepq-O_Kk7aqBvaiGfcAAAAcQ"]
[Thu Sep 17 15:41:58.227380 2026] [security2:error] [pid 20162:tid 20315] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfcQAAAaU"]
[Thu Sep 17 15:41:58.266820 2026] [core:error] [pid 20162:tid 20321] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:58.266846 2026] [core:error] [pid 20162:tid 20321] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:58.298166 2026] [security2:error] [pid 20162:tid 20377] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfeAAAAeM"]
[Thu Sep 17 15:41:58.358224 2026] [security2:error] [pid 20162:tid 20337] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfewAAAbs"]
[Thu Sep 17 15:41:58.412223 2026] [security2:error] [pid 20162:tid 20351] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGffAAAAck"]
[Thu Sep 17 15:41:58.467514 2026] [security2:error] [pid 20162:tid 20313] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfgAAAAaM"]
[Thu Sep 17 15:41:58.470261 2026] [security2:error] [pid 20162:tid 20317] [client 34.95.61.66:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxepq-O_Kk7aqBvaiGfgQAAAac"]
[Thu Sep 17 15:41:58.538171 2026] [security2:error] [pid 20162:tid 20385] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfggAAAes"]
[Thu Sep 17 15:41:58.594457 2026] [security2:error] [pid 20162:tid 20360] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfgwAAAdI"]
[Thu Sep 17 15:41:58.650044 2026] [security2:error] [pid 20162:tid 20386] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfhQAAAew"]
[Thu Sep 17 15:41:58.698480 2026] [security2:error] [pid 20162:tid 20339] [client 143.105.152.240:41159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxepq-O_Kk7aqBvaiGfhgAAAb0"]
[Thu Sep 17 15:41:58.712737 2026] [security2:error] [pid 20162:tid 20311] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfhwAAAaE"]
[Thu Sep 17 15:41:58.724732 2026] [security2:error] [pid 20162:tid 20339] [client 143.105.152.240:41159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxepq-O_Kk7aqBvaiGfhgAAAb0"]
[Thu Sep 17 15:41:58.763119 2026] [security2:error] [pid 20162:tid 20344] [client 34.95.61.66:46788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.61.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-7899391b.hym.qby.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxepq-O_Kk7aqBvaiGfigAAAcI"]
[Thu Sep 17 15:41:58.763996 2026] [security2:error] [pid 20162:tid 20342] [client 34.95.193.102:58616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "aqxepq-O_Kk7aqBvaiGfiQAAAcA"]
[Thu Sep 17 15:41:58.775934 2026] [security2:error] [pid 20162:tid 20341] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfiwAAAb8"]
[Thu Sep 17 15:41:58.829680 2026] [security2:error] [pid 20162:tid 20376] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfkAAAAeI"]
[Thu Sep 17 15:41:58.888835 2026] [security2:error] [pid 20162:tid 20296] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGfkQAAAZI"]
[Thu Sep 17 15:41:58.930203 2026] [security2:error] [pid 20162:tid 20420] [client 34.95.193.102:58616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "aqxepq-O_Kk7aqBvaiGfkgAAAg4"]
[Thu Sep 17 15:41:58.961175 2026] [security2:error] [pid 20162:tid 20392] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxepq-O_Kk7aqBvaiGflgAAAfI"]
[Thu Sep 17 15:41:59.019984 2026] [security2:error] [pid 20162:tid 20298] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGflwAAAZQ"]
[Thu Sep 17 15:41:59.078435 2026] [security2:error] [pid 20162:tid 20323] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfmAAAAa0"]
[Thu Sep 17 15:41:59.123036 2026] [core:error] [pid 20162:tid 20295] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:59.123049 2026] [core:error] [pid 20162:tid 20295] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:59.131997 2026] [security2:error] [pid 20162:tid 20409] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfngAAAgM"]
[Thu Sep 17 15:41:59.187303 2026] [security2:error] [pid 20162:tid 20303] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfoAAAAZk"]
[Thu Sep 17 15:41:59.254882 2026] [security2:error] [pid 20162:tid 20353] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfoQAAAcs"]
[Thu Sep 17 15:41:59.310745 2026] [security2:error] [pid 20162:tid 20407] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfqAAAAgE"]
[Thu Sep 17 15:41:59.371063 2026] [security2:error] [pid 20162:tid 20379] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfqwAAAeU"]
[Thu Sep 17 15:41:59.426552 2026] [security2:error] [pid 20162:tid 20410] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfrQAAAgQ"]
[Thu Sep 17 15:41:59.430950 2026] [security2:error] [pid 20162:tid 20417] [client 103.61.184.148:49160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxep6-O_Kk7aqBvaiGfrgAAAgs"]
[Thu Sep 17 15:41:59.431025 2026] [security2:error] [pid 20162:tid 20417] [client 103.61.184.148:49160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxep6-O_Kk7aqBvaiGfrgAAAgs"]
[Thu Sep 17 15:41:59.480512 2026] [security2:error] [pid 20162:tid 20378] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfswAAAeQ"]
[Thu Sep 17 15:41:59.542296 2026] [security2:error] [pid 20162:tid 20408] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGftQAAAgI"]
[Thu Sep 17 15:41:59.596007 2026] [security2:error] [pid 20162:tid 20355] [client 34.26.62.32:38038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGftgAAAc0"]
[Thu Sep 17 15:41:59.641315 2026] [security2:error] [pid 20162:tid 20305] [client 34.95.193.102:58628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "aqxep6-O_Kk7aqBvaiGfuQAAAZs"]
[Thu Sep 17 15:41:59.819484 2026] [security2:error] [pid 20162:tid 20364] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfwgAAAdY"]
[Thu Sep 17 15:41:59.824365 2026] [core:error] [pid 20162:tid 20394] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:59.824380 2026] [core:error] [pid 20162:tid 20394] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:41:59.881505 2026] [security2:error] [pid 20162:tid 20308] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfxAAAAZ4"]
[Thu Sep 17 15:41:59.938344 2026] [security2:error] [pid 20162:tid 20325] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfxgAAAa8"]
[Thu Sep 17 15:41:59.983907 2026] [security2:error] [pid 20162:tid 20403] [client 79.116.89.151:60875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxep6-O_Kk7aqBvaiGfygAAAf0"]
[Thu Sep 17 15:41:59.984022 2026] [security2:error] [pid 20162:tid 20403] [client 79.116.89.151:60875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxep6-O_Kk7aqBvaiGfygAAAf0"]
[Thu Sep 17 15:41:59.994693 2026] [security2:error] [pid 20162:tid 20297] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxep6-O_Kk7aqBvaiGfywAAAZM"]
[Thu Sep 17 15:42:00.072528 2026] [security2:error] [pid 20162:tid 20336] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGfzQAAAbo"]
[Thu Sep 17 15:42:00.145146 2026] [security2:error] [pid 20162:tid 20320] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf0QAAAao"]
[Thu Sep 17 15:42:00.206068 2026] [security2:error] [pid 20162:tid 20366] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf0gAAAdg"]
[Thu Sep 17 15:42:00.270032 2026] [security2:error] [pid 20162:tid 20328] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf1AAAAbI"]
[Thu Sep 17 15:42:00.325978 2026] [security2:error] [pid 20162:tid 20345] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf2AAAAcM"]
[Thu Sep 17 15:42:00.356305 2026] [core:error] [pid 20162:tid 20363] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:00.356323 2026] [core:error] [pid 20162:tid 20363] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:00.380748 2026] [security2:error] [pid 20162:tid 20356] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf3QAAAc4"]
[Thu Sep 17 15:42:00.440916 2026] [security2:error] [pid 20162:tid 20350] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf3gAAAcg"]
[Thu Sep 17 15:42:00.502397 2026] [security2:error] [pid 20162:tid 20340] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf4gAAAb4"]
[Thu Sep 17 15:42:00.562161 2026] [security2:error] [pid 20162:tid 20381] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf5QAAAec"]
[Thu Sep 17 15:42:00.625267 2026] [security2:error] [pid 20162:tid 20348] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf6gAAAcY"]
[Thu Sep 17 15:42:00.683887 2026] [security2:error] [pid 20162:tid 20373] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf7AAAAd8"]
[Thu Sep 17 15:42:00.739779 2026] [security2:error] [pid 20162:tid 20409] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf7QAAAgM"]
[Thu Sep 17 15:42:00.795312 2026] [security2:error] [pid 20162:tid 20334] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf9AAAAbg"]
[Thu Sep 17 15:42:00.853999 2026] [security2:error] [pid 20162:tid 20322] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf9gAAAaw"]
[Thu Sep 17 15:42:00.914744 2026] [security2:error] [pid 20162:tid 20318] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGf_AAAAag"]
[Thu Sep 17 15:42:00.940074 2026] [core:error] [pid 20162:tid 20370] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:00.940091 2026] [core:error] [pid 20162:tid 20370] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:00.978281 2026] [security2:error] [pid 20162:tid 20355] [client 169.58.197.251:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxeqK-O_Kk7aqBvaiGf_wAAAc0"], referer: binance.com
[Thu Sep 17 15:42:00.979859 2026] [security2:error] [pid 20162:tid 20375] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxeqK-O_Kk7aqBvaiGgAAAAAeE"]
[Thu Sep 17 15:42:01.035478 2026] [security2:error] [pid 20162:tid 20293] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxeqa-O_Kk7aqBvaiGgBAAAAY8"]
[Thu Sep 17 15:42:01.094505 2026] [security2:error] [pid 20162:tid 20393] [client 34.26.62.32:42608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxeqa-O_Kk7aqBvaiGgBQAAAfM"]
[Thu Sep 17 15:42:01.106148 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00493: SIGUSR1 received.  Doing graceful restart
[Thu Sep 17 15:42:02.246687 2026] [:notice] [pid 18931:tid 18931] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 18931 stopped
[Thu Sep 17 15:42:04.894551 2026] [lsapi:notice] [pid 907280:tid 907280] mod_lsapi:  version 1.1-92
[Thu Sep 17 15:42:04.900064 2026] [:notice] [pid 60571:tid 60571] [host root@box5305.bluehost.com] mod_lsapi:  Selfstarter 60571 started
[Thu Sep 17 15:42:04.972809 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tylerblantonmusic.tylerblanton.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:04.981791 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: deraiz-mx.xavierlopezmiranda.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.017389 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ahmedteleb.tasameem-eg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.020473 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fst-i.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.021217 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: fstsprinkler.sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.026335 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: southislandpie.southislandpie.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.043968 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardashphotography.reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.060951 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcp-u.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.061810 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.063298 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reedcustomprinting.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.064194 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpphotorestoration.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.064849 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rcpmobileartscanning.reedartgallery.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.066275 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rjglobalhq.com.rebeccamerzius.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.117798 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mermco.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.118700 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ad1homes.com.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.119689 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-7b36017a.kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.124759 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-3f11e808.livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.153376 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: api.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.154108 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: admin.findmyschool.pk:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.184177 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: hamzaabdulhaq.gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.212574 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: site.tengushee.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.261744 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ayfertbarak.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.262846 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: becorenovation.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.263870 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: agent-immobilier.estimationevaluation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.269869 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sqlerudition.commutervibe.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.275277 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bothe-net.cyber21.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.305983 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: troopkcampcadet.campcadetmontco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.310288 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vedur-app.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.311316 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: weather-is.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.312269 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tengja-net.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.313255 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bookin-city.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.314309 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-c557c2bf.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.315214 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-1a493541.camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.316152 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitlinwhittington.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.316945 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jarrodandcaitlin-us.caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.356892 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b2133dcc.idautovic.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.397911 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wellfedhealth.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.399679 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: wear-out.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.406286 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: vogito-inno.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.434104 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: thegoatmentality.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.451594 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: sprinkonnect.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.470705 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rpimanufacturing.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.471677 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: rosebar.co:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.478973 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: revelinfear.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.481866 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: reneekardash.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.499239 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pazcreativehomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.503234 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: pagepress.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.518976 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nikistepanianmft.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.522198 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: nexgenimplant.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.540629 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mengesphotos.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.543503 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: mdlzbenefits.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.548267 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: macmanagement.ca:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.559804 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: lifepointechurchga.org:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.571757 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kinedsystems.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.576033 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: kbmautomation.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.582529 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: jminner.photo:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.588422 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: janetaylor.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.590029 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: livingsimplypractical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.619852 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: gocbeglobal.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.642778 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ffwdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.644387 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: evansilver.net:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.647079 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ericbabin.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.653448 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: ellenhirshberg.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.677197 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: comfortspecialist.info:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.688541 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: biggselectrical.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.690753 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: camera.is:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.692258 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: caitiemack.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.693617 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bvpowersports.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.694353 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buliblog.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.695278 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: buildingpro.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.699627 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: bodylanguageohio.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.727516 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: afbaco.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.729262 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: abelardpsychotherapy.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.847001 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-b0f84876.robertsinteractive.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.857165 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: tracertgame-com.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.858113 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-f2c0397e.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.860694 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: website-19b382b5.loudcloudlabs.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.942250 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: marinabelous.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.964554 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: houlaentertainment.com:443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:05.999647 2026] [ssl:warn] [pid 907280:tid 907280] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Sep 17 15:42:06.014026 2026] [qos:notice] [pid 907280:tid 907280] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Sep 17 15:42:06.251253 2026] [http2:info] [pid 907280:tid 907280] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Thu Sep 17 15:42:06.256107 2026] [mpm_event:notice] [pid 907280:tid 907280] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Sep 17 15:42:06.256118 2026] [core:notice] [pid 907280:tid 907280] AH00094: Command line: '/usr/sbin/httpd'
[Thu Sep 17 15:42:07.305428 2026] [http2:info] [pid 60716:tid 60716] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:42:07.325117 2026] [security2:error] [pid 60716:tid 60897] [client 169.58.197.253:50442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxer8Psx0SVFjrd622uDwAAAAU"], referer: binance.com
[Thu Sep 17 15:42:07.327303 2026] [security2:error] [pid 60716:tid 60892] [client 66.249.66.36:39738] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "madisonprattvideo.com"] [uri "/robots.txt"] [unique_id "aqxer8Psx0SVFjrd622uDQAAAAA"]
[Thu Sep 17 15:42:07.369244 2026] [security2:error] [pid 60716:tid 60917] [client 74.7.241.133:46026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.kiyetec1.com"] [uri "/robots.txt"] [unique_id "aqxer8Psx0SVFjrd622uGAAAGQM"]
[Thu Sep 17 15:42:07.479093 2026] [security2:error] [pid 60716:tid 60949] [client 18.192.166.72:14850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxer8Psx0SVFjrd622uLwAAADc"], referer: https://faewave.com
[Thu Sep 17 15:42:07.499574 2026] [security2:error] [pid 60716:tid 60965] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxer8Psx0SVFjrd622uMQAAAEc"]
[Thu Sep 17 15:42:07.524960 2026] [core:error] [pid 60716:tid 60985] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:07.524982 2026] [core:error] [pid 60716:tid 60985] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:07.556687 2026] [security2:error] [pid 60716:tid 60994] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxer8Psx0SVFjrd622uPAAAAGQ"]
[Thu Sep 17 15:42:07.592750 2026] [security2:error] [pid 60716:tid 60940] [client 14.96.156.146:53897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxer8Psx0SVFjrd622uQAAAAC4"]
[Thu Sep 17 15:42:07.592959 2026] [security2:error] [pid 60716:tid 60940] [client 14.96.156.146:53897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxer8Psx0SVFjrd622uQAAAAC4"]
[Thu Sep 17 15:42:07.628222 2026] [security2:error] [pid 60716:tid 61000] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxer8Psx0SVFjrd622uQgAAAGo"]
[Thu Sep 17 15:42:07.657209 2026] [security2:error] [pid 60716:tid 60986] [client 92.40.177.20:30193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxer8Psx0SVFjrd622uNgAAXA0"]
[Thu Sep 17 15:42:07.657330 2026] [security2:error] [pid 60716:tid 60986] [client 92.40.177.20:30193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxer8Psx0SVFjrd622uNwAAXAw"]
[Thu Sep 17 15:42:07.681478 2026] [security2:error] [pid 60716:tid 61008] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxer8Psx0SVFjrd622uSgAAAHI"]
[Thu Sep 17 15:42:07.738681 2026] [security2:error] [pid 60716:tid 60953] [client 177.44.133.72:58310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxer8Psx0SVFjrd622uUAAAADs"]
[Thu Sep 17 15:42:07.738873 2026] [security2:error] [pid 60716:tid 60953] [client 177.44.133.72:58310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxer8Psx0SVFjrd622uUAAAADs"]
[Thu Sep 17 15:42:07.741168 2026] [security2:error] [pid 60716:tid 61019] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxer8Psx0SVFjrd622uUQAAAH0"]
[Thu Sep 17 15:42:07.794545 2026] [security2:error] [pid 60716:tid 60903] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxer8Psx0SVFjrd622uVAAAAAs"]
[Thu Sep 17 15:42:07.796460 2026] [access_compat:error] [pid 60716:tid 61016] [client 78.46.218.89:0] AH01797: client denied by server configuration: /home3/freegao8/public_html/the-chronicles-of-shakespeare-romeo-juliet
[Thu Sep 17 15:42:07.799427 2026] [security2:error] [pid 60716:tid 60935] [client 4.240.114.86:57496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jwdnyc.com"] [uri "/wp-login.php"] [unique_id "aqxer8Psx0SVFjrd622uVgAAACk"], referer: binance.com
[Thu Sep 17 15:42:07.800991 2026] [authz_core:error] [pid 60716:tid 60931] [client 40.81.232.68:52028] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:42:07.849679 2026] [security2:error] [pid 60716:tid 60927] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxer8Psx0SVFjrd622uWgAAACI"]
[Thu Sep 17 15:42:07.853709 2026] [security2:error] [pid 60716:tid 60907] [client 156.59.198.136:25286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bppa-nb.com"] [uri "/wp-content/uploads/2016/04/BPPABOATRAMP-5-19-2016v2.pdf"] [unique_id "aqxer8Psx0SVFjrd622uWwAAAA8"]
[Thu Sep 17 15:42:07.903989 2026] [security2:error] [pid 60716:tid 60936] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxer8Psx0SVFjrd622uXQAAACo"]
[Thu Sep 17 15:42:07.957318 2026] [security2:error] [pid 60716:tid 60972] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxer8Psx0SVFjrd622uYwAAAE4"]
[Thu Sep 17 15:42:08.011186 2026] [security2:error] [pid 60716:tid 60976] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxesMPsx0SVFjrd622uZQAAAFI"]
[Thu Sep 17 15:42:08.058326 2026] [core:error] [pid 60716:tid 60977] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:08.058346 2026] [core:error] [pid 60716:tid 60977] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:08.067710 2026] [security2:error] [pid 60716:tid 60968] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxesMPsx0SVFjrd622uaQAAAEo"]
[Thu Sep 17 15:42:08.122593 2026] [security2:error] [pid 60716:tid 60955] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxesMPsx0SVFjrd622ubgAAAD0"]
[Thu Sep 17 15:42:08.186148 2026] [security2:error] [pid 60716:tid 60989] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxesMPsx0SVFjrd622ucgAAAF8"]
[Thu Sep 17 15:42:08.246317 2026] [security2:error] [pid 60716:tid 60993] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxesMPsx0SVFjrd622udAAAAGM"]
[Thu Sep 17 15:42:08.303643 2026] [security2:error] [pid 60716:tid 60997] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxesMPsx0SVFjrd622udwAAAGc"]
[Thu Sep 17 15:42:08.358777 2026] [security2:error] [pid 60716:tid 60995] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxesMPsx0SVFjrd622uegAAAGU"]
[Thu Sep 17 15:42:08.413765 2026] [security2:error] [pid 60716:tid 60999] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxesMPsx0SVFjrd622uewAAAGk"]
[Thu Sep 17 15:42:08.471484 2026] [autoindex:error] [pid 60716:tid 60983] [client 34.165.71.35:42908] AH01276: Cannot serve directory /home4/gcpmanag/public_html/commcapamerica/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:42:08.472413 2026] [security2:error] [pid 60716:tid 60899] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxesMPsx0SVFjrd622ufQAAAAc"]
[Thu Sep 17 15:42:08.529064 2026] [security2:error] [pid 60716:tid 60911] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxesMPsx0SVFjrd622uiQAAABM"]
[Thu Sep 17 15:42:08.585624 2026] [security2:error] [pid 60716:tid 61007] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxesMPsx0SVFjrd622ujQAAAHE"]
[Thu Sep 17 15:42:08.590730 2026] [core:error] [pid 60716:tid 61008] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:08.590747 2026] [core:error] [pid 60716:tid 61008] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:08.641159 2026] [security2:error] [pid 60716:tid 61015] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxesMPsx0SVFjrd622ujwAAAHk"]
[Thu Sep 17 15:42:08.696598 2026] [security2:error] [pid 60716:tid 61003] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxesMPsx0SVFjrd622umQAAAG0"]
[Thu Sep 17 15:42:08.731869 2026] [security2:error] [pid 60716:tid 60913] [client 5.188.86.234:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "networkorbitz.com"] [uri "/blog/wp-login.php"] [unique_id "aqxesMPsx0SVFjrd622umAAAABU"]
[Thu Sep 17 15:42:08.749936 2026] [security2:error] [pid 60716:tid 60894] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxesMPsx0SVFjrd622ungAAAAI"]
[Thu Sep 17 15:42:08.810375 2026] [security2:error] [pid 60716:tid 60951] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxesMPsx0SVFjrd622uoAAAADk"]
[Thu Sep 17 15:42:08.866115 2026] [security2:error] [pid 60716:tid 60910] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxesMPsx0SVFjrd622uoQAAABI"]
[Thu Sep 17 15:42:08.919341 2026] [security2:error] [pid 60716:tid 60950] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxesMPsx0SVFjrd622upgAAADg"]
[Thu Sep 17 15:42:08.974484 2026] [security2:error] [pid 60716:tid 60915] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxesMPsx0SVFjrd622uqAAAABc"]
[Thu Sep 17 15:42:09.048532 2026] [security2:error] [pid 60716:tid 60972] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxescPsx0SVFjrd622uqQAAAE4"]
[Thu Sep 17 15:42:09.089281 2026] [security2:error] [pid 60716:tid 60892] [client 136.158.61.34:40431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxescPsx0SVFjrd622uqwAAAAA"]
[Thu Sep 17 15:42:09.089394 2026] [security2:error] [pid 60716:tid 60892] [client 136.158.61.34:40431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxescPsx0SVFjrd622uqwAAAAA"]
[Thu Sep 17 15:42:09.103999 2026] [security2:error] [pid 60716:tid 60967] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxescPsx0SVFjrd622urgAAAEk"]
[Thu Sep 17 15:42:09.161897 2026] [security2:error] [pid 60716:tid 60968] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxescPsx0SVFjrd622uuwAAAEo"]
[Thu Sep 17 15:42:09.176329 2026] [core:error] [pid 60716:tid 60982] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:09.176346 2026] [core:error] [pid 60716:tid 60982] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:09.184103 2026] [security2:error] [pid 60716:tid 60969] [client 143.105.152.240:22492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxescPsx0SVFjrd622uwgAAAEs"]
[Thu Sep 17 15:42:09.194374 2026] [security2:error] [pid 60716:tid 60969] [client 143.105.152.240:22492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxescPsx0SVFjrd622uwgAAAEs"]
[Thu Sep 17 15:42:09.222468 2026] [security2:error] [pid 60716:tid 60947] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxescPsx0SVFjrd622uwwAAADU"]
[Thu Sep 17 15:42:09.273566 2026] [security2:error] [pid 60716:tid 60822] [remote 5.188.86.234:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "networkorbitz.com"] [uri "/blog/wp-login.php"] [unique_id "aqxescPsx0SVFjrd622uxQAATzw"]
[Thu Sep 17 15:42:09.279928 2026] [security2:error] [pid 60716:tid 60985] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxescPsx0SVFjrd622uxgAAAFs"]
[Thu Sep 17 15:42:09.341691 2026] [security2:error] [pid 60716:tid 60948] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxescPsx0SVFjrd622uygAAADY"]
[Thu Sep 17 15:42:09.395479 2026] [security2:error] [pid 60716:tid 60939] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxescPsx0SVFjrd622uywAAAC0"]
[Thu Sep 17 15:42:09.455221 2026] [security2:error] [pid 60716:tid 60995] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxescPsx0SVFjrd622uzgAAAGU"]
[Thu Sep 17 15:42:09.509494 2026] [security2:error] [pid 60716:tid 60911] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxescPsx0SVFjrd622u0AAAABM"]
[Thu Sep 17 15:42:09.564860 2026] [security2:error] [pid 60716:tid 61010] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxescPsx0SVFjrd622u0gAAAHQ"]
[Thu Sep 17 15:42:09.589709 2026] [security2:error] [pid 60716:tid 61021] [client 139.59.121.144:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinoviaggio.com"] [uri "/index.php"] [unique_id "aqxer8Psx0SVFjrd622uZAAAfxk"], referer: http://vinoviaggio.com/wordpress/
[Thu Sep 17 15:42:09.656257 2026] [security2:error] [pid 60716:tid 60912] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxescPsx0SVFjrd622u1QAAABQ"]
[Thu Sep 17 15:42:09.712857 2026] [security2:error] [pid 60716:tid 61020] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxescPsx0SVFjrd622u4AAAAH4"]
[Thu Sep 17 15:42:09.738155 2026] [core:error] [pid 60716:tid 61003] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:09.738174 2026] [core:error] [pid 60716:tid 61003] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:09.770040 2026] [security2:error] [pid 60716:tid 60987] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxescPsx0SVFjrd622u4wAAAF0"]
[Thu Sep 17 15:42:09.790761 2026] [security2:error] [pid 60716:tid 60923] [client 89.80.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxer8Psx0SVFjrd622uVwAAAB4"], referer: https://hikingforwildness.com
[Thu Sep 17 15:42:09.832326 2026] [security2:error] [pid 60716:tid 60894] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxescPsx0SVFjrd622u5wAAAAI"]
[Thu Sep 17 15:42:09.861195 2026] [security2:error] [pid 60716:tid 61001] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/.env"] [unique_id "aqxescPsx0SVFjrd622u6AAAAGs"]
[Thu Sep 17 15:42:10.104438 2026] [security2:error] [pid 60716:tid 60893] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxescPsx0SVFjrd622u7gAAAAE"]
[Thu Sep 17 15:42:10.119124 2026] [security2:error] [pid 60716:tid 60951] [client 139.59.121.144:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinoviaggio.com"] [uri "/index.php"] [unique_id "aqxessPsx0SVFjrd622u7wAAOUQ"], referer: http://vinoviaggio.com/backup/
[Thu Sep 17 15:42:10.192816 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.248.240:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/.env.bak"] [unique_id "aqxessPsx0SVFjrd622u9AAAAAk"]
[Thu Sep 17 15:42:10.269094 2026] [security2:error] [pid 60716:tid 61017] [client 162.241.226.11:36944] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxessPsx0SVFjrd622u-QAAAHs"]
[Thu Sep 17 15:42:10.303205 2026] [core:error] [pid 60716:tid 60967] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:10.303228 2026] [core:error] [pid 60716:tid 60967] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:10.349433 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.248.240:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/.env.backup"] [unique_id "aqxessPsx0SVFjrd622u_wAAAFg"]
[Thu Sep 17 15:42:10.376885 2026] [security2:error] [pid 60716:tid 60924] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxessPsx0SVFjrd622u-gAAAB8"]
[Thu Sep 17 15:42:10.381804 2026] [security2:error] [pid 60716:tid 60962] [client 134.185.85.61:51704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "realdubrovnikexperience.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxessPsx0SVFjrd622vAAAAAEQ"]
[Thu Sep 17 15:42:10.459626 2026] [security2:error] [pid 60716:tid 60980] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxessPsx0SVFjrd622vAwAAAFY"]
[Thu Sep 17 15:42:10.520495 2026] [security2:error] [pid 60716:tid 60917] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxessPsx0SVFjrd622vBwAAABk"]
[Thu Sep 17 15:42:10.580394 2026] [security2:error] [pid 60716:tid 60974] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxessPsx0SVFjrd622vCQAAAFA"]
[Thu Sep 17 15:42:10.625688 2026] [security2:error] [pid 60716:tid 60892] [client 79.116.89.151:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxessPsx0SVFjrd622vCwAAAAA"]
[Thu Sep 17 15:42:10.625815 2026] [security2:error] [pid 60716:tid 60892] [client 79.116.89.151:61444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxessPsx0SVFjrd622vCwAAAAA"]
[Thu Sep 17 15:42:10.634223 2026] [security2:error] [pid 60716:tid 61013] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxessPsx0SVFjrd622vDAAAAHc"]
[Thu Sep 17 15:42:10.670264 2026] [security2:error] [pid 60716:tid 60914] [client 139.59.121.144:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinoviaggio.com"] [uri "/index.php"] [unique_id "aqxessPsx0SVFjrd622vCAAAFkg"], referer: http://vinoviaggio.com/wp/
[Thu Sep 17 15:42:10.693479 2026] [security2:error] [pid 60716:tid 60958] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxessPsx0SVFjrd622vEgAAAEA"]
[Thu Sep 17 15:42:10.747519 2026] [security2:error] [pid 60716:tid 60939] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxessPsx0SVFjrd622vEwAAAC0"]
[Thu Sep 17 15:42:10.771853 2026] [security2:error] [pid 60716:tid 60994] [client 134.185.85.61:62187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "realdubrovnikexperience.com"] [uri "/media/system/js/core.js"] [unique_id "aqxessPsx0SVFjrd622vFAAAAGQ"]
[Thu Sep 17 15:42:10.803952 2026] [security2:error] [pid 60716:tid 60940] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxessPsx0SVFjrd622vFQAAAC4"]
[Thu Sep 17 15:42:10.812399 2026] [security2:error] [pid 60716:tid 61006] [client 34.95.193.102:44580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "aqxessPsx0SVFjrd622vFgAAAHA"]
[Thu Sep 17 15:42:10.860585 2026] [security2:error] [pid 60716:tid 60995] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxessPsx0SVFjrd622vFwAAAGU"]
[Thu Sep 17 15:42:10.916423 2026] [security2:error] [pid 60716:tid 61009] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxessPsx0SVFjrd622vGwAAAHM"]
[Thu Sep 17 15:42:10.970408 2026] [security2:error] [pid 60716:tid 60957] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxessPsx0SVFjrd622vHAAAAD8"]
[Thu Sep 17 15:42:10.972729 2026] [security2:error] [pid 60716:tid 60952] [client 34.95.193.102:44580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "aqxessPsx0SVFjrd622vHQAAADo"]
[Thu Sep 17 15:42:11.036011 2026] [security2:error] [pid 60716:tid 61012] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxes8Psx0SVFjrd622vHgAAAHY"]
[Thu Sep 17 15:42:11.036706 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.248.240:56154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/.env.old"] [unique_id "aqxes8Psx0SVFjrd622vHwAAAGk"]
[Thu Sep 17 15:42:11.090514 2026] [security2:error] [pid 60716:tid 61020] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxes8Psx0SVFjrd622vIwAAAH4"]
[Thu Sep 17 15:42:11.154077 2026] [security2:error] [pid 60716:tid 61007] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxes8Psx0SVFjrd622vJgAAAHE"]
[Thu Sep 17 15:42:11.185267 2026] [security2:error] [pid 60716:tid 60925] [client 139.59.121.144:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinoviaggio.com"] [uri "/index.php"] [unique_id "aqxes8Psx0SVFjrd622vJAAAIFA"], referer: http://vinoviaggio.com/new/
[Thu Sep 17 15:42:11.210583 2026] [core:error] [pid 60716:tid 60996] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:11.210606 2026] [core:error] [pid 60716:tid 60996] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:11.211153 2026] [security2:error] [pid 60716:tid 61016] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxes8Psx0SVFjrd622vMAAAAHo"]
[Thu Sep 17 15:42:11.272804 2026] [security2:error] [pid 60716:tid 60905] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxes8Psx0SVFjrd622vMQAAAA0"]
[Thu Sep 17 15:42:11.329612 2026] [security2:error] [pid 60716:tid 60900] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxes8Psx0SVFjrd622vMwAAAAg"]
[Thu Sep 17 15:42:11.384132 2026] [security2:error] [pid 60716:tid 60904] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxes8Psx0SVFjrd622vNAAAAAw"]
[Thu Sep 17 15:42:11.438062 2026] [security2:error] [pid 60716:tid 60931] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxes8Psx0SVFjrd622vNwAAACU"]
[Thu Sep 17 15:42:11.491808 2026] [security2:error] [pid 60716:tid 60981] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxes8Psx0SVFjrd622vOAAAAFc"]
[Thu Sep 17 15:42:11.546370 2026] [security2:error] [pid 60716:tid 61011] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxes8Psx0SVFjrd622vOQAAAHU"]
[Thu Sep 17 15:42:11.601767 2026] [security2:error] [pid 60716:tid 60918] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxes8Psx0SVFjrd622vPQAAABo"]
[Thu Sep 17 15:42:11.622251 2026] [security2:error] [pid 60716:tid 60910] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/.env.bak"] [unique_id "aqxes8Psx0SVFjrd622vPwAAABI"]
[Thu Sep 17 15:42:11.657349 2026] [security2:error] [pid 60716:tid 60906] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxes8Psx0SVFjrd622vQAAAAA4"]
[Thu Sep 17 15:42:11.704441 2026] [security2:error] [pid 60716:tid 60927] [client 139.59.121.144:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinoviaggio.com"] [uri "/index.php"] [unique_id "aqxes8Psx0SVFjrd622vPgAAIlU"], referer: http://vinoviaggio.com/old/
[Thu Sep 17 15:42:11.718901 2026] [security2:error] [pid 60716:tid 60901] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxes8Psx0SVFjrd622vQwAAAAk"]
[Thu Sep 17 15:42:11.781136 2026] [security2:error] [pid 60716:tid 60932] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxes8Psx0SVFjrd622vSgAAACY"]
[Thu Sep 17 15:42:11.832257 2026] [core:error] [pid 60716:tid 60986] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:11.832273 2026] [core:error] [pid 60716:tid 60986] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:11.834458 2026] [security2:error] [pid 60716:tid 60971] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxes8Psx0SVFjrd622vTAAAAE0"]
[Thu Sep 17 15:42:11.888268 2026] [security2:error] [pid 60716:tid 60943] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxes8Psx0SVFjrd622vTQAAADE"]
[Thu Sep 17 15:42:11.941163 2026] [security2:error] [pid 60716:tid 60937] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxes8Psx0SVFjrd622vTwAAACs"]
[Thu Sep 17 15:42:11.984347 2026] [security2:error] [pid 60716:tid 60978] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/.env.backup"] [unique_id "aqxes8Psx0SVFjrd622vUwAAAFQ"]
[Thu Sep 17 15:42:11.997297 2026] [security2:error] [pid 60716:tid 60924] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxes8Psx0SVFjrd622vVQAAAB8"]
[Thu Sep 17 15:42:12.050267 2026] [security2:error] [pid 60716:tid 60963] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxetMPsx0SVFjrd622vWAAAAEU"]
[Thu Sep 17 15:42:12.094017 2026] [security2:error] [pid 60716:tid 60980] [client 169.58.197.251:55568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxetMPsx0SVFjrd622vWwAAAFY"], referer: binance.com
[Thu Sep 17 15:42:12.103469 2026] [security2:error] [pid 60716:tid 60969] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxetMPsx0SVFjrd622vXAAAAEs"]
[Thu Sep 17 15:42:12.160197 2026] [security2:error] [pid 60716:tid 60908] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxetMPsx0SVFjrd622vXgAAABA"]
[Thu Sep 17 15:42:12.221910 2026] [security2:error] [pid 60716:tid 60919] [client 139.59.121.144:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinoviaggio.com"] [uri "/index.php"] [unique_id "aqxetMPsx0SVFjrd622vXQAAG1s"], referer: http://vinoviaggio.com/blog/
[Thu Sep 17 15:42:12.225764 2026] [security2:error] [pid 60716:tid 60974] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxetMPsx0SVFjrd622vYQAAAFA"]
[Thu Sep 17 15:42:12.295793 2026] [security2:error] [pid 60716:tid 60892] [client 34.26.62.32:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxetMPsx0SVFjrd622vZAAAAAA"]
[Thu Sep 17 15:42:12.450424 2026] [core:error] [pid 60716:tid 60973] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:12.450443 2026] [core:error] [pid 60716:tid 60973] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:12.480136 2026] [security2:error] [pid 60716:tid 60979] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxetMPsx0SVFjrd622vbAAAAFU"]
[Thu Sep 17 15:42:12.545632 2026] [security2:error] [pid 60716:tid 61010] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxetMPsx0SVFjrd622vbQAAAHQ"]
[Thu Sep 17 15:42:12.550052 2026] [security2:error] [pid 60716:tid 60957] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/.env.old"] [unique_id "aqxetMPsx0SVFjrd622vbgAAAD8"]
[Thu Sep 17 15:42:12.601761 2026] [security2:error] [pid 60716:tid 60999] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxetMPsx0SVFjrd622vcAAAAGk"]
[Thu Sep 17 15:42:12.657151 2026] [security2:error] [pid 60716:tid 60925] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxetMPsx0SVFjrd622vdAAAACA"]
[Thu Sep 17 15:42:12.714093 2026] [security2:error] [pid 60716:tid 61000] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxetMPsx0SVFjrd622vdwAAAGo"]
[Thu Sep 17 15:42:12.770445 2026] [security2:error] [pid 60716:tid 61002] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxetMPsx0SVFjrd622vfAAAAGw"]
[Thu Sep 17 15:42:12.827272 2026] [security2:error] [pid 60716:tid 61015] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxetMPsx0SVFjrd622vhQAAAHk"]
[Thu Sep 17 15:42:12.830882 2026] [core:error] [pid 60716:tid 60913] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:12.830899 2026] [core:error] [pid 60716:tid 60913] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:12.886848 2026] [security2:error] [pid 60716:tid 60964] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxetMPsx0SVFjrd622vhwAAAEY"]
[Thu Sep 17 15:42:12.949855 2026] [security2:error] [pid 60716:tid 60981] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxetMPsx0SVFjrd622viAAAAFc"]
[Thu Sep 17 15:42:13.008209 2026] [security2:error] [pid 60716:tid 60910] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxetcPsx0SVFjrd622vjAAAABI"]
[Thu Sep 17 15:42:13.061244 2026] [core:error] [pid 60716:tid 60932] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:13.061263 2026] [core:error] [pid 60716:tid 60932] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:13.063254 2026] [security2:error] [pid 60716:tid 61005] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxetcPsx0SVFjrd622vkAAAAG8"]
[Thu Sep 17 15:42:13.130648 2026] [security2:error] [pid 60716:tid 60971] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxetcPsx0SVFjrd622vkQAAAE0"]
[Thu Sep 17 15:42:13.180817 2026] [security2:error] [pid 60716:tid 60923] [client 103.61.184.148:49800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxetcPsx0SVFjrd622vkwAAAB4"]
[Thu Sep 17 15:42:13.180919 2026] [security2:error] [pid 60716:tid 60923] [client 103.61.184.148:49800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxetcPsx0SVFjrd622vkwAAAB4"]
[Thu Sep 17 15:42:13.188199 2026] [security2:error] [pid 60716:tid 60998] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxetcPsx0SVFjrd622vlAAAAGg"]
[Thu Sep 17 15:42:13.253710 2026] [security2:error] [pid 60716:tid 60976] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxetcPsx0SVFjrd622vmAAAAFI"]
[Thu Sep 17 15:42:13.313097 2026] [security2:error] [pid 60716:tid 60978] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxetcPsx0SVFjrd622vmQAAAFQ"]
[Thu Sep 17 15:42:13.373347 2026] [security2:error] [pid 60716:tid 60924] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxetcPsx0SVFjrd622vnAAAAB8"]
[Thu Sep 17 15:42:13.441843 2026] [security2:error] [pid 60716:tid 60975] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxetcPsx0SVFjrd622voAAAAFE"]
[Thu Sep 17 15:42:13.506754 2026] [security2:error] [pid 60716:tid 60908] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxetcPsx0SVFjrd622vowAAABA"]
[Thu Sep 17 15:42:13.527389 2026] [core:error] [pid 60716:tid 60959] [client 34.166.135.226:49146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:13.527412 2026] [core:error] [pid 60716:tid 60959] [client 34.166.135.226:49146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:13.567709 2026] [core:error] [pid 60716:tid 60915] [client 34.95.193.102:44614] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:13.567727 2026] [core:error] [pid 60716:tid 60915] [client 34.95.193.102:44614] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:13.571777 2026] [security2:error] [pid 60716:tid 60991] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxetcPsx0SVFjrd622vpwAAAGE"]
[Thu Sep 17 15:42:13.631322 2026] [security2:error] [pid 60716:tid 60947] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxetcPsx0SVFjrd622vqgAAADU"]
[Thu Sep 17 15:42:13.691320 2026] [security2:error] [pid 60716:tid 60948] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxetcPsx0SVFjrd622vrQAAADY"]
[Thu Sep 17 15:42:13.746196 2026] [security2:error] [pid 60716:tid 60989] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxetcPsx0SVFjrd622vsQAAAF8"]
[Thu Sep 17 15:42:13.804199 2026] [security2:error] [pid 60716:tid 60940] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxetcPsx0SVFjrd622vtAAAAC4"]
[Thu Sep 17 15:42:13.871153 2026] [security2:error] [pid 60716:tid 61006] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxetcPsx0SVFjrd622vtQAAAHA"]
[Thu Sep 17 15:42:13.931283 2026] [security2:error] [pid 60716:tid 61010] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxetcPsx0SVFjrd622vuQAAAHQ"]
[Thu Sep 17 15:42:13.984503 2026] [security2:error] [pid 60716:tid 60938] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxetcPsx0SVFjrd622vvQAAACw"]
[Thu Sep 17 15:42:14.053110 2026] [security2:error] [pid 60716:tid 61002] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxetsPsx0SVFjrd622vwAAAAGw"]
[Thu Sep 17 15:42:14.108907 2026] [core:error] [pid 60716:tid 61015] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.108923 2026] [core:error] [pid 60716:tid 61015] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.117427 2026] [security2:error] [pid 60716:tid 60897] [client 34.26.62.32:56776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxetsPsx0SVFjrd622vxQAAAAU"]
[Thu Sep 17 15:42:14.170517 2026] [security2:error] [pid 60716:tid 60909] [client 34.26.62.32:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxetsPsx0SVFjrd622vxwAAABE"]
[Thu Sep 17 15:42:14.217229 2026] [core:error] [pid 60716:tid 60925] [client 34.166.135.226:49152] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.217248 2026] [core:error] [pid 60716:tid 60925] [client 34.166.135.226:49152] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.352484 2026] [security2:error] [pid 60716:tid 60896] [client 34.26.62.32:52916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/info.php"] [unique_id "aqxetsPsx0SVFjrd622v0AAAAAQ"]
[Thu Sep 17 15:42:14.521388 2026] [security2:error] [pid 60716:tid 61009] [client 173.252.69.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxetsPsx0SVFjrd622v0wAAAHM"]
[Thu Sep 17 15:42:14.521657 2026] [security2:error] [pid 60716:tid 61003] [client 34.26.62.32:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/php.php"] [unique_id "aqxetsPsx0SVFjrd622v2AAAAG0"]
[Thu Sep 17 15:42:14.617402 2026] [core:error] [pid 60716:tid 60944] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.617422 2026] [core:error] [pid 60716:tid 60944] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.698095 2026] [security2:error] [pid 60716:tid 60945] [client 34.26.62.32:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/i.php"] [unique_id "aqxetsPsx0SVFjrd622v4wAAADM"]
[Thu Sep 17 15:42:14.759843 2026] [security2:error] [pid 60716:tid 60999] [client 154.23.42.23:41214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiansoncampusnlc.com"] [uri "/index.php"] [unique_id "aqxetsPsx0SVFjrd622v4gAAAGk"], referer: https://christiansoncampusnlc.com/
[Thu Sep 17 15:42:14.897870 2026] [core:error] [pid 60716:tid 60937] [client 34.166.135.226:49164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.897888 2026] [core:error] [pid 60716:tid 60937] [client 34.166.135.226:49164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:14.902721 2026] [security2:error] [pid 60716:tid 60893] [client 34.26.62.32:52948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxetsPsx0SVFjrd622v6AAAAAE"]
[Thu Sep 17 15:42:15.008467 2026] [security2:error] [pid 60716:tid 60998] [client 65.21.136.254:27314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.136.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alexandernovelist.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxetsPsx0SVFjrd622v7AAAAGg"]
[Thu Sep 17 15:42:15.109360 2026] [security2:error] [pid 60716:tid 60947] [client 34.26.62.32:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxet8Psx0SVFjrd622v7wAAADU"]
[Thu Sep 17 15:42:15.114834 2026] [security2:error] [pid 60716:tid 60959] [client 34.95.193.102:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "aqxet8Psx0SVFjrd622v8AAAAEE"]
[Thu Sep 17 15:42:15.227673 2026] [log_config:warn] [pid 20162:tid 20314] (32)Broken pipe: [client 128.1.12.66:39711] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --suffix=-bytes_log
[Thu Sep 17 15:42:15.227690 2026] [log_config:warn] [pid 20162:tid 20314] (32)Broken pipe: [client 128.1.12.66:39711] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=box5305.bluehost.com --mainout=/etc/apache2/logs/access_log
[Thu Sep 17 15:42:15.276676 2026] [security2:error] [pid 60716:tid 60940] [client 34.95.193.102:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/apps/.env"] [unique_id "aqxet8Psx0SVFjrd622v-AAAAC4"]
[Thu Sep 17 15:42:15.322536 2026] [security2:error] [pid 60716:tid 60965] [client 34.26.62.32:52964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/test.php"] [unique_id "aqxet8Psx0SVFjrd622v-wAAAEc"]
[Thu Sep 17 15:42:15.439470 2026] [security2:error] [pid 60716:tid 60938] [client 34.95.193.102:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "aqxet8Psx0SVFjrd622v_AAAACw"]
[Thu Sep 17 15:42:15.451020 2026] [autoindex:error] [pid 60716:tid 60997] [client 34.165.71.35:57882] AH01276: Cannot serve directory /home4/gcpmanag/public_html/commcapusa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:42:15.503305 2026] [security2:error] [pid 60716:tid 60953] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/.env.swp"] [unique_id "aqxet8Psx0SVFjrd622wBAAAADs"]
[Thu Sep 17 15:42:15.546292 2026] [core:error] [pid 60716:tid 60984] [client 138.246.253.24:49880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:15.546309 2026] [core:error] [pid 60716:tid 60984] [client 138.246.253.24:49880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:15.607412 2026] [security2:error] [pid 60716:tid 61012] [client 34.95.193.102:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/web/.env"] [unique_id "aqxet8Psx0SVFjrd622wDAAAAHY"]
[Thu Sep 17 15:42:15.646815 2026] [security2:error] [pid 60716:tid 60900] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxet8Psx0SVFjrd622wCQAAAAg"]
[Thu Sep 17 15:42:15.659482 2026] [core:error] [pid 60716:tid 60916] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:15.659498 2026] [core:error] [pid 60716:tid 60916] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:15.673314 2026] [security2:error] [pid 60716:tid 60894] [client 34.165.71.35:57882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "commcapusa.gcpmanagement.com"] [uri "/"] [unique_id "aqxet8Psx0SVFjrd622wEwAAAAI"]
[Thu Sep 17 15:42:15.708485 2026] [security2:error] [pid 60716:tid 60906] [client 34.26.62.32:52976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/p.php"] [unique_id "aqxet8Psx0SVFjrd622wFgAAAA4"]
[Thu Sep 17 15:42:15.730010 2026] [security2:error] [pid 60716:tid 60932] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/.env~"] [unique_id "aqxet8Psx0SVFjrd622wFwAAACY"]
[Thu Sep 17 15:42:15.768503 2026] [security2:error] [pid 60716:tid 60951] [client 34.95.193.102:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/site/.env"] [unique_id "aqxet8Psx0SVFjrd622wGAAAADk"]
[Thu Sep 17 15:42:15.916658 2026] [security2:error] [pid 60716:tid 60903] [client 34.26.62.32:52990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxet8Psx0SVFjrd622wHAAAAAs"]
[Thu Sep 17 15:42:15.929788 2026] [security2:error] [pid 60716:tid 60923] [client 34.95.193.102:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/public/.env"] [unique_id "aqxet8Psx0SVFjrd622wHQAAAB4"]
[Thu Sep 17 15:42:16.128531 2026] [security2:error] [pid 60716:tid 60972] [client 34.26.62.32:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxeuMPsx0SVFjrd622wJgAAAE4"]
[Thu Sep 17 15:42:16.131064 2026] [core:error] [pid 60716:tid 60963] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:16.131077 2026] [core:error] [pid 60716:tid 60963] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:16.326526 2026] [security2:error] [pid 60716:tid 60988] [client 34.26.62.32:53000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxeuMPsx0SVFjrd622wPAAAAF4"]
[Thu Sep 17 15:42:16.354126 2026] [core:error] [pid 60716:tid 60961] [client 34.166.135.226:49180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:16.354141 2026] [core:error] [pid 60716:tid 60961] [client 34.166.135.226:49180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:16.425371 2026] [security2:error] [pid 60716:tid 60985] [client 34.165.71.35:57888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "commcapusa.gcpmanagement.com"] [uri "/"] [unique_id "aqxeuMPsx0SVFjrd622wPwAAAFs"]
[Thu Sep 17 15:42:16.487837 2026] [security2:error] [pid 60716:tid 60947] [client 14.96.156.146:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeuMPsx0SVFjrd622wQQAAADU"]
[Thu Sep 17 15:42:16.487915 2026] [security2:error] [pid 60716:tid 60947] [client 14.96.156.146:54554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxeuMPsx0SVFjrd622wQQAAADU"]
[Thu Sep 17 15:42:16.519955 2026] [security2:error] [pid 60716:tid 60950] [client 34.26.62.32:53004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxeuMPsx0SVFjrd622wRAAAADg"]
[Thu Sep 17 15:42:16.626456 2026] [security2:error] [pid 60716:tid 61015] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "aqxeuMPsx0SVFjrd622wSgAAAHk"]
[Thu Sep 17 15:42:16.688535 2026] [security2:error] [pid 60716:tid 60973] [client 116.203.43.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moorekuehn.com"] [uri "/index.php"] [unique_id "aqxeuMPsx0SVFjrd622wSQAAAE8"]
[Thu Sep 17 15:42:16.728851 2026] [security2:error] [pid 60716:tid 61012] [client 34.26.62.32:53010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxeuMPsx0SVFjrd622wTwAAAHY"]
[Thu Sep 17 15:42:16.789692 2026] [security2:error] [pid 60716:tid 60906] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/server/.env"] [unique_id "aqxeuMPsx0SVFjrd622wUgAAAA4"]
[Thu Sep 17 15:42:16.940697 2026] [security2:error] [pid 60716:tid 61005] [client 34.26.62.32:53020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxeuMPsx0SVFjrd622wWQAAAG8"]
[Thu Sep 17 15:42:16.950149 2026] [security2:error] [pid 60716:tid 60898] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/frontend/.env"] [unique_id "aqxeuMPsx0SVFjrd622wXAAAAAY"]
[Thu Sep 17 15:42:17.041917 2026] [security2:error] [pid 60716:tid 60896] [client 34.166.135.226:49192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aqxeucPsx0SVFjrd622wZQAAAAQ"]
[Thu Sep 17 15:42:17.099020 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.248.240:56244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/.env.swp"] [unique_id "aqxeucPsx0SVFjrd622waAAAACo"]
[Thu Sep 17 15:42:17.112981 2026] [security2:error] [pid 60716:tid 60946] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/src/.env"] [unique_id "aqxeucPsx0SVFjrd622wbAAAADQ"]
[Thu Sep 17 15:42:17.128853 2026] [security2:error] [pid 60716:tid 60980] [client 34.26.62.32:53028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxeucPsx0SVFjrd622wbwAAAFY"]
[Thu Sep 17 15:42:17.170312 2026] [security2:error] [pid 60716:tid 60976] [client 169.58.197.253:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxeucPsx0SVFjrd622wcwAAAFI"], referer: binance.com
[Thu Sep 17 15:42:17.208116 2026] [security2:error] [pid 60716:tid 60982] [client 34.165.71.35:57892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "commcapusa.gcpmanagement.com"] [uri "/"] [unique_id "aqxeucPsx0SVFjrd622weAAAAFg"]
[Thu Sep 17 15:42:17.208241 2026] [security2:error] [pid 60716:tid 60999] [client 57.141.14.8:36548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxeucPsx0SVFjrd622wYwAAaQg"]
[Thu Sep 17 15:42:17.256790 2026] [security2:error] [pid 60716:tid 60966] [client 34.154.248.240:56244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/.env~"] [unique_id "aqxeucPsx0SVFjrd622wegAAAEg"]
[Thu Sep 17 15:42:17.276370 2026] [security2:error] [pid 60716:tid 60956] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/core/.env"] [unique_id "aqxeucPsx0SVFjrd622wfQAAAD4"]
[Thu Sep 17 15:42:17.304747 2026] [core:error] [pid 60716:tid 60965] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:17.304766 2026] [core:error] [pid 60716:tid 60965] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:17.329839 2026] [security2:error] [pid 60716:tid 60897] [client 192.241.166.94:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxet8Psx0SVFjrd622wFQAABXU"], referer: http://ivorygarlock.com/old/
[Thu Sep 17 15:42:17.344551 2026] [security2:error] [pid 60716:tid 60939] [client 116.203.43.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moorekuehn.com"] [uri "/index.php"] [unique_id "aqxeucPsx0SVFjrd622weQAAAC0"]
[Thu Sep 17 15:42:17.439806 2026] [security2:error] [pid 60716:tid 60892] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/core/app/.env"] [unique_id "aqxeucPsx0SVFjrd622wiAAAAAA"]
[Thu Sep 17 15:42:17.504184 2026] [security2:error] [pid 60716:tid 61015] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeucPsx0SVFjrd622wgwAAAHk"]
[Thu Sep 17 15:42:17.549589 2026] [security2:error] [pid 60716:tid 60987] [client 192.241.166.94:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxeucPsx0SVFjrd622wiQAAXQI"], referer: http://ivorygarlock.com/wordpress/
[Thu Sep 17 15:42:17.564350 2026] [security2:error] [pid 60716:tid 60983] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/app/.env"] [unique_id "aqxeucPsx0SVFjrd622wjgAAAFk"]
[Thu Sep 17 15:42:17.573410 2026] [security2:error] [pid 60716:tid 60975] [client 34.26.62.32:53038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxeucPsx0SVFjrd622wjwAAAFE"]
[Thu Sep 17 15:42:17.605516 2026] [security2:error] [pid 60716:tid 60894] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/config/.env"] [unique_id "aqxeucPsx0SVFjrd622wkAAAAAI"]
[Thu Sep 17 15:42:17.761200 2026] [security2:error] [pid 60716:tid 60902] [client 34.26.62.32:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxeucPsx0SVFjrd622wlwAAAAo"]
[Thu Sep 17 15:42:17.762468 2026] [security2:error] [pid 60716:tid 60960] [client 192.241.166.94:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxeucPsx0SVFjrd622wlgAAQhM"], referer: http://ivorygarlock.com/wp/
[Thu Sep 17 15:42:17.766987 2026] [security2:error] [pid 60716:tid 60898] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/private/.env"] [unique_id "aqxeucPsx0SVFjrd622wmAAAAAY"]
[Thu Sep 17 15:42:17.861849 2026] [security2:error] [pid 60716:tid 60967] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/apps/.env"] [unique_id "aqxeucPsx0SVFjrd622wnAAAAEk"]
[Thu Sep 17 15:42:17.928306 2026] [security2:error] [pid 60716:tid 60977] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/application/.env"] [unique_id "aqxeucPsx0SVFjrd622woQAAAFM"]
[Thu Sep 17 15:42:17.965902 2026] [security2:error] [pid 60716:tid 60901] [client 192.241.166.94:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxeucPsx0SVFjrd622wnQAACRQ"], referer: http://ivorygarlock.com/backup/
[Thu Sep 17 15:42:17.984135 2026] [security2:error] [pid 60716:tid 61018] [client 34.26.62.32:53056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxeucPsx0SVFjrd622wogAAAHw"]
[Thu Sep 17 15:42:18.054283 2026] [security2:error] [pid 60716:tid 61003] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/api/.env"] [unique_id "aqxeusPsx0SVFjrd622wqAAAAG0"]
[Thu Sep 17 15:42:18.055864 2026] [core:error] [pid 60716:tid 61016] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:18.055876 2026] [core:error] [pid 60716:tid 61016] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:18.089467 2026] [security2:error] [pid 60716:tid 60962] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/bootstrap/.env"] [unique_id "aqxeusPsx0SVFjrd622wqgAAAEQ"]
[Thu Sep 17 15:42:18.201175 2026] [security2:error] [pid 60716:tid 60918] [client 34.165.71.35:57896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "commcapusa.gcpmanagement.com"] [uri "/"] [unique_id "aqxeusPsx0SVFjrd622wrgAAABo"]
[Thu Sep 17 15:42:18.211828 2026] [security2:error] [pid 60716:tid 61011] [client 34.26.62.32:53070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxeusPsx0SVFjrd622wrwAAAHU"]
[Thu Sep 17 15:42:18.254674 2026] [security2:error] [pid 60716:tid 60937] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/database/.env"] [unique_id "aqxeusPsx0SVFjrd622wsgAAACs"]
[Thu Sep 17 15:42:18.255392 2026] [security2:error] [pid 60716:tid 60917] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/web/.env"] [unique_id "aqxeusPsx0SVFjrd622wswAAABk"]
[Thu Sep 17 15:42:18.392402 2026] [security2:error] [pid 60716:tid 61013] [client 192.241.166.94:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxeusPsx0SVFjrd622wtQAAdxc"], referer: http://ivorygarlock.com/new/
[Thu Sep 17 15:42:18.417051 2026] [security2:error] [pid 60716:tid 60978] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/storage/.env"] [unique_id "aqxeusPsx0SVFjrd622wtwAAAFQ"]
[Thu Sep 17 15:42:18.420272 2026] [security2:error] [pid 60716:tid 60989] [client 34.26.62.32:53080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxeusPsx0SVFjrd622wuQAAAF8"]
[Thu Sep 17 15:42:18.422618 2026] [security2:error] [pid 60716:tid 60936] [client 177.44.133.72:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeusPsx0SVFjrd622wuwAAACo"]
[Thu Sep 17 15:42:18.422733 2026] [security2:error] [pid 60716:tid 60936] [client 177.44.133.72:59011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxeusPsx0SVFjrd622wuwAAACo"]
[Thu Sep 17 15:42:18.475613 2026] [security2:error] [pid 60716:tid 60914] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/site/.env"] [unique_id "aqxeusPsx0SVFjrd622wvQAAABY"]
[Thu Sep 17 15:42:18.578197 2026] [security2:error] [pid 60716:tid 61000] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/var/www/.env"] [unique_id "aqxeusPsx0SVFjrd622wwAAAAGo"]
[Thu Sep 17 15:42:18.600094 2026] [security2:error] [pid 60716:tid 60968] [client 192.241.166.94:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxeusPsx0SVFjrd622wvgAAShY"], referer: http://ivorygarlock.com/blog/
[Thu Sep 17 15:42:18.621866 2026] [security2:error] [pid 60716:tid 60997] [client 34.26.62.32:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxeusPsx0SVFjrd622wwgAAAGc"]
[Thu Sep 17 15:42:18.740514 2026] [security2:error] [pid 60716:tid 60919] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/var/www/html/.env"] [unique_id "aqxeusPsx0SVFjrd622wxQAAABs"]
[Thu Sep 17 15:42:18.744383 2026] [security2:error] [pid 60716:tid 60981] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/public/.env"] [unique_id "aqxeusPsx0SVFjrd622wxwAAAFc"]
[Thu Sep 17 15:42:18.917035 2026] [security2:error] [pid 60716:tid 61015] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/current/.env"] [unique_id "aqxeusPsx0SVFjrd622wzAAAAHk"]
[Thu Sep 17 15:42:19.067430 2026] [security2:error] [pid 60716:tid 60983] [client 136.0.94.50:38611] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.moorekuehn.com"] [uri "/robots.txt"] [unique_id "aqxeu8Psx0SVFjrd622w0QAAAFk"]
[Thu Sep 17 15:42:19.077968 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/release/.env"] [unique_id "aqxeu8Psx0SVFjrd622w0gAAAGs"]
[Thu Sep 17 15:42:19.139539 2026] [security2:error] [pid 60716:tid 60995] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/.env"] [unique_id "aqxeu8Psx0SVFjrd622w1QAAAGU"]
[Thu Sep 17 15:42:19.141993 2026] [security2:error] [pid 60716:tid 60960] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/backend/.env"] [unique_id "aqxeu8Psx0SVFjrd622w1gAAAEI"]
[Thu Sep 17 15:42:19.147710 2026] [security2:error] [pid 60716:tid 60975] [client 66.249.66.14:63042] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.packforceindustrial.themihelichs.com"] [uri "/robots.txt"] [unique_id "aqxeu8Psx0SVFjrd622w1wAAAFE"]
[Thu Sep 17 15:42:19.203190 2026] [core:error] [pid 60716:tid 60902] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:19.203209 2026] [core:error] [pid 60716:tid 60902] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:19.240563 2026] [security2:error] [pid 60716:tid 61004] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/releases/.env"] [unique_id "aqxeu8Psx0SVFjrd622w3QAAAG4"]
[Thu Sep 17 15:42:19.330917 2026] [security2:error] [pid 60716:tid 60963] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/server/.env"] [unique_id "aqxeu8Psx0SVFjrd622w4gAAAEU"]
[Thu Sep 17 15:42:19.406052 2026] [security2:error] [pid 60716:tid 60951] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeu8Psx0SVFjrd622w4QAAADk"]
[Thu Sep 17 15:42:19.406769 2026] [security2:error] [pid 60716:tid 60901] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/shared/.env"] [unique_id "aqxeu8Psx0SVFjrd622w5gAAAAk"]
[Thu Sep 17 15:42:19.529944 2026] [security2:error] [pid 60716:tid 60994] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/frontend/.env"] [unique_id "aqxeu8Psx0SVFjrd622w7AAAAGQ"]
[Thu Sep 17 15:42:19.568960 2026] [security2:error] [pid 60716:tid 61017] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/deploy/.env"] [unique_id "aqxeu8Psx0SVFjrd622w7gAAAHs"]
[Thu Sep 17 15:42:19.649478 2026] [security2:error] [pid 60716:tid 60896] [client 34.26.62.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/index.php"] [unique_id "aqxeu8Psx0SVFjrd622w7QAAAAQ"]
[Thu Sep 17 15:42:19.728140 2026] [security2:error] [pid 60716:tid 61013] [client 34.26.62.32:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxeu8Psx0SVFjrd622w9gAAAHc"]
[Thu Sep 17 15:42:19.730887 2026] [security2:error] [pid 60716:tid 60908] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/build/.env"] [unique_id "aqxeu8Psx0SVFjrd622w9wAAABA"]
[Thu Sep 17 15:42:19.819396 2026] [security2:error] [pid 60716:tid 60956] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/src/.env"] [unique_id "aqxeu8Psx0SVFjrd622w-QAAAD4"]
[Thu Sep 17 15:42:19.847548 2026] [security2:error] [pid 60716:tid 60977] [client 143.105.152.240:22743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeu8Psx0SVFjrd622w-gAAAFM"]
[Thu Sep 17 15:42:19.868836 2026] [security2:error] [pid 60716:tid 60977] [client 143.105.152.240:22743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxeu8Psx0SVFjrd622w-gAAAFM"]
[Thu Sep 17 15:42:19.892950 2026] [security2:error] [pid 60716:tid 60965] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/dist/.env"] [unique_id "aqxeu8Psx0SVFjrd622w_QAAAEc"]
[Thu Sep 17 15:42:19.922345 2026] [security2:error] [pid 60716:tid 60958] [client 34.26.62.32:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxeu8Psx0SVFjrd622xAQAAAEA"]
[Thu Sep 17 15:42:19.940307 2026] [core:error] [pid 60716:tid 61000] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:19.940325 2026] [core:error] [pid 60716:tid 61000] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:20.027655 2026] [security2:error] [pid 60716:tid 60935] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/core/.env"] [unique_id "aqxevMPsx0SVFjrd622xCQAAACk"]
[Thu Sep 17 15:42:20.054776 2026] [security2:error] [pid 60716:tid 60996] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/public_html/.env"] [unique_id "aqxevMPsx0SVFjrd622xCwAAAGY"]
[Thu Sep 17 15:42:20.115285 2026] [security2:error] [pid 60716:tid 60919] [client 34.26.62.32:53114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxevMPsx0SVFjrd622xDQAAABs"]
[Thu Sep 17 15:42:20.217284 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/htdocs/.env"] [unique_id "aqxevMPsx0SVFjrd622xEgAAAGs"]
[Thu Sep 17 15:42:20.254181 2026] [security2:error] [pid 60716:tid 60925] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/core/app/.env"] [unique_id "aqxevMPsx0SVFjrd622xEwAAACA"]
[Thu Sep 17 15:42:20.324630 2026] [security2:error] [pid 60716:tid 60906] [client 34.26.62.32:53116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxevMPsx0SVFjrd622xFAAAAA4"]
[Thu Sep 17 15:42:20.385877 2026] [security2:error] [pid 60716:tid 60920] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/www/.env"] [unique_id "aqxevMPsx0SVFjrd622xFQAAABw"]
[Thu Sep 17 15:42:20.495810 2026] [security2:error] [pid 60716:tid 61004] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/config/.env"] [unique_id "aqxevMPsx0SVFjrd622xHAAAAG4"]
[Thu Sep 17 15:42:20.537959 2026] [security2:error] [pid 60716:tid 60961] [client 34.26.62.32:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxevMPsx0SVFjrd622xHQAAAEM"]
[Thu Sep 17 15:42:20.550211 2026] [security2:error] [pid 60716:tid 60909] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/html/.env"] [unique_id "aqxevMPsx0SVFjrd622xHgAAABE"]
[Thu Sep 17 15:42:20.696375 2026] [security2:error] [pid 60716:tid 60929] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/private/.env"] [unique_id "aqxevMPsx0SVFjrd622xJQAAACQ"]
[Thu Sep 17 15:42:20.712234 2026] [security2:error] [pid 60716:tid 60942] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/live/.env"] [unique_id "aqxevMPsx0SVFjrd622xJgAAADA"]
[Thu Sep 17 15:42:20.716891 2026] [core:error] [pid 60716:tid 60895] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:20.716906 2026] [core:error] [pid 60716:tid 60895] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:20.751844 2026] [security2:error] [pid 60716:tid 60900] [client 34.26.62.32:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxevMPsx0SVFjrd622xKQAAAAg"]
[Thu Sep 17 15:42:20.853595 2026] [security2:error] [pid 60716:tid 60932] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/.env.bak"] [unique_id "aqxevMPsx0SVFjrd622xKwAAACY"]
[Thu Sep 17 15:42:20.873814 2026] [security2:error] [pid 60716:tid 61017] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/prod/.env"] [unique_id "aqxevMPsx0SVFjrd622xLgAAAHs"]
[Thu Sep 17 15:42:20.934837 2026] [security2:error] [pid 60716:tid 60967] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/application/.env"] [unique_id "aqxevMPsx0SVFjrd622xMAAAAEk"]
[Thu Sep 17 15:42:20.936177 2026] [security2:error] [pid 60716:tid 60962] [client 34.26.62.32:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxevMPsx0SVFjrd622xMQAAAEQ"]
[Thu Sep 17 15:42:20.974641 2026] [authz_core:error] [pid 60716:tid 60903] [client 40.81.232.68:65256] AH01630: client denied by server configuration: /home3/houselif/public_html/wp-includes/widgets/error_log, referer: binance.com
[Thu Sep 17 15:42:20.980259 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.248.240:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/app/.env"] [unique_id "aqxevMPsx0SVFjrd622xMwAAADQ"]
[Thu Sep 17 15:42:21.035024 2026] [security2:error] [pid 60716:tid 60980] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/dev/.env"] [unique_id "aqxevcPsx0SVFjrd622xNAAAAFY"]
[Thu Sep 17 15:42:21.107059 2026] [security2:error] [pid 60716:tid 60904] [client 169.58.197.251:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxevcPsx0SVFjrd622xNQAAAAw"], referer: binance.com
[Thu Sep 17 15:42:21.126177 2026] [security2:error] [pid 60716:tid 60917] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/.env.backup"] [unique_id "aqxevcPsx0SVFjrd622xNwAAABk"]
[Thu Sep 17 15:42:21.136790 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.248.240:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/apps/.env"] [unique_id "aqxevcPsx0SVFjrd622xOAAAAG0"]
[Thu Sep 17 15:42:21.175338 2026] [security2:error] [pid 60716:tid 60918] [client 34.26.62.32:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxevcPsx0SVFjrd622xOwAAABo"]
[Thu Sep 17 15:42:21.189727 2026] [security2:error] [pid 60716:tid 60912] [client 79.116.89.151:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxevcPsx0SVFjrd622xPAAAABQ"]
[Thu Sep 17 15:42:21.189825 2026] [security2:error] [pid 60716:tid 60912] [client 79.116.89.151:62065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxevcPsx0SVFjrd622xPAAAABQ"]
[Thu Sep 17 15:42:21.199264 2026] [security2:error] [pid 60716:tid 60999] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/bootstrap/.env"] [unique_id "aqxevcPsx0SVFjrd622xPgAAAGk"]
[Thu Sep 17 15:42:21.202246 2026] [security2:error] [pid 60716:tid 60998] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/staging/.env"] [unique_id "aqxevcPsx0SVFjrd622xPwAAAGg"]
[Thu Sep 17 15:42:21.319263 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.248.240:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/api/.env"] [unique_id "aqxevcPsx0SVFjrd622xQgAAAEc"]
[Thu Sep 17 15:42:21.373169 2026] [security2:error] [pid 60716:tid 60958] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/opt/.env"] [unique_id "aqxevcPsx0SVFjrd622xQwAAAEA"]
[Thu Sep 17 15:42:21.421787 2026] [security2:error] [pid 60716:tid 60893] [client 34.26.62.32:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxevcPsx0SVFjrd622xRgAAAAE"]
[Thu Sep 17 15:42:21.481551 2026] [security2:error] [pid 60716:tid 61021] [client 34.154.248.240:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/web/.env"] [unique_id "aqxevcPsx0SVFjrd622xSQAAAH8"]
[Thu Sep 17 15:42:21.481578 2026] [security2:error] [pid 60716:tid 60968] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/database/.env"] [unique_id "aqxevcPsx0SVFjrd622xSAAAAEo"]
[Thu Sep 17 15:42:21.537541 2026] [core:error] [pid 60716:tid 60982] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:21.537565 2026] [core:error] [pid 60716:tid 60982] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:21.541783 2026] [security2:error] [pid 60716:tid 60997] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/laravel/.env"] [unique_id "aqxevcPsx0SVFjrd622xSwAAAGc"]
[Thu Sep 17 15:42:21.629862 2026] [security2:error] [pid 60716:tid 60978] [client 136.158.61.34:41616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxevcPsx0SVFjrd622xTQAAAFQ"]
[Thu Sep 17 15:42:21.629990 2026] [security2:error] [pid 60716:tid 60978] [client 136.158.61.34:41616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxevcPsx0SVFjrd622xTQAAAFQ"]
[Thu Sep 17 15:42:21.632331 2026] [security2:error] [pid 60716:tid 60989] [client 34.26.62.32:53174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxevcPsx0SVFjrd622xTgAAAF8"]
[Thu Sep 17 15:42:21.643803 2026] [security2:error] [pid 60716:tid 60949] [client 34.154.248.240:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/site/.env"] [unique_id "aqxevcPsx0SVFjrd622xTwAAADc"]
[Thu Sep 17 15:42:21.660049 2026] [security2:error] [pid 60716:tid 60996] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/.env.old"] [unique_id "aqxevcPsx0SVFjrd622xUAAAAGY"]
[Thu Sep 17 15:42:21.703262 2026] [security2:error] [pid 60716:tid 60916] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/symfony/.env"] [unique_id "aqxevcPsx0SVFjrd622xUwAAABg"]
[Thu Sep 17 15:42:21.776579 2026] [security2:error] [pid 60716:tid 60928] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/storage/.env"] [unique_id "aqxevcPsx0SVFjrd622xVQAAACM"]
[Thu Sep 17 15:42:21.810265 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.248.240:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/public/.env"] [unique_id "aqxevcPsx0SVFjrd622xVgAAAF0"]
[Thu Sep 17 15:42:21.831336 2026] [security2:error] [pid 60716:tid 60947] [client 34.26.62.32:53190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxevcPsx0SVFjrd622xVwAAADU"]
[Thu Sep 17 15:42:21.864794 2026] [security2:error] [pid 60716:tid 60899] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/wordpress/.env"] [unique_id "aqxevcPsx0SVFjrd622xWQAAAAc"]
[Thu Sep 17 15:42:22.026390 2026] [security2:error] [pid 60716:tid 60995] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/wp/.env"] [unique_id "aqxevsPsx0SVFjrd622xXwAAAGU"]
[Thu Sep 17 15:42:22.035730 2026] [security2:error] [pid 60716:tid 61014] [client 34.26.62.32:53206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxevsPsx0SVFjrd622xYAAAAHg"]
[Thu Sep 17 15:42:22.085920 2026] [security2:error] [pid 60716:tid 61004] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/var/www/.env"] [unique_id "aqxevsPsx0SVFjrd622xYgAAAG4"]
[Thu Sep 17 15:42:22.191111 2026] [security2:error] [pid 60716:tid 60993] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/cms/.env"] [unique_id "aqxevsPsx0SVFjrd622xZwAAAGM"]
[Thu Sep 17 15:42:22.239565 2026] [security2:error] [pid 60716:tid 61018] [client 34.26.62.32:53214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxevsPsx0SVFjrd622xaAAAAHw"]
[Thu Sep 17 15:42:22.249203 2026] [security2:error] [pid 60716:tid 60920] [client 34.166.135.226:49252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "aqxevsPsx0SVFjrd622xagAAABw"]
[Thu Sep 17 15:42:22.353921 2026] [security2:error] [pid 60716:tid 61016] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/drupal/.env"] [unique_id "aqxevsPsx0SVFjrd622xawAAAHo"]
[Thu Sep 17 15:42:22.355011 2026] [security2:error] [pid 60716:tid 60900] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/var/www/html/.env"] [unique_id "aqxevsPsx0SVFjrd622xbAAAAAg"]
[Thu Sep 17 15:42:22.441181 2026] [security2:error] [pid 60716:tid 60994] [client 34.26.62.32:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxevsPsx0SVFjrd622xbwAAAGQ"]
[Thu Sep 17 15:42:22.479361 2026] [security2:error] [pid 60716:tid 61017] [client 34.166.135.226:49252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "aqxevsPsx0SVFjrd622xcAAAAHs"]
[Thu Sep 17 15:42:22.500792 2026] [security2:error] [pid 60716:tid 60948] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/backend/.env"] [unique_id "aqxevsPsx0SVFjrd622xcgAAADY"]
[Thu Sep 17 15:42:22.514430 2026] [security2:error] [pid 60716:tid 60941] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/joomla/.env"] [unique_id "aqxevsPsx0SVFjrd622xdAAAAC8"]
[Thu Sep 17 15:42:22.620950 2026] [security2:error] [pid 60716:tid 60903] [client 34.26.62.32:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxevsPsx0SVFjrd622xeAAAAAs"]
[Thu Sep 17 15:42:22.668804 2026] [security2:error] [pid 60716:tid 60992] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/server/.env"] [unique_id "aqxevsPsx0SVFjrd622xfAAAAGI"]
[Thu Sep 17 15:42:22.680262 2026] [security2:error] [pid 60716:tid 60918] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/magento/.env"] [unique_id "aqxevsPsx0SVFjrd622xfQAAABo"]
[Thu Sep 17 15:42:22.716439 2026] [security2:error] [pid 60716:tid 60998] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/current/.env"] [unique_id "aqxevsPsx0SVFjrd622xfgAAAGg"]
[Thu Sep 17 15:42:22.773403 2026] [core:error] [pid 60716:tid 61007] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:22.773421 2026] [core:error] [pid 60716:tid 61007] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:22.837216 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/frontend/.env"] [unique_id "aqxevsPsx0SVFjrd622xiwAAAEc"]
[Thu Sep 17 15:42:22.845509 2026] [security2:error] [pid 60716:tid 60914] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/shopify/.env"] [unique_id "aqxevsPsx0SVFjrd622xjAAAABY"]
[Thu Sep 17 15:42:22.847339 2026] [security2:error] [pid 60716:tid 60977] [client 34.26.62.32:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxevsPsx0SVFjrd622xjQAAAFM"]
[Thu Sep 17 15:42:22.964887 2026] [security2:error] [pid 60716:tid 60944] [client 43.172.196.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxevsPsx0SVFjrd622xigAAADI"]
[Thu Sep 17 15:42:22.996436 2026] [security2:error] [pid 60716:tid 60979] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/release/.env"] [unique_id "aqxevsPsx0SVFjrd622xkwAAAFU"]
[Thu Sep 17 15:42:22.996980 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/src/.env"] [unique_id "aqxevsPsx0SVFjrd622xlAAAAFg"]
[Thu Sep 17 15:42:23.005646 2026] [security2:error] [pid 60716:tid 60973] [client 43.172.194.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxevsPsx0SVFjrd622xiAAAAE8"]
[Thu Sep 17 15:42:23.010121 2026] [security2:error] [pid 60716:tid 60953] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/prestashop/.env"] [unique_id "aqxev8Psx0SVFjrd622xlQAAADs"]
[Thu Sep 17 15:42:23.046366 2026] [security2:error] [pid 60716:tid 60968] [client 34.26.62.32:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxev8Psx0SVFjrd622xlgAAAEo"]
[Thu Sep 17 15:42:23.106727 2026] [security2:error] [pid 60716:tid 60893] [client 43.172.196.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxevsPsx0SVFjrd622xkQAAAAE"]
[Thu Sep 17 15:42:23.160090 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/core/.env"] [unique_id "aqxev8Psx0SVFjrd622xmgAAABM"]
[Thu Sep 17 15:42:23.171873 2026] [security2:error] [pid 60716:tid 60990] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/codeigniter/.env"] [unique_id "aqxev8Psx0SVFjrd622xmwAAAGA"]
[Thu Sep 17 15:42:23.228953 2026] [security2:error] [pid 60716:tid 60950] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/releases/.env"] [unique_id "aqxev8Psx0SVFjrd622xnwAAADg"]
[Thu Sep 17 15:42:23.308257 2026] [security2:error] [pid 60716:tid 60983] [client 34.26.62.32:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxev8Psx0SVFjrd622xoAAAAFk"]
[Thu Sep 17 15:42:23.317250 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/core/app/.env"] [unique_id "aqxev8Psx0SVFjrd622xoQAAAFs"]
[Thu Sep 17 15:42:23.333796 2026] [security2:error] [pid 60716:tid 60927] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/cakephp/.env"] [unique_id "aqxev8Psx0SVFjrd622xowAAACI"]
[Thu Sep 17 15:42:23.416492 2026] [security2:error] [pid 60716:tid 60910] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/shared/.env"] [unique_id "aqxev8Psx0SVFjrd622xpwAAABI"]
[Thu Sep 17 15:42:23.476947 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.135.226:48238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "aqxev8Psx0SVFjrd622xqAAAAF0"]
[Thu Sep 17 15:42:23.482991 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/config/.env"] [unique_id "aqxev8Psx0SVFjrd622xqQAAADM"]
[Thu Sep 17 15:42:23.495233 2026] [security2:error] [pid 60716:tid 61004] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/zend/.env"] [unique_id "aqxev8Psx0SVFjrd622xqgAAAG4"]
[Thu Sep 17 15:42:23.520486 2026] [security2:error] [pid 60716:tid 60926] [client 34.26.62.32:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxev8Psx0SVFjrd622xqwAAACE"]
[Thu Sep 17 15:42:23.543858 2026] [cgid:error] [pid 60716:tid 60819] [remote 104.28.42.106:25887] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:42:23.612622 2026] [security2:error] [pid 60716:tid 60929] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/deploy/.env"] [unique_id "aqxev8Psx0SVFjrd622xrwAAACQ"]
[Thu Sep 17 15:42:23.658781 2026] [security2:error] [pid 60716:tid 60920] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/yii/.env"] [unique_id "aqxev8Psx0SVFjrd622xsgAAABw"]
[Thu Sep 17 15:42:23.668023 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/private/.env"] [unique_id "aqxev8Psx0SVFjrd622xswAAAE0"]
[Thu Sep 17 15:42:23.727722 2026] [security2:error] [pid 60716:tid 60942] [client 34.26.62.32:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxev8Psx0SVFjrd622xtwAAADA"]
[Thu Sep 17 15:42:23.731301 2026] [core:error] [pid 60716:tid 61016] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:23.731319 2026] [core:error] [pid 60716:tid 61016] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:23.817709 2026] [security2:error] [pid 60716:tid 60980] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/build/.env"] [unique_id "aqxev8Psx0SVFjrd622xwQAAAFY"]
[Thu Sep 17 15:42:23.819956 2026] [security2:error] [pid 60716:tid 60946] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/laravel5/.env"] [unique_id "aqxev8Psx0SVFjrd622xwgAAADQ"]
[Thu Sep 17 15:42:23.829411 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/application/.env"] [unique_id "aqxev8Psx0SVFjrd622xxAAAAAw"]
[Thu Sep 17 15:42:23.902155 2026] [security2:error] [pid 60716:tid 60903] [client 34.26.62.32:53200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxev8Psx0SVFjrd622xxQAAAAs"]
[Thu Sep 17 15:42:23.932455 2026] [security2:error] [pid 60716:tid 60957] [client 103.61.184.148:50361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxev8Psx0SVFjrd622xyQAAAD8"]
[Thu Sep 17 15:42:23.932624 2026] [security2:error] [pid 60716:tid 60957] [client 103.61.184.148:50361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxev8Psx0SVFjrd622xyQAAAD8"]
[Thu Sep 17 15:42:23.983305 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/bootstrap/.env"] [unique_id "aqxev8Psx0SVFjrd622xzAAAAH0"]
[Thu Sep 17 15:42:23.986145 2026] [security2:error] [pid 60716:tid 60912] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/v1/.env"] [unique_id "aqxev8Psx0SVFjrd622xzQAAABQ"]
[Thu Sep 17 15:42:24.034895 2026] [security2:error] [pid 60716:tid 60943] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/dist/.env"] [unique_id "aqxewMPsx0SVFjrd622xzgAAADE"]
[Thu Sep 17 15:42:24.119304 2026] [security2:error] [pid 60716:tid 60917] [client 34.26.62.32:53204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxewMPsx0SVFjrd622xzwAAABk"]
[Thu Sep 17 15:42:24.147308 2026] [security2:error] [pid 60716:tid 60970] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/v2/.env"] [unique_id "aqxewMPsx0SVFjrd622x0gAAAEw"]
[Thu Sep 17 15:42:24.150218 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/database/.env"] [unique_id "aqxewMPsx0SVFjrd622x1AAAAEc"]
[Thu Sep 17 15:42:24.293565 2026] [security2:error] [pid 60716:tid 60973] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/public_html/.env"] [unique_id "aqxewMPsx0SVFjrd622x2AAAAE8"]
[Thu Sep 17 15:42:24.306311 2026] [security2:error] [pid 60716:tid 60953] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/storage/.env"] [unique_id "aqxewMPsx0SVFjrd622x2QAAADs"]
[Thu Sep 17 15:42:24.308477 2026] [security2:error] [pid 60716:tid 61002] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/v3/.env"] [unique_id "aqxewMPsx0SVFjrd622x2gAAAGw"]
[Thu Sep 17 15:42:24.324582 2026] [security2:error] [pid 60716:tid 60964] [client 34.26.62.32:53220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxewMPsx0SVFjrd622x3QAAAEY"]
[Thu Sep 17 15:42:24.391851 2026] [security2:error] [pid 60716:tid 60978] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/.env.swp"] [unique_id "aqxewMPsx0SVFjrd622x3wAAAFQ"]
[Thu Sep 17 15:42:24.466592 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/var/www/.env"] [unique_id "aqxewMPsx0SVFjrd622x4gAAAEA"]
[Thu Sep 17 15:42:24.472674 2026] [security2:error] [pid 60716:tid 60916] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/api/v1/.env"] [unique_id "aqxewMPsx0SVFjrd622x4wAAABg"]
[Thu Sep 17 15:42:24.476547 2026] [core:error] [pid 60716:tid 60919] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:24.476571 2026] [core:error] [pid 60716:tid 60919] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:24.502530 2026] [security2:error] [pid 60716:tid 60996] [client 34.26.62.32:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxewMPsx0SVFjrd622x5QAAAGY"]
[Thu Sep 17 15:42:24.552276 2026] [security2:error] [pid 60716:tid 60990] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/htdocs/.env"] [unique_id "aqxewMPsx0SVFjrd622x5wAAAGA"]
[Thu Sep 17 15:42:24.617757 2026] [security2:error] [pid 60716:tid 60950] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/.env~"] [unique_id "aqxewMPsx0SVFjrd622x6QAAADg"]
[Thu Sep 17 15:42:24.623905 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/var/www/html/.env"] [unique_id "aqxewMPsx0SVFjrd622x6gAAADU"]
[Thu Sep 17 15:42:24.635868 2026] [security2:error] [pid 60716:tid 60928] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/api/v2/.env"] [unique_id "aqxewMPsx0SVFjrd622x6wAAACM"]
[Thu Sep 17 15:42:24.694107 2026] [security2:error] [pid 60716:tid 60931] [client 34.26.62.32:53240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.62.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.msq.okl.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxewMPsx0SVFjrd622x7wAAACU"]
[Thu Sep 17 15:42:24.774631 2026] [security2:error] [pid 60716:tid 60926] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/www/.env"] [unique_id "aqxewMPsx0SVFjrd622x8QAAACE"]
[Thu Sep 17 15:42:24.786247 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/current/.env"] [unique_id "aqxewMPsx0SVFjrd622x8gAAAA8"]
[Thu Sep 17 15:42:24.797532 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/rest/.env"] [unique_id "aqxewMPsx0SVFjrd622x8wAAAGs"]
[Thu Sep 17 15:42:24.949886 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/release/.env"] [unique_id "aqxewMPsx0SVFjrd622x9QAAAE0"]
[Thu Sep 17 15:42:24.964124 2026] [security2:error] [pid 60716:tid 60972] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/graphql/.env"] [unique_id "aqxewMPsx0SVFjrd622x9gAAAE4"]
[Thu Sep 17 15:42:24.991933 2026] [security2:error] [pid 60716:tid 60900] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/html/.env"] [unique_id "aqxewMPsx0SVFjrd622x-QAAAAg"]
[Thu Sep 17 15:42:25.109269 2026] [security2:error] [pid 60716:tid 61017] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/releases/.env"] [unique_id "aqxewcPsx0SVFjrd622x_wAAAHs"]
[Thu Sep 17 15:42:25.125736 2026] [security2:error] [pid 60716:tid 60898] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/gateway/.env"] [unique_id "aqxewcPsx0SVFjrd622yAAAAAAY"]
[Thu Sep 17 15:42:25.213938 2026] [core:error] [pid 60716:tid 60957] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:25.213966 2026] [core:error] [pid 60716:tid 60957] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:25.245976 2026] [security2:error] [pid 60716:tid 60998] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/live/.env"] [unique_id "aqxewcPsx0SVFjrd622yCQAAAGg"]
[Thu Sep 17 15:42:25.279368 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/shared/.env"] [unique_id "aqxewcPsx0SVFjrd622yDAAAAH0"]
[Thu Sep 17 15:42:25.287837 2026] [security2:error] [pid 60716:tid 60912] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/microservice/.env"] [unique_id "aqxewcPsx0SVFjrd622yDQAAABQ"]
[Thu Sep 17 15:42:25.430068 2026] [security2:error] [pid 60716:tid 60936] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/prod/.env"] [unique_id "aqxewcPsx0SVFjrd622yEQAAACo"]
[Thu Sep 17 15:42:25.448641 2026] [security2:error] [pid 60716:tid 60995] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/service/.env"] [unique_id "aqxewcPsx0SVFjrd622yEgAAAGU"]
[Thu Sep 17 15:42:25.451759 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/deploy/.env"] [unique_id "aqxewcPsx0SVFjrd622yFAAAAC0"]
[Thu Sep 17 15:42:25.606969 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/build/.env"] [unique_id "aqxewcPsx0SVFjrd622yFwAAAHE"]
[Thu Sep 17 15:42:25.608937 2026] [security2:error] [pid 60716:tid 60909] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/api/v3/.env"] [unique_id "aqxewcPsx0SVFjrd622yGAAAABE"]
[Thu Sep 17 15:42:25.640524 2026] [security2:error] [pid 60716:tid 60970] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/dev/.env"] [unique_id "aqxewcPsx0SVFjrd622yGwAAAEw"]
[Thu Sep 17 15:42:25.766143 2026] [security2:error] [pid 60716:tid 60938] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/dist/.env"] [unique_id "aqxewcPsx0SVFjrd622yIQAAACw"]
[Thu Sep 17 15:42:25.770091 2026] [security2:error] [pid 60716:tid 60969] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/api/dev/.env"] [unique_id "aqxewcPsx0SVFjrd622yIgAAAEs"]
[Thu Sep 17 15:42:25.859452 2026] [security2:error] [pid 60716:tid 60937] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/staging/.env"] [unique_id "aqxewcPsx0SVFjrd622yJAAAACs"]
[Thu Sep 17 15:42:25.923544 2026] [core:error] [pid 60716:tid 60992] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:25.923570 2026] [core:error] [pid 60716:tid 60992] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:25.927367 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/public_html/.env"] [unique_id "aqxewcPsx0SVFjrd622yKQAAACc"]
[Thu Sep 17 15:42:25.931399 2026] [security2:error] [pid 60716:tid 60953] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/api/staging/.env"] [unique_id "aqxewcPsx0SVFjrd622yKgAAADs"]
[Thu Sep 17 15:42:26.089536 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/htdocs/.env"] [unique_id "aqxewsPsx0SVFjrd622yMAAAAEA"]
[Thu Sep 17 15:42:26.089568 2026] [security2:error] [pid 60716:tid 60968] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/opt/.env"] [unique_id "aqxewsPsx0SVFjrd622yLwAAAEo"]
[Thu Sep 17 15:42:26.092724 2026] [security2:error] [pid 60716:tid 60919] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/vendor/.env"] [unique_id "aqxewsPsx0SVFjrd622yMgAAABs"]
[Thu Sep 17 15:42:26.181134 2026] [security2:error] [pid 60716:tid 60928] [client 216.73.216.134:48099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.caitlinannemack.com"] [uri "/shop.php/sitemap624.xml"] [unique_id "aqxewsPsx0SVFjrd622yOQAAACM"]
[Thu Sep 17 15:42:26.251296 2026] [security2:error] [pid 60716:tid 60981] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/www/.env"] [unique_id "aqxewsPsx0SVFjrd622yOwAAAFc"]
[Thu Sep 17 15:42:26.254978 2026] [security2:error] [pid 60716:tid 60910] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/lib/.env"] [unique_id "aqxewsPsx0SVFjrd622yPAAAABI"]
[Thu Sep 17 15:42:26.314504 2026] [security2:error] [pid 60716:tid 60913] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/laravel/.env"] [unique_id "aqxewsPsx0SVFjrd622yQgAAABU"]
[Thu Sep 17 15:42:26.408778 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/html/.env"] [unique_id "aqxewsPsx0SVFjrd622ySAAAACA"]
[Thu Sep 17 15:42:26.416404 2026] [security2:error] [pid 60716:tid 60895] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/resources/.env"] [unique_id "aqxewsPsx0SVFjrd622ySQAAAAM"]
[Thu Sep 17 15:42:26.564968 2026] [security2:error] [pid 60716:tid 61009] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/live/.env"] [unique_id "aqxewsPsx0SVFjrd622yUAAAAHM"]
[Thu Sep 17 15:42:26.577949 2026] [security2:error] [pid 60716:tid 60946] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/assets/.env"] [unique_id "aqxewsPsx0SVFjrd622yUQAAADQ"]
[Thu Sep 17 15:42:26.596629 2026] [security2:error] [pid 60716:tid 60980] [client 34.165.71.35:42908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/symfony/.env"] [unique_id "aqxewsPsx0SVFjrd622yUgAAAFY"]
[Thu Sep 17 15:42:26.618535 2026] [security2:error] [pid 60716:tid 60912] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/app/.env"] [unique_id "aqxewsPsx0SVFjrd622yWAAAABQ"]
[Thu Sep 17 15:42:26.624526 2026] [security2:error] [pid 60716:tid 61008] [client 57.141.14.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.npae.net"] [uri "/index.php"] [unique_id "aqxewMPsx0SVFjrd622x3gAAAHI"]
[Thu Sep 17 15:42:26.640314 2026] [core:error] [pid 60716:tid 60967] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:26.640335 2026] [core:error] [pid 60716:tid 60967] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:26.730939 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/prod/.env"] [unique_id "aqxewsPsx0SVFjrd622yXwAAABE"]
[Thu Sep 17 15:42:26.740146 2026] [security2:error] [pid 60716:tid 60956] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/uploads/.env"] [unique_id "aqxewsPsx0SVFjrd622yYAAAAD4"]
[Thu Sep 17 15:42:26.828316 2026] [security2:error] [pid 60716:tid 60905] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/apps/.env"] [unique_id "aqxewsPsx0SVFjrd622yYgAAAA0"]
[Thu Sep 17 15:42:26.891578 2026] [security2:error] [pid 60716:tid 60949] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/dev/.env"] [unique_id "aqxewsPsx0SVFjrd622yYwAAADc"]
[Thu Sep 17 15:42:26.891707 2026] [security2:error] [pid 60716:tid 60954] [client 40.81.232.68:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "aqxewsPsx0SVFjrd622yZAAAADw"], referer: binance.com
[Thu Sep 17 15:42:26.902193 2026] [security2:error] [pid 60716:tid 60914] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/internal/.env"] [unique_id "aqxewsPsx0SVFjrd622yZQAAABY"]
[Thu Sep 17 15:42:27.024868 2026] [security2:error] [pid 60716:tid 60997] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/api/.env"] [unique_id "aqxew8Psx0SVFjrd622yaQAAAGc"]
[Thu Sep 17 15:42:27.061725 2026] [security2:error] [pid 60716:tid 60959] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/staging/.env"] [unique_id "aqxew8Psx0SVFjrd622yagAAAEE"]
[Thu Sep 17 15:42:27.063885 2026] [security2:error] [pid 60716:tid 61010] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/tools/.env"] [unique_id "aqxew8Psx0SVFjrd622yawAAAHQ"]
[Thu Sep 17 15:42:27.232392 2026] [security2:error] [pid 60716:tid 60935] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/web/.env"] [unique_id "aqxew8Psx0SVFjrd622ydAAAACk"]
[Thu Sep 17 15:42:27.232392 2026] [security2:error] [pid 60716:tid 60899] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/opt/.env"] [unique_id "aqxew8Psx0SVFjrd622ydQAAAAc"]
[Thu Sep 17 15:42:27.232427 2026] [security2:error] [pid 60716:tid 60950] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/scripts/.env"] [unique_id "aqxew8Psx0SVFjrd622ydgAAADg"]
[Thu Sep 17 15:42:27.242045 2026] [security2:error] [pid 60716:tid 60937] [client 14.96.156.146:64381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxew8Psx0SVFjrd622ydwAAACs"]
[Thu Sep 17 15:42:27.242191 2026] [security2:error] [pid 60716:tid 60937] [client 14.96.156.146:64381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxew8Psx0SVFjrd622ydwAAACs"]
[Thu Sep 17 15:42:27.353518 2026] [core:error] [pid 60716:tid 61014] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:27.353535 2026] [core:error] [pid 60716:tid 61014] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:27.398604 2026] [security2:error] [pid 60716:tid 60931] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/bin/.env"] [unique_id "aqxew8Psx0SVFjrd622yfAAAACU"]
[Thu Sep 17 15:42:27.399719 2026] [security2:error] [pid 60716:tid 60978] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/laravel/.env"] [unique_id "aqxew8Psx0SVFjrd622yfQAAAFQ"]
[Thu Sep 17 15:42:27.420016 2026] [security2:error] [pid 60716:tid 60988] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/wordpress/.env"] [unique_id "aqxew8Psx0SVFjrd622yfgAAAF4"]
[Thu Sep 17 15:42:27.431411 2026] [security2:error] [pid 60716:tid 61004] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/site/.env"] [unique_id "aqxew8Psx0SVFjrd622yfwAAAG4"]
[Thu Sep 17 15:42:27.557737 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/symfony/.env"] [unique_id "aqxew8Psx0SVFjrd622ygAAAAA8"]
[Thu Sep 17 15:42:27.562583 2026] [security2:error] [pid 60716:tid 60987] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/sbin/.env"] [unique_id "aqxew8Psx0SVFjrd622ygQAAAF0"]
[Thu Sep 17 15:42:27.632997 2026] [security2:error] [pid 60716:tid 60961] [client 169.58.197.251:57235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxew8Psx0SVFjrd622yhQAAAEM"], referer: binance.com
[Thu Sep 17 15:42:27.655929 2026] [security2:error] [pid 60716:tid 60901] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/public/.env"] [unique_id "aqxew8Psx0SVFjrd622yhgAAAAk"]
[Thu Sep 17 15:42:27.681775 2026] [security2:error] [pid 60716:tid 60972] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/wp/.env"] [unique_id "aqxew8Psx0SVFjrd622yiQAAAE4"]
[Thu Sep 17 15:42:27.713494 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/wordpress/.env"] [unique_id "aqxew8Psx0SVFjrd622yiwAAAGQ"]
[Thu Sep 17 15:42:27.723522 2026] [security2:error] [pid 60716:tid 61017] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/local/.env"] [unique_id "aqxew8Psx0SVFjrd622yjAAAAHs"]
[Thu Sep 17 15:42:27.881063 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/wp/.env"] [unique_id "aqxew8Psx0SVFjrd622yjgAAAEQ"]
[Thu Sep 17 15:42:27.884259 2026] [security2:error] [pid 60716:tid 60941] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/portal/.env"] [unique_id "aqxew8Psx0SVFjrd622yjwAAAC8"]
[Thu Sep 17 15:42:27.910453 2026] [security2:error] [pid 60716:tid 60903] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/cms/.env"] [unique_id "aqxew8Psx0SVFjrd622ykAAAAAs"]
[Thu Sep 17 15:42:28.036001 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/cms/.env"] [unique_id "aqxexMPsx0SVFjrd622ykQAAAFE"]
[Thu Sep 17 15:42:28.044909 2026] [security2:error] [pid 60716:tid 60948] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/dashboard/.env"] [unique_id "aqxexMPsx0SVFjrd622ykwAAADY"]
[Thu Sep 17 15:42:28.069430 2026] [core:error] [pid 60716:tid 60957] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:28.069451 2026] [core:error] [pid 60716:tid 60957] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:28.123423 2026] [security2:error] [pid 60716:tid 60946] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/drupal/.env"] [unique_id "aqxexMPsx0SVFjrd622ymAAAADQ"]
[Thu Sep 17 15:42:28.137991 2026] [security2:error] [pid 60716:tid 60980] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/backend/.env"] [unique_id "aqxexMPsx0SVFjrd622ymQAAAFY"]
[Thu Sep 17 15:42:28.198277 2026] [security2:error] [pid 60716:tid 60908] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/drupal/.env"] [unique_id "aqxexMPsx0SVFjrd622yngAAABA"]
[Thu Sep 17 15:42:28.205724 2026] [security2:error] [pid 60716:tid 61013] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/panel/.env"] [unique_id "aqxexMPsx0SVFjrd622ynwAAAHc"]
[Thu Sep 17 15:42:28.312265 2026] [security2:error] [pid 60716:tid 60952] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/joomla/.env"] [unique_id "aqxexMPsx0SVFjrd622yoQAAADo"]
[Thu Sep 17 15:42:28.339348 2026] [security2:error] [pid 60716:tid 60967] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/server/.env"] [unique_id "aqxexMPsx0SVFjrd622yogAAAEk"]
[Thu Sep 17 15:42:28.360115 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/joomla/.env"] [unique_id "aqxexMPsx0SVFjrd622yowAAAHU"]
[Thu Sep 17 15:42:28.367267 2026] [security2:error] [pid 60716:tid 60934] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/crm/.env"] [unique_id "aqxexMPsx0SVFjrd622ypAAAACg"]
[Thu Sep 17 15:42:28.507998 2026] [security2:error] [pid 60716:tid 60900] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/magento/.env"] [unique_id "aqxexMPsx0SVFjrd622ypQAAAAg"]
[Thu Sep 17 15:42:28.525543 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/magento/.env"] [unique_id "aqxexMPsx0SVFjrd622ypgAAACo"]
[Thu Sep 17 15:42:28.528381 2026] [security2:error] [pid 60716:tid 61006] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/erp/.env"] [unique_id "aqxexMPsx0SVFjrd622ypwAAAHA"]
[Thu Sep 17 15:42:28.573254 2026] [security2:error] [pid 60716:tid 60999] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/frontend/.env"] [unique_id "aqxexMPsx0SVFjrd622yqAAAAGk"]
[Thu Sep 17 15:42:28.689412 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/shopify/.env"] [unique_id "aqxexMPsx0SVFjrd622yrQAAAC0"]
[Thu Sep 17 15:42:28.694198 2026] [security2:error] [pid 60716:tid 60909] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/shop/.env"] [unique_id "aqxexMPsx0SVFjrd622yrgAAABE"]
[Thu Sep 17 15:42:28.739425 2026] [security2:error] [pid 60716:tid 60970] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/shopify/.env"] [unique_id "aqxexMPsx0SVFjrd622yrwAAAEw"]
[Thu Sep 17 15:42:28.801233 2026] [security2:error] [pid 60716:tid 60905] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/src/.env"] [unique_id "aqxexMPsx0SVFjrd622ysQAAAA0"]
[Thu Sep 17 15:42:28.849688 2026] [core:error] [pid 60716:tid 60954] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:28.849706 2026] [core:error] [pid 60716:tid 60954] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:28.855376 2026] [security2:error] [pid 60716:tid 60969] [client 34.95.193.102:37204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/store/.env"] [unique_id "aqxexMPsx0SVFjrd622yuAAAAEs"]
[Thu Sep 17 15:42:28.866932 2026] [security2:error] [pid 60716:tid 60938] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/prestashop/.env"] [unique_id "aqxexMPsx0SVFjrd622yuQAAACw"]
[Thu Sep 17 15:42:28.961046 2026] [security2:error] [pid 60716:tid 60959] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/prestashop/.env"] [unique_id "aqxexMPsx0SVFjrd622yugAAAEE"]
[Thu Sep 17 15:42:29.008723 2026] [security2:error] [pid 60716:tid 61010] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/core/.env"] [unique_id "aqxexcPsx0SVFjrd622yuwAAAHQ"]
[Thu Sep 17 15:42:29.030847 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/codeigniter/.env"] [unique_id "aqxexcPsx0SVFjrd622yvAAAAFU"]
[Thu Sep 17 15:42:29.045240 2026] [security2:error] [pid 60716:tid 60943] [client 177.44.133.72:59682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxexcPsx0SVFjrd622yvQAAADE"]
[Thu Sep 17 15:42:29.045747 2026] [security2:error] [pid 60716:tid 60943] [client 177.44.133.72:59682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxexcPsx0SVFjrd622yvQAAADE"]
[Thu Sep 17 15:42:29.166757 2026] [security2:error] [pid 60716:tid 60928] [client 169.58.197.253:52139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxexcPsx0SVFjrd622ywQAAACM"], referer: binance.com
[Thu Sep 17 15:42:29.169518 2026] [security2:error] [pid 60716:tid 60899] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/codeigniter/.env"] [unique_id "aqxexcPsx0SVFjrd622ywwAAAAc"]
[Thu Sep 17 15:42:29.201042 2026] [security2:error] [pid 60716:tid 60893] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/cakephp/.env"] [unique_id "aqxexcPsx0SVFjrd622yxwAAAAE"]
[Thu Sep 17 15:42:29.244337 2026] [security2:error] [pid 60716:tid 61015] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/core/app/.env"] [unique_id "aqxexcPsx0SVFjrd622yyAAAAHk"]
[Thu Sep 17 15:42:29.362936 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/zend/.env"] [unique_id "aqxexcPsx0SVFjrd622yyQAAABg"]
[Thu Sep 17 15:42:29.378271 2026] [security2:error] [pid 60716:tid 60931] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/cakephp/.env"] [unique_id "aqxexcPsx0SVFjrd622yygAAACU"]
[Thu Sep 17 15:42:29.490498 2026] [security2:error] [pid 60716:tid 60988] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/config/.env"] [unique_id "aqxexcPsx0SVFjrd622yywAAAF4"]
[Thu Sep 17 15:42:29.490501 2026] [security2:error] [pid 60716:tid 60981] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/saas/.env"] [unique_id "aqxexcPsx0SVFjrd622yzAAAAFc"]
[Thu Sep 17 15:42:29.567361 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/yii/.env"] [unique_id "aqxexcPsx0SVFjrd622yzwAAACE"]
[Thu Sep 17 15:42:29.583258 2026] [core:error] [pid 60716:tid 60945] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:29.583273 2026] [core:error] [pid 60716:tid 60945] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:29.638568 2026] [security2:error] [pid 60716:tid 60892] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/zend/.env"] [unique_id "aqxexcPsx0SVFjrd622y0gAAAAA"]
[Thu Sep 17 15:42:29.652102 2026] [security2:error] [pid 60716:tid 60929] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/client/.env"] [unique_id "aqxexcPsx0SVFjrd622y0wAAACQ"]
[Thu Sep 17 15:42:29.727526 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/laravel5/.env"] [unique_id "aqxexcPsx0SVFjrd622y1wAAAGQ"]
[Thu Sep 17 15:42:29.732155 2026] [security2:error] [pid 60716:tid 60963] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/private/.env"] [unique_id "aqxexcPsx0SVFjrd622y2AAAAEU"]
[Thu Sep 17 15:42:29.812445 2026] [security2:error] [pid 60716:tid 61017] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/project/.env"] [unique_id "aqxexcPsx0SVFjrd622y2QAAAHs"]
[Thu Sep 17 15:42:29.845484 2026] [security2:error] [pid 60716:tid 60993] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/yii/.env"] [unique_id "aqxexcPsx0SVFjrd622y2wAAAGM"]
[Thu Sep 17 15:42:29.890456 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/v1/.env"] [unique_id "aqxexcPsx0SVFjrd622y3AAAAAs"]
[Thu Sep 17 15:42:29.939933 2026] [security2:error] [pid 60716:tid 61009] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/application/.env"] [unique_id "aqxexcPsx0SVFjrd622y3QAAAHM"]
[Thu Sep 17 15:42:29.973494 2026] [security2:error] [pid 60716:tid 60904] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/admin-panel/.env"] [unique_id "aqxexcPsx0SVFjrd622y3gAAAAw"]
[Thu Sep 17 15:42:30.096189 2026] [security2:error] [pid 60716:tid 60980] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/laravel5/.env"] [unique_id "aqxexsPsx0SVFjrd622y4QAAAFY"]
[Thu Sep 17 15:42:30.096583 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/v2/.env"] [unique_id "aqxexsPsx0SVFjrd622y4gAAABo"]
[Thu Sep 17 15:42:30.134190 2026] [security2:error] [pid 60716:tid 60908] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/bootstrap/.env"] [unique_id "aqxexsPsx0SVFjrd622y5AAAABA"]
[Thu Sep 17 15:42:30.137313 2026] [security2:error] [pid 60716:tid 61008] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/control-panel/.env"] [unique_id "aqxexsPsx0SVFjrd622y5gAAAHI"]
[Thu Sep 17 15:42:30.263092 2026] [security2:error] [pid 60716:tid 60912] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/v3/.env"] [unique_id "aqxexsPsx0SVFjrd622y6gAAABQ"]
[Thu Sep 17 15:42:30.302139 2026] [security2:error] [pid 60716:tid 60924] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/user-panel/.env"] [unique_id "aqxexsPsx0SVFjrd622y7QAAAB8"]
[Thu Sep 17 15:42:30.322370 2026] [core:error] [pid 60716:tid 60894] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:30.322384 2026] [core:error] [pid 60716:tid 60894] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:30.327378 2026] [security2:error] [pid 60716:tid 60995] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/v1/.env"] [unique_id "aqxexsPsx0SVFjrd622y7wAAAGU"]
[Thu Sep 17 15:42:30.373798 2026] [security2:error] [pid 60716:tid 60934] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/database/.env"] [unique_id "aqxexsPsx0SVFjrd622y8AAAACg"]
[Thu Sep 17 15:42:30.419245 2026] [security2:error] [pid 60716:tid 60975] [client 143.105.152.240:63741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxexsPsx0SVFjrd622y8QAAAFE"]
[Thu Sep 17 15:42:30.422302 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/api/v1/.env"] [unique_id "aqxexsPsx0SVFjrd622y8gAAAAg"]
[Thu Sep 17 15:42:30.422865 2026] [security2:error] [pid 60716:tid 60975] [client 143.105.152.240:63741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxexsPsx0SVFjrd622y8QAAAFE"]
[Thu Sep 17 15:42:30.463722 2026] [security2:error] [pid 60716:tid 60936] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/node/.env"] [unique_id "aqxexsPsx0SVFjrd622y8wAAACo"]
[Thu Sep 17 15:42:30.554179 2026] [security2:error] [pid 60716:tid 60999] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/v2/.env"] [unique_id "aqxexsPsx0SVFjrd622y9AAAAGk"]
[Thu Sep 17 15:42:30.558779 2026] [security2:error] [pid 60716:tid 60939] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/storage/.env"] [unique_id "aqxexsPsx0SVFjrd622y9QAAAC0"]
[Thu Sep 17 15:42:30.584348 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/api/v2/.env"] [unique_id "aqxexsPsx0SVFjrd622y9wAAAHE"]
[Thu Sep 17 15:42:30.628716 2026] [security2:error] [pid 60716:tid 60896] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/express/.env"] [unique_id "aqxexsPsx0SVFjrd622y-QAAAAQ"]
[Thu Sep 17 15:42:30.764054 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/rest/.env"] [unique_id "aqxexsPsx0SVFjrd622y_AAAABw"]
[Thu Sep 17 15:42:30.766993 2026] [security2:error] [pid 60716:tid 60954] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/v3/.env"] [unique_id "aqxexsPsx0SVFjrd622y_gAAADw"]
[Thu Sep 17 15:42:30.791786 2026] [security2:error] [pid 60716:tid 60932] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/next/.env"] [unique_id "aqxexsPsx0SVFjrd622y_wAAACY"]
[Thu Sep 17 15:42:30.806863 2026] [security2:error] [pid 60716:tid 60973] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/var/www/.env"] [unique_id "aqxexsPsx0SVFjrd622zAQAAAE8"]
[Thu Sep 17 15:42:30.918540 2026] [security2:error] [pid 60716:tid 60938] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/graphql/.env"] [unique_id "aqxexsPsx0SVFjrd622zAwAAACw"]
[Thu Sep 17 15:42:30.952137 2026] [security2:error] [pid 60716:tid 60982] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/nuxt/.env"] [unique_id "aqxexsPsx0SVFjrd622zBAAAAFg"]
[Thu Sep 17 15:42:30.980473 2026] [security2:error] [pid 60716:tid 61010] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/api/v1/.env"] [unique_id "aqxexsPsx0SVFjrd622zBQAAAHQ"]
[Thu Sep 17 15:42:31.025487 2026] [core:error] [pid 60716:tid 60979] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:31.025500 2026] [core:error] [pid 60716:tid 60979] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:31.075976 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/gateway/.env"] [unique_id "aqxex8Psx0SVFjrd622zEAAAABs"]
[Thu Sep 17 15:42:31.115422 2026] [security2:error] [pid 60716:tid 60992] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/nest/.env"] [unique_id "aqxex8Psx0SVFjrd622zEgAAAGI"]
[Thu Sep 17 15:42:31.118306 2026] [security2:error] [pid 60716:tid 60977] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/var/www/html/.env"] [unique_id "aqxex8Psx0SVFjrd622zEwAAAFM"]
[Thu Sep 17 15:42:31.174854 2026] [core:error] [pid 60716:tid 60959] [client 129.121.128.70:57168] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Sep 17 15:42:31.190018 2026] [security2:error] [pid 60716:tid 60928] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/api/v2/.env"] [unique_id "aqxex8Psx0SVFjrd622zGAAAACM"]
[Thu Sep 17 15:42:31.241728 2026] [security2:error] [pid 60716:tid 60899] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/microservice/.env"] [unique_id "aqxex8Psx0SVFjrd622zGgAAAAc"]
[Thu Sep 17 15:42:31.276303 2026] [security2:error] [pid 60716:tid 60964] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/react/.env"] [unique_id "aqxex8Psx0SVFjrd622zHAAAAEY"]
[Thu Sep 17 15:42:31.319392 2026] [security2:error] [pid 60716:tid 60927] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/current/.env"] [unique_id "aqxex8Psx0SVFjrd622zHQAAACI"]
[Thu Sep 17 15:42:31.385815 2026] [security2:error] [pid 60716:tid 60910] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/rest/.env"] [unique_id "aqxex8Psx0SVFjrd622zHgAAABI"]
[Thu Sep 17 15:42:31.398508 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/service/.env"] [unique_id "aqxex8Psx0SVFjrd622zHwAAAEA"]
[Thu Sep 17 15:42:31.440044 2026] [security2:error] [pid 60716:tid 60990] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/vue/.env"] [unique_id "aqxex8Psx0SVFjrd622zIAAAAGA"]
[Thu Sep 17 15:42:31.543366 2026] [security2:error] [pid 60716:tid 60898] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/release/.env"] [unique_id "aqxex8Psx0SVFjrd622zJgAAAAY"]
[Thu Sep 17 15:42:31.552891 2026] [security2:error] [pid 60716:tid 60981] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/api/v3/.env"] [unique_id "aqxex8Psx0SVFjrd622zJwAAAFc"]
[Thu Sep 17 15:42:31.583543 2026] [security2:error] [pid 60716:tid 60988] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/graphql/.env"] [unique_id "aqxex8Psx0SVFjrd622zKAAAAF4"]
[Thu Sep 17 15:42:31.600241 2026] [security2:error] [pid 60716:tid 60926] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/angular/.env"] [unique_id "aqxex8Psx0SVFjrd622zKQAAACE"]
[Thu Sep 17 15:42:31.712278 2026] [security2:error] [pid 60716:tid 60931] [client 34.166.135.226:48318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "aqxex8Psx0SVFjrd622zLwAAACU"]
[Thu Sep 17 15:42:31.713416 2026] [security2:error] [pid 60716:tid 60929] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/api/dev/.env"] [unique_id "aqxex8Psx0SVFjrd622zMAAAACQ"]
[Thu Sep 17 15:42:31.763130 2026] [security2:error] [pid 60716:tid 60983] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/svelte/.env"] [unique_id "aqxex8Psx0SVFjrd622zMQAAAFk"]
[Thu Sep 17 15:42:31.787096 2026] [security2:error] [pid 60716:tid 60994] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/gateway/.env"] [unique_id "aqxex8Psx0SVFjrd622zMgAAAGQ"]
[Thu Sep 17 15:42:31.787097 2026] [security2:error] [pid 60716:tid 60963] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/releases/.env"] [unique_id "aqxex8Psx0SVFjrd622zMwAAAEU"]
[Thu Sep 17 15:42:31.804032 2026] [security2:error] [pid 60716:tid 60978] [client 79.116.89.151:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxex8Psx0SVFjrd622zNAAAAFQ"]
[Thu Sep 17 15:42:31.804399 2026] [security2:error] [pid 60716:tid 60978] [client 79.116.89.151:62702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxex8Psx0SVFjrd622zNAAAAFQ"]
[Thu Sep 17 15:42:31.867418 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/api/staging/.env"] [unique_id "aqxex8Psx0SVFjrd622zNQAAACA"]
[Thu Sep 17 15:42:31.924383 2026] [security2:error] [pid 60716:tid 60941] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/vite/.env"] [unique_id "aqxex8Psx0SVFjrd622zPgAAAC8"]
[Thu Sep 17 15:42:31.939667 2026] [security2:error] [pid 60716:tid 60903] [client 34.166.135.226:48318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "aqxex8Psx0SVFjrd622zPwAAAAs"]
[Thu Sep 17 15:42:31.996248 2026] [security2:error] [pid 60716:tid 60902] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/shared/.env"] [unique_id "aqxex8Psx0SVFjrd622zQgAAAAo"]
[Thu Sep 17 15:42:32.022687 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/vendor/.env"] [unique_id "aqxeyMPsx0SVFjrd622zQwAAAAw"]
[Thu Sep 17 15:42:32.032957 2026] [security2:error] [pid 60716:tid 60997] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/microservice/.env"] [unique_id "aqxeyMPsx0SVFjrd622zRQAAAGc"]
[Thu Sep 17 15:42:32.088359 2026] [security2:error] [pid 60716:tid 60908] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/backup/.env"] [unique_id "aqxeyMPsx0SVFjrd622zRgAAABA"]
[Thu Sep 17 15:42:32.176083 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/lib/.env"] [unique_id "aqxeyMPsx0SVFjrd622zTQAAADo"]
[Thu Sep 17 15:42:32.191868 2026] [core:error] [pid 60716:tid 60940] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:32.191897 2026] [core:error] [pid 60716:tid 60940] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:32.245294 2026] [security2:error] [pid 60716:tid 60900] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/service/.env"] [unique_id "aqxeyMPsx0SVFjrd622zTwAAAAg"]
[Thu Sep 17 15:42:32.246046 2026] [security2:error] [pid 60716:tid 60975] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/deploy/.env"] [unique_id "aqxeyMPsx0SVFjrd622zUAAAAFE"]
[Thu Sep 17 15:42:32.249104 2026] [security2:error] [pid 60716:tid 60936] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/backups/.env"] [unique_id "aqxeyMPsx0SVFjrd622zUQAAACo"]
[Thu Sep 17 15:42:32.334318 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/resources/.env"] [unique_id "aqxeyMPsx0SVFjrd622zUwAAAC0"]
[Thu Sep 17 15:42:32.417846 2026] [security2:error] [pid 60716:tid 61007] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/old/.env"] [unique_id "aqxeyMPsx0SVFjrd622zVAAAAHE"]
[Thu Sep 17 15:42:32.447386 2026] [security2:error] [pid 60716:tid 60917] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/api/v3/.env"] [unique_id "aqxeyMPsx0SVFjrd622zVQAAABk"]
[Thu Sep 17 15:42:32.496133 2026] [security2:error] [pid 60716:tid 61020] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/assets/.env"] [unique_id "aqxeyMPsx0SVFjrd622zVgAAAH4"]
[Thu Sep 17 15:42:32.524625 2026] [security2:error] [pid 60716:tid 60909] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/build/.env"] [unique_id "aqxeyMPsx0SVFjrd622zVwAAABE"]
[Thu Sep 17 15:42:32.578489 2026] [security2:error] [pid 60716:tid 60954] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/tmp/.env"] [unique_id "aqxeyMPsx0SVFjrd622zWQAAADw"]
[Thu Sep 17 15:42:32.650422 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/uploads/.env"] [unique_id "aqxeyMPsx0SVFjrd622zWwAAADI"]
[Thu Sep 17 15:42:32.708362 2026] [security2:error] [pid 60716:tid 60969] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/api/dev/.env"] [unique_id "aqxeyMPsx0SVFjrd622zYAAAAEs"]
[Thu Sep 17 15:42:32.741936 2026] [security2:error] [pid 60716:tid 60968] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/temp/.env"] [unique_id "aqxeyMPsx0SVFjrd622zYwAAAEo"]
[Thu Sep 17 15:42:32.753810 2026] [security2:error] [pid 60716:tid 60943] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/dist/.env"] [unique_id "aqxeyMPsx0SVFjrd622zZAAAADE"]
[Thu Sep 17 15:42:32.812366 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/internal/.env"] [unique_id "aqxeyMPsx0SVFjrd622zZQAAABY"]
[Thu Sep 17 15:42:32.899754 2026] [security2:error] [pid 60716:tid 60976] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/api/staging/.env"] [unique_id "aqxeyMPsx0SVFjrd622zbAAAAFI"]
[Thu Sep 17 15:42:32.902658 2026] [security2:error] [pid 60716:tid 60985] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/lab/.env"] [unique_id "aqxeyMPsx0SVFjrd622zbQAAAFs"]
[Thu Sep 17 15:42:32.912463 2026] [core:error] [pid 60716:tid 60949] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:32.912480 2026] [core:error] [pid 60716:tid 60949] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:32.938330 2026] [security2:error] [pid 60716:tid 60966] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/public_html/.env"] [unique_id "aqxeyMPsx0SVFjrd622zbwAAAEg"]
[Thu Sep 17 15:42:32.966841 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/tools/.env"] [unique_id "aqxeyMPsx0SVFjrd622zcQAAAGY"]
[Thu Sep 17 15:42:33.063391 2026] [security2:error] [pid 60716:tid 60950] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/cronlab/.env"] [unique_id "aqxeycPsx0SVFjrd622zdQAAADg"]
[Thu Sep 17 15:42:33.121078 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/scripts/.env"] [unique_id "aqxeycPsx0SVFjrd622zdgAAABI"]
[Thu Sep 17 15:42:33.132429 2026] [security2:error] [pid 60716:tid 60990] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/htdocs/.env"] [unique_id "aqxeycPsx0SVFjrd622zeAAAAGA"]
[Thu Sep 17 15:42:33.156058 2026] [security2:error] [pid 60716:tid 60981] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/vendor/.env"] [unique_id "aqxeycPsx0SVFjrd622zewAAAFc"]
[Thu Sep 17 15:42:33.224977 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/cron/.env"] [unique_id "aqxeycPsx0SVFjrd622zgAAAAGs"]
[Thu Sep 17 15:42:33.276007 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/bin/.env"] [unique_id "aqxeycPsx0SVFjrd622zgQAAACU"]
[Thu Sep 17 15:42:33.347411 2026] [security2:error] [pid 60716:tid 60929] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/www/.env"] [unique_id "aqxeycPsx0SVFjrd622zggAAACQ"]
[Thu Sep 17 15:42:33.353292 2026] [security2:error] [pid 60716:tid 60892] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/lib/.env"] [unique_id "aqxeycPsx0SVFjrd622zgwAAAAA"]
[Thu Sep 17 15:42:33.386814 2026] [security2:error] [pid 60716:tid 60945] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/en/.env"] [unique_id "aqxeycPsx0SVFjrd622zhAAAADM"]
[Thu Sep 17 15:42:33.431114 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/sbin/.env"] [unique_id "aqxeycPsx0SVFjrd622zhQAAAEM"]
[Thu Sep 17 15:42:33.585611 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/local/.env"] [unique_id "aqxeycPsx0SVFjrd622zhwAAAFk"]
[Thu Sep 17 15:42:33.609835 2026] [security2:error] [pid 60716:tid 60978] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/html/.env"] [unique_id "aqxeycPsx0SVFjrd622ziwAAAFQ"]
[Thu Sep 17 15:42:33.611874 2026] [security2:error] [pid 60716:tid 61004] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/administrator/.env"] [unique_id "aqxeycPsx0SVFjrd622zhgAAAG4"]
[Thu Sep 17 15:42:33.619656 2026] [core:error] [pid 60716:tid 61017] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:33.619679 2026] [core:error] [pid 60716:tid 61017] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:33.633245 2026] [security2:error] [pid 60716:tid 60941] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/resources/.env"] [unique_id "aqxeycPsx0SVFjrd622zjQAAAC8"]
[Thu Sep 17 15:42:33.742108 2026] [security2:error] [pid 60716:tid 60895] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/portal/.env"] [unique_id "aqxeycPsx0SVFjrd622zkQAAAAM"]
[Thu Sep 17 15:42:33.773064 2026] [security2:error] [pid 60716:tid 60918] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/psnlink/.env"] [unique_id "aqxeycPsx0SVFjrd622zkgAAABo"]
[Thu Sep 17 15:42:33.816859 2026] [security2:error] [pid 60716:tid 60948] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/assets/.env"] [unique_id "aqxeycPsx0SVFjrd622zkwAAADY"]
[Thu Sep 17 15:42:33.857822 2026] [security2:error] [pid 60716:tid 60972] [client 136.158.61.34:42792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeycPsx0SVFjrd622zlAAAAE4"]
[Thu Sep 17 15:42:33.857933 2026] [security2:error] [pid 60716:tid 60972] [client 136.158.61.34:42792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxeycPsx0SVFjrd622zlAAAAE4"]
[Thu Sep 17 15:42:33.871991 2026] [security2:error] [pid 60716:tid 60907] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/live/.env"] [unique_id "aqxeycPsx0SVFjrd622zlQAAAA8"]
[Thu Sep 17 15:42:33.898278 2026] [security2:error] [pid 60716:tid 60908] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/dashboard/.env"] [unique_id "aqxeycPsx0SVFjrd622zlgAAABA"]
[Thu Sep 17 15:42:33.934757 2026] [security2:error] [pid 60716:tid 61008] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/exapi/.env"] [unique_id "aqxeycPsx0SVFjrd622zlwAAAHI"]
[Thu Sep 17 15:42:34.054011 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/panel/.env"] [unique_id "aqxeysPsx0SVFjrd622zmAAAAEQ"]
[Thu Sep 17 15:42:34.074038 2026] [security2:error] [pid 60716:tid 60993] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/prod/.env"] [unique_id "aqxeysPsx0SVFjrd622zmQAAAGM"]
[Thu Sep 17 15:42:34.095935 2026] [security2:error] [pid 60716:tid 60986] [client 34.95.193.102:54196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/sitemaps/.env"] [unique_id "aqxeysPsx0SVFjrd622zmgAAAFw"]
[Thu Sep 17 15:42:34.100746 2026] [security2:error] [pid 60716:tid 60952] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/uploads/.env"] [unique_id "aqxeysPsx0SVFjrd622zmwAAADo"]
[Thu Sep 17 15:42:34.208889 2026] [security2:error] [pid 60716:tid 60995] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/crm/.env"] [unique_id "aqxeysPsx0SVFjrd622zoAAAAGU"]
[Thu Sep 17 15:42:34.275918 2026] [autoindex:error] [pid 60716:tid 60900] [client 185.228.133.176:0] AH01276: Cannot serve directory /home4/wisdomel/public_html/elementalessences/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://bulkbacklinkreport.website/dir/quality-link-building-63309
[Thu Sep 17 15:42:34.276777 2026] [core:error] [pid 60716:tid 60975] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:34.276795 2026] [core:error] [pid 60716:tid 60975] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:34.292116 2026] [security2:error] [pid 60716:tid 61007] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/dev/.env"] [unique_id "aqxeysPsx0SVFjrd622zpwAAAHE"]
[Thu Sep 17 15:42:34.337704 2026] [security2:error] [pid 60716:tid 60969] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/internal/.env"] [unique_id "aqxeysPsx0SVFjrd622zrAAAAEs"]
[Thu Sep 17 15:42:34.363891 2026] [security2:error] [pid 60716:tid 60938] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/erp/.env"] [unique_id "aqxeysPsx0SVFjrd622zrQAAACw"]
[Thu Sep 17 15:42:34.525977 2026] [security2:error] [pid 60716:tid 60973] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/shop/.env"] [unique_id "aqxeysPsx0SVFjrd622zrgAAAE8"]
[Thu Sep 17 15:42:34.547162 2026] [security2:error] [pid 60716:tid 60915] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/tools/.env"] [unique_id "aqxeysPsx0SVFjrd622zsAAAABc"]
[Thu Sep 17 15:42:34.554594 2026] [security2:error] [pid 60716:tid 60943] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/staging/.env"] [unique_id "aqxeysPsx0SVFjrd622zsQAAADE"]
[Thu Sep 17 15:42:34.680075 2026] [security2:error] [pid 60716:tid 60953] [client 34.154.248.240:33972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/store/.env"] [unique_id "aqxeysPsx0SVFjrd622ztgAAADs"]
[Thu Sep 17 15:42:34.717614 2026] [security2:error] [pid 60716:tid 60954] [client 103.61.184.148:50930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeysPsx0SVFjrd622ztwAAADw"]
[Thu Sep 17 15:42:34.717707 2026] [security2:error] [pid 60716:tid 60954] [client 103.61.184.148:50930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxeysPsx0SVFjrd622ztwAAADw"]
[Thu Sep 17 15:42:34.764871 2026] [security2:error] [pid 60716:tid 60899] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/scripts/.env"] [unique_id "aqxeysPsx0SVFjrd622zuwAAAAc"]
[Thu Sep 17 15:42:34.806917 2026] [security2:error] [pid 60716:tid 61021] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/opt/.env"] [unique_id "aqxeysPsx0SVFjrd622zvgAAAH8"]
[Thu Sep 17 15:42:34.812116 2026] [security2:error] [pid 60716:tid 60959] [client 46.147.34.132:59159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxeysPsx0SVFjrd622zuAAAQXU"]
[Thu Sep 17 15:42:34.821286 2026] [core:error] [pid 60716:tid 60966] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:34.821307 2026] [core:error] [pid 60716:tid 60966] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:34.856420 2026] [core:error] [pid 60716:tid 60950] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:34.856433 2026] [core:error] [pid 60716:tid 60950] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:34.987707 2026] [security2:error] [pid 60716:tid 60965] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/bin/.env"] [unique_id "aqxeysPsx0SVFjrd622zwQAAAEc"]
[Thu Sep 17 15:42:35.002274 2026] [security2:error] [pid 60716:tid 60982] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/laravel/.env"] [unique_id "aqxey8Psx0SVFjrd622zwgAAAFg"]
[Thu Sep 17 15:42:35.148072 2026] [security2:error] [pid 60716:tid 60981] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/saas/.env"] [unique_id "aqxey8Psx0SVFjrd622zxAAAAFc"]
[Thu Sep 17 15:42:35.186338 2026] [security2:error] [pid 60716:tid 60947] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/sbin/.env"] [unique_id "aqxey8Psx0SVFjrd622zxwAAADU"]
[Thu Sep 17 15:42:35.198472 2026] [security2:error] [pid 60716:tid 61001] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/symfony/.env"] [unique_id "aqxey8Psx0SVFjrd622zyAAAAGs"]
[Thu Sep 17 15:42:35.301426 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/client/.env"] [unique_id "aqxey8Psx0SVFjrd622zywAAAEM"]
[Thu Sep 17 15:42:35.343287 2026] [security2:error] [pid 60716:tid 60898] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/logs/.env"] [unique_id "aqxey8Psx0SVFjrd622zzAAAAAY"]
[Thu Sep 17 15:42:35.441789 2026] [security2:error] [pid 60716:tid 61014] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/wordpress/.env"] [unique_id "aqxey8Psx0SVFjrd622zzQAAAHg"]
[Thu Sep 17 15:42:35.454947 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/project/.env"] [unique_id "aqxey8Psx0SVFjrd622zzgAAAG0"]
[Thu Sep 17 15:42:35.455605 2026] [security2:error] [pid 60716:tid 60983] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/local/.env"] [unique_id "aqxey8Psx0SVFjrd622zzwAAAFk"]
[Thu Sep 17 15:42:35.503720 2026] [security2:error] [pid 60716:tid 60978] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/cache/.env"] [unique_id "aqxey8Psx0SVFjrd622z0AAAAFQ"]
[Thu Sep 17 15:42:35.533427 2026] [core:error] [pid 60716:tid 61017] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:35.533439 2026] [core:error] [pid 60716:tid 61017] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:35.613187 2026] [security2:error] [pid 60716:tid 61016] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/admin-panel/.env"] [unique_id "aqxey8Psx0SVFjrd622z1AAAAHo"]
[Thu Sep 17 15:42:35.666051 2026] [security2:error] [pid 60716:tid 60997] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mailer/.env"] [unique_id "aqxey8Psx0SVFjrd622z2wAAAGc"]
[Thu Sep 17 15:42:35.673334 2026] [security2:error] [pid 60716:tid 60994] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/wp/.env"] [unique_id "aqxey8Psx0SVFjrd622z3AAAAGQ"]
[Thu Sep 17 15:42:35.687884 2026] [security2:error] [pid 60716:tid 60895] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/portal/.env"] [unique_id "aqxey8Psx0SVFjrd622z3QAAAAM"]
[Thu Sep 17 15:42:35.777898 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/control-panel/.env"] [unique_id "aqxey8Psx0SVFjrd622z3gAAAAk"]
[Thu Sep 17 15:42:35.828201 2026] [security2:error] [pid 60716:tid 60907] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mail/.env"] [unique_id "aqxey8Psx0SVFjrd622z3wAAAA8"]
[Thu Sep 17 15:42:35.891331 2026] [security2:error] [pid 60716:tid 61008] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/dashboard/.env"] [unique_id "aqxey8Psx0SVFjrd622z4AAAAHI"]
[Thu Sep 17 15:42:35.930460 2026] [security2:error] [pid 60716:tid 61012] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/user-panel/.env"] [unique_id "aqxey8Psx0SVFjrd622z4QAAAHY"]
[Thu Sep 17 15:42:35.982248 2026] [security2:error] [pid 60716:tid 60923] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/cms/.env"] [unique_id "aqxey8Psx0SVFjrd622z4gAAAB4"]
[Thu Sep 17 15:42:35.990758 2026] [security2:error] [pid 60716:tid 60962] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/email/.env"] [unique_id "aqxey8Psx0SVFjrd622z4wAAAEQ"]
[Thu Sep 17 15:42:36.079277 2026] [security2:error] [pid 60716:tid 60986] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/panel/.env"] [unique_id "aqxezMPsx0SVFjrd622z5AAAAFw"]
[Thu Sep 17 15:42:36.086903 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/node/.env"] [unique_id "aqxezMPsx0SVFjrd622z5QAAADo"]
[Thu Sep 17 15:42:36.152359 2026] [security2:error] [pid 60716:tid 60940] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/smtp/.env"] [unique_id "aqxezMPsx0SVFjrd622z6QAAAC4"]
[Thu Sep 17 15:42:36.225651 2026] [security2:error] [pid 60716:tid 60993] [client 34.166.135.226:42646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "aqxezMPsx0SVFjrd622z6wAAAGM"]
[Thu Sep 17 15:42:36.231759 2026] [security2:error] [pid 60716:tid 60975] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/drupal/.env"] [unique_id "aqxezMPsx0SVFjrd622z7AAAAFE"]
[Thu Sep 17 15:42:36.238543 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/express/.env"] [unique_id "aqxezMPsx0SVFjrd622z7gAAACo"]
[Thu Sep 17 15:42:36.296606 2026] [security2:error] [pid 60716:tid 60960] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/crm/.env"] [unique_id "aqxezMPsx0SVFjrd622z7wAAAEI"]
[Thu Sep 17 15:42:36.314520 2026] [security2:error] [pid 60716:tid 61019] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mailing/.env"] [unique_id "aqxezMPsx0SVFjrd622z8AAAAH0"]
[Thu Sep 17 15:42:36.392369 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/next/.env"] [unique_id "aqxezMPsx0SVFjrd622z8QAAAHA"]
[Thu Sep 17 15:42:36.414635 2026] [security2:error] [pid 60716:tid 60916] [client 136.116.35.245:63584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "alanpeckolick.com"] [uri "/.env"] [unique_id "aqxezMPsx0SVFjrd622z8gAAABg"]
[Thu Sep 17 15:42:36.421339 2026] [security2:error] [pid 60716:tid 60934] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/joomla/.env"] [unique_id "aqxezMPsx0SVFjrd622z8wAAACg"]
[Thu Sep 17 15:42:36.454570 2026] [security2:error] [pid 60716:tid 61007] [client 34.166.135.226:42646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "aqxezMPsx0SVFjrd622z9AAAAHE"]
[Thu Sep 17 15:42:36.475265 2026] [security2:error] [pid 60716:tid 60911] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/notifications/.env"] [unique_id "aqxezMPsx0SVFjrd622z9gAAABM"]
[Thu Sep 17 15:42:36.542730 2026] [security2:error] [pid 60716:tid 61010] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/erp/.env"] [unique_id "aqxezMPsx0SVFjrd622z-QAAAHQ"]
[Thu Sep 17 15:42:36.552033 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/nuxt/.env"] [unique_id "aqxezMPsx0SVFjrd622z-gAAAEs"]
[Thu Sep 17 15:42:36.572546 2026] [security2:error] [pid 60716:tid 60944] [client 136.116.35.245:61550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "alanpeckolick.com"] [uri "/.env"] [unique_id "aqxezMPsx0SVFjrd622z_AAAADI"]
[Thu Sep 17 15:42:36.636307 2026] [security2:error] [pid 60716:tid 60968] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/notify/.env"] [unique_id "aqxezMPsx0SVFjrd622z_QAAAEo"]
[Thu Sep 17 15:42:36.683081 2026] [security2:error] [pid 60716:tid 60973] [client 34.166.135.226:42646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "aqxezMPsx0SVFjrd6220AgAAAE8"]
[Thu Sep 17 15:42:36.691750 2026] [security2:error] [pid 60716:tid 60915] [client 34.165.71.35:57898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/magento/.env"] [unique_id "aqxezMPsx0SVFjrd6220AwAAABc"]
[Thu Sep 17 15:42:36.707163 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/nest/.env"] [unique_id "aqxezMPsx0SVFjrd6220BAAAACc"]
[Thu Sep 17 15:42:36.790466 2026] [security2:error] [pid 60716:tid 61013] [client 194.165.114.214:51124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxezMPsx0SVFjrd6220AQAAdw8"]
[Thu Sep 17 15:42:36.798234 2026] [security2:error] [pid 60716:tid 60992] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/sender/.env"] [unique_id "aqxezMPsx0SVFjrd6220BQAAAGI"]
[Thu Sep 17 15:42:36.832188 2026] [security2:error] [pid 60716:tid 60953] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/shop/.env"] [unique_id "aqxezMPsx0SVFjrd6220BgAAADs"]
[Thu Sep 17 15:42:36.872127 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/react/.env"] [unique_id "aqxezMPsx0SVFjrd6220CQAAABs"]
[Thu Sep 17 15:42:36.911363 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.135.226:42646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "aqxezMPsx0SVFjrd6220CgAAAAc"]
[Thu Sep 17 15:42:36.958424 2026] [security2:error] [pid 60716:tid 60893] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/campaign/.env"] [unique_id "aqxezMPsx0SVFjrd6220DAAAAAE"]
[Thu Sep 17 15:42:37.027847 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/vue/.env"] [unique_id "aqxezcPsx0SVFjrd6220DwAAADg"]
[Thu Sep 17 15:42:37.030276 2026] [security2:error] [pid 60716:tid 60980] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/store/.env"] [unique_id "aqxezcPsx0SVFjrd6220EAAAAFY"]
[Thu Sep 17 15:42:37.094032 2026] [security2:error] [pid 60716:tid 60976] [client 148.227.75.216:33059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxezcPsx0SVFjrd6220EQAAAFI"]
[Thu Sep 17 15:42:37.094125 2026] [security2:error] [pid 60716:tid 60976] [client 148.227.75.216:33059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxezcPsx0SVFjrd6220EQAAAFI"]
[Thu Sep 17 15:42:37.118772 2026] [security2:error] [pid 60716:tid 60910] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/newsletter/.env"] [unique_id "aqxezcPsx0SVFjrd6220EgAAABI"]
[Thu Sep 17 15:42:37.140872 2026] [security2:error] [pid 60716:tid 60990] [client 34.166.135.226:42646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "aqxezcPsx0SVFjrd6220FAAAAGA"]
[Thu Sep 17 15:42:37.180048 2026] [security2:error] [pid 60716:tid 60988] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/angular/.env"] [unique_id "aqxezcPsx0SVFjrd6220FwAAAF4"]
[Thu Sep 17 15:42:37.228536 2026] [security2:error] [pid 60716:tid 60929] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/saas/.env"] [unique_id "aqxezcPsx0SVFjrd6220GgAAACQ"]
[Thu Sep 17 15:42:37.280123 2026] [security2:error] [pid 60716:tid 60913] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/ses/.env"] [unique_id "aqxezcPsx0SVFjrd6220GwAAABU"]
[Thu Sep 17 15:42:37.333985 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/svelte/.env"] [unique_id "aqxezcPsx0SVFjrd6220HAAAAAA"]
[Thu Sep 17 15:42:37.369900 2026] [security2:error] [pid 60716:tid 60945] [client 34.166.135.226:42646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "aqxezcPsx0SVFjrd6220HQAAADM"]
[Thu Sep 17 15:42:37.417825 2026] [security2:error] [pid 60716:tid 60898] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/client/.env"] [unique_id "aqxezcPsx0SVFjrd6220IQAAAAY"]
[Thu Sep 17 15:42:37.441079 2026] [security2:error] [pid 60716:tid 60935] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/sendgrid/.env"] [unique_id "aqxezcPsx0SVFjrd6220IgAAACk"]
[Thu Sep 17 15:42:37.464843 2026] [security2:error] [pid 60716:tid 61005] [client 169.58.197.253:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxezcPsx0SVFjrd6220IwAAAG8"], referer: binance.com
[Thu Sep 17 15:42:37.489744 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/vite/.env"] [unique_id "aqxezcPsx0SVFjrd6220JQAAAHg"]
[Thu Sep 17 15:42:37.519324 2026] [security2:error] [pid 60716:tid 60947] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/shopify/.env"] [unique_id "aqxezcPsx0SVFjrd6220JwAAADU"]
[Thu Sep 17 15:42:37.604107 2026] [security2:error] [pid 60716:tid 61016] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/sparkpost/.env"] [unique_id "aqxezcPsx0SVFjrd6220KwAAAHo"]
[Thu Sep 17 15:42:37.617450 2026] [core:error] [pid 60716:tid 60902] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:37.617467 2026] [core:error] [pid 60716:tid 60902] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:37.648841 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/backup/.env"] [unique_id "aqxezcPsx0SVFjrd6220MAAAAAs"]
[Thu Sep 17 15:42:37.653729 2026] [security2:error] [pid 60716:tid 60918] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/project/.env"] [unique_id "aqxezcPsx0SVFjrd6220MQAAABo"]
[Thu Sep 17 15:42:37.750019 2026] [security2:error] [pid 60716:tid 61008] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/prestashop/.env"] [unique_id "aqxezcPsx0SVFjrd6220OAAAAHI"]
[Thu Sep 17 15:42:37.766094 2026] [security2:error] [pid 60716:tid 60923] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/postmark/.env"] [unique_id "aqxezcPsx0SVFjrd6220OQAAAB4"]
[Thu Sep 17 15:42:37.804993 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/backups/.env"] [unique_id "aqxezcPsx0SVFjrd6220PAAAADo"]
[Thu Sep 17 15:42:37.851907 2026] [security2:error] [pid 60716:tid 60941] [client 14.96.156.146:65088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxezcPsx0SVFjrd6220PgAAAC8"]
[Thu Sep 17 15:42:37.852049 2026] [security2:error] [pid 60716:tid 60941] [client 14.96.156.146:65088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxezcPsx0SVFjrd6220PgAAAC8"]
[Thu Sep 17 15:42:37.927964 2026] [security2:error] [pid 60716:tid 61000] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mailgun/.env"] [unique_id "aqxezcPsx0SVFjrd6220PwAAAGo"]
[Thu Sep 17 15:42:37.931035 2026] [security2:error] [pid 60716:tid 60900] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/admin-panel/.env"] [unique_id "aqxezcPsx0SVFjrd6220QAAAAAg"]
[Thu Sep 17 15:42:37.960994 2026] [security2:error] [pid 60716:tid 60894] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/old/.env"] [unique_id "aqxezcPsx0SVFjrd6220QQAAAAI"]
[Thu Sep 17 15:42:37.989020 2026] [security2:error] [pid 60716:tid 60951] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/codeigniter/.env"] [unique_id "aqxezcPsx0SVFjrd6220RAAAADk"]
[Thu Sep 17 15:42:38.090063 2026] [security2:error] [pid 60716:tid 60939] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mandrill/.env"] [unique_id "aqxezsPsx0SVFjrd6220RwAAAC0"]
[Thu Sep 17 15:42:38.114323 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/tmp/.env"] [unique_id "aqxezsPsx0SVFjrd6220SAAAAHE"]
[Thu Sep 17 15:42:38.150916 2026] [security2:error] [pid 60716:tid 60967] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/control-panel/.env"] [unique_id "aqxezsPsx0SVFjrd6220SgAAAEk"]
[Thu Sep 17 15:42:38.215009 2026] [security2:error] [pid 60716:tid 60924] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/cakephp/.env"] [unique_id "aqxezsPsx0SVFjrd6220UAAAAB8"]
[Thu Sep 17 15:42:38.227597 2026] [security2:error] [pid 60716:tid 61019] [client 74.7.227.51:57012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxezsPsx0SVFjrd6220RgAAfSk"], referer: https://bigsisterteams.com/image-sitemap-1.xml
[Thu Sep 17 15:42:38.264351 2026] [security2:error] [pid 60716:tid 61010] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mailjet/.env"] [unique_id "aqxezsPsx0SVFjrd6220UgAAAHQ"]
[Thu Sep 17 15:42:38.268099 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/temp/.env"] [unique_id "aqxezsPsx0SVFjrd6220UwAAAEs"]
[Thu Sep 17 15:42:38.307024 2026] [security2:error] [pid 60716:tid 61006] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "aqxezsPsx0SVFjrd6220VAAAAHA"]
[Thu Sep 17 15:42:38.355873 2026] [security2:error] [pid 60716:tid 60915] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/user-panel/.env"] [unique_id "aqxezsPsx0SVFjrd6220VgAAABc"]
[Thu Sep 17 15:42:38.408266 2026] [security2:error] [pid 60716:tid 60932] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/zend/.env"] [unique_id "aqxezsPsx0SVFjrd6220VwAAACY"]
[Thu Sep 17 15:42:38.422784 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/lab/.env"] [unique_id "aqxezsPsx0SVFjrd6220WwAAADw"]
[Thu Sep 17 15:42:38.428227 2026] [security2:error] [pid 60716:tid 60919] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/brevo/.env"] [unique_id "aqxezsPsx0SVFjrd6220XgAAABs"]
[Thu Sep 17 15:42:38.534641 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "aqxezsPsx0SVFjrd6220YQAAAAc"]
[Thu Sep 17 15:42:38.575275 2026] [security2:error] [pid 60716:tid 61021] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/cronlab/.env"] [unique_id "aqxezsPsx0SVFjrd6220YgAAAH8"]
[Thu Sep 17 15:42:38.579490 2026] [security2:error] [pid 60716:tid 60893] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/node/.env"] [unique_id "aqxezsPsx0SVFjrd6220YwAAAAE"]
[Thu Sep 17 15:42:38.589298 2026] [security2:error] [pid 60716:tid 60996] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/yii/.env"] [unique_id "aqxezsPsx0SVFjrd6220ZAAAAGY"]
[Thu Sep 17 15:42:38.592055 2026] [security2:error] [pid 60716:tid 60942] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/transactional/.env"] [unique_id "aqxezsPsx0SVFjrd6220ZQAAADA"]
[Thu Sep 17 15:42:38.592441 2026] [fcgid:warn] [pid 60716:tid 60964] (70014)End of file found: [client 152.32.202.151:36970] mod_fcgid: can't get data from http client
[Thu Sep 17 15:42:38.737474 2026] [security2:error] [pid 60716:tid 60988] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/cron/.env"] [unique_id "aqxezsPsx0SVFjrd6220bgAAAF4"]
[Thu Sep 17 15:42:38.754093 2026] [security2:error] [pid 60716:tid 60926] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/bulk/.env"] [unique_id "aqxezsPsx0SVFjrd6220bwAAACE"]
[Thu Sep 17 15:42:38.770110 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "aqxezsPsx0SVFjrd6220cAAAAFc"]
[Thu Sep 17 15:42:38.814378 2026] [security2:error] [pid 60716:tid 61001] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/express/.env"] [unique_id "aqxezsPsx0SVFjrd6220cQAAAGs"]
[Thu Sep 17 15:42:38.828765 2026] [security2:error] [pid 60716:tid 60982] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/laravel5/.env"] [unique_id "aqxezsPsx0SVFjrd6220cgAAAFg"]
[Thu Sep 17 15:42:38.901705 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/en/.env"] [unique_id "aqxezsPsx0SVFjrd6220dAAAAEA"]
[Thu Sep 17 15:42:38.916602 2026] [security2:error] [pid 60716:tid 60913] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/aws/.env"] [unique_id "aqxezsPsx0SVFjrd6220dgAAABU"]
[Thu Sep 17 15:42:39.009948 2026] [security2:error] [pid 60716:tid 61005] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "aqxez8Psx0SVFjrd6220egAAAG8"]
[Thu Sep 17 15:42:39.069535 2026] [security2:error] [pid 60716:tid 61014] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/next/.env"] [unique_id "aqxez8Psx0SVFjrd6220fAAAAHg"]
[Thu Sep 17 15:42:39.085232 2026] [security2:error] [pid 60716:tid 61003] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/azure/.env"] [unique_id "aqxez8Psx0SVFjrd6220fQAAAG0"]
[Thu Sep 17 15:42:39.085473 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/administrator/.env"] [unique_id "aqxez8Psx0SVFjrd6220ewAAACI"]
[Thu Sep 17 15:42:39.087980 2026] [security2:error] [pid 60716:tid 60947] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/v1/.env"] [unique_id "aqxez8Psx0SVFjrd6220fgAAADU"]
[Thu Sep 17 15:42:39.228832 2026] [security2:error] [pid 60716:tid 60961] [client 74.7.227.51:57012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxez8Psx0SVFjrd6220fwAAQ2w"], referer: https://bigsisterteams.com/image-sitemap-1.xml
[Thu Sep 17 15:42:39.242434 2026] [security2:error] [pid 60716:tid 61015] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "aqxez8Psx0SVFjrd6220ggAAAHk"]
[Thu Sep 17 15:42:39.254232 2026] [security2:error] [pid 60716:tid 60994] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/gcp/.env"] [unique_id "aqxez8Psx0SVFjrd6220hAAAAGQ"]
[Thu Sep 17 15:42:39.257149 2026] [security2:error] [pid 60716:tid 60963] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/nuxt/.env"] [unique_id "aqxez8Psx0SVFjrd6220hQAAAEU"]
[Thu Sep 17 15:42:39.265435 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/psnlink/.env"] [unique_id "aqxez8Psx0SVFjrd6220hgAAAAs"]
[Thu Sep 17 15:42:39.286943 2026] [security2:error] [pid 60716:tid 60971] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/v2/.env"] [unique_id "aqxez8Psx0SVFjrd6220hwAAAE0"]
[Thu Sep 17 15:42:39.417071 2026] [security2:error] [pid 60716:tid 61012] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/cloud/.env"] [unique_id "aqxez8Psx0SVFjrd6220iwAAAHY"]
[Thu Sep 17 15:42:39.424714 2026] [security2:error] [pid 60716:tid 60923] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/exapi/.env"] [unique_id "aqxez8Psx0SVFjrd6220jAAAAB4"]
[Thu Sep 17 15:42:39.474218 2026] [security2:error] [pid 60716:tid 61000] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/v3/.env"] [unique_id "aqxez8Psx0SVFjrd6220jQAAAGo"]
[Thu Sep 17 15:42:39.476523 2026] [security2:error] [pid 60716:tid 60900] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/core/app/.env"] [unique_id "aqxez8Psx0SVFjrd6220jgAAAAg"]
[Thu Sep 17 15:42:39.495321 2026] [security2:error] [pid 60716:tid 60894] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/nest/.env"] [unique_id "aqxez8Psx0SVFjrd6220jwAAAAI"]
[Thu Sep 17 15:42:39.579015 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.248.240:40948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/sitemaps/.env"] [unique_id "aqxez8Psx0SVFjrd6220kQAAAGk"]
[Thu Sep 17 15:42:39.579156 2026] [security2:error] [pid 60716:tid 60912] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/infrastructure/.env"] [unique_id "aqxez8Psx0SVFjrd6220kgAAABQ"]
[Thu Sep 17 15:42:39.674398 2026] [security2:error] [pid 60716:tid 60908] [client 52.167.144.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "compassalpha.com"] [uri "/index.php"] [unique_id "aqxezcPsx0SVFjrd6220NwAAABA"]
[Thu Sep 17 15:42:39.697733 2026] [security2:error] [pid 60716:tid 60974] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/react/.env"] [unique_id "aqxez8Psx0SVFjrd6220mgAAAFA"]
[Thu Sep 17 15:42:39.699487 2026] [security2:error] [pid 60716:tid 60955] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/api/v1/.env"] [unique_id "aqxez8Psx0SVFjrd6220mwAAAD0"]
[Thu Sep 17 15:42:39.711944 2026] [security2:error] [pid 60716:tid 60924] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "aqxez8Psx0SVFjrd6220nQAAAB8"]
[Thu Sep 17 15:42:39.713749 2026] [security2:error] [pid 60716:tid 60907] [client 177.44.133.72:60350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxez8Psx0SVFjrd6220ngAAAA8"]
[Thu Sep 17 15:42:39.714261 2026] [security2:error] [pid 60716:tid 60907] [client 177.44.133.72:60350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxez8Psx0SVFjrd6220ngAAAA8"]
[Thu Sep 17 15:42:39.740829 2026] [security2:error] [pid 60716:tid 60906] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/docker/.env"] [unique_id "aqxez8Psx0SVFjrd6220owAAAA4"]
[Thu Sep 17 15:42:39.903159 2026] [security2:error] [pid 60716:tid 61006] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/k8s/.env"] [unique_id "aqxez8Psx0SVFjrd6220pQAAAHA"]
[Thu Sep 17 15:42:39.910545 2026] [security2:error] [pid 60716:tid 60915] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/api/v2/.env"] [unique_id "aqxez8Psx0SVFjrd6220pgAAABc"]
[Thu Sep 17 15:42:39.942986 2026] [security2:error] [pid 60716:tid 60954] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/private/.env"] [unique_id "aqxez8Psx0SVFjrd6220pwAAADw"]
[Thu Sep 17 15:42:39.951334 2026] [security2:error] [pid 60716:tid 60919] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/vue/.env"] [unique_id "aqxez8Psx0SVFjrd6220qAAAABs"]
[Thu Sep 17 15:42:40.065460 2026] [security2:error] [pid 60716:tid 60985] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/kubernetes/.env"] [unique_id "aqxe0MPsx0SVFjrd6220qwAAAFs"]
[Thu Sep 17 15:42:40.133071 2026] [security2:error] [pid 60716:tid 60938] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/rest/.env"] [unique_id "aqxe0MPsx0SVFjrd6220rgAAACw"]
[Thu Sep 17 15:42:40.155271 2026] [security2:error] [pid 60716:tid 60899] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/angular/.env"] [unique_id "aqxe0MPsx0SVFjrd6220rwAAAAc"]
[Thu Sep 17 15:42:40.174558 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "aqxe0MPsx0SVFjrd6220sQAAAB0"]
[Thu Sep 17 15:42:40.230953 2026] [security2:error] [pid 60716:tid 60964] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/terraform/.env"] [unique_id "aqxe0MPsx0SVFjrd6220twAAAEY"]
[Thu Sep 17 15:42:40.363724 2026] [security2:error] [pid 60716:tid 60926] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/graphql/.env"] [unique_id "aqxe0MPsx0SVFjrd6220wAAAACE"]
[Thu Sep 17 15:42:40.375236 2026] [security2:error] [pid 60716:tid 60965] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/svelte/.env"] [unique_id "aqxe0MPsx0SVFjrd6220wgAAAEc"]
[Thu Sep 17 15:42:40.393638 2026] [security2:error] [pid 60716:tid 60931] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/ansible/.env"] [unique_id "aqxe0MPsx0SVFjrd6220wwAAACU"]
[Thu Sep 17 15:42:40.401488 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/bootstrap/.env"] [unique_id "aqxe0MPsx0SVFjrd6220xQAAAAA"]
[Thu Sep 17 15:42:40.512609 2026] [security2:error] [pid 60716:tid 60932] [client 43.157.180.116:45304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.180.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alanpeckolick.com"] [uri "/xmlrpc.php"] [unique_id "aqxe0MPsx0SVFjrd6220xwAAACY"]
[Thu Sep 17 15:42:40.556545 2026] [security2:error] [pid 60716:tid 60925] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/.git/.env"] [unique_id "aqxe0MPsx0SVFjrd6220yQAAACA"]
[Thu Sep 17 15:42:40.617302 2026] [security2:error] [pid 60716:tid 60997] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/vite/.env"] [unique_id "aqxe0MPsx0SVFjrd6220ywAAAGc"]
[Thu Sep 17 15:42:40.628305 2026] [security2:error] [pid 60716:tid 60994] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "aqxe0MPsx0SVFjrd6220zAAAAGQ"]
[Thu Sep 17 15:42:40.657533 2026] [security2:error] [pid 60716:tid 60903] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/gateway/.env"] [unique_id "aqxe0MPsx0SVFjrd6220zQAAAAs"]
[Thu Sep 17 15:42:40.717602 2026] [security2:error] [pid 60716:tid 61008] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/ci/.env"] [unique_id "aqxe0MPsx0SVFjrd62200gAAAHI"]
[Thu Sep 17 15:42:40.793106 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/logs/.env"] [unique_id "aqxe0MPsx0SVFjrd62201QAAAEU"]
[Thu Sep 17 15:42:40.835690 2026] [security2:error] [pid 60716:tid 60907] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/backup/.env"] [unique_id "aqxe0MPsx0SVFjrd62201wAAAA8"]
[Thu Sep 17 15:42:40.855717 2026] [security2:error] [pid 60716:tid 60909] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "aqxe0MPsx0SVFjrd62202AAAABE"]
[Thu Sep 17 15:42:40.875922 2026] [security2:error] [pid 60716:tid 60969] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/microservice/.env"] [unique_id "aqxe0MPsx0SVFjrd62202QAAAEs"]
[Thu Sep 17 15:42:40.885857 2026] [security2:error] [pid 60716:tid 60906] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/cd/.env"] [unique_id "aqxe0MPsx0SVFjrd62202wAAAA4"]
[Thu Sep 17 15:42:40.896346 2026] [security2:error] [pid 60716:tid 60911] [client 169.58.197.251:58232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxe0MPsx0SVFjrd62203QAAABM"], referer: binance.com
[Thu Sep 17 15:42:40.955236 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/cache/.env"] [unique_id "aqxe0MPsx0SVFjrd62207AAAADQ"]
[Thu Sep 17 15:42:41.008203 2026] [security2:error] [pid 60716:tid 60896] [client 143.105.152.240:43517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe0MPsx0SVFjrd62209AAAAAQ"]
[Thu Sep 17 15:42:41.008318 2026] [security2:error] [pid 60716:tid 60896] [client 143.105.152.240:43517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe0MPsx0SVFjrd62209AAAAAQ"]
[Thu Sep 17 15:42:41.025362 2026] [security2:error] [pid 60716:tid 61010] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/backups/.env"] [unique_id "aqxe0cPsx0SVFjrd62209QAAAHQ"]
[Thu Sep 17 15:42:41.049794 2026] [security2:error] [pid 60716:tid 60968] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/jenkins/.env"] [unique_id "aqxe0cPsx0SVFjrd62209wAAAEo"]
[Thu Sep 17 15:42:41.082281 2026] [security2:error] [pid 60716:tid 60915] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "aqxe0cPsx0SVFjrd6220-gAAABc"]
[Thu Sep 17 15:42:41.102686 2026] [security2:error] [pid 60716:tid 60985] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/service/.env"] [unique_id "aqxe0cPsx0SVFjrd6220_QAAAFs"]
[Thu Sep 17 15:42:41.108842 2026] [security2:error] [pid 60716:tid 60949] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mailer/.env"] [unique_id "aqxe0cPsx0SVFjrd6220_gAAADc"]
[Thu Sep 17 15:42:41.212562 2026] [security2:error] [pid 60716:tid 60979] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/gitlab/.env"] [unique_id "aqxe0cPsx0SVFjrd6221AgAAAFU"]
[Thu Sep 17 15:42:41.262785 2026] [security2:error] [pid 60716:tid 60981] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mail/.env"] [unique_id "aqxe0cPsx0SVFjrd6221BQAAAFc"]
[Thu Sep 17 15:42:41.262832 2026] [security2:error] [pid 60716:tid 60926] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/old/.env"] [unique_id "aqxe0cPsx0SVFjrd6221BAAAACE"]
[Thu Sep 17 15:42:41.311862 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/var/www/html/.env"] [unique_id "aqxe0cPsx0SVFjrd6221BgAAACs"]
[Thu Sep 17 15:42:41.365958 2026] [security2:error] [pid 60716:tid 60962] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/api/v3/.env"] [unique_id "aqxe0cPsx0SVFjrd6221CQAAAEQ"]
[Thu Sep 17 15:42:41.373144 2026] [security2:error] [pid 60716:tid 60945] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/github/.env"] [unique_id "aqxe0cPsx0SVFjrd6221CwAAADM"]
[Thu Sep 17 15:42:41.417468 2026] [security2:error] [pid 60716:tid 60932] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/email/.env"] [unique_id "aqxe0cPsx0SVFjrd6221DAAAACY"]
[Thu Sep 17 15:42:41.461655 2026] [security2:error] [pid 60716:tid 60925] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/tmp/.env"] [unique_id "aqxe0cPsx0SVFjrd6221DgAAACA"]
[Thu Sep 17 15:42:41.536255 2026] [security2:error] [pid 60716:tid 60997] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/actions/.env"] [unique_id "aqxe0cPsx0SVFjrd6221DwAAAGc"]
[Thu Sep 17 15:42:41.541127 2026] [security2:error] [pid 60716:tid 60994] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/current/.env"] [unique_id "aqxe0cPsx0SVFjrd6221EAAAAGQ"]
[Thu Sep 17 15:42:41.572466 2026] [security2:error] [pid 60716:tid 60976] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/smtp/.env"] [unique_id "aqxe0cPsx0SVFjrd6221EQAAAFI"]
[Thu Sep 17 15:42:41.614332 2026] [security2:error] [pid 60716:tid 60902] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/api/dev/.env"] [unique_id "aqxe0cPsx0SVFjrd6221EgAAAAo"]
[Thu Sep 17 15:42:41.678674 2026] [security2:error] [pid 60716:tid 60909] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/temp/.env"] [unique_id "aqxe0cPsx0SVFjrd6221GAAAABE"]
[Thu Sep 17 15:42:41.702302 2026] [security2:error] [pid 60716:tid 60906] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/circleci/.env"] [unique_id "aqxe0cPsx0SVFjrd6221GQAAAA4"]
[Thu Sep 17 15:42:41.732875 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mailing/.env"] [unique_id "aqxe0cPsx0SVFjrd6221GwAAABM"]
[Thu Sep 17 15:42:41.770187 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/release/.env"] [unique_id "aqxe0cPsx0SVFjrd6221HQAAAH0"]
[Thu Sep 17 15:42:41.828466 2026] [security2:error] [pid 60716:tid 60967] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/api/staging/.env"] [unique_id "aqxe0cPsx0SVFjrd6221IAAAAEk"]
[Thu Sep 17 15:42:41.872459 2026] [security2:error] [pid 60716:tid 60897] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/travis/.env"] [unique_id "aqxe0cPsx0SVFjrd6221IwAAAAU"]
[Thu Sep 17 15:42:41.898060 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/notifications/.env"] [unique_id "aqxe0cPsx0SVFjrd6221JAAAABg"]
[Thu Sep 17 15:42:41.914043 2026] [security2:error] [pid 60716:tid 60915] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/lab/.env"] [unique_id "aqxe0cPsx0SVFjrd6221JQAAABc"]
[Thu Sep 17 15:42:41.969976 2026] [security2:error] [pid 60716:tid 60825] [remote 216.73.217.142:55481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxe0cPsx0SVFjrd6221KAAAVT8"]
[Thu Sep 17 15:42:41.997748 2026] [security2:error] [pid 60716:tid 60959] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/releases/.env"] [unique_id "aqxe0cPsx0SVFjrd6221KgAAAEE"]
[Thu Sep 17 15:42:42.033470 2026] [security2:error] [pid 60716:tid 60905] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/buildkite/.env"] [unique_id "aqxe0sPsx0SVFjrd6221LAAAAA0"]
[Thu Sep 17 15:42:42.047893 2026] [security2:error] [pid 60716:tid 60981] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/vendor/.env"] [unique_id "aqxe0sPsx0SVFjrd6221LgAAAFc"]
[Thu Sep 17 15:42:42.052668 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/notify/.env"] [unique_id "aqxe0sPsx0SVFjrd6221LwAAACE"]
[Thu Sep 17 15:42:42.138572 2026] [security2:error] [pid 60716:tid 60933] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/cronlab/.env"] [unique_id "aqxe0sPsx0SVFjrd6221PQAAACc"]
[Thu Sep 17 15:42:42.197804 2026] [security2:error] [pid 60716:tid 60953] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mysql/.env"] [unique_id "aqxe0sPsx0SVFjrd6221RAAAADs"]
[Thu Sep 17 15:42:42.208097 2026] [security2:error] [pid 60716:tid 60893] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/sender/.env"] [unique_id "aqxe0sPsx0SVFjrd6221RQAAAAE"]
[Thu Sep 17 15:42:42.223867 2026] [security2:error] [pid 60716:tid 60986] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/shared/.env"] [unique_id "aqxe0sPsx0SVFjrd6221RwAAAFw"]
[Thu Sep 17 15:42:42.231122 2026] [security2:error] [pid 60716:tid 60977] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/lib/.env"] [unique_id "aqxe0sPsx0SVFjrd6221SAAAAFM"]
[Thu Sep 17 15:42:42.334542 2026] [security2:error] [pid 60716:tid 60935] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/cron/.env"] [unique_id "aqxe0sPsx0SVFjrd6221SwAAACk"]
[Thu Sep 17 15:42:42.358251 2026] [security2:error] [pid 60716:tid 60929] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/postgres/.env"] [unique_id "aqxe0sPsx0SVFjrd6221TAAAACQ"]
[Thu Sep 17 15:42:42.368897 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/campaign/.env"] [unique_id "aqxe0sPsx0SVFjrd6221TQAAAHg"]
[Thu Sep 17 15:42:42.410927 2026] [security2:error] [pid 60716:tid 60940] [client 79.116.89.151:63329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe0sPsx0SVFjrd6221TgAAAC4"]
[Thu Sep 17 15:42:42.411023 2026] [security2:error] [pid 60716:tid 60940] [client 79.116.89.151:63329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe0sPsx0SVFjrd6221TgAAAC4"]
[Thu Sep 17 15:42:42.449518 2026] [security2:error] [pid 60716:tid 60961] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/deploy/.env"] [unique_id "aqxe0sPsx0SVFjrd6221UAAAAEM"]
[Thu Sep 17 15:42:42.504487 2026] [security2:error] [pid 60716:tid 60994] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/resources/.env"] [unique_id "aqxe0sPsx0SVFjrd6221UQAAAGQ"]
[Thu Sep 17 15:42:42.521202 2026] [security2:error] [pid 60716:tid 60976] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/mongodb/.env"] [unique_id "aqxe0sPsx0SVFjrd6221UgAAAFI"]
[Thu Sep 17 15:42:42.523192 2026] [security2:error] [pid 60716:tid 61012] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/newsletter/.env"] [unique_id "aqxe0sPsx0SVFjrd6221UwAAAHY"]
[Thu Sep 17 15:42:42.525474 2026] [security2:error] [pid 60716:tid 60928] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/en/.env"] [unique_id "aqxe0sPsx0SVFjrd6221VAAAACM"]
[Thu Sep 17 15:42:42.548789 2026] [security2:error] [pid 60716:tid 60970] [client 144.76.22.52:47530] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxe0cPsx0SVFjrd6221JgAAAEw"]
[Thu Sep 17 15:42:42.677349 2026] [security2:error] [pid 60716:tid 60963] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/build/.env"] [unique_id "aqxe0sPsx0SVFjrd6221WwAAAEU"]
[Thu Sep 17 15:42:42.677357 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/ses/.env"] [unique_id "aqxe0sPsx0SVFjrd6221XAAAABM"]
[Thu Sep 17 15:42:42.682464 2026] [security2:error] [pid 60716:tid 61008] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/redis/.env"] [unique_id "aqxe0sPsx0SVFjrd6221XQAAAHI"]
[Thu Sep 17 15:42:42.814322 2026] [security2:error] [pid 60716:tid 60907] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/assets/.env"] [unique_id "aqxe0sPsx0SVFjrd6221YwAAAA8"]
[Thu Sep 17 15:42:42.831325 2026] [security2:error] [pid 60716:tid 60897] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/sendgrid/.env"] [unique_id "aqxe0sPsx0SVFjrd6221ZAAAAAU"]
[Thu Sep 17 15:42:42.839561 2026] [security2:error] [pid 60716:tid 60934] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/administrator/.env"] [unique_id "aqxe0sPsx0SVFjrd6221YgAAACg"]
[Thu Sep 17 15:42:42.853188 2026] [security2:error] [pid 60716:tid 60968] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/elasticsearch/.env"] [unique_id "aqxe0sPsx0SVFjrd6221ZgAAAEo"]
[Thu Sep 17 15:42:42.866609 2026] [security2:error] [pid 60716:tid 60923] [client 20.172.77.255:21762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxe0sPsx0SVFjrd6221WgAAAGg"]
[Thu Sep 17 15:42:42.904027 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/dist/.env"] [unique_id "aqxe0sPsx0SVFjrd6221aAAAAHM"]
[Thu Sep 17 15:42:42.949893 2026] [core:error] [pid 60716:tid 60990] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:42.949910 2026] [core:error] [pid 60716:tid 60990] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:42.986497 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/sparkpost/.env"] [unique_id "aqxe0sPsx0SVFjrd6221bgAAACE"]
[Thu Sep 17 15:42:43.014477 2026] [security2:error] [pid 60716:tid 61011] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/rabbitmq/.env"] [unique_id "aqxe08Psx0SVFjrd6221bwAAAHU"]
[Thu Sep 17 15:42:43.017483 2026] [security2:error] [pid 60716:tid 60982] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/uploads/.env"] [unique_id "aqxe08Psx0SVFjrd6221cAAAAFg"]
[Thu Sep 17 15:42:43.071860 2026] [security2:error] [pid 60716:tid 60944] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/psnlink/.env"] [unique_id "aqxe08Psx0SVFjrd6221cQAAADI"]
[Thu Sep 17 15:42:43.108229 2026] [security2:error] [pid 60716:tid 60954] [client 216.73.216.134:2663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.caitlinannemack.com"] [uri "/design/search.php/sitemap759.xml"] [unique_id "aqxe08Psx0SVFjrd6221cwAAADw"]
[Thu Sep 17 15:42:43.132010 2026] [security2:error] [pid 60716:tid 60900] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/public_html/.env"] [unique_id "aqxe08Psx0SVFjrd6221dQAAAAg"]
[Thu Sep 17 15:42:43.140814 2026] [security2:error] [pid 60716:tid 60989] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/postmark/.env"] [unique_id "aqxe08Psx0SVFjrd6221dgAAAF8"]
[Thu Sep 17 15:42:43.179569 2026] [security2:error] [pid 60716:tid 60898] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/kafka/.env"] [unique_id "aqxe08Psx0SVFjrd6221eQAAAAY"]
[Thu Sep 17 15:42:43.290231 2026] [security2:error] [pid 60716:tid 61005] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/exapi/.env"] [unique_id "aqxe08Psx0SVFjrd6221fAAAAG8"]
[Thu Sep 17 15:42:43.297612 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mailgun/.env"] [unique_id "aqxe08Psx0SVFjrd6221fQAAAAA"]
[Thu Sep 17 15:42:43.299808 2026] [security2:error] [pid 60716:tid 60904] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/internal/.env"] [unique_id "aqxe08Psx0SVFjrd6221fgAAAAw"]
[Thu Sep 17 15:42:43.338186 2026] [security2:error] [pid 60716:tid 60966] [client 169.58.197.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "p3collaborative.com"] [uri "/index.php"] [unique_id "aqxe0MPsx0SVFjrd6220uAAAAEg"], referer: binance.com
[Thu Sep 17 15:42:43.342576 2026] [security2:error] [pid 60716:tid 60932] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/queue/.env"] [unique_id "aqxe08Psx0SVFjrd6221hQAAACY"]
[Thu Sep 17 15:42:43.360013 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/htdocs/.env"] [unique_id "aqxe08Psx0SVFjrd6221iQAAACA"]
[Thu Sep 17 15:42:43.451971 2026] [security2:error] [pid 60716:tid 60997] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mandrill/.env"] [unique_id "aqxe08Psx0SVFjrd6221kgAAAGc"]
[Thu Sep 17 15:42:43.503250 2026] [security2:error] [pid 60716:tid 60976] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/worker/.env"] [unique_id "aqxe08Psx0SVFjrd6221lQAAAFI"]
[Thu Sep 17 15:42:43.543397 2026] [security2:error] [pid 60716:tid 60983] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/sitemaps/.env"] [unique_id "aqxe08Psx0SVFjrd6221lgAAAFk"]
[Thu Sep 17 15:42:43.563270 2026] [security2:error] [pid 60716:tid 60906] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/tools/.env"] [unique_id "aqxe08Psx0SVFjrd6221mQAAAA4"]
[Thu Sep 17 15:42:43.589114 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "aqxe08Psx0SVFjrd6221mwAAAH0"]
[Thu Sep 17 15:42:43.606182 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mailjet/.env"] [unique_id "aqxe08Psx0SVFjrd6221nAAAABE"]
[Thu Sep 17 15:42:43.635878 2026] [core:error] [pid 60716:tid 60914] [client 34.166.220.229:39960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:43.635898 2026] [core:error] [pid 60716:tid 60914] [client 34.166.220.229:39960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:43.668374 2026] [security2:error] [pid 60716:tid 60897] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/job/.env"] [unique_id "aqxe08Psx0SVFjrd6221oQAAAAU"]
[Thu Sep 17 15:42:43.753313 2026] [security2:error] [pid 60716:tid 60974] [client 74.7.227.51:57012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxe08Psx0SVFjrd6221nQAAUEg"], referer: https://bigsisterteams.com/image-sitemap-1.xml
[Thu Sep 17 15:42:43.766682 2026] [security2:error] [pid 60716:tid 61009] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/brevo/.env"] [unique_id "aqxe08Psx0SVFjrd6221pQAAAHM"]
[Thu Sep 17 15:42:43.770041 2026] [security2:error] [pid 60716:tid 60992] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/scripts/.env"] [unique_id "aqxe08Psx0SVFjrd6221pgAAAGI"]
[Thu Sep 17 15:42:43.815412 2026] [security2:error] [pid 60716:tid 60946] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "aqxe08Psx0SVFjrd6221qgAAADQ"]
[Thu Sep 17 15:42:43.829645 2026] [security2:error] [pid 60716:tid 60990] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/test/.env"] [unique_id "aqxe08Psx0SVFjrd6221qwAAAGA"]
[Thu Sep 17 15:42:43.926793 2026] [security2:error] [pid 60716:tid 61002] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/transactional/.env"] [unique_id "aqxe08Psx0SVFjrd6221rAAAAGw"]
[Thu Sep 17 15:42:43.990502 2026] [security2:error] [pid 60716:tid 60895] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/qa/.env"] [unique_id "aqxe08Psx0SVFjrd6221sAAAAAM"]
[Thu Sep 17 15:42:44.008036 2026] [security2:error] [pid 60716:tid 61004] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/bin/.env"] [unique_id "aqxe1MPsx0SVFjrd6221sgAAAG4"]
[Thu Sep 17 15:42:44.042216 2026] [security2:error] [pid 60716:tid 60944] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/live/.env"] [unique_id "aqxe1MPsx0SVFjrd6221swAAADI"]
[Thu Sep 17 15:42:44.082880 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/bulk/.env"] [unique_id "aqxe1MPsx0SVFjrd6221tQAAAAQ"]
[Thu Sep 17 15:42:44.129752 2026] [security2:error] [pid 60716:tid 60920] [client 34.165.71.35:57138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapamerica.gcpmanagement.com"] [uri "/logs/.env"] [unique_id "aqxe1MPsx0SVFjrd6221twAAABw"]
[Thu Sep 17 15:42:44.151895 2026] [security2:error] [pid 60716:tid 60950] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/preview/.env"] [unique_id "aqxe1MPsx0SVFjrd6221ugAAADg"]
[Thu Sep 17 15:42:44.223672 2026] [security2:error] [pid 60716:tid 60929] [client 34.165.71.35:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "commcapusa.gcpmanagement.com"] [uri "/sbin/.env"] [unique_id "aqxe1MPsx0SVFjrd6221wwAAACQ"]
[Thu Sep 17 15:42:44.237534 2026] [security2:error] [pid 60716:tid 60956] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/aws/.env"] [unique_id "aqxe1MPsx0SVFjrd6221xwAAAD4"]
[Thu Sep 17 15:42:44.268850 2026] [security2:error] [pid 60716:tid 60953] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "aqxe1MPsx0SVFjrd6221yAAAADs"]
[Thu Sep 17 15:42:44.314330 2026] [security2:error] [pid 60716:tid 60941] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/beta/.env"] [unique_id "aqxe1MPsx0SVFjrd6221ygAAAC8"]
[Thu Sep 17 15:42:44.316039 2026] [core:error] [pid 60716:tid 61013] [client 34.166.220.229:39972] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:44.316055 2026] [core:error] [pid 60716:tid 61013] [client 34.166.220.229:39972] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:44.392493 2026] [security2:error] [pid 60716:tid 60986] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/azure/.env"] [unique_id "aqxe1MPsx0SVFjrd6221zwAAAFw"]
[Thu Sep 17 15:42:44.475891 2026] [security2:error] [pid 60716:tid 60937] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/uat/.env"] [unique_id "aqxe1MPsx0SVFjrd62210QAAACs"]
[Thu Sep 17 15:42:44.496023 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "aqxe1MPsx0SVFjrd62210wAAAF0"]
[Thu Sep 17 15:42:44.549158 2026] [security2:error] [pid 60716:tid 61016] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/gcp/.env"] [unique_id "aqxe1MPsx0SVFjrd62211gAAAHo"]
[Thu Sep 17 15:42:44.637865 2026] [security2:error] [pid 60716:tid 61012] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/stage/.env"] [unique_id "aqxe1MPsx0SVFjrd62212AAAAHY"]
[Thu Sep 17 15:42:44.709351 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/cloud/.env"] [unique_id "aqxe1MPsx0SVFjrd62213AAAAAk"]
[Thu Sep 17 15:42:44.724204 2026] [security2:error] [pid 60716:tid 60908] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "aqxe1MPsx0SVFjrd62213QAAABA"]
[Thu Sep 17 15:42:44.799447 2026] [security2:error] [pid 60716:tid 60948] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/development/.env"] [unique_id "aqxe1MPsx0SVFjrd62213gAAADY"]
[Thu Sep 17 15:42:44.864178 2026] [security2:error] [pid 60716:tid 60978] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/infrastructure/.env"] [unique_id "aqxe1MPsx0SVFjrd62213wAAAFQ"]
[Thu Sep 17 15:42:44.951920 2026] [security2:error] [pid 60716:tid 60909] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/opt/.env"] [unique_id "aqxe1MPsx0SVFjrd62214QAAABE"]
[Thu Sep 17 15:42:44.964282 2026] [security2:error] [pid 60716:tid 60995] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/production/.env"] [unique_id "aqxe1MPsx0SVFjrd62214gAAAGU"]
[Thu Sep 17 15:42:44.997147 2026] [core:error] [pid 60716:tid 60906] [client 34.166.220.229:39986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:44.997167 2026] [core:error] [pid 60716:tid 60906] [client 34.166.220.229:39986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:45.019752 2026] [security2:error] [pid 60716:tid 60967] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/docker/.env"] [unique_id "aqxe1cPsx0SVFjrd62216AAAAEk"]
[Thu Sep 17 15:42:45.126419 2026] [security2:error] [pid 60716:tid 60968] [client 34.95.193.102:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.embracingthehour.com"] [uri "/___proxy_subdomain_webmail/config/app/.env"] [unique_id "aqxe1cPsx0SVFjrd62217QAAAEo"]
[Thu Sep 17 15:42:45.178706 2026] [security2:error] [pid 60716:tid 60957] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "aqxe1cPsx0SVFjrd62219AAAAD8"]
[Thu Sep 17 15:42:45.178777 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/k8s/.env"] [unique_id "aqxe1cPsx0SVFjrd62219QAAAFA"]
[Thu Sep 17 15:42:45.262832 2026] [security2:error] [pid 60716:tid 60924] [client 40.77.167.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "trcco.org"] [uri "/index.php"] [unique_id "aqxe08Psx0SVFjrd6221sQAAAB8"]
[Thu Sep 17 15:42:45.299681 2026] [security2:error] [pid 60716:tid 60905] [client 34.95.193.102:50448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/phpinfo.php"] [unique_id "aqxe1cPsx0SVFjrd62219gAAAA0"]
[Thu Sep 17 15:42:45.335912 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/kubernetes/.env"] [unique_id "aqxe1cPsx0SVFjrd62219wAAAGo"]
[Thu Sep 17 15:42:45.407530 2026] [security2:error] [pid 60716:tid 60985] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/symfony/.env"] [unique_id "aqxe1cPsx0SVFjrd6221-gAAAFs"]
[Thu Sep 17 15:42:45.491733 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/terraform/.env"] [unique_id "aqxe1cPsx0SVFjrd6221_AAAAAg"]
[Thu Sep 17 15:42:45.635889 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/wordpress/.env"] [unique_id "aqxe1cPsx0SVFjrd6222AAAAACQ"]
[Thu Sep 17 15:42:45.648752 2026] [security2:error] [pid 60716:tid 60894] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/ansible/.env"] [unique_id "aqxe1cPsx0SVFjrd6222AwAAAAI"]
[Thu Sep 17 15:42:45.758915 2026] [core:error] [pid 60716:tid 60951] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:45.758933 2026] [core:error] [pid 60716:tid 60951] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:45.782651 2026] [security2:error] [pid 60716:tid 60904] [client 34.95.193.102:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/info.php"] [unique_id "aqxe1cPsx0SVFjrd6222CQAAAAw"]
[Thu Sep 17 15:42:45.803076 2026] [security2:error] [pid 60716:tid 61015] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/.git/.env"] [unique_id "aqxe1cPsx0SVFjrd6222DQAAAHk"]
[Thu Sep 17 15:42:45.862359 2026] [security2:error] [pid 60716:tid 60970] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "aqxe1cPsx0SVFjrd6222EQAAAEw"]
[Thu Sep 17 15:42:45.957813 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/ci/.env"] [unique_id "aqxe1cPsx0SVFjrd6222FQAAAGY"]
[Thu Sep 17 15:42:46.090412 2026] [security2:error] [pid 60716:tid 60995] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/cms/.env"] [unique_id "aqxe1sPsx0SVFjrd6222GQAAAGU"]
[Thu Sep 17 15:42:46.113134 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/cd/.env"] [unique_id "aqxe1sPsx0SVFjrd6222GwAAAHQ"]
[Thu Sep 17 15:42:46.267707 2026] [security2:error] [pid 60716:tid 61009] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/jenkins/.env"] [unique_id "aqxe1sPsx0SVFjrd6222HwAAAHM"]
[Thu Sep 17 15:42:46.271101 2026] [security2:error] [pid 60716:tid 60916] [client 34.95.193.102:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/php.php"] [unique_id "aqxe1sPsx0SVFjrd6222IAAAABg"]
[Thu Sep 17 15:42:46.320284 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/drupal/.env"] [unique_id "aqxe1sPsx0SVFjrd6222IQAAACw"]
[Thu Sep 17 15:42:46.423146 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/gitlab/.env"] [unique_id "aqxe1sPsx0SVFjrd6222IgAAAHU"]
[Thu Sep 17 15:42:46.483514 2026] [core:error] [pid 60716:tid 60960] [client 34.166.220.229:47268] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:46.483536 2026] [core:error] [pid 60716:tid 60960] [client 34.166.220.229:47268] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:46.552042 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/joomla/.env"] [unique_id "aqxe1sPsx0SVFjrd6222JgAAAFc"]
[Thu Sep 17 15:42:46.576976 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/github/.env"] [unique_id "aqxe1sPsx0SVFjrd6222KAAAAA8"]
[Thu Sep 17 15:42:46.653079 2026] [security2:error] [pid 60716:tid 60911] [client 103.61.184.148:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe1sPsx0SVFjrd6222KwAAABM"]
[Thu Sep 17 15:42:46.653587 2026] [security2:error] [pid 60716:tid 60911] [client 103.61.184.148:51517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe1sPsx0SVFjrd6222KwAAABM"]
[Thu Sep 17 15:42:46.735670 2026] [security2:error] [pid 60716:tid 61004] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/actions/.env"] [unique_id "aqxe1sPsx0SVFjrd6222LwAAAG4"]
[Thu Sep 17 15:42:46.759341 2026] [security2:error] [pid 60716:tid 61002] [client 34.95.193.102:56648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/i.php"] [unique_id "aqxe1sPsx0SVFjrd6222MAAAAGw"]
[Thu Sep 17 15:42:46.777783 2026] [security2:error] [pid 60716:tid 60973] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/magento/.env"] [unique_id "aqxe1sPsx0SVFjrd6222OwAAAE8"]
[Thu Sep 17 15:42:46.890017 2026] [security2:error] [pid 60716:tid 60895] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/circleci/.env"] [unique_id "aqxe1sPsx0SVFjrd6222RAAAAAM"]
[Thu Sep 17 15:42:46.924491 2026] [lsapi:error] [pid 60716:tid 61000] [client 45.115.26.203:0] [host mail.oldschoolrentals.com] Backend fatal error: PHP Fatal error:  Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: http://mail.oldschoolrentals.com/
[Thu Sep 17 15:42:47.003575 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/shopify/.env"] [unique_id "aqxe18Psx0SVFjrd6222VQAAACQ"]
[Thu Sep 17 15:42:47.018107 2026] [security2:error] [pid 60716:tid 61007] [client 24.140.202.61:29726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brownsdailydose.com"] [uri "/xmlrpc.php"] [unique_id "aqxe0cPsx0SVFjrd62209gAAcTo"]
[Thu Sep 17 15:42:47.045600 2026] [security2:error] [pid 60716:tid 60940] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/travis/.env"] [unique_id "aqxe18Psx0SVFjrd6222WQAAAC4"]
[Thu Sep 17 15:42:47.070160 2026] [security2:error] [pid 60716:tid 60922] [client 169.58.197.253:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxe18Psx0SVFjrd6222XQAAAB0"], referer: binance.com
[Thu Sep 17 15:42:47.163286 2026] [security2:error] [pid 60716:tid 60939] [client 34.166.220.229:47270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "aqxe18Psx0SVFjrd6222YgAAAC0"]
[Thu Sep 17 15:42:47.200137 2026] [security2:error] [pid 60716:tid 61013] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/buildkite/.env"] [unique_id "aqxe18Psx0SVFjrd6222ZgAAAHc"]
[Thu Sep 17 15:42:47.230466 2026] [security2:error] [pid 60716:tid 60904] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/prestashop/.env"] [unique_id "aqxe18Psx0SVFjrd6222aAAAAAw"]
[Thu Sep 17 15:42:47.231861 2026] [security2:error] [pid 60716:tid 60988] [client 148.227.75.216:1653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe18Psx0SVFjrd6222aQAAAF4"]
[Thu Sep 17 15:42:47.231961 2026] [security2:error] [pid 60716:tid 60988] [client 148.227.75.216:1653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe18Psx0SVFjrd6222aQAAAF4"]
[Thu Sep 17 15:42:47.244865 2026] [security2:error] [pid 60716:tid 60954] [client 34.95.193.102:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/pi.php"] [unique_id "aqxe18Psx0SVFjrd6222agAAADw"]
[Thu Sep 17 15:42:47.354465 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mysql/.env"] [unique_id "aqxe18Psx0SVFjrd6222awAAADg"]
[Thu Sep 17 15:42:47.360520 2026] [security2:error] [pid 60716:tid 60949] [client 136.158.61.34:43942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe18Psx0SVFjrd6222bAAAADc"]
[Thu Sep 17 15:42:47.360785 2026] [security2:error] [pid 60716:tid 60949] [client 136.158.61.34:43942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe18Psx0SVFjrd6222bAAAADc"]
[Thu Sep 17 15:42:47.423181 2026] [core:error] [pid 60716:tid 60976] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:47.423201 2026] [core:error] [pid 60716:tid 60976] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:47.458607 2026] [security2:error] [pid 60716:tid 60942] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/codeigniter/.env"] [unique_id "aqxe18Psx0SVFjrd6222cwAAADA"]
[Thu Sep 17 15:42:47.510375 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/postgres/.env"] [unique_id "aqxe18Psx0SVFjrd6222dgAAAGY"]
[Thu Sep 17 15:42:47.595419 2026] [security2:error] [pid 60716:tid 60951] [client 24.140.202.61:29726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brownsdailydose.com"] [uri "/xmlrpc.php"] [unique_id "aqxe18Psx0SVFjrd6222YwAAOQ4"]
[Thu Sep 17 15:42:47.664832 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/mongodb/.env"] [unique_id "aqxe18Psx0SVFjrd6222fAAAAHA"]
[Thu Sep 17 15:42:47.682589 2026] [security2:error] [pid 60716:tid 61021] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "commonearthjc.com"] [uri "/index.php"] [unique_id "aqxe1MPsx0SVFjrd6221zgAAAH8"]
[Thu Sep 17 15:42:47.685888 2026] [security2:error] [pid 60716:tid 60997] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/cakephp/.env"] [unique_id "aqxe18Psx0SVFjrd6222fgAAAGc"]
[Thu Sep 17 15:42:47.733729 2026] [security2:error] [pid 60716:tid 61008] [client 34.95.193.102:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/pinfo.php"] [unique_id "aqxe18Psx0SVFjrd6222ggAAAHI"]
[Thu Sep 17 15:42:47.821326 2026] [security2:error] [pid 60716:tid 60981] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/redis/.env"] [unique_id "aqxe18Psx0SVFjrd6222hQAAAFc"]
[Thu Sep 17 15:42:47.912850 2026] [security2:error] [pid 60716:tid 60961] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/zend/.env"] [unique_id "aqxe18Psx0SVFjrd6222iAAAAEM"]
[Thu Sep 17 15:42:47.992375 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/elasticsearch/.env"] [unique_id "aqxe18Psx0SVFjrd6222iQAAAAQ"]
[Thu Sep 17 15:42:48.140111 2026] [security2:error] [pid 60716:tid 60972] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/yii/.env"] [unique_id "aqxe2MPsx0SVFjrd6222kAAAAE4"]
[Thu Sep 17 15:42:48.154696 2026] [security2:error] [pid 60716:tid 60973] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/rabbitmq/.env"] [unique_id "aqxe2MPsx0SVFjrd6222kwAAAE8"]
[Thu Sep 17 15:42:48.158474 2026] [core:error] [pid 60716:tid 60989] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:48.158489 2026] [core:error] [pid 60716:tid 60989] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:48.211070 2026] [security2:error] [pid 60716:tid 60911] [client 137.184.15.198:57950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe2MPsx0SVFjrd6222jAAAExc"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:42:48.234447 2026] [security2:error] [pid 60716:tid 60933] [client 34.95.193.102:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/test.php"] [unique_id "aqxe2MPsx0SVFjrd6222lQAAACc"]
[Thu Sep 17 15:42:48.309228 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/kafka/.env"] [unique_id "aqxe2MPsx0SVFjrd6222mQAAAEY"]
[Thu Sep 17 15:42:48.369226 2026] [security2:error] [pid 60716:tid 60894] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/laravel5/.env"] [unique_id "aqxe2MPsx0SVFjrd6222nAAAAAI"]
[Thu Sep 17 15:42:48.463596 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/queue/.env"] [unique_id "aqxe2MPsx0SVFjrd6222nQAAAG8"]
[Thu Sep 17 15:42:48.586593 2026] [security2:error] [pid 60716:tid 60952] [client 137.184.15.198:57952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe2MPsx0SVFjrd6222ngAAOhw"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260626221113&hideanons=1&limit=100&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:42:48.596138 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "aqxe2MPsx0SVFjrd6222nwAAAAc"]
[Thu Sep 17 15:42:48.617111 2026] [security2:error] [pid 60716:tid 61013] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/worker/.env"] [unique_id "aqxe2MPsx0SVFjrd6222oQAAAHc"]
[Thu Sep 17 15:42:48.753791 2026] [core:error] [pid 60716:tid 60976] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:48.753814 2026] [core:error] [pid 60716:tid 60976] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:48.771874 2026] [security2:error] [pid 60716:tid 61015] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/job/.env"] [unique_id "aqxe2MPsx0SVFjrd6222qAAAAHk"]
[Thu Sep 17 15:42:48.823234 2026] [security2:error] [pid 60716:tid 60942] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "aqxe2MPsx0SVFjrd6222qQAAADA"]
[Thu Sep 17 15:42:48.893358 2026] [core:error] [pid 60716:tid 60897] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:48.893377 2026] [core:error] [pid 60716:tid 60897] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:48.931562 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/test/.env"] [unique_id "aqxe2MPsx0SVFjrd6222rQAAACM"]
[Thu Sep 17 15:42:49.052750 2026] [security2:error] [pid 60716:tid 60963] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/v3/.env"] [unique_id "aqxe2cPsx0SVFjrd6222rgAAAEU"]
[Thu Sep 17 15:42:49.087316 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/qa/.env"] [unique_id "aqxe2cPsx0SVFjrd6222sAAAAH0"]
[Thu Sep 17 15:42:49.243343 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/preview/.env"] [unique_id "aqxe2cPsx0SVFjrd6222swAAADU"]
[Thu Sep 17 15:42:49.247586 2026] [security2:error] [pid 60716:tid 60908] [client 34.95.193.102:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/p.php"] [unique_id "aqxe2cPsx0SVFjrd6222tQAAABA"]
[Thu Sep 17 15:42:49.281511 2026] [security2:error] [pid 60716:tid 60997] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/api/v1/.env"] [unique_id "aqxe2cPsx0SVFjrd6222tgAAAGc"]
[Thu Sep 17 15:42:49.386084 2026] [security2:error] [pid 60716:tid 60925] [client 14.96.156.146:49730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe2cPsx0SVFjrd6222vwAAACA"]
[Thu Sep 17 15:42:49.386193 2026] [security2:error] [pid 60716:tid 60925] [client 14.96.156.146:49730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe2cPsx0SVFjrd6222vwAAACA"]
[Thu Sep 17 15:42:49.397325 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/beta/.env"] [unique_id "aqxe2cPsx0SVFjrd6222wAAAAAQ"]
[Thu Sep 17 15:42:49.508924 2026] [security2:error] [pid 60716:tid 60991] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/api/v2/.env"] [unique_id "aqxe2cPsx0SVFjrd6222zAAAAGE"]
[Thu Sep 17 15:42:49.551671 2026] [security2:error] [pid 60716:tid 60973] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/uat/.env"] [unique_id "aqxe2cPsx0SVFjrd62221QAAAE8"]
[Thu Sep 17 15:42:49.600431 2026] [core:error] [pid 60716:tid 60944] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:49.600461 2026] [core:error] [pid 60716:tid 60944] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:49.707463 2026] [security2:error] [pid 60716:tid 60894] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/stage/.env"] [unique_id "aqxe2cPsx0SVFjrd62223QAAAAI"]
[Thu Sep 17 15:42:49.738375 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/rest/.env"] [unique_id "aqxe2cPsx0SVFjrd62223gAAAAY"]
[Thu Sep 17 15:42:49.744003 2026] [security2:error] [pid 60716:tid 60989] [client 34.95.193.102:56710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/debug.php"] [unique_id "aqxe2cPsx0SVFjrd62223wAAAF8"]
[Thu Sep 17 15:42:49.870098 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/development/.env"] [unique_id "aqxe2cPsx0SVFjrd62225AAAAEc"]
[Thu Sep 17 15:42:49.921456 2026] [security2:error] [pid 60716:tid 60964] [client 50.47.104.246:45009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe2cPsx0SVFjrd62224QAARh0"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:42:49.966784 2026] [security2:error] [pid 60716:tid 60932] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/graphql/.env"] [unique_id "aqxe2cPsx0SVFjrd62225QAAACY"]
[Thu Sep 17 15:42:50.024973 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/production/.env"] [unique_id "aqxe2sPsx0SVFjrd62225wAAAAs"]
[Thu Sep 17 15:42:50.179562 2026] [security2:error] [pid 60716:tid 60977] [client 34.154.248.240:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.edmagik.com"] [uri "/config/app/.env"] [unique_id "aqxe2sPsx0SVFjrd62227gAAAFM"]
[Thu Sep 17 15:42:50.193270 2026] [security2:error] [pid 60716:tid 61020] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/gateway/.env"] [unique_id "aqxe2sPsx0SVFjrd62228AAAAH4"]
[Thu Sep 17 15:42:50.246391 2026] [security2:error] [pid 60716:tid 60987] [client 34.95.193.102:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxe2sPsx0SVFjrd62228QAAAF0"]
[Thu Sep 17 15:42:50.287713 2026] [security2:error] [pid 60716:tid 60988] [client 177.44.133.72:61015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe2sPsx0SVFjrd62228gAAAF4"]
[Thu Sep 17 15:42:50.287886 2026] [security2:error] [pid 60716:tid 60988] [client 177.44.133.72:61015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe2sPsx0SVFjrd62228gAAAF4"]
[Thu Sep 17 15:42:50.314914 2026] [core:error] [pid 60716:tid 60947] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:50.314936 2026] [core:error] [pid 60716:tid 60947] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:50.346723 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.248.240:32936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/phpinfo.php"] [unique_id "aqxe2sPsx0SVFjrd62229wAAABY"]
[Thu Sep 17 15:42:50.424697 2026] [security2:error] [pid 60716:tid 60957] [client 169.58.197.251:59261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxe2sPsx0SVFjrd6222-AAAAD8"], referer: binance.com
[Thu Sep 17 15:42:50.435503 2026] [security2:error] [pid 60716:tid 60962] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/microservice/.env"] [unique_id "aqxe2sPsx0SVFjrd6222-QAAAEQ"]
[Thu Sep 17 15:42:50.662043 2026] [security2:error] [pid 60716:tid 60917] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/service/.env"] [unique_id "aqxe2sPsx0SVFjrd6222_wAAABk"]
[Thu Sep 17 15:42:50.689574 2026] [security2:error] [pid 60716:tid 60925] [client 50.47.104.246:42681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe2sPsx0SVFjrd6222-wAAIAY"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260626221113&hideanons=1&limit=100&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:42:50.753728 2026] [security2:error] [pid 60716:tid 60961] [client 34.95.193.102:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/test/phpinfo.php"] [unique_id "aqxe2sPsx0SVFjrd6223BwAAAEM"]
[Thu Sep 17 15:42:50.783606 2026] [security2:error] [pid 60716:tid 60981] [client 35.224.218.165:40088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxe2sPsx0SVFjrd6223CAAAAFc"]
[Thu Sep 17 15:42:50.818706 2026] [security2:error] [pid 60716:tid 60893] [client 34.154.248.240:33662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/info.php"] [unique_id "aqxe2sPsx0SVFjrd6223CgAAAAE"]
[Thu Sep 17 15:42:50.897592 2026] [security2:error] [pid 60716:tid 60913] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/api/v3/.env"] [unique_id "aqxe2sPsx0SVFjrd6223DgAAABU"]
[Thu Sep 17 15:42:50.915331 2026] [security2:error] [pid 60716:tid 60959] [client 35.224.218.165:40104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxe2sPsx0SVFjrd6223DwAAAEE"]
[Thu Sep 17 15:42:51.025852 2026] [core:error] [pid 60716:tid 60922] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:51.025875 2026] [core:error] [pid 60716:tid 60922] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:51.054065 2026] [security2:error] [pid 60716:tid 61000] [client 35.224.218.165:40110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxe28Psx0SVFjrd6223FAAAAGo"]
[Thu Sep 17 15:42:51.124726 2026] [security2:error] [pid 60716:tid 60920] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/api/dev/.env"] [unique_id "aqxe28Psx0SVFjrd6223FgAAABw"]
[Thu Sep 17 15:42:51.236978 2026] [security2:error] [pid 60716:tid 60952] [client 34.95.193.102:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxe28Psx0SVFjrd6223HQAAADo"]
[Thu Sep 17 15:42:51.255654 2026] [security2:error] [pid 60716:tid 60945] [client 35.224.218.165:40126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/"] [unique_id "aqxe28Psx0SVFjrd6223HgAAADM"]
[Thu Sep 17 15:42:51.284376 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.248.240:33678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/php.php"] [unique_id "aqxe28Psx0SVFjrd6223HwAAABg"]
[Thu Sep 17 15:42:51.351912 2026] [security2:error] [pid 60716:tid 60967] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/api/staging/.env"] [unique_id "aqxe28Psx0SVFjrd6223IQAAAEk"]
[Thu Sep 17 15:42:51.392203 2026] [security2:error] [pid 60716:tid 60942] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/.env"] [unique_id "aqxe28Psx0SVFjrd6223IgAAADA"]
[Thu Sep 17 15:42:51.537228 2026] [security2:error] [pid 60716:tid 60935] [client 143.105.152.240:6971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe28Psx0SVFjrd6223KAAAACk"]
[Thu Sep 17 15:42:51.540952 2026] [security2:error] [pid 60716:tid 60935] [client 143.105.152.240:6971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe28Psx0SVFjrd6223KAAAACk"]
[Thu Sep 17 15:42:51.585480 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "aqxe28Psx0SVFjrd6223KwAAAHo"]
[Thu Sep 17 15:42:51.719713 2026] [security2:error] [pid 60716:tid 60902] [client 34.166.220.229:47326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "aqxe28Psx0SVFjrd6223NQAAAAo"]
[Thu Sep 17 15:42:51.720316 2026] [security2:error] [pid 60716:tid 61015] [client 34.95.193.102:56730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/old/phpinfo.php"] [unique_id "aqxe28Psx0SVFjrd6223NgAAAHk"]
[Thu Sep 17 15:42:51.775564 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.248.240:33684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/i.php"] [unique_id "aqxe28Psx0SVFjrd6223OgAAAH0"]
[Thu Sep 17 15:42:51.814379 2026] [security2:error] [pid 60716:tid 60915] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/lib/.env"] [unique_id "aqxe28Psx0SVFjrd6223PAAAABc"]
[Thu Sep 17 15:42:51.946382 2026] [security2:error] [pid 60716:tid 60984] [client 34.166.220.229:47326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "aqxe28Psx0SVFjrd6223QQAAAFo"]
[Thu Sep 17 15:42:51.954474 2026] [security2:error] [pid 60716:tid 60821] [remote 45.157.54.43:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wholeworkplace.com"] [uri "/xmlrpc.php"] [unique_id "aqxe28Psx0SVFjrd6223QgAAMTs"]
[Thu Sep 17 15:42:51.954618 2026] [security2:error] [pid 60716:tid 60943] [client 45.157.54.43:52864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wholeworkplace.com"] [uri "/xmlrpc.php"] [unique_id "aqxe28Psx0SVFjrd6223QgAAMTs"]
[Thu Sep 17 15:42:52.041715 2026] [security2:error] [pid 60716:tid 61002] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/resources/.env"] [unique_id "aqxe3MPsx0SVFjrd6223SQAAAGw"]
[Thu Sep 17 15:42:52.060874 2026] [security2:error] [pid 60716:tid 60959] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxe3MPsx0SVFjrd6223SwAAAEE"]
[Thu Sep 17 15:42:52.105803 2026] [security2:error] [pid 60716:tid 61007] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxe3MPsx0SVFjrd6223TQAAAHE"]
[Thu Sep 17 15:42:52.204793 2026] [security2:error] [pid 60716:tid 60927] [client 34.95.193.102:56746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxe3MPsx0SVFjrd6223WQAAACI"]
[Thu Sep 17 15:42:52.206028 2026] [core:error] [pid 60716:tid 60920] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:52.206048 2026] [core:error] [pid 60716:tid 60920] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:52.224367 2026] [security2:error] [pid 60716:tid 60941] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxe3MPsx0SVFjrd6223WgAAAC8"]
[Thu Sep 17 15:42:52.240428 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.248.240:33690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/pi.php"] [unique_id "aqxe3MPsx0SVFjrd6223WwAAABs"]
[Thu Sep 17 15:42:52.268095 2026] [security2:error] [pid 60716:tid 61010] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/assets/.env"] [unique_id "aqxe3MPsx0SVFjrd6223XQAAAHQ"]
[Thu Sep 17 15:42:52.494171 2026] [security2:error] [pid 60716:tid 60947] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/uploads/.env"] [unique_id "aqxe3MPsx0SVFjrd6223cAAAADU"]
[Thu Sep 17 15:42:52.694822 2026] [security2:error] [pid 60716:tid 60951] [client 34.95.193.102:56758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/public/phpinfo.php"] [unique_id "aqxe3MPsx0SVFjrd6223ewAAADk"]
[Thu Sep 17 15:42:52.709554 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.248.240:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/pinfo.php"] [unique_id "aqxe3MPsx0SVFjrd6223fAAAAFE"]
[Thu Sep 17 15:42:52.737597 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/internal/.env"] [unique_id "aqxe3MPsx0SVFjrd6223fQAAAH0"]
[Thu Sep 17 15:42:52.906062 2026] [security2:error] [pid 60716:tid 60957] [client 34.166.220.229:47332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "aqxe3MPsx0SVFjrd6223gwAAAD8"]
[Thu Sep 17 15:42:52.971655 2026] [security2:error] [pid 60716:tid 61021] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/tools/.env"] [unique_id "aqxe3MPsx0SVFjrd6223hQAAAH8"]
[Thu Sep 17 15:42:52.995178 2026] [security2:error] [pid 60716:tid 60914] [client 79.116.89.151:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe3MPsx0SVFjrd6223hgAAABY"]
[Thu Sep 17 15:42:52.995256 2026] [security2:error] [pid 60716:tid 60914] [client 79.116.89.151:63956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe3MPsx0SVFjrd6223hgAAABY"]
[Thu Sep 17 15:42:53.184621 2026] [core:error] [pid 60716:tid 60965] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:53.184652 2026] [core:error] [pid 60716:tid 60965] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:53.206607 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.248.240:33714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/test.php"] [unique_id "aqxe3cPsx0SVFjrd6223lQAAAG8"]
[Thu Sep 17 15:42:53.207750 2026] [security2:error] [pid 60716:tid 61000] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/scripts/.env"] [unique_id "aqxe3cPsx0SVFjrd6223lgAAAGo"]
[Thu Sep 17 15:42:53.245166 2026] [core:error] [pid 60716:tid 60919] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:53.245191 2026] [core:error] [pid 60716:tid 60919] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:53.447559 2026] [security2:error] [pid 60716:tid 60988] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/bin/.env"] [unique_id "aqxe3cPsx0SVFjrd6223pgAAAF4"]
[Thu Sep 17 15:42:53.573671 2026] [security2:error] [pid 60716:tid 60935] [client 181.215.65.36:60715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireflyhotglass-org.glassblowingbug.com"] [uri "/index.php"] [unique_id "aqxe3cPsx0SVFjrd6223oAAAKUw"]
[Thu Sep 17 15:42:53.578770 2026] [security2:error] [pid 60716:tid 60991] [client 181.215.65.39:33855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireflyhotglass.glassblowingbug.com"] [uri "/index.php"] [unique_id "aqxe3cPsx0SVFjrd6223oQAAYVA"]
[Thu Sep 17 15:42:53.585400 2026] [security2:error] [pid 60716:tid 60989] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxe3cPsx0SVFjrd6223rQAAAF8"]
[Thu Sep 17 15:42:53.595550 2026] [security2:error] [pid 60716:tid 60999] [client 181.215.65.49:58731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireflyhotglass.org"] [uri "/index.php"] [unique_id "aqxe3cPsx0SVFjrd6223owAAaU4"]
[Thu Sep 17 15:42:53.601100 2026] [security2:error] [pid 60716:tid 61007] [client 181.215.65.44:45425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireflyhotglass-net.glassblowingbug.com"] [uri "/index.php"] [unique_id "aqxe3cPsx0SVFjrd6223ogAAcVE"]
[Thu Sep 17 15:42:53.630969 2026] [security2:error] [pid 60716:tid 60951] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/.env~"] [unique_id "aqxe3cPsx0SVFjrd6223rwAAADk"]
[Thu Sep 17 15:42:53.676714 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/sbin/.env"] [unique_id "aqxe3cPsx0SVFjrd6223sAAAACA"]
[Thu Sep 17 15:42:53.802289 2026] [security2:error] [pid 60716:tid 60912] [client 34.95.193.102:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/php-info.php"] [unique_id "aqxe3cPsx0SVFjrd6223uQAAABQ"]
[Thu Sep 17 15:42:53.903171 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "aqxe3cPsx0SVFjrd6223xgAAABM"]
[Thu Sep 17 15:42:53.904553 2026] [core:error] [pid 60716:tid 60896] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:53.904570 2026] [core:error] [pid 60716:tid 60896] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:54.130088 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "aqxe3sPsx0SVFjrd62230AAAACs"]
[Thu Sep 17 15:42:54.216522 2026] [security2:error] [pid 60716:tid 61002] [client 34.154.248.240:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/p.php"] [unique_id "aqxe3sPsx0SVFjrd62231QAAAGw"]
[Thu Sep 17 15:42:54.287767 2026] [security2:error] [pid 60716:tid 60956] [client 34.95.193.102:33386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/phpversion.php"] [unique_id "aqxe3sPsx0SVFjrd62233AAAAD4"]
[Thu Sep 17 15:42:54.291476 2026] [security2:error] [pid 60716:tid 60996] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxe3sPsx0SVFjrd62233QAAAGY"]
[Thu Sep 17 15:42:54.334287 2026] [security2:error] [pid 60716:tid 60899] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxe3sPsx0SVFjrd62233wAAAAc"]
[Thu Sep 17 15:42:54.363857 2026] [security2:error] [pid 60716:tid 60966] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/dashboard/.env"] [unique_id "aqxe3sPsx0SVFjrd62234AAAAEg"]
[Thu Sep 17 15:42:54.381594 2026] [security2:error] [pid 60716:tid 61012] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxe3sPsx0SVFjrd62234gAAAHY"]
[Thu Sep 17 15:42:54.434042 2026] [security2:error] [pid 60716:tid 60983] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxe3sPsx0SVFjrd62234wAAAFk"]
[Thu Sep 17 15:42:54.478871 2026] [security2:error] [pid 60716:tid 61004] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxe3sPsx0SVFjrd62235gAAAG4"]
[Thu Sep 17 15:42:54.525582 2026] [security2:error] [pid 60716:tid 61014] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxe3sPsx0SVFjrd62236gAAAHg"]
[Thu Sep 17 15:42:54.562981 2026] [security2:error] [pid 60716:tid 60892] [client 181.215.65.46:56329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireflyhotglass.com"] [uri "/index.php"] [unique_id "aqxe3sPsx0SVFjrd62234QAAAFY"]
[Thu Sep 17 15:42:54.590761 2026] [security2:error] [pid 60716:tid 60960] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/panel/.env"] [unique_id "aqxe3sPsx0SVFjrd62237wAAAEI"]
[Thu Sep 17 15:42:54.616619 2026] [core:error] [pid 60716:tid 60986] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:54.616635 2026] [core:error] [pid 60716:tid 60986] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:54.645850 2026] [security2:error] [pid 60716:tid 60950] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxe3sPsx0SVFjrd62239AAAADg"]
[Thu Sep 17 15:42:54.682361 2026] [security2:error] [pid 60716:tid 61020] [client 34.154.248.240:33738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/debug.php"] [unique_id "aqxe3sPsx0SVFjrd6223-AAAAH4"]
[Thu Sep 17 15:42:54.688649 2026] [security2:error] [pid 60716:tid 60917] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxe3sPsx0SVFjrd6223_wAAABk"]
[Thu Sep 17 15:42:54.734653 2026] [security2:error] [pid 60716:tid 60934] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxe3sPsx0SVFjrd6224DgAAACg"]
[Thu Sep 17 15:42:54.772236 2026] [security2:error] [pid 60716:tid 60989] [client 34.95.193.102:33398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/_phpinfo.php"] [unique_id "aqxe3sPsx0SVFjrd6224DwAAAF8"]
[Thu Sep 17 15:42:54.780424 2026] [security2:error] [pid 60716:tid 60972] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxe3sPsx0SVFjrd6224EAAAAE4"]
[Thu Sep 17 15:42:54.818576 2026] [security2:error] [pid 60716:tid 60900] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "aqxe3sPsx0SVFjrd6224EwAAAAg"]
[Thu Sep 17 15:42:54.830146 2026] [security2:error] [pid 60716:tid 60915] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxe3sPsx0SVFjrd6224FAAAABc"]
[Thu Sep 17 15:42:54.849553 2026] [security2:error] [pid 60716:tid 60896] [client 93.152.209.11:57472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jaj.bms.mybluehost.me"] [uri "/.env"] [unique_id "aqxe3sPsx0SVFjrd6224FQAAAAQ"]
[Thu Sep 17 15:42:54.878449 2026] [security2:error] [pid 60716:tid 60908] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxe3sPsx0SVFjrd6224FgAAABA"]
[Thu Sep 17 15:42:54.927831 2026] [security2:error] [pid 60716:tid 60943] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxe3sPsx0SVFjrd6224GwAAADE"]
[Thu Sep 17 15:42:54.971791 2026] [security2:error] [pid 60716:tid 60959] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxe3sPsx0SVFjrd6224HgAAAEE"]
[Thu Sep 17 15:42:54.975845 2026] [security2:error] [pid 60716:tid 60766] [remote 93.152.209.11:26460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jaj.bms.mybluehost.me"] [uri "/.env"] [unique_id "aqxe3sPsx0SVFjrd6224HwAAYwc"]
[Thu Sep 17 15:42:55.016425 2026] [security2:error] [pid 60716:tid 60932] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxe38Psx0SVFjrd6224IgAAACY"]
[Thu Sep 17 15:42:55.047781 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/erp/.env"] [unique_id "aqxe38Psx0SVFjrd6224JgAAAB0"]
[Thu Sep 17 15:42:55.065864 2026] [security2:error] [pid 60716:tid 60940] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxe38Psx0SVFjrd6224JwAAAC4"]
[Thu Sep 17 15:42:55.113777 2026] [security2:error] [pid 60716:tid 60954] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxe38Psx0SVFjrd6224KgAAADw"]
[Thu Sep 17 15:42:55.162609 2026] [security2:error] [pid 60716:tid 60937] [client 34.154.248.240:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxe38Psx0SVFjrd6224LgAAACs"]
[Thu Sep 17 15:42:55.163761 2026] [security2:error] [pid 60716:tid 60912] [client 210.222.43.21:52841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224IQAAABQ"], referer: http://talent-in-borders.com/blog
[Thu Sep 17 15:42:55.175859 2026] [security2:error] [pid 60716:tid 60936] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxe38Psx0SVFjrd6224LwAAACo"]
[Thu Sep 17 15:42:55.219620 2026] [security2:error] [pid 60716:tid 60996] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxe38Psx0SVFjrd6224MgAAAGY"]
[Thu Sep 17 15:42:55.266342 2026] [security2:error] [pid 60716:tid 60966] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxe38Psx0SVFjrd6224NAAAAEg"]
[Thu Sep 17 15:42:55.299635 2026] [security2:error] [pid 60716:tid 61003] [client 34.95.193.102:33414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/old_phpinfo.php"] [unique_id "aqxe38Psx0SVFjrd6224NQAAAG0"]
[Thu Sep 17 15:42:55.301890 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/shop/.env"] [unique_id "aqxe38Psx0SVFjrd6224NgAAAAY"]
[Thu Sep 17 15:42:55.308524 2026] [security2:error] [pid 60716:tid 60953] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxe38Psx0SVFjrd6224OAAAADs"]
[Thu Sep 17 15:42:55.340197 2026] [core:error] [pid 60716:tid 61001] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:55.340215 2026] [core:error] [pid 60716:tid 61001] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:55.354271 2026] [security2:error] [pid 60716:tid 61004] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxe38Psx0SVFjrd6224OwAAAG4"]
[Thu Sep 17 15:42:55.400711 2026] [security2:error] [pid 60716:tid 61016] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxe38Psx0SVFjrd6224PAAAAHo"]
[Thu Sep 17 15:42:55.447174 2026] [security2:error] [pid 60716:tid 60963] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxe38Psx0SVFjrd6224PwAAAEU"]
[Thu Sep 17 15:42:55.493632 2026] [security2:error] [pid 60716:tid 60892] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxe38Psx0SVFjrd6224QAAAAAA"]
[Thu Sep 17 15:42:55.528641 2026] [security2:error] [pid 60716:tid 60927] [client 34.166.135.226:42662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/store/.env"] [unique_id "aqxe38Psx0SVFjrd6224QQAAACI"]
[Thu Sep 17 15:42:55.542049 2026] [security2:error] [pid 60716:tid 60939] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxe38Psx0SVFjrd6224QwAAAC0"]
[Thu Sep 17 15:42:55.584886 2026] [security2:error] [pid 60716:tid 60997] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxe38Psx0SVFjrd6224RgAAAGc"]
[Thu Sep 17 15:42:55.628117 2026] [security2:error] [pid 60716:tid 60999] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxe38Psx0SVFjrd6224SAAAAGk"]
[Thu Sep 17 15:42:55.640495 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.248.240:33756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/test/phpinfo.php"] [unique_id "aqxe38Psx0SVFjrd6224SQAAAFA"]
[Thu Sep 17 15:42:55.643194 2026] [security2:error] [pid 60716:tid 60905] [client 24.140.202.61:29727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "brownsdailydose.com"] [uri "/wp-login.php"] [unique_id "aqxe3cPsx0SVFjrd6223uAAADVM"]
[Thu Sep 17 15:42:55.673346 2026] [security2:error] [pid 60716:tid 60970] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxe38Psx0SVFjrd6224TQAAAEw"]
[Thu Sep 17 15:42:55.698333 2026] [security2:error] [pid 60716:tid 60759] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.bak"] [unique_id "aqxe38Psx0SVFjrd6224UgAADAE"]
[Thu Sep 17 15:42:55.698344 2026] [security2:error] [pid 60716:tid 60761] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.backup"] [unique_id "aqxe38Psx0SVFjrd6224UwAADAM"]
[Thu Sep 17 15:42:55.699190 2026] [security2:error] [pid 60716:tid 60759] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.old"] [unique_id "aqxe38Psx0SVFjrd6224VQAADAE"]
[Thu Sep 17 15:42:55.716313 2026] [security2:error] [pid 60716:tid 61019] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxe38Psx0SVFjrd6224XgAAAH0"]
[Thu Sep 17 15:42:55.752405 2026] [security2:error] [pid 60716:tid 60900] [client 143.244.57.92:47730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqxe38Psx0SVFjrd6224ZwAAAAg"]
[Thu Sep 17 15:42:55.763101 2026] [security2:error] [pid 60716:tid 60984] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxe38Psx0SVFjrd6224aAAAAFo"]
[Thu Sep 17 15:42:55.789312 2026] [security2:error] [pid 60716:tid 60986] [client 34.95.193.102:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/server-info.php"] [unique_id "aqxe38Psx0SVFjrd6224awAAAFw"]
[Thu Sep 17 15:42:55.808953 2026] [security2:error] [pid 60716:tid 60910] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxe38Psx0SVFjrd6224bAAAABI"]
[Thu Sep 17 15:42:55.816488 2026] [security2:error] [pid 60716:tid 60962] [client 162.241.226.11:51084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxe3sPsx0SVFjrd62236wAAAEQ"]
[Thu Sep 17 15:42:55.854558 2026] [security2:error] [pid 60716:tid 61021] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxe38Psx0SVFjrd6224bgAAAH8"]
[Thu Sep 17 15:42:55.864505 2026] [security2:error] [pid 60716:tid 60896] [client 45.61.184.170:63268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "kslandscaping.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxe38Psx0SVFjrd6224bwAAAAQ"]
[Thu Sep 17 15:42:55.899714 2026] [security2:error] [pid 60716:tid 60990] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxe38Psx0SVFjrd6224cAAAAGA"]
[Thu Sep 17 15:42:55.952641 2026] [security2:error] [pid 60716:tid 60922] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxe38Psx0SVFjrd6224cQAAAB0"]
[Thu Sep 17 15:42:55.966335 2026] [security2:error] [pid 60716:tid 60941] [client 169.58.197.253:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxe38Psx0SVFjrd6224cgAAAC8"], referer: binance.com
[Thu Sep 17 15:42:55.996683 2026] [security2:error] [pid 60716:tid 60920] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxe38Psx0SVFjrd6224cwAAABw"]
[Thu Sep 17 15:42:56.026312 2026] [security2:error] [pid 60716:tid 60972] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224YwAAAE4"]
[Thu Sep 17 15:42:56.026314 2026] [security2:error] [pid 60716:tid 60987] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224XwAAAF0"]
[Thu Sep 17 15:42:56.026328 2026] [security2:error] [pid 60716:tid 60975] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224YAAAAFE"]
[Thu Sep 17 15:42:56.027578 2026] [security2:error] [pid 60716:tid 60989] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224YgAAAF8"]
[Thu Sep 17 15:42:56.027597 2026] [security2:error] [pid 60716:tid 60969] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224YQAAAEs"]
[Thu Sep 17 15:42:56.028418 2026] [security2:error] [pid 60716:tid 60926] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224ZQAAACE"]
[Thu Sep 17 15:42:56.029232 2026] [security2:error] [pid 60716:tid 60772] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env"] [unique_id "aqxe38Psx0SVFjrd6224fAAADA0"]
[Thu Sep 17 15:42:56.039512 2026] [security2:error] [pid 60716:tid 61006] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxe4MPsx0SVFjrd6224igAAAHA"]
[Thu Sep 17 15:42:56.042829 2026] [security2:error] [pid 60716:tid 60772] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/.env.php"] [unique_id "aqxe38Psx0SVFjrd6224fwAADA0"]
[Thu Sep 17 15:42:56.062825 2026] [core:error] [pid 60716:tid 60978] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:56.062852 2026] [core:error] [pid 60716:tid 60978] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:56.085679 2026] [security2:error] [pid 60716:tid 60988] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxe4MPsx0SVFjrd6224lAAAAF4"]
[Thu Sep 17 15:42:56.112806 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.248.240:33764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxe4MPsx0SVFjrd6224lQAAAFU"]
[Thu Sep 17 15:42:56.130904 2026] [security2:error] [pid 60716:tid 61016] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxe4MPsx0SVFjrd6224lwAAAHo"]
[Thu Sep 17 15:42:56.174889 2026] [security2:error] [pid 60716:tid 60927] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxe4MPsx0SVFjrd6224mQAAACI"]
[Thu Sep 17 15:42:56.219163 2026] [security2:error] [pid 60716:tid 61017] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxe4MPsx0SVFjrd6224nAAAAHs"]
[Thu Sep 17 15:42:56.263149 2026] [security2:error] [pid 60716:tid 60948] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxe4MPsx0SVFjrd6224nQAAADY"]
[Thu Sep 17 15:42:56.277467 2026] [security2:error] [pid 60716:tid 60947] [client 34.95.193.102:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/server-status.php"] [unique_id "aqxe4MPsx0SVFjrd6224oAAAADU"]
[Thu Sep 17 15:42:56.290862 2026] [security2:error] [pid 60716:tid 61005] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224iwAAAG8"]
[Thu Sep 17 15:42:56.293169 2026] [security2:error] [pid 60716:tid 61012] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224kAAAAHY"]
[Thu Sep 17 15:42:56.294628 2026] [security2:error] [pid 60716:tid 61003] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224jQAAAG0"]
[Thu Sep 17 15:42:56.294771 2026] [security2:error] [pid 60716:tid 60992] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224jwAAAGI"]
[Thu Sep 17 15:42:56.296088 2026] [security2:error] [pid 60716:tid 61008] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224jAAAAHI"]
[Thu Sep 17 15:42:56.297064 2026] [security2:error] [pid 60716:tid 60786] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env~"] [unique_id "aqxe4MPsx0SVFjrd6224ogAADBg"]
[Thu Sep 17 15:42:56.297071 2026] [security2:error] [pid 60716:tid 60777] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.env.swp"] [unique_id "aqxe4MPsx0SVFjrd6224owAADBE"]
[Thu Sep 17 15:42:56.297811 2026] [security2:error] [pid 60716:tid 60898] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224jgAAAAY"]
[Thu Sep 17 15:42:56.307359 2026] [security2:error] [pid 60716:tid 60974] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxe4MPsx0SVFjrd6224pgAAAFA"]
[Thu Sep 17 15:42:56.320327 2026] [security2:error] [pid 60716:tid 60905] [client 143.244.57.92:47740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4MPsx0SVFjrd6224qAAAAA0"]
[Thu Sep 17 15:42:56.322778 2026] [security2:error] [pid 60716:tid 60909] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224kgAAABE"]
[Thu Sep 17 15:42:56.323177 2026] [security2:error] [pid 60716:tid 60953] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224kQAAADs"]
[Thu Sep 17 15:42:56.325088 2026] [security2:error] [pid 60716:tid 60997] [client 127.0.0.1:30234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxe4MPsx0SVFjrd6224nwAAAGc"]
[Thu Sep 17 15:42:56.325276 2026] [security2:error] [pid 60716:tid 60960] [client 74.7.244.9:37708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.flxvoices.com"] [uri "/robots.txt"] [unique_id "aqxe4MPsx0SVFjrd6224ngAAQn8"]
[Thu Sep 17 15:42:56.351026 2026] [security2:error] [pid 60716:tid 60915] [client 35.224.218.165:40130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxe4MPsx0SVFjrd6224qQAAABc"]
[Thu Sep 17 15:42:56.357413 2026] [security2:error] [pid 60716:tid 60961] [client 162.241.226.11:18248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "quaywordspi.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxe4MPsx0SVFjrd6224qgAAAEM"]
[Thu Sep 17 15:42:56.405254 2026] [security2:error] [pid 60716:tid 61014] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/saas/.env"] [unique_id "aqxe4MPsx0SVFjrd6224rAAAAHg"]
[Thu Sep 17 15:42:56.505058 2026] [security2:error] [pid 60716:tid 60940] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxe4MPsx0SVFjrd6224uQAAAC4"]
[Thu Sep 17 15:42:56.553194 2026] [security2:error] [pid 60716:tid 60989] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxe4MPsx0SVFjrd6224wgAAAF8"]
[Thu Sep 17 15:42:56.591128 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.248.240:33768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/old/phpinfo.php"] [unique_id "aqxe4MPsx0SVFjrd6224xgAAAGA"]
[Thu Sep 17 15:42:56.600978 2026] [security2:error] [pid 60716:tid 60929] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxe4MPsx0SVFjrd6224yQAAACQ"]
[Thu Sep 17 15:42:56.612133 2026] [security2:error] [pid 60716:tid 60791] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/api/.env"] [unique_id "aqxe4MPsx0SVFjrd6224ygAADB0"]
[Thu Sep 17 15:42:56.615254 2026] [security2:error] [pid 60716:tid 60926] [client 143.244.57.92:47750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4MPsx0SVFjrd6224zQAAACE"]
[Thu Sep 17 15:42:56.616254 2026] [security2:error] [pid 60716:tid 60807] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/app/.env"] [unique_id "aqxe4MPsx0SVFjrd6224zAAADC0"]
[Thu Sep 17 15:42:56.629653 2026] [security2:error] [pid 60716:tid 60998] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224twAAAGg"]
[Thu Sep 17 15:42:56.634854 2026] [security2:error] [pid 60716:tid 60977] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/client/.env"] [unique_id "aqxe4MPsx0SVFjrd62240AAAAFM"]
[Thu Sep 17 15:42:56.644772 2026] [security2:error] [pid 60716:tid 60936] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxe4MPsx0SVFjrd62240QAAACo"]
[Thu Sep 17 15:42:56.691917 2026] [security2:error] [pid 60716:tid 60967] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxe4MPsx0SVFjrd62242QAAAEk"]
[Thu Sep 17 15:42:56.705492 2026] [security2:error] [pid 60716:tid 60809] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/src/.env"] [unique_id "aqxe4MPsx0SVFjrd62243gAADC8"]
[Thu Sep 17 15:42:56.705493 2026] [security2:error] [pid 60716:tid 60805] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/server/.env"] [unique_id "aqxe4MPsx0SVFjrd62243AAADCs"]
[Thu Sep 17 15:42:56.705671 2026] [security2:error] [pid 60716:tid 60810] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/config/.env"] [unique_id "aqxe4MPsx0SVFjrd62243QAADDA"]
[Thu Sep 17 15:42:56.705744 2026] [security2:error] [pid 60716:tid 60804] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/backend/.env"] [unique_id "aqxe4MPsx0SVFjrd62242wAADCo"]
[Thu Sep 17 15:42:56.707082 2026] [security2:error] [pid 60716:tid 60816] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/web/.env"] [unique_id "aqxe4MPsx0SVFjrd62244AAADDY"]
[Thu Sep 17 15:42:56.722079 2026] [security2:error] [pid 60716:tid 60965] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224vwAAAEc"]
[Thu Sep 17 15:42:56.726825 2026] [security2:error] [pid 60716:tid 60975] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224vQAAAFE"]
[Thu Sep 17 15:42:56.731319 2026] [security2:error] [pid 60716:tid 61009] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224wAAAAHM"]
[Thu Sep 17 15:42:56.740358 2026] [security2:error] [pid 60716:tid 60963] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxe4MPsx0SVFjrd62245gAAAEU"]
[Thu Sep 17 15:42:56.741939 2026] [security2:error] [pid 60716:tid 60954] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224uwAAADw"]
[Thu Sep 17 15:42:56.751970 2026] [security2:error] [pid 60716:tid 60931] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6224wwAAACU"]
[Thu Sep 17 15:42:56.788774 2026] [security2:error] [pid 60716:tid 60974] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxe4MPsx0SVFjrd62247AAAAFA"]
[Thu Sep 17 15:42:56.806275 2026] [core:error] [pid 60716:tid 60905] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:56.806298 2026] [core:error] [pid 60716:tid 60905] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:56.814983 2026] [core:error] [pid 60716:tid 60997] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:56.815006 2026] [core:error] [pid 60716:tid 60997] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:56.833266 2026] [security2:error] [pid 60716:tid 60982] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxe4MPsx0SVFjrd62248gAAAFg"]
[Thu Sep 17 15:42:56.837515 2026] [security2:error] [pid 60716:tid 60788] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/public/.env"] [unique_id "aqxe4MPsx0SVFjrd62249QAADBo"]
[Thu Sep 17 15:42:56.837534 2026] [security2:error] [pid 60716:tid 60818] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/frontend/.env"] [unique_id "aqxe4MPsx0SVFjrd62248wAADDg"]
[Thu Sep 17 15:42:56.837657 2026] [security2:error] [pid 60716:tid 60817] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/client/.env"] [unique_id "aqxe4MPsx0SVFjrd62249AAADDc"]
[Thu Sep 17 15:42:56.840889 2026] [security2:error] [pid 60716:tid 60799] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/var/www/.env"] [unique_id "aqxe4MPsx0SVFjrd62249gAADCU"]
[Thu Sep 17 15:42:56.841501 2026] [security2:error] [pid 60716:tid 60802] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/laravel/.env"] [unique_id "aqxe4MPsx0SVFjrd6224-QAADCg"]
[Thu Sep 17 15:42:56.841596 2026] [security2:error] [pid 60716:tid 60795] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/application/.env"] [unique_id "aqxe4MPsx0SVFjrd6224-AAADCE"]
[Thu Sep 17 15:42:56.841611 2026] [security2:error] [pid 60716:tid 60793] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/var/www/html/.env"] [unique_id "aqxe4MPsx0SVFjrd62249wAADB8"]
[Thu Sep 17 15:42:56.841988 2026] [security2:error] [pid 60716:tid 60803] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/apps/.env"] [unique_id "aqxe4MPsx0SVFjrd6224-gAADCk"]
[Thu Sep 17 15:42:56.861181 2026] [security2:error] [pid 60716:tid 60798] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/back/.env"] [unique_id "aqxe4MPsx0SVFjrd6224_AAADCQ"]
[Thu Sep 17 15:42:56.863691 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/project/.env"] [unique_id "aqxe4MPsx0SVFjrd6224_gAAAH0"]
[Thu Sep 17 15:42:56.864078 2026] [security2:error] [pid 60716:tid 60811] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/backup/.env"] [unique_id "aqxe4MPsx0SVFjrd6224_QAADDE"]
[Thu Sep 17 15:42:56.874211 2026] [security2:error] [pid 60716:tid 60934] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd62241wAAACg"]
[Thu Sep 17 15:42:56.876897 2026] [security2:error] [pid 60716:tid 60821] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/cms/.env"] [unique_id "aqxe4MPsx0SVFjrd6225AAAADDs"]
[Thu Sep 17 15:42:56.876901 2026] [security2:error] [pid 60716:tid 60973] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxe4MPsx0SVFjrd6225AQAAAE8"]
[Thu Sep 17 15:42:56.879464 2026] [security2:error] [pid 60716:tid 60822] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/dev/.env"] [unique_id "aqxe4MPsx0SVFjrd6225AgAADDw"]
[Thu Sep 17 15:42:56.898705 2026] [security2:error] [pid 60716:tid 60964] [client 143.244.57.92:47754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4MPsx0SVFjrd6225BAAAAEY"]
[Thu Sep 17 15:42:56.911711 2026] [security2:error] [pid 60716:tid 60815] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/prod/.env"] [unique_id "aqxe4MPsx0SVFjrd6225BgAADDU"]
[Thu Sep 17 15:42:56.921387 2026] [security2:error] [pid 60716:tid 61007] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxe4MPsx0SVFjrd6225BwAAAHE"]
[Thu Sep 17 15:42:56.921647 2026] [security2:error] [pid 60716:tid 60988] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd62245AAAAF4"]
[Thu Sep 17 15:42:56.965285 2026] [security2:error] [pid 60716:tid 60947] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd62246wAAADU"]
[Thu Sep 17 15:42:56.965749 2026] [security2:error] [pid 60716:tid 60966] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxe4MPsx0SVFjrd6225CAAAAEg"]
[Thu Sep 17 15:42:56.973767 2026] [security2:error] [pid 60716:tid 60763] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/test/.env"] [unique_id "aqxe4MPsx0SVFjrd6225CgAADAU"]
[Thu Sep 17 15:42:56.973865 2026] [security2:error] [pid 60716:tid 60824] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/production/.env"] [unique_id "aqxe4MPsx0SVFjrd6225CwAADD4"]
[Thu Sep 17 15:42:56.973878 2026] [security2:error] [pid 60716:tid 60823] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/staging/.env"] [unique_id "aqxe4MPsx0SVFjrd6225DAAADD0"]
[Thu Sep 17 15:42:56.976357 2026] [security2:error] [pid 60716:tid 60787] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/old/.env"] [unique_id "aqxe4MPsx0SVFjrd6225DQAADBk"]
[Thu Sep 17 15:42:56.976895 2026] [security2:error] [pid 60716:tid 60828] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/new/.env"] [unique_id "aqxe4MPsx0SVFjrd6225DwAADEI"]
[Thu Sep 17 15:42:56.976953 2026] [security2:error] [pid 60716:tid 60812] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/node-api/.env"] [unique_id "aqxe4MPsx0SVFjrd6225EAAADDI"]
[Thu Sep 17 15:42:56.976980 2026] [security2:error] [pid 60716:tid 60829] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/api-backend/.env"] [unique_id "aqxe4MPsx0SVFjrd6225EQAADEM"]
[Thu Sep 17 15:42:56.977161 2026] [security2:error] [pid 60716:tid 60782] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/admin-app/.env"] [unique_id "aqxe4MPsx0SVFjrd6225EgAADBU"]
[Thu Sep 17 15:42:57.000433 2026] [security2:error] [pid 60716:tid 60830] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/public_html/.env"] [unique_id "aqxe4MPsx0SVFjrd6225FQAADEQ"]
[Thu Sep 17 15:42:57.012159 2026] [security2:error] [pid 60716:tid 60962] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxe4cPsx0SVFjrd6225FgAAAEQ"]
[Thu Sep 17 15:42:57.013475 2026] [security2:error] [pid 60716:tid 60832] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/current/.env"] [unique_id "aqxe4cPsx0SVFjrd6225FwAADEY"]
[Thu Sep 17 15:42:57.015636 2026] [security2:error] [pid 60716:tid 60831] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/server/api/.env"] [unique_id "aqxe4cPsx0SVFjrd6225GAAADEU"]
[Thu Sep 17 15:42:57.025191 2026] [security2:error] [pid 60716:tid 60837] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/server/backend/.env"] [unique_id "aqxe4cPsx0SVFjrd6225GQAADEs"]
[Thu Sep 17 15:42:57.047920 2026] [security2:error] [pid 60716:tid 60836] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.docker/.env"] [unique_id "aqxe4cPsx0SVFjrd6225GgAADEo"]
[Thu Sep 17 15:42:57.055231 2026] [security2:error] [pid 60716:tid 60938] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxe4cPsx0SVFjrd6225GwAAACw"]
[Thu Sep 17 15:42:57.062115 2026] [security2:error] [pid 60716:tid 60914] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4MPsx0SVFjrd6225BQAAABY"]
[Thu Sep 17 15:42:57.062928 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.248.240:33774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxe4cPsx0SVFjrd6225HAAAAEA"]
[Thu Sep 17 15:42:57.064698 2026] [security2:error] [pid 60716:tid 60827] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/administrator/.env"] [unique_id "aqxe4MPsx0SVFjrd6225EwAADEE"]
[Thu Sep 17 15:42:57.077026 2026] [security2:error] [pid 60716:tid 60826] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxe4cPsx0SVFjrd6225HQAADEA"]
[Thu Sep 17 15:42:57.092871 2026] [security2:error] [pid 60716:tid 60932] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/admin-panel/.env"] [unique_id "aqxe4cPsx0SVFjrd6225HgAAACY"]
[Thu Sep 17 15:42:57.107049 2026] [security2:error] [pid 60716:tid 60935] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxe4cPsx0SVFjrd6225HwAAACk"]
[Thu Sep 17 15:42:57.110078 2026] [security2:error] [pid 60716:tid 60842] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/stripe/.env"] [unique_id "aqxe4cPsx0SVFjrd6225IgAAXVA"]
[Thu Sep 17 15:42:57.110078 2026] [security2:error] [pid 60716:tid 60834] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/aws/.env"] [unique_id "aqxe4cPsx0SVFjrd6225IAAAXUg"]
[Thu Sep 17 15:42:57.110092 2026] [security2:error] [pid 60716:tid 60838] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.aws/.env"] [unique_id "aqxe4cPsx0SVFjrd6225IQAAXUw"]
[Thu Sep 17 15:42:57.112416 2026] [security2:error] [pid 60716:tid 60839] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/v2/.env"] [unique_id "aqxe4cPsx0SVFjrd6225JgAALU0"]
[Thu Sep 17 15:42:57.112474 2026] [security2:error] [pid 60716:tid 60843] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/v1/.env"] [unique_id "aqxe4cPsx0SVFjrd6225JQAALVE"]
[Thu Sep 17 15:42:57.112478 2026] [security2:error] [pid 60716:tid 60835] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/v3/.env"] [unique_id "aqxe4cPsx0SVFjrd6225JwAALUk"]
[Thu Sep 17 15:42:57.115004 2026] [security2:error] [pid 60716:tid 60844] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/media/.env"] [unique_id "aqxe4cPsx0SVFjrd6225KAAALVI"]
[Thu Sep 17 15:42:57.149526 2026] [security2:error] [pid 60716:tid 60977] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxe4cPsx0SVFjrd6225MAAAAFM"]
[Thu Sep 17 15:42:57.191931 2026] [security2:error] [pid 60716:tid 61017] [client 143.244.57.92:47768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4cPsx0SVFjrd6225QQAAAHs"]
[Thu Sep 17 15:42:57.194941 2026] [security2:error] [pid 60716:tid 60952] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxe4cPsx0SVFjrd6225QgAAADo"]
[Thu Sep 17 15:42:57.237524 2026] [security2:error] [pid 60716:tid 60948] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxe4cPsx0SVFjrd6225SgAAADY"]
[Thu Sep 17 15:42:57.247497 2026] [security2:error] [pid 60716:tid 60855] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.git/config.bak"] [unique_id "aqxe4cPsx0SVFjrd6225TwAALV0"]
[Thu Sep 17 15:42:57.289512 2026] [security2:error] [pid 60716:tid 60969] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxe4cPsx0SVFjrd6225XgAAAEs"]
[Thu Sep 17 15:42:57.321693 2026] [security2:error] [pid 60716:tid 60960] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/control-panel/.env"] [unique_id "aqxe4cPsx0SVFjrd6225YQAAAEI"]
[Thu Sep 17 15:42:57.333830 2026] [security2:error] [pid 60716:tid 60972] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxe4cPsx0SVFjrd6225YwAAAE4"]
[Thu Sep 17 15:42:57.355555 2026] [security2:error] [pid 60716:tid 60933] [client 162.241.226.11:51108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxe38Psx0SVFjrd6224bQAAACc"]
[Thu Sep 17 15:42:57.376184 2026] [security2:error] [pid 60716:tid 60905] [client 162.241.226.11:21298] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxe4cPsx0SVFjrd6225XwAAAA0"]
[Thu Sep 17 15:42:57.380848 2026] [security2:error] [pid 60716:tid 61019] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxe4cPsx0SVFjrd6225ZAAAAH0"]
[Thu Sep 17 15:42:57.403152 2026] [security2:error] [pid 60716:tid 60961] [client 103.61.184.148:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe4cPsx0SVFjrd6225ZQAAAEM"]
[Thu Sep 17 15:42:57.403324 2026] [security2:error] [pid 60716:tid 60961] [client 103.61.184.148:52093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe4cPsx0SVFjrd6225ZQAAAEM"]
[Thu Sep 17 15:42:57.412991 2026] [security2:error] [pid 60716:tid 60980] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225NwAAAFY"]
[Thu Sep 17 15:42:57.416533 2026] [security2:error] [pid 60716:tid 60975] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225PQAAAFE"]
[Thu Sep 17 15:42:57.421362 2026] [security2:error] [pid 60716:tid 60929] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225LQAAACQ"]
[Thu Sep 17 15:42:57.426679 2026] [security2:error] [pid 60716:tid 60984] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxe4cPsx0SVFjrd6225hgAAAFo"]
[Thu Sep 17 15:42:57.447138 2026] [core:error] [pid 60716:tid 60994] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:57.447163 2026] [core:error] [pid 60716:tid 60994] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:57.456652 2026] [security2:error] [pid 60716:tid 60993] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225RwAAAGM"]
[Thu Sep 17 15:42:57.458272 2026] [security2:error] [pid 60716:tid 60956] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225PAAAAD4"]
[Thu Sep 17 15:42:57.471384 2026] [security2:error] [pid 60716:tid 60925] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225LgAAACA"]
[Thu Sep 17 15:42:57.472166 2026] [security2:error] [pid 60716:tid 60981] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxe4cPsx0SVFjrd6225jwAAAFc"]
[Thu Sep 17 15:42:57.472967 2026] [security2:error] [pid 60716:tid 60983] [client 143.244.57.92:47778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4cPsx0SVFjrd6225kAAAAFk"]
[Thu Sep 17 15:42:57.490650 2026] [security2:error] [pid 60716:tid 60954] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225SAAAADw"]
[Thu Sep 17 15:42:57.516460 2026] [security2:error] [pid 60716:tid 61021] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxe4cPsx0SVFjrd6225lAAAAH8"]
[Thu Sep 17 15:42:57.525073 2026] [core:error] [pid 60716:tid 60942] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:57.525089 2026] [core:error] [pid 60716:tid 60942] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:57.528491 2026] [security2:error] [pid 60716:tid 60923] [client 34.154.248.240:33778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/public/phpinfo.php"] [unique_id "aqxe4cPsx0SVFjrd6225lgAAAB4"]
[Thu Sep 17 15:42:57.550639 2026] [security2:error] [pid 60716:tid 60926] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/user-panel/.env"] [unique_id "aqxe4cPsx0SVFjrd6225lwAAACE"]
[Thu Sep 17 15:42:57.559704 2026] [security2:error] [pid 60716:tid 60914] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxe4cPsx0SVFjrd6225mQAAABY"]
[Thu Sep 17 15:42:57.602804 2026] [security2:error] [pid 60716:tid 60935] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxe4cPsx0SVFjrd6225pgAAACk"]
[Thu Sep 17 15:42:57.627067 2026] [security2:error] [pid 60716:tid 60771] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.aws/credentials.bak"] [unique_id "aqxe4cPsx0SVFjrd6225rgAALQw"]
[Thu Sep 17 15:42:57.646259 2026] [security2:error] [pid 60716:tid 60946] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxe4cPsx0SVFjrd6225sgAAADQ"]
[Thu Sep 17 15:42:57.691259 2026] [security2:error] [pid 60716:tid 60972] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxe4cPsx0SVFjrd6225uAAAAE4"]
[Thu Sep 17 15:42:57.733440 2026] [security2:error] [pid 60716:tid 60949] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxe4cPsx0SVFjrd62253gAAADc"]
[Thu Sep 17 15:42:57.750965 2026] [security2:error] [pid 60716:tid 60907] [client 143.244.57.92:47794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4cPsx0SVFjrd62254AAAAA8"]
[Thu Sep 17 15:42:57.772051 2026] [security2:error] [pid 60716:tid 60928] [client 74.7.227.51:57012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225oQAAIw4"], referer: https://bigsisterteams.com/author/admin/
[Thu Sep 17 15:42:57.779575 2026] [security2:error] [pid 60716:tid 60934] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/node/.env"] [unique_id "aqxe4cPsx0SVFjrd62254wAAACg"]
[Thu Sep 17 15:42:57.780972 2026] [security2:error] [pid 60716:tid 60973] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxe4cPsx0SVFjrd62255AAAAE8"]
[Thu Sep 17 15:42:57.825831 2026] [security2:error] [pid 60716:tid 60929] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxe4cPsx0SVFjrd62255wAAACQ"]
[Thu Sep 17 15:42:57.868557 2026] [security2:error] [pid 60716:tid 60976] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxe4cPsx0SVFjrd62258QAAAFI"]
[Thu Sep 17 15:42:57.912114 2026] [security2:error] [pid 60716:tid 60936] [client 148.227.75.216:46502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe4cPsx0SVFjrd62258wAAACo"]
[Thu Sep 17 15:42:57.914026 2026] [security2:error] [pid 60716:tid 60995] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxe4cPsx0SVFjrd62259AAAAGU"]
[Thu Sep 17 15:42:57.916840 2026] [security2:error] [pid 60716:tid 60936] [client 148.227.75.216:46502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe4cPsx0SVFjrd62258wAAACo"]
[Thu Sep 17 15:42:57.959968 2026] [security2:error] [pid 60716:tid 60964] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxe4cPsx0SVFjrd62259QAAAEY"]
[Thu Sep 17 15:42:57.971555 2026] [security2:error] [pid 60716:tid 60944] [client 34.95.193.102:33446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxe4cPsx0SVFjrd62259gAAADI"]
[Thu Sep 17 15:42:58.004386 2026] [security2:error] [pid 60716:tid 60979] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxe4sPsx0SVFjrd6225-gAAAFU"]
[Thu Sep 17 15:42:58.009742 2026] [security2:error] [pid 60716:tid 60988] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/express/.env"] [unique_id "aqxe4sPsx0SVFjrd6225-wAAAF4"]
[Thu Sep 17 15:42:58.046531 2026] [security2:error] [pid 60716:tid 60989] [client 143.244.57.92:47802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4sPsx0SVFjrd6225_AAAAF8"]
[Thu Sep 17 15:42:58.048388 2026] [security2:error] [pid 60716:tid 61010] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxe4sPsx0SVFjrd6225_QAAAHQ"]
[Thu Sep 17 15:42:58.109411 2026] [security2:error] [pid 60716:tid 61020] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxe4sPsx0SVFjrd6226AAAAAH4"]
[Thu Sep 17 15:42:58.152203 2026] [security2:error] [pid 60716:tid 60956] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxe4sPsx0SVFjrd6226AQAAAD4"]
[Thu Sep 17 15:42:58.197407 2026] [security2:error] [pid 60716:tid 60911] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxe4sPsx0SVFjrd6226BAAAABM"]
[Thu Sep 17 15:42:58.237809 2026] [security2:error] [pid 60716:tid 60983] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/next/.env"] [unique_id "aqxe4sPsx0SVFjrd6226CQAAAFk"]
[Thu Sep 17 15:42:58.239095 2026] [security2:error] [pid 60716:tid 60910] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxe4sPsx0SVFjrd6226CgAAABI"]
[Thu Sep 17 15:42:58.265736 2026] [security2:error] [pid 60716:tid 60927] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225PwAAACI"]
[Thu Sep 17 15:42:58.270698 2026] [security2:error] [pid 60716:tid 60992] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225WAAAAGI"]
[Thu Sep 17 15:42:58.272524 2026] [security2:error] [pid 60716:tid 60951] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225SQAAADk"]
[Thu Sep 17 15:42:58.288218 2026] [security2:error] [pid 60716:tid 60919] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225XQAAABs"]
[Thu Sep 17 15:42:58.288730 2026] [security2:error] [pid 60716:tid 60902] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxe4sPsx0SVFjrd6226DAAAAAo"]
[Thu Sep 17 15:42:58.292802 2026] [core:error] [pid 60716:tid 60954] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:58.292824 2026] [core:error] [pid 60716:tid 60954] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:58.301984 2026] [security2:error] [pid 60716:tid 61003] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225WQAAAG0"]
[Thu Sep 17 15:42:58.330041 2026] [security2:error] [pid 60716:tid 60920] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225WgAAABw"]
[Thu Sep 17 15:42:58.331682 2026] [security2:error] [pid 60716:tid 60918] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225WwAAABo"]
[Thu Sep 17 15:42:58.333358 2026] [security2:error] [pid 60716:tid 60971] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxe4sPsx0SVFjrd6226DgAAAE0"]
[Thu Sep 17 15:42:58.335238 2026] [security2:error] [pid 60716:tid 61005] [client 143.244.57.92:47804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4sPsx0SVFjrd6226DwAAAG8"]
[Thu Sep 17 15:42:58.358750 2026] [security2:error] [pid 60716:tid 60974] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225XAAAAFA"]
[Thu Sep 17 15:42:58.376555 2026] [security2:error] [pid 60716:tid 60972] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxe4sPsx0SVFjrd6226EgAAAE4"]
[Thu Sep 17 15:42:58.419361 2026] [security2:error] [pid 60716:tid 60952] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225rAAAADo"]
[Thu Sep 17 15:42:58.421430 2026] [security2:error] [pid 60716:tid 61019] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxe4sPsx0SVFjrd6226FgAAAH0"]
[Thu Sep 17 15:42:58.421521 2026] [security2:error] [pid 60716:tid 60843] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/.ssh/id_rsa"] [unique_id "aqxe4sPsx0SVFjrd6226FQAALVE"]
[Thu Sep 17 15:42:58.427092 2026] [security2:error] [pid 60716:tid 60924] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225kQAAAB8"]
[Thu Sep 17 15:42:58.427293 2026] [security2:error] [pid 60716:tid 60950] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225qQAAADg"]
[Thu Sep 17 15:42:58.428482 2026] [security2:error] [pid 60716:tid 60998] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225qgAAAGg"]
[Thu Sep 17 15:42:58.428580 2026] [security2:error] [pid 60716:tid 60835] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/id_rsa"] [unique_id "aqxe4sPsx0SVFjrd6226GQAALUk"]
[Thu Sep 17 15:42:58.436134 2026] [security2:error] [pid 60716:tid 61011] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225sAAAAHU"]
[Thu Sep 17 15:42:58.447128 2026] [security2:error] [pid 60716:tid 61017] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225rwAAAHs"]
[Thu Sep 17 15:42:58.450009 2026] [security2:error] [pid 60716:tid 60975] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd62255gAAAFE"]
[Thu Sep 17 15:42:58.450188 2026] [security2:error] [pid 60716:tid 60963] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4cPsx0SVFjrd6225sQAAAEU"]
[Thu Sep 17 15:42:58.459340 2026] [security2:error] [pid 60716:tid 60942] [client 34.95.193.102:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxe4sPsx0SVFjrd6226HAAAADA"]
[Thu Sep 17 15:42:58.468552 2026] [security2:error] [pid 60716:tid 60973] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/nuxt/.env"] [unique_id "aqxe4sPsx0SVFjrd6226HwAAAE8"]
[Thu Sep 17 15:42:58.471989 2026] [security2:error] [pid 60716:tid 60937] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxe4sPsx0SVFjrd6226IAAAACs"]
[Thu Sep 17 15:42:58.499812 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.248.240:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/php-info.php"] [unique_id "aqxe4sPsx0SVFjrd6226IgAAACk"]
[Thu Sep 17 15:42:58.514367 2026] [security2:error] [pid 60716:tid 60961] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxe4sPsx0SVFjrd6226JQAAAEM"]
[Thu Sep 17 15:42:58.522754 2026] [security2:error] [pid 60716:tid 60946] [client 128.140.106.114:45196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226IwAAADQ"], referer: https://eris.media
[Thu Sep 17 15:42:58.557972 2026] [security2:error] [pid 60716:tid 60984] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxe4sPsx0SVFjrd6226JwAAAFo"]
[Thu Sep 17 15:42:58.600390 2026] [security2:error] [pid 60716:tid 60947] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxe4sPsx0SVFjrd6226LQAAADU"]
[Thu Sep 17 15:42:58.628358 2026] [security2:error] [pid 60716:tid 61006] [client 143.244.57.92:47812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4sPsx0SVFjrd6226MQAAAHA"]
[Thu Sep 17 15:42:58.651036 2026] [security2:error] [pid 60716:tid 60925] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxe4sPsx0SVFjrd6226MwAAACA"]
[Thu Sep 17 15:42:58.684706 2026] [security2:error] [pid 60716:tid 60979] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226KAAAAFU"]
[Thu Sep 17 15:42:58.689716 2026] [security2:error] [pid 60716:tid 61007] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226KQAAAHE"]
[Thu Sep 17 15:42:58.693865 2026] [security2:error] [pid 60716:tid 60893] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxe4sPsx0SVFjrd6226RQAAAAE"]
[Thu Sep 17 15:42:58.696281 2026] [security2:error] [pid 60716:tid 60919] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/nest/.env"] [unique_id "aqxe4sPsx0SVFjrd6226RgAAABs"]
[Thu Sep 17 15:42:58.737145 2026] [security2:error] [pid 60716:tid 61009] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxe4sPsx0SVFjrd6226SAAAAHM"]
[Thu Sep 17 15:42:58.778349 2026] [security2:error] [pid 60716:tid 61004] [client 169.58.197.251:60110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxe4sPsx0SVFjrd6226UQAAAG4"], referer: binance.com
[Thu Sep 17 15:42:58.781548 2026] [security2:error] [pid 60716:tid 60923] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxe4sPsx0SVFjrd6226UgAAAB4"]
[Thu Sep 17 15:42:58.796114 2026] [security2:error] [pid 60716:tid 61010] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226NAAAAHQ"]
[Thu Sep 17 15:42:58.827050 2026] [security2:error] [pid 60716:tid 60991] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxe4sPsx0SVFjrd6226WwAAAGE"]
[Thu Sep 17 15:42:58.871595 2026] [security2:error] [pid 60716:tid 60932] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxe4sPsx0SVFjrd6226YwAAACY"]
[Thu Sep 17 15:42:58.907597 2026] [security2:error] [pid 60716:tid 60997] [client 143.244.57.92:47828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aqxe4sPsx0SVFjrd6226awAAAGc"]
[Thu Sep 17 15:42:58.913130 2026] [security2:error] [pid 60716:tid 60949] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxe4sPsx0SVFjrd6226bAAAADc"]
[Thu Sep 17 15:42:58.923495 2026] [security2:error] [pid 60716:tid 60907] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/react/.env"] [unique_id "aqxe4sPsx0SVFjrd6226bQAAAA8"]
[Thu Sep 17 15:42:58.944536 2026] [security2:error] [pid 60716:tid 60943] [client 34.95.193.102:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxe4sPsx0SVFjrd6226bgAAADE"]
[Thu Sep 17 15:42:58.956525 2026] [security2:error] [pid 60716:tid 61019] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxe4sPsx0SVFjrd6226bwAAAH0"]
[Thu Sep 17 15:42:58.964275 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.248.240:33810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/phpversion.php"] [unique_id "aqxe4sPsx0SVFjrd6226cQAAAHg"]
[Thu Sep 17 15:42:58.996350 2026] [core:error] [pid 60716:tid 60998] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:58.996364 2026] [core:error] [pid 60716:tid 60998] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:59.001044 2026] [security2:error] [pid 60716:tid 60963] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxe48Psx0SVFjrd6226dwAAAEU"]
[Thu Sep 17 15:42:59.010991 2026] [security2:error] [pid 60716:tid 60761] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/config.php"] [unique_id "aqxe48Psx0SVFjrd6226eAAALQM"]
[Thu Sep 17 15:42:59.042423 2026] [security2:error] [pid 60716:tid 60934] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxe48Psx0SVFjrd6226eQAAACg"]
[Thu Sep 17 15:42:59.084078 2026] [security2:error] [pid 60716:tid 60937] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxe48Psx0SVFjrd6226egAAACs"]
[Thu Sep 17 15:42:59.131795 2026] [security2:error] [pid 60716:tid 60899] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxe48Psx0SVFjrd6226fgAAAAc"]
[Thu Sep 17 15:42:59.151140 2026] [security2:error] [pid 60716:tid 60965] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/vue/.env"] [unique_id "aqxe48Psx0SVFjrd6226gwAAAEc"]
[Thu Sep 17 15:42:59.179376 2026] [security2:error] [pid 60716:tid 60892] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxe48Psx0SVFjrd6226hwAAAAA"]
[Thu Sep 17 15:42:59.180492 2026] [security2:error] [pid 60716:tid 60976] [client 143.244.57.92:47834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aqxe48Psx0SVFjrd6226iQAAAFI"]
[Thu Sep 17 15:42:59.192973 2026] [security2:error] [pid 60716:tid 60952] [client 14.96.156.146:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe48Psx0SVFjrd6226iAAAADo"]
[Thu Sep 17 15:42:59.193158 2026] [security2:error] [pid 60716:tid 60952] [client 14.96.156.146:50408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe48Psx0SVFjrd6226iAAAADo"]
[Thu Sep 17 15:42:59.224246 2026] [security2:error] [pid 60716:tid 60944] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxe48Psx0SVFjrd6226jQAAADI"]
[Thu Sep 17 15:42:59.268163 2026] [security2:error] [pid 60716:tid 60905] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxe48Psx0SVFjrd6226jwAAAA0"]
[Thu Sep 17 15:42:59.314877 2026] [security2:error] [pid 60716:tid 60988] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxe48Psx0SVFjrd6226kAAAAF4"]
[Thu Sep 17 15:42:59.328877 2026] [security2:error] [pid 60716:tid 60897] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226TAAAAAU"]
[Thu Sep 17 15:42:59.345163 2026] [security2:error] [pid 60716:tid 60996] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226TQAAAGY"]
[Thu Sep 17 15:42:59.348385 2026] [security2:error] [pid 60716:tid 60966] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226TgAAAEg"]
[Thu Sep 17 15:42:59.380452 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/angular/.env"] [unique_id "aqxe48Psx0SVFjrd6226lAAAACw"]
[Thu Sep 17 15:42:59.411488 2026] [security2:error] [pid 60716:tid 61020] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxe48Psx0SVFjrd6226kQAAAH4"]
[Thu Sep 17 15:42:59.422460 2026] [security2:error] [pid 60716:tid 60918] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226WAAAABo"]
[Thu Sep 17 15:42:59.425557 2026] [security2:error] [pid 60716:tid 60953] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226XQAAADs"]
[Thu Sep 17 15:42:59.425972 2026] [security2:error] [pid 60716:tid 60904] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226XAAAAAw"]
[Thu Sep 17 15:42:59.428901 2026] [security2:error] [pid 60716:tid 60912] [client 34.95.193.102:33470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxe48Psx0SVFjrd6226lgAAABQ"]
[Thu Sep 17 15:42:59.436830 2026] [security2:error] [pid 60716:tid 60983] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226YAAAAFk"]
[Thu Sep 17 15:42:59.450042 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.248.240:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/_phpinfo.php"] [unique_id "aqxe48Psx0SVFjrd6226lwAAAF0"]
[Thu Sep 17 15:42:59.456130 2026] [security2:error] [pid 60716:tid 60911] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxe48Psx0SVFjrd6226mAAAABM"]
[Thu Sep 17 15:42:59.471216 2026] [security2:error] [pid 60716:tid 61016] [client 143.244.57.92:47842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aqxe48Psx0SVFjrd6226mwAAAHo"]
[Thu Sep 17 15:42:59.500604 2026] [security2:error] [pid 60716:tid 60902] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxe48Psx0SVFjrd6226oQAAAAo"]
[Thu Sep 17 15:42:59.550353 2026] [security2:error] [pid 60716:tid 60982] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxe48Psx0SVFjrd6226pgAAAFg"]
[Thu Sep 17 15:42:59.590211 2026] [security2:error] [pid 60716:tid 60954] [client 127.0.0.1:30260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxe48Psx0SVFjrd6226pwAAADw"]
[Thu Sep 17 15:42:59.590396 2026] [security2:error] [pid 60716:tid 61009] [client 74.7.244.1:45458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.oiy.ojz.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxe48Psx0SVFjrd6226pQAAc1c"]
[Thu Sep 17 15:42:59.595266 2026] [security2:error] [pid 60716:tid 60771] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/config/aws.php"] [unique_id "aqxe48Psx0SVFjrd6226rgAALQw"]
[Thu Sep 17 15:42:59.611087 2026] [security2:error] [pid 60716:tid 60903] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/svelte/.env"] [unique_id "aqxe48Psx0SVFjrd6226tQAAAAs"]
[Thu Sep 17 15:42:59.700449 2026] [core:error] [pid 60716:tid 60934] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:59.700467 2026] [core:error] [pid 60716:tid 60934] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:42:59.730773 2026] [security2:error] [pid 60716:tid 60788] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/config/stripe.php"] [unique_id "aqxe48Psx0SVFjrd6226xgAALRo"]
[Thu Sep 17 15:42:59.731639 2026] [security2:error] [pid 60716:tid 60799] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/config/mail.php"] [unique_id "aqxe48Psx0SVFjrd6226yAAALSU"]
[Thu Sep 17 15:42:59.746427 2026] [security2:error] [pid 60716:tid 60892] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxe48Psx0SVFjrd6226ygAAAAA"]
[Thu Sep 17 15:42:59.751060 2026] [security2:error] [pid 60716:tid 60952] [client 143.244.57.92:47846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aqxe48Psx0SVFjrd6226zAAAADo"]
[Thu Sep 17 15:42:59.790111 2026] [security2:error] [pid 60716:tid 60900] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxe48Psx0SVFjrd6226zwAAAAg"]
[Thu Sep 17 15:42:59.833585 2026] [security2:error] [pid 60716:tid 60901] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxe48Psx0SVFjrd62260AAAAAk"]
[Thu Sep 17 15:42:59.841189 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/vite/.env"] [unique_id "aqxe48Psx0SVFjrd62260QAAAA0"]
[Thu Sep 17 15:42:59.868152 2026] [security2:error] [pid 60716:tid 60796] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/config/config.inc.php"] [unique_id "aqxe48Psx0SVFjrd62260gAALSI"]
[Thu Sep 17 15:42:59.882352 2026] [security2:error] [pid 60716:tid 60946] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxe48Psx0SVFjrd62261QAAADQ"]
[Thu Sep 17 15:42:59.907818 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.248.240:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/old_phpinfo.php"] [unique_id "aqxe48Psx0SVFjrd62261wAAAD0"]
[Thu Sep 17 15:42:59.909148 2026] [security2:error] [pid 60716:tid 60986] [client 136.158.61.34:45098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe48Psx0SVFjrd62262AAAAFw"]
[Thu Sep 17 15:42:59.909243 2026] [security2:error] [pid 60716:tid 60986] [client 136.158.61.34:45098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe48Psx0SVFjrd62262AAAAFw"]
[Thu Sep 17 15:42:59.919788 2026] [security2:error] [pid 60716:tid 60964] [client 34.95.193.102:33472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxe48Psx0SVFjrd62262QAAAEY"]
[Thu Sep 17 15:42:59.924623 2026] [security2:error] [pid 60716:tid 60897] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxe48Psx0SVFjrd62262gAAAAU"]
[Thu Sep 17 15:42:59.975039 2026] [security2:error] [pid 60716:tid 61011] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxe48Psx0SVFjrd62263QAAAHU"]
[Thu Sep 17 15:42:59.981790 2026] [security2:error] [pid 60716:tid 60936] [client 162.241.226.11:21320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226jAAAACo"]
[Thu Sep 17 15:43:00.002860 2026] [security2:error] [pid 60716:tid 60775] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/config/nexmo.php"] [unique_id "aqxe5MPsx0SVFjrd62264QAALQ8"]
[Thu Sep 17 15:43:00.023166 2026] [security2:error] [pid 60716:tid 61015] [client 35.224.218.165:40136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxe5MPsx0SVFjrd62264gAAAHk"]
[Thu Sep 17 15:43:00.043568 2026] [security2:error] [pid 60716:tid 60916] [client 143.244.57.92:33510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aqxe5MPsx0SVFjrd62265AAAABg"]
[Thu Sep 17 15:43:00.070875 2026] [security2:error] [pid 60716:tid 60956] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "aqxe5MPsx0SVFjrd62265QAAAD4"]
[Thu Sep 17 15:43:00.157000 2026] [security2:error] [pid 60716:tid 60917] [client 162.241.226.11:21332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd62264AAAABk"]
[Thu Sep 17 15:43:00.164554 2026] [security2:error] [pid 60716:tid 60999] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxe5MPsx0SVFjrd62267QAAAGk"]
[Thu Sep 17 15:43:00.213266 2026] [security2:error] [pid 60716:tid 61004] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxe5MPsx0SVFjrd62268QAAAG4"]
[Thu Sep 17 15:43:00.258733 2026] [security2:error] [pid 60716:tid 60978] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226XgAAAFQ"]
[Thu Sep 17 15:43:00.264054 2026] [security2:error] [pid 60716:tid 60915] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxe5MPsx0SVFjrd62268gAAABc"]
[Thu Sep 17 15:43:00.261160 2026] [security2:error] [pid 60716:tid 60980] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226hAAAAFY"]
[Thu Sep 17 15:43:00.266412 2026] [security2:error] [pid 60716:tid 60929] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226igAAACQ"]
[Thu Sep 17 15:43:00.270226 2026] [security2:error] [pid 60716:tid 60981] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226XwAAAFc"]
[Thu Sep 17 15:43:00.272738 2026] [security2:error] [pid 60716:tid 60972] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226agAAAE4"]
[Thu Sep 17 15:43:00.279069 2026] [security2:error] [pid 60716:tid 61005] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226YQAAAG8"]
[Thu Sep 17 15:43:00.294189 2026] [security2:error] [pid 60716:tid 61001] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226aQAAAGs"]
[Thu Sep 17 15:43:00.304079 2026] [security2:error] [pid 60716:tid 60974] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe4sPsx0SVFjrd6226YgAAAFA"]
[Thu Sep 17 15:43:00.311342 2026] [security2:error] [pid 60716:tid 61021] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/backups/.env"] [unique_id "aqxe5MPsx0SVFjrd62268wAAAH8"]
[Thu Sep 17 15:43:00.324084 2026] [security2:error] [pid 60716:tid 61019] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxe5MPsx0SVFjrd62269AAAAH0"]
[Thu Sep 17 15:43:00.324185 2026] [security2:error] [pid 60716:tid 60909] [client 143.244.57.92:33522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "chiext.net"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aqxe5MPsx0SVFjrd62269QAAABE"]
[Thu Sep 17 15:43:00.374009 2026] [security2:error] [pid 60716:tid 60998] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxe5MPsx0SVFjrd62269gAAAGg"]
[Thu Sep 17 15:43:00.379163 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.248.240:39878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/server-info.php"] [unique_id "aqxe5MPsx0SVFjrd6226-AAAADw"]
[Thu Sep 17 15:43:00.385050 2026] [security2:error] [pid 60716:tid 60993] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226lQAAAGM"]
[Thu Sep 17 15:43:00.407889 2026] [security2:error] [pid 60716:tid 60957] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226owAAAD8"]
[Thu Sep 17 15:43:00.407896 2026] [security2:error] [pid 60716:tid 60928] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226tgAAACM"]
[Thu Sep 17 15:43:00.408968 2026] [security2:error] [pid 60716:tid 60770] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/wp-config.php"] [unique_id "aqxe5MPsx0SVFjrd6226_gAALQs"]
[Thu Sep 17 15:43:00.409303 2026] [security2:error] [pid 60716:tid 60870] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.org"] [uri "/wp-config.php.bak"] [unique_id "aqxe5MPsx0SVFjrd6227AAAALWw"]
[Thu Sep 17 15:43:00.410430 2026] [security2:error] [pid 60716:tid 60933] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226pAAAACc"]
[Thu Sep 17 15:43:00.411872 2026] [security2:error] [pid 60716:tid 60818] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.org"] [uri "/wp-config.php.old"] [unique_id "aqxe5MPsx0SVFjrd6227AQAALTg"]
[Thu Sep 17 15:43:00.412075 2026] [security2:error] [pid 60716:tid 60898] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226ogAAAAY"]
[Thu Sep 17 15:43:00.416487 2026] [security2:error] [pid 60716:tid 60906] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226twAAAA4"]
[Thu Sep 17 15:43:00.420564 2026] [security2:error] [pid 60716:tid 60914] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd62267AAAABY"]
[Thu Sep 17 15:43:00.420815 2026] [security2:error] [pid 60716:tid 60965] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxe5MPsx0SVFjrd6227AwAAAEc"]
[Thu Sep 17 15:43:00.430556 2026] [security2:error] [pid 60716:tid 60985] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226ugAAAFs"]
[Thu Sep 17 15:43:00.430869 2026] [security2:error] [pid 60716:tid 61002] [client 34.95.193.102:33476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxe5MPsx0SVFjrd6227BAAAAGw"]
[Thu Sep 17 15:43:00.434322 2026] [security2:error] [pid 60716:tid 60805] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "navishiur.org"] [uri "/wp-config.php.new"] [unique_id "aqxe5MPsx0SVFjrd6227BgAALSs"]
[Thu Sep 17 15:43:00.436600 2026] [core:error] [pid 60716:tid 60901] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:00.436612 2026] [core:error] [pid 60716:tid 60901] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:00.446702 2026] [security2:error] [pid 60716:tid 60976] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd6226ywAAAFI"]
[Thu Sep 17 15:43:00.449802 2026] [security2:error] [pid 60716:tid 60988] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe48Psx0SVFjrd62261gAAAF4"]
[Thu Sep 17 15:43:00.454964 2026] [security2:error] [pid 60716:tid 60810] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/.wp-config.php.swp"] [unique_id "aqxe5MPsx0SVFjrd6227CAAALTA"]
[Thu Sep 17 15:43:00.464496 2026] [security2:error] [pid 60716:tid 60990] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxe5MPsx0SVFjrd6227CQAAAGA"]
[Thu Sep 17 15:43:00.515854 2026] [security2:error] [pid 60716:tid 60984] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxe5MPsx0SVFjrd6227CwAAAFo"]
[Thu Sep 17 15:43:00.540351 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "aqxe5MPsx0SVFjrd6227DgAAACw"]
[Thu Sep 17 15:43:00.545303 2026] [security2:error] [pid 60716:tid 60824] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/wp-content/mysql.sql"] [unique_id "aqxe5MPsx0SVFjrd6227EAAALT4"]
[Thu Sep 17 15:43:00.561219 2026] [security2:error] [pid 60716:tid 61020] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxe5MPsx0SVFjrd6227EgAAAH4"]
[Thu Sep 17 15:43:00.564144 2026] [security2:error] [pid 60716:tid 60905] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227BwAAAA0"]
[Thu Sep 17 15:43:00.606051 2026] [security2:error] [pid 60716:tid 60910] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxe5MPsx0SVFjrd6227HQAAABI"]
[Thu Sep 17 15:43:00.610114 2026] [security2:error] [pid 60716:tid 60803] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/terraform.tfstate.backup"] [unique_id "aqxe5MPsx0SVFjrd6227HwAALSk"]
[Thu Sep 17 15:43:00.655093 2026] [security2:error] [pid 60716:tid 60999] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxe5MPsx0SVFjrd6227IAAAAGk"]
[Thu Sep 17 15:43:00.689370 2026] [security2:error] [pid 60716:tid 60939] [client 35.205.88.64:58444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227DwAALRI"]
[Thu Sep 17 15:43:00.700969 2026] [security2:error] [pid 60716:tid 60951] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxe5MPsx0SVFjrd6227KAAAADk"]
[Thu Sep 17 15:43:00.745102 2026] [security2:error] [pid 60716:tid 61008] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227HgAAAHI"]
[Thu Sep 17 15:43:00.745622 2026] [security2:error] [pid 60716:tid 60917] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227HAAAABk"]
[Thu Sep 17 15:43:00.748310 2026] [security2:error] [pid 60716:tid 60903] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxe5MPsx0SVFjrd6227PQAAAAs"]
[Thu Sep 17 15:43:00.776487 2026] [security2:error] [pid 60716:tid 60970] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/tmp/.env"] [unique_id "aqxe5MPsx0SVFjrd6227QQAAAEw"]
[Thu Sep 17 15:43:00.800494 2026] [security2:error] [pid 60716:tid 60959] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxe5MPsx0SVFjrd6227QgAAAEE"]
[Thu Sep 17 15:43:00.801695 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/.env"] [unique_id "aqxe5MPsx0SVFjrd6227QwAAACU"]
[Thu Sep 17 15:43:00.844179 2026] [security2:error] [pid 60716:tid 61013] [client 34.154.248.240:39886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/server-status.php"] [unique_id "aqxe5MPsx0SVFjrd6227SwAAAHc"]
[Thu Sep 17 15:43:00.857037 2026] [security2:error] [pid 60716:tid 61014] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxe5MPsx0SVFjrd6227TQAAAHg"]
[Thu Sep 17 15:43:00.905826 2026] [security2:error] [pid 60716:tid 60998] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxe5MPsx0SVFjrd6227VwAAAGg"]
[Thu Sep 17 15:43:00.926958 2026] [security2:error] [pid 60716:tid 60972] [client 34.95.193.102:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxe5MPsx0SVFjrd6227WAAAAE4"]
[Thu Sep 17 15:43:00.948279 2026] [security2:error] [pid 60716:tid 60935] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxe5MPsx0SVFjrd6227XAAAACk"]
[Thu Sep 17 15:43:01.002677 2026] [security2:error] [pid 60716:tid 60898] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxe5cPsx0SVFjrd6227YQAAAAY"]
[Thu Sep 17 15:43:01.005170 2026] [security2:error] [pid 60716:tid 60906] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/temp/.env"] [unique_id "aqxe5cPsx0SVFjrd6227YwAAAA4"]
[Thu Sep 17 15:43:01.010923 2026] [security2:error] [pid 60716:tid 61012] [client 177.44.133.72:61683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe5cPsx0SVFjrd6227ZAAAAHY"]
[Thu Sep 17 15:43:01.011004 2026] [security2:error] [pid 60716:tid 61012] [client 177.44.133.72:61683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe5cPsx0SVFjrd6227ZAAAAHY"]
[Thu Sep 17 15:43:01.045602 2026] [security2:error] [pid 60716:tid 60914] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxe5cPsx0SVFjrd6227ZQAAABY"]
[Thu Sep 17 15:43:01.090190 2026] [security2:error] [pid 60716:tid 60919] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxe5cPsx0SVFjrd6227aAAAABs"]
[Thu Sep 17 15:43:01.135090 2026] [security2:error] [pid 60716:tid 61002] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxe5cPsx0SVFjrd6227bwAAAGw"]
[Thu Sep 17 15:43:01.145595 2026] [security2:error] [pid 60716:tid 60982] [client 34.166.220.229:53808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "aqxe5cPsx0SVFjrd6227cQAAAFg"]
[Thu Sep 17 15:43:01.190039 2026] [security2:error] [pid 60716:tid 60955] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxe5cPsx0SVFjrd6227dwAAAD0"]
[Thu Sep 17 15:43:01.234057 2026] [security2:error] [pid 60716:tid 60897] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/lab/.env"] [unique_id "aqxe5cPsx0SVFjrd6227ewAAAAU"]
[Thu Sep 17 15:43:01.237122 2026] [security2:error] [pid 60716:tid 60976] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxe5cPsx0SVFjrd6227fAAAAFI"]
[Thu Sep 17 15:43:01.287518 2026] [security2:error] [pid 60716:tid 61011] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxe5cPsx0SVFjrd6227fgAAAHU"]
[Thu Sep 17 15:43:01.335364 2026] [security2:error] [pid 60716:tid 60899] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxe5cPsx0SVFjrd6227hAAAAAc"]
[Thu Sep 17 15:43:01.373400 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.220.229:53808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "aqxe5cPsx0SVFjrd6227iAAAAA0"]
[Thu Sep 17 15:43:01.381148 2026] [security2:error] [pid 60716:tid 60956] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxe5cPsx0SVFjrd6227iQAAAD4"]
[Thu Sep 17 15:43:01.417451 2026] [security2:error] [pid 60716:tid 60968] [client 34.95.193.102:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/phpinfo.php.old"] [unique_id "aqxe5cPsx0SVFjrd6227igAAAEo"]
[Thu Sep 17 15:43:01.420186 2026] [security2:error] [pid 60716:tid 60978] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227MgAAAFQ"]
[Thu Sep 17 15:43:01.427523 2026] [security2:error] [pid 60716:tid 60910] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxe5cPsx0SVFjrd6227iwAAABI"]
[Thu Sep 17 15:43:01.439469 2026] [security2:error] [pid 60716:tid 60915] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227NAAAABc"]
[Thu Sep 17 15:43:01.457739 2026] [security2:error] [pid 60716:tid 60980] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227OAAAAFY"]
[Thu Sep 17 15:43:01.465843 2026] [security2:error] [pid 60716:tid 60999] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/cronlab/.env"] [unique_id "aqxe5cPsx0SVFjrd6227jAAAAGk"]
[Thu Sep 17 15:43:01.478368 2026] [security2:error] [pid 60716:tid 61016] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxe5cPsx0SVFjrd6227jQAAAHo"]
[Thu Sep 17 15:43:01.481115 2026] [security2:error] [pid 60716:tid 60954] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227WQAAADw"]
[Thu Sep 17 15:43:01.483088 2026] [security2:error] [pid 60716:tid 60985] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227bgAAAFs"]
[Thu Sep 17 15:43:01.486967 2026] [security2:error] [pid 60716:tid 61021] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227VAAAAH8"]
[Thu Sep 17 15:43:01.490250 2026] [security2:error] [pid 60716:tid 60997] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227SAAAAGc"]
[Thu Sep 17 15:43:01.502364 2026] [security2:error] [pid 60716:tid 60913] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227OgAAABU"]
[Thu Sep 17 15:43:01.526333 2026] [security2:error] [pid 60716:tid 61005] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxe5cPsx0SVFjrd6227kAAAAG8"]
[Thu Sep 17 15:43:01.529571 2026] [security2:error] [pid 60716:tid 61005] [client 40.81.232.68:64461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "aqxe5cPsx0SVFjrd6227kQAAAG8"], referer: binance.com
[Thu Sep 17 15:43:01.572108 2026] [security2:error] [pid 60716:tid 60894] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxe5cPsx0SVFjrd6227kgAAAAI"]
[Thu Sep 17 15:43:01.617279 2026] [security2:error] [pid 60716:tid 60942] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxe5cPsx0SVFjrd6227mAAAADA"]
[Thu Sep 17 15:43:01.640955 2026] [core:error] [pid 60716:tid 60949] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:01.640974 2026] [core:error] [pid 60716:tid 60949] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:01.664199 2026] [security2:error] [pid 60716:tid 60973] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxe5cPsx0SVFjrd6227mwAAAE8"]
[Thu Sep 17 15:43:01.694885 2026] [security2:error] [pid 60716:tid 60993] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/cron/.env"] [unique_id "aqxe5cPsx0SVFjrd6227ngAAAGM"]
[Thu Sep 17 15:43:01.707164 2026] [security2:error] [pid 60716:tid 61007] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxe5cPsx0SVFjrd6227oQAAAHE"]
[Thu Sep 17 15:43:01.754702 2026] [security2:error] [pid 60716:tid 60901] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxe5cPsx0SVFjrd6227ogAAAAk"]
[Thu Sep 17 15:43:01.798733 2026] [security2:error] [pid 60716:tid 60924] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxe5cPsx0SVFjrd6227owAAAB8"]
[Thu Sep 17 15:43:01.846670 2026] [security2:error] [pid 60716:tid 60990] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxe5cPsx0SVFjrd6227tgAAAGA"]
[Thu Sep 17 15:43:01.888421 2026] [security2:error] [pid 60716:tid 60978] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxe5cPsx0SVFjrd6227wwAAAFQ"]
[Thu Sep 17 15:43:01.904049 2026] [security2:error] [pid 60716:tid 60967] [client 34.95.193.102:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/phpinfo.php~"] [unique_id "aqxe5cPsx0SVFjrd6227xgAAAEk"]
[Thu Sep 17 15:43:01.923150 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/en/.env"] [unique_id "aqxe5cPsx0SVFjrd6227yQAAAFY"]
[Thu Sep 17 15:43:01.931851 2026] [security2:error] [pid 60716:tid 60999] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxe5cPsx0SVFjrd6227ygAAAGk"]
[Thu Sep 17 15:43:01.973951 2026] [security2:error] [pid 60716:tid 60951] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxe5cPsx0SVFjrd6227zQAAADk"]
[Thu Sep 17 15:43:02.022799 2026] [security2:error] [pid 60716:tid 60903] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxe5sPsx0SVFjrd62270gAAAAs"]
[Thu Sep 17 15:43:02.062493 2026] [security2:error] [pid 60716:tid 60912] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227xwAAABQ"]
[Thu Sep 17 15:43:02.066777 2026] [security2:error] [pid 60716:tid 60962] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxe5sPsx0SVFjrd62271QAAAEQ"]
[Thu Sep 17 15:43:02.115666 2026] [security2:error] [pid 60716:tid 60902] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxe5sPsx0SVFjrd62272gAAAAo"]
[Thu Sep 17 15:43:02.160213 2026] [security2:error] [pid 60716:tid 60918] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxe5sPsx0SVFjrd62273wAAABo"]
[Thu Sep 17 15:43:02.185620 2026] [security2:error] [pid 60716:tid 61002] [client 143.105.152.240:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe5sPsx0SVFjrd62274QAAAGw"]
[Thu Sep 17 15:43:02.189399 2026] [security2:error] [pid 60716:tid 61002] [client 143.105.152.240:52838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe5sPsx0SVFjrd62274QAAAGw"]
[Thu Sep 17 15:43:02.203950 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxe5sPsx0SVFjrd62274gAAAEM"]
[Thu Sep 17 15:43:02.208218 2026] [security2:error] [pid 60716:tid 61014] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxe5sPsx0SVFjrd62274wAAAHg"]
[Thu Sep 17 15:43:02.208817 2026] [security2:error] [pid 60716:tid 61013] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/administrator/.env"] [unique_id "aqxe5sPsx0SVFjrd62273AAAAHc"]
[Thu Sep 17 15:43:02.254617 2026] [security2:error] [pid 60716:tid 60998] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxe5sPsx0SVFjrd62275QAAAGg"]
[Thu Sep 17 15:43:02.284719 2026] [security2:error] [pid 60716:tid 60929] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227QAAAACQ"]
[Thu Sep 17 15:43:02.307094 2026] [security2:error] [pid 60716:tid 60969] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxe5sPsx0SVFjrd62275wAAAEs"]
[Thu Sep 17 15:43:02.309359 2026] [security2:error] [pid 60716:tid 60909] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227UgAAABE"]
[Thu Sep 17 15:43:02.324067 2026] [security2:error] [pid 60716:tid 61000] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227RQAAAGo"]
[Thu Sep 17 15:43:02.337245 2026] [security2:error] [pid 60716:tid 60977] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227YAAAAFM"]
[Thu Sep 17 15:43:02.340477 2026] [security2:error] [pid 60716:tid 60950] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227TAAAADg"]
[Thu Sep 17 15:43:02.341689 2026] [security2:error] [pid 60716:tid 61019] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5MPsx0SVFjrd6227UwAAAH0"]
[Thu Sep 17 15:43:02.359067 2026] [security2:error] [pid 60716:tid 60919] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxe5sPsx0SVFjrd62276gAAABs"]
[Thu Sep 17 15:43:02.364454 2026] [security2:error] [pid 60716:tid 61012] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxe5sPsx0SVFjrd62276wAAAHY"]
[Thu Sep 17 15:43:02.380964 2026] [security2:error] [pid 60716:tid 60989] [client 34.154.248.240:39918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxe5sPsx0SVFjrd62277QAAAF8"]
[Thu Sep 17 15:43:02.383554 2026] [core:error] [pid 60716:tid 60965] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:02.383575 2026] [core:error] [pid 60716:tid 60965] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:02.400014 2026] [security2:error] [pid 60716:tid 60963] [client 34.95.193.102:33512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/info.php.bak"] [unique_id "aqxe5sPsx0SVFjrd62277gAAAEU"]
[Thu Sep 17 15:43:02.407019 2026] [security2:error] [pid 60716:tid 61007] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxe5sPsx0SVFjrd62277wAAAHE"]
[Thu Sep 17 15:43:02.422743 2026] [security2:error] [pid 60716:tid 60938] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227hwAAACw"]
[Thu Sep 17 15:43:02.435463 2026] [security2:error] [pid 60716:tid 60945] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227vgAAADM"]
[Thu Sep 17 15:43:02.439487 2026] [security2:error] [pid 60716:tid 60986] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/psnlink/.env"] [unique_id "aqxe5sPsx0SVFjrd62278wAAAFw"]
[Thu Sep 17 15:43:02.439862 2026] [security2:error] [pid 60716:tid 60916] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227uAAAABg"]
[Thu Sep 17 15:43:02.447918 2026] [security2:error] [pid 60716:tid 60937] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227vwAAACs"]
[Thu Sep 17 15:43:02.452965 2026] [security2:error] [pid 60716:tid 60988] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxe5sPsx0SVFjrd62279gAAAF4"]
[Thu Sep 17 15:43:02.458139 2026] [security2:error] [pid 60716:tid 60956] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227vAAAAD4"]
[Thu Sep 17 15:43:02.461517 2026] [security2:error] [pid 60716:tid 61020] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227uwAAAH4"]
[Thu Sep 17 15:43:02.465309 2026] [security2:error] [pid 60716:tid 61004] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd62272wAAAG4"]
[Thu Sep 17 15:43:02.465450 2026] [security2:error] [pid 60716:tid 60905] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227ugAAAA0"]
[Thu Sep 17 15:43:02.467046 2026] [security2:error] [pid 60716:tid 60907] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227vQAAAA8"]
[Thu Sep 17 15:43:02.469447 2026] [security2:error] [pid 60716:tid 60926] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5cPsx0SVFjrd6227uQAAACE"]
[Thu Sep 17 15:43:02.496732 2026] [security2:error] [pid 60716:tid 60908] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxe5sPsx0SVFjrd6228AwAAABA"]
[Thu Sep 17 15:43:02.542186 2026] [security2:error] [pid 60716:tid 60912] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxe5sPsx0SVFjrd6228CQAAABQ"]
[Thu Sep 17 15:43:02.584204 2026] [security2:error] [pid 60716:tid 60845] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228EgAALVM"]
[Thu Sep 17 15:43:02.586929 2026] [security2:error] [pid 60716:tid 60931] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxe5sPsx0SVFjrd6228FAAAACU"]
[Thu Sep 17 15:43:02.603359 2026] [security2:error] [pid 60716:tid 60885] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/info.php"] [unique_id "aqxe5sPsx0SVFjrd6228FgAALXs"]
[Thu Sep 17 15:43:02.607929 2026] [security2:error] [pid 60716:tid 60857] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/infos.php"] [unique_id "aqxe5sPsx0SVFjrd6228GQAALV8"]
[Thu Sep 17 15:43:02.607953 2026] [security2:error] [pid 60716:tid 60783] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/php_info.php"] [unique_id "aqxe5sPsx0SVFjrd6228GgAALRY"]
[Thu Sep 17 15:43:02.608519 2026] [security2:error] [pid 60716:tid 60878] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/php.php"] [unique_id "aqxe5sPsx0SVFjrd6228GwAALXQ"]
[Thu Sep 17 15:43:02.612465 2026] [security2:error] [pid 60716:tid 60780] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/php-info.php"] [unique_id "aqxe5sPsx0SVFjrd6228HAAALRM"]
[Thu Sep 17 15:43:02.614751 2026] [security2:error] [pid 60716:tid 60880] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/infophp.php"] [unique_id "aqxe5sPsx0SVFjrd6228HQAALXY"]
[Thu Sep 17 15:43:02.633622 2026] [security2:error] [pid 60716:tid 60961] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxe5sPsx0SVFjrd6228IAAAAEM"]
[Thu Sep 17 15:43:02.635442 2026] [security2:error] [pid 60716:tid 61014] [client 162.241.226.11:37736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/tortuero2.plt"] [unique_id "aqxe5sPsx0SVFjrd6228HgAAAGQ"]
[Thu Sep 17 15:43:02.670097 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/exapi/.env"] [unique_id "aqxe5sPsx0SVFjrd6228JwAAACQ"]
[Thu Sep 17 15:43:02.679524 2026] [security2:error] [pid 60716:tid 60998] [client 162.241.226.11:37750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/tortuero2.plt"] [unique_id "aqxe5sPsx0SVFjrd6228LQAAAGg"]
[Thu Sep 17 15:43:02.683603 2026] [security2:error] [pid 60716:tid 60925] [client 35.224.218.165:52668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxe5sPsx0SVFjrd6228LgAAACA"]
[Thu Sep 17 15:43:02.730791 2026] [security2:error] [pid 60716:tid 60969] [client 162.241.226.11:37752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/perfil_tortuero2.png"] [unique_id "aqxe5sPsx0SVFjrd6228MgAAAEs"]
[Thu Sep 17 15:43:02.735574 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxe5sPsx0SVFjrd6228MwAAACk"]
[Thu Sep 17 15:43:02.738952 2026] [security2:error] [pid 60716:tid 60972] [client 35.224.218.165:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228MQAAAE4"]
[Thu Sep 17 15:43:02.745311 2026] [security2:error] [pid 60716:tid 60788] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228NAAALRo"]
[Thu Sep 17 15:43:02.749190 2026] [security2:error] [pid 60716:tid 60806] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/admin_phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228NwAALSw"]
[Thu Sep 17 15:43:02.749228 2026] [security2:error] [pid 60716:tid 60799] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228NgAALSU"]
[Thu Sep 17 15:43:02.749250 2026] [security2:error] [pid 60716:tid 60804] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/api/phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228NQAALSo"]
[Thu Sep 17 15:43:02.752958 2026] [security2:error] [pid 60716:tid 60796] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/public/phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228OQAALSI"]
[Thu Sep 17 15:43:02.786129 2026] [security2:error] [pid 60716:tid 61002] [client 74.7.227.51:57012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228HwAAbA0"], referer: https://bigsisterteams.com/author/cassy/
[Thu Sep 17 15:43:02.848116 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.248.240:39930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxe5sPsx0SVFjrd6228QQAAADI"]
[Thu Sep 17 15:43:02.879182 2026] [security2:error] [pid 60716:tid 60893] [client 35.224.218.165:52672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/info.php"] [unique_id "aqxe5sPsx0SVFjrd6228QgAAAAE"]
[Thu Sep 17 15:43:02.890181 2026] [security2:error] [pid 60716:tid 60909] [client 34.95.193.102:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/phpinfo.php.save"] [unique_id "aqxe5sPsx0SVFjrd6228TQAAABE"]
[Thu Sep 17 15:43:02.899420 2026] [security2:error] [pid 60716:tid 60927] [client 34.166.135.226:44422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/sitemaps/.env"] [unique_id "aqxe5sPsx0SVFjrd6228UAAAACI"]
[Thu Sep 17 15:43:03.015840 2026] [security2:error] [pid 60716:tid 60984] [client 35.224.218.165:52684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/php.php"] [unique_id "aqxe58Psx0SVFjrd6228VgAAAFo"]
[Thu Sep 17 15:43:03.107419 2026] [core:error] [pid 60716:tid 60923] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:03.107442 2026] [core:error] [pid 60716:tid 60923] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:03.156285 2026] [security2:error] [pid 60716:tid 60986] [client 35.224.218.165:52690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/i.php"] [unique_id "aqxe58Psx0SVFjrd6228YAAAAFw"]
[Thu Sep 17 15:43:03.158417 2026] [core:error] [pid 60716:tid 60937] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:03.158436 2026] [core:error] [pid 60716:tid 60937] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:03.282415 2026] [security2:error] [pid 60716:tid 60991] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd62279QAAAGE"]
[Thu Sep 17 15:43:03.302364 2026] [security2:error] [pid 60716:tid 60905] [client 35.224.218.165:52700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxe58Psx0SVFjrd6228ZgAAAA0"]
[Thu Sep 17 15:43:03.325881 2026] [security2:error] [pid 60716:tid 60956] [client 34.154.248.240:39942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxe58Psx0SVFjrd6228ZwAAAD4"]
[Thu Sep 17 15:43:03.343919 2026] [security2:error] [pid 60716:tid 61009] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228BgAAAHM"]
[Thu Sep 17 15:43:03.349314 2026] [security2:error] [pid 60716:tid 60954] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228BQAAADw"]
[Thu Sep 17 15:43:03.352948 2026] [security2:error] [pid 60716:tid 61021] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228CAAAAH8"]
[Thu Sep 17 15:43:03.375177 2026] [security2:error] [pid 60716:tid 61004] [client 34.95.193.102:33524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxe58Psx0SVFjrd6228aAAAAG4"]
[Thu Sep 17 15:43:03.414095 2026] [security2:error] [pid 60716:tid 60918] [client 74.7.241.176:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "latranslator.com"] [uri "/robots.txt"] [unique_id "aqxe58Psx0SVFjrd6228aQAAGjo"]
[Thu Sep 17 15:43:03.418574 2026] [security2:error] [pid 60716:tid 60963] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228UwAAAEU"]
[Thu Sep 17 15:43:03.420561 2026] [security2:error] [pid 60716:tid 60932] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228UQAAACY"]
[Thu Sep 17 15:43:03.422104 2026] [security2:error] [pid 60716:tid 60962] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228FwAAAEQ"]
[Thu Sep 17 15:43:03.422725 2026] [security2:error] [pid 60716:tid 60938] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228VAAAACw"]
[Thu Sep 17 15:43:03.423103 2026] [security2:error] [pid 60716:tid 60959] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228EAAAAEE"]
[Thu Sep 17 15:43:03.425305 2026] [security2:error] [pid 60716:tid 60974] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228JAAAAFA"]
[Thu Sep 17 15:43:03.428298 2026] [security2:error] [pid 60716:tid 61007] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228UgAAAHE"]
[Thu Sep 17 15:43:03.443902 2026] [security2:error] [pid 60716:tid 60892] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228JQAAAAA"]
[Thu Sep 17 15:43:03.453464 2026] [security2:error] [pid 60716:tid 60903] [client 35.224.218.165:52716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxe58Psx0SVFjrd6228agAAAAs"]
[Thu Sep 17 15:43:03.453667 2026] [security2:error] [pid 60716:tid 60942] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228PwAAADA"]
[Thu Sep 17 15:43:03.456728 2026] [security2:error] [pid 60716:tid 61000] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228OAAAAGo"]
[Thu Sep 17 15:43:03.459922 2026] [security2:error] [pid 60716:tid 60902] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe5sPsx0SVFjrd6228IgAAAAo"]
[Thu Sep 17 15:43:03.519917 2026] [security2:error] [pid 60716:tid 60800] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/database.sql"] [unique_id "aqxe58Psx0SVFjrd6228fAAALSY"]
[Thu Sep 17 15:43:03.542583 2026] [fcgid:warn] [pid 60716:tid 60923] (70014)End of file found: [client 152.32.218.30:49434] mod_fcgid: can't get data from http client
[Thu Sep 17 15:43:03.586076 2026] [security2:error] [pid 60716:tid 60943] [client 35.224.218.165:52732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/test.php"] [unique_id "aqxe58Psx0SVFjrd6228lQAAADE"]
[Thu Sep 17 15:43:03.654609 2026] [security2:error] [pid 60716:tid 60814] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/app/etc/env.php.bak"] [unique_id "aqxe58Psx0SVFjrd6228owAALTQ"]
[Thu Sep 17 15:43:03.669697 2026] [security2:error] [pid 60716:tid 60908] [client 79.116.89.151:64590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe58Psx0SVFjrd6228pgAAABA"]
[Thu Sep 17 15:43:03.670102 2026] [security2:error] [pid 60716:tid 60908] [client 79.116.89.151:64590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe58Psx0SVFjrd6228pgAAABA"]
[Thu Sep 17 15:43:03.674276 2026] [security2:error] [pid 60716:tid 60765] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/services/.env"] [unique_id "aqxe58Psx0SVFjrd6228pwAALQY"]
[Thu Sep 17 15:43:03.702125 2026] [security2:error] [pid 60716:tid 60821] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/wp-content/uploads/dump.sql"] [unique_id "aqxe58Psx0SVFjrd6228qQAALTs"]
[Thu Sep 17 15:43:03.725004 2026] [security2:error] [pid 60716:tid 60827] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/sites/default/settings.php"] [unique_id "aqxe58Psx0SVFjrd6228rwAALUE"]
[Thu Sep 17 15:43:03.787448 2026] [security2:error] [pid 60716:tid 60968] [client 35.224.218.165:52748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/p.php"] [unique_id "aqxe58Psx0SVFjrd6228tAAAAEo"]
[Thu Sep 17 15:43:03.798988 2026] [security2:error] [pid 60716:tid 60988] [client 34.154.248.240:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxe58Psx0SVFjrd6228uAAAAF4"]
[Thu Sep 17 15:43:03.834439 2026] [core:error] [pid 60716:tid 60979] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:03.834453 2026] [core:error] [pid 60716:tid 60979] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:03.862234 2026] [security2:error] [pid 60716:tid 60978] [client 34.95.193.102:33532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxe58Psx0SVFjrd6228wAAAAFQ"]
[Thu Sep 17 15:43:03.937891 2026] [security2:error] [pid 60716:tid 60995] [client 35.224.218.165:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxe58Psx0SVFjrd6228xQAAAGU"]
[Thu Sep 17 15:43:03.961583 2026] [core:error] [pid 60716:tid 60900] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:03.961599 2026] [core:error] [pid 60716:tid 60900] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:04.098551 2026] [security2:error] [pid 60716:tid 60989] [client 35.224.218.165:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd6228zwAAAF8"]
[Thu Sep 17 15:43:04.247190 2026] [security2:error] [pid 60716:tid 60892] [client 35.224.218.165:52774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd62281QAAAAA"]
[Thu Sep 17 15:43:04.275613 2026] [security2:error] [pid 60716:tid 60997] [client 34.154.248.240:39960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd62281gAAAGc"]
[Thu Sep 17 15:43:04.351498 2026] [security2:error] [pid 60716:tid 60909] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228fgAAABE"]
[Thu Sep 17 15:43:04.360515 2026] [security2:error] [pid 60716:tid 60920] [client 34.95.193.102:56692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd62282gAAABw"]
[Thu Sep 17 15:43:04.379915 2026] [security2:error] [pid 60716:tid 60955] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228gQAAAD0"]
[Thu Sep 17 15:43:04.383590 2026] [security2:error] [pid 60716:tid 60941] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228ggAAAC8"]
[Thu Sep 17 15:43:04.394756 2026] [security2:error] [pid 60716:tid 60948] [client 35.224.218.165:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd62283QAAADY"]
[Thu Sep 17 15:43:04.416808 2026] [security2:error] [pid 60716:tid 60937] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228kAAAACs"]
[Thu Sep 17 15:43:04.416808 2026] [security2:error] [pid 60716:tid 60897] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228kwAAAAU"]
[Thu Sep 17 15:43:04.417798 2026] [security2:error] [pid 60716:tid 60986] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228kQAAAFw"]
[Thu Sep 17 15:43:04.420973 2026] [security2:error] [pid 60716:tid 60962] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228yAAAAEQ"]
[Thu Sep 17 15:43:04.504320 2026] [security2:error] [pid 60716:tid 60860] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/db/.env"] [unique_id "aqxe6MPsx0SVFjrd62283wAALWI"]
[Thu Sep 17 15:43:04.545134 2026] [security2:error] [pid 60716:tid 60945] [client 35.224.218.165:52794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd62285QAAADM"]
[Thu Sep 17 15:43:04.632684 2026] [security2:error] [pid 60716:tid 60977] [client 169.58.197.253:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxe6MPsx0SVFjrd62288QAAAFM"], referer: binance.com
[Thu Sep 17 15:43:04.636646 2026] [core:error] [pid 60716:tid 60944] [client 34.166.220.229:53838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:04.636677 2026] [core:error] [pid 60716:tid 60944] [client 34.166.220.229:53838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:04.652359 2026] [security2:error] [pid 60716:tid 60949] [client 74.7.175.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.owf.sdy.mybluehost.me"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd62283gAAADc"]
[Thu Sep 17 15:43:04.653923 2026] [security2:error] [pid 60716:tid 61013] [client 74.7.175.143:49674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.owf.sdy.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxe6MPsx0SVFjrd62282wAAd0g"]
[Thu Sep 17 15:43:04.677616 2026] [security2:error] [pid 60716:tid 60893] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/logs/.env"] [unique_id "aqxe6MPsx0SVFjrd6228_gAAAAE"]
[Thu Sep 17 15:43:04.701966 2026] [security2:error] [pid 60716:tid 61016] [client 35.224.218.165:52802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd6229AQAAAHo"]
[Thu Sep 17 15:43:04.710679 2026] [security2:error] [pid 60716:tid 60854] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.88.205.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "navishiur.org"] [uri "/wp-config-sample.php"] [unique_id "aqxe6MPsx0SVFjrd6229AgAALVw"]
[Thu Sep 17 15:43:04.746117 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.248.240:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd6229CQAAABU"]
[Thu Sep 17 15:43:04.844471 2026] [security2:error] [pid 60716:tid 61005] [client 35.224.218.165:52804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd6229DwAAAG8"]
[Thu Sep 17 15:43:04.845534 2026] [security2:error] [pid 60716:tid 60777] [remote 35.205.88.64:58444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "navishiur.org"] [uri "/2023/.env"] [unique_id "aqxe6MPsx0SVFjrd6229EAAALRE"]
[Thu Sep 17 15:43:04.849264 2026] [security2:error] [pid 60716:tid 60971] [client 34.95.193.102:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxe6MPsx0SVFjrd6229EgAAAE0"]
[Thu Sep 17 15:43:04.904724 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/cache/.env"] [unique_id "aqxe6MPsx0SVFjrd6229EwAAAAA"]
[Thu Sep 17 15:43:05.130229 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxe6cPsx0SVFjrd6229HQAAACI"]
[Thu Sep 17 15:43:05.131638 2026] [security2:error] [pid 60716:tid 60970] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mailer/.env"] [unique_id "aqxe6cPsx0SVFjrd6229HgAAAEw"]
[Thu Sep 17 15:43:05.164696 2026] [security2:error] [pid 60716:tid 60897] [client 35.224.218.165:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxe6cPsx0SVFjrd6229IgAAAAU"]
[Thu Sep 17 15:43:05.215514 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.248.240:39974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxe6cPsx0SVFjrd6229JAAAABw"]
[Thu Sep 17 15:43:05.257092 2026] [security2:error] [pid 60716:tid 60967] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228oAAAAEk"]
[Thu Sep 17 15:43:05.257477 2026] [security2:error] [pid 60716:tid 60907] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228nwAAAA8"]
[Thu Sep 17 15:43:05.261837 2026] [security2:error] [pid 60716:tid 61015] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228oQAAAHk"]
[Thu Sep 17 15:43:05.263491 2026] [security2:error] [pid 60716:tid 60958] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228sQAAAEA"]
[Thu Sep 17 15:43:05.265834 2026] [security2:error] [pid 60716:tid 60938] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228ywAAACw"]
[Thu Sep 17 15:43:05.269440 2026] [security2:error] [pid 60716:tid 60982] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228ogAAAFg"]
[Thu Sep 17 15:43:05.277106 2026] [security2:error] [pid 60716:tid 60990] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228kgAAAGA"]
[Thu Sep 17 15:43:05.281274 2026] [security2:error] [pid 60716:tid 61014] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228yQAAAHg"]
[Thu Sep 17 15:43:05.283603 2026] [security2:error] [pid 60716:tid 61001] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe58Psx0SVFjrd6228zAAAAGs"]
[Thu Sep 17 15:43:05.284639 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/.env~"] [unique_id "aqxe6cPsx0SVFjrd6229JQAAADM"]
[Thu Sep 17 15:43:05.307146 2026] [security2:error] [pid 60716:tid 60984] [client 35.224.218.165:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxe6cPsx0SVFjrd6229JgAAAFo"]
[Thu Sep 17 15:43:05.337081 2026] [security2:error] [pid 60716:tid 60937] [client 34.95.193.102:56700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxe6cPsx0SVFjrd6229KwAAACs"]
[Thu Sep 17 15:43:05.343724 2026] [core:error] [pid 60716:tid 60954] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:05.343741 2026] [core:error] [pid 60716:tid 60954] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:05.360637 2026] [security2:error] [pid 60716:tid 60895] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "aqxe6cPsx0SVFjrd6229LQAAAAM"]
[Thu Sep 17 15:43:05.387330 2026] [security2:error] [pid 60716:tid 61009] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd62288wAAAHM"]
[Thu Sep 17 15:43:05.387688 2026] [security2:error] [pid 60716:tid 60905] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd62285gAAAA0"]
[Thu Sep 17 15:43:05.387792 2026] [security2:error] [pid 60716:tid 61012] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd6229EQAAAHY"]
[Thu Sep 17 15:43:05.388799 2026] [security2:error] [pid 60716:tid 61004] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd6228-QAAAG4"]
[Thu Sep 17 15:43:05.388956 2026] [security2:error] [pid 60716:tid 60993] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd6229CgAAAGM"]
[Thu Sep 17 15:43:05.402395 2026] [security2:error] [pid 60716:tid 60988] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd62289gAAAF4"]
[Thu Sep 17 15:43:05.403820 2026] [security2:error] [pid 60716:tid 61008] [client 35.205.88.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "navishiur.org"] [uri "/index.php"] [unique_id "aqxe6MPsx0SVFjrd6229CwAAAHI"]
[Thu Sep 17 15:43:05.441801 2026] [security2:error] [pid 60716:tid 60912] [client 35.224.218.165:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxe6cPsx0SVFjrd6229LwAAABQ"]
[Thu Sep 17 15:43:05.589007 2026] [security2:error] [pid 60716:tid 60925] [client 35.224.218.165:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxe6cPsx0SVFjrd6229MwAAACA"]
[Thu Sep 17 15:43:05.589524 2026] [security2:error] [pid 60716:tid 60971] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/email/.env"] [unique_id "aqxe6cPsx0SVFjrd6229MgAAAE0"]
[Thu Sep 17 15:43:05.680529 2026] [security2:error] [pid 60716:tid 60959] [client 34.154.248.240:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/phpinfo.php.old"] [unique_id "aqxe6cPsx0SVFjrd6229OQAAAEE"]
[Thu Sep 17 15:43:05.731710 2026] [security2:error] [pid 60716:tid 60955] [client 35.224.218.165:52868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxe6cPsx0SVFjrd6229PAAAAD0"]
[Thu Sep 17 15:43:05.748152 2026] [security2:error] [pid 60716:tid 60948] [client 93.152.209.11:51926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.janstremmel.com"] [uri "/.env"] [unique_id "aqxe6cPsx0SVFjrd6229PQAAADY"]
[Thu Sep 17 15:43:05.817168 2026] [security2:error] [pid 60716:tid 60946] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/smtp/.env"] [unique_id "aqxe6cPsx0SVFjrd6229QQAAADQ"]
[Thu Sep 17 15:43:05.818035 2026] [security2:error] [pid 60716:tid 60969] [client 34.95.193.102:56710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/www/phpinfo.php"] [unique_id "aqxe6cPsx0SVFjrd6229QgAAAEs"]
[Thu Sep 17 15:43:05.876384 2026] [security2:error] [pid 60716:tid 60935] [client 78.47.173.76:46156] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxe6cPsx0SVFjrd6229RwAAACk"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:43:05.892367 2026] [security2:error] [pid 60716:tid 61019] [client 35.224.218.165:52878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxe6cPsx0SVFjrd6229SAAAAH0"]
[Thu Sep 17 15:43:05.906711 2026] [security2:error] [pid 60716:tid 60782] [remote 93.152.209.11:30984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.janstremmel.com"] [uri "/.env"] [unique_id "aqxe6cPsx0SVFjrd6229SQAATBU"]
[Thu Sep 17 15:43:06.044655 2026] [security2:error] [pid 60716:tid 60919] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mailing/.env"] [unique_id "aqxe6sPsx0SVFjrd6229VAAAABs"]
[Thu Sep 17 15:43:06.145943 2026] [core:error] [pid 60716:tid 60964] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:06.145960 2026] [core:error] [pid 60716:tid 60964] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:06.175655 2026] [security2:error] [pid 60716:tid 61021] [client 34.154.248.240:40000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/phpinfo.php~"] [unique_id "aqxe6sPsx0SVFjrd6229YQAAAH8"]
[Thu Sep 17 15:43:06.263821 2026] [security2:error] [pid 60716:tid 60911] [client 35.224.218.165:52890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxe6sPsx0SVFjrd6229ZwAAABM"]
[Thu Sep 17 15:43:06.273961 2026] [security2:error] [pid 60716:tid 60963] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/notifications/.env"] [unique_id "aqxe6sPsx0SVFjrd6229aAAAAEU"]
[Thu Sep 17 15:43:06.304262 2026] [security2:error] [pid 60716:tid 60944] [client 34.95.193.102:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxe6sPsx0SVFjrd6229aQAAADI"]
[Thu Sep 17 15:43:06.350990 2026] [security2:error] [pid 60716:tid 60905] [client 78.47.173.76:46164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxe6sPsx0SVFjrd6229agAAAA0"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:43:06.431466 2026] [security2:error] [pid 60716:tid 60898] [client 35.224.218.165:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxe6sPsx0SVFjrd6229awAAAAY"]
[Thu Sep 17 15:43:06.502600 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/notify/.env"] [unique_id "aqxe6sPsx0SVFjrd6229bgAAAHo"]
[Thu Sep 17 15:43:06.599714 2026] [security2:error] [pid 60716:tid 60906] [client 35.224.218.165:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxe6sPsx0SVFjrd6229bwAAAA4"]
[Thu Sep 17 15:43:06.643334 2026] [security2:error] [pid 60716:tid 60976] [client 137.184.78.133:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "counselingforchange.net"] [uri "/index.php"] [unique_id "aqxe6sPsx0SVFjrd6229WgAAUkA"], referer: http://counselingforchange.net/blog/
[Thu Sep 17 15:43:06.658322 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.248.240:40008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/info.php.bak"] [unique_id "aqxe6sPsx0SVFjrd6229cwAAAAg"]
[Thu Sep 17 15:43:06.733375 2026] [security2:error] [pid 60716:tid 60956] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/sender/.env"] [unique_id "aqxe6sPsx0SVFjrd6229dwAAAD4"]
[Thu Sep 17 15:43:06.758180 2026] [security2:error] [pid 60716:tid 60995] [client 35.224.218.165:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxe6sPsx0SVFjrd6229eQAAAGU"]
[Thu Sep 17 15:43:06.794521 2026] [security2:error] [pid 60716:tid 60950] [client 34.95.193.102:56738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxe6sPsx0SVFjrd6229ewAAADg"]
[Thu Sep 17 15:43:06.828406 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxe6sPsx0SVFjrd6229fAAAAGo"]
[Thu Sep 17 15:43:06.854230 2026] [security2:error] [pid 60716:tid 60999] [client 34.166.220.229:37858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "aqxe6sPsx0SVFjrd6229fQAAAGk"]
[Thu Sep 17 15:43:06.868296 2026] [security2:error] [pid 60716:tid 60974] [client 137.184.78.133:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "counselingforchange.net"] [uri "/index.php"] [unique_id "aqxe6sPsx0SVFjrd6229egAAUFU"], referer: http://counselingforchange.net/backup/
[Thu Sep 17 15:43:06.901119 2026] [security2:error] [pid 60716:tid 60892] [client 35.224.218.165:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxe6sPsx0SVFjrd6229fgAAAAA"]
[Thu Sep 17 15:43:06.969673 2026] [security2:error] [pid 60716:tid 60972] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/campaign/.env"] [unique_id "aqxe6sPsx0SVFjrd6229gAAAAE4"]
[Thu Sep 17 15:43:06.982330 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxe6sPsx0SVFjrd6229ggAAAAs"]
[Thu Sep 17 15:43:07.036425 2026] [security2:error] [pid 60716:tid 60948] [client 35.224.218.165:52938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxe68Psx0SVFjrd6229hgAAADY"]
[Thu Sep 17 15:43:07.082091 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.220.229:37858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "aqxe68Psx0SVFjrd6229hwAAABY"]
[Thu Sep 17 15:43:07.088875 2026] [security2:error] [pid 60716:tid 60897] [client 137.184.78.133:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "counselingforchange.net"] [uri "/index.php"] [unique_id "aqxe68Psx0SVFjrd6229hAAABRQ"], referer: http://counselingforchange.net/wp/
[Thu Sep 17 15:43:07.140214 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.248.240:40022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/phpinfo.php.save"] [unique_id "aqxe68Psx0SVFjrd6229igAAAD0"]
[Thu Sep 17 15:43:07.148493 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxe68Psx0SVFjrd6229iwAAACk"]
[Thu Sep 17 15:43:07.199828 2026] [security2:error] [pid 60716:tid 60940] [client 35.224.218.165:52948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxe68Psx0SVFjrd6229jwAAAC4"]
[Thu Sep 17 15:43:07.202593 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/newsletter/.env"] [unique_id "aqxe68Psx0SVFjrd6229kAAAAB4"]
[Thu Sep 17 15:43:07.227399 2026] [security2:error] [pid 60716:tid 60899] [client 23.84.183.42:34170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe68Psx0SVFjrd6229iAAABzI"]
[Thu Sep 17 15:43:07.285712 2026] [security2:error] [pid 60716:tid 60907] [client 34.95.193.102:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/site/phpinfo.php"] [unique_id "aqxe68Psx0SVFjrd6229lAAAAA8"]
[Thu Sep 17 15:43:07.305451 2026] [security2:error] [pid 60716:tid 60901] [client 137.184.78.133:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "counselingforchange.net"] [uri "/index.php"] [unique_id "aqxe68Psx0SVFjrd6229kgAACXk"], referer: http://counselingforchange.net/new/
[Thu Sep 17 15:43:07.309652 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxe68Psx0SVFjrd6229lQAAAEA"]
[Thu Sep 17 15:43:07.309694 2026] [security2:error] [pid 60716:tid 60996] [client 34.166.220.229:37858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "aqxe68Psx0SVFjrd6229lgAAAGY"]
[Thu Sep 17 15:43:07.342254 2026] [security2:error] [pid 60716:tid 60966] [client 35.224.218.165:52956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxe68Psx0SVFjrd6229lwAAAEg"]
[Thu Sep 17 15:43:07.436962 2026] [security2:error] [pid 60716:tid 60919] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/ses/.env"] [unique_id "aqxe68Psx0SVFjrd6229mgAAABs"]
[Thu Sep 17 15:43:07.470249 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxe68Psx0SVFjrd6229nAAAABw"]
[Thu Sep 17 15:43:07.474771 2026] [security2:error] [pid 60716:tid 60998] [client 35.224.218.165:52960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxe68Psx0SVFjrd6229nQAAAGg"]
[Thu Sep 17 15:43:07.537234 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.220.229:37858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "aqxe68Psx0SVFjrd6229ngAAAFY"]
[Thu Sep 17 15:43:07.633701 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.248.240:40032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxe68Psx0SVFjrd6229ogAAAGA"]
[Thu Sep 17 15:43:07.636506 2026] [security2:error] [pid 60716:tid 60908] [client 35.224.218.165:52962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxe68Psx0SVFjrd6229owAAABA"]
[Thu Sep 17 15:43:07.638785 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxe68Psx0SVFjrd6229pAAAAFg"]
[Thu Sep 17 15:43:07.670614 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/sendgrid/.env"] [unique_id "aqxe68Psx0SVFjrd6229pgAAACs"]
[Thu Sep 17 15:43:07.742341 2026] [security2:error] [pid 60716:tid 60844] [remote 45.157.54.43:17125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wholeworkplace.com"] [uri "/xmlrpc.php"] [unique_id "aqxe68Psx0SVFjrd6229qgAAGVI"]
[Thu Sep 17 15:43:07.742467 2026] [security2:error] [pid 60716:tid 60917] [client 45.157.54.43:17125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wholeworkplace.com"] [uri "/xmlrpc.php"] [unique_id "aqxe68Psx0SVFjrd6229qgAAGVI"]
[Thu Sep 17 15:43:07.759483 2026] [security2:error] [pid 60716:tid 61003] [client 137.184.78.133:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "counselingforchange.net"] [uri "/index.php"] [unique_id "aqxe68Psx0SVFjrd6229pQAAbXU"], referer: http://counselingforchange.net/wordpress/
[Thu Sep 17 15:43:07.764525 2026] [security2:error] [pid 60716:tid 61021] [client 34.166.220.229:37858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/site/.env"] [unique_id "aqxe68Psx0SVFjrd6229qwAAAH8"]
[Thu Sep 17 15:43:07.775217 2026] [security2:error] [pid 60716:tid 60968] [client 35.224.218.165:52972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxe68Psx0SVFjrd6229rAAAAEo"]
[Thu Sep 17 15:43:07.782404 2026] [security2:error] [pid 60716:tid 60994] [client 34.95.193.102:56746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxe68Psx0SVFjrd6229rQAAAGQ"]
[Thu Sep 17 15:43:07.818751 2026] [security2:error] [pid 60716:tid 60954] [client 169.58.197.251:60847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxe68Psx0SVFjrd6229sAAAADw"], referer: binance.com
[Thu Sep 17 15:43:07.899118 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/sparkpost/.env"] [unique_id "aqxe68Psx0SVFjrd6229sgAAABM"]
[Thu Sep 17 15:43:07.922707 2026] [security2:error] [pid 60716:tid 60926] [client 35.224.218.165:52988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxe68Psx0SVFjrd6229tAAAACE"]
[Thu Sep 17 15:43:07.986326 2026] [security2:error] [pid 60716:tid 61007] [client 137.184.78.133:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "counselingforchange.net"] [uri "/index.php"] [unique_id "aqxe68Psx0SVFjrd6229swAAcXs"], referer: http://counselingforchange.net/old/
[Thu Sep 17 15:43:07.991970 2026] [security2:error] [pid 60716:tid 60979] [client 34.166.220.229:37858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "aqxe68Psx0SVFjrd6229tQAAAFU"]
[Thu Sep 17 15:43:08.003063 2026] [security2:error] [pid 60716:tid 60893] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxe7MPsx0SVFjrd6229twAAAAE"]
[Thu Sep 17 15:43:08.080280 2026] [security2:error] [pid 60716:tid 60905] [client 35.224.218.165:52998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd6229uAAAAA0"]
[Thu Sep 17 15:43:08.103860 2026] [security2:error] [pid 60716:tid 61002] [client 34.154.248.240:40048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd6229ugAAAGw"]
[Thu Sep 17 15:43:08.133673 2026] [security2:error] [pid 60716:tid 60991] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/postmark/.env"] [unique_id "aqxe7MPsx0SVFjrd6229uwAAAGE"]
[Thu Sep 17 15:43:08.161459 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxe7MPsx0SVFjrd6229vAAAAA4"]
[Thu Sep 17 15:43:08.216871 2026] [security2:error] [pid 60716:tid 60976] [client 35.224.218.165:53014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd6229wQAAAFI"]
[Thu Sep 17 15:43:08.218748 2026] [security2:error] [pid 60716:tid 60978] [client 103.61.184.148:52669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe7MPsx0SVFjrd6229wwAAAFQ"]
[Thu Sep 17 15:43:08.219337 2026] [security2:error] [pid 60716:tid 60978] [client 103.61.184.148:52669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe7MPsx0SVFjrd6229wwAAAFQ"]
[Thu Sep 17 15:43:08.264970 2026] [core:error] [pid 60716:tid 60995] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:08.264988 2026] [core:error] [pid 60716:tid 60995] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:08.272180 2026] [security2:error] [pid 60716:tid 60918] [client 34.95.193.102:56756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd6229xgAAABo"]
[Thu Sep 17 15:43:08.320197 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxe7MPsx0SVFjrd6229xwAAAE0"]
[Thu Sep 17 15:43:08.362117 2026] [security2:error] [pid 60716:tid 61000] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mailgun/.env"] [unique_id "aqxe7MPsx0SVFjrd6229yAAAAGo"]
[Thu Sep 17 15:43:08.369392 2026] [security2:error] [pid 60716:tid 60942] [client 35.224.218.165:53028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd6229yQAAADA"]
[Thu Sep 17 15:43:08.473825 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxe7MPsx0SVFjrd6229ygAAACI"]
[Thu Sep 17 15:43:08.508232 2026] [security2:error] [pid 60716:tid 61017] [client 35.224.218.165:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd6229ywAAAHs"]
[Thu Sep 17 15:43:08.542459 2026] [security2:error] [pid 60716:tid 60999] [client 148.227.75.216:39894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe7MPsx0SVFjrd6229zAAAAGk"]
[Thu Sep 17 15:43:08.552050 2026] [security2:error] [pid 60716:tid 60999] [client 148.227.75.216:39894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe7MPsx0SVFjrd6229zAAAAGk"]
[Thu Sep 17 15:43:08.572602 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.248.240:40062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd6229zQAAAAA"]
[Thu Sep 17 15:43:08.590480 2026] [security2:error] [pid 60716:tid 60969] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mandrill/.env"] [unique_id "aqxe7MPsx0SVFjrd6229zgAAAEs"]
[Thu Sep 17 15:43:08.648612 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxe7MPsx0SVFjrd62290QAAAD0"]
[Thu Sep 17 15:43:08.652437 2026] [security2:error] [pid 60716:tid 60914] [client 35.224.218.165:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd62290wAAABY"]
[Thu Sep 17 15:43:08.755181 2026] [security2:error] [pid 60716:tid 60975] [client 145.239.10.137:38275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vagabondhiker.com"] [uri "/manage.php"] [unique_id "aqxe7MPsx0SVFjrd62291QAAAFE"], referer: http://vagabondhiker.com/manage.php
[Thu Sep 17 15:43:08.761400 2026] [security2:error] [pid 60716:tid 60960] [client 34.95.193.102:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd62291wAAAEI"]
[Thu Sep 17 15:43:08.800823 2026] [security2:error] [pid 60716:tid 60973] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxe7MPsx0SVFjrd62292AAAAE8"]
[Thu Sep 17 15:43:08.817725 2026] [security2:error] [pid 60716:tid 60901] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mailjet/.env"] [unique_id "aqxe7MPsx0SVFjrd62292QAAAAk"]
[Thu Sep 17 15:43:08.839928 2026] [security2:error] [pid 60716:tid 60965] [client 35.224.218.165:34532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxe7MPsx0SVFjrd62292wAAAEc"]
[Thu Sep 17 15:43:08.861504 2026] [security2:error] [pid 60716:tid 60924] [client 185.104.184.228:46566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/js/dist/development/"] [unique_id "aqxe7MPsx0SVFjrd62292gAAAB8"]
[Thu Sep 17 15:43:08.946842 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "aqxe7MPsx0SVFjrd62293AAAACw"]
[Thu Sep 17 15:43:08.954454 2026] [security2:error] [pid 60716:tid 61020] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxe7MPsx0SVFjrd62293QAAAH4"]
[Thu Sep 17 15:43:09.026340 2026] [security2:error] [pid 60716:tid 60919] [client 35.224.218.165:34544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd62293gAAABs"]
[Thu Sep 17 15:43:09.036384 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.248.240:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd62293wAAAEA"]
[Thu Sep 17 15:43:09.046887 2026] [security2:error] [pid 60716:tid 60904] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/brevo/.env"] [unique_id "aqxe7cPsx0SVFjrd62294AAAAAw"]
[Thu Sep 17 15:43:09.109863 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxe7cPsx0SVFjrd62294gAAADM"]
[Thu Sep 17 15:43:09.174226 2026] [security2:error] [pid 60716:tid 60984] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "aqxe7cPsx0SVFjrd62295QAAAFo"]
[Thu Sep 17 15:43:09.179122 2026] [security2:error] [pid 60716:tid 60980] [client 35.224.218.165:34548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd62296AAAAFY"]
[Thu Sep 17 15:43:09.264906 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.193.102:56774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/core/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd62296wAAAGs"]
[Thu Sep 17 15:43:09.270112 2026] [security2:error] [pid 60716:tid 60917] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxe7cPsx0SVFjrd62297AAAABk"]
[Thu Sep 17 15:43:09.273796 2026] [security2:error] [pid 60716:tid 60952] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/transactional/.env"] [unique_id "aqxe7cPsx0SVFjrd62297QAAADo"]
[Thu Sep 17 15:43:09.337735 2026] [security2:error] [pid 60716:tid 60981] [client 35.224.218.165:34564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd62297gAAAFc"]
[Thu Sep 17 15:43:09.400990 2026] [security2:error] [pid 60716:tid 60977] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "aqxe7cPsx0SVFjrd62298AAAAFM"]
[Thu Sep 17 15:43:09.424109 2026] [security2:error] [pid 60716:tid 61004] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxe7cPsx0SVFjrd62298QAAAG4"]
[Thu Sep 17 15:43:09.472461 2026] [security2:error] [pid 60716:tid 60910] [client 35.224.218.165:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd62298gAAABI"]
[Thu Sep 17 15:43:09.501020 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.248.240:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd62298wAAAGQ"]
[Thu Sep 17 15:43:09.506814 2026] [security2:error] [pid 60716:tid 60947] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/bulk/.env"] [unique_id "aqxe7cPsx0SVFjrd62299AAAADU"]
[Thu Sep 17 15:43:09.531574 2026] [security2:error] [pid 60716:tid 61012] [client 162.241.226.11:37778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxe7cPsx0SVFjrd62297wAAAHY"]
[Thu Sep 17 15:43:09.581929 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxe7cPsx0SVFjrd62299wAAABM"]
[Thu Sep 17 15:43:09.628861 2026] [security2:error] [pid 60716:tid 60962] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "aqxe7cPsx0SVFjrd6229-QAAAEQ"]
[Thu Sep 17 15:43:09.642104 2026] [security2:error] [pid 60716:tid 60963] [client 23.84.183.42:44624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe7cPsx0SVFjrd6229-AAARRo"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260612184752&hidebots=0&hideliu=1&hidemyself=1&target=The_God-Emperor&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:43:09.650761 2026] [security2:error] [pid 60716:tid 60987] [client 35.224.218.165:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd6229-gAAAF0"]
[Thu Sep 17 15:43:09.726809 2026] [security2:error] [pid 60716:tid 60931] [client 162.241.226.11:37788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxe7cPsx0SVFjrd62299QAAACU"]
[Thu Sep 17 15:43:09.740233 2026] [security2:error] [pid 60716:tid 60976] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/aws/.env"] [unique_id "aqxe7cPsx0SVFjrd622-AQAAAFI"]
[Thu Sep 17 15:43:09.740233 2026] [security2:error] [pid 60716:tid 60912] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxe7cPsx0SVFjrd622-AAAAABQ"]
[Thu Sep 17 15:43:09.755973 2026] [security2:error] [pid 60716:tid 60926] [client 34.95.193.102:56790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.193.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embracingthehour.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd622-AgAAACE"]
[Thu Sep 17 15:43:09.791932 2026] [security2:error] [pid 60716:tid 60906] [client 35.224.218.165:34606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd622-BAAAAA4"]
[Thu Sep 17 15:43:09.855770 2026] [security2:error] [pid 60716:tid 61006] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/core/.env"] [unique_id "aqxe7cPsx0SVFjrd622-BQAAAHA"]
[Thu Sep 17 15:43:09.901894 2026] [security2:error] [pid 60716:tid 60922] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxe7cPsx0SVFjrd622-BgAAAB0"]
[Thu Sep 17 15:43:09.936388 2026] [security2:error] [pid 60716:tid 61013] [client 14.96.156.146:51113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe7cPsx0SVFjrd622-BwAAAHc"]
[Thu Sep 17 15:43:09.936509 2026] [security2:error] [pid 60716:tid 61013] [client 14.96.156.146:51113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe7cPsx0SVFjrd622-BwAAAHc"]
[Thu Sep 17 15:43:09.950386 2026] [security2:error] [pid 60716:tid 61016] [client 35.224.218.165:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.218.224.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kok.bjl.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd622-CAAAAHo"]
[Thu Sep 17 15:43:09.976336 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/azure/.env"] [unique_id "aqxe7cPsx0SVFjrd622-CQAAACQ"]
[Thu Sep 17 15:43:09.991565 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.248.240:60118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/www/phpinfo.php"] [unique_id "aqxe7cPsx0SVFjrd622-CgAAABU"]
[Thu Sep 17 15:43:10.064241 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxe7sPsx0SVFjrd622-DAAAADg"]
[Thu Sep 17 15:43:10.082829 2026] [security2:error] [pid 60716:tid 60942] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/core/app/.env"] [unique_id "aqxe7sPsx0SVFjrd622-DQAAADA"]
[Thu Sep 17 15:43:10.209368 2026] [security2:error] [pid 60716:tid 60946] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/gcp/.env"] [unique_id "aqxe7sPsx0SVFjrd622-FQAAADQ"]
[Thu Sep 17 15:43:10.223750 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxe7sPsx0SVFjrd622-FgAAAGk"]
[Thu Sep 17 15:43:10.225039 2026] [security2:error] [pid 60716:tid 60900] [client 40.77.167.157:19507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "breathingboxing.com"] [uri "/index.php"] [unique_id "aqxe7MPsx0SVFjrd6229vwAACHQ"]
[Thu Sep 17 15:43:10.245956 2026] [core:error] [pid 60716:tid 61000] [client 34.95.193.102:56792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:10.245977 2026] [core:error] [pid 60716:tid 61000] [client 34.95.193.102:56792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:10.310131 2026] [security2:error] [pid 60716:tid 60897] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "aqxe7sPsx0SVFjrd622-OQAAAAU"]
[Thu Sep 17 15:43:10.382682 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxe7sPsx0SVFjrd622-OwAAAFE"]
[Thu Sep 17 15:43:10.444556 2026] [security2:error] [pid 60716:tid 60924] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/cloud/.env"] [unique_id "aqxe7sPsx0SVFjrd622-PgAAAB8"]
[Thu Sep 17 15:43:10.457184 2026] [security2:error] [pid 60716:tid 60923] [client 34.154.248.240:60122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxe7sPsx0SVFjrd622-PwAAAB4"]
[Thu Sep 17 15:43:10.537712 2026] [security2:error] [pid 60716:tid 60916] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/private/.env"] [unique_id "aqxe7sPsx0SVFjrd622-QgAAABg"]
[Thu Sep 17 15:43:10.540993 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxe7sPsx0SVFjrd622-QwAAACo"]
[Thu Sep 17 15:43:10.679494 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/infrastructure/.env"] [unique_id "aqxe7sPsx0SVFjrd622-YQAAACs"]
[Thu Sep 17 15:43:10.704007 2026] [security2:error] [pid 60716:tid 60986] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxe7sPsx0SVFjrd622-YwAAAFw"]
[Thu Sep 17 15:43:10.748563 2026] [core:error] [pid 60716:tid 60958] [client 34.95.193.102:56804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:10.748589 2026] [core:error] [pid 60716:tid 60958] [client 34.95.193.102:56804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:10.764952 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "aqxe7sPsx0SVFjrd622-jwAAAG0"]
[Thu Sep 17 15:43:10.863838 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxe7sPsx0SVFjrd622-kAAAAGA"]
[Thu Sep 17 15:43:10.914467 2026] [security2:error] [pid 60716:tid 60943] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "aqxe7sPsx0SVFjrd622-lAAAADE"]
[Thu Sep 17 15:43:10.945680 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.248.240:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxe7sPsx0SVFjrd622-lgAAAEY"]
[Thu Sep 17 15:43:10.976949 2026] [authz_core:error] [pid 60716:tid 60915] [client 169.58.197.253:54594] AH01630: client denied by server configuration: /home4/ccrmedia/public_html/p3collaborative/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:43:10.993257 2026] [security2:error] [pid 60716:tid 61014] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/bootstrap/.env"] [unique_id "aqxe7sPsx0SVFjrd622-lwAAAHg"]
[Thu Sep 17 15:43:11.029483 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxe78Psx0SVFjrd622-mAAAADU"]
[Thu Sep 17 15:43:11.147404 2026] [security2:error] [pid 60716:tid 61007] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/k8s/.env"] [unique_id "aqxe78Psx0SVFjrd622-nQAAAHE"]
[Thu Sep 17 15:43:11.188384 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxe78Psx0SVFjrd622-owAAACU"]
[Thu Sep 17 15:43:11.219982 2026] [security2:error] [pid 60716:tid 60979] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/database/.env"] [unique_id "aqxe78Psx0SVFjrd622-pQAAAFU"]
[Thu Sep 17 15:43:11.252722 2026] [core:error] [pid 60716:tid 60982] [client 34.95.193.102:56818] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:11.252743 2026] [core:error] [pid 60716:tid 60982] [client 34.95.193.102:56818] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:11.346444 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxe78Psx0SVFjrd622-qgAAAA4"]
[Thu Sep 17 15:43:11.378381 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/kubernetes/.env"] [unique_id "aqxe78Psx0SVFjrd622-rAAAAHo"]
[Thu Sep 17 15:43:11.385863 2026] [security2:error] [pid 60716:tid 60951] [client 185.104.184.228:46566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/js/dist/script-modules/"] [unique_id "aqxe78Psx0SVFjrd622-pwAAADk"]
[Thu Sep 17 15:43:11.423276 2026] [security2:error] [pid 60716:tid 60953] [client 34.154.248.240:60138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/site/phpinfo.php"] [unique_id "aqxe78Psx0SVFjrd622-sgAAADs"]
[Thu Sep 17 15:43:11.447191 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/storage/.env"] [unique_id "aqxe78Psx0SVFjrd622-uAAAACA"]
[Thu Sep 17 15:43:11.513776 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxe78Psx0SVFjrd622-uQAAACc"]
[Thu Sep 17 15:43:11.559065 2026] [security2:error] [pid 60716:tid 60909] [client 185.104.184.228:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.184.104.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/js/dist/script-modules/registry.php"] [unique_id "aqxe78Psx0SVFjrd622-uwAAABE"]
[Thu Sep 17 15:43:11.559237 2026] [security2:error] [pid 60716:tid 60909] [client 185.104.184.228:46566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.freeofgravity.com"] [uri "/wp-includes/js/dist/script-modules/registry.php"] [unique_id "aqxe78Psx0SVFjrd622-uwAAABE"]
[Thu Sep 17 15:43:11.602339 2026] [security2:error] [pid 60716:tid 60976] [client 177.44.133.72:62349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe78Psx0SVFjrd622-vAAAAFI"]
[Thu Sep 17 15:43:11.602471 2026] [security2:error] [pid 60716:tid 60976] [client 177.44.133.72:62349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe78Psx0SVFjrd622-vAAAAFI"]
[Thu Sep 17 15:43:11.609234 2026] [security2:error] [pid 60716:tid 60939] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/terraform/.env"] [unique_id "aqxe78Psx0SVFjrd622-vgAAAC0"]
[Thu Sep 17 15:43:11.671424 2026] [security2:error] [pid 60716:tid 60972] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxe78Psx0SVFjrd622-wgAAAE4"]
[Thu Sep 17 15:43:11.674521 2026] [security2:error] [pid 60716:tid 60903] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "aqxe78Psx0SVFjrd622-wwAAAAs"]
[Thu Sep 17 15:43:11.747944 2026] [core:error] [pid 60716:tid 60950] [client 34.95.193.102:56820] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:11.747974 2026] [core:error] [pid 60716:tid 60950] [client 34.95.193.102:56820] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:11.842847 2026] [security2:error] [pid 60716:tid 60900] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/ansible/.env"] [unique_id "aqxe78Psx0SVFjrd622-0QAAAAg"]
[Thu Sep 17 15:43:11.844632 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxe78Psx0SVFjrd622-0gAAAGo"]
[Thu Sep 17 15:43:11.886943 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.248.240:60148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxe78Psx0SVFjrd622-0wAAADQ"]
[Thu Sep 17 15:43:11.902550 2026] [security2:error] [pid 60716:tid 60955] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "aqxe78Psx0SVFjrd622-1AAAAD0"]
[Thu Sep 17 15:43:12.007077 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxe8MPsx0SVFjrd622-1QAAABY"]
[Thu Sep 17 15:43:12.083844 2026] [security2:error] [pid 60716:tid 60935] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/.git/.env"] [unique_id "aqxe8MPsx0SVFjrd622-1gAAACk"]
[Thu Sep 17 15:43:12.129927 2026] [security2:error] [pid 60716:tid 60907] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "aqxe8MPsx0SVFjrd622-2QAAAA8"]
[Thu Sep 17 15:43:12.165939 2026] [security2:error] [pid 60716:tid 60967] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxe8MPsx0SVFjrd622-2gAAAEk"]
[Thu Sep 17 15:43:12.270962 2026] [core:error] [pid 60716:tid 60899] [client 34.95.193.102:56832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:12.270994 2026] [core:error] [pid 60716:tid 60899] [client 34.95.193.102:56832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:12.319448 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/ci/.env"] [unique_id "aqxe8MPsx0SVFjrd622-3wAAAB4"]
[Thu Sep 17 15:43:12.324099 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxe8MPsx0SVFjrd622-4AAAAGY"]
[Thu Sep 17 15:43:12.358407 2026] [security2:error] [pid 60716:tid 61020] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/release/.env"] [unique_id "aqxe8MPsx0SVFjrd622-4QAAAH4"]
[Thu Sep 17 15:43:12.393067 2026] [security2:error] [pid 60716:tid 60973] [client 34.154.248.240:60154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxe8MPsx0SVFjrd622-5QAAAE8"]
[Thu Sep 17 15:43:12.483156 2026] [security2:error] [pid 60716:tid 60986] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxe8MPsx0SVFjrd622-5gAAAFw"]
[Thu Sep 17 15:43:12.547955 2026] [security2:error] [pid 60716:tid 60958] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/cd/.env"] [unique_id "aqxe8MPsx0SVFjrd622-6QAAAEA"]
[Thu Sep 17 15:43:12.585458 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/releases/.env"] [unique_id "aqxe8MPsx0SVFjrd622-6wAAAG0"]
[Thu Sep 17 15:43:12.636634 2026] [security2:error] [pid 60716:tid 60908] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxe8MPsx0SVFjrd622-_wAAABA"]
[Thu Sep 17 15:43:12.713061 2026] [security2:error] [pid 60716:tid 60998] [client 136.158.61.34:46170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe8MPsx0SVFjrd622_AwAAAGg"]
[Thu Sep 17 15:43:12.713208 2026] [security2:error] [pid 60716:tid 60998] [client 136.158.61.34:46170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe8MPsx0SVFjrd622_AwAAAGg"]
[Thu Sep 17 15:43:12.771416 2026] [core:error] [pid 60716:tid 61021] [client 34.95.193.102:56838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:12.771439 2026] [core:error] [pid 60716:tid 61021] [client 34.95.193.102:56838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:12.776671 2026] [security2:error] [pid 60716:tid 61011] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/jenkins/.env"] [unique_id "aqxe8MPsx0SVFjrd622_BwAAAHU"]
[Thu Sep 17 15:43:12.789296 2026] [security2:error] [pid 60716:tid 60915] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxe8MPsx0SVFjrd622_CAAAABc"]
[Thu Sep 17 15:43:12.791128 2026] [security2:error] [pid 60716:tid 60965] [client 143.105.152.240:27749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe8MPsx0SVFjrd622_CQAAAEc"]
[Thu Sep 17 15:43:12.791235 2026] [security2:error] [pid 60716:tid 60965] [client 143.105.152.240:27749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe8MPsx0SVFjrd622_CQAAAEc"]
[Thu Sep 17 15:43:12.812778 2026] [security2:error] [pid 60716:tid 60947] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "aqxe8MPsx0SVFjrd622_CgAAADU"]
[Thu Sep 17 15:43:12.888701 2026] [security2:error] [pid 60716:tid 61009] [client 34.154.248.240:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxe8MPsx0SVFjrd622_DAAAAHM"]
[Thu Sep 17 15:43:12.942092 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.219.37:57476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxe8MPsx0SVFjrd622_DQAAAEU"]
[Thu Sep 17 15:43:13.009558 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/gitlab/.env"] [unique_id "aqxe8cPsx0SVFjrd622_DgAAAF0"]
[Thu Sep 17 15:43:13.040584 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/deploy/.env"] [unique_id "aqxe8cPsx0SVFjrd622_EAAAAHY"]
[Thu Sep 17 15:43:13.238317 2026] [security2:error] [pid 60716:tid 60906] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/github/.env"] [unique_id "aqxe8cPsx0SVFjrd622_FQAAAA4"]
[Thu Sep 17 15:43:13.258620 2026] [core:error] [pid 60716:tid 60979] [client 34.95.193.102:56840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:13.258649 2026] [core:error] [pid 60716:tid 60979] [client 34.95.193.102:56840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:13.273352 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/build/.env"] [unique_id "aqxe8cPsx0SVFjrd622_GAAAAB0"]
[Thu Sep 17 15:43:13.320075 2026] [security2:error] [pid 60716:tid 61004] [client 169.58.197.253:54844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxe8cPsx0SVFjrd622_GgAAAG4"], referer: binance.com
[Thu Sep 17 15:43:13.355028 2026] [security2:error] [pid 60716:tid 60956] [client 34.154.248.240:60178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/core/phpinfo.php"] [unique_id "aqxe8cPsx0SVFjrd622_GwAAAD4"]
[Thu Sep 17 15:43:13.401774 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxe8cPsx0SVFjrd622_HAAAAHA"]
[Thu Sep 17 15:43:13.467275 2026] [security2:error] [pid 60716:tid 60913] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/actions/.env"] [unique_id "aqxe8cPsx0SVFjrd622_HQAAABU"]
[Thu Sep 17 15:43:13.502455 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/dist/.env"] [unique_id "aqxe8cPsx0SVFjrd622_IAAAACA"]
[Thu Sep 17 15:43:13.560767 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxe8cPsx0SVFjrd622_IgAAAE0"]
[Thu Sep 17 15:43:13.654236 2026] [autoindex:error] [pid 60716:tid 60989] [client 95.111.248.201:45046] AH01276: Cannot serve directory /home1/bejacks1/public_html/bejacksonauthor/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:43:13.695764 2026] [security2:error] [pid 60716:tid 60972] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/circleci/.env"] [unique_id "aqxe8cPsx0SVFjrd622_KQAAAE4"]
[Thu Sep 17 15:43:13.718933 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxe8cPsx0SVFjrd622_KgAAAAs"]
[Thu Sep 17 15:43:13.730526 2026] [security2:error] [pid 60716:tid 60950] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "aqxe8cPsx0SVFjrd622_KwAAADg"]
[Thu Sep 17 15:43:13.755224 2026] [core:error] [pid 60716:tid 60978] [client 34.95.193.102:56850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:13.755248 2026] [core:error] [pid 60716:tid 60978] [client 34.95.193.102:56850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:13.800468 2026] [security2:error] [pid 60716:tid 60939] [client 35.144.66.130:31754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe8cPsx0SVFjrd622_KAAALSI"], referer: https://www.endless-chronicles.com/4382086c56678d969714a6aa9c87d80248ae.mpeg
[Thu Sep 17 15:43:13.837971 2026] [security2:error] [pid 60716:tid 60942] [client 34.154.248.240:60180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.248.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.edmagik.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxe8cPsx0SVFjrd622_LgAAADA"]
[Thu Sep 17 15:43:13.875398 2026] [security2:error] [pid 60716:tid 60902] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxe8cPsx0SVFjrd622_LwAAAAo"]
[Thu Sep 17 15:43:13.924481 2026] [security2:error] [pid 60716:tid 60997] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/travis/.env"] [unique_id "aqxe8cPsx0SVFjrd622_MAAAAGc"]
[Thu Sep 17 15:43:13.958913 2026] [security2:error] [pid 60716:tid 60974] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/htdocs/.env"] [unique_id "aqxe8cPsx0SVFjrd622_MQAAAFA"]
[Thu Sep 17 15:43:14.029238 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxe8sPsx0SVFjrd622_MgAAADQ"]
[Thu Sep 17 15:43:14.153208 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/buildkite/.env"] [unique_id "aqxe8sPsx0SVFjrd622_NAAAABY"]
[Thu Sep 17 15:43:14.181954 2026] [security2:error] [pid 60716:tid 60897] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxe8sPsx0SVFjrd622_OAAAAAU"]
[Thu Sep 17 15:43:14.185862 2026] [security2:error] [pid 60716:tid 60970] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/www/.env"] [unique_id "aqxe8sPsx0SVFjrd622_OQAAAEw"]
[Thu Sep 17 15:43:14.242188 2026] [core:error] [pid 60716:tid 60955] [client 34.95.193.102:34234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:14.242205 2026] [core:error] [pid 60716:tid 60955] [client 34.95.193.102:34234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:14.299934 2026] [security2:error] [pid 60716:tid 60900] [client 79.116.89.151:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe8sPsx0SVFjrd622_OwAAAAg"]
[Thu Sep 17 15:43:14.300172 2026] [security2:error] [pid 60716:tid 60900] [client 79.116.89.151:65223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe8sPsx0SVFjrd622_OwAAAAg"]
[Thu Sep 17 15:43:14.337711 2026] [security2:error] [pid 60716:tid 60941] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxe8sPsx0SVFjrd622_PwAAAC8"]
[Thu Sep 17 15:43:14.381356 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mysql/.env"] [unique_id "aqxe8sPsx0SVFjrd622_QAAAAAc"]
[Thu Sep 17 15:43:14.413601 2026] [security2:error] [pid 60716:tid 60996] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/html/.env"] [unique_id "aqxe8sPsx0SVFjrd622_QQAAAGY"]
[Thu Sep 17 15:43:14.501397 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxe8sPsx0SVFjrd622_QgAAABg"]
[Thu Sep 17 15:43:14.610933 2026] [security2:error] [pid 60716:tid 61020] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/postgres/.env"] [unique_id "aqxe8sPsx0SVFjrd622_QwAAAH4"]
[Thu Sep 17 15:43:14.640530 2026] [security2:error] [pid 60716:tid 60984] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/live/.env"] [unique_id "aqxe8sPsx0SVFjrd622_RQAAAFo"]
[Thu Sep 17 15:43:14.667640 2026] [security2:error] [pid 60716:tid 60895] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxe8sPsx0SVFjrd622_SAAAAAM"]
[Thu Sep 17 15:43:14.730492 2026] [core:error] [pid 60716:tid 60919] [client 34.95.193.102:34238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:14.730511 2026] [core:error] [pid 60716:tid 60919] [client 34.95.193.102:34238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:14.825475 2026] [security2:error] [pid 60716:tid 60917] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxe8sPsx0SVFjrd622_SwAAABk"]
[Thu Sep 17 15:43:14.843490 2026] [security2:error] [pid 60716:tid 60952] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/mongodb/.env"] [unique_id "aqxe8sPsx0SVFjrd622_TwAAADo"]
[Thu Sep 17 15:43:14.869948 2026] [security2:error] [pid 60716:tid 60908] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "aqxe8sPsx0SVFjrd622_UAAAABA"]
[Thu Sep 17 15:43:14.985992 2026] [security2:error] [pid 60716:tid 60998] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxe8sPsx0SVFjrd622_UgAAAGg"]
[Thu Sep 17 15:43:15.025816 2026] [security2:error] [pid 60716:tid 60943] [client 35.144.66.130:31755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxe8sPsx0SVFjrd622_UQAAMUE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260614184753&hideliu=1&limit=100&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:43:15.046851 2026] [security2:error] [pid 60716:tid 60977] [client 74.7.230.20:34356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ldi.any.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxe88Psx0SVFjrd622_UwAAU04"]
[Thu Sep 17 15:43:15.076058 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/redis/.env"] [unique_id "aqxe88Psx0SVFjrd622_VAAAAFY"]
[Thu Sep 17 15:43:15.101001 2026] [security2:error] [pid 60716:tid 61001] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "aqxe88Psx0SVFjrd622_VQAAAGs"]
[Thu Sep 17 15:43:15.140777 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxe88Psx0SVFjrd622_VwAAAHg"]
[Thu Sep 17 15:43:15.220569 2026] [core:error] [pid 60716:tid 60928] [client 34.95.193.102:34242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:15.220587 2026] [core:error] [pid 60716:tid 60928] [client 34.95.193.102:34242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:15.295592 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxe88Psx0SVFjrd622_XQAAAEU"]
[Thu Sep 17 15:43:15.309430 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/elasticsearch/.env"] [unique_id "aqxe88Psx0SVFjrd622_XgAAAHY"]
[Thu Sep 17 15:43:15.328195 2026] [security2:error] [pid 60716:tid 60961] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "aqxe88Psx0SVFjrd622_XwAAAEM"]
[Thu Sep 17 15:43:15.448940 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxe88Psx0SVFjrd622_ZAAAAA4"]
[Thu Sep 17 15:43:15.541152 2026] [security2:error] [pid 60716:tid 60988] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/rabbitmq/.env"] [unique_id "aqxe88Psx0SVFjrd622_ZQAAAF4"]
[Thu Sep 17 15:43:15.555846 2026] [security2:error] [pid 60716:tid 60995] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "aqxe88Psx0SVFjrd622_ZgAAAGU"]
[Thu Sep 17 15:43:15.604574 2026] [security2:error] [pid 60716:tid 61004] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxe88Psx0SVFjrd622_aAAAAG4"]
[Thu Sep 17 15:43:15.718699 2026] [core:error] [pid 60716:tid 60926] [client 34.95.193.102:34252] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:15.718721 2026] [core:error] [pid 60716:tid 60926] [client 34.95.193.102:34252] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:15.760355 2026] [security2:error] [pid 60716:tid 60956] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxe88Psx0SVFjrd622_bQAAAD4"]
[Thu Sep 17 15:43:15.775906 2026] [security2:error] [pid 60716:tid 61006] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/kafka/.env"] [unique_id "aqxe88Psx0SVFjrd622_bgAAAHA"]
[Thu Sep 17 15:43:15.783934 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "aqxe88Psx0SVFjrd622_bwAAACQ"]
[Thu Sep 17 15:43:15.914335 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxe88Psx0SVFjrd622_dAAAAAQ"]
[Thu Sep 17 15:43:16.004708 2026] [security2:error] [pid 60716:tid 60989] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/queue/.env"] [unique_id "aqxe9MPsx0SVFjrd622_dQAAAF8"]
[Thu Sep 17 15:43:16.016271 2026] [security2:error] [pid 60716:tid 60903] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/symfony/.env"] [unique_id "aqxe9MPsx0SVFjrd622_dgAAAAs"]
[Thu Sep 17 15:43:16.076838 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxe9MPsx0SVFjrd622_dwAAABE"]
[Thu Sep 17 15:43:16.206971 2026] [core:error] [pid 60716:tid 60950] [client 34.95.193.102:34260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:16.206996 2026] [core:error] [pid 60716:tid 60950] [client 34.95.193.102:34260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:16.233560 2026] [security2:error] [pid 60716:tid 61002] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxe9MPsx0SVFjrd622_fAAAAGw"]
[Thu Sep 17 15:43:16.239575 2026] [security2:error] [pid 60716:tid 60939] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/worker/.env"] [unique_id "aqxe9MPsx0SVFjrd622_fQAAAC0"]
[Thu Sep 17 15:43:16.243553 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/wordpress/.env"] [unique_id "aqxe9MPsx0SVFjrd622_fgAAAAA"]
[Thu Sep 17 15:43:16.394264 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxe9MPsx0SVFjrd622_gQAAAGo"]
[Thu Sep 17 15:43:16.469380 2026] [security2:error] [pid 60716:tid 60934] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/job/.env"] [unique_id "aqxe9MPsx0SVFjrd622_hQAAACg"]
[Thu Sep 17 15:43:16.470760 2026] [security2:error] [pid 60716:tid 60935] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/wp/.env"] [unique_id "aqxe9MPsx0SVFjrd622_hgAAACk"]
[Thu Sep 17 15:43:16.551071 2026] [security2:error] [pid 60716:tid 60905] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxe9MPsx0SVFjrd622_iAAAAA0"]
[Thu Sep 17 15:43:16.693416 2026] [core:error] [pid 60716:tid 60955] [client 34.95.193.102:34266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:16.693445 2026] [core:error] [pid 60716:tid 60955] [client 34.95.193.102:34266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:16.697720 2026] [security2:error] [pid 60716:tid 60996] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/test/.env"] [unique_id "aqxe9MPsx0SVFjrd622_jQAAAGY"]
[Thu Sep 17 15:43:16.698106 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "aqxe9MPsx0SVFjrd622_jgAAAB4"]
[Thu Sep 17 15:43:16.709450 2026] [security2:error] [pid 60716:tid 60966] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxe9MPsx0SVFjrd622_jwAAAEg"]
[Thu Sep 17 15:43:16.864164 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxe9MPsx0SVFjrd622_kgAAABs"]
[Thu Sep 17 15:43:16.924232 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/drupal/.env"] [unique_id "aqxe9MPsx0SVFjrd622_lgAAACs"]
[Thu Sep 17 15:43:16.924410 2026] [security2:error] [pid 60716:tid 60985] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/qa/.env"] [unique_id "aqxe9MPsx0SVFjrd622_lwAAAFs"]
[Thu Sep 17 15:43:16.960847 2026] [security2:error] [pid 60716:tid 60973] [client 169.58.197.251:61696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxe9MPsx0SVFjrd622_mAAAAE8"], referer: binance.com
[Thu Sep 17 15:43:17.030250 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxe9cPsx0SVFjrd622_mgAAADo"]
[Thu Sep 17 15:43:17.151248 2026] [security2:error] [pid 60716:tid 60990] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/preview/.env"] [unique_id "aqxe9cPsx0SVFjrd622_nwAAAGA"]
[Thu Sep 17 15:43:17.151248 2026] [security2:error] [pid 60716:tid 60936] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/joomla/.env"] [unique_id "aqxe9cPsx0SVFjrd622_ngAAACo"]
[Thu Sep 17 15:43:17.195472 2026] [security2:error] [pid 60716:tid 60980] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxe9cPsx0SVFjrd622_owAAAFY"]
[Thu Sep 17 15:43:17.263350 2026] [core:error] [pid 60716:tid 61014] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:17.263368 2026] [core:error] [pid 60716:tid 61014] [client 34.95.193.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:17.350027 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxe9cPsx0SVFjrd622_qAAAADM"]
[Thu Sep 17 15:43:17.383887 2026] [security2:error] [pid 60716:tid 60962] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/magento/.env"] [unique_id "aqxe9cPsx0SVFjrd622_qQAAAEQ"]
[Thu Sep 17 15:43:17.385593 2026] [security2:error] [pid 60716:tid 60910] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/beta/.env"] [unique_id "aqxe9cPsx0SVFjrd622_qgAAABI"]
[Thu Sep 17 15:43:17.507977 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxe9cPsx0SVFjrd622_rwAAADw"]
[Thu Sep 17 15:43:17.611921 2026] [security2:error] [pid 60716:tid 60963] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/shopify/.env"] [unique_id "aqxe9cPsx0SVFjrd622_sAAAAEU"]
[Thu Sep 17 15:43:17.612995 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/uat/.env"] [unique_id "aqxe9cPsx0SVFjrd622_sQAAAHY"]
[Thu Sep 17 15:43:17.661375 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxe9cPsx0SVFjrd622_swAAAGE"]
[Thu Sep 17 15:43:17.815238 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxe9cPsx0SVFjrd622_twAAAA4"]
[Thu Sep 17 15:43:17.840137 2026] [security2:error] [pid 60716:tid 60988] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/stage/.env"] [unique_id "aqxe9cPsx0SVFjrd622_uQAAAF4"]
[Thu Sep 17 15:43:17.840137 2026] [security2:error] [pid 60716:tid 60949] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/prestashop/.env"] [unique_id "aqxe9cPsx0SVFjrd622_uAAAADc"]
[Thu Sep 17 15:43:17.975875 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxe9cPsx0SVFjrd622_vQAAADI"]
[Thu Sep 17 15:43:18.067241 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/codeigniter/.env"] [unique_id "aqxe9sPsx0SVFjrd622_vgAAAAY"]
[Thu Sep 17 15:43:18.067283 2026] [security2:error] [pid 60716:tid 60951] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "aqxe9sPsx0SVFjrd622_vwAAADk"]
[Thu Sep 17 15:43:18.129797 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxe9sPsx0SVFjrd622_wgAAAFg"]
[Thu Sep 17 15:43:18.204125 2026] [security2:error] [pid 60716:tid 60956] [client 50.6.53.48:18910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.6.50.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intolovinghomes.com.au"] [uri "/wp-cron.php"] [unique_id "aqxe9sPsx0SVFjrd622_xgAAAD4"]
[Thu Sep 17 15:43:18.286511 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxe9sPsx0SVFjrd622_yAAAABE"]
[Thu Sep 17 15:43:18.294798 2026] [security2:error] [pid 60716:tid 60950] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/production/.env"] [unique_id "aqxe9sPsx0SVFjrd622_yQAAADg"]
[Thu Sep 17 15:43:18.294805 2026] [security2:error] [pid 60716:tid 61002] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/cakephp/.env"] [unique_id "aqxe9sPsx0SVFjrd622_ygAAAGw"]
[Thu Sep 17 15:43:18.441196 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxe9sPsx0SVFjrd622_zAAAAFA"]
[Thu Sep 17 15:43:18.521819 2026] [security2:error] [pid 60716:tid 60948] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/zend/.env"] [unique_id "aqxe9sPsx0SVFjrd622_0QAAADY"]
[Thu Sep 17 15:43:18.525752 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.135.226:40956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.iestimatellc.com"] [uri "/___proxy_subdomain_cpanel/config/app/.env"] [unique_id "aqxe9sPsx0SVFjrd622_0gAAABY"]
[Thu Sep 17 15:43:18.595252 2026] [security2:error] [pid 60716:tid 60897] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxe9sPsx0SVFjrd622_0wAAAAU"]
[Thu Sep 17 15:43:18.749774 2026] [security2:error] [pid 60716:tid 60955] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/yii/.env"] [unique_id "aqxe9sPsx0SVFjrd622_2wAAAD0"]
[Thu Sep 17 15:43:18.758420 2026] [security2:error] [pid 60716:tid 60923] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxe9sPsx0SVFjrd622_3QAAAB4"]
[Thu Sep 17 15:43:18.778419 2026] [security2:error] [pid 60716:tid 60996] [client 34.166.135.226:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/phpinfo.php"] [unique_id "aqxe9sPsx0SVFjrd622_3AAAAGY"]
[Thu Sep 17 15:43:18.823495 2026] [security2:error] [pid 60716:tid 60899] [client 103.131.71.233:15481] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "darfieldearthship.com"] [uri "/robots.txt"] [unique_id "aqxe9sPsx0SVFjrd622_4AAAAAc"]
[Thu Sep 17 15:43:18.913604 2026] [security2:error] [pid 60716:tid 60940] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxe9sPsx0SVFjrd622_4gAAAC4"]
[Thu Sep 17 15:43:18.977430 2026] [security2:error] [pid 60716:tid 60957] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/laravel5/.env"] [unique_id "aqxe9sPsx0SVFjrd622_5gAAAD8"]
[Thu Sep 17 15:43:18.981352 2026] [security2:error] [pid 60716:tid 60942] [client 103.61.184.148:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe9sPsx0SVFjrd622_5wAAADA"]
[Thu Sep 17 15:43:18.981440 2026] [security2:error] [pid 60716:tid 60942] [client 103.61.184.148:53249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxe9sPsx0SVFjrd622_5wAAADA"]
[Thu Sep 17 15:43:19.067765 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxe98Psx0SVFjrd622_6AAAAAw"]
[Thu Sep 17 15:43:19.203568 2026] [security2:error] [pid 60716:tid 60998] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "aqxe98Psx0SVFjrd622_8AAAAGg"]
[Thu Sep 17 15:43:19.221141 2026] [security2:error] [pid 60716:tid 60937] [client 148.227.75.216:61551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe98Psx0SVFjrd622_8QAAACs"]
[Thu Sep 17 15:43:19.226968 2026] [security2:error] [pid 60716:tid 60937] [client 148.227.75.216:61551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxe98Psx0SVFjrd622_8QAAACs"]
[Thu Sep 17 15:43:19.233858 2026] [security2:error] [pid 60716:tid 60943] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxe98Psx0SVFjrd622_8gAAADE"]
[Thu Sep 17 15:43:19.399614 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxe98Psx0SVFjrd622_8wAAABo"]
[Thu Sep 17 15:43:19.430625 2026] [security2:error] [pid 60716:tid 60928] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "aqxe98Psx0SVFjrd622_9AAAACM"]
[Thu Sep 17 15:43:19.466381 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.135.226:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/info.php"] [unique_id "aqxe98Psx0SVFjrd622_9QAAAFY"]
[Thu Sep 17 15:43:19.553478 2026] [security2:error] [pid 60716:tid 60953] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxe98Psx0SVFjrd622_-QAAADs"]
[Thu Sep 17 15:43:19.658506 2026] [security2:error] [pid 60716:tid 61010] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "aqxe98Psx0SVFjrd622__wAAAHQ"]
[Thu Sep 17 15:43:19.711148 2026] [security2:error] [pid 60716:tid 61008] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxe98Psx0SVFjrd623AAwAAAHI"]
[Thu Sep 17 15:43:19.833430 2026] [security2:error] [pid 60716:tid 61011] [client 116.179.37.83:17873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cowboywithacamera.com"] [uri "/index.php"] [unique_id "aqxe98Psx0SVFjrd623ACAAAAHU"]
[Thu Sep 17 15:43:19.870126 2026] [security2:error] [pid 60716:tid 60949] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxe98Psx0SVFjrd623ACwAAADc"]
[Thu Sep 17 15:43:19.887758 2026] [security2:error] [pid 60716:tid 61004] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/api/v1/.env"] [unique_id "aqxe98Psx0SVFjrd623ADAAAAG4"]
[Thu Sep 17 15:43:19.951436 2026] [security2:error] [pid 60716:tid 60961] [client 43.173.182.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxe98Psx0SVFjrd623ABgAAAEM"]
[Thu Sep 17 15:43:19.951444 2026] [security2:error] [pid 60716:tid 60906] [client 43.173.176.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxe98Psx0SVFjrd623ACgAAAA4"]
[Thu Sep 17 15:43:20.027764 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxe-MPsx0SVFjrd623ADwAAAAs"]
[Thu Sep 17 15:43:20.116308 2026] [security2:error] [pid 60716:tid 61017] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/api/v2/.env"] [unique_id "aqxe-MPsx0SVFjrd623AFQAAAHs"]
[Thu Sep 17 15:43:20.142803 2026] [security2:error] [pid 60716:tid 60995] [client 34.166.135.226:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/php.php"] [unique_id "aqxe-MPsx0SVFjrd623AGAAAAGU"]
[Thu Sep 17 15:43:20.184395 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxe-MPsx0SVFjrd623AGwAAADQ"]
[Thu Sep 17 15:43:20.338860 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxe-MPsx0SVFjrd623AHQAAACI"]
[Thu Sep 17 15:43:20.344640 2026] [security2:error] [pid 60716:tid 60897] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/rest/.env"] [unique_id "aqxe-MPsx0SVFjrd623AHgAAAAU"]
[Thu Sep 17 15:43:20.393240 2026] [security2:error] [pid 60716:tid 60969] [client 192.178.6.3:53963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxe-MPsx0SVFjrd623AHwAAAEs"]
[Thu Sep 17 15:43:20.497621 2026] [security2:error] [pid 60716:tid 61020] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxe-MPsx0SVFjrd623AJAAAAH4"]
[Thu Sep 17 15:43:20.571860 2026] [security2:error] [pid 60716:tid 60942] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/graphql/.env"] [unique_id "aqxe-MPsx0SVFjrd623AKQAAADA"]
[Thu Sep 17 15:43:20.685337 2026] [security2:error] [pid 60716:tid 60907] [client 14.96.156.146:51829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe-MPsx0SVFjrd623AKwAAAA8"]
[Thu Sep 17 15:43:20.685501 2026] [security2:error] [pid 60716:tid 60907] [client 14.96.156.146:51829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxe-MPsx0SVFjrd623AKwAAAA8"]
[Thu Sep 17 15:43:20.712127 2026] [security2:error] [pid 60716:tid 60895] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxe-MPsx0SVFjrd623ALAAAAAM"]
[Thu Sep 17 15:43:20.801153 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/gateway/.env"] [unique_id "aqxe-MPsx0SVFjrd623AOQAAAFc"]
[Thu Sep 17 15:43:20.832801 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.135.226:42248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/i.php"] [unique_id "aqxe-MPsx0SVFjrd623AOgAAAHo"]
[Thu Sep 17 15:43:20.873805 2026] [security2:error] [pid 60716:tid 60947] [client 169.58.197.253:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxe-MPsx0SVFjrd623APAAAADU"], referer: binance.com
[Thu Sep 17 15:43:20.876104 2026] [security2:error] [pid 60716:tid 60984] [client 57.141.14.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iradtech.com"] [uri "/index.php"] [unique_id "aqxe9sPsx0SVFjrd622_4QAAAFo"]
[Thu Sep 17 15:43:20.878220 2026] [security2:error] [pid 60716:tid 60917] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxe-MPsx0SVFjrd623APQAAABk"]
[Thu Sep 17 15:43:21.029202 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/microservice/.env"] [unique_id "aqxe-cPsx0SVFjrd623APgAAABM"]
[Thu Sep 17 15:43:21.032500 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxe-cPsx0SVFjrd623APwAAAG8"]
[Thu Sep 17 15:43:21.194619 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxe-cPsx0SVFjrd623ARgAAAHE"]
[Thu Sep 17 15:43:21.257376 2026] [security2:error] [pid 60716:tid 60920] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "aqxe-cPsx0SVFjrd623ASAAAABw"]
[Thu Sep 17 15:43:21.356153 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxe-cPsx0SVFjrd623ATAAAABU"]
[Thu Sep 17 15:43:21.484407 2026] [security2:error] [pid 60716:tid 60961] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/api/v3/.env"] [unique_id "aqxe-cPsx0SVFjrd623ATgAAAEM"]
[Thu Sep 17 15:43:21.515313 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxe-cPsx0SVFjrd623ATwAAACA"]
[Thu Sep 17 15:43:21.524785 2026] [security2:error] [pid 60716:tid 60926] [client 34.166.135.226:42254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/pi.php"] [unique_id "aqxe-cPsx0SVFjrd623AUAAAACE"]
[Thu Sep 17 15:43:21.587054 2026] [security2:error] [pid 60716:tid 60979] [client 103.131.71.233:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxe-cPsx0SVFjrd623ASwAAAFU"]
[Thu Sep 17 15:43:21.587085 2026] [security2:error] [pid 60716:tid 60979] [client 103.131.71.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxe-cPsx0SVFjrd623ASwAAAFU"]
[Thu Sep 17 15:43:21.619747 2026] [security2:error] [pid 60716:tid 60963] [client 103.131.71.233:58675] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "darfieldearthship.com"] [uri "/robots.txt"] [unique_id "aqxe-cPsx0SVFjrd623ASQAAAEU"]
[Thu Sep 17 15:43:21.670832 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxe-cPsx0SVFjrd623AWQAAABE"]
[Thu Sep 17 15:43:21.711562 2026] [security2:error] [pid 60716:tid 60950] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/api/dev/.env"] [unique_id "aqxe-cPsx0SVFjrd623AWgAAADg"]
[Thu Sep 17 15:43:21.828036 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxe-cPsx0SVFjrd623AXAAAAGo"]
[Thu Sep 17 15:43:21.939331 2026] [security2:error] [pid 60716:tid 60983] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/api/staging/.env"] [unique_id "aqxe-cPsx0SVFjrd623AYAAAAFk"]
[Thu Sep 17 15:43:21.985678 2026] [security2:error] [pid 60716:tid 60902] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxe-cPsx0SVFjrd623AYQAAAAo"]
[Thu Sep 17 15:43:22.143925 2026] [security2:error] [pid 60716:tid 61020] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxe-sPsx0SVFjrd623AYwAAAH4"]
[Thu Sep 17 15:43:22.173084 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/vendor/.env"] [unique_id "aqxe-sPsx0SVFjrd623AZgAAAAc"]
[Thu Sep 17 15:43:22.214873 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.135.226:42268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/pinfo.php"] [unique_id "aqxe-sPsx0SVFjrd623AagAAAA0"]
[Thu Sep 17 15:43:22.277792 2026] [security2:error] [pid 60716:tid 60927] [client 177.44.133.72:63016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe-sPsx0SVFjrd623AbAAAACI"]
[Thu Sep 17 15:43:22.277905 2026] [security2:error] [pid 60716:tid 60927] [client 177.44.133.72:63016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxe-sPsx0SVFjrd623AbAAAACI"]
[Thu Sep 17 15:43:22.301782 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxe-sPsx0SVFjrd623AbwAAAGA"]
[Thu Sep 17 15:43:22.401170 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/lib/.env"] [unique_id "aqxe-sPsx0SVFjrd623AcwAAAFc"]
[Thu Sep 17 15:43:22.458722 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxe-sPsx0SVFjrd623AdAAAAG0"]
[Thu Sep 17 15:43:22.620758 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxe-sPsx0SVFjrd623AeAAAABo"]
[Thu Sep 17 15:43:22.630065 2026] [security2:error] [pid 60716:tid 60965] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/resources/.env"] [unique_id "aqxe-sPsx0SVFjrd623AegAAAEc"]
[Thu Sep 17 15:43:22.783438 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxe-sPsx0SVFjrd623AfgAAABI"]
[Thu Sep 17 15:43:22.858444 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/assets/.env"] [unique_id "aqxe-sPsx0SVFjrd623AfwAAABM"]
[Thu Sep 17 15:43:22.897722 2026] [security2:error] [pid 60716:tid 60964] [client 34.166.135.226:42272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/test.php"] [unique_id "aqxe-sPsx0SVFjrd623AgAAAAEY"]
[Thu Sep 17 15:43:22.980448 2026] [security2:error] [pid 60716:tid 61009] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxe-sPsx0SVFjrd623AgQAAAHM"]
[Thu Sep 17 15:43:23.086208 2026] [security2:error] [pid 60716:tid 60968] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/uploads/.env"] [unique_id "aqxe-8Psx0SVFjrd623AggAAAEo"]
[Thu Sep 17 15:43:23.140119 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxe-8Psx0SVFjrd623AhAAAAGY"]
[Thu Sep 17 15:43:23.313494 2026] [security2:error] [pid 60716:tid 60932] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxe-8Psx0SVFjrd623AiAAAACY"]
[Thu Sep 17 15:43:23.313530 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/internal/.env"] [unique_id "aqxe-8Psx0SVFjrd623AiQAAAAY"]
[Thu Sep 17 15:43:23.474320 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxe-8Psx0SVFjrd623AigAAAEM"]
[Thu Sep 17 15:43:23.484878 2026] [security2:error] [pid 60716:tid 61010] [client 143.105.152.240:33251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe-8Psx0SVFjrd623AiwAAAHQ"]
[Thu Sep 17 15:43:23.485027 2026] [security2:error] [pid 60716:tid 61010] [client 143.105.152.240:33251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxe-8Psx0SVFjrd623AiwAAAHQ"]
[Thu Sep 17 15:43:23.541759 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/tools/.env"] [unique_id "aqxe-8Psx0SVFjrd623AjwAAAB0"]
[Thu Sep 17 15:43:23.632385 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxe-8Psx0SVFjrd623AlQAAAFU"]
[Thu Sep 17 15:43:23.662711 2026] [security2:error] [pid 60716:tid 60925] [client 103.131.71.233:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.darfieldearthship.com"] [uri "/index.php"] [unique_id "aqxe-8Psx0SVFjrd623AkQAAACA"]
[Thu Sep 17 15:43:23.677474 2026] [core:error] [pid 60716:tid 60956] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:23.677492 2026] [core:error] [pid 60716:tid 60956] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:23.717791 2026] [security2:error] [pid 60716:tid 60949] [client 103.131.71.233:29869] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.darfieldearthship.com"] [uri "/robots.txt"] [unique_id "aqxe-8Psx0SVFjrd623AjQAAADc"]
[Thu Sep 17 15:43:23.773879 2026] [security2:error] [pid 60716:tid 60950] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/scripts/.env"] [unique_id "aqxe-8Psx0SVFjrd623AmgAAADg"]
[Thu Sep 17 15:43:23.790320 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxe-8Psx0SVFjrd623AmwAAAA4"]
[Thu Sep 17 15:43:23.844863 2026] [security2:error] [pid 60716:tid 60962] [client 164.92.220.0:43630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.220.92.164.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxe-8Psx0SVFjrd623AnAAAAEQ"]
[Thu Sep 17 15:43:23.944847 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxe-8Psx0SVFjrd623AoAAAADI"]
[Thu Sep 17 15:43:24.000940 2026] [security2:error] [pid 60716:tid 60999] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/bin/.env"] [unique_id "aqxe-8Psx0SVFjrd623AoQAAAGk"]
[Thu Sep 17 15:43:24.109831 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxe_MPsx0SVFjrd623AowAAADQ"]
[Thu Sep 17 15:43:24.230601 2026] [security2:error] [pid 60716:tid 60939] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/sbin/.env"] [unique_id "aqxe_MPsx0SVFjrd623ApwAAAC0"]
[Thu Sep 17 15:43:24.265517 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxe_MPsx0SVFjrd623AqQAAAFk"]
[Thu Sep 17 15:43:24.407832 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.135.226:48740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/p.php"] [unique_id "aqxe_MPsx0SVFjrd623AqwAAABY"]
[Thu Sep 17 15:43:24.462596 2026] [security2:error] [pid 60716:tid 60942] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "aqxe_MPsx0SVFjrd623ArgAAADA"]
[Thu Sep 17 15:43:24.470291 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxe_MPsx0SVFjrd623ArAAAAFs"]
[Thu Sep 17 15:43:24.624497 2026] [security2:error] [pid 60716:tid 60960] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxe_MPsx0SVFjrd623AsAAAAEI"]
[Thu Sep 17 15:43:24.689156 2026] [security2:error] [pid 60716:tid 60943] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "aqxe_MPsx0SVFjrd623AtQAAADE"]
[Thu Sep 17 15:43:24.782846 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxe_MPsx0SVFjrd623AtwAAAEc"]
[Thu Sep 17 15:43:24.841552 2026] [security2:error] [pid 60716:tid 60948] [client 79.116.89.151:49477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe_MPsx0SVFjrd623AuAAAADY"]
[Thu Sep 17 15:43:24.841761 2026] [security2:error] [pid 60716:tid 60948] [client 79.116.89.151:49477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxe_MPsx0SVFjrd623AuAAAADY"]
[Thu Sep 17 15:43:24.917316 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/dashboard/.env"] [unique_id "aqxe_MPsx0SVFjrd623AuwAAACw"]
[Thu Sep 17 15:43:24.923157 2026] [core:error] [pid 60716:tid 60945] [client 38.128.156.113:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:24.923175 2026] [core:error] [pid 60716:tid 60945] [client 38.128.156.113:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:24.936967 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxe_MPsx0SVFjrd623AvQAAAEs"]
[Thu Sep 17 15:43:25.082456 2026] [security2:error] [pid 60716:tid 61014] [client 136.158.61.34:47294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe_cPsx0SVFjrd623AxQAAAHg"]
[Thu Sep 17 15:43:25.082633 2026] [security2:error] [pid 60716:tid 61014] [client 136.158.61.34:47294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxe_cPsx0SVFjrd623AxQAAAHg"]
[Thu Sep 17 15:43:25.097130 2026] [security2:error] [pid 60716:tid 60928] [client 34.166.135.226:48756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/debug.php"] [unique_id "aqxe_cPsx0SVFjrd623AyQAAACM"]
[Thu Sep 17 15:43:25.144265 2026] [security2:error] [pid 60716:tid 60868] [remote 47.128.111.225:62984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lemuspools.com"] [uri "/reviews/product/468065"] [unique_id "aqxe_cPsx0SVFjrd623A0gAAZmo"]
[Thu Sep 17 15:43:25.149428 2026] [security2:error] [pid 60716:tid 60994] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/panel/.env"] [unique_id "aqxe_cPsx0SVFjrd623A0wAAAGQ"]
[Thu Sep 17 15:43:25.193239 2026] [core:error] [pid 60716:tid 60932] [client 104.222.46.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:25.193261 2026] [core:error] [pid 60716:tid 60932] [client 104.222.46.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:25.376670 2026] [security2:error] [pid 60716:tid 60988] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "aqxe_cPsx0SVFjrd623A4gAAAF4"]
[Thu Sep 17 15:43:25.490120 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.219.37:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxe_cPsx0SVFjrd623A5wAAADI"]
[Thu Sep 17 15:43:25.492372 2026] [security2:error] [pid 60716:tid 60933] [client 164.92.220.0:43646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxe_MPsx0SVFjrd623AqgAAACc"]
[Thu Sep 17 15:43:25.606296 2026] [security2:error] [pid 60716:tid 60946] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "aqxe_cPsx0SVFjrd623A6QAAADQ"]
[Thu Sep 17 15:43:25.787571 2026] [security2:error] [pid 60716:tid 61000] [client 34.166.135.226:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxe_cPsx0SVFjrd623A7QAAAGo"]
[Thu Sep 17 15:43:25.832690 2026] [security2:error] [pid 60716:tid 61017] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "aqxe_cPsx0SVFjrd623A7wAAAHs"]
[Thu Sep 17 15:43:25.852386 2026] [core:error] [pid 60716:tid 60952] [client 104.237.245.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:25.852415 2026] [core:error] [pid 60716:tid 60952] [client 104.237.245.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:25.951808 2026] [security2:error] [pid 60716:tid 60941] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxe_cPsx0SVFjrd623A8gAAAC8"]
[Thu Sep 17 15:43:26.061207 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.220.229:37866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/store/.env"] [unique_id "aqxe_sPsx0SVFjrd623A8wAAAFc"]
[Thu Sep 17 15:43:26.106769 2026] [security2:error] [pid 60716:tid 61002] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxe_sPsx0SVFjrd623A9QAAAGw"]
[Thu Sep 17 15:43:26.229475 2026] [fcgid:warn] [pid 60716:tid 60924] (70014)End of file found: [client 66.132.172.136:6692] mod_fcgid: can't get data from http client
[Thu Sep 17 15:43:26.272794 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxe_sPsx0SVFjrd623A_AAAAGA"]
[Thu Sep 17 15:43:26.288942 2026] [security2:error] [pid 60716:tid 60997] [client 169.58.197.251:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-filter-sentinel.php"] [unique_id "aqxe_sPsx0SVFjrd623A_QAAAGc"], referer: binance.com
[Thu Sep 17 15:43:26.430169 2026] [security2:error] [pid 60716:tid 60984] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxe_sPsx0SVFjrd623A_wAAAFo"]
[Thu Sep 17 15:43:26.475498 2026] [security2:error] [pid 60716:tid 60992] [client 34.166.135.226:48788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/test/phpinfo.php"] [unique_id "aqxe_sPsx0SVFjrd623BAAAAAGI"]
[Thu Sep 17 15:43:26.582636 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxe_sPsx0SVFjrd623BBAAAACo"]
[Thu Sep 17 15:43:26.740718 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxe_sPsx0SVFjrd623BCgAAADU"]
[Thu Sep 17 15:43:26.744791 2026] [security2:error] [pid 60716:tid 60948] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/saas/.env"] [unique_id "aqxe_sPsx0SVFjrd623BCwAAADY"]
[Thu Sep 17 15:43:26.897389 2026] [security2:error] [pid 60716:tid 60932] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxe_sPsx0SVFjrd623BEQAAACY"]
[Thu Sep 17 15:43:26.971488 2026] [security2:error] [pid 60716:tid 61005] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "aqxe_sPsx0SVFjrd623BEwAAAG8"]
[Thu Sep 17 15:43:27.052510 2026] [security2:error] [pid 60716:tid 61008] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxe_8Psx0SVFjrd623BFgAAAHI"]
[Thu Sep 17 15:43:27.163382 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.135.226:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxe_8Psx0SVFjrd623BHQAAAAY"]
[Thu Sep 17 15:43:27.198851 2026] [security2:error] [pid 60716:tid 61004] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "aqxe_8Psx0SVFjrd623BHgAAAG4"]
[Thu Sep 17 15:43:27.210259 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxe_8Psx0SVFjrd623BIQAAACE"]
[Thu Sep 17 15:43:27.367705 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxe_8Psx0SVFjrd623BKAAAADw"]
[Thu Sep 17 15:43:27.425685 2026] [security2:error] [pid 60716:tid 60962] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/admin-panel/.env"] [unique_id "aqxe_8Psx0SVFjrd623BKgAAAEQ"]
[Thu Sep 17 15:43:27.535236 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxe_8Psx0SVFjrd623BLAAAAAA"]
[Thu Sep 17 15:43:27.655208 2026] [security2:error] [pid 60716:tid 60946] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/control-panel/.env"] [unique_id "aqxe_8Psx0SVFjrd623BLwAAADQ"]
[Thu Sep 17 15:43:27.688806 2026] [security2:error] [pid 60716:tid 60973] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxe_8Psx0SVFjrd623BMgAAAE8"]
[Thu Sep 17 15:43:27.841819 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxe_8Psx0SVFjrd623BNAAAAF0"]
[Thu Sep 17 15:43:27.849426 2026] [security2:error] [pid 60716:tid 60934] [client 34.166.135.226:48812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/old/phpinfo.php"] [unique_id "aqxe_8Psx0SVFjrd623BNgAAACg"]
[Thu Sep 17 15:43:27.885845 2026] [security2:error] [pid 60716:tid 60974] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/user-panel/.env"] [unique_id "aqxe_8Psx0SVFjrd623BNwAAAFA"]
[Thu Sep 17 15:43:27.996698 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxe_8Psx0SVFjrd623BOAAAABY"]
[Thu Sep 17 15:43:28.115780 2026] [security2:error] [pid 60716:tid 60952] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "aqxfAMPsx0SVFjrd623BOwAAADo"]
[Thu Sep 17 15:43:28.151719 2026] [security2:error] [pid 60716:tid 60942] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxfAMPsx0SVFjrd623BPQAAADA"]
[Thu Sep 17 15:43:28.313707 2026] [security2:error] [pid 60716:tid 61015] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxfAMPsx0SVFjrd623BQQAAAHk"]
[Thu Sep 17 15:43:28.350610 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/express/.env"] [unique_id "aqxfAMPsx0SVFjrd623BRQAAAG0"]
[Thu Sep 17 15:43:28.467649 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxfAMPsx0SVFjrd623BRwAAACI"]
[Thu Sep 17 15:43:28.538199 2026] [security2:error] [pid 60716:tid 61002] [client 34.166.135.226:48828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfAMPsx0SVFjrd623BSQAAAGw"]
[Thu Sep 17 15:43:28.582200 2026] [security2:error] [pid 60716:tid 60965] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/next/.env"] [unique_id "aqxfAMPsx0SVFjrd623BSgAAAEc"]
[Thu Sep 17 15:43:28.621325 2026] [security2:error] [pid 60716:tid 60917] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxfAMPsx0SVFjrd623BTwAAABk"]
[Thu Sep 17 15:43:28.773665 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxfAMPsx0SVFjrd623BWAAAAGE"]
[Thu Sep 17 15:43:28.809243 2026] [security2:error] [pid 60716:tid 60932] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/nuxt/.env"] [unique_id "aqxfAMPsx0SVFjrd623BWgAAACY"]
[Thu Sep 17 15:43:28.941525 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxfAMPsx0SVFjrd623BXAAAAG8"]
[Thu Sep 17 15:43:29.036354 2026] [security2:error] [pid 60716:tid 61008] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/nest/.env"] [unique_id "aqxfAcPsx0SVFjrd623BXQAAAHI"]
[Thu Sep 17 15:43:29.098679 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxfAcPsx0SVFjrd623BXgAAACU"]
[Thu Sep 17 15:43:29.220953 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.135.226:48830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/public/phpinfo.php"] [unique_id "aqxfAcPsx0SVFjrd623BYwAAAB0"]
[Thu Sep 17 15:43:29.254283 2026] [security2:error] [pid 60716:tid 61004] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxfAcPsx0SVFjrd623BZAAAAG4"]
[Thu Sep 17 15:43:29.264881 2026] [security2:error] [pid 60716:tid 60949] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/react/.env"] [unique_id "aqxfAcPsx0SVFjrd623BZQAAADc"]
[Thu Sep 17 15:43:29.409713 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxfAcPsx0SVFjrd623BZwAAABw"]
[Thu Sep 17 15:43:29.491746 2026] [security2:error] [pid 60716:tid 60913] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/vue/.env"] [unique_id "aqxfAcPsx0SVFjrd623BaAAAABU"]
[Thu Sep 17 15:43:29.563620 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxfAcPsx0SVFjrd623BaQAAAEU"]
[Thu Sep 17 15:43:29.718575 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxfAcPsx0SVFjrd623BcQAAAEQ"]
[Thu Sep 17 15:43:29.721417 2026] [security2:error] [pid 60716:tid 60975] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/angular/.env"] [unique_id "aqxfAcPsx0SVFjrd623BcgAAAFE"]
[Thu Sep 17 15:43:29.779932 2026] [security2:error] [pid 60716:tid 60911] [client 103.61.184.148:53817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfAcPsx0SVFjrd623BdAAAABM"]
[Thu Sep 17 15:43:29.780040 2026] [security2:error] [pid 60716:tid 60911] [client 103.61.184.148:53817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfAcPsx0SVFjrd623BdAAAABM"]
[Thu Sep 17 15:43:29.878411 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxfAcPsx0SVFjrd623BdQAAAFk"]
[Thu Sep 17 15:43:29.882525 2026] [security2:error] [pid 60716:tid 60976] [client 169.58.197.253:55858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxfAcPsx0SVFjrd623BdgAAAFI"], referer: binance.com
[Thu Sep 17 15:43:29.938478 2026] [security2:error] [pid 60716:tid 60892] [client 148.227.75.216:54723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfAcPsx0SVFjrd623BegAAAAA"]
[Thu Sep 17 15:43:29.947852 2026] [security2:error] [pid 60716:tid 60892] [client 148.227.75.216:54723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfAcPsx0SVFjrd623BegAAAAA"]
[Thu Sep 17 15:43:29.951672 2026] [security2:error] [pid 60716:tid 60894] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/svelte/.env"] [unique_id "aqxfAcPsx0SVFjrd623BewAAAAI"]
[Thu Sep 17 15:43:30.014905 2026] [core:error] [pid 60716:tid 60903] [client 104.194.198.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.014928 2026] [core:error] [pid 60716:tid 60903] [client 104.194.198.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.015216 2026] [core:error] [pid 60716:tid 60934] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.015229 2026] [core:error] [pid 60716:tid 60934] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.033631 2026] [security2:error] [pid 60716:tid 60942] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxfAsPsx0SVFjrd623BgAAAADA"]
[Thu Sep 17 15:43:30.181933 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/vite/.env"] [unique_id "aqxfAsPsx0SVFjrd623BhAAAAG0"]
[Thu Sep 17 15:43:30.191391 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxfAsPsx0SVFjrd623BhQAAACk"]
[Thu Sep 17 15:43:30.352688 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxfAsPsx0SVFjrd623BiwAAACo"]
[Thu Sep 17 15:43:30.409252 2026] [security2:error] [pid 60716:tid 60895] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "aqxfAsPsx0SVFjrd623BkAAAAAM"]
[Thu Sep 17 15:43:30.447820 2026] [core:error] [pid 60716:tid 60984] [client 104.194.198.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.447842 2026] [core:error] [pid 60716:tid 60984] [client 104.194.198.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.474182 2026] [security2:error] [pid 60716:tid 60947] [client 40.81.232.68:61900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "aqxfAsPsx0SVFjrd623BkgAAADU"], referer: binance.com
[Thu Sep 17 15:43:30.512741 2026] [security2:error] [pid 60716:tid 60966] [client 201.80.0.88:32077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfAsPsx0SVFjrd623BjgAASFc"]
[Thu Sep 17 15:43:30.513895 2026] [security2:error] [pid 60716:tid 60967] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxfAsPsx0SVFjrd623BkwAAAEk"]
[Thu Sep 17 15:43:30.642676 2026] [security2:error] [pid 60716:tid 60969] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/backups/.env"] [unique_id "aqxfAsPsx0SVFjrd623BlQAAAEs"]
[Thu Sep 17 15:43:30.672281 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxfAsPsx0SVFjrd623BmAAAABI"]
[Thu Sep 17 15:43:30.720784 2026] [security2:error] [pid 60716:tid 60948] [client 34.166.135.226:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/php-info.php"] [unique_id "aqxfAsPsx0SVFjrd623BmgAAADY"]
[Thu Sep 17 15:43:30.828287 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxfAsPsx0SVFjrd623BngAAAG8"]
[Thu Sep 17 15:43:30.834237 2026] [core:error] [pid 60716:tid 60925] [client 104.194.198.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.834260 2026] [core:error] [pid 60716:tid 60925] [client 104.194.198.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:30.870282 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "aqxfAsPsx0SVFjrd623BoAAAAB0"]
[Thu Sep 17 15:43:30.982398 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxfAsPsx0SVFjrd623BowAAACE"]
[Thu Sep 17 15:43:31.102242 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/tmp/.env"] [unique_id "aqxfA8Psx0SVFjrd623BpgAAAHY"]
[Thu Sep 17 15:43:31.137519 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxfA8Psx0SVFjrd623BpwAAABw"]
[Thu Sep 17 15:43:31.235079 2026] [security2:error] [pid 60716:tid 60979] [client 14.96.156.146:52540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfA8Psx0SVFjrd623BrAAAAFU"]
[Thu Sep 17 15:43:31.235210 2026] [security2:error] [pid 60716:tid 60979] [client 14.96.156.146:52540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfA8Psx0SVFjrd623BrAAAAFU"]
[Thu Sep 17 15:43:31.293725 2026] [security2:error] [pid 60716:tid 60989] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxfA8Psx0SVFjrd623BrQAAAF8"]
[Thu Sep 17 15:43:31.339942 2026] [security2:error] [pid 60716:tid 60964] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/temp/.env"] [unique_id "aqxfA8Psx0SVFjrd623BrgAAAEY"]
[Thu Sep 17 15:43:31.419882 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.135.226:48864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/phpversion.php"] [unique_id "aqxfA8Psx0SVFjrd623BsAAAACQ"]
[Thu Sep 17 15:43:31.453451 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxfA8Psx0SVFjrd623BsQAAAEQ"]
[Thu Sep 17 15:43:31.574762 2026] [security2:error] [pid 60716:tid 60995] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/lab/.env"] [unique_id "aqxfA8Psx0SVFjrd623BtAAAAGU"]
[Thu Sep 17 15:43:31.616347 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxfA8Psx0SVFjrd623BtgAAAGk"]
[Thu Sep 17 15:43:31.772801 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxfA8Psx0SVFjrd623BvAAAAGA"]
[Thu Sep 17 15:43:31.776500 2026] [security2:error] [pid 60716:tid 60901] [client 152.32.218.30:40906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxfAcPsx0SVFjrd623BZgAAAAk"], referer: https://mdp.iax.mybluehost.me/favicon.ico
[Thu Sep 17 15:43:31.806808 2026] [security2:error] [pid 60716:tid 60902] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/cronlab/.env"] [unique_id "aqxfA8Psx0SVFjrd623BvQAAAAo"]
[Thu Sep 17 15:43:31.933266 2026] [security2:error] [pid 60716:tid 60934] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxfA8Psx0SVFjrd623BvgAAACg"]
[Thu Sep 17 15:43:32.040488 2026] [security2:error] [pid 60716:tid 60954] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "aqxfBMPsx0SVFjrd623BwwAAADw"]
[Thu Sep 17 15:43:32.096975 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxfBMPsx0SVFjrd623BxgAAAC0"]
[Thu Sep 17 15:43:32.126111 2026] [security2:error] [pid 60716:tid 60903] [client 34.166.135.226:48878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/_phpinfo.php"] [unique_id "aqxfBMPsx0SVFjrd623ByAAAAAs"]
[Thu Sep 17 15:43:32.257727 2026] [security2:error] [pid 60716:tid 60970] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxfBMPsx0SVFjrd623B0AAAAEw"]
[Thu Sep 17 15:43:32.270617 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/en/.env"] [unique_id "aqxfBMPsx0SVFjrd623B0QAAAFc"]
[Thu Sep 17 15:43:32.420102 2026] [security2:error] [pid 60716:tid 60984] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxfBMPsx0SVFjrd623B0gAAAFo"]
[Thu Sep 17 15:43:32.531888 2026] [security2:error] [pid 60716:tid 60915] [client 14.232.208.138:55420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.208.232.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zlt.mai.mybluehost.me"] [uri "/index.php"] [unique_id "aqxfBMPsx0SVFjrd623B1AAAABc"]
[Thu Sep 17 15:43:32.561214 2026] [security2:error] [pid 60716:tid 60916] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "aqxfBMPsx0SVFjrd623B0wAAABg"]
[Thu Sep 17 15:43:32.597294 2026] [security2:error] [pid 60716:tid 60977] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxfBMPsx0SVFjrd623B1wAAAFM"]
[Thu Sep 17 15:43:32.760651 2026] [security2:error] [pid 60716:tid 60948] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxfBMPsx0SVFjrd623B2wAAADY"]
[Thu Sep 17 15:43:32.791080 2026] [security2:error] [pid 60716:tid 60959] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/psnlink/.env"] [unique_id "aqxfBMPsx0SVFjrd623B3QAAAEE"]
[Thu Sep 17 15:43:32.823068 2026] [security2:error] [pid 60716:tid 60997] [client 34.166.135.226:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/old_phpinfo.php"] [unique_id "aqxfBMPsx0SVFjrd623B4AAAAGc"]
[Thu Sep 17 15:43:32.917997 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxfBMPsx0SVFjrd623B4wAAAG8"]
[Thu Sep 17 15:43:33.018055 2026] [security2:error] [pid 60716:tid 61007] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/exapi/.env"] [unique_id "aqxfBcPsx0SVFjrd623B5AAAAHE"]
[Thu Sep 17 15:43:33.055800 2026] [security2:error] [pid 60716:tid 60910] [client 177.44.133.72:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfBcPsx0SVFjrd623B5gAAABI"]
[Thu Sep 17 15:43:33.055964 2026] [security2:error] [pid 60716:tid 60910] [client 177.44.133.72:63691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfBcPsx0SVFjrd623B5gAAABI"]
[Thu Sep 17 15:43:33.073336 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxfBcPsx0SVFjrd623B5wAAACU"]
[Thu Sep 17 15:43:33.233373 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxfBcPsx0SVFjrd623B7QAAAAg"]
[Thu Sep 17 15:43:33.244498 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.220.229:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/sitemaps/.env"] [unique_id "aqxfBcPsx0SVFjrd623B7gAAAHY"]
[Thu Sep 17 15:43:33.386589 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxfBcPsx0SVFjrd623B8AAAAFU"]
[Thu Sep 17 15:43:33.502144 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.135.226:47080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/server-info.php"] [unique_id "aqxfBcPsx0SVFjrd623B9wAAAA0"]
[Thu Sep 17 15:43:33.512488 2026] [security2:error] [pid 60716:tid 60989] [client 102.22.121.54:45112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfBcPsx0SVFjrd623B8gAAX20"]
[Thu Sep 17 15:43:33.517622 2026] [core:error] [pid 60716:tid 60975] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:33.517637 2026] [core:error] [pid 60716:tid 60975] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:33.539256 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxfBcPsx0SVFjrd623B-wAAAGs"]
[Thu Sep 17 15:43:33.698973 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxfBcPsx0SVFjrd623CBQAAAAk"]
[Thu Sep 17 15:43:33.854078 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxfBcPsx0SVFjrd623CBwAAABY"]
[Thu Sep 17 15:43:34.007021 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxfBsPsx0SVFjrd623CCQAAAFs"]
[Thu Sep 17 15:43:34.076199 2026] [security2:error] [pid 60716:tid 60961] [client 143.105.152.240:47494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfBsPsx0SVFjrd623CCgAAAEM"]
[Thu Sep 17 15:43:34.091831 2026] [security2:error] [pid 60716:tid 60961] [client 143.105.152.240:47494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfBsPsx0SVFjrd623CCgAAAEM"]
[Thu Sep 17 15:43:34.165991 2026] [security2:error] [pid 60716:tid 60923] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxfBsPsx0SVFjrd623CDAAAAB4"]
[Thu Sep 17 15:43:34.189784 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.135.226:47086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/server-status.php"] [unique_id "aqxfBsPsx0SVFjrd623CDwAAAF0"]
[Thu Sep 17 15:43:34.191178 2026] [security2:error] [pid 60716:tid 60982] [client 169.58.197.251:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxfBsPsx0SVFjrd623CEAAAAFg"], referer: binance.com
[Thu Sep 17 15:43:34.236896 2026] [core:error] [pid 60716:tid 60927] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:34.236915 2026] [core:error] [pid 60716:tid 60927] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:34.319492 2026] [security2:error] [pid 60716:tid 60924] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxfBsPsx0SVFjrd623CFQAAAB8"]
[Thu Sep 17 15:43:34.481679 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxfBsPsx0SVFjrd623CGgAAAEc"]
[Thu Sep 17 15:43:34.638912 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxfBsPsx0SVFjrd623CHQAAAHg"]
[Thu Sep 17 15:43:34.795391 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxfBsPsx0SVFjrd623CIQAAABo"]
[Thu Sep 17 15:43:34.905741 2026] [core:error] [pid 60716:tid 60991] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:34.905763 2026] [core:error] [pid 60716:tid 60991] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:34.946625 2026] [security2:error] [pid 60716:tid 60916] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/logs/.env"] [unique_id "aqxfBsPsx0SVFjrd623CJwAAABg"]
[Thu Sep 17 15:43:34.947642 2026] [security2:error] [pid 60716:tid 60997] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxfBsPsx0SVFjrd623CKAAAAGc"]
[Thu Sep 17 15:43:35.116226 2026] [security2:error] [pid 60716:tid 60956] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxfB8Psx0SVFjrd623CKwAAAD4"]
[Thu Sep 17 15:43:35.175241 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/cache/.env"] [unique_id "aqxfB8Psx0SVFjrd623CLAAAACA"]
[Thu Sep 17 15:43:35.269488 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.219.37:56394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxfB8Psx0SVFjrd623CMAAAABI"]
[Thu Sep 17 15:43:35.406585 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mailer/.env"] [unique_id "aqxfB8Psx0SVFjrd623CMgAAAAY"]
[Thu Sep 17 15:43:35.436479 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.219.37:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxfB8Psx0SVFjrd623CMwAAADo"]
[Thu Sep 17 15:43:35.481724 2026] [security2:error] [pid 60716:tid 61021] [client 79.116.89.151:50107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfB8Psx0SVFjrd623CNAAAAH8"]
[Thu Sep 17 15:43:35.481873 2026] [security2:error] [pid 60716:tid 61021] [client 79.116.89.151:50107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfB8Psx0SVFjrd623CNAAAAH8"]
[Thu Sep 17 15:43:35.628540 2026] [core:error] [pid 60716:tid 60978] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:35.628562 2026] [core:error] [pid 60716:tid 60978] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:35.639982 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mail/.env"] [unique_id "aqxfB8Psx0SVFjrd623COQAAAB0"]
[Thu Sep 17 15:43:35.787435 2026] [security2:error] [pid 60716:tid 60955] [client 14.232.208.138:52738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.208.232.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zlt.mai.mybluehost.me"] [uri "/index.php"] [unique_id "aqxfB8Psx0SVFjrd623CQgAAAD0"]
[Thu Sep 17 15:43:35.868301 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/email/.env"] [unique_id "aqxfB8Psx0SVFjrd623CRAAAABM"]
[Thu Sep 17 15:43:35.899001 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.219.37:58530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/info.php"] [unique_id "aqxfB8Psx0SVFjrd623CRQAAAEQ"]
[Thu Sep 17 15:43:35.917679 2026] [security2:error] [pid 60716:tid 61013] [client 148.75.189.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxfB8Psx0SVFjrd623CQQAAAHc"], referer: http://m.facebook.com
[Thu Sep 17 15:43:36.101398 2026] [security2:error] [pid 60716:tid 60971] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/smtp/.env"] [unique_id "aqxfCMPsx0SVFjrd623CSwAAAE0"]
[Thu Sep 17 15:43:36.204133 2026] [security2:error] [pid 60716:tid 60822] [remote 111.225.148.153:55210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.npae.net"] [uri "/"] [unique_id "aqxfCMPsx0SVFjrd623CUAAACzw"]
[Thu Sep 17 15:43:36.326305 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.135.226:47112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfCMPsx0SVFjrd623CUwAAABY"]
[Thu Sep 17 15:43:36.340594 2026] [security2:error] [pid 60716:tid 60924] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mailing/.env"] [unique_id "aqxfCMPsx0SVFjrd623CVAAAAB8"]
[Thu Sep 17 15:43:36.370391 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.219.37:58542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/php.php"] [unique_id "aqxfCMPsx0SVFjrd623CVQAAAG0"]
[Thu Sep 17 15:43:36.574013 2026] [security2:error] [pid 60716:tid 60936] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/notifications/.env"] [unique_id "aqxfCMPsx0SVFjrd623CWAAAACo"]
[Thu Sep 17 15:43:36.626039 2026] [security2:error] [pid 60716:tid 60942] [client 123.26.29.200:41030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfCMPsx0SVFjrd623CVgAAMDA"]
[Thu Sep 17 15:43:36.811432 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/notify/.env"] [unique_id "aqxfCMPsx0SVFjrd623CXgAAACs"]
[Thu Sep 17 15:43:36.860625 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.219.37:58544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/i.php"] [unique_id "aqxfCMPsx0SVFjrd623CXwAAABo"]
[Thu Sep 17 15:43:37.026353 2026] [security2:error] [pid 60716:tid 60948] [client 34.166.135.226:47124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxfCcPsx0SVFjrd623CYwAAADY"]
[Thu Sep 17 15:43:37.030205 2026] [security2:error] [pid 60716:tid 60809] [remote 111.225.149.139:30518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.npae.net"] [uri "/product/6061-turret/"] [unique_id "aqxfCcPsx0SVFjrd623CZAAAYS8"]
[Thu Sep 17 15:43:37.044548 2026] [security2:error] [pid 60716:tid 60998] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/sender/.env"] [unique_id "aqxfCcPsx0SVFjrd623CZQAAAGg"]
[Thu Sep 17 15:43:37.276408 2026] [security2:error] [pid 60716:tid 60926] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/campaign/.env"] [unique_id "aqxfCcPsx0SVFjrd623CagAAACE"]
[Thu Sep 17 15:43:37.339107 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.219.37:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxfCcPsx0SVFjrd623CbgAAAAY"]
[Thu Sep 17 15:43:37.507502 2026] [security2:error] [pid 60716:tid 60949] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/newsletter/.env"] [unique_id "aqxfCcPsx0SVFjrd623CdAAAADc"]
[Thu Sep 17 15:43:37.712786 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.135.226:47126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfCcPsx0SVFjrd623CgQAAAB0"]
[Thu Sep 17 15:43:37.737441 2026] [security2:error] [pid 60716:tid 60902] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/ses/.env"] [unique_id "aqxfCcPsx0SVFjrd623CggAAAAo"]
[Thu Sep 17 15:43:37.823842 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.219.37:58558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxfCcPsx0SVFjrd623ChAAAAAk"]
[Thu Sep 17 15:43:37.965334 2026] [security2:error] [pid 60716:tid 60927] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/sendgrid/.env"] [unique_id "aqxfCcPsx0SVFjrd623ChQAAACI"]
[Thu Sep 17 15:43:38.194396 2026] [security2:error] [pid 60716:tid 61015] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/sparkpost/.env"] [unique_id "aqxfCsPsx0SVFjrd623CigAAAHk"]
[Thu Sep 17 15:43:38.233672 2026] [security2:error] [pid 60716:tid 60961] [client 189.63.146.109:57472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.146.63.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "livepoint.dk"] [uri "/xmlrpc.php"] [unique_id "aqxfCsPsx0SVFjrd623CjAAAAEM"]
[Thu Sep 17 15:43:38.233772 2026] [security2:error] [pid 60716:tid 60961] [client 189.63.146.109:57472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "livepoint.dk"] [uri "/xmlrpc.php"] [unique_id "aqxfCsPsx0SVFjrd623CjAAAAEM"]
[Thu Sep 17 15:43:38.366379 2026] [security2:error] [pid 60716:tid 60908] [client 136.158.61.34:48452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfCsPsx0SVFjrd623CjwAAABA"]
[Thu Sep 17 15:43:38.366510 2026] [security2:error] [pid 60716:tid 60908] [client 136.158.61.34:48452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfCsPsx0SVFjrd623CjwAAABA"]
[Thu Sep 17 15:43:38.391684 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.135.226:47130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfCsPsx0SVFjrd623CkAAAAB4"]
[Thu Sep 17 15:43:38.422637 2026] [security2:error] [pid 60716:tid 60941] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/postmark/.env"] [unique_id "aqxfCsPsx0SVFjrd623CkQAAAC8"]
[Thu Sep 17 15:43:38.455733 2026] [fcgid:warn] [pid 60716:tid 60907] (70014)End of file found: [client 152.32.202.151:59462] mod_fcgid: can't get data from http client
[Thu Sep 17 15:43:38.541259 2026] [authz_core:error] [pid 60716:tid 61007] [client 169.58.197.253:56280] AH01630: client denied by server configuration: /home4/ccrmedia/public_html/p3collaborative/wp-admin/includes/error_log, referer: binance.com
[Thu Sep 17 15:43:38.649909 2026] [security2:error] [pid 60716:tid 60915] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mailgun/.env"] [unique_id "aqxfCsPsx0SVFjrd623ClgAAABc"]
[Thu Sep 17 15:43:38.670323 2026] [security2:error] [pid 60716:tid 60984] [client 169.58.197.253:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxfCsPsx0SVFjrd623CmQAAAFo"], referer: binance.com
[Thu Sep 17 15:43:38.724370 2026] [security2:error] [pid 60716:tid 60967] [client 186.189.107.134:53936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfCsPsx0SVFjrd623ClQAASQc"]
[Thu Sep 17 15:43:38.876573 2026] [security2:error] [pid 60716:tid 60895] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mandrill/.env"] [unique_id "aqxfCsPsx0SVFjrd623CoQAAAAM"]
[Thu Sep 17 15:43:38.973875 2026] [security2:error] [pid 60716:tid 61010] [client 162.241.226.11:13702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "zco.rbz.mybluehost.me"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxfCsPsx0SVFjrd623CpgAAAHQ"]
[Thu Sep 17 15:43:39.069852 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.219.37:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/test.php"] [unique_id "aqxfC8Psx0SVFjrd623CqAAAACA"]
[Thu Sep 17 15:43:39.075345 2026] [security2:error] [pid 60716:tid 60956] [client 34.166.135.226:47142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfC8Psx0SVFjrd623CqQAAAD4"]
[Thu Sep 17 15:43:39.106060 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mailjet/.env"] [unique_id "aqxfC8Psx0SVFjrd623CqgAAAFY"]
[Thu Sep 17 15:43:39.334838 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/brevo/.env"] [unique_id "aqxfC8Psx0SVFjrd623CrwAAAHY"]
[Thu Sep 17 15:43:39.562824 2026] [security2:error] [pid 60716:tid 60962] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/transactional/.env"] [unique_id "aqxfC8Psx0SVFjrd623CswAAAEQ"]
[Thu Sep 17 15:43:39.574075 2026] [security2:error] [pid 60716:tid 60972] [client 78.47.98.55:12496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxfC8Psx0SVFjrd623CsQAAAE4"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:43:39.759884 2026] [security2:error] [pid 60716:tid 60968] [client 34.166.135.226:47158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfC8Psx0SVFjrd623CvAAAAEo"]
[Thu Sep 17 15:43:39.779213 2026] [core:error] [pid 60716:tid 61013] [client 172.121.223.61:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:39.779236 2026] [core:error] [pid 60716:tid 61013] [client 172.121.223.61:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:39.789431 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/bulk/.env"] [unique_id "aqxfC8Psx0SVFjrd623CvgAAABM"]
[Thu Sep 17 15:43:39.803301 2026] [security2:error] [pid 60716:tid 60902] [client 34.154.219.37:58572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/p.php"] [unique_id "aqxfC8Psx0SVFjrd623CvwAAAAo"]
[Thu Sep 17 15:43:39.976368 2026] [core:error] [pid 60716:tid 60927] [client 107.172.123.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:39.976386 2026] [core:error] [pid 60716:tid 60927] [client 107.172.123.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.016882 2026] [security2:error] [pid 60716:tid 60939] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/aws/.env"] [unique_id "aqxfDMPsx0SVFjrd623CyAAAAC0"]
[Thu Sep 17 15:43:40.135727 2026] [core:error] [pid 60716:tid 61003] [client 172.121.223.61:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.135746 2026] [core:error] [pid 60716:tid 61003] [client 172.121.223.61:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.184772 2026] [security2:error] [pid 60716:tid 60975] [client 78.47.98.55:12510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxfDMPsx0SVFjrd623CyQAAAFE"], referer: https://www.bigsisterteams.com
[Thu Sep 17 15:43:40.206576 2026] [core:error] [pid 60716:tid 61002] [client 107.172.123.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.206598 2026] [core:error] [pid 60716:tid 61002] [client 107.172.123.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.248454 2026] [security2:error] [pid 60716:tid 60915] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/azure/.env"] [unique_id "aqxfDMPsx0SVFjrd623C1AAAABc"]
[Thu Sep 17 15:43:40.278816 2026] [security2:error] [pid 60716:tid 60985] [client 104.143.88.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.beartoothagilityclub.com"] [uri "/index.php"] [unique_id "aqxfDMPsx0SVFjrd623C0QAAW1w"]
[Thu Sep 17 15:43:40.313379 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.219.37:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxfDMPsx0SVFjrd623C1QAAAH0"]
[Thu Sep 17 15:43:40.380604 2026] [core:error] [pid 60716:tid 60967] [client 107.172.123.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.380624 2026] [core:error] [pid 60716:tid 60967] [client 107.172.123.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.444522 2026] [security2:error] [pid 60716:tid 60944] [client 34.166.135.226:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxfDMPsx0SVFjrd623C3QAAADI"]
[Thu Sep 17 15:43:40.460228 2026] [core:error] [pid 60716:tid 61011] [client 172.121.223.61:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.460248 2026] [core:error] [pid 60716:tid 61011] [client 172.121.223.61:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:40.476972 2026] [security2:error] [pid 60716:tid 61010] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/gcp/.env"] [unique_id "aqxfDMPsx0SVFjrd623C3wAAAHQ"]
[Thu Sep 17 15:43:40.529156 2026] [security2:error] [pid 60716:tid 60965] [client 103.61.184.148:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfDMPsx0SVFjrd623C5gAAAEc"]
[Thu Sep 17 15:43:40.529304 2026] [security2:error] [pid 60716:tid 60965] [client 103.61.184.148:54527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfDMPsx0SVFjrd623C5gAAAEc"]
[Thu Sep 17 15:43:40.655464 2026] [security2:error] [pid 60716:tid 60948] [client 148.227.75.216:61622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfDMPsx0SVFjrd623C5wAAADY"]
[Thu Sep 17 15:43:40.667804 2026] [security2:error] [pid 60716:tid 60948] [client 148.227.75.216:61622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfDMPsx0SVFjrd623C5wAAADY"]
[Thu Sep 17 15:43:40.703374 2026] [security2:error] [pid 60716:tid 60900] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/cloud/.env"] [unique_id "aqxfDMPsx0SVFjrd623C8AAAAAg"]
[Thu Sep 17 15:43:40.827811 2026] [security2:error] [pid 60716:tid 60992] [client 34.154.219.37:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxfDMPsx0SVFjrd623C9AAAAGI"]
[Thu Sep 17 15:43:40.883038 2026] [security2:error] [pid 60716:tid 60978] [client 40.81.232.68:53335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "aqxfDMPsx0SVFjrd623C_wAAAFQ"], referer: binance.com
[Thu Sep 17 15:43:40.939092 2026] [security2:error] [pid 60716:tid 60996] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/infrastructure/.env"] [unique_id "aqxfDMPsx0SVFjrd623DAAAAAGY"]
[Thu Sep 17 15:43:41.131368 2026] [security2:error] [pid 60716:tid 60951] [client 34.166.135.226:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/phpinfo.php.old"] [unique_id "aqxfDcPsx0SVFjrd623DAwAAADk"]
[Thu Sep 17 15:43:41.166690 2026] [security2:error] [pid 60716:tid 60993] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/docker/.env"] [unique_id "aqxfDcPsx0SVFjrd623DBAAAAGM"]
[Thu Sep 17 15:43:41.370618 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.219.37:58592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxfDcPsx0SVFjrd623DDQAAAFU"]
[Thu Sep 17 15:43:41.395425 2026] [security2:error] [pid 60716:tid 60958] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/k8s/.env"] [unique_id "aqxfDcPsx0SVFjrd623DDgAAAEA"]
[Thu Sep 17 15:43:41.624163 2026] [security2:error] [pid 60716:tid 60941] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/kubernetes/.env"] [unique_id "aqxfDcPsx0SVFjrd623DFwAAAC8"]
[Thu Sep 17 15:43:41.665141 2026] [security2:error] [pid 60716:tid 60971] [client 164.92.220.0:57420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commonearthjc.com"] [uri "/index.php"] [unique_id "aqxfDcPsx0SVFjrd623DCwAAAE0"]
[Thu Sep 17 15:43:41.814840 2026] [security2:error] [pid 60716:tid 60975] [client 34.166.135.226:47202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/phpinfo.php~"] [unique_id "aqxfDcPsx0SVFjrd623DHgAAAFE"]
[Thu Sep 17 15:43:41.851960 2026] [security2:error] [pid 60716:tid 60969] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/terraform/.env"] [unique_id "aqxfDcPsx0SVFjrd623DIAAAAEs"]
[Thu Sep 17 15:43:41.858299 2026] [security2:error] [pid 60716:tid 60959] [client 162.241.226.11:13714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "zco.rbz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "aqxfDcPsx0SVFjrd623DIQAAAEE"]
[Thu Sep 17 15:43:41.863717 2026] [security2:error] [pid 60716:tid 60793] [remote 110.249.202.140:20612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cult.cyberpunkonline.net"] [uri "/geffine/GEFFINE-011.txt"] [unique_id "aqxfDcPsx0SVFjrd623DIgAAOx8"]
[Thu Sep 17 15:43:41.870868 2026] [security2:error] [pid 60716:tid 60915] [client 34.154.219.37:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxfDcPsx0SVFjrd623DIwAAABc"]
[Thu Sep 17 15:43:41.923698 2026] [security2:error] [pid 60716:tid 60908] [client 14.96.156.146:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfDcPsx0SVFjrd623DJQAAABA"]
[Thu Sep 17 15:43:41.923851 2026] [security2:error] [pid 60716:tid 60908] [client 14.96.156.146:53248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfDcPsx0SVFjrd623DJQAAABA"]
[Thu Sep 17 15:43:42.079090 2026] [security2:error] [pid 60716:tid 60998] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/ansible/.env"] [unique_id "aqxfDsPsx0SVFjrd623DKQAAAGg"]
[Thu Sep 17 15:43:42.307882 2026] [security2:error] [pid 60716:tid 60931] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/.git/.env"] [unique_id "aqxfDsPsx0SVFjrd623DLgAAACU"]
[Thu Sep 17 15:43:42.393126 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.219.37:58604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxfDsPsx0SVFjrd623DLwAAABI"]
[Thu Sep 17 15:43:42.512985 2026] [security2:error] [pid 60716:tid 61008] [client 34.166.135.226:47214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/info.php.bak"] [unique_id "aqxfDsPsx0SVFjrd623DMQAAAHI"]
[Thu Sep 17 15:43:42.541511 2026] [security2:error] [pid 60716:tid 60913] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/ci/.env"] [unique_id "aqxfDsPsx0SVFjrd623DMgAAABU"]
[Thu Sep 17 15:43:42.775343 2026] [security2:error] [pid 60716:tid 60989] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/cd/.env"] [unique_id "aqxfDsPsx0SVFjrd623DPQAAAF8"]
[Thu Sep 17 15:43:42.853380 2026] [security2:error] [pid 60716:tid 60963] [client 173.252.95.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxfDsPsx0SVFjrd623DOwAAAEU"]
[Thu Sep 17 15:43:42.894016 2026] [security2:error] [pid 60716:tid 60978] [client 34.154.219.37:58616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfDsPsx0SVFjrd623DPgAAAFQ"]
[Thu Sep 17 15:43:42.904465 2026] [security2:error] [pid 60716:tid 60922] [client 169.58.197.251:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-icon-collections-registry.php"] [unique_id "aqxfDsPsx0SVFjrd623DPwAAAB0"], referer: binance.com
[Thu Sep 17 15:43:43.005400 2026] [security2:error] [pid 60716:tid 60902] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/jenkins/.env"] [unique_id "aqxfD8Psx0SVFjrd623DQAAAAAo"]
[Thu Sep 17 15:43:43.191974 2026] [security2:error] [pid 60716:tid 60933] [client 34.166.135.226:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/phpinfo.php.save"] [unique_id "aqxfD8Psx0SVFjrd623DRAAAACc"]
[Thu Sep 17 15:43:43.196709 2026] [security2:error] [pid 60716:tid 60927] [client 162.241.226.11:40046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "zco.rbz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "aqxfD8Psx0SVFjrd623DRQAAACI"]
[Thu Sep 17 15:43:43.233203 2026] [security2:error] [pid 60716:tid 60979] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/gitlab/.env"] [unique_id "aqxfD8Psx0SVFjrd623DSAAAAFU"]
[Thu Sep 17 15:43:43.437400 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.219.37:58628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxfD8Psx0SVFjrd623DTQAAAAk"]
[Thu Sep 17 15:43:43.462784 2026] [security2:error] [pid 60716:tid 60942] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/github/.env"] [unique_id "aqxfD8Psx0SVFjrd623DTgAAADA"]
[Thu Sep 17 15:43:43.698856 2026] [security2:error] [pid 60716:tid 60970] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/actions/.env"] [unique_id "aqxfD8Psx0SVFjrd623DUgAAAEw"]
[Thu Sep 17 15:43:43.750822 2026] [security2:error] [pid 60716:tid 60936] [client 177.44.133.72:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfD8Psx0SVFjrd623DVwAAACo"]
[Thu Sep 17 15:43:43.750926 2026] [security2:error] [pid 60716:tid 60936] [client 177.44.133.72:64363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfD8Psx0SVFjrd623DVwAAACo"]
[Thu Sep 17 15:43:43.881499 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.135.226:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxfD8Psx0SVFjrd623DWAAAAHo"]
[Thu Sep 17 15:43:43.926304 2026] [security2:error] [pid 60716:tid 60967] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/circleci/.env"] [unique_id "aqxfD8Psx0SVFjrd623DXwAAAEk"]
[Thu Sep 17 15:43:44.118951 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.219.37:58642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxfEMPsx0SVFjrd623DZAAAADQ"]
[Thu Sep 17 15:43:44.152962 2026] [security2:error] [pid 60716:tid 60994] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/travis/.env"] [unique_id "aqxfEMPsx0SVFjrd623DZwAAAGQ"]
[Thu Sep 17 15:43:44.380865 2026] [security2:error] [pid 60716:tid 60900] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/buildkite/.env"] [unique_id "aqxfEMPsx0SVFjrd623DbgAAAAg"]
[Thu Sep 17 15:43:44.530743 2026] [security2:error] [pid 60716:tid 60961] [client 143.105.152.240:50467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfEMPsx0SVFjrd623DcAAAAEM"]
[Thu Sep 17 15:43:44.530894 2026] [security2:error] [pid 60716:tid 60961] [client 143.105.152.240:50467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfEMPsx0SVFjrd623DcAAAAEM"]
[Thu Sep 17 15:43:44.570422 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.135.226:36154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxfEMPsx0SVFjrd623DcQAAACA"]
[Thu Sep 17 15:43:44.608374 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mysql/.env"] [unique_id "aqxfEMPsx0SVFjrd623DcgAAAHY"]
[Thu Sep 17 15:43:44.611259 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.219.37:53810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxfEMPsx0SVFjrd623DcwAAADI"]
[Thu Sep 17 15:43:44.836492 2026] [security2:error] [pid 60716:tid 60932] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/postgres/.env"] [unique_id "aqxfEMPsx0SVFjrd623DdwAAACY"]
[Thu Sep 17 15:43:45.063890 2026] [security2:error] [pid 60716:tid 60964] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/mongodb/.env"] [unique_id "aqxfEcPsx0SVFjrd623DeQAAAEY"]
[Thu Sep 17 15:43:45.092823 2026] [security2:error] [pid 60716:tid 61004] [client 34.154.219.37:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxfEcPsx0SVFjrd623DegAAAG4"]
[Thu Sep 17 15:43:45.117186 2026] [security2:error] [pid 60716:tid 60808] [remote 47.128.120.3:16892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.norifon.com"] [uri "/robots.txt"] [unique_id "aqxfEcPsx0SVFjrd623DewAAVy4"]
[Thu Sep 17 15:43:45.256185 2026] [security2:error] [pid 60716:tid 60989] [client 34.166.135.226:36164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxfEcPsx0SVFjrd623DggAAAF8"]
[Thu Sep 17 15:43:45.294775 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/redis/.env"] [unique_id "aqxfEcPsx0SVFjrd623DgwAAAB0"]
[Thu Sep 17 15:43:45.527093 2026] [security2:error] [pid 60716:tid 60927] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/elasticsearch/.env"] [unique_id "aqxfEcPsx0SVFjrd623DiAAAACI"]
[Thu Sep 17 15:43:45.563187 2026] [security2:error] [pid 60716:tid 60973] [client 34.154.219.37:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxfEcPsx0SVFjrd623DiQAAAE8"]
[Thu Sep 17 15:43:45.754633 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/rabbitmq/.env"] [unique_id "aqxfEcPsx0SVFjrd623DjgAAABY"]
[Thu Sep 17 15:43:45.938832 2026] [security2:error] [pid 60716:tid 60986] [client 34.166.135.226:36178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxfEcPsx0SVFjrd623DkQAAAFw"]
[Thu Sep 17 15:43:45.984260 2026] [security2:error] [pid 60716:tid 60936] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/kafka/.env"] [unique_id "aqxfEcPsx0SVFjrd623DkgAAACo"]
[Thu Sep 17 15:43:46.041254 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.219.37:53844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxfEsPsx0SVFjrd623DlAAAAFk"]
[Thu Sep 17 15:43:46.053787 2026] [security2:error] [pid 60716:tid 60923] [client 79.116.89.151:50735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfEsPsx0SVFjrd623DlQAAAB4"]
[Thu Sep 17 15:43:46.054003 2026] [security2:error] [pid 60716:tid 60923] [client 79.116.89.151:50735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfEsPsx0SVFjrd623DlQAAAB4"]
[Thu Sep 17 15:43:46.064412 2026] [security2:error] [pid 60716:tid 60984] [client 169.58.197.253:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxfEsPsx0SVFjrd623DlgAAAFo"], referer: binance.com
[Thu Sep 17 15:43:46.212056 2026] [security2:error] [pid 60716:tid 60969] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/queue/.env"] [unique_id "aqxfEsPsx0SVFjrd623DmwAAAEs"]
[Thu Sep 17 15:43:46.440977 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/worker/.env"] [unique_id "aqxfEsPsx0SVFjrd623DngAAACs"]
[Thu Sep 17 15:43:46.524921 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.219.37:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxfEsPsx0SVFjrd623DogAAADQ"]
[Thu Sep 17 15:43:46.622028 2026] [security2:error] [pid 60716:tid 60895] [client 34.166.135.226:36182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxfEsPsx0SVFjrd623DowAAAAM"]
[Thu Sep 17 15:43:46.667567 2026] [security2:error] [pid 60716:tid 60945] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/job/.env"] [unique_id "aqxfEsPsx0SVFjrd623DpQAAADM"]
[Thu Sep 17 15:43:46.899579 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "aqxfEsPsx0SVFjrd623DqQAAAHM"]
[Thu Sep 17 15:43:46.917424 2026] [security2:error] [pid 60716:tid 61007] [client 41.41.223.93:37368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfEsPsx0SVFjrd623DpwAAcTE"]
[Thu Sep 17 15:43:47.075317 2026] [security2:error] [pid 60716:tid 60898] [client 40.81.232.68:61583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "aqxfE8Psx0SVFjrd623DrQAAAAY"], referer: binance.com
[Thu Sep 17 15:43:47.140144 2026] [security2:error] [pid 60716:tid 60906] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "aqxfE8Psx0SVFjrd623DrwAAAA4"]
[Thu Sep 17 15:43:47.319590 2026] [security2:error] [pid 60716:tid 60910] [client 34.166.135.226:36196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/www/phpinfo.php"] [unique_id "aqxfE8Psx0SVFjrd623DtQAAABI"]
[Thu Sep 17 15:43:47.371855 2026] [security2:error] [pid 60716:tid 60932] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/preview/.env"] [unique_id "aqxfE8Psx0SVFjrd623DtwAAACY"]
[Thu Sep 17 15:43:47.404769 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.219.37:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfE8Psx0SVFjrd623DuAAAABU"]
[Thu Sep 17 15:43:47.600298 2026] [security2:error] [pid 60716:tid 60976] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "aqxfE8Psx0SVFjrd623DugAAAFI"]
[Thu Sep 17 15:43:47.831781 2026] [security2:error] [pid 60716:tid 60903] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/uat/.env"] [unique_id "aqxfE8Psx0SVFjrd623DwgAAAAs"]
[Thu Sep 17 15:43:47.907828 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.219.37:53870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxfE8Psx0SVFjrd623DwwAAACI"]
[Thu Sep 17 15:43:48.003443 2026] [security2:error] [pid 60716:tid 60973] [client 34.166.135.226:36198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfFMPsx0SVFjrd623DxwAAAE8"]
[Thu Sep 17 15:43:48.058298 2026] [security2:error] [pid 60716:tid 60942] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "aqxfFMPsx0SVFjrd623DygAAADA"]
[Thu Sep 17 15:43:48.285780 2026] [security2:error] [pid 60716:tid 60984] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "aqxfFMPsx0SVFjrd623DzwAAAFo"]
[Thu Sep 17 15:43:48.408194 2026] [security2:error] [pid 60716:tid 60923] [client 34.154.219.37:53886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfFMPsx0SVFjrd623D0wAAAB4"]
[Thu Sep 17 15:43:48.435712 2026] [security2:error] [pid 60716:tid 61014] [client 145.239.10.137:40753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fetchandfierce.com"] [uri "/cmd.php"] [unique_id "aqxfFMPsx0SVFjrd623D1AAAAHg"], referer: http://fetchandfierce.com/cmd.php
[Thu Sep 17 15:43:48.513162 2026] [security2:error] [pid 60716:tid 60969] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "aqxfFMPsx0SVFjrd623D1gAAAEs"]
[Thu Sep 17 15:43:48.685276 2026] [security2:error] [pid 60716:tid 60967] [client 34.166.135.226:36212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfFMPsx0SVFjrd623D2gAAAEk"]
[Thu Sep 17 15:43:48.741131 2026] [security2:error] [pid 60716:tid 60945] [client 34.166.220.229:59908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.breathingboxing.com"] [uri "/___proxy_subdomain_cpcontacts/config/app/.env"] [unique_id "aqxfFMPsx0SVFjrd623D2wAAADM"]
[Thu Sep 17 15:43:48.905089 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.219.37:53902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfFMPsx0SVFjrd623D3gAAAA8"]
[Thu Sep 17 15:43:48.974316 2026] [security2:error] [pid 60716:tid 60952] [client 34.166.220.229:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/phpinfo.php"] [unique_id "aqxfFMPsx0SVFjrd623D4AAAADo"]
[Thu Sep 17 15:43:49.378593 2026] [security2:error] [pid 60716:tid 60953] [client 34.166.135.226:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/site/phpinfo.php"] [unique_id "aqxfFcPsx0SVFjrd623D5wAAADs"]
[Thu Sep 17 15:43:49.403825 2026] [security2:error] [pid 60716:tid 60928] [client 152.172.79.118:47270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfFcPsx0SVFjrd623D5QAAI18"]
[Thu Sep 17 15:43:49.423569 2026] [security2:error] [pid 60716:tid 60951] [client 34.154.219.37:53918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfFcPsx0SVFjrd623D6AAAADk"]
[Thu Sep 17 15:43:49.650507 2026] [security2:error] [pid 60716:tid 60935] [client 34.166.220.229:38098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/info.php"] [unique_id "aqxfFcPsx0SVFjrd623D7AAAACk"]
[Thu Sep 17 15:43:49.910883 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.219.37:53934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfFcPsx0SVFjrd623D7wAAAHA"]
[Thu Sep 17 15:43:50.071824 2026] [security2:error] [pid 60716:tid 60940] [client 34.166.135.226:36220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxfFsPsx0SVFjrd623D8AAAAC4"]
[Thu Sep 17 15:43:50.337500 2026] [security2:error] [pid 60716:tid 60996] [client 34.166.220.229:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/php.php"] [unique_id "aqxfFsPsx0SVFjrd623D_QAAAGY"]
[Thu Sep 17 15:43:50.375852 2026] [security2:error] [pid 60716:tid 60988] [client 34.154.219.37:53946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxfFsPsx0SVFjrd623D_gAAAF4"]
[Thu Sep 17 15:43:50.754368 2026] [core:error] [pid 60716:tid 60901] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:50.754387 2026] [core:error] [pid 60716:tid 60901] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:50.757857 2026] [security2:error] [pid 60716:tid 60966] [client 34.166.135.226:36234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfFsPsx0SVFjrd623EBQAAAEg"]
[Thu Sep 17 15:43:50.842224 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.219.37:53954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxfFsPsx0SVFjrd623ECAAAABY"]
[Thu Sep 17 15:43:50.868089 2026] [core:error] [pid 60716:tid 61019] [client 34.94.30.138:45140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:50.868110 2026] [core:error] [pid 60716:tid 61019] [client 34.94.30.138:45140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:50.973228 2026] [core:error] [pid 60716:tid 61014] [client 34.94.30.138:45144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:50.973247 2026] [core:error] [pid 60716:tid 61014] [client 34.94.30.138:45144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.018922 2026] [security2:error] [pid 60716:tid 60970] [client 34.166.220.229:38112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/i.php"] [unique_id "aqxfF8Psx0SVFjrd623ECwAAAEw"]
[Thu Sep 17 15:43:51.062599 2026] [core:error] [pid 60716:tid 60916] [client 34.94.30.138:45148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.062624 2026] [core:error] [pid 60716:tid 60916] [client 34.94.30.138:45148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.240248 2026] [security2:error] [pid 60716:tid 60950] [client 148.227.75.216:49046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfF8Psx0SVFjrd623EFQAAADg"]
[Thu Sep 17 15:43:51.245040 2026] [security2:error] [pid 60716:tid 60950] [client 148.227.75.216:49046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfF8Psx0SVFjrd623EFQAAADg"]
[Thu Sep 17 15:43:51.292973 2026] [core:error] [pid 60716:tid 60977] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.293006 2026] [core:error] [pid 60716:tid 60977] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.333266 2026] [security2:error] [pid 60716:tid 60923] [client 103.61.184.148:55071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfF8Psx0SVFjrd623EGAAAAB4"]
[Thu Sep 17 15:43:51.333395 2026] [security2:error] [pid 60716:tid 60923] [client 103.61.184.148:55071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfF8Psx0SVFjrd623EGAAAAB4"]
[Thu Sep 17 15:43:51.357086 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.219.37:53964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxfF8Psx0SVFjrd623EGQAAABo"]
[Thu Sep 17 15:43:51.442441 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.135.226:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfF8Psx0SVFjrd623EGwAAAG0"]
[Thu Sep 17 15:43:51.442644 2026] [core:error] [pid 60716:tid 61009] [client 34.94.30.138:45162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.442655 2026] [core:error] [pid 60716:tid 61009] [client 34.94.30.138:45162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.485601 2026] [security2:error] [pid 60716:tid 61000] [client 136.158.61.34:49485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfF8Psx0SVFjrd623EHAAAAGo"]
[Thu Sep 17 15:43:51.485742 2026] [security2:error] [pid 60716:tid 61000] [client 136.158.61.34:49485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfF8Psx0SVFjrd623EHAAAAGo"]
[Thu Sep 17 15:43:51.570774 2026] [security2:error] [pid 60716:tid 60953] [client 34.94.30.138:45166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "aqxfF8Psx0SVFjrd623EHgAAADs"]
[Thu Sep 17 15:43:51.655158 2026] [core:error] [pid 60716:tid 60999] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.655176 2026] [core:error] [pid 60716:tid 60999] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.697934 2026] [security2:error] [pid 60716:tid 60993] [client 34.166.220.229:38124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/pi.php"] [unique_id "aqxfF8Psx0SVFjrd623EJwAAAGM"]
[Thu Sep 17 15:43:51.791838 2026] [core:error] [pid 60716:tid 60972] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.791863 2026] [core:error] [pid 60716:tid 60972] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.828834 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.219.37:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxfF8Psx0SVFjrd623EKwAAAD0"]
[Thu Sep 17 15:43:51.960499 2026] [core:error] [pid 60716:tid 61007] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:51.960529 2026] [core:error] [pid 60716:tid 61007] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.104431 2026] [core:error] [pid 60716:tid 60976] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.104451 2026] [core:error] [pid 60716:tid 60976] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.128067 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.135.226:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/core/phpinfo.php"] [unique_id "aqxfGMPsx0SVFjrd623ENAAAAFc"]
[Thu Sep 17 15:43:52.274004 2026] [core:error] [pid 60716:tid 60894] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.274037 2026] [core:error] [pid 60716:tid 60894] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.301070 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.219.37:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxfGMPsx0SVFjrd623EPAAAAAs"]
[Thu Sep 17 15:43:52.371788 2026] [security2:error] [pid 60716:tid 60942] [client 169.58.197.251:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxfGMPsx0SVFjrd623EPQAAADA"], referer: binance.com
[Thu Sep 17 15:43:52.380208 2026] [security2:error] [pid 60716:tid 60958] [client 34.166.220.229:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/pinfo.php"] [unique_id "aqxfGMPsx0SVFjrd623EPgAAAEA"]
[Thu Sep 17 15:43:52.415755 2026] [security2:error] [pid 60716:tid 60973] [client 14.96.156.146:53957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfGMPsx0SVFjrd623EPwAAAE8"]
[Thu Sep 17 15:43:52.415865 2026] [security2:error] [pid 60716:tid 60973] [client 14.96.156.146:53957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfGMPsx0SVFjrd623EPwAAAE8"]
[Thu Sep 17 15:43:52.454754 2026] [core:error] [pid 60716:tid 60986] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.454773 2026] [core:error] [pid 60716:tid 60986] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.686901 2026] [security2:error] [pid 60716:tid 61016] [client 34.94.30.138:45212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "aqxfGMPsx0SVFjrd623ERgAAAHo"]
[Thu Sep 17 15:43:52.714804 2026] [security2:error] [pid 60716:tid 60939] [client 34.94.30.138:45212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "aqxfGMPsx0SVFjrd623ESAAAAC0"]
[Thu Sep 17 15:43:52.779953 2026] [security2:error] [pid 60716:tid 60959] [client 34.154.219.37:53982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxfGMPsx0SVFjrd623ESgAAAEE"]
[Thu Sep 17 15:43:52.784170 2026] [security2:error] [pid 60716:tid 61010] [client 169.58.197.253:57366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxfGMPsx0SVFjrd623ETAAAAHQ"], referer: binance.com
[Thu Sep 17 15:43:52.809741 2026] [security2:error] [pid 60716:tid 61014] [client 34.166.135.226:36262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.135.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iestimatellc.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxfGMPsx0SVFjrd623ETwAAAHg"]
[Thu Sep 17 15:43:52.880962 2026] [core:error] [pid 60716:tid 60907] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:52.880984 2026] [core:error] [pid 60716:tid 60907] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.028627 2026] [security2:error] [pid 60716:tid 60895] [client 34.94.30.138:45226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "aqxfGcPsx0SVFjrd623EVAAAAAM"]
[Thu Sep 17 15:43:53.059499 2026] [security2:error] [pid 60716:tid 60950] [client 34.166.220.229:38140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/test.php"] [unique_id "aqxfGcPsx0SVFjrd623EVQAAADg"]
[Thu Sep 17 15:43:53.201230 2026] [core:error] [pid 60716:tid 60994] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.201266 2026] [core:error] [pid 60716:tid 60994] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.257157 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.219.37:53992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxfGcPsx0SVFjrd623EXwAAAG0"]
[Thu Sep 17 15:43:53.456808 2026] [core:error] [pid 60716:tid 60944] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.456827 2026] [core:error] [pid 60716:tid 60944] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.678290 2026] [core:error] [pid 60716:tid 60902] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.678313 2026] [core:error] [pid 60716:tid 60902] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.719546 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.219.37:53998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxfGcPsx0SVFjrd623EbgAAAGE"]
[Thu Sep 17 15:43:53.760243 2026] [core:error] [pid 60716:tid 61020] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.760266 2026] [core:error] [pid 60716:tid 61020] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.820747 2026] [core:error] [pid 60716:tid 60899] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.820767 2026] [core:error] [pid 60716:tid 60899] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.993638 2026] [core:error] [pid 60716:tid 60934] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:53.993664 2026] [core:error] [pid 60716:tid 60934] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.188547 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.219.37:53066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxfGsPsx0SVFjrd623EgAAAAEA"]
[Thu Sep 17 15:43:54.301475 2026] [security2:error] [pid 60716:tid 60946] [client 40.81.232.68:56833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "aqxfGsPsx0SVFjrd623EgwAAADQ"], referer: binance.com
[Thu Sep 17 15:43:54.311388 2026] [core:error] [pid 60716:tid 60939] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.311409 2026] [core:error] [pid 60716:tid 60939] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.399674 2026] [security2:error] [pid 60716:tid 60973] [client 177.44.133.72:65037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfGsPsx0SVFjrd623EhQAAAE8"]
[Thu Sep 17 15:43:54.399814 2026] [security2:error] [pid 60716:tid 60973] [client 177.44.133.72:65037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfGsPsx0SVFjrd623EhQAAAE8"]
[Thu Sep 17 15:43:54.444141 2026] [security2:error] [pid 60716:tid 60971] [client 34.166.220.229:38154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/p.php"] [unique_id "aqxfGsPsx0SVFjrd623EhwAAAE0"]
[Thu Sep 17 15:43:54.485741 2026] [core:error] [pid 60716:tid 60907] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.485763 2026] [core:error] [pid 60716:tid 60907] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.649279 2026] [core:error] [pid 60716:tid 60928] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.649297 2026] [core:error] [pid 60716:tid 60928] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.663600 2026] [security2:error] [pid 60716:tid 60937] [client 34.154.219.37:53070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxfGsPsx0SVFjrd623ElgAAACs"]
[Thu Sep 17 15:43:54.811016 2026] [core:error] [pid 60716:tid 60898] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:54.811037 2026] [core:error] [pid 60716:tid 60898] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.045200 2026] [core:error] [pid 60716:tid 61007] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.045223 2026] [core:error] [pid 60716:tid 61007] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.076483 2026] [security2:error] [pid 60716:tid 60967] [client 143.105.152.240:8372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfG8Psx0SVFjrd623EpAAAAEk"]
[Thu Sep 17 15:43:55.076619 2026] [security2:error] [pid 60716:tid 60967] [client 143.105.152.240:8372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfG8Psx0SVFjrd623EpAAAAEk"]
[Thu Sep 17 15:43:55.119851 2026] [security2:error] [pid 60716:tid 60949] [client 34.166.220.229:38162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/debug.php"] [unique_id "aqxfG8Psx0SVFjrd623EpwAAADc"]
[Thu Sep 17 15:43:55.135283 2026] [security2:error] [pid 60716:tid 60940] [client 34.154.219.37:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxfG8Psx0SVFjrd623EqAAAAC4"]
[Thu Sep 17 15:43:55.279126 2026] [core:error] [pid 60716:tid 60972] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.279151 2026] [core:error] [pid 60716:tid 60972] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.394254 2026] [security2:error] [pid 60716:tid 60927] [client 34.94.30.138:55128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "aqxfG8Psx0SVFjrd623EsgAAACI"]
[Thu Sep 17 15:43:55.416362 2026] [security2:error] [pid 60716:tid 60981] [client 201.71.6.134:38909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfG8Psx0SVFjrd623ErwAAV1M"]
[Thu Sep 17 15:43:55.424278 2026] [security2:error] [pid 60716:tid 60934] [client 34.94.30.138:55128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "aqxfG8Psx0SVFjrd623EswAAACg"]
[Thu Sep 17 15:43:55.488842 2026] [core:error] [pid 60716:tid 60942] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.488869 2026] [core:error] [pid 60716:tid 60942] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.601948 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.219.37:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfG8Psx0SVFjrd623EuAAAAAs"]
[Thu Sep 17 15:43:55.625059 2026] [security2:error] [pid 60716:tid 60924] [client 192.178.6.3:46446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxfG8Psx0SVFjrd623EuQAAAB8"]
[Thu Sep 17 15:43:55.676093 2026] [core:error] [pid 60716:tid 60939] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.676113 2026] [core:error] [pid 60716:tid 60939] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.798062 2026] [security2:error] [pid 60716:tid 60960] [client 34.166.220.229:59548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxfG8Psx0SVFjrd623ExQAAAEI"]
[Thu Sep 17 15:43:55.895896 2026] [core:error] [pid 60716:tid 60957] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:55.895913 2026] [core:error] [pid 60716:tid 60957] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:56.060110 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.219.37:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfHMPsx0SVFjrd623EzQAAACU"]
[Thu Sep 17 15:43:56.480787 2026] [security2:error] [pid 60716:tid 60994] [client 34.166.220.229:59558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/test/phpinfo.php"] [unique_id "aqxfHMPsx0SVFjrd623E3QAAAGQ"]
[Thu Sep 17 15:43:56.533933 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.219.37:53104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxfHMPsx0SVFjrd623E3wAAAEc"]
[Thu Sep 17 15:43:56.551880 2026] [core:error] [pid 60716:tid 60913] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:56.551898 2026] [core:error] [pid 60716:tid 60913] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:56.591834 2026] [security2:error] [pid 60716:tid 60935] [client 79.116.89.151:51360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfHMPsx0SVFjrd623E4gAAACk"]
[Thu Sep 17 15:43:56.591946 2026] [security2:error] [pid 60716:tid 60935] [client 79.116.89.151:51360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfHMPsx0SVFjrd623E4gAAACk"]
[Thu Sep 17 15:43:56.711778 2026] [core:error] [pid 60716:tid 60988] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:56.711799 2026] [core:error] [pid 60716:tid 60988] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:56.817875 2026] [security2:error] [pid 60716:tid 60893] [client 34.94.30.138:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "aqxfHMPsx0SVFjrd623E7gAAAAE"]
[Thu Sep 17 15:43:56.839819 2026] [security2:error] [pid 60716:tid 60899] [client 34.94.30.138:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "aqxfHMPsx0SVFjrd623E8AAAAAc"]
[Thu Sep 17 15:43:56.880231 2026] [security2:error] [pid 60716:tid 61001] [client 34.94.30.138:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "aqxfHMPsx0SVFjrd623E8QAAAGs"]
[Thu Sep 17 15:43:56.924002 2026] [security2:error] [pid 60716:tid 60979] [client 34.94.30.138:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "aqxfHMPsx0SVFjrd623E9AAAAFU"]
[Thu Sep 17 15:43:56.966007 2026] [security2:error] [pid 60716:tid 60927] [client 34.94.30.138:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/site/.env"] [unique_id "aqxfHMPsx0SVFjrd623E9gAAACI"]
[Thu Sep 17 15:43:56.985049 2026] [core:error] [pid 60716:tid 60934] [client 172.121.218.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:56.985073 2026] [core:error] [pid 60716:tid 60934] [client 172.121.218.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.007896 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.219.37:53108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxfHcPsx0SVFjrd623E-AAAADw"]
[Thu Sep 17 15:43:57.014774 2026] [security2:error] [pid 60716:tid 60983] [client 34.94.30.138:55174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "aqxfHcPsx0SVFjrd623E-QAAAFk"]
[Thu Sep 17 15:43:57.055107 2026] [core:error] [pid 60716:tid 60966] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.055129 2026] [core:error] [pid 60716:tid 60966] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.176446 2026] [security2:error] [pid 60716:tid 60917] [client 34.166.220.229:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxfHcPsx0SVFjrd623E_gAAABk"]
[Thu Sep 17 15:43:57.177594 2026] [security2:error] [pid 60716:tid 60946] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "aqxfHcPsx0SVFjrd623E_wAAADQ"]
[Thu Sep 17 15:43:57.212344 2026] [security2:error] [pid 60716:tid 60958] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "aqxfHcPsx0SVFjrd623FBAAAAEA"]
[Thu Sep 17 15:43:57.239178 2026] [core:error] [pid 60716:tid 60959] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.239202 2026] [core:error] [pid 60716:tid 60959] [client 34.166.135.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.255410 2026] [security2:error] [pid 60716:tid 61015] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "aqxfHcPsx0SVFjrd623FBgAAAHk"]
[Thu Sep 17 15:43:57.282492 2026] [security2:error] [pid 60716:tid 60971] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "aqxfHcPsx0SVFjrd623FCQAAAE0"]
[Thu Sep 17 15:43:57.305750 2026] [security2:error] [pid 60716:tid 60960] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "aqxfHcPsx0SVFjrd623FCwAAAEI"]
[Thu Sep 17 15:43:57.330837 2026] [security2:error] [pid 60716:tid 60894] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/core/app/.env"] [unique_id "aqxfHcPsx0SVFjrd623FDgAAAAI"]
[Thu Sep 17 15:43:57.334859 2026] [core:error] [pid 60716:tid 61017] [client 172.121.218.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.334874 2026] [core:error] [pid 60716:tid 61017] [client 172.121.218.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.368405 2026] [security2:error] [pid 60716:tid 61014] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "aqxfHcPsx0SVFjrd623FEAAAAHg"]
[Thu Sep 17 15:43:57.400167 2026] [security2:error] [pid 60716:tid 60892] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/private/.env"] [unique_id "aqxfHcPsx0SVFjrd623FEQAAAAA"]
[Thu Sep 17 15:43:57.425589 2026] [security2:error] [pid 60716:tid 60924] [client 189.63.146.109:57665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.146.63.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "livepoint.org"] [uri "/xmlrpc.php"] [unique_id "aqxfHcPsx0SVFjrd623FEgAAAB8"]
[Thu Sep 17 15:43:57.425753 2026] [security2:error] [pid 60716:tid 60924] [client 189.63.146.109:57665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "livepoint.org"] [uri "/xmlrpc.php"] [unique_id "aqxfHcPsx0SVFjrd623FEgAAAB8"]
[Thu Sep 17 15:43:57.451408 2026] [security2:error] [pid 60716:tid 60931] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "aqxfHcPsx0SVFjrd623FFAAAACU"]
[Thu Sep 17 15:43:57.477434 2026] [security2:error] [pid 60716:tid 61003] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/bootstrap/.env"] [unique_id "aqxfHcPsx0SVFjrd623FFgAAAG0"]
[Thu Sep 17 15:43:57.487340 2026] [security2:error] [pid 60716:tid 61016] [client 34.154.219.37:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfHcPsx0SVFjrd623FFwAAAHo"]
[Thu Sep 17 15:43:57.494763 2026] [security2:error] [pid 60716:tid 60977] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/database/.env"] [unique_id "aqxfHcPsx0SVFjrd623FGAAAAFM"]
[Thu Sep 17 15:43:57.561344 2026] [security2:error] [pid 60716:tid 60999] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/storage/.env"] [unique_id "aqxfHcPsx0SVFjrd623FGgAAAGk"]
[Thu Sep 17 15:43:57.603381 2026] [security2:error] [pid 60716:tid 60953] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "aqxfHcPsx0SVFjrd623FGwAAADs"]
[Thu Sep 17 15:43:57.644620 2026] [security2:error] [pid 60716:tid 60895] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "aqxfHcPsx0SVFjrd623FIQAAAAM"]
[Thu Sep 17 15:43:57.656754 2026] [core:error] [pid 60716:tid 60937] [client 172.121.218.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.656772 2026] [core:error] [pid 60716:tid 60937] [client 172.121.218.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:57.673355 2026] [security2:error] [pid 60716:tid 60950] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "aqxfHcPsx0SVFjrd623FJAAAADg"]
[Thu Sep 17 15:43:57.703455 2026] [security2:error] [pid 60716:tid 60911] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/release/.env"] [unique_id "aqxfHcPsx0SVFjrd623FJQAAABM"]
[Thu Sep 17 15:43:57.724705 2026] [security2:error] [pid 60716:tid 60994] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/releases/.env"] [unique_id "aqxfHcPsx0SVFjrd623FJgAAAGQ"]
[Thu Sep 17 15:43:57.743401 2026] [security2:error] [pid 60716:tid 60929] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "aqxfHcPsx0SVFjrd623FJwAAACQ"]
[Thu Sep 17 15:43:57.790971 2026] [security2:error] [pid 60716:tid 60913] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/deploy/.env"] [unique_id "aqxfHcPsx0SVFjrd623FKQAAABU"]
[Thu Sep 17 15:43:57.848749 2026] [security2:error] [pid 60716:tid 60932] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/build/.env"] [unique_id "aqxfHcPsx0SVFjrd623FKgAAACY"]
[Thu Sep 17 15:43:57.857373 2026] [security2:error] [pid 60716:tid 60926] [client 34.166.220.229:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/old/phpinfo.php"] [unique_id "aqxfHcPsx0SVFjrd623FLAAAACE"]
[Thu Sep 17 15:43:57.876127 2026] [security2:error] [pid 60716:tid 60896] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/dist/.env"] [unique_id "aqxfHcPsx0SVFjrd623FLQAAAAQ"]
[Thu Sep 17 15:43:57.894642 2026] [security2:error] [pid 60716:tid 60935] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "aqxfHcPsx0SVFjrd623FMAAAACk"]
[Thu Sep 17 15:43:57.917482 2026] [security2:error] [pid 60716:tid 61008] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/htdocs/.env"] [unique_id "aqxfHcPsx0SVFjrd623FMgAAAHI"]
[Thu Sep 17 15:43:57.958565 2026] [security2:error] [pid 60716:tid 60900] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/www/.env"] [unique_id "aqxfHcPsx0SVFjrd623FNAAAAAg"]
[Thu Sep 17 15:43:57.977963 2026] [security2:error] [pid 60716:tid 60991] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/html/.env"] [unique_id "aqxfHcPsx0SVFjrd623FNQAAAGE"]
[Thu Sep 17 15:43:57.981404 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.219.37:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfHcPsx0SVFjrd623FNgAAAFA"]
[Thu Sep 17 15:43:58.022571 2026] [security2:error] [pid 60716:tid 60943] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/live/.env"] [unique_id "aqxfHsPsx0SVFjrd623FOAAAADE"]
[Thu Sep 17 15:43:58.045146 2026] [security2:error] [pid 60716:tid 60988] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "aqxfHsPsx0SVFjrd623FOgAAAF4"]
[Thu Sep 17 15:43:58.097905 2026] [security2:error] [pid 60716:tid 60922] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "aqxfHsPsx0SVFjrd623FOwAAAB0"]
[Thu Sep 17 15:43:58.136645 2026] [security2:error] [pid 60716:tid 60920] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "aqxfHsPsx0SVFjrd623FPQAAABw"]
[Thu Sep 17 15:43:58.141143 2026] [security2:error] [pid 60716:tid 60949] [client 102.213.132.114:18176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfHsPsx0SVFjrd623FOQAAN3A"]
[Thu Sep 17 15:43:58.158603 2026] [security2:error] [pid 60716:tid 60972] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "aqxfHsPsx0SVFjrd623FQAAAAE4"]
[Thu Sep 17 15:43:58.184434 2026] [security2:error] [pid 60716:tid 60995] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "aqxfHsPsx0SVFjrd623FQwAAAGU"]
[Thu Sep 17 15:43:58.233655 2026] [security2:error] [pid 60716:tid 60899] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/symfony/.env"] [unique_id "aqxfHsPsx0SVFjrd623FRAAAAAc"]
[Thu Sep 17 15:43:58.259597 2026] [security2:error] [pid 60716:tid 60982] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/wordpress/.env"] [unique_id "aqxfHsPsx0SVFjrd623FRgAAAFg"]
[Thu Sep 17 15:43:58.310648 2026] [security2:error] [pid 60716:tid 61001] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/wp/.env"] [unique_id "aqxfHsPsx0SVFjrd623FSAAAAGs"]
[Thu Sep 17 15:43:58.359355 2026] [security2:error] [pid 60716:tid 60936] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "aqxfHsPsx0SVFjrd623FSwAAACo"]
[Thu Sep 17 15:43:58.390811 2026] [security2:error] [pid 60716:tid 60941] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/drupal/.env"] [unique_id "aqxfHsPsx0SVFjrd623FTAAAAC8"]
[Thu Sep 17 15:43:58.422755 2026] [security2:error] [pid 60716:tid 60976] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/joomla/.env"] [unique_id "aqxfHsPsx0SVFjrd623FTQAAAFI"]
[Thu Sep 17 15:43:58.468185 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.219.37:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxfHsPsx0SVFjrd623FTwAAACc"]
[Thu Sep 17 15:43:58.471210 2026] [security2:error] [pid 60716:tid 60919] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/magento/.env"] [unique_id "aqxfHsPsx0SVFjrd623FUAAAABs"]
[Thu Sep 17 15:43:58.503546 2026] [security2:error] [pid 60716:tid 60966] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/shopify/.env"] [unique_id "aqxfHsPsx0SVFjrd623FUQAAAEg"]
[Thu Sep 17 15:43:58.540353 2026] [security2:error] [pid 60716:tid 60963] [client 34.166.220.229:59566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfHsPsx0SVFjrd623FUwAAAEU"]
[Thu Sep 17 15:43:58.549149 2026] [security2:error] [pid 60716:tid 60984] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/prestashop/.env"] [unique_id "aqxfHsPsx0SVFjrd623FVAAAAFo"]
[Thu Sep 17 15:43:58.670293 2026] [security2:error] [pid 60716:tid 60968] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/codeigniter/.env"] [unique_id "aqxfHsPsx0SVFjrd623FVgAAAEo"]
[Thu Sep 17 15:43:58.714874 2026] [security2:error] [pid 60716:tid 60946] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/cakephp/.env"] [unique_id "aqxfHsPsx0SVFjrd623FWgAAADQ"]
[Thu Sep 17 15:43:58.715180 2026] [security2:error] [pid 60716:tid 60958] [client 40.81.232.68:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.232.81.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houselifeinc.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "aqxfHsPsx0SVFjrd623FWwAAAEA"], referer: binance.com
[Thu Sep 17 15:43:58.749486 2026] [security2:error] [pid 60716:tid 60959] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/zend/.env"] [unique_id "aqxfHsPsx0SVFjrd623FXQAAAEE"]
[Thu Sep 17 15:43:58.783799 2026] [security2:error] [pid 60716:tid 60952] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/yii/.env"] [unique_id "aqxfHsPsx0SVFjrd623FXwAAADo"]
[Thu Sep 17 15:43:58.811152 2026] [security2:error] [pid 60716:tid 60947] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/laravel5/.env"] [unique_id "aqxfHsPsx0SVFjrd623FYQAAADU"]
[Thu Sep 17 15:43:58.859797 2026] [security2:error] [pid 60716:tid 61017] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "aqxfHsPsx0SVFjrd623FYgAAAHs"]
[Thu Sep 17 15:43:58.899911 2026] [security2:error] [pid 60716:tid 61011] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "aqxfHsPsx0SVFjrd623FYwAAAHU"]
[Thu Sep 17 15:43:58.917944 2026] [security2:error] [pid 60716:tid 60970] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "aqxfHsPsx0SVFjrd623FZQAAAEw"]
[Thu Sep 17 15:43:58.941536 2026] [security2:error] [pid 60716:tid 60960] [client 34.154.219.37:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.219.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.emp.zyt.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxfHsPsx0SVFjrd623FZgAAAEI"]
[Thu Sep 17 15:43:58.956405 2026] [security2:error] [pid 60716:tid 61014] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/api/v1/.env"] [unique_id "aqxfHsPsx0SVFjrd623FZwAAAHg"]
[Thu Sep 17 15:43:58.979137 2026] [security2:error] [pid 60716:tid 60928] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/api/v2/.env"] [unique_id "aqxfHsPsx0SVFjrd623FaQAAACM"]
[Thu Sep 17 15:43:59.005339 2026] [security2:error] [pid 60716:tid 60924] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/rest/.env"] [unique_id "aqxfH8Psx0SVFjrd623FawAAAB8"]
[Thu Sep 17 15:43:59.046091 2026] [security2:error] [pid 60716:tid 60985] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/graphql/.env"] [unique_id "aqxfH8Psx0SVFjrd623FbAAAAFs"]
[Thu Sep 17 15:43:59.090096 2026] [security2:error] [pid 60716:tid 61016] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/gateway/.env"] [unique_id "aqxfH8Psx0SVFjrd623FbgAAAHo"]
[Thu Sep 17 15:43:59.116444 2026] [security2:error] [pid 60716:tid 60906] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/microservice/.env"] [unique_id "aqxfH8Psx0SVFjrd623FbwAAAA4"]
[Thu Sep 17 15:43:59.146036 2026] [security2:error] [pid 60716:tid 60944] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "aqxfH8Psx0SVFjrd623FcwAAADI"]
[Thu Sep 17 15:43:59.195504 2026] [security2:error] [pid 60716:tid 60937] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/api/v3/.env"] [unique_id "aqxfH8Psx0SVFjrd623FdAAAACs"]
[Thu Sep 17 15:43:59.230513 2026] [security2:error] [pid 60716:tid 60993] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/api/dev/.env"] [unique_id "aqxfH8Psx0SVFjrd623FdgAAAGM"]
[Thu Sep 17 15:43:59.233083 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.220.229:59568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/public/phpinfo.php"] [unique_id "aqxfH8Psx0SVFjrd623FdwAAAFY"]
[Thu Sep 17 15:43:59.250313 2026] [security2:error] [pid 60716:tid 61012] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/api/staging/.env"] [unique_id "aqxfH8Psx0SVFjrd623FeAAAAHY"]
[Thu Sep 17 15:43:59.271070 2026] [security2:error] [pid 60716:tid 60950] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/vendor/.env"] [unique_id "aqxfH8Psx0SVFjrd623FeQAAADg"]
[Thu Sep 17 15:43:59.299379 2026] [security2:error] [pid 60716:tid 60905] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/lib/.env"] [unique_id "aqxfH8Psx0SVFjrd623FegAAAA0"]
[Thu Sep 17 15:43:59.325280 2026] [security2:error] [pid 60716:tid 60992] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/resources/.env"] [unique_id "aqxfH8Psx0SVFjrd623FfQAAAGI"]
[Thu Sep 17 15:43:59.346958 2026] [security2:error] [pid 60716:tid 60897] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/assets/.env"] [unique_id "aqxfH8Psx0SVFjrd623FfgAAAAU"]
[Thu Sep 17 15:43:59.373998 2026] [security2:error] [pid 60716:tid 60987] [client 169.58.197.253:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxfH8Psx0SVFjrd623FfwAAAF0"], referer: binance.com
[Thu Sep 17 15:43:59.379645 2026] [security2:error] [pid 60716:tid 60911] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/uploads/.env"] [unique_id "aqxfH8Psx0SVFjrd623FgAAAABM"]
[Thu Sep 17 15:43:59.428042 2026] [security2:error] [pid 60716:tid 60994] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/internal/.env"] [unique_id "aqxfH8Psx0SVFjrd623FgQAAAGQ"]
[Thu Sep 17 15:43:59.455704 2026] [security2:error] [pid 60716:tid 60929] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/tools/.env"] [unique_id "aqxfH8Psx0SVFjrd623FhAAAACQ"]
[Thu Sep 17 15:43:59.486666 2026] [security2:error] [pid 60716:tid 60913] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/scripts/.env"] [unique_id "aqxfH8Psx0SVFjrd623FhgAAABU"]
[Thu Sep 17 15:43:59.509317 2026] [security2:error] [pid 60716:tid 60932] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/bin/.env"] [unique_id "aqxfH8Psx0SVFjrd623FhwAAACY"]
[Thu Sep 17 15:43:59.562185 2026] [security2:error] [pid 60716:tid 60935] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/sbin/.env"] [unique_id "aqxfH8Psx0SVFjrd623FigAAACk"]
[Thu Sep 17 15:43:59.637575 2026] [security2:error] [pid 60716:tid 60938] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "aqxfH8Psx0SVFjrd623FjAAAACw"]
[Thu Sep 17 15:43:59.680367 2026] [security2:error] [pid 60716:tid 60943] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "aqxfH8Psx0SVFjrd623FlQAAADE"]
[Thu Sep 17 15:43:59.764728 2026] [security2:error] [pid 60716:tid 60972] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/dashboard/.env"] [unique_id "aqxfH8Psx0SVFjrd623FmQAAAE4"]
[Thu Sep 17 15:43:59.802827 2026] [security2:error] [pid 60716:tid 60995] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/panel/.env"] [unique_id "aqxfH8Psx0SVFjrd623FmgAAAGU"]
[Thu Sep 17 15:43:59.821738 2026] [security2:error] [pid 60716:tid 60893] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "aqxfH8Psx0SVFjrd623FmwAAAAE"]
[Thu Sep 17 15:43:59.856242 2026] [security2:error] [pid 60716:tid 60909] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "aqxfH8Psx0SVFjrd623FnQAAABE"]
[Thu Sep 17 15:43:59.883298 2026] [security2:error] [pid 60716:tid 61021] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "aqxfH8Psx0SVFjrd623FoAAAAH8"]
[Thu Sep 17 15:43:59.934747 2026] [security2:error] [pid 60716:tid 61001] [client 34.94.30.138:55190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/store/.env"] [unique_id "aqxfH8Psx0SVFjrd623FogAAAGs"]
[Thu Sep 17 15:43:59.997948 2026] [core:error] [pid 60716:tid 60936] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:43:59.997967 2026] [core:error] [pid 60716:tid 60936] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:00.035551 2026] [security2:error] [pid 60716:tid 60942] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/saas/.env"] [unique_id "aqxfIMPsx0SVFjrd623FpwAAADA"]
[Thu Sep 17 15:44:00.077420 2026] [security2:error] [pid 60716:tid 60963] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "aqxfIMPsx0SVFjrd623FqwAAAEU"]
[Thu Sep 17 15:44:00.128028 2026] [security2:error] [pid 60716:tid 60903] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "aqxfIMPsx0SVFjrd623FrAAAAAs"]
[Thu Sep 17 15:44:00.158250 2026] [security2:error] [pid 60716:tid 60939] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/admin-panel/.env"] [unique_id "aqxfIMPsx0SVFjrd623FrwAAAC0"]
[Thu Sep 17 15:44:00.184718 2026] [security2:error] [pid 60716:tid 60917] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/control-panel/.env"] [unique_id "aqxfIMPsx0SVFjrd623FsgAAABk"]
[Thu Sep 17 15:44:00.220011 2026] [security2:error] [pid 60716:tid 60959] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/user-panel/.env"] [unique_id "aqxfIMPsx0SVFjrd623FswAAAEE"]
[Thu Sep 17 15:44:00.244584 2026] [security2:error] [pid 60716:tid 60907] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "aqxfIMPsx0SVFjrd623FtAAAAA8"]
[Thu Sep 17 15:44:00.282958 2026] [security2:error] [pid 60716:tid 61019] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/express/.env"] [unique_id "aqxfIMPsx0SVFjrd623FtwAAAH0"]
[Thu Sep 17 15:44:00.314097 2026] [security2:error] [pid 60716:tid 61010] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/next/.env"] [unique_id "aqxfIMPsx0SVFjrd623FuAAAAHQ"]
[Thu Sep 17 15:44:00.354884 2026] [security2:error] [pid 60716:tid 60952] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/nuxt/.env"] [unique_id "aqxfIMPsx0SVFjrd623FuwAAADo"]
[Thu Sep 17 15:44:00.412569 2026] [security2:error] [pid 60716:tid 60973] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/nest/.env"] [unique_id "aqxfIMPsx0SVFjrd623FvAAAAE8"]
[Thu Sep 17 15:44:00.437930 2026] [security2:error] [pid 60716:tid 60986] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/react/.env"] [unique_id "aqxfIMPsx0SVFjrd623FvQAAAFw"]
[Thu Sep 17 15:44:00.473117 2026] [security2:error] [pid 60716:tid 60998] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/vue/.env"] [unique_id "aqxfIMPsx0SVFjrd623FwQAAAGg"]
[Thu Sep 17 15:44:00.493029 2026] [security2:error] [pid 60716:tid 60945] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/angular/.env"] [unique_id "aqxfIMPsx0SVFjrd623FwwAAADM"]
[Thu Sep 17 15:44:00.527530 2026] [security2:error] [pid 60716:tid 61014] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/svelte/.env"] [unique_id "aqxfIMPsx0SVFjrd623FxQAAAHg"]
[Thu Sep 17 15:44:00.565828 2026] [security2:error] [pid 60716:tid 60892] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/vite/.env"] [unique_id "aqxfIMPsx0SVFjrd623FxgAAAAA"]
[Thu Sep 17 15:44:00.589174 2026] [security2:error] [pid 60716:tid 60928] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "aqxfIMPsx0SVFjrd623FxwAAACM"]
[Thu Sep 17 15:44:00.604971 2026] [security2:error] [pid 60716:tid 60872] [remote 111.225.148.188:43616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.npae.net"] [uri "/category/competition/"] [unique_id "aqxfIMPsx0SVFjrd623FyAAAS24"]
[Thu Sep 17 15:44:00.606972 2026] [security2:error] [pid 60716:tid 60918] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/backups/.env"] [unique_id "aqxfIMPsx0SVFjrd623FyQAAABo"]
[Thu Sep 17 15:44:00.637828 2026] [security2:error] [pid 60716:tid 60924] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "aqxfIMPsx0SVFjrd623FygAAAB8"]
[Thu Sep 17 15:44:00.684463 2026] [security2:error] [pid 60716:tid 61017] [client 34.166.220.229:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/php-info.php"] [unique_id "aqxfIMPsx0SVFjrd623F0gAAAHs"]
[Thu Sep 17 15:44:00.695649 2026] [security2:error] [pid 60716:tid 60944] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/tmp/.env"] [unique_id "aqxfIMPsx0SVFjrd623F0wAAADI"]
[Thu Sep 17 15:44:00.709864 2026] [security2:error] [pid 60716:tid 60993] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/temp/.env"] [unique_id "aqxfIMPsx0SVFjrd623F1AAAAGM"]
[Thu Sep 17 15:44:00.741979 2026] [security2:error] [pid 60716:tid 60950] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/lab/.env"] [unique_id "aqxfIMPsx0SVFjrd623F1wAAADg"]
[Thu Sep 17 15:44:00.833971 2026] [security2:error] [pid 60716:tid 60994] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/cronlab/.env"] [unique_id "aqxfIMPsx0SVFjrd623F3AAAAGQ"]
[Thu Sep 17 15:44:00.879454 2026] [security2:error] [pid 60716:tid 61000] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "aqxfIMPsx0SVFjrd623F4AAAAGo"]
[Thu Sep 17 15:44:00.907504 2026] [security2:error] [pid 60716:tid 60965] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/en/.env"] [unique_id "aqxfIMPsx0SVFjrd623F4QAAAEc"]
[Thu Sep 17 15:44:01.001009 2026] [security2:error] [pid 60716:tid 60908] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "aqxfIMPsx0SVFjrd623F4gAAABA"]
[Thu Sep 17 15:44:01.026837 2026] [security2:error] [pid 60716:tid 60943] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/psnlink/.env"] [unique_id "aqxfIcPsx0SVFjrd623F5AAAADE"]
[Thu Sep 17 15:44:01.087560 2026] [security2:error] [pid 60716:tid 60922] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/exapi/.env"] [unique_id "aqxfIcPsx0SVFjrd623F7gAAAB0"]
[Thu Sep 17 15:44:01.115026 2026] [security2:error] [pid 60716:tid 60972] [client 34.94.30.138:55206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/sitemaps/.env"] [unique_id "aqxfIcPsx0SVFjrd623F8AAAAE4"]
[Thu Sep 17 15:44:01.198721 2026] [security2:error] [pid 60716:tid 60982] [client 169.58.197.251:49568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxfIcPsx0SVFjrd623F9wAAAFg"], referer: binance.com
[Thu Sep 17 15:44:01.207906 2026] [core:error] [pid 60716:tid 61021] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:01.207927 2026] [core:error] [pid 60716:tid 61021] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:01.325538 2026] [core:error] [pid 60716:tid 60925] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:01.325558 2026] [core:error] [pid 60716:tid 60925] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:01.362418 2026] [security2:error] [pid 60716:tid 60900] [client 34.166.220.229:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/phpversion.php"] [unique_id "aqxfIcPsx0SVFjrd623GAwAAAAg"]
[Thu Sep 17 15:44:01.427321 2026] [security2:error] [pid 60716:tid 60958] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/logs/.env"] [unique_id "aqxfIcPsx0SVFjrd623GBAAAAEA"]
[Thu Sep 17 15:44:01.455860 2026] [security2:error] [pid 60716:tid 60964] [client 114.119.141.133:52335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "churchinirving.org"] [uri "/announcements-2/"] [unique_id "aqxfIcPsx0SVFjrd623GBwAAAEY"], referer: https://churchinirving.org/
[Thu Sep 17 15:44:01.472635 2026] [security2:error] [pid 60716:tid 61015] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/cache/.env"] [unique_id "aqxfIcPsx0SVFjrd623GCAAAAHk"]
[Thu Sep 17 15:44:01.507762 2026] [security2:error] [pid 60716:tid 60990] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mailer/.env"] [unique_id "aqxfIcPsx0SVFjrd623GCQAAAGA"]
[Thu Sep 17 15:44:01.545144 2026] [security2:error] [pid 60716:tid 61010] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mail/.env"] [unique_id "aqxfIcPsx0SVFjrd623GDQAAAHQ"]
[Thu Sep 17 15:44:01.572038 2026] [security2:error] [pid 60716:tid 60981] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/email/.env"] [unique_id "aqxfIcPsx0SVFjrd623GEAAAAFc"]
[Thu Sep 17 15:44:01.605473 2026] [security2:error] [pid 60716:tid 60947] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/smtp/.env"] [unique_id "aqxfIcPsx0SVFjrd623GEwAAADU"]
[Thu Sep 17 15:44:01.644333 2026] [security2:error] [pid 60716:tid 60915] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mailing/.env"] [unique_id "aqxfIcPsx0SVFjrd623GFwAAABc"]
[Thu Sep 17 15:44:01.674151 2026] [security2:error] [pid 60716:tid 60985] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/notifications/.env"] [unique_id "aqxfIcPsx0SVFjrd623GGwAAAFs"]
[Thu Sep 17 15:44:01.732792 2026] [security2:error] [pid 60716:tid 60978] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/notify/.env"] [unique_id "aqxfIcPsx0SVFjrd623GHgAAAFQ"]
[Thu Sep 17 15:44:01.752298 2026] [security2:error] [pid 60716:tid 60937] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/sender/.env"] [unique_id "aqxfIcPsx0SVFjrd623GIAAAACs"]
[Thu Sep 17 15:44:01.755822 2026] [security2:error] [pid 60716:tid 60842] [remote 111.225.149.172:41174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "npae.net"] [uri "/"] [unique_id "aqxfIcPsx0SVFjrd623GIQAAelA"]
[Thu Sep 17 15:44:01.778277 2026] [security2:error] [pid 60716:tid 60931] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/campaign/.env"] [unique_id "aqxfIcPsx0SVFjrd623GIgAAACU"]
[Thu Sep 17 15:44:01.808761 2026] [security2:error] [pid 60716:tid 60980] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/newsletter/.env"] [unique_id "aqxfIcPsx0SVFjrd623GJAAAAFY"]
[Thu Sep 17 15:44:01.840819 2026] [security2:error] [pid 60716:tid 60961] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/ses/.env"] [unique_id "aqxfIcPsx0SVFjrd623GJQAAAEM"]
[Thu Sep 17 15:44:01.867032 2026] [security2:error] [pid 60716:tid 60992] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/sendgrid/.env"] [unique_id "aqxfIcPsx0SVFjrd623GJwAAAGI"]
[Thu Sep 17 15:44:01.915808 2026] [security2:error] [pid 60716:tid 60914] [client 103.61.184.148:55613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfIcPsx0SVFjrd623GLAAAABY"]
[Thu Sep 17 15:44:01.915949 2026] [security2:error] [pid 60716:tid 60914] [client 103.61.184.148:55613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfIcPsx0SVFjrd623GLAAAABY"]
[Thu Sep 17 15:44:01.921967 2026] [security2:error] [pid 60716:tid 60994] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/sparkpost/.env"] [unique_id "aqxfIcPsx0SVFjrd623GLQAAAGQ"]
[Thu Sep 17 15:44:01.945700 2026] [security2:error] [pid 60716:tid 60897] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/postmark/.env"] [unique_id "aqxfIcPsx0SVFjrd623GLwAAAAU"]
[Thu Sep 17 15:44:01.977238 2026] [security2:error] [pid 60716:tid 60913] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mailgun/.env"] [unique_id "aqxfIcPsx0SVFjrd623GMgAAABU"]
[Thu Sep 17 15:44:01.998006 2026] [security2:error] [pid 60716:tid 61003] [client 148.227.75.216:4642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfIcPsx0SVFjrd623GMwAAAG0"]
[Thu Sep 17 15:44:02.005442 2026] [security2:error] [pid 60716:tid 60908] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mandrill/.env"] [unique_id "aqxfIsPsx0SVFjrd623GNAAAABA"]
[Thu Sep 17 15:44:02.010074 2026] [security2:error] [pid 60716:tid 61003] [client 148.227.75.216:4642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfIcPsx0SVFjrd623GMwAAAG0"]
[Thu Sep 17 15:44:02.024805 2026] [security2:error] [pid 60716:tid 60943] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mailjet/.env"] [unique_id "aqxfIsPsx0SVFjrd623GNQAAADE"]
[Thu Sep 17 15:44:02.041625 2026] [security2:error] [pid 60716:tid 61005] [client 34.166.220.229:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/_phpinfo.php"] [unique_id "aqxfIsPsx0SVFjrd623GNwAAAG8"]
[Thu Sep 17 15:44:02.123559 2026] [security2:error] [pid 60716:tid 60996] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/brevo/.env"] [unique_id "aqxfIsPsx0SVFjrd623GPQAAAGY"]
[Thu Sep 17 15:44:02.141811 2026] [security2:error] [pid 60716:tid 60893] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/transactional/.env"] [unique_id "aqxfIsPsx0SVFjrd623GPwAAAAE"]
[Thu Sep 17 15:44:02.207582 2026] [security2:error] [pid 60716:tid 60936] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/bulk/.env"] [unique_id "aqxfIsPsx0SVFjrd623GRAAAACo"]
[Thu Sep 17 15:44:02.263386 2026] [security2:error] [pid 60716:tid 60962] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/aws/.env"] [unique_id "aqxfIsPsx0SVFjrd623GRwAAAEQ"]
[Thu Sep 17 15:44:02.307815 2026] [security2:error] [pid 60716:tid 60983] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/azure/.env"] [unique_id "aqxfIsPsx0SVFjrd623GSQAAAFk"]
[Thu Sep 17 15:44:02.367787 2026] [security2:error] [pid 60716:tid 60974] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/gcp/.env"] [unique_id "aqxfIsPsx0SVFjrd623GVwAAAFA"]
[Thu Sep 17 15:44:02.426848 2026] [security2:error] [pid 60716:tid 60939] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/cloud/.env"] [unique_id "aqxfIsPsx0SVFjrd623GbQAAAC0"]
[Thu Sep 17 15:44:02.460681 2026] [security2:error] [pid 60716:tid 60899] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/infrastructure/.env"] [unique_id "aqxfIsPsx0SVFjrd623GbwAAAAc"]
[Thu Sep 17 15:44:02.486837 2026] [security2:error] [pid 60716:tid 60903] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/docker/.env"] [unique_id "aqxfIsPsx0SVFjrd623GcAAAAAs"]
[Thu Sep 17 15:44:02.524992 2026] [security2:error] [pid 60716:tid 60958] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/k8s/.env"] [unique_id "aqxfIsPsx0SVFjrd623GhwAAAEA"]
[Thu Sep 17 15:44:02.567941 2026] [security2:error] [pid 60716:tid 61015] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/kubernetes/.env"] [unique_id "aqxfIsPsx0SVFjrd623GiQAAAHk"]
[Thu Sep 17 15:44:02.626932 2026] [security2:error] [pid 60716:tid 60990] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/terraform/.env"] [unique_id "aqxfIsPsx0SVFjrd623GjAAAAGA"]
[Thu Sep 17 15:44:02.685068 2026] [security2:error] [pid 60716:tid 61010] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/ansible/.env"] [unique_id "aqxfIsPsx0SVFjrd623GjwAAAHQ"]
[Thu Sep 17 15:44:02.729164 2026] [security2:error] [pid 60716:tid 60917] [client 34.166.220.229:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/old_phpinfo.php"] [unique_id "aqxfIsPsx0SVFjrd623GkgAAABk"]
[Thu Sep 17 15:44:02.776672 2026] [security2:error] [pid 60716:tid 60945] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/.git/.env"] [unique_id "aqxfIsPsx0SVFjrd623GlAAAADM"]
[Thu Sep 17 15:44:02.802807 2026] [security2:error] [pid 60716:tid 60894] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/ci/.env"] [unique_id "aqxfIsPsx0SVFjrd623GlQAAAAI"]
[Thu Sep 17 15:44:02.869787 2026] [security2:error] [pid 60716:tid 60985] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/cd/.env"] [unique_id "aqxfIsPsx0SVFjrd623GlgAAAFs"]
[Thu Sep 17 15:44:02.917581 2026] [security2:error] [pid 60716:tid 61014] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/jenkins/.env"] [unique_id "aqxfIsPsx0SVFjrd623GmwAAAHg"]
[Thu Sep 17 15:44:02.946596 2026] [security2:error] [pid 60716:tid 60952] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/gitlab/.env"] [unique_id "aqxfIsPsx0SVFjrd623GnQAAADo"]
[Thu Sep 17 15:44:02.990682 2026] [security2:error] [pid 60716:tid 60993] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/github/.env"] [unique_id "aqxfIsPsx0SVFjrd623GngAAAGM"]
[Thu Sep 17 15:44:03.024603 2026] [security2:error] [pid 60716:tid 60950] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/actions/.env"] [unique_id "aqxfI8Psx0SVFjrd623GnwAAADg"]
[Thu Sep 17 15:44:03.062136 2026] [security2:error] [pid 60716:tid 60895] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/circleci/.env"] [unique_id "aqxfI8Psx0SVFjrd623GowAAAAM"]
[Thu Sep 17 15:44:03.106681 2026] [security2:error] [pid 60716:tid 60913] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/travis/.env"] [unique_id "aqxfI8Psx0SVFjrd623GpQAAABU"]
[Thu Sep 17 15:44:03.150237 2026] [security2:error] [pid 60716:tid 60908] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/buildkite/.env"] [unique_id "aqxfI8Psx0SVFjrd623GpwAAABA"]
[Thu Sep 17 15:44:03.161501 2026] [security2:error] [pid 60716:tid 60906] [client 14.96.156.146:54688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfI8Psx0SVFjrd623GqgAAAA4"]
[Thu Sep 17 15:44:03.161611 2026] [security2:error] [pid 60716:tid 60906] [client 14.96.156.146:54688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfI8Psx0SVFjrd623GqgAAAA4"]
[Thu Sep 17 15:44:03.206619 2026] [security2:error] [pid 60716:tid 60967] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mysql/.env"] [unique_id "aqxfI8Psx0SVFjrd623GrQAAAEk"]
[Thu Sep 17 15:44:03.228308 2026] [security2:error] [pid 60716:tid 60986] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/postgres/.env"] [unique_id "aqxfI8Psx0SVFjrd623GrwAAAFw"]
[Thu Sep 17 15:44:03.264437 2026] [security2:error] [pid 60716:tid 60988] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/mongodb/.env"] [unique_id "aqxfI8Psx0SVFjrd623GtAAAAF4"]
[Thu Sep 17 15:44:03.299432 2026] [security2:error] [pid 60716:tid 60989] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/redis/.env"] [unique_id "aqxfI8Psx0SVFjrd623GvQAAAF8"]
[Thu Sep 17 15:44:03.333427 2026] [security2:error] [pid 60716:tid 60904] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/elasticsearch/.env"] [unique_id "aqxfI8Psx0SVFjrd623GwAAAAAw"]
[Thu Sep 17 15:44:03.366765 2026] [security2:error] [pid 60716:tid 60896] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/rabbitmq/.env"] [unique_id "aqxfI8Psx0SVFjrd623GwQAAAAQ"]
[Thu Sep 17 15:44:03.398964 2026] [security2:error] [pid 60716:tid 60910] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/kafka/.env"] [unique_id "aqxfI8Psx0SVFjrd623GwwAAABI"]
[Thu Sep 17 15:44:03.415145 2026] [security2:error] [pid 60716:tid 61004] [client 34.166.220.229:59612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/server-info.php"] [unique_id "aqxfI8Psx0SVFjrd623GxQAAAG4"]
[Thu Sep 17 15:44:03.421354 2026] [security2:error] [pid 60716:tid 60907] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/queue/.env"] [unique_id "aqxfI8Psx0SVFjrd623GxgAAAA8"]
[Thu Sep 17 15:44:03.473545 2026] [security2:error] [pid 60716:tid 60949] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/worker/.env"] [unique_id "aqxfI8Psx0SVFjrd623GyAAAADc"]
[Thu Sep 17 15:44:03.532675 2026] [security2:error] [pid 60716:tid 61020] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/job/.env"] [unique_id "aqxfI8Psx0SVFjrd623GyQAAAH4"]
[Thu Sep 17 15:44:03.632497 2026] [security2:error] [pid 60716:tid 60934] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "aqxfI8Psx0SVFjrd623GywAAACg"]
[Thu Sep 17 15:44:03.663879 2026] [security2:error] [pid 60716:tid 60951] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "aqxfI8Psx0SVFjrd623GzQAAADk"]
[Thu Sep 17 15:44:03.725152 2026] [security2:error] [pid 60716:tid 60966] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/preview/.env"] [unique_id "aqxfI8Psx0SVFjrd623G0gAAAEg"]
[Thu Sep 17 15:44:03.752280 2026] [security2:error] [pid 60716:tid 61015] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "aqxfI8Psx0SVFjrd623G1QAAAHk"]
[Thu Sep 17 15:44:03.805020 2026] [security2:error] [pid 60716:tid 61010] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/uat/.env"] [unique_id "aqxfI8Psx0SVFjrd623G1wAAAHQ"]
[Thu Sep 17 15:44:03.821453 2026] [security2:error] [pid 60716:tid 60955] [client 136.158.61.34:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfI8Psx0SVFjrd623G2gAAAD0"]
[Thu Sep 17 15:44:03.821577 2026] [security2:error] [pid 60716:tid 60955] [client 136.158.61.34:50514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfI8Psx0SVFjrd623G2gAAAD0"]
[Thu Sep 17 15:44:03.831777 2026] [security2:error] [pid 60716:tid 61002] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "aqxfI8Psx0SVFjrd623G2wAAAGw"]
[Thu Sep 17 15:44:03.868316 2026] [security2:error] [pid 60716:tid 60975] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "aqxfI8Psx0SVFjrd623G3gAAAFE"]
[Thu Sep 17 15:44:03.912471 2026] [security2:error] [pid 60716:tid 61011] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "aqxfI8Psx0SVFjrd623G4QAAAHU"]
[Thu Sep 17 15:44:03.932921 2026] [security2:error] [pid 60716:tid 60892] [client 34.94.30.138:55218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.hendersonlife.info"] [uri "/___proxy_subdomain_webdisk/config/app/.env"] [unique_id "aqxfI8Psx0SVFjrd623G4wAAAAA"]
[Thu Sep 17 15:44:03.988581 2026] [security2:error] [pid 60716:tid 60978] [client 34.94.30.138:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/phpinfo.php"] [unique_id "aqxfI8Psx0SVFjrd623G5gAAAFQ"]
[Thu Sep 17 15:44:04.096344 2026] [security2:error] [pid 60716:tid 60945] [client 34.166.220.229:59614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/server-status.php"] [unique_id "aqxfJMPsx0SVFjrd623G7QAAADM"]
[Thu Sep 17 15:44:04.133418 2026] [security2:error] [pid 60716:tid 60950] [client 34.94.30.138:55228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/info.php"] [unique_id "aqxfJMPsx0SVFjrd623G8AAAADg"]
[Thu Sep 17 15:44:04.251172 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.129.237:38666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.charlesgiraudet.com"] [uri "/"] [unique_id "aqxfJMPsx0SVFjrd623G-wAAAAY"]
[Thu Sep 17 15:44:04.330565 2026] [security2:error] [pid 60716:tid 61008] [client 34.94.30.138:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/php.php"] [unique_id "aqxfJMPsx0SVFjrd623G_QAAAHI"]
[Thu Sep 17 15:44:04.495482 2026] [security2:error] [pid 60716:tid 60907] [client 34.94.30.138:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/i.php"] [unique_id "aqxfJMPsx0SVFjrd623HBAAAAA8"]
[Thu Sep 17 15:44:04.680512 2026] [security2:error] [pid 60716:tid 61007] [client 34.94.30.138:60032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/pi.php"] [unique_id "aqxfJMPsx0SVFjrd623HDgAAAHE"]
[Thu Sep 17 15:44:04.808508 2026] [core:error] [pid 60716:tid 61010] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:04.808538 2026] [core:error] [pid 60716:tid 61010] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:04.846113 2026] [security2:error] [pid 60716:tid 60976] [client 34.94.30.138:60044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/pinfo.php"] [unique_id "aqxfJMPsx0SVFjrd623HHAAAAFI"]
[Thu Sep 17 15:44:04.932330 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.129.237:38674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.charlesgiraudet.com"] [uri "/"] [unique_id "aqxfJMPsx0SVFjrd623HHgAAAAc"]
[Thu Sep 17 15:44:04.985384 2026] [security2:error] [pid 60716:tid 61014] [client 34.94.30.138:60046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/test.php"] [unique_id "aqxfJMPsx0SVFjrd623HHwAAAHg"]
[Thu Sep 17 15:44:05.123466 2026] [security2:error] [pid 60716:tid 60990] [client 177.44.133.72:49327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfJcPsx0SVFjrd623HIQAAAGA"]
[Thu Sep 17 15:44:05.123618 2026] [security2:error] [pid 60716:tid 60990] [client 177.44.133.72:49327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfJcPsx0SVFjrd623HIQAAAGA"]
[Thu Sep 17 15:44:05.173760 2026] [core:error] [pid 60716:tid 60895] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:05.173785 2026] [core:error] [pid 60716:tid 60895] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:05.210549 2026] [security2:error] [pid 60716:tid 60985] [client 162.241.226.11:23638] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxfJcPsx0SVFjrd623HKAAAAFs"]
[Thu Sep 17 15:44:05.330472 2026] [security2:error] [pid 60716:tid 61005] [client 34.94.30.138:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/p.php"] [unique_id "aqxfJcPsx0SVFjrd623HKwAAAG8"]
[Thu Sep 17 15:44:05.468929 2026] [security2:error] [pid 60716:tid 60943] [client 34.94.30.138:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/debug.php"] [unique_id "aqxfJcPsx0SVFjrd623HLQAAADE"]
[Thu Sep 17 15:44:05.523227 2026] [core:error] [pid 60716:tid 60898] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:05.523247 2026] [core:error] [pid 60716:tid 60898] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:05.615015 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.129.237:38678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.charlesgiraudet.com"] [uri "/"] [unique_id "aqxfJcPsx0SVFjrd623HMgAAAB4"]
[Thu Sep 17 15:44:05.621053 2026] [security2:error] [pid 60716:tid 61012] [client 34.94.30.138:60062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/admin/phpinfo.php"] [unique_id "aqxfJcPsx0SVFjrd623HMwAAAHY"]
[Thu Sep 17 15:44:05.748913 2026] [security2:error] [pid 60716:tid 60928] [client 143.105.152.240:48148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfJcPsx0SVFjrd623HPAAAACM"]
[Thu Sep 17 15:44:05.749036 2026] [security2:error] [pid 60716:tid 60928] [client 143.105.152.240:48148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfJcPsx0SVFjrd623HPAAAACM"]
[Thu Sep 17 15:44:05.785927 2026] [security2:error] [pid 60716:tid 60904] [client 34.94.30.138:60076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/test/phpinfo.php"] [unique_id "aqxfJcPsx0SVFjrd623HPgAAAAw"]
[Thu Sep 17 15:44:06.002310 2026] [security2:error] [pid 60716:tid 60926] [client 34.94.30.138:60082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/dev/phpinfo.php"] [unique_id "aqxfJsPsx0SVFjrd623HQQAAACE"]
[Thu Sep 17 15:44:06.090951 2026] [security2:error] [pid 60716:tid 60972] [client 34.94.30.138:60096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/old/phpinfo.php"] [unique_id "aqxfJsPsx0SVFjrd623HQwAAAE4"]
[Thu Sep 17 15:44:06.211792 2026] [security2:error] [pid 60716:tid 61004] [client 34.166.220.229:36468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfJsPsx0SVFjrd623HRwAAAG4"]
[Thu Sep 17 15:44:06.328743 2026] [security2:error] [pid 60716:tid 60981] [client 34.94.30.138:60106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfJsPsx0SVFjrd623HUQAAAFc"]
[Thu Sep 17 15:44:06.330984 2026] [security2:error] [pid 60716:tid 60954] [client 35.150.56.8:59020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiansoncampusnlc.com"] [uri "/index.php"] [unique_id "aqxfJsPsx0SVFjrd623HSAAAPGw"]
[Thu Sep 17 15:44:06.467904 2026] [security2:error] [pid 60716:tid 61014] [client 34.94.30.138:60122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/public/phpinfo.php"] [unique_id "aqxfJsPsx0SVFjrd623HVAAAAHg"]
[Thu Sep 17 15:44:06.530442 2026] [security2:error] [pid 60716:tid 60993] [client 34.166.129.237:38694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.charlesgiraudet.com"] [uri "/"] [unique_id "aqxfJsPsx0SVFjrd623HVwAAAGM"]
[Thu Sep 17 15:44:06.659021 2026] [core:error] [pid 60716:tid 60959] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:06.659046 2026] [core:error] [pid 60716:tid 60959] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:06.800923 2026] [security2:error] [pid 60716:tid 60963] [client 103.186.139.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivorygarlock.com"] [uri "/index.php"] [unique_id "aqxfJsPsx0SVFjrd623HXQAAAEU"], referer: https://ivorygarlock.com/work/
[Thu Sep 17 15:44:06.846896 2026] [security2:error] [pid 60716:tid 60970] [client 34.94.30.138:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/php-info.php"] [unique_id "aqxfJsPsx0SVFjrd623HaAAAAEw"]
[Thu Sep 17 15:44:06.893816 2026] [security2:error] [pid 60716:tid 60946] [client 34.166.220.229:36476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxfJsPsx0SVFjrd623HaQAAADQ"]
[Thu Sep 17 15:44:06.984658 2026] [security2:error] [pid 60716:tid 61000] [client 34.94.30.138:60148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/phpversion.php"] [unique_id "aqxfJsPsx0SVFjrd623HbQAAAGo"]
[Thu Sep 17 15:44:07.200323 2026] [security2:error] [pid 60716:tid 60916] [client 34.94.30.138:60156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/_phpinfo.php"] [unique_id "aqxfJ8Psx0SVFjrd623HcgAAABg"]
[Thu Sep 17 15:44:07.249916 2026] [security2:error] [pid 60716:tid 60994] [client 79.116.89.151:51993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfJ8Psx0SVFjrd623HdQAAAGQ"]
[Thu Sep 17 15:44:07.250100 2026] [security2:error] [pid 60716:tid 60994] [client 79.116.89.151:51993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfJ8Psx0SVFjrd623HdQAAAGQ"]
[Thu Sep 17 15:44:07.349556 2026] [security2:error] [pid 60716:tid 60958] [client 34.94.30.138:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/old_phpinfo.php"] [unique_id "aqxfJ8Psx0SVFjrd623HegAAAEA"]
[Thu Sep 17 15:44:07.543581 2026] [security2:error] [pid 60716:tid 60948] [client 34.94.30.138:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/server-info.php"] [unique_id "aqxfJ8Psx0SVFjrd623HgQAAADY"]
[Thu Sep 17 15:44:07.575580 2026] [security2:error] [pid 60716:tid 60968] [client 34.166.220.229:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfJ8Psx0SVFjrd623HggAAAEo"]
[Thu Sep 17 15:44:07.662551 2026] [security2:error] [pid 60716:tid 60954] [client 34.94.30.138:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/server-status.php"] [unique_id "aqxfJ8Psx0SVFjrd623HiQAAADw"]
[Thu Sep 17 15:44:07.834123 2026] [core:error] [pid 60716:tid 60945] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:07.834147 2026] [core:error] [pid 60716:tid 60945] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:08.066241 2026] [security2:error] [pid 60716:tid 60924] [client 169.58.197.253:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxfKMPsx0SVFjrd623HnwAAAB8"], referer: binance.com
[Thu Sep 17 15:44:08.130483 2026] [core:error] [pid 60716:tid 60943] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:08.130502 2026] [core:error] [pid 60716:tid 60943] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:08.256621 2026] [security2:error] [pid 60716:tid 60977] [client 34.166.220.229:36496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfKMPsx0SVFjrd623HqQAAAFM"]
[Thu Sep 17 15:44:08.264287 2026] [security2:error] [pid 60716:tid 60914] [client 34.94.30.138:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfKMPsx0SVFjrd623HqgAAABY"]
[Thu Sep 17 15:44:08.361957 2026] [security2:error] [pid 60716:tid 60904] [client 34.94.30.138:60214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/mail/phpinfo.php"] [unique_id "aqxfKMPsx0SVFjrd623HrAAAAAw"]
[Thu Sep 17 15:44:08.497778 2026] [security2:error] [pid 60716:tid 60932] [client 104.248.10.213:58608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfKMPsx0SVFjrd623HrgAAJiU"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:44:08.545022 2026] [security2:error] [pid 60716:tid 60934] [client 34.94.30.138:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfKMPsx0SVFjrd623HsQAAACg"]
[Thu Sep 17 15:44:08.723999 2026] [security2:error] [pid 60716:tid 60919] [client 34.94.30.138:60232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfKMPsx0SVFjrd623HuAAAABs"]
[Thu Sep 17 15:44:08.856935 2026] [security2:error] [pid 60716:tid 61006] [client 34.94.30.138:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfKMPsx0SVFjrd623HvAAAAHA"]
[Thu Sep 17 15:44:08.942785 2026] [security2:error] [pid 60716:tid 60935] [client 34.166.220.229:36498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfKMPsx0SVFjrd623HvgAAACk"]
[Thu Sep 17 15:44:08.987859 2026] [security2:error] [pid 60716:tid 60971] [client 34.94.30.138:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfKMPsx0SVFjrd623HwAAAAE0"]
[Thu Sep 17 15:44:09.152640 2026] [security2:error] [pid 60716:tid 61021] [client 34.94.30.138:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/phpinfo.php.bak"] [unique_id "aqxfKcPsx0SVFjrd623HwwAAAH8"]
[Thu Sep 17 15:44:09.278400 2026] [security2:error] [pid 60716:tid 60892] [client 34.94.30.138:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/phpinfo.php.old"] [unique_id "aqxfKcPsx0SVFjrd623HxwAAAAA"]
[Thu Sep 17 15:44:09.464372 2026] [security2:error] [pid 60716:tid 60952] [client 104.248.10.213:58620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfKcPsx0SVFjrd623HygAAOio"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&from=20260818144813&hideanons=1&hideminor=1&hidemyself=1&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:44:09.519294 2026] [security2:error] [pid 60716:tid 60990] [client 34.94.30.138:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/phpinfo.php~"] [unique_id "aqxfKcPsx0SVFjrd623H0AAAAGA"]
[Thu Sep 17 15:44:09.620892 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.220.229:36504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfKcPsx0SVFjrd623H0gAAAHo"]
[Thu Sep 17 15:44:09.665730 2026] [security2:error] [pid 60716:tid 60993] [client 34.94.30.138:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/info.php.bak"] [unique_id "aqxfKcPsx0SVFjrd623H2AAAAGM"]
[Thu Sep 17 15:44:09.733083 2026] [core:error] [pid 60716:tid 60962] [client 103.105.167.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:09.733104 2026] [core:error] [pid 60716:tid 60962] [client 103.105.167.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:09.779359 2026] [security2:error] [pid 60716:tid 60924] [client 34.94.30.138:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/phpinfo.php.save"] [unique_id "aqxfKcPsx0SVFjrd623H4gAAAB8"]
[Thu Sep 17 15:44:09.879798 2026] [security2:error] [pid 60716:tid 60933] [client 69.57.234.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxfKcPsx0SVFjrd623H4QAAACc"], referer: https://instagram.com/
[Thu Sep 17 15:44:09.908949 2026] [security2:error] [pid 60716:tid 60961] [client 34.94.30.138:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/staging/phpinfo.php"] [unique_id "aqxfKcPsx0SVFjrd623H7QAAAEM"]
[Thu Sep 17 15:44:09.963348 2026] [core:error] [pid 60716:tid 60914] [client 103.105.167.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:09.963376 2026] [core:error] [pid 60716:tid 60914] [client 103.105.167.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:10.040776 2026] [security2:error] [pid 60716:tid 60916] [client 34.94.30.138:60324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/beta/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623H9gAAABg"]
[Thu Sep 17 15:44:10.131108 2026] [security2:error] [pid 60716:tid 60984] [client 34.94.30.138:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/uat/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623H-gAAAFo"]
[Thu Sep 17 15:44:10.167431 2026] [core:error] [pid 60716:tid 60972] [client 103.105.167.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:10.167456 2026] [core:error] [pid 60716:tid 60972] [client 103.105.167.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:10.284018 2026] [security2:error] [pid 60716:tid 60896] [client 34.94.30.138:60332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/qa/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623IBwAAAAQ"]
[Thu Sep 17 15:44:10.297739 2026] [security2:error] [pid 60716:tid 60964] [client 34.135.45.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxfKsPsx0SVFjrd623H-wAAAEY"]
[Thu Sep 17 15:44:10.305416 2026] [security2:error] [pid 60716:tid 61020] [client 34.166.220.229:36508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxfKsPsx0SVFjrd623ICAAAAH4"]
[Thu Sep 17 15:44:10.369236 2026] [security2:error] [pid 60716:tid 60960] [client 34.94.30.138:60342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/preview/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623IDQAAAEI"]
[Thu Sep 17 15:44:10.437097 2026] [security2:error] [pid 60716:tid 61021] [client 24.27.38.252:42215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfKsPsx0SVFjrd623ICwAAfyA"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:44:10.493965 2026] [security2:error] [pid 60716:tid 60955] [client 34.94.30.138:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/www/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623IEAAAAD0"]
[Thu Sep 17 15:44:10.642468 2026] [security2:error] [pid 60716:tid 60976] [client 34.94.30.138:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623IGAAAAFI"]
[Thu Sep 17 15:44:10.748950 2026] [security2:error] [pid 60716:tid 61005] [client 34.94.30.138:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623IHAAAAG8"]
[Thu Sep 17 15:44:10.853823 2026] [security2:error] [pid 60716:tid 60962] [client 34.94.30.138:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/site/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623IHgAAAEQ"]
[Thu Sep 17 15:44:10.863579 2026] [security2:error] [pid 60716:tid 60906] [client 169.58.197.251:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxfKsPsx0SVFjrd623IHwAAAA4"], referer: binance.com
[Thu Sep 17 15:44:10.927865 2026] [security2:error] [pid 60716:tid 61000] [client 34.94.30.138:60384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/docs/phpinfo.php"] [unique_id "aqxfKsPsx0SVFjrd623IIAAAAGo"]
[Thu Sep 17 15:44:10.985002 2026] [security2:error] [pid 60716:tid 60913] [client 34.166.220.229:36518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/phpinfo.php.old"] [unique_id "aqxfKsPsx0SVFjrd623IIgAAABU"]
[Thu Sep 17 15:44:11.067540 2026] [security2:error] [pid 60716:tid 60933] [client 34.94.30.138:60390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfK8Psx0SVFjrd623ILwAAACc"]
[Thu Sep 17 15:44:11.143927 2026] [security2:error] [pid 60716:tid 60915] [client 34.94.30.138:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfK8Psx0SVFjrd623IMQAAABc"]
[Thu Sep 17 15:44:11.256573 2026] [security2:error] [pid 60716:tid 61011] [client 34.94.30.138:60404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/core/phpinfo.php"] [unique_id "aqxfK8Psx0SVFjrd623IPAAAAHU"]
[Thu Sep 17 15:44:11.324413 2026] [security2:error] [pid 60716:tid 60979] [client 24.27.38.252:48055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfK8Psx0SVFjrd623IOgAAVSs"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&from=20260818144813&hideanons=1&hideminor=1&hidemyself=1&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:44:11.375717 2026] [security2:error] [pid 60716:tid 60925] [client 34.94.30.138:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.30.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hendersonlife.info"] [uri "/includes/phpinfo.php"] [unique_id "aqxfK8Psx0SVFjrd623IPwAAACA"]
[Thu Sep 17 15:44:11.665837 2026] [security2:error] [pid 60716:tid 61015] [client 34.166.220.229:36526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/phpinfo.php~"] [unique_id "aqxfK8Psx0SVFjrd623ISgAAAHk"]
[Thu Sep 17 15:44:11.776601 2026] [core:error] [pid 60716:tid 60981] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:11.776619 2026] [core:error] [pid 60716:tid 60981] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:12.105614 2026] [core:error] [pid 60716:tid 60985] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:12.105634 2026] [core:error] [pid 60716:tid 60985] [client 34.94.30.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:12.355456 2026] [security2:error] [pid 60716:tid 60913] [client 34.166.220.229:36542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/info.php.bak"] [unique_id "aqxfLMPsx0SVFjrd623IbgAAABU"]
[Thu Sep 17 15:44:12.605653 2026] [security2:error] [pid 60716:tid 60938] [client 103.61.184.148:56141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfLMPsx0SVFjrd623IdAAAACw"]
[Thu Sep 17 15:44:12.605751 2026] [security2:error] [pid 60716:tid 60938] [client 103.61.184.148:56141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfLMPsx0SVFjrd623IdAAAACw"]
[Thu Sep 17 15:44:12.631633 2026] [security2:error] [pid 60716:tid 60907] [client 148.227.75.216:29839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfLMPsx0SVFjrd623IdQAAAA8"]
[Thu Sep 17 15:44:12.631719 2026] [security2:error] [pid 60716:tid 60907] [client 148.227.75.216:29839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfLMPsx0SVFjrd623IdQAAAA8"]
[Thu Sep 17 15:44:13.058020 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.220.229:36554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/phpinfo.php.save"] [unique_id "aqxfLcPsx0SVFjrd623IgQAAAHY"]
[Thu Sep 17 15:44:13.659249 2026] [security2:error] [pid 60716:tid 60949] [client 157.55.39.201:33102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dfwservicesllc.com"] [uri "/index.php"] [unique_id "aqxfLcPsx0SVFjrd623IlAAANzM"]
[Thu Sep 17 15:44:13.740003 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.220.229:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxfLcPsx0SVFjrd623ImwAAAFc"]
[Thu Sep 17 15:44:13.963338 2026] [security2:error] [pid 60716:tid 60976] [client 14.96.156.146:55343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfLcPsx0SVFjrd623IogAAAFI"]
[Thu Sep 17 15:44:13.963520 2026] [security2:error] [pid 60716:tid 60976] [client 14.96.156.146:55343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfLcPsx0SVFjrd623IogAAAFI"]
[Thu Sep 17 15:44:14.416898 2026] [security2:error] [pid 60716:tid 60924] [client 34.166.220.229:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxfLsPsx0SVFjrd623IswAAAB8"]
[Thu Sep 17 15:44:15.095729 2026] [security2:error] [pid 60716:tid 61001] [client 34.166.220.229:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxfL8Psx0SVFjrd623IxgAAAGs"]
[Thu Sep 17 15:44:15.567609 2026] [security2:error] [pid 60716:tid 60931] [client 169.58.197.253:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxfL8Psx0SVFjrd623I1gAAACU"], referer: binance.com
[Thu Sep 17 15:44:15.679858 2026] [security2:error] [pid 60716:tid 60905] [client 177.44.133.72:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfL8Psx0SVFjrd623I2gAAAA0"]
[Thu Sep 17 15:44:15.679975 2026] [security2:error] [pid 60716:tid 60905] [client 177.44.133.72:50005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfL8Psx0SVFjrd623I2gAAAA0"]
[Thu Sep 17 15:44:15.773708 2026] [security2:error] [pid 60716:tid 60954] [client 34.166.220.229:52846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxfL8Psx0SVFjrd623I5gAAADw"]
[Thu Sep 17 15:44:16.333371 2026] [security2:error] [pid 60716:tid 60999] [client 143.105.152.240:50871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfMMPsx0SVFjrd623I9gAAAGk"]
[Thu Sep 17 15:44:16.334383 2026] [security2:error] [pid 60716:tid 60999] [client 143.105.152.240:50871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfMMPsx0SVFjrd623I9gAAAGk"]
[Thu Sep 17 15:44:16.457916 2026] [security2:error] [pid 60716:tid 60928] [client 34.166.220.229:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxfMMPsx0SVFjrd623I_AAAACM"]
[Thu Sep 17 15:44:16.734559 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.55.182:52162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/.env"] [unique_id "aqxfMMPsx0SVFjrd623JBAAAAHU"]
[Thu Sep 17 15:44:17.133099 2026] [security2:error] [pid 60716:tid 61010] [client 34.166.220.229:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/www/phpinfo.php"] [unique_id "aqxfMcPsx0SVFjrd623JEwAAAHQ"]
[Thu Sep 17 15:44:17.221105 2026] [security2:error] [pid 60716:tid 60948] [client 57.141.14.16:62386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxfMcPsx0SVFjrd623JEAAANi4"]
[Thu Sep 17 15:44:17.385712 2026] [security2:error] [pid 60716:tid 60926] [client 136.158.61.34:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfMcPsx0SVFjrd623JIgAAACE"]
[Thu Sep 17 15:44:17.385857 2026] [security2:error] [pid 60716:tid 60926] [client 136.158.61.34:51683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfMcPsx0SVFjrd623JIgAAACE"]
[Thu Sep 17 15:44:17.520383 2026] [security2:error] [pid 60716:tid 60981] [client 131.108.141.164:54566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfMcPsx0SVFjrd623JIwAAVzk"]
[Thu Sep 17 15:44:17.817253 2026] [security2:error] [pid 60716:tid 61008] [client 34.166.220.229:52870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfMcPsx0SVFjrd623JMwAAAHI"]
[Thu Sep 17 15:44:17.838991 2026] [security2:error] [pid 60716:tid 60970] [client 79.116.89.151:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfMcPsx0SVFjrd623JNAAAAEw"]
[Thu Sep 17 15:44:17.839112 2026] [security2:error] [pid 60716:tid 60970] [client 79.116.89.151:52627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfMcPsx0SVFjrd623JNAAAAEw"]
[Thu Sep 17 15:44:17.858789 2026] [security2:error] [pid 60716:tid 60914] [client 169.58.197.251:51096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxfMcPsx0SVFjrd623JNQAAABY"], referer: binance.com
[Thu Sep 17 15:44:17.899745 2026] [security2:error] [pid 60716:tid 60917] [client 93.152.209.11:19392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jolielight.com"] [uri "/.env"] [unique_id "aqxfMcPsx0SVFjrd623JNgAAABk"]
[Thu Sep 17 15:44:18.069520 2026] [security2:error] [pid 60716:tid 60811] [remote 93.152.209.11:63934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jolielight.com"] [uri "/.env"] [unique_id "aqxfMsPsx0SVFjrd623JPQAAHjE"]
[Thu Sep 17 15:44:18.511454 2026] [security2:error] [pid 60716:tid 60919] [client 34.166.220.229:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfMsPsx0SVFjrd623JVwAAABs"]
[Thu Sep 17 15:44:19.216375 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.220.229:52884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/site/phpinfo.php"] [unique_id "aqxfM8Psx0SVFjrd623JcAAAAF0"]
[Thu Sep 17 15:44:19.895209 2026] [security2:error] [pid 60716:tid 60904] [client 34.166.220.229:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxfM8Psx0SVFjrd623JjQAAAAw"]
[Thu Sep 17 15:44:20.127773 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.55.182:52202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxfNMPsx0SVFjrd623JkAAAADg"]
[Thu Sep 17 15:44:20.293009 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.55.182:52202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxfNMPsx0SVFjrd623JlwAAABs"]
[Thu Sep 17 15:44:20.514939 2026] [security2:error] [pid 60716:tid 60942] [client 170.64.152.52:59434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "kwolitee.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxfNMPsx0SVFjrd623JoAAAADA"]
[Thu Sep 17 15:44:20.593314 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.220.229:52906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfNMPsx0SVFjrd623JpAAAAHY"]
[Thu Sep 17 15:44:20.846682 2026] [security2:error] [pid 60716:tid 60920] [client 170.64.152.52:59437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "kwolitee.com"] [uri "/"] [unique_id "aqxfNMPsx0SVFjrd623JsAAAABw"]
[Thu Sep 17 15:44:21.030589 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.55.182:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxfNcPsx0SVFjrd623JuAAAAGQ"]
[Thu Sep 17 15:44:21.157163 2026] [security2:error] [pid 60716:tid 60974] [client 170.64.152.52:59441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "kwolitee.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxfNcPsx0SVFjrd623JvgAAAFA"]
[Thu Sep 17 15:44:21.279298 2026] [security2:error] [pid 60716:tid 60985] [client 34.166.220.229:52922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfNcPsx0SVFjrd623J1wAAAFs"]
[Thu Sep 17 15:44:21.707284 2026] [cgid:error] [pid 60716:tid 60993] [client 221.149.119.65:3642] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/WP
[Thu Sep 17 15:44:21.957060 2026] [security2:error] [pid 60716:tid 60894] [client 34.166.220.229:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/core/phpinfo.php"] [unique_id "aqxfNcPsx0SVFjrd623KBAAAAAI"]
[Thu Sep 17 15:44:22.079343 2026] [security2:error] [pid 60716:tid 60878] [remote 47.128.126.112:17528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/page/2/"] [unique_id "aqxfNsPsx0SVFjrd623KBgAAfXQ"]
[Thu Sep 17 15:44:22.419982 2026] [security2:error] [pid 60716:tid 60981] [client 43.159.136.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "askmrhenderson.com"] [uri "/wp/index.php"] [unique_id "aqxfNcPsx0SVFjrd623J0QAAAFc"]
[Thu Sep 17 15:44:22.635119 2026] [security2:error] [pid 60716:tid 61013] [client 34.166.220.229:52938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.220.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.breathingboxing.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxfNsPsx0SVFjrd623KHgAAAHc"]
[Thu Sep 17 15:44:22.665866 2026] [security2:error] [pid 60716:tid 60976] [client 104.234.19.144:60429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/000.php"] [unique_id "aqxfNsPsx0SVFjrd623KIQAAAFI"]
[Thu Sep 17 15:44:22.986869 2026] [security2:error] [pid 60716:tid 60932] [client 216.24.219.103:39365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/about.php"] [unique_id "aqxfNsPsx0SVFjrd623KNgAAACY"]
[Thu Sep 17 15:44:23.064406 2026] [security2:error] [pid 60716:tid 60941] [client 216.73.216.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxfNcPsx0SVFjrd623JtgAAAC8"]
[Thu Sep 17 15:44:23.143384 2026] [security2:error] [pid 60716:tid 60822] [remote 47.128.58.111:37734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.endless-chronicles.com"] [uri "/robots.txt"] [unique_id "aqxfN8Psx0SVFjrd623KOwAANDw"]
[Thu Sep 17 15:44:23.327163 2026] [core:error] [pid 60716:tid 61006] [client 34.166.220.229:52946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:23.327187 2026] [core:error] [pid 60716:tid 61006] [client 34.166.220.229:52946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:23.580561 2026] [security2:error] [pid 60716:tid 60911] [client 103.61.184.148:56723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfN8Psx0SVFjrd623KSgAAABM"]
[Thu Sep 17 15:44:23.580704 2026] [security2:error] [pid 60716:tid 60911] [client 103.61.184.148:56723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfN8Psx0SVFjrd623KSgAAABM"]
[Thu Sep 17 15:44:23.676219 2026] [security2:error] [pid 60716:tid 60902] [client 193.36.224.212:26735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aqxfN8Psx0SVFjrd623KUQAAAAo"]
[Thu Sep 17 15:44:23.736068 2026] [security2:error] [pid 60716:tid 60964] [client 114.119.133.213:57221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenniferniesslein.com"] [uri "/comments/feed"] [unique_id "aqxfN8Psx0SVFjrd623KUwAAAEY"], referer: https://jenniferniesslein.com/comments/feed
[Thu Sep 17 15:44:23.904895 2026] [security2:error] [pid 60716:tid 61010] [client 216.24.219.104:43765] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/css/about.php"] [unique_id "aqxfN8Psx0SVFjrd623KWwAAAHQ"]
[Thu Sep 17 15:44:23.954576 2026] [security2:error] [pid 60716:tid 60947] [client 74.7.228.38:34236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fireflyhotglass.glassblowingbug.com"] [uri "/index.php"] [unique_id "aqxfN8Psx0SVFjrd623KVwAANS8"]
[Thu Sep 17 15:44:24.026903 2026] [core:error] [pid 60716:tid 60896] [client 34.166.220.229:52948] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:24.026931 2026] [core:error] [pid 60716:tid 60896] [client 34.166.220.229:52948] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:24.144576 2026] [security2:error] [pid 60716:tid 60908] [client 216.24.219.97:64477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/wp-setting.php"] [unique_id "aqxfOMPsx0SVFjrd623KYwAAABA"]
[Thu Sep 17 15:44:24.397364 2026] [security2:error] [pid 60716:tid 60999] [client 193.36.224.212:47087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-includes/hp2.php"] [unique_id "aqxfOMPsx0SVFjrd623KcQAAAGk"]
[Thu Sep 17 15:44:24.544429 2026] [security2:error] [pid 60716:tid 60965] [client 14.96.156.146:55996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KdgAAAEc"]
[Thu Sep 17 15:44:24.544553 2026] [security2:error] [pid 60716:tid 60965] [client 14.96.156.146:55996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KdgAAAEc"]
[Thu Sep 17 15:44:24.577820 2026] [security2:error] [pid 60716:tid 60975] [client 87.236.176.245:39295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.danielstepniak.com"] [uri "/index.php"] [unique_id "aqxfOMPsx0SVFjrd623KcAAAURc"]
[Thu Sep 17 15:44:24.633338 2026] [security2:error] [pid 60716:tid 61008] [client 148.227.75.216:10648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KdwAAAHI"]
[Thu Sep 17 15:44:24.635380 2026] [security2:error] [pid 60716:tid 61008] [client 148.227.75.216:10648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KdwAAAHI"]
[Thu Sep 17 15:44:24.648751 2026] [security2:error] [pid 60716:tid 60916] [client 193.36.224.148:56135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/bless.php"] [unique_id "aqxfOMPsx0SVFjrd623KeQAAABg"]
[Thu Sep 17 15:44:24.700412 2026] [security2:error] [pid 60716:tid 60944] [client 43.162.109.249:37114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.162.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.votersrevenge.info"] [uri "/index.php"] [unique_id "aqxfOMPsx0SVFjrd623KfAAAADI"]
[Thu Sep 17 15:44:24.723491 2026] [core:error] [pid 60716:tid 61003] [client 34.166.220.229:52952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:24.723528 2026] [core:error] [pid 60716:tid 61003] [client 34.166.220.229:52952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:24.816821 2026] [security2:error] [pid 60716:tid 60766] [remote 45.157.54.43:62761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "palveluklubi.com"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KggAANwc"]
[Thu Sep 17 15:44:24.816986 2026] [security2:error] [pid 60716:tid 60949] [client 45.157.54.43:62761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "palveluklubi.com"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KggAANwc"]
[Thu Sep 17 15:44:24.880175 2026] [security2:error] [pid 60716:tid 60996] [client 193.36.224.167:27613] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/goods.php"] [unique_id "aqxfOMPsx0SVFjrd623KhQAAAGY"]
[Thu Sep 17 15:44:24.989898 2026] [security2:error] [pid 60716:tid 60802] [remote 45.157.54.43:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "palveluklubi.com"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KiAAAIyg"]
[Thu Sep 17 15:44:24.990099 2026] [security2:error] [pid 60716:tid 60928] [client 45.157.54.43:62974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "palveluklubi.com"] [uri "/xmlrpc.php"] [unique_id "aqxfOMPsx0SVFjrd623KiAAAIyg"]
[Thu Sep 17 15:44:25.124947 2026] [security2:error] [pid 60716:tid 61002] [client 193.36.224.221:25505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/blurbs.php"] [unique_id "aqxfOcPsx0SVFjrd623KjAAAAGw"]
[Thu Sep 17 15:44:25.156747 2026] [security2:error] [pid 60716:tid 60960] [client 169.58.197.251:51915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxfOcPsx0SVFjrd623KjwAAAEI"], referer: binance.com
[Thu Sep 17 15:44:25.233739 2026] [security2:error] [pid 60716:tid 60910] [client 4.240.114.86:51091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jwdnyc.com"] [uri "/index.php"] [unique_id "aqxfN8Psx0SVFjrd623KWgAAABI"], referer: binance.com
[Thu Sep 17 15:44:25.368000 2026] [security2:error] [pid 60716:tid 60947] [client 104.234.19.144:28431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/css/goods.php"] [unique_id "aqxfOcPsx0SVFjrd623KmgAAADU"]
[Thu Sep 17 15:44:25.416763 2026] [core:error] [pid 60716:tid 60902] [client 34.166.220.229:39138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:25.416782 2026] [core:error] [pid 60716:tid 60902] [client 34.166.220.229:39138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:25.618204 2026] [security2:error] [pid 60716:tid 61013] [client 193.36.224.116:36265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/abcd.php"] [unique_id "aqxfOcPsx0SVFjrd623KoAAAAHc"]
[Thu Sep 17 15:44:25.784518 2026] [security2:error] [pid 60716:tid 60897] [client 169.58.197.253:59428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxfOcPsx0SVFjrd623KqwAAAAU"], referer: binance.com
[Thu Sep 17 15:44:25.906761 2026] [security2:error] [pid 60716:tid 60791] [remote 111.225.149.226:45196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.npae.net"] [uri "/wp-content/uploads/2025/01/2025_nPAE_Calendar.pdf"] [unique_id "aqxfOcPsx0SVFjrd623KrwAAex0"]
[Thu Sep 17 15:44:25.914212 2026] [security2:error] [pid 60716:tid 60957] [client 216.24.219.37:45247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "aqxfOcPsx0SVFjrd623KrgAAAD8"]
[Thu Sep 17 15:44:26.106527 2026] [core:error] [pid 60716:tid 60977] [client 34.166.220.229:39150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:26.106545 2026] [core:error] [pid 60716:tid 60977] [client 34.166.220.229:39150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:26.160693 2026] [security2:error] [pid 60716:tid 60945] [client 193.36.224.168:60955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/dex.php"] [unique_id "aqxfOsPsx0SVFjrd623KvAAAADM"]
[Thu Sep 17 15:44:26.384162 2026] [security2:error] [pid 60716:tid 60894] [client 193.36.224.116:57679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxfOsPsx0SVFjrd623KxQAAAAI"]
[Thu Sep 17 15:44:26.407038 2026] [security2:error] [pid 60716:tid 60963] [client 177.44.133.72:50679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfOsPsx0SVFjrd623KxgAAAEU"]
[Thu Sep 17 15:44:26.407149 2026] [security2:error] [pid 60716:tid 60963] [client 177.44.133.72:50679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfOsPsx0SVFjrd623KxgAAAEU"]
[Thu Sep 17 15:44:26.622711 2026] [security2:error] [pid 60716:tid 61002] [client 104.234.19.150:61563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/css/index.php"] [unique_id "aqxfOsPsx0SVFjrd623KzwAAAGw"]
[Thu Sep 17 15:44:26.796076 2026] [core:error] [pid 60716:tid 60958] [client 34.166.220.229:39154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:26.796103 2026] [core:error] [pid 60716:tid 60958] [client 34.166.220.229:39154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:26.821571 2026] [security2:error] [pid 60716:tid 60935] [client 185.92.26.249:41155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.26.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "heromakers.org"] [uri "/wp-login.php"] [unique_id "aqxfOsPsx0SVFjrd623K1gAAACk"]
[Thu Sep 17 15:44:26.851598 2026] [security2:error] [pid 60716:tid 60925] [client 143.105.152.240:31546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfOsPsx0SVFjrd623K2wAAACA"]
[Thu Sep 17 15:44:26.851761 2026] [security2:error] [pid 60716:tid 60925] [client 143.105.152.240:31546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfOsPsx0SVFjrd623K2wAAACA"]
[Thu Sep 17 15:44:26.856809 2026] [security2:error] [pid 60716:tid 60969] [client 193.36.224.167:58493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/index.php"] [unique_id "aqxfOsPsx0SVFjrd623K3AAAAEs"]
[Thu Sep 17 15:44:27.144412 2026] [security2:error] [pid 60716:tid 60905] [client 193.36.224.150:57789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aqxfO8Psx0SVFjrd623K4AAAAA0"]
[Thu Sep 17 15:44:27.169177 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.55.182:38258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxfO8Psx0SVFjrd623K4wAAACU"]
[Thu Sep 17 15:44:27.345241 2026] [security2:error] [pid 60716:tid 60929] [client 34.154.55.182:38258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/.env~"] [unique_id "aqxfO8Psx0SVFjrd623K7gAAACQ"]
[Thu Sep 17 15:44:27.451710 2026] [security2:error] [pid 60716:tid 60924] [client 162.241.226.11:15972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxfOsPsx0SVFjrd623KswAAAHI"]
[Thu Sep 17 15:44:27.484260 2026] [security2:error] [pid 60716:tid 60993] [client 216.24.219.36:33219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/index.php"] [unique_id "aqxfO8Psx0SVFjrd623K-AAAAGM"]
[Thu Sep 17 15:44:27.504262 2026] [core:error] [pid 60716:tid 60976] [client 34.166.220.229:39166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:27.504280 2026] [core:error] [pid 60716:tid 60976] [client 34.166.220.229:39166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:27.549745 2026] [security2:error] [pid 60716:tid 61003] [client 185.192.20.168:64242] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.192.20.168" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.freeofgravity.com"] [uri "/wp-comments-post.php"] [unique_id "aqxfO8Psx0SVFjrd623LAgAAAG0"], referer: http://www.freeofgravity.com/launch-day-wonder-over-fear/
[Thu Sep 17 15:44:27.549835 2026] [security2:error] [pid 60716:tid 61003] [client 185.192.20.168:64242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.freeofgravity.com"] [uri "/wp-comments-post.php"] [unique_id "aqxfO8Psx0SVFjrd623LAgAAAG0"], referer: http://www.freeofgravity.com/launch-day-wonder-over-fear/
[Thu Sep 17 15:44:27.711281 2026] [security2:error] [pid 60716:tid 60943] [client 216.24.219.35:57127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "aqxfO8Psx0SVFjrd623LBwAAADE"]
[Thu Sep 17 15:44:27.856183 2026] [security2:error] [pid 60716:tid 60918] [client 24.14.56.86:46593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfO8Psx0SVFjrd623LCQAAGmQ"]
[Thu Sep 17 15:44:27.928932 2026] [security2:error] [pid 60716:tid 60912] [client 216.24.219.97:51435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/file.php"] [unique_id "aqxfO8Psx0SVFjrd623LEgAAABQ"]
[Thu Sep 17 15:44:28.049087 2026] [security2:error] [pid 60716:tid 60979] [client 134.185.85.61:49389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "churchinirving.org"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxfPMPsx0SVFjrd623LEwAAAFU"]
[Thu Sep 17 15:44:28.173843 2026] [security2:error] [pid 60716:tid 60911] [client 216.24.219.22:31953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxfPMPsx0SVFjrd623LGQAAABM"]
[Thu Sep 17 15:44:28.193802 2026] [core:error] [pid 60716:tid 60948] [client 34.166.220.229:39172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:28.193819 2026] [core:error] [pid 60716:tid 60948] [client 34.166.220.229:39172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:28.432213 2026] [security2:error] [pid 60716:tid 61009] [client 134.185.85.61:51956] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "churchinirving.org"] [uri "/media/system/js/core.js"] [unique_id "aqxfPMPsx0SVFjrd623LIwAAAHM"]
[Thu Sep 17 15:44:28.509889 2026] [security2:error] [pid 60716:tid 60782] [remote 47.128.123.40:53204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "enduringwanderlust.com"] [uri "/robots.txt"] [unique_id "aqxfPMPsx0SVFjrd623LJAAAKhU"]
[Thu Sep 17 15:44:28.510405 2026] [security2:error] [pid 60716:tid 60955] [client 79.116.89.151:53266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfPMPsx0SVFjrd623LJQAAAD0"]
[Thu Sep 17 15:44:28.510519 2026] [security2:error] [pid 60716:tid 60955] [client 79.116.89.151:53266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfPMPsx0SVFjrd623LJQAAAD0"]
[Thu Sep 17 15:44:28.782943 2026] [security2:error] [pid 60716:tid 60938] [client 162.241.226.11:15980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bppa-nb.com"] [uri "/index.php"] [unique_id "aqxfO8Psx0SVFjrd623K-gAAACw"]
[Thu Sep 17 15:44:28.874915 2026] [core:error] [pid 60716:tid 60988] [client 34.166.220.229:39174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:28.874933 2026] [core:error] [pid 60716:tid 60988] [client 34.166.220.229:39174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:29.244572 2026] [security2:error] [pid 60716:tid 60994] [client 129.159.56.14:59658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.kslandscaping.net"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "aqxfPcPsx0SVFjrd623LPAAAAGQ"]
[Thu Sep 17 15:44:29.428377 2026] [security2:error] [pid 60716:tid 60909] [client 216.24.219.105:37745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-mail.php"] [unique_id "aqxfPcPsx0SVFjrd623LQwAAABE"]
[Thu Sep 17 15:44:29.530747 2026] [security2:error] [pid 60716:tid 60961] [client 24.14.56.86:55117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfPcPsx0SVFjrd623LRQAAQzE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260603224645&hidebots=0&hideliu=1&limit=250&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:44:29.580267 2026] [core:error] [pid 60716:tid 61006] [client 34.166.220.229:39180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:29.580290 2026] [core:error] [pid 60716:tid 61006] [client 34.166.220.229:39180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:29.658277 2026] [security2:error] [pid 60716:tid 60989] [client 104.234.19.151:22409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/ioxi-o.php"] [unique_id "aqxfPcPsx0SVFjrd623LTAAAAF8"]
[Thu Sep 17 15:44:29.878610 2026] [security2:error] [pid 60716:tid 60986] [client 193.36.224.219:65243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/ioxi-o.php"] [unique_id "aqxfPcPsx0SVFjrd623LVwAAAFw"]
[Thu Sep 17 15:44:30.116982 2026] [security2:error] [pid 60716:tid 60981] [client 104.234.19.143:56273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/style.php"] [unique_id "aqxfPsPsx0SVFjrd623LWgAAAFc"]
[Thu Sep 17 15:44:30.281752 2026] [core:error] [pid 60716:tid 60960] [client 34.166.220.229:39188] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:30.281773 2026] [core:error] [pid 60716:tid 60960] [client 34.166.220.229:39188] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:30.352034 2026] [security2:error] [pid 60716:tid 60964] [client 104.234.19.147:48041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/style.php"] [unique_id "aqxfPsPsx0SVFjrd623LZwAAAEY"]
[Thu Sep 17 15:44:30.623614 2026] [security2:error] [pid 60716:tid 61000] [client 193.36.224.169:36927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/themes/style.php"] [unique_id "aqxfPsPsx0SVFjrd623LawAAAGo"]
[Thu Sep 17 15:44:30.844210 2026] [security2:error] [pid 60716:tid 60910] [client 216.24.219.37:20583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-editor.php"] [unique_id "aqxfPsPsx0SVFjrd623LdwAAABI"]
[Thu Sep 17 15:44:30.913127 2026] [security2:error] [pid 60716:tid 60917] [client 136.158.61.34:52723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfPsPsx0SVFjrd623LeQAAABk"]
[Thu Sep 17 15:44:30.913342 2026] [security2:error] [pid 60716:tid 60917] [client 136.158.61.34:52723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfPsPsx0SVFjrd623LeQAAABk"]
[Thu Sep 17 15:44:30.972310 2026] [core:error] [pid 60716:tid 60987] [client 34.166.220.229:39204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:30.972332 2026] [core:error] [pid 60716:tid 60987] [client 34.166.220.229:39204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:31.073074 2026] [security2:error] [pid 60716:tid 60922] [client 216.24.219.35:20097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/lufix.php"] [unique_id "aqxfP8Psx0SVFjrd623LfgAAAB0"]
[Thu Sep 17 15:44:31.318941 2026] [security2:error] [pid 60716:tid 60943] [client 34.154.55.182:38322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxfP8Psx0SVFjrd623LiAAAADE"]
[Thu Sep 17 15:44:31.323425 2026] [security2:error] [pid 60716:tid 60916] [client 216.24.219.36:45819] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/txets.php"] [unique_id "aqxfP8Psx0SVFjrd623LiQAAABg"]
[Thu Sep 17 15:44:31.478050 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.55.182:38322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxfP8Psx0SVFjrd623LjQAAADw"]
[Thu Sep 17 15:44:31.570450 2026] [security2:error] [pid 60716:tid 60903] [client 193.36.224.206:21455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-content/themes/txets.php"] [unique_id "aqxfP8Psx0SVFjrd623LjwAAAAs"]
[Thu Sep 17 15:44:31.638465 2026] [security2:error] [pid 60716:tid 60912] [client 34.154.55.182:38322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxfP8Psx0SVFjrd623LkQAAABQ"]
[Thu Sep 17 15:44:31.659366 2026] [core:error] [pid 60716:tid 61020] [client 34.166.220.229:39220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:31.659383 2026] [core:error] [pid 60716:tid 61020] [client 34.166.220.229:39220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:31.788593 2026] [security2:error] [pid 60716:tid 60900] [client 216.24.219.35:41339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-admin/txets.php"] [unique_id "aqxfP8Psx0SVFjrd623LnQAAAAg"]
[Thu Sep 17 15:44:31.799696 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.55.182:38322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxfP8Psx0SVFjrd623LnwAAAEQ"]
[Thu Sep 17 15:44:31.838985 2026] [security2:error] [pid 60716:tid 60981] [client 34.95.211.140:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxfP8Psx0SVFjrd623LoQAAAFc"]
[Thu Sep 17 15:44:31.888124 2026] [security2:error] [pid 60716:tid 60925] [client 121.37.103.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.languageandsociety.co.il"] [uri "/index.php"] [unique_id "aqxfP8Psx0SVFjrd623LmwAAACA"]
[Thu Sep 17 15:44:31.966835 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.55.182:38322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxfP8Psx0SVFjrd623LowAAADU"]
[Thu Sep 17 15:44:32.007039 2026] [security2:error] [pid 60716:tid 60985] [client 193.36.224.169:29279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/wp-includes/txets.php"] [unique_id "aqxfQMPsx0SVFjrd623LpAAAAFs"]
[Thu Sep 17 15:44:32.147452 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.55.182:38322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxfQMPsx0SVFjrd623LqAAAAA8"]
[Thu Sep 17 15:44:32.296828 2026] [security2:error] [pid 60716:tid 60936] [client 3.19.142.206:58040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfQMPsx0SVFjrd623LrQAAACo"]
[Thu Sep 17 15:44:32.348062 2026] [core:error] [pid 60716:tid 60998] [client 34.166.220.229:39230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:32.348078 2026] [core:error] [pid 60716:tid 60998] [client 34.166.220.229:39230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:32.387288 2026] [security2:error] [pid 60716:tid 60975] [client 104.234.19.146:53303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/goods.php"] [unique_id "aqxfQMPsx0SVFjrd623LtAAAAFE"]
[Thu Sep 17 15:44:32.453331 2026] [security2:error] [pid 60716:tid 61000] [client 34.95.211.140:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/info.php"] [unique_id "aqxfQMPsx0SVFjrd623LtgAAAGo"]
[Thu Sep 17 15:44:32.665561 2026] [security2:error] [pid 60716:tid 60987] [client 216.24.219.35:47455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "memorytrackspodcast.com"] [uri "/php8.php"] [unique_id "aqxfQMPsx0SVFjrd623LvAAAAF0"]
[Thu Sep 17 15:44:32.862214 2026] [security2:error] [pid 60716:tid 60932] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxfQMPsx0SVFjrd623LzgAAACY"]
[Thu Sep 17 15:44:32.942977 2026] [security2:error] [pid 60716:tid 60933] [client 34.95.211.140:35548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/php.php"] [unique_id "aqxfQMPsx0SVFjrd623L0AAAACc"]
[Thu Sep 17 15:44:33.030192 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxfQcPsx0SVFjrd623L0gAAABg"]
[Thu Sep 17 15:44:33.105527 2026] [core:error] [pid 60716:tid 60894] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:33.105545 2026] [core:error] [pid 60716:tid 60894] [client 34.166.220.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:33.196048 2026] [security2:error] [pid 60716:tid 60929] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxfQcPsx0SVFjrd623L5AAAACQ"]
[Thu Sep 17 15:44:33.358683 2026] [security2:error] [pid 60716:tid 61020] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxfQcPsx0SVFjrd623L6wAAAH4"]
[Thu Sep 17 15:44:33.446098 2026] [security2:error] [pid 60716:tid 60939] [client 34.95.211.140:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/i.php"] [unique_id "aqxfQcPsx0SVFjrd623L7gAAAC0"]
[Thu Sep 17 15:44:33.534372 2026] [security2:error] [pid 60716:tid 60968] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxfQcPsx0SVFjrd623L8AAAAEo"]
[Thu Sep 17 15:44:33.699055 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxfQcPsx0SVFjrd623L9QAAAAg"]
[Thu Sep 17 15:44:33.863072 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxfQcPsx0SVFjrd623L-gAAAEs"]
[Thu Sep 17 15:44:33.929635 2026] [security2:error] [pid 60716:tid 60981] [client 34.95.211.140:35570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxfQcPsx0SVFjrd623L_AAAAFc"]
[Thu Sep 17 15:44:33.929681 2026] [security2:error] [pid 60716:tid 60925] [client 169.58.197.251:52715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxfQcPsx0SVFjrd623L-wAAACA"], referer: binance.com
[Thu Sep 17 15:44:34.026324 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxfQsPsx0SVFjrd623L_QAAACk"]
[Thu Sep 17 15:44:34.069236 2026] [security2:error] [pid 60716:tid 60896] [client 169.58.197.253:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxfQsPsx0SVFjrd623L_gAAAAQ"], referer: binance.com
[Thu Sep 17 15:44:34.166477 2026] [security2:error] [pid 60716:tid 60898] [client 93.152.209.11:36694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jpe.rvc.mybluehost.me"] [uri "/.env"] [unique_id "aqxfQsPsx0SVFjrd623MAwAAAAY"]
[Thu Sep 17 15:44:34.200048 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxfQsPsx0SVFjrd623MBAAAAEY"]
[Thu Sep 17 15:44:34.207123 2026] [security2:error] [pid 60716:tid 60902] [client 76.213.115.241:49756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfQsPsx0SVFjrd623MAAAAAAo"]
[Thu Sep 17 15:44:34.207145 2026] [security2:error] [pid 60716:tid 60902] [client 76.213.115.241:49756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfQsPsx0SVFjrd623MAAAAAAo"]
[Thu Sep 17 15:44:34.243982 2026] [security2:error] [pid 60716:tid 61014] [client 103.61.184.148:57298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfQsPsx0SVFjrd623MBwAAAHg"]
[Thu Sep 17 15:44:34.244098 2026] [security2:error] [pid 60716:tid 61014] [client 103.61.184.148:57298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfQsPsx0SVFjrd623MBwAAAHg"]
[Thu Sep 17 15:44:34.309906 2026] [security2:error] [pid 60716:tid 60844] [remote 93.152.209.11:36848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jpe.rvc.mybluehost.me"] [uri "/.env"] [unique_id "aqxfQsPsx0SVFjrd623MCwAAYFI"]
[Thu Sep 17 15:44:34.366426 2026] [security2:error] [pid 60716:tid 61008] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxfQsPsx0SVFjrd623MEAAAAHI"]
[Thu Sep 17 15:44:34.369413 2026] [security2:error] [pid 60716:tid 60915] [client 76.213.115.241:49756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfQsPsx0SVFjrd623MCAAAABc"]
[Thu Sep 17 15:44:34.369430 2026] [security2:error] [pid 60716:tid 60915] [client 76.213.115.241:49756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfQsPsx0SVFjrd623MCAAAABc"]
[Thu Sep 17 15:44:34.419403 2026] [security2:error] [pid 60716:tid 61016] [client 34.95.211.140:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxfQsPsx0SVFjrd623MEgAAAHo"]
[Thu Sep 17 15:44:34.533152 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxfQsPsx0SVFjrd623MFgAAACU"]
[Thu Sep 17 15:44:34.694470 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxfQsPsx0SVFjrd623MGwAAAGM"]
[Thu Sep 17 15:44:34.849569 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxfQsPsx0SVFjrd623MJQAAAGQ"]
[Thu Sep 17 15:44:34.921540 2026] [security2:error] [pid 60716:tid 60977] [client 34.95.211.140:35590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/test.php"] [unique_id "aqxfQsPsx0SVFjrd623MJgAAAFM"]
[Thu Sep 17 15:44:35.011023 2026] [security2:error] [pid 60716:tid 60932] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxfQ8Psx0SVFjrd623MJwAAACY"]
[Thu Sep 17 15:44:35.131778 2026] [security2:error] [pid 60716:tid 60897] [client 14.96.156.146:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfQ8Psx0SVFjrd623MKQAAAAU"]
[Thu Sep 17 15:44:35.131900 2026] [security2:error] [pid 60716:tid 60897] [client 14.96.156.146:56778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfQ8Psx0SVFjrd623MKQAAAAU"]
[Thu Sep 17 15:44:35.180935 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxfQ8Psx0SVFjrd623MLgAAADQ"]
[Thu Sep 17 15:44:35.355241 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxfQ8Psx0SVFjrd623MNAAAAHA"]
[Thu Sep 17 15:44:35.490800 2026] [security2:error] [pid 60716:tid 60972] [client 148.227.75.216:5217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfQ8Psx0SVFjrd623MNgAAAE4"]
[Thu Sep 17 15:44:35.494213 2026] [security2:error] [pid 60716:tid 60972] [client 148.227.75.216:5217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfQ8Psx0SVFjrd623MNgAAAE4"]
[Thu Sep 17 15:44:35.516028 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxfQ8Psx0SVFjrd623MOQAAAAk"]
[Thu Sep 17 15:44:35.585224 2026] [security2:error] [pid 60716:tid 60997] [client 34.95.211.140:35592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/p.php"] [unique_id "aqxfQ8Psx0SVFjrd623MOgAAAGc"]
[Thu Sep 17 15:44:35.728777 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxfQ8Psx0SVFjrd623MPwAAAGs"]
[Thu Sep 17 15:44:35.814468 2026] [core:error] [pid 60716:tid 60986] [client 195.96.139.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:35.814488 2026] [core:error] [pid 60716:tid 60986] [client 195.96.139.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:44:35.890001 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxfQ8Psx0SVFjrd623MRwAAAHQ"]
[Thu Sep 17 15:44:36.058050 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxfRMPsx0SVFjrd623MTgAAAEA"]
[Thu Sep 17 15:44:36.074886 2026] [security2:error] [pid 60716:tid 60899] [client 34.95.211.140:35594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxfRMPsx0SVFjrd623MTwAAAAc"]
[Thu Sep 17 15:44:36.311051 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxfRMPsx0SVFjrd623MVAAAADU"]
[Thu Sep 17 15:44:36.478739 2026] [security2:error] [pid 60716:tid 60955] [client 202.46.62.83:43336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfRMPsx0SVFjrd623MWQAAPQM"]
[Thu Sep 17 15:44:36.512625 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxfRMPsx0SVFjrd623MXQAAABY"]
[Thu Sep 17 15:44:36.531181 2026] [security2:error] [pid 60716:tid 60990] [client 202.46.62.45:30342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfRMPsx0SVFjrd623MWgAAYG0"]
[Thu Sep 17 15:44:36.541022 2026] [security2:error] [pid 60716:tid 61008] [client 202.46.62.24:13825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfRMPsx0SVFjrd623MWwAAcjc"]
[Thu Sep 17 15:44:36.580465 2026] [security2:error] [pid 60716:tid 60895] [client 34.95.211.140:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxfRMPsx0SVFjrd623MXgAAAAM"]
[Thu Sep 17 15:44:36.667101 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxfRMPsx0SVFjrd623MYgAAAFE"]
[Thu Sep 17 15:44:36.830243 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxfRMPsx0SVFjrd623MZAAAAEc"]
[Thu Sep 17 15:44:36.988254 2026] [security2:error] [pid 60716:tid 60938] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxfRMPsx0SVFjrd623MagAAACw"]
[Thu Sep 17 15:44:37.030593 2026] [security2:error] [pid 60716:tid 60926] [client 177.44.133.72:51347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfRcPsx0SVFjrd623MawAAACE"]
[Thu Sep 17 15:44:37.030799 2026] [security2:error] [pid 60716:tid 60926] [client 177.44.133.72:51347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfRcPsx0SVFjrd623MawAAACE"]
[Thu Sep 17 15:44:37.063032 2026] [security2:error] [pid 60716:tid 61017] [client 34.95.211.140:35608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxfRcPsx0SVFjrd623MbAAAAHs"]
[Thu Sep 17 15:44:37.163764 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxfRcPsx0SVFjrd623McAAAAG0"]
[Thu Sep 17 15:44:37.348985 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxfRcPsx0SVFjrd623MdQAAACc"]
[Thu Sep 17 15:44:37.434705 2026] [security2:error] [pid 60716:tid 60922] [client 143.105.152.240:4409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfRcPsx0SVFjrd623MegAAAB0"]
[Thu Sep 17 15:44:37.434836 2026] [security2:error] [pid 60716:tid 60922] [client 143.105.152.240:4409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfRcPsx0SVFjrd623MegAAAB0"]
[Thu Sep 17 15:44:37.521802 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxfRcPsx0SVFjrd623MewAAAHA"]
[Thu Sep 17 15:44:37.547522 2026] [security2:error] [pid 60716:tid 60961] [client 34.95.211.140:35618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxfRcPsx0SVFjrd623MfQAAAEM"]
[Thu Sep 17 15:44:37.693275 2026] [security2:error] [pid 60716:tid 60997] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxfRcPsx0SVFjrd623MgwAAAGc"]
[Thu Sep 17 15:44:37.735127 2026] [security2:error] [pid 60716:tid 60957] [client 177.95.98.172:42400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfRcPsx0SVFjrd623MfgAAP3k"]
[Thu Sep 17 15:44:37.808201 2026] [security2:error] [pid 60716:tid 61020] [client 159.203.57.242:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxfRcPsx0SVFjrd623MhAAAAH4"]
[Thu Sep 17 15:44:37.847058 2026] [security2:error] [pid 60716:tid 60935] [client 43.172.197.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rafaelceara.com"] [uri "/index.php"] [unique_id "aqxfRMPsx0SVFjrd623MTQAAACk"]
[Thu Sep 17 15:44:37.854560 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxfRcPsx0SVFjrd623MiQAAABw"]
[Thu Sep 17 15:44:37.984892 2026] [security2:error] [pid 60716:tid 60967] [client 159.203.57.242:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxfRcPsx0SVFjrd623MiwAAAEk"]
[Thu Sep 17 15:44:38.035222 2026] [security2:error] [pid 60716:tid 60908] [client 34.95.211.140:35632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxfRsPsx0SVFjrd623MkQAAABA"]
[Thu Sep 17 15:44:38.036618 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxfRsPsx0SVFjrd623MkgAAAAQ"]
[Thu Sep 17 15:44:38.166196 2026] [security2:error] [pid 60716:tid 60960] [client 159.203.57.242:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxfRsPsx0SVFjrd623MkwAAAEI"]
[Thu Sep 17 15:44:38.235439 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxfRsPsx0SVFjrd623MmQAAAD0"]
[Thu Sep 17 15:44:38.416932 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxfRsPsx0SVFjrd623MogAAAGo"]
[Thu Sep 17 15:44:38.510154 2026] [security2:error] [pid 60716:tid 61015] [client 159.203.57.242:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxfRsPsx0SVFjrd623MoQAAAHk"]
[Thu Sep 17 15:44:38.525360 2026] [security2:error] [pid 60716:tid 60913] [client 34.95.211.140:35644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfRsPsx0SVFjrd623MowAAABU"]
[Thu Sep 17 15:44:38.605835 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxfRsPsx0SVFjrd623MqAAAAGQ"]
[Thu Sep 17 15:44:38.694379 2026] [security2:error] [pid 60716:tid 60965] [client 159.203.57.242:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxfRsPsx0SVFjrd623MpQAAAEc"]
[Thu Sep 17 15:44:38.768339 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxfRsPsx0SVFjrd623MrQAAAG0"]
[Thu Sep 17 15:44:38.811373 2026] [security2:error] [pid 60716:tid 60893] [client 16.216.88.190:36864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/index.php"] [unique_id "aqxfRcPsx0SVFjrd623McgAAAU0"]
[Thu Sep 17 15:44:38.869614 2026] [security2:error] [pid 60716:tid 60987] [client 159.203.57.242:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxfRsPsx0SVFjrd623MrgAAAF0"]
[Thu Sep 17 15:44:38.939642 2026] [security2:error] [pid 60716:tid 60894] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxfRsPsx0SVFjrd623MtQAAAAI"]
[Thu Sep 17 15:44:39.007916 2026] [security2:error] [pid 60716:tid 60933] [client 34.95.211.140:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxfR8Psx0SVFjrd623MuAAAACc"]
[Thu Sep 17 15:44:39.123231 2026] [security2:error] [pid 60716:tid 60942] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxfR8Psx0SVFjrd623MugAAADA"]
[Thu Sep 17 15:44:39.128787 2026] [security2:error] [pid 60716:tid 60897] [client 79.116.89.151:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfR8Psx0SVFjrd623MuwAAAAU"]
[Thu Sep 17 15:44:39.128880 2026] [security2:error] [pid 60716:tid 60897] [client 79.116.89.151:53896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfR8Psx0SVFjrd623MuwAAAAU"]
[Thu Sep 17 15:44:39.256282 2026] [security2:error] [pid 60716:tid 60961] [client 202.46.62.119:15252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfR8Psx0SVFjrd623MvwAAAEM"]
[Thu Sep 17 15:44:39.287365 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxfR8Psx0SVFjrd623MwQAAAHU"]
[Thu Sep 17 15:44:39.455837 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxfR8Psx0SVFjrd623MyQAAAFk"]
[Thu Sep 17 15:44:39.494432 2026] [security2:error] [pid 60716:tid 60790] [remote 111.225.149.195:13634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "qr.cyberpunkonline.net"] [uri "/"] [unique_id "aqxfR8Psx0SVFjrd623MzAAATRw"]
[Thu Sep 17 15:44:39.639372 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxfR8Psx0SVFjrd623MzwAAACM"]
[Thu Sep 17 15:44:39.658768 2026] [security2:error] [pid 60716:tid 60908] [client 34.95.211.140:39878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxfR8Psx0SVFjrd623M0gAAABA"]
[Thu Sep 17 15:44:39.797184 2026] [security2:error] [pid 60716:tid 60960] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxfR8Psx0SVFjrd623M1gAAAEI"]
[Thu Sep 17 15:44:39.897135 2026] [security2:error] [pid 60716:tid 61004] [client 180.177.225.6:53860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfR8Psx0SVFjrd623M1QAAbnE"]
[Thu Sep 17 15:44:39.964383 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxfR8Psx0SVFjrd623M2gAAACo"]
[Thu Sep 17 15:44:40.128490 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxfSMPsx0SVFjrd623M3gAAAGA"]
[Thu Sep 17 15:44:40.152218 2026] [security2:error] [pid 60716:tid 60914] [client 34.95.211.140:39890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxfSMPsx0SVFjrd623M4gAAABY"]
[Thu Sep 17 15:44:40.316335 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxfSMPsx0SVFjrd623M5QAAABU"]
[Thu Sep 17 15:44:40.497453 2026] [security2:error] [pid 60716:tid 60943] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxfSMPsx0SVFjrd623M8AAAADE"]
[Thu Sep 17 15:44:40.637384 2026] [security2:error] [pid 60716:tid 60996] [client 34.95.211.140:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxfSMPsx0SVFjrd623M8wAAAGY"]
[Thu Sep 17 15:44:40.653118 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxfSMPsx0SVFjrd623M9QAAAF0"]
[Thu Sep 17 15:44:40.808886 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxfSMPsx0SVFjrd623M-wAAAEU"]
[Thu Sep 17 15:44:40.965044 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxfSMPsx0SVFjrd623NAQAAAA4"]
[Thu Sep 17 15:44:41.119787 2026] [security2:error] [pid 60716:tid 60916] [client 34.95.211.140:39900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxfScPsx0SVFjrd623NAwAAABg"]
[Thu Sep 17 15:44:41.120692 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxfScPsx0SVFjrd623NBAAAAAA"]
[Thu Sep 17 15:44:41.235489 2026] [security2:error] [pid 60716:tid 61011] [client 169.58.197.251:53543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxfScPsx0SVFjrd623NCQAAAHU"], referer: binance.com
[Thu Sep 17 15:44:41.282207 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxfScPsx0SVFjrd623NCgAAAFA"]
[Thu Sep 17 15:44:41.461217 2026] [security2:error] [pid 60716:tid 60981] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxfScPsx0SVFjrd623NDwAAAFc"]
[Thu Sep 17 15:44:41.571495 2026] [security2:error] [pid 60716:tid 60983] [client 169.58.197.253:60511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxfScPsx0SVFjrd623NEQAAAFk"], referer: binance.com
[Thu Sep 17 15:44:41.606454 2026] [security2:error] [pid 60716:tid 60900] [client 34.95.211.140:39902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxfScPsx0SVFjrd623NEgAAAAg"]
[Thu Sep 17 15:44:41.639165 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxfScPsx0SVFjrd623NEwAAAC0"]
[Thu Sep 17 15:44:41.802219 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxfScPsx0SVFjrd623NGwAAADg"]
[Thu Sep 17 15:44:41.959869 2026] [security2:error] [pid 60716:tid 61021] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxfScPsx0SVFjrd623NIQAAAH8"]
[Thu Sep 17 15:44:42.094479 2026] [security2:error] [pid 60716:tid 61014] [client 34.95.211.140:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxfSsPsx0SVFjrd623NIgAAAHg"]
[Thu Sep 17 15:44:42.134249 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxfSsPsx0SVFjrd623NJAAAAFs"]
[Thu Sep 17 15:44:42.288151 2026] [security2:error] [pid 60716:tid 61013] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxfSsPsx0SVFjrd623NKQAAAHc"]
[Thu Sep 17 15:44:42.444260 2026] [security2:error] [pid 60716:tid 60970] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxfSsPsx0SVFjrd623NMAAAAEw"]
[Thu Sep 17 15:44:42.607365 2026] [security2:error] [pid 60716:tid 61017] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxfSsPsx0SVFjrd623NNAAAAHs"]
[Thu Sep 17 15:44:42.765732 2026] [security2:error] [pid 60716:tid 60984] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxfSsPsx0SVFjrd623NOgAAAFo"]
[Thu Sep 17 15:44:42.923024 2026] [security2:error] [pid 60716:tid 60922] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxfSsPsx0SVFjrd623NPgAAAB0"]
[Thu Sep 17 15:44:42.929232 2026] [security2:error] [pid 60716:tid 60963] [client 34.95.211.140:39916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfSsPsx0SVFjrd623NPwAAAEU"]
[Thu Sep 17 15:44:43.093567 2026] [security2:error] [pid 60716:tid 60897] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxfS8Psx0SVFjrd623NQwAAAAU"]
[Thu Sep 17 15:44:43.254871 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxfS8Psx0SVFjrd623NSAAAACI"]
[Thu Sep 17 15:44:43.409128 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxfS8Psx0SVFjrd623NUAAAAFU"]
[Thu Sep 17 15:44:43.410556 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.211.140:39918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxfS8Psx0SVFjrd623NUQAAAGs"]
[Thu Sep 17 15:44:43.529931 2026] [security2:error] [pid 60716:tid 60983] [client 3.19.142.206:61368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NVgAAAFk"]
[Thu Sep 17 15:44:43.530005 2026] [security2:error] [pid 60716:tid 60983] [client 3.19.142.206:61368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NVgAAAFk"]
[Thu Sep 17 15:44:43.546947 2026] [security2:error] [pid 60716:tid 61019] [client 3.19.142.206:61358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NVwAAAH0"]
[Thu Sep 17 15:44:43.547043 2026] [security2:error] [pid 60716:tid 61019] [client 3.19.142.206:61358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NVwAAAH0"]
[Thu Sep 17 15:44:43.547102 2026] [security2:error] [pid 60716:tid 60971] [client 3.19.142.206:61361] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NWAAAAE0"]
[Thu Sep 17 15:44:43.547160 2026] [security2:error] [pid 60716:tid 60971] [client 3.19.142.206:61361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NWAAAAE0"]
[Thu Sep 17 15:44:43.580047 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxfS8Psx0SVFjrd623NWgAAAAg"]
[Thu Sep 17 15:44:43.589022 2026] [security2:error] [pid 60716:tid 60916] [client 136.158.61.34:53707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NWQAAABg"]
[Thu Sep 17 15:44:43.589194 2026] [security2:error] [pid 60716:tid 60916] [client 136.158.61.34:53707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfS8Psx0SVFjrd623NWQAAABg"]
[Thu Sep 17 15:44:43.745497 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxfS8Psx0SVFjrd623NXwAAADg"]
[Thu Sep 17 15:44:43.889608 2026] [security2:error] [pid 60716:tid 60896] [client 34.95.211.140:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfS8Psx0SVFjrd623NZwAAAAQ"]
[Thu Sep 17 15:44:43.906177 2026] [security2:error] [pid 60716:tid 61013] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxfS8Psx0SVFjrd623NagAAAHc"]
[Thu Sep 17 15:44:44.061389 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxfTMPsx0SVFjrd623NcAAAADo"]
[Thu Sep 17 15:44:44.218690 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxfTMPsx0SVFjrd623NeAAAADI"]
[Thu Sep 17 15:44:44.373515 2026] [security2:error] [pid 60716:tid 61015] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxfTMPsx0SVFjrd623NewAAAHk"]
[Thu Sep 17 15:44:44.385575 2026] [security2:error] [pid 60716:tid 60982] [client 34.95.211.140:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfTMPsx0SVFjrd623NfQAAAFg"]
[Thu Sep 17 15:44:44.536384 2026] [security2:error] [pid 60716:tid 60943] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxfTMPsx0SVFjrd623NgQAAADE"]
[Thu Sep 17 15:44:44.691031 2026] [security2:error] [pid 60716:tid 60922] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxfTMPsx0SVFjrd623NiAAAAB0"]
[Thu Sep 17 15:44:44.823184 2026] [security2:error] [pid 60716:tid 60988] [client 103.61.184.148:57789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfTMPsx0SVFjrd623NiQAAAF4"]
[Thu Sep 17 15:44:44.823305 2026] [security2:error] [pid 60716:tid 60988] [client 103.61.184.148:57789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfTMPsx0SVFjrd623NiQAAAF4"]
[Thu Sep 17 15:44:44.854345 2026] [security2:error] [pid 60716:tid 60978] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxfTMPsx0SVFjrd623NiwAAAFQ"]
[Thu Sep 17 15:44:44.871121 2026] [security2:error] [pid 60716:tid 60963] [client 34.95.211.140:39954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfTMPsx0SVFjrd623NjQAAAEU"]
[Thu Sep 17 15:44:44.985857 2026] [cgid:error] [pid 60716:tid 60777] [remote 104.28.124.173:16843] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:44:45.009604 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxfTcPsx0SVFjrd623NkwAAAAk"]
[Thu Sep 17 15:44:45.167516 2026] [security2:error] [pid 60716:tid 61002] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxfTcPsx0SVFjrd623NmQAAAGw"]
[Thu Sep 17 15:44:45.321647 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxfTcPsx0SVFjrd623NmwAAAHQ"]
[Thu Sep 17 15:44:45.355452 2026] [security2:error] [pid 60716:tid 60912] [client 34.95.211.140:39960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfTcPsx0SVFjrd623NnAAAABQ"]
[Thu Sep 17 15:44:45.475437 2026] [security2:error] [pid 60716:tid 60980] [client 34.154.55.182:38330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxfTcPsx0SVFjrd623NoQAAAFY"]
[Thu Sep 17 15:44:45.543271 2026] [security2:error] [pid 60716:tid 60898] [client 162.241.226.11:15736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aqxfTcPsx0SVFjrd623NpQAAAAY"]
[Thu Sep 17 15:44:45.593584 2026] [access_compat:error] [pid 60716:tid 61005] [client 186.167.68.19:45707] AH01797: client denied by server configuration: /home2/zphiblgz/public_html/xmlrpc.php
[Thu Sep 17 15:44:45.604919 2026] [security2:error] [pid 60716:tid 61014] [client 3.19.142.206:62093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfTcPsx0SVFjrd623NqgAAAHg"]
[Thu Sep 17 15:44:45.605159 2026] [security2:error] [pid 60716:tid 61014] [client 3.19.142.206:62093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfTcPsx0SVFjrd623NqgAAAHg"]
[Thu Sep 17 15:44:45.609580 2026] [security2:error] [pid 60716:tid 60942] [client 3.19.142.206:62078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfTcPsx0SVFjrd623NrQAAADA"]
[Thu Sep 17 15:44:45.609646 2026] [security2:error] [pid 60716:tid 60942] [client 3.19.142.206:62078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "itsonyou.org"] [uri "/xmlrpc.php"] [unique_id "aqxfTcPsx0SVFjrd623NrQAAADA"]
[Thu Sep 17 15:44:45.757288 2026] [cgid:error] [pid 60716:tid 60951] [client 66.249.66.73:65377] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:44:45.846801 2026] [security2:error] [pid 60716:tid 60931] [client 34.95.211.140:39966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxfTcPsx0SVFjrd623NvQAAACU"]
[Thu Sep 17 15:44:45.936207 2026] [security2:error] [pid 60716:tid 61020] [client 14.96.156.146:57593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfTcPsx0SVFjrd623NwgAAAH4"]
[Thu Sep 17 15:44:45.936307 2026] [security2:error] [pid 60716:tid 61020] [client 14.96.156.146:57593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfTcPsx0SVFjrd623NwgAAAH4"]
[Thu Sep 17 15:44:45.955035 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxfTcPsx0SVFjrd623NwwAAAAw"]
[Thu Sep 17 15:44:46.101340 2026] [security2:error] [pid 60716:tid 60945] [client 148.227.75.216:60709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfTsPsx0SVFjrd623NyAAAADM"]
[Thu Sep 17 15:44:46.101426 2026] [security2:error] [pid 60716:tid 60945] [client 148.227.75.216:60709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfTsPsx0SVFjrd623NyAAAADM"]
[Thu Sep 17 15:44:46.116876 2026] [security2:error] [pid 60716:tid 60992] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxfTsPsx0SVFjrd623NyQAAAGI"]
[Thu Sep 17 15:44:46.282029 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxfTsPsx0SVFjrd623NzgAAAF0"]
[Thu Sep 17 15:44:46.338881 2026] [security2:error] [pid 60716:tid 60995] [client 34.95.211.140:39976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxfTsPsx0SVFjrd623N0AAAAGU"]
[Thu Sep 17 15:44:46.432726 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxfTsPsx0SVFjrd623N1AAAADQ"]
[Thu Sep 17 15:44:46.584050 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxfTsPsx0SVFjrd623N2AAAAAA"]
[Thu Sep 17 15:44:46.736502 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxfTsPsx0SVFjrd623N3QAAAFU"]
[Thu Sep 17 15:44:46.827410 2026] [security2:error] [pid 60716:tid 60958] [client 34.95.211.140:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxfTsPsx0SVFjrd623N3wAAAEA"]
[Thu Sep 17 15:44:46.896039 2026] [security2:error] [pid 60716:tid 60912] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxfTsPsx0SVFjrd623N4wAAABQ"]
[Thu Sep 17 15:44:47.051572 2026] [security2:error] [pid 60716:tid 60980] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxfT8Psx0SVFjrd623N5wAAAFY"]
[Thu Sep 17 15:44:47.206777 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxfT8Psx0SVFjrd623N7AAAAAY"]
[Thu Sep 17 15:44:47.308757 2026] [security2:error] [pid 60716:tid 60902] [client 34.95.211.140:39996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxfT8Psx0SVFjrd623N7gAAAAo"]
[Thu Sep 17 15:44:47.361482 2026] [security2:error] [pid 60716:tid 61021] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxfT8Psx0SVFjrd623N8AAAAH8"]
[Thu Sep 17 15:44:47.514412 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxfT8Psx0SVFjrd623N9gAAAGM"]
[Thu Sep 17 15:44:47.637572 2026] [security2:error] [pid 60716:tid 60972] [client 177.44.133.72:52018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfT8Psx0SVFjrd623N_QAAAE4"]
[Thu Sep 17 15:44:47.637673 2026] [security2:error] [pid 60716:tid 60972] [client 177.44.133.72:52018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfT8Psx0SVFjrd623N_QAAAE4"]
[Thu Sep 17 15:44:47.675226 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxfT8Psx0SVFjrd623OAQAAAAw"]
[Thu Sep 17 15:44:47.799386 2026] [security2:error] [pid 60716:tid 60924] [client 34.95.211.140:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxfT8Psx0SVFjrd623OBAAAAB8"]
[Thu Sep 17 15:44:47.832995 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxfT8Psx0SVFjrd623OBQAAAD0"]
[Thu Sep 17 15:44:47.990338 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxfT8Psx0SVFjrd623OCQAAAGA"]
[Thu Sep 17 15:44:48.042024 2026] [security2:error] [pid 60716:tid 60952] [client 143.105.152.240:32722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfUMPsx0SVFjrd623ODAAAADo"]
[Thu Sep 17 15:44:48.049749 2026] [security2:error] [pid 60716:tid 60952] [client 143.105.152.240:32722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfUMPsx0SVFjrd623ODAAAADo"]
[Thu Sep 17 15:44:48.116652 2026] [security2:error] [pid 60716:tid 60992] [client 162.241.226.11:44990] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxfUMPsx0SVFjrd623ODgAAAGI"]
[Thu Sep 17 15:44:48.147111 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxfUMPsx0SVFjrd623OEAAAAFE"]
[Thu Sep 17 15:44:48.297117 2026] [security2:error] [pid 60716:tid 60994] [client 34.95.211.140:40014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxfUMPsx0SVFjrd623OFgAAAGQ"]
[Thu Sep 17 15:44:48.302154 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxfUMPsx0SVFjrd623OFwAAAF0"]
[Thu Sep 17 15:44:48.379598 2026] [security2:error] [pid 60716:tid 61003] [client 74.7.241.175:48986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.qr.cyberpunkonline.net"] [uri "/404.html"] [unique_id "aqxfUMPsx0SVFjrd623OGAAAbWo"]
[Thu Sep 17 15:44:48.454127 2026] [security2:error] [pid 60716:tid 60894] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxfUMPsx0SVFjrd623OHQAAAAI"]
[Thu Sep 17 15:44:48.606105 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxfUMPsx0SVFjrd623OIAAAAFU"]
[Thu Sep 17 15:44:48.640011 2026] [security2:error] [pid 60716:tid 60901] [client 3.19.142.206:62765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfUMPsx0SVFjrd623OIgAAAAk"]
[Thu Sep 17 15:44:48.769110 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxfUMPsx0SVFjrd623OJwAAAGs"]
[Thu Sep 17 15:44:48.793995 2026] [security2:error] [pid 60716:tid 60938] [client 34.95.211.140:40026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxfUMPsx0SVFjrd623OKAAAACw"]
[Thu Sep 17 15:44:48.934567 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxfUMPsx0SVFjrd623OLwAAAEs"]
[Thu Sep 17 15:44:49.086935 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxfUcPsx0SVFjrd623OMQAAAAg"]
[Thu Sep 17 15:44:49.238112 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxfUcPsx0SVFjrd623OOAAAADg"]
[Thu Sep 17 15:44:49.280225 2026] [security2:error] [pid 60716:tid 60916] [client 34.95.211.140:52978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxfUcPsx0SVFjrd623OOQAAABg"]
[Thu Sep 17 15:44:49.391905 2026] [security2:error] [pid 60716:tid 61013] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxfUcPsx0SVFjrd623OPgAAAHc"]
[Thu Sep 17 15:44:49.549920 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxfUcPsx0SVFjrd623OQwAAAGM"]
[Thu Sep 17 15:44:49.708543 2026] [security2:error] [pid 60716:tid 61008] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxfUcPsx0SVFjrd623OSQAAAHI"]
[Thu Sep 17 15:44:49.774076 2026] [security2:error] [pid 60716:tid 61011] [client 79.116.89.151:54522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfUcPsx0SVFjrd623OSwAAAHU"]
[Thu Sep 17 15:44:49.774627 2026] [security2:error] [pid 60716:tid 61011] [client 79.116.89.151:54522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfUcPsx0SVFjrd623OSwAAAHU"]
[Thu Sep 17 15:44:49.791469 2026] [security2:error] [pid 60716:tid 60936] [client 34.95.211.140:52982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxfUcPsx0SVFjrd623OTAAAACo"]
[Thu Sep 17 15:44:49.910339 2026] [security2:error] [pid 60716:tid 60915] [client 38.25.137.139:47770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfUcPsx0SVFjrd623OTQAAFz0"]
[Thu Sep 17 15:44:49.922760 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxfUcPsx0SVFjrd623OTwAAAGo"]
[Thu Sep 17 15:44:49.976348 2026] [security2:error] [pid 60716:tid 61015] [client 192.178.6.4:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxfUcPsx0SVFjrd623OUwAAAHk"]
[Thu Sep 17 15:44:50.086258 2026] [security2:error] [pid 60716:tid 60943] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxfUsPsx0SVFjrd623OVgAAADE"]
[Thu Sep 17 15:44:50.243368 2026] [security2:error] [pid 60716:tid 60988] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxfUsPsx0SVFjrd623OXgAAAF4"]
[Thu Sep 17 15:44:50.280928 2026] [security2:error] [pid 60716:tid 61009] [client 34.95.211.140:52988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxfUsPsx0SVFjrd623OYAAAAHM"]
[Thu Sep 17 15:44:50.354978 2026] [security2:error] [pid 60716:tid 60995] [client 169.58.197.251:54139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxfUsPsx0SVFjrd623OYwAAAGU"], referer: binance.com
[Thu Sep 17 15:44:50.400831 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.55.182:59464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxfUsPsx0SVFjrd623OZwAAABE"]
[Thu Sep 17 15:44:50.566195 2026] [security2:error] [pid 60716:tid 60958] [client 169.58.197.253:60977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxfUsPsx0SVFjrd623ObwAAAEA"], referer: binance.com
[Thu Sep 17 15:44:50.763958 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.211.140:53002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxfUsPsx0SVFjrd623OeQAAAGs"]
[Thu Sep 17 15:44:51.249009 2026] [security2:error] [pid 60716:tid 60896] [client 34.95.211.140:53018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfU8Psx0SVFjrd623OiAAAAAQ"]
[Thu Sep 17 15:44:51.616926 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxfU8Psx0SVFjrd623OkQAAAHU"]
[Thu Sep 17 15:44:51.746268 2026] [security2:error] [pid 60716:tid 61000] [client 34.95.211.140:53026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfU8Psx0SVFjrd623OlwAAAGo"]
[Thu Sep 17 15:44:51.774689 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxfU8Psx0SVFjrd623OmAAAADo"]
[Thu Sep 17 15:44:51.956851 2026] [security2:error] [pid 60716:tid 61012] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxfU8Psx0SVFjrd623OngAAAHY"]
[Thu Sep 17 15:44:52.130548 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxfVMPsx0SVFjrd623OogAAACM"]
[Thu Sep 17 15:44:52.228398 2026] [security2:error] [pid 60716:tid 60941] [client 34.95.211.140:53030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxfVMPsx0SVFjrd623OpgAAAC8"]
[Thu Sep 17 15:44:52.287646 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxfVMPsx0SVFjrd623OpwAAAEY"]
[Thu Sep 17 15:44:52.420733 2026] [security2:error] [pid 60716:tid 60956] [client 208.109.3.10:25316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bluetech.com"] [uri "/index.php"] [unique_id "aqxfVMPsx0SVFjrd623OoQAAAD4"]
[Thu Sep 17 15:44:52.451089 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxfVMPsx0SVFjrd623OrwAAAFU"]
[Thu Sep 17 15:44:52.605397 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxfVMPsx0SVFjrd623OsQAAAAA"]
[Thu Sep 17 15:44:52.719172 2026] [security2:error] [pid 60716:tid 60934] [client 34.95.211.140:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxfVMPsx0SVFjrd623OtgAAACg"]
[Thu Sep 17 15:44:52.767765 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxfVMPsx0SVFjrd623OtwAAAEs"]
[Thu Sep 17 15:44:52.926483 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxfVMPsx0SVFjrd623OuwAAABo"]
[Thu Sep 17 15:44:53.088992 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxfVcPsx0SVFjrd623OwQAAACk"]
[Thu Sep 17 15:44:53.202577 2026] [security2:error] [pid 60716:tid 60949] [client 34.95.211.140:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfVcPsx0SVFjrd623OxgAAADc"]
[Thu Sep 17 15:44:53.247919 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxfVcPsx0SVFjrd623OyAAAABM"]
[Thu Sep 17 15:44:53.410886 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxfVcPsx0SVFjrd623OywAAACA"]
[Thu Sep 17 15:44:53.568871 2026] [security2:error] [pid 60716:tid 60977] [client 3.19.142.206:64288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxfVMPsx0SVFjrd623OuQAAAFM"]
[Thu Sep 17 15:44:53.569204 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxfVcPsx0SVFjrd623O0AAAAFs"]
[Thu Sep 17 15:44:53.706094 2026] [security2:error] [pid 60716:tid 60931] [client 34.95.211.140:53054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfVcPsx0SVFjrd623O1gAAACU"]
[Thu Sep 17 15:44:53.732671 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxfVcPsx0SVFjrd623O2AAAAD0"]
[Thu Sep 17 15:44:53.891317 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxfVcPsx0SVFjrd623O2wAAAGo"]
[Thu Sep 17 15:44:54.050781 2026] [security2:error] [pid 60716:tid 60932] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxfVsPsx0SVFjrd623O4QAAACY"]
[Thu Sep 17 15:44:54.145044 2026] [security2:error] [pid 60716:tid 60940] [client 36.152.7.94:48908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "talent-in-borders.com"] [uri "/tag/demo-love/"] [unique_id "aqxfVsPsx0SVFjrd623O5AAAAC4"]
[Thu Sep 17 15:44:54.145145 2026] [security2:error] [pid 60716:tid 60940] [client 36.152.7.94:48908] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "talent-in-borders.com"] [uri "/tag/demo-love/"] [unique_id "aqxfVsPsx0SVFjrd623O5AAAAC4"]
[Thu Sep 17 15:44:54.194962 2026] [security2:error] [pid 60716:tid 60996] [client 34.95.211.140:53056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxfVsPsx0SVFjrd623O5gAAAGY"]
[Thu Sep 17 15:44:54.207439 2026] [security2:error] [pid 60716:tid 60937] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxfVsPsx0SVFjrd623O5wAAACs"]
[Thu Sep 17 15:44:54.361490 2026] [security2:error] [pid 60716:tid 60995] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxfVsPsx0SVFjrd623O6gAAAGU"]
[Thu Sep 17 15:44:54.543458 2026] [security2:error] [pid 60716:tid 60897] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxfVsPsx0SVFjrd623O8QAAAAU"]
[Thu Sep 17 15:44:54.594084 2026] [security2:error] [pid 60716:tid 60906] [client 5.188.86.234:51972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/blog/wp-login.php"] [unique_id "aqxfVsPsx0SVFjrd623O8wAAAA4"]
[Thu Sep 17 15:44:54.686996 2026] [security2:error] [pid 60716:tid 60989] [client 34.95.211.140:53060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.211.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hbe.kxw.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxfVsPsx0SVFjrd623O9wAAAF8"]
[Thu Sep 17 15:44:54.704247 2026] [security2:error] [pid 60716:tid 60957] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxfVsPsx0SVFjrd623O-QAAAD8"]
[Thu Sep 17 15:44:54.886611 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxfVsPsx0SVFjrd623O_AAAAAk"]
[Thu Sep 17 15:44:55.047447 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxfV8Psx0SVFjrd623PAgAAAHQ"]
[Thu Sep 17 15:44:55.051474 2026] [security2:error] [pid 60716:tid 60846] [remote 5.188.86.234:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website.learn360lms.com"] [uri "/blog/wp-login.php"] [unique_id "aqxfV8Psx0SVFjrd623PAwAAbFQ"]
[Thu Sep 17 15:44:55.208207 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxfV8Psx0SVFjrd623PCQAAAA8"]
[Thu Sep 17 15:44:55.373746 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxfV8Psx0SVFjrd623PDQAAABg"]
[Thu Sep 17 15:44:55.417470 2026] [security2:error] [pid 60716:tid 61001] [client 186.104.60.63:49284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfV8Psx0SVFjrd623PCwAAa2w"]
[Thu Sep 17 15:44:55.548957 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxfV8Psx0SVFjrd623PFQAAAGM"]
[Thu Sep 17 15:44:55.560923 2026] [security2:error] [pid 60716:tid 60918] [client 103.61.184.148:58363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfV8Psx0SVFjrd623PFgAAABo"]
[Thu Sep 17 15:44:55.561061 2026] [security2:error] [pid 60716:tid 60918] [client 103.61.184.148:58363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfV8Psx0SVFjrd623PFgAAABo"]
[Thu Sep 17 15:44:55.708242 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxfV8Psx0SVFjrd623PHgAAAFs"]
[Thu Sep 17 15:44:55.865552 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxfV8Psx0SVFjrd623PHwAAAEc"]
[Thu Sep 17 15:44:56.024091 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxfWMPsx0SVFjrd623PKAAAACE"]
[Thu Sep 17 15:44:56.185915 2026] [security2:error] [pid 60716:tid 60990] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxfWMPsx0SVFjrd623PMAAAAGA"]
[Thu Sep 17 15:44:56.349946 2026] [security2:error] [pid 60716:tid 60895] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxfWMPsx0SVFjrd623PMgAAAAM"]
[Thu Sep 17 15:44:56.419648 2026] [security2:error] [pid 60716:tid 61000] [client 136.158.61.34:54709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PNwAAAGo"]
[Thu Sep 17 15:44:56.419746 2026] [security2:error] [pid 60716:tid 61000] [client 136.158.61.34:54709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PNwAAAGo"]
[Thu Sep 17 15:44:56.482456 2026] [security2:error] [pid 60716:tid 60944] [client 3.19.142.206:65383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623POwAAADI"]
[Thu Sep 17 15:44:56.482456 2026] [security2:error] [pid 60716:tid 60995] [client 3.19.142.206:65454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623POgAAAGU"]
[Thu Sep 17 15:44:56.482493 2026] [security2:error] [pid 60716:tid 60995] [client 3.19.142.206:65454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623POgAAAGU"]
[Thu Sep 17 15:44:56.482493 2026] [security2:error] [pid 60716:tid 60944] [client 3.19.142.206:65383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623POwAAADI"]
[Thu Sep 17 15:44:56.505532 2026] [security2:error] [pid 60716:tid 60940] [client 14.96.156.146:58273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PPQAAAC4"]
[Thu Sep 17 15:44:56.506615 2026] [security2:error] [pid 60716:tid 60940] [client 14.96.156.146:58273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PPQAAAC4"]
[Thu Sep 17 15:44:56.510832 2026] [security2:error] [pid 60716:tid 60941] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxfWMPsx0SVFjrd623PPgAAAC8"]
[Thu Sep 17 15:44:56.550343 2026] [security2:error] [pid 60716:tid 60910] [client 3.19.142.206:65401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PPwAAABI"]
[Thu Sep 17 15:44:56.550378 2026] [security2:error] [pid 60716:tid 60910] [client 3.19.142.206:65401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PPwAAABI"]
[Thu Sep 17 15:44:56.672905 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxfWMPsx0SVFjrd623PSAAAAFA"]
[Thu Sep 17 15:44:56.761605 2026] [security2:error] [pid 60716:tid 60933] [client 148.227.75.216:61299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PSwAAACc"]
[Thu Sep 17 15:44:56.770094 2026] [security2:error] [pid 60716:tid 60933] [client 148.227.75.216:61299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PSwAAACc"]
[Thu Sep 17 15:44:56.773917 2026] [security2:error] [pid 60716:tid 60971] [client 3.19.142.206:65401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PTAAAAE0"]
[Thu Sep 17 15:44:56.773949 2026] [security2:error] [pid 60716:tid 60971] [client 3.19.142.206:65401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wp/xmlrpc.php"] [unique_id "aqxfWMPsx0SVFjrd623PTAAAAE0"]
[Thu Sep 17 15:44:56.832774 2026] [security2:error] [pid 60716:tid 60968] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxfWMPsx0SVFjrd623PTQAAAEo"]
[Thu Sep 17 15:44:56.863554 2026] [security2:error] [pid 60716:tid 60934] [client 34.166.129.237:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/phpinfo.php"] [unique_id "aqxfWMPsx0SVFjrd623PTgAAACg"]
[Thu Sep 17 15:44:56.996536 2026] [security2:error] [pid 60716:tid 60948] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxfWMPsx0SVFjrd623PVAAAADY"]
[Thu Sep 17 15:44:57.152854 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxfWcPsx0SVFjrd623PWgAAAHE"]
[Thu Sep 17 15:44:57.154412 2026] [security2:error] [pid 60716:tid 61002] [client 129.212.220.28:47544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxfWcPsx0SVFjrd623PVwAAAGw"]
[Thu Sep 17 15:44:57.192698 2026] [security2:error] [pid 60716:tid 60938] [client 210.222.43.21:52778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxfWcPsx0SVFjrd623PWAAAACw"], referer: http://talent-in-borders.com/BLOG
[Thu Sep 17 15:44:57.325255 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxfWcPsx0SVFjrd623PXwAAABY"]
[Thu Sep 17 15:44:57.481555 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxfWcPsx0SVFjrd623PZwAAAAQ"]
[Thu Sep 17 15:44:57.562238 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.129.237:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/info.php"] [unique_id "aqxfWcPsx0SVFjrd623PaAAAACA"]
[Thu Sep 17 15:44:57.638614 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxfWcPsx0SVFjrd623PagAAAHg"]
[Thu Sep 17 15:44:57.824921 2026] [security2:error] [pid 60716:tid 60924] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxfWcPsx0SVFjrd623PbgAAAB8"]
[Thu Sep 17 15:44:57.982769 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxfWcPsx0SVFjrd623PdAAAAHU"]
[Thu Sep 17 15:44:58.137796 2026] [security2:error] [pid 60716:tid 60953] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxfWsPsx0SVFjrd623PdwAAADs"]
[Thu Sep 17 15:44:58.207395 2026] [security2:error] [pid 60716:tid 60988] [client 169.58.197.251:55108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxfWsPsx0SVFjrd623PfgAAAF4"], referer: binance.com
[Thu Sep 17 15:44:58.241493 2026] [security2:error] [pid 60716:tid 60952] [client 34.166.129.237:59524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/php.php"] [unique_id "aqxfWsPsx0SVFjrd623PgQAAADo"]
[Thu Sep 17 15:44:58.285277 2026] [security2:error] [pid 60716:tid 60902] [client 177.44.133.72:52691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfWsPsx0SVFjrd623PgwAAAAo"]
[Thu Sep 17 15:44:58.285383 2026] [security2:error] [pid 60716:tid 60902] [client 177.44.133.72:52691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfWsPsx0SVFjrd623PgwAAAAo"]
[Thu Sep 17 15:44:58.292225 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxfWsPsx0SVFjrd623PhAAAADI"]
[Thu Sep 17 15:44:58.450623 2026] [security2:error] [pid 60716:tid 61017] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxfWsPsx0SVFjrd623PiAAAAHs"]
[Thu Sep 17 15:44:58.528524 2026] [security2:error] [pid 60716:tid 60955] [client 143.105.152.240:50283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfWsPsx0SVFjrd623PjAAAAD0"]
[Thu Sep 17 15:44:58.528601 2026] [security2:error] [pid 60716:tid 60955] [client 143.105.152.240:50283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfWsPsx0SVFjrd623PjAAAAD0"]
[Thu Sep 17 15:44:58.608482 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxfWsPsx0SVFjrd623PjgAAAEA"]
[Thu Sep 17 15:44:58.762992 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxfWsPsx0SVFjrd623PkgAAADw"]
[Thu Sep 17 15:44:58.889731 2026] [security2:error] [pid 60716:tid 60933] [client 3.19.142.206:49904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfWsPsx0SVFjrd623PlAAAACc"]
[Thu Sep 17 15:44:58.919721 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.129.237:59530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/i.php"] [unique_id "aqxfWsPsx0SVFjrd623PlQAAAAA"]
[Thu Sep 17 15:44:58.922525 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxfWsPsx0SVFjrd623PlgAAAE0"]
[Thu Sep 17 15:44:59.083065 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxfW8Psx0SVFjrd623PnQAAAEs"]
[Thu Sep 17 15:44:59.246085 2026] [security2:error] [pid 60716:tid 60912] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxfW8Psx0SVFjrd623PowAAABQ"]
[Thu Sep 17 15:44:59.359528 2026] [security2:error] [pid 60716:tid 60949] [client 169.58.197.253:61520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxfW8Psx0SVFjrd623PpQAAADc"], referer: binance.com
[Thu Sep 17 15:44:59.406292 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxfW8Psx0SVFjrd623PpgAAAHE"]
[Thu Sep 17 15:44:59.605412 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxfW8Psx0SVFjrd623PrQAAAH0"]
[Thu Sep 17 15:44:59.611788 2026] [security2:error] [pid 60716:tid 60960] [client 34.166.129.237:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/pi.php"] [unique_id "aqxfW8Psx0SVFjrd623PrgAAAEI"]
[Thu Sep 17 15:44:59.663438 2026] [security2:error] [pid 60716:tid 60922] [client 40.77.167.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxfWsPsx0SVFjrd623PggAAAB0"]
[Thu Sep 17 15:44:59.764332 2026] [security2:error] [pid 60716:tid 60899] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxfW8Psx0SVFjrd623PtAAAAAc"]
[Thu Sep 17 15:44:59.923912 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxfW8Psx0SVFjrd623PtgAAAFg"]
[Thu Sep 17 15:45:00.088331 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxfXMPsx0SVFjrd623PuwAAADM"]
[Thu Sep 17 15:45:00.266586 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxfXMPsx0SVFjrd623PwQAAADI"]
[Thu Sep 17 15:45:00.299667 2026] [security2:error] [pid 60716:tid 60917] [client 34.166.129.237:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/pinfo.php"] [unique_id "aqxfXMPsx0SVFjrd623PwgAAABk"]
[Thu Sep 17 15:45:00.429707 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxfXMPsx0SVFjrd623PxgAAACM"]
[Thu Sep 17 15:45:00.453569 2026] [security2:error] [pid 60716:tid 60990] [client 79.116.89.151:55152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfXMPsx0SVFjrd623PxwAAAGA"]
[Thu Sep 17 15:45:00.453734 2026] [security2:error] [pid 60716:tid 60990] [client 79.116.89.151:55152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfXMPsx0SVFjrd623PxwAAAGA"]
[Thu Sep 17 15:45:00.583121 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxfXMPsx0SVFjrd623P3AAAAFA"]
[Thu Sep 17 15:45:00.788498 2026] [security2:error] [pid 60716:tid 60934] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxfXMPsx0SVFjrd623P4gAAACg"]
[Thu Sep 17 15:45:00.969432 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxfXMPsx0SVFjrd623P6AAAACI"]
[Thu Sep 17 15:45:00.998743 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.129.237:59556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/test.php"] [unique_id "aqxfXMPsx0SVFjrd623P6gAAAAA"]
[Thu Sep 17 15:45:01.148237 2026] [security2:error] [pid 60716:tid 60966] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxfXcPsx0SVFjrd623P8wAAAEg"]
[Thu Sep 17 15:45:01.309678 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxfXcPsx0SVFjrd623P-AAAAGM"]
[Thu Sep 17 15:45:01.474885 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.55.182:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxfXcPsx0SVFjrd623QAQAAAC0"]
[Thu Sep 17 15:45:01.652092 2026] [security2:error] [pid 60716:tid 60893] [client 34.154.55.182:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxfXcPsx0SVFjrd623QBgAAAAE"]
[Thu Sep 17 15:45:01.930527 2026] [security2:error] [pid 60716:tid 60943] [client 34.166.129.237:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/p.php"] [unique_id "aqxfXcPsx0SVFjrd623QEQAAADE"]
[Thu Sep 17 15:45:02.191554 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.55.182:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/info.php"] [unique_id "aqxfXsPsx0SVFjrd623QGwAAAGQ"]
[Thu Sep 17 15:45:02.308606 2026] [security2:error] [pid 60716:tid 60940] [client 74.7.175.177:53800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.cavi.land"] [uri "/robots.txt"] [unique_id "aqxfXsPsx0SVFjrd623QHgAALgY"]
[Thu Sep 17 15:45:02.612204 2026] [security2:error] [pid 60716:tid 60957] [client 34.166.129.237:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/debug.php"] [unique_id "aqxfXsPsx0SVFjrd623QJAAAAD8"]
[Thu Sep 17 15:45:02.703995 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.55.182:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/php.php"] [unique_id "aqxfXsPsx0SVFjrd623QKAAAADQ"]
[Thu Sep 17 15:45:03.243163 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.55.182:60384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/i.php"] [unique_id "aqxfX8Psx0SVFjrd623QMwAAAEM"]
[Thu Sep 17 15:45:03.295320 2026] [security2:error] [pid 60716:tid 60978] [client 34.166.129.237:50682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxfX8Psx0SVFjrd623QNAAAAFQ"]
[Thu Sep 17 15:45:03.612097 2026] [security2:error] [pid 60716:tid 61002] [client 57.141.14.52:40882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxfX8Psx0SVFjrd623QOQAAbDE"]
[Thu Sep 17 15:45:03.770599 2026] [security2:error] [pid 60716:tid 60951] [client 3.19.142.206:51224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxfX8Psx0SVFjrd623QPAAAADk"]
[Thu Sep 17 15:45:03.812416 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.55.182:60396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxfX8Psx0SVFjrd623QQgAAAC0"]
[Thu Sep 17 15:45:04.003162 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.129.237:50696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/test/phpinfo.php"] [unique_id "aqxfYMPsx0SVFjrd623QRQAAAHo"]
[Thu Sep 17 15:45:04.359904 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.55.182:44676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxfYMPsx0SVFjrd623QTAAAAHU"]
[Thu Sep 17 15:45:04.685694 2026] [security2:error] [pid 60716:tid 60924] [client 34.166.129.237:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxfYMPsx0SVFjrd623QVwAAAB8"]
[Thu Sep 17 15:45:04.875761 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.55.182:44678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/test.php"] [unique_id "aqxfYMPsx0SVFjrd623QWQAAADI"]
[Thu Sep 17 15:45:05.370023 2026] [security2:error] [pid 60716:tid 60941] [client 34.166.129.237:50728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/old/phpinfo.php"] [unique_id "aqxfYcPsx0SVFjrd623QYwAAAC8"]
[Thu Sep 17 15:45:05.553689 2026] [security2:error] [pid 60716:tid 60933] [client 3.19.142.206:52029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QagAAACc"]
[Thu Sep 17 15:45:05.553726 2026] [security2:error] [pid 60716:tid 60933] [client 3.19.142.206:52029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QagAAACc"]
[Thu Sep 17 15:45:05.638113 2026] [security2:error] [pid 60716:tid 60934] [client 3.19.142.206:52034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QawAAACg"]
[Thu Sep 17 15:45:05.638150 2026] [security2:error] [pid 60716:tid 60934] [client 3.19.142.206:52034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QawAAACg"]
[Thu Sep 17 15:45:05.715936 2026] [security2:error] [pid 60716:tid 60955] [client 3.19.142.206:52035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QcQAAAD0"]
[Thu Sep 17 15:45:05.715965 2026] [security2:error] [pid 60716:tid 60955] [client 3.19.142.206:52035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QcQAAAD0"]
[Thu Sep 17 15:45:05.769198 2026] [security2:error] [pid 60716:tid 60989] [client 3.19.142.206:52029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QbwAAAF8"]
[Thu Sep 17 15:45:05.769236 2026] [security2:error] [pid 60716:tid 60989] [client 3.19.142.206:52029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/wordpress/xmlrpc.php"] [unique_id "aqxfYcPsx0SVFjrd623QbwAAAF8"]
[Thu Sep 17 15:45:06.058274 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.129.237:50736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfYsPsx0SVFjrd623QeAAAAAA"]
[Thu Sep 17 15:45:06.094301 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.55.182:44704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/p.php"] [unique_id "aqxfYsPsx0SVFjrd623QeQAAAAY"]
[Thu Sep 17 15:45:06.270494 2026] [security2:error] [pid 60716:tid 60991] [client 103.61.184.148:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfYsPsx0SVFjrd623QfgAAAGE"]
[Thu Sep 17 15:45:06.270619 2026] [security2:error] [pid 60716:tid 60991] [client 103.61.184.148:58935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfYsPsx0SVFjrd623QfgAAAGE"]
[Thu Sep 17 15:45:06.739970 2026] [security2:error] [pid 60716:tid 61016] [client 34.166.129.237:50752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/public/phpinfo.php"] [unique_id "aqxfYsPsx0SVFjrd623QhwAAAHo"]
[Thu Sep 17 15:45:06.775647 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.55.182:44708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxfYsPsx0SVFjrd623QiAAAAH0"]
[Thu Sep 17 15:45:07.221696 2026] [security2:error] [pid 60716:tid 60915] [client 14.96.156.146:58943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfY8Psx0SVFjrd623QkgAAABc"]
[Thu Sep 17 15:45:07.221845 2026] [security2:error] [pid 60716:tid 60915] [client 14.96.156.146:58943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfY8Psx0SVFjrd623QkgAAABc"]
[Thu Sep 17 15:45:07.303797 2026] [security2:error] [pid 60716:tid 61009] [client 45.174.149.8:3248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfY8Psx0SVFjrd623QkAAAc0Y"]
[Thu Sep 17 15:45:07.331802 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.55.182:44724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxfY8Psx0SVFjrd623QkwAAAGo"]
[Thu Sep 17 15:45:07.551630 2026] [security2:error] [pid 60716:tid 60895] [client 148.227.75.216:16204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfY8Psx0SVFjrd623QmQAAAAM"]
[Thu Sep 17 15:45:07.551819 2026] [security2:error] [pid 60716:tid 60895] [client 148.227.75.216:16204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfY8Psx0SVFjrd623QmQAAAAM"]
[Thu Sep 17 15:45:07.662967 2026] [security2:error] [pid 60716:tid 60903] [client 34.166.129.237:50754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/php-info.php"] [unique_id "aqxfY8Psx0SVFjrd623QngAAAAs"]
[Thu Sep 17 15:45:07.675479 2026] [security2:error] [pid 60716:tid 60909] [client 3.19.142.206:52611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfY8Psx0SVFjrd623QnwAAABE"]
[Thu Sep 17 15:45:07.986627 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.55.182:44732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxfY8Psx0SVFjrd623QpAAAAEQ"]
[Thu Sep 17 15:45:08.338989 2026] [security2:error] [pid 60716:tid 60950] [client 169.58.197.251:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxfZMPsx0SVFjrd623QqQAAADg"], referer: binance.com
[Thu Sep 17 15:45:08.343587 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.129.237:50758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/phpversion.php"] [unique_id "aqxfZMPsx0SVFjrd623QqgAAAG0"]
[Thu Sep 17 15:45:08.468156 2026] [security2:error] [pid 60716:tid 60981] [client 169.58.197.253:62109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxfZMPsx0SVFjrd623QrAAAAFc"], referer: binance.com
[Thu Sep 17 15:45:08.602512 2026] [authz_core:error] [pid 60716:tid 60986] [client 4.240.114.86:55620] AH01630: client denied by server configuration: /home1/jwdnycco/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:45:08.712833 2026] [security2:error] [pid 60716:tid 60976] [client 34.154.55.182:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxfZMPsx0SVFjrd623QtgAAAFI"]
[Thu Sep 17 15:45:08.987221 2026] [security2:error] [pid 60716:tid 61001] [client 177.44.133.72:53366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfZMPsx0SVFjrd623QuwAAAGs"]
[Thu Sep 17 15:45:08.987329 2026] [security2:error] [pid 60716:tid 61001] [client 177.44.133.72:53366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfZMPsx0SVFjrd623QuwAAAGs"]
[Thu Sep 17 15:45:09.018413 2026] [security2:error] [pid 60716:tid 60937] [client 34.166.129.237:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/_phpinfo.php"] [unique_id "aqxfZcPsx0SVFjrd623QvAAAACs"]
[Thu Sep 17 15:45:09.165073 2026] [security2:error] [pid 60716:tid 60916] [client 143.105.152.240:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfZcPsx0SVFjrd623QwAAAABg"]
[Thu Sep 17 15:45:09.165172 2026] [security2:error] [pid 60716:tid 60916] [client 143.105.152.240:5447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfZcPsx0SVFjrd623QwAAAABg"]
[Thu Sep 17 15:45:09.230698 2026] [security2:error] [pid 60716:tid 60972] [client 189.180.140.141:55147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfZcPsx0SVFjrd623QvwAATj0"]
[Thu Sep 17 15:45:09.424265 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.55.182:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxfZcPsx0SVFjrd623QyAAAAFk"]
[Thu Sep 17 15:45:09.717922 2026] [security2:error] [pid 60716:tid 60945] [client 34.166.129.237:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/old_phpinfo.php"] [unique_id "aqxfZcPsx0SVFjrd623QzwAAADM"]
[Thu Sep 17 15:45:09.810848 2026] [security2:error] [pid 60716:tid 61000] [client 129.212.220.28:50946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxfZcPsx0SVFjrd623Q0AAAAGo"]
[Thu Sep 17 15:45:09.926837 2026] [security2:error] [pid 60716:tid 60920] [client 3.19.142.206:53268] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "itsonyou.org"] [uri "/old/wp-json/wp/v2/users"] [unique_id "aqxfZcPsx0SVFjrd623Q1AAAABw"]
[Thu Sep 17 15:45:09.941603 2026] [security2:error] [pid 60716:tid 60988] [client 136.158.61.34:55996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfZcPsx0SVFjrd623Q1QAAAF4"]
[Thu Sep 17 15:45:09.941702 2026] [security2:error] [pid 60716:tid 60988] [client 136.158.61.34:55996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfZcPsx0SVFjrd623Q1QAAAF4"]
[Thu Sep 17 15:45:10.092598 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.55.182:44768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfZsPsx0SVFjrd623Q3QAAAFU"]
[Thu Sep 17 15:45:10.428814 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.129.237:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/server-info.php"] [unique_id "aqxfZsPsx0SVFjrd623Q5AAAAAc"]
[Thu Sep 17 15:45:10.477983 2026] [security2:error] [pid 60716:tid 60910] [client 66.248.203.10:28598] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bluetech.com"] [uri "/wp-content/plugins/email-subscribers/readme.txt"] [unique_id "aqxfZsPsx0SVFjrd623Q5QAAABI"]
[Thu Sep 17 15:45:10.639177 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.55.182:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxfZsPsx0SVFjrd623Q7gAAACA"]
[Thu Sep 17 15:45:10.852620 2026] [security2:error] [pid 60716:tid 60918] [client 187.109.131.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxfZcPsx0SVFjrd623QxgAAABo"], referer: https://hikingforwildness.com/
[Thu Sep 17 15:45:11.114812 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.129.237:50800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/server-status.php"] [unique_id "aqxfZ8Psx0SVFjrd623RAAAAAFY"]
[Thu Sep 17 15:45:11.137090 2026] [security2:error] [pid 60716:tid 60993] [client 79.116.89.151:55785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfZ8Psx0SVFjrd623RAQAAAGM"]
[Thu Sep 17 15:45:11.137215 2026] [security2:error] [pid 60716:tid 60993] [client 79.116.89.151:55785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfZ8Psx0SVFjrd623RAQAAAGM"]
[Thu Sep 17 15:45:11.909971 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.55.182:44788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxfZ8Psx0SVFjrd623RFQAAAHU"]
[Thu Sep 17 15:45:11.964344 2026] [security2:error] [pid 60716:tid 60936] [client 3.19.142.206:54027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxfZ8Psx0SVFjrd623REwAAACo"]
[Thu Sep 17 15:45:12.272594 2026] [security2:error] [pid 60716:tid 60894] [client 34.166.129.237:50804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfaMPsx0SVFjrd623RIgAAAAI"]
[Thu Sep 17 15:45:12.408265 2026] [security2:error] [pid 60716:tid 60933] [client 192.178.6.5:61080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxfaMPsx0SVFjrd623RJAAAACc"]
[Thu Sep 17 15:45:12.469635 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.55.182:44796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxfaMPsx0SVFjrd623RJwAAADw"]
[Thu Sep 17 15:45:12.628789 2026] [security2:error] [pid 60716:tid 60975] [client 165.245.228.249:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "test.interlinck.com"] [uri "/index.php"] [unique_id "aqxfZ8Psx0SVFjrd623RDwAAUUA"], referer: http://test.interlinck.com/blog/
[Thu Sep 17 15:45:12.820777 2026] [security2:error] [pid 60716:tid 60935] [client 165.245.228.249:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "test.interlinck.com"] [uri "/index.php"] [unique_id "aqxfaMPsx0SVFjrd623RMwAAKVc"], referer: http://test.interlinck.com/new/
[Thu Sep 17 15:45:12.955049 2026] [security2:error] [pid 60716:tid 61007] [client 34.166.129.237:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxfaMPsx0SVFjrd623ROgAAAHE"]
[Thu Sep 17 15:45:12.996299 2026] [security2:error] [pid 60716:tid 60772] [remote 103.190.47.28:43120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.47.190.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.legalpracticeinbrief.sportsgirlkat.com"] [uri "/wp-login.php"] [unique_id "aqxfaMPsx0SVFjrd623ROQAAXA0"]
[Thu Sep 17 15:45:13.008872 2026] [security2:error] [pid 60716:tid 60960] [client 165.245.228.249:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "test.interlinck.com"] [uri "/index.php"] [unique_id "aqxfaMPsx0SVFjrd623ROwAAQgs"], referer: http://test.interlinck.com/backup/
[Thu Sep 17 15:45:13.065015 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.55.182:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxfacPsx0SVFjrd623RPwAAABY"]
[Thu Sep 17 15:45:13.196273 2026] [security2:error] [pid 60716:tid 60972] [client 165.245.228.249:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "test.interlinck.com"] [uri "/index.php"] [unique_id "aqxfacPsx0SVFjrd623RRwAATmw"], referer: http://test.interlinck.com/old/
[Thu Sep 17 15:45:13.385387 2026] [security2:error] [pid 60716:tid 60902] [client 165.245.228.249:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "test.interlinck.com"] [uri "/index.php"] [unique_id "aqxfacPsx0SVFjrd623RSwAACm0"], referer: http://test.interlinck.com/wordpress/
[Thu Sep 17 15:45:13.638757 2026] [security2:error] [pid 60716:tid 60983] [client 34.166.129.237:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfacPsx0SVFjrd623RVQAAAFk"]
[Thu Sep 17 15:45:13.673618 2026] [security2:error] [pid 60716:tid 60995] [client 34.154.55.182:44802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxfacPsx0SVFjrd623RWgAAAGU"]
[Thu Sep 17 15:45:13.764079 2026] [security2:error] [pid 60716:tid 60970] [client 165.245.228.249:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "test.interlinck.com"] [uri "/index.php"] [unique_id "aqxfacPsx0SVFjrd623RYAAATH0"], referer: http://test.interlinck.com/wp/
[Thu Sep 17 15:45:14.326159 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.129.237:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfasPsx0SVFjrd623RbQAAAFc"]
[Thu Sep 17 15:45:14.355921 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.55.182:36270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxfasPsx0SVFjrd623RbgAAADg"]
[Thu Sep 17 15:45:14.414184 2026] [security2:error] [pid 60716:tid 60925] [client 3.19.142.206:54710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RbwAAACA"]
[Thu Sep 17 15:45:14.414244 2026] [security2:error] [pid 60716:tid 60925] [client 3.19.142.206:54710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RbwAAACA"]
[Thu Sep 17 15:45:14.425424 2026] [security2:error] [pid 60716:tid 60969] [client 3.19.142.206:54769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RcAAAAEs"]
[Thu Sep 17 15:45:14.425469 2026] [security2:error] [pid 60716:tid 60969] [client 3.19.142.206:54769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RcAAAAEs"]
[Thu Sep 17 15:45:14.515470 2026] [security2:error] [pid 60716:tid 60985] [client 3.19.142.206:54797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RdAAAAFs"]
[Thu Sep 17 15:45:14.515525 2026] [security2:error] [pid 60716:tid 60985] [client 3.19.142.206:54797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RdAAAAFs"]
[Thu Sep 17 15:45:14.718391 2026] [security2:error] [pid 60716:tid 60986] [client 3.19.142.206:54797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RfwAAAFw"]
[Thu Sep 17 15:45:14.718430 2026] [security2:error] [pid 60716:tid 60986] [client 3.19.142.206:54797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/old/xmlrpc.php"] [unique_id "aqxfasPsx0SVFjrd623RfwAAAFw"]
[Thu Sep 17 15:45:14.966327 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.55.182:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxfasPsx0SVFjrd623RggAAAGE"]
[Thu Sep 17 15:45:15.027468 2026] [security2:error] [pid 60716:tid 61017] [client 34.166.129.237:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfa8Psx0SVFjrd623RhQAAAHs"]
[Thu Sep 17 15:45:15.727434 2026] [security2:error] [pid 60716:tid 60990] [client 34.166.129.237:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfa8Psx0SVFjrd623RkgAAAGA"]
[Thu Sep 17 15:45:15.785608 2026] [security2:error] [pid 60716:tid 60989] [client 167.172.45.115:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ftlbllc.net"] [uri "/~ftlbllcn/index.php"] [unique_id "aqxfaMPsx0SVFjrd623RLQAAXxo"], referer: http://www.ftlbllc.net/new/
[Thu Sep 17 15:45:15.965497 2026] [security2:error] [pid 60716:tid 60825] [remote 103.190.47.28:43136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.47.190.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "legalpracticeinbrief.sportsgirlkat.com"] [uri "/xmlrpc.php"] [unique_id "aqxfa8Psx0SVFjrd623RmgAART8"]
[Thu Sep 17 15:45:16.070163 2026] [security2:error] [pid 60716:tid 60962] [client 169.58.197.253:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxfbMPsx0SVFjrd623RogAAAEQ"], referer: binance.com
[Thu Sep 17 15:45:16.410785 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.129.237:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxfbMPsx0SVFjrd623RrQAAAF0"]
[Thu Sep 17 15:45:16.519115 2026] [security2:error] [pid 60716:tid 60900] [client 169.58.197.251:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxfbMPsx0SVFjrd623RtAAAAAg"], referer: binance.com
[Thu Sep 17 15:45:16.570624 2026] [security2:error] [pid 60716:tid 60926] [client 167.172.45.115:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ftlbllc.net"] [uri "/~ftlbllcn/index.php"] [unique_id "aqxfbMPsx0SVFjrd623RsAAAISY"], referer: http://www.ftlbllc.net/wordpress/
[Thu Sep 17 15:45:16.573364 2026] [security2:error] [pid 60716:tid 60925] [client 23.245.214.184:57045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfbMPsx0SVFjrd623RrgAAIHE"], referer: https://www.google.com/
[Thu Sep 17 15:45:16.578822 2026] [security2:error] [pid 60716:tid 60794] [remote 103.190.47.28:43148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.47.190.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "legalpracticeinbrief.sportsgirlkat.com"] [uri "/wp-login.php"] [unique_id "aqxfbMPsx0SVFjrd623RtQAAGCA"]
[Thu Sep 17 15:45:16.589218 2026] [security2:error] [pid 60716:tid 60784] [remote 103.190.47.28:43122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.47.190.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.legalpracticeinbrief.sportsgirlkat.com"] [uri "/xmlrpc.php"] [unique_id "aqxfbMPsx0SVFjrd623RtgAABhc"]
[Thu Sep 17 15:45:16.705153 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.55.182:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfbMPsx0SVFjrd623RuwAAAAA"]
[Thu Sep 17 15:45:16.869584 2026] [security2:error] [pid 60716:tid 60969] [client 103.61.184.148:59503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfbMPsx0SVFjrd623RwgAAAEs"]
[Thu Sep 17 15:45:16.869704 2026] [security2:error] [pid 60716:tid 60969] [client 103.61.184.148:59503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfbMPsx0SVFjrd623RwgAAAEs"]
[Thu Sep 17 15:45:16.916804 2026] [security2:error] [pid 60716:tid 61017] [client 3.19.142.206:55563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfbMPsx0SVFjrd623RxAAAAHs"]
[Thu Sep 17 15:45:16.951563 2026] [security2:error] [pid 60716:tid 60991] [client 167.172.45.115:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ftlbllc.net"] [uri "/~ftlbllcn/index.php"] [unique_id "aqxfbMPsx0SVFjrd623RwwAAYV4"], referer: http://www.ftlbllc.net/blog/
[Thu Sep 17 15:45:17.063983 2026] [security2:error] [pid 60716:tid 60953] [client 34.46.138.166:12528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxfacPsx0SVFjrd623RUwAAOz4"]
[Thu Sep 17 15:45:17.077001 2026] [autoindex:error] [pid 60716:tid 60903] [client 169.58.197.251:56661] AH01276: Cannot serve directory /home4/sharlotb/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:45:17.106452 2026] [security2:error] [pid 60716:tid 60993] [client 34.166.129.237:57980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/phpinfo.php.old"] [unique_id "aqxfbcPsx0SVFjrd623RzgAAAGM"]
[Thu Sep 17 15:45:17.189622 2026] [security2:error] [pid 60716:tid 60902] [client 34.46.138.166:12528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxfbcPsx0SVFjrd623RzQAACkc"]
[Thu Sep 17 15:45:17.250937 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.55.182:36314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxfbcPsx0SVFjrd623R1AAAAAQ"]
[Thu Sep 17 15:45:17.322619 2026] [security2:error] [pid 60716:tid 60974] [client 167.172.45.115:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ftlbllc.net"] [uri "/~ftlbllcn/index.php"] [unique_id "aqxfbcPsx0SVFjrd623R1QAAUCs"], referer: http://www.ftlbllc.net/backup/
[Thu Sep 17 15:45:17.476877 2026] [security2:error] [pid 60716:tid 60958] [client 34.46.138.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sharedtablepk.org"] [uri "/index.php"] [unique_id "aqxfbcPsx0SVFjrd623R2AAAAEA"]
[Thu Sep 17 15:45:17.509271 2026] [security2:error] [pid 60716:tid 60906] [client 23.245.214.184:56019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfbcPsx0SVFjrd623R2QAADk4"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818091055&hideanons=1&hidemyself=1&limit=500&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:45:17.703584 2026] [security2:error] [pid 60716:tid 60910] [client 167.172.45.115:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ftlbllc.net"] [uri "/~ftlbllcn/index.php"] [unique_id "aqxfbcPsx0SVFjrd623R5gAAEh4"], referer: http://www.ftlbllc.net/old/
[Thu Sep 17 15:45:17.763726 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.55.182:36322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfbcPsx0SVFjrd623R7wAAABw"]
[Thu Sep 17 15:45:17.807933 2026] [security2:error] [pid 60716:tid 60933] [client 34.166.129.237:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/phpinfo.php~"] [unique_id "aqxfbcPsx0SVFjrd623R8AAAACc"]
[Thu Sep 17 15:45:17.917223 2026] [authz_core:error] [pid 60716:tid 60936] [client 4.240.114.86:60056] AH01630: client denied by server configuration: /home1/jwdnycco/public_html/wp-includes/error_log, referer: binance.com
[Thu Sep 17 15:45:17.947377 2026] [security2:error] [pid 60716:tid 60961] [client 14.96.156.146:59603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfbcPsx0SVFjrd623R8wAAAEM"]
[Thu Sep 17 15:45:17.947450 2026] [security2:error] [pid 60716:tid 60961] [client 14.96.156.146:59603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfbcPsx0SVFjrd623R8wAAAEM"]
[Thu Sep 17 15:45:18.094479 2026] [security2:error] [pid 60716:tid 60892] [client 167.172.45.115:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ftlbllc.net"] [uri "/~ftlbllcn/index.php"] [unique_id "aqxfbsPsx0SVFjrd623R9wAAADs"], referer: http://www.ftlbllc.net/wp/
[Thu Sep 17 15:45:18.192266 2026] [security2:error] [pid 60716:tid 60942] [client 148.227.75.216:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfbsPsx0SVFjrd623R_AAAADA"]
[Thu Sep 17 15:45:18.194844 2026] [security2:error] [pid 60716:tid 60942] [client 148.227.75.216:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfbsPsx0SVFjrd623R_AAAADA"]
[Thu Sep 17 15:45:18.278467 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.55.182:36326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfbsPsx0SVFjrd623R_wAAAGs"]
[Thu Sep 17 15:45:18.502425 2026] [security2:error] [pid 60716:tid 60939] [client 34.166.129.237:57994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/info.php.bak"] [unique_id "aqxfbsPsx0SVFjrd623SAQAAAC0"]
[Thu Sep 17 15:45:18.856233 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.55.182:36330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfbsPsx0SVFjrd623SCgAAAAw"]
[Thu Sep 17 15:45:19.168584 2026] [security2:error] [pid 60716:tid 61014] [client 34.166.34.14:39464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.slimmtech.com"] [uri "/"] [unique_id "aqxfb8Psx0SVFjrd623SFgAAAHg"]
[Thu Sep 17 15:45:19.184271 2026] [security2:error] [pid 60716:tid 60967] [client 34.166.129.237:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/phpinfo.php.save"] [unique_id "aqxfb8Psx0SVFjrd623SGgAAAEk"]
[Thu Sep 17 15:45:19.396269 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.55.182:36336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfb8Psx0SVFjrd623SHwAAADg"]
[Thu Sep 17 15:45:19.698618 2026] [security2:error] [pid 60716:tid 60911] [client 143.105.152.240:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfb8Psx0SVFjrd623SKQAAABM"]
[Thu Sep 17 15:45:19.698779 2026] [security2:error] [pid 60716:tid 60911] [client 143.105.152.240:6382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfb8Psx0SVFjrd623SKQAAABM"]
[Thu Sep 17 15:45:19.703234 2026] [security2:error] [pid 60716:tid 60987] [client 177.44.133.72:54046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfb8Psx0SVFjrd623SKgAAAF0"]
[Thu Sep 17 15:45:19.703338 2026] [security2:error] [pid 60716:tid 60987] [client 177.44.133.72:54046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfb8Psx0SVFjrd623SKgAAAF0"]
[Thu Sep 17 15:45:19.850943 2026] [security2:error] [pid 60716:tid 60916] [client 34.166.34.14:39468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.slimmtech.com"] [uri "/"] [unique_id "aqxfb8Psx0SVFjrd623SLAAAABg"]
[Thu Sep 17 15:45:19.864660 2026] [security2:error] [pid 60716:tid 60999] [client 34.166.129.237:58018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxfb8Psx0SVFjrd623SLgAAAGk"]
[Thu Sep 17 15:45:19.902394 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.55.182:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxfb8Psx0SVFjrd623SLwAAAFg"]
[Thu Sep 17 15:45:20.453156 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.55.182:36346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxfcMPsx0SVFjrd623SOgAAADU"]
[Thu Sep 17 15:45:20.533399 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.34.14:39480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.slimmtech.com"] [uri "/"] [unique_id "aqxfcMPsx0SVFjrd623SPwAAACQ"]
[Thu Sep 17 15:45:20.549778 2026] [security2:error] [pid 60716:tid 61020] [client 34.166.129.237:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxfcMPsx0SVFjrd623SQQAAAH4"]
[Thu Sep 17 15:45:20.851466 2026] [security2:error] [pid 60716:tid 60928] [client 134.185.85.61:52572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "dfdub.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxfcMPsx0SVFjrd623SSwAAACM"]
[Thu Sep 17 15:45:20.957329 2026] [security2:error] [pid 60716:tid 60958] [client 34.154.55.182:36356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxfcMPsx0SVFjrd623STAAAAEA"]
[Thu Sep 17 15:45:21.230734 2026] [security2:error] [pid 60716:tid 60920] [client 134.185.85.61:64694] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "dfdub.com"] [uri "/media/system/js/core.js"] [unique_id "aqxfccPsx0SVFjrd623SVwAAABw"]
[Thu Sep 17 15:45:21.231122 2026] [security2:error] [pid 60716:tid 60914] [client 169.58.197.253:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/wp-login.php"] [unique_id "aqxfccPsx0SVFjrd623SVAAAABY"], referer: binance.com
[Thu Sep 17 15:45:21.232401 2026] [security2:error] [pid 60716:tid 60909] [client 34.166.129.237:58044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxfccPsx0SVFjrd623SWAAAABE"]
[Thu Sep 17 15:45:21.419595 2026] [security2:error] [pid 60716:tid 60954] [client 3.19.142.206:56946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxfccPsx0SVFjrd623SWQAAADw"]
[Thu Sep 17 15:45:21.447519 2026] [security2:error] [pid 60716:tid 60988] [client 34.166.34.14:39484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcontacts.slimmtech.com"] [uri "/"] [unique_id "aqxfccPsx0SVFjrd623SXgAAAF4"]
[Thu Sep 17 15:45:21.462814 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.55.182:36362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxfccPsx0SVFjrd623SXwAAACc"]
[Thu Sep 17 15:45:21.711771 2026] [security2:error] [pid 60716:tid 60950] [client 79.116.89.151:56416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfccPsx0SVFjrd623SaAAAADg"]
[Thu Sep 17 15:45:21.711906 2026] [security2:error] [pid 60716:tid 60950] [client 79.116.89.151:56416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfccPsx0SVFjrd623SaAAAADg"]
[Thu Sep 17 15:45:21.941197 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.129.237:58046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxfccPsx0SVFjrd623SagAAABM"]
[Thu Sep 17 15:45:22.010831 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.55.182:36374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxfcsPsx0SVFjrd623SbAAAABg"]
[Thu Sep 17 15:45:22.487678 2026] [security2:error] [pid 60716:tid 60892] [client 136.158.61.34:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfcsPsx0SVFjrd623SdwAAAAA"]
[Thu Sep 17 15:45:22.487831 2026] [security2:error] [pid 60716:tid 60892] [client 136.158.61.34:57081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfcsPsx0SVFjrd623SdwAAAAA"]
[Thu Sep 17 15:45:22.514148 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.55.182:36382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxfcsPsx0SVFjrd623SeAAAACU"]
[Thu Sep 17 15:45:22.516895 2026] [fcgid:warn] [pid 60716:tid 60929] (70014)End of file found: [client 118.194.235.16:33134] mod_fcgid: can't get data from http client
[Thu Sep 17 15:45:22.631740 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.129.237:48248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxfcsPsx0SVFjrd623SgQAAACA"]
[Thu Sep 17 15:45:23.007523 2026] [security2:error] [pid 60716:tid 60970] [client 34.154.55.182:36392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxfc8Psx0SVFjrd623SkAAAAEw"]
[Thu Sep 17 15:45:23.166680 2026] [security2:error] [pid 60716:tid 60975] [client 138.246.253.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.casualchessclub.org"] [uri "/index.php"] [unique_id "aqxfbcPsx0SVFjrd623R5QAAAFE"]
[Thu Sep 17 15:45:23.323061 2026] [security2:error] [pid 60716:tid 61014] [client 34.166.129.237:48252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/www/phpinfo.php"] [unique_id "aqxfc8Psx0SVFjrd623SnAAAAHg"]
[Thu Sep 17 15:45:23.518180 2026] [security2:error] [pid 60716:tid 60899] [client 4.240.114.86:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "aqxfc8Psx0SVFjrd623SoQAAAAc"], referer: binance.com
[Thu Sep 17 15:45:23.521975 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.55.182:36402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxfc8Psx0SVFjrd623SogAAAHQ"]
[Thu Sep 17 15:45:23.940473 2026] [security2:error] [pid 60716:tid 60905] [client 3.19.142.206:57864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfc8Psx0SVFjrd623StQAAAA0"]
[Thu Sep 17 15:45:23.940529 2026] [security2:error] [pid 60716:tid 60905] [client 3.19.142.206:57864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfc8Psx0SVFjrd623StQAAAA0"]
[Thu Sep 17 15:45:23.956544 2026] [security2:error] [pid 60716:tid 60953] [client 3.19.142.206:57887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfc8Psx0SVFjrd623StwAAADs"]
[Thu Sep 17 15:45:23.956588 2026] [security2:error] [pid 60716:tid 60953] [client 3.19.142.206:57887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfc8Psx0SVFjrd623StwAAADs"]
[Thu Sep 17 15:45:23.957243 2026] [security2:error] [pid 60716:tid 60908] [client 3.19.142.206:57883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfc8Psx0SVFjrd623StgAAABA"]
[Thu Sep 17 15:45:23.957267 2026] [security2:error] [pid 60716:tid 60908] [client 3.19.142.206:57883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfc8Psx0SVFjrd623StgAAABA"]
[Thu Sep 17 15:45:24.001542 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.129.237:48254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfdMPsx0SVFjrd623SuQAAAH0"]
[Thu Sep 17 15:45:24.023090 2026] [security2:error] [pid 60716:tid 60931] [client 3.19.142.206:57883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfdMPsx0SVFjrd623SugAAACU"]
[Thu Sep 17 15:45:24.023143 2026] [security2:error] [pid 60716:tid 60931] [client 3.19.142.206:57883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/new/xmlrpc.php"] [unique_id "aqxfdMPsx0SVFjrd623SugAAACU"]
[Thu Sep 17 15:45:24.029263 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.55.182:48574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxfdMPsx0SVFjrd623SuwAAAGE"]
[Thu Sep 17 15:45:24.526975 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.55.182:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxfdMPsx0SVFjrd623SxwAAAHU"]
[Thu Sep 17 15:45:24.693199 2026] [security2:error] [pid 60716:tid 60917] [client 34.166.129.237:48266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfdMPsx0SVFjrd623SzAAAABk"]
[Thu Sep 17 15:45:24.998016 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.55.182:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxfdMPsx0SVFjrd623S1gAAAFE"]
[Thu Sep 17 15:45:25.059967 2026] [security2:error] [pid 60716:tid 60945] [client 169.58.197.253:63247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxfdcPsx0SVFjrd623S2QAAADM"], referer: binance.com
[Thu Sep 17 15:45:25.264558 2026] [fcgid:warn] [pid 60716:tid 61010] (70014)End of file found: [client 118.194.235.16:32990] mod_fcgid: can't get data from http client
[Thu Sep 17 15:45:25.376444 2026] [security2:error] [pid 60716:tid 60976] [client 34.166.129.237:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/site/phpinfo.php"] [unique_id "aqxfdcPsx0SVFjrd623S4QAAAFI"]
[Thu Sep 17 15:45:25.507192 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.55.182:48606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfdcPsx0SVFjrd623S5wAAAD0"]
[Thu Sep 17 15:45:25.997029 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.55.182:48612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfdcPsx0SVFjrd623S_AAAAGY"]
[Thu Sep 17 15:45:26.056254 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.129.237:48290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxfdsPsx0SVFjrd623S_QAAAA0"]
[Thu Sep 17 15:45:26.151440 2026] [security2:error] [pid 60716:tid 61020] [client 43.173.177.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxfdcPsx0SVFjrd623S-wAAAH4"]
[Thu Sep 17 15:45:26.491533 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.55.182:48626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxfdsPsx0SVFjrd623TLAAAAEU"]
[Thu Sep 17 15:45:26.562185 2026] [security2:error] [pid 60716:tid 60899] [client 3.19.142.206:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxfdsPsx0SVFjrd623TMgAAAAc"]
[Thu Sep 17 15:45:26.739767 2026] [security2:error] [pid 60716:tid 60962] [client 34.166.129.237:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfdsPsx0SVFjrd623TQgAAAEQ"]
[Thu Sep 17 15:45:26.976813 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.55.182:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxfdsPsx0SVFjrd623TVgAAAGk"]
[Thu Sep 17 15:45:27.094722 2026] [authz_core:error] [pid 60716:tid 60980] [client 129.212.220.28:60890] AH01630: client denied by server configuration: /home4/chrisxv2/public_html/error_log
[Thu Sep 17 15:45:27.429848 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.129.237:48314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfd8Psx0SVFjrd623TZgAAAHM"]
[Thu Sep 17 15:45:27.453992 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.55.182:48636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfd8Psx0SVFjrd623TZwAAAC0"]
[Thu Sep 17 15:45:27.531483 2026] [security2:error] [pid 60716:tid 60977] [client 4.240.114.86:64944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/abilities.php"] [unique_id "aqxfd8Psx0SVFjrd623TaQAAAFM"], referer: binance.com
[Thu Sep 17 15:45:27.572557 2026] [security2:error] [pid 60716:tid 60950] [client 103.61.184.148:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfd8Psx0SVFjrd623TbgAAADg"]
[Thu Sep 17 15:45:27.573204 2026] [security2:error] [pid 60716:tid 60950] [client 103.61.184.148:60068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfd8Psx0SVFjrd623TbgAAADg"]
[Thu Sep 17 15:45:27.959642 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.55.182:48650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfd8Psx0SVFjrd623TgAAAABE"]
[Thu Sep 17 15:45:28.119177 2026] [security2:error] [pid 60716:tid 61015] [client 34.166.129.237:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/core/phpinfo.php"] [unique_id "aqxfeMPsx0SVFjrd623ThwAAAHk"]
[Thu Sep 17 15:45:28.314160 2026] [security2:error] [pid 60716:tid 60984] [client 34.13.134.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.brownsdailydose.com"] [uri "/index.php"] [unique_id "aqxfdsPsx0SVFjrd623TLwAAAFo"], referer: http://www.brownsdailydose.com/robots.txt
[Thu Sep 17 15:45:28.370638 2026] [security2:error] [pid 60716:tid 61000] [client 95.32.221.153:1049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfeMPsx0SVFjrd623TjwAAah4"]
[Thu Sep 17 15:45:28.409651 2026] [security2:error] [pid 60716:tid 60898] [client 169.58.197.251:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxfeMPsx0SVFjrd623TlgAAAAY"], referer: binance.com
[Thu Sep 17 15:45:28.482315 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.55.182:48664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxfeMPsx0SVFjrd623TmQAAACI"]
[Thu Sep 17 15:45:28.496172 2026] [security2:error] [pid 60716:tid 61021] [client 43.173.181.86:48738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/items/M414653933"] [unique_id "aqxfeMPsx0SVFjrd623TmgAAAH8"]
[Thu Sep 17 15:45:28.731259 2026] [security2:error] [pid 60716:tid 60966] [client 14.96.156.146:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfeMPsx0SVFjrd623TsAAAAEg"]
[Thu Sep 17 15:45:28.731410 2026] [security2:error] [pid 60716:tid 60966] [client 14.96.156.146:60276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfeMPsx0SVFjrd623TsAAAAEg"]
[Thu Sep 17 15:45:28.752158 2026] [security2:error] [pid 60716:tid 60919] [client 134.185.85.61:52452] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "aellaapartments.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "aqxfeMPsx0SVFjrd623TsgAAABs"]
[Thu Sep 17 15:45:28.805401 2026] [security2:error] [pid 60716:tid 60991] [client 34.166.129.237:48336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.129.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.charlesgiraudet.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxfeMPsx0SVFjrd623TtgAAAGE"]
[Thu Sep 17 15:45:28.923235 2026] [security2:error] [pid 60716:tid 60971] [client 148.227.75.216:2048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfeMPsx0SVFjrd623TvwAAAE0"]
[Thu Sep 17 15:45:28.923379 2026] [security2:error] [pid 60716:tid 60971] [client 148.227.75.216:2048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfeMPsx0SVFjrd623TvwAAAE0"]
[Thu Sep 17 15:45:28.948853 2026] [security2:error] [pid 60716:tid 60907] [client 186.19.123.83:51758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.enolastable.com"] [uri "/index.php"] [unique_id "aqxfeMPsx0SVFjrd623TugAADzk"], referer: https://www.enolastable.com/2016/11/08/it-cost-me-93-95-to-vote/
[Thu Sep 17 15:45:29.005722 2026] [security2:error] [pid 60716:tid 60978] [client 34.154.55.182:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ske.hfz.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxfecPsx0SVFjrd623TwQAAAFQ"]
[Thu Sep 17 15:45:29.109140 2026] [security2:error] [pid 60716:tid 60811] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "aqxfecPsx0SVFjrd623TyAAAJTE"]
[Thu Sep 17 15:45:29.129758 2026] [security2:error] [pid 60716:tid 61010] [client 134.185.85.61:60310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "aellaapartments.com"] [uri "/media/system/js/core.js"] [unique_id "aqxfecPsx0SVFjrd623TygAAAHQ"]
[Thu Sep 17 15:45:29.213236 2026] [security2:error] [pid 60716:tid 60951] [client 47.128.54.3:30282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/robots.txt"] [unique_id "aqxfecPsx0SVFjrd623T0wAAADk"]
[Thu Sep 17 15:45:29.285112 2026] [security2:error] [pid 60716:tid 60975] [client 52.167.144.205:29363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "daprayer.com"] [uri "/index.php"] [unique_id "aqxfd8Psx0SVFjrd623TewAAUU8"]
[Thu Sep 17 15:45:29.384396 2026] [security2:error] [pid 60716:tid 60896] [client 44.239.144.77:49743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worthtranslations.com"] [uri "/index.php"] [unique_id "aqxfd8Psx0SVFjrd623TagAAAAQ"], referer: http://worthtranslations.com/2025
[Thu Sep 17 15:45:29.444851 2026] [proxy:error] [pid 60716:tid 60830] (103)Software caused connection abort: [remote 35.234.44.14:0] AH01095: prefetch request body failed to 127.0.0.1:2082 (127.0.0.1) from 172.69.221.133 (), referer: https://cpanel.dranzarut.com
[Thu Sep 17 15:45:29.446896 2026] [proxy:error] [pid 60716:tid 60830] (103)Software caused connection abort: [remote 35.234.44.14:0] AH01095: prefetch request body failed to 127.0.0.1:2082 (127.0.0.1) from 172.69.221.133 (), referer: https://cpanel.dranzarut.com
[Thu Sep 17 15:45:29.559695 2026] [security2:error] [pid 60716:tid 60970] [client 181.126.168.51:33646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxfecPsx0SVFjrd623T3AAAAEw"], referer: https://bigsisterteams.com/
[Thu Sep 17 15:45:29.602649 2026] [security2:error] [pid 60716:tid 60797] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "aqxfecPsx0SVFjrd623T8AAAQCM"]
[Thu Sep 17 15:45:29.678685 2026] [autoindex:error] [pid 60716:tid 60984] [client 4.240.114.86:49370] AH01276: Cannot serve directory /home1/mybelov5/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:45:29.845698 2026] [security2:error] [pid 60716:tid 60966] [client 162.241.226.11:22480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxfecPsx0SVFjrd623T-QAAAEg"]
[Thu Sep 17 15:45:30.038327 2026] [security2:error] [pid 60716:tid 60776] [remote 35.234.44.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.dranzarut.com"] [uri "/static//app/.env"] [unique_id "aqxfesPsx0SVFjrd623UDAAAOxA"]
[Thu Sep 17 15:45:30.050343 2026] [security2:error] [pid 60716:tid 60944] [client 162.241.226.11:22482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigsisterteams.com"] [uri "/index.php"] [unique_id "aqxfecPsx0SVFjrd623UAwAAADI"]
[Thu Sep 17 15:45:30.277102 2026] [security2:error] [pid 60716:tid 60979] [client 143.105.152.240:39647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfesPsx0SVFjrd623UIwAAAFU"]
[Thu Sep 17 15:45:30.285191 2026] [security2:error] [pid 60716:tid 60979] [client 143.105.152.240:39647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfesPsx0SVFjrd623UIwAAAFU"]
[Thu Sep 17 15:45:30.491111 2026] [security2:error] [pid 60716:tid 60949] [client 177.44.133.72:54729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfesPsx0SVFjrd623UKAAAADc"]
[Thu Sep 17 15:45:30.491201 2026] [security2:error] [pid 60716:tid 60949] [client 177.44.133.72:54729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfesPsx0SVFjrd623UKAAAADc"]
[Thu Sep 17 15:45:30.561855 2026] [security2:error] [pid 60716:tid 60812] [remote 216.73.217.142:48294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxfesPsx0SVFjrd623ULAAAczI"]
[Thu Sep 17 15:45:31.252031 2026] [security2:error] [pid 60716:tid 60981] [client 4.240.114.86:50224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/ai-client.php"] [unique_id "aqxfe8Psx0SVFjrd623UcgAAAFc"], referer: binance.com
[Thu Sep 17 15:45:32.446122 2026] [security2:error] [pid 60716:tid 60937] [client 79.116.89.151:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxffMPsx0SVFjrd623UsAAAACs"]
[Thu Sep 17 15:45:32.446222 2026] [security2:error] [pid 60716:tid 60937] [client 79.116.89.151:57047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxffMPsx0SVFjrd623UsAAAACs"]
[Thu Sep 17 15:45:32.729727 2026] [security2:error] [pid 60716:tid 60923] [client 3.19.142.206:60366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxffMPsx0SVFjrd623UswAAAB4"]
[Thu Sep 17 15:45:32.912769 2026] [security2:error] [pid 60716:tid 60819] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffMPsx0SVFjrd623UzQAAIjk"]
[Thu Sep 17 15:45:33.073231 2026] [security2:error] [pid 60716:tid 60765] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffcPsx0SVFjrd623U1wAAZQY"]
[Thu Sep 17 15:45:33.075410 2026] [security2:error] [pid 60716:tid 60855] [remote 35.234.44.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffcPsx0SVFjrd623U2gAATl0"]
[Thu Sep 17 15:45:33.235657 2026] [security2:error] [pid 60716:tid 60811] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffcPsx0SVFjrd623U6QAATjE"]
[Thu Sep 17 15:45:33.397324 2026] [security2:error] [pid 60716:tid 60832] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffcPsx0SVFjrd623U9QAAJEY"]
[Thu Sep 17 15:45:33.420047 2026] [security2:error] [pid 60716:tid 60949] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxffcPsx0SVFjrd623U1QAAADc"]
[Thu Sep 17 15:45:33.558523 2026] [security2:error] [pid 60716:tid 60776] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffcPsx0SVFjrd623U-AAADhA"]
[Thu Sep 17 15:45:33.722927 2026] [security2:error] [pid 60716:tid 60828] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffcPsx0SVFjrd623VBgAAMEI"]
[Thu Sep 17 15:45:33.771037 2026] [security2:error] [pid 60716:tid 60900] [client 169.58.197.253:63823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxffcPsx0SVFjrd623VCQAAAAg"], referer: binance.com
[Thu Sep 17 15:45:33.795816 2026] [security2:error] [pid 60716:tid 60851] [remote 45.157.54.43:47603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nashobamarketing.com"] [uri "/xmlrpc.php"] [unique_id "aqxffcPsx0SVFjrd623VCwAAH1k"]
[Thu Sep 17 15:45:33.795952 2026] [security2:error] [pid 60716:tid 60924] [client 45.157.54.43:47603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nashobamarketing.com"] [uri "/xmlrpc.php"] [unique_id "aqxffcPsx0SVFjrd623VCwAAH1k"]
[Thu Sep 17 15:45:33.884964 2026] [security2:error] [pid 60716:tid 60812] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffcPsx0SVFjrd623VEAAALzI"]
[Thu Sep 17 15:45:34.047830 2026] [security2:error] [pid 60716:tid 60859] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffsPsx0SVFjrd623VFwAARGE"]
[Thu Sep 17 15:45:34.235654 2026] [security2:error] [pid 60716:tid 60826] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffsPsx0SVFjrd623VJgAAPkA"]
[Thu Sep 17 15:45:34.242622 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.23.235:40744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxffsPsx0SVFjrd623VIQAAAA0"]
[Thu Sep 17 15:45:34.313049 2026] [security2:error] [pid 60716:tid 60876] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqxffsPsx0SVFjrd623VLAAAC3I"]
[Thu Sep 17 15:45:34.516414 2026] [security2:error] [pid 60716:tid 60919] [client 4.240.114.86:51758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "aqxffsPsx0SVFjrd623VMgAAABs"], referer: binance.com
[Thu Sep 17 15:45:34.801480 2026] [security2:error] [pid 60716:tid 60871] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/api/w/default/jobs_u/get_log_file/../../../../proc/self/environ"] [unique_id "aqxffsPsx0SVFjrd623VQQAAJ20"]
[Thu Sep 17 15:45:34.821116 2026] [security2:error] [pid 60716:tid 60909] [client 136.158.61.34:58273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VQgAAABE"]
[Thu Sep 17 15:45:34.821261 2026] [security2:error] [pid 60716:tid 60909] [client 136.158.61.34:58273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VQgAAABE"]
[Thu Sep 17 15:45:34.926718 2026] [security2:error] [pid 60716:tid 60911] [client 34.166.23.235:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/info.php"] [unique_id "aqxffsPsx0SVFjrd623VRQAAABM"]
[Thu Sep 17 15:45:34.981210 2026] [security2:error] [pid 60716:tid 60918] [client 3.19.142.206:61433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VSQAAABo"]
[Thu Sep 17 15:45:34.981257 2026] [security2:error] [pid 60716:tid 60918] [client 3.19.142.206:61433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VSQAAABo"]
[Thu Sep 17 15:45:34.988973 2026] [security2:error] [pid 60716:tid 60958] [client 3.19.142.206:61425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VSAAAAEA"]
[Thu Sep 17 15:45:34.989000 2026] [security2:error] [pid 60716:tid 60958] [client 3.19.142.206:61425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VSAAAAEA"]
[Thu Sep 17 15:45:34.999557 2026] [security2:error] [pid 60716:tid 61010] [client 3.19.142.206:61437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VSwAAAHQ"]
[Thu Sep 17 15:45:34.999583 2026] [security2:error] [pid 60716:tid 61010] [client 3.19.142.206:61437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxffsPsx0SVFjrd623VSwAAAHQ"]
[Thu Sep 17 15:45:35.149121 2026] [security2:error] [pid 60716:tid 60899] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/.env"] [unique_id "aqxff8Psx0SVFjrd623VWQAAAAc"]
[Thu Sep 17 15:45:35.216757 2026] [security2:error] [pid 60716:tid 60917] [client 3.19.142.206:61425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxff8Psx0SVFjrd623VXwAAABk"]
[Thu Sep 17 15:45:35.216794 2026] [security2:error] [pid 60716:tid 60917] [client 3.19.142.206:61425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/blog/xmlrpc.php"] [unique_id "aqxff8Psx0SVFjrd623VXwAAABk"]
[Thu Sep 17 15:45:35.282212 2026] [security2:error] [pid 60716:tid 60818] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ"] [unique_id "aqxff8Psx0SVFjrd623VYwAAKDg"]
[Thu Sep 17 15:45:35.282313 2026] [security2:error] [pid 60716:tid 60823] [remote 35.234.44.14:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.dranzarut.com"] [uri "/api/w/default/jobs_u/get_log_file/../../../../proc/self/environ"] [unique_id "aqxff8Psx0SVFjrd623VYgAAJD0"]
[Thu Sep 17 15:45:35.358245 2026] [fcgid:warn] [pid 60716:tid 60944] (70014)End of file found: [client 152.32.183.236:41598] mod_fcgid: can't get data from http client
[Thu Sep 17 15:45:35.616086 2026] [security2:error] [pid 60716:tid 60992] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxff8Psx0SVFjrd623VaQAAAGI"]
[Thu Sep 17 15:45:35.625641 2026] [security2:error] [pid 60716:tid 60902] [client 34.166.23.235:55044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/php.php"] [unique_id "aqxff8Psx0SVFjrd623VcgAAAAo"]
[Thu Sep 17 15:45:36.094561 2026] [security2:error] [pid 60716:tid 60935] [client 34.38.254.144:45244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.alanpeckolick.com"] [uri "/"] [unique_id "aqxfgMPsx0SVFjrd623VgwAAACk"]
[Thu Sep 17 15:45:36.220825 2026] [security2:error] [pid 60716:tid 60960] [client 34.34.177.236:40920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1462"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.alanpeckolick.com"] [uri "/"] [unique_id "aqxfgMPsx0SVFjrd623ViAAAAEI"]
[Thu Sep 17 15:45:36.322074 2026] [security2:error] [pid 60716:tid 61007] [client 34.166.23.235:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/i.php"] [unique_id "aqxfgMPsx0SVFjrd623ViwAAAHE"]
[Thu Sep 17 15:45:36.664615 2026] [security2:error] [pid 60716:tid 60985] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfgMPsx0SVFjrd623VjwAAAFs"]
[Thu Sep 17 15:45:36.798967 2026] [security2:error] [pid 60716:tid 60995] [client 3.19.142.206:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfgMPsx0SVFjrd623VowAAAGU"]
[Thu Sep 17 15:45:36.848906 2026] [security2:error] [pid 60716:tid 60992] [client 169.58.197.251:58571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxfgMPsx0SVFjrd623VpgAAAGI"], referer: binance.com
[Thu Sep 17 15:45:37.007353 2026] [security2:error] [pid 60716:tid 60986] [client 34.166.23.235:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxfgcPsx0SVFjrd623VqgAAAFw"]
[Thu Sep 17 15:45:37.168970 2026] [security2:error] [pid 60716:tid 60888] [remote 111.225.149.175:38804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.npae.net"] [uri "/neaf-2026/"] [unique_id "aqxfgcPsx0SVFjrd623VtQAATn4"]
[Thu Sep 17 15:45:37.600062 2026] [security2:error] [pid 60716:tid 60935] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfgcPsx0SVFjrd623VvAAAACk"]
[Thu Sep 17 15:45:37.699073 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.23.235:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxfgcPsx0SVFjrd623VxAAAAF0"]
[Thu Sep 17 15:45:38.197561 2026] [security2:error] [pid 60716:tid 61011] [client 103.61.184.148:60634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfgsPsx0SVFjrd623V1wAAAHU"]
[Thu Sep 17 15:45:38.197636 2026] [security2:error] [pid 60716:tid 61011] [client 103.61.184.148:60634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfgsPsx0SVFjrd623V1wAAAHU"]
[Thu Sep 17 15:45:38.375722 2026] [security2:error] [pid 60716:tid 60947] [client 34.166.23.235:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/test.php"] [unique_id "aqxfgsPsx0SVFjrd623V3wAAADU"]
[Thu Sep 17 15:45:38.449036 2026] [security2:error] [pid 60716:tid 60993] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfgsPsx0SVFjrd623V2gAAAGM"]
[Thu Sep 17 15:45:38.565851 2026] [security2:error] [pid 60716:tid 60794] [remote 35.234.44.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.dranzarut.com"] [uri "/js../.env"] [unique_id "aqxfgsPsx0SVFjrd623V5AAAJSA"]
[Thu Sep 17 15:45:38.793108 2026] [security2:error] [pid 60716:tid 60946] [client 107.223.89.111:55652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfgsPsx0SVFjrd623V7AAANEE"]
[Thu Sep 17 15:45:39.086372 2026] [security2:error] [pid 60716:tid 60914] [client 4.240.114.86:54189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/block-editor.php"] [unique_id "aqxfg8Psx0SVFjrd623V-wAAABY"], referer: binance.com
[Thu Sep 17 15:45:39.292098 2026] [security2:error] [pid 60716:tid 60935] [client 34.166.23.235:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/p.php"] [unique_id "aqxfg8Psx0SVFjrd623WAgAAACk"]
[Thu Sep 17 15:45:39.306408 2026] [security2:error] [pid 60716:tid 60906] [client 14.96.156.146:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfg8Psx0SVFjrd623WBAAAAA4"]
[Thu Sep 17 15:45:39.306518 2026] [security2:error] [pid 60716:tid 60906] [client 14.96.156.146:60931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfg8Psx0SVFjrd623WBAAAAA4"]
[Thu Sep 17 15:45:39.587298 2026] [security2:error] [pid 60716:tid 60960] [client 148.227.75.216:48104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfg8Psx0SVFjrd623WEAAAAEI"]
[Thu Sep 17 15:45:39.587413 2026] [security2:error] [pid 60716:tid 60960] [client 148.227.75.216:48104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfg8Psx0SVFjrd623WEAAAAEI"]
[Thu Sep 17 15:45:39.626635 2026] [security2:error] [pid 60716:tid 60915] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfg8Psx0SVFjrd623WDAAAABc"]
[Thu Sep 17 15:45:39.973679 2026] [security2:error] [pid 60716:tid 60896] [client 34.166.23.235:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxfg8Psx0SVFjrd623WGgAAAAQ"]
[Thu Sep 17 15:45:40.154416 2026] [security2:error] [pid 60716:tid 61008] [client 107.223.89.111:55659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfhMPsx0SVFjrd623WHAAAcg4"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818000146&hideliu=1&hidemyself=1&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:45:40.527706 2026] [security2:error] [pid 60716:tid 60929] [client 74.7.244.25:48610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcalendars.sarahsdayoff.com"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxfhMPsx0SVFjrd623WJwAAACQ"]
[Thu Sep 17 15:45:40.652542 2026] [security2:error] [pid 60716:tid 60927] [client 34.166.23.235:52250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxfhMPsx0SVFjrd623WLwAAACI"]
[Thu Sep 17 15:45:40.670781 2026] [security2:error] [pid 60716:tid 60983] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfhMPsx0SVFjrd623WJgAAAFk"]
[Thu Sep 17 15:45:40.946599 2026] [security2:error] [pid 60716:tid 60904] [client 143.105.152.240:40476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfhMPsx0SVFjrd623WOAAAAAw"]
[Thu Sep 17 15:45:40.946707 2026] [security2:error] [pid 60716:tid 60904] [client 143.105.152.240:40476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfhMPsx0SVFjrd623WOAAAAAw"]
[Thu Sep 17 15:45:40.982386 2026] [security2:error] [pid 60716:tid 60837] [remote 35.234.44.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.44.234.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dranzarut.com"] [uri "/lib/terminal-xhr.php"] [unique_id "aqxfhMPsx0SVFjrd623WOgAAKUs"]
[Thu Sep 17 15:45:41.109109 2026] [security2:error] [pid 60716:tid 60914] [client 177.44.133.72:55429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfhcPsx0SVFjrd623WPwAAABY"]
[Thu Sep 17 15:45:41.109573 2026] [security2:error] [pid 60716:tid 60914] [client 177.44.133.72:55429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfhcPsx0SVFjrd623WPwAAABY"]
[Thu Sep 17 15:45:41.195286 2026] [security2:error] [pid 60716:tid 60765] [remote 35.234.44.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.44.234.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dranzarut.com"] [uri "/icecoder/lib/terminal-xhr.php"] [unique_id "aqxfhcPsx0SVFjrd623WQwAAcwY"]
[Thu Sep 17 15:45:41.332035 2026] [security2:error] [pid 60716:tid 60922] [client 34.166.23.235:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxfhcPsx0SVFjrd623WRgAAAB0"]
[Thu Sep 17 15:45:41.344251 2026] [security2:error] [pid 60716:tid 60969] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/.env.bak"] [unique_id "aqxfhcPsx0SVFjrd623WSAAAAEs"]
[Thu Sep 17 15:45:41.519767 2026] [security2:error] [pid 60716:tid 61019] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/.env.backup"] [unique_id "aqxfhcPsx0SVFjrd623WTAAAAH0"]
[Thu Sep 17 15:45:42.019790 2026] [security2:error] [pid 60716:tid 60994] [client 57.141.14.28:37340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxfhcPsx0SVFjrd623WWAAAZEQ"]
[Thu Sep 17 15:45:42.027016 2026] [security2:error] [pid 60716:tid 60966] [client 34.166.23.235:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxfhsPsx0SVFjrd623WXQAAAEg"]
[Thu Sep 17 15:45:42.062376 2026] [security2:error] [pid 60716:tid 60933] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfhcPsx0SVFjrd623WVwAAACc"]
[Thu Sep 17 15:45:42.112260 2026] [security2:error] [pid 60716:tid 60852] [remote 35.234.44.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.dranzarut.com"] [uri "/api/templates/preview"] [unique_id "aqxfhsPsx0SVFjrd623WYAAALFo"]
[Thu Sep 17 15:45:42.299994 2026] [security2:error] [pid 60716:tid 60953] [client 3.19.142.206:64020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxfhsPsx0SVFjrd623WYQAAADs"]
[Thu Sep 17 15:45:42.556970 2026] [security2:error] [pid 60716:tid 60988] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/.env.old"] [unique_id "aqxfhsPsx0SVFjrd623WbQAAAF4"]
[Thu Sep 17 15:45:42.711817 2026] [security2:error] [pid 60716:tid 60991] [client 34.166.23.235:52274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxfhsPsx0SVFjrd623WdQAAAGE"]
[Thu Sep 17 15:45:42.977688 2026] [security2:error] [pid 60716:tid 60951] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfhsPsx0SVFjrd623WeQAAADk"]
[Thu Sep 17 15:45:43.080811 2026] [security2:error] [pid 60716:tid 60949] [client 79.116.89.151:57705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfh8Psx0SVFjrd623WfgAAADc"]
[Thu Sep 17 15:45:43.081111 2026] [security2:error] [pid 60716:tid 60949] [client 79.116.89.151:57705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfh8Psx0SVFjrd623WfgAAADc"]
[Thu Sep 17 15:45:43.395061 2026] [security2:error] [pid 60716:tid 61007] [client 34.166.23.235:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfh8Psx0SVFjrd623WhwAAAHE"]
[Thu Sep 17 15:45:43.489957 2026] [security2:error] [pid 60716:tid 61001] [client 129.212.220.28:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.220.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chriswestlake.com"] [uri "/wp-admin/install.php"] [unique_id "aqxfh8Psx0SVFjrd623WigAAAGs"]
[Thu Sep 17 15:45:43.806729 2026] [security2:error] [pid 60716:tid 60964] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfh8Psx0SVFjrd623WjgAAAEY"]
[Thu Sep 17 15:45:44.089005 2026] [security2:error] [pid 60716:tid 60912] [client 34.166.23.235:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxfiMPsx0SVFjrd623WngAAABQ"]
[Thu Sep 17 15:45:44.829616 2026] [security2:error] [pid 60716:tid 60920] [client 179.26.188.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hikingforwildness.com"] [uri "/index.php"] [unique_id "aqxfiMPsx0SVFjrd623WtgAAABw"], referer: https://nonbinaryblogger.com/
[Thu Sep 17 15:45:44.889879 2026] [security2:error] [pid 60716:tid 60767] [remote 45.157.54.43:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nashobamarketing.com"] [uri "/xmlrpc.php"] [unique_id "aqxfiMPsx0SVFjrd623WwgAAcAg"]
[Thu Sep 17 15:45:44.890079 2026] [security2:error] [pid 60716:tid 61006] [client 45.157.54.43:61684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nashobamarketing.com"] [uri "/xmlrpc.php"] [unique_id "aqxfiMPsx0SVFjrd623WwgAAcAg"]
[Thu Sep 17 15:45:44.942898 2026] [security2:error] [pid 60716:tid 60958] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfiMPsx0SVFjrd623WvgAAAEA"]
[Thu Sep 17 15:45:45.018078 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.23.235:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxficPsx0SVFjrd623WwwAAAH0"]
[Thu Sep 17 15:45:45.288098 2026] [security2:error] [pid 60716:tid 60994] [client 169.58.197.253:64496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxficPsx0SVFjrd623WzAAAAGQ"], referer: binance.com
[Thu Sep 17 15:45:45.711744 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.23.235:52308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxficPsx0SVFjrd623W2QAAACw"]
[Thu Sep 17 15:45:45.996246 2026] [security2:error] [pid 60716:tid 60928] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxficPsx0SVFjrd623W3gAAACM"]
[Thu Sep 17 15:45:46.037772 2026] [security2:error] [pid 60716:tid 60972] [client 152.32.183.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kmd.duj.mybluehost.me"] [uri "/index.php"] [unique_id "aqxficPsx0SVFjrd623W4QAAAE4"]
[Thu Sep 17 15:45:46.389174 2026] [security2:error] [pid 60716:tid 60904] [client 34.166.23.235:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxfisPsx0SVFjrd623W8AAAAAw"]
[Thu Sep 17 15:45:46.524638 2026] [security2:error] [pid 60716:tid 60943] [client 139.59.114.163:54766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.net"] [uri "/index.php"] [unique_id "aqxfisPsx0SVFjrd623W7AAAADE"]
[Thu Sep 17 15:45:46.663446 2026] [security2:error] [pid 60716:tid 60923] [client 3.19.142.206:65148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623W9gAAAB4"]
[Thu Sep 17 15:45:46.663483 2026] [security2:error] [pid 60716:tid 60923] [client 3.19.142.206:65148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623W9gAAAB4"]
[Thu Sep 17 15:45:46.689288 2026] [security2:error] [pid 60716:tid 60940] [client 3.19.142.206:65167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623W9wAAAC4"]
[Thu Sep 17 15:45:46.689324 2026] [security2:error] [pid 60716:tid 60940] [client 3.19.142.206:65167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623W9wAAAC4"]
[Thu Sep 17 15:45:46.756047 2026] [security2:error] [pid 60716:tid 60975] [client 3.19.142.206:65172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623W-gAAAFE"]
[Thu Sep 17 15:45:46.756100 2026] [security2:error] [pid 60716:tid 60975] [client 3.19.142.206:65172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623W-gAAAFE"]
[Thu Sep 17 15:45:46.818576 2026] [security2:error] [pid 60716:tid 60969] [client 3.19.142.206:65167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623XAAAAAEs"]
[Thu Sep 17 15:45:46.818625 2026] [security2:error] [pid 60716:tid 60969] [client 3.19.142.206:65167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/backup/xmlrpc.php"] [unique_id "aqxfisPsx0SVFjrd623XAAAAAEs"]
[Thu Sep 17 15:45:46.968143 2026] [security2:error] [pid 60716:tid 60965] [client 169.58.197.251:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxfisPsx0SVFjrd623XAQAAAEc"], referer: binance.com
[Thu Sep 17 15:45:47.082764 2026] [security2:error] [pid 60716:tid 60966] [client 4.240.114.86:57655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "aqxfi8Psx0SVFjrd623XCQAAAEg"], referer: binance.com
[Thu Sep 17 15:45:47.088791 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.23.235:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxfi8Psx0SVFjrd623XCgAAAH0"]
[Thu Sep 17 15:45:47.276595 2026] [security2:error] [pid 60716:tid 60999] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfi8Psx0SVFjrd623XDAAAAGk"]
[Thu Sep 17 15:45:47.436447 2026] [security2:error] [pid 60716:tid 61001] [client 136.158.61.34:59279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfi8Psx0SVFjrd623XGQAAAGs"]
[Thu Sep 17 15:45:47.436559 2026] [security2:error] [pid 60716:tid 61001] [client 136.158.61.34:59279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfi8Psx0SVFjrd623XGQAAAGs"]
[Thu Sep 17 15:45:47.768996 2026] [security2:error] [pid 60716:tid 60953] [client 34.166.23.235:59772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxfi8Psx0SVFjrd623XKwAAADs"]
[Thu Sep 17 15:45:47.916103 2026] [core:error] [pid 60716:tid 60956] [client 45.249.246.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:45:47.916121 2026] [core:error] [pid 60716:tid 60956] [client 45.249.246.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:45:48.371178 2026] [security2:error] [pid 60716:tid 61000] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfjMPsx0SVFjrd623XOAAAAGo"]
[Thu Sep 17 15:45:48.429524 2026] [security2:error] [pid 60716:tid 60913] [client 177.72.86.98:29915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfjMPsx0SVFjrd623XPgAAFRQ"]
[Thu Sep 17 15:45:48.453522 2026] [security2:error] [pid 60716:tid 60940] [client 34.166.23.235:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxfjMPsx0SVFjrd623XQgAAAC4"]
[Thu Sep 17 15:45:48.823104 2026] [security2:error] [pid 60716:tid 61012] [client 3.19.142.206:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfjMPsx0SVFjrd623XUgAAAHY"]
[Thu Sep 17 15:45:48.879815 2026] [security2:error] [pid 60716:tid 60974] [client 139.59.114.163:54768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.net"] [uri "/index.php"] [unique_id "aqxfjMPsx0SVFjrd623XUQAAAFA"]
[Thu Sep 17 15:45:48.882711 2026] [security2:error] [pid 60716:tid 61007] [client 103.61.184.148:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfjMPsx0SVFjrd623XVQAAAHE"]
[Thu Sep 17 15:45:48.882788 2026] [security2:error] [pid 60716:tid 61007] [client 103.61.184.148:61214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfjMPsx0SVFjrd623XVQAAAHE"]
[Thu Sep 17 15:45:49.172578 2026] [security2:error] [pid 60716:tid 60955] [client 139.59.114.163:54768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.net"] [uri "/index.php"] [unique_id "aqxfjcPsx0SVFjrd623XWwAAAD0"]
[Thu Sep 17 15:45:49.299214 2026] [security2:error] [pid 60716:tid 60918] [client 152.32.183.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kmd.duj.mybluehost.me"] [uri "/index.php"] [unique_id "aqxfjcPsx0SVFjrd623XaQAAABo"]
[Thu Sep 17 15:45:49.306107 2026] [security2:error] [pid 60716:tid 60944] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfjcPsx0SVFjrd623XXgAAADI"]
[Thu Sep 17 15:45:49.462319 2026] [security2:error] [pid 60716:tid 60991] [client 139.59.114.163:54768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechurchinirving.net"] [uri "/index.php"] [unique_id "aqxfjcPsx0SVFjrd623XbgAAAGE"]
[Thu Sep 17 15:45:49.624057 2026] [security2:error] [pid 60716:tid 60941] [client 34.166.23.235:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfjcPsx0SVFjrd623XdQAAAC8"]
[Thu Sep 17 15:45:50.007996 2026] [security2:error] [pid 60716:tid 60987] [client 185.180.141.7:20354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxfjcPsx0SVFjrd623XhwAAXVc"]
[Thu Sep 17 15:45:50.058326 2026] [fcgid:warn] [pid 60716:tid 60979] (70014)End of file found: [client 107.150.103.88:40970] mod_fcgid: can't get data from http client
[Thu Sep 17 15:45:50.132988 2026] [security2:error] [pid 60716:tid 60876] [remote 216.73.217.142:31412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxfjsPsx0SVFjrd623XjQAAUHI"]
[Thu Sep 17 15:45:50.142895 2026] [security2:error] [pid 60716:tid 61012] [client 185.180.141.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxfjsPsx0SVFjrd623XiwAAAHY"]
[Thu Sep 17 15:45:50.155123 2026] [security2:error] [pid 60716:tid 60997] [client 14.96.156.146:61598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfjsPsx0SVFjrd623XkAAAAGc"]
[Thu Sep 17 15:45:50.156323 2026] [security2:error] [pid 60716:tid 60997] [client 14.96.156.146:61598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfjsPsx0SVFjrd623XkAAAAGc"]
[Thu Sep 17 15:45:50.312977 2026] [security2:error] [pid 60716:tid 61002] [client 34.166.23.235:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxfjsPsx0SVFjrd623XnwAAAGw"]
[Thu Sep 17 15:45:50.385695 2026] [security2:error] [pid 60716:tid 60906] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfjsPsx0SVFjrd623XmQAAAA4"]
[Thu Sep 17 15:45:50.429770 2026] [security2:error] [pid 60716:tid 60998] [client 148.227.75.216:37258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfjsPsx0SVFjrd623XpgAAAGg"]
[Thu Sep 17 15:45:50.429867 2026] [security2:error] [pid 60716:tid 60998] [client 148.227.75.216:37258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfjsPsx0SVFjrd623XpgAAAGg"]
[Thu Sep 17 15:45:50.455883 2026] [security2:error] [pid 60716:tid 60939] [client 169.58.197.253:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p3collaborative.com"] [uri "/wp-login.php"] [unique_id "aqxfjsPsx0SVFjrd623XqQAAAC0"], referer: binance.com
[Thu Sep 17 15:45:50.522939 2026] [security2:error] [pid 60716:tid 60935] [client 185.180.141.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "coronadoiscalling.com"] [uri "/index.php"] [unique_id "aqxfjsPsx0SVFjrd623XqgAAACk"], referer: http://coronadoiscalling.com/favicon.ico
[Thu Sep 17 15:45:50.622213 2026] [security2:error] [pid 60716:tid 60818] [remote 47.128.28.119:51974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "npae.net"] [uri "/robots.txt"] [unique_id "aqxfjsPsx0SVFjrd623XrwAAQTg"]
[Thu Sep 17 15:45:50.650766 2026] [fcgid:warn] [pid 60716:tid 60980] (70014)End of file found: [client 45.249.246.196:55734] mod_fcgid: can't get data from http client
[Thu Sep 17 15:45:50.804069 2026] [security2:error] [pid 60716:tid 60976] [client 145.239.10.137:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fetchandfierce.com"] [uri "/ww.php"] [unique_id "aqxfjsPsx0SVFjrd623XuwAAAFI"], referer: http://fetchandfierce.com/ww.php
[Thu Sep 17 15:45:50.987847 2026] [security2:error] [pid 60716:tid 60904] [client 34.166.23.235:59794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfjsPsx0SVFjrd623XxAAAAAw"]
[Thu Sep 17 15:45:51.158825 2026] [security2:error] [pid 60716:tid 60979] [client 4.240.114.86:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/block-template.php"] [unique_id "aqxfj8Psx0SVFjrd623X0gAAAFU"], referer: binance.com
[Thu Sep 17 15:45:51.297470 2026] [security2:error] [pid 60716:tid 61012] [client 187.255.99.249:7763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfj8Psx0SVFjrd623X1AAAdho"]
[Thu Sep 17 15:45:51.403808 2026] [security2:error] [pid 60716:tid 60892] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfj8Psx0SVFjrd623X2gAAAAA"]
[Thu Sep 17 15:45:51.453456 2026] [security2:error] [pid 60716:tid 60909] [client 143.105.152.240:15504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfj8Psx0SVFjrd623X4QAAABE"]
[Thu Sep 17 15:45:51.453606 2026] [security2:error] [pid 60716:tid 60909] [client 143.105.152.240:15504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfj8Psx0SVFjrd623X4QAAABE"]
[Thu Sep 17 15:45:51.664727 2026] [security2:error] [pid 60716:tid 60998] [client 34.166.23.235:59806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxfj8Psx0SVFjrd623X6wAAAGg"]
[Thu Sep 17 15:45:51.737440 2026] [security2:error] [pid 60716:tid 60900] [client 177.44.133.72:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfj8Psx0SVFjrd623X8AAAAAg"]
[Thu Sep 17 15:45:51.737566 2026] [security2:error] [pid 60716:tid 60900] [client 177.44.133.72:56102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfj8Psx0SVFjrd623X8AAAAAg"]
[Thu Sep 17 15:45:52.356040 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.23.235:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxfkMPsx0SVFjrd623YDQAAACQ"]
[Thu Sep 17 15:45:52.424010 2026] [security2:error] [pid 60716:tid 60946] [client 3.19.142.206:50996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxfkMPsx0SVFjrd623YCQAAADQ"]
[Thu Sep 17 15:45:52.782111 2026] [security2:error] [pid 60716:tid 60952] [client 169.58.197.253:64971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxfkMPsx0SVFjrd623YJAAAADo"], referer: binance.com
[Thu Sep 17 15:45:52.944646 2026] [security2:error] [pid 60716:tid 60941] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfkMPsx0SVFjrd623YIwAAAC8"]
[Thu Sep 17 15:45:53.032428 2026] [security2:error] [pid 60716:tid 60958] [client 34.166.23.235:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxfkcPsx0SVFjrd623YMAAAAEA"]
[Thu Sep 17 15:45:53.602387 2026] [security2:error] [pid 60716:tid 60947] [client 69.160.103.186:11103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "meatlessmusings.com"] [uri "/index.php"] [unique_id "aqxfkMPsx0SVFjrd623YDgAAADU"], referer: https://meatlessmusings.com/smoked-salmon-and-avocado-toast
[Thu Sep 17 15:45:53.640391 2026] [security2:error] [pid 60716:tid 61014] [client 74.7.228.44:41144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.yiz.qiv.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "aqxfkcPsx0SVFjrd623YSwAAAHg"]
[Thu Sep 17 15:45:53.709559 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.23.235:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxfkcPsx0SVFjrd623YUQAAAHY"]
[Thu Sep 17 15:45:53.723894 2026] [security2:error] [pid 60716:tid 60896] [client 79.116.89.151:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfkcPsx0SVFjrd623YUgAAAAQ"]
[Thu Sep 17 15:45:53.724175 2026] [security2:error] [pid 60716:tid 60896] [client 79.116.89.151:58484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfkcPsx0SVFjrd623YUgAAAAQ"]
[Thu Sep 17 15:45:54.045839 2026] [security2:error] [pid 60716:tid 60949] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfkcPsx0SVFjrd623YWwAAADc"]
[Thu Sep 17 15:45:54.392119 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.23.235:59844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxfksPsx0SVFjrd623YcgAAAAc"]
[Thu Sep 17 15:45:54.702789 2026] [security2:error] [pid 60716:tid 61001] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/.env.swp"] [unique_id "aqxfksPsx0SVFjrd623YhQAAAGs"]
[Thu Sep 17 15:45:54.960489 2026] [security2:error] [pid 60716:tid 61021] [client 3.19.142.206:52144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfksPsx0SVFjrd623YjwAAAH8"]
[Thu Sep 17 15:45:54.960545 2026] [security2:error] [pid 60716:tid 61021] [client 3.19.142.206:52144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfksPsx0SVFjrd623YjwAAAH8"]
[Thu Sep 17 15:45:54.986211 2026] [security2:error] [pid 60716:tid 60934] [client 3.19.142.206:52156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfksPsx0SVFjrd623YkAAAACg"]
[Thu Sep 17 15:45:54.986270 2026] [security2:error] [pid 60716:tid 60934] [client 3.19.142.206:52156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfksPsx0SVFjrd623YkAAAACg"]
[Thu Sep 17 15:45:54.992407 2026] [security2:error] [pid 60716:tid 60981] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/.env~"] [unique_id "aqxfksPsx0SVFjrd623YkQAAAFc"]
[Thu Sep 17 15:45:55.017948 2026] [security2:error] [pid 60716:tid 60924] [client 3.19.142.206:52144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfk8Psx0SVFjrd623YlAAAAB8"]
[Thu Sep 17 15:45:55.017993 2026] [security2:error] [pid 60716:tid 60924] [client 3.19.142.206:52144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfk8Psx0SVFjrd623YlAAAAB8"]
[Thu Sep 17 15:45:55.070535 2026] [security2:error] [pid 60716:tid 60946] [client 34.166.23.235:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxfk8Psx0SVFjrd623YmQAAADQ"]
[Thu Sep 17 15:45:55.077350 2026] [security2:error] [pid 60716:tid 61012] [client 3.19.142.206:52176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfk8Psx0SVFjrd623YmgAAAHY"]
[Thu Sep 17 15:45:55.077399 2026] [security2:error] [pid 60716:tid 61012] [client 3.19.142.206:52176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/web/xmlrpc.php"] [unique_id "aqxfk8Psx0SVFjrd623YmgAAAHY"]
[Thu Sep 17 15:45:55.189688 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.246.111:41612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/.env"] [unique_id "aqxfk8Psx0SVFjrd623YoAAAACU"]
[Thu Sep 17 15:45:55.408309 2026] [security2:error] [pid 60716:tid 60966] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfk8Psx0SVFjrd623YpAAAAEg"]
[Thu Sep 17 15:45:55.677949 2026] [security2:error] [pid 60716:tid 60960] [client 162.241.226.11:43870] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxfk8Psx0SVFjrd623YsAAAAEI"]
[Thu Sep 17 15:45:55.713292 2026] [security2:error] [pid 60716:tid 60910] [client 187.173.193.12:34158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfk8Psx0SVFjrd623YrAAAElo"]
[Thu Sep 17 15:45:55.756063 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.23.235:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxfk8Psx0SVFjrd623YugAAAG0"]
[Thu Sep 17 15:45:56.071510 2026] [security2:error] [pid 60716:tid 60901] [client 4.240.114.86:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "aqxflMPsx0SVFjrd623YwwAAAAk"], referer: binance.com
[Thu Sep 17 15:45:56.445912 2026] [security2:error] [pid 60716:tid 61021] [client 34.166.23.235:44970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxflMPsx0SVFjrd623Y1gAAAH8"]
[Thu Sep 17 15:45:56.685610 2026] [security2:error] [pid 60716:tid 60971] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxflMPsx0SVFjrd623Y2QAAAE0"]
[Thu Sep 17 15:45:57.131007 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.23.235:44984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxflcPsx0SVFjrd623Y6QAAAA0"]
[Thu Sep 17 15:45:57.344334 2026] [security2:error] [pid 60716:tid 60958] [client 3.19.142.206:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.142.19.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxflcPsx0SVFjrd623Y8wAAAEA"]
[Thu Sep 17 15:45:57.588591 2026] [security2:error] [pid 60716:tid 60941] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxflcPsx0SVFjrd623Y9wAAAC8"]
[Thu Sep 17 15:45:57.813765 2026] [security2:error] [pid 60716:tid 61008] [client 34.166.23.235:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxflcPsx0SVFjrd623ZBQAAAHI"]
[Thu Sep 17 15:45:57.835292 2026] [core:error] [pid 60716:tid 60957] [client 45.249.246.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:45:57.835320 2026] [core:error] [pid 60716:tid 60957] [client 45.249.246.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:45:57.870579 2026] [security2:error] [pid 60716:tid 60929] [client 169.58.197.251:60173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxflcPsx0SVFjrd623ZCQAAACQ"], referer: binance.com
[Thu Sep 17 15:45:58.154340 2026] [security2:error] [pid 60716:tid 61002] [client 181.78.44.18:58128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxflsPsx0SVFjrd623ZCwAAbEI"]
[Thu Sep 17 15:45:58.508435 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.23.235:45006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxflsPsx0SVFjrd623ZHQAAACw"]
[Thu Sep 17 15:45:59.045263 2026] [security2:error] [pid 60716:tid 60904] [client 129.212.220.28:35442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.220.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chriswestlake.com"] [uri "/xmlrpc.php"] [unique_id "aqxflsPsx0SVFjrd623ZLAAAAAw"]
[Thu Sep 17 15:45:59.195934 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.23.235:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxfl8Psx0SVFjrd623ZNQAAAAA"]
[Thu Sep 17 15:45:59.306011 2026] [security2:error] [pid 60716:tid 61000] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfl8Psx0SVFjrd623ZMAAAAGo"]
[Thu Sep 17 15:45:59.568968 2026] [security2:error] [pid 60716:tid 61015] [client 34.154.246.111:46334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/.env.bak"] [unique_id "aqxfl8Psx0SVFjrd623ZOwAAAHk"]
[Thu Sep 17 15:45:59.591077 2026] [security2:error] [pid 60716:tid 61020] [client 103.61.184.148:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfl8Psx0SVFjrd623ZPAAAAH4"]
[Thu Sep 17 15:45:59.591163 2026] [security2:error] [pid 60716:tid 61020] [client 103.61.184.148:61954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfl8Psx0SVFjrd623ZPAAAAH4"]
[Thu Sep 17 15:45:59.767970 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.246.111:46334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/.env.backup"] [unique_id "aqxfl8Psx0SVFjrd623ZQgAAAHE"]
[Thu Sep 17 15:45:59.893378 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.23.235:45030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxfl8Psx0SVFjrd623ZSAAAAB4"]
[Thu Sep 17 15:46:00.177453 2026] [security2:error] [pid 60716:tid 60859] [remote 40.77.167.1:11908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ritamayblog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxfmMPsx0SVFjrd623ZUAAAGWE"], referer: https://ritamayblog.com/its-not-your-fault-you-struggle-with-food/
[Thu Sep 17 15:46:00.235815 2026] [security2:error] [pid 60716:tid 60781] [remote 40.77.167.1:11908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ritamayblog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxfmMPsx0SVFjrd623ZWAAAFxQ"], referer: https://ritamayblog.com/its-not-your-fault-you-struggle-with-food/
[Thu Sep 17 15:46:00.445366 2026] [security2:error] [pid 60716:tid 60934] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfmMPsx0SVFjrd623ZWwAAACg"]
[Thu Sep 17 15:46:00.599645 2026] [security2:error] [pid 60716:tid 60998] [client 34.166.23.235:45038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxfmMPsx0SVFjrd623ZYwAAAGg"]
[Thu Sep 17 15:46:00.708417 2026] [security2:error] [pid 60716:tid 60977] [client 34.154.246.111:46350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/.env.old"] [unique_id "aqxfmMPsx0SVFjrd623ZaQAAAFM"]
[Thu Sep 17 15:46:00.824116 2026] [security2:error] [pid 60716:tid 60978] [client 14.96.156.146:62269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfmMPsx0SVFjrd623ZbwAAAFQ"]
[Thu Sep 17 15:46:00.824213 2026] [security2:error] [pid 60716:tid 60978] [client 14.96.156.146:62269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfmMPsx0SVFjrd623ZbwAAAFQ"]
[Thu Sep 17 15:46:00.903615 2026] [security2:error] [pid 60716:tid 60898] [client 136.158.61.34:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfmMPsx0SVFjrd623ZcgAAAAY"]
[Thu Sep 17 15:46:00.903760 2026] [security2:error] [pid 60716:tid 60898] [client 136.158.61.34:60262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfmMPsx0SVFjrd623ZcgAAAAY"]
[Thu Sep 17 15:46:01.079603 2026] [security2:error] [pid 60716:tid 60947] [client 148.227.75.216:1312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfmcPsx0SVFjrd623ZegAAADU"]
[Thu Sep 17 15:46:01.094616 2026] [security2:error] [pid 60716:tid 60947] [client 148.227.75.216:1312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfmcPsx0SVFjrd623ZegAAADU"]
[Thu Sep 17 15:46:01.280636 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.23.235:45048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfmcPsx0SVFjrd623ZhQAAAG0"]
[Thu Sep 17 15:46:01.472462 2026] [security2:error] [pid 60716:tid 61005] [client 169.58.197.253:65457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxfmcPsx0SVFjrd623ZhwAAAG8"], referer: binance.com
[Thu Sep 17 15:46:01.552414 2026] [security2:error] [pid 60716:tid 60946] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/app/.env"] [unique_id "aqxfmcPsx0SVFjrd623ZiwAAADQ"]
[Thu Sep 17 15:46:01.792966 2026] [security2:error] [pid 60716:tid 60928] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/apps/.env"] [unique_id "aqxfmcPsx0SVFjrd623ZlgAAACM"]
[Thu Sep 17 15:46:01.969787 2026] [security2:error] [pid 60716:tid 60993] [client 34.166.23.235:45052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfmcPsx0SVFjrd623ZnQAAAGM"]
[Thu Sep 17 15:46:02.043393 2026] [security2:error] [pid 60716:tid 60988] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/api/.env"] [unique_id "aqxfmsPsx0SVFjrd623ZoAAAAF4"]
[Thu Sep 17 15:46:02.116058 2026] [security2:error] [pid 60716:tid 60926] [client 143.105.152.240:18291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfmsPsx0SVFjrd623ZoQAAACE"]
[Thu Sep 17 15:46:02.116196 2026] [security2:error] [pid 60716:tid 60926] [client 143.105.152.240:18291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfmsPsx0SVFjrd623ZoQAAACE"]
[Thu Sep 17 15:46:02.228872 2026] [security2:error] [pid 60716:tid 61016] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/web/.env"] [unique_id "aqxfmsPsx0SVFjrd623ZqwAAAHo"]
[Thu Sep 17 15:46:02.339880 2026] [security2:error] [pid 60716:tid 61021] [client 177.44.133.72:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfmsPsx0SVFjrd623ZrgAAAH8"]
[Thu Sep 17 15:46:02.340056 2026] [security2:error] [pid 60716:tid 61021] [client 177.44.133.72:56768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfmsPsx0SVFjrd623ZrgAAAH8"]
[Thu Sep 17 15:46:02.413488 2026] [security2:error] [pid 60716:tid 61006] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/site/.env"] [unique_id "aqxfmsPsx0SVFjrd623ZsAAAAHA"]
[Thu Sep 17 15:46:02.549574 2026] [security2:error] [pid 60716:tid 60898] [client 4.240.114.86:64780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "aqxfmsPsx0SVFjrd623ZtAAAAAY"], referer: binance.com
[Thu Sep 17 15:46:02.615206 2026] [security2:error] [pid 60716:tid 60909] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/public/.env"] [unique_id "aqxfmsPsx0SVFjrd623ZtwAAABE"]
[Thu Sep 17 15:46:02.653612 2026] [security2:error] [pid 60716:tid 60943] [client 34.166.23.235:45066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxfmsPsx0SVFjrd623ZugAAADE"]
[Thu Sep 17 15:46:02.932478 2026] [core:error] [pid 60716:tid 61014] [client 45.249.246.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:46:02.932499 2026] [core:error] [pid 60716:tid 61014] [client 45.249.246.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:46:03.304222 2026] [security2:error] [pid 60716:tid 60992] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfm8Psx0SVFjrd623ZzQAAAGI"]
[Thu Sep 17 15:46:03.335589 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.23.235:45074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxfm8Psx0SVFjrd623Z2AAAACQ"]
[Thu Sep 17 15:46:03.430007 2026] [security2:error] [pid 60716:tid 60917] [client 3.82.141.143:10584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.maggietheturtle.com"] [uri "/config.php"] [unique_id "aqxfm8Psx0SVFjrd623Z4QAAABk"]
[Thu Sep 17 15:46:03.430475 2026] [security2:error] [pid 60716:tid 61002] [client 3.82.141.143:10800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.maggietheturtle.com"] [uri "/wp-config.php~"] [unique_id "aqxfm8Psx0SVFjrd623Z4gAAAGw"]
[Thu Sep 17 15:46:03.430549 2026] [security2:error] [pid 60716:tid 60990] [client 3.82.141.143:10786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.maggietheturtle.com"] [uri "/wp-config.php.save"] [unique_id "aqxfm8Psx0SVFjrd623Z5QAAAGA"]
[Thu Sep 17 15:46:03.434461 2026] [security2:error] [pid 60716:tid 60938] [client 3.82.141.143:10784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.maggietheturtle.com"] [uri "/wp-config.php.bak"] [unique_id "aqxfm8Psx0SVFjrd623Z7gAAACw"]
[Thu Sep 17 15:46:03.434620 2026] [security2:error] [pid 60716:tid 60967] [client 3.82.141.143:10764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.141.82.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.maggietheturtle.com"] [uri "/wp-config.php"] [unique_id "aqxfm8Psx0SVFjrd623Z7AAAAEk"]
[Thu Sep 17 15:46:03.442607 2026] [security2:error] [pid 60716:tid 60961] [client 3.82.141.143:10770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.maggietheturtle.com"] [uri "/wp-config.php.old"] [unique_id "aqxfm8Psx0SVFjrd623aAwAAAEM"]
[Thu Sep 17 15:46:03.515753 2026] [security2:error] [pid 60716:tid 60858] [remote 40.77.167.1:11908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ritamayblog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqxfm8Psx0SVFjrd623aCAAAIGA"], referer: https://ritamayblog.com/its-not-your-fault-you-struggle-with-food/
[Thu Sep 17 15:46:04.028252 2026] [security2:error] [pid 60716:tid 61005] [client 34.166.23.235:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfnMPsx0SVFjrd623aIAAAAG8"]
[Thu Sep 17 15:46:04.380843 2026] [security2:error] [pid 60716:tid 60919] [client 79.116.89.151:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfnMPsx0SVFjrd623aMQAAABs"]
[Thu Sep 17 15:46:04.380988 2026] [security2:error] [pid 60716:tid 60919] [client 79.116.89.151:59182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfnMPsx0SVFjrd623aMQAAABs"]
[Thu Sep 17 15:46:04.500057 2026] [security2:error] [pid 60716:tid 60926] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/backend/.env"] [unique_id "aqxfnMPsx0SVFjrd623aNQAAACE"]
[Thu Sep 17 15:46:04.693860 2026] [security2:error] [pid 60716:tid 60965] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/server/.env"] [unique_id "aqxfnMPsx0SVFjrd623aQAAAAEc"]
[Thu Sep 17 15:46:04.719324 2026] [security2:error] [pid 60716:tid 60988] [client 34.166.23.235:45100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfnMPsx0SVFjrd623aQwAAAF4"]
[Thu Sep 17 15:46:04.870247 2026] [autoindex:error] [pid 60716:tid 61012] [client 4.240.114.86:65510] AH01276: Cannot serve directory /home1/oldschx3/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:46:04.886608 2026] [security2:error] [pid 60716:tid 61021] [client 35.238.73.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recessionnews.org"] [uri "/index.php"] [unique_id "aqxfm8Psx0SVFjrd623aBwAAAH8"]
[Thu Sep 17 15:46:04.889213 2026] [security2:error] [pid 60716:tid 60974] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/frontend/.env"] [unique_id "aqxfnMPsx0SVFjrd623aRwAAAFA"]
[Thu Sep 17 15:46:05.127214 2026] [security2:error] [pid 60716:tid 61017] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/src/.env"] [unique_id "aqxfncPsx0SVFjrd623aTwAAAHs"]
[Thu Sep 17 15:46:05.395641 2026] [security2:error] [pid 60716:tid 60992] [client 34.166.23.235:45112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxfncPsx0SVFjrd623aXAAAAGI"]
[Thu Sep 17 15:46:05.406925 2026] [security2:error] [pid 60716:tid 60967] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/core/.env"] [unique_id "aqxfncPsx0SVFjrd623aXQAAAEk"]
[Thu Sep 17 15:46:05.598753 2026] [security2:error] [pid 60716:tid 60931] [client 92.72.180.217:64648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfncPsx0SVFjrd623aYAAAJV4"]
[Thu Sep 17 15:46:05.610851 2026] [security2:error] [pid 60716:tid 61006] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/core/app/.env"] [unique_id "aqxfncPsx0SVFjrd623aYwAAAHA"]
[Thu Sep 17 15:46:05.809890 2026] [security2:error] [pid 60716:tid 60925] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/config/.env"] [unique_id "aqxfncPsx0SVFjrd623abgAAACA"]
[Thu Sep 17 15:46:05.821106 2026] [security2:error] [pid 60716:tid 60981] [client 203.10.99.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxfncPsx0SVFjrd623aYQAAAFc"]
[Thu Sep 17 15:46:05.974808 2026] [security2:error] [pid 60716:tid 60922] [client 92.72.180.217:64648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxfncPsx0SVFjrd623acgAAHWU"]
[Thu Sep 17 15:46:06.082460 2026] [security2:error] [pid 60716:tid 60919] [client 34.166.23.235:45124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.23.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iql.lho.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxfnsPsx0SVFjrd623aegAAABs"]
[Thu Sep 17 15:46:06.178289 2026] [security2:error] [pid 60716:tid 60896] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/private/.env"] [unique_id "aqxfnsPsx0SVFjrd623agAAAAAQ"]
[Thu Sep 17 15:46:06.405129 2026] [security2:error] [pid 60716:tid 60942] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/application/.env"] [unique_id "aqxfnsPsx0SVFjrd623ahQAAADA"]
[Thu Sep 17 15:46:06.633973 2026] [security2:error] [pid 60716:tid 60996] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/bootstrap/.env"] [unique_id "aqxfnsPsx0SVFjrd623aiQAAAGY"]
[Thu Sep 17 15:46:06.838450 2026] [security2:error] [pid 60716:tid 60980] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/database/.env"] [unique_id "aqxfnsPsx0SVFjrd623algAAAFY"]
[Thu Sep 17 15:46:07.106434 2026] [security2:error] [pid 60716:tid 61007] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/storage/.env"] [unique_id "aqxfn8Psx0SVFjrd623anAAAAHE"]
[Thu Sep 17 15:46:07.126961 2026] [security2:error] [pid 60716:tid 61000] [client 74.7.228.47:51280] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kopecdental.com"] [uri "/index.php"] [unique_id "aqxfm8Psx0SVFjrd623aEQAAago"]
[Thu Sep 17 15:46:07.241609 2026] [security2:error] [pid 60716:tid 60935] [client 4.240.114.86:50557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "aqxfn8Psx0SVFjrd623apQAAACk"], referer: binance.com
[Thu Sep 17 15:46:07.316922 2026] [security2:error] [pid 60716:tid 60917] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/var/www/.env"] [unique_id "aqxfn8Psx0SVFjrd623aqQAAABk"]
[Thu Sep 17 15:46:07.400105 2026] [security2:error] [pid 60716:tid 60952] [client 216.38.230.117:61346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "berenice-vaucher.com"] [uri "/index.php"] [unique_id "aqxfn8Psx0SVFjrd623aqAAAADo"]
[Thu Sep 17 15:46:07.492805 2026] [security2:error] [pid 60716:tid 61008] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/var/www/html/.env"] [unique_id "aqxfn8Psx0SVFjrd623arQAAAHI"]
[Thu Sep 17 15:46:07.755727 2026] [security2:error] [pid 60716:tid 60993] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/current/.env"] [unique_id "aqxfn8Psx0SVFjrd623awAAAAGM"]
[Thu Sep 17 15:46:07.960157 2026] [security2:error] [pid 60716:tid 60988] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/release/.env"] [unique_id "aqxfn8Psx0SVFjrd623aygAAAF4"]
[Thu Sep 17 15:46:08.303232 2026] [security2:error] [pid 60716:tid 61020] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/releases/.env"] [unique_id "aqxfoMPsx0SVFjrd623a2QAAAH4"]
[Thu Sep 17 15:46:08.504648 2026] [security2:error] [pid 60716:tid 61007] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/shared/.env"] [unique_id "aqxfoMPsx0SVFjrd623a3wAAAHE"]
[Thu Sep 17 15:46:08.733788 2026] [security2:error] [pid 60716:tid 60931] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/deploy/.env"] [unique_id "aqxfoMPsx0SVFjrd623a6gAAACU"]
[Thu Sep 17 15:46:08.984120 2026] [security2:error] [pid 60716:tid 60925] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/build/.env"] [unique_id "aqxfoMPsx0SVFjrd623a8gAAACA"]
[Thu Sep 17 15:46:09.143649 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.246.111:35536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/.env.swp"] [unique_id "aqxfocPsx0SVFjrd623a-QAAAGk"]
[Thu Sep 17 15:46:09.169526 2026] [security2:error] [pid 60716:tid 60958] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/dist/.env"] [unique_id "aqxfocPsx0SVFjrd623a-wAAAEA"]
[Thu Sep 17 15:46:09.211765 2026] [security2:error] [pid 60716:tid 60892] [client 169.58.197.251:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wp-view-config-data.php"] [unique_id "aqxfocPsx0SVFjrd623bAQAAAAA"], referer: binance.com
[Thu Sep 17 15:46:09.313120 2026] [security2:error] [pid 60716:tid 60919] [client 143.208.235.26:21401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfocPsx0SVFjrd623a_gAAG2I"]
[Thu Sep 17 15:46:09.325397 2026] [security2:error] [pid 60716:tid 60986] [client 34.154.246.111:35536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/.env~"] [unique_id "aqxfocPsx0SVFjrd623bBgAAAFw"]
[Thu Sep 17 15:46:09.387823 2026] [security2:error] [pid 60716:tid 60988] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/public_html/.env"] [unique_id "aqxfocPsx0SVFjrd623bBwAAAF4"]
[Thu Sep 17 15:46:09.633495 2026] [security2:error] [pid 60716:tid 61005] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/htdocs/.env"] [unique_id "aqxfocPsx0SVFjrd623bDQAAAG8"]
[Thu Sep 17 15:46:09.813835 2026] [security2:error] [pid 60716:tid 60979] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/www/.env"] [unique_id "aqxfocPsx0SVFjrd623bFwAAAFU"]
[Thu Sep 17 15:46:09.989035 2026] [security2:error] [pid 60716:tid 60976] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/html/.env"] [unique_id "aqxfocPsx0SVFjrd623bGQAAAFI"]
[Thu Sep 17 15:46:10.193362 2026] [security2:error] [pid 60716:tid 60992] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/live/.env"] [unique_id "aqxfosPsx0SVFjrd623bIQAAAGI"]
[Thu Sep 17 15:46:10.317707 2026] [security2:error] [pid 60716:tid 61007] [client 103.61.184.148:62632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfosPsx0SVFjrd623bKQAAAHE"]
[Thu Sep 17 15:46:10.317850 2026] [security2:error] [pid 60716:tid 61007] [client 103.61.184.148:62632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfosPsx0SVFjrd623bKQAAAHE"]
[Thu Sep 17 15:46:10.397987 2026] [security2:error] [pid 60716:tid 60931] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/prod/.env"] [unique_id "aqxfosPsx0SVFjrd623bKwAAACU"]
[Thu Sep 17 15:46:10.653032 2026] [security2:error] [pid 60716:tid 60928] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/dev/.env"] [unique_id "aqxfosPsx0SVFjrd623bLwAAACM"]
[Thu Sep 17 15:46:10.784356 2026] [security2:error] [pid 60716:tid 60947] [client 169.58.197.253:49720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxfosPsx0SVFjrd623bRAAAADU"], referer: binance.com
[Thu Sep 17 15:46:10.848418 2026] [security2:error] [pid 60716:tid 60933] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/staging/.env"] [unique_id "aqxfosPsx0SVFjrd623bRQAAACc"]
[Thu Sep 17 15:46:11.052728 2026] [security2:error] [pid 60716:tid 60962] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/opt/.env"] [unique_id "aqxfo8Psx0SVFjrd623bUQAAAEQ"]
[Thu Sep 17 15:46:11.231521 2026] [security2:error] [pid 60716:tid 60912] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/laravel/.env"] [unique_id "aqxfo8Psx0SVFjrd623bXgAAABQ"]
[Thu Sep 17 15:46:11.297259 2026] [security2:error] [pid 60716:tid 61019] [client 66.249.65.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moroccohometravel.com"] [uri "/index.php"] [unique_id "aqxfoMPsx0SVFjrd623a0AAAAH0"]
[Thu Sep 17 15:46:11.428325 2026] [core:error] [pid 60716:tid 60893] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:46:11.428346 2026] [core:error] [pid 60716:tid 60893] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:46:11.497446 2026] [security2:error] [pid 60716:tid 60970] [client 14.96.156.146:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfo8Psx0SVFjrd623baQAAAEw"]
[Thu Sep 17 15:46:11.497573 2026] [security2:error] [pid 60716:tid 60970] [client 14.96.156.146:62933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfo8Psx0SVFjrd623baQAAAEw"]
[Thu Sep 17 15:46:11.536926 2026] [security2:error] [pid 60716:tid 61016] [client 4.240.114.86:52495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "aqxfo8Psx0SVFjrd623bagAAAHo"], referer: binance.com
[Thu Sep 17 15:46:11.540168 2026] [security2:error] [pid 60716:tid 60914] [client 35.228.4.121:43816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/symfony/.env"] [unique_id "aqxfo8Psx0SVFjrd623bawAAABY"]
[Thu Sep 17 15:46:11.857968 2026] [security2:error] [pid 60716:tid 60985] [client 148.227.75.216:15638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfo8Psx0SVFjrd623beAAAAFs"]
[Thu Sep 17 15:46:11.867731 2026] [security2:error] [pid 60716:tid 60985] [client 148.227.75.216:15638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfo8Psx0SVFjrd623beAAAAFs"]
[Thu Sep 17 15:46:12.258909 2026] [security2:error] [pid 60716:tid 60925] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/wordpress/.env"] [unique_id "aqxfpMPsx0SVFjrd623biwAAACA"]
[Thu Sep 17 15:46:12.464967 2026] [security2:error] [pid 60716:tid 60949] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/wp/.env"] [unique_id "aqxfpMPsx0SVFjrd623bkQAAADc"]
[Thu Sep 17 15:46:12.687695 2026] [security2:error] [pid 60716:tid 60986] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/cms/.env"] [unique_id "aqxfpMPsx0SVFjrd623bpQAAAFw"]
[Thu Sep 17 15:46:12.704337 2026] [security2:error] [pid 60716:tid 60905] [client 143.105.152.240:17688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfpMPsx0SVFjrd623bpwAAAA0"]
[Thu Sep 17 15:46:12.711795 2026] [security2:error] [pid 60716:tid 60905] [client 143.105.152.240:17688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfpMPsx0SVFjrd623bpwAAAA0"]
[Thu Sep 17 15:46:12.903837 2026] [security2:error] [pid 60716:tid 60911] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/drupal/.env"] [unique_id "aqxfpMPsx0SVFjrd623bsAAAABM"]
[Thu Sep 17 15:46:12.948002 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.34.14:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/phpinfo.php"] [unique_id "aqxfpMPsx0SVFjrd623bsgAAABY"]
[Thu Sep 17 15:46:13.032008 2026] [security2:error] [pid 60716:tid 60951] [client 177.44.133.72:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfpcPsx0SVFjrd623btgAAADk"]
[Thu Sep 17 15:46:13.032189 2026] [security2:error] [pid 60716:tid 60951] [client 177.44.133.72:57557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfpcPsx0SVFjrd623btgAAADk"]
[Thu Sep 17 15:46:13.177240 2026] [security2:error] [pid 60716:tid 60913] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/joomla/.env"] [unique_id "aqxfpcPsx0SVFjrd623bvAAAABU"]
[Thu Sep 17 15:46:13.207759 2026] [security2:error] [pid 60716:tid 60980] [client 136.158.61.34:61372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfpcPsx0SVFjrd623bvwAAAFY"]
[Thu Sep 17 15:46:13.207864 2026] [security2:error] [pid 60716:tid 60980] [client 136.158.61.34:61372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfpcPsx0SVFjrd623bvwAAAFY"]
[Thu Sep 17 15:46:13.220189 2026] [security2:error] [pid 60716:tid 60916] [client 172.86.81.177:38532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.makingreligionhealthy.com"] [uri "/index.php"] [unique_id "aqxfncPsx0SVFjrd623aTQAAABg"], referer: http://mail.makingreligionhealthy.com/.git/config
[Thu Sep 17 15:46:13.395981 2026] [security2:error] [pid 60716:tid 60915] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/magento/.env"] [unique_id "aqxfpcPsx0SVFjrd623bygAAABc"]
[Thu Sep 17 15:46:13.469113 2026] [security2:error] [pid 60716:tid 60999] [client 216.38.230.114:52716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "zco.rbz.mybluehost.me"] [uri "/index.php"] [unique_id "aqxfpcPsx0SVFjrd623byQAAAGk"]
[Thu Sep 17 15:46:13.588678 2026] [security2:error] [pid 60716:tid 60899] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/shopify/.env"] [unique_id "aqxfpcPsx0SVFjrd623b1AAAAAc"]
[Thu Sep 17 15:46:13.631958 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.34.14:38534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/info.php"] [unique_id "aqxfpcPsx0SVFjrd623b2AAAAHM"]
[Thu Sep 17 15:46:13.733238 2026] [security2:error] [pid 60716:tid 60965] [client 3.19.142.206:54822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itsonyou.org"] [uri "/index.php"] [unique_id "aqxfpcPsx0SVFjrd623bzgAAAEc"]
[Thu Sep 17 15:46:13.771752 2026] [security2:error] [pid 60716:tid 60988] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxfpcPsx0SVFjrd623b4AAAAF4"]
[Thu Sep 17 15:46:13.777430 2026] [security2:error] [pid 60716:tid 60942] [client 186.19.66.165:59678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxfpMPsx0SVFjrd623brAAAMAs"], referer: https://seandaviddeezyn.com
[Thu Sep 17 15:46:13.778320 2026] [security2:error] [pid 60716:tid 60991] [client 74.7.228.2:35014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "aqxfpcPsx0SVFjrd623bzwAAAGE"]
[Thu Sep 17 15:46:13.815317 2026] [security2:error] [pid 60716:tid 60970] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/prestashop/.env"] [unique_id "aqxfpcPsx0SVFjrd623b4QAAAEw"]
[Thu Sep 17 15:46:13.862853 2026] [security2:error] [pid 60716:tid 60911] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpcPsx0SVFjrd623b5QAAABM"], referer: https://cpcalendars.rac.psw.mybluehost.me/robots.txt
[Thu Sep 17 15:46:13.907605 2026] [security2:error] [pid 60716:tid 60974] [client 74.7.228.2:35014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpcPsx0SVFjrd623b4gAAAFA"], referer: https://cpcalendars.rac.psw.mybluehost.me/robots.txt
[Thu Sep 17 15:46:14.007723 2026] [security2:error] [pid 60716:tid 60910] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpsPsx0SVFjrd623b7wAAABI"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.011747 2026] [security2:error] [pid 60716:tid 60936] [client 74.7.228.2:35014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpcPsx0SVFjrd623b7QAAACo"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.032004 2026] [security2:error] [pid 60716:tid 60906] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/codeigniter/.env"] [unique_id "aqxfpsPsx0SVFjrd623b8gAAAA4"]
[Thu Sep 17 15:46:14.102545 2026] [security2:error] [pid 60716:tid 61007] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpsPsx0SVFjrd623b9gAAAHE"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.105648 2026] [security2:error] [pid 60716:tid 60901] [client 74.7.228.2:35014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpsPsx0SVFjrd623b9AAAAAk"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.171102 2026] [security2:error] [pid 60716:tid 60946] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpsPsx0SVFjrd623b_AAAADQ"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.182254 2026] [security2:error] [pid 60716:tid 61008] [client 74.7.228.2:35014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpsPsx0SVFjrd623b-gAAAHI"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.256183 2026] [security2:error] [pid 60716:tid 60959] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpsPsx0SVFjrd623cAwAAAEE"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.259012 2026] [security2:error] [pid 60716:tid 60940] [client 74.7.228.2:35014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "cpcalendars.rac.psw.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/suspendedpage.cgi"] [unique_id "aqxfpsPsx0SVFjrd623cAAAAAC4"], referer: https://cpcalendars.rac.psw.mybluehost.me/cgi-sys/suspendedpage.cgi
[Thu Sep 17 15:46:14.313150 2026] [security2:error] [pid 60716:tid 61012] [client 34.166.34.14:38548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/php.php"] [unique_id "aqxfpsPsx0SVFjrd623cBQAAAHY"]
[Thu Sep 17 15:46:14.347861 2026] [security2:error] [pid 60716:tid 60999] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/cakephp/.env"] [unique_id "aqxfpsPsx0SVFjrd623cCAAAAGk"]
[Thu Sep 17 15:46:14.518717 2026] [security2:error] [pid 60716:tid 60915] [client 34.154.246.111:35600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/app/.env"] [unique_id "aqxfpsPsx0SVFjrd623cCwAAABc"]
[Thu Sep 17 15:46:14.550852 2026] [security2:error] [pid 60716:tid 60933] [client 74.7.228.46:58902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-479c4541.qwr.qfv.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxfpsPsx0SVFjrd623cDAAAACc"]
[Thu Sep 17 15:46:14.662219 2026] [security2:error] [pid 60716:tid 60986] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/zend/.env"] [unique_id "aqxfpsPsx0SVFjrd623cDwAAAFw"]
[Thu Sep 17 15:46:14.703081 2026] [security2:error] [pid 60716:tid 60905] [client 34.154.246.111:35600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/apps/.env"] [unique_id "aqxfpsPsx0SVFjrd623cEgAAAA0"]
[Thu Sep 17 15:46:14.862167 2026] [security2:error] [pid 60716:tid 60988] [client 34.154.246.111:35600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/api/.env"] [unique_id "aqxfpsPsx0SVFjrd623cGAAAAF4"]
[Thu Sep 17 15:46:14.863970 2026] [security2:error] [pid 60716:tid 60990] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/yii/.env"] [unique_id "aqxfpsPsx0SVFjrd623cGQAAAGA"]
[Thu Sep 17 15:46:15.012043 2026] [security2:error] [pid 60716:tid 60914] [client 127.0.0.1:55120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "aqxfpsPsx0SVFjrd623cHgAAABY"]
[Thu Sep 17 15:46:15.012142 2026] [security2:error] [pid 60716:tid 61020] [client 74.7.230.6:48508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.bei.abv.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxfpsPsx0SVFjrd623cHQAAfls"]
[Thu Sep 17 15:46:15.024522 2026] [security2:error] [pid 60716:tid 61015] [client 34.166.34.14:38556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/i.php"] [unique_id "aqxfp8Psx0SVFjrd623cHwAAAHk"]
[Thu Sep 17 15:46:15.025354 2026] [security2:error] [pid 60716:tid 60934] [client 79.116.89.151:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfp8Psx0SVFjrd623cIAAAACg"]
[Thu Sep 17 15:46:15.026038 2026] [security2:error] [pid 60716:tid 60934] [client 79.116.89.151:59845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfp8Psx0SVFjrd623cIAAAACg"]
[Thu Sep 17 15:46:15.082638 2026] [security2:error] [pid 60716:tid 60919] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/laravel5/.env"] [unique_id "aqxfp8Psx0SVFjrd623cIwAAABs"]
[Thu Sep 17 15:46:15.105076 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.246.111:35600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/web/.env"] [unique_id "aqxfp8Psx0SVFjrd623cJAAAAFk"]
[Thu Sep 17 15:46:15.238342 2026] [security2:error] [pid 60716:tid 60939] [client 138.36.215.160:31727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfp8Psx0SVFjrd623cIgAALQM"]
[Thu Sep 17 15:46:15.314563 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.246.111:35600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/site/.env"] [unique_id "aqxfp8Psx0SVFjrd623cMAAAAEM"]
[Thu Sep 17 15:46:15.324357 2026] [security2:error] [pid 60716:tid 61000] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/v1/.env"] [unique_id "aqxfp8Psx0SVFjrd623cMQAAAGo"]
[Thu Sep 17 15:46:15.427395 2026] [security2:error] [pid 60716:tid 60901] [client 158.173.67.247:24199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.67.173.158.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "churchinirving.christiansoncampusnlc.com"] [uri "/xmlrpc.php"] [unique_id "aqxfp8Psx0SVFjrd623cNgAAAAk"]
[Thu Sep 17 15:46:15.525916 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.246.111:35600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/public/.env"] [unique_id "aqxfp8Psx0SVFjrd623cOAAAAGs"]
[Thu Sep 17 15:46:15.590619 2026] [security2:error] [pid 60716:tid 60904] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/v2/.env"] [unique_id "aqxfp8Psx0SVFjrd623cOwAAAAw"]
[Thu Sep 17 15:46:15.718306 2026] [security2:error] [pid 60716:tid 60963] [client 34.166.34.14:38558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/pi.php"] [unique_id "aqxfp8Psx0SVFjrd623cQgAAAEU"]
[Thu Sep 17 15:46:15.830438 2026] [security2:error] [pid 60716:tid 61004] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/v3/.env"] [unique_id "aqxfp8Psx0SVFjrd623cQwAAAG4"]
[Thu Sep 17 15:46:16.085697 2026] [security2:error] [pid 60716:tid 61021] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/api/v1/.env"] [unique_id "aqxfqMPsx0SVFjrd623cSQAAAH8"]
[Thu Sep 17 15:46:16.102545 2026] [security2:error] [pid 60716:tid 60903] [client 129.212.220.28:52346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.220.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chriswestlake.com"] [uri "/phpinfo.php"] [unique_id "aqxfqMPsx0SVFjrd623cSwAAAAs"]
[Thu Sep 17 15:46:16.293280 2026] [security2:error] [pid 60716:tid 60990] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/api/v2/.env"] [unique_id "aqxfqMPsx0SVFjrd623cUwAAAGA"]
[Thu Sep 17 15:46:16.353341 2026] [security2:error] [pid 60716:tid 60900] [client 3.19.142.206:55982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cWAAAAAg"]
[Thu Sep 17 15:46:16.353384 2026] [security2:error] [pid 60716:tid 60900] [client 3.19.142.206:55982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cWAAAAAg"]
[Thu Sep 17 15:46:16.354438 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/backend/.env"] [unique_id "aqxfqMPsx0SVFjrd623cWQAAAA8"]
[Thu Sep 17 15:46:16.360236 2026] [security2:error] [pid 60716:tid 60909] [client 3.19.142.206:55980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cWgAAABE"]
[Thu Sep 17 15:46:16.360273 2026] [security2:error] [pid 60716:tid 60909] [client 3.19.142.206:55980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cWgAAABE"]
[Thu Sep 17 15:46:16.363192 2026] [security2:error] [pid 60716:tid 60908] [client 3.19.142.206:55979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cWwAAABA"]
[Thu Sep 17 15:46:16.363226 2026] [security2:error] [pid 60716:tid 60908] [client 3.19.142.206:55979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cWwAAABA"]
[Thu Sep 17 15:46:16.400368 2026] [security2:error] [pid 60716:tid 60986] [client 34.166.34.14:38574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/pinfo.php"] [unique_id "aqxfqMPsx0SVFjrd623cXwAAAFw"]
[Thu Sep 17 15:46:16.486705 2026] [security2:error] [pid 60716:tid 60919] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/rest/.env"] [unique_id "aqxfqMPsx0SVFjrd623cYQAAABs"]
[Thu Sep 17 15:46:16.519832 2026] [security2:error] [pid 60716:tid 60976] [client 3.19.142.206:55982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cYgAAAFI"]
[Thu Sep 17 15:46:16.519886 2026] [security2:error] [pid 60716:tid 60976] [client 3.19.142.206:55982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itsonyou.org"] [uri "/site/xmlrpc.php"] [unique_id "aqxfqMPsx0SVFjrd623cYgAAAFI"]
[Thu Sep 17 15:46:16.541034 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/server/.env"] [unique_id "aqxfqMPsx0SVFjrd623cYwAAAHA"]
[Thu Sep 17 15:46:16.691215 2026] [security2:error] [pid 60716:tid 61000] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/graphql/.env"] [unique_id "aqxfqMPsx0SVFjrd623caQAAAGo"]
[Thu Sep 17 15:46:16.785441 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/frontend/.env"] [unique_id "aqxfqMPsx0SVFjrd623cagAAADM"]
[Thu Sep 17 15:46:16.945548 2026] [security2:error] [pid 60716:tid 60901] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/gateway/.env"] [unique_id "aqxfqMPsx0SVFjrd623ccAAAAAk"]
[Thu Sep 17 15:46:16.953222 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/src/.env"] [unique_id "aqxfqMPsx0SVFjrd623ccQAAABM"]
[Thu Sep 17 15:46:17.089344 2026] [security2:error] [pid 60716:tid 60997] [client 34.166.34.14:38588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/test.php"] [unique_id "aqxfqcPsx0SVFjrd623cdAAAAGc"]
[Thu Sep 17 15:46:17.139721 2026] [security2:error] [pid 60716:tid 60898] [client 98.169.60.119:43893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfqcPsx0SVFjrd623ccgAABlc"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:46:17.168432 2026] [security2:error] [pid 60716:tid 60994] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/microservice/.env"] [unique_id "aqxfqcPsx0SVFjrd623ceAAAAGQ"]
[Thu Sep 17 15:46:17.174371 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/core/.env"] [unique_id "aqxfqcPsx0SVFjrd623ceQAAAGs"]
[Thu Sep 17 15:46:17.283884 2026] [security2:error] [pid 60716:tid 60925] [client 4.240.114.86:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "aqxfqcPsx0SVFjrd623cegAAACA"], referer: binance.com
[Thu Sep 17 15:46:17.335350 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/core/app/.env"] [unique_id "aqxfqcPsx0SVFjrd623cfAAAABo"]
[Thu Sep 17 15:46:17.452882 2026] [security2:error] [pid 60716:tid 60929] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/service/.env"] [unique_id "aqxfqcPsx0SVFjrd623cgAAAACQ"]
[Thu Sep 17 15:46:17.574319 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/config/.env"] [unique_id "aqxfqcPsx0SVFjrd623cggAAAFs"]
[Thu Sep 17 15:46:17.594875 2026] [fcgid:warn] [pid 60716:tid 61014] (70014)End of file found: [client 152.32.235.107:40750] mod_fcgid: can't get data from http client
[Thu Sep 17 15:46:17.671124 2026] [security2:error] [pid 60716:tid 60975] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/api/v3/.env"] [unique_id "aqxfqcPsx0SVFjrd623chAAAAFE"]
[Thu Sep 17 15:46:17.739796 2026] [security2:error] [pid 60716:tid 61017] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/private/.env"] [unique_id "aqxfqcPsx0SVFjrd623ciAAAAHs"]
[Thu Sep 17 15:46:17.900605 2026] [security2:error] [pid 60716:tid 60943] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/api/dev/.env"] [unique_id "aqxfqcPsx0SVFjrd623clgAAADE"]
[Thu Sep 17 15:46:17.969994 2026] [security2:error] [pid 60716:tid 60899] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/application/.env"] [unique_id "aqxfqcPsx0SVFjrd623clwAAAAc"]
[Thu Sep 17 15:46:18.013521 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.34.14:38590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/p.php"] [unique_id "aqxfqsPsx0SVFjrd623cmAAAAHM"]
[Thu Sep 17 15:46:18.105931 2026] [security2:error] [pid 60716:tid 60991] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/api/staging/.env"] [unique_id "aqxfqsPsx0SVFjrd623cmgAAAGE"]
[Thu Sep 17 15:46:18.141894 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/bootstrap/.env"] [unique_id "aqxfqsPsx0SVFjrd623cmwAAAA8"]
[Thu Sep 17 15:46:18.203012 2026] [security2:error] [pid 60716:tid 60933] [client 201.40.33.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "idautovic.com"] [uri "/index.php"] [unique_id "aqxfqcPsx0SVFjrd623clQAAACc"], referer: https://idautovic.com
[Thu Sep 17 15:46:18.305423 2026] [security2:error] [pid 60716:tid 61015] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/vendor/.env"] [unique_id "aqxfqsPsx0SVFjrd623cowAAAHk"]
[Thu Sep 17 15:46:18.319460 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/database/.env"] [unique_id "aqxfqsPsx0SVFjrd623cpAAAABs"]
[Thu Sep 17 15:46:18.374260 2026] [security2:error] [pid 60716:tid 60927] [client 98.169.60.119:45695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfqsPsx0SVFjrd623cogAAIlE"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818122733&hideanons=1&limit=250&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:46:18.488250 2026] [security2:error] [pid 60716:tid 60941] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/lib/.env"] [unique_id "aqxfqsPsx0SVFjrd623crAAAAC8"]
[Thu Sep 17 15:46:18.598424 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/storage/.env"] [unique_id "aqxfqsPsx0SVFjrd623crwAAAA4"]
[Thu Sep 17 15:46:18.683573 2026] [security2:error] [pid 60716:tid 60916] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/resources/.env"] [unique_id "aqxfqsPsx0SVFjrd623csgAAABg"]
[Thu Sep 17 15:46:18.696606 2026] [security2:error] [pid 60716:tid 60974] [client 34.166.34.14:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/debug.php"] [unique_id "aqxfqsPsx0SVFjrd623cswAAAFA"]
[Thu Sep 17 15:46:18.851373 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/var/www/.env"] [unique_id "aqxfqsPsx0SVFjrd623ctwAAADw"]
[Thu Sep 17 15:46:18.866370 2026] [security2:error] [pid 60716:tid 60911] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/assets/.env"] [unique_id "aqxfqsPsx0SVFjrd623cuQAAABM"]
[Thu Sep 17 15:46:18.965370 2026] [cgid:error] [pid 60716:tid 60786] [remote 200.231.6.3:25344] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:46:19.041298 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/var/www/html/.env"] [unique_id "aqxfq8Psx0SVFjrd623cvgAAAGY"]
[Thu Sep 17 15:46:19.119915 2026] [security2:error] [pid 60716:tid 60904] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/uploads/.env"] [unique_id "aqxfq8Psx0SVFjrd623cvwAAAAw"]
[Thu Sep 17 15:46:19.147897 2026] [security2:error] [pid 60716:tid 60952] [client 169.58.197.251:61877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxfq8Psx0SVFjrd623cwQAAADo"], referer: binance.com
[Thu Sep 17 15:46:19.299852 2026] [security2:error] [pid 60716:tid 60929] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/current/.env"] [unique_id "aqxfq8Psx0SVFjrd623cxgAAACQ"]
[Thu Sep 17 15:46:19.333412 2026] [security2:error] [pid 60716:tid 60985] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/internal/.env"] [unique_id "aqxfq8Psx0SVFjrd623cxwAAAFs"]
[Thu Sep 17 15:46:19.376463 2026] [security2:error] [pid 60716:tid 61008] [client 34.166.34.14:37422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxfq8Psx0SVFjrd623cygAAAHI"]
[Thu Sep 17 15:46:19.515533 2026] [security2:error] [pid 60716:tid 60940] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/release/.env"] [unique_id "aqxfq8Psx0SVFjrd623czQAAAC4"]
[Thu Sep 17 15:46:19.573047 2026] [security2:error] [pid 60716:tid 60928] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/tools/.env"] [unique_id "aqxfq8Psx0SVFjrd623czgAAACM"]
[Thu Sep 17 15:46:19.677158 2026] [security2:error] [pid 60716:tid 60905] [client 169.58.197.253:50283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxfq8Psx0SVFjrd623c0QAAAA0"], referer: binance.com
[Thu Sep 17 15:46:19.726684 2026] [security2:error] [pid 60716:tid 60895] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/releases/.env"] [unique_id "aqxfq8Psx0SVFjrd623c0wAAAAM"]
[Thu Sep 17 15:46:19.760262 2026] [security2:error] [pid 60716:tid 60968] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/scripts/.env"] [unique_id "aqxfq8Psx0SVFjrd623c1QAAAEo"]
[Thu Sep 17 15:46:19.955037 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/shared/.env"] [unique_id "aqxfq8Psx0SVFjrd623c3AAAAGE"]
[Thu Sep 17 15:46:20.019549 2026] [security2:error] [pid 60716:tid 60986] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/bin/.env"] [unique_id "aqxfrMPsx0SVFjrd623c3gAAAFw"]
[Thu Sep 17 15:46:20.056093 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.34.14:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/test/phpinfo.php"] [unique_id "aqxfrMPsx0SVFjrd623c3wAAAHM"]
[Thu Sep 17 15:46:20.151020 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/deploy/.env"] [unique_id "aqxfrMPsx0SVFjrd623c4AAAAD0"]
[Thu Sep 17 15:46:20.345553 2026] [security2:error] [pid 60716:tid 61016] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/sbin/.env"] [unique_id "aqxfrMPsx0SVFjrd623c6QAAAHo"]
[Thu Sep 17 15:46:20.378493 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/build/.env"] [unique_id "aqxfrMPsx0SVFjrd623c7QAAABU"]
[Thu Sep 17 15:46:20.559983 2026] [security2:error] [pid 60716:tid 60912] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/local/.env"] [unique_id "aqxfrMPsx0SVFjrd623c7wAAABQ"]
[Thu Sep 17 15:46:20.626478 2026] [security2:error] [pid 60716:tid 60970] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/dist/.env"] [unique_id "aqxfrMPsx0SVFjrd623c8AAAAEw"]
[Thu Sep 17 15:46:20.741069 2026] [security2:error] [pid 60716:tid 60934] [client 34.166.34.14:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxfrMPsx0SVFjrd623c9AAAACg"]
[Thu Sep 17 15:46:20.798889 2026] [security2:error] [pid 60716:tid 60977] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/public_html/.env"] [unique_id "aqxfrMPsx0SVFjrd623c9wAAAFM"]
[Thu Sep 17 15:46:20.799305 2026] [security2:error] [pid 60716:tid 60906] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/portal/.env"] [unique_id "aqxfrMPsx0SVFjrd623c-AAAAA4"]
[Thu Sep 17 15:46:20.988916 2026] [security2:error] [pid 60716:tid 60967] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/dashboard/.env"] [unique_id "aqxfrMPsx0SVFjrd623c_gAAAEk"]
[Thu Sep 17 15:46:21.005985 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/htdocs/.env"] [unique_id "aqxfrcPsx0SVFjrd623c_wAAAFg"]
[Thu Sep 17 15:46:21.068858 2026] [security2:error] [pid 60716:tid 60957] [client 103.61.184.148:63100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.184.61.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfrcPsx0SVFjrd623dAQAAAD8"]
[Thu Sep 17 15:46:21.068987 2026] [security2:error] [pid 60716:tid 60957] [client 103.61.184.148:63100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thechurchinirving.com"] [uri "/xmlrpc.php"] [unique_id "aqxfrcPsx0SVFjrd623dAQAAAD8"]
[Thu Sep 17 15:46:21.169117 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/www/.env"] [unique_id "aqxfrcPsx0SVFjrd623dAwAAABM"]
[Thu Sep 17 15:46:21.179348 2026] [security2:error] [pid 60716:tid 60998] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/panel/.env"] [unique_id "aqxfrcPsx0SVFjrd623dBAAAAGg"]
[Thu Sep 17 15:46:21.340524 2026] [security2:error] [pid 60716:tid 61003] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/html/.env"] [unique_id "aqxfrcPsx0SVFjrd623dCQAAAG0"]
[Thu Sep 17 15:46:21.417817 2026] [security2:error] [pid 60716:tid 60918] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/crm/.env"] [unique_id "aqxfrcPsx0SVFjrd623dDQAAABo"]
[Thu Sep 17 15:46:21.433036 2026] [security2:error] [pid 60716:tid 60997] [client 34.166.34.14:37454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/old/phpinfo.php"] [unique_id "aqxfrcPsx0SVFjrd623dDgAAAGc"]
[Thu Sep 17 15:46:21.550038 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/live/.env"] [unique_id "aqxfrcPsx0SVFjrd623dEAAAACA"]
[Thu Sep 17 15:46:21.625304 2026] [security2:error] [pid 60716:tid 60963] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/erp/.env"] [unique_id "aqxfrcPsx0SVFjrd623dEwAAAEU"]
[Thu Sep 17 15:46:21.724994 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/prod/.env"] [unique_id "aqxfrcPsx0SVFjrd623dGgAAADU"]
[Thu Sep 17 15:46:21.809845 2026] [security2:error] [pid 60716:tid 60940] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/shop/.env"] [unique_id "aqxfrcPsx0SVFjrd623dGwAAAC4"]
[Thu Sep 17 15:46:21.927839 2026] [security2:error] [pid 60716:tid 60905] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/dev/.env"] [unique_id "aqxfrcPsx0SVFjrd623dHgAAAA0"]
[Thu Sep 17 15:46:22.014636 2026] [security2:error] [pid 60716:tid 61005] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/store/.env"] [unique_id "aqxfrsPsx0SVFjrd623dIQAAAG8"]
[Thu Sep 17 15:46:22.120893 2026] [security2:error] [pid 60716:tid 60978] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/staging/.env"] [unique_id "aqxfrsPsx0SVFjrd623dJAAAAFQ"]
[Thu Sep 17 15:46:22.140038 2026] [security2:error] [pid 60716:tid 60892] [client 34.166.34.14:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfrsPsx0SVFjrd623dJQAAAAA"]
[Thu Sep 17 15:46:22.223491 2026] [security2:error] [pid 60716:tid 61018] [client 14.96.156.146:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfrsPsx0SVFjrd623dKQAAAHw"]
[Thu Sep 17 15:46:22.223616 2026] [security2:error] [pid 60716:tid 61018] [client 14.96.156.146:63584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfrsPsx0SVFjrd623dKQAAAHw"]
[Thu Sep 17 15:46:22.276600 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/opt/.env"] [unique_id "aqxfrsPsx0SVFjrd623dLQAAAGM"]
[Thu Sep 17 15:46:22.293968 2026] [security2:error] [pid 60716:tid 61009] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/saas/.env"] [unique_id "aqxfrsPsx0SVFjrd623dLgAAAHM"]
[Thu Sep 17 15:46:22.453443 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/laravel/.env"] [unique_id "aqxfrsPsx0SVFjrd623dMgAAABY"]
[Thu Sep 17 15:46:22.556826 2026] [security2:error] [pid 60716:tid 60919] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/client/.env"] [unique_id "aqxfrsPsx0SVFjrd623dOAAAABs"]
[Thu Sep 17 15:46:22.639682 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/symfony/.env"] [unique_id "aqxfrsPsx0SVFjrd623dPQAAAE0"]
[Thu Sep 17 15:46:22.651426 2026] [security2:error] [pid 60716:tid 60913] [client 20.15.133.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lemuspools.com"] [uri "/index.php"] [unique_id "aqxfrsPsx0SVFjrd623dNwAAABU"]
[Thu Sep 17 15:46:22.654228 2026] [security2:error] [pid 60716:tid 60908] [client 148.227.75.216:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfrsPsx0SVFjrd623dPwAAABA"]
[Thu Sep 17 15:46:22.654332 2026] [security2:error] [pid 60716:tid 60908] [client 148.227.75.216:58034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfrsPsx0SVFjrd623dPwAAABA"]
[Thu Sep 17 15:46:22.784176 2026] [security2:error] [pid 60716:tid 61019] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/project/.env"] [unique_id "aqxfrsPsx0SVFjrd623dRAAAAH0"]
[Thu Sep 17 15:46:22.836574 2026] [security2:error] [pid 60716:tid 61002] [client 34.166.34.14:37474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/public/phpinfo.php"] [unique_id "aqxfrsPsx0SVFjrd623dRQAAAGw"]
[Thu Sep 17 15:46:22.925548 2026] [security2:error] [pid 60716:tid 60957] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/wordpress/.env"] [unique_id "aqxfrsPsx0SVFjrd623dSQAAAD8"]
[Thu Sep 17 15:46:23.117887 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/wp/.env"] [unique_id "aqxfr8Psx0SVFjrd623dTAAAAEY"]
[Thu Sep 17 15:46:23.136607 2026] [security2:error] [pid 60716:tid 61007] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/admin-panel/.env"] [unique_id "aqxfr8Psx0SVFjrd623dTQAAAHE"]
[Thu Sep 17 15:46:23.294078 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cms/.env"] [unique_id "aqxfr8Psx0SVFjrd623dUQAAAHQ"]
[Thu Sep 17 15:46:23.337634 2026] [security2:error] [pid 60716:tid 60904] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/control-panel/.env"] [unique_id "aqxfr8Psx0SVFjrd623dVAAAAAw"]
[Thu Sep 17 15:46:23.387713 2026] [security2:error] [pid 60716:tid 60948] [client 143.105.152.240:19237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfr8Psx0SVFjrd623dVwAAADY"]
[Thu Sep 17 15:46:23.387856 2026] [security2:error] [pid 60716:tid 60948] [client 143.105.152.240:19237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfr8Psx0SVFjrd623dVwAAADY"]
[Thu Sep 17 15:46:23.502385 2026] [security2:error] [pid 60716:tid 61012] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/drupal/.env"] [unique_id "aqxfr8Psx0SVFjrd623dWgAAAHY"]
[Thu Sep 17 15:46:23.551895 2026] [security2:error] [pid 60716:tid 60922] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/user-panel/.env"] [unique_id "aqxfr8Psx0SVFjrd623dXQAAAB0"]
[Thu Sep 17 15:46:23.680815 2026] [security2:error] [pid 60716:tid 60946] [client 177.44.133.72:58355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfr8Psx0SVFjrd623dYwAAADQ"]
[Thu Sep 17 15:46:23.681357 2026] [security2:error] [pid 60716:tid 60946] [client 177.44.133.72:58355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfr8Psx0SVFjrd623dYwAAADQ"]
[Thu Sep 17 15:46:23.717475 2026] [security2:error] [pid 60716:tid 60905] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/joomla/.env"] [unique_id "aqxfr8Psx0SVFjrd623dZAAAAA0"]
[Thu Sep 17 15:46:23.757599 2026] [security2:error] [pid 60716:tid 60938] [client 34.166.34.14:37478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/php-info.php"] [unique_id "aqxfr8Psx0SVFjrd623dZgAAACw"]
[Thu Sep 17 15:46:23.875432 2026] [security2:error] [pid 60716:tid 61017] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/node/.env"] [unique_id "aqxfr8Psx0SVFjrd623daQAAAHs"]
[Thu Sep 17 15:46:23.932716 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/magento/.env"] [unique_id "aqxfr8Psx0SVFjrd623dawAAAAs"]
[Thu Sep 17 15:46:24.075023 2026] [security2:error] [pid 60716:tid 60991] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/express/.env"] [unique_id "aqxfsMPsx0SVFjrd623dbAAAAGE"]
[Thu Sep 17 15:46:24.130639 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/shopify/.env"] [unique_id "aqxfsMPsx0SVFjrd623dbQAAAA8"]
[Thu Sep 17 15:46:24.347792 2026] [security2:error] [pid 60716:tid 61016] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/next/.env"] [unique_id "aqxfsMPsx0SVFjrd623dcgAAAHo"]
[Thu Sep 17 15:46:24.403895 2026] [security2:error] [pid 60716:tid 60976] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/prestashop/.env"] [unique_id "aqxfsMPsx0SVFjrd623ddwAAAFI"]
[Thu Sep 17 15:46:24.440592 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.34.14:37482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/phpversion.php"] [unique_id "aqxfsMPsx0SVFjrd623deAAAAHM"]
[Thu Sep 17 15:46:24.615808 2026] [security2:error] [pid 60716:tid 60934] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/codeigniter/.env"] [unique_id "aqxfsMPsx0SVFjrd623dfQAAACg"]
[Thu Sep 17 15:46:24.703953 2026] [security2:error] [pid 60716:tid 60983] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/nuxt/.env"] [unique_id "aqxfsMPsx0SVFjrd623dggAAAFk"]
[Thu Sep 17 15:46:24.873836 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cakephp/.env"] [unique_id "aqxfsMPsx0SVFjrd623dhgAAADM"]
[Thu Sep 17 15:46:24.920919 2026] [security2:error] [pid 60716:tid 60931] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/nest/.env"] [unique_id "aqxfsMPsx0SVFjrd623diQAAACU"]
[Thu Sep 17 15:46:24.977936 2026] [security2:error] [pid 60716:tid 60982] [client 74.7.230.29:45558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saadpro.com"] [uri "/robots.txt"] [unique_id "aqxfsMPsx0SVFjrd623diwAAAFg"]
[Thu Sep 17 15:46:25.042943 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/zend/.env"] [unique_id "aqxfscPsx0SVFjrd623djAAAAAk"]
[Thu Sep 17 15:46:25.095225 2026] [security2:error] [pid 60716:tid 60956] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/react/.env"] [unique_id "aqxfscPsx0SVFjrd623djQAAAD4"]
[Thu Sep 17 15:46:25.119063 2026] [security2:error] [pid 60716:tid 60916] [client 34.166.34.14:37490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/_phpinfo.php"] [unique_id "aqxfscPsx0SVFjrd623djgAAABg"]
[Thu Sep 17 15:46:25.210083 2026] [security2:error] [pid 60716:tid 60998] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/yii/.env"] [unique_id "aqxfscPsx0SVFjrd623dkwAAAGg"]
[Thu Sep 17 15:46:25.323293 2026] [security2:error] [pid 60716:tid 61003] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/vue/.env"] [unique_id "aqxfscPsx0SVFjrd623dlwAAAG0"]
[Thu Sep 17 15:46:25.411364 2026] [security2:error] [pid 60716:tid 60902] [client 69.255.170.121:56997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfscPsx0SVFjrd623dlgAACm4"], referer: https://www.google.com/
[Thu Sep 17 15:46:25.437384 2026] [security2:error] [pid 60716:tid 60984] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/laravel5/.env"] [unique_id "aqxfscPsx0SVFjrd623dnAAAAFo"]
[Thu Sep 17 15:46:25.552968 2026] [security2:error] [pid 60716:tid 60997] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/angular/.env"] [unique_id "aqxfscPsx0SVFjrd623dngAAAGc"]
[Thu Sep 17 15:46:25.605341 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/v1/.env"] [unique_id "aqxfscPsx0SVFjrd623dnwAAAGQ"]
[Thu Sep 17 15:46:25.686417 2026] [security2:error] [pid 60716:tid 61010] [client 79.116.89.151:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfscPsx0SVFjrd623dowAAAHQ"]
[Thu Sep 17 15:46:25.686589 2026] [security2:error] [pid 60716:tid 61010] [client 79.116.89.151:60493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfscPsx0SVFjrd623dowAAAHQ"]
[Thu Sep 17 15:46:25.736890 2026] [security2:error] [pid 60716:tid 60791] [remote 122.14.227.72:45364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "golovefoundation.org"] [uri "/main/wp-content/uploads/2022/07/NL_SS-2022-C-v3.pdf"] [unique_id "aqxfscPsx0SVFjrd623dpQAAdR0"]
[Thu Sep 17 15:46:25.763668 2026] [security2:error] [pid 60716:tid 60922] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/v2/.env"] [unique_id "aqxfscPsx0SVFjrd623dpgAAAB0"]
[Thu Sep 17 15:46:25.812093 2026] [security2:error] [pid 60716:tid 61001] [client 34.166.34.14:37506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/old_phpinfo.php"] [unique_id "aqxfscPsx0SVFjrd623dqQAAAGs"]
[Thu Sep 17 15:46:25.848620 2026] [security2:error] [pid 60716:tid 60946] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/svelte/.env"] [unique_id "aqxfscPsx0SVFjrd623dqwAAADQ"]
[Thu Sep 17 15:46:26.004551 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/v3/.env"] [unique_id "aqxfssPsx0SVFjrd623drQAAAAs"]
[Thu Sep 17 15:46:26.014873 2026] [security2:error] [pid 60716:tid 60999] [client 136.158.61.34:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfssPsx0SVFjrd623drgAAAGk"]
[Thu Sep 17 15:46:26.014984 2026] [security2:error] [pid 60716:tid 60999] [client 136.158.61.34:62507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfssPsx0SVFjrd623drgAAAGk"]
[Thu Sep 17 15:46:26.125136 2026] [security2:error] [pid 60716:tid 60928] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/vite/.env"] [unique_id "aqxfssPsx0SVFjrd623dsAAAACM"]
[Thu Sep 17 15:46:26.203603 2026] [security2:error] [pid 60716:tid 60965] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/api/v1/.env"] [unique_id "aqxfssPsx0SVFjrd623dswAAAEc"]
[Thu Sep 17 15:46:26.491461 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.34.14:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/server-info.php"] [unique_id "aqxfssPsx0SVFjrd623dtgAAAAc"]
[Thu Sep 17 15:46:26.493621 2026] [security2:error] [pid 60716:tid 61004] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/api/v2/.env"] [unique_id "aqxfssPsx0SVFjrd623dtwAAAG4"]
[Thu Sep 17 15:46:26.526688 2026] [security2:error] [pid 60716:tid 60976] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/backup/.env"] [unique_id "aqxfssPsx0SVFjrd623duAAAAFI"]
[Thu Sep 17 15:46:26.694017 2026] [security2:error] [pid 60716:tid 60924] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/rest/.env"] [unique_id "aqxfssPsx0SVFjrd623dvAAAAB8"]
[Thu Sep 17 15:46:26.773211 2026] [security2:error] [pid 60716:tid 60969] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/backups/.env"] [unique_id "aqxfssPsx0SVFjrd623dvQAAAEs"]
[Thu Sep 17 15:46:26.890615 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/graphql/.env"] [unique_id "aqxfssPsx0SVFjrd623dwwAAABU"]
[Thu Sep 17 15:46:27.068615 2026] [security2:error] [pid 60716:tid 60970] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/old/.env"] [unique_id "aqxfs8Psx0SVFjrd623dygAAAEw"]
[Thu Sep 17 15:46:27.104854 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/gateway/.env"] [unique_id "aqxfs8Psx0SVFjrd623dywAAAGo"]
[Thu Sep 17 15:46:27.181395 2026] [security2:error] [pid 60716:tid 60944] [client 34.166.34.14:37530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/server-status.php"] [unique_id "aqxfs8Psx0SVFjrd623dzgAAADI"]
[Thu Sep 17 15:46:27.283599 2026] [security2:error] [pid 60716:tid 60900] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/tmp/.env"] [unique_id "aqxfs8Psx0SVFjrd623d0AAAAAg"]
[Thu Sep 17 15:46:27.324843 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/microservice/.env"] [unique_id "aqxfs8Psx0SVFjrd623d0gAAAFg"]
[Thu Sep 17 15:46:27.409754 2026] [security2:error] [pid 60716:tid 60774] [remote 47.128.43.166:12414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musingsofa50yearoldboy.com"] [uri "/robots.txt"] [unique_id "aqxfs8Psx0SVFjrd623d1gAAPw4"]
[Thu Sep 17 15:46:27.499711 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/service/.env"] [unique_id "aqxfs8Psx0SVFjrd623d1wAAADw"]
[Thu Sep 17 15:46:27.563574 2026] [security2:error] [pid 60716:tid 61003] [client 4.240.114.86:60205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "aqxfs8Psx0SVFjrd623d2gAAAG0"], referer: binance.com
[Thu Sep 17 15:46:27.618041 2026] [security2:error] [pid 60716:tid 60902] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/temp/.env"] [unique_id "aqxfs8Psx0SVFjrd623d3QAAAAo"]
[Thu Sep 17 15:46:27.666967 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/api/v3/.env"] [unique_id "aqxfs8Psx0SVFjrd623d4QAAAFE"]
[Thu Sep 17 15:46:27.811881 2026] [security2:error] [pid 60716:tid 60925] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/lab/.env"] [unique_id "aqxfs8Psx0SVFjrd623d5AAAACA"]
[Thu Sep 17 15:46:27.825581 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/api/dev/.env"] [unique_id "aqxfs8Psx0SVFjrd623d5QAAADU"]
[Thu Sep 17 15:46:27.988807 2026] [security2:error] [pid 60716:tid 60905] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/api/staging/.env"] [unique_id "aqxfs8Psx0SVFjrd623d6gAAAA0"]
[Thu Sep 17 15:46:28.040278 2026] [security2:error] [pid 60716:tid 60943] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/cronlab/.env"] [unique_id "aqxftMPsx0SVFjrd623d7AAAADE"]
[Thu Sep 17 15:46:28.041389 2026] [security2:error] [pid 60716:tid 60937] [client 74.7.230.40:45462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "seasiderita.fqr.plo.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxftMPsx0SVFjrd623d7QAAACs"]
[Thu Sep 17 15:46:28.189176 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/vendor/.env"] [unique_id "aqxftMPsx0SVFjrd623d8QAAAAY"]
[Thu Sep 17 15:46:28.224423 2026] [security2:error] [pid 60716:tid 60915] [client 169.58.197.251:62819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxftMPsx0SVFjrd623d8gAAABc"], referer: binance.com
[Thu Sep 17 15:46:28.300909 2026] [security2:error] [pid 60716:tid 60903] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/cron/.env"] [unique_id "aqxftMPsx0SVFjrd623d9QAAAAs"]
[Thu Sep 17 15:46:28.361145 2026] [security2:error] [pid 60716:tid 60935] [client 34.166.34.14:37544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxftMPsx0SVFjrd623d9wAAACk"]
[Thu Sep 17 15:46:28.364322 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/lib/.env"] [unique_id "aqxftMPsx0SVFjrd623d-AAAAAA"]
[Thu Sep 17 15:46:28.516880 2026] [security2:error] [pid 60716:tid 60965] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/en/.env"] [unique_id "aqxftMPsx0SVFjrd623d_gAAAEc"]
[Thu Sep 17 15:46:28.558342 2026] [security2:error] [pid 60716:tid 60986] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/resources/.env"] [unique_id "aqxftMPsx0SVFjrd623eAAAAAFw"]
[Thu Sep 17 15:46:28.810884 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/assets/.env"] [unique_id "aqxftMPsx0SVFjrd623eBgAAAFA"]
[Thu Sep 17 15:46:28.891594 2026] [security2:error] [pid 60716:tid 61004] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/administrator/.env"] [unique_id "aqxftMPsx0SVFjrd623eBwAAAG4"]
[Thu Sep 17 15:46:28.909512 2026] [autoindex:error] [pid 60716:tid 61006] [client 40.87.20.23:23842] AH01276: Cannot serve directory /home1/eishbfmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:46:28.966423 2026] [security2:error] [pid 60716:tid 60941] [client 169.58.197.253:50925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxftMPsx0SVFjrd623eDAAAAC8"], referer: binance.com
[Thu Sep 17 15:46:29.018122 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/uploads/.env"] [unique_id "aqxftcPsx0SVFjrd623eDQAAADg"]
[Thu Sep 17 15:46:29.051703 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.34.14:54682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxftcPsx0SVFjrd623eDwAAAAc"]
[Thu Sep 17 15:46:29.143289 2026] [security2:error] [pid 60716:tid 60911] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/psnlink/.env"] [unique_id "aqxftcPsx0SVFjrd623eEgAAABM"]
[Thu Sep 17 15:46:29.200313 2026] [security2:error] [pid 60716:tid 60981] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/internal/.env"] [unique_id "aqxftcPsx0SVFjrd623eFAAAAFc"]
[Thu Sep 17 15:46:29.367800 2026] [security2:error] [pid 60716:tid 60995] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/tools/.env"] [unique_id "aqxftcPsx0SVFjrd623eFwAAAGU"]
[Thu Sep 17 15:46:29.570467 2026] [security2:error] [pid 60716:tid 61019] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/exapi/.env"] [unique_id "aqxftcPsx0SVFjrd623eHQAAAH0"]
[Thu Sep 17 15:46:29.570467 2026] [security2:error] [pid 60716:tid 61002] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/scripts/.env"] [unique_id "aqxftcPsx0SVFjrd623eHgAAAGw"]
[Thu Sep 17 15:46:29.766636 2026] [security2:error] [pid 60716:tid 60912] [client 185.147.102.92:58078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxftcPsx0SVFjrd623eGwAAFAU"], referer: https://seandaviddeezyn.com
[Thu Sep 17 15:46:29.767394 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/bin/.env"] [unique_id "aqxftcPsx0SVFjrd623eIwAAAHE"]
[Thu Sep 17 15:46:29.855453 2026] [security2:error] [pid 60716:tid 60908] [client 34.166.34.14:54686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxftcPsx0SVFjrd623eJAAAABA"]
[Thu Sep 17 15:46:29.871381 2026] [security2:error] [pid 60716:tid 60987] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/sitemaps/.env"] [unique_id "aqxftcPsx0SVFjrd623eJQAAAF0"]
[Thu Sep 17 15:46:29.926082 2026] [security2:error] [pid 60716:tid 60894] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/sbin/.env"] [unique_id "aqxftcPsx0SVFjrd623eKQAAAAI"]
[Thu Sep 17 15:46:30.105979 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/local/.env"] [unique_id "aqxftsPsx0SVFjrd623eLwAAAHQ"]
[Thu Sep 17 15:46:30.283197 2026] [security2:error] [pid 60716:tid 60915] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/portal/.env"] [unique_id "aqxftsPsx0SVFjrd623eNwAAABc"]
[Thu Sep 17 15:46:30.398224 2026] [security2:error] [pid 60716:tid 60971] [client 167.172.45.115:56684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxftcPsx0SVFjrd623eFQAATUY"], referer: http://www.flyingbookshouse.com/new/
[Thu Sep 17 15:46:30.466419 2026] [security2:error] [pid 60716:tid 60937] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxftsPsx0SVFjrd623eNAAAACs"]
[Thu Sep 17 15:46:30.481458 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/dashboard/.env"] [unique_id "aqxftsPsx0SVFjrd623eOwAAAGk"]
[Thu Sep 17 15:46:30.553079 2026] [security2:error] [pid 60716:tid 61018] [client 34.166.34.14:54688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxftsPsx0SVFjrd623ePgAAAHw"]
[Thu Sep 17 15:46:30.655282 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/panel/.env"] [unique_id "aqxftsPsx0SVFjrd623eQAAAACM"]
[Thu Sep 17 15:46:30.833356 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/crm/.env"] [unique_id "aqxftsPsx0SVFjrd623eRwAAAGM"]
[Thu Sep 17 15:46:31.041574 2026] [security2:error] [pid 60716:tid 60909] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/erp/.env"] [unique_id "aqxft8Psx0SVFjrd623eTQAAABE"]
[Thu Sep 17 15:46:31.234823 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/shop/.env"] [unique_id "aqxft8Psx0SVFjrd623eXQAAACI"]
[Thu Sep 17 15:46:31.244058 2026] [security2:error] [pid 60716:tid 61020] [client 34.166.34.14:54694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxft8Psx0SVFjrd623eXgAAAH4"]
[Thu Sep 17 15:46:31.423175 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.246.111:46884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/store/.env"] [unique_id "aqxft8Psx0SVFjrd623eaQAAAAg"]
[Thu Sep 17 15:46:31.750171 2026] [security2:error] [pid 60716:tid 60908] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxft8Psx0SVFjrd623ecgAAABA"]
[Thu Sep 17 15:46:31.933136 2026] [security2:error] [pid 60716:tid 60952] [client 167.172.45.115:56684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxft8Psx0SVFjrd623eeAAAOmo"], referer: http://www.flyingbookshouse.com/wordpress/
[Thu Sep 17 15:46:31.935398 2026] [security2:error] [pid 60716:tid 61003] [client 34.166.34.14:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxft8Psx0SVFjrd623eewAAAG0"]
[Thu Sep 17 15:46:32.133520 2026] [security2:error] [pid 60716:tid 60985] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/saas/.env"] [unique_id "aqxfuMPsx0SVFjrd623egQAAAFs"]
[Thu Sep 17 15:46:32.140724 2026] [security2:error] [pid 60716:tid 60966] [client 167.172.45.115:56694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfuMPsx0SVFjrd623efgAASEU"], referer: https://www.flyingbookshouse.com/wordpress/
[Thu Sep 17 15:46:32.227684 2026] [security2:error] [pid 60716:tid 60939] [client 35.228.4.121:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/logs/.env"] [unique_id "aqxfuMPsx0SVFjrd623ehgAAAC0"]
[Thu Sep 17 15:46:32.329461 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/client/.env"] [unique_id "aqxfuMPsx0SVFjrd623eiwAAAGs"]
[Thu Sep 17 15:46:32.495832 2026] [security2:error] [pid 60716:tid 60971] [client 167.172.45.115:56684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfuMPsx0SVFjrd623ekAAATWc"], referer: http://www.flyingbookshouse.com/blog/
[Thu Sep 17 15:46:32.530871 2026] [security2:error] [pid 60716:tid 61008] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/project/.env"] [unique_id "aqxfuMPsx0SVFjrd623ekwAAAHI"]
[Thu Sep 17 15:46:32.607313 2026] [security2:error] [pid 60716:tid 60903] [client 179.6.47.25:32585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfuMPsx0SVFjrd623ekQAACzI"]
[Thu Sep 17 15:46:32.617644 2026] [security2:error] [pid 60716:tid 60915] [client 34.166.34.14:54712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxfuMPsx0SVFjrd623elgAAABc"]
[Thu Sep 17 15:46:32.699156 2026] [security2:error] [pid 60716:tid 60968] [client 167.172.45.115:56694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfuMPsx0SVFjrd623elwAASls"], referer: https://www.flyingbookshouse.com/blog/
[Thu Sep 17 15:46:32.743852 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/admin-panel/.env"] [unique_id "aqxfuMPsx0SVFjrd623enAAAACM"]
[Thu Sep 17 15:46:32.769861 2026] [security2:error] [pid 60716:tid 61013] [client 14.96.156.146:64245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfuMPsx0SVFjrd623enwAAAHc"]
[Thu Sep 17 15:46:32.769992 2026] [security2:error] [pid 60716:tid 61013] [client 14.96.156.146:64245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfuMPsx0SVFjrd623enwAAAHc"]
[Thu Sep 17 15:46:32.878127 2026] [security2:error] [pid 60716:tid 60917] [client 129.212.220.28:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.220.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chriswestlake.com"] [uri "/info.php"] [unique_id "aqxfuMPsx0SVFjrd623epgAAABk"]
[Thu Sep 17 15:46:32.913061 2026] [security2:error] [pid 60716:tid 60976] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/control-panel/.env"] [unique_id "aqxfuMPsx0SVFjrd623eqgAAAFI"]
[Thu Sep 17 15:46:33.053893 2026] [security2:error] [pid 60716:tid 60961] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/cache/.env"] [unique_id "aqxfucPsx0SVFjrd623eswAAAEM"]
[Thu Sep 17 15:46:33.059983 2026] [security2:error] [pid 60716:tid 60923] [client 167.172.45.115:56684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfucPsx0SVFjrd623esQAAHno"], referer: http://www.flyingbookshouse.com/backup/
[Thu Sep 17 15:46:33.136339 2026] [security2:error] [pid 60716:tid 61016] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/user-panel/.env"] [unique_id "aqxfucPsx0SVFjrd623ewwAAAHo"]
[Thu Sep 17 15:46:33.203676 2026] [security2:error] [pid 60716:tid 60893] [client 57.141.14.90:21702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireflyhotglass.net"] [uri "/index.php"] [unique_id "aqxfucPsx0SVFjrd623esgAAATo"]
[Thu Sep 17 15:46:33.290062 2026] [security2:error] [pid 60716:tid 60987] [client 167.172.45.115:56694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfucPsx0SVFjrd623eyAAAXW0"], referer: https://www.flyingbookshouse.com/backup/
[Thu Sep 17 15:46:33.306733 2026] [security2:error] [pid 60716:tid 60934] [client 148.227.75.216:42407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfucPsx0SVFjrd623eygAAACg"]
[Thu Sep 17 15:46:33.312640 2026] [security2:error] [pid 60716:tid 60934] [client 148.227.75.216:42407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfucPsx0SVFjrd623eygAAACg"]
[Thu Sep 17 15:46:33.314149 2026] [security2:error] [pid 60716:tid 60951] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/node/.env"] [unique_id "aqxfucPsx0SVFjrd623eywAAADk"]
[Thu Sep 17 15:46:33.319241 2026] [security2:error] [pid 60716:tid 61000] [client 34.166.34.14:54718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/phpinfo.php.old"] [unique_id "aqxfucPsx0SVFjrd623ezAAAAGo"]
[Thu Sep 17 15:46:33.329441 2026] [security2:error] [pid 60716:tid 60957] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mailer/.env"] [unique_id "aqxfucPsx0SVFjrd623ezQAAAD8"]
[Thu Sep 17 15:46:33.508846 2026] [security2:error] [pid 60716:tid 60954] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/express/.env"] [unique_id "aqxfucPsx0SVFjrd623e0wAAADw"]
[Thu Sep 17 15:46:33.648390 2026] [security2:error] [pid 60716:tid 60948] [client 167.172.45.115:56684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfucPsx0SVFjrd623e1QAANjg"], referer: http://www.flyingbookshouse.com/old/
[Thu Sep 17 15:46:33.703588 2026] [security2:error] [pid 60716:tid 60904] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mail/.env"] [unique_id "aqxfucPsx0SVFjrd623e2gAAAAw"]
[Thu Sep 17 15:46:33.741450 2026] [security2:error] [pid 60716:tid 60938] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/next/.env"] [unique_id "aqxfucPsx0SVFjrd623e3gAAACw"]
[Thu Sep 17 15:46:33.820189 2026] [security2:error] [pid 60716:tid 60895] [client 4.240.114.86:63008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "aqxfucPsx0SVFjrd623e4QAAAAM"], referer: binance.com
[Thu Sep 17 15:46:33.855081 2026] [security2:error] [pid 60716:tid 60898] [client 167.172.45.115:56694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfucPsx0SVFjrd623e4AAABgw"], referer: https://www.flyingbookshouse.com/old/
[Thu Sep 17 15:46:33.875928 2026] [security2:error] [pid 60716:tid 60958] [client 143.105.152.240:25375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfucPsx0SVFjrd623e4gAAAEA"]
[Thu Sep 17 15:46:33.884366 2026] [security2:error] [pid 60716:tid 60958] [client 143.105.152.240:25375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfucPsx0SVFjrd623e4gAAAEA"]
[Thu Sep 17 15:46:33.914142 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/nuxt/.env"] [unique_id "aqxfucPsx0SVFjrd623e5wAAAE0"]
[Thu Sep 17 15:46:34.002834 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.34.14:54724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/phpinfo.php~"] [unique_id "aqxfusPsx0SVFjrd623e6QAAAA0"]
[Thu Sep 17 15:46:34.061077 2026] [security2:error] [pid 60716:tid 60915] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/email/.env"] [unique_id "aqxfusPsx0SVFjrd623e6wAAABc"]
[Thu Sep 17 15:46:34.085858 2026] [security2:error] [pid 60716:tid 60941] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/nest/.env"] [unique_id "aqxfusPsx0SVFjrd623e7AAAAC8"]
[Thu Sep 17 15:46:34.219413 2026] [security2:error] [pid 60716:tid 60928] [client 167.172.45.115:56684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfusPsx0SVFjrd623e7gAAI1U"], referer: http://www.flyingbookshouse.com/wp/
[Thu Sep 17 15:46:34.251965 2026] [security2:error] [pid 60716:tid 60955] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/smtp/.env"] [unique_id "aqxfusPsx0SVFjrd623e8wAAAD0"]
[Thu Sep 17 15:46:34.267786 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/react/.env"] [unique_id "aqxfusPsx0SVFjrd623e9AAAADU"]
[Thu Sep 17 15:46:34.372637 2026] [security2:error] [pid 60716:tid 61005] [client 177.44.133.72:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfusPsx0SVFjrd623e9gAAAG8"]
[Thu Sep 17 15:46:34.372759 2026] [security2:error] [pid 60716:tid 61005] [client 177.44.133.72:59043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfusPsx0SVFjrd623e9gAAAG8"]
[Thu Sep 17 15:46:34.436230 2026] [security2:error] [pid 60716:tid 60992] [client 167.172.45.115:56694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flyingbookshouse.com"] [uri "/index.php"] [unique_id "aqxfusPsx0SVFjrd623e-AAAYmA"], referer: https://www.flyingbookshouse.com/wp/
[Thu Sep 17 15:46:34.474707 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/vue/.env"] [unique_id "aqxfusPsx0SVFjrd623e-wAAAEQ"]
[Thu Sep 17 15:46:34.545164 2026] [security2:error] [pid 60716:tid 60960] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mailing/.env"] [unique_id "aqxfusPsx0SVFjrd623e_QAAAEI"]
[Thu Sep 17 15:46:34.710547 2026] [security2:error] [pid 60716:tid 60914] [client 34.166.34.14:54736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/info.php.bak"] [unique_id "aqxfusPsx0SVFjrd623fBwAAABY"]
[Thu Sep 17 15:46:34.737703 2026] [security2:error] [pid 60716:tid 60907] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/notifications/.env"] [unique_id "aqxfusPsx0SVFjrd623fCQAAAA8"]
[Thu Sep 17 15:46:34.739898 2026] [security2:error] [pid 60716:tid 60897] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/angular/.env"] [unique_id "aqxfusPsx0SVFjrd623fCgAAAAU"]
[Thu Sep 17 15:46:34.907699 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/svelte/.env"] [unique_id "aqxfusPsx0SVFjrd623fDgAAACU"]
[Thu Sep 17 15:46:35.015589 2026] [security2:error] [pid 60716:tid 60998] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/notify/.env"] [unique_id "aqxfu8Psx0SVFjrd623fEAAAAGg"]
[Thu Sep 17 15:46:35.111099 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/vite/.env"] [unique_id "aqxfu8Psx0SVFjrd623fFAAAAF0"]
[Thu Sep 17 15:46:35.259530 2026] [security2:error] [pid 60716:tid 61007] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/sender/.env"] [unique_id "aqxfu8Psx0SVFjrd623fGwAAAHE"]
[Thu Sep 17 15:46:35.286646 2026] [fcgid:warn] [pid 60716:tid 60952] (70014)End of file found: [client 152.32.236.116:44478] mod_fcgid: can't get data from http client
[Thu Sep 17 15:46:35.336119 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/backup/.env"] [unique_id "aqxfu8Psx0SVFjrd623fHwAAAHg"]
[Thu Sep 17 15:46:35.381105 2026] [security2:error] [pid 60716:tid 60925] [client 169.58.197.251:63596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/connectors.php"] [unique_id "aqxfu8Psx0SVFjrd623fIAAAACA"], referer: binance.com
[Thu Sep 17 15:46:35.411122 2026] [security2:error] [pid 60716:tid 60956] [client 34.166.34.14:54750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/phpinfo.php.save"] [unique_id "aqxfu8Psx0SVFjrd623fIwAAAD4"]
[Thu Sep 17 15:46:35.472223 2026] [security2:error] [pid 60716:tid 60958] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/campaign/.env"] [unique_id "aqxfu8Psx0SVFjrd623fJQAAAEA"]
[Thu Sep 17 15:46:35.567380 2026] [security2:error] [pid 60716:tid 60937] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/backups/.env"] [unique_id "aqxfu8Psx0SVFjrd623fKAAAACs"]
[Thu Sep 17 15:46:35.724047 2026] [security2:error] [pid 60716:tid 60941] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/newsletter/.env"] [unique_id "aqxfu8Psx0SVFjrd623fLQAAAC8"]
[Thu Sep 17 15:46:35.736725 2026] [security2:error] [pid 60716:tid 60977] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/old/.env"] [unique_id "aqxfu8Psx0SVFjrd623fLgAAAFM"]
[Thu Sep 17 15:46:35.779143 2026] [security2:error] [pid 60716:tid 60972] [client 196.65.19.151:40074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfu8Psx0SVFjrd623fKgAATiU"]
[Thu Sep 17 15:46:35.907056 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/tmp/.env"] [unique_id "aqxfu8Psx0SVFjrd623fNgAAAAQ"]
[Thu Sep 17 15:46:35.912547 2026] [security2:error] [pid 60716:tid 60766] [remote 216.73.217.142:11112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxfu8Psx0SVFjrd623fNwAAYgc"]
[Thu Sep 17 15:46:35.958932 2026] [security2:error] [pid 60716:tid 60913] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/ses/.env"] [unique_id "aqxfu8Psx0SVFjrd623fOAAAABU"]
[Thu Sep 17 15:46:36.087361 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/temp/.env"] [unique_id "aqxfvMPsx0SVFjrd623fTAAAABg"]
[Thu Sep 17 15:46:36.094103 2026] [security2:error] [pid 60716:tid 60955] [client 34.166.34.14:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxfvMPsx0SVFjrd623fTQAAAD0"]
[Thu Sep 17 15:46:36.177632 2026] [security2:error] [pid 60716:tid 61002] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/sendgrid/.env"] [unique_id "aqxfvMPsx0SVFjrd623fUAAAAGw"]
[Thu Sep 17 15:46:36.249285 2026] [security2:error] [pid 60716:tid 60962] [client 79.116.89.151:61115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfvMPsx0SVFjrd623fUwAAAEQ"]
[Thu Sep 17 15:46:36.249407 2026] [security2:error] [pid 60716:tid 60962] [client 79.116.89.151:61115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfvMPsx0SVFjrd623fUwAAAEQ"]
[Thu Sep 17 15:46:36.259434 2026] [security2:error] [pid 60716:tid 60984] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/lab/.env"] [unique_id "aqxfvMPsx0SVFjrd623fVgAAAFo"]
[Thu Sep 17 15:46:36.447915 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cronlab/.env"] [unique_id "aqxfvMPsx0SVFjrd623fYQAAAGo"]
[Thu Sep 17 15:46:36.490667 2026] [security2:error] [pid 60716:tid 61010] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/sparkpost/.env"] [unique_id "aqxfvMPsx0SVFjrd623fZAAAAHQ"]
[Thu Sep 17 15:46:36.624725 2026] [security2:error] [pid 60716:tid 60966] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cron/.env"] [unique_id "aqxfvMPsx0SVFjrd623faAAAAEg"]
[Thu Sep 17 15:46:36.625605 2026] [security2:error] [pid 60716:tid 61011] [client 43.172.197.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxfvMPsx0SVFjrd623fYgAAAHU"]
[Thu Sep 17 15:46:36.694154 2026] [security2:error] [pid 60716:tid 60977] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/postmark/.env"] [unique_id "aqxfvMPsx0SVFjrd623fbAAAAFM"]
[Thu Sep 17 15:46:36.784097 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/en/.env"] [unique_id "aqxfvMPsx0SVFjrd623fbwAAABI"]
[Thu Sep 17 15:46:36.789530 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.34.14:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxfvMPsx0SVFjrd623fcAAAACA"]
[Thu Sep 17 15:46:36.884374 2026] [security2:error] [pid 60716:tid 60934] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mailgun/.env"] [unique_id "aqxfvMPsx0SVFjrd623fcwAAACg"]
[Thu Sep 17 15:46:37.049723 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/administrator/.env"] [unique_id "aqxfvMPsx0SVFjrd623fdwAAAFU"]
[Thu Sep 17 15:46:37.059335 2026] [security2:error] [pid 60716:tid 60959] [client 169.58.197.253:51477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxfvcPsx0SVFjrd623fegAAAEE"], referer: binance.com
[Thu Sep 17 15:46:37.202740 2026] [security2:error] [pid 60716:tid 60978] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mandrill/.env"] [unique_id "aqxfvcPsx0SVFjrd623ffwAAAFQ"]
[Thu Sep 17 15:46:37.266143 2026] [security2:error] [pid 60716:tid 60967] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/psnlink/.env"] [unique_id "aqxfvcPsx0SVFjrd623fggAAAEk"]
[Thu Sep 17 15:46:37.420162 2026] [security2:error] [pid 60716:tid 61004] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mailjet/.env"] [unique_id "aqxfvcPsx0SVFjrd623fhAAAAG4"]
[Thu Sep 17 15:46:37.470020 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/exapi/.env"] [unique_id "aqxfvcPsx0SVFjrd623fiAAAABM"]
[Thu Sep 17 15:46:37.476656 2026] [security2:error] [pid 60716:tid 60944] [client 34.166.34.14:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxfvcPsx0SVFjrd623fiQAAADI"]
[Thu Sep 17 15:46:37.642408 2026] [security2:error] [pid 60716:tid 60964] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/brevo/.env"] [unique_id "aqxfvcPsx0SVFjrd623fjwAAAEY"]
[Thu Sep 17 15:46:37.688700 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.246.111:37768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/sitemaps/.env"] [unique_id "aqxfvcPsx0SVFjrd623fkQAAADM"]
[Thu Sep 17 15:46:37.797805 2026] [security2:error] [pid 60716:tid 60894] [client 4.240.114.86:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "aqxfvcPsx0SVFjrd623flAAAAAI"], referer: binance.com
[Thu Sep 17 15:46:37.817068 2026] [security2:error] [pid 60716:tid 60962] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/transactional/.env"] [unique_id "aqxfvcPsx0SVFjrd623flQAAAEQ"]
[Thu Sep 17 15:46:38.091139 2026] [security2:error] [pid 60716:tid 60918] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/bulk/.env"] [unique_id "aqxfvsPsx0SVFjrd623fnAAAABo"]
[Thu Sep 17 15:46:38.171284 2026] [security2:error] [pid 60716:tid 60994] [client 34.166.34.14:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxfvsPsx0SVFjrd623foQAAAGQ"]
[Thu Sep 17 15:46:38.298763 2026] [security2:error] [pid 60716:tid 60922] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/aws/.env"] [unique_id "aqxfvsPsx0SVFjrd623fowAAAB0"]
[Thu Sep 17 15:46:38.495407 2026] [security2:error] [pid 60716:tid 60968] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/azure/.env"] [unique_id "aqxfvsPsx0SVFjrd623frAAAAEo"]
[Thu Sep 17 15:46:38.709422 2026] [security2:error] [pid 60716:tid 60934] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/gcp/.env"] [unique_id "aqxfvsPsx0SVFjrd623fsgAAACg"]
[Thu Sep 17 15:46:38.837774 2026] [security2:error] [pid 60716:tid 60941] [client 136.158.61.34:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfvsPsx0SVFjrd623fswAAAC8"]
[Thu Sep 17 15:46:38.837952 2026] [security2:error] [pid 60716:tid 60941] [client 136.158.61.34:63727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfvsPsx0SVFjrd623fswAAAC8"]
[Thu Sep 17 15:46:38.861306 2026] [security2:error] [pid 60716:tid 60943] [client 34.166.34.14:53458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxfvsPsx0SVFjrd623ftAAAADE"]
[Thu Sep 17 15:46:38.930969 2026] [security2:error] [pid 60716:tid 60992] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/cloud/.env"] [unique_id "aqxfvsPsx0SVFjrd623ftwAAAGI"]
[Thu Sep 17 15:46:38.933415 2026] [security2:error] [pid 60716:tid 60896] [client 34.166.197.112:39348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/phpinfo.php"] [unique_id "aqxfvsPsx0SVFjrd623ftQAAAAQ"]
[Thu Sep 17 15:46:39.138737 2026] [security2:error] [pid 60716:tid 60978] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/infrastructure/.env"] [unique_id "aqxfv8Psx0SVFjrd623fvAAAAFQ"]
[Thu Sep 17 15:46:39.180123 2026] [security2:error] [pid 60716:tid 60905] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/logs/.env"] [unique_id "aqxfv8Psx0SVFjrd623fvwAAAA0"]
[Thu Sep 17 15:46:39.310667 2026] [security2:error] [pid 60716:tid 60988] [client 90.35.72.31:52232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seandaviddeezyn.com"] [uri "/index.php"] [unique_id "aqxfv8Psx0SVFjrd623fuwAAXig"], referer: https://seandaviddeezyn.com
[Thu Sep 17 15:46:39.343668 2026] [security2:error] [pid 60716:tid 60907] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/docker/.env"] [unique_id "aqxfv8Psx0SVFjrd623fwQAAAA8"]
[Thu Sep 17 15:46:39.411323 2026] [security2:error] [pid 60716:tid 61008] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cache/.env"] [unique_id "aqxfv8Psx0SVFjrd623fwgAAAHI"]
[Thu Sep 17 15:46:39.515202 2026] [security2:error] [pid 60716:tid 61015] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/k8s/.env"] [unique_id "aqxfv8Psx0SVFjrd623fxwAAAHk"]
[Thu Sep 17 15:46:39.548840 2026] [security2:error] [pid 60716:tid 60961] [client 34.166.34.14:53460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/www/phpinfo.php"] [unique_id "aqxfv8Psx0SVFjrd623fyAAAAEM"]
[Thu Sep 17 15:46:39.571379 2026] [security2:error] [pid 60716:tid 60893] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mailer/.env"] [unique_id "aqxfv8Psx0SVFjrd623fyQAAAAE"]
[Thu Sep 17 15:46:39.620842 2026] [security2:error] [pid 60716:tid 61004] [client 34.166.197.112:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/info.php"] [unique_id "aqxfv8Psx0SVFjrd623fygAAAG4"]
[Thu Sep 17 15:46:39.701425 2026] [security2:error] [pid 60716:tid 60945] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/kubernetes/.env"] [unique_id "aqxfv8Psx0SVFjrd623fzwAAADM"]
[Thu Sep 17 15:46:39.855670 2026] [security2:error] [pid 60716:tid 60894] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mail/.env"] [unique_id "aqxfv8Psx0SVFjrd623f0wAAAAI"]
[Thu Sep 17 15:46:39.886981 2026] [security2:error] [pid 60716:tid 60962] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/terraform/.env"] [unique_id "aqxfv8Psx0SVFjrd623f1AAAAEQ"]
[Thu Sep 17 15:46:40.024127 2026] [security2:error] [pid 60716:tid 60897] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/email/.env"] [unique_id "aqxfwMPsx0SVFjrd623f2QAAAAU"]
[Thu Sep 17 15:46:40.107342 2026] [security2:error] [pid 60716:tid 61010] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/ansible/.env"] [unique_id "aqxfwMPsx0SVFjrd623f2gAAAHQ"]
[Thu Sep 17 15:46:40.224056 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/smtp/.env"] [unique_id "aqxfwMPsx0SVFjrd623f4AAAAGE"]
[Thu Sep 17 15:46:40.240460 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.34.14:53476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxfwMPsx0SVFjrd623f4QAAAAc"]
[Thu Sep 17 15:46:40.306994 2026] [security2:error] [pid 60716:tid 60951] [client 34.166.197.112:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/php.php"] [unique_id "aqxfwMPsx0SVFjrd623f5QAAADk"]
[Thu Sep 17 15:46:40.374268 2026] [security2:error] [pid 60716:tid 60936] [client 210.222.43.21:54591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxfwMPsx0SVFjrd623f3wAAACo"], referer: http://talent-in-borders.com/Blog
[Thu Sep 17 15:46:40.378492 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mailing/.env"] [unique_id "aqxfwMPsx0SVFjrd623f5gAAAAw"]
[Thu Sep 17 15:46:40.427261 2026] [security2:error] [pid 60716:tid 60956] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/.git/.env"] [unique_id "aqxfwMPsx0SVFjrd623f5wAAAD4"]
[Thu Sep 17 15:46:40.538727 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/notifications/.env"] [unique_id "aqxfwMPsx0SVFjrd623f7QAAAAY"]
[Thu Sep 17 15:46:40.687922 2026] [security2:error] [pid 60716:tid 60977] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/ci/.env"] [unique_id "aqxfwMPsx0SVFjrd623f7gAAAFM"]
[Thu Sep 17 15:46:40.737708 2026] [security2:error] [pid 60716:tid 60948] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/notify/.env"] [unique_id "aqxfwMPsx0SVFjrd623f8QAAADY"]
[Thu Sep 17 15:46:40.901864 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/sender/.env"] [unique_id "aqxfwMPsx0SVFjrd623f9QAAABI"]
[Thu Sep 17 15:46:40.937200 2026] [security2:error] [pid 60716:tid 60949] [client 34.166.34.14:53488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxfwMPsx0SVFjrd623f-AAAADc"]
[Thu Sep 17 15:46:40.945883 2026] [security2:error] [pid 60716:tid 60941] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/cd/.env"] [unique_id "aqxfwMPsx0SVFjrd623f-QAAAC8"]
[Thu Sep 17 15:46:41.000067 2026] [security2:error] [pid 60716:tid 60953] [client 34.166.197.112:37300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/i.php"] [unique_id "aqxfwMPsx0SVFjrd623f-wAAADs"]
[Thu Sep 17 15:46:41.097691 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/campaign/.env"] [unique_id "aqxfwcPsx0SVFjrd623f_gAAADU"]
[Thu Sep 17 15:46:41.136010 2026] [security2:error] [pid 60716:tid 60979] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/jenkins/.env"] [unique_id "aqxfwcPsx0SVFjrd623gAAAAAFU"]
[Thu Sep 17 15:46:41.268156 2026] [security2:error] [pid 60716:tid 61018] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/newsletter/.env"] [unique_id "aqxfwcPsx0SVFjrd623gBwAAAHw"]
[Thu Sep 17 15:46:41.421587 2026] [security2:error] [pid 60716:tid 60923] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/gitlab/.env"] [unique_id "aqxfwcPsx0SVFjrd623gDgAAAB4"]
[Thu Sep 17 15:46:41.465956 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/ses/.env"] [unique_id "aqxfwcPsx0SVFjrd623gFAAAAD0"]
[Thu Sep 17 15:46:41.616232 2026] [security2:error] [pid 60716:tid 60933] [client 34.166.34.14:53498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/site/phpinfo.php"] [unique_id "aqxfwcPsx0SVFjrd623gFgAAACc"]
[Thu Sep 17 15:46:41.641467 2026] [security2:error] [pid 60716:tid 60942] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/sendgrid/.env"] [unique_id "aqxfwcPsx0SVFjrd623gFwAAADA"]
[Thu Sep 17 15:46:41.686534 2026] [security2:error] [pid 60716:tid 61019] [client 34.166.197.112:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/pi.php"] [unique_id "aqxfwcPsx0SVFjrd623gGwAAAH0"]
[Thu Sep 17 15:46:41.753446 2026] [security2:error] [pid 60716:tid 60916] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/github/.env"] [unique_id "aqxfwcPsx0SVFjrd623gHAAAABg"]
[Thu Sep 17 15:46:41.811835 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/sparkpost/.env"] [unique_id "aqxfwcPsx0SVFjrd623gHQAAACk"]
[Thu Sep 17 15:46:41.900633 2026] [security2:error] [pid 60716:tid 60984] [client 192.178.6.3:37583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxfwcPsx0SVFjrd623gIAAAAFo"]
[Thu Sep 17 15:46:42.016071 2026] [security2:error] [pid 60716:tid 60929] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/actions/.env"] [unique_id "aqxfwsPsx0SVFjrd623gIQAAACQ"]
[Thu Sep 17 15:46:42.092986 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/postmark/.env"] [unique_id "aqxfwsPsx0SVFjrd623gJAAAAHE"]
[Thu Sep 17 15:46:42.185858 2026] [security2:error] [pid 60716:tid 60985] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/circleci/.env"] [unique_id "aqxfwsPsx0SVFjrd623gJwAAAFs"]
[Thu Sep 17 15:46:42.229399 2026] [security2:error] [pid 60716:tid 60990] [client 192.178.6.4:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxfwsPsx0SVFjrd623gKAAAAGA"]
[Thu Sep 17 15:46:42.260657 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mailgun/.env"] [unique_id "aqxfwsPsx0SVFjrd623gKgAAAA4"]
[Thu Sep 17 15:46:42.299695 2026] [security2:error] [pid 60716:tid 60912] [client 34.166.34.14:53514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxfwsPsx0SVFjrd623gKwAAABQ"]
[Thu Sep 17 15:46:42.301128 2026] [security2:error] [pid 60716:tid 60991] [client 4.240.114.86:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "aqxfwsPsx0SVFjrd623gLAAAAGE"], referer: binance.com
[Thu Sep 17 15:46:42.342839 2026] [security2:error] [pid 60716:tid 60969] [client 57.141.14.66:21836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.seedboxpress.com"] [uri "/index.php"] [unique_id "aqxfwsPsx0SVFjrd623gKQAASzE"]
[Thu Sep 17 15:46:42.370175 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.197.112:45064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/pinfo.php"] [unique_id "aqxfwsPsx0SVFjrd623gLwAAAF0"]
[Thu Sep 17 15:46:42.390798 2026] [security2:error] [pid 60716:tid 60924] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/travis/.env"] [unique_id "aqxfwsPsx0SVFjrd623gMAAAAB8"]
[Thu Sep 17 15:46:42.449934 2026] [security2:error] [pid 60716:tid 60994] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mandrill/.env"] [unique_id "aqxfwsPsx0SVFjrd623gMQAAAGQ"]
[Thu Sep 17 15:46:42.576590 2026] [security2:error] [pid 60716:tid 60971] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/buildkite/.env"] [unique_id "aqxfwsPsx0SVFjrd623gMwAAAE0"]
[Thu Sep 17 15:46:42.707048 2026] [security2:error] [pid 60716:tid 60895] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mailjet/.env"] [unique_id "aqxfwsPsx0SVFjrd623gOAAAAAM"]
[Thu Sep 17 15:46:42.871897 2026] [security2:error] [pid 60716:tid 60925] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mysql/.env"] [unique_id "aqxfwsPsx0SVFjrd623gQAAAACA"]
[Thu Sep 17 15:46:42.879188 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/brevo/.env"] [unique_id "aqxfwsPsx0SVFjrd623gQQAAAEU"]
[Thu Sep 17 15:46:42.981968 2026] [security2:error] [pid 60716:tid 60982] [client 34.166.34.14:53516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxfwsPsx0SVFjrd623gRQAAAFg"]
[Thu Sep 17 15:46:43.053117 2026] [security2:error] [pid 60716:tid 61014] [client 34.166.197.112:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/test.php"] [unique_id "aqxfw8Psx0SVFjrd623gRgAAAHg"]
[Thu Sep 17 15:46:43.103268 2026] [security2:error] [pid 60716:tid 60934] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/postgres/.env"] [unique_id "aqxfw8Psx0SVFjrd623gRwAAACg"]
[Thu Sep 17 15:46:43.161839 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/transactional/.env"] [unique_id "aqxfw8Psx0SVFjrd623gSAAAAAQ"]
[Thu Sep 17 15:46:43.347906 2026] [security2:error] [pid 60716:tid 61018] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/mongodb/.env"] [unique_id "aqxfw8Psx0SVFjrd623gTAAAAHw"]
[Thu Sep 17 15:46:43.390052 2026] [security2:error] [pid 60716:tid 60950] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/bulk/.env"] [unique_id "aqxfw8Psx0SVFjrd623gTgAAADg"]
[Thu Sep 17 15:46:43.494750 2026] [security2:error] [pid 60716:tid 60979] [client 14.96.156.146:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfw8Psx0SVFjrd623gUgAAAFU"]
[Thu Sep 17 15:46:43.494865 2026] [security2:error] [pid 60716:tid 60979] [client 14.96.156.146:64897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfw8Psx0SVFjrd623gUgAAAFU"]
[Thu Sep 17 15:46:43.544811 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/aws/.env"] [unique_id "aqxfw8Psx0SVFjrd623gUwAAABM"]
[Thu Sep 17 15:46:43.629358 2026] [security2:error] [pid 60716:tid 60939] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/redis/.env"] [unique_id "aqxfw8Psx0SVFjrd623gVAAAAC0"]
[Thu Sep 17 15:46:43.669622 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.34.14:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxfw8Psx0SVFjrd623gWQAAAB4"]
[Thu Sep 17 15:46:43.760404 2026] [security2:error] [pid 60716:tid 60976] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/azure/.env"] [unique_id "aqxfw8Psx0SVFjrd623gXQAAAFI"]
[Thu Sep 17 15:46:43.910216 2026] [security2:error] [pid 60716:tid 61002] [client 148.227.75.216:43907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfw8Psx0SVFjrd623gXwAAAGw"]
[Thu Sep 17 15:46:43.910332 2026] [security2:error] [pid 60716:tid 61002] [client 148.227.75.216:43907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfw8Psx0SVFjrd623gXwAAAGw"]
[Thu Sep 17 15:46:43.949531 2026] [security2:error] [pid 60716:tid 60907] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/elasticsearch/.env"] [unique_id "aqxfw8Psx0SVFjrd623gYAAAAA8"]
[Thu Sep 17 15:46:43.962610 2026] [security2:error] [pid 60716:tid 60998] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/gcp/.env"] [unique_id "aqxfw8Psx0SVFjrd623gYQAAAGg"]
[Thu Sep 17 15:46:43.962827 2026] [security2:error] [pid 60716:tid 60916] [client 169.58.197.251:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/fonts.php"] [unique_id "aqxfw8Psx0SVFjrd623gYwAAABg"], referer: binance.com
[Thu Sep 17 15:46:43.986523 2026] [security2:error] [pid 60716:tid 60935] [client 34.166.197.112:45082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/p.php"] [unique_id "aqxfw8Psx0SVFjrd623gZQAAACk"]
[Thu Sep 17 15:46:44.130306 2026] [security2:error] [pid 60716:tid 60990] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/rabbitmq/.env"] [unique_id "aqxfxMPsx0SVFjrd623gagAAAGA"]
[Thu Sep 17 15:46:44.132280 2026] [security2:error] [pid 60716:tid 60906] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cloud/.env"] [unique_id "aqxfxMPsx0SVFjrd623gawAAAA4"]
[Thu Sep 17 15:46:44.305199 2026] [security2:error] [pid 60716:tid 61010] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/kafka/.env"] [unique_id "aqxfxMPsx0SVFjrd623gbwAAAHQ"]
[Thu Sep 17 15:46:44.330689 2026] [security2:error] [pid 60716:tid 60997] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/infrastructure/.env"] [unique_id "aqxfxMPsx0SVFjrd623gcAAAAGc"]
[Thu Sep 17 15:46:44.353331 2026] [security2:error] [pid 60716:tid 60985] [client 34.166.34.14:53524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/core/phpinfo.php"] [unique_id "aqxfxMPsx0SVFjrd623gcQAAAFs"]
[Thu Sep 17 15:46:44.495483 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/docker/.env"] [unique_id "aqxfxMPsx0SVFjrd623gdgAAAGs"]
[Thu Sep 17 15:46:44.503001 2026] [security2:error] [pid 60716:tid 60926] [client 143.105.152.240:32363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfxMPsx0SVFjrd623gdwAAACE"]
[Thu Sep 17 15:46:44.503107 2026] [security2:error] [pid 60716:tid 60926] [client 143.105.152.240:32363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfxMPsx0SVFjrd623gdwAAACE"]
[Thu Sep 17 15:46:44.565642 2026] [security2:error] [pid 60716:tid 60937] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/queue/.env"] [unique_id "aqxfxMPsx0SVFjrd623gegAAACs"]
[Thu Sep 17 15:46:44.674954 2026] [security2:error] [pid 60716:tid 60956] [client 34.166.197.112:45096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/debug.php"] [unique_id "aqxfxMPsx0SVFjrd623gfQAAAD4"]
[Thu Sep 17 15:46:44.683053 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/k8s/.env"] [unique_id "aqxfxMPsx0SVFjrd623gfgAAAAY"]
[Thu Sep 17 15:46:44.692685 2026] [security2:error] [pid 60716:tid 61013] [client 143.55.133.68:59398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfxMPsx0SVFjrd623geQAAdwQ"]
[Thu Sep 17 15:46:44.790459 2026] [security2:error] [pid 60716:tid 61012] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/worker/.env"] [unique_id "aqxfxMPsx0SVFjrd623ggAAAAHY"]
[Thu Sep 17 15:46:44.860910 2026] [security2:error] [pid 60716:tid 60946] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/kubernetes/.env"] [unique_id "aqxfxMPsx0SVFjrd623gggAAADQ"]
[Thu Sep 17 15:46:44.967882 2026] [security2:error] [pid 60716:tid 60892] [client 177.44.133.72:59716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfxMPsx0SVFjrd623gigAAAAA"]
[Thu Sep 17 15:46:44.968086 2026] [security2:error] [pid 60716:tid 60892] [client 177.44.133.72:59716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfxMPsx0SVFjrd623gigAAAAA"]
[Thu Sep 17 15:46:45.038236 2026] [security2:error] [pid 60716:tid 60964] [client 34.166.34.14:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.34.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.slimmtech.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxfxcPsx0SVFjrd623gjQAAAEY"]
[Thu Sep 17 15:46:45.061652 2026] [security2:error] [pid 60716:tid 60917] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/job/.env"] [unique_id "aqxfxcPsx0SVFjrd623gjgAAABk"]
[Thu Sep 17 15:46:45.115380 2026] [security2:error] [pid 60716:tid 60960] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/terraform/.env"] [unique_id "aqxfxcPsx0SVFjrd623gjwAAAEI"]
[Thu Sep 17 15:46:45.251485 2026] [security2:error] [pid 60716:tid 60961] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/test/.env"] [unique_id "aqxfxcPsx0SVFjrd623glwAAAEM"]
[Thu Sep 17 15:46:45.306897 2026] [security2:error] [pid 60716:tid 60923] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/ansible/.env"] [unique_id "aqxfxcPsx0SVFjrd623gmAAAAB4"]
[Thu Sep 17 15:46:45.361440 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.197.112:45098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/admin/phpinfo.php"] [unique_id "aqxfxcPsx0SVFjrd623gmgAAAFc"]
[Thu Sep 17 15:46:45.470740 2026] [security2:error] [pid 60716:tid 60965] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/qa/.env"] [unique_id "aqxfxcPsx0SVFjrd623goAAAAEc"]
[Thu Sep 17 15:46:45.549330 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/.git/.env"] [unique_id "aqxfxcPsx0SVFjrd623gogAAADM"]
[Thu Sep 17 15:46:45.710460 2026] [security2:error] [pid 60716:tid 60940] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/preview/.env"] [unique_id "aqxfxcPsx0SVFjrd623gpgAAAC4"]
[Thu Sep 17 15:46:45.721492 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/ci/.env"] [unique_id "aqxfxcPsx0SVFjrd623gpwAAACU"]
[Thu Sep 17 15:46:45.912625 2026] [security2:error] [pid 60716:tid 60986] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cd/.env"] [unique_id "aqxfxcPsx0SVFjrd623grQAAAFw"]
[Thu Sep 17 15:46:46.000425 2026] [security2:error] [pid 60716:tid 61010] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/beta/.env"] [unique_id "aqxfxcPsx0SVFjrd623gtAAAAHQ"]
[Thu Sep 17 15:46:46.054709 2026] [security2:error] [pid 60716:tid 60969] [client 34.166.197.112:45106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/test/phpinfo.php"] [unique_id "aqxfxsPsx0SVFjrd623gtQAAAEs"]
[Thu Sep 17 15:46:46.077218 2026] [security2:error] [pid 60716:tid 60997] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/jenkins/.env"] [unique_id "aqxfxsPsx0SVFjrd623gtgAAAGc"]
[Thu Sep 17 15:46:46.240348 2026] [security2:error] [pid 60716:tid 60937] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/gitlab/.env"] [unique_id "aqxfxsPsx0SVFjrd623guwAAACs"]
[Thu Sep 17 15:46:46.355963 2026] [security2:error] [pid 60716:tid 60898] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/uat/.env"] [unique_id "aqxfxsPsx0SVFjrd623gvQAAAAY"]
[Thu Sep 17 15:46:46.458917 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/github/.env"] [unique_id "aqxfxsPsx0SVFjrd623gwgAAABU"]
[Thu Sep 17 15:46:46.517323 2026] [security2:error] [pid 60716:tid 60901] [client 4.240.114.86:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "aqxfxsPsx0SVFjrd623gxQAAAAk"], referer: binance.com
[Thu Sep 17 15:46:46.634181 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/actions/.env"] [unique_id "aqxfxsPsx0SVFjrd623gxwAAABI"]
[Thu Sep 17 15:46:46.675108 2026] [security2:error] [pid 60716:tid 60928] [client 169.58.197.253:52075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxfxsPsx0SVFjrd623gyAAAACM"], referer: binance.com
[Thu Sep 17 15:46:46.692231 2026] [security2:error] [pid 60716:tid 60970] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/stage/.env"] [unique_id "aqxfxsPsx0SVFjrd623gyQAAAEw"]
[Thu Sep 17 15:46:46.735373 2026] [security2:error] [pid 60716:tid 60925] [client 34.166.197.112:45118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/dev/phpinfo.php"] [unique_id "aqxfxsPsx0SVFjrd623gzQAAACA"]
[Thu Sep 17 15:46:46.787737 2026] [security2:error] [pid 60716:tid 60915] [client 79.116.89.151:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfxsPsx0SVFjrd623gzwAAABc"]
[Thu Sep 17 15:46:46.787867 2026] [security2:error] [pid 60716:tid 60915] [client 79.116.89.151:61736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxfxsPsx0SVFjrd623gzwAAABc"]
[Thu Sep 17 15:46:46.805587 2026] [security2:error] [pid 60716:tid 61014] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/circleci/.env"] [unique_id "aqxfxsPsx0SVFjrd623g0AAAAHg"]
[Thu Sep 17 15:46:46.905342 2026] [security2:error] [pid 60716:tid 61001] [client 122.8.45.84:18439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxfxsPsx0SVFjrd623gxgAAAGs"]
[Thu Sep 17 15:46:46.923082 2026] [security2:error] [pid 60716:tid 60934] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/development/.env"] [unique_id "aqxfxsPsx0SVFjrd623g0gAAACg"]
[Thu Sep 17 15:46:46.965572 2026] [security2:error] [pid 60716:tid 60947] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/travis/.env"] [unique_id "aqxfxsPsx0SVFjrd623g1gAAADU"]
[Thu Sep 17 15:46:47.178431 2026] [security2:error] [pid 60716:tid 60995] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/buildkite/.env"] [unique_id "aqxfx8Psx0SVFjrd623g2gAAAGU"]
[Thu Sep 17 15:46:47.193587 2026] [security2:error] [pid 60716:tid 61015] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/production/.env"] [unique_id "aqxfx8Psx0SVFjrd623g2wAAAHk"]
[Thu Sep 17 15:46:47.342806 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mysql/.env"] [unique_id "aqxfx8Psx0SVFjrd623g4QAAABM"]
[Thu Sep 17 15:46:47.385089 2026] [security2:error] [pid 60716:tid 60981] [client 35.228.4.121:55322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mesuradocooperative.com"] [uri "/config/app/.env"] [unique_id "aqxfx8Psx0SVFjrd623g5AAAAFc"]
[Thu Sep 17 15:46:47.414605 2026] [security2:error] [pid 60716:tid 61011] [client 34.166.197.112:45132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/old/phpinfo.php"] [unique_id "aqxfx8Psx0SVFjrd623g5wAAAHU"]
[Thu Sep 17 15:46:47.467763 2026] [security2:error] [pid 60716:tid 61003] [client 186.193.220.252:36636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "karlabreu.com"] [uri "/index.php"] [unique_id "aqxfx8Psx0SVFjrd623g4AAAbVs"], referer: https://karlabreu.com/
[Thu Sep 17 15:46:47.552369 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/postgres/.env"] [unique_id "aqxfx8Psx0SVFjrd623g8wAAACU"]
[Thu Sep 17 15:46:47.671358 2026] [security2:error] [pid 60716:tid 60988] [client 35.228.4.121:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/phpinfo.php"] [unique_id "aqxfx8Psx0SVFjrd623g9QAAAF4"]
[Thu Sep 17 15:46:47.726677 2026] [security2:error] [pid 60716:tid 60986] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mongodb/.env"] [unique_id "aqxfx8Psx0SVFjrd623g-wAAAFw"]
[Thu Sep 17 15:46:47.954138 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/redis/.env"] [unique_id "aqxfx8Psx0SVFjrd623hAwAAACE"]
[Thu Sep 17 15:46:47.983985 2026] [security2:error] [pid 60716:tid 60965] [client 122.8.45.84:63293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxfx8Psx0SVFjrd623hAQAAAEc"]
[Thu Sep 17 15:46:48.141547 2026] [security2:error] [pid 60716:tid 60980] [client 34.166.197.112:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/tmp/phpinfo.php"] [unique_id "aqxfyMPsx0SVFjrd623hDAAAAFY"]
[Thu Sep 17 15:46:48.177896 2026] [security2:error] [pid 60716:tid 60918] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/elasticsearch/.env"] [unique_id "aqxfyMPsx0SVFjrd623hDgAAABo"]
[Thu Sep 17 15:46:48.265399 2026] [security2:error] [pid 60716:tid 60913] [client 35.228.4.121:53514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/info.php"] [unique_id "aqxfyMPsx0SVFjrd623hEQAAABU"]
[Thu Sep 17 15:46:48.381864 2026] [security2:error] [pid 60716:tid 60941] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/rabbitmq/.env"] [unique_id "aqxfyMPsx0SVFjrd623hGAAAAC8"]
[Thu Sep 17 15:46:48.540807 2026] [security2:error] [pid 60716:tid 60960] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/kafka/.env"] [unique_id "aqxfyMPsx0SVFjrd623hHgAAAEI"]
[Thu Sep 17 15:46:48.719505 2026] [security2:error] [pid 60716:tid 60903] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/queue/.env"] [unique_id "aqxfyMPsx0SVFjrd623hJgAAAAs"]
[Thu Sep 17 15:46:48.821409 2026] [security2:error] [pid 60716:tid 60905] [client 34.166.197.112:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/public/phpinfo.php"] [unique_id "aqxfyMPsx0SVFjrd623hKAAAAA0"]
[Thu Sep 17 15:46:48.874428 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/worker/.env"] [unique_id "aqxfyMPsx0SVFjrd623hKgAAADM"]
[Thu Sep 17 15:46:48.952935 2026] [security2:error] [pid 60716:tid 60876] [remote 216.73.217.142:11112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxfyMPsx0SVFjrd623hLwAAaXI"]
[Thu Sep 17 15:46:49.043752 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/job/.env"] [unique_id "aqxfycPsx0SVFjrd623hNAAAACU"]
[Thu Sep 17 15:46:49.222318 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/test/.env"] [unique_id "aqxfycPsx0SVFjrd623hOwAAAGY"]
[Thu Sep 17 15:46:49.328762 2026] [security2:error] [pid 60716:tid 61002] [client 35.228.4.121:53518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/php.php"] [unique_id "aqxfycPsx0SVFjrd623hPgAAAGw"]
[Thu Sep 17 15:46:49.441431 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/qa/.env"] [unique_id "aqxfycPsx0SVFjrd623hQwAAACc"]
[Thu Sep 17 15:46:49.649533 2026] [security2:error] [pid 60716:tid 61012] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/preview/.env"] [unique_id "aqxfycPsx0SVFjrd623hTQAAAHY"]
[Thu Sep 17 15:46:49.758356 2026] [security2:error] [pid 60716:tid 61009] [client 34.166.197.112:45150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/php-info.php"] [unique_id "aqxfycPsx0SVFjrd623hUAAAAHM"]
[Thu Sep 17 15:46:49.828925 2026] [security2:error] [pid 60716:tid 60970] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/beta/.env"] [unique_id "aqxfycPsx0SVFjrd623hUwAAAEw"]
[Thu Sep 17 15:46:50.002542 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/uat/.env"] [unique_id "aqxfysPsx0SVFjrd623hXQAAAGs"]
[Thu Sep 17 15:46:50.058369 2026] [security2:error] [pid 60716:tid 60901] [client 35.228.4.121:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/i.php"] [unique_id "aqxfysPsx0SVFjrd623hZwAAAAk"]
[Thu Sep 17 15:46:50.084257 2026] [security2:error] [pid 60716:tid 60968] [client 193.142.36.97:26531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.36.142.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/wp-login.php"] [unique_id "aqxfysPsx0SVFjrd623hZQAAAEo"], referer: https://www.google.com
[Thu Sep 17 15:46:50.205719 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/stage/.env"] [unique_id "aqxfysPsx0SVFjrd623hbgAAADo"]
[Thu Sep 17 15:46:50.440057 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/development/.env"] [unique_id "aqxfysPsx0SVFjrd623hdAAAAHU"]
[Thu Sep 17 15:46:50.450164 2026] [security2:error] [pid 60716:tid 60964] [client 34.166.197.112:45162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/phpversion.php"] [unique_id "aqxfysPsx0SVFjrd623hdQAAAEY"]
[Thu Sep 17 15:46:50.622766 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/production/.env"] [unique_id "aqxfysPsx0SVFjrd623hgAAAADI"]
[Thu Sep 17 15:46:50.790428 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.246.111:59160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comfortspecialist.info"] [uri "/config/app/.env"] [unique_id "aqxfysPsx0SVFjrd623hhAAAAGE"]
[Thu Sep 17 15:46:50.800849 2026] [security2:error] [pid 60716:tid 60768] [remote 45.157.54.43:37698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ohanaclinic.com"] [uri "/xmlrpc.php"] [unique_id "aqxfysPsx0SVFjrd623hhQAAOAk"]
[Thu Sep 17 15:46:50.801155 2026] [security2:error] [pid 60716:tid 60950] [client 45.157.54.43:37698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ohanaclinic.com"] [uri "/xmlrpc.php"] [unique_id "aqxfysPsx0SVFjrd623hhQAAOAk"]
[Thu Sep 17 15:46:50.872616 2026] [security2:error] [pid 60716:tid 60962] [client 35.228.4.121:60914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/pi.php"] [unique_id "aqxfysPsx0SVFjrd623hiAAAAEQ"]
[Thu Sep 17 15:46:51.023618 2026] [security2:error] [pid 60716:tid 60894] [client 193.142.36.97:42191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.36.142.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plasticvisual.com"] [uri "/wp-login.php"] [unique_id "aqxfy8Psx0SVFjrd623hjQAAAAI"], referer: https://plasticvisual.com/wp-login.php
[Thu Sep 17 15:46:51.062799 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.246.111:59160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/phpinfo.php"] [unique_id "aqxfy8Psx0SVFjrd623hjwAAACE"]
[Thu Sep 17 15:46:51.106848 2026] [security2:error] [pid 60716:tid 60965] [client 162.241.226.11:29660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/tortuero2.plt"] [unique_id "aqxfy8Psx0SVFjrd623hkQAAAEc"]
[Thu Sep 17 15:46:51.135945 2026] [security2:error] [pid 60716:tid 60975] [client 34.166.197.112:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/_phpinfo.php"] [unique_id "aqxfy8Psx0SVFjrd623hlAAAAFE"]
[Thu Sep 17 15:46:51.138757 2026] [security2:error] [pid 60716:tid 60936] [client 162.241.226.11:29678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/tortuero2.plt"] [unique_id "aqxfy8Psx0SVFjrd623hkwAAACo"]
[Thu Sep 17 15:46:51.169456 2026] [security2:error] [pid 60716:tid 61010] [client 162.241.226.11:29682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/perfil_tortuero2.png"] [unique_id "aqxfy8Psx0SVFjrd623hlwAAAHQ"]
[Thu Sep 17 15:46:51.628789 2026] [security2:error] [pid 60716:tid 61009] [client 35.228.4.121:60918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/pinfo.php"] [unique_id "aqxfy8Psx0SVFjrd623hogAAAHM"]
[Thu Sep 17 15:46:51.726755 2026] [security2:error] [pid 60716:tid 61014] [client 4.240.114.86:54261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "aqxfy8Psx0SVFjrd623hpwAAAHg"], referer: binance.com
[Thu Sep 17 15:46:51.814027 2026] [security2:error] [pid 60716:tid 60925] [client 34.154.246.111:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/info.php"] [unique_id "aqxfy8Psx0SVFjrd623hqAAAACA"]
[Thu Sep 17 15:46:51.819283 2026] [security2:error] [pid 60716:tid 60957] [client 34.166.197.112:45180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/old_phpinfo.php"] [unique_id "aqxfy8Psx0SVFjrd623hqQAAAD8"]
[Thu Sep 17 15:46:52.379338 2026] [security2:error] [pid 60716:tid 60953] [client 136.158.61.34:64882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfzMPsx0SVFjrd623htwAAADs"]
[Thu Sep 17 15:46:52.379539 2026] [security2:error] [pid 60716:tid 60953] [client 136.158.61.34:64882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxfzMPsx0SVFjrd623htwAAADs"]
[Thu Sep 17 15:46:52.448270 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.246.111:60324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/php.php"] [unique_id "aqxfzMPsx0SVFjrd623huQAAAHU"]
[Thu Sep 17 15:46:52.528760 2026] [security2:error] [pid 60716:tid 60981] [client 34.166.197.112:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/server-info.php"] [unique_id "aqxfzMPsx0SVFjrd623hvQAAAFc"]
[Thu Sep 17 15:46:52.670110 2026] [security2:error] [pid 60716:tid 60905] [client 35.228.4.121:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/test.php"] [unique_id "aqxfzMPsx0SVFjrd623hwAAAAA0"]
[Thu Sep 17 15:46:53.004694 2026] [security2:error] [pid 60716:tid 60997] [client 74.7.228.28:59734] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "xn--hz2b27bgxqptl.com"] [uri "/robots.txt"] [unique_id "aqxfzcPsx0SVFjrd623hxwAAAGc"]
[Thu Sep 17 15:46:53.044033 2026] [security2:error] [pid 60716:tid 60912] [client 34.154.246.111:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/i.php"] [unique_id "aqxfzcPsx0SVFjrd623hyQAAABQ"]
[Thu Sep 17 15:46:53.202833 2026] [security2:error] [pid 60716:tid 60975] [client 79.148.14.212:43964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mtbclubdecampo.com"] [uri "/BlogMTB/index.php"] [unique_id "aqxfzcPsx0SVFjrd623hygAAUVw"], referer: https://www.mtbclubdecampo.com/
[Thu Sep 17 15:46:53.219962 2026] [security2:error] [pid 60716:tid 60893] [client 34.166.197.112:50528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/server-status.php"] [unique_id "aqxfzcPsx0SVFjrd623h0QAAAAE"]
[Thu Sep 17 15:46:53.614858 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.246.111:60334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/pi.php"] [unique_id "aqxfzcPsx0SVFjrd623h2wAAAEU"]
[Thu Sep 17 15:46:53.853012 2026] [security2:error] [pid 60716:tid 60800] [remote 45.157.54.43:41540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ohanaclinic.com"] [uri "/xmlrpc.php"] [unique_id "aqxfzcPsx0SVFjrd623h4wAAICY"]
[Thu Sep 17 15:46:53.853158 2026] [security2:error] [pid 60716:tid 60925] [client 45.157.54.43:41540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ohanaclinic.com"] [uri "/xmlrpc.php"] [unique_id "aqxfzcPsx0SVFjrd623h4wAAICY"]
[Thu Sep 17 15:46:53.934208 2026] [security2:error] [pid 60716:tid 60892] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxfzcPsx0SVFjrd623h4QAAAAA"]
[Thu Sep 17 15:46:54.063702 2026] [security2:error] [pid 60716:tid 60956] [client 14.96.156.146:49162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfzsPsx0SVFjrd623h7QAAAD4"]
[Thu Sep 17 15:46:54.063849 2026] [security2:error] [pid 60716:tid 60956] [client 14.96.156.146:49162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxfzsPsx0SVFjrd623h7QAAAD4"]
[Thu Sep 17 15:46:54.361139 2026] [security2:error] [pid 60716:tid 60943] [client 34.154.246.111:60338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/pinfo.php"] [unique_id "aqxfzsPsx0SVFjrd623iAAAAADE"]
[Thu Sep 17 15:46:54.391403 2026] [security2:error] [pid 60716:tid 60904] [client 34.166.197.112:50530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/webroot/index.php/_environment"] [unique_id "aqxfzsPsx0SVFjrd623iAQAAAAw"]
[Thu Sep 17 15:46:54.615121 2026] [security2:error] [pid 60716:tid 61015] [client 148.227.75.216:25121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfzsPsx0SVFjrd623iEgAAAHk"]
[Thu Sep 17 15:46:54.616393 2026] [security2:error] [pid 60716:tid 61015] [client 148.227.75.216:25121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxfzsPsx0SVFjrd623iEgAAAHk"]
[Thu Sep 17 15:46:54.788834 2026] [security2:error] [pid 60716:tid 60990] [client 35.228.4.121:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/p.php"] [unique_id "aqxfzsPsx0SVFjrd623iFwAAAGA"]
[Thu Sep 17 15:46:54.906138 2026] [security2:error] [pid 60716:tid 60984] [client 122.8.45.84:37979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxfzsPsx0SVFjrd623iGAAAAFo"]
[Thu Sep 17 15:46:54.985842 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.246.111:60352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/test.php"] [unique_id "aqxfzsPsx0SVFjrd623iIgAAAFA"]
[Thu Sep 17 15:46:55.006815 2026] [security2:error] [pid 60716:tid 60962] [client 143.105.152.240:5234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfz8Psx0SVFjrd623iJAAAAEQ"]
[Thu Sep 17 15:46:55.014645 2026] [security2:error] [pid 60716:tid 60962] [client 143.105.152.240:5234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxfz8Psx0SVFjrd623iJAAAAEQ"]
[Thu Sep 17 15:46:55.080702 2026] [security2:error] [pid 60716:tid 60893] [client 34.166.197.112:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/mail/phpinfo.php"] [unique_id "aqxfz8Psx0SVFjrd623iJgAAAAE"]
[Thu Sep 17 15:46:55.192160 2026] [security2:error] [pid 60716:tid 60899] [client 169.58.197.253:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxfz8Psx0SVFjrd623iNgAAAAc"], referer: binance.com
[Thu Sep 17 15:46:55.372987 2026] [security2:error] [pid 60716:tid 60980] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxfz8Psx0SVFjrd623iPAAAAFY"]
[Thu Sep 17 15:46:55.445419 2026] [security2:error] [pid 60716:tid 61001] [client 35.228.4.121:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/debug.php"] [unique_id "aqxfz8Psx0SVFjrd623iPwAAAGs"]
[Thu Sep 17 15:46:55.617583 2026] [security2:error] [pid 60716:tid 61018] [client 177.44.133.72:60381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfz8Psx0SVFjrd623iSwAAAHw"]
[Thu Sep 17 15:46:55.617695 2026] [security2:error] [pid 60716:tid 61018] [client 177.44.133.72:60381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxfz8Psx0SVFjrd623iSwAAAHw"]
[Thu Sep 17 15:46:55.711574 2026] [security2:error] [pid 60716:tid 60977] [client 93.86.49.58:46333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxfz8Psx0SVFjrd623iRAAAU1s"]
[Thu Sep 17 15:46:55.765568 2026] [security2:error] [pid 60716:tid 60999] [client 34.166.197.112:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxfz8Psx0SVFjrd623iUQAAAGk"]
[Thu Sep 17 15:46:55.968010 2026] [security2:error] [pid 60716:tid 60903] [client 122.8.45.84:59471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxfz8Psx0SVFjrd623iUwAAAAs"]
[Thu Sep 17 15:46:55.980456 2026] [security2:error] [pid 60716:tid 60990] [client 74.7.230.4:37654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "mail.agent-immobilier.com"] [uri "/robots.txt"] [unique_id "aqxfz8Psx0SVFjrd623iXwAAAGA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Sep 17 15:46:56.060570 2026] [security2:error] [pid 60716:tid 60918] [client 74.7.230.4:37654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.agent-immobilier.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aqxf0MPsx0SVFjrd623iYgAAABo"], referer: https://mail.agent-immobilier.com/robots.txt
[Thu Sep 17 15:46:56.088527 2026] [security2:error] [pid 60716:tid 60893] [client 169.58.197.251:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxf0MPsx0SVFjrd623iZAAAAAE"], referer: binance.com
[Thu Sep 17 15:46:56.147916 2026] [security2:error] [pid 60716:tid 60969] [client 34.154.246.111:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/p.php"] [unique_id "aqxf0MPsx0SVFjrd623iZwAAAEs"]
[Thu Sep 17 15:46:56.277990 2026] [security2:error] [pid 60716:tid 60892] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ibgAAAAA"]
[Thu Sep 17 15:46:56.423606 2026] [security2:error] [pid 60716:tid 61014] [client 35.228.4.121:60954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxf0MPsx0SVFjrd623idQAAAHg"]
[Thu Sep 17 15:46:56.449456 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.197.112:50562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/hosting/phpinfo.php"] [unique_id "aqxf0MPsx0SVFjrd623idgAAAAc"]
[Thu Sep 17 15:46:56.456841 2026] [security2:error] [pid 60716:tid 60961] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623icwAAAEM"]
[Thu Sep 17 15:46:56.608928 2026] [security2:error] [pid 60716:tid 60977] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ihQAAAFM"]
[Thu Sep 17 15:46:56.744955 2026] [security2:error] [pid 60716:tid 61009] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ilgAAAHM"]
[Thu Sep 17 15:46:56.753943 2026] [security2:error] [pid 60716:tid 61008] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ilwAAAHI"]
[Thu Sep 17 15:46:56.793204 2026] [security2:error] [pid 60716:tid 60903] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ipAAAAAs"]
[Thu Sep 17 15:46:56.809987 2026] [security2:error] [pid 60716:tid 60985] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ipQAAAFs"]
[Thu Sep 17 15:46:56.829247 2026] [security2:error] [pid 60716:tid 60974] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ipgAAAFA"]
[Thu Sep 17 15:46:56.833101 2026] [security2:error] [pid 60716:tid 60941] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623ipwAAAC8"]
[Thu Sep 17 15:46:56.884502 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.246.111:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/debug.php"] [unique_id "aqxf0MPsx0SVFjrd623irwAAACU"]
[Thu Sep 17 15:46:56.905435 2026] [security2:error] [pid 60716:tid 60906] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623irAAAAA4"]
[Thu Sep 17 15:46:56.925714 2026] [security2:error] [pid 60716:tid 60995] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623isQAAAGU"]
[Thu Sep 17 15:46:56.929423 2026] [security2:error] [pid 60716:tid 60892] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623itAAAAAA"]
[Thu Sep 17 15:46:56.935930 2026] [security2:error] [pid 60716:tid 60896] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0MPsx0SVFjrd623itQAAAAQ"]
[Thu Sep 17 15:46:56.977610 2026] [security2:error] [pid 60716:tid 60796] [remote 216.73.217.142:11112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/tqn/sitemap_product_109.xml"] [unique_id "aqxf0MPsx0SVFjrd623ivQAAOyI"]
[Thu Sep 17 15:46:57.081424 2026] [security2:error] [pid 60716:tid 60993] [client 35.228.4.121:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/test/phpinfo.php"] [unique_id "aqxf0cPsx0SVFjrd623iwwAAAGM"]
[Thu Sep 17 15:46:57.121317 2026] [security2:error] [pid 60716:tid 60945] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623iwgAAADM"]
[Thu Sep 17 15:46:57.125615 2026] [security2:error] [pid 60716:tid 60926] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623ixgAAACE"]
[Thu Sep 17 15:46:57.135375 2026] [security2:error] [pid 60716:tid 60987] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623iygAAAF0"]
[Thu Sep 17 15:46:57.135847 2026] [security2:error] [pid 60716:tid 60923] [client 34.166.197.112:50578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/webmail/phpinfo.php"] [unique_id "aqxf0cPsx0SVFjrd623i0QAAAB4"]
[Thu Sep 17 15:46:57.152515 2026] [security2:error] [pid 60716:tid 61011] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623izQAAAHU"]
[Thu Sep 17 15:46:57.220252 2026] [security2:error] [pid 60716:tid 60949] [client 122.8.45.84:38381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf0cPsx0SVFjrd623i0AAAADc"]
[Thu Sep 17 15:46:57.263656 2026] [security2:error] [pid 60716:tid 60900] [client 4.240.114.86:56800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "aqxf0cPsx0SVFjrd623i4wAAAAg"], referer: binance.com
[Thu Sep 17 15:46:57.292938 2026] [security2:error] [pid 60716:tid 61008] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623i3wAAAHI"]
[Thu Sep 17 15:46:57.318577 2026] [security2:error] [pid 60716:tid 60954] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623i5gAAADw"]
[Thu Sep 17 15:46:57.330284 2026] [security2:error] [pid 60716:tid 60956] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623i5AAAAD4"]
[Thu Sep 17 15:46:57.417588 2026] [security2:error] [pid 60716:tid 60924] [client 79.116.89.151:62370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf0cPsx0SVFjrd623i6gAAAB8"]
[Thu Sep 17 15:46:57.417732 2026] [security2:error] [pid 60716:tid 60924] [client 79.116.89.151:62370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf0cPsx0SVFjrd623i6gAAAB8"]
[Thu Sep 17 15:46:57.514641 2026] [security2:error] [pid 60716:tid 60917] [client 34.154.246.111:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/admin/phpinfo.php"] [unique_id "aqxf0cPsx0SVFjrd623jBQAAABk"]
[Thu Sep 17 15:46:57.619482 2026] [security2:error] [pid 60716:tid 60934] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623jCAAAACg"]
[Thu Sep 17 15:46:57.780878 2026] [security2:error] [pid 60716:tid 60995] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623jEAAAAGU"]
[Thu Sep 17 15:46:57.823481 2026] [security2:error] [pid 60716:tid 60929] [client 34.166.197.112:50590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/smtp/phpinfo.php"] [unique_id "aqxf0cPsx0SVFjrd623jFAAAACQ"]
[Thu Sep 17 15:46:57.856115 2026] [security2:error] [pid 60716:tid 60986] [client 94.23.181.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf0cPsx0SVFjrd623jEgAAAFw"]
[Thu Sep 17 15:46:57.878209 2026] [security2:error] [pid 60716:tid 61012] [client 35.228.4.121:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxf0cPsx0SVFjrd623jFQAAAHY"]
[Thu Sep 17 15:46:58.208332 2026] [security2:error] [pid 60716:tid 60998] [client 34.154.246.111:35548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/test/phpinfo.php"] [unique_id "aqxf0sPsx0SVFjrd623jIgAAAGg"]
[Thu Sep 17 15:46:58.287378 2026] [security2:error] [pid 60716:tid 61019] [client 122.8.45.84:45253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf0sPsx0SVFjrd623jIQAAAH0"]
[Thu Sep 17 15:46:58.510330 2026] [security2:error] [pid 60716:tid 60945] [client 34.166.197.112:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/phpinfo.php.bak"] [unique_id "aqxf0sPsx0SVFjrd623jLAAAADM"]
[Thu Sep 17 15:46:58.735008 2026] [security2:error] [pid 60716:tid 61006] [client 171.96.91.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "casualchessclub.com"] [uri "/index.php"] [unique_id "aqxf0sPsx0SVFjrd623jHQAAAHA"], referer: https://casualchessclub.com/
[Thu Sep 17 15:46:58.849412 2026] [security2:error] [pid 60716:tid 60911] [client 35.228.4.121:60968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/old/phpinfo.php"] [unique_id "aqxf0sPsx0SVFjrd623jRQAAABM"]
[Thu Sep 17 15:46:58.887009 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.246.111:35564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/dev/phpinfo.php"] [unique_id "aqxf0sPsx0SVFjrd623jSAAAAG8"]
[Thu Sep 17 15:46:58.903461 2026] [security2:error] [pid 60716:tid 61011] [client 162.241.226.11:18460] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxf0sPsx0SVFjrd623jRwAAAHU"]
[Thu Sep 17 15:46:59.226457 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.197.112:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/phpinfo.php.old"] [unique_id "aqxf08Psx0SVFjrd623jZAAAAF0"]
[Thu Sep 17 15:46:59.358888 2026] [security2:error] [pid 60716:tid 60971] [client 122.8.45.84:57739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf08Psx0SVFjrd623jZwAAAE0"]
[Thu Sep 17 15:46:59.577555 2026] [security2:error] [pid 60716:tid 60960] [client 34.154.246.111:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/old/phpinfo.php"] [unique_id "aqxf08Psx0SVFjrd623jbQAAAEI"]
[Thu Sep 17 15:46:59.607364 2026] [security2:error] [pid 60716:tid 60992] [client 35.228.4.121:60970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxf08Psx0SVFjrd623jbgAAAGI"]
[Thu Sep 17 15:46:59.883982 2026] [security2:error] [pid 60716:tid 60805] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.env"] [unique_id "aqxf08Psx0SVFjrd623jdQAAISs"]
[Thu Sep 17 15:46:59.884300 2026] [security2:error] [pid 60716:tid 60867] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.env.bak"] [unique_id "aqxf08Psx0SVFjrd623jegAAIWk"]
[Thu Sep 17 15:46:59.910415 2026] [security2:error] [pid 60716:tid 60947] [client 34.166.197.112:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/phpinfo.php~"] [unique_id "aqxf08Psx0SVFjrd623jhQAAADU"]
[Thu Sep 17 15:47:00.245294 2026] [security2:error] [pid 60716:tid 61006] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf08Psx0SVFjrd623jhAAAAHA"]
[Thu Sep 17 15:47:00.245477 2026] [security2:error] [pid 60716:tid 60961] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf08Psx0SVFjrd623jgwAAAEM"]
[Thu Sep 17 15:47:00.250055 2026] [security2:error] [pid 60716:tid 60819] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.env.old"] [unique_id "aqxf08Psx0SVFjrd623joQAAITk"]
[Thu Sep 17 15:47:00.250812 2026] [security2:error] [pid 60716:tid 60805] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.env.backup"] [unique_id "aqxf08Psx0SVFjrd623jngAAISs"]
[Thu Sep 17 15:47:00.276587 2026] [security2:error] [pid 60716:tid 60931] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf08Psx0SVFjrd623jhgAAACU"]
[Thu Sep 17 15:47:00.279327 2026] [security2:error] [pid 60716:tid 60954] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf08Psx0SVFjrd623jiAAAADw"]
[Thu Sep 17 15:47:00.282131 2026] [security2:error] [pid 60716:tid 60920] [client 34.154.246.111:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/tmp/phpinfo.php"] [unique_id "aqxf1MPsx0SVFjrd623jsQAAABw"]
[Thu Sep 17 15:47:00.285099 2026] [security2:error] [pid 60716:tid 60975] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf08Psx0SVFjrd623jhwAAAFE"]
[Thu Sep 17 15:47:00.298757 2026] [security2:error] [pid 60716:tid 60948] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf08Psx0SVFjrd623jigAAADY"]
[Thu Sep 17 15:47:00.488037 2026] [security2:error] [pid 60716:tid 60965] [client 35.228.4.121:34562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/public/phpinfo.php"] [unique_id "aqxf1MPsx0SVFjrd623jvgAAAEc"]
[Thu Sep 17 15:47:00.566907 2026] [security2:error] [pid 60716:tid 60893] [client 122.8.45.84:65211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf1MPsx0SVFjrd623juwAAAAE"]
[Thu Sep 17 15:47:00.601870 2026] [security2:error] [pid 60716:tid 60950] [client 34.166.197.112:50622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/info.php.bak"] [unique_id "aqxf1MPsx0SVFjrd623jwwAAADg"]
[Thu Sep 17 15:47:00.828542 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.246.111:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/public/phpinfo.php"] [unique_id "aqxf1MPsx0SVFjrd623jyQAAAEY"]
[Thu Sep 17 15:47:01.282743 2026] [security2:error] [pid 60716:tid 60990] [client 34.166.197.112:50626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/phpinfo.php.save"] [unique_id "aqxf1cPsx0SVFjrd623j2wAAAGA"]
[Thu Sep 17 15:47:01.324621 2026] [security2:error] [pid 60716:tid 60920] [client 4.240.114.86:58698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "aqxf1cPsx0SVFjrd623j3AAAABw"], referer: binance.com
[Thu Sep 17 15:47:01.373812 2026] [security2:error] [pid 60716:tid 60902] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623jtwAAAAo"]
[Thu Sep 17 15:47:01.380793 2026] [security2:error] [pid 60716:tid 60867] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/.env.php"] [unique_id "aqxf1MPsx0SVFjrd623j3wAAIWk"]
[Thu Sep 17 15:47:01.383303 2026] [security2:error] [pid 60716:tid 60842] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.env~"] [unique_id "aqxf1MPsx0SVFjrd623j4AAAIVA"]
[Thu Sep 17 15:47:01.387616 2026] [security2:error] [pid 60716:tid 60994] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623jtgAAAGQ"]
[Thu Sep 17 15:47:01.388109 2026] [security2:error] [pid 60716:tid 60852] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.env.swp"] [unique_id "aqxf1MPsx0SVFjrd623j4QAAIVo"]
[Thu Sep 17 15:47:01.395583 2026] [security2:error] [pid 60716:tid 61018] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623jswAAAHw"]
[Thu Sep 17 15:47:01.395583 2026] [security2:error] [pid 60716:tid 60898] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623jsgAAAAY"]
[Thu Sep 17 15:47:01.399492 2026] [security2:error] [pid 60716:tid 60935] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623jtQAAACk"]
[Thu Sep 17 15:47:01.399549 2026] [security2:error] [pid 60716:tid 60968] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623jtAAAAEo"]
[Thu Sep 17 15:47:01.401254 2026] [security2:error] [pid 60716:tid 60986] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623juAAAAFw"]
[Thu Sep 17 15:47:01.462242 2026] [security2:error] [pid 60716:tid 60966] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1MPsx0SVFjrd623jugAAAEg"]
[Thu Sep 17 15:47:01.564862 2026] [security2:error] [pid 60716:tid 60830] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/api/.env"] [unique_id "aqxf1cPsx0SVFjrd623kAQAAIUQ"]
[Thu Sep 17 15:47:01.567250 2026] [security2:error] [pid 60716:tid 60798] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/app/.env"] [unique_id "aqxf1cPsx0SVFjrd623kAgAAISQ"]
[Thu Sep 17 15:47:01.581996 2026] [security2:error] [pid 60716:tid 60772] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/backend/.env"] [unique_id "aqxf1cPsx0SVFjrd623kCwAAIQ0"]
[Thu Sep 17 15:47:01.657060 2026] [security2:error] [pid 60716:tid 61010] [client 122.8.45.84:59815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf1cPsx0SVFjrd623j_AAAAHQ"]
[Thu Sep 17 15:47:01.742510 2026] [security2:error] [pid 60716:tid 60946] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623j9gAAADQ"]
[Thu Sep 17 15:47:01.775471 2026] [security2:error] [pid 60716:tid 60831] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/server/.env"] [unique_id "aqxf1cPsx0SVFjrd623kFwAAIUU"]
[Thu Sep 17 15:47:01.775526 2026] [security2:error] [pid 60716:tid 60760] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/config/.env"] [unique_id "aqxf1cPsx0SVFjrd623kGAAAIQI"]
[Thu Sep 17 15:47:01.924999 2026] [security2:error] [pid 60716:tid 60890] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/web/.env"] [unique_id "aqxf1cPsx0SVFjrd623kHgAAIX8"]
[Thu Sep 17 15:47:01.925001 2026] [security2:error] [pid 60716:tid 60770] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/src/.env"] [unique_id "aqxf1cPsx0SVFjrd623kHQAAIQs"]
[Thu Sep 17 15:47:01.926157 2026] [security2:error] [pid 60716:tid 60885] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/client/.env"] [unique_id "aqxf1cPsx0SVFjrd623kHwAAIXs"]
[Thu Sep 17 15:47:01.926190 2026] [security2:error] [pid 60716:tid 60762] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/frontend/.env"] [unique_id "aqxf1cPsx0SVFjrd623kIAAAIQQ"]
[Thu Sep 17 15:47:01.926391 2026] [security2:error] [pid 60716:tid 60865] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/public/.env"] [unique_id "aqxf1cPsx0SVFjrd623kIQAAIWc"]
[Thu Sep 17 15:47:01.959551 2026] [security2:error] [pid 60716:tid 60758] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/var/www/.env"] [unique_id "aqxf1cPsx0SVFjrd623kJgAAIQA"]
[Thu Sep 17 15:47:01.959565 2026] [security2:error] [pid 60716:tid 60859] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/var/www/html/.env"] [unique_id "aqxf1cPsx0SVFjrd623kJQAAIWE"]
[Thu Sep 17 15:47:01.965151 2026] [security2:error] [pid 60716:tid 60901] [client 34.166.197.112:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/staging/phpinfo.php"] [unique_id "aqxf1cPsx0SVFjrd623kJwAAAAk"]
[Thu Sep 17 15:47:02.082829 2026] [security2:error] [pid 60716:tid 60919] [client 129.212.220.28:37492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623kJAAAABs"]
[Thu Sep 17 15:47:02.106125 2026] [security2:error] [pid 60716:tid 60853] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/laravel/.env"] [unique_id "aqxf1sPsx0SVFjrd623kMAAAIVs"]
[Thu Sep 17 15:47:02.106125 2026] [security2:error] [pid 60716:tid 60781] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/application/.env"] [unique_id "aqxf1sPsx0SVFjrd623kLwAAIRQ"]
[Thu Sep 17 15:47:02.106739 2026] [security2:error] [pid 60716:tid 60778] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/apps/.env"] [unique_id "aqxf1sPsx0SVFjrd623kMQAAIRI"]
[Thu Sep 17 15:47:02.106851 2026] [security2:error] [pid 60716:tid 60761] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/backup/.env"] [unique_id "aqxf1sPsx0SVFjrd623kMwAAIQM"]
[Thu Sep 17 15:47:02.106851 2026] [security2:error] [pid 60716:tid 60880] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/back/.env"] [unique_id "aqxf1sPsx0SVFjrd623kMgAAIXY"]
[Thu Sep 17 15:47:02.141561 2026] [security2:error] [pid 60716:tid 60869] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/dev/.env"] [unique_id "aqxf1sPsx0SVFjrd623kNgAAIWs"]
[Thu Sep 17 15:47:02.141756 2026] [security2:error] [pid 60716:tid 60817] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/cms/.env"] [unique_id "aqxf1sPsx0SVFjrd623kNQAAITc"]
[Thu Sep 17 15:47:02.287847 2026] [security2:error] [pid 60716:tid 60846] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/staging/.env"] [unique_id "aqxf1sPsx0SVFjrd623kPQAAIVQ"]
[Thu Sep 17 15:47:02.287850 2026] [security2:error] [pid 60716:tid 60879] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/production/.env"] [unique_id "aqxf1sPsx0SVFjrd623kPAAAIXU"]
[Thu Sep 17 15:47:02.287850 2026] [security2:error] [pid 60716:tid 60826] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/prod/.env"] [unique_id "aqxf1sPsx0SVFjrd623kOwAAIUA"]
[Thu Sep 17 15:47:02.287922 2026] [security2:error] [pid 60716:tid 60796] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/test/.env"] [unique_id "aqxf1sPsx0SVFjrd623kPgAAISI"]
[Thu Sep 17 15:47:02.287933 2026] [security2:error] [pid 60716:tid 60876] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/old/.env"] [unique_id "aqxf1sPsx0SVFjrd623kPwAAIXI"]
[Thu Sep 17 15:47:02.323732 2026] [security2:error] [pid 60716:tid 60877] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/new/.env"] [unique_id "aqxf1sPsx0SVFjrd623kQQAAIXM"]
[Thu Sep 17 15:47:02.323732 2026] [security2:error] [pid 60716:tid 60887] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/node-api/.env"] [unique_id "aqxf1sPsx0SVFjrd623kQgAAIX0"]
[Thu Sep 17 15:47:02.427598 2026] [security2:error] [pid 60716:tid 60912] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623j7gAAABQ"]
[Thu Sep 17 15:47:02.442262 2026] [security2:error] [pid 60716:tid 60983] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623j8AAAAFk"]
[Thu Sep 17 15:47:02.451262 2026] [security2:error] [pid 60716:tid 60987] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623j8QAAAF0"]
[Thu Sep 17 15:47:02.453941 2026] [security2:error] [pid 60716:tid 60913] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623j7wAAABU"]
[Thu Sep 17 15:47:02.457139 2026] [security2:error] [pid 60716:tid 60955] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623j8gAAAD0"]
[Thu Sep 17 15:47:02.469936 2026] [security2:error] [pid 60716:tid 60780] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/admin-app/.env"] [unique_id "aqxf1sPsx0SVFjrd623kRgAAIRM"]
[Thu Sep 17 15:47:02.469937 2026] [security2:error] [pid 60716:tid 60882] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/api-backend/.env"] [unique_id "aqxf1sPsx0SVFjrd623kRwAAIXg"]
[Thu Sep 17 15:47:02.470077 2026] [security2:error] [pid 60716:tid 60806] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/public_html/.env"] [unique_id "aqxf1sPsx0SVFjrd623kSAAAISw"]
[Thu Sep 17 15:47:02.470523 2026] [security2:error] [pid 60716:tid 60820] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/current/.env"] [unique_id "aqxf1sPsx0SVFjrd623kSgAAITo"]
[Thu Sep 17 15:47:02.506126 2026] [security2:error] [pid 60716:tid 60849] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/server/api/.env"] [unique_id "aqxf1sPsx0SVFjrd623kTQAAIVc"]
[Thu Sep 17 15:47:02.506157 2026] [security2:error] [pid 60716:tid 60883] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/server/backend/.env"] [unique_id "aqxf1sPsx0SVFjrd623kTgAAIXk"]
[Thu Sep 17 15:47:02.520129 2026] [security2:error] [pid 60716:tid 60896] [client 35.228.4.121:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/php-info.php"] [unique_id "aqxf1sPsx0SVFjrd623kUQAAAAQ"]
[Thu Sep 17 15:47:02.531370 2026] [security2:error] [pid 60716:tid 60825] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/administrator/.env"] [unique_id "aqxf1sPsx0SVFjrd623kSQAAIT8"]
[Thu Sep 17 15:47:02.604054 2026] [security2:error] [pid 60716:tid 60871] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.docker/.env"] [unique_id "aqxf1sPsx0SVFjrd623kUgAAIW0"]
[Thu Sep 17 15:47:02.606220 2026] [security2:error] [pid 60716:tid 60818] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxf1sPsx0SVFjrd623kVAAAITg"]
[Thu Sep 17 15:47:02.630021 2026] [security2:error] [pid 60716:tid 60804] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/aws/.env"] [unique_id "aqxf1sPsx0SVFjrd623kVgAAISo"]
[Thu Sep 17 15:47:02.649652 2026] [security2:error] [pid 60716:tid 60898] [client 34.166.197.112:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/beta/phpinfo.php"] [unique_id "aqxf1sPsx0SVFjrd623kWQAAAAY"]
[Thu Sep 17 15:47:02.650860 2026] [security2:error] [pid 60716:tid 60786] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.aws/.env"] [unique_id "aqxf1sPsx0SVFjrd623kWgAAIRg"]
[Thu Sep 17 15:47:02.711212 2026] [security2:error] [pid 60716:tid 60907] [client 122.8.45.84:29059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf1sPsx0SVFjrd623kVQAAAA8"]
[Thu Sep 17 15:47:02.786841 2026] [security2:error] [pid 60716:tid 60858] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/stripe/.env"] [unique_id "aqxf1sPsx0SVFjrd623kXgAAIWA"]
[Thu Sep 17 15:47:02.809376 2026] [security2:error] [pid 60716:tid 60847] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/v2/.env"] [unique_id "aqxf1sPsx0SVFjrd623kZgAAIVU"]
[Thu Sep 17 15:47:02.809420 2026] [security2:error] [pid 60716:tid 60788] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/media/.env"] [unique_id "aqxf1sPsx0SVFjrd623kZQAAIRo"]
[Thu Sep 17 15:47:02.809534 2026] [security2:error] [pid 60716:tid 60873] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/v1/.env"] [unique_id "aqxf1sPsx0SVFjrd623kYgAAIW8"]
[Thu Sep 17 15:47:02.809595 2026] [security2:error] [pid 60716:tid 60888] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/v3/.env"] [unique_id "aqxf1sPsx0SVFjrd623kZwAAIX4"]
[Thu Sep 17 15:47:02.899266 2026] [cgid:error] [pid 60716:tid 60897] [client 66.249.84.6:62610] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/tutorib7/public_html/404.shtml
[Thu Sep 17 15:47:03.019631 2026] [security2:error] [pid 60716:tid 60996] [client 38.83.55.203:60210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "freeofgravity.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623kHAAAAGY"], referer: https://freeofgravity.com/
[Thu Sep 17 15:47:03.065179 2026] [security2:error] [pid 60716:tid 60939] [client 169.58.197.251:49855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxf18Psx0SVFjrd623kjwAAAC0"], referer: binance.com
[Thu Sep 17 15:47:03.330354 2026] [security2:error] [pid 60716:tid 60917] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623kCgAAABk"]
[Thu Sep 17 15:47:03.343774 2026] [security2:error] [pid 60716:tid 60985] [client 34.166.197.112:55070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/uat/phpinfo.php"] [unique_id "aqxf18Psx0SVFjrd623kmgAAAFs"]
[Thu Sep 17 15:47:03.348109 2026] [security2:error] [pid 60716:tid 60959] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623kGwAAAEE"]
[Thu Sep 17 15:47:03.374475 2026] [security2:error] [pid 60716:tid 60988] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623kDQAAAF4"]
[Thu Sep 17 15:47:03.375805 2026] [security2:error] [pid 60716:tid 60945] [client 35.228.4.121:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/phpversion.php"] [unique_id "aqxf18Psx0SVFjrd623knQAAADM"]
[Thu Sep 17 15:47:03.376148 2026] [security2:error] [pid 60716:tid 60941] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623kDAAAAC8"]
[Thu Sep 17 15:47:03.546407 2026] [security2:error] [pid 60716:tid 60813] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.git/config.bak"] [unique_id "aqxf18Psx0SVFjrd623kqQAAITM"]
[Thu Sep 17 15:47:03.666766 2026] [security2:error] [pid 60716:tid 61007] [client 122.8.45.84:35727] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf18Psx0SVFjrd623ksQAAAHE"]
[Thu Sep 17 15:47:03.666876 2026] [security2:error] [pid 60716:tid 61007] [client 122.8.45.84:35727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf18Psx0SVFjrd623ksQAAAHE"]
[Thu Sep 17 15:47:04.032109 2026] [security2:error] [pid 60716:tid 60970] [client 34.166.197.112:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/qa/phpinfo.php"] [unique_id "aqxf2MPsx0SVFjrd623kwwAAAEw"]
[Thu Sep 17 15:47:04.191071 2026] [security2:error] [pid 60716:tid 60966] [client 35.228.4.121:34580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/_phpinfo.php"] [unique_id "aqxf2MPsx0SVFjrd623kxgAAAEg"]
[Thu Sep 17 15:47:04.325772 2026] [security2:error] [pid 60716:tid 61005] [client 169.58.198.243:64407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/plugins/shell/about.php"] [unique_id "aqxf2MPsx0SVFjrd623kywAAAG8"], referer: www.google.com
[Thu Sep 17 15:47:04.647303 2026] [security2:error] [pid 60716:tid 60946] [client 122.8.45.84:47719] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2MPsx0SVFjrd623k1QAAADQ"]
[Thu Sep 17 15:47:04.647449 2026] [security2:error] [pid 60716:tid 60946] [client 122.8.45.84:47719] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2MPsx0SVFjrd623k1QAAADQ"]
[Thu Sep 17 15:47:04.647480 2026] [security2:error] [pid 60716:tid 60946] [client 122.8.45.84:47719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2MPsx0SVFjrd623k1QAAADQ"]
[Thu Sep 17 15:47:04.704931 2026] [security2:error] [pid 60716:tid 60954] [client 169.58.197.253:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxf2MPsx0SVFjrd623k2QAAADw"], referer: binance.com
[Thu Sep 17 15:47:04.721210 2026] [security2:error] [pid 60716:tid 60919] [client 34.166.197.112:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/preview/phpinfo.php"] [unique_id "aqxf2MPsx0SVFjrd623k2wAAABs"]
[Thu Sep 17 15:47:04.798065 2026] [security2:error] [pid 60716:tid 60990] [client 14.96.156.146:50082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf2MPsx0SVFjrd623k3QAAAGA"]
[Thu Sep 17 15:47:04.798228 2026] [security2:error] [pid 60716:tid 60990] [client 14.96.156.146:50082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf2MPsx0SVFjrd623k3QAAAGA"]
[Thu Sep 17 15:47:04.877184 2026] [security2:error] [pid 60716:tid 61015] [client 74.7.228.47:44198] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "kopecdental.com"] [uri "/robots.txt"] [unique_id "aqxf2MPsx0SVFjrd623k5AAAAHk"]
[Thu Sep 17 15:47:04.929779 2026] [security2:error] [pid 60716:tid 60920] [client 35.228.4.121:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/old_phpinfo.php"] [unique_id "aqxf2MPsx0SVFjrd623k5gAAABw"]
[Thu Sep 17 15:47:04.964553 2026] [security2:error] [pid 60716:tid 60904] [client 175.100.46.136:15160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxf2MPsx0SVFjrd623k4gAADCg"]
[Thu Sep 17 15:47:05.114542 2026] [security2:error] [pid 60716:tid 61007] [client 74.7.228.47:53668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kopecdental.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623k6wAAcRk"], referer: http://kopecdental.com/robots.txt
[Thu Sep 17 15:47:05.132672 2026] [security2:error] [pid 60716:tid 60912] [client 136.158.61.34:497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623k7gAAABQ"]
[Thu Sep 17 15:47:05.132810 2026] [security2:error] [pid 60716:tid 60912] [client 136.158.61.34:497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623k7gAAABQ"]
[Thu Sep 17 15:47:05.193633 2026] [security2:error] [pid 60716:tid 60949] [client 148.227.75.216:13742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623k9gAAADc"]
[Thu Sep 17 15:47:05.193772 2026] [security2:error] [pid 60716:tid 60949] [client 148.227.75.216:13742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623k9gAAADc"]
[Thu Sep 17 15:47:05.305711 2026] [security2:error] [pid 60716:tid 60974] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1sPsx0SVFjrd623kdgAAAFA"]
[Thu Sep 17 15:47:05.364870 2026] [security2:error] [pid 60716:tid 60931] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1sPsx0SVFjrd623kdAAAACU"]
[Thu Sep 17 15:47:05.369033 2026] [security2:error] [pid 60716:tid 60996] [client 34.154.246.111:35616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/php-info.php"] [unique_id "aqxf2cPsx0SVFjrd623k-AAAAGY"]
[Thu Sep 17 15:47:05.373332 2026] [security2:error] [pid 60716:tid 60911] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623kjgAAABM"]
[Thu Sep 17 15:47:05.379023 2026] [security2:error] [pid 60716:tid 60991] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1sPsx0SVFjrd623kcQAAAGE"]
[Thu Sep 17 15:47:05.379169 2026] [security2:error] [pid 60716:tid 60940] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1sPsx0SVFjrd623kcgAAAC4"]
[Thu Sep 17 15:47:05.387364 2026] [security2:error] [pid 60716:tid 60903] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1sPsx0SVFjrd623keQAAAAs"]
[Thu Sep 17 15:47:05.407707 2026] [security2:error] [pid 60716:tid 60934] [client 34.166.197.112:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/www/phpinfo.php"] [unique_id "aqxf2cPsx0SVFjrd623k-gAAACg"]
[Thu Sep 17 15:47:05.437113 2026] [security2:error] [pid 60716:tid 61010] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1sPsx0SVFjrd623kdQAAAHQ"]
[Thu Sep 17 15:47:05.445512 2026] [security2:error] [pid 60716:tid 60958] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623kjAAAAEA"]
[Thu Sep 17 15:47:05.449090 2026] [security2:error] [pid 60716:tid 61000] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623kigAAAGo"]
[Thu Sep 17 15:47:05.449313 2026] [security2:error] [pid 60716:tid 60967] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf1sPsx0SVFjrd623kdwAAAEk"]
[Thu Sep 17 15:47:05.456181 2026] [security2:error] [pid 60716:tid 60998] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623kjQAAAGg"]
[Thu Sep 17 15:47:05.555934 2026] [security2:error] [pid 60716:tid 61011] [client 143.105.152.240:27281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623lCAAAAHU"]
[Thu Sep 17 15:47:05.570942 2026] [security2:error] [pid 60716:tid 61011] [client 143.105.152.240:27281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623lCAAAAHU"]
[Thu Sep 17 15:47:05.612070 2026] [security2:error] [pid 60716:tid 60965] [client 122.8.45.84:32717] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623lEwAAAEc"]
[Thu Sep 17 15:47:05.612196 2026] [security2:error] [pid 60716:tid 60965] [client 122.8.45.84:32717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2cPsx0SVFjrd623lEwAAAEc"]
[Thu Sep 17 15:47:05.736230 2026] [security2:error] [pid 60716:tid 60800] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxf2cPsx0SVFjrd623lHQAAISY"]
[Thu Sep 17 15:47:05.863697 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.246.111:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/phpversion.php"] [unique_id "aqxf2cPsx0SVFjrd623lKgAAAFU"]
[Thu Sep 17 15:47:05.869968 2026] [security2:error] [pid 60716:tid 60980] [client 4.240.114.86:60637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "aqxf2cPsx0SVFjrd623lKwAAAFY"], referer: binance.com
[Thu Sep 17 15:47:05.918036 2026] [security2:error] [pid 60716:tid 60783] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxf2cPsx0SVFjrd623lLAAAIRY"]
[Thu Sep 17 15:47:05.919707 2026] [security2:error] [pid 60716:tid 60866] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/id_rsa"] [unique_id "aqxf2cPsx0SVFjrd623lLQAAIWg"]
[Thu Sep 17 15:47:06.117582 2026] [security2:error] [pid 60716:tid 60999] [client 34.166.197.112:55098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxf2sPsx0SVFjrd623lPAAAAGk"]
[Thu Sep 17 15:47:06.174425 2026] [security2:error] [pid 60716:tid 60908] [client 35.228.4.121:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/server-info.php"] [unique_id "aqxf2sPsx0SVFjrd623lPwAAABA"]
[Thu Sep 17 15:47:06.263061 2026] [security2:error] [pid 60716:tid 60974] [client 177.44.133.72:61052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf2sPsx0SVFjrd623lQwAAAFA"]
[Thu Sep 17 15:47:06.263223 2026] [security2:error] [pid 60716:tid 60974] [client 177.44.133.72:61052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf2sPsx0SVFjrd623lQwAAAFA"]
[Thu Sep 17 15:47:06.303093 2026] [security2:error] [pid 60716:tid 60943] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623kkAAAADE"]
[Thu Sep 17 15:47:06.352780 2026] [security2:error] [pid 60716:tid 61010] [client 34.154.246.111:58614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/_phpinfo.php"] [unique_id "aqxf2sPsx0SVFjrd623lRwAAAHQ"]
[Thu Sep 17 15:47:06.383895 2026] [security2:error] [pid 60716:tid 60915] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623krwAAABc"]
[Thu Sep 17 15:47:06.428196 2026] [security2:error] [pid 60716:tid 60986] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623kqgAAAFw"]
[Thu Sep 17 15:47:06.439918 2026] [security2:error] [pid 60716:tid 60906] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623ktwAAAA4"]
[Thu Sep 17 15:47:06.607574 2026] [security2:error] [pid 60716:tid 60978] [client 40.77.167.157:21803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impactreliability.com"] [uri "/index.php"] [unique_id "aqxf1cPsx0SVFjrd623j0gAAVEg"]
[Thu Sep 17 15:47:06.666264 2026] [security2:error] [pid 60716:tid 60903] [client 122.8.45.84:12191] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2sPsx0SVFjrd623lWwAAAAs"]
[Thu Sep 17 15:47:06.666393 2026] [security2:error] [pid 60716:tid 60903] [client 122.8.45.84:12191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf2sPsx0SVFjrd623lWwAAAAs"]
[Thu Sep 17 15:47:06.796015 2026] [security2:error] [pid 60716:tid 60927] [client 34.166.197.112:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/public_html/phpinfo.php"] [unique_id "aqxf2sPsx0SVFjrd623laQAAACI"]
[Thu Sep 17 15:47:06.866361 2026] [security2:error] [pid 60716:tid 60962] [client 34.154.246.111:58630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/old_phpinfo.php"] [unique_id "aqxf2sPsx0SVFjrd623lbAAAAEQ"]
[Thu Sep 17 15:47:06.912147 2026] [security2:error] [pid 60716:tid 61013] [client 35.228.4.121:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/server-status.php"] [unique_id "aqxf2sPsx0SVFjrd623lcwAAAHc"]
[Thu Sep 17 15:47:06.946290 2026] [security2:error] [pid 60716:tid 60938] [client 41.250.130.31:45596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxf2sPsx0SVFjrd623lagAALAs"]
[Thu Sep 17 15:47:07.256829 2026] [security2:error] [pid 60716:tid 60913] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf18Psx0SVFjrd623krQAAABU"]
[Thu Sep 17 15:47:07.379233 2026] [security2:error] [pid 60716:tid 60968] [client 34.154.246.111:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/server-info.php"] [unique_id "aqxf28Psx0SVFjrd623lgQAAAEo"]
[Thu Sep 17 15:47:07.479517 2026] [security2:error] [pid 60716:tid 60899] [client 34.166.197.112:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/site/phpinfo.php"] [unique_id "aqxf28Psx0SVFjrd623lhAAAAAc"]
[Thu Sep 17 15:47:07.728759 2026] [security2:error] [pid 60716:tid 60994] [client 122.8.45.84:16645] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf28Psx0SVFjrd623lkQAAAGQ"]
[Thu Sep 17 15:47:07.728908 2026] [security2:error] [pid 60716:tid 60994] [client 122.8.45.84:16645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf28Psx0SVFjrd623lkQAAAGQ"]
[Thu Sep 17 15:47:07.895004 2026] [security2:error] [pid 60716:tid 60942] [client 34.154.246.111:58644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/server-status.php"] [unique_id "aqxf28Psx0SVFjrd623llAAAADA"]
[Thu Sep 17 15:47:07.907474 2026] [security2:error] [pid 60716:tid 60923] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxf28Psx0SVFjrd623ljwAAAB4"]
[Thu Sep 17 15:47:08.129757 2026] [security2:error] [pid 60716:tid 60955] [client 79.116.89.151:62999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3MPsx0SVFjrd623lnQAAAD0"]
[Thu Sep 17 15:47:08.129874 2026] [security2:error] [pid 60716:tid 60955] [client 79.116.89.151:62999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3MPsx0SVFjrd623lnQAAAD0"]
[Thu Sep 17 15:47:08.174525 2026] [security2:error] [pid 60716:tid 60971] [client 34.166.197.112:55122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/docs/phpinfo.php"] [unique_id "aqxf3MPsx0SVFjrd623loQAAAE0"]
[Thu Sep 17 15:47:08.338999 2026] [security2:error] [pid 60716:tid 61002] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lIgAAAGw"]
[Thu Sep 17 15:47:08.343877 2026] [security2:error] [pid 60716:tid 60949] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lKAAAADc"]
[Thu Sep 17 15:47:08.345427 2026] [security2:error] [pid 60716:tid 61009] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lDwAAAHM"]
[Thu Sep 17 15:47:08.352103 2026] [security2:error] [pid 60716:tid 60920] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lEAAAABw"]
[Thu Sep 17 15:47:08.356469 2026] [security2:error] [pid 60716:tid 60916] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lEQAAABg"]
[Thu Sep 17 15:47:08.388999 2026] [security2:error] [pid 60716:tid 60892] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2sPsx0SVFjrd623lNgAAAAA"]
[Thu Sep 17 15:47:08.442393 2026] [security2:error] [pid 60716:tid 60936] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lEgAAACo"]
[Thu Sep 17 15:47:08.470170 2026] [security2:error] [pid 60716:tid 60909] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lJAAAABE"]
[Thu Sep 17 15:47:08.687521 2026] [security2:error] [pid 60716:tid 60969] [client 122.8.45.84:55575] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3MPsx0SVFjrd623lxQAAAEs"]
[Thu Sep 17 15:47:08.687653 2026] [security2:error] [pid 60716:tid 60969] [client 122.8.45.84:55575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3MPsx0SVFjrd623lxQAAAEs"]
[Thu Sep 17 15:47:08.839335 2026] [security2:error] [pid 60716:tid 60958] [client 51.8.102.235:12807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.espiral.com.mx"] [uri "/index.php"] [unique_id "aqxf28Psx0SVFjrd623lewAAQGE"]
[Thu Sep 17 15:47:08.869147 2026] [security2:error] [pid 60716:tid 60941] [client 34.166.197.112:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxf3MPsx0SVFjrd623l1gAAAC8"]
[Thu Sep 17 15:47:08.926193 2026] [security2:error] [pid 60716:tid 60882] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/config.php"] [unique_id "aqxf3MPsx0SVFjrd623l2gAAIXg"]
[Thu Sep 17 15:47:09.257693 2026] [security2:error] [pid 60716:tid 61007] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lJQAAAHE"]
[Thu Sep 17 15:47:09.376142 2026] [security2:error] [pid 60716:tid 61006] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2sPsx0SVFjrd623ldwAAAHA"]
[Thu Sep 17 15:47:09.443314 2026] [security2:error] [pid 60716:tid 60918] [client 35.228.4.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mesuradocooperative.com"] [uri "/index.php"] [unique_id "aqxf3cPsx0SVFjrd623l8wAAABo"]
[Thu Sep 17 15:47:09.450214 2026] [security2:error] [pid 60716:tid 60933] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2sPsx0SVFjrd623lcgAAACc"]
[Thu Sep 17 15:47:09.462362 2026] [security2:error] [pid 60716:tid 61016] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2cPsx0SVFjrd623lDgAAAHo"]
[Thu Sep 17 15:47:09.481851 2026] [security2:error] [pid 60716:tid 60900] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2sPsx0SVFjrd623lZQAAAAg"]
[Thu Sep 17 15:47:09.557290 2026] [security2:error] [pid 60716:tid 60983] [client 34.166.197.112:55136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/administrator/phpinfo.php"] [unique_id "aqxf3cPsx0SVFjrd623mCAAAAFk"]
[Thu Sep 17 15:47:09.603190 2026] [security2:error] [pid 60716:tid 60914] [client 34.154.246.111:58672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/webroot/index.php/_environment"] [unique_id "aqxf3cPsx0SVFjrd623mDAAAABY"]
[Thu Sep 17 15:47:09.703963 2026] [security2:error] [pid 60716:tid 60911] [client 122.8.45.84:40349] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3cPsx0SVFjrd623mEQAAABM"]
[Thu Sep 17 15:47:09.704086 2026] [security2:error] [pid 60716:tid 60911] [client 122.8.45.84:40349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3cPsx0SVFjrd623mEQAAABM"]
[Thu Sep 17 15:47:10.061999 2026] [security2:error] [pid 60716:tid 60943] [client 169.58.197.251:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxf3sPsx0SVFjrd623mGwAAADE"], referer: binance.com
[Thu Sep 17 15:47:10.081091 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.246.111:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/mail/phpinfo.php"] [unique_id "aqxf3sPsx0SVFjrd623mHAAAAEU"]
[Thu Sep 17 15:47:10.240318 2026] [security2:error] [pid 60716:tid 61002] [client 34.166.197.112:55148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/core/phpinfo.php"] [unique_id "aqxf3sPsx0SVFjrd623mIgAAAGw"]
[Thu Sep 17 15:47:10.257371 2026] [security2:error] [pid 60716:tid 60966] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2sPsx0SVFjrd623lWgAAAEg"]
[Thu Sep 17 15:47:10.288842 2026] [security2:error] [pid 60716:tid 61008] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2sPsx0SVFjrd623lZgAAAHI"]
[Thu Sep 17 15:47:10.309632 2026] [security2:error] [pid 60716:tid 60987] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf2sPsx0SVFjrd623lUwAAAF0"]
[Thu Sep 17 15:47:10.423414 2026] [security2:error] [pid 60716:tid 60894] [client 35.228.4.121:34622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxf3sPsx0SVFjrd623mJgAAAAI"]
[Thu Sep 17 15:47:10.594035 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.246.111:58690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxf3sPsx0SVFjrd623mLwAAACM"]
[Thu Sep 17 15:47:10.660239 2026] [security2:error] [pid 60716:tid 60995] [client 122.8.45.84:19953] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3sPsx0SVFjrd623mMgAAAGU"]
[Thu Sep 17 15:47:10.660514 2026] [security2:error] [pid 60716:tid 60995] [client 122.8.45.84:19953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf3sPsx0SVFjrd623mMgAAAGU"]
[Thu Sep 17 15:47:10.804512 2026] [security2:error] [pid 60716:tid 60934] [client 169.58.198.243:65049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "aqxf3sPsx0SVFjrd623mNwAAACg"], referer: www.google.com
[Thu Sep 17 15:47:10.892361 2026] [autoindex:error] [pid 60716:tid 60896] [client 169.58.197.251:50639] AH01276: Cannot serve directory /home1/cathihat/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Sep 17 15:47:10.918391 2026] [security2:error] [pid 60716:tid 60994] [client 34.166.197.112:55160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.197.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ppfc.net"] [uri "/includes/phpinfo.php"] [unique_id "aqxf3sPsx0SVFjrd623mPwAAAGQ"]
[Thu Sep 17 15:47:11.030391 2026] [security2:error] [pid 60716:tid 60968] [client 4.240.114.86:63012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "aqxf38Psx0SVFjrd623mSAAAAEo"], referer: binance.com
[Thu Sep 17 15:47:11.087343 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.246.111:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/hosting/phpinfo.php"] [unique_id "aqxf38Psx0SVFjrd623mSwAAADI"]
[Thu Sep 17 15:47:11.143989 2026] [security2:error] [pid 60716:tid 60991] [client 35.228.4.121:60810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxf38Psx0SVFjrd623mUQAAAGE"]
[Thu Sep 17 15:47:11.323433 2026] [security2:error] [pid 60716:tid 60988] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3MPsx0SVFjrd623lvgAAAF4"]
[Thu Sep 17 15:47:11.324137 2026] [security2:error] [pid 60716:tid 60978] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3MPsx0SVFjrd623lwwAAAFQ"]
[Thu Sep 17 15:47:11.348533 2026] [security2:error] [pid 60716:tid 60948] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3MPsx0SVFjrd623l0gAAADY"]
[Thu Sep 17 15:47:11.350584 2026] [security2:error] [pid 60716:tid 60982] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3MPsx0SVFjrd623lvwAAAFg"]
[Thu Sep 17 15:47:11.355619 2026] [security2:error] [pid 60716:tid 60898] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3MPsx0SVFjrd623lwAAAAAY"]
[Thu Sep 17 15:47:11.359496 2026] [security2:error] [pid 60716:tid 60908] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3cPsx0SVFjrd623l9AAAABA"]
[Thu Sep 17 15:47:11.372841 2026] [security2:error] [pid 60716:tid 60998] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3cPsx0SVFjrd623l9gAAAGg"]
[Thu Sep 17 15:47:11.375844 2026] [security2:error] [pid 60716:tid 61003] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3MPsx0SVFjrd623l0wAAAG0"]
[Thu Sep 17 15:47:11.384938 2026] [security2:error] [pid 60716:tid 60957] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3MPsx0SVFjrd623lwgAAAD8"]
[Thu Sep 17 15:47:11.461032 2026] [security2:error] [pid 60716:tid 60940] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3cPsx0SVFjrd623mDgAAAC4"]
[Thu Sep 17 15:47:11.463283 2026] [security2:error] [pid 60716:tid 60923] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3cPsx0SVFjrd623mBAAAAB4"]
[Thu Sep 17 15:47:11.467087 2026] [security2:error] [pid 60716:tid 60942] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf3cPsx0SVFjrd623mAwAAADA"]
[Thu Sep 17 15:47:11.533907 2026] [security2:error] [pid 60716:tid 60802] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/config/aws.php"] [unique_id "aqxf38Psx0SVFjrd623maQAAISg"]
[Thu Sep 17 15:47:11.536093 2026] [security2:error] [pid 60716:tid 60774] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/config/stripe.php"] [unique_id "aqxf38Psx0SVFjrd623mawAAIQ4"]
[Thu Sep 17 15:47:11.598368 2026] [security2:error] [pid 60716:tid 61020] [client 122.8.45.84:15977] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf38Psx0SVFjrd623mcAAAAH4"]
[Thu Sep 17 15:47:11.598454 2026] [security2:error] [pid 60716:tid 61020] [client 122.8.45.84:15977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf38Psx0SVFjrd623mcAAAAH4"]
[Thu Sep 17 15:47:11.629484 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.246.111:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/webmail/phpinfo.php"] [unique_id "aqxf38Psx0SVFjrd623mdAAAAEY"]
[Thu Sep 17 15:47:11.689901 2026] [security2:error] [pid 60716:tid 60997] [client 142.132.180.39:28398] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "faewave.com"] [uri "/index.html"] [unique_id "aqxf38Psx0SVFjrd623meAAAAGc"], referer: https://faewave.com
[Thu Sep 17 15:47:11.718570 2026] [security2:error] [pid 60716:tid 60823] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/config/config.inc.php"] [unique_id "aqxf38Psx0SVFjrd623megAAIT0"]
[Thu Sep 17 15:47:11.718600 2026] [security2:error] [pid 60716:tid 60759] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/config/mail.php"] [unique_id "aqxf38Psx0SVFjrd623mfAAAIQE"]
[Thu Sep 17 15:47:11.719082 2026] [security2:error] [pid 60716:tid 60870] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/config/nexmo.php"] [unique_id "aqxf38Psx0SVFjrd623mfgAAIWw"]
[Thu Sep 17 15:47:11.901087 2026] [security2:error] [pid 60716:tid 60799] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/wp-config.php"] [unique_id "aqxf38Psx0SVFjrd623mhgAAISU"]
[Thu Sep 17 15:47:11.901711 2026] [security2:error] [pid 60716:tid 60766] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thezoeyline.com"] [uri "/wp-config.php.new"] [unique_id "aqxf38Psx0SVFjrd623miQAAIQc"]
[Thu Sep 17 15:47:11.901713 2026] [security2:error] [pid 60716:tid 60848] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thezoeyline.com"] [uri "/wp-config.php.old"] [unique_id "aqxf38Psx0SVFjrd623miAAAIVY"]
[Thu Sep 17 15:47:11.901728 2026] [security2:error] [pid 60716:tid 60775] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thezoeyline.com"] [uri "/wp-config.php.bak"] [unique_id "aqxf38Psx0SVFjrd623mhwAAIQ8"]
[Thu Sep 17 15:47:11.902055 2026] [security2:error] [pid 60716:tid 60841] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxf38Psx0SVFjrd623migAAIU8"]
[Thu Sep 17 15:47:11.902538 2026] [security2:error] [pid 60716:tid 60801] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxf38Psx0SVFjrd623mjQAAISc"]
[Thu Sep 17 15:47:12.120403 2026] [security2:error] [pid 60716:tid 60999] [client 34.154.246.111:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/smtp/phpinfo.php"] [unique_id "aqxf4MPsx0SVFjrd623mowAAAGk"]
[Thu Sep 17 15:47:12.151107 2026] [security2:error] [pid 60716:tid 60914] [client 74.7.227.128:44046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kopecdental.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mmQAAFhY"], referer: http://kopecdental.com
[Thu Sep 17 15:47:12.251588 2026] [security2:error] [pid 60716:tid 60977] [client 35.228.4.121:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxf4MPsx0SVFjrd623mqgAAAFM"]
[Thu Sep 17 15:47:12.265175 2026] [security2:error] [pid 60716:tid 60816] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxf4MPsx0SVFjrd623mrAAAITY"]
[Thu Sep 17 15:47:12.555034 2026] [security2:error] [pid 60716:tid 60948] [client 122.8.45.84:23777] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf4MPsx0SVFjrd623mzgAAADY"]
[Thu Sep 17 15:47:12.555147 2026] [security2:error] [pid 60716:tid 60948] [client 122.8.45.84:23777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf4MPsx0SVFjrd623mzgAAADY"]
[Thu Sep 17 15:47:12.625828 2026] [security2:error] [pid 60716:tid 60904] [client 34.154.246.111:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/phpinfo.php.bak"] [unique_id "aqxf4MPsx0SVFjrd623m0AAAAAw"]
[Thu Sep 17 15:47:12.659747 2026] [security2:error] [pid 60716:tid 60896] [client 169.58.197.253:53728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxf4MPsx0SVFjrd623m0gAAAAQ"], referer: binance.com
[Thu Sep 17 15:47:12.720518 2026] [security2:error] [pid 60716:tid 60967] [client 52.167.144.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "impact100sydneynorth.org"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mTwAAAEk"]
[Thu Sep 17 15:47:13.019099 2026] [security2:error] [pid 60716:tid 60997] [client 35.228.4.121:60826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxf4cPsx0SVFjrd623m5QAAAGc"]
[Thu Sep 17 15:47:13.119895 2026] [security2:error] [pid 60716:tid 60899] [client 34.154.246.111:58728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/phpinfo.php.old"] [unique_id "aqxf4cPsx0SVFjrd623m6gAAAAc"]
[Thu Sep 17 15:47:13.321792 2026] [security2:error] [pid 60716:tid 60949] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mYgAAADc"]
[Thu Sep 17 15:47:13.324100 2026] [security2:error] [pid 60716:tid 61000] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mYQAAAGo"]
[Thu Sep 17 15:47:13.341404 2026] [security2:error] [pid 60716:tid 61016] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mYwAAAHo"]
[Thu Sep 17 15:47:13.373992 2026] [security2:error] [pid 60716:tid 60995] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mYAAAAGU"]
[Thu Sep 17 15:47:13.536092 2026] [security2:error] [pid 60716:tid 61015] [client 122.8.45.84:50977] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf4cPsx0SVFjrd623nCwAAAHk"]
[Thu Sep 17 15:47:13.536206 2026] [security2:error] [pid 60716:tid 61015] [client 122.8.45.84:50977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf4cPsx0SVFjrd623nCwAAAHk"]
[Thu Sep 17 15:47:13.618856 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.246.111:58734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/phpinfo.php~"] [unique_id "aqxf4cPsx0SVFjrd623nEAAAAFk"]
[Thu Sep 17 15:47:13.773777 2026] [security2:error] [pid 60716:tid 60946] [client 35.228.4.121:60838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxf4cPsx0SVFjrd623nGgAAADQ"]
[Thu Sep 17 15:47:14.110476 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.246.111:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/info.php.bak"] [unique_id "aqxf4sPsx0SVFjrd623nJgAAABg"]
[Thu Sep 17 15:47:14.537778 2026] [security2:error] [pid 60716:tid 60955] [client 122.8.45.84:44627] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf4sPsx0SVFjrd623nOQAAAD0"]
[Thu Sep 17 15:47:14.537871 2026] [security2:error] [pid 60716:tid 60955] [client 122.8.45.84:44627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf4sPsx0SVFjrd623nOQAAAD0"]
[Thu Sep 17 15:47:14.565555 2026] [security2:error] [pid 60716:tid 60965] [client 35.228.4.121:60852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxf4sPsx0SVFjrd623nPAAAAEc"]
[Thu Sep 17 15:47:14.611476 2026] [security2:error] [pid 60716:tid 60980] [client 34.154.246.111:58740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/phpinfo.php.save"] [unique_id "aqxf4sPsx0SVFjrd623nPQAAAFY"]
[Thu Sep 17 15:47:14.853866 2026] [security2:error] [pid 60716:tid 60946] [client 177.98.118.166:51862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxf4sPsx0SVFjrd623nRAAANC4"]
[Thu Sep 17 15:47:15.095357 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.246.111:58756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/staging/phpinfo.php"] [unique_id "aqxf48Psx0SVFjrd623nUQAAAAY"]
[Thu Sep 17 15:47:15.294034 2026] [security2:error] [pid 60716:tid 60905] [client 35.228.4.121:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxf48Psx0SVFjrd623nWQAAAA0"]
[Thu Sep 17 15:47:15.354292 2026] [security2:error] [pid 60716:tid 60968] [client 4.240.114.86:64966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-filter-sentinel.php"] [unique_id "aqxf48Psx0SVFjrd623nWgAAAEo"], referer: binance.com
[Thu Sep 17 15:47:15.498941 2026] [security2:error] [pid 60716:tid 60956] [client 122.8.45.84:61391] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf48Psx0SVFjrd623nXwAAAD4"]
[Thu Sep 17 15:47:15.499088 2026] [security2:error] [pid 60716:tid 60956] [client 122.8.45.84:61391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf48Psx0SVFjrd623nXwAAAD4"]
[Thu Sep 17 15:47:15.590508 2026] [security2:error] [pid 60716:tid 60967] [client 34.154.246.111:58760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/beta/phpinfo.php"] [unique_id "aqxf48Psx0SVFjrd623nZgAAAEk"]
[Thu Sep 17 15:47:15.617443 2026] [security2:error] [pid 60716:tid 61018] [client 14.96.156.146:50742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf48Psx0SVFjrd623nZwAAAHw"]
[Thu Sep 17 15:47:15.617544 2026] [security2:error] [pid 60716:tid 61018] [client 14.96.156.146:50742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf48Psx0SVFjrd623nZwAAAHw"]
[Thu Sep 17 15:47:15.905571 2026] [security2:error] [pid 60716:tid 60919] [client 148.227.75.216:35188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf48Psx0SVFjrd623ndgAAABs"]
[Thu Sep 17 15:47:15.905717 2026] [security2:error] [pid 60716:tid 60919] [client 148.227.75.216:35188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf48Psx0SVFjrd623ndgAAABs"]
[Thu Sep 17 15:47:16.058648 2026] [security2:error] [pid 60716:tid 60900] [client 34.154.246.111:48128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/uat/phpinfo.php"] [unique_id "aqxf5MPsx0SVFjrd623nfgAAAAg"]
[Thu Sep 17 15:47:16.129940 2026] [security2:error] [pid 60716:tid 60982] [client 143.105.152.240:23389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf5MPsx0SVFjrd623ngQAAAFg"]
[Thu Sep 17 15:47:16.130064 2026] [security2:error] [pid 60716:tid 60982] [client 143.105.152.240:23389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf5MPsx0SVFjrd623ngQAAAFg"]
[Thu Sep 17 15:47:16.188923 2026] [security2:error] [pid 60716:tid 61000] [client 35.228.4.121:60878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/phpinfo.php.old"] [unique_id "aqxf5MPsx0SVFjrd623niAAAAGo"]
[Thu Sep 17 15:47:16.260013 2026] [security2:error] [pid 60716:tid 60963] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mlgAAAEU"]
[Thu Sep 17 15:47:16.271153 2026] [security2:error] [pid 60716:tid 60952] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mpwAAADo"]
[Thu Sep 17 15:47:16.285372 2026] [security2:error] [pid 60716:tid 60957] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mtQAAAD8"]
[Thu Sep 17 15:47:16.286623 2026] [security2:error] [pid 60716:tid 60991] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mkwAAAGE"]
[Thu Sep 17 15:47:16.308396 2026] [security2:error] [pid 60716:tid 61009] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mbwAAAHM"]
[Thu Sep 17 15:47:16.313647 2026] [security2:error] [pid 60716:tid 60920] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mkgAAABw"]
[Thu Sep 17 15:47:16.325332 2026] [security2:error] [pid 60716:tid 60923] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mxgAAAB4"]
[Thu Sep 17 15:47:16.326021 2026] [security2:error] [pid 60716:tid 60946] [client 169.58.197.251:51497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/icons.php"] [unique_id "aqxf5MPsx0SVFjrd623njQAAADQ"], referer: binance.com
[Thu Sep 17 15:47:16.327957 2026] [security2:error] [pid 60716:tid 60935] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mtAAAACk"]
[Thu Sep 17 15:47:16.352758 2026] [security2:error] [pid 60716:tid 60948] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4cPsx0SVFjrd623m_QAAADY"]
[Thu Sep 17 15:47:16.382145 2026] [security2:error] [pid 60716:tid 60985] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mgAAAAFs"]
[Thu Sep 17 15:47:16.389888 2026] [security2:error] [pid 60716:tid 60940] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mxQAAAC4"]
[Thu Sep 17 15:47:16.397990 2026] [security2:error] [pid 60716:tid 60766] [remote 45.138.12.24:50470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf38Psx0SVFjrd623mjAAAIQc"]
[Thu Sep 17 15:47:16.401194 2026] [security2:error] [pid 60716:tid 60969] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4MPsx0SVFjrd623mxwAAAEs"]
[Thu Sep 17 15:47:16.459966 2026] [security2:error] [pid 60716:tid 60943] [client 122.8.45.84:20229] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5MPsx0SVFjrd623nkgAAADE"]
[Thu Sep 17 15:47:16.460092 2026] [security2:error] [pid 60716:tid 60943] [client 122.8.45.84:20229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5MPsx0SVFjrd623nkgAAADE"]
[Thu Sep 17 15:47:16.500845 2026] [security2:error] [pid 60716:tid 61019] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4cPsx0SVFjrd623nDAAAAH0"]
[Thu Sep 17 15:47:16.573096 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.246.111:48132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/qa/phpinfo.php"] [unique_id "aqxf5MPsx0SVFjrd623nnwAAABg"]
[Thu Sep 17 15:47:16.906375 2026] [security2:error] [pid 60716:tid 60913] [client 177.44.133.72:61721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf5MPsx0SVFjrd623nrQAAABU"]
[Thu Sep 17 15:47:16.906533 2026] [security2:error] [pid 60716:tid 60913] [client 177.44.133.72:61721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf5MPsx0SVFjrd623nrQAAABU"]
[Thu Sep 17 15:47:16.929974 2026] [security2:error] [pid 60716:tid 60909] [client 35.228.4.121:60882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/phpinfo.php~"] [unique_id "aqxf5MPsx0SVFjrd623nrgAAABE"]
[Thu Sep 17 15:47:17.055713 2026] [security2:error] [pid 60716:tid 61001] [client 34.154.246.111:48138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/preview/phpinfo.php"] [unique_id "aqxf5cPsx0SVFjrd623ntwAAAGs"]
[Thu Sep 17 15:47:17.209752 2026] [security2:error] [pid 60716:tid 60971] [client 45.156.129.60:53954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lasvegaslife.info"] [uri "/index.php"] [unique_id "aqxf5MPsx0SVFjrd623nrAAATQI"]
[Thu Sep 17 15:47:17.271633 2026] [security2:error] [pid 60716:tid 60901] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4cPsx0SVFjrd623nCgAAAAk"]
[Thu Sep 17 15:47:17.286263 2026] [security2:error] [pid 60716:tid 60934] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf4cPsx0SVFjrd623m_gAAACg"]
[Thu Sep 17 15:47:17.403475 2026] [security2:error] [pid 60716:tid 61018] [client 74.7.230.1:60790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623nvwAAfBw"]
[Thu Sep 17 15:47:17.428276 2026] [security2:error] [pid 60716:tid 61013] [client 122.8.45.84:31101] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5cPsx0SVFjrd623n1QAAAHc"]
[Thu Sep 17 15:47:17.428453 2026] [security2:error] [pid 60716:tid 61013] [client 122.8.45.84:31101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5cPsx0SVFjrd623n1QAAAHc"]
[Thu Sep 17 15:47:17.472088 2026] [security2:error] [pid 60716:tid 60983] [client 129.212.238.116:47830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxf5MPsx0SVFjrd623njAAAWRM"], referer: http://www.adventuresofapril.com/backup/
[Thu Sep 17 15:47:17.540553 2026] [security2:error] [pid 60716:tid 60940] [client 34.154.246.111:48146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/www/phpinfo.php"] [unique_id "aqxf5cPsx0SVFjrd623n3QAAAC4"]
[Thu Sep 17 15:47:17.639056 2026] [security2:error] [pid 60716:tid 60978] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623n0QAAAFQ"]
[Thu Sep 17 15:47:17.651985 2026] [security2:error] [pid 60716:tid 61014] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623nzwAAAHg"]
[Thu Sep 17 15:47:17.652534 2026] [security2:error] [pid 60716:tid 60954] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623n0wAAADw"]
[Thu Sep 17 15:47:17.676969 2026] [security2:error] [pid 60716:tid 60977] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623n0gAAAFM"]
[Thu Sep 17 15:47:17.678308 2026] [security2:error] [pid 60716:tid 61021] [client 45.156.129.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lasvegaslife.info"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623nzQAAAH8"]
[Thu Sep 17 15:47:17.745905 2026] [security2:error] [pid 60716:tid 61012] [client 35.228.4.121:60892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/info.php.bak"] [unique_id "aqxf5cPsx0SVFjrd623n_QAAAHY"]
[Thu Sep 17 15:47:17.842672 2026] [security2:error] [pid 60716:tid 60990] [client 136.158.61.34:1810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5cPsx0SVFjrd623oBAAAAGA"]
[Thu Sep 17 15:47:17.842775 2026] [security2:error] [pid 60716:tid 60990] [client 136.158.61.34:1810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5cPsx0SVFjrd623oBAAAAGA"]
[Thu Sep 17 15:47:17.918857 2026] [security2:error] [pid 60716:tid 60906] [client 129.212.238.116:47830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623oCQAADg4"], referer: http://www.adventuresofapril.com/wp/
[Thu Sep 17 15:47:18.065273 2026] [security2:error] [pid 60716:tid 60944] [client 34.154.246.111:48162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxf5sPsx0SVFjrd623oEwAAADI"]
[Thu Sep 17 15:47:18.381267 2026] [security2:error] [pid 60716:tid 60920] [client 129.212.238.116:47830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxf5sPsx0SVFjrd623oIAAAHAE"], referer: http://www.adventuresofapril.com/new/
[Thu Sep 17 15:47:18.412344 2026] [security2:error] [pid 60716:tid 60993] [client 122.8.45.84:63929] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5sPsx0SVFjrd623oIwAAAGM"]
[Thu Sep 17 15:47:18.412491 2026] [security2:error] [pid 60716:tid 60993] [client 122.8.45.84:63929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf5sPsx0SVFjrd623oIwAAAGM"]
[Thu Sep 17 15:47:18.453677 2026] [security2:error] [pid 60716:tid 60976] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623n-AAAAFI"]
[Thu Sep 17 15:47:18.455147 2026] [security2:error] [pid 60716:tid 60968] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623n9wAAAEo"]
[Thu Sep 17 15:47:18.482456 2026] [security2:error] [pid 60716:tid 60936] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623n_AAAACo"]
[Thu Sep 17 15:47:18.485276 2026] [security2:error] [pid 60716:tid 60925] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623n-gAAACA"]
[Thu Sep 17 15:47:18.535238 2026] [security2:error] [pid 60716:tid 60969] [client 35.228.4.121:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/phpinfo.php.save"] [unique_id "aqxf5sPsx0SVFjrd623oKAAAAEs"]
[Thu Sep 17 15:47:18.537592 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.246.111:48164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/public_html/phpinfo.php"] [unique_id "aqxf5sPsx0SVFjrd623oKQAAAFk"]
[Thu Sep 17 15:47:18.864417 2026] [security2:error] [pid 60716:tid 61005] [client 169.58.197.253:54169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxf5sPsx0SVFjrd623oNAAAAG8"], referer: binance.com
[Thu Sep 17 15:47:19.026250 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.246.111:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/site/phpinfo.php"] [unique_id "aqxf58Psx0SVFjrd623oOAAAAAY"]
[Thu Sep 17 15:47:19.058505 2026] [security2:error] [pid 60716:tid 60937] [client 129.212.238.116:47830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oNwAAKyY"], referer: http://www.adventuresofapril.com/wordpress/
[Thu Sep 17 15:47:19.275635 2026] [security2:error] [pid 60716:tid 60964] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623oAAAAAEY"]
[Thu Sep 17 15:47:19.297123 2026] [security2:error] [pid 60716:tid 60974] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623oDAAAAFA"]
[Thu Sep 17 15:47:19.297124 2026] [security2:error] [pid 60716:tid 60904] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623oCwAAAAw"]
[Thu Sep 17 15:47:19.299722 2026] [security2:error] [pid 60716:tid 60942] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf5cPsx0SVFjrd623oCgAAADA"]
[Thu Sep 17 15:47:19.365753 2026] [security2:error] [pid 60716:tid 60947] [client 122.8.45.84:35653] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf58Psx0SVFjrd623oUAAAADU"]
[Thu Sep 17 15:47:19.365877 2026] [security2:error] [pid 60716:tid 60947] [client 122.8.45.84:35653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf58Psx0SVFjrd623oUAAAADU"]
[Thu Sep 17 15:47:19.472219 2026] [security2:error] [pid 60716:tid 60990] [client 129.212.220.28:41612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oTwAAAGA"]
[Thu Sep 17 15:47:19.492126 2026] [security2:error] [pid 60716:tid 60911] [client 34.154.246.111:48172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/docs/phpinfo.php"] [unique_id "aqxf58Psx0SVFjrd623oWAAAABM"]
[Thu Sep 17 15:47:19.497872 2026] [security2:error] [pid 60716:tid 60933] [client 35.228.4.121:60916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxf58Psx0SVFjrd623oWgAAACc"]
[Thu Sep 17 15:47:19.511094 2026] [security2:error] [pid 60716:tid 60957] [client 129.212.238.116:47830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oVwAAPx8"], referer: http://www.adventuresofapril.com/old/
[Thu Sep 17 15:47:19.686130 2026] [security2:error] [pid 60716:tid 60899] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oTgAAAAc"]
[Thu Sep 17 15:47:19.704322 2026] [security2:error] [pid 60716:tid 60897] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oVAAAAAU"]
[Thu Sep 17 15:47:19.714226 2026] [security2:error] [pid 60716:tid 60997] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oUQAAAGc"]
[Thu Sep 17 15:47:19.715256 2026] [security2:error] [pid 60716:tid 60893] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oUgAAAAE"]
[Thu Sep 17 15:47:19.719430 2026] [security2:error] [pid 60716:tid 60854] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/phpinfo.php"] [unique_id "aqxf58Psx0SVFjrd623odQAAIVw"]
[Thu Sep 17 15:47:19.755272 2026] [security2:error] [pid 60716:tid 61004] [client 79.116.89.151:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf58Psx0SVFjrd623ogwAAAG4"]
[Thu Sep 17 15:47:19.755405 2026] [security2:error] [pid 60716:tid 61004] [client 79.116.89.151:63665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf58Psx0SVFjrd623ogwAAAG4"]
[Thu Sep 17 15:47:19.954940 2026] [security2:error] [pid 60716:tid 60984] [client 129.212.238.116:47830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adventuresofapril.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oiQAAWgA"], referer: http://www.adventuresofapril.com/blog/
[Thu Sep 17 15:47:19.974648 2026] [security2:error] [pid 60716:tid 61006] [client 34.154.246.111:48180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxf58Psx0SVFjrd623oiwAAAHA"]
[Thu Sep 17 15:47:20.087033 2026] [fcgid:warn] [pid 60716:tid 60927] (70014)End of file found: [client 152.32.169.155:38474] mod_fcgid: can't get data from http client
[Thu Sep 17 15:47:20.281095 2026] [security2:error] [pid 60716:tid 60917] [client 35.228.4.121:40726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623ooAAAABk"]
[Thu Sep 17 15:47:20.347831 2026] [security2:error] [pid 60716:tid 60898] [client 122.8.45.84:47041] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf6MPsx0SVFjrd623oogAAAAY"]
[Thu Sep 17 15:47:20.347957 2026] [security2:error] [pid 60716:tid 60898] [client 122.8.45.84:47041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf6MPsx0SVFjrd623oogAAAAY"]
[Thu Sep 17 15:47:20.456821 2026] [security2:error] [pid 60716:tid 60908] [client 34.154.246.111:48188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/administrator/phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623opQAAABA"]
[Thu Sep 17 15:47:20.838364 2026] [security2:error] [pid 60716:tid 60999] [client 162.241.226.11:13058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/tortuero2.plt"] [unique_id "aqxf6MPsx0SVFjrd623otgAAACA"]
[Thu Sep 17 15:47:20.870151 2026] [security2:error] [pid 60716:tid 60954] [client 162.241.226.11:13070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/tortuero2.plt"] [unique_id "aqxf6MPsx0SVFjrd623ouAAAADE"]
[Thu Sep 17 15:47:20.896503 2026] [security2:error] [pid 60716:tid 61017] [client 162.241.226.11:13080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1575"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.mtbclubdecampo.com"] [uri "/Rutas/El_Vado/perfil_tortuero2.png"] [unique_id "aqxf6MPsx0SVFjrd623ouQAAAHs"]
[Thu Sep 17 15:47:20.935309 2026] [security2:error] [pid 60716:tid 60993] [client 34.154.246.111:48198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/core/phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623ovQAAAGM"]
[Thu Sep 17 15:47:21.135108 2026] [security2:error] [pid 60716:tid 60998] [client 181.134.76.51:39544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxf6cPsx0SVFjrd623ovwAAaFg"]
[Thu Sep 17 15:47:21.202601 2026] [security2:error] [pid 60716:tid 60927] [client 34.95.14.119:34078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxf6cPsx0SVFjrd623oyAAAACI"]
[Thu Sep 17 15:47:21.255492 2026] [security2:error] [pid 60716:tid 61002] [client 35.228.4.121:40738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxf6cPsx0SVFjrd623oyQAAAGw"]
[Thu Sep 17 15:47:21.260375 2026] [security2:error] [pid 60716:tid 60962] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623ofgAAAEQ"]
[Thu Sep 17 15:47:21.278581 2026] [security2:error] [pid 60716:tid 60977] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623ofwAAAFM"]
[Thu Sep 17 15:47:21.280170 2026] [security2:error] [pid 60716:tid 60938] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oewAAACw"]
[Thu Sep 17 15:47:21.281011 2026] [security2:error] [pid 60716:tid 61015] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623ogQAAAHk"]
[Thu Sep 17 15:47:21.281951 2026] [security2:error] [pid 60716:tid 60929] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623ofQAAACQ"]
[Thu Sep 17 15:47:21.285315 2026] [security2:error] [pid 60716:tid 60965] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623oggAAAEc"]
[Thu Sep 17 15:47:21.292710 2026] [security2:error] [pid 60716:tid 60986] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623ofAAAAFw"]
[Thu Sep 17 15:47:21.300418 2026] [security2:error] [pid 60716:tid 61021] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf58Psx0SVFjrd623ogAAAAH8"]
[Thu Sep 17 15:47:21.315816 2026] [security2:error] [pid 60716:tid 60830] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/infos.php"] [unique_id "aqxf58Psx0SVFjrd623oygAAIUQ"]
[Thu Sep 17 15:47:21.315831 2026] [security2:error] [pid 60716:tid 60854] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/info.php"] [unique_id "aqxf58Psx0SVFjrd623oywAAIVw"]
[Thu Sep 17 15:47:21.316071 2026] [security2:error] [pid 60716:tid 60854] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/php.php"] [unique_id "aqxf58Psx0SVFjrd623ozQAAIVw"]
[Thu Sep 17 15:47:21.316141 2026] [security2:error] [pid 60716:tid 60830] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/php_info.php"] [unique_id "aqxf58Psx0SVFjrd623ozAAAIUQ"]
[Thu Sep 17 15:47:21.316157 2026] [security2:error] [pid 60716:tid 60824] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/infophp.php"] [unique_id "aqxf58Psx0SVFjrd623ozwAAIT4"]
[Thu Sep 17 15:47:21.316236 2026] [security2:error] [pid 60716:tid 60787] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/php-info.php"] [unique_id "aqxf58Psx0SVFjrd623ozgAAIRk"]
[Thu Sep 17 15:47:21.316429 2026] [security2:error] [pid 60716:tid 60830] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623o0QAAIUQ"]
[Thu Sep 17 15:47:21.316482 2026] [security2:error] [pid 60716:tid 60824] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623o0gAAIT4"]
[Thu Sep 17 15:47:21.316567 2026] [security2:error] [pid 60716:tid 60787] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623o0wAAIRk"]
[Thu Sep 17 15:47:21.316718 2026] [security2:error] [pid 60716:tid 60830] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/api/phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623o1AAAIUQ"]
[Thu Sep 17 15:47:21.316789 2026] [security2:error] [pid 60716:tid 60824] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/public/phpinfo.php"] [unique_id "aqxf6MPsx0SVFjrd623o1QAAIT4"]
[Thu Sep 17 15:47:21.320679 2026] [security2:error] [pid 60716:tid 60960] [client 122.8.45.84:64949] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf6cPsx0SVFjrd623o1gAAAEI"]
[Thu Sep 17 15:47:21.320775 2026] [security2:error] [pid 60716:tid 60960] [client 122.8.45.84:64949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf6cPsx0SVFjrd623o1gAAAEI"]
[Thu Sep 17 15:47:21.410464 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.246.111:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comfortspecialist.info"] [uri "/includes/phpinfo.php"] [unique_id "aqxf6cPsx0SVFjrd623o2QAAAEY"]
[Thu Sep 17 15:47:21.459142 2026] [security2:error] [pid 60716:tid 60902] [client 34.95.14.119:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/info.php"] [unique_id "aqxf6cPsx0SVFjrd623o3AAAAAo"]
[Thu Sep 17 15:47:21.668735 2026] [security2:error] [pid 60716:tid 60898] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623o2AAAAAY"]
[Thu Sep 17 15:47:21.701031 2026] [security2:error] [pid 60716:tid 60765] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/database.sql"] [unique_id "aqxf6cPsx0SVFjrd623o9wAAIQY"]
[Thu Sep 17 15:47:21.718074 2026] [security2:error] [pid 60716:tid 60940] [client 34.95.14.119:48098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/php.php"] [unique_id "aqxf6cPsx0SVFjrd623pCQAAAC4"]
[Thu Sep 17 15:47:21.930633 2026] [security2:error] [pid 60716:tid 60893] [client 35.228.4.121:40750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxf6cPsx0SVFjrd623pHgAAAAE"]
[Thu Sep 17 15:47:22.054738 2026] [security2:error] [pid 60716:tid 60909] [client 34.95.14.119:48106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/i.php"] [unique_id "aqxf6sPsx0SVFjrd623pKQAAABE"]
[Thu Sep 17 15:47:22.277892 2026] [security2:error] [pid 60716:tid 60928] [client 122.8.45.84:59529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf6sPsx0SVFjrd623pMgAAACM"]
[Thu Sep 17 15:47:22.278144 2026] [security2:error] [pid 60716:tid 60928] [client 122.8.45.84:59529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf6sPsx0SVFjrd623pMgAAACM"]
[Thu Sep 17 15:47:22.318240 2026] [security2:error] [pid 60716:tid 61007] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623o6AAAAHE"]
[Thu Sep 17 15:47:22.345779 2026] [security2:error] [pid 60716:tid 61001] [client 34.95.14.119:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxf6sPsx0SVFjrd623pMwAAAGs"]
[Thu Sep 17 15:47:22.358109 2026] [security2:error] [pid 60716:tid 60973] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623o6gAAAE8"]
[Thu Sep 17 15:47:22.399774 2026] [security2:error] [pid 60716:tid 60911] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623o6QAAABM"]
[Thu Sep 17 15:47:22.560243 2026] [security2:error] [pid 60716:tid 60760] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/aws_secret_config.php"] [unique_id "aqxf6sPsx0SVFjrd623pPgAAIQI"]
[Thu Sep 17 15:47:22.600901 2026] [security2:error] [pid 60716:tid 60935] [client 34.95.14.119:48136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxf6sPsx0SVFjrd623pQgAAACk"]
[Thu Sep 17 15:47:22.614162 2026] [security2:error] [pid 60716:tid 60957] [client 192.178.6.3:43369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxf6sPsx0SVFjrd623pQwAAAD8"]
[Thu Sep 17 15:47:22.869202 2026] [security2:error] [pid 60716:tid 61004] [client 34.95.14.119:48138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/test.php"] [unique_id "aqxf6sPsx0SVFjrd623pSgAAAG4"]
[Thu Sep 17 15:47:23.209358 2026] [security2:error] [pid 60716:tid 60945] [client 34.95.14.119:48150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/p.php"] [unique_id "aqxf68Psx0SVFjrd623pVAAAADM"]
[Thu Sep 17 15:47:23.260901 2026] [security2:error] [pid 60716:tid 60993] [client 122.8.45.84:57019] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf68Psx0SVFjrd623pWQAAAGM"]
[Thu Sep 17 15:47:23.261037 2026] [security2:error] [pid 60716:tid 60993] [client 122.8.45.84:57019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf68Psx0SVFjrd623pWQAAAGM"]
[Thu Sep 17 15:47:23.330744 2026] [security2:error] [pid 60716:tid 61008] [client 35.228.4.121:40764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxf68Psx0SVFjrd623pXwAAAHI"]
[Thu Sep 17 15:47:23.467904 2026] [security2:error] [pid 60716:tid 60956] [client 34.95.14.119:48156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxf68Psx0SVFjrd623pZAAAAD4"]
[Thu Sep 17 15:47:23.506186 2026] [security2:error] [pid 60716:tid 61014] [client 43.173.180.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxf68Psx0SVFjrd623pXQAAAHg"]
[Thu Sep 17 15:47:23.731013 2026] [security2:error] [pid 60716:tid 60917] [client 34.95.14.119:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxf68Psx0SVFjrd623pbAAAABk"]
[Thu Sep 17 15:47:23.835605 2026] [security2:error] [pid 60716:tid 60942] [client 169.58.197.251:52363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/json-schema.php"] [unique_id "aqxf68Psx0SVFjrd623pbQAAADA"], referer: binance.com
[Thu Sep 17 15:47:23.971741 2026] [security2:error] [pid 60716:tid 61012] [client 34.95.14.119:48182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxf68Psx0SVFjrd623pcQAAAHY"]
[Thu Sep 17 15:47:24.037666 2026] [security2:error] [pid 60716:tid 60914] [client 4.240.114.86:52589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "aqxf7MPsx0SVFjrd623pcwAAABY"], referer: binance.com
[Thu Sep 17 15:47:24.220397 2026] [security2:error] [pid 60716:tid 61016] [client 34.95.14.119:48188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxf7MPsx0SVFjrd623pegAAAHo"]
[Thu Sep 17 15:47:24.220523 2026] [security2:error] [pid 60716:tid 60946] [client 122.8.45.84:41759] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7MPsx0SVFjrd623peQAAADQ"]
[Thu Sep 17 15:47:24.220614 2026] [security2:error] [pid 60716:tid 60946] [client 122.8.45.84:41759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7MPsx0SVFjrd623peQAAADQ"]
[Thu Sep 17 15:47:24.261375 2026] [security2:error] [pid 60716:tid 60941] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pDAAAAC8"]
[Thu Sep 17 15:47:24.279626 2026] [security2:error] [pid 60716:tid 60957] [client 35.228.4.121:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/www/phpinfo.php"] [unique_id "aqxf7MPsx0SVFjrd623pfAAAAD8"]
[Thu Sep 17 15:47:24.291321 2026] [security2:error] [pid 60716:tid 60954] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pCwAAADw"]
[Thu Sep 17 15:47:24.310834 2026] [security2:error] [pid 60716:tid 60983] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pDQAAAFk"]
[Thu Sep 17 15:47:24.317650 2026] [security2:error] [pid 60716:tid 60916] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pDgAAABg"]
[Thu Sep 17 15:47:24.317975 2026] [security2:error] [pid 60716:tid 61017] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pDwAAAHs"]
[Thu Sep 17 15:47:24.324552 2026] [security2:error] [pid 60716:tid 60920] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pEQAAABw"]
[Thu Sep 17 15:47:24.334502 2026] [security2:error] [pid 60716:tid 60943] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pCgAAADE"]
[Thu Sep 17 15:47:24.346040 2026] [security2:error] [pid 60716:tid 60994] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6sPsx0SVFjrd623pJgAAAGQ"]
[Thu Sep 17 15:47:24.370226 2026] [security2:error] [pid 60716:tid 60922] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pEgAAAB0"]
[Thu Sep 17 15:47:24.383134 2026] [security2:error] [pid 60716:tid 61010] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pHwAAAHQ"]
[Thu Sep 17 15:47:24.384208 2026] [security2:error] [pid 60716:tid 60929] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6sPsx0SVFjrd623pLgAAACQ"]
[Thu Sep 17 15:47:24.406258 2026] [security2:error] [pid 60716:tid 60903] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6cPsx0SVFjrd623pEAAAAAs"]
[Thu Sep 17 15:47:24.472105 2026] [security2:error] [pid 60716:tid 60812] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/textpattern/config.php"] [unique_id "aqxf7MPsx0SVFjrd623pfwAAITI"]
[Thu Sep 17 15:47:24.473641 2026] [security2:error] [pid 60716:tid 60971] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf68Psx0SVFjrd623pVQAAAE0"]
[Thu Sep 17 15:47:24.482755 2026] [security2:error] [pid 60716:tid 60894] [client 34.95.14.119:48198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxf7MPsx0SVFjrd623phAAAAAI"]
[Thu Sep 17 15:47:24.484818 2026] [security2:error] [pid 60716:tid 60898] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6sPsx0SVFjrd623pRAAAAAY"]
[Thu Sep 17 15:47:24.496827 2026] [security2:error] [pid 60716:tid 60926] [client 45.138.12.24:50470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6sPsx0SVFjrd623pOQAAISo"]
[Thu Sep 17 15:47:24.510737 2026] [security2:error] [pid 60716:tid 60906] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf6sPsx0SVFjrd623pRgAAAA4"]
[Thu Sep 17 15:47:24.605378 2026] [security2:error] [pid 60716:tid 60928] [client 74.7.228.41:35304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.jenniferniesslein.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623pjwAAIzM"]
[Thu Sep 17 15:47:24.654747 2026] [security2:error] [pid 60716:tid 60872] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/market/.env"] [unique_id "aqxf7MPsx0SVFjrd623pmgAAIW4"]
[Thu Sep 17 15:47:24.724496 2026] [security2:error] [pid 60716:tid 60902] [client 34.95.14.119:48206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxf7MPsx0SVFjrd623pqAAAAAo"]
[Thu Sep 17 15:47:24.995712 2026] [security2:error] [pid 60716:tid 60954] [client 34.95.14.119:48216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxf7MPsx0SVFjrd623ptgAAADw"]
[Thu Sep 17 15:47:25.014937 2026] [security2:error] [pid 60716:tid 60784] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/www/.env"] [unique_id "aqxf7cPsx0SVFjrd623puAAAIRc"]
[Thu Sep 17 15:47:25.042614 2026] [security2:error] [pid 60716:tid 60799] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.12.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thezoeyline.com"] [uri "/.env.local.php"] [unique_id "aqxf7cPsx0SVFjrd623pugAAISU"]
[Thu Sep 17 15:47:25.043518 2026] [security2:error] [pid 60716:tid 60775] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/back-end/.env"] [unique_id "aqxf7cPsx0SVFjrd623pvAAAIQ8"]
[Thu Sep 17 15:47:25.043556 2026] [security2:error] [pid 60716:tid 60800] [remote 45.138.12.24:50470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thezoeyline.com"] [uri "/ci/.env"] [unique_id "aqxf7cPsx0SVFjrd623puwAAISY"]
[Thu Sep 17 15:47:25.046358 2026] [security2:error] [pid 60716:tid 60910] [client 35.228.4.121:40782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxf7cPsx0SVFjrd623pvgAAABI"]
[Thu Sep 17 15:47:25.223651 2026] [security2:error] [pid 60716:tid 60940] [client 122.8.45.84:20165] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7cPsx0SVFjrd623pxwAAAC4"]
[Thu Sep 17 15:47:25.223757 2026] [security2:error] [pid 60716:tid 60940] [client 122.8.45.84:20165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7cPsx0SVFjrd623pxwAAAC4"]
[Thu Sep 17 15:47:25.324293 2026] [security2:error] [pid 60716:tid 60913] [client 34.95.14.119:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxf7cPsx0SVFjrd623pyQAAABU"]
[Thu Sep 17 15:47:25.531203 2026] [security2:error] [pid 60716:tid 60929] [client 34.95.14.119:48234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxf7cPsx0SVFjrd623p0gAAACQ"]
[Thu Sep 17 15:47:25.773848 2026] [security2:error] [pid 60716:tid 60986] [client 169.58.197.253:54606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxf7cPsx0SVFjrd623p3AAAAFw"], referer: binance.com
[Thu Sep 17 15:47:25.775769 2026] [security2:error] [pid 60716:tid 60937] [client 34.95.14.119:48242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxf7cPsx0SVFjrd623p3QAAACs"]
[Thu Sep 17 15:47:25.869588 2026] [security2:error] [pid 60716:tid 60900] [client 146.190.118.194:52800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "totallyclassicrestoration.com.au"] [uri "/wp-json/batch/v1"] [unique_id "aqxf7cPsx0SVFjrd623p3wAAAAg"]
[Thu Sep 17 15:47:25.926296 2026] [security2:error] [pid 60716:tid 60988] [client 146.190.118.194:52801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "totallyclassicrestoration.com.au"] [uri "/"] [unique_id "aqxf7cPsx0SVFjrd623p4AAAAF4"]
[Thu Sep 17 15:47:25.947652 2026] [security2:error] [pid 60716:tid 60970] [client 35.228.4.121:40788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxf7cPsx0SVFjrd623p4gAAAEw"]
[Thu Sep 17 15:47:25.988208 2026] [security2:error] [pid 60716:tid 60990] [client 34.95.14.119:48250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxf7cPsx0SVFjrd623p5AAAAGA"]
[Thu Sep 17 15:47:26.002734 2026] [security2:error] [pid 60716:tid 60969] [client 146.190.118.194:52805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "totallyclassicrestoration.com.au"] [uri "/wp-json/batch/v1"] [unique_id "aqxf7sPsx0SVFjrd623p5gAAAEs"]
[Thu Sep 17 15:47:26.197273 2026] [security2:error] [pid 60716:tid 61016] [client 34.95.14.119:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxf7sPsx0SVFjrd623p7gAAAHo"]
[Thu Sep 17 15:47:26.219294 2026] [security2:error] [pid 60716:tid 61014] [client 122.8.45.84:45261] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623p7wAAAHg"]
[Thu Sep 17 15:47:26.219445 2026] [security2:error] [pid 60716:tid 61014] [client 122.8.45.84:45261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623p7wAAAHg"]
[Thu Sep 17 15:47:26.241131 2026] [security2:error] [pid 60716:tid 61001] [client 14.96.156.146:51395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623p8AAAAGs"]
[Thu Sep 17 15:47:26.241220 2026] [security2:error] [pid 60716:tid 61001] [client 14.96.156.146:51395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623p8AAAAGs"]
[Thu Sep 17 15:47:26.376715 2026] [security2:error] [pid 60716:tid 60977] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623phQAAAFM"]
[Thu Sep 17 15:47:26.419358 2026] [security2:error] [pid 60716:tid 60901] [client 34.95.14.119:48266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxf7sPsx0SVFjrd623p8gAAAAk"]
[Thu Sep 17 15:47:26.420453 2026] [security2:error] [pid 60716:tid 60948] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623pjAAAADY"]
[Thu Sep 17 15:47:26.421055 2026] [security2:error] [pid 60716:tid 60958] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623ppAAAAEA"]
[Thu Sep 17 15:47:26.426972 2026] [security2:error] [pid 60716:tid 60962] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623piwAAAEQ"]
[Thu Sep 17 15:47:26.431757 2026] [security2:error] [pid 60716:tid 60972] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623ppgAAAE4"]
[Thu Sep 17 15:47:26.439152 2026] [security2:error] [pid 60716:tid 61009] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623ppwAAAHM"]
[Thu Sep 17 15:47:26.443767 2026] [security2:error] [pid 60716:tid 60936] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623psQAAACo"]
[Thu Sep 17 15:47:26.444023 2026] [security2:error] [pid 60716:tid 60899] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623ppQAAAAc"]
[Thu Sep 17 15:47:26.451722 2026] [security2:error] [pid 60716:tid 60892] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7MPsx0SVFjrd623prQAAAAA"]
[Thu Sep 17 15:47:26.461339 2026] [security2:error] [pid 60716:tid 61017] [client 45.138.12.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7cPsx0SVFjrd623pwAAAAHs"]
[Thu Sep 17 15:47:26.463709 2026] [security2:error] [pid 60716:tid 60848] [remote 45.138.12.24:50470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thezoeyline.com"] [uri "/index.php"] [unique_id "aqxf7cPsx0SVFjrd623puQAAIVY"]
[Thu Sep 17 15:47:26.596190 2026] [security2:error] [pid 60716:tid 60951] [client 148.227.75.216:15774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623p-AAAADk"]
[Thu Sep 17 15:47:26.596294 2026] [security2:error] [pid 60716:tid 60951] [client 148.227.75.216:15774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623p-AAAADk"]
[Thu Sep 17 15:47:26.621701 2026] [security2:error] [pid 60716:tid 60946] [client 35.228.4.121:40800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/site/phpinfo.php"] [unique_id "aqxf7sPsx0SVFjrd623p-gAAADQ"]
[Thu Sep 17 15:47:26.818277 2026] [security2:error] [pid 60716:tid 60983] [client 143.105.152.240:44846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623qAgAAAFk"]
[Thu Sep 17 15:47:26.828420 2026] [security2:error] [pid 60716:tid 60983] [client 143.105.152.240:44846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf7sPsx0SVFjrd623qAgAAAFk"]
[Thu Sep 17 15:47:26.829049 2026] [security2:error] [pid 60716:tid 60986] [client 34.95.14.119:48282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxf7sPsx0SVFjrd623qAwAAAFw"]
[Thu Sep 17 15:47:27.106159 2026] [security2:error] [pid 60716:tid 61012] [client 34.95.14.119:48296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxf78Psx0SVFjrd623qDQAAAHY"]
[Thu Sep 17 15:47:27.182962 2026] [security2:error] [pid 60716:tid 61003] [client 122.8.45.84:65267] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf78Psx0SVFjrd623qEgAAAG0"]
[Thu Sep 17 15:47:27.183057 2026] [security2:error] [pid 60716:tid 61003] [client 122.8.45.84:65267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf78Psx0SVFjrd623qEgAAAG0"]
[Thu Sep 17 15:47:27.267118 2026] [security2:error] [pid 60716:tid 60894] [client 169.58.198.243:51202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aqxf78Psx0SVFjrd623qFAAAAAI"], referer: www.google.com
[Thu Sep 17 15:47:27.318810 2026] [security2:error] [pid 60716:tid 60959] [client 34.95.14.119:48306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxf78Psx0SVFjrd623qFQAAAEE"]
[Thu Sep 17 15:47:27.348493 2026] [security2:error] [pid 60716:tid 60961] [client 35.228.4.121:40802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxf78Psx0SVFjrd623qFgAAAEM"]
[Thu Sep 17 15:47:27.482200 2026] [security2:error] [pid 60716:tid 60992] [client 177.44.133.72:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf78Psx0SVFjrd623qGAAAAGI"]
[Thu Sep 17 15:47:27.482344 2026] [security2:error] [pid 60716:tid 60992] [client 177.44.133.72:62386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf78Psx0SVFjrd623qGAAAAGI"]
[Thu Sep 17 15:47:27.570741 2026] [security2:error] [pid 60716:tid 60970] [client 179.24.136.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "npae.net"] [uri "/index.php"] [unique_id "aqxf78Psx0SVFjrd623qCQAAAEw"], referer: https://npae.net/
[Thu Sep 17 15:47:27.589205 2026] [security2:error] [pid 60716:tid 60916] [client 34.95.14.119:48312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxf78Psx0SVFjrd623qHgAAABg"]
[Thu Sep 17 15:47:27.865288 2026] [security2:error] [pid 60716:tid 60905] [client 34.95.14.119:50562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxf78Psx0SVFjrd623qJwAAAA0"]
[Thu Sep 17 15:47:28.145053 2026] [security2:error] [pid 60716:tid 60910] [client 34.95.14.119:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxf8MPsx0SVFjrd623qLwAAABI"]
[Thu Sep 17 15:47:28.147449 2026] [security2:error] [pid 60716:tid 60935] [client 122.8.45.84:52925] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8MPsx0SVFjrd623qMAAAACk"]
[Thu Sep 17 15:47:28.147584 2026] [security2:error] [pid 60716:tid 60935] [client 122.8.45.84:52925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8MPsx0SVFjrd623qMAAAACk"]
[Thu Sep 17 15:47:28.305391 2026] [security2:error] [pid 60716:tid 60926] [client 35.228.4.121:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxf8MPsx0SVFjrd623qOQAAACE"]
[Thu Sep 17 15:47:28.414311 2026] [security2:error] [pid 60716:tid 61018] [client 34.95.14.119:50570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxf8MPsx0SVFjrd623qOwAAAHw"]
[Thu Sep 17 15:47:28.756897 2026] [security2:error] [pid 60716:tid 61012] [client 34.95.14.119:50574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxf8MPsx0SVFjrd623qSgAAAHY"]
[Thu Sep 17 15:47:29.029198 2026] [security2:error] [pid 60716:tid 60894] [client 35.228.4.121:40826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxf8cPsx0SVFjrd623qTgAAAAI"]
[Thu Sep 17 15:47:29.064575 2026] [security2:error] [pid 60716:tid 60901] [client 34.95.14.119:50582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxf8cPsx0SVFjrd623qTwAAAAk"]
[Thu Sep 17 15:47:29.146758 2026] [security2:error] [pid 60716:tid 60902] [client 122.8.45.84:27855] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8cPsx0SVFjrd623qVQAAAAo"]
[Thu Sep 17 15:47:29.146857 2026] [security2:error] [pid 60716:tid 60902] [client 122.8.45.84:27855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8cPsx0SVFjrd623qVQAAAAo"]
[Thu Sep 17 15:47:29.175977 2026] [security2:error] [pid 60716:tid 61009] [client 4.240.114.86:54902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-icon-collections-registry.php"] [unique_id "aqxf8cPsx0SVFjrd623qWAAAAHM"], referer: binance.com
[Thu Sep 17 15:47:29.330366 2026] [security2:error] [pid 60716:tid 60970] [client 79.116.89.151:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8cPsx0SVFjrd623qXwAAAEw"]
[Thu Sep 17 15:47:29.330473 2026] [security2:error] [pid 60716:tid 60970] [client 79.116.89.151:64220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8cPsx0SVFjrd623qXwAAAEw"]
[Thu Sep 17 15:47:29.402426 2026] [security2:error] [pid 60716:tid 60899] [client 34.95.14.119:50598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxf8cPsx0SVFjrd623qYAAAAAc"]
[Thu Sep 17 15:47:29.710506 2026] [security2:error] [pid 60716:tid 60981] [client 34.95.14.119:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxf8cPsx0SVFjrd623qaAAAAFc"]
[Thu Sep 17 15:47:29.931100 2026] [security2:error] [pid 60716:tid 61003] [client 178.95.181.65:35915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxf8cPsx0SVFjrd623qagAAbTU"]
[Thu Sep 17 15:47:30.006380 2026] [security2:error] [pid 60716:tid 61008] [client 34.95.14.119:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxf8sPsx0SVFjrd623qcQAAAHI"]
[Thu Sep 17 15:47:30.160895 2026] [security2:error] [pid 60716:tid 60965] [client 35.228.4.121:40842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/core/phpinfo.php"] [unique_id "aqxf8sPsx0SVFjrd623qfwAAAEc"]
[Thu Sep 17 15:47:30.305304 2026] [security2:error] [pid 60716:tid 60924] [client 34.95.14.119:50628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxf8sPsx0SVFjrd623qggAAAB8"]
[Thu Sep 17 15:47:30.446768 2026] [security2:error] [pid 60716:tid 61007] [client 122.8.45.84:32737] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8sPsx0SVFjrd623qhwAAAHE"]
[Thu Sep 17 15:47:30.446894 2026] [security2:error] [pid 60716:tid 61007] [client 122.8.45.84:32737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8sPsx0SVFjrd623qhwAAAHE"]
[Thu Sep 17 15:47:30.568056 2026] [security2:error] [pid 60716:tid 60908] [client 34.95.14.119:50642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxf8sPsx0SVFjrd623qiwAAABA"]
[Thu Sep 17 15:47:30.801747 2026] [security2:error] [pid 60716:tid 60955] [client 172.226.36.95:40087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "perimetry.com"] [uri "/~perimev0/index.php"] [unique_id "aqxf8sPsx0SVFjrd623qlgAAPVw"]
[Thu Sep 17 15:47:30.838621 2026] [security2:error] [pid 60716:tid 60977] [client 34.95.14.119:50644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxf8sPsx0SVFjrd623qmAAAAFM"]
[Thu Sep 17 15:47:30.909101 2026] [security2:error] [pid 60716:tid 60941] [client 136.158.61.34:2970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8sPsx0SVFjrd623qmQAAAC8"]
[Thu Sep 17 15:47:30.909259 2026] [security2:error] [pid 60716:tid 60941] [client 136.158.61.34:2970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxf8sPsx0SVFjrd623qmQAAAC8"]
[Thu Sep 17 15:47:31.047754 2026] [security2:error] [pid 60716:tid 60948] [client 35.228.4.121:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.4.228.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mesuradocooperative.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxf88Psx0SVFjrd623qmwAAADY"]
[Thu Sep 17 15:47:31.111690 2026] [security2:error] [pid 60716:tid 60970] [client 34.95.14.119:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxf88Psx0SVFjrd623qngAAAEw"]
[Thu Sep 17 15:47:31.421618 2026] [security2:error] [pid 60716:tid 60947] [client 122.8.45.84:14475] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf88Psx0SVFjrd623qpgAAADU"]
[Thu Sep 17 15:47:31.421736 2026] [security2:error] [pid 60716:tid 60947] [client 122.8.45.84:14475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf88Psx0SVFjrd623qpgAAADU"]
[Thu Sep 17 15:47:31.444736 2026] [security2:error] [pid 60716:tid 60907] [client 34.95.14.119:50668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxf88Psx0SVFjrd623qqAAAAA8"]
[Thu Sep 17 15:47:31.569043 2026] [security2:error] [pid 60716:tid 61017] [client 54.222.230.55:14182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "acc.edu.ai"] [uri "/index.php"] [unique_id "aqxf88Psx0SVFjrd623qpQAAe1c"], referer: https://acc.edu.ai/wp-content/et-cache/1505/et-core-unified-deferred-1505.min.css?ver=1789402515
[Thu Sep 17 15:47:31.792192 2026] [security2:error] [pid 60716:tid 60946] [client 34.95.14.119:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxf88Psx0SVFjrd623qsgAAADQ"]
[Thu Sep 17 15:47:32.094667 2026] [security2:error] [pid 60716:tid 60952] [client 34.95.14.119:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxf9MPsx0SVFjrd623qtgAAADo"]
[Thu Sep 17 15:47:32.377738 2026] [security2:error] [pid 60716:tid 60965] [client 122.8.45.84:59175] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf9MPsx0SVFjrd623qwAAAAEc"]
[Thu Sep 17 15:47:32.377855 2026] [security2:error] [pid 60716:tid 60965] [client 122.8.45.84:59175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf9MPsx0SVFjrd623qwAAAAEc"]
[Thu Sep 17 15:47:32.379933 2026] [security2:error] [pid 60716:tid 60917] [client 34.95.14.119:50688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxf9MPsx0SVFjrd623qwQAAABk"]
[Thu Sep 17 15:47:32.779307 2026] [security2:error] [pid 60716:tid 60897] [client 34.95.14.119:50704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxf9MPsx0SVFjrd623q0AAAAAU"]
[Thu Sep 17 15:47:33.040172 2026] [security2:error] [pid 60716:tid 61019] [client 34.95.14.119:50710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxf9cPsx0SVFjrd623q1AAAAH0"]
[Thu Sep 17 15:47:33.079381 2026] [cgid:error] [pid 60716:tid 60914] [client 221.149.119.65:5047] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/old
[Thu Sep 17 15:47:33.323439 2026] [security2:error] [pid 60716:tid 60955] [client 122.8.45.84:46009] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf9cPsx0SVFjrd623q3gAAAD0"]
[Thu Sep 17 15:47:33.323571 2026] [security2:error] [pid 60716:tid 60955] [client 122.8.45.84:46009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf9cPsx0SVFjrd623q3gAAAD0"]
[Thu Sep 17 15:47:33.346046 2026] [security2:error] [pid 60716:tid 60908] [client 169.58.198.243:52003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/plugins/ph-file-manager/wp-file.php"] [unique_id "aqxf9cPsx0SVFjrd623q3wAAABA"], referer: www.google.com
[Thu Sep 17 15:47:33.351287 2026] [security2:error] [pid 60716:tid 60944] [client 34.95.14.119:50714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxf9cPsx0SVFjrd623q4AAAADI"]
[Thu Sep 17 15:47:33.658360 2026] [security2:error] [pid 60716:tid 60953] [client 34.95.14.119:50718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxf9cPsx0SVFjrd623q8gAAADs"]
[Thu Sep 17 15:47:33.710967 2026] [security2:error] [pid 60716:tid 60907] [client 223.181.31.217:12354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxf9cPsx0SVFjrd623q6gAAD3I"]
[Thu Sep 17 15:47:33.960120 2026] [security2:error] [pid 60716:tid 60952] [client 34.95.14.119:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.14.95.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.zif.lok.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxf9cPsx0SVFjrd623q-gAAADo"]
[Thu Sep 17 15:47:34.047123 2026] [security2:error] [pid 60716:tid 60996] [client 169.58.197.251:53205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxf9sPsx0SVFjrd623q-wAAAGY"], referer: binance.com
[Thu Sep 17 15:47:34.303619 2026] [security2:error] [pid 60716:tid 60964] [client 122.8.45.84:59087] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf9sPsx0SVFjrd623rBwAAAEY"]
[Thu Sep 17 15:47:34.303781 2026] [security2:error] [pid 60716:tid 60964] [client 122.8.45.84:59087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf9sPsx0SVFjrd623rBwAAAEY"]
[Thu Sep 17 15:47:34.428139 2026] [security2:error] [pid 60716:tid 60950] [client 4.240.114.86:57275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "aqxf9sPsx0SVFjrd623rCgAAADg"], referer: binance.com
[Thu Sep 17 15:47:34.487729 2026] [security2:error] [pid 60716:tid 61019] [client 169.58.197.253:55105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxf9sPsx0SVFjrd623rEAAAAH0"], referer: binance.com
[Thu Sep 17 15:47:35.273506 2026] [security2:error] [pid 60716:tid 60970] [client 122.8.45.84:41511] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf98Psx0SVFjrd623rLgAAAEw"]
[Thu Sep 17 15:47:35.273619 2026] [security2:error] [pid 60716:tid 60970] [client 122.8.45.84:41511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf98Psx0SVFjrd623rLgAAAEw"]
[Thu Sep 17 15:47:36.188549 2026] [security2:error] [pid 60716:tid 61019] [client 45.232.74.177:11255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxf-MPsx0SVFjrd623rRQAAfT8"]
[Thu Sep 17 15:47:36.269735 2026] [security2:error] [pid 60716:tid 61014] [client 122.8.45.84:45359] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-MPsx0SVFjrd623rTQAAAHg"]
[Thu Sep 17 15:47:36.269831 2026] [security2:error] [pid 60716:tid 61014] [client 122.8.45.84:45359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-MPsx0SVFjrd623rTQAAAHg"]
[Thu Sep 17 15:47:36.858603 2026] [security2:error] [pid 60716:tid 60977] [client 165.227.207.42:44078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cfbpp.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxf-MPsx0SVFjrd623rWQAAAFM"]
[Thu Sep 17 15:47:36.998621 2026] [security2:error] [pid 60716:tid 60976] [client 14.96.156.146:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf-MPsx0SVFjrd623rWwAAAFI"]
[Thu Sep 17 15:47:36.998739 2026] [security2:error] [pid 60716:tid 60976] [client 14.96.156.146:52054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxf-MPsx0SVFjrd623rWwAAAFI"]
[Thu Sep 17 15:47:37.068906 2026] [security2:error] [pid 60716:tid 61013] [client 165.227.207.42:44092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cfbpp.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxf-cPsx0SVFjrd623rXAAAAHc"]
[Thu Sep 17 15:47:37.244382 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:39955] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-cPsx0SVFjrd623rYwAAAFc"]
[Thu Sep 17 15:47:37.244477 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:39955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-cPsx0SVFjrd623rYwAAAFc"]
[Thu Sep 17 15:47:37.279805 2026] [security2:error] [pid 60716:tid 60970] [client 165.227.207.42:44108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "cfbpp.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxf-cPsx0SVFjrd623rZgAAAEw"]
[Thu Sep 17 15:47:37.283596 2026] [security2:error] [pid 60716:tid 60907] [client 148.227.75.216:45213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-cPsx0SVFjrd623rZQAAAA8"]
[Thu Sep 17 15:47:37.283719 2026] [security2:error] [pid 60716:tid 60907] [client 148.227.75.216:45213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-cPsx0SVFjrd623rZQAAAA8"]
[Thu Sep 17 15:47:37.333294 2026] [security2:error] [pid 60716:tid 61021] [client 129.212.220.28:47206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxf-cPsx0SVFjrd623rZAAAAH8"]
[Thu Sep 17 15:47:37.358183 2026] [security2:error] [pid 60716:tid 60953] [client 143.105.152.240:55037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf-cPsx0SVFjrd623raQAAADs"]
[Thu Sep 17 15:47:37.358314 2026] [security2:error] [pid 60716:tid 60953] [client 143.105.152.240:55037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxf-cPsx0SVFjrd623raQAAADs"]
[Thu Sep 17 15:47:37.486353 2026] [security2:error] [pid 60716:tid 61011] [client 165.227.207.42:44112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cfbpp.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxf-cPsx0SVFjrd623rbQAAAHU"]
[Thu Sep 17 15:47:37.692477 2026] [security2:error] [pid 60716:tid 60969] [client 165.227.207.42:44114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cfbpp.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxf-cPsx0SVFjrd623rcgAAAEs"]
[Thu Sep 17 15:47:37.796001 2026] [security2:error] [pid 60716:tid 61003] [client 169.58.198.243:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/plugins/root-file-manager/wp-file.php"] [unique_id "aqxf-cPsx0SVFjrd623rdwAAAG0"], referer: www.google.com
[Thu Sep 17 15:47:37.899262 2026] [security2:error] [pid 60716:tid 61018] [client 165.227.207.42:44116] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "cfbpp.org"] [uri "/wp-json/batch/v1"] [unique_id "aqxf-cPsx0SVFjrd623reQAAAHw"]
[Thu Sep 17 15:47:38.054930 2026] [security2:error] [pid 60716:tid 60972] [client 4.240.114.86:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "aqxf-sPsx0SVFjrd623rfwAAAE4"], referer: binance.com
[Thu Sep 17 15:47:38.057591 2026] [security2:error] [pid 60716:tid 61012] [client 177.44.133.72:63051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf-sPsx0SVFjrd623rgAAAAHY"]
[Thu Sep 17 15:47:38.057716 2026] [security2:error] [pid 60716:tid 61012] [client 177.44.133.72:63051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxf-sPsx0SVFjrd623rgAAAAHY"]
[Thu Sep 17 15:47:38.224632 2026] [security2:error] [pid 60716:tid 60906] [client 122.8.45.84:33093] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-sPsx0SVFjrd623rhwAAAA4"]
[Thu Sep 17 15:47:38.224732 2026] [security2:error] [pid 60716:tid 60906] [client 122.8.45.84:33093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-sPsx0SVFjrd623rhwAAAA4"]
[Thu Sep 17 15:47:39.218672 2026] [security2:error] [pid 60716:tid 60976] [client 122.8.45.84:10401] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-8Psx0SVFjrd623rtgAAAFI"]
[Thu Sep 17 15:47:39.218806 2026] [security2:error] [pid 60716:tid 60976] [client 122.8.45.84:10401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-8Psx0SVFjrd623rtgAAAFI"]
[Thu Sep 17 15:47:39.923270 2026] [security2:error] [pid 60716:tid 60919] [client 142.93.220.18:55734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf-8Psx0SVFjrd623rwgAAGxQ"], referer: http://www.envisionfilmvideo.com/wp/
[Thu Sep 17 15:47:39.958610 2026] [security2:error] [pid 60716:tid 61017] [client 79.116.89.151:64846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-8Psx0SVFjrd623rwwAAAHs"]
[Thu Sep 17 15:47:39.958773 2026] [security2:error] [pid 60716:tid 61017] [client 79.116.89.151:64846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxf-8Psx0SVFjrd623rwwAAAHs"]
[Thu Sep 17 15:47:40.295370 2026] [security2:error] [pid 60716:tid 60917] [client 122.8.45.84:47007] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_MPsx0SVFjrd623rywAAABk"]
[Thu Sep 17 15:47:40.295469 2026] [security2:error] [pid 60716:tid 60917] [client 122.8.45.84:47007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_MPsx0SVFjrd623rywAAABk"]
[Thu Sep 17 15:47:40.606840 2026] [security2:error] [pid 60716:tid 60945] [client 172.235.55.41:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.235.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perimetry.com"] [uri "/index.php"] [unique_id "aqxf_MPsx0SVFjrd623r0AAAADM"]
[Thu Sep 17 15:47:40.609642 2026] [security2:error] [pid 60716:tid 60949] [client 172.235.55.41:58544] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.perimetry.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxf_MPsx0SVFjrd623r0QAAADc"]
[Thu Sep 17 15:47:40.619414 2026] [security2:error] [pid 60716:tid 60914] [client 172.235.55.41:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.235.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perimetry.com"] [uri "/index.php/wp-json/batch/v1"] [unique_id "aqxf_MPsx0SVFjrd623r0wAAABY"]
[Thu Sep 17 15:47:40.621640 2026] [security2:error] [pid 60716:tid 60901] [client 172.235.55.41:58546] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.perimetry.com"] [uri "/"] [unique_id "aqxf_MPsx0SVFjrd623r1AAAAAk"]
[Thu Sep 17 15:47:40.666055 2026] [security2:error] [pid 60716:tid 61009] [client 172.235.55.41:58572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.235.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perimetry.com"] [uri "/index.php/wp-json/batch/v1"] [unique_id "aqxf_MPsx0SVFjrd623r2gAAAHM"]
[Thu Sep 17 15:47:40.667508 2026] [security2:error] [pid 60716:tid 60936] [client 172.235.55.41:58562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.perimetry.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxf_MPsx0SVFjrd623r2wAAACo"]
[Thu Sep 17 15:47:40.674894 2026] [security2:error] [pid 60716:tid 61014] [client 172.235.55.41:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.235.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perimetry.com"] [uri "/index.php"] [unique_id "aqxf_MPsx0SVFjrd623r3QAAAHg"]
[Thu Sep 17 15:47:40.677233 2026] [security2:error] [pid 60716:tid 60941] [client 172.235.55.41:58568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.perimetry.com"] [uri "/"] [unique_id "aqxf_MPsx0SVFjrd623r3AAAAC8"]
[Thu Sep 17 15:47:40.695538 2026] [security2:error] [pid 60716:tid 60933] [client 142.93.220.18:55744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf_MPsx0SVFjrd623r2QAAJ3Y"], referer: https://www.envisionfilmvideo.com/wp/
[Thu Sep 17 15:47:41.274487 2026] [security2:error] [pid 60716:tid 60897] [client 122.8.45.84:41833] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_cPsx0SVFjrd623r6wAAAAU"]
[Thu Sep 17 15:47:41.274633 2026] [security2:error] [pid 60716:tid 60897] [client 122.8.45.84:41833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_cPsx0SVFjrd623r6wAAAAU"]
[Thu Sep 17 15:47:41.516937 2026] [security2:error] [pid 60716:tid 60905] [client 4.240.114.86:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "aqxf_cPsx0SVFjrd623r8QAAAA0"], referer: binance.com
[Thu Sep 17 15:47:41.740972 2026] [security2:error] [pid 60716:tid 60969] [client 169.58.198.243:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/plugins/wp-help/mini.php"] [unique_id "aqxf_cPsx0SVFjrd623r-AAAAEs"], referer: www.google.com
[Thu Sep 17 15:47:41.988942 2026] [security2:error] [pid 60716:tid 60964] [client 142.93.220.18:55734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf_cPsx0SVFjrd623r-gAARjQ"], referer: http://www.envisionfilmvideo.com/backup/
[Thu Sep 17 15:47:42.256703 2026] [security2:error] [pid 60716:tid 61003] [client 122.8.45.84:11435] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_sPsx0SVFjrd623sBAAAAG0"]
[Thu Sep 17 15:47:42.256818 2026] [security2:error] [pid 60716:tid 61003] [client 122.8.45.84:11435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_sPsx0SVFjrd623sBAAAAG0"]
[Thu Sep 17 15:47:42.265728 2026] [security2:error] [pid 60716:tid 61007] [client 142.93.220.18:55744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf_sPsx0SVFjrd623sAwAAcWk"], referer: https://www.envisionfilmvideo.com/backup/
[Thu Sep 17 15:47:42.305338 2026] [security2:error] [pid 60716:tid 60906] [client 159.65.124.120:62313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfwservicesllc.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxf_sPsx0SVFjrd623sBwAAAA4"]
[Thu Sep 17 15:47:42.332741 2026] [security2:error] [pid 60716:tid 60915] [client 34.32.107.79:47036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.yourstrulymaria.com"] [uri "/"] [unique_id "aqxf_sPsx0SVFjrd623sCAAAABc"]
[Thu Sep 17 15:47:42.630238 2026] [security2:error] [pid 60716:tid 60920] [client 159.65.124.120:62320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfwservicesllc.com"] [uri "/"] [unique_id "aqxf_sPsx0SVFjrd623sDQAAABw"]
[Thu Sep 17 15:47:42.762443 2026] [security2:error] [pid 60716:tid 60956] [client 142.93.220.18:55734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf_sPsx0SVFjrd623sFQAAPmE"], referer: http://www.envisionfilmvideo.com/new/
[Thu Sep 17 15:47:42.780560 2026] [security2:error] [pid 60716:tid 60978] [client 34.32.107.79:54910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.yourstrulymaria.com"] [uri "/"] [unique_id "aqxf_sPsx0SVFjrd623sFwAAAFQ"]
[Thu Sep 17 15:47:42.942784 2026] [security2:error] [pid 60716:tid 60926] [client 159.65.124.120:62324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dfwservicesllc.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxf_sPsx0SVFjrd623sGwAAACE"]
[Thu Sep 17 15:47:43.053259 2026] [security2:error] [pid 60716:tid 61013] [client 142.93.220.18:55744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf_8Psx0SVFjrd623sHgAAdwo"], referer: https://www.envisionfilmvideo.com/new/
[Thu Sep 17 15:47:43.227083 2026] [security2:error] [pid 60716:tid 60973] [client 34.32.107.79:54916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.yourstrulymaria.com"] [uri "/"] [unique_id "aqxf_8Psx0SVFjrd623sJQAAAE8"]
[Thu Sep 17 15:47:43.260375 2026] [security2:error] [pid 60716:tid 60987] [client 122.8.45.84:21991] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_8Psx0SVFjrd623sJgAAAF0"]
[Thu Sep 17 15:47:43.260517 2026] [security2:error] [pid 60716:tid 60987] [client 122.8.45.84:21991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxf_8Psx0SVFjrd623sJgAAAF0"]
[Thu Sep 17 15:47:43.555589 2026] [security2:error] [pid 60716:tid 60970] [client 142.93.220.18:55734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxf_8Psx0SVFjrd623sMgAATFw"], referer: http://www.envisionfilmvideo.com/blog/
[Thu Sep 17 15:47:43.876473 2026] [security2:error] [pid 60716:tid 60988] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxf_8Psx0SVFjrd623sPAAAAF4"]
[Thu Sep 17 15:47:44.045585 2026] [security2:error] [pid 60716:tid 61010] [client 172.86.81.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jvrockworks.com"] [uri "/index.php"] [unique_id "aqxf-sPsx0SVFjrd623rpgAAAHQ"], referer: http://jvrockworks.com/.git/config
[Thu Sep 17 15:47:44.109436 2026] [security2:error] [pid 60716:tid 60961] [client 136.158.61.34:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAMPsx0SVFjrd623sRQAAAEM"]
[Thu Sep 17 15:47:44.109549 2026] [security2:error] [pid 60716:tid 60961] [client 136.158.61.34:4238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAMPsx0SVFjrd623sRQAAAEM"]
[Thu Sep 17 15:47:44.181233 2026] [security2:error] [pid 60716:tid 60900] [client 34.32.107.79:54928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.yourstrulymaria.com"] [uri "/"] [unique_id "aqxgAMPsx0SVFjrd623sSQAAAAg"]
[Thu Sep 17 15:47:44.248571 2026] [security2:error] [pid 60716:tid 60947] [client 122.8.45.84:43489] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAMPsx0SVFjrd623sTQAAADU"]
[Thu Sep 17 15:47:44.248669 2026] [security2:error] [pid 60716:tid 60947] [client 122.8.45.84:43489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAMPsx0SVFjrd623sTQAAADU"]
[Thu Sep 17 15:47:44.346566 2026] [security2:error] [pid 60716:tid 60938] [client 142.93.220.18:55734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxgAMPsx0SVFjrd623sTwAALCw"], referer: http://www.envisionfilmvideo.com/wordpress/
[Thu Sep 17 15:47:44.624842 2026] [security2:error] [pid 60716:tid 60916] [client 142.93.220.18:55744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxgAMPsx0SVFjrd623sUwAAGFo"], referer: https://www.envisionfilmvideo.com/wordpress/
[Thu Sep 17 15:47:44.640354 2026] [security2:error] [pid 60716:tid 60941] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/.env"] [unique_id "aqxgAMPsx0SVFjrd623sVgAAAC8"]
[Thu Sep 17 15:47:44.793446 2026] [security2:error] [pid 60716:tid 61013] [client 169.58.197.251:54040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxgAMPsx0SVFjrd623sXAAAAHc"], referer: binance.com
[Thu Sep 17 15:47:44.993268 2026] [security2:error] [pid 60716:tid 60977] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgAMPsx0SVFjrd623sXwAAAFM"]
[Thu Sep 17 15:47:45.121048 2026] [security2:error] [pid 60716:tid 60968] [client 142.93.220.18:55734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxgAcPsx0SVFjrd623sZAAASgU"], referer: http://www.envisionfilmvideo.com/old/
[Thu Sep 17 15:47:45.225206 2026] [security2:error] [pid 60716:tid 60902] [client 122.8.45.84:35213] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAcPsx0SVFjrd623sawAAAAo"]
[Thu Sep 17 15:47:45.225328 2026] [security2:error] [pid 60716:tid 60902] [client 122.8.45.84:35213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAcPsx0SVFjrd623sawAAAAo"]
[Thu Sep 17 15:47:45.399969 2026] [security2:error] [pid 60716:tid 61015] [client 142.93.220.18:55744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "envisionfilmvideo.com"] [uri "/index.php"] [unique_id "aqxgAcPsx0SVFjrd623scAAAeW0"], referer: https://www.envisionfilmvideo.com/old/
[Thu Sep 17 15:47:45.448527 2026] [security2:error] [pid 60716:tid 60991] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgAcPsx0SVFjrd623sbwAAAGE"]
[Thu Sep 17 15:47:45.796241 2026] [security2:error] [pid 60716:tid 60910] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgAcPsx0SVFjrd623sewAAABI"]
[Thu Sep 17 15:47:45.894863 2026] [security2:error] [pid 60716:tid 61016] [client 206.189.130.172:57776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.org"] [uri "/index.php"] [unique_id "aqxgAcPsx0SVFjrd623sgAAAenU"], referer: http://radtechresourcegroup.org/blog/
[Thu Sep 17 15:47:45.964677 2026] [security2:error] [pid 60716:tid 60900] [client 192.178.6.3:46768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxgAcPsx0SVFjrd623shgAAAAg"]
[Thu Sep 17 15:47:46.069116 2026] [security2:error] [pid 60716:tid 60990] [client 216.49.131.135:63479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgAcPsx0SVFjrd623shAAAYEM"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:47:46.108279 2026] [security2:error] [pid 60716:tid 60924] [client 4.240.114.86:62597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "aqxgAsPsx0SVFjrd623sjAAAAB8"], referer: binance.com
[Thu Sep 17 15:47:46.128815 2026] [security2:error] [pid 60716:tid 60986] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgAcPsx0SVFjrd623shwAAAFw"]
[Thu Sep 17 15:47:46.284686 2026] [security2:error] [pid 60716:tid 60950] [client 122.8.45.84:26709] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAsPsx0SVFjrd623slQAAADg"]
[Thu Sep 17 15:47:46.284781 2026] [security2:error] [pid 60716:tid 60950] [client 122.8.45.84:26709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgAsPsx0SVFjrd623slQAAADg"]
[Thu Sep 17 15:47:46.440840 2026] [security2:error] [pid 60716:tid 60955] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgAsPsx0SVFjrd623smQAAAD0"]
[Thu Sep 17 15:47:46.497185 2026] [security2:error] [pid 60716:tid 60931] [client 206.189.130.172:57776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.org"] [uri "/index.php"] [unique_id "aqxgAsPsx0SVFjrd623smgAAJV4"], referer: http://radtechresourcegroup.org/wordpress/
[Thu Sep 17 15:47:46.684991 2026] [security2:error] [pid 60716:tid 60923] [client 169.58.198.243:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/themes/travel/issue.php"] [unique_id "aqxgAsPsx0SVFjrd623soQAAAB4"], referer: www.google.com
[Thu Sep 17 15:47:46.830384 2026] [security2:error] [pid 60716:tid 60995] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgAsPsx0SVFjrd623sowAAAGU"]
[Thu Sep 17 15:47:46.978031 2026] [security2:error] [pid 60716:tid 60902] [client 169.58.197.253:55789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxgAsPsx0SVFjrd623srQAAAAo"], referer: binance.com
[Thu Sep 17 15:47:47.076915 2026] [security2:error] [pid 60716:tid 60903] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/.env.bak"] [unique_id "aqxgA8Psx0SVFjrd623srgAAAAs"]
[Thu Sep 17 15:47:47.120877 2026] [security2:error] [pid 60716:tid 60909] [client 206.189.130.172:57776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.org"] [uri "/index.php"] [unique_id "aqxgAsPsx0SVFjrd623srAAAEVE"], referer: http://radtechresourcegroup.org/wp/
[Thu Sep 17 15:47:47.234085 2026] [security2:error] [pid 60716:tid 60907] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/.env.backup"] [unique_id "aqxgA8Psx0SVFjrd623stQAAAA8"]
[Thu Sep 17 15:47:47.295873 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:61989] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623suQAAAFc"]
[Thu Sep 17 15:47:47.295966 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:61989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623suQAAAFc"]
[Thu Sep 17 15:47:47.346185 2026] [security2:error] [pid 60716:tid 60968] [client 216.49.131.135:63371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgA8Psx0SVFjrd623stwAASns"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260723200026&hideanons=1&hidebots=0&hidemyself=1&target=Team_Fox_Research_Incorporated&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:47:47.633567 2026] [security2:error] [pid 60716:tid 60918] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgA8Psx0SVFjrd623svgAAABo"]
[Thu Sep 17 15:47:47.704626 2026] [security2:error] [pid 60716:tid 60893] [client 14.96.156.146:52706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623sxQAAAAE"]
[Thu Sep 17 15:47:47.704726 2026] [security2:error] [pid 60716:tid 60893] [client 14.96.156.146:52706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623sxQAAAAE"]
[Thu Sep 17 15:47:47.792879 2026] [security2:error] [pid 60716:tid 60963] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/.env.old"] [unique_id "aqxgA8Psx0SVFjrd623syAAAAEU"]
[Thu Sep 17 15:47:47.867151 2026] [security2:error] [pid 60716:tid 60957] [client 148.227.75.216:30309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623sygAAAD8"]
[Thu Sep 17 15:47:47.867234 2026] [security2:error] [pid 60716:tid 60957] [client 148.227.75.216:30309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623sygAAAD8"]
[Thu Sep 17 15:47:47.886213 2026] [security2:error] [pid 60716:tid 60934] [client 143.105.152.240:54415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623sywAAACg"]
[Thu Sep 17 15:47:47.886289 2026] [security2:error] [pid 60716:tid 60934] [client 143.105.152.240:54415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgA8Psx0SVFjrd623sywAAACg"]
[Thu Sep 17 15:47:48.084435 2026] [security2:error] [pid 60716:tid 60892] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgA8Psx0SVFjrd623s1QAAAAA"]
[Thu Sep 17 15:47:48.244431 2026] [security2:error] [pid 60716:tid 61016] [client 122.8.45.84:63359] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBMPsx0SVFjrd623s4gAAAHo"]
[Thu Sep 17 15:47:48.244521 2026] [security2:error] [pid 60716:tid 61016] [client 122.8.45.84:63359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBMPsx0SVFjrd623s4gAAAHo"]
[Thu Sep 17 15:47:48.383406 2026] [core:error] [pid 60716:tid 60813] [remote 74.7.244.18:48296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:47:48.383425 2026] [core:error] [pid 60716:tid 60813] [remote 74.7.244.18:48296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:47:48.383609 2026] [security2:error] [pid 60716:tid 60973] [client 74.7.244.18:48296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-e9bbdf7d.ali.ita.mybluehost.me"] [uri "/website_e9bbdf7d/index.php"] [unique_id "aqxgBMPsx0SVFjrd623s6AAATzM"]
[Thu Sep 17 15:47:48.388179 2026] [security2:error] [pid 60716:tid 60941] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBMPsx0SVFjrd623s4wAAAC8"]
[Thu Sep 17 15:47:48.700038 2026] [security2:error] [pid 60716:tid 60996] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBMPsx0SVFjrd623s7wAAAGY"]
[Thu Sep 17 15:47:48.726181 2026] [security2:error] [pid 60716:tid 61013] [client 177.44.133.72:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgBMPsx0SVFjrd623s-gAAAHc"]
[Thu Sep 17 15:47:48.726280 2026] [security2:error] [pid 60716:tid 61013] [client 177.44.133.72:63727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgBMPsx0SVFjrd623s-gAAAHc"]
[Thu Sep 17 15:47:49.041842 2026] [security2:error] [pid 60716:tid 60946] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBMPsx0SVFjrd623s_QAAADQ"]
[Thu Sep 17 15:47:49.101780 2026] [security2:error] [pid 60716:tid 61010] [client 206.189.130.172:57776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.org"] [uri "/index.php"] [unique_id "aqxgBMPsx0SVFjrd623s_gAAdBc"], referer: http://radtechresourcegroup.org/backup/
[Thu Sep 17 15:47:49.199043 2026] [security2:error] [pid 60716:tid 60988] [client 122.8.45.84:47065] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBcPsx0SVFjrd623tCQAAAF4"]
[Thu Sep 17 15:47:49.199165 2026] [security2:error] [pid 60716:tid 60988] [client 122.8.45.84:47065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBcPsx0SVFjrd623tCQAAAF4"]
[Thu Sep 17 15:47:49.340438 2026] [security2:error] [pid 60716:tid 61018] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBcPsx0SVFjrd623tCwAAAHw"]
[Thu Sep 17 15:47:49.695150 2026] [security2:error] [pid 60716:tid 60892] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBcPsx0SVFjrd623tEwAAAAA"]
[Thu Sep 17 15:47:49.712145 2026] [security2:error] [pid 60716:tid 60913] [client 206.189.130.172:57776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.org"] [uri "/index.php"] [unique_id "aqxgBcPsx0SVFjrd623tFAAAFWw"], referer: http://radtechresourcegroup.org/old/
[Thu Sep 17 15:47:50.063594 2026] [security2:error] [pid 60716:tid 60894] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBcPsx0SVFjrd623tHQAAAAI"]
[Thu Sep 17 15:47:50.270924 2026] [security2:error] [pid 60716:tid 60978] [client 122.8.45.84:9145] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBsPsx0SVFjrd623tJgAAAFQ"]
[Thu Sep 17 15:47:50.271044 2026] [security2:error] [pid 60716:tid 60978] [client 122.8.45.84:9145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBsPsx0SVFjrd623tJgAAAFQ"]
[Thu Sep 17 15:47:50.329556 2026] [security2:error] [pid 60716:tid 60908] [client 206.189.130.172:57776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "radtechresourcegroup.org"] [uri "/index.php"] [unique_id "aqxgBsPsx0SVFjrd623tJwAAED0"], referer: http://radtechresourcegroup.org/new/
[Thu Sep 17 15:47:50.373076 2026] [security2:error] [pid 60716:tid 60970] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBsPsx0SVFjrd623tLwAAAEw"]
[Thu Sep 17 15:47:50.421643 2026] [security2:error] [pid 60716:tid 60922] [client 4.240.114.86:64576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "aqxgBsPsx0SVFjrd623tMAAAAB0"], referer: binance.com
[Thu Sep 17 15:47:50.509513 2026] [security2:error] [pid 60716:tid 60935] [client 79.116.89.151:65470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBsPsx0SVFjrd623tMgAAACk"]
[Thu Sep 17 15:47:50.510061 2026] [security2:error] [pid 60716:tid 60935] [client 79.116.89.151:65470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgBsPsx0SVFjrd623tMgAAACk"]
[Thu Sep 17 15:47:50.511914 2026] [security2:error] [pid 60716:tid 60943] [client 44.213.202.136:1427] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "fleigfinancialsllc.com"] [uri "/"] [unique_id "aqxgBsPsx0SVFjrd623tMwAAADE"]
[Thu Sep 17 15:47:50.554466 2026] [security2:error] [pid 60716:tid 61011] [client 146.190.67.2:58062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stephaniearnold.net"] [uri "/index.php"] [unique_id "aqxgBMPsx0SVFjrd623s-AAAdR4"], referer: http://stephaniearnold.net/backup/
[Thu Sep 17 15:47:50.574022 2026] [security2:error] [pid 60716:tid 60990] [client 43.156.79.172:35158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.79.156.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mechapteriaao.org"] [uri "/xmlrpc.php"] [unique_id "aqxgBsPsx0SVFjrd623tNgAAAGA"]
[Thu Sep 17 15:47:50.737295 2026] [security2:error] [pid 60716:tid 60981] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBsPsx0SVFjrd623tOQAAAFc"]
[Thu Sep 17 15:47:50.838552 2026] [security2:error] [pid 60716:tid 60972] [client 146.190.67.2:58062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stephaniearnold.net"] [uri "/index.php"] [unique_id "aqxgBsPsx0SVFjrd623tPwAATjY"], referer: http://stephaniearnold.net/wp/
[Thu Sep 17 15:47:51.041888 2026] [security2:error] [pid 60716:tid 60974] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgBsPsx0SVFjrd623tRQAAAFA"]
[Thu Sep 17 15:47:51.275545 2026] [security2:error] [pid 60716:tid 61010] [client 122.8.45.84:17857] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgB8Psx0SVFjrd623tWgAAAHQ"]
[Thu Sep 17 15:47:51.275674 2026] [security2:error] [pid 60716:tid 61010] [client 122.8.45.84:17857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgB8Psx0SVFjrd623tWgAAAHQ"]
[Thu Sep 17 15:47:51.419166 2026] [security2:error] [pid 60716:tid 61017] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgB8Psx0SVFjrd623tWwAAAHs"]
[Thu Sep 17 15:47:51.575746 2026] [security2:error] [pid 60716:tid 60925] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/.env.swp"] [unique_id "aqxgB8Psx0SVFjrd623tZAAAACA"]
[Thu Sep 17 15:47:51.707250 2026] [security2:error] [pid 60716:tid 61018] [client 169.58.198.243:54588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.198.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interlinck.com"] [uri "/wp-content/themes/jaida/lang.php"] [unique_id "aqxgB8Psx0SVFjrd623taQAAAHw"], referer: www.google.com
[Thu Sep 17 15:47:51.731460 2026] [security2:error] [pid 60716:tid 60904] [client 146.190.67.2:58062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stephaniearnold.net"] [uri "/index.php"] [unique_id "aqxgB8Psx0SVFjrd623tYwAADCA"], referer: http://stephaniearnold.net/wordpress/
[Thu Sep 17 15:47:51.741861 2026] [security2:error] [pid 60716:tid 60902] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/.env~"] [unique_id "aqxgB8Psx0SVFjrd623tbgAAAAo"]
[Thu Sep 17 15:47:52.026317 2026] [security2:error] [pid 60716:tid 60944] [client 146.190.67.2:58062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stephaniearnold.net"] [uri "/index.php"] [unique_id "aqxgB8Psx0SVFjrd623tcgAAMk8"], referer: http://stephaniearnold.net/new/
[Thu Sep 17 15:47:52.087333 2026] [security2:error] [pid 60716:tid 60897] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgB8Psx0SVFjrd623tdgAAAAU"]
[Thu Sep 17 15:47:52.256878 2026] [security2:error] [pid 60716:tid 60968] [client 122.8.45.84:14827] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgCMPsx0SVFjrd623thAAAAEo"]
[Thu Sep 17 15:47:52.257009 2026] [security2:error] [pid 60716:tid 60968] [client 122.8.45.84:14827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgCMPsx0SVFjrd623thAAAAEo"]
[Thu Sep 17 15:47:52.359980 2026] [security2:error] [pid 60716:tid 60958] [client 146.190.67.2:58062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stephaniearnold.net"] [uri "/index.php"] [unique_id "aqxgCMPsx0SVFjrd623tfwAAQFQ"], referer: http://stephaniearnold.net/old/
[Thu Sep 17 15:47:52.466610 2026] [security2:error] [pid 60716:tid 60907] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgCMPsx0SVFjrd623thwAAAA8"]
[Thu Sep 17 15:47:52.529142 2026] [security2:error] [pid 60716:tid 60963] [client 169.58.197.251:54818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxgCMPsx0SVFjrd623tiwAAAEU"], referer: binance.com
[Thu Sep 17 15:47:52.582712 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.246.111:43496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/.env"] [unique_id "aqxgCMPsx0SVFjrd623tjQAAAE0"]
[Thu Sep 17 15:47:52.819858 2026] [security2:error] [pid 60716:tid 60945] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgCMPsx0SVFjrd623tkwAAADM"]
[Thu Sep 17 15:47:52.876711 2026] [security2:error] [pid 60716:tid 60954] [client 36.36.91.173:13275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cherryfox.co.uk"] [uri "/index.php"] [unique_id "aqxgB8Psx0SVFjrd623tYgAAADw"], referer: http://www.cherryfox.co.uk/robots.txt
[Thu Sep 17 15:47:52.986762 2026] [security2:error] [pid 60716:tid 61016] [client 85.242.171.67:42948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgCMPsx0SVFjrd623tnQAAekg"]
[Thu Sep 17 15:47:53.459329 2026] [security2:error] [pid 60716:tid 61004] [client 122.8.45.84:9567] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgCcPsx0SVFjrd623ttgAAAG4"]
[Thu Sep 17 15:47:53.459438 2026] [security2:error] [pid 60716:tid 61004] [client 122.8.45.84:9567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgCcPsx0SVFjrd623ttgAAAG4"]
[Thu Sep 17 15:47:53.568622 2026] [security2:error] [pid 60716:tid 60953] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgCcPsx0SVFjrd623ttQAAADs"]
[Thu Sep 17 15:47:54.009213 2026] [security2:error] [pid 60716:tid 60984] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgCcPsx0SVFjrd623tyAAAAFo"]
[Thu Sep 17 15:47:54.024794 2026] [security2:error] [pid 60716:tid 60937] [client 91.92.138.251:49209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgCcPsx0SVFjrd623tygAAKwM"]
[Thu Sep 17 15:47:54.171652 2026] [security2:error] [pid 60716:tid 60960] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/app/.env"] [unique_id "aqxgCsPsx0SVFjrd623tzgAAAEI"]
[Thu Sep 17 15:47:54.337455 2026] [security2:error] [pid 60716:tid 60949] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/apps/.env"] [unique_id "aqxgCsPsx0SVFjrd623t1gAAADc"]
[Thu Sep 17 15:47:54.429823 2026] [security2:error] [pid 60716:tid 61008] [client 122.8.45.84:51995] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgCsPsx0SVFjrd623t2QAAAHI"]
[Thu Sep 17 15:47:54.429963 2026] [security2:error] [pid 60716:tid 61008] [client 122.8.45.84:51995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgCsPsx0SVFjrd623t2QAAAHI"]
[Thu Sep 17 15:47:54.491524 2026] [security2:error] [pid 60716:tid 60892] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/api/.env"] [unique_id "aqxgCsPsx0SVFjrd623t2wAAAAA"]
[Thu Sep 17 15:47:54.643084 2026] [security2:error] [pid 60716:tid 60948] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/web/.env"] [unique_id "aqxgCsPsx0SVFjrd623t3QAAADY"]
[Thu Sep 17 15:47:54.791045 2026] [security2:error] [pid 60716:tid 60964] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/site/.env"] [unique_id "aqxgCsPsx0SVFjrd623t5QAAAEY"]
[Thu Sep 17 15:47:54.916665 2026] [security2:error] [pid 60716:tid 60911] [client 129.212.220.28:42098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxgCsPsx0SVFjrd623t6AAAABM"]
[Thu Sep 17 15:47:54.942591 2026] [security2:error] [pid 60716:tid 60993] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/public/.env"] [unique_id "aqxgCsPsx0SVFjrd623t6wAAAGM"]
[Thu Sep 17 15:47:55.010816 2026] [security2:error] [pid 60716:tid 61018] [client 4.240.114.86:50387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "aqxgC8Psx0SVFjrd623t7QAAAHw"], referer: binance.com
[Thu Sep 17 15:47:55.274904 2026] [security2:error] [pid 60716:tid 60956] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgC8Psx0SVFjrd623t8AAAAD4"]
[Thu Sep 17 15:47:55.377541 2026] [security2:error] [pid 60716:tid 60944] [client 169.58.197.253:56265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxgC8Psx0SVFjrd623t-wAAADI"], referer: binance.com
[Thu Sep 17 15:47:55.380891 2026] [security2:error] [pid 60716:tid 60925] [client 122.8.45.84:61313] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgC8Psx0SVFjrd623t_AAAACA"]
[Thu Sep 17 15:47:55.381006 2026] [security2:error] [pid 60716:tid 60925] [client 122.8.45.84:61313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgC8Psx0SVFjrd623t_AAAACA"]
[Thu Sep 17 15:47:55.396594 2026] [security2:error] [pid 60716:tid 60941] [client 91.92.138.251:60953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgC8Psx0SVFjrd623t9wAALyg"]
[Thu Sep 17 15:47:55.439232 2026] [security2:error] [pid 60716:tid 60897] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/backend/.env"] [unique_id "aqxgC8Psx0SVFjrd623t_gAAAAU"]
[Thu Sep 17 15:47:55.587618 2026] [security2:error] [pid 60716:tid 60991] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/server/.env"] [unique_id "aqxgC8Psx0SVFjrd623t_wAAAGE"]
[Thu Sep 17 15:47:55.736909 2026] [security2:error] [pid 60716:tid 61003] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/frontend/.env"] [unique_id "aqxgC8Psx0SVFjrd623uBgAAAG0"]
[Thu Sep 17 15:47:55.837362 2026] [security2:error] [pid 60716:tid 61021] [client 34.154.246.111:43542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/.env.bak"] [unique_id "aqxgC8Psx0SVFjrd623uDQAAAH8"]
[Thu Sep 17 15:47:55.892104 2026] [security2:error] [pid 60716:tid 60939] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/src/.env"] [unique_id "aqxgC8Psx0SVFjrd623uDgAAAC0"]
[Thu Sep 17 15:47:55.993634 2026] [security2:error] [pid 60716:tid 60984] [client 34.154.246.111:43542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/.env.backup"] [unique_id "aqxgC8Psx0SVFjrd623uEwAAAFo"]
[Thu Sep 17 15:47:56.045940 2026] [security2:error] [pid 60716:tid 60981] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/core/.env"] [unique_id "aqxgDMPsx0SVFjrd623uFAAAAFc"]
[Thu Sep 17 15:47:56.199983 2026] [security2:error] [pid 60716:tid 60963] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/core/app/.env"] [unique_id "aqxgDMPsx0SVFjrd623uHgAAAEU"]
[Thu Sep 17 15:47:56.282511 2026] [security2:error] [pid 60716:tid 60971] [client 34.166.149.166:58860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/"] [unique_id "aqxgDMPsx0SVFjrd623uIwAAAE0"]
[Thu Sep 17 15:47:56.354244 2026] [security2:error] [pid 60716:tid 60934] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/config/.env"] [unique_id "aqxgDMPsx0SVFjrd623uKgAAACg"]
[Thu Sep 17 15:47:56.398881 2026] [security2:error] [pid 60716:tid 61005] [client 122.8.45.84:60731] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDMPsx0SVFjrd623uKwAAAG8"]
[Thu Sep 17 15:47:56.398996 2026] [security2:error] [pid 60716:tid 61005] [client 122.8.45.84:60731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDMPsx0SVFjrd623uKwAAAG8"]
[Thu Sep 17 15:47:56.501723 2026] [security2:error] [pid 60716:tid 60915] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/private/.env"] [unique_id "aqxgDMPsx0SVFjrd623uMQAAABc"]
[Thu Sep 17 15:47:56.564372 2026] [security2:error] [pid 60716:tid 60924] [client 131.255.20.231:5957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgDMPsx0SVFjrd623uLgAAH0Q"]
[Thu Sep 17 15:47:56.650752 2026] [security2:error] [pid 60716:tid 60901] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/application/.env"] [unique_id "aqxgDMPsx0SVFjrd623uNQAAAAk"]
[Thu Sep 17 15:47:56.656996 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.246.111:59178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/.env.old"] [unique_id "aqxgDMPsx0SVFjrd623uNgAAAH0"]
[Thu Sep 17 15:47:56.803093 2026] [security2:error] [pid 60716:tid 60993] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/bootstrap/.env"] [unique_id "aqxgDMPsx0SVFjrd623uPwAAAGM"]
[Thu Sep 17 15:47:56.896949 2026] [security2:error] [pid 60716:tid 60954] [client 136.158.61.34:5407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDMPsx0SVFjrd623uQgAAADw"]
[Thu Sep 17 15:47:56.900367 2026] [security2:error] [pid 60716:tid 60954] [client 136.158.61.34:5407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDMPsx0SVFjrd623uQgAAADw"]
[Thu Sep 17 15:47:56.951837 2026] [security2:error] [pid 60716:tid 60940] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/database/.env"] [unique_id "aqxgDMPsx0SVFjrd623uQwAAAC4"]
[Thu Sep 17 15:47:56.960308 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.149.166:49360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/"] [unique_id "aqxgDMPsx0SVFjrd623uRQAAAF0"]
[Thu Sep 17 15:47:57.114031 2026] [security2:error] [pid 60716:tid 60980] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/storage/.env"] [unique_id "aqxgDcPsx0SVFjrd623uRgAAAFY"]
[Thu Sep 17 15:47:57.272035 2026] [security2:error] [pid 60716:tid 60944] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/var/www/.env"] [unique_id "aqxgDcPsx0SVFjrd623uTQAAADI"]
[Thu Sep 17 15:47:57.359566 2026] [security2:error] [pid 60716:tid 60931] [client 122.8.45.84:13709] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDcPsx0SVFjrd623uUwAAACU"]
[Thu Sep 17 15:47:57.359695 2026] [security2:error] [pid 60716:tid 60931] [client 122.8.45.84:13709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDcPsx0SVFjrd623uUwAAACU"]
[Thu Sep 17 15:47:57.426770 2026] [security2:error] [pid 60716:tid 60943] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/var/www/html/.env"] [unique_id "aqxgDcPsx0SVFjrd623uVgAAADE"]
[Thu Sep 17 15:47:57.603031 2026] [security2:error] [pid 60716:tid 60899] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/current/.env"] [unique_id "aqxgDcPsx0SVFjrd623uVwAAAAc"]
[Thu Sep 17 15:47:57.616910 2026] [security2:error] [pid 60716:tid 60976] [client 4.240.114.86:51707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "aqxgDcPsx0SVFjrd623uWAAAAFI"], referer: binance.com
[Thu Sep 17 15:47:57.646958 2026] [security2:error] [pid 60716:tid 60985] [client 34.166.149.166:49362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/"] [unique_id "aqxgDcPsx0SVFjrd623uWQAAAFs"]
[Thu Sep 17 15:47:57.759519 2026] [security2:error] [pid 60716:tid 60946] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/release/.env"] [unique_id "aqxgDcPsx0SVFjrd623uYQAAADQ"]
[Thu Sep 17 15:47:57.907443 2026] [security2:error] [pid 60716:tid 61013] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/releases/.env"] [unique_id "aqxgDcPsx0SVFjrd623uZwAAAHc"]
[Thu Sep 17 15:47:58.058440 2026] [security2:error] [pid 60716:tid 61012] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/shared/.env"] [unique_id "aqxgDsPsx0SVFjrd623uagAAAHY"]
[Thu Sep 17 15:47:58.206188 2026] [security2:error] [pid 60716:tid 61005] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/deploy/.env"] [unique_id "aqxgDsPsx0SVFjrd623ubwAAAG8"]
[Thu Sep 17 15:47:58.332590 2026] [security2:error] [pid 60716:tid 60937] [client 122.8.45.84:51093] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623udgAAACs"]
[Thu Sep 17 15:47:58.332710 2026] [security2:error] [pid 60716:tid 60937] [client 122.8.45.84:51093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623udgAAACs"]
[Thu Sep 17 15:47:58.355610 2026] [security2:error] [pid 60716:tid 61017] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/build/.env"] [unique_id "aqxgDsPsx0SVFjrd623uegAAAHs"]
[Thu Sep 17 15:47:58.418200 2026] [security2:error] [pid 60716:tid 60928] [client 14.96.156.146:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623uewAAACM"]
[Thu Sep 17 15:47:58.418339 2026] [security2:error] [pid 60716:tid 60928] [client 14.96.156.146:53361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623uewAAACM"]
[Thu Sep 17 15:47:58.495635 2026] [security2:error] [pid 60716:tid 61010] [client 143.105.152.240:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623ugAAAAHQ"]
[Thu Sep 17 15:47:58.502021 2026] [security2:error] [pid 60716:tid 61010] [client 143.105.152.240:17490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623ugAAAAHQ"]
[Thu Sep 17 15:47:58.514091 2026] [security2:error] [pid 60716:tid 60954] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/dist/.env"] [unique_id "aqxgDsPsx0SVFjrd623ugQAAADw"]
[Thu Sep 17 15:47:58.565600 2026] [security2:error] [pid 60716:tid 60987] [client 34.166.149.166:49370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/"] [unique_id "aqxgDsPsx0SVFjrd623uhAAAAF0"]
[Thu Sep 17 15:47:58.576272 2026] [autoindex:error] [pid 60716:tid 61009] [client 34.185.180.78:34120] AH01276: Cannot serve directory /home1/jbnbnlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:47:58.663768 2026] [security2:error] [pid 60716:tid 60894] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/public_html/.env"] [unique_id "aqxgDsPsx0SVFjrd623uhQAAAAI"]
[Thu Sep 17 15:47:58.812682 2026] [security2:error] [pid 60716:tid 61011] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/htdocs/.env"] [unique_id "aqxgDsPsx0SVFjrd623ujgAAAHU"]
[Thu Sep 17 15:47:58.926542 2026] [security2:error] [pid 60716:tid 60904] [client 148.227.75.216:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623ukQAAAAw"]
[Thu Sep 17 15:47:58.926646 2026] [security2:error] [pid 60716:tid 60904] [client 148.227.75.216:58413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgDsPsx0SVFjrd623ukQAAAAw"]
[Thu Sep 17 15:47:58.972542 2026] [security2:error] [pid 60716:tid 60994] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/www/.env"] [unique_id "aqxgDsPsx0SVFjrd623ukwAAAGQ"]
[Thu Sep 17 15:47:59.128802 2026] [security2:error] [pid 60716:tid 60951] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/html/.env"] [unique_id "aqxgD8Psx0SVFjrd623ulwAAADk"]
[Thu Sep 17 15:47:59.285793 2026] [security2:error] [pid 60716:tid 60968] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/live/.env"] [unique_id "aqxgD8Psx0SVFjrd623uogAAAEo"]
[Thu Sep 17 15:47:59.342329 2026] [security2:error] [pid 60716:tid 60952] [client 177.44.133.72:64400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgD8Psx0SVFjrd623upAAAADo"]
[Thu Sep 17 15:47:59.342509 2026] [security2:error] [pid 60716:tid 60952] [client 177.44.133.72:64400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgD8Psx0SVFjrd623upAAAADo"]
[Thu Sep 17 15:47:59.367803 2026] [security2:error] [pid 60716:tid 60953] [client 122.8.45.84:51639] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgD8Psx0SVFjrd623upQAAADs"]
[Thu Sep 17 15:47:59.367958 2026] [security2:error] [pid 60716:tid 60953] [client 122.8.45.84:51639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgD8Psx0SVFjrd623upQAAADs"]
[Thu Sep 17 15:47:59.441754 2026] [security2:error] [pid 60716:tid 60981] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/prod/.env"] [unique_id "aqxgD8Psx0SVFjrd623upgAAAFc"]
[Thu Sep 17 15:47:59.591556 2026] [security2:error] [pid 60716:tid 60971] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/dev/.env"] [unique_id "aqxgD8Psx0SVFjrd623urAAAAE0"]
[Thu Sep 17 15:47:59.615003 2026] [security2:error] [pid 60716:tid 60947] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/.env"] [unique_id "aqxgD8Psx0SVFjrd623urQAAADU"]
[Thu Sep 17 15:47:59.761263 2026] [security2:error] [pid 60716:tid 60914] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/staging/.env"] [unique_id "aqxgD8Psx0SVFjrd623utQAAABY"]
[Thu Sep 17 15:47:59.914433 2026] [security2:error] [pid 60716:tid 60937] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/opt/.env"] [unique_id "aqxgD8Psx0SVFjrd623uuAAAACs"]
[Thu Sep 17 15:48:00.063431 2026] [security2:error] [pid 60716:tid 60992] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/laravel/.env"] [unique_id "aqxgEMPsx0SVFjrd623uvwAAAGI"]
[Thu Sep 17 15:48:00.109913 2026] [security2:error] [pid 60716:tid 60993] [client 4.240.114.86:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "aqxgEMPsx0SVFjrd623uwgAAAGM"], referer: binance.com
[Thu Sep 17 15:48:00.213581 2026] [security2:error] [pid 60716:tid 60987] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/symfony/.env"] [unique_id "aqxgEMPsx0SVFjrd623uyAAAAF0"]
[Thu Sep 17 15:48:00.320346 2026] [security2:error] [pid 60716:tid 60908] [client 169.58.197.251:55645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxgEMPsx0SVFjrd623uzAAAABA"], referer: binance.com
[Thu Sep 17 15:48:00.364578 2026] [security2:error] [pid 60716:tid 60936] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/wordpress/.env"] [unique_id "aqxgEMPsx0SVFjrd623uzQAAACo"]
[Thu Sep 17 15:48:00.428823 2026] [security2:error] [pid 60716:tid 60999] [client 122.8.45.84:63895] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEMPsx0SVFjrd623u0AAAAGk"]
[Thu Sep 17 15:48:00.428931 2026] [security2:error] [pid 60716:tid 60999] [client 122.8.45.84:63895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEMPsx0SVFjrd623u0AAAAGk"]
[Thu Sep 17 15:48:00.512982 2026] [security2:error] [pid 60716:tid 60918] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/wp/.env"] [unique_id "aqxgEMPsx0SVFjrd623u1AAAABo"]
[Thu Sep 17 15:48:00.663586 2026] [security2:error] [pid 60716:tid 60966] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/cms/.env"] [unique_id "aqxgEMPsx0SVFjrd623u2wAAAEg"]
[Thu Sep 17 15:48:00.680052 2026] [security2:error] [pid 60716:tid 60899] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxgEMPsx0SVFjrd623u3gAAAAc"]
[Thu Sep 17 15:48:00.703905 2026] [security2:error] [pid 60716:tid 60917] [client 57.129.81.154:45874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxgDMPsx0SVFjrd623uMAAAABk"]
[Thu Sep 17 15:48:00.812247 2026] [security2:error] [pid 60716:tid 60935] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/drupal/.env"] [unique_id "aqxgEMPsx0SVFjrd623u5AAAACk"]
[Thu Sep 17 15:48:00.826935 2026] [security2:error] [pid 60716:tid 60955] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxgEMPsx0SVFjrd623u5QAAAD0"]
[Thu Sep 17 15:48:00.982941 2026] [security2:error] [pid 60716:tid 60952] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/joomla/.env"] [unique_id "aqxgEMPsx0SVFjrd623u6gAAADo"]
[Thu Sep 17 15:48:00.991754 2026] [security2:error] [pid 60716:tid 60986] [client 141.94.94.32:47378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "golovefoundation.org"] [uri "/index.php"] [unique_id "aqxgDsPsx0SVFjrd623ufwAAAFw"]
[Thu Sep 17 15:48:01.134631 2026] [security2:error] [pid 60716:tid 60971] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxgEcPsx0SVFjrd623u7AAAAE0"]
[Thu Sep 17 15:48:01.137599 2026] [security2:error] [pid 60716:tid 60947] [client 34.32.107.79:54936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/magento/.env"] [unique_id "aqxgEcPsx0SVFjrd623u7QAAADU"]
[Thu Sep 17 15:48:01.180725 2026] [security2:error] [pid 60716:tid 60982] [client 79.116.89.151:49710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEcPsx0SVFjrd623u8wAAAFg"]
[Thu Sep 17 15:48:01.184996 2026] [security2:error] [pid 60716:tid 60982] [client 79.116.89.151:49710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEcPsx0SVFjrd623u8wAAAFg"]
[Thu Sep 17 15:48:01.483015 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:44607] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEcPsx0SVFjrd623vAAAAAFc"]
[Thu Sep 17 15:48:01.483165 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:44607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEcPsx0SVFjrd623vAAAAAFc"]
[Thu Sep 17 15:48:01.586514 2026] [security2:error] [pid 60716:tid 60898] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/shopify/.env"] [unique_id "aqxgEcPsx0SVFjrd623vAQAAAAY"]
[Thu Sep 17 15:48:01.738269 2026] [security2:error] [pid 60716:tid 60978] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/prestashop/.env"] [unique_id "aqxgEcPsx0SVFjrd623vCgAAAFQ"]
[Thu Sep 17 15:48:01.835752 2026] [security2:error] [pid 60716:tid 61018] [client 159.224.180.145:59531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgEcPsx0SVFjrd623vCQAAfDw"]
[Thu Sep 17 15:48:01.894560 2026] [security2:error] [pid 60716:tid 60940] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/codeigniter/.env"] [unique_id "aqxgEcPsx0SVFjrd623vEQAAAC4"]
[Thu Sep 17 15:48:02.043738 2026] [security2:error] [pid 60716:tid 60925] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/cakephp/.env"] [unique_id "aqxgEsPsx0SVFjrd623vFgAAACA"]
[Thu Sep 17 15:48:02.193709 2026] [security2:error] [pid 60716:tid 60943] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/zend/.env"] [unique_id "aqxgEsPsx0SVFjrd623vGwAAADE"]
[Thu Sep 17 15:48:02.343251 2026] [security2:error] [pid 60716:tid 60935] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/yii/.env"] [unique_id "aqxgEsPsx0SVFjrd623vJwAAACk"]
[Thu Sep 17 15:48:02.355474 2026] [security2:error] [pid 60716:tid 60977] [client 52.167.144.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kisajufreshherbs.com"] [uri "/index.php"] [unique_id "aqxgC8Psx0SVFjrd623t-gAAU1U"]
[Thu Sep 17 15:48:02.477041 2026] [security2:error] [pid 60716:tid 60996] [client 122.8.45.84:9417] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEsPsx0SVFjrd623vKwAAAGY"]
[Thu Sep 17 15:48:02.477156 2026] [security2:error] [pid 60716:tid 60996] [client 122.8.45.84:9417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgEsPsx0SVFjrd623vKwAAAGY"]
[Thu Sep 17 15:48:02.493699 2026] [security2:error] [pid 60716:tid 60952] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/laravel5/.env"] [unique_id "aqxgEsPsx0SVFjrd623vLQAAADo"]
[Thu Sep 17 15:48:02.645823 2026] [security2:error] [pid 60716:tid 60986] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/v1/.env"] [unique_id "aqxgEsPsx0SVFjrd623vMAAAAFw"]
[Thu Sep 17 15:48:02.792070 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.246.111:59254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/.env.swp"] [unique_id "aqxgEsPsx0SVFjrd623vOwAAADM"]
[Thu Sep 17 15:48:02.800417 2026] [security2:error] [pid 60716:tid 60910] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/v2/.env"] [unique_id "aqxgEsPsx0SVFjrd623vPAAAABI"]
[Thu Sep 17 15:48:02.958826 2026] [security2:error] [pid 60716:tid 60927] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/v3/.env"] [unique_id "aqxgEsPsx0SVFjrd623vQQAAACI"]
[Thu Sep 17 15:48:02.959306 2026] [security2:error] [pid 60716:tid 61012] [client 34.154.246.111:59254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/.env~"] [unique_id "aqxgEsPsx0SVFjrd623vQgAAAHY"]
[Thu Sep 17 15:48:02.991742 2026] [security2:error] [pid 60716:tid 61019] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxgEsPsx0SVFjrd623vQwAAAH0"]
[Thu Sep 17 15:48:03.115120 2026] [security2:error] [pid 60716:tid 61008] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/api/v1/.env"] [unique_id "aqxgE8Psx0SVFjrd623vRwAAAHI"]
[Thu Sep 17 15:48:03.143785 2026] [security2:error] [pid 60716:tid 60929] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/.env~"] [unique_id "aqxgE8Psx0SVFjrd623vSwAAACQ"]
[Thu Sep 17 15:48:03.262455 2026] [security2:error] [pid 60716:tid 60981] [client 4.240.114.86:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "aqxgE8Psx0SVFjrd623vUgAAAFc"], referer: binance.com
[Thu Sep 17 15:48:03.267694 2026] [security2:error] [pid 60716:tid 60911] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/api/v2/.env"] [unique_id "aqxgE8Psx0SVFjrd623vUwAAABM"]
[Thu Sep 17 15:48:03.336773 2026] [core:error] [pid 60716:tid 60903] [client 45.115.26.203:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:48:03.336795 2026] [core:error] [pid 60716:tid 60903] [client 45.115.26.203:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:48:03.421585 2026] [security2:error] [pid 60716:tid 60926] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/rest/.env"] [unique_id "aqxgE8Psx0SVFjrd623vXQAAACE"]
[Thu Sep 17 15:48:03.449117 2026] [security2:error] [pid 60716:tid 60983] [client 122.8.45.84:33149] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgE8Psx0SVFjrd623vXgAAAFk"]
[Thu Sep 17 15:48:03.449265 2026] [security2:error] [pid 60716:tid 60983] [client 122.8.45.84:33149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgE8Psx0SVFjrd623vXgAAAFk"]
[Thu Sep 17 15:48:03.574724 2026] [security2:error] [pid 60716:tid 60936] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/graphql/.env"] [unique_id "aqxgE8Psx0SVFjrd623vYwAAACo"]
[Thu Sep 17 15:48:03.723605 2026] [security2:error] [pid 60716:tid 60941] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/gateway/.env"] [unique_id "aqxgE8Psx0SVFjrd623vbAAAAC8"]
[Thu Sep 17 15:48:03.873451 2026] [security2:error] [pid 60716:tid 60994] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/microservice/.env"] [unique_id "aqxgE8Psx0SVFjrd623vcQAAAGQ"]
[Thu Sep 17 15:48:04.023300 2026] [security2:error] [pid 60716:tid 60985] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/service/.env"] [unique_id "aqxgFMPsx0SVFjrd623vdQAAAFs"]
[Thu Sep 17 15:48:04.074412 2026] [security2:error] [pid 60716:tid 60951] [client 123.253.3.14:45188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgE8Psx0SVFjrd623vdAAAOWw"]
[Thu Sep 17 15:48:04.173309 2026] [security2:error] [pid 60716:tid 60968] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/api/v3/.env"] [unique_id "aqxgFMPsx0SVFjrd623vfQAAAEo"]
[Thu Sep 17 15:48:04.321636 2026] [security2:error] [pid 60716:tid 60905] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/api/dev/.env"] [unique_id "aqxgFMPsx0SVFjrd623viAAAAA0"]
[Thu Sep 17 15:48:04.373739 2026] [security2:error] [pid 60716:tid 60942] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxgFMPsx0SVFjrd623viQAAADA"]
[Thu Sep 17 15:48:04.412155 2026] [security2:error] [pid 60716:tid 61021] [client 122.8.45.84:30723] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgFMPsx0SVFjrd623vigAAAH8"]
[Thu Sep 17 15:48:04.412285 2026] [security2:error] [pid 60716:tid 61021] [client 122.8.45.84:30723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgFMPsx0SVFjrd623vigAAAH8"]
[Thu Sep 17 15:48:04.467211 2026] [security2:error] [pid 60716:tid 60947] [client 169.58.197.253:56835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brianpagano.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxgFMPsx0SVFjrd623vjgAAADU"], referer: binance.com
[Thu Sep 17 15:48:04.472315 2026] [security2:error] [pid 60716:tid 60910] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/api/staging/.env"] [unique_id "aqxgFMPsx0SVFjrd623vjwAAABI"]
[Thu Sep 17 15:48:04.528198 2026] [security2:error] [pid 60716:tid 61012] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxgFMPsx0SVFjrd623vkgAAAHY"]
[Thu Sep 17 15:48:04.622448 2026] [security2:error] [pid 60716:tid 60961] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/vendor/.env"] [unique_id "aqxgFMPsx0SVFjrd623vlAAAAEM"]
[Thu Sep 17 15:48:04.650074 2026] [security2:error] [pid 60716:tid 60949] [client 162.241.226.11:22890] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxgFMPsx0SVFjrd623vlQAAADc"]
[Thu Sep 17 15:48:04.678918 2026] [security2:error] [pid 60716:tid 60928] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxgFMPsx0SVFjrd623vmAAAACM"]
[Thu Sep 17 15:48:04.772464 2026] [security2:error] [pid 60716:tid 60957] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/lib/.env"] [unique_id "aqxgFMPsx0SVFjrd623vnwAAAD8"]
[Thu Sep 17 15:48:04.829270 2026] [security2:error] [pid 60716:tid 61000] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxgFMPsx0SVFjrd623vpAAAAGo"]
[Thu Sep 17 15:48:04.921034 2026] [security2:error] [pid 60716:tid 60902] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/resources/.env"] [unique_id "aqxgFMPsx0SVFjrd623vtwAAAAo"]
[Thu Sep 17 15:48:04.978266 2026] [security2:error] [pid 60716:tid 60969] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/site/.env"] [unique_id "aqxgFMPsx0SVFjrd623vuQAAAEs"]
[Thu Sep 17 15:48:05.072685 2026] [security2:error] [pid 60716:tid 60944] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/assets/.env"] [unique_id "aqxgFcPsx0SVFjrd623vuwAAADI"]
[Thu Sep 17 15:48:05.130883 2026] [security2:error] [pid 60716:tid 60973] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxgFcPsx0SVFjrd623vvgAAAE8"]
[Thu Sep 17 15:48:05.221833 2026] [security2:error] [pid 60716:tid 60951] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/uploads/.env"] [unique_id "aqxgFcPsx0SVFjrd623vygAAADk"]
[Thu Sep 17 15:48:05.372940 2026] [security2:error] [pid 60716:tid 60999] [client 122.8.45.84:33531] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgFcPsx0SVFjrd623vzgAAAGk"]
[Thu Sep 17 15:48:05.373126 2026] [security2:error] [pid 60716:tid 60999] [client 122.8.45.84:33531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgFcPsx0SVFjrd623vzgAAAGk"]
[Thu Sep 17 15:48:05.373449 2026] [security2:error] [pid 60716:tid 60896] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/internal/.env"] [unique_id "aqxgFcPsx0SVFjrd623vzwAAAAQ"]
[Thu Sep 17 15:48:05.453061 2026] [security2:error] [pid 60716:tid 60963] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxgFcPsx0SVFjrd623v0QAAAEU"]
[Thu Sep 17 15:48:05.523324 2026] [security2:error] [pid 60716:tid 60971] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/tools/.env"] [unique_id "aqxgFcPsx0SVFjrd623v1AAAAE0"]
[Thu Sep 17 15:48:05.602859 2026] [security2:error] [pid 60716:tid 60919] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxgFcPsx0SVFjrd623v1gAAABs"]
[Thu Sep 17 15:48:05.671767 2026] [security2:error] [pid 60716:tid 60967] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/scripts/.env"] [unique_id "aqxgFcPsx0SVFjrd623v2AAAAEk"]
[Thu Sep 17 15:48:05.753492 2026] [security2:error] [pid 60716:tid 61012] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxgFcPsx0SVFjrd623v4wAAAHY"]
[Thu Sep 17 15:48:05.820605 2026] [security2:error] [pid 60716:tid 61002] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/bin/.env"] [unique_id "aqxgFcPsx0SVFjrd623v5AAAAGw"]
[Thu Sep 17 15:48:05.891818 2026] [security2:error] [pid 60716:tid 60935] [client 4.240.114.86:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "aqxgFcPsx0SVFjrd623v5QAAACk"], referer: binance.com
[Thu Sep 17 15:48:05.903431 2026] [security2:error] [pid 60716:tid 60934] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxgFcPsx0SVFjrd623v5gAAACg"]
[Thu Sep 17 15:48:05.927463 2026] [security2:error] [pid 60716:tid 60900] [client 88.99.80.227:29406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eris.media"] [uri "/index.php"] [unique_id "aqxgFcPsx0SVFjrd623v5wAAAAg"], referer: https://eris.media
[Thu Sep 17 15:48:05.969559 2026] [security2:error] [pid 60716:tid 60939] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/sbin/.env"] [unique_id "aqxgFcPsx0SVFjrd623v6wAAAC0"]
[Thu Sep 17 15:48:06.062246 2026] [security2:error] [pid 60716:tid 60990] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/core/.env"] [unique_id "aqxgFsPsx0SVFjrd623v8AAAAGA"]
[Thu Sep 17 15:48:06.119094 2026] [security2:error] [pid 60716:tid 61014] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/local/.env"] [unique_id "aqxgFsPsx0SVFjrd623v8gAAAHg"]
[Thu Sep 17 15:48:06.224592 2026] [security2:error] [pid 60716:tid 60993] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/core/app/.env"] [unique_id "aqxgFsPsx0SVFjrd623v_AAAAGM"]
[Thu Sep 17 15:48:06.268938 2026] [security2:error] [pid 60716:tid 60926] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/portal/.env"] [unique_id "aqxgFsPsx0SVFjrd623v_wAAACE"]
[Thu Sep 17 15:48:06.352835 2026] [security2:error] [pid 60716:tid 60960] [client 122.8.45.84:51561] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgFsPsx0SVFjrd623wAQAAAEI"]
[Thu Sep 17 15:48:06.353059 2026] [security2:error] [pid 60716:tid 60960] [client 122.8.45.84:51561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgFsPsx0SVFjrd623wAQAAAEI"]
[Thu Sep 17 15:48:06.375144 2026] [security2:error] [pid 60716:tid 60908] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxgFsPsx0SVFjrd623wAwAAABA"]
[Thu Sep 17 15:48:06.403322 2026] [fcgid:warn] [pid 60716:tid 60914] (70014)End of file found: [client 128.14.229.76:54974] mod_fcgid: can't get data from http client
[Thu Sep 17 15:48:06.418473 2026] [security2:error] [pid 60716:tid 60948] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/dashboard/.env"] [unique_id "aqxgFsPsx0SVFjrd623wBgAAADY"]
[Thu Sep 17 15:48:06.525101 2026] [security2:error] [pid 60716:tid 60950] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/private/.env"] [unique_id "aqxgFsPsx0SVFjrd623wCwAAADg"]
[Thu Sep 17 15:48:06.568514 2026] [security2:error] [pid 60716:tid 61011] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/panel/.env"] [unique_id "aqxgFsPsx0SVFjrd623wDgAAAHU"]
[Thu Sep 17 15:48:06.691830 2026] [security2:error] [pid 60716:tid 60917] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxgFsPsx0SVFjrd623wFAAAABk"]
[Thu Sep 17 15:48:06.720592 2026] [security2:error] [pid 60716:tid 61003] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/crm/.env"] [unique_id "aqxgFsPsx0SVFjrd623wGAAAAG0"]
[Thu Sep 17 15:48:06.722696 2026] [security2:error] [pid 60716:tid 60995] [client 34.154.246.111:47596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/app/.env"] [unique_id "aqxgFsPsx0SVFjrd623wGQAAAGU"]
[Thu Sep 17 15:48:06.841430 2026] [security2:error] [pid 60716:tid 61015] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/bootstrap/.env"] [unique_id "aqxgFsPsx0SVFjrd623wIQAAAHk"]
[Thu Sep 17 15:48:06.869951 2026] [security2:error] [pid 60716:tid 60959] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/erp/.env"] [unique_id "aqxgFsPsx0SVFjrd623wKwAAAEE"]
[Thu Sep 17 15:48:06.882645 2026] [security2:error] [pid 60716:tid 60975] [client 34.154.246.111:47596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/apps/.env"] [unique_id "aqxgFsPsx0SVFjrd623wLgAAAFE"]
[Thu Sep 17 15:48:06.990333 2026] [security2:error] [pid 60716:tid 60986] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/database/.env"] [unique_id "aqxgFsPsx0SVFjrd623wMwAAAFw"]
[Thu Sep 17 15:48:07.018668 2026] [security2:error] [pid 60716:tid 60953] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/shop/.env"] [unique_id "aqxgF8Psx0SVFjrd623wNQAAADs"]
[Thu Sep 17 15:48:07.036932 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.246.111:47596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/api/.env"] [unique_id "aqxgF8Psx0SVFjrd623wNgAAABs"]
[Thu Sep 17 15:48:07.139270 2026] [security2:error] [pid 60716:tid 61021] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/storage/.env"] [unique_id "aqxgF8Psx0SVFjrd623wOwAAAH8"]
[Thu Sep 17 15:48:07.167838 2026] [security2:error] [pid 60716:tid 60942] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/store/.env"] [unique_id "aqxgF8Psx0SVFjrd623wPQAAADA"]
[Thu Sep 17 15:48:07.178265 2026] [security2:error] [pid 60716:tid 60965] [client 57.141.14.67:31174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxgFcPsx0SVFjrd623v1QAAR0g"]
[Thu Sep 17 15:48:07.190692 2026] [security2:error] [pid 60716:tid 60937] [client 34.154.246.111:47596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/web/.env"] [unique_id "aqxgF8Psx0SVFjrd623wQAAAACs"]
[Thu Sep 17 15:48:07.302584 2026] [security2:error] [pid 60716:tid 60900] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxgF8Psx0SVFjrd623wRQAAAAg"]
[Thu Sep 17 15:48:07.317623 2026] [security2:error] [pid 60716:tid 60991] [client 122.8.45.84:26667] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgF8Psx0SVFjrd623wRgAAAGE"]
[Thu Sep 17 15:48:07.317754 2026] [security2:error] [pid 60716:tid 60991] [client 122.8.45.84:26667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgF8Psx0SVFjrd623wRgAAAGE"]
[Thu Sep 17 15:48:07.335849 2026] [security2:error] [pid 60716:tid 60898] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/saas/.env"] [unique_id "aqxgF8Psx0SVFjrd623wSAAAAAY"]
[Thu Sep 17 15:48:07.344516 2026] [security2:error] [pid 60716:tid 60945] [client 34.154.246.111:47596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/site/.env"] [unique_id "aqxgF8Psx0SVFjrd623wSgAAADM"]
[Thu Sep 17 15:48:07.452445 2026] [security2:error] [pid 60716:tid 60894] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxgF8Psx0SVFjrd623wUAAAAAI"]
[Thu Sep 17 15:48:07.486130 2026] [security2:error] [pid 60716:tid 60964] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/client/.env"] [unique_id "aqxgF8Psx0SVFjrd623wUQAAAEY"]
[Thu Sep 17 15:48:07.499096 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.246.111:47596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/public/.env"] [unique_id "aqxgF8Psx0SVFjrd623wUgAAACE"]
[Thu Sep 17 15:48:07.598408 2026] [security2:error] [pid 60716:tid 60984] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxgF8Psx0SVFjrd623wVQAAAFo"]
[Thu Sep 17 15:48:07.636057 2026] [security2:error] [pid 60716:tid 60923] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/project/.env"] [unique_id "aqxgF8Psx0SVFjrd623wVgAAAB4"]
[Thu Sep 17 15:48:07.745236 2026] [security2:error] [pid 60716:tid 60925] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/release/.env"] [unique_id "aqxgF8Psx0SVFjrd623wXwAAACA"]
[Thu Sep 17 15:48:07.786479 2026] [security2:error] [pid 60716:tid 60962] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/admin-panel/.env"] [unique_id "aqxgF8Psx0SVFjrd623wYAAAAEQ"]
[Thu Sep 17 15:48:07.896408 2026] [security2:error] [pid 60716:tid 60920] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/releases/.env"] [unique_id "aqxgF8Psx0SVFjrd623wYgAAABw"]
[Thu Sep 17 15:48:07.938099 2026] [security2:error] [pid 60716:tid 60944] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/control-panel/.env"] [unique_id "aqxgF8Psx0SVFjrd623wYwAAADI"]
[Thu Sep 17 15:48:08.051958 2026] [security2:error] [pid 60716:tid 60994] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/shared/.env"] [unique_id "aqxgGMPsx0SVFjrd623wZQAAAGQ"]
[Thu Sep 17 15:48:08.087615 2026] [security2:error] [pid 60716:tid 60995] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/user-panel/.env"] [unique_id "aqxgGMPsx0SVFjrd623wZwAAAGU"]
[Thu Sep 17 15:48:08.168351 2026] [security2:error] [pid 60716:tid 60893] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/backend/.env"] [unique_id "aqxgGMPsx0SVFjrd623waAAAAAE"]
[Thu Sep 17 15:48:08.203760 2026] [security2:error] [pid 60716:tid 60973] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/deploy/.env"] [unique_id "aqxgGMPsx0SVFjrd623wbAAAAE8"]
[Thu Sep 17 15:48:08.238388 2026] [security2:error] [pid 60716:tid 60897] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/node/.env"] [unique_id "aqxgGMPsx0SVFjrd623wbwAAAAU"]
[Thu Sep 17 15:48:08.270837 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:52829] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGMPsx0SVFjrd623wcAAAAFc"]
[Thu Sep 17 15:48:08.270952 2026] [security2:error] [pid 60716:tid 60981] [client 122.8.45.84:52829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGMPsx0SVFjrd623wcAAAAFc"]
[Thu Sep 17 15:48:08.327767 2026] [security2:error] [pid 60716:tid 60959] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/server/.env"] [unique_id "aqxgGMPsx0SVFjrd623wcwAAAEE"]
[Thu Sep 17 15:48:08.357191 2026] [security2:error] [pid 60716:tid 60975] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/build/.env"] [unique_id "aqxgGMPsx0SVFjrd623wdAAAAFE"]
[Thu Sep 17 15:48:08.387592 2026] [security2:error] [pid 60716:tid 60968] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/express/.env"] [unique_id "aqxgGMPsx0SVFjrd623wdQAAAEo"]
[Thu Sep 17 15:48:08.489490 2026] [security2:error] [pid 60716:tid 60912] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/frontend/.env"] [unique_id "aqxgGMPsx0SVFjrd623weAAAABQ"]
[Thu Sep 17 15:48:08.514125 2026] [security2:error] [pid 60716:tid 61013] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/dist/.env"] [unique_id "aqxgGMPsx0SVFjrd623wegAAAHc"]
[Thu Sep 17 15:48:08.536629 2026] [security2:error] [pid 60716:tid 60971] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/next/.env"] [unique_id "aqxgGMPsx0SVFjrd623wewAAAE0"]
[Thu Sep 17 15:48:08.628532 2026] [security2:error] [pid 60716:tid 60913] [client 213.57.121.85:33798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.joeledmundanderson.com"] [uri "/index.php"] [unique_id "aqxgGMPsx0SVFjrd623wfAAAABU"]
[Thu Sep 17 15:48:08.677677 2026] [security2:error] [pid 60716:tid 60946] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxgGMPsx0SVFjrd623wgQAAADQ"]
[Thu Sep 17 15:48:08.684436 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/src/.env"] [unique_id "aqxgGMPsx0SVFjrd623wggAAABI"]
[Thu Sep 17 15:48:08.685275 2026] [security2:error] [pid 60716:tid 61005] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/nuxt/.env"] [unique_id "aqxgGMPsx0SVFjrd623whAAAAG8"]
[Thu Sep 17 15:48:08.826049 2026] [security2:error] [pid 60716:tid 61002] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/htdocs/.env"] [unique_id "aqxgGMPsx0SVFjrd623wjAAAAGw"]
[Thu Sep 17 15:48:08.839283 2026] [security2:error] [pid 60716:tid 61012] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/nest/.env"] [unique_id "aqxgGMPsx0SVFjrd623wjQAAAHY"]
[Thu Sep 17 15:48:08.844349 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/core/.env"] [unique_id "aqxgGMPsx0SVFjrd623wjwAAAGE"]
[Thu Sep 17 15:48:08.974684 2026] [security2:error] [pid 60716:tid 60993] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/www/.env"] [unique_id "aqxgGMPsx0SVFjrd623wlgAAAGM"]
[Thu Sep 17 15:48:08.993532 2026] [security2:error] [pid 60716:tid 60901] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/react/.env"] [unique_id "aqxgGMPsx0SVFjrd623wmQAAAAk"]
[Thu Sep 17 15:48:08.997366 2026] [security2:error] [pid 60716:tid 61007] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/core/app/.env"] [unique_id "aqxgGMPsx0SVFjrd623wmgAAAHE"]
[Thu Sep 17 15:48:09.043432 2026] [security2:error] [pid 60716:tid 60928] [client 16.216.88.152:16384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.westshorebrewing.com"] [uri "/index.php"] [unique_id "aqxgF8Psx0SVFjrd623wSQAAI2Q"]
[Thu Sep 17 15:48:09.077256 2026] [security2:error] [pid 60716:tid 60924] [client 143.105.152.240:59855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623woAAAAB8"]
[Thu Sep 17 15:48:09.081827 2026] [security2:error] [pid 60716:tid 60924] [client 143.105.152.240:59855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623woAAAAB8"]
[Thu Sep 17 15:48:09.121149 2026] [security2:error] [pid 60716:tid 60923] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/html/.env"] [unique_id "aqxgGcPsx0SVFjrd623wogAAAB4"]
[Thu Sep 17 15:48:09.143030 2026] [security2:error] [pid 60716:tid 60950] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/vue/.env"] [unique_id "aqxgGcPsx0SVFjrd623wowAAADg"]
[Thu Sep 17 15:48:09.146798 2026] [security2:error] [pid 60716:tid 60990] [client 14.96.156.146:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wpAAAAGA"]
[Thu Sep 17 15:48:09.146918 2026] [security2:error] [pid 60716:tid 60990] [client 14.96.156.146:54020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wpAAAAGA"]
[Thu Sep 17 15:48:09.173279 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/config/.env"] [unique_id "aqxgGcPsx0SVFjrd623wpgAAAHU"]
[Thu Sep 17 15:48:09.250026 2026] [security2:error] [pid 60716:tid 60935] [client 122.8.45.84:39337] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wrAAAACk"]
[Thu Sep 17 15:48:09.250374 2026] [security2:error] [pid 60716:tid 60935] [client 122.8.45.84:39337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wrAAAACk"]
[Thu Sep 17 15:48:09.276929 2026] [security2:error] [pid 60716:tid 61004] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/live/.env"] [unique_id "aqxgGcPsx0SVFjrd623wrwAAAG4"]
[Thu Sep 17 15:48:09.294301 2026] [security2:error] [pid 60716:tid 60920] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/angular/.env"] [unique_id "aqxgGcPsx0SVFjrd623wsQAAABw"]
[Thu Sep 17 15:48:09.330731 2026] [security2:error] [pid 60716:tid 60995] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/private/.env"] [unique_id "aqxgGcPsx0SVFjrd623wsgAAAGU"]
[Thu Sep 17 15:48:09.334285 2026] [security2:error] [pid 60716:tid 60914] [client 148.227.75.216:60966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wswAAABY"]
[Thu Sep 17 15:48:09.334361 2026] [security2:error] [pid 60716:tid 60914] [client 148.227.75.216:60966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wswAAABY"]
[Thu Sep 17 15:48:09.430826 2026] [security2:error] [pid 60716:tid 60897] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxgGcPsx0SVFjrd623wtQAAAAU"]
[Thu Sep 17 15:48:09.444176 2026] [security2:error] [pid 60716:tid 60906] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/svelte/.env"] [unique_id "aqxgGcPsx0SVFjrd623wtgAAAA4"]
[Thu Sep 17 15:48:09.487527 2026] [security2:error] [pid 60716:tid 60933] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/application/.env"] [unique_id "aqxgGcPsx0SVFjrd623wtwAAACc"]
[Thu Sep 17 15:48:09.585440 2026] [security2:error] [pid 60716:tid 60899] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxgGcPsx0SVFjrd623wuQAAAAc"]
[Thu Sep 17 15:48:09.593982 2026] [security2:error] [pid 60716:tid 60980] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/vite/.env"] [unique_id "aqxgGcPsx0SVFjrd623wugAAAFY"]
[Thu Sep 17 15:48:09.641875 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/bootstrap/.env"] [unique_id "aqxgGcPsx0SVFjrd623wuwAAAFA"]
[Thu Sep 17 15:48:09.731044 2026] [security2:error] [pid 60716:tid 60972] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxgGcPsx0SVFjrd623wwQAAAE4"]
[Thu Sep 17 15:48:09.744997 2026] [security2:error] [pid 60716:tid 60912] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/backup/.env"] [unique_id "aqxgGcPsx0SVFjrd623wwgAAABQ"]
[Thu Sep 17 15:48:09.795391 2026] [security2:error] [pid 60716:tid 60913] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/database/.env"] [unique_id "aqxgGcPsx0SVFjrd623wxQAAABU"]
[Thu Sep 17 15:48:09.864847 2026] [security2:error] [pid 60716:tid 60996] [client 136.158.61.34:6688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wzAAAAGY"]
[Thu Sep 17 15:48:09.864962 2026] [security2:error] [pid 60716:tid 60996] [client 136.158.61.34:6688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623wzAAAAGY"]
[Thu Sep 17 15:48:09.882605 2026] [security2:error] [pid 60716:tid 60910] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/opt/.env"] [unique_id "aqxgGcPsx0SVFjrd623wzQAAABI"]
[Thu Sep 17 15:48:09.893959 2026] [security2:error] [pid 60716:tid 61005] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/backups/.env"] [unique_id "aqxgGcPsx0SVFjrd623wzgAAAG8"]
[Thu Sep 17 15:48:09.958054 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/storage/.env"] [unique_id "aqxgGcPsx0SVFjrd623w0AAAAEM"]
[Thu Sep 17 15:48:09.959182 2026] [security2:error] [pid 60716:tid 60982] [client 4.240.114.86:57372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "aqxgGcPsx0SVFjrd623w0QAAAFg"], referer: binance.com
[Thu Sep 17 15:48:09.984422 2026] [security2:error] [pid 60716:tid 60959] [client 177.44.133.72:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623w0gAAAEE"]
[Thu Sep 17 15:48:09.984550 2026] [security2:error] [pid 60716:tid 60959] [client 177.44.133.72:65069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgGcPsx0SVFjrd623w0gAAAEE"]
[Thu Sep 17 15:48:10.034110 2026] [security2:error] [pid 60716:tid 60942] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxgGsPsx0SVFjrd623w1AAAADA"]
[Thu Sep 17 15:48:10.043378 2026] [security2:error] [pid 60716:tid 61021] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/old/.env"] [unique_id "aqxgGsPsx0SVFjrd623w1QAAAH8"]
[Thu Sep 17 15:48:10.113222 2026] [security2:error] [pid 60716:tid 60927] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/var/www/.env"] [unique_id "aqxgGsPsx0SVFjrd623w2AAAACI"]
[Thu Sep 17 15:48:10.177988 2026] [security2:error] [pid 60716:tid 61013] [client 122.8.45.84:34303] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGsPsx0SVFjrd623w2gAAAHc"]
[Thu Sep 17 15:48:10.178104 2026] [security2:error] [pid 60716:tid 61013] [client 122.8.45.84:34303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgGsPsx0SVFjrd623w2gAAAHc"]
[Thu Sep 17 15:48:10.185106 2026] [security2:error] [pid 60716:tid 60997] [client 34.185.180.78:34120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/symfony/.env"] [unique_id "aqxgGsPsx0SVFjrd623w3QAAAGc"]
[Thu Sep 17 15:48:10.191935 2026] [security2:error] [pid 60716:tid 60916] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/tmp/.env"] [unique_id "aqxgGsPsx0SVFjrd623w3gAAABg"]
[Thu Sep 17 15:48:10.278363 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/var/www/html/.env"] [unique_id "aqxgGsPsx0SVFjrd623w5AAAACM"]
[Thu Sep 17 15:48:10.331300 2026] [security2:error] [pid 60716:tid 60766] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.env"] [unique_id "aqxgGsPsx0SVFjrd623w5QAAcgc"]
[Thu Sep 17 15:48:10.341698 2026] [security2:error] [pid 60716:tid 61014] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/temp/.env"] [unique_id "aqxgGsPsx0SVFjrd623w7AAAAHg"]
[Thu Sep 17 15:48:10.431370 2026] [security2:error] [pid 60716:tid 60984] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/current/.env"] [unique_id "aqxgGsPsx0SVFjrd623w7gAAAFo"]
[Thu Sep 17 15:48:10.490782 2026] [security2:error] [pid 60716:tid 60970] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/lab/.env"] [unique_id "aqxgGsPsx0SVFjrd623w8gAAAEw"]
[Thu Sep 17 15:48:10.514918 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w6AAAcjI"]
[Thu Sep 17 15:48:10.517289 2026] [security2:error] [pid 60716:tid 60833] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.env.old"] [unique_id "aqxgGsPsx0SVFjrd623w9QAAckc"]
[Thu Sep 17 15:48:10.517300 2026] [security2:error] [pid 60716:tid 60825] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.env.backup"] [unique_id "aqxgGsPsx0SVFjrd623w9gAAcj8"]
[Thu Sep 17 15:48:10.517814 2026] [security2:error] [pid 60716:tid 60847] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.env.bak"] [unique_id "aqxgGsPsx0SVFjrd623w9wAAclU"]
[Thu Sep 17 15:48:10.531004 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w6QAAcgY"]
[Thu Sep 17 15:48:10.587852 2026] [security2:error] [pid 60716:tid 60922] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/release/.env"] [unique_id "aqxgGsPsx0SVFjrd623w_gAAAB0"]
[Thu Sep 17 15:48:10.641127 2026] [security2:error] [pid 60716:tid 60976] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/cronlab/.env"] [unique_id "aqxgGsPsx0SVFjrd623w_wAAAFI"]
[Thu Sep 17 15:48:10.652474 2026] [security2:error] [pid 60716:tid 60919] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/wordpress/.env"] [unique_id "aqxgGsPsx0SVFjrd623xAAAAABs"]
[Thu Sep 17 15:48:10.745341 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/releases/.env"] [unique_id "aqxgGsPsx0SVFjrd623xCQAAACo"]
[Thu Sep 17 15:48:10.771543 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w5wAAcns"]
[Thu Sep 17 15:48:10.771699 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w5gAAcng"]
[Thu Sep 17 15:48:10.771802 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w6gAAcjo"]
[Thu Sep 17 15:48:10.771873 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w6wAAcgc"]
[Thu Sep 17 15:48:10.789834 2026] [security2:error] [pid 60716:tid 60799] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/.env.php"] [unique_id "aqxgGsPsx0SVFjrd623xDAAAciU"]
[Thu Sep 17 15:48:10.791685 2026] [security2:error] [pid 60716:tid 60902] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/cron/.env"] [unique_id "aqxgGsPsx0SVFjrd623xDQAAAAo"]
[Thu Sep 17 15:48:10.806376 2026] [security2:error] [pid 60716:tid 60920] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/wp/.env"] [unique_id "aqxgGsPsx0SVFjrd623xDgAAABw"]
[Thu Sep 17 15:48:10.897444 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/shared/.env"] [unique_id "aqxgGsPsx0SVFjrd623xDwAAAA8"]
[Thu Sep 17 15:48:10.906809 2026] [security2:error] [pid 60716:tid 60800] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.env~"] [unique_id "aqxgGsPsx0SVFjrd623xEQAAciY"]
[Thu Sep 17 15:48:10.906828 2026] [security2:error] [pid 60716:tid 60842] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.env.swp"] [unique_id "aqxgGsPsx0SVFjrd623xEgAAclA"]
[Thu Sep 17 15:48:10.943602 2026] [security2:error] [pid 60716:tid 60957] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/en/.env"] [unique_id "aqxgGsPsx0SVFjrd623xFwAAAD8"]
[Thu Sep 17 15:48:10.968482 2026] [security2:error] [pid 60716:tid 60966] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxgGsPsx0SVFjrd623xGQAAAEg"]
[Thu Sep 17 15:48:11.041792 2026] [security2:error] [pid 60716:tid 60860] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/app/.env"] [unique_id "aqxgG8Psx0SVFjrd623xIAAAcmI"]
[Thu Sep 17 15:48:11.041860 2026] [security2:error] [pid 60716:tid 60851] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/api/.env"] [unique_id "aqxgG8Psx0SVFjrd623xHwAAclk"]
[Thu Sep 17 15:48:11.052721 2026] [security2:error] [pid 60716:tid 60977] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/deploy/.env"] [unique_id "aqxgG8Psx0SVFjrd623xIQAAAFM"]
[Thu Sep 17 15:48:11.112102 2026] [security2:error] [pid 60716:tid 60973] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/administrator/.env"] [unique_id "aqxgG8Psx0SVFjrd623xIgAAAE8"]
[Thu Sep 17 15:48:11.139697 2026] [security2:error] [pid 60716:tid 60906] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/drupal/.env"] [unique_id "aqxgG8Psx0SVFjrd623xJAAAAA4"]
[Thu Sep 17 15:48:11.163463 2026] [security2:error] [pid 60716:tid 60935] [client 122.8.45.84:51567] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgG8Psx0SVFjrd623xJQAAACk"]
[Thu Sep 17 15:48:11.163603 2026] [security2:error] [pid 60716:tid 60935] [client 122.8.45.84:51567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgG8Psx0SVFjrd623xJQAAACk"]
[Thu Sep 17 15:48:11.206880 2026] [security2:error] [pid 60716:tid 60980] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/build/.env"] [unique_id "aqxgG8Psx0SVFjrd623xLgAAAFY"]
[Thu Sep 17 15:48:11.265047 2026] [security2:error] [pid 60716:tid 60975] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/psnlink/.env"] [unique_id "aqxgG8Psx0SVFjrd623xMAAAAFE"]
[Thu Sep 17 15:48:11.294727 2026] [security2:error] [pid 60716:tid 60983] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/joomla/.env"] [unique_id "aqxgG8Psx0SVFjrd623xMQAAAFk"]
[Thu Sep 17 15:48:11.340036 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w9AAAcjI"]
[Thu Sep 17 15:48:11.352231 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w8wAAcn4"]
[Thu Sep 17 15:48:11.356321 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w_AAAcj8"]
[Thu Sep 17 15:48:11.358419 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w-QAAcgw"]
[Thu Sep 17 15:48:11.361263 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w-wAAclU"]
[Thu Sep 17 15:48:11.362165 2026] [security2:error] [pid 60716:tid 60833] [remote 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w-gAAckc"]
[Thu Sep 17 15:48:11.367234 2026] [security2:error] [pid 60716:tid 60896] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/dist/.env"] [unique_id "aqxgG8Psx0SVFjrd623xNQAAAAQ"]
[Thu Sep 17 15:48:11.416068 2026] [security2:error] [pid 60716:tid 60952] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/exapi/.env"] [unique_id "aqxgG8Psx0SVFjrd623xNwAAADo"]
[Thu Sep 17 15:48:11.457317 2026] [security2:error] [pid 60716:tid 60946] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/magento/.env"] [unique_id "aqxgG8Psx0SVFjrd623xOAAAADQ"]
[Thu Sep 17 15:48:11.462978 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623w-AAAcjM"]
[Thu Sep 17 15:48:11.463656 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623xGAAAcj0"]
[Thu Sep 17 15:48:11.476447 2026] [security2:error] [pid 60716:tid 60874] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/backend/.env"] [unique_id "aqxgG8Psx0SVFjrd623xOwAAcnA"]
[Thu Sep 17 15:48:11.491479 2026] [security2:error] [pid 60716:tid 60913] [client 128.140.41.193:50600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pger.net"] [uri "/wildfarm"] [unique_id "aqxgG8Psx0SVFjrd623xPQAAABU"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:48:11.492169 2026] [security2:error] [pid 60716:tid 60848] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/server/.env"] [unique_id "aqxgG8Psx0SVFjrd623xPgAAclY"]
[Thu Sep 17 15:48:11.493493 2026] [security2:error] [pid 60716:tid 60801] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/config/.env"] [unique_id "aqxgG8Psx0SVFjrd623xPwAAcic"]
[Thu Sep 17 15:48:11.498327 2026] [security2:error] [pid 60716:tid 60809] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/web/.env"] [unique_id "aqxgG8Psx0SVFjrd623xQQAAci8"]
[Thu Sep 17 15:48:11.498382 2026] [security2:error] [pid 60716:tid 60798] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/src/.env"] [unique_id "aqxgG8Psx0SVFjrd623xQAAAciQ"]
[Thu Sep 17 15:48:11.528363 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/public_html/.env"] [unique_id "aqxgG8Psx0SVFjrd623xQgAAAFg"]
[Thu Sep 17 15:48:11.565597 2026] [security2:error] [pid 60716:tid 60940] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/sitemaps/.env"] [unique_id "aqxgG8Psx0SVFjrd623xQwAAAC4"]
[Thu Sep 17 15:48:11.609903 2026] [security2:error] [pid 60716:tid 60791] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/client/.env"] [unique_id "aqxgG8Psx0SVFjrd623xRAAAch0"]
[Thu Sep 17 15:48:11.613050 2026] [security2:error] [pid 60716:tid 60841] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/frontend/.env"] [unique_id "aqxgG8Psx0SVFjrd623xRQAAck8"]
[Thu Sep 17 15:48:11.613050 2026] [security2:error] [pid 60716:tid 60797] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/public/.env"] [unique_id "aqxgG8Psx0SVFjrd623xRgAAciM"]
[Thu Sep 17 15:48:11.621194 2026] [security2:error] [pid 60716:tid 60918] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/shopify/.env"] [unique_id "aqxgG8Psx0SVFjrd623xRwAAABo"]
[Thu Sep 17 15:48:11.627075 2026] [security2:error] [pid 60716:tid 60846] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/var/www/.env"] [unique_id "aqxgG8Psx0SVFjrd623xSAAAclQ"]
[Thu Sep 17 15:48:11.628551 2026] [security2:error] [pid 60716:tid 60857] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/var/www/html/.env"] [unique_id "aqxgG8Psx0SVFjrd623xSQAAcl8"]
[Thu Sep 17 15:48:11.632985 2026] [security2:error] [pid 60716:tid 60868] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/laravel/.env"] [unique_id "aqxgG8Psx0SVFjrd623xSgAAcmo"]
[Thu Sep 17 15:48:11.633071 2026] [security2:error] [pid 60716:tid 60783] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/application/.env"] [unique_id "aqxgG8Psx0SVFjrd623xSwAAchY"]
[Thu Sep 17 15:48:11.695587 2026] [security2:error] [pid 60716:tid 61021] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/htdocs/.env"] [unique_id "aqxgG8Psx0SVFjrd623xTwAAAH8"]
[Thu Sep 17 15:48:11.745102 2026] [security2:error] [pid 60716:tid 60877] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/apps/.env"] [unique_id "aqxgG8Psx0SVFjrd623xVQAAcnM"]
[Thu Sep 17 15:48:11.748471 2026] [security2:error] [pid 60716:tid 60781] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/back/.env"] [unique_id "aqxgG8Psx0SVFjrd623xVgAAchQ"]
[Thu Sep 17 15:48:11.748480 2026] [security2:error] [pid 60716:tid 60778] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/backup/.env"] [unique_id "aqxgG8Psx0SVFjrd623xVwAAchI"]
[Thu Sep 17 15:48:11.763309 2026] [security2:error] [pid 60716:tid 60835] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/cms/.env"] [unique_id "aqxgG8Psx0SVFjrd623xWgAAckk"]
[Thu Sep 17 15:48:11.763797 2026] [security2:error] [pid 60716:tid 60761] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/dev/.env"] [unique_id "aqxgG8Psx0SVFjrd623xWwAAcgM"]
[Thu Sep 17 15:48:11.770829 2026] [security2:error] [pid 60716:tid 60853] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/production/.env"] [unique_id "aqxgG8Psx0SVFjrd623xXQAAcls"]
[Thu Sep 17 15:48:11.770832 2026] [security2:error] [pid 60716:tid 60855] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/prod/.env"] [unique_id "aqxgG8Psx0SVFjrd623xXAAAcl0"]
[Thu Sep 17 15:48:11.775893 2026] [security2:error] [pid 60716:tid 60979] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/prestashop/.env"] [unique_id "aqxgG8Psx0SVFjrd623xXgAAAFU"]
[Thu Sep 17 15:48:11.849129 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/www/.env"] [unique_id "aqxgG8Psx0SVFjrd623xYAAAACM"]
[Thu Sep 17 15:48:11.849360 2026] [security2:error] [pid 60716:tid 60961] [client 79.116.89.151:50336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgG8Psx0SVFjrd623xYQAAAEM"]
[Thu Sep 17 15:48:11.852313 2026] [security2:error] [pid 60716:tid 60961] [client 79.116.89.151:50336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgG8Psx0SVFjrd623xYQAAAEM"]
[Thu Sep 17 15:48:11.880696 2026] [security2:error] [pid 60716:tid 60880] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/staging/.env"] [unique_id "aqxgG8Psx0SVFjrd623xYgAAcnY"]
[Thu Sep 17 15:48:11.883877 2026] [security2:error] [pid 60716:tid 60808] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/old/.env"] [unique_id "aqxgG8Psx0SVFjrd623xZAAAci4"]
[Thu Sep 17 15:48:11.883913 2026] [security2:error] [pid 60716:tid 60776] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/test/.env"] [unique_id "aqxgG8Psx0SVFjrd623xYwAAchA"]
[Thu Sep 17 15:48:11.898539 2026] [security2:error] [pid 60716:tid 60802] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/new/.env"] [unique_id "aqxgG8Psx0SVFjrd623xZgAAcig"]
[Thu Sep 17 15:48:11.898586 2026] [security2:error] [pid 60716:tid 60819] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/node-api/.env"] [unique_id "aqxgG8Psx0SVFjrd623xZwAAcjk"]
[Thu Sep 17 15:48:11.905633 2026] [security2:error] [pid 60716:tid 60782] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/api-backend/.env"] [unique_id "aqxgG8Psx0SVFjrd623xaAAAchU"]
[Thu Sep 17 15:48:11.905642 2026] [security2:error] [pid 60716:tid 60786] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/admin-app/.env"] [unique_id "aqxgG8Psx0SVFjrd623xaQAAchg"]
[Thu Sep 17 15:48:11.921036 2026] [security2:error] [pid 60716:tid 60911] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/codeigniter/.env"] [unique_id "aqxgG8Psx0SVFjrd623xagAAABM"]
[Thu Sep 17 15:48:11.923573 2026] [security2:error] [pid 60716:tid 61017] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgG8Psx0SVFjrd623xWAAAAHs"]
[Thu Sep 17 15:48:11.964168 2026] [security2:error] [pid 60716:tid 60901] [client 128.140.41.193:50604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pger.net"] [uri "/wildfarm/"] [unique_id "aqxgG8Psx0SVFjrd623xbgAAAAk"], referer: https://pger.net/wildfarm
[Thu Sep 17 15:48:12.005508 2026] [security2:error] [pid 60716:tid 60908] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/html/.env"] [unique_id "aqxgHMPsx0SVFjrd623xcAAAABA"]
[Thu Sep 17 15:48:12.019153 2026] [security2:error] [pid 60716:tid 60795] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/current/.env"] [unique_id "aqxgHMPsx0SVFjrd623xcwAAciE"]
[Thu Sep 17 15:48:12.019154 2026] [security2:error] [pid 60716:tid 60832] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/public_html/.env"] [unique_id "aqxgHMPsx0SVFjrd623xcgAAckY"]
[Thu Sep 17 15:48:12.033444 2026] [security2:error] [pid 60716:tid 60770] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/server/backend/.env"] [unique_id "aqxgHMPsx0SVFjrd623xdAAAcgs"]
[Thu Sep 17 15:48:12.033511 2026] [security2:error] [pid 60716:tid 60867] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/server/api/.env"] [unique_id "aqxgHMPsx0SVFjrd623xdQAAcmk"]
[Thu Sep 17 15:48:12.040360 2026] [security2:error] [pid 60716:tid 60845] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxgHMPsx0SVFjrd623xeAAAclM"]
[Thu Sep 17 15:48:12.040416 2026] [security2:error] [pid 60716:tid 60787] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.docker/.env"] [unique_id "aqxgHMPsx0SVFjrd623xdwAAchk"]
[Thu Sep 17 15:48:12.068573 2026] [security2:error] [pid 60716:tid 60814] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/administrator/.env"] [unique_id "aqxgHMPsx0SVFjrd623xcQAAcjQ"]
[Thu Sep 17 15:48:12.078018 2026] [security2:error] [pid 60716:tid 60976] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cakephp/.env"] [unique_id "aqxgHMPsx0SVFjrd623xeQAAAFI"]
[Thu Sep 17 15:48:12.123322 2026] [security2:error] [pid 60716:tid 60987] [client 129.212.220.28:46464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chriswestlake.com"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xdgAAAF0"]
[Thu Sep 17 15:48:12.146278 2026] [security2:error] [pid 60716:tid 60934] [client 122.8.45.84:63495] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgHMPsx0SVFjrd623xewAAACg"]
[Thu Sep 17 15:48:12.146394 2026] [security2:error] [pid 60716:tid 60934] [client 122.8.45.84:63495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgHMPsx0SVFjrd623xewAAACg"]
[Thu Sep 17 15:48:12.155705 2026] [security2:error] [pid 60716:tid 60821] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/aws/.env"] [unique_id "aqxgHMPsx0SVFjrd623xfAAAcjs"]
[Thu Sep 17 15:48:12.155727 2026] [security2:error] [pid 60716:tid 60815] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.aws/.env"] [unique_id "aqxgHMPsx0SVFjrd623xfQAAcjU"]
[Thu Sep 17 15:48:12.157173 2026] [security2:error] [pid 60716:tid 60936] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/live/.env"] [unique_id "aqxgHMPsx0SVFjrd623xfgAAACo"]
[Thu Sep 17 15:48:12.201998 2026] [security2:error] [pid 60716:tid 60826] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/v1/.env"] [unique_id "aqxgHMPsx0SVFjrd623xgwAAckA"]
[Thu Sep 17 15:48:12.202075 2026] [security2:error] [pid 60716:tid 60854] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/stripe/.env"] [unique_id "aqxgHMPsx0SVFjrd623xhAAAclw"]
[Thu Sep 17 15:48:12.203025 2026] [security2:error] [pid 60716:tid 60830] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/v2/.env"] [unique_id "aqxgHMPsx0SVFjrd623xhwAAckQ"]
[Thu Sep 17 15:48:12.238406 2026] [security2:error] [pid 60716:tid 60958] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/zend/.env"] [unique_id "aqxgHMPsx0SVFjrd623xjwAAAEA"]
[Thu Sep 17 15:48:12.276090 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623xEAAAcg8"]
[Thu Sep 17 15:48:12.291798 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623xEwAAcmw"]
[Thu Sep 17 15:48:12.294155 2026] [security2:error] [pid 60716:tid 60840] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/media/.env"] [unique_id "aqxgHMPsx0SVFjrd623xkgAAck4"]
[Thu Sep 17 15:48:12.295881 2026] [security2:error] [pid 60716:tid 60834] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/v3/.env"] [unique_id "aqxgHMPsx0SVFjrd623xkQAAckg"]
[Thu Sep 17 15:48:12.306831 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgGsPsx0SVFjrd623xCwAAchc"]
[Thu Sep 17 15:48:12.310121 2026] [security2:error] [pid 60716:tid 60931] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/prod/.env"] [unique_id "aqxgHMPsx0SVFjrd623xkwAAACU"]
[Thu Sep 17 15:48:12.329940 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgG8Psx0SVFjrd623xHgAAch8"]
[Thu Sep 17 15:48:12.334962 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgG8Psx0SVFjrd623xHQAAcko"]
[Thu Sep 17 15:48:12.376975 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgG8Psx0SVFjrd623xHAAAch4"]
[Thu Sep 17 15:48:12.381934 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgG8Psx0SVFjrd623xKQAAcjY"]
[Thu Sep 17 15:48:12.391979 2026] [security2:error] [pid 60716:tid 60964] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/yii/.env"] [unique_id "aqxgHMPsx0SVFjrd623xmQAAAEY"]
[Thu Sep 17 15:48:12.401360 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgG8Psx0SVFjrd623xKgAAcis"]
[Thu Sep 17 15:48:12.437311 2026] [security2:error] [pid 60716:tid 61018] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xkAAAAHw"]
[Thu Sep 17 15:48:12.456165 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xhQAAcn0"]
[Thu Sep 17 15:48:12.462789 2026] [security2:error] [pid 60716:tid 60917] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/dev/.env"] [unique_id "aqxgHMPsx0SVFjrd623xmgAAABk"]
[Thu Sep 17 15:48:12.464580 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xggAAcmE"]
[Thu Sep 17 15:48:12.471995 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgG8Psx0SVFjrd623xPAAAciA"]
[Thu Sep 17 15:48:12.517402 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xlgAAcnk"]
[Thu Sep 17 15:48:12.533043 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xlwAAchE"]
[Thu Sep 17 15:48:12.537379 2026] [security2:error] [pid 60716:tid 60973] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/laravel5/.env"] [unique_id "aqxgHMPsx0SVFjrd623xoAAAAE8"]
[Thu Sep 17 15:48:12.539089 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xlQAAciw"]
[Thu Sep 17 15:48:12.544978 2026] [security2:error] [pid 60716:tid 60828] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.git/config.bak"] [unique_id "aqxgHMPsx0SVFjrd623xpQAAckI"]
[Thu Sep 17 15:48:12.592179 2026] [security2:error] [pid 60716:tid 60906] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/logs/.env"] [unique_id "aqxgHMPsx0SVFjrd623xpwAAAA4"]
[Thu Sep 17 15:48:12.613983 2026] [security2:error] [pid 60716:tid 60980] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/staging/.env"] [unique_id "aqxgHMPsx0SVFjrd623xrAAAAFY"]
[Thu Sep 17 15:48:12.687746 2026] [security2:error] [pid 60716:tid 60899] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxgHMPsx0SVFjrd623xswAAAAc"]
[Thu Sep 17 15:48:12.743726 2026] [security2:error] [pid 60716:tid 60983] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/cache/.env"] [unique_id "aqxgHMPsx0SVFjrd623xtgAAAFk"]
[Thu Sep 17 15:48:12.768305 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/opt/.env"] [unique_id "aqxgHMPsx0SVFjrd623xuQAAADo"]
[Thu Sep 17 15:48:12.837153 2026] [security2:error] [pid 60716:tid 61001] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxgHMPsx0SVFjrd623xvAAAAGs"]
[Thu Sep 17 15:48:12.893494 2026] [security2:error] [pid 60716:tid 60938] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mailer/.env"] [unique_id "aqxgHMPsx0SVFjrd623xvgAAACw"]
[Thu Sep 17 15:48:12.920990 2026] [security2:error] [pid 60716:tid 60942] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/laravel/.env"] [unique_id "aqxgHMPsx0SVFjrd623xvwAAADA"]
[Thu Sep 17 15:48:12.992357 2026] [security2:error] [pid 60716:tid 61019] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxgHMPsx0SVFjrd623xwQAAAH0"]
[Thu Sep 17 15:48:13.045140 2026] [security2:error] [pid 60716:tid 60910] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mail/.env"] [unique_id "aqxgHcPsx0SVFjrd623xwgAAABI"]
[Thu Sep 17 15:48:13.077907 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/symfony/.env"] [unique_id "aqxgHcPsx0SVFjrd623xwwAAABg"]
[Thu Sep 17 15:48:13.090415 2026] [security2:error] [pid 60716:tid 60974] [client 122.8.45.84:35739] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgHcPsx0SVFjrd623xxQAAAFA"]
[Thu Sep 17 15:48:13.090527 2026] [security2:error] [pid 60716:tid 60974] [client 122.8.45.84:35739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgHcPsx0SVFjrd623xxQAAAFA"]
[Thu Sep 17 15:48:13.197853 2026] [security2:error] [pid 60716:tid 60955] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/api/v1/.env"] [unique_id "aqxgHcPsx0SVFjrd623xyAAAAD0"]
[Thu Sep 17 15:48:13.212212 2026] [security2:error] [pid 60716:tid 60978] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/email/.env"] [unique_id "aqxgHcPsx0SVFjrd623xyQAAAFQ"]
[Thu Sep 17 15:48:13.234858 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/wordpress/.env"] [unique_id "aqxgHcPsx0SVFjrd623xzwAAAEU"]
[Thu Sep 17 15:48:13.279597 2026] [security2:error] [pid 60716:tid 60986] [client 4.240.114.86:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "aqxgHcPsx0SVFjrd623x0gAAAFw"], referer: binance.com
[Thu Sep 17 15:48:13.359753 2026] [security2:error] [pid 60716:tid 60984] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/api/v2/.env"] [unique_id "aqxgHcPsx0SVFjrd623x1AAAAFo"]
[Thu Sep 17 15:48:13.365392 2026] [security2:error] [pid 60716:tid 60939] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/smtp/.env"] [unique_id "aqxgHcPsx0SVFjrd623x1QAAAC0"]
[Thu Sep 17 15:48:13.372541 2026] [security2:error] [pid 60716:tid 60997] [client 169.58.197.251:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxgHcPsx0SVFjrd623x1wAAAGc"], referer: binance.com
[Thu Sep 17 15:48:13.398159 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/wp/.env"] [unique_id "aqxgHcPsx0SVFjrd623x2AAAAGo"]
[Thu Sep 17 15:48:13.411397 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xnAAAcgQ"]
[Thu Sep 17 15:48:13.428537 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xngAAclc"]
[Thu Sep 17 15:48:13.430429 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xnQAAcjc"]
[Thu Sep 17 15:48:13.440602 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xowAAcgU"]
[Thu Sep 17 15:48:13.450061 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xmwAAclo"]
[Thu Sep 17 15:48:13.514575 2026] [security2:error] [pid 60716:tid 60976] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/rest/.env"] [unique_id "aqxgHcPsx0SVFjrd623x2wAAAFI"]
[Thu Sep 17 15:48:13.519059 2026] [security2:error] [pid 60716:tid 60919] [client 34.32.107.79:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mailing/.env"] [unique_id "aqxgHcPsx0SVFjrd623x3AAAABs"]
[Thu Sep 17 15:48:13.556033 2026] [security2:error] [pid 60716:tid 60864] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.aws/credentials.bak"] [unique_id "aqxgHcPsx0SVFjrd623x3wAAcmY"]
[Thu Sep 17 15:48:13.557467 2026] [security2:error] [pid 60716:tid 60987] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/cms/.env"] [unique_id "aqxgHcPsx0SVFjrd623x4AAAAF0"]
[Thu Sep 17 15:48:13.676879 2026] [security2:error] [pid 60716:tid 60902] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/graphql/.env"] [unique_id "aqxgHcPsx0SVFjrd623x5QAAAAo"]
[Thu Sep 17 15:48:13.692886 2026] [security2:error] [pid 60716:tid 60822] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.ssh/id_rsa"] [unique_id "aqxgHcPsx0SVFjrd623x6AAAcjw"]
[Thu Sep 17 15:48:13.722264 2026] [security2:error] [pid 60716:tid 60957] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/drupal/.env"] [unique_id "aqxgHcPsx0SVFjrd623x6wAAAD8"]
[Thu Sep 17 15:48:13.829054 2026] [security2:error] [pid 60716:tid 60774] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/id_rsa"] [unique_id "aqxgHcPsx0SVFjrd623x7wAAcg4"]
[Thu Sep 17 15:48:13.836934 2026] [security2:error] [pid 60716:tid 60948] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/gateway/.env"] [unique_id "aqxgHcPsx0SVFjrd623x8AAAADY"]
[Thu Sep 17 15:48:13.876974 2026] [security2:error] [pid 60716:tid 60898] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/joomla/.env"] [unique_id "aqxgHcPsx0SVFjrd623x8QAAAAY"]
[Thu Sep 17 15:48:13.972113 2026] [security2:error] [pid 60716:tid 60893] [client 67.205.2.98:53554] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1615"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "starstoreonline.com"] [uri "/"] [unique_id "aqxgHcPsx0SVFjrd623x8wAAAAE"]
[Thu Sep 17 15:48:13.987028 2026] [security2:error] [pid 60716:tid 60977] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/notifications/.env"] [unique_id "aqxgHcPsx0SVFjrd623x9AAAAFM"]
[Thu Sep 17 15:48:13.988836 2026] [security2:error] [pid 60716:tid 60973] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/microservice/.env"] [unique_id "aqxgHcPsx0SVFjrd623x9QAAAE8"]
[Thu Sep 17 15:48:14.034075 2026] [security2:error] [pid 60716:tid 60980] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/magento/.env"] [unique_id "aqxgHsPsx0SVFjrd623x9wAAAFY"]
[Thu Sep 17 15:48:14.058874 2026] [security2:error] [pid 60716:tid 60892] [client 122.8.45.84:47437] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgHsPsx0SVFjrd623x-QAAAAA"]
[Thu Sep 17 15:48:14.058997 2026] [security2:error] [pid 60716:tid 60892] [client 122.8.45.84:47437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgHsPsx0SVFjrd623x-QAAAAA"]
[Thu Sep 17 15:48:14.138078 2026] [security2:error] [pid 60716:tid 60968] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/notify/.env"] [unique_id "aqxgHsPsx0SVFjrd623x-gAAAEo"]
[Thu Sep 17 15:48:14.141030 2026] [security2:error] [pid 60716:tid 60904] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/service/.env"] [unique_id "aqxgHsPsx0SVFjrd623x-wAAAAw"]
[Thu Sep 17 15:48:14.162994 2026] [security2:error] [pid 60716:tid 60972] [client 67.205.2.98:53558] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1590"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "starstoreonline.com"] [uri "/wp-json/batch/v1"] [unique_id "aqxgHsPsx0SVFjrd623x_wAAAE4"]
[Thu Sep 17 15:48:14.192160 2026] [security2:error] [pid 60716:tid 60983] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/shopify/.env"] [unique_id "aqxgHsPsx0SVFjrd623yAAAAAFk"]
[Thu Sep 17 15:48:14.276595 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xpAAAcks"]
[Thu Sep 17 15:48:14.290042 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xogAAcho"]
[Thu Sep 17 15:48:14.303522 2026] [security2:error] [pid 60716:tid 61001] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/sender/.env"] [unique_id "aqxgHsPsx0SVFjrd623yCQAAAGs"]
[Thu Sep 17 15:48:14.306946 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xoQAAcgI"]
[Thu Sep 17 15:48:14.316227 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xnwAAcmA"]
[Thu Sep 17 15:48:14.320268 2026] [security2:error] [pid 60716:tid 60905] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/api/v3/.env"] [unique_id "aqxgHsPsx0SVFjrd623yCwAAAA0"]
[Thu Sep 17 15:48:14.335895 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xqwAAchw"]
[Thu Sep 17 15:48:14.341617 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xrQAAcmQ"]
[Thu Sep 17 15:48:14.352876 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xqAAAckE"]
[Thu Sep 17 15:48:14.355136 2026] [security2:error] [pid 60716:tid 61019] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/prestashop/.env"] [unique_id "aqxgHsPsx0SVFjrd623yDAAAAH0"]
[Thu Sep 17 15:48:14.373019 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xsQAAcgg"]
[Thu Sep 17 15:48:14.373401 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xpgAAcjE"]
[Thu Sep 17 15:48:14.379352 2026] [security2:error] [pid 60716:tid 60942] [client 67.205.2.98:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.205.67.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "starstoreonline.com"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yDQAAADA"]
[Thu Sep 17 15:48:14.385735 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xrwAAck0"]
[Thu Sep 17 15:48:14.401135 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHMPsx0SVFjrd623xrgAAcm0"]
[Thu Sep 17 15:48:14.446016 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHcPsx0SVFjrd623x3gAAcnQ"]
[Thu Sep 17 15:48:14.458306 2026] [security2:error] [pid 60716:tid 60947] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/campaign/.env"] [unique_id "aqxgHsPsx0SVFjrd623yEwAAADU"]
[Thu Sep 17 15:48:14.458777 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHcPsx0SVFjrd623x4gAAcjg"]
[Thu Sep 17 15:48:14.463406 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHcPsx0SVFjrd623x8gAAcmM"]
[Thu Sep 17 15:48:14.464600 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHcPsx0SVFjrd623x5AAAclE"]
[Thu Sep 17 15:48:14.465010 2026] [security2:error] [pid 60716:tid 61008] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHcPsx0SVFjrd623x4QAAcnc"]
[Thu Sep 17 15:48:14.474672 2026] [security2:error] [pid 60716:tid 60993] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/api/dev/.env"] [unique_id "aqxgHsPsx0SVFjrd623yFQAAAGM"]
[Thu Sep 17 15:48:14.515953 2026] [security2:error] [pid 60716:tid 61013] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/codeigniter/.env"] [unique_id "aqxgHsPsx0SVFjrd623yGAAAAHc"]
[Thu Sep 17 15:48:14.565543 2026] [security2:error] [pid 60716:tid 60900] [client 67.205.2.98:53582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.205.67.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "starstoreonline.com"] [uri "/index.php/wp-json/batch/v1"] [unique_id "aqxgHsPsx0SVFjrd623yIQAAAAg"]
[Thu Sep 17 15:48:14.614906 2026] [security2:error] [pid 60716:tid 60937] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/newsletter/.env"] [unique_id "aqxgHsPsx0SVFjrd623yKgAAACs"]
[Thu Sep 17 15:48:14.628640 2026] [security2:error] [pid 60716:tid 60986] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/api/staging/.env"] [unique_id "aqxgHsPsx0SVFjrd623yKwAAAFw"]
[Thu Sep 17 15:48:14.681758 2026] [security2:error] [pid 60716:tid 60928] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/cakephp/.env"] [unique_id "aqxgHsPsx0SVFjrd623yLgAAACM"]
[Thu Sep 17 15:48:14.775859 2026] [security2:error] [pid 60716:tid 61014] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/ses/.env"] [unique_id "aqxgHsPsx0SVFjrd623yOwAAAHg"]
[Thu Sep 17 15:48:14.798746 2026] [security2:error] [pid 60716:tid 60911] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/vendor/.env"] [unique_id "aqxgHsPsx0SVFjrd623yPAAAABM"]
[Thu Sep 17 15:48:14.817656 2026] [security2:error] [pid 60716:tid 60797] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/config.php"] [unique_id "aqxgHsPsx0SVFjrd623yPwAATCM"]
[Thu Sep 17 15:48:14.842324 2026] [security2:error] [pid 60716:tid 61000] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/zend/.env"] [unique_id "aqxgHsPsx0SVFjrd623yQQAAAGo"]
[Thu Sep 17 15:48:14.931689 2026] [security2:error] [pid 60716:tid 60976] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/sendgrid/.env"] [unique_id "aqxgHsPsx0SVFjrd623yQwAAAFI"]
[Thu Sep 17 15:48:14.962503 2026] [security2:error] [pid 60716:tid 60992] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/lib/.env"] [unique_id "aqxgHsPsx0SVFjrd623yRgAAAGI"]
[Thu Sep 17 15:48:15.001208 2026] [security2:error] [pid 60716:tid 61011] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/yii/.env"] [unique_id "aqxgHsPsx0SVFjrd623yRwAAAHU"]
[Thu Sep 17 15:48:15.086435 2026] [security2:error] [pid 60716:tid 60954] [client 122.8.45.84:63067] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgH8Psx0SVFjrd623ySgAAADw"]
[Thu Sep 17 15:48:15.086580 2026] [security2:error] [pid 60716:tid 60954] [client 122.8.45.84:63067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgH8Psx0SVFjrd623ySgAAADw"]
[Thu Sep 17 15:48:15.089853 2026] [security2:error] [pid 60716:tid 60934] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/sparkpost/.env"] [unique_id "aqxgH8Psx0SVFjrd623ySwAAACg"]
[Thu Sep 17 15:48:15.125517 2026] [security2:error] [pid 60716:tid 60958] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/resources/.env"] [unique_id "aqxgH8Psx0SVFjrd623yTAAAAEA"]
[Thu Sep 17 15:48:15.160325 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/laravel5/.env"] [unique_id "aqxgH8Psx0SVFjrd623yTgAAAA8"]
[Thu Sep 17 15:48:15.244503 2026] [security2:error] [pid 60716:tid 60931] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/postmark/.env"] [unique_id "aqxgH8Psx0SVFjrd623yUwAAACU"]
[Thu Sep 17 15:48:15.278876 2026] [security2:error] [pid 60716:tid 60995] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/assets/.env"] [unique_id "aqxgH8Psx0SVFjrd623yVQAAAGU"]
[Thu Sep 17 15:48:15.283427 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yFAAATDA"]
[Thu Sep 17 15:48:15.326742 2026] [security2:error] [pid 60716:tid 61016] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/v1/.env"] [unique_id "aqxgH8Psx0SVFjrd623yWgAAAHo"]
[Thu Sep 17 15:48:15.403904 2026] [security2:error] [pid 60716:tid 60925] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mailgun/.env"] [unique_id "aqxgH8Psx0SVFjrd623yWwAAACA"]
[Thu Sep 17 15:48:15.423596 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yJAAATH4"]
[Thu Sep 17 15:48:15.431701 2026] [security2:error] [pid 60716:tid 60964] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/uploads/.env"] [unique_id "aqxgH8Psx0SVFjrd623yXQAAAEY"]
[Thu Sep 17 15:48:15.489147 2026] [security2:error] [pid 60716:tid 60948] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/v2/.env"] [unique_id "aqxgH8Psx0SVFjrd623yXgAAADY"]
[Thu Sep 17 15:48:15.558953 2026] [security2:error] [pid 60716:tid 60897] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mandrill/.env"] [unique_id "aqxgH8Psx0SVFjrd623yYAAAAAU"]
[Thu Sep 17 15:48:15.587696 2026] [security2:error] [pid 60716:tid 60893] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/internal/.env"] [unique_id "aqxgH8Psx0SVFjrd623yYgAAAAE"]
[Thu Sep 17 15:48:15.596910 2026] [security2:error] [pid 60716:tid 60977] [client 4.240.114.86:60052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "aqxgH8Psx0SVFjrd623yYwAAAFM"], referer: binance.com
[Thu Sep 17 15:48:15.649450 2026] [security2:error] [pid 60716:tid 60935] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/v3/.env"] [unique_id "aqxgH8Psx0SVFjrd623yZAAAACk"]
[Thu Sep 17 15:48:15.716240 2026] [security2:error] [pid 60716:tid 60941] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mailjet/.env"] [unique_id "aqxgH8Psx0SVFjrd623yagAAAC8"]
[Thu Sep 17 15:48:15.741721 2026] [security2:error] [pid 60716:tid 60933] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/tools/.env"] [unique_id "aqxgH8Psx0SVFjrd623ybQAAACc"]
[Thu Sep 17 15:48:15.805722 2026] [security2:error] [pid 60716:tid 61005] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/api/v1/.env"] [unique_id "aqxgH8Psx0SVFjrd623ycgAAAG8"]
[Thu Sep 17 15:48:15.874581 2026] [security2:error] [pid 60716:tid 61001] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/brevo/.env"] [unique_id "aqxgH8Psx0SVFjrd623ycwAAAGs"]
[Thu Sep 17 15:48:15.904786 2026] [security2:error] [pid 60716:tid 60938] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/scripts/.env"] [unique_id "aqxgH8Psx0SVFjrd623ydAAAACw"]
[Thu Sep 17 15:48:15.972336 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/api/v2/.env"] [unique_id "aqxgH8Psx0SVFjrd623ydQAAAFg"]
[Thu Sep 17 15:48:16.036061 2026] [security2:error] [pid 60716:tid 60999] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/transactional/.env"] [unique_id "aqxgIMPsx0SVFjrd623ydgAAAGk"]
[Thu Sep 17 15:48:16.057170 2026] [security2:error] [pid 60716:tid 60910] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/bin/.env"] [unique_id "aqxgIMPsx0SVFjrd623yeAAAABI"]
[Thu Sep 17 15:48:16.064656 2026] [security2:error] [pid 60716:tid 60973] [client 122.8.45.84:60675] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgIMPsx0SVFjrd623yeQAAAE8"]
[Thu Sep 17 15:48:16.064793 2026] [security2:error] [pid 60716:tid 60973] [client 122.8.45.84:60675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgIMPsx0SVFjrd623yeQAAAE8"]
[Thu Sep 17 15:48:16.132078 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/rest/.env"] [unique_id "aqxgIMPsx0SVFjrd623yegAAABg"]
[Thu Sep 17 15:48:16.195264 2026] [security2:error] [pid 60716:tid 60929] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/bulk/.env"] [unique_id "aqxgIMPsx0SVFjrd623yfAAAACQ"]
[Thu Sep 17 15:48:16.213836 2026] [security2:error] [pid 60716:tid 60952] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/sbin/.env"] [unique_id "aqxgIMPsx0SVFjrd623yfQAAADo"]
[Thu Sep 17 15:48:16.257330 2026] [security2:error] [pid 60716:tid 60890] [remote 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yHgAATH8"]
[Thu Sep 17 15:48:16.274135 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yJQAATD8"]
[Thu Sep 17 15:48:16.275162 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yIwAATDI"]
[Thu Sep 17 15:48:16.277875 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yGgAATGI"]
[Thu Sep 17 15:48:16.279528 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yHwAATCI"]
[Thu Sep 17 15:48:16.279766 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yJwAATFU"]
[Thu Sep 17 15:48:16.281896 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yKAAATEc"]
[Thu Sep 17 15:48:16.298486 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yKQAATDM"]
[Thu Sep 17 15:48:16.301598 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yRAAATF8"]
[Thu Sep 17 15:48:16.303219 2026] [security2:error] [pid 60716:tid 60979] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/graphql/.env"] [unique_id "aqxgIMPsx0SVFjrd623yhQAAAFU"]
[Thu Sep 17 15:48:16.305031 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yNAAATC8"]
[Thu Sep 17 15:48:16.322940 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yRQAATGo"]
[Thu Sep 17 15:48:16.330437 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgH8Psx0SVFjrd623yTQAATGs"]
[Thu Sep 17 15:48:16.348710 2026] [security2:error] [pid 60716:tid 60974] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/aws/.env"] [unique_id "aqxgIMPsx0SVFjrd623yhwAAAFA"]
[Thu Sep 17 15:48:16.358158 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yMgAATFY"]
[Thu Sep 17 15:48:16.358277 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgHsPsx0SVFjrd623yLwAATD0"]
[Thu Sep 17 15:48:16.362278 2026] [security2:error] [pid 60716:tid 60975] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/local/.env"] [unique_id "aqxgIMPsx0SVFjrd623yiAAAAFE"]
[Thu Sep 17 15:48:16.412300 2026] [security2:error] [pid 60716:tid 60808] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/config/aws.php"] [unique_id "aqxgIMPsx0SVFjrd623yjQAATC4"]
[Thu Sep 17 15:48:16.431921 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgH8Psx0SVFjrd623yggAATH8"]
[Thu Sep 17 15:48:16.432195 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgH8Psx0SVFjrd623yXAAATBI"]
[Thu Sep 17 15:48:16.432314 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgH8Psx0SVFjrd623yYQAATBQ"]
[Thu Sep 17 15:48:16.462700 2026] [security2:error] [pid 60716:tid 60937] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/gateway/.env"] [unique_id "aqxgIMPsx0SVFjrd623yjwAAACs"]
[Thu Sep 17 15:48:16.500155 2026] [security2:error] [pid 60716:tid 60894] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/azure/.env"] [unique_id "aqxgIMPsx0SVFjrd623ykQAAAAI"]
[Thu Sep 17 15:48:16.513105 2026] [security2:error] [pid 60716:tid 60986] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/portal/.env"] [unique_id "aqxgIMPsx0SVFjrd623ykgAAAFw"]
[Thu Sep 17 15:48:16.541012 2026] [security2:error] [pid 60716:tid 60795] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/config/config.inc.php"] [unique_id "aqxgIMPsx0SVFjrd623ymAAATCE"]
[Thu Sep 17 15:48:16.541045 2026] [security2:error] [pid 60716:tid 60850] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/config/mail.php"] [unique_id "aqxgIMPsx0SVFjrd623ylwAATFg"]
[Thu Sep 17 15:48:16.541067 2026] [security2:error] [pid 60716:tid 60786] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/config/stripe.php"] [unique_id "aqxgIMPsx0SVFjrd623ylgAATBg"]
[Thu Sep 17 15:48:16.569612 2026] [security2:error] [pid 60716:tid 60770] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/config/nexmo.php"] [unique_id "aqxgIMPsx0SVFjrd623ymwAATAs"]
[Thu Sep 17 15:48:16.576241 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623yiQAATGc"]
[Thu Sep 17 15:48:16.583745 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623yigAATC0"]
[Thu Sep 17 15:48:16.584579 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623yjAAATG8"]
[Thu Sep 17 15:48:16.593170 2026] [security2:error] [pid 60716:tid 60787] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/wp-config.php"] [unique_id "aqxgIMPsx0SVFjrd623ynQAATBk"]
[Thu Sep 17 15:48:16.612770 2026] [security2:error] [pid 60716:tid 60821] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "zainridgecondo.org"] [uri "/wp-config.php.old"] [unique_id "aqxgIMPsx0SVFjrd623yngAATDs"]
[Thu Sep 17 15:48:16.612770 2026] [security2:error] [pid 60716:tid 60814] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "zainridgecondo.org"] [uri "/wp-config.php.bak"] [unique_id "aqxgIMPsx0SVFjrd623yoAAATDQ"]
[Thu Sep 17 15:48:16.612776 2026] [security2:error] [pid 60716:tid 60815] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "zainridgecondo.org"] [uri "/wp-config.php.new"] [unique_id "aqxgIMPsx0SVFjrd623ynwAATDU"]
[Thu Sep 17 15:48:16.624543 2026] [security2:error] [pid 60716:tid 60963] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/microservice/.env"] [unique_id "aqxgIMPsx0SVFjrd623yoQAAAEU"]
[Thu Sep 17 15:48:16.655908 2026] [security2:error] [pid 60716:tid 60991] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/gcp/.env"] [unique_id "aqxgIMPsx0SVFjrd623yogAAAGE"]
[Thu Sep 17 15:48:16.666228 2026] [security2:error] [pid 60716:tid 61014] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/dashboard/.env"] [unique_id "aqxgIMPsx0SVFjrd623yowAAAHg"]
[Thu Sep 17 15:48:16.675961 2026] [security2:error] [pid 60716:tid 60826] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/.wp-config.php.swp"] [unique_id "aqxgIMPsx0SVFjrd623ypQAATEA"]
[Thu Sep 17 15:48:16.680367 2026] [security2:error] [pid 60716:tid 60769] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/wp-content/mysql.sql"] [unique_id "aqxgIMPsx0SVFjrd623ypwAATAo"]
[Thu Sep 17 15:48:16.748505 2026] [security2:error] [pid 60716:tid 60816] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/terraform.tfstate.backup"] [unique_id "aqxgIMPsx0SVFjrd623yswAATDY"]
[Thu Sep 17 15:48:16.783851 2026] [security2:error] [pid 60716:tid 60901] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/service/.env"] [unique_id "aqxgIMPsx0SVFjrd623ytwAAAAk"]
[Thu Sep 17 15:48:16.812970 2026] [security2:error] [pid 60716:tid 60992] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/cloud/.env"] [unique_id "aqxgIMPsx0SVFjrd623yuwAAAGI"]
[Thu Sep 17 15:48:16.818042 2026] [security2:error] [pid 60716:tid 60987] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/panel/.env"] [unique_id "aqxgIMPsx0SVFjrd623yvQAAAF0"]
[Thu Sep 17 15:48:16.874220 2026] [security2:error] [pid 60716:tid 60939] [client 200.55.245.150:55410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ysQAALUo"]
[Thu Sep 17 15:48:16.938782 2026] [security2:error] [pid 60716:tid 60934] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/api/v3/.env"] [unique_id "aqxgIMPsx0SVFjrd623yxQAAACg"]
[Thu Sep 17 15:48:16.963582 2026] [security2:error] [pid 60716:tid 60949] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/infrastructure/.env"] [unique_id "aqxgIMPsx0SVFjrd623yxwAAADc"]
[Thu Sep 17 15:48:16.970487 2026] [security2:error] [pid 60716:tid 60958] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/crm/.env"] [unique_id "aqxgIMPsx0SVFjrd623yyAAAAEA"]
[Thu Sep 17 15:48:17.086635 2026] [security2:error] [pid 60716:tid 60928] [client 122.8.45.84:26489] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgIcPsx0SVFjrd623yzAAAACM"]
[Thu Sep 17 15:48:17.086839 2026] [security2:error] [pid 60716:tid 60928] [client 122.8.45.84:26489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgIcPsx0SVFjrd623yzAAAACM"]
[Thu Sep 17 15:48:17.108494 2026] [security2:error] [pid 60716:tid 60907] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/api/dev/.env"] [unique_id "aqxgIcPsx0SVFjrd623yzgAAAA8"]
[Thu Sep 17 15:48:17.119597 2026] [security2:error] [pid 60716:tid 60957] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/erp/.env"] [unique_id "aqxgIcPsx0SVFjrd623yzwAAAD8"]
[Thu Sep 17 15:48:17.125988 2026] [security2:error] [pid 60716:tid 60931] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/docker/.env"] [unique_id "aqxgIcPsx0SVFjrd623y0AAAACU"]
[Thu Sep 17 15:48:17.267281 2026] [security2:error] [pid 60716:tid 60908] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxgIcPsx0SVFjrd623y2gAAABA"]
[Thu Sep 17 15:48:17.268216 2026] [security2:error] [pid 60716:tid 60924] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/api/staging/.env"] [unique_id "aqxgIcPsx0SVFjrd623y2wAAAB8"]
[Thu Sep 17 15:48:17.276511 2026] [security2:error] [pid 60716:tid 60914] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/k8s/.env"] [unique_id "aqxgIcPsx0SVFjrd623y3AAAABY"]
[Thu Sep 17 15:48:17.291597 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ylQAATBU"]
[Thu Sep 17 15:48:17.304575 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ymQAATEY"]
[Thu Sep 17 15:48:17.336544 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ymgAATGk"]
[Thu Sep 17 15:48:17.361071 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ynAAATFM"]
[Thu Sep 17 15:48:17.415439 2026] [security2:error] [pid 60716:tid 60898] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/store/.env"] [unique_id "aqxgIcPsx0SVFjrd623y4AAAAAY"]
[Thu Sep 17 15:48:17.425141 2026] [security2:error] [pid 60716:tid 60956] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/vendor/.env"] [unique_id "aqxgIcPsx0SVFjrd623y4QAAAD4"]
[Thu Sep 17 15:48:17.433617 2026] [security2:error] [pid 60716:tid 60897] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/kubernetes/.env"] [unique_id "aqxgIcPsx0SVFjrd623y4wAAAAU"]
[Thu Sep 17 15:48:17.458069 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ypgAATEQ"]
[Thu Sep 17 15:48:17.568240 2026] [security2:error] [pid 60716:tid 60933] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/saas/.env"] [unique_id "aqxgIcPsx0SVFjrd623y6QAAACc"]
[Thu Sep 17 15:48:17.585140 2026] [security2:error] [pid 60716:tid 60953] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/lib/.env"] [unique_id "aqxgIcPsx0SVFjrd623y6gAAADs"]
[Thu Sep 17 15:48:17.585206 2026] [security2:error] [pid 60716:tid 60981] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/terraform/.env"] [unique_id "aqxgIcPsx0SVFjrd623y6wAAAFc"]
[Thu Sep 17 15:48:17.714766 2026] [security2:error] [pid 60716:tid 60913] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxgIcPsx0SVFjrd623y8gAAABU"]
[Thu Sep 17 15:48:17.733675 2026] [security2:error] [pid 60716:tid 60918] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/ansible/.env"] [unique_id "aqxgIcPsx0SVFjrd623y9gAAABo"]
[Thu Sep 17 15:48:17.758131 2026] [security2:error] [pid 60716:tid 60982] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/resources/.env"] [unique_id "aqxgIcPsx0SVFjrd623y-QAAAFg"]
[Thu Sep 17 15:48:17.863225 2026] [security2:error] [pid 60716:tid 60940] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/project/.env"] [unique_id "aqxgIcPsx0SVFjrd623y_AAAAC4"]
[Thu Sep 17 15:48:17.883599 2026] [security2:error] [pid 60716:tid 60999] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/.git/.env"] [unique_id "aqxgIcPsx0SVFjrd623y_QAAAGk"]
[Thu Sep 17 15:48:17.909846 2026] [security2:error] [pid 60716:tid 60910] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/assets/.env"] [unique_id "aqxgIcPsx0SVFjrd623zAAAAABI"]
[Thu Sep 17 15:48:18.012512 2026] [security2:error] [pid 60716:tid 60916] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/admin-panel/.env"] [unique_id "aqxgIsPsx0SVFjrd623zAwAAABg"]
[Thu Sep 17 15:48:18.038869 2026] [security2:error] [pid 60716:tid 60971] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/ci/.env"] [unique_id "aqxgIsPsx0SVFjrd623zBAAAAE0"]
[Thu Sep 17 15:48:18.058226 2026] [security2:error] [pid 60716:tid 60983] [client 122.8.45.84:27183] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgIsPsx0SVFjrd623zBgAAAFk"]
[Thu Sep 17 15:48:18.058340 2026] [security2:error] [pid 60716:tid 60983] [client 122.8.45.84:27183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgIsPsx0SVFjrd623zBgAAAFk"]
[Thu Sep 17 15:48:18.067323 2026] [security2:error] [pid 60716:tid 60952] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/uploads/.env"] [unique_id "aqxgIsPsx0SVFjrd623zCAAAADo"]
[Thu Sep 17 15:48:18.159967 2026] [security2:error] [pid 60716:tid 60947] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/control-panel/.env"] [unique_id "aqxgIsPsx0SVFjrd623zCgAAADU"]
[Thu Sep 17 15:48:18.198590 2026] [security2:error] [pid 60716:tid 61007] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/cd/.env"] [unique_id "aqxgIsPsx0SVFjrd623zDgAAAHE"]
[Thu Sep 17 15:48:18.225778 2026] [security2:error] [pid 60716:tid 60955] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/internal/.env"] [unique_id "aqxgIsPsx0SVFjrd623zEQAAAD0"]
[Thu Sep 17 15:48:18.260993 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ypAAATFw"]
[Thu Sep 17 15:48:18.278805 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ywgAATBE"]
[Thu Sep 17 15:48:18.280003 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIcPsx0SVFjrd623yywAATHU"]
[Thu Sep 17 15:48:18.280307 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623yyQAATBM"]
[Thu Sep 17 15:48:18.302818 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623yvgAATCk"]
[Thu Sep 17 15:48:18.307027 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ywwAATCw"]
[Thu Sep 17 15:48:18.317673 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ywAAATCA"]
[Thu Sep 17 15:48:18.319160 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ywQAATHk"]
[Thu Sep 17 15:48:18.322530 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIcPsx0SVFjrd623yzQAATEM"]
[Thu Sep 17 15:48:18.322677 2026] [security2:error] [pid 60716:tid 61009] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/user-panel/.env"] [unique_id "aqxgIsPsx0SVFjrd623zGAAAAHM"]
[Thu Sep 17 15:48:18.333961 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ytAAATB4"]
[Thu Sep 17 15:48:18.341032 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIMPsx0SVFjrd623ytQAATCs"]
[Thu Sep 17 15:48:18.386227 2026] [security2:error] [pid 60716:tid 61012] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/jenkins/.env"] [unique_id "aqxgIsPsx0SVFjrd623zGQAAAHY"]
[Thu Sep 17 15:48:18.393862 2026] [security2:error] [pid 60716:tid 60967] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/tools/.env"] [unique_id "aqxgIsPsx0SVFjrd623zGgAAAEk"]
[Thu Sep 17 15:48:18.428435 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIcPsx0SVFjrd623y7QAATGY"]
[Thu Sep 17 15:48:18.431189 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zDQAATGA"]
[Thu Sep 17 15:48:18.436614 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIcPsx0SVFjrd623y5AAATAQ"]
[Thu Sep 17 15:48:18.437272 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIcPsx0SVFjrd623y6AAATAU"]
[Thu Sep 17 15:48:18.439827 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIcPsx0SVFjrd623y5QAATFc"]
[Thu Sep 17 15:48:18.448447 2026] [security2:error] [pid 60716:tid 61017] [client 4.240.114.86:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "aqxgIsPsx0SVFjrd623zIgAAAHs"], referer: binance.com
[Thu Sep 17 15:48:18.471927 2026] [security2:error] [pid 60716:tid 61002] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/node/.env"] [unique_id "aqxgIsPsx0SVFjrd623zKAAAAGw"]
[Thu Sep 17 15:48:18.545128 2026] [security2:error] [pid 60716:tid 61020] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/gitlab/.env"] [unique_id "aqxgIsPsx0SVFjrd623zLgAAAH4"]
[Thu Sep 17 15:48:18.553239 2026] [security2:error] [pid 60716:tid 60926] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/scripts/.env"] [unique_id "aqxgIsPsx0SVFjrd623zMQAAACE"]
[Thu Sep 17 15:48:18.620215 2026] [security2:error] [pid 60716:tid 60911] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/express/.env"] [unique_id "aqxgIsPsx0SVFjrd623zOAAAABM"]
[Thu Sep 17 15:48:18.696174 2026] [security2:error] [pid 60716:tid 60915] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/github/.env"] [unique_id "aqxgIsPsx0SVFjrd623zOgAAABc"]
[Thu Sep 17 15:48:18.705143 2026] [security2:error] [pid 60716:tid 60951] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/bin/.env"] [unique_id "aqxgIsPsx0SVFjrd623zPAAAADk"]
[Thu Sep 17 15:48:18.772250 2026] [security2:error] [pid 60716:tid 61004] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/next/.env"] [unique_id "aqxgIsPsx0SVFjrd623zQgAAAG4"]
[Thu Sep 17 15:48:18.847458 2026] [security2:error] [pid 60716:tid 61003] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/actions/.env"] [unique_id "aqxgIsPsx0SVFjrd623zRQAAAG0"]
[Thu Sep 17 15:48:18.858593 2026] [security2:error] [pid 60716:tid 60964] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/sbin/.env"] [unique_id "aqxgIsPsx0SVFjrd623zRgAAAEY"]
[Thu Sep 17 15:48:18.920489 2026] [security2:error] [pid 60716:tid 60914] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/nuxt/.env"] [unique_id "aqxgIsPsx0SVFjrd623zSgAAABY"]
[Thu Sep 17 15:48:19.001158 2026] [security2:error] [pid 60716:tid 60920] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/circleci/.env"] [unique_id "aqxgIsPsx0SVFjrd623zSwAAABw"]
[Thu Sep 17 15:48:19.011060 2026] [security2:error] [pid 60716:tid 60902] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/local/.env"] [unique_id "aqxgI8Psx0SVFjrd623zTAAAAAo"]
[Thu Sep 17 15:48:19.035714 2026] [security2:error] [pid 60716:tid 60984] [client 122.8.45.84:20709] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zTwAAAFo"]
[Thu Sep 17 15:48:19.035852 2026] [security2:error] [pid 60716:tid 60984] [client 122.8.45.84:20709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zTwAAAFo"]
[Thu Sep 17 15:48:19.066229 2026] [security2:error] [pid 60716:tid 60962] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/nest/.env"] [unique_id "aqxgI8Psx0SVFjrd623zUAAAAEQ"]
[Thu Sep 17 15:48:19.152360 2026] [security2:error] [pid 60716:tid 60897] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/travis/.env"] [unique_id "aqxgI8Psx0SVFjrd623zUQAAAAU"]
[Thu Sep 17 15:48:19.165131 2026] [security2:error] [pid 60716:tid 60919] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/portal/.env"] [unique_id "aqxgI8Psx0SVFjrd623zVAAAABs"]
[Thu Sep 17 15:48:19.214207 2026] [security2:error] [pid 60716:tid 60933] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/react/.env"] [unique_id "aqxgI8Psx0SVFjrd623zVgAAACc"]
[Thu Sep 17 15:48:19.228632 2026] [security2:error] [pid 60716:tid 60841] [remote 216.73.217.142:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxgI8Psx0SVFjrd623zVwAADE8"]
[Thu Sep 17 15:48:19.298643 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zHgAATDE"]
[Thu Sep 17 15:48:19.305071 2026] [security2:error] [pid 60716:tid 60959] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/buildkite/.env"] [unique_id "aqxgI8Psx0SVFjrd623zXAAAAEE"]
[Thu Sep 17 15:48:19.327409 2026] [security2:error] [pid 60716:tid 60972] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/dashboard/.env"] [unique_id "aqxgI8Psx0SVFjrd623zXQAAAE4"]
[Thu Sep 17 15:48:19.340480 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zJgAATG4"]
[Thu Sep 17 15:48:19.354876 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zJQAATHg"]
[Thu Sep 17 15:48:19.355182 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zIwAATG0"]
[Thu Sep 17 15:48:19.366163 2026] [security2:error] [pid 60716:tid 60903] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/vue/.env"] [unique_id "aqxgI8Psx0SVFjrd623zXgAAAAs"]
[Thu Sep 17 15:48:19.382196 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zJAAATAc"]
[Thu Sep 17 15:48:19.393329 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zJwAATHQ"]
[Thu Sep 17 15:48:19.402576 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zKQAATCU"]
[Thu Sep 17 15:48:19.454751 2026] [security2:error] [pid 60716:tid 60909] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mysql/.env"] [unique_id "aqxgI8Psx0SVFjrd623zYQAAABE"]
[Thu Sep 17 15:48:19.454838 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zLQAATDg"]
[Thu Sep 17 15:48:19.481864 2026] [security2:error] [pid 60716:tid 60810] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/phpinfo.php"] [unique_id "aqxgI8Psx0SVFjrd623zYwAATDA"]
[Thu Sep 17 15:48:19.482750 2026] [security2:error] [pid 60716:tid 61015] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/panel/.env"] [unique_id "aqxgI8Psx0SVFjrd623zZAAAAHk"]
[Thu Sep 17 15:48:19.512772 2026] [security2:error] [pid 60716:tid 60831] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/info.php"] [unique_id "aqxgI8Psx0SVFjrd623zZwAATEU"]
[Thu Sep 17 15:48:19.513728 2026] [security2:error] [pid 60716:tid 60980] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/angular/.env"] [unique_id "aqxgI8Psx0SVFjrd623zaAAAAFY"]
[Thu Sep 17 15:48:19.527162 2026] [security2:error] [pid 60716:tid 60877] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/infos.php"] [unique_id "aqxgI8Psx0SVFjrd623zaQAATHM"]
[Thu Sep 17 15:48:19.564405 2026] [security2:error] [pid 60716:tid 60835] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/php_info.php"] [unique_id "aqxgI8Psx0SVFjrd623zagAATEk"]
[Thu Sep 17 15:48:19.586738 2026] [security2:error] [pid 60716:tid 60853] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/php.php"] [unique_id "aqxgI8Psx0SVFjrd623zawAATFs"]
[Thu Sep 17 15:48:19.603386 2026] [security2:error] [pid 60716:tid 61019] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/postgres/.env"] [unique_id "aqxgI8Psx0SVFjrd623zbAAAAH0"]
[Thu Sep 17 15:48:19.608763 2026] [security2:error] [pid 60716:tid 60761] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/php-info.php"] [unique_id "aqxgI8Psx0SVFjrd623zbQAATAM"]
[Thu Sep 17 15:48:19.616512 2026] [security2:error] [pid 60716:tid 60825] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/infophp.php"] [unique_id "aqxgI8Psx0SVFjrd623zbgAATD8"]
[Thu Sep 17 15:48:19.635247 2026] [security2:error] [pid 60716:tid 60916] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/crm/.env"] [unique_id "aqxgI8Psx0SVFjrd623zcAAAABg"]
[Thu Sep 17 15:48:19.658486 2026] [security2:error] [pid 60716:tid 60971] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/svelte/.env"] [unique_id "aqxgI8Psx0SVFjrd623zcgAAAE0"]
[Thu Sep 17 15:48:19.661449 2026] [security2:error] [pid 60716:tid 60860] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxgI8Psx0SVFjrd623zcwAATGI"]
[Thu Sep 17 15:48:19.698813 2026] [security2:error] [pid 60716:tid 60796] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/admin/phpinfo.php"] [unique_id "aqxgI8Psx0SVFjrd623zdAAATCI"]
[Thu Sep 17 15:48:19.721008 2026] [security2:error] [pid 60716:tid 60833] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/admin_phpinfo.php"] [unique_id "aqxgI8Psx0SVFjrd623zdgAATEc"]
[Thu Sep 17 15:48:19.742782 2026] [security2:error] [pid 60716:tid 60857] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/api/phpinfo.php"] [unique_id "aqxgI8Psx0SVFjrd623zeQAATF8"]
[Thu Sep 17 15:48:19.751049 2026] [security2:error] [pid 60716:tid 60868] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/public/phpinfo.php"] [unique_id "aqxgI8Psx0SVFjrd623zfAAATGo"]
[Thu Sep 17 15:48:19.751732 2026] [security2:error] [pid 60716:tid 60944] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/mongodb/.env"] [unique_id "aqxgI8Psx0SVFjrd623zewAAADI"]
[Thu Sep 17 15:48:19.786492 2026] [security2:error] [pid 60716:tid 60974] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/erp/.env"] [unique_id "aqxgI8Psx0SVFjrd623zgAAAAFA"]
[Thu Sep 17 15:48:19.802926 2026] [security2:error] [pid 60716:tid 60978] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/vite/.env"] [unique_id "aqxgI8Psx0SVFjrd623zgwAAAFQ"]
[Thu Sep 17 15:48:19.825148 2026] [security2:error] [pid 60716:tid 60940] [client 14.96.156.146:54675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zhAAAAC4"]
[Thu Sep 17 15:48:19.825246 2026] [security2:error] [pid 60716:tid 60940] [client 14.96.156.146:54675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zhAAAAC4"]
[Thu Sep 17 15:48:19.902764 2026] [security2:error] [pid 60716:tid 61021] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/redis/.env"] [unique_id "aqxgI8Psx0SVFjrd623zigAAAH8"]
[Thu Sep 17 15:48:19.939548 2026] [security2:error] [pid 60716:tid 60950] [client 143.105.152.240:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zjAAAADg"]
[Thu Sep 17 15:48:19.940461 2026] [security2:error] [pid 60716:tid 60991] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/shop/.env"] [unique_id "aqxgI8Psx0SVFjrd623ziwAAAGE"]
[Thu Sep 17 15:48:19.949431 2026] [security2:error] [pid 60716:tid 60950] [client 143.105.152.240:2009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zjAAAADg"]
[Thu Sep 17 15:48:19.951732 2026] [security2:error] [pid 60716:tid 60942] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxgI8Psx0SVFjrd623zjQAAADA"]
[Thu Sep 17 15:48:19.993248 2026] [security2:error] [pid 60716:tid 60999] [client 122.8.45.84:33813] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zjgAAAGk"]
[Thu Sep 17 15:48:19.993359 2026] [security2:error] [pid 60716:tid 60999] [client 122.8.45.84:33813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgI8Psx0SVFjrd623zjgAAAGk"]
[Thu Sep 17 15:48:20.054159 2026] [security2:error] [pid 60716:tid 60968] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/elasticsearch/.env"] [unique_id "aqxgJMPsx0SVFjrd623zkwAAAEo"]
[Thu Sep 17 15:48:20.058948 2026] [security2:error] [pid 60716:tid 61009] [client 148.227.75.216:57059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJMPsx0SVFjrd623zlAAAAHM"]
[Thu Sep 17 15:48:20.068877 2026] [security2:error] [pid 60716:tid 61009] [client 148.227.75.216:57059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJMPsx0SVFjrd623zlAAAAHM"]
[Thu Sep 17 15:48:20.104797 2026] [security2:error] [pid 60716:tid 60961] [client 34.154.246.111:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/store/.env"] [unique_id "aqxgJMPsx0SVFjrd623zlgAAAEM"]
[Thu Sep 17 15:48:20.105354 2026] [security2:error] [pid 60716:tid 60976] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/backups/.env"] [unique_id "aqxgJMPsx0SVFjrd623zlwAAAFI"]
[Thu Sep 17 15:48:20.193036 2026] [security2:error] [pid 60716:tid 61014] [client 45.156.129.70:11560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623zjwAAeC4"]
[Thu Sep 17 15:48:20.204340 2026] [security2:error] [pid 60716:tid 60911] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/rabbitmq/.env"] [unique_id "aqxgJMPsx0SVFjrd623zmwAAABM"]
[Thu Sep 17 15:48:20.253873 2026] [security2:error] [pid 60716:tid 60998] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxgJMPsx0SVFjrd623znwAAAGg"]
[Thu Sep 17 15:48:20.257656 2026] [security2:error] [pid 60716:tid 60800] [remote 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zNQAATCY"]
[Thu Sep 17 15:48:20.267455 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zOwAATHE"]
[Thu Sep 17 15:48:20.269541 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zNgAATBs"]
[Thu Sep 17 15:48:20.275085 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zPQAATAw"]
[Thu Sep 17 15:48:20.283766 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zLwAATGM"]
[Thu Sep 17 15:48:20.299930 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zNAAATFk"]
[Thu Sep 17 15:48:20.300431 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zMAAATFE"]
[Thu Sep 17 15:48:20.329206 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgIsPsx0SVFjrd623zMgAATHc"]
[Thu Sep 17 15:48:20.355699 2026] [security2:error] [pid 60716:tid 60931] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/kafka/.env"] [unique_id "aqxgJMPsx0SVFjrd623zowAAACU"]
[Thu Sep 17 15:48:20.412071 2026] [security2:error] [pid 60716:tid 60925] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/tmp/.env"] [unique_id "aqxgJMPsx0SVFjrd623zpwAAACA"]
[Thu Sep 17 15:48:20.419130 2026] [security2:error] [pid 60716:tid 60786] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/database.sql"] [unique_id "aqxgJMPsx0SVFjrd623zqAAATBg"]
[Thu Sep 17 15:48:20.444399 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623zYAAATB0"]
[Thu Sep 17 15:48:20.480803 2026] [security2:error] [pid 60716:tid 60783] [remote 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623zYgAATBY"]
[Thu Sep 17 15:48:20.485763 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623zcQAATDI"]
[Thu Sep 17 15:48:20.515623 2026] [security2:error] [pid 60716:tid 60958] [client 45.156.129.70:11560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "churchinirving.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zoAAAQBI"]
[Thu Sep 17 15:48:20.553327 2026] [security2:error] [pid 60716:tid 60957] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/queue/.env"] [unique_id "aqxgJMPsx0SVFjrd623zrAAAAD8"]
[Thu Sep 17 15:48:20.558654 2026] [security2:error] [pid 60716:tid 60914] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/temp/.env"] [unique_id "aqxgJMPsx0SVFjrd623zrgAAABY"]
[Thu Sep 17 15:48:20.574010 2026] [security2:error] [pid 60716:tid 60927] [client 177.44.133.72:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgJMPsx0SVFjrd623zrwAAACI"]
[Thu Sep 17 15:48:20.574174 2026] [security2:error] [pid 60716:tid 60927] [client 177.44.133.72:49348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgJMPsx0SVFjrd623zrwAAACI"]
[Thu Sep 17 15:48:20.588549 2026] [security2:error] [pid 60716:tid 60939] [client 34.154.246.111:38570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/saas/.env"] [unique_id "aqxgJMPsx0SVFjrd623zsgAAAC0"]
[Thu Sep 17 15:48:20.702854 2026] [security2:error] [pid 60716:tid 60948] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/lab/.env"] [unique_id "aqxgJMPsx0SVFjrd623zvQAAADY"]
[Thu Sep 17 15:48:20.706558 2026] [security2:error] [pid 60716:tid 60893] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/worker/.env"] [unique_id "aqxgJMPsx0SVFjrd623zvgAAAAE"]
[Thu Sep 17 15:48:20.742271 2026] [security2:error] [pid 60716:tid 60941] [client 34.154.246.111:38570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/client/.env"] [unique_id "aqxgJMPsx0SVFjrd623zwgAAAC8"]
[Thu Sep 17 15:48:20.764451 2026] [security2:error] [pid 60716:tid 60834] [remote 34.52.133.111:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/sites/default/settings.php.txt"] [unique_id "aqxgJMPsx0SVFjrd623zxAAATEg"]
[Thu Sep 17 15:48:20.861067 2026] [security2:error] [pid 60716:tid 60959] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cronlab/.env"] [unique_id "aqxgJMPsx0SVFjrd623zygAAAEE"]
[Thu Sep 17 15:48:20.861068 2026] [security2:error] [pid 60716:tid 60913] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/job/.env"] [unique_id "aqxgJMPsx0SVFjrd623zyQAAABU"]
[Thu Sep 17 15:48:20.861852 2026] [security2:error] [pid 60716:tid 60946] [client 45.156.129.71:51128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "churchinirving.net"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zxgAAADQ"]
[Thu Sep 17 15:48:20.898212 2026] [security2:error] [pid 60716:tid 60892] [client 34.154.246.111:38570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/project/.env"] [unique_id "aqxgJMPsx0SVFjrd623zywAAAAA"]
[Thu Sep 17 15:48:20.999602 2026] [security2:error] [pid 60716:tid 60924] [client 122.8.45.84:12847] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJMPsx0SVFjrd623zzQAAAB8"]
[Thu Sep 17 15:48:20.999812 2026] [security2:error] [pid 60716:tid 60924] [client 122.8.45.84:12847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJMPsx0SVFjrd623zzQAAAB8"]
[Thu Sep 17 15:48:21.016042 2026] [security2:error] [pid 60716:tid 60982] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cron/.env"] [unique_id "aqxgJcPsx0SVFjrd623zzgAAAFg"]
[Thu Sep 17 15:48:21.024957 2026] [security2:error] [pid 60716:tid 60966] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/test/.env"] [unique_id "aqxgJcPsx0SVFjrd623zzwAAAEg"]
[Thu Sep 17 15:48:21.054957 2026] [security2:error] [pid 60716:tid 60988] [client 34.154.246.111:38570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/admin-panel/.env"] [unique_id "aqxgJcPsx0SVFjrd623z0QAAAF4"]
[Thu Sep 17 15:48:21.177318 2026] [security2:error] [pid 60716:tid 60977] [client 34.185.180.78:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/en/.env"] [unique_id "aqxgJcPsx0SVFjrd623z0wAAAFM"]
[Thu Sep 17 15:48:21.181441 2026] [security2:error] [pid 60716:tid 60973] [client 34.32.107.79:51162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/qa/.env"] [unique_id "aqxgJcPsx0SVFjrd623z1gAAAE8"]
[Thu Sep 17 15:48:21.210097 2026] [security2:error] [pid 60716:tid 60971] [client 34.154.246.111:38570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/control-panel/.env"] [unique_id "aqxgJcPsx0SVFjrd623z1wAAAE0"]
[Thu Sep 17 15:48:21.250983 2026] [fcgid:warn] [pid 60716:tid 60955] (70014)End of file found: [client 152.32.205.184:41706] mod_fcgid: can't get data from http client
[Thu Sep 17 15:48:21.257791 2026] [security2:error] [pid 60716:tid 60888] [remote 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623zZQAATH4"]
[Thu Sep 17 15:48:21.258778 2026] [security2:error] [pid 60716:tid 60848] [remote 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623zhgAATFY"]
[Thu Sep 17 15:48:21.275614 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623zggAATGs"]
[Thu Sep 17 15:48:21.299375 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623ziAAATD0"]
[Thu Sep 17 15:48:21.334644 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgI8Psx0SVFjrd623ziQAATAA"]
[Thu Sep 17 15:48:21.402812 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zpgAATFg"]
[Thu Sep 17 15:48:21.413427 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zpAAATBQ"]
[Thu Sep 17 15:48:21.424170 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zpQAATCE"]
[Thu Sep 17 15:48:21.424384 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zqQAATAs"]
[Thu Sep 17 15:48:21.682282 2026] [http2:info] [pid 102783:tid 102783] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Sep 17 15:48:21.697430 2026] [security2:error] [pid 102783:tid 102913] [client 4.240.114.86:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "aqxgJczioAAmEecB_LG8kQAAAIU"], referer: binance.com
[Thu Sep 17 15:48:21.833970 2026] [security2:error] [pid 102783:tid 102788] [remote 34.52.133.111:51428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/bak/.env"] [unique_id "aqxgJczioAAmEecB_LG8mgAAlAQ"]
[Thu Sep 17 15:48:21.834454 2026] [security2:error] [pid 102783:tid 102785] [remote 34.52.133.111:51428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/.env.prod.bak"] [unique_id "aqxgJczioAAmEecB_LG8lwAAlAE"]
[Thu Sep 17 15:48:21.835035 2026] [security2:error] [pid 102783:tid 102788] [remote 34.52.133.111:51428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/cron/.env"] [unique_id "aqxgJczioAAmEecB_LG8nQAAlAQ"]
[Thu Sep 17 15:48:21.850492 2026] [security2:error] [pid 102783:tid 102914] [client 34.32.107.79:48872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/beta/.env"] [unique_id "aqxgJczioAAmEecB_LG8ngAAAIY"]
[Thu Sep 17 15:48:21.852967 2026] [security2:error] [pid 102783:tid 102919] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/psnlink/.env"] [unique_id "aqxgJczioAAmEecB_LG8nwAAAIs"]
[Thu Sep 17 15:48:21.859381 2026] [security2:error] [pid 102783:tid 102920] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/node/.env"] [unique_id "aqxgJczioAAmEecB_LG8oAAAAIw"]
[Thu Sep 17 15:48:21.967905 2026] [security2:error] [pid 102783:tid 102792] [remote 34.52.133.111:51428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/config.php.txt"] [unique_id "aqxgJczioAAmEecB_LG8ogAAlAg"]
[Thu Sep 17 15:48:22.006888 2026] [security2:error] [pid 102783:tid 102932] [client 34.32.107.79:48872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/uat/.env"] [unique_id "aqxgJszioAAmEecB_LG8qAAAAJg"]
[Thu Sep 17 15:48:22.013576 2026] [security2:error] [pid 102783:tid 102933] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/express/.env"] [unique_id "aqxgJszioAAmEecB_LG8qQAAAJk"]
[Thu Sep 17 15:48:22.014262 2026] [security2:error] [pid 102783:tid 102934] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/exapi/.env"] [unique_id "aqxgJszioAAmEecB_LG8qgAAAJo"]
[Thu Sep 17 15:48:22.131600 2026] [security2:error] [pid 102783:tid 102918] [client 122.8.45.84:31439] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJszioAAmEecB_LG8sAAAAIo"]
[Thu Sep 17 15:48:22.131760 2026] [security2:error] [pid 102783:tid 102918] [client 122.8.45.84:31439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJszioAAmEecB_LG8sAAAAIo"]
[Thu Sep 17 15:48:22.156460 2026] [security2:error] [pid 102783:tid 102939] [client 34.32.107.79:48872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/stage/.env"] [unique_id "aqxgJszioAAmEecB_LG8sQAAAJ8"]
[Thu Sep 17 15:48:22.167063 2026] [security2:error] [pid 102783:tid 102941] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/sitemaps/.env"] [unique_id "aqxgJszioAAmEecB_LG8sgAAAKE"]
[Thu Sep 17 15:48:22.171682 2026] [security2:error] [pid 102783:tid 102944] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/next/.env"] [unique_id "aqxgJszioAAmEecB_LG8tAAAAKQ"]
[Thu Sep 17 15:48:22.276962 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zwwAATE4"]
[Thu Sep 17 15:48:22.277406 2026] [security2:error] [pid 60716:tid 60819] [remote 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zqgAATDk"]
[Thu Sep 17 15:48:22.279859 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zxQAATB8"]
[Thu Sep 17 15:48:22.282225 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zsQAATG8"]
[Thu Sep 17 15:48:22.288656 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623ztwAATEA"]
[Thu Sep 17 15:48:22.291935 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zrQAATC0"]
[Thu Sep 17 15:48:22.295643 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623ztgAATDU"]
[Thu Sep 17 15:48:22.307277 2026] [security2:error] [pid 102783:tid 102950] [client 34.32.107.79:48872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/development/.env"] [unique_id "aqxgJszioAAmEecB_LG8vAAAAKo"]
[Thu Sep 17 15:48:22.313012 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zqwAATGc"]
[Thu Sep 17 15:48:22.330110 2026] [security2:error] [pid 102783:tid 102956] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/nuxt/.env"] [unique_id "aqxgJszioAAmEecB_LG8vgAAALA"]
[Thu Sep 17 15:48:22.365331 2026] [security2:error] [pid 60716:tid 60970] [client 34.52.133.111:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJMPsx0SVFjrd623zzAAATDY"]
[Thu Sep 17 15:48:22.374271 2026] [security2:error] [pid 102783:tid 102804] [remote 34.52.133.111:51428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.133.52.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zainridgecondo.org"] [uri "/bigdump.php"] [unique_id "aqxgJszioAAmEecB_LG8wAAAlBQ"]
[Thu Sep 17 15:48:22.428977 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJczioAAmEecB_LG8owAAlAk"]
[Thu Sep 17 15:48:22.429190 2026] [security2:error] [pid 102783:tid 102810] [remote 34.52.133.111:51428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/mysqldump.sql"] [unique_id "aqxgJszioAAmEecB_LG8yQAAlBo"]
[Thu Sep 17 15:48:22.431229 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJczioAAmEecB_LG8mAAAlAI"]
[Thu Sep 17 15:48:22.457414 2026] [security2:error] [pid 102783:tid 102940] [client 79.116.89.151:50964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJszioAAmEecB_LG8ywAAAKA"]
[Thu Sep 17 15:48:22.457602 2026] [security2:error] [pid 102783:tid 102940] [client 79.116.89.151:50964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJszioAAmEecB_LG8ywAAAKA"]
[Thu Sep 17 15:48:22.467491 2026] [security2:error] [pid 102783:tid 102963] [client 34.32.107.79:48872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/production/.env"] [unique_id "aqxgJszioAAmEecB_LG8zAAAALc"]
[Thu Sep 17 15:48:22.482788 2026] [security2:error] [pid 102783:tid 102965] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/nest/.env"] [unique_id "aqxgJszioAAmEecB_LG8zgAAALk"]
[Thu Sep 17 15:48:22.484549 2026] [security2:error] [pid 102783:tid 102949] [client 43.166.240.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.tab-funkenwerk.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8uwAAAKk"]
[Thu Sep 17 15:48:22.514330 2026] [security2:error] [pid 102783:tid 102813] [remote 34.52.133.111:51428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zainridgecondo.org"] [uri "/service/.env"] [unique_id "aqxgJszioAAmEecB_LG80AAAlB0"]
[Thu Sep 17 15:48:22.566382 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJczioAAmEecB_LG8mwAAlAU"]
[Thu Sep 17 15:48:22.566532 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJczioAAmEecB_LG8pQAAlAo"]
[Thu Sep 17 15:48:22.566604 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJczioAAmEecB_LG8pgAAlAw"]
[Thu Sep 17 15:48:22.566697 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8rwAAlBA"]
[Thu Sep 17 15:48:22.619341 2026] [security2:error] [pid 102783:tid 102969] [client 34.32.107.79:48872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.yourstrulymaria.com"] [uri "/config/app/.env"] [unique_id "aqxgJszioAAmEecB_LG80QAAAL0"]
[Thu Sep 17 15:48:22.623319 2026] [security2:error] [pid 102783:tid 102970] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/logs/.env"] [unique_id "aqxgJszioAAmEecB_LG80gAAAL4"]
[Thu Sep 17 15:48:22.636239 2026] [security2:error] [pid 102783:tid 102972] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/react/.env"] [unique_id "aqxgJszioAAmEecB_LG80wAAAMA"]
[Thu Sep 17 15:48:22.768910 2026] [security2:error] [pid 102783:tid 102978] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cache/.env"] [unique_id "aqxgJszioAAmEecB_LG82QAAAMY"]
[Thu Sep 17 15:48:22.782547 2026] [security2:error] [pid 102783:tid 102978] [client 34.32.107.79:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/phpinfo.php"] [unique_id "aqxgJszioAAmEecB_LG82gAAAMY"]
[Thu Sep 17 15:48:22.787955 2026] [security2:error] [pid 102783:tid 102982] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/vue/.env"] [unique_id "aqxgJszioAAmEecB_LG83AAAAMo"]
[Thu Sep 17 15:48:22.914145 2026] [security2:error] [pid 102783:tid 102988] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mailer/.env"] [unique_id "aqxgJszioAAmEecB_LG83wAAANA"]
[Thu Sep 17 15:48:22.941902 2026] [security2:error] [pid 102783:tid 102992] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/angular/.env"] [unique_id "aqxgJszioAAmEecB_LG84AAAANQ"]
[Thu Sep 17 15:48:23.032353 2026] [security2:error] [pid 102783:tid 102995] [client 169.58.197.251:57522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxgJ8zioAAmEecB_LG84gAAANc"], referer: binance.com
[Thu Sep 17 15:48:23.052177 2026] [security2:error] [pid 102783:tid 102971] [client 122.8.45.84:46611] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJ8zioAAmEecB_LG84wAAAL8"]
[Thu Sep 17 15:48:23.052315 2026] [security2:error] [pid 102783:tid 102971] [client 122.8.45.84:46611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJ8zioAAmEecB_LG84wAAAL8"]
[Thu Sep 17 15:48:23.065174 2026] [security2:error] [pid 102783:tid 102997] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mail/.env"] [unique_id "aqxgJ8zioAAmEecB_LG85AAAANk"]
[Thu Sep 17 15:48:23.094468 2026] [security2:error] [pid 102783:tid 102999] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/svelte/.env"] [unique_id "aqxgJ8zioAAmEecB_LG85QAAANs"]
[Thu Sep 17 15:48:23.215014 2026] [security2:error] [pid 102783:tid 103007] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/email/.env"] [unique_id "aqxgJ8zioAAmEecB_LG87AAAAOM"]
[Thu Sep 17 15:48:23.248589 2026] [security2:error] [pid 102783:tid 102998] [client 34.32.107.79:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/info.php"] [unique_id "aqxgJ8zioAAmEecB_LG88QAAANo"]
[Thu Sep 17 15:48:23.249217 2026] [security2:error] [pid 102783:tid 103011] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/vite/.env"] [unique_id "aqxgJ8zioAAmEecB_LG88AAAAOc"]
[Thu Sep 17 15:48:23.269006 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8wwAAlBU"]
[Thu Sep 17 15:48:23.273380 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8xAAAlBY"]
[Thu Sep 17 15:48:23.277471 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8yAAAlBk"]
[Thu Sep 17 15:48:23.278747 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8xwAAlBg"]
[Thu Sep 17 15:48:23.284770 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8ygAAlBs"]
[Thu Sep 17 15:48:23.375884 2026] [security2:error] [pid 102783:tid 103026] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/smtp/.env"] [unique_id "aqxgJ8zioAAmEecB_LG89gAAAPY"]
[Thu Sep 17 15:48:23.380103 2026] [security2:error] [pid 102783:tid 102928] [client 34.52.133.111:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "zainridgecondo.org"] [uri "/index.php"] [unique_id "aqxgJszioAAmEecB_LG8zwAAlBw"]
[Thu Sep 17 15:48:23.403104 2026] [security2:error] [pid 102783:tid 103028] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/backup/.env"] [unique_id "aqxgJ8zioAAmEecB_LG89wAAAPg"]
[Thu Sep 17 15:48:23.417133 2026] [security2:error] [pid 102783:tid 102996] [client 136.158.61.34:7905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJ8zioAAmEecB_LG8-AAAANg"]
[Thu Sep 17 15:48:23.417276 2026] [security2:error] [pid 102783:tid 102996] [client 136.158.61.34:7905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgJ8zioAAmEecB_LG8-AAAANg"]
[Thu Sep 17 15:48:23.576100 2026] [security2:error] [pid 102783:tid 102913] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/backups/.env"] [unique_id "aqxgJ8zioAAmEecB_LG8-gAAAIU"]
[Thu Sep 17 15:48:23.711381 2026] [security2:error] [pid 102783:tid 103040] [client 34.32.107.79:48898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/php.php"] [unique_id "aqxgJ8zioAAmEecB_LG9AAAAAQQ"]
[Thu Sep 17 15:48:23.728591 2026] [security2:error] [pid 102783:tid 102920] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/old/.env"] [unique_id "aqxgJ8zioAAmEecB_LG9AgAAAIw"]
[Thu Sep 17 15:48:23.881171 2026] [security2:error] [pid 102783:tid 102947] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/tmp/.env"] [unique_id "aqxgJ8zioAAmEecB_LG9DQAAAKc"]
[Thu Sep 17 15:48:23.883471 2026] [security2:error] [pid 102783:tid 102943] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mailing/.env"] [unique_id "aqxgJ8zioAAmEecB_LG9DgAAAKM"]
[Thu Sep 17 15:48:24.006762 2026] [security2:error] [pid 102783:tid 102915] [client 122.8.45.84:24015] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKMzioAAmEecB_LG9FAAAAIc"]
[Thu Sep 17 15:48:24.006875 2026] [security2:error] [pid 102783:tid 102915] [client 122.8.45.84:24015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKMzioAAmEecB_LG9FAAAAIc"]
[Thu Sep 17 15:48:24.033677 2026] [security2:error] [pid 102783:tid 102956] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/temp/.env"] [unique_id "aqxgKMzioAAmEecB_LG9FQAAALA"]
[Thu Sep 17 15:48:24.038220 2026] [security2:error] [pid 102783:tid 102958] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/notifications/.env"] [unique_id "aqxgKMzioAAmEecB_LG9FgAAALI"]
[Thu Sep 17 15:48:24.168410 2026] [security2:error] [pid 102783:tid 102955] [client 34.32.107.79:48912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/i.php"] [unique_id "aqxgKMzioAAmEecB_LG9GAAAAK8"]
[Thu Sep 17 15:48:24.184516 2026] [security2:error] [pid 102783:tid 102954] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/notify/.env"] [unique_id "aqxgKMzioAAmEecB_LG9GgAAAK4"]
[Thu Sep 17 15:48:24.184843 2026] [security2:error] [pid 102783:tid 102940] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/lab/.env"] [unique_id "aqxgKMzioAAmEecB_LG9GwAAAKA"]
[Thu Sep 17 15:48:24.329913 2026] [security2:error] [pid 102783:tid 102972] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/sender/.env"] [unique_id "aqxgKMzioAAmEecB_LG9IgAAAMA"]
[Thu Sep 17 15:48:24.339789 2026] [security2:error] [pid 102783:tid 102979] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/cronlab/.env"] [unique_id "aqxgKMzioAAmEecB_LG9JAAAAMc"]
[Thu Sep 17 15:48:24.477579 2026] [security2:error] [pid 102783:tid 102983] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/campaign/.env"] [unique_id "aqxgKMzioAAmEecB_LG9JQAAAMs"]
[Thu Sep 17 15:48:24.492816 2026] [security2:error] [pid 102783:tid 102977] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/cron/.env"] [unique_id "aqxgKMzioAAmEecB_LG9JgAAAMU"]
[Thu Sep 17 15:48:24.623468 2026] [security2:error] [pid 102783:tid 102974] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/newsletter/.env"] [unique_id "aqxgKMzioAAmEecB_LG9KQAAAMI"]
[Thu Sep 17 15:48:24.628253 2026] [security2:error] [pid 102783:tid 102981] [client 34.32.107.79:48924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/pi.php"] [unique_id "aqxgKMzioAAmEecB_LG9KwAAAMk"]
[Thu Sep 17 15:48:24.649678 2026] [security2:error] [pid 102783:tid 102987] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/en/.env"] [unique_id "aqxgKMzioAAmEecB_LG9LAAAAM8"]
[Thu Sep 17 15:48:24.783425 2026] [security2:error] [pid 102783:tid 103001] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/ses/.env"] [unique_id "aqxgKMzioAAmEecB_LG9MwAAAN0"]
[Thu Sep 17 15:48:24.854634 2026] [security2:error] [pid 102783:tid 103007] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/administrator/.env"] [unique_id "aqxgKMzioAAmEecB_LG9NAAAAOM"]
[Thu Sep 17 15:48:24.941417 2026] [security2:error] [pid 102783:tid 103013] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/sendgrid/.env"] [unique_id "aqxgKMzioAAmEecB_LG9NgAAAOk"]
[Thu Sep 17 15:48:24.967763 2026] [security2:error] [pid 102783:tid 102985] [client 122.8.45.84:29295] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKMzioAAmEecB_LG9NwAAAM0"]
[Thu Sep 17 15:48:24.967906 2026] [security2:error] [pid 102783:tid 102985] [client 122.8.45.84:29295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKMzioAAmEecB_LG9NwAAAM0"]
[Thu Sep 17 15:48:25.007531 2026] [security2:error] [pid 102783:tid 103015] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/psnlink/.env"] [unique_id "aqxgKczioAAmEecB_LG9OAAAAOs"]
[Thu Sep 17 15:48:25.034293 2026] [security2:error] [pid 102783:tid 103024] [client 213.4.39.246:43952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "meatlessmusings.com"] [uri "/index.php"] [unique_id "aqxgJ8zioAAmEecB_LG9EAAA9Co"], referer: https://meatlessmusings.com
[Thu Sep 17 15:48:25.087318 2026] [security2:error] [pid 102783:tid 103019] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/sparkpost/.env"] [unique_id "aqxgKczioAAmEecB_LG9OwAAAO8"]
[Thu Sep 17 15:48:25.092861 2026] [security2:error] [pid 102783:tid 103012] [client 34.32.107.79:48940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/pinfo.php"] [unique_id "aqxgKczioAAmEecB_LG9PAAAAOg"]
[Thu Sep 17 15:48:25.164818 2026] [security2:error] [pid 102783:tid 103016] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/exapi/.env"] [unique_id "aqxgKczioAAmEecB_LG9PQAAAOw"]
[Thu Sep 17 15:48:25.236105 2026] [security2:error] [pid 102783:tid 103026] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/postmark/.env"] [unique_id "aqxgKczioAAmEecB_LG9QQAAAPY"]
[Thu Sep 17 15:48:25.318050 2026] [security2:error] [pid 102783:tid 103031] [client 34.154.246.111:38572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/sitemaps/.env"] [unique_id "aqxgKczioAAmEecB_LG9RwAAAPs"]
[Thu Sep 17 15:48:25.383909 2026] [security2:error] [pid 102783:tid 103037] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mailgun/.env"] [unique_id "aqxgKczioAAmEecB_LG9TAAAAQE"]
[Thu Sep 17 15:48:25.464933 2026] [security2:error] [pid 102783:tid 102996] [client 57.141.14.113:59652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.streetwisepublicationsltd.com"] [uri "/index.php"] [unique_id "aqxgKczioAAmEecB_LG9SAAA2DM"]
[Thu Sep 17 15:48:25.534443 2026] [security2:error] [pid 102783:tid 102927] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mandrill/.env"] [unique_id "aqxgKczioAAmEecB_LG9VwAAAJM"]
[Thu Sep 17 15:48:25.564083 2026] [security2:error] [pid 102783:tid 102923] [client 34.32.107.79:48956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/test.php"] [unique_id "aqxgKczioAAmEecB_LG9WAAAAI8"]
[Thu Sep 17 15:48:25.679347 2026] [security2:error] [pid 102783:tid 102957] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mailjet/.env"] [unique_id "aqxgKczioAAmEecB_LG9WgAAALE"]
[Thu Sep 17 15:48:25.830744 2026] [security2:error] [pid 102783:tid 102967] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/brevo/.env"] [unique_id "aqxgKczioAAmEecB_LG9YQAAALs"]
[Thu Sep 17 15:48:25.874562 2026] [security2:error] [pid 102783:tid 102970] [client 74.7.228.16:33616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.inw.xka.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "aqxgKczioAAmEecB_LG9YgAAAL4"]
[Thu Sep 17 15:48:25.935174 2026] [security2:error] [pid 102783:tid 102916] [client 122.8.45.84:38219] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKczioAAmEecB_LG9ZQAAAIg"]
[Thu Sep 17 15:48:25.935299 2026] [security2:error] [pid 102783:tid 102916] [client 122.8.45.84:38219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKczioAAmEecB_LG9ZQAAAIg"]
[Thu Sep 17 15:48:25.983043 2026] [security2:error] [pid 102783:tid 102930] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/transactional/.env"] [unique_id "aqxgKczioAAmEecB_LG9aAAAAJY"]
[Thu Sep 17 15:48:26.132643 2026] [security2:error] [pid 102783:tid 102991] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/bulk/.env"] [unique_id "aqxgKszioAAmEecB_LG9dAAAANM"]
[Thu Sep 17 15:48:26.205759 2026] [security2:error] [pid 102783:tid 102987] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgKszioAAmEecB_LG9bgAAAM8"]
[Thu Sep 17 15:48:26.280184 2026] [security2:error] [pid 102783:tid 102993] [client 43.172.194.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxgKszioAAmEecB_LG9cwAAANU"]
[Thu Sep 17 15:48:26.290070 2026] [security2:error] [pid 102783:tid 103010] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxgKszioAAmEecB_LG9gQAAAOY"]
[Thu Sep 17 15:48:26.372400 2026] [security2:error] [pid 102783:tid 103027] [client 4.240.114.86:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wp-view-config-data.php"] [unique_id "aqxgKszioAAmEecB_LG9ggAAAPc"], referer: binance.com
[Thu Sep 17 15:48:26.437014 2026] [security2:error] [pid 102783:tid 103028] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/azure/.env"] [unique_id "aqxgKszioAAmEecB_LG9hAAAAPg"]
[Thu Sep 17 15:48:26.508757 2026] [security2:error] [pid 102783:tid 103017] [client 34.32.107.79:48968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/p.php"] [unique_id "aqxgKszioAAmEecB_LG9hgAAAO0"]
[Thu Sep 17 15:48:26.512829 2026] [security2:error] [pid 102783:tid 102983] [client 50.34.97.81:38018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgKszioAAmEecB_LG9gwAAyzo"]
[Thu Sep 17 15:48:26.516091 2026] [security2:error] [pid 102783:tid 103026] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/logs/.env"] [unique_id "aqxgKszioAAmEecB_LG9hwAAAPY"]
[Thu Sep 17 15:48:26.586309 2026] [security2:error] [pid 102783:tid 102928] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/gcp/.env"] [unique_id "aqxgKszioAAmEecB_LG9iAAAAJQ"]
[Thu Sep 17 15:48:26.672743 2026] [security2:error] [pid 102783:tid 103037] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/cache/.env"] [unique_id "aqxgKszioAAmEecB_LG9jAAAAQE"]
[Thu Sep 17 15:48:26.731857 2026] [security2:error] [pid 102783:tid 102947] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cloud/.env"] [unique_id "aqxgKszioAAmEecB_LG9kAAAAKc"]
[Thu Sep 17 15:48:26.829522 2026] [security2:error] [pid 102783:tid 103014] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mailer/.env"] [unique_id "aqxgKszioAAmEecB_LG9lQAAAOo"]
[Thu Sep 17 15:48:26.880973 2026] [security2:error] [pid 102783:tid 102937] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/infrastructure/.env"] [unique_id "aqxgKszioAAmEecB_LG9mAAAAJ0"]
[Thu Sep 17 15:48:26.909415 2026] [security2:error] [pid 102783:tid 103033] [client 122.8.45.84:25703] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKszioAAmEecB_LG9mQAAAP0"]
[Thu Sep 17 15:48:26.909526 2026] [security2:error] [pid 102783:tid 103033] [client 122.8.45.84:25703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgKszioAAmEecB_LG9mQAAAP0"]
[Thu Sep 17 15:48:26.966123 2026] [security2:error] [pid 102783:tid 102946] [client 34.32.107.79:48976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/debug.php"] [unique_id "aqxgKszioAAmEecB_LG9mwAAAKY"]
[Thu Sep 17 15:48:26.985278 2026] [security2:error] [pid 102783:tid 102927] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mail/.env"] [unique_id "aqxgKszioAAmEecB_LG9nAAAAJM"]
[Thu Sep 17 15:48:27.027837 2026] [security2:error] [pid 102783:tid 102951] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/docker/.env"] [unique_id "aqxgK8zioAAmEecB_LG9nQAAAKs"]
[Thu Sep 17 15:48:27.148867 2026] [security2:error] [pid 102783:tid 102956] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/email/.env"] [unique_id "aqxgK8zioAAmEecB_LG9ngAAALA"]
[Thu Sep 17 15:48:27.184249 2026] [security2:error] [pid 102783:tid 102933] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/k8s/.env"] [unique_id "aqxgK8zioAAmEecB_LG9oAAAAJk"]
[Thu Sep 17 15:48:27.304918 2026] [security2:error] [pid 102783:tid 102954] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/smtp/.env"] [unique_id "aqxgK8zioAAmEecB_LG9qQAAAK4"]
[Thu Sep 17 15:48:27.336178 2026] [security2:error] [pid 102783:tid 102961] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/kubernetes/.env"] [unique_id "aqxgK8zioAAmEecB_LG9rQAAALU"]
[Thu Sep 17 15:48:27.416032 2026] [security2:error] [pid 102783:tid 102957] [client 34.32.107.79:48992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxgK8zioAAmEecB_LG9sAAAALE"]
[Thu Sep 17 15:48:27.478804 2026] [security2:error] [pid 102783:tid 102948] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mailing/.env"] [unique_id "aqxgK8zioAAmEecB_LG9tgAAAKg"]
[Thu Sep 17 15:48:27.488262 2026] [security2:error] [pid 102783:tid 102965] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/terraform/.env"] [unique_id "aqxgK8zioAAmEecB_LG9twAAALk"]
[Thu Sep 17 15:48:27.638407 2026] [security2:error] [pid 102783:tid 102976] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/notifications/.env"] [unique_id "aqxgK8zioAAmEecB_LG9vAAAAMQ"]
[Thu Sep 17 15:48:27.641010 2026] [security2:error] [pid 102783:tid 102972] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/ansible/.env"] [unique_id "aqxgK8zioAAmEecB_LG9vQAAAMA"]
[Thu Sep 17 15:48:27.791964 2026] [security2:error] [pid 102783:tid 103002] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/.git/.env"] [unique_id "aqxgK8zioAAmEecB_LG9yQAAAN4"]
[Thu Sep 17 15:48:27.796459 2026] [security2:error] [pid 102783:tid 102997] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/notify/.env"] [unique_id "aqxgK8zioAAmEecB_LG9zAAAANk"]
[Thu Sep 17 15:48:27.881307 2026] [security2:error] [pid 102783:tid 102989] [client 34.32.107.79:49008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/test/phpinfo.php"] [unique_id "aqxgK8zioAAmEecB_LG90wAAANE"]
[Thu Sep 17 15:48:27.901165 2026] [security2:error] [pid 102783:tid 102978] [client 122.8.45.84:57999] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgK8zioAAmEecB_LG91AAAAMY"]
[Thu Sep 17 15:48:27.901278 2026] [security2:error] [pid 102783:tid 102978] [client 122.8.45.84:57999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgK8zioAAmEecB_LG91AAAAMY"]
[Thu Sep 17 15:48:27.943839 2026] [security2:error] [pid 102783:tid 103010] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/ci/.env"] [unique_id "aqxgK8zioAAmEecB_LG92AAAAOY"]
[Thu Sep 17 15:48:27.976526 2026] [security2:error] [pid 102783:tid 103021] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/sender/.env"] [unique_id "aqxgK8zioAAmEecB_LG92QAAAPE"]
[Thu Sep 17 15:48:28.092561 2026] [security2:error] [pid 102783:tid 103034] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cd/.env"] [unique_id "aqxgLMzioAAmEecB_LG92wAAAP4"]
[Thu Sep 17 15:48:28.145098 2026] [security2:error] [pid 102783:tid 103026] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/campaign/.env"] [unique_id "aqxgLMzioAAmEecB_LG93AAAAPY"]
[Thu Sep 17 15:48:28.241285 2026] [security2:error] [pid 102783:tid 102996] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/jenkins/.env"] [unique_id "aqxgLMzioAAmEecB_LG95AAAANg"]
[Thu Sep 17 15:48:28.302231 2026] [security2:error] [pid 102783:tid 102950] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/newsletter/.env"] [unique_id "aqxgLMzioAAmEecB_LG96AAAAKo"]
[Thu Sep 17 15:48:28.345115 2026] [security2:error] [pid 102783:tid 102943] [client 34.32.107.79:42824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxgLMzioAAmEecB_LG96wAAAKM"]
[Thu Sep 17 15:48:28.402201 2026] [security2:error] [pid 102783:tid 102942] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/gitlab/.env"] [unique_id "aqxgLMzioAAmEecB_LG97wAAAKI"]
[Thu Sep 17 15:48:28.460543 2026] [security2:error] [pid 102783:tid 102933] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/ses/.env"] [unique_id "aqxgLMzioAAmEecB_LG98QAAAJk"]
[Thu Sep 17 15:48:28.490148 2026] [security2:error] [pid 102783:tid 102927] [client 50.34.97.81:33541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgLMzioAAmEecB_LG97gAAk0s"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260821122435&hideliu=1&limit=500&target=Explore_the_Endless_Chronicles%3ACopyrights&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:48:28.555991 2026] [security2:error] [pid 102783:tid 102962] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/github/.env"] [unique_id "aqxgLMzioAAmEecB_LG98wAAALY"]
[Thu Sep 17 15:48:28.622714 2026] [security2:error] [pid 102783:tid 102924] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/sendgrid/.env"] [unique_id "aqxgLMzioAAmEecB_LG99AAAAJA"]
[Thu Sep 17 15:48:28.708885 2026] [security2:error] [pid 102783:tid 102990] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/actions/.env"] [unique_id "aqxgLMzioAAmEecB_LG9-AAAANI"]
[Thu Sep 17 15:48:28.741740 2026] [security2:error] [pid 102783:tid 102961] [client 192.178.6.3:37488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxgLMzioAAmEecB_LG9-gAAALU"]
[Thu Sep 17 15:48:28.782233 2026] [security2:error] [pid 102783:tid 102930] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/sparkpost/.env"] [unique_id "aqxgLMzioAAmEecB_LG9_QAAAJY"]
[Thu Sep 17 15:48:28.815034 2026] [security2:error] [pid 102783:tid 102921] [client 34.32.107.79:42836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/old/phpinfo.php"] [unique_id "aqxgLMzioAAmEecB_LG9_wAAAI0"]
[Thu Sep 17 15:48:28.854563 2026] [security2:error] [pid 102783:tid 102999] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/circleci/.env"] [unique_id "aqxgLMzioAAmEecB_LG-AQAAANs"]
[Thu Sep 17 15:48:28.857440 2026] [security2:error] [pid 102783:tid 102923] [client 122.8.45.84:27263] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLMzioAAmEecB_LG-AgAAAI8"]
[Thu Sep 17 15:48:28.857561 2026] [security2:error] [pid 102783:tid 102923] [client 122.8.45.84:27263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLMzioAAmEecB_LG-AgAAAI8"]
[Thu Sep 17 15:48:28.941334 2026] [security2:error] [pid 102783:tid 103002] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/postmark/.env"] [unique_id "aqxgLMzioAAmEecB_LG-BAAAAN4"]
[Thu Sep 17 15:48:29.000551 2026] [security2:error] [pid 102783:tid 103000] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/travis/.env"] [unique_id "aqxgLMzioAAmEecB_LG-BQAAANw"]
[Thu Sep 17 15:48:29.095596 2026] [security2:error] [pid 102783:tid 102989] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mailgun/.env"] [unique_id "aqxgLczioAAmEecB_LG-CAAAANE"]
[Thu Sep 17 15:48:29.147474 2026] [security2:error] [pid 102783:tid 103011] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/buildkite/.env"] [unique_id "aqxgLczioAAmEecB_LG-CwAAAOc"]
[Thu Sep 17 15:48:29.258046 2026] [security2:error] [pid 102783:tid 102988] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mandrill/.env"] [unique_id "aqxgLczioAAmEecB_LG-EAAAANA"]
[Thu Sep 17 15:48:29.277721 2026] [security2:error] [pid 102783:tid 103005] [client 34.32.107.79:42844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxgLczioAAmEecB_LG-EgAAAOE"]
[Thu Sep 17 15:48:29.296111 2026] [security2:error] [pid 102783:tid 103028] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mysql/.env"] [unique_id "aqxgLczioAAmEecB_LG-FAAAAPg"]
[Thu Sep 17 15:48:29.412378 2026] [security2:error] [pid 102783:tid 102985] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mailjet/.env"] [unique_id "aqxgLczioAAmEecB_LG-FwAAAM0"]
[Thu Sep 17 15:48:29.441634 2026] [security2:error] [pid 102783:tid 103017] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/postgres/.env"] [unique_id "aqxgLczioAAmEecB_LG-GAAAAO0"]
[Thu Sep 17 15:48:29.571447 2026] [security2:error] [pid 102783:tid 102984] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/brevo/.env"] [unique_id "aqxgLczioAAmEecB_LG-HgAAAMw"]
[Thu Sep 17 15:48:29.588228 2026] [security2:error] [pid 102783:tid 102931] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mongodb/.env"] [unique_id "aqxgLczioAAmEecB_LG-HwAAAJc"]
[Thu Sep 17 15:48:29.729357 2026] [security2:error] [pid 102783:tid 103012] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/transactional/.env"] [unique_id "aqxgLczioAAmEecB_LG-JQAAAOg"]
[Thu Sep 17 15:48:29.732147 2026] [security2:error] [pid 102783:tid 103004] [client 34.32.107.79:42850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/public/phpinfo.php"] [unique_id "aqxgLczioAAmEecB_LG-JgAAAOA"]
[Thu Sep 17 15:48:29.734591 2026] [security2:error] [pid 102783:tid 102942] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/redis/.env"] [unique_id "aqxgLczioAAmEecB_LG-JwAAAKI"]
[Thu Sep 17 15:48:29.840433 2026] [security2:error] [pid 102783:tid 103034] [client 122.8.45.84:62165] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLczioAAmEecB_LG-KAAAAP4"]
[Thu Sep 17 15:48:29.840550 2026] [security2:error] [pid 102783:tid 103034] [client 122.8.45.84:62165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLczioAAmEecB_LG-KAAAAP4"]
[Thu Sep 17 15:48:29.880717 2026] [security2:error] [pid 102783:tid 102933] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/elasticsearch/.env"] [unique_id "aqxgLczioAAmEecB_LG-KgAAAJk"]
[Thu Sep 17 15:48:29.883729 2026] [security2:error] [pid 102783:tid 102927] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/bulk/.env"] [unique_id "aqxgLczioAAmEecB_LG-KwAAAJM"]
[Thu Sep 17 15:48:30.028961 2026] [security2:error] [pid 102783:tid 102960] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/rabbitmq/.env"] [unique_id "aqxgLszioAAmEecB_LG-LQAAALQ"]
[Thu Sep 17 15:48:30.042188 2026] [security2:error] [pid 102783:tid 102938] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/aws/.env"] [unique_id "aqxgLszioAAmEecB_LG-LgAAAJ4"]
[Thu Sep 17 15:48:30.174506 2026] [security2:error] [pid 102783:tid 102979] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/kafka/.env"] [unique_id "aqxgLszioAAmEecB_LG-MwAAAMc"]
[Thu Sep 17 15:48:30.195401 2026] [security2:error] [pid 102783:tid 102916] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/azure/.env"] [unique_id "aqxgLszioAAmEecB_LG-OAAAAIg"]
[Thu Sep 17 15:48:30.278631 2026] [security2:error] [pid 102783:tid 102936] [client 143.105.152.240:29947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-OwAAAJw"]
[Thu Sep 17 15:48:30.278773 2026] [security2:error] [pid 102783:tid 102936] [client 143.105.152.240:29947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-OwAAAJw"]
[Thu Sep 17 15:48:30.327430 2026] [security2:error] [pid 102783:tid 102952] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/queue/.env"] [unique_id "aqxgLszioAAmEecB_LG-PQAAAKw"]
[Thu Sep 17 15:48:30.348549 2026] [security2:error] [pid 102783:tid 102976] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/gcp/.env"] [unique_id "aqxgLszioAAmEecB_LG-QAAAAMQ"]
[Thu Sep 17 15:48:30.444752 2026] [security2:error] [pid 102783:tid 102975] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgLszioAAmEecB_LG-OgAAAMM"]
[Thu Sep 17 15:48:30.446624 2026] [security2:error] [pid 102783:tid 102957] [client 14.96.156.146:55327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-QwAAALE"]
[Thu Sep 17 15:48:30.446733 2026] [security2:error] [pid 102783:tid 102957] [client 14.96.156.146:55327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-QwAAALE"]
[Thu Sep 17 15:48:30.472319 2026] [security2:error] [pid 102783:tid 102967] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/worker/.env"] [unique_id "aqxgLszioAAmEecB_LG-RAAAALs"]
[Thu Sep 17 15:48:30.502568 2026] [security2:error] [pid 102783:tid 103008] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/cloud/.env"] [unique_id "aqxgLszioAAmEecB_LG-RQAAAOQ"]
[Thu Sep 17 15:48:30.622002 2026] [security2:error] [pid 102783:tid 103015] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/job/.env"] [unique_id "aqxgLszioAAmEecB_LG-RwAAAOs"]
[Thu Sep 17 15:48:30.654904 2026] [security2:error] [pid 102783:tid 103016] [client 169.58.197.251:58253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxgLszioAAmEecB_LG-SQAAAOw"], referer: binance.com
[Thu Sep 17 15:48:30.655739 2026] [security2:error] [pid 102783:tid 103011] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/infrastructure/.env"] [unique_id "aqxgLszioAAmEecB_LG-SAAAAOc"]
[Thu Sep 17 15:48:30.748571 2026] [security2:error] [pid 102783:tid 102993] [client 34.32.107.79:42854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/php-info.php"] [unique_id "aqxgLszioAAmEecB_LG-TQAAANU"]
[Thu Sep 17 15:48:30.765394 2026] [security2:error] [pid 102783:tid 103005] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxgLszioAAmEecB_LG-UAAAAOE"]
[Thu Sep 17 15:48:30.780547 2026] [security2:error] [pid 102783:tid 103013] [client 4.240.114.86:51405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "aqxgLszioAAmEecB_LG-UgAAAOk"], referer: binance.com
[Thu Sep 17 15:48:30.788814 2026] [security2:error] [pid 102783:tid 102998] [client 148.227.75.216:4049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-UwAAANo"]
[Thu Sep 17 15:48:30.794724 2026] [security2:error] [pid 102783:tid 102998] [client 148.227.75.216:4049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-UwAAANo"]
[Thu Sep 17 15:48:30.813726 2026] [security2:error] [pid 102783:tid 103035] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/docker/.env"] [unique_id "aqxgLszioAAmEecB_LG-VQAAAP8"]
[Thu Sep 17 15:48:30.818372 2026] [security2:error] [pid 102783:tid 102999] [client 122.8.45.84:29253] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-VgAAANs"]
[Thu Sep 17 15:48:30.818508 2026] [security2:error] [pid 102783:tid 102999] [client 122.8.45.84:29253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgLszioAAmEecB_LG-VgAAANs"]
[Thu Sep 17 15:48:30.917174 2026] [security2:error] [pid 102783:tid 102980] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/qa/.env"] [unique_id "aqxgLszioAAmEecB_LG-WAAAAMg"]
[Thu Sep 17 15:48:30.968542 2026] [security2:error] [pid 102783:tid 102971] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/k8s/.env"] [unique_id "aqxgLszioAAmEecB_LG-WQAAAL8"]
[Thu Sep 17 15:48:30.980064 2026] [security2:error] [pid 102783:tid 102879] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env"] [unique_id "aqxgLszioAAmEecB_LG-WwAA6F8"]
[Thu Sep 17 15:48:31.046428 2026] [security2:error] [pid 102783:tid 102888] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.env.backup"] [unique_id "aqxgL8zioAAmEecB_LG-cAABA2g"]
[Thu Sep 17 15:48:31.046975 2026] [security2:error] [pid 102783:tid 102891] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.env.bak"] [unique_id "aqxgL8zioAAmEecB_LG-cgAAuGs"]
[Thu Sep 17 15:48:31.064149 2026] [security2:error] [pid 102783:tid 102940] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/preview/.env"] [unique_id "aqxgL8zioAAmEecB_LG-dQAAAKA"]
[Thu Sep 17 15:48:31.078686 2026] [security2:error] [pid 102783:tid 102896] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.env"] [unique_id "aqxgL8zioAAmEecB_LG-eAAA2HA"]
[Thu Sep 17 15:48:31.091578 2026] [security2:error] [pid 102783:tid 102901] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.env.old"] [unique_id "aqxgL8zioAAmEecB_LG-fAAAqXU"]
[Thu Sep 17 15:48:31.123301 2026] [security2:error] [pid 102783:tid 103031] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/kubernetes/.env"] [unique_id "aqxgL8zioAAmEecB_LG-fwAAAPs"]
[Thu Sep 17 15:48:31.159593 2026] [security2:error] [pid 102783:tid 103025] [client 177.44.133.72:50020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgL8zioAAmEecB_LG-gAAAAPU"]
[Thu Sep 17 15:48:31.159976 2026] [security2:error] [pid 102783:tid 103025] [client 177.44.133.72:50020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgL8zioAAmEecB_LG-gAAAAPU"]
[Thu Sep 17 15:48:31.205559 2026] [security2:error] [pid 102783:tid 102937] [client 34.32.107.79:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/phpversion.php"] [unique_id "aqxgL8zioAAmEecB_LG-hQAAAJ0"]
[Thu Sep 17 15:48:31.209252 2026] [security2:error] [pid 102783:tid 102962] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/beta/.env"] [unique_id "aqxgL8zioAAmEecB_LG-hgAAALY"]
[Thu Sep 17 15:48:31.212364 2026] [core:error] [pid 102783:tid 102916] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:48:31.212381 2026] [core:error] [pid 102783:tid 102916] [client 212.156.70.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:48:31.289196 2026] [security2:error] [pid 102783:tid 102952] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/terraform/.env"] [unique_id "aqxgL8zioAAmEecB_LG-jQAAAKw"]
[Thu Sep 17 15:48:31.359538 2026] [security2:error] [pid 102783:tid 102969] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/uat/.env"] [unique_id "aqxgL8zioAAmEecB_LG-jwAAAL0"]
[Thu Sep 17 15:48:31.374232 2026] [security2:error] [pid 102783:tid 102933] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-awAAAJk"]
[Thu Sep 17 15:48:31.380912 2026] [security2:error] [pid 102783:tid 103034] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-aQAAAP4"]
[Thu Sep 17 15:48:31.382909 2026] [security2:error] [pid 102783:tid 102938] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-cQAAnmo"]
[Thu Sep 17 15:48:31.391419 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-aAAAALA"]
[Thu Sep 17 15:48:31.400620 2026] [security2:error] [pid 102783:tid 102908] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env.bak"] [unique_id "aqxgLszioAAmEecB_LG-lAAA6Hw"]
[Thu Sep 17 15:48:31.402439 2026] [security2:error] [pid 102783:tid 102907] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env.old"] [unique_id "aqxgLszioAAmEecB_LG-kwAA6Hs"]
[Thu Sep 17 15:48:31.402933 2026] [security2:error] [pid 102783:tid 102906] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env.backup"] [unique_id "aqxgLszioAAmEecB_LG-kgAA6Ho"]
[Thu Sep 17 15:48:31.416751 2026] [security2:error] [pid 102783:tid 102960] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-bQAAALQ"]
[Thu Sep 17 15:48:31.429632 2026] [security2:error] [pid 102783:tid 102953] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-bgAArWc"]
[Thu Sep 17 15:48:31.431355 2026] [security2:error] [pid 102783:tid 102934] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-ZwAAAJo"]
[Thu Sep 17 15:48:31.431749 2026] [security2:error] [pid 102783:tid 102928] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-bwAAlGk"]
[Thu Sep 17 15:48:31.432643 2026] [security2:error] [pid 102783:tid 102790] [remote 110.249.202.197:21218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ec235nothing.cyberpunkonline.net"] [uri "/"] [unique_id "aqxgL8zioAAmEecB_LG-owAAxwY"]
[Thu Sep 17 15:48:31.432984 2026] [security2:error] [pid 102783:tid 103033] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-fgAA_XY"]
[Thu Sep 17 15:48:31.443593 2026] [security2:error] [pid 102783:tid 103019] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/ansible/.env"] [unique_id "aqxgL8zioAAmEecB_LG-pAAAAO8"]
[Thu Sep 17 15:48:31.503803 2026] [security2:error] [pid 102783:tid 103006] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/stage/.env"] [unique_id "aqxgL8zioAAmEecB_LG-rgAAAOI"]
[Thu Sep 17 15:48:31.590710 2026] [security2:error] [pid 102783:tid 102792] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/.env.php"] [unique_id "aqxgL8zioAAmEecB_LG-tAAAigg"]
[Thu Sep 17 15:48:31.609833 2026] [security2:error] [pid 102783:tid 103035] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/.git/.env"] [unique_id "aqxgL8zioAAmEecB_LG-tQAAAP8"]
[Thu Sep 17 15:48:31.650453 2026] [security2:error] [pid 102783:tid 103001] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/development/.env"] [unique_id "aqxgL8zioAAmEecB_LG-uQAAAN0"]
[Thu Sep 17 15:48:31.659434 2026] [security2:error] [pid 102783:tid 103013] [client 34.32.107.79:42870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/_phpinfo.php"] [unique_id "aqxgL8zioAAmEecB_LG-ugAAAOk"]
[Thu Sep 17 15:48:31.661845 2026] [security2:error] [pid 102783:tid 102798] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env.php"] [unique_id "aqxgL8zioAAmEecB_LG-vAAA6A4"]
[Thu Sep 17 15:48:31.663045 2026] [security2:error] [pid 102783:tid 102801] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env~"] [unique_id "aqxgL8zioAAmEecB_LG-uwAA6BE"]
[Thu Sep 17 15:48:31.663052 2026] [security2:error] [pid 102783:tid 102798] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env.swp"] [unique_id "aqxgL8zioAAmEecB_LG-vgAA6A4"]
[Thu Sep 17 15:48:31.694025 2026] [security2:error] [pid 102783:tid 102807] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.env~"] [unique_id "aqxgL8zioAAmEecB_LG-wQAAzBc"]
[Thu Sep 17 15:48:31.754725 2026] [security2:error] [pid 102783:tid 102786] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.env.swp"] [unique_id "aqxgL8zioAAmEecB_LG-ygAAxQI"]
[Thu Sep 17 15:48:31.770451 2026] [security2:error] [pid 102783:tid 102944] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/ci/.env"] [unique_id "aqxgL8zioAAmEecB_LG-zgAAAKQ"]
[Thu Sep 17 15:48:31.785474 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:16499] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgL8zioAAmEecB_LG-0AAAAK8"]
[Thu Sep 17 15:48:31.785586 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:16499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgL8zioAAmEecB_LG-0AAAAK8"]
[Thu Sep 17 15:48:31.799841 2026] [security2:error] [pid 102783:tid 102983] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxgL8zioAAmEecB_LG-1gAAAMs"]
[Thu Sep 17 15:48:31.924300 2026] [security2:error] [pid 102783:tid 102916] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/cd/.env"] [unique_id "aqxgL8zioAAmEecB_LG-4wAAAIg"]
[Thu Sep 17 15:48:31.932734 2026] [security2:error] [pid 102783:tid 102818] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/api/.env"] [unique_id "aqxgL8zioAAmEecB_LG-5gAA6CI"]
[Thu Sep 17 15:48:31.953465 2026] [security2:error] [pid 102783:tid 102947] [client 34.185.180.78:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jbn.bnl.mybluehost.me"] [uri "/config/app/.env"] [unique_id "aqxgL8zioAAmEecB_LG-6QAAAKc"]
[Thu Sep 17 15:48:32.073335 2026] [security2:error] [pid 102783:tid 102809] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/app/.env"] [unique_id "aqxgMMzioAAmEecB_LG-8gAA6Bk"]
[Thu Sep 17 15:48:32.091919 2026] [security2:error] [pid 102783:tid 102933] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/jenkins/.env"] [unique_id "aqxgMMzioAAmEecB_LG-9AAAAJk"]
[Thu Sep 17 15:48:32.105795 2026] [security2:error] [pid 102783:tid 103034] [client 34.185.180.78:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxgMMzioAAmEecB_LG-9QAAAP4"]
[Thu Sep 17 15:48:32.113486 2026] [security2:error] [pid 102783:tid 103029] [client 34.32.107.79:42872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/old_phpinfo.php"] [unique_id "aqxgMMzioAAmEecB_LG-9wAAAPk"]
[Thu Sep 17 15:48:32.253226 2026] [security2:error] [pid 102783:tid 102992] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/gitlab/.env"] [unique_id "aqxgMMzioAAmEecB_LG_BQAAANQ"]
[Thu Sep 17 15:48:32.275759 2026] [security2:error] [pid 102783:tid 103036] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-bAAAAQA"]
[Thu Sep 17 15:48:32.277042 2026] [security2:error] [pid 102783:tid 102984] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-cwAAzGw"]
[Thu Sep 17 15:48:32.313461 2026] [security2:error] [pid 102783:tid 102963] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-ewAAt3M"]
[Thu Sep 17 15:48:32.385216 2026] [security2:error] [pid 102783:tid 102900] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-fQAAqnQ"]
[Thu Sep 17 15:48:32.406378 2026] [security2:error] [pid 102783:tid 103040] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-egABBHI"]
[Thu Sep 17 15:48:32.417374 2026] [security2:error] [pid 102783:tid 102985] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/github/.env"] [unique_id "aqxgMMzioAAmEecB_LG_DQAAAM0"]
[Thu Sep 17 15:48:32.429420 2026] [security2:error] [pid 102783:tid 102895] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-dwAAi28"]
[Thu Sep 17 15:48:32.570929 2026] [security2:error] [pid 102783:tid 102821] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/api/.env"] [unique_id "aqxgMMzioAAmEecB_LG_GQABAiU"]
[Thu Sep 17 15:48:32.572065 2026] [security2:error] [pid 102783:tid 102980] [client 34.32.107.79:42886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/server-info.php"] [unique_id "aqxgMMzioAAmEecB_LG_GwAAAMg"]
[Thu Sep 17 15:48:32.572368 2026] [security2:error] [pid 102783:tid 102983] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/actions/.env"] [unique_id "aqxgMMzioAAmEecB_LG_GgAAAMs"]
[Thu Sep 17 15:48:32.578796 2026] [security2:error] [pid 102783:tid 102971] [client 34.185.180.78:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/info.php"] [unique_id "aqxgMMzioAAmEecB_LG_HAAAAL8"]
[Thu Sep 17 15:48:32.598471 2026] [security2:error] [pid 102783:tid 102828] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/app/.env"] [unique_id "aqxgMMzioAAmEecB_LG_IQAA3Cw"]
[Thu Sep 17 15:48:32.727795 2026] [security2:error] [pid 102783:tid 102947] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/circleci/.env"] [unique_id "aqxgMMzioAAmEecB_LG_KAAAAKc"]
[Thu Sep 17 15:48:32.737546 2026] [security2:error] [pid 102783:tid 102797] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/backend/.env"] [unique_id "aqxgMMzioAAmEecB_LG_KQABAg0"]
[Thu Sep 17 15:48:32.773430 2026] [security2:error] [pid 102783:tid 102830] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/server/.env"] [unique_id "aqxgMMzioAAmEecB_LG_LgAAxS4"]
[Thu Sep 17 15:48:32.778992 2026] [security2:error] [pid 102783:tid 102918] [client 122.8.45.84:64217] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMMzioAAmEecB_LG_LwAAAIo"]
[Thu Sep 17 15:48:32.779096 2026] [security2:error] [pid 102783:tid 102918] [client 122.8.45.84:64217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMMzioAAmEecB_LG_LwAAAIo"]
[Thu Sep 17 15:48:32.882934 2026] [security2:error] [pid 102783:tid 103033] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/travis/.env"] [unique_id "aqxgMMzioAAmEecB_LG_NQAAAP0"]
[Thu Sep 17 15:48:32.911615 2026] [security2:error] [pid 102783:tid 102834] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/config/.env"] [unique_id "aqxgMMzioAAmEecB_LG_NgAA3DI"]
[Thu Sep 17 15:48:32.939100 2026] [security2:error] [pid 102783:tid 102833] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/src/.env"] [unique_id "aqxgMMzioAAmEecB_LG_OAAAhTE"]
[Thu Sep 17 15:48:33.029600 2026] [security2:error] [pid 102783:tid 102997] [client 34.32.107.79:42900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/server-status.php"] [unique_id "aqxgMczioAAmEecB_LG_PAAAANk"]
[Thu Sep 17 15:48:33.038460 2026] [security2:error] [pid 102783:tid 103006] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/buildkite/.env"] [unique_id "aqxgMczioAAmEecB_LG_PQAAAOI"]
[Thu Sep 17 15:48:33.051233 2026] [security2:error] [pid 102783:tid 103023] [client 34.185.180.78:60932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/php.php"] [unique_id "aqxgMczioAAmEecB_LG_PwAAAPM"]
[Thu Sep 17 15:48:33.088754 2026] [security2:error] [pid 102783:tid 102835] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/web/.env"] [unique_id "aqxgMczioAAmEecB_LG_QAAAxTM"]
[Thu Sep 17 15:48:33.117407 2026] [security2:error] [pid 102783:tid 102824] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/client/.env"] [unique_id "aqxgMczioAAmEecB_LG_QgABAig"]
[Thu Sep 17 15:48:33.143917 2026] [security2:error] [pid 102783:tid 103020] [client 79.116.89.151:51587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMczioAAmEecB_LG_RAAAAPA"]
[Thu Sep 17 15:48:33.144210 2026] [security2:error] [pid 102783:tid 103020] [client 79.116.89.151:51587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMczioAAmEecB_LG_RAAAAPA"]
[Thu Sep 17 15:48:33.196703 2026] [security2:error] [pid 102783:tid 103024] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mysql/.env"] [unique_id "aqxgMczioAAmEecB_LG_SAAAAPQ"]
[Thu Sep 17 15:48:33.260700 2026] [security2:error] [pid 102783:tid 102841] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/frontend/.env"] [unique_id "aqxgMczioAAmEecB_LG_UAAAlzk"]
[Thu Sep 17 15:48:33.288433 2026] [security2:error] [pid 102783:tid 103030] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-eQAA-nE"]
[Thu Sep 17 15:48:33.295720 2026] [security2:error] [pid 102783:tid 102843] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/public/.env"] [unique_id "aqxgMczioAAmEecB_LG_UwAA3Ds"]
[Thu Sep 17 15:48:33.341903 2026] [security2:error] [pid 102783:tid 102913] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-dAAAhW0"]
[Thu Sep 17 15:48:33.368075 2026] [security2:error] [pid 102783:tid 102980] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/postgres/.env"] [unique_id "aqxgMczioAAmEecB_LG_WAAAAMg"]
[Thu Sep 17 15:48:33.410989 2026] [security2:error] [pid 102783:tid 103005] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-qgAAAOE"]
[Thu Sep 17 15:48:33.418894 2026] [security2:error] [pid 102783:tid 102993] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-qQAAANU"]
[Thu Sep 17 15:48:33.436363 2026] [security2:error] [pid 102783:tid 102844] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/var/www/.env"] [unique_id "aqxgMczioAAmEecB_LG_WgAAxTw"]
[Thu Sep 17 15:48:33.470446 2026] [security2:error] [pid 102783:tid 102845] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/var/www/html/.env"] [unique_id "aqxgMczioAAmEecB_LG_XQAA-j0"]
[Thu Sep 17 15:48:33.474841 2026] [security2:error] [pid 102783:tid 103021] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-rAAAAPE"]
[Thu Sep 17 15:48:33.477552 2026] [security2:error] [pid 102783:tid 102977] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-sgAAxX8"]
[Thu Sep 17 15:48:33.483725 2026] [security2:error] [pid 102783:tid 102970] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-pwAAAL4"]
[Thu Sep 17 15:48:33.505898 2026] [security2:error] [pid 102783:tid 102955] [client 34.185.180.78:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/i.php"] [unique_id "aqxgMczioAAmEecB_LG_YAAAAK8"]
[Thu Sep 17 15:48:33.524717 2026] [security2:error] [pid 102783:tid 102972] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/mongodb/.env"] [unique_id "aqxgMczioAAmEecB_LG_YwAAAMA"]
[Thu Sep 17 15:48:33.563697 2026] [security2:error] [pid 102783:tid 102846] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/backend/.env"] [unique_id "aqxgMczioAAmEecB_LG_ZQAA6D4"]
[Thu Sep 17 15:48:33.612671 2026] [security2:error] [pid 102783:tid 102850] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/laravel/.env"] [unique_id "aqxgMczioAAmEecB_LG_agABAkI"]
[Thu Sep 17 15:48:33.615765 2026] [security2:error] [pid 102783:tid 102849] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/server/.env"] [unique_id "aqxgMczioAAmEecB_LG_awAA6EE"]
[Thu Sep 17 15:48:33.622639 2026] [security2:error] [pid 102783:tid 102855] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/application/.env"] [unique_id "aqxgMczioAAmEecB_LG_bAAA3Ec"]
[Thu Sep 17 15:48:33.622643 2026] [security2:error] [pid 102783:tid 102852] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/config/.env"] [unique_id "aqxgMczioAAmEecB_LG_bQAA6EQ"]
[Thu Sep 17 15:48:33.632076 2026] [security2:error] [pid 102783:tid 102853] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/apps/.env"] [unique_id "aqxgMczioAAmEecB_LG_bgAAzEU"]
[Thu Sep 17 15:48:33.670430 2026] [security2:error] [pid 102783:tid 102851] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/src/.env"] [unique_id "aqxgMczioAAmEecB_LG_cgAA6EM"]
[Thu Sep 17 15:48:33.670431 2026] [security2:error] [pid 102783:tid 102856] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/web/.env"] [unique_id "aqxgMczioAAmEecB_LG_cAAA6Eg"]
[Thu Sep 17 15:48:33.670456 2026] [security2:error] [pid 102783:tid 102854] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/client/.env"] [unique_id "aqxgMczioAAmEecB_LG_cQAA6EY"]
[Thu Sep 17 15:48:33.675787 2026] [security2:error] [pid 102783:tid 103029] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgMczioAAmEecB_LG_YQAAAPk"]
[Thu Sep 17 15:48:33.679113 2026] [security2:error] [pid 102783:tid 102940] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/redis/.env"] [unique_id "aqxgMczioAAmEecB_LG_cwAAAKA"]
[Thu Sep 17 15:48:33.701190 2026] [security2:error] [pid 102783:tid 102858] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/back/.env"] [unique_id "aqxgMczioAAmEecB_LG_dgAAxUo"]
[Thu Sep 17 15:48:33.708153 2026] [security2:error] [pid 102783:tid 102860] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/backup/.env"] [unique_id "aqxgMczioAAmEecB_LG_eQABAkw"]
[Thu Sep 17 15:48:33.737964 2026] [security2:error] [pid 102783:tid 102861] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/frontend/.env"] [unique_id "aqxgMczioAAmEecB_LG_egAA6E0"]
[Thu Sep 17 15:48:33.751828 2026] [security2:error] [pid 102783:tid 102922] [client 122.8.45.84:44449] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMczioAAmEecB_LG_fQAAAI4"]
[Thu Sep 17 15:48:33.751925 2026] [security2:error] [pid 102783:tid 102922] [client 122.8.45.84:44449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMczioAAmEecB_LG_fQAAAI4"]
[Thu Sep 17 15:48:33.825065 2026] [security2:error] [pid 102783:tid 102863] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/public/.env"] [unique_id "aqxgMczioAAmEecB_LG_gQAA6E8"]
[Thu Sep 17 15:48:33.825085 2026] [security2:error] [pid 102783:tid 102868] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/var/www/.env"] [unique_id "aqxgMczioAAmEecB_LG_ggAA6FQ"]
[Thu Sep 17 15:48:33.833525 2026] [security2:error] [pid 102783:tid 102926] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/elasticsearch/.env"] [unique_id "aqxgMczioAAmEecB_LG_gwAAAJI"]
[Thu Sep 17 15:48:33.889068 2026] [security2:error] [pid 102783:tid 102866] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/laravel/.env"] [unique_id "aqxgMczioAAmEecB_LG_hwAA6FI"]
[Thu Sep 17 15:48:33.889080 2026] [security2:error] [pid 102783:tid 102865] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/application/.env"] [unique_id "aqxgMczioAAmEecB_LG_iAAA6FE"]
[Thu Sep 17 15:48:33.889117 2026] [security2:error] [pid 102783:tid 102869] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/var/www/html/.env"] [unique_id "aqxgMczioAAmEecB_LG_iQAA6FU"]
[Thu Sep 17 15:48:33.935605 2026] [security2:error] [pid 102783:tid 102870] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/cms/.env"] [unique_id "aqxgMczioAAmEecB_LG_igAAhVY"]
[Thu Sep 17 15:48:33.937513 2026] [security2:error] [pid 102783:tid 102872] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/production/.env"] [unique_id "aqxgMczioAAmEecB_LG_iwAAl1g"]
[Thu Sep 17 15:48:33.946929 2026] [security2:error] [pid 102783:tid 102874] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/prod/.env"] [unique_id "aqxgMczioAAmEecB_LG_jwAAxVo"]
[Thu Sep 17 15:48:33.946956 2026] [security2:error] [pid 102783:tid 102871] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/dev/.env"] [unique_id "aqxgMczioAAmEecB_LG_jQAA3Fc"]
[Thu Sep 17 15:48:33.947018 2026] [security2:error] [pid 102783:tid 102873] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/staging/.env"] [unique_id "aqxgMczioAAmEecB_LG_jgABAlk"]
[Thu Sep 17 15:48:33.960084 2026] [security2:error] [pid 102783:tid 103015] [client 34.185.180.78:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxgMczioAAmEecB_LG_kAAAAOs"]
[Thu Sep 17 15:48:33.990623 2026] [security2:error] [pid 102783:tid 102876] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/back/.env"] [unique_id "aqxgMczioAAmEecB_LG_kwAA6Fw"]
[Thu Sep 17 15:48:33.990619 2026] [security2:error] [pid 102783:tid 102875] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/apps/.env"] [unique_id "aqxgMczioAAmEecB_LG_kgAA6Fs"]
[Thu Sep 17 15:48:33.990752 2026] [security2:error] [pid 102783:tid 102864] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/backup/.env"] [unique_id "aqxgMczioAAmEecB_LG_lAAA6FA"]
[Thu Sep 17 15:48:33.998400 2026] [security2:error] [pid 102783:tid 103024] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/rabbitmq/.env"] [unique_id "aqxgMczioAAmEecB_LG_lQAAAPQ"]
[Thu Sep 17 15:48:34.006563 2026] [security2:error] [pid 102783:tid 102878] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/test/.env"] [unique_id "aqxgMszioAAmEecB_LG_lwAA3F4"]
[Thu Sep 17 15:48:34.030825 2026] [security2:error] [pid 102783:tid 102886] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/dev/.env"] [unique_id "aqxgMszioAAmEecB_LG_mAAA6GY"]
[Thu Sep 17 15:48:34.030872 2026] [security2:error] [pid 102783:tid 102888] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/prod/.env"] [unique_id "aqxgMszioAAmEecB_LG_mgAA6Gg"]
[Thu Sep 17 15:48:34.030956 2026] [security2:error] [pid 102783:tid 102885] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/cms/.env"] [unique_id "aqxgMszioAAmEecB_LG_mQAA6GU"]
[Thu Sep 17 15:48:34.108830 2026] [security2:error] [pid 102783:tid 102891] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/old/.env"] [unique_id "aqxgMszioAAmEecB_LG_nwAA-ms"]
[Thu Sep 17 15:48:34.113935 2026] [security2:error] [pid 102783:tid 102896] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/api-backend/.env"] [unique_id "aqxgMszioAAmEecB_LG_oAAAzHA"]
[Thu Sep 17 15:48:34.114102 2026] [security2:error] [pid 102783:tid 102901] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/new/.env"] [unique_id "aqxgMszioAAmEecB_LG_oQABAnU"]
[Thu Sep 17 15:48:34.123060 2026] [security2:error] [pid 102783:tid 102903] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/node-api/.env"] [unique_id "aqxgMszioAAmEecB_LG_ogAA3Hc"]
[Thu Sep 17 15:48:34.124700 2026] [security2:error] [pid 102783:tid 102890] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/admin-app/.env"] [unique_id "aqxgMszioAAmEecB_LG_owAAxWo"]
[Thu Sep 17 15:48:34.163105 2026] [security2:error] [pid 102783:tid 102785] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/staging/.env"] [unique_id "aqxgMszioAAmEecB_LG_pQAA6AE"]
[Thu Sep 17 15:48:34.163104 2026] [security2:error] [pid 102783:tid 102943] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/kafka/.env"] [unique_id "aqxgMszioAAmEecB_LG_qAAAAKM"]
[Thu Sep 17 15:48:34.163109 2026] [security2:error] [pid 102783:tid 102791] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/production/.env"] [unique_id "aqxgMszioAAmEecB_LG_pwAA6Ac"]
[Thu Sep 17 15:48:34.163163 2026] [security2:error] [pid 102783:tid 102788] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/test/.env"] [unique_id "aqxgMszioAAmEecB_LG_pgAA6AQ"]
[Thu Sep 17 15:48:34.172034 2026] [security2:error] [pid 102783:tid 102881] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/new/.env"] [unique_id "aqxgMszioAAmEecB_LG_qgAA6GE"]
[Thu Sep 17 15:48:34.172083 2026] [security2:error] [pid 102783:tid 102889] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/node-api/.env"] [unique_id "aqxgMszioAAmEecB_LG_qwAA6Gk"]
[Thu Sep 17 15:48:34.172247 2026] [security2:error] [pid 102783:tid 102887] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/old/.env"] [unique_id "aqxgMszioAAmEecB_LG_rAAA6Gc"]
[Thu Sep 17 15:48:34.215579 2026] [security2:error] [pid 102783:tid 102790] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/administrator/.env"] [unique_id "aqxgMszioAAmEecB_LG_rgAAxQY"]
[Thu Sep 17 15:48:34.219574 2026] [security2:error] [pid 102783:tid 102905] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/public_html/.env"] [unique_id "aqxgMszioAAmEecB_LG_tAAAhXk"]
[Thu Sep 17 15:48:34.229715 2026] [security2:error] [pid 102783:tid 102958] [client 34.32.107.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yourstrulymaria.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_ngAAALI"]
[Thu Sep 17 15:48:34.278699 2026] [security2:error] [pid 102783:tid 102792] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/current/.env"] [unique_id "aqxgMszioAAmEecB_LG_twABAgg"]
[Thu Sep 17 15:48:34.284714 2026] [security2:error] [pid 102783:tid 102904] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/server/api/.env"] [unique_id "aqxgMszioAAmEecB_LG_ugAA3Hg"]
[Thu Sep 17 15:48:34.284931 2026] [security2:error] [pid 102783:tid 102984] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-hwAAzHg"]
[Thu Sep 17 15:48:34.289140 2026] [security2:error] [pid 102783:tid 102798] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.docker/.env"] [unique_id "aqxgMszioAAmEecB_LG_vAAAhQ4"]
[Thu Sep 17 15:48:34.291790 2026] [security2:error] [pid 102783:tid 102801] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/server/backend/.env"] [unique_id "aqxgMszioAAmEecB_LG_vQAAxRE"]
[Thu Sep 17 15:48:34.293262 2026] [security2:error] [pid 102783:tid 102807] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/aws/.env"] [unique_id "aqxgMszioAAmEecB_LG_vgAAlxc"]
[Thu Sep 17 15:48:34.308658 2026] [security2:error] [pid 102783:tid 102786] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxgMszioAAmEecB_LG_wQABAgI"]
[Thu Sep 17 15:48:34.312802 2026] [security2:error] [pid 102783:tid 103028] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-swAAAPg"]
[Thu Sep 17 15:48:34.315319 2026] [security2:error] [pid 102783:tid 102794] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/admin-app/.env"] [unique_id "aqxgMszioAAmEecB_LG_wwAA6Ao"]
[Thu Sep 17 15:48:34.315654 2026] [security2:error] [pid 102783:tid 102818] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/administrator/.env"] [unique_id "aqxgMszioAAmEecB_LG_xAAA6CI"]
[Thu Sep 17 15:48:34.316152 2026] [security2:error] [pid 102783:tid 102793] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/api-backend/.env"] [unique_id "aqxgMszioAAmEecB_LG_wgAA6Ak"]
[Thu Sep 17 15:48:34.324409 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-tgAA3As"]
[Thu Sep 17 15:48:34.325005 2026] [security2:error] [pid 102783:tid 102984] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-yQAAzBo"]
[Thu Sep 17 15:48:34.325897 2026] [security2:error] [pid 102783:tid 103003] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-pQAAAN8"]
[Thu Sep 17 15:48:34.328103 2026] [security2:error] [pid 102783:tid 102810] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/server/api/.env"] [unique_id "aqxgMszioAAmEecB_LG_yAAA6Bo"]
[Thu Sep 17 15:48:34.329427 2026] [security2:error] [pid 102783:tid 102809] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/public_html/.env"] [unique_id "aqxgMszioAAmEecB_LG_xQAA6Bk"]
[Thu Sep 17 15:48:34.329841 2026] [security2:error] [pid 102783:tid 102806] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/current/.env"] [unique_id "aqxgMszioAAmEecB_LG_xgAA6BY"]
[Thu Sep 17 15:48:34.331573 2026] [security2:error] [pid 102783:tid 103031] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-3AAAAPs"]
[Thu Sep 17 15:48:34.333704 2026] [security2:error] [pid 102783:tid 102936] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/queue/.env"] [unique_id "aqxgMszioAAmEecB_LG_xwAAAJw"]
[Thu Sep 17 15:48:34.373977 2026] [security2:error] [pid 102783:tid 102931] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-dgAAl24"]
[Thu Sep 17 15:48:34.375218 2026] [security2:error] [pid 102783:tid 103016] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-pgAAAOw"]
[Thu Sep 17 15:48:34.377477 2026] [security2:error] [pid 102783:tid 102955] [client 4.240.114.86:53064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "aqxgMszioAAmEecB_LG_zAAAAK8"], referer: binance.com
[Thu Sep 17 15:48:34.378462 2026] [security2:error] [pid 102783:tid 102913] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-4gAAhSA"]
[Thu Sep 17 15:48:34.396268 2026] [security2:error] [pid 102783:tid 102892] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/stripe/.env"] [unique_id "aqxgMszioAAmEecB_LG_zgAA3Gw"]
[Thu Sep 17 15:48:34.396606 2026] [security2:error] [pid 102783:tid 102814] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.aws/.env"] [unique_id "aqxgMszioAAmEecB_LG_zQABAh4"]
[Thu Sep 17 15:48:34.410964 2026] [security2:error] [pid 102783:tid 102990] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMMzioAAmEecB_LG-7wAAANI"]
[Thu Sep 17 15:48:34.414489 2026] [security2:error] [pid 102783:tid 102947] [client 34.185.180.78:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxgMszioAAmEecB_LG_zwAAAKc"]
[Thu Sep 17 15:48:34.415047 2026] [security2:error] [pid 102783:tid 102977] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-3gAAxR8"]
[Thu Sep 17 15:48:34.443434 2026] [security2:error] [pid 102783:tid 102949] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-4AAAAKk"]
[Thu Sep 17 15:48:34.455248 2026] [security2:error] [pid 102783:tid 102940] [client 34.32.107.79:42902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxgMszioAAmEecB_LG_0gAAAKA"]
[Thu Sep 17 15:48:34.456816 2026] [security2:error] [pid 102783:tid 102883] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/server/backend/.env"] [unique_id "aqxgMszioAAmEecB_LG_0wAA6GM"]
[Thu Sep 17 15:48:34.457332 2026] [security2:error] [pid 102783:tid 102812] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.docker/.env"] [unique_id "aqxgMszioAAmEecB_LG_1AAA6Bw"]
[Thu Sep 17 15:48:34.458247 2026] [security2:error] [pid 102783:tid 102899] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxgMszioAAmEecB_LG_1QAA6HM"]
[Thu Sep 17 15:48:34.462152 2026] [security2:error] [pid 102783:tid 102819] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/v1/.env"] [unique_id "aqxgMszioAAmEecB_LG_1wAA3CM"]
[Thu Sep 17 15:48:34.463678 2026] [security2:error] [pid 102783:tid 102898] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/v2/.env"] [unique_id "aqxgMszioAAmEecB_LG_2AAA-nI"]
[Thu Sep 17 15:48:34.465827 2026] [security2:error] [pid 102783:tid 102821] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.aws/.env"] [unique_id "aqxgMszioAAmEecB_LG_2gAA6CU"]
[Thu Sep 17 15:48:34.465841 2026] [security2:error] [pid 102783:tid 102895] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/aws/.env"] [unique_id "aqxgMszioAAmEecB_LG_2QAA6G8"]
[Thu Sep 17 15:48:34.466603 2026] [security2:error] [pid 102783:tid 102828] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/v3/.env"] [unique_id "aqxgMszioAAmEecB_LG_2wAAxSw"]
[Thu Sep 17 15:48:34.468082 2026] [security2:error] [pid 102783:tid 102825] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/stripe/.env"] [unique_id "aqxgMszioAAmEecB_LG_3AAA6Ck"]
[Thu Sep 17 15:48:34.481882 2026] [security2:error] [pid 102783:tid 102797] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/media/.env"] [unique_id "aqxgMszioAAmEecB_LG_3gAA3A0"]
[Thu Sep 17 15:48:34.492255 2026] [security2:error] [pid 102783:tid 102962] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/worker/.env"] [unique_id "aqxgMszioAAmEecB_LG_3wAAALY"]
[Thu Sep 17 15:48:34.550128 2026] [security2:error] [pid 102783:tid 102799] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/v1/.env"] [unique_id "aqxgMszioAAmEecB_LG_5wAA6A8"]
[Thu Sep 17 15:48:34.595452 2026] [security2:error] [pid 102783:tid 102833] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/v2/.env"] [unique_id "aqxgMszioAAmEecB_LG_7AAA6DE"]
[Thu Sep 17 15:48:34.595961 2026] [security2:error] [pid 102783:tid 102835] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/v3/.env"] [unique_id "aqxgMszioAAmEecB_LG_7gAA6DM"]
[Thu Sep 17 15:48:34.595960 2026] [security2:error] [pid 102783:tid 102824] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/media/.env"] [unique_id "aqxgMszioAAmEecB_LG_7QAA6Cg"]
[Thu Sep 17 15:48:34.648023 2026] [security2:error] [pid 102783:tid 102942] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/job/.env"] [unique_id "aqxgMszioAAmEecB_LG_-wAAAKI"]
[Thu Sep 17 15:48:34.707415 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:52617] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMszioAAmEecB_LHACQAAAI0"]
[Thu Sep 17 15:48:34.707528 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:52617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgMszioAAmEecB_LHACQAAAI0"]
[Thu Sep 17 15:48:34.807904 2026] [security2:error] [pid 102783:tid 102993] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/test/.env"] [unique_id "aqxgMszioAAmEecB_LHAGAAAANU"]
[Thu Sep 17 15:48:34.857019 2026] [security2:error] [pid 102783:tid 102950] [client 34.185.180.78:60970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/test.php"] [unique_id "aqxgMszioAAmEecB_LHAGQAAAKo"]
[Thu Sep 17 15:48:34.913645 2026] [security2:error] [pid 102783:tid 103011] [client 34.32.107.79:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxgMszioAAmEecB_LHAHQAAAOc"]
[Thu Sep 17 15:48:34.967528 2026] [security2:error] [pid 102783:tid 102916] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/qa/.env"] [unique_id "aqxgMszioAAmEecB_LHAHwAAAIg"]
[Thu Sep 17 15:48:35.125953 2026] [security2:error] [pid 102783:tid 102937] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/preview/.env"] [unique_id "aqxgM8zioAAmEecB_LHAJAAAAJ0"]
[Thu Sep 17 15:48:35.286650 2026] [security2:error] [pid 102783:tid 103021] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/beta/.env"] [unique_id "aqxgM8zioAAmEecB_LHALgAAAPE"]
[Thu Sep 17 15:48:35.296151 2026] [security2:error] [pid 102783:tid 102928] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMMzioAAmEecB_LG_BAAAAJQ"]
[Thu Sep 17 15:48:35.308259 2026] [security2:error] [pid 102783:tid 103010] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-qwAAAOY"]
[Thu Sep 17 15:48:35.317432 2026] [security2:error] [pid 102783:tid 102984] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMMzioAAmEecB_LG_KgAAzC8"]
[Thu Sep 17 15:48:35.330834 2026] [security2:error] [pid 102783:tid 102977] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMMzioAAmEecB_LG_IgAAxSs"]
[Thu Sep 17 15:48:35.341229 2026] [security2:error] [pid 102783:tid 103026] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMMzioAAmEecB_LG_FAAAAPY"]
[Thu Sep 17 15:48:35.355627 2026] [security2:error] [pid 102783:tid 102976] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMMzioAAmEecB_LG-8AAAAMQ"]
[Thu Sep 17 15:48:35.366864 2026] [security2:error] [pid 102783:tid 103014] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-xQAAAOo"]
[Thu Sep 17 15:48:35.368639 2026] [security2:error] [pid 102783:tid 102968] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-2wAAALw"]
[Thu Sep 17 15:48:35.373311 2026] [security2:error] [pid 102783:tid 103030] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMMzioAAmEecB_LG_IAAA-ic"]
[Thu Sep 17 15:48:35.388732 2026] [security2:error] [pid 102783:tid 103038] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-ywABAgw"]
[Thu Sep 17 15:48:35.389117 2026] [security2:error] [pid 102783:tid 102961] [client 34.32.107.79:42932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxgM8zioAAmEecB_LHAMwAAALU"]
[Thu Sep 17 15:48:35.448256 2026] [security2:error] [pid 102783:tid 102944] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/uat/.env"] [unique_id "aqxgM8zioAAmEecB_LHANQAAAKQ"]
[Thu Sep 17 15:48:35.457995 2026] [security2:error] [pid 102783:tid 102962] [client 34.185.180.78:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/p.php"] [unique_id "aqxgM8zioAAmEecB_LHANgAAALY"]
[Thu Sep 17 15:48:35.460963 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgL8zioAAmEecB_LG-zwAA3BA"]
[Thu Sep 17 15:48:35.493047 2026] [security2:error] [pid 102783:tid 102853] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.git/config.bak"] [unique_id "aqxgM8zioAAmEecB_LHAOQAA-UU"]
[Thu Sep 17 15:48:35.619940 2026] [security2:error] [pid 102783:tid 102975] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/stage/.env"] [unique_id "aqxgM8zioAAmEecB_LHAPgAAAMM"]
[Thu Sep 17 15:48:35.663524 2026] [security2:error] [pid 102783:tid 102915] [client 122.8.45.84:14735] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgM8zioAAmEecB_LHARAAAAIc"]
[Thu Sep 17 15:48:35.663625 2026] [security2:error] [pid 102783:tid 102915] [client 122.8.45.84:14735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgM8zioAAmEecB_LHARAAAAIc"]
[Thu Sep 17 15:48:35.779835 2026] [security2:error] [pid 102783:tid 103003] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/development/.env"] [unique_id "aqxgM8zioAAmEecB_LHATAAAAN8"]
[Thu Sep 17 15:48:35.843721 2026] [security2:error] [pid 102783:tid 102933] [client 136.158.61.34:8916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgM8zioAAmEecB_LHATwAAAJk"]
[Thu Sep 17 15:48:35.843818 2026] [security2:error] [pid 102783:tid 102933] [client 136.158.61.34:8916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgM8zioAAmEecB_LHATwAAAJk"]
[Thu Sep 17 15:48:35.873937 2026] [security2:error] [pid 102783:tid 102930] [client 34.32.107.79:42948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxgM8zioAAmEecB_LHAUQAAAJY"]
[Thu Sep 17 15:48:35.900291 2026] [security2:error] [pid 102783:tid 102982] [client 34.185.180.78:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxgM8zioAAmEecB_LHAUwAAAMo"]
[Thu Sep 17 15:48:35.935432 2026] [security2:error] [pid 102783:tid 103008] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/production/.env"] [unique_id "aqxgM8zioAAmEecB_LHAVQAAAOQ"]
[Thu Sep 17 15:48:36.088707 2026] [security2:error] [pid 102783:tid 102966] [client 34.154.246.111:57868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.comicsutra.com"] [uri "/config/app/.env"] [unique_id "aqxgNMzioAAmEecB_LHAYgAAALo"]
[Thu Sep 17 15:48:36.098620 2026] [security2:error] [pid 102783:tid 102938] [client 177.199.203.95:33460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgM8zioAAmEecB_LHAVwAAnkk"]
[Thu Sep 17 15:48:36.245093 2026] [security2:error] [pid 102783:tid 102951] [client 34.154.246.111:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/phpinfo.php"] [unique_id "aqxgNMzioAAmEecB_LHAagAAAKs"]
[Thu Sep 17 15:48:36.274514 2026] [security2:error] [pid 102783:tid 102965] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMczioAAmEecB_LG_aAAAALk"]
[Thu Sep 17 15:48:36.337876 2026] [security2:error] [pid 102783:tid 103034] [client 34.32.107.79:42954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxgNMzioAAmEecB_LHAbwAAAP4"]
[Thu Sep 17 15:48:36.340711 2026] [security2:error] [pid 102783:tid 102947] [client 34.185.180.78:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxgNMzioAAmEecB_LHAcgAAAKc"]
[Thu Sep 17 15:48:36.341113 2026] [security2:error] [pid 102783:tid 103038] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHAAgABAj0"]
[Thu Sep 17 15:48:36.347740 2026] [security2:error] [pid 102783:tid 103033] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_5gAA_S4"]
[Thu Sep 17 15:48:36.416207 2026] [security2:error] [pid 102783:tid 103006] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHAAwAAAOI"]
[Thu Sep 17 15:48:36.617586 2026] [security2:error] [pid 102783:tid 102999] [client 122.8.45.84:18163] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgNMzioAAmEecB_LHAfAAAANs"]
[Thu Sep 17 15:48:36.617711 2026] [security2:error] [pid 102783:tid 102999] [client 122.8.45.84:18163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgNMzioAAmEecB_LHAfAAAANs"]
[Thu Sep 17 15:48:36.733558 2026] [security2:error] [pid 102783:tid 102936] [client 34.154.246.111:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/info.php"] [unique_id "aqxgNMzioAAmEecB_LHAhAAAAJw"]
[Thu Sep 17 15:48:36.798804 2026] [security2:error] [pid 102783:tid 102959] [client 34.185.180.78:60986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxgNMzioAAmEecB_LHAjQAAALM"]
[Thu Sep 17 15:48:36.798836 2026] [security2:error] [pid 102783:tid 102937] [client 34.32.107.79:42958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxgNMzioAAmEecB_LHAjgAAAJ0"]
[Thu Sep 17 15:48:37.095596 2026] [security2:error] [pid 102783:tid 102985] [client 4.240.114.86:54453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/connectors.php"] [unique_id "aqxgNczioAAmEecB_LHAlAAAAM0"], referer: binance.com
[Thu Sep 17 15:48:37.239597 2026] [security2:error] [pid 102783:tid 102953] [client 34.154.246.111:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/php.php"] [unique_id "aqxgNczioAAmEecB_LHAlwAAAK0"]
[Thu Sep 17 15:48:37.244346 2026] [security2:error] [pid 102783:tid 102996] [client 34.185.180.78:32770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxgNczioAAmEecB_LHAmQAAANg"]
[Thu Sep 17 15:48:37.263924 2026] [security2:error] [pid 102783:tid 102939] [client 34.32.107.79:42970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxgNczioAAmEecB_LHAnQAAAJ8"]
[Thu Sep 17 15:48:37.280800 2026] [security2:error] [pid 102783:tid 102925] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHAFgAAAJE"]
[Thu Sep 17 15:48:37.284475 2026] [security2:error] [pid 102783:tid 103038] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_-QABAno"]
[Thu Sep 17 15:48:37.291764 2026] [security2:error] [pid 102783:tid 103020] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHABwAAAPA"]
[Thu Sep 17 15:48:37.305644 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_7wAA-Tk"]
[Thu Sep 17 15:48:37.320245 2026] [security2:error] [pid 102783:tid 103022] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHAAQAAAPI"]
[Thu Sep 17 15:48:37.324015 2026] [security2:error] [pid 102783:tid 102840] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHADwAA-jg"]
[Thu Sep 17 15:48:37.336049 2026] [security2:error] [pid 102783:tid 103035] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHAEAAAAP8"]
[Thu Sep 17 15:48:37.341825 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_6gAA3Co"]
[Thu Sep 17 15:48:37.344855 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_0QAA-SQ"]
[Thu Sep 17 15:48:37.344902 2026] [security2:error] [pid 102783:tid 102984] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG__AAAzDw"]
[Thu Sep 17 15:48:37.393005 2026] [security2:error] [pid 102783:tid 102963] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHABgAAALc"]
[Thu Sep 17 15:48:37.414200 2026] [security2:error] [pid 102783:tid 102960] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_6QAAALQ"]
[Thu Sep 17 15:48:37.434575 2026] [security2:error] [pid 102783:tid 103033] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgM8zioAAmEecB_LHAQwAA_Uo"]
[Thu Sep 17 15:48:37.473088 2026] [security2:error] [pid 102783:tid 102978] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHADAAAAMY"]
[Thu Sep 17 15:48:37.508451 2026] [security2:error] [pid 102783:tid 102878] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxgNczioAAmEecB_LHArwABAl4"]
[Thu Sep 17 15:48:37.513715 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_-gAA3H4"]
[Thu Sep 17 15:48:37.559201 2026] [security2:error] [pid 102783:tid 103017] [client 122.8.45.84:10779] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgNczioAAmEecB_LHAswAAAO0"]
[Thu Sep 17 15:48:37.559361 2026] [security2:error] [pid 102783:tid 103017] [client 122.8.45.84:10779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgNczioAAmEecB_LHAswAAAO0"]
[Thu Sep 17 15:48:37.608278 2026] [security2:error] [pid 102783:tid 102877] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxgNczioAAmEecB_LHAtwABAl0"]
[Thu Sep 17 15:48:37.643493 2026] [security2:error] [pid 102783:tid 102891] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/id_rsa"] [unique_id "aqxgNczioAAmEecB_LHAuQAA-ms"]
[Thu Sep 17 15:48:37.693032 2026] [security2:error] [pid 102783:tid 102933] [client 34.185.180.78:32782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxgNczioAAmEecB_LHAvgAAAJk"]
[Thu Sep 17 15:48:37.738931 2026] [security2:error] [pid 102783:tid 103016] [client 34.154.246.111:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/i.php"] [unique_id "aqxgNczioAAmEecB_LHAwgAAAOw"]
[Thu Sep 17 15:48:37.760005 2026] [security2:error] [pid 102783:tid 102959] [client 114.119.137.220:29297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.worthtranslations.com"] [uri "/robots.txt"] [unique_id "aqxgNczioAAmEecB_LHAxAAAALM"], referer: http://www.worthtranslations.com/robots.txt
[Thu Sep 17 15:48:37.783813 2026] [security2:error] [pid 102783:tid 102913] [client 34.32.107.79:42976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/phpinfo.php.old"] [unique_id "aqxgNczioAAmEecB_LHAygAAAIU"]
[Thu Sep 17 15:48:38.147967 2026] [security2:error] [pid 102783:tid 102992] [client 34.185.180.78:32786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxgNszioAAmEecB_LHA2AAAANQ"]
[Thu Sep 17 15:48:38.234907 2026] [security2:error] [pid 102783:tid 102926] [client 34.154.246.111:58172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/pi.php"] [unique_id "aqxgNszioAAmEecB_LHA3AAAAJI"]
[Thu Sep 17 15:48:38.258374 2026] [security2:error] [pid 102783:tid 102859] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNMzioAAmEecB_LHAdgAA3Es"]
[Thu Sep 17 15:48:38.258459 2026] [security2:error] [pid 102783:tid 103022] [client 34.32.107.79:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/phpinfo.php~"] [unique_id "aqxgNszioAAmEecB_LHA3gAAAPI"]
[Thu Sep 17 15:48:38.285279 2026] [security2:error] [pid 102783:tid 103038] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_6wABAjI"]
[Thu Sep 17 15:48:38.289776 2026] [security2:error] [pid 102783:tid 103038] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgM8zioAAmEecB_LHAPAABAkg"]
[Thu Sep 17 15:48:38.301017 2026] [security2:error] [pid 102783:tid 103030] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNMzioAAmEecB_LHAdwAA-lI"]
[Thu Sep 17 15:48:38.305923 2026] [security2:error] [pid 102783:tid 102977] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgM8zioAAmEecB_LHANwAAxT8"]
[Thu Sep 17 15:48:38.308136 2026] [security2:error] [pid 102783:tid 103038] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_1gABAnQ"]
[Thu Sep 17 15:48:38.314911 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHAFQAA3D4"]
[Thu Sep 17 15:48:38.322638 2026] [security2:error] [pid 102783:tid 102922] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LG_5QAAAI4"]
[Thu Sep 17 15:48:38.322849 2026] [security2:error] [pid 102783:tid 102977] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgMszioAAmEecB_LHAAAAAxTQ"]
[Thu Sep 17 15:48:38.332608 2026] [security2:error] [pid 102783:tid 102829] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.git/config.bak"] [unique_id "aqxgM8zioAAmEecB_LHA4gAA6C0"]
[Thu Sep 17 15:48:38.539887 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:51685] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgNszioAAmEecB_LHA8gAAAI0"]
[Thu Sep 17 15:48:38.540000 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:51685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgNszioAAmEecB_LHA8gAAAI0"]
[Thu Sep 17 15:48:38.603325 2026] [security2:error] [pid 102783:tid 102961] [client 34.185.180.78:32788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxgNszioAAmEecB_LHA9AAAALU"]
[Thu Sep 17 15:48:38.710455 2026] [security2:error] [pid 102783:tid 103031] [client 34.32.107.79:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/info.php.bak"] [unique_id "aqxgNszioAAmEecB_LHA-wAAAPs"]
[Thu Sep 17 15:48:38.740876 2026] [security2:error] [pid 102783:tid 103028] [client 34.154.246.111:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/pinfo.php"] [unique_id "aqxgNszioAAmEecB_LHA_wAAAPg"]
[Thu Sep 17 15:48:39.161744 2026] [security2:error] [pid 102783:tid 102959] [client 34.32.107.79:52214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/phpinfo.php.save"] [unique_id "aqxgN8zioAAmEecB_LHBCgAAALM"]
[Thu Sep 17 15:48:39.198425 2026] [security2:error] [pid 102783:tid 102919] [client 34.185.180.78:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxgN8zioAAmEecB_LHBCwAAAIs"]
[Thu Sep 17 15:48:39.235755 2026] [security2:error] [pid 102783:tid 103026] [client 34.154.246.111:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/test.php"] [unique_id "aqxgN8zioAAmEecB_LHBDwAAAPY"]
[Thu Sep 17 15:48:39.315450 2026] [security2:error] [pid 102783:tid 103037] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAqQABAVk"]
[Thu Sep 17 15:48:39.337347 2026] [security2:error] [pid 102783:tid 103011] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAqwAA51s"]
[Thu Sep 17 15:48:39.357965 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAqAAA3Fc"]
[Thu Sep 17 15:48:39.383704 2026] [security2:error] [pid 102783:tid 102977] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAsQAAxWg"]
[Thu Sep 17 15:48:39.391030 2026] [security2:error] [pid 102783:tid 103011] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAyAAA5wE"]
[Thu Sep 17 15:48:39.398521 2026] [security2:error] [pid 102783:tid 102876] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAqgAAxVw"]
[Thu Sep 17 15:48:39.411324 2026] [security2:error] [pid 102783:tid 103030] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAtQAA-mU"]
[Thu Sep 17 15:48:39.413313 2026] [security2:error] [pid 102783:tid 103037] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAzQABAQQ"]
[Thu Sep 17 15:48:39.416767 2026] [security2:error] [pid 102783:tid 103037] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAuwABAXU"]
[Thu Sep 17 15:48:39.427350 2026] [security2:error] [pid 102783:tid 102977] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAvwAAxWo"]
[Thu Sep 17 15:48:39.444319 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAywAA3Ac"]
[Thu Sep 17 15:48:39.447738 2026] [security2:error] [pid 102783:tid 103011] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAsAAA52Y"]
[Thu Sep 17 15:48:39.450557 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAugAA3HA"]
[Thu Sep 17 15:48:39.456913 2026] [security2:error] [pid 102783:tid 102999] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgNczioAAmEecB_LHAtAAAANs"]
[Thu Sep 17 15:48:39.490367 2026] [security2:error] [pid 102783:tid 102937] [client 122.8.45.84:63913] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgN8zioAAmEecB_LHBGgAAAJ0"]
[Thu Sep 17 15:48:39.490475 2026] [security2:error] [pid 102783:tid 102937] [client 122.8.45.84:63913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgN8zioAAmEecB_LHBGgAAAJ0"]
[Thu Sep 17 15:48:39.495995 2026] [security2:error] [pid 102783:tid 102988] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgNszioAAmEecB_LHA6QAAANA"]
[Thu Sep 17 15:48:39.619191 2026] [security2:error] [pid 102783:tid 102914] [client 34.32.107.79:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxgN8zioAAmEecB_LHBJgAAAIY"]
[Thu Sep 17 15:48:39.632334 2026] [security2:error] [pid 102783:tid 102939] [client 34.185.180.78:32816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxgN8zioAAmEecB_LHBKAAAAJ8"]
[Thu Sep 17 15:48:40.075574 2026] [security2:error] [pid 102783:tid 103033] [client 34.185.180.78:32820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxgOMzioAAmEecB_LHBQAAAAP0"]
[Thu Sep 17 15:48:40.077127 2026] [security2:error] [pid 102783:tid 102983] [client 74.7.241.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lemuspools.com"] [uri "/index.php"] [unique_id "aqxgNszioAAmEecB_LHA_QAAAMs"]
[Thu Sep 17 15:48:40.077411 2026] [security2:error] [pid 102783:tid 102951] [client 34.32.107.79:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxgOMzioAAmEecB_LHBQQAAAKs"]
[Thu Sep 17 15:48:40.079020 2026] [security2:error] [pid 102783:tid 102945] [client 74.7.241.156:59088] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lemuspools.com"] [uri "/robots.txt"] [unique_id "aqxgNszioAAmEecB_LHA9wAApRE"]
[Thu Sep 17 15:48:40.130454 2026] [security2:error] [pid 102783:tid 103002] [client 192.178.6.3:64357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxgOMzioAAmEecB_LHBQwAAAN4"]
[Thu Sep 17 15:48:40.249692 2026] [security2:error] [pid 102783:tid 102928] [client 4.240.114.86:56040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/fonts.php"] [unique_id "aqxgOMzioAAmEecB_LHBSAAAAJQ"], referer: binance.com
[Thu Sep 17 15:48:40.264526 2026] [security2:error] [pid 102783:tid 103000] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNszioAAmEecB_LHA7gAA3BQ"]
[Thu Sep 17 15:48:40.284597 2026] [security2:error] [pid 102783:tid 102960] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgNszioAAmEecB_LHA7AAAALQ"]
[Thu Sep 17 15:48:40.309998 2026] [security2:error] [pid 102783:tid 103006] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgNszioAAmEecB_LHA6wAAAOI"]
[Thu Sep 17 15:48:40.316565 2026] [security2:error] [pid 102783:tid 102879] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNszioAAmEecB_LHA7QAA518"]
[Thu Sep 17 15:48:40.327924 2026] [security2:error] [pid 102783:tid 102946] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgNszioAAmEecB_LHA7wAApng"]
[Thu Sep 17 15:48:40.351890 2026] [security2:error] [pid 102783:tid 102948] [client 34.154.246.111:58218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/p.php"] [unique_id "aqxgOMzioAAmEecB_LHBUAAAAKg"]
[Thu Sep 17 15:48:40.402702 2026] [fcgid:warn] [pid 102783:tid 102940] (70014)End of file found: [client 152.32.171.73:57414] mod_fcgid: can't get data from http client
[Thu Sep 17 15:48:40.455697 2026] [security2:error] [pid 102783:tid 103031] [client 122.8.45.84:9173] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOMzioAAmEecB_LHBWAAAAPs"]
[Thu Sep 17 15:48:40.455860 2026] [security2:error] [pid 102783:tid 103031] [client 122.8.45.84:9173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOMzioAAmEecB_LHBWAAAAPs"]
[Thu Sep 17 15:48:40.521169 2026] [security2:error] [pid 102783:tid 102920] [client 34.185.180.78:32822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxgOMzioAAmEecB_LHBXQAAAIw"]
[Thu Sep 17 15:48:40.534173 2026] [security2:error] [pid 102783:tid 103034] [client 34.32.107.79:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxgOMzioAAmEecB_LHBXgAAAP4"]
[Thu Sep 17 15:48:40.814156 2026] [security2:error] [pid 102783:tid 102938] [client 143.105.152.240:13044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgOMzioAAmEecB_LHBaQAAAJ4"]
[Thu Sep 17 15:48:40.814244 2026] [security2:error] [pid 102783:tid 102938] [client 143.105.152.240:13044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgOMzioAAmEecB_LHBaQAAAJ4"]
[Thu Sep 17 15:48:40.887277 2026] [security2:error] [pid 102783:tid 102994] [client 34.154.246.111:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/debug.php"] [unique_id "aqxgOMzioAAmEecB_LHBbwAAANY"]
[Thu Sep 17 15:48:40.987163 2026] [security2:error] [pid 102783:tid 103022] [client 34.185.180.78:39184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxgOMzioAAmEecB_LHBdAAAAPI"]
[Thu Sep 17 15:48:40.999763 2026] [security2:error] [pid 102783:tid 102925] [client 34.32.107.79:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxgOMzioAAmEecB_LHBdwAAAJE"]
[Thu Sep 17 15:48:41.035262 2026] [security2:error] [pid 102783:tid 102921] [client 169.58.197.251:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/utf8.php"] [unique_id "aqxgOczioAAmEecB_LHBeQAAAI0"], referer: binance.com
[Thu Sep 17 15:48:41.086325 2026] [security2:error] [pid 102783:tid 103039] [client 14.96.156.146:55988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBewAAAQM"]
[Thu Sep 17 15:48:41.086421 2026] [security2:error] [pid 102783:tid 103039] [client 14.96.156.146:55988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBewAAAQM"]
[Thu Sep 17 15:48:41.314415 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBKQAAoh0"]
[Thu Sep 17 15:48:41.315890 2026] [security2:error] [pid 102783:tid 103011] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBIgAA5xo"]
[Thu Sep 17 15:48:41.339371 2026] [security2:error] [pid 102783:tid 103011] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBJQAA5wM"]
[Thu Sep 17 15:48:41.341792 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBHAAAoiI"]
[Thu Sep 17 15:48:41.345634 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBIAAAohg"]
[Thu Sep 17 15:48:41.347918 2026] [security2:error] [pid 102783:tid 103038] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBOgABAn0"]
[Thu Sep 17 15:48:41.350852 2026] [security2:error] [pid 102783:tid 103004] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBOQAA4B4"]
[Thu Sep 17 15:48:41.351817 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBHQAAsAk"]
[Thu Sep 17 15:48:41.366598 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBIwAAohk"]
[Thu Sep 17 15:48:41.367714 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBHwAAsAs"]
[Thu Sep 17 15:48:41.370282 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBJAAAsBY"]
[Thu Sep 17 15:48:41.388045 2026] [security2:error] [pid 102783:tid 103011] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBMAAA53s"]
[Thu Sep 17 15:48:41.390001 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBLQAAsCA"]
[Thu Sep 17 15:48:41.402214 2026] [security2:error] [pid 102783:tid 102957] [client 34.154.246.111:58232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxgOczioAAmEecB_LHBjQAAALE"]
[Thu Sep 17 15:48:41.417783 2026] [security2:error] [pid 102783:tid 103007] [client 122.8.45.84:22715] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBjwAAAOM"]
[Thu Sep 17 15:48:41.417919 2026] [security2:error] [pid 102783:tid 103007] [client 122.8.45.84:22715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBjwAAAOM"]
[Thu Sep 17 15:48:41.424229 2026] [security2:error] [pid 102783:tid 102924] [client 34.185.180.78:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxgOczioAAmEecB_LHBkAAAAJA"]
[Thu Sep 17 15:48:41.437906 2026] [security2:error] [pid 102783:tid 103008] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgOMzioAAmEecB_LHBUQAAAOQ"]
[Thu Sep 17 15:48:41.463376 2026] [security2:error] [pid 102783:tid 102934] [client 34.32.107.79:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxgOczioAAmEecB_LHBkwAAAJo"]
[Thu Sep 17 15:48:41.469050 2026] [security2:error] [pid 102783:tid 102949] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgOMzioAAmEecB_LHBVAAAAKk"]
[Thu Sep 17 15:48:41.498791 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOMzioAAmEecB_LHBXAAAsHM"]
[Thu Sep 17 15:48:41.501991 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOMzioAAmEecB_LHBWwAAoiM"]
[Thu Sep 17 15:48:41.508815 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOMzioAAmEecB_LHBWgAAohw"]
[Thu Sep 17 15:48:41.524341 2026] [security2:error] [pid 102783:tid 102838] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/config.php"] [unique_id "aqxgOczioAAmEecB_LHBmwAAojY"]
[Thu Sep 17 15:48:41.566623 2026] [security2:error] [pid 102783:tid 102964] [client 148.227.75.216:45919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBoAAAALg"]
[Thu Sep 17 15:48:41.566739 2026] [security2:error] [pid 102783:tid 102964] [client 148.227.75.216:45919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBoAAAALg"]
[Thu Sep 17 15:48:41.751515 2026] [security2:error] [pid 102783:tid 103006] [client 177.44.133.72:50681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBsAAAAOI"]
[Thu Sep 17 15:48:41.751671 2026] [security2:error] [pid 102783:tid 103006] [client 177.44.133.72:50681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgOczioAAmEecB_LHBsAAAAOI"]
[Thu Sep 17 15:48:41.946745 2026] [security2:error] [pid 102783:tid 103030] [client 34.32.107.79:52270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/www/phpinfo.php"] [unique_id "aqxgOczioAAmEecB_LHBtwAAAPo"]
[Thu Sep 17 15:48:41.991325 2026] [security2:error] [pid 102783:tid 103036] [client 34.154.246.111:58234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/test/phpinfo.php"] [unique_id "aqxgOczioAAmEecB_LHBuQAAAQA"]
[Thu Sep 17 15:48:42.176953 2026] [security2:error] [pid 102783:tid 102994] [client 34.185.180.78:39198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxgOszioAAmEecB_LHBwgAAANY"]
[Thu Sep 17 15:48:42.390613 2026] [security2:error] [pid 102783:tid 102926] [client 122.8.45.84:36157] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOszioAAmEecB_LHBzAAAAJI"]
[Thu Sep 17 15:48:42.390865 2026] [security2:error] [pid 102783:tid 102926] [client 122.8.45.84:36157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgOszioAAmEecB_LHBzAAAAJI"]
[Thu Sep 17 15:48:42.400401 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBkQAA6AY"]
[Thu Sep 17 15:48:42.421785 2026] [security2:error] [pid 102783:tid 102921] [client 34.32.107.79:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxgOszioAAmEecB_LHB0gAAAI0"]
[Thu Sep 17 15:48:42.423698 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBlgAA6C0"]
[Thu Sep 17 15:48:42.507173 2026] [security2:error] [pid 102783:tid 103033] [client 34.154.246.111:58244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxgOszioAAmEecB_LHB1QAAAP0"]
[Thu Sep 17 15:48:42.613068 2026] [security2:error] [pid 102783:tid 102936] [client 34.185.180.78:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxgOszioAAmEecB_LHB2gAAAJw"]
[Thu Sep 17 15:48:42.800111 2026] [security2:error] [pid 102783:tid 102957] [client 4.240.114.86:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "aqxgOszioAAmEecB_LHB4QAAALE"], referer: binance.com
[Thu Sep 17 15:48:42.872747 2026] [security2:error] [pid 102783:tid 102974] [client 34.32.107.79:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxgOszioAAmEecB_LHB5AAAAMI"]
[Thu Sep 17 15:48:42.992529 2026] [security2:error] [pid 102783:tid 103007] [client 34.154.246.111:58248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/old/phpinfo.php"] [unique_id "aqxgOszioAAmEecB_LHB6AAAAOM"]
[Thu Sep 17 15:48:43.052214 2026] [security2:error] [pid 102783:tid 102955] [client 34.185.180.78:39220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxgO8zioAAmEecB_LHB7AAAAK8"]
[Thu Sep 17 15:48:43.264985 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBlQAAsDE"]
[Thu Sep 17 15:48:43.280303 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBlwAAoig"]
[Thu Sep 17 15:48:43.304109 2026] [security2:error] [pid 102783:tid 102981] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBmgAAyWI"]
[Thu Sep 17 15:48:43.317563 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBngAAokE"]
[Thu Sep 17 15:48:43.336414 2026] [security2:error] [pid 102783:tid 102981] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBnAAAyWQ"]
[Thu Sep 17 15:48:43.337760 2026] [security2:error] [pid 102783:tid 102977] [client 34.32.107.79:52290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/site/phpinfo.php"] [unique_id "aqxgO8zioAAmEecB_LHB9gAAAMU"]
[Thu Sep 17 15:48:43.372447 2026] [security2:error] [pid 102783:tid 102934] [client 122.8.45.84:23213] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgO8zioAAmEecB_LHB-QAAAJo"]
[Thu Sep 17 15:48:43.372861 2026] [security2:error] [pid 102783:tid 102934] [client 122.8.45.84:23213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgO8zioAAmEecB_LHB-QAAAJo"]
[Thu Sep 17 15:48:43.376955 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBmQAAsDU"]
[Thu Sep 17 15:48:43.378774 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOszioAAmEecB_LHBvAAAsAw"]
[Thu Sep 17 15:48:43.393186 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBpwAAsEc"]
[Thu Sep 17 15:48:43.397402 2026] [security2:error] [pid 102783:tid 102981] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBqQAAySE"]
[Thu Sep 17 15:48:43.399819 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBpAAAsHw"]
[Thu Sep 17 15:48:43.400928 2026] [security2:error] [pid 102783:tid 102953] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBtAAArRM"]
[Thu Sep 17 15:48:43.409011 2026] [security2:error] [pid 102783:tid 102981] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOszioAAmEecB_LHBvQAAyUQ"]
[Thu Sep 17 15:48:43.424724 2026] [security2:error] [pid 102783:tid 102956] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBqAAAsCY"]
[Thu Sep 17 15:48:43.426161 2026] [security2:error] [pid 102783:tid 102942] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBrQAAohI"]
[Thu Sep 17 15:48:43.434381 2026] [security2:error] [pid 102783:tid 102981] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBnwAAyRs"]
[Thu Sep 17 15:48:43.437008 2026] [security2:error] [pid 102783:tid 102845] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/config/aws.php"] [unique_id "aqxgO8zioAAmEecB_LHB-wAAyT0"]
[Thu Sep 17 15:48:43.444881 2026] [security2:error] [pid 102783:tid 102981] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgOczioAAmEecB_LHBpQAAySs"]
[Thu Sep 17 15:48:43.473342 2026] [security2:error] [pid 102783:tid 102863] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/config/stripe.php"] [unique_id "aqxgO8zioAAmEecB_LHB_gAA_E8"]
[Thu Sep 17 15:48:43.480336 2026] [security2:error] [pid 102783:tid 102965] [client 34.154.246.111:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxgO8zioAAmEecB_LHCAAAAALk"]
[Thu Sep 17 15:48:43.487050 2026] [security2:error] [pid 102783:tid 102939] [client 34.185.180.78:39232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxgO8zioAAmEecB_LHCAQAAAJ8"]
[Thu Sep 17 15:48:43.487427 2026] [security2:error] [pid 102783:tid 102790] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgN8zioAAmEecB_LHBzQAA6AY"]
[Thu Sep 17 15:48:43.491152 2026] [security2:error] [pid 102783:tid 102865] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/config/mail.php"] [unique_id "aqxgO8zioAAmEecB_LHCAgAAj1E"]
[Thu Sep 17 15:48:43.492734 2026] [security2:error] [pid 102783:tid 102869] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/config/config.inc.php"] [unique_id "aqxgO8zioAAmEecB_LHCAwAAhlU"]
[Thu Sep 17 15:48:43.504139 2026] [security2:error] [pid 102783:tid 102829] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgOMzioAAmEecB_LHB0wAA6C0"]
[Thu Sep 17 15:48:43.504138 2026] [security2:error] [pid 102783:tid 102854] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgOMzioAAmEecB_LHBzwAA6EY"]
[Thu Sep 17 15:48:43.564332 2026] [security2:error] [pid 102783:tid 102784] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/config/nexmo.php"] [unique_id "aqxgO8zioAAmEecB_LHCDAAA-QA"]
[Thu Sep 17 15:48:43.604253 2026] [security2:error] [pid 102783:tid 102911] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxgO8zioAAmEecB_LHCFgAA-X8"]
[Thu Sep 17 15:48:43.701510 2026] [security2:error] [pid 102783:tid 102864] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxgO8zioAAmEecB_LHCJAAA-VA"]
[Thu Sep 17 15:48:43.811571 2026] [security2:error] [pid 102783:tid 103035] [client 34.32.107.79:52302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxgO8zioAAmEecB_LHCKgAAAP8"]
[Thu Sep 17 15:48:43.828052 2026] [security2:error] [pid 102783:tid 102991] [client 79.116.89.151:52221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgO8zioAAmEecB_LHCLAAAANM"]
[Thu Sep 17 15:48:43.828650 2026] [security2:error] [pid 102783:tid 102991] [client 79.116.89.151:52221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgO8zioAAmEecB_LHCLAAAANM"]
[Thu Sep 17 15:48:43.919089 2026] [security2:error] [pid 102783:tid 102951] [client 34.185.180.78:39240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxgO8zioAAmEecB_LHCMAAAAKs"]
[Thu Sep 17 15:48:43.960557 2026] [security2:error] [pid 102783:tid 103033] [client 34.154.246.111:58272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/public/phpinfo.php"] [unique_id "aqxgO8zioAAmEecB_LHCMQAAAP0"]
[Thu Sep 17 15:48:44.011334 2026] [security2:error] [pid 102783:tid 102903] [remote 216.73.217.142:54901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zphiblgz.org"] [uri "/Jiv/sitemap_product_304.xml"] [unique_id "aqxgPMzioAAmEecB_LHCMwAAnHc"]
[Thu Sep 17 15:48:44.262932 2026] [security2:error] [pid 102783:tid 102929] [client 34.32.107.79:52304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxgPMzioAAmEecB_LHCPAAAAJU"]
[Thu Sep 17 15:48:44.290393 2026] [security2:error] [pid 102783:tid 102916] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgOszioAAmEecB_LHB1AAAAIg"]
[Thu Sep 17 15:48:44.345005 2026] [security2:error] [pid 102783:tid 102928] [client 122.8.45.84:28479] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgPMzioAAmEecB_LHCQQAAAJQ"]
[Thu Sep 17 15:48:44.345262 2026] [security2:error] [pid 102783:tid 102928] [client 122.8.45.84:28479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgPMzioAAmEecB_LHCQQAAAJQ"]
[Thu Sep 17 15:48:44.354908 2026] [security2:error] [pid 102783:tid 102976] [client 34.185.180.78:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxgPMzioAAmEecB_LHCQwAAAMQ"]
[Thu Sep 17 15:48:44.435453 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHB_AAA5S4"]
[Thu Sep 17 15:48:44.720431 2026] [security2:error] [pid 102783:tid 102942] [client 34.32.107.79:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxgPMzioAAmEecB_LHCZQAAAKI"]
[Thu Sep 17 15:48:44.794281 2026] [security2:error] [pid 102783:tid 102914] [client 34.185.180.78:39268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxgPMzioAAmEecB_LHCaQAAAIY"]
[Thu Sep 17 15:48:44.939419 2026] [security2:error] [pid 102783:tid 102915] [client 34.154.246.111:58294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/php-info.php"] [unique_id "aqxgPMzioAAmEecB_LHCbgAAAIc"]
[Thu Sep 17 15:48:45.170184 2026] [security2:error] [pid 102783:tid 103039] [client 34.32.107.79:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/core/phpinfo.php"] [unique_id "aqxgPczioAAmEecB_LHCeQAAAQM"]
[Thu Sep 17 15:48:45.236207 2026] [security2:error] [pid 102783:tid 102926] [client 34.185.180.78:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxgPczioAAmEecB_LHCfAAAAJI"]
[Thu Sep 17 15:48:45.326829 2026] [security2:error] [pid 102783:tid 102986] [client 122.8.45.84:56193] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgPczioAAmEecB_LHCgQAAAM4"]
[Thu Sep 17 15:48:45.327031 2026] [security2:error] [pid 102783:tid 102986] [client 122.8.45.84:56193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgPczioAAmEecB_LHCgQAAAM4"]
[Thu Sep 17 15:48:45.331645 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCGAAA1nE"]
[Thu Sep 17 15:48:45.339716 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCHAAA5Tc"]
[Thu Sep 17 15:48:45.339775 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCDgAA1m0"]
[Thu Sep 17 15:48:45.364012 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCLwAA1ms"]
[Thu Sep 17 15:48:45.368465 2026] [security2:error] [pid 102783:tid 103018] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCDQAAAO4"]
[Thu Sep 17 15:48:45.372223 2026] [security2:error] [pid 102783:tid 103026] [client 4.240.114.86:58614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/https-detection.php"] [unique_id "aqxgPczioAAmEecB_LHCgwAAAPY"], referer: binance.com
[Thu Sep 17 15:48:45.437583 2026] [security2:error] [pid 102783:tid 102936] [client 34.154.246.111:58304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/phpversion.php"] [unique_id "aqxgPczioAAmEecB_LHCiAAAAJw"]
[Thu Sep 17 15:48:45.632988 2026] [security2:error] [pid 102783:tid 102993] [client 34.32.107.79:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.107.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yourstrulymaria.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxgPczioAAmEecB_LHClAAAANU"]
[Thu Sep 17 15:48:45.674433 2026] [security2:error] [pid 102783:tid 102976] [client 34.185.180.78:39294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxgPczioAAmEecB_LHClwAAAMQ"]
[Thu Sep 17 15:48:45.914746 2026] [security2:error] [pid 102783:tid 103016] [client 34.154.246.111:58318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/_phpinfo.php"] [unique_id "aqxgPczioAAmEecB_LHCoAAAAOw"]
[Thu Sep 17 15:48:46.127411 2026] [security2:error] [pid 102783:tid 102972] [client 34.185.180.78:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxgPszioAAmEecB_LHCqQAAAMA"]
[Thu Sep 17 15:48:46.270418 2026] [security2:error] [pid 102783:tid 102966] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgPMzioAAmEecB_LHCQgAAALo"]
[Thu Sep 17 15:48:46.356814 2026] [security2:error] [pid 102783:tid 102965] [client 122.8.45.84:63429] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgPszioAAmEecB_LHCuwAAALk"]
[Thu Sep 17 15:48:46.357008 2026] [security2:error] [pid 102783:tid 102965] [client 122.8.45.84:63429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgPszioAAmEecB_LHCuwAAALk"]
[Thu Sep 17 15:48:46.363409 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCFAAA5So"]
[Thu Sep 17 15:48:46.383808 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCKwAA1l0"]
[Thu Sep 17 15:48:46.387451 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCCgAA-Xo"]
[Thu Sep 17 15:48:46.395801 2026] [security2:error] [pid 102783:tid 102997] [client 34.154.246.111:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/old_phpinfo.php"] [unique_id "aqxgPszioAAmEecB_LHCvQAAANk"]
[Thu Sep 17 15:48:46.435697 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCGwAA1jw"]
[Thu Sep 17 15:48:46.575341 2026] [security2:error] [pid 102783:tid 102926] [client 34.185.180.78:39310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxgPszioAAmEecB_LHCywAAAJI"]
[Thu Sep 17 15:48:46.865818 2026] [security2:error] [pid 102783:tid 102941] [client 34.154.246.111:54404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/server-info.php"] [unique_id "aqxgPszioAAmEecB_LHC3QAAAKE"]
[Thu Sep 17 15:48:47.036370 2026] [security2:error] [pid 102783:tid 102937] [client 34.185.180.78:39312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxgP8zioAAmEecB_LHC6AAAAJ0"]
[Thu Sep 17 15:48:47.094744 2026] [security2:error] [pid 102783:tid 102919] [client 189.89.29.111:53416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgP8zioAAmEecB_LHC4gAAixo"]
[Thu Sep 17 15:48:47.130187 2026] [security2:error] [pid 102783:tid 103020] [client 34.94.22.173:54826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxgP8zioAAmEecB_LHC6wAAAPA"]
[Thu Sep 17 15:48:47.279562 2026] [security2:error] [pid 102783:tid 102840] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCEwAA5Tg"]
[Thu Sep 17 15:48:47.283285 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCJwAA1l4"]
[Thu Sep 17 15:48:47.305860 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCGgAA1iQ"]
[Thu Sep 17 15:48:47.318687 2026] [security2:error] [pid 102783:tid 102952] [client 122.8.45.84:42265] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgP8zioAAmEecB_LHC9QAAAKw"]
[Thu Sep 17 15:48:47.318874 2026] [security2:error] [pid 102783:tid 102952] [client 122.8.45.84:42265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgP8zioAAmEecB_LHC9QAAAKw"]
[Thu Sep 17 15:48:47.354423 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCHgAA5VM"]
[Thu Sep 17 15:48:47.357228 2026] [security2:error] [pid 102783:tid 102958] [client 34.154.246.111:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/server-status.php"] [unique_id "aqxgP8zioAAmEecB_LHC9gAAALI"]
[Thu Sep 17 15:48:47.361265 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCDwAA1jk"]
[Thu Sep 17 15:48:47.402755 2026] [security2:error] [pid 102783:tid 102972] [client 34.94.22.173:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/info.php"] [unique_id "aqxgP8zioAAmEecB_LHC-QAAAMA"]
[Thu Sep 17 15:48:47.407150 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHCHwAA1ko"]
[Thu Sep 17 15:48:47.427271 2026] [security2:error] [pid 102783:tid 103006] [client 208.109.2.10:22708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bluetech.com"] [uri "/wp-login.php"] [unique_id "aqxgP8zioAAmEecB_LHC7AAAAOI"], referer: https://bluetech.com/wp-admin/admin.php?page=gf_entries
[Thu Sep 17 15:48:47.485142 2026] [security2:error] [pid 102783:tid 102984] [client 34.185.180.78:39314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxgP8zioAAmEecB_LHC_AAAAMw"]
[Thu Sep 17 15:48:47.548230 2026] [security2:error] [pid 102783:tid 103017] [client 34.94.22.173:54854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/php.php"] [unique_id "aqxgP8zioAAmEecB_LHDAAAAAO0"]
[Thu Sep 17 15:48:47.646807 2026] [security2:error] [pid 102783:tid 102968] [client 208.109.2.10:22724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bluetech.com"] [uri "/wp-admin/admin.php"] [unique_id "aqxgP8zioAAmEecB_LHC_wAAALw"], referer: https://bluetech.com/wp-admin/admin.php?page=gf_entries
[Thu Sep 17 15:48:47.797303 2026] [security2:error] [pid 102783:tid 102970] [client 34.94.22.173:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/i.php"] [unique_id "aqxgP8zioAAmEecB_LHDDgAAAL4"]
[Thu Sep 17 15:48:47.833951 2026] [security2:error] [pid 102783:tid 102934] [client 169.58.197.251:59828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/view-config.php"] [unique_id "aqxgP8zioAAmEecB_LHDEgAAAJo"], referer: binance.com
[Thu Sep 17 15:48:47.941364 2026] [security2:error] [pid 102783:tid 102999] [client 34.185.180.78:39322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxgP8zioAAmEecB_LHDHAAAANs"]
[Thu Sep 17 15:48:48.066202 2026] [security2:error] [pid 102783:tid 102940] [client 34.94.22.173:54876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxgQMzioAAmEecB_LHDIwAAAKA"]
[Thu Sep 17 15:48:48.097487 2026] [security2:error] [pid 102783:tid 102947] [client 136.158.61.34:10047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQMzioAAmEecB_LHDJQAAAKc"]
[Thu Sep 17 15:48:48.097633 2026] [security2:error] [pid 102783:tid 102947] [client 136.158.61.34:10047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQMzioAAmEecB_LHDJQAAAKc"]
[Thu Sep 17 15:48:48.212981 2026] [security2:error] [pid 102783:tid 102977] [client 34.94.22.173:54880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxgQMzioAAmEecB_LHDKwAAAMU"]
[Thu Sep 17 15:48:48.299757 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPMzioAAmEecB_LHCXAAA-QI"]
[Thu Sep 17 15:48:48.305360 2026] [security2:error] [pid 102783:tid 102948] [client 122.8.45.84:56053] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQMzioAAmEecB_LHDLwAAAKg"]
[Thu Sep 17 15:48:48.305561 2026] [security2:error] [pid 102783:tid 102948] [client 122.8.45.84:56053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQMzioAAmEecB_LHDLwAAAKg"]
[Thu Sep 17 15:48:48.322628 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgO8zioAAmEecB_LHB_wAA5Ts"]
[Thu Sep 17 15:48:48.335855 2026] [security2:error] [pid 102783:tid 103027] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCuQAAAPc"]
[Thu Sep 17 15:48:48.344125 2026] [security2:error] [pid 102783:tid 102829] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgOszioAAmEecB_LHCggAA6C0"]
[Thu Sep 17 15:48:48.353033 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPczioAAmEecB_LHCjgAA5QQ"]
[Thu Sep 17 15:48:48.396303 2026] [security2:error] [pid 102783:tid 103019] [client 34.185.180.78:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxgQMzioAAmEecB_LHDNAAAAO8"]
[Thu Sep 17 15:48:48.407240 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPczioAAmEecB_LHCjQAA5WU"]
[Thu Sep 17 15:48:48.411203 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPczioAAmEecB_LHCkAAA1mo"]
[Thu Sep 17 15:48:48.428408 2026] [security2:error] [pid 102783:tid 102914] [client 34.94.22.173:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/test.php"] [unique_id "aqxgQMzioAAmEecB_LHDNQAAAIY"]
[Thu Sep 17 15:48:48.441400 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCwAAA-RQ"]
[Thu Sep 17 15:48:48.445583 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCxwAA5Xg"]
[Thu Sep 17 15:48:48.447416 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCzAAA5RU"]
[Thu Sep 17 15:48:48.721548 2026] [security2:error] [pid 102783:tid 102913] [client 34.94.22.173:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/p.php"] [unique_id "aqxgQMzioAAmEecB_LHDUAAAAIU"]
[Thu Sep 17 15:48:48.843254 2026] [security2:error] [pid 102783:tid 103017] [client 34.185.180.78:39340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxgQMzioAAmEecB_LHDUwAAAO0"]
[Thu Sep 17 15:48:48.908540 2026] [security2:error] [pid 102783:tid 102952] [client 43.163.26.168:54636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDOwAArCc"]
[Thu Sep 17 15:48:48.953391 2026] [security2:error] [pid 102783:tid 102955] [client 34.94.22.173:54918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxgQMzioAAmEecB_LHDVQAAAK8"]
[Thu Sep 17 15:48:49.028797 2026] [security2:error] [pid 102783:tid 102983] [client 34.154.246.111:54452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxgQczioAAmEecB_LHDWgAAAMs"]
[Thu Sep 17 15:48:49.153754 2026] [security2:error] [pid 102783:tid 102920] [client 34.94.22.173:54920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDWwAAAIw"]
[Thu Sep 17 15:48:49.280565 2026] [security2:error] [pid 102783:tid 102951] [client 122.8.45.84:19427] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQczioAAmEecB_LHDYwAAAKs"]
[Thu Sep 17 15:48:49.280732 2026] [security2:error] [pid 102783:tid 102951] [client 122.8.45.84:19427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQczioAAmEecB_LHDYwAAAKs"]
[Thu Sep 17 15:48:49.284904 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCzQAA-XI"]
[Thu Sep 17 15:48:49.287732 2026] [security2:error] [pid 102783:tid 102945] [client 34.185.180.78:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDZAAAAKU"]
[Thu Sep 17 15:48:49.289439 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCxAAA-V8"]
[Thu Sep 17 15:48:49.300618 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCzgAA1iU"]
[Thu Sep 17 15:48:49.314123 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCyQAA-R8"]
[Thu Sep 17 15:48:49.323923 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPczioAAmEecB_LHCjwAA-XU"]
[Thu Sep 17 15:48:49.339296 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHC0gAA1m8"]
[Thu Sep 17 15:48:49.358642 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHC0wAA-Sw"]
[Thu Sep 17 15:48:49.383190 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHC2AAA5R0"]
[Thu Sep 17 15:48:49.383601 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHCyAAA1mM"]
[Thu Sep 17 15:48:49.386463 2026] [security2:error] [pid 102783:tid 102924] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgP8zioAAmEecB_LHDGQAAkDM"]
[Thu Sep 17 15:48:49.393656 2026] [security2:error] [pid 102783:tid 102936] [client 34.94.22.173:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDZQAAAJw"]
[Thu Sep 17 15:48:49.475626 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDSgAA1jE"]
[Thu Sep 17 15:48:49.483252 2026] [security2:error] [pid 102783:tid 102998] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDOAAAANo"]
[Thu Sep 17 15:48:49.501930 2026] [security2:error] [pid 102783:tid 102979] [client 4.240.114.86:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/https-migration.php"] [unique_id "aqxgQczioAAmEecB_LHDaAAAAMc"], referer: binance.com
[Thu Sep 17 15:48:49.534064 2026] [security2:error] [pid 102783:tid 102940] [client 34.154.246.111:54462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDawAAAKA"]
[Thu Sep 17 15:48:49.552198 2026] [security2:error] [pid 102783:tid 102942] [client 160.179.66.196:56588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgQczioAAmEecB_LHDZgAAokc"]
[Thu Sep 17 15:48:49.632061 2026] [security2:error] [pid 102783:tid 102941] [client 34.94.22.173:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDdAAAAKE"]
[Thu Sep 17 15:48:49.756565 2026] [security2:error] [pid 102783:tid 102976] [client 34.185.180.78:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDeAAAAMQ"]
[Thu Sep 17 15:48:49.892884 2026] [security2:error] [pid 102783:tid 102914] [client 34.94.22.173:54958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDggAAAIY"]
[Thu Sep 17 15:48:49.957365 2026] [security2:error] [pid 102783:tid 103025] [client 34.166.149.166:40118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxgQczioAAmEecB_LHDgwAAAPU"]
[Thu Sep 17 15:48:50.016059 2026] [security2:error] [pid 102783:tid 102943] [client 34.154.246.111:54472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxgQszioAAmEecB_LHDhAAAAKM"]
[Thu Sep 17 15:48:50.035806 2026] [security2:error] [pid 102783:tid 103031] [client 34.94.22.173:54974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/tmp/phpinfo.php"] [unique_id "aqxgQszioAAmEecB_LHDhwAAAPs"]
[Thu Sep 17 15:48:50.195843 2026] [security2:error] [pid 102783:tid 103006] [client 34.185.180.78:39362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxgQszioAAmEecB_LHDiQAAAOI"]
[Thu Sep 17 15:48:50.245787 2026] [security2:error] [pid 102783:tid 102996] [client 122.8.45.84:32001] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQszioAAmEecB_LHDjAAAANg"]
[Thu Sep 17 15:48:50.245891 2026] [security2:error] [pid 102783:tid 102996] [client 122.8.45.84:32001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQszioAAmEecB_LHDjAAAANg"]
[Thu Sep 17 15:48:50.257892 2026] [security2:error] [pid 102783:tid 102861] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDQQAA-U0"]
[Thu Sep 17 15:48:50.277913 2026] [security2:error] [pid 102783:tid 103021] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDOQAAAPE"]
[Thu Sep 17 15:48:50.277913 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDQgAA-Uw"]
[Thu Sep 17 15:48:50.278139 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDSAAA-Uk"]
[Thu Sep 17 15:48:50.278198 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDRQAA1kM"]
[Thu Sep 17 15:48:50.282580 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDQAAA5RA"]
[Thu Sep 17 15:48:50.282867 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQMzioAAmEecB_LHDSQAA5VQ"]
[Thu Sep 17 15:48:50.320813 2026] [security2:error] [pid 102783:tid 103023] [client 34.94.22.173:54980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxgQszioAAmEecB_LHDjgAAAPM"]
[Thu Sep 17 15:48:50.343154 2026] [security2:error] [pid 102783:tid 102853] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/config/nexmo.php"] [unique_id "aqxgP8zioAAmEecB_LHDjwAA6EU"]
[Thu Sep 17 15:48:50.344028 2026] [security2:error] [pid 102783:tid 102911] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/wp-config.php"] [unique_id "aqxgQMzioAAmEecB_LHDkAAA6H8"]
[Thu Sep 17 15:48:50.344212 2026] [security2:error] [pid 102783:tid 102911] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/wp-config.php.bak"] [unique_id "aqxgQczioAAmEecB_LHDkwAA6H8"]
[Thu Sep 17 15:48:50.344407 2026] [security2:error] [pid 102783:tid 102825] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/wp-config.php.old"] [unique_id "aqxgQczioAAmEecB_LHDlAAA6Ck"]
[Thu Sep 17 15:48:50.344614 2026] [security2:error] [pid 102783:tid 102832] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/wp-config.php.new"] [unique_id "aqxgQczioAAmEecB_LHDlQAA6DA"]
[Thu Sep 17 15:48:50.344987 2026] [security2:error] [pid 102783:tid 102911] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.wp-config.php.swp"] [unique_id "aqxgQczioAAmEecB_LHDlgAA6H8"]
[Thu Sep 17 15:48:50.347281 2026] [security2:error] [pid 102783:tid 102859] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/wp-content/mysql.sql"] [unique_id "aqxgQczioAAmEecB_LHDmQAA6Es"]
[Thu Sep 17 15:48:50.516067 2026] [security2:error] [pid 102783:tid 103028] [client 34.154.246.111:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxgQszioAAmEecB_LHDqQAAAPg"]
[Thu Sep 17 15:48:50.634224 2026] [security2:error] [pid 102783:tid 103015] [client 34.185.180.78:39368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxgQszioAAmEecB_LHDrgAAAOs"]
[Thu Sep 17 15:48:50.640947 2026] [security2:error] [pid 102783:tid 102959] [client 34.166.149.166:60602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/info.php"] [unique_id "aqxgQszioAAmEecB_LHDrwAAALM"]
[Thu Sep 17 15:48:50.687608 2026] [security2:error] [pid 102783:tid 102983] [client 34.94.22.173:54986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxgQszioAAmEecB_LHDsAAAAMs"]
[Thu Sep 17 15:48:50.880534 2026] [security2:error] [pid 102783:tid 102971] [client 34.94.22.173:54994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxgQszioAAmEecB_LHDuAAAAL8"]
[Thu Sep 17 15:48:50.994544 2026] [security2:error] [pid 102783:tid 102930] [client 34.154.246.111:54500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxgQszioAAmEecB_LHDuQAAAJY"]
[Thu Sep 17 15:48:51.014812 2026] [security2:error] [pid 102783:tid 103004] [client 34.94.22.173:55006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHDugAAAOA"]
[Thu Sep 17 15:48:51.070129 2026] [security2:error] [pid 102783:tid 102962] [client 34.185.180.78:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHDwgAAALY"]
[Thu Sep 17 15:48:51.196838 2026] [security2:error] [pid 102783:tid 102920] [client 122.8.45.84:45413] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQ8zioAAmEecB_LHDxAAAAIw"]
[Thu Sep 17 15:48:51.196957 2026] [security2:error] [pid 102783:tid 102920] [client 122.8.45.84:45413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgQ8zioAAmEecB_LHDxAAAAIw"]
[Thu Sep 17 15:48:51.232316 2026] [security2:error] [pid 102783:tid 102940] [client 34.94.22.173:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHDxwAAAKA"]
[Thu Sep 17 15:48:51.294405 2026] [security2:error] [pid 102783:tid 102921] [client 192.178.6.3:47459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxgQ8zioAAmEecB_LHDyQAAAI0"]
[Thu Sep 17 15:48:51.297215 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDbwAA5RM"]
[Thu Sep 17 15:48:51.318874 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDcgAA1hI"]
[Thu Sep 17 15:48:51.325286 2026] [security2:error] [pid 102783:tid 102987] [client 34.166.149.166:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/php.php"] [unique_id "aqxgQ8zioAAmEecB_LHDygAAAM8"]
[Thu Sep 17 15:48:51.337423 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDbgAA5Xw"]
[Thu Sep 17 15:48:51.352073 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDdQAA5T0"]
[Thu Sep 17 15:48:51.354351 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDcwAA1hs"]
[Thu Sep 17 15:48:51.357600 2026] [security2:error] [pid 102783:tid 102974] [client 143.105.152.240:14624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgQ8zioAAmEecB_LHDywAAAMI"]
[Thu Sep 17 15:48:51.357825 2026] [security2:error] [pid 102783:tid 102974] [client 143.105.152.240:14624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgQ8zioAAmEecB_LHDywAAAMI"]
[Thu Sep 17 15:48:51.358267 2026] [security2:error] [pid 102783:tid 103027] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDgQAA91U"]
[Thu Sep 17 15:48:51.374216 2026] [security2:error] [pid 102783:tid 102829] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgPszioAAmEecB_LHDbAAA6C0"]
[Thu Sep 17 15:48:51.388171 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDcAAA-UQ"]
[Thu Sep 17 15:48:51.405234 2026] [security2:error] [pid 102783:tid 103019] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDgAAA71E"]
[Thu Sep 17 15:48:51.409901 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDcQAA-SY"]
[Thu Sep 17 15:48:51.414558 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDdgAA1is"]
[Thu Sep 17 15:48:51.425753 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDmAAA6Hc"]
[Thu Sep 17 15:48:51.429655 2026] [security2:error] [pid 102783:tid 102886] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/terraform.tfstate.backup"] [unique_id "aqxgQszioAAmEecB_LHDzwAA6GY"]
[Thu Sep 17 15:48:51.463522 2026] [security2:error] [pid 102783:tid 102976] [client 34.94.22.173:55024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxgQ8zioAAmEecB_LHD2wAAAMQ"]
[Thu Sep 17 15:48:51.465599 2026] [security2:error] [pid 102783:tid 102941] [client 34.154.246.111:54504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHD3AAAAKE"]
[Thu Sep 17 15:48:51.467334 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDewAA-QY"]
[Thu Sep 17 15:48:51.520055 2026] [security2:error] [pid 102783:tid 102934] [client 34.185.180.78:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHD5AAAAJo"]
[Thu Sep 17 15:48:51.556351 2026] [security2:error] [pid 102783:tid 102902] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHD6QAA1nY"]
[Thu Sep 17 15:48:51.570648 2026] [security2:error] [pid 102783:tid 102787] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/info.php"] [unique_id "aqxgQ8zioAAmEecB_LHD7QAA5QM"]
[Thu Sep 17 15:48:51.585557 2026] [security2:error] [pid 102783:tid 102887] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/infos.php"] [unique_id "aqxgQ8zioAAmEecB_LHD8QAA-Wc"]
[Thu Sep 17 15:48:51.669121 2026] [security2:error] [pid 102783:tid 103040] [client 34.94.22.173:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxgQ8zioAAmEecB_LHD8wAAAQQ"]
[Thu Sep 17 15:48:51.718372 2026] [security2:error] [pid 102783:tid 102840] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/php_info.php"] [unique_id "aqxgQ8zioAAmEecB_LHD9AAA5Tg"]
[Thu Sep 17 15:48:51.724731 2026] [security2:error] [pid 102783:tid 102808] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/php.php"] [unique_id "aqxgQ8zioAAmEecB_LHD9QAA-Rg"]
[Thu Sep 17 15:48:51.736124 2026] [security2:error] [pid 102783:tid 102820] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/php-info.php"] [unique_id "aqxgQ8zioAAmEecB_LHD9wAA-SQ"]
[Thu Sep 17 15:48:51.741519 2026] [security2:error] [pid 102783:tid 102900] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/infophp.php"] [unique_id "aqxgQ8zioAAmEecB_LHD-QAA1nQ"]
[Thu Sep 17 15:48:51.807475 2026] [security2:error] [pid 102783:tid 103006] [client 14.96.156.146:56763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgQ8zioAAmEecB_LHD_AAAAOI"]
[Thu Sep 17 15:48:51.807600 2026] [security2:error] [pid 102783:tid 103006] [client 14.96.156.146:56763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgQ8zioAAmEecB_LHD_AAAAOI"]
[Thu Sep 17 15:48:51.892917 2026] [security2:error] [pid 102783:tid 102841] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHD_gAA1jk"]
[Thu Sep 17 15:48:51.941415 2026] [security2:error] [pid 102783:tid 102917] [client 34.154.246.111:54506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxgQ8zioAAmEecB_LHD_wAAAIk"]
[Thu Sep 17 15:48:51.952631 2026] [security2:error] [pid 102783:tid 102846] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHEAAAA5T4"]
[Thu Sep 17 15:48:51.987315 2026] [security2:error] [pid 102783:tid 103028] [client 34.185.180.78:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxgQ8zioAAmEecB_LHEAQAAAPg"]
[Thu Sep 17 15:48:52.009885 2026] [security2:error] [pid 102783:tid 103039] [client 34.166.149.166:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/i.php"] [unique_id "aqxgRMzioAAmEecB_LHEAgAAAQM"]
[Thu Sep 17 15:48:52.105120 2026] [security2:error] [pid 102783:tid 102929] [client 34.94.22.173:56034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxgRMzioAAmEecB_LHECAAAAJU"]
[Thu Sep 17 15:48:52.150906 2026] [security2:error] [pid 102783:tid 102818] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHECgAA-SI"]
[Thu Sep 17 15:48:52.152559 2026] [security2:error] [pid 102783:tid 103015] [client 148.227.75.216:52473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRMzioAAmEecB_LHECQAAAOs"]
[Thu Sep 17 15:48:52.152629 2026] [security2:error] [pid 102783:tid 103015] [client 148.227.75.216:52473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRMzioAAmEecB_LHECQAAAOs"]
[Thu Sep 17 15:48:52.244705 2026] [security2:error] [pid 102783:tid 102806] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/public/phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHEEQAA5RY"]
[Thu Sep 17 15:48:52.244930 2026] [security2:error] [pid 102783:tid 102795] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/api/phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHEEgAA1gs"]
[Thu Sep 17 15:48:52.249929 2026] [security2:error] [pid 102783:tid 102968] [client 122.8.45.84:27475] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRMzioAAmEecB_LHEEwAAALw"]
[Thu Sep 17 15:48:52.250009 2026] [security2:error] [pid 102783:tid 102968] [client 122.8.45.84:27475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRMzioAAmEecB_LHEEwAAALw"]
[Thu Sep 17 15:48:52.330181 2026] [security2:error] [pid 102783:tid 102933] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDoQAAAJk"]
[Thu Sep 17 15:48:52.356255 2026] [security2:error] [pid 102783:tid 103017] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDowAAAO0"]
[Thu Sep 17 15:48:52.377763 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDmwAA6C4"]
[Thu Sep 17 15:48:52.384111 2026] [security2:error] [pid 102783:tid 102945] [client 34.94.22.173:56048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHEFgAAAKU"]
[Thu Sep 17 15:48:52.385273 2026] [security2:error] [pid 102783:tid 102965] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDogAAALk"]
[Thu Sep 17 15:48:52.438610 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDpAAA5Vs"]
[Thu Sep 17 15:48:52.442398 2026] [security2:error] [pid 102783:tid 102962] [client 34.185.180.78:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHEGgAAALY"]
[Thu Sep 17 15:48:52.453531 2026] [security2:error] [pid 102783:tid 103038] [client 34.154.246.111:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/phpinfo.php.old"] [unique_id "aqxgRMzioAAmEecB_LHEGwAAAQI"]
[Thu Sep 17 15:48:52.459552 2026] [security2:error] [pid 102783:tid 103000] [client 177.44.133.72:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgRMzioAAmEecB_LHEHAAAANw"]
[Thu Sep 17 15:48:52.459682 2026] [security2:error] [pid 102783:tid 103000] [client 177.44.133.72:51342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgRMzioAAmEecB_LHEHAAAANw"]
[Thu Sep 17 15:48:52.588175 2026] [security2:error] [pid 102783:tid 102947] [client 34.94.22.173:56054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHEIAAAAKc"]
[Thu Sep 17 15:48:52.699173 2026] [security2:error] [pid 102783:tid 102935] [client 34.166.149.166:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/pi.php"] [unique_id "aqxgRMzioAAmEecB_LHEIgAAAJs"]
[Thu Sep 17 15:48:52.832964 2026] [security2:error] [pid 102783:tid 103025] [client 34.94.22.173:56058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHEJwAAAPU"]
[Thu Sep 17 15:48:52.886404 2026] [security2:error] [pid 102783:tid 102948] [client 34.185.180.78:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.180.185.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbn.bnl.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxgRMzioAAmEecB_LHEKAAAAKg"]
[Thu Sep 17 15:48:52.963986 2026] [security2:error] [pid 102783:tid 102941] [client 34.154.246.111:54510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/phpinfo.php~"] [unique_id "aqxgRMzioAAmEecB_LHEKwAAAKE"]
[Thu Sep 17 15:48:53.141890 2026] [security2:error] [pid 102783:tid 102919] [client 34.94.22.173:56074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxgRczioAAmEecB_LHEMwAAAIs"]
[Thu Sep 17 15:48:53.210506 2026] [security2:error] [pid 102783:tid 102973] [client 122.8.45.84:9783] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRczioAAmEecB_LHENgAAAME"]
[Thu Sep 17 15:48:53.210624 2026] [security2:error] [pid 102783:tid 102973] [client 122.8.45.84:9783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRczioAAmEecB_LHENgAAAME"]
[Thu Sep 17 15:48:53.263952 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDpQAA-Vc"]
[Thu Sep 17 15:48:53.302595 2026] [security2:error] [pid 102783:tid 102949] [client 34.94.22.173:56090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxgRczioAAmEecB_LHEOAAAAKk"]
[Thu Sep 17 15:48:53.323218 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDpgAA-Wg"]
[Thu Sep 17 15:48:53.332402 2026] [security2:error] [pid 102783:tid 102856] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDmgAA6Eg"]
[Thu Sep 17 15:48:53.344080 2026] [security2:error] [pid 102783:tid 102859] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDnQAA6Es"]
[Thu Sep 17 15:48:53.394785 2026] [security2:error] [pid 102783:tid 103006] [client 34.166.149.166:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/pinfo.php"] [unique_id "aqxgRczioAAmEecB_LHEPAAAAOI"]
[Thu Sep 17 15:48:53.395563 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDpwAA1nE"]
[Thu Sep 17 15:48:53.415643 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDqAAA1jc"]
[Thu Sep 17 15:48:53.447321 2026] [security2:error] [pid 102783:tid 102959] [client 34.154.246.111:54514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/info.php.bak"] [unique_id "aqxgRczioAAmEecB_LHEPQAAALM"]
[Thu Sep 17 15:48:53.593468 2026] [security2:error] [pid 102783:tid 102964] [client 50.6.53.48:26764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.6.50.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intolovinghomes.com.au"] [uri "/wp-cron.php"] [unique_id "aqxgRczioAAmEecB_LHERAAAALg"]
[Thu Sep 17 15:48:53.608128 2026] [security2:error] [pid 102783:tid 102955] [client 34.94.22.173:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxgRczioAAmEecB_LHESgAAAK8"]
[Thu Sep 17 15:48:53.609363 2026] [security2:error] [pid 102783:tid 102797] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/database.sql"] [unique_id "aqxgRczioAAmEecB_LHESwAA5Q0"]
[Thu Sep 17 15:48:53.745704 2026] [security2:error] [pid 102783:tid 102945] [client 34.94.22.173:56110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxgRczioAAmEecB_LHEUwAAAKU"]
[Thu Sep 17 15:48:53.879966 2026] [security2:error] [pid 102783:tid 103010] [client 34.94.22.173:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxgRczioAAmEecB_LHEWQAAAOY"]
[Thu Sep 17 15:48:53.956040 2026] [security2:error] [pid 102783:tid 102935] [client 4.240.114.86:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/icons.php"] [unique_id "aqxgRczioAAmEecB_LHEYAAAAJs"], referer: binance.com
[Thu Sep 17 15:48:53.968449 2026] [core:error] [pid 102783:tid 102904] [remote 216.73.217.16:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:48:53.968471 2026] [core:error] [pid 102783:tid 102904] [remote 216.73.217.16:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:48:53.972739 2026] [security2:error] [pid 102783:tid 102946] [client 34.154.246.111:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/phpinfo.php.save"] [unique_id "aqxgRczioAAmEecB_LHEYgAAAKY"]
[Thu Sep 17 15:48:53.974829 2026] [security2:error] [pid 102783:tid 103031] [client 169.58.197.251:60559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.197.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfvhbt.org"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxgRczioAAmEecB_LHEYwAAAPs"], referer: binance.com
[Thu Sep 17 15:48:54.096226 2026] [security2:error] [pid 102783:tid 103004] [client 34.166.149.166:60638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/test.php"] [unique_id "aqxgRszioAAmEecB_LHEegAAAOA"]
[Thu Sep 17 15:48:54.164385 2026] [security2:error] [pid 102783:tid 102956] [client 122.8.45.84:39709] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRszioAAmEecB_LHEewAAALA"]
[Thu Sep 17 15:48:54.164519 2026] [security2:error] [pid 102783:tid 102956] [client 122.8.45.84:39709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRszioAAmEecB_LHEewAAALA"]
[Thu Sep 17 15:48:54.194018 2026] [security2:error] [pid 102783:tid 102984] [client 34.94.22.173:56132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxgRszioAAmEecB_LHEfgAAAMw"]
[Thu Sep 17 15:48:54.266561 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD4wAA5VI"]
[Thu Sep 17 15:48:54.310759 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD3wAA-WE"]
[Thu Sep 17 15:48:54.312438 2026] [security2:error] [pid 102783:tid 102892] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD5gAA-Ww"]
[Thu Sep 17 15:48:54.323176 2026] [security2:error] [pid 102783:tid 102966] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD7wAAALo"]
[Thu Sep 17 15:48:54.356387 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD7AAA1ho"]
[Thu Sep 17 15:48:54.384827 2026] [security2:error] [pid 102783:tid 103021] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD8AAAAPE"]
[Thu Sep 17 15:48:54.386009 2026] [security2:error] [pid 102783:tid 102996] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD7gAAANg"]
[Thu Sep 17 15:48:54.402459 2026] [security2:error] [pid 102783:tid 102905] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHD0QAA6Hk"]
[Thu Sep 17 15:48:54.403563 2026] [security2:error] [pid 102783:tid 102829] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQczioAAmEecB_LHDzAAA6C0"]
[Thu Sep 17 15:48:54.406849 2026] [security2:error] [pid 102783:tid 102826] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHD0wAA6Co"]
[Thu Sep 17 15:48:54.410280 2026] [security2:error] [pid 102783:tid 102903] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQszioAAmEecB_LHDzgAA6Hc"]
[Thu Sep 17 15:48:54.436197 2026] [security2:error] [pid 102783:tid 103006] [client 34.94.22.173:56138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxgRszioAAmEecB_LHEsAAAAOI"]
[Thu Sep 17 15:48:54.448281 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD4AAA1jw"]
[Thu Sep 17 15:48:54.449364 2026] [security2:error] [pid 102783:tid 102923] [client 34.154.246.111:54522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxgRszioAAmEecB_LHEswAAAI8"]
[Thu Sep 17 15:48:54.450572 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD-gAA1lM"]
[Thu Sep 17 15:48:54.450607 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRMzioAAmEecB_LHEEAAA-Qk"]
[Thu Sep 17 15:48:54.470641 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD3QAA-W4"]
[Thu Sep 17 15:48:54.471412 2026] [security2:error] [pid 102783:tid 102967] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD5wAAALs"]
[Thu Sep 17 15:48:54.482595 2026] [security2:error] [pid 102783:tid 102972] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD4QAAAMA"]
[Thu Sep 17 15:48:54.482595 2026] [security2:error] [pid 102783:tid 103034] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHD4gAAAP4"]
[Thu Sep 17 15:48:54.515795 2026] [security2:error] [pid 102783:tid 102975] [client 79.116.89.151:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRszioAAmEecB_LHEvQAAAMM"]
[Thu Sep 17 15:48:54.515916 2026] [security2:error] [pid 102783:tid 102975] [client 79.116.89.151:52849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgRszioAAmEecB_LHEvQAAAMM"]
[Thu Sep 17 15:48:54.624860 2026] [security2:error] [pid 102783:tid 103033] [client 223.109.255.165:40360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acc.edu.ai"] [uri "/my-acc/"] [unique_id "aqxgRszioAAmEecB_LHEzAAAAP0"]
[Thu Sep 17 15:48:54.624965 2026] [security2:error] [pid 102783:tid 103033] [client 223.109.255.165:40360] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "acc.edu.ai"] [uri "/my-acc/"] [unique_id "aqxgRszioAAmEecB_LHEzAAAAP0"]
[Thu Sep 17 15:48:54.733892 2026] [security2:error] [pid 102783:tid 103000] [client 34.94.22.173:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxgRszioAAmEecB_LHE0wAAANw"]
[Thu Sep 17 15:48:54.986596 2026] [security2:error] [pid 102783:tid 102957] [client 34.154.246.111:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxgRszioAAmEecB_LHE5gAAALE"]
[Thu Sep 17 15:48:55.012869 2026] [security2:error] [pid 102783:tid 102997] [client 34.166.149.166:60652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/p.php"] [unique_id "aqxgR8zioAAmEecB_LHE6gAAANk"]
[Thu Sep 17 15:48:55.086679 2026] [security2:error] [pid 102783:tid 102930] [client 34.94.22.173:56158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxgR8zioAAmEecB_LHE7wAAAJY"]
[Thu Sep 17 15:48:55.122895 2026] [security2:error] [pid 102783:tid 102918] [client 122.8.45.84:58659] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgR8zioAAmEecB_LHE8AAAAIo"]
[Thu Sep 17 15:48:55.123029 2026] [security2:error] [pid 102783:tid 102918] [client 122.8.45.84:58659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgR8zioAAmEecB_LHE8AAAAIo"]
[Thu Sep 17 15:48:55.249366 2026] [security2:error] [pid 102783:tid 102928] [client 34.94.22.173:56172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxgR8zioAAmEecB_LHE-gAAAJQ"]
[Thu Sep 17 15:48:55.439360 2026] [security2:error] [pid 102783:tid 102959] [client 34.94.22.173:56184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxgR8zioAAmEecB_LHFCAAAALM"]
[Thu Sep 17 15:48:55.478875 2026] [security2:error] [pid 102783:tid 102973] [client 34.154.246.111:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxgR8zioAAmEecB_LHFCQAAAME"]
[Thu Sep 17 15:48:55.694947 2026] [security2:error] [pid 102783:tid 102922] [client 34.94.22.173:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxgR8zioAAmEecB_LHFFwAAAI4"]
[Thu Sep 17 15:48:55.697526 2026] [security2:error] [pid 102783:tid 103015] [client 34.166.149.166:60668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/debug.php"] [unique_id "aqxgR8zioAAmEecB_LHFGQAAAOs"]
[Thu Sep 17 15:48:55.756595 2026] [autoindex:error] [pid 102783:tid 102968] [client 34.185.180.78:46090] AH01276: Cannot serve directory /home1/jbnbnlmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:48:55.916800 2026] [security2:error] [pid 102783:tid 102970] [client 34.94.22.173:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxgR8zioAAmEecB_LHFLAAAAL4"]
[Thu Sep 17 15:48:55.975680 2026] [security2:error] [pid 102783:tid 102937] [client 34.154.246.111:56230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxgR8zioAAmEecB_LHFLQAAAJ0"]
[Thu Sep 17 15:48:56.045354 2026] [security2:error] [pid 102783:tid 102943] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/.env"] [unique_id "aqxgSMzioAAmEecB_LHFMwAAAKM"]
[Thu Sep 17 15:48:56.094728 2026] [security2:error] [pid 102783:tid 102914] [client 122.8.45.84:18259] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSMzioAAmEecB_LHFNgAAAIY"]
[Thu Sep 17 15:48:56.094843 2026] [security2:error] [pid 102783:tid 102914] [client 122.8.45.84:18259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSMzioAAmEecB_LHFNgAAAIY"]
[Thu Sep 17 15:48:56.242235 2026] [security2:error] [pid 102783:tid 103040] [client 34.94.22.173:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxgSMzioAAmEecB_LHFSQAAAQQ"]
[Thu Sep 17 15:48:56.375171 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHEywAA1n8"]
[Thu Sep 17 15:48:56.384121 2026] [security2:error] [pid 102783:tid 103004] [client 34.166.149.166:58138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxgSMzioAAmEecB_LHFTgAAAOA"]
[Thu Sep 17 15:48:56.429357 2026] [security2:error] [pid 102783:tid 102919] [client 212.47.68.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "spursandspiritstx.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFRAAAAIs"], referer: https://spursandspiritstx.com/
[Thu Sep 17 15:48:56.436935 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHErwAA-XY"]
[Thu Sep 17 15:48:56.453145 2026] [security2:error] [pid 102783:tid 102965] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHEvwAAALk"]
[Thu Sep 17 15:48:56.466886 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHExgAA5R4"]
[Thu Sep 17 15:48:56.481576 2026] [security2:error] [pid 102783:tid 102972] [client 34.94.22.173:56220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxgSMzioAAmEecB_LHFVQAAAMA"]
[Thu Sep 17 15:48:56.482382 2026] [security2:error] [pid 102783:tid 103019] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHE3wAA70g"]
[Thu Sep 17 15:48:56.482470 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHEuAAA1nQ"]
[Thu Sep 17 15:48:56.483781 2026] [security2:error] [pid 102783:tid 102853] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHEzgAA5UU"]
[Thu Sep 17 15:48:56.488490 2026] [security2:error] [pid 102783:tid 102927] [client 34.154.246.111:56238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxgSMzioAAmEecB_LHFVgAAAJM"]
[Thu Sep 17 15:48:56.488809 2026] [security2:error] [pid 102783:tid 102909] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRMzioAAmEecB_LHEFwAA5X0"]
[Thu Sep 17 15:48:56.606565 2026] [security2:error] [pid 102783:tid 102832] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/site.sql"] [unique_id "aqxgSMzioAAmEecB_LHFXAAA5TA"]
[Thu Sep 17 15:48:56.653684 2026] [security2:error] [pid 102783:tid 102892] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/2022/.env"] [unique_id "aqxgSMzioAAmEecB_LHFZQAA-Ww"]
[Thu Sep 17 15:48:56.730734 2026] [security2:error] [pid 102783:tid 102970] [client 34.94.22.173:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxgSMzioAAmEecB_LHFawAAAL4"]
[Thu Sep 17 15:48:56.793308 2026] [security2:error] [pid 102783:tid 102848] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/config.properties.bak"] [unique_id "aqxgSMzioAAmEecB_LHFbwAA-UA"]
[Thu Sep 17 15:48:56.977975 2026] [security2:error] [pid 102783:tid 102930] [client 34.94.22.173:56238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxgSMzioAAmEecB_LHFdAAAAJY"]
[Thu Sep 17 15:48:56.982209 2026] [security2:error] [pid 102783:tid 102937] [client 34.154.246.111:56246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/www/phpinfo.php"] [unique_id "aqxgSMzioAAmEecB_LHFdgAAAJ0"]
[Thu Sep 17 15:48:57.020227 2026] [security2:error] [pid 102783:tid 102794] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/shop/.env"] [unique_id "aqxgSczioAAmEecB_LHFdwAA1go"]
[Thu Sep 17 15:48:57.070049 2026] [security2:error] [pid 102783:tid 102940] [client 34.166.149.166:58148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/test/phpinfo.php"] [unique_id "aqxgSczioAAmEecB_LHFhQAAAKA"]
[Thu Sep 17 15:48:57.070993 2026] [security2:error] [pid 102783:tid 102926] [client 122.8.45.84:18337] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSczioAAmEecB_LHFhAAAAJI"]
[Thu Sep 17 15:48:57.071089 2026] [security2:error] [pid 102783:tid 102926] [client 122.8.45.84:18337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSczioAAmEecB_LHFhAAAAJI"]
[Thu Sep 17 15:48:57.104897 2026] [security2:error] [pid 102783:tid 102987] [client 34.94.22.173:56250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxgSczioAAmEecB_LHFjQAAAM8"]
[Thu Sep 17 15:48:57.258735 2026] [security2:error] [pid 102783:tid 102786] [remote 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRczioAAmEecB_LHESAAA-QI"]
[Thu Sep 17 15:48:57.273527 2026] [security2:error] [pid 102783:tid 103028] [client 62.169.26.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "spursandspiritstx.com"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHFjwAAAPg"], referer: https://spursandspiritstx.com/
[Thu Sep 17 15:48:57.285860 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHEtQAA5Tg"]
[Thu Sep 17 15:48:57.337220 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRMzioAAmEecB_LHEGAAA-Xs"]
[Thu Sep 17 15:48:57.340398 2026] [security2:error] [pid 102783:tid 102842] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgQ8zioAAmEecB_LHEugAA6Do"]
[Thu Sep 17 15:48:57.353301 2026] [security2:error] [pid 102783:tid 102954] [client 34.94.22.173:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxgSczioAAmEecB_LHFmQAAAK4"]
[Thu Sep 17 15:48:57.372465 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRczioAAmEecB_LHEWAAA1mU"]
[Thu Sep 17 15:48:57.399006 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRczioAAmEecB_LHEVwAA-Vo"]
[Thu Sep 17 15:48:57.417257 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRczioAAmEecB_LHETAAA1gQ"]
[Thu Sep 17 15:48:57.427215 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRczioAAmEecB_LHESQAA5Ts"]
[Thu Sep 17 15:48:57.431916 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRMzioAAmEecB_LHEJQAA-SM"]
[Thu Sep 17 15:48:57.459702 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHEvgAA5Rc"]
[Thu Sep 17 15:48:57.486187 2026] [security2:error] [pid 102783:tid 103014] [client 34.154.246.111:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxgSczioAAmEecB_LHFnAAAAOo"]
[Thu Sep 17 15:48:57.505746 2026] [security2:error] [pid 102783:tid 103008] [client 34.94.22.173:56276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxgSczioAAmEecB_LHFpAAAAOQ"]
[Thu Sep 17 15:48:57.534038 2026] [security2:error] [pid 102783:tid 103007] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/.env.bak"] [unique_id "aqxgSczioAAmEecB_LHFpwAAAOM"]
[Thu Sep 17 15:48:57.695590 2026] [security2:error] [pid 102783:tid 102945] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/.env.backup"] [unique_id "aqxgSczioAAmEecB_LHFqQAAAKU"]
[Thu Sep 17 15:48:57.709730 2026] [security2:error] [pid 102783:tid 103019] [client 34.94.22.173:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.94.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fow.qtd.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxgSczioAAmEecB_LHFqgAAAO8"]
[Thu Sep 17 15:48:57.756411 2026] [security2:error] [pid 102783:tid 103030] [client 34.166.149.166:58150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/dev/phpinfo.php"] [unique_id "aqxgSczioAAmEecB_LHFrQAAAPo"]
[Thu Sep 17 15:48:57.859481 2026] [security2:error] [pid 102783:tid 102980] [client 4.240.114.86:64793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/json-schema.php"] [unique_id "aqxgSczioAAmEecB_LHFtwAAAMg"], referer: binance.com
[Thu Sep 17 15:48:58.021259 2026] [security2:error] [pid 102783:tid 102979] [client 34.154.246.111:56266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/public_html/phpinfo.php"] [unique_id "aqxgSszioAAmEecB_LHFwwAAAMc"]
[Thu Sep 17 15:48:58.023907 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:63737] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSszioAAmEecB_LHFxAAAAK8"]
[Thu Sep 17 15:48:58.024003 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:63737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSszioAAmEecB_LHFxAAAAK8"]
[Thu Sep 17 15:48:58.064539 2026] [security2:error] [pid 102783:tid 102988] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/.env.old"] [unique_id "aqxgSszioAAmEecB_LHFyAAAANA"]
[Thu Sep 17 15:48:58.134123 2026] [security2:error] [pid 102783:tid 102961] [client 50.199.31.86:44559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgSszioAAmEecB_LHFwgAAtWA"]
[Thu Sep 17 15:48:58.368565 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgR8zioAAmEecB_LHFGwAA5SU"]
[Thu Sep 17 15:48:58.396015 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFWgAA5Vw"]
[Thu Sep 17 15:48:58.430212 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFagAA-RA"]
[Thu Sep 17 15:48:58.437555 2026] [security2:error] [pid 102783:tid 103024] [client 34.166.149.166:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/old/phpinfo.php"] [unique_id "aqxgSszioAAmEecB_LHF4QAAAPQ"]
[Thu Sep 17 15:48:58.437873 2026] [security2:error] [pid 102783:tid 102842] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgRszioAAmEecB_LHFmAAA6Do"]
[Thu Sep 17 15:48:58.454252 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFcAAA1iE"]
[Thu Sep 17 15:48:58.517317 2026] [security2:error] [pid 102783:tid 102986] [client 34.154.246.111:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/site/phpinfo.php"] [unique_id "aqxgSszioAAmEecB_LHF5gAAAM4"]
[Thu Sep 17 15:48:58.565960 2026] [security2:error] [pid 102783:tid 102879] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/.env.local.orig"] [unique_id "aqxgSszioAAmEecB_LHF6wAA-V8"]
[Thu Sep 17 15:48:58.615584 2026] [security2:error] [pid 102783:tid 102870] [remote 34.38.113.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.com"] [uri "/app_dev.php"] [unique_id "aqxgSszioAAmEecB_LHF7wAA5VY"]
[Thu Sep 17 15:48:58.739436 2026] [security2:error] [pid 102783:tid 102882] [remote 34.38.113.44:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.com"] [uri "/2020/.env"] [unique_id "aqxgSszioAAmEecB_LHF9wAA1mI"]
[Thu Sep 17 15:48:58.782039 2026] [security2:error] [pid 102783:tid 102917] [client 141.94.78.40:43332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.78.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.seedboxpress.com"] [uri "/wp-login.php"] [unique_id "aqxgSszioAAmEecB_LHF9QAAAIk"]
[Thu Sep 17 15:48:58.977296 2026] [security2:error] [pid 102783:tid 102977] [client 122.8.45.84:58541] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSszioAAmEecB_LHGCAAAAMU"]
[Thu Sep 17 15:48:58.977457 2026] [security2:error] [pid 102783:tid 102977] [client 122.8.45.84:58541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgSszioAAmEecB_LHGCAAAAMU"]
[Thu Sep 17 15:48:59.003490 2026] [security2:error] [pid 102783:tid 103010] [client 34.154.246.111:56298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/docs/phpinfo.php"] [unique_id "aqxgS8zioAAmEecB_LHGCQAAAOY"]
[Thu Sep 17 15:48:59.130592 2026] [security2:error] [pid 102783:tid 103020] [client 34.166.149.166:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxgS8zioAAmEecB_LHGFAAAAPA"]
[Thu Sep 17 15:48:59.282906 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgR8zioAAmEecB_LHFBQAA1ic"]
[Thu Sep 17 15:48:59.284044 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgR8zioAAmEecB_LHFBAAA-Sg"]
[Thu Sep 17 15:48:59.321490 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFXQAA-Qg"]
[Thu Sep 17 15:48:59.323581 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFaQAA1jI"]
[Thu Sep 17 15:48:59.340051 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHFkAAA5Uk"]
[Thu Sep 17 15:48:59.349116 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFYQAA1lA"]
[Thu Sep 17 15:48:59.366299 2026] [security2:error] [pid 102783:tid 103022] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHFmwAA8nk"]
[Thu Sep 17 15:48:59.373183 2026] [security2:error] [pid 102783:tid 102969] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHFpQAAvVM"]
[Thu Sep 17 15:48:59.403781 2026] [security2:error] [pid 102783:tid 103009] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSMzioAAmEecB_LHFaAAA5RM"]
[Thu Sep 17 15:48:59.411613 2026] [security2:error] [pid 102783:tid 102877] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgRczioAAmEecB_LHFUgAA6F0"]
[Thu Sep 17 15:48:59.425053 2026] [security2:error] [pid 102783:tid 102975] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHFswAAw3A"]
[Thu Sep 17 15:48:59.433047 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHFkQAA-T0"]
[Thu Sep 17 15:48:59.462184 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSszioAAmEecB_LHF4AAA1nE"]
[Thu Sep 17 15:48:59.483206 2026] [security2:error] [pid 102783:tid 102916] [client 34.154.246.111:56304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxgS8zioAAmEecB_LHGIwAAAIg"]
[Thu Sep 17 15:48:59.547308 2026] [security2:error] [pid 102783:tid 103003] [client 50.199.31.86:36068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgS8zioAAmEecB_LHGIAAA3ws"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=30&from=20260818013808&hideanons=1&hideminor=1&limit=500&target=The_Cartel&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:48:59.953902 2026] [security2:error] [pid 102783:tid 102941] [client 122.8.45.84:63165] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgS8zioAAmEecB_LHGPgAAAKE"]
[Thu Sep 17 15:48:59.954057 2026] [security2:error] [pid 102783:tid 102941] [client 122.8.45.84:63165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgS8zioAAmEecB_LHGPgAAAKE"]
[Thu Sep 17 15:48:59.993291 2026] [security2:error] [pid 102783:tid 102954] [client 34.154.246.111:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/administrator/phpinfo.php"] [unique_id "aqxgS8zioAAmEecB_LHGPwAAAK4"]
[Thu Sep 17 15:49:00.051633 2026] [security2:error] [pid 102783:tid 102917] [client 34.166.149.166:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxgTMzioAAmEecB_LHGQQAAAIk"]
[Thu Sep 17 15:49:00.272847 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSszioAAmEecB_LHF6AAA-Uo"]
[Thu Sep 17 15:49:00.273691 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSszioAAmEecB_LHF3wAA-Q0"]
[Thu Sep 17 15:49:00.281508 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSszioAAmEecB_LHF_QAA-Sw"]
[Thu Sep 17 15:49:00.289797 2026] [security2:error] [pid 102783:tid 102994] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSszioAAmEecB_LHF7gAA1h8"]
[Thu Sep 17 15:49:00.303686 2026] [security2:error] [pid 102783:tid 102842] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgR8zioAAmEecB_LHF4gAA6Do"]
[Thu Sep 17 15:49:00.341628 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.com"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHFmgAA-R0"]
[Thu Sep 17 15:49:00.445264 2026] [security2:error] [pid 102783:tid 102948] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgS8zioAAmEecB_LHGJAAAAKg"]
[Thu Sep 17 15:49:00.503103 2026] [security2:error] [pid 102783:tid 102953] [client 34.154.246.111:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/core/phpinfo.php"] [unique_id "aqxgTMzioAAmEecB_LHGWAAAAK0"]
[Thu Sep 17 15:49:00.527892 2026] [security2:error] [pid 102783:tid 102925] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGUgAAAJE"]
[Thu Sep 17 15:49:00.575256 2026] [security2:error] [pid 102783:tid 102964] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/.env.swp"] [unique_id "aqxgTMzioAAmEecB_LHGXgAAALg"]
[Thu Sep 17 15:49:00.614156 2026] [security2:error] [pid 102783:tid 102975] [client 4.240.114.86:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/robots-template.php"] [unique_id "aqxgTMzioAAmEecB_LHGYAAAAMM"], referer: binance.com
[Thu Sep 17 15:49:00.705420 2026] [security2:error] [pid 102783:tid 102970] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGWgAAAL4"]
[Thu Sep 17 15:49:00.728796 2026] [security2:error] [pid 102783:tid 102985] [client 34.166.149.166:58182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/phpversion.php"] [unique_id "aqxgTMzioAAmEecB_LHGbQAAAM0"]
[Thu Sep 17 15:49:00.730725 2026] [security2:error] [pid 102783:tid 102842] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgSczioAAmEecB_LHGXAAA6Do"]
[Thu Sep 17 15:49:00.751472 2026] [security2:error] [pid 102783:tid 103028] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/.env~"] [unique_id "aqxgTMzioAAmEecB_LHGcQAAAPg"]
[Thu Sep 17 15:49:00.876625 2026] [security2:error] [pid 102783:tid 102958] [client 52.231.79.181:2319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/autoload_classmap.php"] [unique_id "aqxgTMzioAAmEecB_LHGdgAAALI"]
[Thu Sep 17 15:49:00.888486 2026] [security2:error] [pid 102783:tid 102940] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGawAAAKA"]
[Thu Sep 17 15:49:00.907519 2026] [security2:error] [pid 102783:tid 103000] [client 122.8.45.84:22013] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTMzioAAmEecB_LHGfAAAANw"]
[Thu Sep 17 15:49:00.907617 2026] [security2:error] [pid 102783:tid 103000] [client 122.8.45.84:22013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTMzioAAmEecB_LHGfAAAANw"]
[Thu Sep 17 15:49:00.915502 2026] [security2:error] [pid 102783:tid 102943] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGcAAAAKM"]
[Thu Sep 17 15:49:00.996247 2026] [security2:error] [pid 102783:tid 102929] [client 34.154.246.111:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.246.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.comicsutra.com"] [uri "/includes/phpinfo.php"] [unique_id "aqxgTMzioAAmEecB_LHGhQAAAJU"]
[Thu Sep 17 15:49:01.017265 2026] [security2:error] [pid 102783:tid 102979] [client 52.231.79.181:1876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/post.php"] [unique_id "aqxgTczioAAmEecB_LHGhgAAAMc"]
[Thu Sep 17 15:49:01.073164 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgSszioAAmEecB_LHGeAAA6F0"]
[Thu Sep 17 15:49:01.073944 2026] [security2:error] [pid 102783:tid 102906] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "aqxgS8zioAAmEecB_LHGigAA6Ho"]
[Thu Sep 17 15:49:01.073971 2026] [security2:error] [pid 102783:tid 102873] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/info.php"] [unique_id "aqxgS8zioAAmEecB_LHGjAAA6Fk"]
[Thu Sep 17 15:49:01.074013 2026] [security2:error] [pid 102783:tid 102786] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/infos.php"] [unique_id "aqxgS8zioAAmEecB_LHGjQAA6AI"]
[Thu Sep 17 15:49:01.074315 2026] [security2:error] [pid 102783:tid 102906] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/php_info.php"] [unique_id "aqxgS8zioAAmEecB_LHGjgAA6Ho"]
[Thu Sep 17 15:49:01.074331 2026] [security2:error] [pid 102783:tid 102873] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/php.php"] [unique_id "aqxgTMzioAAmEecB_LHGjwAA6Fk"]
[Thu Sep 17 15:49:01.074419 2026] [security2:error] [pid 102783:tid 102786] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/php-info.php"] [unique_id "aqxgTMzioAAmEecB_LHGkAAA6AI"]
[Thu Sep 17 15:49:01.074623 2026] [security2:error] [pid 102783:tid 102906] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/infophp.php"] [unique_id "aqxgTMzioAAmEecB_LHGkQAA6Ho"]
[Thu Sep 17 15:49:01.074840 2026] [security2:error] [pid 102783:tid 102786] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxgTczioAAmEecB_LHGkwAA6AI"]
[Thu Sep 17 15:49:01.074901 2026] [security2:error] [pid 102783:tid 102906] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "aqxgTczioAAmEecB_LHGlAAA6Ho"]
[Thu Sep 17 15:49:01.105686 2026] [security2:error] [pid 102783:tid 103037] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGgAAAAQE"]
[Thu Sep 17 15:49:01.110075 2026] [security2:error] [pid 102783:tid 102928] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGgwAAAJQ"]
[Thu Sep 17 15:49:01.114475 2026] [security2:error] [pid 102783:tid 103018] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGggAAAO4"]
[Thu Sep 17 15:49:01.208623 2026] [security2:error] [pid 102783:tid 102890] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/admin_phpinfo.php"] [unique_id "aqxgTczioAAmEecB_LHGnwAA6Go"]
[Thu Sep 17 15:49:01.209671 2026] [security2:error] [pid 102783:tid 102818] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/api/phpinfo.php"] [unique_id "aqxgTczioAAmEecB_LHGoQAA6CI"]
[Thu Sep 17 15:49:01.209885 2026] [security2:error] [pid 102783:tid 102788] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/public/phpinfo.php"] [unique_id "aqxgTczioAAmEecB_LHGowAA6AQ"]
[Thu Sep 17 15:49:01.352126 2026] [security2:error] [pid 102783:tid 102844] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/database.sql"] [unique_id "aqxgTczioAAmEecB_LHGwgAA6Dw"]
[Thu Sep 17 15:49:01.421807 2026] [security2:error] [pid 102783:tid 103011] [client 52.231.79.181:1172] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1545"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "stephaniearnold.net"] [uri "/1.php"] [unique_id "aqxgTczioAAmEecB_LHGzQAAAOc"]
[Thu Sep 17 15:49:01.421952 2026] [security2:error] [pid 102783:tid 103011] [client 52.231.79.181:1172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/1.php"] [unique_id "aqxgTczioAAmEecB_LHGzQAAAOc"]
[Thu Sep 17 15:49:01.431354 2026] [security2:error] [pid 102783:tid 103017] [client 34.166.149.166:58198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/_phpinfo.php"] [unique_id "aqxgTczioAAmEecB_LHGzwAAAO0"]
[Thu Sep 17 15:49:01.448847 2026] [security2:error] [pid 102783:tid 102967] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGmgAAALs"]
[Thu Sep 17 15:49:01.513152 2026] [security2:error] [pid 102783:tid 102965] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGswAAALk"]
[Thu Sep 17 15:49:01.528429 2026] [security2:error] [pid 102783:tid 103029] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGtwAAAPk"]
[Thu Sep 17 15:49:01.605473 2026] [security2:error] [pid 102783:tid 103006] [client 136.158.61.34:11276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTczioAAmEecB_LHG4gAAAOI"]
[Thu Sep 17 15:49:01.605695 2026] [security2:error] [pid 102783:tid 103006] [client 136.158.61.34:11276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTczioAAmEecB_LHG4gAAAOI"]
[Thu Sep 17 15:49:01.665151 2026] [security2:error] [pid 102783:tid 102991] [client 16.216.88.147:61440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sportsgirlkat.com"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHG3wAA014"]
[Thu Sep 17 15:49:01.847208 2026] [security2:error] [pid 102783:tid 102992] [client 52.231.79.181:1197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/flower.php"] [unique_id "aqxgTczioAAmEecB_LHG8wAAANQ"]
[Thu Sep 17 15:49:01.888863 2026] [security2:error] [pid 102783:tid 103021] [client 122.8.45.84:17977] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTczioAAmEecB_LHG9AAAAPE"]
[Thu Sep 17 15:49:01.888998 2026] [security2:error] [pid 102783:tid 103021] [client 122.8.45.84:17977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTczioAAmEecB_LHG9AAAAPE"]
[Thu Sep 17 15:49:01.933562 2026] [security2:error] [pid 102783:tid 103034] [client 143.105.152.240:26660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgTczioAAmEecB_LHG9gAAAP4"]
[Thu Sep 17 15:49:01.933687 2026] [security2:error] [pid 102783:tid 103034] [client 143.105.152.240:26660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgTczioAAmEecB_LHG9gAAAP4"]
[Thu Sep 17 15:49:02.113204 2026] [security2:error] [pid 102783:tid 103014] [client 34.166.149.166:58214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/old_phpinfo.php"] [unique_id "aqxgTszioAAmEecB_LHHBwAAAOo"]
[Thu Sep 17 15:49:02.258716 2026] [security2:error] [pid 102783:tid 102981] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGuAAAAMk"]
[Thu Sep 17 15:49:02.262291 2026] [security2:error] [pid 102783:tid 103033] [client 52.231.79.181:2382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/meta.php"] [unique_id "aqxgTszioAAmEecB_LHHEgAAAP0"]
[Thu Sep 17 15:49:02.269918 2026] [security2:error] [pid 102783:tid 103019] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGuQAAAO8"]
[Thu Sep 17 15:49:02.270077 2026] [security2:error] [pid 102783:tid 102933] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGtQAAAJk"]
[Thu Sep 17 15:49:02.282013 2026] [security2:error] [pid 102783:tid 102983] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGnQAAAMs"]
[Thu Sep 17 15:49:02.296117 2026] [security2:error] [pid 102783:tid 102963] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGoAAAALc"]
[Thu Sep 17 15:49:02.332178 2026] [security2:error] [pid 102783:tid 102995] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGtAAAANc"]
[Thu Sep 17 15:49:02.363241 2026] [security2:error] [pid 102783:tid 102980] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGvwAAAMg"]
[Thu Sep 17 15:49:02.456414 2026] [security2:error] [pid 102783:tid 102914] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGzAAAAIY"]
[Thu Sep 17 15:49:02.479641 2026] [security2:error] [pid 102783:tid 102929] [client 4.240.114.86:50767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/script-modules.php"] [unique_id "aqxgTszioAAmEecB_LHHIwAAAJU"], referer: binance.com
[Thu Sep 17 15:49:02.480151 2026] [security2:error] [pid 102783:tid 102960] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHGzgAAALQ"]
[Thu Sep 17 15:49:02.484295 2026] [security2:error] [pid 102783:tid 103032] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/app/.env"] [unique_id "aqxgTszioAAmEecB_LHHJAAAAPw"]
[Thu Sep 17 15:49:02.502333 2026] [security2:error] [pid 102783:tid 102988] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHG0QAAANA"]
[Thu Sep 17 15:49:02.502864 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHG5gAA6Fc"]
[Thu Sep 17 15:49:02.506290 2026] [security2:error] [pid 102783:tid 102938] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHG2gAAAJ4"]
[Thu Sep 17 15:49:02.512406 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHG4QAA6Bk"]
[Thu Sep 17 15:49:02.514074 2026] [security2:error] [pid 102783:tid 103022] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHG0AAAAPI"]
[Thu Sep 17 15:49:02.539366 2026] [security2:error] [pid 102783:tid 102869] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/site.sql"] [unique_id "aqxgTszioAAmEecB_LHHJgAA6FU"]
[Thu Sep 17 15:49:02.543285 2026] [security2:error] [pid 102783:tid 103006] [client 14.96.156.146:57566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgTszioAAmEecB_LHHKgAAAOI"]
[Thu Sep 17 15:49:02.543372 2026] [security2:error] [pid 102783:tid 103006] [client 14.96.156.146:57566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgTszioAAmEecB_LHHKgAAAOI"]
[Thu Sep 17 15:49:02.638693 2026] [security2:error] [pid 102783:tid 102866] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/2022/.env"] [unique_id "aqxgTszioAAmEecB_LHHMQAA6FI"]
[Thu Sep 17 15:49:02.648173 2026] [security2:error] [pid 102783:tid 102822] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/config.properties.bak"] [unique_id "aqxgTszioAAmEecB_LHHNgAA6CY"]
[Thu Sep 17 15:49:02.648589 2026] [security2:error] [pid 102783:tid 103014] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/apps/.env"] [unique_id "aqxgTszioAAmEecB_LHHNwAAAOo"]
[Thu Sep 17 15:49:02.662082 2026] [security2:error] [pid 102783:tid 103001] [client 52.231.79.181:1861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/about.php"] [unique_id "aqxgTszioAAmEecB_LHHPQAAAN0"]
[Thu Sep 17 15:49:02.675800 2026] [security2:error] [pid 102783:tid 102895] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/wp-config.php.backup"] [unique_id "aqxgTszioAAmEecB_LHHPgAA6G8"]
[Thu Sep 17 15:49:02.775312 2026] [security2:error] [pid 102783:tid 102823] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/shop/.env"] [unique_id "aqxgTszioAAmEecB_LHHRwAA6Cc"]
[Thu Sep 17 15:49:02.787671 2026] [security2:error] [pid 102783:tid 102999] [client 148.227.75.216:23760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTszioAAmEecB_LHHSQAAANs"]
[Thu Sep 17 15:49:02.789827 2026] [security2:error] [pid 102783:tid 102990] [client 34.166.149.166:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/server-info.php"] [unique_id "aqxgTszioAAmEecB_LHHSgAAANI"]
[Thu Sep 17 15:49:02.792649 2026] [security2:error] [pid 102783:tid 102999] [client 148.227.75.216:23760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTszioAAmEecB_LHHSQAAANs"]
[Thu Sep 17 15:49:02.807288 2026] [security2:error] [pid 102783:tid 103019] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/api/.env"] [unique_id "aqxgTszioAAmEecB_LHHSwAAAO8"]
[Thu Sep 17 15:49:02.869999 2026] [security2:error] [pid 102783:tid 102951] [client 122.8.45.84:46159] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTszioAAmEecB_LHHTQAAAKs"]
[Thu Sep 17 15:49:02.870136 2026] [security2:error] [pid 102783:tid 102951] [client 122.8.45.84:46159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgTszioAAmEecB_LHHTQAAAKs"]
[Thu Sep 17 15:49:02.965332 2026] [security2:error] [pid 102783:tid 103025] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/web/.env"] [unique_id "aqxgTszioAAmEecB_LHHUQAAAPU"]
[Thu Sep 17 15:49:03.058483 2026] [security2:error] [pid 102783:tid 102994] [client 52.231.79.181:1180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/randkeyword.php"] [unique_id "aqxgT8zioAAmEecB_LHHUgAAANY"]
[Thu Sep 17 15:49:03.105474 2026] [security2:error] [pid 102783:tid 103026] [client 54.174.58.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moorekuehn.com"] [uri "/index.php"] [unique_id "aqxgTMzioAAmEecB_LHGaAAAAPY"]
[Thu Sep 17 15:49:03.127365 2026] [security2:error] [pid 102783:tid 103028] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/site/.env"] [unique_id "aqxgT8zioAAmEecB_LHHVgAAAPg"]
[Thu Sep 17 15:49:03.171145 2026] [security2:error] [pid 102783:tid 102981] [client 177.44.133.72:52009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgT8zioAAmEecB_LHHVwAAAMk"]
[Thu Sep 17 15:49:03.171260 2026] [security2:error] [pid 102783:tid 102981] [client 177.44.133.72:52009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgT8zioAAmEecB_LHHVwAAAMk"]
[Thu Sep 17 15:49:03.288478 2026] [security2:error] [pid 102783:tid 102932] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/public/.env"] [unique_id "aqxgT8zioAAmEecB_LHHWgAAAJg"]
[Thu Sep 17 15:49:03.319921 2026] [security2:error] [pid 102783:tid 102949] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTczioAAmEecB_LHG7AAAAKk"]
[Thu Sep 17 15:49:03.394995 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHGwAA6FY"]
[Thu Sep 17 15:49:03.412981 2026] [security2:error] [pid 102783:tid 103037] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHHQAAAQE"]
[Thu Sep 17 15:49:03.426052 2026] [security2:error] [pid 102783:tid 103013] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHIQAAAOk"]
[Thu Sep 17 15:49:03.460114 2026] [security2:error] [pid 102783:tid 102974] [client 52.231.79.181:1481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/goods.php"] [unique_id "aqxgT8zioAAmEecB_LHHYwAAAMI"]
[Thu Sep 17 15:49:03.466924 2026] [security2:error] [pid 102783:tid 102982] [client 34.166.149.166:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/server-status.php"] [unique_id "aqxgT8zioAAmEecB_LHHZAAAAMo"]
[Thu Sep 17 15:49:03.657196 2026] [security2:error] [pid 102783:tid 103002] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/backend/.env"] [unique_id "aqxgT8zioAAmEecB_LHHcAAAAN4"]
[Thu Sep 17 15:49:03.821385 2026] [security2:error] [pid 102783:tid 103014] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/server/.env"] [unique_id "aqxgT8zioAAmEecB_LHHeAAAAOo"]
[Thu Sep 17 15:49:03.834194 2026] [security2:error] [pid 102783:tid 103004] [client 122.8.45.84:60405] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgT8zioAAmEecB_LHHegAAAOA"]
[Thu Sep 17 15:49:03.834291 2026] [security2:error] [pid 102783:tid 103004] [client 122.8.45.84:60405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgT8zioAAmEecB_LHHegAAAOA"]
[Thu Sep 17 15:49:03.888262 2026] [security2:error] [pid 102783:tid 102956] [client 52.231.79.181:1162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/hehe.php"] [unique_id "aqxgT8zioAAmEecB_LHHfAAAALA"]
[Thu Sep 17 15:49:03.976694 2026] [security2:error] [pid 102783:tid 102947] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/frontend/.env"] [unique_id "aqxgT8zioAAmEecB_LHHfQAAAKc"]
[Thu Sep 17 15:49:04.142292 2026] [security2:error] [pid 102783:tid 102933] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/src/.env"] [unique_id "aqxgUMzioAAmEecB_LHHgQAAAJk"]
[Thu Sep 17 15:49:04.298849 2026] [security2:error] [pid 102783:tid 103003] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/core/.env"] [unique_id "aqxgUMzioAAmEecB_LHHiQAAAN8"]
[Thu Sep 17 15:49:04.306275 2026] [security2:error] [pid 102783:tid 102920] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHIgAAAIw"]
[Thu Sep 17 15:49:04.327645 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHOgAA6Cs"]
[Thu Sep 17 15:49:04.330239 2026] [security2:error] [pid 102783:tid 102928] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHIAAAAJQ"]
[Thu Sep 17 15:49:04.332068 2026] [security2:error] [pid 102783:tid 102972] [client 52.231.79.181:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/user.php"] [unique_id "aqxgUMzioAAmEecB_LHHigAAAMA"]
[Thu Sep 17 15:49:04.343167 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHSAAA6Ag"]
[Thu Sep 17 15:49:04.344680 2026] [security2:error] [pid 102783:tid 103005] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHUAAAAOE"]
[Thu Sep 17 15:49:04.345072 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHMgAA6Bs"]
[Thu Sep 17 15:49:04.363814 2026] [security2:error] [pid 102783:tid 102915] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHPwAAAIc"]
[Thu Sep 17 15:49:04.379213 2026] [security2:error] [pid 102783:tid 102989] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHQAAAANE"]
[Thu Sep 17 15:49:04.380876 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHTAAA6DI"]
[Thu Sep 17 15:49:04.381698 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHKAAA6EE"]
[Thu Sep 17 15:49:04.395711 2026] [security2:error] [pid 102783:tid 103015] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHLAAAAOs"]
[Thu Sep 17 15:49:04.400933 2026] [security2:error] [pid 102783:tid 102948] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgTszioAAmEecB_LHHMwAAAKg"]
[Thu Sep 17 15:49:04.467259 2026] [security2:error] [pid 102783:tid 103013] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/core/app/.env"] [unique_id "aqxgUMzioAAmEecB_LHHjwAAAOk"]
[Thu Sep 17 15:49:04.488967 2026] [security2:error] [pid 102783:tid 102988] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgT8zioAAmEecB_LHHZwAAANA"]
[Thu Sep 17 15:49:04.498764 2026] [security2:error] [pid 102783:tid 102896] [remote 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgT8zioAAmEecB_LHHbQAA6HA"]
[Thu Sep 17 15:49:04.501012 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgT8zioAAmEecB_LHHbAAA6GY"]
[Thu Sep 17 15:49:04.513693 2026] [security2:error] [pid 102783:tid 103007] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgT8zioAAmEecB_LHHagAAAOM"]
[Thu Sep 17 15:49:04.519514 2026] [security2:error] [pid 102783:tid 102814] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/.env.local.orig"] [unique_id "aqxgUMzioAAmEecB_LHHkwAA6B4"]
[Thu Sep 17 15:49:04.521275 2026] [security2:error] [pid 102783:tid 102856] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.113.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/app_dev.php"] [unique_id "aqxgUMzioAAmEecB_LHHlgAA6Eg"]
[Thu Sep 17 15:49:04.521774 2026] [security2:error] [pid 102783:tid 102900] [remote 34.38.113.44:43946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/2020/.env"] [unique_id "aqxgUMzioAAmEecB_LHHlQAA6HQ"]
[Thu Sep 17 15:49:04.618877 2026] [security2:error] [pid 102783:tid 103002] [client 34.166.149.166:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/webroot/index.php/_environment"] [unique_id "aqxgUMzioAAmEecB_LHHnwAAAN4"]
[Thu Sep 17 15:49:04.627011 2026] [security2:error] [pid 102783:tid 102934] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/config/.env"] [unique_id "aqxgUMzioAAmEecB_LHHoAAAAJo"]
[Thu Sep 17 15:49:04.665271 2026] [security2:error] [pid 102783:tid 103004] [client 4.240.114.86:51739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "aqxgUMzioAAmEecB_LHHogAAAOA"], referer: binance.com
[Thu Sep 17 15:49:04.702436 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgUMzioAAmEecB_LHHlAAA6As"]
[Thu Sep 17 15:49:04.707354 2026] [security2:error] [pid 102783:tid 103012] [client 34.38.113.44:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgUMzioAAmEecB_LHHlwAA6EU"]
[Thu Sep 17 15:49:04.731932 2026] [security2:error] [pid 102783:tid 102918] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgUMzioAAmEecB_LHHmwAAAIo"]
[Thu Sep 17 15:49:04.733594 2026] [security2:error] [pid 102783:tid 102957] [client 52.231.79.181:1133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/wp-2019.php"] [unique_id "aqxgUMzioAAmEecB_LHHowAAALE"]
[Thu Sep 17 15:49:04.832595 2026] [security2:error] [pid 102783:tid 102913] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/private/.env"] [unique_id "aqxgUMzioAAmEecB_LHHqAAAAIU"]
[Thu Sep 17 15:49:04.918574 2026] [security2:error] [pid 102783:tid 102981] [client 122.8.45.84:49603] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUMzioAAmEecB_LHHpwAAAMk"]
[Thu Sep 17 15:49:04.918733 2026] [security2:error] [pid 102783:tid 102981] [client 122.8.45.84:49603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUMzioAAmEecB_LHHpwAAAMk"]
[Thu Sep 17 15:49:04.989170 2026] [security2:error] [pid 102783:tid 102951] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/application/.env"] [unique_id "aqxgUMzioAAmEecB_LHHrQAAAKs"]
[Thu Sep 17 15:49:05.146011 2026] [security2:error] [pid 102783:tid 102920] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/bootstrap/.env"] [unique_id "aqxgUczioAAmEecB_LHHsgAAAIw"]
[Thu Sep 17 15:49:05.171906 2026] [security2:error] [pid 102783:tid 103009] [client 79.116.89.151:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUczioAAmEecB_LHHswAAAOU"]
[Thu Sep 17 15:49:05.174748 2026] [security2:error] [pid 102783:tid 103009] [client 79.116.89.151:53484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUczioAAmEecB_LHHswAAAOU"]
[Thu Sep 17 15:49:05.178704 2026] [security2:error] [pid 102783:tid 102933] [client 52.231.79.181:2381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/chosen.php"] [unique_id "aqxgUczioAAmEecB_LHHtAAAAJk"]
[Thu Sep 17 15:49:05.301715 2026] [security2:error] [pid 102783:tid 103028] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/database/.env"] [unique_id "aqxgUczioAAmEecB_LHHtgAAAPg"]
[Thu Sep 17 15:49:05.312585 2026] [security2:error] [pid 102783:tid 103017] [client 34.166.149.166:58248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/mail/phpinfo.php"] [unique_id "aqxgUczioAAmEecB_LHHuQAAAO0"]
[Thu Sep 17 15:49:05.383966 2026] [security2:error] [pid 102783:tid 102943] [client 34.38.113.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneysmartlatina.zyl.uvd.mybluehost.me"] [uri "/index.php"] [unique_id "aqxgUMzioAAmEecB_LHHmgAAAKM"]
[Thu Sep 17 15:49:05.465159 2026] [security2:error] [pid 102783:tid 102968] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/storage/.env"] [unique_id "aqxgUczioAAmEecB_LHHvwAAALw"]
[Thu Sep 17 15:49:05.591443 2026] [security2:error] [pid 102783:tid 102980] [client 52.231.79.181:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/functions.php"] [unique_id "aqxgUczioAAmEecB_LHHxQAAAMg"]
[Thu Sep 17 15:49:05.625500 2026] [security2:error] [pid 102783:tid 103007] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/var/www/.env"] [unique_id "aqxgUczioAAmEecB_LHHxgAAAOM"]
[Thu Sep 17 15:49:05.800849 2026] [security2:error] [pid 102783:tid 102983] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/var/www/html/.env"] [unique_id "aqxgUczioAAmEecB_LHHygAAAMs"]
[Thu Sep 17 15:49:05.883181 2026] [security2:error] [pid 102783:tid 102995] [client 122.8.45.84:38649] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUczioAAmEecB_LHHzAAAANc"]
[Thu Sep 17 15:49:05.883278 2026] [security2:error] [pid 102783:tid 102995] [client 122.8.45.84:38649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUczioAAmEecB_LHHzAAAANc"]
[Thu Sep 17 15:49:05.923523 2026] [security2:error] [pid 102783:tid 102977] [client 34.166.142.248:40422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.mxf.mht.mybluehost.me"] [uri "/"] [unique_id "aqxgUczioAAmEecB_LHHzQAAAMU"]
[Thu Sep 17 15:49:05.959736 2026] [security2:error] [pid 102783:tid 103030] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/current/.env"] [unique_id "aqxgUczioAAmEecB_LHHzwAAAPo"]
[Thu Sep 17 15:49:06.003232 2026] [security2:error] [pid 102783:tid 102929] [client 34.166.149.166:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxgUszioAAmEecB_LHH0QAAAJU"]
[Thu Sep 17 15:49:06.017559 2026] [security2:error] [pid 102783:tid 103034] [client 52.231.79.181:1119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/cron.php"] [unique_id "aqxgUszioAAmEecB_LHH1gAAAP4"]
[Thu Sep 17 15:49:06.122571 2026] [security2:error] [pid 102783:tid 102923] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/release/.env"] [unique_id "aqxgUszioAAmEecB_LHH2QAAAI8"]
[Thu Sep 17 15:49:06.285969 2026] [security2:error] [pid 102783:tid 102999] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/releases/.env"] [unique_id "aqxgUszioAAmEecB_LHH3AAAANs"]
[Thu Sep 17 15:49:06.420897 2026] [security2:error] [pid 102783:tid 102990] [client 52.231.79.181:1486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/gecko-new.php"] [unique_id "aqxgUszioAAmEecB_LHH5AAAANI"]
[Thu Sep 17 15:49:06.447688 2026] [security2:error] [pid 102783:tid 102920] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/shared/.env"] [unique_id "aqxgUszioAAmEecB_LHH5QAAAIw"]
[Thu Sep 17 15:49:06.607307 2026] [security2:error] [pid 102783:tid 103024] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/deploy/.env"] [unique_id "aqxgUszioAAmEecB_LHH7AAAAPQ"]
[Thu Sep 17 15:49:06.624105 2026] [security2:error] [pid 102783:tid 102916] [client 34.166.142.248:40424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.mxf.mht.mybluehost.me"] [uri "/"] [unique_id "aqxgUszioAAmEecB_LHH7QAAAIg"]
[Thu Sep 17 15:49:06.695533 2026] [security2:error] [pid 102783:tid 102928] [client 34.166.149.166:48412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/hosting/phpinfo.php"] [unique_id "aqxgUszioAAmEecB_LHH7wAAAJQ"]
[Thu Sep 17 15:49:06.767972 2026] [security2:error] [pid 102783:tid 102924] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/build/.env"] [unique_id "aqxgUszioAAmEecB_LHH8gAAAJA"]
[Thu Sep 17 15:49:06.819691 2026] [security2:error] [pid 102783:tid 102996] [client 52.231.79.181:1125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/cookie.php"] [unique_id "aqxgUszioAAmEecB_LHH9gAAANg"]
[Thu Sep 17 15:49:06.871279 2026] [security2:error] [pid 102783:tid 103033] [client 122.8.45.84:37395] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUszioAAmEecB_LHH-gAAAP0"]
[Thu Sep 17 15:49:06.871937 2026] [security2:error] [pid 102783:tid 103033] [client 122.8.45.84:37395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgUszioAAmEecB_LHH-gAAAP0"]
[Thu Sep 17 15:49:06.927691 2026] [security2:error] [pid 102783:tid 103029] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/dist/.env"] [unique_id "aqxgUszioAAmEecB_LHH_AAAAPk"]
[Thu Sep 17 15:49:07.091328 2026] [security2:error] [pid 102783:tid 102944] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/public_html/.env"] [unique_id "aqxgU8zioAAmEecB_LHIAgAAAKQ"]
[Thu Sep 17 15:49:07.254792 2026] [security2:error] [pid 102783:tid 102988] [client 52.231.79.181:1114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/xleet.php"] [unique_id "aqxgU8zioAAmEecB_LHIBwAAANA"]
[Thu Sep 17 15:49:07.264458 2026] [security2:error] [pid 102783:tid 102998] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/htdocs/.env"] [unique_id "aqxgU8zioAAmEecB_LHICAAAANo"]
[Thu Sep 17 15:49:07.314182 2026] [security2:error] [pid 102783:tid 102980] [client 34.166.142.248:40438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.mxf.mht.mybluehost.me"] [uri "/"] [unique_id "aqxgU8zioAAmEecB_LHICQAAAMg"]
[Thu Sep 17 15:49:07.395929 2026] [security2:error] [pid 102783:tid 102974] [client 34.166.149.166:48418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/webmail/phpinfo.php"] [unique_id "aqxgU8zioAAmEecB_LHIDgAAAMI"]
[Thu Sep 17 15:49:07.413772 2026] [authz_core:error] [pid 102783:tid 102914] [client 169.58.197.253:60750] AH01630: client denied by server configuration: /home2/brianpag/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:49:07.424401 2026] [security2:error] [pid 102783:tid 102995] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/www/.env"] [unique_id "aqxgU8zioAAmEecB_LHIDwAAANc"]
[Thu Sep 17 15:49:07.581701 2026] [security2:error] [pid 102783:tid 103022] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/html/.env"] [unique_id "aqxgU8zioAAmEecB_LHIEQAAAPI"]
[Thu Sep 17 15:49:07.661558 2026] [security2:error] [pid 102783:tid 103030] [client 52.231.79.181:1969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/spip.php"] [unique_id "aqxgU8zioAAmEecB_LHIFgAAAPo"]
[Thu Sep 17 15:49:07.740514 2026] [security2:error] [pid 102783:tid 102975] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/live/.env"] [unique_id "aqxgU8zioAAmEecB_LHIFwAAAMM"]
[Thu Sep 17 15:49:07.864730 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:26541] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgU8zioAAmEecB_LHIGwAAAI0"]
[Thu Sep 17 15:49:07.864842 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:26541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgU8zioAAmEecB_LHIGwAAAI0"]
[Thu Sep 17 15:49:07.895423 2026] [security2:error] [pid 102783:tid 102918] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/prod/.env"] [unique_id "aqxgU8zioAAmEecB_LHIHAAAAIo"]
[Thu Sep 17 15:49:08.050837 2026] [security2:error] [pid 102783:tid 102999] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/dev/.env"] [unique_id "aqxgVMzioAAmEecB_LHIHgAAANs"]
[Thu Sep 17 15:49:08.060666 2026] [security2:error] [pid 102783:tid 103001] [client 52.231.79.181:2368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/22.php"] [unique_id "aqxgVMzioAAmEecB_LHIHwAAAN0"]
[Thu Sep 17 15:49:08.083344 2026] [security2:error] [pid 102783:tid 103008] [client 34.166.149.166:48424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/smtp/phpinfo.php"] [unique_id "aqxgVMzioAAmEecB_LHIIQAAAOQ"]
[Thu Sep 17 15:49:08.205579 2026] [security2:error] [pid 102783:tid 102955] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/staging/.env"] [unique_id "aqxgVMzioAAmEecB_LHIJgAAAK8"]
[Thu Sep 17 15:49:08.226406 2026] [security2:error] [pid 102783:tid 103027] [client 34.166.142.248:40452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel.mxf.mht.mybluehost.me"] [uri "/"] [unique_id "aqxgVMzioAAmEecB_LHIKAAAAPc"]
[Thu Sep 17 15:49:08.289277 2026] [security2:error] [pid 102783:tid 102916] [client 4.240.114.86:53641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/style-engine.php"] [unique_id "aqxgVMzioAAmEecB_LHILAAAAIg"], referer: binance.com
[Thu Sep 17 15:49:08.363680 2026] [security2:error] [pid 102783:tid 102985] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/opt/.env"] [unique_id "aqxgVMzioAAmEecB_LHILQAAAM0"]
[Thu Sep 17 15:49:08.392125 2026] [security2:error] [pid 102783:tid 102965] [client 66.249.73.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theholyarkproject.com"] [uri "/index.php"] [unique_id "aqxgUszioAAmEecB_LHH4wAAALk"]
[Thu Sep 17 15:49:08.470865 2026] [security2:error] [pid 102783:tid 102945] [client 52.231.79.181:1154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/room.php"] [unique_id "aqxgVMzioAAmEecB_LHIMAAAAKU"]
[Thu Sep 17 15:49:08.521241 2026] [security2:error] [pid 102783:tid 103031] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/laravel/.env"] [unique_id "aqxgVMzioAAmEecB_LHIMQAAAPs"]
[Thu Sep 17 15:49:08.681048 2026] [security2:error] [pid 102783:tid 103026] [client 34.154.21.169:54354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/symfony/.env"] [unique_id "aqxgVMzioAAmEecB_LHIPQAAAPY"]
[Thu Sep 17 15:49:08.763238 2026] [security2:error] [pid 102783:tid 102924] [client 34.166.149.166:48440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/phpinfo.php.bak"] [unique_id "aqxgVMzioAAmEecB_LHIQQAAAJA"]
[Thu Sep 17 15:49:08.856786 2026] [security2:error] [pid 102783:tid 102962] [client 122.8.45.84:29485] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgVMzioAAmEecB_LHIRAAAALY"]
[Thu Sep 17 15:49:08.856908 2026] [security2:error] [pid 102783:tid 102962] [client 122.8.45.84:29485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgVMzioAAmEecB_LHIRAAAALY"]
[Thu Sep 17 15:49:08.875604 2026] [security2:error] [pid 102783:tid 102954] [client 52.231.79.181:2371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/disagreed.php"] [unique_id "aqxgVMzioAAmEecB_LHIRwAAAK4"]
[Thu Sep 17 15:49:09.157678 2026] [security2:error] [pid 102783:tid 102974] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/wordpress/.env"] [unique_id "aqxgVczioAAmEecB_LHIUgAAAMI"]
[Thu Sep 17 15:49:09.322504 2026] [security2:error] [pid 102783:tid 102993] [client 52.231.79.181:1963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/text.php"] [unique_id "aqxgVczioAAmEecB_LHIWAAAANU"]
[Thu Sep 17 15:49:09.323093 2026] [security2:error] [pid 102783:tid 103040] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/wp/.env"] [unique_id "aqxgVczioAAmEecB_LHIWQAAAQQ"]
[Thu Sep 17 15:49:09.442044 2026] [security2:error] [pid 102783:tid 103034] [client 34.166.149.166:48442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/phpinfo.php.old"] [unique_id "aqxgVczioAAmEecB_LHIWwAAAP4"]
[Thu Sep 17 15:49:09.477818 2026] [security2:error] [pid 102783:tid 102921] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/cms/.env"] [unique_id "aqxgVczioAAmEecB_LHIXAAAAI0"]
[Thu Sep 17 15:49:09.574343 2026] [security2:error] [pid 102783:tid 103025] [client 165.154.36.113:60554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxgUszioAAmEecB_LHH_QAAAPU"], referer: https://mdp.iax.mybluehost.me/favicon.ico
[Thu Sep 17 15:49:09.645848 2026] [security2:error] [pid 102783:tid 102955] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/drupal/.env"] [unique_id "aqxgVczioAAmEecB_LHIYwAAAK8"]
[Thu Sep 17 15:49:09.736830 2026] [security2:error] [pid 102783:tid 102951] [client 52.231.79.181:1941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/alfa-rex.php"] [unique_id "aqxgVczioAAmEecB_LHIZQAAAKs"]
[Thu Sep 17 15:49:09.804697 2026] [security2:error] [pid 102783:tid 103010] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/joomla/.env"] [unique_id "aqxgVczioAAmEecB_LHIaQAAAOY"]
[Thu Sep 17 15:49:09.812122 2026] [security2:error] [pid 102783:tid 102997] [client 122.8.45.84:38185] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgVczioAAmEecB_LHIagAAANk"]
[Thu Sep 17 15:49:09.812218 2026] [security2:error] [pid 102783:tid 102997] [client 122.8.45.84:38185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgVczioAAmEecB_LHIagAAANk"]
[Thu Sep 17 15:49:09.959960 2026] [security2:error] [pid 102783:tid 102941] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/magento/.env"] [unique_id "aqxgVczioAAmEecB_LHIbQAAAKE"]
[Thu Sep 17 15:49:10.003803 2026] [security2:error] [pid 102783:tid 102982] [client 105.103.152.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "danijelascatshop.me"] [uri "/index.php"] [unique_id "aqxgU8zioAAmEecB_LHIBgAAAMo"], referer: https://danijelascatshop.com/
[Thu Sep 17 15:49:10.116393 2026] [security2:error] [pid 102783:tid 103026] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/shopify/.env"] [unique_id "aqxgVszioAAmEecB_LHIdAAAAPY"]
[Thu Sep 17 15:49:10.132107 2026] [security2:error] [pid 102783:tid 102945] [client 52.231.79.181:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/alfa-rex.php7"] [unique_id "aqxgVszioAAmEecB_LHIdgAAAKU"]
[Thu Sep 17 15:49:10.143871 2026] [security2:error] [pid 102783:tid 102956] [client 34.166.149.166:48458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/phpinfo.php~"] [unique_id "aqxgVszioAAmEecB_LHIdwAAALA"]
[Thu Sep 17 15:49:10.274004 2026] [security2:error] [pid 102783:tid 102948] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/prestashop/.env"] [unique_id "aqxgVszioAAmEecB_LHIewAAAKg"]
[Thu Sep 17 15:49:10.407297 2026] [security2:error] [pid 102783:tid 103029] [client 74.7.244.27:55086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-f89fe5aa.deh.kei.mybluehost.me"] [uri "/robots.txt"] [unique_id "aqxgVszioAAmEecB_LHIhQAAAPk"]
[Thu Sep 17 15:49:10.437403 2026] [security2:error] [pid 102783:tid 102952] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/codeigniter/.env"] [unique_id "aqxgVszioAAmEecB_LHIhgAAAKw"]
[Thu Sep 17 15:49:10.527770 2026] [security2:error] [pid 102783:tid 103007] [client 52.231.79.181:1937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/radio.php"] [unique_id "aqxgVszioAAmEecB_LHIhwAAAOM"]
[Thu Sep 17 15:49:10.591972 2026] [security2:error] [pid 102783:tid 102998] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/cakephp/.env"] [unique_id "aqxgVszioAAmEecB_LHIiwAAANo"]
[Thu Sep 17 15:49:10.748536 2026] [security2:error] [pid 102783:tid 102923] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/zend/.env"] [unique_id "aqxgVszioAAmEecB_LHIjgAAAI8"]
[Thu Sep 17 15:49:10.770614 2026] [security2:error] [pid 102783:tid 103013] [client 122.8.45.84:20907] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgVszioAAmEecB_LHIkQAAAOk"]
[Thu Sep 17 15:49:10.770714 2026] [security2:error] [pid 102783:tid 103013] [client 122.8.45.84:20907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgVszioAAmEecB_LHIkQAAAOk"]
[Thu Sep 17 15:49:10.821472 2026] [security2:error] [pid 102783:tid 102992] [client 34.166.149.166:48466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/info.php.bak"] [unique_id "aqxgVszioAAmEecB_LHIlAAAANQ"]
[Thu Sep 17 15:49:10.907742 2026] [security2:error] [pid 102783:tid 103030] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/yii/.env"] [unique_id "aqxgVszioAAmEecB_LHIlQAAAPo"]
[Thu Sep 17 15:49:10.925678 2026] [security2:error] [pid 102783:tid 102993] [client 52.231.79.181:1108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/dropdown.php"] [unique_id "aqxgVszioAAmEecB_LHIlgAAANU"]
[Thu Sep 17 15:49:11.033623 2026] [security2:error] [pid 102783:tid 103020] [client 171.225.204.54:9825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgVszioAAmEecB_LHIlwAA8Dw"]
[Thu Sep 17 15:49:11.070961 2026] [security2:error] [pid 102783:tid 102961] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/laravel5/.env"] [unique_id "aqxgV8zioAAmEecB_LHImQAAALU"]
[Thu Sep 17 15:49:11.227174 2026] [security2:error] [pid 102783:tid 103025] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/v1/.env"] [unique_id "aqxgV8zioAAmEecB_LHIngAAAPU"]
[Thu Sep 17 15:49:11.340457 2026] [security2:error] [pid 102783:tid 103001] [client 52.231.79.181:1091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/defaults.php"] [unique_id "aqxgV8zioAAmEecB_LHIowAAAN0"]
[Thu Sep 17 15:49:11.387078 2026] [security2:error] [pid 102783:tid 103027] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/v2/.env"] [unique_id "aqxgV8zioAAmEecB_LHIpAAAAPc"]
[Thu Sep 17 15:49:11.503413 2026] [security2:error] [pid 102783:tid 102990] [client 34.166.149.166:48482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/phpinfo.php.save"] [unique_id "aqxgV8zioAAmEecB_LHIqAAAANI"]
[Thu Sep 17 15:49:11.546758 2026] [security2:error] [pid 102783:tid 103010] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/v3/.env"] [unique_id "aqxgV8zioAAmEecB_LHIqQAAAOY"]
[Thu Sep 17 15:49:11.700406 2026] [security2:error] [pid 102783:tid 102950] [client 122.8.45.84:48483] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgV8zioAAmEecB_LHIsAAAAKo"]
[Thu Sep 17 15:49:11.700540 2026] [security2:error] [pid 102783:tid 102950] [client 122.8.45.84:48483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgV8zioAAmEecB_LHIsAAAAKo"]
[Thu Sep 17 15:49:11.702452 2026] [security2:error] [pid 102783:tid 102965] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/api/v1/.env"] [unique_id "aqxgV8zioAAmEecB_LHIsQAAALk"]
[Thu Sep 17 15:49:11.733391 2026] [security2:error] [pid 102783:tid 102985] [client 52.231.79.181:1101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/system.php"] [unique_id "aqxgV8zioAAmEecB_LHIsgAAAM0"]
[Thu Sep 17 15:49:11.859338 2026] [security2:error] [pid 102783:tid 102978] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/api/v2/.env"] [unique_id "aqxgV8zioAAmEecB_LHItwAAAMY"]
[Thu Sep 17 15:49:11.957469 2026] [security2:error] [pid 102783:tid 103005] [client 162.241.226.11:54632] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "devilsarmynetwork.com"] [uri "/wp-cron.php"] [unique_id "aqxgV8zioAAmEecB_LHIuAAAAOE"]
[Thu Sep 17 15:49:12.014244 2026] [security2:error] [pid 102783:tid 102956] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/rest/.env"] [unique_id "aqxgWMzioAAmEecB_LHIugAAALA"]
[Thu Sep 17 15:49:12.170136 2026] [security2:error] [pid 102783:tid 102991] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/graphql/.env"] [unique_id "aqxgWMzioAAmEecB_LHIvgAAANM"]
[Thu Sep 17 15:49:12.184612 2026] [security2:error] [pid 102783:tid 102945] [client 34.166.149.166:48496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/staging/phpinfo.php"] [unique_id "aqxgWMzioAAmEecB_LHIwAAAAKU"]
[Thu Sep 17 15:49:12.210400 2026] [security2:error] [pid 102783:tid 103015] [client 52.231.79.181:1960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/xmlrpc.php"] [unique_id "aqxgWMzioAAmEecB_LHIvwAAAOs"]
[Thu Sep 17 15:49:12.324920 2026] [security2:error] [pid 102783:tid 103002] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/gateway/.env"] [unique_id "aqxgWMzioAAmEecB_LHIzAAAAN4"]
[Thu Sep 17 15:49:12.439619 2026] [security2:error] [pid 102783:tid 102931] [client 4.240.114.86:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "aqxgWMzioAAmEecB_LHIzwAAAJc"], referer: binance.com
[Thu Sep 17 15:49:12.471787 2026] [security2:error] [pid 102783:tid 103026] [client 143.105.152.240:61346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgWMzioAAmEecB_LHI0AAAAPY"]
[Thu Sep 17 15:49:12.481929 2026] [security2:error] [pid 102783:tid 102974] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/microservice/.env"] [unique_id "aqxgWMzioAAmEecB_LHI0QAAAMI"]
[Thu Sep 17 15:49:12.482502 2026] [security2:error] [pid 102783:tid 103026] [client 143.105.152.240:61346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgWMzioAAmEecB_LHI0AAAAPY"]
[Thu Sep 17 15:49:12.612022 2026] [security2:error] [pid 102783:tid 102944] [client 52.231.79.181:1978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/xmlrpc.php0"] [unique_id "aqxgWMzioAAmEecB_LHI1AAAAKQ"]
[Thu Sep 17 15:49:12.636975 2026] [security2:error] [pid 102783:tid 102962] [client 122.8.45.84:15557] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWMzioAAmEecB_LHI1gAAALY"]
[Thu Sep 17 15:49:12.637103 2026] [security2:error] [pid 102783:tid 102962] [client 122.8.45.84:15557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWMzioAAmEecB_LHI1gAAALY"]
[Thu Sep 17 15:49:12.639365 2026] [security2:error] [pid 102783:tid 103013] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/service/.env"] [unique_id "aqxgWMzioAAmEecB_LHI1wAAAOk"]
[Thu Sep 17 15:49:12.798122 2026] [security2:error] [pid 102783:tid 102961] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/api/v3/.env"] [unique_id "aqxgWMzioAAmEecB_LHI3QAAALU"]
[Thu Sep 17 15:49:12.869696 2026] [security2:error] [pid 102783:tid 103040] [client 34.166.149.166:48512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/beta/phpinfo.php"] [unique_id "aqxgWMzioAAmEecB_LHI3gAAAQQ"]
[Thu Sep 17 15:49:12.952156 2026] [security2:error] [pid 102783:tid 102979] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/api/dev/.env"] [unique_id "aqxgWMzioAAmEecB_LHI4wAAAMc"]
[Thu Sep 17 15:49:13.017861 2026] [security2:error] [pid 102783:tid 102955] [client 52.231.79.181:1104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/colors.php"] [unique_id "aqxgWczioAAmEecB_LHI5QAAAK8"]
[Thu Sep 17 15:49:13.096936 2026] [security2:error] [pid 102783:tid 103001] [client 14.96.156.146:58253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHI5gAAAN0"]
[Thu Sep 17 15:49:13.097064 2026] [security2:error] [pid 102783:tid 103001] [client 14.96.156.146:58253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHI5gAAAN0"]
[Thu Sep 17 15:49:13.109167 2026] [security2:error] [pid 102783:tid 102933] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/api/staging/.env"] [unique_id "aqxgWczioAAmEecB_LHI6QAAAJk"]
[Thu Sep 17 15:49:13.264784 2026] [security2:error] [pid 102783:tid 102943] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/vendor/.env"] [unique_id "aqxgWczioAAmEecB_LHI7wAAAKM"]
[Thu Sep 17 15:49:13.405270 2026] [security2:error] [pid 102783:tid 103038] [client 148.227.75.216:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHI8wAAAQI"]
[Thu Sep 17 15:49:13.408162 2026] [security2:error] [pid 102783:tid 103038] [client 148.227.75.216:42816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHI8wAAAQI"]
[Thu Sep 17 15:49:13.417194 2026] [security2:error] [pid 102783:tid 102978] [client 52.231.79.181:1115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/updates.php"] [unique_id "aqxgWczioAAmEecB_LHI9QAAAMY"]
[Thu Sep 17 15:49:13.417935 2026] [security2:error] [pid 102783:tid 102984] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/lib/.env"] [unique_id "aqxgWczioAAmEecB_LHI9AAAAMw"]
[Thu Sep 17 15:49:13.545179 2026] [security2:error] [pid 102783:tid 103031] [client 34.166.149.166:48516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/uat/phpinfo.php"] [unique_id "aqxgWczioAAmEecB_LHI9gAAAPs"]
[Thu Sep 17 15:49:13.586886 2026] [security2:error] [pid 102783:tid 102969] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/resources/.env"] [unique_id "aqxgWczioAAmEecB_LHI-AAAAL0"]
[Thu Sep 17 15:49:13.590535 2026] [security2:error] [pid 102783:tid 102988] [client 122.8.45.84:41549] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHI-QAAANA"]
[Thu Sep 17 15:49:13.590618 2026] [security2:error] [pid 102783:tid 102988] [client 122.8.45.84:41549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHI-QAAANA"]
[Thu Sep 17 15:49:13.696421 2026] [security2:error] [pid 102783:tid 102922] [client 190.162.110.175:46996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgWczioAAmEecB_LHI9wAAjmk"]
[Thu Sep 17 15:49:13.740400 2026] [security2:error] [pid 102783:tid 102991] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/assets/.env"] [unique_id "aqxgWczioAAmEecB_LHI_gAAANM"]
[Thu Sep 17 15:49:13.749071 2026] [security2:error] [pid 102783:tid 102915] [client 177.44.133.72:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHJAAAAAIc"]
[Thu Sep 17 15:49:13.749174 2026] [security2:error] [pid 102783:tid 102915] [client 177.44.133.72:52664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgWczioAAmEecB_LHJAAAAAIc"]
[Thu Sep 17 15:49:13.809550 2026] [cgid:error] [pid 102783:tid 103000] [client 221.149.119.65:12579] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/theworn6/public_html/404.shtml, referer: http://theworldinc.com/Old
[Thu Sep 17 15:49:13.816005 2026] [security2:error] [pid 102783:tid 102948] [client 52.231.79.181:1980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/alfa-rex1.php"] [unique_id "aqxgWczioAAmEecB_LHJBAAAAKg"]
[Thu Sep 17 15:49:13.901946 2026] [security2:error] [pid 102783:tid 102960] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/uploads/.env"] [unique_id "aqxgWczioAAmEecB_LHJBgAAALQ"]
[Thu Sep 17 15:49:14.090842 2026] [security2:error] [pid 102783:tid 102938] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/internal/.env"] [unique_id "aqxgWszioAAmEecB_LHJCAAAAJ4"]
[Thu Sep 17 15:49:14.245194 2026] [security2:error] [pid 102783:tid 103014] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/tools/.env"] [unique_id "aqxgWszioAAmEecB_LHJDwAAAOo"]
[Thu Sep 17 15:49:14.249856 2026] [security2:error] [pid 102783:tid 102968] [client 34.166.149.166:48526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/qa/phpinfo.php"] [unique_id "aqxgWszioAAmEecB_LHJEAAAALw"]
[Thu Sep 17 15:49:14.267382 2026] [security2:error] [pid 102783:tid 103026] [client 52.231.79.181:1106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/wp-admin.php"] [unique_id "aqxgWszioAAmEecB_LHJEQAAAPY"]
[Thu Sep 17 15:49:14.403624 2026] [security2:error] [pid 102783:tid 102971] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/scripts/.env"] [unique_id "aqxgWszioAAmEecB_LHJFgAAAL8"]
[Thu Sep 17 15:49:14.560249 2026] [security2:error] [pid 102783:tid 103025] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/bin/.env"] [unique_id "aqxgWszioAAmEecB_LHJGgAAAPU"]
[Thu Sep 17 15:49:14.563015 2026] [security2:error] [pid 102783:tid 102944] [client 122.8.45.84:57595] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWszioAAmEecB_LHJGwAAAKQ"]
[Thu Sep 17 15:49:14.563097 2026] [security2:error] [pid 102783:tid 102944] [client 122.8.45.84:57595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWszioAAmEecB_LHJGwAAAKQ"]
[Thu Sep 17 15:49:14.677469 2026] [security2:error] [pid 102783:tid 103004] [client 52.231.79.181:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/alfa.php"] [unique_id "aqxgWszioAAmEecB_LHJHwAAAOA"]
[Thu Sep 17 15:49:14.722006 2026] [security2:error] [pid 102783:tid 103027] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/sbin/.env"] [unique_id "aqxgWszioAAmEecB_LHJIAAAAPc"]
[Thu Sep 17 15:49:14.833939 2026] [security2:error] [pid 102783:tid 102961] [client 136.158.61.34:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWszioAAmEecB_LHJJQAAALU"]
[Thu Sep 17 15:49:14.834107 2026] [security2:error] [pid 102783:tid 102961] [client 136.158.61.34:12383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgWszioAAmEecB_LHJJQAAALU"]
[Thu Sep 17 15:49:14.887862 2026] [security2:error] [pid 102783:tid 102950] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/local/.env"] [unique_id "aqxgWszioAAmEecB_LHJJgAAAKo"]
[Thu Sep 17 15:49:14.932379 2026] [security2:error] [pid 102783:tid 102927] [client 34.166.149.166:48532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/preview/phpinfo.php"] [unique_id "aqxgWszioAAmEecB_LHJJwAAAJM"]
[Thu Sep 17 15:49:15.046927 2026] [security2:error] [pid 102783:tid 102916] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/portal/.env"] [unique_id "aqxgW8zioAAmEecB_LHJKQAAAIg"]
[Thu Sep 17 15:49:15.073648 2026] [security2:error] [pid 102783:tid 103024] [client 52.231.79.181:1100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/alfanew.php7"] [unique_id "aqxgW8zioAAmEecB_LHJKgAAAPQ"]
[Thu Sep 17 15:49:15.203745 2026] [security2:error] [pid 102783:tid 102941] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/dashboard/.env"] [unique_id "aqxgW8zioAAmEecB_LHJLgAAAKE"]
[Thu Sep 17 15:49:15.359654 2026] [security2:error] [pid 102783:tid 103017] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/panel/.env"] [unique_id "aqxgW8zioAAmEecB_LHJMwAAAO0"]
[Thu Sep 17 15:49:15.496140 2026] [security2:error] [pid 102783:tid 102949] [client 52.231.79.181:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/locale.php"] [unique_id "aqxgW8zioAAmEecB_LHJNQAAAKk"]
[Thu Sep 17 15:49:15.517770 2026] [security2:error] [pid 102783:tid 103031] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/crm/.env"] [unique_id "aqxgW8zioAAmEecB_LHJNwAAAPs"]
[Thu Sep 17 15:49:15.518178 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:59391] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgW8zioAAmEecB_LHJNgAAAI0"]
[Thu Sep 17 15:49:15.518235 2026] [security2:error] [pid 102783:tid 102921] [client 122.8.45.84:59391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgW8zioAAmEecB_LHJNgAAAI0"]
[Thu Sep 17 15:49:15.609580 2026] [security2:error] [pid 102783:tid 103038] [client 34.166.149.166:48544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/www/phpinfo.php"] [unique_id "aqxgW8zioAAmEecB_LHJOgAAAQI"]
[Thu Sep 17 15:49:15.679319 2026] [security2:error] [pid 102783:tid 102991] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/erp/.env"] [unique_id "aqxgW8zioAAmEecB_LHJPAAAANM"]
[Thu Sep 17 15:49:15.771138 2026] [security2:error] [pid 102783:tid 102951] [client 79.116.89.151:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgW8zioAAmEecB_LHJQQAAAKs"]
[Thu Sep 17 15:49:15.771222 2026] [security2:error] [pid 102783:tid 102951] [client 79.116.89.151:54117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgW8zioAAmEecB_LHJQQAAAKs"]
[Thu Sep 17 15:49:15.841242 2026] [security2:error] [pid 102783:tid 102942] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/shop/.env"] [unique_id "aqxgW8zioAAmEecB_LHJQwAAAKI"]
[Thu Sep 17 15:49:15.899266 2026] [security2:error] [pid 102783:tid 103000] [client 52.231.79.181:1954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/wxo.php"] [unique_id "aqxgW8zioAAmEecB_LHJRAAAANw"]
[Thu Sep 17 15:49:16.061286 2026] [security2:error] [pid 102783:tid 102939] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/store/.env"] [unique_id "aqxgXMzioAAmEecB_LHJRgAAAJ8"]
[Thu Sep 17 15:49:16.220656 2026] [security2:error] [pid 102783:tid 102974] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/saas/.env"] [unique_id "aqxgXMzioAAmEecB_LHJTgAAAMI"]
[Thu Sep 17 15:49:16.295774 2026] [security2:error] [pid 102783:tid 102962] [client 52.231.79.181:2378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/colour.php"] [unique_id "aqxgXMzioAAmEecB_LHJVAAAALY"]
[Thu Sep 17 15:49:16.301469 2026] [security2:error] [pid 102783:tid 102977] [client 34.166.149.166:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/htdocs/phpinfo.php"] [unique_id "aqxgXMzioAAmEecB_LHJVQAAAMU"]
[Thu Sep 17 15:49:16.394104 2026] [security2:error] [pid 102783:tid 103022] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/client/.env"] [unique_id "aqxgXMzioAAmEecB_LHJVwAAAPI"]
[Thu Sep 17 15:49:16.493877 2026] [security2:error] [pid 102783:tid 103032] [client 122.8.45.84:48161] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgXMzioAAmEecB_LHJWwAAAPw"]
[Thu Sep 17 15:49:16.493970 2026] [security2:error] [pid 102783:tid 103032] [client 122.8.45.84:48161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgXMzioAAmEecB_LHJWwAAAPw"]
[Thu Sep 17 15:49:16.551846 2026] [security2:error] [pid 102783:tid 103037] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/project/.env"] [unique_id "aqxgXMzioAAmEecB_LHJXAAAAQE"]
[Thu Sep 17 15:49:16.709020 2026] [security2:error] [pid 102783:tid 102918] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/admin-panel/.env"] [unique_id "aqxgXMzioAAmEecB_LHJZAAAAIo"]
[Thu Sep 17 15:49:16.720425 2026] [security2:error] [pid 102783:tid 102944] [client 52.231.79.181:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/install.php"] [unique_id "aqxgXMzioAAmEecB_LHJZQAAAKQ"]
[Thu Sep 17 15:49:16.867114 2026] [security2:error] [pid 102783:tid 102916] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/control-panel/.env"] [unique_id "aqxgXMzioAAmEecB_LHJagAAAIg"]
[Thu Sep 17 15:49:16.990955 2026] [security2:error] [pid 102783:tid 102987] [client 34.166.149.166:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/public_html/phpinfo.php"] [unique_id "aqxgXMzioAAmEecB_LHJbQAAAM8"]
[Thu Sep 17 15:49:17.039253 2026] [security2:error] [pid 102783:tid 102928] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/user-panel/.env"] [unique_id "aqxgXczioAAmEecB_LHJbgAAAJQ"]
[Thu Sep 17 15:49:17.126503 2026] [security2:error] [pid 102783:tid 102967] [client 52.231.79.181:2379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/wp-contentt.php"] [unique_id "aqxgXczioAAmEecB_LHJcgAAALs"]
[Thu Sep 17 15:49:17.206743 2026] [security2:error] [pid 102783:tid 103005] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/node/.env"] [unique_id "aqxgXczioAAmEecB_LHJdAAAAOE"]
[Thu Sep 17 15:49:17.320434 2026] [security2:error] [pid 102783:tid 102978] [client 4.240.114.86:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "aqxgXczioAAmEecB_LHJeQAAAMY"], referer: binance.com
[Thu Sep 17 15:49:17.362045 2026] [security2:error] [pid 102783:tid 102956] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/express/.env"] [unique_id "aqxgXczioAAmEecB_LHJewAAALA"]
[Thu Sep 17 15:49:17.457282 2026] [security2:error] [pid 102783:tid 102943] [client 122.8.45.84:32845] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgXczioAAmEecB_LHJfAAAAKM"]
[Thu Sep 17 15:49:17.457391 2026] [security2:error] [pid 102783:tid 102943] [client 122.8.45.84:32845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgXczioAAmEecB_LHJfAAAAKM"]
[Thu Sep 17 15:49:17.523823 2026] [security2:error] [pid 102783:tid 102921] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/next/.env"] [unique_id "aqxgXczioAAmEecB_LHJfQAAAI0"]
[Thu Sep 17 15:49:17.549962 2026] [security2:error] [pid 102783:tid 102949] [client 52.231.79.181:1950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/config.php7"] [unique_id "aqxgXczioAAmEecB_LHJfgAAAKk"]
[Thu Sep 17 15:49:17.672622 2026] [security2:error] [pid 102783:tid 103031] [client 34.166.149.166:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/site/phpinfo.php"] [unique_id "aqxgXczioAAmEecB_LHJgwAAAPs"]
[Thu Sep 17 15:49:17.688809 2026] [security2:error] [pid 102783:tid 102991] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/nuxt/.env"] [unique_id "aqxgXczioAAmEecB_LHJhAAAANM"]
[Thu Sep 17 15:49:17.846292 2026] [security2:error] [pid 102783:tid 103021] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/nest/.env"] [unique_id "aqxgXczioAAmEecB_LHJigAAAPE"]
[Thu Sep 17 15:49:17.950308 2026] [security2:error] [pid 102783:tid 102942] [client 52.231.79.181:1120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/config.php"] [unique_id "aqxgXczioAAmEecB_LHJjAAAAKI"]
[Thu Sep 17 15:49:18.002988 2026] [security2:error] [pid 102783:tid 102946] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/react/.env"] [unique_id "aqxgXszioAAmEecB_LHJjQAAAKY"]
[Thu Sep 17 15:49:18.160544 2026] [security2:error] [pid 102783:tid 102966] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/vue/.env"] [unique_id "aqxgXszioAAmEecB_LHJkQAAALo"]
[Thu Sep 17 15:49:18.321778 2026] [security2:error] [pid 102783:tid 103025] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/angular/.env"] [unique_id "aqxgXszioAAmEecB_LHJmwAAAPU"]
[Thu Sep 17 15:49:18.349464 2026] [security2:error] [pid 102783:tid 102977] [client 52.231.79.181:1959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/theme.php"] [unique_id "aqxgXszioAAmEecB_LHJnQAAAMU"]
[Thu Sep 17 15:49:18.365653 2026] [security2:error] [pid 102783:tid 102931] [client 34.166.149.166:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/docs/phpinfo.php"] [unique_id "aqxgXszioAAmEecB_LHJngAAAJc"]
[Thu Sep 17 15:49:18.367724 2026] [security2:error] [pid 102783:tid 102954] [client 74.7.175.132:54012] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.rvh.yhy.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "aqxgXszioAAmEecB_LHJnAAAAK4"]
[Thu Sep 17 15:49:18.391500 2026] [security2:error] [pid 102783:tid 102983] [client 122.8.45.84:47185] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgXszioAAmEecB_LHJnwAAAMs"]
[Thu Sep 17 15:49:18.391602 2026] [security2:error] [pid 102783:tid 102983] [client 122.8.45.84:47185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgXszioAAmEecB_LHJnwAAAMs"]
[Thu Sep 17 15:49:18.488875 2026] [security2:error] [pid 102783:tid 102973] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/svelte/.env"] [unique_id "aqxgXszioAAmEecB_LHJoAAAAME"]
[Thu Sep 17 15:49:18.669691 2026] [security2:error] [pid 102783:tid 103027] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/vite/.env"] [unique_id "aqxgXszioAAmEecB_LHJpgAAAPc"]
[Thu Sep 17 15:49:18.759054 2026] [security2:error] [pid 102783:tid 103006] [client 52.231.79.181:1109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/block-bindings.php"] [unique_id "aqxgXszioAAmEecB_LHJqgAAAOI"]
[Thu Sep 17 15:49:18.846566 2026] [security2:error] [pid 102783:tid 102979] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/backup/.env"] [unique_id "aqxgXszioAAmEecB_LHJsgAAAMc"]
[Thu Sep 17 15:49:18.862922 2026] [security2:error] [pid 102783:tid 103013] [client 74.7.228.44:43334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.noanimalsaswaste.org"] [uri "/index.php"] [unique_id "aqxgXMzioAAmEecB_LHJTQAA6W0"]
[Thu Sep 17 15:49:19.026191 2026] [security2:error] [pid 102783:tid 102940] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/backups/.env"] [unique_id "aqxgX8zioAAmEecB_LHJtwAAAKA"]
[Thu Sep 17 15:49:19.064390 2026] [security2:error] [pid 102783:tid 102950] [client 34.166.149.166:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/wp-admin/phpinfo.php"] [unique_id "aqxgX8zioAAmEecB_LHJuAAAAKo"]
[Thu Sep 17 15:49:19.154965 2026] [security2:error] [pid 102783:tid 102989] [client 52.231.79.181:1982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/class_api.php"] [unique_id "aqxgX8zioAAmEecB_LHJvQAAANE"]
[Thu Sep 17 15:49:19.215884 2026] [security2:error] [pid 102783:tid 102924] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/old/.env"] [unique_id "aqxgX8zioAAmEecB_LHJvgAAAJA"]
[Thu Sep 17 15:49:19.361191 2026] [security2:error] [pid 102783:tid 102987] [client 122.8.45.84:13197] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgX8zioAAmEecB_LHJxAAAAM8"]
[Thu Sep 17 15:49:19.361313 2026] [security2:error] [pid 102783:tid 102987] [client 122.8.45.84:13197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgX8zioAAmEecB_LHJxAAAAM8"]
[Thu Sep 17 15:49:19.390566 2026] [security2:error] [pid 102783:tid 102925] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/tmp/.env"] [unique_id "aqxgX8zioAAmEecB_LHJxQAAAJE"]
[Thu Sep 17 15:49:19.553927 2026] [security2:error] [pid 102783:tid 102988] [client 52.231.79.181:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/inputs.php"] [unique_id "aqxgX8zioAAmEecB_LHJxwAAANA"]
[Thu Sep 17 15:49:19.566506 2026] [security2:error] [pid 102783:tid 103039] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/temp/.env"] [unique_id "aqxgX8zioAAmEecB_LHJyAAAAQM"]
[Thu Sep 17 15:49:19.746569 2026] [security2:error] [pid 102783:tid 102991] [client 34.166.149.166:57480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/administrator/phpinfo.php"] [unique_id "aqxgX8zioAAmEecB_LHJzQAAANM"]
[Thu Sep 17 15:49:19.775520 2026] [security2:error] [pid 102783:tid 103021] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/lab/.env"] [unique_id "aqxgX8zioAAmEecB_LHJ0QAAAPE"]
[Thu Sep 17 15:49:19.859544 2026] [security2:error] [pid 102783:tid 103020] [client 37.99.71.21:32681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgX8zioAAmEecB_LHJzgAA8A4"]
[Thu Sep 17 15:49:19.956943 2026] [security2:error] [pid 102783:tid 102995] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/cronlab/.env"] [unique_id "aqxgX8zioAAmEecB_LHJ1QAAANc"]
[Thu Sep 17 15:49:19.971294 2026] [security2:error] [pid 102783:tid 102998] [client 52.231.79.181:1964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/root.php"] [unique_id "aqxgX8zioAAmEecB_LHJ1gAAANo"]
[Thu Sep 17 15:49:20.138308 2026] [security2:error] [pid 102783:tid 102974] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/cron/.env"] [unique_id "aqxgYMzioAAmEecB_LHJ2wAAAMI"]
[Thu Sep 17 15:49:20.300968 2026] [security2:error] [pid 102783:tid 102975] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/en/.env"] [unique_id "aqxgYMzioAAmEecB_LHJ5gAAAMM"]
[Thu Sep 17 15:49:20.356004 2026] [security2:error] [pid 102783:tid 102942] [client 122.8.45.84:54179] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgYMzioAAmEecB_LHJ5wAAAKI"]
[Thu Sep 17 15:49:20.356106 2026] [security2:error] [pid 102783:tid 102942] [client 122.8.45.84:54179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgYMzioAAmEecB_LHJ5wAAAKI"]
[Thu Sep 17 15:49:20.412391 2026] [security2:error] [pid 102783:tid 102977] [client 52.231.79.181:2373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/menu.php"] [unique_id "aqxgYMzioAAmEecB_LHJ6QAAAMU"]
[Thu Sep 17 15:49:20.434131 2026] [security2:error] [pid 102783:tid 103030] [client 34.166.149.166:57482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/core/phpinfo.php"] [unique_id "aqxgYMzioAAmEecB_LHJ6gAAAPo"]
[Thu Sep 17 15:49:20.481731 2026] [security2:error] [pid 102783:tid 102958] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/administrator/.env"] [unique_id "aqxgYMzioAAmEecB_LHJ6wAAALI"]
[Thu Sep 17 15:49:20.651457 2026] [security2:error] [pid 102783:tid 103006] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/psnlink/.env"] [unique_id "aqxgYMzioAAmEecB_LHJ8AAAAOI"]
[Thu Sep 17 15:49:20.807333 2026] [security2:error] [pid 102783:tid 102979] [client 52.231.79.181:1936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/cloud.php"] [unique_id "aqxgYMzioAAmEecB_LHJ_AAAAMc"]
[Thu Sep 17 15:49:20.817715 2026] [security2:error] [pid 102783:tid 102986] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/exapi/.env"] [unique_id "aqxgYMzioAAmEecB_LHJ_QAAAM4"]
[Thu Sep 17 15:49:20.991315 2026] [security2:error] [pid 102783:tid 102984] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/sitemaps/.env"] [unique_id "aqxgYMzioAAmEecB_LHKAwAAAMw"]
[Thu Sep 17 15:49:21.120307 2026] [security2:error] [pid 102783:tid 102924] [client 34.166.149.166:57498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.149.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.svu.saz.mybluehost.me"] [uri "/includes/phpinfo.php"] [unique_id "aqxgYczioAAmEecB_LHKCgAAAJA"]
[Thu Sep 17 15:49:21.242859 2026] [security2:error] [pid 102783:tid 102978] [client 52.231.79.181:1971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/configs.php"] [unique_id "aqxgYczioAAmEecB_LHKEAAAAMY"]
[Thu Sep 17 15:49:21.330161 2026] [security2:error] [pid 102783:tid 103012] [client 122.8.45.84:37037] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgYczioAAmEecB_LHKFwAAAOg"]
[Thu Sep 17 15:49:21.330302 2026] [security2:error] [pid 102783:tid 103012] [client 122.8.45.84:37037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgYczioAAmEecB_LHKFwAAAOg"]
[Thu Sep 17 15:49:21.642945 2026] [security2:error] [pid 102783:tid 103037] [client 52.231.79.181:1973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/wp-configs.php"] [unique_id "aqxgYczioAAmEecB_LHKKQAAAQE"]
[Thu Sep 17 15:49:21.645575 2026] [security2:error] [pid 102783:tid 103030] [client 4.240.114.86:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "aqxgYczioAAmEecB_LHKKgAAAPo"], referer: binance.com
[Thu Sep 17 15:49:21.665263 2026] [security2:error] [pid 102783:tid 103036] [client 34.154.21.169:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/logs/.env"] [unique_id "aqxgYczioAAmEecB_LHKLQAAAQA"]
[Thu Sep 17 15:49:21.987491 2026] [security2:error] [pid 102783:tid 102955] [client 66.249.73.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spursandspiritstx.com"] [uri "/index.php"] [unique_id "aqxgYczioAAmEecB_LHKNwAAAK8"]
[Thu Sep 17 15:49:22.060300 2026] [security2:error] [pid 102783:tid 103013] [client 52.231.79.181:1965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/update.php"] [unique_id "aqxgYszioAAmEecB_LHKPAAAAOk"]
[Thu Sep 17 15:49:22.196160 2026] [security2:error] [pid 102783:tid 102970] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/cache/.env"] [unique_id "aqxgYszioAAmEecB_LHKQgAAAL4"]
[Thu Sep 17 15:49:22.294533 2026] [security2:error] [pid 102783:tid 103040] [client 122.8.45.84:13785] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgYszioAAmEecB_LHKSQAAAQQ"]
[Thu Sep 17 15:49:22.294645 2026] [security2:error] [pid 102783:tid 103040] [client 122.8.45.84:13785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgYszioAAmEecB_LHKSQAAAQQ"]
[Thu Sep 17 15:49:22.362041 2026] [security2:error] [pid 102783:tid 103016] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mailer/.env"] [unique_id "aqxgYszioAAmEecB_LHKSwAAAOw"]
[Thu Sep 17 15:49:22.438716 2026] [security2:error] [pid 102783:tid 102924] [client 189.89.245.57:5178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgYszioAAmEecB_LHKRgAAkHA"]
[Thu Sep 17 15:49:22.471571 2026] [security2:error] [pid 102783:tid 102967] [client 52.231.79.181:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/2.php"] [unique_id "aqxgYszioAAmEecB_LHKTQAAALs"]
[Thu Sep 17 15:49:22.534995 2026] [security2:error] [pid 102783:tid 102951] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mail/.env"] [unique_id "aqxgYszioAAmEecB_LHKUAAAAKs"]
[Thu Sep 17 15:49:22.599050 2026] [security2:error] [pid 102783:tid 102897] [remote 47.128.115.42:50814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1463"] [id "909116"] [msg "Golang default UA"] [hostname "www.joeledmundanderson.com"] [uri "/robots.txt"] [unique_id "aqxgYszioAAmEecB_LHKUgAA8XE"]
[Thu Sep 17 15:49:22.700050 2026] [security2:error] [pid 102783:tid 103002] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/email/.env"] [unique_id "aqxgYszioAAmEecB_LHKVgAAAN4"]
[Thu Sep 17 15:49:22.857183 2026] [security2:error] [pid 102783:tid 102962] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/smtp/.env"] [unique_id "aqxgYszioAAmEecB_LHKWwAAALY"]
[Thu Sep 17 15:49:22.868460 2026] [security2:error] [pid 102783:tid 102939] [client 52.231.79.181:1974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.231.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephaniearnold.net"] [uri "/aaa.php"] [unique_id "aqxgYszioAAmEecB_LHKXQAAAJ8"]
[Thu Sep 17 15:49:23.060325 2026] [security2:error] [pid 102783:tid 102974] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mailing/.env"] [unique_id "aqxgY8zioAAmEecB_LHKYwAAAMI"]
[Thu Sep 17 15:49:23.222848 2026] [security2:error] [pid 102783:tid 102923] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/notifications/.env"] [unique_id "aqxgY8zioAAmEecB_LHKaQAAAI8"]
[Thu Sep 17 15:49:23.259633 2026] [security2:error] [pid 102783:tid 102966] [client 122.8.45.84:13077] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKbAAAALo"]
[Thu Sep 17 15:49:23.259737 2026] [security2:error] [pid 102783:tid 102966] [client 122.8.45.84:13077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKbAAAALo"]
[Thu Sep 17 15:49:23.325279 2026] [security2:error] [pid 102783:tid 102946] [client 143.105.152.240:47808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKbwAAAKY"]
[Thu Sep 17 15:49:23.329790 2026] [security2:error] [pid 102783:tid 102946] [client 143.105.152.240:47808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKbwAAAKY"]
[Thu Sep 17 15:49:23.386430 2026] [security2:error] [pid 102783:tid 102927] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/notify/.env"] [unique_id "aqxgY8zioAAmEecB_LHKcQAAAJM"]
[Thu Sep 17 15:49:23.424207 2026] [security2:error] [pid 102783:tid 103039] [client 102.179.26.76:61532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.26.179.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "torringtonhandyman.com"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKcgAAAQM"]
[Thu Sep 17 15:49:23.424404 2026] [security2:error] [pid 102783:tid 103039] [client 102.179.26.76:61532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "torringtonhandyman.com"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKcgAAAQM"]
[Thu Sep 17 15:49:23.558765 2026] [security2:error] [pid 102783:tid 102992] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/sender/.env"] [unique_id "aqxgY8zioAAmEecB_LHKdQAAANQ"]
[Thu Sep 17 15:49:23.729748 2026] [security2:error] [pid 102783:tid 103023] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/campaign/.env"] [unique_id "aqxgY8zioAAmEecB_LHKgAAAAPM"]
[Thu Sep 17 15:49:23.804535 2026] [security2:error] [pid 102783:tid 102941] [client 192.178.6.3:57110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.6.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mercuos.com"] [uri "/shop/customer/bookmark.php"] [unique_id "aqxgY8zioAAmEecB_LHKhQAAAKE"]
[Thu Sep 17 15:49:23.895191 2026] [security2:error] [pid 102783:tid 103015] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/newsletter/.env"] [unique_id "aqxgY8zioAAmEecB_LHKhgAAAOs"]
[Thu Sep 17 15:49:23.921153 2026] [security2:error] [pid 102783:tid 102961] [client 14.96.156.146:58920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKiQAAALU"]
[Thu Sep 17 15:49:23.921260 2026] [security2:error] [pid 102783:tid 102961] [client 14.96.156.146:58920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKiQAAALU"]
[Thu Sep 17 15:49:23.961060 2026] [security2:error] [pid 102783:tid 102997] [client 148.227.75.216:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKjwAAANk"]
[Thu Sep 17 15:49:23.964592 2026] [security2:error] [pid 102783:tid 102997] [client 148.227.75.216:64714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgY8zioAAmEecB_LHKjwAAANk"]
[Thu Sep 17 15:49:24.020339 2026] [security2:error] [pid 102783:tid 102987] [client 4.240.114.86:61614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/utf8.php"] [unique_id "aqxgZMzioAAmEecB_LHKkAAAAM8"], referer: binance.com
[Thu Sep 17 15:49:24.056684 2026] [security2:error] [pid 102783:tid 102924] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/ses/.env"] [unique_id "aqxgZMzioAAmEecB_LHKkQAAAJA"]
[Thu Sep 17 15:49:24.214262 2026] [security2:error] [pid 102783:tid 102991] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/sendgrid/.env"] [unique_id "aqxgZMzioAAmEecB_LHKmQAAANM"]
[Thu Sep 17 15:49:24.219907 2026] [security2:error] [pid 102783:tid 102970] [client 122.8.45.84:62141] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZMzioAAmEecB_LHKmgAAAL4"]
[Thu Sep 17 15:49:24.219992 2026] [security2:error] [pid 102783:tid 102970] [client 122.8.45.84:62141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZMzioAAmEecB_LHKmgAAAL4"]
[Thu Sep 17 15:49:24.379137 2026] [security2:error] [pid 102783:tid 102960] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/sparkpost/.env"] [unique_id "aqxgZMzioAAmEecB_LHKogAAALQ"]
[Thu Sep 17 15:49:24.410902 2026] [security2:error] [pid 102783:tid 102936] [client 177.44.133.72:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgZMzioAAmEecB_LHKpAAAAJw"]
[Thu Sep 17 15:49:24.411007 2026] [security2:error] [pid 102783:tid 102936] [client 177.44.133.72:53321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgZMzioAAmEecB_LHKpAAAAJw"]
[Thu Sep 17 15:49:24.538650 2026] [security2:error] [pid 102783:tid 102962] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/postmark/.env"] [unique_id "aqxgZMzioAAmEecB_LHKqgAAALY"]
[Thu Sep 17 15:49:24.721588 2026] [security2:error] [pid 102783:tid 102975] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mailgun/.env"] [unique_id "aqxgZMzioAAmEecB_LHKsgAAAMM"]
[Thu Sep 17 15:49:24.921538 2026] [security2:error] [pid 102783:tid 102959] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mandrill/.env"] [unique_id "aqxgZMzioAAmEecB_LHKuAAAALM"]
[Thu Sep 17 15:49:25.091098 2026] [security2:error] [pid 102783:tid 103039] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mailjet/.env"] [unique_id "aqxgZczioAAmEecB_LHKvAAAAQM"]
[Thu Sep 17 15:49:25.171523 2026] [security2:error] [pid 102783:tid 103022] [client 122.8.45.84:25387] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZczioAAmEecB_LHKwgAAAPI"]
[Thu Sep 17 15:49:25.171656 2026] [security2:error] [pid 102783:tid 103022] [client 122.8.45.84:25387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZczioAAmEecB_LHKwgAAAPI"]
[Thu Sep 17 15:49:25.257167 2026] [security2:error] [pid 102783:tid 102985] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/brevo/.env"] [unique_id "aqxgZczioAAmEecB_LHKxQAAAM0"]
[Thu Sep 17 15:49:25.417002 2026] [security2:error] [pid 102783:tid 102950] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/transactional/.env"] [unique_id "aqxgZczioAAmEecB_LHKzwAAAKo"]
[Thu Sep 17 15:49:25.462196 2026] [security2:error] [pid 102783:tid 102935] [client 104.243.33.53:63725] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zlj.byd.mybluehost.me"] [uri "/.env"] [unique_id "aqxgZczioAAmEecB_LHK0AAAAJs"]
[Thu Sep 17 15:49:25.576583 2026] [security2:error] [pid 102783:tid 103040] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/bulk/.env"] [unique_id "aqxgZczioAAmEecB_LHK1QAAAQQ"]
[Thu Sep 17 15:49:25.733072 2026] [security2:error] [pid 102783:tid 102978] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/aws/.env"] [unique_id "aqxgZczioAAmEecB_LHK3AAAAMY"]
[Thu Sep 17 15:49:25.896452 2026] [security2:error] [pid 102783:tid 103002] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/azure/.env"] [unique_id "aqxgZczioAAmEecB_LHK4QAAAN4"]
[Thu Sep 17 15:49:26.086482 2026] [security2:error] [pid 102783:tid 102929] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/gcp/.env"] [unique_id "aqxgZszioAAmEecB_LHK5wAAAJU"]
[Thu Sep 17 15:49:26.107119 2026] [security2:error] [pid 102783:tid 102913] [client 122.8.45.84:59019] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZszioAAmEecB_LHK6QAAAIU"]
[Thu Sep 17 15:49:26.107218 2026] [security2:error] [pid 102783:tid 102913] [client 122.8.45.84:59019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZszioAAmEecB_LHK6QAAAIU"]
[Thu Sep 17 15:49:26.254418 2026] [security2:error] [pid 102783:tid 102966] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/cloud/.env"] [unique_id "aqxgZszioAAmEecB_LHK8AAAALo"]
[Thu Sep 17 15:49:26.420879 2026] [security2:error] [pid 102783:tid 102959] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/infrastructure/.env"] [unique_id "aqxgZszioAAmEecB_LHK9gAAALM"]
[Thu Sep 17 15:49:26.423140 2026] [security2:error] [pid 102783:tid 103018] [client 79.116.89.151:54751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZszioAAmEecB_LHK9wAAAO4"]
[Thu Sep 17 15:49:26.423463 2026] [security2:error] [pid 102783:tid 103018] [client 79.116.89.151:54751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZszioAAmEecB_LHK9wAAAO4"]
[Thu Sep 17 15:49:26.462454 2026] [security2:error] [pid 102783:tid 103036] [client 43.173.181.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxgZszioAAmEecB_LHK9QAAAQA"]
[Thu Sep 17 15:49:26.578103 2026] [security2:error] [pid 102783:tid 102973] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/docker/.env"] [unique_id "aqxgZszioAAmEecB_LHK_gAAAME"]
[Thu Sep 17 15:49:26.660785 2026] [security2:error] [pid 102783:tid 102954] [client 43.173.174.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talent-in-borders.com"] [uri "/index.php"] [unique_id "aqxgZszioAAmEecB_LHK_QAAAK4"]
[Thu Sep 17 15:49:26.698410 2026] [core:error] [pid 102783:tid 103031] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:49:26.698431 2026] [core:error] [pid 102783:tid 103031] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:49:26.735921 2026] [security2:error] [pid 102783:tid 102968] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/k8s/.env"] [unique_id "aqxgZszioAAmEecB_LHLBQAAALw"]
[Thu Sep 17 15:49:26.896823 2026] [security2:error] [pid 102783:tid 102918] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/kubernetes/.env"] [unique_id "aqxgZszioAAmEecB_LHLCgAAAIo"]
[Thu Sep 17 15:49:27.033678 2026] [security2:error] [pid 102783:tid 103013] [client 136.158.61.34:13511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZ8zioAAmEecB_LHLCwAAAOk"]
[Thu Sep 17 15:49:27.033853 2026] [security2:error] [pid 102783:tid 103013] [client 136.158.61.34:13511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZ8zioAAmEecB_LHLCwAAAOk"]
[Thu Sep 17 15:49:27.054624 2026] [security2:error] [pid 102783:tid 102976] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/terraform/.env"] [unique_id "aqxgZ8zioAAmEecB_LHLDAAAAMQ"]
[Thu Sep 17 15:49:27.065348 2026] [security2:error] [pid 102783:tid 103026] [client 122.8.45.84:56545] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZ8zioAAmEecB_LHLDQAAAPY"]
[Thu Sep 17 15:49:27.065450 2026] [security2:error] [pid 102783:tid 103026] [client 122.8.45.84:56545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgZ8zioAAmEecB_LHLDQAAAPY"]
[Thu Sep 17 15:49:27.220119 2026] [security2:error] [pid 102783:tid 103016] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/ansible/.env"] [unique_id "aqxgZ8zioAAmEecB_LHLEgAAAOw"]
[Thu Sep 17 15:49:27.381650 2026] [security2:error] [pid 102783:tid 102924] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/.git/.env"] [unique_id "aqxgZ8zioAAmEecB_LHLGQAAAJA"]
[Thu Sep 17 15:49:27.545514 2026] [security2:error] [pid 102783:tid 102925] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/ci/.env"] [unique_id "aqxgZ8zioAAmEecB_LHLIQAAAJE"]
[Thu Sep 17 15:49:27.702183 2026] [security2:error] [pid 102783:tid 102922] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/cd/.env"] [unique_id "aqxgZ8zioAAmEecB_LHLJwAAAI4"]
[Thu Sep 17 15:49:27.875079 2026] [security2:error] [pid 102783:tid 103032] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/jenkins/.env"] [unique_id "aqxgZ8zioAAmEecB_LHLLAAAAPw"]
[Thu Sep 17 15:49:28.016168 2026] [security2:error] [pid 102783:tid 103021] [client 122.8.45.84:16701] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaMzioAAmEecB_LHLLgAAAPE"]
[Thu Sep 17 15:49:28.016305 2026] [security2:error] [pid 102783:tid 103021] [client 122.8.45.84:16701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaMzioAAmEecB_LHLLgAAAPE"]
[Thu Sep 17 15:49:28.038959 2026] [security2:error] [pid 102783:tid 102931] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/gitlab/.env"] [unique_id "aqxgaMzioAAmEecB_LHLLwAAAJc"]
[Thu Sep 17 15:49:28.197916 2026] [security2:error] [pid 102783:tid 103001] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/github/.env"] [unique_id "aqxgaMzioAAmEecB_LHLNgAAAN0"]
[Thu Sep 17 15:49:28.362188 2026] [security2:error] [pid 102783:tid 102992] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/actions/.env"] [unique_id "aqxgaMzioAAmEecB_LHLPgAAANQ"]
[Thu Sep 17 15:49:28.523927 2026] [security2:error] [pid 102783:tid 103022] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/circleci/.env"] [unique_id "aqxgaMzioAAmEecB_LHLPwAAAPI"]
[Thu Sep 17 15:49:28.682502 2026] [security2:error] [pid 102783:tid 103010] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/travis/.env"] [unique_id "aqxgaMzioAAmEecB_LHLRAAAAOY"]
[Thu Sep 17 15:49:28.845306 2026] [security2:error] [pid 102783:tid 102918] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/buildkite/.env"] [unique_id "aqxgaMzioAAmEecB_LHLSQAAAIo"]
[Thu Sep 17 15:49:28.954228 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:11787] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaMzioAAmEecB_LHLSwAAAK8"]
[Thu Sep 17 15:49:28.954357 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:11787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaMzioAAmEecB_LHLSwAAAK8"]
[Thu Sep 17 15:49:29.003342 2026] [security2:error] [pid 102783:tid 103003] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mysql/.env"] [unique_id "aqxgaczioAAmEecB_LHLTAAAAN8"]
[Thu Sep 17 15:49:29.107793 2026] [security2:error] [pid 102783:tid 102785] [remote 111.225.148.154:22126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cult.cyberpunkonline.net"] [uri "/geffine/GEFFINE-014.txt"] [unique_id "aqxgaczioAAmEecB_LHLUAAAxAE"]
[Thu Sep 17 15:49:29.162120 2026] [security2:error] [pid 102783:tid 103016] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/postgres/.env"] [unique_id "aqxgaczioAAmEecB_LHLUwAAAOw"]
[Thu Sep 17 15:49:29.323972 2026] [security2:error] [pid 102783:tid 102925] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/mongodb/.env"] [unique_id "aqxgaczioAAmEecB_LHLWwAAAJE"]
[Thu Sep 17 15:49:29.473110 2026] [security2:error] [pid 102783:tid 102940] [client 4.240.114.86:64404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/view-config.php"] [unique_id "aqxgaczioAAmEecB_LHLXgAAAKA"], referer: binance.com
[Thu Sep 17 15:49:29.486406 2026] [security2:error] [pid 102783:tid 103012] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/redis/.env"] [unique_id "aqxgaczioAAmEecB_LHLYAAAAOg"]
[Thu Sep 17 15:49:29.543351 2026] [security2:error] [pid 102783:tid 102995] [client 45.3.34.141:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dev.ndap.org.ph"] [uri "/wp-login.php"] [unique_id "aqxgaczioAAmEecB_LHLXwAAANc"]
[Thu Sep 17 15:49:29.645866 2026] [security2:error] [pid 102783:tid 102962] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/elasticsearch/.env"] [unique_id "aqxgaczioAAmEecB_LHLYwAAALY"]
[Thu Sep 17 15:49:29.800007 2026] [security2:error] [pid 102783:tid 102964] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/rabbitmq/.env"] [unique_id "aqxgaczioAAmEecB_LHLaQAAALg"]
[Thu Sep 17 15:49:29.912480 2026] [security2:error] [pid 102783:tid 102970] [client 122.8.45.84:46741] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaczioAAmEecB_LHLcAAAAL4"]
[Thu Sep 17 15:49:29.912676 2026] [security2:error] [pid 102783:tid 102970] [client 122.8.45.84:46741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaczioAAmEecB_LHLcAAAAL4"]
[Thu Sep 17 15:49:29.977297 2026] [security2:error] [pid 102783:tid 102930] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/kafka/.env"] [unique_id "aqxgaczioAAmEecB_LHLcQAAAJY"]
[Thu Sep 17 15:49:30.132714 2026] [security2:error] [pid 102783:tid 103001] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/queue/.env"] [unique_id "aqxgaszioAAmEecB_LHLdAAAAN0"]
[Thu Sep 17 15:49:30.292165 2026] [security2:error] [pid 102783:tid 102993] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/worker/.env"] [unique_id "aqxgaszioAAmEecB_LHLggAAANU"]
[Thu Sep 17 15:49:30.403508 2026] [security2:error] [pid 102783:tid 102999] [client 45.3.50.224:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dev.ndap.org.ph"] [uri "/xmlrpc.php"] [unique_id "aqxgaszioAAmEecB_LHLhgAAANs"]
[Thu Sep 17 15:49:30.447918 2026] [security2:error] [pid 102783:tid 102920] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/job/.env"] [unique_id "aqxgaszioAAmEecB_LHLiAAAAIw"]
[Thu Sep 17 15:49:30.620737 2026] [security2:error] [pid 102783:tid 103013] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/test/.env"] [unique_id "aqxgaszioAAmEecB_LHLjQAAAOk"]
[Thu Sep 17 15:49:30.777159 2026] [security2:error] [pid 102783:tid 103033] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/qa/.env"] [unique_id "aqxgaszioAAmEecB_LHLlgAAAP0"]
[Thu Sep 17 15:49:30.868628 2026] [security2:error] [pid 102783:tid 102972] [client 122.8.45.84:47839] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaszioAAmEecB_LHLmAAAAMA"]
[Thu Sep 17 15:49:30.868753 2026] [security2:error] [pid 102783:tid 102972] [client 122.8.45.84:47839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgaszioAAmEecB_LHLmAAAAMA"]
[Thu Sep 17 15:49:30.934693 2026] [security2:error] [pid 102783:tid 103009] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/preview/.env"] [unique_id "aqxgaszioAAmEecB_LHLmwAAAOU"]
[Thu Sep 17 15:49:31.088227 2026] [authz_core:error] [pid 102783:tid 102966] [client 169.58.197.253:62354] AH01630: client denied by server configuration: /home2/brianpag/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:49:31.096985 2026] [security2:error] [pid 102783:tid 102939] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/beta/.env"] [unique_id "aqxga8zioAAmEecB_LHLowAAAJ8"]
[Thu Sep 17 15:49:31.254039 2026] [security2:error] [pid 102783:tid 102995] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/uat/.env"] [unique_id "aqxga8zioAAmEecB_LHLsAAAANc"]
[Thu Sep 17 15:49:31.264613 2026] [security2:error] [pid 102783:tid 102963] [client 104.250.53.240:14296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ritamayblog.com"] [uri "/index.php"] [unique_id "aqxgaczioAAmEecB_LHLTQAAtzo"], referer: https://mckinleyexcied82.blogspot.com
[Thu Sep 17 15:49:31.414647 2026] [security2:error] [pid 102783:tid 102953] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/stage/.env"] [unique_id "aqxga8zioAAmEecB_LHLuwAAAK0"]
[Thu Sep 17 15:49:31.574412 2026] [security2:error] [pid 102783:tid 102975] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/development/.env"] [unique_id "aqxga8zioAAmEecB_LHLvgAAAMM"]
[Thu Sep 17 15:49:31.740317 2026] [security2:error] [pid 102783:tid 102943] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/production/.env"] [unique_id "aqxga8zioAAmEecB_LHLwAAAAKM"]
[Thu Sep 17 15:49:31.789426 2026] [security2:error] [pid 102783:tid 102971] [client 122.8.45.84:27921] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxga8zioAAmEecB_LHLxQAAAL8"]
[Thu Sep 17 15:49:31.789539 2026] [security2:error] [pid 102783:tid 102971] [client 122.8.45.84:27921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxga8zioAAmEecB_LHLxQAAAL8"]
[Thu Sep 17 15:49:31.915967 2026] [security2:error] [pid 102783:tid 103021] [client 34.154.21.169:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.aellaapartments.com"] [uri "/config/app/.env"] [unique_id "aqxga8zioAAmEecB_LHLxgAAAPE"]
[Thu Sep 17 15:49:32.074229 2026] [security2:error] [pid 102783:tid 102954] [client 34.154.21.169:50860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/phpinfo.php"] [unique_id "aqxgbMzioAAmEecB_LHLzAAAAK4"]
[Thu Sep 17 15:49:32.584828 2026] [security2:error] [pid 102783:tid 102918] [client 34.154.21.169:45216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/info.php"] [unique_id "aqxgbMzioAAmEecB_LHL2AAAAIo"]
[Thu Sep 17 15:49:32.677384 2026] [security2:error] [pid 102783:tid 103022] [client 35.145.37.185:27931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgbMzioAAmEecB_LHL1wAA8gU"], referer: https://www.endless-chronicles.com/
[Thu Sep 17 15:49:32.759835 2026] [security2:error] [pid 102783:tid 102992] [client 122.8.45.84:31495] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbMzioAAmEecB_LHL3QAAANQ"]
[Thu Sep 17 15:49:32.759978 2026] [security2:error] [pid 102783:tid 102992] [client 122.8.45.84:31495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbMzioAAmEecB_LHL3QAAANQ"]
[Thu Sep 17 15:49:33.118354 2026] [security2:error] [pid 102783:tid 102981] [client 34.154.21.169:45224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/php.php"] [unique_id "aqxgbczioAAmEecB_LHL4gAAAMk"]
[Thu Sep 17 15:49:33.649636 2026] [security2:error] [pid 102783:tid 102978] [client 34.154.21.169:45234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/i.php"] [unique_id "aqxgbczioAAmEecB_LHL7QAAAMY"]
[Thu Sep 17 15:49:33.659346 2026] [security2:error] [pid 102783:tid 102973] [client 143.105.152.240:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgbczioAAmEecB_LHL7wAAAME"]
[Thu Sep 17 15:49:33.667155 2026] [security2:error] [pid 102783:tid 102973] [client 143.105.152.240:46680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgbczioAAmEecB_LHL7wAAAME"]
[Thu Sep 17 15:49:33.699699 2026] [security2:error] [pid 102783:tid 103032] [client 4.240.114.86:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.114.240.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwdnyc.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "aqxgbczioAAmEecB_LHL8QAAAPw"], referer: binance.com
[Thu Sep 17 15:49:33.764234 2026] [security2:error] [pid 102783:tid 102995] [client 122.8.45.84:15047] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbczioAAmEecB_LHL9QAAANc"]
[Thu Sep 17 15:49:33.764336 2026] [security2:error] [pid 102783:tid 102995] [client 122.8.45.84:15047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbczioAAmEecB_LHL9QAAANc"]
[Thu Sep 17 15:49:34.059974 2026] [security2:error] [pid 102783:tid 103007] [client 102.179.26.76:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.26.179.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "torringtonhandyman.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHL_QAAAOM"]
[Thu Sep 17 15:49:34.060069 2026] [security2:error] [pid 102783:tid 103007] [client 102.179.26.76:62159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "torringtonhandyman.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHL_QAAAOM"]
[Thu Sep 17 15:49:34.167035 2026] [security2:error] [pid 102783:tid 102923] [client 34.154.21.169:45248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/pi.php"] [unique_id "aqxgbszioAAmEecB_LHMAgAAAI8"]
[Thu Sep 17 15:49:34.333998 2026] [security2:error] [pid 102783:tid 102970] [client 35.145.37.185:28163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgbszioAAmEecB_LHMAwAAvhk"], referer: https://www.endless-chronicles.com/explore/wiki/index.php?days=14&from=20260821104313&hideanons=1&hidemyself=1&limit=250&target=The_Incursions&title=Special%3ARecentChangesLinked
[Thu Sep 17 15:49:34.563525 2026] [security2:error] [pid 102783:tid 103010] [client 14.96.156.146:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHMDQAAAOY"]
[Thu Sep 17 15:49:34.563688 2026] [security2:error] [pid 102783:tid 103010] [client 14.96.156.146:59576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHMDQAAAOY"]
[Thu Sep 17 15:49:34.655133 2026] [security2:error] [pid 102783:tid 102944] [client 34.154.21.169:45256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/pinfo.php"] [unique_id "aqxgbszioAAmEecB_LHMDwAAAKQ"]
[Thu Sep 17 15:49:34.710519 2026] [security2:error] [pid 102783:tid 102945] [client 148.227.75.216:27352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHMEwAAAKU"]
[Thu Sep 17 15:49:34.720934 2026] [security2:error] [pid 102783:tid 102945] [client 148.227.75.216:27352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHMEwAAAKU"]
[Thu Sep 17 15:49:34.766078 2026] [security2:error] [pid 102783:tid 102974] [client 122.8.45.84:42453] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHMFQAAAMI"]
[Thu Sep 17 15:49:34.766183 2026] [security2:error] [pid 102783:tid 102974] [client 122.8.45.84:42453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgbszioAAmEecB_LHMFQAAAMI"]
[Thu Sep 17 15:49:35.129696 2026] [security2:error] [pid 102783:tid 103026] [client 177.44.133.72:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgb8zioAAmEecB_LHMIQAAAPY"]
[Thu Sep 17 15:49:35.129848 2026] [security2:error] [pid 102783:tid 103026] [client 177.44.133.72:53986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgb8zioAAmEecB_LHMIQAAAPY"]
[Thu Sep 17 15:49:35.159189 2026] [security2:error] [pid 102783:tid 102987] [client 34.154.21.169:45260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/test.php"] [unique_id "aqxgb8zioAAmEecB_LHMIwAAAM8"]
[Thu Sep 17 15:49:35.772923 2026] [security2:error] [pid 102783:tid 102976] [client 122.8.45.84:25751] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgb8zioAAmEecB_LHMOAAAAMQ"]
[Thu Sep 17 15:49:35.773512 2026] [security2:error] [pid 102783:tid 102976] [client 122.8.45.84:25751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgb8zioAAmEecB_LHMOAAAAMQ"]
[Thu Sep 17 15:49:35.807703 2026] [core:error] [pid 102783:tid 102943] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:49:35.807723 2026] [core:error] [pid 102783:tid 102943] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:49:35.868076 2026] [security2:error] [pid 102783:tid 103009] [client 34.154.21.169:45270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/p.php"] [unique_id "aqxgb8zioAAmEecB_LHMPwAAAOU"]
[Thu Sep 17 15:49:36.435629 2026] [security2:error] [pid 102783:tid 102956] [client 34.154.21.169:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/debug.php"] [unique_id "aqxgcMzioAAmEecB_LHMTwAAALA"]
[Thu Sep 17 15:49:36.756879 2026] [security2:error] [pid 102783:tid 102971] [client 122.8.45.84:54459] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcMzioAAmEecB_LHMWAAAAL8"]
[Thu Sep 17 15:49:36.756997 2026] [security2:error] [pid 102783:tid 102971] [client 122.8.45.84:54459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcMzioAAmEecB_LHMWAAAAL8"]
[Thu Sep 17 15:49:36.974803 2026] [security2:error] [pid 102783:tid 102921] [client 34.154.21.169:53822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxgcMzioAAmEecB_LHMXAAAAI0"]
[Thu Sep 17 15:49:37.088901 2026] [security2:error] [pid 102783:tid 102915] [client 79.116.89.151:55392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcczioAAmEecB_LHMXgAAAIc"]
[Thu Sep 17 15:49:37.089030 2026] [security2:error] [pid 102783:tid 102915] [client 79.116.89.151:55392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcczioAAmEecB_LHMXgAAAIc"]
[Thu Sep 17 15:49:37.460258 2026] [security2:error] [pid 102783:tid 103011] [client 34.154.21.169:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/test/phpinfo.php"] [unique_id "aqxgcczioAAmEecB_LHMZwAAAOc"]
[Thu Sep 17 15:49:37.670951 2026] [security2:error] [pid 102783:tid 102973] [client 93.152.209.11:4788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.lemuspools.com"] [uri "/.env"] [unique_id "aqxgcczioAAmEecB_LHMbgAAAME"]
[Thu Sep 17 15:49:37.712971 2026] [security2:error] [pid 102783:tid 102963] [client 122.8.45.84:38585] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcczioAAmEecB_LHMcAAAALc"]
[Thu Sep 17 15:49:37.713128 2026] [security2:error] [pid 102783:tid 102963] [client 122.8.45.84:38585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcczioAAmEecB_LHMcAAAALc"]
[Thu Sep 17 15:49:37.856126 2026] [security2:error] [pid 102783:tid 102827] [remote 93.152.209.11:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.lemuspools.com"] [uri "/.env"] [unique_id "aqxgcczioAAmEecB_LHMeAAAiys"]
[Thu Sep 17 15:49:37.967544 2026] [security2:error] [pid 102783:tid 102914] [client 34.154.21.169:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/dev/phpinfo.php"] [unique_id "aqxgcczioAAmEecB_LHMeQAAAIY"]
[Thu Sep 17 15:49:38.491779 2026] [security2:error] [pid 102783:tid 103008] [client 34.154.21.169:53854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/old/phpinfo.php"] [unique_id "aqxgcszioAAmEecB_LHMjAAAAOQ"]
[Thu Sep 17 15:49:38.649169 2026] [security2:error] [pid 102783:tid 102989] [client 122.8.45.84:60087] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcszioAAmEecB_LHMlQAAANE"]
[Thu Sep 17 15:49:38.649299 2026] [security2:error] [pid 102783:tid 102989] [client 122.8.45.84:60087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgcszioAAmEecB_LHMlQAAANE"]
[Thu Sep 17 15:49:39.024988 2026] [security2:error] [pid 102783:tid 103014] [client 34.154.21.169:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/tmp/phpinfo.php"] [unique_id "aqxgc8zioAAmEecB_LHMoAAAAOo"]
[Thu Sep 17 15:49:39.508715 2026] [security2:error] [pid 102783:tid 102931] [client 34.154.21.169:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/public/phpinfo.php"] [unique_id "aqxgc8zioAAmEecB_LHMrAAAAJc"]
[Thu Sep 17 15:49:39.550576 2026] [security2:error] [pid 102783:tid 102984] [client 136.158.61.34:14576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.61.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgc8zioAAmEecB_LHMrQAAAMw"]
[Thu Sep 17 15:49:39.550746 2026] [security2:error] [pid 102783:tid 102984] [client 136.158.61.34:14576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "modernaffluents.com"] [uri "/xmlrpc.php"] [unique_id "aqxgc8zioAAmEecB_LHMrQAAAMw"]
[Thu Sep 17 15:49:39.631965 2026] [security2:error] [pid 102783:tid 102926] [client 122.8.45.84:15331] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgc8zioAAmEecB_LHMsAAAAJI"]
[Thu Sep 17 15:49:39.632109 2026] [security2:error] [pid 102783:tid 102926] [client 122.8.45.84:15331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgc8zioAAmEecB_LHMsAAAAJI"]
[Thu Sep 17 15:49:40.226503 2026] [security2:error] [pid 102783:tid 103013] [client 34.154.21.169:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/php-info.php"] [unique_id "aqxgdMzioAAmEecB_LHMyAAAAOk"]
[Thu Sep 17 15:49:40.585826 2026] [security2:error] [pid 102783:tid 103018] [client 122.8.45.84:39653] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgdMzioAAmEecB_LHM0QAAAO4"]
[Thu Sep 17 15:49:40.585980 2026] [security2:error] [pid 102783:tid 103018] [client 122.8.45.84:39653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgdMzioAAmEecB_LHM0QAAAO4"]
[Thu Sep 17 15:49:40.705208 2026] [security2:error] [pid 102783:tid 102946] [client 34.154.21.169:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/phpversion.php"] [unique_id "aqxgdMzioAAmEecB_LHM1gAAAKY"]
[Thu Sep 17 15:49:41.019336 2026] [security2:error] [pid 102783:tid 102935] [client 80.241.223.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxgdMzioAAmEecB_LHM3QAAAJs"], referer: https://kslandscaping.net/
[Thu Sep 17 15:49:41.057146 2026] [autoindex:error] [pid 102783:tid 102922] [client 107.155.56.47:55448] AH01276: Cannot serve directory /home1/gnqazemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Sep 17 15:49:41.191810 2026] [security2:error] [pid 102783:tid 102997] [client 34.154.21.169:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/_phpinfo.php"] [unique_id "aqxgdczioAAmEecB_LHM4wAAANk"]
[Thu Sep 17 15:49:41.361672 2026] [security2:error] [pid 102783:tid 102924] [client 84.54.44.19:61002] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "84.54.44.19" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.freeofgravity.com"] [uri "/wp-comments-post.php"] [unique_id "aqxgdczioAAmEecB_LHM7wAAAJA"], referer: https://www.freeofgravity.com/launch-day-wonder-over-fear/
[Thu Sep 17 15:49:41.361791 2026] [security2:error] [pid 102783:tid 102924] [client 84.54.44.19:61002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.freeofgravity.com"] [uri "/wp-comments-post.php"] [unique_id "aqxgdczioAAmEecB_LHM7wAAAJA"], referer: https://www.freeofgravity.com/launch-day-wonder-over-fear/
[Thu Sep 17 15:49:41.364244 2026] [core:error] [pid 102783:tid 102930] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:49:41.364262 2026] [core:error] [pid 102783:tid 102930] [client 152.32.205.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Sep 17 15:49:41.534441 2026] [security2:error] [pid 102783:tid 103026] [client 122.8.45.84:61945] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgdczioAAmEecB_LHM9gAAAPY"]
[Thu Sep 17 15:49:41.534624 2026] [security2:error] [pid 102783:tid 103026] [client 122.8.45.84:61945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgdczioAAmEecB_LHM9gAAAPY"]
[Thu Sep 17 15:49:41.697243 2026] [security2:error] [pid 102783:tid 103037] [client 34.154.21.169:53902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/old_phpinfo.php"] [unique_id "aqxgdczioAAmEecB_LHM-wAAAQE"]
[Thu Sep 17 15:49:42.190929 2026] [security2:error] [pid 102783:tid 102993] [client 34.154.21.169:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/server-info.php"] [unique_id "aqxgdszioAAmEecB_LHNDQAAANU"]
[Thu Sep 17 15:49:42.493359 2026] [security2:error] [pid 102783:tid 102945] [client 122.8.45.84:49053] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgdszioAAmEecB_LHNGQAAAKU"]
[Thu Sep 17 15:49:42.493465 2026] [security2:error] [pid 102783:tid 102945] [client 122.8.45.84:49053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgdszioAAmEecB_LHNGQAAAKU"]
[Thu Sep 17 15:49:42.674758 2026] [security2:error] [pid 102783:tid 102948] [client 34.154.21.169:53918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/server-status.php"] [unique_id "aqxgdszioAAmEecB_LHNHgAAAKg"]
[Thu Sep 17 15:49:43.524519 2026] [security2:error] [pid 102783:tid 102913] [client 122.8.45.84:35387] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgd8zioAAmEecB_LHNQgAAAIU"]
[Thu Sep 17 15:49:43.524622 2026] [security2:error] [pid 102783:tid 102913] [client 122.8.45.84:35387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgd8zioAAmEecB_LHNQgAAAIU"]
[Thu Sep 17 15:49:43.597814 2026] [security2:error] [pid 102783:tid 102974] [client 34.154.21.169:53930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/webroot/index.php/_environment"] [unique_id "aqxgd8zioAAmEecB_LHNRwAAAMI"]
[Thu Sep 17 15:49:43.741682 2026] [authz_core:error] [pid 102783:tid 102984] [client 169.58.197.251:49256] AH01630: client denied by server configuration: /home2/sfvhbtor/public_html/wp-includes/IXR/error_log, referer: binance.com
[Thu Sep 17 15:49:44.129398 2026] [security2:error] [pid 102783:tid 102957] [client 34.154.21.169:53944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/mail/phpinfo.php"] [unique_id "aqxgeMzioAAmEecB_LHNVwAAALE"]
[Thu Sep 17 15:49:44.255491 2026] [security2:error] [pid 102783:tid 102916] [client 143.105.152.240:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.152.105.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgeMzioAAmEecB_LHNXwAAAIg"]
[Thu Sep 17 15:49:44.255611 2026] [security2:error] [pid 102783:tid 102916] [client 143.105.152.240:53448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "radtechresourcegroup.net"] [uri "/xmlrpc.php"] [unique_id "aqxgeMzioAAmEecB_LHNXwAAAIg"]
[Thu Sep 17 15:49:44.483490 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:28925] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeMzioAAmEecB_LHNaAAAAK8"]
[Thu Sep 17 15:49:44.483601 2026] [security2:error] [pid 102783:tid 102955] [client 122.8.45.84:28925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeMzioAAmEecB_LHNaAAAAK8"]
[Thu Sep 17 15:49:44.637490 2026] [security2:error] [pid 102783:tid 102933] [client 34.154.21.169:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/cpanel/phpinfo.php"] [unique_id "aqxgeMzioAAmEecB_LHNawAAAJk"]
[Thu Sep 17 15:49:44.729834 2026] [security2:error] [pid 102783:tid 102952] [client 80.241.223.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kslandscaping.net"] [uri "/index.php"] [unique_id "aqxgeMzioAAmEecB_LHNagAAAKw"], referer: https://kslandscaping.net/
[Thu Sep 17 15:49:45.179488 2026] [security2:error] [pid 102783:tid 102999] [client 34.154.21.169:53970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/hosting/phpinfo.php"] [unique_id "aqxgeczioAAmEecB_LHNgwAAANs"]
[Thu Sep 17 15:49:45.376379 2026] [security2:error] [pid 102783:tid 102974] [client 148.227.75.216:31397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.75.227.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeczioAAmEecB_LHNjQAAAMI"]
[Thu Sep 17 15:49:45.376500 2026] [security2:error] [pid 102783:tid 102974] [client 148.227.75.216:31397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thevagabondhiker.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeczioAAmEecB_LHNjQAAAMI"]
[Thu Sep 17 15:49:45.445136 2026] [security2:error] [pid 102783:tid 102923] [client 122.8.45.84:64467] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeczioAAmEecB_LHNjgAAAI8"]
[Thu Sep 17 15:49:45.445295 2026] [security2:error] [pid 102783:tid 102923] [client 122.8.45.84:64467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeczioAAmEecB_LHNjgAAAI8"]
[Thu Sep 17 15:49:45.529854 2026] [fcgid:warn] [pid 102783:tid 102971] (70014)End of file found: [client 152.32.202.250:51130] mod_fcgid: can't get data from http client
[Thu Sep 17 15:49:45.694671 2026] [security2:error] [pid 102783:tid 102950] [client 34.154.21.169:53974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/webmail/phpinfo.php"] [unique_id "aqxgeczioAAmEecB_LHNlAAAAKo"]
[Thu Sep 17 15:49:45.758344 2026] [security2:error] [pid 102783:tid 102970] [client 177.44.133.72:54654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.133.44.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgeczioAAmEecB_LHNlwAAAL4"]
[Thu Sep 17 15:49:45.758470 2026] [security2:error] [pid 102783:tid 102970] [client 177.44.133.72:54654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seekingtheway.net"] [uri "/xmlrpc.php"] [unique_id "aqxgeczioAAmEecB_LHNlwAAAL4"]
[Thu Sep 17 15:49:46.216127 2026] [security2:error] [pid 102783:tid 103014] [client 14.96.156.146:60250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.156.96.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgeszioAAmEecB_LHNpwAAAOo"]
[Thu Sep 17 15:49:46.216256 2026] [security2:error] [pid 102783:tid 103014] [client 14.96.156.146:60250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espiral.com.mx"] [uri "/xmlrpc.php"] [unique_id "aqxgeszioAAmEecB_LHNpwAAAOo"]
[Thu Sep 17 15:49:46.231475 2026] [security2:error] [pid 102783:tid 102928] [client 34.154.21.169:36156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/smtp/phpinfo.php"] [unique_id "aqxgeszioAAmEecB_LHNqAAAAJQ"]
[Thu Sep 17 15:49:46.410896 2026] [security2:error] [pid 102783:tid 102932] [client 122.8.45.84:64555] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeszioAAmEecB_LHNsQAAAJg"]
[Thu Sep 17 15:49:46.411088 2026] [security2:error] [pid 102783:tid 102932] [client 122.8.45.84:64555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgeszioAAmEecB_LHNsQAAAJg"]
[Thu Sep 17 15:49:46.789056 2026] [security2:error] [pid 102783:tid 102913] [client 34.154.21.169:36160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/phpinfo.php.bak"] [unique_id "aqxgeszioAAmEecB_LHNwgAAAIU"]
[Thu Sep 17 15:49:47.022038 2026] [security2:error] [pid 102783:tid 102907] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env"] [unique_id "aqxge8zioAAmEecB_LHNygAAqns"]
[Thu Sep 17 15:49:47.032968 2026] [security2:error] [pid 102783:tid 102862] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.old"] [unique_id "aqxge8zioAAmEecB_LHN0wAAqk4"]
[Thu Sep 17 15:49:47.033826 2026] [security2:error] [pid 102783:tid 102862] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.bak"] [unique_id "aqxge8zioAAmEecB_LHN1AAAqk4"]
[Thu Sep 17 15:49:47.034627 2026] [security2:error] [pid 102783:tid 102862] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.backup"] [unique_id "aqxge8zioAAmEecB_LHN1QAAqk4"]
[Thu Sep 17 15:49:47.168445 2026] [security2:error] [pid 102783:tid 102843] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.php"] [unique_id "aqxge8zioAAmEecB_LHN4AAAqjs"]
[Thu Sep 17 15:49:47.169647 2026] [security2:error] [pid 102783:tid 102872] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env~"] [unique_id "aqxge8zioAAmEecB_LHN4gAAqlg"]
[Thu Sep 17 15:49:47.172745 2026] [security2:error] [pid 102783:tid 102806] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.swp"] [unique_id "aqxge8zioAAmEecB_LHN5AAAqhY"]
[Thu Sep 17 15:49:47.303874 2026] [security2:error] [pid 102783:tid 102903] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/api/.env"] [unique_id "aqxge8zioAAmEecB_LHN7QAAqnc"]
[Thu Sep 17 15:49:47.306996 2026] [security2:error] [pid 102783:tid 102838] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/app/.env"] [unique_id "aqxge8zioAAmEecB_LHN7gAAqjY"]
[Thu Sep 17 15:49:47.324464 2026] [security2:error] [pid 102783:tid 102982] [client 34.154.21.169:36174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/phpinfo.php.old"] [unique_id "aqxge8zioAAmEecB_LHN8AAAAMo"]
[Thu Sep 17 15:49:47.369139 2026] [security2:error] [pid 102783:tid 102984] [client 122.8.45.84:11843] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxge8zioAAmEecB_LHN9AAAAMw"]
[Thu Sep 17 15:49:47.369248 2026] [security2:error] [pid 102783:tid 102984] [client 122.8.45.84:11843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxge8zioAAmEecB_LHN9AAAAMw"]
[Thu Sep 17 15:49:47.436899 2026] [security2:error] [pid 102783:tid 102842] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/backend/.env"] [unique_id "aqxge8zioAAmEecB_LHN-wAAqjo"]
[Thu Sep 17 15:49:47.441068 2026] [security2:error] [pid 102783:tid 102859] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/.env"] [unique_id "aqxge8zioAAmEecB_LHN_QAAqks"]
[Thu Sep 17 15:49:47.441469 2026] [security2:error] [pid 102783:tid 102812] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/config/.env"] [unique_id "aqxge8zioAAmEecB_LHN_gAAqhw"]
[Thu Sep 17 15:49:47.447980 2026] [security2:error] [pid 102783:tid 102890] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/src/.env"] [unique_id "aqxge8zioAAmEecB_LHN_wAAqmo"]
[Thu Sep 17 15:49:47.568108 2026] [security2:error] [pid 102783:tid 102839] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/web/.env"] [unique_id "aqxge8zioAAmEecB_LHOAQAAqjc"]
[Thu Sep 17 15:49:47.578089 2026] [security2:error] [pid 102783:tid 102799] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/client/.env"] [unique_id "aqxge8zioAAmEecB_LHOAgAAqg8"]
[Thu Sep 17 15:49:47.580540 2026] [security2:error] [pid 102783:tid 102817] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/public/.env"] [unique_id "aqxge8zioAAmEecB_LHOBAAAqiE"]
[Thu Sep 17 15:49:47.581078 2026] [security2:error] [pid 102783:tid 102804] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/frontend/.env"] [unique_id "aqxge8zioAAmEecB_LHOAwAAqhQ"]
[Thu Sep 17 15:49:47.583106 2026] [security2:error] [pid 102783:tid 102789] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/var/www/.env"] [unique_id "aqxge8zioAAmEecB_LHOBQAAqgU"]
[Thu Sep 17 15:49:47.585627 2026] [security2:error] [pid 102783:tid 102836] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/var/www/html/.env"] [unique_id "aqxge8zioAAmEecB_LHOBgAAqjQ"]
[Thu Sep 17 15:49:47.680722 2026] [security2:error] [pid 102783:tid 103012] [client 169.58.197.253:63288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "p3collaborative.com"] [uri "/index.php"] [unique_id "aqxge8zioAAmEecB_LHN6gAAAOg"], referer: binance.com
[Thu Sep 17 15:49:47.705388 2026] [security2:error] [pid 102783:tid 102835] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/laravel/.env"] [unique_id "aqxge8zioAAmEecB_LHODAAAqjM"]
[Thu Sep 17 15:49:47.714315 2026] [security2:error] [pid 102783:tid 102829] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/application/.env"] [unique_id "aqxge8zioAAmEecB_LHODQAAqi0"]
[Thu Sep 17 15:49:47.716212 2026] [security2:error] [pid 102783:tid 102819] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/back/.env"] [unique_id "aqxge8zioAAmEecB_LHODwAAqiM"]
[Thu Sep 17 15:49:47.716279 2026] [security2:error] [pid 102783:tid 102800] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/apps/.env"] [unique_id "aqxge8zioAAmEecB_LHODgAAqhA"]
[Thu Sep 17 15:49:47.717440 2026] [security2:error] [pid 102783:tid 102877] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/backup/.env"] [unique_id "aqxge8zioAAmEecB_LHOEQAAql0"]
[Thu Sep 17 15:49:47.720530 2026] [security2:error] [pid 102783:tid 102807] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/cms/.env"] [unique_id "aqxge8zioAAmEecB_LHOEgAAqhc"]
[Thu Sep 17 15:49:47.796691 2026] [security2:error] [pid 102783:tid 102995] [client 79.116.89.151:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.89.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxge8zioAAmEecB_LHOFAAAANc"]
[Thu Sep 17 15:49:47.796828 2026] [security2:error] [pid 102783:tid 102995] [client 79.116.89.151:56026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "appalachian-landscapes.com"] [uri "/xmlrpc.php"] [unique_id "aqxge8zioAAmEecB_LHOFAAAANc"]
[Thu Sep 17 15:49:47.845622 2026] [security2:error] [pid 102783:tid 103036] [client 34.154.21.169:36176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/phpinfo.php~"] [unique_id "aqxge8zioAAmEecB_LHOGQAAAQA"]
[Thu Sep 17 15:49:47.847225 2026] [security2:error] [pid 102783:tid 102871] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/dev/.env"] [unique_id "aqxge8zioAAmEecB_LHOGwAAqlc"]
[Thu Sep 17 15:49:47.853142 2026] [security2:error] [pid 102783:tid 102801] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/prod/.env"] [unique_id "aqxge8zioAAmEecB_LHOHQAAqhE"]
[Thu Sep 17 15:49:47.853809 2026] [security2:error] [pid 102783:tid 102894] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/production/.env"] [unique_id "aqxge8zioAAmEecB_LHOHgAAqm4"]
[Thu Sep 17 15:49:47.853810 2026] [security2:error] [pid 102783:tid 102787] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/staging/.env"] [unique_id "aqxge8zioAAmEecB_LHOHwAAqgM"]
[Thu Sep 17 15:49:47.854576 2026] [security2:error] [pid 102783:tid 102809] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/test/.env"] [unique_id "aqxge8zioAAmEecB_LHOIAAAqhk"]
[Thu Sep 17 15:49:47.857918 2026] [security2:error] [pid 102783:tid 102887] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/old/.env"] [unique_id "aqxge8zioAAmEecB_LHOIQAAqmc"]
[Thu Sep 17 15:49:47.946882 2026] [security2:error] [pid 102783:tid 103040] [client 74.7.241.184:33024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "paltals.com"] [uri "/index.php"] [unique_id "aqxgeMzioAAmEecB_LHNWAABBDA"]
[Thu Sep 17 15:49:47.983046 2026] [security2:error] [pid 102783:tid 102841] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/new/.env"] [unique_id "aqxge8zioAAmEecB_LHOKgAAqjk"]
[Thu Sep 17 15:49:47.989268 2026] [security2:error] [pid 102783:tid 102893] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/admin-app/.env"] [unique_id "aqxge8zioAAmEecB_LHOLQAAqm0"]
[Thu Sep 17 15:49:47.989300 2026] [security2:error] [pid 102783:tid 102822] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/api-backend/.env"] [unique_id "aqxge8zioAAmEecB_LHOLAAAqiY"]
[Thu Sep 17 15:49:47.989343 2026] [security2:error] [pid 102783:tid 102898] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/node-api/.env"] [unique_id "aqxge8zioAAmEecB_LHOKwAAqnI"]
[Thu Sep 17 15:49:47.992097 2026] [security2:error] [pid 102783:tid 102824] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/public_html/.env"] [unique_id "aqxge8zioAAmEecB_LHOLwAAqig"]
[Thu Sep 17 15:49:48.045127 2026] [security2:error] [pid 102783:tid 102883] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/administrator/.env"] [unique_id "aqxge8zioAAmEecB_LHOLgAAqmM"]
[Thu Sep 17 15:49:48.121759 2026] [security2:error] [pid 102783:tid 102866] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/current/.env"] [unique_id "aqxgfMzioAAmEecB_LHONQAAqlI"]
[Thu Sep 17 15:49:48.127793 2026] [security2:error] [pid 102783:tid 102870] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.docker/.env"] [unique_id "aqxgfMzioAAmEecB_LHONwAAqlY"]
[Thu Sep 17 15:49:48.128204 2026] [security2:error] [pid 102783:tid 102857] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/api/.env"] [unique_id "aqxgfMzioAAmEecB_LHOOAAAqkk"]
[Thu Sep 17 15:49:48.128852 2026] [security2:error] [pid 102783:tid 102823] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.docker/laravel/app/.env"] [unique_id "aqxgfMzioAAmEecB_LHOOQAAqic"]
[Thu Sep 17 15:49:48.128995 2026] [security2:error] [pid 102783:tid 102864] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/server/backend/.env"] [unique_id "aqxgfMzioAAmEecB_LHONgAAqlA"]
[Thu Sep 17 15:49:48.167542 2026] [security2:error] [pid 102783:tid 102798] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/aws/.env"] [unique_id "aqxgfMzioAAmEecB_LHOOgAAqg4"]
[Thu Sep 17 15:49:48.181149 2026] [security2:error] [pid 102783:tid 102879] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.aws/.env"] [unique_id "aqxgfMzioAAmEecB_LHOOwAAql8"]
[Thu Sep 17 15:49:48.184821 2026] [security2:error] [pid 102783:tid 102803] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/stripe/.env"] [unique_id "aqxgfMzioAAmEecB_LHOPAAAqhM"]
[Thu Sep 17 15:49:48.227490 2026] [security2:error] [pid 102783:tid 102923] [client 165.154.36.113:44176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intolovinghomes.com.au"] [uri "/index.php"] [unique_id "aqxge8zioAAmEecB_LHOGAAAAI8"], referer: https://mdp.iax.mybluehost.me/favicon.ico
[Thu Sep 17 15:49:48.263095 2026] [security2:error] [pid 102783:tid 102846] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v1/.env"] [unique_id "aqxgfMzioAAmEecB_LHORAAAqj4"]
[Thu Sep 17 15:49:48.263143 2026] [security2:error] [pid 102783:tid 102827] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v2/.env"] [unique_id "aqxgfMzioAAmEecB_LHORQAAqis"]
[Thu Sep 17 15:49:48.263991 2026] [security2:error] [pid 102783:tid 102882] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/v3/.env"] [unique_id "aqxgfMzioAAmEecB_LHORgAAqmI"]
[Thu Sep 17 15:49:48.298793 2026] [security2:error] [pid 102783:tid 102792] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/media/.env"] [unique_id "aqxgfMzioAAmEecB_LHOSQAAqgg"]
[Thu Sep 17 15:49:48.350888 2026] [security2:error] [pid 102783:tid 103013] [client 122.8.45.84:52519] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgfMzioAAmEecB_LHOUwAAAOk"]
[Thu Sep 17 15:49:48.350997 2026] [security2:error] [pid 102783:tid 103013] [client 122.8.45.84:52519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgfMzioAAmEecB_LHOUwAAAOk"]
[Thu Sep 17 15:49:48.355866 2026] [security2:error] [pid 102783:tid 103008] [client 34.154.21.169:36186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/info.php.bak"] [unique_id "aqxgfMzioAAmEecB_LHOVAAAAOQ"]
[Thu Sep 17 15:49:48.398961 2026] [security2:error] [pid 102783:tid 102900] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.git/config.bak"] [unique_id "aqxgfMzioAAmEecB_LHOXQAA3nQ"]
[Thu Sep 17 15:49:48.480248 2026] [security2:error] [pid 102783:tid 102884] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.aws/credentials.bak"] [unique_id "aqxgfMzioAAmEecB_LHOZgAAjmQ"]
[Thu Sep 17 15:49:48.534107 2026] [security2:error] [pid 102783:tid 102911] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.ssh/id_rsa"] [unique_id "aqxgfMzioAAmEecB_LHObAAAtH8"]
[Thu Sep 17 15:49:48.536031 2026] [security2:error] [pid 102783:tid 102858] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/id_rsa"] [unique_id "aqxgfMzioAAmEecB_LHObQAAzEo"]
[Thu Sep 17 15:49:48.799928 2026] [security2:error] [pid 102783:tid 102838] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config.php"] [unique_id "aqxgfMzioAAmEecB_LHOlgAAoDY"]
[Thu Sep 17 15:49:48.873463 2026] [security2:error] [pid 102783:tid 102919] [client 86.218.183.192:54304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgfMzioAAmEecB_LHOjgAAi1g"]
[Thu Sep 17 15:49:48.882797 2026] [security2:error] [pid 102783:tid 102985] [client 34.154.21.169:36192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/phpinfo.php.save"] [unique_id "aqxgfMzioAAmEecB_LHOqAAAAM0"]
[Thu Sep 17 15:49:48.889137 2026] [security2:error] [pid 102783:tid 102789] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/aws.php"] [unique_id "aqxgfMzioAAmEecB_LHOqQAA7wU"]
[Thu Sep 17 15:49:48.928239 2026] [security2:error] [pid 102783:tid 102835] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/stripe.php"] [unique_id "aqxgfMzioAAmEecB_LHOrQAA2zM"]
[Thu Sep 17 15:49:48.944092 2026] [security2:error] [pid 102783:tid 102819] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/mail.php"] [unique_id "aqxgfMzioAAmEecB_LHOrwAApCM"]
[Thu Sep 17 15:49:48.945033 2026] [security2:error] [pid 102783:tid 102800] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/config.inc.php"] [unique_id "aqxgfMzioAAmEecB_LHOsAAApBA"]
[Thu Sep 17 15:49:48.945741 2026] [security2:error] [pid 102783:tid 102807] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/config/nexmo.php"] [unique_id "aqxgfMzioAAmEecB_LHOsgAApBc"]
[Thu Sep 17 15:49:48.990421 2026] [security2:error] [pid 102783:tid 102787] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.bak"] [unique_id "aqxgfMzioAAmEecB_LHOtwAAnAM"]
[Thu Sep 17 15:49:48.990804 2026] [security2:error] [pid 102783:tid 102801] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php"] [unique_id "aqxgfMzioAAmEecB_LHOtgAAnBE"]
[Thu Sep 17 15:49:49.005912 2026] [security2:error] [pid 102783:tid 102894] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.old"] [unique_id "aqxgfczioAAmEecB_LHOuAAArm4"]
[Thu Sep 17 15:49:49.006522 2026] [security2:error] [pid 102783:tid 102809] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-config.php.new"] [unique_id "aqxgfczioAAmEecB_LHOuQAA9hk"]
[Thu Sep 17 15:49:49.021955 2026] [security2:error] [pid 102783:tid 102887] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/.wp-config.php.swp"] [unique_id "aqxgfczioAAmEecB_LHOugAAs2c"]
[Thu Sep 17 15:49:49.054006 2026] [security2:error] [pid 102783:tid 102832] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/wp-content/mysql.sql"] [unique_id "aqxgfczioAAmEecB_LHOvQAAqzA"]
[Thu Sep 17 15:49:49.085793 2026] [security2:error] [pid 102783:tid 102840] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/terraform.tfstate.backup"] [unique_id "aqxgfczioAAmEecB_LHOxAAAhTg"]
[Thu Sep 17 15:49:49.319670 2026] [security2:error] [pid 102783:tid 102933] [client 122.8.45.84:14725] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgfczioAAmEecB_LHO7AAAAJk"]
[Thu Sep 17 15:49:49.319781 2026] [security2:error] [pid 102783:tid 102933] [client 122.8.45.84:14725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgfczioAAmEecB_LHO7AAAAJk"]
[Thu Sep 17 15:49:49.410132 2026] [security2:error] [pid 102783:tid 103020] [client 34.154.21.169:36198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/staging/phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHO-AAAAPA"]
[Thu Sep 17 15:49:49.535639 2026] [security2:error] [pid 102783:tid 102863] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHPCgAA508"]
[Thu Sep 17 15:49:49.536547 2026] [security2:error] [pid 102783:tid 102911] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/info.php"] [unique_id "aqxgfczioAAmEecB_LHPDAAAyX8"]
[Thu Sep 17 15:49:49.551531 2026] [security2:error] [pid 102783:tid 102828] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php_info.php"] [unique_id "aqxgfczioAAmEecB_LHPDQAA_yw"]
[Thu Sep 17 15:49:49.551540 2026] [security2:error] [pid 102783:tid 102797] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/infos.php"] [unique_id "aqxgfczioAAmEecB_LHPDgAA_w0"]
[Thu Sep 17 15:49:49.569894 2026] [security2:error] [pid 102783:tid 102813] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/infophp.php"] [unique_id "aqxgfczioAAmEecB_LHPEQAAuB0"]
[Thu Sep 17 15:49:49.569910 2026] [security2:error] [pid 102783:tid 102861] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php-info.php"] [unique_id "aqxgfczioAAmEecB_LHPEAAAuE0"]
[Thu Sep 17 15:49:49.569925 2026] [security2:error] [pid 102783:tid 102909] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/php.php"] [unique_id "aqxgfczioAAmEecB_LHPEgAAuH0"]
[Thu Sep 17 15:49:49.611672 2026] [security2:error] [pid 102783:tid 102851] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHPFAAAuUM"]
[Thu Sep 17 15:49:49.624021 2026] [security2:error] [pid 102783:tid 102808] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/api/phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHPFgAA-hg"]
[Thu Sep 17 15:49:49.624032 2026] [security2:error] [pid 102783:tid 102881] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/admin_phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHPFQAA-mE"]
[Thu Sep 17 15:49:49.624068 2026] [security2:error] [pid 102783:tid 102868] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/admin/phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHPFwAA-lQ"]
[Thu Sep 17 15:49:49.624343 2026] [security2:error] [pid 102783:tid 102891] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.22.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-70311838.newyearworks.com"] [uri "/public/phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHPGAAA-ms"]
[Thu Sep 17 15:49:49.705612 2026] [security2:error] [pid 102783:tid 102788] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/database.sql"] [unique_id "aqxgfczioAAmEecB_LHPIwAAogQ"]
[Thu Sep 17 15:49:49.823098 2026] [security2:error] [pid 102783:tid 103003] [client 194.187.171.146:4631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thevagabondhiker.com"] [uri "/index.php"] [unique_id "aqxgfczioAAmEecB_LHPJAAA3wo"]
[Thu Sep 17 15:49:49.901763 2026] [security2:error] [pid 102783:tid 102862] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/data.bak"] [unique_id "aqxgfczioAAmEecB_LHPRAAAlU4"]
[Thu Sep 17 15:49:49.950193 2026] [security2:error] [pid 102783:tid 103033] [client 34.154.21.169:36208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/beta/phpinfo.php"] [unique_id "aqxgfczioAAmEecB_LHPRwAAAP0"]
[Thu Sep 17 15:49:49.972187 2026] [security2:error] [pid 102783:tid 102800] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/backups/database.sql"] [unique_id "aqxgfczioAAmEecB_LHPSwAArhA"]
[Thu Sep 17 15:49:49.982240 2026] [security2:error] [pid 102783:tid 102859] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/developer/.env"] [unique_id "aqxgfczioAAmEecB_LHPTgAA9ks"]
[Thu Sep 17 15:49:50.033102 2026] [security2:error] [pid 102783:tid 102887] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/.env.local.backup"] [unique_id "aqxgfszioAAmEecB_LHPVQAAs2c"]
[Thu Sep 17 15:49:50.033842 2026] [security2:error] [pid 102783:tid 102793] [remote 34.156.22.222:40856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70311838.newyearworks.com"] [uri "/demo/.env"] [unique_id "aqxgfszioAAmEecB_LHPVwAAswk"]
[Thu Sep 17 15:49:50.260116 2026] [security2:error] [pid 102783:tid 102925] [client 122.8.45.84:36449] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgfszioAAmEecB_LHPXwAAAJE"]
[Thu Sep 17 15:49:50.260241 2026] [security2:error] [pid 102783:tid 102925] [client 122.8.45.84:36449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgfszioAAmEecB_LHPXwAAAJE"]
[Thu Sep 17 15:49:50.473162 2026] [security2:error] [pid 102783:tid 103014] [client 34.154.21.169:36224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/uat/phpinfo.php"] [unique_id "aqxgfszioAAmEecB_LHPagAAAOo"]
[Thu Sep 17 15:49:50.984693 2026] [security2:error] [pid 102783:tid 103035] [client 190.120.252.194:56868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "endless-chronicles.com"] [uri "/explore/wiki/index.php"] [unique_id "aqxgfszioAAmEecB_LHPegAA_x8"]
[Thu Sep 17 15:49:51.007735 2026] [security2:error] [pid 102783:tid 103022] [client 34.154.21.169:36226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/qa/phpinfo.php"] [unique_id "aqxgf8zioAAmEecB_LHPfQAAAPI"]
[Thu Sep 17 15:49:51.245930 2026] [security2:error] [pid 102783:tid 102920] [client 122.8.45.84:44329] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgf8zioAAmEecB_LHPhQAAAIw"]
[Thu Sep 17 15:49:51.246034 2026] [security2:error] [pid 102783:tid 102920] [client 122.8.45.84:44329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxgf8zioAAmEecB_LHPhQAAAIw"]
[Thu Sep 17 15:49:51.510972 2026] [security2:error] [pid 102783:tid 102976] [client 34.154.21.169:36228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/preview/phpinfo.php"] [unique_id "aqxgf8zioAAmEecB_LHPjwAAAMQ"]
[Thu Sep 17 15:49:51.717340 2026] [security2:error] [pid 102783:tid 102963] [client 31.10.170.237:19891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.sharlotbott.com"] [uri "/index.php"] [unique_id "aqxgf8zioAAmEecB_LHPkwAAt1A"]
[Thu Sep 17 15:49:52.045186 2026] [security2:error] [pid 102783:tid 103016] [client 34.154.21.169:36236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.21.154.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1568"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.aellaapartments.com"] [uri "/www/phpinfo.php"] [unique_id "aqxggMzioAAmEecB_LHPpAAAAOw"]
[Thu Sep 17 15:49:52.204197 2026] [security2:error] [pid 102783:tid 102985] [client 122.8.45.84:23645] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1484"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxggMzioAAmEecB_LHPqAAAAM0"]
[Thu Sep 17 15:49:52.204360 2026] [security2:error] [pid 102783:tid 102985] [client 122.8.45.84:23645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "plasticvisual.com"] [uri "/xmlrpc.php"] [unique_id "aqxggMzioAAmEecB_LHPqAAAAM0"]
[Thu Sep 17 15:49:52.330222 2026] [security2:error] [pid 102783:tid 102931] [client 31.10.170.237:19891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1572"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.sharlotbott.com"] [uri "/index.php"] [unique_id "aqxggMzioAAmEecB_LHPrgAAlyQ"]

Youez - 2016 - github.com/yon3zu
LinuXploit